SAFETY ASSESSMENT METHOD, COMPUTER PROGRAM, MACHINE-READABLE STORAGE MEDIUM AND SAFETY ASSESSMENT DEVICE

DE502020010984D1Active Publication Date: 2025-05-28ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502020010984
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-04-25
Filing Date
2020-03-11
Publication Date
2025-05-28
Estimated Expiration
2040-03-11

AI Technical Summary

Technical Problem

Existing safety assessment procedures for production systems are time-consuming and require high levels of personal expertise, making it difficult to efficiently evaluate system changes and ensure compliance with safety standards.

Method used

A software-based procedure for safety assessment that collects and analyzes system model data, process data, and environmental data to automatically evaluate the safety level of production systems, particularly in versatile and customizable production systems.

Benefits of technology

Enables quick and efficient safety assessments, reducing the need for extensive personal involvement and allowing for real-time evaluation of system changes, thereby improving operational safety and reducing risks.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

State of the art

[0001] A method for the safety assessment of a production plant is proposed, wherein the production plant has plant modules and the plant modules are interchangeable and / or supplementable.

[0002] Due to ever-shorter innovation cycles, manufacturing and production facilities must be designed to be adaptable. The ability to assemble, replace, and / or add components, especially so-called system modules, is particularly important for this.

[0003] Document EP 3 098 673 A1, which represents the closest prior art, relates to an automatic validation of safety functions of a modular safety system comprising subsystem modules. Safety-relevant target values ​​of a system forming a modular safety system consisting of at least two subsystem modules, in particular residual error probabilities, failure rates, and / or total reaction times, are stored in machine-readable form in the memory of a verification device, and local, module-specific actual safety-relevant values ​​of at least each individual subsystem module used or intended to be used for the modular construction of the safety system of the system are stored in machine-readable form in the respective subsystem module.The resulting overall safety-relevant actual values ​​are then compared by the checking device with the target values ​​of the system stored in the memory of the checking device and a reaction signal is automatically generated depending on the comparison result.

[0004] The publication DE 10 2008 044018 A1 describes a method for determining a security level in an automation network with nodes by automatically determining the data and process-related connections between the nodes in the automation network and the node-specific security characteristics. The security level in the automation network is then calculated using a calculation rule that combines the determined data and process-related connections between the nodes in the automation network and the determined node-specific security characteristics.

[0005] The document DE 10 2004 020994 A1 relates to a method for the computer-aided design of a safety-related electrical circuit, the method comprising the following steps: providing a plurality of circuit components in a computer-implemented library; computer-aided selection of circuit components from the computer-implemented library; and computer-aided linking of the selected circuit components.

[0006] The paper CHANG KWANGPIL ET AL: "Uncertainty analysis for target SIL determination in the offshore industry," Journal of loss prevention in the process industries, Elsvier, United Kingdom, Vol. 34, January 26, 2015, pages 151-162, XP029155189, addresses the problem of addressing uncertainties in the safety integrity level (SIL) determination phase and presents a practical approach for the offshore industry. Specifically, the risk graph method, LOPA, and the minimum SIL requirement in OLF 070 (OIL AND GAS APPLICATION OF IEC 61508 AND IEC 61511) were introduced and examined with regard to analyzing the uncertainty affecting their SIL results.

[0007] IEC 619362-1 ED3 discloses standards for high-voltage electrical installations. It addresses a building located near high-voltage lines or high-voltage transformer stations. It specifies minimum safety distances to people, house walls, and roofs that must be maintained. Among other safety measures, it lists: avoiding direct contact (e.g., by using barriers or railings, reducing moisture or humidity). The standard discloses safety distances from high-voltage electrical installations to walls that must be maintained during the planning and implementation of stationary high-voltage installations.

