Load control system

By using collaborative security authentication between the control device and the power conversion device, and leveraging the collaborative authentication generation function of hardware and software, the problem of functional confidentiality caused by parameter leakage of the motor control device is solved, and functional security is achieved in legitimate combinations.

CN115883144BActive Publication Date: 2026-04-14FUJI ELECTRIC CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2017-12-29
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

In existing load control systems, parameter leakage of motor control devices leads to the inability to maintain functional confidentiality, and password leakage between multiple devices may result in functional leakage.

Method used

By using collaborative safety authentication between the control device and the power conversion device, and leveraging the collaborative generation capabilities of hardware and software, it ensures that functions are generated only when authentication is successful. This includes authentication of motor identification symbols, program codes, and safety authentication signals, ensuring that functions are used only in legitimate combinations.

Benefits of technology

It enhances the confidentiality of the function, prevents leakage of the function when the device is illegally combined or removed separately, and improves security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115883144B_ABST
    Figure CN115883144B_ABST
Patent Text Reader

Abstract

The load control system is configured to generate, by software, a function capable of using the power conversion device for a prescribed use in a case where hardware and software-based cooperative security authentication is established by cooperation between at least the control device and the power conversion device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of Chinese invention patent application filed on December 29, 2017, with application number 201711485559.8 and invention title "Load Control System". Technical Field

[0002] This invention relates to a load control system, and more particularly to a load control system equipped with a control device. Background Technology

[0003] Previously, a load control system equipped with a control device was known. Such a load control system was disclosed in Japanese Patent No. 5877312.

[0004] Japanese Patent No. 5877312 discloses a motor control system equipped with a motor control device. In this motor control system, parameters for controlling the motor (position loop gain, speed loop gain, etc.) are pre-stored at the time of manufacture. Furthermore, access to the motor control device (reading parameters, setting parameters, etc.) is prohibited at the time of manufacture.

[0005] When access to the motor control device is permitted, firstly, parameters for controlling the motor are sent to the motor control device from an external device. Then, within the motor control device, if it is confirmed that the parameters stored within the motor control device match the parameters sent from the external device, access to the motor control device is permitted. That is, the parameters stored at the factory of the motor control device serve as the password for granting access to the motor control device. Furthermore, the parameters are individually set for each motor control device (different for each motor control device), therefore, unlike situations where multiple motor control devices can be accessed using a single password, access to multiple motor control devices cannot be granted even if the password is leaked.

[0006] However, in the electric motor control system disclosed in Japanese Patent No. 5877312, although parameters to be used as passwords are individually set for each electric motor control device, access to the electric motor control device corresponding to that password is still possible if the password is leaked. This leads to several drawbacks, such as the leakage of functions (e.g., unique circuit functions of the devices) contained within the electric motor control device and the devices controlled by it. In other words, if the password for one of the multiple devices is leaked, the confidentiality of the functions of the other devices cannot be maintained. Summary of the Invention

[0007] This invention was made to solve the problems described above, and one object of this invention is to provide a load control system that can improve the confidentiality of functions.

[0008] To achieve the above objectives, a load control system based on one aspect of the present invention includes: a control device; a power conversion device controlled by the control device; and a load from which power is supplied, wherein the load control system is configured to: generate, in the power conversion device, a function capable of using the power conversion device for a specified purpose by software when a cooperative security authentication is established, the cooperative security authentication being a cooperative security authentication based on at least one of hardware and software, performed by cooperation between the control device and the power conversion device and the load.

[0009] In a load control system based on one aspect of the present invention, as described above, the configuration is such that, when cooperative security authentication is successful, a function enabling the power conversion device to perform a specified purpose is generated by software in the power conversion device. This cooperative security authentication is performed through cooperation between the control device and at least one of the control device and the power conversion device in the load, and is based on at least one of hardware and software. Therefore, when cooperative security authentication fails, the function enabling the power conversion device to perform the specified purpose is not generated in the power conversion device. As a result, even if the internal workings of the power conversion device are analyzed, the function enabling the power conversion device to perform the specified purpose will not be leaked because it is not generated at all. That is, the confidentiality of the function enabling the power conversion device to perform the specified purpose is maintained by the cooperation of multiple devices, including at least the control device and the power conversion device; therefore, even if the password of one of the multiple devices is leaked, the confidentiality of the function is maintained. This improves the confidentiality of the function.

[0010] Furthermore, cooperative safety certification requires cooperation between at least the control device and the power conversion device. Therefore, if the power conversion device is removed from the load control system alone, or if it is removed from the load control system alone and combined with other loads that cannot be certified, cooperative safety certification will not be established. That is, no function is generated in these cases, and therefore no function is leaked. In addition, since no function is generated when safety certification fails, the power conversion device cannot be used alone for its intended purpose.

[0011] In a load control system based on the above aspect, it is preferable that, when cooperative security authentication is established, software is used to generate a function that enables the power conversion device to function as a frequency conversion device capable of outputting a first variable frequency or a first variable voltage. If configured in this way, the confidentiality of the function capable of outputting the first variable frequency or the first variable voltage can be maintained.

