Safety controller and method for loading a new operating program onto the safety controller
First Claim
1. A safety controller for failsafe disconnection of a machine or a machine system in response to process signals from the machine or machine system, the safety controller comprisingan input module for automatically reading the process signals,a failsafe signal processing module for fail-safely processing the process signals, anda failsafe output module for producing control signals in response to the signal processing module, the control signals controlling the disconnection of the machine or machine system,wherein the signal processing module comprises at least one programmable processor and at least a first operating program stored in a non-volatile form in a first read only memory,wherein a second read only memory is provided in which a first hardware information item is stored which is characteristic at least of a current hardware configuration of the signal processing module, andwherein a download device is provided, the download device being designed to transfer a second operating program into the first read only memory,wherein the second operating program comprises a second hardware information item which is characteristic of a minimum required hardware configuration, andwherein the download device is designed to fail-safely inhibit the transfer of the second operating program into the first read only memory as a function of a comparison of the minimum required hardware configuration for said second operating program as defined by said second hardware information item, with the current hardware configuration of the signal processing module as defined by the first hardware information item.
1 Assignment
0 Petitions
Accused Products
Abstract
The invention relates to a safety controller and to a method for loading a new operating program onto such a safety controller. The safety controller has an input module for automatically reading process signals, a failsafe signal processing module for automatically processing the process signals, and a failsafe output module which produces control signals as a function of the signal processing module. The signal processing module comprises at least one programmable processor and at least one read only memory. A current operating program for the processor is stored in a non-volatile form in the read only memory. A download device for transferring a new operating program is provided in the safety controller, with the download device enabling or inhibiting the transfer of a new operating program in a failsafe manner as a function of enabling information.
-
Citations
18 Claims
-
1. A safety controller for failsafe disconnection of a machine or a machine system in response to process signals from the machine or machine system, the safety controller comprising
an input module for automatically reading the process signals, a failsafe signal processing module for fail-safely processing the process signals, and a failsafe output module for producing control signals in response to the signal processing module, the control signals controlling the disconnection of the machine or machine system, wherein the signal processing module comprises at least one programmable processor and at least a first operating program stored in a non-volatile form in a first read only memory, wherein a second read only memory is provided in which a first hardware information item is stored which is characteristic at least of a current hardware configuration of the signal processing module, and wherein a download device is provided, the download device being designed to transfer a second operating program into the first read only memory, wherein the second operating program comprises a second hardware information item which is characteristic of a minimum required hardware configuration, and wherein the download device is designed to fail-safely inhibit the transfer of the second operating program into the first read only memory as a function of a comparison of the minimum required hardware configuration for said second operating program as defined by said second hardware information item, with the current hardware configuration of the signal processing module as defined by the first hardware information item.
-
9. A method for loading a new operating program onto a safety controller, comprising the steps of:
-
providing a safety controller having a first and a second read only memory, wherein a current operating program is stored in the first read only memory, providing a first hardware information item, which is characteristic of the safety controller, in the second read only memory, providing a new operating program including a second hardware information item, with the second hardware information item being characteristic of a minimum required hardware for the new operating program, and transferring the new operating program into the first read only memory as a function of enabling information which contains the first and the second hardware information items, and fail-safely inhibiting the transferring step if the first and the second hardware information items do not match each other.
-
-
10. A safety controller for failsafe control of a safety-critical process, having an input module for automatically reading process signals, a failsafe signal processing module for automatically processing the process signals, and a failsafe output module for producing control signals in response to the signal processing module, with the signal processing module comprising at least one programmable processor and at least a first read only memory in which a current operating program for the processor is stored in a non-volatile form, and having a download device for transferring a new operating program into the first read only memory, with the download device enabling or inhibiting the transfer of the new operating program in a failsafe manner as a function of enabling information;
- wherein a second read only memory is provided in which a first item of hardware information is stored which is characteristic at least of a current hardware configuration of the signal processing module, the new operating program comprises a second item of hardware information which is characteristic of a minimum required hardware configuration, and the download device is adapted to enable or inhibit the transfer of the new operating program as a function of a comparison of the first and the second hardware information items.
- View Dependent Claims (11, 12, 13, 14, 15, 16, 17, 18)
Specification