Robot control device and control method
By parallel processing of kernels 311 and 312 in the robot control device, the problem of excessively long boot time was solved, and a fast and safe boot process was achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SEIKO EPSON CORP
- Filing Date
- 2025-10-27
- Publication Date
- 2026-04-28
AI Technical Summary
In existing technologies, the startup process of robot control devices requires signature verification one by one, resulting in excessively long startup times and reduced efficiency.
The kernels 311 and 312 work together to execute the boot program and verify the signature repeatedly in time. Kernel 311 executes the boot program and kernel 312 performs the signature verification, thus achieving parallel processing.
By using parallel processing, the startup time of the robot control device is significantly shortened, startup efficiency is improved, and system safety is ensured.
Smart Images

Figure CN121928533A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to robot control devices and control methods. Background Technology
[0002] In recent years, due to soaring labor costs and a shortage of skilled workers, factories have automated tasks that were previously performed manually through various robots and their peripheral devices. The operation of the robot is controlled by a robot control unit. This control unit has a storage section containing various programs and a processing section that executes the programs stored in the storage section. These programs include startup programs for initiating the robot control unit and driver programs for driving the robot.
[0003] In such a robot control device, from the viewpoint of improving security, it is preferable to verify that various programs are in a suitable state when the robot control device is started, and in particular, to verify that they have not been tampered with due to external attacks. As a method, one known approach is to pre-sign and store various programs, and then check the suitability of the programs, including whether they have been tampered with, by verifying the signatures of each program at startup.
[0004] For example, in the information processing apparatus described in Patent Document 1, each program is subjected to the following action: the stored program is individually signed and verified; if the signature verification is successful, the program is started. This ensures security by allowing each program to be started only after confirming that it has not been tampered with.
[0005] Patent Document 1: Japanese Patent Application Publication No. 2019-175000
[0006] However, the method described in Patent Document 1 involves sequentially verifying and executing the signature of a program, and performing this process on each program one by one. Therefore, time is consumed before each program can be executed, especially the startup of the robot control device, which requires a considerable amount of time. Summary of the Invention
[0007] The robot control device of the present invention is a robot control device for controlling the operation of a robot, comprising: a first processing unit that executes a control program including starting a startup program of the robot control device; and a second processing unit that performs signature verification on the startup program, wherein the robot control device repeatedly performs signature verification of the startup program by the second processing unit and execution of the startup program being signed and verified by the second processing unit by the first processing unit in time.
[0008] The control method of the present invention is a control method for a robot control device for controlling the operation of a robot, comprising: an execution step in which a first processing unit executes a control program including a startup program for starting the robot control device; and a signature verification step in which a second processing unit, different from the first processing unit, performs signature verification on the startup program, wherein the execution step and the signature verification step are performed repeatedly in time. Attached Figure Description
[0009] Figure 1 This is a diagram showing the overall configuration of a robot system equipped with the robot control device according to the first embodiment of the present invention.
[0010] Figure 2 yes Figure 1 The diagram shows a block diagram of the robot system.
[0011] Figure 3 yes Figure 1 The diagram shows the hardware configuration of the robot control device.
[0012] Figure 4 It is shown Figure 1 A diagram showing the control program stored in the storage section of the robot control device.
[0013] Figure 5 yes Figure 1 The diagram shows the timing of the robot control device executing the startup procedure.
[0014] Figure 6 yes Figure 1 The diagram shows the timing of the robot control device executing the action program.
[0015] Figure 7 It is used for explanation Figure 1 The flowchart shows the control method (signature verification successful) performed by the robot control device.
[0016] Figure 8 It is used for explanation Figure 1 The flowchart shows the control method (signature verification failed) performed by the robot control device.
[0017] Figure 9 This is a hardware configuration diagram of the robot control device according to the second embodiment of the present invention.
