WO2019006546A1 - Valve bank communication module with safety i/o - Google Patents

Valve bank communication module with safety i/o Download PDF

Info

Publication number
WO2019006546A1
WO2019006546A1 PCT/CA2018/050811 CA2018050811W WO2019006546A1 WO 2019006546 A1 WO2019006546 A1 WO 2019006546A1 CA 2018050811 W CA2018050811 W CA 2018050811W WO 2019006546 A1 WO2019006546 A1 WO 2019006546A1
Authority
WO
WIPO (PCT)
Prior art keywords
safety
communication module
power
fluid valve
controller
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CA2018/050811
Other languages
French (fr)
Inventor
César Armando Prieto SILLER
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Magna International Inc
Original Assignee
Magna International Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Magna International Inc filed Critical Magna International Inc
Publication of WO2019006546A1 publication Critical patent/WO2019006546A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/12Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
    • H04L67/125Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks involving control of end-device applications over a network
    • FMECHANICAL ENGINEERING; LIGHTING; HEATING; WEAPONS; BLASTING
    • F15FLUID-PRESSURE ACTUATORS; HYDRAULICS OR PNEUMATICS IN GENERAL
    • F15BSYSTEMS ACTING BY MEANS OF FLUIDS IN GENERAL; FLUID-PRESSURE ACTUATORS, e.g. SERVOMOTORS; DETAILS OF FLUID-PRESSURE SYSTEMS, NOT OTHERWISE PROVIDED FOR
    • F15B13/00Details of servomotor systems ; Valves for servomotor systems
    • F15B13/02Fluid distribution or supply devices characterised by their adaptation to the control of servomotors
    • F15B13/06Fluid distribution or supply devices characterised by their adaptation to the control of servomotors for use with two or more servomotors
    • F15B13/08Assemblies of units, each for the control of a single servomotor only
    • F15B13/0803Modular units
    • F15B13/0846Electrical details
    • F15B13/085Electrical controllers
    • FMECHANICAL ENGINEERING; LIGHTING; HEATING; WEAPONS; BLASTING
    • F15FLUID-PRESSURE ACTUATORS; HYDRAULICS OR PNEUMATICS IN GENERAL
    • F15BSYSTEMS ACTING BY MEANS OF FLUIDS IN GENERAL; FLUID-PRESSURE ACTUATORS, e.g. SERVOMOTORS; DETAILS OF FLUID-PRESSURE SYSTEMS, NOT OTHERWISE PROVIDED FOR
    • F15B20/00Safety arrangements for fluid actuator systems; Applications of safety devices in fluid actuator systems; Emergency measures for fluid actuator systems
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/26Special purpose or proprietary protocols or architectures

