EP2411878A1 - System und verfahren zur automatischen prüfung eines programms für sicherheitsgerichtete automatisierungssysteme - Google Patents
System und verfahren zur automatischen prüfung eines programms für sicherheitsgerichtete automatisierungssystemeInfo
- Publication number
- EP2411878A1 EP2411878A1 EP10711561A EP10711561A EP2411878A1 EP 2411878 A1 EP2411878 A1 EP 2411878A1 EP 10711561 A EP10711561 A EP 10711561A EP 10711561 A EP10711561 A EP 10711561A EP 2411878 A1 EP2411878 A1 EP 2411878A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- safety
- program
- guidelines
- development
- partially
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B19/00—Program-control systems
- G05B19/02—Program-control systems electric
- G05B19/04—Program control other than numerical control, i.e. in sequence controllers or logic controllers
- G05B19/05—Programmable logic controllers, e.g. simulating logic interconnections of signals according to ladder diagrams or function charts
- G05B19/056—Programming the PLC
-
- Y—GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
- Y02—TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
- Y02P—CLIMATE CHANGE MITIGATION TECHNOLOGIES IN THE PRODUCTION OR PROCESSING OF GOODS
- Y02P90/00—Enabling technologies with a potential contribution to greenhouse gas [GHG] emissions mitigation
- Y02P90/02—Total factory control, e.g. smart factories, flexible manufacturing systems [FMS] or integrated manufacturing systems [IMS]
Definitions
- the invention relates to a method and a system for automatic testing of a program for in particular at least partially safety-related automation systems, such as safety-related programmable logic controllers, in terms of compliance with guidelines, in particular guidelines for the design of programs for safety-related programmable logic controllers.
- safety-related automation systems such as safety-related programmable logic controllers
- pre-certified components include:
- Hardware components such as programmable logic controller, input / output modules, bus systems, sensors, actuators;
- Certification of the safety programmable controller program is facilitated if the program is structurally and substantively designed so that the certifying body can understand the operation of the program with the least possible effort. This can be achieved, above all, by restricting the possibilities offered by the programming language used for programmable logic controllers when they are used for a safety-impaired automation system.
- Checking for correctness for example checking against field index overflow, pointer overflow, memory overflow, endless loops, unallocated or unallocated memory, uninitialized variables or unsafe type conversions,
- the invention is therefore based on the object, a solution for automatic testing of a program for automation systems, especially for safety-related automation systems, compliance with guidelines, rules and requirements, also referred to as programming guidelines, in particular programming guidelines for the design of programs for programmable logic, in particular safety-related, to specify controls.
- the invention therefore proposes an automatic check of control programs or program parts of the automation system with regard to compliance with programming guidelines, such as guidelines, rules and specifications, for the design of programs for, in particular safety-related, programmable logic controllers outside a development environment for security software, also as safety-related program.
- programming guidelines such as guidelines, rules and specifications
- the automatic check relates to safety-related control programs or program parts of a safety-related automation system.
- FIG. 1 shows an example flow chart for the method according to the invention
- FIG. 2 shows an exemplary arrangement for carrying out the method.
- Fig. 1 shows in a flow chart after the start of a method for automatically performed program check as the first step, an export of a copy of a program, also referred to as the original program, from a development system for an exemplary safety-related automation system.
- this program copy also referred to as a safety program
- This test equipment is set up for program testing and contains software suitable for - in a third step - software testing intended to test a given set of guidelines for the design of safety programmable controller programs, hereafter referred to as programming guidelines.
- the programming guidelines are preferably of a machine-readable form and are then interpreted during the test program run.
- the program developed and to be tested in the development system can be present, for example, in a programming language according to the standard IEC 61131, for example as a structured text program, as a function block diagram or as a ladder diagram. If the test result states that the program copy to be tested is error-free according to the programming guidelines, in particular the guidelines for the design of programs for safety-related programmable logic controllers, this is output to the development system and / or the programmer, and the process is ended.
- step 4 After a revision of the original program in the development system, it is exported again and loaded into the test facility.
- the retry procedure will either continue until there are no violations of the program being tested against the programming guidelines, or until it detects only violations of such policies that are of lesser importance in the present case, so that no delay in the envisaged certification is expected and the new program version can be used in the safety-related automation system.
- a determination of violations of those programming guidelines, which are of minor importance, is preferably carried out at the start of the method according to the invention.
- the first step ie the export of a copy of the program from the development system
- the test device is designed in this way, the safety program to be tested directly in the Development system to locate and automatically, so without additional export step to load.
