Secure io terminal and security system

CN122804200APending Publication Date: 2026-09-22OMRON CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202580016497.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-15
Filing Date
2025-03-07
Publication Date
2026-09-22

AI Technical Summary

Benefits of technology

[0023]根据本发明,能够实现可进行基于来自多个安全控制器的数据的安全控制的安全IO终端以及包含该安全IO终端的安全系统。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122804200A_ABST
    Figure CN122804200A_ABST
Patent Text Reader

Abstract

Provided are a safety IO terminal capable of performing safety control based on data from a plurality of safety controllers and a safety system including the safety IO terminal. The safety IO terminal includes a safety output circuit that outputs a safety output signal; a safety communication section that is capable of establishing a safety connection with one or more safety controllers; a received data storage section that includes a plurality of independent areas for storing data received by the safety communication section by safety connection; and a safety logic execution section that determines a value of the safety output signal using arbitrary data stored in the plurality of independent areas. The plurality of independent areas each have associated therewith identification information of a safety controller that establishes a safety connection with the safety IO terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to secure I / O terminals and secure systems. Background Technology

[0002] In manufacturing settings, in addition to control devices for equipment or machinery, safety systems are sometimes implemented. Safety systems are used to prevent equipment, machinery, and other threats to human safety.

[0003] A security system may sometimes consist of a security controller for performing security controls, and one or more security I / O terminals for processing security input signals and security output signals.

[0004] Regarding secure I / O terminals, for example, Japanese Patent Application Publication No. 2014-098985 (Patent Document 1) discloses a secure slave unit that can reduce the processing burden of the security controller.

[0005] Existing technical documents

[0006] Patent documents

[0007] Patent Document 1: Japanese Patent Application Publication No. 2014-098985 Summary of the Invention

[0008] The problem that the invention aims to solve

[0009] Typically, a secure I / O terminal is managed by a single security controller. However, the inventors of this application have obtained a novel insight: depending on the application of the security system, it is more preferable for a secure I / O terminal to communicate with multiple security controllers.

[0010] One object of the present invention is to provide a secure I / O terminal capable of performing secure control based on data from multiple security controllers, and a security system including the secure I / O terminal.

[0011] Methods for solving problems

[0012] A secure I / O terminal in one embodiment includes: a secure output circuit that outputs a secure output signal; a secure communication unit capable of establishing a secure connection with one or more secure controllers; a data receiving and storage unit comprising multiple independent areas for storing data received by the secure communication unit according to the secure connection; and a secure logic execution unit that uses arbitrary data stored in the multiple independent areas to determine the value of the secure output signal. Each of the multiple independent areas is configured to be associated with identification information for determining the secure controller that establishes a secure connection with the secure I / O terminal.

[0013] According to this structure, data from multiple security controllers are stored in multiple independent areas of the security I / O terminal. The security I / O terminal can use any data stored in these multiple independent areas to determine the value of the security output signal, thus enabling the implementation of appropriate security logic using data from multiple security controllers, depending on the application.

[0014] Alternatively, one or more security controllers may each send a request to the secure I / O terminal, containing the security controller's identification information and a specification of the independent area to be used, in order to establish a secure connection. This structure prevents data from being incorrectly stored in an independent area that is different from the independent area corresponding to the connection between the security controller and the secure I / O terminal.

[0015] Alternatively, if no identification information is associated with the independent area specified in the request, the security communications unit will associate the identification information included in the request with that independent area. Based on this structure, in situations such as factory shipment status, any security controller can be connected to a security I / O terminal.

[0016] Alternatively, if the identification information associated with the independent region specified in the request matches the identification information included in the request, the secure communication unit establishes a secure connection according to the request. Based on this structure, a connection between the security controller and the secure I / O terminal can be established after confirming that the specified independent region is correct.

[0017] The secure I / O terminal may also include a storage unit for storing a list of identification information, which contains identification information associated with each independent region. According to this structure, even when the independent regions are constructed of volatile storage devices, the identification information associated with each independent region can be managed.

[0018] Alternatively, the safety logic execution unit can perform a logical OR operation with the value of the first data stored in the first independent region of the multiple independent regions and the value of the second data stored in the second independent region of the multiple independent regions as inputs. According to this structure, a safety output signal can be maintained as long as it is connected to any of the multiple safety controllers.

[0019] Alternatively, the safety logic execution unit can perform a logical AND operation with the value of the first data stored in the first independent region of the multiple independent regions and the value of the second data stored in the second independent region of the multiple independent regions as inputs. Based on this structure, the safety output signal can be cut off from any of the multiple safety controllers.

[0020] A secure connection can be established based on at least one of CIP Safety and PROFIsafe. This architecture enables the establishment of secure connections using common communication protocols.

[0021] Another embodiment of the security system includes: a secure I / O terminal; and one or more security controllers capable of executing a security program based on secure input data received from the secure I / O terminal. The secure I / O terminal includes: a secure input circuit that receives secure input signals; a secure output circuit that outputs secure output signals; a secure communication unit capable of establishing a secure connection with one or more security controllers; a data receiving and storage unit comprising multiple independent areas for storing data received by the secure communication unit according to the secure connection; and a secure logic execution unit that uses arbitrary data stored in the multiple independent areas to determine the value of the secure output signal. Each of the multiple independent areas is configured to store identification information for determining the security controller that has established a secure connection with the secure I / O terminal.

[0022] The effects of the invention

[0023] According to the present invention, a secure I / O terminal capable of performing secure control based on data from multiple security controllers and a security system including the secure I / O terminal can be realized. Attached Figure Description

[0024] Figure 1 This is a schematic diagram illustrating a structural example of the safety system in this embodiment.

[0025] Figure 2 This is a schematic diagram illustrating an example of the hardware structure of the security controller of the security system in this embodiment.

[0026] Figure 3 This is a schematic diagram illustrating an example of the hardware structure of a secure I / O terminal constituting the secure system of this embodiment.

