Production systems and control devices

The production system addresses the challenge of secure remote operation authorization in industrial control systems by allowing workers to request and execute operations only with administrator approval, enhancing security and operational efficiency.

JP7835879B2Active Publication Date: 2026-03-25FANUC LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-10-14
Publication Date
2026-03-25

AI Technical Summary

Technical Problem

In industrial control systems, administrators' fluid location and remote operation requirements pose challenges to secure user authentication and authority management, increasing security risks and operational inefficiencies.

Method used

A production system that authorizes operations from an administrator's terminal, allowing workers to request approval remotely and execute operations only upon receiving approval, using a network-connected control device and terminal with authorization and terminal information storage units to manage permissions.

Benefits of technology

Enables secure, remote operation authorization, preventing unauthorized changes and information leakage, improving operational stability and convenience by ensuring only approved operations are executed, even when administrators are not present.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007835879000001
    Figure 0007835879000001
  • Figure 0007835879000002
    Figure 0007835879000002
  • Figure 0007835879000003
    Figure 0007835879000003
Patent Text Reader

Abstract

In a production system according to the present disclosure, a control device for controlling an industrial machine and a terminal used by an approver are connected via a network, and said production system comprises: a permissions information storage unit for storing permissions information relating to operation; a terminal information storage unit for storing terminal information relating to the terminal; an operation reception unit for receiving an operation by an operator; a permissions processing unit for determining whether the operator may execute the operation; and an operation execution unit that executes the operation on the basis of the result of determination by the permissions processing unit. The permissions processing unit determines that the operator may execute an operation only when the operator has permission for the operation or when approval by the approver to execute the operation is obtained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a production system and a control device.

Background Art

[0002] In recent years, with the progress of factory automation and networking, cyberattacks on control devices of industrial machines used in factories have been increasing. Therefore, even in control devices where countermeasures against cyberattacks were relatively sparse in the past, the importance of security functions has been increasing (for example, Patent Document 1, etc.).

[0003] There are various security functions, and one of them is user authentication and authority management. By this measure, even if an attacker intrudes into the factory network, they cannot pass the user authentication, so they cannot obtain the necessary authority, and remote operation and information leakage can be prevented. On the other hand, it is also possible to prevent factory workers from making unauthorized setting changes or performing operations, which also contributes to the stable operation and quality improvement of the factory.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] When setting changes or special operations are required during the operation of the control device, if the necessary authority is restricted only to the administrator and the operator does not have the authority, authentication cannot be performed and the operation cannot be executed unless the administrator is present near the device. Compared with the IT area that deals with information systems and office equipment, etc., in the OT area that deals with production systems and industrial machines, etc., the whereabouts of the administrator are fluid and not fixed, so the impact is also significant.

[0006] Possible workarounds include adding a function that allows administrators to remotely control the system, or communicating authentication information such as passwords to workers via phone or email. However, these methods increase security risks. [Means for solving the problem]

[0007] The production system described in this disclosure solves the above problem by requesting only authorization from the administrator's terminal when an operation requiring administrator privileges occurs, and then granting the privileges to the worker based on the response.

[0008] Furthermore, one aspect of the present disclosure is a production system in which a control device that controls an industrial machine used by an operator for work and a terminal used by an approver that approves the operation of the control device and the functions of the industrial machine by the operator are connected via a network, the system comprising: an authorization information storage unit that stores authorization information related to the operation and a terminal information storage unit that stores terminal information related to the terminal, the control device comprising: an operation reception unit that receives an operation from the operator; an authorization processing unit that determines whether the operator is permitted to perform the operation based on the authorization information stored in the authorization information storage unit; a first communication control unit that controls communication between the terminal used by the approver and the terminal based on the terminal information stored in the terminal information storage unit; and the result of the determination by the authorization processing unit The production system comprises an operation execution unit that performs the aforementioned operation, the terminal comprising a second communication control unit that controls communication with the control device, and an operation feasibility determination unit that determines whether the operator can perform the aforementioned operation based on the operation of the approver, the authorization processing unit refers to the authorization information storage unit to determine if the operator has the authority to perform the aforementioned operation, or sends a request for approval of the operator's execution of the aforementioned operation to the terminal via the first communication control unit, and determines that the operator may perform the aforementioned operation if a response indicating that the operator's execution of the aforementioned operation has been approved is obtained in response to the request, and determines that the operator cannot perform the aforementioned operation if a response indicating that the operator's execution of the aforementioned operation has not been approved is obtained in response to the request. [Brief explanation of the drawing]

