Information processing device, information processing method, and program

The information processing device detects synchronization abnormalities in industrial networks by analyzing frames, facilitating early intervention to prevent system failures.

JP2025116880APending Publication Date: 2025-08-08MOVENSYS INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2025094457
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

Existing control systems connected via industrial networks face challenges in detecting abnormalities early to prevent further operational issues.

Method used

An information processing device connected to a master and slaves via an industrial network, equipped with a receiving unit and an abnormality detection unit that analyzes frames to detect synchronization abnormalities based on a reference time.

Benefits of technology

Enables earlier detection of synchronization abnormalities, allowing for timely intervention to prevent system failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025116880000001_ABST
    Figure 2025116880000001_ABST
Patent Text Reader

Abstract

To provide a technology capable of detecting abnormality that occurs in a control system connected by an industrial network at an earlier stage.SOLUTION: An information processing device connected to a master and one or more slaves through an industrial network includes: a reception part for receiving a frame repeatedly transmitted from the master within the industrial network; and an abnormality detection part for detecting abnormality related to synchronous processing executed on the basis of a reference time distributed within the industrial network and performed between the master and the one or more slaves, by analyzing the frame.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing device, an information processing method, and a program. [Background technology]

[0002] In fields such as robots and factory automation (FA), it is necessary to operate conveyor belts, arms, and other devices as intended. To achieve such operations, it is necessary to synchronize and operate multiple controlled devices such as servo motors and stepping motors with high precision. For example, Patent Document 1 discloses a motion control command system that can achieve smooth control while utilizing inexpensive and simple low-speed communication. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-170435 Summary of the Invention [Problem to be solved by the invention]

[0004] In a control system that includes a controller and controlled devices, the network that connects the controller and controlled devices is called an industrial network. If an abnormality occurs in the operation of a control system connected by an industrial network, it is desirable to detect the abnormality as early as possible and take action such as stopping the operation of the control system in order to reduce the possibility of further problems occurring due to the abnormal operation of the control system.

[0005] Therefore, an object of the present disclosure is to provide a technology that enables earlier detection of abnormalities occurring in control systems connected via an industrial network. [Means for solving the problem]

[0006] An information processing device according to one embodiment of the present disclosure is an information processing device connected to a master and one or more slaves via an industrial network, and includes a receiving unit that receives frames repeatedly transmitted from the master within the industrial network, and an abnormality detection unit that analyzes the frames to detect the presence or absence of an abnormality in synchronization processing performed between the master and one or more slaves based on a reference time distributed within the industrial network. [Effects of the Invention]

[0007] According to the present disclosure, it is possible to provide a technology that enables earlier detection of abnormalities occurring in control systems connected via an industrial network. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a diagram illustrating an example of a control system 1 according to an embodiment of the present invention. [Figure 2] FIG. 1 is a diagram illustrating an example of a frame structure used in an industrial network. [Figure 3] FIG. 10 is a diagram for explaining a time synchronization process. [Figure 4] FIG. 2 illustrates an example of the configuration of a slave. [Figure 5] FIG. 2 illustrates an example of a hardware configuration of a monitoring device. [Figure 6] FIG. 2 is a diagram illustrating an example of a functional block configuration of a monitoring device. [Figure 7] FIG. 10 is a diagram illustrating a state in which synchronization processing is operating normally. [Figure 8] 10A and 10B are diagrams illustrating events that occur when an abnormality occurs in the master and the master is no longer able to transmit frames at equal intervals. [Figure 9] 10A and 10B are diagrams for explaining events that occur when an abnormality occurs in the local clock of a synchronous master-slave, causing a deviation from the reference time. [Figure 10] 10A and 10B are diagrams for explaining events that occur when an abnormality occurs in the local clock of a monitoring device. [Figure 11] FIG. 10 is a diagram illustrating the relationship between combinations of synchronization processing abnormalities and causes of the synchronization processing abnormalities. [Figure 12] 10 is a flowchart illustrating an example of a processing procedure for detecting an abnormality in synchronization processing. [Figure 13] FIG. 10 is a diagram illustrating a specific example of a synchronization abnormality detection process. [Figure 14] FIG. 10 is a diagram for explaining a modified example. [Figure 15] FIG. 10 is a diagram for explaining a modified example. [Figure 16] FIG. 10 is a sequence diagram illustrating an example of a processing procedure for extracting log data and transmitting it to a master when an abnormality occurs. [Figure 17] FIG. 10 is a diagram illustrating an example of frame data stored in pre-failure log data. DETAILED DESCRIPTION OF THE INVENTION

[0009] Embodiments of the present disclosure will be described with reference to the accompanying drawings, in which the same reference numerals denote the same or similar configurations.

[0010] <System configuration> 1 is a diagram showing an example of a control system 1 according to this embodiment. The control system 1 includes a master 10, one or more slaves 20, and a monitoring device 30. The master 10, the one or more slaves 20, and the monitoring device 30 are connected via an industrial network.

[0011] The master 10 is a device that controls the slaves 20 to realize a predetermined function in the control system 1. The master 10 may be, for example, a motion controller, a sequence controller, a robot controller, etc. The master 10 may also be called a controller, a control device, etc. The master 10 may be a device realized using dedicated hardware, or may be a general-purpose information processing device on which a non-real-time OS and a real-time OS are installed. Specific examples of non-real-time OSs include Windows (registered trademark) and macOS (registered trademark). Specific examples of real-time OSs include RTX (Real Time Extension) and RTH (Real Time Hypervisor). Specific examples of general-purpose information processing devices include a PC (personal computer), a laptop PC, a server, etc.

[0012] The slaves 20 are, for example, servo motors (including servo drivers), stepping motors, sensors, etc., and are devices that execute various processes in the control system 1. Each slave is divided into a communication processing unit that processes the communication protocol used in the industrial network, and an application unit that performs processes such as motion control.

[0013] The monitoring device 30 is a device that monitors the operating status of the control system 1, constantly records frames (which may also be called data or packets) flowing through the industrial network, and detects the occurrence of an abnormality in the control system 1. The monitoring device 30 also operates as a slave 20 in the control system 1. In other words, the monitoring device 30 is recognized as a slave 20 by the master 10. The monitoring device 30 may be a device realized using dedicated hardware, or may be a general-purpose information processing device or computer on which a non-real-time OS and a real-time OS are installed.

[0014] Examples of protocols used in industrial networks include EtherCAT (registered trademark) and EtherNet / IP. In the following description, the industrial network will be described as EtherCAT, but the present embodiment is not limited to this. Any communication protocol may be used as long as it communicates in a master-slave manner and has a synchronization function, which will be described later.

[0015] In an industrial network, the master 10 and the slaves 20 (including the monitoring device 30) communicate using an on-the-fly method. In the on-the-fly method, a single fixed-length frame transmitted from the master 10 passes through each slave 20 in order and finally returns to the master 10. As the frame passes through, each slave 20 can read data addressed to itself from the frame and write data addressed to the master 10 or another slave 20 to the frame. In the example of FIG. 1 , a frame transmitted from the master 10 passes through each slave 20 and the monitoring device 30 in the order of S1 to S6 and returns to the master 10. Each slave 20 processes the frame when it first passes through the monitoring device 30, but does not process the frame when it returns from the monitoring device 30 to the master 10. For example, slave 20-1 processes the frame received at S1 (by writing and / or reading data), but forwards the frame received at S5 to the master 10 without processing it. Similarly, the slave 20-2 processes the frame received at S2 (writes and / or reads data), but transfers the frame received at S4 to the slave 20-1 without processing it.

[0016] In this embodiment, the monitoring device 30 is connected after all the slaves 20 in the industrial network to detect abnormalities occurring in the master 10 and the slaves 20. In other words, the monitoring device 30 operates as a terminal slave 20. For example, assume that a slave 20-1 and a slave 20-2 exist in the control system 1. In this case, the monitoring device 30 is connected to the industrial network so that a frame output from the master 10 passes through the slave 20-1, the slave 20-2, and the monitoring device 30 in that order.

[0017] (Frame structure used in industrial networks) 2 is a diagram showing an example of the structure of a frame used in an industrial network. One frame includes an Ethernet header, Ethernet data, and a Frame Check Sequence (FCS). The Ethernet data includes a header and a datagram.

[0018] A datagram is further divided into N datagram areas. Each datagram area further includes a datagram header, data, and a working counter (WKC). The datagram header stores a command indicating how to process the data (write a value, read a value, etc.) and an address indicating the destination where the data will be processed.

