Method for handling security of industrial equipment, electronic control system and industrial equipment system
By introducing safety-related components and control components into the electronic control system of industrial equipment, and using the signature action mechanism, safety-related components can change regulatory standards based on the actual value of industrial equipment, solving the complex safety-level monitoring and signal path problems in the prior art, and achieving flexible adjustment of safety functions and cost-effective improvements.
Patent Information
- Application Number
- CN202280101591.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-15
- Publication Date
- 2025-06-13
AI Technical Summary
The prior art complex safety-level monitoring and signaling paths limit the flexibility and cost-effectiveness of the system when dealing with the safety of industrial equipment.
By introducing safety-related components and control components into the electronic control system, and using the signature action mechanism, safety-related components can change regulatory standards based on the actual value of industrial equipment, thereby achieving flexible adjustment of safety functions.
This method simplifies the process of changing regulatory standards, reduces system complexity and cost, and improves the processing capacity for industrial equipment safety.
Smart Images

Figure CN120152822A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure is mainly related to the safety of industrial equipment. In particular, a method for handling the safety of industrial equipment, an electronic control system for handling the safety of industrial equipment, and an industrial equipment system including the electronic control system and the industrial equipment are provided. Background Art
[0002] Industrial robots are widely used in industrial applications. Controlling an industrial robot individually is usually quite complex. If the industrial robot is controlled together with one or more external axes, the control complexity may increase sharply. Examples of such external axes include conveyor devices, positioners, tracks, reorientable worktables, and servo guns, or other types of tools carried by the industrial robot. An industrial equipment including an industrial robot and external axes may include dozens of axes in total.
[0003] In many applications, safety-level monitoring of observables of industrial equipment (such as the positions, speeds, and torques of the axes of an industrial robot and any external axes) is required. Such safety-level monitoring is usually complex, especially when the number of axes is large.
[0004] WO2018091064A1 discloses an industrial robot system including a plurality of robots. Each robot includes a robot controller for controlling the movement of the robot. Each robot controller is allowed to receive sensor data from at least one safety sensor and includes a safety logic unit configured to generate a safety command based on the sensor data from at least one safety sensor. Summary of the Invention
[0005] To provide safety-level monitoring of observables of industrial equipment, an electronic control system may include both safety-level software and non-safety-level software, and the non-safety-level software is functionally separated from the safety-level software. The safety-level software and the non-safety-level software may be implemented in safety-related components and control components respectively. The non-safety-level software may be used to control the industrial equipment to perform various tasks and may be created and / or modified by human users on-site. The safety-level software may be used to monitor the operation of the industrial equipment according to safety functions and command a protective stop in case the industrial equipment does not conform to the safety functions.
[0006] During the operation of an industrial device, it may be desirable to disable one or more of its axes. One reason for disabling may be that the axis is not required for a particular task. Another reason for disabling may be that the tool of the industrial device should be replaced. Correspondingly, it may also be desirable to enable one or more axes of the industrial device. Regardless of the reason for disabling or enabling an axis, it may be necessary to notify the safety-level software to change the supervision standard of the safety function, so as to prevent an accidental protective stop from occurring. This means that the disabling or enabling of an axis may need to be programmed in two locations, namely in the non-safety-level software and in the safety-level software. However, it is generally not allowed for the non-safety-level software to directly access the safety-level software, for example because the non-safety-level software may be insufficiently reliable, such as in terms of diagnosis and random failures. Therefore, directly sending a command from the non-safety-level software to the safety-level software to change the supervision standard of the safety function implemented in the safety-level software brings a risk of unsafe behavior.
[0007] From the perspective of functional safety, it is unacceptable to use a safety input / output (I / O) module to communicate from a control component to a safety-related component. Therefore, in existing solutions, there is no signal path from the control component to the safety-related component. On the other hand, the communication from the safety-related component to the control component is direct communication, such as using a safety I / O module.
[0008] Suppose it is desired to include the entire application-related algorithm structure on the control component, then the safety-related component will have no information about the nature, state, or degree of progress of this structure. However, in today's existing solutions, this information may be required to solve the immediate problem, resulting in a complex implementation manner, in which the application-related information is also encoded in the safety-related component. For example, an independent safety PLC (programmable logic controller) providing a safety protocol can be used for this purpose. Therefore, the complexity and cost associated with the communication between the non-safety-level software and the safety-level software are high.
[0009] An object of the present invention is to provide an improved method for handling the safety of an industrial device.
[0010] Another object of the present invention is to provide an improved electronic control system for handling the safety of an industrial device.
[0011] Yet another object of the present invention is to provide an improved industrial device system including an electronic control system and an industrial device.
[0012] These objects are achieved by the method according to claim 1, the electronic control system according to claim 7, and the industrial device system according to claim 13.
[0013] The present invention is based on the following understanding: By enabling a safety-class component and a non-safety-class control component to unanimously recognize a specific change in the supervision standard that a specific signature movement of an industrial robot should trigger the safety function of a safety-related component, when the control component commands the industrial robot to execute the signature movement, the safety-related component can be made to make such a change, thereby greatly facilitating the handling of safety.
[0014] According to a first aspect, there is provided a method for handling the safety of an industrial device. The method includes providing an electronic control system, the electronic control system including a safety-related component and a control component. The safety-related component is configured to provide a safety function by: monitoring at least one observable of the industrial device and, in the case where the actual value of the at least one observable violates a supervision standard, commanding a safety response of the industrial device. The control component is configured to control the operation of the industrial device. Wherein, the safety-related component can access one or more reference values of one or more observables associated with the signature movement of the industrial device among the at least one observable; the control component controls the industrial device to execute the signature movement; the safety-related component identifies the signature movement by identifying that one or more actual values of the at least one observable correspond to the one or more reference values; and when the signature movement is identified, the safety-related component changes the supervision standard of the safety function.
