Safety device

The safety device configuration with dual control units and CRC-based data comparison addresses the challenges of high development costs and processing loads in existing safety devices, achieving low-cost, low-processing-load safety function realization.

JP2025095482APending Publication Date: 2025-06-26OMRON CORP

Patent Information

Application Number
JP2023211512
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-14
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing safety devices with embedded real-time operating systems face challenges in implementing functional safety standards, leading to increased development man-hours and costs due to complex authentication processes and high license fees for certified RTOS. Additionally, implementing self-diagnosis functions in non-certified RTOS increases processing load and reduces resource allocation to original device functions.

Method used

A safety device configuration with two control units, each with a real-time operating system and processor, compares data related to task calculations between the two units to detect abnormalities. This configuration uses CRC operations to convert multiple data points into a single code for comparison, allowing for asynchronous task execution and reducing processing load.

Benefits of technology

This approach enables the realization of safety functions at low cost and with low processing load, allowing resources to be allocated to original device functions rather than safety functions. It also allows the use of non-certified RTOS, reducing development man-hours and costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025095482000001_ABST
    Figure 2025095482000001_ABST
Patent Text Reader

Abstract

To provide a technology that enables a safety function of a device operated by a built-in RTOS at a low cost and with a low processing load.SOLUTION: A safety device has at least two control units. Each of the control units has a real-time operating system (RTOS) and a processor that executes a task. Each of the control units is configured to output a safety output signal generated based on calculation results of one or more tasks, perform comparison processing to compare, for one or more tasks that affect a value of the safety output signal, data related to calculation of the own task, which is a task executed by the own processor, with data related to calculation of a corresponding task, which is a task executed by a processor of the other control unit and corresponds to the own task, and if a result of the comparison processing is a mismatch, determine that an abnormality has occurred.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a safety device that operates on an embedded real-time operating system.

Background Art

[0002] In the field of factory automation, in order to ensure the safety of workers in factories and work sites, devices equipped with safety functions (referred to as "safety devices", "safety products", "safety equipment", etc.) are used. This type of safety device is equipped with a function to detect hardware failures and software errors by itself and take necessary safety measures.

[0003] In the design of safety devices, an embedded real-time operating system (embedded RTOS) may be adopted. By using RTOS, the development and implementation of various software become easier, so the man-hours required for developing safety devices that perform complex functions and various processes can be shortened.

[0004] Conventionally, when attempting to realize a safety device implemented with an embedded RTOS, in order to ensure its safety, an RTOS that conforms to a functional safety standard such as IEC61508 (hereinafter referred to as "safety RTOS") is adopted, or a self-diagnosis function for hardware failures and software errors is implemented. Either measure is necessary. Patent Document 1 discloses a configuration example of the former measure.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] When adopting a secure RTOS, if one tries to perform authentication on one's own, the authentication process of the functional safety standard is complex and time-consuming, leading to an increase in the development man-hours of the device. Therefore, it is realistic to obtain a license for a certified secure RTOS from another OS manufacturer, but there is a problem that the license fee will increase the device cost.

[0007] On the other hand, in the case of the latter countermeasure, since one can use a RTOS that has not received the functional safety standard certification (hereinafter referred to as "general-purpose RTOS"), the problem of license fees does not occur. However, another problem occurs, that is, man-hours are generated for additionally implementing a self-diagnosis function. Also, during the operation of the device, in addition to the original tasks, tasks of the self-diagnosis function have to be additionally executed, so that the resources (processor, memory) that can be allocated to the original tasks are reduced, and there is a problem that the performance of the entire device deteriorates.

[0008] The present invention has been made in view of the above circumstances, and an object thereof is to provide a technique for realizing the safety function of a device operating on an embedded RTOS at low cost and with low processing load.

