Safety cooperative control method and device of intelligent robot, and intelligent robot
Patent Information
- Application Number
- CN202610938446.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-26
- Publication Date
- 2026-09-25
Smart Images

Figure CN122807871A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent operation and maintenance execution control technology, and in particular to a safe collaborative control method, device and intelligent robot for intelligent robots. Background Technology
[0002] Currently, high-voltage power distribution rooms are gradually adopting intelligent robots to replace manual labor in tasks such as switching operations, equipment inspections, partial discharge detection, and infrared thermography. These robots need to maintain real-time communication with the backend maintenance platform via wireless network. However, in practical applications, the electromagnetic environment in high-voltage power distribution rooms is complex, and wireless signals are easily interfered with, interrupted, or lost, leading to potential communication failures for the robots. Existing robots often blindly continue execution or shut down immediately after a network outage, which can easily cause malfunctions of the robotic arm, equipment collisions, and personal safety hazards. Furthermore, instrument identification, partial discharge, infrared, and status data collected during the outage are easily lost. Summary of the Invention
[0003] In view of this, the purpose of the present invention is to provide a safe collaborative control method, device and intelligent robot for intelligent robots, so as to improve the operational safety and data integrity of intelligent robots in the complex electromagnetic environment of high voltage power distribution rooms.
[0004] To achieve the above objectives, the technical solutions adopted in the embodiments of the present invention are as follows: In a first aspect, embodiments of the present invention provide a safe collaborative control method for intelligent robots, applied to intelligent robots, including: real-time monitoring of the communication link status between the intelligent robot and a remote operation and maintenance platform; when a communication interruption is detected, immediately triggering a graded safety braking action to physically lock the execution mechanism of the intelligent robot and simultaneously activating a local highest-priority abnormality warning; temporarily storing the continuously collected operation process data during the interruption in a local non-volatile storage unit, and automatically executing the data resume transmission process after the network link is restored.
[0005] Optionally, real-time monitoring of the communication link status between the intelligent robot and the remote operation and maintenance platform includes: monitoring the communication link status between the intelligent robot and the remote operation and maintenance platform through bidirectional periodic heartbeat messages; determining communication interruption when no valid response message is received for a preset number of consecutive times; wherein, under normal communication conditions, the heartbeat message sending interval is a first frequency; when the link signal strength is detected to be lower than a preset strength threshold or the bit error rate exceeds a preset bit error rate threshold, the heartbeat message sending interval is switched to a second frequency higher than the first frequency, and after no valid response message is received for a preset number of consecutive times, the threshold for the number of consecutive unanswered messages required to determine communication interruption is shortened.
[0006] Optionally, when a communication interruption is detected, a graded safety braking action is immediately triggered, including: when the duration of the communication interruption is less than a first preset threshold, a first-level braking action is triggered to cut off the power to the end mechanism; when the duration of the communication interruption reaches or exceeds the first preset threshold but is less than a second preset threshold, a second-level braking action is triggered, including mechanical locking of the end mechanism and parking braking of the mobile chassis; when the duration of the communication interruption reaches or exceeds the second preset threshold, a third-level braking action is triggered, including physical locking of all actuators, energy isolation, and freezing of the digital output channel status, and a braking level change log is written to the local non-volatile storage unit.
[0007] Optionally, the operation process data continuously collected during the interruption can be temporarily stored in a local non-volatile storage unit, including: continuously collecting operation process data during the interruption, and attaching a local trusted timestamp of the collection time, a data length check code, and the current posture identifier of the intelligent robot to each frame of collected operation process data; using the device's unique key stored in the local security chip to digitally sign the preprocessed data frame frame by frame, and after associating the signature result with the original data frame, caching it to the local storage unit in the order of task ID, location ID, and timestamp.
[0008] Optionally, after the network link is restored, the data resume transmission process is automatically executed, including: periodically sending a reconnection signal to the remote operation and maintenance platform, and restoring communication with the remote operation and maintenance platform after the network link is restored, and uploading the network outage event log; uploading cached data in batches in ascending order of timestamp, and waiting for the platform to return a verification response after each batch is transmitted; if any batch verification fails, the batch is retransmitted and the cached data of subsequent batches are not retransmitted.
[0009] Optionally, cached data can be uploaded in batches in ascending order of timestamps, including: dynamically calculating the size of the current optimal batch based on the real-time available bandwidth and round-trip latency after network link recovery; automatically reducing the data size of each batch and increasing the frequency of verification responses when the available bandwidth is lower than the bandwidth threshold; and automatically increasing the data size of each batch to reduce the total number of transmission interactions when the available bandwidth is higher than the bandwidth threshold.
[0010] Optionally, after automatically executing the data resume process, the process also includes: after the data resume is completed, receiving a manual confirmation instruction from the remote operation and maintenance platform and verifying the manual confirmation instruction; if the manual confirmation instruction is successfully verified, the brake lock is released; if the manual confirmation instruction does not arrive within the time limit or the verification fails, the lock state is maintained, and a status heartbeat is pushed to the remote operation and maintenance platform every preset time interval until manual intervention is completed.
[0011] Secondly, embodiments of the present invention provide a safety collaborative control device for an intelligent robot, applied to an intelligent robot, comprising: a real-time monitoring module for real-time monitoring of the communication link status between the intelligent robot and a remote operation and maintenance platform; a safety braking module for immediately triggering a graded safety braking action when a communication interruption is detected, causing the actuator of the intelligent robot to enter physical locking, and simultaneously activating a local highest-priority abnormality warning; and a data continuation module for temporarily storing the continuously collected operation process data during the interruption in a local non-volatile storage unit, and automatically executing the data continuation process after the network link is restored.
[0012] Thirdly, embodiments of the present invention provide an intelligent robot, including a processor and a memory, wherein the memory stores computer-executable instructions that can be executed by the processor, and the processor executes the computer-executable instructions to implement the steps of any of the methods provided in the first aspect above.
[0013] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps of the method provided in any of the first aspects above.
