Safety Controller Commissioning Check via Stored Test Instruction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing safety controllers lack a reliable method to verify if the mandatory commissioning test has been performed by the user before initial installation or after program changes, risking inadequate safety function execution.

Innovation Solution

A method involving a verification routine that checks for a commissioning test instruction in non-volatile memory, automatically executes the test, and ensures successful completion before allowing productive operation, with optional user intervention or automatic shutdown if not completed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a commissioning test is mandated by the manufacturer, then the functional integrity of the safety controller can be verified, but it cannot be verified whether the user actually performed the test

Engineering Contradiction:
Improvefunctional integrity verificationVSAvoidcommissioning test performance status
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by implementing an automatic verification routine that is executed before the safety controller is put into productive operation. The evaluation and control unit automatically checks whether all safety functions can be successfully triggered within a predefined time period, thereby performing the commissioning test verification in advance rather than relying on user declaration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The safety controller performs self-verification through the automatic commissioning test execution. The evaluation and control unit autonomously verifies whether all safety functions are operational by attempting to trigger them, eliminating the need for external verification and providing reliable confirmation that the commissioning test was performed.

Inventive Principle:
Principle #25Self-service

2Reliability

If the commissioning test is not performed, then the safety controller may not execute safety functions adequately, but manual verification is complex and time-consuming

Engineering Contradiction:
Improvesafety function executionVSAvoidverification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The safety controller autonomously verifies its own commissioning status through the automatic verification routine. The evaluation and control unit independently checks whether all safety functions are operational without requiring complex external verification procedures, thereby simplifying the verification process while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback by having the evaluation and control unit monitor the results of the commissioning test and automatically determine whether productive operation can commence. The system provides feedback on the commissioning status and makes the decision to allow or prevent productive operation based on the test results, eliminating complex manual verification.

Inventive Principle:
Principle #23Feedback

3Reliability

If automatic verification is implemented, then the commissioning test performance can be reliably verified, but the device complexity increases

Engineering Contradiction:
Improvecommissioning test verificationVSAvoidverification routine
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The evaluation and control unit performs multiple functions: it controls the safety outputs during normal operation and simultaneously executes the commissioning test verification. This multi-functionality allows the same hardware component to handle both operational control and verification tasks, avoiding the need for separate verification hardware and reducing overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the commissioning test verification function with the existing evaluation and control unit. Rather than adding a separate verification system, the verification routine is integrated into the central control unit that already manages safety functions, thereby achieving reliable verification without proportionally increasing device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4641318A1Method for checking a functional integrity of a safety controller
Publication Date: 2025.10.29 PILZ GMBH & CO KG
  • EP4641318A1 patent drawingFigure 1~2
  • EP4641318A1 patent drawing
  • EP4641318A1 patent drawing

AI summary

A method for verifying the functional integrity of a safety controller, configured to provide a number of safety functions for at least one machine and comprising a central evaluation and control unit for the operation of the safety controller, comprising the steps: a) switching on the safety controller, b) checking a stored, machine-readable instruction to determine whether a commissioning test is to be performed by a user of the safety controller; if no, then terminating the method; if yes, then proceeding to method step c), c) visualizing the information that the commissioning test is to be performed using a display device of the safety controller, d) starting an executable verification routine by means of which the evaluation and control unit automatically verifies thewhether the user has successfully verified each of the safety functions from the number n ≥ 1 provided by the safety controller within a specific time period by triggering the respective safety function, e) delete the instruction from the non-volatile storage medium that the commissioning test is to be carried out if in procedure step d) all safety functions from the number n ≥ 1 provided by the safety controller were successfully verified, or f) store the instruction in the non-volatile storage medium that the commissioning test is to be carried out again if in procedure step d) not all safety functions were successfully verified.