Safety Controller Identifier Verification for Automation Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In industrial automation, ensuring safe commissioning and exchange of safety-relevant participants in automation networks is challenging due to the risk of incorrect configuration imports and the high organizational effort required, especially when multiple networks with different safety controllers are coupled.
Innovation Solution
Assigning an identifier to the safety controller and using a master participant to check if it matches the calculated identifier, ensuring the automation network transitions to a safe state if there's a discrepancy, allowing for fully automatic and safe commissioning and exchange of safety-relevant participants.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a service employee manually downloads the safety controller from backup memory to the safety-relevant participant, then the configuration can be transferred, but there is a risk of accidentally importing the wrong configuration and high organizational effort is required
Solution Approach 1:
The system performs self-verification by automatically calculating and checking the CRC sum of the safety controller configuration. The safety-relevant participant independently verifies the integrity of the imported configuration without requiring manual verification by service employees, thus eliminating human error and reducing organizational effort.
Solution Approach 2:
The system implements a feedback mechanism where the CRC sum calculated from the imported safety controller is compared against an expected value. If the values match, the import is confirmed; if they differ, an error is detected and the import is rejected. This automatic feedback loop ensures configuration accuracy without manual intervention.
2Extent of automation
If stationary backup memory is used for each safety-relevant participant to enable automatic loading, then the safety controller can be automatically and safely loaded, but high hardware outlay is required
Solution Approach 1:
Instead of requiring separate stationary backup memory devices for each safety-relevant participant, the system uses a single centralized backup memory that stores copies of the safety controller configuration. The configuration is distributed from this single source to multiple participants, eliminating the need for redundant backup storage hardware at each node.
Solution Approach 2:
The single backup memory system serves multiple safety-relevant participants simultaneously, making the backup storage resource universal rather than dedicated to each individual participant. This multi-functional approach reduces overall hardware requirements while maintaining automatic configuration loading capability.
3Adaptability or versatility
If multiple automation networks with different safety controllers are coupled together, then network interoperability is achieved, but it becomes difficult to ensure correct assignment of safety controllers to individual networks
Solution Approach 1:
The system uses CRC sum values as unique identifiers or 'signatures' for different safety controller configurations. Each safety controller generates a distinct CRC fingerprint that allows the system to identify and verify the correct configuration for each automation network, preventing misassignment when multiple networks are interconnected.
Solution Approach 2:
The CRC sum verification is performed automatically during the configuration import process before the safety controller is activated. This preliminary check ensures that the correct configuration is assigned to the correct network before operation begins, preventing errors from propagating into the interconnected network system.
Data Source
Figure 1~2
Figure 3A
Figure 3B
AI summary
According to the invention, in order to operate a safety controller in an automation network having a master subscriber which implements the safety controller, the safety controller is assigned an identifier. When loading the safety controller, the master subscriber checks whether the stored identifier in the safety master subscriber matches the identifier calculated from the safety controller, and the automation network changes to a safe state if it is determined that the identifier differs.