[0008] The publication DE 2016 204 174 A1 describes an automation system for automating manufacturing steps, production steps, and applications. The automation system comprises at least one functional module and at least one evaluation unit. The functional module can be arranged in a system area and the functional module comprises a sensor unit for recording environmental data. The evaluation unit is designed to determine the position of the functional module in the system area. Disclosure of the invention

[0009] A method for assessing the safety of a production facility is proposed, comprising the features of claim 1. Furthermore, a computer program for implementing the method, a machine-readable storage medium, and a safety assessment device are proposed. Preferred and / or advantageous embodiments of the invention are evident from the subclaims, the description, and / or the accompanying figures.

[0010] A method for the safety assessment of a production facility is proposed. The safety assessment is designed, for example, as a review of compliance with a required safety level. In particular, the safety assessment is to be understood as a safety relevance to an environment, to components of the production facility, and / or interaction with persons. The method serves, in particular, to subject a configuration change and / or system change of the production facility to a risk assessment and / or safety assessment. In particular, the method is executable and / or implementable as software. The production facility is designed, for example, for the manufacture, assembly, inspection, and / or transport of an object, in particular a component. In particular, the production facility is a versatile and / or adaptable production facility.

[0011] The production plant comprises at least one plant module. Preferably, the production plant comprises a plurality of plant modules. The production plant in particular has a plant room, which can be designed, for example, as a sub-area of ​​a factory and / or factory plant. The plant modules can be arranged in the plant room. In particular, the plant modules can be freely arranged in the plant room. The plant modules of a production plant are, in particular, interchangeable, supplementable, and / or movable. For example, a production plant can be supplemented by further plant modules, a plant module of the production plant can be replaced by a similar or different plant module, and / or the plant modules can be moved and / or rearranged in the plant room. The plant modules preferably have a process function, in particular for the production, processing, and / or transport of the component.The system modules are designed as robot systems, for example, as a multi-axis robot. The system modules can be stationary or mobile. By exchanging, supplementing, and / or rearranging the system modules, the production system can be designed to be adaptable. The system modules specifically form plug-and-produce system modules. It is particularly preferred that the system modules are designed to provide system module data, wherein the system module data includes, for example, self-describing data, such as their functionality or capability, and / or process-related parameters.

[0012] The method provides for the collection of plant module data, process data and environmental data. In particular, the collection of plant module data, process data and environmental data takes place during the runtime of the production plant and / or the plant modules. In particular, the collection of plant module data, process data and environmental data takes place continuously. Plant module data is, for example, a self-description of the plant modules. Process data can be understood as data that is necessary and / or must be set to carry out production and / or activities in the production plant. For example, process data can include a sequence of the steps to be carried out for production. Environmental data is, for example, data on the plant room, obstacles and / or geometries therein. For example, environmental data can include information on walls and / or on the arrangement of the production plants in relation to one another.In particular, the collection of plant module data, process data, and / or environmental data is carried out mechanically, for example, using software and / or a computer. For example, the collection of plant module data, process data, and environmental data is carried out centrally, with the central collection taking place for multiple plant modules of the process plant.

[0013] The method provides for an analysis of the collected data as a procedural step. The analysis of the collected data is carried out for the safety assessment of the production plant, in particular for the safety assessment of the existing and / or current configuration of the production plant. The collected data comprises in particular the plant module data, the process data and / or the environmental data. The existing configuration is understood to be an arrangement and / or the entirety of the plant modules of the production plant at the respective point in time. The respective point in time can in particular be understood to be a time interval, with one time interval transitioning into another time interval when a change is made to the arrangement, the comprehensive plant modules and / or other specific parameters of the production plant. For example, by adding a plant module, an existing configuration can be assumed to be a new existing configuration.By analyzing and / or evaluating the collected data, it is assessed, for example, whether the arrangement and / or the production plant can be operated safely and / or whether safety standards are being violated. For example, the safety assessment concerns whether damage to the plant modules is to be expected and / or whether people are at risk from operating the production plant and / or plant modules. Furthermore, the safety assessment can include an electrical safety assessment, a data protection safety assessment, an explosion protection assessment, and / or a radiation protection safety assessment. In particular, the safety assessment can aim to inform a user how the current configuration should be adapted and / or whether optimization is necessary to improve the safety assessment and / or to ensure that no damage or hazards are present.The analysis of the collected data can, for example, be performed continuously; alternatively and / or additionally, the analysis of the collected data can be triggered by a change in the existing configuration, so that a new analysis is performed whenever the existing configuration changes. It is particularly preferred that the analysis of the collected data takes place during the operation of the production plant. The analysis of the collected data is preferably computer-aided and / or software-implemented.

