Remote safety input / output device
The remote safety input/output device simplifies safety program updates by using a web server and rotary switch, addressing the need for additional interfaces in existing devices and ensuring program integrity.
Patent Information
- Application Number
- JP2024040737
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-15
- Publication Date
- 2025-09-29
AI Technical Summary
Existing safety control devices require additional hardware and software interfaces for programming, necessitating unfamiliar operations by users.
A remote safety input/output device with a memory unit, instruction acquisition unit, and program management unit that allows safety program updates via a web server, enabling easy storage and deletion of safety programs without dedicated hardware or software, and includes a rotary switch for specifying code areas.
Facilitates easy and secure updating of safety programs, ensuring compatibility and integrity through CRC checks, reducing the need for complex user interactions.
Smart Images

Figure 2025141024000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a remote safety input / output device. [Background technology]
[0002] To safely operate the machines used in many manufacturing sites, safety devices (safety components) that comply with international standards must be used. The purpose of this safety device is to prevent human safety from being threatened by automatically moving devices such as robots. Such safety devices include safety controllers that execute safety programs, detection devices that detect the presence or intrusion of people, input devices that accept emergency operations, and output devices that actually stop the equipment.
[0003] As one technique for ensuring safety at manufacturing sites, for example, in Japanese Patent Laid-Open Publication No. 2011-181072 (Patent Document 1), a safety control device has an interface for inputting numeric codes, and the programming of the safety control device itself is realized by inputting these numeric codes. This interface is composed of a key operation unit (keypad, keyboard, etc.). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2011-181072 Summary of the Invention [Problem to be solved by the invention]
[0005] In Patent Document 1, the safety control device requires the addition and implementation of a special interface (hardware and software for realizing the interface) for inputting numerical codes in order to program the safety control device, and the user is also required to perform unfamiliar operations such as operating a key operation unit provided on the safety control device.
[0006] Therefore, there is a need to provide a remote safety input / output device that allows for easier updating of safety programs. [Means for solving the problem]
[0007] The remote safety input / output device according to the present disclosure includes a memory unit for storing a safety program that determines the value of an output signal for operating an output device so as to maintain safety when a predetermined condition is met for the value of an input signal received from an input device, an instruction acquisition unit that acquires user instructions for the remote safety input / output device, and a program management unit that updates the safety program in the memory unit in accordance with the user instructions acquired by the instruction acquisition unit.
[0008] According to the above disclosure, the safety program in the storage unit can be easily updated by using the user instructions acquired by the instruction acquisition unit.
[0009] In the above disclosure, the instruction acquisition unit includes a web server that acquires user instructions from a web browser.
[0010] According to the above disclosure, the storage of the safety program in the memory unit can be realized by using a Web server without implementing dedicated hardware or software in the remote safety input / output device.
[0011] In the above disclosure, the above update includes storing or deleting a safety program, and when the remote safety input / output device stores the safety program in the memory unit, it detects that the unique attributes obtained for the program code of the safety program before storage match the unique attributes obtained for the program code of the safety program after storage.
[0012] According to the above disclosure, when a safety program is stored in a storage unit, it is possible to detect whether the unique attributes of the program code of the safety program before and after storage match, thereby detecting whether the program code of the safety program has been changed between when the safety program was acquired (for example, when it was transferred to a remote safety input / output device) and when it was stored.
[0013] In the above disclosure, the storage unit has, for a safety program, a code area for storing the program code of the safety program, and an attribute area for storing the unique attribute of the program code.
[0014] According to the above disclosure, the program code and its unique attributes of the safety program can be managed independently in the memory unit, so that even if the program code is unintentionally changed in the memory unit, the possibility of the change affecting the unique attributes can be reduced.
[0015] In the above disclosure, the unique attribute includes a value calculated by a predetermined operation on the program code of the safety program, and when the safety program stored in the memory unit is started, a value is calculated by the above-mentioned predetermined operation on the program code in the code area, and it is detected that the calculated value matches the value included in the unique attribute stored in the attribute area.
[0016] According to the disclosure above, when the remote safety input / output device starts a safety program in a storage unit, it detects whether the value of the unique attribute acquired when the safety program was stored matches the value of the unique attribute calculated at the time of subsequent startup, thereby making it possible to detect whether the program code of the safety program has been changed between storage and startup.
[0017] In the above disclosure, the storage unit has a plurality of code areas, and the web server transfers to the web browser a web page that indicates, for each code area, information indicating whether or not program code has been stored in that code area.
[0018] According to the above disclosure, a screen based on information on a web page can be presented to a user via a web browser, and the user can easily identify, from the information displayed on the screen, a code area in the storage unit that does not store program code.
[0019] In the above disclosure, the user instruction includes designation of a code area, among a plurality of code areas, for storing a safety program.
[0020] According to the above disclosure, the user can specify a code area identified from the information on the screen in which no program code is stored as a code area for storing a safety program.
[0021] In the above disclosure, the remote safety input / output device further includes a rotary switch, and receives designation of a code area for storing a safety program based on a user operation of the rotary switch.
[0022] According to the above disclosure, the user can specify a code area for storing a safety program from among a plurality of code areas by operating a rotary switch.
[0023] In the above disclosure, the remote safety input / output device further includes a network interface that connects to a network to which the safety controller belongs and a communication interface that connects to a network for communicating with a web browser, and the safety program includes a remote safety program that determines the value of an output signal for operating an output device so as to maintain safety in accordance with a control signal transferred from the safety controller.
