Joint module of mechanical arm

The robotic arm joint module, with its four-layer decoupled design, achieves a deep integration of high-precision adaptive force control and hardware-level safety, solving the problem of balancing performance and safety in existing technologies and improving the system's reliability and adaptability.

CN121893318APending Publication Date: 2026-04-21HANGZHOU RANDWANWEI TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HANGZHOU RANDWANWEI TECHNOLOGY CO LTD
Filing Date
2026-03-11
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing technologies cannot simultaneously achieve high-precision adaptive force control and fully independent hardware-level redundancy safety within the same system. This forces products to make trade-offs between performance and safety, and the module boundaries are blurred, making it impossible to achieve independent development, independent testing, and cross-platform reuse, resulting in poor adaptability.

Method used

The robotic arm joint module adopts a four-layer decoupled design, including an application adaptation layer, a core control layer, a drive execution layer, and an independent safety protection layer. Through standardized interfaces and bus interaction, it achieves physical isolation between the main control link and the safety control link, and constructs a multi-sensor fusion adaptive force control system and an independent hardware-level safety protection system.

Benefits of technology

It achieves a deep integration of high-precision force control response and system safety, ensuring that the safety protection function is executed independently when the main control system fails. This improves the force control accuracy of the system under complex working conditions and the safety under extreme conditions, reduces the development cycle and cost, and improves the system reliability and adaptability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121893318A_ABST
    Figure CN121893318A_ABST
Patent Text Reader

Abstract

The invention provides a joint module of a mechanical arm, which belongs to the technical field of industrial robot control, and comprises an application adaptation layer, a core control layer, a driving execution layer and an independent safety protection layer, which form a dual-redundancy architecture of physical isolation of a main control link and a safety control link; each layer is composed of a plurality of functional modules, the modules on the same layer interact through an internal standardized bus, and the modules on the cross layers perform data interaction through standardized interfaces. The core control layer is integrated with a multi-sensing data processing and state fusion module, a full-closed-loop control module group and a self-adaptive force control optimization module, so that multi-source data fusion and high-precision force control are realized; the independent security protection layer adopts independent power supply, independent operation and independent sampling, and realizes security protection of physical isolation with a main control link through full link state monitoring, hierarchical security processing and redundant backup control. According to the invention, high-precision force control and high-safety redundancy are considered, and the modularization degree, reliability and scene adaptation capability of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial robot control technology, and in particular to a joint module for a robotic arm. Background Technology

[0002] Currently, as industrial robots develop towards high-precision collaboration, intelligence, and modularity, the control system of the robotic arm joint module, as the core execution unit of the robot, directly determines the motion accuracy, load capacity, and safety reliability of the entire machine. In the process of technology implementation, achieving a balance between high-precision force control and high-redundancy safety has become a key challenge for technological development in this field.

[0003] As shown in patent publication number CN113829384 A, this solution proposes a safety control method and system for industrial robots. Its core technology lies in constructing an abnormal braking protection mechanism independent of the main motion control system. Specifically, through real-time comparison of rotational speeds using dual encoders (motor end and output end), when the speed ratio exceeds a preset threshold, it is determined that the transmission system has failed or is out of control, and an independent braking component is immediately triggered for emergency braking.

[0004] The beneficial effect of this solution is that it solves the problem of the robot's inability to stop in time and the resulting safety risks when the main control system fails or is abnormally interfered with. However, this technical solution has the following shortcomings: First, its safety logic can only achieve passive braking protection after a fault occurs, lacking adaptive fault-tolerant control capabilities and unable to intervene or reduce operation in the early stages of a fault; second, its safety judgment relies solely on the rotational speed data of the dual encoders, which is a single dimension and cannot effectively cope with complex working conditions such as sudden load changes, progressive wear of transmission components, and torque control inaccuracies; in addition, although its control system and safety system are logically distinct, they are highly coupled at the physical level and lack standardized module interfaces, resulting in poor system scalability and incompatibility with high-precision force control functions.

[0005] As shown in patent publication number CN 120395867 A, this scheme proposes an adaptive force control method and system for robotic arms based on multi-sensor fusion. Its core technology lies in preprocessing multi-sensor (such as torque, vision, and current) data using a federated learning algorithm, combining this with extended Kalman filtering for state estimation, and then achieving high-precision adaptive torque control through online identification of dynamic parameters and multi-objective optimization algorithms.

[0006] The beneficial effect of this solution is that it solves the problem of decreased force control accuracy caused by model mismatch or load changes, significantly improving the robot's compliance in complex interactive operations. However, this technical solution has the following safety risks: its safety protection logic (such as torque over-limit protection) is highly integrated into the main control software and strongly coupled with the main computing logic. Once the main controller crashes, the software malfunctions, or the operation is abnormal, the entire safety protection function will fail simultaneously, failing to meet the mandatory requirements of high-safety-level application scenarios such as medical surgery and close human-machine collaboration. At the same time, this solution does not achieve sensor-level fault self-diagnosis and isolation; a single sensor failure can easily cause the entire force control system to diverge or even collapse.

