Support device, support method, and program
The support device simplifies safety design compliance by integrating risk assessment and safety-related part configuration, allowing users to easily manage and document compliance with manufacturing equipment standards.
Patent Information
- Application Number
- PCT/JP2025/025962
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-02
- Filing Date
- 2025-07-22
- Publication Date
- 2026-02-05
AI Technical Summary
Manufacturing equipment safety design compliance with standards like ISO 12100 and IEC 61508 requires specialized knowledge and time-consuming documentation, and existing support devices like JP 2009-37520 do not adequately address compatibility issues and information management for risk reduction measures.
A support device and method that includes a first generation unit for risk assessment, a second generation unit for safety-related part configuration, and a management unit to associate and manage information, providing user interfaces for easy checking and documentation of compliance, including risk assessment sheets and safety device configurations.
Facilitates easy compliance checking and documentation, enabling users to efficiently manage safety design information and demonstrate compliance with standards, reducing the need for specialized knowledge and time.
Smart Images

Figure JP2025025962_05022026_PF_FP_ABST
Abstract
Description
Support device, support method, and program
[0001] The present disclosure relates to a support device, a support method, and a program that support the safety design of a target device.
[0002] Various types of manufacturing equipment are in operation at manufacturing sites. Manufacturing equipment can contain hazards that can cause harm (injury). Therefore, various safety standards have been established to prevent such hazards. For example, the International Organization for Standardization (ISO) has established ISO 12100 (Safety of machinery - General principles for design - Risk assessment and risk reduction) as a safety standard. The International Electrotechnical Commission has also established IEC 61508 (Functional safety of electrical / electronic / programmable electronic safety-related systems). Generally, manufacturers of manufacturing equipment design their equipment to comply with safety standards, and then obtain certification of compliance from a third-party certification body or self-declare that compliance is non-existent.
[0003] Safety design based on safety standards requires specialized knowledge of safety. Furthermore, creating technical documentation to prove compliance and communicating with third-party certification bodies takes time. For this reason, devices to support safety design have been developed. For example, Japanese Patent Laid-Open Publication No. 2009-37520 (Patent Document 1) discloses a consulting device that can select appropriate risk reduction measures depending on the status of hazards.
[0004] JP 2009-37520 A
[0005] The consulting device disclosed in Patent Document 1 creates a risk assessment sheet that includes risk reduction measures selected according to the status of the hazard. However, to prove that there are no compatibility issues, not only the risk assessment sheet but also information on safety-related parts that embodies risk reduction measures according to the risk level is required. Therefore, the user must link a wide range of device design documents to demonstrate compatibility.
[0006] The present disclosure has been made in consideration of the above-mentioned problems, and its purpose is to provide a support device, a support method, and a program that can provide an environment in which users can easily check information related to safety design.
[0007] According to an example of the present disclosure, a support device that supports safety design of a target device includes a first generation unit, a second generation unit, and a management unit. The first generation unit generates first information including results of a risk assessment for each of one or more hazards included in the target device based on input to a first user interface including a first set of questions according to the risk assessment. The second generation unit generates second information indicating the device configuration and wiring of a safety-related part for each of the one or more hazards based on input to a second user interface for supporting the implementation of risk reduction measures. The management unit manages the first information and the second information in association with each other for each of the one or more hazards.
[0008] According to this disclosure, a user can easily check the results of a risk assessment for each of one or more hazards, as well as the device configuration and wiring of safety-related parts. In this way, the support device can provide an environment in which a user can easily check information related to safety design.
[0009] In the above disclosure, the support device further includes an output unit that outputs a first document representing first information corresponding to each of the one or more sources of hazard and a second document representing second information corresponding to each of the one or more sources of hazard.
[0010] According to this disclosure, the user can use the first document and the second document as documents to be submitted to a third-party certification body to prove that there are no problems with compliance with safety standards.
[0011] In the above disclosure, the first group of questions includes questions regarding a plurality of required items required by a safety standard. The first generator generates first information in response to obtaining answers to all of the required items. The first information includes answers to all of the required items.
[0012] According to this disclosure, a user can easily answer multiple required items required by the safety standard. Furthermore, by checking the first information, the user can easily make a self-declaration or have an evaluation by a third-party certification body based on the content required by the safety standard.
[0013] In the above disclosure, the support device further includes a determination unit that determines a performance level of the safety-related unit based on input to a third user interface including an index (e.g., DC (Diagnostic Coverage)) that evaluates the reliability of each safety device included in the safety-related unit and a second group of questions regarding the operating status. The first generation unit determines a required performance level for each of the one or more hazards based on the input to the first user interface. The first information includes the required performance level, the performance level, and a determination result indicating whether the performance level satisfies the required performance level.
[0014] According to this disclosure, a user can easily check whether the performance level of the safety-related part satisfies the required performance level by checking the first information.
[0015] In the above disclosure, the second user interface includes a fourth user interface that prompts the user to select a plurality of safety devices that constitute the safety-related part from a plurality of candidate safety devices, and a fifth user interface that prompts the user to select a terminal pair to be connected from a plurality of terminals included in the plurality of safety devices.
[0016] According to this disclosure, a user can easily select a plurality of safety devices that constitute a safety-related part and easily design wiring.
[0017] In the above disclosure, the support device further includes an output unit that provides a sixth user interface in response to selection of a target hazard from among the one or more hazards, the sixth user interface displaying first information corresponding to the target hazard and second information corresponding to the target hazard.
[0018] According to this disclosure, the user can easily check the first information and the second information for each hazard.
[0019] In the above disclosure, the support device further includes an output unit that provides a seventh user interface in response to selection of the target safety device, the seventh user interface displaying second information corresponding to the target safety-related part including the target safety device and first information corresponding to the target hazard, among one or more hazards, whose risk is reduced by the target safety-related part.
[0020] According to this disclosure, for each safety device, the user can easily check the equipment configuration and wiring of the safety-related part including the safety device, and the risk assessment results for the hazard sources whose risks are reduced by the safety-related part including the safety device.
[0021] According to one example of the present disclosure, a support method for supporting safety design of a target device includes: i) one or more processors generating, for each of one or more hazards included in the target device, first information including results of conducting a risk assessment based on input to a first user interface including a first set of questions according to the risk assessment; ii) the one or more processors generating, for each of the one or more hazards, second information indicating the equipment configuration and wiring of a safety-related part based on input to a second user interface for supporting the implementation of risk reduction measures; and iii) the one or more processors managing, in association with each other, the first information and the second information for each of the one or more hazards.
[0022] According to yet another example of the present disclosure, a program causes a computer to execute the support method. Based on these disclosures, the support method and program can also provide an environment in which a user can easily check information related to safety design.
[0023] According to the present disclosure, the support device, support method, and program can provide an environment in which a user can easily check information related to safety design.
