Method for displaying the setting support device, setting support program, and safety-related parameter group.

JP7926698B2Active Publication Date: 2026-09-30DENSO WAVE INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2022106792
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-07-01
Publication Date
2026-09-30
Estimated Expiration
2042-07-01

AI Technical Summary

Benefits of technology

【0016】 第4の手段に示す構成によれば、安全性の向上と生産性の向上とを両立させつつ、ユーザの設定ミスを好適に抑制できる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007926698000001
    Figure 0007926698000001
  • Figure 0007926698000002
    Figure 0007926698000002
  • Figure 0007926698000003
    Figure 0007926698000003
Patent Text Reader

Abstract

To suppress setting errors related to a safety function, while achieving improvement of safety of a robot and improvement of workability.SOLUTION: A plurality of scenes that is a safety-related parameter group is set in a control device of a robot, and a logic part of a safety-related part determines a movement of the robot with reference to any one of the scenes. In the case of reaching a "CHANGE SCENE" command included in a control program during drive control of the robot on the basis of the control program, the scene as a reference object is switched on the basis of establishment of a switching condition including a position condition of the robot. The control device is connected with a PC for supporting setting of each of the scenes by a user, and the PC displays the safety-related parameter group on a parameter display part D2 of a scene parameter setting screen WD. A display pattern of the safety-related parameter group on the parameter display part D2 is switchable between a main item display and a total item display.SELECTED DRAWING: Figure 12
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a setting support device, a setting support program, and a display method for a safety-related parameter group. [Background Art]

[0002] Some robot control systems applied to robots such as industrial robots include a safety-related section that implements the safety function of the robot and a non-safety-related section that performs drive control of the robot, etc. For the safety-related section, for example, there have been proposed ones that forcibly stop the robot when an obstacle such as a person collides with it (see, for example, Patent Document 1), or forcibly stop the robot when the movement of the driven robot exceeds safety standards by monitoring its force (thrust) and speed. [Prior Art Literature] [Patent Literature]

[0003] [Patent Document 1] Japanese Patent No. 4240517 [Summary of the Invention] [Problem to be Solved by the Invention]

[0004] In recent years, advances in robotics technology have led to an increasing number of tasks that a single robot can perform. When a single robot is used for various tasks, a uniform approach to safety functions makes it difficult to achieve both improved robot safety and increased productivity (work efficiency). In light of these circumstances, the inventors of this invention have devised a configuration that switches the robot's safety functions according to the work content. Here, in order to suppress the impairment of safety functions due to communication errors during the change, it is preferable to use input from a safety-related input unit (so-called safety input) for changing safety functions. However, if safety input is made a mandatory requirement, the constraints on changes will become stronger, which is expected to hinder improvements in the operability of changing safety functions. On the other hand, if this requirement is simply avoided, improved operability can be expected, but there are concerns that confidence in the robot's safety functions will be undermined. Thus, there is still room for improvement in the configuration for changing safety functions in order to improve both the safety and work efficiency of robots.

[0005] Furthermore, in order to improve both safety and productivity, it is effective to provide various safety-related parameters that affect safety functions, enabling detailed consideration of work content and other factors. Here, if a configuration is set up to support the user in setting a group of safety-related parameters (scenes) using a setting support device, the user's workload can be reduced. However, if the number of configurable items increases, it becomes difficult for the user to identify the necessary items. This is undesirable in terms of improving the efficiency of the setting work and can also be a factor in setting errors of safety-related parameters. Thus, in order to improve the safety and workability of robots while suppressing setting errors related to safety functions, there is still room for improvement in the configuration related to setting these safety functions.

[0006] This invention has been made in view of the problems exemplified above, and its main objective is to improve the safety and workability of robots while suppressing errors in setting safety functions. [Means for solving the problem]

[0007] The following describes the means to solve the above problems.

[0008] The first means: A setting support device applied to a robot control system configured to drive and control a robot according to each operation instruction constituting a control program for the robot; an operation determination unit having a safety-related input signal that includes correlation information correlated with at least one of the force and speed of the robot during drive control and a determination criterion for the correlation information stored in advance, which determines the movement of the robot and realizes the safety function of the robot by generating a safety-related output signal according to the determination result, wherein multiple scenes are set, which are groups of safety-related parameters that include the determination criterion as safety-related parameters that affect the safety function, and the operation determination unit is configured to make the determination by referring to one of these scenes, and when a switching instruction for the scene included in the control program is reached during drive control of the robot based on the control program, the referenced scene is switched based on the fulfillment of a predetermined switching condition, and the setting support device assists the user in setting each of the safety-related parameters for each of the scenes. Display unit and The display unit includes a display control unit that displays a parameter setting screen corresponding to the scene specified by the user. Equipped with, The parameter setting screen is provided with two display modes for the safety-related parameter group: a first display mode that displays both the first parameter group and the second parameter group that constitute the safety-related parameter group, and a second display mode that displays only the first parameter group from the first and second parameter groups.

[0009] As shown in the first method, by incorporating scene switching instructions (safety-related parameter sets) into the robot's control program, and enabling scene switching during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to the situation. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the scene is switched automatically, the scene may be switched due to accidental factors such as noise, resulting in a mismatch between the actual situation and the scene. This is a concern as it may hinder the proper performance of safety functions. In this feature, when a switching instruction is reached in the control program, the scene is switched only if predetermined switching conditions are met. This suppresses scene switching that deviates from the user's intention and reduces the occurrence of the aforementioned mismatch.

[0010] Here, if the number of safety-related parameters that users can set for each scene increases, safety functions can be finely modified according to the work content, etc. This is desirable in achieving both improved safety and improved productivity. However, if the number of configurable items increases, it becomes more difficult for users to identify the items they need. This is undesirable in terms of streamlining the setting process and can also lead to errors in setting safety-related parameters. In this regard, the configuration shown in the first means provides two display modes for the safety-related parameter group on the parameter setting screen: a first display mode (all items display) that displays both the first parameter group and the second parameter group that constitute the safety-related parameter group, and a second display mode (main items display) that displays only the first parameter group from the two parameter groups. In the second display mode, the display target is limited to the first parameter group, making it easier for users to narrow down the necessary items. On the other hand, in the first display mode, both the first parameter group and the second parameter group are displayed (configurable), making it possible to set and check individual safety-related parameters. Providing two display modes in this way is desirable because it allows for both improved safety and increased productivity while suppressing user configuration errors.

[0011] A second means: A setting support device applied to a robot control system configured to drive and control the robot according to each operation instruction constituting a control program for the robot, and an operation determination unit that determines the movement of the robot based on a safety-related input signal containing correlation information correlated with at least one of the force and speed of the robot during drive control and a determination criterion for the correlation information stored in advance, and realizes the safety function of the robot by generating a safety-related output signal according to the determination result, wherein multiple scenes are set, which are groups of safety-related parameters that include the determination criterion as safety-related parameters that affect the safety function, and the operation determination unit is configured to make the determination by referring to one of these scenes, and when a switching instruction for the scene included in the control program is reached during drive control of the robot based on the control program, the referenced scene is switched based on the fulfillment of a predetermined switching condition, and the setting support device assists the user in setting each of the safety-related parameters for each of the scenes, Display unit and The display unit includes a display control unit that displays a parameter setting screen corresponding to the scene specified by the user. Equipped with, The parameter setting screen is provided with two display modes for the safety-related parameter group: a first display mode that displays both the first parameter group and the second parameter group that constitute the safety-related parameter group, and a second display mode that displays only the first parameter group from the first and second parameter groups.

[0012] The configuration shown in the second method allows for both improved safety and increased productivity while effectively suppressing user setting errors.

[0013] A third means. A setting support program installed on a computer that can be connected to a robot control device, which is configured to switch the referenced scene when a switching instruction for the scene included in the control program is reached during the robot's drive control based on a predetermined switching condition including a position condition defining the robot's position, and which enables the user to set each of the safety-related parameters for each of the scenes, wherein multiple scenes are set, which are groups of safety-related parameters that include the judgment criteria as safety-related parameters that affect the safety function, and the operation determination unit makes the determination by referring to one of the scenes, and the robot control device is configured to switch the referenced scene when a switching instruction for the scene included in the control program is reached during the robot's drive control based on the control program, based on the fulfillment of a predetermined switching condition including a position condition defining the robot's position, and which enables the user to set each of the safety-related parameters for each of the scenes, The display unit displays a parameter setting screen corresponding to the scene specified by the user. The display modes for the safety-related parameter group in the parameter setting screen are defined as follows: a first display mode that displays both the first parameter group and the second parameter group constituting the safety-related parameter group, and a second display mode that displays only the first parameter group from the first and second parameter groups. Based on a user's switching operation, the display mode is switched between the first display mode and the second display mode.

[0014] The configuration shown in the third method allows for both improved safety and increased productivity while effectively suppressing user setting errors.

[0015] A fourth means. A method for displaying a group of safety-related parameters, which is applied to a robot control system configured such that when a switching instruction for the scene included in the control program is reached during the robot's drive control based on the control program, a switching instruction for the scene included in the control program is reached, and a predetermined switching condition including a position condition defining the robot's position is met, the referenced scene is switched. The method displays a group of safety-related parameters that are set when a user sets or confirms each of the safety-related parameters that constitute each of the scenes. The display unit shows a parameter setting screen corresponding to the scene specified by the user. The display of the safety-related parameter group on the parameter setting screen is switched based on the user's switching operation between a first display that shows both the first parameter group and the second parameter group that constitute the safety-related parameter group, and a second display that shows only the first parameter group out of the first and second parameter groups.

[0016] The configuration shown in the fourth method allows for both improved safety and increased productivity while effectively suppressing user setting errors. [Brief explanation of the drawing]

[0017] [Figure 1] A schematic diagram showing a factory in the first embodiment. [Figure 2] Side view of the robot. [Figure 3] Block diagram showing the electrical configuration of a robot system. [Figure 4] Schematic diagram showing the work routine of a robot. [Figure 5] Schematic diagram showing the relationship between a safety-related part and a non-safety-related part. [Figure 6] (a) Flowchart showing motion monitoring processing, (b) Schematic diagram contrasting determination criteria set for each work scene. [Figure 7] Schematic diagram illustrating an example of a control device that instructs switching of safety functions. [Figure 8] Schematic diagram illustrating an example of switching positions for safety functions. [Figure 9] Schematic diagram showing the flow of a scene change sequence. [Figure 10] Schematic diagram showing items of safety-related parameters in the second embodiment. [Figure 11] Schematic diagram illustrating an example of a main scene setting screen. [Figure 12] Schematic diagram illustrating an example of a main scene setting screen. [Figure 13] Schematic diagram illustrating an example of a setting screen for special scene 1. [Figure 14] Schematic diagram illustrating an example of a setting screen for special scene 2. [Figure 15] Schematic diagram showing a simulation screen in the third embodiment. [Figure 16] Schematic diagram illustrating an example of a flow of program creation. [Figure 17] Schematic diagram contrasting handling methods when a position condition is not satisfied during scene switching. [Figure 18] Flowchart showing the flow of a scene change sequence in simulation. [Figure 19] Schematic diagram illustrating an example of a part of a simulation flow. [Figure 20] Flowchart showing a modified example of a scene change sequence in simulation. [Figure 21] Schematic diagram showing a modified example related to simulation. [Figure 22] A schematic diagram to explain the problem. [Figure 23] A schematic diagram illustrating the settings screen in the fourth embodiment. [Figure 24] A flowchart illustrating the transmission process. [Figure 25] A schematic diagram showing a message box for sending confirmation. [Figure 26] A schematic diagram showing the structure related to the display of names. [Figure 27] A schematic diagram showing the configuration related to the naming of the fifth embodiment. [Figure 28] A schematic diagram showing the types of unique information. [Figure 29] A flowchart illustrating the transmission process. [Figure 30] (a) A schematic diagram comparing the serial number and the name, (b) A schematic diagram showing the name structure in the sixth embodiment. [Figure 31] A schematic diagram illustrating the role of each part that makes up the name. [Figure 32] A schematic diagram showing a manual operation scene in the seventh embodiment. [Figure 33] (a) Schematic diagram showing the control mode, (b) Schematic diagram showing the status of safety-related parts. [Figure 34] A schematic diagram illustrating the scene switching process when an error is resolved. [Figure 35] A schematic diagram showing a variation of the robot system. [Modes for carrying out the invention]

[0018] <First Embodiment> The following describes a first embodiment of a robot system used in factories and other industrial settings, with reference to the drawings. First, with reference to Figure 1, we will describe a factory to which this robot system is applied.

[0019] One section of the factory 10 is provided with a stock area E1 where shelves 12 for storing materials transported to that section by a conveyor 11 and shelves 13 for storing empty containers B are arranged; a processing area E2 where various processing machines 14 for shaping workpieces are arranged; a collection area E3 for accumulating shaped workpieces; a receiving area E4 for receiving materials transported from the conveyor 11; and a passageway E5 connecting these areas E1 to E4. The industrial robot 16 shown in this embodiment (hereinafter referred to as robot 16) moves between areas E1 to E4 via passageway E5 and engages in predetermined tasks at each location.

[0020] As shown in Figure 2, the robot 16 comprises an AGV (Automated Guided Vehicle) 21, a vertical articulated robot arm 31 mounted on the AGV 21, and a control device 51 (see Figure 3) that controls the AGV 21 and the robot arm 31.

[0021] The AGV 21 is equipped with a travel motor 25 and a magnetic sensor 26 that detects magnetism from guide tapes for magnetic induction provided on the floor (see Figure 3). The control device 51 controls the movement of the AGV 21, such as controlling the drive of the travel motor 25 and steering, based on the magnetism detected by the magnetic sensor 26. In this embodiment, guide tapes are arranged in areas E1 to E4 and the passage E5 so as to connect areas E1 to E4, and the movement path (travel route) of the robot 16 is defined by these guide tapes.

[0022] A table 22 on which container B is placed is formed on the top surface of the AGV 21's body, and the AGV 21 can move around the factory 10 with container B on the table 22. The AGV 21 is also equipped with a scanner 27 that can detect obstacles in the path of the robot 16 and an emergency stop switch 28 that can be operated by a worker in an emergency. These scanner 27 and emergency stop switch 28 function as input units for the safety-related section described later, and are configured to perform an emergency stop (a so-called protective stop) on the robot 16 if an obstacle is detected or an emergency stop operation is detected.

[0023] The robot arm 31 has a base 32 fixed to the upper surface of the AGV 21 body (next to the table 22), an arm body 33 attached to the base 32, and a hand 34 provided at the tip (end-effector) of the arm body 33. The hand 34 can be replaced with other end effectors such as tools depending on the task the robot 16 is performing.

[0024] The arm body 33 is made up of multiple movable parts connected together, and each joint is equipped with a drive motor 35 to drive the movable part, a rotary encoder 36 to detect the rotation angle of each joint (axis), and a torque sensor 37 to detect the rotation torque of each joint (axis) (see Figure 3). As shown in Figure 3, the drive motors 35, rotary encoders 36, and torque sensors 37 are connected to a control device 51, and the drive control unit 52 of the control device 51 controls each drive motor 35 based on the rotation angle detected by the rotary encoder 36, etc.

[0025] The control device 51 can be connected to a personal computer (hereinafter referred to as PC60) and a teaching pendant 70 by wire or wireless connection. The control unit 62 of the PC60 has software installed for creating control programs for the robot 16, backing up data from the control device 51, and simulating control programs using a 3D model of the robot 16. The teaching pendant 70 has a setting support application installed to assist the user in setting the movements of the robot 16 (including so-called teaching). For example, the control program created on the PC60 is transmitted to the control device 51, and the drive control unit 52 of the control device 51 controls the drive of the AGV 21 and the robot arm 31 based on the control program. In other words, the work content and work sequence of the robot 16 are defined by this control program. The content of the work and the workflow (routine) of the robot 16 shown in this embodiment will be described below with reference to Figures 1 and 4.

[0026] Robot 16 first sets an empty container B on itself in the stock area E1 (work scene SCN1). Specifically, it extends its robot arm 31 to grasp the empty container B stored on the shelf 13 and places the container B on its table 22. After that, it returns the robot arm 31 to the standby position and moves to the processing area E2 via the passage E5 (work scene SCN2). Note that the robot arm 31 in the standby position is configured so that it does not protrude from the AGV 21 when viewed from above.

[0027] In the processing area E2, workpieces that have been processed are collected from the various processing machines 14 arranged in the processing area E2 (work scene SCN3). Specifically, the robot arm 31 is extended to grasp the workpiece held in the chuck, etc., of the processing machine 14 with the hand 34, and the workpiece is picked up and placed in container B on the table 22. This picking operation is repeated, and collection is completed when the number of collected workpieces reaches a predetermined number. After collection is complete, the robot arm 31 is returned to the standby position, and container B containing the workpieces is transported through passage E5 to the accumulation area E3 (work scene SCN4).

[0028] In the collection area E3, container B is unloaded. Specifically, container B is stacked on pallet 15 (so-called palletizing) (work scene SCN5). The stacked container B on pallet 15 is then transported sequentially to the next process (for example, another processing process).

[0029] Incidentally, if, in the above work scene SCN3, workpieces pile up in container B due to accidental factors, it is assumed that stacking container B in work scene SCN5 will become difficult. The robot arm 31 shown in this embodiment is equipped with a camera (not shown), and the control device 51 can check the state of workpiece storage in container B from the image taken inside container B. In work scene SCN4, the robot arm 31 performs the task of leveling the piled-up workpieces in container B as needed.

[0030] After unloading in the collection area E3, robot 16 returns its robot arm 31 to a standby position and moves from the collection area E3 to the receiving area E4, the end of the conveyor belt 11, via passageway E5 (work scene SCN6). Then, it receives container B containing the workpiece materials from the conveyor belt 11 (work scene SCN7). Specifically, container B is set on table 22 by a crane attached to the conveyor belt 11. At this time, robot arm 31 temporarily changes direction to avoid collision with the crane or container B.

[0031] Robot 16, having received container B, transports container B through passage E5 to stock area E1 (work scene SCN8). After reaching stock area E1, it stores the set container B on shelf 12 (work scene SCN9).

[0032] After storage is complete, the work scenes SCN1 to SCN9 are repeated. Thus, the work routine of the robot 16 in this embodiment is constructed by work scenes SCN1 to SCN9. Depending on the operating status of the conveyor 11, work scenes SCN7 to SCN9 may be skipped.

[0033] In work scenes SCN1 to SCN9, not only are the area where the robot 16 is located and the specific content of the work different, but the relationship with humans (whether or not there is collaboration, etc.) also differs. For example, stock area E1, which corresponds to work scene SCN1 (container acquisition), and processing area E2, which corresponds to work scene SCN3 (picking), are collaborative areas where area managers (people) work together with the robot 16. Specifically, the tasks of taking materials from container B stored on shelves 12 and feeding them into processing machines 14, setting up each processing machine 14, and checking the operation of each processing machine 14 are the roles of the area managers in stock area E1 and processing area E2, while the task of collecting the processed workpieces, including the acquisition of empty container B, is the role of the robot 16. In other words, in stock area E1 and processing area E2, the work is divided between the area managers and the robot 16.

[0034] For work scenes SCN2, SCN4, and SCN6, the work area is specified to be passageway E5, while for work scene SCN5 (palletizing), the work area is specified to be accumulation area E3. Work scenes SCN2, SCN4, SCN5, and SCN6 differ from work scenes SCN1 and SCN3 in that they all involve robot 16 working alone (non-collaborative work). However, while people (area personnel, etc.) are allowed to pass through passageway E5, people are generally prohibited from entering accumulation area E3. In other words, there is a difference in the possibility of contact between robot 16 and people between work scenes SCN2, SCN4, and SCN6 and work scene SCN5 due to the difference in area operation. Specifically, the possibility of contact between people and robot 16 is higher in work scenes SCN2, SCN4, and SCN6 than in work scene SCN5.

[0035] Thus, one of the features of the robot 16 is that it may come into contact with people during its work routine, and in addition to the scanner 27 and emergency stop switch 28 mentioned above, it is equipped with other features that enhance the safety of the robot 16. Below, with reference to Figure 5, the configurations related to the safety functions of the robot 16 will be explained in more detail.

[0036] The control system CS applied to the robot 16 is divided into a safety-related unit PX that realizes the safety functions of the robot 16 by outputting safety-related output signals in response to safety-related input signals, and a non-safety-related unit PY that performs drive control of the AGV 21 and robot arm 31 when safety has been confirmed by the safety-related unit PX and the operation of the AGV 21 and robot arm 31 is permitted.

[0037] The safety-related unit PX consists of an input unit X1 that receives the safety-related input signals, a logic unit X2 that performs safety checks, and an output unit X3 that outputs safety-related output signals. In this embodiment, the scanner 27 and the emergency stop switch 28 correspond to the input unit X1, the monitoring and control unit (safety controller) 53 provided in the control device 51 corresponds to the logic unit X2, and the safety contactor attached to the control device 51 corresponds to the output unit X3.

[0038] The safety contactor is connected to switches in the drive circuit for the AGV21's travel motor 25 and to switches in the drive circuit for the robot arm 31's drive motor 35. When the safety contactor outputs a safety-related output signal to these switches, the power supply to each motor 25 and 35 is cut off, and the robot 16 is forcibly stopped.

[0039] The safety-related unit PX shown in this embodiment includes the rotary encoder 36 and torque sensor 37 in addition to the scanner 27 and emergency stop switch 28. In other words, detection signals from the rotary encoder 36 and torque sensor 37 are input to the logic unit X2 as safety-related input signals. The logic unit X2 monitors the operation of the robot 16 based on the detection signals from the rotary encoder 36 and torque sensor 37. Now, referring to Figure 6(a), the operation monitoring process performed as part of periodic processing in the logic unit X2 (monitoring control unit 53 of the control device 51) will be described.

[0040] In the motion monitoring process, first, the speed, force (thrust), and position (coordinates) of the end-effector (so-called tool center point) of the robot 16 (robot arm 31) are determined based on the detection signal from the rotary encoder 36 and the detection signal from the torque sensor 37 (step S101).

[0041] Next, it is determined whether the current end-effector speed is less than the speed monitoring reference value (speed threshold or upper limit) stored in the memory of the control device 51 (step S102). If the end-effector speed is less than the monitoring reference value, it is determined whether the current end-effector force is less than the force monitoring reference value (force threshold or upper limit) stored in the memory of the control device 51 (step S103). If the end-effector force is less than the monitoring reference value, it is determined whether the current end-effector position is within the monitoring reference area (operational tolerance range) stored in the memory of the control device 51 (step S104). If the end-effector position is within the monitoring reference area, that is, if all three of the above-mentioned criteria are met, the operation is considered to be performed correctly, and this operation monitoring process is terminated. In the following explanation, each monitoring reference value and monitoring reference area will also be referred to as the "criteria".

[0042] On the other hand, if any of the three criteria mentioned above are not met, the emergency stop and abnormality notification processes are executed (step S105), and the operation monitoring process is terminated. In the emergency stop process, the power supply to the motors 25 and 35 is forcibly cut off to stop the robot 16 (hereinafter also referred to as an emergency stop). In the abnormality notification process, a warning lamp provided on the robot 16 is turned on, and information that an abnormality has occurred is sent to the factory 10's management system. Thus, in this embodiment, the force, speed, and position of the robot 16's end effector are parameters for monitoring the robot 16's operation. In the following description, these force, speed, and position parameters, specifically the parameters input to the logic unit X2 from the rotary encoder 36 and torque sensor 37, will also be referred to as "monitoring parameters".

[0043] Furthermore, the monitoring parameters are not limited to the force, speed, and position parameters of the robot's end effector 16. Alternatively, or in addition to these, parameters indicating the force (rotational torque), speed (rotational velocity), and position of each joint (axis) can also be used as monitoring parameters.

[0044] Furthermore, in this embodiment, the judgment criteria for the monitoring parameters also function as targets for suppressing (limiting) the movement of the robot arm 31 (more specifically, the end effector). For example, when a user directly touches the robot arm 31 to teach the robot 16 a movement, the robot arm 31 may be pushed and pulled by momentum, potentially setting a movement that exceeds the judgment criteria. Even in such cases, the movement of the robot arm 31 is limited to stay within the range that does not exceed the judgment criteria, thereby suppressing frequent emergency stops caused by exceeding the judgment criteria during operation.

[0045] As mentioned above, when the robot 16 is used for various tasks, it is assumed that uniform safety functions would make it difficult to achieve both improved safety and improved productivity. In this embodiment, taking these circumstances into consideration, the safety functions of the robot 16, specifically the judgment criteria for each monitoring parameter, can be switched according to the work scene. In other words, the judgment criteria shown in this embodiment are variable parameters (also referred to as safety-related parameters in the following description).

[0046] For example, as shown in Figure 6(b), in the "picking" operation of work scene SCN3, the criteria for monitoring speed parameters is 150 mm / s, the criteria for monitoring force parameters is 100 N, and the criteria for monitoring position parameters is the upper region of AGV31 + the outer region of AGV31 considering the workpiece picking operation (the outer region in a plan view of robot 16). In this case, robot 16 will be brought to an emergency stop if any of the following conditions are met: the end-effector speed exceeds 150 mm / s, the end-effector force exceeds 100 N, or the end-effector position moves outside the upper region + outer region of AGV31.

[0047] In contrast, in the "Transport (1)" work scene SCN4, the criteria for monitoring speed parameters is 200 mm / s, the criteria for monitoring force parameters is 150 N, and the criteria for monitoring position parameters is the area above the AGV 31. In this case, the robot 16 will be brought to an emergency stop if any of the following conditions are met: the speed of the end-effector exceeds 200 mm / s, the force of the end-effector exceeds 150 N, or the position of the end-effector moves outside the above-mentioned area above the AGV 31 (when the robot arm 31 extends beyond the AGV 31 in a plan view).

