Robot safety control hardware platform, system comprising the platform, method for providing the platform and method for operating the system
The dual multi-core processor-based robot safety control platform addresses the complexity and cost issues of existing systems by integrating safety and main control functions, achieving reduced costs, simplified assembly, and enhanced safety compliance with ISO standards.
Patent Information
- Application Number
- PCT/CN2024/079265
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-29
- Publication Date
- 2025-09-04
AI Technical Summary
Existing robot safety control systems are costly and complex, with redundant hardware components leading to increased assembly time and maintenance challenges, while failing to meet the safety standards of ISO13849 and ISO10218 effectively.
A robot safety control hardware platform utilizing a control unit with dual multi-core processors, allowing switching between different safety topologies to integrate safety and main control functions, reducing hardware costs and simplifying assembly, while ensuring compliance with ISO safety standards through redundant safety channels and cross-monitoring.
The solution reduces manufacturing costs, simplifies assembly, and enhances safety by integrating safety and main control functions in a single unit, ensuring real-time performance and immediate safety state restoration upon faults, thus improving operational reliability and safety compliance.
Smart Images

Figure CN2024079265_04092025_PF_FP_ABST
Abstract
Description
ROBOT SAFETY CONTROL HARDWARE PLATFORM, SYSTEM COMPRISING THE PLATFORM, METHOD FOR PROVIDING THE PLATFORM AND METHOD FOR OPERATING THE SYSTEMTECHNICAL FIELD
[0001] The present invention relates to a robot safety control hardware platform, in particular a robot safety control hardware platform architecture, a system comprising a platform as described herein, in particular a system for operating a robot and providing or ensuring safety while operating the robot respectively, a method for providing a platform as described herein and a method for operating a system as described herein respectively.BACKGROUND
[0002] A (n architecture of a) robot safety control system hardware platform typically involves safety inputs, safety logics and safety actuators to detect and respond to potential safety faults and hazards respectively, the safety control system being responsible for monitoring the robot’s behavior and ensuring that it operates within safety limits.
[0003] For robot safety systems, safety inputs can include in particular safety emergency stop buttons, 3-enabling devices, safety protective devices like safety door, safety interlock devices and other safety sensors. Safety actuators can in particular refer to Safety Torque Off (“STO” ) , Safety Brake Control ( “SBC” ) and / or safety outputs to other safety related systems. Safety logics can in particular implement or realize safety control and / or diagnostics functions which make sure that the system can get in safe state with art of fail-in-safe upon a single fault respectively. Following the safety standard ISO13849 and robotic standard ISO10218, as rule of thumb, the robot safety system preferably shall achieve at least CAT3 Pld level, that drives the safety system design to follow redundant path and cross monitoring methodology.
[0004] EP 3581343A1 discloses a safety control system for an industrial robot, wherein the safety control system comprises a first safety controller, which is connected to at least one safety sensor outputting a safety signal and receives said safety signal, and a second safety controller, which is connected to at least one safety-related sensor outputting a safety-related signal and receives said safety-related signal, wherein said first safety controller and said second safety controller are respectively connected to a safety actuating system.
[0005] WO 2022 / 120820 A1 discloses a robot control system comprising: a motion control unit configured to perform motion control of a robot; a rectifier control unit comprising an AC-DC control unit configured to generate a rectifier control signal for driving a rectifier power stage, the rectifier power stage being configured to convert AC power from a grid into DC power; a safety control unit configured to generate, based on an operating state of the robot or a user input, a safety control signal for selectively turning on or off safety switches connected to an output of the rectifier power stage; and a motor control unit configured to perform motor control of the robot based on the DC power received via the safety switches, wherein the motion control unit, the rectifier control unit, and the safety control unit are integrated in a same chip.SUMMARY
[0006] The object of the present invention is to improve providing a robot safety control hardware platform or a system comprising said platform or to improve a robot safety control hardware platform or a system comprising said platform, in particular operating said platform or system, respectively.
[0007] This object is achieved in particular by a robot safety control hardware platform with the features of claim 1. Claims 16, 18 and 20 refer to a system comprising a platform as described herein, a method for providing a platform as described herein and a method for operating a system as described herein respectively. Subclaims relate to advantageous embodiments.
