A safety circuit and a robot

By designing safety circuits in the robot, including safety function modules and controllers, the problem of the robot not having safety functions is solved, and safety function certification and cost reduction are achieved.

CN110919662BActive Publication Date: 2025-07-18QKM TECH (DONG GUAN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201911404672.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-12-31
Publication Date
2025-07-18
Estimated Expiration
2039-12-31

AI Technical Summary

Technical Problem

Existing robots do not have safety functions and cannot meet the safety function certification requirements.

Method used

Design a safety circuit, including a safety function module, a controller and a driver, through which the safety function module is powered on to drive the motor during normal operation, and cut off the power supply in a safe situation to realize the safety function.

Benefits of technology

It realizes the robot's automatic stopping operation in a safe situation, meets the requirements of safety function certification, and reduces costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN110919662B_ABST
    Figure CN110919662B_ABST
Patent Text Reader

Abstract

The present application provides a safety circuit and a robot, relating to the technical field of robots. The safety circuit includes a safety function module, a controller, and a driver. The controller is electrically connected to the safety function module and the driver respectively. The safety function module is used to be connected to a power supply, and the driver is used to be electrically connected to a motor. Wherein, when the safety circuit is in normal operation, the controller is used to control the safety function module to be in a powered-on state, so that the driver drives the motor to work; the safety function module is used to cut off the power supply to the driver when the safety circuit is in a safety situation. The safety circuit and the robot provided by the present application have the advantages of being able to achieve safety functions and having a relatively low cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of robot technology, and more particularly, to a safety circuit and a robot. Background Art

[0002] The safety function is to ensure the safety, reliability of a system and the prevention of safety accidents. Currently, for the robot industry and the traditional automation industry, in some regions, it is required that relevant equipment in the market circulation (sales) must meet the safety function, that is, it must pass the safety function certification.

[0003] However, most current robots do not have the safety function or have not passed the safety function certification.

[0004] In summary, there is a problem in the prior art that robots do not have the safety function. Summary of the Invention

[0005] The purpose of this application is to provide a safety circuit and a robot to solve the problem that robots in the prior art do not have the safety function.

[0006] To achieve the above purpose, the technical solutions adopted in the embodiments of this application are as follows:

[0007] On the one hand, the embodiments of this application provide a safety circuit, which includes a safety function module, a controller, and a driver. The controller is electrically connected to the safety function module and the driver respectively. The safety function module is used to be connected to a power supply, and the driver is used to be electrically connected to a motor. Among them,

[0008] When the robot is in normal operation, the controller is used to control the safety function module to be in the powered-on state, so that the driver drives the motor to work;

[0009] The safety function module is used to cut off the power supply to the driver when the safety circuit is in a safety situation.

[0010] Further, the safety function module includes a trigger, a control unit, and an output unit. The safety switch is electrically connected to the trigger and the input end of the control unit respectively. The controller is electrically connected to the trigger and the input end of the control unit. The output end of the trigger is electrically connected to the input end of the control unit. The output end of the control unit is electrically connected to the output unit. The output unit is electrically connected to the driver. Among them,

[0011] The control unit is used to control the conduction and disconnection of the output unit according to the signals of the safety switch, the trigger, and the controller, so as to control the working state of the driver.

[0012] Further, the trigger includes a first trigger and a second trigger, the control unit includes a first gate circuit and a second gate circuit, the safety switch includes a first switch and a second switch, the first switch is electrically connected to the first trigger and the input terminal of the first gate circuit respectively, the second switch is electrically connected to the second trigger and the input terminal of the second gate circuit respectively, the controller is electrically connected to the input terminals of the first trigger, the second trigger, the first gate circuit and the second gate circuit respectively, and the output terminals of the first gate circuit and the second gate circuit are both electrically connected to the output unit.

[0013] Further, the safety function module further includes a first NOT gate, a second NOT gate, a third NOT gate, a fourth NOT gate, a fifth NOT gate and a sixth NOT gate. The input terminal of the first NOT gate is electrically connected to the first switch, and the output terminal of the first NOT gate is electrically connected to the D pin of the first trigger, the input terminal of the second NOT gate and the first gate circuit respectively. The output terminal of the second NOT gate is electrically connected to the R pin of the first trigger;

[0014] The input terminal of the third NOT gate is electrically connected to the controller, and the output terminal of the third NOT gate is electrically connected to the C pin of the first trigger and the first gate circuit respectively;

[0015] The input terminal of the fourth NOT gate is electrically connected to the second switch, and the output terminal of the fourth NOT gate is electrically connected to the D pin of the second trigger, the input terminal of the fifth NOT gate and the second gate circuit respectively. The output terminal of the fifth NOT gate is electrically connected to the R pin of the second trigger;

[0016] The input terminal of the sixth NOT gate is electrically connected to the controller, and the output terminal of the sixth NOT gate is electrically connected to the C pin of the second trigger and the second gate circuit respectively;

[0017] The Q pin of the first trigger is electrically connected to the first gate circuit and the second gate circuit respectively, and the Q pin of the second trigger is also electrically connected to the first gate circuit and the second gate circuit respectively.

