SAFETY DEVICE AND METHOD FOR OPERATING A SAFETY DEVICE

DE502021008459D1Active Publication Date: 2025-09-18EUCHNER GMBH & CO KG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502021008459
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-20
Publication Date
2025-09-18
Estimated Expiration
2041-09-20

AI Technical Summary

Technical Problem

Existing safety devices require significant hardware upgrades and development efforts to expand functionality, limiting their flexibility and increasing costs.

Method used

Implementing a safety device with a fail-safe processor unit that utilizes virtual functional elements controlled by a terminal device, allowing functionality expansion through data transmission and verification, ensuring tamper-proof and fail-safe operation.

Benefits of technology

Enables flexible and easy expansion of safety device functionality without hardware modifications, meeting safety standards while ensuring fail-safe operation.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a safety device and a method for operating a safety device.

[0002] Such safety devices comprise at least one safety device and are used in the field of safety technology, particularly in the field of machine safety. These safety devices ensure the monitored and therefore safe operation of machines and systems.

[0003] An example of such safety devices are safety locking systems.

[0004] One such system is the MGB safety system from Euchner. This safety system ensures the secure closure of movable safety guards, especially safety doors, and thus secure access to fenced-in safety-critical danger areas.

[0005] This safety locking system comprises a locking module with a handle module attached. These modules serve to securely hold the safety door closed. The handle of the handle module can be held in the locked position by spring force and released by magnetic force. Alternatively, the handle can be held in the locked position by magnetic force and released by spring force.

[0006] The locking module can be extended in its functionality by having additional submodules such as a button module as an operating unit.

[0007] Such safety devices require fail-safe hardware to meet safety requirements. This hardware is limited in its functionality, as its reliable monitoring requires significant effort. Expanding functionality can only be achieved through hardware upgrades, which requires significant development effort and expense.

[0008] EP 1 936 457 A1 discloses a modular safety switching device comprising at least one output module and a central controller connected to all output modules via a bus. The output module is configured to receive input data from at least one sensor or switch and has at least one output for an actuator. The central controller is configured to receive at least some of the input data and evaluate it to determine output data to the output. The output module has its own output module controller, which is configured to evaluate the input data together with the central controller to determine output data to the output.

[0009] EP 3 499 324 A1 discloses a method for verifying a configuration of a device, in particular a safety controller, comprising the steps of dividing the configuration of the device into at least two partial configurations which are verified, allocating the partial configurations to at least one partial configuration sequence in which a dependency of a verification of the partial configurations on each other is specified, determining parameters of each partial configuration, wherein the parameters are used to verify the respective partial configurations, calculating an individual checksum for each partial configuration which represents the verification of the partial configurations, wherein during the verification of a partial configuration following in the partial configuration sequence, the individual checksum of a preceding partial configuration is recalculated and if the individual checksum matches, the verification of the preceding partial configuration is confirmed,and wherein the configuration of the device is verified when, for each partial configuration sequence, the last partial configuration is verified.,

[0010] The invention is based on the object of providing a safety device that can be used flexibly and whose functionality can be expanded with little effort.

[0011] To achieve this object, the features of the independent claims are described. Advantageous embodiments and expedient developments of the invention are described in the dependent claims.

[0012] The invention relates to a safety device according to claim 1.

[0013] The invention further relates to a method according to claim 8.

[0014] The basic idea of ​​the invention is therefore that the security device comprises not only the security device, but also an associated terminal device used to implement virtual functional elements. The virtual functional element(s) can be used to control or specify functions of the security device, thereby expanding the functionality of the security device.

[0015] The implementation of the virtual functional elements meets the necessary safety requirements, as the virtual functional elements are generated by data transmission between the fail-safe processor unit and the safety device. This data transmission is particularly tamper-proof against third-party interference. Furthermore, failure safety is already ensured by the use of the fail-safe processor unit. This has a fail-safe structure, which can be implemented, in particular, by two processors that cyclically monitor each other. Systems with more than two processors, in particular four processors, are also possible. Generally, a system with just one processor is also possible, on which several independent software modules are implemented. The results generated in the software modules are compared with each other for error control purposes.The implementation of the fail-safe processor unit generally depends on the respective safety requirements defined by applicable safety standards such as DIN EN ISO 13849 or IEC 61508. Finally, the security of data transmission between the fail-safe processor unit and the control module is ensured by mutual verification and confirmation of signals sent between the fail-safe processor unit of the safety device and the control module of the terminal device, preventing the incorrect implementation of virtual functional elements in the terminal device.