[0018] Explanation of reference numerals in the attached figures
[0019] 1: Robot; 3: Robot control unit; 4: Teaching pendant; 10: Robotic arm; 11: Base; 12: First arm; 13: Second arm; 14: Third arm; 15: Fourth arm; 16: Fifth arm; 17: Sixth arm; 20: End effector; 30: Storage unit; 31: CPU; 32: ROM; 33: RAM; 34: IF control unit; 35: LED; 36: Bus; 37: Selection unit; 39: Housing; 41: Control unit; 42: Storage unit; 43: Communication unit; 44: Input unit; 100: Robot system; 171: Joint; 172: Joint; 173: Joint; 174: Joint; 175: Joint; 176: Joint; 301: Boot program; 302: BIOS; 303: Loader; 304: Core; 311: Kernel; 312: Internal Core; D1: Motor driver; D2: Motor driver; D3: Motor driver; D4: Motor driver; D5: Motor driver; D6: Motor driver; E1: Encoder; E2: Encoder; E3: Encoder; E4: Encoder; E5: Encoder; E6: Encoder; M1: Motor; M2: Motor; M3: Motor; M4: Motor; M5: Motor; M6: Motor; S11: Step; S12: Step; S13: Step; S14: Step; S15: Step; S16: Step; S17: Step; S21: Step; S22: Step; S23: Step; S24: Step; S25: Step; S26: Step; t1: Time; t2: Time; t3: Time; t4: Time; t5: Time; t6: Time; t7: Time; TCP: Control point. Detailed Implementation
[0020] <First Implementation>
[0021] Figure 1 This is a diagram showing the overall configuration of a robot system equipped with the robot control device according to the first embodiment of the present invention. Figure 2 yes Figure 1 The diagram shows a block diagram of the robot system. Figure 3 yes Figure 1 The diagram shows the hardware configuration of the robot control device. Figure 4 It is shown Figure 1 A diagram showing the control program stored in the storage section of the robot control device. Figure 5 yes Figure 1 The diagram shows the timing of the robot control device executing the startup procedure. Figure 6 yes Figure 1 The diagram shows the timing of the robot control device executing the action program. Figure 7 It is used for explanation Figure 1 The flowchart shows the control method (signature verification successful) performed by the robot control device. Figure 8 It is used for explanation Figure 1 The flowchart shows the control method (signature verification failed) performed by the robot control device.
[0022] The robot control device and control method of the present invention will now be described in detail based on the preferred embodiments shown in the accompanying drawings. It should be noted that, for ease of explanation, the robotic arm will be referred to as... Figure 1 The side of the base 11 is also called the "base end", and its opposite side, namely the end effector 20 side, is also called the "front end".
[0023] like Figure 1 As shown, the robot system 100 includes a robot 1, a robot control device 3 for controlling the operation of the robot 1, and a teaching device 4.
[0024] First, let's explain robot 1.
[0025] Figure 1 The robot 1 shown in this embodiment is a single-arm, six-axis vertical joint robot, having a base 11 and a robotic arm 10. Furthermore, an end effector 20 can be mounted on the front end of the robotic arm 10. The end effector 20 may or may not be a component of the robot 1.
[0026] It should be noted that robot 1 is not limited to the configuration shown in the figure. For example, it could also be a dual-arm multi-joint robot. In addition, robot 1 could also be a horizontal multi-joint robot.
[0027] Base 11 is from Figure 1 The lower part supports the robotic arm 10 as a driveable support, for example, fixed to the ground within a factory. In robot 1, the base 11 is electrically connected to the robot control device 3 via a relay cable. It should be noted that the connection between robot 1 and robot control device 3 is not limited to the following... Figure 1 The configuration shown is achieved through a wired connection, but it could also be achieved through a wireless connection, or via a network connection such as the Internet.
[0028] In this embodiment, the robotic arm 10 has a first arm 12, a second arm 13, a third arm 14, a fourth arm 15, a fifth arm 16, and a sixth arm 17, which are connected in this order starting from the base 11 side. It should be noted that the number of arms in the robotic arm 10 is not limited to six; for example, it can have one, two, three, four, five, or more than seven arms. Furthermore, the overall length and other dimensions of each arm are not particularly limited and can be appropriately set.
[0029] The base 11 and the first arm 12 are connected by a joint 171. Furthermore, the first arm 12 is capable of rotating relative to the base 11 about a first rotation axis parallel to the vertical direction. The first rotation axis coincides with the normal to the ground on which the base 11 is fixed.
[0030] The first arm 12 and the second arm 13 are connected by a joint 172. Furthermore, the second arm 13 is capable of rotating relative to the first arm 12 about a second rotation axis parallel to the horizontal direction. The second rotation axis is parallel to an axis orthogonal to the first rotation axis.
