Control device, control system, and program update method

CN122837338APending Publication Date: 2026-09-29SEIKO EPSON CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202610384348.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-03-27
Filing Date
2026-03-26
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

因此,安全性低

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122837338A_ABST
    Figure CN122837338A_ABST
Patent Text Reader

Abstract

This application provides a control device, a control system, and a method for updating a program that improves safety. The control device is for controlling the operation of a robot with a robotic arm, characterized by comprising: a storage unit for storing an update target program; an update data receiving unit for receiving update data for updating the update target program; a permission signal receiving unit for receiving a permission signal indicating that an operation to update the update target program has been permitted; and an update unit for updating the update target program based on the update data received by the update data receiving unit, wherein the update unit updates the update target program only when the permission signal receiving unit receives the permission signal, and does not update the update target program when the permission signal receiving unit does not receive the permission signal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to control devices, control systems, and methods for updating programs. Background Technology

[0002] In recent years, due to rising labor costs and a shortage of skilled workers, factories have automated tasks previously performed manually through various robots and their peripheral devices. Robots are controlled by a robot control unit. This control unit has a storage section containing various programs and a processing section that executes those programs. These programs include software for starting the robot control unit and software for driving the robotic arm during operations. This software is updated as needed, for example, to accommodate changes in the work content or conditions, or for version upgrades.

[0003] For example, as described in Patent Document 1, the robot control device receives updated software from a host server via a network to update the stored software. This allows the robot control device to operate using the latest program. Furthermore, in Patent Document 1, because the software update is performed when the robot is not in operation, work efficiency can be improved.

[0004] Patent Document 1: Japanese Patent Application Publication No. 2020-149345

[0005] However, the robot control device described in Patent Document 1 updates the software regardless of the robot's working environment or the operator's / administrator's intentions when it receives an update. As a result, there is a possibility that the software on the network might be updated to something different from the intended device due to operational or configuration errors, or that it might be remotely updated with malicious software by a third party. Therefore, security is low. Summary of the Invention

[0006] The control device according to the application example of the present invention controls the operation of a robot with a robotic arm. The control device includes: a storage unit that stores an update target program as an update target; an update data receiving unit that receives update data for updating the update target program; a permission signal receiving unit that receives a permission signal indicating that an operation to update the update target program has been permitted; and an update unit that updates the update target program based on the update data received by the update data receiving unit. The update unit updates the update target program when the permission signal receiving unit receives the permission signal, and does not update the update target program when the permission signal receiving unit does not receive the permission signal.

[0007] The control system according to the application example of the present invention includes a control device and a transmission device. The control device includes: a storage unit that stores an update target program as an update target; an update data receiving unit that receives update data for updating the update target program; a permission signal receiving unit that receives a permission signal indicating that an operation to update the update target program has been permitted; and an update unit that updates the update target program based on the update data. The transmission device sends the permission signal to the permission signal receiving unit. If the permission signal receiving unit receives the permission signal, the update unit updates the update target program; if the permission signal receiving unit does not receive the permission signal, the update target program is not updated.

[0008] The application example of the present invention relates to a program update method that updates an update target program stored in a control device, the control device controlling the operation of a robot with a robotic arm. The program update method includes: an update data receiving step, receiving update data for updating the update target program; a determination step, determining whether a permission signal has been received, the permission signal indicating that an operation to update the update target program has been permitted; and an update step, in which, if it is determined in the determination step that the permission signal has been received, the update target program is updated. Attached Figure Description

[0009] Figure 1 This is a diagram showing the overall configuration of a robot system equipped with the control device according to an embodiment of the present invention.

[0010] Figure 2 yes Figure 1 The diagram shows a block diagram of the robot system.

[0011] Figure 3 yes Figure 1 The diagram shows the block diagram of the control system of the robot system shown.

[0012] Figure 4 It shows based on Figure 3 The diagram shows an example of a notification screen generated by the first notification signal generated by the notification signal generation unit.

[0013] Figure 5 It shows based on Figure 3 The diagram shows an example of a notification screen generated by the second notification signal generated by the notification signal generation unit.

[0014] Figure 6 This is a flowchart illustrating an example of a program update method according to an embodiment of the present invention.

[0015] Explanation of reference numerals in the attached figures

[0016] 1: Robot, 2: Robot control unit, 3: Teaching pendant, 4: Safety door, 5: Emergency stop switch, 6: PLC, 7: Safety PLC, 8: Teach pendant, 9: Personal computer, 10: Robotic arm, 11: Base, 12: First arm, 13: Second arm, 14: Third arm, 15: Fourth arm, 16: Fifth arm, 17: Sixth arm, 20: End effector, 21: Main control unit, 22: Safety monitoring unit, 23: Update data receiving unit, 24: Permission signal receiving unit, 25: Notification signal generating unit, 35: Display unit, 81: Emergency stop switch, 82: Enable switch, 95: Display unit, 100: Robot system, 171: Joint, 172: Joint, 173: Joint, 174: Joint, 175: Joint, 176: Joint, 200: Control system, 211: Drive control unit, 21 2: Storage unit, 213: Communication unit, 214: Update unit, 221: Monitoring unit, 222: Storage unit, 223: Communication unit, 224: Update unit, 300: Transmitting device, 400: Server, 500: Notification screen, 600: Notification screen, D1: Motor driver, D2: Motor driver, D3: Motor driver, D4: Motor driver, D5: Motor driver, D6: Motor driver, DA: Update data, E1: Encoder, E2: Encoder, E3: Encoder, E4: Encoder, E5: Encoder, E6: Encoder, M1: Motor, M2: Motor, M3: Motor, M4: Motor, M5: Motor, M6: Motor, S1: Permission signal, S101: Step, S102: Step, S103: Step, S104: Step, S105: Step, TCP: Control point. Detailed Implementation

[0017] First Implementation Method

[0018] Figure 1 This is a diagram showing the overall configuration of a robot system equipped with the control device according to an embodiment of the present invention. Figure 2 yes Figure 1 The diagram shows a block diagram of the robot system. Figure 3 yes Figure 1 The diagram shows the block diagram of the control system of the robot system shown. Figure 4 It shows based on Figure 3 The diagram shows an example of a notification screen generated by the first notification signal generated by the notification signal generation unit. Figure 5 It shows based on Figure 3 The diagram shows an example of a notification screen generated by the second notification signal generated by the notification signal generation unit. Figure 6This is a flowchart illustrating an example of a program update method according to an embodiment of the present invention.

[0019] The control device, control system, and program updating method of the present invention will now be described in detail based on the preferred embodiments shown in the accompanying drawings. It should be noted that, for ease of explanation, the robotic arm will be referred to below as... Figure 1 The side of the base 11 is also called the "base end", and its opposite side, namely the end effector 20, is also called the "front end".

