VERIFICATION OF SAFETY-RELEVANT PARAMETER VALUES
Patent Information
- Application Number
- DE502021009229
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-07-09
- Publication Date
- 2025-12-04
- Estimated Expiration
- 2041-07-09
Description
[0001] The invention relates to a method for checking safety-relevant parameter values and a parameterization device suitable for carrying out this method. The invention also relates to a system comprising a parameterization device and a switching device.
[0002] Numerous industrial switching devices, such as overload relays, circuit breakers, motor starters, soft starters, and motor management systems, also serve as protective devices. These prevent, for example, an overloaded motor or a dry-running pump from overheating and becoming an ignition source. These switching devices thus influence technical safety and must comply with the relevant directives, such as the ATEX product directive for explosion protection. Electronic switching devices must therefore comply with safety engineering standards, such as Safety Integrity Level 1 (SIL 1).
[0003] The setting of parameters must also be considered: These switching devices have one or more safety-relevant parameters, such as motor rated current and tripping class. It must be ensured that these parameters are set to the correct values on the switching device; otherwise, the protective function may be ineffective. Various methods are known today for setting parameters considered safety-relevant: For overcurrent protection devices such as thermal overload relays, mechanical setting devices such as rotary encoders or potentiometers are known, which can be used to set the rated operational current of a monitored device on the overcurrent protection device.A check to ensure that the parameter setting has been carried out correctly can be done indirectly by determining the actual tripping time when the overcurrent protection device is subjected to a defined current and comparing it with a target tripping time specified by a time-current characteristic curve.
[0004] On the failsafe Siemens SIMATIC ET200SP motor starter, the parameters rated operational current (Ie) and shutdown class (CLASS), which are considered safety-relevant in ATEX operation, can be set by reading a data set or using engineering software. However, before the motor starter adopts new parameter values for the safety-relevant parameters, a user must check and confirm the new parameter values using a flashing sequence indicated by LEDs located on the motor starter (LED = Light Emitting Diode).
[0005] With the Siemens SIRIUS 3RW55 soft starter, safety-relevant parameter values are entered by a user on the soft starter's HMI ("3RW5 HMI High-Feature") and written by the soft starter as a text file to an SD memory card (HMI = Human Machine Interface; SD = Secure Digital). The user must check the parameter values in the text file, e.g., on a PC, and then confirm them on the HMI (PC = Personal Computer).
[0006] Another possible approach involves using not only the device being parameterized but also engineering software, which is used to set the safety-relevant parameters, that meets the safety requirements. In this case, it is technically ensured that the parameter values entered by the user in the engineering software are correctly received by the device; therefore, no additional verification of the parameter values is necessary. However, this approach would severely restrict the use of currently available engineering software products that do not meet the safety requirements.
[0007] The object of the invention is to provide a method with which improved verification of safety-relevant parameter values of a switching device can be carried out.
[0008] This problem is solved according to the invention by the method according to independent claim 1. Advantageous embodiments of the method according to the invention are the subject of the dependent claims. Patent literature EP2341406A1 relates to a method for the safe parameterization of an electrical device, wherein a parameter entered by a user at an operating unit is transferred to the electrical device and stored there in write-protected form, the stored parameter is transferred back to the operating unit and displayed there for confirmation by the user, and the confirmation is transmitted to the electrical device. DE102011088236 relates to a method for the safe operation of a field device for process automation technology.
[0009] The computer-implemented method according to the invention serves to verify safety-relevant parameter values of a switching device using engineering software running on a parameterization device. The engineering software comprises a first and a second sub-area, which are independent of each other, i.e., they independently control their respective process steps. The method includes a step in which the parameterization device, controlled by the first sub-area, receives parameter values for the switching device, comprising the safety-relevant parameter values. The method includes a step in which the parameterization device sends the parameter values to the switching device.The procedure includes a step in which the parameterization device receives at least one safety parameter data set from the switching device, containing the safety-relevant parameter values extracted from the parameter values by the switching device. The procedure also includes a step in which the parameterization device, controlled by the second sub-area, displays the safety-relevant parameter values received with the safety parameter data set for user verification.