[0024] According to the above disclosure, the remote safety input / output device can implement both an operating mode in which an output device is operated to maintain safety in accordance with a control signal from a safety controller, and an operating mode in which an output device is operated to maintain safety in accordance with an input signal from an input device. [Effects of the Invention]
[0025] According to the present disclosure, it is possible to provide a remote safety input / output device that allows a safety program to be easily updated. [Brief explanation of the drawings]
[0026] [Figure 1] 1 is a diagram illustrating a configuration of a safety IO unit according to an embodiment of the present invention in association with peripheral devices. [Figure 2] FIG. 1 is a diagram illustrating an example of a system configuration of a safety system. [Figure 3] FIG. 2 is a schematic diagram showing an example of a device configuration of a safety controller according to the present embodiment. [Figure 4] FIG. 1 is a schematic diagram showing an example of a hardware configuration of an information processing device according to an embodiment of the present invention. [Figure 5] 1 is a diagram illustrating a network including a safety IO unit and a safety controller according to an embodiment of the present invention. [Figure 6] FIG. 2 is a diagram illustrating a hardware configuration of a safety IO unit according to the present embodiment. [Figure 7] 7 is a diagram schematically illustrating an example of information stored in a storage unit in FIG. 6. FIG. [Figure 8] FIG. 8 is a diagram showing an example of the configuration of the areas in FIG. 7. [Figure 9] FIG. 2 is a diagram schematically illustrating a software configuration of the safety IO unit according to the present embodiment. [Figure 10] FIG. 3 is a diagram showing an example of a web screen displayed on a display according to the present embodiment. [Figure 11] FIG. 3 is a diagram showing an example of a web screen displayed on a display according to the present embodiment. [Figure 12] FIG. 3 is a diagram showing an example of a web screen displayed on a display according to the present embodiment. [Figure 13] 10 is an example of a flowchart of a storage process of a safety program according to the present embodiment. [Figure 14]This is an example of a flowchart for storing a safety program according to the present embodiment. [Figure 15] This is a diagram showing an example of a Web screen displayed on a display according to the present embodiment. [Figure 16] This is a diagram showing an example of a Web screen displayed on a display according to the present embodiment. [Figure 17] This is a diagram showing an example of a Web screen displayed on a display according to the present embodiment. [Figure 18] This is an example of a flowchart for deleting a safety program according to the present embodiment. [Figure 19] This is a flowchart showing the processing when the safety I / O unit of the present embodiment is powered on.
Embodiments for Carrying Out the Invention
[0027] Hereinafter, each embodiment according to the present invention will be described while referring to the drawings. In the following description, the same parts and components are denoted by the same reference numerals. Their names and functions are also the same. Therefore, detailed descriptions thereof will not be repeated. Note that the embodiments and each modification described below may be selectively combined as appropriate.
[0028] <A. Application Example> First, an example of a scene to which the present invention is applied will be described. In this specification, the remote safety input / output device is described as the safety I / O (Input / Output) unit 20. FIG. 1 is a diagram showing the configuration of the safety I / O unit 20 according to the present embodiment in association with peripheral devices.
[0029] Referring to FIG. 1, the safety I / O unit 20 includes a storage unit 32 configured to include a non-volatile storage device for storing a safety program, a Web server 31, a program management unit 33 for managing the safety program in the storage unit 32, and a rotary switch 24. The Web server 31 is an example of an instruction acquisition unit that acquires user instructions for the safety I / O unit 20.
[0030] The storage unit 32 in FIG. 1 stores safety programs for a plurality of types of operation modes indicated by, for example, safety programs 30(0) to 30(XX). The operation mode of the safety IO unit 20 indicates a mode in which the output device 60 is operated so as to maintain safety. In this embodiment, a safety program 30 is executed for each operation mode. In the following, explanations common to the safety programs 30(0) to 30(XX) will be collectively referred to as the safety program 30. When executed by the safety IO unit 20, the safety program 30 determines the value of an output signal for operating the output device 60 so as to maintain safety when a predetermined condition (safety condition) is established for the value of an input signal received from the input device 50.
[0031] The input device 50 includes a safety sensor, a safety door switch, a safety limit switch, an emergency stop switch, a safety switch, etc. The output device 60 is a device that is driven in conjunction with an operation on the input device 50. The output device 60 includes, for example, a safety relay that drives a contactor to cut off an electric circuit that supplies power to a controlled object. In addition, a danger area is set around a device driven by a motor, and the input device 50 is placed around the danger area. The input device 50 includes, for example, a detection device that detects the presence or intrusion of a person, and an input device that accepts operations in an emergency. The safety relay is driven by receiving an input signal from such an input device 50.
[0032] When updating the safety program 30, the web server 31 communicates with a web browser 222 installed in the information processing device 200. The information processing device 200 is, for example, a personal computer (PC), a tablet terminal, a smartphone, or other communication terminal.
[0033] More specifically, the safety IO unit 20 communicates with the information processing device 200 by using an Ethernet (registered trademark) port (not shown) built into the safety IO unit 20. In this Ethernet-based communication, the Web server 31 causes the Web browser 222 to display a screen of a Web page based on the information from the Web server 31 on the GUI (Graphical User Interface) of the Web browser 222, and receives a user instruction indicated by a user operation on the Web page from the Web browser 222. The program management unit 33 stores the safety program 30 in the storage unit 32 or deletes the safety program 30 from the storage unit 32 according to the user instruction acquired by the Web server 31.
[0034] The rotary switch 24 is operated to specify the safety program 30 to be started from among a plurality of types of safety programs 30 stored in the storage unit 32.
[0035] As described above, in the present embodiment, the update (storage and deletion) of the safety program 30 in the storage unit 32 can be easily realized in the safety IO unit 20 without implementing dedicated hardware or software by using the Web server 31.
[0036] <B. Safety Program> In this specification, the safety program 30 provides some safety functions related to a drive device, such as STO (Safe Torque Off), SS1 (Safe Stop 1), SS2 (Safe Stop 2), and SOS (Safe Operating Stop) defined in IEC61800-5-2.
[0037] The safety program 30 includes a combination of instructions for determining the values of one or more output signals with respect to one or more input signals. The safety program 30 may be one or more source codes, one or more object codes, or in a form (execution form) executable by the processor of the safety IO unit 20.
[0038] In addition, the safety program 30 may be described using a function block diagram (FBD: Function Block Diagram). Alternatively, it may be described using any one of a ladder diagram (LD: Ladder Diagram), an instruction list (IL: Instruction List), structured text (ST: Structured Text), and a sequential function chart (SFC: Sequential Function Chart), or a combination thereof. Furthermore, it may be described using a general-purpose programming language such as JavaScript (registered trademark) or the C language.