[0020] like Figure 1 , Figure 2 and Figure 3 As shown, the robot system 100 includes a robot 1, a robot control device 2 (an example of the control device of the present invention), a teaching pendant 3, a safety door 4, an emergency stop switch 5, a PLC 6, a safety PLC 7, a teach pendant 8, and a personal computer 9. The teaching pendant 3, safety door 4, emergency stop switch 5, PLC 6, safety PLC 7, teach pendant 8, and personal computer 9 are each a transmitting device 300. Furthermore, the robot control device 2 and each transmitting device 300 constitute a control system 200.

[0021] First, let's explain robot 1.

[0022] like Figure 1 As shown, in this embodiment, robot 1 is a single-arm, six-axis vertical joint robot, having a base 11 and a robotic arm 10. Furthermore, an end effector 20 can be mounted on the front end of the robotic arm 10. The end effector 20 may or may not be a component of robot 1.

[0023] It should be noted that robot 1 is not limited to the configuration shown in the figure. For example, it can also be a dual-arm multi-joint robot or a horizontal multi-joint robot. In addition, robot 1 can also be a mobile robot.

[0024] Base 11 is from Figure 1 The lower part of the robot arm 10 is supported by a driveable support, for example, fixed to the ground within a factory. The base 11 of the robot 1 is electrically connected to the robot control device 2 via a relay cable. It should be noted that the connection between the robot 1 and the robot control device 2 is not limited to... Figure 1 The connection can be made via a wired connection, as shown, but it could also be wireless, or via a network such as the Internet. Furthermore, the robot control device 2 can be built into the base station 11.

[0025] In this embodiment, the robotic arm 10 has a first arm 12, a second arm 13, a third arm 14, a fourth arm 15, a fifth arm 16, and a sixth arm 17, which are connected sequentially from the base 11 side. It should be noted that the number of arms in the robotic arm 10 is not limited to six; for example, it can have one, two, three, four, five, or more than seven arms. Furthermore, the overall length and size of each arm are not particularly limited and can be appropriately set.

[0026] The base 11 and the first arm 12 are connected via a joint 171. Furthermore, the first arm 12 is capable of rotating relative to the base 11 about a first rotation axis parallel to the vertical direction. The first rotation axis coincides with the normal to the ground on which the base 11 is fixed.

[0027] The first arm 12 and the second arm 13 are connected via a joint 172. Furthermore, the second arm 13 is capable of rotating relative to the first arm 12 about a second axis of rotation parallel to the horizontal direction. This second axis of rotation is parallel to an axis orthogonal to the first axis of rotation.

[0028] The second arm 13 and the third arm 14 are connected by a joint 173. Furthermore, the third arm 14 is capable of rotating relative to the second arm 13 about a third axis of rotation parallel to the horizontal direction. This third axis of rotation is parallel to the second axis of rotation.

[0029] The third arm 14 and the fourth arm 15 are connected by a joint 174. Furthermore, the fourth arm 15 is capable of rotating relative to the third arm 14 about a fourth rotation axis parallel to the central axis of the third arm 14. The fourth rotation axis is orthogonal to the third rotation axis.

[0030] The fourth arm 15 and the fifth arm 16 are connected by a joint 175. Furthermore, the fifth arm 16 is capable of rotating relative to the fourth arm 15 about a fifth rotation axis. The fifth rotation axis is orthogonal to the fourth rotation axis.

[0031] The fifth arm 16 and the sixth arm 17 are connected by a joint 176. Furthermore, the sixth arm 17 is capable of rotating relative to the fifth arm 16 about a sixth rotation axis. The sixth rotation axis is orthogonal to the fifth rotation axis.

[0032] Furthermore, the sixth arm 17 is located at the foremost end of the robot arm 10. This sixth arm 17 is driven by the robot arm 10 and can rotate together with the end effector 20.

[0033] like Figure 2As shown, robot 1 includes motors M1, M2, M3, M4, M5, and M6 as drive units, and encoders E1, E2, E3, E4, E5, and E6. Motor M1 is integrated into joint 171, causing the base 11 to rotate relative to the first arm 12. Motor M2 is integrated into joint 172, causing the first arm 12 to rotate relative to the second arm 13. Motor M3 is integrated into joint 173, causing the second arm 13 to rotate relative to the third arm 14. Motor M4 is integrated into joint 174, causing the third arm 14 to rotate relative to the fourth arm 15. Motor M5 is integrated into joint 175, causing the fourth arm 15 to rotate relative to the fifth arm 16. Motor M6 is integrated into joint 176, causing the fifth arm 16 to rotate relative to the sixth arm 17.

[0034] In addition, encoder E1 is built into joint 171 to detect the position of motor M1. Encoder E2 is built into joint 172 to detect the position of motor M2. Encoder E3 is built into joint 173 to detect the position of motor M3. Encoder E4 is built into joint 174 to detect the position of motor M4. Encoder E5 is built into the fifth arm 16 to detect the position of motor M5. Encoder E6 is built into the sixth arm 17 to detect the position of motor M6.

[0035] Encoders E1-E6 are electrically connected to robot control device 2. The position information (rotation amount) of motors M1-M6 is sent to robot control device 2 as electrical signals. Based on this information, robot control device 2 then... Figure 2 The motors M1 to M6 are driven by motor drivers D1 to D6. In other words, controlling the robotic arm 10 means controlling motors M1 to M6.

[0036] The end effector 20 can be detachably mounted to the front end of the robotic arm 10. In this embodiment, the end effector 20 is composed of a gripper having a pair of claws that can approach or separate from each other, and the workpiece is gripped and released by the claws. It should be noted that the end effector 20 is not limited to the configuration shown in the figure, and can also be a gripper that grips the work object (workpiece or tool) by suction. In addition, the end effector 20 can also be, for example, a grinding machine, a milling machine, a cutting machine, a coating device, a spray gun, a screwdriver, a wrench, or other tools.

[0037] Robot 1 uses such an end effector 20 to enable the robotic arm 10 to operate as desired, such as performing various tasks like transporting, manufacturing, processing, assembling, and painting work objects. Hereinafter, these various tasks will be collectively referred to as "tasks".

[0038] Furthermore, the control point TCP is set at the front end of the end effector 20. In the robot system 100, by knowing the location of the control point TCP in advance, the control point TCP can be used as a reference for control.

[0039] Next, the teaching device 3 will be explained.

[0040] like Figure 3 As shown, the teaching pendant 3 is a device for users, administrators, etc., to teach the robot 1. That is, the teaching pendant 3 has the function of creating, inputting, changing, and adjusting the motion program of the robotic arm 10 by inputting and setting various data. Here, "user" refers to users, administrators, etc. Furthermore, the teaching pendant 3 is also a transmitting device 300 that sends the permission signal S1 (described later) to the robot control device 2. There is no particular limitation on the form of the teaching pendant 3; for example, tablet terminals, personal computers, and smartphones can be listed. The permission signal S1 is a general term for permission signals S11 and S12. Permission signal S11 corresponds to the update data DA (described later) used for data in the drive control unit 211, and permission signal S12 corresponds to the update data DA used for data in the monitoring unit 221.

