EMULATED VOLTAGE-FREE SAFETY CONTACT
20240274378 ยท 2024-08-15
Assignee
Inventors
Cpc classification
B61L15/0009
PERFORMING OPERATIONS; TRANSPORTING
B61L15/0081
PERFORMING OPERATIONS; TRANSPORTING
B61L15/0072
PERFORMING OPERATIONS; TRANSPORTING
B61L15/0063
PERFORMING OPERATIONS; TRANSPORTING
B61L15/0036
PERFORMING OPERATIONS; TRANSPORTING
International classification
H01H47/00
ELECTRICITY
Abstract
The present invention concerns a safety contact for a safety line in a train, the safety contact comprising a controller and a safety switch circuit. wherein the controller comprises a sensor input for receiving signals indicating failure, wherein the safety contact comprises an input for a safety line input signal. which input is operably connected to the controller, whereby the controller is configured to receive a control signal representing a safety line state which is dependent on the safety line input signal received at the input, wherein the safety switch circuit comprises a set of at least one safety switch, the safety switch being positioned between a power supply and an output. wherein the controller is configured to: upon receiving a control signal indicating a working safety line state and a sensor input value representing no safety function failure. close said safety switch of the safety line circuit. thereby putting an output signal on the output. the output signal indicating a working safety line state. and upon receiving a control signal indicating a non-working safety line state or a sensor input value representing a safety function failure. open said safety switch of the safety line circuit. thereby essentially interrupting the safety line.
Claims
1. A safety contact for a safety line in a train, the safety contact comprising a controller and a safety switch circuit, wherein the controller comprises a sensor input for receiving signals indicating failure, wherein the safety contact comprises an input for a safety line input signal, wherein the input is operably connected to the controller, wherein the controller is configured to receive a control signal representing a safety line state which is dependent on the safety line input signal received at the input, wherein the safety switch circuit comprises at least one safety switch, the at least one safety switch being positioned between a power supply and an output, wherein the controller is configured to: in response to the control signal indicating a working safety line state and a first sensor input value representing no safety function failure, close said at least one safety switch of the safety switch circuit, thereby connecting the output of the safety switch circuit to the power supply, thus putting an output signal on the output, the output signal indicating the working safety line state, and in response to the control signal indicating a non-working safety line state or a second sensor input value representing a safety function failure, open said at least one safety switch of the safety switch circuit, thereby essentially interrupting the safety line.
2. The safety contact according to claim 1, further comprising a safety line state detector, wherein the safety line state detector comprises said input for the safety line input signal, and wherein the input is operably connected to the controller via the safety line state detector, wherein the safety line state detector comprises a control signal output, said safety line state detector being configured to provide the controller with the control signal via said control signal output representing the safety line state, the safety line state being dependent on the safety line input signal received at the input.
3. The safety contact according to claim 2, wherein the safety line state detector is comprised in the controller.
4. The safety contact according to claim 1, wherein the safety switch circuit comprises at least two safety switches in series between the power supply and the output, wherein each of the at least two safety switches is operably connected to the controller, and wherein closing said at least one safety switch of the safety switch circuit comprises closing each safety switch of the safety switch circuit, and opening said at least one safety switch of the safety switch circuit comprises opening each safety switch of the safety switch circuit.
5. The safety contact according to claim 1, wherein the safety switch circuit comprises a feedback logic circuit connected between the output of the safety switch circuit and the controller for providing the controller with a signal indicative of the output signal.
6. The safety contact according to claim 1, wherein the safety switch circuit comprises a current sensor between the power supply and the at least one safety switch, the current sensor being operably connected to the controller, wherein the controller is configured to interrupt the at least one safety switch in response to receiving a signal from the current sensor indicative of an over-current.
7. The safety contact according to claim 1, wherein the at least one safety switch does not have moving parts.
8. The safety contact according to claim 7, wherein the at least one safety switch comprises a MOSFET switch.
9. The safety contact according to claim 2, wherein the safety line state detector comprises: an inactive testing switch, which is positioned in series between the input of the safety line state detector and the control signal output, and is configured to disconnect the input from the control signal output if the inactive testing switch is opened, and/or an active testing switch, which is positioned between the power supply and the control signal output and is thus configured to provide a power input to the control signal output, independent of an input signal at the input.
