Support device, support method, and program
The support device simplifies safety design compliance by integrating risk assessment and safety-related part configuration, allowing users to efficiently generate and manage necessary documentation for compliance verification.
Patent Information
- Application Number
- JP2024126507
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-02
- Publication Date
- 2026-02-13
AI Technical Summary
Existing safety design systems require specialized knowledge and time to create technical documentation to prove compliance with safety standards, and users need to link device design documents to demonstrate compatibility, which is cumbersome and inefficient.
A support device and method that includes a first generation unit for risk assessment, a second generation unit for safety-related part configuration, and a management unit to associate and manage information, providing user interfaces for easy checking and documentation of safety design compliance.
Enables users to easily check and document safety design compliance, facilitating self-declaration or third-party certification by generating comprehensive safety information and device configuration documents.
Smart Images

Figure 2026024133000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a support device, a support method, and a program that support the safety design of a target device. [Background technology]
[0002] Various types of manufacturing equipment are in operation at manufacturing sites. Manufacturing equipment can contain hazards that can cause harm (injury). Therefore, various safety standards have been established to prevent such hazards. For example, the International Organization for Standardization (ISO) has established ISO 12100 (Safety of machinery - General principles for design - Risk assessment and risk reduction) as a safety standard. The International Electrotechnical Commission has also established IEC 61508 (Functional safety of electrical / electronic / programmable electronic safety-related systems). Generally, manufacturers of manufacturing equipment design their equipment to comply with safety standards, and then obtain certification that there are no compliance issues from a third-party certification body or self-declare that there are no compliance issues.
[0003] Safety design based on safety standards requires specialized knowledge of safety. It also takes time to create technical documentation to prove compliance and to communicate with third-party certification bodies. For this reason, devices to support safety design have been developed. For example, Japanese Patent Laid-Open Publication No. 2009-37520 (Patent Document 1) discloses a consulting device that can select appropriate risk reduction measures depending on the status of hazards. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2009-37520 Summary of the Invention [Problem to be solved by the invention]
[0005] According to the consulting device disclosed in Patent Document 1, a risk assessment sheet is created that includes risk reduction measures selected according to the status of the hazard. However, to prove that there are no problems with compatibility, not only the risk assessment sheet but also information on safety-related parts that embodies risk reduction measures according to the risk level is required. Therefore, the user needs to link a wide range of device design documents to demonstrate compatibility.
[0006] The present disclosure has been made in consideration of the above-mentioned problems, and its purpose is to provide a support device, a support method, and a program that can provide an environment in which users can easily check information related to safety design. [Means for solving the problem]
[0007] According to one example of the present disclosure, a support device that supports safety design of a target device includes a first generation unit, a second generation unit, and a management unit. The first generation unit generates first information including results of a risk assessment for each of one or more hazards included in the target device based on input to a first user interface including a first set of questions according to the risk assessment. The second generation unit generates second information indicating the device configuration and wiring of safety-related parts based on input to a second user interface for supporting the implementation of risk reduction measures for each of the one or more hazards. The management unit manages the first information and the second information in association with each other for each of the one or more hazards.
[0008] According to this disclosure, a user can easily check the results of risk assessment for each of one or more hazards, as well as the device configuration and wiring of safety-related parts. In this way, the support device can provide an environment in which a user can easily check information related to safety design.
[0009] In the above disclosure, the support device further includes an output unit that outputs a first document representing first information corresponding to each of the one or more sources of hazard, and a second document representing second information corresponding to each of the one or more sources of hazard.
[0010] According to this disclosure, the user can use the first document and the second document as documents to be submitted to a third-party certification body to prove that there are no problems with compliance with safety standards.
[0011] In the disclosure above, the first group of questions includes questions regarding a plurality of required items required by a safety standard. The first generator generates first information in response to obtaining answers to all of the required items. The first information includes answers to all of the required items.
[0012] According to this disclosure, a user can easily answer multiple required items required by the safety standard. Furthermore, by checking the first information, the user can easily make a self-declaration or have an evaluation by a third-party certification body based on the contents required by the safety standard.
[0013] In the above disclosure, the support device further includes a determination unit that determines a performance level of the safety-related unit based on input to a third user interface including an index (e.g., DC (Diagnostic coverage)) that evaluates the reliability of each safety device included in the safety-related unit and a second group of questions regarding operating status. The first generation unit determines a required performance level for each of the one or more hazards based on the input to the first user interface. The first information includes the required performance level, the performance level, and a determination result as to whether the performance level satisfies the required performance level.
[0014] According to this disclosure, the user can easily check whether the performance level of the safety-related part satisfies the required performance level by checking the first information.
[0015] In the above disclosure, the second user interface includes a fourth user interface that prompts the user to select multiple safety devices that constitute the safety-related part from multiple candidate safety devices, and a fifth user interface that prompts the user to select terminal pairs to be connected from multiple terminals included in the multiple safety devices.
[0016] According to this disclosure, a user can easily select a plurality of safety devices that constitute a safety-related part and easily design wiring.
[0017] In the above disclosure, the support device further includes an output unit that provides a sixth user interface in response to selection of a target hazard from among the one or more hazards, the sixth user interface displaying first information corresponding to the target hazard and second information corresponding to the target hazard.
[0018] According to this disclosure, the user can easily check the first information and the second information for each hazard.
[0019] In the above disclosure, the support device further includes an output unit that provides a seventh user interface in response to selection of the target safety device, the seventh user interface displaying second information corresponding to the target safety-related part including the target safety device and first information corresponding to the target hazard, among one or more hazards, whose risk is reduced by the target safety-related part.
[0020] According to this disclosure, for each safety device, the user can easily check the equipment configuration and wiring of the safety-related part including the safety device, and the risk assessment results for the hazard sources whose risks are reduced by the safety-related part including the safety device.
[0021] According to one example of the present disclosure, a support method for supporting safety design of a target device includes: i) one or more processors generating, for each of one or more hazards included in the target device, first information including results of conducting a risk assessment based on input to a first user interface including a first set of questions according to the risk assessment; ii) one or more processors generating, for each of the one or more hazards, second information indicating the equipment configuration and wiring of a safety-related part based on input to a second user interface for supporting the implementation of risk reduction measures; and iii) one or more processors managing, in association with each other, the first information and the second information for each of the one or more hazards.