[0018] Further, the safety function module further includes an alarm unit, and the alarm unit is electrically connected to the output terminals of the first gate circuit and the second gate circuit respectively.

[0019] Further, the alarm unit includes a first triode, a second triode and an alarm output driver. The emitter of the first triode is electrically connected to the output terminal of the first gate circuit, the collector of the first triode is electrically connected to the alarm output driver, the base of the first triode is electrically connected to the collector of the second triode, the emitter of the second triode is grounded, and the base of the second triode is electrically connected to the output terminal of the second gate circuit.

[0020] Further, the first gate circuit and the second gate circuit include an AND gate or a NAND gate.

[0021] Further, the safety function module further includes a delay unit, and the delay unit is electrically connected to the safety switch and the input end of the trigger respectively.

[0022] Further, the output unit includes a rectifying unit, a relay unit, and a filtering unit. The rectifying unit, the relay unit, and the filtering unit are electrically connected in sequence. The rectifying unit is electrically connected to the power supply, the filtering unit is electrically connected to the driver, and the control unit is electrically connected to the relay unit. The controller is used to control the conduction and disconnection of the relay unit to control the working state of the driver.

[0023] On the other hand, the present application also provides a robot, and the robot includes the above-mentioned safety circuit.

[0024] Compared with the prior art, the present application has the following beneficial effects:

[0025] The present application provides a safety circuit and a robot. The safety circuit includes a safety function module, a controller, and a driver. The controller is electrically connected to the safety function module and the driver respectively. The safety function module is used to be connected to the power supply, and the driver is used to be electrically connected to a motor. When the robot is in normal operation, the controller is used to control the safety function module to be in a powered-on state so that the driver drives the motor to work. The safety function module is used to cut off the power supply to the driver when the safety circuit is in a safe situation. Since the safety function module is provided in the safety circuit of the present application, when in a safe situation, the robot can be stopped to work, realizing the safety function. Moreover, the safety function module is provided in the safety circuit, and there is no need to purchase relevant safety function modules separately, so the cost is lower.

[0026] To make the above objects, features, and advantages of the present application more obvious and understandable, the following specific embodiments are given in conjunction with the accompanying drawings and are described in detail as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and thus should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0028] Figure 1 The first module schematic diagram of the safety circuit provided by the embodiment of the present application.

[0029] Figure 2 This is the second schematic diagram of the module of the safety circuit provided by the embodiment of the present application.

[0030] Figure 3 This is the third schematic diagram of the module of the safety circuit provided by the embodiment of the present application.

[0031] Figure 4 This is the fourth schematic diagram of the module of the safety circuit provided by the embodiment of the present application.

[0032] Figure 5 This is a schematic diagram of a circuit of the safety function module provided by the embodiment of the present application.

[0033] Figure 6 This is another schematic diagram of a circuit of the safety function module provided by the embodiment of the present application.

[0034] In the figure: 100 - safety circuit; 110 - safety switch; 120 - safety function module; 130 - driver; 140 - controller; P1 - first NOT gate; P2 - second NOT gate; P3 - third NOT gate; P4 - fourth NOT gate; P5 - fifth NOT gate; P6 - sixth NOT gate; P7 - first output driver; P8 - second output driver; P9 - alarm output driver; D1 - first flip - flop; D2 - second flip - flop; U1 - first AND gate; U2 - second AND gate. Detailed implementation manners

[0035] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Usually, the components of the embodiments of the present application described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.

[0036] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application claimed, but merely represents selected embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts fall within the scope of protection of the present application.

[0037] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for descriptive distinction and cannot be understood as indicating or implying relative importance.

[0038] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0039] In the description of the present application, it should be noted that the orientation or positional relationship indicated by the terms "upper", "lower", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the product of this application is customarily placed during use. It is only for the convenience of describing the present application and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation to the present application.

[0040] In the description of the present application, it should also be noted that unless otherwise clearly specified and defined, the terms "set" and "connect" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific circumstances.

[0041] The following will describe in detail some embodiments of the present application with reference to the drawings. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0042] As described in the background art, currently most robots do not have safety functions or have not passed safety function certification. However, with the gradual strengthening of safety awareness, more and more regions require that related devices circulating (sold) in the market must meet safety functions, that is, they must pass safety function certification.

[0043] In view of this, the present application provides a safety circuit, which realizes the safety function design through a safety function module composed of electronic devices, meets the safety function and safety risk assessment, meets the safety function certification, and can thus meet the safety function level requirements of the robot industry and the traditional automation industry.

