Brake force monitoring device and method
The device monitors actual braking force in machines using a controller to lock the drive unit when the force drops below a threshold, addressing reliability issues in brake monitoring systems, ensuring safety and compliance in high-speed machines.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- PILZ GMBH & CO KG
- Filing Date
- 2024-01-18
- Publication Date
- 2026-04-15
AI Technical Summary
Existing brake monitoring systems in machines like presses fail to reliably detect brake degradation due to high cycle rates and varying operating conditions, leading to safety risks, as they rely on overrun monitoring which is influenced by factors other than actual braking force, and are not adaptable to modern press machines with electronic camshafts and high speeds.
A device using a first controller to determine actual braking force by analyzing encoder signals for acceleration, locking the drive unit if the force falls below a threshold, independent of overrun angle, and optionally assisted by a second fail-safe controller for redundant testing.
Ensures reliable safety-related locking based on actual braking force, adaptable to high-speed systems, and provides timely maintenance indications, enhancing safety and compliance with standards.
Smart Images

Figure 0007846714000001 
Figure 0007846714000002 
Figure 0007846714000003
Abstract
Description
[Technical Field]
[0001] This disclosure relates to a device for monitoring the braking force of a drive unit and safety-related locking, e.g., switching off, of a drive unit in a technical system comprising two mechanical parts that are relatively movable and move toward each other by a drive unit at a predetermined operating interval. Furthermore, this disclosure relates to a corresponding method. [Background technology]
[0002] This type of technical system may be a machine tool for shaping a workpiece, such as a bending press, mechanical press brake, punching machine, or cutting machine, where two machine parts move toward each other to shape a workpiece inserted between them. Needless to say, such machines can pose a high risk to the operator, especially if the insertion operation—that is, intervention with the tool for inserting raw parts or removing finished parts—is performed manually by the operator.
[0003] Therefore, in order to operate this type of technical system safely, various requirements specified in the standards by the responsible authorities must be met. For complex technical systems, it is usually necessary to consider the requirements of various individual standards in order to ensure comprehensive protection. In Europe, for example, the standard DIN EN ISO 12100 "Safety of Machinery," which includes general design principles for risk assessment and risk mitigation as well as machinery, must always be applied to all machines. In the case of presses, for example, further individual standards that define specific safety requirements must be considered, such as the standard DIN EN ISO 16092-2 for eccentric presses. Furthermore, the individual standard DIN EN ISO 13849-1 "Safety-Related Parts of Control Systems," which further specifies specific requirements for presses in automatic mode, must also be referenced for safe machine control.
[0004] One specific safety requirement for a press machine is, for example, continuous monitoring of brake performance (braking force monitoring). During proper operation, the press machine should stop at top dead center (OTP), usually the 0° position of the drive shaft, at the end of each work cycle (operating interval), thereby allowing a specified overrun (delayed stop), for example, a 15° overrun. If the press machine exceeds the overrun specified in the standard (overrun monitoring), the press machine must be safely locked.
[0005] With recent improvements in press machine performance, measuring overrun is not always practical, especially in terms of strokes per minute, and the regulations specified in standards are not reliable enough to effectively detect actual brake degradation.
[0006] For example, with some press machines, monitoring at the end of each operating interval is impossible from a measurement technology standpoint and is only possible when the press machine actually stops. Furthermore, while monitoring is specified in the standard only when the press machine stops at OTP (Out-of-Touch Point), the press machine may also stop at locations other than OTP during other operating modes, such as during setup or maintenance.
[0007] Furthermore, due to the high number of cycles in modern presses, electronic camshafts are used instead of typical camshafts, making overrun monitoring impossible in the manner specified by standards. Also, at high speeds, values from encoders can only be recorded and processed by ultra-high-speed controllers (control units), and cannot be recorded and processed by special safety controllers that have a slower processing speed than standard controllers without these functions, as specified for safety features. Therefore, known safety devices cannot be easily adapted to modern presses.
