Safety I / O terminal and safety system
The safety IO terminal can communicate with multiple safety controllers, ensuring flexible and reliable safety control by using individual data storage and logic execution, addressing the limitations of single-controller systems.
Patent Information
- Application Number
- JP2024040640
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-15
- Publication Date
- 2025-09-29
AI Technical Summary
Existing safety IO terminals are limited to communicating with a single safety controller, restricting their applicability and flexibility in complex safety systems.
A safety IO terminal capable of establishing safety connections with multiple safety controllers, utilizing individual data storage areas for each connection and a safety logic execution unit to determine output signals based on data from multiple controllers, ensuring correct data storage and logical operations.
Enables safety control based on data from multiple safety controllers, enhancing flexibility and reliability in safety systems by allowing parallel connections and maintaining appropriate safety logic regardless of controller changes.
Smart Images

Figure 2025140964000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a secure IO terminal and a secure system. [Background technology]
[0002] In manufacturing sites, safety systems are sometimes introduced in addition to control devices for equipment and machinery. Safety systems are designed to prevent equipment and machinery from threatening human safety.
[0003] A safety system may be composed of, for example, a safety controller for executing safety control, and one or more safety IO terminals for handling safety input signals and safety output signals.
[0004] Regarding a safety IO terminal, for example, Japanese Patent Application Laid-Open Publication No. 2014-098985 (Patent Document 1) discloses a safety slave unit that can reduce the processing load on a safety controller. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2014-098985 Summary of the Invention [Problem to be solved by the invention]
[0006] Generally, one safety IO terminal is under the control of one safety controller. However, the inventors of the present application have newly discovered that it is more preferable for one safety IO terminal to communicate with multiple safety controllers depending on the application to which the safety system is applied.
[0007] An object of the present invention is to provide a safety IO terminal capable of safety control based on data from a plurality of safety controllers, and a safety system including the safety IO terminal. [Means for solving the problem]
[0008] A safety IO terminal according to an embodiment includes a safety output circuit that outputs a safety output signal, a safety communication unit that can establish a safety connection with one or more safety controllers, a received data storage unit that includes multiple individual areas for storing data received by the safety communication unit for each safety connection, and a safety logic execution unit that determines the value of the safety output signal using any data stored in the multiple individual areas, each of which is configured to be associated with identification information for identifying the safety controller that establishes the safety connection with the safety IO terminal.
[0009] According to this configuration, data from the multiple safety controllers is stored in multiple individual areas of the safety IO terminal. The safety IO terminal can determine the value of a safety output signal using any data stored in the multiple individual areas, so that appropriate safety logic can be realized using data from the multiple safety controllers depending on the application.
[0010] In order to establish a safety connection, each of the one or more safety controllers may send a request to the safety IO terminal, the request including identification information of the safety controller and a designation of the individual area to be used. This configuration prevents data from being mistakenly stored in an individual area different from the individual area corresponding to the connection between the safety controller and the safety IO terminal.
[0011] The safety communication unit may associate the identification information included in the request with the individual area if no identification information is associated with the individual area specified by the request. According to this configuration, in a factory default state, any safety controller can be connected to the safety IO terminal.
[0012] The safety communication unit may establish a safety connection in accordance with the request if identification information associated with the individual area specified by the request matches identification information included in the request. With this configuration, it is possible to establish a connection between the safety controller and the safety IO terminal after confirming that the specification of the corresponding individual area is correct.
[0013] The secure IO terminal may further include a storage unit for storing an identification information list including identification information associated with each individual area. With this configuration, even if the individual area is configured using a volatile storage device, the identification information associated with the individual area can be managed.
[0014] The safety logic execution unit may perform a logical OR operation using as input a value indicated by first data stored in a first individual area among the plurality of individual areas and a value indicated by second data stored in a second individual area among the plurality of individual areas. With this configuration, the safety output signal can be maintained as long as the safety logic execution unit is connected to any one of the plurality of safety controllers.
[0015] The safety logic execution unit may perform a logical AND operation using as input a value indicated by first data stored in a first individual area among the plurality of individual areas and a value indicated by second data stored in a second individual area among the plurality of individual areas. With this configuration, the safety output signal can be cut off from any of the plurality of safety controllers.
[0016] The safety connection may be established based on at least one of CIP Safety and PROFIsafe. This configuration allows the safety connection to be established using a general-purpose communication protocol.
[0017] A safety system according to another embodiment includes a safety IO terminal and one or more safety controllers capable of executing a safety program based on safety input data received from the safety IO terminal. The safety IO terminal includes a safety input circuit that accepts a safety input signal, a safety output circuit that outputs a safety output signal, a safety communication unit that can establish a safety connection with one or more safety controllers, a received data storage unit including multiple individual areas for storing data received by the safety communication unit for each safety connection, and a safety logic execution unit that determines the value of the safety output signal using any data stored in the multiple individual areas. Each of the multiple individual areas is configured to store identification information for identifying the safety controller that establishes a safety connection with the safety IO terminal. [Effects of the Invention]
[0018] According to the present invention, it is possible to realize a safety IO terminal capable of safety control based on data from a plurality of safety controllers, and a safety system including the safety IO terminal. [Brief explanation of the drawings]
[0019] [Figure 1] 1 is a schematic diagram showing a configuration example of a safety system according to an embodiment of the present invention; [Figure 2] FIG. 2 is a schematic diagram showing an example of a hardware configuration of a safety controller of the safety system according to the present embodiment. [Figure 3] 1 is a schematic diagram showing an example of a hardware configuration of a safety IO terminal that configures a safety system according to the present embodiment. FIG. [Figure 4] FIG. 1 is a schematic diagram illustrating an example of a functional configuration of a safety IO terminal according to the related art. [Figure 5] 2 is a schematic diagram showing an example of a functional configuration of a safety IO terminal that configures the safety system according to the present embodiment. FIG. [Figure 6] 10 is a sequence diagram showing an example of a communication procedure in a factory-shipped state of the safety IO terminal according to the present embodiment. FIG. [Figure 7]It is a sequence diagram showing an example of a communication procedure when the safety IO terminal according to this embodiment is normally started up. [Figure 8] It is a schematic diagram showing a configuration example of the safety system 1A using a transport robot equipped with a safety IO terminal according to this embodiment. [Figure 9] It is a flowchart showing an example of an operation procedure of the safety system shown in FIG. 8. [Figure 10] It is a schematic diagram showing a configuration example of a safety system that enables safety control between zones according to this embodiment. ] [Figure 11] It is a diagram for comparing the features of the devices constituting the safety system according to this embodiment. <A
Embodiments for Carrying Out the Invention
[0020] Embodiments of the present technology will be described in detail with reference to the drawings. For the same or corresponding parts in the drawings, the same reference numerals are given and the description thereof will not be repeated. <00A
[0021] <A. Application Example>[ First, an example of a scene to which the present invention is applied will be described.