Definitions

  • One type of arrangement includes a communication module to switch an output power and to direct the pneumatic valves to go to a specified fluid flow configuration in response to a control signal that is communicated via a communications channel.
  • a safety output power is a source of energy that can be reliably removed in order to cause devices such as pneumatic valves to go to a known or "safe" state.
  • An objective of the present disclosure is to provide a communication module and an associated method of operation for controlling a safety output power to at least one fluid valve as part of a control system that exceeds the functional safety standard for machinery as set forth in the Safety Integrity Level (SIL) as defined in the International Electrotechnical Commission's (IEC) 61508 standard and/or a Performance Level (PL) safety level as defined by the International Organization for Standardization in ISO 13849-1.
  • SIL Safety Integrity Level
  • IEC International Electrotechnical Commission's
  • PL Performance Level
  • a communication module that can provide a given functional safety standard for machinery up to Performance Level "e” (PLe) and/or Safety Integration Level 4 (SIL4), which each define the highest risk reduction factor (RRF) within the respective functional safety standard and to do so without the need for additional safety I/O devices or an additional safety relay.
  • Pe Performance Level
  • SIL4 Safety Integration Level 4
  • a communication module for controlling a valve bank including at least one fluid valve may include a module body configured to mechanically and electrically couple to the fluid valve or valves and a first communications channel for receiving a first control signal from a safety controller.
  • the communications module may also include an electrical interface for controlling the fluid valves.
  • the communication module provides a second control signal to the fluid valve to change a fluid flow characteristic of the fluid valve based upon the first control signal.
  • a safety power controller within the module body provides a safety output power to the fluid valve.
  • the communication module also includes a safety processor that receives and verifies the integrity of a safety input/output data within the first control signal and which removes the safety output power from the fluid valves in the case of an error in the safety input/output data or in response to a power-off command from the safety controller.
  • communication module is also provided and which includes the steps of receiving by the communication module electrical energy from a power supply; receiving by the communication module a first control signal from a safety controller via a first communications channel;
  • the device and method of the present disclosure may provide several advantages over the prior art including reductions in cost and complexity of a control system that includes fewer safety rated devices, and space savings within control panels and in the physical layout of an automation cell on a factory floor. It may also provide for reduction in the amount of networking cabling required which may reduce cost and increase system reliability. Furthermore, the device and method of the present disclosure may provide for a reduced number of I/O and/or memory requirements within the safety PLC and may simplify the programming of the safety PLC and may also reduce engineering and design time and associated costs.
  • FIG. 1 is a schematic diagram of a system in accordance with the prior art
  • FIG. 2 is a block diagram of a system in accordance with the prior art
  • FIG. 3 is a schematic diagram of a system in accordance with the present disclosure.
  • FIG. 4 is a block diagram of a system in accordance with the present disclosure.
  • FIG. 5 is a flow chart of a method in accordance with the present disclosure. DETAILED DESCRIPTION OF THE EXAMPLE EMBODIMENTS
  • a communication module 20 for controlling a valve bank 22 including at least one fluid valve 24 is disclosed.
  • the fluid valves 24, which may also be called electrovalves, may each be fluidly connected to a mechanical actuator 26, such as those used on industrial machinery, using one or more fluid conduits 28.
  • a communication module 20 is provided for controlling at least one fluid valve 24 within a valve bank 22.
  • the communication module 20 includes a module body 30 with a standard, or non-safety processor 32 and is configured to mechanically and electrically couple to the fluid valves 24 in order to control the flow of a fluid through the fluid valves 24.
  • the standard processor 32 of the communication module 20 is configured to cause a corresponding one of the fluid valves 24 to change its fluid characteristics (i.e. to allow or to disallow fluid communication between two fluid ports) based upon a standard control signal, such as a standard (non-safety) CIP signal, that is communicated via a first
  • a safety controller 36 which may be, for example, a Safety Programmable Logic Controller (PLC) such as a GuardLogix processor by Allen Bradley and which may be installed in a PLC chassis 38.
  • the safety controller 36 may be located within a first electrical panel 40, which may also be called a PLC panel.
  • the communication module 20 may be, for example, an EX600-SEN1 Ethernet/IP module by SMC and may provide Common Industrial Protocol (CIP) connectivity over Ethernet.
  • Industrial Protocol Ethernet (Ethernet/IP) and CIP are both technologies managed by ODVA, Inc. (formerly Open DeviceNet Vendors Association, Inc.) for communications between industrial automation devices.
  • a second electrical panel 42 may be configured to provide the valve bank 22 with safety output power 43 in order to satisfy a given functional safety standard for machinery.
  • the safety output power 43 may be supplied to the valve bank 22 by an electrical power cable 44 connected between the second electrical panel 42 and the communication module 20.
  • the second electrical panel 42 may include a power supply 46, which may supply the communications module with a low voltage DC power, such as 5-50 VDC. In one example embodiment, the power supply 46 provides the valve bank 22 with 24 VDC.
  • the second electrical panel 42 may also include one or more overcurrent protection devices 48 such as fuses or circuit breakers to prevent an electrical current produced from exceeding a predetermined value.
  • the first and second electrical panels 40, 42 may be physically combined together into one combined electrical panel 40, 42.
  • the second electrical panel 42 may further include a safety processor 50, which may include, for instance, a safety Point I/O module such as a 1734-OB8S safety output module from Allen Bradley and one or more safety relays 52 each having redundant and self-monitoring contacts for reliably controlling the supply of the safety output power 43 to the valve bank 22 in order to satisfy the requirements of the given functional safety standard.
  • a safety relay 52 is catalog number 700-Z by Allen Bradley.
  • the safety processor 50 may be responsive to a power-off control signal from the safety controller 36 as communicated by a second communications channel 54 therebetween, which may be designated as a safety communications channel.
  • the safety processor 50 may also monitor the integrity of the second communications channel in order to ensure that vital signals such as the power-off control signal are received and may function to remove the safety output power 43 in case a malfunction in the second communications channel 54 or with the safety controller 36 is detected. Such action by a safety processor 50 may be required in order to satisfy a given functional safety standard for machinery.