[0048] Furthermore, in the "palletizing" operation of work scene SCN5, the criteria for monitoring speed parameters is 100 mm / s, the criteria for monitoring force parameters is 300 N, and the criteria for monitoring position parameters is the upper region of AGV31 + the outer region of AGV31 considering the palletizing operation (the outer region in a plan view of robot 16). In this case, robot 16 will be brought to an emergency stop if any of the following conditions are met: the end-effector speed exceeds 100 mm / s, the end-effector force exceeds 300 N, or the end-effector position moves outside the upper region + outer region of AGV31.

[0049] Three control devices are provided that allow the safety functions of the safety-related unit PX to be switched: (1) teaching pendant 70, (2) drive control unit 52 (see PackScript for details), and (3) external general-purpose input / output 80 (hereinafter referred to as IO80) (see Figure 5). All three of these control devices correspond to the non-safety-related unit PY. Now, with reference to Figure 7, the configuration related to the switching of safety functions will be explained.

[0050] The teaching pendant 70 has an application installed for switching safety functions. When the user performs a safety function switching operation, i.e., a work scene switching operation, a scene change sequence is executed by the teaching pendant 70, which is a non-safety-related unit PY, and the safety FPGA (Field Programmable Gate Array) of the safety-related unit PX to switch the safety function. As will be described in detail later, in this scene change sequence, a command (request command) instructing the switching of safety functions and diagnostic information (CRC) to diagnose whether the command was sent and received successfully are sent to the safety FPGA of the safety-related unit PX. Based on this command, the safety FPGA switches the judgment criteria for monitoring parameters. Note that the specific configuration of the logic unit X2 of the safety-related unit PX is not limited to a safety FPGA, and can also be a microcontroller or CPU.

[0051] IO80 is connected to sensors and the factory control center 10 for communication, and safety functions can be switched from external devices other than the teaching pendant 70. In other words, the scene change sequence is initiated by a signal from IO80.

[0052] Furthermore, the control system CS shown in this embodiment employs a configuration that allows the control device 51 to actively switch safety functions based on its judgment. Specifically, during the automatic operation of the robot 16, the judgment criteria for monitoring parameters are switched according to the work scene. Specifically, in the control program for the robot 16, the movement of the robot 16 in the work scene is defined by a combination of multiple motion control commands. In addition to these motion control commands, there is a safety function switching command for switching safety functions, specifically a "CHANGE SECEN" command for executing a scene change sequence. This "CHANGE SECEN" command includes information indicating the target work scene (scene number, described later) as information on how to set the safety functions. In other words, the user can specify the target work scene using the "CHANGE SECEN" command when creating the control program. After the scene change sequence is started, the execution of the next task, i.e., the progress of the control program, is interrupted until the scene change sequence is completed.

[0053] Here, the motion control command includes a command that specifies the destination of the robot 16, and this command moves the robot 16 to a predetermined control point in the next work area (the first control point in this embodiment). In the control program, the above-mentioned "CHANGE SECEN" command is written after this command, and after the process of moving the robot 16 to the predetermined control point is executed, the "CHANGE SECEN" command starts the sea change sequence.

[0054] For example, in the example shown in Figure 8, the robot 16 moves in the order of processing area E2 → passageway E5 → accumulation area E3. In passageway E5, the scene change sequence starts at control point PT4 (corresponding to the predetermined control point mentioned above), which is the first point to move from processing area E2. The robot arm 31 is driven to return to a standby position when picking is completed in processing area E2, and the robot 16 moves to control point PT4 with the robot arm 31 basically in a standby position. After the scene change sequence is completed, the robot arm 31 performs load leveling as needed.

[0055] Furthermore, in the accumulation area E3, the sea change sequence is initiated at control point PT5 (corresponding to the predetermined control point mentioned above), which is the first control point to move from passage E5. The robot arm 31 is driven and controlled to return to a standby position once it has finished leveling the load in passage E5, and the robot 16 basically moves to control point PT5 with the robot arm 31 in a standby position. Then, after the sea change sequence is completed, the unloading by the robot arm 31 begins.

[0056] Next, referring to Figure 9, we will explain the scene change sequence executed by the non-safety related unit PY and the safety related unit PX (specifically, the safety FPGA).

[0057] In the scene change sequence, the first step is to confirm that the robot 16 (AGV 21 and robot arm 31) is stopped (stationary) in the non-safety related section PY (first process P1). The safety function switching is basically performed under conditions where the robot 16 is stopped, taking safety into consideration. If the robot 16 is not stopped due to a delay in operation, the sequence proceeds only after the robot 16 has stopped.

[0058] Incidentally, in this embodiment, the scene change sequence is advanced only when it is confirmed that both the AGV 21 and the robot arm 31 are stopped (stationary). However, this can be changed so that the scene change sequence is advanced even if the AGV 21 is moving, as long as it is confirmed that the robot arm 31 is stopped.

[0059] If it is confirmed that the robot 16 has stopped, the position of the robot 16 is checked (second process P2). Specifically, the robot 16 is equipped with a locator 41 that can identify the position of the robot 16 in the factory 10, and based on the position information (e.g., coordinates) of the robot 16 obtained from this locator 41, it is confirmed that the robot 16 is located at the predetermined control point in the designated area. The robot 16 has a certain size, and in the position check described above, it is configured to determine whether a specific part of the robot 16 (the end effector of the robot arm 31 in this embodiment) is located at the predetermined control point in the designated area.

[0060] Furthermore, in the position confirmation in the second process P2, it is confirmed that the end-effector of the robot arm 31 is positioned at a preset position (the standby position, which corresponds to the standby posture described above in this embodiment) based on the encoder information obtained from the rotary encoder 36. In other words, in this embodiment, the condition for switching the safety function is that the position of the robot 16 and the position of the end-effector of the robot arm 31 are at preset positions.

[0061] If the above-mentioned stop conditions and position conditions (switching conditions) are met, the non-safety related unit PY instructs the safety related unit PX to switch the safety function of the safety related unit PX, i.e., to switch the monitoring parameters (judgment criteria) (see the third process P3). Specifically, a request command requesting the safety FPGA of the safety related unit PX to switch the safety function, and a CRC, which is diagnostic information to diagnose whether the transmission and reception of the request command were successful, are sent to the safety FPGA of the safety related unit PX.

[0062] In this embodiment, the safety functions are defined for each work scene (work scenes SCN1 to SCN9) of the robot 16. A request command consists of a command ID that includes information to identify the control device that is the source of the request, information indicating that the request is for switching safety functions, and data (scene number) that indicates the criteria to be referenced in subsequent decisions. If the source of the request command related to switching safety functions is the teaching pendant 70, the command ID is "11"; if it is the drive control unit 52 (PackScript in detail), the command ID is "12"; and if it is the IO 80, the command ID is "13".

[0063] Furthermore, when a request command related to switching safety functions is set, the data will be one of nine numbers from "1" to "9". For example, if the next operation scene is SCN3 (picking), the data will be "3", if the next operation scene is SCN4 (transport (1)), the data will be "4", and if the next operation scene is SCN5 (palletizing), the data will be "5". The CRC is a checksum between the command ID and the data number. For example, if the drive control unit 52 is the source and the next operation scene is picking SCN3, the CRC will be "12" + "3" = "15".

[0064] In the safety-related department PX, based on instructions received from the non-safety-related department PY, the PX diagnoses whether there are any abnormalities such as corruption in the current request command and CRC (fourth process P4). Specifically, it determines whether the sum of the command ID number and the data number of the request command matches the CRC. If they match, it is considered that the instruction was sent and received successfully, and then it diagnoses whether the request command itself is normal. Specifically, it refers to the command ID to identify that the instruction is a safety function switch and determines whether the data is within the range corresponding to the current command ID. As mentioned above, if the command ID is "11" to "13", the data will be one of "1" to "9". If the current data is one of "1" to "9", it is diagnosed that the request command is normal.

[0065] Next, based on the position information (e.g., coordinates) of the robot 16 obtained from the locator 41, it is confirmed that the robot 16 is located in the designated area, specifically the predetermined control point, and based on the encoder information obtained from the rotary encoder 36, it is confirmed that the end-effector of the robot arm 31 is positioned at the standby position (fifth process P5). The position confirmation in this fifth process P5 is the same as the position confirmation in the second process P2.

[0066] If the request command is diagnosed as abnormal, or if it is determined that the end effector of robot 16 or robot arm 31 is not in the specified position, the control center of factory 10 will be notified that a communication error or other abnormality has occurred, and this scene change sequence will be terminated.

[0067] If the current request command is valid and the end effector of robot 16 or robot arm 31 is in the specified position, the request command is accepted, and the safety function, i.e., the judgment criteria for monitoring parameters, is switched according to the instructions of the non-safety related unit PY (sixth process P6). Specifically, the memory of the control device 51 stores the correspondence between data numbers and each monitoring parameter and judgment criteria. Based on the specified data number and the correspondence stored in memory, the safety function (judgment criteria) is switched. In other words, the values ​​of the above safety-related parameters are changed.

[0068] After the safety function switchover is complete, the safety-related unit PX sends information to the non-safety-related unit PY to identify the settings of the safety function after the switchover (process 7, P7). Specifically, after the safety function switchover is complete, an acknowledgment signal is sent to the non-safety-related unit PY to report that the request command has been received. When the non-safety-related unit PY receives an acknowledgment signal from the safety-related unit PX, it requests information from the safety-related unit PX to identify the settings of the safety function after the switchover, that is, information to identify the judgment criteria currently set as the reference target. A CRC may also be added to this request.

[0069] The safety-related unit PX, in response to a confirmation request from the non-safety-related unit PY, sends a request command (more specifically, a command mimicking the request command) and a CRC (Critical Reference Code) to the non-safety-related unit PY to diagnose whether the transmission and reception of the request command were successful. The request command from the safety-related unit PX, like the request command from the non-safety-related unit PY, consists of a command ID that includes information to identify that the sender is the safety-related unit PX and information indicating that the request is for switching safety functions, and data (scene number) that indicates the criteria to be referenced in subsequent decisions. The CRC is the sum of the command ID number and data number of the command being returned. For example, if the current setting corresponds to "picking" in work scene SCN3 in response to a request from the non-safety-related unit PY, the safety-related unit PX (safety FPGA) will return command ID = "19", data number = "3", and CRC = "22". Incidentally, the CRC only needs to be determined based on the command ID and data number, and the specific calculation method is arbitrary.

[0070] Upon receiving a response from the safety-related unit PX, the non-safety-related unit PY determines whether the safety functions of the safety-related unit PX have switched over successfully in response to a request from the non-safety-related unit PY (process 8, P8). Specifically, it first diagnoses whether the response was successfully sent and received based on the request command and CRC. More specifically, it checks if the sum of the command ID number and data number of the request command matches the CRC. If they match, it is considered that the response was successfully sent and received. The non-safety-related unit PY stores the relationship between the command ID and data of the request command from the safety-related unit PX, and based on these relationships, it determines whether the command ID and data match those of the request command it sent to the safety-related unit PX. If it is confirmed that the response from the safety-related unit PX matches its instructions, the scene change sequence is completed.

[0071] According to the first embodiment described in detail above, the following excellent effects can be expected.

[0072] Having a single robot handle multiple different tasks is desirable for promoting automation in manufacturing processes and other areas. However, if a uniform configuration is adopted where the same level of safety functions (judgment criteria for motion monitoring) is applied to multiple work scenes with different work content, it becomes difficult to achieve both improved safety and increased productivity. In this regard, as shown in this embodiment, a configuration in which safety functions are switched (judgment criteria for motion monitoring are changed) for each work scene can contribute to improving both the safety of the robot and the work efficiency.

[0073] As mentioned above, enabling the switching of safety functions has various technical advantages. However, incorporating such a switching function raises the following new concerns. Specifically, if the safety function is suddenly switched due to an accidental reason while the robot 16 is operating, movements that would normally be fine may be flagged by the monitoring system. This unnecessarily increases the opportunities for the robot to be forcibly stopped, reducing productivity. Therefore, as shown in this embodiment, if the safety function is configured to allow switching only when the robot 16 has stopped after completing one work scene during automatic operation, the above concerns can be suitably mitigated.

[0074] In this embodiment, the aforementioned stopping conditions and position conditions are used as the switching conditions for the safety function. In other words, the configuration is such that the safety function is switched after confirming the position of the end effector of the robot 16 or robot arm 31. Considering that the work content differs depending on the area in which the robot 16 works, and that the appropriate safety function differs accordingly, it is preferable to configure the system to switch the safety function after confirming the position in order to improve the reliability of the switching.

[0075] When switching between multiple types of judgment criteria (force judgment criteria, speed judgment criteria, etc.), instead of specifying each judgment criterion individually, specifying a predefined combination of those judgment criteria (scene number) can suppress the complexity of instructions from the non-safety-related part PY to the safety-related part PX. This is a desirable configuration for increasing the number of tasks that the robot can perform while considering safety functions.

[0076] When switching safety functions, a switching instruction is sent from the non-safety related unit PY to the safety related unit PX. This instruction consists of a request command and a CRC, and the safety related unit PX diagnoses whether the instruction was received successfully based on the request command and CRC, and whether the instruction itself is normal. If the diagnosis shows no abnormalities, the instruction from the non-safety related unit PY is accepted, and the safety related unit PX switches the judgment criteria to be referenced according to the instruction. In other words, even if the instruction comes from the non-safety related unit PY, if it is determined that there are no abnormalities in the instruction such as transmission errors, the judgment criteria will be switched. By achieving safe switching from the non-safety related unit PY in this way, the operability related to changing safety functions in the control system CS can be improved accordingly.

[0077] According to the configuration shown in this embodiment, even when switching the safety function of the safety-related unit PX from the non-safety-related unit PY, it is possible to suppress a decrease in reliability due to the change in safety function, and to avoid stronger constraints on the change compared to when the input for changing the safety function is input from the input unit X1 (so-called safety input). As a result, the operability of changing the safety function can be suitably improved.

[0078] As shown in this embodiment, if the safety-related unit PX diagnoses whether the instruction from the non-safety-related unit PY is normal by comparing the type of instruction stored in advance with the current instruction, it is possible to effectively suppress the switching of the safety function based on the damaged instruction when the instruction is damaged due to bit sticking, communication errors, etc.

[0079] <Example 1> In the first embodiment described above, the position of the end-effector of the robot arm 31 (position on the robot 16), which is one of the safety function switching conditions, was set to a common position corresponding to the standby posture of the robot arm 31 regardless of the work scene, but it is not limited to this. The position of the end-effector of the robot arm 31 (position on the robot 16), which is a safety function switching condition, may be set differently depending on the work scene (e.g., work area) in which the safety function is switched. Also, the position confirmation of the robot 16 was based on the end-effector of the robot arm 31, but it is not limited to this. For example, the base 32 of the robot arm 31 may be used as the reference for position confirmation, the center of the robot 16 may be used as the reference for position confirmation, or the center or tip of the AGV 21 may be used as the reference for position confirmation.

[0080] <Modification 2> In the first embodiment described above, the position of the robot 16 was determined based on information from the locator 41 mounted on the robot 16, and the position of the end-effector of the robot arm 31 was determined based on information from the rotary encoder 36. However, the specific configuration for determining these positions is arbitrary. For example, the position of the robot 16 and the position of the end-effector of the robot arm 31 could be determined based on images captured by surveillance cameras installed in the factory 10. Alternatively, electronic tags could be placed in each area, and the position could be determined by reading these electronic tags with a reader mounted on the robot 16.

[0081] <Variation 3> In the first embodiment described above, when executing a scene change sequence, the non-safety related unit PY (drive control unit 52) ​​sends a request command and CRC to the safety related unit PX (safety FPGA), but does not send the position information of the robot 16 or the end-effector of the robot arm 31. That is, the safety related unit PX independently acquires this position information from the input unit X1. This can be changed so that when executing a scene change sequence, the non-safety related unit PY (drive control unit 52) ​​sends the position information of the robot 16 and the end-effector of the robot arm 31 along with the request command and CRC to the safety related unit PX (safety FPGA). In such a configuration, it is advisable to set the CRC taking the position information into account.

[0082] <Modification 4> In the first embodiment described above, picking and palletizing were given as examples of tasks for which the robot 16 is to perform, but it is not limited to these. The robot 16 can also be used for tasks such as processing, assembly, welding, and inspection.

[0083] <Second Embodiment> In the first embodiment described above, the safety and productivity of the robot 16 were improved simultaneously by switching the judgment criteria for safety functions, specifically for three monitoring parameters: "speed," "force," and "position," for each work scene (work scenes SCN1 to SCN9). Here, for example, when focusing on "speed" or "force," the acceptable speed and force from a safety standpoint may differ between movement in one direction and movement in another. Also, when defining judgment criteria for "speed," "force," and "position," the coordinate system to be used as the reference may differ depending on the work scene. Furthermore, by providing safety-related parameters that can be set for each work scene in addition to the judgment criteria for the three monitoring parameters described above, it is possible to further improve safety and productivity. In this embodiment, taking these circumstances into consideration, various configurable safety-related parameters are provided in addition to the judgment criteria described above. The following describes the characteristic configuration of this embodiment, focusing on the differences from the first embodiment. In the following description, the judgment criteria (values) for monitoring parameters set by the user and the setting values ​​of safety-related parameters other than the judgment criteria will be collectively referred to as "setting values" or simply "values." In the following explanation, the safety-related parameter group will also be referred to as a "scene" to distinguish it from the "work scene" in which the robot 16 is engaged, as shown in the first embodiment.

[0084] As shown in Figure 10, the safety-related parameters in this embodiment are broadly classified into basic items (basic parameters), items related to monitoring the operating range (monitoring criterion parameters), items related to monitoring speed (monitoring criterion parameters), items related to monitoring force (monitoring criterion parameters), items related to scene switching conditions (switching criterion parameters), and items related to sensor input (parameters for sensor input).

[0085] The basic items include "Collaborative Action Setting (Collaborative / Non-Collaborative)," which indicates whether the scene supports collaborative or non-collaborative actions; "Tool Number," which indicates the type of end effector (tool) to be used; "Work Number," which indicates the type of work; and "Object Number," which indicates the type of object numerically. For example, for "Collaborative Action Setting (Collaborative / Non-Collaborative)," setting the value to "0" indicates collaborative action, and setting the value to "1" indicates non-collaborative action.

[0086] During collaborative operation, speed and force must be controlled, and safety limits are set for these speed and force reference values. By specifying collaborative operation in the "Collaborative Operation Settings (Collaborative / Non-Collaborative)" above, the range of settings for speed and force reference values ​​is restricted so that the user can set them within the limits mentioned above. In addition, during the automatic operation of robot 16, whether or not collaborative operation is in progress is notified externally by switching IO80 according to the setting value of "Collaborative Operation Settings (Collaborative / Non-Collaborative)". "Tool Number", "Work Number", and "Object Number" are parameters that specify a particular coordinate system. Basically, since the scene (safety-related parameter group) is linked to a specific task, the various coordinate systems such as the tool coordinate system are configured to switch accordingly, improving the convenience of setting the safety-related parameter group.

[0087] Furthermore, the robot 16 (specifically the robot arm 31) has a function to slow down or stop when a worker approaches. For example, by switching the length / short distance at which the deceleration begins and the strength / weakness of the deceleration according to the cooperative / non-cooperative setting, it is possible to suitably achieve both improved safety and improved productivity. In addition, since the weight of the tip of the robot arm 31 differs depending on the type of tool, workpiece, and object, the appropriate timing for starting the deceleration of the robot arm 31 as it approaches a worker and the appropriate degree of deceleration also differ. By setting the "tool number," "workpiece number," and "object number" as parameters, it becomes possible to respond in a way that is more realistic. In other words, these basic items can contribute not only to improved safety through motion monitoring as shown in the first embodiment, but also to improved safety through collision avoidance with obstacles, etc.

[0088] The items related to monitoring the operating range include "RLO Enable Setting (Enable / Disable)," which specifies whether RLO (Robot Limited Orientation) monitoring is enabled or disabled; "RLO Monitoring Orientation Rx (deg)," "RLO Monitoring Orientation Ry (deg)," and "RLO Monitoring Orientation Rz (deg)," which specify the monitoring orientation (angle) for each coordinate axis as the judgment criterion; and "RLO Monitoring Allowable Angle (deg)," which specifies the monitoring allowable angle. In addition, items related to monitoring the operating range include "Positive Software Limit J1 (deg)" to "Positive Software Limit J8 (deg)" and "Negative Software Limit J1 (deg)" to "Negative Software Limit J8 (deg)," which specify the limit angle for each axis from J1 to J8. For "RLO Enable Setting (Enable / Disable)," setting the value to "0" disables it, and setting the value to "1" enables it.

[0089] The settings related to speed monitoring include "RLS Enable / Disable" which specifies whether RLS (Robot Limited Speed) monitoring is enabled or disabled, "RLS Monitoring Speed ​​(mm / s)" which specifies speed as the criterion for judgment without limiting the direction, and settings for individually specifying the speed in each axis direction in the end-effector coordinate system. For "RLS Enable / Disable" setting, setting the value to "0" disables it, and setting the value to "1" enables it.

[0090] The items related to force monitoring include "RLF Enabled / Disabled" which specifies whether RLF (Robot Limited Force) monitoring is enabled or disabled using a numerical value, "RLF Monitoring Force (N)" which specifies force as a judgment criterion without limiting the direction, and items that specify the force in each axis direction in the end-effector coordinate system. For "RLF Enabled / Disabled" the setting value is disabled by setting it to "0" and enabled by setting it to "1".

[0091] The items related to scene transition conditions include "Scene transition condition <position> setting," which is an item for selecting whether the position condition, one of the execution conditions for the scene change sequence, is a control point or the area containing that control point, and "Scene transition condition," which is an item for specifying the control point for the transition. <point>The field includes a number and items for specifying the area, such as "Scene switching condition <Area> X (mm)", "Scene switching condition <Area> Y (mm)", "Scene switching condition <Area> Z (mm)", "Scene switching condition <Area> RX (deg)", "Scene switching condition <Area> RY (deg)", "Scene switching condition <Area> RZ (deg)", "Scene switching condition <Area> DX (mm)", "Scene switching condition <Area> DY (mm)", and "Scene switching condition <Area> DZ (mm)". The field also includes various items for specifying the position or area of ​​the robot 16 when the position condition is met, and an item called "Scene switching condition <Stop state> Enabled setting (Enabled / Disabled)" which specifies the enabled / disabled setting of the stop condition (stopping the robot arm 31), which is one of the execution conditions of the scene change sequence, using a number.

[0092] The sensor input section links the IO80's sensor input numbers and their states to reference values ​​for speed and force. It also functions to switch the reference values ​​for speed and force depending on the state of the IO80 (similar to the subscene function described later).

[0093] As mentioned above, while increasing the number of configurable items allows for more appropriate setting of safety functions to suit different work scenarios, it also raises new concerns. Specifically, it can lead to increased user error and difficulty in identifying necessary items compared to a system with fewer configurable items. This hinders the effective implementation of safety improvements. One of the features of this embodiment is that it incorporates features that address these new challenges.

[0094] The control unit 62 of the PC 60 has software installed to assist the user in setting each safety-related parameter for each scene. By running this software, a safety-related parameter setting screen (hereinafter referred to as the scene parameter setting screen) is displayed on the PC 60's display 61. As shown in Figures 11 and 12, the scene parameter setting screen WD is provided with a scene display unit D1 that displays registered scenes and a parameter display unit D2 that displays various parameters. When the user selects one scene from the scenes displayed on the scene display unit D1, the parameter group corresponding to that scene is displayed on the parameter display unit D2 along with the set values. In this embodiment, the scenes are mainly divided into main scenes corresponding to various work scenes during autonomous driving and special scenes that are other scenes, and multiple main scenes (specifically nine) are provided.

[0095] The number of main scenes may be fixed, or it may be possible to add or delete them. However, having an excessive number of main scenes can make scene management difficult. Therefore, although the details will be described later, in this embodiment, a practically preferable configuration is achieved by keeping the number of main scenes constant and allowing the setting of sub-scenes for each of those main scenes.

[0096] In the examples shown in Figures 11 and 12, Main Scenes 1 to 9 are provided as main scenes. The display mode of the parameter display unit D2 (types of parameters displayed, order, and layout) is common to all of these Main Scenes 1 to 9. In this embodiment, the display of the parameter display unit D2 can be switched between multiple patterns, specifically, all-item display and main-item display. The user can switch between all-item display and main-item display by operating the display switching tabs (tab for all-item display and tab for main-item display) provided at the top of the parameter display unit D2. In this embodiment, the scene numbers for Main Scenes 1 to 9 are defined as "1" to "9", and the scene numbers for Special Scenes 1 to 2 are defined as "11" to "12".

[0097] In the full item display shown in Figure 11, all safety-related parameters are displayed, arranged vertically in the following order: basic items, items related to monitoring the operating range, items related to monitoring speed, items related to monitoring force, items related to scene switching conditions, and items related to sensor input. Since there are many safety-related parameters, those that do not fit within the frame of the parameter display unit D2 can be displayed by scrolling the list within the parameter display unit D2.

[0098] In the main item display shown in Figure 12, the displayed items are limited to show only a selection of parameters extracted from all safety-related parameters. Specifically, at least some parameters are extracted from each of the following items: basic items, speed monitoring items, force monitoring items, scene switching conditions items, and sensor input items, and these extracted parameters are displayed separately according to their application. More specifically, all safety-related parameters are displayed for the basic items, scene switching conditions items, and sensor input items, while all safety-related parameters are excluded from the operating range monitoring item. For the remaining items (speed monitoring items and force monitoring items), only the main safety-related parameters for each item are displayed.