[0022] According to yet another example of the present disclosure, a program causes a computer to execute the support method. Based on these disclosures, the support method and program can also provide an environment in which a user can easily check information related to safety design. [Effects of the Invention]
[0023] According to the present disclosure, the support device, support method, and program can provide an environment in which a user can easily check information related to safety design. [Brief explanation of the drawings]
[0024] [Figure 1] FIG. 1 is a diagram illustrating an example of a system including a support device according to an embodiment. [Figure 2] FIG. 2 is a schematic diagram illustrating an example of a hardware configuration of a support device. [Figure 3] FIG. 2 is a schematic diagram illustrating an example of a functional configuration of a support device. [Figure 4] 10 is a flowchart illustrating an example of a processing flow of a support device. [Figure 5] FIG. 10 is a diagram illustrating an example of a user interface that displays the result of determining restrictions on the target device. [Figure 6] 5 is a flowchart showing an example of a subroutine of step S2 shown in FIG. [Figure 7] FIG. 10 illustrates an example of a user interface including a set of questions regarding hazardous situations. [Figure 8] FIG. 10 is a diagram showing an example of a pull-down menu for each question for identifying a hazard. [Figure 9] FIG. 10 is a diagram showing an example of a pull-down menu of elements that constitute a risk. [Figure 10] FIG. 10 is a diagram illustrating an example of a method for calculating a risk level. [Figure 11] FIG. 10 is a diagram illustrating a method for calculating a required performance level PLr. [Figure 12] FIG. 10 shows an example of a user interface that may be provided to the terminal in step S24. [Figure 13] FIG. 10 illustrates an example of a user interface including a set of questions regarding risk mitigation strategies. [Figure 14] FIG. 10 is a diagram showing an example of a data set for creating a risk assessment sheet. [Figure 15] FIG. 10 is a diagram showing an example of a user interface provided to the terminal in step S27. [Figure 16] 5 is a flowchart showing an example of a subroutine of step S3 shown in FIG. 4. [Figure 17] FIG. 10 is a diagram illustrating an example of a user interface that prompts the user to select a safety device. [Figure 18] FIG. 10 is a diagram illustrating an example of a pop-up window that prompts the user to select a safety device. [Figure 19] FIG. 10 illustrates an example of a user interface that supports wiring. [Figure 20] FIG. 1 is a diagram showing an example of a wiring diagram. [Figure 21] FIG. 1 is a diagram illustrating an example of a block diagram. [Figure 22] 5 is a flowchart showing an example of a subroutine of step S4 shown in FIG. [Figure 23] FIG. 10 is a diagram showing an example of a user interface including a group of questions regarding indicators for evaluating the reliability of each safety device and operational status. [Figure 24] FIG. 10 is a diagram showing an example of a user interface for checking multiple confirmation items related to resistance to CCF. [Figure 25] FIG. 10 is a diagram showing an example of a user interface showing the evaluation result of a performance level PL. [Figure 26] 5 is a flowchart showing an example of a subroutine of step S5 shown in FIG. 4. [Figure 27] FIG. 10 is a diagram showing an example of a user interface that prompts input of values of elements that constitute a risk when a safety measure is implemented by a safety-related part. [Figure 28] FIG. 10 is a diagram showing an example of a user interface showing the risk level and acceptability when a safety measure is implemented by a safety-related part. [Figure 29] FIG. 10 is a diagram illustrating the second process of step S7. [Figure 30] FIG. 10 is a diagram illustrating a third process in step S7. [Figure 31] FIG. 1 illustrates an example of a user interface including a truth table. DETAILED DESCRIPTION OF THE INVENTION
[0025] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present disclosure will be described in detail with reference to the accompanying drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals and the description thereof will not be repeated.
[0026] §1 Application Examples 1 is a diagram illustrating an example of a system including a support device according to an embodiment. The system illustrated in FIG. 1 includes a support device 100 and a terminal 200.
[0027] The support device 100 supports a user in designing the safety of a target device. The target device is a device that includes one or more hazards that can cause harm, such as manufacturing equipment. Users primarily include, but are not limited to, electrical design engineers. The one or more hazards include, for example, rotating mechanisms, heating devices, etc.
[0028] The support device 100 can be realized as one or more computers, a virtual machine built in a cloud environment, or a combination of these. In the example shown in Fig. 1, the support device 100 is a cloud server that provides a tool related to safety design (hereinafter referred to as a "safety design tool") as SaaS (Software as a Service).
[0029] The terminal 200 is connected to the support device 100 via a network and uses a safety design tool provided by the support device 100. The terminal 200 is, for example, a notebook or desktop personal computer (PC), a tablet terminal, a smartphone, or any other information processing device.
[0030] As shown in FIG. 1, the support device 100 includes a first generation unit 10, a second generation unit 11, and a management unit 12.
[0031] The first generation unit 10 provides the terminal 200 with a user interface including a set of questions according to a risk assessment for each of one or more hazards included in the target device. The user answers the set of questions by operating the terminal 200. In this specification, "risk assessment" refers to all processes including risk analysis, risk evaluation, and risk reduction measures. "Risk" indicates the amount of harm and the probability of it occurring. The first generation unit 10 generates first information 50 including the results of the risk assessment for each of one or more hazards based on input to the user interface. The first information 50 typically includes a risk assessment sheet.
[0032] The second generation unit 11 generates second information 60 indicating the device configuration and wiring of a safety-related unit based on input to a user interface for supporting the realization of risk reduction measures for each of one or more hazards included in the target device. The safety-related unit is a part of a control system that provides safety functions. The safety-related unit includes multiple safety devices. The multiple safety devices generally include an input device (Input) that acquires safety-related information, a logic operation device (Logic) that makes safety-related decisions, and an output device (Output) that performs safety-related control. The second information 60 includes information that identifies the multiple safety devices that make up the safety-related unit and information indicating the wiring between the devices.
[0033] The management unit 12 manages the first information 50 and the second information 60 in association with each other for each of one or more hazards included in the target device.
[0034] By using the support device 100 of this embodiment, a user can easily check the results of risk assessment for each of one or more hazards, as well as the device configuration and wiring of safety-related parts. In this way, the support device 100 of this embodiment can provide an environment in which the user can easily check information related to safety design.
[0035] §2 Specific examples <Hardware configuration of the supported device> The hardware configuration of the support device 100 will be described with reference to Fig. 2. Fig. 2 is a schematic diagram showing an example of the hardware configuration of the support device.
[0036] The support device 100 includes one or more processors 102, memory 104, a network controller 106, and storage 110. These components are communicatively coupled to one another via a bus.
[0037] The processor 102 reads out a program stored in the storage 110, expands it in the memory 104, and executes it. The processor 102 includes, for example, a central processing unit (CPU) or a micro-processing unit (MPU). The memory 104 is a volatile memory such as a dynamic random access memory (DRAM) or a static random access memory (SRAM). The storage 110 is a non-volatile memory such as a hard disk or flash memory. The storage 110 stores a system program 112 and a safety design program 114.
[0038] The processor 102 executes the safety design program 114 to provide a safety design tool.
[0039] 2 shows an example in which the necessary processing is realized by the processor 102 executing a program, but some or all of the functions handled by the processor 102 may be replaced by hardwired circuits (for example, an ASIC (Application Specific Integrated Circuit) and an FPGA (Field-Programmable Gate Array)). Also, a SoC (System on Chip) incorporating a processor may be employed.
[0040] In this specification, the term "processor" encompasses processors in the narrow sense, such as CPUs and GPUs, as well as hardwired circuits such as ASICs and FPGAs, DSPs (Digital Signal Processors), and AI (Artificial Intelligence) chips.
[0041] The network controller 106 exchanges data with the terminal 200 etc. Specifically, the network controller 106 provides a user interface to the terminal 200 and receives input to the user interface.
[0042] <Functional configuration of support devices> The functional configuration of the support device 100 will be described with reference to Fig. 3. Fig. 3 is a schematic diagram showing an example of the functional configuration of the support device.
[0043] 3, the support device 100 includes a risk level calculation unit 13, a risk tolerance determination unit 14, a risk reduction measure reception unit 15, a PLr calculation unit 16, a safety device selection unit 17, a pin assignment drawing unit 18, a pin wiring design reception unit 19, a PL determination unit 20, a block diagram creation unit 21, a management unit 12, and an output unit 22. The risk level calculation unit 13, the risk tolerance determination unit 14, the risk reduction measure reception unit 15, and the PLr calculation unit 16 constitute the first generation unit 10 shown in FIG. 1. The safety device selection unit 17, the pin assignment drawing unit 18, the pin wiring design reception unit 19, and the block diagram creation unit 21 constitute the second generation unit 11 shown in FIG. 1. The risk level calculation unit 13, risk tolerance determination unit 14, risk reduction measure reception unit 15, PLr calculation unit 16, safety device selection unit 17, pin assignment drawing unit 18, pin wiring design reception unit 19, PL determination unit 20, block diagram creation unit 21, and output unit 22 are realized by the processor 102 shown in Fig. 2 executing the safety design program 114. The management unit 12 is realized by the processor 102, memory 104, and storage 110 shown in Fig. 2.
[0044] Each unit of the support device 100 creates a user interface 70 and provides it to the terminal 200. Furthermore, each unit of the support device 100 accepts input to the user interface 70 and performs processing according to the input.
[0045] The risk level calculation unit 13 calculates a risk level for each of one or more hazards included in the target device in response to an input to the user interface 70, which includes a group of questions regarding dangerous situations.