Means for Solving the Problems

[0009] The present disclosure has at least two control units, and each of the two control units has a real-time operating system (RTOS) and a processor that executes a task operating on the RTOS, and is configured to output a safety output signal generated based on the calculation results of one or more tasks, and affects the value of the safety output signal For each of one or more tasks, comparison processing is executed to compare data related to the calculation of the self-task, which is the task executed by its own processor, with data related to the calculation of the corresponding task, which is the task executed by the processor of the other control unit and corresponds to the self-task, and when the result of the comparison processing is inconsistent, it is configured to determine it as an abnormality, including a safety device.

[0010] The data related to the operation of the task includes a plurality of data. Each of the two control units converts the plurality of data related to the operation of the self-task into one code, transmits the converted code to the processor of the other control unit, receives the code converted from the plurality of data related to the operation of the corresponding task from the processor of the other control unit, and may be configured to compare the code of the self-task and the code of the corresponding task in the comparison process.

[0011] Each of the two control units may convert the plurality of data related to the operation of the self-task into one code by CRC operation.

[0012] The CRC operation may be executed by a CRC operation unit provided separately from the processor.

[0013] Each of the two control units may be configured to execute the comparison process by a comparison task independent of the self-task and the corresponding task.

[0014] The two control units are configured to execute tasks asynchronously. The comparison task can asynchronously execute the process of acquiring the data to be compared from the self-task and the process of acquiring the data to be compared from the corresponding task, and may be configured to execute the comparison process at the timing when the data of both the self-task and the corresponding task are complete.

[0015] If the comparison task fails to acquire the other data within a predetermined time after acquiring one of the data to be compared of the self-task and the data to be compared of the corresponding task, it may be determined as an abnormality.

[0016] The data related to the operation of the task may include the data output as the operation result of the task.

[0017] Data related to the operation of the task may include data input to the operation of the task.

[0018] The RTOS may be an RTOS that has not received functional safety standard certification.

[0019] The present invention may be regarded as a safety device (also called a safety product or safety equipment) having at least a part of the above configuration. Further, the present invention can also be regarded as a control method of a safety device including at least a part of the above processing, a method for detecting an abnormality of a safety device, or a program for realizing such a method and a recording medium in which the program is non-temporarily recorded. Note that each of the above configurations and processes can be combined with each other as much as possible to constitute the present invention.

Effect of the Invention

[0020] According to the present invention, the safety function of a device operating on an embedded RTOS can be realized at low cost and with low processing load.

Brief Description of the Drawings

[0021]

Figure 1

Figure 2

Figure 3

Figure 4

Modes for Carrying Out the Invention

[0022] <Application Example> With reference to FIG. 1, one application example of the present invention will be described.

[0023] FIG. 1 is a block diagram schematically showing the internal configuration of a safety device to which the present invention is applied. The safety device 1 is a type of industrial equipment used in factories, work sites, etc., and refers to equipment equipped with a so-called safety function. Representative safety devices 1 include, for example, safety sensors such as safety light curtains and safety laser scanners, safety controllers, safety switches, and the like.

[0024] The safety device 1 employs a dual configuration consisting of at least two control units 10A and 10B. Since the configurations of the control unit 10A and the control unit 10B are basically the same, hereinafter, in the common description of both units 10A and 10B, they may sometimes be referred to as "control unit 10". The control unit 10 is a small computer having a processor, a memory, peripherals (peripheral devices), and the like. The memory stores an embedded RTOS, software programs operating on the RTOS, and the like.

[0025] The control unit 10 is configured to generate a safety output signal based on the calculation results of one or more tasks and output the safety output signal to an external device 2 via an output circuit (not shown). The same task is executed by the control unit 10A and the control unit 10B, and safety output signals are output from both units 10A and 10B, respectively. In the external device 2, safety control of the device is performed based on the two systems of safety output signals input from the safety device 1.

