Robot control device and control method
The robot control device addresses the issue of signature verification during power interruptions by using a sub-power supply to create verification files, ensuring secure robot operation upon power restoration.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SEIKO EPSON CORP
- Filing Date
- 2024-11-08
- Publication Date
- 2026-05-20
AI Technical Summary
Existing robot control devices fail to perform signature verification on updated programs and data during power interruptions, compromising safety upon power restoration.
A robot control device connected to both a main and sub-power supply, with a determination unit to detect power states and a creation unit that creates verification files using sub-power during interruptions, ensuring signature verification upon power restoration.
Enhances safety by detecting and preventing tampering of robot information during power outages, ensuring secure operation upon power restoration.
Smart Images

Figure 2026083740000001_ABST
Abstract
Description
Technical Field
[0004]
[0001] The present invention relates to a robot control device and a control method.
Background Art
[0002] In recent years, in factories, due to soaring labor costs and a shortage of personnel, automation of operations that have been performed manually has been attempted using various robots and peripheral devices thereof. The operation of a robot is controlled by a robot control device. The robot control device includes a storage unit in which various programs are stored, and a processing unit that executes the programs stored in the storage unit.
[0003] In such a robot control device, from the viewpoint of improving safety, it is preferable to check whether various programs are in an appropriate state, particularly whether they have been illegally modified, etc. due to external attacks, etc. when the robot control device is started up. As this method, there is known a method of storing signatures for various programs and detecting the propriety of the programs including the presence or absence of tampering by verifying the signatures of the various programs at startup.
[0004] For example, in the information processing device described in Patent Document 1, signature verification is performed one by one for each of the various programs stored, and when the signature verification is successful, the operation of starting up that program is performed for each program. Thereby, it is possible to start up the program after confirming that the program has not been tampered with, and it is possible to ensure safety.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] However, the information processing device described in Patent Document 1 is configured to store various programs with signatures and perform signature verification of the various programs at startup. Therefore, it is not possible to perform signature verification on programs and data that are updated when the robot is operated. In particular, if the power supply to the robot control device is unintentionally interrupted due to a power outage, for example, the safety when power is restored is insufficient. [Means for solving the problem]
[0007] The robot control device of the present invention is electrically connected to a main power supply or a sub-power supply and controls the operation of a robot, A determination unit that determines whether it is a first state in which power is supplied from the main power supply to the robot control device, or a second state in which the power supply to the robot control device is cut off from the first state, When the determination unit determines that the second state is reached, the creation unit operates using power supplied from the sub-power supply and creates a verification file for robot information relating to the robot that will be subject to signature verification when the first state is reached again. The system includes a storage unit that stores the verification file created by the creation unit.
[0008] The present invention relates to a control method for a robot control device that is electrically connected to a main power supply or sub-power supply and includes a determination unit, a creation unit, and a storage unit, and controls the operation of a robot. The first step is for the determination unit to determine whether it is in a first state where power is supplied from the main power supply to the robot control device, or in a second state where the power supply to the robot control device is cut off from the first state. If the determination unit determines in the first step that the second state is in place, the second step is to supply power from the sub-power supply to the robot control device, The creation unit operates using power supplied from the sub-power supply, and the third step involves creating a verification file for robot information relating to the robot that will be subject to signature verification the next time the first state is reached, The storage unit has a fourth step of storing the verification file created in the third step. [Brief explanation of the drawing]
[0009] [Figure 1] Figure 1 shows the overall configuration of a robot system equipped with a robot control device according to a first embodiment of the present invention. [Figure 2] Figure 2 is a block diagram of the robot system shown in Figure 1. [Figure 3] Figure 3 is a hardware configuration diagram of the robot control device shown in Figure 1. [Figure 4] Figure 4 is a time chart showing the control operation of the robot control device. [Figure 5] Figure 5 is a flowchart illustrating an example of the control method of the present invention. [Modes for carrying out the invention]
[0010] <First Embodiment> Figure 1 is a diagram showing the overall configuration of a robot system equipped with a robot control device according to a first embodiment of the present invention. Figure 2 is a block diagram of the robot system shown in Figure 1. Figure 3 is a hardware configuration diagram of the robot control device shown in Figure 1. Figure 4 is a time chart showing the control operation of the robot control device. Figure 5 is a flowchart illustrating an example of the control method of the present invention.
[0011] The robot control device and control method of the present invention will be described in detail below based on preferred embodiments shown in the accompanying drawings. For convenience of explanation, the robot arm will be referred to as the "base end" on the base 11 side in Figure 1, and the opposite side, i.e., the "tip end" on the end effector 20 side.
