Secure data transfer method and system
Abstract
Die Erfindung erreicht durch Bereitstellung zusammenwirkender, verteilt in Kommunikationsteilnehmern (21, 22) angeordnete Auswerteeinheiten (212, 222) zur Auswertung sicherheitsgerichteter Daten auf einfache und kostengünstige Weise eine sichere Datenübertragung in einem Kommunikationssystem (1), welches zur Steuerung sicherheitsrelevanter Prozesse eingesetzt wird. Dementsprechend sieht die Erfindung ein Verfahren vor bei dem eine Datennachricht von einem ersten Teilnehmer (21) über ein zur seriellen Datenübertragung ausgebildetes Kommunikationssystem (1) zu einem zweiten Teilnehmer übertragen wird und die Datennachricht durch eine zweite, in dem zweiten Teilnehmer (22) angeordnete Auswerteeinheit (222) überprüft wird. In Abhängigkeit des Ergebnisses der Überprüfung der Datennachricht wird von dem zweiten Teilnehmer (22) zu dem ersten Teilnehmer (21) eine Quittungsnachricht übertragen, welche wiederum von der ersten, in dem ersten Teilnehmer (21) angeordneten Auswerteeinheit (212) überprüft wird. Ferner sieht die Erfindung ein System zur Durchführung des Verfahrens vor.

Term
Projected expiry 1 November 2027.
- Priority
- Filed
- Published
- Today
- Projected expiry
16 claims: 10 independent, 6 dependent
- 1Verfahren zur sicheren Datenübertragung zwischen wenigstens einem ersten (21, 21', 23, 26) und einem zweiten (22, 22', 24, 27) Teilnehmer eines Kommunikationssystems (1, 1'), das zur seriellen Datenübertragung zwischen den Teilnehmern (21, 22, 21', 22', 23, 24, 26, 27) ausgebildet ist, wobei der erste Teilnehmer eine erste Auswerteeinheit (212, 232, 262) und der zweite Teilnehmer eine zweite Auswerteeinheit (222, 242, 272) umfasst, mit den Schritten - Übertragen einer Datennachricht von dem ersten Teilnehmer (21, 21', 23, 26) zu dem zweiten Teilnehmer (22, 22', 24, 27), - Überprüfen der Datennachricht durch die zweite, in dem zweiten Teilnehmer angeordnete Auswerteeinheit, - Übertragen einer Quittungsnachricht von dem zweiten Teilnehmer zu dem ersten Teilnehmer in Abhängigkeit des Ergebnisses der Überprüfung der Datennachricht, und - Überprüfen der Quittungsnachricht durch die erste, in dem ersten Teilnehmer angeordnete Auswerteeinheit.
- 2Verfahren nach vorstehendem Anspruch, wobei das Überprüfen einer Datennachricht durch eine Auswerteeinheit, das Überprüfen einer Quittungsnachricht durch eine Auswerteeinheit, das Überwachen des Datenstroms durch eine Überwachungsschaltung und/oder das Überwachen der Funktionsfähigkeit einer Auswerteeinheit durch eine Überwachungsschaltung durch Ausführen einer in dem ausführenden Teilnehmer (22) hinterlegten Funktion (22p1, 22p2) erfolgt, und wobei vor Ausführen der Funktion Teile (22p2) der auszuführenden Funktion und/oder Parameter zum Ausführen der Funktion von einem weiteren Teilnehmer (21) zu dem ausführenden Teilnehmer (22) übertragen werden.
- 3Verfahren nach einem der vorstehenden Ansprüche, wobei zwischen den ersten und den zweiten Teilnehmer ein Steuer-oder Sensorelement (70) geschaltet ist, das keine Auswerteeinheit umfasst.
- 4Verfahren nach Anspruch 3, wobei das Steuer- oder Sensorelement (70) als mechanisches Element ausgebildet ist.
- 5Verfahren nach einem der vorstehenden Ansprüche, wobei die serielle Datenübertragung zwischen den Teilnehmern (21, 22, 21', 22', 23, 24, 26, 27) mittels eines Datenübertragungsprotokolls erfolgt, und/oder wobei die serielle Datenübertragung zwischen den Teilnehmern über einen kabelgebunden (30) oder drahtlos (30') ausgebildeten seriellen Bus erfolgt, und/oder wobei der erste und/oder der zweite Teilnehmer als Sensor oder Aktuator eines Automatisierungssystems ausgebildet ist, und/oder wobei die Datennachricht ein Ein- oder Ausgangssignal eines Sensors bzw. Aktors umfasst, und/oder wobei das Überprüfen der Datennachricht und/oder der Quittungsnachricht ein Überprüfen der in der Nachricht enthaltenen Daten auf Plausibilität umfasst, und/oder wobei das Überprüfen der Quittungsnachricht ein Vergleichen von in der Quittungsnachricht enthaltenen Daten mit in der Datennachricht enthaltenen Daten umfasst, und/oder wobei die Quittungsnachricht eine weitere gültige Datennachricht umfasst, und/oder wobei das den ersten und zweiten Teilnehmer umfassende Kommunikationssystem (1, 1') als Master/Slave-System ausgebildet ist, wobei der erste oder zweite Teilnehmer als Master ausgebildet ist, und/oder wobei der erste oder zweite Teilnehmer an ein übergeordnetes Bussystem (40) angeschlossen ist.