[0026] In the example of FIG. 1, in control unit 10A, six tasks, namely tasks T1A, T2A, T3A, T4A, T5A, and T6A, are executed. Similarly, in control unit 10B, six tasks, namely tasks T1B, T2B, T3B, T4B, T5B, and T6B, are executed. Here, the numbers (1 to 6) in the reference signs attached to the tasks represent the types of tasks, and the alphabet (A or B) attached at the end of the reference sign represents the control unit in which the task is executed. That is, task T1A executed in control unit 10A and task T1B executed in control unit 10B are tasks of the same type. In a context where it is not necessary to distinguish control units, the alphabet at the end of the reference sign may be omitted, and it may be simply described as "task T1" or the like. Also, using "x" representing an arbitrary number, it may be described as "task Tx" or the like.

[0027] Each task Tx can be modeled by an operation Px, and data Ix and Ox related to the operation Px. Data Ix is input data input as an operand to the operation Px, and data Ox is output data output as the operation result of the operation Px. One task Tx contains one or more operations Px, and each operation Px has zero or more input data Ix and one or more output data Ox. In the example of FIG. 1, among the six tasks T1 to T6, the tasks that finally affect the value of the safety output signal (hereinafter, these are referred to as "safety tasks") are five tasks, namely tasks T1, T2, T4, and T5. The other tasks T3 and T6 are irrelevant to the calculation of the safety output signal (hereinafter, these are referred to as "non-safety tasks"). Among the data Ix and Ox related to the operation Px in the safety task, those that affect the value of the safety output signal are referred to as "safety variables". Other data, that is, data Ix and Ox related to the operation Px in the safety task that do not affect the value of the safety output signal and data in the non-safety task are referred to as "non-safety variables".

[0028] For each of the safety tasks T1, T2, T4, and T5, the control unit 10 executes a comparison process that compares a safety variable related to the operation of a task executed by its own processor (referred to as the "self-task") with a safety variable related to the operation of a task executed by the processor of the other control unit and corresponding to the self-task (referred to as the "corresponding task").

[0029] For example, when focusing on the safety task T2, in the control unit 10A, a comparison process is executed between the safety variable O2 related to the operation P2 of the self-task T2A and the safety variable O2 related to the operation P2 of the corresponding task T2B. The same comparison process is also executed in the other control unit 10B. That is, in the control unit 10B, a comparison process is executed between the safety variable O2 related to the operation P2 of the self-task T2B and the safety variable O2 related to the operation P2 of the corresponding task T2A. Note that the safety variable to be compared may be only the output data Ox, only the input data Ix, or both the output data Ox and the input data Ix. Also, only a part of the output data Ox or only a part of the input data Ix may be used as the comparison target.

[0030] If a hardware failure or software error occurs in either of the control units 10A and 10B, there is a high probability that a difference will occur between the operation results of the safety tasks on the control unit 10A side and those on the control unit 10B side. Therefore, when the result of the comparison process is inconsistent, the control unit 10 determines it as an abnormality and outputs an error. According to this method, faults occurring within a task (such as memory errors (faults in the main memory device or cache), instruction errors in the processor, etc.) can be detected at the end of each task, and the process can immediately shift to error handling, thus minimizing the impact on other tasks.

[0031] Conventionally, for each control unit, abnormalities such as instruction code abnormalities and failures of memory and peripherals were diagnosed individually, and a large amount of resources were required for the self-diagnosis function. However, according to the above configuration, it is possible to determine the presence or absence of abnormalities with extremely simple processing that only compares the safety variables of each safety task, so the processing load can be significantly reduced. As a result, the resources of the device can be allocated to the original functions of the device (for example, sensing processing in the case of a safety sensor) rather than for safety functions, so that it is possible to realize useful functions for customers and improve the performance of the device.