[0019] In an industrial network, different datagrams are used when transmitting data from the master 10 to the slaves 20 and when transmitting data from the slaves 20 to the master 10. In other words, at least two datagrams are assigned to one slave 20 that transmits and receives data to and from the master 10.

[0020] Here, in order for the master 10 to write a value to a memory (also called a register) included in the slave 20 or to read a value from the memory included in the slave 20, the master 10 needs to specify the address of the memory to which the value is to be written or read. In an industrial network, there are two methods for specifying a memory address.

[0021] The first method is to directly specify the physical address of the memory by combining an identifier that identifies the slave 20 (called a "setting address" in EtherCat) with an address of the memory in the slave 20 (meaning a real address, called a "register address" in EtherCat). When writing or reading a value to or from the memory in the slave 20, an index and a subindex can also be used instead of the register address. The index and subindex correspond to the contents of the data stored in the memory, and by specifying the index and subindex, it is possible to write or read a value without being aware of the real address. The correspondence between the index and subindex and the memory address is defined in advance in the slave 20.

[0022] The second method is to regard the memory spaces of all the slaves 20 in the control system 1 as a single memory space, and to express a location in the memory space as a single logical address. Data indicating the correspondence between the logical address and the address (actual address) of the memory of each slave 20 is set in advance in each slave 20. By using the logical address, the master 10 can write and read data without being aware of which slave 20 it is accessing.

[0023] The master 10 performs processing such as writing values to memory and reading values from memory by specifying a command in addition to specifying a memory address. Examples of commands include FPWR (writing data by specifying the slave 20 and a real address), FPRD (reading data by specifying the slave 20 and a real address), LWR (writing data by specifying a logical address), and LRD (reading data by specifying a logical address).

[0024] (Overview of synchronization process) FIG. 3 is a diagram for explaining an overview of synchronization processing. The industrial network has a mechanism for performing highly accurate time synchronization (for example, a time synchronization deviation of within 1 μsec) between each slave 20. In the case of EtherCAT, this synchronization processing is called DC (Distributed Clocks) synchronization. By performing the synchronization processing, each slave 20 is synchronized with a predetermined reference time (hereinafter referred to as the "reference time"), and each slave 20 performs various processes according to the reference time. Note that the accuracy of the clock provided in the master 10 is often lower than the accuracy of the clocks provided in the slaves 20 to reduce costs. Therefore, in the synchronization processing, a local clock held by a slave 20 that can perform synchronization processing among the slaves 20 connected in series to the industrial network may be used as the reference time. In the following description, a slave 20 that uses a local clock as the reference time is referred to as a "synchronization master slave." Note that in this embodiment, the synchronization master slave will be described as the first slave 20 that can perform synchronization processing among the slaves 20 connected in series to the industrial network (slave 20-1 in the example of FIG. 1). In EtherCAT, the reference time is called the Reference Clock. If the master 10 has a clock with the same high accuracy as that of the slave 20, the local clock of the master 10 may be used as the reference time.

[0025] The reference time is expressed as an absolute time with a certain time as the starting point (zero). The reference time may be expressed as a value with a predetermined number of bits. For example, in EtherCAT, the reference time is expressed as a 32-bit or 64-bit numerical value with the starting point being January 1, 2001, 00:00:00. The smallest unit of the reference time may be 1 microsecond or 1 nanosecond.

[0026] To achieve synchronization processing, the master 10 measures in advance, in accordance with the EtherCAT specifications, the propagation delay of frames between the synchronization master slave and each slave 20, the difference between the reference time and the local clock of each slave (offset value), and other data, and writes these data into the memory of each slave 20. Each slave 20 other than the synchronization master slave can calculate the reference time by adding the offset value to its own local clock.

[0027] Generally, there is a slight difference (also called drift) in the time that a clock ticks, and the difference from the reference time increases as time passes after synchronization is completed. Therefore, the master 10 periodically distributes the reference time to suppress the difference from the reference time (i.e., to compensate for the clock drift).

[0028] Specifically, the synchronization master slave stores the reference time in a frame received from the master 10 in accordance with an instruction from the master 10, and transmits the frame with the reference time stored therein to the next slave 20. Each slave 20 acquires the reference time from the received frame in which the reference time is stored, and writes the acquired reference time frame to its own memory. In the following description, a frame for distributing the reference time to each slave 20 is referred to as a "reference time frame." Note that all frames repeatedly transmitted from the master 10 may be reference time frames. Alternatively, the reference time frame may be one every N frames (N is a natural number) out of all frames repeatedly transmitted from the master 10. The example in FIG. 3 illustrates how all frames are reference time frames, and how the synchronization master slave 20-1 stores the reference time in frames A and B received from the master 10 and transmits them to the slave 20-2.

[0029] Each slave 20 other than the synchronization master slave acquires the reference time from the received reference time frame. As described above, each slave 20 knows the propagation delay between itself and the synchronization master slave, and therefore can recognize the correct reference time by adding the propagation delay to the reference time included in the reference time frame. In other words, each slave 20 other than the synchronization master slave can correct the reference time that it recognizes to the correct reference time based on the reference time included in the reference time frame.

[0030] As described above, the synchronous master slave stores the time of its own local clock as the reference time in the frame received from the master 10, and transmits it to the next slave 20. The value of the local clock that the synchronous master slave stores as the reference time may be any value that corresponds to the time between when the synchronous master slave receives the frame and when it transmits the frame containing the reference time to the next slave 20.

[0031] FIG. 4 is a diagram showing an example of the configuration of a slave. The communication processing unit 20b included in each slave synchronizes with the reference time by referring to the reference time, propagation delay, offset, etc. written in the memory 20a of the communication processing unit. Next, each slave repeatedly generates a synchronization signal at a predetermined period according to the synchronized reference time and notifies the application unit 20c included in each slave. In EtherCAT, the synchronization signal is called SYNC0 / SYNC1, etc. The first time when the synchronization signal is repeatedly generated (hereinafter referred to as the "start time of the synchronization signal") and the generation period of the synchronization signal (hereinafter referred to as the "synchronization signal period") are notified in advance to each slave 20 by the master 10. The start time of the synchronization signal is specified as absolute time according to the time axis of the reference time.

[0032] When synchronization processing is used, the master 10 repeatedly transmits frames at the same cycle as the generation cycle of the synchronization signal so that one frame arrives at each slave 20 between two consecutive synchronization signals. However, as mentioned above, the accuracy of the clock provided in the master 10 is often lower than the accuracy of the clock provided in the slave 20. Therefore, the cycle at which frames arrive at each slave 20 may vary slightly compared to the cycle at which synchronization signals are generated in each slave 20.

[0033] The frame repeatedly transmitted by the master 10 at a predetermined interval includes an area for storing data in addition to the reference time. For example, this area stores commands and values for writing values to the memory of each slave 20, and / or commands for reading values from the memory 20a of each slave 20. The communication processing unit 20b of each slave 20 reads values from the received frame and writes them to the memory 20a in accordance with the commands. Furthermore, the application unit 20c of each slave 20 performs application processing (e.g., motion control) using the values written to the memory 20a upon receiving a synchronization signal from the communication function unit. In other words, as long as the time synchronization function operates normally and the master 10 continues to transmit frames at a predetermined interval, the timing at which each slave 20 generates a synchronization signal will be consistent across the slaves 20, and the timing at which each slave 20 performs application processing will also be consistent.

[0034] 3, the frame arrival time at slave 20-2 is delayed by the transmission delay between synchronization master slave 20-1 and slave 20-2. However, because application processing (AP processing) is executed using a synchronization signal as a trigger, the timing at which application processing is started at synchronization master slave 20-1 and the timing at which application processing is started at slave 20-2 will match.

[0035] (Overview of the processing performed by the monitoring device) In this embodiment, the monitoring device 30 performs the following processing.

[0036] 1. Detection of abnormality in synchronization processing: The monitoring device 30 detects that an abnormality has occurred in synchronization processing, and notifies the user who manages the control system 1 or the master 10.

[0037] 2. Recording frames immediately before an abnormality occurs: The monitoring device 30 constantly records (captures) frames flowing through the industrial network and saves log data of one or more captured frames. Furthermore, when it detects that an abnormality has occurred in the control system 1, it extracts log data of one or more frames that flowed through the industrial network during a predetermined period before the abnormality occurred from the saved log data. Furthermore, when the monitoring device 30 receives a request from the master 10, it transmits the log data of the one or more extracted frames to the master 10 via the industrial network.

