SAFETY DEVICE AND METHOD FOR OPERATING A SAFETY DEVICE
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- EUCHNER GMBH & CO KG
- Filing Date
- 2021-06-11
- Publication Date
- 2026-05-07
AI Technical Summary
Existing safety devices face challenges in reliably transmitting and generating safety switching signals and other output signals to a safety controller without fail, especially in complex applications with multiple actuators, which is crucial for ensuring machine safety.
A safety device with a safety switch that reads actuator data via RFID, generates safety switching signals, and outputs all signals through a secure serial or bus interface, ensuring fail-safe transmission using checksums and redundant computer structures.
Ensures reliable and fail-safe transmission of all output signals, including safety switching signals, enhancing the fault tolerance and functionality of the safety device, allowing for complex monitoring and control functions with minimal design effort.
Description
[0001] The invention relates to a safety device and a method for operating a safety device.
[0002] Such safety devices comprise a safety switch and at least one actuator that is movable relative to the safety switch. This type of safety device is commonly used in safety engineering. One example of such an application is access control to a hazardous area, where access can be closed off with a safety door. In this case, the actuator is typically located on the safety door, while the safety switch is located on a frame structure adjacent to the access point. The term "safety door" includes doors, gates, flaps, hoods, covers, swing and sliding doors, and similar devices.
[0003] Common safety switches feature an RFID system with a transponder integrated into the actuator and a reader integrated into the safety switch. This RFID system allows monitoring of the closed position of the safety door. Only when the door is in the closed position is the transponder in the actuator spatially aligned with the reader in the safety switch, enabling the reader to receive transponder signals.
[0004] In complex applications, the safety device can have several actuators assigned to the safety switch. For example, the actuators can be configured to detect different positions of the systems or system components to be monitored. Examples include monitoring devices for rotary tables, roller doors, or robots. Depending on which actuator, and thus which position, is detected by the safety switch, a specific monitoring function is triggered, which is primarily defined by a safety controller.
[0005] One problem here is that the safety switch must generate characteristic output signals for the different information contained in the actuators and feed them to the safety controller so that it can perform its intended monitoring function. This problem is further exacerbated by the fact that the information from the actuators must be transmitted to the safety controller reliably, i.e., without fail.
[0006] DE 10 2008 060 004 A1 relates to a safety switch for generating a system release signal depending on the position of a movable safety door, which secures access to a hazardous area of a system. When the system release signal is present, at least one part of the system located within the hazardous area can be operated. The switch includes a door part for attachment to the movable safety door and a frame part for attachment to a door counterpart. An actuator is adjustable between a first and a second position, with a recess into which the actuator can engage in the second position. A locking element is designed to block the actuator in the second position. A first position sensor is designed to uniquely detect at least one of the actuator's positions in order to generate the system release signal accordingly.A door release unit can assume a locking state and an unlocking state, wherein in the locking state a blockage of the actuator by the locking element in the second position is permitted or maintained, and in the unlocking state a blockage of the actuator by the locking element in the second position is not permitted or is lifted.
[0007] DE 10 2004 020 997 A1 relates to a safety switching device for a safety circuit, comprising a control unit for processing an input signal and at least one switching element having at least one active and one inactive switching state. The control unit is configured to control the switching element to generate an output signal at an output that depends on the input signal. Furthermore, a diagnostic function for detecting a malfunction is provided, wherein the control unit is configured to control the switching element to the inactive state when a malfunction is detected. The control unit is also configured to generate a data telegram at the output that depends on the detected malfunction.
[0008] EP 3 779 899 A1 relates to a control device for a system controlled by a controller, comprising an evaluation unit and at least one acquisition unit connected to the evaluation unit. Depending on the input variables entered into the acquisition unit, the evaluation unit can select an operating mode and / or assign access authorization. The resulting output variables can be output to the controller via an output stage.
[0009] In Bernstein: "Gesamtprogramm Schaltertechnik und Sicherheitstechnik", May 1, 2027 (2017-05-01), pages 1-172, XP093172684, online, a series connection of safety switches in an AS-Inface bus system is described.
[0010] The invention is based on the objective of providing a safety device of the type mentioned above, which can implement complex monitoring functions with minimal design effort.