- the first step ie the export of a program copy
- the test equipment is set up directly in the development system on the to access the safety program to be tested and thus carry out the testing of the program within the development system.
- the tester does not change the program within the development system unless a user initiates a modification.
- a safety-related automation system 1 interacts with a development computer 2.
- the safety-related automation system 1 contains a safety-related programmable logic controller 11 and a non-safety-related programmable logic controller 12 communicating therewith.
- safety-related input / output devices 13 and non-safety-related input / output devices 14 are present which are connected to the controllers by means of a data transmission system 11 and 12 are connected.
- the development computer 2 contains a development system 21 with a programming environment for the development of a safety-related program, also referred to as safety software, and a test device 22 for testing the safety software.
- a programmer 3 has access to both the development system 21 and the checking device 22.
- the development computer 2 may be connected to the safety-related programmable logic controller 11 and / or the non-safety-related programmable logic controller 12. The operation of the arrangement shown in Fig. 2 corresponds to the procedure described with reference to FIG.
- the method according to the invention and the corresponding system not only relieve a programmer of the time-consuming program check, but are also non-reactive insofar as the checking device does not effect any modification of the original program in the development system. This is a prerequisite for continuing to use the development system as pre-certified without further testing during the development of the safety-related system program.
- Another advantage is that a flexible adaptation of the programming guidelines for the design of programs for, in particular safety-oriented, programmable logic controllers to a respective required SIL level (Safety Integrity Level) is possible.
- test device in particular the guidelines to be tested for the design of programs for safety-oriented programmable logic controllers, without having to modify the development system and therefore having to recertify it.
Landscapes
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Engineering & Computer Science (AREA)
- Automation & Control Theory (AREA)
- Programmable Controllers (AREA)
- Debugging And Monitoring (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102009014698A DE102009014698A1 (de) | 2009-03-27 | 2009-03-27 | System und Verfahren zur automatischen Prüfung eines Programms für sicherheitsgerichtete Automatisierungssysteme |
| PCT/EP2010/001503 WO2010108594A1 (de) | 2009-03-27 | 2010-03-11 | System und verfahren zur automatischen prüfung eines programms für sicherheitsgerichtete automatisierungssysteme |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2411878A1 true EP2411878A1 (de) | 2012-02-01 |
Family
ID=42315587
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP10711561A Withdrawn EP2411878A1 (de) | 2009-03-27 | 2010-03-11 | System und verfahren zur automatischen prüfung eines programms für sicherheitsgerichtete automatisierungssysteme |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US8539448B2 (de) |
| EP (1) | EP2411878A1 (de) |
| CN (1) | CN102395928A (de) |
| DE (1) | DE102009014698A1 (de) |
| WO (1) | WO2010108594A1 (de) |
Families Citing this family (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102009054157C5 (de) * | 2009-11-23 | 2014-10-23 | Abb Ag | Steuerungssystem zum Steuern von sicherheitskritischen und nichtsicherheitskritischen Prozessen |
| CN102566562A (zh) * | 2010-12-07 | 2012-07-11 | 镇江灵芯软件实验室有限公司 | 一种对plc程序自动测试的方法 |
| CN103019930A (zh) * | 2012-11-15 | 2013-04-03 | 陈钢 | 一种针对含有时间控制的plc程序自动测试的方法 |
| US9582389B2 (en) * | 2013-07-10 | 2017-02-28 | International Business Machines Corporation | Automated verification of appliance procedures |
| CN103761184B (zh) * | 2013-12-31 | 2017-01-04 | 华为技术有限公司 | 程序的代码段测试方法、装置和系统 |
| US10025287B2 (en) * | 2015-03-30 | 2018-07-17 | Rockwell Automation Germany Gmbh & Co. Kg | Method for assignment of verification numbers |