[0046] The risk tolerance determination unit 14 determines whether the risk level is within a tolerable range. The tolerable range is determined in advance according to, for example, the social environment of the country in which the target device is used, the policy of the company that manufactures the target device, or the policy of the customer to whom the target device is delivered.
[0047] The risk reduction measure receiving unit 15 receives the risk reduction measure via the user interface 70 in response to the risk level being outside the allowable range.
[0048] The PLr calculation unit 16 calculates a required performance level PLr for each of one or more hazards included in the target device in response to an input to the user interface 70, which includes a group of questions regarding hazardous situations. The required performance level PLr represents the performance required of a safety-related part in response to risk.
[0049] The first generation unit 10 generates first information 50 indicating a risk level, a determination result as to whether the risk level is within an acceptable range, a risk reduction measure, and a required performance level PLr. Furthermore, the first generation unit 10 includes information input to a user interface 70, including a group of questions regarding the dangerous situation, in the first information 50.
[0050] The safety device selection unit 17 selects, for each of one or more hazards included in the target device, a plurality of safety devices that constitute the safety-related part, based on input to the user interface 70. Specifically, the safety device selection unit 17 selects the input devices, logical operation devices, and output devices that constitute the safety-related part.
[0051] The safety device selection unit 17 selects a plurality of safety devices from a plurality of safety device candidates, for example, in response to an input to a user interface including a plurality of safety device candidates. The safety device selection unit 17 stores device data for each of the plurality of safety device candidates in advance. For example, the device data includes data conforming to standard sheet 66413 of the VDMA (German Industrial Machinery Association). A user may import device data for a new safety device candidate into the safety device selection unit 17 from a general-purpose database conforming to standard sheet 66413 of the VDMA. Furthermore, the device data includes device specifications (appearance images and input / output terminal configurations), values for reliability evaluation (for example, B 10D and mean time to dangerous failure (MTTF) D ) is included. B 10D is the number of operations until 10% of the parts fail dangerously.
[0052] The pin assignment drawing unit 18 creates an image object representing each terminal (pin) of the selected plurality of safety devices. The pin assignment drawing unit 18 stores in advance configuration information indicating the configuration of input / output terminals for each of the plurality of safety device candidates, and creates an image object based on the configuration information corresponding to each selected safety device.
[0053] The pin wiring design receiving unit 19 receives a wiring design between the selected plurality of safety devices. Specifically, the pin wiring design receiving unit 19 provides a user interface 70 that includes an image object created by the pin assignment drawing unit 18 and prompts the user to select a pair of terminals to be connected from a plurality of terminals included in the plurality of safety devices. The pin wiring design receiving unit 19 receives the selection of the pair of terminals to be connected via the user interface 70.
[0054] The pin wiring design receiving unit 19 creates a wiring diagram of the safety-related part based on the received wiring design.
[0055] The block diagram creation unit 21 creates a block diagram of a plurality of safety devices that constitute the safety-related part based on the wiring diagram of the safety-related part.
[0056] The second generation unit 11 generates second information 60 including information identifying each of the selected plurality of safety devices, information indicating the wiring design accepted by the pin wiring design acceptance unit 19, information indicating the wiring diagram created by the pin wiring design acceptance unit 19, and information indicating the block diagram created by the block diagram creation unit 21.
[0057] The PL determination unit 20 determines the performance level PL of the safety-related part based on input to the user interface 70, which includes an index for evaluating the reliability of each safety device included in the safety-related part and a group of questions regarding the operating status. For example, DC (Diagnostic Coverage) can be used as an index for evaluating the reliability of the safety devices. DC (Diagnostic Coverage) is also called "diagnostic coverage." The performance level PL is defined in ISO 13849-1. Furthermore, the PL determination unit 20 determines whether the performance level PL is equal to or greater than the required performance level PLr.
[0058] The PL determining unit 20 includes in the first information 50 the performance level PL and the determination result as to whether the performance level PL is equal to or greater than the required performance level PLr.
[0059] In response to a request from a user, the output unit 22 outputs the first information 50 and the second information 60. For example, the output unit 22 outputs a document representing the first information 50 and a document representing the second information 60. Alternatively, the output unit 22 outputs a user interface including the first information 50 and the second information 60 to the terminal 200.
[0060] <Support device processing flow> 4 is a flowchart showing an example of the processing flow of the support device. As shown in FIG. 4, in step S1, the processor 102 determines the restrictions of the target device. Specifically, the processor 102 provides a user interface that prompts input of the restrictions of the target device, and determines the restrictions of the target device according to the input to the user interface. The restrictions of the target device include restrictions on use, space, and time.
[0061] Fig. 5 is a diagram showing an example of a user interface showing the determination result of the restrictions on the target device. User interface 70A shown in Fig. 5 is created by processor 102 after completion of step S1 and provided to terminal 200. As shown in Fig. 5, processor 102 determines the name, specifications, purpose, and target users who will use the target device as the restrictions on the target device.
[0062] 4, after step S1, a loop process L1 is executed for each of one or more hazards included in the target device. The loop process L1 includes steps S2 to S6.
[0063] In step S2, the processor 102 operating as the first generator 10 generates first information 50 including the results of the risk assessment based on input to a user interface including a group of questions according to the risk assessment.
[0064] In the next step S3, the processor 102 operating as the second generation unit 11 generates second information 60 indicating the equipment configuration and wiring of the safety-related parts based on input to a user interface to assist in the implementation of risk reduction measures.
[0065] In the next step S4, the processor 102 operating as the PL determining unit 20 evaluates the performance level PL of the safety-related part. The evaluation result of the performance level PL is included in the first information 50.
[0066] In the next step S5, the processor 102 operating as the first generator 10 estimates the risk when the risk reduction measure is implemented based on an input to a user interface including a group of questions regarding the dangerous situation after the risk reduction measure is implemented. The result of estimating the risk when the risk reduction measure is implemented is included in the first information 50.
[0067] In the next step S6, the processor 102 operating as the management unit 12 manages the first information 50 and the second information 60 in the memory 104 or the storage 110 in association with each other.
[0068] When the loop process L1 for all of the one or more hazards included in the target device is completed, in step S7, the processor 102 outputs the first information 50 and the second information 60 in response to a request from the user.
[0069] <Subroutine of Step S2> The subroutine of step S2 will be described with reference to Figures 6 to 15. Figure 6 is a flowchart showing an example of the subroutine of step S2 shown in Figure 4.
[0070] First, in step S21, the processor 102 operating as the first generator 10 provides the terminal 200 with a user interface including a group of questions relating to dangerous situations.
[0071] Fig. 7 is a diagram showing an example of a user interface including a group of questions regarding dangerous situations. User interface 70B shown in Fig. 7 is an example of the "first user interface" of the present disclosure. User interface 70B includes input fields 71a to 71f and 72a to 72c for inputting answers to the group of questions regarding dangerous situations.
[0072] The input fields 71a to 71f are used to input answers to questions for identifying hazards. Specifically, the input fields 71a to 71f are used to input "type of hazard," "cause," "result," "body part," "hazardous state," and "hazardous event," respectively.
[0073] Input fields 72a to 72c are used to input the elements that make up risk. The safety standard ISO13849-1 specifies a method for estimating risk based on the magnitude of each of the following: "Severity of Harm," "Frequency and / or Duration of Exposure to Hazard," and "Probability of Avoiding Hazard or Limiting Harm." Therefore, input fields 72a to 72c are used to input "Severity of Harm (S)," "Frequency of Exposure to Hazard (F)," and "Avoidance of Hazard (P)," respectively, to conform to the safety standard. The elements that make up risk are used to calculate the risk level. Therefore, the elements that make up risk are also called explanatory variables of the risk level.
[0074] 6, in the next step S22, the user inputs answers to the questions for identifying hazards in input fields 71a to 71f. To support user input, processor 102 may provide pull-down menus corresponding to some of the input fields. This allows the user to select a desired option from the pull-down menu.
