Information processing device, information processing method, and program
By designing information processing equipment in the control system, extracting and transmitting pre-fault log data, the problem of slow analysis and recovery speed of industrial network-connected control systems is solved when abnormalities occur, and fast response and high-reliability system recovery is achieved.
Patent Information
- Application Number
- JP2024574546
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-09-26
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2043-09-26
AI Technical Summary
In the control system of industrial network connection, it is difficult to quickly perform abnormal analysis and recovery when an abnormality occurs.
An information processing device is designed to store the log data of the frame by receiving repeated frames from the main device, and extract log data within a certain time range as pre-fault log data when an exception occurs, and transmit it to the main device for analysis and recovery.
It realizes rapid abnormality analysis and recovery when abnormalities occur in control system, and improves the system's response speed and reliability.
Smart Images

Figure 0007678644000001 
Figure 0007678644000002 
Figure 0007678644000003
Abstract
Description
[Technical field]
[0001] The present disclosure relates to an information processing device, an information processing method, and a program. [Background technology]
[0002] In the fields of robots and FA (factory automation), it is necessary to operate the position of a conveyor belt, an arm, etc. as intended. To achieve such operations, it is necessary to operate a plurality of controlled devices such as servo motors and stepping motors while synchronizing them with high precision. For example, Patent Document 1 discloses a motion control command system that can achieve smooth control while utilizing inexpensive and simple low-speed communication. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2010-170435 A Summary of the Invention [Problem to be solved by the invention]
[0004] In a control system that includes a controller and controlled devices, the network that connects the controller and the controlled devices is called an industrial network. If an abnormality occurs in the operation of a control system connected by an industrial network, it is desirable to investigate the cause of the abnormality and to smoothly restore the system based on the results of the investigation.
[0005] Therefore, an object of the present disclosure is to provide a technique that enables faster analysis of an abnormality and / or recovery when an abnormality occurs in a control system connected via an industrial network. [Means for solving the problem]
[0006] An information processing device according to one embodiment of the present disclosure is an information processing device connected to a master and one or more slaves via an industrial network, and includes: a receiving unit that receives frames repeatedly transmitted from the master within the industrial network; a first memory unit that stores log data of the frames; an extracting unit that, when an abnormality is detected in the master or one or more slaves, extracts from the first memory unit frame log data from the time when the abnormality was detected to a predetermined time before; a second memory unit that stores the extracted frame log data as pre-failure log data; and a transmitting unit that transmits the pre-failure log data to the master via the industrial network in response to a request from the master. Effect of the Invention
[0007] According to the present disclosure, it is possible to provide a technique that enables faster analysis of an abnormality and / or recovery when an abnormality occurs in a control system connected via an industrial network. [Brief description of the drawings]
[0008] [Figure 1] 1 is a diagram illustrating an example of a control system 1 according to an embodiment of the present invention. [Diagram 2] FIG. 2 is a diagram illustrating an example of a frame structure used in an industrial network. [Diagram 3] FIG. 11 is a diagram for explaining a time synchronization process. [Figure 4] FIG. 2 illustrates an example of the configuration of a slave. [Diagram 5] FIG. 2 illustrates an example of a hardware configuration of a monitoring device. [Figure 6] FIG. 2 is a diagram illustrating an example of a functional block configuration of a monitoring device. [Figure 7] FIG. 13 is a diagram illustrating a state in which synchronization processing is operating normally. [Figure 8] 11 is a diagram for explaining an event that occurs when an abnormality occurs in the master and the master is no longer able to transmit frames at equal intervals. FIG. [Figure 9]11 is a diagram for explaining an event that occurs when an abnormality occurs in the local clock of a synchronous master-slave, causing a deviation in the reference time. [Figure 10] 1 is a diagram for explaining an event that occurs when an abnormality occurs in a local clock of a monitoring device; [Figure 11] 11 is a diagram illustrating the relationship between combinations of synchronization processing abnormalities and causes of occurrence of the synchronization processing abnormalities. [Figure 12] 13 is a flowchart illustrating an example of a processing procedure for detecting an abnormality in synchronization processing. [Figure 13] 11A and 11B are diagrams illustrating a specific example of a synchronization anomaly detection process. [Figure 14] FIG. 13 is a diagram for explaining a modified example. [Figure 15] FIG. 13 is a diagram for explaining a modified example. [Figure 16] 11 is a sequence diagram illustrating an example of a processing procedure for extracting log data and transmitting the data to a master when an abnormality occurs. FIG. [Figure 17] FIG. 13 is a diagram illustrating an example of frame data stored in pre-failure log data. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present disclosure will be described with reference to the accompanying drawings, in which the same reference numerals denote the same or similar configurations.
[0010] <System configuration> 1 is a diagram showing an example of a control system 1 according to this embodiment. The control system 1 includes a master 10, one or more slaves 20, and a monitoring device 30. The master 10, the one or more slaves 20, and the monitoring device 30 are connected via an industrial network.
[0011] The master 10 is a device that realizes a predetermined function in the control system 1 by controlling the slave 20. The master 10 may be, for example, a motion controller, a sequence controller, a robot controller, etc. The master 10 may also be called a controller, a control device, etc. The master 10 may be a device realized by using dedicated hardware, or may be a general-purpose information processing device in which a non-real-time OS and a real-time OS are installed. Specific examples of the non-real-time OS include Windows (registered trademark), macOS (registered trademark), etc. Specific examples of the real-time OS include RTX (Real Time Extension), RTH (Real Time Hypervisor), etc. Specific examples of the general-purpose information processing device include, for example, a PC (personal computer), a notebook PC, a server, etc.
[0012] The slaves 20 are, for example, servo motors (including servo drivers), stepping motors, sensors, etc., and are devices that execute various processes in the control system 1. Each slave is divided into a communication processing unit that processes a communication protocol used in the industrial network, and an application unit that performs processes such as motion control.
[0013] The monitoring device 30 is a device that monitors the operating state of the control system 1, constantly records frames (which may also be called data or packets) flowing through the industrial network, and detects the occurrence of an abnormality in the control system 1. The monitoring device 30 also operates as a slave 20 in the control system 1. In other words, the monitoring device 30 is recognized as the slave 20 by the master 10. The monitoring device 30 may be a device realized using dedicated hardware, or may be a general-purpose information processing device or computer on which a non-real-time OS and a real-time OS are installed.
[0014] Examples of protocols used in industrial networks include EtherCAT (registered trademark) and Ethernet / IP (EtherNet / IP). In the following description, the industrial network is described as EtherCAT, but the present embodiment is not limited to this. Any communication protocol may be used as long as it communicates in a master-slave manner and has a synchronization function, which will be described later.
[0015] In the industrial network, the master 10 and the slaves 20 (including the monitoring device 30) communicate with each other by an on-the-fly method. In the on-the-fly method, one fixed-length frame transmitted from the master 10 passes through each slave 20 in order and finally returns to the master 10. In addition, each slave 20 can read data addressed to itself from the frame when the frame passes through, and can write data addressed to the master 10 or another slave 20 to the frame. In the example of FIG. 1, the frame transmitted from the master 10 passes through each slave 20 and the monitoring device 30 in the order of S1 to S6, and returns to the master 10. Note that each slave 20 processes the frame when it first passes through the monitoring device 30, and does not process the frame when it returns from the monitoring device 30 to the master 10. For example, the slave 20-1 processes the frame received at S1 (writes and / or reads data), but transfers the frame received at S5 to the master 10 without processing it. Similarly, the slave 20-2 processes the frame received in S2 (writes and / or reads data), but does not process the frame received in S4 and transfers it directly to the slave 20-1.
[0016] In this embodiment, the monitoring device 30 is connected after all the slaves 20 in the industrial network in order to detect abnormalities occurring in the master 10 and the slaves 20. In other words, the monitoring device 30 operates as a terminal slave 20. For example, assume that a slave 20-1 and a slave 20-2 exist in the control system 1. In this case, the monitoring device 30 is connected to the industrial network so that a frame output from the master 10 passes through the slave 20-1, the slave 20-2, and the monitoring device 30 in this order.
[0017] (Frame structure used in industrial networks) 2 is a diagram showing an example of a frame structure used in an industrial network. One frame includes an Ethernet header, Ethernet data, and a Frame Check Sequence (FCS). The Ethernet data includes a header and a datagram.
[0018] The datagram is further divided into N datagram fields. Each datagram field further includes a datagram header, data, and a working counter (WKC). The datagram header stores a command indicating how to process the data (write a value, read a value, etc.) and an address indicating the destination for processing the data.