10. The safety contact according to claim 9, comprising said inactive testing switch and said active testing switch, wherein the controller is configured to test the safety contact for failure during a testing phase, the controller hereby configured to: open the inactive testing switch and open the active testing switch, thereby checking that the control signal at the control signal output is indicative of an absence of the safety line input signal, and/or open the inactive testing switch and close the active testing switch, thereby essentially connecting the power supply to the control signal output, thereby checking if the safety line state detector is correctly informing the controller of an active safety line via output control signal.
11. The safety contact according to claim 2, wherein the safety line state detector comprises a logic level convertor positioned in series between the input and the control signal output, the logic level convertor being configured to transform a power supply voltage level to a controller voltage level.
12. The safety contact according to claim 2, wherein the safety line state detector comprises a leaking protection subcircuit between the input and other electronic components of the safety line state detector to protect the input from leaking test voltages out of the input.
13. The safety contact according to claim 2, wherein the safety contact comprises a logic safe-guard circuit configured to take as input the control signal from the safety line state detector and the control signal for the at least one safety switch coming from the controller, and to provide as output a safe-guarded switch control signal to the at least one safety switch, wherein the logic safe-guard circuit is configured to pass through the control signal from the controller only if the control signal from the safety line state detector indicates that the safety line is in a working state.
14. The safety contact according to claim 1, the safety contact being bidirectional.
15. The safety contact according to claim 2, the safety contact comprising the controller, wherein the safety line state is a first safety line state, and wherein the at least one safety switch is a first at least one safety switch, and wherein the output signal is a first output signal, and wherein the safety contact is bidirectional and wherein the safety line state detector is a left-to-right (L2R) safety line state detector and the safety switch circuit is a left-to-right (L2R) safety switch circuit and wherein the safety contact further comprises a right-to-left (R2L) safety line state detector and a right-to-left (R2L) safety switch circuit, wherein an input of the L2R safety line state detector is connected to an output of the R2L safety switch circuit and an output of the L2R safety switch circuit is connected to an input of the R2L safety line state detector, wherein the R2L safety line state detector is operably connected to the controller via an R2L control signal output, wherein the R2L safety line state detector is configured to provide the controller with an R2L control signal representing a second safety line state which is dependent on an R2L safety line input signal received at the input of the R2L safety line state detector, wherein the R2L safety switch circuit comprises a second at least one safety switch, the second at least one safety switch being positioned between the power supply and an R2L output, wherein the controller is further configured to, during a start-up phase, detect a process direction, and, based on the process direction: link the L2R safety line state detector and the L2R safety switch circuit within the safety line and disconnect the R2L safety line state detector and the R2L safety switch circuit from the safety line, or link the R2L safety line state detector and the R2L safety switch circuit within the safety line and disconnect the L2R safety line state detector and the L2R safety switch circuit from the safety line, thereby obtaining a linked safety line state detector and a linked safety switch circuit, and wherein the controller is further configured to: in response to the R2L control signal indicating the working safety line state and the first sensor input value representing no safety function failure, close the second at least one safety switch of the linked safety switch circuit, thereby connecting an output of the linked safety switch circuit to the power supply, thus putting a second output signal on the output of the linked safety switch circuit, the second output signal indicating the working safety line state, and in response to the R2L control signal indicating the non-working safety line state or the second sensor input value representing the safety function failure, open said second at least one safety switch of the linked safety switch circuit, thereby essentially interrupting the safety line.
16. The safety contact according to claim 2, wherein the safety switch circuit comprises at least two safety switches in series between the power supply and the output, wherein each of the at least two safety switches is operably connected to the controller, and wherein: closing said at least one safety switch of the safety switch circuit comprises closing each safety switch of the safety switch circuit, and opening said at least one safety switch of the safety switch circuit comprises opening each safety switch of the safety switch circuit.
