Gateway device, relay method, and relay program
The gateway device addresses synchronization lags by verifying safe inputs before relaying non-safe outputs, ensuring timely safety transitions and meeting response time requirements in safety control.
Patent Information
- Application Number
- JP2024568578
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-04-03
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2043-04-03
AI Technical Summary
Existing systems fail to satisfy the required response time in safety control due to synchronization lags between the gateway device and the control device, leading to potential omission of necessary control actions.
A gateway device that relays communication between input and output devices, incorporating an input determination unit to verify the receipt of a safe input during a storage period before transmitting a non-safe output, ensuring timely transition to a safe state.
The solution ensures that even with synchronization lags, the required response time in safety control is met by preventing the relay of non-safe outputs and transmitting safe outputs when necessary, maintaining equipment safety.
Smart Images

Figure 0007710622000001 
Figure 0007710622000002 
Figure 0007710622000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a gateway device that relays communication between an input device and an output device and a control device that controls the output device based on an input signal from the input device.
Background Art
[0002] With the recent development of cloud computing, a method of utilizing the cloud for control has been studied. In the manufacturing industry, by realizing the control of on-site equipment with a virtual PLC on the cloud, it is possible to reduce the man-hours in operation management. PLC is an abbreviation for Programmable Logic Controller.
[0003] When realizing the control of on-site equipment using the cloud, it is necessary to consider safety control. Safety control is control related to the protection of on-site workers and the prevention of accidents. As safety control, for example, it is required to have a characteristic that realizes fail-safe. It is important to guarantee the response time in such safety control. In particular, the required response time for the transition of on-site equipment from a state where it may cause harm to workers to a safe state is clearly set based on the safety distance ensured by the on-site equipment. In control using the cloud, since the transmission delay during communication over the public network between the on-site and the cloud is longer than the transmission delay in control completed within the on-site, the problem is that the required response time cannot be satisfied.
[0004] Patent Document 1 describes a method of having some processing performed on-site in order to satisfy the required response time. The system configuration in the method of Patent Document 1 is such that a plurality of networks are each connected to a higher-level control device via a gateway device. In this configuration, when the result of control based on the input of an input / output device within a network is output to the input / output device within the same network, the gateway device substitutes for the higher-level control device and performs the control.
[0005] In Patent Document 1, in order to compensate for the disadvantage that a gateway device is also required on-site in addition to the upper control device, measures are taken to reduce the processing required by the gateway device and to reduce the number of required gateway devices. Specifically, only fragments of the processing in the control program that are restricted by the safety response time are implemented in the gateway device. Then, as an entire system combining the control device and the gateway device, a vertical distributed processing system that meets the safety requirements is configured. In the control program of the control method called sequence control (sequential control) in FA, a control structure in which the operation for the same input changes depending on the control context is common. FA is an abbreviation for Factory Automation. Therefore, simply cutting out a part of the control program will result in control that does not match the context, and the safety requirements will not be met. Thus, in Patent Document 1, the gateway device is made to identify the control state in the control device from the data to be relayed, so that the control is correctly performed.
Prior Art Documents
Patent Documents
[0006]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0007] In the method of Patent Document 1, there is a time lag until the control state of the gateway device synchronizes with the control state of the control device. Due to this time lag, omission of control that the gateway device should substitute for may occur. As a result, a situation where the required response time cannot be satisfied may occur. An object of the present disclosure is to satisfy the required response time in safety control.
Means for Solving the Problems
[0008] The gateway device according to the present disclosure is A gateway device that relays communication between an input device and an output device and a control device that controls the output device based on an input signal from the input device, When receiving a non-safe output, which is an output signal for controlling the control state of the output device to a non-safe state, from the control device, an input determination unit determines whether a safe input, which is an input signal for controlling the control state to a safe state during a storage period before reception, is received from the input device, When it is determined by the input determination unit that the safe input is received, an activation control unit does not relay the non-safe output to the output device and transmits a safe output, which is an output signal for controlling the control state of the output device to a safe state, to the output device and includes.