[0008] According to one aspect of the present invention a robot safety control hardware platform, preferably a robot safety control hardware platform architecture, comprises a control unit.
[0009] According to some embodiments said control unit may comprise, in particular be, an, preferably integrated, control board.
[0010] According to some embodiments the control unit comprises at least two processors which are called a first and second processor respectively herein.
[0011] According to some embodiments the first processor is a multi-core processor comprising two or more (processor) cores, preferably a multi-core System-on-Chip ( “SoC” ) processor. Additionally or alternatively the second processor may be a multi-core processor comprising two or more (processor) cores, preferably a multi-core SoC processor. Accordingly, the control unit comprises three or more cores (one or more of the first processor and one or more of the second processor) .
[0012] According to some embodiments the control unit is (according to some embodiments was or already is, respectively) switched into one of two or more different safety topologies, each safety topology comprising another combination of the cores of the control unit for providing at least two safety channels, and / or is (according to some embodiments still is) adapted to be switched into (one of) two or more different safety topologies, each safety topology comprising another combination of the cores of the control unit for providing at least two safety channels, respectively.
[0013] Accordingly, according to one aspect of the present invention a method for providing at least one robot safety control hardware platform as described herein comprises switching the control unit of said at least one robot safety control hardware into one of the different safety topologies. Thus, the control unit serves as or provides safety control respectively.
[0014] According to some embodiments the control unit (also) serves as or provides a main robot controller or is adapted to this (purpose) respectively. Main robot control (er) can in particular comprise, preferably regular or normal respectively, robot motion control, servo control, in particular servo drive control, and / or fieldbus and / or communication control, preferably for non-safety purpose.
[0015] Thus, according to some embodiments safety control and main control, preferably servo (drive) control, are combined in one integrated control unit, preferably board, but at least, preferably only, two, preferably multi-core and / or System-on-Chip, processors, are used to allocate and distribute different function units in different cores to formulate an optimized control and computation functioning system, and additionally it is (already) switched and / or can (still) be switched between safety architecture variants in different configuration topology by using different cores of the processors, respectively, in particular as safety logic controllers.
[0016] Said combining may in particular reduce the total costs, preferably eliminate additional PCBA manufacturing costs and / or make assembling by robots easier. Additional cost savings may be achieved by combining sharing use of power supplies, protections and / or peripherals on one control board.
[0017] Preferably the control unit provides a multi-core distributed architectural real-time control system, allowing or improving multi-core computation, preferably independently and / or simultaneously, to allow or improve real-time performance, respectively.
[0018] Combining the safety control and main control, preferably servo (drive) control, in one, preferably integrated, control unit, preferably board, but using, preferably only, two processors, preferably multi-cores and / or System-on-Chip processors, i.e. in particular multi-cores System-on-Chip processors, advantageously allows to allocate and distribute different function units in different cores to formulate an optimized control and computation functioning system.
[0019] According to some embodiments the control unit is switched into one of different safety architecture variants in different configuration topology by using different cores of the SoCs as safety logic controllers, or is adapted to this (purpose) , respectively.
[0020] Accordingly, according to some embodiments the method for providing at least one robot safety control hardware platform comprises switching the control unit of at least one robot safety control hardware as described herein into one of the different safety topologies and switching the control unit of at least one other robot safety control hardware as described herein into another one of the different (possible or designated respectively) safety topologies.
[0021] According to some embodiments at least one safety channel of at least one safety topology (into which the control unit can be switched) comprises at least one core of the first processor for outputting safe stop commands, and at least one other safety channel of this safety topology comprises at least one core of the second processor for outputting safe stop commands. In other words, cores of both processors (are used to) output safe stop commands. This can increase safety.
[0022] Additionally or alternatively, according to some embodiments at least one safety channel of at least one safety topology (into which the control unit can be switched) comprises at least one core of the first processor, preferably of a MCU domain of the first processor, for outputting safe stop commands, and at least one other safety channel of this safety topology comprises at least one other core of the first processor, preferably of a main domain of the first processor, for outputting safe stop commands. In other words, different cores of the same processor (are used to) output safe stop commands. This can provide additional or alternative communication channels respectively.
