SAFETY-ORIENTED CONTROL SYSTEM
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2020-06-19
- Publication Date
- 2026-04-02
AI Technical Summary
Existing safety-related control systems for hazardous plant components are inflexible, require extensive wiring, and are complex to configure and maintain, necessitating high bandwidth communication and central control that is prone to errors.
A decentralized safety-related control system using a fieldbus to directly connect safety sensors and actuators, allowing for simple configuration and execution of safety responses via a programming device that assigns safety responses to individual lines, eliminating the need for central control and reducing bandwidth requirements.
Facilitates simple, safe, and flexible configuration of safety responses, reduces maintenance effort, and minimizes errors by decentralizing logic execution within the safety actuator units, enhancing system safety and efficiency.
Description
[0001] The present invention relates to a safety-related control system and a method for operating a safety-related control system.
[0002] Safety-related control systems are used in process and automation engineering to safeguard hazardous plant components and thus prevent personal injury or material damage. This is typically achieved using so-called safety functions, which are triggered by safety-related sensors, such as emergency stop buttons, light barriers, or similar devices. When these safety functions are executed, the hazardous plant components are brought to a safe state, for example, shut down or operated within a safe parameter range that eliminates any risk. This transition to a safe state via the safety function constitutes a safety-related response or a safety reaction.
[0003] The execution of safety functions is generally carried out in such a safeguarded manner that malfunctions cause an automatic return of the hazardous part of the system to a safe state. Permissible safety functions and their configurations are defined in various national and international standards.
[0004] To execute safety functions, safety-related control systems typically include safety-related actuators in addition to safety-related sensors. These actuators execute the safety responses. Such actuators can be designed, for example, as contactors that interrupt the power supply to the hazardous part of the system, or as protected drives that restrict the position and / or movement of the hazardous part to a safe parameter range. Safety responses that can be executed by drives include, for example, an uncontrolled shutdown (STO). - safe torque off or safely switched-off moment), a safely limited speed operation (SLS - safely limited speed ) or a safely regulated shutdown ( safe stop ).
[0005] The signal-based linking of safety-related sensors and actuators for the execution of safety functions is achieved, among other things, using hard-wired safety relays, in which the individual actuators are connected to the sensors used for triggering via separate lines. However, such a solution is very inflexible and requires a high degree of wiring. Furthermore, the system can only be subdivided into areas with different safety requirements and safety responses with considerable effort.
[0006] In addition to hardwired safety relays, dedicated safety controllers can also be used. These controllers are connected to the safety-related sensors and actuators of a plant or plant area, for example via a fieldbus, and control the safety-related actuators based on logical operations derived from input signals provided by the safety-related sensors. Such safety controllers typically require complex programming and validation of the logical operations. Furthermore, data transmission between the central safety controller and the safety-related sensors and actuators requires a communication channel with a sufficiently high bandwidth.
[0007] The publications EP 2 302 472 A2 and DE 10 2012 102 187 B3 each describe control systems for controlling safety-critical processes in which safe network participants carry out fail-safe communication with each other.
[0008] The object of the invention is to improve a safety-oriented control system and a method for operating a safety-oriented control system, among other things, in such a way that safety functions can be configured and executed simply and safely.
[0009] This task is solved by a safety-related control system and a method for operating a safety-related control system according to the independent claims. Further developments are specified in the dependent claims.
[0010] A safety-related control system is specified, comprising at least one safety sensor unit and at least one safety actuator unit, which are interconnected via a fieldbus, and a programming device. The at least one safety sensor unit provides sensor connections for connecting safety sensors to the fieldbus, with the sensor connections being assigned to safety lines. The programming device is configured to display the available safety lines to a user via an output interface and to receive user input via an input interface, whereby the user input assigns a selected safety response, executable by the safety actuator unit, to at least one selected safety line.The programming unit is further configured to store the assignment between the selected safety line and the selected safety response in the safety actuator unit as a safety configuration. The safety lines assigned to the individual sensor connections can be activated independently by the at least one safety sensor unit by sending line activation signals from the individual safety lines. The safety actuator unit is configured to receive the line activation signals directly from the at least one safety sensor unit via the fieldbus and, upon receiving a line activation signal from an activated safety line, to independently execute the safety response stored in the safety configuration for that activated safety line.
[0011] In such a safety-oriented control system, the individual safety responses of the safety actuator unit connected to the fieldbus are not controlled by a central safety controller, but are triggered directly in the safety actuator unit by the at least one safety sensor unit via the safety lines over the fieldbus. The necessary logic for executing the safety responses, in the form of the safety configuration, is stored decentrally within the safety actuator unit, and the safety actuator unit executes the assigned safety responses independently, without the involvement of an intermediate control unit, when it receives the line activation signals directly from the at least one safety sensor unit via the fieldbus.The safety lines that can be activated via the fieldbus by the at least one safety sensor unit thus each form direct fixed wiring or links between the safety actuator unit and the sensor connections of the at least one safety sensor unit that are assigned to the individual safety lines.
[0012] Such direct triggering of safety responses via pre-configured safety lines over a fieldbus reduces the bandwidth required for implementing the safety responses on the fieldbus, since only a single line activation signal needs to be transmitted for each safety line, which can then directly trigger a safety response in virtually any number of safety actuator units. For example, it is not necessary to generate and transmit a separate output signal over the fieldbus for each safety actuator unit addressed by an activated safety line, or for each safety response.
[0013] In the claimed safety-related control system, the safety responses executed by the safety actuator unit can be defined by simply configuring the safety actuator unit. This is done by assigning safety responses to each safety line and then storing them as a safety configuration within the safety actuator unit. Therefore, the complex creation of a control program that maps all safety responses of the safety-related control system, as would be required, for example, for a central safety controller, is eliminated. Consequently, the effort and potential for errors during commissioning of the control system are reduced.Furthermore, the maintenance effort during operation is reduced, since when changes are made to the safety-related control system, for example when adding or removing individual safety actuator units or safety sensor units, only individual configurations need to be changed, but not a complex control program.
