System for secure control of machines, facilities or similar
Abstract
The invention relates to a system for secure control of plant, machinery or the like. The system comprises the following components: a controller (1), at least a connected terminal assembly (2A, 2B) and at least one of the terminal assembly (2A, 2B) connected to the sensor (4A) or actuator (4b). The terminal assembly (2A, 2B) is located within a local security zone, which is spatially remote from the controller (1), and monitors the sent status of the connected sensor / actuator, wherein when a safety-relevant status information of a signal to the controller (1) is that triggers a security requirement in the control. In this case, a communication failure between the terminal assembly (2A, 2B) and the controller (1) also triggers a safety requirement in the controller (1). In this case, in each case a manually operable local and a global acknowledgment means (6A, 6B) are present. The connector assembly (2A, 2B) also leads in the case of a communication fault with a status monitoring and stores the occurrence of a safety-related status information throughout the duration of the communication fault status as memory value. The controller (1) is replaced by a reconstruction of the communication status memory value of the terminal assembly (2A, 2B) and, after the reconstruction of the communication based on the state memory-more about a restart of the system.

Term
8.4 yearsto projected expiry
Projected expiry 6 March 2035, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
10 claims: 5 independent, 5 dependent
- c-de-0001System for safe control of plant, machinery or the like, - The system comprising the following components:▪ control (1), ▪ at least one via a communication link (3A, 3B) to the controller (1) connected to terminal assembly (2A, 2B) in the form of an input module or output module, ▪ at least one via a communication link (5A, 5B) connected to the connection module (2A, 2B) sensor (4A) or actuator (4B), - Wherein the connection assembly (2A, 2B) with the connected sensor (4A) or actuator (4B) is located within a local security zone, which is spatially remote from the controller (1), - Wherein the connection assembly (2A, 2B) the status of the connected sensor (4A) or actuator (4B) is monitored and at least one safety-relevant status information of a signal to the controller (1) sends, which triggers a safety requirement in the controller, - Wherein a disturbance in the communication between the line module (2A, 2B) and the controller (1) also triggers a safety requirement in the control (1), wherein a manually actuable local acknowledgment means (6A, 6B) is provided, which is arranged in the local security zone and with the connection module (2A, 2B) and / or the control (1), - - Wherein a manually operable global acknowledgment means (10) is present, which is designed as part of the controller (1) or arranged in the vicinity of the controller (1) and is connected to this, characterized in that - The connection module (2A, 2B) also in the event of communication failure the status of the connected sensor (4A) or actuator (4B) monitors, - The connection module (2A, 2B) stores the occurrence of a safety-related status information throughout the duration of the communication fault status as a memory value, - The controller (1) the status of memory value is replaced by a reconstruction of the communication as a signal of the terminal assembly (2A, 2B), - The controller (1) for the reconstruction of the communication based on the state-memory value determines whether a restart of the system a) is carried out only by a previous operation of the global Quittierungsmittels (10) without an operation of local Quittierungsmittels, or b) is carried out only by a previous actuation of at least the local Quittierungsmittels (6A, 6B).
- c-de-0006System according to one of the preceding claims, characterized in that the local acknowledgment means (6A, 6B) a switch or button is.
- c-de-0007System according to one of the preceding claims, characterized in that the global acknowledgment means (10) is a switch or pushbutton is.
- c-de-0008System according to one of claims 1 to 6, characterized in that global acknowledgment means (10) is an answerable via a man-machine interface query in a sequence program in the controller (1).
- c-de-0009System according to one of the preceding claims, characterized in that the terminal assembly (2A, 2B), an evaluation and storage unit (2A0, 2B0) having to evaluate and store a status memory value the status of the connected sensors (4A) or actuators (4B).
- c-de-0010Connection assembly (2A, 2B) for use in a system according to one of the preceding claims, characterized in that same an evaluation and storage unit (2A0, 2B0) having to evaluate and store a status memory value the status of the connected sensors (4A) or actuators (4B).
Independent claims6
29 paragraphs in 1 section, as filed
0001The invention relates to a system for control of equipment, machines or the like according to the preamble of claim 1.