[0024] 1 is a diagram schematically illustrating an example of a system including a support device according to an embodiment. FIG. 1 is a diagram illustrating an example of a hardware configuration of the support device. FIG. 2 is a diagram illustrating an example of a functional configuration of the support device. FIG. 3 is a flowchart illustrating an example of a processing flow of the support device. FIG. 4 is a diagram illustrating an example of a user interface showing a result of determining restrictions on a target device. FIG. 5 is a flowchart illustrating an example of a subroutine of step S2 shown in FIG. 4. FIG. 6 is a diagram illustrating an example of a user interface including a group of questions regarding a hazardous situation. FIG. 7 is a diagram illustrating an example of a pull-down menu for each question for identifying a hazard source. FIG. 8 is a diagram illustrating an example of a pull-down menu for elements constituting a risk. FIG. 9 is a diagram illustrating an example of a method for calculating a risk level. FIG. 10 is a diagram illustrating a method for calculating a required performance level PLr. FIG. 11 is a diagram illustrating an example of a user interface that can be provided to a terminal in step S24. FIG. 12 is a diagram illustrating an example of a user interface including a group of questions regarding risk reduction measures. FIG. 13 is a diagram illustrating an example of a data set for creating a risk assessment sheet. FIG. 14 is a diagram illustrating an example of a user interface provided to a terminal in step S27. FIG. 15 is a flowchart illustrating an example of a subroutine of step S3 shown in FIG. 4. FIG. 16 is a diagram illustrating an example of a user interface prompting selection of safety devices. FIG. 17 is a diagram illustrating an example of a pop-up window prompting selection of safety devices. FIG. 18 is a diagram illustrating an example of a user interface that supports wiring. FIG. 19 is a diagram illustrating an example of a wiring diagram. FIG. 19 is a diagram illustrating an example of a block diagram. FIG. 19 is a flowchart illustrating an example of a subroutine of step S4 shown in FIG. 4 is a diagram showing an example of a user interface including an index for evaluating the reliability of each safety device and a group of questions regarding the operating status. FIG. 5 is a diagram showing an example of a user interface for checking a plurality of confirmation items regarding resistance to CCF. FIG. 6 is a diagram showing an example of a user interface showing the evaluation results of the performance level PL. FIG. 7 is a flowchart showing an example of a subroutine of step S5 shown in FIG. 4. FIG. 8 is a diagram showing an example of a user interface for prompting input of values of elements that constitute the risk when a safety measure is implemented by a safety-related unit. FIG. 9 is a diagram showing an example of a user interface showing the risk level and acceptability when a safety measure is implemented by a safety-related unit.10 is a diagram illustrating a second process of step S7. FIG. 11 is a diagram illustrating a third process of step S7. FIG. 12 is a diagram illustrating an example of a user interface including a truth table. FIG.
[0025] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present disclosure will be described in detail with reference to the accompanying drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals and the description thereof will not be repeated.
[0026] §1 Application Example Fig. 1 is a diagram illustrating a typical example of a system including a support device according to an embodiment. The system shown in Fig. 1 includes a support device 100 and a terminal 200.
[0027] The support device 100 supports a user in designing a safety target device. The target device is a device that includes one or more hazards that may cause harm, such as manufacturing equipment. Users primarily include, but are not limited to, electrical design engineers. The one or more hazards may include, for example, a rotating mechanism, a heating device, etc.
[0028] The support device 100 can be realized as one or more computers, a virtual machine built in a cloud environment, or a combination of these. In the example shown in Fig. 1, the support device 100 is a cloud server that provides a tool related to safety design (hereinafter referred to as a "safety design tool") as SaaS (Software as a Service).
[0029] The terminal 200 is connected to the support device 100 via a network and uses a safety design tool provided by the support device 100. The terminal 200 is, for example, a notebook or desktop personal computer (PC), a tablet terminal, a smartphone, or any other information processing device.
[0030] As shown in FIG. 1 , the support device 100 includes a first generation unit 10 , a second generation unit 11 , and a management unit 12 .
[0031] The first generation unit 10 provides the terminal 200 with a user interface including a set of questions according to a risk assessment for each of one or more hazards included in the target device. The user answers the set of questions by operating the terminal 200. In this specification, "risk assessment" refers to all processes including risk analysis, risk evaluation, and risk reduction measures. "Risk" indicates the amount of harm and the probability of occurrence. The first generation unit 10 generates first information 50 including the results of the risk assessment for each of the one or more hazards based on input to the user interface. The first information 50 typically includes a risk assessment sheet.
[0032] The second generation unit 11 generates second information 60 indicating the device configuration and wiring of a safety-related unit based on input to a user interface for supporting the realization of risk reduction measures for each of one or more hazards included in the target device. The safety-related unit is a part of a control system that provides safety functions. The safety-related unit includes multiple safety devices. The multiple safety devices generally include an input device (Input) that acquires safety-related information, a logic operation device (Logic) that makes safety-related decisions, and an output device (Output) that performs safety-related control. The second information 60 includes information that identifies the multiple safety devices that make up the safety-related unit and information indicating the wiring between the devices.
[0033] The management unit 12 manages first information 50 and second information 60 in association with each other for each of one or more hazards included in the target device.
[0034] By using the support device 100 of this embodiment, a user can easily check the results of risk assessment for each of one or more hazards, as well as the device configuration and wiring of safety-related parts. In this way, the support device 100 of this embodiment can provide an environment in which the user can easily check information related to safety design.
[0035] §2 Specific Example <Hardware Configuration of Support Device> The hardware configuration of the support device 100 will be described with reference to Fig. 2. Fig. 2 is a schematic diagram showing an example of the hardware configuration of the support device.
[0036] The support device 100 includes one or more processors 102, memory 104, a network controller 106, and storage 110. These components are communicatively coupled to one another via a bus.
[0037] The processor 102 reads a program stored in the storage 110, loads it into the memory 104, and executes it. The processor 102 includes, for example, a central processing unit (CPU) or a micro-processing unit (MPU). The memory 104 is a volatile memory such as a dynamic random access memory (DRAM) or a static random access memory (SRAM). The storage 110 is a non-volatile memory such as a hard disk or flash memory. The storage 110 stores a system program 112 and a safety design program 114.
[0038] The processor 102 executes the safety design program 114 to provide a safety design tool.
[0039] 2 shows an example in which the necessary processing is realized by the processor 102 executing a program, but some or all of the functions handled by the processor 102 may be replaced by a hardwired circuit (e.g., an ASIC (Application Specific Integrated Circuit) and an FPGA (Field-Programmable Gate Array)). Also, a SoC (System on Chip) incorporating a processor may be employed.
[0040] In this specification, the term "processor" encompasses processors in the narrow sense, such as CPUs and GPUs, as well as hardwired circuits such as ASICs and FPGAs, DSPs (Digital Signal Processors), and AI (Artificial Intelligence) chips.
[0041] The network controller 106 exchanges data with the terminal 200 etc. Specifically, the network controller 106 provides a user interface to the terminal 200 and receives input to the user interface.
[0042] <Functional Configuration of Support Device> The functional configuration of the support device 100 will be described with reference to Fig. 3. Fig. 3 is a schematic diagram showing an example of the functional configuration of the support device.
[0043] 3, the support device 100 includes a risk level calculation unit 13, a risk tolerance determination unit 14, a risk reduction measure reception unit 15, a PLr calculation unit 16, a safety device selection unit 17, a pin assignment drawing unit 18, a pin wiring design reception unit 19, a PL determination unit 20, a block diagram creation unit 21, a management unit 12, and an output unit 22. The risk level calculation unit 13, the risk tolerance determination unit 14, the risk reduction measure reception unit 15, and the PLr calculation unit 16 constitute the first generation unit 10 shown in FIG. 1. The safety device selection unit 17, the pin assignment drawing unit 18, the pin wiring design reception unit 19, and the block diagram creation unit 21 constitute the second generation unit 11 shown in FIG. 1. The risk level calculation unit 13, risk tolerance determination unit 14, risk reduction measure reception unit 15, PLr calculation unit 16, safety device selection unit 17, pin assignment drawing unit 18, pin wiring design reception unit 19, PL determination unit 20, block diagram creation unit 21, and output unit 22 are realized by the processor 102 shown in Fig. 2 executing the safety design program 114. The management unit 12 is realized by the processor 102, memory 104, and storage 110 shown in Fig. 2.
[0044] Each unit of the support device 100 creates a user interface 70 and provides it to the terminal 200. Furthermore, each unit of the support device 100 accepts input to the user interface 70 and performs processing according to the input.
[0045] The risk level calculation unit 13 calculates a risk level for each of one or more hazards included in the target device in response to an input to the user interface 70, which includes a group of questions regarding dangerous situations.
[0046] The risk tolerance determination unit 14 determines whether the risk level is within a tolerable range. The tolerable range is determined in advance according to, for example, the social environment of the country in which the target device is used, the policy of the company that manufactures the target device, or the policy of the customer to whom the target device is delivered.
[0047] The risk reduction measure receiving unit 15 receives the risk reduction measure via the user interface 70 in response to the risk level being outside the acceptable range.
