The present invention relates to autoclaves, and in particular to control systems for autoclaves.
Autoclaves are used in a large number of applications, and in many of these it is important to ensure that the autoclave is operating correctly. For example, in medical applications it is essential that, for example, surgical devices and dental tools are properly sterilized. Various methods of testing the operation of an autoclave are known, but these generally comprise running test cycles which are separate from any normal operational cycles. This takes up time preventing use of the autoclave, and also does not check every operational cycle, so the autoclave may run a number of cycles before any fault is detected. There is therefore an ongoing need to improve the reliability of autoclaves.
Accordingly the present invention provides an autoclave comprising an enclosure defining a chamber, steam supply means arranged to supply steam to the chamber, a control system arranged to control operation of the autoclave, wherein the control system comprises control means and monitoring means, the control means and monitoring means each being arranged to define a respective set of conditions required for a change of state of the autoclave, and the control system is arranged to allow the change of state only if both sets of conditions have been met.
The change of state may be to a ‘passed’ state indicating that a sterilization cycle of the autoclave has been correctly completed. The control means may include an arbiter arranged to receive inputs from each of the first and second controllers and to allow the autoclave to move to the ‘passed’ state only if both controllers have determined that their respective set of conditions has been met.
The control means and the monitoring means may each be arranged to monitor at least one parameter, and to determine therefrom whether its respective conditions have been met. For example the at least one parameter may be one or more of temperature, pressure and time. For example they may monitor temperature or pressure of the chamber (or some other part of the system), or both, as a function of time, or they may measure temperature or pressure, or both, at predetermined times.
The present invention further provides an autoclave comprising an enclosure defining a chamber, steam supply means arranged to supply steam to the chamber, a temperature sensor arranged to produce a signal that varies with the temperature in the chamber, a pressure sensor arranged to produce a signal that varies with the pressure in the chamber and control means arranged to receive the signals from the temperature sensor and the pressure sensor, to determine whether the relationship between the two signals meets a predetermined condition, and produce an error output if the condition is not met.
Preferred embodiments of the present invention will now be described by way of example only with reference to the accompanying drawings in which:
a is a diagram of an arbiter forming part of the control system of the autoclave of
Referring to
A feed water tank 24 provides a source of water and is connected to the chamber 12 by a water feed pipe 26. A feed water valve 28 is arranged to control the flow of water from the feed water tank 24 to an inlet 30 in the boiler 20. A steam outlet 32 in the top of the chamber 12 is connected via an outlet pipe 34 to the inlet 36 of a condenser 38. A chamber vent valve 40 is arranged to control the flow of steam through the vent pipe 34 to the condenser 38. A boiler drain pipe 42 connects the bottom of the boiler 20 to the inlet 36 of the condenser 38 to enable the boiler 20 to be drained if required, under control of a drain valve 43 in the drain pipe 42. The outlet 44 of the condenser 38 is connected via a return pipe 46 to the feed water tank 24. A pump 48 is provided in the return pipe 46 to pump condensed water from the condenser 38 back to the feed water tank 24. A waste water tank 50 is also connected to the return pipe 46 to collect condensed water that is not returned to the water feed tank 24. In other embodiments this waste water tank 50 can be omitted and the water returned to the feed water tank 24.
The chamber 12 has an air inlet 52 which is connected to atmosphere via an air filter 54 and an air inlet valve 56, which is arranged to control the inlet of air to the chamber 12. The chamber 12 also has a safety air outlet 58 that vents to atmosphere via a safety valve 60, which is arranged to open if the pressure in the chamber 12 exceeds a predetermined level. An electric heater in the form of a band heater 62 is provided to heat the chamber 12.