[0012] In this case, it is preferable that, in the event that the cooperative security certification is not established, the power conversion device becomes a frequency conversion device capable of outputting a second variable frequency or a second variable voltage, different from a frequency conversion device capable of outputting a first variable frequency or a first variable voltage. If configured in this way, in the event that the cooperative security certification is not established, the power conversion device can be used as a frequency conversion device capable of outputting a second variable frequency or a second variable voltage for a purpose different from that of a power conversion device capable of outputting a first variable frequency or a first variable voltage.

[0013] In a load control system based on the above aspect, it is preferable that, when a collaborative security authentication based on both hardware and software is established through cooperation between the control device and the power conversion device and at least the control device and the power conversion device in the load, the power conversion device generates a function through software that enables the power conversion device to be used for a specified purpose. If configured in this way, the collaborative security authentication is established based on both hardware and software, thus improving confidentiality compared to cases where the collaborative security authentication is established based on only one of the hardware or software.

[0014] In a load control system based on the above-mentioned aspect, it is preferable to configure the power conversion device such that, when a collaborative security authentication based on at least one of hardware and software, achieved through cooperation between the control device, the power conversion device, and the load, is established, the power conversion device generates a function via software that enables it to be used for a specified purpose. If configured in this way, confidentiality (security level) can be improved compared to the case where collaborative security authentication is established solely through cooperation between the control device and the power conversion device.

[0015] In a load control system based on the above aspect, it is preferable that the control device and the power conversion device are connected via hardware wiring, and the hardware-based cooperative security authentication includes authenticating the following: communication between the control device and the power conversion device is possible via the wiring. If configured in this way, hardware-based cooperative security authentication based on the wiring can be performed.

[0016] In this case, it is preferable that the control device is configured to send program code to the power conversion device to generate functions that enable the power conversion device to be used for a specified purpose. Hardware-based cooperative security authentication includes authenticating a function generation permission signal, which is output when communication between the control device and the power conversion device is possible via wiring. This function generation permission signal allows the function to be generated via the program code. If configured this way, if communication between the control device and the power conversion device is not possible via wiring, the function generation permission signal is not output, and therefore the function is not generated. This prevents function leakage.

[0017] In the aforementioned load control system that authenticates the function generation permission signal, it is preferable to further include a switch, which is hardware that turns on when the function generation permission signal is authenticated. The load control system is configured such that the switch is turned on when the function generation permission signal is authenticated, thereby outputting a signal from a software-based function block via the switch. With this configuration, collaborative security authentication combining hardware and software can be performed.

[0018] In a load control system based on the above aspect, preferably, the load includes inherent load determination information, which is stored in a control device and a power conversion device. The control device is configured to send the stored load determination information to the power conversion device. Software-based cooperative security authentication includes authentication if the load determination information stored in the power conversion device matches the load determination information sent from the control device. If configured this way, when a pre-included load in the load control system is replaced with another load, the load determination information of the pre-included load in the load control system differs from the load determination information of the replaced load. Therefore, cooperative security authentication fails when the load is replaced, thus preventing the generation (operation) of a function when the load is replaced.

[0019] In a load control system based on the above-mentioned aspect, it is preferable that the control device is configured to send program code to a power conversion device, which generates functions that enable the power conversion device to be used for a specified purpose. Software-based cooperative security authentication includes authenticating the program code sent from the control device based on predetermined conditions. If configured in this way, when the control device pre-included in the load control system is replaced with another control device, the program code sent from the other control device does not meet the predetermined conditions, and therefore cooperative security authentication fails. This prevents the generation (operation) of functions when the control device is replaced.

[0020] In a load control system based on the above aspect, it is preferable that at least one of the control device, the power conversion device, and the load has an inherent security authentication. The load control system is configured such that, when the inherent security authentication of at least one of the control device, the power conversion device, and the load is established, and the cooperative security authentication is established, software in the power conversion device generates a function that enables the power conversion device to be used for a specified purpose. If configured in this way, in addition to the cooperative security authentication, the inherent security authentication is also required, thus further enhancing confidentiality.

[0021] In this case, it is preferable that the inherent security authentication of the control device includes a control device security authentication for initiating the control device. If configured in this way, in addition to the cooperative security authentication, the control device security authentication of the control device also needs to be established, thus further enhancing confidentiality.

[0022] In the aforementioned load control system with inherent security authentication, it is preferable that the load includes load determination information inherent to the load, and the inherent security authentication of the load includes load security authentication that uses a password to obtain the load determination information from the load. If configured in this way, in addition to collaborative security authentication, load security authentication also needs to be established, thus further enhancing confidentiality.

[0023] To achieve the above objectives, a load control system based on one aspect of the present invention includes: a control device; a power conversion device controlled by the control device; and a load from which power is supplied, wherein the power conversion device includes a standard functional area and a dedicated functional area, the standard functional area having a frequency setting unit, and the dedicated functional area having a plurality of function blocks pre-configured, wherein the load control system is configured to: when a cooperative security authentication is established, generate, via software, a function in the power conversion device that enables the power conversion device to be used for a specified purpose, wherein the cooperative security authentication is performed by cooperation between the control device and at least one of the control device and the power conversion device among the load, and is based on at least one of hardware and software; the load control system is configured to: when the cooperative security authentication is established, generate, via software, a function that enables the power conversion device to be used for a specified purpose. The load control system is configured such that, in the event that the cooperative security authentication fails, the power conversion device becomes a frequency conversion device that outputs a second variable frequency or a second variable voltage, different from the frequency conversion device capable of outputting the first variable frequency or the first variable voltage, based on the instruction value set by the frequency setting unit of the standard functional area. The control device is configured to send program code to the power conversion device, which generates a function that enables the power conversion device to be used for a specified purpose. The software-based cooperative security authentication includes authenticating the program code sent from the control device based on predetermined conditions. In the event that the cooperative security authentication succeeds, based on the program code sent from the control device, the plurality of function blocks located in the dedicated functional area function in a predetermined order, thereby generating a function that can be used for the specified purpose.