[0038] <Hardware configuration> 5 is a diagram illustrating an example of the hardware configuration of the monitoring device 30. The monitoring device 30 includes a processor 11 such as a CPU (Central Processing Unit) or a GPU (Graphical Processing Unit), a memory (for example, a RAM (Random Access Memory) or a ROM (Read Only Memory)), a storage device 12 such as an HDD (Hard Disk Drive) and / or an SSD (Solid State Drive), a network IF (Network Interface) 13 for wired or wireless communication, an input device 14 for accepting input operations, and an output device 15 for outputting information. The input device 14 is, for example, a keyboard, a touch panel, a mouse, and / or a microphone. The output device 15 is, for example, a display, a touch panel, and / or a speaker.

[0039] <Function block configuration> 6 is a diagram showing an example of a functional block configuration of the monitoring device 30. The monitoring device 30 has a non-real-time OS 100, a real-time OS 200, and a second storage unit 300. The non-real-time OS 100 includes a display unit 110, a collection unit 120, a first detection unit 130, an extraction unit 140, and a first storage unit 150. The real-time OS 200 includes a slave processing unit 210. The slave processing unit 210 includes a communication module 220 and a fixed-cycle processing unit 230. The communication module 220 includes a third storage unit 221, and the fixed-cycle processing unit 230 includes a second detection unit 231.

[0040] The first storage unit 150, the second storage unit 300, and the third storage unit 221 can be realized using the storage unit 12 included in the monitoring device 30. The display unit 110, the collection unit 120, the first detection unit 130, the extraction unit 140, and the slave processing unit 210 can be realized by the processor 11 of the monitoring device 30 executing a program stored in the storage unit 12. The program can be stored in a storage medium. The storage medium storing the program may be a non-transitory computer-readable medium. The non-transitory storage medium is not particularly limited, and may be, for example, a storage medium such as a universal serial bus (USB) memory or a compact disc read-only memory (CD-ROM).

[0041] The first storage unit 150 is provided in the non-real-time OS and stores a log accumulation database (DB) 151 and a setting file 152. The log accumulation DB 151 is a database that stores frames transmitted through the industrial network, captured by the communication module 220 of the real-time OS 200. The setting file 152 stores various data that define the operation of the monitoring device 30.

[0042] The second storage unit 300 is provided in a memory that can be referenced by both the non-real-time OS 100 and the real-time OS.

[0043] The display unit 110 operates on a non-real-time OS and displays various screens on a display etc. For example, the display unit 110 displays a screen showing the details of a detected abnormality on a display etc.

[0044] The collection unit 120 operates on a non-real-time OS, acquires frames flowing through the industrial network from the real-time OS 200 via a FIFO (First In First Out) queue 310 included in the second storage unit 300, and stores the frames in a log accumulation DB 151 of the first storage unit 150. In other words, the first storage unit 150 (log accumulation DB 151) stores log data of one or more received frames.

[0045] The first detection unit 130 operates on a non-real-time OS and analyzes frames received by the communication module 220 to detect whether there is an abnormality in the synchronization process performed between the master 10 and one or more slaves 20 based on a reference time distributed within the industrial network.

[0046] The extraction unit 140 operates on a non-real-time OS, and when the first detection unit 130 detects that an abnormality has occurred in the master 10 or one or more slaves 20, the extraction unit 140 extracts, from the log accumulation DB 151, log data of frames from the time when the abnormality was detected until a predetermined time before (second time before). The extraction unit 140 also stores the extracted log data of the frames in the second storage unit 300 as pre-failure log data 320. In other words, the second storage unit 300 stores the log data extracted by the extraction unit 140 as pre-failure log data 320.

[0047] The slave processing unit 210 performs various processes for the monitoring device 30 to operate as the slave 20 .

[0048] The communication module 220 operates on the real-time OS 200, captures frames flowing through the industrial network, and stores them in the third storage unit 221. The communication module 220 also acquires data addressed to itself and stores it in the third storage unit 221 in accordance with instructions in commands contained in frames flowing through the industrial network. The communication module 220 also acquires data to be transmitted to the master 10 from the third storage unit 221 and stores it in a frame in accordance with instructions in commands contained in frames flowing through the industrial network. As described above, the monitoring device 30 operates as the terminal slave 20. That is, the third storage unit 221 corresponds to the memory of the slave 20 described in "(Frame Structure Used in Industrial Networks)". For example, when the command contained in the frame is FPWR and the address contained in the frame points to the monitoring device 30, the communication module 220 stores the value contained in the frame in an area of the third storage unit 221 specified by the address contained in the frame. In addition, if the command included in the frame is FPRD and the address included in the frame points to the monitoring device 30, the communication module 220 obtains a value from the area in the third memory unit 221 specified by the address included in the frame and stores it in the frame.

[0049] The fixed-cycle processing unit 230 operates on the real-time OS 200. The fixed-cycle processing unit 230 repeatedly performs a process of acquiring frames flowing through the industrial network from the third storage unit 221 and storing the frames in the FIFO queue 310 at a predetermined cycle (for example, the cycle at which frames are transmitted from the master 10). The fixed-cycle processing unit 230 also acquires data to be stored in the frames from the pre-fault log data 320 and stores the data in the third storage unit 221.

[0050] The second detection unit 231 analyzes the frames captured by the communication module 220 to detect the presence or absence of an abnormality in the synchronization process performed between the master 10 and one or more slaves 20 based on a reference time distributed within the industrial network. The monitoring device 30 is assumed to include at least either the first detection unit 130 or the second detection unit 231. That is, the monitoring device 30 may detect the presence or absence of an abnormality in the synchronization process on the non-real-time OS 100 side (i.e., the first detection unit 130), or may detect the presence or absence of an abnormality in the synchronization process on the real-time OS 200 side (i.e., the second detection unit 231). The first detection unit 130 and the second detection unit 231 may be referred to as "abnormality detection units."

[0051] The communication module 220 may also be referred to as a "transmitter" and a "receiver." The communication module 220 (receiver) receives frames repeatedly transmitted from the master 10 within the industrial network. In addition, the communication module 220 (transmitter) transmits pre-fault log data 320 to the master 10 via the industrial network in response to a request from the master 10.

[0052] <Processing Procedure> (Detection of synchronization processing abnormalities) Next, a specific description will be given of the process by which the monitoring device 30 detects that an abnormality has occurred in the synchronization process. In the following description, it is assumed that the detection of the synchronization process abnormality is performed by the first detection unit 130, but as mentioned above, it is also possible to detect the synchronization process abnormality by the second detection unit 231. In addition, in the following description, it is assumed that the slave 20 and the monitoring device 30 are different devices.

[0053] The monitoring device 30 detects two types of synchronization abnormalities, synchronization abnormality A and synchronization abnormality B, which will be described below, and determines the cause of the synchronization abnormality based on the combination of the two types of synchronization abnormalities. Note that synchronization abnormality A and synchronization abnormality B may also be called the "first abnormality" and the "second abnormality," respectively.

[0054] Synchronization Abnormality A: When the reference time stored in the reference time frame is not included between the times when two consecutive synchronization signals are generated, when the reference time frame should be received. Synchronization abnormality B: When the difference between the reference times included in each of two consecutive time synchronization frames is different from the difference between the times at which the monitoring device 30 received each of the two consecutive time synchronization frames.

[0055] 7 is a diagram showing a state in which the synchronization process is operating normally. The process of detecting synchronization abnormality A and synchronization abnormality B will be specifically described with reference to FIG.

[0056] [Synchronization error A] 7, the horizontal axis t represents the time at which a synchronization signal is generated. The time at which a synchronization signal is generated may be expressed in any manner, but may be expressed as a 32-bit or 64-bit numerical value, for example, starting from 0:00:00 on January 1, 2000, with the smallest unit of time being 1 nanosecond.

[0057] In the example of FIG. 7, the synchronization signal period is set to 1000 (e.g., 1 ms), and each frame is a reference time frame. Furthermore, slave 20-1 is a synchronization master slave, and will be referred to as synchronization master slave 20-1 in the following description. That is, synchronization master slave 20-1 stores a reference time in a reference time frame received from master 10 and transmits the reference time frame to slave 20-2. Slave 20-2 acquires the reference time from the received reference time frame and transmits the reference time frame to monitoring device 30. Monitoring device 30 also acquires the reference time from the received reference time frame and transmits the reference time frame to master 10.