[0019] In an industrial network, different datagrams are used when transmitting data from the master 10 to the slave 20 and when transmitting data from the slave 20 to the master 10. In other words, at least two datagrams are assigned to one slave 20 that transmits and receives data to and from the master 10.
[0020] Here, in order for the master 10 to write a value to a memory (also called a register) included in the slave 20 or to read a value from the memory included in the slave 20, the master 10 needs to specify the address of the memory to which the value is to be written or read. In an industrial network, there are two methods for specifying a memory address.
[0021] The first method is to directly specify the physical address of the memory by combining an identifier for identifying the slave 20 (called a "setting address" in EtherCat) with an address of the memory in the slave 20 (meaning an actual address, called a "register address" in EtherCat). When writing or reading a value to or from the memory in the slave 20, an index and a subindex can also be used instead of the register address. The index and subindex correspond to the contents of the data stored in the memory, and by specifying the index and subindex, it is possible to write or read a value without being aware of the actual address. The correspondence between the index and subindex and the memory address is defined in advance in the slave 20.
[0022] The second method is to regard the memory spaces of all the slaves 20 in the control system 1 as one memory space, and to express a position in the memory space by one logical address. Data indicating the correspondence between the logical address and the address (actual address) of the memory of each slave 20 is set in advance in each slave 20. By using the logical address, the master 10 can write and read data without being aware of which slave 20 it is accessing.
[0023] The master 10 performs processes such as writing values to the memory and reading values from the memory by specifying a command in addition to specifying a memory address. Examples of commands include FPWR (data write specifying the slave 20 and real address), FPRD (data read specifying the slave 20 and real address), LWR (data write specifying a logical address), and LRD (data read specifying a logical address).
[0024] (Overview of synchronization process) FIG. 3 is a diagram for explaining an overview of the synchronization process. The industrial network has a mechanism for performing highly accurate time synchronization (for example, the time synchronization deviation is within 1 μs) between each slave 20. In the case of EtherCat, the synchronization process is called DC (Distributed Clocks) synchronization. By performing the synchronization process, each slave 20 is synchronized with a predetermined reference time (hereinafter referred to as "reference time"), and each slave 20 performs various processes according to the reference time. Note that the accuracy of the clock provided in the master 10 is often lower than the accuracy of the clock provided in the slave 20 in order to reduce costs. Therefore, in the synchronization process, a local clock held by a slave 20 capable of executing the synchronization process among the slaves 20 connected in series to the industrial network may be used as the reference time. In the following description, the slave 20 whose local clock is used as the reference time is called a "synchronization master slave." Note that in this embodiment, the synchronization master slave will be described as the first slave 20 capable of executing the synchronization process among the slaves 20 connected in series to the industrial network (slave 20-1 in the example of FIG. 1). In EtherCat, the reference time is called the Reference Clock. If the master 10 has a clock with the same high accuracy as that of the slave 20, the local clock of the master 10 may be used as the reference time.
[0025] The reference time is expressed as an absolute time with a certain time as the origin (zero). The reference time may be expressed as a value with a predetermined number of bits. For example, in EtherCat, the reference time is expressed as a 32-bit or 64-bit numerical value with the origin at 00:00:00 on January 1, 2001. The minimum unit of the reference time may be 1 microsecond or 1 nanosecond.
[0026] To realize the synchronization process, the master 10 measures in advance, in accordance with the EtherCAT specifications, the frame propagation delay between the synchronous master slave and each slave 20, the difference between the reference time and the local clock of each slave (offset value), etc., and writes these values into the memory of each slave 20. Each slave 20 other than the synchronous master slave can calculate the reference time by adding the offset value to its own local clock.
[0027] Generally, the time that a clock ticks has a slight difference (also called drift), so the difference from the reference time becomes larger the longer the time that passes after synchronization is completed. Therefore, in order to suppress the difference from the reference time (i.e., to compensate for the clock drift), the master 10 periodically distributes the reference time.
[0028] Specifically, the synchronous master slave stores the reference time in a frame received from the master 10 according to an instruction from the master 10, and transmits the frame with the reference time stored therein to the next slave 20. Each slave 20 acquires the reference time from the received frame in which the reference time is stored, and writes the acquired reference time frame in the slave 20's own memory. In the following description, a frame for distributing the reference time to each slave 20 is called a "reference time frame." Note that all frames repeatedly transmitted from the master 10 may be reference time frames. Alternatively, the reference time frame may be one every N frames (N is a natural number) out of all frames repeatedly transmitted from the master 10. In the example of FIG. 3, all frames are reference time frames, and the synchronous master slave 20-1 stores the reference time in frames A and B received from the master 10 and transmits them to the slave 20-2.
[0029] Each slave 20 other than the synchronous master slave acquires the reference time from the received reference time frame. As described above, each slave 20 knows the propagation delay between itself and the synchronous master slave, and therefore can recognize the correct reference time by adding the propagation delay to the reference time included in the reference time frame. In other words, each slave 20 other than the synchronous master slave can correct the reference time that it recognizes to the correct reference time based on the reference time included in the reference time frame.
[0030] As described above, the synchronous master slave stores the time of its own local clock as the reference time in the frame received from the master 10, and transmits it to the next slave 20. The value of the local clock that the synchronous master slave stores as the reference time may be any value that corresponds to the time from when the synchronous master slave receives the frame to when it transmits the frame containing the reference time to the next slave 20.
[0031] FIG. 4 is a diagram showing an example of the configuration of a slave. The communication processing unit 20b included in each slave refers to the reference time, propagation delay, offset, etc. written in the memory 20a of the communication processing unit, and synchronizes with the reference time. Then, each slave repeatedly generates a synchronization signal at a predetermined period according to the synchronized reference time, and notifies the application unit 20c included in each slave. In EtherCat, the synchronization signal is called SYNC0 / SYNC1, etc. The first time when the synchronization signal is repeatedly generated (hereinafter referred to as the "start time of the synchronization signal") and the generation period of the synchronization signal (hereinafter referred to as the "synchronization signal period") are notified in advance to each slave 20 by the master 10. The start time of the synchronization signal is specified as absolute time according to the time axis of the reference time.
[0032] When the synchronization process is used, the master 10 repeatedly transmits frames at the same period as the generation period of the synchronization signal so that one frame arrives at each slave 20 between two successive synchronization signals. However, as described above, the accuracy of the clock provided in the master 10 is often lower than the accuracy of the clock provided in the slave 20. Therefore, the period in which the frames arrive at each slave 20 may vary slightly compared to the period in which the synchronization signal is generated in each slave 20.
[0033] The frame repeatedly transmitted by the master 10 at a predetermined cycle includes an area for storing data in addition to the reference time described above. For example, a command and a value for writing a value to the memory of each slave 20 and / or a command for reading a value from the memory 20a of each slave 20 are stored in the area. The communication processing unit 20b of the slave 20 reads a value from the received frame and writes it to the memory 20a in accordance with the command. Furthermore, the application unit 20c of the slave 20 performs application processing (e.g., motion control, etc.) using the value written in the memory 20a at the timing when a synchronization signal is notified from the communication function unit. In other words, as long as the time synchronization function operates normally and the master 10 continues to transmit frames at a predetermined cycle, the timing when the synchronization signal is generated in each slave 20 will be consistent between the slaves 20, and the timing when each slave 20 performs application processing will also be consistent.
[0034] 3, the arrival time of the frame is delayed in the slave 20-2 by an amount corresponding to a transmission delay between the synchronization master slave 20-1 and the slave 20-2. However, since the application process (AP process) is executed using the synchronization signal as a trigger, the timing at which the application process is started in the synchronization master slave 20-1 and the timing at which the application process is started in the slave 20-2 will be the same.
[0035] (Overview of the process performed by the monitoring device) In this embodiment, the monitoring device 30 performs the following processes.
[0036] 1. Detection of abnormality in synchronization processing: The monitoring device 30 detects that an abnormality has occurred in the synchronization processing, and notifies the user or the master 10 that manages the control system 1.
[0037] 2. Recording of frames immediately before an abnormality occurs: The monitoring device 30 constantly records (captures) frames flowing through the industrial network and saves log data of one or more captured frames. Furthermore, when it detects that an abnormality has occurred in the control system 1, it extracts log data of one or more frames that flowed through the industrial network during a predetermined period before the abnormality occurred from the saved log data. Furthermore, when the monitoring device 30 receives a request from the master 10, it transmits the extracted log data of one or more frames to the master 10 via the industrial network.
