Safety device

The safety device integrates a web server and command generator to facilitate user-friendly setup and management of safety commands, addressing the challenge of configuring safety devices without dedicated tools, ensuring secure and efficient operation.

JP2025141027APending Publication Date: 2025-09-29OMRON CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024040741
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-15
Publication Date
2025-09-29

AI Technical Summary

Technical Problem

Users face difficulties in setting up safety devices for safety communication without dedicated tools or devices, especially when unfamiliar with the operation, leading to a time-consuming process.

Method used

A safety device equipped with a web server and command generator that allows users to input safety commands through a web interface, generating device identifiers and executing safety commands via a network, reducing the need for dedicated tools and simplifying the configuration.

Benefits of technology

Enables users to set up and manage safety devices for safety communication efficiently through a web server, ensuring secure and trouble-free operation without constant processing load on the device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025141027000001_ABST
    Figure 2025141027000001_ABST
Patent Text Reader

Abstract

To provide a safety device allowed to acquire a safety command related to safe communication from a user by a simple configuration and without requiring the user to take labor and time.SOLUTION: A safety device is configured to execute a safety command related to safe communication. The safety device comprises: a Web server that acquires a user instruction to the safety device from a user; and a command generating section that generates the safety command based on the user instruction acquired from the user by the Web server.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to safety devices. [Background technology]

[0002] Traditionally, in the field of FA (factory automation), systems have been used in which control devices and various devices such as sensors and actuators are connected via a network. With the advancement of ICT (Information and Communication Technology), the application of more advanced communication technologies is progressing.

[0003] For example, communication between control devices and between a control device and any device can be achieved using a network technology called CIP (Common Industrial Protocol), which is managed and provided by ODVA, Inc., headquartered in the United States. During communication, an identifier is assigned to the device. Regarding identifier setting technology, Japanese Patent Application Laid-Open Publication No. 2019-174950 (Patent Document 1) discloses a dedicated setting tool and support device for setting information in safety devices that exchange data according to communication protocols such as CIP and CIP Safety. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2019-174950 Summary of the Invention [Problem to be solved by the invention]

[0005] In an environment where the setting tool and support device described in Patent Document 1 are unavailable, the user cannot instruct the safety device to set information. Even if the setting tool and support device are available, there is a problem that users who are unfamiliar with the operation find it time-consuming to give instructions.

[0006] The present invention has been made in consideration of the above-mentioned problems, and its object is to provide a safety device that can obtain safety commands related to safety communication from a user with a simple configuration and without causing the user any trouble. [Means for solving the problem]

[0007] The safety device according to the present disclosure is a safety device capable of executing safety commands related to safety communication, and includes a web server that receives user instructions for the safety device, and a command generator that generates safety commands based on the user instructions received by the web server.

[0008] According to the above disclosure, a user can input safety commands to a safety device by using a Web server without using a dedicated tool or device. Therefore, the safety device can obtain safety commands related to safety communication from the user with a simple configuration of a Web server and without causing the user any trouble.

[0009] In the above disclosure, the safety command generated by the command generating unit includes a command for setting a device identifier for identifying a safety device in safety communication.

[0010] According to the above disclosure, a user can use a web server to input a safety command to set a device identifier for a safety device.

[0011] In the above disclosure, the safety device further includes a network interface that connects the control device to a network to which the safety device belongs, and generates a device identifier by combining an identifier of the network and an IP address of the safety device.

[0012] According to the above disclosure, the safety device is configured to communicate with the control device over a network, and the safety device can generate a device identifier by combining the identifier of the network to which the safety device belongs with the IP address of the safety device.

[0013] In the above disclosure, the safety device further includes a processing unit that executes processing according to the safety command, and the command generating unit establishes a connection for exchanging safety commands between the command generating unit and the processing unit.

[0014] According to the above disclosure, within the safety device, a connection is set up between the command generation unit and the processing unit that processes the safety commands, allowing the safety commands to be exchanged safely, and then the safety commands can be exchanged.

[0015] In the above disclosure, the safety device further includes a network interface that connects the control device to a network to which the safety device belongs. The safety commands executable by the safety device include safety commands transferred from the control device via the network. The safety device further includes a first processing unit that executes a first process in accordance with the safety commands transferred from the control device.

[0016] According to the above disclosure, the safety device can execute processing in accordance with a safety command based on a user instruction via a web server and a first processing in accordance with a safety command transferred from a control device via a network.

[0017] In the above disclosure, the safety device further includes an input port for connecting an input device, and the first process includes a process of outputting a value of an input signal received from the input device to a network via a network interface in accordance with a safety command transferred from the control device.

[0018] According to the above disclosure, the safety device can transfer the value of the input signal received from the input device to the control device via the network in accordance with the safety command transferred from the control device via the network.

[0019] In the above disclosure, the safety device further includes an output port to which an output device is connected, and the first process includes a process of determining a value of an output signal for operating the output device so as to maintain safety in accordance with a safety command transferred from the control device.

[0020] According to the above disclosure, the safety device is able to operate the output equipment in a manner that maintains safety by determining the value of the output signal in accordance with a safety command transferred from the control device via a network.

[0021] In the above disclosure, the Web server activates the command generation unit when it receives a user instruction.

[0022] According to the above disclosure, the command generation unit is activated when the Web server receives a user instruction for the safety device. Therefore, the processing load on the safety device can be reduced compared to a configuration in which the command generation unit is constantly operating.

[0023] In the above disclosure, the safety device further includes a storage unit for storing the device identifier, and the safety command generated by the command generating unit based on a user instruction includes a command for deleting the device identifier from the storage unit.