[0023] According to some embodiments one or more of said stop commands (each) may comprise a safety torque off ( “STO” ) command and / or a Safety Brake Control ( “SBC” ) command. According to some embodiments a STO / SBC system is provided, preferably with reset and safety actuator, which can advantageously guarantee to get in safety state immediately whenever there is a hardware fault. Preferably meanwhile the SoC (s) is / are reset for a safety system restart. This can increase safety and / or improve operation, in particular reduce downtime or the like.
[0024] Additionally or alternatively, according to some embodiments at least one safety channel of at least one safety topology (into which the control unit can be switched) comprises at least one core of the first processor for performing a first safety logic, in particular serving as a first safety controller, and at least one other safety channel of this safety topology comprises at least one core of the second processor for performing a second safety logic, in particular serving as a second safety controller. In other words, cores of both processors are used (as safety controllers) to perform safety logics. This can increase safety.
[0025] Additionally or alternatively, according to some embodiments at least one safety channel of at least one safety topology (into which the control unit can be switched) comprises at least one core of the first processor for performing a first safety logic, in particular serving as a first safety controller, and at least one other safety channel of this safety topology comprises at least one other core of the first processor for performing a second safety logic, in particular serving as a second safety controller. In other words, different cores of the same processor are used (as safety controllers) to perform safety logics. This can provide additional or alternative safety controllers respectively.
[0026] Said embodiments with cores of both processors or one of said processors (being used for or adapted to respectively) outputting safe stop commands and cores of both processors or one of said processors (being used for or adapted to respectively) performing safety logics, in particular serving as safety controllers, may advantageously be combined.
[0027] According to some embodiments the control unit communicates with a teach pendant, preferably with an emergency stop and / or an enabling device, preferably a 3-(way ) enabling device, and / or with position sensors of a robot, preferably safety rated position sensors, according to some embodiments an RDC unit in the robot, or is adapted to this (purpose) respectively. According to some embodiments one of the first and second processor communicates with the teach pendant and the other one of the first and second processor communicates with the position sensors or the first and second processor are adapted to this (purpose) respectively. This can increase safety.
[0028] According to some embodiments the control unit communicates via FOSE (FailSafe over EtherCAT) , preferably with the teach pendant, according to some embodiments its emergency stop and / or (3- (way) ) enabling device, and / or with the position sensors, or is adapted to this (purpose) respectively. According to some embodiments a safety motion link is realized through FSOE to retrive position data from safety rated RDC unit in the robot for safe axis position, speed monitoring and / or safe zone monitoring. Accordingly, according to some embodiments an FSOE communication with teach pendant to access emergency stop and / or (3- (way) ) enabling device signal change information through FSOE is established or used or the system or platform adapted to this (purpose) respectively. This can increase safety.
[0029] According to some embodiments the first and second processor cross-communicate with each other, preferably trough serial link, according to some embodiments two serial links and / or two sync I / Os, or are adapted to this (purpose) respectively. This can increase safety.
[0030] According to some embodiments two or more cores of the control unit comprise or operate with different operation systems or are adapted to this (purpose) respectively. This can increase safety and / or improve performance.
[0031] According to some embodiments at least one of the first and second processor comprises a main domain and a MCU domain, preferably said domains are separated physically internally and / or interconnected and / or communicate by IPC internally, preferably power is separately provided to separate domains and / or monitored by a PDN system.
[0032] According to some embodiments the control unit is switched or can be switched into (the respective of) the different safety topologies based on at least one input signal, respectively, preferably (is or can be switched based on) at least one input signal from the first and / or second processor, and / or (is or can be switched based on at least one input signal) using a Mux method, preferably a 2: 1 Mux method, or an AND logic method, or is adapted to this (purpose) respectively. This can increase safety and / or improve providing the different safety topologies or safety channels respectively.
[0033] According to one aspect of the present invention a system comprises a robot safety control hardware platform as described herein. According to some embodiments the system further comprises a robot and / or a teach pendant and / or one or more safety input devices and / or one or more safety output devices and / or a power unit. According to some embodiments the robot is a robot manipulator, preferably a multi-axis robot arm, and / or is controlled by the control unit of robot safety control hardware platform or the platform is adapted to this (purpose) respectively.