[0075] Fig. 8 is a diagram showing an example of a pull-down menu for each question for identifying a hazard. As shown in Fig. 8, the user interface 70B has pull-down menus 73a to 73d corresponding to the input fields 71a to 71d, respectively.
[0076] Annex B of ISO12100 lists types of hazards. Therefore, the pull-down menu 73a is created in advance so as to match the list of "types of hazards" listed in Annex B of ISO12100.
[0077] Furthermore, in Annex B of ISO 12100, hazards are expressed by a combination of "causes" and "consequences" according to the type of hazard. For example, Annex B of ISO 12100 lists "acceleration, deceleration," "edgy parts," etc. as causes of "mechanical hazards." Annex B of ISO 12100 lists "being run over," "being thrown out," etc. as consequences of "mechanical hazards." Therefore, when input field 71b is operated with "mechanical hazard" entered in input field 71a, user interface 70B displays pull-down menu 73b that matches the list of "causes" of "mechanical hazards" specified by ISO 12100. Similarly, when input field 71c is operated with "mechanical hazard" entered in input field 71a, user interface 70B displays pull-down menu 73c that matches the list of "consequences" of "mechanical hazards" specified by ISO 12100.
[0078] Thus, the questions included in user interface 70B include questions about multiple essential items required by safety standards. By using pull-down menus 73a to 73c, the user can enter desired options from the list of "hazard type," "cause," and "result" specified by ISO 12100 into input fields 71a to 71c.
[0079] The pull-down menu 73d is pre-populated to include a list of potential main body parts that may be harmed.
[0080] The user interface 70B can accept any character string in the input fields 71e and 71f (see FIG. 7). The user can input a character string representing a dangerous state into the input field 71e and a character string representing a dangerous event into the input field 71f. A "dangerous state" refers to a situation in which a person is exposed to a source of danger. A "dangerous event" refers to an event that results from a dangerous state and leads to harm.
[0081] 6, in the next step S23, the user inputs values of the elements that constitute the risk (explanatory variables of the risk level) into input fields 72a to 72c. To support user input, processor 102 may provide a pull-down menu corresponding to each input field. This allows the user to select a desired option from the pull-down menu.
[0082] FIG. 9 is a diagram showing an example of a pull-down menu for elements constituting a risk. The user interface 70B has pull-down menus 74 corresponding to each of the input fields 72a to 72c. In the example shown in FIG. 9, only the pull-down menu 74 corresponding to the input field 72c is shown. The pull-down menu 74 corresponding to the input field 72a includes options "S1: Minor injury" and "S2: Serious injury." The pull-down menu 74 corresponding to the input field 72b includes options "F1: Rare" and "F2: Frequent." The pull-down menu 74 corresponding to the input field 72c includes options "P1: Possible under certain conditions" and "P2: Almost impossible."
[0083] The user can easily input values for the elements that make up the risk (explanatory variables for the risk level) by using the pull-down menu 74. In this way, even if the user has little knowledge of safety standards, the user can easily answer questions about multiple essential items required by the safety standards for identifying hazards and estimating risks via the user interface 70B.
[0084] Returning to FIG. 6, in the next step S24, processor 102 estimates risk and outputs the risk level, acceptability, and required performance level. To estimate risk, at least input is required into input fields corresponding to multiple required items required by the safety standard. Therefore, processor 102 starts step S24 of estimating risk when answers to all of the multiple required items have been obtained. In this embodiment, processor 102 starts step S24 when answers to all of input fields 71a to 71f and 72a to 72c have been obtained.
[0085] FIG. 10 is a diagram showing an example of a method for calculating a risk level. The calculation method shown in FIG. 10 uses a classification chart method (risk graph method). The processor 102 calculates the risk level by selecting a branch path from the starting point according to the values of the explanatory variables of the risk level. For example, in the example shown in FIG. 10, if "S2: Serious injury," "F1: Rare," and "P2: Almost impossible" are input, the processor 102 calculates a risk level of "3." Note that the method for calculating the risk level is not limited to the classification chart method. For example, a matrix method or a point method can be used to calculate the risk level. These calculation methods are also introduced in the "Guidelines for Surveys on Danger or Harmfulness, etc." published by the Ministry of Health, Labor, and Welfare.
[0086] The processor 102 determines whether the risk level is within an acceptable range. The acceptable range is determined in advance according to the social environment of the country in which the target device is used, the policy of the company that manufactures the target device, the policy of the customer of the target device, etc.
[0087] FIG. 11 is a diagram illustrating a method for calculating the required performance level PLr. As shown in FIG. 11, the processor 102 calculates the required performance level PLr by using a classification chart method (risk graph method) to select a branch path from the starting point according to the value of the explanatory variable of the risk level. The required performance level PLr is classified into one of five levels of indicators, "a" to "e." The method for determining the required performance level PLr is shown in Annex A of ISO 13849-1. For example, in the example shown in FIG. 11, when "S2: Serious Injury," "F1: Rare," and "P2: Almost Impossible" are input, the processor 102 calculates the required performance level PLr as "d."
[0088] In step S24, the processor 102 may provide the terminal 200 with a user interface that indicates the risk level, acceptability, and required performance level PLr.
[0089] 12 is a diagram showing an example of a user interface that may be provided to the terminal in step S24. As shown in FIG. 12, a user interface 70C shows the risk levels “IV” and “unacceptable” and the required performance level PLr “d.”
[0090] Returning to FIG. 6, in the next step S25, the processor 102 provides the terminal 200 with a user interface including a set of questions regarding risk reduction measures.
[0091] FIG. 13 is a diagram illustrating an example of a user interface including a group of questions regarding risk reduction measures. User interface 70D illustrated in FIG. 13 is an example of the “first user interface” of the present disclosure. ISO 12100 specifies a three-step method for designing risk reduction measures. The three-step method involves performing the following steps in this order: a first step for determining “intrinsic safety design measures,” a second step for determining “safeguarding measures” and “additional protective measures,” and a third step for determining “information for use.” Therefore, as illustrated in FIG. 13, user interface 70D includes input fields 75a to 75e in accordance with the three-step method specified in ISO 12100. Input field 75a is used to input the “intrinsic safety design measures.” Input field 75b is used to input the “safeguarding measures.” Input field 75c is used to input details of the “safeguarding measures.” Input field 75d is used to input the “additional protective measures.” Input field 75e is used to input the “information for use.”
[0092] Returning to FIG. 6, in the next step S26, the user inputs answers to the questions regarding risk reduction measures in input fields 75a to 75e. To support the user's input, processor 102 provides pull-down menus 76 corresponding to each of input fields 75a, 75b, 75d, and 75e. This allows the user to select a desired option from pull-down menu 76. Note that only pull-down menu 76 corresponding to input field 75d is displayed in FIG. 13.
[0093] ISO12100 lists examples of "intrinsically safe design measures." Therefore, in response to an operation on input field 75a, user interface 70D displays pull-down menu 76 containing options for the "intrinsically safe design measures" listed in ISO12100.
[0094] The following measures are known as typical examples of "safeguarding measures." -Fixed guard is used. · Use detection and protection equipment (safety light curtains, safety laser scanners, safety mats, etc.). -Uses a movable guard with interlock. Therefore, in response to an operation on the input field 75b, the user interface 70D displays a pull-down menu 76 including these measures as options. Note that the user interface 70D accepts input of any character string that indicates the details of the "safeguarding measures" in the input field 75c.
[0095] The following measures are known as typical examples of "additional protection measures." -Install an emergency stop function in a location that is quickly accessible. · Install a lockable shutoff device. Therefore, in response to an operation on the input field 75d, the user interface 70D displays a pull-down menu 76 that includes these measures as options.
[0096] ISO 12100 lists examples of "usage information" to alert device users and inform them of appropriate device handling procedures. Therefore, in response to an operation on input field 75e, user interface 70D displays a pull-down menu containing options for "usage information" listed in ISO 12100.