[0014] The procedure provides for a safety assessment of the modified production facility to be performed automatically upon integration, replacement, and / or modification of a plant module during the production facility's operation. For example, it is detected that a plant module has been replaced, supplemented, added (also referred to as integration), and / or relocated, resulting in a modified production facility and / or modified configuration. This triggers a new analysis for the safety assessment.

[0015] In particular, the replacement, addition and / or removal of a plant module can be understood as a modified production plant and / or new configuration.

[0016] This provides a process specifically designed for adaptable and / or plug-and-produce production facilities, allowing for rapid safety assessments. In particular, the process steps are performed using software and / or a computer, thus reducing the need for lengthy, personal and labor-intensive safety assessments. In particular, the safety assessment is performed during production and the operation of the production facility, allowing changes to be considered instantly.

[0017] This solves the problem that system adaptations and / or system changes to a production facility could previously only be tested in a very time-consuming manner and required a high level of human expertise. The present invention provides a concept that, as a software solution, can implement a method that enables a risk assessment for the adaptable production facility. The concept includes analyzing the safety level based on the automatically collected data in order to determine, for example, the safety status of the newly configured entire facility.

[0018] One embodiment of the invention provides that the plant module data, the process data, and / or the environmental data are designed as reusable and / or standardized data sets. Standardized and / or reusable data sets are understood to be, for example, data sets that have a common, uniform, and / or similar data structure. For example, the plant module data includes and / or describes safety functions for the plant modules and / or includes safety-relevant information about the plant modules. The process data includes and / or describes, for example, safety functions and / or safety-relevant information about the processes and / or functions. For example, the process data can include information on the interaction between multiple plant modules.The environmental data includes, for example, safety information regarding the environment, such as information about areas where people may be located and / or where obstacles may be and / or are located.

[0019] Optionally, it is provided that display data is presented to a user graphically. The display takes place, for example, on a display unit, for example a display and preferably on a touchscreen. The display data is shown, for example, using a GUI. The display is preferably implemented using software. The display data can also be displayed alphanumerically and graphically. The display data include, for example, the safety assessment, so that the result of the analysis and / or the safety assessment is provided and displayed, in particular, to the user. In particular, the display and / or the display data can also be designed as a 3D view of the production plant. For example, the 3D view allows a user to quickly and visually identify safety-relevant information.In particular, it can also be provided that the 3D view of the production plant includes the safety assessments, so that these are displayed, for example, in the 3D view and / or the model. Furthermore, the display data can include suggestions for improvement, for example, how the safety assessment can be improved. The display data can, in particular, also include context information. The context information is, for example, the application and / or information about which standard is used to analyze the data. For example, the context information can include which DIN standard is applied and / or which safety-relevant aspects are being tested, for example, whether electrical safety or exclusion safety is being tested. Furthermore, the display data can include selection options.For example, the user may be presented with options to select, such as context information selection options and / or which context information to apply. Furthermore, the display data may include database information, such as which information and / or databases are being and / or can be accessed.

[0020] In particular, it is intended that user profiles can be selected, defined and / or saved. The user profiles can be defined and / or directed at individual users; alternatively and / or additionally, the user profiles can be directed at user groups, for example different security personnel and / or security experts and / or people with different levels of experience (layperson, trained operator, engineers, engineers with a security background, etc.), for example from different fields such as electrical engineering or explosion protection. In particular, it is intended that the display data and / or the display data to be displayed are related to the user profiles. For example, a user profile is assigned which of the display data and / or which parts of the display data are to be displayed. The display data to be displayed can be personally defined, for example initially and / or by selection.Alternatively, the display data to be displayed can be preset for the user profiles and / or adapted through machine learning.

