Information Processing Apparatus, Information Processing Method, and Program

The information processing apparatus in the control system connected by an industrial network detects synchronization processing abnormalities by analyzing frames transmitted by the master, thereby enabling early detection of system issues and preventing failures.

JP7695768B1Active Publication Date: 2025-06-19MUWANSI SOFTWARE TECHNOLOGY CO LTD
View PDF 18 Cites 0 Cited by

Patent Information

Application Number
JP2024573436
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-09-26
Publication Date
2025-06-19
Estimated Expiration
2043-09-26

AI Technical Summary

Technical Problem

Existing control systems connected by industrial networks face challenges in detecting abnormalities early enough to prevent further issues, leading to potential system failures.

Method used

An information processing apparatus connected to a master and slaves via an industrial network, equipped with a receiving unit to analyze frames repeatedly transmitted by the master, and an abnormality detection unit to identify synchronization processing abnormalities related to reference time distribution.

Benefits of technology

Enables earlier detection of abnormalities in control systems connected by industrial networks, allowing for timely intervention to prevent system failures and ensure smooth operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007695768000001
    Figure 0007695768000001
  • Figure 0007695768000002
    Figure 0007695768000002
  • Figure 0007695768000003
    Figure 0007695768000003
Patent Text Reader

Abstract

An information processing apparatus connected to a master and one or more slaves via an industrial network, the apparatus comprising: a receiving unit that receives frames repeatedly transmitted from the master within the industrial network; and an abnormality detection unit that analyzes the frames to detect the presence or absence of an abnormality related to synchronization processing performed between the master and the one or more slaves, the synchronization processing being executed based on a reference time distributed within the industrial network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing apparatus, an information processing method, and a program.

Background Art

[0002] In fields such as robots and FA (Factory Automation), it is required to operate the position of a belt conveyor, the position of an arm, etc. as intended. In order to perform such an operation, it is necessary to operate a plurality of controlled devices such as a servo motor and a stepping motor while synchronizing them with high precision. For example, Patent Document 1 discloses a motion control command system capable of realizing smooth control while using inexpensive and simple low-speed communication.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In a control system including a controller and controlled devices, the network connecting the controller and the controlled devices is called an industrial network. When an abnormality occurs in the operation of a control system connected by an industrial network, in order to reduce the possibility of further problems caused by the abnormal operation of the control system, it is desirable to detect the occurrence of the abnormality as early as possible and take measures such as stopping the operation of the control system.

[0005] Therefore, an object of the present disclosure is to provide a technique that enables an abnormality occurring in a control system connected by an industrial network to be detected earlier.

Means for Solving the Problems

[0006] An information processing apparatus according to an aspect of the present disclosure is an information processing apparatus connected to a master and one or more slaves via an industrial network, and includes a receiving unit that receives a frame repeatedly transmitted from the master within the industrial network, and an abnormality detection unit that analyzes the frame to detect the presence or absence of an abnormality related to synchronization processing performed between the master and one or more slaves, which is executed based on a reference time distributed within the industrial network.

Advantages of the Invention

[0007] According to the present disclosure, it is possible to provide a technique that enables earlier detection of an abnormality occurring in a control system connected by an industrial network.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Embodiments for Carrying Out the Invention

[0009] Embodiments of the present disclosure will be described with reference to the accompanying drawings. In each figure, those with the same reference numerals have the same or similar configurations.

[0010] <System Configuration> FIG. 1 is a diagram showing an example of a control system 1 according to the present embodiment. The control system 1 includes a master 10, one or more slaves 20, and a monitoring device 30. The master 10, one or more slaves 20, and the monitoring device 30 are connected via an industrial network.

[0011] The master 10 is a device that realizes a predetermined function in the control system 1 by controlling the slave 20. The master 10 may be, for example, a motion controller, a sequence controller, a robot controller, etc. Also, the master 10 may be called a controller, a control device, etc. The master 10 may be a device realized using dedicated hardware, or a general-purpose information processing device installed with a non-real-time OS and a real-time OS. Specific examples of the non-real-time OS include, for example, Windows (registered trademark), macOS (registered trademark), etc. Also, specific examples of the real-time OS include, for example, RTX (Real Time Extension), RTH (Real Time Hypervisor), etc. Also, specific examples of the general-purpose information processing device include, for example, a PC (personal computer), a notebook PC, a server, etc.

[0012] The slave 20 is, for example, a servo motor (including a servo driver), a stepping motor, a sensor, etc., and is a device that executes various processes in the control system 1. Each slave is divided into a communication processing unit that processes a communication protocol used in an industrial network and an application unit that performs processes such as motion control.

[0013] The monitoring device 30 is a device that monitors the operating state of the control system 1, constantly records frames (which may be called data or packets) flowing through the industrial network, and detects that an abnormality has occurred in the control system 1. Also, the monitoring device 30 operates as a slave 20 in the control system 1. That is, the monitoring device 30 is recognized as a slave 20 by the master 10. The monitoring device 30 may be a device realized using dedicated hardware, or a general-purpose information processing device or computer installed with a non-real-time OS and a real-time OS.

[0014] Protocols used in industrial networks include, for example, EtherCAT (registered trademark), EtherNet / IP, etc. In the following description, the industrial network is described as being EtherCAT, but the present embodiment is not limited thereto. Any communication protocol may be used as long as it communicates in a master-slave manner and has a synchronization function described later.

[0015] In an industrial network, the master 10 and the slaves 20 (including the monitoring device 30) communicate in an on-the-fly manner. In the on-the-fly manner, one fixed-length frame transmitted from the master 10 passes through each slave 20 in order and finally returns to the master 10. Also, each slave 20 can read the data addressed to itself from the frame and write the data addressed to the master 10 or another slave 20 into the frame when the frame passes through. In the example of FIG. 1, the frame transmitted from the master 10 passes through each slave 20 and the monitoring device 30 in the order of S1 to S6 and returns to the master 10. Note that each slave 20 performs processing when the frame first passes through the monitoring device 30, and each slave 20 does not perform frame processing when the frame returns from the monitoring device 30 to the master 10. For example, the slave 20-1 performs processing (writing and / or reading of data) on the frame received at S1, but transfers the frame received at S5 to the master 10 without performing processing. Similarly, the slave 20-2 performs processing (writing and / or reading of data) on the frame received at S2, but transfers the frame received at S4 to the slave 20-1 without performing processing.

[0016] In this embodiment, the monitoring device 30 is connected after all the slaves 20 in the industrial network in order to detect abnormalities occurring in the master 10 and the slaves 20. In other words, the monitoring device 30 operates as the terminal slave 20. For example, assume that there are slaves 20-1 and 20-2 in the control system 1. In this case, the monitoring device 30 is connected to the industrial network so that the frame output from the master 10 passes through the slaves 20-1, 20-2, and the monitoring device 30 in this order.

[0017] (Frame Structure Used in Industrial Network) FIG. 2 is a diagram showing an example of the structure of a frame used in an industrial network. One frame includes an Ethernet header, Ethernet data, and FCS (Flame Check Sequence). The Ethernet data includes a header and a datagram.

[0018] The datagram is further divided into N datagram areas. Each datagram area further includes a datagram header, data, and a working counter (WKC). The datagram header stores a command indicating a data processing method (such as value writing, value reading, etc.) and an address indicating a destination for processing the data.

[0019] In the industrial network, different datagrams are used when data is transmitted from the master 10 to the slave 20 and when data is transmitted from the slave 20 to the master 10. That is, at least two datagrams are assigned to one slave 20 that transmits and receives data to and from the master 10.

[0020] Here, in order for the master 10 to write a value to the memory (also called a register) provided in the slave 20 or read a value from the memory provided in the slave 20, the master 10 needs to specify the address of the memory for which the value writing or reading is to be performed. In an industrial network, there are two ways to specify the address of a memory.

[0021] The first method is a method of directly specifying the physical address of the memory by combining an identifier for identifying the slave 20 (referred to as a "configured address" in Ethernet) and the address of the memory provided in the slave 20 (meaning the actual address, referred to as a "register address" in Ethernet). When writing or reading a value to / from the memory provided in the slave 20, an index and a sub-index can also be used instead of the register address. The index and the sub-index are associated with the content of the data stored in the memory, and by specifying the index and the sub-index, it is possible to write and read values without being aware of the actual address. Note that the correspondence between the index and the sub-index and the address of the memory is predefined in the slave 20.

[0022] The second method is a method of treating the memory spaces provided in all the slaves 20 existing in the control system 1 as one memory space as a whole and expressing the position in the memory space by one logical address. Note that data indicating the correspondence between the logical address and the address (actual address) of the memory provided in each slave 20 is set in each slave 20 in advance. By using the logical address, the master 10 can write and read data without being aware of which slave 20 it is accessing.

[0023] In addition to specifying the address of the memory, the master 10 performs processes such as writing a value to the memory and reading a value from the memory by specifying a command. Examples of commands include FPWR (data writing specifying the slave 20 and the actual address), FPRD (data reading specifying the slave 20 and the actual address), LWR (data writing specifying the logical address), LRD (data reading specifying the logical address), and the like.