[0014] Outputting the available safety lines via the programming device's output interface and configuring the safety response to assign the safety response and safety line via user input through the input interface has the technical effect of providing a user interface that enables simple and safe configuration of the safety response. This user interface replicates the separate wiring of a safety relay with individual safety sensors, a process already familiar to those skilled in the art, and is thus particularly well-suited to the concept of individual safety circuits. This allows even inexperienced users to quickly and easily configure the control system with a focus on safety.
[0015] For example, the safety lines displayed via the output interface represent individual safety circuits to which the user can "connect" the safety actuator unit using user input received via the input interface. This results in expanded configuration options compared to hardwiring, as any safety response executable by the safety actuator unit can be assigned to the safety line. Such a safety response can, for example, include a safely limited speed (SLS) or a safely controlled shutdown (SS1 / SS2) and is therefore not limited to a safe uncontrolled shutdown (STO), as would be the case with a simple safety relay.
[0016] The safety-related control system can include, in addition to the claimed safety actuator unit, further safety actuator units connected to the fieldbus and configured in the same way as the claimed safety actuator unit. The programming device can receive at least one user input for each safety actuator unit via the input interface, which assigns a selected safety response executable by the respective safety actuator unit to at least one safety line. The individual assignments between the safety lines and the safety responses can be stored as safety configurations in each safety actuator unit. The safety responses assigned to the individual safety actuator units can differ from one another.
[0017] The claimed at least one safety sensor unit can have a single sensor connection or multiple sensor connections. Particularly in cases where the claimed at least one safety sensor unit has only a single sensor connection, but also in all other cases, the safety-related control system can include further safety sensor units in addition to the claimed at least one safety sensor unit. Each of the individual safety sensor units has at least one safe sensor connection for connecting safety sensors to the fieldbus, where the safety sensors can be, for example, emergency stop buttons, light barriers, light curtains, temperature sensors, or the like.The safety sensor units then convert sensor signals from the safety sensors into line activation signals, i.e., when a safety sensor connected to one of their safe sensor connections is triggered, they send the line activation signal assigned to the sensor connection via the fieldbus.
[0018] The individual sensor connections of the safety sensor units connected to the fieldbus can each be assigned to different safety lines. Alternatively, several sensor connections of the safety sensor units connected to the fieldbus can be assigned to a single safety line, so that the line activation signal assigned to that single safety line is transmitted via the fieldbus, regardless of which of the safety sensors connected to the multiple sensor connections is activated. Sensor connections assigned to the same safety line can be located in a single safety sensor unit or in different safety sensor units.
[0019] The assignment of individual sensor connections to safety lines can depend on the sensor type and / or the spatial arrangement of the safety sensors connected to the individual sensor connections. For example, all sensor connections to which safety sensors of the same sensor type are connected, such as emergency stop buttons, and / or sensor connections whose safety sensors protect the same area, and / or sensor connections that are part of the same safety sensor unit, can be assigned to the same safety line.
[0020] The individual sensor connections of the safety sensor units connected to the fieldbus can each be assigned to exactly one safety line. Alternatively, individual sensor connections can also be assigned to several safety lines, so that when the safety sensors connected to the respective sensor connections are activated, more than one line activation signal is sent via the fieldbus.
[0021] The line activation signal can be transmitted as a binary signal via the fieldbus. Such a binary line activation signal indicates, in a particularly simple and data-efficient manner, whether the associated safety line has been activated or not.
[0022] The at least one safety sensor unit can be configured to perform fail-safe preprocessing of safety sensor data received via a safe sensor port to determine whether to activate the safety line to which the safe sensor port is assigned and send the corresponding line activation signal. The safety sensor data can be, for example, analog or digital data. The safety sensor data can vary within a data range that encompasses more than two states. For example, the safety sensor data could be the speed or rotational speed of a machine influenced by the safety-related control system.
[0023] During fail-safe preprocessing, the safety sensor data can be checked against one or more criteria, such as a threshold value, to determine whether it falls within a safe range. The safety line can then be activated if the sensor data falls outside this safe range. This safe range could, for example, be a predefined permissible speed or rotational speed range for the controlled machine. Fail-safe preprocessing can be achieved, for instance, by implementing redundancy.
[0024] The fail-safe preprocessing of safety sensor data can also include fault checking of the circuit generating the safety sensor data. Such fault checking can, for example, include short-circuit or ground fault testing. In this case, the safe value range can be defined, for example, by a safe resistance or impedance range of the circuit. The fault checking can also include a functional test of a safety sensor present in the circuit, where the safe value range is defined by safety sensor data indicating the functionality of the safety sensor.
[0025] The safety actuator units are used to connect safe actuators to the fieldbus. These safe actuators can be, for example, drives, relays, valves, or similar devices. The safety actuator units control the safety actuators according to the control signals received via the fieldbus and, upon receiving a line activation signal, put the actuators into a safe state defined by the safety response associated with that signal.
[0026] The safety actuator units can have a fail-safe, for example redundantly implemented, safety module to execute the safety response. This safety module can be designed to be safety-technically separate from a non-fail-safe standard module of the safety actuator unit, which is controlled by a standard control unit of the safety-related control system. The fail-safe safety module can be implemented, for example, using fail-safe hardware and / or fail-safe software.
[0027] The safety module can independently receive the line activation signals from at least one safety sensor unit via the fieldbus, separate from the standard module. The safety module can, for example, have its own fieldbus address and / or be connected to the fieldbus via its own bus interface. The safety response can include the safety module reliably monitoring the output signals provided by the standard module within the safety actuator unit. In the event of a safety-critical deviation of the output signals from a safe signal parameter range, the safety module can then put the corresponding output into a safe state, for example, by switching it off.
[0028] The fieldbus can be an Ethernet-based fieldbus, for example, a real-time capable Ethernet-based fieldbus, such as a SERCOS fieldbus, or a SERCOS III fieldbus. The fieldbus can also be configured as a UPC UA over TSN network.
[0029] The safety sensor units and the safety sensors, as well as the safety actuator units and the safety actuators, can each be fail-safe ( fail safe ) be designed, for example, using diversity, redundancy, and / or by utilizing the quiescent current principle. The transmission of the line activation signals via the fieldbus can be achieved using a fail-safe transmission protocol, for example, using the CIP safety, The fail-safe transmission protocol can implement measures to secure the data signals transmitted via the fieldbus, such as timestamps and time expectations, message IDs, security checksums, redundant messages, or the like.