[0015] Since the safety-related component changes the supervision standard based on one or more actual values from the industrial device, it may not be necessary to send a dedicated command signal for changing the supervision standard from the control component to the safety-related component. Instead, the supervision standard can be changed entirely based on the observable operations of the industrial device. In this way, a robust and cost-effective solution with lower complexity can be used to achieve a safe change in the supervision standard, such as safely enabling and / or disabling an axis of the industrial device. The method can easily change the supervision standard without a safety I / O module or a safety PLC between the safety-related component and the control component, or without using a safety I / O module or a safety PLC.
[0016] The execution of the signature movement by the industrial device represents an expected request for changing the safety function response. The signature movement can be a predefined behavior of the industrial device that will trigger a change in the supervision standard.
[0017] Since the control component is configured to control an industrial device to perform a signature action and the safety-related component can access one or more reference values related to the signature action, it can be said that the function of changing the supervision standard in response to a specific signature action is agreed upon by the safety-related component and the control component. Therefore, the signature action represents a signature that can be recognized by the safety-related component and thus can be said to constitute a handshake action. This method enables the collection of application-related information only in the control component. By using the signature action as a way to transfer information from the control component to the safety-related component, the safety-related component can participate in some application-specific steps. Therefore, this method reduces the complexity of the implementation manner of the application. For example, this method may not require a safety PLC. Therefore, the cost can be reduced. Once the safety-related component changes the supervision standard, the safety-related component can send a confirmation signal to the control component.
[0018] Identifying that at least one observable one or more actual values correspond to one or more reference values may include comparing the actual pattern of the one or more actual values with the reference pattern of the one or more reference values. If the actual pattern matches the reference pattern, for example within a defined tolerance, the safety-related component can identify that the signature action has been performed.
[0019] In an industrial device, a unique signature action can be designed, which can be commanded by the control component and is practically impossible to be performed due to errors or malfunctions, such as a specific movement or posture of an industrial robot. Thus, this consistency between the safety-related component and the control computer component regarding the signature action ensures that there will be no unexpected change in the safety function response due to errors or malfunctions. Therefore, the execution of the signature action indicates to the safety-related component the intention of the control component to change the supervision standard. Therefore, the signature action can also be referred to as a supervision standard change action.
[0020] An industrial device can be configured to perform actions, such as tasks, within a physical workspace. Depending on the type of task to be performed, it may be desirable to disable one or more axes of the industrial device, for example, within a certain time period. For example, the industrial device can include a track and an industrial robot positioned on the track. In this case, the track may not need to move to perform certain tasks and can subsequently be disabled. In another example, the tool of the industrial robot can be disabled before being disassembled.
[0021] When an axis is disabled, power supply to the axis can be stopped and signal communication with the axis can be stopped. The disabling and enabling of the axes of the industrial device achieve flexibility in production.
[0022] An industrial device may include one or more axes. Each axis may define a degree of freedom. The industrial device may include one or more sensors, and actual values may be read from each sensor. For example, a signature motion may be identified based on a set of actual values read from multiple sensors.
[0023] The industrial device may include at least one actuator for driving each axis. One or more sensors may be associated with one or more axes. However, one or more actual values of at least one observable may be obtained from sensors that are not necessarily associated with a particular axis, such as a camera or other type of sensor that monitors the industrial device to provide actual values of the observable.
[0024] At least one observable may include, for example, position, velocity, acceleration, torque, signal connection, power supply, and / or temperature. Each observable may be associated with an axis of the industrial device. Each observable may be a parameter.
[0025] Safety-related components may utilize safety functions to monitor the operation of the industrial device. One or more observables monitored by the safety function may be the same as or different from one or more observables used to identify the signature motion.
[0026] The safety-related components may, for example, compare the actual values of the observables with regulatory parameter values to provide a safety function. The regulatory parameter values may indicate limits or ranges of acceptable actual values of the industrial device that do not trigger a safety response. The safety-related components may, for example, monitor whether the actual values of at least one observable exceed the regulatory parameter values to determine whether the actual values violate regulatory standards. Changing the regulatory standards may include changing one or more such regulatory parameter values.
[0027] One or more reference values and / or one or more regulatory parameter values may be stored in an electronic control system, such as in its safety-related memory. Alternatively, or additionally, one or more reference values and / or one or more regulatory parameter values may be accessed from an external source.
[0028] As another example, changing the regulatory standards may include changing the type of safety response, i.e., the output of the safety function. As another example, changing the regulatory standards may include enabling or disabling a particular input to the safety function.
[0029] The safety-related components and the control components may be provided on the same or different hardware. The safety-related components and the control components may respectively include safety-level software and non-safety-level software. Safety-level may refer here, for example, to the International Electrotechnical Commission (IEC) standard 61508-3, Edition 2.0, April 2010. The safety function may be implemented according to the International Organization for Standardization (ISO) standard 13849-1.
[0030] The signature action can involve one, several, or all axes of the industrial equipment. Changing the supervision standard can include changing the supervision standard for one, several, or all axes of the industrial equipment.
[0031] The safety response can include putting the industrial equipment into a safe state, which can in turn include stopping the industrial equipment, enabling brakes, restricting power to one or more actuators, and / or removing power to one or more actuators. In particular, the safety response can include a protective stop, for example, a Category 0 stop, a Category 1 stop, or a Category 2 stop as defined in IEC 60204-1:2016. A Category 0 stop can be an uncontrolled stop of the industrial equipment achieved by immediately removing power to any actuator of the industrial equipment. Then, the industrial equipment can be braked by one or more power-off brakes. A Category 1 stop can be a controlled stop of the industrial equipment, in which the actuator can obtain power to achieve the stop and then the power is removed after the stop is achieved. A Category 2 stop can be a controlled stop that leaves power available for the actuator.
[0032] Each signature action can include the movement and / or position of the industrial equipment.
[0033] The industrial equipment can include an industrial robot. The industrial robot can include a manipulator having a plurality of axes (e.g., at least three axes). According to one example, the industrial robot includes a manipulator having six or seven axes.