[0038] <Hardware configuration> 5 is a diagram showing an example of a hardware configuration of the monitoring device 30. The monitoring device 30 includes a processor 11 such as a CPU (Central Processing Unit) or a GPU (Graphical Processing Unit), a memory (e.g., a RAM (Random Access Memory) or a ROM (Read Only Memory)), a storage device 12 such as a HDD (Hard Disk Drive) and / or an SSD (Solid State Drive), a network IF (Network Interface) 13 for wired or wireless communication, an input device 14 for accepting input operations, and an output device 15 for outputting information. The input device 14 is, for example, a keyboard, a touch panel, a mouse, and / or a microphone. The output device 15 is, for example, a display, a touch panel, and / or a speaker.
[0039] <Function block configuration> 6 is a diagram showing an example of a functional block configuration of the monitoring device 30. The monitoring device 30 has a non-real-time OS 100, a real-time OS 200, and a second storage unit 300. The non-real-time OS 100 includes a display unit 110, a collection unit 120, a first detection unit 130, an extraction unit 140, and a first storage unit 150. The real-time OS 200 includes a slave processing unit 210. The slave processing unit 210 includes a communication module 220 and a fixed-cycle processing unit 230. The communication module 220 includes a third storage unit 221, and the fixed-cycle processing unit 230 includes a second detection unit 231.
[0040] The first storage unit 150, the second storage unit 300, and the third storage unit 221 can be realized by using the storage unit 12 included in the monitoring device 30. The display unit 110, the collection unit 120, the first detection unit 130, the extraction unit 140, and the slave processing unit 210 can be realized by the processor 11 of the monitoring device 30 executing a program stored in the storage unit 12. The program can be stored in a storage medium. The storage medium storing the program may be a non-transitory computer readable medium. The non-transitory storage medium is not particularly limited, and may be, for example, a storage medium such as a Universal Serial Bus (USB) memory or a Compact Disc Read-Only Memory (CD-ROM).
[0041] The first storage unit 150 is provided in the non-real-time OS, and stores a log accumulation DB (DataBase) 151 and a setting file 152. The log accumulation DB 151 is a database that stores frames transmitted through the industrial network, which are captured by the communication module 220 of the real-time OS 200. The setting file 152 stores various data that specifies the operation of the monitoring device 30.
[0042] The second storage unit 300 is provided in a memory that can be referenced by both the non-real-time OS 100 and the real-time OS.
[0043] The display unit 110 operates on a non-real-time OS and displays various screens on a display etc. For example, the display unit 110 displays a screen showing the contents of a detected abnormality on a display etc.
[0044] The collection unit 120 operates on a non-real-time OS, acquires frames flowing through the industrial network from the real-time OS 200 via a FIFO (First In First Out) queue 310 included in the second storage unit 300, and stores the frames in a log accumulation DB 151 of the first storage unit 150. In other words, the first storage unit 150 (log accumulation DB 151) stores log data of one or more received frames.
[0045] The first detection unit 130 runs on a non-real-time OS and analyzes frames received by the communication module 220 to detect the presence or absence of an abnormality in the synchronization process performed between the master 10 and one or more slaves 20 based on a reference time distributed within the industrial network.
[0046] The extraction unit 140 operates on a non-real-time OS, and when the first detection unit 130 detects that an abnormality has occurred in the master 10 or one or more slaves 20, the extraction unit 140 extracts, from the log accumulation DB 151, log data of frames from the time when the abnormality was detected to a predetermined time before (the second time before). The extraction unit 140 also stores the extracted log data of the frames in the second storage unit 300 as pre-failure log data 320. In other words, the second storage unit 300 stores the log data extracted by the extraction unit 140 as pre-failure log data 320.
[0047] The slave processing unit 210 performs various processes for the monitoring device 30 to operate as the slave 20 .
[0048] The communication module 220 operates on the real-time OS 200, captures a frame flowing through the industrial network, and stores it in the third storage unit 221. The communication module 220 also acquires data addressed to itself according to the command included in the frame flowing through the industrial network, and stores it in the third storage unit 221. Also, according to the command included in the frame flowing through the industrial network, the communication module 220 acquires data to be transmitted to the master 10 from the third storage unit 221, and stores it in the frame. As described above, the monitoring device 30 operates as the terminal slave 20. That is, the third storage unit 221 corresponds to the memory of the slave 20 described in "(Frame structure used in industrial networks)". For example, when the command included in the frame is FPWR, and the address included in the frame indicates the monitoring device 30, the communication module 220 stores the value included in the frame in an area of the third storage unit 221 designated by the address included in the frame. In addition, when the command contained in the frame is FPRD and the address contained in the frame points to the monitoring device 30, the communication module 220 retrieves a value from an area in the third memory unit 221 specified by the address contained in the frame and stores it in the frame.
[0049] The fixed-period processing unit 230 operates on the real-time OS 200. The fixed-period processing unit 230 repeatedly performs a process of acquiring frames flowing through the industrial network from the third storage unit 221 and storing the frames in the FIFO queue 310 at a predetermined period (for example, the period at which frames are transmitted from the master 10). The fixed-period processing unit 230 also acquires data to be stored in the frames from the pre-fault log data 320 and stores the data in the third storage unit 221.
[0050] The second detection unit 231 detects the presence or absence of an abnormality in the synchronization process performed between the master 10 and one or more slaves 20 based on a reference time distributed within the industrial network by analyzing the frame captured by the communication module 220. The monitoring device 30 is assumed to include at least one of the first detection unit 130 and the second detection unit 231. That is, the monitoring device 30 may detect the presence or absence of an abnormality in the synchronization process on the non-real-time OS 100 side (i.e., the first detection unit 130), or may detect the presence or absence of an abnormality in the synchronization process on the real-time OS 200 side (i.e., the second detection unit 231). The first detection unit 130 and the second detection unit 231 may be called "abnormality detection units."
[0051] The communication module 220 may be referred to as a "transmitter" and a "receiver." The communication module 220 (receiver) receives frames repeatedly transmitted from the master 10 within the industrial network. In addition, the communication module 220 (transmitter) transmits pre-fault log data 320 to the master 10 via the industrial network in response to a request from the master 10.
[0052] <Processing Procedure> (Detection of synchronization abnormality) Next, a process in which the monitoring device 30 detects that an abnormality has occurred in the synchronization process will be specifically described. In the following description, it is assumed that the detection of the synchronization process abnormality is performed by the first detection unit 130, but as described above, it is also possible to detect the synchronization process abnormality by the second detection unit 231. In addition, in the following description, it is assumed that the slave 20 and the monitoring device 30 are different devices.
[0053] The monitoring device 30 detects two types of synchronization abnormality, synchronization abnormality A and synchronization abnormality B, which will be described below, and determines the cause of the synchronization abnormality based on the combination of the two types of synchronization abnormality. Note that synchronization abnormality A and synchronization abnormality B may be called the "first abnormality" and the "second abnormality", respectively.
[0054] Synchronization Abnormality A: When the reference time stored in the reference time frame is not included between the times when two consecutive synchronization signals are generated, during which the reference time frame should be received. Synchronization abnormality B: A case in which the difference between the reference times included in each of two consecutive time synchronization frames is different from the difference between the times at which the monitoring device 30 received each of the two consecutive time synchronization frames.
[0055] 7 is a diagram showing a state in which the synchronization process is operating normally. The process of detecting the synchronization abnormality A and the synchronization abnormality B will be specifically described with reference to FIG.
[0056] [Synchronization error A] 7, the horizontal axis t represents the time when the synchronization signal is generated. The time when the synchronization signal is generated may be expressed in any manner, but may be expressed, for example, as a 32-bit or 64-bit numerical value starting from 00:00:00 on Jan. 1, 2000, with the smallest unit of time being 1 nanosecond.
[0057] 7, the synchronization signal period is set to 1000 (e.g., 1 ms), and each frame is a reference time frame. Furthermore, the slave 20-1 is a synchronization master slave, and will be referred to as the synchronization master slave 20-1 in the following description. That is, the synchronization master slave 20-1 stores a reference time in a reference time frame received from the master 10 and transmits the reference time frame to the slave 20-2. The slave 20-2 acquires the reference time from the received reference time frame, and transmits the reference time frame to the monitoring device 30. The monitoring device 30 also acquires the reference time from the received reference time frame, and transmits the reference time frame to the master 10.
[0058] The reference time frames are repeatedly transmitted from the master 10 at a period almost identical to the synchronization signal period. For example, reference time frame A is transmitted from the master 10 between the generation of synchronization signal Sy1 and the generation of synchronization signal Sy2, passes through slave 20-1, slave 20-2, and monitoring device 30, and returns to the master 10 before synchronization signal Sy2 is generated. Therefore, if the synchronization process is normal, the slave 20 and monitoring device 30 will always receive one reference time frame between two consecutive synchronization signals.
