Information processing method and information processing device

The method allows for the generation and customization of secure control programs for household appliances by selecting and ordering functional blocks, addressing safety and development effort challenges in conventional systems.

JP7842269B2Active Publication Date: 2026-04-07PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Conventional control programs for household appliances and housing equipment are difficult to generate, customize, and update, and there is a risk of unsafe applications being developed by third parties due to lack of information sharing, leading to safety concerns and increased development effort.

Method used

An information processing method that generates control programs by selecting and ordering functional blocks for actuators and heaters, ensuring safety through pre-execution verification against predefined rules, allowing customization and distribution of safe applications.

Benefits of technology

Enables easy generation of a wide variety of secure control programs, reducing development effort while ensuring safety and confidentiality of manufacturer know-how.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007842269000001
    Figure 0007842269000001
  • Figure 0007842269000002
    Figure 0007842269000002
  • Figure 0007842269000003
    Figure 0007842269000003
Patent Text Reader

Abstract

To provide an information processing method capable of easily generating a wide variety of safe control programs.SOLUTION: An information processing method which is executed by a computer system includes: generating an application including M blocks by setting, according to input operation performed by an operator, an order of executing the M blocks for driving at least one of an actuator 22 and a heater 23 included in an apparatus 20 (Step S42); and consulting a rule that when one of predetermined in two or more blocks is executed, prohibits at least one of the remaining blocks included in the two or more blocks from not being executed, and when the rule applies to the M selected blocks included in the application, presenting an error to the operator (Step S51).SELECTED DRAWING: Figure 25
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing method for generating a control program for a device including an actuator and / or a heater, and the like.

Background Art

[0002] Conventionally, household appliances and housing equipment are controlled according to operating conditions (control programs) prepared in advance by manufacturers and the like. Patent Document 1 discloses a washing machine capable of setting washing operation conditions desired by a user.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the above conventional technology, a control program developed in advance by a manufacturer or the like of a product must be stored in the product in advance, and it is difficult to generate, customize, and update various and safe control programs.

[0005] Therefore, the present disclosure provides an information processing method and the like that can easily generate a variety of and safe control programs.

Means for Solving the Problems

[0006] An information processing method according to one aspect of the present disclosure is an information processing method performed by a computer system, which (a) generates an application including M blocks by setting the order in which each of M blocks (where M is an integer of 1 or more) for driving at least one of an actuator and a heater provided in a controlled device is executed in accordance with an input operation by an operator, and (b) presents an error to the operator if the M selected blocks included in the application fall under a rule that prohibits at least one of two or more predetermined blocks from not being executed when one of the two or more predetermined blocks is executed.

[0007] Furthermore, an information processing method according to one aspect of the present disclosure is an information processing method executed by a computer system, comprising: (a) selecting M blocks (M is an integer of 1 or more and less than or equal to N) as selected blocks from N blocks (N is an integer of 2 or more) for driving at least one actuator and heater provided in a controlled device, in response to an input operation by an operator; (b) generating an application including at least the M selected blocks by setting the order in which at least the M selected blocks are executed in response to an input operation by the operator; (c) modifying the application if the M selected blocks included in the application fall under the rule that prohibits at least one of the predetermined two or more blocks from not being executed when one of the predetermined two or more blocks is executed; and (d) outputting the modified application.

[0008] These comprehensive or specific embodiments may be implemented as a system, method, integrated circuit, computer program, or recording medium such as a computer-readable CD-ROM, or as any combination of a system, method, integrated circuit, computer program, and recording medium. [Effects of the Invention]

[0009] An information processing method relating to one aspect of this disclosure can easily generate a wide variety of secure control programs. [Brief explanation of the drawing]

[0010] [Figure 1] Figure 1 is a hardware configuration diagram of the system in Embodiment 1. [Figure 2A] Figure 2A is a hardware configuration diagram of the cloud server in Embodiment 1. [Figure 2B] Figure 2B is a hardware configuration diagram of the device in Embodiment 1. [Figure 2C] Figure 2C is a hardware configuration diagram of the terminal in Embodiment 1. [Figure 3] Figure 3 is a functional configuration diagram of the system in Embodiment 1. [Figure 4] Figure 4 shows an example of a block that defines the application in Embodiment 1. [Figure 5] Figure 5 shows multiple blocks for the washing machine in Embodiment 1. [Figure 6] Figure 6 shows multiple blocks for a microwave oven in Embodiment 1. [Figure 7] Figure 7 shows multiple blocks for the rice cooker in Embodiment 1. [Figure 8] Figure 8 is a sequence diagram of the system in Embodiment 1. [Figure 9] Figure 9 shows an example of a device database in Embodiment 1. [Figure 10] Figure 10 shows an example of an execution content declaration in Embodiment 1. [Figure 11] Figure 11 shows a flowchart of the pre-execution verification process in Embodiment 1. [Figure 12] Figure 12 shows an example of a rule database in Embodiment 1. [Figure 13] Figure 13 shows an example of application modification in Embodiment 1. [Figure 14] Figure 14 shows an example of application change in Embodiment 1. [Figure 15A] Figure 15A is a sequence diagram of the system in Variant 1 of Embodiment 1. [Figure 15B] Figure 15B is a sequence diagram of the system in Variant 2 of Embodiment 1. [Figure 15C] Figure 15C is a sequence diagram of the system in Variant 3 of Embodiment 1. [Figure 15D] Figure 15D is a sequence diagram of the system in Variant 4 of Embodiment 1. [Figure 15E] Figure 15E is a sequence diagram of the system in Variant 5 of Embodiment 1. [Figure 16] Figure 16 shows a flowchart of the pre-execution confirmation process in Embodiment 2. [Figure 17] Figure 17 shows a flowchart of the pre-execution confirmation process in Embodiment 3. [Figure 18] Figure 18 shows a flowchart of the pre-execution confirmation process in Embodiment 4. [Figure 19] Figure 19 is a diagram showing a configuration example of the information processing system in Embodiment 5. [Figure 20] Figure 20 is a diagram showing an example of information stored in each of the block database and the rule database in Embodiment 5. [Figure 21] Figure 21 is a diagram showing an example of a general rule included in the rule database in Embodiment 5. [Figure 22] Figure 22 is a sequence diagram of the information processing system in Embodiment 5. [Figure 23] Figure 23 is a flowchart showing the overall processing operation of the development tool in Embodiment 5. [Figure 24] Figure 24 is a flowchart showing an example of the automatic correction process of the layout in Embodiment 5. [Figure 25]Figure 25 is a flowchart showing an example of the error presentation process for placement in Embodiment 5. [Figure 26] Figure 26 shows an example of the sequence generation screen in Embodiment 5. [Figure 27] Figure 27 shows an example of how the block list is displayed in Embodiment 5. [Figure 28A] Figure 28A shows an example of the placement process of functional blocks and the automatic placement correction process in Embodiment 5. [Figure 28B] Figure 28B shows another example of the functional block placement process and the automatic placement correction process in Embodiment 5. [Figure 29] Figure 29 shows an example of the error presentation process for placement in Embodiment 5. [Figure 30] Figure 30 shows another example of the connection error notification process in Embodiment 5. [Figure 31] Figure 31 shows another example of the countermeasure presented in Embodiment 5. [Figure 32] Figure 32 shows yet another example of the countermeasure in Embodiment 5. [Figure 33] Figure 33 is a flowchart showing the processing operation of the development tool in a modified example of Embodiment 5. [Modes for carrying out the invention]

[0011] (Knowledge that forms the basis of this disclosure) The present inventors will now explain the circumstances leading to this disclosure. In household electrical appliances and the like that have actuators and / or heaters, open development environments are required in order to develop control programs that meet the diverse needs of users. In other words, there is a need for an environment that reduces the difficulty of developing control programs and allows third parties to easily participate in the development of control programs. In such an environment, for example, an apparel company could develop a control program for a washing machine to wash the clothes it sells.

[0012] Therefore, the inventors have investigated a mechanism that allows for the development of control programs while maintaining safety standards, using functional blocks that abstract the control of actuators and / or heaters included in the product, and that allows for the packaging of control programs consisting of combinations of multiple functional blocks and their distribution as applications. This enables the distribution of a wide variety of applications, making it possible to customize and update the product to meet the needs of a wider range of users. However, in such an environment, there is a possibility that dangerous applications (i.e., applications that cannot safely control the product) may be distributed, which would reduce the safety of the product.

[0013] For example, the programs included in household electrical appliances are embedded in devices that directly control actuators and / or heaters, and are expected to include a mix of programs developed by the manufacturer and programs developed by third parties. In this case, the manufacturer is unlikely to disclose all information about the household electrical appliances, including know-how, to third parties. For example, the parameters or timing for driving actuators and / or heaters are know-how related to the performance of the manufacturer's household electrical appliances. Therefore, because it could lead to a decline in competitiveness, the manufacturer is unlikely to open up its know-how to third parties so that they can freely operate the household electrical appliances.

[0014] Therefore, due to a lack of information on household electrical appliances, third parties may create applications that include control combinations or parameter ranges not anticipated by the manufacturer, i.e., applications whose safety cannot be guaranteed. Providing such applications to users is undesirable.

[0015] Furthermore, manufacturers of household electrical appliances and similar products may attempt to update users' lives by providing new control programs. However, developing a wide variety of new control programs requires a tremendous amount of effort, including parameter adjustment and hardware performance evaluation. Because household electrical appliances and similar products physically operate actuators and / or heaters, it is easy to predict that the effort required for program development, such as performance evaluation, will be greater compared to smartphone programs. However, in an era where on-demand development tailored to the individual lifestyles of each user is required, rather than mass production, it is necessary to develop a wide variety of control programs for household electrical appliances and similar products, just as it is for smartphone programs. Therefore, manufacturers must create a wide variety of applications that ensure product safety while reducing the enormous amount of effort required.

[0016] Furthermore, manufacturers may want to guarantee that their home appliances and other devices will operate safely even when using applications provided by third parties. In this case, it is desirable to reduce the amount of work required to actually run a wide variety of applications on home appliances and other devices to verify their safety.

[0017] Therefore, this disclosure provides a device that can more easily and safely execute a wide variety of applications defined by multiple functional blocks that drive actuators and / or heaters.

[0018] The embodiments will be described in detail below with reference to the drawings.

[0019] The embodiments described below are all general or specific examples. The numerical values, shapes, materials, components, arrangement and connection configurations of components, steps, and the order of steps shown in the following embodiments are examples only and are not intended to limit the scope of the claims.

[0020] Furthermore, the figures are not necessarily strictly accurate. In each figure, substantially identical components are denoted by the same reference numerals, and redundant explanations are omitted or simplified.

[0021] (Embodiment 1) [1.1 Hardware Configuration] The hardware configuration of System 1 in this embodiment will be described with reference to Figures 1 to 2C. Figure 1 is a hardware configuration diagram of System 1 in Embodiment 1. Figure 2A is a hardware configuration diagram of the cloud server 10 in Embodiment 1. Figure 2B is a hardware configuration diagram of the device 20 in Embodiment 1. Figure 2C is a hardware configuration diagram of the terminal 30 in Embodiment 1.

[0022] As shown in Figure 1, the system 1 in this embodiment comprises a cloud server 10, devices 20a to 20h used in facilities 2a to 2d, and terminals 30a to 30d. Facilities 2a to 2d are, for example, residences, but are not limited to these. Facilities 2a to 2d may be, for example, apartments, shops, offices, etc.

[0023] The cloud server 10 is a virtual server provided via a computer network (e.g., the Internet). The cloud server 10 is connected to devices 20a-20h and terminals 30a-30d via the computer network. A physical server may be used instead of the cloud server 10.

[0024] As shown in Figure 2A, the cloud server 10 virtually comprises a processor 11 and memory 12 connected to the processor 11. The processor 11 functions as a sequence manager and device manager, as described later, when instructions or software programs stored in memory 12 are executed.

[0025] Devices 20a to 20h are electrical machinery and equipment used in facilities 2a to 2d. Note that in Figure 1, devices 20c to 20h, used in facilities 2b to 2d, are not shown. In the following, devices 20a to 20h will be referred to as "device 20" unless otherwise specified.

[0026] The device 20 can be household electrical appliances (home appliances) and housing equipment, etc. Household electrical appliances (home appliances) and housing equipment, etc. are not limited to equipment used in a residence, but also include equipment used in a business. In this disclosure, household electrical appliances and housing equipment, etc. may be abbreviated as household electrical appliances, etc. Examples of household appliances include microwave ovens, rice cookers, blenders, electric ovens, electric toasters, electric kettles, hot plates, induction heating (IH) cookers, roasters, bakeries, electric pressure cookers, electric waterless cooking pots, multi-cookers, coffee makers, refrigerators, washing machines, dishwashers, vacuum cleaners, air conditioners, air purifiers, humidifiers, hair dryers, fans, and ion generators. Examples of housing equipment include electric shutters, electronic locks, and electric water heaters for bathtubs. The device 20 is not limited to these.

[0027] As shown in Figure 2B, the device 20 comprises a housing 21, an actuator 22, a heater 23, and a control unit 24. Note that the device 20 only needs to include at least one of the actuator 22 and the heater 23; it does not need to include both the actuator 22 and the heater 23.

[0028] The housing 21 houses the actuator 22, the heater 23, and the control unit 24. The housing 21 may also have an internal space for processing an object. For example, the washing tub of a washing machine, the heating chamber of a microwave oven, and the inner pot of a rice cooker are examples of internal spaces for processing an object.

[0029] The actuator 22 is a mechanical element that converts input energy into physical motion based on an electrical signal. Examples of actuators 22 include, but are not limited to, electric motors, hydraulic cylinders, and pneumatic actuators.

[0030] The heater 23 is an electric heater that converts electrical energy into thermal energy. The heater 23 heats the object by means of, for example, Joule heating, induction heating, and dielectric heating. For example, a nichrome wire, a coil, and a magnetron can be used as the heater 23.

[0031] Here, we will explain an example of why the apparatus 20 of this disclosure includes an actuator 22 and / or a heater 23. Consider a case where a manufacturer of household electrical appliances provides a third party with a development environment in which all parameters and drive combinations for driving the actuator 22 and the heater 23 can be freely controlled. In this case, the third party can create a program that controls the actuator 22 and / or heater 23 in a manner that deviates from the parameter range or drive limits of the actuator 22 and / or heater 23 that the manufacturer has assumed to be able to safely drive. In particular, driving the physically moving actuator 22 or the heater 23 that outputs thermal energy in a manner not assumed by the manufacturer presents a significant challenge in ensuring safety. Examples of driving in a manner not assumed by the manufacturer include high-speed rotation of an electric motor, which is an example of an actuator, and the supply of overcurrent to the heater 23. The inventors of this application aimed to avoid hindering the creation of an environment that can provide users with a wide variety of applications by excessively considering safety aspects. Therefore, the present disclosure focuses on the apparatus 20, specifically on the actuator 22 that moves physically, or the heater 23 that outputs thermal energy, with the aim of ensuring safety.

