Safety system and safety modules therefor

The modular safety system with daisy-chainable modules addresses the need for intuitive design in automated machinery safety systems by facilitating quick and compatible integration through unlabeled and labeled signal transmission.

WO2025194242A1PCT designated stage Publication Date: 2025-09-25VENTION INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CA2025/050247
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-22
Filing Date
2025-02-25
Publication Date
2025-09-25

AI Technical Summary

Technical Problem

Designing safety systems for automated machinery often requires highly qualified personnel and is a custom process, lacking a modular and intuitive approach.

Method used

A modular safety system with daisy-chainable safety modules that include a communication link, sensors, and controllers to facilitate intuitive design and operation, allowing unlabeled and labeled signal transmission for safety actions.

Benefits of technology

Enables quick and compatible design of safety systems for automated machinery cells with plug-and-play compatibility, reducing the need for individual programming and enhancing safety system integration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CA2025050247_25092025_PF_FP_ABST
    Figure CA2025050247_25092025_PF_FP_ABST
Patent Text Reader

Abstract

A modular safety system for an automated machinery cell, having a communication link; a sensor for transmitting, upon detection of an event, an unlabeled signal downstream along the link, a safety module communicatively coupled to the sensor via the link and immediately downstream of the sensor along the link, and having a module controller configured for receiving the unlabeled signal from the sensor, generating a labeled signal including a label associated with the detection of the event at the sensor, and transmitting the labeled signal downstream along the communication link. A main controller is communicatively coupled to the safety module via the link and downstream of the safety module along the link, the main controller configured for receiving the labeled signal, identifying the label in the labeled signal, and determining a safety action to be performed at a unit of the automated machinery cell when the event is detected.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SAFETY SYSTEM AND SAFETY MODULES THEREFOR

[0002] CROSS-REFERENCE TO RELATED APPLICATION

[0003] The present application claims the priority of U.S. Patent Application Serial No. 63 / 568,805 filed March 22, 2024, the entire content of which is incorporated herein by reference.

[0004] TECHNICAL FIELD

[0005] The present application relates generally to safety systems and safety chains of automated machinery cells and more particularly, to daisy-chainable safety modules for modular safety systems of automated machinery cells, and methods of operation for the same.

[0006] BACKGROUND

[0007] Design of safety systems for automated machinery typically relies on the use of safety rated equipment realizing safety functions for the safety of an operator (or objects) coming into the vicinity of the machinery in operation. Safety system designers or integrators often have to select and verify the compatibility of off-the-shelf safety equipment on a per-project basis. Safety systems are often custom solutions that can be made from several equipment available on the market. While safety system integrators can adapt the safety system to a specific installation, the process of designing safety systems for automated machinery, such as robot cells and the like, often requires highly qualified personnel for design and production of the custom control cabinets.

[0008] SUMMARY

[0009] There is a need for a modular design approach to facilitate and render more intuitive the design process of safety systems.

[0010] In accordance with an aspect, there is provided a modular safety system for an automated machinery cell, the modular safety system comprising: a communication link; a sensor configured for transmitting, upon detection of an event, an unlabeled signal downstream along the communication link; a safety module communicatively coupled to the sensor via the communication link and immediately downstream of the sensor along the communication link, the safety module having a module controller configured for: receiving the unlabeled signal from the sensor, generating a labeled signal including a first label associated with the detection of the event at the sensor, and transmitting the labeled signal downstream along the communication link; and a main controller communicatively coupled to the safety module via the communication link and downstream of the safety module along the communication link, the main controller configured for receiving the labeled signal, identifying the first label in the labeled signal, and determining a safety action to be performed at a unit of the automated machinery cell when the event is detected at the sensor.

[0011] Further in accordance with the above aspect, for example, the safety module is configured for generating and transmitting an unlabeled signal downstream along the communication link in addition to the labeled signal, the main controller configured for controlling the unit of the automated machinery cell in accordance with the safety action upon receiving the unlabeled signal.

[0012] Further in accordance with the above aspects, for example, the safety module is configured for receiving other labeled signals and repeating or transmitting the one or more other labeled signals further downstream along the communication link.

[0013] Further in accordance with the above aspects, for example, the unlabeled signal has at least one of an output signal switching device (OSSD) signal, redundant dry contacts, a safety protocol over EtherCAT or a safety protocol over EtherNet.

[0014] Further in accordance with the above aspects, for example, the unlabeled signal is an unlabeled coded signal.

[0015] Further in accordance with the above aspects, for example, the modular safety system includes a plurality of safety modules serially connected to one another upstream of the main controller along the communication link, the safety module being a first safety module of the plurality of safety modules and the labeled signal being a first labeled signal, wherein the module controller is further configured for: receiving a second labeled signal from a second safety module of the plurality of safety modules, the second safety module upstream of the first safety module along the communication link; and transmitting the second labeled signal from the second safety module downstream along the communication link, said transmitting the second labeled signal including no modification to the second labeled signal.

[0016] Further in accordance with the above aspects, for example, the safety module is a first safety module, the sensor is a first sensor, the module controller is a first module controller and the unlabeled signal is a first unlabeled signal, the first safety module having a housing enclosing the first module controller, a first communication port communicatively coupled to the sensor and a second communication port communicatively coupled to the communication link downstream of the first safety module, the modular safety system further comprises at least a second safety module connected serially downstream of the first safety module along the communication link and a second sensor communicatively coupled to the second safety module, the second safety module having: a housing having a third communication port communicatively coupled to the second communication port via the communication link, and a fourth communication port communicatively coupled to the second sensor, the second safety module having a second module controller configured for: receiving a second unlabeled signal from the second sensor or the first safety module, generating a second labeled signal including a second label associated with a detection of another event at the second sensor or at the first safety module, receiving the labeled signal from the first safety module, and transmitting the labeled signal and the second labeled signal downstream along the communication link.

[0017] Further in accordance with the above aspects, for example, the safety module is a first safety module, the sensor is a first sensor, the module controller is a first module controller and the unlabeled signal is a first unlabeled signal, the first safety module having, the first safety module having a housing enclosing the first module controller, a first communication port communicatively coupled to the first sensor and a second communication port communicatively coupled to the communication link downstream of the first safety module, the modular safety system further comprises at least a second safety module connected serially downstream of the first safety module along the communication link, the second safety module configured for interfacing the unit with the main controller, the second safety module having: a housing having a third communication port communicatively coupled to the second communication port via the communication link, and at least a fourth communication port communicatively coupled downstream on the communication link, the second safety module having a second module controller configured for: receiving from the unit a unit signal indicative of a default event at the unit or an operating mode of the unit, processing the unit signal received from the unit, and transmitting the processed unit signal received from the unit to the main controller.

[0018] Further in accordance with the above aspects, for example, the safety module is part of a plurality of safety modules of the modular safety system, the plurality of safety modules configured for interfacing respective sensors with the main controller via the communication link, the plurality of safety modules serially communicatively coupled in a daisy-chain configuration, the plurality of safety modules including: a first set of safety modules communicatively coupled to each other to define a main safety chain, a second set of safety modules communicatively coupled to each other to define an auxiliary chain, the main safety chain and the auxiliary chain both communicatively coupled to a common safety module of the plurality of safety modules so as to have the main safety chain and the auxiliary chain parallel to each other, the common safety module configured for interfacing the unit with the main controller.

[0019] Further in accordance with the above aspects, for example, the common safety module has a common module controller configured for: receiving from the unit a unit signal indicative of a default event at a robot or an operating mode of the robot, processing the unit signal received from the unit, and transmitting the processed signal received from the unit to the main controller.

[0020] Further in accordance with the above aspects, for example, the common module controller of the common safety module is further configured for: receiving a unit operation signal from the main controller, and transmitting the unit operation signal to the robot.

[0021] Further in accordance with the above aspects, for example, the common safety module has a common module controller configured for: receiving the labeled signal of the safety module of the plurality of safety modules, transmitting or repeating the labeled signal downstream on the communication link towards the main controller, receiving a unit operation signal from the main controller, and causing a change of operating mode of the unit based on the labeled signal and / or the unit operation signal.

[0022] Further in accordance with the above aspects, for example, upon receiving the labeled signal from any one of the safety modules of the auxiliary chain at the common safety module or the main controller, the common safety module is configured to prompt a change of operating mode of a robot.

[0023] Further in accordance with the above aspects, for example, upon receiving the labeled signal from any one of the safety modules of the main safety chain at the common safety module or the main controller, the common safety module is configured to trigger an emergency stop of the automated machinery cell.