  • Other alternative configurations may be used for the second communications channel 54 which are designed and/or certified to verify the integrity of I/O data to satisfy a given functional safety standard for machinery, such as, for example, Safety variations of Device ET, Profibus or Profinet.
  • the communication module 20 includes an electrical interface 56 for controlling the fluid valves 24.
  • the valve bank 22 may be directly mechanically coupled to the communication module 20, which may directly replace an existing (non-safety) communication module 20 of the prior art.
  • the communication module 20 provides a second control signal to the fluid valve 24, which may be communicated, for instance, across a direct mechanical coupling or through a backplane and/or a chassis in order to change a fluid flow characteristic of the fluid valve 24 based upon the first control signal.
  • the second control signal may use, for example, DeviceNet, a serial protocol such as RS-485 and/or a POINTBus protocol by Allen Bradley.
  • RS-485 serial protocol
  • POINTBus protocol by Allen Bradley
  • a plurality of different fluid valves 24 are mechanically coupled to one-another in a stacked configuration, which is mechanically and electrically coupled to the communication module 20.
  • the fluid valves 22 may be provided as modules that individually couple to a backplane or chassis that provides the electrical and mechanical connection to the communication module 20.
  • One or more of the fluid valves 24 may also be provided with a source of pressurized fluid from the backplane or chassis or from one or more adjacent ones of the fluid valves 24 in the valve stack 22.
  • the fluid valves 24 may control, hydraulic or pneumatic (e.g. compressed air) flow to a mechanical actuator 26 such as in an industrial machine.
  • a communication module 20 for controlling a valve bank 22 including at least one fluid valve 24 includes a module body 30 configured to mechanically and electrically couple to the fluid valve or valves 24 and which also includes a safety processor 50 is provided.
  • the communication module 20 may be configured to receive a first control signal, which may be for example, a CIP safety signal or an ASIsafe signal or a Profisafe signal via a first communications channel 34 from a safety controller 36, which may be, for example, a safety PLC such as a GuardLogix processor by Allen Bradley.
  • the first communications channel 34 may transmit the first control signal using one or more physical networks, which may use, for example, EtherNet/IP and/or DeviceNet protocols.
  • the first communications channel 34 may be designed and/or certified to verify the integrity of I/O data to satisfy a given functional safety standard for machinery, such as, for example, Safety variations of ControlNet, EtherCat, Profibus, Profinet, or AS-Interface (AS-i).
  • AS-i AS-Interface
  • the power supply 46 directly provides electrical power, such as a low voltage power to the communication module 20, without the electrical power being interrupted by a safety power controller 58 before the communication module 20. Therefore, the communications module 20 can remain powered and able to provide diagnostics and other communications, even in cases where safety power is removed, for example, if an emergency stop (E-stop) is activated.
  • the low voltage power provided by the power supply 46 may be 3-60 V AC or DC and is preferably 12 VDC or 24 VDC or 24 VAC.
  • the communication module 20 may be directly powered with AC control power such as 120 VAC or 250 VAC.
  • a safety power controller 58 within the module body 30 provides a safety output power 43 to the fluid valve 24.
  • the communication module 20 also includes a safety processor 50 that receives and verifies the integrity of safety input/output data within the first control signal and which may also monitor the safety power controller 58 and which removes the safety output power 43 from the fluid valve 24 in the case of an error in the safety input/output data or in response to a power-off command from the safety controller 36.
  • the first, or safety control signal may enable the safety power controller 58 to reliably control the safety output power 43 supplied to the fluid valves 24 in order to satisfy the given functional safety standard for machinery.
  • the present disclosure provides a communication module 20 that accepts a CD 3 safety control signal to reliably control each of fluid valves 24 and which also triggers the safety output power 43 to the fluid valves 24 on and off without the need for additional safety hardware.
  • the communication module 20 is also configured to control and/or monitor one or more electrical input or output (I/O) channels connected to an electrical I/O interface 60 which is mechanically and electrically coupled to the module body 30.
  • the electrical I/O may include one or more digital, analog, and/or specialty inputs or outputs, which may be configured to control and/or monitor one or more electrical signals by the safety controller 36. Specialty inputs may include, for example, thermocouple or RTD temperature inputs.
  • the electrical I/O interface 60 also be configured to use the safety output power 43.
  • the first, or safety control signal may enable the safety power controller 58 to reliably control the safety output power 43 supplied to the electrical I/O interface 60 in order to satisfy the given functional safety standard for machinery.
  • the communication module 20 may also include a safety relay 52 having redundant and self-monitoring contacts for removing the safety output power 43 from the fluid valve 24 in the presence of a malfunction with the safety power controller 58.
  • a safety relay 52 may include, for example, multiple positive-guided relays which can detect malfunctions such as a stuck or "welded" contact, and which include redundant contacts capable of switching the safety output power 43 even when a malfunction exists.
  • Such a safety relay 52 may also signal the detection of a detected malfunction to prevent the safety output power 43 from being restored until the malfunctioning component is replaced.
  • the subject disclosure also includes a method 100 for controlling a safety output power 43 to a fluid valve 24 by a communication module 20 and which includes the steps of: 102 receiving by the communication module 20 electrical energy from a power supply 46; 104 receiving by the communication module 20 a first control signal from a safety controller 36 via a first communications channel 34; 106 receiving and verifying the integrity of safety input/output data within the first control signal by the safety processor 50 of the communication module 20; and 108 removing by the safety power controller 58 the safety output power 43 to the fluid valve 24 in response to an error in the safety input/output data or in response to a power-off command from the safety controller 36.
  • Such a power-off command may include, for example, an emergency stop (e-stop) command to remove the safety output power 43 from the fluid valve 24 and to thereby cause any machinery connected thereto to go to a known safe condition.
  • the method 100 may also include the step of 110 removing by the safety power controller 58 the safety output power 43 from the fluid valve 24 in the presence of a malfunction with the safety power controller, such as may be detected by a safety relay 52 within the safety power controller and which has redundant and self-monitoring circuitry.
  • Errors in the input/output data may include lost or malformed data packets, such as those that fail an error checking mechanism or those that are not received within a