[0031] The second arm 13 and the third arm 14 are connected by a joint 173. Furthermore, the third arm 14 is capable of rotating relative to the second arm 13 about a third rotation axis parallel to the horizontal direction. The third rotation axis is parallel to the second rotation axis.
[0032] The third arm 14 and the fourth arm 15 are connected by a joint 174. Furthermore, the fourth arm 15 is capable of rotating relative to the third arm 14 about a fourth rotation axis parallel to the central axis of the third arm 14. The fourth rotation axis is orthogonal to the third rotation axis.
[0033] The fourth arm 15 and the fifth arm 16 are connected by a joint 175. Furthermore, the fifth arm 16 is capable of rotating relative to the fourth arm 15 about a fifth rotation axis. The fifth rotation axis is orthogonal to the fourth rotation axis.
[0034] The fifth arm 16 and the sixth arm 17 are connected by a joint 176. Furthermore, the sixth arm 17 is capable of rotating relative to the fifth arm 16 about a sixth rotation axis. The sixth rotation axis is orthogonal to the fifth rotation axis.
[0035] In addition, the sixth arm 17 becomes the robot's foremost end piece located at the far end of the robotic arm 10. This sixth arm 17 is driven by the robotic arm 10 and can rotate together with the end effector 20.
[0036] Robot 1 includes motors M1, M2, M3, M4, M5, and M6 as drive units, and encoders E1, E2, E3, E4, E5, and E6. Motor M1 is integrated into joint 171 and rotates the base 11 relative to the first arm 12. Motor M2 is integrated into joint 172 and rotates the first arm 12 relative to the second arm 13. Motor M3 is integrated into joint 173 and rotates the second arm 13 relative to the third arm 14. Motor M4 is integrated into joint 174 and rotates the third arm 14 relative to the fourth arm 15. Motor M5 is integrated into joint 175 and rotates the fourth arm 15 relative to the fifth arm 16. Motor M6 is integrated into joint 176 and rotates the fifth arm 16 relative to the sixth arm 17.
[0037] Additionally, encoder E1 is integrated into joint 171 and detects the position of motor M1. Encoder E2 is integrated into joint 172 and detects the position of motor M2. Encoder E3 is integrated into joint 173 and detects the position of motor M3. Encoder E4 is integrated into joint 174 and detects the position of motor M4. Encoder E5 is integrated into the fifth arm 16 and detects the position of motor M5. Encoder E6 is integrated into the sixth arm 17 and detects the position of motor M6.
[0038] Encoders E1 to E6 are electrically connected to robot control device 3. The position information, i.e., the rotation amount, of motors M1 to M6 is sent to robot control device 3 as an electrical signal. Furthermore, robot control device 3, based on this information, such as... Figure 2 As shown, motors M1 to M6 are driven by motor drivers D1 to D6. That is, controlling the robotic arm 10 means controlling motors M1 to M6.
[0039] An end effector 20 can be detachably mounted on the front end of the robotic arm 10. In this embodiment, the end effector 20 is composed of a hand having a pair of claws that can approach and separate from each other, and holding and releasing a workpiece through each claw. It should be noted that the end effector 20 is not limited to the configuration shown in the figure, and can also be a hand that holds the work object (workpiece or tool) by suction. In addition, the end effector 20 can be, for example, a grinding machine, a cutting machine, a coating device, a spray gun, a screwdriver, a wrench, or other tools.
[0040] Robot 1 uses such an end effector 20 to make the robotic arm 10 operate as desired, performing various tasks such as conveying, manufacturing, processing, assembling, and painting of work objects (hereinafter collectively referred to as "tasks").
[0041] In addition, a control point TCP is set at the front end of the end effector 20. In the robot system 100, by knowing the location of the control point TCP in advance, the control point TCP can be used as a reference for control.
[0042] Next, the teaching device 4 will be explained.
[0043] like Figure 1 and Figure 2 As shown, the teaching pendant 4 has a display unit and functions such as creating and inputting motion programs for the robotic arm 10. There are no particular limitations on the teaching pendant 4; for example, a tablet computer, personal computer, smartphone, or teaching pendant can be used.