[0041] The teaching device 3 includes a control unit (not shown), a storage unit, a communication unit, an input unit, and a display unit 35.

[0042] The control unit of the teaching device 3 has at least one processor, which is, for example, a CPU (Central Processing Unit) and reads various programs, files, and data stored in the storage unit, such as teaching programs.

[0043] The storage unit of the teaching pendant 3 has the function of storing various programs, files, and data. For example, such a storage unit may be composed of volatile memory such as RAM (Random Access Memory), non-volatile memory such as ROM (Read Only Memory), and removable external storage devices.

[0044] The communication unit of the teaching pendant 3 can transmit and receive signals with the robot control device 2 using external interfaces such as wired LAN (Local Area Network), wireless LAN, or RS-485. Alternatively, it can directly transmit and receive signals with the personal computer 9 or server 400, which will be described later.

[0045] The display unit 35 may be composed of, for example, a liquid crystal display or an organic EL display, and is capable of displaying a specified image. The display unit 35 may also be a so-called touch panel type display unit in which operation selection, item selection, input of various data, and selection of whether to update the update program (described later) can be performed by contacting buttons or the like (digital switches) displayed on the screen.

[0046] The input unit consists of a keyboard, mouse, connector, external connection terminals, etc., allowing users to input or select desired information while viewing the display unit 35 and operating the keyboard or mouse. It also allows users to choose whether to update the update program described later.

[0047] It should be noted that when the display unit 35 is a touch panel type display unit, the buttons and the like (digital switches) displayed on the screen constitute all or part of the input unit.

[0048] By performing a prescribed operation using the input section of the teach pendant 3, the user can generate a permission signal S1 for updating the update program of the robot control device 2 and send it to the robot control device 2. Thus, the robot control device 2 can update the update program based on the user's awareness of the update. Here, the prescribed operation on the teach pendant 3 is, for example, an operation by the user selecting to update the update program via the input section. Furthermore, the prescribed operation on the teach pendant 3 can also be an operation by inputting specific keys on the keyboard or an operation by inputting specific commands via the input section.

[0049] Next, safety door 4 will be explained.

[0050] like Figure 3 As shown, although not illustrated, the safety door 4 includes a safety fence, an opening / closing door installed on the safety fence, an opening / closing detection unit, and an opening / closing signal transmitting unit. The safety door 4 has the function of sending a signal indicating the opening / closing status of the opening / closing unit to the robot control device 2, and also functions as a transmitting device 300 for sending a permission signal S1 to the robot control device 2.

[0051] A safety fence is set up around the movable area of ​​robot 1. This prevents people, obstacles, and other objects from accidentally entering the movable area or approaching robot 1 during its operation, thus ensuring safety.

[0052] The safety fence has openings in certain areas that allow users to enter and exit, and these openings are equipped with doors. When the doors are open, users can enter the inside of the safety fence to perform tasks such as setting up, replacing, or removing workpieces on the robot, or maintaining the robot. Conversely, when the doors are closed, they prevent users from entering or exiting.

[0053] An opening / closing detection unit is installed near the door to detect its open or closed state. The unit generates information about the detected open or closed state, and outputs this information to an opening / closing signal transmitter. The detection method is not particularly limited; examples include optical, contact, and electrostatic capacitive methods.

[0054] The opening / closing signal transmitting unit converts the opening / closing status information output by the opening / closing detection unit into an electrical signal and sends it to the robot control device 2. Furthermore, when the control device is in a state where it can accept permission for program updates, the electrical signal containing the opening / closing status information functions as a permission signal S1. Examples of states where the robot control device 2 can accept permission for program updates include: the period from when the power to the robot control device 2 is turned on until the robot 1 begins to move, and after the user switches to the program update execution mode from the teaching pendant 3.

[0055] Furthermore, when the safety door 4 is subjected to a prescribed operation while the robot 1 is not operating, a permission signal S1 is generated to update the update program of the robot control device 2, and sent to the robot control device 2. Thus, the robot control device 2 can update the update program based on the user's awareness of the update process. Here, the prescribed operation on the safety door 4 is, for example, the user changing the opening / closing door from an open state to a closed state; in other words, the user closing an open opening / closing door. Alternatively, the prescribed operation on the safety door 4 could also be the user changing the opening / closing door from a closed state to an open state.

[0056] Next, the emergency stop switch 5 will be explained.

[0057] like Figure 3 As shown, the emergency stop switch 5 has the function of stopping the robot 1 in an emergency when the user performs a prescribed operation while the robot 1 is running, and also functions as a transmitting device 300 that sends a permission signal S1 to the robot control device 2.

[0058] When the emergency stop switch 5 is operated as described later, it generates an emergency stop signal and sends it to the robot control device 2. Upon receiving the emergency stop signal, the robot control device 2 cuts off power to each motor of the robot 1. This enables the robot 1 to stop in an emergency. At this time, the robot control device 2 can also activate a brake (not shown).

[0059] The emergency stop switch 5 can be a mechanical switch such as a push-button type, slide type, toggle type, or latch type, or it can be a digital switch such as a touch panel type that contacts a button displayed on the screen of the display unit 35, 95, etc. Here, the prescribed operation on the emergency stop switch 5 is, for example, the operation by which the user changes the emergency stop switch 5 from an inactive state to an active state. The operation of changing the emergency stop switch 5 from an inactive state to an active state, for example, is pressing the button when the emergency stop switch 5 is a push-button type.

[0060] Furthermore, when the emergency stop switch 5 is operated as described above while the robot 1 is not in operation, a permission signal S1 is generated authorizing the updating of the robot 1's update program, and sent to the robot control device 2. Thus, the robot control device 2 can update the update program based on the user's awareness of the update process. Here, the condition for generating the permission signal S1 is not limited to the operation described above; for example, it could also be when the user's operation of changing the emergency stop switch 5 from an active state to an inactive state is accepted.

[0061] Next, PLC6 and safety PLC7 will be explained.

[0062] like Figure 3 As shown, PLC6 assists the main control unit 21 (described later), and safety PLC7 assists the safety monitoring unit 22 (described later). Furthermore, PLC6 and safety PLC7 also function as transmitting devices 300 that send permission signals S1 to the robot control device 2.

[0063] PLC6 and safety PLC7 are composed of so-called programmable logic controllers. When they receive an input signal from an input switch (not shown), they output a predetermined signal to the robot control device 2 according to a pre-defined program.

[0064] As an example of the aforementioned input switch, a switch such as the emergency stop switch 5 can be described. As for the aforementioned predetermined procedure, a procedure can be listed for switching the power supply to the robot control device 2, issuing action instructions (interruption action instructions) for the robot 1, issuing emergency stop signals for the robot 1, and sending permission signals S1.