[0011] The features of the independent claims are provided to solve this problem. Advantageous embodiments and expedient further developments of the invention are described in the dependent claims.
[0012] The invention relates to a safety device comprising a safety switch, an arrangement of actuators associated with the safety switch, and a safety controller. The safety switch is configured to read actuator data from each associated actuator and, depending on the actuator data, to generate safety switching signals and output them to the safety controller. The safety switch has a safe output structure in the form of a safe serial interface or a safe bus interface, through which all output signals are transmitted.
[0013] The invention further relates to a method for operating a safety device.
[0014] The safety device according to the invention comprises a safety switch to which an arrangement of actuators is assigned, whereby in the simplest case only one actuator may be provided.
[0015] The safety device according to the invention is used in the field of safety engineering, specifically in the area of machine safety. The safety device generates a safety function, particularly for monitoring a system or a hazardous area within a system. This safety function is implemented by the safety switch generating a safety switching signal, depending on whether it detects an associated actuator. This signal is then output to a safety controller, which controls and / or monitors the operation of the system. Specifically, if the actuator is detected in the safety switch, a release signal is generated within the safety switch, enabling the system to operate via the safety controller.
[0016] Advantageously, each actuator has a transponder. An RFID reader is located in the safety switch. When an actuator approaches the safety switch closely enough that the transponder is within the reading range of the RFID reader, the actuator data stored in the transponder is read.
[0017] According to the invention, the safety switch has a safe output structure in the form of a safe serial interface or a safe bus interface, through which not only the safety switching signal but also all other output signals are output. The output signals are transmitted from the safety switch to the safety controller via this safe output structure in a fail-safe manner. This is particularly important for the output of the safety switching signal. Since the safety switching signals output by the safety switch trigger a safety function in the safety controller, the output and transmission of the safety switching signal must be fail-safe to meet the applicable safety requirements.
[0018] A key advantage of the invention is that, in addition to the safety switching signals, all other output signals are also output via the safe output structure, thus ensuring fail-safe output and transmission for these signals as well, without any further effort, regardless of whether the other output signals are safety-relevant or not. Other output signals can be alarm signals, actuator indicators, or signals for displays.
[0019] The fault tolerance of the secure output structure, i.e., the secure serial interface or the secure bus interface, can be ensured, firstly, by securing the information transmitted via the secure output structure with secure identifiers such as checksums. These are imprinted on the information at the sending end and checked at the receiving end, in particular by comparison with predefined expectations. Alternatively or additionally, redundant, especially dual-channel, computer structures can be provided at the sending and / or receiving end, whereby error checking is carried out by means of a multi-channel comparison of the information to be transmitted and the information received.
[0020] Data transmission via the secure output structure can generally be single-channel. In particular, well-known safety bus systems such as IO-Link Safety or dual-channel data transmission can be used.
[0021] According to an advantageous embodiment, the actuator data of each actuator contains identification data by which the actuator can be reliably identified in the safety switch.
[0022] By reliably identifying the actuators based on their actuator data, i.e., in a fault-free manner, the fault tolerance of the entire safety device is increased.
[0023] Such fault tolerance is achieved, for example, by securing the actuator data, which is available as codes, via test numbers, checksums and the like, whereby when the actuator data of an actuator is read into the safety switch, the test numbers or checksums are compared with predefined expectations.
[0024] Furthermore, it is essential that the actuators are clearly identified based on their identification data, i.e., that they are also distinguished from one another, so that confusions which could lead to malfunctions of the safety device are avoided.
[0025] According to an advantageous embodiment, it is possible to determine, based on actuator data read into the safety switch, whether this actuator is a permissible or impermissible actuator.
[0026] Advantageous are partial data entries of the actuator data, which are in the form of bit sequences and are configured to define an actuator function. For example, a function can be defined such that the actuator monitors a separating protective device, such as a safety door, requiring only one actuator. Furthermore, a function can be configured such that an actuator performs monitoring tasks on a rotary table, in which case multiple actuators are used.
[0027] In particular, new safety functions become possible because the controller can switch safety-relevant machine functions based on the safe actuator data by uniquely and securely identifying a specific actuator or group of actuators. The smallest possible actuator in this group can be a single actuator.