17. The safety contact according to claim 3, wherein the safety switch circuit comprises at least two safety switches in series between the power supply and the output, wherein each of the at least two safety switches is operably connected to the controller, and wherein: closing said at least one safety switch of the safety switch circuit comprises closing each safety switch of the safety switch circuit, and opening said at least one safety switch of the safety switch circuit comprises opening each safety switch of the safety switch circuit.
18. The safety contact according to claim 2, wherein the safety switch circuit comprises a feedback logic circuit connected between the output of the safety switch circuit and the controller for providing the controller with a signal indicative of the output signal.
19. The safety contact according to claim 3, wherein the safety switch circuit comprises a feedback logic circuit connected between the output of the safety switch circuit and the controller for providing the controller with a signal indicative of the output signal.
20. The safety contact according to claim 4, wherein the safety switch circuit comprises a feedback logic circuit connected between the output of the safety switch circuit and the controller for providing the controller with a signal indicative of the output signal.
Description
OVERVIEW OF THE FIGURES
[0036]
[0037]
[0038]
[0039]
[0040]
[0041]
[0042]
[0043]
[0044]
DETAILED DESCRIPTION OF THE INVENTION
[0045] The invention will now be described in more detail, with reference to the figures.
[0046]
[0049] It should be noted that the safety line is typically used for checking the proper functioning of critical components of the train, i.e. typically components which are critical for ensuring safety of passengers or goods. As illustrated in
[0050] Note that, in general, it may not be known which carriage will serve as the active cab of the train. Moreover, a train may comprise a number of consists, each consist comprising a number of carriage. Typically the active cab will be a carriage at the end of a consist. Hence, preferably every carriage at the end of a consist is provided with a power supply (4), and with an alarm (5). Once the composition of the train is known, the active cab is known as well as the back carriage, i.e. the carriage at the opposite end of the active cab. Then, the alarm of the active cab and the power supply of the back carriage can be connected to the safety line.
[0051]
[0052]
[0055] Preferably the safety switch (17) is open unless actively closed by the control signal.
[0056] Because the output (19) of the safety switch circuit (13) is connected via the safety switch (17) to the power supply (18) in case of a working safety line state, there are no additive voltage drops when using many safety contacts in series on the safety line, i.e. the output signal for each safety contact in the safety line is typically the voltage provided by the power supply, with only a small voltage drop due to a single safety switch circuit (13) and therefore does not degrade with additional safety switches (6A-C) connected in series.
[0057] In an embodiment of the invention, as illustrated in
[0058] In an embodiment of the invention, the safety switch circuit (13) comprises a current sensor (20) between the power supply (18) and the safety switch (17), the current sensor (20) being operably connected (21) to the controller (11). Hereby, the controller (11) is configured to interrupt the safety switch (17) upon receiving a signal from the current sensor (21) indicative of an over-current. Preferably, the controller (11) is configured to interrupt the safety switch (17) if the signal from the current sensor (20) indicates that the current is larger than a pre-set current threshold. The presence of a current sensor (20) basically protects the one or more switches in the safety switch circuit against current surges.
[0059] The controller may preferably comprise a discrete logic circuitry, a programmable logic component, a field programmable gate array, a CPLD, a microcontroller and/or any combination thereof.
[0060] In an embodiment of the invention, the safety switch circuit (13) comprises a feedback logic circuit (22) connected between the output (19) of the safety switch circuit (13) and the controller (11) for providing the controller (11) with a signal indicative of the output signal. This feedback logic circuit (22) allows the controller (11) to check if the output signal corresponds with the state of the safety switch (17) controlled by the controller (11), i.e. if the controller has closed the safety switch, it can check via the feedback logic circuit that the output signal indeed corresponds to a closed safety switch, and thus to a working safety line state, while if the controller has opened the safety switch, it can check via the feedback logic circuit that the output signal indeed is zero, as it should be for an open safety switch. Hereby, if the controller (11) detects a discrepancy between the measured output signal and the expected output signal, the controller (11) is preferably configured to open the safety switch (17) and notify a central train controller of the occurrence of said discrepancy. As such, the controller (11) comprises a self-testing capability.
