Safety IO terminal and safety system

The safety IO terminal addresses the limitation of single-controller communication by enabling multiple connections and data processing from various controllers, ensuring robust and adaptable safety control.

WO2025192466A1PCT designated stage Publication Date: 2025-09-18OMRON CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/008501
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-15
Filing Date
2025-03-07
Publication Date
2025-09-18

AI Technical Summary

Technical Problem

Existing safety IO terminals are limited to communicating with a single safety controller, restricting their ability to adapt to diverse applications and potentially leading to data storage and logic execution inefficiencies.

Method used

A safety IO terminal capable of establishing multiple safety connections with different safety controllers, utilizing individual data storage areas for each connection and implementing safety logic based on data from multiple controllers, ensuring correct data association and maintaining safety output signals.

Benefits of technology

Enables flexible safety control by allowing the safety IO terminal to communicate with and process data from multiple controllers, preventing data misstorage and ensuring continuous safety output signals, even when connections change.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025008501_18092025_PF_FP_ABST
    Figure JP2025008501_18092025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a safety IO terminal capable of performing safety control based on data from a plurality of safety controllers, and a safety system including the safety IO terminal. The safety IO terminal comprises: a safety output circuit that outputs a safety output signal; a safety communication unit capable of establishing a safety connection with one or more safety controllers; a received data storage unit that includes a plurality of individual areas for storing, for each safety connection, data received by the safety communication unit; and a safety logic executing unit that uses arbitrary data stored in the plurality of individual areas to determine a value for the safety output signal. Each of the plurality of individual areas is configured to associate identification information for identifying a safety controller that establishes a safety connection with the safety IO terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Safety IO terminal and safety system

[0001] The present invention relates to a safety IO terminal and a safety system.

[0002] In manufacturing sites, safety systems are sometimes introduced in addition to control devices for equipment and machinery. Safety systems are designed to prevent equipment and machinery from threatening human safety.

[0003] A safety system may be composed of, for example, a safety controller for executing safety control, and one or more safety IO terminals for handling safety input signals and safety output signals.

[0004] Regarding safety IO terminals, for example, Japanese Patent Application Laid-Open Publication No. 2014-098985 (Patent Document 1) discloses a safety slave unit that can reduce the processing load on a safety controller.

[0005] Japanese Patent Application Publication No. 2014-098985

[0006] Generally, one safety IO terminal is under the control of one safety controller. However, the inventors of the present application have newly discovered that it is more preferable for one safety IO terminal to communicate with multiple safety controllers depending on the application to which the safety system is applied.

[0007] An object of the present invention is to provide a safety IO terminal capable of safety control based on data from a plurality of safety controllers, and a safety system including the safety IO terminal.

[0008] A safety IO terminal according to an embodiment includes a safety output circuit that outputs a safety output signal, a safety communication unit that can establish a safety connection with one or more safety controllers, a received data storage unit that includes a plurality of individual areas for storing data received by the safety communication unit for each safety connection, and a safety logic execution unit that determines the value of the safety output signal using any data stored in the plurality of individual areas, wherein each of the plurality of individual areas is configured to be associated with identification information for identifying the safety controller that establishes the safety connection with the safety IO terminal.

[0009] According to this configuration, data from the multiple safety controllers is stored in multiple individual areas of the safety IO terminal, respectively. The safety IO terminal can determine the value of a safety output signal using any data stored in the multiple individual areas, so that appropriate safety logic can be realized using data from the multiple safety controllers depending on the application.

[0010] In order to establish a safety connection, each of the one or more safety controllers may transmit a request including identification information of the safety controller and designation of the individual area to be used to the safety IO terminal. This configuration makes it possible to prevent data from being mistakenly stored in an individual area different from the individual area corresponding to the connection between the safety controller and the safety IO terminal.

[0011] The safety communication unit may associate the identification information included in the request with the individual area if no identification information is associated with the individual area specified by the request. According to this configuration, in a factory default state, any safety controller can be connected to the safety IO terminal.

[0012] The safety communication unit may establish a safety connection in accordance with the request if identification information associated with the individual area specified by the request matches identification information included in the request. With this configuration, it is possible to establish a connection between the safety controller and the safety IO terminal after confirming that the specification of the corresponding individual area is correct.

[0013] The safety IO terminal may further include a storage unit for storing an identification information list including identification information associated with each individual area. With this configuration, even if the individual area is configured using a volatile storage device, the identification information associated with the individual area can be managed.

[0014] The safety logic execution unit may perform a logical OR operation on a value indicated by first data stored in a first individual area among the plurality of individual areas and a value indicated by second data stored in a second individual area among the plurality of individual areas. With this configuration, the safety output signal can be maintained as long as the safety logic execution unit is connected to any one of the plurality of safety controllers.

[0015] The safety logic execution unit may perform a logical AND operation on a value indicated by first data stored in a first individual area among the plurality of individual areas and a value indicated by second data stored in a second individual area among the plurality of individual areas. With this configuration, the safety output signal can be cut off from any of the plurality of safety controllers.

[0016] The safety connection may be established based on at least one of CIP Safety and PROFIsafe. This configuration allows a safety connection to be established using a general-purpose communication protocol.

[0017] A safety system according to another embodiment includes a safety IO terminal and one or more safety controllers capable of executing a safety program based on safety input data received from the safety IO terminal. The safety IO terminal includes a safety input circuit that accepts a safety input signal, a safety output circuit that outputs a safety output signal, a safety communication unit that can establish a safety connection with one or more safety controllers, a received data storage unit including a plurality of individual areas for storing data received by the safety communication unit for each safety connection, and a safety logic execution unit that determines a value of the safety output signal using any data stored in the plurality of individual areas. Each of the plurality of individual areas is configured to store identification information for identifying a safety controller that establishes a safety connection with the safety IO terminal.