[0044] Specifically, the teaching device 4 includes a control unit 41, a storage unit 42, a communication unit 43, and an input unit 44.
[0045] The control unit 41 is composed of, for example, a CPU (Central Processing Unit) and reads various programs such as teaching programs stored in the storage unit 42.
[0046] The communication unit 43 uses external interfaces such as wired LAN (Local Area Network) or wireless LAN to transmit and receive signals with the robot control device 3.
[0047] The input unit 44 consists of a keyboard, mouse, connector, external connection terminals, etc. Users can operate, for example, the keyboard or mouse, to input or select desired information.
[0048] Next, the robot control device 3 will be explained.
[0049] like Figure 1 , Figure 2 and Figure 3 As shown, the robot control device 3 has the function of acquiring and storing the operation information of the robot 1, and also has the function of controlling the operation of the robot 1.
[0050] like Figure 1 As shown, in this embodiment, the robot control device 3 is located separately from the robot 1. However, it is not limited to this configuration; for example, the robot control device 3 may also be built into the base 11 of the robot 1.
[0051] <Hardware Composition of Robot Control Device 3>
[0052] like Figure 1 and Figure 3 As shown, the robot control device 3 includes a CPU 31, a ROM 32, a RAM 33, an IF control unit 34 (communication unit), an LED 35, a bus 36, and a housing 39 for housing or mounting these components. The bus 36 interconnects the CPU 31, ROM 32, RAM 33, IF control unit 34, and LED 35. The storage unit 30 is composed of ROM 32 and RAM 33.
[0053] In this embodiment, the CPU 31 is composed of a multiprocessor with multiple core processors. The CPU 31 has a core 311 and a core 312 that serve as core processors. The CPU 31 executes control programs such as the startup program and action program described later, and performs unified system control of the entire robot control device 3.
[0054] Kernel 311 is the first processing unit that executes the control program, including the boot program and action program (described later). Kernel 312 is the second processing unit that performs signature verification on the boot program and action program. It should be noted that kernel 312 can also have the function of executing the action program.
[0055] "Perform signature verification" means verifying whether the first hash value obtained by multiplying the startup program or action program by a hash function is consistent with the second hash value obtained by decoding the electronic signature used by the startup program or action program using a public key.
[0056] "Signature verification successful" means that the first hash value is compared with the second hash value and they are the same. In the case of successful signature verification, the program has not been tampered with, and the robot control device 3 can be started with high security. Furthermore, the robot 1 can be safely driven.
[0057] "Signature verification failed" refers to a situation where the first hash value is compared with the second hash value and the two values are different. In the event of signature verification failure, the program may be tampered with, the security of the robot control device 3's startup is not guaranteed, and the security of the robot 1's operation is also not guaranteed.
[0058] ROM32 is a read-only memory that stores programs and other data. The control program includes the startup program and the action program.
[0059] The startup program is a program used to start the system of the robot control device 3. As a startup program, such as... Figure 4 As shown, examples include the bootloader 301, BIOS (Basic Input / Output System) 302, loader 303, and kernel 304. In other words, the bootloader 301, BIOS 302, loader 303, and kernel 304 are the boot programs. It should be noted that, in addition to the above, boot programs can also include native programs, Java programs, and other programs.
[0060] The motion program includes programs that demonstrate the path of the control point TCP of robot 1, the posture of the robotic arm 10 changing over time, the speed information of the control point TCP, and other conditions for driving robot 1. These programs are the motion programs.
[0061] like Figure 3As shown, RAM33 is Random Access Memory, a volatile memory used by the CPU31 to temporarily store the control program stored in ROM32 while the CPU31 executes various programs. The IF control unit 34 communicates with external devices, such as the robot 1 and the teaching pendant 4, via a network to send and receive data. The LED35 operates by lighting up or flashing according to a predetermined pattern, and notifies, for example, of abnormal robot 1 operation, system malfunctions in the robot control unit 3, or the result of signature verification (failure, etc., as described later). In other words, the LED35 functions as a notification unit. Such an LED35 is positioned, for example, exposed on the outer surface of the housing 39 of the robot control unit 3, so that the user can visually identify it.
