A safety control system for industrial robot networking and a control method thereof

By constructing a three-level linkage security control system between local, edge, and cloud, the problems of insufficient hardware-level security verification and insufficient network isolation design in existing technologies are solved. This achieves hardware-level security protection and multi-scenario adaptability for industrial robots connected to the network, ensuring the safe and stable operation of robots in offline scenarios.

CN122419946APending Publication Date: 2026-07-17HENGYUANHE (SHANGHAI) TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610730932.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-26
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing industrial robot networking security control solutions lack hardware-level low-level security verification, making them vulnerable to being bypassed by malicious programs. Insufficient network boundary isolation design leads to a high risk of cross-boundary propagation of network penetration attacks, and security protection functions fail when cloud communication is interrupted. They cannot meet the multi-scenario, multi-protocol, and high real-time industrial robot networking security requirements.

Method used

A three-tiered, end-to-end security management system is constructed, linking local, edge, and cloud environments. This system utilizes local robot security terminals, edge security gateways, and cloud security management platforms to achieve hardware-level motion control command verification, physical-level network isolation, and offline emergency security. Combined with hardware emergency stop, two-way data isolation, and offline emergency modes, a comprehensive security protection mechanism is built.

Benefits of technology

It achieves hardware-level security protection for industrial robot motion control, improves the protection level of network boundaries, ensures the safe and stable operation of robots in offline scenarios, adapts to the network security needs of industrial robots in multiple scenarios and with multiple protocols, and enhances the applicability and comprehensiveness of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122419946A_ABST
    Figure CN122419946A_ABST
Patent Text Reader

Abstract

This invention discloses a safety control system for industrial robot networking, relating to the field of industrial robot safety control technology. Addressing the shortcomings of existing industrial robot networking solutions—such as single protection layers, susceptibility to malicious program bypass, ineffective security control in network outage scenarios, and lack of a comprehensive protection system—this system comprises a local robot security terminal, an edge security gateway, and a cloud-based security management platform. The local terminal integrates multiple sets of hardware security circuits to achieve hardware-level protection for robot motion control. The edge gateway uses physical isolation switching circuits to achieve security control at the internal and external network boundaries and emergency protection during network outages. The cloud platform provides global security control and operation and maintenance auditing, constructing a three-level, interconnected, comprehensive security management system that balances security, real-time performance, and reliability, adapting to the diverse security management needs of industrial robot networking across various scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial robot safety control technology, and in particular to a safety control system for networking industrial robots. Background Technology

[0002] Safety control systems for industrial robot networking are specialized automated systems applied in industrial intelligent manufacturing scenarios. They provide motion control safety protection, network communication security management, and remote operation and maintenance compliance auditing for industrial robots connected to enterprise intranets, wide area networks, or cloud management platforms. These systems are the core foundation for achieving digital cluster management, remote operation and maintenance debugging, and interconnection of production data for industrial robots. Their core function is to prevent security risks such as malicious control command injection, illegal network intrusion, production data tampering and leakage, and unauthorized remote operation throughout the entire process of industrial robot networking and interaction, ensuring the stable operation of industrial robots and production safety in industrial settings. With the rapid implementation of Industry 4.0, the deployment rate of networked industrial robots continues to increase, and the corresponding safety control systems have become an indispensable core supporting technology in the field of industrial automation.

[0003] Existing industrial robot network security control solutions are mostly structured around a single network firewall paired with software-level security protection plugins. Some optimized solutions only add a single gateway protection device, performing basic traffic filtering and access restriction at the industrial robot's network access layer. They lack hardware-level security verification mechanisms for the robot's local motion control layer, and cannot perform real-time low-level verification of motion control commands sent to the servo drive unit. This makes them vulnerable to malicious programs bypassing software protection and injecting illegal control commands. Furthermore, existing solutions often use logical isolation methods such as firewalls to separate internal and external networks, lacking physical-level isolation and bridging designs. This poses a risk of network penetration attacks propagating across boundaries. Most solutions also heavily rely on the control capabilities of cloud platforms and lack local emergency control units. In scenarios where communication with the cloud is interrupted, core security protection functions become significantly ineffective, failing to guarantee the safety of offline robot operation. In addition, existing solutions lack a three-level linkage end-to-end control system connecting local, edge, and cloud, making it impossible to achieve dynamic adaptation and updates of security policies and full-process traceability and auditing of maintenance operations. This makes them ill-suited to the multi-scenario, multi-protocol, and high-real-time network security control requirements of industrial robots. Summary of the Invention