[0032] The control unit 24 is a controller that controls the actuator 22 and / or heater 23, and functions as a device described later. The control unit 24 is composed of, for example, an integrated circuit.

[0033] Terminals 30a to 30d are used in facilities 2a to 2d, respectively, and function as user interfaces. Note that in Figure 1, terminals 30b to 30d, which are used in facilities 2b to 2d, are not shown. In the following, terminals 30a to 30d will be referred to as terminal 30 when distinction between them is unnecessary.

[0034] Terminal 30 is connected to the cloud server 10 and the device 20 via a computer network and functions as a user interface (UI), as described later. A portable information terminal such as a smartphone or tablet computer can be used as Terminal 30. Terminal 30 may also be a terminal fixed to the wall, floor, or ceiling of facilities 2a to 2d. Furthermore, Terminal 30 may be included within the device 20. For example, Terminal 30 may be implemented as a display terminal having a built-in display in each of the devices 20a to 20h.

[0035] As shown in Figure 2C, the terminal 30 includes a display 31 and an input device 32. For example, a liquid crystal display and an organic EL display can be used as the display 31. For example, a touch panel, keyboard, mouse, and mechanical buttons can be used as the input device 32. Alternatively, a voice input device may be used as the input device 32. The display 31 and the input device 32 may be integrated as a touchscreen. Alternatively, a gesture input device may be used as the input device 32. A gesture input device, for example, includes a camera and a recognition unit. The camera captures an image including the gesture, and the recognition unit recognizes the gesture using the image.

[0036] [1.2 Functional Configuration] Next, the functional configuration of System 1 in this embodiment will be described with reference to Figure 3. Figure 3 is a functional configuration diagram of System 1 in Embodiment 1.

[0037] The cloud server 10 includes a sequence manager 100 and a device manager 200. Devices 20a to 20h each include devices 300a to 300h. Terminals 30a to 30d each include UIs 400a to 400d.

[0038] In the following, if it is not necessary to distinguish between devices 300a to 300h, it will be referred to as device 300. Similarly, if it is not necessary to distinguish between UI400a to 400d, it will be referred to as UI400.

[0039] The sequence manager 100 manages multiple applications. These applications are downloaded to the sequence manager 100 from the application distribution platform, for example, through user actions. Alternatively, applications included in the application distribution platform do not necessarily need to be downloaded to the sequence manager 100. In that case, information indicating that the applications included in the application distribution platform are associated with the sequence manager 100 may be recorded in the sequence manager 100's database. Details about the applications will be described later.

[0040] The device manager 200 has a database for managing multiple facilities 2a-2d and the devices 300 and UI 400 used in each of the facilities 2a-2d. The device manager 200 manages the devices 300 and UI 400 by recording device information and UI information associated with facilities 2a-2d in the database. The device information and UI information include, for example, control functions, drive functions, and operating status. For example, the device manager 200 can manage the operating status of device 300 and understand the operating schedule of device 300. The device manager 200 may also manage log information for device 300.

[0041] Note that such a database may be held by the sequence manager 100 instead of the device manager 200, or both the sequence manager 100 and the device manager 200 may hold it.

[0042] Device 300 has control and drive functions for the apparatus 20. Device 300 can drive the apparatus 20 according to instructions from the device manager 200.

[0043] UI400 provides information to the user and accepts input from the user.

[0044] Here, we will describe the application. In this embodiment, the application (hereinafter sometimes abbreviated as "app") means a control program defined by a plurality of functional blocks (hereinafter abbreviated as "blocks") that drive the actuator 22 and / or heater 23. Each of the plurality of blocks may include parameters for driving the actuator 22 or heater 23. Specifically, each of the plurality of blocks is an abstraction of the control of the actuator 22 or heater 23. In addition to the plurality of blocks that drive the actuator 22 and / or heater 23, the application may also include blocks that do not drive the actuator 22 and / or heater 23. An example of a block that does not drive the actuator 22 and / or heater 23 is an information display using the interface of device 300, an audio output using the buzzer of device 300, or turning on or off a lamp of device 300. Furthermore, the block may include conditions for starting the driving of the actuator 22 or heater 23. For example, an application including the first block and the second block will be described as an example. Here, when switching to the second block during the execution of the first block, the switch occurs when the start condition included in the second block is met. Furthermore, the block may also include a termination condition instead of a start condition. When switching to the second block during the execution of the first block, the switch occurs when the termination condition included in the first block is met.

[0045] Figure 4 shows an example of a block defining the application in Embodiment 1. Block 1000 shown in Figure 4 is a block that controls the agitation operation of the washing machine and includes parameters 1001 to 1006. Parameter 1001 includes information indicating the type of agitation (e.g., normal, dancing, swaying). Parameter 1001 can also be rephrased as indicating the type of function. Parameter 1002 includes a value indicating the rotation speed of the drum. Parameter 1002 can also be rephrased as indicating the intensity of the drive of the actuator 22 and / or heater 23. Parameter 1003 includes a value indicating the amount of water supplied into the drum as the water level after water supply. Parameter 1003 can also be rephrased as indicating the state after the actuator 22 and / or heater 23 are driven. Parameter 1004 includes a value indicating the on / off state of the circulation pump. Parameter 1004 can also be rephrased as indicating whether or not to drive the actuator 22 and / or heater 23. Parameter 1005 includes information indicating the stirring interval in stages (e.g., short, medium, long). Parameter 1006 includes a value indicating the stirring time.

[0046] Multiple such blocks are used to define an application. For example, multiple blocks like those shown in Figures 5 to 7 are used.

[0047] Figure 5 shows multiple blocks for a washing machine in Embodiment 1. Figure 6 shows multiple blocks for a microwave oven in Embodiment 1. Figure 7 shows multiple blocks for a rice cooker in Embodiment 1. Note that the multiple blocks shown in Figures 5 to 7 are illustrative, and the blocks for the washing machine, microwave oven, and rice cooker are not limited to these. For example, the multiple blocks may be hierarchically structured by levels of abstraction.

[0048] For example, you might change the level of abstraction between the manufacturer-facing hierarchy and the non-manufacturer-facing hierarchy. Examples of non-manufacturer-facing hierarchies include hierarchies for other manufacturers and hierarchies for third parties.

[0049] In this case, the hierarchy for manufacturers is less abstract than the hierarchy for non-manufacturers. A lower level of abstraction means that the control is closer to the parameters that drive the actuators and heaters.

[0050] On the other hand, the manufacturer can enable non-manufacturers to develop applications by providing blocks with the minimum level of abstraction necessary to guarantee know-how and safety. The manufacturer can then enable more people to develop applications by providing general users with blocks with an even higher level of abstraction. An even higher level of abstraction corresponds to blocks defined in terms that general users can understand even without specialized knowledge. Terms that can be understood without specialized knowledge correspond to the functions of household electrical appliances, for example. Specifically, if "plenty" is selected as the water volume parameter in the "wash" block for a washing machine, changes will be made in one concrete layer, such as raising the water level parameter in the water supply block from 60 mm to 100 mm and lowering the rotation speed parameter in the agitation block from 120 rpm to 100 rpm. As described above, rearranging blocks and changing parameters at a higher level of abstraction can be achieved with blocks at a lower level of abstraction. In addition, multiple blocks can be defined for devices other than washing machines, microwave ovens, and rice cookers, similar to Figures 5 to 7. These blocks allow for flexible application development through reconfiguration and parameter adjustment, while ensuring safety and confidentiality regarding the operation of actuators and heaters.

[0051] Furthermore, by providing other manufacturers with blocks that have the minimum level of abstraction necessary to guarantee know-how and safety, other manufacturers can independently define and implement blocks with an even higher level of concretization to realize the provided blocks. This allows each manufacturer to guarantee their own know-how and safety while enabling third parties who only develop the applications to freely develop applications related to the operation of each manufacturer's actuators and heaters.

[0052] At this time, other manufacturers may not develop blocks with a higher level of detail that match the minimum level of abstraction required to guarantee the know-how and safety provided by the manufacturer. Instead, they may return an error and inform the app developer and user that the blocks provided by the manufacturer are unusable or operate within a limited parameter range. Specifically, if "high speed" is selected as the motor rotation parameter in the "agitation" block for a washing machine, and the manufacturer's washing machine can achieve a parameter of 150 rpm to realize "high speed," but another manufacturer's washing machine can only rotate up to 120 rpm due to the characteristics of its motor, the app developer or user may be informed of an error or that it will operate at the limit of 120 rpm.

[0053] [1.3 Processing] Next, the processing of System 1 configured as described above will be explained with reference to Figure 8. Figure 8 is a sequence diagram of System 1 in Embodiment 1.

[0054] [1.3.1 Preparation Phase F100] First, let's explain the preparation phase F100.

[0055] (Step S110) The sequence manager 100 transmits sequence manager information to the device manager 200. This transmission of sequence manager information is performed, for example, by a command from the system administrator. The device manager 200 registers the received sequence manager information in, for example, the sequence manager database. Note that if the sequence manager information is already registered in the sequence manager database, this step may be skipped.

[0056] The sequence manager information includes, for example, the identifier and / or address of sequence manager 100 (e.g., URL (Uniform Resource Locator), IP (Internet Protocol) address, etc.). Furthermore, the sequence manager information may include any other information.

[0057] (Step S112) Device 300 sends device information 1101 to device manager 200. This transmission of device information 1101 occurs, for example, when device 300 is connected to a computer network. Device manager 200 registers the received device information 1101 in device database 1100. Note that if device information 1101 is already registered in device database 1100, this step may be skipped.

[0058] Alternatively, the device information 1101 may be sent to the UI400 and then registered with the device manager 200 via the UI400.

[0059] Device information 1101 includes the identifier and / or address of device 300. Furthermore, device information 1101 may include arbitrary information. Figure 9 shows an example of a device database in Embodiment 1. The device database 1100 in Figure 9 has multiple device information entries, including device information 1101. Each device information entry includes a device ID, address, type, manufacturer name, model number, actuator / heater, and degradation level. The actuator / heater is the identification information of the actuator 22 and / or heater 23 that constitute device 300. The degradation level is an example of degradation information indicating whether the actuator 22 and / or heater 23 that constitute device 300 are degraded or not. Here, a higher value indicates greater degradation. Device information 1101 may include information on executable blocks. Information on executable blocks may be information that associates whether the blocks included in the database are executable or not, or it may be information only on executable blocks. Furthermore, whether or not a block is executable can be determined in advance based on information such as actuators / heaters included in the device information 1101.

[0060] Furthermore, device information 1101 may include information that can identify facilities 2a to 2d.

[0061] (Step S114) UI400 transmits UI information to device manager 200. This transmission of UI information is performed, for example, by user instruction. Device manager 200 registers the received UI information in a UI database, for example. Note that this step may be skipped if the UI information is already registered in the UI database.

[0062] UI information includes, for example, the identifier and / or address of UI400. Furthermore, UI information may include any other information.

[0063] Furthermore, the UI information may include information that can identify facilities 2a to 2d.

[0064] Through the above process, the sequence manager 100, device manager 200, device 300, and UI400 can be linked to each other and establish connections. This completes the preparation phase F100.

[0065] [1.3.2 Pre-application execution phase F200] Next, we will explain the pre-application execution phase F200. Prior to the pre-application execution phase F200, the application is downloaded from the application distribution platform to the sequence manager 100 according to instructions from the user via the UI400. With the application downloaded to the sequence manager 100 in this state, the following processes are performed.

[0066] (Step S210) The UI400 receives an application execution request from the user and sends the application execution request, which includes the application's identification information, to the sequence manager 100. For example, the user selects an application from among several applications downloaded to the sequence manager 100 via the UI400 and instructs the sequence manager 100 to execute the selected application.

[0067] Furthermore, the application execution request sent from UI400 to sequence manager 100 is sent together with information that can identify facilities 2a to 2d.

[0068] Furthermore, the application execution request does not necessarily have to be explicitly received from the user. For example, the application execution request may be automatically sent to the sequence manager 100 based on the detection result after detecting the user's actions or state.

[0069] (Step S212) The sequence manager 100 sends an execution declaration for the application identified by the application execution request to the device manager 200. The execution declaration includes information on multiple blocks that define the application to be executed and information that can identify facilities 2a to 2d.

[0070] Figure 10 shows an example of an execution declaration in Embodiment 1. Figure 10 shows an execution declaration 1200 for an application defined by combining multiple blocks for a washing machine as shown in Figure 5. The execution declaration 1200 includes multiple blocks 1201, information 1202 about the devices required for the execution of each block 1201, and information 1203 about the order in which each block 1201 is executed.

[0071] Note that the execution declaration 1200 does not need to include device information 1202. In that case, the device manager 200 needs to search for a device capable of executing the block in the facility indicated by the received facility information from the information of multiple blocks 1201 and then assign the device.

[0072] In Figure 10, the device information 1202 shows the model number of device 300, but is not limited to this. The device information 1202 can be any information that can indicate the conditions for device 300 that can be assigned to a block. For example, the device information 1202 may include multiple model numbers, or it may include only the type of device, intended use, location, or any combination thereof.

[0073] (Step S214) The device manager 200 assigns a device 300 associated with the device manager 200 to each block included in the execution declaration, based on information that can identify facilities 2a to 2d. For example, the device manager 200 assigns to each of the multiple blocks 1201 shown in Figure 10 a device DEV001 with model number WM-0001, which is registered in the device database 1100 in Figure 9 as connected to the facility indicated by the received facility information. Note that if the operating status of a device 300 or its connection status to the cloud is managed, the assignment of an operating device 300 may be prohibited.

[0074] Furthermore, if, for example, the multiple blocks shown in Figure 10 are not registered as connected to the facility indicated by the received facility information, that is, if the target device does not exist at the facility, the device manager 200 notifies the sequence manager 100 that the execution of the declared application is not possible.

[0075] (Step S215) The device manager 200 notifies the device 300 of the device assignment results. As a result, multiple blocks included in the application are sent to the respective assigned devices 300.

[0076] (Step S216) Device 300 verifies the block before executing it. That is, before executing the block, device 300 checks whether any problems will occur in device 300 when the block is executed. For example, device 300 checks for safety and / or efficiency issues.

[0077] Then, device 300 modifies the block based on the verification results. This corrects the block so that the problem does not occur.

[0078] This pre-execution verification process will be explained in more detail with reference to Figure 11. Figure 11 shows a flowchart of the pre-execution verification process in Embodiment 1.