[0062] <Software Composition of Robot Control Device 3>
[0063] like Figure 4 As shown, the robot control device 3 includes a boot program 301, a BIOS 302, a loader 303, a core 304, and various action programs as software modules. The boot program 301 is a program that executes a series of procedures after the robot control device 3 is powered on and before it becomes capable of operating the operating system (OS). The BIOS 302 is an initialization program that initializes hardware such as the ROM 32 and the IF control unit 34. "Initialization" refers to clearing data from the cache area. The loader 303 is a loading program that loads the boot program from the ROM to the RAM. The core 304 is a program that manages the execution state of programs in operation or manages the hardware to enable programs to utilize hardware functions.
[0064] Conventionally, when starting the device, the signature of software module A, which corresponds to the bootloader 301, is verified. If the signature verification is successful, software module A is executed. Next, the signature of software module B, which corresponds to the BIOS 302, is verified. If the signature verification is successful, software module B is executed. Because this process is repeated for each bootloader, starting the device is time-consuming. In contrast, in this invention, by performing the following process, the robot control device 3 can be started quickly and safely.
[0065] <Execute startup program>
[0066] After the power is turned on (not shown), the kernel 311 of the robot control device 3 begins to execute the boot program 301. Figure 5 At time t1 in the process. Next, kernel 312 begins signature verification of bootloader 301 ( Figure 5At time t2 in the middle. After kernel 312 completes the signature verification of bootloader 301, that is, after the signature verification is successful ( Figure 5 At time t3, kernel 311 completed the execution of bootloader 301. Figure 5 (At time t4). Therefore, in the robot control device 3, the signature verification of the bootloader by kernel 312 and the execution of the bootloader being signed by kernel 312 by kernel 311 are repeated in time (hereinafter referred to as "repetition processing"). That is, in the robot control device 3, signature verification is performed in parallel during the execution of bootloader 301. This shortens the time before the execution of bootloader 301 compared to the past. Therefore, the robot control device 3 can be started quickly.
[0067] In the robot control unit 3, the execution via kernel 311 and the signature verification via kernel 312 are repeated in time for BIOS 302, loader 303, and kernel 304, as described above. This allows for a faster startup of the robot control unit 3.
[0068] It should be noted that, although this embodiment involves repeatedly performing the execution via kernel 311 and the signature verification via kernel 312 on all boot programs in terms of time, the present invention is not limited to this. As long as at least one boot program is repeatedly subjected to the execution via kernel 311 and the signature verification via kernel 312 in terms of time, the effects of the present invention can be fully realized. In this case, it is preferable to prioritize repeating the processing of boot programs that require a longer startup time among all boot programs.
[0069] As mentioned earlier, after kernel 311, acting as the first processing unit, begins executing the startup program, kernel 312, acting as the second processing unit, begins signature verification of the startup program. Since signature verification of the startup program tends to take less time from start to finish than execution of the startup program, kernel 311 executes the startup program first. This effectively reduces the time spent on repetitive processing, which includes execution by kernel 311 and signature verification by kernel 312. Therefore, the robot control device 3 can be started more quickly.
[0070] It should be noted that the execution of the bootloader by kernel 311 and the signature verification of the bootloader by kernel 312 can start simultaneously, or the signature verification of the bootloader by kernel 312 can start first.
[0071] If the signature verification performed by kernel 312 fails, the boot program is stopped, and LED 35 flashes to indicate the signature verification failure. This prevents the boot program from being tampered with and thus prevents the robot control device 3 from starting without this consideration. It should be noted that it can also be configured so that even if the signature verification performed by kernel 312 fails, the entire boot program or a portion thereof continues to execute. In this case, it is preferable to notify the user via LED 35 at the point of signature verification failure.
[0072] It should be noted that, alternatively, if the signature verification of the boot program performed by kernel 312 is successful, LED35 can also be run to notify of this. In this case, LED35 can also be configured to operate in a different manner than in the case of signature verification failure (blinking), for example, by being lit for a certain period of time.