[0024] (Overview of Synchronization Processing) FIG. 3 is a diagram for explaining the overview of the synchronization processing. The industrial network is provided with a mechanism for performing high-precision time synchronization (for example, the deviation of time synchronization is within 1 μs) between the slave devices 20. In the case of Ethernet, this synchronization processing is called DC (Distributed Clocks) synchronization. By executing the synchronization processing, each slave 20 is synchronized at a predetermined reference time (hereinafter referred to as the "reference time"), and each slave 20 performs various processes according to the reference time. Note that, for cost reduction, the accuracy of the clock provided in the master 10 is often lower than the accuracy of the clock provided in the slave 20. Therefore, in the synchronization processing, among the slave devices 20 connected in series to the industrial network, the local clock held by the slave 20 capable of executing the synchronization processing may be used as the reference time. In the following description, the slave 20 in which the local clock is used as the reference time is referred to as the "synchronization master slave". In the present embodiment, the synchronization master slave will be described as the first slave 20 (slave 20-1 in the example of FIG. 1) capable of executing the synchronization processing among the slave devices 20 connected in series to the industrial network. Also, in Ethernet, the reference time is called the reference clock. Note that when the master 10 holds a clock with the same high accuracy as the slave 20, the local clock of the master 10 may be used as the reference time.

[0025] The reference time is expressed as an absolute time with a certain time as the starting point (zero). The reference time may be expressed as a value of a predetermined number of bits. For example, in Ethernet, it is expressed as a 32-bit or 64-bit numerical value starting from 0:00:00 on January 1, 2001. Also, the minimum unit of the reference time may be 1 microsecond or 1 nanosecond.

[0026] In order to achieve synchronization processing, the master 10 measures in advance the propagation delay of frames between the synchronization master-slave and each slave 20 and the difference (offset value) between the reference time and the local clock of each slave according to the Ethernet specification, and writes them into the memory of each slave 20. Each slave 20 other than the synchronization master-slave can calculate the reference time by adding the offset value to its own local clock.

[0027] Note that generally, there is a minute deviation (also called drift) in the time marked by the clock. Therefore, if a long time elapses after synchronization is completed, the deviation from the reference time also increases. Therefore, the master 10 periodically distributes the reference time in order to suppress the deviation from the reference time (that is, to compensate for the drift of the clock).

[0028] Specifically, the synchronization master-slave stores the reference time in the frame received from the master 10 according to the instruction of the master 10, and transmits the frame storing the reference time to the next slave 20. Each slave 20 acquires the reference time from the frame storing the received reference time, and writes the acquired reference time frame into the memory of the slave 20 itself. In the following description, the frame for distributing the reference time to each slave 20 is called a "reference time frame". Note that all frames repeatedly transmitted from the master 10 may be reference time frames. Alternatively, the reference time frame may be one out of every N frames (N is a natural number) among all frames repeatedly transmitted from the master 10. In the example of FIG. 3, all frames are reference time frames, and the synchronization master-slave 20-1 stores the reference time in frames A and B received from the master 10 and transmits them to the slave 20-2.

[0029] Each slave 20 other than the synchronous master slave acquires the reference time from the received reference time frame. As described above, since each slave 20 grasps the propagation delay with the synchronous master slave, the correct reference time can be recognized by adding the propagation delay to the reference time included in the reference time frame. That is, each slave 20 other than the synchronous master slave can correct its recognized reference time to the correct reference time based on the reference time included in the reference time frame.

[0030] As described above, the synchronous master slave stores the time of its own local clock as the reference time in the frame received from the master 10 and transmits it to the next slave 20. The value of the local clock stored as the reference time by the synchronous master slave may be the time from when the synchronous master slave receives the frame until it transmits the frame storing the reference time to the next slave 20.

[0031] FIG. 4 is a diagram showing a configuration example of a slave. The communication processing unit 20b provided in each slave refers to the reference time, propagation delay, offset, etc. written in the memory 20a of the communication processing unit and synchronizes with the reference time. Subsequently, each slave repeatedly generates a synchronization signal at a predetermined cycle according to the synchronized reference time and notifies the application unit 20c provided in each slave. In Ethernet, the synchronization signal is called SYNC0 / SYNC1, etc. The first time when the synchronization signal is repeatedly generated (hereinafter referred to as the "start time of the synchronization signal") and the generation cycle of the synchronization signal (hereinafter referred to as the "synchronization signal cycle") are notified in advance from the master 10 to each slave 20. The start time of the synchronization signal is specified as an absolute time according to the time axis of the reference time.

[0032] When synchronous processing is used, the master 10 repeatedly transmits frames at the same period as the generation period of the synchronization signal so that one frame arrives at each slave 20 between two consecutive synchronization signals. However, as described above, the accuracy of the clock provided in the master 10 is often lower than that of the clock provided in the slave 20. Therefore, the period in which the frame arrives at each slave 20 may vary somewhat when compared with the period in which the synchronization signal is generated in each slave 20.

[0033] The frame repeatedly transmitted by the master 10 at a predetermined period includes, in addition to the reference time described above, an area for storing data. For example, commands and values for writing values to the memories of the respective slaves 20 and / or commands for reading values from the memories 20a of the respective slaves 20 are stored in this area. The communication processing unit 20b of the slave 20 reads values from the received frame according to the commands and writes them to the memory 20a. Further, the application unit 20c of the slave 20 performs application processing (for example, motion control, etc.) using the values written to the memory 20a at the timing when the synchronization signal is notified from the communication function unit. That is, as long as the time synchronization function operates normally and the master 10 continues to transmit frames at a predetermined period, the timing at which the synchronization signal is generated in each slave 20 coincides among the slaves 20, and the timing at which each slave 20 performs application processing also coincides.

[0034] For example, as shown in FIG. 3, the arrival time of the frame is delayed for the slave 20-2 by the amount of the transmission delay between the synchronous master slave 20-1 and the slave 20-2. However, since the application processing (AP processing) is executed using the synchronization signal as a trigger, the timing at which the application processing is started in the synchronous master slave 20-1 and the timing at which the application processing is started in the slave 20-2 coincide.

[0035] (Outline of processing performed by the monitoring device) In the present embodiment, the monitoring device 30 performs the following processing.

[0036] 1. Detection of Synchronization Processing Abnormality: The monitoring device 30 detects that an abnormality has occurred in the synchronization processing and notifies the user or master 10 that manages the control system 1.

[0037] 2. Frame Recording Just Before Abnormality Occurrence: The monitoring device 30 constantly records (captures) the frames flowing through the industrial network and stores the log data of one or more captured frames. Also, when it detects that an abnormality has occurred in the control system 1, it extracts the log data of one or more frames that were flowing through the industrial network during a predetermined period before the abnormality from the stored log data. Further, when the monitoring device 30 receives a request from the master 10, it transmits the log data of the one or more extracted frames to the master 10 via the industrial network.

[0038] <Hardware Configuration> FIG. 5 is a diagram showing an example of the hardware configuration of the monitoring device 30. The monitoring device 30 includes a processor 11 such as a CPU (Central Processing Unit) and a GPU (Graphical Processing Unit), a memory (e.g., RAM (Random Access Memory) or ROM (Read Only Memory)), a storage device 12 such as an HDD (Hard Disk Drive) and / or an SSD (Solid State Drive), a network IF (Network Interface) 13 for wired or wireless communication, an input device 14 that receives input operations, and an output device 15 that outputs information. The input device 14 is, for example, a keyboard, a touch panel, a mouse, and / or a microphone, etc. The output device 15 is, for example, a display, a touch panel, and / or a speaker, etc.

[0039] <Functional Block Configuration> FIG. 6 is a diagram showing an example of the functional block configuration of the monitoring device 30. The monitoring device 30 includes a non-real-time OS 100, a real-time OS 200, and a second storage unit 300. The non-real-time OS 100 includes a display unit 110, a collection unit 120, a first detection unit 130, an extraction unit 140, and a first storage unit 150. The real-time OS 200 includes a slave processing unit 210. The slave processing unit 210 includes a communication module 220 and a fixed-cycle processing unit 230. The communication module 220 includes a third storage unit 221, and the fixed-cycle processing unit 230 includes a second detection unit 231.

[0040] The first storage unit 150, the second storage unit 300, and the third storage unit 221 can be realized by using the storage device 12 provided in the monitoring device 30. Further, the display unit 110, the collection unit 120, the first detection unit 130, the extraction unit 140, and the slave processing unit 210 can be realized by the processor 11 of the monitoring device 30 executing a program stored in the storage device 12. Further, the program can be stored in a storage medium. The storage medium storing the program may be a computer-readable non-transitory storage medium (Non-transitory computer readable medium). The non-transitory storage medium is not particularly limited, and may be, for example, a storage medium such as a USB (Universal Serial Bus) memory or a CD-ROM (Compact Disc Read-Only Memory).