[0014] The embodiments of the present invention bring the following beneficial effects: The intelligent robot safety collaborative control method, device, and intelligent robot provided by this invention first monitor the communication link status between the intelligent robot and the remote operation and maintenance platform in real time. When a communication interruption is detected, a graded safety braking action is immediately triggered, causing the intelligent robot's actuator to enter physical locking, and simultaneously activating the local highest-priority anomaly warning. Then, the operation process data continuously collected during the interruption is temporarily stored in a local non-volatile storage unit, and the data resume transmission process is automatically executed after the network link is restored. In the above method, when a communication interruption between the intelligent robot and the remote operation and maintenance platform is detected, a graded safety braking action can be immediately triggered to cause the intelligent robot's actuator to enter physical locking, and the local highest-priority anomaly warning can be activated simultaneously, thereby improving the operational safety of the intelligent robot in the complex electromagnetic environment of a high-voltage power distribution room. At the same time, the operation process data can be continuously collected and temporarily stored during the interruption, and the data resume transmission process can be automatically executed after the network link is restored, thereby improving the data integrity of the intelligent robot in the complex electromagnetic environment of a high-voltage power distribution room.
[0015] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention are realized and obtained in accordance with the structures particularly pointed out in the description, claims and drawings.
[0016] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0017] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0018] Figure 1 A flowchart illustrating a safe collaborative control method for an intelligent robot provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of a safe collaborative control system for an intelligent robot provided in an embodiment of the present invention; Figure 3 A flowchart illustrating a safe collaborative control method for an intelligent robot provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of a safety collaborative control device for an intelligent robot provided in an embodiment of the present invention; Figure 5 This is a structural schematic diagram of an intelligent robot provided in an embodiment of the present invention. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] In practical applications, the electromagnetic environment in high-voltage power distribution rooms is complex, and wireless signals are easily interfered with, interrupted, or lost, making robots prone to communication failures. Current robots often blindly continue execution or shut down directly after a network outage, which can easily lead to malfunctions of the robotic arm, equipment collisions, and personal safety hazards. Furthermore, instrument identification, partial discharge, infrared, and status data collected during the outage are easily lost.
[0021] Based on this, the present invention provides a safe collaborative control method, device and intelligent robot for intelligent robots, which can improve the operational safety and data integrity of intelligent robots in the complex electromagnetic environment of high-voltage power distribution rooms.
[0022] To facilitate understanding of this embodiment, a detailed description of a safe collaborative control method for an intelligent robot disclosed in this embodiment of the invention will be provided first. This method is applied to intelligent robots. See [link to relevant documentation]. Figure 1 The flowchart shown illustrates a safe collaborative control method for an intelligent robot, which mainly includes the following steps S101 to S103: Step S101: Monitor the status of the communication link between the intelligent robot and the remote operation and maintenance platform in real time.
[0023] In one implementation, the intelligent robot and the remote operation and maintenance platform send heartbeat messages bidirectionally at a 200ms cycle to detect the connectivity status of the communication link in real time. If no response is received for several consecutive times (3-5 times), it is determined that the network is disconnected and communication is interrupted.
[0024] Step S102: When a communication interruption is detected, the graded safety braking action is immediately triggered, causing the actuator of the intelligent robot to enter physical lock, and the highest priority local abnormality warning is activated simultaneously.
[0025] In one implementation, upon determining that communication has been interrupted, multi-level safety braking is immediately executed, including but not limited to: locking the robotic arm, emergency braking of the chassis, maintaining the current state of all output mechanisms, and simultaneously activating the local highest priority audible and visual alarm.
[0026] Step S103: Temporarily store the continuously collected job process data during the interruption in the local non-volatile storage unit, and automatically execute the data resume transmission process after the network link is restored.
[0027] In one implementation, the inspection data, operation logs, images, and sensor data continuously collected during the interruption are cached in the local storage unit according to the task ID, location ID, and timestamp. The intelligent robot periodically attempts to reconnect to the platform, and automatically executes the data resume transmission process after the network is restored. It prioritizes uploading the network outage event log, and then automatically resumes the cached data in the order of timestamps to ensure that the data is not lost or out of order.
[0028] The safety collaborative control method for intelligent robots provided in this embodiment of the invention can immediately trigger a graded safety braking action to physically lock the actuators of the intelligent robot when a communication interruption is detected between the intelligent robot and the remote operation and maintenance platform, and simultaneously activate the highest priority local anomaly warning, thereby improving the operational safety of the intelligent robot in the complex electromagnetic environment of the high-voltage power distribution room; at the same time, it can continuously collect operation process data and temporarily store the data during the interruption, and automatically execute the data resume transmission process after the network link is restored, thereby improving the data integrity of the intelligent robot in the complex electromagnetic environment of the high-voltage power distribution room.
[0029] In this embodiment of the invention, the local highest priority abnormal warning of the communication interruption sound and light combination method has an adaptive adjustment function: according to the ambient noise decibel value and ambient light intensity of the current environment of the intelligent robot, the output power of the warning sound and the flashing frequency and brightness of the warning light are automatically adjusted; at the same time, after the warning is triggered, the intelligent robot starts the local microphone array to collect ambient sound. If a specific emergency voice command is identified, the intensity of the sound and light warning is temporarily reduced and the current braking state is replaced with a predefined local emergency response sequence.
[0030] In practical implementation, the intelligent robot can be equipped with a high-precision digital environmental noise sensor and a wide dynamic range ambient light sensor, either in its factory configuration or during on-site deployment. The environmental noise sensor is installed on the top or side of the intelligent robot, away from its own mechanical vibration sources, and is equipped with a windproof cover to reduce wind noise interference. The ambient light sensor is installed in a conspicuous position on the robot's outer shell, with its photosensitive surface facing the same direction as the robot's normal movement, and has a hemispherical light-transmitting cover to achieve uniform collection of ambient light from multiple directions. After the intelligent robot completes its power-on self-test, it first performs a sensor initialization calibration process: the noise sensor collects the background noise baseline value under the condition that all moving parts of the intelligent robot are stationary and there is no active sound source interference in the surroundings. This baseline value serves as the zero-point reference for subsequent ambient noise decibel measurements. The light sensor undergoes gain calibration under standard light source illumination to ensure that its output value deviates from the measurement of a standard illuminance meter within the allowable tolerance range. After calibration, the sensors enter a continuous real-time acquisition mode.