[0022] FIG. 1 is a schematic diagram showing a configuration example of the safety system 1 according to this embodiment. Referring to FIG. 1, the safety system 1 includes, as an example, safety controllers 100-1 and 100-2 (hereinafter, also collectively referred to as "safety controller 100") and a safety IO terminal 200.
[0023] FIG. 1 shows a configuration example in which the safety controller 100 and the safety IO terminal 200 are wired-connected via the network 2, but a configuration example of wireless connection may also be adopted. For the network 2, industrial network protocols such as EtherCAT (registered trademark), EtherNet / IP (registered trademark), PROFIBUS, and PROFINET may be adopted.
[0024] The safety controller 100 executes a safety program created in advance. The safety program includes a combination of instructions for implementing processes to prevent human safety from being threatened by equipment, machinery, etc. The safety controller 100 includes, for example, a calculation unit for executing the safety program. The safety control executed by the safety controller 100 is designed to meet the requirements specified in IEC 61508, a functional safety standard.
[0025] The safety IO terminal 200 includes a safety output circuit that outputs a safety output signal (for example, a binary signal of True / False). The safety IO terminal 200 outputs the safety output signal in accordance with an output value of the safety controller 100 (hereinafter also referred to as a "safety output value").
[0026] The safety IO terminal 200 may further include a safety input circuit that receives a safety input signal (for example, a binary signal of True / False). The safety IO terminal 200 transmits the value of the received safety input signal (hereinafter also referred to as a “safety input value”) to the safety controller 100.
[0027] One or more safety input values may be transmitted as aggregated data, and one or more safety output values may be transmitted as aggregated data, so one or more safety input values may also be referred to as "safety input data" and one or more safety outputs may also be referred to as "safety output data."
[0028] The safety controller 100 can execute a safety program based on safety input values received from the safety IO terminal 200. The safety controller 100 can also send safety output data determined by the execution of the safety program to the safety IO terminal 200. In this manner, the safety IO terminal 200 functions as a remote IO device for the safety controller 100.
[0029] The safety controller 100 may further include a signal processing section (for example, a safety IO unit) for processing safety input / output signals.
[0030] The safety IO terminal 200 can establish safety connections in parallel with a plurality of safety controllers 100. A safety connection is established between the safety controller 100 and the safety IO terminal 200.
[0031] A safety connection refers to a logical connection established in accordance with a safety communication protocol. The safety communication protocol used must meet a predetermined level (e.g., SIL3 (Safety Integrity Level 3)) specified in the functional safety standard IEC 61508. For example, protocols such as CIP Safety and PROFIsafe are used. In other words, the safety connection may be established based on at least one of CIP Safety and PROFIsafe. However, any safety communication protocol may be used as long as it meets the predetermined level specified in IEC 61508.
[0032] For example, the safety IO terminal 200 exchanges safety input values and safety output data with the safety controller 100-1, and in parallel exchanges safety input values and safety output data with the safety controller 100-2. Note that the safety IO terminal 200 does not always have to exchange data with all the safety controllers 100. For example, the safety IO terminal 200 may exchange data only with the safety controller 100-1 at a specific time, and only with the safety controller 100-2 at another time.
[0033] The safety IO terminal 200 can execute safety logic for determining one or more safety output data values based on one or more safety input values. The scale of the safety logic that the safety IO terminal 200 can execute is smaller than the safety program that the safety controller 100 executes.
[0034] In the safety logic that the safety IO terminal 200 can execute, it is also possible to handle the safety output data from the safety controller 100 as a safety input value. Since the safety IO terminal 200 can establish a safety connection in parallel with a plurality of safety controllers 100, for example, safety logic based on the safety output data from the safety controller 100-1 and the safety output data from the safety controller 100-2 can be configured.
[0035] In FIG. 1, an example is shown in which in the safety IO terminal 200, a safety logic 290 for determining the safety output value of the safety IO terminal 200 is configured by an OR circuit (logical sum) of a safety output value 1 (one value included in the safety output data) from the safety controller 100-1 and a safety output value 2 from the safety controller 100-2. By configuring the safety logic 290, the safety devices (such as safety relays and safety drives) connected to the safety IO terminal 200 can be operated from either of the safety controllers 100-1 and 100-2.
[0036] Note that a support device for creating, transferring, changing, etc. of the safety program and / or the safety logic 290 may be connectable to the safety controller 100 and the safety IO terminal 200.
[0037] <B. Hardware Configuration Example of Safety System 1> Next, a hardware configuration example of the safety system 1 will be described.
[0038] (b1: Safety Controller 100) FIG. 2 is a schematic diagram showing a hardware configuration example of the safety controller 100 of the safety system 1 according to the present embodiment.