| JP6540561B2 (ja) * | 2016-03-14 | 2019-07-10 | オムロン株式会社 | 評価システム、評価プログラムおよび評価方法 |
| GB2551517B (en) | 2016-06-20 | 2020-06-03 | Jaguar Land Rover Ltd | Software interlock |
| EP3845984B1 (de) * | 2019-12-31 | 2025-09-10 | Schneider Electric Systems USA, Inc. | Sicheres netzwerk von sicherheits-sps für industrieanlagen |
Family Cites Families (27)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5233611A (en) * | 1990-08-20 | 1993-08-03 | International Business Machines Corporation | Automated function testing of application programs |
| US6071316A (en) * | 1997-09-29 | 2000-06-06 | Honeywell Inc. | Automated validation and verification of computer software |
| US6243835B1 (en) * | 1998-01-30 | 2001-06-05 | Fujitsu Limited | Test specification generation system and storage medium storing a test specification generation program |
| US6353924B1 (en) * | 1999-02-08 | 2002-03-05 | Incert Software Corporation | Method for back tracing program execution |
| US6634019B1 (en) * | 1999-07-16 | 2003-10-14 | Lamarck, Inc. | Toggling software characteristics in a fault tolerant and combinatorial software environment system, method and medium |
| US6546547B1 (en) * | 1999-09-22 | 2003-04-08 | Cisco Technology, Inc. | Method and system for an automated net booting tool |
| US6784883B1 (en) * | 2001-06-28 | 2004-08-31 | Microsoft Corporation | Dynamic tree-node property page extensions |
| US7003765B1 (en) * | 2001-12-12 | 2006-02-21 | Oracle International Corporation | Computer-based pre-execution analysis and verification utility for shell scripts |
| US7216339B2 (en) * | 2003-03-14 | 2007-05-08 | Lockheed Martin Corporation | System and method of determining software maturity using Bayesian design of experiments |
| EP1627303A4 (de) * | 2003-04-18 | 2009-01-14 | Ounce Labs Inc | Verfahren und system zum nachweis von schwachstellen in quellcodes |
| US7152227B1 (en) * | 2003-06-17 | 2006-12-19 | Xilinx, Inc. | Automated assessment of programming language coverage by one or more test programs |
| US7421680B2 (en) * | 2003-09-22 | 2008-09-02 | Microsoft Corporation | Persisted specifications of method pre-and post-conditions for static checking |
| US7027880B2 (en) * | 2003-09-30 | 2006-04-11 | Rockwell Automation Technologies, Inc. | Safety controller providing rapid recovery of safety program data |
| US7584455B2 (en) * | 2003-10-23 | 2009-09-01 | Microsoft Corporation | Predicate-based test coverage and generation |
| US7707557B1 (en) * | 2003-12-30 | 2010-04-27 | Sap Ag | Execution of modified byte code for debugging, testing and/or monitoring of object oriented software |
| US7340725B1 (en) * | 2004-03-31 | 2008-03-04 | Microsoft Corporation | Smart test attributes and test case scenario in object oriented programming environment |
| EP1637956A1 (de) * | 2004-09-15 | 2006-03-22 | Ubs Ag | Erzeugung anonymisierter Datensätze zum Testen und Entwickeln von Anwendungen |
| US7716641B2 (en) * | 2004-12-01 | 2010-05-11 | Microsoft Corporation | Method and system for automatically identifying and marking subsets of localizable resources |
| CN100347682C (zh) * | 2004-12-08 | 2007-11-07 | 上海科泰世纪科技有限公司 | 自动化测试构建方法 |
| US7770153B2 (en) * | 2005-05-20 | 2010-08-03 | Microsoft Corporation | Heap-based bug identification using anomaly detection |
| CN100377109C (zh) * | 2005-11-07 | 2008-03-26 | 华为技术有限公司 | 一种利用测试套完成产品自动化测试的方法 |
| US7730453B2 (en) * | 2005-12-13 | 2010-06-01 | Microsoft Corporation | Runtime detection for invalid use of zero-length memory allocations |
| US8117600B1 (en) * | 2005-12-29 | 2012-02-14 | Symantec Operating Corporation | System and method for detecting in-line synchronization primitives in binary applications |
| US8104021B2 (en) * | 2006-06-09 | 2012-01-24 | Microsoft Corporation | Verifiable integrity guarantees for machine code programs |
| DE102007043214A1 (de) * | 2007-09-11 | 2009-03-12 | Delta Electronics, Inc. | Verfahren zum Editieren eines Programms für eine programmierbare logische Steuerung (PLC) |
| US8122436B2 (en) * | 2007-11-16 | 2012-02-21 | Microsoft Corporation | Privacy enhanced error reports |
| US8276123B1 (en) * | 2008-07-22 | 2012-09-25 | Juniper Networks, Inc. | Adaptive regression test selection within testing environments |
-
2009
- 2009-03-27 DE DE102009014698A patent/DE102009014698A1/de not_active Ceased
-
2010