[0099] For items related to speed monitoring and force monitoring, safety-related parameters that have judgment criteria set regardless of direction and safety-related parameters that have judgment criteria set separately for multiple directions are extracted as the main parameters. For example, "RLS monitoring speed (mm / s)" is extracted from the group of items related to speed monitoring, and "RLF monitoring force (N)" is extracted from the group of items related to force monitoring. The extracted safety-related parameters are then displayed separately according to their application. Here, we will provide a supplementary explanation regarding the display of parameter display section D2 when the main items are displayed.

[0100] In the main item display, the parameter display unit D2 is divided into three display units G1 to G3. The first display unit G1 displays a group of safety-related parameters belonging to the basic items, the second display unit G2 displays a group of safety-related parameters belonging to items related to sensor input, and the third display unit G3 displays a group of safety-related parameters extracted from items related to speed monitoring, safety-related parameters extracted from items related to force monitoring, and safety-related parameters belonging to items related to scene switching conditions.

[0101] In this embodiment, scenes derived from the main scene, specifically scenes that differ only in the settings of safety-related parameters displayed on the display unit G3, can be registered as sub-scenes. This is a measure to prevent a proliferation of main scenes and reduce the complexity of scene management by the user, and is effective in preventing incorrect settings. For example, if the setting values ​​of the parameters displayed on the display unit G1 are the same, but you want to change at least one of the settings of "RLS monitoring speed (mm / s)" and "RLF monitoring force (N)", or if you want to change the setting values ​​related to scene switching conditions, you can use the sub-scene registration function.

[0102] More specifically, in the transport (1) work scene SCN4 shown in the first embodiment, the robot 16 travels through the passage E5, which is bent (see Figure 1). Since the external forces acting on the robot arm 31 differ between straight-line movement and turning, the appropriate "RLF monitoring force (N)" may differ. Therefore, it is advisable to set the main scene as transport (1), register sub-scene 1 for straight-line movement, and sub-scene 2 for turning, and individually set the criteria for determining the "RLF monitoring force (N)". In addition, in the factory 10, it is assumed that the number of people using passage E5 increases during specific times such as lunch breaks, and the appropriate "RLS monitoring speed (mm / s)" and "RLF monitoring force (N)" may differ. Therefore, it is best to set the main scene as "transport (1)", register sub-scene 1 for times other than the specific time period, and sub-scene 2 for the specific time period, and then individually set the criteria for "RLS monitoring speed (mm / s)" and "RLF monitoring power (N)".

[0103] Furthermore, if multiple sub-scenes are registered for the selected main scene, you can switch between them by operating the tabs located at the top of the G3 display unit.

[0104] If multiple subscenes are registered for a main scene (1), displaying all items will show all the parameter sets corresponding to each subscene. Specifically, for example, if subscene 1 and subscene 2 are registered, "RLS monitoring speed (mm / s) subscene 1" and "RLS monitoring speed (mm / s) subscene 2" will be displayed side by side. In other words, if the number of subscenes for a main scene (1) increases, the number of parameters displayed in the list (the number of parameters to be displayed) will also increase when displaying all items. In contrast, with the main items display, even if the number of registered subscenes increases, the number of parameters displayed together in the parameter display section D2 (the number of parameters to be displayed) remains constant because it is possible to switch the display of subscenes.

[0105] Here, we will explain the user's parameter setting process. When the scene parameter setting screen WD is opened on the PC60's display 61, the parameter display unit D2 is configured to display the main items. The fact that the main items display takes precedence over the all-items display remains the same even if the selected scene is changed to another main scene or special scene. By setting each safety-related parameter while the main items are displayed, the settings for the main safety function parameters are completed. After that, detailed settings can be made as needed. When making detailed settings, the parameter display unit D2 is switched from the main items display to the all-items display. At this time, the settings made in the main items display are carried over to the all-items display. In other words, since some safety-related parameters are already set when the all-items display is selected, the user can focus on setting the unset safety-related parameters. Note that if "RLS monitoring speed (mm / s)" or "RLF monitoring force (N)" is set in the main items display, "RLS enable setting (enabled / disabled)" and "RLF enable setting (enabled / disabled)" will automatically become "enabled".

[0106] As described above, in this embodiment, in addition to the main scene, special scene 1 and special scene 2 are registered. Special scene 1 is assumed to be the default during automatic operation (automatic control). For example, when the robot 16 is started and automatic operation begins, the scene will be this special scene 1 until the first work scene is reached. As shown in Figure 13, when special scene 1 is selected by the user in the scene display unit D1, the display in the parameter display unit D2 becomes the main item display. In this main item display, the number of parameters displayed is smaller compared to the main scene. In this embodiment, "Collaborative operation setting (collaborative / non-collaborative)", "RLS monitoring speed (mm / s)", and "RLF monitoring force (N)" are displayed, and other parameters such as the parameter group belonging to the basic items are not displayed. Even if a parameter is necessary in the main scene, which is a scene assumed to be for automatic operation, if it is substantially unnecessary or of low importance in special scene 1, it is excluded from the main item display. As a result, the items displayed in the main item display are streamlined.

[0107] Special Scene 2 assumes a scenario where the user manually moves the robot 16 (robot arm 31). For example, it applies to a scenario where the robot 16 moves outside the area and is forced to stop, and the user manually moves the robot 16 back into the area. As shown in Figure 14, when Special Scene 2 is selected by the user in the Scene Display Unit D1, the Parameter Display Unit D2 displays the main items. In this main item display, fewer parameters are displayed compared to the main scene. Specifically, "RLS monitoring speed (mm / s)" and "RLF monitoring force (N)" are displayed, while other parameters are not displayed.

[0108] In Special Scene 1 and Special Scene 2, there is no need to configure the safety-related parameters belonging to the scene switching conditions section and the safety-related parameters belonging to the sensor input section. When all items are displayed, these safety-related parameters will also be displayed, but input of setting values ​​will be restricted.

[0109] If the number of user-configurable safety-related parameters increases for each scene, safety functions can be finely adjusted to suit the work content, etc. This is desirable for achieving both improved safety and increased productivity. However, if the number of configurable items increases, it becomes more difficult for users to identify the necessary items. This can lead to incorrect settings. In this regard, according to the configuration shown in this embodiment, the display pattern (corresponding to "display mode") of the safety-related parameter group in the parameter display section D2 of the scene parameter setting screen WD (corresponding to "parameter setting screen") can be switched between displaying all items (corresponding to "first display mode") and displaying main items (corresponding to "second display mode"). In the main items display, the displayed items are limited to some safety-related parameters, making it easier for users to narrow down the necessary items. On the other hand, in the all-items display, all safety-related parameters are displayed (configurable), making it possible to set and check individual safety-related parameters. Thus, providing two display patterns for the parameter display unit D2—all items displayed and main items displayed—is preferable in order to achieve both improved safety and increased productivity while suppressing user setting errors.

[0110] If you wish to make detailed settings for a specific safety-related parameter displayed in the main items view, you can do so by switching from the main items view to the all items view. Whether or not such detailed settings are necessary depends on various circumstances. It is preferable to exclude these detailed setting parameters from the main items view to narrow the displayed items, as this helps prevent important parameters from being overlooked.

[0111] In this embodiment, the number of safety-related parameters displayed in the main items display is less than the number of safety-related parameters displayed in the all-items display, thus significantly narrowing down the items extracted for the main items display. This allows the main items display and the all-items display to coexist appropriately according to the purpose.

[0112] In the main items display, safety-related parameters are categorized into multiple groups. This makes it easier for users to find the items they want if they are included in the items displayed in the main items display. Furthermore, encouraging users to set parameters in groups according to their categories is desirable in reducing errors in parameter settings.

[0113] When a user opens the Scene Parameter Settings screen (WD), the safety-related parameters are initially displayed in a main items-only view. This allows the user to configure a limited set of items. Subsequently, the user can switch the display pattern to show all items, providing an opportunity to configure other items that are not displayed when the Scene Parameter Settings screen (WD) is launched.

[0114] When a main scene is specified by the user, the safety-related parameters corresponding to that main scene are displayed in the main items section. Even when setting safety-related parameters for multiple main scenes, displaying only the safety-related parameters for the specified main scene in the main items section effectively prevents information overload and user confusion.

[0115] In each main scene for autonomous driving, the items displayed in the main item display are consistent across all main scenes. This configuration allows users to set parameters in one main scene using the main item display, and then, when setting parameters in another main scene using the main item display, they can perform the setting work while maintaining the same visual representation as the previous setting. This is desirable for reducing setting errors.

[0116] In some main scenes, only certain safety-related parameters may differ. If it were possible to adjust only those specific safety-related parameters using sub-scenes, it would be possible to prevent an overabundance of main scenes and reduce user confusion between them.

[0117] As shown in this embodiment, by distinguishing between items set for each subscene and items common to all subscenes, the items set for each subscene can be clearly indicated to the user. Furthermore, distinguishing between items common to all subscenes is preferable in preventing the settings of these common items from being accidentally changed during the subscene setting process.

[0118] <Example 1> In the second embodiment described above, a configuration was described to provide setting support when setting safety-related parameters using the PC 60. However, if safety-related parameters can be set using the teaching pendant 70, the configuration related to setting support may be applied to the teaching pendant 70. Furthermore, in this embodiment, the case where setting support software is pre-installed in the control unit 62 of the PC 60 was illustrated. However, this software may be distributed via an internet connection or the like, allowing the user to install the software on the control unit 62 of the PC 60 of their choice at any time.

[0119] <Modification 2> In the second embodiment described above, when the scene parameter setting screen WD is opened or when each scene is selected, the safety-related parameters are initially displayed with the main items shown. However, this can be changed so that all items are initially displayed.

[0120] <Variation 3> In the second embodiment described above, when all items are displayed in special scene 1 and special scene 2, the safety-related parameter groups belonging to the scene switching conditions and the safety-related parameter groups belonging to the sensor inputs are displayed, and the input of set values ​​is restricted. However, it is also possible to exclude these parameter groups from the display even when all items are displayed. However, it is preferable to unify the items displayed in all items in each main scene and each special scene in order to prevent the user from feeling uncomfortable with the absence of some items.

[0121] <Third Embodiment> In the robot systems described in the first and second embodiments above, a control program created by the user on a PC 60 is transmitted to the control device 51 of the robot 16, and the robot 16 operates according to this control program. The PC 60 can execute the created control program on the PC 60 and perform simulations to check the operation, posture, interference, etc., of the robot 16 without actually operating the robot 16. This embodiment is characterized by its simulation configuration. The characteristic configuration of this embodiment will be described below, focusing on the differences from the second embodiment.

[0122] When the simulation software installed on the control unit 62 of the PC60 is launched, the simulation screen is displayed on the PC60's display 61. As shown in Figure 15, the simulation screen has a program display unit WP that displays the control program created by the user, and a 3D view WV that can display 3D models of the robot 16, peripheral devices, factory equipment 10, etc., in a virtual space. In addition, the 3D view allows for the display / hide of individual 3D models, and Figure 15 shows an example where only the robot arm 31 model RM is displayed.

[0123] The user specifies a control program and initiates the simulation, which is then executed on the PC60. This causes the model RM displayed in the 3D view WV to move in accordance with the progress of the control program. The user can verify whether the control program is configured as intended by observing the model RM's movements. Furthermore, the program display unit WP highlights the currently executing line in the control program, making it easier for the user to understand which line of the control program corresponds to the model RM's movements.

[0124] The simulation screen also includes a Scene Setting Monitor (WM), which displays various safety-related parameters. This allows the user to check the settings of these parameters as needed. However, because there are many safety-related parameters (see Figure 10), the Scene Setting Monitor (WM) limits its display to show only some of the major safety-related parameters.

[0125] In this embodiment, the control program for the robot 16 is designed to assume that the robot 16 is engaged in multiple different tasks, and multiple "CHANGE SCENE" commands are provided to switch safety functions for each task. As already explained, the robot 16 starts a scene change sequence when this "CHANGE SCENE" command is issued, and a simulated scene change sequence is also executed in the simulation.

[0126] In the scene change sequence, the safety function is switched between the non-safety related unit PY and the safety related unit PX when it is confirmed that the robot 16 is stopped (stationary) (stop condition) and that the end-effectors of the robot 16 and the robot arm 31 are in the specified positions (position condition). Similarly, in the simulation shown in this embodiment, the safety function is switched when the stop condition and position condition are basically met.

[0127] Next, we will illustrate the general procedure for when a user creates a control program. In Pattern A shown in Figure 16(a), the first phase involves determining the outline of the robot 16's movements (PA1), and then creating a control program according to that outline (PA2). However, at this stage, priority is given to defining the robot 16's movements, and the scene is only a provisional setting before thorough verification. After creating the control program, the process moves to the second phase, where the control program is refined by repeatedly performing simulation-based operation verification (PA3) and modifying the control program based on the results (PA4). Once the control program is somewhat finalized, the process moves to the third phase, where the scene is set up properly (PA5). Then, simulation-based operation verification and scene setting verification are performed again (PA6). The scene settings and control program are modified as needed. Following these steps, the control program and scene settings are completed. On the other hand, in Pattern B shown in Figure 16(b), the first phase involves determining the outline of the robot 16's movements and the outline of the scene (PB1), and then creating a control program and setting up the scene according to that outline (PB2). After that, the process moves to the second phase, where the operation and scene settings are verified through simulation (PB3), and the control program and scene settings are modified based on the results (PB4). In the second phase, verification and modification are repeated until the control program and scene settings are completed. In most cases, the control program is created and the scene is set up using one of the two patterns described above.

[0128] If the control program is complete and the scenes are properly set (especially the setting of scene transition positions), the above positional conditions related to the switching of safety functions will be met without any problems, and the simulation will proceed smoothly. On the other hand, in order to efficiently proceed with the creation of the control program and to check whether the program is correct at any given time, there are situations in which the user may want to run a simulation before the creation of the control program or the setting of the scenes is complete (at an intermediate stage), as illustrated in Figures 16(a) and (b). In addition, there is a possibility that the user will want to check the operation after the switching of safety functions, and if the scene setting is not complete, the scene change sequence cannot be completed, and the simulation of the part (row) that the user wanted to check cannot be executed. This is a new challenge that arises when attempting to run a simulation on a control program that includes the switching of safety functions.

[0129] If the position conditions are not met for any accidental reason during the automatic operation of robot 16, an error will occur and robot 16 will stop. In this case, the user can resume automatic operation by checking the status of robot 16 and returning robot 16 to the correct position (see Figure 17). On the other hand, during the creation of control programs, simulations may be executed knowing that the scene settings are not correct. It is undesirable for the simulation to be unable to continue in such situations, or for the effort required to resolve the position condition failure to be significant. Therefore, in this embodiment, if the position conditions are not met during the simulation, a simpler response than that during the automatic operation of robot 16 will be used to allow the simulation to continue. The general flow of the scene change sequence executed during the simulation will be explained below with reference to Figures 18 and 19. In the simulation, a virtual non-safety related unit (virtual drive control unit) and a virtual safety related unit (virtual safety FPGA) are set on the PC 60 by software, and a flow similar to the flow shown in Figure 9 is reproduced between these virtual non-safety related unit and virtual safety related unit. In other words, the scene change sequence is also executed as part of the simulation.

[0130] As shown in Figure 18, in the scene change sequence during the simulation, it is first confirmed that the model simulating robot 16, i.e., the model simulating AGV 21 and the model RM simulating robot arm 31 (see Figure 15), are stopped (S201). If it is confirmed that they are stopped, the position of the model simulating robot 16 and the position of the end-effector of the model RM simulating robot arm 31 are confirmed (S202). This confirmation is first performed on the virtual non-safety related unit side, and then on the virtual safety related unit side. If both the stop condition and the position condition are met and the virtual request command etc. are confirmed, and if all conditions are met (S203: YES), the safety function is switched. That is, each safety-related parameter is changed to one that corresponds to the next scene (S204). Then, each safety-related parameter displayed on the scene setting monitor WM is changed to a value that corresponds to the next scene (S205).

[0131] On the other hand, if the scene settings are not properly configured, the position condition will be deemed unmet during the position check on the virtual non-safety related parts (S203: NO). If the position condition is unmet, the simulation is interrupted (S206), and a message indicating that the position condition is unmet is displayed in the scene change sequence (S207). Specifically, as shown in Figure 19(a), a message box MB1 pops up over the 3D view WV where the model RM etc. is displayed. This message box MB1 displays the title "CHANGE SCENE," indicating that the message relates to the scene change sequence, and the message "The current state does not meet the switching conditions (position condition). Do you want to resume the program?", which clearly indicates that the position condition is unmet and asks for confirmation to resume the program. Then, icons that the user can select are displayed: a "Resume" button to instruct the simulation to continue and a "Cancel" button to instruct the simulation to end. The 3D viewer WV displays information indicating the current scene, but the message box MB1 is displayed in a position that does not overlap with this information, ensuring that the visibility of the information is maintained even when the message box MB1 is displayed. In addition, the program display unit WP maintains the "CHANGE SCENE" command highlighted to clearly indicate the current program position (line).

[0132] Returning to the explanation in Figure 18, after displaying the message box MB1, it is determined whether the user has performed a continuation operation of the simulation, i.e., pressed the "Resume" button (S208). If this operation has been performed, the simulation is resumed (S209). In other words, the result of the position condition determination is invalidated and the simulation continues as is. Then, the safety functions are switched, as in the case when various stop conditions and position conditions are met. That is, each safety-related parameter is changed to the value corresponding to the next scene (S204). Then, each safety-related parameter displayed on the scene setting monitor WM is changed to the value corresponding to the next scene (S205). When the simulation is resumed, the message box MB1 is hidden, and the highlight on the program display unit WP moves from the "CHANGE SCENE" command to the next command (in the example shown in Figure 19(b), the "APPROACH" command).

[0133] Incidentally, if the user terminates the simulation, i.e., by pressing the "Cancel" button (S210:YES), the simulation will be terminated (S211). If the user then initiates the simulation, the simulation will be executed again from the beginning of the control program.

[0134] Furthermore, the simulation configuration described in detail above can also be applied to the robot system shown in the first embodiment.

[0135] According to the configuration shown in this embodiment, the simulation can continue not only when the scene switching conditions are met, but also when the scene switching conditions are not met. Since the robot does not actually operate during the simulation, continuing the simulation does not affect safety. Therefore, this configuration can suitably support the creation of control programs that take into account both the safety and productivity of the robot.

[0136] In this embodiment, when the "CHANGE SCENE" command in the control program is reached, the user is notified. This reduces the chance that the user might miss a scene change. Furthermore, configuring the simulation to pause and wait for the user to restart it is preferable to a configuration where the simulation does not pause, as it allows the user to pay attention to the display of safety-related parameters, etc.

[0137] <Example 1> In the third embodiment described above, when executing a scene change sequence in the simulation, even if the switching conditions (specifically, position conditions) for switching the safety function are not met, the simulation is continued by invalidating this result, or more precisely, the simulation is continued after the safety function is switched. To modify this and allow the simulation to continue even if the position conditions are not met, the determination of the position conditions itself may be not performed (the determination function itself is disabled). Specific examples will be explained below with reference to Figures 20 and 21(a). Figure 20 shows a modified example of a scene change sequence in a simulation.

[0138] During a scene change sequence in a simulation, the system first checks whether the model RM, which simulates the robot arm 31, is stopped. If it is confirmed that the model is stopped, a virtual request command is sent from the virtual non-safety related unit to the virtual safety related unit, which then diagnoses the request command. If the diagnosis confirms that the command is appropriate, the safety function settings are switched without checking the position conditions. That is, each safety-related parameter is changed to the value corresponding to the next scene (S302). Then, each safety-related parameter displayed on the scene setting monitor WM is changed to the value corresponding to the next scene (S303). After that, the simulation is temporarily suspended (S304), and a message indicating that the scene change sequence has been executed is displayed (S305). Specifically, as shown in Figure 21(a), a message box MB2 pops up over the 3D view WV where the model RM is displayed. This message box MB2 displays the title "CHANGE SCENE," which indicates that this message box MB2 relates to the scene change sequence, and the message "Do you want to resume the program?", which confirms the resumption of the program. Then, two icons are displayed that the user can select and operate: a "Resume" button to instruct the user to continue the simulation, and a "Cancel" button to instruct the user to end the simulation. The 3D view WV is configured to display information indicating the scenes before and after the switch, but the message box MB2 is displayed in a position that does not overlap with this information, ensuring the visibility of the information. In addition, the program display unit WP keeps the "CHANGE SCENE" command highlighted to clearly indicate the current program position (line). Returning to the explanation of Figure 20, after the message box MB2 is displayed, if the user operates the "Resume" button (S306:YES), the simulation is resumed (S307). On the other hand, if the user operates the "Cancel" button (S308:YES), the simulation is terminated (S211).

[0139] Furthermore, it is possible to configure the system so that the scene change sequence ("CHANGE SCENE" command) itself can be disabled during simulation, for example, allowing the user to choose whether to enable or disable the scene change sequence.

[0140] <Modification 2> The simulation execution mode may include a condition check avoidance mode (see Figure 21(a)) in which the safety function switching conditions (especially position conditions) are not determined, and a condition check execution mode (see Figure 21(b)) in which the switching conditions are determined, allowing the user to select whether or not the switching conditions need to be determined. In the condition check execution mode, if the conditions are not met, the same error message (message box MB3) as during automatic operation of the robot 16 should be displayed.

[0141] <Variation 3> In the third embodiment described above, if the simulation is interrupted because the positional conditions are not met during a scene change sequence, the user can continue the simulation, which will change the safety-related parameters to the values ​​corresponding to the next scene, and also change the safety-related parameters displayed on the scene setting monitor (WM) to the values ​​corresponding to the next scene. Alternatively, this could be changed to a configuration that notifies the user in advance of the values ​​of the safety-related parameters corresponding to the next scene when the simulation is interrupted due to unmet conditions. For example, the values ​​of the safety-related parameters corresponding to the next scene could be displayed in a message box, or the safety-related parameters displayed on the scene setting monitor (WM) could be changed in advance to the values ​​corresponding to the next scene.

[0142] <Modification 4> As shown in the third embodiment and the modified example above, when the simulation is to continue by invalidating the determination of the switching condition (position condition) or invalidating the determination result of the switching condition, the safety function may be switched and the simulation may continue without confirming the user's intention to continue. Even in such a configuration, it is preferable to notify the user that the safety function has been switched.

[0143] <Modification 5> The specific configuration for notifying the user in a non-error manner when switching conditions such as position conditions are not met during a scene change sequence in a simulation is optional. For example, the configuration could output a message in the simulation log indicating that the switching conditions such as position conditions were not met.

[0144] <Variation 6> During simulation, it is preferable to design the display in a way that makes it easy to distinguish between safety-related parameters whose values ​​change due to scene changes and those whose values ​​do not change. For example, it is advisable to display safety-related parameters whose values ​​change in a different color than those whose values ​​do not change, or to highlight one of the safety-related parameters whose values ​​change or those whose values ​​do not change, in order to support visual identification.

[0145] <Example 7> In the simulation shown in the third embodiment above, a configuration was used to perform a stop confirmation when executing a scene change sequence, but the system is not limited to this. The simulation may also be configured not to perform a stop confirmation during the scene change sequence.

[0146] <Fourth Embodiment> As shown in the first to third embodiments, enabling the switching of safety functions according to the work scene is preferable in order to achieve both improved safety of the robot 16 and improved productivity by the robot 16. The control unit 62 of the PC 60 has software installed that assists in setting various safety-related parameters related to safety functions, thereby improving the efficiency of setting safety-related parameters. In particular, as shown in the second embodiment, while further improvements in safety and productivity can be expected as the number of safety-related parameters to be set increases, the workload of the setting work also increases. Therefore, the support effect becomes even more pronounced by centrally managing the safety-related parameter groups for each scene with the PC 60.

[0147] The safety-related parameters set on PC60 are transmitted from PC60 to robot 16 and stored in the robot 16's (control device 51's) memory. The robot 16 then refers to the safety-related parameters stored in memory during control. However, there is a concern that if a user mistakenly transmits safety-related parameters set for a specific work scenario by a particular robot to another robot, the incorrectly transmitted parameters may be applied to that other robot, making it difficult to achieve both safety and productivity.

[0148] For example, in the example shown in Figure 22, robot 16X located in the first area EX of the factory and robot 16Y located in the second area EY are of the same type, but the tasks they perform in each area are different, and the work content does not overlap. Specifically, the main scene 1 for robot 16X and the main scene 1 for robot 16Y are different. The user sets a set of safety-related parameters for robot 16X on the PC 60, assuming the main scene 1. There is no problem when this set of safety-related parameters is sent to the target (robot 16X) and stored in the memory 55X of the control device 51X as a set of safety-related parameters corresponding to the main scene 1. However, the above-mentioned problem occurs when this set of safety-related parameters is mistakenly sent to robot 16Y and stored in the memory 55Y of the control device 51Y as a set of safety-related parameters corresponding to the main scene 1. The teaching pendant 70X connected to robot 16X displays the safety-related parameters stored in memory 55X on the display 71X for visual confirmation, and the teaching pendant 70Y connected to robot 16Y displays the safety-related parameters stored in memory 55Y on the display 71Y for visual confirmation.

[0149] However, while a user could discover that a set of safety-related parameters is not appropriate for robot 16Y's main scene 1 by checking each parameter individually, if the number of safety-related parameters is large, visually checking each set parameter becomes a significant effort, making discovery practically impossible. Furthermore, when transmitting from PC60, there is a possibility that a set of safety-related parameters created for a different robot, even if it is the same main scene 1, may be mistakenly selected as the transmission target.

[0150] One of the features of this embodiment is that it incorporates measures to suppress operational errors such as sending safety-related parameters to the wrong destination or sending the wrong set of safety-related parameters. The following describes these measures, focusing on the differences from the second embodiment.