[0079] (Step S2165) Device 300 retrieves rules corresponding to the application. Here, the rules prohibit the execution of at least one of two or more predetermined blocks if one of those blocks is executed. For example, device 300 retrieves a combination of two or more predetermined blocks by referring to a rule database. The rule database may be contained in device 300, for example, or in sequence manager 100 or device manager 200.

[0080] One rule could be, for example, one that prohibits the execution of the first block before the execution of the second block. More specifically, one rule could be, for example, one that prohibits the execution of the first block from the start of the application until before the execution of the second block. Such a first block could be, for example, a block that sets the environment so that the second block can be executed. Specifically, as the first block, a drainage block could be used to create a water-restricted environment before the execution of the second block (for example, a dewatering block).

[0081] Furthermore, rules can be used, for example, to prohibit the execution of a third block after the execution of a second block. More specifically, a rule can be used, for example, to prohibit the execution of a third block between the execution of a second block and the termination of the application. Such a third block could be, for example, a block for returning the environment changed by the execution of the second block back to the environment before the execution of the second block. Specifically, as the third block, a fan block could be used to return the temperature that rose due to the execution of the second block (for example, a drying block) back to the temperature before the execution of the second block.

[0082] Figure 12 shows an example of a rule database in Embodiment 1. Rule database 1300 in Figure 12 has rules 1301 and 1302 registered. Each of rules 1301 and 1302 has information on a predetermined combination of two or more blocks. For example, rule 1301 indicates that it is prohibited for a drain block not to be executed before a dewatering block is executed. Also, for example, rule 1302 indicates that it is prohibited for a blowing block not to be executed after a drying block.

[0083] Such predetermined combinations of two or more blocks include, for example, combinations of blocks that prevent the internal space of the housing 21, the actuator 22, or the heater 23 from reaching the tolerance temperature. Tolerance temperature refers to the rated temperature, which indicates the maximum temperature that can be allowed. Therefore, if the actuator 22 or the heater 23 is driven using the predetermined combination of two or more blocks, the temperature of the internal space of the housing 21, the actuator 22, or the heater 23 will not reach an unacceptable temperature. In other words, the rule is to ensure that the predetermined combination of two or more blocks is executed in order to prevent the internal space of the housing 21, the actuator 22, or the heater 23 from reaching the tolerance temperature.

[0084] Note that in Figure 12, rules 1301 and 1302 each represent a combination of two blocks, but are not limited to this. For example, in addition to a combination of two blocks, a rule may also represent a range of parameters for at least one of those two blocks. Furthermore, the rules define a wide range of blocks that can be used for the development of a diverse range of applications.

[0085] For example, the rules for safely operating the actuator 22 or heater 23 may change depending on the environment of the device 300, such as the internal space of the housing 21, and the rules may not depend solely on the performance of the actuator 22 or heater 23 itself. Therefore, in order to operate safely in any environment, the rules will have a high weight on safety considerations, reducing the scope for developing a wide variety of applications. For this reason, the rules may be associated with information such as the device 300, independently of the application. By using such rules, it is possible to achieve both safety and the development of a wide variety of applications.

[0086] The rule relates to the range in which the actuator 22 or heater 23 can be safely operated. The range in which it can be safely operated may be a range that takes into account the block's start or end conditions. Consider a first block and a second block that is executed after the first block as an example. A rule may be set to assume that executing the first block until the start condition of the second block is reached places a load that affects the safety of the actuator 22 or heater 23. In other words, the rule depends on the performance of the actuator 22 or heater 23, the block's start or end conditions, etc.

[0087] Each of rules 1301 and 1302 further includes a type and a manufacturer's name. This allows device 300 to retrieve rules from the rule database 1300 that correspond to the actuator 22 or heater 23 driven by the block. For example, device 300 retrieves rules 1301 and 1302 for WM-0001 by referring to the rule database 1300 in Figure 12.

[0088] (Step S2166) Device 300 determines whether multiple blocks included in the application fall under the rule.

[0089] For example, if a rule prohibits the execution of the first block before the execution of the second block, and the application includes the second block but does not include the first block before it, then device 300 determines that multiple blocks included in the application fall under the rule. Specifically, if the application includes the second block but does not include the first block, then device 300 determines that multiple blocks included in the application fall under the rule. Also, if the application includes the second block and includes the first block only after it, then device 300 determines that multiple blocks included in the application fall under the rule. On the other hand, if the application includes the second block and includes the first block before it, then device 300 determines that multiple blocks included in the application do not fall under the rule. Also, if the application does not include either the first or second block, then device 300 determines that multiple blocks included in the application do not fall under the rule. Furthermore, if the application includes the first block but does not include the second block, device 300 determines that the multiple blocks included in the application do not fall under the rule.

[0090] For example, if a rule prohibits the execution of a third block after the execution of a second block, and the application includes a second block but does not include a third block after it, then device 300 determines that the multiple blocks included in the application comply with the rule. Specifically, if the application includes a second block but does not include a third block, then device 300 determines that the multiple blocks included in the application comply with the rule. Also, if the application includes a second block and includes a third block only before it, then device 300 determines that the multiple blocks included in the application comply with the rule. On the other hand, if the application includes a second block and includes a third block after it, then device 300 determines that the multiple blocks included in the application do not comply with the rule. Also, if the application does not include either a second or a third block, then device 300 determines that the multiple blocks included in the application do not comply with the rule. Furthermore, if the application includes a third block but does not include a second block, device 300 determines that the multiple blocks included in the application do not fall under the rules.

[0091] If it is determined that multiple blocks do not meet the rule (No in S2166), device 300 skips the subsequent step S2167 and terminates the pre-execution verification process. On the other hand, if it is determined that multiple blocks meet the rule (Yes in S2166), device 300 proceeds to the next step S2167.

[0092] (Step S2167) Device 300 modifies the application and terminates the pre-execution verification process. Modifying the application means (i) adding a new block to a set of blocks, (ii) changing the order of blocks, (iii) deleting any of blocks, or (iv) any combination thereof. These methods of modifying the application may be defined in rules.

[0093] Specific examples of such application changes will be explained with reference to Figures 13 and 14.

[0094] Figure 13 shows an example of a modification to the application in Embodiment 1. In Figure 13, a drain block (first block) is added before the spin-drying block (second block). This allows water to be drained from inside the washing machine before the spin-drying block is executed, enabling safe operation of the actuator 22 during spin-drying.

[0095] Figure 14 shows an example of application modification in Embodiment 1. In Figure 14, a fan block (third block) is added after the drying block (second block). This allows the fan to lower the temperature of the washing machine after it has risen due to drying, thereby preventing the user from getting burned and improving the safety of the washing machine.

[0096] While this explanation focused on modifying the application for washing machines, the same method can be used to modify applications for other devices.

[0097] For example, if an application for a rice cooker includes a steaming block (second block) that utilizes the steam function, and does not include a steam heating block (first block) before the steaming block, the steam heating block may be added 10 minutes before the steaming block is executed. This allows the steam heater to be heated before the steaming block is executed, enabling smooth steam irradiation when the steaming block is executed.

[0098] For example, if an application for a microwave oven includes a steaming block (second block) and does not include a steam heating block (first block) before the steaming block, the steam heating block may be added 10 minutes before the steaming block is executed. This allows the steam heater to be heated before the steaming block is executed, enabling smooth steam irradiation during the steaming block's execution. Also, if an application for a microwave oven includes an oven block (second block) and does not include a fan block (third block) after the oven block, the fan block may be added after the oven block. This allows the fan block to cool the oven cavity, which has become very hot after the oven block is executed, thus speeding up the execution of the next block.

[0099] (Step S217) Device 300 sends the results of the pre-execution check to Device Manager 200. If a block has been modified, the modified block may also be sent to Device Manager 200.

[0100] (Step S218) The device manager 200 returns the device assignment results to the sequence manager 100. Additionally, if blocks have been modified during pre-execution verification, the application containing the modified blocks may be sent to the sequence manager 100.

[0101] (Step S220) The sequence manager 100 receives the assignment result notification from the device manager 200 and notifies the user via the UI 400 that it is ready to run.

[0102] (Step S222) UI400 displays a list of devices on which the application will run, and also displays a graphical user interface (GUI) for receiving user input to confirm application execution. UI400 may also accept user requests to change device assignments. Furthermore, UI400 does not necessarily need to display a list of devices.

[0103] (Step S224) UI400 receives confirmation input from the user and sends an application start command to device manager 200. Device manager 200 forwards the application start command to sequence manager 100.

[0104] Steps S220, S222, and S224 provide the user with additional information before the application is executed, but they may be omitted as they could increase the user's workload.

[0105] This completes the pre-application execution phase F200.

[0106] [1.3.3 Application Execution Phase F300] Next, we will explain the application execution phase F300.

[0107] (Step S310) Upon receiving an application start command, the sequence manager 100 selects the first block (the first block) from among the multiple blocks included in the application. Then, the sequence manager 100 sends an execution command for the selected first block to the device manager 200.

[0108] Furthermore, if multiple blocks are to be operated sequentially, the sequence manager 100 may send the execution instructions for multiple blocks together to the device manager 200.

[0109] Based on the execution instructions for the first block received from the sequence manager 100, the device manager 200 sends the execution instructions for the first block to the device 300 assigned to the first block.

[0110] (Step S312) Upon receiving the execution instruction for the first block, Device Manager 200 updates the schedule (scheduled usage time) for each device.

[0111] (Step S314) Device 300 receives an instruction to execute the first block and executes the first block.

[0112] (Step S316) Device 300 sends a completion notification to device manager 200 when the execution of the first block is complete. If an error occurs during the execution of the first block, device 300 may also send error information to device manager 200. In addition, device 300 may send event information to device manager 200 during the execution of the first block. Event information may include, but is not limited to, sensor output values ​​or equipment operations. Device manager 200 forwards the completion notification and / or various information received from device 300 to sequence manager 100.

[0113] (Step S318) The sequence manager 100 receives a notification that the first block is complete, updates the application's progress, and selects the next block (the second block). The sequence manager 100 also executes a corresponding process (e.g., return to the previous block, return to the first block, wait, etc.) if it receives error information. Information regarding the error response process may be stored in the sequence manager 100 beforehand, or it may be received from the user via the UI 400. Furthermore, the sequence manager 100 executes a corresponding process if it receives event information. For example, if the event information includes the output value of the water level sensor, the sequence manager 100 updates the water level parameter to display the water level included in the currently executing block.

[0114] (Step S320) The sequence manager 100 sends an execution instruction for the selected second block to the device manager 200.

[0115] The execution instruction in the second block may be for the same device as the execution instruction in the first block (S310), or it may be for a different device.

[0116] Note that, similar to the execution instructions for the first block, the execution instructions for the second block may be sent to the device manager 200 as a bundle of execution instructions for multiple blocks.

[0117] The subsequent processing is the same as the processing for the first block (S312-S318), so the illustrations and explanations are omitted. The blocks included in the application are executed in order, and when the execution of the last block is completed, the application execution phase F300 ends.

[0118] Note that, while block execution is instructed one by one in this example, it is not limited to this. For example, the execution of multiple blocks assigned to the same device may be instructed together. In that case, it may be necessary to check in advance whether each block meets the parameter range for function execution, or to download the corresponding block to the device before execution. Alternatively, for example, block execution instructions may be issued to multiple devices individually.

[0119] [1.4 Effects, etc.] As described above, the application, including blocks, and the rule database provide an environment in which a wide variety of applications can be developed, and in that environment, it is possible to safely drive the physically moving actuator 22 or the heater 23 that outputs thermal energy for the application that has been freely developed. In other words, it provides an environment in which applications can be freely developed, and also provides functions to ensure safety independently of the application. As a result, for example, it becomes possible to create a wide variety of applications with a high degree of freedom and to develop a rule database to ensure safety in parallel, making it possible to develop a wide variety of applications at an early stage.

[0120] Furthermore, even after the application has been released, it is possible to modify the rule database to create an application with enhanced security. Also, even if improvements are needed in situations that the manufacturer did not anticipate, the rule database is defined independently of the application itself. By updating the rule database, it becomes possible to address all applications without changing the diverse range of applications themselves.

[0121] One possible approach is to maintain an error handling rule database by detecting the state of the application when it is executed, without modifying the application itself. However, this approach would always deal with errors after they occur, meaning it would be acceptable to allow situations that put a load on the appliance or where safety cannot be guaranteed. Therefore, by maintaining a rule database independently of the application and modifying the application's content by referring to the rule data, safety can be ensured.

[0122] The apparatus 20 in this embodiment includes at least one actuator 22 and a heater 23, and a control unit 24 that controls at least one of the actuator 22 and the heater 23. The control unit 24 obtains an application defined by a plurality of blocks that drive at least one of the actuator 22 and the heater 23, and refers to a rule that prohibits at least one of the remaining two or more blocks from being executed when one of the two or more blocks is executed. If the plurality of blocks included in the application meet the rule, the control unit 24 modifies the application and drives at least one of the actuator 22 and the heater 23 based on the modified application.

[0123] According to this, the actuator 22 and / or heater 23 can be driven based on an application defined by multiple blocks. Therefore, it becomes possible to develop applications using blocks that abstract the control of the device 20, allowing not only the manufacturer but also third parties to develop a wide variety of applications, and these applications can be easily executed on the device 20. Furthermore, if the application falls under a rule that prohibits the execution of at least one of two or more predetermined blocks when one of those blocks is executed, the application can be modified before the actuator 22 and / or heater 23 are driven based on the application. Therefore, it can be ensured that one of two or more predetermined blocks is executed in combination with at least one of the other two or more predetermined blocks. In other words, even if an application developer mistakenly instructs the execution of a block that is not permitted to be executed alone, it can be prevented from executing an application that cannot safely control the device 20. Therefore, even if an application developer creates an application that prioritizes user convenience over ensuring the safety of the actuator 22 and / or heater 23, the safety of the device 20 controlled by the application can be improved.

[0124] For example, in the device 20 of this embodiment, the control unit 24 may modify the application by (a) adding a new block to a plurality of blocks, (b) changing the order of a plurality of blocks, or (c) deleting any of the plurality of blocks.

[0125] More specifically, for example, in the device 20 of this embodiment, the application includes information on the order in which each of a plurality of blocks is executed, the predetermined two or more blocks include a first block and a second block, the rule prohibits the first block from being executed before the second block, and the control unit 24 may modify the application by adding the first block before the second block if the application includes the second block and does not include the first block before the second block.

[0126] For example, in the device 20 of this embodiment, the application includes information on the order in which each of a plurality of blocks is executed, the predetermined two or more blocks include a first block and a second block, the rule prohibits the first block from being executed before the second block, and the control unit 24 may modify the application by changing the order of the first block to be before the order of the second block if the application includes a first block and a second block and does not include a first block before the second block.