[0061] The operation of the safety contact is outlined in the flowchart of
[0062]
[0065] The presence of two safety switches (17, 42), and optionally even more than two safety switches in series, reduces the risk of a dangerously non functional safety switch through the failure of a safety contact. For instance, a single point of failure such as a short circuited switch, does not lead to a failing safety contact. In a particularly preferred embodiment, the safety switch circuits (17, 42) comprises a feedback logic circuit (22, 45) for each of the at least two safety switches, each feedback logic circuit (22, 45) operably connected to the controller (11), for providing the controller with a signal indicative of the signal on the safety line after each safety switch (17, 42). As such, the controller is allowed to, and preferably is configured to, check after each safety switch, if the signal on the safety line corresponds to the expected signal. Hereby, in case of failure of one of the safety switches, the controller is capable of identifying which safety switch is failing.
[0066]
[0069] The presence of two safety switches (17, 42), and optionally even more than two safety switches in series, reduces the risk of a dangerously non functional safety switch through the failure of a safety contact. For instance, a single point of failure such as a short circuited switch, does not lead to a failing safety contact. In a particularly preferred embodiment, the safety switch circuits (17, 42) comprises a feedback logic circuit (22, 45) for each of the at least two safety switches, each feedback logic circuit (22, 45) operably connected to the controller (11), for providing the controller with a signal indicative of the signal on the safety line after each safety switch (17, 42). As such, the controller is allowed to, and preferably is configured to, check after each safety switch, if the signal on the safety line corresponds to the expected signal. Hereby, in case of failure of one of the safety switches, the controller is capable of identifying which safety switch is failing.
[0070] The controller (11) may open and close the one or more safety switches (17, 42) by sending a switch control signal. The exact form of the switch control signal depends on the nature of the one or more safety switches. Preferably the one, two or more safety switches do not have moving parts, preferably the safety switches are solid state switches, more preferably electronic switches, still more preferably purely electronic switches, such as transistors, more preferably MOSFET switches and/or bipolar switches, more preferably MOSFET power switches, such as pMOS and/or nMOS power switches. Solid state switches are particularly preferred because they are vibration insensitive, which makes them possible to install and use on high-vibration train components such as bogies. Furthermore, purely electronic switches are preferred to switches such as the opto-electronic switches in document WO 2010/031570 A1, because purely electronic switches comprise lower impedance.
[0071] In a preferred embodiment of the invention, the safety line state detector (12) comprises self-testing capability. Preferably hereby, and with reference to the figures, the safety line state detector (12) comprises an active testing switch (47) and/or an inactive testing switch (46). Preferably the active testing switch (47) and/or the inactive testing switch (46) are electronic switches, such as transistors, more preferably MOSFET switches and/or bipolar switches, more preferably MOSFET power switches, such as pMOS and/or nMOS power switches. In a particularly preferred embodiment, the active testing switch (47) and/or the inactive testing switch (46) implemented in the same technology as the safety switches (14, 42). Thus preferably, the one, two or more safety switches, the active testing switch (47) and the inactive testing switch (46) are each an electronic switch, such as a transistor, more preferably a MOSFET switch or a bipolar switch, more preferably a MOSFET power switch, such as a pMOS or an nMOS power switch.
[0072] The inactive testing switch (46) is positioned in series between the input (15) of the emulator (12) and the control signal output (16) and is thus configured to disconnect the input (15) from the control signal output (16) if the inactive testing switch (46) is opened. The active testing switch (47) is positioned between the power supply (18) and the control signal output (16) and is thus configured to provide a power input to the control signal output (16), independent of the input signal at the input (15). The inactive testing switch (46) and/or active testing switch (47) allow testing of the input and input signal.