[0009] [Figure 1] This is a schematic hardware configuration diagram of a production system according to the first embodiment of the present disclosure. [Figure 2] This block diagram shows the schematic functions of a production system according to the first embodiment of this disclosure. [Figure 3] This figure shows an example of operation information according to the first embodiment. [Figure 4] This figure shows an example of authorization information according to the first embodiment. [Figure 5] This figure shows an example of the operation permission request setting screen according to the first embodiment. [Figure 6] This figure shows an example of terminal information according to the first embodiment. [Figure 7] This figure shows an example of a screen for determining whether an operation is possible according to the first embodiment. [Figure 8] This is a flowchart illustrating the processing flow performed in the production system according to the first embodiment. [Figure 9] This block diagram shows the schematic functions of a production system according to a second embodiment of the present disclosure. [Figure 10] This block diagram shows schematic functions illustrating a production system according to other embodiments of the present disclosure. [Modes for carrying out the invention]

[0010] The embodiments of this disclosure will be described below with reference to the drawings. [First Embodiment] Figure 1 is a schematic hardware configuration diagram showing the main components of a production system according to the first embodiment of this disclosure. The production system 300 according to this embodiment is configured such that a control device 1 and a terminal 8 are connected via a network 5. The control device 1 controls industrial machinery 3 installed at a manufacturing site such as a factory based on operations performed by workers. The terminal 8 is, for example, a terminal owned by an administrator who manages the control device 1.

[0011] The CPU 11 in the control device 1 according to this embodiment is a processor that controls the control device 1 as a whole. The CPU 11 reads the system program stored in the ROM 12 via the bus 22 and controls the entire control device 1 according to the system program. The RAM 13 temporarily stores temporary calculation data, display data, and various data input from external sources.

[0012] The non-volatile memory 14 is composed of, for example, a memory backed up by a battery (not shown) or an SSD (Solid State Drive), and its stored state is maintained even when the power to the control device 1 is turned off. The non-volatile memory 14 stores data acquired from the industrial machine 3, programs and data read from external devices 72 via the interface 15, programs and data input via the input device 71, and programs and data acquired from other devices via the network 5. The programs and data stored in the non-volatile memory 14 may be expanded into the RAM 13 when executed / used. In addition, various system programs, such as known analysis programs, are pre-written in the ROM 12.

[0013] Interface 15 is an interface for connecting the CPU 11 of the control device 1 to an external device 72 such as a USB device. The external device 72 may be an external storage means such as a memory reader that reads and writes recording media such as CompactFlash® or SD cards, or a disk drive that reads and writes recording media such as CDs, DVDs, or BDs. Programs and setting data, for example, can be read from the external device 72. In addition, programs and setting data edited within the control device 1 can be stored in the external storage means via the external device 72.

[0014] The interface 20 is an interface for connecting the CPU 11 of the control device 1 to a wired or wireless network 5. To the network 5, control devices of other industrial machines, fog computers 6, cloud servers 7, terminals 8 operated by administrators, etc. are connected, and data is exchanged with the control device 1 mutually.

[0015] To the display device 70, each data read onto the memory, data obtained as a result of execution of a program, etc. are output via the interface 17 and displayed. The display device 70 may be provided with LED indicators and warning lamps indicating the state of the machine. Further, an input device 71 composed of a keyboard, a pointing device, a card reader, etc. passes commands, data, etc. based on operations by an operator to the CPU 11 via the interface 18.

[0016] The control device 1 controls the industrial machine 3 based on a control program, an external signal, a command by an operator, etc. The industrial machine 3 is a machine tool, an electric discharge machining machine, a robot, etc. installed at a manufacturing site such as a factory.

[0017] The terminal 8 operated by the administrator may be, for example, a personal computer installed remotely from the industrial machine 3 or the control device 1. Further, it may be a portable device carried by the administrator, a wearable terminal, etc. The terminal 8 exchanges data and programs with the control device 1 at least via the network 5 according to the operation of the administrator.

[0018] The CPU 811 included in the terminal 8 is a processor that controls the terminal 8 as a whole. The CPU 811 reads out the system program stored in the ROM 812 via the bus 822 and controls the entire terminal 8 according to the system program. Temporary calculation data, display data, and various data input from the outside are temporarily stored in the RAM 8 / 13.

