A hardware-level safety control device and control method for intelligent robots

Through the hardware-level security control device of the intelligent robot, the hard-wire direct connection channel and independent safety protection module are adopted to solve the problem of poor reliability of the robot's emergency stop control, and realize that even if the main control system is invaded, it can reliably block power and network communication, ensuring safety and response speed.

CN120395918BActive Publication Date: 2025-09-02TIANJIN HAISHI INTELLIGENT TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510919522.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-09-02
Estimated Expiration
2045-07-04

AI Technical Summary

Technical Problem

The emergency stop control of existing robot safety control devices is poor, and it is prone to fail due to intrusion of the main control system, resulting in the interception or blocking of safety instructions.

Method used

A hardware-level security control device of intelligent robots is designed, including a power cut-off execution module, a network destroy module and an independent security protection module. A closed-loop security control system is formed through a hard-wire direct connection channel, and triggerable circuit breaker components, isolation components and encrypted communication units are used to ensure the independent transmission and execution of emergency instructions.

Benefits of technology

It realizes that even if the main control system is invaded, it can reliably block power output and network communication, prevent hardware out of control and data leakage, ensure the safety and response speed of emergency channels, and is independent of the impact of attacks or failures of the main system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120395918B_ABST
    Figure CN120395918B_ABST
Patent Text Reader

Abstract

The present application provides a hardware-level safety control device for an intelligent robot, comprising a power cut-off execution module including a triggerable circuit breaker component arranged in the main power circuit of the robot; a network destruction module configured with an isolation component that can physically destroy the network communication unit of the robot; an independent safety protection module integrating a hardware firewall and an encryption communication unit; an emergency control module electrically connected to the power cut-off execution module and the network destruction module respectively through a hard-wired direct connection channel, and establishing an encrypted communication channel with an external control terminal through the independent safety protection module, forming a closed-loop safety control system independent of the robot's main control system, and through the synergistic effect of the power cut-off execution module and the network destruction module, the robot's power output and network communication are synchronously blocked, completely eliminating the dual risks of hardware loss of control and data leakage, and forming comprehensive safety protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of intelligent robots, and in particular to a hardware-level safety control device and control method for an intelligent robot. Background Art

[0002] Current robot safety control devices mostly focus on the emergency stop control of servo motors, such as triggering an emergency stop signal through mechanical pressing and supplemented by a status indicator light. For example, the application number is 202210773192.4, and the name is an invention patent for a servo control position command filter and emergency stop device. However, the emergency module designed for this control shares a communication path with the robot's main control system. Once the robot's main control system is invaded, the safety command may be intercepted or blocked, and the reliability of the emergency stop control is poor. Summary of the Invention

[0003] In view of the above-mentioned defects or deficiencies in the prior art, the present application aims to provide a hardware-level safety control device and control method for an intelligent robot to improve the reliability of emergency stop control;

[0004] In a first aspect, the present application proposes a hardware-level safety control device for an intelligent robot, comprising:

[0005] A power cut-off execution module, the power cut-off execution module including a triggerable circuit breaker component provided in the main power circuit of the robot;

[0006] a network destruction module configured with an isolation component capable of physically destroying the robot's network communication unit;

[0007] An independent security protection module, wherein the independent security protection module integrates a hardware firewall and an encrypted communication unit;

[0008] An emergency control module is electrically connected to the power cut-off execution module and the network destruction module through hard-wired direct connection channels, and establishes an encrypted communication channel with the external control terminal through the independent security protection module, forming a closed-loop safety control system independent of the robot's main control system.

[0009] According to the technical solution provided in this application, the triggerable circuit breaker assembly is a PBD assembly that adopts an explosion-driven circuit breaker mechanism. The PBD assembly includes a fusible conductor segment arranged in the main power circuit, a micro-blasting unit coupled to the fusible conductor segment, and an ignition trigger circuit.

[0010] According to the technical solution provided in this application, the PBD component is provided with a dual trigger interface, which includes a physical operation interface and a wireless control interface. The physical operation interface is equipped with a mechanical emergency stop button or a pull rod trigger mechanism, and the wireless control interface supports Bluetooth, radio frequency or infrared remote control triggering methods.

[0011] According to the technical solution provided in this application, the isolation component adopts an IGB isolation component, and the IGB isolation component includes at least one of the following physical destruction units: an overvoltage breakdown unit connected in parallel on the network signal line, an independently powered electromagnetic pulse generator, and a physical disconnection mechanism configured with a micro-shearing component.

[0012] According to the technical solution provided in this application, the encryption communication unit includes a security chip and a physically isolated storage unit, and the security chip is solidified with a custom communication protocol stack; the storage unit stores encryption keys and authentication data, and the hardware firewall is integrated on an independent circuit board to be physically isolated from the main control system.