- 6Verfahren nach einem der vorstehenden Ansprüche, wobei jeder Auswerteeinheit (212, 222, 232, 242) eine Überwachungsschaltung (214, 224, 234, 244) zugeordnet ist, die den Datenstrom zu und/oder von der zugeordneten Auswerteeinheit (212, 222, 232, 242) gemäß einem vorgegebenen Protokoll auf Gültigkeit überwacht und im Fehlerfall die zugeordnete Auswerteeinheit (212, 222, 232, 242) und/oder einen durch die zugeordnete Auswerteeinheit gesteuerten Sensor oder Aktor in einen sicheren Zustand setzt, wobei ein Überwachen des Datenstroms durch die Überwachungsschaltung (214, 224, 234, 244) insbesondere das Erkennen eines vorgegebenen Musters umfasst, und/oder wobei die Überwachungsschaltung (214, 224, 234, 244) insbesondere die Funktionsfähigkeit der zugeordneten Auswerteeinheit (212, 222, 232, 242) überwacht.
- 7System zur Übertragung sicherheitsgerichteter Daten zur Steuerung eines Automatisierungssystems, insbesondere ausgebildet zur Ausführung eines Verfahrens nach einem der vorstehenden Ansprüche, umfassend - ein serielles Kommunikationssystem (1) mit wenigstens einem ersten und einem zweiten daran angeschlossenen Teilnehmer (21, 22, 21', 22', 23, 24, 26, 27), - wenigstens eine erste, in dem ersten Teilnehmer (21, 21', 23, 26) angeordnete Auswerteeinheit (212 , 232, 262), und - wenigstens eine zweite, in dem zweiten Teilnehmer (22, 22', 24, 27) angeordnete Auswerteeinheit (222, 242, 272), wobei die zweite Auswerteeinheit zum Überprüfen einer von dem ersten Teilnehmer empfangenen Datennachricht und zum Generieren einer Quittungsnachricht in Abhängigkeit des Ergebnisses der Überprüfung der Datennachricht ausgebildet ist, die erste Auswerteeinheit zum Überprüfen einer von dem zweiten Teilnehmer empfangenen Quittungsnachricht ausgebildet ist, und der erste und/oder der zweite Teilnehmer dazu ausgebildet sind, im Fehlerfall eine Sicherheitsfunktion auszuführen.
- 8System nach Anspruch 7, wobei wenigstens ein Teilnehmer dazu ausgebildet ist, das Überprüfen einer Datennachricht durch eine Auswerteeinheit, das Überprüfen einer Quittungsnachricht durch eine Auswerteeinheit, das Überwachen des Datenstroms durch eine Überwachungsschaltung und/oder das Überwachen der Funktionsfähigkeit einer Auswerteeinheit durch eine Überwachungsschaltung durch Ausführen einer in dem Teilnehmer (22) hinterlegten Funktion (22p1, 22p2) durchzuführen, wobei der wenigstens eine Teilnehmer (22) ferner dazu ausgebildet ist, zum Ausführen der Funktion ausführbare Funktionsteile (22p2) und/oder Parameter von einem weiteren Teilnehmer (21) anzufordern.
- 9System nach einem der vorstehenden Ansprüche 7 bis 8, wobei zwischen den ersten und den zweiten Teilnehmer ein Steuer- oder Sensorelement (70) geschaltet ist, das keine Auswerteeinheit umfasst.
- 10System nach Anspruch 9, wobei das Steuer- oder Sensorelement (70) als mechanisches Element ausgebildet ist.
- 11System nach einem der vorstehenden Ansprüche 7 bis 10, wobei der erste (23) und der zweite (24) Teilnehmer in einer gemeinsamen Baugruppe (25) angeordnet sind.
- 12System nach einem der vorstehenden Ansprüche 7 bis 10, wobei das Datenübertragungsprotokoll des Kommunikationssystems (1) als sicheres Kommunikationsprotokoll ausgebildet ist, und/oder wobei das Kommunikationssystem (1, 1') zur seriellen Datenübertragung zwischen den Teilnehmern einen kabelgebundenen (30) oder drahtlosen (30') seriellen Bus umfasst, und/oder wobei der erste und/oder zweite Teilnehmer als Sensor oder Aktuator des Automatisierungssystems ausgebildet ist, und/oder wobei die erste und/oder zweite Auswerteeinheit zum Überprüfen von in einer Datennachricht oder einer Quittungsnachricht enthaltenen Daten auf Plausibilität ausgebildet ist, und/oder wobei die erste und/oder zweite Auswerteeinheit zum Vergleichen von in einer Datennachricht enthaltenen Daten mit in einer Quittungsnachricht enthaltenen Daten ausgebildet ist, und/oder wobei wenigstens die zweite Auswerteeinheit zum Generieren einer Quittungsnachricht ausgebildet ist, welche eine weitere gültige Datennachricht umfasst.