[0010] The parameterization device is suitable for parameterizing the switching device by transmitting parameter values for one or more parameters, defined by the switching device's functionality, from the parameterization device to the switching device via a communication channel; this process is called parameterization of the switching device. The communication channel between the parameterization device and the switching device can be a wireless communication connection, e.g., via Bluetooth or WLAN, or a wired communication connection, e.g., an Ethernet connection via a LAN cable.
[0011] The parameters are divided into safety-relevant and non-safety-relevant parameters. Safety-relevant parameters can include, for example, the following: motor rated current, setting current, trip class, dry-running protection trip threshold, and dry-running protection delay. Non-safety-relevant parameters can include, for example, trip thresholds for temperatures and analog values, hysteresis, and delays.
[0012] The parameterization device is a software-controlled device (hardware) capable of executing engineering software that enables or supports the parameterization of the switching device. The parameterization device can be a dedicated electronic device or a general-purpose electronic device such as a PC, laptop, or smartphone running the engineering software. The device is configured via the engineering software, which then configures it to function as a parameterization device for the switching device.
[0013] The engineering software is a software program divided into several sub-areas that operate independently but communicate with an external communication partner via a common communication interface, for example, to exchange data. The engineering software has a first sub-area and a second sub-area; this allows for separate input and output of parameter values: parameter values are entered for transmission to the switching device via the first sub-area of the engineering software, while parameter values are output for verification via the second sub-area.
[0014] The invention represents a significant improvement on known methods for verifying safety-relevant parameter values. It enables the use of engineering software developed according to standard (i.e., not safety) standards for parameterizing a switching device that was developed and complies with safety standards. This eliminates the need for engineering software that complies with safety standards, the development of which is considerably more complex than that of software that merely meets standard requirements. A first section (program part) of the engineering software controls the transmission of the safety-relevant parameter values, along with other non-safety-relevant parameter values, from the parameterization device—more precisely, from an I / O interface of the parameterization device—to the switching device via a communication channel.The switching device receives these parameter values, extracts the safety-relevant parameter values, and compiles them into a safety parameter data set. This safety parameter data set is secured with a checksum and transferred to the parameterization device, specifically to its I / O interface. A second part of the engineering software, separate from the first part, reads this data set, verifies the checksum, and displays the safety-relevant parameter values contained in the data set in a separate display window of the parameterization device—that is, different from the display window used for entering parameter values into the parameterization device. A user can release the parameters from within the engineering software using an "ATEX Release" command.The terms "user" and "user" are used synonymously in this description, both denoting a user of hardware / device or software.
[0015] The invention achieves diversity a) by transferring the safety-relevant parameter values both from the parameterization device to the switching device and from the switching device to the parameterization device using two different data packages, and b) by dividing the engineering software into a first and a second sub-area.
[0016] According to a preferred embodiment of the method, the parameterization device receives the parameter values from at least one of the following sources: Receiving from an initial GUI of the parameterization device, into which the parameter values, e.g. for start-up parameterization, were manually entered by a user; receiving from a control center, e.g. a process control system, or a web server; receiving from a database or reading a predefined parameter set for a sample application; reading from a description file, e.g. a GSDML file, which is a standardized description file for all ProfiNet Device devices.
[0017] An advantage of this is that the possibility of using different data sources increases the scope of application of the method.
[0018] According to a preferred embodiment of the method, the parameterization device outputs the safety-relevant parameter values for verification on a second GUI of the parameterization device. An advantage of this is that diversity is achieved by displaying the safety-relevant parameter values contained in the data set in a separate display window of the parameterization device, i.e., different from a display window used for entering the parameter values into the parameterization device.
[0019] According to a preferred embodiment of the method, the parameterization device transmits the parameter values to a software component of the engineering software, where the parameter values are rewritten into one or more parameter data sets for transmission. These parameter data sets are then transmitted from a communication interface of the parameterization device to the switching device via a communication channel. The switching device receives the parameter data sets, extracts the safety-relevant parameter values, and compiles these values into a safety parameter data set in a single write operation. An advantage of this approach is that the parameter data sets improve the transmission and processing of the parameter values.