[0013] According to the technical solution provided in this application, the physical operation interface is provided with a multi-level safety protection mechanism, which includes a rotary unlocking protective cover, a dual-contact parallel trigger circuit and a pressure sensing component; and when the rotary unlocking protective cover is rotated open, the applied pressure simultaneously covers the dual-contact area of ​​the dual-contact parallel trigger circuit, and the pressure value displayed by the pressure sensing component exceeds a first preset pressure and remains for more than a first preset time to trigger an emergency command.

[0014] In a second aspect, the present application proposes a hardware-level security control method for an intelligent robot, which is implemented based on the intelligent robot hardware-level security control device as described above; the method comprises the following steps:

[0015] The independent security protection module monitors abnormal signals of the main control system in real time and determines the threat level, wherein the abnormal signals include at least one of illegal instruction injection, unauthorized protocol communication, and control signal mutation;

[0016] If it is detected that the threat level is greater than the first preset level, a hardware-level emergency instruction is generated; the hardware-level emergency instruction includes a power circuit fuse code and a network physical isolation code;

[0017] Through the hard-wired direct connection channel of the emergency control module, the power circuit fuse code is converted into a first drive signal to trigger the triggerable circuit breaker component, and at the same time, the network physical isolation code is converted into a second drive signal to activate the selected physical destruction unit in the isolation component, so as to parallel the power circuit fuse and the physical cutoff of the network communication line.

[0018] According to the technical solution provided in the embodiment of the present application, the physical destruction unit selected in the isolation component is an overvoltage breakdown unit, and the second driving signal is used to trigger the overvoltage breakdown unit to generate a preset threshold voltage;

[0019] After the parallel power circuit is fused and the network communication line is physically cut off, the following steps are also included:

[0020] Sending an operation verification report to the external control terminal via the encrypted communication channel;

[0021] The operation verification report includes:

[0022] A trigger timing diagram of the micro-blasting unit in the triggerable circuit breaker assembly, wherein the trigger timing diagram is generated by real-time acquisition of the encrypted ignition signal by the hard-wire direct connection channel;

[0023] Signal spectrum analysis data after the network communication unit is broken down is acquired by a spectrum sampling circuit built into the overvoltage breakdown unit;

[0024] The operation of the encrypted communication channel is independent of the network protocol stack of the robot main control system.

[0025] According to the technical solution provided in the embodiment of the present application, the independent security protection module is used to monitor abnormal signals of the main control system in real time and determine the threat level, including the following steps:

[0026] Obtaining the density of people around the robot and the confined space coefficient of the robot to obtain an environmental sensitivity factor, and determining the type of space the robot is in, where the space type includes open space and confined space;

[0027] Obtaining the threat level according to the number of abnormal signals and the environmental sensitivity factor;

[0028] The method includes converting the power circuit fuse code into a first drive signal to trigger the triggerable circuit breaker component through the hard-wired direct connection channel of the emergency control module, and converting the network physical isolation code into a second drive signal to activate the selected physical destruction unit in the isolation component, including the following steps:

[0029] If the space type is a confined space, the power circuit fuse code is converted into a first drive signal through the hard-wired direct connection channel of the emergency control module to trigger the triggerable circuit breaker component, and the network physical isolation code is converted into a second drive signal to activate the selected physical destruction unit in the isolation component.

[0030] According to the technical solution provided in the embodiment of the present application, after obtaining the threat level according to the number of abnormal signals and the environmental sensitivity factor, the following steps are further included:

[0031] If the space type is an open space, the physical disconnection of the network communication line is performed first, and then the power circuit is disconnected.

[0032] Compared with the prior art, the beneficial effects of the present application are as follows: the present application, through the synergistic effect of the power cut-off execution module and the network destruction module, synchronously blocks the robot's power output and network communication, completely eliminating the dual risks of hardware loss of control and data leakage, and forming comprehensive safety protection; the hard-wired direct connection channel directly drives the power cut-off and network destruction modules to avoid signal interference caused by the invasion of the main control system; the hardware firewall and the encryption communication unit build an independent secure communication link to prevent external attacks from penetrating. The safety control device proposed in this application can ensure that even if the main system is controlled, the power and network can still be cut off through hardware when the main control fails. Physically destroying network communications to prevent remote control, the independent safety protection module avoids being affected by vulnerabilities in the main system, ensuring the safety of the emergency channel, the hard-wired direct connection ensures that the signal is not tampered with, the response speed is fast, and the closed-loop system is independent of the main system and will not be affected by failures or attacks of the main system. Therefore, the robot equipped with this safety control device is more reliable in terms of safety control. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 A schematic diagram of the structure of the hardware-level safety control device for an intelligent robot provided in this application;

[0034] Figure 2 This is a flowchart of the steps of the intelligent robot hardware-level security control method provided in this application. DETAILED DESCRIPTION

[0035] The present application will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely for the purpose of explaining the relevant invention and are not intended to limit the invention. It should also be noted that, for ease of description, only portions relevant to the invention are shown in the accompanying drawings.