Advantages of the Invention
[0009] In the present disclosure, when the gateway device receives a non-safe output from the control device, if the safe input is received from the input device during the storage period before reception, the gateway device does not relay the non-safe output to the output device and transmits the safe output to the output device. Thereby, even if there is a time lag until the control state of the gateway device synchronizes with the control state of the control device, the required response time in safety control can be satisfied.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
MODE FOR CARRYING OUT THE INVENTION
[0011] Embodiment 1. The premise of the following description will be explained. In Embodiment 1, the control device controls the input / output device using control logic. The input / output device operates the equipment to be controlled according to the control by the control device. The control logic is configured by combining safety logic defined by a standard such as PLCopen, and has a safe state and a non-safe state. The non-safe state is a state in which the equipment to be controlled may cause harm to people. The non-safe state is, for example, the state during the operation of the equipment. The safe state is a state that is not a non-safe state. The safe state is, for example, the state during the stop of the equipment. Also, based on the principle that the equipment is started as soon as safety is confirmed, the initial state is the safe state. The control logic outputs an output signal corresponding to the destination state according to the state transition table based on the input signal from the input / output device and the current state. An input signal that causes a transition from a safe state to an unsafe state is called an unsafe input. An input signal that causes a transition from an unsafe state to a safe state is called a safe input. An output signal output when the state of the control logic is a safe state is called a safe output. An output signal output when the state of the control logic is an unsafe state is called an unsafe output.
[0012] ***Description of the situation*** The operation of safe stop by the method of Patent Document 1 will be classified and described into a normal system in which the gateway device can perform control as expected and an abnormal system in which problems occur.
[0013] Referring to FIG. 1, the normal system will be described. FIG. 1 is a timing chart with the horizontal axis as the time axis, showing the flow of relaying of inputs and outputs and the propagation of state transitions between devices. The initial state is a safe state. At this time, an unsafe input is transmitted from the input / output device. The gateway device receives the unsafe input. Then, the gateway device relays the unsafe input to the control device. When the control device receives the unsafe input, it switches the control state from the safe state to the unsafe state. Then, the control device transmits an unsafe output to the gateway device. When the gateway device receives the unsafe output, it switches the control state from the safe state to the unsafe state. Then, the gateway device relays the unsafe output to the input / output device. The input / output device receives the unsafe output. As a result, it becomes an unsafe state, and for example, the equipment starts operating.
[0014] Thereafter, a safe input is transmitted from the input / output device. The gateway device receives the safe input. Then, the gateway device switches the control state from the unsafe state to the safe state. Then, the gateway device relays the safe input to the control device and, on behalf of the control device, transmits a safe output to the input / output device. The input / output device receives the safe output. As a result, it becomes a safe state, and for example, the equipment stops operating. When the control device receives a safety input, it switches the control state from a non-safe state to a safe state. Then, the control device sends a safety output to the gateway device. When the gateway device receives the safety output, it relays the safety output to the input / output device. The input / output device has already entered the safe state when it receives the safety output. Therefore, for example, the state where the equipment is stopped continues.
[0015] As described above, when the gateway device receives a safety input in the non-safe state, it sends a safety output to the input / output device on behalf of the control device. That is, when a safety input is sent, a safety output is immediately sent from the gateway device. Thereby, the required response time in safety control is satisfied.
[0016] Referring to Figure 2, the abnormal system will be described. The initial state is a safe state. At this time, a non-safe input is sent from the input / output device. The gateway device receives the non-safe input. Let this time be time t0. Then, the gateway device relays the non-safe input to the control device. When the control device receives the non-safe input, it switches the control state from the safe state to the non-safe state. Then, the control device sends a non-safe output to the gateway device. The gateway device receives the non-safe output. Let this time be time t2. Then, the gateway device switches the control state from the safe state to the non-safe state. Then, the gateway device relays the non-safe output to the input / output device. The input / output device receives the non-safe output. As a result, it enters the non-safe state, and for example, the equipment starts operating.
[0017] Between time t0 and time t2, a safety input is sent from the input / output device. The gateway device receives the safety input. Let this time be time t1. Then, the gateway device relays the safety input to the control device. At time t1, the control state of the gateway device is in the safe state. Therefore, the gateway device does not send a safety output to the input / output device on behalf of the control device. This is because there is no need to urgently stop the equipment in the safe state. When the control device receives a safety input, it switches the control state from an unsafe state to a safe state. Then, the control device sends a safety output to the gateway device. When the gateway device receives the safety output, it switches the control state from an unsafe state to a safe state. Then, the gateway device relays the safety output to the input / output device. The input / output device receives the safety output. As a result, it enters a safe state, for example, the equipment stops operating. Let this time be time t3.