[0008] Controllers for press machines are also often configured to adjust the brake switch-off point, or advance angle, to suit each speed. To ensure the press machine stops precisely at the OTP, for example, the controller can determine the deviation from the OTP at each stop at the OTP and, based on this, adjust the brake switch-off angle, or advance angle, so that the press machine stops at the OTP again at the next stop. However, dynamic adjustment of the cut-off angle prevents slow brake wear from being detected via overrun monitoring.
[0009] Another issue is that the monitoring procedures described in the DIN EN ISO 16092-2 standard do not take into account the total downtime of the press machine, which must be considered when determining the safety distance, particularly when using electrical sensing protection equipment (ESPE) such as light curtains. However, it would be desirable to consider the total downtime of the press machine for a comprehensive safety assessment.
[0010] Furthermore, other conditions may affect the total stopping time. For example, general air pressure affects the time it takes to bleed the brake cylinders, which in turn alters the total stopping time. These conditions may affect the total stopping time and the associated machine overrun, even if they do not directly relate to the actual braking force (performance) of the brakes.
[0011] Finally, the maximum overrun angle required by the standard (e.g., 15°) is related to the maximum speed of the press machine. At speeds lower than the maximum speed, the same amount of wear results in less overrun. As a result, brake wear can be significant at high speeds, but it cannot be detected by overrun monitoring at low speeds. [Overview of the Initiative] [Problems that the invention aims to solve]
[0012] Against this backdrop, this disclosure aims to provide an improved device of the type described above that takes into account and avoids the aforementioned problems. It aims to identify a device of the type described above that enables reliable and unaffected braking force monitoring. Furthermore, this disclosure aims to provide a device that can reliably ensure safety lock even in machines with a high number of strokes and / or cycles. [Means for solving the problem]
[0013] According to one aspect of the present disclosure, this objective is solved by a device for monitoring the braking force of a drive unit and for safety-related locking, in particular switch-off, of a drive unit in a technical system having two mechanical components that are relatively movable and move toward each other by a drive unit at a predetermined operating interval, the device comprising a first controller having an input for receiving an encoder signal from an encoder coupled to the drive shaft of the drive unit and an output for outputting an error signal, in particular a switch-off signal for stopping the drive unit, the first controller being configured to determine an acceleration value from the encoder signal when a brake coupled to the drive shaft acts on the drive shaft of the drive unit with its maximum possible braking force, and to lock the drive unit in a safety-related manner if the determined value exceeds a limit value stored in the first controller.
[0014] According to further aspects of the present disclosure, this objective is further achieved by a method for monitoring the braking force of a drive and safety-related locking, in particular, switching off, of a drive for a technical system comprising two mechanical parts that are relatively movable and move toward each other by a drive at a predetermined operating interval, the method being: • At the input of the first controller, an encoder signal is received from an encoder coupled to the drive shaft of the drive device. Based on the processing of the encoder signal by the first controller, the output of the first controller includes outputting an error signal, in particular a switch-off signal for stopping the drive unit. The first controller determines the acceleration value from the encoder signal when the brake coupled to the drive shaft acts on the drive shaft of the drive unit with its maximum possible braking force, and locks the drive unit in a safety-related manner if the determined value exceeds a limit value stored in the controller.
[0015] Therefore, the idea of this disclosure is to perform safety-related locking of the drive unit of a technical system such as a press or punching machine by monitoring the actual braking force of the brakes (braking force monitoring). This means that the threshold for locking the drive unit and / or machine is related to a value or function representing the actual braking force, rather than to the overrun angle.
[0016] The controller can determine the actual braking force by receiving position values (angular position) from an encoder coupled to the drive shaft of the drive unit, determining the speed (velocity) of the drive shaft from the received position values via the first derivative, and determining its acceleration via the second derivative. Negative acceleration means that the drive shaft is decelerating (i.e., the brakes are being applied).