[0027] Figure 4 This is a schematic diagram illustrating the functional structure of a secure I / O terminal for related technologies.

[0028] Figure 5 This is a schematic diagram illustrating an example of the functional structure of a secure I / O terminal constituting the secure system of this embodiment.

[0029] Figure 6 This is a sequence diagram illustrating an example of the communication process when the secure I / O terminal of this embodiment is in a factory shipment state.

[0030] Figure 7 This is a sequence diagram illustrating an example of the communication process during the normal startup of the secure I / O terminal in this embodiment.

[0031] Figure 8 is a schematic diagram showing a structural example of a safety system 1A that uses a conveying robot equipped with the safety IO terminal according to the present embodiment.

[0032] Figure 9 is a diagram showing Figure 8 is a flow chart showing an example of the operation process of the safety system shown in

[0033] Figure 10 is a schematic diagram showing a structural example of a safety system capable of zone-based safety control according to the present embodiment.

[0034] Figure 11 is a diagram for comparing the characteristics of devices constituting the safety system of the present embodiment. DETAILED DESCRIPTION OF EMBODIMENTS

[0035] Embodiments of the present technology will be described in detail with reference to the accompanying drawings. In addition, the same or corresponding parts in the drawings are denoted by the same reference numerals, and repeated description thereof will be omitted.

[0036] <A. Application Example>

[0037] First, an example of a scenario to which the present invention is applied will be described.

[0038] Figure 1 is a schematic diagram showing a structural example of the safety system 1 according to the present embodiment. With reference to Figure 1 , as an example, the safety system 1 includes safety controllers 100-1 and 100-2 (hereinafter also collectively referred to as "safety controllers 100") and a safety IO terminal 200.

[0039] Figure 1 shows a structural example in which the safety controller 100 and the safety IO terminal 200 are wired-connected via a network 2, but a structure in which they are wirelessly connected may also be employed. The network 2 may also employ industrial network protocols such as EtherCAT (registered trademark), EtherNet / IP (registered trademark), PROFIBUS, and PROFINET.

[0040] The safety controller 100 executes a pre-created safety program. The safety program includes a combination of commands for implementing processing for preventing human safety from being threatened by equipment, machinery, etc. The safety controller 100 includes, for example, an operation unit for executing the safety program. The safety control executed by the safety controller 100 is designed to satisfy the requirements specified in IEC61508, which is a functional safety standard.

[0041] The safety I / O terminal 200 includes a safety output circuit that outputs a safety output signal (e.g., a binary signal of True / False). The safety I / O terminal 200 outputs a safety output signal according to the output value of the safety controller 100 (hereinafter also referred to as the "safety output value").

[0042] The security I / O terminal 200 may also include a security input circuit that accepts security input signals (e.g., binary signals of True / False). The security I / O terminal 200 sends the value of the accepted security input signal (hereinafter also referred to as the "security input value") to the security controller 100.

[0043] One or more secure input values ​​can be sent as a set of data, and one or more secure output values ​​can also be sent as a set of data. Therefore, one or more secure input values ​​are referred to as "secure input data," and one or more secure outputs are referred to as "secure output data."

[0044] The security controller 100 is capable of executing a security program based on security input values ​​received from the security I / O terminal 200. The security controller 100 is also capable of sending security output data determined by the execution of the security program to the security I / O terminal 200. In this way, the security I / O terminal 200 functions as a remote I / O device of the security controller 100.

[0045] The safety controller 100 may also include a signal processing unit (e.g., a safety I / O unit) for processing safety input / output signals.

[0046] The secure I / O terminal 200 can establish secure connections with multiple security controllers 100 in parallel. A secure connection is established between the security controller 100 and the secure I / O terminal 200.

[0047] A secure connection is a logical connection established in accordance with a secure communication protocol. The secure communication protocol uses protocols that meet the levels specified in IEC 61508, a functional safety standard (e.g., SIL3 (Safety Integrity Level 3)). For example, protocols such as CIP Safety and PROFIsafe can be used. That is, a secure connection can be established based on at least one of CIP Safety and PROFIsafe. However, the secure communication protocol can be any protocol as long as it meets the levels specified in IEC 61508.

[0048] For example, the safety IO terminal 200 exchanges safety input values and safety output data with the safety controller 100-1, and also exchanges safety input values and safety output data with the safety controller 100-2 in parallel. In addition, the safety IO terminal 200 does not necessarily need to exchange data with all safety controllers 100 at all times. For example, the safety IO terminal 200 may also exchange data only with the safety controller 100-1 in a specific period, and exchange data only with the safety controller 100-2 in other periods.

[0049] The safety IO terminal 200 can execute safety logic for determining values of one or more safety output data based on one or more safety input values. The scale of the safety logic executable by the safety IO terminal 200 is smaller than that of the safety program executed by the safety controller 100.

[0050] In the safety logic executable by the safety IO terminal 200, safety output data from the safety controller 100 can also be processed as safety input values. The safety IO terminal 200 can establish safety connections with a plurality of safety controllers 100 in parallel, therefore, for example, safety logic based on safety output data from the safety controller 100-1 and safety output data from the safety controller 100-2 can be configured.

[0051] Figure 1 shows an example where: in the safety IO terminal 200, a safety logic 290 for determining the safety output value of the safety IO terminal 200 is configured through an OR circuit (logical OR) of a safety output value 1 (a value included in the safety output data) from the safety controller 100-1 and a safety output value 2 from the safety controller 100-2. By configuring the safety logic 290, a safety device (such as a safety relay, a safety driver, etc.) connected to the safety IO terminal 200 can be actuated by either of the safety controllers 100-1 and 100-2.

[0052] In addition, a support device for creating, transferring, changing, etc. the safety program and / or the safety logic 290 can also be connected to the safety controller 100 and the safety IO terminal 200.