[0034] According to some embodiments, based on multi-core distributed architectural a real-time control system performs multi-core computation independently and simultaneously to ensure the real-time performance and / or improve the computation power. According to some embodiments a R5F core integrates real-time bus stack protocols, thus reducing additional hardware module costs. Multi functional configurable blocks may provide easily extendable bus and extension axis solutions.
[0035] Further advantages and features can be gathered from the dependent claims and the exemplary embodiments.BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Fig. 1 shows a system with a robot safety control hardware platform (architecture) according to one embodiment of the present invention;
[0037] Fig. 2 shows a first safety topology or safety control hardware (architecture) variant, respectively;
[0038] Fig. 3 shows a second safety topology or safety control hardware (architecture) variant, respectively;
[0039] Fig. 4 shows a third safety topology or safety control hardware (architecture) variant, respectively;
[0040] Fig. 5 shows a switching (method) of the control unit between the third variant and the first or second variant respectively according to one embodiment of the present invention; and
[0041] Fig. 6 shows a switching (method) of the control unit between the third variant and the first or second variant respectively according to another embodiment of the present invention.
[0042] Reference list
[0043] 1 robot
[0044] 2 safety input devices
[0045] 3 safety output devices
[0046] 4 control unit
[0047] 5 power unit
[0048] 6 robot controller
[0049] 7 RDC (safe position feedback unit / position sensors)
[0050] 8 teach pendant
[0051] 8.1 E stop
[0052] 8.2 3-enabling device
[0053] 10 first / primary SoC
[0054] 11 core
[0055] 12 core
[0056] 13 core
[0057] 14 core
[0058] 15 core
[0059] 20 second (ary) SoC
[0060] 31 power system of SoC 10
[0061] 32 Q / Awatchdog
[0062] 33 voltage-monitor-OV / UV
[0063] 34 discrete FS output, STO / SCB
[0064] 35 discrete safety input
[0065] 41 power system of SoC 20
[0066] 42 reset / watchdog
[0067] 43 voltage-monitor-OV / UV
[0068] 44 discrete FS output, STO / SCB
[0069] 45 discrete safety input
[0070] 51 MCU domain
[0071] 51A first SoC MCU Logic A
[0072] 52 main domain
[0073] 53 PL
[0074] 54 PS
[0075] 61 ESC S In
[0076] 62 ESC S Out
[0077] 70 ECAT Master
[0078] 80 Mux 2: 1
[0079] 81 jumper
[0080] 82 AND
[0081] 340 first channel STO / SBC
[0082] 440 second channel STO / SBC
[0083] 443 STO / SBC of variant number 3
[0084] 4412 STO / SBC of variant number 1 and 2
[0085] A first safety logic
[0086] B second safety logic
[0087] B.1 Safety I / O B
[0088] c cross communication and monitoring
[0089] EN EN_DRV
[0090] F FSoE communication
[0091] FB feedback
[0092] IU I2C
[0093] o STO / SBC signals
[0094] O1 operating system
[0095] O2 operating system
[0096] O3 operating system
[0097] p power
[0098] PU pull-up
[0099] P1 PORz_SoC
[0100] P2 PORz_MCU
[0101] R Reset_PS
[0102] s servo control (signals)
[0103] SE SEL_CTRL
[0104] SW software ( (input) signal (s) )
[0105] UV UV_RSTDETAILED DESCRIPTION
[0106] Fig. 1 shows a system with a robot safety control hardware platform (architecture) or controller safety hardware platform (architecture) , respectively, according to one embodiment of the present invention.
[0107] The (safety control) system for a robot 1 comprises various safety input devices 2 and safety output devices 3, a control unit 4 and a power unit 5 within a robot controller 6, a safe position feedback unit within robot 1, in the exemplary embodiment an resolver digital converter ( “RDC” ) 7, and a teach pendant 8, preferably comprising an E (mergency) stop 8.1 and / or (3- (way ) ) enabling device 8.2. Both, teach pendant 8, in particular its E (mergency) stop and / or (3- (way ) ) enabling device, and RDC 7, can communicate via FSOE protocol with control unit 4 to accomplish safety data communication throughout the entire control system.
