Connection Module Local Status Memory for Automatic Restart

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face high re-commissioning effort due to unnecessary shutdowns triggered by communication failures between input modules and controllers, requiring manual actuation of acknowledgment devices, even for apparent faults, leading to inefficiency.

Innovation Solution

The connection modules monitor and store safety-relevant status information during communication failures, allowing the system to restart automatically without local acknowledgment if no actual fault occurred, reducing manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system shuts down upon communication failure between input module and controller, then safety is improved, but re-commissioning effort increases

Engineering Contradiction:
ImprovesafetyVSAvoidre-commissioning effort
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The input module autonomously monitors sensor status during communication failures and stores safety-relevant status information locally, enabling the system to self-assess whether a shutdown was necessary without requiring manual intervention or travel to the controller location

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The input module performs preliminary monitoring and stores safety status information during the communication failure period before restart is attempted, allowing the controller to make informed restart decisions without requiring manual inspection

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual acknowledgment is required for system restart after safety shutdown, then safety is ensured, but operational efficiency decreases

Engineering Contradiction:
ImprovesafetyVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The controller receives feedback about safety-relevant status information that was stored during the communication failure period, allowing it to automatically determine whether the shutdown cause has been resolved and whether restart is safe without requiring manual acknowledgment

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system automatically determines restart eligibility by evaluating stored safety status information, eliminating the need for manual acknowledgment and enabling autonomous recovery from communication failures

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If the controller is located far from the local safety zone, then system architecture flexibility is improved, but restart complexity increases

Engineering Contradiction:
Improvesystem architecture flexibilityVSAvoidrestart complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The monitoring function is segmented from the controller and placed in the input module at the local safety zone, allowing the controller to be located remotely while the input module independently monitors and stores safety status information locally

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The input module acts as an intermediary between the sensor and controller, storing safety-relevant status information locally during communication failures and transmitting it to the controller when communication is restored, eliminating the need for manual travel between locations

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2919086B1System for secure control of machines, facilities or similar
Publication Date: 2019.07.24 PHOENIX CONTACT GMBH & CO KG
  • EP2919086B1 patent drawingFigure 1
  • EP2919086B1 patent drawingFigure 2
  • EP2919086B1 patent drawingFigure 3

AI summary

The invention relates to a system for the safe control of systems, machines, or the like. The system comprises the following components: a controller (1), at least one connected terminal assembly (2A, 2B), and at least one sensor (4A) or actuator (4B) connected to the terminal assembly (2A, 2B). The terminal assembly (2A, 2B) is located within a local safety zone, spatially separated from that of the controller (1), and monitors the status of the connected sensor/actuator. When safety-relevant status information is received, a signal is sent to the controller (1), triggering a safety request in the controller. A disruption in communication between the terminal assembly (2A, 2B) and the controller (1) also triggers a safety request in the controller (1). The system includes a manually operable local and a global acknowledgment device (6A, 6B).The connection module (2A, 2B) also performs status monitoring in the event of a communication failure and stores the occurrence of safety-relevant status information during the duration of the communication failure as a status memory value. After communication is re-established, the controller (1) receives the status memory value from the connection module (2A, 2B) and uses this value to decide whether to restart the system.