[0017] Assuming that the brake acting on the drive shaft acts with the maximum available braking force within a defined period, the determined (negative) acceleration directly corresponds to the braking force of the brake. In a mechanical press, since the braking force is determined solely by the force of the brake's spring assembly, braking is usually always performed with the maximum possible braking force. In other words, in the case of a mechanical press, the defined period during which the relevant brake acts with maximum braking force corresponds to the period during which the negative acceleration of the drive shaft is measured. Therefore, when the speed of a mechanical press is plotted against time, the braking process is represented as a downward ramp where the negative slope corresponds to the actual braking force of the brake. Based on the actual braking force value, if the actual braking force falls below a defined value, a safety-related lock of the drive unit can be triggered. Therefore, the trigger for the safety-related lock of the drive unit can be the minimum braking ramp that is monitored and triggers the lock as needed, rather than the overrun angle.
[0018] Therefore, the safety-related locks relating to this disclosure are directly related to the actual braking force and not to values derived indirectly from the braking force, such as the overrun angle, which may depend on a variety of other factors. For example, the braking force determined in accordance with this disclosure is independent of the current air pressure, because the current air pressure is relevant only when the brakes are released (when the brake cylinders are bled), and therefore affects the overrun but not the actual braking force.
[0019] In the proposed actual braking force monitoring, the monitoring is not performed for a specific location such as OTP, but is based only on the braking process, so it is irrelevant at which point in the operation interval the brake is applied. Therefore, even when the machine is operating in another operating mode that requires stopping at a location other than OTP, for example, during machine setup or maintenance, the monitoring is possible. According to the proposed monitoring, when the braking force falls below a specific threshold, it is also possible to trigger a safety-related lock in these operating modes. This effectively protects the operator from the possible consequences caused by the decrease in braking force even in these special operating modes.
[0020] Therefore, the proposed device for the safety-related lock of the drive device enables the monitoring of the braking performance (braking force monitoring) of the drive device as required by the standard, and at the same time is more flexible and versatile than other monitoring procedures based only on overrunning monitoring. Thus, the above-mentioned object is completely achieved.
[0021] In a further improved form, the controller can be configured to determine the difference between the determined value of the acceleration and the stored limit value and output this difference.
[0022] According to this improved form, in addition to the locking mechanism, it is possible to set the wear control of the brake. For example, it is conceivable to store a further threshold value and compare it with the determined difference in order to detect a decrease in the braking force and, in a timely manner, maintain or replace the brake. This device determines the actual braking force rather than a value derived from the actual braking force, so wear is indicated only when the brake no longer actually has sufficient force. This makes the maintenance and repair of the brake more effective and efficient.
[0023] In a further improved form, the first controller can be configured to determine one or more further parameters of the technical system and / or the first controller in order to determine the total stopping time.
[0024] According to this improved form, the controller determines at least one further parameter in order to determine the total stop time. The total stop time is the time required from the stop signal transmission until the stop target part actually stops. The total stop time is particularly relevant for the sizing of the electrical detection protection equipment. The braking force determined by the device is a factor that can affect the total stop time. Other parameters that can also be recorded according to a preferred design are, for example, the signal execution time of the stop signal or the switching time of the brake valve. By individually recording the parameters related to the total stop time, the total stop time can be determined more accurately, and a more differentiated reference can be made about the conceivable reasons for the increase in the total stop time.
[0025] In a further improved form, the device comprises a second controller that can be coupled to the first controller, and one or more fault detection means can be provided to carry out fault detection measures.
[0026] Therefore, according to this improved configuration, the device can have two controllers. The first controller can not only collect and evaluate values from encoders related to braking force monitoring, but can also control the entire process. The monitoring function performed by the first controller can be guaranteed by the second controller. The advantage of dividing the work between the two controllers is that each controller can be configured for its own work. The first controller can be a high-speed standard controller (ST controller), which can, for example, record one angular position from the encoder every millisecond and process it accordingly. The second controller can be a fail-safe (FS) controller, which operates at a slower processing speed than the first controller but can have fail-safe functions that enable fail-safe processing. The fail-safe functions of the second controller can include multi-channel redundant data processing and periodic self-tests or similar. The configuration with two controllers allows for effective and reliable monitoring of braking force even in ultra-high-speed systems with very short operating intervals. It is also understood that the two controllers can be configured as a single integrated controller combined in one housing, with different tasks performed by functionally separate units, where at least one first unit corresponding to the first controller is a standard unit, and the second unit corresponding to the second controller is a fail-safe (FS) unit.