[0151] As shown in Figure 23, the scene parameter setting screen WD displayed on the PC60's display 61 is equipped with a name display unit D3 that displays the name of the selected scene, i.e., the safety-related parameter group currently displayed. The name of this name display unit D3 can be arbitrarily set and changed by the user. In other words, in addition to the unchangeable name (fixed name) set for identification by the PC60 software, i.e., the name displayed in the scene display unit D1, the user can set and change an arbitrary name (arbitrary name). This arbitrary name can be set and changed by clicking on the name display unit D3, and the set name is stored in association with the parameter group. Incidentally, the names displayed in the scene display unit D1 (Main Scene 1 to Main Scene 9, Special Scene 1 to Special Scene 2) will be the same even when setting scenes (safety-related parameter groups) for other robots.

[0152] In the example shown in Figure 23, the arbitrary name is set to a composite name combining the name of the robot to which the message will be sent and the area that the robot is responsible for, specifically "Robot X_Parameters for Area 1". If no arbitrary name is set, a message prompting the user to set a name will be displayed in the name display unit D3. Note that Figure 23 illustrates the case where the main items are displayed, but when the scene parameter setting screen WD is open, the name display unit D3 will remain displayed regardless of whether the main items are displayed or all items are displayed.

[0153] Furthermore, the scene parameter setting screen WD displays a send button SB, which is an operation icon for sending the current set of parameters to the robot 16. This send button SB is displayed when the main items are displayed, and when the user operates this send button SB, the safety-related parameters of the selected scene are sent to the robot 16.

[0154] Next, referring to Figure 24, we will explain the transmission process that is executed on PC60 as part of periodic processing when the software related to the configuration support described above is running.

[0155] In the transmission process, first, in step S401, it is determined whether the system is currently performing confirmation with the user before sending the parameter set (confirmation of the recipient and final confirmation). If confirmation is not in progress, the process proceeds to step S402. In step S402, it is determined whether the send button SB on the scene parameter setting screen WD has been operated. If the send button SB has not been operated, the transmission process ends immediately. If the send button SB has been operated, a positive determination is made in step S402, and the process proceeds to step S403.

[0156] In step S403, it is determined whether or not the above-mentioned arbitrary name has been set. If no arbitrary name has been set, in step S404, a teaching process is executed to instruct the user to set an arbitrary name, and then this transmission process is terminated. During this teaching process, a message such as "A name must be set to send" is displayed near the send button SB on the scene parameter setting screen WD. This message is hidden if an arbitrary name has been set.

[0157] On the other hand, if an arbitrary name is set, the transmission confirmation process is executed in step S405, and then the transmission process ends. During the transmission confirmation process, a message box is displayed in the center of the scene parameter setting screen WD. As shown in Figure 25(a), this message box MB3 first displays a list of robots to which the PC60 is connected. Specifically, it obtains unique information (e.g., robot name, controller name, serial number, etc.) to identify the robot from the connected robot and displays the obtained unique information as a candidate destination. When the user specifies a destination from this list of candidates, the message box MB3 switches to a display for final transmission confirmation. Specifically, as shown in Figure 25(b), a title indicating that it is the final confirmation before transmission, a final confirmation message, and operation icons, an execute button and a cancel button, are displayed. The final confirmation message includes the unique information to identify the destination robot and the set arbitrary name. For example, in the example shown in Figure 25(b), "Destination: Robot X" is displayed as the unique information, and "Robot X_Parameters for Area 1" is displayed as the arbitrary name.

[0158] Returning to the explanation of Figure 24, if the message box MB3 is displayed, proceed to step S406 to determine whether the final confirmation operation has been performed. That is, determine whether the execute button was pressed while the recipient and arbitrary name were displayed in the message box MB3. If the determination in step S406 is negative, proceed to step S407 to determine whether a cancel operation has been performed. If a cancel operation has been performed, in step S408, a cancellation process is executed to stop the transmission of parameters, and then this transmission process is terminated.

[0159] If a positive result is obtained in step S406, the transmission process is executed in step S409, and then the transmission process is terminated. In the transmission process in step S409, the scene number, safety-related parameters, and an arbitrary name set by the user are sent to the robot specified as the destination. In other words, the user is given an opportunity to confirm the main safety-related parameters, the arbitrary name, and the destination when performing the transmission procedure. This is a measure to reduce the occurrence of the above-mentioned errors during transmission.

[0160] The control device 51 of the robot 16 stores various information received from the PC 60 in its memory. By connecting the teaching pendant 70 to the robot 16, the various information stored in the memory can be displayed on the display 71 of the teaching pendant 70. In other words, the user can check the arbitrary name displayed on the display 71 of the teaching pendant 70 on-site. The display of the arbitrary name helps the user to confirm whether the parameters are appropriate for the robot 16.

[0161] In the example shown in Figure 26, similar to the example shown in Figure 22, the safety-related parameters for robot 16X, which were set on PC 60, are mistakenly transmitted to robot 16Y. However, the user can recognize that the safety-related parameters may have been mistakenly transmitted by checking the arbitrary name displayed on the display 71Y of the teaching pendant 70Y for robot 16Y. Providing an opportunity to detect such a mistransmission is desirable in reducing the chances of robot 16 being operated with inappropriate parameters.

[0162] The more configurable safety-related parameters there are, depending on various conditions such as the surrounding environment and work content, the more precisely safety functions can be adjusted (modified) according to the situation. This is advantageous in achieving both improved robot safety and increased productivity. However, if the number of configurable items increases, the number of items that the user must check when sending a group of safety-related parameters (scenes) from the PC60 to the control device increases, making it practically impossible to check all items each time. As a result, users are more likely to make work errors, such as selecting the wrong group of safety-related parameters to send and sending them without realizing it. If the wrong group of safety-related parameters is stored in the control device, there is a concern that the robot's safety functions will not be properly performed due to the application of that group of parameters. In this regard, the configuration shown in this embodiment allows for the setting of an arbitrary name for each scene (corresponding to "scene name"), and this arbitrary name is announced for the scene being set. By using such a function, it is possible to realize a configuration in which the user can easily understand what the group of safety-related parameters is without having to check each safety-related parameter individually. For example, users can determine if their work is appropriate by checking an arbitrary name without having to check each individual safety-related parameter when sending data. In other words, allowing users to set arbitrary names for groups of safety-related parameters is effective in suppressing the aforementioned work errors. For these reasons, switching between scenes consisting of groups of safety-related parameters can improve both the safety of the robot and the productivity of the robot, while suppressing the increase in work errors caused by these factors.

[0163] In PC60, scenes can be properly managed by using scene numbers. However, it is unclear whether a user can properly identify a scene (a group of safety-related parameters) by looking at the scene number. For example, if the identification information is simply a number or a string of numbers, it becomes difficult to intuitively understand the corresponding scene or the robot to which that scene applies from the scene number. In this regard, by configuring the system to allow users to set arbitrary names for scenes in addition to the system's scene number, users can more intuitively understand the corresponding scene from the arbitrary name. Therefore, it becomes easier to understand what the scene is without having to check each item of the safety-related parameters that make up the scene. This is desirable because it reduces the effort required to check individual safety-related parameters when sending a scene to the control device, as mentioned above.

[0164] As shown in this embodiment, if the arbitrary name set by the user is displayed on the display 61 along with the scene (safety-related parameter group) to which the arbitrary name corresponds, the user can easily confirm the relationship between the safety-related parameter group and the arbitrary name. This is preferable in reducing the aforementioned work errors. Furthermore, since the arbitrary name set by the user is displayed on the scene parameter setting screen WD, the user can appropriately check the arbitrary name when setting safety-related parameters for each scene, thereby reducing setting errors (work errors) due to confusion with other scenes (including scenes for other control devices).

[0165] When transmitting a scene to a control device, informing the user of an arbitrary name at least before the transmission operation is performed can reduce the chances of erroneous transmission or incorrect setting of the scene.

[0166] By connecting a device other than the one that transmitted the scene or arbitrary name (for example, a teaching pendant) to the control device, the scene and arbitrary name can be displayed on that other device, allowing the user to retrospectively check whether any erroneous transmission of scenes or other errors have occurred.

[0167] <Example 1> In the fourth embodiment described above, the PC60, which allows setting and changing safety-related parameters, is configured to allow setting and changing arbitrary names, while the teaching pendant 70, which does not allow setting or changing these safety-related parameters, does not allow setting or changing arbitrary names. If the teaching pendant 70 is configured to allow setting and changing safety-related parameters, it may be possible to set and change names on the teaching pendant 70. When multiple devices are provided that allow setting and changing parameters and setting and changing arbitrary names, it is preferable to share the latest setting values ​​and latest arbitrary names of the safety-related parameters among these devices. To realize such a configuration, for example, it is advisable to teach the arbitrary names to include version information and date information of the setting values, or to add this information to the arbitrary names on the device side. <Modification 2> In the fourth embodiment described above, a configuration in which the user directly inputs an arbitrary name was illustrated. However, a configuration in which a list of arbitrary name candidates is displayed via a pull-down menu and the user selects one arbitrary name from among them is also possible. Furthermore, as shown in the fourth embodiment, constructing an arbitrary name by combining multiple pieces of information makes it easier to enhance the distinctiveness of the name. In constructing a name by combining multiple pieces of information in this way, a configuration in which each piece of information is selected individually from pull-down menus is also possible.

[0168] <Variation 3> In the fourth embodiment described above, an example was given of a case where an arbitrary name is constructed by a combination of two pieces of information, the robot name and the area name (a composite name), but it is not limited to this. The arbitrary name may be constructed by one piece of information, or by a combination of three or more pieces of information. For example, it is possible to set the arbitrary name to "Parameters for the first area".

[0169] Furthermore, while the fourth embodiment described above allows the user to arbitrarily set the entire arbitrary name, it is not limited to this. As shown in the first modified example above, the arbitrary name can also be composed of a part that the user can arbitrarily set and a part that is forcibly determined by the device.

[0170] <Modification 4> In the fourth embodiment described above, the send button is displayed when the main items are displayed, that is, the safety-related parameter group can be sent when the main items are displayed, but the embodiment is not limited to this. The send button may be displayed when all items are displayed, or the send button may be displayed regardless of whether the main items or all items are displayed.

[0171] <Modification 5> If at least one of the values ​​in the safety-related parameter group is changed due to a review of the safety-related parameter values, it is possible to configure the system so that the previous arbitrary name cannot be carried over and the user is required to change the arbitrary name (for example, a configuration where saving or sending is not possible unless the name is changed). In particular, for the values ​​of the safety-related parameter group that have already been sent to the robot 16, making it mandatory to change the arbitrary name when the values ​​of the safety-related parameters are reviewed can mitigate the difficulty in determining whether the values ​​of the safety-related parameter group stored in the robot 16 have been updated to the latest version. For example, it would be good to include the date and time of change in the name, include personally identifiable information such as the login user ID or username, or include version information.

[0172] <Variation 6> In this embodiment, we have provided an example where the PC60 has configuration support software pre-installed. However, this software may also be distributed via the Internet or the like, allowing the user to install it on the desired PC60 at any time.

[0173] <Fifth Embodiment> In the fourth embodiment described above, an arbitrary name that the user can arbitrarily set is provided for the safety-related parameter group, and an opportunity is provided to display this arbitrary name when the safety-related parameter group is transmitted from the PC 60 or after the safety-related parameter group is received by the robot 16. With this configuration, it is possible to suppress the erroneous transmission of the safety-related parameter group and to detect missettings early. One of the features of this embodiment is that the above effect is enhanced by the system intervening more actively in the use of the arbitrary name. The characteristic configuration of this embodiment will be described below, focusing on the differences from the fourth embodiment.

[0174] First, in this embodiment, the arbitrary name is composed of a first part and a second part. One of the parts (the second part) prompts the user to set an arbitrary string, while the other part (the first part) provides guidelines for setting it. Specifically, one part (the first part) is configured to prompt the user to input the unique information of the destination robot.

[0175] As shown in Figure 27, when no arbitrary name has been set, the name display section D3 of the scene parameter setting screen WD displays the message "Recipient's unique information_Arbitrary string" to prompt the user to set a name that conforms to the above guidelines. This message disappears when the user clicks on the name display section D3 and starts typing. For example, in the example shown in Figure 27, the arbitrary name is composed of the combination of unique information = "Robot X" and arbitrary string = "Parameters for the first area".

[0176] Unique information can be broadly divided into fixed information (such as ID and serial number) that is set for each individual robot and cannot be changed, and arbitrary information (such as controller name and robot name) that can be arbitrarily set by the user using the teaching pendant 70, etc. (see Figure 28). Unique information is information that the user can confirm from the manufacturing plate of the robot 16 or from the teaching pendant 70.

[0177] In this embodiment, the occurrence of erroneous transmissions is suppressed by comparing the unique information contained in the arbitrary name set by the user with the unique information stored in the robot 16 when transmitting safety-related parameters. The transmission process in this embodiment will now be explained with reference to Figure 29, focusing on the differences from the transmission process shown in the fourth embodiment.

[0178] In the transmission process of this embodiment, if it is determined that the final confirmation operation has been performed in step S406, the process proceeds to step S501. In step S501, unique information is obtained from the robot specified as the destination by the user. Specifically, fixed information such as the ID and serial number stored in the robot, and arbitrarily set information such as the controller name and robot name are obtained. The configuration for specifying the destination is the same as in the fourth embodiment, so the explanation is omitted.

[0179] After obtaining unique information from the destination robot, the process proceeds to step S502, where the unique information contained in the user-defined arbitrary name is compared with the unique information obtained from the destination. If, in this comparison, the unique information contained in the user-defined arbitrary name matches any of the unique information obtained from the destination, a positive determination is made in step S503, and the process proceeds to step S409, where the transmission process is executed and then terminated. In the transmission process, the scene number, safety-related parameters, and the user-defined arbitrary name (the destination's unique information and an arbitrary string) are sent to the robot designated as the destination. Note that the transmission process can also be configured to send only the arbitrary string from the arbitrary name.

[0180] In the matching process in step S502, if the unique information contained in the arbitrary name set by the user does not match any of the unique information obtained from the destination, a negative determination is made in step S503, and the process proceeds to step S506, where the transmission of safety-related parameters is canceled (same as in step S408) and the name setting is taught (same as in step S403), and then the transmission process is terminated.

[0181] The user-defined arbitrary name includes unique information specific to the recipient's control device, enabling verification using this unique information. By configuring the system to identify erroneous transmissions in this way, human error can be significantly reduced.

[0182] <Example 1> In the fifth embodiment described above, the PC 60 compares the unique information contained in the arbitrary name set by the user with the unique information of the destination robot 16, and if the unique information contained in the arbitrary name set by the user is not included in the unique information of the destination robot 16, the transmission is stopped (i.e., the safety-related parameter group is not transmitted). However, this may be changed as follows. That is, the robot 16 compares the unique information contained in the arbitrary name set by the user with the unique information of the destination robot 16, and if the unique information contained in the arbitrary name set by the user is not included in the unique information of the destination robot 16, the robot 16 may refuse to receive the safety-related parameter group.

[0183] <Modification 2> The robot 16 may specify information to be included in the arbitrary name, and restrict the transmission and reception of safety-related parameters, etc., to be permitted only if the specified information is included in the arbitrary name, and to prevent transmission or reception if it is not included. Alternatively, the robot 16 may specify an arbitrary name, and restrict the transmission and reception of safety-related parameters, etc., to be permitted only if the specified arbitrary name matches the arbitrary name set by the user on the PC 60, and to prevent transmission or reception if they do not match.

[0184] <Variation 3> A configuration may be used to create a unique value from a group of safety-related parameters using CRC calculation, and to monitor for data loss or tampering by comparing the results of the CRC calculation performed on the transmitting side (PC60 side) with the results of the CRC calculation performed on the receiving side (robot 16 side). Alternatively, the CRC calculation of the safety-related parameter group may include some or all of an arbitrary name.

[0185] <Sixth Embodiment> The unique information shown in the fifth embodiment above has significant differences in characteristics between fixed information (e.g., ID and serial number) and arbitrarily set information (e.g., robot name and controller name). IDs and serial numbers are assumed to be set in a way that avoids duplication (collisions) when identifying them with other devices. In other words, since there are virtually no robots with the same fixed information, the likelihood of matching (risk of confusion) when comparing fixed information is low. However, much of the fixed information consists of meaningless combinations of alphanumeric characters, making it difficult for users to identify which robot corresponds to a given fixed information (see example in Figure 30(a)).

[0186] On the other hand, for arbitrary setting information such as controller names and robot names, it is possible to use names that are meaningful enough for the user to understand (easy-to-understand names). Therefore, it becomes easier for the user to identify which robot corresponds to an arbitrary name from the arbitrary setting information compared to identifying it from fixed information (see example in Figure 30(a)). However, by leaving the setting of arbitrary setting information to the user, the possibility of the same arbitrary name being set for multiple robots becomes higher than with the fixed information mentioned above.

[0187] One of the features of this embodiment is that, taking into account these differences in characteristics, guidelines for setting arbitrary names are defined as follows. Below, the characteristic configuration of this embodiment will be described, focusing on the differences from the fifth embodiment.

[0188] As shown in Figure 30(b), in the name display unit D3 shown in this embodiment, if an arbitrary name has not been set, a message is displayed instructing the user on how to set an arbitrary name (specifically, "Fixed information (serial number, etc.) - Arbitrary setting information (controller name, etc.) - Arbitrary string"). In other words, in this embodiment, the user is instructed to construct the arbitrary name using a combination of three pieces of information. Furthermore, when the user moves the cursor over the name display unit D3, more detailed guidelines (for example, other examples of fixed information and arbitrary setting information, and how to check each piece of information) will be displayed in a pop-up window.

[0189] For example, when setting an arbitrary name for a group of parameters for a robot with serial number = "0001" and controller name = "RobotX", if the user sets the arbitrary string = "Parameters for Area 1", setting the arbitrary name according to the guidelines will result in the arbitrary name = "0001_RobotX_Parameters for Area 1" (see Figure 31). Now, referring to Figure 31, the handling of each piece of information constituting the arbitrary name in this embodiment will be explained.

[0190] In the example shown in Figure 31, robot 16X, located in the first area EX of the factory, and robot 16Y, located in the second area EY, are identical in type, but they perform different tasks in each area. In other words, the tasks do not overlap. Specifically, the main scene 1 for robot 16X and the main scene 1 for robot 16Y are assumed to be different tasks.

[0191] The user then sets the parameters for the main scene 1 for robot 16X on PC60, and sets an arbitrary name, "0001_RobotX_Parameters for the first area," which is a combination of the fixed information, the robot 16X's manufacturing number "0001," the arbitrary setting information, the controller name "RobotX," and the arbitrary string "Parameters for the first area." When sending this set of parameters to robot 16X, the information is verified between PC60 and robot 16X, as in the fifth embodiment described above.

[0192] In this embodiment, the target of verification is defined as "fixed information." In other words, the verification checks whether the fixed information (manufacturing number) included in the arbitrary name matches the fixed information (manufacturing number) stored in the robot 16X. In the example in Figure 31, since the manufacturing numbers match, the safety-related parameter group, scene number, and arbitrary name set in the PC 60 are transmitted to the robot 16X, and the transmitted safety-related parameter group is stored in the robot 16X's memory as the safety-related parameter group corresponding to main scene 1. As a result, the teaching pendant 70X connected to the robot 16X can display and verify the safety-related parameter group corresponding to main scene 1 stored in memory 55X on the display 71X. Furthermore, when the safety-related parameter group is displayed on the display 71X, not only the safety-related parameter group but also the arbitrary name is displayed together. Specifically, the arbitrary name is displayed as "Current parameter <0001_RobotX_Parameter for area 1>". In other words, the displayed arbitrary name includes the arbitrary setting information (controller name) "RobotX" and the arbitrary string "Parameter for area 1". The "RobotX" and "Parameters for Area 1" displayed on the display 71X can be used by the user to visually confirm whether the safety-related parameters applied to robot 16X are intended for this robot 16X.

[0193] Here, the above verification is also performed if an attempt is made to mistakenly send the above safety-related parameter set to robot 16Y. In the example in Figure 31, the fixed information (serial number) included in the arbitrary name does not match the fixed information (serial number) stored in robot 16Y. Therefore, as a result of the verification, the transmission of the safety-related parameter set from PC 60 to robot 16Y is not possible, and the erroneous transmission is avoided. In other words, the parameter overwrite is not performed on robot 16Y, and the parameters and names displayed on the teaching pendant 70Y's display 71Y remain unchanged.

[0194] <Example 1> In the sixth embodiment described above, the teaching pendants 70X and 70Y are configured to display arbitrary names of safety-related parameter groups on their displays 71X and 71Y. However, the configuration may also be such that the displayed arbitrary names display unique information stored in the robots 16X and 16Y. By visually comparing these, the user can easily confirm whether an incorrect set of safety-related parameters has been applied, thereby facilitating the verification process.

[0195] <Modification 2> In the sixth embodiment described above, the teaching pendants 70X and 70Y are configured to display all of the fixed information, arbitrary setting information, and arbitrary strings that constitute the arbitrary names of the safety-related parameter group on the displays 71X and 71Y. However, it is sufficient to display at least the arbitrary setting information, preferably the arbitrary setting information and arbitrary strings. In other words, it is possible to exclude the fixed information included in the arbitrary names from being displayed.

[0196] <Variation 3> In the sixth embodiment described above, the configuration was such that only fixed information was verified when transmitting safety-related parameter groups, etc., from the PC60 to the robots 16X and 16Y. However, the configuration may also include verification of arbitrarily set information.

[0197] <Seventh Embodiment> In each of the first to sixth embodiments described above, the safety of the robot 16 is improved by configuring the system to stop the robot 16 if it detects a force or speed exceeding a standard value or movement outside the standard area, thereby indicating an error. For example, if the robot 16 stops during automatic operation due to an error related to the force or position, the user can restart the robot 16's automatic operation by manually moving the robot 16 to resolve the error. In addition, when setting a movement trajectory for the robot 16, the user may operate the robot 16 by jogging or manually push and pull the robot 16 to teach it the movement trajectory, etc. As shown in the first embodiment, etc., it is preferable to configure the system to monitor by the safety-related unit PX not only during automatic operation but also during manual operation in order to improve the safety of the robot 16. However, the appropriate values ​​for each safety-related parameter are likely to differ depending on the situation and content of the manual operation. Furthermore, in order to achieve both improved convenience and improved safety when utilizing the manual operation function, the likelihood of the appropriate values ​​for each safety-related parameter differing becomes even higher.

[0198] In this embodiment, one of its features is that, taking these circumstances into consideration, measures have been taken to achieve both improved safety and convenience during manual operation. The measures will be explained below, with reference to Figure 32, focusing on the differences from the first embodiment. In the following explanation, the safety-related parameter group will also be referred to as a "scene," distinguishing it from the "work scene" in which the robot 16 operates, as shown in the first embodiment.

[0199] In this embodiment, instead of the special scene 2 shown in the first embodiment, manual operation scene D, manual operation scene R, and manual operation scenes 1 to 3 are provided. In other words, these five scenes are registered as scenes for manual operation, and during manual operation, monitoring etc. by the safety-related unit PX is performed based on one of these five scenes depending on the situation and work content.

[0200] Manual operation scene D is the default scene for manual operation. For example, it is set when the control mode in the drive control unit 52 is switched to manual operation mode, as described later, or when an error is resolved or teaching is completed. In manual operation scene D, speed and force are monitored (reference value setting = "enabled"), while position is not monitored (reference area setting = "disabled"). In the example shown in Figure 32, the speed and force limit levels are set to HI level, and the speed and force are severely limited, but this is not the only option. The limit levels are arbitrary. Force may also be excluded from monitoring. Excluding force from monitoring is effective in reducing the effort required to switch the state of the safety-related unit PX to recovery or to manual operation scene R each time the jog operation causes contact with equipment and applies force, resulting in a stop.

[0201] Manual operation scene R is intended to be selected when performing recovery work on a robot 16 that has stopped due to an error. In manual operation scene D, speed, force, and position are all monitored, but the limit levels for all of them are set to LOW. For example, when performing recovery work on a situation where robot 16 has stopped while stuck on equipment, the force required to pull robot 16 free may be large. As mentioned above, by lowering the force monitoring level, the difficulty of the recovery work is suppressed. Also, since manual operation scene R is set when robot 16 has gone outside the reference area, lowering the position monitoring level also suppresses the position monitoring function from interfering with the recovery work. Note that, as will be described later, this manual operation scene R is set when the safety-related unit PX is in the "recovery state," in which case force and position monitoring is disabled. Therefore, at least in combination with the "recovery state," even if the force and position judgment criteria mentioned above are triggered, the movement of robot 16 will not be hindered.

[0202] Manual Operation Scene 1 is intended to be selected when teaching is performed by jog operation on the teaching pendant 70, etc. Although manual operation is assumed, the user does not directly touch the robot 16, so the speed, force, and position limit levels are set to the minimum (MIN). In other words, it has the least restrictive limitations among Manual Operation Scenes 1-3.

[0203] Manual operation scenes 2 and 3 are intended to be selected when performing so-called direct teaching. Similar to manual operation scene 1, speed, force, and position are all monitored. However, unlike teaching via jog operation, direct teaching involves the user directly touching the robot 16. Therefore, the monitoring levels for speed, force, and position are all higher compared to manual operation scene 1.

[0204] Manual operation scenes 2 and 3 differ from each other in at least some safety-related parameters (e.g., at least one of speed, force, or position). In the example shown in Figure 32, manual operation scene 3 is differentiated by setting a higher speed limit level than manual operation scene 2, allowing users to select between these two manual operation scenes 2 and 3 depending on the situation in which direct teaching is performed. Since the robot 16 engages in various tasks in various areas, it is preferable to have a configuration that allows for selection of direct teaching depending on the situation in order to improve work safety and work efficiency.