[0020] According to a preferred embodiment of the method, the parameterization device outputs the safety-relevant parameter values for verification on a monitor of the parameterization device. An advantage of this is that the safety-relevant parameter values can be checked quickly and easily without the need for additional equipment.
[0021] According to a preferred embodiment of the method, the at least one safety data record received by the switching device is secured with a checksum. The parameterization device checks the checksum and outputs the safety-relevant parameter values for verification by a user if the integrity of the safety-relevant parameter values is confirmed during the checksum verification. An advantage of this method is that any change to the safety-relevant parameter values, e.g., due to a transmission error or manipulation, is detectable.
[0022] It is also possible that one or more parameter data sets contain exclusively safety-relevant parameter values.
[0023] According to a preferred embodiment of the method, after a user has verified the safety-relevant parameter values and confirmed their correctness, the parameterization device receives a corresponding release command from the user. This action can be performed by pressing a release button in a GUI. The parameterization device then sends a message to the switching device to release the safety-relevant parameter values received with the safety parameter data set. An advantage of this approach is that the switching device is explicitly signaled that the safety-relevant parameter values it received from the parameterization device are correct.
[0024] Another solution to the problem is a parameterization device for carrying out the method according to one of claims 1 to 5, comprising a communication interface for sending parameter values of a switching device to the switching device, for receiving a safety parameter data set with safety-relevant parameter values from the switching device and for sending a message to release the safety-relevant parameter values to the switching device; an output unit for outputting the received safety-relevant parameter values for verification by a user; an input unit for receiving a release command from the user after positive verification of the received safety-relevant parameter values; and a processor unit for executing the engineering software and for controlling the communication interface, output unit and input unit.
[0025] Possibleis a computer-implemented method for extracting safety-relevant parameter values of a switching device from received parameter values, wherein the method comprises the following steps: Receiving, at a switching device, parameter values for the
[0026] Switching device from a parameterization device, wherein the parameter values include the safety-relevant parameter values; Extracting, by the switching device, the safety-relevant parameter values from the parameter values; Generating at least one safety parameter data set containing the extracted safety-relevant parameter values; and sending the at least one safety parameter data set to the parameterization device for verification of the safety-relevant parameter values.
[0027] According to a preferred embodiment of the method, the at least one security parameter data set is secured with a checksum. An advantage of this is that the integrity of the security-relevant parameter values is protected during transmission.
[0028] A switching device is possible for carrying out the method for extracting safety-relevant parameter values of a switching device from received parameter values, comprising a processor unit for extracting safety-relevant parameter values from received parameter values and for generating at least one safety parameter data set containing the extracted safety-relevant parameter values; and a communication interface for receiving parameter values for the switching device, comprising the safety-relevant parameter values, and for sending a safety parameter data set with the safety-relevant parameter values.
[0029] Another solution to the problem is a system comprising a parameterization device according to the invention and a switching device.
[0030] Another solution to the problem is a computer program product which has a first and a second sub-area that are independent of each other, comprising commands that cause a parameterization device to execute the inventive method for checking safety-relevant parameter values of a switching device.
[0031] Possible is a computer program product comprising commands that cause a switching device to execute the inventive method for extracting safety-relevant parameter values of a switching device.
[0032] The outlined problem is also solved by computer-readable media on which the computer program product according to the invention is stored.
[0033] The computer program product, also referred to more simply as the computer program, comprises instructions that cause the parameterization device of claim 6 to execute the method steps according to any one of claims 1 to 5. The computer program product is designed to be executable in a parameterization device. The computer program product can be stored as software or firmware in a memory unit of the parameterization device and be designed to be executable by a processor of the parameterization device, e.g., a processing unit or a processor (CPU) or a microcontroller (µC). Alternatively or additionally, the computer program product can also be designed, at least partially, as a hard-wired circuit, for example, as an ASIC (application-specific integrated circuit). According to the invention, the computer program product is designed to implement and execute at least one embodiment of the outlined method.The computer program product can integrate all sub-functions of the process within itself, i.e., it can be monolithic. Alternatively, the computer program product can be segmented, distributing sub-functions across segments that run on separate hardware. For example, part of the process can be performed in a parameterization device, and another part in a higher-level control unit, such as a PLC, a control center PC, or a computer cloud.