[0044] An exemplary description of the safety circuit provided by this application is as follows:

[0045] Please refer to Figures 1 to 4 , as a possible implementation manner of this application, the safety circuit 100 includes a safety function module 120, a controller 140, and a driver 130. The controller 140 is electrically connected to the safety function module 120 and the driver 130 respectively, and the safety function module 120 is used to be connected to a power supply, and the driver 130 is used to be electrically connected to a motor.

[0046] It should be noted that, as an application scenario, the safety circuit 100 provided by this application can be applied to a robot. Of course, the safety circuit 100 provided by this application can also be applied to other devices that require safety function design, and this application does not make any limitations in this regard. At the same time, the robot described in this application can be an intelligent walking robot, such as an intelligent housekeeper robot, or an automated equipment robot, such as a machine used during the elongation process of a production line, and this application does not make any limitations in this regard either.

[0047] Moreover, as an optional implementation manner, the safety circuit provided by this application can also be encapsulated into a module, and this module can be installed on any automated equipment, thereby realizing the safety function.

[0048] During the actual application process, when it is necessary to control the actions of the robot, the controller 140 will first check whether the robot system and hardware are correct. If a problem is detected during the check, an alarm signal will be generated, etc., to play a role in prompting the operator; when no problem is detected during the check, the safety switch 110 will be released.

[0049] Furthermore, as an optional implementation manner, the safety circuit 100 further includes a safety switch 110. The safety function module 120 is used to be electrically connected to the safety switch 110, and the controller 140 is also electrically connected to the safety switch 110.

[0050] Among them, the safety switch 110 described in this application can be a switch in the form of a button or a touch screen click switch. As long as it can achieve interaction with the robot system, it can be used as the safety switch 110 described in this application. And the release of the safety switch 110 mentioned in this application means that the operator can operate the safety switch 110 to achieve signal interaction with the robot.

[0051] For example, taking the safety switch 110 as a button as an example for description, when the safety switch 110 is not released, the safety switch 110 is in a locked state, and the operator cannot press this button; or this button is in an offline state, and even if the operator can press this button, data interaction with the robot cannot be achieved through the button. When the safety switch 110 is released, after the operator presses this button, an emergency stop signal can be sent to the robot.

[0052] Meanwhile, when it is checked that there are no problems with the robot system and hardware, etc., the robot system is powered on, and then the robot is started to make the robot start to move. For example, if the robot is applied to pipeline production, the production line is controlled to start running.

[0053] Among them, when the robot is working normally, the controller 140 can control the safety function module 120 to be in the powered-on state, so that the driver 130 drives the motor to work, and then the robot moves. For example, when it is checked that there are no problems with the robot, the controller 140 can send an enabling signal Pwr_en to the safety function module 120, and the safety function module 120 is powered on after receiving the enabling signal. And when the safety function module 120 is powered on, the power supply can supply power to the driver 130, and then drive the motor to work.

[0054] When in a safe situation, the safety function module can cut off the power supply to the driver, and then stop the motor from working to achieve the safety function.

[0055] Among them, the safe situation refers to the situation where it is necessary to control the motor to stop running. For example, when someone approaches the device carrying the safety function module, since a safety accident may occur, it is necessary to control the motor to stop running. Or, when a fault of the safety circuit itself is detected, it is also determined that it is in a safe situation at this time, so the safety function module can also cut off the power supply to the driver at this time.

[0056] As an alternative implementation, when a safe situation occurs, for example, during the operation of the robot, a safety accident is found, and the operator immediately presses the safety switch 110. At this time, when the safety function module 120 detects the emergency stop signal sent by the safety switch 110, it will switch to the powered-off state, that is, cut off the power supply to the driver 130 to stop the motor from running.

[0057] As another implementation of the present application, the safety circuit can also adaptively identify the safe situation. For example, a plurality of sensors are arranged in the driver. When it is detected that it is in a safe situation, the driver can send information to the controller, and then the controller is used to control the safety function module to cut off the power supply to the driver. Or, the safety function module itself can identify the safe situation. For example, when it is identified that someone is approaching, the power supply to the driver is cut off. The present application does not make any limitation on this.

[0058] Optionally, the present application does not make any limitation on the connection manner of the safety function module 120, the controller 140, the driver 130, and the safety switch 110. For example, please refer to Figure 2, In addition to the above connection methods, the present application can also adopt a connection where the controller 140 is respectively connected to the safety function module 120, the driver 130, and the safety switch 110 is also respectively connected to the safety function module 120 and the driver 130. The present application does not make any limitations in this regard. Furthermore, when the safety switch 110 sends a signal, both the safety function module 120 and the driver 130 can receive the signal, and the driver 130 can perform corresponding processing on the signal and send it to the controller 140.

[0059] Optionally, the safety circuit 100 provided by the present application further includes an AC / DC module, which is electrically connected to the power supply and the controller 140 respectively. Among them, the power supply can be mains electricity. By setting the AC / DC module, the power supply for the operation of the controller 140 can be provided.

