Module with embedded safety function to decrease safety reaction time
By embedding an internal evaluation component in I/O modules to locally manage safety functions, the safety reaction time in industrial automation systems is reduced, addressing the challenge of prolonged safety transitions in existing systems.
Patent Information
- Application Number
- PCT/US2024/017240
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-26
- Publication Date
- 2025-09-04
AI Technical Summary
Existing industrial automation systems lack the capability to rapidly transition to a safe state in response to hazardous conditions due to the centralized execution of safety functions, leading to prolonged safety reaction times.
Integrate an internal evaluation component with an embedded safety function within I/O modules, allowing them to locally evaluate input signals and override output states to a safe state, thereby reducing the safety reaction time.
Significantly decreases the overall safety reaction time by enabling I/O modules to quickly transition to a safe state without relying on central controller processing, enhancing safety and efficiency in industrial automation systems.
Smart Images

Figure US2024017240_04092025_PF_FP_ABST
Abstract
Description
[0001] MODULE WITH EMBEDDED SAFETY FUNCTION TO DECREASE SAFETY REACTION
[0002] TIME
[0003] Technical Field
[0004] Aspects of the present disclosure generally relate to industrial and other automation systems, and more particularly to a module with an embedded safety function to decrease a safety reaction time in connection with an automation system including input / output (I / O) modules.
[0005] Background Art
[0006] Industrial automation systems are used in different industrial fields to automatically perform a plurality of tasks, for example in a manufacturing process or an assembly line of a production facility. Industrial automation systems comprise a plurality of interconnected components, such as for example sensors, actuators, and control devices. The control devices can be for example programmable logic controllers for controlling and monitoring process parameters.
[0007] A programmable logic controller (PLC) is used to monitor input signals from a variety of input points (input sensors) which report events and conditions occurring in a controlled process. A control program stored in a memory within the PLC is configured to instruct the PLC what actions to take upon encountering specific input signals or conditions. In response to these input signals, the PLC derives and generates output signals which are transmitted via PLC output points to various output devices, such as actuators and relays, to control the process.
[0008] The input points and output points referred to above are typically associated with input modules and output modules, respectively. Input modules and output modules are collectively referred to as I / O modules herein. Those skilled in the art may also refer to I / O modules as I / O cards or I / O boards. The I / O modules are typically pluggable into respective slots located on a backplane board of the PLC or provided as distributed I / O connected through a network interface.
[0009] Standard I / O modules do not perform safety functions. Safety functions are executed by designated safety modules or safety relays configured to bring a whole system to a safe state.
[0010] In contrast, fail-safe I / O modules perform safety functions, for example enter a safe state immediately when an error occurs or remain in a safe mode. Fail-safe systems or components are used wherever maximum safety must be guaranteed for people, machine or the environment, and accidents and damage resulting from a fault must be avoided. Summary
[0011] Briefly described, aspects of the present disclosure relate to industrial and other automation systems, and more particularly to an internal evaluation component with an embedded safety function to decrease a safety reaction time in connection with input / output (I / O) modules, such as failsafe input / output (I / O) modules.
[0012] More specifically, a first aspect of the present disclosure provides an input / output (I / O) module comprising multiple input ports configured to receive input signals, wherein each input signal comprises an input state, and an internal evaluation component configured to receive and evaluate the input states and to execute an embedded safety function.
[0013] A second aspect of the present disclosure provides an input / output (I / O) control system comprising a central controller, a plurality of input / output (I / O) modules, wherein at least one fail-safe I / O module comprises multiple input ports configured to receive input signals, wherein each input signal comprises an input state, and an internal evaluation component configured to receive and evaluate the input states and to execute an embedded safety function.
[0014] A third aspect of the present disclosure provides a method for evaluating input states in an I / O module, the method comprising receiving and evaluating one or more input signals from one or more input devices, and executing an embedded safety function, wherein the embedded safety function comprises overriding or transitioning an output state for an output signal from a first state to a second state.
[0015] Brief Description of the Drawings
[0016] FIG. 1 illustrates a schematic diagram of a known control system comprising multiple modules in accordance with an exemplary embodiment of the present disclosure.
[0017] FIG. 2 illustrates a schematic diagram of a known distributed control system with distributed I / O modules in accordance with an exemplary embodiment of the present disclosure.
[0018] FIG. 3 illustrates a schematic diagram of an input / output (I / O) module with embedded safety function in accordance with a first exemplary embodiment of the present disclosure.