[0031] When the intelligent robot determines that a local highest-priority anomaly alert needs to be triggered, its main control unit immediately sends synchronous data reading commands to the environmental noise and ambient light sensors simultaneously with the issuance of the alert-driven hardware control command. Upon receiving the reading commands, the two sensors synchronously sample the ambient noise decibels and ambient light intensity within a preset, extremely short acquisition window, and return the sampling results to the main control unit. This synchronous acquisition must be completed before the alert-driven hardware control command actually takes effect to ensure that the initial settings of the alert parameters accurately reflect the actual environmental conditions at the moment of alert triggering, and to avoid interference from the audio-visual signals emitted by the alert itself with subsequent environmental perception.
[0032] After acquiring the current ambient noise decibel value, the main control unit compares the measured decibel value with a preset ambient noise level mapping table. This mapping table pre-divides multiple ambient noise level ranges, each corresponding to a warning sound output power level. When the measured ambient noise decibel value is in a lower range, a lower power sound output level is automatically matched to avoid excessive noise pollution in quiet environments; when the measured ambient noise decibel value is in a higher range, a higher power sound output level is automatically matched to ensure that the warning sound can penetrate background noise and be clearly perceived by surrounding personnel.
[0033] Meanwhile, based on the acquired ambient light intensity value and according to the preset light-warning parameter mapping relationship, the main control unit dynamically determines the flashing frequency and brightness levels of the warning light. In strong ambient light conditions, it automatically increases the brightness of the warning light and decreases the flashing frequency, ensuring sufficient visual contrast and visibility even in bright light. In weak ambient light or dark environments, it automatically decreases the brightness of the warning light and appropriately increases the flashing frequency to avoid glare from excessive light, while simultaneously enhancing the visual alertness of the warning through frequency changes. After completing the mapping, the main control unit sends the sound output power, warning light brightness, and flashing frequency as control signals to the sound driver amplifier and the warning light driver circuit, respectively, enabling the audible and visual warning to begin operating with initial parameters adapted to the current environment.
[0034] During continuous operation of the audible and visual warning system, the environmental noise sensor and ambient light sensor maintain continuous data acquisition and continuously feed back the latest environmental parameters to the main control unit at a preset sampling update cycle. At the end of each sampling cycle, the main control unit compares the latest acquired ambient noise decibel value with the noise level range corresponding to the current sound output power. If the latest noise value is still within the level range corresponding to the current power level, the current output power remains unchanged; if the latest noise value crosses to an adjacent higher level range, the main control unit immediately sends a power boost command to the sound driver amplifier, increasing the warning sound output power to a higher level that matches the current ambient noise; if the latest noise value drops to an adjacent lower level range, the main control unit, after confirming that the low noise state has remained stable for a preset confirmation time, gradually reduces the sound output power to the corresponding lower level to avoid frequent fluctuations in warning power caused by single transient noise fluctuations. Similarly, the main control unit synchronously tracks the real-time changes in ambient light intensity. When the ambient light intensity changes across different ranges, it adaptively adjusts the brightness and flashing frequency of the warning lights according to the same dynamic adjustment logic to ensure that the sound and light warning effect remains optimally matched with the on-site environment throughout the entire warning period.
[0035] When the intelligent robot is equipped with an integrated audio-visual warning device, the main control unit also executes an audio-visual coordinated scheduling strategy during the adaptive adjustment process. Specifically, the main control unit dynamically adjusts the activation timing relationship between the audible and visual warning signals based on the combination of the current ambient noise level and ambient light intensity. In high-noise and low-light environments, high-frequency flashing of the visual warning is prioritized as the primary warning method, with the audible warning serving as a secondary method; in low-noise and high-light environments, the audible warning is prioritized as the primary warning method, with the visual warning serving as a secondary method. Simultaneously, the main control unit staggers the on / off timing of the warning lights and the intermittent sounding timing of the audible warnings to avoid simultaneous peak power spikes and instantaneous energy concentration. This reduces the instantaneous impact on the intelligent robot's power supply system and improves the visibility of the warning signals in complex environments.
[0036] Furthermore, the intelligent robot has multiple miniature digital microphones installed in a ring or rectangular array around its body, forming a local microphone array. When an anomaly warning is triggered, the intelligent robot activates the multiple miniature digital microphones arranged in a ring around its body. Utilizing the phase and time differences between the sound signals received by each microphone, multiple receiving beams are formed to cover the entire space, achieving spatial directional separation of ambient sound and background noise suppression.
[0037] The intelligent robot's local non-volatile storage unit is pre-loaded with an emergency voice command keyword recognition library. Each command template corresponds to a set of acoustic feature parameter vectors and a predefined local emergency response sequence. The microphone array continuously collects ambient sound and filters out non-speech frames after voice activity detection. For valid speech frames, acoustic features such as frequency domain energy distribution, fundamental frequency trajectory, and cepstral coefficients are extracted and compared with the command templates in the recognition library using multi-dimensional feature space similarity. When the matching confidence is higher than a preset threshold, recognition is considered successful. When the confidence of multiple templates is close, auxiliary weighted judgment is performed using the spatial orientation of the sound source and the location of the preset emergency command station.
[0038] After successfully recognizing a specific emergency voice command, the intelligent robot performs two operations in parallel: First, it immediately attenuates the output power of the warning sound to a low-power maintenance level, dims the brightness of the warning light, and reduces it to a slow, breathing-like indication frequency to temporarily reduce audio-visual interference while retaining a minimum level of indication functionality. Second, it retrieves the corresponding emergency response sequence from its local storage and sends each action command in the sequence to the actuator drive module in a preset order, completing the emergency response locally in a closed loop, without relying on real-time commands from a remote maintenance platform. Simultaneously, the intelligent robot employs mechanisms for repeated confirmation of operating commands, sound source distance determination, and emergency cancellation to prevent accidental triggering. If recognition fails continuously within the monitoring window, the current braking and locking state is maintained, the recognition failure event is recorded, and the sampling rate is gradually reduced to switch to a passive trigger waiting mode.