[0021] For example, the user can select their user profile, in which case the corresponding display data will be shown to the user. By displaying the display data to be displayed, the user can, in particular, select and / or display additional data.

[0022] It is particularly preferred that the collected data be saved. In particular, the collected data is saved for the associated existing configuration. For example, if the existing configuration is changed, the data to be collected is saved in a new and / or additional data set. For example, the collected data is saved for the configuration. In particular, the collected data can be saved for the security assessment; for example, this makes it possible to trace how the security assessment was determined. In particular, the associated security assessment can be saved for the existing configuration and / or for each existing and / or changed configuration. For example, a user can load the security assessment for an existing configuration in this way.The idea behind this design is to provide a procedure that can be easily and efficiently integrated into a quality management system.

[0023] One embodiment of the invention provides that the analysis of the collected data for the safety assessment comprises at least one, preferably several analysis steps. The analysis steps and / or the order in which the analysis steps are carried out is stored in analysis modules. The analysis module describes, for example, which analysis steps are to be carried out to analyze the collected data for the safety assessment. The analysis modules are preferably stored and / or storable. Analysis modules can, for example, relate to different analyses, for example the analysis of the data for the assessment of the electrical, mechanical, radiation protection, or explosion protection safety assessment. In particular, a user can select an analysis module to be used. For example, relevant and / or all analysis modules are displayed to the user, with the user selecting the analysis module to be used.In particular, the user can be provided with a pre-selection of analysis modules so that, for example, only analysis modules are displayed that are useful and / or possible for the data collected.

[0024] It is particularly preferred that the collected data is analyzed using the analysis steps, wherein the analysis steps are stored in analysis modules as described above. The selection of the analysis modules to be used and / or the analysis module to be used preferably occurs automatically, in particular in the form of a preselection that must be verified by a user. For example, the automatic selection of the analysis module to be used is based on context information. The context information describes, for example, the production plant and / or the participating plant modules. For example, it is known that a participating plant module has an increased electrical hazard potential, so that the context information is aimed, for example, at examining the collected data for electrical safety.In particular, the automatic selection of the analysis modules to be applied can be carried out and / or improved by using a neural network and / or machine learning algorithms.

[0025] According to the invention, the collected data is analyzed using a computer-aided simulation device. Specifically, the collected data is analyzed using a physics engine, also known in English and / or in technical terms as a physics engine. According to the invention, the simulation is performed in a 3D scene and / or in a 3D model of the production plant. For example, to analyze the collected data, the simulation device can simulate the analysis module and / or one of the analysis modules, for example in the form of differential equations. The simulation and / or analysis using the simulation device is performed, for example, using known physical, chemical, and / or mechanical laws. Specifically, the collected data can be analyzed by simulating the functions of the plant modules, for example based on the plant module data, the process data, and / or the environmental data.

[0026] Specifically, it is intended that the security assessment be provided and / or displayed to a user. The security assessment is to be approved and / or rejected by one or more persons. In particular, the security assessment can be amended and / or improved. Specifically, it is intended that the security assessment is to be approved and / or rejected by independent persons and / or groups of persons, thus achieving additional security.

[0027] According to the invention, the method steps are implemented in software. For example, the method and / or the method steps are carried out by software. The method and / or the method steps can be carried out as a software implementation, for example, on a computer, a processor, or a computer.

[0028] A further subject of the invention is a computer program. The computer program is designed to carry out the method as described above when the computer program is executed on a computer, a processor, and / or a safety assessment device.

[0029] A further subject matter of the invention is a machine-readable storage medium, wherein the storage medium comprises the described computer program. In particular, the computer program is stored on the machine-readable storage medium as described above. The machine-readable storage medium is, for example, a CD, a DVD, a memory chip, and / or a USB stick.