[0060] Among them, the safety function module 120 can be a safety function design implemented by using electronic devices. As an alternative implementation, the safety function module 120 includes a trigger, a control unit, and an output unit. The safety switch 110 is electrically connected to the input terminals of the trigger and the control unit respectively, the controller 140 is electrically connected to the input terminals of the trigger and the control unit, the output terminal of the trigger is electrically connected to the input terminal of the control unit, the output terminal of the control unit is electrically connected to the output unit, and the output unit is electrically connected to the driver 130. Moreover, the control unit provided by the present application can control the conduction and disconnection of the output unit according to the signals of the safety switch 110, the trigger, and the controller 140, so as to control the operating state of the driver 130.

[0061] As an alternative implementation, please refer to Figure 4 , the present application adopts a dual-loop to achieve control, thereby improving the safety level.

[0062] That is, the trigger includes a first trigger D1 and a second trigger D2, the control unit includes a first gate circuit and a second gate circuit, the safety switch 110 includes a first switch and a second switch. The first switch is electrically connected to the input terminals of the first trigger D1 and the first gate circuit respectively, the second switch is electrically connected to the input terminals of the second trigger D2 and the second gate circuit respectively, the controller 140 is electrically connected to the input terminals of the first trigger D1, the second trigger D2, the first gate circuit, and the second gate circuit respectively, and the output terminals of the first gate circuit and the second gate circuit are both electrically connected to the output unit.

[0063] Among them, the signals of the first switch and the second switch are synchronized, that is, the first switch and the second switch are both at a high level or both at a low level at the same time. In practical applications, the safety switch 110 can be only one, and this safety switch 110 can simultaneously trigger the signals of the first switch and the second switch. And the controller 140 can send an enable signal to the first trigger D1, the second trigger D2, the first gate circuit, and the second gate circuit.

[0064] Among them, the flip-flop provided in this application can be a D flip-flop. Of course, in some other embodiments, the type of the flip-flop can also be other types, such as a JK flip-flop. The first gate circuit and the second gate circuit can also be AND gates or NAND gates.

[0065] Hereinafter, it is taken as an example that the safety switch 110 defaults to high-validity triggering for emergency stop, the enable electrical signal of the controller 140 defaults to low-validity enable input, the flip-flop is a D flip-flop, and both the first gate circuit and the second gate circuit are AND gates for illustration.

[0066] On this basis, the safety function module 120 further includes a first NOT gate P1, a second NOT gate P2, a third NOT gate P3, a fourth NOT gate P4, a fifth NOT gate P5, and a sixth NOT gate P6. The input end of the first NOT gate P1 is electrically connected to the first switch, and the output end of the first NOT gate P1 is respectively electrically connected to the D pin of the first flip-flop D1, the input end of the second NOT gate P2, and the first gate circuit. The output end of the second NOT gate P2 is electrically connected to the R pin of the first flip-flop D1; the input end of the third NOT gate P3 is electrically connected to the controller 140, and the output end of the third NOT gate P3 is respectively electrically connected to the C pin of the first flip-flop D1 and the first gate circuit; the input end of the fourth NOT gate P4 is electrically connected to the second switch, and the output end of the fourth NOT gate P4 is respectively electrically connected to the D pin of the second flip-flop D2, the input end of the fifth NOT gate P5, and the second gate circuit. The output end of the fifth NOT gate P5 is electrically connected to the R pin of the second flip-flop D2; the input end of the sixth NOT gate P6 is electrically connected to the controller 140, and the output end of the sixth NOT gate P6 is respectively electrically connected to the C pin of the second flip-flop D2 and the second gate circuit. And, the S pins of the first flip-flop D1 and the second flip-flop D2 are both grounded, and the pins of the first flip-flop D1 and the second flip-flop D2 are left unconnected. The Q pin of the first flip-flop D1 is respectively electrically connected to the first gate circuit and the second gate circuit, and the Q pin of the second flip-flop is also respectively electrically connected to the first gate circuit and the second gate circuit.

[0067] Meanwhile, in order to play a prompting role, the safety function module 120 further includes an alarm unit, and the alarm unit is respectively electrically connected to the output ends of the first gate circuit and the second gate circuit.

[0068] As a possible implementation manner, the alarm unit includes a first triode, a second triode, and an alarm output driver P9. The emitter of the first triode is electrically connected to the output end of the first gate circuit, the collector of the first triode is electrically connected to the alarm output driver P9, the base of the first triode is electrically connected to the collector of the second triode, the emitter of the second triode is grounded, and the base of the second triode is electrically connected to the output end of the second gate circuit. The alarm output driver P9 can be connected to an external alarm device, such as an indicator light, an alarm bell, or an electrical signal lamp and other devices, and the signal output by the alarm output driver P9 can control the external alarm device.