[0039] In one implementation, for the aforementioned step S101, i.e., when monitoring the communication link status between the intelligent robot and the remote operation and maintenance platform in real time, the following methods are employed, including but not limited to: monitoring the communication link status between the intelligent robot and the remote operation and maintenance platform through bidirectional periodic heartbeat messages; if no valid response message is received for a preset number of consecutive times, the communication is determined to be interrupted; wherein, the bidirectional periodic heartbeat messages adopt a dynamic interval sending strategy: under normal communication conditions, the sending interval of the heartbeat messages is a first frequency; when the link signal strength is detected to be lower than a preset strength threshold or the bit error rate exceeds a preset bit error rate threshold, the sending interval of the heartbeat messages is switched to a second frequency higher than the first frequency, and after no valid response message is received for a preset number of consecutive times, the threshold for the number of consecutive unresponding times required to determine the communication interruption is shortened.
[0040] In practical implementation, after the intelligent robot completes its power-on self-test and establishes an initial communication connection with the remote operation and maintenance platform, it first enters the link quality baseline determination phase. During this phase, the intelligent robot continuously sends a preset number of heartbeat probe request messages to the remote operation and maintenance platform at the system's default standard sending interval. Upon receiving each heartbeat probe request, the remote operation and maintenance platform immediately returns a corresponding response message. Upon receiving each response message, the intelligent robot simultaneously records the signal reception strength indicator value and the data transmission error rate statistics during this interaction. After completing the preset number of probe interactions, the intelligent robot takes the arithmetic mean of all collected signal strength values and uses this average as the signal strength baseline reference value for that communication period; simultaneously, it takes the arithmetic mean of the bit error rate statistics as the bit error rate baseline reference value. These baseline reference values are dynamically updated with each successful communication session to adapt to the electromagnetic interference characteristics under different working environments.
[0041] Under normal communication conditions, where the signal strength is not lower than a preset strength threshold and the bit error rate is not higher than a preset bit error rate threshold, the intelligent robot sends heartbeat request messages at a first frequency. This first frequency is set as the minimum effective frequency sufficient to maintain link liveness detection, in order to save communication bandwidth and the intelligent robot's own power consumption. After each heartbeat request message is sent, the intelligent robot starts a corresponding heartbeat timeout timer. If a valid response message is received from the remote operation and maintenance platform before the timer expires, the heartbeat interaction is considered successful, the timer is reset, and preparations are made for the next heartbeat transmission according to the time interval of the first frequency. If no response message is received before the timer expires, or if the received response message is verified as an invalid response, the heartbeat interaction is marked as a suspected loss event. However, communication is not immediately determined to be interrupted; instead, the count of the suspected loss event is incremented, and the next round of heartbeat interaction continues.
[0042] Each time the intelligent robot receives a response message from the remote maintenance platform, it measures the received wireless signal strength corresponding to that message in real time and calculates the instantaneous bit error rate (BER) of the current communication link. When the intelligent robot detects that the received signal strength is below a preset threshold for a certain number of consecutive times, or that the BER exceeds a preset threshold for a certain number of consecutive times, it determines that the quality of the current communication link has substantially deteriorated and immediately switches its operating mode from normal communication mode to link degradation warning mode.
[0043] Upon entering the link degradation early warning mode, the intelligent robot automatically switches the heartbeat message transmission interval from the first frequency to the second frequency. This second frequency has a shorter time interval than the first frequency, meaning the heartbeat message transmission density is significantly increased. In this mode, the intelligent robot continuously records the response and reception status of each heartbeat request, and continuously incorporates the signal strength and bit error rate of each received response message into its statistics.
[0044] In normal communication mode, the intelligent robot needs to fail to receive a preset number of valid response messages (e.g., five consecutive times) before determining that the communication link has been formally interrupted. However, in link degradation warning mode, since the link quality is already poor, to ensure timely safety braking, the intelligent robot automatically shortens the required threshold of consecutive unanswered messages. That is, in degradation mode, the number of consecutive unanswered messages only needs to reach half of the number in normal mode (e.g., three consecutive times) to determine that the communication link has been substantially interrupted. This dynamic shortening mechanism ensures that in severe link conditions, the intelligent robot can trigger subsequent graded safety braking actions with a shorter response delay.
[0045] In this embodiment of the invention, the response message must not only contain a sequence number that matches the heartbeat request message, but also a dynamic verification code generated by the remote operation and maintenance platform based on the current time window. After receiving the response message, the intelligent robot first uses the local synchronization clock and the pre-shared key to verify the dynamic verification code. Only after the verification is passed will the response message be counted as a valid response; otherwise, it will be considered invalid and an early link anomaly warning will be directly triggered.
[0046] In one implementation, for the aforementioned step S102, i.e., when a communication interruption is detected and the graded safety braking action is immediately triggered, the following methods may be adopted, including but not limited to: When the duration of the communication interruption is less than the first preset threshold, the first-level braking of cutting off the power of the end effector is triggered; when the duration of the communication interruption reaches or exceeds the first preset threshold but is less than the second preset threshold, the second-level braking, including mechanical locking of the end effector and parking brake of the mobile chassis, is triggered; when the duration of the communication interruption reaches or exceeds the second preset threshold, the third-level braking, including physical locking of all actuators, energy isolation and freezing of digital output channel status, is triggered, and the braking level change log is written to the local non-volatile storage unit.
[0047] In practical implementation, during the deployment and debugging phase of the intelligent robot, maintenance personnel write two key time parameters—a first preset threshold and a second preset threshold—to the local non-volatile storage unit via a remote maintenance platform. These two thresholds represent the tolerance duration for brief communication fluctuations and the minimum duration for which the highest level of safety protection must be activated, respectively. The specific values are determined based on factors such as the operational hazard level and the inertial characteristics of the mechanism. These values are automatically loaded into memory when the intelligent robot is powered on for decision-making purposes.