[0024] According to the above disclosure, a user can use a web server to input a safety command to a safety device to delete the device identifier from the storage unit. [Effects of the Invention]

[0025] According to the present disclosure, it is possible to provide a safety device that can acquire safety commands related to safety communication with a simple configuration and without causing the user any trouble. [Brief explanation of the drawings]

[0026] [Figure 1] 1 is a diagram showing the configuration of a safety device 20 according to the present embodiment in relation to peripheral devices. [Figure 2] 1 is a diagram illustrating an example of a system configuration of a safety control system 1. FIG. [Figure 3] FIG. 10 is a diagram illustrating another example of the configuration of the safety control system according to the present embodiment. [Figure 4] 1 is a schematic diagram showing an example of a device configuration of a safety controller 100 according to the present embodiment. [Figure 5] 1 is a schematic diagram showing an example of a hardware configuration of an information processing device 200 according to the present embodiment. [Figure 6] 1 is a diagram showing a network including a safety device 20 and a safety controller 100 according to the present embodiment. [Figure 7] 2 is a diagram illustrating a hardware configuration of a safety device 20 according to the present embodiment. FIG. [Figure 8] FIG. 8 is a diagram schematically illustrating an example of information stored in a storage unit 32 of FIG. 7. [Figure 9] 2 is a diagram showing an example of how modules are mounted in a safety device 20 according to the present embodiment. FIG. [Figure 10] 1 is a diagram showing a module configuration of a safety device 20 according to the present embodiment. [Figure 11] FIG. 10 is a diagram showing an example of a web screen for TUNID settings according to the present embodiment. [Figure 12] FIG. 10 is a diagram showing an example of a web screen for IP address setting according to the present embodiment. [Figure 13] 10 is a flowchart of a TUNID setting process according to the present embodiment. [Figure 14]This is a flowchart of the TUNID setting process according to the present embodiment. [Figure 15] This is a diagram showing an example of a web page in memory clearing according to the present embodiment. [Figure 16] This is a flowchart of the memory clearing process according to the present embodiment. [Figure 17] This is a flowchart of the memory clearing process according to the present embodiment.

Modes for Carrying Out the Invention

[0027] Hereinafter, each embodiment according to the present invention will be described with reference to the drawings. In the following description, the same parts and components are denoted by the same reference numerals. Their names and functions are also the same. Therefore, detailed descriptions thereof will not be repeated.

[0028] <A. Application Example> First, an example of a scenario to which the present invention is applied will be described. In this specification, a safety control system including a safety bus, for example, applies the IEC 61508, which is a functional safety standard. IEC 61508 requires the use of secure communication when dealing with functional safety and data communication. In the present embodiment, for example, CIP Safety is used as a communication protocol for realizing secure communication. A "safety command" is a command related to secure communication defined by such a secure communication protocol.

[0029] In this specification, "safety control" is a general term for processes for preventing the safety of people from being threatened by some equipment, machine, etc. due to some defect. Safety control includes, for example, processes for stopping the control target not only when the behavior of the control target itself is different from normal but also when it is determined that some abnormality has occurred in the control device itself.

[0030] The term "device" encompasses any device that can be connected via a network. Devices include at least some of the following: a single sensor, a single actuator, a relay device for connecting one or more sensors or actuators to a network, a remote I / O terminal for connecting one or more sensors or actuators to a network, and various control devices such as a robot controller, a temperature controller, and a flow rate controller. In particular, a "device" for realizing safety control is also called a "safety device."

[0031] An "IP address" is an identification number within a network that is assigned to a control device and each safety device. IP (Internet Protocol) addresses are set so that they are unique within the same network.

[0032] "SNN (Safety Network Number)" is an example of network identification information, and is identification information set for a range that the control device treats as a single network. In the safety control system, it is set for each network so that it does not overlap with other networks.

[0033] "TUNID (Target Unique Network Identifier)" is an identifier that identifies a device on a network in safety communication where the CIP Safety protocol is applied. The TUNID of a safety device is a data string that combines the SNN of the network to which the safety device belongs and the IP address of the safety device. Note that the identification information used to identify a safety device on a network in safety communication is not limited to the TUNID.

[0034] 1 is a diagram showing the configuration of a safety device 20 according to this embodiment in association with peripheral devices. The safety device 20 is configured to be able to execute safety commands related to safety communication. The safety device 20 includes a Web server 21 that acquires user instructions for the safety device 20, a command generation unit 22 that generates safety commands based on the user instructions acquired by the Web server 21, and a command processing unit 23 that executes processing in accordance with the safety commands.

[0035] The web server 21 communicates with a web browser 222 installed in the information processing device 200. The web browser 222 displays a web screen of a GUI (Graphical User Interface) based on a web page transferred from the web server 21. The web browser 222 accepts user operations via the web screen and transfers instructions based on the accepted user operations to the web server 21. Data including web pages exchanged between the web server 21 and the web browser 222 includes, for example, data conforming to HTML (Hyper Text Markup Language).

[0036] The safety command generated by the command generation unit 22 includes a command to set TUNID 39, which is a device identifier for identifying a safety device in safety communication, in the safety device 20. The set TUNID 39 is stored in the nonvolatile memories 35 and 36. The safety command generated by the command generation unit 22 also includes a command to delete TUNID 39 from the nonvolatile memories 35 and 36. Note that the types of safety commands generated by the command generation unit 22 are not limited to these.

[0037] The safety commands executed by the command processing unit 23 include safety commands from the command generation unit 22 and safety commands transferred from the network to the safety device 20. The command processing unit 23 includes a first processing unit 24 that executes processing in accordance with the safety commands transferred from the network. The safety commands transferred from the network to the safety device 20 may include safety commands transferred from a control device of the safety control system and safety commands transferred from a dedicated tool (for example, an SNCT (Safety Network Configuration Tool) of the information processing device 200).

[0038] The nonvolatile memories 35, 36 can further store one or more safety programs 30. Here, one safety program 30 is stored. When executed by the safety device 20, the safety program 30 determines the value of an output signal for operating the output device 60 so as to maintain safety when a predetermined condition (safety condition) is met for the value of an input signal received from the input device 50.

