WO2021127805A1 - 一种变频器的功能安全装置 - Google Patents

一种变频器的功能安全装置 Download PDF

Info

Publication number
WO2021127805A1
WO2021127805A1 PCT/CN2019/127312 CN2019127312W WO2021127805A1 WO 2021127805 A1 WO2021127805 A1 WO 2021127805A1 CN 2019127312 W CN2019127312 W CN 2019127312W WO 2021127805 A1 WO2021127805 A1 WO 2021127805A1
Authority
WO
WIPO (PCT)
Prior art keywords
functional safety
module
controller
frequency converter
trigger
Prior art date
Application number
PCT/CN2019/127312
Other languages
English (en)
French (fr)
Inventor
付吉勇
唐益宏
Original Assignee
深圳市英威腾电气股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳市英威腾电气股份有限公司 filed Critical 深圳市英威腾电气股份有限公司
Priority to PCT/CN2019/127312 priority Critical patent/WO2021127805A1/zh
Priority to CN201980100990.7A priority patent/CN114467062A/zh
Publication of WO2021127805A1 publication Critical patent/WO2021127805A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G01MEASURING; TESTING
    • G01RMEASURING ELECTRIC VARIABLES; MEASURING MAGNETIC VARIABLES
    • G01R31/00Arrangements for testing electric properties; Arrangements for locating electric faults; Arrangements for electrical testing characterised by what is being tested not provided for elsewhere
    • GPHYSICS
    • G05CONTROLLING; REGULATING
    • G05BCONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
    • G05B9/00Safety arrangements
    • G05B9/02Safety arrangements electric
    • G05B9/03Safety arrangements electric with multiple-channel loop, i.e. redundant control systems
    • HELECTRICITY
    • H02GENERATION; CONVERSION OR DISTRIBUTION OF ELECTRIC POWER
    • H02HEMERGENCY PROTECTIVE CIRCUIT ARRANGEMENTS
    • H02H3/00Emergency protective circuit arrangements for automatic disconnection directly responsive to an undesired change from normal electric working condition with or without subsequent reconnection ; integrated protection
    • H02H3/02Details
    • H02H3/05Details with means for increasing reliability, e.g. redundancy arrangements