[0069] In this implementation, the signal of the first switch is denoted as Estop1, the signal of the first switch is denoted as Estop2, the enable signal sent by the controller 140 is denoted as Pwr_en, and the signal output by the alarm output driving P9 is denoted as Flag.

[0070] It can be understood that:

[0071] When in the first scenario, that is, when the safety circuit is in the normal working condition:

[0072] When preparing to start running, the controller 140 releases the emergency stop button. At this time, Estop1 and Estop2 = 0 (L), Pwr_en = 1 (H) (held);

[0073] At this time, the inputs of the first flip-flop D1 and the second flip-flop D2 are: R = 0 (not reset), D = 1, C = 0; the output: Q = 0 (held);

[0074] The inputs of the first AND gate U1 and the second AND gate U2 are: A = 0, B = 1, C = 0, D = 0; the output: F = 0;

[0075] The external outputs are: Ctr1 = 0, Ctr2 = 1, Flag = 0 (alarm).

[0076] When the system is controlling the operation, the controller 140 outputs enable: Estop1 and Estop2 = 0 (L), Pwr_en = 0 (L) (enabled). At this time:

[0077] The inputs of the first flip-flop D1 and the second flip-flop D2 are: R = 0 (not reset), D = 1, C = ↑ (rising edge); the output: Q = D = 1;

[0078] The inputs of the first AND gate U1 and the second AND gate U2 are: A = 1, B = 1, C = 1, D = 1; the output: F = 1; at this time the output unit is turned on and the motor runs;

[0079] The external outputs are: Ctr1 = 1, Ctr2 = 0, Flag = 1 (not alarm).

[0080] From the above signal analysis, it can be seen that when the controller 140 does not control the robot to work during normal operation, the output unit is not turned on, the motor does not run, and the system alarms; when the controller 140 controls the robot to work, the output unit is turned on, the motor runs, and the system does not alarm.

[0081] When in the second scenario, that is, when the safety circuit is in the first safety condition:

[0082] During operation, the operator presses the emergency stop and then releases it. Estop1 and Estop2 = 1, Pwr_en = 0. At this time:

[0083] Inputs of the first flip-flop D1 and the second flip-flop D2: R = 1 (reset), D = 0, C = 1; Output: Q = 0 (reset);

[0084] Inputs of the first AND gate U1 and the second AND gate U2: A = 0, B = 0, C = 0, D = 1; Output: F = 0;

[0085] External outputs: Ctr1 = 0, Ctr2 = 1, Flag = 0 (alarm).

[0086] That is, after the emergency stop, the system cannot be automatically started.

[0087] When maintaining the system state and releasing (restoring) the emergency stop button: At this time, Estop1 and Estop2 = 0 (L), Pwr_en = 0. At this time:

[0088] Inputs of the first flip-flop D1 and the second flip-flop D2: R = 0 (not reset), D = 1, C = 1; Output: Q = 0 (hold);

[0089] Inputs of the first AND gate U1 and the second AND gate U2: A = 0, B = 1, C = 0, D = 1; Output: F = 0;

[0090] External outputs: Ctr1 = 0, Ctr2 = 1, Flag = 0 (alarm).

[0091] That is, the system is not allowed to run automatically after the emergency stop and must be enabled again.

[0092] When in the second scenario, that is, when the safety circuit is in the second safety situation, first enable Pwr_en and then release the emergency stop.

[0093] At this time, the system is controlled to run, and the controller 140 outputs enable: Estop1 and Estop2 = 1, Pwr_en = 0 (enabled). At this time:

[0094] Inputs of the first flip-flop D1 and the second flip-flop D2: R = 1 (reset), D = 0, C = ↑ (rising edge); Output: Q = 0 (reset);

[0095] Inputs of the first AND gate U1 and the second AND gate U2: A = 0, B = 0, C = 0, D = 1; Output: F = 0;

[0096] External outputs: Ctr1 = 0, Ctr2 = 1, Flag = 0 (alarm).

[0097] When the emergency stop button is released (restored), Estop1 and Estop2 == 0, Pwr_en = 0. At this time:

[0098] Inputs of the first flip-flop D1 and the second flip-flop D2: R = 0 (not reset), D = 1, C = 1; Output: Q = 0 (held);

[0099] Inputs of the first AND gate U1 and the second AND gate U2: A = 0, B = 1, C = 0, D = 1; Output: F = 0;

[0100] External outputs: Ctr1 = 0, Ctr2 = 1, Flag = 0 (alarm).

[0101] From the above signal analysis, it can be seen that before enabling the system, the emergency stop button must be released first to run the system.

[0102] Moreover, it should be noted that the above implementation method is only one possible implementation method of this application. In the actual application process, other similar implementation methods can also be selected. For example:

[0103] In this application, the signals Estop1 and Estop2 default to high-validity triggering for emergency stop. Of course, the user can also choose low (L)-validity triggering for emergency stop. For example, by removing the first NOT gate P1 and the fourth NOT gate P4, or modifying the first NOT gate P1 and the fourth NOT gate P4 to use an inverter.