[0039] Referring to FIG. 2, the safety controller 100 includes arithmetic circuits 110 and 120, storages 130 and 140, a communication circuit 102, an internal bus circuit 104, and a memory card interface 106.
[0040] The arithmetic circuits 110 and 120 execute programs (such as a system program 132 and a safety program 134) stored in the storages 130 and 140, respectively. The arithmetic circuits 110 and 120 compare their arithmetic results with each other. If the arithmetic results do not match, it is determined that some kind of abnormality has occurred.
[0041] The operational circuit 110 includes a processor 112 and a memory 114. The operational circuit 120 includes a processor 122 and a memory .
[0042] The processors 112 and 122 are configured by, for example, a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit).
[0043] The memories 114 and 124 are configured by, for example, volatile storage devices such as DRAM (Dynamic Random Access Memory) and SRAM (Static Random Access Memory).
[0044] The storages 130 and 140 are configured by non-volatile storage devices such as Flash Read-Only Memory (FROM) and Electrically Erasable Programmable Read-Only Memory (EEPROM), for example.
[0045] The system program 132 includes computer-readable instructions for providing an execution environment for the arithmetic circuits 110 and 120 to execute the programs. The safety program 134 includes computer-readable instructions for implementing processing to prevent human safety from being threatened by facilities, machines, etc. The safety program 134 may be written in accordance with standards such as IEC 61131-3.
[0046] The communication circuit 102 is responsible for communication with other devices (such as other safety controllers 100 and safety IO terminals 200) via the network 2.
[0047] The internal bus circuit 104 is responsible for communication with a safety unit (not shown) and the like. Similar to the safety IO terminal 200, the safety unit includes at least one of a safety input circuit that receives a safety input signal and a safety output circuit that outputs a safety output signal.
[0048] The memory card interface 106 reads and writes any data from and to a memory card 108, which is an example of a removable storage medium.
[0049] (b2: Safety IO terminal 200) FIG. 3 is a schematic diagram showing an example of a hardware configuration of a safety IO terminal 200 constituting the safety system 1 according to the present embodiment.
[0050] Referring to FIG. 3, the safety IO terminal 200 includes operation circuits 210 and 220 , storages 230 and 232 , a communication circuit 202 , a safety input circuit 204 , and a safety output circuit 206 .
[0051] The arithmetic circuits 210 and 220 execute programs (such as a system program 234 and safety logic 290) stored in the storages 230 and 232, respectively. The arithmetic results of the arithmetic circuits 210 and 220 are compared with each other. If the arithmetic results do not match, it is determined that some kind of abnormality has occurred.
[0052] The operational circuitry 210 includes a processor 212 and a memory 214. The operational circuitry 220 includes a processor 222 and a memory 224.
[0053] The processors 212 and 222 are configured by, for example, a CPU or a GPU. The memories 214 and 224 are configured by, for example, volatile storage devices such as DRAM and SRAM.
[0054] The storages 230 and 232 are configured by, for example, non-volatile storage devices such as ROM and EEPROM.
[0055] The system program 234 includes computer-readable instructions for providing an execution environment for the execution of the programs by the arithmetic circuits 210 and 220. The safety logic 290 defines the logical relationship between the safety input signal input to the safety input circuit 204 and / or the safety output value from the safety controller 100 and one or more safety output values. The safety logic 290 may be described using an OR circuit (logical sum) and an AND circuit (logical multiplication).
[0056] The communication circuit 202 is responsible for communication with other devices (such as the safety controller 100) via the network 2. The communication circuit 202 may have a memory unit for storing data received from the safety controller 100 (such as the safety output value).
[0057] The safety input circuit 204 receives safety input signals from one or more safety devices (e.g., a safety light curtain, a safety laser scanner, a safety door switch, a safety limit switch, a safety mat, an emergency stop push button switch, etc.) The safety input circuit 204 may have a different circuit configuration depending on the type of safety device.
[0058] The safety output circuit 206 outputs a safety output signal to one or more safety devices (for example, a safety relay, a safety drive, etc.) The safety output circuit 206 may have a different circuit configuration depending on the type of the safety device.
[0059] (b3: Other forms) In this specification, the term "processor" includes processing circuits that execute processing using stored programs, such as CPUs and GPUs, as well as dedicated hardware circuits with pre-programmed programs (e.g., ASICs (Application Specific Integrated Circuits) or FPGAs (Field-Programmable Gate Arrays)).
[0060] As used herein, the term "memory" includes non-volatile memory devices and volatile memory devices.
[0061] <C. Functional Configuration Example of Safety IO Terminal> Next, a functional configuration example of the safety IO terminal 200 according to this embodiment will be described.
[0062] FIG. 4 is a schematic diagram showing a functional configuration example of a safety IO terminal 200A according to the related art. Referring to FIG. 4, the safety IO terminal 200A includes a safety communication function 240A, a received data storage area 250A, and a safety output function 270A.
[0063] The safety communication function 240A is realized by the execution of a system program 234 by the communication circuit 202 (FIG. 3) and / or the arithmetic circuits 210 and 220.
[0064] The received data storage area 250A is realized by using the memory 214 of the arithmetic circuit 210 and the memory 224 of the arithmetic circuit 220. The received data storage area 250A may be realized by using a memory prepared in the communication circuit 202.
[0065] The safety output function 270A is realized by the execution of a system program 234 by the safety output circuit 206 (FIG. 3) and / or the arithmetic circuits 210 and 220.
[0066] In the functional configuration example shown in FIG. 4, a safety connection 10-1 is established between the safety controller 100-1 and the safety IO terminal 200. The safety connection 10-1 is, for example, based on the CIP Safety protocol.