[0053] <B. Example of Hardware Structure of Safety System 1>

[0054] Next, an example of the hardware structure of the safety system 1 will be described.

[0055] (b1: Safety Controller 100)

[0056] Figure 2 is a schematic diagram showing an example of the hardware structure of the safety controller 100 of the safety system 1 according to the present embodiment.

[0057] with reference to Figure 2 The security controller 100 includes arithmetic circuits 110 and 120, storage devices 130 and 140, communication circuit 102, internal bus circuit 104, and memory card interface 106.

[0058] The arithmetic circuits 110 and 120 execute programs (system program 132 and security program 134, etc.) stored in storage devices 130 and 140, respectively. The arithmetic circuits 110 and 120 compare their calculation results. If the results are inconsistent, it is determined that some kind of anomaly has occurred.

[0059] The arithmetic circuit 110 includes a processor 112 and a memory 114. The arithmetic circuit 120 includes a processor 122 and a memory 124.

[0060] Processors 112 and 122 are composed of, for example, CPU (Central Processing Unit) and GPU (Graphics Processing Unit).

[0061] The memories 114 and 124 are composed of volatile storage devices such as DRAM (Dynamic Random Access Memory) and SRAM (Static Random Access Memory).

[0062] Storage devices 130 and 140 are, for example, composed of non-volatile storage devices such as FROM (Flash Read-Only Memory) and EEPROM (Electrically Erasable Programmable Read-Only Memory).

[0063] System program 132 contains computer-readable commands for providing an execution environment, which is used by arithmetic circuits 110 and 120 to execute the program. Safety program 134 contains computer-readable commands for implementing processing to prevent human safety from being threatened by equipment or machinery. Safety program 134 may also be described in accordance with standards such as IEC 61131-3.

[0064] The communication circuit 102 is responsible for communication with other devices (other security controllers 100, security I / O terminals 200, etc.) via the network 2.

[0065] The internal bus circuit 104 is responsible for communication with security units (not shown). Like the security I / O terminal 200, the security unit includes at least one of a security input circuit that accepts security input signals and a security output circuit that outputs security output signals.

[0066] The memory card interface 106 reads and writes arbitrary data to a memory card 108, which is an example of a removable storage medium.

[0067] (b2: Secure I / O Terminal 200)

[0068] Figure 3 This is a schematic diagram illustrating an example of the hardware structure of the security I / O terminal 200 constituting the security system 1 of this embodiment.

[0069] Reference Figure 3 The secure I / O terminal 200 includes arithmetic circuits 210 and 220, storage devices 230 and 232, communication circuit 202, secure input circuit 204, and secure output circuit 206.

[0070] The arithmetic circuits 210 and 220 execute programs (system program 234 and security logic 290, etc.) stored in storage devices 230 and 232, respectively. The arithmetic circuits 210 and 220 compare their calculation results. If the results are inconsistent, it is determined that some kind of anomaly has occurred.

[0071] The arithmetic circuit 210 includes a processor 212 and a memory 214. The arithmetic circuit 220 includes a processor 222 and a memory 224.

[0072] Processors 212 and 222 are composed of, for example, CPUs, GPUs, etc.

[0073] The memory 214 and 224 are composed of volatile storage devices such as DRAM and SRAM.

[0074] Storage devices 230 and 232 are, for example, composed of non-volatile storage devices such as FROM and EEPROM.

[0075] System program 234 contains computer-readable commands to provide an execution environment, which is used by arithmetic circuits 210 and 220 to execute the program. Safety logic 290 defines the logical relationship between safety input signals input to safety input circuit 204 and / or safety output values ​​from safety controller 100 and one or more safety output values. Safety logic 290 can be described using OR (logical OR) and AND (logical AND) circuits.

[0076] The communication circuit 202 is responsible for communicating with other devices (such as the safety controller 100) via the network 2. The communication circuit 202 may also include a storage unit for storing data (such as safety output values) received from the safety controller 100.

[0077] The safety input circuit 204 receives safety input signals from one or more safety devices (e.g., safety light curtains, safety laser scanners, safety door switches, safety limit switches, safety mats, emergency stop push-button switches, etc.). The circuit structure of the safety input circuit 204 may also vary depending on the type of safety device.

[0078] The safety output circuit 206 outputs safety output signals to one or more safety devices (e.g., safety relays, safety drives, etc.). The circuit structure of the safety output circuit 206 may also vary depending on the type of safety device.

[0079] (b3: Other aspects)

[0080] In this specification, the term "processor" includes processing circuits such as CPUs and GPUs that execute processing in a stored-program manner, as well as dedicated hardware circuits with pre-fixed programs (e.g., ASIC (Application Specific Integrated Circuit) or FPGA (Field-Programmable Gate Array), etc.).

[0081] In this specification, the term "memory" includes both non-volatile storage devices and volatile storage devices.

[0082] <C. Example of Functional Structure of Safety IO Terminal>

[0083] Next, an example of the functional structure of the safety IO terminal 200 according to the present embodiment will be described.

[0084] Figure 4 is a schematic diagram showing an example of the functional structure of a safety IO terminal 200A in the related art. With reference to Figure 4 , the safety IO terminal 200A includes a safety communication function 240A, a received data storage area 250A, and a safety output function 270A.

[0085] The safety communication function 240A is implemented by the communication circuit 202 ( Figure 3 ) and / or the arithmetic circuits 210, 220 executing the system program 234.

[0086] The receive data storage area 250A is implemented using the memory 214 of the arithmetic circuit 210 and the memory 224 of the arithmetic circuit 220. The receive data storage area 250A can also be implemented using a memory prepared within the communication circuit 202.

[0087] Safety output function 270A via safety output circuit 206 ( Figure 3 The system program 234 is implemented by the execution of the system program 234 by the arithmetic circuits 210 and 220.

[0088] exist Figure 4 In the illustrated functional architecture example, a secure connection 10-1 is established between the security controller 100-1 and the security I / O terminal 200. The secure connection 10-1 is, for example, based on the CIP Safety protocol.