[0018] According to the present invention, it is possible to realize a safety IO terminal capable of safety control based on data from a plurality of safety controllers, and a safety system including the safety IO terminal.

[0019] FIG. 10 is a schematic diagram showing an example of the configuration of a safety system according to the present embodiment. FIG. 11 is a schematic diagram showing an example of the hardware configuration of a safety controller of the safety system according to the present embodiment. FIG. 12 is a schematic diagram showing an example of the hardware configuration of a safety IO terminal constituting the safety system according to the present embodiment. FIG. 13 is a schematic diagram showing an example of the functional configuration of a safety IO terminal according to the related art. FIG. 14 is a schematic diagram showing an example of the functional configuration of the safety IO terminal constituting the safety system according to the present embodiment. FIG. 15 is a sequence diagram showing an example of a communication procedure in a factory shipment state of the safety IO terminal according to the present embodiment. FIG. 16 is a sequence diagram showing an example of a communication procedure in a normal startup of the safety IO terminal according to the present embodiment. FIG. 17 is a schematic diagram showing an example of the configuration of a safety system 1A using a transport robot equipped with a safety IO terminal according to the present embodiment. FIG. 18 is a flowchart showing an example of the operation procedure of the safety system shown in FIG. 8. FIG. 19 is a schematic diagram showing an example of the configuration of a safety system that enables safety control between zones according to the present embodiment. FIG. 19 is a diagram for comparing features of devices constituting the safety system according to the present embodiment.

[0020] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present invention will be described in detail with reference to the accompanying drawings, in which the same or corresponding parts are denoted by the same reference numerals and the description thereof will not be repeated.

[0021] <A. Application Example> First, an example of a situation in which the present invention is applied will be described.

[0022] 1 is a schematic diagram showing an example of the configuration of a safety system 1 according to the present embodiment. Referring to FIG. 1, safety system 1 includes, as an example, safety controllers 100-1 and 100-2 (hereinafter also collectively referred to as "safety controllers 100") and a safety IO terminal 200.

[0023] 1 shows an example of a configuration in which the safety controller 100 and the safety IO terminal 200 are connected by wire via a network 2, but a configuration in which they are connected wirelessly may also be employed. The network 2 may employ an industrial network protocol such as EtherCAT (registered trademark), EtherNet / IP (registered trademark), PROFIBUS, or PROFINET.

[0024] The safety controller 100 executes a safety program created in advance. The safety program includes a combination of instructions for implementing processes to prevent human safety from being threatened by equipment, machinery, etc. The safety controller 100 includes, for example, a calculation unit for executing the safety program. The safety control executed by the safety controller 100 is designed to meet the requirements defined in IEC 61508, a functional safety standard.

[0025] The safety IO terminal 200 includes a safety output circuit that outputs a safety output signal (e.g., a binary signal of True / False). The safety IO terminal 200 outputs the safety output signal in accordance with an output value of the safety controller 100 (hereinafter also referred to as a "safety output value").

[0026] The safety IO terminal 200 may further include a safety input circuit that receives a safety input signal (e.g., a binary signal of True / False). The safety IO terminal 200 transmits the value of the received safety input signal (hereinafter also referred to as a “safety input value”) to the safety controller 100.

[0027] One or more safety input values ​​may be transmitted as aggregated data, and one or more safety output values ​​may be transmitted as aggregated data, and therefore one or more safety input values ​​may also be referred to as "safety input data," and one or more safety outputs may also be referred to as "safety output data."

[0028] The safety controller 100 can execute a safety program based on safety input values ​​received from the safety IO terminal 200. The safety controller 100 can also transmit safety output data determined by the execution of the safety program to the safety IO terminal 200. In this way, the safety IO terminal 200 functions as a remote IO device for the safety controller 100.

[0029] The safety controller 100 may further include a signal processing unit (for example, a safety IO unit) for processing safety input / output signals.

[0030] The safety IO terminal 200 can establish safety connections in parallel with a plurality of safety controllers 100. A safety connection is established between the safety controller 100 and the safety IO terminal 200.

[0031] A safety connection refers to a logical connection established in accordance with a safety communication protocol. The safety communication protocol used satisfies a predetermined level (e.g., SIL3 (Safety Integrity Level 3)) defined in IEC 61508, a functional safety standard. For example, protocols such as CIP Safety and PROFIsafe are used. That is, the safety connection may be established based on at least one of CIP Safety and PROFIsafe. However, any safety communication protocol may be used as long as it satisfies the predetermined level defined in IEC 61508.

[0032] For example, the safety IO terminal 200 exchanges safety input values ​​and safety output data with the safety controller 100-1, and in parallel, exchanges safety input values ​​and safety output data with the safety controller 100-2. Note that the safety IO terminal 200 does not always have to exchange data with all the safety controllers 100. For example, the safety IO terminal 200 may exchange data only with the safety controller 100-1 at a specific time, and only with the safety controller 100-2 at another time.

[0033] The safety IO terminal 200 can execute a safety logic for determining one or more safety output data values ​​based on one or more safety input values. The scale of the safety logic that the safety IO terminal 200 can execute is smaller than the safety program that the safety controller 100 executes.

[0034] In the safety logic executable by the safety IO terminal 200, it is also possible to handle the safety output data from the safety controller 100 as a safety input value. The safety IO terminal 200 can establish safety connections with multiple safety controllers 100 in parallel, so that it is possible to configure a safety logic based on, for example, the safety output data from the safety controller 100-1 and the safety output data from the safety controller 100-2.

[0035] 1 shows an example in which a safety logic 290 for determining a safety output value of the safety IO terminal 200 is configured by an OR circuit (logical sum) of a safety output value 1 (one value included in the safety output data) from the safety controller 100-1 and a safety output value 2 from the safety controller 100-2 in the safety IO terminal 200. By configuring the safety logic 290, a safety device (such as a safety relay or a safety drive) connected to the safety IO terminal 200 can be operated from either the safety controller 100-1 or 100-2.