[0016] This ensures the necessary fail-safe performance when implementing virtual functional elements, even if the terminal device with the control module itself is not fail-safe. This reduces the hardware complexity required to implement the safety device according to the invention.

[0017] Using the virtual functional element(s), a user of an end device can control or configure functions of the security device. The advantage of this is that virtual functional elements can be operated on the end device, independent of the security device's installation location.

[0018] In principle, the terminal device can be formed by a stationary computer unit, which can, for example, be formed by a control center of a plant.

[0019] A particularly advantageous option is a mobile device such as a smartphone, tablet, personal computer, AR (augmented reality) or VR (virtual reality) headset. This makes the device completely independent of the security device's installation location.

[0020] This is especially true if a wireless data transmission link is provided between the security device and the mobile device, i.e., contactless data transmission is generally used. The data transmission link is preferably implemented as a radio link, although conventional data connections such as Bluetooth or Wi-Fi can be used. Of course, a wired data connection can also be used.

[0021] The virtual functional element(s) generally form units that can be operated by users to specify functions for the security device.

[0022] This specification is made by the user entering appropriate inputs into the device. Depending on the device's configuration, inputs can be made conventionally via keyboards or touch panels, which are standard features on devices such as personal computers, tablets, and smartphones.

[0023] In general, inputs can also be made via the user's voice. Virtual input options are also conceivable.

[0024] A key advantage of the invention is that the functionality of the security device can be expanded using the virtual functional elements generated in the terminal device without having to expand the hardware of the security device itself. This allows the functionality of the security device to be expanded flexibly and easily using variably specified virtual functional elements.

[0025] Generally, to specify virtual functional elements, a configuration is sent from the fail-safe processor unit to the control module of the terminal device. This configuration contains the parameters of all possible virtual functional elements for the safety device. The user can then select the desired virtual functional elements from the configuration.

[0026] The virtual functional elements can be used, in particular, to activate and specify functions of the safety device that cannot be specified using physical units provided on the safety device itself, such as control elements. Examples of this include the activation of operating modes, particularly service modes, that cannot be activated using the control elements present on the safety device. The virtual functional elements can also be used to set configuration parameters. Hardware or software modules of the safety device can also be controlled using the safety device.

[0027] A virtual functional element can, for example, be formed by a configuration menu. The virtual functional element is advantageously displayed on an output unit of the mobile device, for example, on the screen of a personal computer, a tablet, or a smartphone, so that a user can select functions of the security device or, if necessary, parameterize them through inputs, for example, on touch panels.

[0028] According to the invention, the virtual functional element(s) are embodied as virtual operating units. For example, operating elements physically provided on the security device, such as switches or buttons, are virtually replicated on the terminal device, in particular the mobile terminal, using the virtual operating units. This allows the user to set functions of the security device by operating virtual operating units on the terminal device, instead of operating the operating elements provided on the security device. With a terminal device embodied as a mobile terminal, the user can operate the virtual operating unit at freely selectable locations, regardless of the installation location of the security device.

[0029] Particularly advantageous is the ability to generate and activate virtual control units in the terminal device based on the configurations read by the fail-safe processor unit, even if they are not physically present on the safety device. The virtual control units thus create new control elements that expand the functionality of the safety device. This functional extension requires no hardware modifications to the safety device.

[0030] The safety device of the safety device according to the invention can advantageously be formed by a safety locking system. However, the safety device is not limited to this. Rather, the safety device can also comprise other safety devices, such as safety switches, bus modules, access control systems, or safety devices for selecting operating modes of a safety system.

[0031] Generally, the safety device includes a fail-safe processor unit. The fail-safe processor unit can be integrated into the safety device or form a single unit with it, for example, through attachment, mechanical or electrical coupling, etc. Finally, it may even be sufficient for the fail-safe processor unit to be connected to the safety device via wired communication units or via contactless interfaces.