[0039] Note that it is preferable to create the safety program 30 in accordance with the regulations published by PLCopen (registered trademark), a third-party organization that conducts activities for the popularization of the international standard IEC 61131-3 (JIS B 3503) for PLC (Programmable Logic Controller) programming and formulates and certifies the specifications of standard function block diagrams independent of vendors, in technical committee 5.
[0040] In the following description, the safety program 30 described as a variable program will be exemplified. Therefore, signals (typically, input signals and output signals) actually exchanged between the safety I / O unit 20 and safety components (input device 50 or output device 60) and the like will be treated as "variables" within the safety program 30, respectively. Since these actual signals and the corresponding variables within the safety program 30 are essentially the same, in the following description, these "signals" can be treated not only as the actual electrical signals being exchanged but also as the values (values referred to by variables) assigned to those electrical signals on the safety I / O unit 20.
[0041] <C. System Configuration> Next, a safety system including the safety IO unit 20 according to this embodiment will be described. Fig. 2 is a diagram showing an example of the system configuration of the safety system 1.
[0042] 2, a safety system 1 is applied to, for example, factory automation (FA) of a production line. The safety system 1 mainly includes a safety controller 100, an information processing device 200 having a display 211, a control device 300 that controls equipment, machinery, etc., and a safety IO unit 20. Although the safety system 1 in FIG. 2 includes a plurality of safety IO units 20, the number of safety IO units 20 may be one or more.
[0043] The control device 300 is typically configured with a PLC or the like, and executes a predetermined user program on input data acquired from a control target, and issues commands to the control target according to output data calculated thereby. In FIG. 2, a motor 510 and a driver 512 that drives the motor 510 are exemplified as the control target. In accordance with the user program, when a certain drive start condition is met, the control device 300 outputs a drive command to the driver 512 to drive the motor 510 in rotation. Furthermore, when a certain drive stop condition is met, the control device 300 stops outputting the drive command to the driver 512 to stop the motor 510 in rotation.
[0044] In addition to the control of the controlled object by such control device 300, a safety controller 100 is typically further provided to ensure the safety of workers and others associated with the controlled object. When a predetermined condition (safety condition) associated with an input signal from input device 400 (such as a safety sensor, a safety door switch, a safety limit switch, an emergency stop switch, or a safety switch) serving as a safety device is met, safety controller 100 outputs an output signal (control signal) to safety relay 514, an example of an output device, for operating to maintain safety. Safety relay 514 operates in response to the output signal from safety controller 100 and cuts off the power supply to driver 512 that drives motor 510. As a result, motor 510 is forcibly stopped.
[0045] The safety controller 100 also remotely controls the safety IO unit 20. The safety IO unit 20 has a remote operation mode as an operation mode in which it executes a safety program 30(0) (see FIG. 1) of an emergency stop application. In the remote operation mode, the safety IO unit 20 determines that a predetermined condition (safety condition) is met upon receiving a control signal from the safety controller 100, determines the value of an output signal for operating the output device 60 so as to maintain safety, and transfers the control signal to another safety IO unit 20. The safety program 30(0) of the emergency stop application is a remote safety program that enables the safety controller 100 to remotely control the output device 60 (or the safety IO unit 20).
[0046] For example, the safety controller 100 outputs a control signal to a predetermined safety IO unit 20 among the multiple safety IO units 20 in response to a detection signal from a safety sensor, which is an input device 400. The predetermined safety IO unit 20 implements the remote operation mode in response to receiving the control signal from the safety controller 100, and the other safety IO units 20 also implement the remote operation mode in response to receiving the control signal transferred from the predetermined safety IO unit 20. As a result, the output device 60 (safety relay) connected to each safety IO unit 20 receives an output signal for safe operation, and the motor associated with the safety relay is forcibly stopped. This forcible stopping of the motor ensures the safety of workers who enter a hazardous area.
[0047] In the safety IO unit 20, the priority of execution of the safety program 30(0) in the above-described remote operation mode is higher than the priority of execution of the safety programs 30(1) to (XX) in other types of operation modes. Therefore, in the safety IO unit 20, a remote operation mode in which a control signal from the safety controller 100 is processed with priority over an input signal from an input device 50 connected to the safety IO unit 20, and an operation mode (non-remote operation mode) in which an output signal determined based on the value of the input signal from the input device 50 is output to the output device 60 can be implemented in one safety IO unit 20.
[0048] In the configuration example shown in FIG. 2, the safety controller 100, the control device 300, and the safety I / O unit 20 are connected via the control network NW1 and can exchange data held internally by each other. Further, the safety controller 100, the control device 300, and the safety I / O unit 20 are connected to the information processing device 200 via the information network NW2. As the control network NW1 to which the safety controller 100, the control device 300, and the safety I / O unit 20 belong, for example, a network protocol that guarantees timing such as EtherCAT (registered trademark) is preferable. The information network NW2 to which the information processing device 200 belongs may adopt Ethernet, which is a general network protocol, or EtherNet / IP (registered trademark).
[0049] The information processing device 200 is a support tool for providing functions such as management of programs executed by the safety controller 100, the control device 300, and the safety I / O unit 20, program development, confirmation of the execution state of programs, and program modification.
[0050] <D. Device Configuration> Next, referring to FIGS. 3 and 4, the device configuration of each device constituting the safety system 1 according to the present embodiment will be described.
[0051] (d1: Safety Controller 100) FIG. 3 is a schematic diagram showing an example of the device configuration of the safety controller 100 according to the present embodiment. Referring to FIG. 3, the safety controller 100 includes an arithmetic processing unit 108 including a processor 102, a main memory 104, and a flash memory 106, and various interfaces.
[0052] In the arithmetic processing unit 108, the processor 102 expands and executes a system program, a safety program, etc. stored in the flash memory 106 in the main memory 104 to realize functional safety according to the control target.