Referring now also to
A first temperature sensor 112 produces an output signal C_CHT indicative of the temperature in the chamber, which is input to the controller 100, together with further signals indicative of the band heater temperature and boiler temperature. A door closure sensor 114 produces a signal C_DRS indicative of whether the door 14 is open or closed, and that is also input to the controller 100. A first door lock sensor 116 produces a signal C_DLS indicative of the state of the first door lock (or control door lock) 16, which is input to the protective system 102. A second door lock sensor 118 produces a signal P_DLS indicative of the state of the second door lock (or protective door lock) 18, which is input to the controller 100. A second chamber temperature sensor 120 produces an output signal P_CHT indicative of the temperature in the chamber, which is input to the protective system 100. A chamber pressure sensor 122 produces an output signal P_CHP indicative of the pressure in the chamber, which is input to the protective system 100. An independent second chamber pressure sensor 124 in the form of a pressure switch is arranged to cut the drive signal to the door lock actuator for the first door lock 16 if the chamber pressure exceeds a predetermined maximum. This additional safety feature ensures that the chamber door cannot be opened if the chamber pressure is above this maximum safe pressure. Water level sensors 126, 128, 130 in the feed water tank 24, waste water tank 50 and boiler 20 respectively are arranged to produce signals C_FWL, C_WWL and C_BWL that are indicative of the water level in the feed water tank 24, waste water tank 50 and boiler 20 respectively. Those signals are input to the controller 100. A ‘covers on’ service port 132 provides test and diagnostic accesses for service technicians to the controller 100. An internal and production test port 134 provides access to the controller 100 and protective system 102 for production and test purposes.
The controller 100 provides door lock control signals to a power driver 136 for the solenoid of the first door lock 16 to control locking and unlocking of the first door lock, a power driver 138 for the system's valves which can open and close them, and a power driver 140 for the system's heaters and pumps to turn them on and off. The protective system 102 provides control signals to a power driver 142 for the solenoid of the second door lock 18 to control locking and unlocking of the second door lock, and to a safety cut-out relay (SAF) 144 which can cut the power to the power driver 140 in the event of a fault. The protective system 102 provides an output to a printer/traceability interface 146. This enables it to output a record of the operation of the autoclave.
Power is provided to the autoclave from a mains power connector 148, via an EMC filter, switch and fuses, collectively indicated as 150, which provide mains AC power to the power driver 140 via the safety cut-out relay, and to the power drivers 136, 138, 142 for the valves and door locks via a low voltage power supply unit 152.
The autoclave also includes a graphical user interface (GUI) 154. This includes a processor, real time clock, display and LEDs to provide visual feedback to a user, buttons to provide a user input, and a speaker to provide audible feedback to the user. Both the controller 100 and protective system 102 can receive inputs from the GUI 154, and the controller 100, and to a lesser extent the protective system, can produce outputs to the GUI to produce feedback to the user in the form of information and prompts to prompt the user to carry out certain operations. The GUI 154 also includes a fail-safe arbiter 156, which is arranged to indicate to a user when a sterilization cycle has been performed correctly, i.e. when the cycle has passed, based on signals from the controller 100 and protective system 102. The GUI includes an indicator LED 158 arranged to be lit when a cycle has passed.
As shown in
The door locking system, which is included in
Referring to
The software of the protective system 102 is written in an object-oriented manner so as to provide code segregation to improve comprehension and analysis, and to permit predictable behaviour after rework. Referring to
During operation of the autoclave the controller 100 and the protective system 102 each move between various control states. They also communicate with each other over a serial link so that each can determine the current state of the other and the states that they are in can be coordinated. They also communicate to each other over the serial link the measurements and readings that they receive from the various sensors, and the results of all tests and checks that they carry out during operation of the autoclave. This enables each of them to check whether various conditions are met to enable them to change state, or to cause them to change state, or to enable them, or cause them, to remain in their current state. In general the states of the controller 100 and protective system 102 are coordinated so that they are both in the same state, and therefore the state that they are both in can be considered as the state of the autoclave as a whole. Therefore the state of the autoclave as a whole can, in many cases, only change from one of the states to another if both the controller 100 and the protective system 102 agree on the new state. If they are in different states, then this may be transitory, or it may be indicative of a fault. Generally at transitions from one state to another each of the CO 100 and PR 102 checks that its conditions for the transitions have been met, then enters the new state, and then checks that the other has entered the new state. Only then do they both determine that the system as a whole has entered the new state and continue with the operations appropriate to that state.
