Control device
The control device integrates safety and non-safety signal handling units with software processing to dynamically switch signal types, addressing the need for cost-effective expansion without additional hardware, thus reducing system costs and complexity.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- FANUC LTD
- Filing Date
- 2024-11-28
- Publication Date
- 2026-06-04
AI Technical Summary
Existing industrial control devices require additional hardware for both safety and non-safety signals, increasing costs and complexity when expanding connection points, necessitating a cost-effective solution to integrate both types without additional hardware.
A control device with integrated safety and non-safety signal handling units, utilizing redundant CPUs and software processing to switch between signal types, eliminating the need for additional hardware by dynamically configuring signal handling based on user settings.
Enables cost reduction and simplified hardware configuration by allowing flexible switching between safety and non-safety signals without requiring additional hardware, thereby reducing system costs and complexity.
Smart Images

Figure JP2024042197_04062026_PF_FP_ABST
Abstract
Description
Control device
[0001] The present disclosure relates to a control device.
[0002] Signals handled by a control device of an industrial machine include safety signals and non-safety signals that comply with a predetermined safety standard. A safety signal is a duplicated signal, and the control device monitors whether the duplicated signals match each other when the signals are input and output. On the other hand, a non-safety signal represents a general signal that is not a safety signal, and a single signal is used as the non-safety signal. In this regard, Patent Document 1 describes a safety signal system that exchanges safety signals between a numerical control device and an IO unit.
[0003] Japanese Patent Application Laid-Open No. 2013-234300
[0004] Normally, when it is desired to increase the number of connection points for safety signals and non-safety signals connected to a control device, it is necessary to prepare additional hardware called an IO device. Normally, the hardware configuration of an IO device is different for safety signals and non-safety signals. When it is desired to increase the number of connection points for both safety signals and non-safety signals, it is necessary to prepare both types of additional hardware (safety IO devices and normal IO devices). Therefore, in order to provide a control device with a sufficient number of connection points for safety signals and non-safety signals, it is necessary to prepare an IO device with a sufficient number of connection points for each of safety signals and non-safety signals. Even when it is desired to increase the number of connection points for both safety signals and non-safety signals, a technique that can avoid an increase in additional hardware and achieve cost reduction of the system is desired.
[0005] One aspect of the present disclosure is a control device of an industrial machine, including a safety signal control unit that handles duplicated safety signals, a non-safety signal control unit that handles non-safety signals, and a switching unit that can switch whether one or more signals input to or output from the control device are handled by the safety signal control unit as safety signals or by the non-safety signal control unit as non-safety signals.
[0006] These and other objects, features, and advantages of the present invention will become even clearer from the detailed description of typical embodiments of the present invention shown in the accompanying drawings.
[0007] This figure shows the equipment configuration of a robot system including a robot control device according to one embodiment. This figure shows the hardware configuration of the robot control device and the safety I / O device. This figure shows the functional configuration of the first embodiment relating to the function of switching between the handling of non-safety signals by the non-safety signal control unit and the handling of safety signals by the safety signal control unit. This figure shows the functional configuration of the second embodiment relating to the function of switching between the handling of non-safety signals by the non-safety signal control unit and the handling of safety signals by the safety signal control unit. This figure is for explaining the setting of safety signal setting information via a setting screen. This figure shows a setting screen for switching between the handling of non-safety signals by the non-safety signal control unit and the handling of safety signals by the safety signal control unit according to a safety signal different from the safety signal. This figure explains the switching of safety signals when a robot enters or exits a specific area. This figure explains the switching of safety signals when a robot enters or exits a specific area. This is a reference figure showing the equipment configuration of a robot system in the prior art. This figure shows the connection status of external devices to the safety signal connection point of the safety I / O device.
[0008] Next, embodiments of the present disclosure will be described with reference to the drawings. In the drawings, similar components or functional parts are given the same reference numerals. For ease of understanding, the scale of these drawings has been appropriately changed. Furthermore, the embodiments shown in the drawings are just one example of how to carry out the present invention, and the present invention is not limited to the illustrated embodiments.
[0009] External devices connected to a robot control system include safety-related equipment such as emergency stop switches and light curtains. Communication between such external devices and the robot control system is typically conducted using redundant safety signals compliant with predetermined safety standards. The robot control system uses redundant CPUs (Central Processing Units) to mutually confirm the status of these redundant signals. On the other hand, external devices connected to the robot control system that constitute the robot system include devices that input and output normal signals (non-redundant signals), such as hands, regular switches, and cameras. These normal signals, which differ from safety signals (redundant signals), are called non-safety signals.