[0024] According to the present invention, as described above, the confidentiality of the function can be improved. Attached Figure Description

[0025] Figure 1 This is a block diagram of an electric motor control system based on one embodiment of the present invention.

[0026] Figure 2 This is a block diagram (showing functional blocks) of a power conversion device based on one embodiment of the present invention.

[0027] Figure 3 This is a diagram illustrating electric motor safety certification based on one embodiment of the present invention.

[0028] Figure 4This is a flowchart illustrating the cooperative safety authentication of a motor control system based on one embodiment of the present invention. Detailed Implementation

[0029] The embodiments that embody the present invention will now be described with reference to the accompanying drawings.

[0030] Reference Figures 1-4 The structure of the motor control system 100 based on this embodiment will be described below. Furthermore, the motor control system 100 is an example of the "load control system" claimed in the claims.

[0031] <Structure of Electric Motor Control System>

[0032] like Figure 1 As shown, the motor control system 100 includes a control device 1 such as a higher-level controller, a power conversion device 2 controlled by instructions from the control device 1, and a motor 3 supplied with power from the power conversion device 2. Furthermore, the motor 3 is an example of the "load" in the claims. Additionally, the motor control system 100 can be applied to, for example, conveyors, processing machines, air conditioners, etc.

[0033] Control device 1 and power conversion device 2 are connected via a dedicated cable 4a. Communication between control device 1 and power conversion device 2 via cable 4a is based on a dedicated protocol. That is, if control device 1 and power conversion device 2 are replaced with devices that do not use (or do not have) the dedicated protocol, communication between control device 1 and power conversion device 2 is impossible. Furthermore, communication via cable 4a is either analog or digital communication. Additionally, cable 4a is an example of the "wiring" specified in the claims.

[0034] The power conversion device 2 and the motor 3 are connected via cable 4b. Cable 4b is a standard wiring. Furthermore, the communication between the power conversion device 2 and the motor 3 is not based on a proprietary protocol.

[0035] <Structure of the control device>

[0036] Next, refer to Figure 2 To explain the structure of control device 1. Furthermore, in Figure 2 For convenience, two control devices 1 are depicted, but in reality, there is only one control device 1.

[0037] like Figure 2As shown, the configuration is as follows: in the control device 1, the motor identification symbol of the motor 3 is set (stored) as a dedicated code, and the stored motor identification symbol is sent to the power conversion device 2. Furthermore, the motor identification symbol is a symbol inherent to the motor 3. The motor 3 can be identified through the motor identification symbol. Additionally, the motor identification symbol is an example of the "load determination information" in the claims.

[0038] Furthermore, control device 1 is configured to send program code to power conversion device 2, which generates functions that enable power conversion device 2 to be used for a specified purpose. Additionally, control device 1 is configured to send frequency commands to power conversion device 2. Moreover, motor identification symbols, program code, and frequency commands are transmitted to power conversion device 2 via cable 4a. Furthermore, motor identification symbols, program code, and frequency commands are respectively sent to addresses 21a, 21b, and 21c, which are addresses defined for control device 1, based on a dedicated protocol. Furthermore, the frequency command is a command used to cause power conversion device 2 to output a desired frequency or a desired voltage.

[0039] Furthermore, control device 1 is configured to send a safety authentication signal and a code generation permission signal to power conversion device 2. Details of the safety authentication signal and the code generation permission signal will be described later.

[0040] In this embodiment, the control device 1 has inherent security authentication. Specifically, the control device 1 performs control device security authentication to enable its startup. Control device security authentication includes, for example, enabling the control device 1 to be in a state where software can be installed by initiating a deactivation procedure. Furthermore, control device security authentication enables software startup by outputting a multi-bit key specific to the control device 1. Additionally, control device security authentication allows for detailed model settings, changes to various access codes, and access code management by inputting the control device 1's setting access code. Moreover, this control device security authentication is an example of the "inherent security authentication" claimed in the claims.

[0041] <Structure of Power Conversion Device>

[0042] Next, refer to Figure 2 The structure of the power conversion device 2 will be explained below. Furthermore, the motor mutual authentication processing unit 22, safety authentication processing unit 23, program code authentication processing unit 24, code authentication unit 25, and special function unit 26, described below, are function blocks composed of software. These function blocks are located in the control unit (not shown) of the power conversion device 2.

[0043] like Figure 2As shown, the power conversion device 2 includes a standard functional area 2a and a dedicated functional area 2b. The standard functional area 2a is equipped with a frequency setting unit 31, a standard control circuit 32, and a PWM circuit 33. The desired frequency is set by the frequency setting unit 31, and the command value of the set frequency is input to the standard control circuit 32. Then, the PWM circuit 33 operates, and a voltage based on the frequency of the command value is output from the power conversion device 2 to the motor 3.