[0036] Note that the safety controller 100 and the safety IO terminal 200 may be connectable to a support device for creating, transferring, changing, etc. the safety program and / or the safety logic 290 .

[0037] <B. Example of Hardware Configuration of Safety System 1> Next, an example of the hardware configuration of the safety system 1 will be described.

[0038] (b1: Safety Controller 100) FIG. 2 is a schematic diagram showing an example of a hardware configuration of safety controller 100 of safety system 1 according to the present embodiment.

[0039] Referring to FIG. 2, the safety controller 100 includes arithmetic circuits 110 and 120, storages 130 and 140, a communication circuit 102, an internal bus circuit 104, and a memory card interface 106.

[0040] The arithmetic circuits 110 and 120 execute programs (such as a system program 132 and a safety program 134) stored in the storages 130 and 140, respectively. The arithmetic circuits 110 and 120 compare their arithmetic results with each other. If the arithmetic results do not match, it is determined that some kind of abnormality has occurred.

[0041] The operational circuitry 110 includes a processor 112 and a memory 114. The operational circuitry 120 includes a processor 122 and a memory .

[0042] The processors 112 and 122 are configured by, for example, a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit).

[0043] The memories 114 and 124 are configured by volatile storage devices such as dynamic random access memory (DRAM) and static random access memory (SRAM), for example.

[0044] The storages 130 and 140 are configured by non-volatile storage devices such as Flash Read-Only Memory (FROM) and Electrically Erasable Programmable Read-Only Memory (EEPROM), for example.

[0045] The system program 132 includes computer-readable instructions for providing an execution environment for the arithmetic circuits 110 and 120 to execute the programs. The safety program 134 includes computer-readable instructions for implementing processes to prevent human safety from being threatened by facilities, machines, etc. The safety program 134 may be written in accordance with standards such as IEC 61131-3.

[0046] The communication circuit 102 is responsible for communication with other devices (such as other safety controllers 100 and safety IO terminals 200) via the network 2.

[0047] The internal bus circuit 104 is responsible for communication with a safety unit (not shown) and the like. Similar to the safety IO terminal 200, the safety unit includes at least one of a safety input circuit that receives a safety input signal and a safety output circuit that outputs a safety output signal.

[0048] The memory card interface 106 reads and writes any data from and to a memory card 108, which is an example of a removable storage medium.

[0049] (b2: Safety IO Terminal 200) FIG. 3 is a schematic diagram showing an example of a hardware configuration of the safety IO terminal 200 constituting the safety system 1 according to the present embodiment.

[0050] Referring to FIG. 3 , the safety IO terminal 200 includes arithmetic circuits 210 and 220 , storages 230 and 232 , a communication circuit 202 , a safety input circuit 204 , and a safety output circuit 206 .

[0051] The arithmetic circuits 210 and 220 execute programs (such as a system program 234 and safety logic 290) stored in the storages 230 and 232, respectively. The arithmetic circuits 210 and 220 compare their arithmetic results with each other. If the arithmetic results do not match, it is determined that some kind of abnormality has occurred.

[0052] The operational circuitry 210 includes a processor 212 and a memory 214. The operational circuitry 220 includes a processor 222 and a memory 224.

[0053] The processors 212 and 222 are configured, for example, by a CPU, a GPU, etc. The memories 214 and 224 are configured, for example, by a volatile storage device such as a DRAM or an SRAM.

[0054] The storages 230 and 232 are configured by non-volatile storage devices such as FROM and EEPROM.

[0055] The system program 234 includes computer-readable instructions for providing an execution environment for the execution of the programs by the arithmetic circuits 210 and 220. The safety logic 290 defines the logical relationship between the safety input signal input to the safety input circuit 204 and / or the safety output value from the safety controller 100 and one or more safety output values. The safety logic 290 may be described using an OR circuit (logical sum) and an AND circuit (logical product).

[0056] Communication circuit 202 is responsible for communication with other devices (such as safety controller 100) via network 2. Communication circuit 202 may have a memory unit for storing data received from safety controller 100 (such as safety output values).

[0057] The safety input circuit 204 receives safety input signals from one or more safety devices (e.g., a safety light curtain, a safety laser scanner, a safety door switch, a safety limit switch, a safety mat, an emergency stop push button switch, etc.) The safety input circuit 204 may have a different circuit configuration depending on the type of the safety device.

[0058] The safety output circuit 206 outputs a safety output signal to one or more safety devices (for example, a safety relay, a safety drive, etc.) The safety output circuit 206 may have a different circuit configuration depending on the type of the safety device.

[0059] (b3: Other Forms) In this specification, the term "processor" includes processing circuits that execute processing using stored programs, such as CPUs and GPUs, as well as dedicated hardware circuits with pre-fixed programs (e.g., ASICs (Application Specific Integrated Circuits) or FPGAs (Field-Programmable Gate Arrays)).

[0060] As used herein, the term "memory" encompasses non-volatile and volatile storage.

[0061] <C. Example of Functional Configuration of Safety IO Terminal> Next, an example of the functional configuration of the safety IO terminal 200 according to the present embodiment will be described.

[0062] 4 is a schematic diagram showing an example of a functional configuration of a safety IO terminal 200A according to the related art. Referring to FIG. 4, the safety IO terminal 200A includes a safety communication function 240A, a received data storage area 250A, and a safety output function 270A.

[0063] The secure communication function 240A is realized by the execution of the system program 234 by the communication circuit 202 (FIG. 3) and / or the arithmetic circuits 210 and 220.

[0064] The received data storage area 250A is realized using the memory 214 of the arithmetic circuit 210 and the memory 224 of the arithmetic circuit 220. The received data storage area 250A may also be realized using a memory provided within the communication circuit 202.

[0065] The safety output function 270A is realized by the execution of the system program 234 by the safety output circuit 206 (FIG. 3) and / or the arithmetic circuits 210 and 220.