[0089] Data sent from the security controller 100-1 (security output data) is stored in the receive data storage area 250A. The receive data storage area 250A directly controls the security output signal from the security I / O terminal 200. That is, the security output data stored in the receive data storage area 250A is directly assigned to the security output function 270A. For example, if the security output data is byte data, the security output function 270A directly determines the value (True / False) of the pre-specified (pre-allocated) bits in the byte data as the security output value. Then, the security output function 270A outputs a security output signal representing the pre-specified bit value.

[0090] In the secure I / O terminal 200A according to related technologies, the data storage area 250A is associated with only one secure connection. Therefore, when the secure I / O terminal 200A has established a secure connection 10-1 with the security controller 100-1, it cannot establish other secure connections 10-2 with the security controller 100-2. That is, the secure I / O terminal 200A establishes an exclusive secure connection with the security controller 100.

[0091] Therefore, the security output function 270A of the security I / O terminal 200A cannot simultaneously reference security output data from multiple security controllers 100.

[0092] Figure 5 This is a schematic diagram illustrating a functional structure example of the security I / O terminal 200 constituting the security system 1 of this embodiment.

[0093] Reference Figure 5 The secure I / O terminal 200 includes a secure communication function 240, a data receiving and storage area 250, a secure logic function 260, a secure output function 270, and a connection history storage unit 280.

[0094] The secure communication function 240 is equivalent to a secure communication unit, which is connected by the communication circuit 202 ( Figure 3 The system program 234 is implemented by the execution of the arithmetic circuits 210 and 220. The secure communication function 240 can establish a secure connection with one or more security controllers 100.

[0095] The receive data storage area 250 is equivalent to a receive data storage unit, and is implemented using the memory 214 of the arithmetic circuit 210 and the memory 224 of the arithmetic circuit 220. The receive data storage area 250 can also be implemented using a memory prepared within the communication circuit 202.

[0096] The safety logic function 260 is equivalent to the safety logic execution unit, which is implemented by the arithmetic circuits 210 and 220 executing the system program 234 and the safety logic 290.

[0097] Safety output function 270 via safety output circuit 206 ( Figure 3 The system program 234 is executed by the arithmetic circuits 210 and 220.

[0098] The connection to the history preservation unit 280 is achieved using storage devices 230 and 232.

[0099] exist Figure 5 In the illustrated functional architecture example, a secure connection 10-1 is established between the security controller 100-1 and the secure I / O terminal 200. A secure connection 10-2 is established between the security controller 100-2 and the secure I / O terminal 200. Secure connections 10-1 and 10-2 (hereinafter, also collectively referred to as "secure connection 10") are, for example, based on the CIP Safety protocol.

[0100] The received data storage area 250 includes separate areas 252-1, 252-2, ... (hereinafter collectively referred to as "separate areas 252") for storing data received by the secure communication function 240 via the secure connection 10. Separate areas 252 and received data storage area 250A ( Figure 4 Unlike other secure controllers, it does not directly control secure output signals from secure I / O terminal 200. Each independent area 252 is associated with secure connection 10. Each independent area 252 is a storage area used to store data (secure output values, etc.) received from secure controller 100 according to the secure connection.

[0101] Multiple independent regions 252 are each configured to be associated with identification information for determining the security controller 100 that establishes a secure connection with the secure I / O terminal 200. More specifically, independent regions 252-1, 252-2, ... contain areas for storing identification information 254-1, 254-2, ... (hereinafter collectively referred to as "identification information 254"), which indicates which security controller 100 the stored received data is associated with. Security controllers 100-1, 100-2, ... have identification information 154-1, 154-2, ... (hereinafter collectively referred to as "identification information 154"). For example, in the CIP Safety protocol, an "initiator ID" can be used as identification information 154, 254.

[0102] Security logic function 260 uses arbitrary data stored in independent areas 252-1, 252-2, ... to determine the value of the security output signal. More specifically, security logic function 260 includes input processing 262, logic processing 264, and output processing 266. Security logic function 260 reflects security logic 290. Input processing 262 includes processing to determine a security input value based on received data stored in one or more pre-specified independent areas 252. Logic processing 264 includes processing to determine one or more security output values ​​based on one or more pre-specified security input values. Output processing 266 includes processing to provide a security output value to security output function 270.

[0103] One or more data referenced in input processing 262 (security output values) can also be specified when the user creates security logic 290. Security logic 290 includes the specification of values ​​contained in the received data used as security input values. Alternatively, the settings (data allocation) of data used as security input values ​​for security logic 290 can be prepared separately from security logic 290. The data settings can also be stored in storage devices 230, 232 ( Figure 3 )middle.

[0104] In the following discussion Figure 8 In the security logic 290 shown, the security logic function 260 performs a logical OR operation with the value represented by the received data stored in independent area 252-1 and the value represented by the received data stored in independent area 252-2 as inputs.

[0105] In the following discussion Figure 10 In the security logic 290 shown, the security logic function 260 performs a logical AND operation with the value represented by the received data stored in independent area 252-1 and the value represented by the received data stored in independent area 252-2 as inputs.

[0106] The safety output function 270 outputs a safety output signal representing the safety output value output from the safety logic function 260.

[0107] The connection history storage unit 280, which functions as a storage unit, stores the identification information list 282. The identification information list 282 contains identification information 254 associated with each independent region 252. If a security connection 10 is established with a new security controller 100, the identification information 154 of the security controller 100 is associated with an independent region 252 that is not associated with any identification information 254, and the associated identification information 154 (identification information 254) is appended to the identification information list 282. Thus, when identification information 254 is temporarily associated with each independent region 252 of the received data storage area 250, the association of identification information 254 is maintained until initialization, reset, or similar processes are performed.

[0108] For example, in the factory shipment state, the identification information 254 of the independent area 252 of the security I / O terminal 200 indicates "null". The identification information 154 of the security controller 100, which initially established a secure connection 10 with each independent area 252, is stored.