Landscapes

  • Engineering & Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Computing Systems (AREA)
  • Signal Processing (AREA)
  • Fluid Mechanics (AREA)
  • Mechanical Engineering (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Medical Informatics (AREA)
  • Chemical & Material Sciences (AREA)
  • Analytical Chemistry (AREA)
  • Computer Security & Cryptography (AREA)
  • Safety Devices In Control Systems (AREA)

Abstract

A communication module and associated method of operation for controlling a valve bank including at least one fluid valve is provided. The communication module includes a module body mechanically and electrically coupled to the fluid valves and includes a safety processor which is responsive to a CIP safety control signal from a safety controller. The communication module also includes a safety power controller that is operable to remove safety output power from the fluid valves connected thereto in order to satisfy a given functional safety standard for machinery such as PLe or SIL4. The communication module may also include a safety relay with redundant and self-monitoring contacts to further its ability to reliably remove the safety output power from the fluid valves, particularly in the presence of a malfunction with the safety power controller.

Description

VALVE BANK COMMUNICATION MODULE WITH SAFETY I/O
CROSS REFERENCE TO RELATED APPLICATION
[0001] This PCT International Patent Application claims the benefit of U.S. Provisional
Patent Application Serial No. 62/528, 110 filed July 2, 2017 entitled "Valve Bank
Communication Module with Safety I/O," the entire disclosure of the application being considered part of the disclosure of this application and hereby incorporated by reference.
BACKGROUND
[0002] Different arrangements exist for controlling valve banks of one or more pneumatic valves such as those used for industrial automation equipment. One type of arrangement includes a communication module to switch an output power and to direct the pneumatic valves to go to a specified fluid flow configuration in response to a control signal that is communicated via a communications channel. A safety output power is a source of energy that can be reliably removed in order to cause devices such as pneumatic valves to go to a known or "safe" state.
[0003] An objective of the present disclosure is to provide a communication module and an associated method of operation for controlling a safety output power to at least one fluid valve as part of a control system that exceeds the functional safety standard for machinery as set forth in the Safety Integrity Level (SIL) as defined in the International Electrotechnical Commission's (IEC) 61508 standard and/or a Performance Level (PL) safety level as defined by the International Organization for Standardization in ISO 13849-1. In particular, it is an objective to provide a communication module that can provide a given functional safety standard for machinery up to Performance Level "e" (PLe) and/or Safety Integration Level 4 (SIL4), which each define the highest risk reduction factor (RRF) within the respective functional safety standard and to do so without the need for additional safety I/O devices or an additional safety relay.
SUMMARY
[0004] A communication module for controlling a valve bank including at least one fluid valve is provided. The communication module may include a module body configured to mechanically and electrically couple to the fluid valve or valves and a first communications channel for receiving a first control signal from a safety controller. The communications module may also include an electrical interface for controlling the fluid valves. The communication module provides a second control signal to the fluid valve to change a fluid flow characteristic of the fluid valve based upon the first control signal. A safety power controller within the module body provides a safety output power to the fluid valve. The communication module also includes a safety processor that receives and verifies the integrity of a safety input/output data within the first control signal and which removes the safety output power from the fluid valves in the case of an error in the safety input/output data or in response to a power-off command from the safety controller.
[0005] A method for controlling a safety output power to a fluid valve by a
communication module is also provided and which includes the steps of receiving by the communication module electrical energy from a power supply; receiving by the communication module a first control signal from a safety controller via a first communications channel;
receiving and verifying the integrity of a safety input/output data within the first control signal by the safety processor of the communication module; and removing by the safety power controller the safety output power to the fluid valve or valves in response to an error in the safety input/output data or in response to a power-off command from the safety controller.
[0006] The device and method of the present disclosure may provide several advantages over the prior art including reductions in cost and complexity of a control system that includes fewer safety rated devices, and space savings within control panels and in the physical layout of an automation cell on a factory floor. It may also provide for reduction in the amount of networking cabling required which may reduce cost and increase system reliability. Furthermore, the device and method of the present disclosure may provide for a reduced number of I/O and/or memory requirements within the safety PLC and may simplify the programming of the safety PLC and may also reduce engineering and design time and associated costs.
DESCRIPTION OF THE DRAWINGS
[0007] The detailed description refers to the following drawings, in which like numerals refer to like items, and in which:
[0008] FIG. 1 is a schematic diagram of a system in accordance with the prior art;
[0009] FIG. 2 is a block diagram of a system in accordance with the prior art;
[0010] FIG. 3 is a schematic diagram of a system in accordance with the present disclosure;
[0011] FIG. 4 is a block diagram of a system in accordance with the present disclosure; and
[0012] FIG. 5 is a flow chart of a method in accordance with the present disclosure. DETAILED DESCRIPTION OF THE EXAMPLE EMBODIMENTS