[0030] A further subject of the invention is a safety assessment device for assessing the safety of a production plant. The safety assessment device is designed, for example, as a central device, for example, as a computer unit. The production plant is designed, in particular, as described above and / or comprises at least one, preferably several, plant modules. The plant modules of the production plant are interchangeable, can be arranged in a spatially variable manner, and / or can be supplemented. For example, a plant module can be added to the production plant, removed, or the plant modules can be spatially rearranged so that other production processes and / or process steps can be carried out.

[0031] The safety assessment device has a data interface for data-based coupling with at least one of the system modules, preferably with several or all of the system modules of the production plant. The data interface can be a virtual interface; alternatively and / or additionally, the data interface is designed as a real interface, for example, as a radio interface or cable interface. In particular, system module data, process data, and / or environmental data can be provided to the safety assessment device via the data interface. For example, the system module can thus provide its functions, capabilities, and / or hazard potentials to the safety assessment device as system module data.

[0032] The safety assessment device has an evaluation module. The evaluation module can be embodied as a hardware or software module. The evaluation module is designed to carry out the method as described above and / or method steps of the method. For example, the evaluation module is designed to collect data via the data interface, for example to collect the system module data, collect process data, and / or collect environmental data. Furthermore, the evaluation module is designed, for example, to analyze the collected data and carry out a safety assessment of the existing configuration, in particular of the production system. In particular, the safety assessment device is designed to carry out the analysis and / or the collection of data during the runtime of the production system.In particular, the safety assessment device is designed to detect a change in the existing configuration, for example because a system module has been exchanged, supplemented or replaced and / or because system modules have been spatially re-arranged, and to collect further data after this detection and to subject this collected data to a further safety assessment and to analyze this data.

[0033] This provides a safety assessment system that can detect changes in a production facility and quickly and easily perform a safety assessment, for example, by computer-aided evaluation and assessment of the collected data. Specifically, it enables a continuous safety assessment during the operation of the production facility.

[0034] It is particularly preferred that the safety assessment device has a display unit for displaying display data. The display unit is preferably designed as a screen, in particular as a touchscreen. In particular, a user can evaluate, accept, adjust, or reject the safety assessment using the display unit. The display unit forms, for example, an input unit.

[0035] Optionally, the safety assessment device may have a database interface. The database interface may be implemented as a virtual or real interface. Database information is provided and / or can be provided to the safety assessment device via the database interface. The database information may include, for example, applicable analysis modules and sample analysis modules. Furthermore, the database information may include DIN standards, safety protocols, safety requirements, and / or additional information for the safety assessment of the production facility.

[0036] Further advantages, effects, and embodiments of the invention will become apparent from the accompanying figures and their description. In the following, Figure 1 shows a schematic representation of a production plant and its components; Figure 2 shows an exemplary schematic process flow; Figure 3 shows a further exemplary process flow; Figure 4 shows an exemplary computer implementation of the process.

[0037] Figure 1shows a schematic of a production plant 1. The production plant 1 comprises a plurality of plant modules 2. The plant modules 2 are arranged in a plant room 3. The production plant 1 is designed for the production and / or processing of a component. The plant modules 2 are modular plant modules that can be freely arranged within the plant room 3. The plant modules 2 are designed to carry out an electrical, mechanical or measuring step. In particular, the plant modules 2 can be operated in an interactive manner with one another. The plant modules 2 have interfaces for radio data transmission 4. In particular, plant modules 2 that participate in the production plant 1 can be exchanged for further, different and / or plant modules 2'.

[0038] In order for the production plant 1 to be operable, in particular in terms of occupational health and safety regulations and / or production or safety technology, the production plant 1 must be checked for compliance with safety standards and / or safety levels. Such a check is understood in particular as a safety assessment of the production plant 1. After the configuration changes when a plant module 2 is replaced with a plant module 2' or by integrating another plant module 2', the safety assessment must be performed again in the event of such a change. This is done in particular by means of a safety assessment device 5. The safety assessment device 5 carries out a method as a software application and / or in a computer-protected manner. By means of this method and / or by applying the safety assessment device 5, an efficient safety assessment can be carried out, in particular with reduced personnel expenditure.