[0048] The PLr calculation unit 16 calculates a required performance level PLr for each of one or more hazards included in the target device in response to an input to the user interface 70, which includes a group of questions regarding hazardous situations. The required performance level PLr represents the performance required of a safety-related part in response to risk.
[0049] The first generating unit 10 generates first information 50 indicating a risk level, a determination result as to whether the risk level is within an acceptable range, a risk reduction measure, and a required performance level PLr. Furthermore, the first generating unit 10 includes information input to a user interface 70, including a group of questions regarding the dangerous situation, in the first information 50.
[0050] The safety device selection unit 17 selects, for each of one or more hazards included in the target device, a plurality of safety devices that constitute the safety-related part, based on input to the user interface 70. Specifically, the safety device selection unit 17 selects the input devices, logical operation devices, and output devices that constitute the safety-related part.
[0051] The safety device selection unit 17 selects a plurality of safety devices from a plurality of safety device candidates, for example, in response to an input to a user interface including a plurality of safety device candidates. The safety device selection unit 17 stores device data for each of the plurality of safety device candidates in advance. For example, the device data includes data conforming to standard sheet 66413 of VDMA (the Federation of German Industrial Machinery). A user may import device data for a new safety device candidate into the safety device selection unit 17 from a general-purpose database conforming to standard sheet 66413 of VDMA. Furthermore, the device data may include device specifications (appearance images and configuration of input / output terminals), values for reliability evaluation (for example, B 10D and mean time to dangerous failure (MTTF) D ) is included. 10D is the number of operations until 10% of the parts fail dangerously.
[0052] The pin assignment drawing unit 18 creates an image object representing each terminal (pin) of the selected plurality of safety devices. The pin assignment drawing unit 18 stores in advance configuration information indicating the configuration of input / output terminals for each of the plurality of safety device candidates, and creates an image object based on the configuration information corresponding to each selected safety device.
[0053] The pin wiring design receiving unit 19 receives a wiring design between the selected plurality of safety devices. Specifically, the pin wiring design receiving unit 19 provides a user interface 70 that includes an image object created by the pin assignment drawing unit 18 and prompts the user to select a pair of terminals to be connected from a plurality of terminals included in the plurality of safety devices. The pin wiring design receiving unit 19 receives the selection of the pair of terminals to be connected via the user interface 70.
[0054] The pin wiring design receiving unit 19 creates a wiring diagram of the safety-related part based on the received wiring design.
[0055] The block diagram creation unit 21 creates a block diagram of a plurality of safety devices that constitute the safety-related part based on the wiring diagram of the safety-related part.
[0056] The second generation unit 11 generates second information 60 including information identifying each of the selected plurality of safety devices, information indicating the wiring design accepted by the pin wiring design acceptance unit 19, information indicating the wiring diagram created by the pin wiring design acceptance unit 19, and information indicating the block diagram created by the block diagram creation unit 21.
[0057] The PL determination unit 20 determines the performance level PL of the safety-related unit based on input to the user interface 70, which includes an index for evaluating the reliability of each safety device included in the safety-related unit and a set of questions regarding the operating status. For example, DC (Diagnostic Coverage) can be used as an index for evaluating the reliability of the safety devices. DC (Diagnostic Coverage) is also referred to as "diagnostic coverage." The performance level PL is defined in ISO 13849-1. Furthermore, the PL determination unit 20 determines whether the performance level PL is equal to or greater than the required performance level PLr.
[0058] The PL determining unit 20 includes in the first information 50 the performance level PL and a determination result as to whether the performance level PL is equal to or greater than the required performance level PLr.
[0059] In response to a request from a user, the output unit 22 outputs the first information 50 and the second information 60. For example, the output unit 22 outputs a document representing the first information 50 and a document representing the second information 60. Alternatively, the output unit 22 outputs a user interface including the first information 50 and the second information 60 to the terminal 200.
[0060] <Processing Flow of Support Device> Figure 4 is a flowchart showing an example of the processing flow of the support device. As shown in Figure 4, in step S1, the processor 102 determines the restrictions of the target device. Specifically, the processor 102 provides a user interface that prompts input of the restrictions of the target device, and determines the restrictions of the target device in accordance with the input to the user interface. The restrictions of the target device include usage restrictions, space restrictions, and time restrictions.
[0061] Fig. 5 is a diagram showing an example of a user interface showing the determination result of the restrictions on the target device. The user interface 70A shown in Fig. 5 is created by the processor 102 after completion of step S1 and provided to the terminal 200. As shown in Fig. 5, the processor 102 determines the name, specifications, purpose, and target users who will use the target device as the restrictions on the target device.
[0062] 4, after step S1, a loop process L1 is executed for each of one or more hazards included in the target device. The loop process L1 includes steps S2 to S6.
[0063] In step S2, the processor 102 operating as the first generation unit 10 generates first information 50 including the results of the risk assessment based on input to a user interface including a set of questions according to the risk assessment.
[0064] In the next step S3, the processor 102 operating as the second generation unit 11 generates second information 60 indicating the equipment configuration and wiring of the safety-related parts based on input to a user interface to assist in the implementation of risk reduction measures.
[0065] In the next step S4, the processor 102 operating as the PL determining unit 20 evaluates the performance level PL of the safety-related part. The evaluation result of the performance level PL is included in the first information 50.
[0066] In the next step S5, the processor 102 operating as the first generator 10 estimates the risk when the risk reduction measure is implemented, based on an input to a user interface including a group of questions regarding the dangerous situation after the risk reduction measure is implemented. The result of estimating the risk when the risk reduction measure is implemented is included in the first information 50.
[0067] In the next step S6, the processor 102 operating as the management unit 12 manages the first information 50 and the second information 60 in association with each other in the memory 104 or the storage 110.
[0068] When the loop process L1 for all of the one or more hazards included in the target device is completed, in step S7, the processor 102 outputs the first information 50 and the second information 60 in response to a request from the user.
[0069] <Subroutine of Step S2> The subroutine of step S2 will be described with reference to Figures 6 to 15. Figure 6 is a flowchart showing an example of the subroutine of step S2 shown in Figure 4.
[0070] First, in step S21, the processor 102 operating as the first generator 10 provides the terminal 200 with a user interface including a group of questions regarding dangerous situations.
[0071] 7 is a diagram showing an example of a user interface including a group of questions regarding dangerous situations. User interface 70B shown in FIG. 7 is an example of a "first user interface" of the present disclosure. User interface 70B includes input fields 71a to 71f and 72a to 72c for inputting answers to the group of questions regarding dangerous situations.
[0072] The input fields 71a to 71f are used to input answers to questions for identifying hazards. Specifically, the input fields 71a to 71f are used to input "type of hazard," "cause," "result," "body part," "hazardous state," and "hazardous event," respectively.
[0073] The input fields 72a to 72c are used to input the elements that make up a risk. The safety standard ISO 13849-1 specifies a method for estimating risk based on the magnitude of each of the following: "severity of harm," "frequency and / or duration of exposure to a hazard," and "possibility of avoiding the hazard or limiting the harm." Therefore, the input fields 72a to 72c are used to input the "severity of harm (S)," "frequency of exposure to a hazard (F)," and "avoidance of a hazard (P)," respectively, in accordance with the safety standard. The elements that make up a risk are used to calculate a risk level. Therefore, the elements that make up a risk are also referred to as explanatory variables of the risk level.
[0074] 6, in the next step S22, the user inputs answers to the questions for identifying hazards in the input fields 71a to 71f. To support user input, the processor 102 may provide pull-down menus corresponding to some of the input fields. This allows the user to select a desired option from the pull-down menu.
[0075] 8 is a diagram showing an example of a pull-down menu for each question for identifying a hazard. As shown in FIG. 8, the user interface 70B has pull-down menus 73a to 73d corresponding to the input fields 71a to 71d, respectively.
[0076] Annex B of ISO 12100 lists types of hazards. Therefore, the pull-down menu 73a is created in advance so as to match the list of "types of hazards" listed in Annex B of ISO 12100.
