Robot sudden stop safety response control equipment and method thereof

The robot emergency stop safety response control device, which incorporates a self-resetting normally closed emergency stop switch and low-voltage power supply redundancy, solves the problems of ease of operation and maintenance, signal transmission delay, and power supply reliability in the robot system's emergency stop function, thereby improving safety and operational efficiency.

CN120909260APending Publication Date: 2025-11-07SUZHOU ZHONGKE HANHAI HIGH TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511029291.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-25
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

The emergency stop function of existing robot systems suffers from problems such as insufficient ease of operation and maintenance, delayed emergency stop signal transmission, poor reliability of low-voltage power supply, and poor coordination of power-on and power-off processes, resulting in low safety and low operation and maintenance efficiency.

Method used

The emergency stop safety response control equipment consists of a self-resetting normally closed emergency stop switch, chassis VCU, energy storage and charging main control, interface board and domain controller. It directly transmits emergency stop signals through a three-wire branch circuit. Combined with low-voltage power supply redundancy design and multi-dimensional status feedback, it realizes real-time transmission and reliable response of emergency stop signals and deeply coordinates with the power-on and power-off processes.

Benefits of technology

It improves the timeliness and reliability of emergency stop response, reduces operation and maintenance costs, ensures the continuity of system status and the intuitiveness of operation, and reduces equipment and personnel safety risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120909260A_ABST
    Figure CN120909260A_ABST
Patent Text Reader

Abstract

The invention provides robot sudden stop safety response control equipment and a method thereof, and relates to the technical field of robot safety control. The equipment comprises a self-recovery normally-closed emergency stop switch, a chassis VCU, a storage and charging master controller, an interface board and a domain controller, the emergency stop switch is connected with the chassis VCU, the storage and charging master controller and the interface board through a three-wire branch circuit, direct transmission of an emergency stop signal is achieved, the emergency stop triggering process is that the self-recovery normally-closed emergency stop switch is pressed to be loosened for about one second, the emergency stop signal is synchronously transmitted to all components, and the self-recovery normally-closed emergency stop switch is started. And the storage and charging master control cuts off high-voltage output, the interface board cuts off external power supply, and the domain control state lamp flashes red. And sudden stop release supports two modes. The problem that traditional sudden stop needs to be reset on site is solved through the design of a self-recovery switch, response timeliness is improved through three-wire branch transmission, the reliability of the process is guaranteed by combining low-voltage power supply redundancy, the stable state is guaranteed by cooperating with the power-on and power-off process, and the safety of robot sudden stop safety response, the operation and maintenance efficiency and the system reliability are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of robot safety control, more specifically, particularly relates to a robot emergency stop safety response control device and method thereof. BACKGROUND

[0002] In a robot system with automatic power-on and power-off, high-voltage management and peripheral control functions, the emergency stop function is the key to ensuring the safety of equipment operation and personnel operation, but the existing technology has the following outstanding problems:

[0003] Conventional emergency stop switch operation convenience is insufficient: existing emergency stop switches are mostly non-self-recovery type, and after pressing the trigger to stop, manual reset is required to remove the state on site, in unattended scenarios, once the emergency stop occurs, personnel must be arranged to operate on site, resulting in system recovery delay, significantly increasing operation and maintenance cost and time cost.

[0004] Emergency stop signal transmission has delay risk: existing emergency stop signals are often transmitted through a single communication path, such as being transferred through a central controller and then distributed to each execution component, which can cause key safety operation response lag, such as chassis braking and high-voltage cutoff. Especially in emergency situations, the chassis may not stop in time, which may cause a collision, and the delay in high-voltage output cutoff of the storage and charging system may cause the risk of electric shock or equipment damage.

[0005] Low-voltage power supply reliability is difficult to guarantee the entire emergency stop: during the emergency stop process, the chassis control unit, storage and charging controller and other core components need to be continuously powered to maintain signal monitoring and instruction execution, but existing low-voltage power supply mostly relies on a single power source, if the power source fails (such as battery depletion, high-voltage conversion power interruption), the core components may be powered off, resulting in emergency stop signal transmission interruption, relay control failure, and further causing emergency stop process jamming or complete failure.

[0006] Poor coordination with power-on and power-off processes leads to system state confusion: robot systems usually have a clear power-on and power-off logic, such as specific operations triggering power-on and specific operations triggering power-off, but existing emergency stop functions are often independent of this logic, and after triggering the emergency stop, the system state is forcibly reset, and when the emergency stop is released, the complete power-on and power-off process needs to be executed again, resulting in the loss of the original working state, which not only reduces the operation efficiency, but also easily causes system state conflict.

[0007] The above problems restrict the safety, reliability and operation efficiency of the robot system emergency stop function, and a new emergency stop safety response scheme is needed to solve the above technical defects. SUMMARY

[0008] To solve the above technical problems, the present application provides a robot emergency stop safety response control device and method thereof to solve the above problems.

[0009] A robot emergency stop safety response control device, comprising: a self-restoring normally closed emergency stop switch, a chassis VCU, a storage and charging master control, an interface board, a domain control and a status lamp;

[0010] The self-restoring normally closed emergency stop switch is connected with the chassis VCU, the storage and charging master control and the interface board respectively, and is used for outputting an emergency stop signal and an emergency stop release signal;

[0011] The chassis VCU communicates with the domain control through CAN, and is used for controlling the chassis to brake and hold the brake after receiving the emergency stop signal, and releasing the emergency stop state after receiving the emergency stop release signal;

[0012] The storage and charging master control is connected with the interface board, and is used for stopping charging or power supplement and disconnecting the main positive and negative relays after receiving the emergency stop signal, and connecting the main positive and negative relays after receiving the emergency stop release signal;

[0013] The interface board is connected with the domain control and the storage and charging master control respectively, and is used for transmitting the emergency stop signal to the domain control and turning off the power supply of external devices, and transmitting the emergency stop release signal to the domain control and connecting the power supply of external devices;

[0014] The domain control is used for controlling the status lamp to flash red light after receiving the emergency stop signal, and controlling the status lamp to be always green after receiving the emergency stop release signal, and sending a power-on command to the interface board and sending the emergency stop release signal to the storage and charging system.

[0015] Preferably, the self-restoring normally closed emergency stop switch is self-restoring, and can be automatically reset after being pressed, and the emergency stop signal is transmitted to the chassis VCU, the storage and charging master control and the interface board through a three-wire branch circuit respectively, and the domain control communicates with the platform through MQTT, and is used for receiving an emergency stop release command issued by the platform, and transmitting the command to the interface board and the chassis VCU to release the emergency stop state.

[0016] Another technical problem to be solved by the application is to provide a robot emergency stop safety response control method, comprising an emergency stop triggering process and an emergency stop release process.

[0017] The emergency stop triggering process comprises:

[0018] S1. pressing the self-restoring normally closed emergency stop switch, and the switch outputting an emergency stop signal;

[0019] S2. the chassis VCU receiving the emergency stop signal, and controlling the chassis to brake and hold the brake immediately;

[0020] S3. the storage and charging master control receiving the emergency stop signal, and stopping charging or power supplement and disconnecting the main positive and negative relays to cut off the high-voltage output if the storage and charging master control is in a charging or power supplement state;

[0021] S4. the interface board receiving the emergency stop signal and transmitting the emergency stop signal to the domain control, and turning off the power supply of external devices;

[0022] S5. the domain control receiving the emergency stop signal, and controlling the status lamp to flash red light;

[0023] The emergency stop release process comprises:

[0024] S6. Receiving an emergency stop release instruction, which is a signal generated after long pressing the self-recovery normally closed emergency stop switch for 5 seconds or a remote command issued by the platform;

[0025] S7. After the interface board and the chassis VCU detect the emergency stop release instruction, they respectively send an emergency stop release signal to the domain control;

[0026] S8. After the domain control receives the emergency stop release signal, the control state light becomes always green, an upper power command is sent to the interface board, and an emergency stop release signal is sent to the storage and charging system;

[0027] S9. After the interface board receives the upper power command, the external device power supply is turned on;

[0028] S10. After the storage and charging system receives the emergency stop release signal, the main positive and main negative relays are turned on;

[0029] S11. After the chassis VCU receives the emergency stop release signal, the emergency stop state is released, and the system returns to normal standby.

[0030] Preferably, in step S3, after the storage and charging master control turns off the main positive and main negative relays, the domain control detects that the storage and charging system high voltage is disconnected, and sends a control light command to the interface board to control the state light to flash red.

[0031] Preferably, in step S6, the remote command issued by the platform is transmitted to the domain control through the MQTT protocol, and the domain control starts the emergency stop release process after receiving it.

[0032] Preferably, in step S8, after the domain control sends the upper power command to the interface board, the interface board controls the double-line connection through the internal relay for 3 seconds to activate the upper power of the storage and charging system.

[0033] Preferably, in step S10, after the storage and charging system turns on the main positive and main negative relays, the domain control queries the high voltage power-on state, and if the state is normal, the power supply relay is turned on.

[0034] Preferably, in step S2, the response time of the chassis VCU controlling the chassis brake and holding brake is not more than 1 second.

[0035] Preferably, in step S5, the state light flashes at a frequency of 1-2 times per second, and in step S8, when the state light is always green, the loudspeaker synchronously broadcasts “emergency stop has been released”.

[0036] Compared with the prior art, the present application has the following beneficial effects:

[0037] 1. Improve the timeliness of emergency stop response and strengthen safety protection capability: The three-wire branch circuit of the application directly transmits the emergency stop signal to the chassis VCU, storage and charging main control and interface board, avoiding the delay of the domain control relay, the emergency stop signal can trigger the chassis to stop immediately, the storage and charging main control to cut off the high voltage output (turn off the main positive and negative relays), and the peripheral device to power off quickly, ensuring that the core safety operation (such as high voltage cut-off and chassis braking) is completed within 1 second, which significantly improves the response speed of traditional single signal transmission and maximally reduces the safety risk of equipment and personnel during emergency stop.

[0038] 2. Solve the operation and maintenance pain points of traditional emergency stop switch and improve remote control efficiency: The self-recovery normally closed emergency stop switch breaks through the limitation of traditional emergency stop switch that needs to be manually reset on site after pressing, and realizes local and remote dual-mode control of emergency stop state through local operation of "pressing for 1 second to trigger emergency stop and long pressing for 5 seconds to release emergency stop" or remote operation of platform remote emergency stop release command. It is especially suitable for unattended scenes, without the need for personnel to go to the scene to restore the system, greatly improving the operation and maintenance efficiency and reducing the operation and maintenance cost.

[0039] 3. Rely on low-voltage power supply redundancy design to ensure the continuity and reliability of emergency stop process: During the emergency stop process, the chassis and domain control system are hot standby powered by 12V storage battery and power supply C (the storage battery seamlessly takes over when power supply C is interrupted), and the storage and charging system is hot standby powered by power supply A and power supply B. The core control components (chassis VCU, storage and charging main control, interface board) are powered throughout the emergency stop process, ensuring real-time monitoring, transmission and response of emergency stop signal without interruption, avoiding the emergency stop process from being stuck or failing due to power failure, and significantly improving the reliability of the system under extreme power supply conditions (such as storage battery depletion).

[0040] 4. Deep coordination with power-on and power-off process to ensure system state consistency and operation stability: The emergency stop response of the application does not change the original system power-on / power-off state: when the system is in power-on state before emergency stop is triggered, it automatically resumes the power-on process (such as re-powering the peripheral device and connecting the power supply relay) after the emergency stop is released; when the system is in power-off process before emergency stop is triggered, it continues to complete power-off (such as the storage and charging main control continues to turn off the relay and the VCU finally cuts off the storage battery output) after the emergency stop is released. This design deeply adapts to the power-on and power-off logic, avoids conflicts between emergency stop and power-on / power-off process, ensures the continuity and stability of the system state, and reduces the risk of abnormal operation.

[0041] 5. Improve the intuitiveness and controllability of system operation through multi-dimensional state feedback: When the emergency stop is triggered, the domain control state light flashes red and the loudspeaker does not broadcast (different from the normal state); after the emergency stop is released, the state light is always green and the loudspeaker broadcasts "emergency stop released". Multi-dimensional state feedback (light and sound) enables the operator to intuitively judge the system state, improves the controllability of operation, and reduces the probability of misoperation. BRIEF DESCRIPTION OF DRAWINGS

[0042] Fig. 1 is a schematic diagram of the connection relationship of various components of the device in the present application;

[0043] Fig. 2 is a schematic diagram of the flow of the method in the present application. DETAILED DESCRIPTION

[0044] The embodiments of the present application will be further described in detail below with reference to the accompanying drawings and examples. The following examples are used to illustrate the present application, but cannot be used to limit the scope of the present application.

[0045] Please refer to Figs. 1-2 , the present application provides a robot emergency stop safety response control device and method, wherein the emergency stop safety response system of the present application is constructed based on the power-on and power-off control logic of the robot and the low-voltage power supply redundancy design, the core components and the connection relationship are as follows:

[0046] Hardware components and connections:

[0047] Self-recovery normally closed emergency stop switch: self-recovery design (automatic reset after pressing), connected to the chassis VCU, storage and charging master control, interface board through three-wire branch circuit, used for synchronous transmission of emergency stop signal and emergency stop release signal (three-wire branch circuit design).

[0048] Chassis VCU: as the core control node, access to 12V storage battery (constant power supply), communicate with domain control through CAN bus, control chassis motor, DCDC module, storage battery relay, etc., while real-time monitor power switch signal and emergency stop signal.

[0049] Storage and charging master control: responsible for the high-voltage management of the storage and charging system, connected to the main positive and negative relays, power supply relays, communicates with the interface board, cuts off the high-voltage output after receiving the emergency stop signal, and restores the high-voltage loop after receiving the release signal.

[0050] Domain control: communicate with the interface board through RS485 interface, control display screen, laser radar, status light, loudspeaker, etc. peripherals, interact with the chassis VCU through CAN (send 370 / 378 messages), and communicate with the remote platform to receive the emergency stop release command.

[0051] Interface board: as an intermediate node, connected to the domain control, storage and charging master control, peripheral relays, control the power-on / power-off of display screen, laser radar, etc. peripherals, forward emergency stop signal and release signal.

[0052] Low-voltage power supply system: the system is initially powered by a 12V battery; after power-on, the chassis and domain control system are powered by power supply C (high-voltage input conversion) and the battery in hot standby (power supply C outputs 13.8V, slightly higher than the battery voltage, priority power supply and power compensation); the storage and charging system is powered by power supply A and power supply B in hot standby (to ensure low-voltage redundancy, low-voltage power supply system redundancy design).

[0053] Software and communication logic:

[0054] Signal priority: the emergency stop signal has the highest priority and can interrupt the normal power-on and power-off process of the robot (e.g., if the emergency stop signal takes effect when the power-on or power-off is being performed).

[0055] Communication protocol: the chassis VCU and the domain control transmit control instructions (such as 378 power-on and power-off instructions, 370 keep-alive messages) through the CAN bus; the domain control and the platform communicate through the MQTT protocol for receiving remote emergency stop release commands; the interface board and the domain control transmit peripheral control signals through the RS485 interface.

[0056] Emergency stop trigger process:

[0057] The emergency stop trigger is triggered by pressing the self-recovery normally closed emergency stop switch for about 1 second and then releasing it. The process design follows the principle of "safety first" and synchronously cuts off the power output, high-voltage loop, and peripheral power supply. The specific steps are as follows:

[0058] 1. Signal generation and transmission:

[0059] The operator presses the self-recovery normally closed emergency stop switch for 1 second and then releases it. The switch automatically resets (remains normally closed) and the emergency stop signal is transmitted synchronously to three nodes through a three-wire branch circuit:

[0060] Branch 1: directly transmitted to the chassis VCU (no transfer, ensuring real-time performance);

[0061] Branch 2: directly transmitted to the storage and charging master control (avoiding delay through the domain control);

[0062] Branch 3: transmitted to the interface board, which then forwards it to the domain control.

[0063] 2. Response logic of each component:

[0064] Chassis VCU response: upon receiving the emergency stop signal, the chassis motor is immediately controlled to "stop and engage the brake" (completed within 0.5 seconds to ensure that the robot stops moving), and the chassis DCDC module output (13.8V) is suspended, leaving only the 12V battery for low-power self-supply (maintaining signal monitoring capability, VCU low-power design).

[0065] Response of the storage and charging master control: If in the charging / power supply state (such as the battery power supply to 13.2V), stop the charging / power supply action immediately; at the same time, disconnect the main positive and main negative relay, cut off the high voltage output (including the power supply loop), and feedback to the domain control that the high voltage has been cut off (the main positive and main negative relay is turned off).

[0066] Response of the interface board and the domain control: After the interface board receives the emergency stop signal, the peripheral relay is turned off (the power supply of the display screen, laser radar, ultrasonic wave, etc. is cut off); after the domain control receives the signal, the state light changes from green to red flashing (frequency 1 / second), and the sending of 370 keep-alive messages is stopped (the current power-on state is temporarily stored to prepare for subsequent recovery).

[0067] Emergency stop release process (double mode design):

[0068] The emergency stop release supports two ways of "long pressing the emergency stop switch for 5 seconds" and "platform remote command", and after the release, the system returns to the power-on / power-off state before the emergency stop (to avoid process conflicts), and the specific steps are as follows:

[0069] 1. Long press emergency stop switch release (local release):

[0070] Signal generation: After the operator long presses the self-recovery normally closed emergency stop switch for 5 seconds and then releases it, the emergency stop release signal is output by the switch and transmitted to the chassis VCU, storage and charging master control, and interface board through the three-wire branch circuit.

[0071] Chassis recovery: After the chassis VCU receives the release signal, the motor brake is released, and the chassis DCDC module outputs 13.8V (if the battery voltage is lower than 13.2V, the battery is simultaneously powered, and the reverse charging amount is charged).

[0072] Storage and charging system recovery: After the storage and charging master control receives the release signal, the main positive and main negative relays are closed, the high voltage loop is restored, and the domain control is fed back that the high voltage is ready; after the domain control confirms, it sends the "turn on the power supply relay" command to restore the power output of the storage and charging system (the same as the "power supply relay on" logic in the normal power-on process).

[0073] Peripheral and state recovery: After the interface board receives the release signal, it feeds back to the domain control that the peripherals can be powered on; the domain control sends the "turn on the peripherals" command, the interface board closes the peripheral relay (restores the power supply of the display screen, laser radar, etc.), at the same time, the domain control controls the state light to change from red flashing to green, the loudspeaker broadcasts "emergency stop release, system recovery normal" (power-on success broadcast), and sends the 370 keep-alive message to the VCU to confirm the recovery.

[0074] 2. Platform remote command release (remote release):

[0075] Command transmission: the platform sends an "emergency stop release command" to the domain control through the MQTT protocol, which is forwarded to the chassis VCU, storage and charging master control through the CAN bus, and to the interface board through the RS485 bus.

[0076] Recovery process: completely consistent with "long press release" (chassis release brake, storage and charging restore high pressure, peripheral power on, status light always green and voice broadcast), only the signal source changes from "emergency stop switch" to "platform command" (platform release).

[0077] Example 1: Emergency stop response in normal power-on state (basic scenario):

[0078] System initial state: the robot has completed the "long press 3 seconds power-on" process and is in the power-on state - the chassis motor is normally powered, the 12V battery voltage is 12.5V (supplemented by power C to below 13.2V), the storage and charging system power supply relay is closed, the display screen and laser radar are powered on (status light always green), and the domain control continuously sends 370 keep-alive messages.

[0079] Emergency stop trigger:

[0080] The operator presses the emergency stop switch for 1 second and then releases it, and the emergency stop signal is transmitted simultaneously to the chassis VCU, storage and charging master control, and interface board;

[0081] The chassis VCU immediately controls the motor to stop and brake, and suspends the DCDC output (only the battery constant power is retained);

[0082] The storage and charging master control stops the current power supplement action, disconnects the main positive and main negative relays, and cuts off the high voltage output;

[0083] The interface board turns off the peripheral relays (the display screen and laser radar are powered off, and the status light is off), and the domain control controls the status light to flash red after receiving the signal and stops sending 370 messages.

[0084] Emergency stop release (long press 5 seconds):

[0085] After pressing the emergency stop switch for 5 seconds, the release signal triggers the chassis VCU to release the brake and restart the DCDC output of 13.8V (for battery power supplement);

[0086] The storage and charging master control closes the main positive and main negative relays, and the domain control connects the power supply relay after confirmation;

[0087] The interface board restores the peripheral power supply, the status light is always green, the speaker broadcasts "emergency stop release", the domain control resumes sending 370 messages, and the system returns to the power-on state.

[0088] Example 2: Emergency stop response in battery depletion state (low voltage redundancy scenario):

[0089] System initial state: the robot is in the power-on state, but the 12V battery voltage is 11.8V (lower than the 12V threshold), and the VCU has triggered "power C priority power supply" (hot standby power supply) - power C outputs 13.8V, which is the main power supply and charges the battery, and the storage and charging system is hot standby powered by power A and B (no risk of power failure).

[0090] Emergency stop trigger:

[0091] After pressing the emergency stop switch for 1 second, the emergency stop signal triggers the chassis VCU to stop the brake, and the storage and charging master turns off the main positive and negative relays (high-voltage cut-off);

[0092] Because the main positive and negative relays are turned off, power C (which relies on high-voltage input) stops outputting, and at this time the 12V battery automatically takes over the power supply (low-voltage redundancy takes effect), ensuring that the chassis VCU, storage and charging master, and interface board maintain low-power operation (monitoring the emergency stop signal);

[0093] The interface board turns off the peripheral relays, and the domain control state light flashes red (the battery power is sufficient to support the state light and communication).

[0094] Emergency stop release (platform remote command):

[0095] The platform sends an "emergency stop release" command, which is forwarded by the domain control to each component;

[0096] The storage and charging master closes the main positive and negative relays, the high-voltage loop is restored, and power C restarts outputting 13.8V (re-takes over the power supply and charges the battery);

[0097] The chassis VCU releases the brake, the DCDC resumes output, the interface board resumes peripheral power supply, the state light is always green, the loudspeaker plays a recovery message, and the system returns to the power-on state.

[0098] Example 3: Emergency stop response during power-off process (process conflict scenario):

[0099] System initial state: the robot is executing the "long press 5 seconds power-off" process - the domain control has sent a 378 power-off command, the storage and charging master is turning off the main positive and negative relays, and the interface board is gradually turning off peripherals (state light flashing yellow), but has not completed "chassis motor power-off" and "battery output shutdown".

[0100] Emergency stop trigger:

[0101] After pressing the emergency stop switch for 1 second, the emergency stop signal takes precedence over the power-off signal;

[0102] The chassis VCU interrupts the power-off process and forcibly triggers the motor brake (even if the power-off process has started to power off, it still ensures emergency braking);

[0103] The power-off logic of the "step-by-step disconnecting relay" of the storage and charging master is stopped, and the main positive and main negative relays are directly forced to be disconnected (high-voltage cut-off is 2 seconds faster than normal power-off);

[0104] The interface board immediately turns off all peripherals (including devices that are being gradually turned off), and the status light changes from yellow flashing to red flashing.

[0105] Emergency stop release:

[0106] After pressing the emergency stop switch for 5 seconds, the system returns to the "power-off process breakpoint" - the storage and charging master continues to execute the incomplete power-off steps (disconnecting the power supply relay and stopping discharging externally);

[0107] The interface board no longer restores the supply of peripherals (following the power-on process), and the domain control continues to send power-off instructions;

[0108] Finally, the VCU monitors that "peripherals have been turned off and power has been cut off", turns off the battery output, and completes the power-off (same as the "battery output shutdown" logic of the normal power-off process).

[0109] The advantage of the self-recovery switch: solves the pain point of the traditional emergency stop switch "after pressing, it needs to be reset on site", through "self-recovery + long-press release / remote release", realizes the emergency stop recovery in unattended scenarios (self-recovery design).

[0110] Real-time signal transmission: the emergency stop signal is directly connected to the chassis VCU and storage and charging master through three-wire branching, avoiding the delay of passing through the domain control, ensuring that the safety operations such as chassis braking and high-voltage cut-off are completed within 1 second (improving the response speed compared to traditional single signal transmission).

[0111] Coordination with power-on and power-off processes: the emergency stop does not change the original state of the system (power-on / power-off), and after release, it automatically returns to the process node before the emergency stop (such as resuming work in the power-on state or continuing power-off in the power-off state), avoiding process conflicts (state inheritance).

[0112] Support of low-voltage redundancy: during the emergency stop process, the battery and the hot standby power supply (power supply A / B / C) cooperate to supply power - even if the main power supply (such as power supply C) stops output due to high-voltage cut-off, the battery can still maintain the low-power operation of the VCU and the storage and charging master, ensuring that the emergency stop signal monitoring does not interrupt (hot standby power supply).

[0113] The above embodiments are only specific application scenarios of the present application, and the core logic is based on the design requirements of the three disclosure documents, and does not deviate from the protection scope of the invention. Any modification or equivalent replacement of the above embodiments according to the technical essence of the present application is within the protection scope of the present application.

[0114] The embodiments of the present application are presented by way of example and description, and are not intended to be exhaustive or to limit the application to the form disclosed. Many modifications and variations will be apparent to those skilled in the art. Embodiments are chosen and described in order to best explain the principles of the application and its practical application, and to thereby enable others skilled in the art to best utilize the application in various embodiments and with various modifications as are suited to the particular use contemplated.

Claims

1. A robot emergency stop safety response control device characterized by comprising: The application relates to a self-recovery normally closed emergency stop switch, a chassis VCU, a storage and charging master control, an interface board, a domain control and a state lamp. The self-recovery normally closed emergency stop switch is connected with the chassis VCU, the storage and charging master control and the interface board respectively and is used for outputting an emergency stop signal and an emergency stop release signal. The chassis VCU communicates with the domain control through CAN and is used for controlling the chassis to brake and hold the brake after receiving the emergency stop signal and releasing the emergency stop state after receiving the emergency stop release signal. The storage and charging master control is connected with the interface board and is used for stopping charging or power supplement and disconnecting main positive and main negative relays after receiving the emergency stop signal and connecting the main positive and main negative relays after receiving the emergency stop release signal. The interface board is connected with the domain control and the storage and charging master control and is used for transmitting the emergency stop signal to the domain control, turning off external device power supply and transmitting the emergency stop release signal to the domain control and turning on the external device power supply. The domain control is used for controlling the state lamp to flash red light after receiving the emergency stop signal, controlling the state lamp to be always green after receiving the emergency stop release signal, sending a power-on command to the interface board and sending the emergency stop release signal to the storage and charging system. The self-recovery normally closed emergency stop switch is self-recovery, can be automatically reset after being pressed and can transmit the emergency stop signal to the chassis VCU, the storage and charging master control and the interface board through a three-wire branch circuit.

2. The apparatus of claim 1, wherein, The domain control communicates with a platform through MQTT and is used for receiving an emergency stop release command sent by the platform and transmitting the command to the interface board and the chassis VCU to release the emergency stop state.

3. The apparatus of claim 1, wherein, The application further discloses an emergency stop triggering process and an emergency stop release process.

4. A robot emergency stop safety response control method, characterized by, The emergency stop triggering process comprises the following steps: S1, pressing the self-recovery normally closed emergency stop switch to output an emergency stop signal; S2, the chassis VCU receiving the emergency stop signal to control the chassis to brake and hold the brake immediately; S3, the storage and charging master control receiving the emergency stop signal to stop charging or power supplement and disconnect the main positive and main negative relays to cut off high-voltage output if the storage and charging master control is in a charging or power supplement state; S4, the interface board receiving the emergency stop signal and transmitting the emergency stop signal to the domain control and turning off external device power supply; S5, the domain control receiving the emergency stop signal to control the state lamp to flash red light; The emergency stop release process comprises the following steps: S6, receiving an emergency stop release instruction, the emergency stop release instruction being a signal generated after the self-recovery normally closed emergency stop switch is pressed for 5 seconds or a remote command sent by the platform; S7, the interface board and the chassis VCU detecting the emergency stop release instruction to send an emergency stop release signal to the domain control respectively; S8, the domain control receiving the emergency stop release signal to control the state lamp to be always green, send a power-on command to the interface board and send the emergency stop release signal to the storage and charging system; S9, the interface board receiving the power-on command to turn on external device power supply; S10, the storage and charging system receiving the emergency stop release signal to turn on the main positive and main negative relays; S11, the chassis VCU receiving the emergency stop release signal to release the emergency stop state and restore the system to normal standby. In step S3, the domain control detects that the high voltage of the storage and charging system is disconnected after the storage and charging master control disconnects the main positive and main negative relays and sends a control lamp command to the interface board to control the state lamp to flash red light.

5. The method of claim 4, wherein, In step S6, the remote command sent by the platform is transmitted to the domain control through the MQTT protocol, and the domain control starts the emergency stop release process after receiving the remote command.

6. The method of claim 4, wherein, In step S8, the domain control sends a power-on command to the interface board, and the interface board controls double-wire connection for 3 seconds through a relay in the interface board to activate the power-on of the storage and charging system.

7. The method of claim 4, wherein, ​ 8. The method of claim 4, wherein, In step S10, after the charging system connects the main positive and negative relays, the domain control queries the high-voltage power-on state, and if the state is normal, the power supply relay is controlled to be connected.

9. The method of claim 4, wherein, In step S2, the chassis VCU controls the response time of the chassis brake stop brake to be not more than 1 second.

10. The method of claim 4, wherein, In step S5, the state light flashes at a frequency of 1-2 times per second, and in step S8, when the state light is always green, the loudspeaker synchronously broadcasts "emergency stop has been released".