The main states of the autoclave will now be described with reference to
In each state the CO 102 and PR 100 perform a number of operations and generally it is a requirement that certain functions must be performed and certain checks made before that state can be entered. Also while this clearly applies to the states of
During the sterilizing cycle the boiler heater 22 is turned on and steam begins to flow slowly increasing the temperature of the chamber 12. Once a significant amount of steam begins to enter and condense in the condenser 38, the back-pressure generated by this increases the chamber pressure up to an equilibrium level. Chamber temperature then continues to increase as the proportion of steam in the chamber mix increases towards saturation. When the chamber reaches saturation it equilibrates at the pressure caused by the flow through the condenser and the associated saturated steam temperature. The temperature and pressure in the chamber therefore level off. At this point further heating does not affect the temperature or pressure within the chamber 12. Then eventually the cycle moves into a phase of increasing pressure, and the temperature and pressure increase in proportion based on the relationship determined by steam saturation. The cycle includes a pre-conditioning phase in which the temperature and pressure are increased and decreased in a controlled manner in order to ensure that steam reaches all parts of the equipment to be sterilised. It then enters a sterilisation phase in which the temperature and pressure are held constant at a plateau for a predetermined hold time. The final phase of the cycle is a post conditioning phase during which cooling and drying are carried out. The controller 100 has the temperatures, pressures and timings that are required through the cycle programmed into it and controls the various components of the system to ensure that the cycle is followed. The controller 100 and protective system 102 both check various parameters of the cycle, which may be the same parameters for them both or may be different, to check whether the cycle has been successfully completed or not. These parameters include the temperature and pressure of the chamber and the times at which they are reached and the times for which they are maintained. More specifically these checks are carried out at predetermined times or waypoints in the cycle. Each of the controller 100 and protective system 102 determine when these times occur using their respective clocks. They then each check the chamber temperature using their respective temperature sensors 112, 120, the protective system 102 checks the chamber pressure using the pressure sensor 122, and communicates the measured pressure to the controller 100. The controller 100 checks that the relationship between the measured pressure and measured temperature meets predetermined criteria, as expected under saturated steam conditions. Provided all of these measurements are in agreement then the waypoint is deemed to have been reached. If any of the waypoints is not reached, i.e. the temperature and pressure are not confirmed as correct by the controller 100 and the protective system 102, then the cycle is deemed to have failed and the system enters the fail state.
Referring to
If at step 714 the CO 100 and PR 102 determine that the door is open, the system proceeds to step 718 where the CO 100 unlocks the first door lock 16 and the PR 102 unlocks the second door lock 18. When the appropriate control signals have been sent to the drivers for the door lock actuators to cause this to happen, the CO 100 and PR 102 check at step 720 that the locks are indeed both locked from the P_DLS and C_DLS signals, and provided they are, the system proceeds to step 722 where it checks for any unacknowledged failed cycle signals. The reason for this is as follows. Where the system has entered the fail state, normally a user has to input an acknowledgment signal via the GUI 154 before the system can leave the fail state. However, if the system has been switched off when in the fail state, an unacknowledged failed cycle indicator may still be recorded in memory. If such an indicator is detected, the system will return to the fail state until an appropriate acknowledgement is input by the user. This prevents access to a non-sterile load without the proper acknowledgement.
From step 722, if no unacknowledged failed cycles are detected, then the system proceeds to step 724 where the CO and PR both check that the band heater temperature is below a safe threshold, in this case 55° C. Both the PR & CO detect this from their sensor signals. If it is, then the system proceeds to step 726 where the CO takes the appropriate steps to relieve any vacuum or pressure in the chamber and allow the temperature in the chamber to reach a safe and appropriate temperature, and to maintain a suitable water level in the boiler. In this case the band heater and boiler heater are turned off, the water supply valve 28 is closed, the drain valve 43 is opened, and the air inlet valve 56 is opened. The system then proceeds to step 728 where the CO and PR check the temperature of the chamber using the signals from the respective temperature sensors 112, 120, and then check with each other that the two temperature sensors agree and both indicate the same chamber temperature. Provided that they do, the system proceeds to step 730 where the CO and PR each unlock their respective door locks 16, 18 and then each check from the signals from the door lock sensors 116118 that the door locks have indeed been unlocked. Provided they have, the test is completed, and the CO and PR both enter the idle state.