[0007] In summary, existing technical solutions all suffer from the inability to simultaneously meet the two core requirements of high-precision adaptive force control and fully independent hardware-level redundancy safety within the same system, forcing products to make trade-offs between performance and safety. Both the safety module and the force control module are strongly coupled with the main control system, resulting in blurred module boundaries. This hinders independent development, testing, and cross-platform reuse, leading to long secondary development cycles and high costs. Furthermore, the lack of module-level fault isolation mechanisms means that a fault in a single module or sensor can easily propagate through coupled logical links to the entire system, causing system crashes or loss of control. Additionally, existing systems often employ centralized control architectures, which are poorly adaptable to multi-degree-of-freedom robotic arm configurations with varying load levels, making it difficult to achieve high-precision multi-joint distributed synchronous control. Summary of the Invention

[0008] This invention aims to address the industry pain point that existing technologies cannot simultaneously achieve high-precision force control and high safety redundancy, and provides a joint module for a robotic arm that achieves high precision, high safety, high reusability, and high scalability in the control system.

[0009] On one hand, the present invention provides a joint module for a robotic arm, including: an application adapter layer for interacting with external devices, performing protocol conversion and instruction encapsulation;

[0010] The core control layer, connected to the application adaptation layer, is used to receive standardized instructions and perform motion planning, closed-loop control, and adaptive force control optimization based on multi-sensor fusion data. The drive execution layer, connected to the core control layer, is used to convert control commands into hardware drive signals and collect raw sensor data. An independent security protection layer is connected to the application adaptation layer, the core control layer, and the driver execution layer respectively. It adopts a power supply, computing, and sampling channel independent of the main control link, and is used to monitor the status of the entire system in real time and execute independent security protection actions in case of anomalies. The application adaptation layer, core control layer, and driver execution layer constitute the main control link, and the independent security protection layer constitutes a security control link that is physically isolated from the main control link. The application adaptation layer, core control layer, driver execution layer, and independent security protection layer are all composed of several functional modules. Modules in the same layer interact through an internal standardized bus, while modules across layers only interact through standardized interfaces, and the layers are completely decoupled.

[0011] According to the present invention, a joint module for a robotic arm includes an application adapter layer comprising: The bus communication adapter module is used to parse and convert various industrial bus protocols, and realize bidirectional conversion between external commands and internal standardized data frames; The secondary development adaptation module is used to encapsulate standardized function call interfaces and provide users with a cross-platform API function library; The unified status reporting module is used to summarize the operating status, feedback data and fault information of all modules in the entire system, and report them in a unified manner after completing standardized encapsulation.

[0012] According to the present invention, a joint module for a robotic arm includes a core control layer comprising: The instruction parsing and trajectory planning module is used to verify the legality of standardized target instructions and complete motion trajectory planning and interpolation. The multi-sensor data processing and state fusion module is used to preprocess and fuse raw data from multiple sensors, output joint state estimates, and perform sensor-level fault self-checking and location. The fully closed-loop control module group includes a position loop control module, a speed loop control module, and a current loop control module that are independent of each other and connected in sequence, and are used to complete multi-loop closed-loop control calculations. The adaptive force control optimization module is connected to the multi-sensor data processing and state fusion module and the full closed-loop control module group respectively. It is used to output torque compensation commands based on the joint full state data, through dynamic model identification and multi-objective optimization. The multi-joint synchronization control module is used to achieve global synchronization of the control cycle of the multi-joint module based on a distributed clock synchronization protocol. The fault-tolerant control scheduling module is connected to the multi-sensor data processing and state fusion module and is used to execute a hierarchical fault-tolerant control strategy based on the fault signal.

[0013] According to the present invention, a joint module for a robotic arm includes a multi-sensor data processing and state fusion module comprising: The data preprocessing and fusion unit is used to preprocess the raw data from each sensor using a federated learning algorithm, and to fuse the preprocessed data using an extended Kalman filter algorithm to output joint state estimates. The sensor fault self-test and location unit is used to compare the data of the two encoders in real time based on the theoretical transmission ratio of the first detection unit at the motor end and the second detection unit at the output end, and combine the sampling data of the torque, current and temperature sensors to achieve accurate location of the sensor-level fault source.

[0014] According to the joint module of a robotic arm provided by the present invention, the adaptive force control optimization module is a pluggable module, and its built-in multi-objective optimization function is:

[0015] in, For the purpose of force, For practical strength, For torque, For speed smoothness, , , This is a weighting factor that can be adaptively adjusted according to the task scenario.

[0016] According to the present invention, a joint module for a robotic arm includes a drive execution layer comprising: The motor drive control module is used to receive modulation signals from the core control layer to drive the motor, and to prioritize the execution of emergency stop control signals from the independent safety protection layer. The sensor signal acquisition module is used to synchronously acquire all sensor signals and generate digital raw sampling data; the sensor signal acquisition module has two independent sampling channels, which are respectively connected to the core control layer and the independent security protection layer; The power failure braking control module is used to implement the logic control of the power failure braking component of the joint module, and to receive dual redundant control commands from the core control layer and the independent safety protection layer, and to prioritize the execution of the braking command from the independent safety protection layer. The hardware status monitoring module is used to collect hardware status data in real time and send it to the unified status reporting module and the independent security protection layer.