Definitions

  • the invention relates to the field of mechanical safety, in particular to a functional safety device of a frequency converter.
  • the purpose of the present invention is to provide a functional safety device for the frequency converter.
  • the functional safety device and the frequency converter product are independently set up, and there is no shared relationship between some software and hardware modules, thereby reducing the design difficulty of the frequency converter product; moreover, in the follow-up When the product design is upgraded, the functional safety device and the inverter product do not interfere with each other, thereby reducing the difficulty of design upgrading and higher flexibility.
  • the present invention provides a functional safety device for a frequency converter, including:
  • the detection module connected with the motor is used to detect the working parameters of the motor
  • the functional safety modules which are located outside the inverter and respectively connected to the detection module and the inverter, are used to determine the inverter based on the motor operating parameters and the inverter operating parameters sent by the inverter Whether it meets the preset functional safety trigger condition, and if so, triggers the functional safety operation of the frequency converter.
  • the functional safety module includes:
  • the first functional safety sub-module respectively connected to the detection module and the frequency converter is used to send the working parameters of the frequency converter to the second functional safety sub-module;
  • a second functional safety sub-module connected to the detection module and having the same structure as the first functional safety sub-module;
  • the first functional safety submodule and the second functional safety submodule are both used to determine whether the same type of data received by the two functional safety modules are consistent, and if so, perform corresponding operations based on the same type of data; if not, Then directly trigger the functional safety operation of the inverter.
  • the first functional safety sub-module includes:
  • Command input module used to receive functional safety commands
  • a functional safety trigger module connected to the frequency converter
  • a first controller connected to the instruction input module, the detection module, the functional safety trigger module, and the frequency converter respectively, and is used to send the working parameters of the frequency converter to the second functional safety sub-module In the second controller; determine whether the data of the same type received by the controllers in the two functional safety modules are consistent, if so, perform corresponding operations according to the same type of data; if not, use the functional safety trigger module to directly trigger Functional safety operation of the frequency converter;
  • the same type of data includes motor working parameters and functional safety instructions.
  • the functional safety instructions include SBC instructions
  • the first functional safety sub-module further includes:
  • the instruction output module respectively connected to the motor brake device and the first controller; the first controller is also used to send the brake device to the motor brake device through the instruction output module after receiving the SBC instruction A brake command to enable the motor brake device to perform a motor brake operation.
  • the first functional safety sub-module further includes:
  • the software and hardware fault diagnosis modules respectively connected to the instruction input module, the instruction output module, the first controller, and the functional safety trigger module are used to detect whether the module device connected to itself has a fault; if so, Then when the first controller is normal, the first controller is used to trigger the functional safety operation of the frequency converter; when the first controller is abnormal, the functional safety trigger module is directly used to trigger the frequency conversion Functional safety operation of the device.
  • the instruction input module includes:
  • the first switch connected to the DC power supply at the first end is used to be in the closed state when there is no functional safety command input, and to be in the open state when there is a functional safety command input; wherein the command input in the second functional safety submodule
  • the second switch included in the module and the first switch form a linkage switch;
  • Command input channel modules respectively connected to the second end of the first switch and the first controller
  • the first controller is further configured to use the software and hardware fault diagnosis module to periodically send diagnostic pulses to the instruction input channel module to detect whether the instruction input module exists based on the condition of the pulse signal output by the instruction input channel module If the fault is, the functional safety trigger module is used to trigger the functional safety operation of the frequency converter.
  • the motor brake device includes a safety brake power supply, a first relay, a second relay, and a brake brake device;
  • the first relay includes a first coil and a first contact switch;
  • the second relay Including the second coil and the second contact switch; among them:
  • the safety brake power supply is connected to the first end of the first contact switch, the second end of the first contact switch is connected to the first end of the second contact switch, and the second contact
  • the second end of the point switch is connected to the brake device, the first end of the first coil and the first end of the second coil are both connected to a DC power source, and the second end of the first coil Are respectively connected to the instruction output module and the software and hardware fault diagnosis module in the first functional safety sub-module, and the second end of the second coil is respectively connected to the instruction output module and the software and hardware fault diagnosis in the second functional safety sub-module Module connection;
  • the first controller is specifically configured to control the first coil to turn off and the first contact switch to turn on through the instruction output module after receiving the SBC instruction, so that the brake device is de-energized Perform motor brake operation;
  • the first controller is also used to detect whether the corresponding instruction output module has a fault according to the on-off condition of the first coil fed back by the software and hardware fault diagnosis module, and if so, use the functional safety trigger module to trigger the Describes the functional safety operation of the inverter.
  • the software and hardware fault diagnosis module is specifically configured to detect whether the first controller exists according to the timing of the pulse signal output by the GPIO pin of the first controller If it is a fault, the functional safety trigger module is directly used to trigger the functional safety operation of the frequency converter.
  • the first controller is further configured to use the functional safety trigger module to send a diagnostic pulse signal to the frequency converter to determine the safety trigger channel of the functional safety trigger module based on the signal condition fed back by the frequency converter Whether it meets the expected working state, if not, the functional safety trigger module is used to trigger the functional safety operation of the inverter.
  • the functional safety device further includes:
  • the parameter setting module connected to the first controller is used to set a one-to-one correspondence between different input channels of the instruction input module and different functional safety instructions, and/or set different parameters received by the first controller One-to-one correspondence with different functional safety operations, and sending the correspondence to the first controller;
  • a status display module connected to the second controller; the second controller is configured to output the corresponding relationship to the status display module after receiving the corresponding relationship sent by the first controller .
  • the present invention provides a functional safety device of the frequency converter, which is independent of the setting of the frequency converter. It can trigger the function of the frequency converter when it is determined that the frequency converter meets the preset functional safety triggering conditions according to the working parameters of the motor and the frequency converter. Safe operation to ensure the functional safety of the inverter. It can be seen that the functional safety device of this application and the inverter product are independently set up, and there is no shared relationship between some software and hardware modules, thus reducing the design difficulty of the inverter product; moreover, in the subsequent product design upgrade, the functional safety device and the inverter The device products do not interfere with each other, thereby reducing the difficulty of design upgrades and higher flexibility.
  • Fig. 1 is a schematic structural diagram of a functional safety device for a frequency converter according to an embodiment of the present invention
  • FIG. 2 is a schematic diagram of a specific structure of a functional safety device of a frequency converter provided by an embodiment of the present invention
  • FIG. 3 is a schematic diagram of diagnosis of an instruction input module provided by an embodiment of the present invention.
  • FIG. 4 is a schematic diagram of diagnosis of an instruction output module provided by an embodiment of the present invention.
  • FIG. 5 is a schematic diagram of diagnosis of a controller provided by an embodiment of the present invention.
  • FIG. 6 is a schematic diagram of timing monitoring of a controller provided by an embodiment of the present invention.
  • FIG. 7 is a schematic diagram of signal transmission of a functional safety trigger module provided by an embodiment of the present invention.
  • the core of the present invention is to provide a functional safety device of the frequency converter.
  • the functional safety device and the frequency converter product are independently set up, and there is no shared relationship between some software and hardware modules, thereby reducing the design difficulty of the frequency converter product; moreover, in the follow-up When the product design is upgraded, the functional safety device and the inverter product do not interfere with each other, thereby reducing the difficulty of design upgrading and higher flexibility.
  • FIG. 1 is a schematic structural diagram of a functional safety device for a frequency converter according to an embodiment of the present invention.
  • the functional safety devices of the inverter include:
  • the detection module 1 connected with the motor is used to detect the working parameters of the motor;
  • the functional safety module 2 which is located outside the inverter and connected to the detection module 1 and the inverter respectively, is used to determine whether the inverter is satisfied with the preset functional safety trigger according to the working parameters of the motor and the working parameters of the inverter sent by the inverter The condition, if yes, triggers the functional safety operation of the inverter.
  • the functional safety device of the inverter of this application is independent of the inverter product settings, and includes the detection module 1 and the functional safety module 2. Its working principle is:
  • the detection module 1 is connected to the motor, can detect the working parameters of the motor, and send the working parameters of the motor to the functional safety module 2.
  • Functional safety module 2 receives the motor working parameters on the one hand; on the other hand, it interacts with the inverter to obtain the inverter working parameters from the inverter, and then determines whether the inverter is satisfied with the preset functional safety trigger according to the motor working parameters and the inverter working parameters Condition: If the inverter meets the preset functional safety trigger conditions, the inverter's functional safety operation will be triggered; if the inverter does not meet the preset functional safety trigger conditions, the inverter's functional safety operation will not be triggered.