[0066] 4, a safety connection 10-1 is established between a safety controller 100-1 and a safety IO terminal 200. The safety connection 10-1 is based on, for example, the CIP Safety protocol.

[0067] Data (safety output data) transmitted from the safety controller 100-1 is stored in the received data storage area 250A. The received data storage area 250A directly controls the safety output signal from the safety IO terminal 200. In other words, the safety output data stored in the received data storage area 250A is directly assigned to the safety output function 270A. For example, if the safety output data is byte data, the safety output function 270A determines that the value (True / False) of a pre-specified (pre-assigned) bit in the byte data is the safety output value. Then, the safety output function 270A outputs a safety output signal indicating the value of the pre-specified bit.

[0068] In the safety IO terminal 200A according to the related art, the received data storage area 250A is associated with only one safety connection, so that the safety IO terminal 200A cannot establish another safety connection 10-2 with the safety controller 100-2 while the safety connection 10-1 with the safety controller 100-1 has been established. In other words, the safety IO terminal 200A establishes an exclusive safety connection with the safety controller 100.

[0069] Therefore, the safety output function 270A of the safety IO terminal 200A cannot simultaneously refer to the safety output data from a plurality of safety controllers 100.

[0070] FIG. 5 is a schematic diagram showing an example of a functional configuration of a safety IO terminal 200 constituting the safety system 1 according to the present embodiment.

[0071] Referring to FIG. 5, the safety IO terminal 200 includes a safety communication function 240 , a received data storage area 250 , a safety logic function 260 , a safety output function 270 , and a connection history storage unit 280 .

[0072] The safety communication function 240 corresponds to a safety communication unit, and is realized by execution of the system program 234 by the communication circuit 202 (FIG. 3) and / or the arithmetic circuits 210 and 220. The safety communication function 240 can establish a safety connection with one or more safety controllers 100.

[0073] The received data storage area 250 corresponds to a received data storage unit, and is realized using the memory 214 of the arithmetic circuit 210 and the memory 224 of the arithmetic circuit 220. The received data storage area 250 may be realized using a memory provided within the communication circuit 202.

[0074] The safety logic function 260 corresponds to a safety logic execution unit, and is realized by the execution of the system program 234 and the safety logic 290 by the arithmetic circuits 210 and 220 .

[0075] The safety output function 270 is realized by the execution of the system program 234 by the safety output circuit 206 (FIG. 3) and / or the arithmetic circuits 210 and 220.

[0076] The connection history storage unit 280 is realized using the storages 230 and 232. In the functional configuration example shown in Fig. 5, a safety connection 10-1 is established between the safety controller 100-1 and the safety IO terminal 200. A safety connection 10-2 is established between the safety controller 100-2 and the safety IO terminal 200. The safety connections 10-1 and 10-2 (hereinafter also collectively referred to as "safety connections 10") are based on, for example, the CIP Safety protocol.

[0077] The received data storage area 250 includes individual areas 252-1, 252-2, ... (hereinafter also collectively referred to as "individual areas 252") for storing data received by the safety communication function 240 for each safety connection 10. Unlike the received data storage area 250A (FIG. 4), the individual areas 252 do not directly control the safety output signal from the safety IO terminal 200. Each individual area 252 is associated with a safety connection 10. Each individual area 252 is a memory area for storing data (such as a safety output value) received from the safety controller 100 for each safety connection 10.

[0078] Each of the multiple individual areas 252 is configured to be associated with identification information for identifying the safety controller 100 that establishes a safety connection with the safety IO terminal 200. More specifically, the individual areas 252-1, 252-2, ... include areas for storing identification information 254-1, 254-2, ... (hereinafter also collectively referred to as "identification information 254") indicating which safety controller 100 the stored received data is associated with. The safety controllers 100-1, 100-2, ... have identification information 154-1, 154-2, ... (hereinafter also collectively referred to as "identification information 154"). For example, in the CIP Safety protocol, an "originator ID" can be adopted as the identification information 154, 254.

[0079] The safety logic function 260 determines the value of a safety output signal using any data stored in the individual areas 252-1, 252-2, .... More specifically, the safety logic function 260 includes an input process 262, a logic process 264, and an output process 266. The safety logic function 260 reflects the safety logic 290. The input process 262 includes a process for determining a safety input value from received data stored in one or more pre-specified individual areas 252. The logic process 264 includes a process for determining one or more safety output values ​​based on one or more pre-specified safety input values. The output process 266 includes a process for providing the safety output value to the safety output function 270.

[0080] The one or more pieces of data (safety output values) referenced in the input processing 262 may be specified by the user when creating the safety logic 290. The safety logic 290 includes specification of values ​​included in the received data to be used as safety input values. Alternatively, a setting (data allocation) of data to be used as the safety input values ​​of the safety logic 290 may be prepared separately from the safety logic 290. The data setting may be stored in the storages 230 and 232 (FIG. 3).

[0081] In the safety logic 290 shown in Figure 8 described below, the safety logic function 260 calculates a logical sum using as input the value indicated by the received data stored in individual area 252-1 and the value indicated by the received data stored in individual area 252-2.

[0082] In the safety logic 290 shown in FIG. 10, which will be described later, the safety logic function 260 calculates a logical product of the value indicated by the received data stored in the individual area 252-1 and the value indicated by the received data stored in the individual area 252-2 as inputs.

[0083] The safety output function 270 outputs a safety output signal indicative of the safety output value output from the safety logic function 260 .

[0084] The connection history storage unit 280 corresponds to a storage unit and stores an identification information list 282. The identification information list 282 includes identification information 254 associated with each individual area 252. When a new safety controller 100 and safety connection 10 are established, the identification information 154 of the safety controller 100 is associated with an individual area 252 that has no associated identification information 254, and the associated identification information 154 (identification information 254) is added to the identification information list 282. In this way, once the identification information 254 is associated with each individual area 252 of the received data storage area 250, the association of the identification information 254 is maintained until initialization, reset, or the like is performed.