[0017] According to the present invention, a joint module for a robotic arm includes an independent safety protection layer comprising: The end-to-end status monitoring module collects raw sensor data and heartbeat signals from all modules in real time through an independent sampling channel to identify abnormal states of the entire system. A tiered security processing module, connected to the end-to-end status monitoring module, is used to match a preset security policy based on the anomaly type and level, and output security instructions of the corresponding level; the security instructions have a higher priority than all instructions of the main control link. The redundant backup control module is used to monitor the operating status of the core control layer main module in real time, and seamlessly take over system control and execute a safe shutdown procedure when the main module fails.

[0018] According to the joint module of a robotic arm provided by the present invention, the hierarchical safety processing module has a preset safety strategy including four levels: The early warning level is used to send early warning signals without interfering with the normal operation of the system. Derating stage, used to send derating commands to limit motor output; The stop level is used to send a smooth stop command to the trajectory planning module and simultaneously trigger braking; The emergency stop stage is used to send emergency stop commands directly to the motor drive control module and the power failure braking control module via hardware I / O, cutting off the power supply to the motor and immediately triggering the brake.

[0019] According to the present invention, a joint module for a robotic arm is provided, wherein the system supports distributed cascading collaboration of multiple joint modules; The control system for each joint module is an independent modular system, which is daisy-chained through an industrial bus. The multi-joint synchronization control module of all modules achieves global clock synchronization through the bus, so that the control cycle and sampling cycle of all modules are aligned and the synchronization error is ≤1μs. When a single module fails, it is isolated independently, without affecting the normal operation of other modules.

[0020] A safety control method based on the joint module of the aforementioned robotic arm includes the following data flow: The downlink main data stream is transmitted unidirectionally along the application adaptation layer, core control layer to drive execution layer, and is used to convert external commands into motor drive signals. The feedback uplink data stream is transmitted unidirectionally along the drive execution layer, core control layer to application adaptation layer, and is used to summarize and report sensor data. An independent security emergency data stream operates in a closed loop within an independent security protection layer and is directly output to the driver execution layer. This allows for the execution of hardware-level security protection actions without going through the core control layer when an anomaly is detected.

[0021] Compared with the prior art, the beneficial effects of this application are as follows: By constructing a dual-redundancy architecture with physical isolation between the main control link and the safety control link, and a four-layer decoupling design of the application adaptation layer, core control layer, drive execution layer, and independent safety protection layer, this invention deeply integrates a multi-sensor fusion adaptive force control system with an independent hardware-level safety protection system in terms of control performance and safety. It achieves high-precision force control response through multi-source data fusion and dynamic parameter identification, while ensuring independent execution of safety protection functions even in the event of a main control system failure through an independent power supply, independent computation, and independent sampling safety control link. This effectively balances force control accuracy under complex operating conditions with system safety under extreme circumstances. Secondly, regarding system reliability and maintainability, this invention constructs an integrated perception system of dual-encoder redundant detection and multi-sensor fusion, achieving accurate estimation of the entire joint state and precise location and redundancy switching of sensor-level faults. Simultaneously, through the collaborative design of hierarchical safety strategies and fault-tolerant control, it achieves full-process protection from anomaly warning to emergency braking and module-level fault isolation, significantly improving the system's continuous operation capability and overall reliability in the face of a single fault. Secondly, regarding development efficiency and scenario adaptability, the entire system adopts a modular design and establishes a unified standardized interface specification. Each functional module has clear functional boundaries and fixed interaction interfaces, allowing for independent debugging, replacement, customization, and reuse. This significantly reduces the system's development cycle and the threshold for secondary development, and enables rapid adaptation to robotic arm application scenarios with different loads and degrees of freedom. Finally, in terms of multi-machine collaboration and scalability, each joint module is a modular system with complete autonomous control capabilities and independent safety protection capabilities. It supports daisy-chain cascading of multiple modules and high-precision global clock synchronization, effectively reducing the computational pressure on the host computer and the burden of bus communication while achieving flexible and scalable distributed collaborative control.

[0022] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.

[0023] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0024] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a schematic diagram of the logic framework of the robotic arm shutdown module provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of the joint module safety control data flow framework provided in an embodiment of the present invention. Detailed Implementation

[0025] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0026] Example 1 This embodiment provides a joint module control system adapted to a 6-axis medical collaborative robotic arm with a rated output torque of 50 N·m. Medical scenarios have extremely high requirements for force control precision and safety redundancy; this embodiment aims to demonstrate the specific implementation of the invention in scenarios with high precision and high safety requirements.

[0027] The control system in this embodiment runs on an embedded control board inside the joint module. It adopts a three-core heterogeneous dual-redundancy hardware architecture to achieve physical isolation between the main control link and the safety control link. The specific hardware configuration is as follows: The main control chip is an STM32H743IIT6 with a main frequency of 400MHz, which is responsible for running all software modules of the application adaptation layer and the core control layer.