[0053] The safety controller 100 includes, as interfaces, a control network interface 110, an information network interface 112, a field bus interface 114, a memory card interface 116, a local communication interface 120, and an internal bus interface 122.
[0054] The control network interface 110 mediates communication with other devices via the control network NW1 (see FIG. 2). The information network interface 112 mediates communication with other devices via the information network NW2 (see FIG. 2).
[0055] The fieldbus interface 114 mediates communication with an input / output unit connected via a fieldbus (not shown). As the fieldbus, a network protocol that guarantees punctuality, such as EtherCAT (registered trademark), EtherNet / IP (registered trademark), DeviceNet (registered trademark), or CompoNet (registered trademark), is preferred.
[0056] The memory card interface 116 is configured to allow a memory card 118 to be inserted therein, and reads and writes data from and to the memory card 118 .
[0057] The local communication interface 120 is an interface for directly connecting to the information processing device 200 or other devices, and uses, for example, a USB (Universal Serial Bus).
[0058] The internal bus interface 122 mediates communication between the safety controller 100 and an input / output unit directly attached thereto via the internal bus.
[0059] (d2: information processing device 200) Next, an example of a hardware configuration of information processing device 200 will be described. Fig. 4 is a schematic diagram showing an example of a hardware configuration of information processing device 200 according to the present embodiment.
[0060] The information processing device 200 may be a portable terminal such as a notebook PC, a tablet terminal, or a smartphone, or may be a non-portable terminal such as a desktop PC.
[0061] The information processing device 200 includes, as its main components, a processor 202 that executes a system program 224 including an operating system (OS) and various programs as described below, a main memory 204 that provides a work area for storing data necessary for the program execution by the processor 202, an operation unit 206 that accepts user operations such as a keyboard or a mouse, an output unit 208 that outputs processing results such as a display 211, various indicators, and a printer, an information network NW2 and a network interface 210 for communicating with the information network NW2, an optical drive 212 to which an optical recording medium (for example, a DVD (Digital Versatile Disc)) 214 is removably attached, a local communication interface 216 for communicating with the safety controller 100 and the like, and an auxiliary storage device 220. These components are connected to each other so as to be able to communicate data with each other via an internal bus 218 or the like.
[0062] The auxiliary storage device 220 is composed of, for example, an HDD (Hard Disk Drive), an SSD (Flash Solid State Drive), etc., and stores programs executed by the processor 202. Specifically, the auxiliary storage device 220 stores a system program 226 including an OS (Operating System), one or more safety programs 30, and application programs. The application programs include programs for managing programs executed by the safety controller 100, the control device 300, and the safety IO unit 20, developing various programs including the safety program 30, checking the execution state of the programs, changing the programs, etc., and support tool programs for providing such functions. In the auxiliary storage device 220, each of the one or more safety programs 30 is stored as a binary file including executable code. A number for identifying the safety program is assigned to the binary file. In the present embodiment, the support tool program includes a program 227 of a Web browser 222 having a GUI.
[0063] (d3: Control device 300) The control device 300 according to the present embodiment has the same device configuration as the safety controller 100 shown in FIG. 3, and thus detailed description will not be repeated. Note that the safety controller 100 employs duplication of a processor or the like and a safety module, but generally such a configuration is not adopted for the control device 300. Also, in the control device 300, a user program is executed instead of the above-described safety program.
[0064] <E. Network configuration of the safety IO unit 20> FIG. 5 is a diagram showing a network including the safety IO unit 20 according to the present embodiment and the safety controller 100. The communication network in FIG. 5 includes the safety controller 100 which is a communication master and a plurality of safety IO units 20 which are communication slaves.
[0065] The safety controller 100 and a plurality of safety I / O units 20 are sequentially connected (daisy-chain connection) by a link and constitute a network as a whole. A frame including a control command sent from the safety controller 100 is sequentially transferred through a path passing through the safety I / O units 20 connected to the network. Such a communication path is assumed to be a network conforming to EtherCAT.
[0066] The safety I / O unit 20 includes a network interface 22, a safety input circuit having a plurality of input ports P1 to P4, and a safety output circuit having a plurality of output ports P5 to P8. Each input port receives an input signal from an input device 50 connected to the input port. The input signal is treated as the value (true or false) of a boolean-type variable in the safety program 30. Also, each output port outputs an output signal (on or off) corresponding to the value calculated by the safety program 30 to an output device 60 connected to the output port by the safety program 30.
[0067] <F. Hardware Configuration of Safety I / O Unit 20> FIG. 6 is a diagram showing the hardware configuration of the safety I / O unit 20 according to the present embodiment. In FIG. 6, the control unit 21 has a MPU (Micro Processing Unit) 31, a storage unit 32, a main memory 38 including a non-volatile storage medium, a network interface 22 having a communication circuit such as a communication coupler unit and controlling communication with the control system network NW1, a communication interface 23 having a communication circuit such as a communication coupler unit and controlling communication with the information system network NW2, and a rotary switch 24.
[0068] Also, the safety I / O unit 20 has a safety control unit duplicated to ensure reliable safe operation, and a safety input circuit 25 and a safety output circuit 26 that communicate with each other between the safety control units. The safety input circuit 25 has the input ports P1 to P4 in FIG. 5, and the safety output circuit 26 has the output ports P5 to P8 in FIG. 5.
[0069] The MPU 31 is connected to the network interface 22, the communication interface 23, the storage unit 32, and the duplicated safety control unit, and enables communication between these modules.
[0070] The rotary switch 24 is operated by the user to selectively designate the safety program 30 to be loaded into the safety control unit of the safety IO unit 20. The rotary switch 24 includes a mechanical switch that is provided on the housing of the safety IO unit 20 in a manner that allows the user to operate it. The rotary switch 24 has a switch that is operated, for example, by rotating a dial, and when the rotation of the switch is stopped at one of multiple positions, the position where the rotation has stopped (operated position) is detected and output by an encoder. The multiple positions of the switch are respectively associated with the safety programs 30(0) to 30(XX).