[0004] To address the aforementioned deficiencies in existing technologies, the present invention aims to provide a safety control system for industrial robot networking, constructing a three-level linkage end-to-end safety management and control system that integrates local, edge, and cloud environments. This system achieves hardware-level security protection at the robot motion control layer, physical-level isolation and control of internal and external network boundaries, and emergency safety assurance in network outage scenarios, while balancing the security of industrial robot network communication with the real-time performance and reliability of local motion control.

[0005] To address the aforementioned technical problems, the present invention provides the following technical solution: a safety control system for industrial robot networking, comprising a local robot safety terminal, an edge safety gateway, and a cloud-based safety management platform; the local robot safety terminal is electrically connected to a corresponding unit within the industrial robot control cabinet, the edge safety gateway is communicatively connected to the local robot safety terminal and the industrial field control bus, and the edge safety gateway can communicate with the cloud-based safety management platform via a wide area network;

[0006] The local robot safety terminal integrates a main control circuit, an instruction security verification circuit, a local encryption / decryption circuit, a motion state monitoring circuit, a bus interface isolation circuit, and an emergency stop execution circuit. The instruction security verification circuit is connected between the industrial robot main controller and the servo drive unit, and is used to perform whitelist verification on motion control instructions. The input end of the motion state monitoring circuit is connected to the signal of the industrial robot sensing unit, and the output end is connected to the main control circuit. The emergency stop execution circuit is connected in series to the industrial robot hardware emergency stop loop. The bus interface isolation circuit adopts an ADUM1400 dual-channel digital isolation circuit, which is connected in series between the local terminal and the fieldbus. The local encryption / decryption circuit adopts an AES-256 hardware encryption circuit, which is bidirectionally connected to the main control circuit.

[0007] The edge security gateway integrates a bidirectional data isolation and transfer circuit, an industrial protocol deep parsing circuit, a traffic anomaly detection circuit, a VPN encrypted tunnel circuit, and a local caching and emergency control circuit. The bidirectional data isolation and transfer circuit adopts a physical isolation transfer circuit based on IDT70V24 dual-port RAM, which is connected to the internal network and external network interfaces respectively. The industrial protocol deep parsing circuit and the traffic anomaly detection circuit are connected to the corresponding interfaces of the transfer circuit respectively. The VPN encrypted tunnel circuit is used to build an encrypted communication tunnel between the edge and the cloud.

[0008] The cloud-based security management platform includes a device identity authentication module, a security policy management module, a threat intelligence update module, and an operation and maintenance audit module, which can perform global security management on connected devices.

[0009] Furthermore, the main control circuit adopts the STM32H743 industrial-grade main control circuit, which can coordinate the function scheduling and logic processing of the local terminal.

[0010] Furthermore, the instruction security verification circuit adopts an FPGA hardware verification circuit, which pre-stores a whitelist of compliant motion control instructions, and can perform real-time verification of issued instructions and block instructions that fail verification.

[0011] Furthermore, the abnormal emergency stop execution circuit includes a TLP521-1 opto-isolation coupling circuit and a relay drive circuit, which can cut off the servo drive power supply and trigger a hardware emergency stop after receiving a trigger signal from the main control circuit.

[0012] Furthermore, the local cache and emergency control circuit has a built-in FM24CL64 ferroelectric storage circuit, which can store local security policies and anomaly logs. When communication with the cloud is interrupted, it can switch to offline emergency mode to perform local management and control.

[0013] A safety control method for networking industrial robots includes the following steps:

[0014] After the S1 device is powered on, it initiates identity authentication to the cloud. Once the authentication is successful, the connection is completed, and the cloud sends out the initial security policy and configuration.