[0044] Furthermore, a motor mutual authentication processing unit 22 is provided in the dedicated functional area 2b. Motor identification symbols are input from the control device 1 to the motor mutual authentication processing unit 22. Moreover, in this embodiment, the motor mutual authentication processing unit 22 performs authentication (comparison) when the motor identification symbol stored in the power conversion device 2 matches the motor identification symbol sent from the control device 1. That is, the motor mutual authentication processing unit 22 is configured to perform cooperative security authentication, which is a software-based cooperative security authentication performed through cooperation between the control device 1, the power conversion device 2, and the motor 3.

[0045] Additionally, a security authentication processing unit 23 is provided in the dedicated functional area 2b. This unit is configured to send a security authentication signal from the control device 1 to the security authentication processing unit 23. Furthermore, the security authentication signal is a hardware-based (cable 4a) cooperative security authentication. Specifically, the security authentication signal authenticates when communication between the control device 1 and the power conversion device 2 is possible via the cable 4a. In other words, the security authentication signal is a signal sent from the control device 1 when the control device 1 and the power conversion device 2 are connected by a dedicated cable 4a and communication based on a dedicated protocol is possible. For example, the security authentication signal is sent when the voltage applied to the dedicated cable 4a is a predetermined voltage.

[0046] In addition, a program code authentication processing unit 24 is provided in the dedicated functional area 2b. The program code authentication processing unit 24 is configured to authenticate the program code sent from the control device 1, which is used to generate functions that enable the power conversion device 2 to be used for a specified purpose. Specifically, in this embodiment, the program code authentication processing unit 24 authenticates the program code sent from the control device 1 based on predetermined conditions (software-based cooperative security authentication).

[0047] For example, by having multiple function blocks 26a, 26b, and 26c, pre-set in the dedicated function unit 26, function in a predetermined order, a function enabling the power conversion device 2 to be used for a predetermined purpose is realized (generated). Furthermore, this predetermined order is pre-stored in the power conversion device 2. The program code sent from the control device 1 contains this predetermined order. Then, the program code authentication processing unit 24 authenticates (compares) whether the predetermined order pre-stored in the power conversion device 2 matches the predetermined order contained in the program code sent from the control device 1.

[0048] Furthermore, a code authentication unit 25 is provided in the dedicated functional area 2b. A code generation permission signal is input to the code authentication unit 25. The code generation permission signal is output when communication between the control device 1 and the power conversion device 2 is possible via the cable 4a. Moreover, in this embodiment, the code authentication unit 25 is configured to authenticate the input code generation permission signal (based on cooperative security authentication via the cable 4a as hardware). In addition, the code generation permission signal is an example of the "functional generation permission signal" in the claims.

[0049] Furthermore, in this embodiment, a switch 40 is provided, which is hardware that is turned on when the code generation enable signal is authenticated. Moreover, the switch 40 is configured such that when the code generation enable signal is authenticated, the switch 40 is turned on, thereby outputting a signal from a software-configured function block via the switch 40. For example, when the code generation enable signal is authenticated, function block 26c is connected to switch 40 (refer to the dashed line inside dedicated function unit 26), and a signal is output from function block 26c to the outside of dedicated function unit 26 via switch 40.

[0050] Furthermore, a dedicated function unit 26 is provided in the dedicated function area 2b. In the dedicated function unit 26 (power conversion device 2), it is configured such that, when cooperative security authentication is established, software generates functions that enable the power conversion device 2 to be used for a specified purpose. That is, as described above, when cooperative security authentication is established, multiple function blocks 26a, 26b, and 26c pre-set in the dedicated function unit 26 perform their functions in a predetermined order.

[0051] Furthermore, the power conversion device 2 is provided with function codes (not shown). These function codes are used to change the function of the power conversion device 2 by modifying its settings. Moreover, the function codes are only known to administrators and not to third parties. Furthermore, the authentication of the function codes (using the function codes to modify settings, etc.) is an example of the "inherent safety authentication" in the claims.

[0052] <Structure of an electric motor>

[0053] Next, refer to Figure 3 To illustrate the structure of motor 3.

[0054] like Figure 3 As shown, the motor 3 includes a motor identification symbol inherent to the motor 3. The motor identification symbol is stored, for example, in an IC chip 41 disposed within the motor 3.

[0055] In this embodiment, the motor 3 is configured to perform inherent motor safety authentication. For example, a motor identification symbol is read from the motor 3, which is equipped with an IC chip 41, using a reader 42. Reading the motor identification symbol from the IC chip 41 requires a password (PIN: Personal Identification Number). This password is known only to administrators and not to third parties. Furthermore, the read motor identification symbol is input into the management system 43 and set (saved) as a dedicated code for the control device 1 and the power conversion device 2. This motor safety authentication is an example of the "inherent safety authentication" and "load safety authentication" claimed in the claims.

[0056] Furthermore, in this embodiment, the configuration is such that, when a cooperation security authentication based on at least one of the hardware and software (specifically, both hardware and software) is established, performed by cooperation between at least the control device 1 and the power conversion device 2 (specifically, the control device 1, the power conversion device 2, and the motor 3), a function enabling the power conversion device 2 to be used for a specified purpose is generated in the power conversion device 2 via software. The cooperation security authentication will now be explained.