[0034] A computer program product is further proposed that can be directly loaded into the internal memory of a digital processing unit and comprises software code sections that execute the steps of the procedure described herein when the product is running on the parameterization device. The processing unit is, in particular, a processing unit for controlling a parameterization device. The computer program product can be stored on a data carrier, such as a USB flash drive, a DVD or CD-ROM, flash memory, EEPROM, or an SD card. The computer program product can also be in the form of a signal that can be loaded via a wired or wireless network.
[0035] The method is preferably implemented in the form of a computer program product for automatic execution. The invention is thus, on the one hand, a computer program product with program code instructions executable by a computer, and on the other hand, a storage medium containing such a computer program, i.e., a computer program product with program code means.
[0036] When procedural steps or sequences of steps are described below, this refers to actions that occur as a result of, or under the control of, the computer program product, unless it is expressly stated that individual actions are initiated by a user of the computer program product. At a minimum, any use of the term "automatically" means that the action in question occurs as a result of, or under the control of, the computer program.
[0037] Instead of a computer program with individual program code instructions, the method described here and below can also be implemented in the form of firmware. It is clear to those skilled in the art that, instead of implementing a method in software, it is always also possible to implement it in firmware, in firmware and software, or in firmware and hardware. Therefore, for the purposes of this description, the terms "software" and "computer program" should be understood to encompass other implementation possibilities, namely, in particular, implementation in firmware, in firmware and software, or in firmware and hardware.
[0038] The properties, features, and advantages of this invention described above, as well as the manner in which they are achieved, will become clearer and more easily understood through the following description of the drawings. These drawings are shown schematically and not to scale: FIG 1 a switching device and a parameterizing device for parameterizing the switching device; and FIG 2 a diagram of the time sequence.
[0039] FIG 1 and 2 Figure 1 shows a parameterization device 1 and a switching device 2. Parameterization device 1 is capable of parameterizing switching device 2 by transmitting one or more parameter values 30, which define functions of switching device 2, from parameterization device 1 to switching device 2 via a communication channel 50; this process is referred to as parameterization of switching device 2. The communication channel 50 can be a wireless communication connection, e.g., via Bluetooth or WLAN, or a wired communication connection, e.g., an Ethernet connection via a LAN cable.
[0040] The parameterization device 1 is a software-controlled device (hardware) capable of executing engineering software that enables or supports the parameterization of the switching device. Parameterization device 1 can be a dedicated electronic device or a general-purpose electronic device such as a PC, laptop, or smartphone running the engineering software. Parameterization device 1 comprises the following hardware components: a processor 18, main memory (RAM = Random Access Memory), data storage such as a hard drive, and a GUI as an HMI (GUI = Graphical User Interface; HMI = Human Machine Interface). The engineering software can be stored in the data storage, from where it is loaded into main memory for execution by the processor. A user can transmit input data to parameterization device 1 via the HMI, e.g.,Enter parameter values into a parameter form via a keyboard and receive output data from parameterization device 1, e.g. displaying parameter values present in switching device 2 in a window of a GUI.
[0041] The engineering software has a first sub-area 11A and a second sub-area 11B; this allows parameter values to be entered and checked separately using the engineering software: parameter values are entered via the first sub-area 11A of the engineering software, and parameter values are checked using the second sub-area 11B of the engineering software.
[0042] In a first GUI window 13, which is controlled by the first sub-area 11A of the engineering software, a user enters parameter values 30, a subset of which are safety-relevant parameter values 30s. The parameter values 30 are passed to a software component 15 "Read / Write Data Set" of the engineering software, where the parameter values 30 are rewritten into several parameter data sets 31-34. The parameter data sets 31-34 thus created are transmitted from a communication interface 12 of the parameterization device 1 via the communication channel 50 to the switching device 2 130.
[0043] The switching device 2 has a communication interface 22 and a processor unit 28. The switching device 2 receives the parameter data sets 31-34 via the communication interface 22, extracts the safety-relevant parameter values 30s from them using the processor 28, and collects the extracted safety-relevant parameter values 30s in a write operation 132 in a safety parameter data set 40, which is secured by a checksum 42 added to the safety parameter data set 40. The safety parameter data set 40 thus created is transmitted by the switching device 2 via the communication channel 50 to the communication interface 12 of the parameterization device 1 140.