[0041] The first storage unit 150 is provided in the non-real-time OS and stores a log accumulation DB (DataBase) 151 and a setting file 152. The log accumulation DB 151 is a database that stores frames flowing through the industrial network captured by the communication module 220 of the real-time OS 200. The setting file 152 stores various data that define the operation of the monitoring device 30.

[0042] The second storage unit 300 is provided in a memory that can be referred to from both the non-real-time OS 100 and the real-time OS.

[0043] The display unit 110 operates on a non-real-time OS and displays various screens on a display or the like. For example, the display unit 110 causes a screen indicating the content of the detected abnormality or the like to be displayed on a display or the like.

[0044] The collection unit 120 operates on a non-real-time OS, acquires frames flowing through the industrial network from the real-time OS 200 via the FIFO (First In First Out) queue 310 included in the second storage unit 300, and stores them in the log storage DB 151 of the first storage unit 150. In other words, the first storage unit 150 (log storage DB 151) stores log data of one or more received frames.

[0045] The first detection unit 130 operates on a non-real-time OS, analyzes the frames received by the communication module 220, and detects the presence or absence of an abnormality related to the synchronization process performed between the master 10 and one or more slaves 20, which is executed based on the reference time distributed within the industrial network.

[0046] When the first detection unit 130 detects that an abnormality has occurred in the master 10 or one or more slaves 20, the extraction unit 140 operates on the non-real-time OS and extracts the log data of the frames from the time a predetermined time (second hour before) before the time when the occurrence of the abnormality was detected from the log storage DB 151. Further, the extraction unit 140 stores the extracted log data of the frames in the second storage unit 300 as pre-failure log data 320. In other words, the second storage unit 300 stores the log data extracted by the extraction unit 140 as pre-failure log data 320.

[0047] The slave processing unit 210 performs various processes for the monitoring device 30 to operate as the slave 20.

[0048] The communication module 220 operates on the real-time OS 200, captures frames flowing through the industrial network, and stores them in the third storage unit 221. Also, the communication module 220 acquires data addressed to itself according to the instruction of the command included in the frame flowing through the industrial network and stores it in the third storage unit 221. Further, according to the instruction of the command included in the frame flowing through the industrial network, the communication module 220 acquires data to be transmitted to the master 10 from the third storage unit 221 and stores it in the frame. As described above, the monitoring device 30 operates as a slave 20 at the end. That is, the third storage unit 221 corresponds to the memory of the slave 20 described in "(frame structure used in the industrial network)". For example, when the command included in the frame is FPWR and the address included in the frame points to the monitoring device 30, the communication module 220 stores the value included in the frame in the area specified by the address included in the frame in the third storage unit 221. Also, when the command included in the frame is FPRD and the address included in the frame points to the monitoring device 30, the communication module 220 acquires a value from the area specified by the address included in the frame in the third storage unit 221 and stores it in the frame.

[0049] The fixed-cycle processing unit 230 operates on the real-time OS 200. The fixed-cycle processing unit 230 repeatedly performs a process of acquiring frames flowing through the industrial network from the third storage unit 221 and storing them in the FIFO queue 310 at a predetermined cycle (for example, the cycle at which the master 10 transmits frames). Also, the fixed-cycle processing unit 230 acquires data to be stored in the frame from the pre-failure log data 320 and stores it in the third storage unit 221.

[0050] The second detection unit 231 analyzes the frame captured by the communication module 220 to detect the presence or absence of an abnormality related to the synchronization process performed between the master 10 and one or more slaves 20, which is executed based on the reference time distributed within the industrial network. Note that the monitoring device 30 is assumed to include at least one of the first detection unit 130 and the second detection unit 231. That is, the monitoring device 30 may detect the presence or absence of an abnormality in the synchronization process on the non-real-time OS 100 side (i.e., by the first detection unit 130), or may detect the presence or absence of an abnormality in the synchronization process on the real-time OS 200 side (i.e., by the second detection unit 231). The first detection unit 130 and the second detection unit 231 may be referred to as an "abnormality detection unit".

[0051] The communication module 220 may be referred to as a "transmission unit" and a "reception unit". The communication module 220 (reception unit) receives the frames repeatedly transmitted from the master 10 within the industrial network. Also, the communication module 220 (transmission unit) transmits the pre-failure log data 320 to the master 10 via the industrial network in response to a request from the master 10.

[0052] <Processing Procedure> (Detection of Synchronization Process Abnormality) Subsequently, the process by which the monitoring device 30 detects that an abnormality has occurred in the synchronization process will be specifically described. In the following description, the detection of the synchronization process abnormality is described on the premise that it is performed by the first detection unit 130. However, as described above, it is also possible to perform the detection of the synchronization process abnormality by the second detection unit 231. Also, in the following description, the slave 20 and the monitoring device 30 are described as different devices.

[0053] The monitoring device 30 detects two patterns of synchronization process abnormalities, namely synchronization abnormality A and synchronization abnormality B, which will be described below, and determines the cause of the occurrence of the synchronization process abnormality based on the combination of these two patterns of synchronization process abnormalities. Note that synchronization abnormality A and synchronization abnormality B may be referred to as a "first abnormality" and a "second abnormality", respectively.

[0054] Synchronization anomaly A: When the reference time stored in the reference time frame is not included between the times at which two consecutive synchronization signals are generated, where the reference time frame should be received. Synchronization anomaly B: When the difference between the reference times included in each of two consecutive time synchronization frames and the difference between the times at which the monitoring device 30 received each of the two consecutive time synchronization frames deviate from each other.

[0055] FIG. 7 is a diagram showing a state in which the synchronization process is operating normally. The process of detecting synchronization anomaly A and synchronization anomaly B will be specifically described with reference to FIG. 7.

[0056] [Synchronization anomaly A] In FIG. 7, the horizontal axis t represents the time at which the synchronization signal is generated. The time at which the synchronization signal is generated may be expressed in any manner, for example, as a 32-bit or 64-bit numerical value starting from 0:00:00 on January 1, 2000, and the minimum unit of time may be 1 nanosecond.

[0057] In the example of FIG. 7, the synchronization signal period is set to 1000 (for example, 1 ms), and each frame is assumed to be a reference time frame. Also, slave 20-1 is a synchronous master-slave, and in the following description, it will be referred to as synchronous master-slave 20-1. That is, synchronous master-slave 20-1 stores the reference time in the reference time frame received from master 10 and transmits it to slave 20-2. Slave 20-2 acquires the reference time from the received reference time frame and transmits the reference time frame to monitoring device 30. Monitoring device 30 also acquires the reference time from the received reference time frame and transmits the reference time frame to master 10.

[0058] The reference time frame is repeatedly transmitted from the master 10 at a cycle approximately the same as the synchronization signal cycle. For example, the reference time frame A is transmitted from the master 10 between the generation of the synchronization signal Sy1 and the generation of the synchronization signal Sy2, passes through the slaves 20-1, 20-2, and the monitoring device 30, and returns to the master 10 before the generation of the synchronization signal Sy2. Therefore, when the synchronization process is normal, the slaves 20 and the monitoring device 30 will surely receive one reference time frame between two consecutive synchronization signals.

[0059] The time when the synchronization signal is first generated is the time specified as the "start time of the synchronization signal", and the subsequent synchronization signals are generated every time the "synchronization signal cycle" elapses. That is, the time when the Nth (N is an integer greater than or equal to 1) synchronization signal is generated can be calculated using the formula "start time of the synchronization signal + ((N - 1) × synchronization signal cycle)". Then, it can be said that the frame transmitted for the Nth time after the start of the synchronization process should be received by each slave 20 between "start time of the synchronization signal + (N - 1) × synchronization signal cycle" and "start time of the synchronization signal + N × synchronization signal cycle".

[0060] Here, the synchronous master slave 20-1 stores the time of its own local clock as the reference time in the reference time frame received from the master 10 and transmits it to the slave 20-2. As described above, the value of the local clock that the synchronous master slave 20-1 stores as the reference time only needs to be the time between when the synchronous master slave 20-1 receives the frame and when it transmits the frame storing the reference time to the slave 20-2. Therefore, the first detection unit 130 determines whether there is a reference time between the times when two consecutive synchronization signals that the reference time frame should be received are generated for the reference time frame among the frames repeatedly transmitted from the master 10, thereby detecting the presence or absence of the abnormality of the synchronization abnormality A.

[0061] More specifically, when there is a reference time between the times at which two consecutive synchronization signals are generated within one or more slaves 20 (or within the synchronous master slave) that should be received by the first detection unit 130 in the reference time frame, the first detection unit 130 determines that synchronization anomaly A has not occurred. Also, when there is no reference time between the times at which two consecutive synchronization signals are generated within one or more slaves 20 (or within the synchronous master slave) that should be received by the first detection unit 130 in the reference time frame, the first detection unit 130 determines that synchronization anomaly A has occurred.