[0048] Upon detecting a communication interruption, an event notification is immediately sent to the braking decision module. The braking decision module reads the current system clock as the interrupt start timestamp and starts a dedicated interrupt duration timer. The timer continuously accumulates driven by the system clock interrupt, unaffected by other task scheduling, and the timer value is compared in real time with two thresholds to determine the current braking level range.
[0049] When the interruption timer value is less than the first preset threshold, the braking decision module determines that braking is at level one and sends a power cut-off command to the power drive unit of the end effector. The drive unit immediately disconnects the power supply circuit of the drive motor, causing the motor to lose its driving torque, and the end effector naturally decelerates and stops due to its own inertia and friction.
[0050] When the timing value reaches or exceeds the first preset threshold but is still less than the second preset threshold, the braking decision module detects a boundary crossing and triggers a braking level transition. Before the transition, it checks whether the first-level braking is effective. If effective, it executes the upgrade action; otherwise, it directly executes all actions of the second-level braking. Subsequently, the braking level is updated to second level, and the corresponding control command sequence is executed.
[0051] During secondary braking, the decision module sends a command to the end locking drive device, which drives the locking pin or caliper brake to extend and clamp to achieve mechanical locking; at the same time, it sends a command to the chassis drive controller to cut off the power to the drive wheels and then apply continuous friction braking force by the parking brake to stop the chassis.
[0052] When the interruption timer value reaches or exceeds the second preset threshold, a three-level braking system is triggered. The main power supply management system cuts off power to all functional modules except for the safety monitoring, timer, and storage units, forming physical energy isolation; all actuator locking devices simultaneously activate to constrain all degrees of freedom of motion; the digital output channel maintains its current level frozen to prevent malfunctions of external linkage equipment, achieving the highest level of safety protection.
[0053] After all three levels of braking have been executed and stable locking has been confirmed, the braking decision module writes a braking level change log to the non-volatile storage unit. The log includes the interrupt start timestamp, the timing value at the time of the third-level trigger, the execution time and confirmation status of each braking level, and the attitude data before braking. The log is written atomically; after all data has been successfully written and verified, the completion flag is set to ensure complete and consistent records.
[0054] In one implementation, for the aforementioned step S102, i.e., when temporarily storing the continuously collected operation process data during the interruption in the local non-volatile storage unit, the following methods may be adopted, including but not limited to: First, continuously collect operation process data during the interruption, and attach a local trusted timestamp of the collection time, a data length check code, and the current posture identifier of the intelligent robot to each frame of collected operation process data; then, use the device's unique key stored in the local security chip to digitally sign the preprocessed data frame frame by frame, and after associating the signature result with the original data frame, cache it in the local storage unit in the order of task ID, point ID, and timestamp.
[0055] In practice, while communication interruption triggers graded braking, the intelligent robot's data acquisition module continues to operate, continuously collecting various operational process data at a fixed sampling period, including actuator displacement, speed, torque, chassis pose, and environmental perception information. After each frame of data is acquired, the acquisition module allocates storage space for that frame according to a preset data frame structure. This space is logically divided into a data payload area and a metadata appendage area, reserving space for subsequent information appending.
[0056] The acquisition module immediately sends a timestamp request to a local high-precision trusted clock source the instant each frame of data is sampled. The trusted clock source has a built-in independent crystal oscillator-driven real-time clock circuit and is equipped with tamper-proof physical protection, unaffected by clock adjustments in the main control system. The acquisition module returns the time value accurate to the millisecond level, using it as the timestamp of the data frame's acquisition moment and filling it into a designated field in the metadata area, ensuring that the time information cannot be retrospectively modified.
[0057] After timestamp appending, all valid data bytes in the data payload area of the frame are summed and verified to generate a data length checksum. This checksum reflects the complete length information and total byte content of the data frame from start to finish. After generation, the checksum is filled into the verification field of the metadata area, used by the platform to verify whether any bytes have been lost or content altered during storage and retrieval of the data frame during subsequent transmission.
[0058] While attaching the checksum, the robot requests complete attitude information for the current moment from the robot attitude perception subsystem, including at least the roll and pitch angles of the chassis relative to the horizontal plane, and the joint angles of the end effector relative to the base. After the attitude perception subsystem returns, the acquisition module arranges these attitude data in a predetermined order and compresses them into attitude identification codes, which are then filled into the attitude identification field of the metadata area, so that each frame of data is associated with the robot's spatial configuration at the time of acquisition.
[0059] After attaching the metadata, the acquisition module sends a digital signature request to the local security chip. Before receiving the request, the security chip first verifies the acquisition module's access permissions. Once it confirms the request originates from a legitimate firmware module, it unlocks the internally stored device-unique key. The security chip then uses the device-unique key to perform a digital signature operation on the entire content of the data frame (including the data payload and all additional information in the metadata area), generating a signature value that corresponds one-to-one with the data frame. After the signature value is returned to the acquisition module, it is associated and stored in the signature area at the end of the data frame. Once the signature value is bound to the original data frame, any single-byte modification to the data frame will cause subsequent signature verification to fail, effectively ensuring the integrity and authenticity of the data.
[0060] While performing digital signature operations, the acquisition module reads the task ID code of the current job from the currently executing task manager. Then, it categorizes the complete data frames that have completed signature processing according to their task IDs, grouping all data frames generated by the same task ID into the same logical group. Within the logical group of the same task ID, the acquisition module further performs secondary subgrouping based on the job location ID corresponding to the data frame. Each location ID corresponds to a specific job location or target object, and the acquisition module groups data frames from different locations under the same task into their respective location subgroups. After completing the secondary grouping by task ID and location ID, the acquisition module arranges the data frames in ascending order of timestamp from earliest to latest within each location subgroup, and then writes the arranged data frames sequentially into a contiguous storage area of the local non-volatile storage unit. For each data frame written, the acquisition module synchronously updates the cache management index table, recording the frame's physical storage address, task ID, location ID, and timestamp information, forming a complete retrieval mapping.