[0030] The programming device can be connected to the safety sensor units and safety actuator units via the fieldbus. The programming device can be connected directly to the fieldbus or via a central control unit, such as a standard, non-safety-related control unit. The programming device can be configured to store the safety configurations in the safety actuator units by transmitting them via the fieldbus.
[0031] The programming device can be implemented as a software module running on a data processing unit connected to the fieldbus, such as a computer. Alternatively, the programming device can be implemented as a software module on a standard control unit of the control system. The output interface and / or the input interface can be physical interfaces, such as for connecting a display device (e.g., a screen) or an input device (e.g., a keyboard). The output interface and / or the input interface can also be remote access interfaces, such as network interfaces, which can be accessed via a network using a separate user device.
[0032] The programming device can be configured to query the safety sensor units connected to the fieldbus directly via the fieldbus. It can also receive information about the available safety sensor units from another unit connected to the fieldbus, such as a non-safety-related standard control unit or a master unit. The programming device can also be configured to display, in addition to the available safety lines, the safety responses executable by the safety actuator unit via the output interface, for example, as selection lists linked to the individual safety lines.
[0033] According to one embodiment, the safety responses executable by the safety actuator unit are stored within the safety actuator unit and can be retrieved by the programming device for selection by the user, for example, via the fieldbus. This ensures, in a simple and secure manner, that the user only selects safety responses that can actually be executed by the connected safety actuator unit. In alternative embodiments, the safety responses can also be stored within the programming device itself. Regardless of the storage location, the safety responses can each be stored in a database.
[0034] According to one embodiment, the safety responses of the safety actuator unit, selectable via user input, are stored as configurable program blocks. Storing the safety responses as configurable program blocks enables particularly secure and efficient creation of safety configurations, since only individual parameters can be changed by the user and require safety verification. To further enhance safety, the program blocks can be stored with safeguards, such as a checksum. This allows for the detection and prevention of potentially dangerous changes to the program blocks. Additionally, the program blocks can be configured to be parameterized only within predefined, safe parameter ranges. These parameter ranges, like the program blocks themselves, can also be stored with safeguards.
[0035] According to one embodiment, the programming device is configured, after the safety response has been selected, to display user-modifiable configuration parameters of the selected safety response via the output interface and to receive further user input via the input interface, wherein the further user input assigns at least one of the displayed configuration parameters to the selected safety response. This enables particularly simple and secure configuration of the safety response.
[0036] The programming device is configured to receive user input via the input interface to select the safety actuator unit connected to the fieldbus and to display the available safety lines and the safety responses executable by the selected safety actuator unit to the user via the output interface. Using the user input to select the safety actuator unit, the desired unit can be chosen, for example, from among all safety actuator units connected to the fieldbus. This enables simple and clear configuration of the safety actuator units.By displaying the available security lines and the security responses executable by the selected security actuator unit in the output interface after the user has made their selection, a simple and error-free assignment of the security responses to the individual security lines is made possible, and the error susceptibility of the configuration is further reduced.
[0037] According to one embodiment, the programming device is configured to receive user input via the input interface for programming a non-safety standard control program of a non-safety standard control unit connected to the fieldbus, wherein the programming device is further configured to execute the programming of the standard control program and a safety configuration for creating the safety configuration using separate programming modules and / or to display them in separate output areas via the output interface.
[0038] Programming the standard control program using the same programming device used for safety configuration simplifies the entire configuration of the safety-related control system. By executing the programming of the standard control program and the safety configuration in separate programming modules or displaying them in separate output areas, a separation of non-safety-critical programming and safety-relevant configuration is achieved, thus increasing safety when configuring the entire control system.
[0039] Safety configuration can be performed using a safety programming module, which checks the selection and / or parameterization of the safety responses from a safety perspective and, for example, verifies and validates the parameterizable program blocks used for safety configuration. The separate output areas can be, for example, separate display elements such as windows, tabs, or the like, which may, for instance, only be displayed alternately.
[0040] The programming device is configured to store the selected safety response in the safety actuator unit only after it has received a user input with a user-defined selection for each safety line. This ensures that the behavior of the safety actuator unit is predefined for each safety line and that no undefined states can occur during the operation of the safety-related control system. The user-defined selection can, for example, specify a safety response. According to the invention, the user-defined selection can also specify that no safety response should occur, meaning that the safety actuator unit should not be linked to the relevant safety line.
[0041] According to one embodiment, the assignment of one or more sensor connections of the safety sensor unit to the safety lines is stored in the safety sensor unit. Generally, the assignment of each individual sensor connection to the safety lines can be stored in the safety sensor unit encompassing that specific sensor connection. This ensures reliably and without user intervention that each sensor connection is assigned a safety line, which is then displayed during subsequent safety configuration. The programming device can be configured to query the stored safety lines from the safety sensor units, for example, via the fieldbus, either directly via the fieldbus or via a standard control unit or master unit connected to the fieldbus and the programming device.
[0042] By storing the assignment of the sensor connection to the safety line in the safety sensor unit, the individual safety sensor units can also be pre-configured and / or delivered. The safety-related control system, the safety sensor unit, and / or the safety actuator unit can be configured to independently and automatically commission the safety lines after the safety sensor unit and the safety actuator unit are connected to the fieldbus, in particular without the need for user input. This can be achieved by storing the assignment of the sensor connections to the individual safety lines in the safety sensor unit and by storing the safety responses assigned to the individual safety lines or line activation signals as safety configurations in the safety actuator unit.
[0043] The programming device can be configured to modify the mapping between sensor connections and safety lines stored in the safety sensor unit based on user input. For this purpose, the programming device can be configured to represent the individual sensor connections of the safety sensor units connected to the fieldbus via the output interface using unique identifiers. Such unique identifiers can, for example, each comprise a sub-identifier that designates one of the safety sensor units and another sub-identifier that designates a single sensor connection of the respective safety sensor unit.
