Gateway device, relay method, and relay program
By introducing an input determination and start control unit into the gateway device, the response time problem caused by the state synchronization delay between the gateway device and the control device is solved, ensuring timely response of safety control and realizing rapid transition of safety state.
Patent Information
- Application Number
- CN202380096066.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-03
- Publication Date
- 2025-10-31
AI Technical Summary
There is a time lag before the control state of the gateway device is synchronized with the control state of the control device, which may result in a response time that does not meet the requirements of security control.
The gateway device has an input determination unit and a start control unit, which are used to determine whether a secure input has been received when a non-secure output is received, and send a secure output instead of a non-secure output when a secure input is received, so as to ensure that the response time meets the requirements.
Even if there is a time lag before the control state of the gateway device is synchronized with the control state of the control device, the required response time in security control can still be met, avoiding the omission of device state transitions.
Smart Images

Figure CN120883576A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a gateway device for relaying communication between an input device and an output device and a control device that controls the output device based on input signals from the input device. Background Technology
[0002] With the development of cloud computing in recent years, research has been conducted on how to leverage the cloud in control systems. In manufacturing, virtual PLCs in the cloud are used to control field equipment, thereby reducing management time. PLC is an abbreviation for Programmable Logic Controller.
[0003] When implementing control of field devices that leverage the cloud, safety controls must be considered. Safety controls are controls related to the protection of field operators and the prevention of accidents. For example, safety controls are required to have fail-safe features.
[0004] In such safety controls, ensuring response time is crucial. Specifically, the required response time for transitioning from a state where field equipment could pose a hazard to the operator to a safe state is explicitly set at a maximum value based on factors such as the safe distance ensured by the field equipment. In control systems utilizing the cloud, the transmission latency during communication over the public network between the field and the cloud is longer than the transmission latency during control operations performed on-site; therefore, failing to meet the required response time becomes a challenge.
[0005] Patent Document 1 describes a method where, in order to meet required response times, a portion of the processing is performed on-site. In the system architecture of Patent Document 1, multiple networks are connected to a higher-level control device via gateway devices. In this architecture, when a control result based on input from an input / output device within a network is output to another input / output device within the same network, the gateway device performs control on behalf of the higher-level control device.
[0006] In Patent Document 1, in addition to the higher-level control device, a gateway device is also required on-site. To overcome this shortcoming, research was conducted on reducing the processing required for the gateway device and minimizing the number of required gateway devices. Specifically, only the processing segments in the control program that impose restrictions on the response time for safety aspects are installed in the gateway device. Furthermore, as a whole system integrating the control device and the gateway device, a vertically distributed processing system is constructed that satisfies safety requirements.
[0007] In Factory Automation (FA), the control program, known as sequential control, typically has the following control structure: actions change for the same input depending on the control context. FA is an abbreviation for Factory Automation. Therefore, simply cutting out a portion of the control program will result in control that is not context-appropriate, thus failing to meet safety requirements. Therefore, in Patent Document 1, the gateway device determines the control state in the control unit based on the data to be relayed, thereby enabling correct control.
[0008] Existing technical documents
[0009] Patent documents
[0010] Patent Document 1: International Publication No. 2022 / 239116 Summary of the Invention
[0011] The problem that the invention aims to solve
[0012] In the approach described in Patent Document 1, there is a time lag before the control state of the gateway device synchronizes with the control state of the control device. Due to this time lag, the control that the gateway device should perform may be missed. As a result, situations may arise where the required response time is not met.
[0013] The purpose of this disclosure is to meet the response time requirements in security controls.
[0014] Methods for solving problems
[0015] The gateway device disclosed herein relays communication between an input device and an output device and a control device that controls the output device based on an input signal from the input device. The gateway device includes: an input determination unit that, upon receiving an unsafe output from the control device as an output signal that controls the control state of the output device to an unsafe state, determines whether a safe input, as an input signal that controls the control state to a safe state, was received from the input device during a storage period prior to receipt; and a start control unit that, if the input determination unit determines that the safe input has been received, does not relay the unsafe output to the output device, but instead sends a safe output to the output device as an output signal that controls the control state of the output device to a safe state.