[0027] The fault detection means of the second (FS) controller may include at least one cycle test of the limit value detection means of the first controller.
[0028] Failures in the limit detection mechanism, specifically failures when comparing a determined value with a stored value and performing a response based on this, must be detected in a reliable and fail-safe manner. This can be achieved by periodically testing the limit detection mechanism.
[0029] In a further improved version, the second controller may be configured to periodically transmit a signal to the first controller, thereby causing the first controller to modify the stored limit value using a defined calculation rule so that the first controller determines that the limit value has been exceeded.
[0030] Therefore, according to this improved configuration, the second controller performs a test of the limit detection means of the first controller by sending a test signal to the first controller at predetermined intervals and observing the first controller's response to the test signal. If there is no response, for example, if a predetermined output of the first controller is not shut off, the second controller can initiate a safety-related lock of the technical system on behalf of the first controller. The first controller can be configured to perform a predetermined response based on the test signal by shifting the stored limit by calculation rather than actually replacing it after receiving the test signal, so that it is interpreted as exceeding a stored limit, and thus, for example, the output of the first controller switches. The tests are performed periodically, so that the interval between individual tests (test interval) can be greater than the interval between two operations of mechanical parts moving relative to each other (operation interval). According to this configuration, the first controller can be effectively tested by the second controller to meet the overall requirements of a high protection category, such as the safety requirements of performance level c category 2 of the EN ISO 13849-1 standard.
[0031] In a preferred improved form, the second controller may have a multi-channel redundant design, for example, with two mutually redundant processing units providing two independent processing channels.
[0032] Therefore, according to this improved configuration, the second controller is a safety controller that includes means for ensuring fail-safe recording, processing, and output of control / process data. Such a controller enables simple and effective fail-safe testing.
[0033] In a further improved form, the first controller can be configured to detect at least one angular position of the drive shaft as an encoder signal at intervals of less than a millisecond.
[0034] According to this improved configuration, the first controller can be a high-speed controller, such as a single-channel controller, equipped with a processing unit capable of recording encoder data (i.e., position data) every millisecond or less. High-speed recording and processing of position data within a specified time range ensures that speed and acceleration are reliably determined with sufficient accuracy, even in ultra-high-speed systems with very short operating intervals. Therefore, this configuration makes it possible to monitor braking forces even in ultra-high-speed systems such as eccentric presses.
[0035] It is understood that the features described above and those described below can be used not only in the combinations shown in each case, but also in other combinations or individually, without departing from the scope of the present invention.
[0036] Examples of embodiments of the present invention are shown in the drawings and described in more detail below. [Brief explanation of the drawing]
[0037] [Figure 1] Figure 1 is a schematic diagram of an example of a braking force monitoring device. [Figure 2] Figure 2 shows the speed-time curve of the braking process. [Figure 3] Figure 3 is a flowchart of one embodiment of the braking force monitoring method according to this disclosure. [Modes for carrying out the invention]
[0038] Figure 1 shows a schematic diagram of one embodiment of the braking force monitoring device according to this disclosure. Here, the entire device is denoted by reference numeral 10.
[0039] Device 10 is coupled to the technical system 12 to monitor the braking force of the brake 14 of the technical system 12. The technical system 12 can be, for example, a forming machine such as a press, and a first mechanical part 16 and a second mechanical part 18 move toward each other to deform a workpiece 20 when the mechanical parts 16 and 18 come into contact. At least one of the mechanical parts 16 and 18 is actuated for this purpose by a drive unit 22. The drive unit 22 can be, for example, an electric motor that drives a drive shaft 24 via a clutch 26 and a flywheel 28. The driven mechanical part (here, the first mechanical part 16) is driven by the rotating drive shaft 24 toward the second mechanical part 18. vertical The drive shaft 24 can be coupled to move in a certain direction. For this purpose, the drive shaft 24 can be a crankshaft 30 or an eccentric shaft, or can be coupled to such a shaft, depending on the design of the technical system 12.