[0010] Generally, in order to provide a robot control device with a sufficient number of connection points for safety signals, additional hardware for safety signals (safety I / O devices) must be provided. Similarly, in order to provide a sufficient number of connection points for non-safety signals, additional hardware for non-safety signals (standard I / O devices) must be provided. A reference diagram of the equipment configuration of a robot system in such conventional technology is shown in Figure 8. Robot system 1 includes a robot 2, a robot control device 5, and a teaching control panel 4. As shown in the reference diagram in Figure 8, in order to connect a light curtain 80, which is an external device corresponding to safety signals, to the robot control device 5, a dedicated safety I / O device 70 corresponding to safety signals is connected to the robot control device 5, and the light curtain 80 is connected via the connection point of the safety I / O device 70. The light curtain 80 is a detection device that detects when an object passes through a detection area and outputs a detection signal as a safety signal (duplex signal). On the other hand, in order to connect ordinary external devices such as ordinary switches 91 and 92 to the robot control device 5, an ordinary I / O device 85 is connected to the robot control device 5, and the switches 91 and 92 are connected via the connection points of the I / O device 85.
[0011] Conventionally, when increasing the number of connection points for both safety signals and non-safety signals, it is necessary to add expansion hardware of both types: safety I / O devices 70 for safety signals and I / O devices 85 for non-safety signals to the robot system 1. In contrast, the robot control device according to this embodiment, as described below, eliminates the need to add expansion hardware of both types, safety I / O devices and normal I / O devices, even when increasing the number of connection points for both safety signals and non-safety signals, thereby reducing the cost of the robot system in such cases.
[0012] Figure 1 shows the equipment configuration of a robot system 100 including a robot control device 50 according to one embodiment. The robot system 100 includes a robot 10, a robot control device 50 that controls the robot 10, and a teaching control panel 40 connected to the robot control device 50.
[0013] A light curtain 80, which is an external device corresponding to a safety signal, is connected to the robot control device 50 via a safety I / O device 70 that corresponds to a safety signal. In this embodiment, switches 91 and 92, which are external devices that output non-safety signals, may be connected to the connection point of the safety I / O device 70. As will be described in detail below, the robot control device 50 is configured to switch whether to treat the signal connected to the connection point of the safety I / O device 70 as a safety signal or as a non-safety signal.
[0014] In Figure 1, robot 10 is shown as an example of a vertical articulated robot, but various types of robots may be used as robot 10 depending on the task, such as a horizontal articulated robot, a parallel link robot, or a dual-arm robot. Robot 10 can perform desired tasks using an end effector attached to its wrist. The end effector is an external device that can be replaced depending on the application, such as a hand, welding gun, or tool.
[0015] The robot control device 50 controls the movement of the robot 10 according to the operation program or commands from the teaching control panel 40.
[0016] Figure 2 shows the hardware configuration of the robot control device 50 and the safety I / O device 70. The robot control device 50 is configured as a system capable of processing safety signals, and includes redundant CPUs 51a and 51b. The robot control device 50 includes CPU 51a, CPU 51b, memory 52a, memory 52b, and a communication controller 55. CPU 51a can access memory 52a, and CPU 51b can access memory 52b. CPU 51a and CPU 51b may communicate with each other. The communication controller 55 is connected to memories 52a and 52b via a dedicated bus. The communication controller 55 includes a DMA (Dynamic Memory Access) controller 55a. The DMA controller 55a can access predetermined areas of memories 52a and 52b according to the settings in the setting registers.
[0017] The robot control device 50 is equipped with a storage device 53, a servo controller 54, a communication controller 56, an input / output interface 57, etc., and these components are connected to the CPU (51a, 51b) via a bus. The storage device 53 consists of, for example, non-volatile memory or a hard disk drive. The storage device 53 stores an operation program for controlling the robot 10, various setting information, etc.
[0018] A safety I / O device 70 is connected to the communication controller 55 of the robot control device 50 via a serial communication channel 75 that conforms to a predetermined communication standard. The robot control device 50 exchanges DI / DO data signals (input signals / output signals) with the safety I / O device 70 via the communication controller 55, the communication channel 75, and the communication controller 71. The safety I / O device 70 is equipped with redundant communication controllers 71 and 72, and can exchange redundant DI data signals or redundant DO data signals with external devices (such as a light curtain 80). The communication controller 71 is equipped with a receiver 71a and a driver 71b for inputting and outputting DI data signals / DO data signals with external devices. The communication controller 72 is equipped with a receiver 72a and a driver 72b for inputting and outputting DI data signals / DO data signals with external devices.