[0039] The input device 50 includes a safety sensor, a safety door switch, a safety limit switch, an emergency stop switch, a safety switch, etc. The output device 60 is a device that is driven in response to an operation of the input device 50. The output device 60 includes, for example, a safety relay that drives a contactor to interrupt an electrical circuit that supplies power to a controlled object. A dangerous area is defined around a motor-driven device, and the input device 50 is disposed around the dangerous area. The input device 50 includes, for example, a detection device that detects the presence or intrusion of a person, and an input device that accepts an operation in an emergency. The safety relay is driven by receiving an input signal from such an input device 50. In this embodiment, the safety device 20 is illustrated as a device that is connected to the input device 50 and the output device 60 and executes the safety program 30, but is not limited to this configuration. For example, the safety device 20 may be configured such that the input device 50 and the output device 60 are not connected.

[0040] As described above, the safety device 20 can obtain safety commands based on user instructions by using the web server 21 without using a dedicated tool or device. Further, the command processing unit 23 is applied to both the safety commands obtained from the web server 21 and the safety commands transferred to the safety device 20 via the network. Therefore, for the same safety command, even if the path through which the safety command is transferred to the safety device 20 is different, the command processing unit 23 can execute the same process according to the safety command.

[0041] <B. System Configuration> Next, a safety control system including the safety device 20 according to the present embodiment will be described. FIG. 2 is a diagram showing an example of the system configuration of the safety control system 1.

[0042] Referring to FIG. 2, the safety control system 1 is applied to, for example, FA (Factory Automation) of a production line. The safety control system 1 mainly includes a safety controller 100, an information processing device 200 having a display 211, a control device 300 that controls equipment, machines, etc., and a safety device 20. The safety control system 1 in FIG. 2 has a plurality of safety devices 20, but the number of safety devices 20 may be one or more.

[0043] The control device 300 is typically configured with a programmable logic controller (PLC) or the like, and executes a predetermined user program on input data acquired from a control target, and issues commands to the control target according to output data calculated thereby. In FIG. 2, a motor 510 and a driver 512 that drives the motor 510 are exemplified as control targets. In accordance with the user program, when a certain drive start condition is met, the control device 300 outputs a drive command to the driver 512 to drive the motor 510 in rotation. Furthermore, when a certain drive stop condition is met, the control device 300 stops outputting the drive command to the driver 512 to stop the motor 510 in rotation.

[0044] In addition to the control of the controlled object by such control device 300, a safety controller 100 is typically further provided to ensure the safety of workers and others associated with the controlled object. When a predetermined condition (safety condition) associated with an input signal from input device 400 (such as a safety sensor, a safety door switch, a safety limit switch, an emergency stop switch, or a safety switch) serving as a safety device is met, safety controller 100 outputs an output signal (control signal) to safety relay 514, an example of an output device, for operating to maintain safety. Safety relay 514 operates in response to the output signal from safety controller 100 and cuts off the power supply to driver 512 that drives motor 510. As a result, motor 510 is forcibly stopped.

[0045] Furthermore, the safety controller 100 remotely controls the safety device 20 by safety communication so that the safety device 20 operates remotely. The first processing unit 24 of the safety device 20 executes a first process in accordance with a control signal (safety command) from the safety controller 100, more specifically, determines that the reception of the first control signal means that a predetermined condition (safety condition) is met, determines the value of an output signal for operating the output device 60 so as to maintain safety, and transfers the control signal to another safety device 20.

[0046] For example, the safety controller 100 outputs a control signal to a predetermined safety device 20 among the multiple safety devices 20 in response to a detection signal from a safety sensor, which is the input device 400. The predetermined safety device 20 performs the above remote operation in response to receiving the control signal from the safety controller 100, and the other safety devices 20 also perform the above remote operation in response to receiving the control signal transferred from the predetermined safety device 20. As a result, the output device 60 (safety relay) connected to each safety device 20 receives an output signal for safe operation, and the motor associated with the safety relay is forcibly stopped. By forcibly stopping the motor in this way, the safety of a worker who enters a hazardous area can be ensured.

[0047] Furthermore, when the first processing unit 24 of the safety device 20 receives a second control signal through safety communication, the first processing unit 24 may execute processing to output, in accordance with the second control signal, the value of the input signal received from the input device to the network for transfer to the safety controller 100. The safety device 20 may execute one or more of processing in response to the first control signal from the safety controller 100, processing in response to the second control signal, and processing in response to another control signal.

[0048] In the configuration example shown in FIG. 2, the safety controller 100, the control device 300, and the safety device 20 are connected via a control network NW1 and can exchange data held internally with each other. Further, the safety controller 100, the control device 300, and the safety device 20 are connected to the information processing device 200 via an information network NW2. As the control network NW1 to which the safety controller 100, the control device 300, and the safety device 20 belong, a network protocol that guarantees timing, such as EtherCAT (registered trademark), is preferable. As the information network NW2 to which the information processing device 200 belongs, Ethernet (registered trademark) or EtherNet / IP (registered trademark), which is a general network protocol, may be adopted.

[0049] FIG. 3 is a diagram showing another example of the configuration of the safety control system according to the present embodiment. In FIG. 3, there are a safety controller 100A and a safety controller 100 that communicate with each other via a control network NW1. The safety controller 100A is provided as a device that integrates the control device 300 and the safety controller 100. The control network NW1 to which the safety controller 100 belongs includes safety devices 20(1) and 20(2) that are safety IO units, and a safety device 20(3) that is a robot. The control network NW1 to which the safety controller 100 belongs includes safety devices 20(4) that are safety servo drivers and a safety device 20(5) that is a safety laser scanner. In FIG. 3, distributed control of a plurality of safety devices 20 is realized by the safety controllers 100 and 100A.

[0050] <C. Device Configuration> The configuration of each device will be described with reference to FIGS. 4 and 5.

[0051] (c1: Safety Controller 100) Fig. 4 is a schematic diagram showing an example of the device configuration of safety controller 100 according to the present embodiment. Referring to Fig. 4, safety controller 100 includes processor 102, main memory 104, and arithmetic processing unit 108 including flash memory 106, and various interfaces.

[0052] In the arithmetic processing unit 108, the processor 102 loads the system program and safety program 30 stored in the flash memory 106 into the main memory 104 and executes them, thereby realizing functional safety according to the control target.

[0053] The safety controller 100 includes, as interfaces, a control network interface 110, an information network interface 112, a field bus interface 114, a memory card interface 116, a local communication interface 120, and an internal bus interface 122.