[0015] The motion control commands of the S2 industrial robot are verified in real time by the local terminal, and the robot motion parameters are collected and matched synchronously. When an abnormality occurs, the hardware emergency stop can be triggered and the abnormal log is uploaded.

[0016] The S3 robot's internal and external network interaction data is processed through an edge gateway for protocol parsing, traffic detection, and controllable data transfer to intercept abnormal access and unauthorized operations.

[0017] The S4 cloud receives device operation data and anomaly logs, completes threat analysis and source tracing, can update and distribute security policies according to the operation status, and audits and records operation and maintenance operations.

[0018] When communication between the S5 edge gateway and the cloud is interrupted, it can switch to offline emergency mode to complete management and control based on local security policies. After communication is restored, relevant data will be synchronized.

[0019] Furthermore, in step S2, the verification content of the motion control command includes the command format, operation permission and motion parameter threshold. Commands that pass the verification can be sent to the servo drive unit.

[0020] Furthermore, in step S3, the data transfer between internal and external networks adopts a one-way controllable mechanism, and the written data must undergo compliance verification to ensure data transmission security.

[0021] Furthermore, in step S5, local security control and log caching functions can be retained in offline emergency mode, and offline data can be synchronized and security policies updated after communication is restored.

[0022] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages compared with the prior art:

[0023] 1. This invention deploys a local robot safety terminal with multiple sets of hardware safety circuits integrated in the local control cabinet of the industrial robot. It realizes real-time verification of motion control commands at the underlying level through FPGA hardware verification circuit. Compared with software-level protection, it is not easy to be bypassed by malicious programs and has higher protection reliability. At the same time, the dual-channel digital isolation circuit realizes electrical isolation between the fieldbus and the local terminal, effectively blocking the transmission of surges, electrostatic interference and network penetration attacks on the bus side. Combined with motion status monitoring and hardware emergency stop execution circuit, it realizes hardware-level safety protection for the entire process of robot motion control.

[0024] 2. This invention achieves unidirectional controllable data transfer between internal and external networks through a physical isolation transfer circuit based on dual-port RAM in the edge security gateway. Compared with the logical isolation method of traditional firewalls, physical isolation provides a higher level of protection and can fundamentally block the cross-boundary propagation of network layer penetration attacks. At the same time, it is equipped with industrial protocol deep parsing circuit and traffic anomaly detection circuit, which can adapt to the compliance verification of various dedicated bus protocols in industrial fields, realize the real-time identification and interception of abnormal traffic on the external network, and balance the comprehensiveness of boundary protection with the real-time nature of industrial communication.

[0025] 3. This invention configures a local cache and emergency control circuit with built-in ferroelectric storage in the edge security gateway. When communication with the cloud security management platform is interrupted, it can automatically switch to offline emergency mode and complete the whole process security management based on the locally pre-stored security policy. This solves the problem of existing solutions being highly dependent on cloud management and the failure of security protection functions in network outage scenarios, and ensures the safety and stability of the robot's operation in all scenarios.

[0026] 4. This invention constructs a three-level linkage end-to-end security management system that connects local, edge, and cloud. Through the cloud platform, it realizes global device identity authentication, dynamic updates of security policies, and full-process auditing of operation and maintenance. It can dynamically adapt security protection strategies according to changes in the operating scenarios and tasks of industrial robots, and can adapt to the network security management needs of multi-brand and multi-protocol industrial robots, greatly improving the applicability and comprehensiveness of the system.