[0016] Invention Effects
[0017] In this disclosure, when the gateway device receives a non-safe output from the control device, and if it receives a safe input from the input device during the pre-reception storage period, it does not relay the non-safe output to the output device, but instead sends a safe output to the output device. Therefore, even if there is a time lag before the control state of the gateway device synchronizes with the control state of the control device, the required response time in safety control is met. Attached Figure Description
[0018] Figure 1 This is an illustration of a normal system in the prior art.
[0019] Figure 2 This is an illustrative diagram of an abnormal system in the prior art.
[0020] Figure 3 This is a structural diagram of the control system 100 according to Embodiment 1.
[0021] Figure 4 This is a hardware structure diagram of the gateway device 10 according to Embodiment 1.
[0022] Figure 5 This is a functional structure diagram of the gateway device 10 according to Embodiment 1.
[0023] Figure 6 This is a flowchart of the processing of the gateway device 10 in Implementation Method 1.
[0024] Figure 7 This is an explanatory diagram of the data relay processing in Implementation Method 1.
[0025] Figure 8 This is an explanatory diagram of the status monitoring unit 114 in Embodiment 1.
[0026] Figure 9 This is an explanatory diagram of the input determination process in Implementation Method 1.
[0027] Figure 10 This is an explanatory diagram illustrating the effect of the gateway device 10 in Embodiment 1.
[0028] Figure 11 This is a hardware structure diagram of the engineering tool 40 in implementation method 2.
[0029] Figure 12 This is a functional structure diagram of the engineering tool 40 in implementation method 2.
[0030] Figure 13 This is an explanatory diagram of the basic state transitions of the gateway device 10 in Embodiment 2.
[0031] Figure 14 This is a diagram illustrating an example of the state transition of the control device 30 in Embodiment 2.
[0032] Figure 15 This is a diagram showing an example of the state transitions of the control device 30 in Embodiment 2 in tabular form.
[0033] Figure 16 This is a diagram showing an example of the state transitions of the gateway device 10 in Embodiment 2 in tabular form. Detailed Implementation
[0034] Implementation Method 1
[0035] The following explanation is based on certain premises.
[0036] In Implementation 1, the control device uses control logic to control the input / output devices. The input / output devices operate the controlled equipment according to the control of the control device. The control logic is, for example, a combination of safety logic defined by standard specifications such as PLCopen, and has both safe and unsafe states.
[0037] An unsafe state is a state in which the controlled equipment may pose a danger to people. An example of an unsafe state is when the equipment is in operation. A safe state is a state that is not unsafe. An example of a safe state is when the equipment is stopped. Furthermore, based on the principle that the equipment can be started immediately if it is confirmed to be safe, the initial state is a safe state.
[0038] The control logic, based on the input signals from the input / output devices and the current state, outputs an output signal corresponding to the target state according to the state transition table. Input signals transitioning from a safe state to a non-safe state are called non-safe inputs. Input signals transitioning from a non-safe state to a safe state are called safe inputs. Output signals output when the control logic is in a safe state are called safe outputs. Output signals output when the control logic is in a non-safe state are called non-safe outputs.
[0039] ***Situation Description***
[0040] The safe stopping action in the manner described in Patent Document 1 is categorized into a normal system where the gateway device can perform control as assumed, and an abnormal system that generates such a problem.
[0041] Reference Figure 1 Provide an explanation of the normal system. Figure 1 It is a timing diagram with the horizontal axis set as the time axis, representing the flow of input and output relays and the propagation of state transitions between devices.
[0042] The initial state is a safe state. At this time, an unsafe input is sent from the input / output device. The gateway device receives the unsafe input. Then, the gateway device relays the unsafe input to the control device. Upon receiving the unsafe input, the control device switches its control state from a safe state to an unsafe state. Then, the control device sends an unsafe output to the gateway device. Upon receiving the unsafe output, the gateway device switches its control state from a safe state to an unsafe state. Then, the gateway device relays the unsafe output to the input / output device. The input / output device receives the unsafe output. This creates an unsafe state, for example, the device begins operation.