[0019] The non-volatile memory 814 is composed of, for example, a battery-backed memory (not shown) or an SSD (Solid State Drive), and its memory state is maintained even when the terminal 8 is powered off. The non-volatile memory 814 stores programs and data acquired from the control device 1 and other devices via the network 5, as well as programs and data input via the input device 871. The programs and data stored in the non-volatile memory 814 may be loaded into the RAM 813 when executed or used. In addition, various system programs, such as known image processing programs, are pre-written into the ROM 812.

[0020] Interface 815 is an interface for connecting the CPU 811 of terminal 8 to an external device 872 such as a USB device. The external device 872 may be an external storage means such as a memory reader that reads and writes recording media such as CompactFlash® or SD cards, or a disk drive that reads and writes recording media such as CDs, DVDs, or BDs. Programs and data, for example, can be read from the external device 872. In addition, programs and data created within terminal 8 can be recorded to the external storage means via the external device 872.

[0021] Interface 820 is an interface for connecting the CPU 811 of terminal 8 to a wired or wireless network 5. The network 5 is connected to the control device 1, industrial machinery 3, fog computer 6, cloud server 7, etc., and exchanges data with terminal 8.

[0022] The display device 870 displays data, programs, and other data obtained as a result of their execution, which are read into memory, via the interface 817. The input device 871, consisting of a keyboard, pointing device, touch panel, etc., transmits commands and data based on operator input to the CPU 811 via the interface 818.

[0023] Figure 2 is a schematic block diagram showing the functions of the control device 1 and terminal 8 according to this embodiment. Each function of the control device 1 and terminal 8 according to this embodiment is realized by the CPU 11 of the control device 1 and the CPU 811 of the terminal 8, as shown in Figure 1, executing system programs and controlling the operation of each part of the control device 1 and terminal 8.

[0024] The control device 1 according to this embodiment includes an operator authentication unit 100, an operation reception unit 110, an authorization processing unit 120, a communication control unit 130, and an operation execution unit 140. Furthermore, the RAM 13 to non-volatile memory 14 of the control device 1 are pre-configured with an authentication information storage unit 200, which is a pre-configured area for storing information necessary to authenticate operators who operate each function of the control device 1 and the industrial machine 3; an authorization information storage unit 210, which is a pre-configured area for storing authorization information related to the operation of each function of the control device 1 and the industrial machine 3; and a terminal information storage unit 220, which is a pre-configured area for storing information related to the terminal used by the approver.

[0025] The operator authentication unit 100 authenticates the operator performing the operation on the control device 1. It then outputs the authenticated operator's identification information to the operation reception unit 110. The operator authentication unit 100 may, for example, display a prompt on the display device 70 to input authentication information. In this case, it may acquire the authentication information input from the input device 71 in response to this prompt and authenticate the operator based on the acquired authentication information. At this time, the authentication information can be information that uniquely identifies the operator and a password corresponding to that identification information. The operator authentication unit 100, having acquired the authentication information, compares the received authentication information with the information stored in the authentication information storage unit 200. If, as a result of the comparison, it is determined that the combination of identification information and password is correct, it determines that the operator has been correctly authenticated and outputs the operator's identification information to the operation reception unit 110. The operator authentication unit 100 may also, for example, display a token such as an ID card held by the operator on the display device 70. In this case, the operator authentication unit 100 performs a predetermined exchange with the token (such as PIN code verification), and as a result obtains information that uniquely identifies the operator from the token via the input device 71. Having obtained the operator's identification information, the operator authentication unit 100 compares the received identification information with the information stored in the authentication information storage unit 200. If the operator's identification information is stored in the authentication information storage unit 200, it determines that the operator has been correctly authenticated and outputs the operator's identification information to the operation reception unit 110. The operator authentication performed by the operator authentication unit 100 may use other known methods as long as the operator can be uniquely authenticated.

[0026] The operation reception unit 110 creates operation information based on the operations performed by the operator. It then outputs the created operation information to the authorization processing unit 120. The operations accepted by the operation reception unit 110 include, for example, operations performed by the operator on the input device 71, operations performed on a control panel (not shown), operation requests based on external signals, and operation requests from other computers such as the fog computer 6 via the network 5. The content of the operations accepted by the operation reception unit 110 includes all operations that can be performed on the control device 1, such as operations related to the control of the industrial machine 3, operations related to reading, writing, editing, and executing control programs for controlling the industrial machine 3, operations related to the settings of the control device 1, and maintenance operations such as data backup and restore. The operation information created by the operation reception unit 110 includes, for example, information that uniquely identifies the operator and information that specifies the content of the operation. The information that uniquely identifies the operator included in the operation information may be the operator identification information input from the operator authentication unit 100 if the operation was received from the input device 71 or the control panel. Furthermore, if the operation is an operation request via an external signal or network 5, the operator identification information included in the operation request may be the operator identification information. On the other hand, the information that identifies the operation content may include information that uniquely identifies the operation content and auxiliary information corresponding to that operation content. The auxiliary information may include, for example, the object or parameters related to the operation.

