Security system
Abstract
The present invention relates to a programmable safety system intended to be used for safety functions, in which a fault in a control circuit does not lead to a safety function being disabled, which system comprises monitoring functions containing at least two control units, input terminals separately coupled to both control units, whereby each control unit executes its own instruction set and continuously compares a result from the execution with each other. At least one control unit can access the in and output terminal status of a second control unit and/or a number of flags, and the control units are arranged to monitor the result of respectively executed instruction sets and control that the results of the executions are substantially equivalent.
Claims
exact text as granted — not AI-modified1 . A programmable safety system intended to be used for safety functions, in which a fault in a control circuit does not lead to a safety function being disabled which system comprises monitoring functions containing at least two control units, inputs separately coupled to both the control units, whereby each control unit executes its own instruction set and continuously compares a result from the execution with each other, characterized in
that at least one control unit can access the status of the input and output terminal of a second control unit and/or a number of flags and that the control units are arranged to monitor the result of respectively executed instruction sets and to control that the results of the executions are substantially equivalent.
2 . A system as claimed in claim 1 , characterized in
that it complies with the requirement of category 4 according to the harmonized standard EN 954-1.
3 . A system as claimed in claim 1 , characterized in
that it complies with the requirement of the machinery directive 98/37/EG Appendix 1, 1.2.7.
4 . A system as claimed in claim 1 , characterized in
that the input terminals are continuously read at a certain frequency.
5 . A system as claimed in claim 4 , characterized in
that a filter time is based on a decision being made based on the majority of the three latest readings, i.e. two readings after a change.
6 . A system as claimed in claim 4 or 5 , characterized in
that some of the input terminals have pull-up or pull-down resistors, which are software controlled, for selectively receiving NPN- or PNP sensors.
7 . A system as claimed in claim 1 - 6 , characterized in
that the system comprises a charging generator, where the output voltage is generated by a capacitor which is continuously charged and discharged by transistors.
8 . A system as claimed in claim 7 , characterized in
that the transistors which are each controlled by a respective control unit alternately conduct so that the capacitor is firstly charged by means of the first transistor opening to plus, thereafter discharge occurs by means of the first transistors closing and the second transistor opening to zero volt.
9 . A system as claimed in claim 8 , characterized in
that the charging generator requires that the control units are active, which leads to an immediate interruption of the energy supply to the output terminal if a control unit ceases to executing instructions in a correct way.
10 . A system as claimed in claim 7 , characterized in
that a more even output voltage is obtained by means of two charging generators being coupled in parallel with each other.
11 . A system as claimed in claim 1 , characterized in
that each control unit controls a respective relay via separate transistors.
12 . A system as claimed in claim 10 , characterized in
that the both transistors are made of different technology.
13 . A system as claimed in claim 10 , characterized in
that the relays have forced contacts, monitored by the control units.
14 . A system as claimed in claim 12 , characterized in
that a switching contact in every forced relay is coupled back to the control unit for controlling that it has fallen, and if the control unit only receives an answer from one of two relays doubling each other, the unit tries to conduct and fell the missing relay again.
15 . A system as claimed in claim 1 , characterized in
that the fall time is monitored at the output terminal, which fall time also can be used for detecting external short circuit to another foreign voltage.
16 . A system as claimed in claim 15 , characterized in
that when the supervision detects short circuit to a foreign voltage, the output terminal is prevented from returning and a fault is indicated.
17 . A system as claimed in claim 1 , characterized in
that the output terminals are dynamic, which operate input terminals generating a unique pulse train, which implies that short circuits between channels coupled to different output terminals can be detected.
18 . A system as claimed in claim 1 , characterized in
that each unit in a network is identified by means of an identity carrier.
19 . A system as claimed in claim 18 , characterized in
that the identifier is an externally mounted circuit which stores a unique number and constitutes a part of the electric installation location where the unit is physically mounted.
20 . A system as claimed in claim 19 , characterized in
that a unit is arranged to read the number of the identifier, and thereby determine its own identity.
21 . A system as claimed in claim 18 , characterized in
that the correct identity is maintained in case of change of a unit.
22 . A system as claimed in claim 1 , characterized in
that the units are coupled together via a data buss and have access to each other's input and output terminal status and/or a number of flags.
23 . A system as claimed in claim 22 , characterized in
that when a unit loses contact with the bus communication, the other units consider its I/O as logical zeroes.
24 . A system as claimed in claim 22 , characterized in
that the bus is a CAN bus.
25 . A system as claimed in claim 1 , characterized in
that the system is connected to light barriers, the transmitters of which are operated by one dynamic output terminal each, that the receivers are coupled to one output terminal each, that the input terminals are provided with output transistors via which return voltage is applied to cables from the receiver to the input terminal, whereby the system thereby performs a test sequence which can distinguish short circuits between the output cables of the receivers from excess lighting.
26 . A method in a programmable safety system intended to be used for safety functions, in which a fault in a control circuit does not lead to a safety function being disabled which system comprises monitored functions containing at least two control units, input terminals separately coupled to both control units, whereby each control unit executes its own instruction set and continuously compares a result from the execution with each other, characterized in
that at least the in- and output terminal status of a second control unit and/or a number of flags are made available for a control unit, and that the control units are arranged to supervise the result of each respectively executed instruction set and to control that the results of the executions are substantially equivalent
27 . A method as claimed in claim 26 , characterized in
that the result of the executions is provided in the form of status for the input terminals and/or output terminals and/or a number of flags.Join the waitlist — get patent alerts
Track US2003074608A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.