[0065] Furthermore, when a specified operation is performed on PLC6 and safety PLC7 using an input switch (not shown) while robot 1 is not running, a permission signal S1 is generated and sent to robot control device 2. This allows robot control device 2 to update the update program based on the user's awareness of the update process. Here, the specified operation on PLC6 and safety PLC7 is, for example, the user's operation of an input switch (not shown), more specifically, pressing an input switch. The specified operation on PLC6 and safety PLC7 can also be releasing a pressed input switch.

[0066] Next, the teaching box 8 will be explained.

[0067] like Figure 3 As shown, the teach pendant 8 is a device for teaching the robot 1, and has the same function as the teach pendant 3. It also functions as a transmitting device 300 that generates a permission signal S1 and sends it to the robot control device 2.

[0068] The teach pendant 8 has an emergency stop switch 81 and an enable switch 82.

[0069] The emergency stop switch 81 can adopt the same configuration as the aforementioned emergency stop switch 5. That is, when the emergency stop switch 81 is subjected to a specified operation, it generates an emergency stop signal and sends it to the robot control device 2. Upon receiving the emergency stop signal, the robot control device 2 cuts off the power supply to each motor of the robot 1. Thus, the robot 1 can be brought to an emergency stop.

[0070] When the enable switch 82 is turned on, it sends an action permission signal to the robot control device 2, authorizing the robot 1 to operate. When the robot control device 2 receives the action permission signal, it becomes capable of enabling the robot 1 to operate.

[0071] Examples of emergency stop switches 81 and 82 can be listed as those shown in the examples of emergency stop switches 5.

[0072] Furthermore, when the emergency stop switch 81 and enable switch 82 are operated as described above while the robot 1 is not running, an authorization signal S1 is generated and sent to the robot control device 2. Thus, the robot control device 2 can update the update program based on user permission (awareness). Here, the operation specified on the teach pendant 8 is, for example, the user pressing the emergency stop switch 81 or the enable switch 82. The operation specified on the teach pendant 8 can also be the user continuously pressing the emergency stop switch 81 or the enable switch 82 for a certain period of time, or the user releasing the emergency stop switch 81 or the enable switch 82 while it is being pressed.

[0073] Next, the personal computer 9 will be explained.

[0074] like Figure 3 As shown, the personal computer 9 includes a control unit, a storage unit, a communication unit, an input unit (not shown), and a display unit 95.

[0075] The control unit of the personal computer 9 has at least one processor, which is, for example, a CPU (Central Processing Unit), and reads various programs, files, and data stored in the storage unit.

[0076] The communication unit of the personal computer 9 uses external interfaces such as wired LAN (Local Area Network) or wireless LAN to send and receive signals with the server 400 and the robot control device 2.

[0077] The storage unit of the personal computer 9 can be listed as having the same structure and function as the storage unit of the teaching device 3 described above.

[0078] The display unit 95 of the personal computer 9 can be an example of a display unit with the same configuration and function as the display unit 35 of the teaching device 3 described above.

[0079] The input section of the personal computer 9 can be listed as having the same structure and function as the input section of the teaching device 3 described above.

[0080] By performing a prescribed operation using the input section of the personal computer 9, the user can generate an authorization signal S1 that permits the updating of the robot control device 2's update program, and send it to the robot control device 2. Thus, the robot control device 2 can update the update program based on the user's authorization (awareness) of the update. Here, the prescribed operation on the personal computer 9 is, for example, an operation by which the user selects to update the update program via the input section. Furthermore, the prescribed operation on the personal computer 9 can also be an operation by inputting specific keys on the keyboard or an operation by inputting specific commands via the input section.

[0081] Personal computers 9 can be desktop, laptop, tablet, etc., and their form factor is not particularly limited.

[0082] like Figure 3As shown, the personal computer 9 connects to the server 400 via a network through its own communication unit, and receives update data DA from the server 400 for updating the update target program stored in the robot control device 2. Furthermore, when the personal computer 9 receives the update data DA from the server 400, it sends the update data DA to the robot control device 2.

[0083] The personal computer 9 may be configured to send update data DA to the robot control device 2 after the robot control device 2 receives the permission signal S1, or it may be configured to send update data DA to the robot control device 2 before the robot control device 2 receives the permission signal S1, for example, at the time when it receives update data DA from the server 400.

[0084] The update data DA is data used to rewrite the update target program described later. Specifically, for example, it can include the control program of the robotic arm 10 executed by the main control unit 21, the communication program with external devices, the monitoring program executed by the safety monitoring unit 22, the attribute information such as the size of the robotic arm 10 used in the program, the operating system, the teaching data, and the setting information of the control device.

[0085] The data DA used for updating can be local data or it can be all the data of the program that rewrites the update object.

[0086] Furthermore, the update data DA is preferably data encrypted with a hash value using a public or private key. In this case, the robot control device 2 verifies the signature of the update data DA; if the signature verification is successful, the update data DA is used to update the program being updated. This further enhances security.

[0087] Furthermore, the personal computer 9 also functions as a transmitting device 300 for sending an authorization signal S1 to the robot control device 2. When a specified operation is performed using the personal computer 9, the personal computer 9 generates an authorization signal S1 and sends it to the robot control device 2. Thus, the robot control device 2 can update the update program based on the user's permission (awareness) to do so.

[0088] It should be noted that the personal computer 9 can also have the function of teaching the robot 1. That is, it can also have the same configuration or function as the aforementioned teaching device 3.

[0089] Next, the robot control device 2 will be described.

[0090] like Figure 1 , Figure 2 and Figure 3As shown, the robot control device 2 has various functions, including controlling the operation of the robot 1 and updating the program (update target program) stored internally. The robot control device 2 includes a main control unit 21, a safety monitoring unit 22, an update data receiving unit 23, a permission signal receiving unit 24, and a notification signal generating unit 25.

[0091] The main control unit 21 includes a drive control unit 211, a storage unit 212, a communication unit 213, and an update unit 214 (first update unit).

[0092] The drive control unit 211 has functions such as controlling the drive of the robot 1, and determining whether the permission signal receiving unit 24 has received the permission signal S1 when the update data DA is the data used for monitoring unit 211 (described later). The drive control unit 211 has at least one processor. This processor is, for example, a CPU (Central Processing Unit). The drive control unit 211 reads and executes the action program stored in the storage unit 212. The action program is a program created by the teaching device 3, etc.

[0093] Storage unit 212 has the function of storing various programs, files, and data, such as operation programs. As storage unit 212, for example, storage units composed of volatile memory such as RAM (Random Access Memory), non-volatile memory such as ROM (Read Only Memory), and removable external storage devices can be listed.