[0067] Data (safety output data) transmitted from the safety controller 100-1 is stored in the received data storage area 250A. The received data storage area 250A directly controls the safety output signal from the safety IO terminal 200. That is, the safety output data stored in the received data storage area 250A is directly assigned to the safety output function 270A. For example, if the safety output data is byte data, the safety output function 270A determines that the value (True / False) of a pre-specified (pre-assigned) bit in the byte data is the safety output value as is. Then, the safety output function 270A outputs a safety output signal indicating the value of the pre-specified bit.
[0068] In the safety IO terminal 200A according to the related art, the received data storage area 250A is associated with only one safety connection, so that the safety IO terminal 200A cannot establish another safety connection 10-2 with the safety controller 100-2 while the safety connection 10-1 with the safety controller 100-1 has been established. In other words, the safety IO terminal 200A establishes an exclusive safety connection with the safety controller 100.
[0069] Therefore, the safety output function 270A of the safety IO terminal 200A cannot refer to the safety output data from a plurality of safety controllers 100 at the same time.
[0070] FIG. 5 is a schematic diagram showing an example of a functional configuration of a safety IO terminal 200 constituting the safety system 1 according to the present embodiment.
[0071] Referring to FIG. 5, the safety IO terminal 200 includes a safety communication function 240, a received data storage area 250, a safety logic function 260, a safety output function 270, and a connection history storage unit 280.
[0072] The safety communication function 240 corresponds to a safety communication unit, and is realized by execution of the system program 234 by the communication circuit 202 (FIG. 3) and / or the arithmetic circuits 210, 220. The safety communication function 240 can establish a safety connection with one or more safety controllers 100.
[0073] The received data storage area 250 corresponds to a received data storage unit, and is realized using the memory 214 of the arithmetic circuit 210 and the memory 224 of the arithmetic circuit 220. The received data storage area 250 may also be realized using a memory provided within the communication circuit 202.
[0074] The safety logic function 260 corresponds to a safety logic execution unit, and is realized by the execution of the system program 234 and the safety logic 290 by the arithmetic circuits 210 and 220 .
[0075] The safety output function 270 is realized by the execution of the system program 234 by the safety output circuit 206 (FIG. 3) and / or the arithmetic circuits 210 and 220.
[0076] The connection history storage unit 280 is realized using the storages 230 and 232 . 5, a safety connection 10-1 is established between a safety controller 100-1 and a safety IO terminal 200. A safety connection 10-2 is established between a safety controller 100-2 and a safety IO terminal 200. The safety connections 10-1 and 10-2 (hereinafter also collectively referred to as "safety connections 10") are based on, for example, the CIP Safety protocol.
[0077] The received data storage area 250 includes individual areas 252-1, 252-2, ... (hereinafter also collectively referred to as "individual areas 252") for storing data received by the safety communication function 240 for each safety connection 10. Unlike the received data storage area 250A (FIG. 4), the individual areas 252 do not directly control the safety output signal from the safety IO terminal 200. Each individual area 252 is associated with a safety connection 10. Each individual area 252 is a memory area for storing data (such as a safety output value) received from the safety controller 100 for each safety connection 10.
[0078] Each of the multiple individual areas 252 is configured to be associated with identification information for identifying the safety controller 100 that establishes a safety connection with the safety IO terminal 200. More specifically, the individual areas 252-1, 252-2, ... include areas for storing identification information 254-1, 254-2, ... (hereinafter also collectively referred to as "identification information 254") indicating which safety controller 100 the stored received data is associated with. The safety controllers 100-1, 100-2, ... have identification information 154-1, 154-2, ... (hereinafter also collectively referred to as "identification information 154"). For example, in the CIP Safety protocol, an "originator ID" can be adopted as the identification information 154, 254.
[0079] The safety logic function 260 determines the value of a safety output signal using any data stored in the individual areas 252-1, 252-2, .... More specifically, the safety logic function 260 includes an input process 262, a logic process 264, and an output process 266. The safety logic function 260 reflects the safety logic 290. The input process 262 includes a process for determining a safety input value from received data stored in one or more pre-specified individual areas 252. The logic process 264 includes a process for determining one or more safety output values based on one or more pre-specified safety input values. The output process 266 includes a process for providing the safety output value to the safety output function 270.
[0080] The one or more pieces of data (safety output values) referenced in input processing 262 may be specified by the user when creating safety logic 290. Safety logic 290 includes specification of values included in received data to be used as safety input values. Alternatively, a setting (data allocation) of data to be used as safety input values of safety logic 290 may be prepared separately from safety logic 290. The data setting may be stored in storage 230, 232 (FIG. 3).
[0081] In the safety logic 290 shown in FIG. 8 described below, the safety logic function 260 calculates a logical sum using as input the value indicated by the received data stored in the individual area 252-1 and the value indicated by the received data stored in the individual area 252-2.
[0082] In the safety logic 290 shown in FIG. 10 described below, the safety logic function 260 calculates a logical product of the value indicated by the received data stored in the individual area 252-1 and the value indicated by the received data stored in the individual area 252-2 as inputs.
[0083] The safety output function 270 outputs a safety output signal indicative of the safety output value output from the safety logic function 260 .
[0084] The connection history storage unit 280 corresponds to a storage unit, and stores an identification information list 282. The identification information list 282 includes identification information 254 associated with each individual area 252. When a safety connection 10 is established with a new safety controller 100, the identification information 154 of the safety controller 100 is associated with an individual area 252 that has not been associated with any identification information 254, and the associated identification information 154 (identification information 254) is added to the identification information list 282. In this way, once the identification information 254 is associated with each individual area 252 of the received data storage area 250, the association of the identification information 254 is maintained until initialization, reset, or the like is performed.
[0085] For example, in the factory default state, the identification information 254 of the individual area 252 of the safety IO terminal 200 indicates "null." The identification information 154 of the safety controller 100 that first established the safety connection 10 with each individual area 252 is stored.