[0108] The control unit 4 is located in the robot controller 6. For safety purpose it plays a role as the safety related logical control of entire safety system. For non-safety purpose it plays multiple roles as robot motion control, servo control and fieldbus / communication control center. Power unit 5 is also located in the robot controller 6, in particular for safety purpose.
[0109] The power unit 5 plays a role as the actuator to implement STO / SBC safety functions to stop the robot 1 safely. For non-safety purpose it serves as power invertor to provide power to the motors (not shown) of robot 1 and generates different intermediate power supplies that other units need.
[0110] Between control unit 4 and power unit 5, there are power and control signals interacted and transmitted, in particular power p, servo control (signals) s and STO / SBC signals o.
[0111] The control unit 4 provides safety logic of the entire safety control system. Inside of control unit 4 there are two SoCs: first or primary SoC 10, respectively, and second or secondary SoC 20, respectively.
[0112] For functional safety purpose, SoC 10 and SoC 20 can form into different safety hardware architecture variants as will be explained with respect to Fig. 2 (variant number 1) , Fig. 3 (variant number 2) and Fig. 4 (variant number 3) , respectively.
[0113] The exemplary embodiments illustrate one hardware platform to support three (kinds of) safety (architecture) topologies. In other words the art of this hardware architecture is that it can create three different safety architecture variants with the same hardware platform:
[0114] Safety architecture variant number 1 (see Fig. 2) embodies that SoC 10 provides a first safety (logic) channel while SoC 20 provides a second safety (logic) channel, preferably to construct as a Cat3 structure per ISO13849. SoC 10 and SoC 20 are cross-communicated and preferably checked via a serial communication method. The communication methods can in particular be Uart, SPI, PCIe, Ethernat etc.
[0115] Safety architecture variant number 2 (see Fig. 3) embodies that core 11 of SoC 10 in MCU domain 51 provides a first safety (logic) channel and core 12 of SoC 10 in main domain 52 provides a second safety (logic) channel, while SoC 20 serves as the safety I / O expension of said second safety channel for outputting safe stop commands.
[0116] Safety architecture variant number 3 (see Fig. 4) embodies that both safety I / O channels and logics are distributed on MCU domain 51 and main domain 52 of SoC 10 separately. SoC 20 functions as a non-safety related processor.
[0117] Two preferred methods of switching between different variants will be explained below.
[0118] Fig. 2 shows a first safety topology or safety control hardware (architecture) variant number 1 respectively.
[0119] Inside of control unit 4, there are two SoCs 10, 20. For functional safety purpose these two SoCs 10, 20 provide or serve as a first safety (logic) channel or safety logical and a second safety (logic) channel or safety logical, respectively. This is indicated by “A” and “B” for the first and second safety logic in Fig. 2.
[0120] The dual SoCs 10, 20 with cores 11, 14 providing safety logics A and B, respectively, form into a redundant system with cross communication and cross monitoring c aiming to meet Category 3 structure of standard ISO 13849-1. Cross monitoring between SoCs 10, 20 or between safety logics A, B, respectively, is achieved by serial communication and interrupt monitoring. SoC 10 system is equipped with dedicated power system and voltage monitoring system, reset and watchdog. SoC 20 system also is equipped with the same peripherals as SoC 10. SoCs 10, 20 or safety logics A, B, respectively, receive safety input and issue safety output and STO / SBC signals in a redundant path.
[0121] SoC 10 acts as safety communication master to communicate with robot RDC 7 to receive position feedback through FSOE communication F. During safety communication SoC 20 continuously receives RDC data frames and transmits to core 13 of SoC 10 for further data analysis and processing. SoC 10 also communicates with teach pendant 8 through FSOE protocol communication F.
[0122] In general, in the entire safety system control unit’s SoC 10 together with SoC 20 implement a safety logical role to calculate, analyze and determine safety action upon a safety demand and / or safety fault / incident.