[0054] The control network interface 110 mediates communication with other devices via the control network NW1 (see FIG. 2). The information network interface 112 mediates communication with other devices via the information network NW2 (see FIG. 2).

[0055] The fieldbus interface 114 mediates communication with an input / output unit connected via a fieldbus (not shown). As the fieldbus, a network protocol that guarantees punctuality, such as EtherCAT (registered trademark), EtherNet / IP (registered trademark), DeviceNet (registered trademark), or CompoNet (registered trademark), is preferred.

[0056] The memory card interface 116 is configured to allow a memory card 118 to be inserted therein, and reads and writes data from and to the memory card 118 .

[0057] The local communication interface 120 is an interface for directly connecting to the information processing device 200 or other devices, and uses, for example, a USB (Universal Serial Bus).

[0058] The internal bus interface 122 mediates communication between the safety controller 100 and an input / output unit directly attached thereto via the internal bus.

[0059] (c2: information processing device 200) Next, an example of the hardware configuration of the information processing device 200 will be described. Fig. 5 is a schematic diagram showing an example of the hardware configuration of the information processing device 200 according to this embodiment.

[0060] The information processing device 200 may be a portable terminal such as a notebook PC (Personal Computer), a tablet terminal, or a smartphone, or may be a non-portable terminal such as a desktop PC.

[0061] Information processing device 200 includes, as its main components, a processor 202 that executes a system program 224 including an operating system (OS) and various programs as described below, and a main memory 204 that provides a work area for storing data necessary for program execution by processor 202. Information processing device 200 also includes an operation unit 206 that accepts user operations such as a keyboard or mouse, an output unit 208 that outputs processing results such as a display 211, various indicators, and a printer, a network interface 210 for communicating with information network NW2, an optical drive 212 to which an optical recording medium (e.g., a DVD (Digital Versatile Disc)) 214 is removably attached, a local communication interface 216 for communicating with safety controller 100 and the like, and an auxiliary storage device 220. These components are connected to each other so as to be able to communicate data via an internal bus 218 or the like.

[0062] The auxiliary storage device 220 is composed of, for example, an HDD (Hard Disk Drive) or an SSD (Flash Solid State Drive), etc., and stores programs executed by the processor 202. Specifically, the auxiliary storage device 220 stores a system program 226 including an OS (Operating System) and application programs. The application programs include programs for managing programs executed by the safety controller 100, the control device 300, and the safety device 20, developing various programs, checking the execution status of programs, changing programs, etc. In the present embodiment, the application programs include a program 229 of a Web browser 222 having a GUI and a support program 228. The support program 228 includes an SNCT program 223 that realizes SNCT when executed.

[0063] (c3: Control device 300) The control device 300 according to the present embodiment has the same device configuration as the safety controller 100 shown in FIG. 4, so detailed description will not be repeated. Note that the safety controller 100 employs duplication of a processor or the like and a safety module, but generally, such a configuration is not employed in the control device 300. Also, in the control device 300, a user program is executed instead of a safety program.

[0064] <D. Network configuration of safety device 20> FIG. 6 is a diagram showing a network including the safety device 20 and the safety controller 100 according to the present embodiment. The communication network in FIG. 6 includes a safety controller 100 that is a communication master and a plurality of safety devices 20 that are communication slaves.

[0065] The safety controller 100 and the multiple safety devices 20 are connected in series (daisy-chain connection) by links, and together they form a network. A frame containing a control command sent from the safety controller 100 is transferred in series along a path that passes through the safety devices 20 connected to the network.

[0066] As a protocol for network data transmission, industrial network protocols such as EtherNet / IP (registered trademark), DeviceNet (registered trademark), and CompoNet (registered trademark) can be used. The program (application) executed by the safety controller 100 and / or the safety device 20 according to the embodiment of the present invention uses such a protocol for data transmission to exchange data in accordance with a communication protocol such as CIP (Common Industrial Protocol) or CIP Safety. For data exchange, a frame including TUNID is used.

[0067] In the following description, an example of an architecture in which communication between the safety controller 100 and one or more safety devices 20 on the control network NW1 utilizes the CIP Safety communication protocol (application layer function) over EtherNet / IP (registered trademark).

[0068] The safety device 20 includes a network interface 29 having a port for connecting to the control network NW1, a safety input circuit having a plurality of input ports P1 to P4, and a safety output circuit having a plurality of output ports P5 to P8. Each input port receives an input signal from an input device 50 connected to the input port. The input signal is treated as a Boolean variable value (true or false) in the safety program 30. Each output port outputs an output signal (on or off) corresponding to a value calculated by the safety program 30 to an output device 60 connected to the output port.

[0069] <Hardware Configuration of Safety Device 20> FIG. 7 is a diagram showing the hardware configuration of the safety device 20 according to the present embodiment. In FIG. 7, the safety device 20 includes an MPU (Micro Processing Unit) 31, a storage unit 32, a main memory 38 including a non-volatile storage medium, a network interface 29 that controls communication with a control network NW1, a communication interface 27 that controls communication with an information network NW2, a safety control unit 37, a safety input circuit 25 that exchanges data with the safety control unit 37, and a safety output circuit 26. The safety input circuit 25 has input ports P1 to P4 in FIG. 6, and the safety output circuit 26 has output ports P5 to P8 in FIG. 5. The network interface 29 and the communication interface 27 each include a transmission circuit, a reception circuit, and a memory including a buffer that stores data volatilely or non-volatilely.

[0070] The MPU 31 is connected to the network interface 29, the communication interface 27, the storage unit 32, and the duplicated safety control unit, enabling exchanges with these modules.

[0071] The safety control unit 37 has a dual system including a system including a CPU (Central Processing Unit) A33 and a non-volatile memory 35 accessed by the CPU A33, and a system including a CPU B34 and a non-volatile memory 36 accessed by the CPU B34. The CPU A33 and the CPU B34 are each connected to the safety input circuit 25 and the safety output circuit 26. The non-volatile memories 35 and 36 each store the safety program 30 in an executable format and store the TUNID 39.