[0024] Further in accordance with the above aspects, for example, the automated machinery cell includes a machine control system configured to supply power to and operate the unit, the main controller configured for controlling the unit through communication with the machine control system interfacing with the unit. In accordance with another aspect, there is provided a safety module for a daisy-chain safety system of an automated machinery cell, the daisy-chain system having a communication link, a sensor configured for transmitting, upon detection of an event, an unlabeled signal downstream along the communication link, and a main controller communicatively coupled to the communication link, the safety module comprising: a housing; an input port communicatively couplable to the sensor via the communication link; an output port communicatively couplable to the main controller via the communication link; a processor, and a non-volatile computer memory having instructions stored thereon which when executed by the processor cause the safety module to perform the steps of: receiving the unlabeled signal from the sensor via the input port, generating a labeled signal including a first label associated with the detection of the event at the sensor, and transmitting the labeled signal downstream along the communication link via the output port.

[0025] Further in accordance with the above aspect, for example, the steps further comprises generating and transmitting another unlabeled signal downstream along the communication link in addition to the labeled signal, the main controller configured for controlling a unit of the automated machinery cell in accordance with a safety action upon receiving the unlabeled signal.

[0026] In accordance with another aspect, there is provided a daisy chainable safety module for a modular safety system of an automated machinery, comprising: a housing; a plurality of input ports and at least one output port mounted to the housing; a controller in the housing and communicatively coupled to the plurality of input ports and to the at least one output port, the plurality of input ports configured to receive signals from at least one sensor or another daisy chainable safety module communicatively upstream in a safety chain of the modular safety system and communicatively couplable to at least one of the plurality of input ports, the at least one output port configured to transmit signals downstream in the safety chain towards a main controller of the modular safety system via the at least one output port, the controller configured for: receiving a signal from at least one input port of the plurality of input ports; processing the signal according to a predetermined safety logic stored on a non-transitory memory of the controller, said processing including at least one of: upon determining that the signal is labeled, transmitting the signal downstream in the safety chain via the at least one output port; and upon determining that the signal is unlabeled, generating a labeled signal including a label associated with a detection of an event at the at least one sensor, and transmitting said generated labeled signal downstream in the safety chain towards the main controller. Further in accordance with the above aspect, for example, the controller is further configured for generating and transmitting an unlabeled signal downstream in the safety chain towards the main controller in addition to the generated labeled signal, the main controller configured for controlling a unit of the automated machinery in accordance with a safety action upon receiving the unlabeled signal.

[0027] Many further features and combinations thereof concerning the present disclosure will appear to those skilled in the art following a reading of the present disclosure.

[0028] DESCRIPTION OF THE DRAWINGS

[0029] Fig. 1 is a perspective view of an exemplary automated machinery cell including a modular safety system.

[0030] Fig. 2 is a perspective view of an example of a safety module of the modular safety system of Fig. 1 , shown with lock and unlock buttons, and a set of input ports and output ports, according to an embodiment.

[0031] Fig. 3 is a graph showing an example of a safety logic of a safety module such as the example of Fig. 2, according to an embodiment, the differences in shading illustrate a change of state at inputs, at an output, as part of an embedded safety function embodied by the safety logic.

[0032] Fig. 4 is a schematic view of an exemplary safety system including a safety module as the example of Fig. 2, shown with guard locks, according to an embodiment.

[0033] Fig. 5 is a schematic view of another exemplary safety system, shown with light curtains and an emergency stop button, according to another embodiment.

[0034] Fig. 6 is a graph showing another example of a safety logic for the safety system of Fig. 5, according to another embodiment, the differences in shading illustrate a change of state at inputs, at an output, as part of an embedded safety function embodied by the safety logic.

[0035] Fig. 7 is a schematic view of yet another exemplary safety system, shown with an area scanner and an emergency stop button, according to another embodiment.

[0036] Fig. 8 is a graph showing of another example of a safety logic for the safety system of Fig. 7, according to another embodiment, the differences in shading illustrate a change of state at inputs, and at an output, as part of an embedded safety function embodied by the safety logic. Fig. 9 is a perspective view of an example of a safety module of the modular safety system of Fig. 1 , shown with a set of input ports and output ports, according to another embodiment.

[0037] Fig. 10 is a schematic view of another exemplary safety system including the safety module of Fig. 9, according to an embodiment.

[0038] Fig. 11 is a schematic view of another exemplary safety system including safety modules of Figs. 2 and 9 in a daisy-chain configuration, according to an embodiment.

[0039] Fig. 12 is a block diagram of an exemplary safety chain and an auxiliary chain of a modular safety system.

[0040] Fig. 13A is a block diagram of an exemplary safety chain including safety modules of Figs. 2-9 in a daisy-chain configuration, according to an embodiment.

[0041] Fig. 13B is a graph showing an example of an unlabeled signal transmitted by a sensor of a safety system according to an embodiment.

[0042] Fig. 13C is a graph showing a labeled signal with a label associated with an event detected at a sensor of a safety system according to an embodiment.

[0043] Fig. 14 is a block diagram of a safety management method for controlling a unit of an automated machinery cell via a safety system according to an embodiment.

[0044] Fig. 15 is a block diagram illustrating an example of a computing device main controller of the modular safety system of Fig. 1.

[0045] DETAILED DESCRIPTION

[0046] Fig. 1 illustrates an exemplary automated machinery cell 10. The automated machinery cell 10 includes various machinery components, frame structures and safety equipment. The automated machinery cell 10 may be deployed in a plant or facility with a plurality of automated cells that are configured to accomplish respective dedicated tasks. In the example shown, the automated machinery cell 10 includes a robot 11 , a control cabinet 12, a conveyor 13, user interfaces 14, a main controller 15 and a safety system 16. Other automated machine cell 10 are contemplated, for example without robot 11 , conveyor 13, or with a different number or configuration of those machinery components. The automated machine cell 10 may be a robot palletizer, as the example shown, or be configured for other applications, e.g., box erecting, picking & placing objects, case packing, sanding & surface finishing, bin picking, as some possibilities. The robot 11 is one example of actuated unit, other actuated unit could be contemplated, such as other types of actuators (e.g., pneumatic or electric actuators). While control cabinet 12 is referred to throughout herein, this is only one example, as other types of machine control system configured for operating actuated unit(s) could also be contemplated.

[0047] The main controller 15 may interact with the control cabinet 12 and / or robot 11 to generate motion control, and / or allow automation control of various components of the automated machinery cell 10.

[0048] The main controller 15 can be provided as a combination of hardware and software components, which can be implemented in the form of a computing device 15A, an example of which is described with reference to Fig. 15. The computing device 15A can have a processor 15B, a memory 15C, and I / O interface 15D. Instructions 15E for generating motion control and / or control the safety system 16 can be stored on the memory 15C and accessible by the processor 15B. The processor 15B can be, for example, a general-purpose microprocessor or microcontroller, a digital signal processing (DSP) processor, an integrated circuit, a field-programmable gate array (FPGA), a reconfigurable processor, a programmable read-only memory (PROM), a programmable logic controller (PLC), or any combination thereof. The memory 15C can include a suitable combination of any type of computer-readable memory that is located either internally or externally such as, for example, random-access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), and electrically-erasable programmable read-only memory (EEPROM), Ferroelectric RAM (FRAM) or the like. Each I / O interface 15D enables the computing device 15A to interconnect with one or more input devices, such as a module of the safety system 16 (as described later), or with one or more output devices such as the user interface 14. Each I / O interface 15D enables the controller to communicate with other components, to exchange data with other components, to access and connect to network resources, to server applications, and perform other computing applications by connecting to a network (or multiple networks) capable of carrying data including the Internet, Ethernet, coaxial cable, fibre optics, satellite, mobile, wireless (e.g. Wi-Fi, WiMAX), SS7 signaling network, fixed line, local area network, wide area network, and others, including any combination of these. For example, the main controller 15 may be controlled remotely from a control station, via a cloud based interface, or otherwise. The main controller 15 can be communicatively coupled to a personal computer or a server for data collection, programming, simulation, for example. The computing device 15A and any software application that can be run by the computing device 15A are meant to be examples only. Other suitable embodiments of the main controller 15 can also be provided, as it will be apparent to the skilled reader.

[0049] Although the previous paragraph describes a specific example of the main controller 15, it is intended that any other controller described herein can have a hardware and / or software configuration similar to that of the main controller 15. For instance, the controller 35 (described below), and / or the controller 85 (described below) can all individually include one or more computing device(s) similar to the computing device 15A described with reference to Fig. 15.

[0050] Returning back to Fig. 1 , the safety system 16 includes sensor(s) 20 in communication with the main controller 15. The main controller 15 may communicate with external modules forming, with the sensors 20 and the main controller 15, components of a modular safety system 16 to perform one or more functions. For instance, one example function may include the detections of safety hazard, e.g., human entering a working area or cell, object placed in the trajectory of the robot 11. Such functions may be monitored and controlled via the main controller 15. The main controller 15 may generate, store and / or act on safety data associated with signals from sensors 20.