[0028] The drive coprocessor chip uses an XC7A35T FPGA, which is responsible for running the high-frequency logic of the sensor signal acquisition module and motor drive control module of the drive execution layer, and realizing a current loop sampling and control frequency of 20kHz.

[0029] The security coprocessor chip selected is the STM32G031K8T6. This chip employs an independent power supply circuit, an independent crystal clock source, and an independent ADC sampling channel. It only interacts with the main control chip through the SPI bus, achieving complete physical isolation. Even if the main control chip crashes or its power fails, the security coprocessor chip and its peripheral circuits can still operate independently, thus forming a security control link that is physically isolated from the main control link.

[0030] The system control cycle is set to 1ms, the current loop control frequency is 20kHz, the position / speed loop control frequency is 5kHz, the status monitoring and safety operation frequency is 1kHz, the bus communication adopts the EtherCAT protocol, the synchronization cycle is 1ms, and the measured multi-joint synchronization error is ≤1μs.

[0031] The system adopts a top-down four-layer decoupled architecture, consisting of an application adaptation layer, a core control layer, a driver execution layer, and an independent security protection layer. Each layer interacts with the other through standardized interfaces, and the layers are completely decoupled. Modules in the same layer interact through an internal standardized bus. All modules follow a unified standardized interface specification, including standardized data frames in a unified format, standardized function call interfaces, a clock synchronization interface with 1μs precision, and a hardware I / O + bus dual-redundant security instruction interface.

[0032] The application adaptation layer serves as the interaction point between the system and external devices, and includes three functional modules: The bus communication adapter module runs the EtherCAT slave protocol stack on the STM32H7 and has a built-in parsing engine for CANopen and Profinet protocols. It can automatically identify and adapt to different industrial bus protocols based on bus signals. The module's input is the raw command frame sent by the host computer via the industrial bus, and the output is a standardized target command frame in a unified format within the system. This module also supports daisy-chain cascading of multi-joint modules and is compatible with the IEEE 1588 PTP precision clock synchronization protocol, ensuring a multi-joint synchronization error ≤1μs.

[0033] The secondary development adaptation module encapsulates standardized function call interfaces, providing users with a cross-platform API function library, including `move_joint()`, `set_torque()`, `get_state()`, and `safety_reset()`. Users can develop custom functions by calling these APIs without needing to concern themselves with the underlying control logic. This module supports individual calls to any functional module.

[0034] The unified status reporting module aggregates the operating status, feedback data, fault information, and abnormal and safety action signals from all modules in the entire system via polling. After standardized encapsulation, it generates a unified format status reporting frame, which is then uploaded to the host computer via the bus communication adapter module. This module supports individual reporting of module-level status and can accurately locate faulty modules and fault sources.

[0035] The core control layer is the computational core of the entire control system, containing six completely independent functional modules, each with clear functional boundaries and fixed input / output interfaces.

[0036] The instruction parsing and trajectory planning module receives standardized target instruction frames from the application adaptation layer and performs CRC checks and instruction validity verification. It incorporates S-curve acceleration / deceleration planning, linear interpolation, and circular interpolation algorithms to generate discrete target position / velocity / torque sequences for each control cycle. The module supports independent configuration of planning parameters and can be replaced with custom planning algorithms via a standardized interface.

[0037] The multi-sensor data processing and state fusion module consists of two sub-units: The data preprocessing and fusion unit receives full-dimensional raw sampled data from the sensor signal acquisition module of the drive execution layer, including data from the 17-bit incremental encoder at the motor end (first detection unit), the 23-bit absolute multi-turn encoder at the output end (second detection unit), torque sensor, current sensor, temperature sensor, vibration sensor, and collision sensor. This unit first uses a federated learning algorithm to preprocess the raw data from each sensor by filtering, denoising, feature extraction, and normalization. Then, it fuses the preprocessed multi-source data using an extended Kalman filter algorithm to output accurate joint state estimates (position, velocity, current, torque, temperature, and vibration). The extended Kalman filter algorithm includes state prediction equations, covariance prediction equations, and measurement update equations, achieving real-time full-state updates at a frequency of 1 kHz.

[0038] The sensor fault self-diagnosis and location unit is based on the theoretical transmission ratio of the dual encoders (in this embodiment, the harmonic reducer reduction ratio is 100:1). A preset multiple range is set to ±5% of the theoretical value (i.e., 95:1 to 105:1). It compares the speed / position data of the motor-end encoder and the output-end encoder in real time, and combines this with sampling data from torque, current, and temperature sensors to achieve precise location of the sensor-level fault source. The specific judgment logic is as follows: If the data from the first detection unit is within the preset range, but the data from the second detection unit exceeds the preset range, then the second detection unit or the deceleration mechanism is determined to be faulty. If the data from the first detection unit exceeds the preset range, while the data from the second detection unit is within the preset range, then the first detection unit is determined to be faulty. If the data from both detection units exceed the preset range, then the drive mechanism or the deceleration mechanism is determined to be faulty. Simultaneously, by combining data from other sensors, fault diagnosis and location of torque, temperature, and vibration sensors can be achieved.