0002In generic systems a safety requirement is triggered when, for example, an input module detects a safety-related status information of the connected sensor to it from the controller. The triggering of the safety requirement by controlling turn causes eg. The facility decommissioned, that is decommissioned. For safety reasons, a failure of communication between the input module and the controller then triggers a safety requirement in the control, since a failure of communication security status information of the sensor so can no longer be transmitted to the control.
0003An example of such a system is a system for controlling a robot system, the access to the robot system by a light barrier is monitored as a sensor. Here, the photoelectric sensor at the location of the robot system is connected to an input module, which in turn is connected via a communication link to the controller, which controls directly or indirectly the operation of the robot system. The input module and the photoelectric sensor are in a so-called local security zone, the working range of the robot system, arranged, while the controller is arranged spatially away. In many cases, the physical distance between the controller and the local security zone is relatively large, especially when it comes to control, for example. For a robotic line with a variety of robotic systems, so that control in another section of the building or even may be located in a different building than the local security zone. Now, if the controller had a safety requirement is triggered, it is because a person passes through the light barrier ( "actual fault") and a corresponding sensor-status signal is generated, or whether because the communication is disrupted between the input module and the controller is ( "certificate error"), causes this safety requirement that the robot system is decommissioned so that there is in the local security zone no or no further danger. For a subsequent restart of the system at least the manual operation of a local Quittierungsmittels (eg switch or button) in the local security zone for security reasons in advance required. This ensures that it is determined by visual inspection at the site of the local security zone if the security requirement triggering disorder actually no longer exists. Here, the local acknowledgment means is connected to the input module and / or the controller, so that the operation of Quittierungsmittels can be electronically transmitted either indirectly via the input module or directly to the controller. The sequence program in the controller then ensures that a restart of the system - in this case, the re-commissioning of the robotic system - takes place only if the local acknowledgment means has been operated. Optionally, it can be provided that it is necessary for a restart, in addition to actuate a so-called global acknowledgment means manually, which is formed as part of the controller or located in the vicinity of the controller, and connected thereto.
0004Because even in the event of a communication failure between the input module and the control a safety requirement is triggered, it is necessary for a restart of the system, to cover long walkways to the local security zone to operate the local acknowledgment means. This means that the re-opening is also connected in the case of "apparent failure" with a relatively high expense.
0005From the <patcit id="pcit0001" dnum="DE4331666C2"><text>DE 43 31 666 C2</text></patcit> is an arrangement for controlling devices such as motors etc. known having monitoring sensors responsive under critical operating conditions. Here, the arrangement of a braking system on which can set the device still, so this is no longer operational, the braking system is triggered when a monitoring sensor responds ( "actual fault") or when a fault on the lines of the monitoring sensor is present ( "certificate error"). According to<patcit id="pcit0002" dnum="DE4331666C2"><text>DE 43 31 666 C2</text></patcit> It is envisaged that the operator previously blocked the device can be put back into operation for a predetermined time period by actuation of a switch (Inaktivierungsschalter which causes inactivation of the blocking system). After the predetermined time period, the device on the braking system is then automatically taken back out of operation.
0006Object of the invention is to realize a re-commissioning of the generic system of a communication failure between the connection module and the controller in a simple, yet secure manner.
0007This object is achieved by the features of claim 1. The subsequent dependent claims relate to advantageous embodiments of the invention. Claim 10 relates to an inventively constructed terminal assembly.
0008According to the invention monitors the terminal assembly in the event of a communication failure between the terminal assembly and the control of the status of the connected sensor or actuator, wherein the connection module stores the occurrence of a safety-relevant status information for the duration of the communication fault as a status memory value. After a reconstruction of previously disturbed communication, control the status memory value as a signal of the terminal assembly. The controller decides according to the state memory value if a restart of the system<ol><li>a) is carried out only by a previous operation of the global Quittierungsmittels without an operation of local Quittierungsmittels, or</li><li>b) is carried out only by a previous actuation of at least the local Quittierungsmittels.</li></ol>
0009If the connection module has a security status information from the connected sensor or actuator detected or determined during the communication failure, the line module stores a status memory value. By reading this status memory point, the controller will be informed later about the fact that during the phase of the communication disorder in which the control was virtually blind to the status information of the sensor or actuator, at least once existed a security status information. In this case, the control allows the reconnection of the system only when the previously manually operable acknowledgment means has been operated in the local security zone.