[0044] The safety sensor unit and the programming device can be configured to transmit the assignments of the individual sensor connections to the safety lines, as stored in the safety sensor unit, to the programming device via the fieldbus. This can occur, for example, as soon as a connection between the safety sensor unit and the programming device has been established via the fieldbus. The programming device can also be configured to store a changed assignment of the individual sensor connections of a safety sensor unit to the safety lines in the affected safety sensor unit by means of transmission via the fieldbus. The changed assignment of the individual sensor connections to the safety lines can, for example, be based on user input, such as via the input interface.
[0045] The safety-related control system can be configured to perform a comparison during commissioning between the assignments of sensor connections to the individual safety lines stored in the individual safety sensor units and user-defined assignments of sensor connections to the individual safety lines. Such a user-defined assignment of sensor connections to the individual safety lines can also be referred to as a line configuration. The line configuration may, for example, have been created beforehand using the programming device. The line configuration can be stored centrally in the safety-related control system, for example, in a control unit connected to the fieldbus, such as a standard control unit connected to the fieldbus, or in the programming device connected to the fieldbus.For example, the line configuration can be stored in a control program of the control unit, such as a standard control program of the control unit.
[0046] If a discrepancy is detected between the assignments stored in the individual safety sensor units and the line configuration during the comparison, the assignments of the individual sensor connections to the safety lines can be reconfigured. This comparison and / or reconfiguration can be performed, for example, by the control unit (such as the standard control unit) or a master unit controlling communication on the fieldbus. During reconfiguration, the assignments stored in the individual safety sensor units can be changed to the assignments of the sensor connections to the safety lines that are centrally stored in the line configuration.
[0047] The safety configuration stored in the at least one safety actuator unit can also include the assignment of the individual safety sensor units and / or their sensor connections to the individual safety lines. The safety actuator unit can be configured to monitor the communication link to the individual safety sensor units, which can trigger a safety response in the safety actuator unit, via the fieldbus, for example, by receiving information periodically sent by the safety sensor units and expected by the safety actuator unit. Furthermore, the safety actuator unit can be configured to execute, in the event of a disruption in the communication link to one of the safety sensor units, those safety responses that are defined for the safety lines that can be triggered by the respective safety sensor unit.
[0048] According to an alternative embodiment, the programming device is configured to automatically detect the individual safety sensor units upon connection to the fieldbus and to automatically assign a safety line to each detected safety sensor unit. In this case, the individual safety sensor units can also be configured without a predefined assignment of the sensor connections to individual safety lines. Assigning the sensor connections to the safety lines in the programming device allows for particularly flexible allocation of the safety lines to the individual sensor connections and, for example, enables the allocation to be carried out depending on the individual safety sensor units or safety sensors connected to the fieldbus.
[0049] According to one embodiment, the at least one safety sensor unit has a plurality of safe sensor connections for connecting safety sensors, with each sensor connection being assigned its own safety line, and the safety sensor unit is configured to send a separate line activation signal via the fieldbus when each individual safety sensor is actuated. This reduces the complexity and cost of the safety-related control system, since a single safety sensor unit can be used to connect multiple safety sensors.
[0050] According to one embodiment, the safety-related control system includes an additional safety actuator unit connected to the fieldbus. The programming device is configured to display safety responses executable by the additional safety actuator unit via the output interface and to receive additional user input via the input interface, wherein the additional user input assigns a selected additional safety response executable by the additional safety actuator unit to the selected safety line.
[0051] By configuring the programming device to receive user input that assigns different safety responses to the safety actuator unit on the one hand and the other safety actuator unit on the other, the safety-related control system can be configured with particular flexibility. For example, the safety actuator unit and the other safety actuator unit can be located at different protection zones of the protected system, such as at a material feed device and a product discharge device, where different hazards occur in the different protection zones.In this case, safety responses adapted to the hazards can be defined for each individual protection area, for example a safe shutdown for the directly endangered material feed device and operation at a safely reduced speed for the product discharge device that is only indirectly endangered.
[0052] Configuring the additional safety actuator unit can be performed, for example, when connecting it to the fieldbus for the first time, such as when subsequently expanding a control system that already includes the safety actuator unit. This allows the control system to be easily and flexibly expanded to include additional safety actuator units.
[0053] According to one embodiment, the safety actuator unit is configured to execute a safety response stored for a first safety line with a higher activation priority than a safety response stored for a second safety line. Thus, if the first and second safety lines are activated simultaneously, the safety response with the higher activation priority—i.e., the safety response stored for the first safety line—is executed, and conflicts are reliably resolved. The individual activation priorities can, for example, depend on a residual hazard that remains even after the safety response is executed. A safety response with a lower residual hazard, such as a safe shutdown, can therefore be executed with a higher activation priority than a safety response with a higher residual hazard, such as operation at a safely limited speed.
[0054] Alternatively or additionally, the control system can be configured to transmit the first line activation signal of the first safety line with a higher transmission priority over the fieldbus than the second line activation signal of the second safety line. This further increases the safety of the control system. The priorities assigned to the individual line activation signals can, for example, be derived from the activation priorities of the safety responses assigned to the individual safety lines.If the first safety line is assigned a safety response with a higher activation priority, for example a safe shutdown, and the second safety line is assigned a safety response with a lower activation priority, for example operation with a safely limited speed, then the line activation signal of the first safety line can be transmitted with a higher transmission priority than the line activation signal of the second safety line.
[0055] According to one embodiment, the programming device is configured to receive a linking user input via the user interface, wherein the linking user input assigns the selected safety response executable by the safety actuator unit to a logical link between the selected safety line and another selected safety line. The programming device is configured to store the logical link and the selected safety response as a safety configuration in the safety actuator unit, and the safety actuator unit is configured to independently evaluate the logical link upon receiving the line activation signal of the selected safety line and / or the selected other safety line.
[0056] Complex safety responses can be implemented by logically combining multiple safety lines. This logical combination can be, for example, an AND operation, an OR operation, or similar. With an AND operation, the selected safety response is only executed when both safety lines are activated, such as when a safety door is opened and a light barrier is interrupted simultaneously. If only one safety line is activated, no safety response or a different safety response is executed.
[0057] According to one embodiment, the control system comprises a non-safety-related standard control unit connected to the fieldbus. The standard control unit is configured to receive and process the activation signals of the safety lines as input data, and all safety responses selected for the safety actuator unit are stored in the standard control unit. The standard control unit is further configured to control the safety actuator unit upon receiving a line activation signal from an activated safety line, in accordance with the safety response selected for the activated safety line. The safety actuator unit is also configured to independently and safely monitor the control by the standard control unit during the autonomous execution of the safety response.
