Method and apparatus for safety-related communication in a communication network of an automation system
First Claim
Patent Images
1. An automated manufacturing system comprising:
- a non-safe communication master of the automated manufacturing system, wherein the non-safe communication master is not configured for error-proof communication by means of a secure network protocol; and
a plurality of local network subscribers of the automated manufacturing system, the local network subscribers being connected to the non-safe communication master via a communication network,wherein communication between the local network subscribers in the communication network is realized via telegrams,wherein at least two of the local network subscribers i) are safety network subscribers between which safety-related data are transferred based on error-proof communication, wherein a verification of a communication in conformity to one or more safety requirements includes checking a received telegram by a receiving subscriber for at least one of the following characteristics;
a time stamp, a transmitter identity, and a receiver identity, and ii) form a logical group of network subscribers for performing a safety-related function, andwherein the non-safe communication master maintains a routing table that stores logical connections between the local safety network subscribers in accordance with the safety-related function, the non-safe communication master being configured to control automatic routing of data from a transmitting safety network subscriber to a receiving safety network subscriber in accordance with the routing table, such that each communication among the safety network subscribers of one logical group occurs via two point-to-point connections, namely from the transmitting safety network subscriber to the non-safe communication master and then from the non-safe communication master to the receiving safety network subscriber,wherein the receiving safety network subscriber is configured to perform a safety-related action according to the received telegram, andwherein the communication network includes a means to retrieve information from the safety network subscribers for establishing the routing table, and to establish the routing table on the basis of the information.
1 Assignment
0 Petitions
Accused Products
Abstract
The invention relates to communication between safety-related modules in a communication network of an automation system. The object of the invention is to simplify installation and development of safety-related modules in an automation network. To this end, the safety functions of a system are divided into small, manageable, locally delimitable and simply verifiable groups of modules.
-
Citations
10 Claims
-
1. An automated manufacturing system comprising:
-
a non-safe communication master of the automated manufacturing system, wherein the non-safe communication master is not configured for error-proof communication by means of a secure network protocol; and a plurality of local network subscribers of the automated manufacturing system, the local network subscribers being connected to the non-safe communication master via a communication network, wherein communication between the local network subscribers in the communication network is realized via telegrams, wherein at least two of the local network subscribers i) are safety network subscribers between which safety-related data are transferred based on error-proof communication, wherein a verification of a communication in conformity to one or more safety requirements includes checking a received telegram by a receiving subscriber for at least one of the following characteristics;
a time stamp, a transmitter identity, and a receiver identity, and ii) form a logical group of network subscribers for performing a safety-related function, andwherein the non-safe communication master maintains a routing table that stores logical connections between the local safety network subscribers in accordance with the safety-related function, the non-safe communication master being configured to control automatic routing of data from a transmitting safety network subscriber to a receiving safety network subscriber in accordance with the routing table, such that each communication among the safety network subscribers of one logical group occurs via two point-to-point connections, namely from the transmitting safety network subscriber to the non-safe communication master and then from the non-safe communication master to the receiving safety network subscriber, wherein the receiving safety network subscriber is configured to perform a safety-related action according to the received telegram, and wherein the communication network includes a means to retrieve information from the safety network subscribers for establishing the routing table, and to establish the routing table on the basis of the information. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. A method for monitoring safety functions in an automated manufacturing system comprising a communication master that is not configured for error-proof communication by means of a secure network protocol and a plurality of local network subscribers, the local network subscribers being connected to the non-safe communication master via a communication network, and communication between the local network subscribers in the communication network being realized via telegrams, the method comprising:
-
retrieving information from safety network subscribers for establishing a routing table that stores logical connections between the safety network subscribers in accordance with a safety-related function, wherein at least two of the local network subscribers i) are the safety network subscribers between which safety-related data are transferred based on error-proof communication, wherein a verification of a communication in conformity to one or more safety requirements includes checking a received telegram by a receiving subscriber for at least one of the following characteristics;
a time stamp, a transmitter identity, and a receiver identity, and ii) form a logical group of network subscribers for performing the safety-related function;maintaining, at the non-safe communication master, the routing table on the basis of the information retrieved; automatically routing, through the non-safe communication master, data from a transmitting safety network subscriber to a receiving safety network subscriber in accordance with the routing table, such that each communication among the safety network subscribers of one logical group occurs via two point-to-point connections, namely from the transmitting safety network subscriber to the non-safe communication master and then from the non-safe communication master to the receiving safety network subscriber; and performing, at the receiving safety network subscriber, the safety-related action according to the received telegram.
-
Specification