[0059] The time when the first synchronization signal is generated is the time specified as the "synchronization signal start time," and the second and subsequent synchronization signals are generated every time a "synchronization signal period" passes. In other words, the time when the Nth synchronization signal (N is an integer equal to or greater than 1) is generated can be calculated using the formula "synchronization signal start time + ((N-1) x synchronization signal period." Thus, it can be said that the Nth frame to be transmitted after the start of synchronization processing should be received by each slave 20 between the "synchronization signal start time + (N-1) x synchronization signal period" and the "synchronization signal start time + N x synchronization signal period."
[0060] Here, the synchronization master slave 20-1 stores the time of its own local clock as the reference time in the reference time frame received from the master 10, and transmits it to the slave 20-2. As described above, the value of the local clock stored by the synchronization master slave 20-1 as the reference time may be the time from when the synchronization master slave 20-1 receives a frame to when it transmits the frame storing the reference time to the slave 20-2. Therefore, the first detection unit 130 detects the presence or absence of the synchronization anomaly A by determining whether or not the reference time exists between the times when two consecutive synchronization signals are generated, at which the reference time frame should be received, for the reference time frame among the frames repeatedly transmitted from the master 10.
[0061] More specifically, the first detection unit 130 determines that synchronization abnormality A has not occurred if the reference time exists between the times when two consecutive synchronization signals are generated in one or more slaves 20 (or in the synchronization master slave) and the reference time frame should be received by one or more slaves 20 (or the synchronization master slave). Also, the first detection unit 130 determines that synchronization abnormality A has occurred if the reference time does not exist between the times when two consecutive synchronization signals are generated in one or more slaves 20 (or in the synchronization master slave) and the reference time frame should be received by one or more slaves 20 (or the synchronization master slave).
[0062] The first detection unit 130 may obtain the "start time of the synchronization signal" and the "synchronization signal period", and calculate (estimate) the time when two consecutive synchronization signals are generated, at which the reference time frame should be received, based on the obtained "start time of the synchronization signal" and "synchronization signal period". For example, it is assumed that the reference time frame is a frame transmitted Xth after the start time of the synchronization signal. In this case, the first detection unit 130 can calculate (estimate) the time when the first synchronization signal of the two consecutive synchronization signals, at which the reference time frame should be received, is generated, using the formula "start time of the synchronization signal+(X-1)×synchronization signal period". The first detection unit 130 can also calculate (estimate) the time when the second synchronization signal of the two consecutive synchronization signals, at which the reference time frame should be received, is generated, using the formula "start time of the synchronization signal+X×synchronization signal period".
[0063] As will be explained below, synchronization anomaly A is detected when the master 10 is no longer able to transmit frames at equal intervals due to a failure of the local clock within the master 10, or when the local clock of a synchronous master-slave fails, causing a deviation in the reference time stored in the reference time frame.
[0064] FIG. 8 is a diagram for explaining an event that occurs when an abnormality occurs in the master 10 and frames cannot be transmitted at equal intervals. Points that are not particularly mentioned may be the same as those in FIG. 7. In the example of FIG. 8, some abnormality occurs in the master 10, and the timing of transmitting the reference time frame C from the master 10 is delayed. In this case, the reference time stored in the reference time frame C is the time (8600) when the synchronization master slave 20-1 receives the reference time frame C. However, the time when the reference time frame C should be received by each slave 20 is between the time (7500) when the synchronization signal Sy3 is generated and the time (8500) when the synchronization signal Sy4 is generated. Therefore, when the first detection unit 130 receives the reference time frame C, it determines that the reference time (8600) included in the reference time frame C does not exist in the period when the reference time frame C should be received (between the time (7500) when the synchronization signal Sy3 is generated and the time (8500) when the synchronization signal Sy4 is generated), and detects that a synchronization abnormality A has occurred.
[0065] FIG. 9 is a diagram for explaining an event that occurs when an abnormality occurs in the local clock of the synchronization master slave, causing a deviation in the reference time. Points that are not particularly mentioned may be the same as those in FIG. 7. In the example of FIG. 9, the time ticked by the local clock of the synchronization master slave 20-1 becomes faster than the actual time, and as a result, the reference times stored in frames C and D are shifted to 8600 and 11500, respectively, instead of the actual times (7800 and 8800 shown in FIG. 7). Therefore, when the first detection unit 130 receives the reference time frame C, it determines that the reference time (8600) included in the reference time frame C does not exist in the period when the reference time frame C should be received (between the time (7500) when the synchronization signal Sy3 is generated and the time (8500) when the synchronization signal Sy4 is generated), and detects that a synchronization abnormality A has occurred.
[0066] [Synchronization error B] If the local clock of the synchronization master slave 20-1 is normal (i.e., the reference time stored in the reference time frame by the synchronization master slave 20-1 is normal) and the local clock of the monitoring device 30 is also normal, the difference between the times when the monitoring device 30 receives two successive reference time frames and the difference between the reference times included in the two reference time frames should be approximately the same value. For example, in the example of Fig. 7, the difference (1000) between the time (5950) when the monitoring device 30 receives frame A and the time (6950) when the monitoring device 30 receives frame B is the same as the difference (6800) between the reference time of frame A and the reference time of frame B and the difference (5800) between the reference time of frame A and the reference time of frame B.
[0067] Therefore, the first detection unit 130 detects the presence or absence of an abnormality in the synchronization process based on the difference between the times when the monitoring device 30 receives each of two consecutive reference time frames including the reference time and the difference between the reference times included in each of the two consecutive reference time frames. More specifically, the first detection unit 130 determines that the synchronization abnormality B has not occurred if the "degree of deviation" between the difference between the times when the monitoring device 30 receives each of the two consecutive reference time frames and the difference between the reference times included in each of the two consecutive reference time frames is equal to or less than a predetermined value. Also, the first detection unit 130 determines that the synchronization abnormality B has occurred if the "degree of deviation" between the difference between the times when the monitoring device 30 receives each of the two consecutive reference time frames and the difference between the reference times included in each of the two consecutive reference time frames exceeds a predetermined value. A method of calculating the degree of deviation will be described later.
[0068] As described below, synchronization abnormality B is detected when the local clock of synchronization master slave 20-1 fails, causing a deviation in the reference time stored in the reference time frame, or when the local clock of monitoring device 30 fails, causing monitoring device 30 to be unable to correctly measure the time at which it received the frame.
[0069] 9, the time recorded by the local clock of synchronization master slave 20-1 has become faster than the actual time, and as a result, the reference times stored in frames C and D are shifted to 8600, not the actual times (7800 and 8800 shown in FIG. 7). Therefore, the first detection unit 130 determines that the degree of deviation between the difference (1000) between the time frame B (6950) and the time frame C (7950) are received and the difference (1800) between the reference time (6800) stored in frame B and the reference time (8600) stored in frame C exceeds a predetermined value (e.g., 0.1), and detects that synchronization abnormality B has occurred.
[0070] FIG. 10 is a diagram for explaining an event that occurs when an abnormality occurs in the local clock of the monitoring device 30. Points that are not particularly mentioned may be the same as those in FIG. 7. In the example of FIG. 10, the time ticked by the local clock of the monitoring device 30 becomes slower than the actual time, and as a result, the times at which frames C and D are received are shifted to 7450 and 7950, rather than the actual times (7950 and 8950 shown in FIG. 7). Therefore, the first detection unit 130 determines that the degree of deviation between the difference (500) between the time at which frame B is received (6950) and the time at which frame C is received (7450) and the difference (1000) between the reference time (6800) stored in frame B and the reference time (7800) stored in frame C exceeds a predetermined value (e.g., 0.1), and detects that a synchronization abnormality B has occurred.
[0071] As described above, there are three possible causes for a synchronization anomaly: when an abnormality occurs in the master 10 and frames cannot be transmitted at equal intervals, when a failure occurs in the local clock of the synchronization master slave 20-1 and a deviation occurs in the reference time stored in the reference time frame, or when an abnormality occurs in the local clock of the monitoring device 30. In addition, depending on the cause, the pattern in which the abnormality is detected, either synchronization abnormality A or synchronization abnormality B, differs.