[0019] In relation to safety signals (duplication signals), when we refer to a single connection point, we are talking about the input point of the two duplicated signals (DI signals) or the output point of the two duplicated signals (DO signals). Therefore, the input points 71c, 72c of the two signals to the receivers 71a, 72a of the duplicated communication controllers 71, 72 shown in Figure 2, or the output points 71d, 72d of the two signals from the drivers 71b, 72b of the duplicated communication controllers 71, 72, correspond to a single connection point of the safety signal. The safety I / O device 70 is equipped with the same number of configurations consisting of the illustrated duplicated communication controllers 71, 72 as there are connection points of the safety signal.
[0020] For example, Figure 9 shows the configuration of the input / output connector 70a of the safety I / O device 70 when the safety I / O device 70 supports 10 connection points for safety signals. The redundant signal lines K1 and K2 from the light curtain 80 are connected to the two input points of one of the 10 safety signal connection points, CP1. In addition, the non-safety signals from switches 91 and 92 can each be connected to the two input points of one of the safety signal connection points, CP2.
[0021] The communication controller 55 of the robot control device 50 operates as a master, and the communication controllers 71 and 72 of the safety I / O device 70 operate as slaves, communicating one-to-one in a master-slave configuration. The communication controller 55 can be automatically started at a fixed interval or at any arbitrary timing by an external start signal. When the communication controller 55 is started, the DMA controller 55a can acquire DO data from predetermined areas on the memories 52a and 52b according to the settings in the setting register. The communication controller 55 can transmit the acquired DO data to the communication controllers 71 and 72 via the communication path 75. The DMA controller 55a can also store DI data acquired from the communication controllers 71 and 72 in predetermined areas of the memories 52a and 52b. The CPUs 51a and 51b can access predetermined areas of the memories 52a and 52b and process the DO data and DI data, respectively.
[0022] The teaching control panel 40 is used as an operating terminal for teaching the robot 10 and performing various settings. A teaching device consisting of a tablet terminal or the like may be used as the teaching control panel 40. The teaching control panel 40 may have a hardware configuration as a general computer, including a processor, memory (ROM, RAM, non-volatile memory, etc.), storage device, display unit 41, operation unit 42, input / output interface, network interface, etc. (see Figures 1 and 2).
[0023] The following describes two configuration examples (the first and second embodiments) for enabling the switching between treating two signals connected to the connection point of the safety I / O device 70 as safety signals and treating them as non-safe signals. For convenience of explanation, this switching function may be referred to as the "safe signal / non-safe signal switching function" below. Both the first and second embodiments are configurations realized by software processing by the CPU of the robot control device 50 (either CPU 51a or CPU 51b, or the cooperation of CPU 51a and CPU 51b), and it should be noted that the safety I / O device 70 does not need to have a specific hardware or software configuration to achieve the above switching function; in other words, conventional safety I / O devices can be applied to the robot system 100.
[0024] (First Embodiment) Figure 3 is a diagram showing a functional block configuration that realizes the safety signal / non-safety signal switching function according to the first embodiment. The functional configuration in Figure 3 can be realized as software processing by either CPU 51a or CPU 51b, or by the cooperation of CPU 51a and CPU 51b. For this reason, in Figure 3, the CPU is represented by reference numeral 51. As shown in Figure 3, the functional block that realizes the safety signal / non-safety signal switching function includes a non-safety signal control unit 151, a safety signal control unit 152, a switching unit 153, and a setting unit 154. The functional block that realizes the safety signal / non-safety signal switching function may also include a switching diagnostic unit 158 that has the function of determining whether the switching of the safety signal / non-safety signal via the setting unit 154 has been successful or failed. Details of the function of the switching diagnostic unit 158 will be described later.
[0025] Figure 3 illustrates the motion control unit 171, which controls the robot 10 according to the motion program 180. The motion control unit 171 sends commands for each axis of the robot 10, generated according to the motion program 180, to the servo controller 54. The servo controller 54 performs servo control for the servo motors of each axis according to the commands from the motion control unit 171.
[0026] Here, we assume the handling of the case where a DI signal is input to the safety I / O device 70, and the two signals (two DI signals) input to one connection point of the safety I / O device 70 (for example, connection point CP1 or CP2 in Figure 9) will be referred to as signal 1 and signal 2. In this case, the data of signal 1 and the data of signal 2 are stored in memory 52a and memory 52b, respectively, by the function of the communication controller 55, and become accessible from CPU 51a and CPU 51b.