[0085] For example, in the factory default state, the identification information 254 of the individual area 252 of the safety IO terminal 200 indicates "null." The identification information 154 of the safety controller 100 that first established the safety connection 10 with each of the individual areas 252 is stored.

[0086] When the safety IO terminal 200 is activated, the identification list 282 is referenced and the associated identification 254 is stored in the individual area 252 .

[0087] The command for the safety controller 100 to establish the safety connection 10 with the safety IO terminal 200 includes the designation of the individual area 252 to be used for storing the safety output data (received data). That is, in order to establish a safety connection, each of the one or more safety controllers 100 transmits to the safety IO terminal 200 a request including the identification information 154 of each safety controller 100 and the designation of the individual area to be used (area designation 152).

[0088] The safety communication function 240 determines whether the identification information 254 associated with the individual area 252 specified by the command matches the identification information 154 of the safety controller 100 that sent the command. If the identification information 154 and the identification information 254 match, the safety communication function 240 allows the establishment of a safety connection, and does not allow it if they do not match.

[0089] By determining whether or not a safety connection can be established based on the identification information, even when the safety IO terminal 200 establishes safety connections 10 with multiple safety controllers 100, the safety controller 100 that sent the received data stored in the individual area 252 can be guaranteed.

[0090] In this way, the safety IO terminal 200 according to this embodiment can perform safety communication with a plurality of safety controllers 100. The safety IO terminal 200 can input any value of the data received from each of the plurality of safety controllers 100 and perform logic processing 264.

[0091] <D. Communication Procedure Between the Safety Controller 100 and the Safety IO Terminal 200> Next, an example of a communication procedure between the safety controller 100 and the safety IO terminal 200 will be described.

[0092] 6 is a sequence diagram showing an example of a communication procedure in the factory-shipped state of the safety IO terminal 200 according to this embodiment. Fig. 6 shows an example of a communication procedure when the safety IO terminal 200 establishes safety connections 10-1 and 10-2 with the safety controllers 100-1 and 100-2, respectively. The safety controllers 100-1 and 100-2 are assumed to be originators in the CIP Safety protocol.

[0093] 6, the processing executed by the safety IO terminal 200 may be handled by the safety communication function 240 in FIG.

[0094] 6, the safety controller 100-1, which is the originator, transmits a safety communication establishment command 150-1 to the safety IO terminal 200 according to the settings (sequence SQ10). The safety communication establishment command 150-1 includes identification information 154-1 of the safety controller 100-1 and an area designation 152-1 for designating the individual area 252 (in this example, the individual area 252-1) to be used in the safety IO terminal 200.

[0095] When the safety IO terminal 200 receives the safety communication establishment command 150-1, it determines whether any identification information 254-1 is associated with the individual area 252-1 specified by the area designation 152-1. In the example shown in FIG. 6 , the value of the identification information 254-1 associated with the individual area 252-1 is "empty." Therefore, the safety IO terminal 200 associates the identification information 154-1 included in the safety communication establishment command 150-1 with the individual area 252-1 (sequence SQ12). This changes the value of the identification information 254-1 from "empty" to "xxxx" (the identification information 154-1 of the safety controller 100-1). The safety IO terminal 200 stores the newly associated identification information 254-1 in the identification information list 282 (sequence SQ14). The safety IO terminal 200 then transmits an OK response to the safety controller 100-1 (sequence SQ16).

[0096] In this way, if no identification information 254 is associated with the individual area 252 specified by the request, the safety IO terminal 200 (safety communication function 240 in Figure 5) associates the identification information 154 included in the request with that individual area 252.

[0097] Through the above communication procedure, a safety connection 10-1 is established between the safety controller 100-1 and the safety IO terminal 200. Safety communication (transmission and reception of safety output data and safety input data) is repeatedly executed between the safety controller 100-1 and the safety IO terminal 200 (sequence SQ18).

[0098] Similarly, the safety controller 100-2, which is the originator, transmits a safety communication establishment command 150-2 to the safety IO terminal 200 in accordance with the settings (sequence SQ20). The safety communication establishment command 150-2 includes identification information 154-2 of the safety controller 100-2 and an area designation 152-2 for designating the individual area 252 (in this example, the individual area 252-2) to be used in the safety IO terminal 200.

[0099] When the safety IO terminal 200 receives the safety communication establishment command 150-2, it determines whether any identification information 254-2 is associated with the individual area 252-2 specified by the area designation 152-2. In the example shown in FIG. 6 , the value of the identification information 254-2 associated with the individual area 252-2 is "empty." Therefore, the safety IO terminal 200 associates the identification information 154-2 included in the safety communication establishment command 150-2 with the individual area 252-2 (sequence SQ22). This changes the value of the identification information 254-2 from "empty" to "yyyy" (the identification information 154-2 of the safety controller 100-2). The safety IO terminal 200 stores the newly associated identification information 254-2 in the identification information list 282 (sequence SQ24). The safety IO terminal 200 then transmits an OK response to the safety controller 100-1 (sequence SQ26).

[0100] Through the above communication procedure, a safety connection 10-2 is established between the safety controller 100-2 and the safety IO terminal 200. Safety communication (transmission and reception of safety output data and safety input data) is repeatedly executed between the safety controller 100-2 and the safety IO terminal 200 (sequence SQ28).

[0101] 7 is a sequence diagram showing an example of a communication procedure when the safety IO terminal 200 according to this embodiment is normally started. In FIG. 7, it is assumed that the safety IO terminal 200 has previously established safety connections 10-1 and 10-2 with the safety controllers 100-1 and 100-2, respectively. Therefore, the identification information list 282 stores the identification information of the safety controllers 100-1 and 100-2.

[0102] In FIG. 7, the processing executed by the safety IO terminal 200 may be handled by the safety communication function 240 in FIG.