0010However, if the connector assembly has no safety-relevant status information from the connected sensor or actuator detected or determined during the communication failure, the line module stores no state memory value, or in contrast to the case described above in accordance with different value. In this case, where no actual disturbance in the local security zone was present, allows control of the re-commissioning of the system without first local acknowledgment means must be operated in a complex manner. A manual operation of the global Quittierungsmittels, which is arranged on or at least near the central controller, but may be optionally provided also in this case.
0011With the inventive idea, an intelligent, automatic restart management is realized, whereby only an expensive manual operation of the local Quittierungsmittels is necessary if is assumed that in fact existed a disturbance in the local security zone. Local security zones are those areas to a system or machine around or to parts of the plant or parts of the machine around, in which at least one connection assembly is arranged with a sensor or actuator connected thereto, wherein a safety-relevant status information of this sensor or actuator is a safety-critical situation persons and / or for the plant / machine or parts thereof signaled in this area.
0012The invention is illustrated below with reference to exemplary embodiments and with reference to figures. In which:<dl id="dl0001"><dt>figure 1</dt><dd>a block diagram of the system according to the invention,</dd><dt>figure 2</dt><dd>a flowchart for a system correct execution,</dd><dt>figure 3</dt><dd>an application example of the inventive system,</dd></dl>
0013<figref idrefs="f0004">Fig. 4A</figref>/ B are timing diagrams for the sensor status and the status memory-value.
0014In <figref idrefs="f0001">figure 1</figref> is shown a block diagram of the system. To a central controller (1) via a communication link (3A), a first terminal assembly (2A) in the form of an input module (2A) is connected and via a further communication connection (3B), a second connection module (2B) in the form of an output module (2B) connected , The two communication links (3a, 3B) are preferably part of a fieldbus (eg Profibus, Profinet, Interbus or Industrial Ethernet). A sensor (4A) and to the output module (2B) is connected to the input module (2A), an actuator (4b). The connector (5A, 5B) between the sensors (4A) or actuators (4B) and the associated connection module (2A, 2B) can be implemented in various ways, for example via a two-wire line or via a fieldbus. At the sensors and actuators is part of the controlled systems or machines.
0015The terminal assemblies (2A, 2B) serve known to be substantially the treatment and / or conversion of the sensor or actuator signals for a data transmission via the communication link (3A, 3B) to the controller (1). The terminal assemblies (2A, 2B) monitor in particular the status of the connected sensor (4A) or actuator (4B), wherein in the presence of a safety-relevant status information from the terminal assembly (2A, 2B) is sent a signal to the controller (1) which then triggers in the control (1) a safety requirement, which in turn causes such as a decommissioning (decommissioning) of the controlled system or machine. Such safety requirement is, however, not only triggered if a safety-relevant status information on the sensor (4A) or actuator (4B) is applied, but also when a communication failure (eg disconnection) between a terminal assembly (2A, 2B) and the control is present (1). The terminal assemblies (2A, 2B) are each arranged in a local security zone, which is arranged spatially separated from the control system (1) with the sensor or actuator connected to it.
0016In the local security zone a manually operated local acknowledgment means (6A, 6B) is present in each case. To tell the actuation of Quittierungsmittels (6A, 6B) of the control (1), the acknowledgment means (6A, 6B) is connected in one variant directly to the controller (1) via lines (7A, 7B) or by radio. In an alternative variant the local Quittierungsmitte (6A, 6B) is connected to the connection module (2A, 2B), so that the information about the operation of the local Quittierungsmittels is forwarded via the connection module to the controller. In a further variant it is provided that the local acknowledgment means (6A, 6B) is connected to both the connector assembly (2A, 2B) as well as directly to the controller (1), so that the information about the operation of the local Quittierungsmittels control can reach both directly and indirectly through the terminal assembly.
0017In addition, a manually operable global acknowledgment means (10) is present, which is designed as part of the controller (1) or is arranged and is connected thereto in the vicinity of the controller (1). This acknowledgment means (10) is referred to as global as it is based on the system globally only once, while the local acknowledgment means (6A, 6B) in the - are arranged decentralized local security zones - usually duplicate. In this sense, the control (1) may be referred to as global (central) control.