[0018] In the normal system, when the gateway device receives a safety input, it immediately sends a safety output to the input / output device. However, in the abnormal system, the gateway device receives a safety input at time t1, but the input / output device receives the safety output at time t3. That is, the response time in safety control becomes long. Since the maximum value of the response time is required to be guaranteed in all cases, the system response time cannot be guaranteed due to the abnormal system.
[0019] That is, for the gateway device to transmit a safety output to the input / output device on behalf of the control device, the control state needs to be in an unsafe state. However, the gateway device recognizes the unsafe state at time t2 when it receives an unsafe output. Therefore, if the gateway device receives a safety input between time t0 when it receives an unsafe input and time t2 when it receives an unsafe output, it does not transmit a safety output to the input / output device on behalf of the control device. That is, there is a miss in the control to be substituted. This is because the transmission time from when the input / output device sends an input signal until the gateway device receives the output signal is longer than the transmission time from when the input / output device sends an input signal until the gateway device receives the input signal.
[0020] ***Description of the Configuration*** Referring to FIG. 3, the configuration of the control system 100 according to Embodiment 1 will be described. The control system 100 includes a gateway device 10, a plurality of input / output devices 20, and a control device 30. The gateway device 10 and each input / output device 20 are connected via a transmission line 91. The gateway device 10 and the control device 30 are connected via a transmission line 92. Here, the transmission line 91 is assumed to be a network such as a LAN within a facility such as a factory. LAN is an abbreviation for Local Area Network. The transmission line 92 is assumed to be a public network.
[0021] The gateway device 10 relays the communication between the input / output device 20 and the control device 30. The input / output device 20 is divided into an input device 21 and an output device 22. The input device 21 is a device that transmits an input from a connected sensor or switch, etc. as an input signal to a higher-level device. The output device 22 is a device that outputs an operation according to an output signal received from a higher-level device to an actuator, etc. connected downstream. Based on the input signal from the input device 21 and the control state, the control device 30 transmits an output signal to the output device 22 to control the output device 22. Thereby, an actuator, etc. connected to the output device 22 is operated.
[0022] Referring to FIG. 4, the hardware configuration of the gateway device 10 according to Embodiment 1 will be described. The gateway device 10 is a computer. The gateway device 10 includes hardware such as a CPU 11, a memory 12, a non-volatile memory 13, and a bus 14. CPU is an abbreviation for Central Processing Unit. In the non-volatile memory 13, a program and parameters for realizing the functions of the functional components included in the gateway device 10 are stored. The CPU 11 reads the program and parameters stored in the non-volatile memory 13 into the memory 12 via the bus 14. The CPU 11 executes the program read into the memory 12. Thereby, the functions of the gateway device 10 are realized.
[0023] These hardware components are developed in accordance with safety-related requirements. These hardware components may be configured such that some or all of the components are duplicated in order to meet the required safety integrity level (SIL). SIL is the abbreviation of Safety Integrity Level. Note that the gateway device 10 may also be duplicated.
[0024] The gateway device 10 includes a communication method 1 port 15 and a communication method 2 port 16 for communication with other devices, and a setting port 17 for setting by an engineering tool. In Embodiment 1, the communication method 1 port is a port for communicating with the control device 30. In Embodiment 1, the communication method 2 port is a port for communicating with the input / output device 20.
[0025] Referring to FIG. 5, the functional configuration of the gateway device 10 according to Embodiment 1 will be described. The gateway device 10 includes, as functional components, a data relay unit 111, a activation control unit 112, an input determination unit 113, and a state monitoring unit 114. The data relay unit 111 functions to relay communication between the input / output device 20 and the control device 30. The input determination unit 113, the activation control unit 112, and the state monitoring unit 114 function to meet the required response time in safety control.
[0026] ***Description of Operations*** Referring to FIGS. 6 to 9, the operations of the gateway device 10 according to Embodiment 1 will be described. The operation procedure of the gateway device 10 according to Embodiment 1 corresponds to the relay method according to Embodiment 1. Also, the program for realizing the operations of the gateway device 10 according to Embodiment 1 corresponds to the relay program according to Embodiment 1.