[0057] Collaborative Security Authentication

[0058] Next, refer to Figure 4 To explain collaborative safety certification. Furthermore, the following collaborative safety certification process is primarily performed by the control unit (not shown) of the power conversion device 2. Additionally, it is assumed that the control device safety certification of the control device 1, the function code certification of the power conversion device 2, and the motor safety certification of the motor 3 are performed in advance.

[0059] like Figure 4 As shown, in step S1, the security authentication signal sent from the control device 1 is read.

[0060] Next, in step S2, the security authentication signal is authenticated by the security authentication processing unit 23. That is, when communication is possible via the cable 4a between the control device 1 and the power conversion device 2, the security authentication signal sent from the control device 1 is authenticated. Thus, the switch 27a (refer to...) Figure 2 The circuit is switched on. Furthermore, switch 27a is a software switch, not a mechanical one. Additionally, if the security authentication signal is not authenticated by the security authentication processing unit 23, the collaborative security authentication process ends. Furthermore, the authentication in step S2 is based on hardware (cable 4a).

[0061] Next, in step S3, communication is initiated via cable 4a between control device 1 and power conversion device 2.

[0062] Next, in step S4, the motor identification symbol is acquired (received) from the control device 1 via cable 4a. Furthermore, the motor identification symbol is acquired by the motor mutual authentication processing unit 22.

[0063] Next, in step S5, the motor identification symbol that is set (saved) as the dedicated code of the power conversion device 2 is obtained by the motor mutual authentication processing unit 22.

[0064] Next, in step S6, the motor mutual authentication processing unit 22 determines (authenticates) whether the motor determination symbol stored in the power conversion device 2 matches the motor determination symbol sent from the control device 1. If the motor determination symbol stored in the power conversion device 2 matches the motor determination symbol sent from the control device 1, the software switch 27b (see reference)... Figure 2 The connection is established, and the process proceeds to step S7. In case of inconsistency, the collaborative security authentication process ends. Furthermore, the authentication in step S6 is a collaborative security authentication based on software (motor mutual authentication processing unit 22).

[0065] Next, in step S7, program code is acquired (received) from control device 1 via cable 4a. Furthermore, program code is acquired via program code authentication processing unit 24.

[0066] Next, in step S8, the program code authentication processing unit 24 performs program code authentication. Specifically, as described above, authentication (comparison) is performed on the following: whether the predetermined order stored in the power conversion device 2, which enables the multiple function blocks 26a, 26b, and 26c provided in the dedicated function unit 26 to function in a predetermined order, matches the predetermined order contained in the program code sent from the control device 1. If the predetermined order stored in the power conversion device 2 matches the predetermined order contained in the program code sent from the control device 1, the process proceeds to step S9; otherwise, the cooperative security authentication process ends. Furthermore, the authentication in step S8 is a cooperative security authentication based on software (program code authentication processing unit 24).

[0067] Next, in step S9, a code generation permission signal is acquired (received) from the control device 1. Furthermore, the code generation permission signal is acquired via the code authentication unit 25. The code generation permission signal is a signal that allows the generation of functions via program code.

[0068] Next, in step S10, the code generation permission signal is authenticated by the code authentication unit 25. When communication between the control device 1 and the power conversion device 2 is possible via cable 4a, the code generation permission signal is output (authenticated). Furthermore, the authentication of the code generation permission signal is a hardware-based (cable 4a) cooperative security authentication. If the code generation permission signal is authenticated in step S10, the process proceeds to step S11; otherwise, if the code generation permission signal is not authenticated, the cooperative security authentication process ends.

[0069] Additionally, in step S10, if the code generation permission signal is authenticated, switch 34a (refer to...) Figure 2 ) is turned on, and switch 34b (refer to) Figure 2 () was disconnected.

[0070] Next, in step S11, in the dedicated function unit 26 of the power conversion device 2, a function capable of using the power conversion device 2 for a specified purpose is generated by software. Furthermore, generating the function by software involves: "Sending program code for generating a function capable of being used for the specified purpose from the control device 1 to the power conversion device 2; within the power conversion device 2, authentication is performed based on the program code and predetermined conditions; and the function capable of being used for the specified purpose is generated by software." Specifically, in this embodiment, when cooperative security authentication is successful, a function capable of using the power conversion device 2 as a frequency converter capable of outputting a first variable frequency or a first variable voltage is generated by software. More specifically, based on the program code sent from the control device 1, multiple function blocks 26a, 26b, and 26c provided in the dedicated function unit 26 function in a predetermined order. Thus, based on the software generated by the dedicated function unit 26, the power conversion device 2 can be used as a frequency converter capable of outputting a first variable frequency or a first variable voltage for the specified purpose. As a result, the standard control circuit 32 and the PWM circuit 33 operate, causing the power conversion device 2 to output a first variable frequency or a first variable voltage. Here, the generated software is stored in a volatile memory unit such as RAM, and the stored information cannot be retained when power is no longer supplied, thus losing its function for the intended purpose.