[0019] FIG. 4 illustrates a schematic diagram of an input / output (I / O) module with embedded safety function in accordance with a second exemplary embodiment of the present disclosure.
[0020] FIG. 5 illustrates a flow chart of a method including executing an embedded safety function in accordance with an exemplary embodiment of the present disclosure. Detailed Description
[0021] To facilitate an understanding of embodiments, principles, and features of the present disclosure, they are explained hereinafter with reference to implementation in illustrative embodiments. They are described in the context of an input / output (I / O) module including an internal evaluation component with an embedded safety function.
[0022] The components and materials described hereinafter as making up the various embodiments are intended to be illustrative and not restrictive. Many suitable components and materials that would perform the same or a similar function as the materials described herein are intended to be embraced within the scope of embodiments of the present disclosure. Like reference symbols in the various drawings indicate like elements.
[0023] FIG. 1 illustrates a schematic diagram of a known control system 100 comprising multiple I / O channels in accordance with an exemplary embodiment of the present disclosure. In an exemplary embodiment, the control system 100 can be configured and / or comprises one or more programmable logic controllers (PLCs), which can comprise multiple modules. As noted, PLCs are typically used in combination with automation systems in different industrial fields to automatically perform a plurality of tasks, for example in a manufacturing process or an assembly line of a production facility. PLCs are control devices for controlling and monitoring process parameters.
[0024] With further reference to FIG. 1 , the control system 100 comprises a central processing unit (CPU) 110, an input 120 comprising digital and / or analog input channels 122, 124, an output 130 comprising digital and / or analog output channels 132, 134 and a power supply 140 which supplies power, specifically direct current (DC) power, to the CPU 110, the input 120 and the output 130. The input and output 120, 130 typically operate with 24 volts (V) direct current (DC) and the CPU 110 typically operates with 3.3V DC. The CPU 120 can further comprise one or more memories (ROM and / or RAM) 112 and one or more Ethernet interface(s) 114. The input and output 120, 130 are collectively referred to as I / O modules herein.
[0025] The CPU 110 monitors input signals from the input channels 122, 124, such as input sensors, which report events and conditions occurring in a controlled process. An application 150, herein also referred to as control program, is downloaded and stored within the CPU 110 and comprises instructions what actions to take upon encountering specific input signals or conditions. In response to the input signals, the CPU 110 derives and generates output signals which are transmitted via the output channels 132, 134 to various output devices, such as actuators and relays.
[0026] Further components of the control system 100 may include operator terminals which provide interfaces to the control system for monitoring, controlling, and displaying information to an operator or end user. Operator terminals are also known as Human-Machine-Interface (HMI) devices which allow effective operation and control of the components and devices of the automation system from the human end, i. e. the operator or end user, while the components / devices of the automation system feed information back to the operator / end user. It should be noted that those skilled in the art are familiar with such control system and PLCs.
[0027] FIG. 2 illustrates a schematic diagram of a known control system 200 with distributed I / O modules in accordance with an exemplary embodiment of the present disclosure.
[0028] A plant configuration often features multiple I / O components within a central automation system. Wiring of I / O components installed at a distance away from an automation system may soon become highly complex and susceptible to electromagnetic interference. Distributed I / O systems provide a solution for such configurations, because they include field devices with a wide range of I / O options, and the field devices (inputs and outputs) are operated locally in a distributed configuration. These field devices can include digital and analog channels, temperature measurements, counter inputs etc.
[0029] FIG. 2 illustrates a control system 200 comprising multiple distributed modules and components which together form the distributed system 200. The components include controller 210, multiple different I / O devices 220, 230, including analog and / or digital inputs / outputs, a human- machine-interface (HMI) device 240 and programming interface 250. The components are operably coupled via industrial ethernet 260, or other suitable communication networks, which ensures communication between sensors, actuators, and the I / O modules and components of the system 200. It should be noted that FIG. 2 illustrates a simplistic view of distributed control system 200, and further details will not be explained herein because one of ordinary skill in the art is familiar with such a control system 200.