[0062] The first detection unit 130 may obtain the "start time of the synchronization signal" and the "synchronization signal period", and calculate (estimate) the times at which two consecutive synchronization signals that should be received in the reference time frame are generated based on the obtained "start time of the synchronization signal" and "synchronization signal period". For example, assume that the reference time frame is the frame transmitted Xth after the start time of the synchronization signal. In this case, the first detection unit 130 can calculate (estimate) the time at which the first synchronization signal of the two consecutive synchronization signals that should be received in the reference time frame is generated using the formula "start time of the synchronization signal + (X - 1) × synchronization signal period". Also, the first detection unit 130 can calculate (estimate) the time at which the second synchronization signal of the two consecutive synchronization signals that should be received in the reference time frame is generated using the formula "start time of the synchronization signal + X × synchronization signal period".

[0063] As will be described below, synchronization anomaly A is detected when, due to a failure of the local clock in the master 10 or the like, the master 10 is unable to transmit frames at equal intervals, or when the local clock of the synchronous master slave fails and a deviation occurs in the reference time stored in the reference time frame.

[0064] FIG. 8 is a diagram for explaining an event that occurs when an abnormality occurs in the master 10 and it becomes impossible to transmit frames at equal intervals. Points not particularly mentioned may be the same as those in FIG. 7. In the example of FIG. 8, some abnormality occurs in the master 10, and the timing at which the reference time frame C is transmitted from the master 10 is delayed. In this case, the reference time stored in the reference time frame C is the time (8600) when the synchronous master-slave 20-1 receives the reference time frame C. However, the time when the reference time frame C should be received by each slave 20 is between the time (7500) when the synchronous signal Sy3 is generated and the time (8500) when the synchronous signal Sy4 is generated. Therefore, when the first detection unit 130 receives the reference time frame C, it determines that the reference time (8600) included in the reference time frame C does not exist during the period when the reference time frame C should be received (between the time (7500) when the synchronous signal Sy3 is generated and the time (8500) when the synchronous signal Sy4 is generated), and detects that the synchronization abnormality A has occurred.

[0065] FIG. 9 is a diagram for explaining an event that occurs when an abnormality occurs in the local clock of the synchronous master-slave and a deviation occurs in the reference time. Points not particularly mentioned may be the same as those in FIG. 7. In the example of FIG. 9, as a result of the time ticked by the local clock of the synchronous master-slave 20-1 being earlier than the actual time, the reference times stored in the frame C and the frame D are shifted to 8600 and 11500 instead of the actual times (7800 and 8800 shown in FIG. 7). Therefore, when the first detection unit 130 receives the reference time frame C, it determines that the reference time (8600) included in the reference time frame C does not exist during the period when the reference time frame C should be received (between the time (7500) when the synchronous signal Sy3 is generated and the time (8500) when the synchronous signal Sy4 is generated), and detects that the synchronization abnormality A has occurred.

[0066] [Synchronization Abnormality B] When the local clock of the synchronous master slave 20-1 is normal (that is, when the reference time stored in the reference time frame by the synchronous master slave 20-1 is normal), and when the local clock of the monitoring device 30 is also normal, the difference between the times when the monitoring device 30 receives two consecutive reference time frames and the difference between the reference times included in the two reference time frames should be approximately the same value. For example, in the example of FIG. 7, the difference (1000) between the time (5950) when the monitoring device 30 receives frame A and the time (6950) when the monitoring device 30 receives frame B, and the difference (6800) between the reference time of frame A and the reference time of frame B, and the difference (5800) between the reference time of frame A and the difference (1000) are the same.

[0067] Therefore, the first detection unit 130 detects the presence or absence of an abnormality related to the synchronization process based on the difference between the times when the monitoring device 30 receives each of two consecutive reference time frames including the reference time and the difference between the reference times included in each of the two consecutive reference time frames. More specifically, when the "degree of deviation" between the difference between the times when each of two consecutive reference time frames is received and the difference between the reference times included in each of the two consecutive reference time frames is equal to or less than a predetermined value, the first detection unit 130 determines that synchronization abnormality B has not occurred. Further, when the "degree of deviation" between the difference between the times when each of two consecutive reference time frames is received and the difference between the reference times included in each of the two consecutive reference time frames exceeds a predetermined value, the first detection unit 130 determines that synchronization abnormality B has occurred. The method for calculating the degree of deviation will be described later.

[0068] As described below, synchronization abnormality B is detected when the local clock of the synchronous master slave 20-1 fails and a deviation occurs in the reference time stored in the reference time frame, or when the monitoring device 30 fails to correctly measure the time when it receives a frame due to a failure of the local clock of the monitoring device 30 or the like.

[0069] In the example of FIG. 9, as a result of the time indicated by the local clock of the synchronous master slave 20-1 being earlier than the actual time, the reference times stored in frame C and frame D are shifted to 8600 instead of the actual times (7800 and 8800 shown in FIG. 7). Therefore, the first detection unit 130 determines that the degree of deviation between the difference (1000) between the time (6950) when frame B is received and the time (7950) when frame C is received, and the difference (1800) between the reference time (6800) stored in frame B and the reference time (8600) stored in frame C exceeds a predetermined value (for example, 0.1, etc.), and detects that synchronous abnormality B has occurred.

[0070] FIG. 10 is a diagram for explaining the events that occur when an abnormality occurs in the local clock of the monitoring device 30. Points not specifically mentioned may be the same as those in FIG. 7. In the example of FIG. 10, as a result of the time indicated by the local clock of the monitoring device 30 being later than the actual time, the times when frame C and frame D are received are shifted to 7450 and 7950 instead of the actual times (7950 and 8950 shown in FIG. 7). Therefore, the first detection unit 130 determines that the degree of deviation between the difference (500) between the time (6950) when frame B is received and the time (7450) when frame C is received, and the difference (1000) between the reference time (6800) stored in frame B and the reference time (7800) stored in frame C exceeds a predetermined value (for example, 0.1, etc.), and detects that synchronous abnormality B has occurred.

[0071] As described above, the causes of synchronous abnormality include three cases: when an abnormality occurs in the master 10 and it becomes impossible to transmit frames at equal intervals; when the local clock of the synchronous master slave 20-1 malfunctions and a deviation occurs in the reference time stored in the reference time frame; or when an abnormality occurs in the local clock of the monitoring device 30. Also, depending on the cause, which pattern of synchronous abnormality A or synchronous abnormality B is detected differs.

[0072] When this relationship is shown in a table, it becomes as shown in FIG. 11. FIG. 11 is a diagram showing the relationship between combinations of synchronization processing anomalies and the causes of synchronization processing anomalies. The first detection unit 130 determines the cause of the anomaly based on the relationship shown in FIG. 11. Specifically, when synchronization anomaly A has occurred and synchronization anomaly B has not occurred, the first detection unit 130 determines that there is an anomaly in the transmission period of the frame repeatedly transmitted from the master 10. Also, when synchronization anomaly A has not occurred and synchronization anomaly B has occurred, the first detection unit 130 determines that there is an anomaly in the clock provided in the monitoring device 30. Further, when both synchronization anomaly A and synchronization anomaly B have occurred, the first detection unit 130 determines that there is an anomaly in the clock of the synchronization master-slave.

[0073] (Procedure for Detecting Synchronization Processing Anomaly) Reference Signal Frame FIG. 12 is a flowchart showing an example of a processing procedure for detecting a synchronization processing anomaly. In the description of FIG. 12, it is assumed that the master 10 repeatedly transmits frames according to the synchronization signal period. Also, "frame" means both the reference time frame and frames other than the reference time frame (that is, frames not including the reference time). The control system 1 performs initialization processing such as distribution of settings of various data used for motion control and the like before starting operations that the control system 1 such as motion control should perform. When the initialization processing is completed, the control system 1 transitions to a state where it can start operations (referred to as the "operable state"). Also, it is assumed that the monitoring device 30 has acquired in advance the "start time of the synchronization signal" and the "synchronization signal period" before transitioning to the operable state. Note that T-init used in the following description means the "start time of the synchronization signal". The counter m is an integer of 1 or more and represents the cumulative number of times the monitoring device 30 has received the reference time frame. The counter n is an integer of 1 or more and represents the cumulative number of times the monitoring device 30 has received a frame (however, the first reference time frame is regarded as the first frame, and frames received before the reference time frame are not counted). Also, the initial values of the counters n and m are assumed to be 0.

[0074] In step S20, the first detection unit 130 acquires one frame from the log storage DB 151.

[0075] In step S21, if the frame is a reference time frame, the first detection unit 130 proceeds to the processing procedure of step S22. If the frame is not a reference time frame, the first detection unit 130 proceeds to the processing procedure of step S23.

[0076] In step S22, if the counter m is 1 or more, the first detection unit 130 adds 1 to the counter n and proceeds to the processing procedure of step S37. If the counter m is 0, the first detection unit 130 proceeds to the processing procedure of step S37 without performing anything.

[0077] In step S23, the first detection unit 130 adds 1 to the counters n and m.

[0078] In step S24, the first detection unit 130 stores the value of the reference time included in the reference time frame in the variable Rt[m].