[0103] Furthermore, the safety controller 100-3 attempts to establish a safety connection with the safety IO terminal 200. It is assumed that the safety controllers 100-1, 100-2, and 100-3 are originators in the CIP Safety protocol.

[0104] 7, the safety controller 100-1, which is the originator, transmits a safety communication establishment command 150-1 to the safety IO terminal 200 in accordance with the settings (sequence SQ50). Upon receiving the safety communication establishment command 150-1, the safety IO terminal 200 determines whether the identification information 254-1 associated with the individual area 252-1 specified by the area specification 152-1 matches the identification information 154-1 included in the safety communication establishment command 150-1 (sequence SQ52).

[0105] If the identification information 254-1 associated with the individual area 252-1 matches the identification information 154-1 included in the safety communication establishment command 150-1, the safety IO terminal 200 transmits an OK response to the safety controller 100-1 (sequence SQ54). Through the above communication procedure, the safety connection 10-1 between the safety controller 100-1 and the safety IO terminal 200 is (re)established. Safety communication (transmission and reception of safety output data and safety input data) is repeatedly executed between the safety controller 100-1 and the safety IO terminal 200 (sequence SQ56).

[0106] In this manner, the safety IO terminal 200 (safety communication function 240 in FIG. 5) establishes a safety connection in accordance with the request if the identification information 254 associated with the individual area 252 specified by the request matches the identification information 154 included in the request.

[0107] Meanwhile, the safety controller 100-3, which is the originator, transmits a safety communication establishment command 150-3 to the safety IO terminal 200 in accordance with the settings (sequence SQ60). Upon receiving the safety communication establishment command 150-3, the safety IO terminal 200 determines whether the identification information 254-2 associated with the individual area 252-2 specified by the area specification 152-3 matches the identification information 154-3 included in the safety communication establishment command 150-3 (sequence SQ62).

[0108] If the identification information 254-2 associated with the individual area 252-2 does not match the identification information 154-3 included in the safety communication establishment command 150-3, the safety IO terminal 200 transmits an NG response to the safety controller 100-3 (sequence SQ64). Through the above communication procedure, the safety connection 10 is not established between the safety controller 100-3 and the safety IO terminal 200.

[0109] The safety controller 100-2, which is the originator, transmits a safety communication establishment command 150-2 to the safety IO terminal 200 in accordance with the settings (sequence SQ70). Upon receiving the safety communication establishment command 150-2, the safety IO terminal 200 determines whether the identification information 254-2 associated with the individual area 252-2 specified by the area specification 152-2 matches the identification information 154-2 included in the safety communication establishment command 150-2 (sequence SQ72).

[0110] If the identification information 254-2 associated with the individual area 252-2 matches the identification information 154-2 included in the safety communication establishment command 150-2, the safety IO terminal 200 transmits an OK response to the safety controller 100-2 (sequence SQ74). Through the above communication procedure, the safety connection 10-2 between the safety controller 100-2 and the safety IO terminal 200 is (re)established. Safety communication (transmission and reception of safety output data and safety input data) is repeatedly executed between the safety controller 100-2 and the safety IO terminal 200 (sequence SQ76).

[0111] <E. Application Example> Next, an example of an application using the safety IO terminal 200 according to the present embodiment will be described.

[0112] (e1: Transfer Robot) First, a safety system using a transfer robot 300 equipped with a safety IO terminal 200 will be described.

[0113] 8 is a schematic diagram showing a configuration example of a safety system 1A using a transfer robot 300 equipped with a safety IO terminal 200 according to the present embodiment. Referring to FIG. 8, the safety system 1A includes safety controllers 100-1 and 100-2 and a transfer robot 300 equipped with the safety IO terminal 200.

[0114] The safety controller 100-1 is connected to the wireless repeater 180-1. When the transfer robot 300 is present in zone 1, the safety controller 100-1 establishes a safety connection with the safety IO terminal 200 via a wireless connection.

[0115] Similarly, the safety controller 100-2 is connected to the wireless repeater 180-2. When the transfer robot 300 is present in zone 2, the safety controller 100-2 establishes a safety connection with the safety IO terminal 200 via a wireless connection.

[0116] In the safety system 1A, even when the transfer robot 300 moves between zone 1 and zone 2, it is necessary for at least one of the safety controllers 100-1 and 100-2 to keep the safety IO terminal 200 under control.

[0117] Normally, the safety output signal of the safety IO terminal 200 indicates True (ON) under normal conditions in accordance with the safety output value from the safety controller 100. Therefore, if the safety connection between the safety controller 100 and the safety IO terminal 200 is disconnected and the safety IO terminal 200 cannot receive the safety output value from the safety controller 100, the safety output signal of the safety IO terminal 200 indicates False (OFF). In other words, the safety output signal is blocked. As a result, an instruction to perform a safe operation (usually, to stop) is given to the transport robot 300 and / or the devices mounted on the transport robot 300.

[0118] The safety IO terminal 200 according to this embodiment can establish safety connections in parallel with a plurality of safety controllers 100. More specifically, when the transport robot 300 is present in zone 1, the safety IO terminal 200 can receive safety output data from the safety controller 100-1, and when the transport robot 300 is present in zone 2, the safety IO terminal 200 can receive safety output data from the safety controller 100-2.

[0119] Therefore, by configuring the safety IO terminal 200 with a safety logic 290 including an OR circuit (logical sum) of the safety output data from the safety controller 100-1 and the safety output data from the safety controller 100-2, it is possible to prevent the safety output signal from being blocked regardless of which zone the transport robot 300 is in.

[0120] 8 shows an example of safety logic 290 that outputs the logical sum of the value of the first bit of received data 291 (safety output data) received from safety controller 100-1 and the value of the first bit of received data 292 (safety output data) received from safety controller 100-2 as a safety output value 293. By employing such safety logic 290, it is possible to continue outputting a safety output signal.