Referring to
Referring to
During the rest of the cycle, indicated as step 920 the CO 100 and PR 102 both continue to monitor the measurable cycle parameters, in this case temperature and pressure reached at each stage, and the length of time taken to reach each stage, and the length of time for which each stage is maintained, to check that they meet predetermined conditions. Each of the CO 100 and PR 102 independently determines whether the conditions have been met and therefore whether the cycle has been passed or failed, and indicates this by means of an arbiter signal to the arbiter 156 at step 922. The arbiter monitors the arbiter signals from both the CO and the PR and if they both indicate that the cycle has been passed, it determines that the cycle has indeed been passed and indicates this to the user via the GUI as described above. If either the CO or the PR determines that the cycle has not been passed, then one of the required signals will not be sent to the arbiter and the arbiter will not indicate a pass via the indicator LED 158.
During operation of the autoclave as described above, if any of the checks does not result in the expected outcome as required for a successful cycle, then the system goes to the fail state. For example if the CO and the PR do not agree, or at least do not agree within a predetermined time limit, on the state in which the system should be, or if they do not agree on the measurements of any of the measurable parameters of the systems operation, then the system enters the fail state. As indicated in
A further check carried out during operation of the system is for a service connection having been made to the system, as indicated by the presence of an ‘active service’ flag. If a service connection is detected, then the system enters the ‘service’ state and waits for the service technician to input the appropriate authorization code to clear the active service flag.
Referring back to
The sequencing for the process executive has several phases. Close co-operation will normally take place between the PR 102 and the CO 100 as described above. Each will maintain a copy of the state that the other is in, which is communicated to it by means of the inter-processor link. The basic idea is that each independently determines whether a change of state should take place, but will not proceed unless both agree.
Whenever there is disagreement, the nature of the disagreement is recorded in memory in the fault log of the PR 102. During a sterilizing cycle, the PR 102 is arranged to announce any faults to the user by recording a suitable announcement in the cycle log data sent to the traceability system, and to announce a fault to the arbiter 156 on the GUI 154. The CO 100 is also arranged to record the nature of the disagreement in its fault log, and announce such faults to the user via the GUI 156. In addition, the PR 102 is arranged to maintain in an area of memory set aside for the purpose, an unacknowledged failed cycle error code. This code is cleared to “No Fault” on correct acknowledgement by the user via the GUI 156. In the event of a fault causing either CO 100 or PR 102 to move to a state without agreement, the other will then be able to detect the fault and take the necessary action to safeguard the system. Within the PR 102 there are mainly autonomous objects as shown in
It will be appreciated that the embodiments described above monitor their operation during each sterilizing cycle that they perform, and can determine whether they have performed the sterilizing cycle correctly or not, and indicate this to a user. Furthermore, because the controller 100 and protective system 102 both check performance of the cycle, and confirm passing to the arbiter which then determines whether both have determined that the cycle has been passed before indicating to a user that it has been passed, the chances of the arbiter indicating that the cycle has been passed when it has not are exceedingly small. It is therefore expected that the autoclaves described above could operate on a system of parametric release, in which the autoclave system itself checks the parameters of the cycle it has performed and makes the final decision as to whether the cycle has been passed or failed, and no further system checks are required.
It will be appreciated that many modifications can be made to the embodiment described whilst still falling within the scope of the invention. For example, while the controller 100 and protective system 102 are each provided in the form of a single control unit with a processor and associated memory, either of them could include a number of processors either located together or spaced apart in a distributed manner.
Number | Date | Country | Kind |
---|---|---|---|
0614988.4 | Jul 2006 | GB | national |