[0027] Referring to FIG. 6, the processing of the gateway device 10 according to Embodiment 1 will be described. (Step S1: Data Relay Processing) When the input / output device 20 is activated, its state transitions according to the input signal from the initial safe state. At this time, as shown in FIG. 7, in the gateway device 10, the data relay unit 111 relays the communication between the input / output device 20 and the control device 30. That is, the data relay unit 111 transmits the input signal received from the input device 21 to the control device 30 via the shared memory for the input signal, and transmits the output signal received from the control device 30 to the output device 22 via the shared memory for the output signal.
[0028] At this time, as shown in FIG. 7, the activation control unit 112 stores the input signal received from the input / output device 20 in the input signal buffer. The input signal buffer is set in the memory 12, for example. Here, the period during which the input signal is stored in the input signal buffer is called the storage period. The storage period is a period longer than the period from when the input signal is received from the input device 21 until the output signal for controlling the output device 22 based on the input signal is received from the control device 30. The activation control unit 112 sequentially deletes the input signals that have passed the storage period from the input signal buffer.
[0029] Note that the activation control unit 112 does not need to store the input signal when the input / output device 20 is in a non-safe state. Here, as shown in FIG. 8, the state monitoring unit 114 manages the state of the input / output device 20 by monitoring the input signal. Therefore, the activation control unit 112 may not store the input signal when the state of the input / output device 20 managed by the state monitoring unit 114 is in a non-safe state. Also, the activation control unit 112 does not need to store the input signals that are not used by the input determination unit 113, which will be described later, among the input signals.
[0030] During the execution of the process in step S1, a non-safe input is transmitted from the input device 21. Then, the data relay unit 111 relays the non-safe input to the control device 30. The control device 30 executes the control logic and transmits the non-safe output to the gateway device 10. When the data relay unit 111 receives this non-safe output, the process in step S2 is executed.
[0031] (Step S2: Input determination process) As shown in FIG. 9, the input determination unit 113 determines whether or not the input signal stored in the input signal buffer includes a safe input. That is, the input determination unit 113 determines whether or not a safe input has been received from the input device 21 during the storage period before the reception of the non-safe output. In other words, the input determination unit 113 determines whether or not a safe input has been transmitted from the input device 21 after a non-safe input has been transmitted from the input device 21. This corresponds to the input determination unit 113 determining whether or not the current state becomes a safe state when the input signals stored in the input signal buffer are applied in time series. When the input determination unit 113 determines that a safe input is included, the process proceeds to step S3. On the other hand, when the input determination unit 113 determines that no safe input is included, the process proceeds to step S4.
[0032] (Step S3: Relay Hold Process) The activation control unit 112 does not relay the non-safe output to the output device 22 and transmits the safe output to the output device 22. In practice, instead of the activation control unit 112 directly transmitting the safe output, the activation control unit 112 may instruct the data relay unit 111 to transmit the safe output. Thereby, even when there is a safe input immediately after a non-safe input, the influence of the public network can be excluded from the response time in the protection operation. The activation control unit 112 stops relaying the non-safe output received from the control device 30 to the output device 22 and continues to transmit the safe output until it receives the safe output from the control device 30. When the activation control unit 112 receives the safe output from the control device 30, the process returns to step S1.
[0033] (Step S4: Relay Continuation Process) The activation control unit 112 transmits the non-safe output to the output device 22. That is, the activation control unit 112 relays the non-safe output. In practice, instead of the activation control unit 112 directly transmitting the non-safe output, the activation control unit 112 may instruct the data relay unit 111 to transmit the non-safe output. Then, the activation control unit 112 returns the process to step S1.
[0034] ***Effects of Embodiment 1*** As described above, when the gateway device 10 according to Embodiment 1 receives a non-safe output from the control device 30, if it has received a safe input from the input device 21 during the storage period before the reception, it does not relay the non-safe output to the output device 22, but transmits the safe output to the output device 22. As a result, even if there is a time lag until the control state of the gateway device 10 synchronizes with the control state of the control device 30, the request response time in the safety control can be satisfied.