[0127] For example, in the device 20 of this embodiment, the application includes information on the order in which each of a plurality of blocks is executed, a predetermined two or more blocks include a first block and a second block, the rule prohibits the first block from being executed before the second block, and the control unit 24 may modify the application by deleting the second block if the application includes the second block and does not include the first block before the second block.

[0128] According to these methods, it is possible to ensure that the first block is executed before the second block by adding a new block, changing the order of blocks, or deleting blocks before the application is executed. Therefore, application developers can freely develop applications with a lower priority on ensuring the safe operation of the actuator 22 and heater 23. Furthermore, developers of the software incorporated into the device 20 that controls the actuator 22 and heater 23 can permit the execution of blocks without having to check the safety of each application every time.

[0129] For example, in the device 20 of this embodiment, the application includes information on the order in which each of a plurality of blocks is executed, the predetermined two or more blocks include a second block and a third block, the rule prohibits the execution of the third block after the execution of the second block, and the control unit 24 may modify the application by adding a third block after the second block if the application includes a second block and does not include a third block after the second block.

[0130] For example, in the device 20 of this embodiment, the application includes information on the order in which each of a plurality of blocks is executed, the predetermined two or more blocks include a second block and a third block, the rule prohibits the execution of the third block after the execution of the second block, and the control unit 24 may modify the application by changing the order of the third block to be after the order of the second block if the application includes a second block and a third block and does not include a third block after the second block.

[0131] For example, in the device 20 of this embodiment, the application includes information on the order in which each of a plurality of blocks is executed, the predetermined two or more blocks include a second block and a third block, the rule prohibits the execution of the third block after the execution of the second block, and the control unit 24 may modify the application by deleting the second block if the application includes the second block and does not include the third block after the second block.

[0132] For example, in the device 20 of this embodiment, if the application includes information on multiple blocks and the order in which each block is executed, and the rule includes information that at least one block among the multiple blocks cannot be executed, the developer may be presented with error information indicating that the application cannot be developed or information on the block that cannot be executed.

[0133] According to these methods, it is possible to ensure that a third block is executed after a second block by adding a new block, changing the order of blocks, or deleting blocks before the application is executed. Therefore, application developers can freely develop applications with a lower priority on ensuring the safe operation of the actuator 22 and heater 23. Furthermore, developers of the software incorporated into the device 20 that controls the actuator 22 and heater 23 can permit the execution of blocks without having to check the safety of each application every time.

[0134] For example, in the apparatus 20 of this embodiment, the rule may be a rule to ensure that two or more predetermined blocks are executed in combination in order to prevent at least one of the actuator 22 and the heater 23 from reaching its durability temperature.

[0135] According to this, it is possible to prevent the actuator 22 and / or heater 23 from reaching their tolerable temperature when the application is executed, thereby improving the safety of the device 20 controlled by the application.

[0136] For example, the apparatus 20 in this embodiment may include a housing 21 having an internal space, and the first rule may be a rule to ensure that two or more predetermined blocks are combined and executed in order to prevent the internal space from reaching a durable temperature.

[0137] According to this, it is possible to suppress the internal space of the enclosure 21 from reaching the tolerance temperature when the application is executed, thereby improving the safety of the device 20 controlled by the application.

[0138] (Modified version of Embodiment 1) In the above embodiment 1, the processing of system 1 was explained with reference to Figure 8, but the processing flow is not limited thereto. In particular, the timing of the pre-execution check (S216) that is explained in detail and the main module involved are not limited thereto. Therefore, several modifications of the sequence diagram of system 1 will be specifically explained with reference to Figures 15A to 15E.

[0139] Figure 15A is a sequence diagram of System 1 in Modification 1 of Embodiment 1. In Figure 15A, pre-execution confirmation (S216) is performed by device 300 immediately before device 300 receives an execution instruction (S310) and executes the block (S314).

[0140] This allows the software incorporated into device 300 to have a simple configuration in which pre-execution checks are performed immediately before execution of a block. In other words, steps S215 and S217 can be omitted. As a result, it becomes unnecessary to incorporate functions and communication APIs for performing those processes into device 300, and it becomes possible to reduce the memory usage of the microcontroller mounted on device 300.

[0141] Furthermore, the results of the pre-execution check may be notified to the device manager 200 and / or UI400. For example, if a parameter change or a block execution stop instruction is issued as a result of the pre-execution check, the check results may be notified to the device manager 200 or UI400.

[0142] Figure 15B is a sequence diagram of System 1 in Modification 2 of Embodiment 1. In Figure 15B, the pre-execution check (S216) is performed by the Device Manager 200 when the Device Manager 200 notifies the allocation result (S218).

[0143] This means that the software incorporated into device 300 does not need to include the pre-execution verification (S216) function. Therefore, the memory usage of device 300 can be reduced, leading to a reduction in the cost of device 300.

[0144] Furthermore, in the above embodiment 1, the block execution (S314) by device 300 was described as being performed by instructions from sequence manager 100 implemented on cloud server 10, but the form in which block execution (S314) is performed is not limited to this.

[0145] For example, the notification content from the sequence manager 100 may be stored in the memory of the device 300, and the block may be executed by direct instruction from the user through the UI of the device 20 or the UI 400 of the terminal 30. In other words, the application may be downloaded to the device, and the user may execute the application at any time.

[0146] Figure 15C is a sequence diagram of System 1 in Modification 3 of Embodiment 1. In Figure 15C, during the application execution phase F300, the sequence manager 100 notifies the device 300 of one or more blocks to be executed by the device 300 (S310C). The device 300 then saves the one or more notified blocks to memory (S311C).

[0147] Subsequently, device 300 receives instructions from the user to execute one or more saved blocks (S312C), and executes one or more blocks in order from the first block (S314).

[0148] As described above, by saving the block to device 300, device 300 can be controlled without communication between device manager 200 and device 300. This reduces the risk of device 300 stopping or experiencing delays due to unstable communication between cloud server 10 and device 20. Therefore, this modified version is more effective in environments where communication with cloud server 10 is unreliable, and / or in devices 300 where device stopping or delays during application execution are unacceptable.

[0149] In Modification Example 3, as in Embodiment 1, the pre-execution check (S216) is of significant importance, but the timing of the pre-execution check (S216) and the main module involved are not limited to those shown in Figure 15C. In other words, Modification Example 3 may be combined with Modification Example 1 or 2.

[0150] Figure 15D is a sequence diagram of System 1 in Modification 4 of Embodiment 1. Modification 4 corresponds to a combination of Modification 1 and Modification 3. In Modification 4, as shown in Figure 15D, pre-execution confirmation (S216) is performed by device 300 immediately before device 300 receives an execution instruction (S312C) and executes the block (S314).

[0151] If a block is downloaded to device 300 and the user executes it at their discretion, there is a high probability that the timing of the block download and execution will be significantly different. In other words, the block may be executed several days, months, or even years after it is downloaded to device 300. In such cases, the degradation level of device 300 may change between the time the block is downloaded and the time it is executed. Therefore, for device 300, where the execution of the block is affected by the degradation level, a pre-execution check is performed by device 300 immediately before the block is executed, enabling a pre-execution check that is appropriate to the degradation level.

[0152] Figure 15E is a sequence diagram of System 1 in Modification 5 of Embodiment 1. Modification 5 corresponds to a combination of Modification 2 and Modification 3. In Modification 5, as shown in Figure 15E, the pre-execution confirmation (S216) is performed by the device manager 200 when the device manager 200 notifies the allocation result (S218).

[0153] (Embodiment 2) Next, Embodiment 2 will be described. This embodiment differs from Embodiment 1 in that pre-execution verification is skipped if the application is already authenticated. The following description will focus on the differences from Embodiment 1.

[0154] The hardware configuration and functional configuration of System 1 in this embodiment are the same as those in Embodiment 1 described above, so they are not shown or described.

[0155] [2.1 Processing] In this embodiment, the process is the same as in Embodiment 1, except that step S216 of the pre-execution verification process is replaced by step S216A. Therefore, step S216A of the pre-execution verification process will be explained with reference to Figure 16.

[0156] Figure 16 shows a flowchart of the pre-execution verification process in Embodiment 2.

[0157] (Step S2161A) Device 300 obtains app authentication information. App authentication information includes information indicating that the application is authenticated, if so.

[0158] Application authentication is a mechanism to guarantee the quality of an application, for example, and allows verification of the application's security and / or identity (that it has not been tampered with). An example of an application with authentication information is described below. If the change history of the application's code shows that no changes were made to the parameter range, then information indicating that the application is authenticated is associated with it.

[0159] (Step S2162A) Device 300 determines whether the application is authenticated based on the acquired application information. If it is determined that the application is authenticated (Yes in S2162A), device 300 skips the following steps S2165 to S2167 and terminates the pre-execution verification process. On the other hand, if it is determined that the application is not authenticated (No in S2162A), device 300 proceeds to the next step S2165.

[0160] [2.2 Effects, etc.] As described above, the apparatus 20 in this embodiment comprises at least one actuator 22 and a heater 23, and a control unit 24 that controls at least one of the actuator 22 and the heater 23. The control unit 24 acquires an application which is defined by a plurality of blocks that drive at least one of the actuator 22 and the heater 23 and includes information indicating whether or not it is authenticated. If the application does not include information indicating that it is authenticated, it refers to a rule indicating that two or more predetermined blocks are executed in combination. If the plurality of blocks included in the application do not match the rule, it modifies the application and drives at least one of the actuator 22 and the heater 23 based on the modified application.

[0161] This allows for the same effects as in Embodiment 1. Furthermore, it enables processing that involves modifying the application when the application is not authenticated, and reduces the processing load when the application is authenticated. Therefore, it is not necessary to perform judgment processing on block combinations for all applications, and management through authentication reduces the processing load and establishes design standards for block combinations, enabling easier and safer design for application developers.

[0162] Furthermore, for example, in the device 20 of this embodiment, if the application has information indicating that it is authenticated, the application does not need to be modified without referring to the first rule.

[0163] According to this, if the application is authenticated, the process of modifying the block can be skipped, thereby reducing the processing load.

[0164] (Embodiment 3) Next, Embodiment 3 will be described. This embodiment differs from Embodiment 1 in that pre-execution verification is skipped when the application creator and the device creator are the same person. The following description will focus on the differences from Embodiment 1.

[0165] The hardware configuration and functional configuration of System 1 in this embodiment are the same as those in Embodiment 1 described above, so they are not shown or described.

[0166] [3.1 Processing] In this embodiment, the process is the same as in Embodiment 1, except that step S216 of the pre-execution verification process is replaced by step S216B. Therefore, step S216B of the pre-execution verification process will be explained with reference to Figure 17.

[0167] Figure 17 shows a flowchart of the pre-execution verification process in Embodiment 3.

[0168] (Step S2161B) Device 300 retrieves app creator information. App creator information indicates the creator of the application. The creator refers to the company, individual, or organization that created the application, and may also be called the developer or author.

[0169] (Step S2163B) Device 300 retrieves device manufacturer information. Device manufacturer information indicates the manufacturer of the device. The manufacturer refers to the company, individual, or organization that manufactured device 300 (i.e., device 20), and is sometimes referred to as the producer.

[0170] (Step S2164B) Device 300 determines whether the creator of the application and the creator of Device 300 are different. If the creator of the application is an individual and the creator of Device 300 is a company, Device 300 may determine that the creator of the application and the creator of Device 300 are the same if the company to which the application creator belongs matches the creator of Device 300. Alternatively, Device 300 may determine that the creator of the application and the creator of Device 300 are the same if the application creator is a development contractor of the creator of Device 300.

[0171] If the creator of the application and the creator of device 300 are the same (No in S2164B), device 300 skips the subsequent steps S2165 to S2167 and terminates the pre-execution verification process. On the other hand, if the creator of the application and the creator of device 300 are different (Yes in S2164B), device 300 proceeds to the next step S2165.

[0172] [3.2 Effects, etc.] As described above, the apparatus 20 in this embodiment comprises at least one actuator 22 and a heater 23, and a control unit 24 that controls at least one of the actuator 22 and the heater 23. The control unit 24 acquires an application which is defined by a plurality of blocks that drive at least one of the actuator 22 and the heater 23 and includes information indicating the creator, acquires information indicating the creator of the apparatus 20, and if the creator of the application and the creator of the apparatus 20 are different, it refers to a rule which indicates that two or more predetermined blocks are executed in combination, modifies the application if the plurality of blocks included in the application do not fall under the rule, and drives at least one of the actuator 22 and the heater 23 based on the modified application.

[0173] This allows for achieving the same effects as in Embodiment 1. Furthermore, when the application creator and the manufacturer of the device 20 are different, processing involving changes to the application can be performed, and when the application creator and the manufacturer of the device 20 are the same, the processing load can be reduced.

[0174] (Embodiment 4) Next, Embodiment 4 will be described. This embodiment differs from Embodiment 1 in that pre-execution checks are performed using rules corresponding to the degradation level of the device. The following description will focus on the differences from Embodiment 1.

[0175] The hardware configuration and functional configuration of System 1 in this embodiment are the same as those in Embodiment 1 described above, so they are not shown or described.

[0176] [4.1 Processing] In this embodiment, the process is the same as in Embodiment 1, except that step S216 of the pre-execution verification process is replaced by step S216C. Therefore, step S216C of the pre-execution verification process will be explained with reference to Figure 18.

[0177] Figure 18 shows a flowchart of the pre-execution verification process in Embodiment 4.

[0178] (Step S2163C) Device 300 acquires device degradation information. The device degradation information indicates the degradation level of the actuator 22 and / or heater 23 included in the apparatus 20. The method for detecting the degradation level is not particularly limited and may be detected by a sensor, for example.

[0179] (Step S2165C) Device 300 retrieves a rule corresponding to the degradation level. For example, device 300 refers to a rule database to retrieve a rule corresponding to the degradation level of the actuator 22 or heater 23 driven by the block.

[0180] The factors that determine the degradation level include, for example, the number of uses, usage time, or number of days of use from the start of operation to the present for the actuator 22 and / or heater 23 included in device 300. These factors are assumed to increase in roughly proportional proportion to user usage. Therefore, the rules are determined such that the degradation level increases as the value corresponding to each factor increases.

[0181] Furthermore, the items that determine the degradation level are, for example, the sum of the temperatures of the heater 23, or the degree of reproducibility of the input and output of the actuator 22 and / or the heater 23. The sum of the temperatures of the heater 23 is the sum of the temperatures when the heater 23 is driven. For example, the average temperature, intermediate temperature, or maximum temperature of the heater 23 during block execution can be used. The temperature of the heater 23 may also be the ratio of the execution temperature to the limit temperature of the heater 23, or the difference between the execution temperature and the limit temperature of the heater 23.