[0034] The industrial equipment can also include at least one axis other than the axes of the industrial robot. Examples of such additional axes or external axes include conveyor devices, tracks, reorientable worktables, and tools. In the case where the industrial robot includes a detachable tool with an axis, the axis can be considered an external axis relative to the industrial robot. Examples of such tools include grippers and servo guns.
[0035] The movement and / or position can be the movement and / or position of the tool center point, TCP, of the industrial robot. In the case of moving and / or positioning the TCP in a specific manner to perform the signature action, it is usually necessary to move several axes of the industrial robot, and thus, multiple actual values may have to correspond to the respective reference values. For this reason, the handshake between the safety-related component and the control component is much more reliable than sending a single signal from the control component to the safety-related component, because the single signal may be incorrect. If the signature action is a sequence including multiple movements and / or multiple positions of the TCP, the reliability will increase significantly.
[0036] According to one variant, each position of the TCP is a pose representing both the position and orientation of the TCP.
[0037] Alternatively, in the case of an industrial device including a belt conveyor, the movement and / or position of the signature action can be the movement and / or position of the belt of the belt conveyor.
[0038] The signature action can include a disabling action. In this case, changing the supervision standard can include increasing the value of the supervision parameter to be compared with the actual value of at least one observable, or muting the safety function. In this way, it can be ensured that, for example, a safety response is not inadvertently triggered due to tool replacement of an industrial robot. The value of the supervision parameter can be increased by at least 20%, for example, by at least 50%, to allow a larger actual value of the industrial device without triggering a safety response. Muting means temporarily suspending the safety function, for example, in accordance with ISO standard 13849-1.
[0039] When attaching, detaching, enabling, or disabling an axis of an industrial device, one or more actual values from that axis may fluctuate. By increasing the value of the supervision parameter or muting the safety function, it is possible to avoid such attaching, detaching, enabling, or disabling inadvertently triggering a safety response.
[0040] Alternatively, or additionally, the signature action can include an enabling action. In this case, changing the supervision standard can include decreasing the value of the supervision parameter to be compared with the actual value of at least one observable, or unmuting the safety function. The value of the supervision parameter can be decreased by at least 20%, for example, by at least 50%, to only allow a smaller actual value of the industrial device without triggering a safety response.
[0041] As an alternative to the enabling action, after the expiration of a predefined time limit from the initial change of the supervision standard, the supervision standard can be restored, for example, the value of the supervision parameter can be decreased or the safety function can be unmuted. The time limit can be, for example, at least 1 second and / or less than 60 seconds.
[0042] In the case of an industrial device including an industrial robot, the method can include providing one or more safety change regions. The safety-related components can change the supervision standard in response to one or more positionings and / or movements of the TCP relative to such safety change regions. According to one example, when the TCP enters and leaves one such safety change region, the value of the supervision parameter can be increased and decreased accordingly. Each such positioning and / or movement of the TCP can constitute a signature action according to the present disclosure.
[0043] According to an alternative example, the method may include reducing a supervision parameter value or silencing a safety function after the TCP enters and exits a safety change area in a first manner, and increasing the supervision parameter value or unsilencing the safety function after the TCP enters and exits the safety change area in a second manner different from the first manner. Also in this alternative example, each such movement of the TCP may constitute a signature action according to the present disclosure.
[0044] In any case, the movement of the TCP performing the signature action may be commanded by a control component and detected by a safety-related component. The disable action and the enable action may alternatively be referred to as a first type of action and a second type of action, respectively. The disable action may be different from the enable action.
[0045] According to a second aspect, there is provided an electronic control system for handling the security of an industrial device, the electronic control system including a safety-related component and a control component, the safety-related component being configured to provide a safety function by: monitoring at least one observable of the industrial device and, in the case where an actual value of the at least one observable violates a supervision standard, commanding a safety response of the industrial device, the control component being configured to control the action of the industrial device; wherein the safety-related component is able to access one or more reference values of one or more observables related to a signature action of the industrial device among the at least one observable; wherein the control component is configured to control the industrial device to perform a signature action; and wherein the safety-related component is configured to, by identifying that one or more actual values of the at least one observable correspond to the one or more reference values, identify the signature action and, when the signature action is identified, change the supervision standard of the safety function.
[0046] The safety-related component and / or the control component may include program code which, when executed by at least one data processing device, causes the at least one data processing device to perform or command the performance of any of the steps described in connection with the first aspect. The electronic control system and the industrial device of the second aspect may be of any type described in connection with the first aspect, and vice versa.
[0047] Each signature action may include a movement and / or a position of the industrial device.
[0048] The industrial device may include an industrial robot.
[0049] The movement and / or the position may be a movement and / or a position of the tool center point TCP of the industrial robot.
[0050] The signature action may include a disable action. In this case, changing the supervision standard may include increasing a supervision parameter value to be compared with an actual value of the at least one observable or silencing the safety function.
[0051] Alternatively, or additionally, the signature action may include an enabling action. In this case, changing the regulatory standard may include reducing the value of the regulatory parameter to be compared with the actual value of at least one observable, or de-silencing a safety function.
[0052] According to a third aspect, an industrial equipment system is provided, including an electronic control system according to the second aspect, and industrial equipment. The industrial equipment may be of any type described in connection with the first aspect.