[0035] Referring to FIG. 10, the effects of the gateway device 10 according to Embodiment 1 will be described. The initial state is a safe state. At this time, a non-safe input is transmitted from the input / output device 20. The gateway device 10 receives the non-safe input. Then, the gateway device 10 relays the non-safe input to the control device. When the control device 30 receives the non-safe input, it switches the control state from the safe state to the non-safe state. Then, the control device 30 transmits a non-safe output to the gateway device 10. The flow up to here is the same as the abnormal system described with reference to FIG. 2. Before the gateway device 10 receives a safe output, a safe input is transmitted from the input / output device 20. The gateway device 10 receives the safe input. Then, the gateway device relays the safe input to the control device. After that, the gateway device 10 receives a non-safe output. Then, the gateway device 10 determines whether the input signal stored in the input signal buffer includes the safe input (step S2 in FIG. 6). Here, the safe input is included. Therefore, the gateway device 10 does not relay the non-safe output to the output device 22, but transmits the safe output to the output device 22 (step S3 in FIG. 6). Therefore, the state of the input / output device 20 remains in the safe state, and the operation of the equipment is not started. The response time is the time from when the safe input is transmitted until the safe output is transmitted. In other words, the response time is the time from when the safe input is transmitted until the safe state is realized. In the example of FIG. 10, the safe state is maintained after the safe input is made. Therefore, the response time is substantially zero.
[0036] ***Other configurations*** <Modification Example 1> In Embodiment 1, each functional component was realized by software. However, as Modification Example 1, each functional component may be realized by hardware. Regarding this Modification Example 1, the differences from Embodiment 1 will be described.
[0037] When each functional component is realized by hardware, the gateway device 10 includes an electronic circuit instead of the CPU 11, the memory 12, and the non-volatile memory 13. The electronic circuit is a dedicated circuit that realizes the functions of each functional component, the memory 12, and the non-volatile memory 13.
[0038] As the electronic circuit, a single circuit, a composite circuit, a programmed processor, a parallel-programmed processor, a logic IC, a GA, an ASIC, or an FPGA is assumed. GA is an abbreviation for Gate Array. ASIC is an abbreviation for Application Specific Integrated Circuit. FPGA is an abbreviation for Field-Programmable Gate Array. Each functional component may be realized by one electronic circuit, or each functional component may be realized by being distributed among a plurality of electronic circuits.
[0039] <Modification Example 2> As Modification Example 2, some of each functional component may be realized by hardware, and the other functional components may be realized by software.
[0040] The CPU 11, the memory 12, the non-volatile memory 13, and the electronic circuit are referred to as a processing circuit. That is, the functions of each functional component are realized by the processing circuit.
[0041] Embodiment 2. In Embodiment 2, a method for generating the control logic of the gateway device 10 will be described.
[0042] In order for the gateway device 10 to implement the processing shown in FIG. 6, it is necessary to implement control logic different from that of the control device 30. The control logic implemented by the gateway device 10 is generated from the control program executed by the control device 30. The control logic implemented by the gateway device 10 can be realized by state transition.
[0043] The derivation of the control logic implemented by the gateway device 10 needs to be performed before the start of control of the gateway device 10. As for the control logic implemented by the gateway device 10, a method of adding an automatic derivation function to the engineering tool 40, or a method of adding to the gateway device 10 a function of calling and using what has been derived in advance by the vendor of the gateway device 10 or the engineering tool 40, etc. can be considered. In Embodiment 2, an example in which the engineering tool 40 generates the control logic implemented by the gateway device 10 will be described.
[0044] ***Description of Configuration*** With reference to FIG. 11, the hardware configuration of the engineering tool 40 according to Embodiment 2 will be described. The engineering tool 40 is a computer. The engineering tool 40 includes hardware such as a CPU 41, a memory 42, a non-volatile memory 43, and a bus 44. In the non-volatile memory 43, programs and parameters for realizing the functions of the functional components included in the engineering tool 40 are stored. The CPU 41 reads the programs and parameters stored in the non-volatile memory 43 into the memory 42 via the bus 44. The CPU 41 executes the programs read into the memory 42. Thereby, the functions of the engineering tool 40 are realized.
[0045] The engineering tool 40 includes a setting port 45 for setting the gateway device 10 or the control device 30.
[0046] Referring to FIG. 12, the functional configuration of the engineering tool 40 according to Embodiment 2 will be described. The engineering tool 40 includes, as functional components, a gateway logic generation unit 411, a gateway logic setting unit 412, a control logic generation unit 413, a control logic setting unit 414, and a programming unit 415. The gateway logic generation unit 411 has a function of generating the control logic of the gateway device 10. The gateway logic setting unit 412 has a function of setting the control logic in the gateway device 10. The control logic generation unit 413 has a function of generating the control logic of the control device 30. The control logic setting unit 414 has a function of setting the control logic in the control device 30. The programming unit 415 has a function of assisting in the generation of the control logic. Here, the gateway logic generation unit 411 and the gateway logic setting unit 412 will be described.