[0012] As shown in Figure 1, the robot system 100 comprises a robot 1, a robot control device 3 that controls the operation of the robot 1, a teaching device 4, and a selection unit 5. As shown in Figures 1, 2, and 3, the robot control device 3 and the selection unit 5, the teaching device 4 and the selection unit 5, and the main power supply 200 and the selection unit 5 are each connected by power lines (power supply wiring) 6.
[0013] First, let me explain Robot 1. The robot 1 shown in Figure 1 is a single-arm, six-axis vertical articulated robot in this embodiment, and comprises a base 11 and a robot arm 10. An end effector 20 can be attached to the tip of the robot arm 10. The end effector 20 may or may not be a component of the robot 1.
[0014] Note that robot 1 is not limited to the configuration shown in the figure, and may be, for example, a dual-arm articulated robot. Also, robot 1 may be a horizontal articulated robot.
[0015] The base 11 is a support that enables the robot arm 10 to be driven from the lower side in Figure 1, and is fixed, for example, to the floor of a factory. The robot 1 is electrically connected to the robot control device 3 via a relay cable on the base 11. Note that the connection between the robot 1 and the robot control device 3 is not limited to a wired connection as shown in Figure 1, but may also be a wireless connection, or even a connection via a network such as the Internet.
[0016] In this embodiment, the robot arm 10 has a first arm 12, a second arm 13, a third arm 14, a fourth arm 15, a fifth arm 16, and a sixth arm 17, and these arms are connected in this order from the base 11 side. The number of arms that the robot arm 10 has is not limited to six, but may be one, two, three, four, five, or seven or more. Also, the size of each arm, such as the total length, is not particularly limited and can be set as appropriate.
[0017] The base 11 and the first arm 12 are connected via a joint 171. The first arm 12 is rotatable about a first rotation axis parallel to the vertical direction with respect to the base 11, and the first rotation axis is coincident with the normal line of the floor to which the base 11 is fixed.
[0018] The first arm 12 and the second arm 13 are connected via a joint 172. The second arm 13 is rotatable about a second rotation axis parallel to the horizontal direction with respect to the first arm 12, and the second rotation axis is parallel to an axis orthogonal to the first rotation axis.
[0019] The second arm 13 and the third arm 14 are connected via a joint 173. The third arm 14 is rotatable about a third rotation axis parallel to the horizontal direction with respect to the second arm 13, and the third rotation axis is parallel to the second rotation axis.
[0020] The third arm 14 and the fourth arm 15 are connected via a joint 174. The fourth arm 15 is rotatable about a fourth rotation axis parallel to the central axis direction of the third arm 14 with respect to the third arm 14, and the fourth rotation axis is orthogonal to the third rotation axis.
[0021] The fourth arm 15 and the fifth arm 16 are connected via a joint 175. The fifth arm 16 is rotatable about a fifth rotation axis with respect to the fourth arm 15, and the fifth rotation axis is orthogonal to the fourth rotation axis.
[0022] The fifth arm 16 and the sixth arm 17 are connected via a joint 176. The sixth arm 17 is rotatable about a sixth rotation axis with respect to the fifth arm 16, and the sixth rotation axis is orthogonal to the fifth rotation axis.
[0023] Furthermore, the sixth arm 17 is the robot's tip, located at the very front of the robot arm 10. This sixth arm 17 can rotate together with the end effector 20 by the drive of the robot arm 10.
[0024] Robot 1 includes motors M1, M2, M3, M4, M5, and M6 as drive units, and encoders E1, E2, E3, E4, E5, and E6. Motor M1 is built into joint 171 and rotates the base 11 and the first arm 12 relative to each other. Motor M2 is built into joint 172 and rotates the first arm 12 and the second arm 13 relative to each other. Motor M3 is built into joint 173 and rotates the second arm 13 and the third arm 14 relative to each other. Motor M4 is built into joint 174 and rotates the third arm 14 and the fourth arm 15 relative to each other. Motor M5 is built into joint 175 and rotates the fourth arm 15 and the fifth arm 16 relative to each other. Motor M6 is built into joint 176 and rotates the fifth arm 16 and the sixth arm 17 relative to each other.