[0121] Fig. 9 is a flowchart showing an example of an operation procedure of the safety system 1A shown in Fig. 8. Referring to Fig. 9, the user provides the safety controllers 100-1 and 100-2 with settings for establishing a safety connection with the safety IO terminal 200 (step S2). The user provides the safety IO terminal 200 with settings for the safety logic 290 (step S4).

[0122] The user places the transfer robot 300 in area 1 (step S6), for example. Then, the user activates the safety controllers 100-1 and 100-2 and the safety IO terminal 200 to bring them into normal operating state (step S8).

[0123] The safety controller 100-1 establishes a safety connection with the safety IO terminal 200 mounted on the transfer robot 300 (step S10). The safety IO terminal 200 outputs a safety output signal based on the received data 291 (safety output data) received from the safety controller 100-1 (step S12).

[0124] Subsequently, when the transfer robot 300 moves to area 2 (YES in step S14), the safety connection between the safety controller 100-1 and the safety IO terminal 200 is disconnected (step S16). Meanwhile, the safety controller 100-2 establishes a safety connection with the safety IO terminal 200 (step S18). The safety IO terminal 200 outputs a safety output signal based on the received data 292 (safety output data) received from the safety controller 100-2 (step S20).

[0125] Furthermore, when the transfer robot 300 moves to area 1 (YES in step S22), the safety connection between the safety controller 100-2 and the safety IO terminal 200 is cut off (step S24), and the processing from step S10 onwards is repeated.

[0126] (e2: Safety Control Across Multiple Zones) Next, an example of safety control across multiple zones will be described.

[0127] 10 is a schematic diagram showing an example of the configuration of a safety system 1B that enables inter-zone safety control according to this embodiment. Referring to FIG. 10, the safety system 1B includes safety controllers 100-1 and 100-2 and a safety IO terminal 200 that are connected to each other via a network 2.

[0128] The safety IO terminal 200 is connected to a safety device (for example, a safety relay 40 or a light curtain) for stopping equipment that spans zone 1 and zone 2. The safety controller 100-1 is connected to an emergency stop switch 30-1 as a safety device. The safety controller 100-2 is connected to an emergency stop switch 30-2 as a safety device.

[0129] In the safety system 1B, the equipment can be stopped by the safety relay 40 regardless of whether the emergency stop switch 30-1 or the emergency stop switch 30-2 is pressed.

[0130] In the safety IO terminal 200, by configuring a safety logic 290 including an AND circuit (logical product) of the safety output data from the safety controller 100-1 and the safety output data from the safety controller 100-2, the safety relay 40 can be shut off regardless of whether the emergency stop switch 30-1 or the emergency stop switch 30-2 is pressed.

[0131] The example shown in Figure 10 shows an example of safety logic 290 that outputs the logical product of the value of the first bit of received data 291 (safety output data) received from safety controller 100-1 and the value of the first bit of received data 292 (safety output data) received from safety controller 100-2 as a safety output value 293.

[0132] In this way, the safety IO terminal 200 according to this embodiment can easily achieve safety control across a plurality of zones.

[0133] <F. Safety Controller and Safety IO Terminal> The safety controller 100 and the safety IO terminal 200 described above will be compared and explained.

[0134] Fig. 11 is a diagram for comparing the features of the devices that configure the safety system 1 according to this embodiment. Fig. 11 shows an explanation of the items of safety connection, number of connections, safety control, and cost for each of the safety controller 100 and the safety IO terminal 200.

[0135] With respect to a safety connection, the safety controller 100 is the originator in the CIP Safety protocol, whereas the safety IO terminal 200 is the target in the CIP Safety protocol.

[0136] Regarding the number of connections, the safety controller 100 can simultaneously establish a relatively large number of connections, whereas the safety IO terminal 200 can simultaneously establish a relatively small number of connections.

[0137] Regarding safety control, any safety program can be created in the safety controller 100, whereas small-scale safety logic can be created in the safety IO terminal 200. Note that the safety logic available in the safety IO terminal 200 is limited to that prepared in advance, and it may be configured so that users cannot add or change the safety logic.

[0138] In terms of cost, the safety controller 100 is expensive because it requires a relatively high-performance processor and a relatively large-capacity memory, whereas the safety IO terminal 200 is often implemented with the minimum necessary processor and memory.

[0139] <G. Modifications> In the above description, a configuration example is shown in which the safety IO terminal 200 establishes safety connections with two safety controllers 100, but safety connections may be established with more safety controllers 100. In this case, safety output values ​​from three or more safety controllers may be input to an OR circuit (logical sum) and / or an AND circuit (logical product).

[0140] <H. Supplementary Notes> The present embodiment as described above includes the following technical ideas.

[0141] [Configuration 1] A safety IO terminal (200) comprising: a safety output circuit (206) that outputs a safety output signal; a safety communication unit (240) that can establish a safety connection with one or more safety controllers (100); a received data storage unit (250) that includes a plurality of individual areas (252) for storing data received by the safety communication unit for each safety connection; and a safety logic execution unit (260) that determines the value of a safety output signal using any data stored in the plurality of individual areas, wherein each of the plurality of individual areas is configured to be associated with identification information (254) for identifying a safety controller that establishes a safety connection with the safety IO terminal.

[0142] [Configuration 2] The safety IO terminal of configuration 1, wherein each of the one or more safety controllers sends a request (150) to the safety IO terminal to establish a safety connection, the request including identification information (154) of the safety controller and a designation (152) of an individual area to be used.

[0143] [Configuration 3] The safety IO terminal according to Configuration 2, wherein if no identification information is associated with the individual area specified by the request, the safety communication unit associates the identification information included in the request with the individual area (SQ12, SQ14, SQ22, SQ24).

[0144] [Configuration 4] The safety IO terminal according to Configuration 2, wherein the safety communication unit establishes a safety connection in accordance with the request if identification information associated with the individual area specified by the request matches identification information included in the request (SQ52, SQ54, SQ72, SQ74).