[0079] In step S25, the first detection unit 130 stores the time when the communication module 220 received the reference time frame (the value of the clock of the monitoring device 30) in the variable Nt[m].

[0080] In step S26, if m = 1, the process proceeds to the processing procedure of step S27. If m ≠ 1, the process proceeds to the processing procedure of step S28.

[0081] In step S27, the first detection unit 130 calculates the time when the monitoring device 30 starts the abnormality detection process (hereinafter referred to as "abnormality detection start time") (T-start). The abnormality detection start time (T-start) can be calculated using the following formula (1). Here, X is an integer of 0 or more.

[0082] Formula (1): When T-start = T-init + (synchronization signal period × X), the largest T-start that satisfies T-start < variable Rt[1] In step S28, the first detection unit 130 calculates the variable T using the following equation (2). n to calculate.

[0083] Equation (2): T n = T-start + synchronization signal period × (n - 1) In step S29, the first detection unit 130 calculates the variable T using the following equation (3). n+1 to calculate.

[0084] Equation (3): T n+1 = T-start + synchronization signal period × (n) In step S30, if the first detection unit 130 satisfies the following equation (4), it proceeds to the processing procedure of step S31, and if it does not satisfy the following equation (4), it proceeds to the processing procedure of step S32.

[0085] Equation (4): T n < Rt[m] < T n+1 In step S31, the first detection unit 130 determines that synchronization anomaly A has been detected.

[0086] In step S32, if the counter m is 2 or more, the first detection unit 130 proceeds to the processing procedure of step S33, and if the counter m is 1, it proceeds to the processing procedure of step S37.

[0087] In step S33, the first detection unit 130 calculates the variable E1 using the following equation (5).

[0088] Equation (5): E1 = Rt[m] - Rt[m - 1] In step S34, the first detection unit 130 calculates the variable E2 using the following equation (6).

[0089] Equation (6): E2 = Nt[m] - Nt[m - 1] In step S35, the first detection unit 130 calculates the degree of deviation using the following formula (7). If the degree of deviation exceeds a predetermined value, the process proceeds to the processing procedure of step S36. If the degree of deviation is equal to or less than the predetermined value, the process proceeds to the processing procedure of step S37. Note that Abs in formula (7) means absolute value.

[0090] Formula (7): Degree of deviation = Abs(1.0 - (E1 / E2)) In step S36, the first detection unit 130 determines that synchronous anomaly B has been detected.

[0091] In step S37, if the first detection unit 130 does not end the anomaly detection process, it returns to step S20. If it ends the anomaly detection process, it ends the process of FIG. 12.

[0092] By executing the processing procedure described above, an example in which a clock anomaly of the synchronous master - slave is detected as one of the synchronous anomalies will be specifically described with reference to FIG. 13.

[0093] FIG. 13 is a diagram showing a specific example of the synchronous anomaly detection process. In the example of FIG. 13, assume that the start time (T - init) of the synchronous signal is 5500 (time when the starting point of the reference time is 0), and the synchronous signal period is 1000 (e.g., 1 ms). Also assume that the reference times stored in the reference time frames B, D, E, and H are 7000, 9000, 11000, and 14000 respectively.

[0094] Hereinafter, assuming that an anomaly occurs in the local clock of the synchronous master - slave, the process by which the monitoring device 30 detects a synchronous anomaly will be described with reference to FIGS. 12 and 13. Note that the predetermined value in the processing procedure of step S35 in FIG. 12 is 0.1.

[0095] First, the first detection unit 130 acquires frame A (S20, S21-NO, S22, S37-NO in FIG. 12). Subsequently, the first detection unit 130 acquires the reference time frame B and adds 1 to each of the counters n and m (S20, S21-YES, S23 in FIG. 12). Also, the first detection unit 130 stores the value 7000 of the reference time included in the reference time frame B in the variable Rt[1], stores the time 7200 when the communication module 220 received the reference time frame B in the variable Nt[1], and calculates the variable T-start according to formula (1) (S24, S25, S26-YES, S27 in FIG. 12).

[0096] Here, in formula (1), when X = 1, T-start is T-start = 5500 + 1000 = 6500, and T-start < 7000 is satisfied. Next, when X = 2, T-start is T-start = 5500 + 1000×2 = 7500, and T-start < 7000 is not satisfied. Therefore, the value of T-start becomes 6500.

[0097] Subsequently, the first detection unit 130 n and the variable T n+1 are calculated according to formulas (2) and (3) (S28, S29 in FIG. 12). At this point, since n = 1, T n becomes 6500 + 1000×(1 - 1) = 6500. Similarly, T n+1 becomes 6500 + 1000×1 = 7500.

[0098] The first detection unit 130 determines whether formula (4) is satisfied. At this point, since m = 1 and Rt[1] is 7000, 6500 < Rt[1] < 7500 is satisfied (S30 in FIG. 12). Therefore, the first detection unit 130 determines that synchronization anomaly A has not occurred. Subsequently, since m = 1, the first detection unit 130 skips the processing procedures of steps S33 to S36 in FIG. 12 (S32-NO).

[0099] Subsequently, the first detection unit 130 receives frame C and adds 1 to n (S20, S21-NO, S22 in FIG. 12). At this point, n = 2 and m = 1.

[0100] Subsequently, the first detection unit 130 acquires the reference time frame D and adds 1 to each of the counters n and m (S20, S21-YES, S23 in FIG. 12). Further, the first detection unit 130 stores the value 9000 of the reference time included in the reference time frame D in the variable Rt[2], and stores the time 9200 when the communication module 220 received the reference time frame D in the variable Nt[2]. (S24, S25 in FIG. 12).

[0101] Subsequently, the first detection unit 130 n and the variable T n+1 are calculated according to equations (2) and (3) (S28, S29 in FIG. 12). Since n = 3 at this point, T n becomes 6500 + 1000×(3 - 1)=8500. Similarly, T n+1 becomes 6500 + 1000×3 = 9500.

[0102] The first detection unit 130 determines whether equation (4) is satisfied. At this point, m = 2 and Rt[2] is 9000, so 8500 < Rt[2] < 9500 is satisfied (S30-YES in FIG. 12). Therefore, the first detection unit 130 determines that synchronization anomaly A has not occurred. Further, the first detection unit 130 calculates E1 and E2 according to equations (5) and (6) (S32-YES, S33, S34 in FIG. 12). E1 is Rt[2]-Rt[1]=9000 - 7000 = 2000, and E2 is Nt[2]-Nt[1]=9200 - 7200 = 2000. The first detection unit 130 determines whether equation (7) is satisfied (S35 in FIG. 12). Abs(1.0 - E2 / E1)=1.0 - 2000 / 2000 = 0, which is less than or equal to the predetermined value 100, so the first detection unit 130 determines that synchronization anomaly B has not occurred (S35-YES in FIG. 12).

[0103] Subsequently, the first detection unit 130 receives frame E and adds 1 to n (S20, S21-NO, S22 in FIG. 9). At this point, n = 4 and m = 2.

[0104] Subsequently, the first detection unit 130 acquires the reference time frame F, adds 1 to the counter n and the counter m, stores the reference time value 11000 included in the reference time frame F in the variable Rt[3], stores the time 11200 when the communication module 220 received the reference time frame F in the variable Nt[3], and calculates the variables T n and the variable T n+1 according to formulas (2) and (3) (S23, S24, S25, S26-NO, S28, S29 in FIG. 12). Since n = 5 at this point, T n becomes 6500 + 1000×(5 - 1)=10500. Similarly, T n+1 becomes 6500 + 1000×5 = 11500.

[0105] The first detection unit 130 determines whether formula (4) is satisfied. At this point, m = 3 and Rt[3] is 11000, so 10500 < Rt[3] < 11500 is satisfied (S30-NO in FIG. 12). Therefore, the first detection unit 130 determines that synchronization anomaly A has not occurred. Also, the first detection unit 130 calculates E1 and E2 according to formulas (5) and (6) (S33, S34 in FIG. 12). E1 is Rt[3]-Rt[3]=11000 - 9000 = 2000, and E2 is Nt[3]-Nt[2]=11200 - 9200 = 2000. The first detection unit 130 determines whether formula (7) is satisfied (S35 in FIG. 12). Abs(1.0 - E2 / E1)=1.0 - 2000 / 2000 = 0, which is less than or equal to the predetermined value 100, so the first detection unit 130 determines that synchronization anomaly B has not occurred (S35-NO in FIG. 12).

[0106] Subsequently, the first detection unit 130 receives frame G and adds 1 to n (S22 in FIG. 12). At this point, n = 6 and m = 3.

[0107] Subsequently, the first detection unit 130 acquires the reference time frame H and increments the counters n and m by 1 (S20, S21 - YES, S23 in FIG. 12). Also, the first detection unit 130 stores the reference time value 14000 included in the reference time frame H in the variable Rt[4], stores the time 13200 when the communication module 220 received the reference time frame H in the variable Nt[4], and calculates the variables T n and the variable T n+1 according to equations (2) and (3) (S24, S25, S26 - NO, S28, S29 in FIG. 12). At this point, since n = 7, T n becomes 6500 + 1000×(7 - 1) = 12500. Similarly, T n+1 becomes 6500 + 1000×7 = 13500.