[0032] According to the method according to the invention, data is transmitted between the fail-safe processor unit of the security device and the control module of the terminal device in an encrypted form. This makes the data transmission tamper-proof and protected against access or interference by third parties.

[0033] The specification of virtual functional elements in the terminal device takes place within a session of a secure data transmission, which is initiated by a start signal from the control module in the terminal device.

[0034] Upon the start signal from the fail-safe processor unit, the configuration is transferred to the control module in the terminal device.

[0035] The configuration is displayed in the end device and is thus available to the user, allowing the user to select virtual functional elements.

[0036] This selection is sent from the control module to the fail-safe processor unit.

[0037] The selection is then verified by a verification signal sent from the fail-safe processor unit to the control module.

[0038] The verification signal verifies the selection made to determine whether it is permissible and compliant with the configuration present in the fail-safe processor unit, i.e. the selection is checked in the fail-safe processor unit.

[0039] The verification signal is then confirmed by the control module by sending a confirmation signal to the fail-safe processor unit, whereupon the fail-safe processor unit sends a confirmation signal to the control module for counter-confirmation, whereupon the selected virtual functional element is activated.

[0040] Verification and subsequent confirmation and counterconfirmation of the selection ensure fail-safe operation of the virtual functional elements in the terminal device, thus fulfilling the requirements for use in safety technology. Through the safe, controlled selection of the virtual functional elements, they form tested, fail-safe units. In particular, it is not necessary to secure the transmission of the configuration from the fail-safe processor unit to the control module of the terminal device itself with verification and confirmation signals, since the virtual functional elements selected from the configuration are themselves verified and controlled by confirmation signals. This ensures fail-safe selection and activation of virtual functional elements with minimal effort.

[0041] The virtual functional elements are only activated if the aforementioned procedure runs without errors. If an error occurs, the activation of the virtual functional elements is not enabled.

[0042] The invention is explained below with reference to the drawings. They show: Figures 1 - 4: Embodiments of the safety device according to the invention in different phases during the selection and activation of a virtual control unit. Figure 5: Embodiments of the safety device according to the invention with a selection option for configuration parameters.

[0043] The Figures 1 to 4 show an embodiment of the security device 1 according to the invention. The security device 1 comprises a security device 2 and a terminal, which in the present case is designed as a mobile terminal 3.

[0044] The security device 2 can generally be implemented as a safety switch, an access control system, or as a security device 2 for selecting operating modes of a security system. Furthermore, the security device 2 can also be a bus module.

[0045] In the present case, safety device 2 forms a safety locking system.

[0046] The safety locking system ensures the secure locking of a guard, such as a safety door. The safety device 2 comprises a locking module, which is stationary and mounted on a frame or the like, and a handle module mounted on the safety door, which can be moved with the safety door. The locking module securely holds the safety door in the closed state, thus providing protection against a hazardous area on a machine or the like.

[0047] The safety device 2 further comprises an arrangement of control elements 4, 5 by means of which functions of the safety device 2 can be adjusted. In the present case, two control elements 4, 5 are provided, each with three buttons 4a, 4b, 4c and 5a, 5b, 5c, respectively. In general, the safety device 2 can also have a different number or design of control elements 4, 5. In particular, the control elements 4, 5 can also have switches.

[0048] The safety device 2 further comprises a fail-safe processor unit 6. This advantageously consists of two cyclically monitoring processors. This gives the safety device 2 a fail-safe design. The fail-safe processor unit 6 comprises a memory unit (not shown separately) in which a configuration of the safety device 2 is stored in a fail-safe manner.

[0049] In the present case, the mobile terminal 3 assigned to the security device 2 is designed as a smartphone, the screen of which forms a touch panel on which a user can enter input variables in a known manner by touching the screen.

[0050] Alternatively, the mobile device 3 can be configured as a personal computer, tablet, or even VR (virtual reality) or AR (augmented reality) headset. Depending on the configuration, other input options, such as voice commands or visual inputs, may also be provided.