[0044] The parameterization device 1 receives the safety parameter data set 40 and transmits it to the software component 15 "Read / Write Data Set" of the engineering software, where the safety parameter data set 40 is read. The data read from the safety parameter data set 40, i.e., the safety-relevant parameter values 30s and the checksum 42, are transferred to a software component 16 "Checksum Verification" of the engineering software, controlled by the second sub-area 11B of the engineering software 145. After the software component 16 "Checksum Verification" has successfully verified the integrity of the safety-relevant parameter values 30s using the checksum 42, the safety-relevant parameter values 30s are displayed to the user for verification in a second GUI window 14, which is controlled by the second sub-area 11A of the engineering software 150.
[0045] If the user has verified that the safety-relevant parameter values 30s displayed in the second GUI window 14 are correct, he initiates, by means of a software component 17 "Release of safety-relevant parameter values" of the engineering software, e.g. by clicking a release button in a screen window, the sending of a signal from the parameterization device 1 to the switching device 2, indicating that the safety-relevant parameter values 30s transmitted to the switching device 2 in the parameter data sets 31-34 are correct.
Claims
1. Computer-implemented method for verifying safety-relevant parameter values (30s) of a switching device (2) using engineering software (11) running on a parameterization device (1), wherein the engineering software has a first (11A) and a second (11B) subsection that are independent of each other, wherein the method comprises the following steps: - the parameterization device (1), controlled by the first subsection (11A), receives parameter values (30) for the switching device (2) comprising the safety-relevant parameter values (30s); - the parameterization device (1) sends the parameter values (30) to the switching device (2); - the parameterization device (1) receives from the switching device (2) at least one safety parameter data record (40) with the safety-relevant parameter values (30s) which were extracted from the parameter values (30) by the switching device (2); and - the parameterization device (1), controlled by the second subsection (11B), outputs the safety-relevant parameter values (30s) received with the safety parameter data record (40) for verification by a user.
2. Method according to Claim 1, wherein the parameterization device (1) receives the parameter values (30) from at least one of the following sources: - receiving from a first GUI (13) of the parameterization device (1) in which the parameter values (30) were manually entered by a user; - receiving (110) from a control centre or a web server; - receiving (110) from a database; - reading in from a description file.
3. Method according to Claim 1 or 2, wherein the parameterization device (1) outputs the safety-relevant parameter values (30s) for verification on a second GUI (14) of the parameterization device (1).
4. Method according to any one of the previous claims, wherein the at least one safety parameter data record (40) received by the switching device (2) is secured with a checksum (42), the parameterization device (1) checks the checksum (42) and the parameterization device (1) outputs the safety-relevant parameter values (30s) for verification by a user if the integrity of the safety-relevant parameter values (30s) was established when the checksum (42) was checked.
5. Method according to any one of the previous claims, wherein the parameterization device (1), after the safety-relevant parameter values (30s) have been verified by a user as being correct, receives a corresponding release command from the user and sends a message to the switching device (2) to release the safety-relevant parameter values (30s) received with the safety parameter data record (40).
6. Parameterization device (1) for carrying out the method according to any one of Claims 1 to 5, comprising: - a communication interface (12) for sending parameter values (30) of a switching device (2) to the switching device (2), for receiving a safety parameter data record (40) with safety-relevant parameter values (30s) from the switching device (2), and for sending a message to the switching device (2) to release the safety-relevant parameter values (30s); - an output unit (14) for outputting the received safety-relevant parameter values (30s) for verification by a user; - an input unit (17) for receiving a release command from the user after positive verification of the received safety-relevant parameter values (30s); and - a processor unit (18) for processing the engineering software (11) and controlling the communication interface (12), output unit (14), and input unit (17).
7. System comprising a parameterization device (1) according to Claim 6 and a switching device (2).
8. Computer program product which has a first (11A) and a second (11B) subsection that are independent of each other, comprising commands which cause a parameterization device (1) to carry out the method according to any one of Claims 1 to 5.
9. Computer-readable medium on which the computer program product according to Claim 8 is stored.