- 13System nach einem der vorstehenden Ansprüche 7 bis 12, wobei jeder Auswerteeinheit (212, 222, 232, 242) eine Überwachungsschaltung (214, 224, 234, 244) zugeordnet ist, die dazu ausgebildet ist, den Datenstrom zu und/oder von der zugeordneten Auswerteeinheit (212, 222, 232, 242) gemäß einem vorgegebenen Protokoll auf Gültigkeit zu überwachen und im Fehlerfall die zugeordnete Auswerteeinheit (212, 222, 232, 242) und/oder einen durch die zugeordnete Auswerteeinheit gesteuerten Sensor oder Aktor in einen sicheren Zustand zu setzen, wobei .
- 1413. System nach Anspruch 13 wobei die Überwachungsschaltung (214, 224, 234, 244) zum Erkennen eines vorgegebenen Musters ausgebildet ist.
- 1514. System nach Anspruch 13 oder 14, wobei die Überwachungsschaltung (214, 224, 234, 244) dazu ausgebildet ist, die Funktionsfähigkeit der zugeordneten Auswerteeinheit (212, 222, 232, 242) mittels einer Funktion zu überwachen.
- 1615. System nach einem der vorstehenden Ansprüche 7 bis 14, wobei das den ersten und zweiten Teilnehmer umfassende Kommunikationssystem (1, 1') als Master/Slave-System ausgebildet ist, wobei der erste oder zweite Teilnehmer als Master ausgebildet ist, und/oder wobei der erste oder zweite Teilnehmer an ein weiteres, übergeordnetes Kommunikationssystem (40) angeschlossen ist.
Independent claims16
77 paragraphs, as filed
p0001The invention relates generally to the safety engineering of automation systems, and particularly to a method and a system for secure data transmission between subscribers of a communication system used to control a machine or plant.
p0002Security technology is used in automated processes in various industrial sectors in order to protect employees from injury and to preserve the functionality of machinery and equipment. In safety-related applications, the entire signal path of a safety function is considered. This comprises the safety devices, such as control units, sensors and actuators, and their interconnections. These compounds are largely designed in parallel wiring. However, parallel wired routes require high expenditure for fault detection of secure cabling. This is seen by diagnostic functions of secure devices to, for example, landscape or shorts or open connections. Depending on the security requirements, these systems are also designed diversely redundant or partly to control or detect the possibility of errors occurring. This approach is impractical in the planning and for some application areas and beyond the execution is often complicated and costly.
p0003A significant cost item within the planning, cabling and equipment costs, the transformation costs for signal matching between logic signal and peripheral signals that occur through transfer points between the input or output components and the control.
p0004In modern systems, secure networks solve large parts of these routes from through serial connections, as this simplifies the signal path between the input or output component and control. However, the serial networking with the current network solutions is very costly and is currently used only for high-end devices. The reason for this is the most different working principle of cabling monitoring, the redundancy in the wiring and the simplicity of the sensors, such as a purely mechanical opener. A combination of devices with a network connection and parallel wiring is not possible in this context. A networkable sensor, for example, is thus not simply be exchanged for a wired sensor.
p0005On the transmission and processing of safety-related data in a set for controlling an automation system serial communication system special demands are made. Safety-related data in this context are those data which are used to control safety-relevant processes of a machine or system, each process is relevant to safety, of which a non-negligible risk to human and / or material goods starts when an error occurs.
p0006One approach to this problem of the prior art is, in particular, the safety-related components of the system at a certain security level multi-channel, ie build redundant. For example, it can be provided in an automation bus system, Sicherheitsbuskomponenten, ie, for example, bus users that are associated with a safety-related machine, equipped with redundant hardware components. At the same time, the central control and the bus be constructed multi-channel, or even be provided for controlling the safety-relevant components separate from the process control and special circumstances redundant safety control. The bus is typically provided with a secure protocol, which also secure protocol itself may have a redundancy. The security control essentially performs the links between the safety-related input information and then transmits, for example, via an automation, safety related link data to output components. The starting components in turn process the received security measures and enter after a positive test this to the periphery of. In addition, they switch their outputs into a safe state if they find an error or have within a predetermined time period to receive any valid data. A control system for controlling safety-critical processes, in which the safety-directed arrangements comprise a multi-channel structure is, for example,<patcit id="pcit0001" dnum="EP1188096B1"><text>EP 188 096 B1 1</text></patcit> known.
p0007It is also known, specially trained to provide secure communication participants, in which an increase of security by a redundant evaluation logic in combination with a fail-safe comparator is reached. Such safety bus are used for example in on INTERBUS Safety based systems.
p0008The systems described, however, the provision of redundant hardware components disadvantageously leads to increased complexity and increased costs.
p0009The object of the invention is therefore to show a way, as in a communication system, a secure data transmission in a simple and cost-effective manner can be provided, in particular by using standard components and integration of simple, in particular mechanical sensors or actuators.
p0010Further object of the invention is to provide a safety-related communication system which manages with low hardware costs and can be flexibly adapted to the respective Anfordernisse.
p0011The invention solves this problem with a method having the features of claim 1 and a trained for carrying out such a process system according to claim 7. Further developments of the invention are specified in the subclaims.