[0051] Safety modules 30 interface sensors 20 with the main controller 15. The safety modules 30 act as communication hubs that are communicatively coupled to respective sensors 20. Sensor signals are received at the safety modules 30. The safety modules 30 may process the sensor signals and transmit information to the main controller 15 to act on those, if necessary. As will be described later, some safety modules 30 may interface an actuated unit, such as robot 11 (or other types of actuated unit) with the main controller 15. In application, the safety modules 30 and other components of the safety system 16 may be part of a modular manufacturing automation platform. Plug-and-play compatibility between the safety modules 30 and the robot 11 (or other actuated unit) and / or sensors 20, and the main controller 15 may allow users to quickly design automation solutions and ensure that signals from sensors, actuated units, etc., which are sent towards the main controller 15 are compatible with the logic of the main controller 15. The modules presented herein are in the form of plug-and-play blocks having native embedded safety functions. These native embedded safety functions circumvents the need for individual programming of the safety modules 30 by the user / designer to enable the desired safety functions. The embedded safety functions of the modules are pre-programmed, hard coded, or otherwise configured for implementing a safety logic stored (e.g., embedded) therein. In at least some embodiments, the safety functions of the modules may be customized via code-free programming, via software, such as the MachineLogic™ visual programming and simulation tool dedicated to the creation of controller programs, as commercialized by Vention™. The modules 30 are adapted to interconnect, by wire connection, for example, to other safety equipment and other modules 30.

[0052] The safety modules 30, when paired with sensors 20, or other input units, logic units, contactors or other types of output units may perform safety functions and cooperate with the main controller 15 as part of the safety system 16. Each safety module 30 may have one or more safety functions embedded therein. In operation, the safety modules 30 may report safety states to the main controller 15 that are specific to the safety function(s) embedded therein.

[0053] The safety modules 30 may be communicatively coupled to various types of sensors 20, for example area scanners, light curtains, proximity sensors or other safety devices to perform safety functions. In some embodiments, a safety module 30 may be connected to more than one sensor 20 and, depending on the input port and / or safety logic of the safety module 30 associated with the input port, perform the safety function embedded in the safety module 30.

[0054] As shown in Fig. 2, the safety module 30 comprises a housing 31. The safety module 30 may have one or more input ports 32 and output ports 33 for connection to one or more sensors 20. Some of the input ports 32 and output ports 33 may be associated to the safety function, and control the activation and deactivation of other components connected to the other input ports 32 and output ports 33. Input ports 32 and output ports 33 may be configured for connection to other safety modules 30 upstream or downstream thereof in a daisy-chained configuration (described later). The physical interface of the safety module 30 may be different in other embodiments. For example, the safety module 30 may have less or more input ports 32 or output ports 33, they may include push buttons for manual operation of a safety function, such as the depicted lock button and unlock button, have one or more visual indicators, etc. The input ports 32 and output ports 33 may include quick-connector sockets compatible with an 8-pin M12 connectors, 12-pin M12 connectors, or other similar industrial automation connectors, for example. The safety modules 30 may be mountable to frame members of the automated machine cell 10 via mounting brackets (not shown). They may thus be located within the automated machinery cell 10 to facilitate access, or connection / disconnection.

[0055] The safety module 30 includes a controller 35. The controller 35 is enclosed in the housing 31. The controller 35 may be communicatively coupled with the input ports 32 and output ports 33, through wired connection, for example. The controller 35 may include a processing unit which may be used with a non-transitory computer-readable memory (e.g., non-volatile computer memory) communicatively coupled to the processing unit and comprising computer-readable program instructions (e.g., part of a firmware) executable by the processing unit for performing safety functions. In an embodiment, the controller 35 includes a safety circuitry (e.g., a safe PLC). The controller 35 is configured for receiving signals from one or more sensors 20 connected to the safety module 30. It is intended that the signal(s) received from the sensor(s) are unlabeled and can be referred to as "unlabeled signals." In other words, taken alone, these signals may not indicate their respective origins. An unlabeled signal may carry a Boolean value (e.g., 0 or 1) without any other information, or be an analog signal. Accordingly, receiving such an unlabeled signal may be indicative that an upstream one of the sensors has been activated (or deactivated), but may not indicate which one of the sensors has been activated (or deactivated). The unlabeled signals can include alert information and / or status information, depending on the embodiment. For example, the signal(s) received can be provided in the form of unlabeled coded signals, such as unlabeled output signal switching device (OSSD) signals. The controller 35 may also be configured to get the states of its own outputs and inputs to detect the state of the chain of modules. The controller 35 may process the signal received from the sensor(s) 20 and, implementing an embedded safety logic, the controller 35 may communicate (directly or via an intermediate component of the safety module) with the main controller 15 to provide an information about the signal received. Such information may be communicated as an a labeled signal (e.g., headered signal), which may be an encoded signal. In a variant, the labeled signal could carry the Boolean value associated with the activation or deactivation of one of the sensors together with any information (e.g., metadata) which can identify which one of the sensors has been activated (or deactivated), for instance. The labeled signal can include a status or status change of the sensor(s) 20 (e.g., ON / OFF, triggered / not triggered, activated state / deactivated state), a position of the sensor(s) 20 (e.g., location of the sensor(s) 20 in a surrounding environment of the automated machinery), a diagnostic error of the sensor(s) 20, an identification of a source of the unlabeled signal or the safety module 30 from which the labeled signal originates, a position of the safety module 30 with respect to other safety modules 30 in a daisychain topology of a safety chain (described later), a state change request (e.g., request for an emergency stop) or instructions, or a combination of the foregoing, for example. In an embodiment, the labeled signal is generated based on the unlabeled signal. Stated otherwise, the safety module 30 may generate a labeled signal upon receiving an unlabeled signal from the sensor 20. The labeled signal includes a label indicative of the sensor (e.g., sensor related information as mentioned above) or safety module 30 from which the label is generated. The labeled signal does not necessarily include the unlabeled signal received from the sensor 20, but rather include an indication of which sensor has detected an event. In some cases, the labeled signals may not be safety rated. In at least some embodiments, the labeled signal may be transmitted in addition to an unlabeled signal generated by the safety module 30, such as safety signals OSSD, redundant dry contacts and / or safety protocol over EtherCAT™ or EtherNet / IP™ for example. Stated otherwise, the labeled signal, which may not be safety rated, may be transmitted in addition to a safety rated, unlabeled signal. In such cases, the labeled signal and the unlabeled signal generated by the safety module 30 may be transmitted, simultaneously or sequentially, downstream towards the main controller 15 for the main controller to act on those signals. Upon receiving an unlabeled signal from another safety module upstream, the safety module 30 may generate a labeled signal (as described above) and in turn transmit such labeled signal downstream towards the main controller 15 to provide information about the receiving of an unlabeled signal from another safety module upstream thereof. In some cases, the safety module 30 may generate an unlabeled signal upon receiving an unlabeled signal from a safety module upstream thereof for transmission downstream towards the main controller 15 and / or a subsequent safety module in the safety chain, and so on. In some cases, the safety module 30 receiving an unlabeled signal from another safety module upstream thereof may both generate an unlabeled signal for transmission downstream towards the main controller 15 and / or a subsequent safety module in the safety chain, and generating and transmitting a labeled signal downstream, in addition of the unlabeled signal that it transmits downstream towards the main controller 15 and / or a subsequent safety module in the safety chain. It may be assumed that an unlabeled signal received at any given safety module may be automatically associated with the safety module and / or sensor immediately upstream from the given safety module along the communication link.

[0056] Such communication and signal labeling capability between the safety module 30 and the main controller 15 may enable the main controller 15 to map a topology of a safety system 16. Such communication capability may also enable the main controller 15 to inform an operator (e.g., through a user interface 14) on the status of sensor(s) 20, position of the sensor(s) 20, system or sensor error, diagnostic error / status, identity of a triggered sensor(s) within a safety chain, etc., so that the operator may act on those if necessary. For example, upon receiving such an encoded / labeled signal from a safety module 30, the main controller 15 may prompt the operator via a user interface or visual indicator, and / or prompt a recovery / reinitialization procedure, or other control procedures. Such prompt may include the visualization, via the user interface 14, of the mapped topology of the safety system 16. Such mapping may include graphical representations of the components of the safety system 16, e.g., icons, blocks, text or other identifiers, displayed on the user interface 14, for example. These graphical representations may show a map of the connections of the components over which can be overlaid respective statuses to provide valuable information concerning the safety system 16 at a glance. For instance, an exemplary status can be provided in the form of a graphical representation of a text box overlaid proximate to one of the components. Another exemplary status can be provided in the form of a graphical representation of a connection link (connecting two components of the safety system 16) which may change color (e.g., from green to red, or vice versa) upon a status change.