[0028] If an actuator in the safety switch is recognized as permissible based on the actuator data and thus accepted, the safety switching signal can be generated and output to the safety controller depending on the actuator data of this actuator, thereby triggering a corresponding safety function.
[0029] If, on the other hand, an actuator in the safety switch is identified as invalid based on the actuator data and thus rejected, then, depending on the actuator data of this actuator in the safety switch, no safety switching signal can be generated.
[0030] Particularly in functions where multiple actuators are used to perform monitoring tasks, it is advantageous that multiple actuators are accepted as permissible in the safety switch based on identical partial data in their actuator data.
[0031] It is advantageous that actuators can be programmed individually or in groups into the safety switch.
[0032] The actuators can be taught in during a teaching-in process, particularly when the safety switch is powered up. The taught-in actuators are then assigned to the respective application.
[0033] For example, if the safety device monitors the closed state of a safety door providing access to a hazardous area, an actuator is attached to the safety door and then programmed by the safety switch, whereby the actuator is uniquely identified using its identification data. After the programming process, only this actuator can then be used to monitor the safety door.
[0034] The process of teaching actuators to a group can be simplified by making some of the actuator data identical for all group members. This allows only one actuator to be taught as a representative for the group, automatically teaching all other actuators in the group.
[0035] In a simple embodiment, the switch can accept any actuator and securely forward the secure data contained in the actuator from the factory to the controller.
[0036] According to an advantageous embodiment of the invention, the actuator data of an actuator contains information about the properties and / or the condition of the object provided with this actuator.
[0037] For example, this information may include whether the actuator is located on a safety door, a rotary table, or a storage station for robots.
[0038] Rotary tables must be positioned in predefined locations to enable specific work processes. Actuators are used for this type of position monitoring.
[0039] Furthermore, storage positions in storage stations for robots can be monitored using actuators to avoid misassignments.
[0040] It is also possible to monitor the change of robot tools using actuators.
[0041] Another application example is the reliable identification of containers.
[0042] In these cases, the actuator data may contain information about the properties of the respective objects, their positions, or even customer-specific information. The number of valid copies of an actuator may also be stored in the actuator data.
[0043] The actuator data read into the safety switches of such actuators thus provides extensive information about the respective application.
[0044] According to an advantageous embodiment, the operation and / or operating state of an actuator can be predetermined based on actuator data that is read into the safety switch.
[0045] By teaching the actuator data to the safety switch, the actuator thus assumes a control function with which the operation of the safety switch can be changed or adjusted.
[0046] This significantly simplifies the manufacturing of safety switches, as it eliminates the need to define and stock numerous different variants. Instead, the operating mode and / or operating state can be determined via the actuator data. The number of actuators that can be used for a single operating mode of the safety switch is freely selectable. These actuators can also be used during the safety device's operation to perform monitoring functions.
[0047] The operating mode of the safety switches to be set can, for example, consist of which type of actuator of safety switches is accepted, how the data processing in the safety switch takes place, which indicators are provided, and the like.
[0048] Another example of a setting for a working method could be that different actuators and / or actuator groups are taught in, whereby the safety switch accepts and distinguishes these based on the (partial) actuator data and then shows different behaviors.
[0049] In particular, the number of accepted actuators can be specified or changed via the actuator data in the safety switch.
[0050] Furthermore, the actuator data in the safety switch can specify which information from actuator data is accepted by actuators.
[0051] Finally, output signals can be specified via the actuator data, which are then output by the safety switch via the safe output structure.
[0052] According to an advantageous embodiment, actuator data, parts of actuator data and / or data derived from actuator data in the safety switch are transmitted to the safety controller via the safe output structure of the safety switch.
[0053] This means that actuator data, or parts thereof, are also available in the safety switches. It is also possible to perform evaluations in the safety switch based on the actuator data and to transfer the results to the safety controller.
[0054] The data transmitted in this way can represent explicit information that can be used directly by the safety controller, for example to perform evaluations, carry out error checks, control displays, or the like.
[0055] Alternatively, the security controller can use the transmitted data to retrieve stored information in order to carry out certain processing operations.
[0056] Generally, only actuator data or information derived from it is transmitted from the safety switch to the safety controller if it originates from actuators recognized as permissible.