p0012Accordingly provides an inventive method for secure data transmission between at least a first and a second subscriber of a communication system, which is designed to sereillen data transmission between the participants, initially transmitting a data message from the first subscriber to the second subscriber before. The data message is checked by a second, arranged in the second subscriber evaluation unit. Depending on the result of the review of the data message by the second evaluation, this generates an acknowledgment message which is transmitted from the second party to the first party. Preferably, an acknowledgment message is sent only upon successful verification of the data message. The acknowledgment message is checked upon receipt by the first, arranged in the first party evaluation. There is thus a redundant checking by the first and second evaluation unit, wherein the first and second participants form a corresponding pair of participants.
p0013The process is particularly preferably used in the sensor plane of systems for controlling safety-related automated processes. Accordingly, the first or the second subscriber is particularly advantageously designed as a sensor or actuator of an automation system. The data message comprises thus advantageously an input or output signal of a sensor or actuator of the automation system.
p0014Advantageously comprises the checking of the data message and / or the acknowledgment message by the first and second evaluation, a check of the data contained in the message for plausibility. Accordingly, preferably a check of the data contained in the abzusendenden by the first subscriber data message by the first evaluation done before the data message is transmitted to the second party, said after receiving the data message, a further review of the data contained by the second evaluation in the second subscriber takes place. In this embodiment, the check of acknowledgment message can be limited to a register the receipt of a pre-defined message.
p0015In a further advantageous embodiment, the second subscriber by means of the second evaluation unit generates an acknowledgment message comprising the data contained in the received data message. In this embodiment the checking of the acknowledgment message by the first evaluation unit comprises a comparing contained in the acknowledgment message with data contained in the data message previously transmitted data. For this purpose, transmitted from the first subscriber in a data message data are buffered at least until receipt of the corresponding acknowledgment message.
p0016In yet another advantageous embodiment, the second party generates a receipt message, which includes a more valid data message.
p0017If it is detected in checking the data message or the acknowledgment message by an evaluation error, leads the participant whose evaluation detected the error, preferably a safety-related function.
p0018For data transmission between the participants can be provided depending on the purpose advantageously a wired or wireless serial bus or a wired or contactless-acting network. In the simplest case, a point-to-point protocol between the first and second party is used, where one of the participants referred to for example as a sensor or actuator and the other as input or output component, hereinafter referred to as I / O module, is trained.
p0019The serial data transmission between the subscribers of the communication system is advantageously based on a predetermined communication protocol. Since the described method can be used both advantageous in the standard sensors and -Aktuatorik and in security systems, are placed on the communication protocol used in the additional requirements, the predetermined communication protocol is preferably either secure or not configured securely.
p0020For the control of safety-related processes a predetermined secure communication protocol is dementpsrechend advantageously used in which, for example, by redundant data content error detection is enabled, the review of the data message and / or the acknowledgment message by the first and second evaluation error checking in accordance with the predetermined secure communication protocol includes , The secure communication protocol, for this purpose, for example, a checksum as the cyclic redundancy check (CRC; Cyclic Redundancy Check) include.
p0021A secure communication protocol can also provide with advantage that recurring of all or a predetermined group of subscribers of the communications system, for example, once per communication cycle, a specific message is sent, which can also change according to a defined algorithm.
p0022The invention is thus based on the principle advantage of a serial secure connection between two subscribers. To reduce the area covered by the prior art secure and redundantly designed evaluation per unit, is shifted in each endpoint is a part of the safe evaluation. Through an acknowledgment of data security is provided redundantly available.
p0023By distributing the guarantees safety redundancy on two distributed evaluation of the use of standard components for the transmission of secure data is particularly advantageous possible.
p0024In a further embodiment of the method according to the invention the second evaluation unit is arranged together with the first evaluation unit in a common assembly, which is formed in two channels in this embodiment. Also in this embodiment can be advantageously used a dual-channel standard component.
p0025The distributed redundancy and in particular through the exchange of data between the first and second evaluation unit is further enables particularly advantageous, simple and even mechanical components, as designed, for example as NC or standard or safety switches to integrate while maintaining security with.
p0026Accordingly, in a further particularly preferred embodiment of the invention between the first and the second evaluation unit a control or sensor element is connected, which itself does not include the evaluation unit and in particular as a simple, preferably formed mechanical sensor or actuator.
p0027Preferably the mechanical member is coupled to an output of the first evaluation unit and to an input of the second evaluation unit, wherein an output of the second evaluation unit is connected to an input of the first evaluation unit. Such a special wiring can be realized in a particularly simple manner with a first and second subscriber, which are arranged in a common assembly.
p0028For monitoring of the distributed evaluation means disposed in the respective subscriber monitoring circuit is preferably used to the data stream and / or monitored by the respectively associated evaluation unit in accordance with a predetermined protocol for validity and the associated evaluation unit and / or a controlled by the associated evaluation unit in case of failure sensor or actuator in a safe state or is served by an appropriate replacement value. About a missing acknowledgment message or a lack of valid data stream information on the occurrence of failure of the other party shall be immediately notified.