[0027] Figure 3 shows an example of operation information created based on operator actions. In the example in Figure 3, the operator's name, "Operator A," is included as information to uniquely identify the operator. The operation is "Setting Change," and the supplementary information includes that the target of the change is "Machining Accuracy Setting" and the change is "Change from Normal Setting to Accuracy Prioritized." Note that the operation content does not necessarily need to include supplementary information. For example, in the example in Figure 3, if there is no need to finely divide permissions based on the target of the change or the content of the change for the "Setting Change" operation, then supplementary information such as the target of the change and the content of the change is unnecessary.

[0028] The authorization processing unit 120 determines whether the operator performing the operation has the authority to perform the operation, based on the operation information input from the operation reception unit 110 and the authorization information stored in the authorization information storage unit 210. The authorization information associates each operation that can be executed by the control device 1 with authorization holder identification information, which is information for identifying the person who has the authority to perform the operation, and approver identification information, which is information for identifying the person who approves the execution of the operation. The authorization processing unit 120 reads the authorization information corresponding to the operation content from the authorization information storage unit 210 based on the operation content contained in the operation information. Then, it matches the operator identification information contained in the operation information with the authorization holder identification information contained in the read authorization information to determine whether the operator has the authority to perform the operation. If it determines that the operator has the authority to perform the operation, it decides that the operator may perform the operation and instructs the operation execution unit 140 to perform the operation. On the other hand, if it determines that the operator does not have the authority to perform the operation, it creates an operation permission request to send to one of the approvers included in the approver identification information contained in the read authorization information. This operation permission request may include information useful to the approver in determining whether or not to permit the operation. For example, the operation permission request may include information that uniquely identifies the industrial machine 3, information that uniquely identifies the operator, the operation details, information related to the current operating status of the industrial machine 3 (alarms, coordinate values, etc.), information related to the operating environment of the industrial machine 3 (ambient temperature, etc.), and comments from the operator. The communication control unit 130 is then instructed to transmit the created operation permission request. If the approver's response to the operation permission request is "permitted," the system determines that the operator may perform the operation and instructs the operation execution unit 140 to perform the operation. On the other hand, if the response is "not permitted," the system determines that the operator cannot perform the operation, responds to the operator that the operation cannot be performed, and discards the operation information.

[0029] Figure 4 shows an example of authorization information stored in the authorization information storage unit 210. In the example in Figure 4, for "Operation A" that can be executed by the control device 1, workers such as worker D and worker E have the authority to execute the operation. Furthermore, even if they cannot execute the operation, they can execute it by obtaining approval from approvers such as administrator A and administrator B. The authorization holder identification information may be a whitelist that specifies those who have the authority to execute the operation. It may also be a blacklist that specifies those who are prohibited from executing the operation. Furthermore, it may be a combination of these. In the example in Figure 4, authorization information is prepared for each individual operation, but for example, multiple operations may be grouped together, and authorization information may be created for all operations belonging to that group together. Also, in the example in Figure 4, authorization holder identification information and approver identification information are created as lists on a worker-by-worker and administrator-by-administrator basis, but group information that groups workers and administrators into predetermined groups may be created in advance, and authorization holder identification information and approver identification information may be created using that group information.

[0030] Figure 5 illustrates a screen that allows the operator to perform necessary settings when the authorization processing unit 120 sends an operation permission request. When the authorization processing unit 120 sends an operation permission request to the terminal 8 used by the approver, it may display a screen that allows the operator to select the approver, as illustrated in Figure 5. It may also allow the operator to input comments such as the purpose of performing the operation.

[0031] The authorization processing unit 120 may discard operation information created based on operation requests from other computers via the network 5, treating the operation as unexecutable. For example, even if an operation request is received directly from a terminal 8 owned by the administrator, the operation information related to that operation may be discarded.