[0182] The degree of reproducibility of the input and output of the actuator 22 and / or heater 23 is determined by referring to the relationship between the input value for driving the actuator 22 and / or heater 23 and the output of the actuator 22 and / or heater 23. The ratio of the actual output value for a given input to the output value defined in the relationship is used.

[0183] [4.2 Effects, etc.] As described above, the apparatus 20 in this embodiment comprises at least one actuator 22 and a heater 23, and a control unit 24 that controls at least one of the actuator 22 and the heater 23. The control unit 24 acquires an application defined by a plurality of blocks that drive at least one of the actuator 22 and the heater 23, acquires degradation information indicating whether at least one of the actuator 22 and the heater 23 is degraded, and refers to a rule corresponding to the degradation information that indicates that two or more predetermined blocks are executed in combination. If the plurality of blocks included in the application do not match the rule, the control unit 24 modifies the application and drives at least one of the actuator 22 and the heater 23 based on the modified application.

[0184] This allows for the same effects as in Embodiment 1. Furthermore, rules corresponding to the degradation information of the device 20 can be used, and by using blocks, drive instructions from the application to the actuator 22 and / or heater 23 can be executed while considering the performance of the device as it ages, thereby further improving the safety of the device 20 controlled by the application.

[0185] (Embodiment 5) In embodiments 1 to 4 described above, blocks included in an already distributed application are modified before the application is executed. In this embodiment, the timing of the application modification is before the application is distributed, that is, during the development or production stage of the application, and in this respect, this embodiment differs from embodiments 1 to 4. The following describes this embodiment in detail, focusing on the differences from embodiments 1 to 4. Note that this embodiment may be the same as embodiments 1 to 4 except for the timing of the application modification. Also, for each component in this embodiment that is the same as in embodiments 1 to 4, the same reference numerals are used, and detailed descriptions are omitted.

[0186] [5.1 Structure] Figure 19 shows an example of the configuration of an information processing system used for application development.

[0187] The information processing system 2000 comprises a block database 41, a rule database 42, a development tool 50, multiple devices 20 and multiple terminals 30, an application provision server 60, and a sequence manager 100. For example, these components provided in the information processing system 2000 are connected via a communication network such as the Internet.

[0188] The block database 41, also called a block DB, is a recording medium that stores a list of blocks, including multiple functional blocks. These functional blocks are also called blocks, as in Embodiments 1 to 4. The rule database 42, also called a rule DB, is a recording medium that stores multiple rules. The rule database 42 may be the same as, for example, the rule database 1300 shown in Figure 12. These recording media can be hard disks, RAM (Random Access Memory), ROM (Read Only Memory), or semiconductor memory. Such recording media may be volatile or non-volatile.

[0189] The development tool 50 is a computer system comprising, for example, a processor 51, memory 52, a display 53, and an input unit 54. The processor 51 executes the processes described below by, for example, executing instructions or software programs stored in memory 52, and displays characters or images on the display 53. The display 53 is, for example, a liquid crystal display, a plasma display, or an organic EL (Electro-Luminescence) display, but is not limited to these. The input unit 54 is configured as, for example, a keyboard, a touch sensor, a touchpad, or a mouse. Such a development tool 50 is used, for example, by an application developer to generate a sequence or application containing multiple functional blocks. In this embodiment, the development tool 50 is an example of an information processing device.

[0190] The application provision server 60 retrieves and stores applications generated by the development tool 50 from the development tool 50 via the communication network. Then, in response to instructions from the UI 400 on the terminal 30, the application provision server 60 downloads the stored applications to the sequence manager 100.

[0191] Figure 20 shows an example of the information stored in the block database 41 and the rule database 42, respectively.

[0192] As shown in Figure 20(a), the block database 41 stores a list of functional blocks for each of the multiple types of devices 20, as the block list described above. For example, block lists 41a to 41e are stored. Block list 41a includes functional blocks FB11 to FB14 for driving an oven range. Block list 41b includes functional blocks FB21 to FB24 for driving a multi-cooker. These functional blocks may be the same as or similar to the blocks in embodiments 1 to 4 described above.

[0193] As shown in Figure 20(b), the rule database 42 stores a set of rules for each of the multiple types of devices 20, each consisting of at least one rule applicable to that type of device 20. For example, rule sets 42a to 42e are stored. Rule set 42a includes rules R100 and R11 to R13 that apply to oven ranges. Rule set 42b includes rules R200 and R21 to R23 that apply to multi-cookers. Rule set 42d includes rules R400 and R41 to R43 that apply to washing machines. These rules may be the same as or similar to the rules in embodiments 1 to 4 described above.

[0194] Here, each of the oven range rules R11 to R13 is a specific rule applicable to a specific model of oven range manufactured by a specific manufacturer. Similarly, each of the multi-cooker rules R21 to R23 is a specific rule applicable to a specific model of multi-cooker manufactured by a specific manufacturer. Similarly, each of the washing machine rules R41 to R43 is a specific rule applicable to a specific model of washing machine manufactured by a specific manufacturer. Specifically, each of the specific rules R41 to R43 may be, for example, rule 1301 or 1302 shown in Figure 12.

[0195] On the other hand, Rule R100 for microwave ovens is a general rule for microwave ovens that can be applied to various types of microwave ovens, for example. Similarly, Rule R200 for multi-cookers is a general rule for multi-cookers that can be applied to various types of multi-cookers, for example.

[0196] Figure 21 shows an example of a general-purpose rule included in the rule database 42.

[0197] The washing machine rule group 42d stored in the rule database 42 includes, for example, the general rule R400 shown in Figure 21(a). This general rule R400 is applicable to each of several types of washing machines and prohibits that at least one of two or more predetermined blocks is not executed when one of those two or more predetermined blocks is executed. In other words, the rule, as in embodiments 1 to 4 above, indicates requirements for a combination of two or more predetermined blocks. Hereinafter, a combination of two or more predetermined blocks will also be simply called a combination, and the requirements for that combination will also be called a combination rule. The general rule R400 may indicate multiple combination rules. For example, the general rule R400 may indicate a first combination rule and a second combination rule. The first combination rule is a requirement for a first block, which is a drainage function block, and a second block, which is a spin-drying function block. In other words, the first combination rule indicates that it is prohibited for the drainage block not to be executed before the spin-drying block is executed. The second combination rule is a requirement for a second block, which is a drying function block, and a third block, which is a blowing function block. In other words, the second combination rule indicates that it is forbidden for a blowing block not to be executed after a drying block.

[0198] The drain block is a functional block that causes the washing machine to drain water, and the spin-dry block is a functional block that causes the washing machine to spin-dry water. Similarly, the drying block is a functional block that causes the washing machine to dry water, and the blower block is a functional block that causes the washing machine to blow air.

[0199] Furthermore, the multiple types of washing machines to which general rule R400 applies include washing machines offered by multiple manufacturers. Also, if each manufacturer offers multiple models of washing machines, then those multiple types of washing machines include those multiple models. In short, the combinations shown in general rule R400 apply to any washing machine, regardless of manufacturer or model.

[0200] Furthermore, the general rule R400 for the washing machine may also represent a combination rule applicable to washing machines from multiple manufacturers, as shown in Figure 21(b). For example, the general rule R400 may represent a combination rule applicable to multiple models of washing machines provided by manufacturer "Company A" and a combination rule applicable to multiple models of washing machines provided by manufacturer "Company B".

[0201] Thus, the rule in this embodiment, like in embodiments 1 to 4, is a rule that prohibits at least one of two or more predetermined blocks from being executed when one of those blocks is executed. The two or more predetermined blocks include a first block and a second block, and the rule prohibits the first block from being executed before the second block is executed. In other words, the rule prohibits the first block from being executed from the start of the application until before the second block is executed. This first block, like in embodiments 1 to 4, is a block for setting the environment so that the second block can be executed.

[0202] Alternatively, the specified two or more blocks include a second block and a third block, and the rule prohibits the execution of the third block after the execution of the second block. That is, the rule prohibits the execution of the third block from the time the second block is executed until the termination of the application. Such a third block, as in embodiments 1 to 4, is a block for restoring the environment changed by the execution of the second block back to the environment before the execution of the second block.

[0203] The rules in this embodiment may also be rules that ensure, for example, that two or more predetermined blocks are executed in combination to prevent the internal space of the housing 21, the actuator 22, or the heater 23 from reaching the durable temperature, similar to embodiments 1 to 4.

[0204] [5.2 Processing] Figure 22 is a sequence diagram of the information processing system 2000.

[0205] (Step S11) First, the development tool 50 installs one or more functional blocks. Specifically, the development tool 50 obtains one or more functional blocks by downloading them from the block database 41. For example, the development tool 50 may obtain the block list 41a for the microwave oven, or it may obtain only some of the functional blocks from that block list 41a. Then, the development tool 50 makes the obtained one or more functional blocks available for sequence generation.

[0206] Here, each functional block stored in the block database 41 may have device information corresponding to that functional block attached to it. This device information indicates, for example, the manufacturer, type, model, or part number of the device 20 that is driven according to the functional block corresponding to that device information. Therefore, the development tool 50 may download one or more functional blocks based on that device information. For example, the development tool 50 may download one or more functional blocks to drive each device 20 provided by the same manufacturer, or it may download one or more functional blocks to drive each device 20 used for heating food.

[0207] (Step S12) Next, the development tool 50 generates a sequence. Specifically, the development tool 50 generates a sequence using one or more downloaded functional blocks in response to an input operation to the input unit 54 by the operator. The operator may be the developer of the application which is the sequence. In this embodiment, in step S12, the development tool 50 refers to the above-described rule and modifies the application based on that rule.

[0208] (Step S13) Next, the development tool 50 uploads the generated sequence. Specifically, in response to the user's input operation to the input unit 54, the development tool 50 generates transmission information based on the content of the sequence for sending the generated sequence to the application provision server 60, and sends this transmission information to the application provision server 60. This transmission information may be, for example, JSON (JavaScript Object Notation). As a result, the sequence is sent to the application provision server 60 and stored there as an application.

[0209] (Step S14) Next, the user of terminal 30 accesses the application distribution server 60 by operating the UI 400 on terminal 30 and views a list of applications stored on the application distribution server 60. Then, in response to the user's operation, the UI 400 selects an application from the list and requests the application distribution server 60 to download that application.

[0210] (Step S15) When the application server 60 receives a download request from the UI400, it downloads the selected application to the sequence manager 100 associated with that user.

[0211] Figure 23 is a flowchart showing the overall processing operation of the development tool 50. Specifically, the flowchart shown in Figure 23 illustrates the detailed processing operation of steps S11 and S12 in the sequence shown in Figure 22.

[0212] (Step S21) The development tool 50 first installs several functional blocks to drive a device 20, such as a washing machine.

[0213] (Step S22) Next, the development tool 50 performs the function block placement process in response to the operator's input operation to the input unit 54. That is, the development tool 50 displays the multiple function blocks installed in step S21 on the display 53, and in response to the operator's input operation to the input unit 54, selects one function block from the displayed multiple function blocks. Then, in response to the operator's input operation to the input unit 54, the development tool 50 places that function block in the selection block area on the sequence generation screen on the display 53. The sequence generation screen will be described later with reference to Figure 26. In other words, the operator drags and drops one of the multiple function blocks into its selection block area.

[0214] (Step S23) Next, the development tool 50 performs parameter setting processing for the function block placed in step S22 in response to the operator's input operation to the input unit 54. That is, the development tool 50 displays a reception image in the parameter setting area of ​​the sequence generation screen described above to receive the contents of the parameters used for that function block. Then, in response to the operator's input operation to the input unit 54, the development tool 50 receives the contents of those parameters and displays the contents of those parameters in the parameter setting area. As a result, the parameters are set for that function block.

[0215] (Step S24) Next, the development tool 50 refers to the parameter rules applied to the device 20, such as a washing machine, and determines whether the parameters set in step S23 are outside the parameter range indicated in the parameter rules, i.e., outside the non-acceptable range.

[0216] (Step S25) If the development tool 50 determines in step S24 that the parameter is not outside the acceptable range (No. in step S24), it performs parameter setting support processing. In this parameter setting support processing, the development tool 50 performs either error presentation processing, which presents an error to the operator, or automatic parameter correction processing. In automatic parameter correction processing, the development tool 50 modifies the function block by changing a parameter outside the acceptable range to a parameter within the acceptable range. In error presentation processing, the development tool 50 displays a message on the display 53 as an error, for example, indicating that the parameter set in the previous step S23 is outside the acceptable range, and prompts the operator to change the parameter. After the processing in step S25 is completed, the development tool 50 repeats the processing from step S23.

[0217] Furthermore, if the process in step S23 is performed after the automatic parameter correction process in step S25, in step S23, the development tool 50 displays the parameters after they have been changed by the automatic correction process in the parameter setting area. On the other hand, if the process in step S23 is performed after the error notification process in step S25, in step S23, the development tool 50 again accepts the contents of the parameters in response to the input operation to the input unit 54 by the operator, as described above. As a result, the parameters for that function block are changed. In other words, the function block is changed.

[0218] (Step S26) If the development tool 50 determines in step S24 that the parameter is outside the acceptable range (Yes in step S24), it further determines whether the connection of the function block placed in step S22 is permitted. For example, in step S22, a function block is placed immediately before or after an existing block, which is another function block already placed in the selected block area. As a result, the function block is placed connected to the existing block. In other words, the function block is placed so that the processing of the device 20 by the function block and the processing of the device 20 by the existing block are executed consecutively. In this case, the development tool 50 determines whether the connection between the function block and the existing block is permitted by referring to the connection rules applied to the device 20, such as a washing machine.

[0219] (Step S27) If the development tool 50 determines in step S26 that the connection is not permitted (No. in step S26), it performs connection support processing. In this connection support processing, the development tool 50 performs error presentation processing to present an error to the operator, or performs automatic connection correction processing. The development tool 50 then repeats the processing from step S22.

[0220] If the process in step S22 is performed after the automatic connection correction process in step S27, then in step S22, the development tool 50 displays two or more function blocks that have been reconnected by the automatic correction process in the selected block area. On the other hand, if the process in step S22 is performed after the error presentation process in step S27, then in step S22, the development tool 50 rearranges the function blocks again in response to the input operation to the input unit 54 by the operator, as described above. Furthermore, if the process from step S27 to step S22 is repeated, the development tool 50 may skip the processes from step S22 to steps S23 to S25 because the parameters of the function blocks have already been set within the acceptable range.