[0094] The program stored in storage unit 212 is an update target program that is updated based on update data DA received by update data receiving unit 23. In addition to the above-mentioned action program, update target programs may include boot programs used to start robot control device 2 such as boot programs, BIOS, loader, and kernel, as well as various files and data associated with them.

[0095] The communication unit 213 uses external interfaces such as wired LAN (Local Area Network) or wireless LAN to transmit and receive signals with the robot 1.

[0096] The update unit 214 has the function of updating the update target program stored in the storage unit 212 based on the update data DA. "Update the update target program" in this specification includes processes such as rewriting all or part of the program being updated, in other words, applying append programs, and deleting part of the update target program. Hereinafter, the processes of rewriting all or part of the program being updated, applying append programs, and deleting part of the update target program are sometimes simply referred to as "processing". Updating the update target program includes, for example, rewriting a part of the files, data, etc., included in the update target program, adding other programs to the update target program, and reconstructing all or part of the update target program.

[0097] For the purpose of updating the program, for example, one could change some functions of robot 1, add functions to robot 1, correct errors in the program, maintain or improve the safety level, etc.

[0098] Updates to an object can be of the following types: (1), (2), (3), and (4).

[0099] (1) Feature updater: This is an updater that adds features to the OS, also known as a "major upgrade" or "upgrade".

[0100] (2) Quality update procedure: This is an update procedure aimed at correcting problems and errors in the system and enhancing security.

[0101] (3) Definition files of viruses and malware: This is the program that updates the definition files of viruses and malware.

[0102] (4) Model addition file: This is a program that updates the information of the robotic arm when a robotic arm model is added.

[0103] The update unit 214 has at least one processor. Examples of processors include a CPU. The update unit 214 reads and executes an update program stored in the storage unit 212. The update program is a program used to perform the aforementioned processing.

[0104] The update unit 214 may be configured to perform the aforementioned processing on the program before the update, or it may be configured to pre-copy the program before the update and perform the aforementioned processing on the copied data.

[0105] It should be noted that the drive control unit 211 and the update unit 214 can also be composed of a single processor.

[0106] The security monitoring unit 22 includes a monitoring unit 221, a storage unit 222, a communication unit 223, and an update unit 224 (second update unit).

[0107] The monitoring unit 221 has functions such as monitoring the drive of the robot 1 and determining whether the permission signal receiving unit 24 has received the permission signal S1 when the update data DA is the data used for the monitoring unit 221 (described later). As functions for monitoring the operation of the robot 1, for example, monitoring the speed, position, etc., of specified parts of the robotic arm 10. The monitoring unit 221 has at least one processor. For example, a CPU (Central Processing Unit) can be included as a processor. The monitoring unit 221 reads and executes the monitoring program stored in the storage unit 222. The monitoring program is, for example, a program created by the teaching device 3, etc.

[0108] Storage unit 222 has the function of storing various programs, files, and data, such as monitoring programs. For example, storage units 222 can be configured with volatile memory such as RAM, non-volatile memory such as ROM, and removable external storage devices.

[0109] The program stored in storage unit 222 is an update target program that is updated based on update data DA received by update data receiving unit 23. In addition to the monitoring program mentioned above, other update target programs may include boot programs, BIOS, loader, kernel, and other boot programs used to start the robot control device 2.

[0110] The communication unit 223 uses external interfaces such as wired LAN (Local Area Network) or wireless LAN to transmit and receive signals with the robot 1.

[0111] The update unit 224 has the function of updating the update target program stored in the storage unit 222 based on the update data DA. The update unit 224 has at least one processor. Examples of processors include a CPU. The update unit 224 reads and executes the update program stored in the storage unit 222. The update program is a program used to perform the above-described processing.

[0112] It should be noted that the monitoring unit 221 and the update unit 224 can also be composed of a single processor. The update units 214 and 224 are collectively referred to as the "update unit".

[0113] The update data receiving unit 23 has the function of receiving update data DA for updating the program to be updated. The update data DA is as described above. Examples of update data receiving units 23 include terminals connected to signal lines from the personal computer 9 and communication modules that communicate with the personal computer 9.

[0114] When an operation to update the target program has been authorized, the authorization signal receiving unit 24 receives an authorization signal S1 indicating that the operation has been performed. The authorization signal S1 is a signal transmitted from each of the aforementioned transmitting devices 300. The authorization signal receiving unit 24 may include, for example, a terminal connected to the signal line from each transmitting device 300, a communication module that communicates with the personal computer 9, etc.

[0115] Notification signal generation unit 25, for example, generates signals for generating Figure 4 The first notification signal of the notification screen 500 shown, and the signal used to generate Figure 5 The second notification signal is shown in the notification screen 600.

[0116] The first notification signal is used to notify that the permission signal S1 has not been received when the update data receiving unit 23 receives update data DA and the permission signal receiving unit 24 does not receive the permission signal S1. The second notification signal is used to notify that the update of the update target program has been completed when the update unit 214 or the update unit 224 has completed the update.

[0117] The notification signal generation unit 25 sends a first notification signal and a second notification signal to the personal computer 9. The personal computer 9 generates a notification signal based on the received first notification signal through its own control unit. Figure 4 The notification screen 500 shown is, for example, displayed on the display unit 95. Furthermore, the personal computer 9 generates a notification screen based on the received second notification signal via its own control unit. Figure 5 The notification screen 600 shown is displayed, for example, on the display unit 95. Thus, the display unit 95 can visually notify users that update data DA has been received but the permission signal S1 has not yet been received, and that the update of the target program has been completed. It should be noted that the notification may also be displayed on the display unit 35 of the teaching pendant 3 instead of the display unit 95, or on a display unit not shown other than the display units 35 and 95. Furthermore, the notification method is not limited to visual notifications such as those displayed on the display units 35 and 95; for example, notifications may be made via sound, or through serial communication, or via electrical output from external devices.

[0118] In this embodiment, the notification signal generation unit 25 generates a signal that visually notifies the above content. However, in this invention, the notification method is not limited to this. The notification signal generation unit 25 may also generate a signal that notifies the above content audibly or tactilely.

[0119] In the case of auditory notification, for example, methods can be described by setting up a buzzer or speaker and emitting sound from the buzzer or speaker to make the notification.

[0120] In this control system 200, the personal computer 9 receives update data DA from the server 400 and sends update data DA to the robot control device 2. When the robot control device 2 receives the update data DA, it does not automatically or immediately update the program to be updated as in the past. Instead, if it receives a permission signal S1 from the aforementioned sending devices 300, it updates the program to be updated based on the update data DA. If it does not receive a permission signal S1, it does not update the program to be updated.

[0121] Receiving the permission signal S1 from the transmitting device 300 indicates that a user near the robot 1 has given permission (awareness) to update the program. Updates can only be performed with user permission. This prevents unintentional updates to the program, such as malicious third-party tampering or malicious virus intrusion. Therefore, the security level is increased, enhancing safety. Furthermore, it prevents the program from being updated at unexpected times, preventing updates from causing unexpected interruptions to the robot 1's operation, ensuring continuous and smooth operation.

