System for secure control of machines, facilities or similar
9 claims: 4 independent, 5 dependent
- 1System zur sicheren Steuerung von Anlagen, Maschinen oder dergleichen, - wobei das System folgende Komponenten aufweist:▪ eine Steuerung (1), ▪ mindestens eine über eine Kommunikationsverbindung (3A, 3B) an die Steuerung (1) angeschlossene Anschlussbaugruppe (2A, 2B) in Form einer Eingangsbaugruppe oder Ausgangsbaugruppe, ▪ mindestens einen über eine Kommunikationsverbindung (5A, 5B) an die Anschlussbaugruppe (2A, 2B) angeschlossenen Sensor (4A) oder Aktor (4B), - wobei die Anschlussbaugruppe (2A, 2B) mit dem angeschlossenen Sensor (4A) oder Aktor (4B) innerhalb einer lokalen Sicherheitszone angeordnet ist, die räumlich von der Steuerung (1) entfernt ist, - wobei die Anschlussbaugruppe (2A, 2B) den Status des angeschlossenen Sensors (4A) oder Aktors (4B) überwacht und bei mindestens einer sicherheitsrelevanten Statusinformation ein Signal an die Steuerung (1) sendet, welches in der Steuerung eine Sicherheitsanforderung auslöst, - wobei eine Störung der Kommunikation zwischen der Anschlussbaugruppe (2A, 2B) und der Steuerung (1) ebenfalls eine Sicherheitsanforderung in der Steuerung (1) auslöst, - die Anschlussbaugruppe (2A, 2B) auch im Falle einer Kommunikationsstörung den Status des angeschlossenen Sensors (4A) oder Aktors (4B) überwacht, - die Anschlussbaugruppe (2A, 2B) das Auftreten einer sicherheitsrelevanten Statusinformation während der Dauer der Kommunikationsstörung als Status-Memory-Wert speichert, - als Status-Memory-Wert ein erster Wert (FALSE, "0") abgespeichert wird, wenn während der Dauer der Kommunikationsstörung eine sicherheitsrelevante Statusinformation aufgetreten ist, - als Status-Memory-Wert ein zweiter, vom ersten verschiedener Wert (TRUE, "1") abgespeichert wird, wenn während der Dauer der Kommunikationsstörung keine sicherheitsrelevante Statusinformation aufgetreten ist, - die Steuerung (1) nach einem Wiederaufbau der Kommunikation den Status-Memory-Wert als Signal von der Anschlussbaugruppe (2A, 2B) erhält, dadurch gekennzeichnet, dass - ein manuell betätigbares lokales Quittierungsmittel (6A, 6B) vorhanden ist, welches in der lokalen Sicherheitszone angeordnet ist und mit der Anschlussbaugruppe (2A, 2B) und/oder der Steuerung (1) verbunden ist, - ein manuell betätigbares globales Quittierungsmittel (10) vorhanden ist, welches als Teil der Steuerung (1) ausgebildet ist oder in der Nähe der Steuerung (1) angeordnet und mit dieser verbunden ist, - die Steuerung (1) nach dem Wiederaufbau der Kommunikation anhand des Status-Memory-Wertes über die Art der Wiederinbetriebnahme entscheidet, wobei a) dann, wenn der Status-Memory-Wert den zweiten Wert (TRUE, "1") aufweist, eine Wiederinbetriebnahme nur durch eine vorhergehende Betätigung des globalen Quittierungsmittels (10) ohne eine Betätigung des lokalen Quittierungsmittels durchgeführt wird, b) dann, wenn der Status-Memory-Wert den ersten Wert (FALSE, "0") aufweist, eine Wiederinbetriebnahme nur durch eine vorhergehende Betätigung zumindest des lokalen Quittierungsmittels (6A, 6B) durchgeführt wird.