[0027] The storage device 53 stores a table (safety signal setting information 155) that defines whether the 10 safety signal connection points of the safety I / O device 70 should be treated as safety signals or non-safety signals. The contents of this safety signal setting information 155 can be set by the user via the setting function of the setting unit 154. An example of the settings of the safety signal setting information 155 is shown in Table 1 below. As shown in Table 1, the safety signal setting information 155 includes information that defines whether each safety signal connection point should be treated as a safety signal or a non-safety signal. Table 1 below shows an example in which the first connection point and the third to tenth connection points are used as safety signal connection points, and the two signal input points of the second connection point are set as non-safety signal input points.
[0028]
[0029] The setting unit 154 may be configured to display a setting screen (user interface) for setting safety signal setting information 155 on the display unit 41 of the teaching operation panel 40, and to accept the setting of safety signal setting information 155 through this setting screen.
[0030] The switching unit 153, by referring to the safety signal setting information 155, grants the safety signal control unit 152 access rights for the two signals of the connection point to be processed if the connection point to be processed is set to "safety signal enabled," but does not grant the non-safety signal control unit 151 access rights for the two signals. On the other hand, if the switching unit 153 grants the non-safety signal control unit 151 access rights for the two signals of the connection point if the connection point to be processed is set to "safety signal disabled (non-safety signal)," it does not grant the safety signal control unit 152 access rights for the two signals.
[0031] Assume that the safety signal of the light curtain 80 is connected to the first connection point. In this case, the switching unit 153 grants the safety signal control unit 152 the authority to access a predetermined area of the memory space where the safety signal from the first connection point is stored, according to the safety signal setting information 155 in Table 1. Therefore, the safety signal control unit 152 can access the data from the light curtain 80 (safety signal 163 in Figure 3).
[0032] The safety signal control unit 152 may have a function to perform a predetermined diagnosis on the duplicated safety signal. The predetermined diagnosis by the safety signal control unit 152 may include at least one of the following: a function to check whether the two signals match or not, and a function to check whether the signal is stuck or malfunctioning. In the function to check whether the two signals match or not, the safety signal control unit 152 determines that the duplicated safety signal is abnormal if the two signals do not match. Therefore, in this case, the detection signal from the light curtain 80 is not treated appropriately. If the safety signal is determined to be abnormal, the safety signal control unit 152 may, in cooperation with the motion control unit 171, stop the driving of each motor of the robot 10 and move the entire robot system to a safe state. On the other hand, if the two signals match, the detection signal from the light curtain 80 indicated by the safety signal is treated appropriately. For example, in this case, the safety signal control unit 152 may, in cooperation with the motion control unit 171, execute a predetermined hazard avoidance operation of the robot 10 in response to the detection signal from the light curtain 80.
[0033] The function to check whether the signal is stuck may be performed by checking whether the safety signal information (safety signal 163 in Figure 3) read by the safety signal control unit 152 is switched on and off while the safety signal is forcibly switched on and off by an external device. Alternatively, the function to check whether the signal is stuck may be performed by checking whether the safety signal information (safety signal 163 in Figure 3) read by the safety signal control unit 152 is switched on and off while the data in the memory area of the safety signal inside the robot control device 50 is forcibly switched on and off. Note that this type of stuck failure check may be performed, for example, by setting a test period of a certain duration during the operation of the robot control device 50 and performing the check during this test period. In this case, the safety signal control unit 152 will retain the control state immediately before the start of the test period (such as the state of the safety signal before the test period).
[0034] On the other hand, assume that signals from switches 91 and 92 are input to the second connection point of the safety I / O device 70. As described above, these signals are represented as signal 1 and signal 2 in Figure 3. Due to the functions of the communication controllers 71 and 72 of the safety I / O device 70, the data for signals 1 and 2 are stored in predetermined areas of the memory space. In Figure 3, the data for signals 1 and 2 stored in the memory space are represented by dashed blocks as non-safety signal 1 (reference numeral 161) and non-safety signal 2 (reference numeral 162). Non-safety signal 1 (reference numeral 161) is data representing the ON / OFF state of switch 91, and non-safety signal 2 (reference numeral 162) is data representing the ON / OFF state of switch 92.
[0035] The switching unit 153 grants the non-safety signal control unit 151 access rights to signals 1 and 2 when the processing target is the second connection point, according to the safety signal setting information 155 in Table 1. Therefore, the non-safety signal control unit 151 can read the data of non-safety signal 1 (reference numeral 161) and non-safety signal 2 (reference numeral 162). The non-safety signal control unit 151 can perform predetermined control in cooperation with the operation control unit 171 according to the ON / OFF state of switch 91 or the ON / OFF state of switch 92.
