A robot controller adapted for multiple simultaneous wireless connections

The robot controller with a SCM facilitates multiple secure wireless connections using shared processing and independent radio layers, addressing efficiency and security challenges in maintaining wireless links.

WO2025247478A1PCT designated stage Publication Date: 2025-12-04ABB (SCHWEIZ) AG

Patent Information

Application Number
PCT/EP2024/064561
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-28
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

State-of-the-art robot controllers face challenges in maintaining multiple wireless data links efficiently while managing increased cyber-security risks and costs, with wireless communication being complex, costly, and prone to attacks.

Method used

A robot controller equipped with a simultaneous connectivity module (SCM) that supports two or more simultaneous wireless data links using shared processing resources, independent radio technology layers, and security mechanisms, allowing flexible network configuration and enhanced security.

Benefits of technology

The SCM enables efficient, secure, and cost-effective multiple wireless connections, reducing capital and operational costs, and enhancing resilience against cyber threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024064561_04122025_PF_FP_ABST
    Figure EP2024064561_04122025_PF_FP_ABST
Patent Text Reader

Abstract

A robot controller (110) comprising processing circuitry (111) and a simultaneous connectivity module (113). The processing circuitry is configured to execute an operating system (140) and to execute software applications (140) in the operating system. The software applications include a robot control application for controlling an industrial robot (120). The SCM is configured to maintain two or more simultaneous data links (131, 132) between the processing circuitry and external entities (121, 122). For this purpose, the SCM comprises two or more radio technology layers, each having a transceiver chain and a software stack for supporting the transceiver chain, and a shared processing resource, which is operable for use in the execution of the software stacks. The processing circuitry is authorized to control the execution of each of the software stacks in the SCM.
Need to check novelty before this filing date? Find Prior Art

Description

A ROBOT CONTROLLER ADAPTED FOR MULTIPLE SIMULTANEOUS WIRELESS CONNECTIONSTECHNICAL FIELD

[0001] The present disclosure relates to the field of industrial robots. In particular, it proposes a robot controller equipped with a simultaneous connectivity module specially configured to maintain two or more simultaneous wireless data links with external entities. Network interfaces corresponding to each of the data links can be arranged in the robot controller’s operating system, and they can be allocated for data transfer relating to different functionalities, applications and services.BACKGROUND

[0002] State-of-the-art robot controllers are being designed with a growing number of wired network ports. This tendency has been spurred by long-term developments in the industry including the ever more stringent cyber-security requirements, the compelling economics of externalizing heavy computational tasks, as well as various demands from the user community for remote monitoring, remote fleet management, live visualization and similar ‘connected’ services. Common to these developments, they give rise to new data streams which cannot - or preferably should not - coexist on the same network port but need to use different network ports. A representative robot controller marketed by the applicant at the time of filing contains at least six Ethernet ports: one for local robot management, one towards a teach pendant unit, one for cameras and other peripheral devices, one towards an input / output network for programmable logic controller (PLC) communication, one gateway to integrate connected services, and one towards a factory network. A future generation of the same robot controller is expected to include an even higher number of interfaces on the central processing unit board and / or on further boards managed by the robot controller. Each of the latter four network interfaces has a dedicated purpose, e.g., toward the connected services gateway, the factory network, or a local network with a PLC, particularly a Profmet™ compatible PLC.

[0003] Parallel to this, there is a general desire to replace wired network connections with wireless connections. Straightforwardly replacing the wired network ports in a state-of-the-art robot controller with wireless equivalents one by one is apossibly working but rather costly solution. Not only is wireless communication equipment generally more complex than wired equipment, but it may also require more maintenance and active management over its active life cycle. To illustrate, the applicant’s prior application published as W02023030658A1 discloses a control network in which a processor has multiple wireless network interfaces at its disposal. The wireless network interfaces are operable to maintain physical connections to respective radio access networks. While the disclosed control network is well adapted for its intended purpose, its performance and / or economic competitiveness might not remain equally advantageous if further network interfaces are added. There is a pressure to do so in view of the long-term developments outlined above.

[0004] Another important aspect is that wireless communication, compared to wired communication, is more prone to various attacks. This is likely to introduce additional risks to the operation of industrial robots and their controllers. Such risks might stem from, e.g., “wardriving” (searching for networks with unsecured or weakly secured access), “evil twin” networking (fake network impersonating a trusted one), sniffing network traffic and connection piggybacking. In these ways, unauthorized third parties could gain access to sensitive information and intrude into factory networks and other local area networks.SUMMARY

[0005] On this background, it is an objective of the present disclosure to make available an economically attractive robot controller with an ability to maintain two or more simultaneous wireless data links. Preferably, in order to limit the capital expenditure, the workload on all or most hardware components of the operating robot controller should be sensibly even, and specialized components should be used only to a minimal extent. A further objective is to enable easy and efficient system integration, notably integration with the robot controller’s operating system. A still further objective is to enable adequate security measures, including protecting the data flows in the robot controller from attacks by malicious actors.