- 2System nach Anspruch 1, dadurch gekennzeichnet, dass das System Mittel aufweist, die die Anschlussbaugruppe (2A, 2B) permanent, auch im Falle einer Kommunikationsstörung, mit Spannung versorgt.
- 3System nach Anspruch 1 oder 2, dadurch gekennzeichnet, dass die Kommunikationsverbindung zwischen der Anschlussbaugruppe (2A, 2B) und der Steuerung (1) ein Feldbus ist.
- 4System nach Anspruch 3, dadurch gekennzeichnet, dass der Status-Memory-Wert in Form einer logischen "0" oder einer logischen "1" übertragen wird.
- 5System nach Anspruch 1 oder 2, dadurch gekennzeichnet, dass der der Status-Memory-Wert in Form eines analogen Minimalwerts oder Maximalwerts übertragen wird.
- 6System nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das lokale Quittierungsmittel (6A, 6B) ein Schalter oder Taster ist.
- 7System nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das globale Quittierungsmittel (10) ein Schalter oder Taster ist.
- 8System nach einem der Ansprüche 1 bis 6, dadurch gekennzeichnet, dass das globale Quittierungsmittel (10) eine über eine Mensch-Maschine-Schnittstelle beantwortbare Abfrage in einem Ablaufprogramm in der Steuerung (1) ist.
- 9System nach einem der vorstehenden Ansprüche, dadurch gekennzeichnet, dass die Anschlussbaugruppe (2A,2B) eine Auswerte- und Speichereinheit (2A0, 2B0) aufweist, um den Status der angeschlossenen Sensoren (4A) oder Aktoren (4B) auszuwerten und einen entsprechenden Status-Memory-Wert abzuspeichern.
Independent claims9
32 paragraphs in 1 section, as filed
0001The invention relates to a system for controlling systems, machines or the like according to the preamble of claim 1.
0002In generic systems, a safety request is triggered by the controller if, for example, an input module detects safety-relevant status information of the sensor connected to it. The triggering of the safety requirement by the controller, in turn, causes, for example, the plant to be shut down, ie taken out of service. For safety reasons, a fault in the communication between the input module and the controller now also triggers a safety request in the controller since, in the event of a communication error, safety-relevant status information of the sensor can no longer be transmitted to the controller.
0003An example of such a system is a system for controlling a robot system, wherein the access to the robot system is monitored by a light barrier as a sensor. In this case, the light barrier sensor is connected at the location of the robot system to an input module, which in turn is connected via a communication link to the controller, which controls the operation of the robot system directly or indirectly. The input module and the light barrier sensor are arranged in a so-called local safety zone, the working area of the robot system, while the control is arranged spatially away from it. In many cases, the spatial distance between the controller and the local security zone is relatively large, especially if it is a controller, for example. for a robot road with a variety of robotic systems, so that the controller can be located in another building section or even in a building other than the local security zone. If a safety request is triggered in the control system, either because a person steps through the light barrier ("actual fault") and generates a corresponding sensor status signal, or it is because the communication between the input module and the control unit is disturbed ( "Apparent fault"), this safety requirement causes the robot system to be taken out of operation so that there is no or no further danger in the local safety zone. For safety reasons, at least the manual actuation of a local acknowledgment means (eg switch or button) in the local safety zone is required for a subsequent restart of the system. This ensures that it is determined by inspection at the location of the local security zone whether the disturbance triggering the security request actually no longer exists. In this case, the local acknowledgment means is connected to the input module and / or the controller, so that the actuation of the acknowledgment means can be transmitted electronically either indirectly via the input module or directly to the controller. The sequence program in the controller then ensures that a re-commissioning of the system - in this case, the re-commissioning of the robot system - only takes place when the local acknowledgment was pressed. Optionally, it may be provided that it is necessary for a restart, in addition manually to operate a so-called global acknowledgment means, which is formed as part of the controller or disposed in the vicinity of the controller and connected thereto.