[0013] The invention is described more fully hereinafter with references to the accompanying drawings, in which exemplary embodiments of the invention are shown. This invention may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these exemplary embodiments are provided so that this disclosure is thorough, and will fully convey the scope of the invention to those skilled in the art. It will be understood that for the purposes of this disclosure, "at least one of each" will be interpreted to mean any combination the enumerated elements following the respective language, including combination of multiples of the enumerated elements. For example, "at least one of X, Y, and Z" will be construed to mean X only, Y only, Z only, or any combination of two or more items X, Y, and Z (e.g., XYZ, XZ, YZ, X). Throughout the drawings and the detailed description, unless otherwise described, the same drawing reference numerals are understood to refer to the same elements, features, and structures. The relative size and depiction of these elements may be exaggerated for clarity, illustration, and convenience. Unless otherwise stated, any reference to moving between two or more different positions should be construed as including moving in either direction from one position to another position or vice-versa.
[0014] Referring to the Figures, wherein like numerals indicate corresponding parts throughout the several views, a communication module 20 for controlling a valve bank 22 including at least one fluid valve 24 is disclosed. The fluid valves 24, which may also be called electrovalves, may each be fluidly connected to a mechanical actuator 26, such as those used on industrial machinery, using one or more fluid conduits 28. [0015] As shown in FIGS. 1-2, a communication module 20 is provided for controlling at least one fluid valve 24 within a valve bank 22. The communication module 20 includes a module body 30 with a standard, or non-safety processor 32 and is configured to mechanically and electrically couple to the fluid valves 24 in order to control the flow of a fluid through the fluid valves 24. The standard processor 32 of the communication module 20 is configured to cause a corresponding one of the fluid valves 24 to change its fluid characteristics (i.e. to allow or to disallow fluid communication between two fluid ports) based upon a standard control signal, such as a standard (non-safety) CIP signal, that is communicated via a first
communications channel 34 from a safety controller 36, which may be, for example, a Safety Programmable Logic Controller (PLC) such as a GuardLogix processor by Allen Bradley and which may be installed in a PLC chassis 38. The safety controller 36 may be located within a first electrical panel 40, which may also be called a PLC panel. The communication module 20 may be, for example, an EX600-SEN1 Ethernet/IP module by SMC and may provide Common Industrial Protocol (CIP) connectivity over Ethernet. Industrial Protocol Ethernet (Ethernet/IP) and CIP are both technologies managed by ODVA, Inc. (formerly Open DeviceNet Vendors Association, Inc.) for communications between industrial automation devices.
[0016] As shown in Fig. 1, a second electrical panel 42 may be configured to provide the valve bank 22 with safety output power 43 in order to satisfy a given functional safety standard for machinery. The safety output power 43 may be supplied to the valve bank 22 by an electrical power cable 44 connected between the second electrical panel 42 and the communication module 20. The second electrical panel 42 may include a power supply 46, which may supply the communications module with a low voltage DC power, such as 5-50 VDC. In one example embodiment, the power supply 46 provides the valve bank 22 with 24 VDC. The second electrical panel 42 may also include one or more overcurrent protection devices 48 such as fuses or circuit breakers to prevent an electrical current produced from exceeding a predetermined value. The first and second electrical panels 40, 42 may be physically combined together into one combined electrical panel 40, 42. The second electrical panel 42 may further include a safety processor 50, which may include, for instance, a safety Point I/O module such as a 1734-OB8S safety output module from Allen Bradley and one or more safety relays 52 each having redundant and self-monitoring contacts for reliably controlling the supply of the safety output power 43 to the valve bank 22 in order to satisfy the requirements of the given functional safety standard. An example of such a safety relay 52 is catalog number 700-Z by Allen Bradley. The safety processor 50 may be responsive to a power-off control signal from the safety controller 36 as communicated by a second communications channel 54 therebetween, which may be designated as a safety communications channel. The safety processor 50 may also monitor the integrity of the second communications channel in order to ensure that vital signals such as the power-off control signal are received and may function to remove the safety output power 43 in case a malfunction in the second communications channel 54 or with the safety controller 36 is detected. Such action by a safety processor 50 may be required in order to satisfy a given functional safety standard for machinery. Other alternative configurations may be used for the second communications channel 54 which are designed and/or certified to verify the integrity of I/O data to satisfy a given functional safety standard for machinery, such as, for example, Safety variations of Device ET, Profibus or Profinet.
[0017] The communication module 20 includes an electrical interface 56 for controlling the fluid valves 24. As shown in FIGS. 1-4, the valve bank 22 may be directly mechanically coupled to the communication module 20, which may directly replace an existing (non-safety) communication module 20 of the prior art. The communication module 20 provides a second control signal to the fluid valve 24, which may be communicated, for instance, across a direct mechanical coupling or through a backplane and/or a chassis in order to change a fluid flow characteristic of the fluid valve 24 based upon the first control signal. The second control signal may use, for example, DeviceNet, a serial protocol such as RS-485 and/or a POINTBus protocol by Allen Bradley. In the example shown in FIGS. 1-4, a plurality of different fluid valves 24 are mechanically coupled to one-another in a stacked configuration, which is mechanically and electrically coupled to the communication module 20. Alternatively, the fluid valves 22 may be provided as modules that individually couple to a backplane or chassis that provides the electrical and mechanical connection to the communication module 20. One or more of the fluid valves 24 may also be provided with a source of pressurized fluid from the backplane or chassis or from one or more adjacent ones of the fluid valves 24 in the valve stack 22. As shown in FIGS. 1 and 3, the fluid valves 24 may control, hydraulic or pneumatic (e.g. compressed air) flow to a mechanical actuator 26 such as in an industrial machine.