[0058] By controlling the safety actuator unit after activation of the safety line by the standard control unit, the safety response can be executed using the resources of the standard control unit, such as its logic units, and the safety actuator unit can be designed relatively simply. To monitor the non-fail-safe control of the safety actuator unit by the standard control unit, the safety actuator unit can include a safety module implemented separately from the standard module.
[0059] According to one embodiment, the control system comprises a master unit configured to control bus access to the fieldbus according to the master-slave method. The safety actuator units and / or the safety sensor units are connected to the fieldbus as slave units, and the control system is configured to transmit the line activation signals via the fieldbus in direct cross-traffic without safety-related intermediate processing by the master unit from the safety sensor units to the safety actuator units.
[0060] The master unit enables deterministic bus access and thus, for example, real-time data transmission via the fieldbus. By transmitting the line activation signals directly through the master unit without intermediate processing, particularly fast triggering of the safety responses associated with the activated safety line is made possible. Direct cross-traffic can be achieved, for example, by having the safety actuator units, or the safety modules of the safety actuator units, read the line activation signals directly from fieldbus telegrams populated by the safety sensor units.Alternatively, direct cross-traffic can also include copying the line activation signals from fieldbus telegrams filled by the safety actuator units into separate fieldbus telegrams read out by the safety actuator units, whereby the copying is carried out by the master unit without further reading or evaluation of the line activation signals.
[0061] Direct cross-traffic can also be implemented using a publisher / subscriber communication, in which the safety sensor units transmit the line activation signals via the fieldbus by making them available for retrieval by the safety actuator units or their safety modules, and in which the safety actuator units or the safety modules receive the line activation signals directly via the fieldbus by independently retrieving the line activation signals from the safety sensor units.
[0062] The provision of line activation signals by the safety sensor units and / or the retrieval of line activation signals by the safety actuator units can, for example, occur cyclically and / or at deterministic intervals. Alternatively, the provision of line activation signals by the safety sensor units can also be event-driven, where an event triggering the provision could be, for example, a change in the state of a sensor signal received via an assigned sensor port. For cross-traffic, for example, publisher / subscriber communication via UPC UA over TSN can be used.
[0063] A method for operating a safety-related control system with at least one safety sensor unit and at least one safety actuator unit, which are connected to each other via a fieldbus, and with a programming device, comprises the steps according to claim 13.
[0064] The method can be used in particular for operating the safety-related control system according to the claim. In this respect, all technical effects and embodiments described in connection with the safety-related control system according to the claim also apply to the method according to the claim, and vice versa.
[0065] The invention is explained below with reference to figures. These figures are shown in schematic representations: Fig. 1 a safety-related control system; Fig. 2 a first user output of a programming device of the control system; Fig. 3 a second user output of the programming device; Fig. 4 a third user output of the programming device; Fig. 5 a fourth user output of the programming device; Fig. 6 a first part of a method for operating the safety-related control system; and Fig. 7 a second part of the method for operating the safety-related control system.
[0066] Fig. 1 Figure 1 shows a safety-related control system 1 with a first safety sensor unit 11, a second safety sensor unit 12, a first safety actuator unit 21, a second safety actuator unit 22, and a third safety actuator unit 23. The safety sensor units 11, 12 and the safety actuator units 21, 22, 23 are interconnected via a fieldbus 50. The first safety sensor unit 11 comprises a first safe sensor connection 14 and a second safe sensor connection 15, to each of which a safety sensor 10 is connected. The second safety sensor unit 12 comprises a single third safe sensor connection 16 with another safety sensor 10 connected to it. Each of the safety actuator units 21, 22, 23 connects a safety actuator 20 to the fieldbus 50, with the safety actuators 20 each being configured as drives.
[0067] The safety sensors 10 connected to the first safety sensor unit 11 serve to safeguard a first protective zone, and the safety sensor 10 connected to the second safety sensor unit 12 serves to safeguard a second protective zone. Within the first protective zone, machine parts perform a hazardous movement, which is driven by the safety actuator 20 connected to the first safety actuator unit 21. Within the second protective zone, machine parts perform a hazardous movement, which is driven by the safety actuators 20 connected to the second and third safety actuator units 22 and 23.
[0068] The first safety sensor unit 11 is configured to send a first line activation signal via the fieldbus 50 to activate a first safety line 30 when the safety sensor 10 connected to the first sensor terminal 14 is activated, and a second line activation signal to activate a second safety line 31 when the safety sensor 10 connected to the second sensor terminal 15 is activated. Similarly, the second safety sensor unit 12 is configured to send a third line activation signal to activate a third safety line 33 when the safety sensor 10 connected to the third sensor terminal 16 is activated.
[0069] The safety sensor 10, connected to the first sensor terminal 14 of the first safety sensor unit 11, is designed as a rotary encoder. This encoder transmits sensor data via the first sensor terminal 14 to the first safety sensor unit 11, representing the rotational speed of a machine part located within the first protective zone. The first safety sensor unit 11 performs fail-safe preprocessing of the encoder's sensor data and checks the sensor data for exceeding a permissible value range. If the permissible value range is exceeded, the first safety sensor unit 11 activates the first safety line to which the first sensor terminal 14 is assigned.
[0070] The safety sensors 10 connected to the second and third sensor terminals 15, 16 are each configured as switches, which each send a binary sensor signal via the second or third sensor terminal 15, 16 to the safety sensor units 11, 12. The second or third safety sensor unit 11, 12 each send the second or third line activation signal via the fieldbus 50 as soon as the binary sensor signal received via the assigned sensor terminal 15, 16 indicates that the corresponding switch has been actuated.
[0071] The first safety actuator unit 21 contains a first safety configuration 131, the second safety actuator unit 22 a second safety configuration 132, and the third safety actuator unit 23 a third safety configuration 133. The first safety configuration 131 assigns selected first safety reactions R11, R12 with first configuration parameters P11, P12, executable by the first safety actuator unit 21, to the first and second safety lines 30, 31 respectively, and no safety reaction from the first safety actuator unit 21 to the third safety line 32.The second and third safety configurations 132, 133 assign selected second safety reactions R21, R22, R23 with second configuration parameters P21, P22, P23, executable by the second safety actuator unit 22, to the individual safety lines 30, 31, 32, and selected third safety reactions R31, R32, R33 with third configuration parameters P31, P32, P33, executable by the third safety actuator unit 23.