[0058] The reference time frames are repeatedly transmitted from the master 10 at a period that is approximately the same as the synchronization signal period. For example, reference time frame A is transmitted from the master 10 between the generation of synchronization signal Sy1 and the generation of synchronization signal Sy2, passes through slave 20-1, slave 20-2, and monitoring device 30, and returns to the master 10 before synchronization signal Sy2 is generated. Therefore, if the synchronization process is normal, the slave 20 and monitoring device 30 will always receive one reference time frame between two consecutive synchronization signals.

[0059] The time when the first synchronization signal is generated is the time specified as the "synchronization signal start time," and the second and subsequent synchronization signals are generated every time a "synchronization signal period" passes. In other words, the time when the Nth synchronization signal (N is an integer greater than or equal to 1) is generated can be calculated using the formula "synchronization signal start time + ((N-1) × synchronization signal period." This means that the Nth frame to be transmitted after the start of synchronization processing should be received by each slave 20 between "synchronization signal start time + (N-1) × synchronization signal period" and "synchronization signal start time + N × synchronization signal period."

[0060] Here, the synchronization master slave 20-1 stores the time of its own local clock as the reference time in the reference time frame received from the master 10 and transmits it to the slave 20-2. As described above, the local clock value stored by the synchronization master slave 20-1 as the reference time may be any value that corresponds to the time between when the synchronization master slave 20-1 receives a frame and when it transmits the frame containing the reference time to the slave 20-2. Therefore, the first detection unit 130 detects the presence or absence of synchronization anomaly A by determining, for a reference time frame among the frames repeatedly transmitted from the master 10, whether the reference time exists between the times at which two consecutive synchronization signals are generated, at which the reference time frame should be received.

[0061] More specifically, the first detection unit 130 determines that synchronization abnormality A has not occurred if the reference time exists between the times when two consecutive synchronization signals are generated in one or more slaves 20 (or synchronization master slaves) so that the reference time frame should be received by the one or more slaves 20 (or synchronization master slaves).Furthermore, the first detection unit 130 determines that synchronization abnormality A has occurred if the reference time does not exist between the times when two consecutive synchronization signals are generated in one or more slaves 20 (or synchronization master slaves) so that the reference time frame should be received by the one or more slaves 20 (or synchronization master slaves).

[0062] The first detection unit 130 may acquire the "synchronization signal start time" and the "synchronization signal period," and calculate (estimate) the time at which two consecutive synchronization signals, at which the reference time frame should be received, are generated, based on the acquired "synchronization signal start time" and "synchronization signal period." For example, assume that the reference time frame is the Xth frame transmitted after the synchronization signal start time. In this case, the first detection unit 130 can calculate (estimate) the time at which the first of the two consecutive synchronization signals, at which the reference time frame should be received, is generated, using the formula "synchronization signal start time + (X - 1) × synchronization signal period." Furthermore, the first detection unit 130 can calculate (estimate) the time at which the second of the two consecutive synchronization signals, at which the reference time frame should be received, is generated, using the formula "synchronization signal start time + X × synchronization signal period."

[0063] As explained below, synchronization abnormality A is detected when the master 10 is unable to transmit frames at regular intervals due to a failure of the local clock within the master 10, or when the local clock of the synchronous master-slave fails, causing a deviation in the reference time stored in the reference time frame.

[0064] FIG. 8 is a diagram illustrating an event that occurs when an abnormality occurs in the master 10 and it becomes unable to transmit frames at regular intervals. Points not otherwise mentioned may be the same as those in FIG. 7. In the example of FIG. 8, some abnormality occurs in the master 10, causing a delay in the timing at which the master 10 transmits the reference time frame C. In this case, the reference time stored in the reference time frame C is the time (8600) at which the synchronization master slave 20-1 receives the reference time frame C. However, the time at which the reference time frame C should be received by each slave 20 is between the time (7500) at which the synchronization signal Sy3 is generated and the time (8500) at which the synchronization signal Sy4 is generated. Therefore, when the first detection unit 130 receives the reference time frame C, it determines that the reference time (8600) included in the reference time frame C does not fall within the period during which the reference time frame C should be received (between the time (7500) at which the synchronization signal Sy3 is generated and the time (8500) at which the synchronization signal Sy4 is generated), and detects that a synchronization abnormality A has occurred.

[0065] FIG. 9 is a diagram illustrating an event that occurs when an abnormality occurs in the local clock of a synchronization master slave, causing a deviation in the reference time. Points that are not particularly mentioned may be the same as those in FIG. 7. In the example of FIG. 9, the time recorded by the local clock of synchronization master slave 20-1 is earlier than the actual time, resulting in the reference times stored in frames C and D being shifted to 8600 and 11500, respectively, rather than the actual times (7800 and 8800 shown in FIG. 7). Therefore, upon receiving reference time frame C, the first detection unit 130 determines that the reference time (8600) included in reference time frame C does not fall within the period during which reference time frame C should be received (between the time (7500) when synchronization signal Sy3 is generated and the time (8500) when synchronization signal Sy4 is generated), and detects that synchronization abnormality A has occurred.

[0066] [Synchronization error B] If the local clock of synchronization master slave 20-1 is normal (that is, if the reference time stored in the reference time frame by synchronization master slave 20-1 is normal) and the local clock of monitoring device 30 is also normal, the difference between the time when two consecutive reference time frames are received by monitoring device 30 and the difference between the reference times included in those two reference time frames should be approximately the same value. For example, in the example of Fig. 7, the difference (1000) between the time (5950) when frame A is received by monitoring device 30 and the time (6950) when frame B is received by monitoring device 30 is the same as the difference (1000) between the reference time of frame A and the reference time of frame B (6800) and the difference (5800) between the reference time of frame A and the reference time of frame B.

[0067] Therefore, the first detection unit 130 detects whether or not there is an abnormality in the synchronization process based on the difference between the times when the monitoring device 30 receives each of two consecutive reference time frames, including a reference time, and the difference between the reference times included in each of the two consecutive reference time frames. More specifically, the first detection unit 130 determines that synchronization abnormality B has not occurred if the "degree of deviation" between the difference between the times when each of two consecutive reference time frames was received and the difference between the reference times included in each of the two consecutive reference time frames is equal to or less than a predetermined value. Furthermore, the first detection unit 130 determines that synchronization abnormality B has occurred if the "degree of deviation" between the difference between the times when each of two consecutive reference time frames was received and the difference between the reference times included in each of the two consecutive reference time frames exceeds a predetermined value. The method for calculating the degree of deviation will be described later.

[0068] As will be explained below, synchronization abnormality B is detected when the local clock of synchronization master slave 20-1 fails, causing a deviation in the reference time stored in the reference time frame, or when the local clock of monitoring device 30 fails, causing monitoring device 30 to be unable to correctly measure the time at which the frame was received.

[0069] 9, the time recorded by the local clock of synchronization master slave 20-1 has become faster than the actual time, and as a result, the reference times stored in frames C and D are shifted to 8600 instead of the actual times (7800 and 8800 shown in FIG. 7). Therefore, the first detection unit 130 determines that the degree of deviation between the difference (1000) between the time frame B (6950) and the time frame C (7950) are received and the difference (1800) between the reference time (6800) stored in frame B and the reference time (8600) stored in frame C exceeds a predetermined value (e.g., 0.1), and detects that synchronization abnormality B has occurred.

[0070] FIG. 10 is a diagram illustrating an event that occurs when an abnormality occurs in the local clock of the monitoring device 30. Points that are not particularly mentioned may be the same as those in FIG. 7. In the example of FIG. 10, the time recorded by the local clock of the monitoring device 30 is delayed compared to the actual time, resulting in the times at which frames C and D are received being shifted to 7450 and 7950, respectively, rather than the actual times (7950 and 8950 shown in FIG. 7). Therefore, the first detection unit 130 determines that the degree of deviation between the difference (500) between the time at which frame B is received (6950) and the time at which frame C is received (7450) and the difference (1000) between the reference time (6800) stored in frame B and the reference time (7800) stored in frame C exceeds a predetermined value (e.g., 0.1), and detects that synchronization abnormality B has occurred.

[0071] As explained above, there are three possible causes for a synchronization anomaly: when an abnormality occurs in the master 10, making it unable to transmit frames at regular intervals; when a failure occurs in the local clock of the synchronization master slave 20-1, causing a deviation in the reference time stored in the reference time frame; or when an abnormality occurs in the local clock of the monitoring device 30. Furthermore, depending on the cause, the pattern in which the anomaly is detected, either synchronization anomaly A or synchronization anomaly B, differs.