[0040] Therefore, the rotational motion 32 of the drive shaft 24 is vertical This directly relates to the directional motion 34 and, therefore, directly to the operating interval of the technical system 12. The operating interval represents the cycle in which the first mechanical component 16 moves from its initial position toward the second mechanical component 18, engages with the second mechanical component 18, and returns to its initial position. The initial position is usually the position where the first mechanical component 16 is furthest from the second mechanical component 18, and is also called the top dead center. The top dead center can also define the 0° position of the drive shaft 24.
[0041] The drive shaft 24 is also coupled to a brake 14. The brake 14 can decelerate and stop the drive shaft 24. The brake 14 and clutch 26 may be a brake-clutch combination, but the present invention is not limited to such a combination. In various embodiments, the brake 14 may be configured to stop the drive shaft 24 once per operating interval, for example, at top dead center. In this context, “stop” means decelerating the speed of the drive shaft 24 to zero.
[0042] The brake 14 may have a spring assembly that compresses the brake lining (friction pad) when the brake is applied, thereby slowing down the movement of the drive shaft 24 through the resulting friction. After such a brake 14 is applied, deceleration is performed with maximum braking force. The brake 14 is not limited to this particular configuration, and variations are possible. However, for the purpose of braking force monitoring according to this disclosure, it is important that the brake 14 operates with maximum braking force during a defined monitoring period.
[0043] The device 10 has at least one first controller 36 coupled to the technical system 12. In this embodiment, the first controller 36 is hardware and has a modular design comprising an input module 38 having an input 40, an output module 42 having an output 44, and a processing module 46 having a processing unit 48. As shown here, the modules can be assembled into a single hardware unit that can be installed in a control cabinet. However, the individual modules of the controller 36 can also be distributed to sites near the technical system 12 and connected via a communication channel. In addition to the monitoring described below, the first controller 36 may perform other control tasks of the technical system 12, but these will not be described here for simplicity.
[0044] In the embodiment shown herein, the first controller 36 is primarily used to monitor the braking force of the brake 14. The input 40 of the input module 38 is connected to an encoder 50 located on the drive shaft 24, which monitors the rotational motion 32 of the drive shaft 24. The encoder 50 may be a rotary encoder that provides position data of the drive shaft 24 in the form of angular position and supplies it to the first controller 36 via the input 40. For example, the encoder 50 may determine and provide the angular position every millisecond. The first controller 36 continuously reads the angular position values, and the processing unit 48 calculates the velocity (first derivative) and acceleration (second derivative) of the drive shaft 24 from the provided angular position values.
[0045] As will be explained in more detail below, the processing unit 48 estimates the current actual braking force of the brake 14 from the determined acceleration. If the determined braking force falls below a defined threshold, the processing unit 48 generates an error signal and can switch output 44 accordingly. To stop the drive unit when an error signal is present, output 44 can be coupled to the drive unit 22. For example, output 44 may be connected to a contactor 52 located at the power supply 54 of the drive unit 22, and the drive unit 22 receives power from the power supply 54 only when the contactor 52 is turned on by the signal from output 44. Thus, the drive unit 22 can be stopped via output 44 and contactor 52, ensuring that the drive unit 22 is not restarted. The drive unit 22 is locked in a fail-safe manner when the power to the contactor 52 is cut off and it is turned off. However, it is understood that safety-related locks can be achieved in various other ways.
[0046] The processing unit 48 estimates the current braking force of the brake 14 by observing the determined acceleration, for example, its progression over time, and continuously compares the determined acceleration with a limit value. For example, the processing unit 48 can observe the acceleration (braking ramp) over a defined period, determine the average value of the acceleration over this period, and compare this value with a stored limit value for the minimum allowable braking ramp (gradient). The defined period is the period during which the brake 14 decelerates the drive shaft 24 with maximum braking force. In various embodiments, the defined period is the period during which negative acceleration of the drive shaft can be measured. In other embodiments, the defined period may be determined by another method and may be actively signaled to the processing unit 48 by another device. When the processing unit 48 detects a decrease in braking force, it triggers the safety-related lock of the drive unit 22 described above.