[0109] When the secure I / O terminal 200 starts, it refers to the identification information list 282 and saves the associated identification information 254 in an independent area 252.

[0110] The command used by the security controller 100 to establish a secure connection 10 with the security I / O terminal 200 includes the designation of a separate area 252 for storing secure output data (received data). That is, one or more security controllers 100 each send a request containing the identification information 154 of each security controller 100 and the designation of the separate area used (area designation 152) to the security I / O terminal 200 in order to establish a secure connection.

[0111] The secure communication function 240 determines whether the identification information 254 associated with the independent area 252 specified by the command matches the identification information 154 of the security controller 100, which is the source of the command. If the identification information 154 matches the identification information 254, the secure communication function 240 allows the establishment of a secure connection; otherwise, it does not.

[0112] By determining whether a secure connection can be established based on identification information, even when the secure I / O terminal 200 establishes a secure connection 10 with multiple security controllers 100, the security controller 100, which is the source of the receiving data stored in the independent area 252, can still be guaranteed.

[0113] In this way, the safety IO terminal 200 of the present embodiment can perform safety communication with a plurality of safety controllers 100. The safety IO terminal 200 can input any value among the data respectively received from the plurality of safety controllers 100, and perform logic processing 264.

[0114] <D. Communication Process between Safety Controller 100 and Safety IO Terminal 200>

[0115] Next, an example of the communication process between the safety controller 100 and the safety IO terminal 200 will be described.

[0116] Figure 6 is a sequence diagram showing an example of the communication process when the safety IO terminal 200 of the present embodiment is in a factory shipment state. Figure 6 An example of the communication process when the safety IO terminal 200 establishes safety connections 10-1 and 10-2 with the safety controllers 100-1 and 100-2 respectively is shown. It is assumed that the safety controllers 100-1 and 100-2 are originators in the CIP Safety protocol.

[0117] In Figure 6 , the processing executed by the safety IO terminal 200 may also be undertaken by the Figure 5 safety communication function 240.

[0118] Referring to Figure 6 , the safety controller 100-1 serving as an originator sends a safety communication establishment command 150-1 to the safety IO terminal 200 according to settings (sequence SQ10). The safety communication establishment command 150-1 includes identification information 154-1 of the safety controller 100-1, and an area designation 152-1 for designating an independent area 252 (the independent area 252-1 in this example) to be used in the safety IO terminal 200.

[0119] When the safety IO terminal 200 receives the safety communication establishment command 150-1, it determines whether any identification information 254-1 is associated with the independent area 252-1 designated by the area designation 152-1. In Figure 6In the example shown, the value of identification information 254-1 associated with independent region 252-1 is "empty". Therefore, the secure I / O terminal 200 associates identification information 154-1 contained in the secure communication establishment command 150-1 with independent region 252-1 (sequence SQ12). As a result, the value of identification information 254-1 is changed from "empty" to "xxxx" (identification information 154-1 of security controller 100-1). The secure I / O terminal 200 saves the newly associated identification information 254-1 in identification information list 282 (sequence SQ14). Then, the secure I / O terminal 200 sends an OK response to security controller 100-1 (sequence SQ16).

[0120] Thus, secure I / O terminal 200 ( Figure 5 (Secure communication function 240) If no identification information 254 is associated with the independent region 252 specified by the request, then the identification information 154 contained in the request is associated with the independent region 252.

[0121] Through the above communication process, a secure connection 10-1 is established between the security controller 100-1 and the security I / O terminal 200. Secure communication (sending and receiving secure output data and secure input data) (sequence SQ18) is repeatedly performed between the security controller 100-1 and the security I / O terminal 200.

[0122] Similarly, the security controller 100-2, as the initiator, sends a secure communication establishment command 150-2 to the secure I / O terminal 200 (sequence SQ20) according to the settings. The secure communication establishment command 150-2 includes the identification information 154-2 of the security controller 100-2, and the region designation 152-2 for specifying the independent region 252 (in this example, independent region 252-2) used in the secure I / O terminal 200.

[0123] When the secure I / O terminal 200 receives the secure communication establishment command 150-2, it determines whether the independent region 252-2 specified by the region designation 152-2 is associated with certain identification information 254-2. Figure 6In the example shown, the value of identification information 254-2 associated with independent region 252-2 is "empty". Therefore, the secure I / O terminal 200 associates identification information 154-2 contained in the secure communication establishment command 150-2 with independent region 252-2 (sequence SQ22). As a result, the value of identification information 254-2 is changed from "empty" to "yyyy" (identification information 154-2 of security controller 100-2). The secure I / O terminal 200 saves the newly associated identification information 254-2 in identification information list 282 (sequence SQ24). Then, the secure I / O terminal 200 sends an OK response to security controller 100-1 (sequence SQ26).

[0124] Through the above communication process, a secure connection 10-2 is established between the security controller 100-2 and the secure I / O terminal 200. Secure communication (sending and receiving secure output data and secure input data) is repeatedly performed between the security controller 100-2 and the secure I / O terminal 200 (sequence SQ28).

[0125] Figure 7 This is a sequence diagram illustrating an example of the communication process during the normal startup of the secure I / O terminal 200 in this embodiment. Figure 7 In the process, the secure I / O terminal 200 has sometimes established a secure connection 10-1 with the security controllers 100-1 and 100-2, respectively. Therefore, the identification information of the security controllers 100-1 and 100-2 is stored in the identification information list 282.

[0126] exist Figure 7 In the process, the processing performed by the secure I / O terminal 200 can also be handled by... Figure 5 The secure communication function 240 is responsible for.

[0127] Additionally, safety controller 100-3 needs to establish a secure connection with security I / O terminal 200. Assume that safety controllers 100-1, 100-2, and 100-3 are the initiators in the CIP Safety protocol.