0004Since a safety request is triggered even in the event of a communication fault between the input module and the controller, it is necessary for a system restart to cover long paths to the local safety zone to actuate the local acknowledgment means. This means that the recommissioning is connected in the case of a "pseudo-disorder" with a relatively high cost.
0005From the <patcit id="pcit0001" dnum="DE4331666C2"><text>DE 43 31 666 C2</text></patcit> For example, an arrangement for controlling devices such as motors, etc., having monitoring sensors responsive to critical operating conditions is known. In this case, the arrangement has a blocking system, which can put the device down so that it is no longer ready, the blocking system is triggered when a monitoring sensor responds ("actual fault") or if there is a fault in the lines of the monitoring sensor ( "apparent failure"). According to<patcit id="pcit0002" dnum="DE4331666C2"><text>DE 43 31 666 C2</text></patcit> it is envisaged that the operator can the previously blocked device by the operation of a switch (inactivation switch, which causes an inactivation of the blocking system) can be put back into operation for a predetermined period of time. After the predetermined period of time, the device is then taken over the blocking system automatically out of service.
0006From the <patcit id="pcit0003" dnum="US20040215354A1"><text>US2004 / 0215354 A1</text></patcit> a system is known with a central control, to which two or more connection modules in the form of an input module or output module are connected via a communication link, in turn, sensors or actuators are connected to a respective terminal assembly.
0007The connection module receives safety-related status information. The connector assembly then sends a safety response to the controller upon request by the controller. In addition, the result of the security check is also stored in the connection board.
0008If the controller can not receive the "safety response" in the event of a communication fault between the connection module and the controller, it will be sent after the communication has been rebuilt (elimination / correction of the communication error). This is possible because it was saved.
0009The object of the invention is to realize a restart of the generic system after a communication failure between a terminal assembly and the controller in a simple yet secure manner.
0010This object is achieved by the features of claim 1. The subsequent dependent claims relate to advantageous embodiments of the invention.
0011According to the invention, the connection module also monitors the status of the connected sensor or actuator in the event of a communication fault between the connection module and the controller, wherein the connection module stores the occurrence of safety-relevant status information as a status memory value during the duration of the communication interference. After a reconstruction of the previously disturbed communication, the controller receives the status memory value as a signal from the connection module. The controller decides on the basis of the status memory value, whether a restart of the system<ol id="ol0001" compact="compact" ol-style=""><li>a) is performed only by a previous operation of the global acknowledgment means without an actuation of the local acknowledgment means, or</li><li>b) is carried out only by a previous operation of at least the local acknowledgment means.</li></ol>
0012If the connection module detects or ascertains safety-related status information from the connected sensor or actuator during the communication fault, the connection module saves a corresponding status memory value. By reading this status memory value, the controller is now subsequently informed that during the phase of the communication failure in which the controller was virtually blind to the status information of the sensor or actuator, at least once was a safety-related status information. In this case, the control does not allow the system to be restarted until the manually operable acknowledgment means in the local safety zone has been actuated beforehand.
0013If, however, the connection module has not detected or ascertained safety-relevant status information from the connected sensor or actuator during the communication disturbance, the connection module does not store a status memory value or a value that differs from the above case. In this case, where there was no actual fault in the local safety zone, the controller allows the system to be restarted without the need to manually operate the local acknowledgment means beforehand. However, manual actuation of the global acknowledgment means, which is arranged at or at least in the vicinity of the central control, can also optionally be provided in this case.
0014With the idea according to the invention, an intelligent, automatic recommissioning management is realized, whereby only a complex manual operation of the local acknowledgment means is necessary, although it is to be assumed that there was actually a disturbance in the local security zone. Local safety zones are such areas around a plant or machine around or around parts of the system or parts of the machine around, in which at least one connection assembly is arranged with a sensor or actuator connected thereto, a safety-related status information of this sensor or actuator is a safety-critical situation Persons and / or for the plant / machine or parts thereof in this area.