[0051] The mobile terminal 3 has a control module (not shown) that is implemented as a software module, particularly in the form of an app. Unlike the security device 2, the mobile terminal 3 does not have a fail-safe design, although this would be possible in principle.

[0052] A wireless, i.e., contactless, data transmission path is provided between the security device 2 and the mobile terminal 3. In this case, the data transmission path is designed as a radio link, over which radio signals can be transmitted bidirectionally. For this purpose, a transceiver unit is provided in both the security device 2 and the mobile terminal 3, with which radio signals can be sent and received. Generally, a wired data transmission path can also be provided between the security device 2 and the mobile terminal 3.

[0053] According to the invention, in the safety device 1, virtual functional elements can be generated and activated in a fail-safe manner in the mobile terminal 3 depending on a configuration stored in the fail-safe processor unit 6. This expands the functionality of the safety device 2 without requiring any modification of the hardware of the safety device 2. A user can then control the function of the mobile terminal 3 by making inputs to the virtual functional elements, completely independent of the installation location of the safety device 2.

[0054] The Figures 1 to 4 show a first embodiment for the generation and activation of virtual functional elements in the form of virtual operating units 7, 8, 9, which again have buttons 7a to 7c, 8a to 8c, 9a to 9c. Figure 1shows a first step of this process. To establish a session, a bidirectional data transmission is established between the security device 2 and the mobile terminal 3 (arrow a in Figure 1 ). Data transmission is encrypted so that it cannot be manipulated by third parties.

[0055] The fail-safe processor unit 6 then reads the configuration from the memory unit (arrow b in Figure 1 ). The configuration includes, in particular, parameters characterizing control elements, such as the type and number of elements (buttons or switches), colors, values, safe states of the elements, and so on.

[0056] After the configuration has been read into the control module, the available virtual control units 7, 8, and 9 are displayed on the screen of the mobile device 3. Arrow I indicates that additional virtual control units can be displayed by scrolling.

[0057] The user can then select an element of a virtual control unit 7, 8, 9 by pressing it. In this case, this is the virtual control unit 9, which is selected by pressing the button 9a on the screen. The virtual control unit 9 is a control element that is not physically present on the safety device 2.

[0058] This selection is confirmed with a Select signal (arrow c in Figure 2) is sent from the control module to the fail-safe processor unit 6. There, the selection is checked. If it is recognized as correct and valid in the fail-safe processor unit 6, a verification signal is sent to the control module (arrow d in Figure 2 ).

[0059] The selection is then sent to the control module for confirmation. If the user recognizes the selection as correct and confirms it, the control module sends a confirmation signal (arrow e in Figure 3 ), whereby the fail-safe processor unit 6 also sends a confirmation signal to the control module as acknowledgement (arrow f in Figure 3 ).

[0060] The variable control unit 9 is now selected and can be confirmed as Figure 3 shows. In this case, Figure 3 a confirmation button 10 for confirming an entry and a cancel button 11 for deleting an entry.

[0061] Figure 4 shows the situation when the virtual control unit 9 is activated, with button 9a pressed. Arrow g represents a cyclic data exchange between the fail-safe processor unit 6 and the mobile terminal 3, which continuously monitors the presence and correct functioning of the mobile terminal 3. If an error occurs, the virtual control units 7, 8, 9 revert to the safe state.

[0062] Figure 4 shows additional virtual control units 7, 8, which can be selected and activated in the same way. These virtual control units 7, 8 correspond in function to control elements 4, 5. This allows one and the same function of the safety device 2 to be changed either by operating control element 4 or the virtual control unit 7. The same applies to control element 5 and the virtual control unit 8.

[0063] If an error occurs in the selection of a virtual control unit 9 during the above procedure, the selection is not confirmed and the virtual control unit 9 is not activated.

[0064] Figure 5 shows a variant of the embodiment according to the Figures 1 to 4 .

[0065] This shows Figure 5 a configuration menu that is configured according to the procedure set out in the Figures 1 to 4 can be selected and activated. The configuration menu has three input buttons (12, 13, 14) and a numeric input (15).