[0032] In addition, since the safety of Safety Device 1 and the RTOS can be ensured by the above comparison processing, a general-purpose RTOS that has not received functional safety standard certification can be adopted instead of a safety RTOS. Also, there is no need to implement individual self-diagnosis functions with a high processing load as in the prior art. As a result, the man-hours for developing Safety Device 1 can be shortened, and the safety function can be realized at low cost. If there are no issues regarding man-hours and cost, a safety RTOS can be adopted for Safety Device 1, and the above comparison processing can be executed on the safety RTOS, or individual self-diagnosis functions as in the prior art can be additionally implemented.

[0033] <Embodiment> Next, a specific example of applying the present invention to a safety sensor, which is a type of safety device, will be described.

[0034] FIG. 2 schematically shows the hardware configuration of Safety Device 1. Safety Device 1 generally includes two control units 10A and 10B, a sensor unit 11, a display unit 12, and output circuits 13A and 13B corresponding to each control unit. Control unit 10A includes a CPU 100A, a RAM 101A, a ROM 102A, an I / O port 103A, a pe It is composed of a microcontroller (MCU) having a referrer 104A. The control unit 10B is also composed of a microcontroller (MCU) having a CPU 100B, a RAM 101B, a ROM 102B, an I / O port 103B, and a peripheral 104B. Since the configurations of the control unit 10A and the control unit 10B are basically the same, hereinafter, in the common description of both units 10A and 10B, they will be referred to as "control unit 10", "CPU 100", "RAM 101", "ROM 102", "I / O port 103", and "peripheral 104".

[0035] The CPU 100 is a processor that executes an RTOS or tasks. The RAM 101 is a main memory device used as a work memory. The ROM 102 is a non-volatile storage device that stores an RTOS or software programs non-temporarily. The I / O port 103 is a circuit responsible for input / output between the sensor unit 11 and the display unit 12. The peripheral 104 is a peripheral device of a circuit separate from the CPU 100, and may include, for example, at least any one of a memory management unit (MMU), a memory protection unit, a CRC calculation unit, a timer, and an A / D converter.

[0036] In the safety device 1 of this embodiment, a general-purpose RTOS that has not received functional safety standard certification is incorporated. There are various general-purpose RTOSs. For example, there are FreeRTOS, Micrium μC / OS, TI-RTOS, Azure RTOS, etc., which can be appropriately selected according to the application.

[0037] The sensor unit 11 detects or measures a sensing target. For example, in the case of a safety laser scanner, the sensor unit 11 is composed of a laser projector, a laser receiver, a motor, an angle encoder, etc. Also, in the case of a safety light curtain, the sensor unit 11 is composed of a projector and a receiver, etc.

[0038] The display unit 12 is a device for outputting sensing results and various types of information. For example, it is composed of an LED, a liquid crystal display, an organic EL display, etc.

[0039] The output circuit 13A is a circuit that converts the output signal of the control unit 10A into a signal for external output (for example, a 24V signal, a communication signal, etc.). The safety output signal output from the control unit 10A is output to the external device 2 via this output circuit 13A. The output circuit 13B is a circuit that converts the output signal of the control unit 10B into a signal for external output (for example, a 24V signal, a communication signal, etc.). The safety output signal output from the control unit 10B is output to the external device 2 via this output circuit 13B. Since the configurations of the output circuit 13A and the output circuit 13B are basically the same, hereinafter, in the description common to the output circuit 13A and the output circuit 13B, it will be referred to as "output circuit 13".

[0040] FIG. 3 shows the flow of the comparison process executed in the safety device 1. The left flowchart shows the process when the safety task TA is executed in the control unit 10A. Note that the safety task TA includes two operations P1 and P2, and the operation P1 is configured to output the output data O1 based on the input data I1, and the operation P2 is configured to output the output data O2 based on the input data I2. The right flowchart shows the process when the safety task TB is executed in the control unit 10B. The safety task TA and the safety task TB are corresponding tasks.