[0071] Furthermore, in this embodiment, if the cooperative security authentication fails in any of steps S2, S6, S8, and S10, the power conversion device 2 becomes a frequency conversion device capable of outputting a second variable frequency or a second variable voltage, used for a different purpose than the power conversion device 2 capable of outputting a first variable frequency or a first variable voltage. That is, the software switch 34a remains off, and the software switch 34b remains on. As a result, the standard control circuit 32 and the PWM circuit 33 operate, causing the power conversion device 2 to output a second variable frequency or a second variable voltage based on the command value set by the frequency setting unit 31 of the standard functional area 2a.

[0072] Thus, in this embodiment, collaborative security authentication (authentication of the motor identification symbol) is performed through cooperation between the control device 1, the power conversion device 2, and the motor 3, and collaborative security authentication (authentication of security authentication signals, program code, and code generation permission signals) is performed through cooperation between the control device 1 and the power conversion device 2. Furthermore, collaborative security authentication is performed based on both hardware (cable 4a) and software (security authentication processing unit 23, motor mutual authentication processing unit 22, program code authentication processing unit 24, and code authentication unit 25).

[0073] Furthermore, as described above, collaborative safety certification is performed based on the prior safety certification of the control device 1, the functional code certification of the power conversion device 2, and the motor safety certification of the motor 3. That is, in this embodiment, the configuration is such that, when the safety certification of the control device 1, the functional code certification of the power conversion device 2, and the motor safety certification of the motor 3 are successful, and the collaborative safety certification is successful, software in the power conversion device 2 generates functions that enable the power conversion device 2 to be used for a specified purpose.

[0074] (Effects of this implementation method)

[0075] In this embodiment, the following effects can be obtained.

[0076] In this embodiment, as described above, the configuration is such that, when a collaborative security authentication based on at least one of the hardware and software components—control device 1, power conversion device 2, and motor 3—is successful, a function enabling the power conversion device 2 to be used for a specified purpose is generated in the power conversion device 2 via software. Therefore, if the collaborative security authentication fails, no function enabling the power conversion device 2 to be used for a specified purpose is generated in the power conversion device 2. As a result, even if the internal workings of the power conversion device 2 are analyzed, the function enabling the power conversion device 2 to be used for a specified purpose will not be leaked, because the function is not generated at all. Thus, the confidentiality of the function is maintained. That is, the confidentiality of the function enabling the power conversion device 2 to be used for a specified purpose is maintained by the collaboration of multiple devices such as at least control device 1 and power conversion device 2; therefore, even if the password of one of the multiple devices is leaked, the confidentiality of the function is maintained. Thus, the confidentiality of the function is improved.

[0077] Furthermore, since a cooperative safety certification requires cooperation between at least the control device 1 and the power conversion device 2, the cooperative safety certification fails when the power conversion device 2 is removed from the motor control system 100 alone, or when it is removed from the motor control system 100 alone and combined with another motor 3 that cannot be certified. That is, no function is generated in these cases, and therefore no function is leaked. Additionally, since no function is generated when the safety certification fails, the power conversion device 2 cannot be used alone for its intended purpose.

[0078] Furthermore, in this embodiment, as described above, the configuration is such that, when cooperative security authentication is established, software generates a function that enables the power conversion device 2 to function as a frequency conversion device capable of outputting a first variable frequency or a first variable voltage. This maintains the confidentiality of the power conversion device function capable of outputting a first variable frequency or a first variable voltage.

[0079] Furthermore, in this embodiment, as described above, the power conversion device 2 is configured such that, in the event that the cooperative security authentication fails, it becomes a frequency conversion device capable of outputting a second variable frequency or a second variable voltage, used for a different purpose than the power conversion device 2 capable of outputting a first variable frequency or a first variable voltage. Therefore, in the event that the cooperative security authentication fails, the power conversion device 2 can be used as a frequency conversion device capable of outputting a second variable frequency or a second variable voltage.

[0080] Furthermore, in this embodiment, as described above, the configuration is such that, when a collaborative security authentication based on both hardware and software is established, performed through cooperation between at least the control device 1 and the power conversion device 2 (among the motor 3), the power conversion device 2 generates a function through software that enables it to be used for a specified purpose. Therefore, since the collaborative security authentication is established based on both hardware and software, confidentiality is improved compared to cases where the collaborative security authentication is based on only one of hardware or software.

[0081] Furthermore, in this embodiment, as described above, the configuration is such that, when a collaborative security authentication based on at least one of hardware and software, achieved through cooperation between the control device 1, the power conversion device 2, and the motor 3, is established, the power conversion device 2 generates a function through software that enables it to be used for a specified purpose. Therefore, compared to the case where collaborative security authentication is established solely through cooperation between the control device 1 and the power conversion device 2, confidentiality (security level) can be improved.

[0082] Furthermore, in this embodiment, as described above, the control device 1 and the power conversion device 2 are connected via a cable 4a, which is hardware. Hardware-based cooperative security authentication includes authenticating when communication between the control device 1 and the power conversion device 2 is possible via the cable 4a. Therefore, cooperative security authentication based on the hardware of the cable 4a is possible.

[0083] Furthermore, in this embodiment, as described above, the hardware-based collaborative security authentication includes authenticating a code generation permission signal. This code generation permission signal is output when communication between the control device 1 and the power conversion device 2 is possible via cable 4a. This code generation permission signal allows the generation of functions through program code. Therefore, when communication between the control device 1 and the power conversion device 2 is not possible via cable 4a, the code generation permission signal is not output, and thus no function is generated. This prevents the leakage of functions.