[0030] FIG. 3 illustrates a schematic diagram of an input / output (I / O) module 300 with embedded safety function in accordance with a first exemplary embodiment of the present disclosure. The input / output (I / O) module 300 comprises multiple input ports (points) 310 configured to receive input signals 312, wherein each input signal 312 comprises an input state. The input signals 312 are received from various input devices, for example safety switches, light curtains, etc. Specifically, the module 300 is a fail-safe I / O module, which means that the input signals 312 are fail-safe inputs. As note before, fail-safe I / O modules perform safety functions, for example enter a safe state immediately when an error occurs or remain in a safe mode. Failsafe systems or components are used wherever maximum safety must be guaranteed for people, machine or the environment, and accidents and damage resulting from a fault must be avoided. The I / O module 300 further comprises one or more output port(s) (points) 320 configured to transmit or send output signals 322, each output signal 322 comprising an output state. The output signals 322 are transmitted to output devices, such as actuators, electric motors, etc. In case that the module 300 is a fail-safe I / O module, the output signals 322 are fail-safe outputs. In accordance with an exemplary embodiment of the present disclosure, the module 300 comprises an internal evaluation component 350 configured to receive and evaluate the input signals 312, specifically the respective input states, and to execute an internal evaluation function 360, stored in the internal evaluation component 350. The internal evaluation function 360 is herein also referred to as an embedded safety function 360.
[0031] The internal evaluation component 350 is operably coupled with or integrated in the I / O module 300. The evaluation component 350 with embedded safety function 360 may be embodied as software or a combination of software and hardware. The evaluation component 350 may be a separate component or may be an existing component programmed to perform a function or method as described herein, e. g., internal evaluation function 360. For example, the internal evaluation component 350 may be incorporated, for example programmed, into the I / O module 300.
[0032] Typically, within a distributed automation system, such as a distributed I / O system 200 as shown in FIG. 2, control logic with respect to I / O modules is executed in a central controller, for example in controller 210 in FIG. 2. This is accomplished by reading a current state of inputs, for example from input modules, referenced by the control program stored in the central controller, executing the control program, and then writing control outputs, for example to output modules. When interfacing to input and output modules, this takes time. Thus, an overall reaction time is reading an input, communicating the inputs states over a bus system to the central controller, executing the control program, writing the outputs states over a bus system, and writing the actual outputs. The safety reaction time is the amount of time it takes from some input event(s) occurring until an output(s), used in a particular safety function, is turned off (transitioned to the safe state). Expressed simply, an input event occurs, and a hazard needs to be turned off for the application to be safe. Thus, it is desirable to reduce the safety reaction time to transition an output to a safe state, e. g., turn off a hazard.
[0033] In accordance with an exemplary embodiment of the present disclosure, the above-described safety reaction response is fully integrated into an individual module, specifically into an I / O module, such as fail-safe module 300, instead of being performed by a central (remote) controller. The output port 320 is still enabled and controlled by a central controller, for example controller 210 with its control program; however, the module 300 is permitted to turn the output / hazard off based upon internal logic / operations evaluating the input signals 312 local to the module 300. This allows the module 300 to override the state of the output signals 322 to the off state; thereby, significantly decreasing the overall safety reaction time. More specifically, the embedded safety function 360 includes overriding or transitioning an output state of an output signal from a first state to a second state, when necessary. The first state comprises an ON state and the second state comprises an OFF state, wherein the embedded safety function is configured to override the ON state to the OFF state. If the output state is already in an OFF state, overriding is not necessary and not performed. An ON state as used herein corresponds to “1” or “true”, and the OFF state corresponds to “0” or “false”, within Boolean algebra or logic. The output port 320 is configured to transmit an output signal 322 based on the OFF state to an output device, for example to turn off an electric motor.
[0034] The transitioning or overriding of the output state from the first state (ON) to the second state (OFF) is based on the input states of the input signals 312. The internal evaluation component 350 comprises Boolean logic to execute the embedded safety function 360, specifically a logical operator “AND” (conjunction) to process the input signals. All input signals 312 with their respective states of “1” or “0” are combined by “AND” logic.
[0035] FIG. 3 illustrates multiple input signals 312, which are fail-safe inputs, wherein the output state is OFF when at least one input signal 312 has an input state that is “0”. It should be noted that the internal evaluation function 360 can utilize both fail-safe inputs and standard inputs with the restriction that there must be at least one fail-safe input connected. More specifically, FIG. 3 illustrates two outputs, output A and output B, which are fail-safe outputs. Output signal of output A may be based on two or more input signals 312, which are combined by logical operator “AND”. Similarly, output signal of output B may be based on two or more input signals 312, which are, in a separate logic, are combined by “AND”. For each output A and B, the respective output signal 322 is OFF or 0, when at least one of the respective input signals 312 is 0. The embedded safety function 360 may only reside in modules 300 including both fail-safe inputs and fail-safe outputs, in order to be able to affect the safety reaction time.