[0071] The safety control section has a dual system consisting of a system including a CPU (Central Processing Unit) A33 and a nonvolatile memory 35 accessed by the CPU A33, and a system including a CPU B34 and a nonvolatile memory 36 accessed by the CPU B34. The CPU A33 and the CPU B34 are connected to a safety input circuit 25 and a safety output circuit 26, respectively.
[0072] The MPU 31 detects the operating position of the rotary switch 24, and based on the detected operating position, searches for one of the safety programs 30(0) to 30(XX) in the storage unit 32 that corresponds to the operating position (encoded value), and transfers the searched safety program 30 to the CPU A 33 and the CPU B 34. The CPU A 33 and the CPU B 34 load the transferred safety program 30 into the nonvolatile memory 35 and the nonvolatile memory 36, respectively, and execute it. By operating the rotary switch 24 in this way, the user can load one or more safety programs 30 into the nonvolatile memory 35 and the nonvolatile memory 36.
[0073] The safety control unit is multiplexed for safety. More specifically, when both the CPU A33 and the CPU B34 execute the same safety program 30, one of them compares the values calculated by the CPU A33 and the CPU B34 through the execution of the safety program 30. When the comparison result indicates the coincidence of both values, the one outputs an output signal of the coincident value to the safety output circuit 26. When the comparison result indicates a non - coincidence, the one determines a value for operating the output device 60 so that safety is maintained, and causes the safety output circuit 26 to output an output signal of the determined value.
[0074] <G. Configuration of the storage unit> FIG. 7 is a diagram schematically showing an example of information stored in the storage unit 32 of FIG. 6. The storage unit 32 includes an area E1 for storing a system program including an OS, an area E2 for storing safety programs 30(0) to 30(XX), an area E3 for storing data related to the Web server program 40, and an area E4 for storing application programs and data. The application programs in the area E4 include a CRC (Cyclic Redundancy Check) program 71 and a management program 72. When the management program 72 is executed, it realizes the program management unit 33.
[0075] FIG. 8 is a diagram showing an example of the configuration of area E2 in FIG. 7. In FIG. 8, area E2 includes a code area E22 that stores program code for one or more safety programs 30, and a management area E21 that stores data for managing the safety programs 30 stored in the code area E22. The management area E21 includes records 80 corresponding to each safety program 30 in the code area E22. Each record 80 stores a number 81 that uniquely identifies the record and attribute data specific to the safety program 30. The attribute data includes a program name 82, a CRC value 83 that is a value specific to the program code, and an update date and time 84 that indicates the date and time when the safety program 30 was written (stored) in the code area E22. The data for these items in the record 80 is fixed length. The CRC value 83 indicates a value calculated for the program code (executable code) of the safety program 30 by a predetermined calculation of the CRC program.
[0076] In this embodiment, the program name 82 includes, for example, an identifier of an operation mode that is realized by executing the safety program 30. For example, the program name 82 includes an emergency stop application, a safety door application, a safety curtain application, and the like.
[0077] The code area E22 stores a record 90 for each of one or more safety programs 30. The record 90 includes a number 91 that identifies the record and the program code of the safety program 30 (executable code for setting 92 for safety input FBs, setting 93 for safety control FBs, and setting 94 for safety output FBs). This executable code may include, but is not limited to, data in binary format, for example. The data for these items in the record 90 is of a fixed length.
[0078] When the program code of the safety program 30 is not stored in the record 90, it is filled with all 0s (zeros) to indicate unused (no program code stored). Also, when the record 90 is set to unused, the record 80 having the number 81 indicating a value that matches the value of the number 91 of the record 90 is also set to unused, with the area except for the number 81 filled with all 0s (zeros).
[0079] In FIG. 8, as the numbers 81 and 91 are shown as any values from 00 to 15, in this embodiment, a maximum of 16 safety programs 30 are stored in the area E2. Note that the number of safety programs 30 to be stored is not limited to 16. Also, between the management area E21 and the code area E22, for the same safety program 30, the numbers 81 and 91 in the records 80 and 90 indicate the same value. Therefore, for the safety program 30, the records 80 and 90 may be treated as one integrated record. Thereby, the data (attributes and program code) of the safety program 30 can be stored in one record, and the size (capacity) consumed for storing the safety program 30 in the storage unit 32 can be saved.
[0080] <Software Configuration of the Safety I / O Unit 20> FIG. 9 is a diagram schematically showing the software configuration of the safety I / O unit 20 according to the present embodiment. In FIG. 9, it includes a program management unit 33 responsible for managing the safety program 30 in the storage unit 32, a switch interface 34 that outputs the operation position detected in the rotary switch 24 to the program management unit 33, a Web server 31, and an error detection unit 37 that detects errors in the safety program 30 by executing a CRC program 71 for the safety program 30.
[0081] The modules including the program management unit 33, the switch interface 34, the Web server 31, and the error detection unit 37 in FIG. 9 are, for example, composed of programs. Instead of this configuration, all or part of these modules may be implemented by a hardwired circuit. For example, the functions provided by the processor of the safety IO unit 20 executing the above various programs may be implemented using an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array).
[0082] Referring to FIG. 9, the safety program 30 according to this embodiment includes a safety input FB (Function Block) that receives, as an input, an input signal from an input device 50 via an input port, a safety control FB that performs a logical operation on the input signal from the safety input FB, and a safety output FB that outputs, via an output port, an output signal indicating the operation result from the safety control FB to a corresponding output device 60.
[0083] <I. Storage Process of Safety Program 30> A process of storing the safety program 30 based on a user instruction received via a Web screen will be described. FIGS. 10, 11, and 12 are diagrams showing an example of a Web screen displayed on the display 211 according to this embodiment. The "application name" in the Web screen corresponds to the program name. FIGS. 13 and 14 are examples of flowcharts of the storage process of the safety program 30 according to this embodiment. The flowcharts in FIGS. 13 and 14 show the processes performed by the Web server 31 or the Web browser 222 realized by the execution of the Web server program 40 or the program 227 of the Web browser 222 by the processor.