[0077] Furthermore, in Annex B of ISO 12100, hazards are expressed by a combination of "cause" and "effect" depending on the type of hazard. For example, Annex B of ISO 12100 lists "acceleration, deceleration," "edgy parts," etc. as causes of "mechanical hazards." Annex B of ISO 12100 lists "being run over," "being thrown out," etc. as consequences of "mechanical hazards." Therefore, when input field 71b is operated with "mechanical hazard" entered in input field 71a, user interface 70B displays pull-down menu 73b that matches the list of "causes" of "mechanical hazards" specified by ISO 12100. Similarly, when input field 71c is operated with "mechanical hazard" entered in input field 71a, user interface 70B displays pull-down menu 73c that matches the list of "effects" of "mechanical hazards" specified by ISO 12100.
[0078] Thus, the questions included in the user interface 70B include questions about multiple essential items required by the safety standard. By using the pull-down menus 73a to 73c, the user can input desired options from the lists of "type of hazard," "cause," and "result" specified by ISO 12100 into the input fields 71a to 71c.
[0079] The pull-down menu 73d is pre-populated to include a list of the main candidates for body parts that may be harmed.
[0080] The user interface 70B can accept any character string in input fields 71e and 71f (see FIG. 7). The user can input a character string representing a dangerous state into the input field 71e and a character string representing a dangerous event into the input field 71f. A "dangerous state" refers to a situation in which a person is exposed to a source of danger. A "dangerous event" refers to an event that results from a dangerous state and leads to harm.
[0081] 6, in the next step S23, the user inputs values of the elements that constitute the risk (explanatory variables of the risk level) into the input fields 72a to 72c. To support the user's input, the processor 102 may provide a pull-down menu corresponding to each input field. This allows the user to select a desired option from the pull-down menu.
[0082] FIG. 9 is a diagram showing an example of a pull-down menu for elements constituting a risk. The user interface 70B has pull-down menus 74 corresponding to each of the input fields 72a to 72c. In the example shown in FIG. 9, only the pull-down menu 74 corresponding to the input field 72c is shown. The pull-down menu 74 corresponding to the input field 72a includes options "S1: Minor injury" and "S2: Severe injury." The pull-down menu 74 corresponding to the input field 72b includes options "F1: Rare" and "F2: Frequent." The pull-down menu 74 corresponding to the input field 72c includes options "P1: Possible under certain conditions" and "P2: Almost impossible."
[0083] The user can easily input values for the elements that make up the risk (explanatory variables for the risk level) by using the pull-down menu 74. In this way, even if the user has little knowledge of safety standards, the user can easily answer questions about multiple essential items required by the safety standards for identifying hazards and estimating risks via the user interface 70B.
[0084] 6 , in the next step S24, the processor 102 estimates the risk and outputs the risk level, acceptability, and required performance level. Estimating the risk requires input into at least the input fields corresponding to the multiple required items required by the safety standard. Therefore, the processor 102 starts step S24 of estimating the risk when it has obtained answers to all of the multiple required items. In this embodiment, the processor 102 starts step S24 when it has obtained answers to all of the input fields 71a to 71f and 72a to 72c.
[0085] FIG. 10 is a diagram illustrating an example of a risk level calculation method. The calculation method illustrated in FIG. 10 uses a classification chart method (risk graph method). The processor 102 calculates the risk level by selecting a branch path from the starting point according to the values of the explanatory variables of the risk level. For example, in the example illustrated in FIG. 10, if "S2: Serious Injury," "F1: Rare," and "P2: Almost Impossible" are input, the processor 102 calculates a risk level of "3." Note that the method of calculating the risk level is not limited to the classification chart method. For example, a matrix method or a point method may be used to calculate the risk level. These calculation methods are also introduced in the "Guidelines for Surveys on Danger or Harmfulness, etc." published by the Ministry of Health, Labor, and Welfare.
[0086] The processor 102 determines whether the risk level is within an acceptable range. The acceptable range is determined in advance according to the social environment of the country in which the target device is used, the policy of the company that manufactures the target device, the policy of the customer of the target device, etc.
[0087] FIG. 11 is a diagram illustrating a method for calculating the required performance level PLr. As shown in FIG. 11, the processor 102 calculates the required performance level PLr by using a classification chart method (risk graph method) to select a branch path from the starting point according to the value of the explanatory variable of the risk level. The required performance level PLr is classified into one of five levels, "a" to "e." The method for determining the required performance level PLr is shown in Annex A of ISO 13849-1. For example, in the example shown in FIG. 11, if "S2: Serious Injury," "F1: Rare," and "P2: Almost Impossible" are input, the processor 102 calculates the required performance level PLr as "d."
[0088] In step S24, the processor 102 may provide the terminal 200 with a user interface indicating the risk level, acceptability, and required performance level PLr.
[0089] 12 is a diagram showing an example of a user interface that may be provided to the terminal in step S24. As shown in FIG. 12, a user interface 70C shows the risk levels “IV” and “unacceptable” and the required performance level PLr “d”.
[0090] Returning to FIG. 6, in the next step S25, the processor 102 provides the terminal 200 with a user interface including a set of questions regarding risk reduction measures.
[0091] FIG. 13 is a diagram showing an example of a user interface including a group of questions regarding risk reduction measures. A user interface 70D shown in FIG. 13 is an example of a "first user interface" of the present disclosure. ISO 12100 specifies a three-step method for designing risk reduction measures. The three-step method indicates that a first step is to determine "intrinsic safety design measures," a second step is to determine "safeguarding measures" and "additional protective measures," and a third step is to determine "information for use," in that order. Therefore, as shown in FIG. 13, the user interface 70D includes input fields 75a to 75e in accordance with the three-step method specified in ISO 12100. The input field 75a is used to input the "intrinsic safety design measures." The input field 75b is used to input the "safeguarding measures." The input field 75c is used to input details of the "safeguarding measures." The input field 75d is used to input the "additional protective measures." The input field 75e is used to input the "information for use."
[0092] Returning to Fig. 6, in the next step S26, the user inputs answers to the group of questions regarding risk reduction measures in the input fields 75a to 75e. To support the user's input, the processor 102 provides pull-down menus 76 corresponding to the input fields 75a, 75b, 75d, and 75e. This allows the user to select a desired option from the pull-down menu 76. Note that Fig. 13 only shows the pull-down menu 76 corresponding to the input field 75d.
[0093] ISO 12100 lists examples of "intrinsically safe design measures." Therefore, in response to an operation on the input field 75 a, the user interface 70D displays a pull-down menu 76 that includes, as options, examples of "intrinsically safe design measures" listed in ISO 12100.
[0094] The following measures are known as typical examples of "safeguarding measures." - Employing fixed guards. - Employing detection protection equipment (safety light curtains, safety laser scanners, safety mats, etc.). - Employing interlocked movable guards. Therefore, in response to an operation on the input field 75b, the user interface 70D displays a pull-down menu 76 that includes these measures as options. Note that the user interface 70D accepts the input of any character string that indicates the details of the "safeguarding measures" in the input field 75c.
[0095] The following measures are known as typical examples of "additional protective measures." Providing an emergency stop function in a position that is quickly accessible. Installing a lockable cutoff device. Therefore, in response to an operation on the input field 75d, the user interface 70D displays a pull-down menu 76 that includes these measures as options.
[0096] ISO 12100 lists examples of "usage information" to alert device users and inform them of appropriate device handling procedures. Therefore, in response to an operation on input field 75e, user interface 70D displays a pull-down menu containing options for the "usage information" listed in ISO 12100.
[0097] The user interface 70D includes a button 77 for instructing the generation of the first information 50. In response to the button 77 being pressed, the subroutine of S2 proceeds to step S27.