[0032] The communication control unit 130 sends an operation permission request to the terminal 8 used by the approver in response to a command from the authorization processing unit 120. Then, it receives an operation permission determination, which is the response to the operation permission request, from the terminal 8 used by the approver and outputs it to the authorization processing unit 120. The communication control unit 130 refers to the terminal information storage unit 220 in order to identify the terminal 8 used by the approver. Figure 6 shows an example of terminal information stored in the terminal information storage unit 220. The terminal information storage unit 220 stores approver terminal information, which is pre-associated with information that identifies the approver and the terminal used by the approver. The terminal identification information may be information that can uniquely identify the terminal 8 used by the approver on the network 5, such as an IP address in a TCP / IP network or a computer name in a Windows network. It may also be an email address or an identifier on a designated SNS. The terminal information stored in the terminal information storage unit 220 should be obtained in advance and stored in the terminal information storage unit 220. Furthermore, when the administrator changes the terminal 8 being used, the terminal information stored in the terminal information storage unit 220 may be updated based on the terminal information change command sent from terminal 8. The transmitted communication control unit 130 refers to the terminal information storage unit 220 to identify the terminal 8 being used by the approver included in the operation permission request, and sends the operation permission request to the identified terminal 8.

[0033] The communication control unit 130 may be configured to use known technologies such as communication encryption and digital signature attachment when communicating with the terminal 8. Ideally, the communication between the communication control unit 130 and the terminal 8 should be designed so that its contents cannot be intercepted or falsified by anyone, including workers and administrators.

[0034] The operation execution unit 140 then executes the operator's operations based on commands from the authorization processing unit 120. The operations executed by the operation execution unit 140 include all operations that can be executed in the control device 1, such as operations related to the control of the industrial machine 3, operations related to reading, writing, editing, and executing control programs for controlling the industrial machine 3, and operations related to the settings of the control device 1.

[0035] On the other hand, the terminal 8 according to this embodiment includes a communication control unit 880 and an operation feasibility determination unit 890. The communication control unit 880 of terminal 8 receives an operation permission request transmitted from control unit 1 via network 5. It then outputs the received operation permission request to the operation permission determination unit 890.

[0036] The operation permission determination unit 890 determines whether to grant permission to the operator for the operation included in the operation permission request input from the communication control unit 880. For example, the operation permission determination unit 890 may present an operation permission determination screen to the approver, who is the user of terminal 8, and prompt the approver to input whether to permit the operation or not. Figure 7 shows an example of an operation permission determination screen. As illustrated in Figure 7, the operation permission determination screen shows the approver the request content included in the operation permission request. The approver selects whether to permit or deny the operation to the operator according to the request content. The operation permission determination unit 890 creates an operation permission response based on the approver's selection and outputs the created operation permission response to the communication control unit 880.

[0037] The communication control unit 880 then transmits the operation feasibility response received from the operation feasibility determination unit 890 to the control device 1 via the network 5. The communication control unit 880 may be configured to use known technologies such as communication encryption and digital signature attachment when communicating with the control device 1. Ideally, the communication between the communication control unit 880 and the control device 1 should be designed so that its contents cannot be intercepted or falsified by anyone, including workers and administrators.

[0038] Figure 8 is a flowchart illustrating the flow of processes performed in the production system 300. The operator authentication unit 100 first authenticates the worker as an operator when the worker starts working with the industrial machine 3 (step SA01). Next, the operation reception unit 110 receives the worker's operation to the control device 1 (step SA02). The authorization processing unit 120 determines whether the authenticated operator has the authority to perform the received operation (step SA03). If the operator has the authority to perform the operation (step SA03: Yes), the operation execution unit 140 executes the operation (step SA11).

[0039] If the operator does not have the authority to perform the operation (Step SA03: No), the authorization processing unit 120 creates an operation permission request according to the operator's instructions (Step SA04), and the communication control unit 130 sends the created operation permission request to the terminal 8 (Step SA05).

[0040] When the communication control unit 880 of terminal 8 receives an operation permission request (step SA06), the operation permission determination unit 890 creates an operation permission response according to the instructions of the approver (step SA07). Then, the communication control unit 880 transmits the created operation permission response to the control device 1 (step SA08).

[0041] When the communication control unit 130 of the control device 1 receives an operation permission response (step SA09), the authorization processing unit 120 determines whether the operator is permitted to perform the operation based on the operation permission response (step SA10). If the operator is permitted to perform the operation (step SA10: Yes), the operation execution unit 140 performs the operation (step SA11). On the other hand, if the operator is not permitted to perform the operation (step SA10: No), the authorization processing unit 120 responds to the operator that the operation cannot be performed and discards the operation information (step SA12). Thereafter, steps SA02 to SA12 are repeated while the operator is performing the operation.