[0205] Here, with reference to Figure 33, we will provide a supplementary explanation regarding the control mode in the drive control unit 52 and the state of the safety-related unit PX.

[0206] As shown in Figure 33(a), the drive control unit 52 is provided with two control modes: an automatic control mode for automatic operation and a manual operation mode for manual operation. In automatic control mode, drive control is performed according to the progress of an operation program created by the user, and the scene is switched to the scene specified by the "CHANGE SCENE" command, which is a scene switching command in the operation program. In contrast, in manual operation mode, the scene is switched according to the user's operation. In other words, the user can arbitrarily decide the timing and destination of the scene switch. Thus, the trigger for scene switching differs between automatic control mode and manual operation mode. Furthermore, the scene switching in manual operation mode is also related to the state of the safety-related unit PX. The state of the safety-related unit PX will be explained in more detail below with reference to Figure 33(b).

[0207] The state of the safety-related unit PX can be broadly classified into three categories: "normal state," "safe state," and "recovery state." The normal state allows the robot 16 to operate, and the drive control unit 52 can execute the operation program only when the safety-related unit PX is in the normal state and in automatic operation mode. If the above error occurs while in the normal state, the robot is forcibly stopped, and the state of the safety-related unit PX switches from the normal state to the safe state. In other words, the safe state can be described as a state in which the robot's operation is disabled and the robot 16 is held in the stopped position. In this safe state, the safety-related unit PX continues to monitor the robot 16, making it difficult to move the robot 16 from that position. Therefore, in order to restore the robot 16, it is necessary to switch the state of the safety-related unit PX to the recovery state. In the recovery state, force and position monitoring is disabled, so the monitoring function does not hinder the robot 16 from returning to the correct position and resolving the error.

[0208] Here, referring to Figure 34, the error resolution process will be explained, taking into account the relationship between the control mode, the state of the safety-related unit PX, and the set scene.

[0209] When the user initiates the operation to start driving while the safety-related unit PX is in the "normal state," automatic driving starts with the operating program specified by the user (see ta1). When automatic driving starts, the set scene is "Special Scene 1," which is the default in automatic control mode, and switches to one of "Main Scene 1 to Main Scene 9" as the operating program progresses.

[0210] During autonomous driving, the control mode is "Automatic Control Mode," the state of the safety-related unit PX is "Normal State," and the scene is one of "Main Scene 1 to Main Scene 9" or "Special Scene 1." If an error occurs during autonomous driving, such as when the robot 16 moves outside the reference area, the safety-related unit PX switches from "Normal State" to "Safe State," the robot 16 is forcibly stopped, and the scene automatically switches to "Special Scene 1" (see ta2).

[0211] Subsequently, the user switches the control mode from "automatic control mode" to "manual operation mode" by operating the teaching pendant 70, thereby switching the scene from "special scene 1" to "manual operation scene D," which is the default for "manual operation mode" (see ta3). Once the switch to "manual operation mode" is complete and the system is in "manual operation mode" and in a "safe state," a switch button to switch to "recovery state" appears on the teaching pendant 70's display 71 (see the top screen for details) (see ta4). In other words, the switch button is not normally displayed on the top screen of the display 71, and is only displayed when the above-mentioned conditions of "manual operation mode" and "safe state" are met. This is a measure to prevent the user from accidentally switching to recovery mode during autonomous driving.

[0212] When the user operates the toggle button, the safety-related unit PX switches from "safe state" to "recovery state," and the set scene switches to "manual operation scene R" (see ta5). This enables the recovery operation of the robot 16. When the user manually moves the robot 16 to perform the recovery operation, force and position monitoring is disabled because the safety-related unit PX is in the "recovery state" (see ta6). Although the disabled function in the "recovery state" is configured to perform monitoring using the scene's judgment criteria (reference values ​​and reference areas), the result (decision to stop) is disabled. However, this does not preclude the option of configuring the system to not perform monitoring at all. Incidentally, if the system remains in the "recovery state" for a certain period of time, the safety-related unit PX automatically returns to the state it was in before entering the "recovery state," i.e., the "safe state."

[0213] Once the recovery process is complete and the error is resolved, the safety-related unit PX returns from "recovery state" to "normal state," and the scene switches from the recovery-use "manual operation scene R" to the default "manual operation scene D" (see ta7). Subsequently, when the user switches to automatic control mode, the control mode switches from "manual operation mode" to "automatic control mode," and the scene switches from "manual operation scene D" to "special scene 1," which is the default in automatic control mode (see ta8).

[0214] Subsequently, the automatic operation will resume from the point where it was interrupted due to an error in the operating program (see ta9). At this point, the scene that was set when the operating program resumed will be reset, and from then on, the scenes will switch sequentially according to the "CHANGE SCENE" command in the operating program.

[0215] As shown in this embodiment, providing an automatic control mode for automated operation (corresponding to the "automatic operation mode") and a manual operation mode for manual operation as control modes for the robot, and considering manual operation as described above, is preferable for improving safety and work efficiency when performing such manual operation. However, the situations assumed in the automatic control mode and the manual operation mode are significantly different, and various safety-related parameters may differ in order to properly perform safety functions. In other words, if the same scene is referenced in both the automatic control mode and the manual operation mode, it may become difficult to achieve improved safety and productivity during automated operation, as well as improved safety and work efficiency during manual operation. In this regard, the configuration shown in this embodiment provides a scene that is referenced when the robot is automated and a scene that is referenced when the robot is manually operated. This makes it possible to properly perform safety functions during both automated and manual operation.

[0216] Furthermore, during autonomous driving, the scene automatically switches according to the control program's switching instructions, as described above, while the scene for manual operation switches according to the user's input. This configuration prevents the scene from suddenly switching at times unintended by the user. This is desirable for further improving safety.

[0217] If the robot stops because it has moved outside the monitoring reference area specified by the user, an operation is performed to return the robot to the monitoring reference area. In the configuration shown in this feature, the robot's position is irrelevant when switching to a manual operation scene, so there is no inconvenience such as difficulty in switching to a manual operation scene depending on the robot's position. This is preferable for smoothly performing recovery operations to restart the robot's movement.

[0218] According to the seventh embodiment described in detail above, it is possible to improve the safety of the robot while contributing to increased productivity by the robot during autonomous operation and improved work efficiency for the user during manual operation.

[0219] <Example 1> During autonomous driving, it is possible to disable switching to a manual operation scene. For example, during autonomous driving, the robot 16's position is checked when safety-related parameters are automatically switched to avoid inappropriate scene switching. In contrast, the user can switch to a manual operation scene, but no position check is performed at that time. If a manual operation scene is set as an autonomous driving scene, the reliability of the safety function may decrease because position checks are not performed. Therefore, as shown in this modified example, disabling switching to a manual operation scene during autonomous driving has technical significance in preventing a decrease in reliability.

[0220] <Modification 2> In the seventh embodiment described above, a manual operation scene R for recovery is provided in addition to the manual operation scene D for defaults, but the system is not limited to this configuration. It is also possible for manual operation scene D to also serve as manual operation scene R. Furthermore, it is possible for manual operation scene D and manual operation scene R to also serve as manual operation scene 1 for teaching via jog operation. Note that the number of manual operation scenes is not limited to five. As long as at least multiple scenes, including a manual operation scene for defaults, are provided as manual operation scenes, the number is arbitrary. For example, there may be two, three, four, or six or more.

[0221] <Variation 3> In the seventh embodiment described above, when the safety-related unit PX is in a safe state and the control mode is in manual operation mode, a recovery button is displayed on the display 71 of the teaching pendant 70, and the system switches to the recovery state and manual operation scene R when the user operates the recovery button. However, it is also possible to configure the system to separate the operation of switching to the recovery state from the operation of switching to the manual operation scene R. It is also possible to configure the system to allow switching to the recovery state or manual operation scene R when the safety-related unit PX is in a safe state and the control mode is in automatic control mode.

[0222] <Modification 4> If the robot 16 is stopped by a safety function, and a switch operation to manual operation mode is performed, it is also possible to configure the system so that the system switches to manual operation scene R as a result of this switch operation.

[0223] <Modification 5> For manual operation scenes 1 to 3, it is preferable to configure the system so that when the user selects a scene while in manual operation mode, the system switches to the selected scene.

[0224] <Variation 6> The manual operation scenes 2 and 3 shown in the seventh embodiment described above can also be defined as sub-scenes of the manual operation scene.

[0225] <Other Embodiments> Furthermore, the implementation is not limited to the descriptions of each embodiment above, and may be carried out as follows, for example. Incidentally, each of the following configurations may be applied individually to each of the above embodiments, or some or all of them may be applied to each of the above embodiments in combination. In addition, it is possible to arbitrarily combine all or some of the various configurations shown in each of the above embodiments. In this case, it is preferable that the technical significance (effects exhibited) of each configuration to be combined is ensured. Each of the following configurations may be applied individually to a new configuration consisting of a combination of embodiments, or some or all of them may be applied in combination.

[0226] In a configuration where the robot 16 performs multiple tasks (work routines) according to a predetermined time schedule, it is also possible to configure the system to manage the progress of the work routine based on the time elapsed since the start of the routine or the current time, and to switch safety functions based on that time or time. Furthermore, to account for delays in the schedule, it is also possible to configure the system to switch safety functions based on the time or time and information indicating the delay time. In addition to the configuration that switches safety functions according to the work scene of the robot 16 as shown in each of the embodiments above, it is also possible to configure the system to switch safety functions based on the elapsed time or the current time.

[0227] In each of the above embodiments, the AGV 21 and the robot arm 31 are combined to form the robot 16, which moves between areas by self-propulsion, but the configuration is not limited to this. For example, as shown in Figure 35, a base 19 is installed between two lines L1 and L2, and the base 32 of the robot arm 31 is fixed to the base 19. The arm body 33 of the robot arm 31 can then rotate horizontally to change its orientation, allowing it to switch between a state in which it is engaged in a first task in the first work area LE1 of the first line L1, and a state in which it is engaged in a second task different from the first task in the second work area LE2 of the second line L2. In this case, it is preferable to configure the robot arm 31 so that when the end-effector of the robot arm 31 moves from the second work area LE2 to the reference position LP1 in the first work area LE1, the safety function of the robot arm 31 (such as the judgment criteria for operation monitoring parameters) switches to the first work mode, and when the end-effector of the robot arm 31 moves from the first work area LE1 to the reference position LP2 in the second work area LE2, the safety function of the robot arm 31 switches to the second work mode.

[0228] Furthermore, in a configuration where a robot installed at a predetermined position on a line performs multiple different types of tasks depending on the type of workpiece supplied by a conveyor, etc., it is also possible to configure the system to identify the work scene and switch safety functions (safety-related parameters) for each work scene. In addition, the work scenes may be further subdivided as described above, and the safety functions may be switched for each subdivided scene.

[0229] In the picking operation scene SCN3, the safety function may be configured to switch between two separate scenes: the scene of removing the workpiece from the processing machine 14 and the scene of moving to the adjacent processing machine. Furthermore, the safety function may be configured to switch between the first half (until the workpiece is grasped) and the second half (until the workpiece is moved to container B) of the workpiece removal scene.

[0230] Furthermore, it is possible to subdivide the work scene into scenes where the distance between people is expected to be relatively close and scenes where the distance between people is expected to be relatively far, and to configure the system to switch safety functions for each of these subdivided scenes.

[0231] The specific timing for starting a scene change sequence is arbitrary. For example, when moving from one work scene to the next, the start time could be when the previous work scene is completed or when the transition to the next work scene begins. Alternatively, it could be just before or immediately after moving from one work area to another.

[0232] Whether or not to allow the robot arm 31 to continue operating during the switching of safety functions is optional. It is also possible to configure the system so that the robot arm 31 is temporarily stopped when switching to a stricter judgment criterion, while the robot arm 31 continues operating when switching to a less strict judgment criterion.

[0233] In each of the above embodiments, a CRC (Critical Reference Code) is added as diagnostic information to diagnose whether transmission and reception between the non-safety related unit PY and the safety related unit PX are functioning correctly. The method of setting this CRC is arbitrary and does not necessarily have to be based on the command ID and data of the request command.

[0234] In the first embodiment described above, the request commands from each non-safety related part PY (control device) are configured to share a common number (scene number = 1 to 9) that specifies the work scenes SCN1 to SCN9, but the system is not limited to this configuration. The scene number may be different depending on which non-safety related part PY the request command originates from. For example, the scene number may be 1 to 9 for a request command when the control device is the teaching pendant 70, 11 to 19 for a request command when the control device is the drive control unit 52 (PackScript), and 21 to 29 for a request command when the control device is the IO80.

[0235] The control device 51 in each of the above embodiments is configured to pre-store values ​​of the safety-related parameter group in association with scene numbers, and to identify each value from the scene number specified by the non-safety-related unit PY, but it is not limited to this configuration. The non-safety-related unit PY may also be configured to send each setting value to the safety-related unit PX instead of the scene number.

[0236] • In the embodiments described above, the scene was constructed using a set of safety-related parameters, but the invention is not limited thereto. The robot's safety function may be implemented by a simple configuration that monitors the robot's movement based on one criterion (e.g., speed or force). However, even with such a configuration, it is preferable to switch the criterion depending on the situation, for example, switching the criterion based on a criterion switching command during autonomous driving, and switching to a manual operation criterion based on user operation during manual operation.

[0237] • In the embodiments described above, examples were given of applying the robot 16 to a processing line in a factory 10, but the application of the robot 16 is not limited to processing lines. The robot 16 can also be applied to assembly lines, inspection lines, and packaging lines.

[0238] <Regarding the group of inventions extracted from the above embodiments> The following describes the features of the group of inventions extracted from the above embodiments, showing their effects and other aspects as necessary. For ease of understanding, corresponding configurations in the above embodiments will be indicated in parentheses as appropriate, but the invention is not limited to these specific configurations.

[0239] <Features Group A> Scene Name The following characteristic group A is based on the background technology, which states that "robot control systems applied to robots such as industrial robots have a safety-related section that implements safety functions for the robot and a non-safety-related section that performs drive control of the robot, etc. Regarding the safety-related section, for example, it has been proposed that the robot will be forcibly stopped if it collides with an obstacle such as a person (see, for example, Patent Document 1), or that the force (thrust) and speed of the robot in motion will be monitored and the robot will be forcibly stopped if it moves outside of safety standards." In recent years, due to advances in robot technology, the types of tasks that a single robot can perform are increasing. When a single robot is used for various tasks, if the safety functions are uniform, it may be difficult to achieve both improved robot safety and improved productivity (work efficiency) by the robot. In view of these circumstances, the inventor of this invention has devised a configuration that switches the safety functions of the robot according to the work content, etc. Here, in order to suppress the impairment of safety functions due to communication errors, etc. during the change, the input for changing the safety function is set to the safety-related input section or It is preferable to use these inputs (so-called safety inputs). However, if safety inputs are made a mandatory requirement, the constraints on changes will become stronger, which is expected to hinder the improvement of the operability of changing safety functions. On the other hand, if this requirement is simply avoided, improved operability can be expected, but there are concerns that confidence in the robot's safety functions will be shaken. Thus, there is still room for improvement in the configuration related to changing safety functions in order to improve the safety and work efficiency of the robot. Furthermore, in order to improve both safety and productivity, it is effective to provide various safety-related parameters that affect safety functions, enabling detailed consideration of work content, etc. A setting support system that assists the user in setting a group of safety-related parameters (scenes) and transmits the set safety-related parameter group to the robot control device can contribute to reducing the user's workload. However, if the number of configurable items increases, the number of items that the user must check when transmitting the safety-related parameter group to the robot control device will increase, and it will become practically difficult to check all items each time.As a result, users are more likely to make operational errors, such as mistakenly selecting the wrong set of safety-related parameters to send and sending them without realizing it. If the incorrect set of safety-related parameters is stored and referenced in the robot control system, there is a concern that the robot's safety functions will not function properly. Thus, in order to improve the safety and workability of the robot while suppressing setting errors related to safety functions, there is still room for improvement in the configuration related to the setting of said safety functions. This was done in consideration of the background and challenges described above.

[0240] Feature A1. The robot (robot 16) is driven and controlled according to each operation instruction (command for drive control) that constitutes the control program for the robot (robot 16), and the robot is driven and controlled by a drive control unit (drive control unit 52), which has an operation determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) that includes correlation information correlated with at least one of the force and speed of the robot during drive control, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple scenes (e.g., main scenes) which are groups of safety-related parameters that include the determination criteria as safety-related parameters that affect the safety function are set, and the operation determination unit is configured to make the determination by referring to one of these scenes, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the scene included in the control program is made A setting support system is connected to a robot control device (control device 51) that is configured to switch the referenced scene based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful) when the "SCENE" command is reached, and which assists the user in setting each of the aforementioned scenes. A storage means (storage function of PC60) that stores each of the safety-related parameters entered by the user for each scene, A transmission means (communication function of PC60) that transmits the scene stored in the storage means to the robot control device based on a user's transmission operation. Equipped with, The system is configured so that users can set a scene name for each of the aforementioned scenes. A setting support system equipped with a notification means (for example, a function to display the scene name on the display 61) for notifying the user of the scene name set by the user for the scene being set up.

[0241] As shown in this feature, by incorporating scene (safety-related parameter group) switching instructions into the robot's control program, and enabling scene switching during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to various conditions such as the surrounding environment and work content. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the scene is switched automatically, inappropriate scene switching may occur due to disturbances in the robot's behavior or noise, which may result in a mismatch between the pre-planned scene and the actual scene. This is a concern as it may hinder the proper performance of safety functions. In this regard, this feature is configured so that when a switching instruction is reached in the control program, the scene is switched only if predetermined switching conditions are met. In other words, the configuration allows for confirmation of requirements such as whether or not a scene can be switched. This is desirable for suppressing scene switching that deviates from the user's intention and for suppressing the occurrence of the aforementioned mismatch.

[0242] Here, if there are many safety-related parameters that can be set according to various conditions such as the surrounding environment and work content, safety functions can be finely adjusted (changed) according to the situation. This is advantageous in achieving both improved robot safety and improved productivity by the robot. However, if there are many configurable items, the number of items that the user must check when sending the safety-related parameter group (scene) from the setting support system to the robot control device increases, and it becomes practically difficult to check all items each time. As a result, users are more likely to make work errors, such as selecting the wrong safety-related parameter group to send and sending it without realizing it. If the wrong safety-related parameter group is stored in the robot control device, there is a concern that the robot's safety functions will not be properly performed due to the application of that parameter group. In this regard, the configuration shown in this feature allows setting a name for each scene (scene name), and the scene name is notified for the scene being set. By using such a function, it is possible to realize a configuration in which the safety-related parameter group can be easily understood without checking each safety-related parameter individually. For example, users can determine if their work is appropriate by checking the scene name without having to check individual safety-related parameters when sending data. In other words, being able to set a scene name for a group of safety-related parameters is effective in suppressing the aforementioned work errors. For these reasons, by switching scenes consisting of a group of safety-related parameters, it is possible to achieve both improved robot safety and increased productivity while suppressing the increase in work errors caused by these factors.

[0243] Furthermore, the description "a setting support system that can be connected to a robot control device (controller 51) configured to switch the referenced scene based on predetermined switching conditions (e.g., stop condition, position condition, command normal) being met when a scene switching instruction ("CHANGE SCENE" command) included in the control program is reached during drive control of the robot based on the control program, and assists the user in setting each of the aforementioned scenes" may be changed to "a setting support system that can be connected to a robot control device (controller 51) configured to switch the referenced scene based on predetermined switching conditions (e.g., stop condition, position condition, command normal) being met when a scene switching instruction ("CHANGE SCENE" command) included in the control program is reached during drive control of the robot based on the control program, and continues drive control of the robot, while interrupting drive control of the robot if the predetermined switching conditions are not met, and assists the user in setting each of the aforementioned safety-related parameters for each of the aforementioned scenes."

[0244] Incidentally, for example, if the diagnosis of a command related to a switching instruction results in the command being deemed normal and it is confirmed that the robot is in the correct position, then it would be good to set the "predetermined switching condition" to "fulfilled".

[0245] Feature A2. The robot (robot 16) is driven and controlled according to each operation instruction (command for drive control) that constitutes the control program for the robot (robot 16), and the robot is driven and controlled by a drive control unit (drive control unit 52), which has an operation determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) that includes correlation information correlated with at least one of the force and speed of the robot during drive control, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple scenes (e.g., main scenes) which are groups of safety-related parameters that include the determination criteria as safety-related parameters that affect the safety function are set, and the operation determination unit is configured to make the determination by referring to one of these scenes, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the scene included in the control program is made A setting support system is connected to a robot control device (control device 51) configured to switch the reference scene based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful) including position conditions that define the position of the robot when the "SCENE" command is reached, and which assists the user in setting each of the safety-related parameters for each of the scenes. A storage means (storage function of PC60) that stores each of the safety-related parameters entered by the user for each scene, A transmission means (communication function of PC60) that transmits the scene stored in the storage means to the robot control device based on a user's transmission operation. Equipped with, The system is configured so that users can set a scene name for each of the aforementioned scenes. A setting support system equipped with a notification means (a function that displays the name of the scene on the display 61) for notifying the user of the scene name set by the user for the scene being set up.

[0246] As shown in this feature, by incorporating scene (safety-related parameter group) switching instructions into the robot's control program, and enabling scene switching during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to various conditions such as the surrounding environment and work content. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the scene is switched automatically, inappropriate scene switching may occur due to disturbances in the robot's behavior or noise, potentially resulting in a mismatch between the pre-planned scene and the actual scene. This is a concern as it may hinder the proper performance of safety functions. Here, even if the robot is engaged in various tasks, its movements will basically follow the control program described above, so there will be a certain relationship between the task and the area (operating area) in which the task is performed. Taking this into consideration, this feature is configured to switch scenes only when predetermined switching conditions, including position conditions, are met. In this way, by performing at least a position check when switching scenes, the above concerns can be eliminated, and it is possible to switch scenes appropriately.

[0247] Here, if there are many items of safety-related parameters that can be set in accordance with various situations such as the surrounding environment and work content, the safety function can be finely adjusted (changed) in accordance with the situation. This is advantageous for achieving both improvement of robot safety and improvement of productivity by the robot. However, when the number of settable items increases, the number of items that a user should check when transmitting a safety-related parameter group (scene) from the setting support system to a robot control device increases, and it becomes substantially difficult to check all items every time. As a result, work errors such as the user not noticing when incorrectly selecting the safety-related parameter group to be transmitted and transmitting it as it is are likely to occur. If an incorrect safety-related parameter group is stored in the robot control device as it is, there is a concern that the safety function of the robot may not be properly exhibited due to the application of the parameter group. In this regard, with the configuration shown in the present feature, a name of the scene (scene name) can be set for each scene, and the scene name is notified for the scene under setting support. By using such a function, it is possible to realize a configuration that allows easy understanding of what the safety-related parameter group is without individually checking the safety-related parameters. For example, the user can determine whether his / her own work is appropriate by checking the scene name without checking individual safety-related parameters at the time of transmission. In other words, making the scene name of the safety-related parameter group settable is effective in suppressing the above-described work errors. For the above reasons, by switching scenes composed of safety-related parameter groups, it is possible to achieve both improvement of robot safety and improvement of productivity by the robot, while suppressing an increase in work errors caused thereby.

[0248] Feature A3. The setting support system according to Feature A1 or Feature A2, wherein the scene name is a name (for example, an arbitrary name) that can be set by a user, separately from identification information (for example, a scene number) assigned by the setting support system for identifying the scene by the setting support system.

[0249] In the setting support system, the scenes can be appropriately managed by using identification information for scene identification. However, it is unclear whether users can view such identification information and appropriately identify the scenes (safety-related parameter groups). For example, if the identification information is merely numbers or a string of numbers, it is difficult to intuitively understand the corresponding scene or the robot to which the scene is applied from the identification information. With regard to this point, if the structure is such that the user can set a scene name separately from the system identification information, it becomes easier for the user to intuitively understand the corresponding scene and the like from the name. Therefore, it becomes easier to understand what the scene is like without checking each item of the safety-related parameters constituting the scene. This is advantageous in reducing the work of checking individual safety-related parameters when transmitting the scene to a robot controller, as described in Feature A1.

[0250] Feature A4. The setting support system according to any one of Features A1 to A3, wherein the display unit (display 61) is caused to display each of the safety-related parameters constituting the scene that is being supported for setting, and the scene name of the scene.

[0251] If the structure is such that the scene name set by the user as shown in this feature is displayed on the display unit together with the scene (safety-related parameter group) corresponding to the scene name, the user can easily check the relationship between the safety-related parameter group and the scene name. This is advantageous in reducing operation errors as described in Feature A1 etc.

[0252] Note that, for example, a configuration in which the scene name set by the user is displayed on the setting screen of each scene is preferable. With such a configuration, since the user can check the scene name as appropriate when setting safety-related parameters for each scene, setting errors (operation errors) caused by confusion with other scenes (including scenes for other robot controllers) can be reduced.

[0253] Feature A5. A setting support system according to any one of Feature A1 to Feature A4, wherein when transmitting the scene to the robot control device based on a user's transmission operation, the user is notified of the scene name of the scene at least before the transmission operation is performed.

[0254] As shown in this feature, when transmitting a scene to a robot control device, informing the user of the scene name at least before the transmission operation is performed can reduce the chances of erroneous scene transmission or misconfiguration. For example, it is advisable to display the names of the safety-related parameter groups on the transmission screen when transmitting a scene.