[0145] [Configuration 5] The secure IO terminal of any one of configurations 1 to 4, further comprising a storage unit (280) for storing an identification information list (282) including identification information associated with each individual area.

[0146] [Configuration 6] The safety IO terminal according to any one of configurations 1 to 5, wherein the safety logic execution unit calculates a logical sum using as input a value indicated by first data stored in a first individual area (252-1) among the plurality of individual areas and a value indicated by second data stored in a second individual area (252-2) among the plurality of individual areas.

[0147] [Configuration 7] The safety IO terminal according to any one of configurations 1 to 6, wherein the safety logic execution unit calculates a logical product of a value indicated by first data stored in a first individual area (252-1) among the plurality of individual areas and a value indicated by second data stored in a second individual area (252-2) among the plurality of individual areas as inputs.

[0148] [Configuration 8] The safety IO terminal according to any one of configurations 1 to 7, wherein the safety connection is established based on at least one of CIP Safety and PROFIsafe.

[0149] [Configuration 9] A safety system comprising: a safety IO terminal (200); and one or more safety controllers (100) capable of executing a safety program (134) based on safety input data received from the safety IO terminal, wherein the safety IO terminal comprises: a safety input circuit (204) that receives a safety input signal; a safety output circuit (206) that outputs a safety output signal; a safety communication unit (240) that can establish a safety connection with one or more safety controllers; a received data storage unit (250) including a plurality of individual areas (252) for storing data received by the safety communication unit for each safety connection; and a safety logic execution unit (260) that determines a value of a safety output signal using any data stored in the plurality of individual areas, wherein each of the plurality of individual areas is configured to store identification information (254) for identifying a safety controller that establishes a safety connection with the safety IO terminal.

[0150] <I. Advantages> The safety IO terminal according to this embodiment can establish a safety connection with each of multiple safety controllers and store data received from each safety controller in an individual area. The safety IO terminal can then execute safety logic using any data stored in the individual area. This allows safety logic to be configured using data from multiple safety controllers depending on the application.

[0151] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope of the claims.

[0152] 1, 1A, 1B Safety system, 2 Network, 10 Safety connection, 30 Emergency stop switch, 40 Safety relay, 100 Safety controller, 102, 202 Communication circuit, 104 Internal bus circuit, 106 Memory card interface, 108 Memory card, 110, 120, 210, 220 Arithmetic circuit, 112, 122, 212, 222 Processor, 114, 124, 214, 224 Memory, 130, 140, 230, 232 Storage, 132, 234 System program, 134 Safety program, 150 Safety communication establishment command, 152 Area designation, 154, 254 Identification information, 180 Wireless repeater, 200, 200A Safety IO terminal, 204 Safety input circuit, 206 Safety output circuit, 240, 240A Safety communication function, 250, 250A received data storage area, 252 individual area, 260 safety logic function, 262 input processing, 264 logic processing, 266 output processing, 270, 270A safety output function, 280 connection history storage unit, 282 identification information list, 290 safety logic, 291, 292 received data, 300 transport robot.

Claims

1. A safety IO terminal comprising: a safety output circuit that outputs a safety output signal; a safety communication unit that can establish a safety connection with one or more safety controllers; a received data storage unit that includes multiple individual areas for storing data received by the safety communication unit for each safety connection; and a safety logic execution unit that determines the value of a safety output signal using any data stored in the multiple individual areas, wherein each of the multiple individual areas is configured to be associated with identification information for identifying the safety controller that establishes a safety connection with the safety IO terminal.

2. The safety IO terminal of claim 1, wherein each of the one or more safety controllers sends a request to the safety IO terminal to establish a safety connection, the request including identification information of the safety controller and a designation of the individual area to be used.

3. The safety IO terminal according to claim 2, wherein the safety communication unit associates the identification information included in the request with the individual area if no identification information is associated with the individual area specified by the request.

4. The safety IO terminal of claim 2, wherein the safety communication unit establishes a safety connection in accordance with the request if identification information associated with the individual area specified by the request matches identification information included in the request.

5. A secure IO terminal according to any one of claims 1 to 4, further comprising a storage unit for storing an identification information list including identification information associated with each individual area.

6. A safety IO terminal as claimed in any one of claims 1 to 5, wherein the safety logic execution unit calculates a logical sum using as input a value indicated by first data stored in a first individual area among the plurality of individual areas and a value indicated by second data stored in a second individual area among the plurality of individual areas.

7. A safety IO terminal as claimed in any one of claims 1 to 6, wherein the safety logic execution unit calculates a logical product of a value indicated by first data stored in a first individual area among the plurality of individual areas and a value indicated by second data stored in a second individual area among the plurality of individual areas.

8. A safety IO terminal according to any one of claims 1 to 7, wherein the safety connection is established based on at least one of CIP Safety and PROFIsafe.

9. A safety system comprising: a safety IO terminal; and one or more safety controllers capable of executing a safety program based on safety input data received from the safety IO terminal, wherein the safety IO terminal comprises: a safety input circuit that receives a safety input signal; a safety output circuit that outputs a safety output signal; a safety communication unit that can establish a safety connection with one or more safety controllers; a received data storage unit including a plurality of individual areas for storing data received by the safety communication unit for each safety connection; and a safety logic execution unit that determines the value of a safety output signal using any data stored in the plurality of individual areas, wherein each of the plurality of individual areas is configured to store identification information for identifying the safety controller that establishes a safety connection with the safety IO terminal.

Citation Information

Patent Citations

  • Safety slave unit, control method thereof, control program thereof, and safety control system

    JP2014098985A

  • Equipment for controlling safety-critical processes

    JP2003507810A

  • Command processing system and command processing method

    JP2016129286A

  • Robot control device and robot control method, robot

    JP2023519155A

  • System and Method of Communicating Data Over High Availability Industrial Control Systems

    US20200033840A1