[0073] <Execution Procedure>
[0074] If kernel 312 successfully verifies the signature of the bootloader, it enters a state where it can execute the action program. When executing the action program, kernel 312 first begins verifying the signature of the action program. Figure 6 At time t5 in the kernel 312, the signature verification of the action program is completed, i.e., the signature verification is successful. Figure 6 At time t6, after a predetermined interval, kernel 311 begins executing the action program ( Figure 6 (Time t7 in the text). Therefore, regarding the action program, execution is based on the successful signature verification of the action program, without performing redundant processing that duplicates the signature verification of the action program. This prevents the execution of inappropriate action programs that may be tampered with, ensuring security. In particular, since the action program is often used to make the robotic arm 10 perform actions, it requires higher security than the startup program. Therefore, this configuration is effective.
[0075] Therefore, the control program includes an action program that enables robot 1 to perform actions. The kernel 312, acting as the second processing unit, performs signature verification on the action program. After successful signature verification and after the robot control device 3 is started, the kernel 311, acting as the first processing unit, executes the action program. Thus, robot 1 can perform actions while ensuring high security.
[0076] It should be noted that the action program can also be configured as follows: based on its content, it repeats the same processing over time as the startup program, namely, execution through kernel 311 and signature verification through kernel 312.
[0077] In this case, for all the action procedures, such as the initial stage of the execution of action procedures like setting, confirming, and adjusting the initial position of the control point TCP, the procedures whose relative security of their action content has been ensured can be repeated.
[0078] If kernel 312 fails to verify the signature of the action program, the action program will not be executed. Instead, the failure will be indicated by the operation of LED 35 (e.g., flashing). This allows the user to be aware of the possibility that the action program has been tampered with and to take pre-defined actions such as terminating the execution of the action program.
[0079] It should be noted that, alternatively, if kernel 312 successfully verifies the signature of the action program, LED35 can also be run to notify of this. In this case, LED35 can also be configured to operate in a different manner than in the case of signature verification failure (blinking), for example, by being lit for a certain period of time.
[0080] Furthermore, the notification of the signature verification result (success or failure) via the operation of LED35 can be delivered in the same or different ways during the startup and operation procedures. Also, the notification of the signature verification result is not limited to notification via the operation of LED35; for example, it can be a display unit other than LED35 or a notification via sound. Examples of displays other than LED35 include liquid crystal displays, such as the liquid crystal display included in the teaching pendant 4.
[0081] As explained above, the robot control device 3 is a robot control device that controls the operation of the robot 1. It comprises: a kernel 311 as a first processing unit that executes a control program including a startup program to launch the robot control device 3; and a kernel 312 as a second processing unit that performs signature verification on the startup program. The robot control device 3 repeatedly performs signature verification of the startup program by the kernel 312 and execution of the startup program by the kernel 311 while the kernel 312 is performing signature verification on the startup program. Therefore, the robot control device 3 can be launched quickly and securely.
[0082] It should be noted that in this embodiment, the case where kernel 311 and kernel 312 exist in the same CPU is described, but this is not the case in the present invention. Kernel 311 and kernel 312 may also exist in different CPUs.
[0083] The robot control device 3 includes: a storage unit 30 having a ROM 32 and a RAM 33; and an IF control unit 34 serving as a communication unit, communicating with the robot 1. The startup program includes at least one of a BIOS 302 serving as an initialization program and a loader 303 serving as a loading program (both in this embodiment). The BIOS 302 is stored in the ROM 32 and initializes the storage unit 30 (ROM 32, RAM 33) and the IF control unit 34. The loader 303 expands the startup program from the ROM 32 of the storage unit 30 to the RAM 33. Since the execution of the BIOS 302 and the loader 303 tends to be time-consuming, the effects of the present invention can be more significantly achieved by repeatedly executing and verifying the signature of the BIOS 302 and the loader 303 over time.
[0084] It should be noted that, although this embodiment describes a configuration in which execution and signature verification are repeatedly performed on both BIOS 302 and loader 303 in time, the present invention is not limited to this, and it may also be a configuration in which execution and signature verification are repeatedly performed on only either BIOS 302 or loader 303 in time.
[0085] Next, use Figure 7 and Figure 8 The flowchart shown illustrates an example of the control method of the present invention. The following description focuses on the case where execution and signature verification are performed only repeatedly over time on the loader 303.
[0086] First, refer to Figure 7 This section explains the successful signature verification process.