[0057] An exemplary safety logic SL1 of the safety module 30 is illustrated in Fig. 3. Accordingly, in a variant of the safety module 30, a first sensor 20 (e.g., a proximity sensor) may be connected to a first channel associated with a first input port identified as channel A of the safety module 30 and a second sensor 20 (e.g., a proximity sensor) may be connected to a second channel associated with a second input port identified as channel B. In at least some embodiments, the safety module 30 may have an embedded sensor muting function embodied by the safety logic SL1 of Fig. 3. The sensor muting function of such safety module 30 may be triggered when the first channel becomes triggered followed by a trigger of the second channel (identified as channel B). For example, in an application, the muting sensors A and B, identified as such for corresponding to the channel identification for ease of understanding, may be placed in a specific order (physical positioning) along a conveyor or entrance path for example, to activate the sensor muting function at the safety module 30. In an embodiment, the safety logic SL1 is such that the muting sensors A and B may be consecutively triggered within a triggering time interval, e.g., in an embodiment 2 seconds, for the muting to occur. As one possibility, activating the muting sensors for more than 10 consecutive seconds could disable muting. Other values could be contemplated. The triggering order may not matter, in at least some embodiments. However, other contemplated safety logic may require a specific triggering order to activate the safety function. While both muting sensors A and B are triggered, a sensor 20 connected on a “Device” port ,as represented in Fig. 3, which may be a light curtain for example, is muted. As such, a signal from the sensor 20 communicated to the safety module 30, if the muting is activated, will not trigger a the transmission of a labeled signal at the output port of the safety module 30 to realize a safety action within the safety system 16. Stated otherwise, if A and B are triggered, the triggering of the “Device” sensor will not cause the safety out signal to drop or activate as it will be muted. Another exemplary embedded safety function may be an access request function. For example, referring to Fig. 4, in some safety systems, the safety module 30 may be connected to guard lock devices to be interfaced with the main controller 15. In Fig. 4, the safety module 30 is configured for interfacing guard locks 40 with the main controller 15. An optional emergency stop button module 50 may also be connected to the safety module 30 to enable a manual emergency stop function (e.g., emergency shutdown). A guard lock 40 as part of a cell or machine may prevent a user to open a door or gate based on a safety or programmed condition. A lock / unlock request may be triggered manually by an operator. For example, in an embodiment, the safety module 30 may include actuators (e.g., buttons, switch) activatable by an operator to send a lock / unlock request to the main controller 15 via the safety module 30. Actuation of the actuator(s) of the safety module 30 may send a signal indicative of such request to the main controller 15. The main controller 15 may then send a request to the safety module 30 to lock / unlock the guard lock 40. The safety conditions to be met may be a “cell safe” input from a sensor 20, 60 or safe state output from a robot connected to the safety chain. For example, if a sensor or a robot connected on the safety chain conveys a signal to a safety module paired therewith that is indicative of an absence of a safety hazard (e.g., absence of movement within the robot cell I safety zone, robot placed in a safe location within the safety zone), that safety module may communicate a “cell safe” signal to the main controller 15 (or vice versa), which may then allow the unlocking of the guard lock 40 in response to the lock / unlock request triggered by the operator at the safety module 30 shown in Fig. 4. In contrast, if a safety hazard is detected, a safety module may communicate an alert signal to the main controller 15 (or vice versa), which may maintain the guard lock 40 in a locked state or refuse an unlock request, for example.

[0058] Another exemplary embedded safety function may be a mode switching function. For example, referring to Figs. 5-6, in some safety systems, the safety module 30 may be connected to light curtains 60 to be interfaced with the main controller 15. In Fig. 5, the safety module 30 is configured for interfacing the light curtains 60 with the main controller 15. An optional emergency stop button module 50 may also be connected to the safety module 30 to enable a manual emergency stop function (e.g., emergency shutdown). Light curtains 60 may be connected to the safety module 30 on one or more channels, though other wiring configuration could be contemplated depending on the sensor(s) or sensor types. A mode switching function embedded in the safety module 30 may be achieved by the exemplary safety logic SL2 of Fig. 6. For example, if the “A” device (e.g., a first light curtain) was not triggered since a reset, a “B” device (e.g., a second light curtain) can be crossed without triggering an output signal at the safety module 30. When the “A” device is triggered (e.g., first light curtains crossed), then triggering the “B” device may trigger an output signal at the safety module 30. In the example shown, there are two groups of mode switching (represented as A1 / B1 and A2 / B2). If the “B” device is triggered while the “A” device is triggered then the output signal at the safety module 30 may be triggered. As depicted in this embodiment, the safety module 30 can include two different pairs of “A” and “B” devices. In an embodiment, the safety function may be activated only when the two “A” and “B” devices of a given pair are simultaneously triggered. In some other embodiments, the triggering of any one of the “A” devices simultaneously to the triggering of any one of the “B” devices may be required to activate the safety function. The safety hazard state may be latched until a manual reset is engaged.

[0059] Another exemplary embedded safety function may be an auto-reset safety function. For example, referring to Figs. 7-8, in some safety systems, the safety module 30 may be connected to an area scanner 70 to be interfaced with the main controller 15. In Fig. 7, the safety module 30 is configured for interfacing the area scanner 70 with the main controller 15. An optional emergency stop button module 50 may also be connected to the safety module 30 to enable a manual emergency stop function (e.g., emergency shutdown). An auto-reset safety function embedded in the safety module 30 may be achieved by the exemplary safety logic SL3 of Fig. 8. In the example shown, the safety module 30 has three devices connected to respective input ports. It is understood that three devices is only one possibility, as there could be more or less devices. These devices may be multiple light curtains or a single area scanner 70 with 3 outputs, for example. As shown, the safety logic SL3 requires a sequence of triggering events to overlap (at least partially) to activate the safety function. An inverse sequence of triggering events once the safety function is activated will trigger an automatic reset, referred to as an internal reset in the figure, to return to an initial, untriggered, state. In the example shown, the sequence of triggering events must overlap and an incorrect sequence will cancel the internal reset. The internal reset does not send a reset signal outside of the safety module 30 (e.g., to the main controller 15). Once the sequence is initiated, an output signal at the safety module 30 may be outputted. If the predetermined triggering events sequence is not respected, the safety module 30 will not autoreset. Stated differently, if the sequence is not respected, no auto-reset will be triggered and a manual reset will be necessary. In an embodiment, the internal reset may happen after a predetermined time interval during which the triggering sequence is respected, e.g., five seconds after the sequence is respected. The safety module 30 with an embedded auto-reset safety function as described, may change the safety state (e.g., by conveying an output signal to the main controller) if certain conditions are met, once the signal input coming from the sensor(s) indicates that the safety hazard event is over.

[0060] The safety modules 30 are daisy-chainable such that, as part of a safety chain, multiple safety modules 30 may be connected serially upstream of the main controller 15 and / or a robot safety module (described below) to realize safety functions. As the signal transmitted from a safety module 30 is labeled so as to identify the source of the alert signal, or otherwise provide information that can be specific to the safety module 30 issuing the signal towards the main controller 15 and allowing the main controller 15 to identify the source, such signal may transit through one or more safety modules 30 located downstream in the safety chain and still provide information to the main controller 15 as to the source of the signal. Such information may assist the operator to locate the unsafe area or the triggered sensor within the cell. The operator may thus be made aware of the state of the cell (or an area therefrom), even from a remote location with respect to the cell, and take the proper action to solve a problem. The main controller 15 may also monitor and act on such information, without the implication of the operator. For example, as mentioned above, a recovery / reinitialization procedure, or other control procedures may be prompted by the main controller 15 upon receiving and processing the labeled signal received.

[0061] In an embodiment, a labeled signal generated at a first safety module 30 may serially transit through one or more other safety modules downstream thereof until reaching the main controller 15. Such a serial transit may be performed through a number of safety modules without alteration. The labeled signal generated at the first safety module 30 may thus be the same signal as that received at the main controller 15. However, in some embodiments, a labeled signal generated by a safety module 30 on a daisy chain may only be transmitted to the safety module 30 immediately downstream thereof in the safety chain. Such other safety module 30 immediately downstream from the preceding safety module 30 may generate a new labeled signal upon receiving the labeled signal from upstream, and so on, towards the main controller 15, until a labeled signal reaches the main controller 15. This latter labeled signal may include one or more labels (or any relevant information) carried from any upstream ones of the safety modules. As mentioned above, in at least some embodiments, the first safety module 30 could generate an unlabeled signal in addition to generating a labeled signal, and transmit both signals downstream to a subsequent safety module 30 along the safety chain, and so on in a cascading manner from one safety module 30 to another one until an unlabeled signal and a labeled signal reach the main controller 15 so that the main controller 15 may act on those to prompt a safety action. Another example of safety module 30 will now be described with reference to Figs. 9-11 and referred to as item 80. Like features of the safety module 80 with respect to safety module 30 will not be described again for brevity. In the embodiment shown, the safety module 80 is configured for interfacing a robot with the main controller 15 and / or one or more safety modules, such as the safety module 30 described above. For ease of reference in this disclosure, the safety module 80 of Figs. 9-11 will be referred to as a robot safety module 80 (“RSM 80”).