[0086] When the secure IO terminal 200 is activated, the identification list 282 is referenced and the associated identification 254 is stored in the individual area 252 .
[0087] The command for the safety controller 100 to establish the safety connection 10 with the safety IO terminal 200 includes a specification of an individual area 252 to be used for storing the safety output data (received data). That is, to establish a safety connection, each of the one or more safety controllers 100 sends a request to the safety IO terminal 200, including the identification information 154 of each safety controller 100 and a specification of the individual area to be used (area specification 152).
[0088] The safety communication function 240 determines whether the identification information 254 associated with the individual area 252 specified by the command matches the identification information 154 of the safety controller 100 that sent the command. If the identification information 154 and the identification information 254 match, the safety communication function 240 allows the establishment of a safety connection, and does not allow it if they do not match.
[0089] By determining whether or not a safety connection can be established based on the identification information, even when the safety IO terminal 200 establishes safety connections 10 with multiple safety controllers 100, the safety controller 100 that sent the received data stored in the individual area 252 can be guaranteed.
[0090] In this way, the safety IO terminal 200 according to this embodiment can perform safety communication with multiple safety controllers 100. The safety IO terminal 200 can input any value of the data received from each of the multiple safety controllers 100 and perform logic processing 264.
[0091] <D. Communication Procedure between Safety Controller 100 and Safety IO Terminal 200> Next, an example of the communication procedure between the safety controller 100 and the safety IO terminal 200 will be described.
[0092] FIG. 6 is a sequence diagram showing an example of the communication procedure of the safety IO terminal 200 in the factory shipment state according to the present embodiment. FIG. 6 shows an example of the communication procedure when the safety IO terminal 200 establishes safety connections 10-1 and 10-2 with the safety controllers 100-1 and 100-2, respectively. The safety controllers 100-1 and 100-2 are assumed to be originators in the CIP Safety protocol.
[0093] In FIG. 6, the processing executed by the safety IO terminal 200 may be performed by the safety communication function 240 in FIG. 5.
[0094] Referring to FIG. 6, the originator safety controller 100-1 transmits a safety communication establishment command 150-1 to the safety IO terminal 200 according to the settings (sequence SQ10). The safety communication establishment command 150-1 includes the identification information 154-1 of the safety controller 100-1 and an area designation 152-1 for designating the individual area 252 (in this example, the individual area 252-1) used in the safety IO terminal 200.
[0095] When the safety IO terminal 200 receives the safety communication establishment command 150-1, it determines whether any identification information 254-1 is associated with the individual area 252-1 specified by the area specification 152-1. In the example shown in FIG. 6, the value of the identification information 254-1 associated with the individual area 252-1 is "empty." Therefore, the safety IO terminal 200 associates the identification information 154-1 included in the safety communication establishment command 150-1 with the individual area 252-1 (sequence SQ12). As a result, the value of the identification information 254-1 is changed from "empty" to "xxxx" (the identification information 154-1 of the safety controller 100-1). The safety IO terminal 200 stores the newly associated identification information 254-1 in the identification information list 282 (sequence SQ14). Then, the safety IO terminal 200 transmits an OK response to the safety controller 100-1 (sequence SQ16).
[0096] In this manner, if no identification information 254 is associated with the individual area 252 specified by the request, the safety IO terminal 200 (safety communication function 240 in FIG. 5) associates the identification information 154 included in the request with the individual area 252.
[0097] Through the above communication procedure, a safety connection 10-1 is established between the safety controller 100-1 and the safety IO terminal 200. Safety communication (transmission and reception of safety output data and safety input data) is repeatedly executed between the safety controller 100-1 and the safety IO terminal 200 (sequence SQ18).
[0098] Similarly, the safety controller 100-2, which is the originator, transmits a safety communication establishment command 150-2 to the safety IO terminal 200 in accordance with the settings (sequence SQ20). The safety communication establishment command 150-2 includes identification information 154-2 of the safety controller 100-2 and an area specification 152-2 for specifying the individual area 252 (in this example, the individual area 252-2) to be used in the safety IO terminal 200.
[0099] When the safety IO terminal 200 receives the safety communication establishment command 150-2, it determines whether any identification information 254-2 is associated with the individual area 252-2 specified by the area specification 152-2. In the example shown in FIG. 6, the value of the identification information 254-2 associated with the individual area 252-2 is "empty." Therefore, the safety IO terminal 200 associates the identification information 154-2 included in the safety communication establishment command 150-2 with the individual area 252-2 (sequence SQ22). As a result, the value of the identification information 254-2 is changed from "empty" to "yyyy" (the identification information 154-2 of the safety controller 100-2). The safety IO terminal 200 stores the newly associated identification information 254-2 in the identification information list 282 (sequence SQ24). Then, the safety IO terminal 200 transmits an OK response to the safety controller 100-1 (sequence SQ26).
[0100] Through the above communication procedure, a safety connection 10-2 is established between the safety controller 100-2 and the safety IO terminal 200. Safety communication (transmission and reception of safety output data and safety input data) is repeatedly executed between the safety controller 100-2 and the safety IO terminal 200 (sequence SQ28).
[0101] 7 is a sequence diagram showing an example of a communication procedure when the safety IO terminal 200 according to this embodiment is normally started. In FIG. 7, it is assumed that the safety IO terminal 200 has previously established safety connections 10-1 and 10-2 with the safety controllers 100-1 and 100-2, respectively. Therefore, the identification information list 282 stores the identification information of the safety controllers 100-1 and 100-2.
[0102] 7, the processing executed by the safety IO terminal 200 may be handled by the safety communication function 240 in FIG.
[0103] Furthermore, the safety controller 100-3 attempts to establish a safety connection with the safety IO terminal 200. It is assumed that the safety controllers 100-1, 100-2, and 100-3 are originators in the CIP Safety protocol.