[0025] Encoder E1 is built into joint 171 and detects the position of motor M1. Encoder E2 is built into joint 172 and detects the position of motor M2. Encoder E3 is built into joint 173 and detects the position of motor M3. Encoder E4 is built into joint 174 and detects the position of motor M4. Encoder E5 is built into fifth arm 16 and detects the position of motor M5. Encoder E6 is built into sixth arm 17 and detects the position of motor M6.
[0026] Encoders E1 to E6 are electrically connected to the robot control device 3, and the position information of motors M1 to M6, i.e., the amount of rotation, is transmitted to the robot control device 3 as an electrical signal. Based on this information, the robot control device 3 drives motors M1 to M6 via motor drivers D1 to D6, as shown in Figure 2. In other words, controlling the robot arm 10 means controlling motors M1 to M6.
[0027] An end effector 20 can be detachably attached to the tip of the robot arm 10. In this embodiment, the end effector 20 is a hand having a pair of claws that can move closer to and further apart from each other, and each claw grips and releases the workpiece. The end effector 20 is not limited to the configuration shown, and may be a hand that grips the workpiece or tool by suction. The end effector 20 may also be, for example, a polishing machine, grinding machine, cutting machine, coating device, spray gun, or a tool such as a screwdriver or wrench.
[0028] Robot 1 uses such an end effector 20 to operate the robot arm 10 as desired to perform various tasks such as transporting, manufacturing, processing, assembling, and painting of workpieces.
[0029] Furthermore, a control point TCP is set at the tip of the end effector 20. In the robot system 100, by knowing the position of the control point TCP, the control point TCP can be used as the control reference.
[0030] Next, we will describe the teaching device 4. As shown in Figures 1 and 2, the teaching device 4 has a display unit 40 and an input unit 44, and by operating the input unit 44, it is possible to create and input an operation program for the robot arm 10. The teaching device 4 is not particularly limited and can include, for example, a desktop or notebook computer, a tablet terminal, a smartphone, a teaching pendant, etc.
[0031] Specifically, the teaching device 4 comprises a display unit 40, a control unit 41, a storage unit 42, a communication unit 43, and an input unit 44.
[0032] The display unit 40 is composed of, for example, a liquid crystal display or an organic EL display. The control unit 41 is composed of, for example, a CPU (Central Processing Unit) and reads various programs such as teaching programs stored in the memory unit 42. The memory unit 42 has, for example, ROM or RAM and stores the above-mentioned various programs.
[0033] The communication unit 43 transmits and receives signals to and from the robot control device 3 using an external interface such as a wired LAN (Local Area Network) or wireless LAN.
[0034] The input unit 44 consists of a keyboard, mouse, connectors, external connection terminals, etc., and the user can input or select desired information by, for example, operating the keyboard or mouse.
[0035] If the display unit 40 is composed of a touch panel type liquid crystal display, the display unit 40 The desired information can be entered by touching the display surface with a finger, stylus, or the like. In this case, the display unit 40 also serves as the input unit 44.
[0036] Furthermore, the teaching device 4 has a battery 45 as its power source, and the display unit 40, control unit 41, memory unit 42, communication unit 43, and input unit 44 of the teaching device 4 are driven by the power stored in the battery 45. The battery 45 is not particularly limited, but examples include lead-acid batteries, lithium-ion batteries, nickel-metal hydride batteries, nickel-cadmium batteries, etc. The battery 45 may be fixedly installed on the teaching device 4 or may be installed in a way that allows it to be attached and detached.
[0037] The teaching device 4 has input / output terminals 46 for supplying power, and can charge the battery 45 via the input / output terminals 46 from an external power source (not shown), such as a 100V or 200V AC power source. The battery 45 can supply the stored power to external devices, particularly the robot control device 3, connected via the input / output terminals 46 and power lines 6, etc. Although the input / output terminals 46 serve both as power input (receiving) and output (discharging), the configuration is not limited to this, and for example, separate power input terminals and power output terminals may be provided instead of the input / output terminals 46.
[0038] Next, we will describe the robot control device 3. As shown in Figures 1, 2, and 3, the robot control device 3 controls the operation of the robot 1 and also has the function of acquiring and storing the operation history of the robot 1.
[0039] As shown in Figure 1, in this embodiment, the robot control device 3 is installed at a location separate from the robot 1. However, the configuration is not limited to this, and for example, the robot control device 3 may be built into the base 11 of the robot 1.
[0040] As shown in Figure 3, the robot control device 3 comprises a CPU 31, a ROM 32, a RAM 33, an IF control unit 34 (communication unit), an LED 35, a bus 36, a power receiving unit 37, a power detection unit 38, and a casing 39 for housing or installing these components. The bus 36 interconnects the CPU 31, ROM 32, RAM 33, IF control unit 34, LED 35, and power detection unit 38. The ROM 32 and RAM 33 constitute the storage unit 30.
