Redundant Machine Control Circuit for Safety on Standard Industrial PCs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current safety-critical automation tasks require dedicated hardware, such as fail-proof PLCs, which are expensive and difficult to obtain, limiting their implementation on standard industrial hardware.
Innovation Solution
A circuit arrangement using two electronic computing devices with internal and external data sensors, where the devices are redundant and communicate to ensure safe operation, allowing safety-critical functions to be executed on standard industrial PCs without dedicated hardware, enabling seamless upgrades and fault tolerance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated hardware such as fail-safe PLC is used for safety-critical automation tasks, then reliability and safety are improved, but cost and device complexity increase
Solution Approach 1:
The patent creates a virtual copy of the safety function by implementing a safety management virtual machine that runs on standard hardware. This virtual machine replicates the safety-critical control logic that would traditionally require dedicated fail-safe PLC hardware, thereby maintaining reliability while eliminating the need for specialized complex hardware.
Solution Approach 2:
The patent replaces the mechanical/electrical dedicated hardware system (fail-safe PLC) with a software-based virtual machine system running on standard industrial PCs. This substitution uses software abstraction layers and virtualization technology to achieve the same safety functions without the physical complexity of dedicated safety hardware.
2Reliability
If dedicated fail-safe PLC hardware is used, then safety-critical functions can be executed reliably, but availability and ease of upgrade are reduced
Solution Approach 1:
The patent implements a dynamic safety management system where the safety control logic is contained in a virtual machine that can be dynamically loaded, updated, and replaced without hardware changes. This allows the safety system to adapt to new requirements and be upgraded seamlessly, unlike static dedicated hardware which requires physical replacement for any logic changes.
Solution Approach 2:
The safety management virtual machine is designed to be universal, capable of running on any standard industrial PC hardware platform. This universality allows the same safety software to be deployed across different hardware configurations and enables easy migration and upgrade paths without being locked into proprietary hardware architectures.
3Device complexity
If standard industrial hardware is used for safety-critical tasks, then cost is reduced and adaptability is improved, but reliability and safety assurance are worsened
Solution Approach 1:
The patent introduces a safety management virtual machine as an intermediary layer between the standard hardware and the safety-critical control functions. This virtual machine acts as a mediator that ensures safety requirements are met by implementing safety logic, monitoring, and control mechanisms in software, thereby assuring reliability even when running on non-dedicated standard hardware.
Solution Approach 2:
The system implements prior cushioning by incorporating safety monitoring and fault detection mechanisms within the virtual machine that proactively identify and respond to potential failures before they compromise safety. This includes redundant safety logic and emergency stop capabilities that are pre-configured to protect against hardware failures.
Data Source
Figure 1~2

AI summary
The invention relates to a circuit arrangement (16) comprising a first electronic computing unit (18) for generating a first control signal (20), wherein the first electronic computing unit (18) has an internal first data sensor (22) for generating a first safety signal (26) for a safety device (14), wherein the circuit arrangement (16) has a second electronic computing unit (28) configured for generating a second control signal (30), wherein the second electronic computing unit (28) has an internal second data sensor (32) for generating a second safety signal (36), wherein the first electronic computing unit (18) has an external second data sensor (38) coupled to the internal second data sensor (32), and wherein the second electronic computing unit (28) has an external first data sensor (40).which is coupled to the internal first data sensor (22), and wherein a respective safety signal (26, 36) can additionally be generated by the external first data sensor (40) and/or the external second data sensor (38).