Automation system with integrated safe and standard control functionality
First Claim
Patent Images
1. An industrial control system, comprising:
- a machine having a restricted access portion presenting a danger to a human operator in the restricted access portion;
a machine controller executing a stored control program to;
a) identify a need for a human operator to be in the restricted access portion wherein the need is based on a planned machine-operator interaction indicated by a point in the control program and not based on detection of a human presence or on an operator input,b) place the machine into a ready state in response to the identification of the need for the operator to be in the restricted access portion by suspending operation of the machine through machine control, andc) upon the control program placing the machine into the ready state, generate a ready message signaling that the control program has identified the machine is in the ready state;
a protection sensor providing a safety signal, wherein the safety signal implements fault tolerance or fault detection according to the target safety level of the control system, indicating the presence of a human in the restricted access portion; and
a safety controller, wherein the machine controller and the safety controller are independently functioning computing devices with separate memory for storing variables and programs and each controller independently executes its respective program, the safety controller executing a stored program to;
a) receive the ready message from the machine,b) receive the safety signal indicating the presence of the human operator in the restricted access portion from the protection sensor,c) after receiving either one of the ready message or the safety signal, initiate placing the machine into a safe state, wherein the safe state suspends operation of at least the restricted portion of the machine by interrupting power to at least the restricted portion of the machine,d) verify that the machine has been placed in the safe state with no fault conditions, ande) if the machine has been placed in the safe state with no fault conditions, provide a human interaction indication sensible by a human that indicates that the machine is ready for human interaction with the restricted access portion in response to receiving the ready message and placing the machine into a safe state;
whereby the machine is placed in the safe state before the human operator moves into the restricted access portion.
1 Assignment
0 Petitions
Accused Products
Abstract
An industrial control system includes a machine, a machine controller, and a safety controller. The machine controller is operable to identify a need for a human interaction, place the machine into a ready state for the human interaction, and generate a ready message responsive to placing the machine into the ready state. The safety controller is operable to receive the ready message, place the machine into a safe state responsive to receiving the ready message, and provide a human interaction indication responsive to placing the machine into the safe state.
-
Citations
25 Claims
-
1. An industrial control system, comprising:
-
a machine having a restricted access portion presenting a danger to a human operator in the restricted access portion; a machine controller executing a stored control program to; a) identify a need for a human operator to be in the restricted access portion wherein the need is based on a planned machine-operator interaction indicated by a point in the control program and not based on detection of a human presence or on an operator input, b) place the machine into a ready state in response to the identification of the need for the operator to be in the restricted access portion by suspending operation of the machine through machine control, and c) upon the control program placing the machine into the ready state, generate a ready message signaling that the control program has identified the machine is in the ready state; a protection sensor providing a safety signal, wherein the safety signal implements fault tolerance or fault detection according to the target safety level of the control system, indicating the presence of a human in the restricted access portion; and a safety controller, wherein the machine controller and the safety controller are independently functioning computing devices with separate memory for storing variables and programs and each controller independently executes its respective program, the safety controller executing a stored program to; a) receive the ready message from the machine, b) receive the safety signal indicating the presence of the human operator in the restricted access portion from the protection sensor, c) after receiving either one of the ready message or the safety signal, initiate placing the machine into a safe state, wherein the safe state suspends operation of at least the restricted portion of the machine by interrupting power to at least the restricted portion of the machine, d) verify that the machine has been placed in the safe state with no fault conditions, and e) if the machine has been placed in the safe state with no fault conditions, provide a human interaction indication sensible by a human that indicates that the machine is ready for human interaction with the restricted access portion in response to receiving the ready message and placing the machine into a safe state; whereby the machine is placed in the safe state before the human operator moves into the restricted access portion. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. A method for controlling a human interaction with a machine, comprising:
-
in a machine controller, executing a stored control program, identifying a need for a human to be within a restricted access portion of the machine during normal machine operation wherein the need is based on a planned machine-operator interaction indicated by a point in the control program and not based on detection of a human presence or on an operator input; placing the machine into a ready state for the human interaction in response to the identification of the need for the operator to be in the restricted access portion by temporarily suspending normal machine operation through machine control signals from the machine controller; generating a ready message in the machine controller responsive to the control program placing the machine into the ready state signaling that the control program has identified the machine is in the ready state; transmitting the ready message to a safety controller, wherein the machine controller and the safety controller are independently functioning computing devices with separate memory for storing variables and programs and each controller independently executes its respective program; placing the machine into a safe state using the safety controller responsive to receiving the ready message or a safety signal from a protection sensor indicating the presence of the human operator in the restricted access portion, wherein the safe state suspends operation of at least the restricted access portion of the machine by interrupting power to at least the restricted access portion of the machine and wherein the safety signal implements fault tolerance or fault detection according to the target safety level of the control system; verifying that the machine is in the safe state with no fault conditions; and providing a human interaction indication sensible by a human from the safety controller indicating the machine is ready for human interaction with the restricted access portion responsive to placing the machine into the safe state and receiving the ready message. - View Dependent Claims (15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25)
-
Specification