[0041] In this embodiment, the CPU 31 is configured as a multiprocessor having multiple core processors (cores), for example. The CPU 31 executes various programs and comprehensively controls the entire system of the robot control device 3.
[0042] The CPU 31 has the function of performing various processes, such as process A, which executes various programs stored in the memory unit 30; process B, which creates verification files to be subject to signature verification for the various programs being executed, as will be described later; process C, which determines whether or not power is being supplied to the power receiving unit 37, as will be described later; and process D, which generates a command signal SS to select a power supply source. Of the CPU 31, the core that performs process C is also called the determination unit 311 as a functional unit, and the core that performs process B is also called the creation unit 312 as a functional unit.
[0043] Furthermore, the configuration may involve different cores executing various processes, or a single core executing multiple processes. Also, the configuration is not limited to a single CPU 31 executing various processes; multiple CPUs (not shown) may share the execution of various processes.
[0044] "Creating a verification file to be used for signature verification" means encrypting a hash value using a public key or private key for specified data or a specified program. In other words, a verification file is the specified data or program that has been encrypted.
[0045] The signature verification of the verification file is performed, and if successful, the original data or program can be read and executed. On the other hand, if the signature verification of the verification file fails, the original data or program cannot be read or executed. However, the data or program may be configured to be read and executable even if the signature verification fails. In this case, it is preferable to notify the system that the signature verification failed or to store it in the storage unit 30.
[0046] "Signature verification" refers to verifying whether a first hash value obtained by applying a hash function to the startup program or operating program matches a second hash value obtained by decrypting the digital signature for the startup program or operating program using a public key. However, it is not limited to this.
[0047] "Successful signature verification" means that the first hash value and the second hash value are compared and found to be the same. If signature verification is successful, the program has not been tampered with, the robot control device 3 can be started with high security, and the robot 1 can be driven safely.
[0048] "Signature verification failure" means that when comparing the first hash value and the second hash value, they are different values. If signature verification fails, the program may have been tampered with, or the program may be in an improper or incomplete state. Therefore, the safety of starting the robot control device 3 and the safety of driving the robot 1 cannot be guaranteed.
[0049] ROM32 is a read-only memory that stores robot information, including various programs and data. The robot information is related to robot 1 and includes startup programs and operation programs as various programs, and robot operation parameters and robot operation history as various data.
[0050] The startup program is a program used to start the system of the robot control device 3. Examples of startup programs include boot programs, BIOS (Basic Input / Output System), loaders, kernels, native programs, and Java® programs.
[0051] The operation program includes programs that specify various conditions for driving the robot 1, such as the path of the control point TCP of the robot 1, the posture of the robot arm 10 over time, and the speed information of the control point TCP. Each of these constitutes an operation program.
[0052] The operating parameters include force control parameters for the robot arm 10, such as the mass coefficient, viscosity coefficient, and elastic modulus, as well as settings for peripheral equipment such as cameras and sensors (not shown).
[0053] The operation history includes information on changes in the posture of the robot arm 10 over time, information on the progress of the work, and information such as the date and time when an error occurred.
[0054] As shown in Figure 3, RAM33 is Random Access Memory, a non-volatile memory used by the CPU31 to temporarily store robot information stored in ROM32 when executing various programs.
[0055] Furthermore, the robot information stored in RAM33 can be rewritten by CPU31. The operation program, operation parameters, and operation history can be rewritten at predetermined timings. The operation program and operation parameters can be input, selected, or changed (rewritten) by, for example, the user operating the input unit 44 of the teaching device 4. The operation history is newly accumulated each time the robot 1 operates and can be obtained from the robot 1 in real time or at predetermined time intervals. The rewritten operation program, operation parameters, and operation history are encrypted by CPU31 and become verification files.
[0056] The IF control unit 34 communicates with the outside world via the network, i.e., with the robot 1, teaching device 4, and selection unit 5, etc., and transmits and receives various data. The IF control unit 34 is an output unit that outputs a command signal SS to the selection unit 5. In this embodiment, the output unit is the IF control unit 34, but it is not limited to this and may be provided separately from the IF control unit 34.