[0039] The filtered and fused joint full-state data, sensor fault signals and fault location information output by this module are sent to the full closed-loop control module group, the adaptive force control optimization module, the independent safety protection layer and the unified status reporting module, respectively.

[0040] The fully closed-loop control module group breaks down the multi-loop control into three completely independent closed-loop control modules: The position loop control module takes the target position from the trajectory planning module and the actual position data from the output of the multi-sensor data processing module as inputs, and outputs the target speed command. It has a built-in PID control algorithm and supports replacement with custom algorithms such as adaptive robust control and sliding mode control.

[0041] The speed loop control module takes the target speed output from the position loop and the actual motor speed data from the multi-sensor data processing module as inputs, and outputs the target torque command; it has a built-in PID+feedforward control algorithm and supports custom algorithm replacement.

[0042] The current loop control module takes the target torque output from the speed loop and the actual phase current data of the motor from the multi-sensor data processing module as inputs, and outputs an SVPWM modulation signal. Its core function is to perform field-oriented FOC vector control calculations to achieve precise control of the motor torque, with a sampling frequency ≥20kHz.

[0043] The three modules interact only through standardized data frames, and the rings are completely decoupled. The control algorithm of any one module can be replaced without affecting the operation of other modules.

[0044] The adaptive force control optimization module is a standardized, pluggable module that can be enabled, disabled, or replaced as needed. Based on the fused joint full-state data, the module utilizes a robotic arm dynamics model built upon the Lagrange equations to construct a multi-objective optimization function that integrates force control error, energy consumption, and speed smoothness. This multi-objective optimization function is specifically as follows:

[0045] in, For the purpose of force, For practical strength, For torque, For speed smoothness, , , To provide a weighting factor that can be adaptively adjusted according to the task scenario, the module uses recursive least squares to identify dynamic parameters in real time, combines it with particle swarm optimization to dynamically optimize the weighting factor, and outputs the optimized torque compensation command to the current loop control module to achieve adaptive force control optimization. In this embodiment, to meet the high-precision force control requirements of medical scenarios, The default setting for force control error weight is 0.7, which makes the force control accuracy ±0.3N.

[0046] The multi-joint synchronization control module, based on a distributed clock synchronization protocol, receives the global synchronization clock signal from the bus communication adapter module and the synchronization status data from the cascaded joint modules, generating synchronization trigger signals and synchronization status feedback signals for the local module. This module is completely decoupled from the core control logic and can be adapted to cascaded configurations of robotic arms with any degree of freedom from 3 to 7 axes.

[0047] The fault-tolerant control and scheduling module receives fault signals and fault location information from the multi-sensor data processing and state fusion module, and executes module-level fault-tolerant control strategies. It has three preset fault-tolerant strategies: redundancy switching (automatically switching to data from another encoder if one encoder fails), derating operation (limiting output torque to 50% if the temperature is too high), and safe shutdown (triggering a safe shutdown command if both encoders experience simultaneous data anomalies). This strategy enables the system to operate without derating when non-core sensors fail, through redundant data fusion, avoiding system shutdown caused by a single sensor failure.

[0048] The driver execution layer is the interaction layer between the control system and the hardware. It contains four completely independent functional modules, and the hardware adaptation logic is completely decoupled from the upper-level control logic.

[0049] The motor drive control module, running within the FPGA, receives SVPWM modulation signals from the core control layer's current loop control module to drive the intelligent power module, achieving precise servo motor drive. The module includes a hardware emergency stop input, directly connected to the GPIO of the safety coprocessor chip. Upon receiving an emergency stop control signal from the independent safety protection layer, it unconditionally blocks the PWM output and prioritizes the execution of the hardware emergency stop command.

[0050] The sensor signal acquisition module, also running on the FPGA, synchronously acquires signals from all sensors, including the original analog / digital signals from the motor encoder, output encoder, torque sensor, current sensor, temperature sensor, vibration sensor, and collision sensor. After decoding and A / D conversion, it generates digitized raw sampled data. This module has two independent sampling channels: one transmits data via a high-speed parallel bus to the multi-sensor data processing and state fusion module (main control link), and the other transmits directly via the SPI bus to an independent security layer, achieving sampling redundancy. The module supports multi-channel synchronous sampling, with the sampling frequency fully synchronized with the control cycle. Adapting to different types and ranges of sensors only requires modifying the configuration parameters of this module, without modifying the upper-level modules.

[0051] The power-off braking control module implements the logic control of the joint module's power-off braking assembly, completing normal braking, stop braking, and emergency braking. The braking assembly adopts a normally closed power-off braking structure; when the coil is energized, the brake pads separate; when power is de-energized, the permanent magnet attracts the brake pads to achieve braking. This module receives two independent control signals: one is a stop status signal from the core control layer (normal braking), and the other is a braking command directly from the independent safety protection layer (emergency braking). The power supply circuit of the braking assembly is connected to the power supply through a normally closed relay, which is controlled by two signal lines, and hardware logic gates ensure that the commands from the independent safety protection layer have the highest priority. Even if the main control link fails completely, the emergency braking command can still be executed independently through the independent safety protection layer.

