Fail-Safe Analog Output Read-Back for SIL3 Actuator Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current safety-related control systems in automation lack fail-safe analog value regulation, as digital outputs do not provide sufficient safety for analog actuators, despite the need for safe states to prevent harm to operators.
Innovation Solution
A method and system that convert digital output values into analog values using a converter, with a read-back device applying fail-safe criteria to ensure the output is safe, involving dual-channel designs and safety protocols like PROFI Safe, and comparing values to initiate safety actions if deviations occur.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If digital output values are used for control, then device complexity is reduced and ease of operation is improved, but fail-safe analog regulation capability is lost
Solution Approach 1:
The patent introduces a converter as an intermediary device that translates digital output values into analog output values. This converter acts as a mediator between the digital control system and analog actuators, enabling fail-safe analog regulation while maintaining the simplicity of digital control interfaces. The converter includes internal safety mechanisms that ensure reliable operation without complicating the user interface.
Solution Approach 2:
The system is segmented into distinct functional modules: a control unit for digital processing, a converter for digital-to-analog translation with embedded safety logic, and a release device for final output control. This segmentation allows each module to specialize in its function, maintaining operational simplicity while achieving fail-safe capability through distributed safety mechanisms.
2Productivity
If analog output values are provided directly without verification, then productivity is improved and device complexity is reduced, but safety is compromised
Solution Approach 1:
The patent implements a feedback mechanism where the analog output value is converted back into a digital value and fed back to the control unit for verification. This closed-loop feedback enables continuous plausibility checks without significantly impacting productivity, as the verification process occurs in parallel with the control cycle. The feedback ensures safety by detecting deviations between commanded and actual output values.
Solution Approach 2:
The system performs preliminary safety verification by converting the analog output back to digital and comparing it with the original digital output value before the analog value is fully utilized by the actuator. This preliminary check prevents unsafe operations from occurring, maintaining both safety and productivity by avoiding rework from unsafe states.
3Reliability
If dual-channel verification and plausibility checks are implemented, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent merges the safety verification functions into the converter module itself, rather than requiring separate external verification systems. The converter integrates the digital-to-analog conversion, the analog-to-digital read-back conversion, and the plausibility check logic in a single unified device. This merging achieves high reliability through dual-channel verification while minimizing the increase in overall system complexity by consolidating functions.
4Reliability
If fail-safe criteria are applied to analog output, then safety is improved, but ease of manufacture worsens
Solution Approach 1:
The converter is designed as a universal module that can be integrated into various control systems regardless of the specific actuator type or application. By creating a standardized fail-safe converter with integrated safety logic and dual-channel verification, the system achieves high safety standards without requiring custom-manufactured solutions for each application. This multi-functionality improves ease of manufacture through standardization while maintaining rigorous safety criteria.
Data Source
AI summary
A method for fail-safe provision of an analog output value for a control process designed for functional safety, wherein the output value is specified by a control unit as a digital output value and, in a first step, the digital output value is converted into the analog output value via a converter, in a second step, the analog output value is converted into a fail-safe digital output value using fail-safe criteria via a read-back device and, in a third step, the originally provided digital output value is compared with the converted fail-safe digital output value, where in the event of the comparison revealing a deviation or of a plausibility criterion being infringed, a safety action is performed, otherwise, the analog output value is output to the control process with the aid of a release device.