[0072] This relationship can be expressed in a table as shown in FIG. 11. FIG. 11 is a diagram showing the relationship between combinations of synchronization processing anomalies and causes of synchronization processing anomalies. The first detection unit 130 determines the cause of the anomaly based on the relationship shown in FIG. 11. Specifically, if synchronization anomaly A occurs but synchronization anomaly B does not occur, the first detection unit 130 determines that there is an anomaly in the transmission period of the frames repeatedly transmitted from the master 10. Furthermore, if synchronization anomaly A does not occur but synchronization anomaly B occurs, the first detection unit 130 determines that there is an anomaly in the clock provided in the monitoring device 30. Furthermore, if both synchronization anomaly A and synchronization anomaly B occur, the first detection unit 130 determines that there is an anomaly in the clock of the synchronization master-slave.

[0073] (Synchronization processing abnormality detection procedure) Reference signal frame FIG. 12 is a flowchart showing an example of a processing procedure for detecting a synchronization processing abnormality. In the description of FIG. 12, the master 10 is assumed to repeatedly transmit frames in accordance with the synchronization signal period. Furthermore, the term "frame" refers to both the reference time frame and frames other than the reference time frame (i.e., frames that do not include the reference time). Before starting an operation to be performed by the control system 1, such as motion control, the control system 1 performs initialization processing, such as distributing settings for various data used for motion control. Upon completion of the initialization processing, the control system 1 transitions to a state in which it can begin operation (referred to as the "operational state"). Furthermore, it is assumed that the monitoring device 30 has previously acquired the "start time of the synchronization signal" and the "synchronization signal period" before transitioning to the operational state. Note that, in the following description, T-init refers to the "start time of the synchronization signal." The counter m is an integer equal to or greater than 1 and represents the cumulative number of times the monitoring device 30 has received the reference time frame. Counter n is an integer equal to or greater than 1, and indicates the cumulative number of times that the monitoring device 30 has received a frame (however, the first reference time frame is counted as the first frame, and frames received before that reference time frame are not counted). The initial values of counters n and m are assumed to be 0.

[0074] In step S20, the first detector 130 acquires one frame from the log accumulation DB 151.

[0075] In step S21, if the frame is a reference time frame, the first detection unit 130 proceeds to the processing procedure of step S22, and if the frame is not a reference time frame, the first detection unit 130 proceeds to the processing procedure of step S23.

[0076] In step S22, if counter m is 1 or greater, first detection unit 130 adds 1 to counter n and proceeds to the processing procedure of step S37. If counter m is 0, first detection unit 130 proceeds to the processing procedure of step S37 without doing anything.

[0077] In step S23, the first detection unit 130 adds 1 to the counters n and m.

[0078] In step S24, the first detection unit 130 stores the value of the reference time included in the reference time frame in the variable Rt[m].

[0079] In step S25, the first detector 130 stores the time when the communication module 220 receives the reference time frame (the clock value of the monitoring device 30) in the variable Nt[m].

[0080] In step S26, if m=1, the process proceeds to step S27, and if m=1 is not true, the process proceeds to step S28.

[0081] In step S27, the first detection unit 130 calculates the time (T-start) when the monitoring device 30 starts the abnormality detection process (hereinafter referred to as the "abnormality detection start time"). The abnormality detection start time (T-start) can be calculated using the following formula (1). X is an integer equal to or greater than 0.

[0082] Formula (1): T-start = T-init + (synchronization signal period × X), the largest T-start that satisfies T-start < variable Rt[1] In step S28, the first detection unit 130 calculates the variable T n Calculate.

[0083] Formula (2): T n = T-start + synchronization signal period × (n-1) In step S29, the first detection unit 130 calculates the variable T n+1 Calculate.

[0084] Formula (3): T n+1 = T-start + synchronization signal period × (n) In step S30, if the following formula (4) is satisfied, the first detection unit 130 proceeds to the processing procedure of step S31, and if the following formula (4) is not satisfied, the first detection unit 130 proceeds to the processing procedure of step S32.

[0085] Formula (4): T n < Rt[m] < T n+1 In step S31, the first detector 130 determines that a synchronization abnormality A has been detected.

[0086] In step S32, if the counter m is 2 or more, the first detection unit 130 proceeds to the processing procedure of step S33, and if the counter m is 1, the first detection unit 130 proceeds to the processing procedure of step S37.

[0087] In step S33, the first detection unit 130 calculates a variable E1 using the following equation (5).

[0088] Equation (5): E1 = Rt[m] - Rt[m-1] In step S34, the first detection unit 130 calculates a variable E2 using the following equation (6).

[0089] Equation (6): E2 = Nt[m] - Nt[m-1] In step S35, the first detection unit 130 calculates the degree of deviation using the following equation (7), and if the degree of deviation exceeds a predetermined value, proceeds to the processing procedure of step S36, and if the degree of deviation is equal to or less than the predetermined value, proceeds to the processing procedure of step S37. Note that Abs in equation (7) means an absolute value.

[0090] Equation (7): Deviation degree = Abs(1.0-(E1 / E2)) In step S36, the first detector 130 determines that a synchronization abnormality B has been detected.

[0091] In step S37, if the first detection unit 130 does not want to end the abnormality detection process, the process returns to step S20, and if the first detection unit 130 wants to end the abnormality detection process, the process in FIG. 12 ends.

[0092] An example in which a clock abnormality between a synchronization master and a slave is detected as one type of synchronization abnormality by executing the processing procedure described above will be specifically described with reference to FIG.

[0093] Fig. 13 is a diagram showing a specific example of synchronization anomaly detection processing. In the example of Fig. 13, the start time (T-init) of the synchronization signal is 5500 (the time when the starting point of the reference time is 0), and the synchronization signal period is 1000 (for example, 1 ms). Furthermore, the reference times stored in reference time frames B, D, E, and H are 7000, 9000, 11000, and 14000, respectively.

[0094] 12 and 13, the process of the monitoring device 30 detecting a synchronization abnormality will be described assuming that an abnormality occurs in the local clock of the synchronization master / slave. Note that the predetermined value in the processing procedure of step S35 in FIG. 12 is assumed to be 0.1.

[0095] First, the first detection unit 130 acquires frame A (S20, S21-NO, S22, S37-NO in FIG. 12). Next, the first detection unit 130 acquires reference time frame B and increments counters n and m by 1 (S20, S21-YES, S23 in FIG. 12). The first detection unit 130 also stores the reference time value 7000 included in reference time frame B in variable Rt[1], stores the time 7200 when reference time frame B was received by the communications module 220 in variable Nt[1], and calculates variable T-start according to equation (1) (S24, S25, S26-YES, S27 in FIG. 12).

[0096] Here, in equation (1), when X=1, T-start is T-start=5500+1000=6500, which satisfies T-start < 7000. Next, when X=2, T-start is T-start=5500+1000×2=7500, which does not satisfy T-start < 7000. Therefore, the value of T-start is 6500.

[0097] Next, the first detection unit 130 calculates the variable T n and variable T n+1 is calculated according to equations (2) and (3) (S28 and S29 in FIG. 12). At this point, n=1, so T n becomes 6500+1000×(1-1)=6500. Similarly, T n+1 becomes 6500+1000×1=7500.

[0098] The first detection unit 130 determines whether or not formula (4) is satisfied. At this point, m=1 and Rt[1] is 7000, so 6500 < Rt[1] < 7500 is satisfied (S30 in FIG. 12). Therefore, the first detection unit 130 determines that synchronization abnormality A has not occurred. Subsequently, since m=1, the first detection unit 130 skips the processing procedures of steps S33 to S36 in FIG. 12 (S32-NO).

[0099] Next, the first detector 130 receives frame C and adds 1 to n (S20, S21-NO, S22 in FIG. 12). At this point, n=2 and m=1.

[0100] Next, the first detection unit 130 acquires the reference time frame D and increments the counters n and m by 1 (S20, S21-YES, S23 in FIG. 12). The first detection unit 130 also stores the value 9000 of the reference time included in the reference time frame D in the variable Rt[2], and stores the time 9200 when the communication module 220 received the reference time frame D in the variable Nt[2] (S24, S25 in FIG. 12).

[0101] Next, the first detection unit 130 calculates the variable T n and variable T n+1 is calculated according to equations (2) and (3) (S28 and S29 in FIG. 12). At this point, n=3, so T n becomes 6500+1000×(3-1)=8500. Similarly, T n+1 becomes 6500+1000×3=9500.