[0087] After a power source (not shown) is switched on, in step S11, kernel 312 initializes the device (hardware). Next, kernel 312 boots kernel 311 (step S12), and kernel 311 initializes the device (step S21). That is, kernel 311 reads and executes bootloader 301 and BIOS 302 from ROM 32. Next, kernel 311 reads and executes loader 303 from ROM 32, performing the process of expanding the control program stored in ROM 32 to RAM 33 (step S22: execution step). On the other hand, kernel 312 performs signature verification on the control program stored in ROM 32 (step S13: signature verification step). The signature verification of loader 303 in step S13 and step S22 are repeated in time. This facilitates the rapid startup of the robot control device 3.
[0088] Kernel 311 initializes the application during signature verification (step S23). That is, it initializes each bootloader, and then waits for permission to start each bootloader in step S24.
[0089] If all signature verifications are successful, kernel 312 allows kernel 311 to boot (step S14). Then, in steps S15 and S25, kernel 311 and kernel 312 start the application. That is, the system of robot control device 3 is started, and robot 1 is set to a controllable state.
[0090] Next, refer to Figure 8 This section explains the situations where signature verification fails during program startup.
[0091] It should be noted that since steps S11 to S13 and steps S21 to S24 are the same as the successful signature verification of the startup program, their descriptions are omitted, and only steps S16, S17 and S26 are described.
[0092] If the signature verification fails in step S13, in step S16, kernel 312 sends a signal to kernel 311 to immediately stop the boot of kernel 311, and kernel 311 stops executing the boot program (step S26). After kernel 312 stops booting kernel 311, kernel 312 notifies and stops (step S17). This notification is made by causing LED 35 to operate in a predetermined pattern (blinking).
[0093] As explained above, the control method is a control method for the robot control device 3 that controls the operation of robot 1. It includes: an execution step, where a kernel 311, acting as a first processing unit, executes a control program including a startup program for starting the robot control device 3; and a signature verification step, where a kernel 312, acting as a second processing unit (different from the kernel 311), performs signature verification on the startup program. In this control method, the execution step and the signature verification step are repeated over time. Therefore, the robot control device 3 can be started quickly and safely.
[0094] <Second Implementation>
[0095] Figure 9 This is a hardware configuration diagram of the robot control device according to the second embodiment of the present invention.
[0096] The following reference Figure 9 A second embodiment of the robot control device and control method of the present invention will be described below, focusing on the differences from the first embodiment, and omitting descriptions of the same items.
[0097] like Figure 9As shown, the robot control device 3 has a selection unit 37 that selects a first mode and a second mode. The first mode is, as described in the first embodiment, a mode in which the execution of the boot program by kernel 311 and the signature verification of the boot program by kernel 312 are repeated over time. The second mode is a mode in which kernel 311 executes the boot program after kernel 312 has successfully verified the signature of the boot program.
[0098] The selection unit 37, for example, is composed of a CPU and is interconnected with the CPU 31, ROM 32, RAM 33, IF control unit 34 (communication unit), and LED 35 via bus 36. When the user uses, for example... Figure 1 and Figure 2 When the input unit 44 of the teaching pendant 4 shown, or other input device not shown, selects and inputs a first mode or a second mode, the input mode is set. Then, the CPU 31 reads and executes the program corresponding to the set mode (first mode or second mode). Specifically, although not shown, a first program for executing the first mode and a second program for executing the second mode are stored in the ROM 32. The selection unit 37 sends a signal to the CPU 31 to execute the first mode or the second mode, and the CPU 31 executes the corresponding program according to the signal.
[0099] After the selection unit 37 selects the first mode, the control described in the first embodiment is performed. The advantages of the first mode are as previously stated. After the selection unit 37 selects the second mode, the kernel 312 performs signature verification of the boot program 301, the kernel 302 performs signature execution of the boot program 311, and the kernel 311 performs signature verification of the boot program 312 and execution of the boot program 311, respectively, for the boot program 301, BIOS 302, loader 303, kernel 304, and various action programs. That is, the second mode does not repeat the signature verification and execution in time. The advantages of the second mode include simpler control processing and enhanced security.
[0100] Therefore, by selecting and executing either the first or second mode, one can choose to prioritize either startup speed or high safety and simplified control processing. Thus, users can select the appropriate mode by considering various factors such as the content, level, importance, duration (speed), frequency, time interval between tasks, and the likelihood of tampering with the control program (especially the startup and action programs). This improves convenience.