  • the functional safety trigger conditions are set in advance, and the functional safety operation of the inverter triggered when the functional safety trigger conditions are met is also set in advance.
  • the detection module 1 of the present application is a speed and direction measurement module used to detect motor speed and motor rotation
  • the functional safety trigger conditions include: the motor speed exceeds the preset speed threshold, and the corresponding trigger is the SLS (safely limited speed) of the inverter. ) Functional safety operation; the motor rotates incorrectly, and the corresponding trigger is the STO (Safe Torque Off) functional safety operation of the inverter.
  • the present invention provides a functional safety device of the frequency converter, which is independent of the setting of the frequency converter. It can trigger the function of the frequency converter when it is determined that the frequency converter meets the preset functional safety triggering conditions according to the working parameters of the motor and the frequency converter. Safe operation to ensure the functional safety of the inverter. It can be seen that the functional safety device of this application and the inverter product are independently set up, and there is no shared relationship between some software and hardware modules, thus reducing the design difficulty of the inverter product; moreover, in the subsequent product design upgrade, the functional safety device and the inverter The device products do not interfere with each other, thereby reducing the difficulty of design upgrades and higher flexibility.
  • FIG. 2 is a schematic diagram of a specific structure of a functional safety device of a frequency converter according to an embodiment of the present invention.
  • the functional safety device is based on the above embodiment:
  • the functional safety module 2 includes:
  • the first functional safety sub-module connected to the detection module and the frequency converter respectively is used to send the working parameters of the frequency converter to the second functional safety sub-module;
  • a second functional safety sub-module connected to the detection module and having the same structure as the first functional safety sub-module;
  • the first functional safety sub-module and the second functional safety sub-module are both used to determine whether the same type of data received by the two functional safety modules are consistent. If so, perform corresponding operations based on the same type of data; if not, directly trigger the inverter's Functional safety operation.
  • the functional safety module 2 of the present application adopts a redundancy mechanism and is set as a dual-module architecture; the detection module 1 can also adopt a redundancy mechanism and is set as a dual-module architecture (as shown in FIG. 2, A and B are used to distinguish two Modules with the same structure), the functional safety device specifically includes detection module_A, detection module_B, functional safety module_A (also called the first functional safety submodule), and functional safety module_B (also called second Functional safety sub-module).
  • the detection module 1 may also not adopt a redundancy mechanism, that is, set to a single-module architecture, and the first functional safety sub-module and the second functional safety sub-module share the same detection module, thereby reducing the device cost.
  • first functional safety sub-module and the second functional safety sub-module While the first functional safety sub-module and the second functional safety sub-module are operating independently, they interact with the received data. It is understandable that the same type of data received by the two should be consistent. Otherwise, the system There are security issues, so after the first functional safety sub-module and the second functional safety sub-module of this application interact with the received data, they both judge whether the same type of data received by the two functional safety modules are consistent. Perform corresponding operations with the same type of data; if they are inconsistent, directly trigger the default functional safety operation of the inverter (such as STO functional safety operation).
  • the detection module 1 is a speed and direction finding module. If the direction of the motor detected by the speed and direction finding module _A is inconsistent with the direction of the motor detected by the speed and direction finding module _B, both the first functional safety sub-module and the second functional safety sub-module are Directly trigger the safe operation of the STO function of the inverter.
  • the present application adopts a dual-module architecture to independently operate two sets of functional safety devices with the same structure, and the two sets of functional safety devices are used for comparison and verification, which greatly improves the safety and reliability of the functional safety devices. Moreover, when one set of functional safety devices fails, another set of functional safety devices can still be used to complete the corresponding functional safety protection.
  • the first functional safety submodule includes:
  • Command input module used to receive functional safety commands
  • the functional safety trigger module connected with the frequency converter
  • the first controller connected to the instruction input module, the detection module, the functional safety trigger module, and the frequency converter respectively, is used to send the working parameters of the frequency converter to the second controller in the second functional safety sub-module; judge the two functional safety Whether the data of the same type received by the controller in the module is consistent, if yes, perform corresponding operations based on the same type of data; if not, use the functional safety trigger module to directly trigger the functional safety operation of the inverter;
  • the same type of data includes motor working parameters and functional safety instructions.
  • first functional safety sub-module and the second functional safety sub-module are the same. Subsequent embodiments of the present application take the first functional safety sub-module as an example to introduce the structural principles, and the structure of the second functional safety sub-module The principle introduction can refer to the first functional safety sub-module.
  • the first functional safety submodule of the present application includes an instruction input module, a functional safety trigger module, and a controller (referred to as the first controller), and its working principle is:
  • the instruction input module can receive functional safety instructions sent by users, such as STO functional safety instructions, SS1 (safe stop 1) functional safety instructions, SLS (safe limited speed) functional safety instructions, SOS (safe operation stop) functional safety instructions, SS2 ( Safe stop 2) Functional safety instructions, etc., and send the functional safety instructions to the first controller.
  • the first controller receives functional safety instructions on the one hand, and receives motor operating parameters and inverter operating parameters on the other.
  • the controller in the second functional safety sub-module (referred to as the second controller) also receives functional safety instructions on the one hand, and on the other hand receives the working parameters of the motor and the working parameters of the inverter. It should be noted that the second controller Obtain the working parameters of the inverter from the first controller.
  • the first controller and the second controller interact with the received data of the motor working parameters and functional safety instructions, and then determine whether the same type of data received by the two are consistent, and if they are consistent, perform corresponding operations based on the same type of data (If the functional safety instructions received by the two are the same, use the functional safety trigger module to trigger the inverter to execute the corresponding functional safety instruction actions); if they are inconsistent, use the functional safety trigger module to directly trigger the default functional safety operation of the inverter.
  • the first controller of the present application includes a CPU and a parameter storage module connected to the CPU.
  • the CPU is used to store the data in the parameter storage module after receiving the data; after judging that the CPU received in the two controllers When the data of the same type is consistent, the data is obtained from the parameter storage module for use.
  • the functional safety instructions include SBC instructions
  • the first functional safety sub-module also includes:
  • the command output module connected to the motor brake device and the first controller respectively; the first controller is also used to send a brake command to the motor brake device through the command output module after receiving the SBC command to make the motor brake The device performs motor brake operation.
  • the first functional safety sub-module also includes an instruction output module, and its working principle is:
  • both controllers send a brake command to the motor brake device through their corresponding command output modules, and the motor brake device executes the motor brake after receiving the brake command operating.
  • the first functional safety submodule further includes:
  • the software and hardware fault diagnosis modules respectively connected to the instruction input module, instruction output module, first controller and functional safety trigger module are used to detect whether the module device connected to itself has a fault; if so, when the first controller is normal , Use the first controller to trigger the functional safety operation of the inverter; when the first controller is abnormal, directly use the functional safety trigger module to trigger the functional safety operation of the inverter.
  • the first functional safety submodule of the present application also includes a software and hardware fault diagnosis module, which is used to detect the command input module, the command output module, the first controller, and the functional safety trigger module in the first functional safety submodule. working condition. If the software and hardware fault diagnosis module detects a fault in the connected module device, it triggers the functional safety operation of the inverter. Specifically, when the first controller is normal, the first controller uses the functional safety trigger module to trigger the inverter’s operation. Default functional safety operation; when the first controller is abnormal, the software and hardware fault diagnosis module directly uses the functional safety trigger module to trigger the default functional safety operation of the inverter.
  • FIG. 3 is a schematic diagram of a diagnosis of an instruction input module according to an embodiment of the present invention.
  • the instruction input module includes:
  • the first switch K11 connected to the DC power supply at the first end is used to be in the closed state when there is no functional safety command input, and to be in the open state when there is a functional safety command input; among them, the command input module in the second functional safety sub-module
  • the included second switch K12 and the first switch K11 constitute a linkage switch
  • Command input channel modules respectively connected to the second end of the first switch K11 and the first controller
  • the first controller is also used to periodically send diagnostic pulses to the command input channel module using the software and hardware fault diagnosis module to detect whether the command input module is faulty based on the pulse signal output by the command input channel module, and if so, use functional safety to trigger the module Trigger the functional safety operation of the inverter.
  • the instruction input module of the present application includes a first switch K11 and an instruction input channel module, and its working principle is as follows:
  • the command input channel adopts A/B dual-channel redundancy. deal with.
  • the failure detection principle of the command input module in the first functional safety sub-module is (the failure detection principle of the command input module in the second functional safety sub-module is the same, and will not be repeated here in this application): the first switch K11 and the second switch K12 It forms a linkage switch. When there is no functional safety command input, the linkage switch remains closed; when there is a functional safety command input, the linkage switch opens at the same time.