[0039] For this purpose, data must be provided to the safety assessment facility 5 and / or the facility must collect this data. The data to be collected is specifically referred to as collected data 6. The collected data 6 includes environmental data 7, plant module data 8, and process data 9.

[0040] The environmental data is a model of the plant room 3. The environmental data 7 depends, for example, on the environment in which the production plant is operated, for example the factory room of the factory 10. The environmental data 7 are provided in data form to the safety assessment device 5.

[0041] The production plant 1 comprises a plurality of plant modules 2. The plant modules 2 comprise plant module data 8, which, for example, describe and / or include their functionality and / or their hazard potential. The plant module data 8 can be provided as a manufacturer data set 11. The plant module data 8 is provided to the safety assessment facility 5.

[0042] The process-related information, also referred to as process data 9, depends on the product being manufactured. For example, the process data 9 can describe and / or include hazardous steps during production. The process data 9 is provided to the safety assessment device 5. In particular, the process data 9, the system module data 8, and the environmental data 7 are continuously provided to the safety assessment device 5. In particular, this collected data is stored by the safety assessment device 5.

[0043] The safety assessment device 5 is configured to analyze and / or evaluate the collected data, here the environmental data 7, the process data 9, and the plant module data 8. Analyzing the collected data serves to assess the safety level of the production plant in its current configuration. In doing so, the production plant 1 in its current configuration is checked for compliance with safety standards, potential hazards are identified, and suggestions for improvement can be made if necessary. The analysis and / or safety assessment is based in particular on safety regulations, which may, for example, be contained in database information.

[0044] The analysis of the collected data and the safety assessment performed by the safety assessment facility 5 ultimately result in the safety assessment being made available to a user 12. The safety assessment must be reviewed, verified, or rejected by the user 12. If necessary, the safety assessment can be amended, adapted, and / or improved by the user 12, depending on the situation, with or without actual adjustments to the plant module 2, the process 9, or the production plant 1. After the safety assessment has been approved by the user 12, the production plant 1 can be operated safely. A change to the production plant 1 through the integration or replacement of a plant module 2 results in a new safety assessment by the safety assessment facility 5.

[0045] Figure 2shows a schematic abstraction of the method according to the invention in one exemplary embodiment. In a method step 100, the data is collected. The data collection relates to environmental data 7, system module data 8, and process data 9. This data collection occurs, in particular, continuously.

[0046] In an evaluation step 200, the collected data is analyzed and evaluated. In particular, a context analysis can be performed. Based on this analysis, context information can be compiled. In a context identification step 300, this information is used, for example, to display useful analysis modules 14a-14e (the analysis modules being expandable) to the user 12 in a display 13. The analysis modules 14a-14e describe, for example, different analysis options for the collected data for different safety assessments. For example, the analysis module 14a describes an inspection for flying objects and / or items during execution and / or operation of the production plant 1. The analysis module 14b describes a safety assessment with regard to route planning and / or trajectory planning and / or obstacles.The analysis module 14c describes, for example, the presence of falling objects and, optionally, the formation of new crushing and cutting points. The analysis module 14d describes, for example, safety hazards caused by laser radiation, scattered radiation, or light reflections. The analysis module 14e describes, for example, distance problems and / or bottlenecks that can lead to safety problems and / or are required by safety standards. The user 12 can, for example, select one of these analysis modules 14a-14e as the analysis module to be applied. This analysis module is fed to the context identification step 300.

[0047] In a security assessment step 400, the selected analysis module 14 is applied to the collected data. The collected data is transferred, for example, from the evaluation step 200 to step 400. The evaluation and / or application of the analysis module 14 serves to determine the security level and results in a security assessment, which is displayed in an output step 500.