[0072] The safety control section 37 is multiplexed for safety reasons. When both CPU A33 and CPU B34 execute the same safety program 30, one of the two compares the values ​​calculated by CPU A33 and CPU B34 through execution of the safety program 30, and if the comparison result indicates a match between the two values, that one outputs an output signal of the matched value to the safety output circuit 26. If the comparison result indicates a mismatch, that one determines a value for operating the output device 60 so as to maintain safety, and outputs an output signal of the determined value to the safety output circuit 26.

[0073] The network interface 29 receives frames transmitted over the control network NW1. When the control network NW1 includes multiple safety devices 20 connected in a daisy chain, upon receiving a frame from a device located upstream on the network interface 29, each safety device 20 copies all or part of the data in the frame internally and forwards it to a device located downstream. Similarly, upon receiving a frame from a device located downstream on the network interface 29, the network interface 29 copies all or part of the data in the frame internally and forwards it to a device located upstream. Data transmission between each safety device 20 and the safety controller 100 or the control device 300 is achieved by sequentially forwarding frames in this manner.

[0074] The MPU 31 transfers the frame from the network interface 29 to the safety control unit 37. The CPUs A33 and B34 of the safety control unit 37 respectively compare the TUNID included in the frame with the TUNID 39 stored in the non-volatile memories 35 and 36. When the comparison result indicates that the two TUNIDs match, the frame is accepted and processing according to the control command (safety command) in the frame is executed. However, when the comparison result indicates a mismatch, the frame is discarded. Therefore, the safety controller 100 or the control device 300 can specify the device to be controlled among the plurality of safety devices 20 on the control network NW1 by the TUNID. Also, the safety device 20 can accept only the frames addressed to the self-device among the plurality of frames transmitted through the control network NW1 by using the TUNID 39 set for the self-device, and execute processing according to the safety command of the frame. The safety device 20 sends out the frame storing the result of the processing, the TUNID of the self-device, and the destination on the network interface 29. The destination is, for example, the identifier of the safety controller 100 or the control device 300, and indicates an identifier according to the protocol of the secure communication.

[0075] <F. Configuration of the storage unit> FIG. 8 is a diagram schematically showing an example of information stored in the storage unit 32 of FIG. 7. The storage unit 32 includes an area E1 for storing a system program including an OS, an area E2 for storing the safety programs 30(0) to 30(XX), an area E3 for storing data related to the Web server program 40, and an area E4 for storing application programs and data 73. The number of safety programs 30 stored in the area E2 may be one. The application programs in the area E4 include a command generation program 71 that realizes the command generation unit 22 when executed and a command processing program 72 that realizes the command processing unit 23 when executed. The MPU 31 reads the Web server program 40 and the command generation program 71 from the storage unit 32, expands (loads) them into the main memory 38, and executes them. The safety program in the area E2 and the command processing program 72 in the area E4 are read from the storage unit 32 and expanded into the nonvolatile memories 35 and 36. The CPUs A and B 33 and 34 execute the programs expanded in the nonvolatile memories 35 and 36.

[0076] The data 73 in the area E4 includes the IP address 731 of the safety device 20 and the SNN 732 of the control network NW1 to which the safety device 20 belongs. Note that the storage locations of the IP address 731 and the SNN 732 are not limited to the storage unit 32. For example, as shown in FIG. 7, the IP address 731 may be non-volatilely stored in the communication interface 27 that connects the information network NW2.

[0077] <G. Implementation Example of Modules of Safety Device 20> FIG. 9 is a diagram showing an implementation example of modules in the safety device 20 according to the present embodiment. In FIG. 9, mainly, modules related to executing a safety command based on a user instruction acquired from a web browser 222 are shown. In FIG. 9, the IP address 731 of the safety device 20 is set in a communication interface 27 having a communication port for connecting to an information network NW2. A web server 21 corresponding to a web server program 40 executed by the MPU 31 acquires a user instruction from the web browser 222, and a command generation unit 22 generates a CIP command 51 which is an example of a safety command based on the acquired user instruction. The generated CIP command is executed by a command processing unit 23 corresponding to a command processing program 72 executed by the CPU A 33 and the CPU B 34.

[0078] In the present embodiment, when the web server 21 acquires a user instruction from the web browser 222, the command generation unit 22 is started and set to an executable state. Thus, compared with the case where the command generation unit 22 is always in an executable state, the load on the MPU 31 can be reduced. Further, the command generation unit 22 establishes a connection according to the CIP Safety protocol for exchanging the CIP command 51 between the command generation unit 22 and the command processing unit 23. After the connection for secure communication is established, the CIP command 51 is exchanged. In secure communication, since necessary error checking is performed on the exchanged data, between the command generation unit 22 and the command processing unit 23, the CIP command 51 can be protected from communication risks and errors (such as corruption, deletion, etc.).

[0079] <H. Module Configuration of Safety Device 20> 10 is a diagram showing the module configuration of the safety device 20 according to this embodiment. In FIG. 10, the command generation unit 22 is shown as being independent from the Web server 21, but it may be built into the Web server 21. The command generation unit 22 exchanges data including CIP commands 51 with the command processing unit 23 via the safety communication unit 231. The safety communication unit 231 is a module that is realized when the MPU 31 executes an application program in the storage unit 32.

[0080] The safety communication unit 231 establishes a safety communication connection between the command generation unit 22 and the command processing unit 23. When the safety device 20 communicates with the SNCT 227, the safety communication unit 231 establishes a safety communication connection to exchange CIP commands 51 between the SNCT 227 and the command processing unit 23. The safety communication unit 231 also establishes a safety communication connection between the safety device 20 and the safety controller 100.

[0081] Furthermore, the safety device 20 has a first processing unit 24 that performs safety input / output processing. The first processing unit 24 is a module that is realized by executing the safety program 30, and is configured to include a safety input FB (Function Block) that receives a signal from an input device 50, a safety control FB that processes the value of the input signal, and a safety output FB that outputs a signal of the value resulting from the processing of the safety control FB to an output device 60. The safety program 30 is configured to be able to input instructions of CIP commands 51 and perform processing according to the input instructions.