p0029As already mentioned above, the evaluation units communicate advantageous over a secure protocol each other and check the sent data content. The load connected to the evaluation unit monitoring circuit checks the data stream to be valid, this being done in the simplest case by pattern recognition, without knowing the secure content. Accordingly, the monitoring of the data stream by the monitoring circuit preferably includes detecting at least one predetermined pattern. Advantageously, the monitoring also include a dynamic pattern recognition, for example, by comparing simple content. To this end, the transmitted data messages can be provided with a date, which varies according to a predetermined algorithm. The monitoring circuit can also monitor its associated evaluation unit for functionality, for example by means of a watchdog function. As a watchdog function is a function of the monitoring circuit is referred to in this context, which monitors the receive periodic signals from the associated evaluation unit, and detects the absence of these signals as an error.
p0030The checking described above a data or acknowledgment message by an evaluation unit, and the monitoring of the data stream by a monitoring circuit and / or monitoring the functioning of an evaluation unit by a monitoring circuit typically comprise the execution of a function, wherein the function advantageously identical in the first and second evaluation is available. For this purpose, a memory and a microprocessor is advantageously provided, wherein performing the function comprises performing a data stored in the memory or program execution code by the microprocessor.
p0031Because of the versatility of the sensors and actuators of an automation system and the resulting variety of different functions, which can not be unified as desired, it is not appropriate, in a configured as I / O module participants serving as a corresponding to a sensor or actuator participants is used to provide the total number of different functionalities by default.
p0032Rather, advantageously a part of the stored in the sensor or actuator safety-related application function and / or to perform the function required parameters of the sensor or actuator is transmitted to the corresponding subscriber. This is preferably done within an initialization phase before the start of data transfer safety-related data between the participants.
p0033The corresponding subscriber to the formed of a sensor or actuator as participants parts of a safety-related application function are transmitted in the form of a program or execution code, preferably has an appropriate interpreter to run the program or execution code.
p0034By loading part of the application program of a sensor or actuator, especially that part which is to be to increase the safety redundantly available to the cooperating input and output components, these can edit the sensor or actuator application with. The necessary raw data such as sensor signals and the results needed for further processing are exchanged serially between the participants. This allows a particularly advantageous cost-effective manufacture of the sensor or actuator, as only a single-channel hardware is through the participation of the intelligent input or output device that processes the transferred application code, for example by means of an interpreter, in the sensor or actuator required.
p0035Accordingly, that the method provides advantageous checking a data message by an evaluation unit, the checking of an acknowledgment message by an evaluation, monitoring the data stream by a monitoring circuit and / or monitoring the functioning of an evaluation by a monitoring circuit by performing exporting in the participants assigned function occurs, wherein parts of the function and / or parameters for performing the function of a new participant to the exporting participant to be made are transferred before executing the function.
p0036Part of an evaluation performed by an evaluation unit can each participant as described above by another participant, in particular by the evaluation of a corresponding sensor or actuator are transmitted. Alternatively, the corresponding parts of the program, for example, by reading out the functionality of the corresponding sensor or actuator can also be transmitted from a central control unit by the control unit. The transfer of the program components can advantageously be automatically, and optionally depending a predetermined configuration of the automation system. The transmission can take place depending on the purpose of a separate communication channel.
p0037As described above, the first or second user is preferably formed as a sensor or actuator. For communication with higher-level data processing units corresponding respectively to the sensor or actuator and for meadow configured as I / O module subscriber is preferably connected to a further, overarching bus system.
p0038Also, a plurality of first or second subscriber can be provided. For example, may be connected as a sensor or actuator trained participants via a serial bus attachable to a corresponding subscriber a plurality. Advantageously can be carried out according to the master / slave principle, the serial communication between the participants, in which instance the corresponding participant to master and trained as a sensor or actuator participants form the slaves.
p0039The corresponding subscriber may also be advantageous additionally connected to a higher-level bus, which is designed for example as a serial, on a fieldbus or Ethernet-based bus.
p0040An inventive system for transmitting safety-related data for controlling an automation system, which is designed in particular for performing a method as described above, includes a serial communication system having at least a first and a second subscriber connected thereto, at least one first, arranged in the first party evaluation, and at least one second, arranged in the second party evaluation, the second evaluation unit for checking a message received from the first subscriber data message and to generate an acknowledgment message is formed depending on the result of the review of the data message, the first evaluation unit for checking a second of the participants received acknowledgment message is formed and the first and / or second subscriber are configured to perform a safety function in case of failure.
p0041Particularly advantageously, the communication system for serial data transmission between the participants on a wired or wirelessly acting serial bus.
p0042The first and / or second user is advantageously constructed as a sensor or actuator of an automation system. The evaluation units are accordingly in particular for evaluation of safety-related input and / or output data of a sensor and / or actuator affecting a safety-relevant process of an automation system.
p0043The first and second evaluation unit thus form a distributed redundancy, wherein the evaluation units are arranged for this purpose in different subscribers.
p0044In a preferred embodiment, the first and second participants form a corresponding pair of participants, one of the participants are formed as sensor or actuator and the other party as a corresponding input or output component. Further, the participants arranged in corresponding first and second evaluation units may advantageously be the functionality of the respective other evaluation unit comprise. It is therefore acting in both directions interface provided, so that the participants can be used as input or output components.