[0084] Furthermore, in this embodiment, as described above, a switch 40 is provided. This switch 40 is hardware that is activated when the code generation permission signal is authenticated. The switch 40 is configured such that when the code generation permission signal is authenticated, the switch 40 is activated, thereby outputting a signal from a software-based function block via the switch 40. This enables collaborative security authentication through hardware and software cooperation. For example, if the switch 40 is deactivated due to a broken or pulled cable 4a in operation or at rest, the function is no longer valid.

[0085] Furthermore, in this embodiment, as described above, the software-based collaborative security authentication includes authentication in the following case: the motor identification symbol stored in the power conversion device 2 matches the motor identification symbol sent from the control device 1. Therefore, when the motor 3 pre-included in the motor control system 100 is replaced with another motor 3, the motor identification symbol of the motor 3 pre-included in the motor control system 100 differs from the motor identification symbol of the replaced motor 3. Thus, collaborative security authentication fails when the motor 3 is replaced, thereby preventing the generation (function) of the function when the motor 3 is replaced.

[0086] Furthermore, in this embodiment, as described above, the software-based collaborative security authentication includes authenticating the program code sent from the control device 1 based on predetermined conditions. Therefore, if the control device 1 pre-included in the motor control system 100 is replaced with another control device 1, the program code sent from the other control device 1 does not meet the predetermined conditions, and thus collaborative security authentication fails. This prevents the generation (function) of a function when the control device 1 has been replaced.

[0087] Furthermore, in this embodiment, as described above, at least one of the control device 1, the power conversion device 2, and the motor 3 has an inherent security authentication. This is configured such that, when the inherent security authentication of at least one of the control device 1, the power conversion device 2, and the motor 3 is established, and the cooperative security authentication is also established, software in the power conversion device 2 generates a function that enables the power conversion device 2 to be used for a specified purpose. Therefore, in addition to the cooperative security authentication, an inherent security authentication is also required, thus further enhancing confidentiality.

[0088] Furthermore, in this embodiment, as described above, the inherent security authentication of the control device 1 includes a control device security authentication for activating the control device 1. Therefore, in addition to the cooperative security authentication, the control device security authentication of the control device 1 also needs to be established, thus further enhancing confidentiality.

[0089] Furthermore, in this embodiment, as described above, the motor 3 includes a motor identification symbol inherent to the motor 3, and the inherent security authentication of the motor 3 includes motor security authentication that uses a password to obtain the motor identification symbol from the motor 3. Therefore, in addition to collaborative security authentication, motor security authentication is also required, thus further enhancing confidentiality.

[0090] [Variation Example]

[0091] Furthermore, it should be understood that all aspects of the embodiments disclosed herein are illustrative and not restrictive. The scope of the invention is not defined by the description of the embodiments above, but by the claims, and includes all modifications (variations) within the meaning and scope equivalent to the claims.

[0092] For example, in the above embodiments, an example is shown where, under the condition of successful cooperative security authentication, software is used to generate a function that enables the power conversion device to function as a frequency conversion device capable of outputting a first variable frequency or a first variable voltage. However, the present invention is not limited thereto. For example, under the condition of successful cooperative security authentication, software may be used to generate a function that enables the power conversion device to function as a device other than a frequency conversion device capable of outputting a first variable frequency or a first variable voltage.

[0093] Furthermore, the above embodiments illustrate an example where functionality is generated via software when collaborative security authentication based on both hardware and software is successful; however, the present invention is not limited to this. For example, functionality can also be generated via software when collaborative security authentication based solely on either hardware or software is successful.

[0094] Furthermore, the above embodiments illustrate an example where a collaborative safety authentication performed by the cooperation of the control device, the power conversion device, and the motor is successful, and the invention is not limited thereto. For example, the function could also be generated by software when a collaborative safety authentication performed by the cooperation of the control device and the power conversion device is successful.

[0095] Furthermore, the above embodiments illustrate a hardware-based collaborative security authentication method that is wired authentication; however, the invention is not limited to this. For example, collaborative security authentication based on hardware other than wired connections can also be performed.

[0096] Furthermore, in the above embodiments, an example was shown where software-based collaborative security authentication was performed by a security authentication processing unit, a motor mutual authentication processing unit, a program code authentication processing unit, and a code authentication unit; however, the present invention is not limited thereto. For example, software-based collaborative security authentication could also be performed in a component other than the security authentication processing unit, the motor mutual authentication processing unit, the program code authentication processing unit, and the code authentication unit.

[0097] Furthermore, the above embodiments illustrate an example where the control device, power conversion device, and motor all possess inherent safety certifications; however, the present invention is not limited to this. For example, it is also possible that any one or both of the control device, power conversion device, and motor possess inherent safety certifications. Alternatively, it is also possible that the inherent safety certifications of the control device, power conversion device, and motor are not used, and the functionality is generated by software only when the cooperative safety certification is established.

[0098] Furthermore, in the above embodiments, an example was shown where the inherent security authentication of the control device is an authentication used to activate the control device; however, the present invention is not limited thereto. For example, the inherent security authentication of the control device could be an authentication other than activating the control device.