[0082] The safety program 30 provides several safety functions related to the drive device, such as STO (Safe Torque Off), SS1 (Safe Stop 1), SS2 (Safe Stop 2), and SOS (Safe Operating Stop), as specified in IEC 61800-5-2.

[0083] In this embodiment, the safety program 30 is written using a function block diagram (FBD), but the description format is not limited to this and may be written in any one of a ladder diagram (LD), an instruction list (IL), structured text (ST), and a sequential function chart (SFC), or a combination of these. Furthermore, the safety program 30 may be written in a general-purpose programming language such as JavaScript (registered trademark) or C language.

[0084] The safety program 30 is written as a variable program. Therefore, signals actually exchanged between the safety device 20 and safety components (input devices 50 or output devices 60) are treated as "variables" in the safety program 30. These real signals and the corresponding variables in the safety program 30 are essentially the same, so the signals can be treated as values ​​(values ​​referenced by the variables).

[0085] 10 are configured, for example, by programs stored in the storage unit 32, but instead of this configuration, all or part of these modules may be implemented as hardwired circuits. For example, the functions provided by the processor of the safety device 20 executing the various programs described above may be implemented using an ASIC (Application Specific Integrated Circuit) or FPGA (Field-Programmable Gate Array).

[0086] (h1. First processing section) The first processing unit 24 receives a control command (CIP command) transferred from the safety controller 100 of the control network NW1 via the safety communication unit 231 and executes a first process.

[0087] The first process performed by the first processing unit 24 includes, for example, storing the value of the input signal received from the input device 50 in a frame according to a control command transferred from the safety controller 100, and outputting the frame to the network interface 29 in order to output it to the control system network NW1. The frame includes the value of the input signal and the TUNID 39 of the source safety device 20.

[0088] The first process also includes determining the value of the output signal for operating the output device 60 so as to ensure safety according to the control command in the frame transferred from the safety controller 100.

[0089] <I. Setting of TUNID> In the safety communication according to the CIP Safety protocol, the safety controller 100 and the safety device 20 need to hold the same TUNID. On the other hand, since the TUNID is determined depending on the SNN which is the identification information of the network to which the safety device 20 belongs or the IP address of the safety device 20, when newly adding the safety device 20 to a network or when changing the network to which the safety device 20 belongs, etc., it is necessary to set the TUNID for the safety device 20 from the outside. This setting of the TUNID may involve an operation of deleting the TUNID already set in the safety device 20.

[0090] First, the setting of the TUNID will be described. FIG. 11 is a diagram showing an example of a web screen for TUNID setting according to this embodiment. FIG. 12 is a diagram showing an example of a web screen for IP address setting according to this embodiment. In FIG. 11, when button 119 is operated, a web screen for TUNID setting is displayed based on a web page transferred from web server 21. The web screen includes a window 121 that accepts user operations for SNN setting, a button 124 that is operated to instruct confirmation of the operation in window 121, and a box 125 that displays the TUNID set in safety device 20. Window 121 includes a box 126 that displays an automatically generated SNN, a box 123 for text input of an SNN 732 specified by the user, and a radio button 127. The user can operate radio button 127 to select whether to set the SNN in box 126 or box 123.

[0091] 12, when button 130 is operated, a web screen for setting an IP address is displayed based on a web page transferred from web server 21. The web screen includes button 132 for accepting user settings for an IP address, buttons 133 and 134 for accepting user settings related to DNS (Domain Name Server) settings, and button 135 for confirming the settings in these buttons.

[0092] In this embodiment, the TUNID is obtained by combining the SNN 732 specified by the user's operation on the Web screen of FIG. 11 with the IP address set by the user on the Web screen of FIG.

[0093] (i1.TUNID setting flowchart) 13 and 14 are flowcharts of the TUNID setting process according to this embodiment. In this TUNID setting process, TUNID is set in the safety device 20 using commands such as "Propose_TUNID" and "Apply_TUNID" in accordance with the CIP Safety standard.

[0094] First, on the web screen of Figure 11 displayed on the display 211 of the information processing device 200, when the button 124 instructing the setting is operated, the web browser 222 acquires the SNN set by the user in the window 121 and transfers the user instruction for setting the TUNID together with the acquired SNN to the web server 21 (step S131).

[0095] In the safety device 20, when the Web server 21 receives a user instruction from the Web browser 222, the command generating unit 22 acquires (generates) a "device status read command" based on the user instruction received by the Web server 21 (step S132).

[0096] The command generation unit 22 transmits a "device status read command" to the CPU A33 via the safety communication unit 231. The "device status read command" may be transmitted to the CPU B34 (step S133).

[0097] The CPU A33 searches for the device status from the nonvolatile memory 35 in accordance with the "device status read command." The MPU 31 determines whether the searched device status indicates "Waiting for TUNID" (step S134). "Waiting for TUNID" indicates that TUNID has not been set in the safety device 20. If it is determined that the device status does not indicate "Waiting for TUNID" (NO in step S134), the Web server 21 transfers an error message indicating that TUNID has already been set in the safety device 20 to the Web browser 222 for display on the Web screen (step S135).

[0098] If it is determined that the device status indicates "Waiting for TUNID" (YES in step S134), the command generation unit 22 generates a TUNID by combining the IP address and the SNN based on the user instruction including the SNN that the Web server 21 acquired from the Web browser 222 in step S131, and acquires (generates) a "Propose_TUNID" command for setting the TUNID (step S136). The command generation unit 22 transmits the "Propose_TUNID" command to CPU A33 and CPU B34 via the secure communication unit 231 (step S137).

[0099] In each of CPU A33 and CPU B34, the command processing unit 23 executes processing to store TUNID in the main memory 38 in accordance with the "Propose_TUNID" command. If this storage processing is successful, the command processing unit 23 transmits a "Success" notification to the command generation unit 22. If the command generation unit 22 determines that it has received the "Success" notification (YES in step S138), it proceeds to step S141, which will be described later. If it determines that it has not received the "Success" notification (NO in step S138), the Web server 21 transfers an error message, which indicates that TUNID could not be set in the safety device 20, to the Web browser 222 for display on the Web screen (step S139).