[0027] Other advantages, objectives and features of the invention will be set forth in part in the description which follows, and in part will be apparent to those skilled in the art from the following examination or study, or may be learned from the practice of the invention. Attached Figure Description

[0028] Figure 1 This is a diagram of the overall system architecture of the present invention;

[0029] Figure 2 This is a timing diagram of device access and identity authentication according to the present invention;

[0030] Figure 3This invention relates to the internal and external network data transfer and detection mechanism;

[0031] Figure 4 This is a timing diagram of the offline emergency mode switching and recovery of the present invention;

[0032] Figure 5 This is a schematic diagram of the AES-256 hardware encryption of the local encryption / decryption circuit of the present invention;

[0033] Figure 6 This is a schematic diagram of the FPGA hardware verification circuit for instruction security verification of the present invention;

[0034] Figure 7 This is a schematic diagram of the bidirectional data isolation transfer circuit IDT70V24 dual-port RAM of the present invention;

[0035] Figure 8 This is a schematic diagram of the FM24CL64 ferroelectric storage circuit for local caching and emergency control of the present invention. Detailed Implementation

[0036] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0037] It should be noted that the terms "vertical," "horizontal," "up," "down," "left," "right," and similar expressions used in this article are for illustrative purposes only and do not represent the only possible implementation.

[0038] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to limit the invention; the term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0039] like Figure 1-8 As shown in the figure, this embodiment provides a safety control system for industrial robot networking, including a local robot safety terminal, an edge security gateway, and a cloud security management platform.

[0040] In this embodiment, the local robot safety terminal is deployed inside the industrial robot's control cabinet. Its main control circuit uses a minimum system circuit built with an STM32H743 industrial-grade main control chip and has a built-in FreeRTOS real-time operating system, enabling microsecond-level task scheduling and ensuring the real-time performance of local security protection. The instruction security verification circuit uses a hardware verification circuit built with an Altera Cyclone IV series FPGA chip. The circuit pre-stores a whitelist of compliant motion control instructions such as point-to-point control, speed control, and torque control. The whitelist includes the standard format of the instructions and the parameter threshold range. The FPGA circuit can complete the full verification of a single instruction within 1ms. Only instructions that pass the verification can be sent to the servo drive unit, while instructions that fail the verification are directly intercepted and an abnormal alarm signal is sent to the main control circuit. The motion status monitoring circuit is connected to the industrial robot's axis encoder and torque sensor through a differential signal interface, which can collect the position, speed, and force of each axis of the robot in real time. Motion parameters such as moment are collected and fed back to the main control circuit. The main control circuit compares the expected parameters with the actual collected parameters. When the deviation exceeds the preset threshold, an abnormality is immediately triggered. The TLP521-1 optocoupler circuit of the emergency stop execution circuit realizes electrical isolation between the control signal and the high-voltage circuit. The output contacts of the relay drive circuit are connected in series to the dual-circuit hardware emergency stop circuit of the industrial robot. It can cut off the servo drive power supply within 10ms after receiving the emergency stop signal from the main control circuit, triggering the hardware emergency stop. The bus interface isolation circuit uses the ADUM1400 dual-channel digital isolation chip with an isolation withstand voltage of 2500Vrms. It is connected in series between the industrial bus interface and the fieldbus of the local robot safety terminal to block interference and attack transmission on the bus side. The local encryption and decryption circuit uses the AES-256 hardware encryption chip, which is bidirectionally connected to the main control circuit through the SPI interface. It performs hardware-level encryption and decryption on the locally exchanged control data and collected data to prevent data from being tampered with or stolen.

[0041] In this embodiment, the edge security gateway is deployed in a control cabinet in the industrial site. The bidirectional data isolation transfer circuit uses an IDT70V24 dual-port static RAM chip, paired with an internal network MCU and an external network MCU. The internal network MCU and the external network MCU have no direct electrical connection; unidirectional controllable reading and writing of data is achieved only through the dual-port RAM. Data uploaded from the internal network to the public network can only be written to the dual-port RAM through the internal network MCU; the external network MCU can only read and not write. Similarly, data sent from the public network to the internal network can only be written to the dual-port RAM through the external network MCU; the internal network MCU can only read and not write. All written data must undergo compliance verification; data that fails verification cannot be written, thus achieving physical layer isolation between the internal and external networks. The industrial protocol deep parsing circuit is built using a multi-core industrial-grade processor, supporting mainstream industrial bus protocols such as Profinet, EtherCAT, ModbusTCP, and DeviceNet, as well as mainstream industrial machines from ABB, KUKA, and FANUC. The robot's dedicated control protocol features deep analysis, enabling it to identify function codes, address ranges, and data content within data packets, and intercept packets that do not conform to protocol specifications or exceed operational permissions. The traffic anomaly detection circuit monitors the source address, access frequency, and data packet characteristics of external network access traffic in real time, identifying and intercepting abnormal access behaviors such as port scanning, brute-force attacks, and DDoS attacks. The VPN encrypted tunnel circuit uses a national cryptographic algorithm to encrypt the VPN tunnel, constructing an encrypted communication channel between the edge security gateway and the cloud security management platform, ensuring the security of wide area network data transmission. The local cache and emergency control circuit incorporates an FM24CL64 ferroelectric storage chip, ensuring data retention even after power failure. It stores local security policies, device whitelists, and anomaly logs. When a communication interruption with the cloud is detected to exceed a preset 30-second threshold, it automatically switches to offline emergency mode, completing all security checks and anomaly interception operations based on locally stored security policies, ensuring that security management remains effective even during network outages.