[0041] In the control unit 10A, when the task TA is started, the CPU 100A reads the input data I1 from the RAM 101A (step S10A), and executes the operation P1 by using the input data I1 as an operand (step S11A). Subsequently, the CPU 100A reads the input data I2 from the RAM 101A (step S12A), and the operation result of the operation P1 The operation P2 is executed with the output data O1 and the input data I2 as operands (step S13A). The CPU 100A outputs the output data O1 that is the operation result of the operation P1 and the output data O2 that is the operation result of the operation P2 to a subsequent task (not shown) (step S14A).

[0042] The CPU 100A delivers safety variables to be compared (here, all of the input data I1, I2, output data O1, and O2 are to be compared) to the CRC operation unit of the peripheral 104A and executes a CRC operation (step S15A). By the CRC operation, the four data of the input data I1, I2, output data O1, and O2 are converted into one CRC code CA. When the CPU 100A receives the CRC code CA from the CRC operation unit, the CPU 100A stores the CRC code CA in the RAM 101A and transmits the CRC code CA to the CPU 100B of the other control unit 10B (step S16A).

[0043] On the other hand, the same processing is also executed in the control unit 10B. That is, when the task TB is started in the control unit 10B, the CPU 100B reads the input data I1 from the RAM 101B (step S10B) and executes the operation P1 with the input data I1 as an operand (step S11B). Subsequently, the CPU 100B reads the input data I2 from the RAM 101B (step S12B) and executes the operation P2 with the output data O1 that is the operation result of the operation P1 and the input data I2 as operands (step S13B). The CPU 100B outputs the output data O1 that is the operation result of the operation P1 and the output data O2 that is the operation result of the operation P2 to a subsequent task (not shown) (step S14B).

[0044] The CPU 100B delivers the safety variables to be compared (here, all of the input data I1, I2, and output data O1, O2 are to be compared) to the CRC operation unit of the peripheral 104B and executes a CRC operation (step S15B). Through the CRC operation, the four data items of the input data I1, I2, and output data O1, O2 are converted into one CRC code CB. When the CPU 100B receives the CRC code CB from the CRC operation unit, it stores the CRC code CB in the RAM 101B and transmits the CRC code CB to the CPU 100A of the other control unit 10A (step S16B).

[0045] When both the CRC code CA of the task TA on the control unit 10A side and the CRC code CB of the task TB on the control unit 10B side are available (steps S17A, S17B), the CPU 100A and the CPU 100B perform comparison processing on the CRC code CA and the CRC code CB, respectively (steps S18A, S18B). If the CRC code CA and the CRC code CB do not match, the CPU 100A determines that an abnormality has occurred in the control unit 10A or the control unit 10B and outputs an error. Similarly, if the CRC code CA and the CRC code CB do not match, the CPU 100B determines that an abnormality has occurred in the control unit 10A or the control unit 10B and outputs an error. If no error occurs in either of the CPUs 100A and 100B, the process proceeds to the next task.

[0046] When the processing of CPU 100A and the processing of CPU 100B are executed asynchronously, the acquisition timings of CRC code CA and CRC code CB may be misaligned. Therefore, after obtaining the CRC code CA of its own task TA, CPU 100A sets a timer and waits to receive the CRC code CB of the corresponding task TB from the other CPU 100B. If the CRC code CB cannot be obtained within a predetermined time, CPU 100A determines that an abnormality has occurred in control unit 10A or control unit 10B and outputs an error. The same processing is also executed by CPU 100B. That is, after obtaining the CRC code CB of its own task TB, CPU 100B sets a timer and waits to receive the CRC code CA of the corresponding task TA from the other CPU 100A. If the CRC code CA cannot be obtained within a predetermined time, CPU 100B determines that an abnormality has occurred in control unit 10A or control unit 10B and outputs an error.

[0047] Referring to the timing chart of FIG. 4, a specific implementation example of asynchronous processing will be described.