[0108] The first detection unit 130 determines whether equation (4) is satisfied. At this point, m = 4 and Rt[4] = 14000, so 12500 < Rt[4] < 13500 is not satisfied (S30 - NO in FIG. 12). Therefore, the first detection unit 130 determines that synchronization anomaly A has occurred (S31 in FIG. 12). Also, the first detection unit 130 calculates E1 and E2 according to equations (5) and (6) (S33, S34 in FIG. 12). E1 is Rt[4] - Rt[3] = 14000 - 11000 = 3000, and E2 is Nt[4] - Nt[3] = 13200 - 11200 = 2000. The first detection unit 130 determines whether equation (7) is satisfied (S35 in FIG. 12). Abs(1.0 - E2 / E1) = Abs(1.0 - 3000 / 2000) = 0.5, which is not less than the predetermined value of 0.1. Therefore, the first detection unit 130 determines that synchronization anomaly B has occurred (S35 - NO, S36 in FIG. 12).

[0109] As described above, the first detection unit 130 detects synchronization anomaly A and synchronization anomaly B, and according to the table in FIG. 11, determines that the clock of the synchronization master - slave 20 - 1 is abnormal.

[0110] [Variants in the Detection of Synchronization Processing Abnormalities] (Variant 1) In the detection of the synchronization process abnormality described above, the monitoring device 30 may be configured to execute only the detection of either the synchronization abnormality A or the synchronization abnormality B.

[0111] (Modification Example 2) In the log storage DB 151, the content of the latest frame captured by the communication module 220 is sequentially stored in association with the time when each frame is received by the monitoring device 30 (more specifically, the communication module 220). Therefore, the first detection unit 130 may quickly detect the occurrence of a synchronization abnormality by sequentially analyzing the frames sequentially stored in the log storage DB 151 according to the flowchart shown in FIG. 12. Alternatively, the first detection unit 130 may detect the occurrence of a synchronization abnormality retrospectively by analyzing the frames stored in the log storage DB 151 in the past in a batch process according to the flowchart shown in FIG. 12.

[0112] (Modification Example 3) The clock of the monitoring device 30 does not necessarily need to operate on the same time axis as the reference time. The clock of the monitoring device 30 may operate on a time axis different from the reference time.

[0113] (Modification Example 4) FIGS. 14 and 15 are diagrams for explaining a modification example. Since the industrial network processes frames in an on-the-fly manner, a time lag corresponding to the propagation delay occurs from the arrival of a frame at the synchronization master slave until the frame arrives at the slave 20 that finally processes the frame. In addition, it is considered that a certain time lag is required from the arrival of the frame at the slave 20 until it becomes processable by the application unit.

[0114] For example, in the example of FIG. 14, since frame A arrives at slave 20-2 immediately before time t2 when synchronization signal 2 is generated, it is considered difficult for slave 20-2 to start AP processing in accordance with time t2 even if it receives frame A at this time. Therefore, the first detection unit 130 may detect the presence or absence of abnormality of synchronization abnormality A in consideration of the time lag.

[0115] For example, for the reference time frame among the frames repeatedly transmitted from master 10, the first detection unit 130 determines whether a reference time exists between the time (t1 in FIG. 15) when the first synchronization signal 1 of two consecutive synchronization signals, at which the reference time frame should be received, is generated and the time (t2-a in FIG. 15) that is a predetermined time (third time) before the time (t2 in FIG. 15) when the second synchronization signal 2 is generated, to detect the presence or absence of abnormality of synchronization abnormality A. The predetermined time (third time) may be set to a time longer than the total value of the propagation delay D between the synchronization master slave and the last slave 20 that processes the frame and the processing delay time in slave 20.

[0116] More specifically, when a reference time exists between the time when the first synchronization signal of two consecutive synchronization signals, at which the reference time frame should be received by one or more slaves 20 (or synchronization master slave), is generated within one or more slaves (or synchronization master slave) and the time that is a predetermined time (third time) before the time when the second synchronization signal is generated within one or more slaves (or synchronization master slave), the first detection unit 130 may determine that synchronization abnormality A has not occurred. Also, when no reference time exists between the time when the first synchronization signal of two consecutive synchronization signals, at which the reference time frame should be received by one or more slaves 20 (or synchronization master slave), is generated within one or more slaves (or synchronization master slave) and the time that is a predetermined time (third time) before the time when the second synchronization signal is generated within one or more slaves (or synchronization master slave), the first detection unit 130 may determine that synchronization abnormality A has occurred.

[0117] (Frame recording immediately before abnormality occurrence) Next, when an abnormality occurs in the control system 1, the process of extracting the log data of the frames flowing through the industrial network before the occurrence of the abnormality and transmitting the extracted log data to the master 10 will be described.

[0118] Here, the content of the data stored in the log accumulation DB 151 will be described. In the log accumulation DB 151, frames flowing through the industrial network captured by the communication module 220 of the real-time OS 200 are stored. At this time, the frame data stored in the log accumulation DB 151 may include an identifier (first identifier) that uniquely identifies the frames repeatedly transmitted from the master 10. The identifier that uniquely identifies a frame is called a "cycle number". The cycle number is a number managed by the master 10 and the monitoring device 30 and is not included in the frame. For example, the master 10 sets the cycle number of the first frame transmitted after transitioning to the operable state to 0, and increments the cycle number by one each time a frame is transmitted. Similarly, the monitoring device 30 sets the cycle number of the first frame received after transitioning to the operable state to 0, and increments the cycle number by one each time a frame is received.

[0119] Also, the frame data stored in the log accumulation DB 151 may include an identifier (second identifier) indicating the memory location where data (also called an object) is written or read in the frames repeatedly transmitted from the master 10. The identifier indicating the memory location may be a combination of an identifier (setting address) that identifies the slave 20, an index, and a sub-index.

[0120] Similarly, the pre-failure log data 320 storing the log data extracted from the log accumulation DB 151 may also include a cycle number and an identifier (second identifier) indicating the memory location.

[0121] That is, when the cycle number is specified, the monitoring device 30 can acquire the data of the frame transmitted from the master with the specified cycle number from among the pre-failure log data 320. Further, when the cycle number and the identifier indicating the memory position are specified, the monitoring device 30 can acquire, from among the pre-failure log data 320, the data of the frame transmitted from the master with the specified cycle number, which is data addressed to a specific memory of a specific slave 20 or data read from a specific memory of a specific slave 20 and stored in the frame.

[0122] When the extraction unit 140 is notified that an abnormality has occurred in the master 10 or one or more slaves 20, the extraction unit 140 extracts log data from the log accumulation DB 151 from the time a predetermined time (first hour) before the time when the abnormality was detected. Note that the time when the abnormality was detected may be the time when the monitoring device 30 detected the occurrence of the abnormality, or may be the time when the monitoring device 30 received the frame in which the abnormality occurred. Further, the extraction unit 140 stores the extracted log data as pre-failure log data 320 in a second storage unit 300 that can be referenced from the real-time OS 200.

[0123] Here, the predetermined time (first hour) may be specified from the master 10 or may be stored in the preset file 152 in advance. The predetermined time may be expressed in terms of the number of cycles (for example, 1000 cycles, etc.) or may be expressed in terms of a specific time length (for example, 1 second, etc.). When expressed in terms of the number of cycles, the predetermined time may be referred to as the "specified number of cycles". Since the time length of one cycle is the same as the synchronization signal period, the number of cycles and the time length can be converted into each other. Therefore, expressing the predetermined time in terms of a specific time length and expressing it in terms of the number of cycles are synonymous.

[0124] When the second detection unit 231 fails to receive the frames repeatedly transmitted from the master 10 for a certain period of time (the second time period), it may be determined that an abnormality has occurred in the master 10. The certain period of time may be referred to as a "WD (watchdog) timer". The WD timer may be specified by the master 10 or may be stored in the preset file 152 in advance. Further, when the monitoring device 30 detects the above-described synchronization abnormality A or synchronization abnormality B, it may be determined that an abnormality has occurred in the master 10 or one or more slaves 20. The WD timer may be expressed in terms of the number of cycles (for example, 100 cycles, etc.) or in terms of a specific time length (for example, 0.1 second, etc.). As described above, since the number of cycles and the time length can be converted into each other, expressing the WD timer in terms of a specific time length and expressing it in terms of the number of cycles are synonymous.

[0125] The communication module 220 transmits the log data stored in the pre-failure log data 320 to the master 10 via the industrial network in response to a request from the master 10. Specifically, the communication module 220 (reception unit) receives a transmission request for the pre-failure log data including the cycle number (the first identifier) from the master 10. Further, when the communication module 220 (transmission unit) receives the transmission request, it transmits the data of the frame designated by the cycle number among the pre-failure log data to the master 10.