[0006] At least some of these objectives are achieved by the invention as defined by the independent claim. The dependent claims relate to advantageous embodiments of the invention.

[0007] In a first aspect, there is provided a robot controller comprising processing circuitry and a simultaneous connectivity module (SCM). The processing circuitry is configured to execute an operating system and to execute software applications in the operating system. The software applications include a robot control application for controlling an industrial robot. The SCM for its part is configured to maintain two or more simultaneous data links between the processing circuitry and external entities, it being understood that the physical layer of each data link includes at least one wireless segment. For this purpose, the SCM comprises two or more radio technology layers, each having a transceiver chain and a software stack for supporting the transceiver chain, and a shared processing resource, which is operable for use in the execution of the software stacks. According to the first aspect, the processing circuitry shall be authorized to control the execution of each of the software stacks in the SCM.

[0008] For the avoidance of doubt, the radio technology layers are not in a hierarchical relationship to each other. Rather, each constitutes a subsystem which carries out its assigned functions independently of the other radio technology layers. Because multiple radio technology layers have a shared processing resource at their disposal for executing the transceiver-related software stacks, the architecture of the SCM is beneficial from the point of view of resource usage. More precisely, for a representative usage pattern where each data link experiences short data bursts - generally corresponding to such periods where a corresponding software application is actively using a central processing resource - the software stacks will tend to execute in periods with a limited time overlap. The execution threads of the software stacks are unlikely to compete for the shared processing resource outside these periods.

[0009] Another advantage of the robot controller according to the first aspect is scalability: the number of simultaneous wireless data links can be easily adapted to a particular use case (provided, of course, radio resources are available), while maintaining performance and cost at a competitive level. This is possible with the evident proviso that sufficient radio spectrum is available. The adaptability would be more difficult in a robot controller where wired network ports have been replaced with wireless equivalents one by one.

[0010] In some embodiments, at least two of the radio technology layers of the SCM are configured for a common cellular or non-cellular radio access technology.Specifically, the radio technology layers which are configured for a common radio access technology can be restricted to operate in disjoint frequency bands.[oon] According to some embodiments, the operating system has a single SCM driver for controlling and / or managing the SCM. As used herein, a “driver” includes software for managing and controlling a hardware component or group of hardware components. In particular, the single SCM driver can be configured to support a single serial data bus, in particular a single high-speed serial data bus, such as one PCI-Express™ (PCIe) lane. This is in the interest of an easy and cost-efficient system integration, knowing that a conventional wireless data link not managed through an SCM would normally require a separate driver for each connectivity module, such as a separate PCIe lane. Reduced software complexity and / or reduced hardware costs can be expected. Another advantage relates to an improved flexibility of the networking configuration of the robot controller.

[0012] In some embodiments, the operating system includes two or more wireless network interfaces associated with the respective radio technology layers of the SCM. Functionally, a “network interface” is a point for handing over data between the application layer and the lower protocol layers, where “layers” now refers to hierarchical layers (de- / encapsulation layers), like those defined by the Open Systems Interconnection (OSI) model. The network interfaces can be allocated to data related to different applications or services, such as robot fleet management, visualization services, remote access, remote condition monitoring, remote fleet assessment, remote diagnostics, machine-learning based maintenance services, data-driven maintenance services, input / output signals, sensor data (including condition-driven reporting from sensors), motion control signals and feedback, safety signals (e.g., emergency signals, alarms), outgoing and incoming data to or from an external computational resource, and the like. Further, the operating system may be configured to logically isolate the two or more wireless network interfaces from one another with respect to network traffic forwarding. In other words, benefits comparable to those of the conventional structure with a number of wired network interfaces in the robot controller - with a somewhat dedicated purpose for each of them - can be obtained by purposefully using the wireless network interfaces of an SCM, notably if the wireless network interfaces are configured to match actual operational needs. This will provide more flexibility in configuring or modifying thenetwork interfaces of the robot controller; even a comparatively affordable SCM can support a significant number of interfaces, so that the system owner may decide which ones to use at the time of installation, configuration or reconfiguration.

[0013] In some embodiments, with regard to the processing circuitry’s controlling of the execution of the software stacks in the SCM, the processing circuitry is authorized to enable and disable execution of each software stack of the radio technology layers.

[0014] In some embodiments, the processing circuitry is configured to operate an endpoint of a network control interface for controlling each of the software stacks. Optionally, the software applications executed by the processing circuitry may include two or more server applications which realize said endpoint of the network control interface, wherein at least two independently configurable access-control policies apply to respective ones of said server applications. This separation of the endpoint of the network control interface into two software applications allows a system owner to set a more restrictive access-control policy for the software application which has the more crucial responsibilities and / or handles more sensitive types of data. This would not be easily achievable if the endpoint of the network control interface was realized by a single software application.