[0057] The LED 35 operates to light up or blink in a predetermined pattern, and notifies various types of information, such as abnormal operation of the robot 1, abnormal system operation of the robot control device 3, detection results of the power detection unit 38, selection results of the power supply source to the robot control device 3, and the results of signature verification (failure, etc.) described later. In other words, the LED 35 functions as a notification unit. Such an LED 35 is installed exposed on the outer surface of the casing 39 of the robot control device 3, for example, so that it can be seen by the user (see Figure 1). This notification information may also be displayed on the display unit 40 of the teaching device 4 simultaneously with or instead of the operation of the LED 35. In this case, the display unit 40 functions as a notification unit.
[0058] As shown in Figures 2 and 3, the power receiving unit 37 receives power from either the main power supply 200 or the battery 45 of the teaching device 4, which is a sub-power supply (auxiliary power supply), via the power line 6, etc. Hereinafter, receiving power will also be referred to as "receiving power". The power receiving unit 37 is connected to the main power supply 200 via the selection unit 5 and the power line 6. The power receiving unit 37 is also connected to the battery 45 of the teaching device 4, which serves as a sub-power supply, via the selection unit 5 and the power line 6.
[0059] The main power supply 200 is, for example, a 100V or 200V AC power supply. The power receiving unit 37 is a terminal that supplies power to the robot control device 3 and is provided on a connector or the like that is exposed on the outer surface of the casing 39.
[0060] The power detection unit 38 is, for example, composed of a voltmeter and detects the power supplied from the main power supply 200. The information of the detected value from the power detection unit 38 is transmitted to the CPU 31 as an electrical signal. By providing the power detection unit 38, the robot control device 3 can detect the appropriateness of the power being received.
[0061] In this embodiment, the power detection unit 38 is included in the robot control device 3, but it is not limited to this and may be installed separately from the robot control device 3. For example, it may be installed in the selection unit 5, or it may be installed between the selection unit 5 and the power receiving unit 37.
[0062] The selection unit 5 selects either the main power supply 200 or the battery 45 of the teaching device 4 as the power supply source to the power receiving unit 37, and includes power supply equipment such as USB PD and PoE, as well as relay equipment such as relays and OR gates. As shown in Figures 2 and 3, the selection unit 5 receives a command signal SS generated by the CPU 31 and selects whether to use the main power supply 200 or the battery 45 of the teaching device 4 as the power supply source according to the command signal SS. The power receiving unit 37 can only receive power from the selected power supply source.
[0063] Since the selection unit 5 has USB PD and PoE, the present invention can be realized with a simple configuration and low cost.
[0064] In this embodiment, the selection unit 5 is installed separately from the robot control device 3 and the teaching device 4, but it is not limited to this configuration and may be included in the robot control device 3 or in the teaching device 4.
[0065] Normally, such a robot control device 3 operates when the power receiving unit 37 receives power supplied from the main power supply 200. For example, if a power outage occurs in the factory where the robot control device 3 is installed, or if the power supply is unintentionally cut off due to a circuit breaker tripping due to excessive power usage, a break in the power line 6, a loose outlet or connector, poor contact, etc., the power supply from the main power supply 200 to the robot control device 3 will be cut off. In this case, the robot control device 3 will perform the following control.
[0066] The determination unit 311 determines whether the system is in a first state, where power is supplied from the main power supply 200 to the power receiving unit 37, or in a second state, where the power supply to the power receiving unit 37 has been cut off from the first state. Note that if the user intentionally turns off a power switch (not shown), this does not need to be included in the second state. In other words, the second state is defined as when the power supply from the main power supply 200 is cut off unintentionally (when an unintended power interruption occurs).
[0067] The determination unit 311 determines whether the system is in the first or second state based on whether the detected value from the power detection unit 38 is below a threshold. If the determination unit 311 determines that the system is in the second state, the CPU 31 generates a command signal SS, and the IF control unit 34 outputs a command signal SS to the selection unit 5 indicating that the teaching device 4 is selected as the power supply source. Upon receiving the command signal SS, the selection unit 5 outputs the power stored in the battery 45 of the teaching device 4 from the input / output terminal 46 and supplies it to the robot control device 3 via the power line 6 and the selection unit 5, as shown in Figures 2 and 3.
[0068] In the robot control device 3, the CPU 31 operates using power supplied from the battery 45 of the teaching device 4, and performs the following processing.