[0052] The hardware status monitoring module collects real-time hardware status data from the driver board, motor, and power module, including voltage, current, temperature, and insulation status. It uses threshold comparisons to provide early warnings of hardware failures. Output data is sent to both the unified status reporting module and an independent safety protection layer.

[0053] The independent security protection layer is an independent security protection unit of the system. It adopts a redundant design with independent power supply, independent operation and independent sampling. The security logic is completely physically isolated from the main control link and contains three completely independent functional modules.

[0054] The end-to-end status monitoring module runs on the STM32G031 security coprocessor chip. It receives independent sampling data from the sensor signal acquisition module in real time via an independent sampling channel (SPI interface), and simultaneously monitors signals from the main control chip, FPGA, and all functional modules through redundant heartbeat lines. This module does not rely on any computational results from the main control link, incorporates dual-encoder anomaly detection logic, and extends its capabilities to identify all types of anomalies, including torque overload, overheating, collision, voltage anomalies, communication interruptions, and module heartbeat loss. It monitors 16 core fault points in real time and outputs anomaly type signals, anomaly level signals, and fault location information.

[0055] The tiered security handling module matches the anomaly type and level with a preset security policy, outputting corresponding security commands. These security commands take precedence over all commands in the main control link. A four-level preset security policy is provided. Warning level: When the temperature is detected to be high but not exceeding the limit, a warning signal is sent to the unified status reporting module and reported to the host computer without interfering with the normal operation of the system.

[0056] Derating level: When continuous overload is detected, a derating command frame is sent to the full closed-loop control module group of the core control layer via SPI to forcibly limit the motor output torque and speed, and at the same time send a warning signal.

[0057] Stopping level: When a slight loss of synchronization is detected in the dual encoder data, on the one hand, a smooth stop command is sent to the command parsing and trajectory planning module via the bus to execute the normal stop process, and on the other hand, a braking command is sent to the power failure braking control module via independent IO to trigger the holding brake after the stop.

[0058] Emergency Stop Level: When a collision sensor trigger is detected or the main control chip heartbeat is completely lost, a high level is sent directly to the emergency stop terminal of the motor drive control module and the relay control terminal of the power failure braking control module through two independent hardware IO lines, respectively, to cut off the motor power supply and immediately trigger the brake. The entire process does not pass through any computing module of the main control link, realizing a hardware emergency stop with a microsecond response.

[0059] The redundant backup control module operates independently of the main control module and incorporates simplified safety control logic. It monitors the heartbeat signal of the core control layer main module in real time. When a failure of the main control module or loss of heartbeat is detected (switching time ≤ 1ms), it seamlessly takes over system control, outputs a set of pre-stored emergency stop trajectory instructions to the motor drive module, and simultaneously sends an emergency stop command to the power failure braking control module to execute the safety stop procedure, ensuring system safety and complying with ISO 13849-1 PLd functional safety level.

[0060] This system is designed with three mutually isolated, time-controlled, and fixed-path core data streams. The specific transmission logic is as follows: The command downlink main data stream is initiated by the host computer sending target commands via the industrial bus. These commands are then parsed and converted into internal standardized command frames by the bus communication adapter module and sent to the command parsing and trajectory planning module. This module, in conjunction with the synchronization trigger signal from the multi-joint synchronous control module, generates a discrete target sequence, which is then sent to the full closed-loop control module group and the adaptive force control optimization module. The adaptive force control optimization module outputs torque compensation commands to the current loop control module. The full closed-loop control module group sequentially completes position loop, speed loop, and current loop calculations, outputting SVPWM modulation signals to the motor drive control module to drive the motor. This entire path follows the principle of top-down, layer-by-layer transmission, and controllable timing.

[0061] The feedback uplink data stream is processed by the sensor signal acquisition module, which synchronously acquires raw signals through dual redundant channels in each control cycle. One channel sends the data to the multi-sensor data processing and status fusion module, while the other sends it directly to the independent security protection layer. After preprocessing, fusing, and fault self-checking, the multi-sensor data processing and status fusion module sends the status data to the full closed-loop control module group, the adaptive force control optimization module, the fault-tolerant control scheduling module, and the unified status reporting module. The operating status of the hardware status monitoring module, the independent security protection layer, and each module is also synchronously sent to the unified status reporting module. This module aggregates all data, standardizes and encapsulates it, and then reports it to the host computer via the bus communication adapter module. This path follows the principles of bottom-up, layer-by-layer aggregation, and synchronous acquisition.

[0062] An independent safety emergency data stream is implemented. The end-to-end status monitoring module collects raw sensor data, module heartbeat signals, and hardware status data in real time through an independent sampling channel. It identifies the type and level of anomalies and generates anomaly signals, which are then sent to the tiered safety processing module. The tiered safety processing module matches the safety policy and outputs safety commands. Warning / degradation commands are sent via the bus, shutdown commands are sent via both the bus and hardware I / O, and emergency stop commands are sent directly via hardware I / O to the motor drive control module and the power failure braking control module, cutting off the motor power supply and immediately triggering the brake. Simultaneously, a redundant backup control module monitors the main module's status in real time and seamlessly takes over and executes a safe shutdown in the event of a main module failure. This data stream does not pass through the core computing module of the main control link and is completely physically isolated.