[0104] 7, the safety controller 100-1, which is the originator, transmits a safety communication establishment command 150-1 to the safety IO terminal 200 in accordance with the settings (sequence SQ50). Upon receiving the safety communication establishment command 150-1, the safety IO terminal 200 determines whether or not the identification information 254-1 associated with the individual area 252-1 specified by the area specification 152-1 matches the identification information 154-1 included in the safety communication establishment command 150-1 (sequence SQ52).
[0105] If the identification information 254-1 associated with the individual area 252-1 matches the identification information 154-1 included in the safety communication establishment command 150-1, the safety IO terminal 200 transmits an OK response to the safety controller 100-1 (sequence SQ54). Through the above communication procedure, the safety connection 10-1 between the safety controller 100-1 and the safety IO terminal 200 is (re)established. Safety communication (transmission and reception of safety output data and safety input data) is repeatedly executed between the safety controller 100-1 and the safety IO terminal 200 (sequence SQ56).
[0106] In this manner, the safety IO terminal 200 (safety communication function 240 in FIG. 5) establishes a safety connection in accordance with the request if the identification information 254 associated with the individual area 252 specified by the request matches the identification information 154 included in the request.
[0107] Meanwhile, the safety controller 100-3, which is the originator, transmits a safety communication establishment command 150-3 to the safety IO terminal 200 in accordance with the settings (sequence SQ60). Upon receiving the safety communication establishment command 150-3, the safety IO terminal 200 determines whether the identification information 254-2 associated with the individual area 252-2 specified by the area specification 152-3 matches the identification information 154-3 included in the safety communication establishment command 150-3 (sequence SQ62).
[0108] If the identification information 254-2 associated with the individual area 252-2 does not match the identification information 154-3 included in the safety communication establishment command 150-3, the safety IO terminal 200 transmits an NG response to the safety controller 100-3 (sequence SQ64). Through the above communication procedure, the safety connection 10 is not established between the safety controller 100-3 and the safety IO terminal 200.
[0109] Furthermore, the safety controller 100-2, which is the originator, transmits a safety communication establishment command 150-2 to the safety IO terminal 200 in accordance with the settings (sequence SQ70). Upon receiving the safety communication establishment command 150-2, the safety IO terminal 200 determines whether the identification information 254-2 associated with the individual area 252-2 specified by the area specification 152-2 matches the identification information 154-2 included in the safety communication establishment command 150-2 (sequence SQ72).
[0110] If the identification information 254-2 associated with the individual area 252-2 matches the identification information 154-2 included in the safety communication establishment command 150-2, the safety IO terminal 200 sends an OK response to the safety controller 100-2 (sequence SQ74). Through the above communication procedure, the safety connection 10-2 between the safety controller 100-2 and the safety IO terminal 200 is (re)established. Safety communication (transmission and reception of safety output data and safety input data) is repeatedly executed between the safety controller 100-2 and the safety IO terminal 200 (sequence SQ76).
[0111] <E. Application Example> Next, an example of an application using the safety IO terminal 200 according to this embodiment will be described.
[0112] (e1: Conveyor Robot) First, a safety system using a conveyor robot 300 equipped with a safety IO terminal 200 will be described.
[0113] FIG. 8 is a schematic diagram showing a configuration example of a safety system 1A using a conveyor robot 300 equipped with a safety IO terminal 200 according to this embodiment. Referring to FIG. 8, the safety system 1A includes safety controllers 100-1 and 100-2, and a conveyor robot 300 equipped with a safety IO terminal 200.
[0114] The safety controller 100-1 is connected to a wireless repeater 180-1. When the conveyor robot 300 is present in zone 1, the safety controller 100-1 establishes a safety connection with the safety IO terminal 200 through a wireless connection.
[0115] Similarly, the safety controller 100-2 is connected to a wireless repeater 180-2. When the conveyor robot 300 is present in zone 2, the safety controller 100-2 establishes a safety connection with the safety IO terminal 200 through a wireless connection.
[0116] In the safety system 1A, even when the conveyor robot 300 travels between zone 1 and zone 2, it is necessary for at least one of the safety controllers 100-1 and 100-2 to manage the safety IO terminal 200.
[0117] Normally, the safety output signal of the safety IO terminal 200 indicates True (ON) under normal conditions in accordance with the safety output value from the safety controller 100. Therefore, if the safety connection between the safety controller 100 and the safety IO terminal 200 is disconnected and the safety IO terminal 200 cannot receive the safety output value from the safety controller 100, the safety output signal of the safety IO terminal 200 indicates False (OFF). In other words, the safety output signal is blocked. As a result, an instruction to perform a safe operation (usually, to stop) is given to the transport robot 300 and / or the devices mounted on the transport robot 300.
[0118] The safety IO terminal 200 according to this embodiment can establish safety connections in parallel with multiple safety controllers 100. More specifically, when the transfer robot 300 is present in zone 1, the safety IO terminal 200 can receive safety output data from the safety controller 100-1, and when the transfer robot 300 is present in zone 2, the safety IO terminal 200 can receive safety output data from the safety controller 100-2.
[0119] Therefore, by configuring the safety IO terminal 200 with a safety logic 290 including an OR circuit (logical sum) of the safety output data from the safety controller 100-1 and the safety output data from the safety controller 100-2, it is possible to prevent the safety output signal from being blocked regardless of which zone the transport robot 300 is in.
[0120] 8 shows an example of safety logic 290 that outputs the logical sum of the value of the first bit of received data 291 (safety output data) received from safety controller 100-1 and the value of the first bit of received data 292 (safety output data) received from safety controller 100-2 as safety output value 293. By employing such safety logic 290, it is possible to continue outputting a safety output signal.