[0123] The entire safe system safety state preferably is safe stoppage (STO, SBC, SS1 and / or SS2) and can be issued successfully upon failures to let system fall in safe state, for some cases safety communication can be terminated, for some cases control board power can be shut-off.
[0124] Besides the safety logical functions, SoC 10 plays as role of a main control (ler) to do motion control, multi-OS function, servo speed / position loop and multi-customer communication interface. SoC 20 plays a role of servo (drive) control (ler) to do servo drive control and current loop control.
[0125] Multiple operating systems ( “OS” ) can advantageously be used for different cores according to core function usage. For example core 12 on SoC 10 can run a linux operating system for real-time operating purpose, core 11 and core 14 can run some small operating systems to provide safety application operation. Operating systems are indicated by O1, O2, …etc. in Fig. 2.
[0126] In Fig. 2 31 denotes a power system of SoC 10, 32 denotes a Q / Awatchdog, 33 denotes a voltage-monitor-OV / UV, 34 denotes discrete FS output, STO / SCB in first safety channel or of safety logic A, respectively, and 35 denotes discrete safety inputs in first safety channel or of safety logic A, respectively.
[0127] Accordingly, 41 denotes a power system of SoC 20, 42 denotes a reset / watchdog, 43 denotes a voltage-monitor-OV / UV, 44 denotes discrete FS output, STO / SCB in second safety channel or of safety logic B, respectively, and 45 denotes discrete safety inputs in second safety channel or of safety logic B, respectively, in Fig. 2.
[0128] Moreover, 53 denotes programmable logic ( “PL” ) , 54 denotes processing system ( “PS” ) , 61 denotes ESC S In, 62 denotes ESC S Out, 70 denotes ECAT Master, P1 denotes PORz_SoC, P2 denotes PORz_MCU, UV denotes UV_RST, R denotes Reset_PS, EN denotes EN_DRV and IU denotes I2C in Fig. 2.
[0129] Fig. 3 shows a second safety topology or safety control hardware (architecture) variant number 2, respectively. Corresponding features are indicated with the same reference signs. Thus reference is made to the foregoing description while in particular differences with respect to Fig. 2 will be further explained in the following.
[0130] In the embodiment of Fig. 3 the first safety channel comprises safety logic A, discrete safety inputs and outputs and is fully implemented in MCU domain 51 of SoC 10 as in the embodiment of Fig. 2.
[0131] However, in the embodiment of Fig. 3 second safety channel is split between main domain 52 of SoC 10 for its (second) safety logic B and SoC 20 as its discrete safety inputs and outputs. Accordingly, B. 1 in Fig. 3 denotes I / O of second safety channel or Safety I / O B, respectively.
[0132] As in the embodiment of Fig. 2 SoC 10 is powered and monitored by power (management) system 31 of SoC 10. This power system 31 can provide system hardware safety diagnostic and protection functions for SoC 10. A separated PORz reset signal for MCU domain 51 (see P2 in Fig. 2, 3) and SoC 10 (see P1 in Fig. 2, 3) can be generated by the power (management) system 31 of SoC 10, a dedicated Q / Awatchdog 32 is used to monitor for MCU domain software lockup. Two error signal monitor ( “ESM” ) inputs with fault injection options to monitor the error signals from the attached MCU or Main domain 51, 52 of SoC 10 and voltage monitoring (see 33 in Fig. 2, 3) are implemented on input and all BUCK and LDO regulator outputs to trip a safety stop whenever there is a over voltage ( “OV” ) or under voltage ( “UV” ) fault happened.
[0133] SoC 20 serves as I / O expansion of the second safety channel. It communicates with core 12 of SoC 10 through serial interface, its power supplies are all monitored by a voltage supervisor, and the OV (over voltage) / UV (under voltage) results are linked to safety stop output STO / SBC / SO channel as well, in case of any single voltage failure, the system will go into a safe state. A separated watchdog is used to watch over the ZYNQ system in case of program stuck or runout.
[0134] Fig. 4 shows a third safety topology or safety control hardware (architecture) variant number 3 respectively. Corresponding features are indicated with the same reference signs. Thus reference is made to the foregoing description while in particular differences with respect to Fig. 2, 3 will be further explained in the following.