[0063] This system supports distributed cascading collaboration of multiple joint modules. Each joint module's control system is a complete, independent, modular system with fully autonomous control capabilities and independent safety protection. Multiple joint modules are daisy-chained via an industrial bus. The first module's bus communication adapter module connects to the host computer, and subsequent modules are cascaded sequentially. All modules' multi-joint synchronization control modules achieve global clock synchronization via the bus, ensuring complete alignment of control cycles and sampling cycles with a synchronization error ≤1μs. The host computer only needs to send target commands for multi-joint collaborative motion via the bus. Each module independently completes local joint trajectory planning, closed-loop control, force control optimization, and drive execution, without requiring host computer involvement in low-level calculations. Each module's independent safety protection layer operates independently; an anomaly in one module will not affect the normal operation of other modules, enabling fault isolation and safety protection for single joints.

[0064] Example 2 This embodiment aims to demonstrate the reusability and scalability of the modular system of the present invention. The difference from Embodiment 1 is that the joint module control system adapted to a 20kg load industrial robotic arm requires only the following modifications: Hardware parameters were adjusted, including modifying the current loop PID parameters of the motor drive control module in the drive execution layer to adapt to higher power servo motors; and modifying the encoder resolution configuration parameters of the sensor signal acquisition module.

[0065] Algorithm parameter adjustments were made, including adjusting the weighting factors of the multi-objective optimization function in the adaptive force control optimization module, and adjusting the energy consumption weight. The value was increased from 0.2 to 0.5 to meet the higher energy efficiency requirements of industrial scenarios.

[0066] Module reuse is achieved through the complete reuse of code, interfaces, and logic across all modules in the application adaptation layer, core control layer (excluding parameter configuration), and independent security protection layer, requiring no modification. This fully demonstrates the advantages of the modular design of this invention.

[0067] Example 3 This invention does not limit the specific control algorithm. For example, the position loop control module in the full closed-loop control module group can replace the built-in PID algorithm with an adaptive robust control algorithm or a sliding mode control algorithm. As long as the input interface (target position, feedback position) and output interface (target speed) of the module remain unchanged, it can be seamlessly integrated into the system without affecting other modules or the entire hierarchical architecture.

[0068] The bus communication adapter module can be adapted to other industrial bus protocols such as Modbus TCP, EtherNet / IP, and Powerlink by changing the protocol stack. The modification is limited to the internal workings of this module and does not change the standardized data frame format within the system.

[0069] The core of this invention is a modular, layered architecture, rather than a specific chip model. All software modules are written in standard C language and can be ported to any embedded platform such as DSP, ARM Cortex-A series processors, and x86 industrial PCs, requiring only the hardware abstraction layer of the driver execution layer to be rewritten.

[0070] For simple applications, the adaptive force control optimization module or the fault-tolerant control scheduling module can be removed, and the system can still operate normally in position / velocity mode. For advanced applications, a vibration suppression module or a drag-and-drop teaching module can be added. As long as the added module follows the standardized interface specifications of this invention (unified data frame format, standard API), it can be used plug and play.

[0071] The power failure braking control module is compatible with different types of braking components such as electromagnetic brakes and hydraulic brakes. Only the drive parameters of this module need to be modified, without changing the dual-redundant braking control logic and independent safety protection architecture.

[0072] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A joint module for a robotic arm, characterized in that, include: The application adaptation layer is used to interact with external devices, performing protocol conversion and instruction encapsulation. The core control layer, connected to the application adaptation layer, is used to receive standardized instructions and perform motion planning, closed-loop control, and adaptive force control optimization based on multi-sensor fusion data. The drive execution layer, connected to the core control layer, is used to convert control commands into hardware drive signals and collect raw sensor data. An independent security protection layer is connected to the application adaptation layer, the core control layer, and the driver execution layer respectively. It adopts a power supply, computing, and sampling channel independent of the main control link, and is used to monitor the status of the entire system in real time and execute independent security protection actions in case of anomalies. The application adaptation layer, core control layer, and driver execution layer constitute the main control link, and the independent security protection layer constitutes a security control link that is physically isolated from the main control link. The application adaptation layer, core control layer, driver execution layer, and independent security protection layer are all composed of several functional modules. Modules in the same layer interact through an internal standardized bus, while modules across layers only interact through standardized interfaces, and the layers are completely decoupled.

2. The joint module of a robotic arm according to claim 1, characterized in that, The application adaptation layer includes: The bus communication adapter module is used to parse and convert various industrial bus protocols, and realize bidirectional conversion between external commands and internal standardized data frames; The secondary development adaptation module is used to encapsulate standardized function call interfaces and provide users with a cross-platform API function library; The unified status reporting module is used to summarize the operating status, feedback data and fault information of all modules in the entire system, and report them in a unified manner after completing standardized encapsulation.