[0128] Reference Figure 7 As the initiator, the security controller 100-1 sends a secure communication establishment command 150-1 to the secure I / O terminal 200 according to the settings (sequence SQ50). When the secure I / O terminal 200 receives the secure communication establishment command 150-1, it determines whether the identification information 254-1 associated with the independent region 252-1 specified by the region designation 152-1 is consistent with the identification information 154-1 contained in the secure communication establishment command 150-1 (sequence SQ52).

[0129] If the identification information 254-1 associated with independent region 252-1 matches the identification information 154-1 contained in the secure communication establishment command 150-1, then the secure I / O terminal 200 sends an OK response to the security controller 100-1 (sequence SQ54). Through the above communication process, a secure connection 10-1 is (again) established between the security controller 100-1 and the secure I / O terminal 200. Secure communication (sending and receiving secure output data and secure input data) is repeatedly performed between the security controller 100-1 and the secure I / O terminal 200 (sequence SQ56).

[0130] Thus, if the identification information 254 associated with the independent region 252 specified by the request matches the identification information 154 included in the request, then the secure I / O terminal 200 ( Figure 5 (Secure Communication Function 240) Establishes a secure connection upon request.

[0131] On the other hand, the security controller 100-3, as the initiator, sends a secure communication establishment command 150-3 to the secure I / O terminal 200 according to the settings (sequence SQ60). When the secure I / O terminal 200 receives the secure communication establishment command 150-3, it determines whether the identification information 254-2 associated with the independent region 252-2 specified by the region designation 152-3 is consistent with the identification information 154-3 contained in the secure communication establishment command 150-3 (sequence SQ62).

[0132] If the identification information 254-2 associated with independent region 252-2 is inconsistent with the identification information 154-3 contained in the secure communication establishment command 150-3, the secure I / O terminal 200 sends an NG response to the security controller 100-3 (sequence SQ64). Through the above communication process, a secure connection 10 is not established between the security controller 100-3 and the secure I / O terminal 200.

[0133] Additionally, the security controller 100-2, acting as the initiator, sends a secure communication establishment command 150-2 to the secure I / O terminal 200 (sequence SQ70) according to its settings. Upon receiving the secure communication establishment command 150-2, the secure I / O terminal 200 determines whether the identification information 254-2 associated with the independent region 252-2 specified by the region designation 152-2 is consistent with the identification information 154-2 contained in the secure communication establishment command 150-2 (sequence SQ72).

[0134] If the identification information 254-2 associated with the independent area 252-2 matches the identification information 154-2 included in the secure communication establishment command 150-2, the safe IO terminal 200 sends an OK response to the safety controller 100-2 (sequence SQ74). Through the above communication process, the secure connection 10-2 between the safety controller 100-2 and the safe IO terminal 200 is (re-)established. Secure communication (transmission and reception of safety output data and safety input data) is repeatedly executed between the safety controller 100-2 and the safe IO terminal 200 (sequence SQ76).

[0135] <E. Application Example>

[0136] Next, an example of an application using the safe IO terminal 200 according to the present embodiment will be described.

[0137] (e1: Transfer Robot)

[0138] First, a safety system using a transfer robot 300 equipped with the safe IO terminal 200 according to the present embodiment will be described.

[0139] Figure 8 is a schematic diagram showing a structural example of the safety system 1A using the transfer robot 300 equipped with the safe IO terminal 200 according to the present embodiment. With reference to Figure 8 , the safety system 1A includes safety controllers 100-1, 100-2, and the transfer robot 300 equipped with the safe IO terminal 200.

[0140] The safety controller 100-1 is connected to a wireless repeater 180-1. When the transfer robot 300 is located in zone 1, the safety controller 100-1 establishes a secure connection with the safe IO terminal 200 via a wireless connection.

[0141] Similarly, the safety controller 100-2 is connected to a wireless repeater 180-2. When the transfer robot 300 is located in zone 2, the safety controller 100-2 establishes a secure connection with the safe IO terminal 200 via a wireless connection.

[0142] In the safety system 1A, even when the transfer robot 300 travels back and forth between zone 1 and zone 2, at least one of the safety controller 100-1 and the safety controller 100-2 is required to manage the safe IO terminal 200.

[0143] Normally, the safety output signal of the safety I / O terminal 200 represents True (on) under normal conditions, according to the safety output value received from the safety controller 100. Therefore, if the safety connection between the safety controller 100 and the safety I / O terminal 200 is severed, the safety I / O terminal 200 cannot receive the safety output value from the safety controller 100, and the safety output signal of the safety I / O terminal 200 represents False (off). That is, the safety output signal is cut off. As a result, an instruction is issued to the handling robot 300 and / or the equipment mounted on the handling robot 300 to perform a safety action (usually a stop).

[0144] The safety I / O terminal 200 of this embodiment can establish safety connections in parallel with multiple safety controllers 100. More specifically, when the handling robot 300 is present in zone 1, the safety I / O terminal 200 can receive safety output data from safety controller 100-1, and when the handling robot 300 is present in zone 2, the safety I / O terminal 200 can receive safety output data from safety controller 100-2.

[0145] Therefore, in the safety I / O terminal 200, by constructing a safety logic 290 that includes an OR circuit (logical OR) of safety output data from safety controller 100-1 and safety output data from safety controller 100-2, the safety output signal can be maintained regardless of which zone the handling robot 300 is located in.

[0146] exist Figure 8 The example shown illustrates a security logic 290 that outputs a security output value 293 as a logical OR of the value of the first bit of the received data 291 (security output data) received from security controller 100-1 and the value of the first bit of the received data 292 (security output data) received from security controller 100-2. By employing such security logic 290, the output of the security output signal can continue.

[0147] Figure 9 It means Figure 8 The flowchart illustrates an example of the operation of security system 1A. (Refer to...) Figure 9 The user provides settings to security controllers 100-1 and 100-2 for establishing a secure connection with security I / O terminal 200 (step S2). The user provides settings to security logic 290 to security I / O terminal 200 (step S4).

