Redundant Safety Control Logic for Fail-Operate Modes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current safety control systems in discrete manufacturing often result in unnecessary machine stops during temporary failures of sensors or communication issues, leading to reduced productivity due to treating failure situations the same as hazard situations, even if no hazard is detected.
Innovation Solution
A safety control system with redundant sensor subsystems that activates different modes of operation based on the availability of these subsystems, allowing for normal, fail-stop, or fail-operate modes to minimize productivity loss while maintaining safety, by switching to redundant devices or functions during failures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the control logic treats failure situations the same as hazard situations by activating emergency stop, then safety is maintained, but productivity is reduced due to unnecessary machine stops
Solution Approach 1:
The patent segments the response to safety events by distinguishing between hazard situations and failure situations. The control logic is divided into separate evaluation paths: one for hazards that require emergency stop, and another for failures that may allow continued operation in a degraded mode. This segmentation allows the system to apply appropriate responses based on the specific situation, avoiding unnecessary productivity loss while maintaining safety.
Solution Approach 2:
The patent implements dynamic response selection based on the type of situation detected. Instead of a static emergency stop response for all safety events, the system dynamically selects between emergency stop (for hazards) and degraded operation (for temporary failures). The control logic adapts its behavior based on real-time assessment of whether the situation represents a true hazard or a recoverable failure, enabling productivity maintenance when safe.
2Reliability
If the machine is stopped in case of temporary sensor failures, then safety is ensured, but production losses occur due to unnecessary stops
Solution Approach 1:
The patent employs feedback mechanisms where the control logic continuously monitors sensor availability and system state. When a failure is detected, the system provides feedback to switch to degraded operation mode rather than stopping. The feedback loop tracks whether the failure is temporary or persistent, allowing the system to maintain operation during transient failures while still responding to genuine hazards, thereby reducing production losses without compromising safety.
3Adaptability or versatility
If redundant sensor subsystems are implemented to distinguish failure situations from hazard situations, then better decision-making is enabled, but device complexity increases
Solution Approach 1:
The patent implements multi-functionality in the control logic that handles both hazard detection and failure detection through a unified evaluation framework. The same control unit that monitors for hazards also evaluates sensor availability and communication status. This universal approach allows the system to distinguish between hazard situations and failure situations without requiring entirely separate systems, reducing overall complexity while maintaining advanced decision-making capability.
Data Source
AI summary
A safety control system has a control unit with safety control logic, a safety sensor arrangement, a machine arrangement operable in different operation modes, each operation mode having a different productivity, the control unit receiving and evaluating input from the safety sensor arrangement, and, in reaction to evaluation result(s), activating an operation mode determined by the safety control logic, the safety sensor arrangement having at least two functionally redundant subsystems, control unit input including information indicating availability of the functionally redundant subsystems, the control logic being configured to activate normal operation mode with normal productivity if input indicates availability of all subsystems, activate fail-stop operation mode with zero productivity if input indicates unavailability of all subsystems, activate fail-operate operation mode with productivity less than normal but above zero if input indicates at least temporary unavailability of at least one and availability of at least another one of the subsystems.