  • the first controller uses the software and hardware fault diagnosis module to periodically send diagnostic pulses to the command input channel module.
  • the first controller can receive the diagnostic pulse output by the command input channel module;
  • the linkage switch is turned on and the instruction input channel module has no fault, the first controller may receive the functional safety instruction output by the instruction input channel module. Therefore, the first controller can detect whether the linkage switch and the command input channel module have faults through the diagnostic pulse.
  • the first controller and the second controller each detect the diagnostic pulse output by the command input channel module, and then compare the respective detected diagnostic pulses , When the two are consistent, it means that the command input module is not faulty, and the current working state is kept without action.
  • the linkage switch When there is a functional safety command input, the linkage switch is turned on at the same time, and the first controller and the second controller respectively detect the functional safety command output by the command input channel module, and then compare the detected functional safety commands. When the two are the same, use the functional safety trigger module to trigger the inverter to execute the corresponding functional safety command action; when the two are inconsistent, directly use the functional safety trigger module to trigger the default functional safety operation of the inverter.
  • the linkage switch When there is no functional safety command input, the linkage switch remains closed. If any command input channel module has a fault, such as a device short circuit or open circuit fault, the first controller and the second controller respectively detect the output of the command input channel module. In the case of channel signal, there may be two controllers that can detect the channel signal; there may also be one controller that can detect the channel signal, and the other controller cannot detect the channel signal. Therefore, the first controller and the second controller can detect the channel signal. When comparing the detected channel signals, if the two are inconsistent or there is no valid channel signal detected, the functional safety trigger module is directly used to trigger the default functional safety operation of the inverter.
  • the functional safety trigger module is directly used to trigger the default functional safety operation of the inverter.
  • FIG. 4 is a schematic diagram of a diagnosis of an instruction output module according to an embodiment of the present invention.
  • the motor brake device includes a safety brake power supply, a first relay K1, a second relay K2, and a brake brake device;
  • the first relay K1 includes a first coil and a first contact switch;
  • the second relay K2 includes a second coil and a second contact switch; among them:
  • the safety brake power supply is connected to the first end of the first contact switch, the second end of the first contact switch is connected to the first end of the second contact switch, and the second end of the second contact switch is connected to the brake
  • the gate device is connected, the first end of the first coil and the first end of the second coil are both connected to the DC power supply, and the second end of the first coil is respectively connected with the command output module and the software and hardware fault diagnosis module in the first functional safety sub-module Connected, the second end of the second coil is respectively connected with the command output module and the software and hardware fault diagnosis module in the second functional safety sub-module;
  • the first controller is specifically configured to control the first coil to be disconnected and the first contact switch to be opened through the command output module after receiving the SBC command, so that the brake brake device loses power to perform the motor brake operation;
  • the first controller is also used to detect whether the corresponding instruction output module has a fault according to the on-off condition of the first coil fed back by the software and hardware fault diagnosis module, and if so, use the functional safety trigger module to trigger the functional safety operation of the inverter.
  • the motor brake device of the present application includes a safety brake power supply, a first relay K1, a second relay K2, and a brake brake device, and its working principle is:
  • the first controller and the second controller respectively output a low level to the coils of the first relay K1 and the second relay K2 through their respective command output modules to turn on the first relay K1 and the second relay
  • the coil of K2 the switch contacts of the first relay K1 and the second relay K2 are closed, the brake device is energized and released, and the motor can operate normally.
  • the first controller and the second controller respectively output high levels to the coils of the first relay K1 and the second relay K2 through their respective instruction output modules to disconnect the first relays K1 and K2.
  • the coil of the second relay K2, the switch contacts of the first relay K1 and the second relay K2 are opened, the brake and brake device loses power and brakes, and the motor is braked by the brake.
  • the on-off condition of the first coil fed back by the hardware fault diagnosis module is to detect whether the corresponding instruction output module has a fault.
  • the first controller compares the feedback signal of the software and hardware fault diagnosis module with the feedback signal of the second controller after detecting that the first coil is in the conducting state. If they are inconsistent or the two are inconsistent with the expected value, the functional safety trigger module is directly used to trigger the default functional safety operation of the inverter.
  • the SBC functional safety instruction needs to be executed, the first controller will compare the feedback signal of the software and hardware fault diagnosis module with the corresponding feedback signal of the second controller after detecting that the first coil is in the disconnected state. If the two are inconsistent Or the two are inconsistent with the expected value, directly use the functional safety trigger module to trigger the default functional safety operation of the inverter.
  • FIG. 5 is a schematic diagram of a diagnosis of a controller according to an embodiment of the present invention.
  • the hardware and software fault diagnosis module is specifically configured to detect whether the first controller has a fault according to the timing of the pulse signal output by the GPIO pin of the first controller, If yes, directly use the functional safety trigger module to trigger the functional safety operation of the inverter.
  • the fault detection principle of the first controller is (the fault detection principle of the second controller is the same, and this application will not repeat it here): the software and hardware fault diagnosis module is based on the GPIO (General-purpose input/ output, the timing of the pulse signal output by the general-purpose input/output pin, to detect whether the first controller has a fault. It is understandable that when the program of the first controller is not running normally, there are the following situations: the GPIO pin of the first controller has no pulse output; the pulse signal output by the GPIO pin of the first controller is too early or too late ,As shown in Figure 6.
  • the software and hardware fault diagnosis module detects that the GPIO pin of the first controller has no pulse output or the pulse output is too early or too late, it directly uses the functional safety trigger module to trigger the functional safety operation of the inverter, and can output low level To the reset terminal of the first controller to forcibly reset the first controller.
  • the software and hardware fault diagnosis module can start timing when the pulse signal is received. If a new pulse signal is received within a period of time before the predetermined timing time, it means that the pulse output is too early; A new pulse signal is received within a period of time, indicating that the pulse output is too late; if a new pulse signal has not been received for a long time, it is considered that there is no pulse output.
  • the first controller is further configured to use the functional safety trigger module to send a diagnostic pulse signal to the inverter to determine whether the safety trigger channel of the functional safety trigger module meets the expected operation based on the signal condition fed back by the inverter Status, if not, use the functional safety trigger module to trigger the functional safety operation of the inverter.
  • the first controller also uses the functional safety trigger module to send a diagnostic pulse signal to the frequency converter, and the diagnostic pulse signal covers the entire safety trigger path.
  • the inverter After the inverter successfully receives the diagnostic pulse signal, it will generate a feedback signal and return to the first controller via the functional safety trigger module.
  • the first controller judges whether the safety trigger channel of the functional safety trigger module meets the expected working state based on the feedback signal. If it does not meet the expected working state, the functional safety trigger module is used to trigger the default functional safety operation of the inverter (the second controller corresponds to The working status diagnosis of the safety trigger path of the functional safety trigger module is the same, and this application will not repeat it here).
  • the software and hardware fault diagnosis module can also detect the power rail condition of the functional safety trigger module.
  • the functional safety trigger module can be used to trigger the default functional safety operation of the inverter. For details, refer to Figure 7 to understand the signal transmission of the functional safety trigger module.
  • the functional safety device further includes:
  • the parameter setting module connected to the first controller is used to set the one-to-one correspondence between different input channels of the instruction input module and different functional safety instructions, and/or to set different parameters received by the first controller and different functional safety operations One-to-one correspondence, and sending the correspondence to the first controller;
  • the status display module connected with the second controller; the second controller is used for outputting the corresponding relationship to the status display module for display after receiving the corresponding relationship sent by the first controller.
  • the functional safety device of the present application also includes a parameter setting module and a status display module, and its working principle is as follows:
  • the parameter setting module can be used to set the one-to-one correspondence between different input channels of the command input module and different functional safety instructions (referred to as the channel command correspondence) and/or the one-to-one correspondence between different parameters received by the first controller and different functional safety operations.
  • a correspondence relationship (parameter operation correspondence relationship for short), and then the channel instruction correspondence relationship and/or the parameter operation correspondence relationship are sent to the first controller.
  • the first controller sends the channel instruction correspondence and/or parameter operation correspondence to the second controller, so that the second controller outputs the channel instruction correspondence and/or parameter operation correspondence to the status display module for display, For users to view.
  • the corresponding relationship displayed by the status display module is consistent with the corresponding relationship set by the parameter setting module, it indicates that the corresponding relationship setting between the first controller and the second controller is normal; otherwise, it indicates the corresponding relationship setting of the first controller and the second controller. abnormal. Since the parameter setting module and the status display module of the present application use the first controller and the second controller to interact separately, the safety level of the device can be improved.