[0102] The first detection unit 130 determines whether or not formula (4) is satisfied. At this point, m=2 and Rt[2] is 9000, so 8500 < Rt[2] < 9500 is satisfied (YES in S30 of FIG. 12). Therefore, the first detection unit 130 determines that synchronization abnormality A has not occurred. The first detection unit 130 also calculates E1 and E2 according to formulas (5) and (6) (YES in S32, S33, S34 of FIG. 12). E1 is Rt[2]-Rt[1]=9000-7000=2000, and E2 is Nt[2]-Nt[1]=9200-7200=2000. The first detection unit 130 determines whether or not formula (7) is satisfied (S35 of FIG. 12). Abs(1.0-E2 / E1)=1.0-2000 / 2000=0, which is equal to or less than the predetermined value 100, so the first detector 130 determines that synchronization abnormality B has not occurred (YES in S35 of FIG. 12).

[0103] Next, the first detector 130 receives frame E and adds 1 to n (S20, S21-NO, S22 in FIG. 9). At this point, n=4 and m=2.

[0104] Next, the first detection unit 130 acquires the reference time frame F, adds 1 to the counter n and the counter m, stores the value of the reference time included in the reference time frame F, 11000, in the variable Rt[3], stores the time, 11200, when the communication module 220 received the reference time frame F, in the variable Nt[3], and stores the time, 11200, when the communication module 220 received the reference time frame F, in the variable T n and variable T n+1 is calculated according to the formula (2) and the formula (3) (S23, S24, S25, S26-NO, S28, S29 in FIG. 12). At this point, n=5, so T n becomes 6500+1000×(5-1)=10500. Similarly, T n+1 becomes 6500+1000×5=11500.

[0105] The first detection unit 130 determines whether or not formula (4) is satisfied. At this point, m=3 and Rt[3] is 11,000, so 10,500 < Rt[3] < 11,500 is satisfied (S30-NO in FIG. 12). Therefore, the first detection unit 130 determines that synchronization abnormality A has not occurred. The first detection unit 130 also calculates E1 and E2 according to formulas (5) and (6) (S33, S34 in FIG. 12). E1 is Rt[3]-Rt[3]=11,000-9,000=2,000, and E2 is Nt[3]-Nt[2]=11,200-9,200=2,000. The first detection unit 130 determines whether or not formula (7) is satisfied (S35 in FIG. 12). Abs(1.0-E2 / E1)=1.0-2000 / 2000=0, which is equal to or less than the predetermined value 100, so the first detector 130 determines that synchronization abnormality B has not occurred (S35-NO in FIG. 12).

[0106] Next, the first detector 130 receives frame G and adds 1 to n (S22 in FIG. 12). At this point, n=6 and m=3.

[0107] Next, the first detection unit 130 acquires the reference time frame H and adds 1 to the counter n and counter m (S20, S21-YES, S23 in FIG. 12). The first detection unit 130 also stores the value of the reference time included in the reference time frame H, 14000, in the variable Rt[4], stores the time 13200 when the communication module 220 receives the reference time frame H, in the variable Nt[4], and adds 1 to the variable T n and variable T n+1 is calculated according to equations (2) and (3) (S24, S25, S26-NO, S28, S29 in FIG. 12). At this point, n=7, so T n becomes 6500+1000×(7-1)=12500. Similarly, T n+1 becomes 6500+1000×7=13500.

[0108] The first detection unit 130 determines whether or not formula (4) is satisfied. At this point, m=4 and Rt[4] is 14,000, so 12,500 < Rt[4] < 13,500 is not satisfied (NO in S30 of FIG. 12). Therefore, the first detection unit 130 determines that synchronization abnormality A has occurred (S31 of FIG. 12). The first detection unit 130 also calculates E1 and E2 according to formulas (5) and (6) (S33 and S34 of FIG. 12). E1 is Rt[4]-Rt[3]=14,000-11,000=3,000, and E2 is Nt[4]-Nt[3]=13,200-11,200=2,000. The first detection unit 130 determines whether or not formula (7) is satisfied (S35 of FIG. 12). Abs(1.0-E2 / E1)=Abs(1.0-3000 / 2000)=0.5, which is not equal to or less than the predetermined value 0.1, so the first detector 130 determines that a synchronization abnormality B has occurred (NO in S35, S36 in FIG. 12).

[0109] As described above, the first detection section 130 detects synchronization abnormality A and synchronization abnormality B, and determines that the clock of the synchronization master slave 20-1 is abnormal according to the table of FIG.

[0110] [Modification of detection of synchronization processing abnormality] (Variation 1) In the detection of the synchronization process abnormality described above, the monitoring device 30 may perform only one of the detection of synchronization abnormality A and the detection of synchronization abnormality B.

[0111] (Variation 2) The log accumulation DB 151 sequentially stores the contents of the latest frames captured by the communication module 220 in association with the time at which each frame was received by the monitoring device 30 (more specifically, the communication module 220). Therefore, the first detection unit 130 may be configured to quickly detect the occurrence of a synchronization anomaly by sequentially analyzing the frames sequentially stored in the log accumulation DB 151 according to the flowchart shown in Fig. 12. Alternatively, the first detection unit 130 may be configured to detect the occurrence of a synchronization anomaly after the fact by analyzing frames previously accumulated in the log accumulation DB 151 by batch processing according to the flowchart shown in Fig. 12.

[0112] (Variation 3) The clock of the monitoring device 30 does not necessarily have to operate on the same time axis as the reference time, but may operate on a time axis different from the reference time.

[0113] (Variation 4) 14 and 15 are diagrams for explaining modified examples. Since industrial networks process frames on the fly, a time lag corresponding to a propagation delay occurs between the time a frame arrives at the synchronization master slave and the time the frame finally arrives at the slave 20 that processes the frame. It is also considered that a slight time lag is required between the time the frame arrives at the slave 20 and the time the frame can be processed by the application unit.

[0114] 14, frame A arrives at slave 20-2 immediately before time t2 when synchronization signal 2 is generated, so even if slave 20-2 receives frame A at this time, it may be difficult for it to start AP processing at time t2. Therefore, the first detection unit 130 may detect the presence or absence of synchronization anomaly A, taking this time lag into consideration.

[0115] For example, the first detection unit 130 may detect the presence or absence of the synchronization anomaly A by determining whether or not a reference time exists between the time (t1 in FIG. 15) when the first of two consecutive synchronization signals, at which the reference time frame should be received, is generated (t1 in FIG. 15), and a time (t2-a in FIG. 15) that is a predetermined time (third time) before the time (t2 in FIG. 15) when the second synchronization signal 2 is generated, for a reference time frame among frames repeatedly transmitted from the master 10. The predetermined time (third time) may be set to a time longer than the sum of the propagation delay D between the synchronization master slave and the slave 20 that last processes the frame and the processing delay time within the slave 20.

[0116] More specifically, the first detection unit 130 may determine that synchronization abnormality A has not occurred if there is a reference time between the time when the first of two consecutive synchronization signals, which should be received by one or more slaves 20 (or synchronization master slaves), is generated in one or more slaves (or synchronization master slaves) and the time a predetermined time (third time) before the time when the second synchronization signal is generated in one or more slaves.Also, the first detection unit 130 may determine that synchronization abnormality A has occurred if there is no reference time between the time when the first of two consecutive synchronization signals, which should be received by one or more slaves 20 (or synchronization master slaves), is generated in one or more slaves (or synchronization master slaves) and the time a predetermined time (third time) before the time when the second synchronization signal is generated in one or more slaves (or synchronization master slaves).

[0117] (Recording of the frame immediately before the abnormality occurred) Next, a process will be described in which, when an abnormality occurs in the control system 1, log data of frames that were flowing through the industrial network before the abnormality occurred is extracted and the extracted log data is transmitted to the master 10.

[0118] Here, the contents of the data accumulated in the log accumulation DB 151 will be described. The log accumulation DB 151 stores frames that are captured by the communication module 220 of the real-time OS 200 and flow through the industrial network. At this time, the frame data stored in the log accumulation DB 151 may include an identifier (first identifier) that uniquely identifies a frame repeatedly transmitted from the master 10. The identifier that uniquely identifies a frame is called a "cycle number." The cycle number is a number managed by the master 10 and the monitoring device 30, and is not included in the frame. For example, the master 10 sets the cycle number of the first frame it transmits after transitioning to an operational state to 0, and increments the cycle number by one each time it transmits a frame. Similarly, the monitoring device 30 sets the cycle number of the first frame it receives after transitioning to an operational state to 0, and increments the cycle number by one each time it receives a frame.