[0015] In some embodiments, each software stack of the radio technology layers is configured with an independent security mechanism, such as a mechanism compliant with WPA3, CHAP etc. Because a malicious actor normally has to break all these security mechanisms in order to gain complete access to the robot controller, his attack is all the more likely to fail than if a single security mechanism had been implemented. Particularly, in implementations where the SCM uses different parts of radio spectrum (e.g., one Wi-Fi interface over 2.4 GHz and another one over 5 GHz), it is less likely for radio-level or physical-level attacks - such as with radio jamming - to occur simultaneously on all those spectrum parts. That way, a higher resiliency to attacks can be achieved, i.e., at least one of the radio technology layers may still be available to ensure the robot controller a minimum level of connectivity.

[0016] Another possible security measure, which can be practiced in addition or alternative to the security mechanisms, is to regulate the radio transmit power of at least one of the transceiver chains in the SCM, for thereby limiting radio signal propagation outside a preconfigured area of operation of the robot controller.

[0017] To respond to demands for even more numerous data links, it is envisaged to use multiple parallel SCMs in the robot controller. In particular, each SCM can be configured for a different cellular or non-cellular radio access technology. Each SCM can be managed by a single SCM driver.

[0018] In a second aspect, there is provided a robot system comprising one or more industrial robots, auxiliary equipment for assisting said one or more industrial robots in carrying out a utility task, and a robot controller with the features of the first aspect. Here, the SCM of the robot controller is configured to maintain two or more simultaneous data links between the processing circuitry and the auxiliary equipment.

[0019] In the terminology of the present disclosure, “industrial robot” is used in a broad sense, to cover in particular manufacturing robots, material-handling robots, assembly robots, cutting / welding robots, service robots, collaborative robots, hygiene robots, industrial robot tracks, industrial robot positioners. An industrial robot may be a stationary robot or a mobile robot, such as an automated guided vehicle (AGV), an autonomous mobile robot (AMR) or an autonomous mobile manipulator robot (AMMR).

[0020] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to “a / an / the element, apparatus, component, means, step, etc.” are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any method described herein do not have to be performed in the exact order disclosed, unless this is explicitly stated.BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Aspects and embodiments are now described, by way of example, with reference to the accompanying drawings, on which: figure 1 is a block diagram showing a robot controller with an SCM, according to embodiments herein; figure 2 is a detailed view of the SCM in figure 1;figure 3 illustrates a robot controller equipped with multiple SCMs, according to embodiments herein; and figure 4 is a sequence diagram illustrating an example exchange between a robot controller according to embodiments herein, a network management process and two software applications constituting endpoints of a network control interface adapted for controlling software stacks in the SCM.DETAILED DESCRIPTION

[0022] The aspects of the present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, on which certain embodiments of the invention are shown. These aspects may, however, be embodied in many different forms and should not be construed as limiting; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and to fully convey the scope of all aspects of the invention to those skilled in the art. Like numbers refer to like elements throughout the description.

[0023] Figure 1 shows, in block diagram form, a robot controller no suitable for use with an industrial robot 120. The industrial robot 120 and the robot controller 110 are joined by a bidirectional data connection 130, which conveys control signals, sensor data etc. As suggested in figure 1, the industrial robot 120 may for example include an arm (manipulator), which extends from a stationary or movable base, and which is made up of structural elements and at least one linear or rotary joint. The arm may further carry tools that allow it to interact with various workpieces, which are present in a work area of the industrial robot 120. The workpieces are subject to manufacturing, processing or handling by the industrial robot 120. The work area may further include additional objects, such as containers, fixtures, separators, insulators, supports etc.; these objects maybe generic or maybe specifically adapted to the workpieces handled by the industrial robot 120. The work area may in particular include auxiliary equipment for assisting the industrial robot 120 in carrying out a utility task. The auxiliary equipment may for example be a workpiece positioner 122, as depicted in figure 1. The arm of the industrial robot 120 is movable by action of internal motors, drives or actuators (not shown), and it includes transducers, sensors and other measuring equipment, from which the arm’s current position, pose, technical condition, load etc. can be derived, to some degree ofaccuracy. The position, pose etc. of the industrial robot 120 may in particular refer to a point on the arm, particularly to a tool-center point (TCP).

[0024] An industrial robot system 100 in the sense of the present disclosure may comprise one or more industrial robots 120 and one or more robot controllers no, and it may optionally comprise the auxiliary equipment.

[0025] The example robot controller no in figure 1 comprises a central processing unit (processing circuitry; CPU) 111, a simultaneous connectivity module (SCM) 113, as well as wired network interface 144. The processing circuitry 111 is configured to execute an operating system (OS) 140. Within the OS 140, the processing circuitry 111 enables the executing of at least one wireless network interface 141, wired network interface 144, an SCM driver 142 and other hardware drivers, as well as software applications 143. Software processes execute in an OS in the sense that the OS acts as an intermediary for accessing storage and processing resources, including such resources offered by the processing circuitry 111 of the robot controller no.