[0043] Then, a safety input is sent from the input / output device. The gateway device receives the safety input. The gateway device then switches the control state from a non-safe state to a safe state. The gateway device then relays the safety input to the control device and sends a safety output to the input / output device on behalf of the control device. The input / output device receives the safety output. This establishes a safe state, for example, the device stops operating.
[0044] When the control device receives a safety input, it switches the control state from a non-safe state to a safe state. Then, the control device sends a safety output to the gateway device. Upon receiving the safety output, the gateway device relays the safety output to the input / output devices. The input / output devices receive the safety output, but are already in a safe state. Therefore, for example, the device remains in a stopped state.
[0045] As described above, when the gateway device receives a security input in an insecure state, it sends a security output to the input / output device on behalf of the control device. That is, upon sending a security input, a security output is immediately generated from the gateway device. This satisfies the required response time in security control.
[0046] Reference Figure 2 Provide an explanation of the abnormal system.
[0047] The initial state is a safe state. At this time, an unsafe input is sent from the input / output device. The gateway device receives the unsafe input. Let's set this moment as time t0. Then, the gateway device relays the unsafe input to the control device. Upon receiving the unsafe input, the control device switches its control state from a safe state to an unsafe state. Then, the control device sends an unsafe output to the gateway device. The gateway device receives the unsafe output. Let's set this moment as time t2. The gateway device then switches its control state from a safe state to an unsafe state. Then, the gateway device relays the unsafe output to the input / output device. The input / output device receives the unsafe output. Thus, the system enters an unsafe state, for example, the device begins operation.
[0048] During the period from time t0 to time t2, a safety input is sent from the input / output device. The gateway device receives the safety input. This time is designated as time t1. The gateway device then relays the safety input to the control device. At time t1, the control state in the gateway device becomes a safe state. Therefore, the gateway device does not send a safety output to the input / output device on behalf of the control device. This is because, if it is a safe state, there is no need to urgently stop the equipment.
[0049] When the control device receives a safety input, it switches the control state from a non-safe state to a safe state. Then, the control device sends a safety output to the gateway device. Upon receiving the safety output, the gateway device switches the control state from a non-safe state to a safe state. Then, the gateway device relays the safety output to the input / output devices. The input / output devices receive the safety output. This establishes a safe state, for example, the equipment stops operating. This moment is designated as time t3.
[0050] In a normal system, when the gateway device receives a security input, it immediately sends a security output to the input / output device. However, in an abnormal system, the gateway device receives a security input at time t1, but the input / output device receives the security output at time t3. That is, the response time in security control becomes longer. The response time is required to guarantee the maximum value across all cases; therefore, the system's response time cannot be guaranteed due to the abnormal system.
[0051] That is, when the gateway device sends a safety output to the input / output device on behalf of the control device, the control state needs to become an unsafe state. However, the gateway device recognizes the unsafe state at the moment it receives the unsafe output, t2. Therefore, if the gateway device receives a safety input during the period from the moment it receives the unsafe input, t0, to the moment it receives the unsafe output, t2, it does not send a safety output to the input / output device on behalf of the control device. In other words, a control that should have been performed is missed.
[0052] This is because the transmission time from when the input / output device sends an input signal to when the gateway device receives the output signal is longer than the transmission time from when the input / output device sends an input signal to when the gateway device receives the input signal.
[0053] ***Structure Description***
[0054] Reference Figure 3 The structure of the control system 100 of Embodiment 1 will be described.
[0055] The control system 100 includes a gateway device 10, multiple input / output devices 20, and a control device 30. The gateway device 10 and each input / output device 20 are connected via transmission path 91. The gateway device 10 and the control device 30 are connected via transmission path 92. Here, transmission path 91 is assumed to be a network such as a LAN within a facility such as a factory. LAN is an abbreviation for Local Area Network. Transmission path 92 is assumed to be a public network.