[0097] The user interface 70D includes a button 77 for instructing the generation of the first information 50. In response to the button 77 being pressed, the subroutine of S2 proceeds to step S27.
[0098] In step S27, the processor 102 generates and saves a data set for creating a risk assessment sheet as the first information 50. As described above, the user interfaces 70B and 70D include input fields for questions regarding multiple mandatory items required by safety standards. Therefore, the processor 102 operating as the first generator 10 generates a data set for creating a risk assessment sheet as the first information 50 in response to obtaining answers to all of the input fields in the user interfaces 70B and 70D.
[0099] FIG. 14 is a diagram showing an example of a dataset for creating a risk assessment sheet. As shown in FIG. 14, dataset 50a shows the contents of multiple items included in each of five categories: "Accident Scenario," "Risk Estimation (Initial Risk)," "Risk Reduction," "Risk Estimation (After Risk Reduction)," and "Final Risk Assessment." Data set 50a is created for each hazard. FIG. 14 shows dataset 50a corresponding to hazard "No. 1."
[0100] The processor 102 sets the inputs into the input fields 71a to 71f in FIG. 7 as the contents of the items "Type," "Cause," "Result," "Human Body Part," "Dangerous State," and "Dangerous Event," which belong to the classification "Accident Scenario" in the dataset 50a.
[0101] 7 as the contents of the items "Severity of Harm," "Frequency of Exposure to Hazard," and "Avoidance of Hazard," which belong to the classification "Risk Estimation (Initial Risk)" in data set 50a. Furthermore, processor 102 sets the risk level, required performance level PLr, and acceptability output in step S24 as the contents of the items "Risk Level," "PLr," and "Risk Assessment," which belong to the classification "Risk Estimation (Initial Risk)," in data set 50a.
[0102] Processor 102 sets the inputs into input fields 75a to 75e in Figure 13 as the contents of the items "intrinsic safety design," "safety protection measures," "safety protection details," "additional protection measures," and "usage information," which belong to the classification "risk reduction" in dataset 50a.
[0103] In this way, the processor 102 operating as the first generation unit 10 includes answers to a plurality of essential items required by the safety standard for risk assessment in the first information 50. As a result, by checking the first information 50, the user can easily make a self-declaration or have an evaluation by a third-party certification body based on the content required by the safety standard.
[0104] In step S2, processor 102 cannot determine the items in dataset 50a that belong to the categories "Risk Estimation (After Risk Reduction)" and "Final Risk Assessment." Therefore, in step S27, processor 102 sets the contents of these items in dataset 50a to blank.
[0105] In step S27, the processor 102 provides the terminal 200 with a user interface including a risk assessment sheet created based on the data set 50a.
[0106] 15 is a diagram showing an example of a user interface provided to the terminal in step S27. As shown in FIG. 15, user interface 70E includes areas 78 and 79. Area 78 displays the content of each item in the risk assessment sheet created based on dataset 50a. Area 79 includes five check boxes corresponding to the five classifications in dataset 50a. Processor 102 displays in area 78 only the items in the classifications corresponding to the checked check boxes in area 79.
[0107] The user interface 70E includes a menu icon 81. The menu icon 81 is used to transition to a user interface that supports the instantiation of a safety-related part. That is, in response to an operation of the menu icon 81, the processor 102 advances the process to step S3.
[0108] <Subroutine of Step S3> The subroutine of step S3 will be described with reference to Figures 16 to 21. Figure 16 is a flowchart showing an example of the subroutine of step S3 shown in Figure 4.
[0109] First, in step S31, the processor 102 operating as the second generation unit 11 provides the terminal 200 with a user interface that prompts the user to select a safety device.
[0110] FIG. 17 is a diagram showing an example of a user interface that prompts the user to select a safety device. The user interface 70F shown in FIG. 17 is an example of a "second user interface" of the present disclosure. The user interface 70F includes an input field 82 for selecting a category. The "category" represents the classification of the circuit structure (architecture) of the safety-related part. The categories include "Category B," "Category 1," "Category 2," "Category 3," and "Category 4."
[0111] "Category B" safety-related parts are required to be able to perform the intended safety functions. "Category 1" safety-related parts are required to be highly reliable in addition to being able to perform the intended safety functions. "Category B" or "Category 1" safety-related parts have a single-channel structure that includes only one signal system: input device - logic operation device - output device.
[0112] "Category 2" safety-related parts are required to have a supplementary inspection function that can compensate for the loss of safety function due to a dangerous failure. "Category 2" safety-related parts have a single channel structure and also an inspection function. The inspection function includes inspection equipment and equipment for outputting the inspection results.
[0113] "Category 3" safety-related parts are required to maintain the safety function as a whole even if a failure occurs in a part of the safety function. "Category 4" safety-related parts are required to maintain the safety function even if a certain number of failures accumulate. "Category 3" or "Category 4" safety-related parts have a two-channel structure with redundant signal systems.
[0114] 16, in the next step S32, the user inputs a desired category in the input field 82. The user may select a category in consideration of the risk level and the required performance level PLr.
[0115] In response to a category input into the input field 82, the processor 102 updates the user interface 70F to include blocks 83 corresponding to each of the multiple safety devices that make up the safety-related part of the input category. In the example shown in FIG. 17, "Category 3" has been input. The safety-related part of "Category 3" has a two-channel structure with redundant signal systems. As an example, the user interface 70F includes two blocks 83a corresponding to input devices, one block 83b corresponding to a logic operation device, and two blocks 83c corresponding to output devices.
[0116] Returning to FIG. 16, in the next step S33, the user operates block 83 to input the model number of each safety device that constitutes the safety-related part.
[0117] In response to clicking on block 83, processor 102 provides terminal 200 with a pop-up window prompting the selection of a safety device.
[0118] FIG. 18 is a diagram showing an example of a pop-up window that prompts the user to select a safety device. The pop-up window 70G shown in FIG. 18 is an example of the "second user interface" and "fourth user interface" of the present disclosure. The pop-up window 70G is displayed in response to clicking on a block 83a corresponding to an input device. The pop-up window 70G includes a list 85 of multiple safety device candidates. In response to selecting one safety device from the list 85, the pop-up window 70G displays a list 86 of models of the selected safety device. The list 86 includes radio buttons 86a corresponding to each model. The user selects the desired model by operating the radio button 86a. The pop-up window 70G includes a button 87 for completing the selection input. In response to pressing the button 87, the subroutine proceeds to step S34.
[0119] Each safety device may be composed of multiple units. For example, a logical operation device may be composed of an input unit, a CPU unit, and an output unit. In this case, the user selects multiple units.
[0120] 16, in step S34, the processor 102 reads out the configuration information corresponding to the model of the selected safety device and identifies the arrangement and connection method of the terminals of the safety device. The connection method indicates the conditions for connectable terminal pairs, the number of wires required between the devices, etc.
[0121] In the next step S35, the processor 102 provides a user interface that supports wiring. Specifically, the processor 102 generates a graphical object that represents each terminal (pin) of the selected plurality of safety devices. The processor 102 provides a user interface that includes the graphical object and prompts the user to select a pair of terminals to be connected from among the plurality of terminals included in the plurality of safety devices.
[0122] FIG. 19 is a diagram illustrating an example of a user interface that supports wiring. A user interface 70H illustrated in FIG. 19 is an example of the "second user interface" and the "fifth user interface" of the present disclosure. The user interface 70H includes image objects 80, 88a to 88d as image objects that represent the terminals (pins) of each of a plurality of safety devices. The image object 80 represents the arrangement of the terminals included in the logical operation device. The image object 88a represents a list of terminals of the input device "aaa." The image object 88b represents a list of terminals of the input units that constitute the logical operation device. The image object 88c represents a list of terminals of the output units that constitute the logical operation device. The image object 88d represents a list of terminals of the output device. To accommodate a safety-related part having a two-channel structure, the number of image objects 88a and 88d corresponding to each of the input device and the output device is two.