[0026] The software applications 143 include a robot control application for controlling the industrial robot 120, in accordance with the performing of useful tasks or other behaviors programmed by an operator or a system owner. A robot program may include a plurality of movement instructions relating to locations, such as points, poses, paths or modulated paths. A program may be a compiled executable (a binary) or a script. A movement instruction relating to a modulated path may be expressed as - or may include - a process-on-path instruction. The robot programs may be created by an operator with the aid of a robot programming device (programming station, teach pendant) or a general-purpose computer, or they may be created directly at the robot controller no if it has an operator interface (not shown). In the first two cases, versions of the robot programs may be downloaded to the robot controller 110 over a wired or wireless connection or by being temporarily stored on a portable memory.

[0027] The CPU 111 may have access to further resources, including basic settings, software implementing generic movements, sensing, self-monitoring, generically useful functionalities and services (all typically contributed by an original manufacturer), task- or role-specific configurations, configuration templates (typically contributed by a robot system integrator), and site-specific settings (typically contributed by the operator). These further resources may be offered by asoftware library or dedicated robotics middleware, such as the open-source Robot Operating System (see www.ros.org), which is to be used in conjunction with the generic OS 140, or the applicant’s library RobotWare™.

[0028] The SCM 113 is configured to maintain two or more simultaneous data links 131, 132 between the processing circuitry and various entities which are external to the robot controller no. Each data link 131, 132 includes at least one wireless link segment, in addition to any wired link segment(s). The external entities may include:- a fleet management system,- a host computer 121 offering connected services or cloud solutions, which may include server, storage and / or auxiliary processing resources,- an edge / cloud platform,- a wireless teach pendant or another human-machine interface for use by an operator,- another industrial robot, such as a stationary industrial robot or a mobile industrial robot, or even a robot controller associated with said other industrial robot,- the auxiliary equipment in the work area discussed above.The inventors foresee that a wireless data link may not be the preferred medium for communications between the robot controller no and its associated industrial robot 120; for that purpose, a wired data link 130 is more likely to meet typical requirements on latency and bandwidth.

[0029] As shown in more detail in figure 2, the SCM 113 comprises two or more radio technology layers 210. Each radio technology layer 210 consists, in general terms, of hardware and software for maintaining a data link 131, 132 between the processing circuitry 111 and an entity external to the robot controller no. For this purpose, it comprises a transceiver chain 213 and a software stack 212 for supporting the transceiver chain. Each transceiver chain 213 includes a radio front end and baseband circuitry, and it is associated with an antenna arrangement 214. Each software stack 212, which maybe stored in a suitable memory 211 in the radio technology layer 210, is configured for one or more of the following functionalities relating to the radio technology layers:- control functionalities,- signal processing functionalities,- assistance functionalities,- supervisory functionalities.The software stacks 212 can be executed by a shared processing resource (processing circuitry) 220, which is at the disposal of all radio technology layers 210 in the SCM 113. By allocating the respective radio technology layers 210 to different responsibilities (e.g., transfer of data relating to different applications or services), the occurrence of collision periods in which two or more radio technology layers 210 need to utilize the shared processing resource 220 can be made relatively rare. This will be discussed in detail below, in connection with the wireless network interfaces 141 in the OS 140.

[0030] The following example products available at the time of filing may be considered to be a Wi-Fi-enabled SCM 113 in the sense of the present disclosure: UBlox JODY-W3 module, AzureWave AW-XM458 module based on an NXP 88W9098 chip, Quectel FC6xE module, Voxmicro AIRETOS E20 module based on a Qualcomm QCA206X chips, Renesas CL8000 chips. Further, the following example products available at the time of filing maybe said to constitute a cellular-enabled SCM 113: MediaTek M80, Cradlepoint 1200M-B.

[0031] In some implementations of the SCM 113, each software stack 212 of the radio technology layers 210 is configured with an independent security mechanism. The security mechanisms may be compliant with one or more of:- Wi-Fi Protected Access 3 (WPA3),- Wi-Fi Protected Access 2 (WPA2), preferably with Advanced EncryptionStandard (AES),- Challenge Handshake Authentication Protocol (CHAP),- Password Authentication Protocol (PAP).The third and fourth options can be used with a cellular SCM 113. In addition, if the SCM 113 is 3GPP LTE-compliant, it supports the so-called 4G Evolved Packet System Authentication and Key Agreement (EPS-AKA). For 3GPP NR, the so-called Extensible Authentication Protocol - Transport Layer Security (EAP-TLS) method isrecommended, as its model of trust between a client device and the network is based on (non-cellular-specific) public key infrastructure.