[0048] The upper part of FIG. 4 represents the state of CPU 100A of control unit 10A, showing the state in which tasks T10A, T11A, and T12A are executed in this order on the RTOS. The lower part of FIG. 4 represents the state of CPU 100B of control unit 10B, showing the state in which tasks T10B, T11B, and T12B are executed in this order on the RTOS. Here, tasks T10A, T11A, T10B, and T11B are safety tasks, and tasks T12A and T12B are tasks dedicated to comparison processing (referred to as "comparison tasks"). The comparison tasks T12A and T12B are tasks independent of the safety tasks T10A, T11A, T10B, and T11B.

[0049] In CPU100A, in task T10A, operation P1 and operation P2 are executed in sequence. At this time, the data related to operation P1 and the data related to operation P2 are sent to the CRC operation unit, and a CRC code is generated. At the checkpoint within task T10A, the CRC code is stored in RAM101A and transmitted to the other CPU100B. CPU100B stores the CRC code received from CPU100A in RAM101B.

[0050] After the completion of task T10A, task T11A is executed. Similarly in task T11A, the data related to the operation is converted into a CRC code, and the CRC code is stored in RAM101A and transmitted to CPU100B. CPU100B stores the CRC code received from CPU100A in RAM101B.

[0051] After the completion of task T11A, comparison task T12A is executed. When comparison task T12A reads out the CRC codes of its own tasks T10A and T11A stored in RAM101A, it checks whether the CRC codes of the corresponding tasks T10B and T11B are stored in RAM101A. In the example of Figure 4, at the start time of the execution of comparison task T12A, the processing of the corresponding tasks T10B and T11B has already been completed and the CRC codes are stored in RAM101A. Therefore, the comparison process of the CRC codes of task T10A and T10B and the comparison process of the CRC codes of task T11A and T11B are immediately executed. If there is a mismatch, it is determined that an abnormality has occurred and an error is output.

[0052] On the other hand, on the CPU100B side, safety tasks T10B and T11B are also executed, and their CRC codes are stored in its own RAM101B and the RAM101A of the other control unit 10A. Then, the comparison task T12B is executed. At the start of the execution of the comparison task T12B, since the CRC codes of tasks T10A and T10B have been acquired, the comparison process of the CRC codes of tasks T10A and T10B is immediately executed. However, as shown in FIG. 4, since the CRC code of task T11A has not yet been acquired, the comparison task T12B waits to receive the CRC code of task T11A from the CPU100B. Note that the comparison task T12B may be terminated once, and the comparison of the CRC codes of tasks T11A and T11B may be performed in the next comparison task (not shown). In any case, if the CPU100B cannot acquire the CRC code of the corresponding task T11A within a predetermined time after acquiring the CRC code of its own task T11B, it proceeds to error processing. In this way, by providing a comparison task independent of the safety tasks, the asynchronous processing of the CPU100A and the CPU100B can be easily realized.

[0053] <Summary> The safety device 1 according to the above embodiment has the following advantages.

[0054] Each of the control units 10A and 10B executes a comparison process of comparing data related to the calculation of its own task executed by its own CPU 100 with data related to the calculation of the corresponding task executed by the CPU 100 of the other control unit for each of one or more safety tasks that affect the value of the safety output signal, and is configured to determine an abnormality when the result of the comparison process is inconsistent. According to this configuration, it is possible to determine the presence or absence of an abnormality with a very simple process of only comparing the data related to the calculation of the task, so that the processing load related to the safety function can be significantly reduced compared to the conventional case. As a result, the resources of the device can be allocated to the original function of the device rather than for the safety function, so that it is possible to realize useful functions for the customer and improve the performance of the device. In addition, since a general-purpose RTOS that has not received functional safety standard certification can be adopted, the development man-hours of the safety device 1 can be shortened and the safety function can be realized at low cost.

[0055] When the data to be compared includes a plurality of data, each of the control units 10A and 10B is configured to convert the plurality of data into one code by CRC calculation and compare the code of its own task with the code of the corresponding task. By grouping the data together, the number of comparison processes can be reduced, so that the overall processing speed is increased. Also, by using CRC calculation, the number of bits of the data to be compared can be reduced, so that the comparison operation itself can be simplified.