p0045For the evaluation of input and / or output signals, for example, sensor signals or control signals for actuators, the first and / or second evaluation unit are preferably configured for checking contained in a data message or an acknowledgment message data for plausibility. Further, the first and / or second evaluation unit can be advantageously adapted to compare data contained in a data message with information contained in an acknowledgment message. In a further advantageous embodiment, the first and / or second evaluation unit to be configured to generate a more valid data message as an acknowledgment message.
p0046The system may further advantageously comprise any of the embodiments described above in connection with the method.
p0047Accordingly, the evaluation units are particularly preferably configured to exchange data using a secure communications protocol. For maximum flexibility in operational capability, the evaluation can preferably represent digital and analog values via the protocol, runtime and parameter data for secure and nonsecure applications can also occur mixed.
p0048Further particularly advantageous simple, in particular mechanical sensors or actuators can be integrated in the system that have no evaluation unit for evaluating safety-related data and which are connected to that end between the first and second evaluation. The possibility next networkable sensors and actuators to be able to use standard mechanical components, simplifies the repair of existing systems and is compatible with current sensors and actuators.
p0049For easy wiring of a standard mechanical component of the first and second nodes are arranged advantageously in a common assembly.
p0050To further increase the safety of each analysis unit is preferably assigned a monitoring circuit which is adapted to monitor the data flow to and / or from the associated evaluation unit in accordance with a predetermined protocol for validity and in the case of a fault the associated evaluation unit and / or an assigned by the evaluation unit to set controlled sensor or actuator in a safe state.
p0051The monitoring circuit is preferably designed for this purpose for recognizing a predetermined static or dynamic pattern, and may further include a watchdog function for monitoring the operational capability of the associated evaluation unit. In the simplest case, is sufficient a survival of the single-channel monitoring hardware to control the secure process and to provide in case of failure the input or output to ensure safety with a substitute value.
p0052As already described above in connection with the method, the communication system is advantageously configured as a master / slave system, wherein the first or second party is the master. Furthermore, the first or second subscriber is preferably connected to a further higher-level communication system for exchanging data with a superordinate data processing or control unit.
p0053In order not to have to maintain functionality of the evaluation for every conceivable application in each subscriber, the first and / or second subscriber are advantageously adapted and / or to request functional parts parameters selected by other users.
p0054Accordingly, a subscriber is preferably at least configured to checking of a data message by an evaluation unit, the checking of an acknowledgment message by an evaluation unit, the monitoring of the data stream by a monitoring circuit and / or monitoring the functioning of an evaluation unit by a monitoring circuit by performing in the subscriber perform assigned function, wherein the at least one subscriber is further adapted to request for performing the function executable functional parts and / or parameters of another subscriber.
p0055Conveniently, the corresponding subscriber in a memory for storing the execution code of the function to be executed, in which a basic function of the subscriber is stored, plus the requested or obtained automatically as needed functional components and / or parameters are stored in the in the startup phase of the system. To carry out the function of the subscriber advantageously has a microprocessor. Furthermore, an interpreter in the subscriber is provided to increase the flexibility advantage that is used to perform the additional function parts.
p0056The additional functional components and / or parameters can also be advantageously produced by a central control unit, for example in response to a predetermined configuration of the automation system, available.
p0057The invention provides in a simple way enables secure data communication. The inventively equipped sensors or actuators can be produced cost-effectively and with less variance. This also applies to trained as central modules or decentralized network subscriber I / O cards Automatierungssystemen.
p0058Furthermore, current installation guidelines can be simplified by the present invention, thereby misbehavior and ignorance of the connected sensors and actuators has less influence on the function of the safety technology.
p0059The invention is described by way of example with reference to preferred embodiments and with reference to the accompanying drawings. Here, the same reference numerals in the drawings, the same or like parts.
p0060Show it:<dl id="dl0001" compact="compact"><dt>FIG. 1a:</dt><dd>a schematic representation of an exemplary signal path of an input signal towards a control unit with a parallel connection,</dd><dt>Fig 1b.:</dt><dd>a schematic representation of an exemplary signal path of an input signal, to a control unit in serial connection,</dd><dt>Fig. 2:</dt><dd>a schematic representation of an embodiment with a first and second subscriber,</dd><dt>Fig. 3:</dt><dd>a schematic representation of an embodiment in which an emergency stop switch is connected between a first and a second subscriber,</dd><dt>Fig. 4:</dt><dd>a schematic representation of an embodiment in which an emergency stop switch is connected between a first and a second party, wherein the first and second nodes are arranged in a common assembly,</dd><dt>Fig. 5</dt><dd>a schematic representation of a first embodiment of the functional components of the in <figref idrefs="f0002">FIG. 2</figref> illustrated first and second subscriber,</dd><dt>Fig. 6</dt><dd>a schematic representation of a second embodiment of the functional components of the in <figref idrefs="f0002">FIG. 2</figref> illustrated first and second subscriber,</dd><dt>Fig. 7</dt><dd>a schematic representation of an embodiment in which the serial communication between the first and second subscriber is wireless, and</dd><dt>Fig. 8</dt><dd>a schematic representation of an embodiment in which the first and second participants form a light grid.</dd></dl>
p0061The <figref idrefs="f0001">Figures 1a and 1b</figref> show for a safety application by way of example the signal of an input signal from a sensor, to a trained component as an input I / O module, the typical cost of a parallel and a serial connection is compared.