[0032] As a possible further security measure, which may be practiced in some embodiments, the SCM 113 is configured to regulate a radio transmit power of at least one of the transceiver chains 213 in such manner that radio signal propagation outside a preconfigured area of operation is limited. An advantage of these embodiments, if the area is configured consistent with the extent of a facility (e.g., a plant, factory premises, a logistics center) to which physical access is restricted, the transmit power regulation stops or hinders such digital attacks on the robot controller no which are attempted by parties outside this facility; these attacks could include network wardriving, evil twin networking, network traffic sniffing or connection piggybacking, all described above. The transmit power regulation may aim to limit the radiated power outside the facility so that the radiated power stays below a threshold value that normally does not allow reliable reception, while still providing sufficient transmit power to legitimate communication parties inside the facility. The transmit power regulation may take into account known radiated emission patterns of directional and non-directional antennas and / or local transmit power measurements away from the robot controller no.

[0033] Turning now to certain system integration aspects, it may be advantageous in some use cases for the robot controller no to run an operating system 140 with a single SCM driver 142, which is configured to control and / or manage the SCM 113. The SCM driver 142 maybe constituted by an executing software process. The SCM driver 142 may be configured to support a single high-speed serial data bus. It is understood that a serial data bus is configured to convey a single data stream, e.g., as obtained by multiplexing a plurality of data sub-streams into one. In particular, the SCM driver 142 may be implemented based on a driver compliant with the PCI- Express™ (PCIe) standard, such as PCIe version 4.0 or higher. In particular, the SCM driver 142 may be implemented by adapting a driver with a single PCIe lane.

[0034] For any number of SCM drivers 142 used in the OS 140, including the preferred choice of a single SCM driver 142, the OS 140 further includes two or more wireless network interfaces 141 which are associated with the respective radio technology layers 210 of the SCM 113. Each network interface 141 functionally acts as a point for handing over incoming or outgoing data between the OSI application layerand the lower protocol layers, at which (de)encapsulation according to the applicable communication protocols may take place. The respective network interfaces 141 may be allocated to transfer data related to specific applications or services, and may thus enable the system designer to separate data streams as desired. In particular, the system designer could make use of this ability for the purpose of separating such data streams which should not use a common network port, as discussed initially. For example, the OS 140 may include two or more of the following:- a wireless network interface 141 allocated to transfer data related to connected services;- a wireless network interface 141 allocated to transfer data related to robot fleet management;- a wireless network interface 141 allocated to transfer data related to visualization services;- a wireless network interface 141 allocated to transfer data related to remote access, remote condition monitoring, remote fleet assessment and / or remote diagnostics;- a wireless network interface 141 allocated to transfer data related to machinelearning based maintenance services and / or data-driven maintenance services;- a wireless network interface 141 allocated to transfer input / output signals;- a wireless network interface 141 allocated to transfer sensor data, including condition-driven reporting by sensors, by which a sensor value is reported only if it exceeds a preconfigured normal operating range, and / or the sensor value is reported only if it exhibits a preconfigured time evolution;- a wireless network interface 141 allocated to transfer motion control signals and motion feedback;- a wireless network interface 141 allocated to transfer safety signals;- a wireless network interface 141 allocated to transfer outgoing and incoming data to or from an external computational resource 121.As mentioned above, the respective radio technology layers 210 can be allocated to different responsibilities, such that the occurrence of collision periods in which twoor more radio technology layers 210 compete for the shared processing resource 220 are relatively rare. For example, time-critical application / service (e.g., safety signals, motion control and motion feedback) and an application / service which is normally not time-critical (e.g., robot fleet management, remote diagnostics) can usually coexist as beneficiaries of the same SCM 113 with a single shared processing resource 220.

[0035] In some embodiments, the OS 140 logically isolates the two wireless network interfaces 141 from one another with respect to network traffic forwarding. The effect may be to inhibit or block the forwarding of network traffic between network interfaces 141. For example, assuming that a first network interface 141 is used by the robot controller no to communicate with a remote fleet manager and a second network interface 141 is used for communicating with a connected services host computer, then, if the robot controller 110 receives any network traffic on the second network interface 141, it will under no circumstances forward that traffic to the first network interface 141, and vice versa. This way, network traffic arriving at the robot controller no from a public communication network cannot be used for attempting a data breach (attack) into an on-premises, private communication network. The non-forwarding behavior, with which the OS 140 is configured in these embodiments, may act as an additional security layer.

[0036] In its various further embodiments, the SCM 113 may comprise at least two radio technology layers 210 which are configured for a common cellular radio access technology (RAT) or for a common non-cellular RAT. Example RATs include 3GPP LTE / 4G, 3GG NR / 5G and various releases of IEEE 802.11, such as Wi-Fi™ 6 / 5 / 4- In some embodiments, at least two of the radio technology layers 210 are configured for a common RAT, and they are restricted to operate in disjoint frequency bands, such as one Wi-Fi interface in a 2.4 GHz band and another one operating in a 5 GHz band. Alternatively, the radio technology layers 210 of the SCM 113 maybe configured for different RATs.

[0037] Figure 3 illustrates an embodiment of the robot controller no, where it comprises multiple SCMs 113. In this embodiment, there is one SCM 113a configured to maintain three simultaneous wireless data links supported by a first RAT, and one SCM 113b configured to maintain two simultaneous wireless data links supported by a second RAT. The further technical aspects of this robot controller 110 maybeimplemented in accordance with the general description herein and / or in accordance with the explanations relating to the robot controller no depicted in figure i. In some embodiments of the multi-SCM robot controller no in figure 3, the OS 140 has a single SCM driver 142 for each SCM 113.