[0061] In one implementation, for the aforementioned step S103, i.e., when automatically executing the data resume transmission process after the network link is restored, the following methods may be adopted, including but not limited to: First, periodically send a reconnection signal to the remote operation and maintenance platform, and after the network link is restored, restore communication with the remote operation and maintenance platform and upload the network outage event log; then upload the cached data in batches in ascending order of timestamp, and wait for the platform to return a verification response after each batch is transmitted; if any batch verification fails, retransmit that batch and do not retransmit the cached data of subsequent batches.
[0062] In practice, after confirming communication restoration, the network outage event log is uploaded; then, a resumption start signal is sent to the data resumption module. The resumption module first reads the cache management index table in the local non-volatile storage unit to count the total number of data frames to be uploaded. Subsequently, according to a preset fixed number of frames or a fixed amount of data, all data frames to be uploaded are divided into several consecutive batches. Each batch is independently numbered, and the data range boundaries of each batch are determined by ascending timestamps, generating a batch upload order list.
[0063] After receiving the batch data packets, the remote operation and maintenance platform performs integrity verification on each frame of data within the packet. First, it verifies the length checksum of each frame to confirm byte integrity. Then, it uses the digital signature associated with each frame to verify the authenticity and integrity of the data. Once all frames pass verification, the platform generates a positive verification response code containing the batch number and a success identifier. If any frame fails verification, a negative verification response code containing the index of the failed frame is generated and returned to the intelligent robot.
[0064] The intelligent robot continuously listens for verification responses from the platform before the timer expires. If a positive response code is received, the upload of that batch is considered successful. The robot then marks the batch status as "confirmed upload" in the local cache management index table and releases the storage space resources occupied by that batch of data. If no response is received before the timer expires or a negative response code is received, the upload of that batch is considered to have failed.
[0065] If an upload fails, that batch is immediately marked as a batch to be retransmitted, and its retransmission priority is raised to the highest level. Before initiating retransmission, the historical retransmission count for that batch is checked. If it does not exceed the preset maximum retransmission count limit, the batch is repackaged and uploaded again. During retransmission, the packaged content and frame order of that batch remain completely consistent with the initial upload, ensuring that the platform can perform independent verification based on newly received data. Once a batch enters the retransmission process, all subsequent batches that have not yet been uploaded are immediately frozen, and their data packaging and upload operations are suspended. If a batch fails to receive a positive response after reaching the preset maximum retransmission count, it is determined that the batch cannot be successfully uploaded under the current link conditions.
[0066] In this embodiment of the invention, after retransmitting the cached data of the current batch without retransmitting subsequent batches, the method further includes: recording the number of failures of the batch that failed verification; when the number of consecutive verification failures of the same batch exceeds the preset retransmission limit, skipping the batch and marking it as pending manual verification, and continuing to upload subsequent batches of data; after all uploadable batches of data have been transmitted, generating an abnormal data list containing information on all skipped batches, and uploading this list separately to the remote operation and maintenance platform as the highest priority data packet.
[0067] In one implementation, when uploading cached data in batches in ascending order of timestamps, the following methods may be used, including but not limited to: dynamically calculating the size of the current optimal batch based on the real-time available bandwidth and round-trip latency after the network link is restored; automatically reducing the data size of each batch and increasing the frequency of verification responses when the available bandwidth is lower than the bandwidth threshold; and automatically increasing the data size of each batch to reduce the total number of transmission interactions when the available bandwidth is higher than the bandwidth threshold.
[0068] In practice, the optimal batch size is dynamically calculated based on the real-time available bandwidth and round-trip latency after the network link is restored. When the available bandwidth is lower than the bandwidth threshold, the data size of each batch is automatically reduced and the frequency of verification responses is increased to reduce the retransmission overhead after a single transmission failure. When the available bandwidth is higher than the bandwidth threshold, the data size of each batch is automatically increased to reduce the total number of transmission interactions and improve the efficiency of retransmission.
[0069] In one implementation, after the automatic execution of the data resume process, the method further includes: after the data resume is completed, receiving a manual confirmation instruction from the remote operation and maintenance platform and verifying the manual confirmation instruction; if the manual confirmation instruction is successfully verified, the brake lock is released; if the manual confirmation instruction does not arrive within the time limit or the verification fails, the lock state is maintained, and a status heartbeat is pushed to the remote operation and maintenance platform every preset time interval until manual intervention is completed.
[0070] In practice, after data transmission is completed, the intelligent robot remains offline. Operations personnel must manually confirm in the background before task execution can resume to avoid the risks associated with automatic restarts. Specifically, the operations personnel initiate a manual confirmation command, which includes a command payload signed by the remote operations platform using its private key and a dynamic password hash value entered by the operator. The intelligent robot first verifies the digital signature of the command payload using a pre-stored platform public key to confirm the legitimacy of the command's source. Then, it verifies the dynamic password hash value using a locally stored operator password verification table. Verification is considered successful only after both verifications pass. If the confirmation command times out or verification fails, the robot remains locked and pushes a status heartbeat to the platform every 30 seconds until manual intervention completes the closed loop.
[0071] For ease of understanding, this embodiment of the invention provides an example of safe collaborative control for an intelligent robot, see [link to relevant documentation]. Figure 2 As shown and Figure 3 As shown, it mainly includes: First, the communication heartbeat detection robot and the back-end operation and maintenance platform send heartbeat messages bidirectionally at a 200ms cycle. If no response is received after 3 consecutive attempts, it is determined that the network is disconnected.
[0072] Second, the safety braking system for network disconnection immediately executes the following actions upon network disconnection: locking the robotic arm, braking the chassis, and maintaining the output mechanism; at the same time, it activates the highest priority alarm of the audible and visual alarm device.
[0073] Third, the local data cache writes the instrument identification, infrared, partial discharge, and status data collected during the network outage into the local cache unit according to the timestamp, task ID, and location ID.