[0104] The enable signal Pwr_en is a power enable input, controlled by the controller 140. By default, it is a low (L)-validity enable input. Of course, the user can also choose high (H)-validity enable. For example, by removing the third NOT gate P3 and the sixth NOT gate P6, or modifying the third NOT gate P3 and the sixth NOT gate P6 to use an inverter.

[0105] This safety function module 120 further includes a first output driver P7 and a second output driver P8. The first output driver P7 is electrically connected to the output terminal of the first AND gate U1, and the second output driver P8 is electrically connected to the output terminal of the second AND gate U2. The first output driver P7 and the second output driver P8 output externally in a mutually exclusive manner, which is more in line with the safety function. Of course, according to the actual situation, it can also be modified to use two inverters or two non-inverters.

[0106] At the same time, the first gate circuit and the second gate circuit can also use NAND gates. When using NAND gates, an inverter can be added to the output terminal of the NAND gate, or the first triode and the second triode in the alarm unit can be adjusted.

[0107] Of course, the alarm output driver P9 in the alarm unit does not have to use the inverter in the figure, but can be modified to use a non-inverter.

[0108] Moreover, the output unit provided in this application includes a rectification unit, a relay unit, and a filtering unit. The rectification unit, the relay unit, and the filtering unit are electrically connected in sequence. The rectification unit is electrically connected to the power supply, the filtering unit is electrically connected to the driver 130, and the control unit is electrically connected to the relay unit. The controller 140 is used to control the conduction and disconnection of the relay unit to control the operating state of the driver 130. It can be understood that the output unit is equivalent to an AC / DC converter, which can convert the output 220V AC voltage into 310V DC voltage.

[0109] Moreover, in order to achieve safer operation, the output unit further includes a fuse and soft start, and this application does not make any limitations on this. By integrating the safety function module and the AC / DC converter into one module, the safety and stability of the robot during operation can be increased, and at the same time, the size is greatly reduced, which can reduce the system space requirement.

[0110] As another implementation manner of this application, please refer to Figure 6 , in order to reserve enough time for the system to process the emergency stop response of the robot or automation equipment and then trigger the safety function in hardware, which can be more reliable and safer. The safety circuit 100 provided in this application can also have an emergency stop trigger delay function.

[0111] That is, the safety function module 120 further includes a delay device, and the delay device is electrically connected to the safety switch 110 and the input end of the trigger respectively.

[0112] As a possible implementation manner of this application, please refer to Figure 5 , it can be understood that:

[0113] When in the first scenario, that is, when the safety circuit is in normal working condition: when preparing to start running, the controller 140 will release the emergency stop button. At this time, Estop1 and Estop2 = 0 (L), Pwr_en = 1 (H) (held);

[0114] At this time: Inputs of the first flip-flop D1 and the second flip-flop D2: R = 0 (not reset), D = 1, C = 0; Output: Q = 0 (held);

[0115] Inputs of the first AND gate U1 and the second AND gate U2: A = 0, B = 1, C = 0, D = 0; Output: F = 0;

[0116] External output: Ctr1 = 0, Ctr2 = 1, Flag = 0 (alarm).

[0117] The system controls the operation, and the controller 140 outputs enable: Estop1 and Estop2 = 0 (L), Pwr_en = 0 (L) (enabled). At this time:

[0118] Inputs of the first flip-flop D1 and the second flip-flop D2: R = 0 (not reset), D = 1, C = ↑ (rising edge); Output: Q = D = 1;

[0119] Inputs of the first AND gate U1 and the second AND gate U2: A = 1, B = 1, C = 1, D = 1; Output: F = 1; At this time, the output unit is turned on and the motor runs;

[0120] External output: Ctr1 = 1, Ctr2 = 0, Flag = 1 (no alarm).

[0121] From the above signal analysis, it can be seen that when the controller 140 does not control the robot to work during normal operation, the output unit is not turned on, the motor does not run, and the system alarms; when the controller 140 controls the robot to work, the output unit is turned on, the motor runs, and the system does not alarm.

[0122] When in the second scenario, that is, when the safety circuit is in the first safety situation:

[0123] When working, the operator presses the emergency stop and then releases the emergency stop, Estop1 and Estop2 = 1, Pwr_en = 0. At this time:

[0124] Inputs of the first flip-flop D1 and the second flip-flop D2: R = 0 (not reset), D = 1, C = 1; Output: Q = 1 (held);

[0125] Inputs of the first flip-flop D1 and the second flip-flop D2: A = 1, B = 1, C = 1, D = 1; Output: F = 1;

[0126] External output: Ctr1 = 1, Ctr2 = 0, Flag = 1 (no alarm);

[0127] After a delay of Td:

[0128] Inputs of the first flip-flop D1 and the second flip-flop D2: R = 1 (reset), D = 0, C = 1; Output: Q = 0 (reset);

[0129] Inputs of the first AND gate U1 and the second AND gate U2: A = 0, B = 0, C = 0, D = 1; Output: F = 0;

[0130] External output: Ctr1 = 0, Ctr2 = 1, Flag = 0 (alarm).