[0255] Feature A6. A setting support system according to any one of Feature A1 to Feature A5, wherein for scenes in which the scene name has not been set, transmission to the robot control device is not possible.

[0256] By defining the setting of a scene name as a condition for transmitting the scene to the robot control device, the effects shown in Feature A1, etc., can be effectively achieved.

[0257] Feature A7. A setting support system according to any one of Feature A1 to Feature A6, wherein when transmitting the scene to the robot control device, the robot control device is notified of the scene name along with the scene.

[0258] By notifying the robot control device of the scene name, the robot control device can also recognize the scene name.

[0259] Feature A8. The setting support system according to Feature A7, which has a plurality of devices connected to the robot control device, and is configured such that the scene and scene name can be displayed by connecting devices other than the device that transmitted the scene to the robot control device to the robot control device.

[0260] By connecting a device other than the one that transmitted the scene and scene name (for example, a teaching pendant) to the robot control unit, the scene and scene name can be displayed on that other device, allowing the user to retrospectively check whether any scenes were transmitted incorrectly.

[0261] Feature A9. The setting includes means for prompting the user to include unique information relating to the robot control device that will be the destination, The setting support system according to feature A7 or feature A8, which, when transmitting the aforementioned scene to the robot control device, compares the scene name with the unique information relating to the destination robot control device, and if the scene name contains the unique information, the scene can be set on the robot control device, while if the scene name does not contain the unique information, the scene cannot be set on the robot control device.

[0262] The scene name set by the user includes unique information specific to the receiving robot control device, enabling matching using this unique information. By configuring the system to identify erroneous transmissions in this way, human error can be significantly reduced.

[0263] Feature A10. A setting support system according to any one of Feature A7 to Feature A9, which allows the user to change each of the safety-related parameters for the configured scene, and has a means to prompt the user to change the scene name of the scene when such change is made.

[0264] As shown in this feature, prompting the user to change the scene name when any one of the safety-related parameters is changed is preferable in order to prevent confusion between the scenes before and after the change.

[0265] Feature A11. A setting support system according to any one of Feature A7 to Feature A10, wherein if any of the safety-related parameters for a pre-configured scene are changed, the transmission of the safety-related parameter group to the robot control device is disabled until the scene name of that scene is changed.

[0266] By requiring a change in the scene name when any of the safety-related parameters for a pre-configured scene are changed, the effects described in Feature A10 above can be effectively achieved.

[0267] Feature A12. A setting support system according to any one of Feature A1 to Feature A11, wherein a plurality of devices are connected to the robot control device, and the setting of the scene name is possible in a specific device among the plurality of devices that is capable of setting the scene, and the setting of the scene name is not possible in other devices that are not capable of setting the scene.

[0268] By allowing scene name settings only on specific devices where scene settings are possible, it is possible to prevent accidental setting or changing of scene names due to operational errors when operating other devices where scene settings are not possible. This is preferable, for example, in order to effectively support the confirmation of scene names when checking them retrospectively.

[0269] Feature A13. The robot (robot 16) is driven and controlled according to each operation instruction (command for drive control) that constitutes the control program for the robot (robot 16), and the robot the operation determination unit (logic unit X2) which has a safety-related unit (safety-related unit PX) which has an operation determination unit (logic unit X2) which determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) that includes correlation information that correlates with at least one of the force and speed of the robot during drive control and a determination criterion (reference value or reference area) for the correlation information that is stored in advance, and realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple scenes (e.g., main scene) which are a group of safety-related parameters that include the determination criterion as a safety-related parameter that affects the safety function are set, and the operation determination unit is configured to make the determination by referring to one of the scenes, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the scene included in the control program is made A setting support system is connected to a robot control device (control device 51) that is configured to switch the referenced scene based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful) when the "SCENE" command is reached, and which assists the user in setting each of the aforementioned scenes. A configuration support system configured to allow the user to set a scene name for each of the aforementioned scenes.

[0270] As described in this feature, if an instruction to switch a scene (a group of safety-related parameters) is incorporated into a robot control program to enable scene switching during drive control (during automatic operation), this can contribute to realizing a configuration that allows safety functions to be properly exhibited in accordance with various situations such as the surrounding environment and work content. This is preferable for achieving both improvement in robot safety and improvement in productivity by the robot at the same time. However, as described in this feature, when adopting a configuration in which scenes are automatically switched, inappropriate scene switching may occur due to disturbances in robot behavior, noise, or the like, which may cause a mismatch between a pre-assumed scene and the actual scene. This is feared to be an obstacle to properly exhibiting the safety functions. Regarding this point, in this feature, when a switching instruction in the control program is reached, the configuration is such that scene switching is executed on the condition that a predetermined switching condition is satisfied. In other words, the configuration allows for checking requirements such as whether switching is permitted when switching scenes. This is preferable for suppressing scene switching that deviates from the user's intention and suppressing the occurrence of the mismatch described above.

[0271] Here, if there are many safety-related parameters that can be set according to various conditions such as the surrounding environment and work content, safety functions can be finely adjusted (modified) according to the situation. This is advantageous in achieving both improved robot safety and improved productivity by the robot. However, if there are many configurable items, the number of items that the user must check when sending the safety-related parameter group (scene) from the setting support system to the robot control device increases, and it becomes practically difficult to check all items each time. As a result, users are more likely to make work errors, such as selecting the wrong safety-related parameter group to send and sending it without realizing it. If the wrong safety-related parameter group is stored in the robot control device, there is a concern that the robot's safety functions will not be properly performed due to the application of that parameter group. In this regard, the configuration shown in this feature allows setting a name for each scene (scene name). By using this name setting function, it is possible to realize a configuration in which it is easy to understand what the safety-related parameter group is without checking each safety-related parameter individually. For example, when sending, the user can determine whether their work is appropriate by checking the scene name without checking each safety-related parameter. In other words, enabling the setting of scene names for safety-related parameter groups is effective in suppressing the aforementioned work errors. For these reasons, by switching scenes consisting of safety-related parameter groups, it is possible to achieve both improved robot safety and increased productivity while suppressing the increase in work errors caused by these factors.

[0272] Furthermore, the description in this feature, "A setting support system that can be connected to a robot control device (controller 51) configured to switch the referenced scene based on predetermined switching conditions (e.g., stop condition, position condition, command normal) being met when a scene switching instruction ("CHANGE SCENE" command) included in the control program is reached during drive control of the robot based on the control program, and assists the user in setting each of the aforementioned scenes," may be changed to "A setting support system that can be connected to a robot control device (controller 51) configured to switch the referenced scene based on predetermined switching conditions (e.g., stop condition, position condition, command normal) including position conditions defining the position of the robot being reached when a scene switching instruction ("CHANGE SCENE" command) included in the control program is reached during drive control of the robot based on the control program, and assists the user in setting each of the aforementioned safety-related parameters for each of the aforementioned scenes."

[0273] Feature A14. The robot (robot 16) is driven and controlled according to each operation instruction (command for drive control) that constitutes the control program for the robot (robot 16), and the robot is driven and controlled by a drive control unit (drive control unit 52), which has an operation determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) that includes correlation information correlated with at least one of the force and speed of the robot during drive control, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple scenes (e.g., main scenes) which are groups of safety-related parameters that include the determination criteria as safety-related parameters that affect the safety function are set, and the operation determination unit is configured to make the determination by referring to one of these scenes, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the scene included in the control program is made A setting support program installed on a computer that can be connected to a robot control device (control device 51) configured to switch the referenced scene based on predetermined switching conditions (e.g., stop condition, position condition, command successful) being met when the "SCENE" command is reached, and which allows the computer to assist the user in setting each of the aforementioned scenes, A setting support program that controls the computer so that the user can set a scene name for each scene.

[0274] The configuration described in this feature makes it possible to achieve both improved safety and increased productivity while suppressing the increase in work errors that may result from them.

[0275] Feature A15. The robot (robot 16) is driven and controlled according to each operation instruction (command for drive control) that constitutes the control program for the robot (robot 16), and the robot the operation determination unit (logic unit X2) which has a safety-related unit (safety-related unit PX) which has an operation determination unit (logic unit X2) which determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) which contains correlation information that correlates with at least one of the force and speed of the robot during drive control and a determination criterion (reference value or reference area) for the correlation information that is stored in advance, and realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple scenes (e.g., main scene) which are a group of safety-related parameters that include the determination criterion as a safety-related parameter that affects the safety function are set, and the operation determination unit is configured to make the determination by referring to one of the scenes, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the scene included in the control program is made A setting support program installed on a computer that can be connected to a robot control device (control device 51) configured to switch the referenced scene based on predetermined switching conditions (e.g., stop condition, position condition, command successful) being met when the "SCENE" command is reached, and which allows the computer to assist the user in setting each of the aforementioned scenes, To the aforementioned computer, A storage process that stores each of the safety-related parameters entered by the user for each scene, A transmission process that transmits the stored scene to the robot control device based on the user's transmission operation. Make it run, The aforementioned computer allows the user to set a scene name for each scene. A setting support program that causes the computer to perform a notification process to notify the computer of the scene name of the scene being supported in the setting process.

[0276] The configuration described in this feature makes it possible to achieve both improved safety and increased productivity while suppressing the increase in work errors that may result from them.

[0277] Furthermore, the technical concepts described in Features A2 through A12 can also be applied to this feature.

[0278] <Features Group B> Main Items Display The following characteristic group B is related to the background technology, which states that "robot control systems applied to robots such as industrial robots have a safety-related section that realizes the safety functions of the robot and a non-safety-related section that performs drive control of the robot, etc. Regarding the safety-related section, for example, it has been proposed that the robot will be forcibly stopped if it collides with an obstacle such as a person (see, for example, Patent Document 1), or that the force (thrust) and speed of the robot in motion will be monitored and the robot will be forcibly stopped if it moves outside of safety standards." In recent years, due to advances in robot technology, the types of tasks that a single robot can perform are increasing. When a single robot is used for various tasks, if the safety functions are uniform, it may be difficult to achieve both improved robot safety and improved productivity (work efficiency) by the robot. In view of these circumstances, the inventor of this invention has devised a configuration that switches the safety functions of the robot according to the work content, etc. Here, in order to suppress the impairment of the safety function due to communication errors, etc. during the change, it is preferable to make the input for changing the safety function an input from a safety-related input section (so-called safety input). However, if safety input is made a mandatory requirement, the constraints on changes will become stronger, which is expected to hinder improvements in the operability of changing safety functions. On the other hand, if this requirement is simply avoided, improvements in operability can be expected, but there are concerns that confidence in the robot's safety functions will be undermined. Thus, there is still room for improvement in the configuration related to changing safety functions in order to improve the safety and work efficiency of the robot. Furthermore, in order to improve both safety and productivity, it is effective to provide various safety-related parameters that affect safety functions, enabling detailed consideration of work content, etc. If a configuration is set up to support the user in setting a group of safety-related parameters (scenes) using a setting support device, the workload on the user can be reduced. However, if there are many configurable items, it will be difficult for the user to identify the necessary items. This is undesirable in terms of improving the efficiency of the setting work and can also be a factor in setting errors of safety-related parameters. Thus, in order to achieve improved safety and workability of the robot while suppressing setting errors related to safety functions, there is still room for improvement in the configuration related to setting these safety functions.This was done in consideration of the background and challenges mentioned above.

[0279] Feature B1. The robot (robot 16) is driven and controlled according to each operation instruction (command for drive control) that constitutes the control program for the robot (robot 16), and the robot is driven and controlled by a drive control unit (drive control unit 52), which has an operation determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) that includes correlation information correlated with at least one of the force and speed of the robot during drive control, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple scenes (e.g., main scenes) which are groups of safety-related parameters that include the determination criteria as safety-related parameters that affect the safety function are set, and the operation determination unit is configured to make the determination by referring to one of these scenes, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the scene included in the control program is made This setting support device (PC60) is applied to a robot control system (control system CS) configured to switch the reference scene based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful) when the "SCENE" command is reached, and assists the user in setting each of the safety-related parameters for each of the scenes, The display unit (PC60's display 61) and The display unit includes a display control unit (control unit 62 of PC60) that displays a parameter setting screen (parameter display unit D2 of the scene parameter setting screen WD) corresponding to the scene specified by the user, and Equipped with, A setting support device provided with a parameter setting screen that includes a first display mode (display of all items) which displays both the first parameter group and the second parameter group constituting the safety-related parameter group, and a second display mode (display of main items) which displays only the first parameter group out of the first and second parameter groups.

[0280] As shown in this feature, by incorporating scene (safety-related parameter group) switching instructions into the robot's control program, and enabling scene switching during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to the situation. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the scene is switched automatically, the scene may be switched due to accidental factors such as noise, resulting in a mismatch between the actual situation and the scene. This is a concern as it may hinder the proper performance of safety functions. In this feature, when a switching instruction is reached in the control program, the scene is switched only if predetermined switching conditions are met. This suppresses scene switching that deviates from the user's intention and reduces the occurrence of the aforementioned mismatch.

[0281] Here, if the number of user-configurable safety-related parameters for each scene increases, safety functions can be finely modified to suit the work content, etc. This is desirable in achieving both improved safety and increased productivity. However, if the number of configurable items increases, it becomes more difficult for users to identify the necessary items. This is undesirable in terms of streamlining the configuration process and can lead to errors in setting safety-related parameters. In this regard, the configuration shown in this feature provides two display modes for the safety-related parameter group on the parameter setting screen: a first display mode (all items display) that displays both the first and second parameter groups that constitute the safety-related parameter group, and a second display mode (main items display) that displays only the first parameter group from the two parameter groups. In the second display mode, the display target is limited to the first parameter group, making it easier for users to narrow down the necessary items. On the other hand, in the first display mode, both the first and second parameter groups are displayed (configurable), making it possible to set and check individual safety-related parameters. Providing two display modes in this way is desirable because it allows for both improved safety and increased productivity while suppressing user configuration errors.

[0282] Furthermore, the description of the "second display mode" shown in this feature may be changed from "displays the first parameter group from the first and second parameter groups" to "displays the first parameter group while not displaying the second parameter group."

[0283] Incidentally, for example, if the diagnosis of a command related to a switching instruction results in the command being deemed normal and it is confirmed that the robot is in the correct position, then it would be good to set the "predetermined switching condition" to "fulfilled".

[0284] Feature B2. The robot (robot 16) is driven and controlled according to each operation instruction (command for drive control) that constitutes the control program for the robot (robot 16), and the robot is driven and controlled by a drive control unit (drive control unit 52), which has an operation determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) that includes correlation information correlated with at least one of the force and speed of the robot during drive control, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple scenes (e.g., main scenes) which are groups of safety-related parameters that include the determination criteria as safety-related parameters that affect the safety function are set, and the operation determination unit is configured to make the determination by referring to one of these scenes, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the scene included in the control program is made This setting support device (PC60) is applied to a robot control system (control system CS) configured to switch the reference scene based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful) when the "SCENE" command is reached, and assists the user in setting each of the safety-related parameters for each of the scenes, The display unit (PC60's display 61) and The display unit includes a display control unit (control unit 62 of PC60) that displays a parameter setting screen (parameter display unit D2 of the scene parameter setting screen WD) corresponding to the scene specified by the user, and Equipped with, A setting support device provided with a parameter setting screen that includes a first display mode (display of all items) which displays both the first parameter group and the second parameter group constituting the safety-related parameter group, and a second display mode (display of main items) which displays only the first parameter group out of the first and second parameter groups.

[0285] As shown in this feature, by incorporating scene (safety-related parameter group) switching instructions into the robot's control program, and enabling scene switching during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to the situation. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the scene is switched automatically, the scene may be switched due to accidental factors such as noise, resulting in a mismatch between the actual situation and the scene. This is a concern as it may hinder the proper performance of safety functions. Here, even if the robot is engaged in various tasks, its movements will basically follow the control program described above, so there will be a certain relationship between the task and the area (operating area) in which the task is performed. Taking this reality into consideration, this feature is configured to switch scenes on the condition that predetermined switching conditions, including position conditions, are met. In this way, by performing at least position confirmation when switching scenes, the above concerns can be eliminated, and it is possible to switch scenes appropriately.

[0286] Here, if the number of safety-related parameters that users can set for each scene increases, safety functions can be finely modified according to the work content, etc. This is desirable in achieving both improved safety and increased productivity. However, if the number of configurable items increases, it becomes more difficult for users to identify the necessary items. This can lead to incorrect settings. In this regard, the configuration shown in this feature provides two display modes for the safety-related parameter group on the parameter setting screen: a first display mode (all items display) that displays both the first and second parameter groups that constitute the safety-related parameter group, and a second display mode (main items display) that displays only the first parameter group from the two parameter groups. In the second display mode, the display target is limited to the first parameter group, making it easier for users to narrow down the necessary items. On the other hand, in the first display mode, both the first and second parameter groups are displayed (configurable), making it possible to set and check individual safety-related parameters. Thus, providing two display modes is desirable in achieving both improved safety and increased productivity while suppressing user setting errors.

[0287] Feature B3. The setting support device according to Feature B2, which switches the display mode of the safety-related parameter group on the parameter setting screen between the first display mode and the second display mode based on a user's switching operation.

[0288] As shown in this feature, a configuration that allows users to arbitrarily switch display modes is preferable in order to improve user convenience.

[0289] Feature B4. The setting support device according to Feature B3, wherein the second parameter group includes multiple safety-related parameters for detailed settings related to specific safety-related parameters included in the first parameter group.

[0290] If you wish to make detailed settings for specific safety-related parameters displayed in the second display mode, you can do so by switching from the second display mode to the first display mode. Whether or not such detailed settings are necessary depends on various circumstances. In the second display mode, it is preferable to exclude these detailed setting parameters from the display to narrow the display items, as this prevents important parameters from being overlooked.

[0291] Feature B5. A setting support device according to any one of Feature B2 to Feature B4, wherein the first parameter group and the second parameter group are classified such that the number of safety-related parameter items constituting the first parameter group is less than the number of safety-related parameter items constituting the second parameter group.

[0292] By narrowing down the items to be extracted for the second display mode, such that the items of safety-related parameters constituting the first parameter group are less than the items of safety-related parameters constituting the second parameter group, the two display modes can be suitably made to coexist according to their purpose.

[0293] Feature B6. In the second display mode, the setting support device according to any one of Feature B2 to Feature B5 displays the first set of parameters in a state where they are classified into multiple groups.

[0294] As shown in this feature, in the second display mode, the first set of parameters is displayed in a grouped manner, making it easier for the user to find the desired item if it is included in the items displayed in the second display mode. Furthermore, prompting the user to set parameters in groups according to their classification is desirable in preventing errors in parameter settings by the user.

[0295] Feature B7. A setting support device according to any one of Feature B2 to Feature B6, wherein the display mode when the parameter setting screen is launched based on a user's start operation is set to the second display mode, and the display mode is switched to the first display mode based on a user's switching operation.

[0296] When a user opens the parameter settings screen, the safety-related parameters are initially displayed in the second display mode. This allows the user to configure a limited set of items. Afterwards, the display mode can be switched back to the first display mode, providing an opportunity to configure other items that are not displayed when the parameter settings screen is launched.

[0297] Feature B8. A setting support device according to any one of Feature B2 to Feature B7, which, when the user performs the operation to specify a scene while the parameter setting screen is displayed, displays the safety-related parameter group of the specified scene in the second display mode.

[0298] When a scene is specified by the user, the safety-related parameters corresponding to that scene are displayed in a second display mode. Even when setting safety-related parameters for multiple scenes, displaying only the safety-related parameters for the specified scene in the second display mode effectively prevents information overload and user confusion.

[0299] Feature B9. The aforementioned scene includes a first scene and a second scene, which assume that the robot's drive control is performed according to the control program. A setting support device described in any one of features B2 to B8, wherein the items of the first parameter group in the first scene and the items of the first parameter group in the second scene match.

[0300] In the first and second scenes for autonomous driving, the items displayed in the second display mode are the same for both scenes. With this configuration, if you set the first set of parameters in the second display mode for one of the first or second scenes, and then set the first set of parameters in the second display mode for the other scene, you can perform the setting work while maintaining the same image as the previous setting. This is desirable in reducing setting errors. In particular, when combined with feature B7, if you set the first set of parameters for the first scene and then specify the second scene, the first set of parameters will be displayed, allowing you to set the first set of parameters efficiently.

[0301] Feature B10. The aforementioned scene is the main scene, The setting support device according to any one of features 2 to B9, wherein the main scene can be configured with multiple subscenes that differ only in a predetermined set of safety-related parameters, which are part of the safety-related parameter group that constitutes the main scene.

[0302] In some main scenes, only certain safety-related parameters may differ. If it were possible to adjust only those specific safety-related parameters using sub-scenes, it would be possible to prevent an overabundance of main scenes and reduce user confusion between them.

[0303] Feature B11. In the first display mode, the specific safety-related parameters are displayed for all subscenes corresponding to the main scene specified by the user. The setting support device according to feature B10, which in the second display mode displays the specific safety-related parameters for one subscene specified by the user from among all subscenes corresponding to the main scene specified by the user.

[0304] In the second display mode, safety-related parameters are displayed for one subscene specified by the user, allowing for focused settings and verification of that specific subscene. Narrowing the display target in this way is preferable in preventing missetting of safety-related parameters. In contrast, in the first display mode, safety-related parameters are displayed for all subscenes, allowing for comparison of these subscenes without switching between subscenes for the specified main scene. By differentiating the handling of subscenes in these two display modes, a practically preferable configuration can be achieved.

[0305] Feature B12. The setting support device according to Feature B10 or Feature B11, which in the second display mode displays safety-related parameters common to all subscenes corresponding to the main scene specified by the user, distinguishing them from the predetermined safety-related parameters.

[0306] As shown in this feature, by distinguishing between items that are set for each subscene and items that are common to all subscenes, the items that are set for each subscene can be clearly indicated to the user. Furthermore, distinguishing between items that are common to all subscenes is preferable in preventing the settings of these common items from being accidentally changed when setting up subscenes.

[0307] Feature B13. The robot (robot 16) is driven and controlled according to each operation instruction (drive control command) that constitutes the control program for the robot (robot 16), and the robot is driven and controlled by a drive control unit (drive control unit 52), and the robot is driven and controlled by an operation determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) which includes correlation information that correlates with at least one of the force and speed of the robot during drive control, and a safety-related unit (safety-related unit PX) which realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple scenes (e.g., main scenes) which are groups of safety-related parameters that include the determination criteria as safety-related parameters that affect the safety function are set, and the operation determination unit is configured to make the determination by referring to one of these scenes, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the scene included in the control program is made A setting support program installed on a computer that can be connected to a robot control device (control device 51) configured to switch the referenced scene based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful) including position conditions that define the position of the robot when the "SCENE" command is reached, and which causes the computer to assist the user in setting each of the safety-related parameters for each of the scenes, The display unit (PC60's display 61) displays the parameter setting screen (parameter display unit D2 of the scene parameter setting screen WD) corresponding to the scene specified by the user. The following display modes are defined for the safety-related parameter group in the parameter setting screen: a first display mode (all items display) that displays both the first parameter group and the second parameter group constituting the safety-related parameter group, and a second display mode (main items display) that displays only the first parameter group out of the first and second parameter groups. A setting support program that switches the display mode between the first display mode and the second display mode based on a user's switching operation.

[0308] The configuration described in this feature allows for both improved safety and increased productivity while effectively suppressing user configuration errors.

[0309] Feature B14. The robot (robot 16) is driven and controlled according to each operation instruction (command for drive control) that constitutes the control program for the robot (robot 16), and the robot the operation determination unit (logic unit X2) which has a safety-related unit (safety-related unit PX) which has an operation determination unit (logic unit X2) which determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) which contains correlation information that correlates with at least one of the force and speed of the robot during drive control and a determination criterion (reference value or reference area) for the correlation information that is stored in advance, and realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple scenes (e.g., main scene) which are a group of safety-related parameters that include the determination criterion as a safety-related parameter that affects the safety function are set, and the operation determination unit is configured to make the determination by referring to one of the scenes, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the scene included in the control program is made This method applies to a robot control system (control system CS) configured to switch the referenced scene when the "SCENE" command is reached, based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful) including position conditions that define the position of the robot, and displays a group of safety-related parameters when the user sets or confirms each of the safety-related parameters that constitute each of the scenes, The display unit (PC60's display 61) displays a parameter setting screen (parameter display unit D2 of the scene parameter setting screen WD) corresponding to the scene specified by the user. A method for displaying safety-related parameters on the parameter setting screen, which switches the display of the safety-related parameter group on the parameter setting screen between a first display (display of all items) that displays both the first parameter group and the second parameter group that constitute the safety-related parameter group, and a second display (display of main items) that displays only the first parameter group from the first and second parameter groups, based on a user's switching operation.

[0310] The configuration described in this feature allows for both improved safety and increased productivity while effectively suppressing user configuration errors.

[0311] Furthermore, the technical concepts described in Features B3 to B12 may also be applied to Features B13 and B14.