[0073] The inactive testing switch (46) and/or the active testing switch (47) are controlled by the controller (11). During an operational phase of the safety line (3), the inactive testing switch (46) is closed and the active testing switch is open (47), allowing to send a control signal on the basis of the safety line input signal to the controller (11). Preferably the controller (11) is configured to test the safety contact, and preferably the line state detector (12), for failure during a testing phase at certain moments, e.g. at start-up and/or on regular intervals. The controller (11) is hereby preferably configured to: [0074] open the inactive testing switch (46) and open the active testing switch (47), thereby checking that the control signal at the control signal output (16) is indicative of the absence of a safety line input signal. This allows the controller to check for leakages and/or short circuits in the system, resulting in an incorrect active output control signal (16). [0075] open the inactive testing switch (46) and close the active testing switch (47), thereby essentially connecting the power supply (18) to the control signal output (16), thereby essentially determining the control signal by the power supply. This allows the controller to check if the safety line state detector circuit is correctly informing the controller (11) of a active safety line via output control signal (16).
[0076] In a preferred embodiment, the safety line state detector (12) comprises a logic level convertor (48) positioned in series between the input (15) and the control signal output (16), and preferably between the active and/or inactive switches (46, 47) on the one side and the controller output (16) on the other side. The logic level convertor (48) is configured to transform a power supply voltage level to a controller voltage level.
[0077] In a preferred embodiment, the safety line state detector (12) comprises a leaking protection subcircuit (49) between the input (15) and other electronic components (46, 47, 48) of the safety line state detector (12) to protect the input (15) from leaking test voltages out of the input. Preferably, the leakage protection subcircuit (49) comprises a diode (50) positioned between the input (15) and the other electronic components of the safety line state detector (12).
[0078] In a preferred embodiment and with reference to
[0079] Preferably, in the case the safety switch circuit (13) comprises at least two safety switches (17, 42), as is shown in
[0080] In an embodiment, the safety contact is uni-directional as shown in
[0081] In an embodiment, a bidirectional safety contact may comprise two unidirectional safety contacts, one arranged for each direction. Hereby, the safety contacts may be implemented separated. The safety contacts may hereby also preferably comprise a unidirectional pass-through subcircuit at the input of the safety line state detector and/or at the output of the safety switch circuit, to ensure unidirectional flow.
[0082] However, the present invention also concerns a bidirectional safety contact (60) comprising a safety contact according to the present invention and as illustrated in
[0085] Linking a safety line state detector and a safety switch circuit in the safety line refers to configuring the controller to use this safety line state detector and this safety switch for any input and output signals concerned with driving the safety switches. Disconnecting a safety line state detector and a safety switch circuit from the safety line refers to configuring the controller to not use this safety line state detector and this safety switch for any input and output signals concerned with driving the safety switches. Disconnecting may preferably be achieved by opening at least one, and preferably each of the safety switches of the disconnected safety switch circuit, and/or by opening at least one, and preferably each of testing switches, such as the active testing switch and/or the inactive testing switch, of the disconnected safety line state detector. Alternatively or additionally, disconnecting may preferably be achieved by the controller being configured to ignore signals from the disconnected safety line state detector and/or the disconnected safety switch circuit.
[0086] The methodology for deciding upon the direction of flow, is illustrated in the flow chart of
[0087] It is understood that the terms left-to-right (L2R) and right-to-left (R2L) are used to distinguish between the two possible directions in which a safety line can be operated, and do not necessarily indicate the actual directions in space. The terms are merely coined this way in order to correspond to the directions in the figures for ease of explanation.
[0088] In a preferred embodiment, the controller comprises a field-programmable gate array (FPGA), a complex programmable logic device (CPLD), an application-specific integrated circuit (ASIC) and/or a processing unit, such as a central processing unit (CPU), most preferably the controller comprises or is implemented in a field-programmable array.
[0089] It is understood that the different embodiments described above with respect to more specific implementations of the invention, in particular related to the safety line state detector, the safety switch circuit, the logic safe-guard circuit, etc. can also be implemented in the bidirectional safety contact according to the present invention. For instance, the embodiment wherein the safety switch circuit comprises at least two safety switches in series in the safety line can be applied to the bidirectional safety contact whereby the LR2 safety switch circuit and/or the R2L safety switch circuit comprises at least two safety switches. Further,