[0221] (Step S28) If the development tool 50 determines in step S26 that a connection is permitted (Yes in step S26), it further determines whether the sequence generation is complete in response to the operator's input operation to the input unit 54. If the development tool 50 determines that the sequence generation is not complete (No in step S28), it repeats the process from step S22. In this case, the development tool 50 selects a new block from the multiple blocks installed in step S21 in response to the operator's input operation to the input unit 54 and places it in the selected block area described above.

[0222] (Step S29) If the development tool 50 determines that the generation of the sequence is complete in step S28 (Yes in step S28), it further determines whether the flow of the entire generated sequence is permitted. For example, if the second functional block is placed before or after the first functional block in the sequence, while the combination rule applied to the device 20, such as a washing machine, does not permit the combination of the first and second functional blocks, the development tool 50 determines that the flow of the entire generated sequence is not permitted. Alternatively, if the combination rule applied to the device 20, such as a washing machine, requires that the second functional block be placed before or after the first functional block, the development tool 50 determines that the flow of the entire generated sequence is permitted.

[0223] In other words, the development tool 50 refers to the rules applied to the device 20, such as a washing machine, and determines whether the sequence generated in step S28, i.e., the multiple functional blocks included in the application, fall under those rules. If the multiple functional blocks fall under the rules, the development tool 50 determines that the flow of the entire sequence generated in step S28 is not permitted. On the other hand, if the multiple functional blocks do not fall under the rules, the development tool 50 determines that the flow of the entire sequence generated in step S28 is permitted. The rules referred to in step S29 are the general-purpose rules or dedicated rules applied to the device 20, and more specifically, the combination rules included in those rules. The method for determining whether or not a rule applies is the same as in embodiments 1 to 4 described above.

[0224] (Step S30) If the development tool 50 determines in step S29 that the flow of the entire sequence is not permitted (No. in step S29), it performs placement support processing. In this placement support processing, the development tool 50 performs either placement error presentation processing that presents an error to the operator, or automatic correction processing of the placement of functional blocks. The development tool 50 then repeats the processing from step S22.

[0225] Furthermore, if the process in step S22 is performed after the automatic placement correction process in step S30, the development tool 50 displays two or more function blocks that have been rearranged by the automatic correction process in the selected block area in step S22. Also, if the processes from step S30 to step S22 are repeated, the development tool 50 may skip the processes in steps S23 to S25 after step S22 because the parameters of the function blocks have already been set within the acceptable range. In addition, the development tool 50 may skip the processes in steps S26 and S27 because the connection of the function blocks has already been permitted. Furthermore, the development tool 50 may also skip the process in step S28.

[0226] Figure 24 is a flowchart showing an example of an automated layout correction process.

[0227] (Step S41) The development tool 50 selects M function blocks (where M is an integer between 2 and N) from N function blocks (where N is an integer between 2 and N) for driving a device 20, such as a washing machine, in response to an input operation by the operator to the input unit 54. In other words, the development tool 50 selects each of the M function blocks as selected blocks from N function blocks for driving at least one of the actuators 22 and heaters 23 provided in the device 20, which is the controlled device, in response to an input operation by the operator to the input unit 54.

[0228] (Step S42) Next, the development tool 50 generates a sequence, or application, by arranging each of the selected M functional blocks in the aforementioned selection block area in an orderly manner. In other words, the development tool 50 generates an application containing at least M selected blocks by setting the order in which each of the at least M selected blocks is executed according to the input operation of the operator to the input unit 54. Each of the M selected blocks included in this application may contain parameters for driving at least one of the actuator 22 and the heater 23.

[0229] (Step S43) Next, the development tool 50 refers to the rules applicable to the washing machine, if each of the M functional blocks is a block for driving the washing machine. For example, if the application generated in step S42 is applicable to multiple types of washing machines, the development tool 50 refers to the general rule R400. Also, if the application generated in step S42 is applicable to a predetermined model of washing machine, the development tool 50 refers to the rule from the dedicated rules R41 to R43 that is associated with that model of washing machine. In other words, the development tool 50 determines whether the application generated in step S42 is an application dedicated to the controlled device or a general-purpose application applicable to that controlled device and other devices. Then, the development tool 50 refers to the rule candidate corresponding to the determination result of the application, from among several rule candidates that prohibit the execution of at least one of two or more predetermined blocks when one of those blocks is executed, as the rule described above.

[0230] (Step S44) The development tool 50 then determines whether the M functional blocks set in step S42 correspond to the above-mentioned rules. In other words, the development tool 50 determines whether the M functional blocks included in the application correspond to the combination rules included in that rule.

[0231] (Step S45) Here, if the development tool 50 determines that the M functional blocks meet the rule (Yes in step S44), it modifies the application. That is, the development tool 50 refers to a rule that prohibits at least one of two or more predetermined blocks from being executed when one of those blocks is executed, and modifies the application if the M selected blocks included in the application meet that rule. Specifically, the development tool 50 modifies the application by (1) adding a new block to the M selected blocks, (2) changing the order of the M selected blocks, or (3) deleting any of the M selected blocks. These methods of modifying the application may be defined in the rule.

[0232] (Step S46) Then, development tool 50 outputs the modified application.

[0233] Figure 25 is a flowchart showing an example of the error notification process for placement.

[0234] (Steps S41-S44) The development tool 50 executes the processes in steps S41 to S44, similar to the example shown in Figure 24.

[0235] (Step S51) If the development tool 50 determines in step S44 that M functional blocks meet the rule (Yes in step S44), it displays an error on the display 53 without automatically modifying the application. This presents the error to the operator. In other words, in the processing of steps S43, S44, and S51, the development tool 50 presents the error by referring to the rule. Specifically, the development tool 50 refers to a rule that prohibits the execution of at least one of two or more predetermined blocks when one of those blocks is executed, and presents an error to the operator if M selected blocks included in the application meet that rule.

[0236] Furthermore, the development tool 50 may present an error and show the operator multiple solutions, prompting the operator to choose a solution. In this case, the development tool 50 may show the operator the differences in output performance for each of the multiple solutions. Also, in this case, the development tool 50 may present at least two of the following solutions: a first solution involving the addition of a new functional block, a second solution involving changing the order of M selected blocks, and a third solution involving deleting any of the functional blocks. These solutions are then presented to the operator, for example, an application developer. As a result, the application developer, having seen these solutions, can easily modify the application generated in step S42 according to the solution by performing an input operation to the input unit 54 of the development tool 50.

[0237] (Step S52) Upon seeing the error, the operator modifies the application generated in step S42 by performing an input operation to the input unit 54 of the development tool 50. If multiple solutions are presented to the operator as options, the operator selects a solution from these options by performing an input operation. As a result, the development tool 50 modifies the application. In other words, the development tool 50 modifies the application in response to the input operation by the operator who received the error. The development tool 50 then repeatedly executes the process from step S43 onwards.

[0238] (Step S46) If the development tool 50 determines in step S44 that M functional blocks do not meet the rule (No. in step S44), it outputs the application. At this time, if the application was modified in step S52, the modified application is output. On the other hand, if the application was not modified in step S52, the application generated in step S42 is output.

[0239] In addition, when the process of step S51 is repeated, the development tool 50 may present a method for dealing with errors according to the number of repetitions. For example, when the number of error presentations is K times or more (K is an integer of 2 or more), the development tool 50 may present a plurality of methods for dealing with the error. That is, when the number of error presentations is K times or more, the development tool 50 presents at least two of the above-described first method for dealing with errors, second method for dealing with errors, and third method for dealing with errors to the operator.

[0240] [5.3 Display Example] FIG. 26 is a diagram showing an example of a sequence generation screen.

[0241] The development tool 50 displays the above-described sequence generation screen on the display 53. The sequence generation screen includes a parameter setting area D1, a block list area D2, a target device area D3, and a selected block area D4.

[0242] In the parameter setting area D1, a reception image for receiving the content of the parameters used in the function block is displayed.

[0243] In the block list area D2, block lists of each of a plurality of types of devices 20 are displayed. These block lists include function blocks downloaded from the block database 41 and installed in the development tool 50.

[0244] In the target device area D3, the type name of the device 20 selected from a plurality of types of devices 20 is displayed.

[0245] In the selected block area D4, the function block selected from the block list displayed in the block list area D2 is arranged and displayed. The function block is displayed, for example, as an icon.

[0246] For example, the operator determines the type name of the device 20 to which the application is applied by performing an input operation on the input unit 54 of the development tool 50. The development tool 50 displays the determined type name in the target device area D3. For example, the determined type name "rice cooker" is displayed. Next, the operator selects a function block to drive the device 20 with the determined type name "rice cooker" from the block list displayed in the block list area D2 by performing an input operation. Then, the operator places the selected function block, i.e., the selected block, in the selection block area D4 by performing an input operation. The selection and placement of this function block may be done by drag and drop. One or more function blocks placed in this selection block area D4 may be executed in the order in which they are placed. For example, in Figure 26, the function blocks are executed sequentially from left to right. In other words, the application includes information on the order in which each of the M selected blocks placed in the selection block area D4 is executed, and information on the timing in which each of the M selected blocks is executed.

[0247] When a functional block is placed in the selection block area D4, the development tool 50 displays the input images for the parameters used in that functional block in the parameter setting area D1.

[0248] Figure 27 shows an example of how the block list is displayed.

[0249] The operator selects the type name of the device 20 to which the application to be generated will be applied from among the type names of multiple devices 20 displayed in the block list area D2 shown in Figure 26 by performing an input operation on the input unit 54. The development tool 50 displays the block list corresponding to the selected type name of device 20, for example, as shown in Figures 27(a) and (b). For example, as shown in Figure 27(a), when an oven range is selected, the development tool 50 displays the block list for that oven range. For example, this block list includes function blocks that realize the functions of baking, microwave heating, oven, grill, steaming, preheating, and superheated steam. Also, as shown in Figure 27(b), when a multi-cooker is selected, the development tool 50 displays the block list for that multi-cooker. For example, this block list includes function blocks that realize the functions of preheating, keeping warm, stir-frying, pressure cooking, boiling, steaming, simmering, mixing, and simmering.

[0250] The operator selects a function block from the displayed block list by performing an input operation to the input unit 54, and places the selected function block in the selection block area D4 shown in Figure 26. In other words, the development tool 50 performs the process of step S22 shown in Figure 23, that is, the function block placement process, in response to such an input operation.

[0251] Figure 28A shows an example of the placement process for functional blocks and the automatic correction process for their placement.

[0252] The development tool 50 displays, for example, as an icon, the function block that has been dragged and dropped from the block list and placed in the selected block area D4, as shown in Figure 28A(a). Specifically, the development tool 50 places M function blocks, including the dewatering function block FB42, in the selected block area D4 in response to the operator's input operation to the input unit 54. In this way, the development tool 50 performs the function block placement process shown in step S22 of Figure 23 in response to the operator's input operation.

[0253] Furthermore, once an application is generated as a result of the functional block placement process, the development tool 50 determines whether the overall flow of the application is permitted, as shown in step S29 of Figure 23. That is, the development tool 50 makes a determination on the M functional blocks placed in the selected block area D4 using rules. Then, the development tool 50 performs an automatic correction process for their placement.

[0254] Specifically, the development tool 50 first refers to the washing machine rules corresponding to those M functional blocks. For example, the development tool 50 identifies the washing machine rule group 42d from the rule database 42 shown in Figure 20(b), and refers to any one of the rules included in that rule group 42d. That rule may be a general-purpose rule R400, a dedicated rule R41, or the like. For example, the rule may include a combination rule that prohibits the first block, the draining function block FB41, from being executed before the second block, the spin-drying function block FB42, is executed.

[0255] Then, the development tool 50 modifies the application when it determines that the M functional blocks that are placed meet the rule. For example, the development tool 50 modifies the washing machine application by adding the drain functional block FB41 before the functional block FB42, as shown in Figure 28A(b).

[0256] Thus, in this embodiment, the development tool 50 modifies the application by adding the first block before the second block if the application includes the second block and does not include the first block before the second block. As a result of this modification, M functional blocks no longer meet the rules.

[0257] Furthermore, if the functional block placement process results in the first block, the drainage functional block FB41, being placed after the second block, the dewatering functional block FB42, the development tool 50 may move the drainage functional block FB41 forward. In other words, the development tool 50 modifies the application by changing the order of the first block to be before the order of the second block if the application includes the first block and the second block, and does not include the first block before the second block. Even with such a change, M functional blocks will no longer fall under the rule.

[0258] Furthermore, the development tool 50 may delete the second block, which is the dehydration function block FB42. In other words, the development tool 50 modifies the application by deleting the second block if the application contains the second block and does not have a first block before it. Such a modification also results in M ​​function blocks no longer meeting the rule.

[0259] Figure 28B shows another example of the functional block placement process and the automatic placement correction process.

[0260] The development tool 50 displays, for example, as icons, the function blocks that have been dragged and dropped from the block list and placed in the selected block area D4, as shown in Figure 28B(a). Specifically, the development tool 50 places M function blocks, including the drying function block FB44, in the selected block area D4 in response to the operator's input operation to the input unit 54. In this way, the development tool 50 performs the function block placement process shown in step S22 of Figure 23 in response to the operator's input operation.

[0261] In addition, when an application is generated as a result of the arrangement process of the functional blocks, the development tool 50 determines whether the flow of the entire application is permitted as in step S29 of FIG. 23. That is, the development tool 50 makes a determination for the M functional blocks arranged in the selection block area D4 using rules. Then, the development tool 50 performs automatic correction processing for the arrangement.

[0262] Specifically, the development tool 50 first refers to the rules of the washing machine corresponding to those M functional blocks. For example, the development tool 50 identifies the rule group 42d of the washing machine among the rule databases 42 shown in (b) of FIG. 20 and refers to any one rule included in the rule group 42d. The rule may be a general rule R400 or a dedicated rule R41, etc. For example, the rule includes a combination rule that prohibits the execution of the blowing functional block FB45, which is the third block, after the drying functional block FB44, which is the second block, is executed.

[0263] When the development tool 50 determines that the M arranged functional blocks comply with the rule, it changes the application. For example, as shown in (b) of FIG. 28B, the development tool 50 changes the washing machine application by adding the blowing functional block FB45 after the functional block FB44.

[0264] In this way, in the present embodiment, when the application includes the second block and does not include the third block after the second block, the development tool 50 changes the application by adding the third block after the second block. By such a change, the M functional blocks are in a state where they do not comply with the rule.

[0265] Furthermore, if the placement process of the functional blocks results in the third block, the blower functional block FB45, being placed before the second block, the drying functional block FB44, the development tool 50 may move the blower functional block FB45 to the rear. In other words, the development tool 50 modifies the application by changing the order of the third block to be after the order of the second block if the application includes the second and third blocks, and does not include the third block after the second block. Even with such a change, M functional blocks will no longer fall under the rule.