[0042] The production system 300 according to this embodiment, with the above configuration, enables the necessary approval process to be performed even when the manager of the industrial machine 3 is not near the control device 1, while reliably preventing the execution of operations not intended by the manager. Workers can request approval for an operation from a manager who is not present, and can execute the operation after receiving permission. In this production system, remote operation and information leakage can be prevented by not granting authority to operation requests sent to the control device 1 from an external computer via the network 5. Furthermore, unauthorized operations by workers can be prevented by not transmitting the approver's authentication information to the worker. Moreover, even in the OT domain where the manager's location is fluid, it becomes possible to perform necessary operations regardless of the manager's location or status, greatly improving convenience and minimizing machine downtime.

[0043] As one variation of the production system 300 according to this embodiment, the authorization processing unit 120 may record the time when it sent an operation permission request to the terminal 8. If a predetermined time has elapsed since the operation permission request was sent and no response regarding operation permission has been received, the system may respond to the operator that the operation requested cannot be performed and discard the operation information. Alternatively, the system may accept cancellation of the operation by the worker after sending the operation permission request but before receiving the response regarding operation permission. This configuration allows for flexible responses to the situations of the operator and approver, such as when the approver is busy and unable to respond, when the operation for which permission was requested is no longer needed, or when the approver is changed.

[0044] As another variation of the production system 300 according to this embodiment, the communication control unit 130 may restrict the transmission of operation permission requests depending on the connection status of the terminal 8 to the network 5. For example, the terminal information storage unit 220 manages the connection status of the terminal 8 used by each approver to the network 5. If the approver selected by the operator is connected to the network 5 via an external provider, the operator may be notified that the selected approver is unsuitable as a destination for operation permission requests and to change the settings for operation permission requests. By configuring it in this way, security that takes into account the connection status of the terminal 8 can be achieved.

[0045] As another modification of the production system 300 according to this embodiment, the communication control unit 130 may include predetermined code information in the operation permission request sent to the terminal 8. In this case, the communication control unit 130 stores the transmitted operation permission request. The communication control unit 880 of the terminal 8 includes the same code information as that contained in the operation permission request in the operation permission response corresponding to the operation permission request. The communication control unit 130 of the control device 1, upon receiving the operation permission response, determines whether the code information contained in the received operation permission response matches the code information contained in the operation permission request that was stored at the time of transmission. If they do not match, the received operation permission response is discarded. This configuration makes it possible to respond to attacks such as those in which operation permission information is intentionally created and sent.

[0046] As another variation of the production system 300 according to this embodiment, approver identification information may be omitted from the authorization information, and those deemed to have operational authority based on the authorization identification information may be treated as approvers. In factories and other similar settings, those who have operational authority may also act as approvers. In such cases, configuring the system to allow the selection of those with operational authority as approvers can save the storage area required for the authorization information storage unit 210, and also eliminate the need to separately set up approvers.

[0047] In another variation of the production system 300 according to this embodiment, the control device 1 may be incorporated as a component of the industrial machine 3. In this case, each function of the control device 1 is implemented as a component of the industrial machine 3.

[0048] [Second Embodiment] Figure 9 is a schematic block diagram showing the functions of the control device 1 and terminal 8 according to the second embodiment. The functions of the control device 1 and terminal 8 according to this embodiment are realized by the CPU 11 of the control device 1 and the CPU 811 of the terminal 8, as shown in Figure 1, executing system programs and controlling the operation of each part of the control device 1 and terminal 8.

[0049] The production system 300 according to this embodiment differs from the production system 300 according to the first disclosure in that the authentication information storage unit 200, the authorization information storage unit 210, and the terminal information storage unit 220, which were provided in the control device 1, are provided on a higher-level computer such as the fog computer 6.

[0050] The operator authentication unit 100, the authorization processing unit 120, and the communication control unit 130 of the control device 1 according to this embodiment access the fog computer 6 via the network 5 when accessing the authentication information stored in the authentication information storage unit 200, the authorization information stored in the authorization information storage unit 210, and the terminal information stored in the terminal information storage unit 220, respectively. When accessing the fog computer 6, known encryption and digital signature technologies are used for secure access. Otherwise, it is the same as the production system 300 according to the first disclosure.

[0051] The production system 300 according to this embodiment, with the above configuration, enables centralized management of authentication information stored in the authentication information storage unit 200, authorization information stored in the authorization information storage unit 210, and terminal information stored in the terminal information storage unit 220. Furthermore, this information can be shared and used by multiple control devices 1. As a result, the maintainability of the information that needs to be managed in the production system 300 is improved.