[0056] In the above embodiment, since the configuration of executing CRC calculation by a CRC calculation unit provided separately from the CPU 100 is adopted, CRC calculation does not consume the resources of the CPU 100. Therefore, there is an advantage that the safety function by the comparison process can be realized without degrading the performance of the entire device.

[0057] Each of the control units 10A and 10B is configured to execute the comparison process by a comparison task independent of the safety tasks (self-task and corresponding task). As a result, it becomes easy to execute the task processing of the CPU 100A and the task processing of the CPU 100B asynchronously, which is highly convenient. At this time, by determining an abnormality when a pair of data to be compared is not complete within a predetermined time, the safety accuracy can be further improved.

[0058] The data to be compared may include data output as an operation result of a task. Thereby, it is possible to detect abnormalities in the hardware and software related to the execution of the arithmetic process. Here, the data input to the arithmetic operation of the task may be included in the data to be compared. The more the data to be compared increases, the higher the safety accuracy can be further improved.

[0059] <Others> The above embodiments merely exemplarily explain the configuration examples of the present invention. The present invention is not limited to the above specific forms, and various modifications are possible within the scope of its technical idea. For example, in the above embodiment, a general-purpose RTOS is adopted, but a safety RTOS and the safety function by the comparison process described above may be combined. By combining with a safety RTOS, the safety accuracy can be further improved. Further, in the above embodiment, the data to be compared is grouped together by CRC calculation, but the method of grouping the data may be other than CRC calculation. Also, instead of grouping the data, pairs of individual data may be compared. Further, in the above embodiment, the comparison process is performed by a comparison task. However, for example, the comparison process may be executed by a peripheral, or may be executed by a third CPU. In the case of a multi-core CPU, the comparison process may be executed using a core different from the task. Also, the comparison process may be executed in the middle of the task (the final stage of the task). In that case, since the task on the CPU 100A side and the corresponding task on the CPU 100B side directly exchange data, it is preferable that both CPUs 100A and 100B synchronize the task processing.

[0060] This specification includes the following disclosures.

[0061] [Appendix 1] Having at least two control units (10A, 10B), Each of the two control units (10A, 10B) Has a real-time operating system (RTOS) and a processor (100A, 100B) that executes tasks operating on the RTOS, Is configured to output a safety output signal generated based on the calculation results of one or more tasks, For each of the one or more tasks that affect the value of the safety output signal, data related to the calculation of the self-task, which is a task executed by its own processor (100A, 100B), and data related to the calculation of the corresponding task, which is a task executed by the processor (100B, 100A) of the other control unit (10B, 10A) and corresponds to the self-task, are compared, and when the result of the comparison process is inconsistent, it is configured to determine it as an abnormality. Safety device (1).

[0062] [Appendix 2] The data related to the calculation of the task includes a plurality of data, Each of the two control units (10A, 10B) Converts the plurality of data related to the calculation of the self-task into one code, Transmits the converted code to the processor (100B, 100A) of the other control unit (10B, 10A), Receives the code converted from the plurality of data related to the calculation of the corresponding task from the processor (100B, 100A) of the other control unit (10B, 10A), Is configured to compare the code of the self-task with the code of the corresponding task in the comparison process. The safety device (1) according to Appendix 1.

[0063] [Appendix 3] Each of the two control units (10A, 10B) converts a plurality of data related to the calculation of the self-task into one code by CRC calculation. The safety device (1) according to appended note 2.

[0064] [Appended note 4] The CRC calculation is executed by a CRC calculation unit (104A, 104B) provided separately from the processors (100A, 100B). The safety device (1) according to appended note 3.