[0036] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0037] Example 1

[0038] As mentioned in the background technology, in order to solve the problems in the prior art, this application proposes a hardware-level safety control device for intelligent robots, such as Figure 1 As shown, including:

[0039] A power cut-off execution module, the power cut-off execution module including a triggerable circuit breaker component provided in the main power circuit of the robot;

[0040] a network destruction module configured with an isolation component capable of physically destroying the robot's network communication unit;

[0041] An independent security protection module, wherein the independent security protection module integrates a hardware firewall and an encrypted communication unit;

[0042] An emergency control module is electrically connected to the power cut-off execution module and the network destruction module through hard-wired direct connection channels, and establishes an encrypted communication channel with the external control terminal through the independent security protection module, forming a closed-loop safety control system independent of the robot's main control system.

[0043] Specifically, the power cut-off execution module is directly embedded in the robot's main power circuit (such as a 48V DC power supply bus or a 380V AC main circuit) and is connected in series between the power distribution unit (PDU) and the drive motor. Its core component is a triggerable circuit breaker component that forcibly disconnects the circuit through physical contacts or a fuse mechanism. The trigger signal path receives the drive signal from the emergency control module through a hard-wired direct connection channel, bypassing any intermediate processing links in the main control system. The network destruction module is closely attached to the robot's network communication unit (such as an Ethernet switch, Wi-Fi module, or 5G communication board), and the physical destruction unit is directly soldered to the PCB circuit of the network interface. Its core component is an isolation component, which achieves network isolation through high-voltage breakdown, chip burning, or physical disconnection. Triggering method: Directly driven by the hard-wired signal of the emergency control module, the trigger response time is <10ms. The independent security protection module, separate from the main control system's dedicated circuit board and physically separated by at least 10mm, connects to the emergency control module via shielded cables. Its core components include a hardware firewall and an FPGA-based deep packet inspection (DPI) engine for real-time analysis of communication protocols between the main control system and external networks. It also includes an encrypted communication unit: a security chip utilizing the nationally recognized SM4 algorithm, and a physically isolated FRAM memory unit for storing encryption keys. The communication interface interacts with the emergency control module via an optocoupler-isolated SPI bus to ensure electrical isolation. The emergency control module is housed in a separate metal shielded box and directly connects to each actuator module via aviation plugs. Hardwired direct connections utilize twisted-pair shielded cable to connect directly to the trigger terminals of the power cutoff module and network destroy module to prevent signal interference. The encrypted communication channel establishes an AES-256 encrypted link with the remote control terminal via the independent security module's encryption chip, transmitting commands using a dedicated frequency band (such as ISM 868MHz).

[0044] The collaborative workflow is described as follows: Anomaly Detection Phase: The hardware firewall of the independent security protection module continuously monitors the network traffic of the main control system. If an abnormal command (such as an unauthenticated CAN bus command) is detected, a threat level assessment is immediately initiated. The encrypted communication unit simultaneously verifies the identity of the external control terminal and triggers an alarm signal if unauthorized access is detected. Emergency Response Phase: The emergency control module sends a high-voltage pulse signal (e.g., 24V / 2A) to the power disconnect module via a hardwired direct channel, driving the disconnect component to fuse the power circuit within 20ms. Simultaneously, a trigger signal is sent to the network destruction module, activating the overvoltage breakdown unit (e.g., releasing a 48V reverse voltage) to burn out the pins of the network PHY chip. Feedback and Verification Phase: The independent security module sends a disconnect status report (e.g., the disconnect component's trigger timestamp and the residual signal strength after network isolation) to the control terminal via an encrypted channel. After the main control system is completely powered off, the emergency control module switches to a backup power source (e.g., a supercapacitor) to maintain encrypted communication for at least 30 minutes.

[0045] This implementation achieves physical isolation reliability. Through hardwired direct connection and independent power supply design, emergency commands can be successfully executed even if the main control CPU is compromised. System-wide response time: The total delay from anomaly detection to power cutoff and network isolation is very short, meeting safety standards.

[0046] In a preferred embodiment, the triggerable circuit breaker assembly is a PBD assembly that adopts an explosion-driven circuit breaker mechanism. The PBD assembly includes a fusible conductor segment arranged in the main power circuit, a micro-explosive unit coupled to the fusible conductor segment, and an ignition trigger circuit.