Abstract

一种变频器的功能安全装置,包括:与电机连接的检测模块(1),用于检测电机的工作参数;设于变频器的外部,且分别与检测模块(1)和变频器连接的功能安全模块(2),用于根据电机工作参数和变频器发送的变频器工作参数,判定变频器是否满足于预设功能安全触发条件,若是,则触发变频器的功能安全操作。功能安全装置与变频器产品各自独立设置,不存在部分软硬件模块共用的关系,从而降低了变频器产品的设计难度和设计升级难度,灵活性较高。

Description

一种变频器的功能安全装置 技术领域
本发明涉及机械安全领域,特别是涉及一种变频器的功能安全装置。
背景技术
基于工业自动化水平的持续提升,涉及变频器和电机的工业应用越来越广泛。在提升系统效率、降低系统能耗的基础上,系统机械的安全性也日益重要。现有技术中,为保证变频器的功能安全,通常在变频器产品的内部集成有与变频器功能安全相关的软硬件模块(称为功能安全模块)。但是,这些功能安全模块和变频器产品内部原有的与变频功能相关的软硬件模块(称为变频功能模块),通常存在部分软硬件模块共用的关系,二者相互独立性不强,导致变频器产品的设计难度较高;而且,在后续产品设计升级时,功能安全模块和变频功能模块相互干扰,导致设计升级难度较大,灵活性较低。
因此,如何提供一种解决上述技术问题的方案是本领域的技术人员目前需要解决的问题。
发明内容
本发明的目的是提供一种变频器的功能安全装置,功能安全装置与变频器产品各自独立设置,不存在部分软硬件模块共用的关系,从而降低了变频器产品的设计难度;而且,在后续产品设计升级时,功能安全装置与变频器产品互不干扰,从而降低了设计升级难度,灵活性较高。
为解决上述技术问题,本发明提供了一种变频器的功能安全装置,包括:
与电机连接的检测模块,用于检测所述电机的工作参数;
设于所述变频器的外部,且分别与所述检测模块和所述变频器连接的功能安全模块,用于根据电机工作参数和所述变频器发送的变频器工作参数,判定所述变频器是否满足于预设功能安全触发条件,若是,则触发所述变频器的功能安全操作。
优选地,所述功能安全模块包括:
分别与所述检测模块和所述变频器连接的第一功能安全子模块,用于将所述变频器工作参数发送至第二功能安全子模块;
与所述检测模块连接,且与所述第一功能安全子模块的结构相同的第二功能安全子模块;
所述第一功能安全子模块和所述第二功能安全子模块均用于判断两个功能安全模块接收的同类型数据是否一致,若是,则根据所述同类型数据执行相应操作;若否,则直接触发所述变频器的功能安全操作。
优选地,所述第一功能安全子模块包括:
指令输入模块,用于接收功能安全指令;
与所述变频器连接的功能安全触发模块;
分别与所述指令输入模块、所述检测模块、所述功能安全触发模块及所述变频器连接的第一控制器,用于将所述变频器工作参数发送至所述第二功能安全子模块内的第二控制器;判断两个功能安全模块中控制器接收的同类型数据是否一致,若是,则根据所述同类型数据执行相应操作;若否,则利用所述功能安全触发模块直接触发所述变频器的功能安全操作;
其中,所述同类型数据包括电机工作参数及功能安全指令。
优选地,所述功能安全指令包括SBC指令;
相应的,所述第一功能安全子模块还包括:
分别与电机抱闸装置和所述第一控制器连接的指令输出模块;所述第一控制器还用于在接收到SBC指令后,通过所述指令输出模块向所述电机抱闸装置发送抱闸指令,以使所述电机抱闸装置执行电机抱闸操作。
优选地,所述第一功能安全子模块还包括:
分别与所述指令输入模块、所述指令输出模块、所述第一控制器及所述功能安全触发模块连接的软硬件故障诊断模块,用于检测自身所连接的模块器件是否存在故障;若是,则在所述第一控制器正常时,利用所述第一控制器触发所述变频器的功能安全操作;在所述第一控制器异常时,直接利用所述功能安全触发模块触发所述变频器的功能安全操作。
优选地,所述指令输入模块包括:
第一端接入直流电源的第一开关,用于在无功能安全指令输入时处于闭合状态,在有功能安全指令输入时处于断开状态;其中,所述第二功能安全子模块中指令输入模块所包含的第二开关与所述第一开关组成一联动开关;
分别与所述第一开关的第二端和所述第一控制器连接的指令输入通道模块;
所述第一控制器还用于利用所述软硬件故障诊断模块周期性向所述指令输入通道模块发送诊断脉冲,以基于所述指令输入通道模块输出的脉冲信号情况检测所述指令输入模块是否存在故障,若是,则利用所述功能安全触发模块触发所述变频器的功能安全操作。
优选地,所述电机抱闸装置包括安全抱闸电源、第一继电器、第二继电器及制动抱闸装置;所述第一继电器包括第一线圈和第一触点开关;所述第二继电器包括第二线圈和第二触点开关;其中:
所述安全抱闸电源与所述第一触点开关的第一端连接,所述第一触点开关的第二端与所述第二触点开关的第一端连接,所述第二触点开关的第二端与所述制动抱闸装置连接,所述第一线圈的第一端和所述第二线圈的第一端均接入直流电源,所述第一线圈的第二端分别与所述第一功能安全子模块内指令输出模块及软硬件故障诊断模块连接,所述第二线圈的第二端分别与所述第二功能安全子模块内指令输出模块及软硬件故障诊断模块连接;
则所述第一控制器具体用于在接收到SBC指令后,通过所述指令输出模块控制所述第一线圈断开、第一触点开关打开,以使所述制动抱闸装置失电执行电机抱闸操作;
且所述第一控制器还用于根据所述软硬件故障诊断模块反馈的第一线圈的通断情况,检测对应的指令输出模块是否存在故障,若是,则利用所述功能安全触发模块触发所述变频器的功能安全操作。
优选地,在检测所述第一控制器时,所述软硬件故障诊断模块具体用于根据所述第一控制器的GPIO管脚输出的脉冲信号的时序,检测所述第 一控制器是否存在故障,若是,则直接利用所述功能安全触发模块触发所述变频器的功能安全操作。
优选地,所述第一控制器还用于利用所述功能安全触发模块向所述变频器发送诊断脉冲信号,以基于所述变频器反馈的信号情况判断所述功能安全触发模块的安全触发通道是否符合预期工作状态,若否,则利用所述功能安全触发模块触发所述变频器的功能安全操作。
优选地,所述功能安全装置还包括:
与所述第一控制器连接的参数设置模块,用于设置所述指令输入模块的不同输入通道与不同功能安全指令的一一对应关系,和/或设置所述第一控制器接收的不同参数与不同功能安全操作的一一对应关系,并将所述对应关系发送至所述第一控制器;
与所述第二控制器连接的状态显示模块;所述第二控制器用于在接收到所述第一控制器发送的所述对应关系后,将所述对应关系输出至所述状态显示模块显示。
本发明提供了一种变频器的功能安全装置,独立于变频器设置,其可在根据电机工作参数和变频器工作参数判定出变频器满足于预设功能安全触发条件时,触发变频器的功能安全操作,以保证变频器的功能安全。可见,本申请的功能安全装置与变频器产品各自独立设置,不存在部分软硬件模块共用的关系,从而降低了变频器产品的设计难度;而且,在后续产品设计升级时,功能安全装置与变频器产品互不干扰,从而降低了设计升级难度,灵活性较高。
附图说明
为了更清楚地说明本发明实施例中的技术方案,下面将对现有技术和实施例中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本发明实施例提供的一种变频器的功能安全装置的结构示意图;
图2为本发明实施例提供的一种变频器的功能安全装置的具体结构示意图;
图3为本发明实施例提供的一种指令输入模块的诊断示意图;
图4为本发明实施例提供的一种指令输出模块的诊断示意图;
图5为本发明实施例提供的一种控制器的诊断示意图;
图6为本发明实施例提供的一种控制器的时序监控示意图;
图7为本发明实施例提供的一种功能安全触发模块的信号传输示意图。
具体实施方式
本发明的核心是提供一种变频器的功能安全装置,功能安全装置与变频器产品各自独立设置,不存在部分软硬件模块共用的关系,从而降低了变频器产品的设计难度;而且,在后续产品设计升级时,功能安全装置与变频器产品互不干扰,从而降低了设计升级难度,灵活性较高。
为使本发明实施例的目的、技术方案和优点更加清楚,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
请参照图1,图1为本发明实施例提供的一种变频器的功能安全装置的结构示意图。
该变频器的功能安全装置包括:
与电机连接的检测模块1,用于检测电机的工作参数;
设于变频器的外部,且分别与检测模块1和变频器连接的功能安全模块2,用于根据电机工作参数和变频器发送的变频器工作参数,判定变频器是否满足于预设功能安全触发条件,若是,则触发变频器的功能安全操作。