[0135] Compared with variant number 1 and variant number 2 described above with respect to Figs. 2, 3, variant number 3 shown in Fig. 4 implements the redundant safety channels on MCU domain 51 and main domain 52 of SoC 10.
[0136] MCU domain core 11 performs first safety logic A or functions or serves as a first safety controller in the first safety channel respectively and connects discrete safety inputs and safety output / STO / SBC.
[0137] Main domain core 15 performs second safety logic B functions or serves as a second safety controller in the second safety channel respectively. MCU domain 51 and main domain 52 are separated physically internally and interconnected and communicate by IPC internally, power is separately provided to separate domains and monitored by a PDN system. PDN system PMIC functions as a third monitoring device to provide protection and diagnostics for SoC 10. EN_DRV signal ( “EN” in Fig. 4) from power system PMIC will activate both safety channels or safety logics A and B STO / SBC and safety output. Freedom from interference FFI between two domains is implemented to prevent from both channel breakdown simultaneously.
[0138] In a variant, the discrete safety inputs in second safety channel or of safety logic B, respectively, denoted by 45 in Fig. 4, may be handled as the discrete FS output, STO / SCB in second safety channel or of safety logic B, respectively, denoted by 44 in Fig. 4. In particular, one or both of 44, 45 may be switched by software ( (input) signals) as indicated by “SW” and a cross in Fig. 4.
[0139] As can be understood from Figs. 2-4 and the foregoing description, in variant number 1 (see Fig. 2) one safety channel comprises core 11 of the first processor 10 for outputting safe stop commands and for performing first safety logic A and the other safety channel comprises core 14 of the second processor 20 for outputting safe stop commands and for performing second safety logic B. In variant number 2 (see Fig. 3) one safety channel comprises core 11 of the first processor 10 for outputting safe stop commands and for performing first safety logic A. However, in variant number 2 the other safety channel comprises core 14 of the second processor 20 for outputting safe stop commands and comprises core 12 of the first processor 10 for performing second safety logic B. In variant number 3 (see Fig. 4) one safety channel comprises core 11 of the first processor 10 for outputting safe stop commands and for performing first safety logic A and the other safety channel comprises core 15 of the first processor 10 for outputting safe stop commands and for performing second safety logic B.
[0140] Since variant number 1 and variant number 2 share the same platform, switching between variant number 3 and variant number 1, 2 can be performed in particular by two methods as described below.
[0141] A first method is illustrated in Fig. 5 which shows a 2: 1 Mux method which is controlled by an I / O from main domain 52. An I / O pin is called SEL_CTRL, the SEL_CTRL status is also monitored by SoC 20, SEL_CTRL is pulled up by default, so variant number 1 and variant number 2 are selected, variant number 3 can be selected by controlling pull low of SEL_CTRL. Jumper 81 is also available for debug purpose.
[0142] Accordingly, 51A denotes first SoC MCU Logic A, 340 denotes first channel STO / SBC, PU denotes pull-up, 443 denotes STO / SBC of variant number 3, 4412 denotes STO / SBC of variant number 1 and 2, 80 denotes Mux 2: 1, 440 denotes second channel STO / SBC, SE denotes SEL_CTRL and FB denotes feedback in Fig. 5.
[0143] A second method is illustrated in Fig. 6 which shows an AND logic method. This method uses a AND logic to combine the two inputs from main domain 52 of SoC 10 and SoC 20. In this way, if variant number 1, 2 is (to be) chosen, STO / SBC output from main domain 52 of SoC 10 will be pulled high by software while STO / SBC output from SoC 20 is the functioning output. Accordingly 82 denotes (logical) “AND” .
[0144] In the present disclosure “comprises one / an X” in general does not imply an exclusive list but is a short form of “comprises at least one / an X” and also comprises “comprises two or more X” -Although exemplary embodiments have been discussed in the preceding description, it should be pointed out that a large number of modifications are possible. It should also be pointed out that the exemplary embodiments are only examples that are not intended to limit the scope of protection or the possible applications and structure of the invention in any way. Rather, the person skilled in the art is given a guide for the realization of at least one exemplary embodiment by the preceding description, wherein various modifications, in particular with regard to the function and arrangement of the described components or features, may be realized without leaving the scope of protection as derived from the claims and features combinations equivalent thereto respectively.