[0065] [Appended note 5] Each of the two control units (10A, 10B) is configured to execute the comparison process by a comparison task independent of the self-task and the corresponding task. The safety device (1) according to any one of appended notes 1 to 4.

[0066] [Appended note 6] The two control units (10A, 10B) are configured to execute tasks asynchronously. The comparison task can asynchronously execute the process of acquiring comparison target data from the self-task and the process of acquiring comparison target data from the corresponding task, and is configured to execute the comparison process at the timing when the data of both the self-task and the corresponding task are complete. The comparison task is configured to determine an abnormality when it fails to acquire the other data within a predetermined time after acquiring one of the comparison target data of the self-task and the comparison target data of the corresponding task. The safety device (1) according to appended note 5.

[0067] [Appended note 7] The comparison task is configured to determine an abnormality when it fails to acquire the other data within a predetermined time after acquiring one of the comparison target data of the self-task and the comparison target data of the corresponding task. The safety device (1) according to appended note 6.

[0068] [Appended note 8] The data related to the calculation of the task includes the data output as the calculation result of the task. The safety device (1) described in any one of Supplementary Notes 1 to 7.

[0069] [Supplementary Note 9] Data related to the operation of the task includes the data input to the operation of the task. The safety device (1) described in Supplementary Note 8.

[0070] [Supplementary Note 10] The RTOS is an RTOS that has not received functional safety standard certification. The safety device (1) described in any one of Supplementary Notes 1 to 9.

Explanation of Signs

[0071] 1: Safety device 10A, 10B: Control unit 100A, 100B: CPU 101A, 101B: RAM 102A, 102B: ROM 103A, 103B: I / O port 104A, 104B: Peripheral 11: Sensor unit 12: Display unit 13A, 13B: Output circuit 2: External device

Claims

1. having at least two control units, each of the two control units has a real-time operating system (RTOS) and a processor for executing tasks operating on the RTOS, is configured to output a safety output signal generated based on the calculation results of one or more tasks, for each of the one or more tasks that affect the value of the safety output signal, data related to the calculation of its own task, which is a task executed by its own processor, and data related to the calculation of the corresponding task, which is a task executed by the processor of the other control unit and corresponds to the own task, are compared, and when the result of the comparison process is inconsistent, it is configured to determine it as an abnormality, a safety device.

2. The data related to the calculation of the task includes a plurality of data, each of the two control units converts a plurality of data related to the calculation of its own task into one code, transmits the converted code to the processor of the other control unit, receives the code converted from a plurality of data related to the calculation of the corresponding task from the processor of the other control unit, and is configured to compare the code of its own task and the code of the corresponding task in the comparison process. The safety device according to claim 1.

3. Each of the two control units converts a plurality of data related to the calculation of its own task into one code by CRC calculation. The safety device according to claim 2.

4. The CRC calculation is executed by a CRC calculation unit provided separately from the processor. The safety device according to claim 3.

5. Each of the two control units is configured to execute the comparison process by a comparison task independent of the own task and the corresponding task. The safety device according to claim 1.

6. The two control units are configured to execute tasks asynchronously, the comparison task is configured to be able to execute asynchronously the process of acquiring comparison target data from the own task and the process of acquiring comparison target data from the corresponding task, and execute the comparison process at the timing when the data of both the own task and the corresponding task are complete. The safety device according to claim 5.

7. After the comparison task acquires one of the data to be compared of the self-task and the data to be compared of the corresponding task, if the other data cannot be acquired within a predetermined time, it determines that it is abnormal. The safety device according to claim 6.

8. The data related to the calculation of the task includes the data output as the calculation result of the task. 、 The safety device according to claim 1.

9. The data related to the calculation of the task includes the data input to the calculation of the task. The safety device according to claim 8.

10. The RTOS is an RTOS that has not received certification of functional safety standards. The safety device according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Safety industrial controller providing diversity in single multicore processor

    US10520928B2

Cited By

  • Process control system, control method, and control program

    JP7878540B1