[0018] In accordance with the present invention and as shown in FIGS. 3-4, a communication module 20 for controlling a valve bank 22 including at least one fluid valve 24 includes a module body 30 configured to mechanically and electrically couple to the fluid valve or valves 24 and which also includes a safety processor 50 is provided. The communication module 20 may be configured to receive a first control signal, which may be for example, a CIP safety signal or an ASIsafe signal or a Profisafe signal via a first communications channel 34 from a safety controller 36, which may be, for example, a safety PLC such as a GuardLogix processor by Allen Bradley. The first communications channel 34 may transmit the first control signal using one or more physical networks, which may use, for example, EtherNet/IP and/or DeviceNet protocols. Other networking hardware and/or protocols may be used for the first communications channel 34 which are designed and/or certified to verify the integrity of I/O data to satisfy a given functional safety standard for machinery, such as, for example, Safety variations of ControlNet, EtherCat, Profibus, Profinet, or AS-Interface (AS-i).
[0019] As also shown in FIGS. 3-4, the power supply 46 directly provides electrical power, such as a low voltage power to the communication module 20, without the electrical power being interrupted by a safety power controller 58 before the communication module 20. Therefore, the communications module 20 can remain powered and able to provide diagnostics and other communications, even in cases where safety power is removed, for example, if an emergency stop (E-stop) is activated. The low voltage power provided by the power supply 46 may be 3-60 V AC or DC and is preferably 12 VDC or 24 VDC or 24 VAC. Alternatively, the communication module 20 may be directly powered with AC control power such as 120 VAC or 250 VAC.
[0020] In accordance with the present invention and as shown in FIGS. 3-4, a safety power controller 58 within the module body 30 provides a safety output power 43 to the fluid valve 24. The communication module 20 also includes a safety processor 50 that receives and verifies the integrity of safety input/output data within the first control signal and which may also monitor the safety power controller 58 and which removes the safety output power 43 from the fluid valve 24 in the case of an error in the safety input/output data or in response to a power-off command from the safety controller 36. The first, or safety control signal may enable the safety power controller 58 to reliably control the safety output power 43 supplied to the fluid valves 24 in order to satisfy the given functional safety standard for machinery. In other words, the present disclosure provides a communication module 20 that accepts a CD3 safety control signal to reliably control each of fluid valves 24 and which also triggers the safety output power 43 to the fluid valves 24 on and off without the need for additional safety hardware.
[0021] As also shown in FIG. 3, the communication module 20 is also configured to control and/or monitor one or more electrical input or output (I/O) channels connected to an electrical I/O interface 60 which is mechanically and electrically coupled to the module body 30. The electrical I/O may include one or more digital, analog, and/or specialty inputs or outputs, which may be configured to control and/or monitor one or more electrical signals by the safety controller 36. Specialty inputs may include, for example, thermocouple or RTD temperature inputs. The electrical I/O interface 60 also be configured to use the safety output power 43. The first, or safety control signal may enable the safety power controller 58 to reliably control the safety output power 43 supplied to the electrical I/O interface 60 in order to satisfy the given functional safety standard for machinery.
[0022] According to an aspect, the communication module 20 may also include a safety relay 52 having redundant and self-monitoring contacts for removing the safety output power 43 from the fluid valve 24 in the presence of a malfunction with the safety power controller 58. Such a safety relay 52 may include, for example, multiple positive-guided relays which can detect malfunctions such as a stuck or "welded" contact, and which include redundant contacts capable of switching the safety output power 43 even when a malfunction exists. Such a safety relay 52 may also signal the detection of a detected malfunction to prevent the safety output power 43 from being restored until the malfunctioning component is replaced. [0023] As shown in FIG. 5, the subject disclosure also includes a method 100 for controlling a safety output power 43 to a fluid valve 24 by a communication module 20 and which includes the steps of: 102 receiving by the communication module 20 electrical energy from a power supply 46; 104 receiving by the communication module 20 a first control signal from a safety controller 36 via a first communications channel 34; 106 receiving and verifying the integrity of safety input/output data within the first control signal by the safety processor 50 of the communication module 20; and 108 removing by the safety power controller 58 the safety output power 43 to the fluid valve 24 in response to an error in the safety input/output data or in response to a power-off command from the safety controller 36. Such a power-off command may include, for example, an emergency stop (e-stop) command to remove the safety output power 43 from the fluid valve 24 and to thereby cause any machinery connected thereto to go to a known safe condition. The method 100 may also include the step of 110 removing by the safety power controller 58 the safety output power 43 from the fluid valve 24 in the presence of a malfunction with the safety power controller, such as may be detected by a safety relay 52 within the safety power controller and which has redundant and self-monitoring circuitry. Errors in the input/output data may include lost or malformed data packets, such as those that fail an error checking mechanism or those that are not received within a
predetermined period of time.
[0024] Obviously, many modifications and variations of the present invention are possible in light of the above teachings and may be practiced otherwise than as specifically described while within the scope of the appended claims.