[0036] As described above, according to the configuration of the first embodiment, it is possible to switch whether the DI signal input to the safety signal connection point of the safety I / O device 70 is treated as a safety signal or a non-safety signal, according to the preset setting information. As illustrated in Table 1, if the safety I / O device 70 has 10 safety signal connection points, it is possible to set them to a desired state, whether to use them as safety signal connection points or as non-safety signal input points.
[0037] Therefore, according to the configuration of the first embodiment, when increasing the number of connection points for both safety signals and non-safety signals, it is possible to eliminate the need to add additional hardware of both safety I / O devices and normal I / O devices, thereby reducing the cost of the robot system in such cases.
[0038] Furthermore, even when the CPU 51 handles the DO signal, the switching unit 153 can switch between two functions: one that generates a duplicated DO signal in accordance with the safety signal setting information 155 and outputs it via the connection point of the safety I / O device 70 to the safety signal control unit 152, and another that outputs one or two DO signals via the connection point of the safety I / O device 70 to the non-safety signal control unit 151. In this case as well, similar to the first embodiment regarding the DI signal described above, when increasing the number of connection points for both safety signals and non-safety signals, the need to add additional hardware of both safety I / O devices and normal I / O devices is eliminated, thereby reducing the cost of the robot system in such cases.
[0039] (Second Embodiment) Figure 4 is a diagram showing the functional block configuration that realizes the safety signal / non-safety signal switching function according to the second embodiment. The functional configuration in Figure 4 is realized as software processing by either CPU 51a or CPU 51b, or by the cooperation of CPU 51a and CPU 51b. For this reason, in Figure 4, the CPU is represented by reference numeral 51. In Figure 4, functional blocks that have substantially the same function as the functional blocks of the first embodiment are given the same reference numerals.
[0040] As shown in Figure 4, the functional block that implements the safety signal / non-safety signal switching function according to the second embodiment includes a non-safety signal control unit 151, a safety signal control unit 152a, a switching unit 153, a setting unit 154, and a safety signal diagnostic unit 157. The functional block that implements the safety signal / non-safety signal switching function may also include a switching diagnostic unit 158 that has the function of determining whether the switching of safety signals / non-safety signals via the setting unit 154 has been successful or failed. Details of the functions of the switching diagnostic unit 158 will be described later.
[0041] The safety signal diagnostic unit 157 is responsible for performing a predetermined diagnosis on the safety signal input from the safety signal connection point. The predetermined diagnosis by the safety signal diagnostic unit 157 may include at least one of the following: a function to check whether two signals match or not, and a function to check whether the signal is stuck or malfunctioning. If the safety signal diagnostic unit 157 has a function to check whether the signal is stuck or malfunctioning, the safety signal diagnostic unit 157 can function as a signal malfunction diagnostic unit.
[0042] The function to check whether a signal is stuck or faulty may be performed by checking whether the safety signal information (safety signal 163 in Figure 3) read by the safety signal control unit 152a is switched on and off while an external device forcibly switches the safety signal on and off. Alternatively, the function to check whether a signal is stuck or faulty may be performed by checking whether the safety signal information (safety signal 163 in Figure 4) read by the safety signal control unit 152a is switched on and off while the safety signal diagnostic unit 157 forcibly switches the data in the memory area of the safety signal on and off. Note that such a check for stuck or faulty signals may be performed, for example, by setting a test period during the operation of the robot control device 50 and performing the check during this test period. In this case, the safety signal control unit 152a will retain the control state immediately before the start of the test period (such as the state of the safety signal before the test period).
[0043] Therefore, in the second embodiment, the safety signal control unit 152a does not need to have a function that controls the execution of a predetermined diagnosis.
[0044] The switching unit 153 sets the validity / invalidity of a predetermined diagnosis by the safety signal diagnosis unit 157 according to the setting information as exemplified in Table 1 above. For example, when one connection point of the safety signal is set to be safety signal valid, the switching unit 153 makes a predetermined diagnosis by the safety signal diagnosis unit 157 valid for the safety signal from that connection point.
[0045] Assume that the processing target is the signal of the first connection point and the first connection point is set to be safety signal valid in the safety signal setting information 155. In FIG. 4, two signals taken into the memory space of the CPU 51 via the first connection point are represented as signal 1 and signal 2. In this case, the switching unit 153 makes a predetermined diagnosis by the safety signal diagnosis unit 157 valid. The safety signal diagnosis unit 157 provides the safety signal control unit 152a with the result of the predetermined diagnosis and the safety signal 163. If the result of the predetermined diagnosis is OK, the safety signal control unit 152 takes in the data represented by the taken-in safety signal 163 as appropriate data and performs processing on the data. For example, when the taken-in safety signal 163 is the detection result from the light curtain 80, the safety signal control unit 152a executes danger avoidance control according to the detection result in cooperation with the operation control unit 171. When the result of the predetermined diagnosis on the safety signal by the safety signal diagnosis unit 157 is abnormal, the safety signal control unit 152a may operate to stop the driving of each motor of the robot 10 and shift the entire robot system to a safe state by cooperating with the operation control unit 171.