p0062As in <figref idrefs="f0001">Fig. 1A</figref> shown, a physical quantity 101 of a process 100 is determined. For this, a measurement of a typically analog quantity is made in a process-oriented unit 110 by a sensor 111 initially. These electrically evaluable measurement quantity is converted by an A / D converter 112 into a digital processable size and processed by a processing unit 113 to a digital application value. In parallel wiring will now be given for the purpose of data transmission to an I / O module 120, in turn, a conversion of the digital application value in a standard signal by a D / A converter 114. This standard signal is now using a cabling 130, for example the nip, sub-distribution, etc., transmitted to the I / O module 120, wherein the wiring for the transmission of safety-related signals are typically to make special demands. In the I / O module 120 by means of A / D converter 121 there is a reconversion of the transmitted signal in the digital application value which is processed by processing unit 122 and, if necessary, converted to transfer to secondary systems by converter 123, for example, a network protocol.
p0063The invention simplifies the signal path from the perspective of security technology such that the efforts in the devices, sensors and actuators and the wiring can be minimized. To this end, the invention as shown in<figref idrefs="f0001">Fig. 1B</figref> shown, advantageously a direct serial connection 140 between the processing units 113 and 122 of the sensor module 110 'or the I / O module 120' before.
p0064In non-security systems are made of the prior art serial bus systems for control of sensors and actuators, although already known in some cases, however, come in safety engineering requirements added, which are not met by the prior art.
p0065One way to comply with safety regulations would be to provide redundant evaluation units in the sensors or actuators. To minimize hardware costs, a distributed redundancy of evaluation units is in a system according to the invention, however, advantageously provided by in each case an evaluation unit is arranged in corresponding participants.
p0066In <figref idrefs="f0002">FIG. 2</figref> is an exemplary serial communication system 1 is illustrated which is suitable for use of the invention and the two participants 21 and 22, between which there is a serial secure connection over the bus system 30th The bus subscribers 21 and 22 each include an evaluation unit 212 and 222, which each form a part of a corresponding pair of evaluation units for achievement of a distributed redundancy. The participants 21 and 22 also each include a monitoring circuit 214 or 224 which monitors the data stream, as well as an interface to a safety-relevant application 216 and 226, respectively, in the<figref idrefs="f0002">FIG. 2</figref> is represented symbolically as a switch. The safety-related application typically includes an executable, Undocked in a memory program, which is adapted to influence potentially hazardous processes of an automation system.
p0067The evaluation units 212 and 222 communicate via the secure protocol each other and check the sent data content. Through an acknowledgment of data security is provided redundantly available. The load connected to the respective evaluation unit monitoring circuit 214 or 224 checks the data stream by means of pattern recognition for validity and sets in the event of a fault, the evaluation unit 212 or 222 in the safe state.
p0068As in <figref idrefs="f0002">Fig. 3</figref> illustrated, the invention also allows the simple mechanical connection control and sensor elements. Shown are in turn the participants 21 and 22, which are interconnected via the serial bus system 30th In this embodiment, the bus nodes 21 and 22 are so connected with the mechanical emergency stop switch 70 that the signal path from the output of the evaluation unit 212 to the input of the evaluation unit 222 passes through the emergency stop button 70, and the integrated, redundant switch 71 and 72 happened. The emergency stop button 70 is designed such that upon manual actuation of both switches 71 and 72 are operated simultaneously. Through the exchange of data between the distributed evaluation units 212 and 222 operating the emergency stop button is detected. About respective circuits can also select NO and NO / NC combinations using besides the illustrated openers (emergency stop button). This can also be used with a separate test signal injection or common test signal infeed.
p0069In <figref idrefs="f0003">Fig. 4</figref> is a preferred modification of the in <figref idrefs="f0002">Fig. 3</figref> Illustrated embodiment shown in which the participants 23 and 24 that the Teilnehmner 21 and 22 substantially correspond, are arranged in a common assembly 25, which is connected to the emergency stop button 70th Participants 23 and 24 again comprise evaluation units 232 and 242, respectively, and associated monitoring circuits 234 and 244, as well as interfaces for security-related applications 236 and 246. In this embodiment extends the signal path from the output of the evaluation unit 242 to the input of the evaluation unit 232 through the switch 71 and 72 of the emergency stop button 70, the corresponding output of the evaluation unit 232 is connected to the corresponding input of the evaluation unit 242b.
p0070<figref idrefs="f0004">Fig. 5</figref> shows a schematic representation of the functional components of the in <figref idrefs="f0002">FIG. 2</figref> illustrated first and second subscriber 21 and 22. To perform a safety-related application is 21 and 22, a memory 21s and 22s provided in each of the participants, in which a respective executable execution code is 21p or 22p stored. For the execution of the application is a microprocessor in each case 21m and 22m are provided in the nodes 21 and 22, has access to the respective memory.
