Abstract:
The invention relates to a method for process control, wherein at least one process device to be controlled is controlled by at least one process module and by at least one safety module, in that process signals not relevant to safety are transmitted to a local control unit associated with the process device by the process module and safety signals relating to the process safety are transmitted by the safety module, wherein the process signals and the safety signals are logically linked to one another in the control unit and the result of the logical link is made available at a control output of the control unit to which the process device to be controlled is connected.The invention moreover relates to a system for process control, in particular for the carrying out of the method in accordance with the invention.
Abstract:
While a microcomputer 100A is executing a self-diagnosis (A), second diagnosis pulse output means 110B of a B-system microcomputer 100B is not used utterly. Further, during this time, the B-system microcomputer 100B does not execute a processing relating to at least the self-diagnosis (A) utterly. By shifting the timings for the A-system and the B-system to output the diagnosis pulses, independencies can be secured between respective diagnosis processing (self-diagnoses (A) and (B)). Thus, the independencies between the A-system and the B-system can be verified briefly by the self-diagnosis (A) on the A-system side. Further, first diagnosis pulse group are outputted parallel and simultaneously from first diagnosis pulse output means 110A. Thus, since cyclic control is not required for respective external input devices, it can be done to verify the independencies between the A-system and the B-system within a short period of time.
Abstract:
A cascade of safety switches includes safety switches for the monitoring of accesses of an automation system, at least one connection unit for the arrangement between two safety switches, and a terminator for the termination of the cascade of safety switches. Each safety switch has a first conductor and a second conductor. The first conductor includes conductor cores for transmitting signals and for receiving voltage. The second conductor includes conductor cores for receiving signals and for forwarding the voltage. The connection unit has a first circuit and a second circuit. The first circuit is provided for receiving the signals of a subsequent safety switch and for forwarding the signals of the subsequent safety switch to an upstream safety switch and the second circuit is provided for connecting the connection unit to a voltage source and to a conductor core for receiving the voltage of the subsequent safety switch.
Abstract:
While a microcomputer is executing a self-diagnosis (A), second diagnosis pulse output means of a B-system microcomputer is not used utterly. Further, during this time, the B-system microcomputer 100B does not execute a processing relating to at least the self-diagnosis (A) utterly. By shifting the timings for the A-system and the B-system to output the diagnosis pulses, independencies can be secured between respective diagnosis processing (self-diagnoses (A) and (B)). Thus, the independencies between the A-system and the B-system can be verified briefly by the self-diagnosis (A) on the A-system side. Further, first diagnosis pulse group are outputted parallel and simultaneously from first diagnosis pulse output means. Thus, since cyclic control is not required for respective external input devices, it can be done to verify the independencies between the A-system and the B-system within a short period of time.
Abstract:
The invention relates to a method for process control, wherein at least one process device to be controlled is controlled by at least one process module and by at least one safety module, in that process signals not relevant to safety are transmitted to a local control unit associated with the process device by the process module and safety signals relating to the process safety are transmitted by the safety module, wherein the process signals and the safety signals are logically linked to one another in the control unit and the result of the logical link is made available at a control output of the control unit to which the process device to be controlled is connected. The invention moreover relates to a system for process control, in particular for the carrying out of the method in accordance with the invention.
Abstract:
An apparatus includes one or more channels. Each channel includes circuitry configured to receive an input current from a universal input/output (UIO) and provide an output to a field device in a hazardous or potentially hazardous zone, the circuitry further configured to limit energy to the field device by limiting at least one of a voltage, a current, or a power of the output. Each channel also includes terminals configured to connect the circuitry to one or more cables coupling the field device to the apparatus. Each channel is configured to provide an intrinsically safe barrier between the field device and a controller that controls operation of the field device.
Abstract:
An arrangement for controlling an automated system, having a number of sensors and actuators, in particular for controlling a railroad system. A programmable control unit runs a user program to process input data from the sensors and to generate control commands for the actuators. The sensors and the actuators are connected to a remote I/O unit, which is connected to the control unit via a communication network. The control unit and the I/O unit interchange data messages in order to transmit the input data and the control commands. The arrangement has a remote disconnection unit, which is coupled to the remote I/O unit independently from the input data and control commands. The control unit is designed to integrate specific verification data for the disconnection unit into the data messages for the I/O unit. The disconnection unit is designed to deactivate the I/O unit depending on the specific verification data.
Abstract:
An arrangement for controlling an automated system, having a number of sensors and actuators, in particular for controlling a railroad system. A programmable control unit runs a user program to process input data from the sensors and to generate control commands for the actuators. The sensors and the actuators are connected to a remote I/O unit, which is connected to the control unit via a communication network. The control unit and the I/O unit interchange data messages in order to transmit the input data and the control commands. The arrangement has a remote disconnection unit, which is coupled to the remote I/O unit independently from the input data and control commands. The control unit is designed to integrate specific verification data for the disconnection unit into the data messages for the I/O unit. The disconnection unit is designed to deactivate the I/O unit depending on the specific verification data.
Abstract:
The safe PLC1 and the safe slaves 2 are connected with each other via the safe network 3. The safe PLC has the function of transmitting a request of safety information by broadcast message to the safe slaves. The safe slaves are each provided with a safety information transmission function for transmitting safety information indicative of whether the safe slave is in a safe condition or not; and a changing function for changing a priority of a transmission frame which carries the safety information. As a result, when the safe slaves send back safe responses at once in response to the broadcast message, safety information (danger) with a higher priority is transmitted ahead of others to the safe PLC.
Abstract:
The safe PLC1 and the safe slaves 2 are connected with each other via the safe network 3. The safe PLC has the function of transmitting a request of safety information by broadcast message to the safe slaves. The safe slaves are each provided with a safety information transmission function for transmitting safety information indicative of whether the safe slave is in a safe condition or not; and a changing means for changing a priority of a transmission frame which carries the safety information. As a result, when the safe slaves send back safe responses at once in response to the broadcast message, safety information (danger) with a higher priority is transmitted ahead of others to the safe PLC.