[0131] When maintaining the system state and releasing (restoring) the emergency stop button: At this time, Estop1 and Estop2 = 0(L), Pwr_en = 0

[0132] Inputs of the first flip-flop D1 and the second flip-flop D2: R = 0 (not reset), D = 1, C = 1; Output: Q = 0 (hold);

[0133] Inputs of the first AND gate U1 and the second AND gate U2: A = 0, B = 1, C = 0, D = 1; Output: F = 0;

[0134] External outputs: Ctr1 = 0, Ctr2 = 1, Flag = 0 (alarm);

[0135] That is, after an emergency stop, the system is not allowed to run automatically and must be enabled again.

[0136] When in the third scenario, that is, when the safety circuit is in the first safety situation: First enable Pwr_en, and then release the emergency stop.

[0137] At this time, the system controls the operation, and the controller 140 outputs enabling: Estop1 and Estop2 = 1, Pwr_en = 0 (enabled).

[0138] Inputs of the first flip-flop D1 and the second flip-flop D2: R = 1 (reset), D = 0, C = ↑ (rising edge); Output: Q = 0 (reset);

[0139] Inputs of the first AND gate U1 and the second AND gate U2: A = 0, B = 0, C = 0, D = 1; Output: F = 0;

[0140] External outputs: Ctr1 = 0, Ctr2 = 1, Flag = 0 (alarm).

[0141] When releasing (restoring) the emergency stop button, when Estop1 and Estop2 == 0, Pwr_en = 0:

[0142] Inputs of the first flip-flop D1 and the second flip-flop D2: R = 0 (not reset), D = 1, C = 1; Output: Q = 0 (hold);

[0143] Inputs of the first AND gate U1 and the second AND gate U2: A = 0, B = 1, C = 0, D = 1; Output: F = 0;

[0144] External outputs: Ctr1 = 0, Ctr2 = 1, Flag = 0 (alarm).

[0145] From the above signal analysis, it can be seen that before enabling the system, the emergency stop button must be released first in order to run the system.

[0146] Moreover, it should also be noted that the controller 140 and the driver 130 provided in this application are also communicatively connected to the safety switch 110, and this communicative connection can be a direct or indirect connection. For example, the controller 140 is communicatively connected to an external host computer system via a LAN bus, and the external host computer system can obtain the status of the safety switch 110 in real time.

[0147] When the operator presses the safety switch 110, the safety function module 120, the controller 140, and the driver 130 can simultaneously detect the emergency stop signals (Estop1, Estop2). Moreover, after the safety function module 120 monitors the Estop1 and Estop2 signals, it starts timing; before reaching the maximum delay of the safety circuit 100, if an invalid Pwr_en command is received, the input end AC power supply will be immediately cut off; if the maximum delay is reached, the safety circuit 100 will immediately cut off the input end AC power supply to prevent the further expansion of safety accidents. At this time, the safety function circuit belongs to secondary protection for a safer handling in case of the failure of the controller 140.

[0148] After the controller 140 monitors the Estop1 and Estop2 signals, the system starts to plan deceleration according to the position and speed status of the robot, and stops the robot at the appropriate position at the fastest speed. Then, the motor is locked and braked to prevent the robotic arm from flying out due to inertia. At the same time, it will also force Pwr_en to be invalid. It should be noted that during the deceleration process, the power of the controller 140 comes from the energy stored in the capacitor of the safety function module 120.

[0149] After the driver 130 monitors the Estop1 and Estop2, it starts timing. When the maximum delay of the driver 130 is reached, if the system has not processed the robotic arm yet, for example, there may be a situation where it is not detected or the controller 140 is damaged. The driver 130 starts to forcefully stop the robotic arm and locks the braking motor to prevent the expansion of safety accidents.

[0150] At the same time, after clearing the problem, when the emergency stop button is released, the system does not allow automatic operation at this time. It must be restarted by the system. Then, the controller 140 first forces Pwr_en to be invalid, and then enables Pwr_en to power on the safety function module 120, and then runs the robot according to the normal process.

[0151] On this basis, the embodiment of this application also provides a robot, and this robot includes the safety circuit 100 as described above.