[0119] Furthermore, the data of the frame stored in the log accumulation DB 151 may include an identifier (second identifier) indicating a memory location to which data (also called an object) is written or read in the frame repeatedly transmitted from the master 10. The identifier indicating the memory location may be a combination of an identifier (setting address) for identifying the slave 20, an index, and a sub-index.

[0120] Similarly, the pre-failure log data 320 in which the log data extracted from the log accumulation DB 151 is stored may also include a cycle number and an identifier (second identifier) indicating a memory location.

[0121] That is, by specifying a cycle number, the monitoring device 30 can acquire frame data transmitted from the master at the specified cycle number from the pre-failure log data 320. Furthermore, by specifying a cycle number and an identifier indicating a memory location, the monitoring device 30 can acquire, from the pre-failure log data 320, frame data transmitted from the master at the specified cycle number, which is data addressed to a specific memory of a specific slave 20, or data read from a specific memory of a specific slave 20 and stored in a frame.

[0122] When the extraction unit 140 is notified that an abnormality has occurred in the master 10 or one or more slaves 20, the extraction unit 140 extracts, from the log accumulation DB 151, log data from the time when the abnormality was detected to a predetermined time before (first time before). The time when the abnormality was detected may be the time when the monitoring device 30 detected the abnormality, or the time when the monitoring device 30 received a frame that detected the abnormality. The extraction unit 140 also stores the extracted log data as pre-failure log data 320 in the second storage unit 300 that can be referenced by the real-time OS 200.

[0123] Here, the predetermined time (first time) may be specified by the master 10 or may be stored in advance in the configuration file 152. The predetermined time may be expressed as a number of cycles (e.g., 1000 cycles) or as a specific time length (e.g., 1 second). When expressed as a number of cycles, the predetermined time may be called a "specified number of cycles." Note that, since the time length of one cycle is the same as the synchronization signal period, the number of cycles and the time length can be converted into each other. Therefore, expressing the predetermined time as a specific time length and expressing it as a number of cycles are synonymous.

[0124] The second detection unit 231 may determine that an abnormality has occurred in the master 10 if it fails to receive frames repeatedly transmitted from the master 10 for a certain period of time (second period). The certain period of time may be called a "WD (watchdog) timer." The WD timer may be specified by the master 10 or may be stored in advance in the configuration file 152. Furthermore, if the monitoring device 30 detects the above-described synchronization abnormality A or synchronization abnormality B, it may determine that an abnormality has occurred in the master 10 or one or more slaves 20. The WD timer may be expressed in terms of the number of cycles (e.g., 100 cycles) or a specific time length (e.g., 0.1 seconds). As mentioned above, the number of cycles and the time length can be converted into each other, so expressing the WD timer in terms of a specific time length and expressing it in terms of the number of cycles are synonymous.

[0125] The communication module 220 transmits the log data stored in the pre-failure log data 320 to the master 10 via the industrial network in response to a request from the master 10. Specifically, the communication module 220 (receiving unit) receives a transmission request for pre-failure log data including a cycle number (first identifier) from the master 10. Furthermore, when the communication module 220 (transmitting unit) receives the transmission request, it transmits the data of the frame specified by the cycle number from the pre-failure log data to the master 10.

[0126] Furthermore, the communication module 220 (receiving unit) may receive a request to transmit pre-failure log data including a cycle number (first identifier) and an identifier (second identifier) indicating a memory location from the master 10. Furthermore, when the communication module 220 (transmitting unit) receives the transmission request, the communication module 220 may transmit to the master 10 data from the pre-failure log data that corresponds to the identifier indicating the memory location in the frame specified by the cycle number (i.e., data to be written to the memory indicated by the identifier or data read from the memory indicated by the identifier).

[0127] The slave processing unit 210 may be configured to delete the pre-failure log data 320 when instructed to do so by the master 10. Specifically, the communication module 220 (receiving unit) may receive a request to delete the pre-failure log data 320 from the master 10, and the second detection unit 231 may delete the pre-failure log data 320 when the second detection unit 231 receives the deletion request. The second detection unit 231 may be called a "deletion processing unit."

[0128] FIG. 16 is a sequence diagram showing an example of a processing procedure for extracting log data and transmitting it to the master 10 when an abnormality occurs.

[0129] In step S100, the master 10 transmits a frame including the WD timer and the designated number of cycles, thereby writing the WD timer and the designated number of cycles to a predetermined memory area in the third storage unit 221 of the monitoring device 30. The second detection unit 231 of the monitoring device 30 acquires the WD timer and the designated number of cycles written in the third storage unit 221, thereby recognizing the value of the WD timer and the designated number of cycles.

[0130] After the processing procedure of step S100 is completed, the control system 1 transitions to an operational state, and the master 10 starts transmitting frames.

[0131] In step S101, the second detection unit 231 detects the occurrence of an abnormality. For example, the second detection unit 231 may detect the occurrence of an abnormality if it is unable to receive a frame from the master 10 for a period set by the WD timer. When the second detection unit 231 detects the occurrence of an abnormality, it stores, in the third storage unit 221, an “abnormality detection flag” indicating that an abnormality has been detected and an “abnormality detection cycle number” indicating the cycle number of the last frame received when the abnormality was detected. Note that the reason for storing the abnormality detection flag and the abnormality detection cycle number in the third storage unit 221 is to enable the master 10 to recognize that an abnormality has occurred in the industrial network. The second detection unit 231 also notifies the extraction unit 140 that an abnormality has occurred. For example, the second detection unit 231 may store the abnormality detection flag and the abnormality detection cycle number in the second storage unit 300, and the extraction unit 140 may periodically refer to the second storage unit 300 to acquire the abnormality detection flag and the abnormality detection cycle number.

[0132] In step S102, when the extracting unit 140 is notified by the second detecting unit 231 that an abnormality has occurred, the extracting unit 140 extracts, from the log accumulation DB 151, log data of frames from the cycle number when the abnormality was detected up to a specified number of cycles before, and stores the extracted data in the pre-failure log data 320. The extracting unit 140 also notifies the second detecting unit 231 that the pre-failure log data 320 has been stored. For example, the extracting unit 140 may store information indicating that storage of the pre-failure log data 320 has been completed in the second storage unit 300, and the extracting unit 140 may periodically refer to the second storage unit 300 to check whether or not the information exists, thereby recognizing that the pre-failure log data 320 has been stored in the second storage unit 300.

[0133] When the pre-failure log data 320 is stored in the second storage unit 300, the second detection unit 231 stores an extraction completion flag in the third storage unit 221. The extraction completion flag indicates that extraction of the pre-failure log data 320 has been completed and that the pre-failure log data 320 can now be read from the master 10.

[0134] In step S103, upon receiving an instruction from the master 10, the communication module 220 stores the abnormality detection flag, the cycle number at which the abnormality was detected, and the extraction completion flag in a frame and transmits the frame to the master 10. By reading the abnormality detection flag, the cycle number at which the abnormality was detected, and the extraction completion flag from the received frame, the master 10 recognizes that an abnormality has been detected in the monitoring device 30, the cycle number at which the abnormality occurred, and that it is now possible to read the pre-failure log data 320 from the monitoring device 30. Note that the processing procedure of step S103 may be executed, for example, by an administrator or the like who manages the master 10 operating the screen of the master 10.

[0135] In step S104, the master 10 determines, from the monitoring device 30, which cycle number of the frame to read from among the cycles from the cycle number at the time of abnormality detection up to the specified number of cycles before, which slave 20 to read the frame addressed to, which index and subindex values to read, etc. Note that this determination may be made by an administrator or the like who manages the master 10 specifying the cycle number, etc.

[0136] In step S105, in order to read data of a frame having the cycle number determined in the processing procedure of step S104, the master 10 transmits a frame including an identifier indicating the monitoring device 30, the cycle number of the frame to be read, the identifier (setting address) of the slave 20 from which the data is to be read, and an index and subindex corresponding to the value to be read. Note that the identifier of the slave 20 from which the data is to be read, and the index and subindex corresponding to the value to be read may be omitted. For example, if it is desired to obtain all data of a frame having a certain cycle number, the master 10 may specify only the cycle number and omit the identifier of the slave 20 from which the data is to be read, the index, and the subindex.

[0137] In step S106, the communication module 220 stores the frame data of the cycle number specified by the master 10 in the processing procedure of step S105 in the frame received from the master 10 in the processing procedure of step S105 and transmits the frame to the master 10. The master 10 acquires the frame data of the specified cycle number from the received frame. Note that when reading frame data of multiple cycles, the master 10 repeats the processing procedures of steps S105 and S106.