[0122] Furthermore, the robot control device 2, as described above, is connected to each of the transmitting devices 300. The following description focuses on the teaching pendant 3 and the safety door 4 within each of the transmitting devices 300. Specifically, the teaching pendant 3 is the first transmitting device, and the safety door 4 is the second transmitting device.

[0123] In the robot control device 2, the update unit 214 or update unit 224 may update the program to be updated only when a permission signal S1 is received from either the teach pendant 3 or the safety gate 4. This allows for faster updates to the program to be updated while ensuring safety.

[0124] Furthermore, in the robot control device 2, the update unit 214 or update unit 224 can update the program to be updated when a permission signal S1 is received from both the teach pendant 3 and the safety gate 4. This further enhances safety.

[0125] It should be noted that in the above description, the teaching pendant 3 was used as an example of the first transmitting device and the safety door 4 was used as an example of the second transmitting device. However, this invention is not limited to these examples. The first transmitting device can also be a transmitting device 300 other than the teaching pendant 3, that is, the safety door 4, the emergency stop switch 5, the PLC 6, the safety PLC 7, the teaching pendant 8, and the personal computer 9 are all acceptable. In this case, the second transmitting device is a transmitting device 300 other than the first transmitting device.

[0126] Preferably, the first transmitting device is the teaching pendant 3 and the second transmitting device is the teaching box 8. The teaching pendant 3 and the teaching box 8 are likely to be carried by the user at all times, and can quickly transmit the permission signal S1.

[0127] Furthermore, from other perspectives, the first and second transmitting devices are preferably any one of the following: a teaching pendant 3 for teaching the robot 1, an emergency stop switch 5 for causing the robot 1 to stop urgently, a safety gate 4 located around the robot 1, and a teaching pendant 8. These devices are actually used in various field applications, therefore, the present invention is easy to apply and has excellent versatility.

[0128] Furthermore, in the robot control device 2, the update unit 214 or update unit 224 may update the program to be updated when a permission signal S1 is received from three or more of the transmitting devices 300, including the teach pendant 3, safety door 4, emergency stop switch 5, PLC 6, safety PLC 7, teach pendant 8, and personal computer 9. This further enhances safety.

[0129] Thus, the first or second transmitting device is a safety input device that sends safety-related signals about the robot 1's movements to the robot control device 2, which serves as a control device. This further enhances safety.

[0130] Next, we will explain according to the types of data DA used for updating.

[0131] The update data DA exists in two forms: one for the drive control unit 211 and the other for the monitoring unit 221. Specifically, the update data DA exists for updating the program executed by the drive control unit 211 and for updating the program executed by the monitoring unit 221. The type of update data DA can be identified by the personal computer 9, and the identification result information can be sent to the robot control device 2 along with the update data DA.

[0132] In this embodiment, the permission signal S1, which is the object of the determination of whether the update data DA has been received, varies depending on the type of update data DA. More specifically, when the update data DA is data used for the drive control unit 211, it is determined whether the permission signal S11 has been received. If the permission signal S11 is determined to have been received, the update procedure is executed. When the update data DA is data used for the monitoring unit 221, it is determined whether the permission signal S12 has been received. If the permission signal S12 is determined to have been received, the update procedure is executed.

[0133] In the above configuration, for example, suppose that after receiving update data DA, a permission signal S11 is received, but a permission signal S12 is not received. In this case, if the update data DA is data used for the drive control unit 211, it is determined that the permission signal S11 has been received, and therefore, the update procedure is executed. On the other hand, if the update data DA is data used for the monitoring unit 221, it is determined that the permission signal S12 has not been received, and therefore, the update procedure is not executed. According to this configuration, by requiring the receipt of different permission signals depending on the type of update data DA, unintentional updates to the program to be updated can be prevented, and security can be further improved.

[0134] It should be noted that in this embodiment, the configuration described below is illustrated: when the update data DA is data used for the drive control unit 211, it is determined whether a permission signal S11 has been received; when the update data DA is data used for the monitoring unit 221, it is determined whether a permission signal S12 has been received, but this is not a limitation. For example, the configuration described below can also be adopted: depending on the type of update data DA, if either permission signal S11 or S12 is received, the update procedure is executed. Furthermore, to avoid system complexity, the configuration described below can also be adopted: the permission signal is only S11, and regardless of the type of update data DA, if permission signal S11 is received, the update procedure is executed.

[0135] Furthermore, in the robot control device 2, when the update data DA is data used by the drive control unit 211, the drive control unit 211 determines whether the permission signal receiving unit 24 has received the permission signal S11. When the update data DA is data used by the monitoring unit 221, the monitoring unit 221 determines whether the permission signal receiving unit 24 has received the permission signal S12. In this way, by distributing the determination of whether the permission signal S1 has been received according to the various types of update data DA, i.e., by distributing the determination processing and update processing, the overall processing can be performed smoothly. Therefore, the update program can be updated quickly while reducing the burden on each processor.

[0136] It should be noted that, alternatively, if the update data DA is data used for the drive control unit 211, the determination of whether the license signal receiving unit 24 has received the license signal S11 can be performed by a processor other than the drive control unit 211. Furthermore, if the update data DA is data used for the monitoring unit 221, the determination of whether the license signal receiving unit 24 has received the license signal S12 can be performed by a processor other than the monitoring unit 221.

[0137] Here, the permission signals S11 and S12 can also be transmitted from different transmitting devices 300. For example, the following configuration can be adopted: permission signal S11 can be generated by the teaching pendant 3, safety door 4, and emergency stop switch 5, and permission signal S12 can be generated by PLC 6, safety PLC 7, teaching pendant 8, and personal computer 9. The transmitting device 300 capable of generating permission signal S11 and the transmitting device 300 capable of generating permission signal S12 are not limited to the above-mentioned transmitting device 300 and can be appropriately configured. In addition, a configuration can be adopted that has a transmitting device 300 capable of generating both permission signals S11 and S12.

[0138] As explained above, the robot control device 2 is a control device for controlling the operation of the robot 1 with the robotic arm 10. It includes: storage units 212 and 222 for storing an update target program; an update data receiving unit 23 for receiving update data DA for updating the update target program; a permission signal receiving unit 24 for receiving a permission signal indicating that an operation to update the update target program has been permitted; and update units 214 and 224 for updating the update target program based on the update data DA received by the update data receiving unit 23. The update units 214 and 224 update the update target program only when the permission signal receiving unit 24 receives the permission signal; otherwise, they do not update the update target program. This prevents unintentional updates to the update target program, such as preventing malicious third-party tampering or intrusion by harmful viruses. Therefore, security is improved.