[0123] The user interface 70H displays terminal objects 89 corresponding to each terminal in the list indicated by the image objects 88a to 88d near the image objects 88a to 88d. The terminal objects 89 are used to select a pair of terminals to be connected.
[0124] Returning to Fig. 16, in the next step S36, the user selects a pair of terminals to be connected from among a plurality of terminals included in a plurality of safety devices. Specifically, the user performs an operation on the user interface 70H shown in Fig. 19 to connect two terminal objects 89 corresponding to the pair of terminals to be connected with a line. This results in wiring between the two terminal objects 89. In the example shown in Fig. 19, terminal objects 89a and 89b are selected as the two terminal objects 89 corresponding to the pair of terminals to be connected.
[0125] In order to prevent incorrect wiring designation, when a terminal object 89 is selected, the user interface 70H may highlight terminal objects 89 corresponding to one or more terminals connectable to the terminal corresponding to the terminal object 89. The highlighted terminal objects 89 are identified based on the conditions for connectable terminal pairs. The conditions are indicated by configuration information corresponding to the type of selected safety device. For example, as shown in FIG. 19 , when a cursor 90 is placed over a terminal object 89c, the user interface 70H highlights terminal objects 89d corresponding to each of one or more terminals connectable to the terminal corresponding to the terminal object 89c.
[0126] Furthermore, the user interface 70H may output a message prompting the user to specify wiring when fewer than the required number of wirings have been specified. For example, when the number of wirings between the image object 88c and the image object 88d is less than the required number, the user interface 70H displays a message indicating that the logic operation device and the output device are not wired.
[0127] The user interface 70H updates the image object 80 in accordance with the wiring designation. The image object 80 schematically shows the surface on which the input / output terminals of the logic operation device are arranged, with each terminal being shown as a circle corresponding to its position. The user interface 70H differentiates the display mode of the terminals designated for wiring from the display mode of the remaining terminals. The display mode may include, for example, color, gradation, hatching, shape, whether or not to blink, etc.
[0128] In response to the completion of the selection of the terminal pairs to be connected, in the next step S37, the processor 102 creates a wiring diagram of the safety-related parts based on the selection and saves the created wiring diagram as the second information 60.
[0129] Fig. 20 is a diagram showing an example of a wiring diagram. A wiring diagram 60a shown in Fig. 20 shows wiring between an input device "safety curtain aaa", a logical operation device "bbb", and an output device "safety relay ccc". For example, the wiring diagram 60a shows that a terminal "OSSD1" of the input device is wired to a terminal "Si0" of the logical operation device.
[0130] 16, in the next step S38, the processor 102 creates a block diagram of the plurality of safety devices that make up the safety-related part based on the wiring diagram 60a of the safety-related part, and saves the created block diagram as second information 60. After step S38 is completed, the processing proceeds to step S4.
[0131] Fig. 21 is a diagram showing an example of a block diagram. A block diagram 60b shown in Fig. 20 shows that the safety-related part includes an input device "safety curtain aaa", a logical operation device "bbb", and an output device "safety relay ccc", and has a two-channel structure.
[0132] <Subroutine of step S4> The subroutine of step S4 will be described with reference to Figures 22 to 25. Figure 22 is a flowchart showing an example of the subroutine of step S4 shown in Figure 4.
[0133] First, in step S41, the processor 102 operating as the PL determination unit 20 provides the terminal 200 with a user interface including a set of questions regarding the diagnostic range and operating status of each safety device included in the safety-related unit.
[0134] FIG. 23 is a diagram illustrating an example of a user interface including a group of questions regarding the operational status and indicators for evaluating the reliability of each safety device. The user interface 70I illustrated in FIG. 23 is an example of a “third user interface” of the present disclosure. The user interface 70I includes an input field for inputting the diagnostic coverage (DC) of each safety device. “Diagnostic coverage (DC)” is a parameter indicating the probability of detecting a dangerous failure in a safety-related part. If the safety device includes multiple units, the user interface 70I may accept input of the diagnostic coverage for each of the multiple units. In the example illustrated in FIG. 23, the user interface 70I includes two input fields 91a corresponding to the two channels of the input device, three input fields 91b corresponding to the three units constituting the logic operation device, and two input fields 91c corresponding to the two channels of the output device.
[0135] Furthermore, the user interface 70I includes input fields 92a-92c and 93a-93c for inputting the operating status of the safety devices. The input fields 92a-92c accept input of the average time interval between one operation cycle, the operating hours per day, and the number of operating days per year for the input devices. The input fields 93a-93c accept input of the average time interval between one operation cycle, the operating hours per day, and the number of operating days per year for the output devices.
[0136] The user interface 70I includes display fields 92d and 93d. The display field 92d displays the total number of times the input device has been operated per year. The display field 93d displays the total number of times the output device has been operated per year.
[0137] Returning to FIG. 22, in the next step S42, the user inputs the DC (Diagnostic coverage) of each safety device in the input fields 91a to 91c.
[0138] In the next step S43, the user inputs the operating status of the safety devices into input fields 92a-92c and 93a-93c. Specifically, the user inputs the average time interval between one operation cycle, the operating hours per day, and the number of operating days per year for the input devices into input fields 92a-92c. Furthermore, the user inputs the average time interval between one operation cycle, the operating hours per day, and the number of operating days per year for the output devices into input fields 93a-93c.
[0139] The user interface 70I updates the value displayed in the display field 92d in response to inputs made to the input fields 92a to 92c. Specifically, the user interface 70I updates the value t cycle , the value h entered in the input field 92b op , and the value d entered in the input field 92c op The value n obtained by substituting op is displayed in the display field 92d. Similarly, the user interface 70I updates the values displayed in the display field 93d in response to inputs made to the input fields 93a to 93c.
[0140]
number
[0141] In the next step S44, the processor 102 calculates the mean time to dangerous failure (MTTF) for each safety device. D Calculate the mean time to dangerous failure (MTTF). D is the average time it takes to cause a dangerous failure. Specifically, the processor 102 calculates the mean time to dangerous failure (MTTF) for each safety device according to the following formula (2): D Calculate B 10D is the number of operations until 10% of the parts fail dangerously, and is included in the equipment data corresponding to the safety equipment.
[0142]
number
[0143] In the next step S45, the processor 102 provides the terminal 200 with a user interface for checking a plurality of check items related to resistance to Common Cause Failures (CCFs).
[0144] In the next step S46, the user checks, on the user interface, the check items that apply to the safety-related part among the plurality of check items.
[0145] Fig. 24 is a diagram showing an example of a user interface for checking multiple check items related to resistance to CCF. The user interface 70J shown in Fig. 24 displays multiple check items according to the list of measures for reducing CCF provided in Annex F of ISO 13849-1. Furthermore, the user interface 70J includes check boxes 94 for each of the multiple check items. The user checks the check boxes 94 corresponding to the check items that apply to safety-related parts.
[0146] 22, in the next step S47, processor 102 calculates the CCF score based on the check results of check boxes 94 for the multiple check items. A score is assigned to each of the multiple check items in advance. Processor 102 calculates the CCF score by adding up the scores assigned to the check items for which check boxes 94 are checked.
[0147] In the next step S48, the processor 102 calculates the performance level PL of the safety-related part. Specifically, the processor 102 calculates the mean time to dangerous failure (MTTF) for each category and safety device input in the input field 82 shown in FIG. D , and D.C.avg Based on this, the probability of a dangerous failure occurring per unit time (PFH) is calculated for each subsystem that constitutes the safety-related part. D "Subsystem" refers to a functional unit that corresponds to the characteristics of a safety-related part. For example, the input devices, logic operation devices, and output devices that make up a safety-related part are each set up as a subsystem. Note that ISO / TR23849 allows subsystems with the same configuration to be combined together. Therefore, for example, input devices and output devices can be combined into the same subsystem.