3. The joint module of a robotic arm according to claim 1, characterized in that, The core control layer includes: The instruction parsing and trajectory planning module is used to verify the legality of standardized target instructions and complete motion trajectory planning and interpolation. The multi-sensor data processing and state fusion module is used to preprocess and fuse raw data from multiple sensors, output joint state estimates, and perform sensor-level fault self-checking and location. The fully closed-loop control module group includes a position loop control module, a speed loop control module, and a current loop control module that are independent of each other and connected in sequence, and are used to complete multi-loop closed-loop control calculations. The adaptive force control optimization module is connected to the multi-sensor data processing and state fusion module and the full closed-loop control module group respectively. It is used to output torque compensation commands based on the joint full state data, through dynamic model identification and multi-objective optimization. The multi-joint synchronization control module is used to achieve global synchronization of the control cycle of the multi-joint module based on a distributed clock synchronization protocol. The fault-tolerant control scheduling module is connected to the multi-sensor data processing and state fusion module and is used to execute a hierarchical fault-tolerant control strategy based on the fault signal.

4. The joint module of a robotic arm according to claim 3, characterized in that, The multi-sensor data processing and state fusion module includes: The data preprocessing and fusion unit is used to preprocess the raw data from each sensor using a federated learning algorithm, and to fuse the preprocessed data using an extended Kalman filter algorithm to output joint state estimates. The sensor fault self-test and location unit is used to compare the data of the two encoders in real time based on the theoretical transmission ratio of the first detection unit at the motor end and the second detection unit at the output end, and combine the sampling data of the torque, current and temperature sensors to achieve accurate location of the sensor-level fault source.

5. The joint module of a robotic arm according to claim 3, characterized in that, The adaptive force control optimization module is a pluggable module, and its built-in multi-objective optimization function is: in, For the purpose of force, For practical strength, For torque, For speed smoothness, , , This is a weighting factor that can be adaptively adjusted according to the task scenario.

6. The joint module of a robotic arm according to claim 1, characterized in that, The driver execution layer includes: The motor drive control module is used to receive modulation signals from the core control layer to drive the motor, and to prioritize the execution of emergency stop control signals from the independent safety protection layer. The sensor signal acquisition module is used to synchronously acquire all sensor signals and generate digital raw sampling data; the sensor signal acquisition module has two independent sampling channels, which are respectively connected to the core control layer and the independent security protection layer; The power failure braking control module is used to implement the logic control of the power failure braking component of the joint module, and to receive dual redundant control commands from the core control layer and the independent safety protection layer, and to prioritize the execution of the braking command from the independent safety protection layer. The hardware status monitoring module is used to collect hardware status data in real time and send it to the unified status reporting module and the independent security protection layer.

7. The joint module of a robotic arm according to claim 1, characterized in that, The independent security protection layer includes: The end-to-end status monitoring module collects raw sensor data and heartbeat signals from all modules in real time through an independent sampling channel to identify abnormal states of the entire system. A tiered security processing module, connected to the end-to-end status monitoring module, is used to match a preset security policy based on the anomaly type and level, and output security instructions of the corresponding level; the security instructions have a higher priority than all instructions of the main control link. The redundant backup control module is used to monitor the operating status of the core control layer main module in real time, and seamlessly take over system control and execute a safe shutdown procedure when the main module fails.

8. The joint module of a robotic arm according to claim 7, characterized in that, The hierarchical security processing module has four preset security policies: The early warning level is used to send early warning signals without interfering with the normal operation of the system. Derating stage, used to send derating commands to limit motor output; The stop level is used to send a smooth stop command to the trajectory planning module and simultaneously trigger braking; The emergency stop stage is used to send emergency stop commands directly to the motor drive control module and the power failure braking control module via hardware I / O, cutting off the power supply to the motor and immediately triggering the brake.

9. The joint module of a robotic arm according to claim 1, characterized in that, The system supports distributed cascading collaboration of multi-joint modules; The control system for each joint module is an independent modular system, which is daisy-chained through an industrial bus. The multi-joint synchronization control module of all modules achieves global clock synchronization through the bus, so that the control cycle and sampling cycle of all modules are aligned and the synchronization error is ≤1μs. When a single module fails, it is isolated independently, without affecting the normal operation of other modules.

10. A safety control method for a joint module of a robotic arm based on any one of claims 1 to 9, characterized in that, Includes the following data streams: The downlink main data stream is transmitted unidirectionally along the application adaptation layer, core control layer to drive execution layer, and is used to convert external commands into motor drive signals. The feedback uplink data stream is transmitted unidirectionally along the drive execution layer, core control layer to application adaptation layer, and is used to summarize and report sensor data. An independent security emergency data stream operates in a closed loop within an independent security protection layer and is directly output to the driver execution layer. This allows for the execution of hardware-level security protection actions without going through the core control layer when an anomaly is detected.

Citation Information

Patent Citations

  • Mechanical arm joint module and mechanical arm thereof

    CN113829384A

  • Multi-sensor fusion mechanical arm joint module force control system and debugging method

    CN120395867A