[0048] Figure 3 shows a further embodiment of the method in an abstract representation. The method comprises five method steps 600, 700, 800, 900, and 1000. Method steps 600 to 1000 are executed cyclically, with method step 1000 being followed by method step 600. The method and the method steps can be implemented in software, for example, by means of a computer unit or the safety assessment device 5.

[0049] In method step 600, also called the runtime integration step, a production plant 1 is adapted and / or modified by a user 12. Plant modules 2 are, for example, replaced and / or newly added. The plant modules 2 perform production tasks and / or functions within the production plant 1. The plant modules 2 have radio interfaces 15, via which plant module data 8 are provided for implementing the method, for example, to the safety assessment device 5.

[0050] In configuration step 700, environmental data 16 for implementing the method is read in, collected, and / or provided by a user. The environmental data 7 describes the system space as a spatial model. The environmental data 7 further includes information on distances and / or obstacles. Furthermore, the environmental data includes distances between the system modules 2.

[0051] In the process data collection step 800, data is collected that describes the process and / or production of the production plant 1. For example, this data includes the interaction between the plant modules 2 as well as the tasks of user 12 during operation. In particular, the collection and / or

[0052] Collecting the data in steps 600, 700 and 800 can be operated and / or carried out automatically by the safety assessment device 5 and / or a software as data collection.

[0053] In the safety determination step 900, the collected data is analyzed, and based on this, a safety assessment of production facility 1 is performed. The safety assessment includes, for example, an investigation into existing hazard sources. The safety assessment can be issued as a hazard report or as safety documentation containing hazard sources, risk levels, and relevant safety measures.

[0054] Method step 1000 concerns the human evaluation of the computer-generated safety assessment. The safety assessment is displayed to a person 12, in particular a safety engineer, who can check the safety assessment for accuracy and accept 15, reject 16, or change it.

[0055] If the safety assessment has been accepted, production facility 1 can be operated routinely. However, process step 1000 is followed by process step 600, so that if a change is made to production facility 1, process steps 600, 700, and so on are repeated, and the modified production facility 1 is subjected to a safety assessment.

[0056] Figure 4shows an example of a possible software architecture for carrying out the method and / or the computer program. The structure of the computer program 20 comprises several sub-software modules. The computer program 20 is designed to interact with the system modules 2 of the production system 1. This interaction is embodied as a data exchange 21 between the computer program 20 and the system modules 2. During this data exchange 21, system module data is exchanged. Furthermore, environmental data and process data can be collected by the computer program 20 by means of the data exchange 21 and / or by means of further data exchange. In an additional data exchange 22, data can be obtained from a cloud 23 or stored therein. For this purpose, the software 20 comprises a communication interface 24. The communication interface forms a virtual interface for data exchange.The communication interface 24 in turn exchanges data with an application module 25 and an implementation module 26.

[0057] The software 20 further comprises a user interface 27, which is also called a user interface in English. The user interface 27 can, for example, form a user interface for common operating systems. For example, the user interface 27 is implemented in the C# programming language. In the user interface 27, interaction elements for the user 12 are represented and / or implemented, in particular visually. Furthermore, the user interface 27 has a 3D display, wherein a spatial configuration of the production plant is and / or is displayed in the 3D display. Furthermore, the user interface 27 includes user management, in which the user interface was and / or is adapted with regard to the user. Both the display of the 3D display of the production plant 1 and, in particular, the interaction elements depend on the selected user profile.

[0058] The user interface 27 exchanges data with the application module 25. For example, applications and / or processes can be started, configured, or stopped using the user interface 27 in the module 25. The application module 25 designates and / or describes functions and / or program components of the software to support and / or carry out the risk assessment. Risk assessment is understood, in particular, to mean the safety assessment. In this module 25, data is collected, data is processed, and analysis modules 14 are called. Furthermore, information can be output in this module 25. The application module 25 collects the data as collected data, in particular the environmental data, the process data, and the system module data. The application module 25 exchanges data with a data management module 28.Data management module 28 is designed to store the data of the respective configuration 29 as well as the data 30 calculated from this data, which includes, for example, the safety assessment.

