Emergency stop device
The emergency stop device with a three-level safety concept selectively shuts down individual mechanisms, ensuring data retrieval and rapid restarts by maintaining energy to critical components, addressing the limitations of conventional systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- ROBERT BOSCH GMBH
- Filing Date
- 2021-07-07
- Publication Date
- 2026-06-02
AI Technical Summary
Conventional emergency stop devices for systems with multiple mechanisms controlled by a single control device often result in the complete shutdown of all electric mechanisms upon activation, preventing data retrieval and hindering rapid restarts, as they lack selective control over individual mechanisms.
An emergency stop device with a three-level safety concept based on ISO standard 26262 allows selective shutdown of individual mechanisms by utilizing a first level for controlled shutdown, a second level for error correction, and a third level for fixed shutdown, ensuring essential mechanisms remain energized for data retrieval and rapid restart.
Enables selective shutdown of specific mechanisms during emergencies, allowing data retrieval and rapid system restarts by maintaining energy supply to critical components, thereby enhancing system safety and efficiency.
Smart Images

Figure 0007869189000001 
Figure 0007869189000002
Abstract
Description
Technical Field
[0001] The present invention relates to an emergency stop device for a system having a plurality of mechanisms controlled by one common control device.
Background Art
[0002] The general safety integrity of an electronic control device, that is, the sufficient independence of safety-related measures, can be ensured by a three-level safety concept based on ISO standard 26262. In the three-level safety concept, the first level functions as a functional level, the second level functions as a safety level that monitors the first level, and the third level guarantees the integrity of the second level. Such a control device can be used for controlling various actuators, for example, vehicle engines such as marine engines, engines of agricultural machinery, or engines of machine tools. In this regard, the electrical energy supply of the engine is performed via the control device.
[0003] An emergency stop switch for interrupting the electrical energy supply of the control device is provided so that such an engine can be quickly turned off in case of danger or to avoid danger. Thereby, the electrical energy supply of the engine, and thus also of all electric mechanisms of the engine, is immediately interrupted.
Summary of the Invention
Means for Solving the Problems
[0004] An emergency stop device for a system with multiple mechanisms controlled by a single common control device can be used, in particular, to control and shut down engines such as marine engines. When such a marine engine is stopped by a conventional emergency stop switch, which cuts off the electrical energy supply to the engine's control device, all the electric mechanisms of the engine are immediately turned off. This can cause, for example, the engine's throttle valve to return to its initial position, potentially preventing the engine from being restarted. Furthermore, when electrical energy is no longer supplied to the control device, it becomes impossible to read data from individual mechanisms. Therefore, this emergency stop device is adapted to turn off only the selected mechanisms, without turning off the control device. This allows for the reading of mechanism data even after the emergency stop device has been activated, thus enabling quick recognition of the reason why an emergency stop was necessary and, in some cases, the cause to be eliminated. If individual mechanisms continue to receive electrical energy in the emergency stop state, a rapid restart of the system is also possible.
[0005] Preferably, the control device is a control device having a three-level safety concept, in particular a three-level safety concept based on ISO standard 26262. This existing safety concept can be used to implement a selection function at the first and second levels, respectively, which is adapted to select a mechanism in response to the activation of an emergency stop device, depending on the operating state of the mechanism. Depending on the operating state of the mechanism, it can be determined which mechanism may be disconnected from the energy supply and which must continue to receive electrical energy. If there is a malfunction at the first level during selection, this function can also be taken over by the second level.
[0006] The first level, as a functional level, has the role of controlling the mechanism and supplying electrical energy, and therefore has a control connection to the mechanism. This control connection is preferably also adapted to allow the selection of the mechanism to be turned off. In this way, while the selection of the mechanism is provided at the first level, that is, while this selection is provided by the first level itself or by the second level to the first level in the event of a failure of selection at the first level, individual mechanisms can be selectively turned off without providing any additional electrical or data connections for this purpose.