[0138] In step S107, the master 10 stores the data of the acquired frame.

[0139] 17 is a diagram showing an example of frame data stored in the pre-failure log data 320. The recorded value index is an identifier for uniquely identifying a record recorded in the pre-failure log data 320. For example, if it is desired to acquire all values in frames with cycle numbers of 1000 to 1049, the master 10 specifies the cycle number of 1000 in the processing procedure of step S105, and repeats the procedure of acquiring data for the frame with the cycle number of 1000 in the processing procedure of step S106 50 times while increasing the cycle number by 1. Returning to FIG. 16, the explanation will be continued.

[0140] The frames used in the processing procedures of steps S105 and S106 may be frames or frames that are transmitted aperiodically regardless of the synchronization processing.

[0141] In step S108, in order to erase the pre-failure log data 320 stored in the monitoring device 30, the master 10 writes the reset command flag to a specified memory area in the third memory unit 221 of the monitoring device 30 by transmitting a frame including the identifier of the monitoring device 30, an index and subindex indicating the memory area in which the reset command flag is stored, and the value of the reset command flag.

[0142] In step S109, if the second detection unit 231 of the monitoring device 30 detects that a reset command flag has been written to the third storage unit 221, it deletes the pre-fault log data 320. In addition, the second detection unit 231 deletes the abnormality detection flag, the cycle number at the time of abnormality detection, and the extraction completion flag stored in the third storage unit 221.

[0143] <Summary> According to the embodiment described above, it is possible to detect an abnormality occurring in a control system connected via an industrial network at an earlier stage, and when an abnormality occurs in a control system connected via an industrial network, it is possible to more quickly analyze the abnormality and / or perform recovery.

[0144] Furthermore, since the monitoring device 30 analyzes the frames transmitted from the master 10 at each synchronization signal generation cycle, it is possible to quickly detect the occurrence of a synchronization abnormality before the next synchronization signal generation cycle arrives.

[0145] Furthermore, the monitoring device 30 is configured to detect two types of abnormality, synchronization abnormality A and synchronization abnormality B. This enables the monitoring device 30 to specifically identify the cause of a synchronization abnormality when it occurs in the control system 1. Specifically, it becomes possible to identify whether the abnormality is in the clock of the monitoring device 30 itself, whether there is an abnormality in the transmission period of the frame transmitted by the master 10, or whether there is an abnormality in the local clock of the synchronization master-slave.

[0146] Without the monitoring device 30, even if a synchronization abnormality occurs, it is difficult to determine whether the abnormality occurs in the local clock of the master 10 or in the local clock of a synchronous master-slave. On the other hand, in this embodiment, the occurrence of a synchronization abnormality is monitored by the monitoring device 30 separate from the master 10, making it possible to specifically identify the cause of the synchronization abnormality.

[0147] Furthermore, the monitoring device 30 captures frames transmitted from the master 10 and stores them in a log accumulation DB 151 on the non-real-time OS 100. By storing the log accumulation DB 151 on the non-real-time OS side, which can handle large amounts of data, the monitoring device 30 can capture and store large amounts of frame data.

[0148] Furthermore, when the monitoring device 30 detects the occurrence of an abnormality, it extracts data of a frame immediately before the occurrence of the abnormality from the log accumulation DB 151 and stores the extracted pre-failure log data 320 in a memory that can be referenced by the real-time OS 200. Since it is difficult for a non-real-time OS to perform real-time processing, it is impossible to acquire the pre-failure log data 320 according to the frame period and write it to a frame. However, by making the pre-failure log data 320 accessible to the real-time OS 200, the monitoring device 30 can acquire the pre-failure log data 320 according to the synchronization signal period and write it to a frame. In other words, the master 10 can read the pre-failure log data 320 using frames that are repeatedly transmitted according to the synchronization signal period.

[0149] Furthermore, by reading the pre-fault log data 320, the master 10 can identify the position where the motion control stopped, and after recovery from the abnormality, it becomes possible to resume the motion control from the position where it stopped.

[0150] Furthermore, the monitoring device 30 transmits the pre-failure log data 320 via an industrial network. This allows the monitoring device 30 to easily transmit the pre-failure log data 320 to the master 10 even if the master 10 used in the control system 1 has difficulty in receiving external inputs such as USB.

[0151] The above-described embodiments are intended to facilitate understanding of the present disclosure and are not intended to limit the present disclosure. The flowcharts, sequences, elements included in the embodiments, and their arrangements, materials, conditions, shapes, sizes, etc., described in the embodiments are not limited to those illustrated and can be modified as appropriate. Furthermore, configurations shown in different embodiments can be partially substituted or combined with each other. [Explanation of symbols]

[0152] 1 Control system, 10 Master, 11 Processor, 12 Storage device, 13 Network IF, 14 Input device, 15 Output device, 20 Slave, 30 Monitoring device, 110 Display unit, 120 Collection unit, 130 First detection unit, 140 Extraction unit, 150 First memory unit, 151 Log accumulation DB, 152 Configuration file, 210 Slave processing unit, 220 Communication module, 221 Third memory unit, 230 Fixed-period processing unit, 231 Second detection unit, 300 Second memory unit, 310 FIFO queue, 320 Pre-failure log data

Claims

1. An information processing device connected to a master and one or more slaves via an industrial network, a receiving unit that receives frames repeatedly transmitted from the master within the industrial network; an abnormality detection unit that analyzes the frame to detect the presence or absence of an abnormality in a synchronization process performed between the master and the one or more slaves based on a reference time distributed within the industrial network; An information processing device having the above.

2. the frame is repeatedly transmitted from the master at the same period as a synchronization signal period in which a synchronization signal is repeatedly generated within the one or more slaves; the abnormality detection unit detects the presence or absence of a first abnormality in the synchronization process by determining whether or not the reference time exists between times at which two consecutive synchronization signals are generated, for a frame including the reference time among frames repeatedly transmitted from the master, at which the frame should be received; The information processing device according to claim 1 .

3. The abnormality detection unit If the reference time is between the times when the two consecutive synchronization signals are generated in the one or more slaves, it is determined that the first abnormality has not occurred; determining that the first abnormality has occurred if the reference time does not exist between the times at which the two consecutive synchronization signals are generated in the one or more slaves; The information processing device according to claim 2 .

4. the frame is repeatedly transmitted from the master at the same cycle as a cycle in which a synchronization signal is repeatedly generated within the one or more slaves; the anomaly detection unit detects the presence or absence of a second anomaly related to the synchronization process based on a difference between the times at which each of two consecutive frames including the reference time was received by the information processing device and a difference between the reference times included in each of the two consecutive frames; 4. The information processing device according to claim 2 or 3.

5. The abnormality detection unit determining that the second abnormality has not occurred if the degree of deviation between the difference between the times at which the two consecutive frames were received and the difference between the reference times included in the two consecutive frames is equal to or less than a predetermined value; determining that the second abnormality has occurred when the degree of deviation between the difference between the times at which the two consecutive frames were received and the difference between the reference times included in the two consecutive frames exceeds a predetermined value; The information processing device according to claim 4 .

6. the abnormality detection unit determines that there is an abnormality in the transmission period of frames repeatedly transmitted from the master when the first abnormality has occurred and the second abnormality has not occurred; The information processing device according to claim 4 .

7. the abnormality detection unit determines that an abnormality exists in a clock included in the information processing device when the first abnormality does not occur and the second abnormality occurs; The information processing device according to claim 4 .

8. the anomaly detection unit determines that an anomaly exists in the clock of the slave that distributes the reference time when both the first anomaly and the second anomaly have occurred; The information processing device according to claim 4 .

9. An information processing method executed by an information processing device connected to a master and one or more slaves via an industrial network, comprising: receiving a frame repeatedly transmitted from the master within the industrial network; analyzing the frame to detect whether or not there is an abnormality in a synchronization process performed between the master and the one or more slaves based on a reference time distributed within the industrial network; An information processing method, including:

10. A computer connected to a master and one or more slaves via an industrial network, receiving a frame repeatedly transmitted from the master within the industrial network; analyzing the frame to detect whether or not there is an abnormality in a synchronization process performed between the master and the one or more slaves based on a reference time distributed within the industrial network; A program to execute.

Citation Information

Patent Citations

  • Hydraulic support electrohydraulic control method based on EtherCAT bus

    CN112647992A

  • Cycle control synchronizing system

    JP2002164872A

  • Communication control device and communication system

    JP2014183386A

  • Control device and control method

    JP2019101480A

  • Relay device, communication system, and fault detection method

    WO2017033416A1