[0057] In general, it is also possible to read actuator data from unauthorized actuators in safety switches and, if necessary combined with warning messages, forward it to the safety controller.
[0058] The functionality of the safety device according to the invention can be further extended by enabling information to be written into an actuator in a fault-proof manner using the safety switch, the safety controller and / or a separate writing station.
[0059] The writing station can, for example, consist of a personal computer connected to the safety switch.
[0060] The registration process can take place before the security device is put into operation or during its operation.
[0061] The data content of actuator data can be flexibly modified or expanded using the write operations. This allows information relevant to the control of the entire system to be written to the actuator even while the safety device is in operation. In this way, it is possible for a safety switch to be installed at one point in the system, but for the information from this safety switch to be used at another point in the system with a different safety switch.
[0062] According to an advantageous embodiment of the invention, the safety device comprises several safety switches integrated into a safe bus system. The safe output structures of the safety switches are then formed by safe bus interfaces, which serve for connection to the bus system. Addresses are then assigned to the safety switches, under which they can be addressed by a bus system, for example, by a master. Examples of such safe bus systems are PROFIsafe, IO-Link Safety, or CIP Safety.
[0063] The invention will be explained below with reference to the drawings. The drawings show: Figure 1: Schematic representation of an embodiment of the safety device according to the invention. Figure 2: Detail view of a safety switch with an associated actuator for the safety device according to the invention. Figure 1 Figure 3: First application example for the safety device according to Figure 1 Figure 4: Second application example for the safety device according to Figure 1 Figure 5: Third application example for the safety device according to Figure 1 .
[0064] Figure 1 Figure 1 shows an embodiment of the safety device 1 according to the invention. The safety device 1 serves to monitor and secure a system 2 from which dangers to persons may emanate.
[0065] The system 2 is controlled by a safety controller 3. The safety controller 3 has a fail-safe design, which is realized in particular by a multi-channel design, especially by two mutually monitoring computer units 12.
[0066] The safety device 1 also has a safety switch 4.
[0067] According to the invention, the safety switch 4 has a safe output structure 5 in the form of a safe serial interface or a safe bus interface. The safety controller 3 has a corresponding interface 6. This establishes a safe data transmission path 7 between the safety switch 4 and the safety controller 3.
[0068] The output signals from the safety switch 4 are transmitted to the safety controller 3 via the safe output structure 5 in a fail-safe manner. In principle, the data transmission path 7 can be bidirectional.
[0069] The fault tolerance of the secure output structure 5, i.e., the secure serial interface or the secure bus interface, can be ensured, firstly, by securing the information transmitted via the secure output structure 5 with secure identifiers such as checksums or verification numbers. These identifiers are imprinted on the information at the sending end and checked at the receiving end, in particular by comparison with predefined expectations. Alternatively or additionally, redundant, especially dual-channel, computer structures can be specified at the sending and / or receiving end, whereby error checking is performed by a multi-channel comparison of the information to be transmitted and the information received.
[0070] Data transmission via the safe output structure 5 can generally be single-channel. In particular, well-known safety bus systems such as IO-Link Safety or dual-channel data transmission can be used.
[0071] How Figure 1 The safety switch 4 is shown to be assigned an arrangement of actuators 8 as further components of the safety device 1.
[0072] Depending on actuator data from an actuator 8, which is read into the safety switch 4, the safety switch 4 generates a safety switching signal, which, according to the invention, is output via the safe output structure 5. The safety switching signal triggers a safety function in the safety controller 3. In particular, if a valid signal is detected in the safety switch 4 based on the actuator data, a release signal is generated as a safety switching signal, which enables the operation of the system 2.
[0073] Figure 2 shows a detailed view of the safety switch 4 with an actuator 8. This shows Figure 2The situation arises when the actuator 8 is located within the activation range of the safety switch 4. In this case, this is the case because the actuator 8 has retracted into a recess 9 in the safety switch 4. However, providing such a recess 9 is not strictly necessary.
[0074] When an actuator 8 is inserted into the recess 9 of the safety switch 4, a transponder 10 is located in the actuator 8 within the detection range of an RFID reading unit 11 of the safety switch 4, so that data stored in the transponder 10 is read by the RFID reading unit 11 and processed in a computer unit 12 of the safety switch 4. The computer unit 12 is connected to the safe output structure 5.