[0007] Furthermore, it is preferable that the second level is connected to a module of the third level, which has at least one off-connection to the mechanism, and that this off-connection is adapted to turn off the selection of the mechanism. This off-connection may be used when it is not possible to transmit an off-signal via the control connection. This off-connection may also be used when the first level exhibits such severe malfunction that it is no longer able to perform a selection of the mechanism on its own, nor can it receive a selection from the second level. In this case, after a selection is generated at the second level, the second level can directly turn off via the off-connection. In this regard, the use of a module of the third level is preferable because the three-level safety concept provides a Hardware-Error-Management-Module (EMM) at the third level. It is advantageous that this module can be used for turning off because it already has hardware-oriented functions implemented in it.
[0008] Furthermore, it is preferable that a fixed selection of mechanisms is stored at a third level. This fixed selection of mechanisms can be used as a last-reverse option at the third level in case the first two levels are unable to select a mechanism, for example, because data about the operating state of the mechanism can no longer be received, and this selection includes mechanisms that must be turned off at all times to avoid danger. Using a fixed selection without evaluating the operating state is certainly not as advantageous as turning off based on a selection that may have been made at the first or second level, but it is known to be hazardless and still allows for the continued energization of mechanisms essential for restarting the system, as well as maintaining the electrical energy supply to control equipment.
[0009] In this regard, it is particularly preferable that the fixed-setting selection of the mechanism is stored in a third-level monitoring module. In the three-level safety concept, the monitoring module is located in a hardware unit isolated from other control equipment by hardware and software mechanisms, and is therefore particularly well protected from interference that may affect other parts of the control equipment.
[0010] Preferably, the third level has at least one off-connection to the mechanism, which is adapted to turn off the selection of the mechanism stored at the third level. This independent off-connection, which does not go through the first and second levels, also allows for special certainty of emergency stop in hazardous situations.
[0011] To minimize the number of additional electrical or data connections required for the emergency stop device, it is even more preferable that the third level off connection is partially connected to the second level off connection via a common line.
[0012] One exemplary embodiment of the present invention is shown in the drawings and will be described in more detail below. [Brief explanation of the drawing]
[0013] [Figure 1] This is a diagram showing a system based on current technology that includes an emergency stop device. [Figure 2] This figure shows one exemplary embodiment of an emergency stop device according to the present invention. [Modes for carrying out the invention]
[0014] Figure 1 shows a conventional emergency stop device 10 in the form of an emergency stop switch provided to turn off system 20. System 20 has a control device 31 with a hardware module 32. The control device 31 has a safety concept with three levels 40, 50, and 60 based on ISO standard 26262. The electrical energy supply 33 of the control device 31 has a cutoff switch 34. Activation of the emergency stop device 10 opens this cutoff switch 34, thereby cutting off the supply of electrical energy to the control device 31. In this exemplary embodiment, the control device 31 controls a diesel engine that drives a ship. This diesel engine has mechanisms 71-74 in the form of an allocation unit 71 for the diesel engine's high-pressure pump, a throttle valve 72, an air valve 73 positioned before the throttle valve, and an injection driver 74. The functional module 41 at the first level 40 controls these mechanisms 71-74 via a control line 81. The control line 81 is illustrated in Figure 1 as a single connection for simplicity. However, in reality, four control lines 81 are provided, and therefore each of the mechanisms 71-74 is connected to a separate control line 81. The control lines 81 also supply electrical energy to the mechanisms 71-74. Therefore, the activation of the emergency stop device 10 results in the shutdown of not only the control equipment 31 and its hardware module 32, but also all of the mechanisms 71-74.
[0015] In the 3-level safety concept, a safety module 51 is located at the second level 50, and the safety module 51 monitors the function module 41. For this purpose, the safety module 51 receives data from the function module 41 and sends data back to the function module 41. At the third level 60, a memory test module 61 is located to perform memory tests of the second level 50 and the third level 60. A configuration test module 62 monitors the hardware configuration of the second level 50 and the third level 60. A hardware test module 63 monitors additional hardware modules of the control device 31. Data from the memory test module 61, the configuration test module 62, and the hardware test module 63 is collected by a PFC module (Program Flow Check). The PFC module also exchanges data with the safety module 51 at the second level 50. Although structurally isolated from the other control devices 31, the monitoring module 65 within the hardware module 32, which constitutes part of the third level 60, can send queries to the memory test module 61, the configuration test module 62, and the hardware test module 63, as well as to the safety module 51 of the second level 50. After the responses from these modules 51, 61, 62, and 63 are collected by the PFC module 64, the responses can be passed to the monitoring module 65, thereby ensuring the integrity of the second level 50. The third level also includes safety mechanisms 66 and an EMM (Hardware-Error-Management-Module) 67 for hardware memory testing in the form of ECC (Error-Code-Correction).