[0052] [Other embodiments] In the embodiment described above, functions other than the operation reception unit 110, the authorization processing unit 120, the communication control unit 130, and the operation execution unit 140 may be provided on a computer attached to the control device 1, or on another computer connected to the control device 1 via a network. For example, as illustrated in Figure 10, just as each storage unit is provided on a higher-level computer, the operator authentication unit 100 may also be provided on another computer or a higher-level computer instead of being placed on the control device 1. In this configuration, the control device 1 transmits information for identifying the acquired operator and information for authentication to the operator authentication unit 100 located on the other computer or a higher-level computer. Then, upon receiving a response indicating that the operator has been authenticated, the control device 1 can determine that the operator has been correctly authenticated.

[0053] This configuration makes it possible to build a flexible system that is tailored to the operating conditions of the control device 1 and industrial machine 3 at each manufacturing site.

[0054] The production system 300 according to each embodiment described above enables the necessary approval process to be carried out while reliably preventing the execution of operations unintended by the manager, even when the manager of the industrial machine 3 is not near the control device 1.

[0055] Although the present disclosure has been described in detail above, it is not limited to the individual embodiments described above. These embodiments can be added, replaced, modified, partially deleted, etc., in any way that does not depart from the gist of the present disclosure or from the intent of the present disclosure derived from the claims and their equivalents. Furthermore, these embodiments can be implemented in combination. For example, the order of operations and processes in the embodiments described above are given as examples only and are not limited thereto. The same applies when numerical values ​​or mathematical formulas are used in the description of the embodiments described above.

[0056] The following are additional notes regarding embodiments of this disclosure. (Note 1) A production system (300) according to one aspect of the present disclosure includes: a control device (1) that controls an industrial machine (3) used by an operator for work; a terminal (8) used by an approver, which is connected to the control device (1) via a network (5) and approves operations performed by the operator on the functions of the control device (1) and the industrial machine (3); an authorization information storage unit (210) that stores authorization information related to the operation; and a terminal information storage unit (220) that stores terminal information related to the terminal (8). The control device (1) includes: an operation reception unit (110) that receives operations from the operator; an authorization processing unit (120) that determines whether the operator is permitted to perform the operation based on the authorization information stored in the authorization information storage unit (210); and a first communication control unit (130) that controls communication between the control device (1) and the terminal (8) used by the approver based on the terminal information stored in the terminal information storage unit (220). The terminal (8) comprises an operation execution unit (140) that executes the operation based on the result of the determination by the authorization processing unit (120), and an operation feasibility determination unit (890) that determines whether the operator can perform the operation based on the operation of the approver, and the authorization processing unit (120) refers to the authorization information storage unit (210) to determine if the operator has the authority to perform the operation, or sends a request for approval of the operator's execution of the operation to the terminal (8) via the first communication control unit (130), and when a response is obtained indicating that the operator's operation has been approved in response to the request, the authorization processing unit (120) determines that the operator may perform the operation, and when a response is obtained indicating that the operator's operation has not been approved in response to the request, the authorization processing unit (120) determines that the operator cannot perform the operation. (Note 2) In other embodiments of the present disclosure, the production system (300) further determines that the authorization processing unit (120) cannot perform the operation if the operation was obtained via the network (5). (Note 3) In other embodiments of the present disclosure, the production system (300) further includes a terminal information storage unit (220) whose terminal information is updated when there is a change in the terminal (8) used by the approver. (Note 4) In other embodiments of the present disclosure, the production system (300) further determines that the authorization processing unit (120) cannot perform the operation if it has not received the response within a predetermined time after sending the request. (Note 5) In other aspects of the present disclosure, the production system (300) further includes an authorization processing unit (120) that notifies the operator of information regarding the connection status of the terminal (8) to which the request is to be sent. (Note 6) A production system (300) in another aspect of the present disclosure further includes, in which the first communication control unit (130) includes predetermined code information in the request to be transmitted to the terminal (8), and when a response to the request is received, discards the received response if the code information contained in the response does not match the response included in the request. (Note 7) A control device (1) according to one aspect of the present disclosure includes: an operation reception unit (110) that receives operations from an operator; an authorization processing unit (120) that determines whether the operator is permitted to perform the operation by referring to an authorization information storage unit (210) that stores authorization information related to the operation; a first communication control unit (130) that controls communication with the terminal (8) used by an approver by referring to a terminal information storage unit (220) that stores terminal information related to the terminal used by an approver who approves operations related to the functions of the control device (1) and the industrial machine (3) to be controlled; and based on the result of the determination by the authorization processing unit (120) The system includes an operation execution unit (140) that performs the aforementioned operation, and the authorization processing unit (120) refers to the authorization information storage unit (210) to determine if the operator has the authority to perform the aforementioned operation, or to send a request for approval of the operator's execution of the aforementioned operation to the terminal (8) via the first communication control unit (130). If a response is obtained indicating that the operator's execution of the aforementioned operation has been approved in response to the request, the system determines that the operator may perform the aforementioned operation. If a response is obtained indicating that the operator's execution of the aforementioned operation has not been approved in response to the request, the system determines that the operator cannot perform the aforementioned operation. [Explanation of symbols]