[0069] The creation unit 312 creates a verification file for robot information that will be subject to signature verification the next time the system enters the first state, and stores it in RAM 33. Specifically, it overwrites the robot information stored in RAM 33 with the latest information and encrypts the overwritten data. Then, it shuts down the system. The next time the system enters the first state, for example, when a power outage is restored (when an unintended power interruption is resolved), the CPU 31 performs signature verification on the verification file stored in RAM 33. If the signature verification is successful, it decrypts the verification file and executes the program. With this configuration, even if the program in the verification file is tampered with externally in the second state, it is possible to prevent the execution of the tampered program after the system returns from the second state to the first state. Therefore, the security of the operation of robot 1 can be sufficiently enhanced.
[0070] As shown in Figure 4, in this embodiment, in the second state, the creation unit 312 creates a verification file for the operation history. This makes it possible to obtain as much operation history as possible accurately. Regarding the operation program and operation parameters, verification files are created at a desired timing in the first state, before entering the second state. This simplifies the process of creating verification files when entering the second state. Furthermore, by creating a verification file for the operation program, the next time the system enters the first state, it is possible to execute a safe operation program and operate the robot arm 10 with safe settings.
[0071] In the robot control device 3, in the first state, the creation unit 312 creates a verification file when the user resets, i.e., rewrites, the operation program. This allows for the rapid creation of a verification file after rewriting. Alternatively, in the first state, verification files for the operation program may be created periodically at predetermined time intervals. The interval for creating verification files may be configured as appropriate by the user.
[0072] In the robot control device 3, in the first state, the creation unit 312 creates a verification file when the user resets, i.e., rewrites, the operation parameters. This allows for the rapid creation of a verification file after rewriting. Alternatively, in the first state, verification files of the operation parameters may be created periodically at predetermined time intervals.
[0073] It goes without saying that, in this invention, the control operation of the robot control device 3 is not limited to the operation shown in the time chart in Figure 4. The creation of the operation program and the verification files for operation parameters may not be limited to being performed periodically as described above, but may also be performed, for example, each time a series of operations of the robot 1 is completed, or each time a predetermined unit operation is completed.
[0074] As described above, the robot control device 3 is electrically connected to the main power supply 200 or the battery 45 of the teaching device 4 as a sub-power supply, and controls the operation of the robot 1. The robot control device 3 includes a determination unit 311 that determines whether it is in a first state where power is supplied to the robot control device 3 from the main power supply 200, or a second state where the power supply to the robot control device 3 is cut off from the first state; a creation unit 312 that operates using power supplied from the battery 45 of the teaching device 4 when the determination unit 311 determines it is in the second state, and creates a verification file for robot information relating to the robot 1 that will be subject to signature verification the next time it returns to the first state; and a storage unit 30 that stores the verification file created by the creation unit 312. As a result, even if the robot information is tampered with or otherwise becomes inappropriate or incomplete when it is in the second state due to an unintended power interruption or the like, the tampering can be detected by performing signature verification on the robot information verification file the next time it returns to the first state. Thus, the safety of the operation of the robot 1 can be enhanced.
[0075] In this embodiment, an AC power supply was used as an example of a main power supply, but the present invention is not limited thereto. Any battery other than the battery 45 of the teaching device 4, a portable battery, various generators, and especially a generator installed in a factory or a portable generator may be used as the main power supply.
[0076] Furthermore, the robot control device 3 includes a power receiving unit 37 that receives power from either the main power supply 200 or the teaching device 4 as a sub-power supply, and an IF control unit 34 as an output unit that outputs a command signal SS to the selection unit 5, which selects either the main power supply 200 or the battery 45 of the teaching device 4 as the power supply source to be supplied to the power receiving unit 37 when the determination unit 311 determines that a second state has been reached. When the command signal SS is output from the IF control unit 34, the creation unit 312 creates a verification file for robot information. This makes it possible to create a verification file for robot information more accurately and improves the safety of the operation of the robot 1.
[0077] The robot information includes at least one (three in this embodiment) of the following: the robot 1's operating program, the robot 1's operating parameters, and the robot 1's operating history. This allows for the creation of verification files for the robot 1's operating program, operating parameters, and operating history, thereby further enhancing safety.
[0078] The robot information includes the operating history of robot 1, and in the second state, the creation unit 312 creates a verification file of the operating history of robot 1. This makes it possible to obtain as much of the operating history as possible accurately.
[0079] However, the configuration is not limited to the above, and in the second state, the creation unit 312 may be configured to create all verification files for the robot 1's operation program, robot 1's operation parameters, and robot 1's operation history.
[0080] The robot information includes the operation program and operation parameters of robot 1. In the first state, the creation unit 312 creates verification files for the operation program and operation parameters of robot 1 at a predetermined timing. This simplifies the process when creating verification files in the second state.