[0062] The RSM 80 may be connected to an actuated unit such as robot 11 according to its specific wiring diagram. Various types of robots can be contemplated, including a collaborative robot, also known as cobot (robot adapted for safe collaboration between humans and machines). Examples of collaborative robots include collaborative robots commercialized under the brand Universal Robots, FANUC, or Doosan. Other programmable robots or manipulators may be contemplated. In Fig. 10, the RSM 80 is connected to an exemplary control cabinet 12 through which a robot arm may be supplied with power and / or communicate through input and output signals.

[0063] The RSM 80 has a plurality of input ports 82 and output ports 83. The RSM 80 comprises a Housing 81. An input port 82 of the RSM 80 may be connected to a safety module 30 communicatively coupled upstream of the RSM 80. The physical interface of the RSM 80 may be different in other embodiments. For example, the RSM 80 may have less or more input ports 82 or output ports 83, may include push buttons for manual operation of a safety function, have one or more visual indicators, etc.

[0064] The RSM 80 allows bilateral communication between the main controller 15 and the robot interfaced with the RSM 80. The RSM 80 may allow an operator, via programming and / or communication with the main controller 15, to use embedded functions of the robot and trigger a change of operating mode of the robot from the main controller 15, through signal transiting via the RSM 80 to the robot (or control cabinet 12). In some cases, collaborative robots may have embedded a plurality of operating modes in their control logic. For example, the robot may have a collaborative mode. A collaborative mode is a set of safety functions of a robot that allow collaborative work (i.e. , robot with operator sharing a task). It may include speed monitoring of gripper or joints, force monitoring, momentum monitoring, power monitoring, or the like. The robot may also have a protective stop mode. A protective stop mode may be a category 2 stop, meaning that the robot may stop its action and a standstill monitoring may be activated. Under the protective stop mode, if the robot moves, a category 0 or 1 stop may be activated, meaning that power is safely removed from the robot. In machine safety, as known, a stop category 0 is an uncontrolled stop by immediately removing power to machine actuators. A category 1 is a controlled stop with power to the machine actuators available to achieve the stop then remove power when the stop is achieved. The robots may have other operating modes, or a single operating mode (e.g., a standard / default operating mode), depending on embodiments.

[0065] In at least some embodiments, the RSM 80 may communicate (or “publish”) safety state to the main controller 15. For example, in case of a default event at the robot, or selection of an operating mode of the robot, the RSM 80 may convey a signal indicative of the default event or operating mode selection of the robot to the main controller 15. In a variant, the RSM 80 could operate without the main controller 15 where, for example, the RSM 80 is used as an interfacing module between a robot and a heads up signal. In at least some embodiments, the RSM 80 may thus not need to wait for a prompt from the main controller 15 to take safety actions towards the robot.

[0066] As described above with respect to the safety module 30, the RSM 80 includes a controller 85. The controller 85 is enclosed in the housing 81. The controller 85 may be communicatively coupled with the input ports 82 and output ports 83, through wired connection, for example. The controller 85 may include a processing unit which may be used with a non-transitory computer- readable memory (e.g., non-volatile computer memory) communicatively coupled to the processing unit and comprising computer-readable program instructions (e.g., part of a firmware) executable by the processing unit for performing safety functions. For example, in an embodiment, the controller 85 may include a safety PLC. The controller 85 is configured for receiving a signal from a user interface, or an emergency stop switch, as shown, connected to the RSM 80. The controller 85 may also be configured for receiving signals from one ore more safety modules 30 upstream thereof in the safety chain, and / or for communicating with the robot communicatively coupled thereto. The RSM 80 may act as a hub through which data information or signal may transit to reach the main controller 15. The signal received at the RSM 80 may be an unlabeled and / or labeled signal, as described above. The controller 85 may process the signals received from a sensor 20, an emergency stop module 50, or another safety module 30 communicatively coupled thereto and / or the robot 11 communicatively coupled thereto and, implementing an embedded safety logic, the controller 85 may communicate (directly or via an intermediate component of the safety module) with the main controller 15 to transmit the signal received, or provide an information thereon by generating a signal (labeled and / or unlabeled) based on the signal received and transmitting such generated signal to the main controller 15. Such information may be communicated as an encoded information signal, or labeled signal, as similarly described above and not repeated for brevity. A plurality of RSM 80 may be daisy-chained, for example in applications requiring the cooperation of multiple robots in a cell. When a plurality of RSM 80 are daisy-chained, labeled signal(s) transmitted to the main controller 15 via one or more of the daisy-chained RSM 80 may allow to identify the source of the signal it received, as described above. As such, in operation, when several RSM 80 are daisy-chained, if a robot 11 goes to an emergency stop, or if an area of the cell goes to an emergency stop because of the detection of a safety hazard event at a specific location within the cell or in the surrounding of that robot, other robots communicatively coupled to other RSM 80 within the daisy-chain may not stop. While the example described above relates the RSM 80 to a robot 11 , the RSM 80 could be paired with other types of actuated units.

[0067] The daisy-chain configuration will now be further described. To illustrate a daisy-chain configuration, a safety chain including a plurality of safety modules 30 that are daisy-chained is presented in Fig. 11.

[0068] As shown, the safety chain includes a user interface 14, at least one sensor 20, and a plurality of safety modules 30. The safety chain is communicatively coupled to a main controller 15 (as the main controller described above). An emergency (one or many) stop button module 50 may also be connected to the safety module 30 to enable a manual emergency stop function (e.g., emergency shutdown).

[0069] The user interface 14 may include a screen (e.g., touch screen) allowing bilateral communication with an operator. The user interface 14 may allow the operator to enter commands to act on one or more of the modules 30 of the safety chain, or visualize information received from another device of the safety chain. The user interface 14 may be a handheld device. The user interface 14 may include an emergency stop button, which may be activated by an operator holding the user interface 14.

[0070] In the embodiment shown, the sensor 20 is a light curtain sensor. This is only one possibility, since other sensors could be contemplated, as described herein above. The sensor 20 is communicatively coupled to a first safety module 30. The first safety module 30 is configured for interfacing the sensor 20 with the remainder of the safety chain. The first safety module 30 is communicatively coupled to a second safety module 30. In the embodiment shown, one of the safety modules 30, referred to as the second safety module, is a RSM 80 (as the RSM described above) that is configured for interfacing a robot (here only the control cabinet 12 is shown) with the main controller 15. In the configuration shown, the user interface 14 is serially connected with the emergency stop button module 50, which is serially connected to the RSM 80. The RSM 80 is further communicatively coupled to the control cabinet 12 and to the main controller 15. In the example shown, the RSM 80 is the most downstream safety module 30 of the safety chain. The controller 35 of the first safety module 30 may process the unlabeled signal received from the sensor 20 and, implementing an embedded safety logic, the controller 35 may communicate with the main controller 15 to provide an information about the signal received. The signal transmitted from the first safety module 30 to the main controller 15 may transit through the second safety module, here RSM 80, which is communicatively downstream of the first safety module 30. Since the signal transmitted from the first safety module 30 is labeled, the main controller 15 may identify the source of the labeled signal, in this example, the first safety module 30, even if the labeled signal transited through the RSM 80 before reaching the main controller 15.

[0071] Upon receiving the labeled signal, the main controller 15 may prompt the operator, by conveying an information to the user interface 14, for example, to notify of a safety hazard event associated with a change of state sensed at the sensor 20. The main controller 15 may prompt a control procedure with or without action from the operator (as described above). As another example, the operator may request an emergency stop by activating the emergency stop button of the user interface 14. Actuation of the emergency stop button may convey a signal to the main controller 15, here through the optional emergency stop module 50 and the RSM 80.

[0072] Referring to Fig. 12, another exemplary safety system 16 including a main controller 15, a user interface 14, an emergency stop module 50, and a robot 11 , as those described herein above, will now be described. The safety system 16 includes a main safety chain MSC and an auxiliary chain ACC.

[0073] The main safety chain MSC includes a user interface 14, an emergency stop module 50 (or emergency stop switch), and a plurality of safety modules 30 serially communicatively coupled in a daisy-chain configuration. In Fig. 12, one of the safety modules 30 of the main safety chain MSC is a robot safety module 80 (RSM), as described above, that is configured for interfacing a robot 11 with the main safety chain MSC and / or a main controller 15. The safety modules 30 that are communicatively upstream of the RSM 80 in the main safety chain MSC may be communicatively coupled to respective sensors (not shown), as described herein. The main safety chain MSC may serve as an emergency stop chain. An emergency stop chain in safety systems may also be referred to as a stop category 0 or 1. The main safety chain MSC may thus be configured for triggering an emergency stop if a signal indicative of a safety hazard is outputted at one of the safety modules 30 of the main safety chain MSC and transited through one or more safety modules 30 located downstream in the safety chain MSC, to reach the main controller 15. The safety modules 30, including the RSM 80, may communicate with the main controller 15 as described herein (not repeated for brevity).