[0098] In step S27, the processor 102 generates and saves a data set for creating a risk assessment sheet as the first information 50. As described above, the user interfaces 70B and 70D include input fields for questions regarding multiple mandatory items required by safety standards. Therefore, the processor 102 operating as the first generator 10 generates a data set for creating a risk assessment sheet as the first information 50 in response to obtaining answers to all of the input fields in the user interfaces 70B and 70D.
[0099] FIG. 14 is a diagram showing an example of a data set for creating a risk assessment sheet. As shown in FIG. 14, a data set 50a shows the contents of multiple items included in each of five categories: "Accident Scenario," "Risk Estimation (Initial Risk)," "Risk Reduction," "Risk Estimation (After Risk Reduction)," and "Final Risk Assessment." A data set 50a is created for each hazard. FIG. 14 shows the data set 50a corresponding to the hazard "No. 1."
[0100] The processor 102 sets the inputs into the input fields 71a to 71f in Figure 7 as the contents of the items "Type," "Cause," "Result," "Human Body Part," "Dangerous Condition," and "Dangerous Event," which belong to the classification "Accident Scenario" in the dataset 50a.
[0101] 7 as the contents of the items "Severity of Harm," "Frequency of Exposure to Hazard," and "Avoidance of Hazard," which belong to the category "Risk Estimation (Initial Risk)" in the data set 50a. Furthermore, the processor 102 sets the risk level, required performance level PLr, and acceptability output in step S24 as the contents of the items "Risk Level," "PLr," and "Risk Assessment," which belong to the category "Risk Estimation (Initial Risk)," in the data set 50a.
[0102] The processor 102 sets the inputs into the input fields 75a to 75e in FIG. 13 as the contents of the items "inherently safe design," "safety protection measures," "safety protection details," "additional protection measures," and "usage information," which belong to the category "risk reduction" in the data set 50a.
[0103] In this way, the processor 102 operating as the first generator 10 includes answers to a plurality of essential items required by the safety standard for risk assessment in the first information 50. As a result, by checking the first information 50, the user can easily make a self-declaration or have an evaluation by a third-party certification body based on the content required by the safety standard.
[0104] In step S2, the processor 102 cannot determine the items in the dataset 50a that belong to the categories "Risk Estimation (After Risk Reduction)" and "Final Risk Assessment." Therefore, in step S27, the processor 102 sets the contents of these items in the dataset 50a to blank.
[0105] In step S27, the processor 102 provides the terminal 200 with a user interface including a risk assessment sheet created based on the data set 50a.
[0106] 15 is a diagram showing an example of a user interface provided to the terminal in step S27. As shown in FIG. 15, the user interface 70E includes areas 78 and 79. Area 78 displays the contents of each item in the risk assessment sheet created based on the dataset 50a. Area 79 includes five check boxes corresponding to the five categories in the dataset 50a. The processor 102 displays in area 78 only the items in the categories corresponding to the checked check boxes in area 79.
[0107] The user interface 70E includes a menu icon 81. The menu icon 81 is used to transition to a user interface that supports the instantiation of a safety-related part. That is, in response to an operation of the menu icon 81, the processor 102 advances the processing to step S3.
[0108] <Subroutine of Step S3> The subroutine of step S3 will be described with reference to Figures 16 to 21. Figure 16 is a flowchart showing an example of the subroutine of step S3 shown in Figure 4.
[0109] First, in step S31, the processor 102 operating as the second generation unit 11 provides the terminal 200 with a user interface that prompts the user to select a safety device.
[0110] Fig. 17 is a diagram showing an example of a user interface that prompts a user to select a safety device. A user interface 70F shown in Fig. 17 is an example of a "second user interface" of the present disclosure. The user interface 70F includes an input field 82 for selecting a category. A "category" represents a classification of the circuit structure (architecture) of a safety-related part. The categories include "Category B," "Category 1," "Category 2," "Category 3," and "Category 4."
[0111] "Category B" safety-related parts are required to be able to perform the intended safety functions. "Category 1" safety-related parts are required to be highly reliable in addition to being able to perform the intended safety functions. "Category B" or "Category 1" safety-related parts have a single channel structure that includes only one signal system: input device - logic operation device - output device.
[0112] "Category 2" safety-related parts are required to have a supplementary inspection function that can compensate for the loss of the safety function due to a dangerous failure. "Category 2" safety-related parts have a single-channel structure and also an inspection function. The inspection function includes inspection equipment and equipment for outputting the inspection results.
[0113] "Category 3" safety-related parts are required to maintain the safety function as a whole even if a failure occurs in a part of the safety function. "Category 4" safety-related parts are required to maintain the safety function even if a certain number of failures accumulate in the safety function. "Category 3" or "Category 4" safety-related parts have a two-channel structure with redundant signal systems.
[0114] 16, in the next step S32, the user inputs a desired category in the input field 82. The user may select a category taking into consideration the risk level and the required performance level PLr.
[0115] In response to a category input into the input field 82, the processor 102 updates the user interface 70F to include blocks 83 corresponding to each of the multiple safety devices that make up the safety-related part of the input category. In the example shown in FIG. 17 , "Category 3" is input. The safety-related part of "Category 3" has a two-channel structure with redundant signal systems. For example, the user interface 70F includes two blocks 83a corresponding to input devices, one block 83b corresponding to a logic operation device, and two blocks 83c corresponding to output devices.
[0116] Returning to FIG. 16, in the next step S33, the user operates block 83 to input the model number of each safety device that constitutes the safety-related part.
[0117] In response to clicking on block 83, processor 102 provides terminal 200 with a pop-up window that prompts the user to select a safety device.
[0118] FIG. 18 is a diagram showing an example of a pop-up window that prompts the user to select a safety device. The pop-up window 70G shown in FIG. 18 is an example of the "second user interface" and "fourth user interface" of the present disclosure. The pop-up window 70G is displayed in response to clicking on a block 83a corresponding to an input device. The pop-up window 70G includes a list 85 of multiple safety device candidates. In response to selecting one safety device from the list 85, the pop-up window 70G displays a list 86 of models of the selected safety device. The list 86 includes radio buttons 86a corresponding to each model. The user selects the desired model by operating the radio button 86a. The pop-up window 70G includes a button 87 for completing the selection input. In response to pressing the button 87, the subroutine proceeds to step S34.
[0119] Each safety device may be composed of a plurality of units. For example, a logical operation device may be composed of an input unit, a CPU unit, and an output unit. In this case, the user selects a plurality of units.
[0120] 16, in step S34, the processor 102 reads out configuration information corresponding to the selected safety device model and identifies the terminal arrangement and connection method of the safety device. The connection method indicates the conditions for connectable terminal pairs, the number of wires required between devices, etc.
[0121] In the next step S35, the processor 102 provides a user interface that supports wiring. Specifically, the processor 102 generates a graphical object that represents each terminal (pin) of the selected plurality of safety devices. The processor 102 provides a user interface that includes the graphical object and prompts the user to select a pair of terminals to be connected from among the plurality of terminals included in the plurality of safety devices.
[0122] FIG. 19 is a diagram illustrating an example of a user interface that supports wiring. The user interface 70H illustrated in FIG. 19 is an example of the "second user interface" and the "fifth user interface" of the present disclosure. The user interface 70H includes image objects 80, 88a to 88d as image objects representing the terminals (pins) of each of a plurality of safety devices. The image object 80 represents the arrangement of the terminals included in the logic operation device. The image object 88a represents a list of terminals of the input device "aaa." The image object 88b represents a list of terminals of the input units that make up the logic operation device. The image object 88c represents a list of terminals of the output units that make up the logic operation device. The image object 88d represents a list of terminals of the output device. To accommodate a safety-related part having a two-channel structure, the number of image objects 88a and 88d corresponding to each of the input devices and the output devices is two.
[0123] The user interface 70H displays terminal objects 89 corresponding to each terminal in the list represented by the image objects 88a to 88d, near the image objects 88a to 88d. The terminal objects 89 are used to select a pair of terminals to be connected.