[0053] The industrial equipment may include an industrial robot, or consist of an industrial robot. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Further details, advantages, and aspects of the present disclosure will become apparent from the following description in conjunction with the accompanying drawings, in which:
[0055] Figure 1 A side view of an industrial equipment system according to an example is schematically shown, the industrial equipment system including industrial equipment and an electronic control system;
[0056] Figure 2 A block diagram of the industrial equipment system is schematically shown;
[0057] Figure 3 A side view of the industrial equipment system when the industrial equipment performs an action according to an example is schematically shown;
[0058] Figure 4 A side view of the industrial equipment system when the industrial equipment performs an action according to another example and a protective stop of the industrial equipment is commanded is schematically shown;
[0059] Figure 5 A side view of the industrial equipment system when the industrial equipment performs a disabling action according to an example is schematically shown;
[0060] Figure 6 A side view of the industrial equipment system after a tool change is performed by the industrial equipment according to an example after a regulatory standard change is schematically shown;
[0061] Figure 7 A side view of the industrial equipment system when the industrial equipment performs an enabling action according to an example is schematically shown;
[0062] Figure 8 A side view of an industrial equipment system according to another example is schematically shown;
[0063] Figure 9 A side view of the industrial equipment system when the industrial equipment performs an action according to another example and a protective stop of the industrial equipment is commanded is schematically shown;
[0064] Figure 10 Schematically shows a side view of an industrial equipment system when the industrial equipment performs a disabling action according to another example;
[0065] Figure 11 Schematically shows a side view of an industrial equipment system after a tool change is performed by the industrial equipment according to another example;
[0066] Figure 12 Schematically shows a partial view of an industrial equipment system when the industrial equipment moves along a first path of a disabling action according to another example;
[0067] Figure 13 Schematically shows during Figure 12 a partial view of the industrial equipment system during movement along a second path of the disabling action;
[0068] Figure 14 Schematically shows a partial view of an industrial equipment system when the industrial equipment moves along a first path of an enabling action according to another example;
[0069] Figure 15 Schematically shows during Figure 14 a partial view of the industrial equipment system during movement along a second path of the enabling action;
[0070] Figure 16 Schematically shows a side view of an industrial equipment system according to another example;
[0071] Figure 17 Schematically shows a side view of an industrial equipment system when the industrial equipment performs a disabling action according to another example;
[0072] Figure 18 Schematically shows a side view of an industrial equipment system after a tool change is performed according to another example;
[0073] Figure 19 Schematically shows a side view of an industrial equipment system when the industrial equipment performs an enabling action according to another example; and
[0074] Figure 20 is a block diagram outlining the general steps of a method according to one example. Detailed Description
[0075] A method for handling the security of an industrial equipment, an electronic control system for handling the security of an industrial equipment, and an industrial equipment system including the electronic control system and the industrial equipment will be described below. The same or similar reference numerals will be used to denote the same or similar structural features.
[0076] Figure 1A side view of an industrial equipment system 10 according to an example is schematically shown. The industrial equipment system 10 includes an industrial equipment 12 and an electronic control system 14. Here, the electronic control system 14 is illustrated as a robot controller.
[0077] In this example, the industrial equipment 12 includes an industrial robot 16. In this example, the industrial robot 16 includes a base 18 and a manipulator 20 that can move relative to the base 18. In this specific example, the manipulator 20 includes a first link 22a that can rotate about a first axis 24a relative to the base 18, a second link 22b that can rotate about a second axis 24b relative to the first link 22a, a third link 22c that can rotate about a third axis 24c relative to the second link 22b, a fourth link 22d that can rotate about a fourth axis 24d relative to the third link 22c, a fifth link 22e that can rotate about a fifth axis 24e relative to the fourth link 22d, and a sixth link 22f that can rotate about a sixth axis 24f relative to the fifth link 22e. Figure 1 The tool center point, TCP, 26 of the industrial robot 16 is also shown.
[0078] The industrial robot 16 further includes a first tool 24g1, which is illustrated here as a gripper having one degree of freedom. When attached to the industrial robot 16, the first tool 24g1 forms a seventh axis relative to the external axes of the industrial robot 16 and the industrial equipment 12.
[0079] In this example, the first tool 24g1 is detachably mounted on a tool flange 28 fixed to the sixth link 22f. Figure 1 The manipulator 20 in is a serial manipulator, and the first tool 24g1 is provided at the distal end of its kinematic chain. However, Figure 1 the industrial robot 16 of is just one of many examples. The manipulator 20 may alternatively or additionally include one or more translational axes, for example.
[0080] In this example, the industrial equipment 12 further includes a second tool 24g2 for attaching to the industrial robot 16 in place of the first tool 24g1. In Figure 1 , the second tool 24g2 is attached to a tool holder 30 and thus not in use. One or both of the first tool 24g1 and the second tool 24g2 may also be denoted by the reference numeral "24g".
[0081] In this particular non - restrictive example, the industrial device 12 further includes a conveying device 24h. In this example, the conveying device 24h includes an endless conveyor belt. The conveying device 24h forms another example of an external axis relative to the industrial robot 16, here the eighth axis of the industrial device 12. One, several, or all of the axes 24a - 24h may also be denoted by the reference numeral "24". In Figure 1 this case, each axis 24 respectively has one degree of freedom.
[0082] In this specific example, the electronic control system 14 includes a safety - related component 32 and a control component 34. The safety - related component 32 monitors the industrial device 12 according to safety functions. In this example, the safety - related component 32 monitors each of the axes 24a - 24h.
[0083] The control component 34 is configured to control the industrial device 12 to perform various tasks. For example, the conveying device 24h can be driven closer to or farther from the industrial robot 16, and the industrial robot 16 can pick up an article 36 from the conveying device 24h or place the article 36 on the conveying device 24h using the first tool 24g1.
[0084] When attaching and detaching the axis 24, the axis 24 can be mechanically connected and disconnected accordingly. When the axis 24 is enabled, the axis 24 can be addressed from the electronic control system 14, that is, power and control signals can be obtained between the electronic control system 14 and the axis 24. In this case, the electronic control system 14 can cause the axis 24 to perform functions. If the axis 24 is disabled, the axis 24 may not be addressable from the electronic control system 14.