[0121] Fig. 9 is a flowchart showing an example of an operation procedure of the safety system 1A shown in Fig. 8. Referring to Fig. 9, the user provides the safety controllers 100-1 and 100-2 with settings for establishing a safety connection with the safety IO terminal 200 (step S2). The user provides the safety IO terminal 200 with settings for the safety logic 290 (step S4).
[0122] For example, the user places the transfer robot 300 in area 1 (step S6). Then, the user starts up the safety controllers 100-1 and 100-2 and the safety IO terminal 200, and sets them to a normal operating state (step S8).
[0123] The safety controller 100-1 establishes a safety connection with the safety IO terminal 200 mounted on the transfer robot 300 (step S10). The safety IO terminal 200 outputs a safety output signal based on the received data 291 (safety output data) received from the safety controller 100-1 (step S12).
[0124] Subsequently, when the transfer robot 300 moves to area 2 (YES in step S14), the safety connection between the safety controller 100-1 and the safety IO terminal 200 is disconnected (step S16). Meanwhile, the safety controller 100-2 establishes a safety connection with the safety IO terminal 200 (step S18). The safety IO terminal 200 outputs a safety output signal based on the received data 292 (safety output data) received from the safety controller 100-2 (step S20).
[0125] Furthermore, when the transfer robot 300 moves to area 1 (YES in step S22), the safety connection between the safety controller 100-2 and the safety IO terminal 200 is cut off (step S24), and the processing from step S10 onwards is repeated.
[0126] (e2: Safety control across multiple zones) Next, an example of safety control across multiple zones will be described.
[0127] 10 is a schematic diagram showing an example of the configuration of a safety system 1B that enables inter-zone safety control according to this embodiment. Referring to FIG. 10, the safety system 1B includes safety controllers 100-1 and 100-2 and a safety IO terminal 200 that are connected to each other via a network 2.
[0128] The safety IO terminal 200 is connected to a safety device (for example, a safety relay 40 or a light curtain) for stopping equipment that spans zone 1 and zone 2. The safety controller 100-1 is connected to an emergency stop switch 30-1 as a safety device. The safety controller 100-2 is connected to an emergency stop switch 30-2 as a safety device.
[0129] In the safety system 1B, the safety relay 40 can stop the equipment when either the emergency stop switch 30-1 or the emergency stop switch 30-2 is pressed.
[0130] In the safety IO terminal 200, by configuring a safety logic 290 including an AND circuit (logical product) of the safety output data from the safety controller 100-1 and the safety output data from the safety controller 100-2, the safety relay 40 can be shut off regardless of whether the emergency stop switch 30-1 or the emergency stop switch 30-2 is pressed.
[0131] The example shown in Figure 10 shows an example of safety logic 290 that outputs as a safety output value 293 the logical product of the value of the first bit of received data 291 (safety output data) received from the safety controller 100-1 and the value of the first bit of received data 292 (safety output data) received from the safety controller 100-2.
[0132] In this way, the safety IO terminal 200 according to this embodiment can easily achieve safety control across a plurality of zones.
[0133] <F. Safety Controller and Safety IO Terminal> The above-described safety controller 100 and safety IO terminal 200 will be described by comparison.
[0134] FIG. 11 is a diagram for comparing the features of the devices constituting the safety system 1 according to the present embodiment. In FIG. 11, for each of the safety controller 100 and the safety IO terminal 200, descriptions of items such as safety connection, number of connections, safety control, and cost are shown.
[0135] Regarding the safety connection, the safety controller 100 is an originator in the CIP Safety protocol. In contrast, the safety IO terminal 200 is a target in the CIP Safety protocol.
[0136] Regarding the number of connections, the safety controller 100 can establish a relatively large number of connections simultaneously, whereas the number of connections that the safety IO terminal 200 can establish simultaneously is relatively small. [[ID=,17]]
[0137] Regarding safety control, in the safety controller 100, any safety program can be created, whereas in the safety IO terminal 200, a small-scale safety logic can be created. Note that the safety logic available in the safety IO terminal 200 may only be those prepared in advance and may not be added or changed by the user.
[0138] Regarding cost, the safety controller 100 requires a relatively high-performance processor and a relatively large-capacity memory and is expensive, whereas the safety IO terminal 200 often has a minimum required processor and memory implemented.
[0139] <G. Modification Example> In the above description, a configuration example in which the safety IO terminal 200 establishes a safety connection with two safety controllers 100 is shown, but it may establish a safety connection with more safety controllers 100. In that case, the safety output values from three or more safety controllers may be input to an OR circuit (logical sum) and / or an AND circuit (logical product).
[0140] <H. Supplementary Note> The present embodiment as described above includes the following technical ideas.
[0141] [Configuration 1] A safety IO terminal (200), A safety output circuit (206) that outputs a safety output signal, A safety communication unit (240) capable of establishing a safety connection with one or more safety controllers (100), A received data storage unit (250) including a plurality of individual areas (252) for storing the data received by the safety communication unit separately for each safety connection, A safety logic execution unit (260) that determines the value of the safety output signal using any data stored in the plurality of individual areas, and Each of the plurality of individual areas is configured to be associated with identification information (254) for identifying a safety controller that establishes a safety connection with the safety IO terminal, a safety IO terminal.
[0142] [Configuration 2] Each of the one or more safety controllers transmits a request (150) including the identification information (154) of the safety controller and the designation (152) of the individual area to be used to the safety IO terminal in order to establish a safety connection, the safety IO terminal according to Configuration 1.
[0143] [Configuration 3] 3. The safety IO terminal of claim 2, wherein if no identification information is associated with the individual area specified by the request, the safety communication unit associates the identification information included in the request with the individual area (SQ12, SQ14, SQ22, SQ24).