[0056] The gateway device 10 relays the communication between the input / output device 20 and the control device 30.
[0057] The input / output device 20 is divided into an input device 21 and an output device 22. The input device 21 is a device that sends input signals from connected sensors or switches to a higher-level device as input signals. The output device 22 is a device that outputs actions corresponding to the output signals received from the higher-level device to actuators or the like connected to a lower-level device.
[0058] The control device 30 sends an output signal to the output device 22 based on the input signal and control status from the input device 21, thereby controlling the output device 22. This, in turn, operates actuators and the like connected to the output device 22.
[0059] Reference Figure 4 The hardware structure of the gateway device 10 in Embodiment 1 will be described.
[0060] Gateway device 10 is a computer. Gateway device 10 has hardware such as CPU 11, memory 12, non-volatile memory 13, and bus 14. CPU is an abbreviation for Central Processing Unit.
[0061] The non-volatile memory 13 stores programs and parameters that implement the functional structural elements of the gateway device 10. The CPU 11 reads the programs and parameters stored in the non-volatile memory 13 into the memory 12 via the bus 14. The CPU 11 executes the program read into the memory 12. Thus, the functions of the gateway device 10 are implemented.
[0062] This hardware is developed in accordance with the requirements of a security-related system. This hardware can also be a structure that dualizes part or all of the structural elements to meet the necessary Safety Integrity Level (SIL). Additionally, the gateway device 10 can also be dualized.
[0063] The gateway device 10 has a communication mode 1 port 15 and a communication mode 2 port 16 for communicating with other devices, and a setting port 17 for making settings based on engineering tools. In Embodiment 1, the communication mode 1 port is a port for communicating with the control device 30. In Embodiment 1, the communication mode 2 port is a port for communicating with the input / output device 20.
[0064] Reference Figure 5 The functional structure of the gateway device 10 in Embodiment 1 will be described.
[0065] As functional structural elements, the gateway device 10 includes a data relay unit 111, a start control unit 112, an input determination unit 113, and a status monitoring unit 114.
[0066] The data relay unit 111 relays communication between the input / output device 20 and the control device 30. The input determination unit 113, the start control unit 112, and the status monitoring unit 114 are functions used to meet the response time requirements in safety control.
[0067] ***Instructions for Action***
[0068] Reference Figures 6-9 The operation of the gateway device 10 in Embodiment 1 will be explained.
[0069] The operation steps of the gateway device 10 in Embodiment 1 are equivalent to the relay method in Embodiment 1. Furthermore, the program that implements the operation of the gateway device 10 in Embodiment 1 is equivalent to the relay program in Embodiment 1.
[0070] Reference Figure 6 The processing of the gateway device 10 in Embodiment 1 will be described.
[0071] (Step S1: Data relay processing)
[0072] When the input / output device 20 is started, the state changes from the initial safe state according to the input signal. At this time, as follows: Figure 7 As shown, in the gateway device 10, the data relay unit 111 relays the communication between the input / output device 20 and the control device 30. That is, the data relay unit 111 sends the input signal received from the input device 21 to the control device 30 via the shared memory for input signals, and sends the output signal received from the control device 30 to the output device 22 via the shared memory for output signals.
[0073] At this time, as Figure 7As shown, the start control unit 112 stores the input signal received from the input / output device 20 in an input signal buffer. The input signal buffer is, for example, set in the memory 12. Here, the period during which the input signal is stored in the input signal buffer is called the storage period. The storage period is the period from when the input device 21 receives the input signal until the control device 30 receives the output signal that controls the output device 22 based on the input signal. The start control unit 112 sequentially deletes input signals from the input signal buffer that have passed the storage period.
[0074] Additionally, the start control unit 112 may not save the input signals when the input / output device 20 is in an unsafe state. Here, for example... Figure 8 As shown, the status monitoring unit 114 monitors the input signals, thereby managing the status of the input / output device 20. Therefore, the start control unit 112 does not need to store the input signals when the status of the input / output device 20 managed by the status monitoring unit 114 is in an unsafe state.
[0075] Furthermore, the start control unit 112 may also choose not to store input signals that are not used by the input determination unit 113 (described later) among the input signals.
[0076] During the processing of step S1, an insecure input is sent from input device 21. Data relay unit 111 then relays the insecure input to control device 30. Control device 30 executes control logic and sends an insecure output to gateway device 10. When data relay unit 111 receives this insecure output, it executes the processing of step S2.
[0077] (Step S2: Input Decision Processing)
[0078] like Figure 9 As shown, the input determination unit 113 determines whether the input signal stored in the input signal buffer contains a secure input. That is, the input determination unit 113 determines whether a secure input was received from the input device 21 during the storage period before the reception of an insecure output. In other words, the input determination unit 113 determines whether a secure input was sent from the input device 21 after an insecure input was sent from the input device 21. This is equivalent to the input determination unit 113 determining whether the current state is a secure state when the input signal stored in the input signal buffer is applied in a timely manner.
[0079] If a security input is included, the input determination unit 113 causes the process to proceed to step S3. On the other hand, if a security input is not included, the input determination unit 113 causes the process to proceed to step S4.
[0080] (Step S3: Relay reservation processing)
[0081] The activation control unit 112 does not relay unsafe outputs to the output device 22, but instead sends a safe output to the output device 22. Alternatively, instead of the activation control unit 112 sending the safe output, the activation control unit 112 may instruct the data relay unit 111 to send the safe output. Therefore, even if a safe input immediately follows an unsafe input, the influence of the public network can be eliminated from the response time during protection operation.
[0082] The start control unit 112 stops relaying unsafe outputs received from the control device 30 to the output device 22 and continues to send safe outputs until a safe output is received from the control device 30. When the start control unit 112 receives a safe output from the control device 30, it returns the process to step S1.
[0083] (Step S4: Relay continuous processing)
[0084] The activation control unit 112 sends an unsafe output to the output device 22. That is, the activation control unit 112 relays the unsafe output. Alternatively, in practice, instead of the activation control unit 112 sending the unsafe output, the activation control unit 112 may instruct the data relay unit 111 to send the unsafe output. Then, the activation control unit 112 returns the process to step S1.
[0085] ***Effects of Implementation Method 1***
[0086] As described above, when the gateway device 10 of Embodiment 1 receives an unsafe output from the control device 30, and if it receives a safe input from the input device 21 during the storage period before receiving the input, it does not relay the unsafe output to the output device 22, but instead sends a safe output to the output device 22. Therefore, even if there is a time lag before the control state of the gateway device 10 synchronizes with the control state of the control device 30, the required response time in safety control is met.
[0087] Reference Figure 10 The effects of the gateway device 10 in Embodiment 1 will be explained.
[0088] The initial state is a safe state. At this time, an unsafe input is sent from input / output device 20. Gateway device 10 receives the unsafe input. Then, gateway device 10 relays the unsafe input to the control device. When the control device 30 receives the unsafe input, it switches the control state from a safe state to an unsafe state. Then, control device 30 sends an unsafe output to gateway device 10. The process up to this point is consistent with the reference. Figure 2 The abnormal system described is the same.
[0089] Before the gateway device 10 receives a secure output, a secure input is sent from the input / output device 20. The gateway device 10 receives the secure input. Then, the gateway device relays the secure input to the control device. Next, the gateway device 10 receives a non-secure input. Then, the gateway device 10 determines whether the input signals stored in the input signal buffer contain a secure input. Figure 6 Step S2). Here, a secure input is included. Therefore, the gateway device 10 does not relay non-secure outputs to the output device 22, but sends secure outputs to the output device 22. Figure 6 (Step S3). Therefore, the input / output device 20 remains in a safe state, and the device has not yet started operating.
[0090] Response time is the time from sending a secure input to sending a secure output. In other words, response time is the time from sending a secure input to achieving a secure state. Figure 10 In the example, the safe state is maintained even after a safe input is made. Therefore, the response time is effectively 0.
[0091] ***Other Structures***
[0092] <Variation Example 1>
[0093] In Implementation Example 1, each functional structural element is implemented through software. However, as a variation 1, each functional structural element can also be implemented through hardware. Regarding this variation 1, the differences from Implementation Example 1 will be explained.
[0094] When the various functional structural elements are implemented in hardware, the gateway device 10 has electronic circuitry instead of the CPU 11, memory 12, and non-volatile memory 13. The electronic circuitry is a dedicated circuitry for implementing the functions of the various functional structural elements, memory 12, and non-volatile memory 13.
[0095] As electronic circuits, they can be categorized as single circuits, composite circuits, programmable processors, parallel programmable processors, logic ICs, GAs, ASICs, and FPGAs. GA stands for Gate Array. ASIC stands for Application Specific Integrated Circuit. FPGA stands for Field-Programmable Gate Array.
[0096] Each functional structural element can be implemented using a single electronic circuit, or multiple electronic circuits can be used to implement each functional structural element separately.
[0097] <Variation Example 2>
[0098] As a variation 2, some of the functional structural elements can be implemented through hardware, while other functional structural elements can be implemented through software.
[0099] The CPU 11, memory 12, non-volatile memory 13, and electronic circuits are collectively referred to as the processing circuit. That is, the functions of each functional structural element are realized through the processing circuit.
[0100] Implementation Method 2
[0101] In Embodiment 2, the method for generating the control logic of the gateway device 10 will be described.
[0102] In order to achieve Figure 6 As shown in the process, gateway device 10 needs to implement control logic different from that of control device 30. The control logic implemented by gateway device 10 is generated based on the control program executed by control device 30. The control logic implemented by gateway device 10 can be implemented through state transitions.
[0103] The control logic implemented by the gateway device 10 needs to be exported before the control of the gateway device 10 begins. Regarding the control logic implemented by the gateway device 10, methods such as adding an automatic export function to the engineering tool 40 or adding a function to the gateway device 10 to retrieve and use the control logic pre-exported by the supplier of the gateway device 10 or the engineering tool 40 are considered.
[0104] In Embodiment 2, an example of the control logic implemented by the gateway device 10 generated by the engineering tool 40 will be described.
[0105] ***Structure Description***
[0106] Reference Figure 11 The hardware structure of the engineering tool 40 in Implementation Method 2 will be described.
[0107] Engineering tool 40 is a computer. Engineering tool 40 has hardware such as CPU 41, memory 42, non-volatile memory 43 and bus 44.
[0108] The non-volatile memory 43 stores the program and parameters that implement the functional structural elements of the engineering tool 40. The CPU 41 reads the program and parameters stored in the non-volatile memory 43 into the memory 42 via the bus 44. The CPU 41 executes the program read into the memory 42. Thus, the functions of the engineering tool 40 are realized.
[0109] The engineering tool 40 has a setting port 45 for setting the gateway device 10 or the control device 30.
[0110] Reference Figure 12The functional structure of the engineering tool 40 in Implementation Method 2 will be explained.
[0111] As a functional structural element, the engineering tool 40 includes a gateway logic generation unit 411, a gateway logic setting unit 412, a control logic generation unit 413, a control logic setting unit 414, and a programming unit 415.
[0112] The gateway logic generation unit 411 generates the control logic for the gateway device 10. The gateway logic setting unit 412 sets the control logic for the gateway device 10. The control logic generation unit 413 generates the control logic for the control device 30. The control logic setting unit 414 sets the control logic for the control device 30. The programming unit 415 assists in generating the control logic.
[0113] Here, the gateway logic generation unit 411 and the gateway logic setting unit 412 will be described.
[0114] ***Instructions for Action***
[0115] Reference Figures 13-16 The operation of the engineering tool 40 in Implementation Method 1 will be explained.
[0116] The operation steps of the engineering tool 40 in Embodiment 2 are equivalent to the logic generation method in Embodiment 2. Furthermore, the program that implements the operation of the engineering tool 40 in Embodiment 2 is equivalent to the logic generation program in Embodiment 2.
[0117] Reference Figure 13 The basic state transitions of the gateway device 10 in Embodiment 2 will be explained.
[0118] As states, the gateway device 10 has a secure state, an insecure state, a secure standby state, a check standby state, and an insecure standby state.
[0119] When a non-safe output is received in a safe state, the state transitions to a non-safe state. When a safe input is received in a non-safe state, the state transitions to a safe standby state. When a safe output is received in a safe standby state, the state transitions to a check standby state. When a non-safe output is received in a check standby state, the state transitions to a non-safe standby state. When a safe input is present in the input signal buffer (described later) in a non-safe standby state, the state transitions to a safe standby state. When no safe input is present in the input signal buffer (described later) in a non-safe standby state, the state transitions to a non-safe state.
[0120] The safe standby state is a state in which a safe output is sent to the output device 22 instead of relaying a non-safe output. That is, the safe standby state is in progress. Figure 6The status of step S3.
[0121] Checking the standby state involves storing the input signal in the input signal buffer and monitoring the state of non-safe outputs. In other words, checking the standby state is... Figure 6 In step S1, the input signal is stored in the state of the input signal buffer.
[0122] The unsafe standby state is the state used to determine whether to relay an unsafe output to output device 22. That is, the unsafe standby state is in progress. Figure 6 The status of step S2.
[0123] Reference Figures 14-16 A specific example of the state transition of the gateway device 10 in Embodiment 1 will be described.
[0124] Here, we assume that the control logic of the control device 30 passes through... Figure 14 This is achieved through the state transitions shown. Figure 15 In Chinese, it is presented in tabular form. Figure 14 The state transition is shown.
[0125] exist Figure 14 In the state transitions shown, when condition 1 is satisfied in the safe state 0 (initial state), the state transitions to safe state 1. When condition 2 is satisfied in safe state 1, the state transitions to safe state 2. When condition 3 is satisfied in safe state 2, the state transitions to safe state 1. When condition 4 is satisfied in safe state 2, the state transitions to unsafe state 1. That is, unsafe inputs satisfy condition 4. When condition 5 is satisfied in unsafe state 1, the state transitions to unsafe state 2. When condition 6 is satisfied in unsafe state 2, the state transitions to unsafe state 1. When condition 7 is satisfied in unsafe state 2, the state transitions to safe state 3. That is, safe inputs satisfy condition 7. When condition 8 is satisfied in safe state 3, the state transitions to safe state 2.
[0126] The gateway logic generation unit 411 sequentially performs the following steps (1) to (5) to generate... Figure 16 The state transition is shown.
[0127] (1) The gateway logic generation unit 411 generates a table showing the control logic of the control device 30 (see reference). Figure 15 Extract records whose current state is unsafe. Here, extract... Figure 15 The three records numbered 5 to 7 are set as Figure 16 The records numbered 1 to 3.
[0128] (2) The gateway logic generation unit 411 adds a record with the current state being the non-safe standby state, the condition being that there is a safety input in the input signal buffer, and the next state being the safe standby state. Here, add Figure 16 the record with line number 4.
[0129] In addition, the gateway logic generation unit 411 adds a line where the current state is the non-safe standby state, the condition is that there is no safety input in the input signal buffer, and the next state is the non-safe state. Also, in the case where there are multiple non-safe states transitioning from the safe state, the gateway logic generation unit 411 adds that number of records. Here, add Figure 16 the record with line number 5.
[0130] (3) The gateway logic generation unit 411 adds a record with the current state being the non-safe state, the condition being that a safety input is received, and the next state being the safe standby state. Also, in the case where there are multiple non-safe states transitioning to the safe state, the gateway logic generation unit 411 adds that number of records. Here, add Figure 16 the record with line number 6.
[0131] (4) The gateway logic generation unit 411 adds a record with the current state being the safe standby state, the condition being the reception of a safety output, and the next state being the inspection standby state. Here, add Figure 16 the record with line number 7.
[0132] (5) The gateway logic generation unit 411 adds a record with the current state being the inspection standby state, the condition being the reception of a non-safe output, and the next state being the non-safe standby state. Here, add Figure 16 the record with line number 8.
[0133] Then, the gateway logic setting unit 412 sets the control logic shown by the generated state transition for the gateway device 10.
[0134] ***Effects of Embodiment 2***
[0135] As described above, the engineering tool 40 of Embodiment 2 generates the control logic of the gateway device 10 based on the control logic of the control device 30. Thus, the control logic of the gateway device 10 can be easily generated.
[0136] In addition, in the above description, "unit" can be rewritten as "circuit", "process", "step", "processing", or "processing circuit".
[0137] The embodiments and modifications of this disclosure have been described above. Several embodiments and modifications may also be implemented in combination. Furthermore, any one or more embodiments and modifications may be implemented partially. In addition, this disclosure is not limited to the above embodiments and modifications, and various changes can be made as needed.
[0138] Label Explanation
[0139] 100: Control system; 10: Gateway device; 11: CPU; 12: Memory; 13: Non-volatile memory; 14: Bus; 15: Communication mode 1 port; 16: Communication mode 2 port; 17: Setting port; 111: Data relay unit; 112: Start control unit; 113: Input determination unit; 114: Status monitoring unit; 20: Input / output device; 21: Input device; 22: Output device; 30: Control device; 40: Engineering tool; 41: CPU; 42: Memory; 43: Non-volatile memory; 44: Bus; 45: Setting port; 411: Gateway logic generation unit; 412: Gateway logic setting unit; 413: Control logic generation unit; 414: Control logic setting unit; 415: Programming unit; 91: Transmission path; 92: Transmission path.
Claims
1. A gateway device that relays communication between an input device and an output device and a control device that controls the output device based on an input signal from the input device, wherein, The gateway device has: The input determination unit, when receiving an unsafe output from the control device as an output signal that controls the control state of the output device to an unsafe state, determines whether a safe input that controls the control state to a safe state was received from the input device during the storage period prior to receipt. as well as The activation control unit, when the input determination unit determines that the safe input has been received, does not relay the unsafe output to the output device, but instead sends a safe output to the output device as an output signal to control the control state of the output device to a safe state.
2. The gateway device according to claim 1, wherein, If the input determination unit determines that the safety input has not been received, the start control unit sends a non-safe output to the output device as an output signal to control the control state to a non-safe state.
3. The gateway device according to claim 1 or 2, wherein, If the input determination unit determines that the safe input has been received, the start control unit stops relaying the unsafe output received from the control device to the output device until the safe output is received from the control device.
4. The gateway device according to claim 3, wherein, When the start-up control unit receives the safety output from the control device, it begins to relay the non-safety output received from the control device to the output device.
5. The gateway device according to any one of claims 1 to 4, wherein, The storage period is the period preceding the period from when the input device receives an input signal to when the control device receives an output signal that controls the output device based on the input signal.
6. A relay method for relaying communication between an input device and an output device and a control device that controls the output device based on an input signal from the input device, wherein, When the gateway device receives an unsafe output from the control device as an output signal that controls the control state of the output device to an unsafe state, it determines whether it received a safe input from the input device as an input signal that controls the control state to a safe state during the storage period prior to receiving the input. When the gateway device determines that it has received the secure input, it does not relay the insecure output to the output device, but instead sends a secure output to the output device as an output signal to control the control state of the output device to a secure state.
7. A relay procedure that relays communication between an input device and an output device and a control device that controls the output device based on an input signal from the input device, wherein, The relay program enables the computer to function as a gateway device, which performs the following processes: The input determination unit, when receiving an unsafe output from the control device as an output signal that controls the control state of the output device to an unsafe state, determines whether a safe input that controls the control state to a safe state was received from the input device during the storage period prior to receipt. as well as The activation control unit, when the input determination unit determines that the safe input has been received, does not relay the unsafe output to the output device, but instead sends a safe output to the output device as an output signal to control the control state of the output device to a safe state.
Citation Information
Patent Citations
Gateway device, gateway control method, and gateway control program
WO2022239116A1