- 2010-03-11 CN CN2010800159342A patent/CN102395928A/zh active Pending
- 2010-03-11 WO PCT/EP2010/001503 patent/WO2010108594A1/de not_active Ceased
- 2010-03-11 EP EP10711561A patent/EP2411878A1/de not_active Withdrawn
-
2011
- 2011-09-27 US US13/246,338 patent/US8539448B2/en not_active Expired - Fee Related
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2010108594A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| US8539448B2 (en) | 2013-09-17 |
| DE102009014698A1 (de) | 2010-10-07 |
| WO2010108594A1 (de) | 2010-09-30 |
| CN102395928A (zh) | 2012-03-28 |
| US20120036499A1 (en) | 2012-02-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2010108594A1 (de) | System und verfahren zur automatischen prüfung eines programms für sicherheitsgerichtete automatisierungssysteme | |
| WO2013004389A1 (de) | Verfahren und vorrichtung zur programmierung und konfigurierung einer speicherprogrammierbaren steuereinrichtung | |
| EP1906377A1 (de) | System und Verfahren zur Integration eines Prozessleitsystems in einen Trainingssimulator | |
| EP2911024A1 (de) | Verfahren zur Inbetriebnahme eines industriellen Automatisierungsnetzwerks sowie Feldgerät | |
| DE102016119320A1 (de) | Verfahren zum Konfigurieren eines realen oder virtuellen elektronischen Steuergerätes | |
| DE102005042126A1 (de) | Verfahren und Vorrichtung zum automatisierten Bewerten der Qualität eines Software-Quellcodes | |
| DE102014101321A1 (de) | Testeinrichtung zum Test eines virtuellen Steuergeräts | |
| EP3306295A1 (de) | Verfahren und vorrichtung zum testen elektronischer steuerungen, insbesondere zum testen von automobilsteuerungen | |
| EP1904923A1 (de) | Verfahren und softwaresystem zur konfiguration eines modularen systems | |
| DE102008043374A1 (de) | Vorrichtung und Verfahren zur Generierung redundanter, aber unterschiedlicher Maschinencodes aus einem Quellcode zur Verifizierung für ein sicherheitskritisches System | |
| EP3349082A1 (de) | System und simulator zur abschaltbaren simulation von anlagen oder maschinen innerhalb von speicherprogrammierbaren steuerungen | |
| DE102021132302A1 (de) | Compilervalidierung | |
| DE102009004531B4 (de) | Verfahren zum Verifizieren eines Fertigungsprozesses | |
| DE102021208759A1 (de) | Verfahren zum Trainieren eines Algorithmus des maschinellen Lernens zum Erzeugen von Testspezifikationen zum Testen eines auf Software basierenden Systems | |
| EP3702922A1 (de) | Verfahren zur rechnergestützten validierung von eingebetteter software | |
| DE102023126332A1 (de) | Verfahren zum Generieren eines Steuerprogramms für ein Automatisierungssystem und Entwicklungsumgebung | |
| DE102020213809A1 (de) | Verfahren zum Betreiben eines Steuergeräts beim Testen einer Software des Steuergeräts und Verfahren zum Betreiben eines Testcomputers beim Testen einer Software eines Steuergeräts | |
| DE102020109093A1 (de) | Verfahren zur Überprüfung der zuverlässigen Funktion eines automatisierungstechnischen Prozesses innerhalb eines IO-Link-Systems | |
| EP3696621A1 (de) | Computerimplementiertes verfahren und vorrichtung zum steuern eines modularen technischen systems | |
| DE102010014720A1 (de) | Verfahren zum Verifizieren eines aus einem Quellmodell generierten Zielprogramms | |
| EP2864845A1 (de) | Automatisierte rekonfiguration eines ereignisdiskreten regelkreises | |
| EP4509992A1 (de) | Test von automatisierungsanwendungen | |
| EP2418583A1 (de) | Prüfeinrichtung für einen Programmteil einer industriellen Automatisierungsanordnung | |
| DE102012203252A1 (de) | Vorrichtung und Verfahren zum Testen von elektronischen Geräten mit einer räumlich getrennten Steuereinrichtung | |
| DE102023205751A1 (de) | Rechnergestütztes Verfahren zur automatisierten Erzeugung und Verifizierung eines Computerprogramms |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20110914 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO SE SI SK SM TR |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: NEUPAERTL, HEINRICH Inventor name: GRAMBERG, OLIVER Inventor name: VERYHA, YAUHENI Inventor name: DRATH, RAINER Inventor name: HOERNICKE, MARIO |
|
| DAX | Request for extension of the european patent (deleted) | ||
| 17Q | First examination report despatched |
Effective date: 20120912 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20171003 |