[0042] The cloud-based security management platform is deployed on the enterprise's private cloud server. The device authentication module adopts an asymmetric authentication mechanism based on the national cryptographic SM2 algorithm, assigning a unique digital certificate to each connected industrial robot, local robot security terminal, and edge security gateway. Devices without valid digital certificates cannot access the system. It also supports multi-factor authentication of remote maintenance personnel using account passwords and dynamic tokens, as well as hierarchical management of operation permissions. The security policy management module can configure and dynamically update security policies, command whitelists, and access permission rules based on the global device's operating scenarios and tasks. Policies are digitally signed and verified before being issued to prevent tampering. The threat intelligence update module can synchronize the latest industrial control system vulnerability database and network attack threat intelligence to the edge security gateway and local robot security terminal. The maintenance audit module can record and store the entire process of all remote maintenance operations, including the operator, operation time, operation content, and operation results. It supports backtracking and querying of operation logs, enabling full traceability of remote maintenance operations.

[0043] In this embodiment, the system first completes device authentication and initialization. After the local robot security terminal and edge security gateway are powered on, they initiate an authentication request to the cloud security management platform through the VPN encrypted tunnel circuit of the edge security gateway. The device authentication module verifies the device's digital certificate. After successful verification, the device access is completed. The cloud security management platform issues initial security policies, command whitelists, and the latest threat intelligence to the edge security gateway and local robot security terminal through the security policy management module. During the operation of the industrial robot, the motion control commands issued by the main controller first undergo real-time hardware verification through the command security verification circuit. At the same time, the motion status monitoring circuit collects the robot's motion parameters in real time. The main control circuit then combines the verified commands with the collected motion parameters. The system performs coordinated matching, immediately triggering a hardware emergency stop and uploading anomaly logs upon detection of anomalies. All interaction data between the industrial robot and internal / external networks is controlled via a bidirectional data isolation and transfer circuit on the edge security gateway. Industrial protocol deep parsing circuits and traffic anomaly detection circuits respectively perform compliance verification of internal network data packets and anomaly detection of external network traffic, intercepting unauthorized access and violations. The cloud-based security management platform receives device operation data and anomaly logs uploaded by the edge security gateway, performs threat analysis and tracing, dynamically updates security policies, and conducts full-process auditing of remote operation and maintenance. When communication between the edge security gateway and the cloud is interrupted, it automatically switches to offline emergency mode, performing security management based on locally cached security policies. After communication is restored, offline data is synchronized and the latest security policies are updated.

[0044] Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Anyone skilled in the art can make various modifications and alterations without departing from the spirit and scope of the present invention. Therefore, the scope of protection of the present invention should be determined by the claims.