[0046] Next, assume that the target of the process is the signal at the first connection point and the first connection point is set to be a non-safe signal (non-safe signal) in the safety signal setting information 155. In this case, the switching unit 153 invalidates the predetermined diagnosis by the safety signal diagnosis unit 157. Therefore, in this case, the safety signal diagnosis unit 157 provides the two signals (signal 1, signal 2) captured from the first connection point as they are to the non-safe signal control unit 151 as non-safe signal 1 (reference numeral 161) and non-safe signal 2 (reference numeral 162). The non-safe signal control unit 151 executes control according to the non-safe signal 1 (reference numeral 161) and the non-safe signal 2 (reference numeral 162). For example, if the non-safe signal 1 (reference numeral 161) and the non-safe signal 2 (reference numeral 162) are signals from the switches 91 and 92 respectively, the non-safe signal control unit 151 executes control according to the ON / OFF states of the switches 91 and 92 in cooperation with the operation control unit 171.
[0047] As described above, even in the case of the configuration of the second embodiment, whether to handle the DI signal input to the connection point of the safety signal of the safety IO device 70 as a safety signal or as a non-safe signal can be switched according to the preset setting information. Therefore, according to the configuration of the second embodiment, when increasing the number of connection points for both the safety signal and the non-safe signal, the necessity of adding additional hardware of both types of the safety IO device and the normal IO device is eliminated, and the cost of the robot system in such a case can be reduced.
[0048] The configuration of the second embodiment described above can be said to be a configuration that realizes the safety signal / non-safe signal switching function by switching the validity / invalidity of the function of the safety signal diagnosis unit 157 by the switching unit 153.
[0049] The above is the description of the safety signal / non-safe signal switching function according to the first embodiment and the second embodiment. In both the first embodiment and the second embodiment, the switching unit 153 controls to switch whether the safety signal control units 152 and 152a handle one or more signals input to or output from the robot control device 50 as a safety signal or the non-safe signal control unit 151 handles them as a non-safe signal.
[0050] Next, the setting function of the setting unit 154 via the setting screen (user interface) for setting safety signal setting information 155 will be explained. Figure 5 is a diagram illustrating the setting of safety signal setting information 155 via the setting screen 200, which is generated by the setting unit 154 and displayed on the display unit 41 of the teaching operation panel 40. The setting screen 200 shows the setting status of the 10 safety signal connection points (SFDI(1) to SFDI(10)) of the safety I / O device 70. Here, 'ENABLE' represents the setting to enable the safety signal, and 'DISABLE' represents the setting to disable the safety signal (non-safety signal).
[0051] The top setting screen 200 in Figure 5 displays the current setting status of the safety signal setting information 155. The first connection point (SFDI(1)) indicated by reference numeral 201 is set to 'ENABLE' (safety signal enabled). Users who wish to use the first connection point (SFDI(1)) for non-safety signals can select 'DISABLE' (safety signal disabled) as the setting for the first connection point (SFDI(1)), as shown in the middle setting screen 200 in Figure 5. This operation may be performed, for example, by selecting the setting information for the first connection point (SFDI(1)) and then pressing the 'CHOICE' button (reference numeral 211) at the bottom of the screen to select either 'ENABLE' or 'DISABLE'.
[0052] When the user presses the 'APPLY' button (reference numeral 212) in the middle setting screen 200 of Figure 5, after making a selection using the 'CHOICE' button (reference numeral 211), an input field 202 prompting the user to enter a password is presented, as shown in the bottom setting screen 200 of Figure 5. In this case, the edited settings are formally applied to the security signal setting information 155 only if the password entered in the input field 202 matches a pre-stored password. This enhances security against changes to the security function. In other words, it prevents situations where an unauthorized user accidentally applies settings inadvertently. Furthermore, even for authorized users, introducing a user authentication process after changing settings and before applying those changes prevents situations where incorrect settings are applied inadvertently (for example, it prevents the application of a setting that a user has accidentally switched to a non-security signal).
[0053] Here, we have described an example of enhancing security against changes to security features by requiring a password when the user presses the 'APPLY' button. However, if security against changes to security features is already ensured (for example, if the user authentication process is performed when the system starts up), then password authentication at this stage may be omitted.