[0072] A non-safety standard control unit 40 and two non-safety standard sensor units 42 are also connected to the fieldbus 50. The standard control unit 40 is connected to the fieldbus 50 via a master unit 52. The non-safety standard sensor units 42 serve to connect non-safety standard sensors 44 and, based on sensor data from the connected standard sensors 44, generate non-safety-critical input data, which is then transmitted via the fieldbus 50 to the standard control unit 40 for further processing. The standard control unit 40 processes the input data according to a standard control program 140 stored in the standard control unit 40 and generates non-safety-related output data based on the input data. Using the non-safety-related output data, the standard control unit 40 controls Fig. 1 Not shown are unsafe standard actuator units.
[0073] The control system 1 further comprises a programming unit 100, which is connected to the fieldbus 50 via the standard control unit 40 and the master unit 52 and is connected to the safety actuator units 21, 22, 23. The programming unit 100 includes a safety programming module 105 for creating the safety configurations 131, 132, 133, and a standard programming module 107 for creating the standard control program 140. Furthermore, the programming unit 100 includes an output interface 110 with a connected display device 111, and an input interface 120 with a connected input device 121.
[0074] Fig. 2 Figure 1 shows the first user output of the programming device 100 displayed on the display device 111 via the output interface 110. The user output shown includes a menu tree with a standard programming query 118, through which the programming of the standard control program 140 can be selected using the standard programming module 107, and with a safety actuator query 113, in which the individual safety actuator units 21, 22, 23 are listed and can be selected for further configuration by means of user input.
[0075] At the in Fig. 2 In the illustration shown, the first safety actuator unit 21 is selected, and the safety programming module 105 of the programming device 100 displays a safety programming query 119 in a safety output area 112, selectable via a tab 101, through which the first safety configuration 131 can be created using the safety programming module 105. Similarly, when the second or third safety actuator unit 22, 23 is selected, the safety programming module 105 of the programming device 100 displays safety programming queries for the second or third safety actuator unit 22, 23, respectively, selectable via tab 101 in the safety actuator query 113, through which the second and third safety configurations 132, 133 can be created using the safety programming module 105. Further details are provided in Fig. 2 The tab shown allows for the configuration of non-safe default parameters of the selected safety actuator unit 21.
[0076] The safety programming module 105 of the programming device 100 displays the available safety lines 30, 31, 32, each with a safety response query 116, in the safety output area 112 during the safety programming query 119. This allows the user to assign a safety response executable by the first safety actuator unit 21 to each of the individual safety lines 30, 31, 32 via user input. The safety response queries 116 are each displayed as selection menus that can be selected via user input.
[0077] Fig. 3 A second user output, displayed via output interface 110 on the display device 111 of the programming unit 100, appears after the safety programming module 105 of the programming unit 100 has received user inputs. These inputs can be selected as follows: first, to assign a first safety reaction R11 to the first safety actuator unit 21, namely a safe torque off (STO) of the connected drive 10; and second, to assign no safety reaction to the first safety actuator unit 21 as a selection from the third safety line 32. Simultaneously, the safety programming module 105 of the programming unit 100 displays in a selection list the safety reactions 114 that can be executed by the first safety actuator unit 21 and assigned to the second safety line 31.
[0078] Fig. 4 A third user output is shown, displayed via the output interface 110 on the display device 111 of the programming unit 100, after the safety programming module 105 of the programming unit 100 has received a user input that assigns a second safety response R12 of the first safety actuator unit 21, namely a safely limited speed (STO) of the connected drive 10, to the second safety line 31. The safety programming module 105 displays parameter queries 117 for the two selected safety responses R11 and R12, respectively, for entering configuration parameters of the safety responses R11 and R12, which are designed as selection menus.
[0079] Fig. 5 Figure 1 shows a third user output of the programming device 100 for parameterizing the second safety reaction R12, displayed via output interface 110 on the display device 111. The selection menu displayed via parameter query 117 shows individual configuration parameters 115 of the second safety reaction R12, which can be changed by user input.
[0080] Fig. 6 shows a first part of a procedure 300 for operating the safety-related control system 1, in which the standard control program 140 is programmed and the safety configurations 131, 132, 133 of the safety actuator units 21, 22, 23 are created.
[0081] Procedure 300 first comprises assigning 307 the sensor connections 14, 15, 16 provided by the safety sensor units 11, 12 to the safety lines 30, 31, 32 within the safety sensor units 11, 12. Procedure 300 then comprises detecting 305 the safety sensor units 11, 12 and the stored safety lines 30, 31, 32 via the fieldbus 50 by the programming device 100. Subsequently, a user input is used to select either 310 the configuration of the safety actuator units 21, 22, 23 or 400 the programming of the standard control program 140. If 400 the programming of the standard control program 140 is selected, 405 user input for programming the standard control program 140 is received. Subsequently, the user can again select 310 to configure the safety actuator units 21, 22, 23. 22, 23 or selection 400 to program the standard control program 140.
[0082] After selection 310 to configure the security actuator units 21, 22, 23, a user input is received 315 to select the security actuator unit 21, 22, 23 to be configured, and security responses 114 that can be performed by the selected security actuator unit 21, 22, 23 and are stored in the selected security actuator unit 21, 22, 23 are retrieved 317. The procedure then includes displaying 320 the available security lines 30, 31, 32 and displaying 325 the executable security responses 114 in the security output area 112. Finally, a user input is received 330 to assign an executable security response 114 to one of the available security lines 30, 31, 32.Optionally, a linking user input can also be received (332), which logically links two available security lines 30, 31, 32 to form an additional security line, for example by means of an AND or OR link.