Claims

1. A safety control system for networking industrial robots, comprising a local robot safety terminal, an edge safety gateway, and a cloud-based safety management platform; wherein the local robot safety terminal is electrically connected to a corresponding unit within the industrial robot control cabinet, the edge safety gateway is communicatively connected to the local robot safety terminal and an industrial field control bus, and the edge safety gateway can communicate with the cloud-based safety management platform via a wide area network, characterized in that: The local robot safety terminal integrates a main control circuit, an instruction security verification circuit, a local encryption / decryption circuit, a motion state monitoring circuit, a bus interface isolation circuit, and an emergency stop execution circuit. The instruction security verification circuit is connected between the industrial robot main controller and the servo drive unit, and is used to perform whitelist verification on motion control instructions. The input end of the motion state monitoring circuit is connected to the signal of the industrial robot sensing unit, and the output end is connected to the main control circuit. The emergency stop execution circuit is connected in series to the industrial robot hardware emergency stop loop. The bus interface isolation circuit adopts an ADUM1400 dual-channel digital isolation circuit, which is connected in series between the local terminal and the fieldbus. The local encryption / decryption circuit adopts an AES-256 hardware encryption circuit, which is bidirectionally connected to the main control circuit. The edge security gateway integrates a bidirectional data isolation and transfer circuit, an industrial protocol deep parsing circuit, a traffic anomaly detection circuit, a VPN encrypted tunnel circuit, and a local cache and emergency control circuit; the bidirectional data isolation and transfer circuit adopts a physical isolation and transfer circuit based on IDT70V24 dual-port RAM, which is connected to the internal network and external network interfaces respectively. The industrial protocol deep parsing circuit and the traffic anomaly detection circuit are respectively connected to the corresponding interfaces of the ferry circuit; the VPN encrypted tunnel circuit is used to construct an encrypted communication tunnel between the edge and the cloud. The cloud-based security management platform includes a device identity authentication module, a security policy management module, a threat intelligence update module, and an operation and maintenance audit module, which can perform global security management on connected devices.

2. The system according to claim 1, characterized in that, The main control circuit adopts the STM32H743 industrial-grade main control circuit, which can coordinate the function scheduling and logic processing of the local terminal.

3. The system according to claim 1, characterized in that, The instruction security verification circuit adopts an FPGA hardware verification circuit, which has a pre-stored whitelist of compliant motion control instructions. It can perform real-time verification of issued instructions and block instructions that fail the verification.

4. The system according to claim 1, characterized in that, The abnormal emergency stop execution circuit includes a TLP521-1 opto-isolation coupling circuit and a relay drive circuit. After receiving a trigger signal from the main control circuit, it can cut off the servo drive power supply and trigger a hardware emergency stop.

5. The system according to claim 1, characterized in that, The local cache and emergency control circuit has a built-in FM24CL64 ferroelectric storage circuit, which can store local security policies and anomaly logs. When communication with the cloud is interrupted, it can switch to offline emergency mode to perform local management and control.

6. A safety control method for networking industrial robots, characterized in that, Includes the following steps: After the S1 device is powered on, it initiates identity authentication to the cloud. Once the authentication is successful, the connection is completed, and the cloud sends out the initial security policy and configuration. The motion control commands of the S2 industrial robot are verified in real time by the local terminal, and the robot motion parameters are collected and matched synchronously. When an abnormality occurs, the hardware emergency stop can be triggered and the abnormal log is uploaded. The S3 robot's internal and external network interaction data is processed through an edge gateway for protocol parsing, traffic detection, and controllable data transfer to intercept abnormal access and unauthorized operations. The S4 cloud receives device operation data and anomaly logs, completes threat analysis and source tracing, can update and distribute security policies according to the operation status, and audits and records operation and maintenance operations. When communication between the S5 edge gateway and the cloud is interrupted, it can switch to offline emergency mode to complete management and control based on local security policies. After communication is restored, relevant data will be synchronized.

7. The method according to claim 6, characterized in that, In step S2, the verification of motion control commands includes command format, operation permissions, and motion parameter thresholds. Commands that pass the verification can be sent to the servo drive unit.

8. The method according to claim 6, characterized in that, In step S3, the data transfer between internal and external networks adopts a one-way controllable mechanism. The written data must undergo compliance verification to ensure the security of data transmission.

9. The method according to claim 6, characterized in that, In step S5, local security management and log caching functions can be retained in offline emergency mode. After communication is restored, offline data will be synchronized and security policies will be updated.