[0074] In the safety system 16 shown in Fig. 12, the main safety chain MSC is in parallel with an auxiliary chain ACC. In the safety system 16 shown, the main safety chain MSC and the auxiliary chain ACC are both communicatively coupled to a same RSM 80. As shown, the auxiliary chain ACC includes a plurality of safety modules 30 as described herein. The auxiliary chain ACC could include a single safety module 30, as another possibility. The safety modules 30 of the auxiliary chain ACC in a daisy-chain configuration with a common safety module, here the RSM 80, may operate, and cooperate, to change a state or mode of operation of the robot 11. For example, a signal (e.g. including labeled signal) transmitted by one of the safety modules 30 on the auxiliary chain ACC to the RSM 80 and / or the main controller 15 may prompt a change of operating mode of the robot 11 from a standard operating mode to a collaborative mode (described herein above) or a protective stop mode (described herein above). At the main controller 15, signals received from the safety modules 30 of the auxiliary chain ACC versus those of the main safety chain MSC may be categorized (or weighted differently) so as to provide a relative priority level therebetween. For example, the signals from the safety modules 30 on the auxiliary chain ACC may have a lower priority level relative to the alert signals from the safety modules 30 on the main safety chain MSC. For example, the alert signals received from the auxiliary chain ACC may be labeled as of lower priority, or as corresponding to a less critical hazard than a safety hazard corresponding to signals received from the main safety chain MSC. In an application, a detection of a human circulating at a safe distance with respect to the robot 11 or entering a safety zone for example, may cause the main controller 15 to trigger a change of operating mode of the robot 11 from a standard operating mode (e.g., full speed), to a collaborative mode, a reduced speed mode, or a stop category 2 to avoid injuries in case of collision. Upon detecting a trespassing of the human into an unsafe working area, for example, a stop category 0 or 1 could be triggered. Sensors associated with the main safety chain MSC may thus be positioned in the cell and / or configured to detect the high priority level safety hazard, whereas sensors associated with the auxiliary chain ACC may be positioned in the cell and / or configured to detect low priority level safety hazard.

[0075] The presence of the main safety chain MSC for stop category 0 or 1 and the auxiliary chain ACC for stop category 2, change of operating mode (or protective stop mode) of the robot 11 , or dedicated for other purposes, is one safety chain configuration possibility, which may allow to dedicate a physically distinct safety chain to robot controls and maintain a main safety chain for emergency stops, for safety reasons.

[0076] The safety chains MSC, ACC described above includes safety modules 30, 80 with controller 35, 85 having the communication capability with signal labeling with an emergency stop button module 50 without or without such communication capability. As such, in some embodiments, the emergency stop button module 50 may convey an unlabeled signal to a safety module immediately downstream thereof and, upon receiving such unlabeled signal, the safety module 30, 80 may assign a label indicative of such signal to inform the main controller 15 that the emergency stop button module 50 was triggered. In some embodiments, for example, the safety module 30, 80 (e.g., via their controller 35, 85) may be configured to detect an unlabeled signal from another safety module and associate such unlabeled signal to that safety module that conveyed an unlabeled signal. In an example, an emergency stop button module 50, which may not have the communication capability described above (signal labeling capability), may convey only an unlabeled signal to the safety module 30, 80 immediately communicatively downstream thereof and such unlabeled signal may trigger the generation of a labeled signal at that safety module 30, 80. Stated differently, one or more modules 30, 80 may be pre-programmed, or have a safety logic embedded therein that, upon receiving an unlabeled signal, generate a labeled signal with a default label associated with the unlabeled signal received, where such default label, once received by the main controller 15, can be associated as a label corresponding to the emergency stop button module 50. Accordingly, in some configurations, a module without the capabilities described above to generated a labeled signal to identify itself or a module / sensor communicatively upstream thereof in a daisy chain configuration can be part of a safety system including a plurality of safety modules as described herein. However, in some variants, only safety modules with such capability of signal labeling could be daisy-chained as part of a safety chain MSC, ACC.

[0077] Figs. 13A to 13C illustrate an exemplary safety system 16 including safety modules 30 as described above in a daisy-chain configuration, and a visual representation of an unlabeled signal 17A transmitted by a sensor 20 of the safety system 16 and of a labeled signal 17B with a label associated with an event detected at a sensor 20 of the safety system 16. Fig. 13A shows a plurality of safety modules 30 in a daisy-chain configuration. A serial communication link 18 is shown and includes the safety modules 30, and wiring connection between them, and the main controller 15. The safety modules 30 form part of the serial communication link 18 in that they may act as a hub through which information / signals may transit along the daisy chain. Sensors 20 are associated with respective safety modules 30, though there could be more than one sensor 20 on a same safety module 30. While safety modules 30 are identified, one or more modules could be modules described as RMS 80 herein. Upon detecting an event at one of the sensors 20, an unlabeled signal 17A (Fig. 13B) can be transmitted downstream along the communication link 18 towards the safety module 30 connected to such sensor 20 and configured to receive signal therefrom. In Fig. 13B, such an unlabeled signal 17A is illustrated, on a graph (with arbitrary units). An indication EDS that an event is detected at the sensor 20 is represented as a step function, for illustrative purpose only. The indication of an event detected at the sensor 20 could trigger a pulse signal, or other types of signal defining a variation in a signal, such as a variation in voltage, current, etc., or other types of signal variation. The safety module 30 receiving such unlabeled signal 17A can generate a labeled signal 17B including a label associated with the detection of the event at the sensor 20. In Fig. 13C, such a labeled signal 17B is illustrated, on a graph (with arbitrary units) similar to that in Fig. 13B. The indication EDS that an event is detected at the sensor 20 is identified, and a label is generated. The label can be a signal modifier, a signal identifier, and / or header applied to the unlabeled signal 17A, for instance. The label may allow to identify the sensor 20 from which the unlabeled signal 17A originates, and / or allow to identify the safety module 30 from which the labeled signal 17B is generated, for example. The safety module 30 having generated the labeled signal 17B may then transmit such labeled signal 17B downstream along the communication link 18 towards the main controller 15. Such labeled signal 17B may be transmitted through other safety modules 30 downstream on the communication link 18 before reaching the main controller 15, as discussed above, or trigger the generation of a labeleled signal in a cascading manner at the following safety module 30 immediately downstream thereof, as discussed above. A safety module 30 downstream on the communication link 18 with respect to the safety module 30 from which the labeled signal 17B was generated and transmitted can transmit “as is” said labeled signal 17B further downstream on the communication link 18, either directly to the main controller 15 or to another daisy chained safety module 30, though this is only one possibility, as mentioned above. More than one of the safety modules 30 can receive an unlabeled signal 17A from a respective sensor 20, and generate a labeled signal 17B upon the detection of an event at the respective sensor 20. A safety module 30 may receive a plurality of labeled signals 17B from upstream in the communication link 18, and repeating these labeled signals 17B downstream along the communication link 18. The so-transmitted labeled signals 17B may be transmitted unaltered or be repeated as is before retransmitting downstream along the communication link 18. A safety module 30 may generate its own labeled signal 17B and receive from upstream the labeled signal 17B generated by another safety module 30, then transmit these labeled signals 17B downstream along the communication link 18. It is intended that instead of repeating the labeled signal 17B received from upstream along the communication link 18, any given safety module 30 may generate a new labeled signal in response to the reception of an original labeled signal from an upstream one of the safety modules 30. The new label signal can include a new label which may include the label from the original labeled signal, in addition to some other new information, for example, and transmit it downstream along the communication link 18.