[0075] The actuator data for actuator 8 is stored in the form of codes secured by checksums. Based on this actuator data, each actuator 8 can be uniquely identified in the safety switch 4. The identification is error-free thanks to a comparison of the checksums with a predefined expectation, i.e., stored target values.
[0076] Furthermore, the actuator data in the safety switch 4 is used to determine whether a permissible or impermissible actuator 8 is present, whereby safety switching signals for the safety control 3 are only generated depending on the actuator data of a permissible actuator 8 in the safety switch 4.
[0077] In particular, several actuators 8 are accepted as permissible based on identical partial data in their actuator data in the safety switch 4.
[0078] Actuators 8 identified as impermissible are therefore rejected in the safety switch 4, so that their actuator data cannot generate a safety switching signal.
[0079] Advantageously, the actuator data of an actuator 8 contains information about the properties and / or the condition of the object equipped with this actuator 8.
[0080] As a result, by learning the actuator data, extensive information about the respective application is available in the safety switch 4.
[0081] The functionality of the safety device 1 is extended by the fact that, based on actuator data of an actuator 8 which is read into the safety switch 4, its operating mode and / or its operating state can be specified.
[0082] This allows the safety switch 4 to be configured via the actuator data and adapted for a specific application. In particular, this configuration allows you to define which actuator values are accepted by the safety switch 4, i.e., which actuators 8 are recognized as permissible by the safety switch 4.
[0083] The actuator(s) 8, which are used to configure the safety switches 4, can also be used in subsequent operation to perform monitoring functions by generating the safety switching signal in the safety switch 4 depending on the actuator data of these actuators 8.
[0084] A further enhancement of the functionality of the safety device 1 according to the invention consists in the fact that actuator data or parts of actuator data read into the safety switch 4 by an actuator 8 are supplied to the safety controller 3 via the safe output structure 5. Furthermore, it is possible for the safety switch 4 to process the actuator data and transmit the results of the processing to the safety controller 3.
[0085] The transmitted data may contain, in particular, information about the respective application, for example, information about the properties or condition of an object with which the actuator 8 is equipped.
[0086] The data transmitted from the safety switch 4 to the safety controller 3 can contain explicit information that can be directly evaluated by the safety controller 3. It is also possible for the safety controller 3 to retrieve stored information based on the transmitted data and then evaluate or process it.
[0087] The safety device 1 according to Figure 1 The system can be extended to allow information to be written to the actuators 8, enabling information transfer not only from the actuators 8 to the safety switch 4 but also in the reverse direction. Data can be written using the safety switch 4, the safety controller 3, or a separate writing station such as a personal computer or similar device. In particular, the safety switch 4 can be connected to a personal computer or similar device and thus used as a writing station.
[0088] Finally, it is possible to extend the safety device 1 by providing several safety switches 4 that are integrated into a safe bus system.
[0089] Figure 3 shows a first application example for the safety device 1 according to Figure 1 In this example, the danger zone of a system 2 is secured by a fence 13. Access to the danger zone is via a safety gate 14 integrated into the fence 13. The safety switch 4 is fixedly mounted on a frame of the fence 13. An actuator 8 is located on the safety gate 14, which is programmed into the safety switch 4 during a programming process. After this programming, the actuator 8 can now also be used for this safety device 1.
[0090] When the safety door 14 is in its closed position, the transponder 10 of the actuator 8 is within the reading range of the RFID reader 11 of the safety switch 4, and the actuator data of the actuator 8 is transmitted to the safety switch 4. The safety switch 4 then generates a release signal as a safety switching signal, which enables the operation of the system 2 via the safety controller 3. When the safety door 14 is open, the operation of the system 2 is not enabled, as the transponder 10 of the actuator 8 is outside the reading range of the RFID reader 11.
[0091] Figure 4Figure 1 shows another application example of the safety device 1. This safety device 1 provides system protection for a rotary table 15, to which a control unit 16 is assigned. The individual rotational positions of the rotary table 15 are monitored by actuators 8 (not shown), which interact with a safety switch 4.