[0085] Figure 2 A block diagram of the industrial device system 10 is schematically shown. Figure 2Illustrated in this particular non - limiting example, industrial device 12 includes a plurality of sensors that are in signal communication with each of safety - related component 32 and control component 34, namely, a first sensor 38a arranged to detect the actual value of a first observable 40a associated with a first axis 24a, a second sensor 38b arranged to detect the actual value of a second observable 40b associated with a second axis 24b, a third sensor 38c arranged to detect the actual value of a third observable 40c associated with a third axis 24c, a fourth sensor 38d arranged to detect the actual value of a fourth observable 40d associated with a fourth axis 24d, a fifth sensor 38e arranged to detect the actual value of a fifth observable 40e associated with a fifth axis 24e, a sixth sensor 38f arranged to detect the actual value of a sixth observable 40f associated with a sixth axis 24f, a seventh sensor 38g arranged to detect the actual value of a seventh observable 40g associated with a seventh axis 24g, and an eighth sensor 38h arranged to detect the actual value of an eighth observable 40h associated with an eighth axis 24h. One, several, or all of sensors 38a - 38h may also be denoted by the reference numeral "38". One, several, or all of observables 40a - 40h may also be denoted by the reference numeral "40". Examples of observables 40 include position, velocity, acceleration, torque, signal connection, power supply, and / or temperature. Although not shown, industrial device 12 may also include actuators associated with each axis 24, such as electric motors. In Figure 2 this specific example, safety - related component 32 and control component 34 are in signal communication with each sensor 38.
[0086] In this example, safety - related component 32 includes safety - related data - processing device 42 and safety - related memory 44. In this example, safety - related computer program 46 and reference value 48 are stored in safety - related memory 44. Safety - related computer program 46 contains program code that, when executed by safety - related data - processing device 42, causes safety - related data - processing device 42 to perform or command the performance of the various steps described herein.
[0087] In this example, the safety-related component 32 further includes a safety function 50. The safety function 50 is configured to monitor observables 40 of the industrial device 12 according to one or more regulatory standards. In this example, the safety function 50 includes at least one logical sequence, which includes an input function 51, a logic function 53, and an output function 55. Each logic function 53 can form a safety-related component of a control system (SRP / CS) according to ISO standard 13849-1. Each input function 51 can receive one of the observables 40. If the actual value of the observable 40 exceeds the regulatory parameter value 57 determined by the logic function 53, the output function 55 commands a safety response of the industrial device 12. Thus, the respective regulatory parameter values 57 form the regulatory standards. Each regulatory parameter value 57 can define an allowed interval for the actual value of the associated observable 40. As a non-limiting example, the observable 40 can be the speed of the shaft 24, and the regulatory parameter value 57 can define the maximum speed of the shaft 24. Thus, the safety function 50 monitors whether any actual value of the observable 40 violates the regulatory standards. In this example, the safety function 50 compares the actual values of multiple observables 40 with the corresponding regulatory parameter values 57. Thus, the safety function 50 is used to monitor the operation of the industrial device 12 and issue a safety response in case the operation does not comply with the safety standards. A safety-related computer program 46 can change one or more regulatory parameter values 57 of the safety function 50.
[0088] In this example, a plurality of signatures 52 are also stored in the safety-related memory 44. Each signature 52 represents a signature action of the industrial device 12 and is associated with a set of reference values 48. In this example, each such associated set of reference values 48 represents the expected values of the observables 40 when the industrial device 12 performs the signature action. The reference values 48 can include, for example, numbers, closed intervals, or open intervals.
[0089] In this example, the control component 34 includes a control data processing device 54 and a control memory 56. In this example, a control computer program 58 is stored in the control memory 56. The control computer program 58 contains program code that, when executed by the control data processing device 54, causes the control data processing device 54 to perform or command the performance of the various steps described herein. The control computer program 58 contains program code that, when executed by the control data processing device 54, causes the control data processing device 54 to command the industrial device 12 to perform various actions, such as tasks. The control computer program 58 can be programmed by a human user, for example, using a programming device (such as a teach pendant unit). The control component 34 can command the industrial device 12 to perform various tasks in the physical environment.
[0090] In this example, a plurality of signatures 52 are also stored in the control memory 56. The signatures 52 in the control memory 56 correspond to the signatures 52 in the safety-related memory 44. The control component 34 is configured to command the industrial device 12 to perform signature actions related to the signature 52 for each signature 52.
[0091] For example, if the control component 34 intends to disassemble the first tool 24g1 so as to be able to pick up the second tool 24g2, this intention may not be known to the safety-related component 32. If the supervision standard of the safety function 50 has not changed, the safety function 50 will detect the disassembly of the first tool 24g1 as a loss of function, that is, a violation of the supervision standard, and issue a safety response. In this example, such a safety response is inconsistent with the intention of the control component 34.
[0092] In the electronic control system 14, there is a distinct functional separation between the safety-related component 32 and the control component 34. This separation can also be physical, as in this example. In this example, the safety-related component 32 and the control component 34 respectively include safety-level software and non-safety-level software.
[0093] Figure 3 A side view of the industrial device system 10 is schematically shown. The control component 34 has commanded the industrial device 12 to perform an action 60a according to an example. The action 60a is the movement of the TCP 26 along a path. During the execution of the action 60a, the safety-related component 32 continuously or repeatedly monitors whether the actual value of the observable 40 measured by the sensor 38 conforms to the safety function 50. The safety-related component 32 also continuously or repeatedly monitors whether the actual value of the observable 40 during the execution of the action 60a corresponds to the reference value 48 of any signature 52.
[0094] Figure 4 A side view of the industrial device system 10 is schematically shown when the industrial device 12 performs an action 60b according to another example. The action 60b is the disabling and disassembly of the first tool 24g1 as commanded by the control component 34. Since the safety-related component 32 does not know that the first tool 24g1 should be disabled and disassembled, and some observables 40 start to show greater fluctuations after this disabling and disassembly, therefore, because one or more observables 40 violate the relevant supervision standard by exceeding the relevant supervision parameter value 57, the safety-related component 32 (i.e., the safety function 50) commands a protective stop 62 of the industrial device 12. The protective stop 62 is an example of a safety response according to the present disclosure. Figure 4 The protective stop 62 is unintentional because the stop is triggered when the industrial device 12 has performed the intentional action 60b.