[0266] Furthermore, the development tool 50 may delete the second block, which is the drying function block FB44. In other words, the development tool 50 modifies the application by deleting the second block if the application contains the second block and does not contain a third block after the second block. Such a modification also results in M ​​function blocks no longer meeting the rule.

[0267] As shown in Figures 28A and 28B, in this embodiment, an automatic arrangement correction process is performed. Therefore, even if the operator, who is an application developer, mistakenly places M function blocks in a way that conforms to the rule, those M function blocks will be automatically rearranged so that they do not conform to the rule. Thus, the safety of the washing machine can be ensured.

[0268] Figure 29 shows an example of error reporting processing for placement.

[0269] The development tool 50 places M functional blocks, including the dewatering functional block FB42, in the selection block area D4, as shown in Figure 29, similar to the example in Figure 28A. Then, once an application is generated as a result of this placement, the development tool 50 determines whether the entire application flow is permitted, as shown in step S29 of Figure 23. That is, the development tool 50 makes the determination for the M functional blocks placed in the selection block area D4 using rules. For example, the rules include a combination rule that prohibits the first block, the drainage functional block FB41, from being executed before the second block, the dewatering functional block FB42.

[0270] Then, when the development tool 50 determines that the M functional blocks fall under the rule, it performs an error notification process. Specifically, as shown in Figure 29, the development tool 50 displays error message E1 as an error. This error message E1 indicates that the functional block corresponding to the dewatering functional block FB42 is not placed before it. In other words, this error message E1 notifies that the M functional blocks fall under the rule that prohibits the first block, the drainage functional block FB41, from being executed before the second block, the dewatering functional block FB42. Such error notification processing is performed, for example, in step S51 in Figure 25.

[0271] Thus, in this embodiment, the development tool 50 refers to a rule that prohibits at least one of two or more predetermined blocks from being executed when one of those blocks is executed, and if any of the M selected blocks included in the application fall under this rule, it presents an error to the operator. Then, in response to the input operation by the operator who received the error, the development tool 50 modifies the application by changing the order in which each of the M selected blocks is executed.

[0272] By presenting such an error, the application developer, who is the operator, can easily rearrange the M functional blocks that fall under the rule so that they no longer fall under that rule. Therefore, the safety of the washing machine can be ensured.

[0273] Furthermore, in the error presentation process, the development tool 50 may also display solutions C1 and C2 to address the error indicated by the error message E1. Solution C1 indicates that the error can be resolved by adding a drain function block before the spin-dry function block. In other words, solution C1 is the first solution described above, which adds a new block to the M selection blocks. Furthermore, the development tool 50 may also display the effects of performing solution C1 along with solution C1. For example, the development tool 50 may display that the processing time for the entire washing process will be longer, but that spin-drying will be performed properly as an effect.

[0274] Furthermore, solution C2 states that the error can be resolved by deleting the spin-drying function block. In other words, solution C2 is a third solution that deletes one of the M selection blocks. In addition, development tool 50 may display the effects of performing solution C2 along with solution C2. For example, development tool 50 may display that spin-drying cannot be performed, but the safety of the washing machine can be ensured as an effect.

[0275] Figure 30 shows another example of connection error notification processing.

[0276] The development tool 50 places M functional blocks, including the drying functional block FB44, in the selection block area D4, as shown in Figure 30, similar to the example in Figure 28B. Then, once an application is generated as a result of this placement, the development tool 50 determines whether the entire application flow is permitted, as shown in step S29 of Figure 23. That is, the development tool 50 makes the determination for the M functional blocks placed in the selection block area D4 using rules. For example, the rules include a combination rule that prohibits the execution of the third block, the blowing functional block FB45, after the execution of the second block, the drying functional block FB44.

[0277] Then, when the development tool 50 determines that the M functional blocks fall under the rule, it performs an error notification process. Specifically, as shown in Figure 30, the development tool 50 displays error message E2 as an error. This error message E2 indicates that there is no functional block corresponding to the drying functional block FB44 placed after it. In other words, this error message E2 notifies that the M functional blocks fall under the rule that prohibits the execution of the third block, the blowing functional block FB45, after the execution of the second block, the drying functional block FB44. Such error notification processing is performed, for example, in step S51 in Figure 25.

[0278] By presenting such an error, the application developer, who is the operator, can easily rearrange the M functional blocks that fall under the rule so that they no longer fall under that rule. Therefore, the safety of the washing machine can be ensured.

[0279] Furthermore, in the error presentation process, the development tool 50 may also display solutions C3 to C5 to address the error indicated by the error message E2. Solution C3 indicates that the error can be resolved by adding a blower function block after the drying function block. In other words, solution C3 is the first solution described above, which adds a new block to the M selection blocks. Furthermore, the development tool 50 may also display the effects of performing solution C3 along with solution C3. For example, the development tool 50 may display that the processing time for the entire washing process will be longer, but the safety of the washing machine can be ensured as an effect.

[0280] Furthermore, solution C4 states that the error can be resolved by moving the fan function block, which is located before the drying function block, to after the drying function block. In other words, solution C4 is the second solution described above, which changes the order of the M selection blocks. In addition, the development tool 50 may display the effects of performing solution C4 along with solution C4. For example, the development tool 50 may display that the safety of the washing machine can be ensured as an effect.

[0281] Furthermore, solution C5 states that the error can be resolved by deleting the drying function block. In other words, solution C5 is a third solution that deletes one of the M selection blocks. In addition, development tool 50 may display the effects of performing solution C5 along with solution C5. For example, development tool 50 may display that drying cannot be performed, but the safety of the washing machine can be ensured as an effect.

[0282] Thus, in this embodiment, the development tool 50 presents multiple solutions to an error. The development tool 50 then modifies the application in response to the input operation by the user who has received the error and the presented multiple solutions.

[0283] For example, the multiple solutions include at least two of the first, second, and third solutions described above. Furthermore, in this embodiment, the development tool 50 presents the effects on the object or application acted upon by the operation of the actuator 22 or heater 23 when each of the multiple solutions is performed.

[0284] By presenting multiple solutions and their effects, the application developer, or operator, can more easily rearrange the M functional blocks that fall under a rule so that they no longer fall under that rule. Therefore, the safety of the washing machine can be ensured.

[0285] Error messages E1 and E2, and solutions C1-C5, may be displayed in any area of ​​the sequence generation screen. Furthermore, these error messages E1 and E2, and solutions C1-C5, may each be shown in association with combination rules. Also, while the above example displays error messages E1 and E2 and solutions C1-C5, their presentation format is not limited to this example and may be any format. For example, errors may be presented via audio.

[0286] Furthermore, if the number of times the error is presented is K or more (where K is an integer greater than or equal to 2), the development tool 50 may present the operator with multiple solutions to the error. In other words, if the process of step S51 shown in Figure 25 is repeated, the development tool 50 may change the way the error is presented depending on the number of repetitions. Specifically, if the number of times the error is presented is less than K, the development tool 50 presents the error but does not present a solution, and if the number of times the error is presented is K or more, it displays both the error and a solution.

[0287] Figure 31 shows other examples of suggested solutions.

[0288] In the example above, the solution is presented as a message, but the development tool 50 may present the solution in other ways, as shown in Figure 31. For example, the development tool 50 presents the solution in a way that allows the functional block to be easily selected from the block list to avoid the error. That is, when the development tool 50 determines that the first block is not placed before the second block shown in the combination rule, it displays the block list as shown in Figure 32. In this block list, only the functional block that is the first block to be placed before the second block is displayed in a different way from the other functional blocks included in the block list. Specifically, in the washing machine block list, only the drain functional block that should be added before the spin-dry functional block is displayed brightly, while the other functional blocks are displayed dimly. This allows the operator, who is the application developer, to easily select the drain functional block and add it to the selection block area D4, thereby improving the usability of modifying the application.

[0289] Figure 32 shows yet another example of a proposed solution.

[0290] In the example above, the solution is presented only by message, but the development tool 50 may also present the solution using objects such as arrows, as shown in Figure 32. For example, if the development tool 50 determines that functional blocks FB34 and FB37 meet the rule, it presents a second solution, which is to reverse the order of those functional blocks, using both a message and an arrow. This allows the application developer to easily avoid the error by reversing the order of those functional blocks, thereby improving the usability of modifying the application.

[0291] [5.4 Effects, etc.] As described above, this embodiment provides an environment in which a wide variety of safe applications can be developed using an application including blocks and a rule database. Therefore, it enables the safe operation of a physically moving actuator 22 or a heater 23 that outputs thermal energy for an application freely developed in that environment. As a result, for example, it becomes possible to create a wide variety of applications with a high degree of freedom and a rule database to ensure safety in parallel, enabling the early development of a wide variety of safe applications.

[0292] Furthermore, by combining this embodiment with any of the embodiments 1 to 4, it becomes possible to modify the application to ensure greater security even after the application has been provided, by changing the rule database. Also, even if improvements become necessary in situations not anticipated by the manufacturer in advance, it is possible to support all applications by updating the rule database, which is defined independently of the applications themselves, without having to change the diverse range of applications.

[0293] Specifically, the information processing method in this embodiment is an information processing method executed by a computer system such as the development tool 50. In this information processing method, (a) from N blocks (N is an integer of 2 or more) for driving at least one of the actuator 22 and heater 23 provided in the device 20 which is the controlled device, each of M blocks (M is an integer of 1 or more and less than or equal to N) is selected as a selected block in response to an input operation by the operator; (b) an application containing at least M selected blocks is generated by setting the execution order of each of the M selected blocks in response to an input operation by the operator; (c) the application is modified if the M selected blocks included in the application meet the rule which prohibits the execution of at least one of two or more predetermined blocks when one of those two or more blocks is executed; and (d) the modified application is output.

[0294] According to this, the actuator 22 and / or heater 23 can be driven based on an application defined by M blocks. Therefore, it becomes possible to develop applications using blocks that abstract the control of the device 20, allowing not only the manufacturer but also third parties to develop a wide variety of applications, and these applications can be easily executed on the device 20. Furthermore, during this development, the application containing M selected blocks that fall under the above rule is automatically modified. As a result, the application can be automatically changed to an application containing M selected blocks that do not fall under the rule. Therefore, it can be ensured that one of the two or more predetermined blocks is executed in combination with at least one of the remaining blocks. In other words, even if an operator who is an application developer mistakenly generates an application that executes a block that is not allowed to be executed alone, it is possible to suppress the generation of an application that cannot safely control the device 20. Therefore, even if an application developer creates or generates an application that prioritizes suitability for the user of the actuator 22 and / or heater 23, the safety of the device 20 controlled by that application can be ensured and its safety can be improved.

[0295] Furthermore, in (c) above, the application may be modified by (1) adding a new block to the M selected blocks, (2) changing the order of the M selected blocks, or (3) deleting any of the M selected blocks.

[0296] More specifically, the two or more specified blocks include a first block and a second block, and the rule prohibits the first block from being executed before the second block. Furthermore, in (c) above, if the application includes a second block and does not have a first block before the second block, the application may be modified by adding a first block before the second block.

[0297] Furthermore, in (c) above, if the application includes a first block and a second block, and does not include a first block before the second block, the application may be modified by changing the order of the first block to one before the order of the second block.

[0298] Furthermore, in (c) above, if the application includes a second block and does not include a first block before the second block, the application may be modified by deleting the second block.

[0299] According to these methods, during application development, it is possible to ensure that the first block is executed before the second block by adding new blocks, changing the order of blocks, or deleting blocks. Therefore, the application developer, or the developer of the software incorporated into the device 20 that controls the actuator 22 and heater 23, can ensure the safety of the device 20 without having to check the safety of each individual application every time.

[0300] Specifically, the above rule may also prohibit the first block from being executed between the start of the application and the execution of the second block. Furthermore, the first block may be a block that sets the environment for the execution of the second block.

[0301] Furthermore, the two or more blocks specified above may include a second block and a third block, and the rule may prohibit the execution of the third block after the execution of the second block. In this case, (c) above may modify the application by adding a third block after the second block if the application includes a second block and does not include a third block after the second block.

[0302] Furthermore, in (c) above, if the application includes a second block and a third block, and does not include a third block after the second block, the application may be modified by changing the order of the third block to one that is later than the order of the second block.

[0303] Furthermore, in (c) above, if the application includes a second block and does not include a third block after the second block, the application is modified by deleting the second block.

[0304] According to these methods, during application development, it is possible to ensure that a third block is executed after a second block by adding a new block, changing the order of blocks, or deleting blocks. Therefore, the application developer, or the developer of the software incorporated into the device 20 that controls the actuator 22 and heater 23, can ensure the safety of the device 20 without having to check the safety of each individual application every time.

[0305] Furthermore, the above rule may also prohibit the execution of the third block between the time the second block is executed and the termination of the application. Additionally, the third block may be a block used to revert the environment, which was changed by the execution of the second block, back to the environment it was in before the execution of the second block.

[0306] Furthermore, the rules may also be rules that ensure that the above-mentioned two or more predetermined blocks are executed in combination in order to prevent at least one of the actuator 22 and the heater 23 from reaching its durability temperature.

[0307] According to this, it is possible to prevent the actuator 22 and / or heater 23 from reaching their tolerable temperature when the application is executed, thereby improving the safety of the device 20 controlled by the application.

[0308] Furthermore, the device 20, which is the controlled device, includes a housing 21 having an internal space, and the rules may be rules that ensure that the above-mentioned two or more predetermined blocks are executed in combination in order to prevent the internal space from reaching the tolerance temperature.

[0309] According to this, it is possible to suppress the internal space of the enclosure 21 from reaching the tolerance temperature when the application is executed, thereby improving the safety of the device 20 controlled by the application.

[0310] Furthermore, in (c) above, it may be determined whether the generated application is an application dedicated to the controlled device or a general-purpose application applicable to the controlled device and devices other than the controlled device, and a rule candidate corresponding to the determination result of the application may be referenced as a rule from among several rule candidates that prohibit the execution of at least one of the two or more predetermined blocks when one of those two or more predetermined blocks is executed.

[0311] This allows for an increase in application variations, such as dedicated applications and general-purpose applications. Furthermore, since rules appropriate to each variation are referenced, each variation can be appropriately modified for that specific application.

[0312] Furthermore, the information processing method in this embodiment is an information processing method executed by a computer system such as the development tool 50, and may present errors. In other words, the information processing method (a) selects M blocks (M is an integer between 2 and N) from N blocks (N is an integer of 2 or more) for driving at least one of the actuator 22 and heater 23 provided in the device 20, which is the controlled device, as selected blocks in response to an input operation by the operator; (b) generates an application containing at least M selected blocks by setting the execution order of at least each of the M selected blocks in response to an input operation by the operator; (c) refers to a rule that prohibits at least one of the remaining two or more predetermined blocks from not being executed when one of those two or more predetermined blocks is executed, and presents an error to the operator if any of the M selected blocks included in the application fall under that rule; (d) modifies the application in response to an input operation by the operator who has received the error; and (e) outputs the modified application.