[0078] Fig. 14 is a block diagram of a safety management method 1400 for controlling a unit of an automated machinery cell via a safety system 16, such as the example represented at Fig. 13A. A serial communication link 18 including at least a sensor 20, a safety module 30, and a main controller 15 of an automated machinery cell 10 is established (1402). The communication link 18 between the modules 30 and the main controller 15 may be implemented by wiring. Wireless connection could also be contemplated for the transmission of certain information between the safety modules 30, 80, and main controller 15. Upon detecting an event at the sensor 20, a first unlabeled signal 17A (Fig. 13B) is transmitted downstream along the communication link 18 towards the safety module 30 (1404). The safety module 30 receives the first unlabeled signal 17A from the sensor 20, generates a first labeled signal 17B (Fig. 3C) including a first label associated with the detection of the event at the sensor 20, and transmits the first labeled signal 17B downstream along the communication link 18 towards the main controller 15 (1406). The safety module 30 may receive a second labeled signal 17B (Fig. 3C) from the communication link

[0079] 18 and may transmit the second labeled signal 17B as is downstream along the communication link 18 (1408). The main controller 15 receives the first labeled signal 17B, identifies the first label in the first labeled signal 17B, and determines a first safety action (e.g., emergency stop, change of operating mode of the automated machinery cell, prompting a user via a user interface) to be performed when the event is detected at the sensor 20 based on a safety logic stored in the main controller 15 (1410). While the labeled signal 17B may provide more information than the unlabeled signal 17A by the presence of the label, the safety action may be taken upon receiving an unlabeled signal (or only taking into account the unlabeled part of the labeled signal). Stated otherwise, the label may provide context on a detected event, to generate prompt for acting on such events, and the unlabeled part of the labeled signal may be processed to prompt the safety action. The main controller 15 may then control a unit, by transmitting one or more control signal(s)

[0080] 19 of the automated machinery cell 10 in accordance with the first safety action. A second, a third, a fourth (and so on) safety action can simultaneously or subsequently occur, for example when an event is detected at a plurality of sensors 20, or multiple events are detected at a same sensor 20.

[0081] Having the safety modules 30 as standalone physical modules instead of, for example, conventional safety cabinets may allow to position the safety modules at physically different locations within the machinery cell, regardless of where the main controller 15 is located in the environment of the machinery cell. In addition, a safety module 30 can be placed physically close to the sensors associated with it to reduce the wiring encumbrance. Such decentralization of the safety modules 30 from the main controller 15, or a convention custom safety cabinet for example, may result in savings in wiring and installation time, and also allow for modifications to a machinery cell layout by moving sensors, modules, etc., and / or physically resizing a cell to adapt it to a given task or operation, etc. This design flexibility may allow more efficient adaptation of a safety system, e.g., more efficient than with conventional custom cabinets which may be designed for a single application or a single predetermined machinery cell layout.

[0082] The modularity of the safety system 16 that is achieved by the safety modules 30 and safety ecosystem disclosed herein may also advantageously allow to establish a network of daisy- chained safety modules 30 on a same communication link, physically placed at different locations within the environment of the machinery cell. The communication ability of the safety modules 30 that allows the transmission of labeled signals through one or more daisy-chained safety modules 30 may also reduce wiring and facilitate the installation of the safety system. The ability to communicate through other modules 30 may also allow for the creation of complex safety systems, with chains dedicated to emergency stops and one or more parallel chains connecting a line of modules with their sensors associated with lower-level hazard events, yet in a more design intuitive manner.

[0083] In accordance with the above, there is disclosed a safety system 16 for the safety management of an automated machinery cell 10. The safety system 16 includes a communication link 18 (e.g., wired or wireless connection(s), series of communicatively coupled devices defining parts of a continuous communication link 18 through which information signal may transit) and at least one sensor 20 configured for transmitting, upon detection of an event (e.g., safety hazard), an unlabeled signal 17A downstream along the communication link 18. The daisy-chain system includes a safety module 30 (at least one, but preferably more to benefit from certain advantages of a daisy-chain configuration as described herein) communicatively coupled to the sensor 20 via the communication link 18 and immediately downstream of the sensor 20 along the communication link 18. The safety module 30 has a processor, and a non-volatile computer memory having instructions stored thereon. In operation, the execution of these instructions by the processor may allow the safety module 30 to perform the following steps: receiving the unlabeled signal 17A from the sensor 20, generating a labeled signal 17B including a label associated with the detection of the event at the sensor 20, and transmitting the labeled signal 17B downstream along the communication link 18.

[0084] The safety system 16 includes a main controller 15, communicatively coupled to the safety module 30 via the communication link 18 and downstream of the safety module 30 along the communication link 18. The main controller 15 is configured for receiving the labeled signal 17B, identifying the label in the labeled signal 17B, determining a safety action to be performed when the event is detected at the sensor 20 based on a safety logic stored in the main controller 15, and controlling a unit 11 of the automated machinery cell 10 in accordance with the safety action. The labeled signal 17B may be received at the main controller 15 which, via processing of the received signal, may act to prompt a control procedure and / or prompt an operator to inform hi m / her / it of the occurrence of the detected event.

[0085] According to various embodiments, the modular safety system 16 includes a plurality of safety modules 30 serially connected to one another upstream of the main controller 15 along the communication link 18. A safety module 30 may receive a labeled signal 17B from a another safety module 30 upstream on the communication link, and transmit the labeled signal 17B received therefrom downstream along the communication link 18. The transmission / retransmission of such labeled signal may include no modification to that labeled signal 17B. The communication ports (input / output ports) may be configured to receive and / or transmit information / signal. While references were made to input and output ports, it is understood that each input / output port may allow bilateral communication. More than one safety modules 30 along the communication link 18 may be communicatively coupled with respective sensors 20 to receive signals therefrom. As such, a safety module 30 in the daisy chain may receive an unlabeled signal 17A from a sensor 20 communicatively coupled to such safety module 30, and such safety module 30 may generate a labeled signal 17B including a label associated with the detection of an event at said sensor 20, and receive the labeled signal 17B from a safety module 30 upstream thereof along the communication link 18. The safety module 30 may transmit the labeled signal 17B from that other safety module 30 upstream along the communication link 18 and the labeled signal 17B that it generated, downstream along the communication link 18. As mentioned above, an unlabeled signal can be generated and transmitted by the safety module 30 having generated the labeled signal 17B (sequentially or simultaneously). Such unlabeled signal may be transmitted downstream along the communication link 18 to reach a subsequent safety module in the chain, etc., as mentioned above.

[0086] In at least some cases, a robot safety module 80 may be communicatively coupled to the safety module 30 downstream thereof along the communication link 18. The safety module 80 part of the communication link 18 may receive from an actuated unit (e.g., robot 11) of the automated machinery cell 10 a signal indicative of a default event at the actuated unit or an operating mode of the actuated unit, and the safety module 80 may process the signal received from said actuated unit, and transmit the processed signal received from the actuated unit to the main controller 15. The robot safety module 80 may receive labeled signals from upstream, and act as a transit for such labeled signal towards the main controller 15. In some embodiments, the safety module 80 may receive signals (from a sensor or from another safety module) and take safety actions toward the actuated unit without waiting for a prompt signal from the controller 15.

[0087] In at least some cases, in which the modular safety system 16 includes a plurality of safety modules 30, a first set of safety modules 30 may be communicatively coupled to each other to define a main safety chain MSC, a second set of safety modules 30 may be communicatively coupled to each other to define an auxiliary chain ACC. The main safety chain MSC and the auxiliary chain ACC may form part of a safety topology where they are both communicatively coupled to a common safety module of the plurality of safety modules 30 so as to have the main safety chain MSC and the auxiliary chain ACC communicatively coupled parallel to each other. The common safety module may interface an actuated unit with the main controller 15, and the main safety chain MSC and the auxiliary chain ACC with the actuated unit and / or the main controller 15. The common safety module may be a robot safety module 80 as described herein, and be configured to receive from the actuated unit a signal indicative of a default event at the actuated unit or an operating mode of the actuated unit, processing the signal received from the actuated unit, and transmitting the processed signal received from the actuated unit to the main controller 15. In at least some cases, the common safety module may be configured to receive an actuated unit operation signal from the main controller 15, and transmit the actuated unit operation signal to the actuated unit. In a daisy chain configuration as described herein, the common safety module may be configured to: receive the labeled signal 17B of a safety module 30 upstream thereof; transmit the received labeled signal 17B downstream on the communication link 18 to the main controller 15; receive an actuated unit operation signal from the main controller 15; and cause a change of operating mode of the actuated unit based on the labeled signal 17B and / or the actuated unit operation signal. Upon receiving a labeled signal 17B from any one of the safety modules 30 of the auxiliary chain ACC at the common safety module or the main controller 15, the common safety module may prompt a change of operating mode of the actuated unit. Upon receiving a labeled signal 17B from any one of the safety modules 30 of the main safety chain MSC at the common safety module or the main controller 15, the common safety module is configured to trigger an emergency stop of the automated machinery cell 10.

[0088] Yet in accordance with the above, there is disclosed a safety module 30 for a daisy-chain system having a communication link 18, a sensor 20 (at least one) configured for transmitting, upon detection of an event (e.g., safety hazard), an unlabeled signal 17A downstream along the communication link 18, and a machine control system (e.g., control cabinet 12) communicatively coupled to the communication link 18 and configured for controlling an actuated unit (e.g., robot 11). The safety module 30 has a housing 31 , at least one input port 32 communicatively couplable to the sensor 20 via the communication link 18, and at least one output port 33 communicatively couplable to the machine control system via the communication link 18. The safety module 30 has a controller 35, for example including a processor, and a non-volatile computer memory having instructions stored. In operation, the execution of these instructions by the controller 35 may allow the safety module 30 to perform the following steps: receiving the unlabeled signal 17A from the sensor 20 via the input port 32, generating a labeled signal 17B including a label associated with the detection of an event at the sensor 20, and transmitting the labeled signal 17B downstream along the communication link 18 via the output port 33.