[0124] 16 , in the next step S36, the user selects a pair of terminals to be connected from among a plurality of terminals included in a plurality of safety devices. Specifically, the user performs an operation on the user interface 70H shown in FIG. 19 to connect two terminal objects 89 corresponding to the pair of terminals to be connected with a line. This results in wiring between the two terminal objects 89. In the example shown in FIG. 19 , terminal objects 89 a and 89 b are selected as the two terminal objects 89 corresponding to the pair of terminals to be connected.
[0125] In order to prevent incorrect wiring designation, when a terminal object 89 is selected, the user interface 70H may highlight terminal objects 89 corresponding to one or more terminals connectable to the terminal corresponding to the terminal object 89. The highlighted terminal objects 89 are identified based on the conditions for connectable terminal pairs. The conditions are indicated by configuration information corresponding to the type of selected safety device. For example, as shown in FIG. 19 , when a cursor 90 is placed over a terminal object 89c, the user interface 70H highlights terminal objects 89d corresponding to each of one or more terminals connectable to the terminal corresponding to the terminal object 89c.
[0126] Furthermore, the user interface 70H may output a message prompting the user to specify wiring when fewer than the required number of wirings have been specified. For example, when the number of wirings between the image objects 88c and 88d is less than the required number, the user interface 70H displays a message indicating that the logic operation device and the output device are not wired.
[0127] The user interface 70H updates the image object 80 in accordance with the wiring designation. The image object 80 schematically shows the surface on which the input / output terminals of the logic operation device are arranged, with each terminal being shown as a circle corresponding to its position. The user interface 70H differentiates the display mode of the terminals designated for wiring from the display mode of the remaining terminals. The display mode may include, for example, color, gradation, hatching, shape, whether or not to blink, etc.
[0128] Upon completion of the selection of the terminal pairs to be connected, in the next step S37, the processor 102 creates a wiring diagram of the safety-related parts based on the selection and saves the created wiring diagram as second information 60.
[0129] Fig. 20 is a diagram showing an example of a wiring diagram. A wiring diagram 60a shown in Fig. 20 shows wiring between an input device "safety curtain aaa", a logical operation device "bbb", and an output device "safety relay ccc". For example, the wiring diagram 60a shows that a terminal "OSSD1" of the input device is wired to a terminal "Si0" of the logical operation device.
[0130] 16 , in the next step S38, the processor 102 creates a block diagram of the plurality of safety devices that make up the safety-related part based on the wiring diagram 60a of the safety-related part, and saves the created block diagram as the second information 60. After step S38 is completed, the processing proceeds to step S4.
[0131] Fig. 21 is a diagram showing an example of a block diagram. A block diagram 60b shown in Fig. 20 shows that the safety-related part includes an input device "safety curtain aaa", a logical operation device "bbb", and an output device "safety relay ccc", and has a two-channel structure.
[0132] <Subroutine of Step S4> The subroutine of step S4 will be described with reference to Figures 22 to 25. Figure 22 is a flowchart showing an example of the subroutine of step S4 shown in Figure 4.
[0133] First, in step S41, the processor 102 operating as the PL determination unit 20 provides the terminal 200 with a user interface including a set of questions regarding the diagnostic range and operating status of each safety device included in the safety-related unit.
[0134] FIG. 23 is a diagram illustrating an example of a user interface including a group of questions regarding indicators for evaluating the reliability of each safety device and the operating status of each safety device. The user interface 70I illustrated in FIG. 23 is an example of a “third user interface” of the present disclosure. The user interface 70I includes an input field for inputting the diagnostic coverage (DC) of each safety device. “Diagnostic coverage (DC)” is a parameter indicating the probability of detecting a dangerous failure in a safety-related part. If the safety device includes multiple units, the user interface 70I may also accept input of the diagnostic coverage for each of the multiple units. In the example illustrated in FIG. 23 , the user interface 70I includes two input fields 91a corresponding to two channels of the input device, three input fields 91b corresponding to three units constituting the logic operation device, and two input fields 91c corresponding to two channels of the output device.
[0135] Furthermore, the user interface 70I includes input fields 92a-92c and 93a-93c for inputting the operating status of the safety devices. The input fields 92a-92c accept input of the average time interval between one operation cycle, the operating hours per day, and the number of operating days per year for the input devices. The input fields 93a-93c accept input of the average time interval between one operation cycle, the operating hours per day, and the number of operating days per year for the output devices.
[0136] The user interface 70I includes display fields 92d and 93d. The display field 92d displays the total number of times the input device has been operated per year. The display field 93d displays the total number of times the output device has been operated per year.
[0137] Returning to FIG. 22, in the next step S42, the user inputs the DC (Diagnostic coverage) of each safety device in the input fields 91a to 91c.
[0138] In the next step S43, the user inputs the operating status of the safety devices into input fields 92a to 92c and 93a to 93c. Specifically, the user inputs the average time interval between one operation cycle, the operating hours per day, and the number of operating days per year for the input devices into input fields 92a to 92c. Furthermore, the user inputs the average time interval between one operation cycle, the operating hours per day, and the number of operating days per year for the output devices into input fields 93a to 93c.
[0139] The user interface 70I updates the value displayed in the display field 92d in response to inputs made to the input fields 92a to 92c. Specifically, the user interface 70I updates the value t cycle , the value h entered in the input field 92b op , and the value d entered in the entry field 92c op The value n obtained by substituting op is displayed in the display field 92d. Similarly, the user interface 70I updates the value displayed in the display field 93d in response to inputs made to the input fields 93a to 93c.
[0140]
[0141] In the next step S44, the processor 102 calculates the mean time to dangerous failure (MTTF) for each safety device. D Calculate the mean time to dangerous failure (MTTF). D is the average time it takes to cause a dangerous failure. Specifically, the processor 102 calculates the mean time to dangerous failure (MTTF) for each safety device according to the following equation (2): D Calculate the following. 10D is the number of operations until 10% of the parts cause a dangerous failure, and is included in the equipment data corresponding to the safety equipment.
[0142]
[0143] In the next step S45, the processor 102 provides the terminal 200 with a user interface for checking a plurality of check items related to resistance to Common Cause Failures (CCF).
[0144] In the next step S46, the user checks, on the user interface, the check items that apply to the safety-related part among the plurality of check items.
[0145] 24 is a diagram showing an example of a user interface for checking multiple check items related to CCF resistance. The user interface 70J shown in FIG. 24 displays multiple check items in accordance with the list of measures for reducing CCF provided in Annex F of ISO 13849-1. Furthermore, the user interface 70J includes check boxes 94 for each of the multiple check items. The user checks the check boxes 94 corresponding to the check items that apply to safety-related parts among the multiple check items.
[0146] 22 , in the next step S47, the processor 102 calculates a CCF score based on the check results of the check boxes 94 for the multiple check items. Each of the multiple check items has a predetermined score. The processor 102 calculates the CCF score by adding up the scores assigned to the check items for which the check boxes 94 have been checked.
[0147] In the next step S48, the processor 102 calculates the performance level PL of the safety-related part. Specifically, the processor 102 calculates the mean time to dangerous failure (MTTF) for each category and safety device input in the input field 82 shown in FIG. D , and D.C. avg Based on this, the probability of a dangerous failure occurring per unit time, PFH, is calculated for each subsystem that constitutes the safety-related part. D "Subsystem" refers to a functional grouping according to the characteristics of a safety-related part. For example, the input devices, logic operation devices, and output devices that make up a safety-related part are each set as a subsystem. Note that ISO / TR23849 allows subsystems with the same configuration to be combined together. Therefore, for example, input devices and output devices can be combined into the same subsystem.
[0148] DC avgis calculated by averaging the diagnostic ranges (DC) of one or more safety devices that make up the subsystem. Specifically, the processor 102 calculates DC based on the following equation (3): avg In equation (3), DCi represents the DC of the i-th safety device. D i is the mean time to dangerous failure (MTTF) of the i-th safety device D Shows.
[0149]
[0150] Category, Mean Time to Dangerous Failure (MTTF) D , D.C. avg , and probability PFH D The relationship between the above and the probability PFH for each subsystem is shown in Annex K of ISO 13849-1. D It is sufficient to identify the following.