[0066] Input buttons 12 and 13 are in their enabled position, so that the functions of safety device 2 assigned to these input buttons 12 and 13 are activated. Input button 14 is in its disabled position, so that the functions assigned to this input button 14 are deactivated. For example, parameter values ​​can be specified in the form of alphanumeric characters using the numeric input 15. List of reference symbols

[0067] (1)Safety device (2)Safety device (3)Mobile device (4)Operating element (4a - c)Button (5)Operating element (5a - c)Button (6)Fail-safe processor unit (7)Virtual operating unit (7a - c)Button (8)Virtual operating unit (8a - c)Button (9)Virtual operating unit (9a - c)Button (10)Confirmation button (11)Cancel button (12)Enter button (13)Enter button (14)Enter button (15)Numerical input

Claims

1. Safety system (1) with a safety device (2) comprising a fail-safe processor unit (6) and a terminal device assigned to the safety device (2) with a control module, wherein the control module is designed to establish data transmission between itself and the fail-safe processor unit (6), in which data is transmitted in encrypted form, which transmit data in encrypted form, wherein a configuration with functionalities of the safety device (2) is transmitted to the control module by means of the data transmission from the fail-safe processor unit (6), wherein, by means of the control module, at least one virtual functional element for the safety device (2) is activated in the terminal device depending on the configuration, wherein the virtual function element is a virtual operating unit (7, 8, 9) with which a user of the terminal device can control or set functions of the security device (2) and the virtual operating unit (7, 8, 9) forms a function extension of the security device (2), characterised in that the safety system (1) is designed to perform the following steps: - transferring the configuration from the fail-safe processor unit (6) to the control module, - displaying the configuration in the end device, - sending a user selection of virtual function elements to the fail-safe processor unit (6), - checking the selection in the fail-safe processor unit (6) and verifying the selection by means of a verification signal sent by the fail-safe processor unit (6) to the control module, - confirming the verification signal by the control module by sending a confirmation signal to the fail-safe processor unit (6), - sending a confirmation signal to the fail-safe processor unit (6) for counter-confirmation, whereupon the selected functional element is activated.

2. Safety system (1) according to claim 1, characterised in that the configuration comprises parameters which define the functions of virtual operating units (7, 8, 9) or configuration menus.

3. Safety system (1) according to one of claims 1 and 2, characterised in that the terminal device is a mobile terminal device (3).

4. Safety device (I) according to one of claims 1 to 3, characterised in that the terminal device is not fail-safe with the control module.

5. Safety system (1) according to one of claims 1 to 4, characterised in that the safety device (2) is a safety interlock system, a safety switch, a bus module, an access control system or an operating mode selection system.

6. Safety system (1) according to one of claims 1 to 5, characterised in that the data transmission takes place via a wired or wireless data transmission link.

7. Safety system (1) according to one of claims 1 to 6, characterised in that a session of data transmission is initiated by a start signal from the control module in the terminal device.

8. Method for operating a safety system (1) with a safety unit (2) having a fail-safe processor unit (6) and a terminal device assigned to the safety unit (2) with a control module, wherein the control module is designed to establish data transmission between itself and the fail-safe processor unit (6), which transmit data in encrypted form, wherein a configuration with functionalities of the safety device (2) is transmitted to the control module by means of the data transmission from the fail-safe processor unit (6), wherein, by means of the control module, at least one virtual functional element for the safety device (2) is activated in the end device depending on the configuration, wherein the virtual function element is a virtual operating unit (7, 8, 9) with which a user of the terminal device can control or set functions of the safety device (2), and the virtual operating unit (7, 8, 9) forms a function extension of the safety device (2), characterised in that the safety system (1) performs the following steps: - transmitting the configuration from the fail-safe processor unit (6) to the control module, - displaying the configuration in the end device, - sending a user selection of virtual function elements to the fail-safe processor unit (6), - checking the selection in the fail-safe processor unit (6) and verifying the selection by means of a verification signal sent by the fail-safe processor unit (6) to the control module, - confirming the verification signal by the control module by sending a confirmation signal to the fail-safe processor unit (6), - sending a confirmation signal to the control module for counter-confirmation by the fail-safe processor unit (6), whereupon the selected virtual function element is activated.