[0081] The robot information includes the operation program and operation parameters of robot 1. In the first state, the creation unit 312 creates a verification file when the operation program and operation parameters of robot 1 are rewritten. This allows for the rapid creation of a verification file after rewriting.
[0082] The robot information includes the robot 1's operation program, robot 1's operation parameters, and robot 1's operation history. In the first state, the creation unit 312 creates verification files for the robot 1's operation program and robot 1's operation parameters when they are rewritten. In the second state, it creates a verification file for the robot 1's operation history. This allows for accurate acquisition of as much operation history as possible and simplifies the process of creating verification files in the second state. Furthermore, verification files can be created quickly after rewriting.
[0083] The auxiliary power supply is installed in the teaching device 4, which provides instruction to the robot 1. By using the battery 45 of the teaching device 4, which is widely used when operating the robot 1 or setting up the robot control device 3, as the auxiliary power supply, it is not necessary to prepare a new power supply as an auxiliary power supply. Therefore, the configuration is not complicated when implementing the present invention, and the present invention can be easily introduced.
[0084] In this embodiment, the battery 45 of the teaching device 4 was described as the sub-power source, but the present invention is not limited thereto, and any battery other than battery 45 may be used, such as batteries mounted on external devices, portable batteries, low-power devices, storage batteries, generators for private power generation, portable generators, and other types of generators.
[0085] Next, an example of the control method of the present invention will be explained using the flowchart shown in Figure 5. First, in step S101, the selection unit 5 selects the main power supply 200 as the power source, and the robot control device 3 operates the robot 1 while receiving power from the main power supply 200. That is, the robot control device 3 executes the specified operation program with the specified operation parameters. At this time, a verification file of the operation program and operation parameters is created at a predetermined timing and stored in the storage unit 30. This step is the first state.
[0086] Next, in step S102, the determination unit 311 determines whether or not it is in the second state. That is, it determines whether or not it has switched from the first state to the second state. In this step, the determination unit 311 determines whether or not it is in the second state based on the detected value of the power detection unit 38.
[0087] If it is determined in step S102 that the system is in the second state, the system proceeds to step S103 (S102:YES). If it is determined in step S102 that the system is not in the second state, the system proceeds back to step S101 (S102:NO). This step S102 is the first step.
[0088] In step S103, the selection unit 5 selects a sub-power supply as the power source. That is, the CPU 31 generates a command signal SS, and the IF control unit 34 outputs a command signal SS to the selection unit 5 to select the battery 45 of the teaching device 4 as the power source. This step S103 is the second step. Upon receiving the command signal SS, the selection unit 5 supplies the necessary power from the battery 45 of the teaching device 4 to the robot control device 3 via the input / output terminal 46 and the power receiving unit 37.
[0089] Next, in step S104, the creation unit 312 creates a verification file. That is, the creation unit 312 creates a verification file for robot information that will be subject to signature verification the next time the system enters the first state, and in step S105, it stores the verification file in the RAM 33 of the storage unit 30. Specifically, it overwrites the operation program, operation parameters, and operation history stored in the RAM 33 with the latest information and encrypts the overwritten data. Then, in step S106, it shuts down the system. Step S104 is the third step, and step S105 is the fourth step.
[0090] By going through steps S101 to S106, even if the robot information is tampered with externally while in the second state, the next time it returns to the first state, the tampering can be detected by performing signature verification on the verification file of the robot information. Therefore, the safety of the operation of robot 1 can be enhanced.
[0091] As described above, the control method of the present invention is a control method for a robot control device 3 that controls the operation of a robot 1, and is electrically connected to a main power supply 200 and a battery 45 of a teaching device 4 as a sub-power supply, and has a determination unit 311, a creation unit 312, and a storage unit 30, comprising: a first step in which the determination unit 311 determines whether it is in a first state in which power is supplied to the robot control device 3 from the main power supply 200, or a second state in which the power supply to the robot control device 3 is cut off from the first state; a second step in which, if the determination unit 311 determines in the first step that it is in the second state, power is supplied to the robot control device 3 from the battery 45 of the teaching device 4; a third step in which the creation unit 312 operates using the power supplied from the battery 45 of the teaching device 4 and creates a verification file of robot information relating to the robot 1 that will be subject to signature verification the next time it returns to the first state; and a fourth step in which the storage unit 30 stores the verification file created in the third step. This allows the robot to detect external tampering or other inappropriate or incomplete state even if it is in the second state, by performing signature verification on the robot information verification file the next time it returns to the first state. Therefore, the safety of robot 1's operation can be enhanced.