具体地,本申请的变频器的功能安全装置独立于变频器产品设置,包 括检测模块1和功能安全模块2,其工作原理为:
检测模块1与电机连接,可检测电机的工作参数,并将电机的工作参数发送至功能安全模块2。功能安全模块2一方面接收电机工作参数;另一方面与变频器交互,以从变频器获取变频器工作参数,然后根据电机工作参数和变频器工作参数判定变频器是否满足于预设功能安全触发条件,若变频器满足于预设功能安全触发条件,则触发变频器的功能安全操作;若变频器不满足于预设功能安全触发条件,则不触发变频器的功能安全操作。
需要说明的是,这里的功能安全触发条件是提前设置好的,且在满足功能安全触发条件时所触发的变频器的功能安全操作也是提前设置好的。
比如,本申请的检测模块1为用于检测电机转速和电机转向的测速测向模块,则功能安全触发条件包括:电机转速超过预设速度阈值,对应触发的是变频器的SLS(安全限速)功能安全操作;电机转向错误,对应触发的是变频器的STO(安全转矩截止)功能安全操作。
本发明提供了一种变频器的功能安全装置,独立于变频器设置,其可在根据电机工作参数和变频器工作参数判定出变频器满足于预设功能安全触发条件时,触发变频器的功能安全操作,以保证变频器的功能安全。可见,本申请的功能安全装置与变频器产品各自独立设置,不存在部分软硬件模块共用的关系,从而降低了变频器产品的设计难度;而且,在后续产品设计升级时,功能安全装置与变频器产品互不干扰,从而降低了设计升级难度,灵活性较高。
请参照图2,图2为本发明实施例提供的一种变频器的功能安全装置的具体结构示意图。该功能安全装置在上述实施例的基础上:
作为一种可选的实施例,功能安全模块2包括:
分别与检测模块和变频器连接的第一功能安全子模块,用于将变频器工作参数发送至第二功能安全子模块;
与检测模块连接,且与第一功能安全子模块的结构相同的第二功能安全子模块;
第一功能安全子模块和第二功能安全子模块均用于判断两个功能安全模块接收的同类型数据是否一致,若是,则根据同类型数据执行相应操作;若否,则直接触发变频器的功能安全操作。
具体地,本申请的功能安全模块2采用冗余机制,设置为双模块架构;检测模块1也可采用冗余机制,设置为双模块架构(如图2所示,用A、B区分两个结构相同的模块),则功能安全装置具体包括检测模块_A、检测模块_B、功能安全模块_A(也称为第一功能安全子模块)及功能安全模块_B(也称为第二功能安全子模块)。当然,检测模块1也可不采用冗余机制,即设置为单模块架构,则第一功能安全子模块和第二功能安全子模块共用同一检测模块,从而降低装置成本。
第一功能安全子模块和第二功能安全子模块在各自独立运行的同时,二者交互所接收的数据,可以理解的是,二者所接收的同类型数据应保持一致,否则的话,说明系统存在安全问题,所以本申请的第一功能安全子模块和第二功能安全子模块在交互所接收的数据后,均判断两个功能安全模块所接收的同类型数据是否一致,若一致,则根据同类型数据执行相应操作;若不一致,则直接触发变频器的默认功能安全操作(如STO功能安全操作)。
比如,检测模块1为测速测向模块,若测速测向模块_A检测的电机转向与测速测向模块_B检测的电机转向不一致,则第一功能安全子模块和第二功能安全子模块均直接触发变频器的STO功能安全操作。
可见,本申请采用双模块架构独立运行两套结构相同的功能安全装置,且两套功能安全装置进行对比验证使用,较大地提高功能安全装置的安全性及可靠性。而且,当其中一套功能安全装置出现故障时,仍可通过另一套功能安全装置来完成相应功能安全保护。
作为一种可选的实施例,第一功能安全子模块包括:
指令输入模块,用于接收功能安全指令;
与变频器连接的功能安全触发模块;
分别与指令输入模块、检测模块、功能安全触发模块及变频器连接的第一控制器,用于将变频器工作参数发送至第二功能安全子模块内的第二 控制器;判断两个功能安全模块中控制器接收的同类型数据是否一致,若是,则根据同类型数据执行相应操作;若否,则利用功能安全触发模块直接触发变频器的功能安全操作;
其中,同类型数据包括电机工作参数及功能安全指令。
需要说明的是,第一功能安全子模块和第二功能安全子模块的结构相同,本申请的后续实施例以第一功能安全子模块为例进行结构原理介绍,第二功能安全子模块的结构原理介绍参照第一功能安全子模块即可。
具体地,本申请的第一功能安全子模块包括指令输入模块、功能安全触发模块、控制器(称为第一控制器),其工作原理为:
指令输入模块可接收用户发送的功能安全指令,如STO功能安全指令、SS1(安全停止1)功能安全指令、SLS(安全限速)功能安全指令、SOS(安全操作停止)功能安全指令、SS2(安全停止2)功能安全指令等,并将功能安全指令发送至第一控制器。第一控制器一方面接收功能安全指令,另一方面接收电机工作参数及变频器工作参数。同时,第二功能安全子模块内的控制器(称为第二控制器)也一方面接收功能安全指令,另一方面接收电机工作参数及变频器工作参数,需要说明的是,第二控制器从第一控制器中获取变频器工作参数。
基于此,第一控制器和第二控制器交互所接收的电机工作参数、功能安全指令这些数据,然后判断二者所接收的同类型数据是否一致,若一致,则根据同类型数据执行相应操作(如二者所接收的功能安全指令一致,则利用功能安全触发模块触发变频器执行相应的功能安全指令动作);若不一致,则利用功能安全触发模块直接触发变频器的默认功能安全操作。
更具体地,本申请的第一控制器包括CPU和与CPU连接的参数存储模块,CPU用于在接收到数据后,将数据存储至参数存储模块;在判断出两控制器内CPU所接收的同类型数据一致时,从参数存储模块中获取数据使用。
作为一种可选的实施例,功能安全指令包括SBC指令;
相应的,第一功能安全子模块还包括:
分别与电机抱闸装置和第一控制器连接的指令输出模块;第一控制器 还用于在接收到SBC指令后,通过指令输出模块向电机抱闸装置发送抱闸指令,以使电机抱闸装置执行电机抱闸操作。
具体地,当本申请的功能安全指令包括SBC(安全抱闸)指令时,第一功能安全子模块还包括指令输出模块,其工作原理为:
在判断出两控制器所接收的SBC指令一致时,两控制器均通过各自对应的指令输出模块向电机抱闸装置发送抱闸指令,电机抱闸装置在接收到抱闸指令后执行电机抱闸操作。
作为一种可选的实施例,第一功能安全子模块还包括:
分别与指令输入模块、指令输出模块、第一控制器及功能安全触发模块连接的软硬件故障诊断模块,用于检测自身所连接的模块器件是否存在故障;若是,则在第一控制器正常时,利用第一控制器触发变频器的功能安全操作;在第一控制器异常时,直接利用功能安全触发模块触发变频器的功能安全操作。
进一步地,本申请的第一功能安全子模块还包括软硬件故障诊断模块,其用来检测第一功能安全子模块内的指令输入模块、指令输出模块、第一控制器及功能安全触发模块的工作情况。若软硬件故障诊断模块检测到所连接的模块器件存在故障,则触发变频器的功能安全操作,具体地,在第一控制器正常时,由第一控制器利用功能安全触发模块触发变频器的默认功能安全操作;在第一控制器异常时,由软硬件故障诊断模块直接利用功能安全触发模块触发变频器的默认功能安全操作。
请参照图3,图3为本发明实施例提供的一种指令输入模块的诊断示意图。
作为一种可选的实施例,指令输入模块包括:
第一端接入直流电源的第一开关K11,用于在无功能安全指令输入时处于闭合状态,在有功能安全指令输入时处于断开状态;其中,第二功能安全子模块中指令输入模块所包含的第二开关K12与第一开关K11组成一联动开关;
分别与第一开关K11的第二端和第一控制器连接的指令输入通道模块;
第一控制器还用于利用软硬件故障诊断模块周期性向指令输入通道模块发送诊断脉冲,以基于指令输入通道模块输出的脉冲信号情况检测指令输入模块是否存在故障,若是,则利用功能安全触发模块触发变频器的功能安全操作。
具体地,本申请的指令输入模块包括第一开关K11和指令输入通道模块,其工作原理为:
如图3所示,在第一功能安全子模块中指令输入通道模块_A和第二功能安全子模块中指令输入通道模块_B的设计下,实现指令输入通道采用A/B双通道冗余处理。第一功能安全子模块中指令输入模块的故障检测原理为(第二功能安全子模块中指令输入模块的故障检测原理相同,本申请在此不再赘述):第一开关K11和第二开关K12组成一联动开关,当没有功能安全指令输入时,联动开关保持闭合状态;当有功能安全指令输入时,联动开关同时打开。第一控制器利用软硬件故障诊断模块周期性向指令输入通道模块发送诊断脉冲,在联动开关闭合且指令输入通道模块无故障时,第一控制器可接收到指令输入通道模块输出的诊断脉冲;在联动开关打开且指令输入通道模块无故障时,第一控制器可接收到指令输入通道模块输出的功能安全指令。因此,第一控制器可通过诊断脉冲来检测联动开关及指令输入通道模块是否有故障发生。