[0047] Figure 2 shows an example of a speed-time curve for the braking process of the technical system 12. Time t is plotted on the horizontal axis 56, and angular velocity ω is plotted on the vertical axis 58. In the figure, the first and second braking operations are shown by the first and second curves, respectively. The first curve 60 shows the braking process at a fast first output speed ω0, and the second curve 62 shows the braking process at a second output speed ω1 that is slower than the first output speed ω0.
[0048] The speeds ω0 and ω1 of the drive shaft 24 are initially constant. At time t0, as soon as a signal to stop the press machine is supplied to the technical system 12, the technical system 12 turns off the valve of the brake 14 at time t1 with a signal propagation delay. Once the valve engages the brake, the actual braking process begins at time t2. In the case of the first initial speed ω0, the technical system 12 turns off its operation at time t 3,0 It stops at time t. In the case of the second initial velocity ω1, the technical system 12 operates over time t 3,1 It stops at time t2 to time t 3,0 or t 3,1 The curves of the actual braking process up to a certain point represent the brake ramps ε0 and ε1, both of which occur due to the application of the brake 14. When using the same brake 14, the respective gradients of the brake ramps ε0 and ε1 are the same regardless of the initial speed. At different speeds, the actual stopping time t 3,0 and t 3,1 Only the following is different.
[0049] Assuming that the brake 14 acts with maximum braking force during the braking process, the gradients of the brake ramps ε0 and ε1 directly correspond to the actual braking force of the brake 14, and thus the braking force is the same in both cases, regardless of the initial velocity.
[0050] Additionally, the dashed lines indicate two brake ramps ε with a gentler slope. 0,k and ε 1,kare shown, and in each case these correspond to the critical braking force. If the measured gradient of the braking ramp falls below the gradient of the critical braking ramp, the technical system 12 must be locked until the brake 14 is serviced or replaced and the brake shows a braking ramp with a steeper gradient again. As a result, the value of the gradient of the minimum braking ramp can be used as a safety limit and compared with the actual gradient of the measured braking ramp to trigger a safety-related lock. Thereby, the safety-related lock is directly based on the actual braking force of the brake 14.
[0051] The gradients of the two critical braking ramps ε 0,k and ε 1,k are the same, so the safety-related lock is carried out in both cases when the braking performance falls below a defined level. Thus, even when operating the technical system 12 at a reduced output speed ω1, a safety-related lock is carried out when the braking force decreases to a certain extent, even if the stopping time (t 4,1 ) at the low output speed ω1 has not yet exceeded the critical value, as it does at the high output speed ω0 (t 4,0 ). Therefore, the safety-related lock is not a value derived from the actual braking force, but is precisely associated with the actual braking force and can cause different switching-off operations.
[0052] The monitoring of the braking force according to the proposed procedure is a limit value detection, similar to known overrunning monitoring systems, and the safety limit value is based on the minimum braking ramp rather than the overrunning angle. Since fail-safe limit value detection cannot be directly achieved by redundant processing of the angular position read at a very high angular velocity, a second controller 64 (FIG. 1) can be provided, and the second controller 64 is configured to monitor the limit value detection means of the first controller 36 in a fail-safe manner. For example, the second controller 64 may perform a cycle test of the limit value detection means of the first controller 36.
[0053] The second controller 64 can be a safety controller, which can provide control and / or recording, evaluation, and output of process data in a fail-safe manner. The second controller 64 may have two channels with fail-safe devices enabling redundant processing on two separate processing channels, and a test device to continuously synchronize the two channels. The second controller 64 may perform special tests to verify the functionality of the limit detection means of the first controller 36.