[0148] For example, the user configures the handling robot 300 in area 1 (step S6). Then, the user starts the safety controllers 100-1, 100-2 and the safety I / O terminal 200 and sets them to normal operating status (step S8).

[0149] Safety controller 100-1 establishes a secure connection with safety I / O terminal 200 mounted on handling robot 300 (step S10). Safety I / O terminal 200 outputs a safety output signal based on received data 291 (safety output data) received from safety controller 100-1 (step S12).

[0150] Next, when the handling robot 300 moves to area 2 (Yes in step S14), the secure connection between the safety controller 100-1 and the safety I / O terminal 200 is severed (step S16). On the other hand, the safety controller 100-2 establishes a secure connection with the safety I / O terminal 200 (step S18). The safety I / O terminal 200 outputs a safety output signal based on the received data 292 (safety output data) received from the safety controller 100-2 (step S20).

[0151] Then, when the handling robot 300 moves to area 1 (yes in step S22), the safety connection between the safety controller 100-2 and the safety I / O terminal 200 is cut off (step S24). Then, the process from step S10 onwards is repeated.

[0152] (e2: Security controls across multiple zones)

[0153] Next, an example of security control spanning multiple zones will be explained.

[0154] Figure 10 This is a schematic diagram illustrating a structural example of a safety system 1B capable of performing safety control over the area described in this embodiment. (Refer to...) Figure 10 Security system 1B includes security controllers 100-1 and 100-2 and a security I / O terminal 200 that are interconnected via network 2.

[0155] Safety I / O terminal 200 is connected to a safety device (e.g., safety relay 40, light curtain) for stopping equipment crossing zones 1 and 2. Safety controller 100-1 is connected as a safety device to emergency stop switch 30-1. Safety controller 100-2 is connected as a safety device to emergency stop switch 30-2.

[0156] In safety system 1B, the equipment can be stopped via safety relay 40 regardless of whether either emergency stop switch 30-1 or emergency stop switch 30-2 is pressed.

[0157] In the safety I / O terminal 200, by constructing a safety logic 290 that includes an AND circuit containing safety output data from safety controller 100-1 and safety output data from safety controller 100-2, the safety relay 40 can be cut off regardless of which of the emergency stop switches 30-1 and 30-2 is pressed.

[0158] In Figure 10 the illustrated example, there is shown an example of safety logic 290 that outputs the logical AND of the value of the first bit of received data 291 (safety output data) received from the safety controller 100-1 and the value of the first bit of received data 292 (safety output data) received from the safety controller 100-2 as a safety output value 293.

[0159] In this way, the safety IO terminal 200 of the present embodiment can easily implement safety control across a plurality of zones.

[0160] <F. Safety Controllers and Safety IO Terminals>

[0161] A comparative description of the above safety controller 100 and safety IO terminal 200 will be given below.

[0162] Figure 11 is a diagram for comparing the characteristics of the devices constituting the safety system 1 of the present embodiment. Figure 11 descriptions of items regarding safety connections, number of connections, safety control, and cost are shown for the safety controller 100 and the safety IO terminal 200, respectively.

[0163] Regarding safety connections, the safety controller 100 is an originator in the CIP Safety protocol. In contrast, the safety IO terminal 200 is a target in the CIP Safety protocol.

[0164] Regarding the number of connections, the safety controller 100 can establish a relatively large number of connections simultaneously, whereas the number of connections that the safety IO terminal 200 can establish simultaneously is relatively small.

[0165] Regarding safety control, in the safety controller 100, any arbitrary safety program can be created, whereas in the safety IO terminal 200, only small-scale safety logic can be created. In addition, the safety logic available in the safety IO terminal 200 may only be pre-prepared and cannot be added or changed by a user.

[0166] Regarding cost, the safety controller 100 requires a relatively high-performance processor and a relatively large-capacity memory and is expensive, whereas the safety IO terminal 200 is mostly equipped with the minimum required processor and memory.

[0167] <G. Modifications>

[0168] In the above description, an example structure in which the safety IO terminal 200 establishes a safety connection with two safety controllers 100 is illustrated, but a safety connection may also be established with more safety controllers 100. In this case, safety output values from three or more safety controllers may also be input to an OR circuit (logical OR) and / or an AND circuit (logical AND).

[0169] <H.Supplementary Notes>

[0170] The present embodiment as described above includes the following technical ideas.

[0171] [Structure 1]

[0172] A safety IO terminal (200), wherein the safety IO terminal comprises: a safety output circuit (206) that outputs a safety output signal; a safety communication unit (240) that is capable of establishing a safety connection with one or more safety controllers (100); a received data storage unit (250) comprising a plurality of independent regions (252), wherein the plurality of independent regions (252) are used to store data received by the safety communication unit for each safety connection; and a safety logic execution unit (260) that determines the value of the safety output signal using any data stored in the plurality of independent regions, each of the plurality of independent regions is configured to be associated with identification information (254) for determining the safety controller that establishes the safety connection with the safety IO terminal.

[0173] [Structure 2]

[0174] In the safety IO terminal described in Structure 1, in order to establish a safety connection, each of the one or more safety controllers transmits a request (150) including the identification information (154) of the safety controller and a specification (152) of an independent region to be used to the safety IO terminal.

[0175] [Structure 3]

[0176] In the safety IO terminal described in Structure 2, if no identification information is associated with the independent region specified by the request, the safety communication unit associates the identification information included in the request with the independent region (SQ12, SQ14, SQ22, SQ24).

[0177] [Structure 4]

[0178] In the secure I / O terminal described in Structure 2, if the identification information associated with the independent area specified by the request is consistent with the identification information included in the request, the secure communication unit establishes a secure connection (SQ52, SQ54, SQ72, SQ74) according to the request.