更具体地,当没有功能安全指令输入时,联动开关保持闭合状态,则第一控制器和第二控制器各自检测指令输入通道模块输出的诊断脉冲,然后对各自检测到的诊断脉冲进行比对,当二者一致时,说明指令输入模块无故障,则保持当前工作状态不动作。
当有功能安全指令输入时,联动开关同时打开,则第一控制器和第二控制器各自检测指令输入通道模块输出的功能安全指令,然后对各自检测到的功能安全指令进行比对,当二者一致时,利用功能安全触发模块触发变频器执行相应的功能安全指令动作;当二者不一致时,直接利用功能安全触发模块触发变频器的默认功能安全操作。
当没有功能安全指令输入时,联动开关保持闭合状态,若任一指令输入通道模块存在故障,如器件短路或者断路故障,则在第一控制器和第二 控制器各自检测指令输入通道模块输出的通道信号时,可能存在两控制器都可检测到通道信号;也可能存在一个控制器可检测到通道信号、另一个控制器检测不到通道信号,所以在第一控制器和第二控制器对各自检测到的通道信号进行比对时,若二者不一致或存在检测不到有效的通道信号的情况,则直接利用功能安全触发模块触发变频器的默认功能安全操作。
请参照图4,图4为本发明实施例提供的一种指令输出模块的诊断示意图。
作为一种可选的实施例,电机抱闸装置包括安全抱闸电源、第一继电器K1、第二继电器K2及制动抱闸装置;第一继电器K1包括第一线圈和第一触点开关;第二继电器K2包括第二线圈和第二触点开关;其中:
安全抱闸电源与第一触点开关的第一端连接,第一触点开关的第二端与第二触点开关的第一端连接,第二触点开关的第二端与制动抱闸装置连接,第一线圈的第一端和第二线圈的第一端均接入直流电源,第一线圈的第二端分别与第一功能安全子模块内指令输出模块及软硬件故障诊断模块连接,第二线圈的第二端分别与第二功能安全子模块内指令输出模块及软硬件故障诊断模块连接;
则第一控制器具体用于在接收到SBC指令后,通过指令输出模块控制第一线圈断开、第一触点开关打开,以使制动抱闸装置失电执行电机抱闸操作;
且第一控制器还用于根据软硬件故障诊断模块反馈的第一线圈的通断情况,检测对应的指令输出模块是否存在故障,若是,则利用功能安全触发模块触发变频器的功能安全操作。
具体地,本申请的电机抱闸装置包括安全抱闸电源、第一继电器K1、第二继电器K2及制动抱闸装置,其工作原理为:
当电机正常运转时,第一控制器和第二控制器分别通过各自的指令输出模块输出低电平至第一继电器K1和第二继电器K2的线圈,以导通第一继电器K1和第二继电器K2的线圈,第一继电器K1和第二继电器K2的开关触点吸合,制动抱闸装置得电松开,电机得以正常运转。当需要执行SBC功能安全指令时,第一控制器和第二控制器分别通过各自的指令输出 模块输出高电平至第一继电器K1和第二继电器K2的线圈,以断开第一继电器K1和第二继电器K2的线圈,第一继电器K1和第二继电器K2的开关触点打开,制动抱闸装置失电抱闸,电机被抱闸制动。
基于此,第一功能安全子模块中指令输出模块的故障检测原理为(第二功能安全子模块中指令输出模块的故障检测原理相同,本申请在此不再赘述):第一控制器根据软硬件故障诊断模块反馈的第一线圈的通断情况,检测对应的指令输出模块是否存在故障。
更具体地,当电机正常运转时,第一控制器在检测到第一线圈处于导通状态后,将软硬件故障诊断模块的反馈信号与第二控制器对应的反馈信号进行对比,若二者不一致或者二者与预期值不一致,则直接利用功能安全触发模块触发变频器的默认功能安全操作。当需要执行SBC功能安全指令时,第一控制器在检测到第一线圈处于断开状态后,将软硬件故障诊断模块的反馈信号与第二控制器对应的反馈信号进行对比,若二者不一致或者二者与预期值不一致,则直接利用功能安全触发模块触发变频器的默认功能安全操作。
请参照图5,图5为本发明实施例提供的一种控制器的诊断示意图。
作为一种可选的实施例,在检测第一控制器时,软硬件故障诊断模块具体用于根据第一控制器的GPIO管脚输出的脉冲信号的时序,检测第一控制器是否存在故障,若是,则直接利用功能安全触发模块触发变频器的功能安全操作。
具体地,第一控制器的故障检测原理为(第二控制器的故障检测原理相同,本申请在此不再赘述):软硬件故障诊断模块根据第一控制器的GPIO(General-purpose input/output,通用输入/输出)管脚输出的脉冲信号的时序,检测第一控制器是否存在故障。可以理解的是,当第一控制器的程序运行不正常时,存在以下情况:第一控制器的GPIO管脚无脉冲输出;第一控制器的GPIO管脚输出的脉冲信号过早或过迟,如图6所示。所以软硬件故障诊断模块当检测到第一控制器的GPIO管脚无脉冲输出或者脉冲输出过早或过迟时,直接利用功能安全触发模块触发变频器的功能安全操作,并且可输出低电平至第一控制器的复位端,以强制复位第一控制器。
更具体地,软硬件故障诊断模块可从接收到脉冲信号时开始计时,若到达预定计时时间之前的一段时间内便接收到新的脉冲信号,说明脉冲输出过早;若到达预定计时时间之后的一段时间内才接收到新的脉冲信号,说明脉冲输出过迟;若在较长时间内一直未接收到新的脉冲信号,认为无脉冲输出。
作为一种可选的实施例,第一控制器还用于利用功能安全触发模块向变频器发送诊断脉冲信号,以基于变频器反馈的信号情况判断功能安全触发模块的安全触发通道是否符合预期工作状态,若否,则利用功能安全触发模块触发变频器的功能安全操作。
进一步地,为了诊断第一控制器对应的功能安全触发模块的安全触发通路的工作状态,第一控制器还利用功能安全触发模块向变频器发送诊断脉冲信号,诊断脉冲信号覆盖整个安全触发通路。变频器在成功接收到诊断脉冲信号后,会生成反馈信号经功能安全触发模块返回至第一控制器。第一控制器基于反馈信号判断功能安全触发模块的安全触发通道是否符合预期工作状态,若不符合预期工作状态,则利用功能安全触发模块触发变频器的默认功能安全操作(第二控制器对应的功能安全触发模块的安全触发通路的工作状态诊断同理,本申请在此不再赘述)。
此外,软硬件故障诊断模块还可检测功能安全触发模块的电源轨情况,当其电源轨出现过压、欠压故障时,可利用功能安全触发模块触发变频器的默认功能安全操作。具体可参照图7了解功能安全触发模块的信号传输情况。
作为一种可选的实施例,功能安全装置还包括:
与第一控制器连接的参数设置模块,用于设置指令输入模块的不同输入通道与不同功能安全指令的一一对应关系,和/或设置第一控制器接收的不同参数与不同功能安全操作的一一对应关系,并将对应关系发送至第一控制器;
与第二控制器连接的状态显示模块;第二控制器用于在接收到第一控制器发送的对应关系后,将对应关系输出至状态显示模块显示。
进一步地,本申请的功能安全装置还包括参数设置模块和状态显示模 块,其工作原理为:
本申请可通过参数设置模块设置指令输入模块的不同输入通道与不同功能安全指令的一一对应关系(简称通道指令对应关系)和/或第一控制器接收的不同参数与不同功能安全操作的一一对应关系(简称参数操作对应关系),然后将通道指令对应关系和/或参数操作对应关系发送至第一控制器。同时,第一控制器将通道指令对应关系和/或参数操作对应关系发送至第二控制器,以由第二控制器将通道指令对应关系和/或参数操作对应关系输出至状态显示模块显示,供用户查看。若状态显示模块显示的对应关系与参数设置模块设置的对应关系一致,说明第一控制器和第二控制器的对应关系设置正常;否则,说明第一控制器和第二控制器的对应关系设置异常。由于本申请的参数设置模块和状态显示模块分别用第一控制器和第二控制器单独交互,所以可提高装置安全等级。
还需要说明的是,在本说明书中,诸如第一和第二等之类的关系术语仅仅用来将一个实体或者操作与另一个实体或操作区分开来,而不一定要求或者暗示这些实体或操作之间存在任何这种实际的关系或者顺序。而且,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、物品或者设备中还存在另外的相同要素。
对所公开的实施例的上述说明,使本领域专业技术人员能够实现或使用本发明。对这些实施例的多种修改对本领域的专业技术人员来说将是显而易见的,本文中所定义的一般原理可以在不脱离本发明的精神或范围的情况下,在其他实施例中实现。因此,本发明将不会被限制于本文所示的这些实施例,而是要符合与本文所公开的原理和新颖特点相一致的最宽的范围。