[0312] <Feature Group C> Scene changes during simulation The following characteristic group C is based on the background technology, which states that "robot control systems applied to robots such as industrial robots have a safety-related section that implements safety functions for the robot and a non-safety-related section that performs drive control of the robot, etc. Regarding the safety-related section, for example, it has been proposed to forcibly stop the robot when it collides with an obstacle such as a person (see, for example, Patent Document 1), or to forcibly stop the robot if it moves outside of safety standards by monitoring the force (thrust) and speed of the robot while it is in motion." In recent years, due to advances in robot technology, the types of tasks that a single robot can perform are also increasing. When a single robot is used for various tasks, if the safety functions are uniform, it may be difficult to achieve both improved robot safety and improved productivity (work efficiency) by the robot. In view of these circumstances, the inventor of this invention has devised a configuration that switches the safety functions of the robot according to the work content, etc. Here, in order to suppress the impairment of safety functions due to communication errors, etc. during the change, the input for changing the safety function is input from the safety-related input section (so-called safety It is preferable to have all inputs. However, if safety input is made a mandatory requirement, the constraints on changes will become stronger, which is expected to hinder the improvement of the operability of changing safety functions. On the other hand, if this requirement is simply avoided, improved operability can be expected, but there are concerns that confidence in the robot's safety functions will be shaken. Thus, there is still room for improvement in the configuration related to changing safety functions in order to improve the safety and work efficiency of robots. In recent years, simulation technology that uses a robot model displayed in a virtual space to verify operation has become widespread, and by efficiently verifying whether the created control program is functioning correctly, it has been realized that the creation period of control programs has been shortened. However, when simulating a control program that includes safety function switching instructions, a new concern arises that these switching instructions may hinder the effective use of the simulation. This is because the flow of creating control programs etc. varies from creator to creator, and simulations are not always performed with switching instructions properly made.In other words, for control programs that include instructions for switching safety functions during operational verification, the use of simulation is heavily restricted, which can reduce the efficiency of work when creating control programs. Thus, there is still room for improvement in the configuration of the support system for creating control programs that take into account both robot safety and productivity. This was done in light of these background and challenges.

[0313] Feature C1. The robot (robot 16) is driven and controlled according to each operation instruction (drive control command) that constitutes the control program for the robot (robot 16), and the robot is driven and controlled by a drive control unit (drive control unit 52), which has an operation determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) that includes correlation information correlated with at least one of the force and speed of the robot during drive control, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple candidates for the determination criteria referenced by the operation determination unit can be set, and the operation determination unit is configured to make the determination by referring to one of the determination criteria, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the determination criteria included in the control program is made This simulation device is applied to a robot control system (control system CS) configured to switch the referenced judgment criteria and continue drive control of the robot based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command normal) when the "SCENE" command is reached, while interrupting drive control of the robot based on the failure to fulfill the predetermined switching conditions, and is capable of executing a simulation by operating a model of the robot (e.g., model RM) in a virtual area according to each of the operation instructions that constitute the control program, A simulation device configured such that, when the switching instruction in the control program is reached during the simulation, the simulation can be continued not only when the predetermined switching conditions are met, but also when the predetermined switching conditions are not met.

[0314] As shown in this feature, by incorporating a judgment criterion switching instruction into the robot's control program, and configuring the system to switch the judgment criterion during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to the situation. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the judgment criterion is switched automatically, the judgment criterion may be switched due to accidental factors such as noise, resulting in a mismatch between the expected situation and the judgment criterion. This is a concern as it may hinder the proper performance of safety functions. In this feature, when a switching instruction is reached in the control program, the judgment criterion is switched on the condition that predetermined switching conditions are met. This suppresses the switching of scenes that deviate from the user's intention and reduces the occurrence of the aforementioned mismatch.

[0315] In recent years, simulation technology, which uses robot models displayed in a virtual space to verify operation, has become widespread. This allows for efficient verification of whether the created control program is functioning correctly, thereby shortening the control program creation period. However, when simulating a control program that includes instructions for switching judgment criteria, the verification becomes difficult if the predetermined switching conditions are not met, preventing the simulation from continuing. In other words, a new concern arises: simulation may not be effectively utilized for control programs that incorporate safety function switching. This is because the process of creating control programs varies from creator to creator, and the progress of creating the operation program does not necessarily correlate with the progress of setting judgment criteria and switching conditions (especially position conditions). In short, the requirement that predetermined switching conditions be met during operation verification strengthens the constraints on the use of simulation and can reduce the efficiency of control program creation. This concern is particularly strong when considering that, when switching judgment criteria in various ways, it is less likely to have to re-set judgment criteria and switching conditions after the operation program has been largely finalized. In this regard, the configuration described in this feature allows the simulation to continue not only when the predetermined switching conditions are met, but also when the predetermined switching conditions are not met. Since the robot does not actually operate during the simulation, continuing the simulation does not have any substantial impact on safety. Therefore, the above configuration can suitably support the creation of control programs that take into account both the safety and productivity of the robot.

[0316] Furthermore, the phrase "when the switching instruction in the control program is reached during the simulation, even if the predetermined switching conditions are not met" includes not only cases where the predetermined switching conditions are actually determined and the result is negative, but also cases where the predetermined switching conditions are not determined, but if the determination were made, it would be negative. This also applies to features C2 and C3 below.

[0317] Feature C2. The robot (robot 16) is driven and controlled according to each operation instruction (command for drive control) that constitutes the control program for the robot (robot 16), and the robot is driven and controlled by a drive control unit (drive control unit 52), which has an operation determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) that includes correlation information correlated with at least one of the force and speed of the robot during drive control, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple candidates for the determination criteria referenced by the operation determination unit can be set, and the operation determination unit is configured to make the determination by referring to one of the determination criteria, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the determination criteria included in the control program is made This applies to a robot control system (control system CS) configured to switch the referenced judgment criteria and continue drive control of the robot based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command normal) including position conditions that define the position of the robot when the "SCENE" command is reached, while interrupting drive control of the robot based on the failure to fulfill the predetermined switching conditions, and is a simulation device capable of executing a simulation by operating a model of the robot (e.g., model RM) in a virtual area according to each of the operation instructions that constitute the control program, A simulation device configured such that, when the switching instruction in the control program is reached during the simulation, the simulation can be continued not only when the predetermined switching conditions are met, but also when the predetermined switching conditions are not met.

[0318] As shown in this feature, by incorporating a judgment criterion switching instruction into the robot's control program, and configuring the system to switch the judgment criterion during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to the situation. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the judgment criterion is switched automatically, the judgment criterion may be switched due to accidental factors such as noise, which could lead to a mismatch between the actual situation and the judgment criterion. This is a concern as it could hinder the proper performance of safety functions. Here, even if the robot is engaged in various tasks, its movements will basically follow the control program described above, so there is a certain relationship between the task and the area (operating area) in which the task is performed. Taking this into consideration, this feature uses a configuration that switches the judgment criterion on the condition that predetermined switching conditions, including position conditions, are met. In this way, by performing at least a position check when switching judgment criteria, the above concerns can be eliminated, and the judgment criterion can be switched appropriately.

[0319] In recent years, simulation technology, which uses robot models displayed in a virtual space to verify their operation, has become widespread. This allows for efficient verification of whether the created control program is functioning correctly, thereby shortening the control program creation period. However, when simulating a control program that includes instructions for switching judgment criteria, the verification becomes difficult if the predetermined switching conditions are not met, preventing the simulation from continuing. In other words, a new concern arises: simulation may not be effectively utilized for control programs that incorporate safety function switching. This is because the process of creating control programs varies from creator to creator, and the progress of creating the operation program does not necessarily correlate with the progress of setting judgment criteria and switching conditions (especially position conditions). In short, the requirement that predetermined switching conditions be met during operation verification strengthens the constraints on the use of simulation and can reduce the efficiency of control program creation. This concern is particularly strong when considering that, when switching judgment criteria in various ways, it is less likely to have to readjust the judgment criteria and switching conditions after the operation program, including the robot's movement trajectory, has been largely finalized. In this regard, the configuration described in this feature allows the simulation to continue not only when the predetermined switching conditions are met, but also when the predetermined switching conditions are not met. Since the robot does not actually operate during the simulation, continuing the simulation does not have any substantial impact on safety. Therefore, the above configuration can suitably support the creation of control programs that take into account both the safety and productivity of the robot.

[0320] Feature C3. The robot (robot 16) is driven and controlled according to each operation instruction (command for drive control) that constitutes the control program for the robot (robot 16), and the robot is driven and controlled by a drive control unit (drive control unit 52), which has an operation determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) that includes correlation information correlated with at least one of the force and speed of the robot during drive control, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple scenes (e.g., main scenes) which are groups of safety-related parameters that include the determination criteria as safety-related parameters that affect the safety function can be set, and the operation determination unit is configured to make the determination by referring to one of these scenes, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the scene included in the control program is made This simulation device is applied to a robot control system (control system CS) configured to switch the referenced scene and continue drive control of the robot when the command "SCENE" is reached, based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful) including position conditions that define the position of the robot, and interrupt the drive control of the robot when the predetermined switching conditions are not fulfilled, and is capable of executing a simulation by operating a model of the robot (e.g., model RM) in a virtual area according to each of the operation instructions that constitute the control program, A simulation device configured such that, when the switching instruction in the control program is reached during the simulation, the simulation can be continued not only when the predetermined switching conditions are met, but also when the predetermined switching conditions are not met.

[0321] As shown in this feature, by incorporating scene (safety-related parameter group) switching instructions into the robot's control program, and enabling scene switching during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to the situation. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the scene is switched automatically, the scene may be switched due to accidental factors such as noise, resulting in a mismatch between the actual situation and the scene. This is a concern as it may hinder the proper performance of safety functions. Here, even if the robot is engaged in various tasks, its movements will basically follow the control program described above, so there will be a certain relationship between the task and the area (operating area) in which the task is performed. Taking this reality into consideration, this feature is configured to switch scenes on the condition that predetermined switching conditions, including position conditions, are met. In this way, by performing at least position confirmation when switching scenes, the above concerns can be eliminated, and it is possible to switch scenes appropriately.

[0322] In recent years, simulation technology, which uses robot models displayed in a virtual space to verify their operation, has become widespread. This allows for efficient verification of whether the created control program is functioning correctly, thereby shortening the control program creation period. However, when simulating a control program that includes scene switching instructions, the verification becomes difficult if the predetermined switching conditions are not met, preventing the simulation from continuing. In other words, a new concern arises: simulation may not be effectively utilized for control programs that incorporate safety function switching. This is because the process of creating control programs varies from creator to creator, and the progress of creating the operation program does not necessarily correlate with the progress of setting scenes and switching conditions (especially position conditions). In short, the requirement that predetermined switching conditions be met for operation verification strengthens the constraints on the use of simulation and can reduce the efficiency of control program creation. This concern becomes particularly strong when there are many setting items related to scenes when switching between various scenes, considering that it is less likely to have to redo scene settings once the operation program, including the robot's movement trajectory, is somewhat finalized. In this regard, the configuration described in this feature allows the simulation to continue not only when the predetermined switching conditions are met, but also when the predetermined switching conditions are not met. Since the robot does not actually operate during the simulation, continuing the simulation does not affect safety. Therefore, this configuration can suitably support the creation of control programs that take into account both the safety and productivity of the robot.

[0323] Feature C4. The simulation device according to Feature C3, wherein in the simulation, the simulation can be continued by switching the scene in accordance with the switching instruction, not only when the predetermined switching conditions are met, but also when the predetermined switching conditions are not met.

[0324] In simulations, since the model operates in a virtual space, forcing a scene switch when predetermined switching conditions are not met does not actually affect safety. Furthermore, by forcing a scene switch, users can also verify the relationship between the robot's movements and the scene in the simulation, thus better supporting the creation of control programs that consider both robot safety and productivity.

[0325] Feature C5. The simulation apparatus according to Feature C3 or Feature C4, wherein, in the simulation, if the determination result of the predetermined switching condition is a determination result that the predetermined switching condition is not met, the determination result is invalidated and the simulation continues.

[0326] As shown in this feature, by configuring the system to make decisions regarding predetermined switching conditions during simulation, it is possible to synchronize the actual drive control with the simulated drive control. In such a configuration, by invalidating the decision result and continuing the simulation, even if the predetermined switching conditions are not met, it is possible to prevent this from interfering with the simulation.

[0327] Feature C6. The simulation apparatus according to Feature C3 or Feature C4, wherein the simulation is continued by skipping the determination of the predetermined switching conditions in the control program.

[0328] As shown in this feature, by configuring the system to skip the determination of predetermined switching conditions during simulation, the technical ideas shown in feature C3, etc., can be easily implemented, and operational verification through simulation can be carried out smoothly.

[0329] Feature C7. A simulation apparatus according to any one of Feature C3 to Feature C6, wherein when the simulation progresses and reaches the switching instruction in the control program, the simulation is temporarily stopped, the user is notified that the switching instruction has been reached, and the simulation is restarted based on the user's operation to restart the simulation.

[0330] According to the simulation device described in this feature, the user is notified when a scene change instruction has been reached. This reduces the chances of the user missing a scene change. Furthermore, configuring the simulation to pause and wait for the user to restart it is preferable to a configuration where the simulation does not pause, as it ensures that the user has an opportunity to pay attention to the display of safety-related parameters, etc.

[0331] Feature C8. The simulation apparatus according to Feature C7, wherein, when switching scenes based on the switching instruction during the simulation, the newly applied scene is notified in advance of the restart operation.

[0332] By providing advance notification of the scene after the switch before the restart operation, users can be given ample time to confirm the changed scene. For example, the advance notification can be initiated based on the arrival of the switch instruction and continued until the restart operation is performed.

[0333] Feature C9. A simulation apparatus according to any one of Feature C3 to Feature C8, comprising a parameter display unit that displays the group of safety-related parameters constituting the scene in the simulation, wherein the parameter display unit performs a specific display that differentiates the display of the safety-related parameters that are changed from the display of the safety-related parameters that are not changed when the scene is switched based on the switching instruction.

[0334] The configuration described in this feature helps to verify whether the scene is switching as expected by the user. When verifying the movement of the model and the scene switching, the number of items to check increases, which can lead to oversights and subsequent re-simulation, thus reducing the efficiency of verification. In this regard, as described above, by using a specific display that differs between the display of safety-related parameters that are subject to change and those that are not, the opportunities for such re-simulation can be reduced.

[0335] Feature C10. The safety-related part of the robot system is configured to issue an error notification when the switching instruction in the control program is reached during the drive control of the robot and the predetermined switching condition is not met. A simulation apparatus according to any one of features C3 to C9, wherein if the switching instruction in the control program is reached during the simulation and the predetermined switching condition is not met, an error notification is given in the same manner as the error notification.

[0336] If a predetermined switching condition is not met during the simulation, an error notification will be issued in the same manner as if the predetermined switching condition were not met in an actual robot. This configuration allows for a more realistic simulation, including the possibility of scene switching failures.

[0337] Feature C11. The robot control system is configured to determine that the predetermined switching condition is met when the position condition and the stop condition indicating that the robot is stopped are met, and to determine that the predetermined switching condition is not met when at least one of the position condition and the stop condition is not met. The simulation apparatus according to any one of features C3 to C10, wherein in the simulation, it is determined that the predetermined switching condition is met when the position condition and the stop condition are met, and it is determined that the predetermined switching condition is not met when at least one of the position condition and the stop condition is not met.

[0338] As shown in this feature, in a configuration where the predetermined switching conditions include position conditions and stop conditions, the hurdle for fulfilling those predetermined switching conditions during simulation becomes higher. In other words, while this can contribute to improved reliability in actual robots, it can hinder the promotion of simulation use. Applying the technical ideas shown in feature C3, etc., to such a configuration can improve reliability while also contributing to the promotion of simulation use.

[0339] Furthermore, it is also possible to apply each of the technical concepts shown in features C4 to C11 to feature C1 or feature C2.

[0340] Feature C12. The robot (robot 16) is driven and controlled according to each operation instruction (drive control command) that constitutes the control program for the robot (robot 16), and the robot is driven and controlled by a drive control unit (drive control unit 52), which has an operation determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) that includes correlation information correlated with at least one of the force and speed of the robot during drive control, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple candidates for the determination criteria referenced by the operation determination unit can be set, and the operation determination unit is configured to make the determination by referring to any of the determination criteria, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the determination criteria included in the control program is made. A simulation program installed on a computer connectable to a robot control system (control system CS) configured to switch the referenced judgment criteria and continue drive control of the robot when a predetermined switching condition (e.g., stop condition, position condition, command normal) is met when the "SCENE" command is reached, and to interrupt drive control of the robot when the predetermined switching condition is not met, causing the computer to execute a simulation by operating a model of the robot in a virtual area according to the operation instructions of the control program, A simulation program that, when the switching instruction in the control program is reached during the simulation, allows the simulation to continue not only when the predetermined switching conditions are met, but also when the predetermined switching conditions are not met.

[0341] The configuration described in this feature can suitably support the creation of control programs that take into account both the safety and productivity of the robot.

[0342] Feature C13. The robot (robot 16) is driven and controlled according to each operation instruction (command for drive control) that constitutes the control program for the robot (robot 16), and the robot the operation determination unit (logic unit X2) which has a safety-related unit (safety-related unit PX) which has an operation determination unit (logic unit X2) which determines the movement of the robot based on a safety-related input signal (signal from rotary encoder 36, torque sensor 37, etc.) that includes correlation information correlated with at least one of the force and speed of the robot during drive control and a determination criterion (reference value or reference area) for the correlation information that is stored in advance, and realizes the safety function of the robot by generating a safety-related output signal according to the determination result, and multiple scenes (e.g., main scene) which are a group of safety-related parameters that include the determination criterion as a safety-related parameter that affects the safety function can be set, and the operation determination unit is configured to make the determination by referring to one of these scenes, and during drive control of the robot based on the control program, a switching instruction ("CHANGE") for the scene included in the control program is made A simulation program installed on a computer connectable to a robot control system (control system CS) configured to switch the referenced scene and continue drive control of the robot based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful) including position conditions that define the position of the robot when the "SCENE" command is reached, while interrupting drive control of the robot if the predetermined switching conditions are not fulfilled, and causing the computer to execute a simulation by operating a model of the robot in a virtual area according to the operation instructions of the control program, A simulation program that, when the switching instruction in the control program is reached during the simulation, allows the simulation to continue not only when the predetermined switching conditions are met, but also when the predetermined switching conditions are not met.

[0343] The configuration described in this feature can suitably support the creation of control programs that take into account both the safety and productivity of the robot.

[0344] Furthermore, it is also possible to apply each of the technical concepts shown in features C4 to C11 to feature C12 or C13.

[0345] <Feature Group D> Scenes for manual operation The following characteristic group D is based on the background technology, which states that "robot control systems applied to robots such as industrial robots have a safety-related section that implements safety functions for the robot and a non-safety-related section that performs drive control of the robot, etc. Regarding the safety-related section, for example, it has been proposed that the robot will be forcibly stopped if it collides with an obstacle such as a person (see, for example, Patent Document 1), or that the force (thrust) and speed of the robot while it is in motion will be monitored and the robot will be forcibly stopped if it moves in a way that deviates from safety standards." In recent years, due to advances in robot technology, the types of tasks that a single robot can perform are also increasing. When a single robot is used for various tasks, if the safety functions are uniform, it may be difficult to achieve both improved robot safety and improved productivity (work efficiency) by the robot. In view of these circumstances, the inventor of this invention has devised a configuration that switches the safety functions of the robot according to the work content, etc. Here, in order to suppress the impairment of safety functions due to communication errors, etc. during the change, the input for changing the safety function is set to the safety-related input section or It is preferable to use these inputs (so-called safety inputs). However, if safety inputs are made a mandatory requirement, the constraints on changes will become stronger, which is expected to hinder the improvement of the operability of changing safety functions. On the other hand, if this requirement is simply avoided, improved operability can be expected, but there are concerns that confidence in the robot's safety functions will be shaken. Thus, there is still room for improvement in the configuration related to changing safety functions in order to improve the safety and work efficiency of the robot. In recent years, methods such as teaching the robot by having the user manually operate the robot have been used to shorten the time required to create control programs. Also, if abnormal operation occurs during automatic operation, the safety function may activate and stop the robot, and the user may manually operate the robot during recovery. Providing an automatic operation mode for automatic operation and a manual operation mode for manual operation as control modes for the robot, and taking the above-mentioned manual operation into consideration, is preferable in order to improve safety and workability when performing such manual operation.However, the expected situations in automatic driving mode and manual operation mode differ significantly, and the appropriate safety functions may differ. In other words, if safety functions designed for automatic driving mode are applied to manual operation mode, it may become difficult to achieve improved safety and productivity during automatic driving, as well as improved safety and work efficiency during manual operation. Thus, there is still room for improvement in the configuration of safety functions in order to improve robot safety, contribute to increased productivity by the robot during automatic driving, and contribute to improved work efficiency for the user during manual operation. This was done in consideration of the background and challenges described above.

[0346] Feature D1. A robot control system (control system CS) is provided, which includes a motion determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from a rotary encoder 36, torque sensor 37, etc.) that includes a parameter correlated with at least one of the force and speed of the robot (robot 16) in motion, and a determination criterion (reference value or reference range) for the parameter that is stored in advance, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, The robot's control modes include an automatic operation mode, which is applied when the robot is operated according to each operation instruction (drive control command) that constitutes the control program for the robot, and a manual operation mode, which is applied when the robot is manually operated by a user. Multiple scenes (e.g., main scenes) can be set, which are groups of safety-related parameters that include the aforementioned judgment criteria as safety-related parameters that affect the safety function. The operation judgment unit is configured to make the judgment by referring to one of these scenes. The aforementioned scenes include multiple autonomous driving scenes (for example, Main Scene 1 to Main Scene 9) that are referenced when the autonomous driving mode is enabled. During the aforementioned automatic driving mode, when a switching instruction ("CHANGE SCENE" command) for the automatic driving scene included in the control program is reached during the drive control of the robot based on the control program, the configuration is such that the referenced scene is switched to the automatic driving scene specified by the switching instruction from among a plurality of automatic driving scenes, based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful). A robot control system in which the aforementioned scene includes manual operation scenes (for example, manual operation scene R and manual operation scenes 1 to 3) that are referenced when the manual operation mode is enabled.

[0347] As shown in this feature, by incorporating scene (safety-related parameter group) switching instructions into the robot's control program, and enabling scene switching during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to various conditions such as the surrounding environment and work content. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the scene is switched automatically, inappropriate scene switching may occur due to disturbances in the robot's behavior or noise, which may result in a mismatch between the pre-planned scene and the actual scene. This is a concern as it may hinder the proper performance of safety functions. In this regard, this feature is configured so that when a switching instruction is reached in the control program, the scene is switched only if predetermined switching conditions are met. In other words, the configuration allows for confirmation of requirements such as whether or not a scene can be switched. This is desirable for suppressing scene switching that deviates from the user's intention and for suppressing the occurrence of the aforementioned mismatch.

[0348] In recent years, methods such as teaching robots by having users manually operate them have been used to shorten the time required to create control programs. Furthermore, if abnormal operation occurs during automatic operation, safety functions may activate and stop the robot, and the user may need to manually operate the robot to recover from such a situation. As described above, it is preferable to provide both an automatic operation mode for automatic operation and a manual operation mode for manual operation as control modes for the robot, and to take manual operation into consideration as described above, in order to improve safety and work efficiency when performing such manual operation.

[0349] However, the expected situations in autonomous driving mode and manual operation mode differ significantly, and various safety-related parameters may differ in order to properly utilize safety functions. In other words, if the same scene is referenced in both autonomous driving mode and manual operation mode, it may become difficult to improve safety and productivity during autonomous driving, as well as improve safety and work efficiency during manual operation. In this regard, the configuration shown in this feature provides separate scenes to be referenced when the robot is driven autonomously and when the robot is operated manually. This allows safety functions to be properly utilized in both autonomous and manual operation modes.

[0350] For the reasons stated above, this technology can improve robot safety while also contributing to increased productivity during autonomous operation and improved user efficiency during manual operation.

[0351] Feature D2. A robot control system (control system CS) is provided, which includes a motion determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from a rotary encoder 36, torque sensor 37, etc.) that includes a parameter correlated with at least one of the force and speed of the robot (robot 16) in motion, and a predetermined determination criterion (reference value or reference range) for the parameter, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, The robot's control modes include an automatic operation mode, which is applied when the robot is operated according to each operation instruction (drive control command) that constitutes the control program for the robot, and a manual operation mode, which is applied when the robot is manually operated by a user. Multiple scenes (e.g., main scenes) can be set, which are groups of safety-related parameters that include the aforementioned judgment criteria as safety-related parameters that affect the safety function. The operation judgment unit is configured to make the judgment by referring to one of these scenes. The aforementioned scenes include multiple autonomous driving scenes (for example, Main Scene 1 to Main Scene 9) that are referenced when the autonomous driving mode is enabled. During the aforementioned automatic driving mode, when a switching instruction ("CHANGE SCENE" command) for the automatic driving scene included in the control program is reached during the drive control of the robot based on the control program, the configuration is such that the scene to be referenced is switched to the automatic driving scene specified by the switching instruction from among a plurality of automatic driving scenes, based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful) including position conditions that define the position of the robot. A robot control system in which the aforementioned scene includes manual operation scenes (for example, manual operation scene R and manual operation scenes 1 to 3) that are referenced when the manual operation mode is enabled.

[0352] As shown in this feature, by incorporating scene (safety-related parameter group) switching instructions into the robot's control program, and enabling scene switching during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to various conditions such as the surrounding environment and work content. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the scene is switched automatically, inappropriate scene switching may occur due to disturbances in the robot's behavior or noise, potentially resulting in a mismatch between the pre-planned scene and the actual scene. This is a concern as it may hinder the proper performance of safety functions. Here, even if the robot is engaged in various tasks, its movements will basically follow the control program described above, so there will be a certain relationship between the task and the area (operating area) in which the task is performed. Taking this into consideration, this feature is configured to switch scenes only when predetermined switching conditions, including position conditions, are met. In this way, by performing at least a position check when switching scenes, the above concerns can be eliminated, and it is possible to switch scenes appropriately.

[0353] In recent years, methods such as teaching robots by having users manually operate them have been used to shorten the time required to create control programs. Furthermore, if abnormal operation occurs during automatic operation, safety functions may activate and stop the robot, and the user may need to manually operate the robot to recover from such a situation. As described above, it is preferable to provide both an automatic operation mode for automatic operation and a manual operation mode for manual operation as control modes for the robot, and to take manual operation into consideration as described above, in order to improve safety and work efficiency when performing such manual operation.