[0016] An emergency stop device 10 based on one exemplary embodiment of the present invention is shown in Figure 2. In this exemplary embodiment, the cutoff switch 34 is eliminated. Instead, the emergency stop device 10 transmits an emergency stop request via two redundant lines to a first level 40 function module 41 and a second level 50 safety module 51. The function module 41 determines, based on the operating status of mechanisms 71-74, which mechanisms 71-74 must be turned off and which can continue to operate without danger. Based on this selection, The selected mechanism It is then turned off via control connection 81.
[0017] The safety module 51 also receives the emergency stop request and, in some cases, reproduces the selection of mechanisms 71-74 that are running within the function module 41 and corrects any selection errors that may have occurred at the first level 40. If error correction or transmission of an off request via the control connection 81 fails, the safety module 51 instead forwards the off request selected by the safety module 51 to the third level 60 EMM 67 via the second level 50 off module 52. The EMM 67 is connected to the outputs of control lines 81-84 via the off connection 82, which is a wired connection not provided in conventional systems of the control equipment 31, and can turn off mechanisms 71-74 based on the off request.
[0018] If the execution of an emergency stop request fails at either the first level 40 or the second level 50, this is recognized by the monitoring module 65. The monitoring module 65 does not attempt to independently select which mechanisms 71-74 should be turned off. Instead, the monitoring module 65 accesses a fixed selection of mechanisms 71-74 stored in the monitoring module 65, which presents in the form of a list which mechanisms 71-74 should be turned off when all other off paths fail. In this exemplary embodiment, this list specifies, for example, only the turning off of the injection driver 74. This off request is sent to mechanisms 71-74 via an additional off connection 83. The off connection 83 is implemented as an additional wired connection that originates in the hardware module 32 and is integrated into an off connection 82 in the control device 31.
[0019] The control device 31 and its hardware module 32 remain active even after the emergency stop device 10 is activated. The control device 31 and its hardware module 32 continue to provide data about mechanisms 71-74 and enable a rapid restart of the entire system 20 as soon as the emergency stop request is withdrawn.
Claims
1. In a system (20) having an emergency stop device (10) and a plurality of mechanisms (71-74) controlled by a single common control device (31) connected to the emergency stop device (10), The control device (31) has a safety concept with three levels: a first level (40), a second level (50), and a third level (60). The first level (40) and the second level (50) are equipped with a selection function that selects one of the plurality of mechanisms (71 to 74) according to the operating state of the plurality of mechanisms (71 to 74). The emergency stop device (10) transmits an emergency stop request to the first level (40) and the second level (50) in order to turn off the selected mechanisms (71-74). A system characterized by (20).
2. The system (20) according to claim 1, characterized in that the first level (40) has a control connection (81) to the mechanisms (71-74), the control connection (81) is adapted to control the mechanisms (71-74) and to turn off the selected mechanisms (71-74).
3. The system (20) according to claim 1 or 2, characterized in that the second level (50) is connected to a module of the third level (60), the module has at least one off-connection (82) to the mechanisms (71-74), and the off-connection (82) is adapted to turn off the selected mechanisms (71-74).
4. The system (20) according to any one of claims 1 to 3, characterized in that information on which mechanisms (71 to 74) should be turned off is stored at the third level (60).
5. The system (20) according to claim 4, wherein the third level (60) has at least one off connection (83) to the mechanisms (71-74), and the off connection (83) is adapted to information stored in the third level (60) of which mechanisms (71-74) should be turned off.