[0126] Further, the communication module 220 (reception unit) may receive a transmission request for the pre-failure log data including the cycle number (the first identifier and the identifier indicating the memory position (the second identifier)) from the master 10. Further, when the communication module 220 (transmission unit) receives the transmission request, among the pre-failure log data, the data corresponding to the identifier indicating the memory position in the frame designated by the cycle number (that is, the data written to the memory indicated by the identifier or the data read from the memory indicated by the identifier) may be transmitted to the master 10.

[0127] Note that when the slave processing unit 210 receives an instruction from the master 10, it may delete the pre-failure log data 320. Specifically, the communication module 220 (reception unit) may receive a deletion request for the pre-failure log data 320 from the master 10, and when the second detection unit 231 receives the deletion request, it may delete the pre-failure log data 320. Note that the second detection unit 231 may be called a "deletion processing unit".

[0128] FIG. 16 is a sequence diagram showing an example of a processing procedure for extracting log data at the time of occurrence of an abnormality and transmitting it to the master 10.

[0129] In step S100, the master 10 writes the WD timer and the specified number of cycles to a predetermined memory area in the third storage unit 221 of the monitoring device 30 by transmitting a frame including the WD timer and the specified number of cycles. The second detection unit 231 of the monitoring device 30 recognizes the value of the WD timer and the specified number of cycles by acquiring the WD timer and the specified number of cycles written in the third storage unit 221.

[0130] After the processing procedure of step S100 is completed, the control system 1 transitions to an operable state, and the transmission of frames from the master 10 is started.

[0131] In step S101, the second detection unit 231 detects the occurrence of an abnormality. For example, the second detection unit 231 may be configured to detect the occurrence of an abnormality when it fails to receive a frame from the master 10 during a period set by the WD timer. When the second detection unit 231 detects the occurrence of an abnormality, it stores in the third storage unit 221 an "abnormality detection flag" indicating that an abnormality has been detected, and an "abnormality detection cycle number" indicating the cycle number of the last received frame when the abnormality was detected. Note that storing the abnormality detection flag and the abnormality detection cycle number in the third storage unit 221 is to enable the master 10 to recognize that an abnormality has occurred within the industrial network. Further, the second detection unit 231 notifies the extraction unit 140 that an abnormality has occurred. For example, the second detection unit 231 stores the abnormality detection flag and the abnormality detection cycle number in the second storage unit 300, and the extraction unit 140 may obtain the abnormality detection flag and the abnormality detection cycle number by periodically referring to the second storage unit 300.

[0132] In step S102, when notified by the second detection unit 231 that an abnormality has occurred, the extraction unit 140 extracts from the log accumulation DB 151 the log data of the frames from the cycle number at which the abnormality was detected up to a specified number of cycles before, and stores it in the pre-failure log data 320. Further, the extraction unit 140 notifies the second detection unit 231 that the pre-failure log data 320 has been stored. For example, the extraction unit 140 stores in the second storage unit 300 information indicating that the storage of the pre-failure log data 320 has been completed, and the extraction unit 140 may recognize that the pre-failure log data 320 has been stored in the second storage unit 300 by periodically referring to the second storage unit 300 to check the presence or absence of the information.

[0133] When the pre-failure log data 320 is stored in the second storage unit 300, the second detection unit 231 stores an extraction completion flag in the third storage unit 221. The extraction completion flag indicates that the extraction of the pre-failure log data 320 has been completed and the master 10 can read the pre-failure log data 320.

[0134] In step S103, upon receiving an instruction from master 10, communication module 220 stores the anomaly detection flag, the cycle number at the time of anomaly detection, and the extraction completion flag in a frame and transmits it to master 10. Master 10 reads the anomaly detection flag, the cycle number at the time of anomaly detection, and the extraction completion flag from the received frame, thereby recognizing that an anomaly has been detected by monitoring device 30, the cycle number at the time of the anomaly occurrence, and that it has become possible to read the pre-failure log data 320 from monitoring device 30. Note that the processing procedure of step S103 may be executed, for example, when an administrator or the like who manages master 10 operates the screen of master 10.

[0135] In step S104, master 10 determines, from monitoring device 30, which cycle number frame to read among the cycles up to the specified number of cycles before the cycle number at the time of anomaly detection, which frames are addressed to slave 20, which index and sub-index values to read, and so on. Note that this determination may be made by an administrator or the like who manages master 10 by specifying the cycle number and the like.

[0136] In step S105, master 10 transmits a frame including the identifier indicating monitoring device 30, the cycle number of the frame to be read, the identifier (set address) of slave 20 that is the target to be read, and the index and sub-index corresponding to the value to be read, in order to read the data of the frame with the cycle number determined in the processing procedure of step S104. Note that the identifier of slave 20 that is the target to be read, the index and sub-index corresponding to the value to be read may be omitted. For example, when it is desired to acquire all the data of a frame with a certain cycle number, master 10 may specify only the cycle number and omit the identifier, index, and sub-index of slave 20 that is the target to be read.

[0137] In step S106, the communication module 220 stores the data of the frame with the cycle number instructed by the master 10 in the process of step S105 into the frame received from the master 10 in the process of step S105 and transmits it to the master 10. The master 10 acquires the data of the frame with the specified cycle number from the received frame. When the master 10 reads the data of the frames of multiple cycles, the processing procedures of step S105 and step S106 are repeated.

[0138] In step S107, the master 10 stores the acquired frame data.

[0139] FIG. 17 is a diagram showing an example of the data of the frame stored in the pre-fault log data 320. The recorded value index is an identifier for uniquely identifying the record recorded in the pre-fault log data 320. For example, when it is desired to acquire all the values in the frame where the cycle number is 1000 to 1049, the master 10 designates the cycle number 1000 in the process of step S105, and repeats the procedure of acquiring the data of the frame with the cycle number 1000 50 times while increasing the cycle number by 1 in the process of step S106. Returning to FIG. 16, the description continues.

[0140] Note that the frame used in the processing procedures of step S105 and step S106 may be a frame or a frame that is transmitted aperiodically regardless of the synchronization process.

[0141] In step S108, in order for the master 10 to erase the pre-fault log data 320 stored in the monitoring device 30, the master 10 transmits a frame including the identifier of the monitoring device 30, the index and sub-index indicating the memory area where the reset command flag is stored, and the value of the reset command flag, so as to write the reset command flag into a predetermined memory area in the third storage unit 221 of the monitoring device 30.

[0142] In step S109, when the second detection unit 231 of the monitoring device 30 detects that a reset command flag has been written to the third storage unit 221, it deletes the pre-failure log data 320. Further, the second detection unit 231 deletes the abnormality detection flag, the cycle number at the time of abnormality detection, and the extraction completion flag stored in the third storage unit 221.

[0143] <Summary> According to the embodiment described above, it becomes possible to detect an abnormality occurring in a control system connected by an industrial network at an earlier stage. Further, when an abnormality occurs in a control system connected by an industrial network, it becomes possible to perform abnormality analysis and / or recovery more quickly.

[0144] In addition, since the monitoring device 30 analyzes the frame transmitted from the master 10 for each generation cycle of the synchronization signal, it becomes possible to quickly detect the occurrence of a synchronization abnormality by the time the next generation cycle of the synchronization signal arrives.

[0145] In addition, the monitoring device 30 is configured to detect two patterns of abnormalities, i.e., synchronization abnormality A and synchronization abnormality B. As a result, the monitoring device 30 can specifically identify the cause when a synchronization abnormality occurs in the control system 1. Specifically, it becomes possible to identify whether there is an abnormality in the clock of the monitoring device 30 itself, whether there is an abnormality in the transmission cycle of the frame transmitted by the master 10, or whether there is an abnormality in the local clock of the synchronous master-slave.

[0146] When the monitoring device 30 does not exist, even if a synchronization abnormality occurs, it has been difficult to identify whether an abnormality has occurred in the local clock of the master 10 or in the local clock of the synchronous master-slave. On the other hand, in the present embodiment, since the monitoring device 30 monitors the occurrence of a synchronization abnormality separately from the master 10, it becomes possible to specifically identify the cause of the synchronization abnormality.

[0147] In addition, the monitoring device 30 captures the frames transmitted from the master 10 and stores them in the log storage DB 151 on the non-real-time OS 100. By storing the log storage DB 151 on the non-real-time OS side that can handle a large amount of data, the monitoring device 30 can capture and store the data of a large number of frames.

[0148] In addition, when the monitoring device 30 detects that an abnormality has occurred, it extracts the data of the frame immediately before the abnormality occurs from the log storage DB 151, and stores the extracted pre-failure log data 320 on the memory that can be referenced from the real-time OS 200. Since it is difficult for the non-real-time OS to perform real-time processing, it is impossible to acquire the pre-failure log data 320 according to the frame period and write it to the frame. However, by making the pre-failure log data 320 referable from the real-time OS 200, the monitoring device 30 can acquire the pre-failure log data 320 according to the synchronization signal period and write it to the frame. In other words, the master 10 can read the pre-failure log data 320 using the frame repeatedly transmitted according to the synchronization signal period.