[0179] [Structure 5]

[0180] In any of the structures 1 to 4, the secure I / O terminal also has a storage unit (280) for storing an identification information list (282), which contains identification information associated with each independent region.

[0181] [Structure 6]

[0182] In any of the structures 1 to 5, the secure I / O terminal performs a logical OR operation with the value of the first data stored in the first independent region (252-1) of the plurality of independent regions and the value of the second data stored in the second independent region (252-2) of the plurality of independent regions as input.

[0183] [Structure 7]

[0184] In any of the structures 1 to 6, the secure I / O terminal performs a logical AND operation with the value of the first data representation stored in the first independent region (252-1) of the plurality of independent regions and the value of the second data representation stored in the second independent region (252-2) of the plurality of independent regions as input.

[0185] [Structure 8]

[0186] In any of the safety I / O terminals described in structures 1 to 7, the safety connection is established based on at least one of CIP Safety and PROFIsafe.

[0187] [Structure 9]

[0188] A security system, wherein the security system has: Secure I / O terminal (200); and One or more security controllers (100) are capable of executing a security program (134) based on security input data received from the security I / O terminal. The secure I / O terminal has: Safety input circuit (204), which accepts safety input signals; Safety output circuit (206), which outputs a safety output signal; A secure communication unit (240), configured to establish a secure connection with one or more safety controllers; A received data storage unit (250), comprising a plurality of independent regions (252), wherein the plurality of independent regions (252) are configured to store data received by the secure communication unit by secure connection; and A safety logic execution unit (260), configured to determine the value of a safety output signal using any data stored in the plurality of independent regions, each of the plurality of independent regions is configured to store identification information (254) for determining a safety controller that establishes a secure connection with the safety IO terminal.

[0189] <I.Advantages>

[0190] The safety IO terminal according to the present embodiment can establish secure connections with a plurality of safety controllers respectively, and can store data received from each safety controller into independent regions. On this basis, the safety IO terminal can execute safety logic using any data stored in the independent regions. Accordingly, safety logic using data from a plurality of safety controllers can be configured according to an application.

[0191] The embodiment disclosed herein is to be considered as illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims rather than the foregoing description, and is intended to include all modifications within the meaning and scope equivalent to the claims.

[0192] Description of Reference Numerals

[0193] 1, 1A, 1B: Security system; 2: Network; 10: Secure connection; 30: Emergency stop switch; 40: Safety relay; 100: Security controller; 102, 202: Communication circuit; 104: Internal bus circuit; 106: Memory card interface; 108: Memory card; 110, 120, 210, 220: Arithmetic circuit; 112, 122, 212, 222: Processor; 114, 124, 214, 224: Memory; 130, 140, 230, 232: Storage device; 132, 234: System program; 134: Security program; 150: Secure communication establishment command; 152: Area designation; 154, 254: Identification information; 180: Wireless repeater; 200, 200A: Secure I / O terminal; 204: Secure input circuit; 206: Secure output circuit; 240, 240A: Secure communication function; 250, 250A: Received data storage area; 252: Independent area; 260: Secure logic function; 262: Input processing; 264: Logic processing; 266: Output processing; 270, 270A: Secure output function; 280: Connection to history storage unit; 282: Identification information list; 290: Secure logic; 291, 292: Received data; 300: Handling robot.

Claims

1. A secure I / O terminal, wherein, This secure I / O terminal has: The safety output circuit outputs a safety output signal. The secure communications unit is capable of establishing secure connections with one or more security controllers. A data storage unit includes multiple independent areas for storing data received by the secure communication unit via a secure connection. as well as The safety logic execution unit uses arbitrary data stored in the multiple independent areas to determine the value of the safety output signal. Each of the multiple independent regions is associated with identification information for determining a security controller that establishes a secure connection with the secure I / O terminal.

2. The secure I / O terminal according to claim 1, wherein, In order to establish a secure connection, each of the one or more security controllers sends a request, including the security controller's identification information and the designation of the independent area to be used, to the secure I / O terminal.

3. The secure I / O terminal according to claim 2, wherein, If no identification information is associated with the independent area specified by the request, the secure communication unit will associate the identification information contained in the request with that independent area.

4. The secure I / O terminal according to claim 2, wherein, If the identification information associated with the independent area specified by the request matches the identification information included in the request, then the secure communication unit establishes a secure connection according to the request.

5. The secure I / O terminal according to any one of claims 1 to 4, wherein, The secure I / O terminal also has a storage unit for storing a list of identification information, which contains identification information associated with each independent region.

6. The secure I / O terminal according to any one of claims 1 to 5, wherein, The security logic execution unit performs a logical OR operation with the value of the first data stored in the first independent region of the plurality of independent regions and the value of the second data stored in the second independent region of the plurality of independent regions as inputs.

7. The secure I / O terminal according to any one of claims 1 to 6, wherein, The security logic execution unit performs a logical AND operation with the value of the first data stored in the first independent region of the plurality of independent regions and the value of the second data stored in the second independent region of the plurality of independent regions as inputs.

8. The secure I / O terminal according to any one of claims 1 to 7, wherein, The safety connection is established based on at least one of CIP Safety and PROFIsafe.

9. A security system, wherein, This security system has the following features: Secure I / O endpoints; and One or more security controllers are capable of executing security procedures based on security input data received from the security I / O terminal. The secure I / O terminal has: Safety input circuit, which accepts safety input signals; The safety output circuit outputs a safety output signal. The secure communications unit is capable of establishing secure connections with one or more security controllers. A data storage unit includes multiple independent areas for storing data received by the secure communication unit via a secure connection. as well as The safety logic execution unit uses arbitrary data stored in the multiple independent areas to determine the value of the safety output signal. Each of the multiple independent regions is configured to store identification information for a security controller used to determine the establishment of a secure connection with the secure I / O terminal.

Citation Information

Patent Citations

  • Safety slave unit, control method thereof, control program thereof, and safety control system

    JP2014098985A