[0059] The application module 25 communicates with the module 26 in terms of gardening technology. A network management module 31 is stored in the module 26, which is designed to retrieve data from the cloud 23. A physics engine 32 is also stored, which is designed to perform data analyses and / or simulations. Furthermore, a library 33 is stored in this module 26, which can, for example, access standards and / or has stored security standards or analysis protocols.

[0060] Module 26 communicates with an analysis module storage module 34, in which the various analysis modules 14a, 14b, 14c, and possibly others, are stored. From this module, the respective selected analysis module can be retrieved and accessed. Module 26 is then configured to perform the security assessment based on the collected data, the selected module, the cloud-related data, and / or by means of the physics engine 32. The determined security assessment can then be displayed to user 12 via application module 25 on user interface 27.

Claims

1. Method for assessing the safety of a production plant (1), wherein the production plant (1) has at least one plant module (2, 2'), wherein the plant module (2, 2') is interchangeable and / or plant modules (2, 2') can be added, wherein the at least one plant module (2, 2') is designed as a robot plant, having the software-implemented method steps of: - collecting plant module data (8), process data (9) and environmental data (7) as collected data, - analysing the collected data for the safety assessment of the present configuration by means of a computer-aided simulation device, wherein, if the plant module (2, 2') is interchanged or if a plant module (2, 2') is added and / or removed during production and a running time of the production plant (1), a safety assessment of the modified production plant (1) is automatically carried out by means of the method steps, wherein the environmental data (7) comprise data from a plant room on obstacles and / or geometries therein or walls, wherein display data comprising the safety assessment are displayed graphically to a user (12), wherein the production plant (1) is operated safely after the safety assessment has been approved by the user (12), wherein the environmental data (7) describe the plant room as a spatial model, wherein a simulation is carried out in a 3D scene and / or in a 3D model of the production plant (1), and wherein the safety assessment includes an analysis with respect to path planning and / or trajectory planning and / or the obstacles.

2. Method according to Claim 1, characterized in that the plant module data (8), the process data (9) and / or the environmental data (7) are formed as reusable and / or standardized data sets.

3. Method according to Claim 1 or 2, characterized in that the display data comprise a 3D view of the production plant (1), context information, database information and / or selection options.

4. Method according to Claim 3, characterized in that user profiles are selectable and / or definable, wherein the display data to be displayed are from the selected user profile.

5. Method according to one of the preceding claims, characterized in that the collected data for the present configuration are stored and / or in that the safety assessment is stored.

6. Method according to one of the preceding claims, characterized in that the analysis of the collected data for the safety assessment comprises analysis steps, wherein the analysis steps are stored in analysis modules (14a-14e), wherein an analysis module to be used can be selected from the analysis modules (14a-14e) by the user (12).

7. Method according to one of the preceding claims, characterized in that the analysis of the collected data for the safety assessment comprises analysis steps, wherein the analysis steps are stored in analysis modules (14a-14e), wherein an analysis module to be used is automatically selected from the analysis modules (14a-14e) based on context information.

8. Method according to one of the preceding claims, characterized in that the safety assessment must be evaluated, adapted and / or rejected by a user (12).

9. Computer program, wherein the computer program is designed to carry out the method according to one of the preceding claims when the computer program is executed on a computer, a processor and / or a safety assessment device (5).

10. Machine-readable storage medium, wherein the computer program according to Claim 9 is stored on the storage medium.

11. Safety assessment device (5) for assessing the safety of a production plant (1), wherein the production plant (1) has at least one plant module (2, 2'), wherein plant modules (2, 2') are interchangeable and / or can be added, having a data interface for coupling to at least one of the plant modules (2, 2') using data technology, characterized by an evaluation module, wherein the evaluation module is designed to carry out the method and / or the method steps according to one of Claims 1 to 8.

12. Safety assessment device (5) according to Claim 11, characterized by a display unit (13) for displaying the display data.

13. Safety assessment device (5) according to either of Claims 11 and 12, characterized by a database interface for obtaining database information.