[0084] First, when the web browser 222 is started in the information processing device 200, the web browser 222 specifies the IP (Internet Protocol) address of the safety IO unit 20. For example, the IP address in the address bar 191 in Fig. 10 is clicked. Communication with the safety IO unit 20 is established using the IP address.
[0085] In FIG. 13, the user operates the "Operation Mode Setting" button 192 on the Web screen of FIG. 10, and the Web browser 222 accepts the user's operation and transfers it to the Web server 31 (step S10).
[0086] Based on the user operation received from the web browser 222, the web server 31 uses the program management unit 33 to search for the number 81 and attribute data (program name 82, CRC value 83, and update date and time 84) from each record 80 in the management area E21 of the storage unit 32. The web server 31 generates a web page including the searched data and transfers the generated web page to the web browser 222 (step S11). The web page is generated using data conforming to HTML (Hyper Text Markup Language), for example.
[0087] The web browser 222 displays a web screen based on the web page from the web server 31 on the display 211 (step S12). In step S12, a list of numbers 81 and attributes (program name 82, CRC value 83, and update date and time 84) is displayed for each record 80 in the management area E21 in FIG.
[0088] In Fig. 14, when the user selectively designates a desired operation mode on the screen of Fig. 10 and clicks on "Settings" button 193, Web browser 222 accepts the operation and displays the "Operation Mode Settings" Web screen of Fig. 11 based on the accepted user operation (step S122). The list of Fig. 10 shows that records 80 and 90 with numbers 81 and 91 indicating "11" to "14" do not store the safety program 30. In Fig. 11, designation 194a has been performed on records 80 and 90 with numbers 81 and 91 indicating "11" as the storage destination area for the safety program 30.
[0089] 11, the Web browser 222 accepts the operation (step S123) and displays a file selection screen based on the accepted user operation (step S124). The Web browser 222 searches the auxiliary storage device 220 for an executable code (e.g., binary) file of the safety program 30 that corresponds to the user-selected operating mode accepted from the file selection screen, and displays the search results (step S125). The Web browser 222 displays, on the display 211, attribute data (program name, CRC value, and update date and time) of the safety program 30 that corresponds to the searched executable code file. The CRC value displayed in step S125 indicates a CRC value calculated by the Web browser 222 according to a predetermined calculation for the executable code of the safety program 30 that was searched for from the auxiliary storage device 220.
[0090] 11, the user clicks on "Write" button 195. Web browser 222 determines whether to accept this operation (step S126). If it is determined that the click on "Write" button 195 has not been accepted (NO in step S126), Web browser 222 repeats the process of step S126.
[0091] If it is determined that the click operation on the "Write" button 195 has been accepted (YES in step S126), the Web browser 222 transmits the executable code file of the retrieved safety program 30, the number "11" of the area specification 194a, and the attribute data (program name, CRC value, and update date and time) to the Web server 31.
[0092] When the Web server 31 receives the data transferred from the Web browser 222, the program management unit 33 stores the received data in area E2 of the storage unit 32 (step S127). At this time, attribute data and program code (executable code) are written into the user-selected area, i.e., into record 80 having number 81 indicating "11" in the specification 194a and record 90 having number 91 indicating "11," respectively.
[0093] The program management unit 33 calculates a CRC value for the written data, for example, the executable code written in record 90 (the code for setting 92 for safety input FB, setting 93 for safety control FB, and setting 94 for safety output FB) according to a predetermined calculation, and compares the calculated CRC value with the CRC value of the executable code before it was written to determine whether they match (step S129). The program management unit 33 calculates the CRC value and compares the CRC values by executing the CRC program 71. Here, the CRC value before it was written is the CRC value displayed in step S125.
[0094] In this way, when the safety program 30 transferred from the information processing device 200 is stored in the memory unit 32 of the safety IO unit 20, the safety IO unit 20 verifies, based on the results of a check using a CRC value, that there is a match between the safety program 30 before and after storage, i.e., that there is no code inconsistency or that the code is consistent.
[0095] If it is determined that both CRC values match (YES in step S129), the Web server 31 notifies the Web browser 222 that the writing is completed. When the Web browser 222 receives the notification of the completion of writing, it switches the screen of the display 211 to the screen of "Operation Mode List" in FIG. 12 based on the Web page received from the Web server 31 (step S130). In step S130, the Web page transferred from the Web server 31 to the Web browser 222 displays a list of numbers 81 and attributes (program name 82, CRC value 83, and update date / time 84) for each record 80 in the management area E21 of the storage unit 32 after the completion of writing.
[0096] Therefore, in the "Operation Mode List" section 196 of the screen in FIG. 12, the attributes of the security program 30 selected by the user are displayed in the column of number 91 of "11". The user can confirm from the information in section 196 that the storage of the security program 30 has been successful.
[0097] If it is determined that both CRC values do not match (NO in step S129), the Web server 31 notifies the user of the writing failure via the Web browser 222, and the Web server 31 deletes the data written from records 80 and 90 in step S127 by the program management unit 33 (step S131). The program management unit 33 returns the records 80 and 90 to the state where the security program 30 is not stored.
[0098] The Web browser 222 switches the screen of the display 211 to the "Operation Mode List" screen (the screen in FIG. 10) based on the Web page received from the Web server 31 (step S132). In step S132, the Web page transferred from the Web server 31 to the Web browser 222 is based on the attribute data (program name 82, CRC value 83, and update date / time 84) of each record 80 in the management area E21 of the storage unit 32 after the data deletion is performed in step S131.
[0099] <J. Deletion Process of Security Program 30> The process of deleting the safety program 30 based on a user instruction received via a web screen will now be described. FIGS. 15, 16, and 17 are diagrams showing examples of web screens displayed on the display 211 according to this embodiment. FIG. 18 is an example of a flowchart of the process of deleting the safety program 30 according to this embodiment. The flowchart in FIG. 18 shows the process performed by the web server 31 or the web browser 222, which is realized by the processor executing the web server program 40 or the program 227 of the web browser 222. The process of establishing communication between the web browser 222 and the web server 31 is similar to the process described in the process of FIG. 13, and therefore will not be described again.