[0152] In summary, the embodiments of the present application provide a safety circuit and a robot. The safety circuit includes a safety function module, a controller, and a driver. The controller is electrically connected to the safety function module and the driver respectively. The safety function module is used to be connected to a power supply, and the driver is used to be electrically connected to a motor. Among them, when the robot is in normal operation, the controller is used to control the safety function module to be in the powered-on state, so that the driver drives the motor to work; the safety function module is used to cut off the power supply to the driver when the safety circuit is in a safe situation. Since the safety function module is provided in the safety circuit of the present application, when in a safe situation, the robot can be stopped from working to achieve the safety function. Moreover, the safety function module is provided in the safety circuit, and there is no need to separately purchase relevant safety function modules, so the cost is lower.

[0153] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

[0154] For those skilled in the art, it is obvious that the present application is not limited to the details of the above exemplary embodiments, and can be implemented in other specific forms without departing from the spirit or basic characteristics of the present application. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present application is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be included in the present application. Any reference signs in the claims should not be regarded as limiting the claims involved.

Claims

1. A safety circuit, characterized in that, The safety circuit includes a safety function module, a controller, and a driver. The controller is electrically connected to the safety function module and the driver respectively. The safety function module is used to be connected to a power supply, and the driver is used to be electrically connected to a motor. Among them, when the safety circuit is in normal operation, the controller is used to control the safety function module to be in the powered-on state, so that the driver drives the motor to work; the safety function module is used to cut off the power supply to the driver when the safety circuit is in a safety situation; the safety circuit includes a safety switch. The safety function module includes a trigger, a control unit, and an output unit. The safety switch is electrically connected to the trigger and the input end of the control unit respectively. The controller is electrically connected to the trigger and the input end of the control unit. The output end of the trigger is electrically connected to the input end of the control unit. The output end of the control unit is electrically connected to the output unit. The output unit is electrically connected to the driver. Among them, the control unit is used to control the conduction and disconnection of the output unit according to the signals of the safety switch, the trigger, and the controller, so as to control the working state of the driver; the trigger includes a first trigger and a second trigger. The control unit includes a first gate circuit and a second gate circuit. The safety switch includes a first switch and a second switch. The first switch is electrically connected to the first trigger and the input end of the first gate circuit respectively. The second switch is electrically connected to the second trigger and the input end of the second gate circuit respectively. The controller is electrically connected to the first trigger, the second trigger, the input end of the first gate circuit, and the input end of the second gate circuit respectively. The output ends of the first gate circuit and the second gate circuit are both electrically connected to the output unit; the safety function module further includes a first NOT gate, a second NOT gate, a third NOT gate, a fourth NOT gate, a fifth NOT gate, and a sixth NOT gate. The input end of the first NOT gate is electrically connected to the first switch. The output end of the first NOT gate is electrically connected to the D pin of the first trigger, the input end of the second NOT gate, and the first gate circuit respectively. The output end of the second NOT gate is electrically connected to the R pin of the first trigger; the input end of the third NOT gate is electrically connected to the controller, and the output end of the third NOT gate is electrically connected to the C pin of the first trigger and the first gate circuit respectively; the input end of the fourth NOT gate is electrically connected to the second switch. The output end of the fourth NOT gate is electrically connected to the D pin of the second trigger, the input end of the fifth NOT gate, and the second gate circuit respectively. The output end of the fifth NOT gate is electrically connected to the R pin of the second trigger; the input end of the sixth NOT gate is electrically connected to the controller, and the output end of the sixth NOT gate is electrically connected to the C pin of the second trigger and the second gate circuit respectively; the Q pin of the first trigger is electrically connected to the first gate circuit and the second gate circuit respectively. The Q pin of the second trigger is also electrically connected to the first gate circuit and the second gate circuit respectively; The safety function module further includes an alarm unit, and the alarm unit is electrically connected to the output ends of the first gate circuit and the second gate circuit respectively.

2. The safety circuit according to claim 1, wherein The alarm unit includes a first triode, a second triode and an alarm output driver. The emitter of the first triode is electrically connected to the output end of the first gate circuit, the collector of the first triode is electrically connected to the alarm output driver, the base of the first triode is electrically connected to the collector of the second triode, the emitter of the second triode is grounded, and the base of the second triode is electrically connected to the output end of the second gate circuit.

3. The safety circuit according to claim 1, characterized in that, The first gate circuit and the second gate circuit include an AND gate or a NAND gate.

4. The safety circuit according to claim 1, characterized in that, The safety function module further includes a time delay device, and the time delay device is electrically connected to the safety switch and the input end of the trigger respectively.

5. The safety circuit according to claim 1, characterized in that, The output unit includes a rectification unit, a relay unit and a filtering unit. The rectification unit, the relay unit and the filtering unit are electrically connected in sequence. The rectification unit is electrically connected to the power supply, the filtering unit is electrically connected to the driver, the control unit is electrically connected to the relay unit, and the controller is used to control the conduction and disconnection of the relay unit to control the working state of the driver.

6. A robot, characterized in that, The robot includes the safety circuit according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Industrial robot safety control system as well as backup safety circuit and safety module

    CN104777805A

  • Safety circuit and robot

    CN211415177U