[0047] Specifically, the fusible conductor segment is constructed from a 0.1mm thick copper-nickel alloy sheet, with the designed breaking point located at the V-shaped groove in the middle of the conductor. It is welded between the positive and negative poles of the power busbar and can carry a maximum current of 200A during normal operation. The micro-blasting unit houses a sealed metal chamber containing a 50mg lead azide explosive, isolated from the conductor segment by a ceramic insulator. The trigger circuit utilizes a dual-verification mechanism using optocoupler isolation, receiving both a 12V trigger signal from the emergency module and an encrypted verification code from an independent safety module. The ignition trigger circuit utilizes two parallel MOSFET drive circuits to ensure that single-point failures do not affect trigger reliability. The housing meets IP67 protection and is filled with epoxy resin to prevent moisture intrusion. The overall workflow is as follows: When the emergency control module confirms the need to disconnect power, it sends an encrypted ignition command to the PBD assembly. After verifying the command signature, the ignition circuit applies a 12V / 1A current to the micro-blasting unit, detonating the explosive. The blast wave breaks the conductor segment at the V-shaped groove, creating a permanent air gap.

[0048] In a preferred embodiment, the PBD component is provided with a dual trigger interface, which includes a physical operation interface and a wireless control interface. The physical operation interface is equipped with a mechanical emergency stop button or a pull rod trigger mechanism, and the wireless control interface supports Bluetooth, radio frequency or infrared remote control triggering methods.

[0049] Specifically, the mechanical emergency stop button is a red mushroom-head button with built-in bimetallic contacts. It is installed in a prominent position on the robot shell (such as the back or top) and is connected to the PBD component through a waterproof connector. When the button is pressed, the mechanical linkage directly short-circuits the safety lock of the ignition circuit, bypassing the electronic verification link. The communication protocol of the wireless control interface is a private radio frequency protocol based on AES-128 encryption (frequency band 433MHz), with an effective control distance of 50m and dynamic rolling code verification. Each trigger must match a 32-bit random number to prevent replay attacks. Collaborative trigger logic: The physical interface has the highest priority. Pressing the emergency stop button can directly trigger the PBD fuse to blow without going through the emergency control module. The wireless interface must pass the identity authentication of an independent security module: After the control terminal sends the command, the security chip compares the pre-stored key and forwards the trigger signal after verification. This implementation method has redundant reliability and a high success rate for dual-channel triggering.

[0050] In a preferred embodiment, the isolation component adopts an IGB isolation component, and the IGB isolation component includes at least one of the following physical destruction units: an overvoltage breakdown unit connected in parallel on the network signal line, an independently powered electromagnetic pulse generator, and a physical disconnection mechanism equipped with a micro-shearing component.

[0051] Specifically, the IGB isolation component is an isolated gate breaker (IGB). The overvoltage breakdown unit is a TVS diode array connected in parallel with the network signal lines (such as Ethernet TX / RX lines). The breakdown voltage is set to three times the network voltage (e.g., 15V). The triggering method is: the emergency module sends a 12V drive signal, which causes the TVS diode to enter avalanche breakdown, creating a permanent short circuit. The electromagnetic pulse generator circuit design: a three-stage Marx generator, outputting a 20kV / 10ns pulse, which is coupled to the network chip power pins via a loop antenna. The installation location is directly soldered to the VCC and GND pads of the network PHY chip. The electromagnetic pulse (EMP pulse) can burn out the chip's internal circuitry. The physical disconnection mechanism is a micro linear motor driving a tungsten carbide blade to cut the network cable (such as an RJ45 cable). The trigger logic is that after receiving a 24V pulse, the motor completes the cutting action within 30ms. The collaborative working mode: Selective triggering: Activating different destruction units based on the threat type: Data leakage risk: Prioritizing EMP to burn out the chip. Physical intrusion scenario: Activate the shear mechanism to completely cut the line.

[0052] In a preferred embodiment, the encryption communication unit includes a security chip and a physically isolated storage unit, wherein the security chip is solidified with a custom communication protocol stack; the storage unit stores encryption keys and authentication data, and the hardware firewall is integrated on an independent circuit board to be physically isolated from the main control system.

[0053] The security chip can optionally be an ASIC supporting the nationally encrypted SM4 and SM2 algorithms, with a computing speed of up to 1 Gbps. Protocol stack hardening: Custom communication protocols (such as Modbus-based security extensions) are burned into the chip's ROM to prevent tampering. Physically isolated storage: FRAM (ferroelectric random access memory) is used, isolated from the main control system by an optical coupler, allowing access only to the security chip. Key management: Root keys are pre-injected into the FRAM, session keys are dynamically generated, and the storage unit features a layer of protection against side-channel attacks. Hardware firewall architecture: An independent circuit board design connects to the main control board via pin headers, and inter-board communication utilizes an encrypted SPI bus tunnel. Packet filtering rules: 200 pre-set rules plus dynamically learned rules are available, capable of identifying Stuxnet-like attack signatures. Encrypted communication process: Identity authentication: The external terminal sends an SM2 digital certificate, and the security chip verifies the certificate chain before establishing a session. Data transmission: Commands are encrypted using SM4-CTR mode, with each data packet appended with an HMAC-SM3 signature. Emergency command priority transmission: The encrypted channel reserves dedicated bandwidth for emergency commands, ensuring latency of less than 10ms.

[0054] In a preferred embodiment, the physical operation interface is provided with a multi-level safety protection mechanism, which includes a rotary unlocking protective cover, a dual-contact parallel trigger circuit and a pressure sensing component; and when the rotary unlocking protective cover is rotated open, the applied pressure simultaneously covers the dual contact area of ​​the dual-contact parallel trigger circuit, and the pressure value displayed by the pressure sensing component exceeds a first preset pressure and remains for more than a first preset time to trigger an emergency instruction.

[0055] Specifically, the rotary unlocking protective cover is constructed of 316L stainless steel and features an embedded double-row ball bearing. It requires a 120° clockwise rotation to unlock. A Hall effect sensor integrated into the bottom of the cover monitors the rotation angle in real time and transmits the signal to the emergency control module. It is installed in the center of the emergency operation panel on the robot's housing, coaxially with the dual-contact trigger mechanism. The bimetallic contacts of the dual-contact parallel trigger circuit are made of silver-nickel alloy (contact diameter 8mm), with a spacing of 15mm. They are connected in parallel to the 24V DC safety circuit and are gold-plated with a contact resistance of <10mΩ. They are connected to the emergency control module via redundant dual signal lines. The triggering logic requires simultaneous pressing of two contact areas (each 150mm²) to close the circuit. The pressure sensing component utilizes MEMS piezoresistive pressure sensors. The sensor array is arranged directly below the contacts, covering a 30mm diameter circular area, with a sampling frequency of 100Hz.

[0056] Specifically, data processing: Pressure data is transmitted via the CAN bus to the independent safety protection module, where it is continuously monitored using a sliding window algorithm (500ms window duration). The first preset pressure can be 8kg (the combined pressure on both contacts must be greater than 16kg), and the first preset duration can be 3 seconds, meaning the hold time must be ≥ 3 seconds. Collaborative Workflow: Protective Cover Unlocking Phase: When the operator rotates the protective cover clockwise to 120°, the Hall Effect sensor detects the change in magnetic poles and sends an unlock signal to the emergency control module. The protective cover automatically pops up 10mm, revealing the dual-contact operating area underneath. During this time, the trigger circuit remains open. Dual-contact Pressing Phase: The operator covers both contact areas with their palms simultaneously (to prevent accidental single-finger presses) and applies vertical pressure. The pressure sensor monitors the pressure distribution in real time: a valid press is determined if the pressure on one side is greater than 5kg and the pressure difference between the two sides is less than 30%. Duration Verification Phase: When the cumulative pressure exceeds 16kg and persists for 3 seconds, the independent safety protection module generates a dynamic verification code (a 6-digit rolling code). The emergency control module compares the verification code with the pre-stored key and, upon confirmation, sends an emergency command to the power cutoff execution module. Emergency command execution: A hard-wired direct channel transmits a 24V drive signal with a 100ms pulse width, triggering the PBD assembly's micro-explosion unit and simultaneously activating the network destruction module's physical disconnect mechanism, severing the network connection.

[0057] This implementation achieves a dual mechanical-electronic interlock: the physical unlocking of the rotating protective cover and the electronic verification form a serial logic, requiring both steps to be completed sequentially (rotation followed by pressing) to prevent direct triggering by force. Pressure distribution identification: By analyzing the pressure difference between two contact points and verifying the duration of force application, it effectively distinguishes between intentional human intervention and accidental collisions (such as the momentary impact caused by a dropped tool). Dynamic key protection: The rolling code generated by each trigger is bound to the security chip's clock signal, ensuring that even an attacker who steals historical data cannot forge valid instructions.

[0058] Example 2

[0059] This embodiment proposes a hardware-level security control method for an intelligent robot, which is implemented based on the hardware-level security control device for an intelligent robot as described in Example 1; Figure 2 As shown, the following steps are included:

[0060] S1. Real-time monitoring of abnormal signals of the main control system by the independent security protection module, and determination of the threat level, wherein the abnormal signals include at least one of illegal instruction injection, unauthorized protocol communication, and control signal mutation;

[0061] Specifically, the monitoring targets of abnormal signals include: Illegal instruction injection: Through the instruction whitelist mechanism of the hardware firewall, the CAN bus instructions received by the main control system are compared with the pre-stored legal instruction feature codes (such as check bits and timing characteristics). Unauthorized protocol communication: Deep packet inspection (DPI) technology is used to identify protocol types that are not registered in the RFC standard library (such as custom TCP ports > 49151). Control signal mutation: A Kalman filter prediction model is established for motor control signals (such as PWM duty cycle), and an alarm is triggered when the deviation between the actual value and the predicted value is >15%. Data acquisition method: The main control system I / O signal is captured in real time through a high-speed ADC (sampling rate 1MHz). Parallel signal processing is implemented using FPGA.

[0062] S2. If it is detected that the threat level is greater than a first preset level, a hardware-level emergency instruction is generated; the hardware-level emergency instruction includes a power circuit fuse code and a network physical isolation code;

[0063] Optionally, the threat level is divided into 5 levels (L1-L5). The first preset level refers to the demarcation level in the threat level assessment. The first preset level is usually set to L3 (corresponding to a comprehensive score of 8). When the threat level exceeds L3, a hardware-level emergency response is triggered. Threat level determination algorithm: Construct a multi-dimensional threat assessment matrix, and distribute the weights as follows: illegal instructions (40%), protocol anomalies (30%), and signal mutations (30%). Emergency instruction generation coding rules: Power circuit fuse coding: 32-bit dynamic encryption instruction, including the target circuit breaker ID (such as the PBD component serial number) and the fuse priority (0-255). Network physical isolation coding: 16-bit control word, specifying the type of destruction unit to be activated (such as overvoltage breakdown = 0x01, electromagnetic pulse = 0x02).

[0064] S3. Through the hard-wired direct connection channel of the emergency control module, the power circuit fuse code is converted into a first drive signal to trigger the triggerable circuit breaker component, and at the same time, the network physical isolation code is converted into a second drive signal to activate the physical destruction unit selected in the isolation component, so as to parallel the power circuit fuse and the physical disconnection of the network communication line.

[0065] Specifically, the first drive signal converts the fuse code into a 24V pulse with a pulse width of 100ms, and drives the PBD ignition module through the optocoupler isolation circuit. The second drive signal selects the corresponding destruction unit according to the network physical isolation code, such as outputting a 48V reverse voltage to the overvoltage breakdown unit. A hardware timer is used to ensure that the trigger time difference between power cut-off and network destruction is less than 5ms.

[0066] This implementation can achieve physical signal-level monitoring, directly capturing raw electrical signals at the hardware layer, and avoiding the risk of data tampering at the operating system level. It is also triggered through a hard-wired direct connection, and the emergency command transmission path completely bypasses the main control CPU, ensuring that it can still be executed even if the main control system crashes.

[0067] In a preferred embodiment, the physical destruction unit selected in the isolation component is an overvoltage breakdown unit, and the second driving signal is used to trigger the overvoltage breakdown unit to generate a preset threshold voltage;

[0068] After the parallel power circuit is fused and the network communication line is physically cut off, the following steps are also included:

[0069] Sending an operation verification report to the external control terminal via the encrypted communication channel;

[0070] The operation verification report includes:

[0071] A trigger timing diagram of the micro-blasting unit in the triggerable circuit breaker assembly, wherein the trigger timing diagram is generated by real-time acquisition of the encrypted ignition signal by the hard-wire direct connection channel;

[0072] Signal spectrum analysis data after the network communication unit is broken down is acquired by a spectrum sampling circuit built into the overvoltage breakdown unit;

[0073] The operation of the encrypted communication channel is independent of the network protocol stack of the robot main control system.

[0074] Specifically, the circuit design of the overvoltage breakdown unit involves connecting a bidirectional TVS diode array in parallel to the Ethernet TX+ / TX- lines, with a breakdown voltage set to 48V. A storage capacitor bank is configured to instantly release stored energy through MOSFET switches. Triggering process: The emergency control module sends a second drive signal to activate the charging circuit. The capacitor bank charges to 48V within 5ms, then triggers the thyristor to conduct, injecting reverse high voltage into the network line. The TVS diode breaks down, creating a permanent short circuit and melting the PHY chip pins.

[0075] Specifically, the operational verification report is generated as follows: Trigger timing diagram acquisition: A high-speed digital isolator is used to capture the rising edge timing of the PBD ignition circuit in real time. The data is encrypted with AES-128 and then packaged into a binary log file. Spectrum analysis is implemented: The overvoltage breakdown unit has a built-in RF sampling circuit, and residual signal strength is analyzed using FFT. Independent communication channel: LoRa modulation technology (433MHz frequency band) is used to establish a point-to-point link, which is physically isolated from the Wi-Fi / Ethernet of the main control system.

[0076] In a preferred embodiment, the independent safety protection module is used to monitor abnormal signals of the main control system in real time and determine the threat level, including the following steps:

[0077] Obtaining the density of people around the robot and the confined space coefficient of the robot to obtain an environmental sensitivity factor, and determining the type of space the robot is in, where the space type includes open space and confined space;

[0078] Obtaining the threat level according to the number of abnormal signals and the environmental sensitivity factor;

[0079] The method includes converting the power circuit fuse code into a first drive signal to trigger the triggerable circuit breaker component through the hard-wired direct connection channel of the emergency control module, and converting the network physical isolation code into a second drive signal to activate the selected physical destruction unit in the isolation component, including the following steps:

[0080] If the space type is a confined space, the power circuit fuse code is converted into a first drive signal through the hard-wired direct connection channel of the emergency control module to trigger the triggerable circuit breaker component, and the network physical isolation code is converted into a second drive signal to activate the selected physical destruction unit in the isolation component.

[0081] Specifically, the safety control device in Example 1 also includes an environmental perception module, which is used to detect the density of people and determine the type of space. The UWB positioning system tracks the number of people within a 5m radius around the robot in real time, and assists in visual recognition: a 2-megapixel wide-angle camera cooperates with the YOLOv5 algorithm to detect human bodies. Density value = instantaneous number of people / area of ​​the detection area, sampling interval 1 second. Calculation of space sealing coefficient: Parameter collection: obtain the space dimensions (length × width × height) through a laser rangefinder, use an air pressure sensor to detect the pressure difference at the vent, and calculate the effective ventilation area. Calculation formula: Sealing coefficient = space volume (m³) / (ventilation area (m²) × 10), a sealing coefficient > 5 is determined to be a closed space, and a sealing coefficient 5 is determined to be an open space. The environmental sensitivity factor (a parameter for quantifying environmental risks) is dynamically related to the comprehensive score (S) corresponding to the threat level: the calculation formula for the comprehensive score (S) of the threat level is: S=log2(1+number of abnormal signals)×sealing coefficient; Example: When 3 abnormal signals are detected and the sealing coefficient = 6, S=log2(4)×6=2×6=12; Threat level mapping: Comprehensive score S<8 → Threat level L1 / L2 (response: only alarm); Comprehensive score 8≤S<15 → Threat level L3 (response: partial function restriction); Comprehensive score S≥15 → Threat level L4 / L5 (response: triggering hardware-level emergency); When it is determined to be a confined space (such as an elevator cabin or explosion-proof room), priority is given to ensuring the safety of personnel: synchronously cut off the power to prevent mechanical loss of control and collision, and immediately destroy the network to block remote control. It should be noted that the power cut-off and network destruction described above are only for confined space scenarios.

[0082] In a preferred embodiment, after obtaining the threat level based on the number of abnormal signals and the environmental sensitivity factor, the following steps are further included:

[0083] If the space type is an open space, the physical disconnection of the network communication line is performed first, and then the power circuit is disconnected.

[0084] Specifically, the emergency control module first sends a network isolation code, activating the physical destruction unit and setting a 300ms time window to ensure network destruction before triggering the power fuse. This sequential execution in this scenario blocks the remote control channel, preventing an attacker from sending final commands during a power outage. It also allows for safe deceleration time for the power system (e.g., during servo motor braking).

[0085] Specifically, the delayed fuse control timing management uses a hardware watchdog timer to monitor the network destruction completion signal. If the completion signal is not received within 300ms, the power fuse is forcibly triggered.

[0086] This article uses specific examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core ideas of this application. The above is only the preferred implementation method of this application. It should be pointed out that due to the limitations of textual expression, there are objectively infinite specific structures. For ordinary technicians in this technical field, without departing from the principles of the present invention, they can also make several improvements, modifications or changes, and can also combine the above technical features in an appropriate manner; these improvements, modifications, changes or combinations, or the direct application of the inventive concept and technical solution to other occasions without improvement, should be regarded as the scope of protection of this application.

Claims

1. A hardware-level safety control device for an intelligent robot, characterized in that: include: A power cut-off execution module, the power cut-off execution module including a triggerable circuit breaker component provided in the main power circuit of the robot; a network destruction module configured with an isolation component capable of physically destroying the robot's network communication unit; An independent security protection module, wherein the independent security protection module integrates a hardware firewall and an encrypted communication unit; An emergency control module, the emergency control module being electrically connected to the power cut-off execution module and the network destruction module through hard-wired direct connection channels, and establishing an encrypted communication channel with an external control terminal via the independent security protection module, thereby forming a closed-loop safety control system independent of the robot's main control system; The triggerable circuit breaker assembly is a PBD assembly that uses an explosion-driven circuit breaker mechanism. The PBD assembly includes a fusible conductor segment provided in the main power circuit, a micro-explosion unit coupled to the fusible conductor segment, and an ignition trigger circuit. The PBD component is provided with a dual trigger interface, which includes a physical operation interface and a wireless control interface. The physical operation interface is equipped with a mechanical emergency stop button or a pull-rod trigger mechanism, and the wireless control interface supports Bluetooth, radio frequency or infrared remote control triggering mode; The physical operation interface is provided with a multi-level safety protection mechanism, which includes a rotary unlocking protective cover, a dual-contact parallel trigger circuit and a pressure sensing component; and when the rotary unlocking protective cover is rotated to open, the applied pressure simultaneously covers the dual contact areas of the dual-contact parallel trigger circuit, and the pressure value displayed by the pressure sensing component exceeds a first preset pressure and remains for more than a first preset time, which can trigger an emergency command.

2. The intelligent robot hardware-level safety control device according to claim 1, characterized in that: The isolation component adopts an IGB isolation component, and the IGB isolation component includes at least one of the following physical destruction units: an overvoltage breakdown unit connected in parallel on the network signal line, an independently powered electromagnetic pulse generator, and a physical disconnection mechanism equipped with a micro shearing component.

3. The intelligent robot hardware-level safety control device according to claim 1, characterized in that: The encryption communication unit includes a security chip and a physically isolated storage unit. The security chip is solidified with a custom communication protocol stack; the storage unit stores encryption keys and authentication data. The hardware firewall is integrated on an independent circuit board to be physically isolated from the main control system.

4. A method for hardware-level security control of an intelligent robot, implemented based on the intelligent robot hardware-level security control device according to any one of claims 1 to 3; characterized in that: The following steps are involved: The independent security protection module monitors abnormal signals of the main control system in real time and determines the threat level, wherein the abnormal signals include at least one of illegal instruction injection, unauthorized protocol communication, and control signal mutation; If it is detected that the threat level is greater than the first preset level, a hardware-level emergency instruction is generated; the hardware-level emergency instruction includes a power circuit fuse code and a network physical isolation code; Through the hard-wired direct connection channel of the emergency control module, the power circuit fuse code is converted into a first drive signal to trigger the triggerable circuit breaker component, and at the same time, the network physical isolation code is converted into a second drive signal to activate the selected physical destruction unit in the isolation component, so as to parallel the power circuit fuse and the physical cutoff of the network communication line.

5. The intelligent robot hardware-level security control method according to claim 4, characterized in that: The physical destruction unit selected in the isolation component is an overvoltage breakdown unit, and the second driving signal is used to trigger the overvoltage breakdown unit to generate a preset threshold voltage; After the parallel power circuit is fused and the network communication line is physically cut off, the following steps are also included: Sending an operation verification report to the external control terminal via the encrypted communication channel; The operation verification report includes: A trigger timing diagram of the micro-blasting unit in the triggerable circuit breaker assembly, wherein the trigger timing diagram is generated by real-time acquisition of the encrypted ignition signal by the hard-wire direct connection channel; Signal spectrum analysis data after the network communication unit is broken down is acquired by a spectrum sampling circuit built into the overvoltage breakdown unit; The operation of the encrypted communication channel is independent of the network protocol stack of the robot main control system.

6. The intelligent robot hardware-level security control method according to claim 4, characterized in that: The independent safety protection module is used to monitor abnormal signals of the main control system in real time and determine the threat level, including the following steps: Obtaining the density of people around the robot and the confined space coefficient of the robot to obtain an environmental sensitivity factor, and determining the type of space the robot is in, where the space type includes open space and confined space; Obtaining the threat level according to the number of abnormal signals and the environmental sensitivity factor; The method includes converting the power circuit fuse code into a first drive signal to trigger the triggerable circuit breaker component through the hard-wired direct connection channel of the emergency control module, and converting the network physical isolation code into a second drive signal to activate the selected physical destruction unit in the isolation component, including the following steps: If the space type is a confined space, the power circuit fuse code is converted into a first drive signal through the hard-wired direct connection channel of the emergency control module to trigger the triggerable circuit breaker component, and the network physical isolation code is converted into a second drive signal to activate the selected physical destruction unit in the isolation component.

7. The intelligent robot hardware-level security control method according to claim 6, characterized in that: After obtaining the threat level according to the number of abnormal signals and the environmental sensitivity factor, the method further includes the following steps: If the space type is an open space, the physical disconnection of the network communication line is performed first, and then the power circuit is disconnected.

Citation Information

Patent Citations

  • Servo control position instruction filtering and emergency stop device

    CN115274332A

  • Robot safety circuit and control method thereof

    CN110794805A

  • Safety control equipment of robot, control method of robot and robot

    CN111331619A