[0054] Furthermore, while this example describes user authentication by password entry when the user presses the 'APPLY' button, other authentication methods (e.g., facial recognition) may be used as long as user authentication can be performed.
[0055] If a password mismatch is detected during user authentication using a password, the edited settings will not be applied, and a message notifying the user of the password mismatch may be displayed, for example, on the settings screen 200 at the bottom of Figure 5.
[0056] The settings unit 154 controls user operations and user authentication related to the settings screen 200 as described above.
[0057] In this way, the user can set the safety signal setting information 155 to a desired state via the setting screen 200 (user interface) displayed on the display unit 41 of the teaching operation panel 40.
[0058] From the standpoint of ensuring safety in switching between safety signals and non-safe signals, the robot control device 50 may further include a function to detect whether the switching between safety signals and non-safe signals was successful or unsuccessful after applying the setting switch via the setting unit 154. The following describes a function for diagnosing whether the switching between safety signals and non-safe signals was successful or unsuccessful. The CPU 51 may include a switching diagnostic unit 158 as a component responsible for this diagnostic function (see Figures 3 and 4). The switching diagnostic unit 158 performs this diagnostic function independently of the non-safe signal control unit 151 and the safety signal control units (152, 152a), and is responsible for ensuring safety in switching between safety signals and non-safe signals.
[0059] If the above password input is successful and the setting for separating safe and unsafe signals is applied as safe signal setting information 155, the switching diagnostic unit 158 may determine that the switching has failed, consider it an abnormal state, and take measures to transition the robot system to a safe state, such as stopping the robot 10. Alternatively, if the switching diagnostic unit 158 determines that the switching of safe and unsafe signals via the setting unit 154 has failed (or if the success of the switching cannot be confirmed), it may operate in a way that prevents the application of the changed setting information via the setting unit 154. In this case as well, the switching diagnostic unit 158 may consider the robot system to be in an abnormal state and guide the robot system to a safer state. Note that even in configurations where user authentication by password or the like is not used, the diagnostic function of the switching diagnostic unit 158 described here may be applied.
[0060] The following describes two operational examples of how the switching diagnostic unit 158 determines whether the switching between safe and unsafe signals was successful or unsuccessful.
[0061] (First Operation Example) In the first operation example, the switching diagnostic unit 158 determines whether the CPU 51 is reading / writing to a memory area (a memory area within memory 52a or memory 52b) used to exchange DI / DO signals for a certain port as a safe signal or as an unsafe signal. The switching diagnostic unit 158 can then determine that the switching has failed if, despite the switching of the port from a safe signal to an unsafe signal, the CPU 51 attempts to read / write to the memory area as a safe signal, or if, despite the switching of the port from an unsafe signal to a safe signal, the CPU 51 attempts to read / write to the memory area as an unsafe signal. More specifically, the switching diagnostic unit 158 can determine that the switching has failed if, despite the switching of the port from a safe signal to an unsafe signal, the safe signal control unit (152, 152a) reads / writes to the memory area, or if, despite the switching of the port from an unsafe signal to a safe signal, the unsafe signal control unit 151 reads / writes to the memory area.
[0062] (Second Operation Example) In the second operation example, the switching diagnostic unit 158 determines whether the switching was successful or unsuccessful based on the signal usage status. For example, consider a case where the setting for a certain port is switched from a safe signal to an unsafe signal while the robot 10 is in operation. In this case, even though the signal has been switched from a safe signal to an unsafe signal, if the CPU 51 continues to receive the same signal value after a predetermined time has elapsed, it can be determined that the switching has failed. In this case, it is desirable that the predetermined time be a sufficiently long time, such as one hour, half a day, or one day. This is because if the signal value received by the CPU 51 does not change for a relatively long time, it can be considered that the switching from a safe signal to an unsafe signal has not been performed (a failed state). Similarly, even if the signal has been switched from an unsafe signal to a safe signal, if the CPU 51 continues to receive the same signal value after a predetermined time has elapsed, it can also be determined that the switching from an unsafe signal to a safe signal has failed.
[0063] In the second example of operation described above, the operation was described in which the predetermined time for monitoring whether the signal values are the same after switching between a safe signal and a non-safe signal is set to a sufficiently long time. However, the predetermined time for monitoring may be a short time (for example, one second). When the predetermined time for monitoring is set to a short time, the external device connected to the port and the robot control device 50 shall operate according to the following operation specifications. For example, after switching a port from a safe signal to a non-safe signal, the external device connected to that port operates to make the two signals as non-safe signals mismatch for a certain period (for example, one second). The robot control device 50 (CPU 51) determines that the switch from a safe signal to a non-safe signal was successful by confirming that the two signals have become mismatched. If the two signals as non-safe signals do not become mismatched during this certain period, the switching diagnostic unit 158 can determine that the switch has failed. Furthermore, during a certain period of time when the switching diagnostic unit 158 waits for the two signals to become mismatched, the switching diagnostic unit 158 may take measures to prevent the memory area from being used, such as fixing the signal value in the memory area of the port to on or off.