[0139] Furthermore, the control system 200 includes a robot control device 2 as a control unit and a transmitting device 300. The robot control device 2 includes: storage units 212 and 222 storing an update target program; an update data receiving unit 23 receiving update data DA for updating the update target program; a permission signal receiving unit 24 receiving a permission signal S1, indicating that an operation to update the update target program has been permitted; and update units 214 and 224 updating the update target program based on the update data DA. The transmitting device 300 sends the permission signal S1 to the permission signal receiving unit 24. The update units 214 and 224 update the update target program only when the permission signal receiving unit receives the permission signal S1; otherwise, they do not update the update target program. This prevents unintentional updates to the update target program, such as preventing malicious third-party tampering or intrusion by harmful viruses. Therefore, security is improved.

[0140] The transmitting device 300 is a safety input device that sends safety-related signals from the actions of the controlled object, which are controlled by the robot control device 2 as a control device, to the robot control device 2. This further enhances safety.

[0141] It should be noted that the transmitting device 300 is described using the teaching pendant 3, safety door 4, emergency stop switch 5, PLC 6, safety PLC 7, teaching box 8, and personal computer 9 as examples, but the control system 200 may not have all of them.

[0142] The permission signal receiving unit 24 of the robot control device 2 is connected to the teaching device 3, which is an example of a first transmitting device, and the safety door 4, which is an example of a second transmitting device, respectively. When the permission signal receiving unit 24 receives the permission signal S1 from at least one of the teaching device 3 and the safety door 4, the updating units 214 and 224 update the program to be updated. As a result, the program to be updated can be updated more quickly and easily while ensuring safety.

[0143] The permission signal receiving unit 24 of the robot control device 2 is connected to the teaching device 3, which is an example of a first transmitting device, and the safety door 4, which is an example of a second transmitting device, respectively. When the permission signal receiving unit 24 receives the permission signal S1 from both the teaching device 3 and the safety door 4, the updating units 214 and 224 update the program to be updated. As a result, safety can be further improved.

[0144] The first sending device is any one of the following: a teaching pendant 3 for teaching robot 1, an emergency stop switch 5 for causing robot 1 to stop urgently, a safety gate 4 located around robot 1, and a teach pendant 8. The second sending device is any one of the following: a teaching pendant 3 for teaching robot 1, an emergency stop switch 5 for causing robot 1 to stop urgently, a safety gate 4 located around robot 1, and a teach pendant 8, but of a different type from the first sending device. These devices are actually used in various field applications, therefore, the present invention can be easily applied and has excellent versatility. Therefore, it has excellent convenience and can update the program of the updated object more quickly and easily.

[0145] The robot control device 2 includes a drive control unit 211 for controlling the drive of the robot 1 and a monitoring unit 221 for monitoring the drive of the robot 1. When the update data DA is data used by the drive control unit 211, the drive control unit 211 determines whether the permission signal receiving unit 24 has received the permission signal S1. When the update data DA is data used by the monitoring unit 221, the monitoring unit 221 determines whether the permission signal receiving unit 24 has received the permission signal. In this way, by distributing the determination of whether the permission signal S1 has been received according to various types of update data DA, that is, by distributing the determination processing and update processing, the overall processing can be performed quickly and smoothly. Therefore, the update program can be updated quickly and smoothly while reducing the burden on each processor.

[0146] The robot control device 2 includes a notification signal generation unit 25. When the update data receiving unit 23 receives update data DA and the permission signal receiving unit 24 does not receive the permission signal S1, the notification signal generation unit 25 generates a first notification signal indicating that the permission signal S1 has not been received. By notifying the user based on the first notification signal, the user can understand that the permission signal receiving unit 24 has not received the permission signal S1. Therefore, the user can easily and reliably know when the update opportunity has arrived and will not miss it; furthermore, the user can easily and reliably know when to postpone the update.

[0147] When the update units 214 and 224 complete the update of the target program, the notification signal generation unit 25 generates a second notification signal indicating that the update is complete. By notifying the user based on the second notification signal, the user can easily and reliably know that the update of the target program is complete.

[0148] Next, for an example of the program update method of the present invention, see... Figure 6 The flowchart shown will be used for illustration.

[0149] First, in step S101, update data DA is received. That is, the update data receiving unit 23 receives update data DA from the personal computer 9. Furthermore, the update data receiving unit 23 receives information from the personal computer 9 along with the update data DA indicating whether the update data DA is for the drive control unit 211 or for the monitoring unit 221. Step S101 is the update data receiving step.

[0150] Next, in step S102, it is determined whether a permission signal S1 has been received. This step is performed by either the drive control unit 211 or the monitoring unit 221. If the update data DA received in step S101 is data for the drive control unit 211, step S102 is performed by the monitoring unit 221; otherwise, if the update data DA is data for the monitoring unit 221, step S102 is performed by the drive control unit 211. Step S102 is a determination step.

[0151] If in step S102 it is determined that a permission signal S1 corresponding to the type of data DA to be updated has been received (step S102: Yes), proceed to step S103; if it is determined that no permission signal S1 has been received (step S102: No), proceed to step S105.

[0152] In step S103, the program to be updated is determined and updated. In this step, if the update data DA received in step S101 is data for the drive control unit 211, the update unit 214 updates the program to be updated stored in the storage unit 212 based on the update data DA; if it is data for the monitoring unit 221, the update unit 224 updates the program to be updated stored in the storage unit 222 based on the update data DA. Step S103 is the update step.

[0153] Next, in step S104, a notification is made. Specifically, the notification signal generation unit 25 generates a second notification signal to notify the update unit 214 or update unit 224 that the update of the program to be updated has been completed, and sends it to the personal computer 9. Then, the personal computer 9 displays a notification screen 600 on the display unit 95 based on the second notification signal (see reference). Figure 5 Therefore, the user can be aware that the update of the updated object program has been completed.

[0154] On the other hand, if it is determined in step S102 that a permission signal S1 corresponding to the type of update data DA has not been received, a notification is made in step S105. That is, the notification signal generation unit 25 generates a first notification signal to notify that the permission signal S1 has not been received and sends it to the personal computer 9. Then, the personal computer 9 displays a notification screen 500 on the display unit 95 (see reference 500) based on the first notification signal. Figure 4 Thus, the user can detect when the permission signal S1 has not been sent. Therefore, the user determines whether to send the permission signal S1 and takes further action.

[0155] After step S105, proceed to step S102 and execute step S102.

[0156] When displaying the notification screen 500 on the display unit 95 as in step S105, it is preferable to also display information on the notification screen 500 regarding whether the update data DA is data used for the drive control unit 211 or data used for the monitoring unit 221. That is, it is preferable that the first notification signal includes information about the type of the received update data DA. As a result, the user has more information to make when deciding whether to send the permission signal S1, and can make a more appropriate judgment. It should be noted that this judgment is based on the progress of the operation, the importance of the update, etc.