[0149] In addition, by reading the pre-failure log data 320, the master 10 can identify the position where the motion control has stopped, and after the abnormality is recovered, it becomes possible to continue the motion control from the stopped position.

[0150] In addition, the monitoring device 30 is configured to transmit the pre-failure log data 320 via the industrial network. As a result, even when it is difficult for the master 10 used in the control system 1 to have an external input such as a USB, the monitoring device 30 can easily transmit the pre-failure log data 320 to the master 10.

[0151] The embodiments described above are for facilitating the understanding of the present disclosure and are not for limiting the interpretation of the present disclosure. The flowcharts, sequences, each element included in the embodiments, and their arrangements, materials, conditions, shapes, sizes, etc. described in the embodiments are not limited to those illustrated and can be changed as appropriate. Also, it is possible to partially substitute or combine the configurations shown in different embodiments.

Description of Reference Numerals

[0152] 1 Control system, 10 Master, 11 Processor, 12 Storage device, 13 Network IF, 14 Input device, 15 Output device, 20 Slave, 30 Monitoring device, 110 Display unit, 120 Collection unit, 130 First detection unit, 140 Extraction unit, 150 First storage unit, 151 Log accumulation DB, 152 Setting file, 210 Slave processing unit, 220 Communication module, 221 Third storage unit, 230 Fixed-cycle processing unit, 231 Second detection unit, 300 Second storage unit, 310 FIFO queue, 320 Pre-failure log data

Claims

1. A monitoring device connected to a master and one or more slaves via an industrial network, a receiving unit that receives frames repeatedly transmitted from the master within the industrial network; an abnormality detection unit that detects the presence or absence of an abnormality related to synchronization processing performed between the master and the one or more slaves, which is executed based on a reference time distributed within the industrial network, by analyzing the frames; having the frames are repeatedly transmitted from the master at the same period as a synchronization signal period in which a synchronization signal is repeatedly generated within the one or more slaves, the abnormality detection unit detects the presence or absence of a first abnormality related to the synchronization processing by determining whether the reference time exists between times at which two consecutive synchronization signals to be generated are received for a frame including the reference time among the frames repeatedly transmitted from the master; the abnormality detection unit detects the presence or absence of a second abnormality related to the synchronization processing based on a difference in the times at which the monitoring device receives each of two consecutive frames including the reference time and a difference in the reference times included in each of the two consecutive frames; when the first abnormality does not occur and the second abnormality occurs, the abnormality detection unit determines that there is an abnormality in a clock included in the monitoring device; Monitoring device.

2. A monitoring device connected to a master and one or more slaves via an industrial network, a receiving unit that receives frames repeatedly transmitted from the master within the industrial network; an abnormality detection unit that detects the presence or absence of an abnormality related to synchronization processing performed between the master and the one or more slaves, which is executed based on a reference time distributed within the industrial network, by analyzing the frames; having The frame is repeatedly transmitted from the master at the same period as the synchronization signal period in which the synchronization signal is repeatedly generated within the one or more slaves, The abnormality detection unit determines whether or not the reference time exists between the times when two consecutive synchronization signals are generated, for which the frame including the reference time among the frames repeatedly transmitted from the master should be received, thereby detecting the presence or absence of a first abnormality related to the synchronization process, The abnormality detection unit detects the presence or absence of a second abnormality related to the synchronization process based on the difference in the reception times of each of the two consecutive frames including the reference time and the difference in the reference times included in each of the two consecutive frames, When both the first abnormality and the second abnormality occur, the abnormality detection unit determines that there is an abnormality in the clock of the slave that distributes the reference time, Monitoring device.

3. The abnormality detection unit, When the reference time exists between the times when the two consecutive synchronization signals are generated within the one or more slaves, it is determined that the first abnormality has not occurred, When the reference time does not exist between the times when the two consecutive synchronization signals are generated within the one or more slaves, it is determined that the first abnormality has occurred, The monitoring device according to claim 1 or 2.

4. The abnormality detection unit, When the degree of deviation between the difference in the reception times of each of the two consecutive frames and the difference in the reference times included in each of the two consecutive frames is equal to or less than a predetermined value, it is determined that the second abnormality has not occurred, When the degree of deviation between the difference in the reception times of each of the two consecutive frames and the difference in the reference times included in each of the two consecutive frames exceeds a predetermined value, it is determined that the second abnormality has occurred, The monitoring device according to claim 1 or 2.

5. When the first abnormality has occurred and the second abnormality has not occurred, the abnormality detection unit determines that there is an abnormality in the transmission cycle of the frame repeatedly transmitted from the master. The monitoring device according to claim 1 or 2.

6. An information processing method executed by a monitoring device connected to a master and one or more slaves via an industrial network, receiving a frame repeatedly transmitted from the master within the industrial network; detecting the presence or absence of an abnormality related to synchronization processing performed between the master and the one or more slaves, which is executed based on a reference time distributed within the industrial network, by analyzing the frame; including The frame is repeatedly transmitted from the master at the same period as the synchronization signal period in which a synchronization signal is repeatedly generated within the one or more slaves, The detecting step detects the presence or absence of a first abnormality related to the synchronization processing by determining whether the reference time exists between the times when two consecutive synchronization signals to be generated are received for the frame including the reference time among the frames repeatedly transmitted from the master. The detecting step detects the presence or absence of a second abnormality related to the synchronization processing based on the difference between the times when the monitoring device receives each of two consecutive frames including the reference time and the difference between the reference times included in each of the two consecutive frames. When the first abnormality has not occurred and the second abnormality has occurred, the detecting step determines that there is an abnormality in the clock included in the monitoring device. Information processing method.

7. An information processing method executed by a monitoring device connected to a master and one or more slaves via an industrial network, receiving a frame repeatedly transmitted from the master within the industrial network; By analyzing the frame, detecting whether there is an abnormality related to the synchronization process performed between the master and the one or more slaves, which is executed based on the reference time distributed within the industrial network; including; The frame is repeatedly transmitted from the master at the same period as the synchronization signal period in which the synchronization signal is repeatedly generated within the one or more slaves; The detecting step determines whether the reference time exists between the times when two consecutive synchronization signals are generated for which the frame including the reference time among the frames repeatedly transmitted from the master should be received, thereby detecting whether there is a first abnormality related to the synchronization process; The detecting step detects whether there is a second abnormality related to the synchronization process based on the difference in the time when the monitoring device receives each of two consecutive frames including the reference time and the difference in the reference time included in each of the two consecutive frames; The detecting step determines that there is an abnormality in the clock of the slave that distributes the reference time when both the first abnormality and the second abnormality occur; Information processing method.

8. A monitoring device connected to a master and one or more slaves via an industrial network, receiving the frame repeatedly transmitted from the master within the industrial network; By analyzing the frame, detecting whether there is an abnormality related to the synchronization process performed between the master and the one or more slaves, which is executed based on the reference time distributed within the industrial network; causing to execute; The frame is repeatedly transmitted from the master at the same period as the synchronization signal period in which the synchronization signal is repeatedly generated within the one or more slaves; The detecting step determines whether the reference time exists between the times when two consecutive synchronization signals to be generated are generated for a frame including the reference time among the frames repeatedly transmitted from the master, so as to detect whether there is a first abnormality related to the synchronization process. The detecting step detects whether there is a second abnormality related to the synchronization process based on the difference between the times when the monitoring device receives each of two consecutive frames including the reference time and the difference between the reference times included in each of the two consecutive frames. When the first abnormality does not occur and the second abnormality occurs in the detecting step, it is determined that there is an abnormality in the clock provided in the monitoring device. Program.

9. In a monitoring device connected to a master and one or more slaves via an industrial network, receiving a frame repeatedly transmitted from the master within the industrial network; detecting whether there is an abnormality related to a synchronization process performed between the master and the one or more slaves, which is executed based on a reference time distributed within the industrial network, by analyzing the frame; and causing the above to be executed, the frame is repeatedly transmitted from the master at the same period as a synchronization signal period in which a synchronization signal is repeatedly generated within the one or more slaves, The detecting step determines whether the reference time exists between the times when two consecutive synchronization signals to be generated are generated for a frame including the reference time among the frames repeatedly transmitted from the master, so as to detect whether there is a first abnormality related to the synchronization process. The detecting step detects whether there is a second abnormality related to the synchronization process based on the difference between the times when the monitoring device receives each of two consecutive frames including the reference time and the difference between the reference times included in each of the two consecutive frames. The detecting step determines that there is an abnormality in the clock of the slave that distributes the reference time when both the first abnormality and the second abnormality occur. Program.

Citation Information

Patent Citations

  • Extended small base station system and clock synchronization system and clock synchronization method thereof

    CN115694698A

  • Vehicle-mounted TSN clock synchronization error test method

    CN116015520A

  • Data communication control equipment

    JP1999261581A

  • Industrial controller

    JP2009157913A

  • Control system, and proxy slave, proxy master, and control method used for the same

    JP2013197656A