[0313] According to this, if an application developer (operator) mistakenly generates an application that executes a block independently that is not permitted to be executed independently, an error will be presented, thus preventing the generation of an application that cannot safely control the device 20. In other words, it can achieve the same effect as when the application is automatically modified as described above.

[0314] Furthermore, in (c) above, multiple solutions to the error may be presented, and in (d) above, the application may be modified by changing the order in which each of the M selection blocks is executed in response to the input operation by the operator who has received the error and the presentation of multiple solutions. In other words, the information processing method in this embodiment is an information processing method that is performed by a computer system such as the development tool 50, and may present an error and multiple solutions at the same time.

[0315] According to this, the effort required for an operator to modify the application after seeing an error message can be reduced.

[0316] Furthermore, these multiple solutions may include at least two of the following: a first solution that adds a new block to the M selected blocks; a second solution that changes the order of the M selected blocks; and a third solution that deletes any of the M selected blocks.

[0317] This allows the user to modify the application while appropriately avoiding errors by following one of several possible solutions. Furthermore, when the user selects a solution, they can choose an option (i.e., a solution) that fulfills their intent in creating the application.

[0318] Furthermore, in (c) above, the effects on the object acted upon by the drive of the actuator 22 or heater 23, or on the application thereof, when each of the multiple countermeasures is performed may be presented. In other words, the information processing method in this embodiment is an information processing method performed by a computer system such as the development tool 50, which presents countermeasures for errors and simultaneously presents the effects on the application when those countermeasures are implemented.

[0319] According to this, when an operator chooses a solution, they can make an intuitive choice that aligns with the intent behind creating the application.

[0320] Furthermore, in this information processing method, after (d) above, steps (c) and (d) above may be repeatedly executed, and if the number of times an error is presented is K or more (where K is an integer greater than or equal to 2), multiple solutions to the error may be presented to the operator.

[0321] According to this, if an error is repeatedly presented, multiple solutions are offered, allowing the user to easily change the execution order of each of the M selection blocks according to those solutions, thus making it easier to create a secure application.

[0322] (Modified version of Embodiment 5) Whether the hardware of device 20 operates safely under an application depends on the environmental conditions of that hardware. Therefore, the rules of the application should be determined to suit the most severe environmental conditions. Consequently, under certain environmental conditions, it may not be possible to fully utilize the hardware's capabilities.

[0323] Therefore, in this modified example, the development tool 50 develops and produces applications for use in the device 20 manufactured by the application creator without using any rules, provided that the application creator is also the device manufacturer. This is because an application creator understands the environmental conditions necessary to safely operate the device 20 manufactured by that application creator. An application creator is a person, group, or company that develops or produces an application, and is also called an application developer. A device manufacturer is a person, group, or company that manufactures or produces equipment such as the device 20, and is also called the manufacturer or producer of the device 20.

[0324] In other words, in this modified example, the development tool 50 develops applications using the rules when the app creator and the device manufacturer are different, and develops applications without using the rules when the app creator and the device manufacturer are the same.

[0325] More specifically, in Embodiment 5, as described above, the application is modified according to the rules during the development or production stage. In this modified example, even at this stage, if the application creator and the device manufacturer are the same, as in Embodiment 3, the modification of the application is skipped.

[0326] Figure 33 is a flowchart showing the processing operation of the development tool 50 in this modified example.

[0327] (Step S51) First, the development tool 50 generates an application by performing functional block placement and parameter setting processes. In other words, the development tool 50 generates an application that includes one or more functional blocks for driving at least one of the actuators and heaters provided in the device 20, which is the controlled device. For example, in step S51, the development tool 50 performs the processes shown in steps S21 to S23 of Figure 23.

[0328] Subsequently, the development tool 50 executes steps S2161B, S2163B, S2164B, S2165, S2166, and S2167, similar to the third embodiment. Specifically, the development tool 50 operates as follows:

[0329] (Step S2161B) The development tool 50 identifies the creator of the application (i.e., the app creator) by obtaining information about the app creator.

[0330] (Step S2163B) The development tool 50 identifies the manufacturer (i.e., the device manufacturer) of the device 20, which is the controlled device, by obtaining device manufacturer information.

[0331] (Step S2164B) The development tool 50 determines whether the application creator and the device manufacturer are different. In other words, the development tool 50 determines whether the application creator and the manufacturer of the controlled device mentioned above are the same.

[0332] (Step S2165) If the app creator and the device manufacturer do not match (Yes in step S2164B), the development tool 50 retrieves rules for one or more blocks included in the application.

[0333] (Step S2166) The development tool 50 determines whether one or more functional blocks included in the application meet the rule.

[0334] (Step S2167) If the development tool 50 determines that one or more of those functional blocks meet a rule (Yes in step S2166), it modifies the application according to that rule.

[0335] (Step S52) The development tool 50 performs an append process to the application if the application creator and the device manufacturer are the same person (No. in step S2164B). In the append process, the development tool 50 appends first append information and at least one of the second and third append information to the application. The first append information indicates that no rules apply to the application. The second append information indicates when the application was created. For example, the second append information indicates the date the application was created. This date is also referred to as the application creation date. The third append information is manufacturer identification information to identify the manufacturer if the application creator is the device manufacturer.

[0336] (Step S53) After processing in step S2167, the development tool 50 outputs the modified application. On the other hand, after processing in step S52, the development tool 50 outputs the application with added processing. In other words, if the application creator and the device manufacturer are the same (No. in step S2164B), the development tool 50 outputs the application with added information without applying the rules to the application.

[0337] Thus, the information processing method in this modified example is an information processing method executed by a computer system such as the development tool 50. This information processing method generates an application that includes one or more blocks for driving at least one of the actuators and heaters provided in the controlled device, identifies the creator of the application, identifies the manufacturer of the controlled device, determines whether the creator of the application and the manufacturer of the controlled device are the same, (a) if the creator of the application and the manufacturer of the controlled device are not the same, obtains rules for one or more blocks included in the application, modifies the application according to those rules, and outputs the modified application, and (b) if the creator of the application and the manufacturer of the controlled device are the same, outputs the application without applying the rules to the application.

[0338] Therefore, in this modified example, if the application creator and the device manufacturer are different, the application is modified by applying the rules to the application, thus achieving the same effect as in Embodiment 5. Furthermore, if the application creator and the device manufacturer are the same, the application of rules and modification of the application are omitted, as in Embodiment 3, thus reducing the processing load. Moreover, in that case, the hardware of the device 20, which is the controlled device, operates with the application to which the rules are not applied, so the functions of that hardware can be effectively utilized.

[0339] Furthermore, in (b) above, the information processing method in this modified example, an additional processing step is performed to add the first additional information and at least one of the second and third additional information to the application. The output of the application is the application after the additional processing has been performed. Here, the first additional information is information indicating that no rules have been applied to the application, and the second additional information is information indicating when the application was created. The third additional information is information for identifying the manufacturer if the creator of the application is the manufacturer of the equipment.

[0340] Therefore, in this modified example, if no rules are applied to the application, device 300 of the controlled device 20 acquires the application with added information.

[0341] For example, if an application has first and second additional information attached to it, device 300 can determine whether or not to apply a rule to the application because the first additional information is attached to the application. Specifically, device 300 can appropriately determine whether or not to apply the rule based on the second additional information attached to the application. For example, device 300 can identify the rule's update date, and if that update date is before the application creation date indicated by the second additional information, it can determine that the rule should not be applied to the application. As a result, device 300 can avoid both applying the rule and modifying the application. In other words, similar to the development tool 50, device 300 can also reduce its processing load.

[0342] On the other hand, device 300 can determine that if its update date is later than the application creation date, it should apply the updated rules to the application. In other words, if the generated application is outdated, it may be difficult to guarantee the security of device 20 if it operates using that outdated application. However, in such cases, the second additional information will apply the rules to the outdated application, and the application will be modified. Therefore, the security of device 20 can be easily guaranteed.

[0343] Furthermore, even if the application has first and third additional information attached to it, the device 300 can determine whether or not to apply the rule to the application because the first additional information is attached to the application. Specifically, the device 300 can appropriately determine whether or not to apply the rule based on the third additional information attached to the application. For example, the device 300 determines whether or not the manufacturer of the apparatus 20, which includes the device 300, matches the manufacturer identified by the third additional information, which is manufacturer identification information. If the device 300 determines that the manufacturers match, it can then determine not to apply the rule to the application. As a result, the device 300 can avoid both applying the rule and modifying the application. In other words, similar to the development tool 50, the device 300 can also reduce the processing load.

[0344] On the other hand, if device 300 determines that the manufacturers do not match, it can decide to apply the rule to the application. For example, a generated application may be used not only on device 20, which is a controlled device manufactured by the application developer, but also on device 20 manufactured by other device manufacturers. When device 20 manufactured by other device manufacturers operates using that application, it may be difficult to guarantee the safety of device 20. However, in such cases, the rule is applied to the application by the third additional information, and the application is modified. Therefore, the safety of device 20 manufactured by other device manufacturers can be easily guaranteed.

[0345] In the example described above, device 300 applies rules and modifies the application based on the information attached to the application. However, as in embodiments 1 to 4, a device manager 200 or the like may apply rules and modify the application based on the information attached to the application instead of device 300.

[0346] (Other embodiments) Although a system relating to one or more embodiments of this disclosure has been described above based on embodiments, this disclosure is not limited to these embodiments. Without departing from the spirit of this disclosure, various modifications to these embodiments that a person skilled in the art could conceive of, or forms constructed by combining components from different embodiments, may also be included within the scope of one or more embodiments of this disclosure.

[0347] Furthermore, in each of the above embodiments, the sequence manager 100 and the device manager 200 were included in the cloud server 10, but are not limited to this. The sequence manager 100 and / or the device manager 200 may be included in the device 20. Also, the UI 400 was included in the terminal 30, but may be included in the device 20.

[0348] Furthermore, in each of the above embodiments, the application may be modified based on the degradation information. For example, device 300 may refer to parameter conversion information, which associates a plurality of degradation levels with a plurality of parameter conversion methods, to obtain a conversion method corresponding to a degradation level, and use the obtained conversion method to convert the parameters included in the block. The conversion method may be defined, for example, by the converted value, or by a coefficient applied to the value before conversion.

[0349] Furthermore, in each of the above embodiments, the application was modified during pre-execution verification and then executed, but this is not the only way. For example, if the state of device 300 is different from what was expected, the application may not be modified, and the device manager 200 and / or sequence manager 100 may be notified of execution termination (error). [Industrial applicability]

[0350] It can be used in home appliances that can execute applications defined by multiple functional blocks, and in devices that generate such applications. [Explanation of Symbols]

[0351] 1 System 2a, 2b, 2c, 2d facilities 10 Cloud Servers 11 processors 12 memory 20, 20a, 20b, 20c, 20d, 20e, 20f, 20g, 20h equipment 21 cabinets 22 Actuators 23 Heater 24 Control Unit Terminals 30, 30a, 30b, 30c, 30d 31 displays 32 Input Devices 41 Block Databases 42, 1300 Rule Database 50 Development Tools 51 processors 52 memory 53 displays 54 Input section 60 application delivery servers 100 Sequence Manager 200 Device Manager 300, 300a, 300b, 300c, 300d, 300e, 300f, 300g, 300h devices 400, 400a, 400b, 400c, 400d UI 1000, 1201 blocks Parameters 1001, 1002, 1003, 1004, 1005, 1006 1100 Device Database 1101 Device Information 1200 Declaration of Execution Content 1202 Device Information 1203 Order Information 1301, 1302 Rules 2000 Information Processing Systems C1-C5 Solutions D1 Parameter setting area D2 Block List Area D3 Target device area D4 Selected block area E1, E2 Error Messages F100 Preparation Phase F200 App Pre-Execution Phase F300 Application Execution Phase Rules specific to R11-R13, R21-R23, R31-R33, and R41-R43. R100, R200, R300, R400 General Rules

Claims

1. An information processing method performed by a computer system, (a) An application including the M blocks is generated by setting the execution order of each of the M blocks (where M is an integer of 1 or more) for driving at least one of the actuators and heaters provided in the controlled device, in accordance with the operator's input. (b) Referencing a rule that prohibits at least one of the remaining two or more predetermined blocks from being executed when one of the two or more predetermined blocks is executed, if the M blocks included in the application fall under the rule, an error is presented to the operator. Furthermore, at least one way to deal with the aforementioned error, This document presents the effects on the object acted upon by the operation of the actuator or heater, or on the application, when the aforementioned countermeasures are implemented. Information processing methods.

2. The aforementioned information processing method further includes, (c) In response to an input operation by the operator who has received the error, the application is modified. The information processing method according to claim 1.

3. In (b) above, further, The remaining at least one of the two or more predetermined blocks is presented as a method for dealing with the error. The information processing method according to claim 1.

4. In (a) above, each time the order of one of the M blocks is set according to the input operation by the operator, the process in (b) above is performed. The information processing method according to claim 1.

5. The above (b) further states that there are multiple ways to deal with the error, A first method of adding new blocks to the aforementioned M blocks, A second method for changing the order of the aforementioned M blocks, We present at least two of the following: a third method of dealing with the situation, which involves deleting any of the M blocks mentioned above. The information processing method according to claim 1.

6. The above (b) further states that, as a method for dealing with the error, The presenter offers either to change the order of the M blocks or to delete any of the M blocks. The information processing method according to claim 1.

7. Processor and The processor is connected to a memory, The processor uses the memory to: (a) An application including the M blocks is generated by setting the execution order of each of the M blocks (where M is an integer of 1 or more) for driving at least one of the actuators and heaters provided in the controlled device, in accordance with the operator's input. (b) Referencing a rule that prohibits at least one of the remaining two or more predetermined blocks from being executed when one of the two or more predetermined blocks is executed, if the M blocks included in the application fall under the rule, an error is presented to the operator. Furthermore, at least one way to deal with the aforementioned error, This document presents the effects on the object acted upon by the operation of the actuator or heater, or on the application, when the aforementioned countermeasures are implemented. Information processing device.

Citation Information

Patent Citations

  • System for preparing operational procedure of device, recording medium with its operational procedure and control system recorded thereon

    JP2001147704A

  • Washing machine

    JP2003284889A

  • Software development support system, development support method, and program

    JP2010102362A

  • Device and method for supporting creation of flow using visual programming tool

    JP2020042679A

  • Program, method, and apparatus for assisting creation of business model chart

    WO2006033159A1