[0092] How Figure 4 As shown, a safety switch 4 is provided in the control unit 16. The actuators 8 (not shown) are arranged in the rotary table 15 and mark the individual positions of the rotary table 15.
[0093] The actuators 8 of the rotary table 15 form a group of actuators 8 that share a common set of actuator data, which are taught in a teaching process. It is sufficient to teach in one actuator 8 as a representative of the entire group based on the common set of actuator data.
[0094] Figure 5 Figure 1 shows another application example of the safety device 1. In this case, storage locations 17 of a storage station 18 are provided, into which tools 20 can be placed or removed by means of a robot 19. This is controlled by the safety device 1 according to the invention, wherein for this purpose a safety switch 4 is provided on an arm of the robot 19 and actuators 8 are provided on the tools 20. Reference symbol list
[0095] (1) Safety device (2) System (3) Safety controller (4) Safety switch (5) Safe output structure (6) Interface (7) Data transmission path (8) Actuator (9) Recess (10) Transponder (11) RFID reader (12) Computer unit (13) Enclosure (14) Safety door (15) Rotary table (16) Control unit (17) Storage location (18) Storage station (19) Robot (20) Tool
Claims
1. Safety system (1) with a safety switch (4), an arrangement of actuators (8) assigned to the safety switch (4) and a safety control (3), wherein the safety switch (4) is designed to read in actuator data from each assigned actuator (8) and, depending on the data from the actuator (8) and to output safety switching signals to the safety control (3), characterised in that the safety switch (4) has a safe output structure (5) in the form of a safe serial interface or a safe bus interface, via which all output signals are output.
2. Safety system (1) according to claim 1, characterised in that the actuator data of each actuator (8) contains identification data by means of which the actuator (8) can be reliably identified in the safety switch (4).
3. Safety system (1) according to claim 1, characterised in that the actuator data in the safety switch (4) is used to determine whether an authorised or unauthorised actuator (8) is present, whereby safety switching signals are generated in the safety switch (4) according to an authorised actuator (8) for the safety control (3).
4. Safety system (1) according to claim 3, characterised in that several actuators (8) are accepted as permissible on the basis of identical partial data in their actuator data in the safety switch (4).
5. Safety system (1) according to one of claims 1 to 4, characterised in that actuators (8) can be programmed individually or in groups in the safety switch (4).
6. Safety system (1) according to claim 5, characterised in that, in a group of actuators (8), part of the actuator data matches and only one actuator (8) is programmed on behalf of the entire group.
7. Safety system (1) according to one of claims 1 to 6, characterised in the actuator data of an actuator (8) contains information about properties and / or the condition of the object equipped with this actuator (8).
8. Safety system (1) according to one of claims 1 to 7, characterised in that the operating mode and / or operating state of an actuator (8) can be specified on the basis of actuator data from this actuator that is read into the safety switch (4).
9. Safety system (1) according to claim 8, characterised in that the number of accepted actuators (8) is specified or changed by the actuator data in the safety switch (4).
10. Safety system (1) according to one of claims 8 or 9, characterised in that the actuator data in the safety switch (4) can be used to specify which information from actuator data from actuators (8) is accepted.
11. Safety system (1) according to one of claims 7 to 10, characterised in that the actuator data can be used to specify output signals that are output by the safety switch (4) via the safe output structure (5).
12. Safety system (1) according to one of claims 1 to 11, characterised in that actuator data, parts of actuator data and / or data derived from actuator data in the safety switch (4) are transmitted to the safety control (3) via the safe output structure (5) of the safety switch (4).
13. Safety system (1) according to claim 12, characterised in that information can be written to an actuator (8) in a fail-safe manner by means of the safety switch (4), the safety controller (3) and / or a separate writing station.
14. Safety system (1) according to one of claims 1 to 13, characterised in that several safety switches (4) are provided, which are integrated into a safe bus system.
15. Method for operating a safety system (1) with a safety switch (4), an arrangement of actuators (8) associated with the safety switch (4) and with a safety control (3), wherein the safety switch (4) is designed to read in actuator data from each associated actuator (8) and, depending on the data from the actuator (8) and outputting safety switching signals to the safety control system (3), characterised in that the safety switch (4) has a safe output structure (5) in the form of a safe serial interface or a safe bus interface, via which all output signals are output.