[0100] If it is determined that a "Success" notification has been received (YES in step S138), the command generation unit 22 generates a TUNID by combining the IP address and the SNN based on the user instruction including the SNN that the Web server 21 obtained from the Web browser 222 in step S131, and obtains (generates) an "Apply_TUNID" command for setting the TUNID (step S141 in FIG. 14). The command generation unit 22 transmits the "Apply_TUNID" command to CPU A33 and CPU B34 via the secure communication unit 231 (step S142).

[0101] In each of CPU A33 and CPU B34, the command processing unit 23 compares the received TUNID with the TUNID stored in the main memory 38 in accordance with the "Apply_TUNID" command, and if the comparison results in a match, executes a process of storing the TUNID in the non-volatile memories 35 and 36. If this storage process is successful, the command processing unit 23 sends a "Success" notification to the command generation unit 22. If the command generation unit 22 determines that it has received the "Success" notification (YES in step S143), it proceeds to step S145, which will be described later. If it determines that it has not received the "Success" notification (NO in step S143), the web server 21 transfers an error message, indicating that it was not possible to set the TUNID in the safety device 20, to the web browser 222 to display on the web screen (step S144).

[0102] The command generation unit 22 acquires (generates) a read command for TUNID (step S145) and sends it to CPU A33 and CPU B34 via the secure communication unit 231 (step S146). In CPU A33 and CPU B34, the command processing unit 23 respectively searches for TUNID from nonvolatile memories 35 and 36 in accordance with the read command for TUNID and sends the searched TUNID to the Web server 21.

[0103] The Web server 21 transfers the TUNID retrieved from the nonvolatile memories 35 and 36 to the Web browser 222 for display on the Web screen (step S147). The TUNID retrieved from the nonvolatile memories 35 and 36 is displayed in box 125 on the Web screen in Fig. 11. From the TUNID displayed in box 125, the user can confirm that the TUNID has been successfully set in the safety device 20 and that the TUNID has been set.

[0104] <J.メモリクリア> The setting of the TUNID described above is performed, for example, after deleting the set TUNID from the safety device 20. In this embodiment, the user instructs the safety device 20 to delete the TUNID by operating the web screen. In this embodiment, the process of deleting the TUNID from the non-volatile memories 35 and 36 of the safety device 20 is also referred to as "memory clear," which initializes the memory. When "memory clear" is performed, the device status of the safety device 20 is set to "Waiting for TUNID."

[0105] 15 is a diagram showing an example of a web screen for memory clearing according to the present embodiment. In FIG. 15, when button 160 is operated, a web screen for accepting a user operation for memory clearing is displayed based on a web page transferred from web server 21. The web screen includes box 161 for inputting a password and button 162 operated to instruct the start of memory clearing. In box 161, the user inputs the password set in safety device 20 to initialize it (clear all memory) and then operates button 162.

[0106] (j1. Memory clearing flowchart) 16 and 17 are flowcharts of the memory clear process according to this embodiment. Web browser 222 accepts a user operation of initialization button 160 in FIG. 15 (step S161), and when button 162 on the web screen instructing execution of memory clear is operated, acquires the password set in box 161 (step S162). Web browser 222 transfers the acquired password and the user instruction to clear memory to Web server 21.

[0107] In the safety device 20, it is determined whether the password received by the Web server 21 matches the password set in the safety device 20 (step S163). If it is determined that the passwords do not match (NO in step S163), the Web server 21 transfers an error message indicating that the passwords do not match to the Web browser 222 for display on the Web screen (step S164).

[0108] If it is determined that the passwords match (YES in step S163), command generation unit 22 acquires (generates) a command to read TUNID based on a user instruction to clear memory from Web server 21 (step S165), and transmits the command to read TUNID to CPU A33 and CPU B34 via secure communication unit 231 (step S166). In CPU A33 and CPU B34, command processing unit 23 respectively searches for TUNID from nonvolatile memories 35 and 36 in accordance with the TUNID read command. Based on the search results, it is determined whether or not the read was successful (step S167). If it is determined that the read of TUNID was not successful (NO in step S167), Web server 21 transfers an error message indicating that TUNID has not been set to Web browser 222 for display on the Web screen (step S168).

[0109] If it is determined that the TUNID has been read successfully (YES in step S167), the command generating unit 22 acquires (generates) a "Safety_Reset" command based on the user instruction (step S171).

[0110] In the CIP Safety standard, the reset type (restart / complete clear / clear specific area), password, and TUNID are specified as parameters for the initialization command ("Safety_Reset" command). Since a complete clear is specified on the web screen in FIG. 15, the reset type is not required (fixed) in the parameters of the "Safety_Reset" command. Furthermore, since TUNID can also be obtained from the safety device 20, it does not need to be specified by the user. Therefore, only the password specified by the user on the web screen in FIG. 15 is specified as a parameter of the "Safety_Reset" command.

[0111] The command generation unit 22 transmits the "Safety_Reset" command to CPU A33 and CPU B34 via the safety communication unit 231 (step S172). In CPU A33 and CPU B34, the command processing unit 23 executes processing in accordance with the "Safety_Reset" command. In the processing, TUNID is deleted from nonvolatile memories 35 and 36. If the deletion is successful, the command processing unit 23 transmits a "Success" notification to the command generation unit 22.

[0112] If the command generation unit 22 determines that it has not received a "Success" notification (NO in step S173), the Web server 21 transfers an error message indicating that the TUNID could not be deleted from the safety device 20, i.e., an initialization failure, to the Web browser 222 for display on the Web screen (step S174). If it determines that it has received a "Success" notification (YES in step S173), the Web server 21 transfers an error message indicating that the TUNID could be deleted from the safety device 20, i.e., an initialization completion, to the Web browser 222 for display on the Web screen (step S175).

[0113] The protocol for secure communication applicable to the present embodiment is not limited to CIP Safety, and PROFIsafe (registered trademark), FSoE (Safety over EtherCAT), CC-Link Safety, etc. can be applied.