[0151] The processor 102 calculates the probability PFH for each subsystem. D The performance level PL of the entire safety-related part is determined from the sum of the probability PFH D The relationship between the performance level PL and the parameter .DELTA..times ...
[0152] In the next step S49, the processor 102 determines whether or not PLr≦PL is satisfied. After step S49 is completed, the process proceeds to step S5. Note that, after completing step S49, the processor 102 may provide a user interface that shows the evaluation result of the performance level PL.
[0153] 25 is a diagram showing an example of a user interface showing the evaluation result of the performance level PL. As shown in FIG. 25, the user interface 70K displays the required performance level PLr, the performance level PL, the determination result of whether or not PLr≦PL is satisfied, and the probability PFH for each subsystem. D The sum of (in the figure, simply "PFH D") and CCF score (simply "CCF" in the figure).
[0154] <Subroutine of Step S5> The subroutine of step S5 will be described with reference to Figures 26 to 28. Figure 26 is a flowchart showing an example of the subroutine of step S5 shown in Figure 4.
[0155] First, in step S51, the processor 102 operating as the first generation unit 10 provides the terminal 200 with a user interface that prompts input of values of elements that constitute the risk (explanatory variables of the risk level) when risk reduction measures are implemented by the safety-related unit.
[0156] FIG. 27 is a diagram showing an example of a user interface that prompts the user to input values of elements that constitute risk when a safety measure by a safety-related part is implemented. As shown in FIG. 27, the user interface 70L includes input fields 95a to 95e and a radio button 95f. The input fields 95a to 95c, like the input fields 72a to 72c shown in FIG. 7, are used to input the "Severity of Harm (S)," "Frequency of Exposure to Hazard (F)," and "Avoidance of Hazard (P)," respectively. The input field 95d is used to input any comments. The input field 95e is used to input character strings that identify reference documents and reference standards. The radio button 95f is used to input whether further risk reduction is required.
[0157] 26, in the next step S52, the user inputs values of the elements that make up the risk (explanatory variables of the risk level) into input fields 95a to 95c. Furthermore, the user operates radio button 95f and enters the necessary information into input fields 95d and 95e.
[0158] In the next step S53, the processor 102 estimates the risk and calculates the risk level based on the inputs in the input fields 96a to 96c.
[0159] In the next step S54, the processor 102 determines whether the risk level is within an acceptable range. At this time, the processor 102 may provide the terminal 200 with a user interface indicating the risk level and whether it is acceptable.
[0160] 28 is a diagram showing an example of a user interface showing the risk level and whether it is acceptable when a safety measure is implemented by a safety-related part. A user can check the risk level and whether it is acceptable via the user interface 70M shown in FIG.
[0161] 26, in the next step S55, the processor 102 updates the first information 50. After step S55 ends, the processing proceeds to step S6.
[0162] Specifically, the processor 102 sets the contents of the items belonging to the categories "Risk Estimation (After Risk Reduction)" and "Final Risk Assessment" of the data set 50a shown in FIG. 14. That is, the processor 102 sets the values entered in the input fields 95a to 95c shown in FIG. 27 as the contents of the items "Severity of Harm," "Frequency of Exposure to Hazard," and "Avoidance of Hazard" belonging to the category "Risk Estimation (After Risk Reduction)." Furthermore, the processor 102 sets the necessity selected using the radio button 95f as the contents of the item "Necessary Further Risk Reduction" belonging to the category "Risk Estimation (After Risk Reduction)." The processor 102 sets the character strings entered in the input fields 95d and 95e as the contents of the items "Free Comments" and "References and Standards" belonging to the category "Risk Estimation (After Risk Reduction)," respectively.
[0163] Furthermore, the processor 102 sets the risk level calculated in step S53, the judgment result of step S54, the performance level PL, and the judgment result of whether PLr≦PL is satisfied as the contents of the items “Risk Level,” “Final Risk Assessment,” “PL,” and “PLr≦PL,” which belong to the category “Final Risk Assessment,” respectively.
[0164] <Example of Processing in Step S7> In step S7, the processor 102 may perform the following first to third processes, for example.
[0165] (First Process) The processor 102 outputs a first document representing first information 50 corresponding to each of one or more hazards for the target device, and a second document representing second information 60 corresponding to each of the one or more hazards. Specifically, the processor 102 outputs a file representing the first document and a file representing the second document. Alternatively, the processor 102 outputs a single file that combines the first document and the second document. The file has, for example, a PDF format.
[0166] (Second Processing) FIG. 29 is a diagram illustrating the second processing of step S7. As shown in FIG. 29, the processor 102 provides the terminal 200 with a user interface 70N including a list of one or more hazards registered for the target device. The processor 102 provides a user interface 70O in response to selection of the target hazard in the user interface 70N. The user interface 70O is an example of a "sixth user interface" of the present disclosure. The user interface 70O includes areas 96a and 96b. The processor 102 displays first information 50 corresponding to the target hazard in the area 96a. For example, a risk assessment sheet created based on the data set 50a is displayed in the area 96a. Furthermore, the processor 102 displays second information 60 (e.g., a wiring diagram 60a and a block diagram 60b) corresponding to the target hazard in the area 96b.
[0167] (Third Processing) FIG. 30 is a diagram illustrating the third processing of step S7. As shown in FIG. 30 , the processor 102 provides the terminal 200 with a user interface 70P including a list of safety devices included in any safety-related part employed in the target apparatus. In response to selection of the target safety device in the user interface 70P, the processor 102 provides a user interface 70Q. The user interface 70Q is an example of a "seventh user interface" of the present disclosure. The user interface 70Q includes areas 98a and 98b for each safety-related part including the target safety device. The processor 102 displays second information 60 (e.g., a wiring diagram 60a and a block diagram 60b) corresponding to the target safety-related part in the area 98a corresponding to the target safety-related part. Furthermore, the processor 102 displays first information 50 corresponding to a target hazard, among one or more hazards, whose risk is reduced by the target safety-related part in the area 98b. For example, a risk assessment sheet created based on the dataset 50a is displayed in the area 98a.
[0168] <Variation 1> The support device 100 may perform processing in cooperation with other applications. For example, the support device 100 may cooperate with a development support application installed on the terminal 200. The development support application supports the development of a user program to be executed in the programmable logic controller. The user program includes instructions for calculations based on data collected from various devices connected to the programmable logic controller, and instructions for outputting data for controlling the operation of a control target based on the calculation results.
[0169] The processor 102 of the support device 100 may operate as a creation unit that analyzes the user program stored in the terminal 200, identifies the relationship between the safety devices and the reset operations of each control object in response to the output signal from the safety-related part including the safety devices, and creates a truth table indicating the relationship. Furthermore, the processor 102 may output a user interface including the truth table or output a document indicating the truth table.
[0170] 31 is a diagram showing an example of a user interface including a truth table. As shown in FIG. 31, the user interface 70R includes a truth table 99 showing the relationship between the safety devices and the reset operations of the transport robot, ball screw, transport conveyor, and transfer robot in response to output signals from the safety-related parts including the safety devices. This allows the user to easily understand the control range based on the safety devices.
[0171] <Variation 2> An embodiment is also possible in which a general-purpose computer functions as the support device 100 according to the above-described embodiment. Specifically, a safety design program 114 that describes the processing content that realizes each function of the support device 100 according to the above-described embodiment is stored in the memory of the general-purpose computer, and the safety design program 114 is read and executed by a processor. Therefore, the invention according to this embodiment can also be realized as a safety design program 114 that can be executed by one or more processors, or a non-transitory computer-readable medium that stores the safety design program 114.
[0172] §3 Supplementary Note As described above, the present embodiment includes the following disclosure.