Claims

CLAIMS What is claimed is:
Claim 1. A communication module for controlling a valve bank including a fluid valve and comprising:
a module body configured to mechanically and electrically couple to the fluid valve in the valve bank;
a first communications channel for receiving a first control signal from a safety controller;
an electrical interface for controlling the at least one fluid valve;
wherein said communication module provides a second control signal to the at least one fluid valve to change a fluid flow characteristic of the at least one fluid valve based upon said first control signal;
a safety power controller within said module body providing a safety output power to said at least one fluid valve; and
a safety processor configured to receive and verify the integrity of a safety input/output data within the first control signal to cause said safety power controller to remove said safety output power from said at least one fluid valve in the case of an error in said safety input/output data or in response to a power-off command from the safety controller.
Claim 2. The communication module according to Claim 1, wherein said safety power controller includes a safety relay having redundant and self-monitoring contacts for removing said safety output power from said at least one fluid valve in the presence of a malfunction with said safety power controller.
Claim 3. The communication module according to Claim 1, wherein said first communications channel uses Common Industrial Protocol (CIP) safety protocol.
Claim 4. The communication module according to Claim 1, wherein said first communications channel uses an EtherNet/IP protocol.
Claim 5. The communication module according to Claim 1, wherein said first communications channel uses a DeviceNet protocol.
Claim 6. The communication module according to Claim 1, wherein said first communications channel uses a PROFINET protocol.
Claim 7. The communication module according to Claim 1, further including said communication module receiving a low-voltage DC power from a power supply.
Claim 8. The communication module according to Claim 7, wherein said power supply provides said low-voltage DC power at 24 VDC.
Claim 9. The communication module according to Claim 7, wherein said safety output power is sourced from said low-voltage DC power.
Claim 10. The communication module according to Claim 1, wherein said module body is mechanically and electrically coupled to said fluid valve with one of a backplane or a chassis.
Claim 11. The communication module according to Claim 1, wherein said second control signal uses a POINTBus protocol.
Claim 12. The communication module according to Claim 1, wherein said valve bank includes a plurality of fluid valves in a stacked configuration electrically and
mechanically coupled to said module body.
Claim 13. The communication module according to Claim 1, wherein said safety processor is configured to control or to monitor an electrical input or output channel connected to an electrical I/O interface electrically and mechanically coupled to said module body.
Claim 14. A method for controlling a safety output power to at least one fluid valve by a communication module comprising:
receiving by the communication module a first control signal from a safety controller via a first communications channel;
receiving and verifying the integrity of a safety input/output data within the first control signal by a safety processor of the communication module; and removing by a safety power controller of the communication module the safety output power to the at least one fluid valve in response to an error in the safety input/output data or in response to a power-off command from the safety controller.
Claim 15. The method for controlling a safety output power to at least one fluid valve by a communication module according to Claim 14 and further including:
removing by the safety power controller the safety output power from the at least one fluid valve in the presence of a malfunction with the safety power controller.
PCT/CA2018/050811 2017-07-02 2018-06-29 Valve bank communication module with safety i/o Ceased WO2019006546A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US201762528110P 2017-07-02 2017-07-02
US62/528,110 2017-07-02