0015The invention is explained below with reference to exemplary embodiments and with reference to figures. Showing:<dl id="dl0001"><dt>FIG. 1</dt><dd>a block diagram of the system according to the invention,</dd><dt>FIG. 2</dt><dd>a flowchart for a systemic process,</dd><dt>FIG. 3</dt><dd>an application example of the system according to the invention,</dd></dl>
0016<figref idref="f0004">Fig. 4A</figref>/ B Time charts for the sensor status and the status memory value.
0017In <figref idref="f0001">FIG. 1</figref> a block diagram of the system is shown. A first connection module (2A) in the form of an input module (2A) is connected to a central controller (1) via a communication link (3A) and a second connection module (2B) in the form of an output module (2B) is connected via a further communication link (3B) , The two communication links (3a, 3b) are preferably part of a fieldbus (eg Profibus, Profinet, Interbus or Industrial Ethernet). In this case, a sensor (4A) is connected to the input module (2A) and an actuator (4B) is connected to the output module (2B). The connection (5A, 5B) between the sensors (4A) or actuators (4B) and the associated connection assembly (2A, 2B) can be realized in various ways, for example via a two-wire cable or via a fieldbus. The sensors and actuators are parts of the systems or machines to be controlled.
0018As is known, the connection assemblies (2A, 2B) essentially serve to process and / or convert the sensor or actuator signals for data transmission via the communication connection (3A, 3B) to the controller (1). In particular, the connection assemblies (2A, 2B) also monitor the status of the connected sensor (4A) or actuator (4B), wherein in the presence of a security-relevant status informationn from the terminal assembly (2A, 2B) a signal to the controller (1) is sent, which then triggers a safety request in the controller (1), which in turn causes a shutdown (decommissioning) of the system or machine to be controlled. However, such a security request is triggered not only when a safety-related status information is applied to the sensor (4A) or actuator (4B), but also if a communication (eg disconnection) between a terminal assembly (2A, 2B) and the Control (1) is present. The connection assemblies (2A, 2B) with the sensor or actuator connected thereto are each arranged in a local safety zone, which is spatially arranged by the controller (1).
0019In each of the local security zones there is a manually operable local acknowledgment means (6A, 6B). In order to communicate the actuation of the acknowledgment means (6A, 6B) to the controller (1), the acknowledgment means (6A, 6B) is connected in a variant directly to the controller (1) via lines (7A, 7B) or by radio. In an alternative variant, the local acknowledgment center (6A, 6B) is connected to the connection module (2A, 2B) so that the information about the actuation of the local acknowledgment device is forwarded to the controller via the connection module. In a further variant, it is provided that the local acknowledgment means (6A, 6B) is connected both to the terminal assembly (2A, 2B) and directly to the controller (1),
0020In addition, a manually operable global acknowledgment means (10) is provided, which is formed as part of the controller (1) or in the vicinity of the controller (1) is arranged and connected thereto. This acknowledgment means (10) is referred to as global, since it is globally present only once with respect to the system, while the local acknowledgment means (6A, 6B) are arranged in the - usually multiple existing - decentralized local security zones. In this sense, the controller (1) may also be referred to as global (central) controller.
0021For the realization of the basic idea according to the invention, it is irrelevant whether there is only one local security zone or whether there are several local security zones or whether there are several connection modules according to the invention in a local security zone. For the realization of the basic idea according to the invention is also irrelevant, if there is in addition to the control according to the invention still has a superordinate large-scale control.
0022The connection modules (2A, 2B) now also monitor the status of the connected sensor (4A) or actuator (4B) in the event of a communication fault between the connection module (2A, 2B) and the controller (1), the connection modules indicating the occurrence of a safety-related Status information during the duration of the communication failure stores as a status memory value. After rebuilding the previously disturbed communication, the controller (1) receives the status memory value as a signal from the terminal board (2A, 2B). The controller (1) decides on the basis of the status memory value whether a restart of the system a) is carried out only by a previous actuation of the global acknowledgment means (10) without an actuation of the local acknowledgment means (6A, 6B),
0023The terminal assemblies (2A, 2B) according to the invention have an evaluation and memory unit (2A0, 2B0) in order to evaluate the status of the connected sensors or actuators and to store a corresponding status memory value. In this case, the evaluation and storage unit may be formed as an integral unit or be formed as two separate units.