[0114] According to the present embodiment, by operating the Web screen, the user can set the TUNID 39 in the safety device 20 and also delete the set TUNID 39 from the safety device 20. Therefore, the user can set and delete the TUNID 39 in the safety device 20 without using a dedicated tool. As a result, when the safety device 20 in the safety control system 1 is replaced due to a failure or regular maintenance of the safety device 20, the user can input an can input an instruction to set or delete the TUNID 39 in the safety device 20 to be replaced from the Web screen. This can shorten the time required to establish a secure communication connection between the safety controller 100 and the safety device 20 in the safety control system 1, and the safety control system 1 can be started up earlier.

[0115] <K. Appendix> In this specification, the following configurations are disclosed.

[0116] [Configuration 1] A safety device (20) capable of executing a safety command (51) related to secure communication, a Web server (21) that acquires a user instruction for the safety device, [[ID=Temp19]] and a command generation unit (22) that generates the safety command based on the user instruction acquired by the Web server.

[0117] [Configuration 2] 2. The safety device according to claim 1, wherein the safety command generated by the command generation unit includes a command to set a device identifier (39) for identifying the safety device in the safety communication.

[0118] [Configuration 3] Further provided is a network interface that connects the control device (100, 300) to a network to which the safety device belongs; 3. The safety device of configuration 2, wherein the device identifier is generated by combining an identifier of the network and an IP address of the safety device.

[0119] [Configuration 4] A processing unit (23) that executes processing in accordance with the safety command is further provided, 4. The safety device according to any one of configurations 1 to 3, wherein the command generation unit establishes a connection for exchanging the safety command between the command generation unit and the processing unit.

[0120] [Configuration 5] Further provided is a network interface (29) that connects the control device to a network to which the safety device belongs; the safety commands executable by the safety device include safety commands transferred from the control device via the network; 5. The safety device according to any one of configurations 1 to 4, further comprising a first processing unit (24) that executes a first process in accordance with a safety command transferred from the control device.

[0121] [Configuration 6] further comprising input ports (P1 to P4) for connecting an input device (50); The safety device of configuration 5, wherein the first processing includes a process of outputting the value of an input signal received from the input device to the network via the network interface in accordance with a safety command transferred from the control device.

[0122] [Configuration 7] Further provided are output ports (P5 to P8) for connecting output devices (60), 7. A safety device according to configuration 5 or 6, wherein the first processing includes processing for determining a value of an output signal for operating the output device so as to maintain safety in accordance with a safety command transferred from the control device.

[0123] [Configuration 8] 8. The safety device according to any one of configurations 1 to 7, wherein the Web server activates the command generation unit when the user instruction is acquired.

[0124] [Configuration 9] further comprising a storage unit (35, 36) for storing the device identifier; 4. The safety device according to configuration 2 or 3, wherein the safety command generated by the command generation unit based on the user instruction includes a command to delete the device identifier from the storage unit.

[0125] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]

[0126] 1 Safety control system, 20 Safety device, 21 Web server, 22 Command generation unit, 23 Command processing unit, 24 First processing unit, 25 Safety input circuit, 26 Safety output circuit, 27 Communication interface, 29, 210 Network interface, 30 Safety program, 32 Storage unit, 35, 36 Non-volatile memory, 37 Safety control unit, 38 Main memory, 40 Web server program, 50, 400 Input device, 51 CIP command, 60 Output device, 71 Command generation program, 72 Command processing program, 73 Data, 100, 100A Safety controller, 102, 202 Processor, 104, 204 Main memory, 106 Flash memory, 108 Processing unit, 110 Control system network interface, 112 Information system network interface, 114 Fieldbus interface, 116 Memory card interface, 118 Memory card, 119,124,130,132,133,134,135,160,162 Button, 120,216 Local communication interface, 121 Window, 122 Internal bus interface, 123,125,126,161 Box, 127 Radio button, 200 Information processing device, 206 Operation unit, 208 Output unit, 211 Display, 212 Optical drive, 218 Internal bus, 220 Auxiliary storage device, 222 Web browser, 223 SNCT program, 229 Program, 224,226 System program, 228 Support program, 231 Safety communication unit, 300 Control device, NW1 Control system network, NW2 Information system network, P1~P4 Input ports, P5~P8 Output ports.

Claims

1. A safety device capable of executing safety commands related to safety communication, a web server that acquires user instructions for the safety device; a command generating unit that generates the safety command based on the user instruction acquired by the web server.

2. The safety device according to claim 1 , wherein the safety command generated by the command generation unit includes a command for setting a device identifier for identifying the safety device in the safety communication.

3. Further provided is a network interface that connects the control device to a network to which the safety device belongs, The safety device of claim 2 , wherein the device identifier is generated by combining an identifier of the network and an IP address of the safety device.

4. a processing unit that executes processing in accordance with the safety command; The safety device according to claim 1 or 2, wherein the command generating unit establishes a connection for exchanging the safety command between the command generating unit and the processing unit.

5. Further provided is a network interface that connects the control device to a network to which the safety device belongs, the safety commands executable by the safety device include safety commands transferred from the control device via the network; The safety device according to claim 4 , further comprising a first processing unit that executes a first process in accordance with a safety command transferred from the control device.

6. further comprising an input port for connecting an input device; 6. The safety device according to claim 5, wherein the first processing includes a processing of outputting a value of an input signal received from the input device to the network via the network interface in accordance with a safety command transferred from the control device.

7. further comprising an output port for connecting an output device; The safety device according to claim 5 , wherein the first processing includes a process of determining a value of an output signal for operating the output device so as to maintain safety in accordance with a safety command transferred from the control device.

8. The safety device according to claim 1 , wherein the web server activates the command generating unit when the web server receives the user instruction.

9. further comprising a storage unit for storing the device identifier; The safety device according to claim 2 or 3, wherein the safety command generated by the command generating unit based on the user instruction includes a command to delete the device identifier from the storage unit.

Citation Information

Patent Citations

  • Support device, support program, and setting method

    JP2019174950A