[0083] The procedure 300 further comprises receiving 335 another user input for assigning the configuration parameters 115 to the selected safety responses 114. Subsequently, a check 338 is performed to verify that the selected safety actuator unit 21, 22, 23 is fully configured. This check includes verifying whether, for each available safety line 30, 31, 32, a user input has been used to select whether and, if so, which safety response 114 is assigned to the individual safety lines 30, 31, 32. Finally, the selected safety responses 114 are stored 340 as a safety configuration 131, 132, 133 in the selected safety actuator unit 21, 22, 23, and the selected safety responses 114 are stored 342 in the standard control unit 40.
[0084] Fig. 7 Figure 300 shows a second part of the procedure, in which a safety line 30, 31, 32 is activated during normal operation of the safety-related control system 1 (350). Subsequently, a line activation signal associated with the activated safety line 30, 31, 32 is transmitted via the fieldbus 50 (352) by being made available for retrieval via the fieldbus 50 by the relevant safety sensor unit 11, 12, and received by the safety actuator units 21, 22, 23 in direct cross-communication via the fieldbus 50 (360), by being retrieved by the safety actuator units 21, 22, 23 from the providing safety sensor unit 11, 12.
[0085] In the individual safety actuator units 21, 22, 23, an optional evaluation 362 of a logical link of several safety lines 30, 31, 32 is then carried out, and the safety reaction 114 assigned to the activated safety line 30, 31, 32 is executed independently 370. In parallel, the standard control unit 40 receives 365 the line activation signal, whereupon the standard control unit 40 controls the safety actuator units 21, 22, 23 according to the respective stored safety reactions 114 (375), and the control 375 by the standard control unit 40 is monitored in a fail-safe manner during the execution 370 of the safety reaction 114 in the safety actuator unit 21, 22, 23. Bezugszeichenliste
[0086] 1 Safety-related control system 10 Safety sensors 11 First safety sensor unit 12 Second safety sensor unit 14 First sensor connection 15 Second sensor connection 16 Third sensor connection 20 Safety actuators 21 First safety actuator unit 22 Second safety actuator unit 23 Third safety actuator unit 30 First safety line 31 Second safety line 32 Third safety line 40 Standard control unit 42 Standard sensor unit 44 Standard sensor 50 Fieldbus 52 Master unit 100 Programming device 101 Tab 105 Safety programming module 107 Standard programming module 110 Output interface 111 Display device 112 Safety output area 113 Safety actuator query 114 Safety response 115 Configuration parameters 116 Safety response query 117 Parameter query 118 Standard programming query 119 Safety programming query 120 Input interface 121 Input device 131 First security configuration 132 Second security configuration 133 Third security configuration140 Standard control program 300 Procedure 305 Detect safety sensor units 307 Assign safety lines 310 Select a configuration of safety actuator units 315 Receive user input to select a safety actuator unit 317 Retrieve executable safety responses 320 Display available safety lines 325 Display executable safety responses 330 Receive user input to assign a safety line 332 Receive link user input 335 Receive further user input to assign a configuration parameter 338 Check for complete configuration 340 Store the selected safety response in the safety actuator unit 342 Store the selected safety response in the standard control unit 350 Activate a safety line 352 Send a line activation signal 360 Receive the line activation signal 362 Evaluate a logical link 365 Receive aLine activation signal in standard control unit 370 Execute a safety response 375 Control according to selected safety response 400 Select programming of the standard control program 405 Receive user input to configure a standard control program
Claims
1. A safety-directed control system (1) comprising at least one safety sensor unit (11, 12) and at least one safety actuator unit (21, 22, 23), which are connected to one another via a fieldbus (50), and a programming device (100), wherein sensor connections (14, 15, 16) for connecting safety sensors (10) to the fieldbus (50) are provided by the at least one safety sensor unit (11, 12) and the sensor connections (14, 15, 16) are associated with safety lines (30, 31, 32), wherein the programming device (100) is configured to display the available safety lines (30, 31, 32) to a user via an output interface (110), wherein the programming device (100) is configured to receive a user input of the user via an input interface (120), with the user input associating a selected safety response (114), which is executable by the safety actuator unit (21, 22, 23), with at least one selected safety line (30, 31, 32), wherein the programming device (100) is configured to store the association between the selected safety line (30, 31, 32) and the selected safety response (114) in the safety actuator unit (21, 22, 23) as a safety configuration (131, 132, 133), wherein the safety lines (30, 31, 32) associated with the individual sensor connections (14, 15, 16) can be independently activated by the at least one safety sensor unit (11, 12) by transmitting line activation signals of the individual safety lines (30, 31, 32) via the fieldbus (50), wherein the safety actuator unit (21, 22, 23) is configured to receive the line activation signals via the fieldbus (50) directly from the at least one safety sensor unit (11, 12) and, on the reception of a line activation signal of an activated safety line (30, 31, 32), to independently execute the safety response (114) stored for the activated safety line (30, 31, 32) in the safety configuration (131, 132, 133), wherein the programming device (100) is configured to receive, via the input interface (120), a user input for selecting the safety actuator unit (21, 22, 23) connected to the fieldbus (50), wherein the programming device (100) is configured to display the available safety lines (30, 31, 32) and the safety responses (114) executable by the selected safety actuator unit (21, 22, 23) to the user via the output interface (110), wherein the programming device (100) is configured to only store the selected safety response (114) in the safety actuator unit (21, 22, 23) when the programming device (100) has received a user input having a user-defined selection for each safety line (30, 31, 32), wherein the user-defined selection can specify that no safety response is to take, i.e. that the safety actuator unit (21, 22, 23) is not to be linked to the respective safety line (30, 31, 32).
2. A safety-directed control system (1) according to claim 1, wherein the safety responses (114) executable by the safety actuator unit (21, 22, 23) are stored in the safety actuator unit (21, 22, 23) and can be invoked by the programming device (100) for selection by the user.
3. A safety-directed control system (1) according to one of the preceding claims, wherein the safety responses (114) of the safety actuator unit (21, 22, 23) selectable by means of the user input are stored as parameterizable program modules.
4. A safety-directed control system (1) according to any one of the preceding claims, wherein the programming device (100) is configured to display, after the selection of the safety response (114), configuration parameters (115) of the selected safety response (114), which can be changed by the user, to the user via the output interface (110), wherein the programming device (100) is configured to receive a further user input via the input interface (120), wherein the further user input assigns at least one of the displayed configuration parameters (115) to the selected safety response (114).