[0036] In a practical example, a user or customer is permitted to select a combination of inputs 310 / 312, which are local to the module 300, which are then “ANDed” together. If any of the inputs evaluates to 0, then the state of the output(s) is overridden directly by the module 300. The result of this behavior is a much faster reaction time to turn the hazard off.
[0037] FIG. 4 illustrates a schematic diagram of an input / output (I / O) module 400 with embedded safety function in accordance with a second exemplary embodiment of the present disclosure. Like the example module 300 of FIG. 3, the input / output (I / O) module 400 comprises multiple input ports 410 configured to receive input signals 412, wherein each input signal 412 comprises an input state. As shown in FIG. 4, the input signals 412 include a fail-safe input and a standard input.
[0038] In this example, a signal to a fail-safe input is received from an emergency stop switch (input device), and another signal to a standard input is configured as “Acknowledge Input”. The Acknowledge Input provides an input signal, in addition to the input signal of the emergency stop switch, to be able to control the embedded safety function 460. The embedded safety function 460 is configured as an emergency stop function 460 of internal evaluation component 450.
[0039] The I / O module 400 further comprises one or more output port(s) 420 configured to transmit or send output signals 422, each output signal 422 comprising an output state. In this example, the output signals 422 comprise a fail-safe output signal that is transmitted to an output device, such as an actuator, electric motor, etc. Another output signal is an “Acknowledge Request Output”.
[0040] The emergency stop switch comprises an input signal with an input state “1” when the switch is not activated, i. e. in normal situations / working environment. When the emergency stop switch is activated, the input state is “0”, which means that the output state is OFF because at least one input signal 412 has an input state that is “0”.
[0041] FIG. 5 illustrates a flow chart of a method 500 including executing an embedded safety function in accordance with an exemplary embodiment of the present disclosure.
[0042] While the method 500 is described as a series of acts that are performed in a sequence, it is to be understood that the method 500 may not be limited by the order of the sequence. For instance, unless stated otherwise, some acts may occur in a different order than what is described herein. In addition, in some cases, an act may occur concurrently with another act. Furthermore, in some instances, not all acts may be required to implement a methodology described herein.
[0043] The method is performed by an I / O module 300, 400 as described herein, specifically fail-safe modules 300, 400. The method may start at 502. At 510, one or more input signals 312, 412 from one or more input devices are received and evaluated by the I / O module 300, 400. At 520, an internal evaluation function 360, 460 is executed, stored in the internal evaluation component 350, 450, wherein the internal evaluation function 360, 460 comprises overriding or transitioning an output state for an output signal 322, 422 from a first state to a second state, when necessary. As described herein, the first state comprises an ON state and the second state comprises an OFF state, wherein the overriding or transitioning is from the ON state to the OFF state.
[0044] The method 500 further comprises act 530 of transmitting an output signal 322, 422 to an output device via an output port 320, 420, the output signal 322, 422 comprising an output state based on the OFF state. Practically, this means that the output signal 322, 422 is an OFF signal, for example to turn off a hazard or other type of output device. The input signals 312, 412 and output signals 322, 422 are fail-safe input signals and fail-safe output signals. The described modules 300, 400 and system provide solutions that significantly reduce overall safety reaction time for a given safety function. The modules 300, 400 are permitted to override the ON state of the safety output managed by the control program, for example CPU 210. The override is based upon the evaluation of the discrete inputs specified in the user parameterization shown above. It is permitted for the module 300, 400 to override the safety output to the OFF state only. This can be accomplished much faster than comparable PLC control. The described modules 300, 400 can be distributed I / O modules within a distributed system 200 or local modules located within a local base of the CPU.
[0045] While embodiments of the present disclosure have been disclosed in exemplary forms, it will be apparent to those skilled in the art that many modifications, additions, and deletions can be made therein without departing from the spirit and scope of the disclosure and its equivalents, as set forth in the following claims.
Claims
Claims1. An input / output (I / O) module (300, 400) comprising: multiple input ports (310, 410) configured to receive input signals (312, 412), wherein each input signal (312, 412) comprises an input state, and an internal evaluation component (350, 450) configured to receive and evaluate the input states and to execute an embedded safety function (360, 460).
2. The I / O module (300, 400) of claim 1 , further comprising: an output port (320, 420) configured to transmit output signals (322, 422), each output signal (322, 422) comprising an output state, wherein the embedded safety function (360, 460) includes transitioning an output state from a first state to a second state.