[0157] As explained above, the program update method is a method for updating an update target program stored in a robot control device 2, which controls the operation of a robot 1 with a robotic arm 10. The program update method includes: an update data receiving step, receiving update data DA for updating the update target program; a determination step, determining whether a permission signal S1 has been received, indicating that an operation to update the update target program has been permitted; and an update step, updating the update target program if the determination step indicates that the permission signal S1 has been received. By executing such a program update method, unintentional updates to the update target program can be prevented, for example, preventing malicious third-party tampering with the update target program or intrusion by harmful viruses. Therefore, security can be improved.

[0158] In this embodiment, examples of transmitting devices 300 include a teaching pendant 3, a safety door 4, an emergency stop switch 5, a PLC 6, a safety PLC 7, a teach pendant 8, and a personal computer 9. The safety door 4, emergency stop switch 5, and safety PLC 7 among these transmitting devices 300 can be considered as transmitting devices 300 that send safety-related signals from the robot 1's actions to the robot control device 2. When the robot control device 2 receives a safety-related signal, it performs actions such as stopping the robot 1. The transmitting devices 300 that send safety-related signals to the robot control device 2 are collectively referred to as safety input devices. In this embodiment, the safety door 4, emergency stop switch 5, and safety PLC 7 correspond to safety input devices.

[0159] Here, robot 1 is an example of a controlled object whose actions are controlled by a control device. The controlled object whose actions are controlled by a control device is not limited to a robot; it could also be a machine tool. In this case, any system configuration that includes a control device for controlling the machine tool can be used instead of robot control device 2.

[0160] As a variation of this embodiment, the security input device can also be configured as a transmitting device 300 capable of generating a permission signal S1. Such a security input device is highly likely to be equipped with a user monitoring the robot 1's actions in an environment where the robot 1 is actually performing its actions. Therefore, by having a user monitoring the robot 1 operate the security input device to confirm the update of the update target program, unintentional updates to the update target program can be prevented, for example, preventing malicious third parties from tampering with the update target program or the intrusion of harmful viruses. Thus, security can be improved.

[0161] Furthermore, the configuration of the update data receiving unit, the permission signal receiving unit, and the notification signal generating unit in this embodiment is just one example. For example, at least one of the update data receiving unit, the permission signal receiving unit, and the notification signal generating unit may also be included in the main control unit or the security monitoring unit.

[0162] The control device, control system, and program updating method of the present invention have been described above based on the illustrated embodiments, but the present invention is not limited thereto. Furthermore, each part and step of the control device, control system, and program updating method can be replaced with any structure or step that can perform the same function. Additionally, any arbitrary structure or step may be added.

Claims

1. A control device, characterized in that, The control device for controlling the operation of a robot with a robotic arm includes: The storage department stores the update object program, which is the object to be updated. The update data receiving unit receives update data for updating the program to be updated; The permission signal receiving unit receives a permission signal, which indicates that permission has been granted to update the program being updated. as well as The update unit updates the program to be updated based on the update data received by the update data receiving unit. The updating unit updates the program to be updated when the license signal receiving unit receives the license signal, and does not update the program to be updated when the license signal receiving unit does not receive the license signal.

2. The control device according to claim 1, characterized in that, The permission signal receiving unit is connected to the first transmitting device and the second transmitting device that transmit the permission signal, respectively. When the license signal receiving unit receives the license signal from at least one of the first transmitting device and the second transmitting device, the updating unit updates the update target program.

3. The control device according to claim 1, characterized in that, The permission signal receiving unit is connected to the first transmitting device and the second transmitting device that transmit the permission signal, respectively. When the license signal receiving unit receives the license signal from both the first transmitting device and the second transmitting device, the updating unit updates the program to be updated.

4. The control device according to claim 2 or 3, characterized in that, The first transmitting device is any one of the following: a teaching pendant for teaching the robot, an emergency stop switch for causing the robot to stop in an emergency, a safety door located around the robot, or a teaching pendant. The second transmitting device is any one of the following: the teaching device for teaching the robot, the emergency stop switch for causing the robot to stop in an emergency, the safety door located around the robot, or the teaching box, and is of a different type from the first transmitting device.

5. The control device according to claim 2 or 3, characterized in that, The first or second transmitting device is a safety input device that sends safety-related signals related to the robot's actions to the control device.

6. The control device according to any one of claims 1 to 3, characterized in that, The control device includes: A drive control unit controls the drive of the robot; and The monitoring unit monitors the robot's operation. When the update data is data used by the drive control unit, the drive control unit determines whether the permission signal receiving unit has received the permission signal. When the update data is data used by the monitoring unit, the monitoring unit determines whether the permission signal receiving unit has received the permission signal.

7. The control device according to any one of claims 1 to 3, characterized in that, The control device includes: A drive control unit controls the drive of the robot; and The monitoring unit monitors the robot's operation. When the update data is data used for the drive control unit. The first update unit, included in the update unit, updates the program to be updated when the license signal receiving unit receives the first license signal from the license signals; otherwise, it does not update the program to be updated when the license signal receiving unit does not receive the first license signal. When the update data is data used for the monitoring unit. The second update unit included in the update unit updates the update target program when the license signal receiving unit receives a second license signal that is different from the first license signal in the license signal, and does not update the update target program when the license signal receiving unit does not receive the second license signal.

8. The control device according to any one of claims 1 to 3, characterized in that, The control device includes a notification signal generation unit that generates a first notification signal that indicates that the permission signal has not been received when the update data receiving unit receives the update data and the permission signal receiving unit does not receive the permission signal.

9. The control device according to claim 8, characterized in that, The notification signal generation unit generates a second notification signal indicating that the update of the update target program by the update unit has been completed.

10. A control system, characterized in that, Equipped with control and transmission devices, The control device includes: The storage department stores the update object program, which is the object to be updated. The update data receiving unit receives update data for updating the program to be updated; The permission signal receiving unit receives a permission signal, which indicates that permission has been granted to update the program being updated. as well as The update unit updates the program to be updated based on the update data. The transmitting device sends the permission signal to the permission signal receiving unit. The updating unit updates the program to be updated when the license signal receiving unit receives the license signal, and does not update the program to be updated when the license signal receiving unit does not receive the license signal.

11. The control system according to claim 10, characterized in that, The transmitting device is a safety input device that sends safety-related signals about the actions of a controlled object to the control device.

12. A method for updating a program, characterized in that, The update method involves updating the update target program stored in the control device, which controls the operation of a robot with a robotic arm. The update data receiving step involves receiving update data used to update the program being updated. The determination step involves determining whether a permission signal has been received, whereby the permission signal indicates that permission has been granted to update the program being updated. as well as The update step involves updating the program to be updated if the permission signal is received as determined in the judgment step.

Citation Information

Patent Citations

  • Automatic updating system, and updating method and program therefor

    JP2020149345A