[0038] Resuming the description of the robot controller 110 depicted in figure 1, the processing circuitry 111 is authorized to control the execution of each of the software stacks 212. In some embodiments of the robot controller 110, the processing circuitry 111 is authorized to enable and disable execution of each software stack 212 of the radio technology layers 210. This faculty may be used to economize processing power by disabling one or more of the wireless data links 131, 132 in periods where they are not actively used.

[0039] To exercise this control over the execution of the software stacks 212, the processing circuitry 111 in some embodiments uses a network control interface, which is here exemplified by an Application Programming Interface (API) termed NetCon 150. The NetCon API comprises, at least, requests to enable / disable SCM stacks 212, to read / write their configurations, and to retrieve performance information. In a Wi-Fi-based SCM 113, the following configuration parameters (and possible further ones) maybe provided for the stacks via the NetCon API: operation state, identifier of the network to connect to, network security mechanism, and security key. Similarly, if robot controllers integrate cellular based SCMs, the NetCon API allows, for example, the following minimum configuration set: operation state, PIN number, identifier of the network to connect to, and username / password for connecting. Different frameworks and protocols can be used to realize the NetCon API, for example, Representational state transfer (REST) with HTTP or HTTP Secure (HTTPS), or the OpenAPI specification. As a possible implementation, the NetCon API is a RESTful API and makes use of protocol HTTP or HTTPS and the JSON data format.

[0040] In these embodiments, a first endpoint of the NetCon API 150 is operated by the processing circuitry 111 and a second endpoint by the shared processing resource 220 in the SCM 113. The first endpoint of the NetCon API 150 maybe realized by two or more server applications (or servers) 151, 152 executing on the processing circuitry 111. This allows the system owner to configure an equal number of independently configurable access-control policies, which apply to respective ones of said server applications. As a result, the system owner may achieve goodusability / convenience without sacrificing the degree of data security. To illustrate, it is assumed that the server applications include:- a first server application, NetConFig 151 configured to respond to one or more of: requests to read capability information relating to the SCM 113, requests to enable or disable execution of a software stack 212, requests to read a configuration of a software stack, requests to write a configuration of a software stack; and- a second server application, NetConMon 152 configured to respond to requests to read performance information for a software stack.For these server applications, the system owner may configure a more restrictive access-control policy which applies to NetConFig 151, and a less restrictive accesscontrol policy which applies to NetConMon 152. Alternatively, the system owner may configure a first access-control policy which prohibits remote access and applies to NetConFig 151, and a second access-control policy which permits remote access and applies to NetConMon 152. In other words, the NetConFig server 151 is accessible only through an Ethernet port of the robot controller no for local robot management and is assigned a private IP address (e.g., 192.168.1.1). If the NetCon API is RESTful, then NetConFig may use HTTP instead of HTTPS. On the other hand, the NetConMon server 152 maybe accessed through other (wireless) network interfaces of the robot controller no (e.g., for the fleet management purposes). If the NetCon API 150 is RESTful, a NetConMon implementation employs HTTPS running over the TLS protocol. This way, client authenticity, data privacy and data integrity are upheld when communicating with the NetConMon server 152, also when the server is accessed during use of wireless connectivity.

[0041] Figure 4 is a sequence diagram illustrating an example exchange taking place among the following entities:- the processing circuitry 111 of a robot controller no according to embodiments herein,- a network management process in the OS 140, and- the NetConFig 151 and NetConMon 152 servers.The example exchange includes messages with the following content:Mi Fetch SCM capabilities (dashed arrow below indicates response)M2 Read SCM capabilities (dashed arrow below indicates response)M3 Write SCM configurationM4 Forward SCM configurationM5 Enforce SCM configurationM6 Connectivity establishedM7 Connectivity establishedM8 Fetch SCM performanceM9 Read performance for all SCM stacks (dashed arrow below indicates response)Mio Write new SCM configurationMil Forward new SCM configurationM12 enforce new SCM configurationM13 Connectivity re-establishedM14 Connectivity re-establishedHere, reference 410 represents a phase where a configuration is defined which enables the software stacks 212 in the SCM 113. Reference 411 indicates a condition where the software stacks 212 in the SCM driver 142 are up and running. Reference 412 indicates a condition where wireless network interfaces 141 in the OS 140 are connected to a given network. Reference 420 indicates a phase of requesting a performance report for all software stacks 212 in the SCM 113. Reference 430 indicates a phase of requesting the software stack 212 to connect to another network, assuming this is needed for operational reasons or because the quality of service of the existing network is deteriorating. Reference 431 finally indicates a condition where the wireless network interface 141 in the OS 140 has been reconnected.