3. The I / O module (300, 400) of claim 2, wherein the output port (320, 420) is enabled and controlled by a central controller, the central controller being configured to provide the output state according to a central control program, and wherein the embedded safety function (360, 460) is configured to override the output state when necessary.
4. The I / O module (300, 400) of claim 2, wherein the first state comprises an ON state and the second state comprises an OFF state, and wherein the embedded safety function (360, 460) is configured to override the ON state to the OFF state.
5. The I / O module (300, 400) of claim 4, wherein the output port (320, 420) is configured to transmit a fail-safe output signal based on the OFF state.
6. The I / O module (300, 400) of claim 3, wherein the transitioning or overriding of the output state from the first state to the second state is based on the input states of the input signals, and wherein the output state is OFF when at least one input state is 0.
7. The I / O module (300, 400) of claim 1 , wherein the internal evaluation component (350, 450) comprises Boolean logic to execute the embedded safety function (360, 460).
8. The I / O module (300, 400) of claim 4, wherein an input signal (412) is received from an emergency stop switch, wherein the embedded safety function is configured as an emergency stop function (460), and wherein the output port (422) is configured to transmit an output signal based on the OFF state to turn off a hazard.
9. The I / O module (300, 400) of claim 1 , configured as fail-safe input module or fail-safe output module, comprising integrated safety functions.
10. An input / output (I / O) control system (200) comprising: a central controller (210), a plurality of input / output (I / O) modules (300, 400), wherein at least one fail-safe I / O module (300, 400) comprises: multiple input ports (310, 410) configured to receive input signals (312, 412), wherein each input signal (312, 412) comprises an input state, and an internal evaluation component (350, 450) configured to receive and evaluate the input states and to execute an embedded safety function (360, 460).11 . The system (200) of claim 10, further comprising: an output port (320, 420) configured to transmit output signals (322, 422), each output signal (322, 422) comprising an output state, wherein the embedded safety function (360, 460) includes transitioning or overriding an output state from a first state to a second state.
12. The system (200) of claim 11 , wherein the output port (320, 420) is enabled and controlled by the central controller (210), the central controller (210) being configured to provide the output state according to a central control program, and wherein the embedded safety function (360, 460) is configured to override the output state when necessary.
13. The system (200) of claim 11 , wherein the first state comprises an ON state and the second state comprises an OFF state, and wherein the embedded safety function (360, 460) is configured to override the ON state to the OFF state, wherein the output port (320, 420) is configured to transmit a fail-safe output signal based on the OFF state.
14. The system (200) of claim 11 , wherein the transitioning or overriding of the output state from the first state to the second state is based on the input states of the input signals (312, 412), and wherein the output state is OFF when at least one input state is 0, wherein the internal evaluation component (350, 450) comprises Boolean logic to execute the embedded safety function (360, 460).
15. The system (200) of claim 11 , wherein an input signal (412) is received from an emergency stop switch, wherein the embedded safety function is configured as an emergency stop function (460), and wherein the output port (420) is configured to transmit a fail-safe output signal based on the OFF state to turn off a hazard.
16. A method (500) for evaluating input states in an I / O module (300, 400), the method (500) comprising: receiving and evaluating (510) one or more input signals (312, 412) from one or more input devices, and executing (520) an embedded safety function (360, 460), wherein the embedded safety function (360, 460) comprises overriding or transitioning an output state for an output signal (322, 422) from a first state to a second state.
17. The method (500) of claim 16, wherein the first state comprises an ON state and the second state comprises an OFF state, and wherein the overriding or transitioning is from the ON state to the OFF state.
18. The method (500) of claim 17, further comprising: transmitting (530) an output signal (322, 422) to an output device via an output port (320, 420), the output signal (322, 422) comprising an output state based on the OFF state.
19. The method (500) of claim 16, wherein the transitioning or overriding of the output state from the first state to the second state is based on the input states of the input signals (312, 412), and wherein the output state is OFF when at least one input state is 0.
20. The method (500) of claim 16, wherein the internal evaluation component (350, 450) comprises Boolean logic to execute the embedded safety function (360, 460).
Citation Information
Patent Citations
Sensor arrangement for detecting a safe installation state of an installation operated in an automated manner
US20130233044A1
System and method for shutting down a field device
US20150005904A1
Control of Safety Input / Output by Non-Safety System During Safe Times
US20180164752A1
Devices and methods for microcontroller port control
US20230079901A1
Method and system for safety monitored terminal block
US8285402B2