[0101] It should be noted that in this embodiment, the selection unit 37 is composed of a CPU different from the CPU 31, but it is not limited to this, and the selection unit 37 may also exist in the CPU 31.
[0102] As explained above, the robot control device 3 includes a selection unit 37 for selecting a first mode and a second mode. The first mode is a mode in which the execution of the startup program by the kernel 311 (as a first processing unit) and the signature verification of the startup program by the kernel 312 (as a second processing unit) are repeated over time. The second mode is a mode in which the kernel 311 executes the startup program after the kernel 312 successfully verifies the signature of the startup program. This improves convenience.
[0103] It should be noted that the robot control device 3 can also be configured to select a mode other than the first mode and the second mode (a third mode). For example, a mode other than the first mode and the second mode can be a mode that can select a control program that repeatedly performs signature verification and execution over time.
[0104] In addition, in this embodiment, the selection and input of the first mode or the second mode are configured to be performed by the user, but it is not limited to this. For example, the selection of such a mode may also be configured to be automatically selected and set according to the aforementioned conditions.
[0105] Furthermore, when performing tasks using robot 1, the mode selection is not limited to being done through user operation each time. For example, it can be configured such that the previous mode continues unchanged as long as no mode change operation is performed. This has the advantage of reducing the time users spend selecting tasks while ensuring sufficient safety.
[0106] Alternatively, the configuration could be as follows: when performing tasks via robot 1, the first mode (either the first or second mode) is preferentially selected, and the second mode can only be selected if the user deselects it. This offers the advantage of reducing the time the user spends selecting tasks while ensuring sufficient safety.
[0107] Alternatively, the configuration can be set up to restrict the selectable mode in either the first or second mode based on the history of signature verification results during program startup. For example, it could be configured such that, given a history of "signature verification failure," the first mode cannot be selected until a certain time or number of operations have elapsed; only the second mode can be chosen. This ensures higher security. It should be noted that the same applies when a third mode is added.
[0108] The robot control device and control method of the present invention have been described above with reference to the various embodiments illustrated, but the present invention is not limited to these. Furthermore, each part and each process of the robot control device and control method can be replaced with any structure or process that can perform the same function. Additionally, any arbitrary structure or process may be added.
Claims
1. A robot control device, characterized in that, The robot control device, which controls the operation of the robot, includes: The first processing unit executes a control program that includes initiating a startup procedure for the robot control device; and The second processing unit performs signature verification on the startup program. The robot control device repeats the signature verification of the startup program by the second processing unit and the execution of the startup program by the first processing unit while the signature verification is being performed by the second processing unit in time.
2. The robot control device according to claim 1, characterized in that, The control program includes action programs that cause the robot to perform actions. The second processing unit performs signature verification on the action program. After the signature verification is successful and the robot control device is started, the first processing unit executes the action program.
3. The robot control device according to claim 1 or 2, characterized in that, After the first processing unit begins executing the startup program, the second processing unit begins signature verification of the startup program.
4. The robot control device according to claim 1 or 2, characterized in that, The robot control device includes: The storage section has ROM and RAM; and The communication unit communicates with the robot. The boot program includes at least one of an initialization program and a loading program. The initialization program is stored in the ROM and initializes the storage unit and the communication unit. The loading program expands the boot program from the ROM of the storage unit to the RAM.
5. The robot control device according to claim 1 or 2, characterized in that, The robot control device includes a selection unit for selecting a first mode and a second mode. The first mode is a mode in which the execution of the startup program by the first processing unit and the signature verification of the startup program by the second processing unit are repeated over time. The second mode is a mode in which the startup program is executed by the first processing unit after the signature verification of the startup program by the second processing unit is successful.
6. A control method, characterized in that, It is a control method for a robot control device that controls the operation of a robot, the control method comprising: The execution steps include the first processing unit executing a control program that includes initiating the startup program for the robot control device; and In the signature verification step, a second processing unit, different from the first processing unit, performs signature verification on the startup program. The execution step and the signature verification step are repeated over time.
Citation Information
Patent Citations
Information processing apparatus and information processing method
JP2019175000A