[0089] As can be understood, the examples described above and illustrated are intended to be exemplary only. The scope is indicated by the appended claims.

Claims

CLAIMS1. A modular safety system for an automated machinery cell, the modular safety system comprising: a communication link; a sensor configured for transmitting, upon detection of an event, an unlabeled signal downstream along the communication link; a safety module communicatively coupled to the sensor via the communication link and immediately downstream of the sensor along the communication link, the safety module having a module controller configured for: receiving the unlabeled signal from the sensor, generating a labeled signal including a first label associated with the detection of the event at the sensor, and transmitting the labeled signal downstream along the communication link; and a main controller communicatively coupled to the safety module via the communication link and downstream of the safety module along the communication link, the main controller configured for receiving the labeled signal, identifying the first label in the labeled signal, and determining a safety action to be performed at a unit of the automated machinery cell when the event is detected at the sensor.

2. The modular safety system of claim 1 , wherein the safety module is configured for generating and transmitting an unlabeled signal downstream along the communication link in addition to the labeled signal, the main controller configured for controlling the unit of the automated machinery cell in accordance with the safety action upon receiving the unlabeled signal.

3. The modular safety system of claim 1 , wherein the safety module is configured for receiving other labeled signals and repeating or transmitting the one or more other labeled signals further downstream along the communication link.

4. The modular safety system of any one of claims 1 and 2, wherein the unlabeled signal has at least one of an output signal switching device (OSSD) signal, redundant dry contacts, a safety protocol over EtherCAT or a safety protocol over EtherNet.

5. The modular safety system of any one of claims 1 to 4, wherein the unlabeled signal is an unlabeled coded signal.

6. The modular safety system of any one of claims 1 to 5, wherein the modular safety system includes a plurality of safety modules serially connected to one another upstream of the main controller along the communication link, the safety module being a first safety module of the plurality of safety modules and the labeled signal being a first labeled signal, wherein the module controller is further configured for: receiving a second labeled signal from a second safety module of the plurality of safety modules, the second safety module upstream of the first safety module along the communication link; and transmitting the second labeled signal from the second safety module downstream along the communication link, said transmitting the second labeled signal including no modification to the second labeled signal.

7. The modular safety system of any one of claims 1 to 5, wherein the safety module is a first safety module, the sensor is a first sensor, the module controller is a first module controller and the unlabeled signal is a first unlabeled signal, the first safety module having a housing enclosing the first module controller, a first communication port communicatively coupled to the sensor and a second communication port communicatively coupled to the communication link downstream of the first safety module, the modular safety system further comprises at least a second safety module connected serially downstream of the first safety module along the communication link and a second sensor communicatively coupled to the second safety module, the second safety module having: a housing having a third communication port communicatively coupled to the second communication port via the communication link, and a fourth communication port communicatively coupled to the second sensor, the second safety module having a second module controller configured for: receiving a second unlabeled signal from the second sensor or the first safety module, generating a second labeled signal including a second label associated with a detection of another event at the second sensor or at the first safety module, receiving the labeled signal from the first safety module, and transmitting thelabeled signal and the second labeled signal downstream along the communication link.

8. The modular safety system of any one of claims 1 to 5, wherein the safety module is a first safety module, the sensor is a first sensor, the module controller is a first module controller and the unlabeled signal is a first unlabeled signal, the first safety module having, the first safety module having a housing enclosing the first module controller, a first communication port communicatively coupled to the first sensor and a second communication port communicatively coupled to the communication link downstream of the first safety module, the modular safety system further comprises at least a second safety module connected serially downstream of the first safety module along the communication link, the second safety module configured for interfacing the unit with the main controller, the second safety module having: a housing having a third communication port communicatively coupled to the second communication port via the communication link, and at least a fourth communication port communicatively coupled downstream on the communication link, the second safety module having a second module controller configured for: receiving from the unit a unit signal indicative of a default event at the unit or an operating mode of the unit, processing the unit signal received from the unit, and transmitting the processed unit signal received from the unit to the main controller.

9. The modular safety system of any one of claims 1 to 5, wherein the safety module is part of a plurality of safety modules of the modular safety system, the plurality of safety modules configured for interfacing respective sensors with the main controller via the communication link, the plurality of safety modules serially communicatively coupled in a daisy-chain configuration, the plurality of safety modules including: a first set of safety modules communicatively coupled to each other to define a main safety chain, a second set of safety modules communicatively coupled to each other to define an auxiliary chain, the main safety chain and the auxiliary chain both communicatively coupled to a common safety module of the plurality of safety modules so as to have the main safety chain and the auxiliary chain parallel to each other, the common safety module configured for interfacing the unit with the main controller.

10. The modular safety system of claim 9, wherein the common safety module has a common module controller configured for:receiving from the unit a unit signal indicative of a default event at a robot or an operating mode of the robot, processing the unit signal received from the unit, and transmitting the processed signal received from the unit to the main controller.11 . The modular safety system of claim 10, wherein the common module controller of the common safety module is further configured for: receiving a unit operation signal from the main controller, and transmitting the unit operation signal to the robot.

12. The modular safety system of claim 9, wherein the common safety module has a common module controller configured for: receiving the labeled signal of the safety module of the plurality of safety modules, transmitting or repeating the labeled signal downstream on the communication link towards the main controller, receiving a unit operation signal from the main controller, and causing a change of operating mode of the unit based on the labeled signal and / or the unit operation signal.

13. The modular safety system of claim 9, wherein upon receiving the labeled signal from any one of the safety modules of the auxiliary chain at the common safety module or the main controller, the common safety module is configured to prompt a change of operating mode of a robot.

14. The modular safety system of claim 9, wherein upon receiving the labeled signal from any one of the safety modules of the main safety chain at the common safety module or the main controller, the common safety module is configured to trigger an emergency stop of the automated machinery cell.

15. The modular safety system of any one of claims 1 to 14, wherein the automated machinery cell includes a machine control system configured to supply power to and operate the unit, the main controller configured for controlling the unit through communication with the machine control system interfacing with the unit.

16. A safety module for a daisy-chain safety system of an automated machinery cell, the daisychain system having a communication link, a sensor configured for transmitting, upon detectionof an event, an unlabeled signal downstream along the communication link, and a main controller communicatively coupled to the communication link, the safety module comprising: a housing; an input port communicatively couplable to the sensor via the communication link; an output port communicatively couplable to the main controller via the communication link; a processor, and a non-volatile computer memory having instructions stored thereon which when executed by the processor cause the safety module to perform the steps of: receiving the unlabeled signal from the sensor via the input port, generating a labeled signal including a first label associated with the detection of the event at the sensor, and transmitting the labeled signal downstream along the communication link via the output port.

17. The safety module of claim 16, wherein the steps further comprises generating and transmitting another unlabeled signal downstream along the communication link in addition to the labeled signal, the main controller configured for controlling a unit of the automated machinery cell in accordance with a safety action upon receiving the unlabeled signal.

18. A daisy chainable safety module for a modular safety system of an automated machinery, comprising: a housing; a plurality of input ports and at least one output port mounted to the housing; a controller in the housing and communicatively coupled to the plurality of input ports and to the at least one output port, the plurality of input ports configured to receive signals from at least one sensor or another daisy chainable safety module communicatively upstream in a safety chain of the modular safety system and communicatively couplable to at least one of the plurality of input ports, the at least one output port configured to transmit signals downstream in the safety chain towards a main controller of the modular safety system via the at least one output port, the controller configured for:receiving a signal from at least one input port of the plurality of input ports; processing the signal according to a predetermined safety logic stored on a non- transitory memory of the controller, said processing including at least one of: upon determining that the signal is labeled, transmitting the signal downstream in the safety chain via the at least one output port; and upon determining that the signal is unlabeled, generating a labeled signal including a label associated with a detection of an event at the at least one sensor, and transmitting said generated labeled signal downstream in the safety chain towards the main controller.

19. The daisy chainable safety module of claim 18, wherein the controller is further configured for generating and transmitting an unlabeled signal downstream in the safety chain towards the main controller in addition to the generated labeled signal, the main controller configured for controlling a unit of the automated machinery in accordance with a safety action upon receiving the unlabeled signal.

Citation Information

Patent Citations

  • Modular safety control

    EP2312408B1

  • Modular safety monitoring and warning system and methods for use thereof

    US10409252B2

  • Configurable modular safety system

    US7395123B2