Claims (10)

  1. 一种变频器的功能安全装置,其特征在于,包括:
    与电机连接的检测模块,用于检测所述电机的工作参数;
    设于所述变频器的外部,且分别与所述检测模块和所述变频器连接的功能安全模块,用于根据电机工作参数和所述变频器发送的变频器工作参数,判定所述变频器是否满足于预设功能安全触发条件,若是,则触发所述变频器的功能安全操作。
  2. 如权利要求1所述的变频器的功能安全装置,其特征在于,所述功能安全模块包括:
    分别与所述检测模块和所述变频器连接的第一功能安全子模块,用于将所述变频器工作参数发送至第二功能安全子模块;
    与所述检测模块连接,且与所述第一功能安全子模块的结构相同的第二功能安全子模块;
    所述第一功能安全子模块和所述第二功能安全子模块均用于判断两个功能安全模块接收的同类型数据是否一致,若是,则根据所述同类型数据执行相应操作;若否,则直接触发所述变频器的功能安全操作。
  3. 如权利要求2所述的变频器的功能安全装置,其特征在于,所述第一功能安全子模块包括:
    指令输入模块,用于接收功能安全指令;
    与所述变频器连接的功能安全触发模块;
    分别与所述指令输入模块、所述检测模块、所述功能安全触发模块及所述变频器连接的第一控制器,用于将所述变频器工作参数发送至所述第二功能安全子模块内的第二控制器;判断两个功能安全模块中控制器接收的同类型数据是否一致,若是,则根据所述同类型数据执行相应操作;若否,则利用所述功能安全触发模块直接触发所述变频器的功能安全操作;
    其中,所述同类型数据包括电机工作参数及功能安全指令。
  4. 如权利要求3所述的变频器的功能安全装置,其特征在于,所述功能安全指令包括SBC指令;
    相应的,所述第一功能安全子模块还包括:
    分别与电机抱闸装置和所述第一控制器连接的指令输出模块;所述第一控制器还用于在接收到SBC指令后,通过所述指令输出模块向所述电机抱闸装置发送抱闸指令,以使所述电机抱闸装置执行电机抱闸操作。
  5. 如权利要求4所述的变频器的功能安全装置,其特征在于,所述第一功能安全子模块还包括:
    分别与所述指令输入模块、所述指令输出模块、所述第一控制器及所述功能安全触发模块连接的软硬件故障诊断模块,用于检测自身所连接的模块器件是否存在故障;若是,则在所述第一控制器正常时,利用所述第一控制器触发所述变频器的功能安全操作;在所述第一控制器异常时,直接利用所述功能安全触发模块触发所述变频器的功能安全操作。
  6. 如权利要求5所述的变频器的功能安全装置,其特征在于,所述指令输入模块包括:
    第一端接入直流电源的第一开关,用于在无功能安全指令输入时处于闭合状态,在有功能安全指令输入时处于断开状态;其中,所述第二功能安全子模块中指令输入模块所包含的第二开关与所述第一开关组成一联动开关;
    分别与所述第一开关的第二端和所述第一控制器连接的指令输入通道模块;
    所述第一控制器还用于利用所述软硬件故障诊断模块周期性向所述指令输入通道模块发送诊断脉冲,以基于所述指令输入通道模块输出的脉冲信号情况检测所述指令输入模块是否存在故障,若是,则利用所述功能安全触发模块触发所述变频器的功能安全操作。
  7. 如权利要求5所述的变频器的功能安全装置,其特征在于,所述电机抱闸装置包括安全抱闸电源、第一继电器、第二继电器及制动抱闸装置;所述第一继电器包括第一线圈和第一触点开关;所述第二继电器包括第二线圈和第二触点开关;其中:
    所述安全抱闸电源与所述第一触点开关的第一端连接,所述第一触点开关的第二端与所述第二触点开关的第一端连接,所述第二触点开关的第二端与所述制动抱闸装置连接,所述第一线圈的第一端和所述第二线圈的 第一端均接入直流电源,所述第一线圈的第二端分别与所述第一功能安全子模块内指令输出模块及软硬件故障诊断模块连接,所述第二线圈的第二端分别与所述第二功能安全子模块内指令输出模块及软硬件故障诊断模块连接;
    则所述第一控制器具体用于在接收到SBC指令后,通过所述指令输出模块控制所述第一线圈断开、第一触点开关打开,以使所述制动抱闸装置失电执行电机抱闸操作;
    且所述第一控制器还用于根据所述软硬件故障诊断模块反馈的第一线圈的通断情况,检测对应的指令输出模块是否存在故障,若是,则利用所述功能安全触发模块触发所述变频器的功能安全操作。
  8. 如权利要求5所述的变频器的功能安全装置,其特征在于,在检测所述第一控制器时,所述软硬件故障诊断模块具体用于根据所述第一控制器的GPIO管脚输出的脉冲信号的时序,检测所述第一控制器是否存在故障,若是,则直接利用所述功能安全触发模块触发所述变频器的功能安全操作。
  9. 如权利要求3所述的变频器的功能安全装置,其特征在于,所述第一控制器还用于利用所述功能安全触发模块向所述变频器发送诊断脉冲信号,以基于所述变频器反馈的信号情况判断所述功能安全触发模块的安全触发通道是否符合预期工作状态,若否,则利用所述功能安全触发模块触发所述变频器的功能安全操作。
  10. 如权利要求3所述的变频器的功能安全装置,其特征在于,所述功能安全装置还包括:
    与所述第一控制器连接的参数设置模块,用于设置所述指令输入模块的不同输入通道与不同功能安全指令的一一对应关系,和/或设置所述第一控制器接收的不同参数与不同功能安全操作的一一对应关系,并将所述对应关系发送至所述第一控制器;
    与所述第二控制器连接的状态显示模块;所述第二控制器用于在接收到所述第一控制器发送的所述对应关系后,将所述对应关系输出至所述状态显示模块显示。
PCT/CN2019/127312 2019-12-23 2019-12-23 一种变频器的功能安全装置 WO2021127805A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2019/127312 WO2021127805A1 (zh) 2019-12-23 2019-12-23 一种变频器的功能安全装置
CN201980100990.7A CN114467062A (zh) 2019-12-23 2019-12-23 一种变频器的功能安全装置

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2019/127312 WO2021127805A1 (zh) 2019-12-23 2019-12-23 一种变频器的功能安全装置

Publications (1)

Publication Number Publication Date
WO2021127805A1 true WO2021127805A1 (zh) 2021-07-01

Family

ID=76572932

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/127312 WO2021127805A1 (zh) 2019-12-23 2019-12-23 一种变频器的功能安全装置

Country Status (2)

Country Link
CN (1) CN114467062A (zh)
WO (1) WO2021127805A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115031406A (zh) * 2022-05-23 2022-09-09 河源锐天科技有限公司 等离子熄火保护电路、控制器及燃气设备

Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101793931A (zh) * 2010-02-26 2010-08-04 上海新时达电气股份有限公司 高压变频器测试系统
CN202230380U (zh) * 2011-10-17 2012-05-23 重庆明宝科技发展有限公司 一种工业在线冗余控制系统
CN103780062A (zh) * 2012-10-24 2014-05-07 包米勒公司 电气机器的安全功能控制
CN104917424A (zh) * 2015-05-26 2015-09-16 深圳市英威腾电气股份有限公司 一种施工升降机的电机抱闸控制系统
CN105573113A (zh) * 2016-02-18 2016-05-11 上海凯泉泵业(集团)有限公司 一种数字化集成式冗余控制系统
JP6073181B2 (ja) * 2013-04-26 2017-02-01 東洋電機製造株式会社 電力変換器及び電力変換システム
CN110045210A (zh) * 2019-05-15 2019-07-23 深圳市英威腾电气股份有限公司 功能安全检测方法、装置、功能安全模块及检测系统
JP2019161759A (ja) * 2018-03-09 2019-09-19 富士電機株式会社 モータ駆動システム

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE102007043769B4 (de) * 2007-09-13 2016-09-01 Sew-Eurodrive Gmbh & Co Kg Gerät, Verfahren zur Adressierung, Umrichter und Verfahren zur sicheren Datenübertragung
US9628065B2 (en) * 2012-10-05 2017-04-18 Fisher-Rosemount Systems, Inc. Safety instrumented process control apparatus and methods

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101793931A (zh) * 2010-02-26 2010-08-04 上海新时达电气股份有限公司 高压变频器测试系统
CN202230380U (zh) * 2011-10-17 2012-05-23 重庆明宝科技发展有限公司 一种工业在线冗余控制系统
CN103780062A (zh) * 2012-10-24 2014-05-07 包米勒公司 电气机器的安全功能控制
JP6073181B2 (ja) * 2013-04-26 2017-02-01 東洋電機製造株式会社 電力変換器及び電力変換システム
CN104917424A (zh) * 2015-05-26 2015-09-16 深圳市英威腾电气股份有限公司 一种施工升降机的电机抱闸控制系统
CN105573113A (zh) * 2016-02-18 2016-05-11 上海凯泉泵业(集团)有限公司 一种数字化集成式冗余控制系统
JP2019161759A (ja) * 2018-03-09 2019-09-19 富士電機株式会社 モータ駆動システム
CN110045210A (zh) * 2019-05-15 2019-07-23 深圳市英威腾电气股份有限公司 功能安全检测方法、装置、功能安全模块及检测系统

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115031406A (zh) * 2022-05-23 2022-09-09 河源锐天科技有限公司 等离子熄火保护电路、控制器及燃气设备

Also Published As

Publication number Publication date
CN114467062A (zh) 2022-05-10

Similar Documents

Publication Publication Date Title
EP3588208B1 (en) Servo system
US8476860B2 (en) Electric power converter
EP3065290B1 (en) Motor control device
CN107895937B (zh) 一种电机控制器冗余保护电路和电子设备
CN108547694B (zh) 一种电磁风扇的检测方法、检测装置和检测系统
JP6222362B2 (ja) 電力変換装置
EP3667860A1 (en) Charging output protection circuit and method thereof
US11190004B2 (en) Relay failure diagnosis circuit
WO2021127805A1 (zh) 一种变频器的功能安全装置
CN110178306A (zh) 马达控制装置以及马达控制系统
JP6825412B2 (ja) モータ制御装置
WO2023241442A1 (zh) 一种异构电机控制装置及方法
CN110962603B (zh) 控制模块、电池管理系统、电路检测及控制方法
WO2020110652A1 (ja) 電磁ブレーキ制御装置及び制御装置
CN114467245A (zh) 可编程电子功率调节器
US11355297B2 (en) Safety-related switching device
CN111942306B (zh) 一种汽车电子执行器控制方法及系统
CN202583805U (zh) 数字控制系统
CN112721639B (zh) 一种继电器控制方法及装置
CN110686358B (zh) 一种基于检测工装的变频空调器故障诊断方法
CN218117959U (zh) 风电变桨控制系统及风电设备
CN116079763B (zh) 一种机器人、安全扭矩关断电路及安全扭矩控制方法
JPH02217099A (ja) 負荷制御装置
CN220455472U (zh) 一种开关检测装置和机器人
CN116409690B (zh) 一种电梯封星自适应实现方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19957162

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19957162

Country of ref document: EP

Kind code of ref document: A1

122 Ep: pct application non-entry in european phase

Ref document number: 19957162

Country of ref document: EP

Kind code of ref document: A1