[0148] DC avg is calculated by averaging the diagnostic ranges (DC) of one or more safety devices that make up the subsystem. Specifically, the processor 102 calculates DC based on the following equation (3): avg In equation (3), DCi represents the DC of the i-th safety device. MTTF D i is the mean time to dangerous failure (MTTF) of the ith safety device D Shows.
[0149]
number
[0150] Category, Mean Time to Dangerous Failure (MTTF) D , D.C. avg , and probability PFH D The relationship between the above is shown in Annex K of ISO13849-1. The processor 102 calculates the probability PFH for each subsystem using the information representing the relationship. D It is sufficient to identify the following.
[0151] The processor 102 calculates the probability PFH for each subsystem. D The performance level PL of the entire safety-related part is determined from the sum of the probability PFH D The relationship between the performance level PL and the parameter .DELTA..times ...
[0152] In the next step S49, the processor 102 determines whether or not PLr≦PL is satisfied. After step S49 is completed, the process proceeds to step S5. Note that, after completing step S49, the processor 102 may provide a user interface that shows the evaluation result of the performance level PL.
[0153] 25 is a diagram showing an example of a user interface showing the evaluation result of the performance level PL. As shown in FIG. 25, the user interface 70K displays the required performance level PLr, the performance level PL, the determination result of whether or not PLr≦PL is satisfied, and the probability PFH for each subsystem. D The sum of (in the figure, simply "PFH D ") and CCF score (simply "CCF" in the figure).
[0154] <Subroutine of Step S5> The subroutine of step S5 will be described with reference to Figures 26 to 28. Figure 26 is a flowchart showing an example of the subroutine of step S5 shown in Figure 4.
[0155] First, in step S51, the processor 102 operating as the first generation unit 10 provides the terminal 200 with a user interface that prompts input of values of elements (explanatory variables of the risk level) that constitute the risk when risk reduction measures are implemented by the safety-related unit.
[0156] FIG. 27 is a diagram showing an example of a user interface that prompts the user to input values of elements that constitute risk when a safety measure by a safety-related part is implemented. As shown in FIG. 27, the user interface 70L includes input fields 95a to 95e and a radio button 95f. The input fields 95a to 95c are used to input the "severity of harm (S)," "frequency of exposure to hazard (F)," and "avoidance of hazard (P)," respectively, similar to the input fields 72a to 72c shown in FIG. 7. The input field 95d is used to input any comments. The input field 95e is used to input character strings that identify reference documents and reference standards. The radio button 95f is used to input whether further risk reduction is required.
[0157] 26, in the next step S52, the user inputs values of the elements that make up the risk (explanatory variables of the risk level) into input fields 95a to 95c. Furthermore, the user operates radio button 95f and fills in the necessary information into input fields 95d and 95e.
[0158] In the next step S53, the processor 102 estimates the risk based on the inputs in the input fields 96a to 96c, and calculates the risk level.
[0159] In the next step S54, the processor 102 determines whether the risk level is within an acceptable range. At this time, the processor 102 may provide the terminal 200 with a user interface indicating the risk level and whether it is acceptable.
[0160] 28 is a diagram showing an example of a user interface that indicates the risk level and whether it is acceptable when a safety measure is implemented by a safety-related part. A user can check the risk level and whether it is acceptable via user interface 70M shown in FIG.
[0161] 26, in the next step S55, the processor 102 updates the first information 50. After step S55 ends, the process proceeds to step S6.
[0162] Specifically, processor 102 sets the contents of the items belonging to the categories "Risk Estimation (After Risk Reduction)" and "Final Risk Assessment" of data set 50a shown in FIG. 14. That is, processor 102 sets the values entered in input fields 95a to 95c shown in FIG. 27 as the contents of the items "Severity of Harm," "Frequency of Exposure to Hazard," and "Avoidance of Hazard" belonging to the category "Risk Estimation (After Risk Reduction)." Furthermore, processor 102 sets the necessity selected by radio button 95f as the contents of the item "Necessary Further Risk Reduction" belonging to the category "Risk Estimation (After Risk Reduction)." Processor 102 sets the character strings entered in input fields 95d and 95e as the contents of the items "Free Comments" and "References and Standards" belonging to the category "Risk Estimation (After Risk Reduction)," respectively.
[0163] Furthermore, the processor 102 sets the risk level calculated in step S53, the judgment result of step S54, the performance level PL, and the judgment result of whether PLr≦PL is satisfied as the contents of the items “Risk Level,” “Final Risk Assessment,” “PL,” and “PLr≦PL,” which belong to the category “Final Risk Assessment.”
[0164] <Processing example of step S7> In step S7, the processor 102 may perform, for example, the following first to third processes.
[0165] (First process) The processor 102 outputs a first document representing first information 50 corresponding to each of one or more hazards for the target device, and a second document representing second information 60 corresponding to each of the one or more hazards. Specifically, the processor 102 outputs a file representing the first document and a file representing the second document. Alternatively, the processor 102 outputs a single file that combines the first document and the second document. The file has, for example, a PDF format.
[0166] (Second process) FIG. 29 is a diagram illustrating the second processing of step S7. As shown in FIG. 29, the processor 102 provides the terminal 200 with a user interface 70N including a list of one or more hazards registered for the target device. The processor 102 provides the user interface 70O in response to selection of the target hazard in the user interface 70N. The user interface 70O is an example of the "sixth user interface" of the present disclosure. The user interface 70O includes areas 96a and 96b. The processor 102 displays first information 50 corresponding to the target hazard in the area 96a. For example, a risk assessment sheet created based on the data set 50a is displayed in the area 96a. Furthermore, the processor 102 displays second information 60 (e.g., a wiring diagram 60a and a block diagram 60b) corresponding to the target hazard in the area 96b.
[0167] (Third Processing) FIG. 30 is a diagram illustrating the third process of step S7. As shown in FIG. 30, the processor 102 provides the terminal 200 with a user interface 70P including a list of safety devices included in any safety-related part employed in the target apparatus. The processor 102 provides a user interface 70Q in response to selection of the target safety device in the user interface 70P. The user interface 70Q is an example of a "seventh user interface" of the present disclosure. The user interface 70Q includes areas 98a and 98b for each safety-related part including the target safety device. The processor 102 displays second information 60 (e.g., a wiring diagram 60a and a block diagram 60b) corresponding to the target safety-related part in the area 98a corresponding to the target safety-related part. Furthermore, the processor 102 displays first information 50 corresponding to a target hazard, among one or more hazards, whose risk is reduced by the target safety-related part in the area 98b. For example, a risk assessment sheet created based on the dataset 50a is displayed in the area 98a.
[0168] <Variation 1> The support device 100 may perform processing in cooperation with other applications. For example, the support device 100 may cooperate with a development support application installed on the terminal 200. The development support application supports the development of a user program to be executed in the programmable logic controller. The user program includes instructions for calculations based on data collected from various devices connected to the programmable logic controller, and instructions for outputting data for controlling the operation of a control target based on the calculation results.
[0169] The processor 102 of the support device 100 may operate as a creation unit that analyzes a user program stored in the terminal 200, identifies the relationship between the safety devices and the reset operations of each control object in response to output signals from a safety-related part including the safety devices, and creates a truth table indicating the relationship. Furthermore, the processor 102 may output a user interface including the truth table or output a document indicating the truth table.
[0170] 31 is a diagram showing an example of a user interface including a truth table. As shown in FIG. 31, the user interface 70R includes a truth table 99 that shows the relationship between the safety devices and the reset operations of the transport robot, ball screw, transport conveyor, and transfer robot in response to output signals from safety-related parts including the safety devices. This allows the user to easily understand the control range based on the safety devices.
[0171] <Variation 2> An embodiment is also possible in which a general-purpose computer functions as the support device 100 according to the above-described embodiment. Specifically, a safety design program 114, which describes the processing content that realizes each function of the support device 100 according to the above-described embodiment, is stored in the memory of the general-purpose computer, and the safety design program 114 is read and executed by a processor. Therefore, the invention according to this embodiment can also be realized as a safety design program 114 executable by one or more processors, or a non-transitory computer-readable medium that stores the safety design program 114.