[0144] [Configuration 4] The safety IO terminal according to configuration 2, wherein the safety communication unit establishes a safety connection in accordance with the request if identification information associated with the individual area specified by the request matches identification information included in the request (SQ52, SQ54, SQ72, SQ74).
[0145] [Configuration 5] 5. The secure IO terminal of any one of configurations 1 to 4, further comprising a storage unit (280) for storing an identification information list (282) including identification information associated with each individual area.
[0146] [Configuration 6] The safety IO terminal according to any one of configurations 1 to 5, wherein the safety logic execution unit calculates a logical sum using as input a value indicated by first data stored in a first individual area (252-1) among the plurality of individual areas and a value indicated by second data stored in a second individual area (252-2) among the plurality of individual areas.
[0147] [Configuration 7] The safety IO terminal according to any one of configurations 1 to 6, wherein the safety logic execution unit calculates a logical product of a value indicated by first data stored in a first individual area (252-1) among the plurality of individual areas and a value indicated by second data stored in a second individual area (252-2) among the plurality of individual areas as inputs.
[0148] [Configuration 8] 8. The safety IO terminal according to any one of configurations 1 to 7, wherein the safety connection is established based on at least one of CIP Safety and PROFIsafe.
[0149] [Configuration 9] A safety IO terminal (200) and one or more safety controllers (100) capable of executing a safety program (134) based on safety input data received from the safety IO terminal, wherein the safety IO terminal includes a safety input circuit (204) for receiving a safety input signal, a safety output circuit (206) for outputting a safety output signal, a safety communication unit (240) capable of establishing a safety connection with one or more safety controllers, a received data storage unit (250) including a plurality of individual areas (2,52) for storing data received by the safety communication unit separately for each safety connection, and a safety logic execution unit (No. 260) for determining the value of a safety output signal using any data stored in the plurality of individual areas, where each of the plurality of individual areas is configured to store identification information (254) for identifying a safety controller that establishes a safety connection with the safety IO terminal, a safety system.
[0150] <I. Advantages> The safety IO terminal according to the present embodiment can establish a safety connection with each of a plurality of safety controllers and store data received from each safety controller in an individual area. Moreover, the safety IO terminal can execute safety logic using any data stored in the individual area. As a result, safety logic using data from a plurality of safety controllers can be configured according to an application.
[0151] The embodiments disclosed this time should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is shown not by the above description but by the claims, and it is intended that all modifications within the meaning and scope equivalent to the claims are included. 1,1A,1B Safety system, 2 Network, 10 Safety connection, 30 Emergency stop switch, 40 Safety relay, 100 Safety controller, 102,202 Communication circuit, 104 Internal bus circuit, 106 Memory card interface, 108 Memory card, 110,120,210,220 Calculation circuit, 112,122,212,222 Processor, 114,124,214,224 Memory, 130,140,230,232 Storage, 132,234 System program, 134 Safety program, 150 Safety communication establishment command, 152 Area designation, 154,254 Identification information, 180 Wireless repeater, 200,200A Safety IO terminal, 204 Safety input circuit, 206 Safety output circuit, 240,240A Safety communication function, 250, 250A received data storage area, 252 individual area, 260 safety logic function, 262 input processing, 264 logic processing, 266 output processing, 270, 270A safety output function, 280 connection history storage section, 282 identification information list, 290 safety logic, 291, 292 received data, 300 transport robot.
Claims
1. A safety IO terminal, a safety output circuit that outputs a safety output signal; a safety communication unit capable of establishing a safety connection with one or more safety controllers; a received data storage unit including a plurality of individual areas for storing data received by the safety communication unit for each safety connection; a safety logic execution unit that determines a value of a safety output signal using any data stored in the plurality of individual areas; A safety IO terminal configured such that each of the plurality of individual areas is associated with identification information for identifying a safety controller that establishes a safety connection with the safety IO terminal.
2. The safety IO terminal of claim 1 , wherein each of the one or more safety controllers sends a request to the safety IO terminal to establish a safety connection, the request including identification information of the safety controller and a designation of an individual area to be used.
3. The safety IO terminal according to claim 2 , wherein the safety communication unit associates the identification information included in the request with the individual area if no identification information is associated with the individual area specified by the request.
4. The safety IO terminal according to claim 2 , wherein the safety communication unit establishes a safety connection in accordance with the request if identification information associated with the individual area specified by the request matches identification information included in the request.
5. The secure IO terminal according to any one of claims 1 to 4, further comprising a storage unit for storing an identification information list including identification information associated with each individual area.
6. The safety IO terminal according to any one of claims 1 to 4, wherein the safety logic execution unit calculates a logical sum of a value indicated by first data stored in a first individual area among the plurality of individual areas and a value indicated by second data stored in a second individual area among the plurality of individual areas.
7. The safety IO terminal according to any one of claims 1 to 4, wherein the safety logic execution unit calculates a logical product of a value indicated by first data stored in a first individual area among the plurality of individual areas and a value indicated by second data stored in a second individual area among the plurality of individual areas.
8. 5. The safety IO terminal according to claim 1, wherein the safety connection is established based on at least one of CIP Safety and PROFIsafe.
9. A safety IO terminal, one or more safety controllers capable of executing a safety program based on safety input data received from the safety IO terminal; The safety IO terminal is a safety input circuit that receives a safety input signal; a safety output circuit that outputs a safety output signal; a safety communication unit capable of establishing a safety connection with one or more safety controllers; a received data storage unit including a plurality of individual areas for storing data received by the safety communication unit for each safety connection; a safety logic execution unit that determines a value of a safety output signal using any data stored in the plurality of individual areas; A safety system, wherein each of the plurality of individual areas is configured to store identification information for identifying a safety controller that establishes a safety connection with the safety IO terminal.
Citation Information
Patent Citations
Safety slave unit, control method thereof, control program thereof, and safety control system
JP2014098985A