[0072] This relationship is shown in a table in FIG. 11. FIG. 11 is a diagram showing the relationship between combinations of synchronization process anomalies and causes of synchronization process anomalies. The first detection unit 130 judges the cause of the anomaly based on the relationship shown in FIG. 11. Specifically, when synchronization anomaly A occurs but synchronization anomaly B does not occur, the first detection unit 130 judges that there is an anomaly in the transmission period of the frames repeatedly transmitted from the master 10. Furthermore, when synchronization anomaly A does not occur but synchronization anomaly B occurs, the first detection unit 130 judges that there is an anomaly in the clock provided in the monitoring device 30. Furthermore, when synchronization anomaly A and synchronization anomaly B both occur, the first detection unit 130 judges that there is an anomaly in the clock of the synchronization master slave.
[0073] (Procedure for detecting abnormalities in synchronization processing) Reference signal frame FIG. 12 is a flowchart showing an example of a processing procedure for detecting an abnormality in synchronization processing. In the description of FIG. 12, the master 10 is assumed to repeatedly transmit frames according to the synchronization signal period. Moreover, the term "frame" refers to both the reference time frame and frames other than the reference time frame (i.e., frames not including the reference time). Before starting an operation to be performed by the control system 1, such as motion control, the control system 1 performs an initialization process such as distributing settings of various data used for motion control, etc. When the initialization process is completed, the control system 1 transitions to a state in which it can start operating (referred to as an "operational state"). Moreover, it is assumed that the monitoring device 30 has acquired the "start time of the synchronization signal" and the "synchronization signal period" in advance before transitioning to the operational state. Note that T-init used in the following description refers to the "start time of the synchronization signal". The counter m is an integer equal to or greater than 1, and indicates the cumulative number of times the monitoring device 30 has received the reference time frame. Counter n is an integer equal to or greater than 1, and indicates the cumulative number of times that the monitoring device 30 has received a frame (however, the first reference time frame is counted as the first frame, and frames received before that reference time frame are not counted). The initial values of counters n and m are set to 0.
[0074] In step S20, the first detection unit 130 obtains one frame from the log accumulation DB 151.
[0075] In step S21, if the frame is a reference time frame, the first detection unit 130 proceeds to a processing procedure of step S22, whereas if the frame is not a reference time frame, the first detection unit 130 proceeds to a processing procedure of step S23.
[0076] In step S22, if counter m is equal to or greater than 1, first detection unit 130 adds 1 to counter n and proceeds to the processing procedure of step S37. If counter m is 0, first detection unit 130 proceeds to the processing procedure of step S37 without performing anything.
[0077] In step S23, the first detection unit 130 adds 1 to the counters n and m.
[0078] In step S24, the first detection unit 130 stores the value of the reference time included in the reference time frame in a variable Rt[m].
[0079] In step S25, the first detector 130 stores the time when the communication module 220 receives the reference time frame (the clock value of the monitoring device 30) in a variable Nt[m].
[0080] In step S26, if m=1, the process proceeds to step S27, and if m=1 is not true, the process proceeds to step S28.
[0081] In step S27, the first detection unit 130 calculates the time (T-start) at which the monitoring device 30 starts the abnormality detection process (hereinafter referred to as the "abnormality detection start time"). The abnormality detection start time (T-start) can be calculated using the following formula (1). X is an integer equal to or greater than 0.
[0082] Equation (1): T-start = T-init + (sync signal period × X), the largest T-start that satisfies T-start < variable Rt[1] In step S28, the first detection unit 130 calculates a variable T n Calculate.
[0083] Formula (2): T n = T-start + synchronization signal period × (n-1) In step S29, the first detection unit 130 calculates a variable T n+1 Calculate.
[0084] Formula (3): T n+1 = T-start + synchronization signal period × (n) In step S30, if the following formula (4) is satisfied, the first detection unit 130 proceeds to the processing procedure of step S31, and if the following formula (4) is not satisfied, the first detection unit 130 proceeds to the processing procedure of step S32.
[0085] Formula (4): T n < Rt[m] < T n+1 In step S31, the first detection section 130 determines that a synchronization abnormality A has been detected.
[0086] In step S32, if the counter m is equal to or greater than 2, the first detection unit 130 proceeds to the processing procedure of step S33, and if the counter m is equal to 1, the first detection unit 130 proceeds to the processing procedure of step S37.
[0087] In step S33, the first detection unit 130 calculates a variable E1 using the following formula (5).
[0088] Equation (5): E1 = Rt[m] -Rt[m-1] In step S34, the first detection unit 130 calculates a variable E2 using the following formula (6).
[0089] Equation (6): E2 = Nt[m] -Nt[m-1] In step S35, the first detection unit 130 calculates the degree of deviation using the following formula (7), and if the degree of deviation exceeds a predetermined value, the process proceeds to the processing procedure of step S36, and if the degree of deviation is equal to or smaller than the predetermined value, the process proceeds to the processing procedure of step S37. Note that Abs in formula (7) means an absolute value.
[0090] Equation (7): Deviation degree = Abs(1.0-(E1 / E2)) In step S36, the first detection section 130 determines that synchronization abnormality B has been detected.
[0091] In step S37, if the first detection section 130 does not want to end the abnormality detection process, the process returns to step S20, and if the first detection section 130 wants to end the abnormality detection process, the process ends the process in FIG.
[0092] An example in which a clock abnormality in a synchronous master / slave is detected as one type of synchronization abnormality by executing the above-described processing procedure will be specifically described with reference to FIG.
[0093] Fig. 13 is a diagram showing a specific example of the synchronization anomaly detection process. In the example of Fig. 13, the start time (T-init) of the synchronization signal is 5500 (time when the starting point of the reference time is 0), and the synchronization signal period is 1000 (for example, 1 ms). In addition, the reference times stored in the reference time frames B, D, E, and H are 7000, 9000, 11000, and 14000, respectively.
[0094] 12 and 13, a process of detecting a synchronization abnormality by the monitoring device 30 will be described assuming that an abnormality occurs in the local clock of the synchronization master-slave. Note that the predetermined value in the process procedure of step S35 in FIG. 12 is 0.1.
[0095] First, the first detection unit 130 acquires frame A (S20, S21-NO, S22, S37-NO in FIG. 12). Next, the first detection unit 130 acquires reference time frame B and adds 1 to counters n and m (S20, S21-YES, S23 in FIG. 12). The first detection unit 130 also stores the value 7000 of the reference time included in reference time frame B in variable Rt[1], stores the time 7200 at which the communication module 220 received reference time frame B in variable Nt[1], and calculates the variable T-start according to equation (1) (S24, S25, S26-YES, S27 in FIG. 12).
[0096] Here, in formula (1), when X=1, T-start is T-start=5500+1000=6500, which satisfies T-start < 7000. Next, when X=2, T-start is T-start=5500+1000×2=7500, which does not satisfy T-start < 7000. Therefore, the value of T-start becomes 6500.
[0097] Next, the first detection unit 130 detects the variable T n and variable T n+1 is calculated according to equations (2) and (3) (S28 and S29 in FIG. 12). Since n=1 at this point, T n becomes 6500+1000×(1-1)=6500. Similarly, T n+1 becomes 6500+1000×1=7500.
[0098] The first detection unit 130 determines whether or not formula (4) is satisfied. At this point, m=1 and Rt[1] is 7000, so 6500<Rt[1]<7500 is satisfied (S30 in FIG. 12). Therefore, the first detection unit 130 determines that synchronization anomaly A has not occurred. Next, since m=1, the first detection unit 130 skips the processing procedure of steps S33 to S36 in FIG. 12 (S32-NO).
[0099] Next, the first detection unit 130 receives frame C and adds 1 to n (S20, S21-NO, S22 in FIG. 12). At this point, n=2 and m=1.
[0100] Next, the first detection unit 130 acquires the reference time frame D and adds 1 to each of the counters n and m (S20, S21-YES, S23 in FIG. 12). The first detection unit 130 also stores the value 9000 of the reference time included in the reference time frame D in the variable Rt[2], and stores the time 9200 at which the communications module 220 received the reference time frame D in the variable Nt[2] (S24, S25 in FIG. 12).
[0101] Next, the first detection unit 130 detects the variable T n and variable T n+1 is calculated according to the formulas (2) and (3) (S28 and S29 in FIG. 12). Since n=3 at this point, T n becomes 6500+1000×(3-1)=8500. Similarly, T n+1 The result is 6500+1000×3=9500.