0024In order to ensure the evaluation of the sensor or actuator outputs even in the event of a communication fault between the terminal assembly (2A, 2B) and the controller (1), means are provided which supply the terminal assembly in the event of a communication failure with voltage. These means may be a separate power connection for the terminal assembly or a battery integrated in the terminal assembly.
0025The local and the global acknowledgment means (6A, 6B, 10) can be designed as switches or pushbuttons. The global acknowledgment means (10) can also be configured as a request that can be answered via a man-machine interface (eg touch screen) in a sequence program in the controller (1).
0026The systemic procedure after the triggering of a security request is in <figref idref="f0002">FIG. 2</figref> illustrated by a flow chart.
0027In <figref idref="f0003">FIG. 3</figref> is shown application example of the system according to the invention. In the example shown, a secure control of a filling system is effected by the system according to the invention. In this case, a container (8) via a pump (4B) is filled as an actuator with a dangerous liquid and the liquid from the reservoir (8) via a withdrawal line (80) is automatically removed for further use. In this case, filling via the pump (4B) and the removal is regulated so that there is actually no overflowing of the container (= failure). However, in order to surely prevent overflow of the container, a level sensor (4A) is provided as an overflow alarm. In this case, the pump (4B) is connected to the system-appropriate output module (2B) and the level sensor (4A) to a system-based input module (2A). Before it can overflow, the level sensor (4A) generates safety-related status information, which is reported via the input module (2A) to the controller (1), which then triggers a safety request that causes the pump (4B) to shut down. In the present case, a restart of the system, ie in particular a restart of the pump (4B) only possible if previously the local Acknowledge button (6A) has been operated in the local safety zone, as always a visual inspection of the container and its level is connected , which leads to switching off the pump (4B). In the present case, a restart of the system, ie in particular a restart of the pump (4B) only possible if previously the local Acknowledge button (6A) has been operated in the local safety zone, as always a visual inspection of the container and its level is connected , which leads to switching off the pump (4B). In the present case, a restart of the system, ie in particular a restart of the pump (4B) only possible if previously the local Acknowledge button (6A) has been operated in the local safety zone, as always a visual inspection of the container and its level is connected ,
0028As mentioned above, even in the event of a communication failure between the input module (2A) and the controller (1), a safety request switching off the pump (4B) would be triggered. However, in this case, the intelligent, automatic recommissioning management would come to fruition, whereby only a complex manual operation of the local acknowledgment button (6A) is necessary, although it can be assumed that actually a fault in the local security zone, ie Overflow warning signal of the level sensor (4A) was present. By inspecting before local acknowledgment, the operator can determine if the level in the container has returned to an uncritical level.
0029Monitoring of actuators (in this case the pump) for safety-relevant status information (for example overheating signal) during a communication failure between the output module and the control by the connected output module is useful and provided, as in the case of the input module and the connected level sensor.
0030In <figref idref="f0004">FIG. 4A</figref> is a timing chart showing the sensor status of a sensor connected to an input module and the status memory value in the input module. As long as the sensor status is "TRUE" or logic "1" or has a high level, this is not a safety-related status information. If the sensor status is "FALSE" or logic "0" or has a low level, safety-related status information exists which triggers a safety request if the communication between the input module and the controller in the controller is intact. As in<figref idref="f0004">FIG. 4A</figref> can be detected, the sensor status changes from "TRUE" to "FALSE" during the communication fault and then returns to "TRUE" during the communication fault, so that the sensor status during the communication reconstruction becomes "TRUE". Has. Due to the fact that the sensor status is also evaluated by the input module during the communication fault and a corresponding status memory value is stored, the controller is informed that security-relevant status information was present at least once during the communication fault on the sensor. If the status memory value has assumed the value "FALSE" due to safety-relevant status information, this value remains stored even if the sensor status returns to "<figref idref="f0004">FIG. 4A</figref> In the case shown, a restart of the system is possible only with prior local acknowledgment.