[0095] Figure 5A side view of the industrial equipment system 10 is schematically shown when the industrial equipment 12 performs an action 60c according to another example. The action 60c constitutes a signature action according to one example and a disabling action according to one example. The action 60c is commanded by the control component 34, here based on one of the signatures 52. In this particular and non-limiting example, the action 60c includes moving the TCP 26 in a spiral form including three full turns. At this time, the safety-related component 32 detects that during the execution of the action 60c, the actual value of the observable 40 corresponds to the reference value 48 of one of the signatures 52. For example, the observable 40 in the form of the position of each axis 24 can be used to detect this correspondence. As a result, the safety-related component 32 performs a change in the supervision standard of the safety function 50, where the change is associated with the signature 52. In this example, in response to identifying that the industrial equipment 12 performs the action 60c, the safety-related component 32 increases a plurality of supervision parameter values 57 of the safety function 50. This is illustrated as the frame line of the safety function 50 changing from Figure 4 the solid line to Figure 5 the dashed line. After these changes in the supervision standard of the safety function 50, in this example, the value of the observable 40 is allowed to fluctuate to a greater extent. For this purpose, the safety-related computer program 46 can include program code that, when executed by the safety-related data processing device 42, causes the safety-related data processing device 42 to change one or more supervision parameter values 57 of the safety function 50 in response to identifying the action 60c. When one or more supervision parameter values 57 are changed, the parameterization of the safety function 50 is also changed, thereby changing the response of the safety function 50. The parameterization of the safety function 50 can be changed, for example, by the safety-related computer program 46 without changing the performance level of the safety function 50 and without re-verifying and validating the safety function 50. Examples of the supervision parameter values 57 can include predefined limits on the position, speed, acceleration, or torque of the actual value 40 of the observable 40.
[0096] Since the safety-related component 32 changes the supervision standard of the safety function 50 based on the actual value from the industrial equipment 12, it may not be necessary to send a dedicated command signal for changing the supervision standard from the control component 34 to the safety-related component 32. Therefore, the method provides a robust, low-complexity, and cost-effective way to handle the safety of the industrial equipment 12.
[0097] Figure 6Schematically shows a side view of the industrial equipment system 10 after the industrial equipment 12 has performed an action 60d according to another example. The action 60d is a tool change and is commanded by the control component 34. The action 60d includes disabling the first tool 24g1, removing the first tool 24g1 from the industrial robot 16 and placing the first tool 24g1 on the tool rack 30, attaching the second tool 24g2 picked up by the industrial robot 16 from the tool rack 30, and enabling the second tool 24g2. Similar to Figure 4 After the first tool 24g1 is disabled and removed, the observable 40 begins to exhibit greater fluctuations. However, since the regulatory parameter value 57 has been increased, the safety function 50 does not command the execution of a protective stop 62. After the regulatory parameter value 57 is increased, the safety function 50 can, for example, allow a higher peak value of the current supplied to the axis 24, which increases during the tool change.
[0098] Figure 7 Schematically shows a side view of the industrial equipment system 10 when the industrial equipment 12 performs an action 60e according to another example. The action 60e constitutes a signature action according to one example and constitutes an enabling action according to one example. The action 60e is commanded by the control component 34, here based on one of the signatures 52. In this particular and non-limiting example, the action 60e includes moving the TCP 26 in a spiral form including three full turns, here in a direction opposite to the Figure 5 spiral. At this time, the safety-related component 32 detects that during the execution of the action 60e, the actual value of the observable 40 corresponds to the reference value 48 of a signature 52. As a result, the safety-related component 32 performs a change in the regulatory standard of the safety function 50, where the change is associated with the signature 52. In this example, in response to identifying that the industrial equipment 12 performs the action 60e, the safety-related component 32 reduces a plurality of regulatory parameter values 57 of the safety function 50. This is illustrated as the box line of the safety function 50 changing from Figure 6 a dotted line to Figure 7 a solid line. After this change in the regulatory standard of the safety function 50, in this example, the value of the observable 40 is allowed to fluctuate only to a lesser extent.
[0099] The disabling action 60c and the enabling action 60e represent the consistency between the safety-related component 32 and the control component 34 without involving the corresponding domain information of the safety-related component 32 and the control component 34. This achieves great flexibility in the safety processing of the industrial equipment 12 and a very low error risk.
[0100] The signature actions 60c and 60e can be designed on-site, for example, after the industrial equipment system 10 is installed. The signature actions 60c and 60e should be selected such that the control component 34 cannot be erroneously programmed to command the industrial equipment 12 to perform these actions.
[0101] Figure 8 A side view of the industrial equipment system 10 according to another example is schematically shown. The differences with respect to Figures 3 to 7 will be mainly described below. As Figure 8 shown, in the safety-related component 32 and the control component 34, a virtual safety change region 64a related to the industrial equipment 12 is defined. Here, the safety change region 64a is illustrated as a sphere with a predetermined radius. Alternatively, the safety change region 64a can be a cube or a volume of any shape. In this example, there is an agreement between the safety-related component 32 and the control component 34 that when the TCP 26 enters the safety change region 64a, the safety-related component 32 shall increase a plurality of supervision parameter values 57 of the safety function 50, and when the TCP 26 leaves the safety change region 64a, the safety-related component 32 shall decrease the plurality of supervision parameter values 57 of the safety function 50.
[0102] Figure 9 A side view of the industrial equipment system 10 when the industrial equipment 12 performs an action 60f according to another example is schematically shown. The action 60f is the disabling and detaching of the first tool 24g1 on the transfer device 24h commanded by the control component 34. Since the disabling and detaching of the first tool 24g1 occur outside the safety change region 64a, the supervision criteria of the safety function 50 remain unchanged. Therefore, fluctuations in some actual values of the observables 40 related to the disabling and detaching of the first tool 24g1 will cause the safety function 50 to command the execution of the protective stop 62 of the industrial equipment 12. Therefore, when the TCP 26 is positioned outside the safety change region 64a, if the enabling, disabling, attaching, or detaching of the tool 24g is performed, a protective stop 62 can be issued in this example.
[0103] Figure 10 A side view of the industrial equipment system 10 when the industrial equipment 12 performs an action 60g according to another example is schematically shown. The action 60g constitutes a signature action and a disabling action. The action 60g is commanded by the control component 34, here based on one of the signatures 52. The action 60g includes moving the TCP 26 into the safety change region 64a. At this time, the safety-related component 32 detects that during the execution of the action 60g, the actual value of the observables 40 corresponds to the reference value 48 of one of the signatures 52. As a result, in response to recognizing that the TCP 26 has entered the safety change region 64a, the safety-related component 32 increases a plurality of supervision parameter values 57 of the safety function 50. When the TCP 26 is within the safety change region 64a, the value of the observables 40 is allowed to fluctuate to a greater extent, and tool replacement can be performed.
[0104] Figure 11Schematically shows a side view of the industrial equipment system 10 after the industrial equipment 12 has performed an action 60h according to another example. The action 60h is a tool change, a signature action, and an enabling action. As Figure 11 shown, when the TCP 26 is located within the safety change region 64a and the monitored parameter value 57 of the safety function 50 thus increases, the industrial robot 16 has disassembled the first tool 24g1 and attached the second tool 24g2 to the tool flange 28. When the action 60h ends and the TCP 26 leaves the safety change region 64a, multiple monitored parameter values 57 of the safety function 50 are decreased. Therefore, enabling and disabling the tool 24g is only allowed when the TCP 26 is located within the safety change region 64a. In this example, in response to the position of the TCP 26 relative to the safety change region 64a, the safety-related component 32 changes the monitoring criteria of the safety function 50.
[0105] Figure 12 Schematically shows a partial view of the industrial equipment system 10 when the industrial equipment 12 performs an action 60i and the TCP 26 moves along a first path relative to the virtual safety change region 64b. The differences relative to Figures 8 to 11 will be mainly described below. In Figure 12 , the control component 34 has commanded the TCP 26 to move along the first path and enter the safety change region 64b from above.
[0106] Figure 13 Schematically shows a partial view of the industrial equipment system 10 when the industrial equipment 12 continues to perform the action 60i by moving the TCP 26 along a second path. In Figure 13 , the control component 34 has commanded the TCP 26 to move along the second path and leave the safety change region 64b towards the right.
[0107] The action 60i constitutes a signature action and a disabling action. To disassemble and disable the first tool 24g1, the TCP 26 must enter the safety change region 64b from above and leave the safety change region 64b towards the right. In this example, the tool change can occur outside the safety change region 64b.
[0108] Only when the safety-related component 32 identifies that the TCP 26 enters and leaves the safety change region 64b along the Figure 12 and Figure 13 first path and second path in Figure 12 respectively, the monitored parameter value 57 is increased by the safety function 50. These paths represent a clear and definite indication of the intention of the control component 34 to change the monitoring criteria to perform the tool change. If the TCP 26 approaches the safety change region 64b from a direction other than the direction shown in Figure 12 , or if the TCP 26 leaves from Figure 13If it leaves the safe change area 64b in a direction other than the indicated direction, the supervision standard remains unchanged.
[0109] Figure 14 Schematically shows a partial view of the industrial equipment system 10 when the industrial equipment 12 performs the action 60j by moving the TCP 26 along a first path according to another example. In Figure 14 it, the control component 34 has commanded the TCP 26 to enter the safe change area 64b from the left along the first path.
[0110] Figure 15 Schematically shows a partial view of the industrial equipment system 10 when the industrial equipment 12 continues to perform the action 60j by moving the TCP 26 along a second path. In Figure 15 it, the control component 34 has commanded the TCP 26 to move downward along the second path to leave the safe change area 64b.
[0111] The action 60j constitutes a signature action and an enabling action. Only when the safety-related component 32 recognizes this specific path of the TCP 26 entering and leaving the safe change area 64b, the supervision parameter value 57 is reduced by the safety function 50. This path represents a clear and definite indication of the intention of the control component 34 to resume the supervision standard after tool replacement. Many alternative movements of the TCP 26 relative to the safe change area 64b can also be envisaged, such that the safety-related component 32 changes one or more supervision standards of the safety function 50.
[0112] Figure 16 Schematically shows a side view of the industrial equipment system 10 according to another example. The differences relative to Figures 3 to 7 will be mainly described below. In Figure 16 it, the supervision parameter value 57 of the safety function 50 is set to a predefined relatively small value. Figure 17 Schematically shows a side view of the industrial equipment system 10 when the industrial equipment 12 performs the action 60k according to another example. The action 60k constitutes a signature action and a disabling action. In Figure 17 it, the control component 34 has commanded the industrial robot 16 to adopt a first posture 66a, which is here based on one of the signatures 52. The posture of the industrial robot 16 includes a specific position and a specific orientation of the TCP 26. As Figure 17 shown, the first posture 66a is an unusual posture that the industrial robot 16 will never use except as a signature for changing the supervision standard. When the safety-related component 32 recognizes that the industrial robot 16 is in the first posture 66a based on the value of the observable quantity 40, the safety-related component 32 increases the supervision parameter value 57 of the safety function 50 to a predefined relatively large value. In this way, the supervision standard is changed from Figure 16 the supervision standard of
[0113] Figure 18 A side view of the industrial equipment system 10 after performing an action 60l according to another example is schematically shown. The action 60l is a tool change. When the monitored parameter value 57 of the safety function 50 has a relatively large value to avoid triggering a protective stop 62, the first tool 24g1 has been disabled and disassembled, and the second tool 24g2 has been attached and enabled.
[0114] Figure 19 A side view of the industrial equipment system 10 when the industrial equipment 12 performs an action 60m according to another example is schematically shown. The action 60m constitutes a signature action and an enabling action. In Figure 19 , the control component 34 has commanded the industrial robot 16 to adopt a second posture 66b different from the first posture 66a. As Figure 19 shown, the second posture 66b is also an unusual posture that the industrial robot 16 will never use except as a signature for changing the regulatory standard. When the safety-related component 32 identifies that the industrial robot 16 is in the second posture 66b based on the value of the observable quantity 40, the safety-related component 32 reduces the monitored parameter value 57 of the safety function 50 to Figure 16 the corresponding value.
[0115] Figure 20 is a block diagram outlining the general steps of a method according to an example. The method includes block S10: providing an electronic control system 14, the electronic control system 14 including a safety-related component 32 and a control component 34, the safety-related component 32 being configured to provide a safety function 50 by: monitoring at least one observable quantity 40 of the industrial equipment 12, and in the case where the actual value of the at least one observable quantity 40 violates the regulatory standard, commanding a safety response 62 of the industrial equipment 12, the control component 34 being configured to control the actions 60a - 60m of the industrial equipment 12, wherein the safety-related component 32 can access one or more reference values 48 of one or more observable quantities among the at least one observable quantity 40 related to the signature actions 60c, 60e, 60g, 60h, 60i, 60j, 60k and 60m of the industrial equipment 12. The method further includes block S12: the control component 34 controls the industrial equipment 12 to perform the signature actions 60c, 60e, 60g, 60h, 60i, 60j, 60k and 60m. The method further includes block S14: the safety-related component 32 identifies the signature actions 60c, 60e, 60g, 60h, 60i, 60j, 60k and 60m by identifying that one or more actual values of the at least one observable quantity 40 correspond to one or more reference values 48. The method further includes step S16: when the signature actions 60c, 60e, 60g, 60h, 60i, 60j, 60k and 60m are identified, the safety-related component 32 changes the regulatory standard of the safety function 50.
[0116] Although the present disclosure has been described with reference to exemplary embodiments, it should be understood that the present invention is not limited to these embodiments described above. For example, it should be understood that the dimensions of the components can be changed as needed. Therefore, the present invention is intended to be limited only by the scope of the appended claims.
Claims
1. A method for handling the safety of an industrial device (12), the method comprising: providing (S10) an electronic control system (14) comprising safety-related components (32) and control components (34), the safety-related components (32) being configured to provide a safety function (50) by: monitoring at least one observable (40) of the industrial device (12), and commanding a safety response (62) of the industrial device (12) in the case where an actual value of the at least one observable (40) violates a regulatory standard, the control components (34) being configured to control the actions (60a - 60m) of the industrial device (12), wherein the safety-related components (32) are able to access one or more reference values (48) of one or more observables among the at least one observable (40) associated with signature actions (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m) of the industrial device (12); controlling (S12) by the control components (34) the industrial device (12) to perform the signature actions (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m); identifying (S14) by the safety-related components (32) the signature actions (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m) by identifying that one or more actual values of the at least one observable (40) correspond to the one or more reference values (48); and changing (S16) by the safety-related components (32) the regulatory standard of the safety function (50) upon identifying the signature actions (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m).
2. The method according to claim 1, wherein, each signature action (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m) comprises a movement and / or a position of the industrial device (12).
3. The method according to any one of the preceding claims, wherein, the industrial device (12) comprises an industrial robot (16).
4. The method according to claims 2 and 3, wherein, the movement and / or the position is a movement and / or a position of a tool center point TCP (26) of the industrial robot (16).
5. The method according to any one of the preceding claims, wherein, the signature actions (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m) comprise disabling actions (60c, 60g, 60i, 60k), and wherein the changing (S16) the regulatory standard comprises: increasing a regulatory parameter value (57) to be compared with an actual value of the at least one observable (40), or silencing the safety function (50).
6. The method according to any one of the preceding claims, wherein, The signature actions (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m) include enabling actions (60e, 60h, 60j, 60m), and wherein, the changing (S16) of the regulatory standard includes: reducing a regulatory parameter value (57) to be compared with an actual value of the at least one observable (40), or un-silencing the safety function (50).
7. An electronic control system (14) for handling the safety of an industrial device (12), the electronic control system (14) comprises: safety-related components (32) configured to provide a safety function (50) by: monitoring at least one observable (40) of the industrial device (12), and commanding a safety response (62) of the industrial device (12) in case an actual value of the at least one observable (40) violates a regulatory standard, and control components (34) configured to control an action (60a - 60m) of the industrial device (12); wherein, the safety-related components (32) can access one or more reference values (48) of one or more observables associated with a signature action (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m) of the industrial device (12) among the at least one observable (40); wherein, the control components (34) are configured to control (S12) the industrial device (12) to perform the signature action (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m); and wherein, the safety-related components (32) are configured to: identify (S14) the signature action (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m) by identifying that one or more actual values of the at least one observable (40) correspond to the one or more reference values (48), and upon identifying the signature action (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m), change (S16) the regulatory standard of the safety function (50).
8. The electronic control system (14) according to claim 7, wherein, each signature action (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m) includes a movement and / or a position of the industrial device (12).
9. The electronic control system (14) according to claim 7 or 8, wherein, the industrial device (12) includes an industrial robot (16).
10. The electronic control system (14) according to claims 8 and 9, wherein, the movement and / or the position is a movement and / or a position of a tool center point TCP (26) of the industrial robot (16).
11. The electronic control system (14) according to any one of claims 6 to 8, wherein, The signature actions (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m) include disabling actions (60c, 60g, 60i, 60k), and wherein the changing (S16) of the regulatory standard includes: increasing the value of the regulatory parameter (57) to be compared with the actual value of the at least one observable (40), or silencing the safety function.
12. The electronic control system (14) according to any one of claims 7 to 11, wherein, The signature actions (60c, 60e, 60g, 60h, 60i, 60j, 60k, 60m) include enabling actions (60e, 60h, 60j, 60m), and wherein the changing (S16) of the regulatory standard includes: decreasing the value of the regulatory parameter (57) to be compared with the actual value of the at least one observable (40), or unsilencing the safety function.
13. An industrial equipment system (10) comprising the electronic control system (14) according to any one of claims 7 to 12, and the industrial equipment (12).
14. The industrial equipment system (10) according to claim 13, wherein, The industrial equipment (12) includes an industrial robot (16) or consists of an industrial robot (16).
Citation Information
Patent Citations
An industrial robot system comprising a plurality of robots and a plurality of safety sensors
WO2018091064A1