[0042] Depending on the specific SCM implementation, when reading SCM capabilities, NetConFig 151 provides at least this information:- the number of wireless stacks (e.g., ‘wireless stack 1’ and ‘wireless stack 2’);- wireless technology type and its standardso (e.g., ‘wireless stack i: wi-fi 6 / 5 / 4’ and ‘wireless stack 2: wi-fi 5 / 4’, or o ‘wireless stack 1: 5g / nr’ and ‘wireless stack 2: lte / 4g’);- supported radio channels o (e.g., ‘wireless stack 1: 2.4 ghz [1-13], 5 ghz [36-169], 6 ghz [5-229]’ and ‘wireless stack 2: 2.4 ghz [1-13], 5 ghz [36-169]’, or o ‘wireless stack 1: fr2 [n257, n258, n26i]’ and ‘wireless stack 2: [bi- b43]’); and- security mechanisms o (e.g., ‘wireless stack 1: wpa3 wpa2 wpa’ and ‘wireless stack 2: wpa3 wpa2 wpa’, or o ‘wireless stack 1: pap chap’ and ‘wireless stack 2: pap chap’).(Throughout, the values in round brackets are example values for the purpose of illustration.) When writing configuration of an SCM stack, values of the following example set of parameters may be specified:- Wi-Fi based SCM, o ‘wireless stack 1: state = enable, role = client, network = fleet_management-6_ghz, security = auto, key = unbreakablei2345, power_management = ieee_power_save‘; o ‘wireless stack 2: state = enable, role = client, network = connected_services-2.4_ghz, security = wpa3-personal, key = unbreakable6789, power_management = ieee_power_save‘;- or cellular based SCM, o ‘wireless stack 1: state = enable, role = client, pin = 2058, operator = telia, network = fleet_management_apn, security = auto, username = controller, password = unbreakablei23456789, roaming = enable4; o ‘wireless stack 2: state = enable, role = client, pin = 1739, operator = telia, network = connected_services_apn, security = chap, username = , password = , roaming = enable4.By fetching performance summary for an SCM stack, this information could be given:- Wi-Fi based SCM, o ‘wireless stack i: state = connected, role = client, network = fleet_management-6_ghz, standard = wi-fi 6, band = 6 ghz, channel = 75, security = wpa3-personal, connection_quality = excellent, connection_speed = 100 mbps4; o ‘wireless stack 2: state = connected, role = client, network = connected_services-2.4_ghz, standard = wi-fi 5, band = 2.4 ghz, channel = 6, security = wpa3-personal, connection_quality = good, connection_speed = 40 mbps4;- or cellular based SCM, o ‘wireless stack 1: state = connected, role = client, operator = telia, network = fleet_management_apn, standard = 5g, security = chap, connection_quality = excellent, connection_speed = 150 mbps4; o ‘wireless stack 2: state = connected, role = client, operator = telia, network = connected_services_apn, standard = 4g, security = chap, connection_quality = excellent, connection_speed = 50 mbps4.It is understood that the sequence shown in figure 4 could represent a brief runtime period of the robot controller no. However, the server applications 151, 152 could also experience relatively long periods of low or no activity while the robot controller 110 operates.

[0043] To summarize, the present disclosure has described- A robot controller architecture with secure shared wireless networkingRobot controllers offer the capability to simultaneously connect to two (or more) wireless networks, while capital costs regarding wireless networking are contained.Applied security measures mitigate risks from using wireless connectivity.- A network connectivity API with an easy-to-manage-wireless approachThe API provides a basic set of configuration and monitoring features, while encapsulating many wireless technology specifics.Proposed API design enables a flexible implementation in robot controllers.- Ways of dynamically or semi-statically adapting communication resources to suit robotics needsWireless connectivity modules can be reconfigured for different communication purposes, whereby robot controller do not need dedicated network interfaces / ports.This may allow capital costs with respect to wireless networking in robot controllers to be controlled, as well as operating costs regarding their maintenance and management. The described solutions may act as a networking facilitator for novel mobile robot applications, such as around a collaborative task execution.

[0044] The aspects of the present disclosure have mainly been described above with reference to a few embodiments. However, as is readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the invention, as defined by the appended patent claims.

Claims

CLAIMS1. A robot controller (no) comprising: processing circuitry (in), which is configured to execute an operating system (140) and to execute software applications (143) in the operating system, including a robot control application for controlling an industrial robot (120); and a simultaneous connectivity module, SCM (113), which is configured to maintain two or more simultaneous data links (131, 132) between the processing circuitry and external entities (121, 122), the SCM comprising:- two or more radio technology layers (210), each having a transceiver chain (213) and a software stack (212) for supporting the transceiver chain; and- a shared processing resource (220), which is operable for execution of the software stacks, wherein the processing circuitry is authorized to control the execution of each of the software stacks.

2. The robot controller (110) of claim 1, wherein at least two of the radio technology layers (210) of the SCM (113) are configured for a common cellular or non-cellular radio access technology.