[0054] For such testing, the second controller 64 may be connected to the first controller 36 via an input / output module 66, and the second controller 64 may send a test signal to the first controller 36 causing the first controller 36 to "operate" the limit detection means in a predetermined manner. For example, when a test signal is applied to the first controller 36, the first controller 36 can calculate and shift the stored limit value, and as a result, the first controller 36 interprets this as exceeding the stored limit value and acts on the output in response. The second controller 64 is connected to this output and can verify whether the first controller 36 responds as expected. If the test fails, the second controller 64 can act on the technical system 12 via its own output module 68 on behalf of the first controller 36. In one embodiment, for this purpose, the second controller 64 may use the same device (such as a contactor 52) as the first controller 36.
[0055] Having two separate controllers 36 and 64 has the advantage that each controller can be configured for its respective task. For example, the first controller 36 may have a high-speed processing unit 48 that can accurately determine values essential for monitoring even when the technical system 12 is high-speed. The second controller 64 can then be configured to perform fail-safe tests, and for this purpose, slower processing units 70A and 70B can be utilized, enabling parallel and redundant execution and evaluation of the tests. In this way, the high-speed standard controller does not need to supplement the safety-related devices, and the existing safety controller does not need to have a higher-speed processing unit.
[0056] In further embodiments, the first controller 36 and / or the second controller 64 (if present) can determine and monitor further parameters of the technical system 12. Other parameters may be, for example, the signal execution time of the stop signal (the time interval between t0 and t1 in Figure 2) or the switching time of the brake valve (the time interval between t1 and t2 in Figure 2). Based on these values, it is possible to determine the total stop time, which can then be used for further safety-related considerations.
[0057] The first controller 36 may also determine the difference between a stored limit value and an actual measurement and make it available for further processing. Based on this difference, a wear indicator can be implemented, for example, in the form of a display on a screen or as a message to a higher-level control system. The wear indicator can be used to service or replace the brake 14 before the braking force of the brake 14 falls below a safety-critical level, which could lead to an unexpected shutdown of the technical system 12.
[0058] The proposed device 10, especially when designed with two controllers, can be used to independently achieve standard-compliant braking force monitoring, even in very high safety categories. However, the proposed device 10 could also be used to complement previous monitoring systems based on overrun monitoring to improve overall monitoring.
[0059] Finally, Figure 3 shows a flowchart of one embodiment of the braking force monitoring method according to the present disclosure. This method is shown here in its entirety by reference numeral 100 and can be performed on the apparatus 10 described above.
[0060] This method begins with providing a first controller that has an input for receiving encoder signals from an encoder coupled to the drive shaft of the drive unit, and an output for providing error signals such as a switch-off signal for stopping the drive unit (102).
[0061] This is followed by periodic monitoring of the limit value. To do so, the first controller receives an encoder signal, preferably an angular position, from the encoder at intervals of less than a millisecond (104).
[0062] The first controller determines the acceleration value of the drive shaft 24 from the continuously recorded angular position and derives the current braking force value from there (106). As described above, the determined acceleration may directly represent the current braking force value.
[0063] The first controller then compares the current braking force value with the minimum braking force limit value stored in the first controller (108). If the determined braking force is greater than the minimum braking force, the first controller indicates this, for example, by an enable signal (110), and continues comparing the determined braking force with the minimum braking force (112). If the measured braking force is less than the minimum braking force, the first controller triggers a safety-related lock of the technical system 12 (114).
[0064] The first controller may trigger the respective desired response by outputting an enable signal in step 110 and prohibiting its provision in step 112.
[0065] In a preferred embodiment, the continuous testing of the limit detection means in step 108 can be performed in a parallel process. For this purpose, the second controller can send a test signal to the first controller (116), and the limit detection means (108) is then "operated" in a predetermined manner so that the first controller interprets the limit as being exceeded. The second controller detects the first controller's response to the test signal (118) and compares it to an expectation (120). If the first controller operates as expected, the second controller pauses and resumes testing after a predetermined test interval has elapsed (122). However, if the response deviates from the expected response, the second controller triggers a safety-related lock of the technical system 12 on behalf of the first controller (114).