[0102] The first detection unit 130 judges whether or not the formula (4) is satisfied. At this time, m=2 and Rt[2] is 9000, so 8500 < Rt[2] < 9500 is satisfied (S30-YES in FIG. 12). Therefore, the first detection unit 130 judges that the synchronization anomaly A has not occurred. The first detection unit 130 also calculates E1 and E2 according to the formulas (5) and (6) (S32-YES, S33, S34 in FIG. 12). E1 is Rt[2]-Rt[1]=9000-7000=2000, and E2 is Nt[2]-Nt[1]=9200-7200=2000. The first detection unit 130 judges whether or not the formula (7) is satisfied (S35 in FIG. 12). Since Abs(1.0-E2 / E1)=1.0-2000 / 2000=0, which is equal to or less than the predetermined value 100, the first detection section 130 determines that the synchronization abnormality B has not occurred (S35-YES in FIG. 12).
[0103] Next, the first detector 130 receives frame E and adds 1 to n (S20, S21-NO, S22 in FIG. 9). At this point, n=4 and m=2.
[0104] Next, the first detection unit 130 acquires the reference time frame F, adds 1 to the counter n and counter m, stores the value of the reference time included in the reference time frame F, 11000, in the variable Rt[3], stores the time, 11200, when the communication module 220 receives the reference time frame F, in the variable Nt[3], and n and variable T n+1 is calculated according to the formula (2) and the formula (3) (S23, S24, S25, S26-NO, S28, S29 in FIG. 12). Since n=5 at this point, T n becomes 6500+1000×(5-1)=10500. Similarly, T n+1 The result is 6500+1000×5=11500.
[0105] The first detection unit 130 judges whether or not the formula (4) is satisfied. At this time, m=3 and Rt[3] is 11000, so 10500 < Rt[3] < 11500 is satisfied (S30-NO in FIG. 12). Therefore, the first detection unit 130 judges that the synchronization anomaly A has not occurred. The first detection unit 130 also calculates E1 and E2 according to the formulas (5) and (6) (S33, S34 in FIG. 12). E1 is Rt[3]-Rt[3]=11000-9000=2000, and E2 is Nt[3]-Nt[2]=11200-9200=2000. The first detection unit 130 judges whether or not the formula (7) is satisfied (S35 in FIG. 12). Since Abs(1.0-E2 / E1)=1.0-2000 / 2000=0, which is equal to or less than the predetermined value 100, the first detection section 130 determines that the synchronization abnormality B has not occurred (S35-NO in FIG. 12).
[0106] Next, the first detection unit 130 receives frame G and adds 1 to n (S22 in FIG. 12). At this point, n=6 and m=3.
[0107] Next, the first detection unit 130 acquires the reference time frame H, and adds 1 to the counter n and counter m (S20, S21-YES, S23 in FIG. 12). The first detection unit 130 also stores the value of the reference time included in the reference time frame H, 14000, in the variable Rt[4], stores the time 13200 when the communication module 220 receives the reference time frame H, in the variable Nt[4], and n and variable T n+1 is calculated according to the formulas (2) and (3) (S24, S25, S26-NO, S28, and S29 in FIG. 12). Since n=7 at this point, T n becomes 6500+1000×(7-1)=12500. Similarly, T n+1 The result is 6500+1000×7=13500.
[0108] The first detection unit 130 judges whether or not the formula (4) is satisfied. At this point, m=4 and Rt[4] is 14000, so 12500 < Rt[4] < 13500 is not satisfied (S30-NO in FIG. 12). Therefore, the first detection unit 130 judges that a synchronization anomaly A has occurred (S31 in FIG. 12). The first detection unit 130 also calculates E1 and E2 according to the formulas (5) and (6) (S33, S34 in FIG. 12). E1 is Rt[4]-Rt[3]=14000-11000=3000, and E2 is Nt[4]-Nt[3]=13200-11200=2000. The first detection unit 130 judges whether or not the formula (7) is satisfied (S35 in FIG. 12). Since Abs(1.0-E2 / E1)=Abs(1.0-3000 / 2000)=0.5, which is not equal to or less than the predetermined value 0.1, the first detection section 130 determines that a synchronization abnormality B has occurred (NO in S35, S36 in FIG. 12).
[0109] As described above, the first detection section 130 detects the synchronization abnormality A and the synchronization abnormality B, and determines that the clock of the synchronization master slave 20-1 is abnormal according to the table of FIG.
[0110] [Modification of detection of abnormality in synchronization processing] (Variation 1) In the detection of the synchronization process abnormality described above, the monitoring device 30 may execute only one of the detection of the synchronization abnormality A or the detection of the synchronization abnormality B.
[0111] (Variation 2) In the log accumulation DB 151, the contents of the latest frame captured by the communication module 220 are sequentially stored in association with the time when each frame was received by the monitoring device 30 (more specifically, the communication module 220). Therefore, the first detection unit 130 may be configured to promptly detect the occurrence of a synchronization anomaly by sequentially analyzing the frames sequentially stored in the log accumulation DB 151 according to the flowchart shown in Fig. 12. Alternatively, the first detection unit 130 may be configured to detect the occurrence of a synchronization anomaly after the fact by analyzing the frames previously accumulated in the log accumulation DB 151 by batch processing according to the flowchart shown in Fig. 12.
[0112] (Variation 3) The clock of the monitoring device 30 does not necessarily have to operate on the same time axis as the reference time, but may operate on a time axis different from the reference time.
[0113] (Variation 4) 14 and 15 are diagrams for explaining the modified example. Since the industrial network processes frames on the fly, a time lag due to a propagation delay occurs between the time when the frame arrives at the synchronous master slave and the time when the frame arrives at the slave 20 that processes the frame last. Also, it is considered that a certain time lag is required between the time when the frame arrives at the slave 20 and the time when the frame can be processed by the application unit.
[0114] 14, frame A arrives at slave 20-2 immediately before time t2 when synchronization signal 2 is generated, so even if slave 20-2 receives frame A at this time, it may be difficult for the slave to start AP processing at time t2. Therefore, the first detection unit 130 may detect the presence or absence of synchronization anomaly A, taking into account the time lag.
[0115] For example, the first detection unit 130 may detect the presence or absence of the synchronization anomaly A by determining whether or not a reference time exists between the time (t1 in FIG. 15) when the first of two consecutive synchronization signals, from which the reference time frame should be received, is generated and the time (t2-a in FIG. 15) that is a predetermined time (third time) before the time (t2 in FIG. 15) when the second synchronization signal 2 is generated, for a reference time frame among frames repeatedly transmitted from the master 10. The predetermined time (third time) may be set to a time longer than the sum of the propagation delay D between the synchronization master slave and the slave 20 that last processes the frame and the processing delay time in the slave 20.
[0116] More specifically, the first detection unit 130 may determine that the synchronization abnormality A has not occurred if the reference time exists between the time when the first of two consecutive synchronization signals, which should be received by one or more slaves 20 (or synchronization master slaves), is generated in one or more slaves (or synchronization master slaves) and the time a predetermined time (third time) before the time when the second synchronization signal is generated in one or more slaves. The first detection unit 130 may also determine that the synchronization abnormality A has occurred if the reference time does not exist between the time when the first of two consecutive synchronization signals, which should be received by one or more slaves 20 (or synchronization master slaves), is generated in one or more slaves (or synchronization master slaves) and the time a predetermined time (third time) before the time when the second synchronization signal is generated in one or more slaves (or synchronization master slaves).
[0117] (Frame recording immediately before the abnormality occurred) Next, a process of extracting log data of frames flowing through the industrial network before an abnormality occurs in the control system 1 and transmitting the extracted log data to the master 10 will be described.
[0118] Here, the contents of data stored in the log accumulation DB 151 will be described. The log accumulation DB 151 stores frames captured by the communication module 220 of the real-time OS 200 and flowing through the industrial network. At this time, the data of the frames stored in the log accumulation DB 151 may include an identifier (first identifier) that uniquely identifies the frame repeatedly transmitted from the master 10. The identifier that uniquely identifies the frame is called a "cycle number." The cycle number is a number managed by the master 10 and the monitoring device 30, and is not included in the frame. For example, the master 10 sets the cycle number of the frame that is transmitted first after transitioning to an operational state to 0, and increases the cycle number by one each time the master 10 transmits a frame. Similarly, the monitoring device 30 sets the cycle number of the frame that is received first after transitioning to an operational state to 0, and increases the cycle number by one each time the master 10 receives a frame.
[0119] Furthermore, the data of the frame stored in the log accumulation DB 151 may include an identifier (second identifier) indicating a memory location to which data (also called an object) is to be written or read in the frame repeatedly transmitted from the master 10. The identifier indicating the memory location may be a combination of an identifier (setting address) for identifying the slave 20, an index, and a sub-index.