Claims
1.A robot safety control hardware platform, comprising a control unit (4) which comprises:a first processor (10) ;a second processor (20) ;wherein at least one of the first and second processor is a multi-core processor so that the control unit comprises at least three cores;wherein the control unit is adapted to serve as a main robot controller; andwherein the control unit is switched or is adapted to be switched into one of at least two different safety topologies, said different safety topologies comprising different combinations of said at least three cores for providing at least two safety channels.2.The robot safety control hardware platform according to claim 1, wherein at least one safety channel of at least one safety topology comprises at least one core of the first processor for outputting safe stop commands and at least one other safety channel of said safety topology comprises at least one core of the second processor for outputting safe stop commands.3.The robot safety control hardware platform according to any one of the preceding claims, wherein at least one safety channel of at least one safety topology comprises at least one core of the first processor for outputting safe stop commands and at least one other safety channel of said safety topology comprises at least one other core of the first processor for outputting safe stop commands.4.The robot safety control hardware platform according to claim 2 or 3, wherein at least one stop command comprises at least one of a safety torque off command and a safety brake control command.5.The robot safety control hardware platform according to any one of the preceding claims, wherein at least one safety channel of at least one safety topology comprises at least one core of the first processor for performing a first safety logic and at least one other safety channel of said safety topology comprises at least one core of the second processor for performing a second safety logic.6.The robot safety control hardware platform according to any one of the preceding claims, wherein at least one safety channel of at least one safety topology comprises at least one core of the first processor for performing a first safety logic and at least one other safety channel of said safety topology comprises at least one other core of the first processor for performing a second safety logic.7.The robot safety control hardware platform according to any one of the preceding claims, wherein the control unit is adapted to communicate with at least one of a teach pendant (8) and position sensors (7) of a robot (1) .8.The robot safety control hardware platform according to claim 7, wherein one of the first and second processor is adapted to communicate with the teach pendant and the other one of the first and second processor is adapted to communicate with the position sensors.9.The robot safety control hardware platform according to any one of the preceding claims, wherein the control unit is adapted to communicate via FOSE.10.The robot safety control hardware platform according to any one of the preceding claims, wherein the first and second processor is adapted to cross-communicate with each other, preferably trough serial link.11.The robot safety control hardware platform according to any one of the preceding claims, wherein the first processor is a multi-core SoC processor.12.The robot safety control hardware platform according to any one of the preceding claims, wherein the second processor is a multi-core SoC processor.13.The robot safety control hardware platform according to any one of the preceding claims, wherein at least two cores of the control unit comprise different operation systems.14.The robot safety control hardware platform according to any one of the preceding claims, wherein at least one of the first and second processor comprises a main domain and a MCU domain.15.The robot safety control hardware platform according to any one of the preceding claims, wherein the control unit is adapted to be switched into different safety topologies based on at least one input signal.16.A robot system comprising a robot (1) and a robot safety control hardware platform according to any one of the preceding claims.17.The robot system according to claim 16, comprising at least one of a teach pendant (8) , one or more safety input devices (2) , one or more safety output devices (3) and a power unit (5) .18.A method for providing at least one robot safety control hardware platform according to any one of the preceding claims, the method comprising switching the control unit of the at least one robot safety control hardware into one of the different safety topologies.19.The method according to claim 18, comprising switching the control unit of at least one robot safety control hardware into one of the different safety topologies and switching the control unit of at least one other robot safety control hardware into another one of the different safety topologies.20.A method for operating a robot system according to claim 16 or 17, comprising controlling the robot by the control unit.
Citation Information
Patent Citations
Safety control method and device of robot, electronic equipment and readable storage medium
CN113618744A
Dynamic event triggering and quantitative control method for single-arm manipulator under multi-channel attack
CN116160455A
Robot control system and control method, electronic equipment and storage medium
CN116604588A
Apparatus for preventing inner winding part of coil from dropping
KR1020250054463A
Cooperative operation of robotic arms
US20200405417A1