Publications (1)

Publication Number Publication Date
WO2019006546A1 true WO2019006546A1 (en) 2019-01-10

Family

ID=64949557

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CA2018/050811 Ceased WO2019006546A1 (en) 2017-07-02 2018-06-29 Valve bank communication module with safety i/o

Country Status (1)

Country Link
WO (1) WO2019006546A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116228205A (en) * 2023-03-29 2023-06-06 东莞先知大数据有限公司 Charging pile outage risk diagnosis method, device and storage medium

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030236579A1 (en) * 2000-07-07 2003-12-25 Markus Hauhia Wireless diagnostic system in industrial processes
US20120296448A1 (en) * 2011-05-19 2012-11-22 Fisher-Rosemount Systems, Inc. Software lockout coordination between a process control system and an asset management system
US20160041539A1 (en) * 2014-08-11 2016-02-11 Fisher Controls International Llc Control device diagnostic using accelerometer

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030236579A1 (en) * 2000-07-07 2003-12-25 Markus Hauhia Wireless diagnostic system in industrial processes
US20120296448A1 (en) * 2011-05-19 2012-11-22 Fisher-Rosemount Systems, Inc. Software lockout coordination between a process control system and an asset management system
US20160041539A1 (en) * 2014-08-11 2016-02-11 Fisher Controls International Llc Control device diagnostic using accelerometer

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116228205A (en) * 2023-03-29 2023-06-06 东莞先知大数据有限公司 Charging pile outage risk diagnosis method, device and storage medium
CN116228205B (en) * 2023-03-29 2023-11-21 东莞先知大数据有限公司 Charging pile outage risk diagnosis method, device and storage medium

Similar Documents

Publication Publication Date Title
RU2543366C2 (en) Apparatus, method and programme for test of solenoids of automatic safety systems
US10089271B2 (en) Field bus system
US8867184B2 (en) Electrical circuit with redundant trunk
CN215416351U (en) Fault-tolerant redundancy control device
US9852852B2 (en) Safety switching apparatus with switching element in the auxiliary contact current path
CN104795275A (en) Safety relay with contacts capable of being detected independently
US20080294273A1 (en) Combination control system with intermediate module
CN103975407B (en) The motor starter of safety
CN103339572A (en) Safety switching devices for fail-safe switching off of consumers
WO2009045246A1 (en) Valve manifold assemblies and method of operating valve manifold assemblies
US20070182255A1 (en) Safety switching module
CN109644150B (en) Serial modules, functional module units and control units of modular construction
CN109565250B (en) Soft starter, operation method and switch system
WO2019006546A1 (en) Valve bank communication module with safety i/o
KR102014691B1 (en) Remote input-output apparatus for industrial controllers with duplicated power and compler module
US20120123562A1 (en) Control system for controlling a process
SE541958C2 (en) Safe tool changer
EP3196913B1 (en) Relay circuit and method for performing self-test of relay circuit
US20220206451A1 (en) System having a controller and having an actuator and also having an assembly for providing functional safety
CN112653562B (en) Power supply module
EP3217603B1 (en) Communications device comprising relays
CN102545150B (en) Fail-safe switch module
CN103998998B (en) There is the security system of expansion module
JP3248777U (en) Programmable Logic Controller Redundancy System
CN108700858B (en) Safety switching device and safety-oriented device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18829106

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18829106

Country of ref document: EP

Kind code of ref document: A1