0018For the realization of the inventive basic idea, it is irrelevant whether there is only a local security zone or if there are several local security zones or if there are several connection modules according to the invention in a local security zone. For the realization of the basic idea of the invention also there, if there is still an overriding major control in addition to the control of the invention is negligible.
0019The terminal assemblies (2A, 2B) now monitor in the event of a communication fault between the line module (2A, 2B) and the control (1) the status of the connected sensor (4A) or actuator (4B), said terminal assemblies, the occurrence of a safety-relevant status stores information as a status memory value for the duration of the communication fault. After a reconstruction of previously disturbed communication control (1) the status memory value as a signal of the terminal assembly (2A, 2B). It decides the control (1) based on the state-memory value if a restart of the system a) only by a previous operation of the global Quittierungsmittels (10) without an operation of local Quittierungsmittels (6A, 6B) is carried out, or b) only during a previous actuation of at least the local Quittierungsmittels (6A, 6B) is performed.
0020The terminal assembly according to the invention (2A, 2B) have an evaluation and storage unit (2A0, 2B0) to evaluate and store a status memory value the status of connected sensors and actuators. Here, the evaluation and storage unit as an integral unit be configured or designed as two separate units.
0021In order to ensure the evaluation of the sensor or actuator outputs are also in the case of a communication failure between the terminal assembly (2A, 2B) and the controller (1), means are provided which supply the terminal assembly in the event of a communication fault with voltage. These means may be a separate power connector for the connection module or integrated in the connection module battery.
0022The local and the global acknowledgment means (6A, 6B, 10) can be configured as switches or buttons. The global acknowledgment means (10) can also be configured as a via a man-machine interface (eg touch screen) answerable query in a sequence program in the controller (1).
0023The system proper sequence after triggering a safety requirement is in <figref idrefs="f0002">figure 2</figref> illustrated by a flow chart.
0024In <figref idrefs="f0003">figure 3</figref> illustrated application example of the inventive system. In the illustrated example a secure control of a filling system is effected by the inventive system. In this case, a container (8) via a pump (4B) is filled as an actuator with a hazardous liquid and the liquid from the reservoir (8) is automatically removed via a removal line (80) for further use. It filled via the pump (4B) and the extraction is regulated so that it is not actually a tank overflow (= failure). However, to prevent an overflow of the reservoir to make a level sensor (4A) is provided as overflow alarms. The pump (4B) to the system proper output module (2B) and the level sensor is (4A) to a system proper input module (2A) connected. Before it can come to an overflow, the level sensor (4A) generates a safety-relevant status information via the input module (2A) to the controller (1) is reported, which then triggers a safety requirement, which leads to switching off the pump (Figure 4B). In this case, a restart of the system, ie, in particular, a restart of the pump (4B) is only possible if previously the local reset button (6A) has been operated in the local security zone, there is always associated a visual inspection of the container and its filling level ,
0025a failure of communication between the input module (2A) and the control (1) a pump (4B) would, as mentioned above triggered deactivating safety requirement in the event. However, would in this case, the intelligent automatic restart management come into play, with only an expensive manual actuation of the local acknowledgment button (6A) is necessary if is assumed that in fact a disturbance in the local security zone, ie a overflow warning signal of the level sensor (4A) was present. By visual inspection before the local acknowledgment, the operator can determine if the level has fallen back to an uncritical level in the container.
0026Also monitoring of actuators (here the pump) is on safety-relevant status information (for example, overheating signal) during a failure of communication between the output module and the control of the connected output module - as in the case of the input module and the connected level sensor - useful and provided.