[0120] Similarly, the pre-failure log data 320 in which the log data extracted from the log accumulation DB 151 is stored may also include a cycle number and an identifier (second identifier) indicating a memory location.
[0121] That is, by specifying a cycle number, the monitoring device 30 can acquire frame data transmitted from the master at the specified cycle number from the pre-failure log data 320. Furthermore, by specifying a cycle number and an identifier indicating a memory location, the monitoring device 30 can acquire, from the pre-failure log data 320, frame data transmitted from the master at the specified cycle number and which is addressed to a specific memory of a specific slave 20, or which has been read from a specific memory of a specific slave 20 and stored in a frame.
[0122] When the extraction unit 140 is notified that an abnormality has occurred in the master 10 or one or more slaves 20, the extraction unit 140 extracts log data from the log accumulation DB 151, from the time when the abnormality is detected to a predetermined time before (the first time before). The time when the abnormality is detected may be the time when the monitoring device 30 detects the abnormality, or the time when the monitoring device 30 receives a frame in which the abnormality has been detected. The extraction unit 140 stores the extracted log data as pre-failure log data 320 in the second storage unit 300 that can be referenced by the real-time OS 200.
[0123] Here, the predetermined time (first time) may be specified by the master 10, or may be stored in advance in the setting file 152. The predetermined time may be expressed as the number of cycles (e.g., 1000 cycles, etc.) or as a specific time length (e.g., 1 second, etc.). When expressed as the number of cycles, the predetermined time may be called a "specified number of cycles." Note that, since the time length of one cycle is the same as the synchronization signal period, the number of cycles and the time length can be converted into each other. Therefore, expressing the predetermined time as a specific time length is synonymous with expressing it as the number of cycles.
[0124] The second detection unit 231 may determine that an abnormality has occurred in the master 10 when it is unable to receive a frame repeatedly transmitted from the master 10 for a certain time (second time). The certain time may be called a "WD (watchdog) timer". The WD timer may be specified by the master 10 or may be stored in the configuration file 152 in advance. In addition, when the monitoring device 30 detects the above-mentioned synchronization abnormality A or synchronization abnormality B, it may determine that an abnormality has occurred in the master 10 or one or more slaves 20. The WD timer may be expressed by the number of cycles (e.g., 100 cycles, etc.) or by a specific time length (e.g., 0.1 seconds, etc.). As described above, the number of cycles and the time length can be converted into each other, so expressing the WD timer by a specific time length and expressing it by the number of cycles are synonymous.
[0125] The communication module 220 transmits the log data stored in the pre-failure log data 320 to the master 10 via the industrial network in response to a request from the master 10. Specifically, the communication module 220 (receiving unit) receives a transmission request for pre-failure log data including a cycle number (first identifier) from the master 10. Furthermore, when the communication module 220 (transmitting unit) receives the transmission request, it transmits the data of a frame specified by the cycle number from the pre-failure log data to the master 10.
[0126] Furthermore, the communication module 220 (receiving unit) may receive a transmission request for pre-failure log data including a cycle number (first identifier and an identifier indicating a memory location (second identifier) from the master 10. Furthermore, when the communication module 220 (transmitting unit) receives the transmission request, the communication module 220 may transmit to the master 10 data from the pre-failure log data that corresponds to an identifier indicating a memory location in a frame specified by the cycle number (i.e., data to be written to the memory indicated by the identifier or data read from the memory indicated by the identifier).
[0127] Incidentally, the slave processing unit 210 may be configured to delete the pre-failure log data 320 when instructed by the master 10. Specifically, the communication module 220 (receiving unit) may receive a request to delete the pre-failure log data 320 from the master 10, and the second detection unit 231 may be configured to delete the pre-failure log data 320 when the second detection unit 231 receives the deletion request. Incidentally, the second detection unit 231 may be called a "deletion processing unit."
[0128] FIG. 16 is a sequence diagram showing an example of a processing procedure for extracting log data and transmitting it to the master 10 when an abnormality occurs.
[0129] In step S100, the master 10 transmits a frame including the WD timer and the designated cycle number, thereby writing the WD timer and the designated cycle number to a predetermined memory area in the third storage unit 221 of the monitoring device 30. The second detection unit 231 of the monitoring device 30 acquires the WD timer and the designated cycle number written in the third storage unit 221, thereby recognizing the value of the WD timer and the designated cycle number.
[0130] After the processing procedure of step S100 is completed, the control system 1 transitions to an operational state, and the master 10 starts transmitting frames.
[0131] In step S101, the second detection unit 231 detects an abnormality. For example, the second detection unit 231 may detect an abnormality when it is not possible to receive a frame from the master 10 during a period set by the WD timer. When the second detection unit 231 detects an abnormality, it stores an "abnormality detection flag" indicating that an abnormality has been detected, and an "abnormality detection cycle number" indicating the cycle number of the last frame received when the abnormality is detected, in the third storage unit 221. The abnormality detection flag and the abnormality detection cycle number are stored in the third storage unit 221 so that the master 10 can recognize that an abnormality has occurred in the industrial network. In addition, the second detection unit 231 notifies the extraction unit 140 that an abnormality has occurred. For example, the second detection unit 231 may store the abnormality detection flag and the abnormality detection cycle number in the second storage unit 300, and the extraction unit 140 may periodically refer to the second storage unit 300 to acquire the abnormality detection flag and the abnormality detection cycle number.
[0132] In step S102, when the extracting unit 140 is notified by the second detecting unit 231 that an abnormality has occurred, the extracting unit 140 extracts from the log accumulation DB 151 log data of frames from the cycle number when the abnormality was detected up to the designated number of cycles ago, and stores the extracted log data in the pre-failure log data 320. The extracting unit 140 also notifies the second detecting unit 231 that the pre-failure log data 320 has been stored. For example, the extracting unit 140 may store information indicating that the storage of the pre-failure log data 320 has been completed in the second storage unit 300, and the extracting unit 140 may periodically refer to the second storage unit 300 to check whether the information exists, thereby recognizing that the pre-failure log data 320 has been stored in the second storage unit 300.
[0133] When the pre-failure log data 320 is stored in the second storage unit 300, the second detection unit 231 stores an extraction completion flag in the third storage unit 221. The extraction completion flag indicates that the extraction of the pre-failure log data 320 has been completed and that the pre-failure log data 320 can be read from the master 10.
[0134] In step S103, upon receiving an instruction from the master 10, the communication module 220 stores the abnormality detection flag, the cycle number at the time of abnormality detection, and the extraction completion flag in a frame and transmits the frame to the master 10. By reading the abnormality detection flag, the cycle number at the time of abnormality detection, and the extraction completion flag from the received frame, the master 10 recognizes that an abnormality has been detected in the monitoring device 30, the cycle number when the abnormality occurred, and that it is now possible to read the pre-fault log data 320 from the monitoring device 30. Note that the processing procedure of step S103 may be executed, for example, by an administrator or the like who manages the master 10 operating the screen of the master 10.
[0135] In step S104, the master 10 determines, from the monitoring device 30, which cycle number of the frame to read from among the cycles from the cycle number at the time of abnormality detection up to the designated number of cycles before, which slave 20 to read the frame addressed to, which index and sub-index values to read, etc. Note that this determination may be made by an administrator or the like managing the master 10 designating the cycle number, etc.
[0136] In step S105, in order to read out data of a frame having the cycle number determined in the processing procedure of step S104, the master 10 transmits a frame including an identifier indicating the monitoring device 30, the cycle number of the frame to be read out, the identifier (setting address) of the slave 20 to be read out, and an index and subindex corresponding to the value to be read out. Note that the identifier of the slave 20 to be read out, and the index and subindex corresponding to the value to be read out may be omitted. For example, when it is desired to obtain all data of a frame having a certain cycle number, the master 10 may specify only the cycle number and omit the identifier of the slave 20 to be read out, the index and subindex.
[0137] In step S106, the communications module 220 stores the frame data of the cycle number specified by the master 10 in the processing procedure of step S105 in the frame received from the master 10 in the processing procedure of step S105, and transmits the frame to the master 10. The master 10 acquires the frame data of the specified cycle number from the received frame. Note that when reading frame data of multiple cycles, the master 10 repeats the processing procedures of steps S105 and S106.
[0138] In step S107, the master 10 stores the data of the acquired frame.
[0139] Fig. 17 is a diagram showing an example of frame data stored in the pre-failure log data 320. The recorded value index is an identifier for uniquely identifying a record recorded in the pre-failure log data 320. For example, when it is desired to acquire all values in frames with cycle numbers from 1000 to 1049, the master 10 specifies the cycle number 1000 in the processing procedure of step S105, and repeats the procedure of acquiring data of the frame with the cycle number 1000 in the processing procedure of step S106 50 times while incrementing the cycle number by 1. Returning to Fig. 16, the explanation will be continued.