[0100] 18, the web browser 222 displays the "operation mode list" screen of Fig. 15 based on the web page received from the web server 31. When the user selects an operation mode from the list on the web screen of Fig. 15, specifies the number "10", and operates the "delete button" 131, the web browser 222 accepts the operation of the "delete button" (step S141).
[0101] When the web browser 222 accepts the operation of the "Delete button," it displays the web screen shown in Fig. 16 for deleting the user-selected operation mode (step S142). In the window 132 of the screen shown in Fig. 16, the web browser 222 displays the attribute data (program name, CRC value, and update date and time) of the safety program 30 corresponding to the record 80 with the number 81 indicating the value "10" of the user selection 132a (step S143).
[0102] 16 screen to accept the user's operation of "Delete" button 133 (step S144). If it is not determined that the operation of "Delete button" 133 has been accepted (NO in step S144), Web browser 222 repeats step S144.
[0103] When it is determined that the operation of the "Delete Button" 133 has been received (YES in step S144), the Web browser 222 transfers the user operation of the "Delete Button" 133 and the user-selected value "10" to the Web server 31.
[0104] The Web server 31 deletes the user-selected safety program 30 in the storage unit 32 according to the user operation of the "Delete Button" 133 (step S145). In step S145, the Web server is to search for records 80 and 90 having numbers 81 and 91 indicating the value "10" received from the Web browser 222. The Web server 31 deletes the retrieved records 80 and 90. In the deletion, for example, the retrieved records 80 and 90 are filled with 0 (zero) or overwritten with 0, so that the records are set to a state where the safety program 30 is not stored.
[0105] The Web browser 222 displays the Web screen of FIG. 17 based on the Web page transferred from the Web server 31 (step S146). In step S146, the Web page that the Web server 31 transfers to the Web browser 222 is based on the attribute data (program name 82, CRC value 83, and update date and time 84) retrieved from each record 80 in the management area E21 of the storage unit 32 after the data deletion is performed in step S145. As a result, on the Web screen of FIG. 17, the window 134 indicates that the deletion process of the safety program 30 has been successfully performed in the records 80 and 90 with numbers 81 and 91 indicating "10" selected by the user on the Web screen of FIG. 15.
[0106] <K. Processing at Power-On> Next, the processing procedure at power-on in the safety IO unit 20 of the present embodiment will be described. FIG. 19 is a flowchart showing the processing at power-on of the safety IO unit 20 of the present embodiment.
[0107] 19, when the safety IO unit 20 is powered on (step S151), the program management unit 33 acquires a value (number) designated (selected) by a user operation from the rotary switch 24 (step S152). Next, the program management unit 33 determines whether a safety program 30 is stored in the code area E22 of the storage unit 32 based on the acquired value (step S153). More specifically, the program management unit 33 searches for a record 90 with a program number 91 that indicates a value matching the acquired value, and determines whether the record 90 is an unused record based on the data of the searched record 90, i.e., whether a user-designated safety program 30 is stored in the storage unit 32.
[0108] If it is determined that the user-specified safety program 30 is stored (YES in step S153), the program management unit 33 proceeds to step S155, which will be described later. If it is determined that the user-specified safety program 30 is not stored (NO in step S153), the program management unit 33 starts the safety IO unit 20 in the normal mode (step S154). More specifically, the safety IO unit 20 operates in the remote operation mode.
[0109] In step S155, the program management unit 33 calculates a CRC value for the program code of the record 90 determined in step S153 (step S155). Based on the program number 91 of the record 90, the program management unit 33 searches the management area E21 for a record 80 having a program number 81 that indicates a value that matches the value of the program number 91. The program management unit 33 compares the calculated CRC value with the CRC value 83 of the record 80 found in the management area E21, and determines whether the two CRC values match based on the comparison result (step S156).
[0110] When it is determined that the CRC values match (YES in step S156), the program management unit 33 starts the user-specified safety program 30 (step S157). More specifically, the program management unit 33 reads the program code (executable code) from the record 90 in the storage unit 32, expands the read program code in each of the non-volatile memories 35 and 36 of the safety control unit, and starts the safety program 30 of the program code expanded in the non-volatile memories 35 and 36 via the CPU A33 and the CPU B34.
[0111] As a result, the user-specified safety program 30 is executed in the safety control unit. As a result, in the safety IO unit 20, the operation mode of the safety program 30 is implemented.
[0112] When it is determined that the CRC values do not match (NO in step S156), that is, when the program management unit 33 detects that the safety program 30 is corrupt data, the safety IO unit 20 is forcibly stopped (step S158).
[0113] <L. Modified Example> In the above embodiment, the configuration for obtaining a user instruction for updating (storing and deleting) the safety program 30 for the safety IO unit 20 is realized by the interaction between the web server 31 and the web browser 222. However, the configuration for realization is not limited to this. For example, the information processing apparatus 200 may include a module that communicates with the safety IO unit 20 based on Ethernet (registered trademark) instead of the web browser 222, and the safety IO unit 20 may include an Ethernet-based communication module that communicates with the information processing apparatus 200 instead of the web server 31. The information processing apparatus 200 transmits a communication command based on a user operation received from the operation unit 206 to the safety IO unit 20, and the safety IO unit 20 stores or deletes the safety program 30 in the storage unit 32 according to the command received from the information processing apparatus.
[0114] The check for the consistency of such a safety program 30 may be caused when transferring the safety program 30 from the information processing apparatus 200 to the safety IO unit 20, or when changing (such as data loss, data tampering, etc.) the safety program 30 after it is stored in the storage unit 32. The value used for such a check is not limited to the CRC value, and may be a checksum value calculated by a predetermined operation on the program code. Also, a check using the coincidence of the update date and time may be used. Alternatively, for the check, one or a plurality of combinations of the coincidence of the CRC value, the coincidence of the checksum value, and the coincidence of the update date and time may be used.