0031In <figref idref="f0004">FIG. 4B</figref> the case is shown where, during a communication disturbance, no safety-relevant status information was present at the sensor. In this case it is possible to restart the system without local acknowledgment.
LIST OF REFERENCE NUMBERS
0032<dl id="dl0002" compact="compact"><dt>1</dt><dd>control</dd><dt>10</dt><dd>Global acknowledgment at the control</dd><dt>2A</dt><dd>input unit</dd><dt>2A0</dt><dd>Evaluation and memory unit in the input module</dd><dt>2 B</dt><dd>output unit</dd><dt>2B0</dt><dd>Evaluation and memory unit in the output module</dd><dt>3A</dt><dd>Communication connection between input module and controller</dd><dt>3B</dt><dd>Communication connection between output module and controller</dd><dt>4A</dt><dd>sensor</dd><dt>4B</dt><dd>actuator</dd><dt>5A</dt><dd>Connection between sensor and input module</dd><dt>5B</dt><dd>Connection between actuator and output module</dd><dt>6A and 6B</dt><dd>Local funds in the local security zones</dd><dt>7A + 7B</dt><dd>Connections between the local acknowledgment means and the controller</dd><dt>8th</dt><dd>container</dd><dt>80</dt><dd>Extraction line in the tank</dd></dl>
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP1396963A1 | Cites | European Patent Office (EPO) | – |
| US2004210620A1 | Cites | United States of America | – |
| US2004215354A1 | Cites | United States of America | – |
| US7369902B2 | Cites | United States of America | – |
| None | Non-patent | – | Examiner |
3 members in 2 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 102014103135 | Germany | A | |
| 102014103135 | Germany | – | |
| DE201410103135 | – | – | – |
| 102014103135 | – | – | – |
Members3
| Document | Office | Kind | |
|---|---|---|---|
| DE102014103135B3 | Germany | B3 | |
| EP2919086A1 | European Patent Office (EPO) | A1 | |
| EP2919086B1This record | European Patent Office (EPO) | B1 |
79 legal events, as 10 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapse because of not paying annual feesLapsedMM01 | MM01 | AT | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Information on lapse in contracting state deletedLapsedPG2D | PG2D | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Invalidated european patentMG4D | MG4D | LT | |
| Patent invalid in the netherlands as no translation has been filedMP | MP | NL | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| De no longer designated stateR108 | R108 | DE | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE PATENT HAS BEEN GRANTEDSTAA | STAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: EXAMINATION IS IN PROGRESSSTAA | STAA | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 2919086
- Publication, DOCDB
- 2919086
- Publication, EPODOC
- EP2919086
- Application
- 15158022
- Application, DOCDB
- 15158022
- Application, EPODOC
- EP20150158022
Titles3
- German
- SYSTEM ZUR SICHEREN STEUERUNG VON MASCHINEN, ANLAGEN ODER DERGLEICHEN
- English
- SYSTEM FOR SECURE CONTROL OF MACHINES, FACILITIES OR SIMILAR
- French
- SYSTÈME DE COMMANDE FIABLE DE MACHINES, INSTALLATIONS OU SIMILAIRES
Classification
- CPC, 3
- G05B9/02
- G05B19/0428
- G05B2219/14037
- IPC, 2
- G05B23 02
- G05B19 05
Designated states37
- Contracting states, 37
- Albania
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
- Monaco
and 13 moreShow fewer
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Serbia
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye
