Intelligent robot hardware-level safety control device and control method

Through the intelligent robot hardware-level security control device, the synergy between power cut-off and network destroy modules is adopted to form independent closed-loop control, solving the problem of poor reliability of robot safety control, ensuring independent transmission and execution of emergency commands, and achieving fast and reliable security protection.

CN120395918AActive Publication Date: 2025-08-01TIANJIN HAISHI INTELLIGENT TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510919522.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-08-01
Estimated Expiration
2045-07-04

AI Technical Summary

Technical Problem

The emergency stop control of existing robot safety control devices is poor, and it is prone to fail due to intrusion of the main control system, resulting in the interception or blocking of safety instructions.

Method used

A hardware-level security control device for intelligent robots is designed, including a power cut-off execution module, a network destroy module and an independent security protection module. A closed-loop security control system is formed through a hard-wire direct connection channel, and a triggerable circuit breaker component, an isolation component and an encrypted communication unit are used to ensure the independent transmission and execution of emergency instructions.

Benefits of technology

It realizes that even if the main control system is invaded, it can reliably block power output and network communication, prevent hardware loss and data leakage, ensure the independence and rapid response of security control, and avoid signal interference and tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120395918A_ABST
    Figure CN120395918A_ABST
Patent Text Reader

Abstract

The invention provides a hardware-level safety control device of an intelligent robot. The hardware-level safety control device of the intelligent robot comprises a power cut-off execution module, the network destroying module is provided with an isolation assembly capable of physically destroying a robot network communication unit; the independent security protection module integrates a hardware firewall and an encryption communication unit; the emergency control module is electrically connected with the power cut-off execution module and the network destroying module through a hard wire direct connection channel, an encryption communication channel with an external control terminal is established through the independent safety protection module, and a closed-loop safety control system independent of a robot main control system is formed. Through the synergistic effect of the power cut-off execution module and the network destroying module, power output and network communication of the robot are synchronously blocked, the double risks of out-of-control of hardware and data leakage are thoroughly eliminated, and comprehensive safety protection is formed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of intelligent robots, and particularly to a hardware-level safety control device and control method for intelligent robots. Background Art

[0002] Current robot safety control devices mostly focus on the emergency stop control of servo motors. For example, an emergency stop signal is triggered by mechanical pressing and supplemented with a status indicator light, such as the invention patent with the application number 202210773192.4 and the name of a servo control position command filtering and emergency stop device. However, the emergency module designed by this control shares the communication path with the main control system of the robot. If the main control system of the robot is invaded, it may cause the safety command to be intercepted or blocked, and the reliability of controlling the emergency stop is poor. Summary of the Invention

[0003] In view of the above defects or deficiencies in the prior art, this application aims to provide a hardware-level safety control device and control method for intelligent robots to improve the reliability of emergency stop control; In a first aspect, this application proposes a hardware-level safety control device for intelligent robots, including: A power cut-off execution module, where the power cut-off execution module includes a triggerable circuit breaker component disposed in the main power circuit of the robot; A network destruction module, where the network destruction module is configured with an isolation component that can physically damage the robot network communication unit; An independent safety protection module, where the independent safety protection module integrates a hardware firewall and an encrypted communication unit; An emergency control module, where the emergency control module is electrically connected to the power cut-off execution module and the network destruction module respectively through a hard-wired direct connection channel, and establishes an encrypted communication channel with an external control terminal through the independent safety protection module, forming a closed-loop safety control system independent of the main control system of the robot.

[0004] According to the technical solution provided by this application, the triggerable circuit breaker component is a PBD component using an explosion-driven circuit breaker mechanism. The PBD component includes a fusible conductor section disposed in the main power circuit, a micro-explosion unit coupled to the fusible conductor section, and an ignition trigger circuit.

[0005] According to the technical solution provided by this application, the PBD component is provided with a dual trigger interface. The dual trigger interface includes a physical operation interface and a wireless control interface. The physical operation interface is equipped with a mechanical emergency stop button or a pull rod trigger mechanism, and the wireless control interface supports trigger methods such as Bluetooth, radio frequency, or infrared remote control.

[0006] According to the technical solution provided in this application, the isolation component adopts an IGB isolation component, and the IGB isolation component includes at least one of the following physical destruction units: an overvoltage breakdown unit connected in parallel on the network signal line, an independently powered electromagnetic pulse generator, and a physical disconnection mechanism configured with a micro-shearing component.

[0007] According to the technical solution provided in this application, the encryption communication unit includes a security chip and a physically isolated storage unit, and the security chip is solidified with a custom communication protocol stack; the storage unit stores encryption keys and authentication data, and the hardware firewall is integrated on an independent circuit board to be physically isolated from the main control system.

[0008] According to the technical solution provided in this application, the physical operation interface is provided with a multi-level safety protection mechanism, which includes a rotary unlocking protective cover, a dual-contact parallel trigger circuit and a pressure sensing component; and when the rotary unlocking protective cover is rotated open, the applied pressure simultaneously covers the dual-contact area of the dual-contact parallel trigger circuit, and the pressure value displayed by the pressure sensing component exceeds a first preset pressure and remains for more than a first preset time to trigger an emergency command.

[0009] In a second aspect, the present application proposes a hardware-level security control method for an intelligent robot, which is implemented based on the intelligent robot hardware-level security control device as described above; the method comprises the following steps: The independent security protection module monitors abnormal signals of the main control system in real time and determines the threat level, wherein the abnormal signals include at least one of illegal instruction injection, unauthorized protocol communication, and control signal mutation; If it is detected that the threat level is greater than the first preset level, a hardware-level emergency instruction is generated; the hardware-level emergency instruction includes a power circuit fuse code and a network physical isolation code; Through the hard-wired direct connection channel of the emergency control module, the power circuit fuse code is converted into a first drive signal to trigger the triggerable circuit breaker component, and at the same time, the network physical isolation code is converted into a second drive signal to activate the selected physical destruction unit in the isolation component, so as to parallel the power circuit fuse and the physical cutoff of the network communication line.

[0010] According to the technical solution provided in the embodiment of the present application, the physical destruction unit selected in the isolation component is an overvoltage breakdown unit, and the second driving signal is used to trigger the overvoltage breakdown unit to generate a preset threshold voltage; After the parallel power circuit is fused and the network communication line is physically cut off, the following steps are also included: Sending an operation verification report to the external control terminal via the encrypted communication channel; The operation verification report includes: The trigger timing diagram of the micro-explosion unit in the triggerable circuit breaker component, where the trigger timing diagram is generated by directly collecting encrypted ignition signals in real time through the hard-wired direct connection channel; The signal spectrum analysis data after breaking through the network communication unit is obtained by the spectrum sampling circuit built in the overvoltage breakdown unit; The operation of the encrypted communication channel is independent of the network protocol stack of the robot main control system.

[0011] According to the technical solution provided by the embodiment of the present application, the real-time monitoring of the abnormal signals of the main control system by the independent security protection module and the judgment of the threat level include the following steps: Obtain the personnel density around the robot and the space tightness coefficient where the robot is located to obtain the environmental sensitivity factor, and judge the space type where the robot is located, where the space type includes an open space and a closed space; Obtain the threat level according to the number of the abnormal signals and the environmental sensitivity factor; The hard-wired direct connection channel of the emergency control module converts the power circuit fuse coding into a first drive signal to trigger the triggerable circuit breaker component, and at the same time converts the network physical isolation coding into a second drive signal to activate the selected physical damage unit in the isolation component, including the following steps: If the space type is a closed space, then through the hard-wired direct connection channel of the emergency control module, convert the power circuit fuse coding into a first drive signal to trigger the triggerable circuit breaker component, and at the same time convert the network physical isolation coding into a second drive signal to activate the selected physical damage unit in the isolation component.

[0012] According to the technical solution provided by the embodiment of the present application, after obtaining the threat level according to the number of the abnormal signals and the environmental sensitivity factor, the following steps are further included: If the space type is an open space, give priority to physically truncating the network communication line and then fusing the power circuit.

[0013] Compared with the prior art, the beneficial effects of the present application are as follows: Through the synergistic effect of the power cut-off execution module and the network destruction module, the present application synchronously blocks the power output and network communication of the robot, completely eliminates the dual risks of hardware out-of-control and data leakage, and forms a comprehensive security protection; the hard-wired direct connection channel directly drives the power cut-off and network destruction modules to avoid signal interference caused by the intrusion of the main control system; the hardware firewall and the encrypted communication unit build an independent secure communication link to prevent external attack penetration. The security control device proposed in the present application can ensure that even if the main system is controlled when the main control fails, the power and network can still be cut off by hardware. Physically destroy the network communication to prevent remote control. The independent security protection module is not affected by the vulnerabilities of the main system, ensuring the safety of the emergency channel. The hard-wired direct connection ensures that the signal is not tampered with, and the response speed is fast. The closed-loop system is independent of the main system and will not be affected by the failures or attacks of the main system. Therefore, the robot equipped with this security control device is more reliable in terms of security control. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 FIG. is a schematic structural diagram of a hardware-level security control device for an intelligent robot provided by the present application; Figure 2 FIG. is a flowchart of the steps of a hardware-level security control method for an intelligent robot provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0015] The present application will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention, rather than limiting the invention. In addition, it should be noted that only the parts related to the invention are shown in the drawings for the convenience of description.

[0016] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.

[0017] Embodiment 1 As mentioned in the background art, in view of the problems in the prior art, the present application proposes a hardware-level security control device for an intelligent robot, as Figure 1 shown, including: A power cut-off execution module, the power cut-off execution module includes a triggerable circuit breaker component provided in the main power circuit of the robot; A network destruction module, the network destruction module is configured with an isolation component that can physically destroy the network communication unit of the robot; An independent security protection module, the independent security protection module integrates a hardware firewall and an encrypted communication unit; Emergency control module, which is electrically connected to the power cut-off execution module and the network destruction module respectively through hard-wired direct connection channels, and establishes an encrypted communication channel with an external control terminal via the independent security protection module, forming a closed-loop security control system independent of the robot's main control system.

[0018] Specifically, the power cut-off execution module is directly embedded in the robot's main power circuit (such as a 48V DC power supply bus or a 380V AC main circuit), connected in series between the power distribution unit (PDU) and the drive motor. Its core component is a triggerable circuit breaker component, which forcibly disconnects the circuit through physical contacts or a fusing mechanism. The trigger signal path is to receive the drive signal of the emergency control module through the hard-wired direct connection channel, bypassing any intermediate processing links of the main control system. The network destruction module is closely attached to the robot's network communication unit (such as an Ethernet switch, a Wi-Fi module, or a 5G communication board), and the physical destruction unit is directly soldered on the PCB line of the network interface. Its core component is an isolation component, which realizes network isolation through high-voltage breakdown, chip burning, or physical wire breaking. Trigger mode: directly driven by the hard-wired signal of the emergency control module, with a trigger response time < 10ms. The independent security protection module is a dedicated circuit board independent of the main control system, maintaining a physical distance of at least 10mm from the main control board, and is connected to the emergency control module through shielded cables. Its core components include a hardware firewall, a deep packet inspection (DPI) engine based on FPGA, which analyzes the communication protocols between the main control system and the external network in real time, and also includes an encrypted communication unit: a security chip using the national secret SM4 algorithm, and the storage unit uses a physically isolated FRAM memory to store keys. The communication interface interacts with the emergency control module through an optically isolated SPI bus to ensure electrical isolation. The emergency control module is in an independent metal shielding box and is directly connected to each execution module through aviation plugs. The hard-wired direct connection channel uses a twisted pair shielded wire to directly connect the trigger ends of the power cut-off module and the network destruction module to avoid signal interference. The encrypted communication channel establishes an AES-256 encrypted link with the remote control terminal through the encrypted chip of the independent security module, and uses a dedicated frequency band (such as ISM 868MHz) to transmit instructions.

[0019] Describe the collaborative workflow: Anomaly detection phase: The hardware firewall of the independent security protection module continuously monitors the network traffic of the master control system. If an abnormal instruction (such as an unverified CAN bus command) is detected, the threat level assessment is immediately initiated. The encryption communication unit synchronously verifies the identity of the external control terminal. If unauthorized access is found, an alarm signal is triggered. Emergency response phase: The emergency control module sends a high-voltage pulse signal (such as 24V / 2A) to the power cut-off module through a hard-wired direct connection channel, driving the circuit breaker component to fuse the power supply circuit within 20ms. At the same time, a trigger signal is sent to the network destruction module to activate the overvoltage breakdown unit (such as releasing a 48V reverse voltage) to burn the pins of the network PHY chip. Feedback and verification phase: The independent security module sends a fuse status report (such as the trigger timestamp of the circuit breaker component, the signal residue strength after network isolation) to the control terminal through an encrypted channel. After the master control system is completely powered off, the emergency control module switches to the backup power supply (such as a super capacitor) to maintain encrypted communication for at least 30 minutes.

[0020] This embodiment can achieve physical isolation reliability. Through the hard-wired direct connection and independent power supply design, even if the master control CPU is invaded, the emergency instructions can still be executed smoothly. The overall system response time: The total delay from anomaly detection to the completion of power cut-off and network isolation is very short, meeting the safety standards.

[0021] In a preferred embodiment, the triggerable circuit breaker component is a PBD component using an explosion-driven circuit breaker mechanism. The PBD component includes a fusible conductor segment provided in the main power circuit, a micro-explosion unit coupled to the fusible conductor segment, and an ignition trigger circuit.

[0022] Specifically, the fusible conductor segment uses a copper-nickel alloy thin sheet with a thickness of 0.1mm. The designed fracture point is located at the V-shaped groove in the middle of the conductor, and it is welded between the positive and negative poles of the power bus. It can carry a maximum current of 200A during normal operation. The micro-explosion unit is a sealed metal cavity filled with lead azide explosive (explosive charge 50mg), which is isolated from the conductor segment by a ceramic insulator. The trigger circuit uses an opto-isolated dual-verification mechanism and needs to receive both the 12V trigger signal from the emergency module and the encrypted verification code from the independent security module simultaneously. The ignition trigger circuit uses a parallel connection of a dual-channel MOSFET drive circuit to ensure that a single-point failure does not affect the trigger reliability. The housing meets the IP67 protection level, and the interior is filled with epoxy resin to prevent moisture intrusion. The entire working process is as follows: When the emergency control module confirms that the power needs to be cut off, it sends an encrypted ignition instruction to the PBD component. After the ignition circuit verifies the instruction signature, it applies a 12V / 1A current to the micro-explosion unit to detonate the explosive. The explosion shock wave causes the conductor segment to break at the V-shaped groove, forming a permanent air gap.

[0023] In a preferred embodiment, the PBD component is provided with a dual trigger interface, which includes a physical operation interface and a wireless control interface. The physical operation interface is equipped with a mechanical emergency stop button or a pull rod trigger mechanism, and the wireless control interface supports Bluetooth, radio frequency or infrared remote control triggering methods.

[0024] Specifically, the mechanical emergency stop button is a red mushroom-head button with built-in bimetallic contacts. It is installed in a prominent position on the robot shell (such as the back or top) and is connected to the PBD component through a waterproof connector. When the button is pressed, the mechanical linkage directly short-circuits the safety lock of the ignition circuit, bypassing the electronic verification link. The communication protocol of the wireless control interface is a private radio frequency protocol based on AES-128 encryption (frequency band 433MHz), with an effective control distance of 50m and dynamic rolling code verification. Each trigger must match a 32-bit random number to prevent replay attacks. Collaborative trigger logic: The physical interface has the highest priority. Pressing the emergency stop button can directly trigger the PBD fuse to blow without going through the emergency control module. The wireless interface must pass the identity authentication of an independent security module: After the control terminal sends the command, the security chip compares the pre-stored key and forwards the trigger signal after verification. This implementation method has redundant reliability and a high success rate for dual-channel triggering.

[0025] In a preferred embodiment, the isolation component adopts an IGB isolation component, and the IGB isolation component includes at least one of the following physical destruction units: an overvoltage breakdown unit connected in parallel on the network signal line, an independently powered electromagnetic pulse generator, and a physical disconnection mechanism equipped with a micro-shearing component.

[0026] Specifically, the IGB isolation component is an isolated gate breaker (IGB). The overvoltage breakdown unit is a TVS diode array connected in parallel with the network signal lines (such as Ethernet TX / RX lines). The breakdown voltage is set to three times the network voltage (e.g., 15V). The triggering method is: the emergency module sends a 12V drive signal, which causes the TVS diode to enter avalanche breakdown, creating a permanent short circuit. The electromagnetic pulse generator circuit design: a three-stage Marx generator, outputting a 20kV / 10ns pulse, which is coupled to the network chip power pins via a loop antenna. The installation location is directly soldered to the VCC and GND pads of the network PHY chip. The electromagnetic pulse (EMP pulse) can burn out the chip's internal circuitry. The physical disconnection mechanism is a micro linear motor driving a tungsten carbide blade to cut the network cable (such as an RJ45 cable). The trigger logic is that after receiving a 24V pulse, the motor completes the cutting action within 30ms. The collaborative working mode: Selective triggering: Activating different destruction units based on the threat type: Data leakage risk: Prioritizing EMP to burn out the chip. Physical intrusion scenario: Activate the shear mechanism to completely cut the line.

[0027] In a preferred embodiment, the encryption communication unit includes a security chip and a physically isolated storage unit, wherein the security chip is solidified with a custom communication protocol stack; the storage unit stores encryption keys and authentication data, and the hardware firewall is integrated on an independent circuit board to be physically isolated from the main control system.

[0028] The security chip can optionally be an ASIC supporting the nationally encrypted SM4 and SM2 algorithms, with a computing speed of up to 1 Gbps. Protocol stack hardening: Custom communication protocols (such as Modbus-based security extensions) are burned into the chip's ROM to prevent tampering. Physically isolated storage: FRAM (ferroelectric random access memory) is used, isolated from the main control system by an optical coupler, allowing access only to the security chip. Key management: Root keys are pre-injected into the FRAM, session keys are dynamically generated, and the storage unit features a layer of protection against side-channel attacks. Hardware firewall architecture: An independent circuit board design connects to the main control board via pin headers, and inter-board communication utilizes an encrypted SPI bus tunnel. Packet filtering rules: 200 pre-set rules plus dynamically learned rules are available, capable of identifying Stuxnet-like attack signatures. Encrypted communication process: Identity authentication: The external terminal sends an SM2 digital certificate, and the security chip verifies the certificate chain before establishing a session. Data transmission: Commands are encrypted using SM4-CTR mode, with each data packet appended with an HMAC-SM3 signature. Emergency command priority transmission: The encrypted channel reserves dedicated bandwidth for emergency commands, ensuring latency of less than 10ms.

[0029] In a preferred embodiment, the physical operation interface is provided with a multi-level safety protection mechanism, which includes a rotary unlocking protective cover, a dual-contact parallel trigger circuit and a pressure sensing component; and when the rotary unlocking protective cover is rotated open, the applied pressure simultaneously covers the dual contact area of the dual-contact parallel trigger circuit, and the pressure value displayed by the pressure sensing component exceeds a first preset pressure and remains for more than a first preset time to trigger an emergency instruction.

[0030] Specifically, the rotary unlocking protective cover is made of 316L stainless steel and embedded with double-row ball bearings. It requires a 120° clockwise rotation to unlock. A Hall sensor is integrated at the bottom of the protective cover to monitor the rotation angle in real time and transmit the signal to the emergency control module. The installation position is at the center of the emergency operation panel on the robot housing and is coaxially installed with the double-contact trigger mechanism. The bimetallic contacts of the double-contact parallel trigger circuit are made of silver-nickel alloy material (contact diameter 8mm), with a spacing of 15mm, and are connected in parallel to a 24V DC safety circuit. The contact surface is gold-plated, with a contact resistance <10mΩ, and is connected to the emergency control module through redundant dual-channel signal lines. Trigger logic: It is necessary to press both contact areas (each with an area of 150mm²) simultaneously to form a closed circuit. The pressure sensing component uses a MEMS piezoresistive pressure sensor. The sensor array is arranged directly below the contacts and covers a circular area with a diameter of 30mm, with a sampling frequency of 100Hz.

[0031] Specifically, data processing: The pressure data is transmitted to the independent safety protection module through the CAN bus and continuously monitored using a sliding window algorithm (window duration 500ms). The first preset pressure can be selected as 8kg (the total for the double contacts needs to be >16kg), and the first preset duration can be selected as 3 seconds, that is, the holding duration needs to be ≥3 seconds. Cooperative work process: Protective cover unlocking stage: When the operator rotates the protective cover clockwise to 120°, the Hall sensor detects the pole change and sends an unlocking signal to the emergency control module. The protective cover automatically pops up 10mm, exposing the double-contact operation area below. At this time, the trigger circuit is still in an open state. Double-contact pressing stage: The operator needs to cover both contact areas with the palm (to prevent accidental single-finger touch) and apply a vertical pressure. The pressure sensor continuously detects the distribution state: If the unilateral pressure >5kg and the bilateral pressure difference <30%, it is determined as a valid press. Duration verification stage: When the cumulative pressure value exceeds 16kg and lasts for 3 seconds, the independent safety protection module generates a dynamic verification code (6-digit rolling code). The emergency control module compares the verification code with the pre-stored key. After confirmation, it sends an emergency instruction to the power cut-off execution module. Emergency instruction execution: A 24V drive signal with a pulse width of 100ms is transmitted through a hard-wired direct connection channel to trigger the micro-explosion unit of the PBD component, and at the same time, activate the physical disconnection mechanism of the network destruction module to cut off the network connection.

[0032] This embodiment realizes mechanical-electronic double interlock: The physical unlocking of the rotary protective cover and the electronic verification form a series logic. Two operations (rotation first and then pressing) must be completed in sequence to prevent direct triggering by violent destruction. Pressure distribution recognition: By analyzing the pressure difference between the double contacts and verifying the force application duration, it can effectively distinguish between intentional human operations and accidental collisions (such as instantaneous impacts caused by tool drops). Dynamic key protection: The rolling code generated each time a trigger occurs is bound to the clock signal of the security chip, ensuring that even if an attacker steals historical data, they cannot forge valid instructions.

[0033] Example 2 This embodiment proposes a hardware-level security control method for intelligent robots, which is implemented based on the intelligent robot hardware-level security control device described in Example 1; as Figure 2 shown, it includes the following steps: S1. The independent security protection module is used to continuously monitor the abnormal signals of the main control system in real time and judge the threat level. The abnormal signals include at least one of illegal instruction injection, unauthorized protocol communication, and control signal mutation; Specifically, the monitoring objects of abnormal signals include: Illegal instruction injection: By means of the instruction whitelist mechanism of the hardware firewall, compare the CAN bus instructions received by the main control system with the pre-stored legal instruction signature codes (such as check bits, timing characteristics). Unauthorized protocol communication: Use deep packet inspection (DPI) technology to identify protocol types not registered in the RFC standard library (such as custom TCP port > 49151). Control signal mutation: Establish a Kalman filter prediction model for the motor control signal (such as PWM duty cycle). When the deviation between the actual value and the predicted value > 15%, an alarm is triggered. Data acquisition method: Real-time capture of the main control system I / O signals through a high-speed ADC (sampling rate 1MHz). Use FPGA to implement parallel signal processing.

[0034] S2. If it is detected that the threat level is greater than the first preset level, generate a hardware-level emergency instruction; the hardware-level emergency instruction includes a power circuit fuse coding and a network physical isolation coding; Optionally, the threat level is divided into 5 levels (L1-L5). The first preset level refers to the demarcation level in threat level assessment, and the first preset level is usually set to L3 (corresponding comprehensive score is 8). When the threat level exceeds L3, a hardware-level emergency response is triggered. Threat level determination algorithm: Construct a multi-dimensional threat assessment matrix, weight assignment: illegal instruction (40%), protocol exception (30%), signal mutation (30%). Emergency instruction generation coding rule: Power circuit fuse coding: 32-bit dynamic encryption instruction, including the target circuit breaker ID (such as PBD component serial number), fuse priority (0-255). Network physical isolation coding: 16-bit control word, specifying the type of activated destruction unit (such as overvoltage breakdown = 0x01, electromagnetic pulse = 0x02).

[0035] S3. Through the hard-wired direct connection channel of the emergency control module, convert the power circuit fuse coding into a first drive signal to trigger the triggerable circuit breaker component, and at the same time convert the network physical isolation coding into a second drive signal to activate the selected physical destruction unit in the isolation component, so as to simultaneously fuse the power circuit and physically cut off the network communication line.

[0036] Specifically, the first drive signal converts the fusing code into a 24V pulse with a pulse width of 100ms, drives the PBD ignition module through an optocoupler isolation circuit, and the second drive signal selects the corresponding destruction unit according to the network physical isolation code. For example, a 48V reverse voltage is output to the overvoltage breakdown unit, and a hardware timer is used to ensure that the trigger time difference between power cut-off and network destruction is <5ms.

[0037] This embodiment can achieve physical signal-level monitoring, directly capture the original electrical signal at the hardware layer, and avoid the risk of data tampering at the operating system level; it also triggers through hardwired direct connection, and the emergency instruction transmission path completely bypasses the main control CPU, ensuring that it can still be executed even if the main control system crashes.

[0038] In a preferred embodiment, the selected physical destruction unit in the isolation component is an overvoltage breakdown unit, and the second drive signal is used to trigger the overvoltage breakdown unit to generate a preset threshold voltage; After the parallel power circuit is fused and the network communication line is physically truncated, the following steps are further included: Send an operation verification report to the external control terminal through the encrypted communication channel; Among them, the operation verification report includes: The trigger timing diagram of the micro-explosion unit in the triggerable circuit breaker component, and the trigger timing diagram is generated by real-time collecting the encrypted ignition signal through the hardwired direct connection channel; The signal spectrum analysis data after breaking through the network communication unit is obtained by the spectrum sampling circuit built in the overvoltage breakdown unit; The operation of the encrypted communication channel is independent of the network protocol stack of the robot main control system.

[0039] Specifically, the circuit design of the overvoltage breakdown unit: A bidirectional TVS diode array is connected in parallel on the Ethernet TX+ / TX- line, and the breakdown voltage is set to 48V. A energy storage capacitor bank is configured, and the stored electrical energy is instantaneously released through a MOSFET switch. Trigger process: The emergency control module sends a second drive signal to activate the charging circuit, the capacitor bank is charged to 48V within 5ms, and then the thyristor is triggered to conduct, injecting a reverse high voltage into the network line. The TVS tube breaks down to form a permanent short circuit, and the PHY chip pin melts.

[0040] Specifically, the generation of the operation verification report: Trigger timing diagram acquisition: Use a high-speed digital isolator to capture the rising edge time of the PBD ignition circuit in real time, and the data is encrypted by AES-128 and encapsulated into a binary log file. Spectrum analysis implementation: The overvoltage breakdown unit is built with a radio frequency sampling circuit, and the residual signal strength is analyzed by FFT. Independent communication channel: Use LoRa modulation technology (frequency band 433MHz) to establish a point-to-point link, which is physically isolated from the Wi-Fi / ethernet of the main control system.

[0041] In a preferred embodiment, the independent security protection module monitors the abnormal signals of the main control system in real time and judges the threat level, including the following steps: Obtain the personnel density around the robot and the space tightness coefficient where the robot is located to obtain an environmental sensitivity factor, and judge the space type where the robot is located. The space type includes an open space and a closed space; Obtain the threat level according to the number of the abnormal signals and the environmental sensitivity factor; The hard-wired direct connection channel of the emergency control module converts the power circuit fuse code into a first drive signal to trigger the triggerable circuit breaker component, and at the same time converts the network physical isolation code into a second drive signal to activate the selected physical damage unit in the isolation component, including the following steps: If the space type is a closed space, through the hard-wired direct connection channel of the emergency control module, convert the power circuit fuse code into a first drive signal to trigger the triggerable circuit breaker component, and at the same time convert the network physical isolation code into a second drive signal to activate the selected physical damage unit in the isolation component.

[0042] Specifically, the safety control device in Embodiment 1 further includes an environmental perception module. The environmental perception module is used for personnel density detection and space type determination. The UWB positioning system real-time tracks the number of people within a radius of 5 m around the robot to assist visual recognition: a 2-million-pixel wide-angle camera cooperates with the YOLOv5 algorithm for human detection. Density value = instantaneous number of people / detection area, sampling interval is 1 second. Space tightness coefficient calculation: Parameter acquisition: Obtain the space size (length × width × height) through a laser rangefinder, and use a barometric pressure sensor to detect the pressure difference at the ventilation opening to calculate the effective ventilation area. Calculation formula: tightness coefficient = space volume (m³) / (ventilation area (m²) × 10). When the tightness coefficient > 5, it is determined as a closed space, and the tightness coefficient 5 is determined as an open space. The environmental sensitivity factor (a parameter for quantifying environmental risk) is dynamically related to the comprehensive score (S) corresponding to the threat level: The formula for calculating the comprehensive score (S) of the threat level: S = log2(1 + the number of abnormal signals) × the enclosure coefficient; Example: When 3 abnormal signals are detected and the enclosure coefficient = 6, S = log2(4) × 6 = 2 × 6 = 12; Threat level mapping: Comprehensive score S < 8 → Threat level L1 / L2 (Response: Only alarm); Comprehensive score 8 ≤ S < 15 → Threat level L3 (Response: Partial function limitation); Comprehensive score S ≥ 15 → Threat level L4 / L5 (Response: Trigger hardware-level emergency); When it is determined as an enclosed space (such as an elevator cabin, explosion-proof chamber), the safety of personnel is ensured first: Synchronously cut off the power to prevent mechanical out-of-control collision, and immediately destroy the network to block remote control. It should be noted that the above-described parallel power cut-off and network destruction are only applicable to the scenario of an enclosed space.

[0043] In a preferred embodiment, after obtaining the threat level according to the number of abnormal signals and the environmental sensitivity factor, the following steps are further included: If the space type is an open space, the physical truncation of the network communication line is preferentially executed, and then the power circuit is fused.

[0044] Specifically, the emergency control module first sends a network isolation code to activate the physical destruction unit, sets a 300 ms time window, and ensures that the power fuse is triggered after the network is destroyed. Executing in sequence in this scenario can block the remote control channel, prevent the attacker from sending the last instruction during the power-off interval, and can also reserve a safe deceleration time for the power system (such as the braking process of a servo motor).

[0045] Specifically, the delayed fuse control timing management uses a hardware watchdog timer to monitor the network destruction completion signal. If the completion signal is not received within 300 ms, the power fuse is forcibly triggered.

[0046] In this article, specific examples are used to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. The above is only the preferred implementation manner of the present application. It should be noted that due to the limited nature of written expression and objectively there are infinite specific structures, for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements, refinements or changes can be made, or the above technical features can be combined in an appropriate manner; these improvements, refinements, changes or combinations, or directly applying the concept and technical solution of the invention to other occasions without improvement, should all be regarded as the protection scope of the present application.

Claims

1. An intelligent robot hardware-level safety control device, characterized in that include: A power cut-off execution module, the power cut-off execution module including a triggerable circuit breaker component provided in the main power circuit of the robot; a network destruction module configured with an isolation component capable of physically destroying the robot's network communication unit; An independent security protection module, wherein the independent security protection module integrates a hardware firewall and an encrypted communication unit; An emergency control module is electrically connected to the power cut-off execution module and the network destruction module through hard-wired direct connection channels, and establishes an encrypted communication channel with the external control terminal through the independent security protection module, forming a closed-loop safety control system independent of the robot's main control system.

2. The intelligent robot hardware-level safety control device according to claim 1, wherein: The triggerable circuit breaker assembly is a PBD assembly that adopts an explosion-driven circuit breaker mechanism. The PBD assembly includes a fusible conductor segment arranged in the main power circuit, a micro-blasting unit coupled to the fusible conductor segment, and an ignition trigger circuit.

3. The intelligent robot hardware-level safety control device according to claim 2, wherein: The PBD component is provided with a dual trigger interface, which includes a physical operation interface and a wireless control interface. The physical operation interface is equipped with a mechanical emergency stop button or a pull rod trigger mechanism, and the wireless control interface supports Bluetooth, radio frequency or infrared remote control triggering methods.

4. The intelligent robot hardware-level safety control device according to claim 1, characterized in that: The isolation component adopts an IGB isolation component, and the IGB isolation component includes at least one of the following physical destruction units: an overvoltage breakdown unit connected in parallel on the network signal line, an independently powered electromagnetic pulse generator, and a physical disconnection mechanism equipped with a micro shearing component.

5. The intelligent robot hardware-level safety control device according to claim 1, wherein: The encryption communication unit includes a security chip and a physically isolated storage unit. The security chip is solidified with a custom communication protocol stack; the storage unit stores encryption keys and authentication data. The hardware firewall is integrated on an independent circuit board to be physically isolated from the main control system.

6. The intelligent robot hardware-level safety control device according to claim 3, wherein: The physical operation interface is provided with a multi-level safety protection mechanism, which includes a rotary unlocking protective cover, a dual-contact parallel trigger circuit and a pressure sensing component; and when the rotary unlocking protective cover is rotated to open, the applied pressure simultaneously covers the dual contact areas of the dual-contact parallel trigger circuit, and the pressure value displayed by the pressure sensing component exceeds a first preset pressure and remains for more than a first preset time to trigger an emergency command.

7. An intelligent robot hardware-level security control method, which is implemented based on the intelligent robot hardware-level security control device described in any one of claims 1-6; characterized in that: The following steps are involved: The independent security protection module monitors abnormal signals of the main control system in real time and determines the threat level, wherein the abnormal signals include at least one of illegal instruction injection, unauthorized protocol communication, and control signal mutation; If it is detected that the threat level is greater than the first preset level, a hardware-level emergency instruction is generated; the hardware-level emergency instruction includes a power circuit fuse code and a network physical isolation code; Through the hard-wired direct connection channel of the emergency control module, the power circuit fuse code is converted into a first drive signal to trigger the triggerable circuit breaker component, and at the same time, the network physical isolation code is converted into a second drive signal to activate the selected physical destruction unit in the isolation component, so as to parallel the power circuit fuse and the physical cutoff of the network communication line.

8. The intelligent robot hardware-level security control method according to claim 7, characterized in that: The selected physical damage unit in the isolation component is an overvoltage breakdown unit, and the second drive signal is used to trigger the overvoltage breakdown unit to generate a preset threshold voltage; After the parallel power circuit is fused and the network communication line is physically truncated, the following steps are further included: Send an operation verification report to an external control terminal through the encrypted communication channel; Among them, the operation verification report includes: The trigger timing diagram of the micro-explosion unit in the triggerable circuit breaker component, which is generated by the hardwired direct connection channel in real time by collecting encrypted ignition signals; The signal spectrum analysis data after the network communication unit is broken down, which is obtained by the spectrum sampling circuit built in the overvoltage breakdown unit; The operation of the encrypted communication channel is independent of the network protocol stack of the robot main control system.

9. The intelligent robot hardware-level security control method according to claim 7, wherein: The steps of the independent security protection module for real-time monitoring of abnormal signals of the main control system and judging the threat level include: Obtain the personnel density around the robot and the space tightness coefficient where the robot is located to obtain an environmental sensitivity factor, and judge the space type where the robot is located. The space type includes an open space and a closed space; Obtain the threat level according to the number of the abnormal signals and the environmental sensitivity factor; The steps of converting the power circuit fuse code into a first drive signal through the hardwired direct connection channel of the emergency control module to trigger the triggerable circuit breaker component, and at the same time converting the network physical isolation code into a second drive signal to activate the selected physical damage unit in the isolation component include: If the space type is a closed space, convert the power circuit fuse code into a first drive signal through the hardwired direct connection channel of the emergency control module to trigger the triggerable circuit breaker component, and at the same time convert the network physical isolation code into a second drive signal to activate the selected physical damage unit in the isolation component.

10. The intelligent robot hardware-level security control method according to claim 9, characterized in that: After obtaining the threat level according to the number of the abnormal signals and the environmental sensitivity factor, the following steps are further included: If the space type is an open space, first perform the physical truncation of the network communication line, and then perform the power circuit fuse.

Citation Information

Patent Citations

  • Robot safety circuit and control method thereof

    CN110794805A

  • Safety control equipment of robot, control method of robot and robot

    CN111331619A

  • Network security equipment integration system of intelligent building

    CN118675277A

  • SF6 gas state intelligent diagnosis and early warning system based on Internet of Things

    CN120160765A

  • Methods and systems providing cyber defense for electronic identification, vehicles, ancillary vehicle platforms and telematics platforms

    US20210075825A1

Cited By

  • Computer communication security processing device

    CN121441620A

  • A computer communication security processing device

    CN121441620B