[0047] ***Description of Operations*** Referring to FIGS. 13 to 16, the operations of the engineering tool 40 according to Embodiment 1 will be described. The operation procedure of the engineering tool 40 according to Embodiment 2 corresponds to the logic generation method according to Embodiment 2. Also, the program for realizing the operations of the engineering tool 40 according to Embodiment 2 corresponds to the logic generation program according to Embodiment 2.
[0048] Referring to FIG. 13, the basic state transition of the gateway device 10 according to Embodiment 2 will be described. The gateway device 10 has, as states, a safe state, a non-safe state, a safe standby state, an inspection standby state, and a non-safe standby state. When a non-safe output is received in a safe state, the state transitions to a non-safe state. When a safe input is received in a non-safe state, the state transitions to a safe standby state. When a safe output is received in a safe standby state, the state transitions to an inspection standby state. When a non-safe output is received in an inspection standby state, the state transitions to a non-safe standby state. When there is a safe input in the input signal buffer described later in the non-safe standby state, the state transitions to a safe standby state. When there is no safe input in the input signal buffer described later in the non-safe standby state, the state transitions to a non-safe state.
[0049] The safe standby state is a state in which a non-safe output is not relayed to the output device 22 and a safe output is transmitted to the output device 22. That is, the safe standby state is a state in which the process of step S3 in FIG. 6 is being performed. The inspection standby state is a state in which the input signal is stored in the input signal buffer while monitoring the non-safe output. That is, the inspection standby state is a state in which the input signal is stored in the input signal buffer in step S1 of FIG. 6. The non-safe standby state is a state in which it is determined whether or not to relay the non-safe output to the output device 22. That is, the non-safe standby state is a state in which the process of step S2 in FIG. 6 is being performed.
[0050] With reference to FIGS. 14 to 16, a specific example of the state transition of the gateway device 10 according to Embodiment 1 will be described. Here, it is assumed that the control logic of the control device 30 is realized by the state transition shown in FIG. 14. In FIG. 15, the state transition shown in FIG. 14 is represented in a table format. In the state transition shown in FIG. 14, when Condition 1 is satisfied in the initial state, i.e., Safe State 0, the state transitions to Safe State 1. When Condition 2 is satisfied in Safe State 1, the state transitions to Safe State 2. When Condition 3 is satisfied in Safe State 2, the state transitions to Safe State 1. When Condition 4 is satisfied in Safe State 2, the state transitions to Unsafe State 1. That is, satisfying Condition 4 is an unsafe input. When Condition 5 is satisfied in Unsafe State 1, the state transitions to Unsafe State 2. When Condition 6 is satisfied in Unsafe State 2, the state transitions to Unsafe State 1. When Condition 7 is satisfied in Unsafe State 2, the state transitions to Safe State 3. That is, satisfying Condition 7 is a safe input. When Condition 8 is satisfied in Safe State 3, the state transitions to Safe State 2.
[0051] The gateway logic generation unit 411 performs the following steps (1) to (5) in order to generate the state transition shown in FIG. 16.
[0052] (1) The gateway logic generation unit 411 extracts records in which the current state is an unsafe state from the table (see FIG. 15) showing the control logic of the control device 30. Here, three records with line numbers 5 to 7 in FIG. 15 are extracted and set as records with line numbers 1 to 3 in FIG. 16.
[0053] (2) The gateway logic generation unit 411 adds a record in which the current state is an unsafe standby state, there is a safe input in the input signal buffer, and the next state is a safe standby state. Here, the record with line number 4 in FIG. 16 is added. In addition, the gateway logic generation unit 411 adds a row in which the current state is an unsafe standby state, there is no safe input in the input signal buffer, and the next state is an unsafe state. When there are multiple unsafe states transitioning from a safe state, the gateway logic generation unit 411 adds records equal to that number. Here, the record with line number 5 in FIG. 16 is added.
[0054] (3) The gateway logic generation unit 411 adds a record where the current state is a non-safe state, the condition is receiving a safe input, and the next state is a safe standby state. Note that when there are multiple non-safe states that transition to a safe state, the gateway logic generation unit 411 adds records for each of them. Here, the record at line number 6 in FIG. 16 is added.