[0140] The frames used in the processing procedures of steps S105 and S106 may be frames or frames that are transmitted aperiodically regardless of the synchronization processing.
[0141] In step S108, in order to erase the pre-fault log data 320 stored in the monitoring device 30, the master 10 writes the reset command flag to a specified memory area in the third memory unit 221 of the monitoring device 30 by transmitting a frame including the identifier of the monitoring device 30, an index and subindex indicating the memory area in which the reset command flag is stored, and the value of the reset command flag.
[0142] In step S109, if the second detection unit 231 of the monitoring device 30 detects that the reset command flag has been written to the third storage unit 221, it deletes the pre-fault log data 320. In addition, the second detection unit 231 deletes the abnormality detection flag, the cycle number at the time of abnormality detection, and the extraction completion flag stored in the third storage unit 221.
[0143] <Summary> According to the embodiment described above, it is possible to detect an abnormality occurring in a control system connected to an industrial network at an earlier stage. Furthermore, when an abnormality occurs in a control system connected to an industrial network, it is possible to more quickly analyze the abnormality and / or perform recovery.
[0144] In addition, since the monitoring device 30 analyzes the frames transmitted from the master 10 for each generation cycle of the synchronization signal, it is possible to quickly detect the occurrence of a synchronization abnormality before the next generation cycle of the synchronization signal arrives.
[0145] The monitoring device 30 is also adapted to detect two types of abnormality, synchronization abnormality A and synchronization abnormality B. This enables the monitoring device 30 to specifically identify the cause of a synchronization abnormality that occurs in the control system 1. Specifically, it becomes possible to identify whether the clock of the monitoring device 30 itself is abnormal, whether there is an abnormality in the transmission period of the frame transmitted by the master 10, or whether there is an abnormality in the local clock of the synchronous master-slave.
[0146] In the absence of the monitoring device 30, even if a synchronization abnormality occurs, it is difficult to distinguish whether the abnormality occurs in the local clock of the master 10 or in the local clock of the synchronous master slave. On the other hand, in this embodiment, the occurrence of a synchronization abnormality is monitored by the monitoring device 30 separately from the master 10, so that it becomes possible to specifically identify the cause of the synchronization abnormality.
[0147] Furthermore, the monitoring device 30 captures frames transmitted from the master 10 and stores them in a log accumulation DB 151 on the non-real-time OS 100. By storing the log accumulation DB 151 on the non-real-time OS side that can handle large amounts of data, the monitoring device 30 becomes able to capture and store large amounts of frame data.
[0148] Furthermore, when the monitoring device 30 detects the occurrence of an abnormality, it extracts data of a frame immediately before the occurrence of the abnormality from the log accumulation DB 151, and stores the extracted pre-failure log data 320 in a memory that can be referenced from the real-time OS 200. Since it is difficult for a non-real-time OS to perform real-time processing, it is impossible to obtain the pre-failure log data 320 according to the frame period and write it in a frame. However, by making the pre-failure log data 320 accessible from the real-time OS 200, the monitoring device 30 can obtain the pre-failure log data 320 according to the synchronization signal period and write it in a frame. In other words, the master 10 can read the pre-failure log data 320 by using a frame that is repeatedly transmitted according to the synchronization signal period.
[0149] Furthermore, the master 10 can identify the position where the motion control stopped by reading the pre-fault log data 320, and after recovery from the abnormality, it becomes possible to resume the motion control from the position where it stopped.
[0150] In addition, the monitoring device 30 transmits the pre-failure log data 320 via an industrial network. This allows the monitoring device 30 to easily transmit the pre-failure log data 320 to the master 10 even if the master 10 used in the control system 1 has difficulty in receiving external input such as a USB.
[0151] The above-described embodiments are intended to facilitate understanding of the present disclosure, and are not intended to limit the present disclosure. The flow charts, sequences, elements included in the embodiments, and their arrangements, materials, conditions, shapes, sizes, etc. are not limited to those illustrated, and can be changed as appropriate. In addition, configurations shown in different embodiments can be partially replaced or combined with each other. [Explanation of symbols]
[0152] 1 Control system, 10 Master, 11 Processor, 12 Storage device, 13 Network IF, 14 Input device, 15 Output device, 20 Slave, 30 Monitoring device, 110 Display unit, 120 Collection unit, 130 First detection unit, 140 Extraction unit, 150 First storage unit, 151 Log accumulation DB, 152 Setting file, 210 Slave processing unit, 220 Communication module, 221 Third storage unit, 230 Fixed-period processing unit, 231 Second detection unit, 300 Second storage unit, 310 FIFO queue, 320 Pre-failure log data
Claims
1. An information processing device connected to a master and one or more slaves via an industrial network, a receiving unit for receiving frames repeatedly transmitted from the master within the industrial network; a first storage unit that stores log data of the frame; an extracting unit that extracts, when it is detected that an abnormality has occurred in the master or the one or more slaves, from the first storage unit, log data of the frames from a time when it is detected that the abnormality has occurred until a predetermined time before the time when the abnormality has occurred; a second storage unit that stores the extracted log data of the frame as pre-failure log data; a transmission unit that transmits the pre-failure log data to the master via the industrial network in response to a request from the master; having the log data of the frame includes a first identifier that uniquely identifies the frame repeatedly transmitted from the master, and a second identifier that indicates a memory location associated with data stored in the frame repeatedly transmitted from the master; The receiving unit receives a transmission request for the pre-failure log data including the first identifier and the second identifier from the master, When the transmission request is received, the transmission unit transmits, to the master, data corresponding to the second identifier of the frame designated by the first identifier, among the pre-failure log data. Information processing device.
2. The information processing device has a non-real-time OS and a real-time OS, The receiving unit operates on the real-time OS, the first storage unit is provided in the non-real-time OS, The extraction unit operates on the non-real-time OS, the second storage unit is provided in the real-time OS and a memory accessible from the real-time OS; The transmission unit operates on the real-time OS. The information processing device according to claim 1 .
3. The receiving unit receives a request to delete the pre-failure log data from the master, a deletion processing unit that deletes the pre-failure log data when the deletion request is received, The information processing device according to claim 1 .
4. An information processing method executed by an information processing device connected to a master and one or more slaves via an industrial network, comprising: receiving a frame repeatedly transmitted from the master within the industrial network; storing log data of the frame in a first storage unit; extracting, when it is detected that an abnormality has occurred in the master or the one or more slaves, from the first storage unit, log data of the frames from a time when it is detected that the abnormality has occurred until a predetermined time before; storing the extracted log data of the frame in a second storage unit as pre-failure log data; transmitting the pre-failure log data to the master via the industrial network in response to a request from the master; Including, the log data of the frame includes a first identifier that uniquely identifies the frame repeatedly transmitted from the master, and a second identifier that indicates a memory location associated with data stored in the frame repeatedly transmitted from the master; The receiving step includes receiving, from the master, a request to transmit the pre-failure log data including the first identifier and the second identifier; the transmitting step includes, when the transmission request is received, transmitting, to the master, data of the pre-failure log data corresponding to the second identifier of the frame designated by the first identifier. Information processing methods.
5. A computer connected to a master and one or more slaves via an industrial network, receiving a frame repeatedly transmitted from the master within the industrial network; storing log data of the frame in a first storage unit; extracting, when it is detected that an abnormality has occurred in the master or the one or more slaves, from the first storage unit, log data of the frames from a time when it is detected that the abnormality has occurred until a predetermined time before; storing the extracted log data of the frame in a second storage unit as pre-failure log data; transmitting the pre-failure log data to the master via the industrial network in response to a request from the master; Run the command, the log data of the frame includes a first identifier that uniquely identifies the frame repeatedly transmitted from the master, and a second identifier that indicates a memory location associated with data stored in the frame repeatedly transmitted from the master; The receiving step includes receiving, from the master, a request to transmit the pre-failure log data including the first identifier and the second identifier; the transmitting step includes, when the transmission request is received, transmitting, to the master, data of the pre-failure log data corresponding to the second identifier of the frame designated by the first identifier. program.
Citation Information
Patent Citations
Data communication control equipment
JP1999261581A
Industrial controller
JP2009157913A
Control system, and proxy slave, proxy master, and control method used for the same
JP2013197656A
Information collection system, information collection method and information collection program
JP2014182538A
Information processing device, information processing device control method, and control program
JP2015001758A