[0115] When storing or deleting the safety program 30, the user selectively designates the area (records 80, 90) of the safety program 30 from the list of safety operation modes, but the designation method is not limited to this. For example, it may be the operation position of the rotary switch 24. The program management unit 33 specifies, as the area for storing or deleting the safety program 30, the records 80, 90 having the numbers 81, 91 indicating the values detected from the user operation position.
[0116] [[ID=]7] <M. Appendix> The following configurations are disclosed in this specification. [Configuration 1] A remote safety input / output device (20), a storage unit (32) for storing a safety program (30) for determining the value of an output signal for operating an output device (60) so that safety is maintained when a predetermined condition for the value of an input signal received from an input device (50) is satisfied; an instruction acquisition unit (31) for acquiring a user instruction for the remote safety input / output device; a program management unit (33) for updating the safety program in the storage unit according to the user instruction acquired by the instruction acquisition unit. A remote safety input / output device comprising the above. [Configuration 2][[ID=]23] 2. The remote safety input / output device according to configuration 1, wherein the instruction acquisition unit includes a Web server (31) that acquires the user instruction from a Web browser (222). [Configuration 3] The update includes storing or deleting a safety program in the storage unit, The remote safety input / output device according to configuration 2, wherein when storing the safety program in the memory unit, it detects that the unique attributes (83, 84) acquired for the program code of the safety program before storage match the unique attributes acquired for the program code of the safety program after storage. [Configuration 4] The remote safety input / output device according to configuration 2 or 3, wherein the memory unit has a code area (E22, 90) for storing program code of the safety program, and an attribute area (E21, 80) for storing unique attributes of the program code. [Configuration 5] The inherent attribute includes a value (83) calculated by a predetermined operation on the program code of the safety program; 5. The remote safety input / output device according to configuration 4, wherein when the safety program stored in the memory unit is started, the value is calculated by the predetermined operation for the program code in the code area, and it is detected that the calculated value matches the value included in the unique attribute stored in the attribute area. [Configuration 6] The storage unit has a plurality of the code regions (90), 6. The remote safety input / output device according to claim 5, wherein the web server transfers to the web browser a web page that indicates, for each of the plurality of code areas, whether the code area has already stored the program code. [Configuration 7] 7. The remote safety input / output device according to claim 6, wherein the user instruction includes designation of a code area among the plurality of code areas for storing the safety program. [Configuration 8] Further comprising a rotary switch (24); 8. The remote safety input / output device according to configuration 7, wherein the remote safety input / output device accepts designation of the code area for storing the safety program based on a user operation of the rotary switch. [Configuration 9] a network interface (22) for connecting a network (NW1) to which the safety controller belongs; a communication interface (23) that connects to a network (NW2) for communicating with the web browser; The safety program 3. The remote safety input / output device according to configuration 2, further comprising a remote safety program that determines a value of an output signal for operating the output device so as to maintain safety in accordance with a control signal transferred from the safety controller.
[0117] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]
[0118] 1 Safety system, 20 Safety IO unit, 21 Control unit, 22, 210 Network interface, 23 Communication interface, 24 Rotary switch, 25 Safety input circuit, 26 Safety output circuit, 30 Safety program, 31 Web server, 32 Storage unit, 33 Program management unit, 34 Switch interface, 35, 36 Non-volatile memory, 37 Error detection unit, 38 Main memory, 40 Server program, 50, 400 Input device, 60 Output device, 71 CRC program, 72 Management program, 80, 90 Record, 81, 91 Program number, 82 Program name, 83 CRC value, 84 Update date and time, 100 Safety controller, 200 Information processing device, 222 Web browser, E1, E2, E3, E4 Area, E21 Management area, E22 Code area, NW1 Control system network, NW2 Information system network, P1 to P4 Input port, P5~P8 output port.
Claims
1. A remote safety input / output device, a storage unit for storing a safety program that determines a value of an output signal for operating an output device so as to maintain safety when a predetermined condition is satisfied with respect to the value of an input signal received from the input device; an instruction acquisition unit that acquires a user instruction for the remote safety input / output device; a program management unit that updates a safety program in the storage unit in accordance with a user instruction acquired by the instruction acquisition unit.
2. The remote safe input / output device according to claim 1 , wherein the instruction acquisition unit includes a web server that acquires the user instruction from a web browser.
3. The update includes storing or deleting a safety program in the storage unit, 3. The remote safety input / output device according to claim 2, wherein when the safety program is stored in the memory unit, it is detected that the unique attribute acquired for the program code of the safety program before storage matches the unique attribute acquired for the program code of the safety program after storage.
4. 4. The remote safety input / output device according to claim 2, wherein the storage unit has a code area for storing program code of the safety program, and an attribute area for storing unique attributes of the program code.
5. the inherent attribute includes a value calculated by a predetermined operation on the program code of the safety program; 5. The remote safety input / output device according to claim 4, wherein when the safety program stored in the storage unit is started, the value is calculated by the predetermined operation for the program code in the code area, and it is detected that the calculated value matches the value included in the unique attribute stored in the attribute area.
6. the storage unit has a plurality of the code areas, 6. The remote safe input / output device according to claim 5, wherein the web server transfers to the web browser a web page indicating, for each of the plurality of code areas, whether or not the program code has been stored in that code area.
7. The remote safety input / output device according to claim 6 , wherein the user instruction includes designation of the code area for storing the safety program among the plurality of code areas.
8. It also has a rotary switch, The remote safety input / output device according to claim 7 , wherein the remote safety input / output device accepts designation of the code area for storing the safety program based on a user operation of the rotary switch.
9. a network interface for connecting a network to which the safety controller belongs; a communication interface for connecting to a network for communication with the web browser; The safety program 3. The remote safety input / output device according to claim 2, further comprising a remote safety program that determines values of output signals for operating said output devices so as to maintain safety in accordance with control signals transferred from said safety controller.
Citation Information
Patent Citations
Safety device having safety control device which can be configured in system configuration
JP2011181072A