[0354] However, the expected situations in autonomous driving mode and manual operation mode differ significantly, and various safety-related parameters may differ in order to properly utilize safety functions. In other words, if the same scene is referenced in both autonomous driving mode and manual operation mode, it may become difficult to improve safety and productivity during autonomous driving, as well as improve safety and work efficiency during manual operation. In this regard, the configuration shown in this feature provides separate scenes to be referenced when the robot is driven autonomously and when the robot is operated manually. This allows safety functions to be properly utilized in both autonomous and manual operation modes.

[0355] For the reasons stated above, this technology can improve robot safety while also contributing to increased productivity during autonomous operation and improved user efficiency during manual operation.

[0356] Feature D3. A robot control system (control system CS) is provided, which includes a motion determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from a rotary encoder 36, torque sensor 37, etc.) that includes a parameter correlated with at least one of the force and speed of the robot (robot 16) in motion, and a predetermined determination criterion (reference value or reference range) for the parameter, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, The robot's control modes include an automatic operation mode, which is applied when the robot is operated according to each operation instruction (drive control command) that constitutes the control program for the robot, and a manual operation mode, which is applied when the robot is manually operated by a user. Multiple scenes (e.g., main scenes) can be set, which are groups of safety-related parameters that include the aforementioned judgment criteria as safety-related parameters that affect the safety function. The operation judgment unit is configured to make the judgment by referring to one of these scenes. Multiple scenes are provided, including automatic driving scenes (e.g., main scenes 1 to 9) that are referenced when the system is in automatic driving mode, and manual operation scenes (e.g., manual operation scene R and manual operation scenes 1 to 3) that are referenced when the system is in manual operation mode. At least multiple settings are possible for the aforementioned autonomous driving scenes. During the aforementioned automatic driving mode, when a switching instruction ("CHANGE SCENE" command) for the automatic driving scene included in the control program is reached during the drive control of the robot based on the control program, the configuration is such that the scene to be referenced is switched to the automatic driving scene specified by the switching instruction from among a plurality of automatic driving scenes, based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command successful) including position conditions that define the position of the robot. A robot control system that, when in the manual operation mode or when in the manual operation mode, switches the referenced scene to the manual operation scene based on a predetermined operation by the user.

[0357] As shown in this feature, by incorporating scene (safety-related parameter group) switching instructions into the robot's control program, and enabling scene switching during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to various conditions such as the surrounding environment and work content. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the scene is switched automatically, inappropriate scene switching may occur due to disturbances in the robot's behavior or noise, potentially resulting in a mismatch between the pre-planned scene and the actual scene. This is a concern as it may hinder the proper performance of safety functions. Here, even if the robot is engaged in various tasks, its movements will basically follow the control program described above, so there will be a certain relationship between the task and the area (operating area) in which the task is performed. Taking this into consideration, this feature is configured to switch scenes only when predetermined switching conditions, including position conditions, are met. In this way, by performing at least a position check when switching scenes, the above concerns can be eliminated, and it is possible to switch scenes appropriately.

[0358] In recent years, methods such as teaching robots by having users manually operate them have been used to shorten the time required to create control programs. Furthermore, if abnormal operation occurs during automatic operation, safety functions may activate and stop the robot, and the user may need to manually operate the robot to recover from such a situation. As described above, it is preferable to provide both an automatic operation mode for automatic operation and a manual operation mode for manual operation as control modes for the robot, and to take manual operation into consideration as described above, in order to improve safety and work efficiency when performing such manual operation.

[0359] However, the expected situations in autonomous driving mode and manual operation mode differ significantly, and various safety-related parameters may differ in order to properly utilize safety functions. In other words, if the same scene is referenced in both autonomous driving mode and manual operation mode, it may become difficult to improve safety and productivity during autonomous driving, as well as improve safety and work efficiency during manual operation. In this regard, the configuration shown in this feature provides separate scenes to be referenced when the robot is driven autonomously and when the robot is operated manually. This allows safety functions to be properly utilized in both autonomous and manual operation modes.

[0360] Furthermore, during autonomous driving, the scene automatically switches according to the control program's switching instructions, as described above, while the scene for manual operation switches according to the user's input. This configuration prevents the scene from suddenly switching at times unintended by the user. This is desirable for further improving safety.

[0361] For the reasons stated above, this technology can improve robot safety while also contributing to increased productivity during autonomous operation and improved user efficiency during manual operation.

[0362] Feature D4. Multiple manual operation scenes can be set. A robot control system according to feature D2 or feature D3, which switches the referenced scene to a manual operation scene specified by the user from among a plurality of manual operation scenes based on the fact that a predetermined operation, which is an operation to specify the manual operation scene, has been performed during the manual operation mode.

[0363] As illustrated in Feature D1, the manner of manual operation differs depending on the work content, such as teaching and recovery. Therefore, by providing multiple manual operation scenes and allowing the user to select one of these scenes while in manual operation mode, safety functions can be properly activated according to the work content.

[0364] Feature D5. A robot control system according to any one of Feature D2 to Feature D4, wherein when the control mode is the automatic operation mode, it is not possible to switch the referenced scene to the manual operation scene, and when the control mode is the manual operation mode, it is possible to switch the referenced scene to the manual operation scene.

[0365] The underlying conditions differ significantly between automatic driving mode and manual operation mode, potentially resulting in substantial differences in monitoring levels for force, speed, position, etc. Therefore, it is preferable to configure the system so that switching to manual operation scenes is not possible while in automatic driving mode, and only permitted when switching to manual operation mode, in order to achieve the safety and work efficiency improvements shown in Feature D1, etc.

[0366] Feature D6. Multiple manual operation scenes can be set. A robot control system according to feature D2 or feature D3, which switches the referenced scene to a predetermined manual operation scene from among a plurality of manual operation scenes based on the predetermined operation which is an operation for switching from the automatic driving mode to the manual operation mode.

[0367] As shown in this feature, by configuring the system so that switching from automatic driving mode to manual operation mode switches the referenced scene to a predetermined manual operation scene (for example, a default for manual operation), the opportunities for manual operation to be performed while the scene remains in the automatic driving mode can be reduced. The underlying conditions differ significantly between automatic driving mode and manual operation mode, and significant differences can occur in the monitoring levels of force, speed, position, etc. Therefore, there is clear technical significance in automatically switching the scene to a manual operation scene when switching to manual operation mode.

[0368] Feature D7. The safety-related parameters include position monitoring parameters for monitoring the robot's operating position, and the safety-related unit is configured to stop the robot using the safety-related output signal when the robot's operating position deviates from the reference area. The robot control system according to feature D2 or feature D3, wherein when the robot is stopped by the safety-related unit, the referenced scene can be switched to the manual operation scene regardless of the robot's position.

[0369] If the robot stops because it has moved outside the reference area specified by the user, an operation is performed to return the robot to the reference area. In the configuration shown in this feature, the robot's position is irrelevant when switching to a manual operation scene, so there is no inconvenience such as difficulty in switching to a manual operation scene depending on the robot's position. This is preferable for smoothly performing recovery operations to restart the robot's movement.

[0370] Feature D8. The manual operation scene includes a recovery scene corresponding to the recovery operation of the robot. The robot control system according to feature D2 or feature D3, wherein when a switching operation is performed from the automatic operation mode to the manual operation mode while the robot is stopped based on the judgment result of the operation determination unit, it is possible to switch to the recovery scene.

[0371] If a robot becomes unable to operate normally due to getting caught on factory equipment or workpieces, the safety-related components can stop the robot to protect it. In such cases, increasing or eliminating the upper limit of the robot's driving force during recovery can help resolve the obstruction. However, if a recovery scenario is used in a situation other than recovery, the robot's driving force may become excessive. In this regard, as shown in this feature, if the system is configured to switch to the recovery scenario when the robot is stopped and the system switches from automatic operation mode to manual operation mode, unintentional switching to the recovery scenario can be suppressed.

[0372] Feature D9. The robot control system according to any one of Feature D2 to Feature D8, wherein the manual operation scene includes a direct teaching scene corresponding to direct teaching and a recovery scene corresponding to the robot's recovery operation.

[0373] For tasks involving manual robot operation, examples include direct teaching and recovery. Since the appropriate safety features may differ for these tasks, a practically preferable configuration can be achieved by providing separate scenes for direct teaching and recovery.

[0374] Feature D10. A robot control system (control system CS) is provided, which includes an action determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from a rotary encoder 36, torque sensor 37, etc.) that includes a parameter correlated with at least one of the force and speed of the robot (robot 16) in operation, and a predetermined determination criterion (reference value or reference range) for the parameter, and which realizes the safety function of the robot by generating a safety-related output signal according to the determination result, The robot's control modes include an automatic operation mode, which is applied when the robot is operated according to each operation instruction (drive control command) that constitutes the control program for the robot, and a manual operation mode, which is applied when the robot is manually operated by a user. Multiple candidate criteria for the parameters referenced by the operation determination unit can be set, and the operation determination unit is configured to perform the determination by referring to any of these criteria. As the aforementioned determination criteria, there are a number of first-class determination criteria that are referenced when the vehicle is in the automatic driving mode. During the automatic driving mode, when a switching instruction ("CHANGE SCENE" command) for the first type of judgment criterion included in the control program is reached during the drive control of the robot based on the control program, the configuration is such that the judgment criterion to be referenced is switched to the first type of judgment criterion specified by the switching instruction from among a plurality of first type judgment criteria, based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command normal). A robot control system in which the judgment criteria include a second type of judgment criterion that is referenced when the manual operation mode is enabled.

[0375] As shown in this feature, by incorporating a judgment criterion switching instruction into the robot's control program, and configuring the system to switch the judgment criterion during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to the situation. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the judgment criterion is switched automatically, the judgment criterion may be switched due to accidental factors such as noise, resulting in a mismatch between the expected situation and the judgment criterion. This is a concern as it may hinder the proper performance of safety functions. In this feature, when a switching instruction is reached in the control program, the judgment criterion is switched on the condition that predetermined switching conditions are met. This suppresses the switching of scenes that deviate from the user's intention and reduces the occurrence of the aforementioned mismatch.

[0376] In recent years, methods such as teaching robots by having users manually operate them have been used to shorten the time required to create control programs. Furthermore, if abnormal operation occurs during automatic operation, safety functions may activate and stop the robot, and the user may need to manually operate the robot to recover from such a situation. As described above, it is preferable to provide both an automatic operation mode for automatic operation and a manual operation mode for manual operation as control modes for the robot, and to take manual operation into consideration as described above, in order to improve safety and work efficiency when performing such manual operation.

[0377] However, the expected situations in autonomous driving mode and manual operation mode differ significantly, and various safety-related parameters may differ in order to properly perform safety functions. In other words, if the same judgment criteria are referenced in both autonomous driving mode and manual operation mode, it may become difficult to improve safety and productivity during autonomous driving, as well as improve safety and work efficiency during manual operation. In this regard, the configuration shown in this feature provides separate judgment criteria that are referenced when the robot is driven autonomously and when the robot is operated manually. This allows safety functions to be properly performed in both autonomous and manual operation modes.

[0378] For the reasons stated above, this technology can improve robot safety while also contributing to increased productivity during autonomous operation and improved user efficiency during manual operation.

[0379] Feature D11. A robot control system (control system CS) is provided, which includes a motion determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from a rotary encoder 36, torque sensor 37, etc.) that includes a parameter correlated with at least one of the force and speed of the operating robot (robot 16), and a predetermined determination criterion (reference value or reference range) for said parameter, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, The robot's control modes include an automatic operation mode, which is applied when the robot is operated according to each operation instruction (drive control command) that constitutes the control program for the robot, and a manual operation mode, which is applied when the robot is manually operated by a user. Multiple candidate criteria for the parameters referenced by the operation determination unit can be set, and the operation determination unit is configured to perform the determination by referring to any of these criteria. As the aforementioned determination criteria, there are a number of first-class determination criteria that are referenced when the vehicle is in the automatic driving mode. During the automatic driving mode, when a switching instruction ("CHANGE SCENE" command) for the first type of judgment criterion included in the control program is reached during the drive control of the robot based on the control program, the configuration is such that the judgment criterion to be referenced is switched to the first type of judgment criterion specified by the switching instruction from among a plurality of first type judgment criteria, based on the fulfillment of predetermined switching conditions (e.g., stop condition, position condition, command normal) including position conditions that define the position of the robot. A robot control system in which the judgment criteria include a second type of judgment criterion that is referenced when the manual operation mode is enabled.

[0380] As shown in this feature, by incorporating a judgment criterion switching instruction into the robot's control program, and configuring the system to switch the judgment criterion during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to the situation. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the judgment criterion is switched automatically, the judgment criterion may be switched due to accidental factors such as noise, resulting in a mismatch between the expected situation and the judgment criterion. This is a concern as it may hinder the proper performance of safety functions. Here, even if the robot is engaged in various tasks, its movements will basically follow the control program described above, so there is a certain relationship between the task and the area (operating area) in which the task is performed. Taking this reality into consideration, this feature configures the system to switch the judgment criterion on the condition that predetermined switching conditions, including position conditions, are met. In this way, by performing at least a position check when switching the judgment criterion, the above concerns can be eliminated, and the judgment criterion can be switched appropriately.

[0381] In recent years, methods such as teaching robots by having users manually operate them have been used to shorten the time required to create control programs. Furthermore, if abnormal operation occurs during automatic operation, safety functions may activate and stop the robot, and the user may need to manually operate the robot to recover from such a situation. As described above, it is preferable to provide both an automatic operation mode for automatic operation and a manual operation mode for manual operation as control modes for the robot, and to take manual operation into consideration as described above, in order to improve safety and work efficiency when performing such manual operation.

[0382] However, the expected situations in automatic driving mode and manual operation mode differ significantly, and the criteria for ensuring that safety functions are properly implemented may also differ. In other words, if the same criteria are used in both automatic and manual operation modes, it may become difficult to improve safety and productivity during automatic driving, as well as improve safety and work efficiency during manual operation. In this regard, the configuration described in this feature provides separate criteria for when the robot is in automatic driving mode and for when the robot is in manual operation mode. This allows for the proper implementation of safety functions in both automatic and manual operation modes.

[0383] For the reasons stated above, this technology can improve robot safety while also contributing to increased productivity during autonomous operation and improved user efficiency during manual operation.

[0384] Feature D12. A robot control system (control system CS) is provided, which includes a motion determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from a rotary encoder 36, torque sensor 37, etc.) that includes a parameter correlated with at least one of the force and speed of the robot (robot 16) in operation, and a predetermined determination criterion (reference value or reference range) for the parameter, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, The robot's control modes include an automatic operation mode, which is applied when the robot is operated according to each operation instruction (drive control command) that constitutes the control program for the robot, and a manual operation mode, which is applied when the robot is manually operated by a user. As candidates for the judgment criteria for the parameters referenced by the operation determination unit, there are a plurality of first-type judgment criteria referenced when the automatic operation mode is active, and a plurality of second-type judgment criteria referenced when the manual operation mode is active, and the operation determination unit is configured to make the determination by referring to any of these judgment criteria. During the automatic driving mode, when a switching instruction ("CHANGE SCENE" command) for the first type of judgment criterion included in the control program is reached during the drive control of the robot based on the control program, the judgment criterion to be referenced is switched to the first type of judgment criterion specified by the switching instruction from among a plurality of first type judgment criteria, based on the fact that predetermined switching conditions (e.g., stop condition, position condition, command normal) including position conditions that define the position of the robot have been met. A robot control system that, when in the manual operation mode, switches the referenced judgment criterion to the second type judgment criterion specified by the user based on a predetermined operation by the user.

[0385] As shown in this feature, by incorporating a judgment criterion switching instruction into the robot's control program, and configuring the system to switch the judgment criterion during drive control (automatic operation), it is possible to realize a configuration that appropriately performs safety functions according to the situation. This is desirable for achieving both improved robot safety and improved productivity by the robot. However, as shown in this feature, if the judgment criterion is switched automatically, the judgment criterion may be switched due to accidental factors such as noise, resulting in a mismatch between the expected situation and the judgment criterion. This is a concern as it may hinder the proper performance of safety functions. Here, even if the robot is engaged in various tasks, its movements will basically follow the control program described above, so there is a certain relationship between the task and the area (operating area) in which the task is performed. Taking this reality into consideration, this feature configures the system to switch the judgment criterion on the condition that predetermined switching conditions, including position conditions, are met. In this way, by performing at least a position check when switching the judgment criterion, the above concerns can be eliminated, and the judgment criterion can be switched appropriately.

[0386] In recent years, methods such as teaching robots by having users manually operate them have been used to shorten the time required to create control programs. Furthermore, if abnormal operation occurs during automatic operation, safety functions may activate and stop the robot, and the user may need to manually operate the robot to recover from such a situation. As described above, it is preferable to provide both an automatic operation mode for automatic operation and a manual operation mode for manual operation as control modes for the robot, and to take manual operation into consideration as described above, in order to improve safety and work efficiency when performing such manual operation.

[0387] However, the expected situations in automatic driving mode and manual operation mode differ significantly, and the criteria for ensuring that safety functions are properly implemented may also differ. In other words, if the same criteria are used in both automatic and manual operation modes, it may become difficult to improve safety and productivity during automatic driving, as well as improve safety and work efficiency during manual operation. In this regard, the configuration described in this feature provides separate criteria for when the robot is in automatic driving mode and for when the robot is in manual operation mode. This allows for the proper implementation of safety functions in both automatic and manual operation modes.

[0388] Furthermore, during autonomous driving, the judgment criteria automatically switch according to the control program's switching instructions, while the judgment criteria for manual operation switch according to the user's actions. This configuration prevents the judgment criteria from suddenly switching at times unintended by the user. This is desirable for further improving safety.

[0389] For the reasons stated above, this technology can improve robot safety while also contributing to increased productivity during autonomous operation and improved user efficiency during manual operation.

[0390] Feature D13. A robot control system (control system CS) is provided, which includes a motion determination unit (logic unit X2) that determines the movement of the robot based on a safety-related input signal (signal from a rotary encoder 36, torque sensor 37, etc.) that includes a parameter correlated with at least one of the force and speed of the operating robot (robot 16), and a predetermined determination criterion (reference value or reference range) for said parameter, and a safety-related unit (safety-related unit PX) that realizes the safety function of the robot by generating a safety-related output signal according to the determination result, The robot's control modes include an automatic operation mode, which is applied when the robot is operated according to each operation instruction (drive control command) that constitutes the control program for the robot, and a manual operation mode, which is applied when the robot is manually operated by a user. Multiple scenes (e.g., main scenes) can be set, which are groups of safety-related parameters that include the aforementioned judgment criteria as safety-related parameters that affect the safety function. The operation judgment unit is configured to make the judgment by referring to one of these scenes. A robot control system provided with multiple scenes, including automatic driving scenes (e.g., main scenes 1 to 9) that are referenced when the system is in automatic driving mode, and manual operation scenes (e.g., manual operation scene R and manual operation scenes 1 to 3) that are referenced when the system is in manual operation mode.

[0391] The configuration described in these features can improve robot safety while contributing to increased productivity by the robot during autonomous operation and improved user work efficiency during manual operation.

[0392] <Feature Group E> Switching of safety functions from non-safety related parts The following characteristic group E is related to the background technology, which states that "robot control systems applied to robots such as industrial robots have a safety-related section that implements safety functions for the robot and a non-safety-related section that performs drive control of the robot, etc. Regarding the safety-related section, for example, it has been proposed that the robot will be forcibly stopped if it collides with an obstacle such as a person (see, for example, Patent Document 1), or that the force (thrust) and speed of the robot in motion will be monitored and the robot will be forcibly stopped if it moves outside of safety standards." In recent years, due to advances in robot technology, the types of tasks that a single robot can perform are also increasing. When a single robot is to perform various tasks, it is important to be able to change (operate) the safety functions to ensure safety. This could be advantageous in improving the work efficiency of the robot. Here, in order to suppress the impairment of safety functions due to communication errors during changes, it is preferable that the input for changing safety functions also be an input from the safety-related input unit (so-called safety input). However, if safety input is required, the constraints on changes will be strong, and it is assumed that this will hinder the improvement of the oper...

Claims

1. A setting support device is applied to a robot control system configured to drive and control a robot according to each motion instruction constituting an motion program for the robot, and to switch the referenced scene when a switching instruction for the scene included in the motion program is reached as the motion program progresses during drive control of the robot, and a safety-related unit which determines the movement of the robot based on a safety-related input signal containing correlation information correlated with at least one of the force and speed of the robot during drive control and a judgment criterion for the correlation information stored in advance, and realizes the safety function of the robot by generating a safety-related output signal according to the judgment result, wherein multiple scenes are set, which are groups of safety-related parameters that include the judgment criterion as safety-related parameters that affect the safety function, and the motion determination unit is configured to make the determination by referring to one of these scenes, and when a switching instruction for the scene included in the motion program is reached as the motion program progresses during drive control of the robot based on the motion program, the referenced scene is switched based on the fulfillment of a predetermined switching condition, and the setting support device assists the user in setting each of the safety-related parameters for each of the scenes. Display unit and The display unit includes a display control unit that displays a parameter setting screen corresponding to the scene specified by the user. Equipped with, A setting support device is provided with a parameter setting screen that includes a first display mode which displays both the first parameter group and the second parameter group constituting the safety-related parameter group, and a second display mode which displays only the first parameter group from the first and second parameter groups.

2. A setting support device is applied to a robot control system configured to drive and control a robot according to each motion instruction constituting an motion program for the robot, and to switch the referenced scene when a switching instruction for the scene included in the motion program is reached as the motion program progresses during drive control of the robot, and a safety-related unit which determines the movement of the robot based on a safety-related input signal containing correlation information correlated with at least one of the force and speed of the robot during drive control and a judgment criterion for the correlation information stored in advance, and realizes the safety function of the robot by generating a safety-related output signal according to the judgment result, wherein multiple scenes are set, which are groups of safety-related parameters that include the judgment criterion as safety-related parameters that affect the safety function, and the motion determination unit is configured to make the determination by referring to one of these scenes, and when a switching instruction for the scene included in the motion program is reached as the motion program progresses during drive control of the robot based on the motion program, the referenced scene is switched based on the fulfillment of a predetermined switching condition, and the setting support device assists the user in setting each of the safety-related parameters for each of the scenes. Display unit and The display unit includes a display control unit that displays a parameter setting screen corresponding to the scene specified by the user. Equipped with, A setting support device is provided with a parameter setting screen that includes a first display mode which displays both the first parameter group and the second parameter group constituting the safety-related parameter group, and a second display mode which displays only the first parameter group from the first and second parameter groups.

3. The setting support device according to claim 1 or claim 2, wherein in the second display mode, the first group of parameters is displayed in a state classified into multiple groups.

4. A robot control device comprising: a drive control unit that drives and controls the robot according to each motion instruction constituting the robot's motion program; a motion determination unit that determines the robot's movement based on a safety-related input signal containing correlation information correlated with at least one of the robot's force and speed during drive control, and a predetermined determination criterion for the correlation information stored in advance, and realizes the robot's safety function by generating a safety-related output signal according to the determination result, wherein multiple scenes are set, which are groups of safety-related parameters that include the determination criterion as safety-related parameters that affect the safety function, and the motion determination unit is configured to make the determination by referring to one of these scenes, and the robot control device is configured to switch the referenced scene when, during drive control of the robot based on the motion program, the motion program progresses and a switching instruction for the scene included in the motion program is reached, and a predetermined switching condition including a position condition defining the robot's position is met, and the robot control device is configured to switch the referenced scene, and the robot control device is installed on a computer that can be connected to the computer, and the computer is configured to assist the user in setting each of the safety-related parameters for each of the scenes, The display unit displays a parameter setting screen corresponding to the scene specified by the user. The display modes for the safety-related parameter group in the parameter setting screen are defined as follows: a first display mode that displays both the first parameter group and the second parameter group constituting the safety-related parameter group, and a second display mode that displays only the first parameter group from the first and second parameter groups. A setting support program that switches the display mode between the first display mode and the second display mode based on a user's switching operation.

5. A robot control system comprising: a drive control unit that drives and controls the robot according to each motion instruction constituting an motion program for the robot; a motion determination unit that determines the movement of the robot based on a safety-related input signal containing correlation information correlated with at least one of the force and speed of the robot during drive control and a predetermined determination criterion for the correlation information stored in advance, and realizes the safety function of the robot by generating a safety-related output signal according to the determination result, wherein multiple scenes are set, which are groups of safety-related parameters that include the determination criterion as safety-related parameters that affect the safety function, and the motion determination unit is configured to make the determination by referring to one of these scenes, wherein during drive control of the robot based on the motion program, when the motion program progresses and a switching instruction for the scenes included in the motion program is reached, the referenced scene is switched based on the fact that predetermined switching conditions, including position conditions that define the position of the robot, have been met, and a method for displaying a group of safety-related parameters that display the safety-related parameters when a user sets or confirms each of the safety-related parameters that constitute each of the scenes, The display unit shows a parameter setting screen corresponding to the scene specified by the user. A method for displaying a group of safety-related parameters on the parameter setting screen, which switches the display of the safety-related parameter group on the parameter setting screen between a first display that displays both the first parameter group and the second parameter group that constitute the safety-related parameter group, and a second display that displays only the first parameter group from the first parameter group and the second parameter group, based on a user switching operation.

Citation Information

Patent Citations

  • Robot safety monitoring device

    JP2017077608A

  • Simulator device, and control method for simulator device

    JP2019123052A

  • Control device, robot and robot system

    JP2019177434A

  • Control device and robot system

    JP2019202364A

  • Robot system

    JP2020189367A