[0172] §3 Supplementary Note As described above, the present embodiment includes the following disclosures.
[0173] (Configuration 1) A support device (100) that supports the safety design of a target device, a first generation unit (10) that generates first information (50) including a result of the risk assessment based on an input to a first user interface (70B, 70D) including a first group of questions according to the risk assessment for each of one or more hazards included in the target device; a second generation unit (11) that generates second information (60) indicating the device configuration and wiring of the safety-related part based on an input to a second user interface (70F, 70G, 70H) for supporting the realization of risk reduction measures for each of the one or more hazards; A support device (100) comprising a management unit (12) that manages the first information (50) and the second information (60) in association with each other for each of the one or more hazards.
[0174] (Configuration 2) The support device (100) according to configuration 1 further comprises an output unit (22) that outputs a first document representing the first information (50) corresponding to each of the one or more hazards and a second document representing the second information (60) corresponding to each of the one or more hazards.
[0175] (Configuration 3) the first group of questions includes questions regarding a plurality of essential items required by a safety standard; the first generation unit (10) generates the first information (50) in response to acquiring answers to all of the plurality of required items; 3. The support device (100) according to claim 1 or 2, wherein the first information (50) includes answers to all of the plurality of required items.
[0176] (Configuration 4) a determination unit (20) that determines a performance level of the safety-related unit based on an input to a third user interface (70I) that includes a second group of questions regarding the diagnostic range and operating status of each safety device included in the safety-related unit, the first generation unit (10) determines a required performance level for each of the one or more hazards based on an input to the first user interface; A support device (100) according to any one of configurations 1 to 3, wherein the first information (50) includes the required performance level, the performance level, and a determination result as to whether the performance level satisfies the required performance level.
[0177] (Configuration 5) The second user interface includes: a fourth user interface (70F, 70G) that prompts the user to select a plurality of safety devices that constitute the safety-related part from a plurality of safety device candidates; and a fifth user interface (70H) that prompts the user to select a terminal pair to be connected from among a plurality of terminals included in the plurality of safety devices.
[0178] (Configuration 6) an output unit (22) that provides a sixth user interface (70O) in response to selection of a target hazard from among the one or more hazards; The support device (100) according to any one of configurations 1 to 5, wherein the sixth user interface (70O) displays the first information (50) corresponding to the target hazard and the second information (60) corresponding to the target hazard.
[0179] (Configuration 7) an output unit (22) that provides a seventh user interface (70Q) in response to the selection of the target safety device; The support device (100) according to any one of configurations 1 to 5, wherein the seventh user interface (70Q) displays the second information (60) corresponding to the target safety-related part including the target safety equipment, and the first information (50) corresponding to a target hazard among the one or more hazards whose risk is reduced by the target safety-related part.
[0180] (Configuration 8) A support method for supporting safety design of a target device, comprising: one or more processors (102) generate first information (50) including results of a risk assessment based on input to a first user interface (70B, 70D) including a first set of questions according to the risk assessment for each of one or more hazards included in the target device; generating, by the one or more processors (102), second information (60) indicating the device configuration and wiring of a safety-related part based on an input to a second user interface (70F, 70G, 70H) for supporting the implementation of risk reduction measures for each of the one or more hazards; The support method comprises the one or more processors (102) associating and managing the first information (50) and the second information (60) for each of the one or more hazards.
[0181] (Configuration 9) A program for causing a computer to execute a support method for supporting safety design of a target device, The support method includes: generating first information (50) including results of a risk assessment based on input to a first user interface (70B, 70D) including a first set of questions according to the risk assessment for each of one or more hazards included in the target device; generating second information (60) indicating the device configuration and wiring of the safety-related part based on an input to a second user interface (70F, 70G, 70H) for supporting the implementation of risk reduction measures for each of the one or more hazards; and managing the first information (50) and the second information (60) in association with each other for each of the one or more hazards.
[0182] Although the embodiments of the present invention have been described, the embodiments disclosed herein should be considered to be illustrative and not restrictive in all respects. The scope of the present invention is defined by the claims, and it is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]
[0183] 10 first generation unit, 11 second generation unit, 12 management unit, 13 risk level calculation unit, 14 risk tolerance determination unit, 15 risk reduction measure reception unit, 16 PLr calculation unit, 17 safety device selection unit, 18 pin assignment drawing unit, 19 wiring design reception unit, 20 PL determination unit, 21 block diagram creation unit, 22 output unit, 50 first information, 50a dataset, 60 second information, 60a wiring diagram, 60b block diagram, 70, 70A to 70H, 70I to 70R user interface, 70G pop-up window, 99 truth table, 100 support device, 102 processor, 104 memory, 106 network controller, 110 storage, 112 system program, 114 safety design program, 200 terminal.
Claims
1. A support device that supports the safety design of a target device, a first generation unit that generates first information including a result of the risk assessment for each of one or more hazards included in the target device based on an input to a first user interface including a first group of questions according to the risk assessment; a second generation unit that generates second information indicating a device configuration and wiring of a safety-related part based on an input to a second user interface that supports the implementation of a risk reduction measure for each of the one or more hazards; a management unit that manages the first information and the second information in association with each other for each of the one or more hazards.
2. The support device according to claim 1 , further comprising an output unit that outputs a first document representing the first information corresponding to each of the one or more hazards and a second document representing the second information corresponding to each of the one or more hazards.
3. the first group of questions includes questions regarding a plurality of essential items required by a safety standard; the first generation unit generates the first information in response to obtaining answers to all of the plurality of required items; The support device according to claim 1 , wherein the first information includes answers to the plurality of required items.
4. a determination unit that determines a performance level of the safety-related unit based on an input to a third user interface that includes a second group of questions regarding an operating status and an index that evaluates the reliability of each safety device included in the safety-related unit; the first generation unit determines a required performance level for each of the one or more hazards based on an input to the first user interface; The support device according to claim 1 , wherein the first information includes the required performance level, the performance level, and a determination result as to whether or not the performance level satisfies the required performance level.
5. The second user interface includes: a fourth user interface that prompts the user to select a plurality of safety devices that constitute the safety-related part from a plurality of safety device candidates; The support device according to claim 1 , further comprising: a fifth user interface that prompts the user to select a terminal pair to be connected from among a plurality of terminals included in the plurality of safety devices.
6. an output unit that provides a sixth user interface in response to selection of a target hazard from among the one or more hazards; The support device according to claim 1 , wherein the sixth user interface displays the first information corresponding to the target hazard and the second information corresponding to the target hazard.
7. An output unit that provides a seventh user interface in response to the selection of the target safety device, The support device according to claim 1, wherein the seventh user interface displays the second information corresponding to a target safety-related part including the target safety device, and the first information corresponding to a target hazard among the one or more hazards whose risk is reduced by the target safety-related part.
8. A support method for supporting safety design of a target device, comprising: one or more processors generating first information including results of a risk assessment based on input to a first user interface including a first set of questions according to the risk assessment for each of one or more hazards included in the target device; generating, by the one or more processors, second information indicating a device configuration and wiring of a safety-related part for each of the one or more hazards based on an input to a second user interface for supporting implementation of a risk reduction measure; and managing, by the one or more processors, the first information and the second information in association with each other for each of the one or more hazards.
9. A program for causing a computer to execute a support method for supporting safety design of a target device, The support method includes: generating first information including a result of performing a risk assessment for each of one or more hazards included in the target device based on an input to a first user interface including a first set of questions according to the risk assessment; generating second information indicating a device configuration and wiring of a safety-related part based on an input to a second user interface for supporting implementation of a risk reduction measure for each of the one or more hazards; and managing the first information and the second information in association with each other for each of the one or more hazards.
Citation Information
Patent Citations
Consulting device and consulting program
JP2009037520A