5. A safety-directed control system (1) according to any one of the preceding claims, wherein the programming device (100) is configured to receive, via the input interface (120), user inputs for programming a non-safe standard control program (140) of a non-safe standard control unit (40) connected to the fieldbus (50), wherein the programming device (100) is configured to execute the programming of the standard control program (140) and a safety configuration for creating the safety configuration (131, 132, 133) by means of separate programming modules (105, 107) and / or to display them in separate output regions (112) via the output interface (110).
6. A safety-directed control system (1) according to any one of the preceding claims, wherein an association of one sensor connection (14, 15, 16) or a plurality of sensor connections (14, 15, 16) of the safety sensor unit (11, 12) with the safety lines (30, 31, 32) is stored in the safety sensor unit (11, 12).
7. A safety-directed control system (1) according to any one of the preceding claims, wherein the at least one safety sensor unit (11, 12) has a plurality of safe sensor connections (14, 15, 16) for connecting safety sensors (10), wherein a separate safety line (30, 31, 32) is associated with each sensor connection (14, 15, 16), wherein the safety sensor unit (11, 12) is configured to transmit a respective separate line activation signal via the fieldbus (50) on the actuation of the individual safety sensors (10).
8. A safety-directed control system (1) according to any one of the preceding claims, comprising a further safety actuator unit (21, 22, 23) connected to the fieldbus (50), wherein the programming device (100) is configured to display safety responses (114), which are executable by the further safety actuator unit (21, 22, 23), via the output interface (110), wherein the programming device (100) is configured to receive an additional user input via the input interface (120), with the additional user input associating a selected further safety response (114), which is executable by the further safety actuator unit (21, 22, 23), with the selected safety line (30, 31, 32), wherein the further safety response (114) differs from the safety response (114) selected for the safety actuator unit (21, 22, 23).
9. A safety-directed control system (1) according to any one of the preceding claims, wherein the safety actuator unit (21, 22, 23) is configured to execute a safety response (114) stored for a first safety line (30, 31, 32) at a higher activation priority than a safety response (114) stored for a second safety line (30, 31, 32).
10. A safety-directed control system (1) according to any one of the preceding claims, wherein the programming device (100) is configured to receive a link user input via the user interface, wherein the link user input associates the selected safety response (114), which is executable by the safety actuator unit (21, 22, 23), with a logical link of the selected safety line (30, 31, 32) to a further selected safety line (30, 31, 32), wherein the programming device (100) is configured to store the logical link and the selected safety response (114) as a safety configuration (131, 132, 133) in the safety actuator unit (21, 22, 23), wherein the safety actuator unit (21, 22, 23) is configured to independently evaluate the logical link on the reception of the line activation signal of the selected safety line (30, 31, 32) and / or of the selected further safety line (30, 31, 32).
11. A safety-directed control system (1) according to any one of the preceding claims, wherein the control system (1) comprises a non-safe standard control unit (40) connected to the fieldbus (50), wherein the standard control unit (40) is configured to receive and process the activation signals of the safety lines (30, 31, 32) as input data, wherein all the safety responses (114) selected for the safety actuator unit (21, 22, 23) are stored in the standard control unit (40), wherein the standard control unit (40) is configured to control the safety actuator unit (21, 22, 23) on the reception of a line activation signal of an activated safety line (30, 31, 32) in accordance with the safety response (114) selected for the activated safety line (30, 31, 32), wherein the safety actuator unit (21, 22, 23) is configured to independently safely monitor the control by the standard control unit (40) as part of the independent execution of the safety response (114).
12. A safety-directed control system (1) according to any one of the preceding claims, wherein the control system (1) has a master unit (52), wherein the master unit (52) is configured to control a bus access to the fieldbus (50) in accordance with the master-slave method, wherein the safety actuator units (21, 22, 23) and / or the safety sensor units (11, 12) are connected to the fieldbus (50) as slave units, wherein the control system (1) is configured to transmit the line activation signals from the safety sensor units (11, 12) to the safety actuator units (21, 22, 23) via the fieldbus (50) in direct cross traffic without a safety-directed intermediate processing by the master unit (52).
13. A method (300) of operating a safety-directed control system (1) comprising at least one safety sensor unit (11, 12) and at least one safety actuator unit (21, 22, 23), which are connected to one another via a fieldbus (50), and a programming device (100), wherein the method (300) comprises the following steps: - associating (307) sensor connections (14, 15, 16), which are provided by the at least one safety sensor unit (11, 12), for connecting safety sensors (10) to the fieldbus (50) with safety lines (30, 31, 32); - receiving a user input for selecting the safety actuator unit (21, 22, 23), which is connected to the fieldbus (50), via an input interface (120) of the programming device (100); - displaying (325) the available safety lines (30, 31, 32) and the safety responses (114), which are executable by the selected safety actuator unit (21, 22, 23), via an output interface (110) of the programming device (100); - receiving (330) a user input via the input interface (120) of the programming device (100), wherein the user input associates a selected safety response (114), which is executable by the safety actuator unit (21, 22, 23), with at least one selected safety line (30, 31, 32); - storing (340) the association between the selected safety line (30, 31, 32) and the selected safety response (114) in the safety actuator unit (21, 22, 23) as a safety configuration (131, 132, 133) by means of the programming device (100); - independently activating (350) a safety line (30, 31, 32), which is associated with a sensor connection (14, 15, 16) of the safety sensor unit (11, 12), by transmitting a line activation signal via the fieldbus (50) by the safety sensor unit (11, 12); - directly receiving (360) the line activation signal from the safety sensor unit (11, 12) by the safety actuator unit (21, 22, 23) via the fieldbus (50); and - independently executing (370) the safety response (114), which is stored for the activated safety line (30, 31, 32) in the safety configuration (131, 132, 133), by the safety actuator unit (21, 22, 23) on the reception of the line activation signal, wherein the selected safety response (114) is only stored in the safety actuator unit (21, 22, 23) when the programming device (100) has received a user input having a user-defined selection for each safety line (30, 31, 32), and wherein the user-defined selection can specify that no safety response is to take, i.e. that the safety actuator unit (21, 22, 23) is not to be linked to the respective safety line (30, 31, 32).