[0074] Fourth, the network reconnection and resume robot attempts to reconnect every second. After the network is restored, it first uploads the network outage event log, and then uploads the cached data to the backend operation and maintenance platform in the order of timestamps.
[0075] Fifth, after manual confirmation that the data transmission has resumed, the robot remains offline. Only after the maintenance personnel confirm in the background can the robot continue to perform its tasks.
[0076] Sixth, dynamic status updates: If communication is interrupted again or the environment changes, repeat the above process to maintain security control and data closure.
[0077] In this embodiment, when the robot performs opening and closing operations on a 6kV / 35kV switchgear, a WiFi interruption occurs. Within 300ms, the locking arm and braking are completed, and the operation process data is cached locally. After the network is restored, the data is automatically resumed and awaits manual confirmation, fully meeting the safety and data requirements of high-voltage scenarios.
[0078] Compared with the prior art, the above-mentioned method provided by the present invention has the following beneficial effects: (1) It can realize safe shutdown and arm locking at the moment of network failure, eliminate blind operation, and ensure the safety of high-voltage equipment and personnel; (2) Network failure data is time-stamped and cached and orderly resumed, ensuring that the operation and maintenance data is complete and traceable; (3) After the network is restored, manual confirmation is required before the operation can continue, which complies with the power safety operation specifications; (4) Local sound and light, platform and centralized control three-level linkage alarm improves the response speed of abnormal handling.
[0079] In addition to the intelligent robot safety collaborative control method provided in the foregoing embodiments, this invention also provides an intelligent robot safety collaborative control device, see [link to relevant documentation]. Figure 4 The diagram shows a structural schematic of a safety collaborative control device for an intelligent robot, which may include the following parts: The real-time monitoring module 401 is used to monitor the communication link status between the intelligent robot and the remote operation and maintenance platform in real time.
[0080] The safety braking module 402 is used to immediately trigger a graded safety braking action when a communication interruption is detected, so that the actuator of the intelligent robot enters physical locking and simultaneously starts the local highest priority abnormality warning.
[0081] The data resume module 403 is used to temporarily store the continuously collected operation process data during the interruption in the local non-volatile storage unit, and automatically execute the data resume process after the network link is restored.
[0082] The safety collaborative control device for intelligent robots provided in this embodiment of the invention can immediately trigger a graded safety braking action to physically lock the actuator of the intelligent robot when it detects a communication interruption between the intelligent robot and the remote operation and maintenance platform, and simultaneously activate the highest priority local abnormal warning, thereby improving the operational safety of the intelligent robot in the complex electromagnetic environment of the high-voltage power distribution room; at the same time, it can continuously collect operation process data and temporarily store the data during the interruption, and automatically execute the data resume transmission process after the network link is restored, thereby improving the data integrity of the intelligent robot in the complex electromagnetic environment of the high-voltage power distribution room.
[0083] In one embodiment, the real-time monitoring module 401 is specifically used to: monitor the communication link status between the intelligent robot and the remote operation and maintenance platform through bidirectional periodic heartbeat messages; if no valid response message is received for a preset number of consecutive times, the communication is determined to be interrupted; wherein, under normal communication conditions, the heartbeat message sending interval is a first frequency; when the link signal strength is detected to be lower than a preset strength threshold or the bit error rate exceeds a preset bit error rate threshold, the heartbeat message sending interval is switched to a second frequency higher than the first frequency, and after no valid response message is received for a preset number of consecutive times, the threshold for the number of consecutive unanswered messages required to determine the communication interruption is shortened.
[0084] In one embodiment, the aforementioned safety braking module 402 is specifically used to: trigger a first-level braking mechanism to cut off power when the duration of the communication interruption is less than a first preset threshold; trigger a second-level braking mechanism including mechanical locking of the end mechanism and parking brake of the mobile chassis when the duration of the communication interruption reaches or exceeds the first preset threshold but is less than a second preset threshold; trigger a third-level braking mechanism including physical locking of all actuators, energy isolation and freezing of digital output channel status when the duration of the communication interruption reaches or exceeds the second preset threshold, and write a braking level change log in the local non-volatile storage unit.
[0085] In one embodiment, the data continuation module 403 is specifically used to: continuously collect operation process data during the interruption, and add a local trusted timestamp of the collection time, a data length check code, and the current posture identifier of the intelligent robot to each frame of collected operation process data; use the device unique key stored in the local security chip to digitally sign the preprocessed data frame frame by frame, and after associating the signature result with the original data frame, cache it in the local storage unit in the order of task ID, point ID, and timestamp.
[0086] In one implementation, the data reconnection module 403 is specifically used to: periodically send a reconnection signal to the remote operation and maintenance platform, and after the network link is restored, restore communication with the remote operation and maintenance platform and upload the network outage event log; upload cached data in batches in ascending order of timestamp, and wait for the platform to return a verification response after each batch is transmitted; if any batch verification fails, retransmit the batch and do not retransmit the cached data of subsequent batches.
[0087] In one implementation, the data continuation module 403 is specifically used to: dynamically calculate the current optimal batch size based on the real-time available bandwidth and round-trip delay after the network link is restored; automatically reduce the data size of each batch and increase the frequency of verification responses when the available bandwidth is lower than the bandwidth threshold; and automatically increase the data size of each batch to reduce the total number of transmission interactions when the available bandwidth is higher than the bandwidth threshold.
[0088] In one embodiment, the above-mentioned device further includes: a manual confirmation module, used to: receive a manual confirmation instruction issued by the remote operation and maintenance platform after the data transmission is completed, and verify the manual confirmation instruction; if the manual confirmation instruction is successfully verified, the brake lock is released; if the manual confirmation instruction does not arrive within the time limit or the verification fails, the lock state is maintained, and a status heartbeat is pushed to the remote operation and maintenance platform once every preset time interval until manual intervention is completed.
[0089] It should be noted that the device provided in the embodiments of the present invention has the same implementation principle and technical effect as the aforementioned method embodiments. For the sake of brevity, any parts not mentioned in the device embodiments can be referred to the corresponding content in the aforementioned method embodiments.