0027In <figref idrefs="f0004">4A</figref> is shown in the input module is a timing chart for the sensor status of equipment connected to an input module and the sensor for the status memory value. As long as the sensor status "TRUE" or logic "1" is or is at a high level, it is not a safety related status information. If the sensor status "FALSE" or logic "0" or has a low level, there is a safety-relevant status information that triggers a security requirement for an intact communication link between input module and control in the controller. As in<figref idrefs="f0004">4A</figref> can be seen, the sensor status changes during the communication failure of "TRUE" to "FAL SE" and then returns even back during the communication failure to "TRUE", so that the sensor status in the reconstruction of the communication of the value " TRUE "has. This, however, that the sensor status evaluated by the input module during the communication error and a corresponding state memory value is stored, control is informed that during the communication trouble at the sensor at least once existed a safety-relevant status information. If the state memory value adopted because of a security-related status information is "FALSE", this value is saved even when the sensor status has changed again towards "TRUE". Status memory value is only after a restart of the system to "TRUE" reset. In which, in<figref idrefs="f0004">4A</figref> Illustrated case, a restart of the system is possible only with prior local acknowledgment.
0028In <figref idrefs="f0004">4B</figref> shows the case where no security status information was present during a communication failure at the sensor. In this case, a restart of the system without a local acknowledgment is possible.
LIST OF REFERENCE NUMBERS
0029<dl id="dl0002" compact="compact"><dt>1</dt><dd>control</dd><dt>10</dt><dd>Global acknowledgment means at the controller</dd><dt>2A</dt><dd>input unit</dd><dt>2A0</dt><dd>Evaluation and storage unit in the input module</dd><dt>2 B</dt><dd>output unit</dd><dt>2B0</dt><dd>Evaluation and storage unit in the output module</dd><dt>3A</dt><dd>Communication link between input module and controller</dd><dt>3B</dt><dd>Communication link between the output module and control</dd><dt>4A</dt><dd>sensor</dd><dt>4B</dt><dd>actuator</dd><dt>5A</dt><dd>Terminal connection between the sensor and input module</dd><dt>5B</dt><dd>Terminal connection between the actuator and output module</dd><dt>6A + 6B</dt><dd>Local acknowledgment means in the local security zone</dd><dt>7A + 7B</dt><dd>Connections between the local and the control Quittierungsmitteln</dd><dt>8th</dt><dd>container</dd><dt>80</dt><dd>Extraction line in the container</dd></dl>
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| EP1396963A1 | Cites | European Patent Office (EPO) | A | Search report | 1-10 |
| US2004210620A1 | Cites | United States of America | A | Search report | 1-10 |
| US2004215354A1 | Cites | United States of America | I | Search report | 1-10 |
| DE4331666C2 | Cites | Germany | – | Applicant | – |
| US7369902B2 | Cites | United States of America | I | Search report | 1-10 |
3 members in 2 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 102014103135 | Germany | A | |
| 102014103135 | Germany | – | |
| 102014103135 | – | – | – |
| DE201410103135 | – | – | – |
Members3
| Document | Office | Kind | |
|---|---|---|---|
| DE102014103135B3 | Germany | B3 | |
| EP2919086A1This record | European Patent Office (EPO) | A1 | |
| EP2919086B1 | European Patent Office (EPO) | B1 |
79 legal events, as 10 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapse because of not paying annual feesLapsedMM01 | MM01 | AT | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Information on lapse in contracting state deletedLapsedPG2D | PG2D | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Invalidated european patentMG4D | MG4D | LT | |
| Patent invalid in the netherlands as no translation has been filedMP | MP | NL | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| De no longer designated stateR108 | R108 | DE | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE PATENT HAS BEEN GRANTEDSTAA | STAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: EXAMINATION IS IN PROGRESSSTAA | STAA | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 2919086
- Publication, DOCDB
- 2919086
- Publication, EPODOC
- EP2919086
- Application
- 151580222
- Application, DOCDB
- 15158022
- Application, EPODOC
- EP20150158022
Titles3
- German
- SYSTEM ZUR SICHEREN STEUERUNG VON MASCHINEN, ANLAGEN ODER DERGLEICHEN
- English
- SYSTEM FOR SECURE CONTROL OF MACHINES, FACILITIES OR SIMILAR
- French
- SYSTÈME DE COMMANDE FIABLE DE MACHINES, INSTALLATIONS OU SIMILAIRES
Classification
- CPC, 3
- G05B9/02
- G05B19/0428
- G05B2219/14037
- IPC, 2
- G05B23 02
- G05B19 05
Designated states2
- Contracting states, 1
- Türkiye
- Extension states, 1
- Montenegro