[0099] Furthermore, the above embodiments illustrate an example where the inherent security authentication of the electric motor uses a password to obtain a specific symbol from the motor; however, the present invention is not limited to this. For example, the inherent security authentication of the electric motor could be any authentication other than using a password to obtain a specific symbol from the motor.

[0100] Furthermore, in the above embodiment, an example was shown where the "load determination information" is a motor determination symbol, but the present invention is not limited thereto. For example, a load determination symbol capable of determining the load may be used instead of the motor determination symbol. In this case, an IC chip storing the load determination symbol is provided inside the load device driven by the motor.

[0101] Furthermore, the above embodiments illustrate an example of using an electric motor as a load supplied with power from a power conversion device, but the present invention is not limited thereto. For example, power may also be supplied from the power conversion device to loads other than electric motors.

[0102] Furthermore, while the above embodiments illustrate an example of a power conversion device functioning as a frequency conversion device, the present invention is not limited thereto. For example, the power conversion device may also function as a device other than a frequency conversion device.

Claims

1. A load control system, comprising: Control device; A power conversion device, controlled by the control device; and The load, which is supplied with power from the power conversion device, in, The power conversion device includes standard functional areas and dedicated functional areas. A frequency setting unit is provided in the standard functional area. The dedicated functional area is pre-configured with multiple functional blocks. The load control system is configured such that, when cooperative security authentication is established at both the control device and the power conversion device, the power conversion device generates functions via software to enable its use for a specified purpose. This cooperative security authentication is based on both hardware and software cooperation between the control device, the power conversion device, and the load, at least between the control device and the power conversion device. The load control system is configured such that, upon successful completion of the cooperative security authentication, software generates a function that enables the power conversion device to function as a frequency conversion device capable of outputting a first variable frequency or a first variable voltage for the specified purpose. The load control system is configured such that, in the event that the cooperative security authentication fails, the power conversion device becomes a frequency conversion device that, based on the command value set by the frequency setting unit of the standard functional area, can output a second variable frequency or a second variable voltage, different from the frequency conversion device capable of outputting the first variable frequency or the first variable voltage. The control device and the power conversion device are connected via wiring, which is considered hardware. The hardware-based collaborative security authentication includes authenticating when communication between the control device and the power conversion device is possible via the wiring. When communication between the control device and the power conversion device is possible via the wiring, the control device is configured to send program code to the power conversion device, the program code being used to generate functionality that enables the power conversion device to function as a frequency conversion device capable of outputting the first variable frequency or the first variable voltage. The software-based collaborative security authentication includes the power conversion device's program code authentication processing unit authenticating the program code sent from the control device based on predetermined conditions. When the cooperative security authentication is established, based on the program code sent from the control device, the plurality of functional blocks set in the dedicated functional area perform their functions in a predetermined order, thereby generating the function of the frequency conversion device capable of outputting the first variable frequency or the first variable voltage.

2. The load control system according to claim 1, characterized in that, The load control system is configured such that, when the security authentication based on both hardware and software is established through cooperation between the control device, the power conversion device, and the load, the power conversion device generates functions via software that enable it to be used for a specified purpose.

3. The load control system according to claim 1, characterized in that, The hardware-based collaborative security authentication includes authenticating a function generation permission signal, which is output when communication between the control device and the power conversion device is possible via the wiring. This function generation permission signal allows the generation of a function through the program code.

4. The load control system according to claim 3, characterized in that, It also includes a switch, which consists of hardware that activates when the function generates an enable signal and is authenticated. The load control system is configured such that when the function generation permission signal is authenticated, the switch is turned on, thereby outputting a signal from a software-based function block via the switch.

5. The load control system according to claim 1, characterized in that, The load includes load determination information inherent to the load. The load determination information is stored in the control device and the power conversion device. The control device is configured to send the stored load determination information to the power conversion device. The software-based collaborative security authentication includes authenticating if the load determination information stored in the power conversion device is consistent with the load determination information sent from the control device.

6. The load control system according to claim 1, characterized in that, At least one of the control device, the power conversion device, and the load has inherent safety certification. The load control system is configured such that, when the inherent security authentication of at least one of the control device, the power conversion device, and the load is established, and the cooperative security authentication is established, software in the power conversion device generates functions that enable the power conversion device to be used for a specified purpose.

7. The load control system according to claim 6, characterized in that, The inherent security authentication inherent in the control device includes control device security authentication for enabling the control device to start.

8. The load control system according to claim 6, characterized in that, The load includes load determination information inherent to the load. The inherent security authentication of the load includes load security authentication that uses a password to obtain load determination information from the load.

9. The load control system according to claim 1, characterized in that, The power conversion device also includes a volatile storage unit, in which the generated software, which enables the multiple functional blocks to function in the prescribed order when the cooperative security authentication is successful, is stored. Without supplying power to the power conversion device, the generated software stored in the storage unit is eliminated.

Citation Information

Patent Citations

  • Magnification circuit

    JP1983077312A

  • Load control system

    CN108512823A

  • Load control system

    CN118523685A

  • METHOD FOR CONTROLLING ELECTRIC DRIVE AND ELECTRIC DRIVE

    FI124495B

  • Power supply, method and program for controlling power supply, maintenance apparatus, maintenance method and maintenance program

    JP2006288101A