[0090] This invention also provides an intelligent robot, specifically, the intelligent robot includes a processor and a storage device; the storage device stores a computer program, and the computer program, when run by the processor, executes the method described in any of the above embodiments.
[0091] Figure 5This is a schematic diagram of the structure of an intelligent robot provided in an embodiment of the present invention. The intelligent robot 100 includes: a processor 50, a memory 51, a bus 52, and a communication interface 53. The processor 50, the communication interface 53, and the memory 51 are connected through the bus 52. The processor 50 is used to execute executable modules, such as computer programs, stored in the memory 51.
[0092] The memory 51 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 53 (which can be wired or wireless), such as the Internet, wide area network, local area network, metropolitan area network, etc.
[0093] Bus 52 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 5 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.
[0094] The memory 51 is used to store programs. After receiving an execution instruction, the processor 50 executes the programs. The method executed by the device for defining the flow process disclosed in any of the foregoing embodiments of the present invention can be applied to the processor 50 or implemented by the processor 50.
[0095] Processor 50 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of processor 50 or by instructions in software form. Processor 50 can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this invention can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 51. The processor 50 reads the information in memory 51 and, in conjunction with its hardware, completes the steps of the above method.
[0096] The computer program product of the readable storage medium provided in the embodiments of the present invention includes a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the methods described in the foregoing method embodiments. For specific implementation, please refer to the foregoing method embodiments, which will not be repeated here.
[0097] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0098] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit it. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A safe collaborative control method for intelligent robots, characterized in that, Applications in intelligent robots, including: Real-time monitoring of the communication link status between the intelligent robot and the remote operation and maintenance platform; When a communication interruption is detected, a graded safety braking action is immediately triggered, causing the actuator of the intelligent robot to enter physical lock, and simultaneously activating the local highest priority abnormality warning. The operation process data continuously collected during the interruption is temporarily stored in the local non-volatile storage unit, and the data resume process is automatically executed after the network link is restored.
2. The method according to claim 1, characterized in that, Real-time monitoring of the communication link status between the intelligent robot and the remote operation and maintenance platform, including: The communication link status between the intelligent robot and the remote operation and maintenance platform is monitored by bidirectional periodic heartbeat messages. If no valid response message is received for a preset number of consecutive times, the communication is determined to be interrupted. Under normal communication conditions, the heartbeat message sending interval is a first frequency. When the link signal strength is detected to be lower than a preset strength threshold or the bit error rate exceeds a preset bit error rate threshold, the heartbeat message sending interval is switched to a second frequency higher than the first frequency, and after no valid response message is received for a preset number of consecutive times, the threshold for the number of consecutive unanswered messages required to determine the communication interruption is shortened.
3. The method according to claim 1, characterized in that, Upon detection of a communication interruption, a tiered safety braking action is immediately triggered, including: When the duration of the communication interruption is less than the first preset threshold, the first-level braking of the end mechanism is triggered to cut off the power. When the duration of the communication interruption reaches or exceeds the first preset threshold but is less than the second preset threshold, a secondary braking system is triggered, including mechanical locking of the end mechanism and parking brake of the mobile chassis. When the duration of the communication interruption reaches or exceeds the second preset threshold, a three-level braking mechanism is triggered, including physical locking of all actuators, energy isolation, and freezing of the digital output channel status, and a braking level change log is written to the local non-volatile storage unit.
4. The method according to claim 1, characterized in that, The job process data continuously collected during the interruption is temporarily stored in the local non-volatile storage unit, including: During the interruption, the operation process data is continuously collected, and each frame of collected operation process data is appended with a local trusted timestamp of the collection time, a data length check code, and the current posture identifier of the intelligent robot. The preprocessed data frames are digitally signed frame by frame using the device's unique key stored in the local security chip. The signature results are then associated with the original data frames and cached in the local storage unit in the order of task ID, location ID, and timestamp.
5. The method according to claim 1, characterized in that, After the network link is restored, the data resume process is automatically executed, including: The system periodically sends reconnection signals to the remote operation and maintenance platform, and resumes communication with the remote operation and maintenance platform after the network link is restored, and uploads the network outage event log. Upload cached data in batches in ascending order of timestamp, and wait for the platform to return a verification response after each batch is transmitted; If any batch fails verification, the batch will be retransmitted, but the cached data for subsequent batches will not be retransmitted.
6. The method according to claim 5, characterized in that, Upload cached data in batches in ascending order of timestamp, including: Based on the real-time available bandwidth and round-trip latency after the network link is restored, the current optimal batch size is dynamically calculated. When the available bandwidth is lower than the bandwidth threshold, the amount of data per batch is automatically reduced and the frequency of verification responses is increased. When the available bandwidth is higher than the bandwidth threshold, the amount of data in each batch is automatically increased to reduce the total number of transmission interactions.
7. The method according to claim 5, characterized in that, After automatically executing the data resume process, it also includes: After the data transmission is resumed, a manual confirmation instruction is received from the remote operation and maintenance platform, and the manual confirmation instruction is verified. If the manual confirmation command is successfully verified, the brake lock will be released; If the manual confirmation command fails to arrive within a time limit or fails to be verified, the system remains locked and a status heartbeat is pushed to the remote operation and maintenance platform at preset time intervals until manual intervention is completed.
8. A safety collaborative control device for an intelligent robot, characterized in that, Applications in intelligent robots, including: The real-time monitoring module is used to monitor the communication link status between the intelligent robot and the remote operation and maintenance platform in real time. The safety braking module is used to immediately trigger a graded safety braking action when a communication interruption is detected, so that the actuator of the intelligent robot enters physical locking and simultaneously activates the local highest priority abnormality warning. The data resume module is used to temporarily store the continuously collected operation process data during the interruption in the local non-volatile storage unit, and automatically execute the data resume process after the network link is restored.
9. An intelligent robot, characterized in that, The method includes a processor and a memory, the memory storing computer-executable instructions executable by the processor, the processor executing the computer-executable instructions to implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program thereon, characterized in that, The computer program is executed by the processor to perform the steps of the method described in any one of claims 1 to 7.