[0057] 1 Control device 3. Industrial Machinery 5 Network 6. Fog Computer 7 Cloud Server 8 devices 11 CPU 12 ROM 13 RAM 14 Non-volatile memory 15,17,18,20 Interface 22 buses 70 Display device 71 Input device 72 External equipment 100 Operator Authentication Unit 110 Operation reception unit 120 Permission Processing Unit 130 Communication Control Unit 140 Operation Execution Unit 200 Authentication Information Storage Unit 210 Authority Information Storage Unit 220 Terminal Information Storage Unit 300 Production Systems 811 CPU 812 ROM 813 RAM 814 Non-volatile memory 815, 817, 818, 820 Interface 822 Bus 870 Display device 871 Input device 872 External equipment 880 Communication Control Unit 890 Operation possibility determination section

Claims

1. A control device that controls the industrial machinery used by the operator for work, A terminal used by an approver who is connected to the control device via a network and approves the operation of the control device and the functions of the industrial machine by the operator, A permission information storage unit that stores permission information related to the aforementioned operation, A terminal information storage unit that stores terminal information relating to the aforementioned terminal, Equipped with, The control device is An operation reception unit that receives operations from the aforementioned operator, An authorization processing unit that determines whether the operator is permitted to perform the operation based on the authorization information stored in the authorization information storage unit, A first communication control unit controls communication with the terminal used by the approver based on the terminal information stored in the terminal information storage unit, An operation execution unit that performs the operation based on the result of the determination by the authority processing unit, Equipped with, The aforementioned terminal is A second communication control unit that controls communication with the control device, An operation feasibility determination unit that determines whether the operator can perform the operation based on the actions of the approver, Equipped with, The authorization processing unit, by referring to the authorization information storage unit, determines if the operator has the authority to perform the operation, or sends a request for approval of the operator's execution of the operation to the terminal via the first communication control unit, and if a response indicating that the operator's operation has been approved is received in response to the request, determines that the operator may perform the operation; and if a response indicating that the operator's operation has not been approved is received in response to the request, determines that the operator cannot perform the operation. Production system.

2. The authorization processing unit determines that if the operation was obtained via the network, the operation cannot be executed. The production system according to claim 1.

3. The terminal information stored in the terminal information storage unit is updated when there is a change in the terminal used by the approver. The production system according to claim 1.

4. The authorization processing unit determines that it cannot perform the operation if it fails to receive the response within a predetermined time after sending the request. The production system according to claim 1.

5. The authorization processing unit notifies the operator of information regarding the connection status to the terminal from which the request is to be sent. The production system according to claim 1.

6. The first communication control unit includes predetermined code information in the request to be transmitted to the terminal, and when it receives the response to the request, if the code information included in the response does not match the response included in the request, it discards the received response. The production system according to claim 1.

7. An operation reception unit that receives operations from the operator, An authorization processing unit that refers to an authorization information storage unit that stores authorization information related to the said operation and determines whether or not the operator is allowed to perform the said operation, A first communication control unit controls communication with the terminal used by the approver, by referring to a terminal information storage unit that stores terminal information relating to the terminal used by the approver who approves the operation of the control device and the industrial machine to be controlled by the operator, An operation execution unit that performs the operation based on the result of the determination by the authority processing unit, Equipped with, The authorization processing unit, by referring to the authorization information storage unit, determines if the operator has the authority to perform the operation, or sends a request for approval of the operator's execution of the operation to the terminal via the first communication control unit, and if a response indicating that the operator's operation has been approved is received in response to the request, determines that the operator may perform the operation; and if a response indicating that the operator's operation has not been approved is received in response to the request, determines that the operator cannot perform the operation. Control device.

Citation Information

Patent Citations

  • Control system and control method for industrial equipment

    JP2002163016A

  • Vehicle control system and qualification control program

    JP2008189261A

  • Operator identification system

    JP2018097524A

  • Industrial machine start-up control system, start-up control method, and program

    JP2019102046A