p0071In the illustrated embodiment, the user 21 as a sensor and the subscriber 22 is formed as an I / O module that communicate over the serial bus system 30 with each other. The component acting as input I / O module 22 is additionally connected to a superordinate communication system 40, which allows, for example, communication with a higher-level control unit.
p0072The Applications 21p and 22p are in the illustrated embodiment is substantially identical to in the <figref idrefs="f0002">FIG. 2</figref> illustrated corresponding evaluation to be carried out 212 or 222nd
p0073<figref idrefs="f0004">Fig. 6</figref> shows a preferred embodiment of the functional components of the in <figref idrefs="f0002">FIG. 2</figref> illustrated first and second subscriber 21 and 22, again of the subscriber 21 are formed as a sensor and the subscriber 22 as a corresponding I / O module. In this embodiment, the subscriber has a 21 stored in the memory 21s safety application, comprising the application parts 21p1 and 21p2 which initially partially or completely not in corresponding subscriber 22 available.
p0074In the illustrated embodiment of the subscriber 22 has a stored in its memory 22s basic functionality 22P1 corresponding to the application part 21p1. In the startup phase of the system the subscriber 22 requests the missing application part 21p1 of the subscriber 21, which it thereafter transmits to the subscriber 22nd The participant 22 stores the received application part 22p2 22s in storage. In order to ensure a high degree of flexibility, an interpreter in this embodiment, in the subscriber 22 further 22i provided, which has access to the memory 22s is connected to the microprocessor and 22m. The interpreter 22i is configured to at least the execution code also provided to interpret 22p2 and thus allow a run by the microprocessor 22m.
p0075The additional application part 22p2 can be the subscriber 22 alternatively transmitted based by a central control unit to a configuration of an automation system via the parent communication system 40th The transmission can for example take place via a separate communication channel.
p0076<figref idrefs="f0005">Fig. 7</figref> shows a communication system 1 'with the participants 21' and 22 ', which in the modification in <figref idrefs="f0002">FIG. 2</figref> Participants represented 21 and 22 'communicate via a wireless serial interface 30th For this purpose, to the subscriber 21 'and 22' corresponding transceivers 218 and 228, respectively, by means of which 21 'and 22' allow a safe serial communication between the subscribers wirelessly. For the rest, the construction corresponds to the subscriber 21 'and 22' which in the<figref idrefs="f0002">FIG. 2</figref> Participants represented 21 and 22nd
p0077In <figref idrefs="f0005">Fig. 8</figref> is shown a further embodiment of the invention. There is provided a light grid with a transmitter 26 and a receiver 27. The transmitter 26 comprises a plurality of light sources 265, an evaluation unit 262 and a separately controlled light source 266. The receiver 27 comprises a plurality of light sensors 275, an evaluation unit 272, and a separately readable light sensor 276. the transmitter 26 and the receiver 27 form a first and second subscriber of a serial communication system. The serial data exchange between the evaluation unit 262 and the evaluation unit 272 is performed in this embodiment by means of a. By the light source 266 and the light sensor 276 formed optical data transmission channel, and an electrical return channel 32
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP1188096B1 | Cites | European Patent Office (EPO) | Applicant |
11 members in 3 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 102006054124 | Germany | – | |
| 102006054124 | Germany | A | |
| 07021351 | European Patent Office (EPO) | A |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| DE102006054124A1 | Germany | A1 | |
| EP1923759A2 | European Patent Office (EPO) | A2 | |
| EP1923759A3 | European Patent Office (EPO) | A3 | |
| US2008150713A1 | United States of America | A1 | |
| DE102006054124B4 | Germany | B4 | |
| EP2385433A2 | European Patent Office (EPO) | A2 | |
| EP2390735A2This record | European Patent Office (EPO) | A2 | |
| US8537726B2 | United States of America | B2 | |
| EP2385433A3 | European Patent Office (EPO) | A3 | |
| EP2390735A3 | European Patent Office (EPO) | A3 | |
| EP1923759B1 | European Patent Office (EPO) | B1 |
23 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| Request for examination filed17P | 17P | |
| Designated contracting states (corrected)RBV | RBV | |
| Designated contracting statesAK | AK | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Divisional application: reference to earlier applicationAC | AC | |
| Designated contracting statesAK | AK | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 2390735
- Application
- 110044773
Titles3
- German
- Verfahren und System zur sicheren Datenübertragung
- English
- Secure data transfer method and system
- French
- Procédé et système de transmission de données sécurisée
Classification
- CPC, 11
- H04L12/403
- H04L1/0061
- H04L1/16
- H04L43/00
- G05B19/0428
- G05B19/048
- G05B19/058
- G05B19/4185
- H04L1/1671
- H04L63/123
- Y02P90/02
- IPC, 7
- G05B19 042
- G05B19 048
- G05B19 05
- G05B19 418
- H04L1 14
- H04L12 06
- H04L12 403
Designated states32
- Contracting states, 32
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
- Monaco
- Malta
and 8 moreShow fewer
- Netherlands (Kingdom of the)
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye