Sudden stop protection control method for multi-console electric control system

By introducing a distributed coordination and deterministic time-limit mechanism into the multi-control console electronic control system, the problem of conflicting emergency stop commands from multiple control consoles was solved, achieving rapid and reliable global safety state convergence and improving the production safety and stability of the flexible manufacturing line.

CN121454886AActive Publication Date: 2026-02-03MT TITLIS BEIJING CONTROL TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511498477.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-20
Publication Date
2026-02-03
Estimated Expiration
2045-10-20

AI Technical Summary

Technical Problem

In flexible manufacturing lines with multiple control consoles, emergency stop commands may lead to inconsistent equipment stops, response delays, and safety risks. Existing technologies struggle to dynamically adjust priorities and coordinate state synchronization between multiple control consoles in high-concurrency scenarios.

Method used

By establishing a communication domain oriented towards safety-related signals, performing time base alignment and message integrity protection, generating emergency stop event messages carrying safety zone identifiers and timestamps, performing range arbitration based on the device safety dependency graph, achieving global target shutdown within a deterministic time limit, and employing distributed coordination and fault-tolerant rollback mechanisms to ensure the system quickly converges to a safe state.

Benefits of technology

It significantly improves the reliability and consistency of emergency stop response, avoids inconsistent or delayed equipment stops, enhances the real-time performance and anti-interference capabilities of the system, reduces the frequency of production interruptions, and improves the maintainability and traceability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121454886A_ABST
    Figure CN121454886A_ABST
Patent Text Reader

Abstract

The invention discloses a sudden stop protection control method for a multi-console electric control system, relates to the technical field of industrial automation and electromechanical equipment function safety, and is based on a distributed consistency protocol and range arbitration, and the method realizes automatic sorting and range expansion of sudden stop commands, and improves the safety of the system. Inconsistent equipment stop or delay caused by local decision in a traditional system is avoided, so that equipment collision and security vulnerability risks are reduced; by setting a deterministic time limit and integrating time slot scheduling of wireless communication, the system can still ensure that the sudden stop operation is completed within controllable time under the worst working condition, the real-time performance and the anti-interference capability are enhanced, and the system is particularly stable in a high-load or signal competition environment; in addition, redundancy protection is provided by a fail-safe backspacing and asynchronous auditing log mechanism, so that the system can be gracefully degraded when the node fails or the network is abnormal, and the overall safety level is maintained.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of industrial automation and functional safety of electromechanical equipment, and in particular to an emergency stop protection control method for a multi-console electric control system. BACKGROUND

[0002] In flexible manufacturing lines, emergency stop protection control methods are widely used in multi-operation console electric control systems to ensure production safety. Such systems are mostly composed of multiple independent consoles, such as robot consoles, conveyor belt consoles, and quality inspection consoles, each of which monitors a specific work section through wireless communication or local controllers. Common solutions in existing technologies include wireless roaming emergency stop systems based on IO-Link Wireless, which support portable emergency stop devices switching between manufacturing units, and safety controllers integrated with formal verification, which are used to verify the correctness of the emergency stop logic of individual control units. These technologies aim to improve the flexibility and reliability of emergency stop to meet the needs of dynamic production environments.

[0003] However, in multi-operation scenarios, when an abnormality occurs in the production line, multiple operators may simultaneously trigger emergency stop commands from different consoles. Due to the lack of a global coordination mechanism, the emergency stop execution sequence depends on local decision-making or fixed communication protocols. This can lead to command conflicts, such as some devices stopping while others continue to run, or emergency stop response delays, causing motion mismatch between devices. While the wireless roaming system supports device movement, it does not address the priority allocation problem when multiple commands are concurrent. The safety controller with formal verification ensures the correctness of individual controllers but cannot handle the state synchronization challenge between multiple consoles.

[0004] Some solutions in existing technologies address these shortcomings by expanding communication protocols or introducing distributed computing. For example, the wireless roaming system uses the IO-Link Safety protocol to enhance data transmission security, and some solutions use digital twin technology to simulate multi-console interactions to identify potential conflicts. However, these methods still rely on preset switching rules or centralized coordination, making it difficult to dynamically adjust emergency stop priorities in real-time high-concurrency scenarios, leading to system coverage or omission when dealing with sudden multiple commands. SUMMARY

[0005] In view of the above existing problems, the present application is proposed.

[0006] The present application provides an emergency stop protection control method for a multi-console electric control system to solve the problem of inconsistent device stoppage, response delay, and safety risks caused by multi-operation console emergency stop command conflicts in flexible manufacturing lines.

[0007] To solve the above technical problems, the present application provides the following technical solutions:

[0008] The embodiment of the present application provides a kind of emergency stop protection control method of multi console electric control system, it includes:

[0009] Step S1, the communication domain for safety-related signal is established, and time base alignment and message integrity protection are completed between control consoles;

[0010] Step S2, when any control console detects emergency stop trigger, the relevant execution element of the safety zone to which the control console belongs is immediately disabled or enters controlled shutdown, and an emergency stop event message carrying safety zone identification, time stamp and monotonic count is generated;

[0011] Step S3, after the rest of the control console receives the emergency stop event message, the safety zone involved is arbitrated based on the locally stored device safety dependency graph, to obtain a global target shutdown range set, and the global target shutdown range set is the union of each concurrent emergency stop and is extended according to the dependency relationship;Device safety dependency graph is used to represent the energy coupling or safety dependency relationship between devices;

[0012] Step S4, under the condition that the target shutdown range is not more than the deterministic time limit , the device in the target shutdown range is placed in a safe state;If consistency convergence is not completed or a missing node is detected within , global emergency stop rollback is performed;The global emergency stop rollback refers to implementing system-level disablement on all controlled devices within the communication domain;The missing node refers to a control console that has not been confirmed within ;

[0013] Step S5, generate event records of emergency stop disposal results and time parameters.

[0014] As a preferred scheme of the emergency stop protection control method of the multi console electric control system, wherein: the range arbitration includes two-stage broadcast:

[0015] The pre-decision message is used to announce the candidate shutdown range and merge according to the monotonic union rule, and the submission message is used to determine the final range and solve the coverage relationship of concurrent messages according to the deterministic sequence rule of time stamp and control console identification.

[0016] As a preferred scheme of the emergency stop protection control method of the multi console electric control system, wherein: the deterministic time limit Is set according to the communication round-trip time statistical quantity, clock synchronization error upper bound and device disablement time upper bound;

[0017] The determining method is as follows:

[0018] a) split caliber and verifiable upper bound, give the backbone relationship of deterministic time limit in verifiable split, as upper limit and running period review basis:

[0019] ,

[0020] wherein, denotes the deterministic time limit, denotes the device de-energization time upper bound, denotes the time base alignment synchronization error upper bound, denotes the emergency stop message worst transmission delay, denotes the control execution overhead upper bound, denotes the de-energization segment, denotes the transmission segment, denotes the control execution segment;

[0021] b) Measurement and estimation methods of the four upper bounds are as follows:

[0022] 1) Device de-energization upper bound: Perform loop layout power and position measurement, take the emergency stop rising edge as the trigger time, take the energy isolation threshold as the termination time, collect samples across temperature, load and aging conditions, take the upper bound by taking the upper bound and adding environmental and life margins;

[0023] 2) Synchronization error upper bound: Continuously collect local-reference clock difference in online state, use sliding window upper bound statistics and out-of-bound monitoring, take the upper bound value as the larger one of the protocol design upper bound and the online observed upper bound;

[0024] 3) Transmission delay upper bound: In time division multiple access, emergency slots are reserved for emergency stop, measured by air interface packet capture and control console timestamp from both sides, covering queuing, identification, air interface and confirmation, and re-measured under high load interference and boundary signal-to-noise to take the upper bound, and once retransmission is included in the same cycle redundancy gap or the next cycle according to the strategy;

[0025] 4) Control execution upper bound: Analyze emergency stop in firmware, query dependency graph, and dot state machine migration, measure in the largest range set and busy path, take the upper bound as the upper bound value, and review in running period with lightweight tracking;

[0026] c) Establish a consistent statistical yardstick for the three measurable upper bounds:

[0027] ,

[0028] wherein, denotes the upper bound of the item to be estimated, denotes the segment to which the upper bound belongs, denotes the one-sided upper bound quantile estimation of the segment under multi-condition test, denotes the quantile level, denotes the environmental and life correction margin; the synchronization error item does not use quantile estimation, but takes the upper bound of the design upper bound and the online observed upper bound;

[0029] d) Complete type test and field joint debugging before going online, output four online values and substitute into step a) to calculate;

[0030] During operation, recalculate three measurable indicators using a sliding window, compare with online values, if any exceeds the online value or the synchronous error is out of bounds, enter fault safety rollback, and record observation data;

[0031] e) After the treatment is completed, record four online values, the observation value and the window statistics, write into the cross console consistency replication log, which does not participate in real-time closed loop, only for traceability and reevaluation.

[0032] As a preferred scheme of the emergency stop protection control method of the multi-console electric control system, wherein: the communication domain adopts a wireless industrial protocol supporting security extension and has multicast / broadcast capability.

[0033] As a preferred scheme of the emergency stop protection control method of the multi-console electric control system, wherein: the wireless access layer adopts time division multiple access scheduling, reserves a fixed minimum emergency time slot quota for emergency stop events, and reallocates between emergency and non-emergency services according to a preset time slot allocation strategy under the constraint of constant total time slots;

[0034] The time slot allocation strategy ensures that the emergency stop event obtains transmission opportunity within a single cycle and gives the worst transmission delay upper bound;

[0035] The definition of the time slot allocation strategy and the derivation of the worst transmission delay upper bound are as follows:

[0036] f) Adopt time division multiple access single cycle length and emergency time slot equal interval configuration, emergency stop message enters the nearest emergency reserved gap transmission, then the worst transmission delay upper bound of single transmission is:

[0037] ,

[0038] Wherein, represents the worst transmission delay upper bound of single transmission scenario, represents the length of a single TDMA cycle, represents the number of emergency reserved time slots per cycle, represents the total length of physical layer and discrimination overhead available in a single time slot, represents the total length of confirmation and protection interval, represents transmission related quantity, subscript represents a single transmission scenario;

[0039] g) In the condition of total time slots unchanged, non-emergency service can only be allocated in idle multiplexing at the beginning of the period, and the revocable token is generated using the emergency reserved gap that is not occupied by the emergency stop queue in the period. Once the emergency stop queue appears in the period, the subsequent emergency reserved gap is preferentially scheduled for emergency stop, and the unused token is invalid, and cross-gap preemption does not occur. This rule makes the non-emergency service load not constitute a lift to the upper bound obtained in step f);

[0040] h) When a retransmission is needed, the retransmission occupies the nearest emergency reserved gap of the next period, and the upper bound of the worst transmission delay in the two-period window is:

[0041] ,

[0042] wherein, represents the upper bound of the worst transmission delay containing one retransmission, and the subscript represents a two-period window scenario;

[0043] i) In the constraint of the total number of time slots per period being fixed, the emergency and non-emergency occupation satisfies:

[0044] ,

[0045] wherein, represents the number of emergency reserved time slots, represents the number of non-emergency available time slots, represents the total number of time slots per period;

[0046] The upper limit of concurrent emergency stop is given during engineering setting and the upper limit of two-period window , the configuration satisfies , then one-period is reached, and in , two-period is reached in combination with step h); the subscript represents emergency-related quantities, , represents a single period and a two-period window;

[0047] j) measured by air interface packet capture and console timestamp from both sides, statically given by the scheduling table and solidified in online audit, set according to the number of safety zones, operation mode and historical statistics, and rolling evaluation during operation; the upper bounds obtained in steps f) and h) are substituted into the foregoing for the overall calculation of ; the upper bound of the worst transmission delay is used for the setting of .

[0048] As a preferred scheme of the emergency stop protection control method of the multi-console electric control system, the time base alignment adopts network clock synchronization, and the upper limit of synchronization error is not more than a preset , the participation is set and online checking and out-of-limit rollback are performed in operation.

[0049] As a preferred scheme of the emergency stop protection control method of the multi-console electric control system, the fault safety rollback includes:

[0050] When any console does not confirm entering the target shutdown range or detects message replay / tampering risk within the , a rollback emergency stop instruction is broadcasted and system-level de-energization is triggered;

[0051] The rollback triggering threshold is dynamically adjusted according to the time delay and packet loss observation of the sliding window, but does not exceed a fixed upper limit.

[0052] As a preferred scheme of the emergency stop protection control method of the multi-console electric control system, leader election and majority consensus replication are used for ordered writing and cross-console retention of emergency stop event audit logs, and the consensus replication does not participate in the real-time closed loop of steps S2 to S4, but is recorded asynchronously after completing the safety disposal.

[0053] As a preferred scheme of the emergency stop protection control method of the multi-console electric control system, the target shutdown range is conservatively expanded based on a risk assessment model, and the output of the risk assessment model is only used to expand the shutdown range or shorten the disposal time limit, and cannot reduce the range obtained in step S3;

[0054] The risk assessment model input includes operating mode and environmental sensing, and includes a regularized rollback in an unavailable / uncertain scenario.

[0055] As a preferred scheme of the emergency stop protection control method of the multi-console electric control system, the device layer supports a safety de-energization interface or a controlled shutdown interface, and maintains the execution of energy isolation before the interface returns a confirmation;

[0056] If the confirmation times out, the global emergency stop is entered in the fault safety rollback mode.

[0057] The present application has the advantages that: by introducing a distributed coordination and deterministic time limit mechanism in the multi-console electric control system, the reliability and consistency of the emergency stop response are significantly improved. In the multi-station scene such as a flexible manufacturing line, the system can effectively solve the problem of concurrent command conflict of multiple operation stations, and ensure that the emergency stop event quickly converges to a global safe state.

[0058] The application is based on a distributed consensus protocol and range arbitration, and the method realizes automatic sequencing and range expansion of the emergency stop command, avoids the inconsistency or delay of device stop caused by local decision in traditional systems, thereby reducing the risk of device collision and security vulnerabilities. By setting a deterministic time limit and integrating time slot scheduling of wireless communication, the system can still ensure that the emergency stop operation is completed within a controllable time under the worst working condition, enhancing the real-time performance and anti-interference ability, especially in high-load or signal competition environment. In addition, the fault safety fallback and asynchronous audit log mechanism provides redundant protection to ensure that the system can gracefully degrade and maintain the overall security level when the node fails or the network is abnormal. The method supports dynamic priority adjustment and risk assessment expansion, which adapts to the flexible needs of modern manufacturing without increasing hardware costs, and improves the maintainability and traceability of the system.

[0059] The application realizes seamless cooperation between multiple consoles through algorithm optimization, reduces the frequency of production interruption, improves the confidence of operators and the overall safety of the system, and provides an efficient and safe emergency stop solution for industrial automation. BRIEF DESCRIPTION OF DRAWINGS

[0060] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope of the present application.

[0061] Figure 1 The flowchart of the emergency stop protection control method of the multi-console electric control system in the embodiment. DETAILED DESCRIPTION

[0062] In order to make the purpose, technical solutions and advantages of the present application more clear, the following will further illustrate the present application in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.

[0063] All terms used in the present application (including technical and scientific terms) have the meanings generally understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted to have meanings consistent with the context of the present specification, and should not be interpreted in an idealized or overly formal manner.

[0064] For example, the terms "first", "second", etc. used in the present application are only used to distinguish similar objects, to distinguish the first object from another object, and are not used to describe a specific order or sequence, nor can be understood as indicating or implying relative importance.

[0065] The application provides an emergency stop protection control method of a multi-console electric control system Figure 1 As shown in the figure, the multi-console electric control system comprises consoles and controlled devices distributed in multiple sections, and the emergency stop protection control method comprises the following steps:

[0066] Step S1, a communication domain for safety-related signals is established, and time base alignment and message integrity protection are completed between the consoles; in this embodiment, the communication domain refers to a logical broadcast range defined between the consoles and the controlled devices participating in the emergency stop interaction, and the acquisition method is to determine the member list during the online commissioning stage and solidify it to each console; the time base alignment refers to maintaining a unified reference time for each console to determine the event sequence and window alignment, and the acquisition method is network clock synchronization; the message integrity protection refers to tamper and replay protection realized by using the monotonic count and authentication field in the message. The default synchronization maintenance period is 1-2 seconds, which can be adjusted to 0.2-5 seconds, and is set according to the online clock jitter measurement and load evaluation; the default message keep-alive period is 2-3 communication periods, which can be adjusted to 1-10 periods, and is set according to the link stability. The upper bound of the synchronization error is obtained from the larger value of the online type test and the online observation, and the typical value is not more than 100 microseconds, which can be adjusted to 50-500 microseconds according to the process urgency. Alternatively, the repeated detection other than the authentication field can be realized by the monotonic count, and the authentication field is only used for integrity check. When any member loses clock synchronization or fails in authentication check, it is regarded as a communication domain exception, enters the minimum execution criterion of the fault safety fallback, and records the abnormal reason.

[0067] Step S2, when any console detects an emergency stop trigger, the console immediately de-energizes or enters controlled shutdown of the relevant execution elements of its own safety zone, and generates an emergency stop event message carrying the safety zone identification, timestamp and monotonic count; Specifically, the safety zone refers to the smallest safety disposal unit divided according to the energy coupling relationship of the equipment, and the acquisition method is to generate and issue by the dependency list during engineering setting; De-energization / controlled shutdown refers to driving energy isolation or stopping to a safe state with controlled deceleration, and the acquisition method is to call the safety interface provided by the equipment; The timestamp and monotonic count are used for sequential judgment and replay protection respectively. The default de-energization confirmation threshold is that the residual energy on the power side is lower than 5% or the execution element speed is lower than the safety limit, which is satisfied for 100 milliseconds, and can be adjusted to 50-300 milliseconds, which is set according to the inertia and energy release characteristics of the equipment; The default event timestamp resolution is not less than 1 microsecond, the monotonic count step is 1, and the count wraparound time is not less than one year. The measured upper bound of the de-energization time of the equipment is to take the maximum observed value under different temperatures, loads and aging and add the environmental allowance, and its typical range is tens to hundreds of milliseconds. Alternatively, if the equipment only supports a controlled shutdown interface, the controlled shutdown reaches the safety speed as the confirmation condition, and the output semantics remains the same. When the equipment does not return the confirmation within the specified time, it immediately reports the absence and triggers the failsafe fallback.

[0068] Step S3, after the remaining consoles receive the emergency stop event message, the safety zones involved are range arbitrated based on the locally stored device safety dependency graph, and a global target shutdown range set is obtained, which is the union of each concurrent emergency stop and is expanded according to the dependency relationship; For example, the device safety dependency graph refers to a directed relationship structure describing the shutdown propagation relationship between devices caused by energy, mechanical coupling or process coupling, and the acquisition method is to import it by the process engineer during online setting and store it locally on each console. The default dependency graph verification period is 24 hours or immediately after each process change; The range arbitration window uses 1 communication cycle by default, and can be adjusted to 1-3 cycles, which is set according to the concurrent trigger probability and convergence time evaluation. The acquisition method of the upper bound of the control execution overhead is to take the maximum observed value by timing the analysis, query and state transition under the maximum range set and the busiest path, and the typical range is hundreds of microseconds to milliseconds. Alternatively, the dependency graph can be divided into several partitions according to the safety zone to reduce the query overhead, and the output global target set remains unchanged. When the dependency graph is missing or fails to verify, the adjacent dependencies are included in the target range according to the conservative strategy and reported to the audit.

[0069] Step S4, under the condition that the deterministic time limit is not exceeded , the equipment in the target shutdown range is placed in a safe state; if the If the consistency convergence is not completed or the missing node is detected, a global emergency stop fallback is performed; similarly, the deterministic time limit refers to the maximum processing time allowed to ensure the completion of consistency convergence or trigger the fallback under the worst-case scenario, which is obtained by online calculation and rolling verification during operation. The default upper limit of the processing timeout is set to the order of 100 milliseconds, which can be adjusted to 20-300 milliseconds, and is set comprehensively according to the upper limit values of the device disablement capability, communication delay and synchronization error. The upper limit of the transmission delay is obtained by measuring the total time of waiting for the nearest emergency reserved time slot, transmission and confirmation under time division multiple access, and taking the maximum observed value under high load interference and edge signal-to-noise; the upper limit of the synchronization error is derived from the larger one of the design and online observation. Optionally, if the processing is close to the timeout threshold, the global fallback can be triggered in advance to ensure safety. When the missing node, message replay or authentication failure occurs, the fallback is triggered immediately and the event reason is broadcast to prevent residual motion in the partition.

[0070] In step S5, an event record of the emergency stop processing result and time parameters is generated for auditing; optionally, the event record refers to a structured entry containing the processing start and end time, the participating console identifier, the involved safety area and the processing result, which is obtained by submitting any online console after the processing is completed and stored through consistency replication. The default record submission deadline is within 500 milliseconds after the processing is completed, which can be adjusted to 100-1000 milliseconds, and is set according to the background throughput capability and link stability; the default retention period is not less than one year, which can be adjusted according to the compliance requirements. The time parameters and upper limit values in the log entry are derived from the observation record and the online value of the processing, which typically include processing time, waiting time and confirmation time. When the audit log submission fails or times out, local persistence is adopted and the submission is supplemented after the link is restored.

[0071] In one embodiment, the range arbitration includes two-stage broadcasting:

[0072] The pre-decision message is used to announce the candidate shutdown range and perform monotonic and set merging, and the submission message is used to determine the final range, and the deterministic sequence rule is used to solve the coverage relationship of concurrent messages with time stamp and console identifier; further, the pre-decision message contains the candidate range and the source identifier, which is obtained by triggering the end immediately after the emergency stop event is generated; the submission message contains the final range and the convergence mark, which is obtained by broadcasting the confirmation after each node completes the set expansion. The default pre-decision waiting window is 1 communication cycle, which can be adjusted to 1-3 cycles; the default submission timeout is the sum of two waiting windows, which is set according to the concurrent size and link delay. The precedence in the deterministic sequence rule is dominated by the time stamp, and the console identifier is only used for tie-breaking, and the typical determination granularity is not less than the microsecond level. Optionally, the submission message can be omitted when the candidate range and the final range are consistent to shorten the processing time. If there is still conflict or node absence in the submission stage, the global fallback is processed and the conflict reason is recorded.

[0073] In one embodiment, the deterministic time limit is set according to the communication round-trip time statistics, the clock synchronization error upper bound, and the device de-energization time upper bound, the calculation aperture and parameter bound meet the convergence or rollback of step S4 under the worst working condition;

[0074] The determination method is as follows:

[0075] a) Perform aperture splitting and verifiable upper bound, and give the backbone relationship of the deterministic time limit in the verifiable splitting, which is used as the upper limit and the running period review basis:

[0076]

[0077] Among them, represents the deterministic time limit, represents the device de-energization time upper bound, represents the upper bound of the synchronization error of the time base alignment, represents the worst transmission delay of the emergency stop message (including one retransmission), represents the control execution overhead upper bound, represents the de-energization link, represents the transmission link, represents the control execution link;

[0078] b) The measurement and estimation method of the four upper bounds is as follows:

[0079] 1) Device de-energization upper bound: Perform loop layout energy and position measurement, trigger the rising edge of the emergency stop, terminate when the energy isolation threshold is reached, collect samples across temperature, load and aging conditions, and take the upper limit value by taking the upper bound and adding environmental and life margins;

[0080] 2) Synchronization error upper bound: Continuously collect local-reference clock differences in online state, use sliding window upper bound statistics and out-of-bound monitoring, and take the upper limit value as the larger one of the protocol design upper bound and the online observation upper bound;

[0081] 3) Transmission delay upper bound: In time division multiple access, emergency slots are reserved for emergency stop, measured by air interface packet capture and control console timestamp from both sides, covering queuing, identification, air interface and confirmation, and retested under high load interference and boundary signal-to-noise to take the upper bound. One retransmission is included in the same cycle redundancy gap or the next cycle according to the strategy;

[0082] 4) Control execution upper bound: Analyze the emergency stop in the firmware, query the dependency graph, and dot the state machine migration, measure in the maximum range set and busy path, take the upper bound as the upper limit value, and review in the running period with light tracking;

[0083] c) Establish a consistent statistical aperture for the three measurable upper bounds:​

[0084] ,

[0085] wherein, represents the upper bound of the item to be estimated, represents the link to which the upper bound belongs, represents the one-side upper partial quantile estimation of the multi-condition test of the link, represents the quantile level (it is recommended not to be less than ), represents the environment and life correction margin; the synchronization error item does not use quantile estimation, and the upper bound of the design upper bound and the online observation upper bound is directly taken as the upper bound;

[0086] d) Complete type test and field joint debugging before going online, output four online values and substitute into step a) for calculation;

[0087] During operation, three measurable indicators are recalculated by using a sliding window, compared with the online values, and if any one exceeds the online value or the synchronization error goes out of bounds, the fault safety rollback is entered, and the observation data is recorded;

[0088] e) After the disposal is completed, four online values, observation values and window statistics are recorded, and written into the cross-control console consistency replication log, which does not participate in real-time closed loop, and is only used for tracing and re-evaluation;

[0089] Specifically, the deterministic time limit is split into four independent and measurable upper bounds, a unified statistical and margin synthesis method is given, and a through pass is formed in the type test, field joint debugging and operation stage; the decomposition items correspond to four links of device action, clock synchronization, air interface transmission and control execution, which can cover the time delay lifting of the system in scenes such as high load interference, edge signal noise, temperature drift and aging; during operation, online review is performed by using a sliding window, and compared with the online values, once the observation result deviates from the established boundary, the rollback is triggered to maintain the safety side; the audit link adopts cross-control console consistency replication, saves the observation and statistics, and is beneficial to positioning the bottleneck and adjusting the margin strategy; in the embodiment, in order to facilitate review, the four online values and observation values of the current time are written into the audit entry after the disposal is completed, and the acquisition method is to aggregate and send to the replication channel by the disposal initiation end. The default sliding window length is nearly 1 minute, which can be adjusted to 10 seconds to 5 minutes according to the time-varying nature and sampling load of the field; the default quantile level is not less than the extremely high quantile, which is determined according to the type test results and expert rules. The environment and life margin is derived from the test results of temperature, humidity, aging and power fluctuation, and the typical synthesis range is several milliseconds to tens of milliseconds. Alternatively, if the full-quantity packet capture cannot be carried out on site, the console double-sided timestamp can be used instead of air interface measurement to maintain the same caliber. When the window statistics abnormally jump, the threshold is reduced and a one-time rollback is triggered to prevent risk leakage caused by caliber mismatch.

[0090] In one embodiment, the communication domain adopts a wireless industrial protocol supporting security extension and multicast / broadcast capability, the protocol is compatible with IO-Link Wireless or its equivalent implementation, used for synchronizing emergency stop events and acknowledgments between the console and the device; for example, multicast / broadcast is used to distribute emergency stop events and acknowledgments within the communication domain at one time, and the acquisition method is to configure the corresponding address family and filtering rules in the protocol stack. The default single wireless communication cycle is 5-20 milliseconds, adjustable to 2-50 milliseconds, set according to air interface occupation and reliability test; the default emergency stop dedicated priority is the highest, and non-emergency stop business cannot be preempted. The acknowledgment period is composed of physical layer processing time and protocol identification time, and its typical range is ten to hundreds of microseconds. Optionally, when broadcast is limited, it can be degraded to multicast, and the member set remains consistent with the communication domain. When air interface congestion or interference is detected, the emergency stop message repetition factor is immediately increased or the cycle length is shortened to ensure that the processing is completed within a deterministic time limit.

[0091] In one embodiment, the wireless access layer adopts time division multiple access scheduling, reserves a fixed minimum emergency time slot quota for emergency stop events, and reallocates between emergency and non-emergency traffic according to a preset time slot allocation strategy under the constraint that the total time slot remains unchanged;

[0092] The time slot allocation strategy ensures that the emergency stop event obtains a transmission opportunity within a single cycle and gives an upper bound of the worst transmission delay;

[0093] The definition of the time slot allocation strategy and the derivation of the upper bound of the worst transmission delay are as follows:

[0094] f) Adopt time division multiple access single cycle length and emergency time slot equal interval configuration, emergency stop message enters the nearest emergency reserved gap transmission, then the upper bound of the worst transmission delay of single transmission (excluding retransmission) is:

[0095] ,

[0096] Wherein, represents the upper bound of the worst transmission delay in the single transmission scenario, represents the length of a single TDMA cycle, represents the number of emergency reserved time slots per cycle (equally spaced), represents the total physical layer and identification overhead available in a single time slot, represents the total length of the acknowledgment and protection interval, represents the transmission-related quantity, subscript represents a one-time transmission scenario;

[0097] g) In the condition of total time slots unchanged, non-emergency service can only be allocated in idle multiplexing at the beginning of the period, and the revocable token is generated using the emergency reserved gap not occupied by the emergency stop queue in the period. Once the emergency stop queue appears in the period, the subsequent emergency reserved gap is preferentially scheduled for emergency stop, and the unused token is invalid, and cross-gap preemption does not occur. This rule makes the non-emergency service load not constitute a lift to the upper bound obtained in step f);

[0098] h) When a retransmission is needed, the retransmission occupies the nearest emergency reserved gap of the next period (or when the period redundancy gap exists, such as configuration), then the worst transmission delay upper bound in the two-period window is:

[0099] ,

[0100] wherein, represents the worst transmission delay upper bound containing one retransmission, and the subscript represents the two-period window scenario;

[0101] i) In the constraint that the total number of time slots per period is fixed, the emergency and non-emergency occupation satisfies:

[0102] ,

[0103] wherein, represents the number of emergency reserved time slots, represents the number of non-emergency available time slots, represents the total number of time slots per period;

[0104] The upper limit of concurrent emergency stop (maximum emergency stop trigger count in any period) and the two-period window upper limit (maximum emergency stop trigger count in adjacent two periods) are given when engineering is set, and the configuration satisfies then one period is reached, and in two periods are reached in combination with step h); the subscript represents emergency-related quantities, , represents single-period and two-period windows;

[0105] j) measured by air interface packet capture and console timestamp from both sides, statically given by the scheduling table and solidified in online audit, set according to the number of safety zones, operation mode and historical statistics, and rolling evaluated in the running period; the upper bounds obtained in steps f) and h) are substituted into the foregoing term for the overall calculation of ;

[0106] Specifically, this paper takes the equal interval reserved emergency slot as the baseline, the worst delay of single transmission is composed of waiting for the nearest reserved gap + transmission and confirmation, and in the presence of one retransmission, the upper limit within two periods of window is realized through the nearest reserved gap of the next cycle; The competition and multiplexing adopt the idle multiplexing and revocable token method at the beginning of the cycle, so that the non-emergency high load does not introduce the upper limit of the lift; The capacity and duty cycle part takes the total slot as the constraint, combines the concurrent emergency stop upper limit of single cycle and two cycle window, forms a one period must reach / two period must reach provable condition, which is convenient for solidification in the engineering setting stage with static table and upper limit audit, and in the running period, the window concurrent upper limit is rolled over by observing the data. Recheck and reevaluation, maintain the upper limit and the field performance consistent; Similarly, in order to ensure that the measured cycle length, time slot and confirmation period are consistent with the upper limit audit, the acquisition method is to measure periodically and update the audit baseline during the maintenance period. The default retest cycle is one week, which can be adjusted to 1~30 days according to environmental fluctuations and operation arrangement; The default number of emergency reserved slots is not less than the upper limit of single cycle concurrent emergency stop, which is set according to historical statistics and process risk. The upper limit of the worst delay of single transmission scenario and two period window scenario is derived from the combination of waiting for the nearest reserved gap and cross cycle waiting, and the typical proportional relationship is proportional to the cycle length. Optionally, when there are redundant reserved gaps, one retransmission can be completed within the same cycle, and the output worst delay upper limit is calculated according to the same cycle redundancy. When the window concurrent upper limit is continuously broken through, the disposal strategy is immediately switched to global rollback and engineering setting review is triggered.

[0107] In one embodiment, the time base alignment adopts network clock synchronization, and the upper limit of synchronization error is not more than the pre-set , The setting is participated in and online check and out of limit rollback is carried out in running time; optionally, the clock synchronization adopts master-slave or peer negotiation two ways, and the acquisition method is to select and solidify according to network topology when online. The default resynchronization interval is 10~30 seconds, which can be adjusted to 1~60 seconds according to drift rate and network load; The default out of limit alarm threshold is lower than 80% of the upper limit of synchronization error, leaving disposal advance. The out of limit criterion is composed of two conditions of continuous multiple observations exceeding the threshold and single large jump, and the typical minimum duration is several communication cycles. When the continuous out of limit reaches the set number of times, global rollback is immediately triggered and the clock source is marked as abnormal.

[0108] In one embodiment, the fault safety rollback includes:

[0109] When any console does not confirm entering the target shutdown range or detects message replay / falsification risk within , broadcast rollback emergency stop instruction and trigger system level disablement;

[0110] The rollback trigger threshold is dynamically adjusted according to the time delay and packet loss observation of the sliding window, but does not exceed the fixed upper limit; further, the dynamic adjustment is obtained by correcting the rollback threshold by a limited amplitude at the end of each window according to the observed mean, upper deviation and jitter. The default threshold adjustment step is not more than 5% of the original value, which can be adjusted by 1% to 10%, and is set according to the field stability; the default minimum duration is two windows to prevent frequent switching caused by short disturbances. The fixed upper limit comes from the sum of the deterministic time limit and the safety margin calculated online, and its typical value is higher than the running threshold to provide fault tolerance space. When the window statistics are not available or the sample is insufficient, the online threshold is used and the adaptive adjustment is suspended until it is restored.

[0111] In one embodiment, leader election and majority consensus replication are used for ordered writing and cross-console retention of the emergency stop event audit log, the consensus replication does not participate in the real-time closed loop of steps S2 to S4, and only records asynchronously after the safe disposal is completed to achieve traceability; in this embodiment, the leader election is obtained by initiating a timed election during the idle period of the audit channel and reselecting when the leader is lost, and the replication is only performed for audit entries. The default election timeout is 300 to 800 milliseconds, which can be adjusted by 100 to 1500 milliseconds, and is set according to the number of nodes and network delay; the default disk writing batch threshold is 10 entries or 1 second, whichever is earlier. The replication confirmation is based on the successful persistence of the majority of nodes, and the typical node threshold is more than half. Alternatively, when the load is low, it can be changed to submit one by one to reduce the risk of loss. When the majority is unreachable, local persistence is performed first and playback is performed after recovery, which does not affect real-time disposal.

[0112] In one embodiment, the target shutdown range is conservatively expanded based on a risk assessment model, and the output of the risk assessment model is only used to expand the shutdown range or shorten the disposal time limit, and cannot reduce the range obtained in step S3;

[0113] The risk assessment model input includes operating mode and environmental sensing, and includes a regularized rollback in unavailable / uncertain scenarios; specifically, the risk assessment model only performs conservative expansion, and the acquisition method is to incorporate the evaluation results into the target range or shorten the disposal time limit when triggered concurrently, and cannot reduce the established range. The default expansion amplitude does not exceed one adjacent layer of dependence, which can be adjusted to two layers, and is set according to process risk and historical events; the default time limit shortening amplitude is 5% to 20% of the original value, and is set according to the device response capability. When the input is missing, a regularized rollback is performed, i.e., a fixed expansion amplitude and a fixed time limit shortening are performed, and the typical values are given by engineering setting. Alternatively, the model parameters can be updated during the non-production period, and the output semantics remain unchanged. When the model output is inconsistent or the reasoning times out, the model result is ignored and the original range and threshold are executed.

[0114] In one embodiment, the device layer supports a safe de-energizing interface or a controlled shutdown interface, and maintains the execution energy isolation until the interface returns an acknowledgement;

[0115] If the acknowledgement times out, the system enters a global emergency stop in a fail-safe fallback manner. For example, the device layer acknowledgement is obtained by reading the completion flag of the safe de-energizing interface or the controlled shutdown interface, and if the reading is unavailable, it is considered to be a timeout. The default interface acknowledgement timeout is 200 milliseconds, which can be adjusted to 50-500 milliseconds according to the drive response and field test settings. The default retry number is 1, which can be adjusted to 0-3. The energy isolation criterion is derived from the power or position measurement reaching a safety threshold and stably maintaining a minimum duration, and the typical duration is 50-100 milliseconds. Alternatively, when the interface supports intermediate state reporting, the power can be reduced before reaching the safety threshold, and the output handling result remains unchanged. When the interface returns an error code or a read / write exception, the system immediately broadcasts a defect message and enters a global fallback to prevent motion mismatch caused by residual energy.

[0116] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

[0117] In addition, those skilled in the art can understand that although some embodiments herein include certain features included in other embodiments rather than other features, the combination of features of different embodiments means to be within the scope of the present application and forms different embodiments. For example, all the above embodiments can be used in any combination. The information disclosed in the background section is only intended to deepen the understanding of the overall background of the present application, and should not be regarded as acknowledging or implying in any form that the information constitutes prior art known to those skilled in the art.

Claims

1. An emergency stop protection control method for a multi-control console electronic control system, characterized in that, The multi-control console electrical control system includes control consoles and controlled equipment distributed across multiple work sections. The emergency stop protection control method includes: Step S1: Establish a communication domain for security-related signals and complete time base alignment and message integrity protection between consoles; Step S2: When any console detects an emergency stop trigger, the console immediately disables or enters controlled shutdown of the relevant execution elements in its security zone and generates an emergency stop event message carrying the security zone identifier, timestamp, and monotonic count. Step S3: After receiving the emergency stop event message, the other consoles perform range arbitration on the relevant security zones based on the locally stored device security dependency graph to obtain a global target shutdown range set. The global target shutdown range set is the union of all concurrent emergency stops and expanded according to the dependency relationship. The device security dependency graph is used to represent the directed relationship of energy coupling or security dependency between devices. Step S4, within the deterministic time limit Under the conditions specified, place the equipment within the target shutdown range into a safe state; if in If consensus is not achieved or an absent node is detected, a global emergency stop rollback is executed; the global emergency stop rollback refers to system-level disabling of all controlled devices within the communication domain; an absent node refers to... The console was not confirmed as required. Step S5: Generate an event record containing the emergency stop response results and time parameters.

2. The emergency stop protection control method for a multi-control console electronic control system as described in claim 1, characterized in that, The scope arbitration includes a two-stage broadcast: The pre-decision message is used to announce the candidate shutdown range and merge them according to the monotonic union rule. The commit message is used to determine the final range and resolve the coverage relationship of concurrent messages using the deterministic order rule of timestamp and console identifier.

3. The emergency stop protection control method for a multi-control console electronic control system as described in claim 1, characterized in that, The deterministic time limit The parameters are set based on the communication round-trip delay statistics, the upper limit of the clock synchronization error, and the upper limit of the device deactivation time. The The determination method is as follows: a) Decompose the scope and establish verifiable upper bounds. In the verifiable scope, provide the core relationships with deterministic time limits to serve as the basis for review during deployment and operation: , in, Indicates a deterministic time limit, This indicates the upper bound of the device's deactivation time. This represents the upper bound of the synchronization error for time base alignment. This indicates the worst-case transmission delay for the emergency stop message. This indicates the upper bound of the control execution overhead. Indicates the energy removal process. Indicates the transmission stage. Indicates the control execution stage; b) The methods for measuring and estimating the four upper bounds are as follows: 1) Equipment energy upper limit: Install power and location measurements in the execution loop, take the emergency stop rising edge as the trigger time, and take the energy isolation threshold as the termination time. Collect samples across temperature, load and aging conditions, take the upper bias and add environmental and life margin to form the upper limit value. 2) Upper bound of synchronization error: Local-reference clock difference is continuously collected in online mode, and sliding window upper bias statistics and over-boundary monitoring are adopted. The upper limit value is the larger of the protocol design upper limit and the online observation upper limit. 3) Upper bound of transmission delay: In time division multiple access, an emergency time slot quota is reserved for emergency stop. The measurement is carried out by both air interface packet capture and console timestamp, covering queuing, identification, air interface and confirmation. The upper offset is measured again under high load interference and boundary signal-to-noise. A retransmission is included in the same period redundancy slot or the next period according to the strategy. 4) Control execution upper bound: The firmware performs emergency stop parsing, dependency graph querying, and state machine transition point marking. Measurements are taken under the maximum range set and busy path, and the upper bias is taken as the upper limit value. Lightweight tracing is used to verify the upper bound during runtime. c) Establish a consistent statistical definition for the three measurable upper bounds: , in, This indicates the upper bound of the term to be estimated. Indicates the segment to which the upper bound belongs. This represents the partial quantile estimate on one side of the multi-condition test in this stage. Indicates quantile level. This represents the environmental and lifespan correction margin; the synchronization error term does not use quantile estimation, but directly takes the supremum of the design upper bound and the online observation upper bound; d) Before going online, complete type testing and on-site commissioning, generate four online values ​​and substitute them into the calculation in step a); During operation, a sliding window is used to recalculate three measurable indicators and compare them with the upper limit values. If any one of them exceeds the upper limit value or the synchronization error exceeds the limit, the fault safety rollback is initiated and the observation data is recorded. e) After the process is completed, record the four online values, the current observation value and window statistics, and write them to the cross-console consistency replication log. This record does not participate in the real-time closed loop and is only used for traceability and reassessment.

4. The emergency stop protection control method for a multi-control console electronic control system as described in claim 1, characterized in that, The communication domain adopts a wireless industrial protocol that supports security extensions and has multicast / broadcast capabilities.

5. The emergency stop protection control method for a multi-control console electronic control system as described in claim 4, characterized in that, The wireless access layer adopts time-division multiple access scheduling, which reserves a fixed minimum emergency time slot quota for emergency stop events, and reallocates the time slots between emergency and non-emergency services according to a preset time slot allocation strategy under the constraint of unchanged total time slots. The time slot allocation strategy guarantees that emergency stop events have a transmission opportunity within a single cycle and provides an upper bound for the worst transmission delay. The definition of the time slot allocation strategy and the derivation of the worst transmission delay upper bound are as follows: f) Using a time-division multiple access (TDMA) configuration with equal intervals between single-cycle lengths and emergency time slots, emergency stop messages are transmitted into the nearest emergency reserved slot. The worst-case transmission delay upper bound for a single transmission is: , in, This represents the upper bound of the worst-case transmission delay for a single transmission scenario. Indicates the length of a single TDMA cycle. This indicates the number of emergency reserved time slots per cycle. This represents the total duration of physical layer and authentication overhead available for a single time slot. This indicates the total duration of the confirmation and protection intervals. Indicates transmission-related quantities, subscript This indicates a single sending scenario; g) Under the condition that the total time slots remain unchanged, non-urgent services can only be allocated idle multiplexing at the beginning of the cycle. The emergency reserved slots that are not occupied by the emergency stop queue in the current cycle are used to generate revocable tokens. Once an emergency stop queue appears in the cycle, the subsequent emergency reserved slots will prioritize scheduling emergency stops. Unused tokens are invalidated and no cross-slot preemption occurs. This rule ensures that the load of non-urgent services does not raise the upper bound obtained in step f). h) When a retransmission is required, the retransmission occupies the nearest urgent reservation slot in the next cycle. Therefore, the upper bound of the worst-case transmission delay within the two-cycle window is: , in, Indicates the upper bound of the worst transmission delay including one retransmission, index This indicates a two-phase window scenario; i) Under the constraint of a fixed total number of time slots per cycle, urgent and non-urgent occupancy satisfy the following: , in, Indicates the number of time slots reserved in emergency situations. This indicates the number of non-urgent available time slots. This indicates the total number of time slots per cycle; The maximum number of concurrent emergency stops is given during project setup. With the upper limit of the two-phase window Configuration meets Then it will definitely be achieved in one phase. The following combined steps (h) can achieve the goal in two phases; subscript Indicates quantities related to urgency. , Indicates single-cycle and two-cycle windows; j) Measured by both air interface packet capture and console timestamp. The schedule is statically provided and fixed during the online audit. Based on the number of safe zones, operating modes, and historical statistics, and with rolling evaluations during operation; substitute the upper bounds obtained in steps f) and h) into the aforementioned... Item used for The overall calculation; the worst-case transmission delay upper bound is used for The settings.

6. The emergency stop protection control method for a multi-control console electronic control system as described in claim 1, characterized in that, The time base alignment uses network clock synchronization, and its synchronization error upper bound does not exceed a preset limit. The participate The settings are configured and online verification and rollback are performed at runtime.

7. The emergency stop protection control method for a multi-control console electronic control system as described in claim 3, characterized in that, The fault-safe rollback includes: In any console If it is not confirmed that the target shutdown range has been entered or if the risk of message replay / tampering is detected, a rollback emergency stop instruction is broadcast and a system-level deactivation is triggered. The backoff trigger threshold is dynamically adjusted based on the delay of the sliding window and packet loss observations, but it does not exceed a fixed upper bound.

8. The emergency stop protection control method for a multi-control console electronic control system as described in claim 3, characterized in that, Leader election and majority consensus replication are used for the ordered writing and cross-console retention of emergency stop event audit logs. The consensus replication does not participate in the real-time closed loop of steps S2 to S4, but is only recorded asynchronously after the safety handling is completed.

9. The emergency stop protection control method for a multi-control console electronic control system as described in claim 1, characterized in that, The target shutdown range is conservatively expanded based on the risk assessment model. The output of the risk assessment model is only used to expand the shutdown range or shorten the handling time limit, and shall not reduce the range obtained in step S3. The risk assessment model inputs include operating modes and environmental sensing, and include rule-based fallback for unavailable / uncertain scenarios.

10. The emergency stop protection control method for a multi-control console electronic control system as described in claim 1, characterized in that, The device layer supports safe de-energization interfaces or controlled shutdown interfaces, and maintains energy isolation until the interface returns an acknowledgment; If a timeout is confirmed, the system will proceed to a global emergency stop via fail-safe rollback.

Citation Information

Patent Citations

  • Industrial scene-oriented data acquisition system and acquisition method thereof

    CN120428658A

  • Multi-stage embedded control equipment state sensing and energy cascade scheduling system

    CN120704215A

  • Motion control system and method, and control platform

    WO2025011616A1