Connection Module Local Status Memory for Automatic Restart
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face high re-commissioning effort due to unnecessary shutdowns triggered by communication failures between input modules and controllers, requiring manual actuation of acknowledgment devices, even for apparent faults, leading to inefficiency.
Innovation Solution
The connection modules monitor and store safety-relevant status information during communication failures, allowing the system to restart automatically without local acknowledgment if no actual fault occurred, reducing manual intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the system shuts down upon communication failure between input module and controller, then safety is improved, but re-commissioning effort increases
Solution Approach 1:
The input module autonomously monitors sensor status during communication failures and stores safety-relevant status information locally, enabling the system to self-assess whether a shutdown was necessary without requiring manual intervention or travel to the controller location
Solution Approach 2:
The input module performs preliminary monitoring and stores safety status information during the communication failure period before restart is attempted, allowing the controller to make informed restart decisions without requiring manual inspection
2Reliability
If manual acknowledgment is required for system restart after safety shutdown, then safety is ensured, but operational efficiency decreases
Solution Approach 1:
The controller receives feedback about safety-relevant status information that was stored during the communication failure period, allowing it to automatically determine whether the shutdown cause has been resolved and whether restart is safe without requiring manual acknowledgment
Solution Approach 2:
The system automatically determines restart eligibility by evaluating stored safety status information, eliminating the need for manual acknowledgment and enabling autonomous recovery from communication failures
3Adaptability or versatility
If the controller is located far from the local safety zone, then system architecture flexibility is improved, but restart complexity increases
Solution Approach 1:
The monitoring function is segmented from the controller and placed in the input module at the local safety zone, allowing the controller to be located remotely while the input module independently monitors and stores safety status information locally
Solution Approach 2:
The input module acts as an intermediary between the sensor and controller, storing safety-relevant status information locally during communication failures and transmitting it to the controller when communication is restored, eliminating the need for manual travel between locations
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a system for the safe control of systems, machines, or the like. The system comprises the following components: a controller (1), at least one connected terminal assembly (2A, 2B), and at least one sensor (4A) or actuator (4B) connected to the terminal assembly (2A, 2B). The terminal assembly (2A, 2B) is located within a local safety zone, spatially separated from that of the controller (1), and monitors the status of the connected sensor/actuator. When safety-relevant status information is received, a signal is sent to the controller (1), triggering a safety request in the controller. A disruption in communication between the terminal assembly (2A, 2B) and the controller (1) also triggers a safety request in the controller (1). The system includes a manually operable local and a global acknowledgment device (6A, 6B).The connection module (2A, 2B) also performs status monitoring in the event of a communication failure and stores the occurrence of safety-relevant status information during the duration of the communication failure as a status memory value. After communication is re-established, the controller (1) receives the status memory value from the connection module (2A, 2B) and uses this value to decide whether to restart the system.