[0173] (Configuration 1) A support device (100) that supports the safety design of a target device, comprising: a first generation unit (10) that generates first information (50) including results of a risk assessment based on input to a first user interface (70B, 70D) including a first group of questions according to the risk assessment for each of one or more hazards included in the target device; a second generation unit (11) that generates second information (60) indicating the equipment configuration and wiring of a safety-related part based on input to a second user interface (70F, 70G, 70H) for supporting the realization of risk reduction measures for each of the one or more hazards; and a management unit (12) that manages the first information (50) and the second information (60) in association with each other for each of the one or more hazards.
[0174] (Configuration 2) The support device (100) according to Configuration 1, further comprising an output unit (22) that outputs a first document representing the first information (50) corresponding to each of the one or more hazards and a second document representing the second information (60) corresponding to each of the one or more hazards.
[0175] (Configuration 3) The support device (100) according to configuration 1 or 2, wherein the first group of questions includes questions regarding a plurality of required items required by a safety standard, the first generation unit (10) generates the first information (50) in response to obtaining answers to all of the plurality of required items, and the first information (50) includes answers to all of the plurality of required items.
[0176] (Configuration 4) The support device (100) according to any one of configurations 1 to 3, further comprising a determination unit (20) that determines a performance level of the safety-related part based on an input to a third user interface (70I) including a second group of questions regarding the diagnostic range and operating status of each safety device included in the safety-related part, wherein the first generation unit (10) determines a required performance level for each of the one or more hazards based on the input to the first user interface, and the first information (50) includes the required performance level, the performance level, and a determination result as to whether the performance level satisfies the required performance level.
[0177] (Configuration 5) The support device (100) according to any one of configurations 1 to 4, wherein the second user interface includes: a fourth user interface (70F, 70G) that prompts the user to select a plurality of safety devices that constitute the safety-related part from a plurality of candidate safety devices; and a fifth user interface (70H) that prompts the user to select a terminal pair to be connected from a plurality of terminals included in the plurality of safety devices.
[0178] (Configuration 6) The support device (100) according to any one of configurations 1 to 5, further comprising an output unit (22) that provides a sixth user interface (70O) in response to selection of a target hazard from among the one or more hazards, wherein the sixth user interface (70O) displays the first information (50) corresponding to the target hazard and the second information (60) corresponding to the target hazard.
[0179] (Configuration 7) The support device (100) according to any one of configurations 1 to 5, further comprising an output unit (22) that provides a seventh user interface (70Q) in response to selection of a target safety device, wherein the seventh user interface (70Q) displays the second information (60) corresponding to a target safety-related part including the target safety device, and the first information (50) corresponding to a target hazard whose risk is reduced by the target safety-related part among the one or more hazards.
[0180] (Configuration 8) A support method for supporting the safety design of a target device, comprising: one or more processors (102) generating, for each of one or more hazards included in the target device, first information (50) including results of the risk assessment based on input to a first user interface (70B, 70D) including a first group of questions according to the risk assessment; the one or more processors (102) generating, for each of the one or more hazards, second information (60) indicating the equipment configuration and wiring of a safety-related part based on input to a second user interface (70F, 70G, 70H) for supporting the implementation of risk reduction measures; and the one or more processors (102) managing, in association with each other, the first information (50) and the second information (60) for each of the one or more hazards.
[0181] (Configuration 9) A program causing a computer to execute a support method for supporting safety design of a target device, the support method including: generating first information (50) including results of a risk assessment for each of one or more hazards included in the target device, based on input to a first user interface (70B, 70D) including a first group of questions according to the risk assessment; generating second information (60) indicating the equipment configuration and wiring of safety-related parts for each of the one or more hazards, based on input to a second user interface (70F, 70G, 70H) for supporting the realization of risk reduction measures; and managing the first information (50) and the second information (60) in association with each other for each of the one or more hazards.
[0182] Although the embodiments of the present invention have been described, the embodiments disclosed herein should be considered to be illustrative and not restrictive in all respects. The scope of the present invention is defined by the claims, and it is intended to include all modifications within the meaning and scope of the claims.
[0183] 10 First generation unit, 11 Second generation unit, 12 Management unit, 13 Risk level calculation unit, 14 Risk tolerance determination unit, 15 Risk reduction measure reception unit, 16 PLr calculation unit, 17 Safety device selection unit, 18 Pin assignment drawing unit, 19 Wiring design reception unit, 20 PL determination unit, 21 Block diagram creation unit, 22 Output unit, 50 First information, 50a Data set, 60 Second information, 60a Wiring diagram, 60b Block diagram, 70, 70A to 70H, 70I to 70R User interface, 70G Pop-up window, 99 Truth table, 100 Support device, 102 Processor, 104 Memory, 106 Network controller, 110 Storage, 112 System program, 114 Safety design program, 200 Terminal.
Claims
1. A support device that supports the safety design of a target device, comprising: a first generation unit that generates first information including the results of a risk assessment for each of one or more hazards included in the target device based on input to a first user interface including a first group of questions in accordance with the risk assessment; a second generation unit that generates second information indicating the equipment configuration and wiring of safety-related parts based on input to a second user interface for supporting the realization of risk reduction measures for each of the one or more hazards; and a management unit that manages the first information and the second information in association with each other for each of the one or more hazards.
2. The support device described in claim 1, further comprising a first output unit that outputs a first document representing the first information corresponding to each of the one or more hazards and a second document representing the second information corresponding to each of the one or more hazards.
3. A support device as described in claim 1 or 2, wherein the first group of questions includes questions regarding multiple required items required by safety standards, the first generation unit generates the first information in response to obtaining answers to all of the multiple required items, and the first information includes answers to the multiple required items.
4. A support device as described in any one of claims 1 to 3, further comprising a judgment unit that judges the performance level of the safety-related part based on input to a third user interface including an index for evaluating the reliability of each safety device included in the safety-related part and a second group of questions regarding operating status, wherein the first generation unit determines a required performance level for each of the one or more hazards based on the input to the first user interface, and the first information includes the required performance level, the performance level, and a judgment result as to whether the performance level satisfies the required performance level.
5. A support device as claimed in any one of claims 1 to 4, wherein the second user interface includes: a fourth user interface that prompts the user to select a plurality of safety devices that constitute the safety-related part from a plurality of candidate safety devices; and a fifth user interface that prompts the user to select a terminal pair to be connected from a plurality of terminals included in the plurality of safety devices.
6. A support device as described in any one of claims 1 to 5, further comprising a second output unit that provides a sixth user interface in response to selection of a target hazard from among the one or more hazards, wherein the sixth user interface displays the first information corresponding to the target hazard and the second information corresponding to the target hazard.
7. A support device as described in any one of claims 1 to 5, further comprising a second output unit that provides a seventh user interface in response to selection of a target safety device, wherein the seventh user interface displays the second information corresponding to a target safety-related part including the target safety device, and the first information corresponding to a target hazard, among the one or more hazards, whose risk is reduced by the target safety-related part.
8. A support method for supporting the safety design of a target device, comprising: one or more processors generating, for each of one or more hazards included in the target device, first information including the results of implementing the risk assessment based on input to a first user interface including a first set of questions in accordance with the risk assessment; the one or more processors generating, for each of the one or more hazards, second information indicating the equipment configuration and wiring of safety-related parts based on input to a second user interface for supporting the realization of risk reduction measures; and the one or more processors managing, in association with each other, the first information and the second information for each of the one or more hazards.
9. A program that causes a computer to execute a support method for supporting the safety design of a target device, the support method comprising: generating first information including the results of a risk assessment for each of one or more hazards included in the target device, based on input to a first user interface including a first group of questions in accordance with the risk assessment; generating second information indicating the equipment configuration and wiring of safety-related parts for each of the one or more hazards, based on input to a second user interface for supporting the realization of risk reduction measures; and managing the first information and the second information in association with each other for each of the one or more hazards.
Citation Information
Patent Citations
Facility, and method and apparatus for controlling facility
JP2008262490A
Electrical wire interconnect system risk assessment tool
US20070050178A1
Safety automation builder
US20140222383A1
Safety automation builder - integrator
US20230092348A1