[0092] Although the robot control device and control method of the present invention have been described above in the illustrated embodiments, the present invention is not limited thereto. Furthermore, each part and each process of the robot control device and control method can be replaced with any structure or process that can perform similar functions. In addition, any structure or process may be added. [Explanation of Symbols]
[0093] 1...Robot, 3...Robot control device, 4...Teaching device, 5...Selection unit, 6...Power line, 10...Robot arm, 11...Base, 12...First arm, 13...Second arm, 14...Third arm, 15...Fourth arm, 16...Fifth arm, 17...Sixth arm, 20...End effector, 30...Memory unit, 31...CPU, 32...ROM, 33...RAM, 34...IF control unit, 35...LED, 36...Bus, 37...Power receiving unit, 38...Power detection unit, 39...Casing, 40...Display unit, 41...Control unit, 42...Memory unit, 43...Communication unit, 44...Input unit, 45...Battery (sub-power supply), 46...Input / output terminals, 100...Robot system, 171...Joint, 172...Joint, 173...Joint, 174...Joint, 1 75...Joint, 176...Joint, 200...Main power supply, 311...Determination unit, 312...Creation unit, D1...Motor driver, D2...Motor driver, D3...Motor driver, D4...Motor driver, D5...Motor driver, D6...Motor driver, E1...Encoder, E2...Encoder, E3...Encoder, E4...Encoder, E5...Encoder, E6...Encoder, M1...Motor, M2...Motor, M3...Motor, M4...Motor, M5...Motor, M6...Motor, S101...Step, S102...Step, S103...Step, S104...Step, S105...Step, S106...Step, SS...Command signal, TCP...Control point
Claims
1. A robot control device that is electrically connected to a main power supply or sub-power supply and controls the operation of a robot, A determination unit that determines whether it is a first state in which power is supplied from the main power supply to the robot control device, or a second state in which the power supply to the robot control device is cut off from the first state, When the determination unit determines that the second state is reached, the creation unit operates using power supplied from the sub-power supply and creates a verification file for robot information relating to the robot that will be subject to signature verification the next time the first state is reached, A robot control device comprising a storage unit for storing the verification file created by the creation unit.
2. The robot control device according to claim 1, wherein the robot information includes at least one of the robot's operation program, the robot's operation parameters, and the robot's operation history.
3. The robot information includes the robot's operating history, The robot control device according to claim 2, wherein the creation unit creates the verification file of the robot's operating history in the second state.
4. The robot information includes the robot's operating program and the robot's operating parameters. The robot control device according to claim 2, wherein the creation unit creates the robot's operation program and the verification file of the robot's operation parameters at a predetermined timing in the first state.
5. The robot information includes the robot's operating program and the robot's operating parameters. The robot control device according to claim 4, wherein the creation unit creates the verification file when the robot's operation program and the robot's operation parameters are rewritten in the first state.
6. The robot information includes the robot's operating program, the robot's operating parameters, and the robot's operating history. The robot control device according to claim 1, wherein the creation unit creates the verification files for the robot's operation program and robot's operation parameters when the robot's operation program and robot's operation parameters are rewritten in the first state, and creates the verification files for the robot's operation history in the second state.
7. The robot control device according to claim 1 or 2, wherein the sub-power supply is installed in a teaching device that provides teaching instructions to the robot.
8. A power receiving unit that receives power from either the main power supply or the sub-power supply, When the determination unit determines that the second state is reached, the system includes an output unit that outputs a command signal to the selection unit to select either the main power supply or the sub-power supply as the power supply source to the power receiving unit, and to select the sub-power supply. The robot control device according to claim 1, wherein when the command signal is output from the output unit, the creation unit creates the verification file for the robot information.
9. A control method for a robot control device that is electrically connected to a main power supply or sub-power supply and has a determination unit, a creation unit, and a storage unit, and controls the operation of a robot, The first step is for the determination unit to determine whether it is in a first state where power is supplied from the main power supply to the robot control device, or in a second state where the power supply to the robot control device is cut off from the first state. If the determination unit determines in the first step that the second state is in place, the second step is to supply power from the sub-power supply to the robot control device, The creation unit operates using power supplied from the sub-power supply, and the third step is to create a verification file for robot information relating to the robot that will be subject to signature verification the next time the first state is reached, A control method characterized by comprising: a fourth step in which the storage unit stores the verification file created in the third step.