3. The robot controller (110) of claim 2, wherein said at least two of the radio technology layers (210), which are configured for a common cellular or non-cellular radio access technology, are restricted to operate in disjoint frequency bands.

4. The robot controller (110) of any of the preceding claims, wherein the operating system (140) includes a single SCM driver (142) for controlling and / or managing the SCM (113).

5. The robot controller (110) of claim 4, wherein the single SCM driver (142) is configured to support a single high-speed serial data bus.

6. The robot controller (110) of any of the preceding claims, wherein the operating system (140) includes two or more wireless network interfaces (141) associated with the respective radio technology layers (210) of the SCM (113).

7. The robot controller (110) of claim 6, wherein the operating system (140) includes at least two of the following:a wireless network interface (141) allocated to transfer data related to connected services; a wireless network interface allocated to transfer data related to robot fleet management; a wireless network interface allocated to transfer data related to visualization services; a wireless network interface allocated to transfer data related to remote access, remote condition monitoring, remote fleet assessment and / or remote diagnostics; a wireless network interface allocated to transfer data related to machine-learning based maintenance services and / or data-driven maintenance services; a wireless network interface allocated to transfer input / output signals; a wireless network interface allocated to transfer sensor data; a wireless network interface allocated to transfer motion control signals and feedback; a wireless network interface allocated to transfer safety signals; a wireless network interface allocated to transfer outgoing and incoming data to or from an external computational resource.

8. The robot controller (110) of claim 6 or 7, wherein the operating system (140) is configured to logically isolate the two or more wireless network interfaces (141) from one another with respect to network traffic forwarding.

9. The robot controller (110) of any of the preceding claims, wherein the processing circuitry (111) is authorized to enable and disable execution of each software stack (212) of the radio technology layers (210).

10. The robot controller (110) of any of the preceding claims, wherein the processing circuitry (111) is configured to operate an endpoint of a network control interface (150) for controlling each of the software stacks (212).

11. The robot controller (110) of claim 10, wherein the software applications (143) executed by the processing circuitry (111) include two or more server applications (151, 152) which realize said endpoint of the network control interface (150), whereinat least two independently configurable access-control policies apply to respective ones of said server applications.

12. The robot controller (no) of claim n, wherein said server applications include:- a first server application (151) configured to respond to one or more of: requests to read capability information relating to the SCM (113), requests to enable or disable execution of a software stack (212), requests to read a configuration of a software stack, requests to write a configuration of a software stack; and- a second server application (152) configured to respond to requests to read performance information for a software stack, and wherein a more restrictive access-control policy applies to the first server application than to the second server application.

13. The robot controller (no) of claim 11, wherein said server applications include:- a first server application (151) configured to respond to one or more of: requests to read capability information relating to the SCM (113), requests to enable or disable execution of a software stack (212), requests to read a configuration of a software stack, requests to write a configuration of a software stack; and- a second server application (152) configured to respond to requests to read performance information for a software stack, and wherein a first access-control policy, which prohibits remote access, applies to the first server application and a second access-control policy, which permits remote access, applies to the second server application.

14. The robot controller (no) of any of the preceding claims, wherein each software stack (212) of the radio technology layers (210) is configured with an independent security mechanism.

15. The robot controller (no) of claim 14, wherein the security mechanisms of said software stacks (212) are compliant with one or more of:Wi-Fi Protected Access 3, WPA3; Wi-Fi Protected Access 2, WPA2; Challenge Handshake Authentication Protocol, CHAP; Password Authentication Protocol, PAP.

16. The robot controller (no) of any of the preceding claims, wherein the robot controller (no) comprises at least two SCMs (113), each of which is configured for a different cellular or non-cellular radio access technology.

17. The robot controller (no) of any of the preceding claims, wherein the SCM (113) is configured to regulate a radio transmit power of at least one of the transceiver chains (213), for thereby limiting radio signal propagation outside a preconfigured area of operation.

18. The robot controller (no) of any of the preceding claims, wherein each software stack (212) of the radio technology layers (210) is configured for one or more of the following functionalities relating to the radio technology layers: control functionalities, signal processing functionalities, assistance functionalities, supervisory functionalities.

19. The robot controller (no) of any of the preceding claims, wherein each transceiver chain (213) includes a radio frontend and baseband circuitry, and is associated with an antenna arrangement (214).

20. An industrial robot system (100) comprising: one or more industrial robots (120); auxiliary equipment (122) for assisting said one or more industrial robots in carrying out a utility task; and the robot controller (no) of any of the preceding claims, wherein the SCM (113) of the robot controller is configured to maintain two or more simultaneous data links between the processing circuitry and the auxiliary equipment.

Citation Information

Patent Citations

  • An automation network with actively managed redundant connectivity

    WO2023030658A1

  • Technique for Reliable Communication in a Cloud Robotics System

    US20200187286A1

  • Replication in a Wireless Communication Network

    US20230319625A1

Cited By

  • Wireless programming device for use with an industrial controller

    WO2026158785A1