[0055] (4) The gateway logic generation unit 411 adds a record where the current state is a safe standby state, the condition is receiving a safe output, and the next state is an inspection standby state. Here, the record at line number 7 in FIG. 16 is added.
[0056] (5) The gateway logic generation unit 411 adds a record where the current state is an inspection standby state, the condition is receiving a non-safe output, and the next state is a non-safe standby state. Here, the record at line number 8 in FIG. 16 is added.
[0057] Then, the gateway logic setting unit 412 sets the control logic indicated by the generated state transition in the gateway device 10.
[0058] ***Effects of Embodiment 2*** As described above, the engineering tool 40 according to Embodiment 2 generates the control logic of the gateway device 10 from the control logic of the control device 30. Thereby, it is possible to easily generate the control logic of the gateway device 10.
[0059] Also, in the above description, the “unit” may be read as “circuit”, “step”, “procedure”, “process” or “processing circuit”.
[0060] The embodiments and modification examples of the present disclosure have been described above. Some of these embodiments and modification examples may be combined and implemented. Also, any one or some of them may be partially implemented. Note that the present disclosure is not limited to the above embodiments and modification examples, and various changes can be made as necessary.
Description of Reference Numerals
[0061] 100 Control system, 10 Gateway device, 11 CPU, 12 Memory, 13 Non-volatile memory, 14 Bus, 15 Communication method 1 port, 16 Communication method 2 port, 17 Setting port, 111 Data relay section, 112 Activation control section, 113 Input determination section, 114 State monitoring section, 20 Input / output device, 21 Input device, 22 Output device, 30 Control device, 40 Engineering tool, 41 CPU, 42 Memory, 43 Non-volatile memory, 44 Bus, 45 Setting port, 411 Gateway logic generation section, 412 Gateway logic setting section, 413 Control logic generation section, 414 Control logic setting section, 415 Programming section, 91 Transmission line, 92 Transmission line.
Claims
1. A gateway device that relays communication between an input device and an output device and a control device that controls the output device based on an input signal from the input device, when receiving a non-safe output, which is an output signal for controlling the control state of the output device to a non-safe state, from the control device, determines whether a safe input, which is an input signal for controlling the control state to a safe state during a storage period before reception, has been received from the input device; an input determination unit, when determined by the input determination unit that the safe input has been received, does not relay the non-safe output to the output device, and transmits a safe output, which is an output signal for controlling the control state of the output device to a safe state, to the output device; an activation control unit A gateway device comprising:
2. When determined by the input determination unit that the safe input has not been received, the activation control unit transmits a non-safe output, which is an output signal for controlling the control state of the output device to a non-safe state, to the output device The gateway device according to claim 1.
3. When determined by the input determination unit that the safe input has been received, the activation control unit stops relaying the non-safe output received from the control device to the output device until the safe output is received from the control device The gateway device according to claim 1.
4. When the activation control unit receives the safe output from the control device, it starts relaying the non-safe output received from the control device to the output device The gateway device according to claim 3.
5. The storage period is a period longer than the period from receiving a certain input signal from the input device until receiving an output signal for controlling the output device based on the certain input signal from the control device The gateway device according to claim 1.
6. A relay method for relaying communication between an input device and an output device and a control device that controls the output device based on an input signal from the input device, when a gateway device receives a non-safe output, which is an output signal for controlling the control state of the output device to a non-safe state, from the control device, determines whether a safe input, which is an input signal for controlling the control state to a safe state during a storage period before reception, has been received from the input device, A relay method in which, when it is determined that the gateway device has received the safety input, the gateway device does not relay the non-safety output to the output device, but transmits to the output device a safety output which is an output signal for controlling the control state of the output device to a safe state.
7. A relay program for relaying communication between an input device and an output device and a control device that controls the output device based on an input signal from the input device, an input determination unit that, when receiving a non-safety output which is an output signal for controlling the control state of the output device to a non-safe state from the control device, determines whether or not a safety input which is an input signal for controlling the control state to a safe state has been received from the input device during a storage period before reception; an activation control unit that, when determined by the input determination unit that the safety input has been received, does not relay the non-safety output to the output device, but transmits to the output device a safety output which is an output signal for controlling the control state of the output device to a safe state A relay program that causes a computer to function as a gateway device that performs the above.
Citation Information
Patent Citations
Safety network system, safety slave, and safety controller
WO2003001306A1
Gateway device, gateway control method, and gateway control program
WO2022239116A1