[0066] The description of the method is merely illustrative, and it should be understood that further steps may be added before, during, or after the method described above. It should also be noted that elements of the disclosed apparatus may be realized by corresponding hardware and / or software elements, such as appropriate circuits. A circuit is a structural arrangement of electronic components, including conventional circuit elements, integrated circuits (including application-specific integrated circuits, standard integrated circuits, application-specific standard products, and field-programmable gate arrays). Furthermore, a circuit may include a central processing unit, graphics processing unit, and microprocessor programmed or configured according to software code. While the circuit includes the aforementioned hardware that runs the software, the circuit is not purely software.
[0067] The above example should be understood as merely an example that does not limit the scope of protection. The scope of protection is defined solely by the following claims.
Claims
1. A device (10) for monitoring the braking force of a drive unit (22) of a technical system (12) comprising two mechanical parts (16, 18) that are relatively movable and move toward each other by a drive unit (22) at a predetermined operating interval, The drive unit (22) includes a first controller (36) having an input (40) for receiving an encoder signal from an encoder (50) coupled to the drive shaft (24), and an output (44) for outputting an error signal. The apparatus is characterized in that the first controller (36) is configured to determine from the encoder signal the value of acceleration as the actual braking force of the brake (14) when the brake (14) coupled to the drive shaft (24) acts on the drive shaft (24) of the drive device (22) with the maximum possible braking force, and to lock the drive device (22) if the determined value of acceleration falls below a threshold for the actual braking force.
2. The apparatus according to claim 1, wherein the first controller (36) is further configured to determine the difference between the determined value of the acceleration and a limit value stored in the first controller (36), and to output this difference.
3. The apparatus according to claim 1 or 2, wherein the first controller (36) is configured to determine one or more further parameters of at least one of the technical system (12) and the first controller (36) in order to determine the total downtime.
4. The apparatus according to claim 3, wherein one of the further parameters is the signal propagation time of the stop signal or the switching time of the brake valve.
5. The apparatus according to claim 1, further comprising a second controller (64) that can be coupled to the first controller (36), and providing one or more fault detection means.
6. The apparatus according to claim 5, wherein the one or more fault detection means includes at least one cycle test of the limit value detection means of the first controller (36).
7. The apparatus according to claim 6, wherein the second controller (64) is configured to periodically transmit a signal to the first controller (36), so that the first controller (36) modifies the threshold for the actual braking force according to a defined calculation rule, so that the first controller (36) determines that the value of the determined acceleration has fallen below the threshold for the actual braking force.
8. The apparatus according to claim 5, wherein the second controller (64) has a multi-channel redundant design.
9. The apparatus according to claim 8, wherein the second controller (64) comprises two mutually redundant processing units (70A, 70B), each having two independent processing channels.
10. The apparatus according to claim 1, wherein the first controller (36) is configured to detect at least one angular position of the drive shaft (24) as an encoder signal at intervals of milliseconds or less.
11. The apparatus according to claim 1, wherein the first controller (36) is a standard controller that processes the encoder signal in a single-channel manner.
12. The apparatus according to claim 1, wherein the error signal is a switch-off signal for stopping the drive unit (22).
13. A method (100) for monitoring the braking force of a drive unit (22) of a technical system (12) comprising two mechanical parts (16, 18) that are relatively movable and move toward each other by a drive unit (22) at a predetermined operating interval, wherein the method is At the input (38) of the first controller (36), an encoder signal is received from the encoder (50) coupled to the drive shaft (24) of the drive device (22). Based on the processing of the encoder signal by the first controller (36), the output (44) of the first controller (36) outputs an error signal. The first controller (36) determines, based on the encoder signal, the value of the acceleration as the actual braking force of the brake (14) when the brake (14) coupled to the drive shaft (24) acts on the drive shaft (24) of the drive device (22) with the maximum possible braking force, and locks the drive device (22) if the value falls below a threshold for the actual braking force.
14. The method according to claim 13, wherein the error signal is a switch-off signal for stopping the drive device (22).
Citation Information
Patent Citations
Device for detecting brake abnormality for press machine
JP1995290296A
Method and control device for monitoring the movement of an elevator cage
JP2015508367A
Press device, press device abnormality detection method and abnormality detection program
JP2020185586A
Safety module for a safe drive control of a drive system in an automation system, drive system and automation system
US20220388541A1