[0064] Based on the first and second operation examples described above, it is possible to determine whether the switching of the safety signal / unsafe signal via the setting unit 154 has been successful or unsuccessful, thereby ensuring safety during the switching between the safety signal and the unsafe signal.
[0065] The switching unit 153 may have a function to switch whether two signals connected to the safety signal connection point of the safety I / O device 70 are used as safety signals or non-safety signals, according to a specific signal. For example, the switching unit 153 may have a function to switch whether two signals connected to the safety signal connection point of the safety I / O device 70 are used as safety signals or non-safety signals, according to a safety signal generated inside the robot control device 50. An example of a configuration that realizes such a function will be described below.
[0066] The setting unit 154 presents a setting screen that allows switching between using two signals connected to the safety signal connection point of the safety I / O device 70 as safety signals or non-safety signals, depending on a safety signal different from the aforementioned safety signal. Figure 6 shows an example of such a setting screen 220. Here, as an example, we will consider an example in which the robot control device 50 switches between using two signals connected to the safety signal connection point of the safety I / O device 70 as safety signals or non-safety signals in response to a safety signal generated when the robot 10 enters a predetermined area in the workspace. The safety signal generated when the robot 10 enters a predetermined area in the workspace will be referred to here as the safety signal CPC. The safety signal CPC is a signal that turns ON when the control point (e.g., TCP (Tool Center Point)) of the robot 10 enters a predetermined area R in the workspace, and turns OFF when the control point (TCP) of the robot 10 is outside area R, as illustrated in Figures 7A and 7B. In other words, the safety signal CPC is a signal that turns on and off when the robot 10 enters and exits a specific area.
[0067] The user can configure the settings via the setting screen 220 displayed on the display unit 41 of the teaching operation panel 40 to switch between using two signals connected to the safety signal connection points of the safety I / O device 70 as safety signals or non-safety signals, according to the safety signals. The setting screen 220 has a field (reference numeral 221) for setting a specific signal to apply to the switching for the 10 safety signal connection points (SFDI(1) to SFDI(10)) of the safety I / O device 70, and a field 222 for showing the status of safety signal application for each connection point (SFDI(1) to SFDI(10)). In Figure 6, the first connection point (SFDI(1)) is set to be used as a safety signal when the safety signal CPC is ON. In this case, when the safety signal CPC is OFF, the signal at the first connection point (SFDI(1)) is used as a non-safety signal. The settings shown in Figure 6 are stored as safety signal setting information 155.
[0068] The switching unit 153 can switch whether to use the two signals connected to the safety signal connection point of the safety I / O device 70 as safety signals or non-safety signals, according to the safety signal setting information 155 which reflects the contents of the setting screen 220 in Figure 6, and in accordance with the safety signal CPC (see Figures 3 and 4) input to the switching unit 153.
[0069] The above-described configuration example, with reference to Figures 6 and 7A-7B, dynamically switches whether a signal input to the same connection point (first connection point) of the safety I / O device 70 is considered a safety signal or a non-safe signal, depending on the CPC signal. Therefore, in this case, the external device connected to the first connection point also needs to have a function to switch between sending a safety signal and sending a non-safe signal. In such a case, for example, the robot control device 50 and the external device connected to the first connection point are connected via a control device such as a PLC (Programmable Logic Controller). The CPC signal generated inside the robot control device 50 is then provided to the PLC. With such a configuration, the external device can operate under the control of the PLC to send a safety signal when the CPC signal is ON, and to switch its operation to send a non-safe signal when the CPC signal is OFF. Alternatively, in such cases, the notification from the robot control device 50 to the external device instructing the switching between sending a safety signal and sending a non-safety signal can be realized by (1) a configuration in which the robot control device 50 sends the notification to the external device via a network, or (2) a configuration in which a connection point pre-set as a non-safety signal of the safety I / O device 70 is used as a communication path for sending the notification from the robot control device 50 to the external device.
[0070] In the above, an example configuration was described in which the signal input from an external device to the same connection point (first connection point) of the safety I / O device 70 is dynamically switched between being a safety signal and a non-safe signal. However, equivalent functionality may be realized by the following configuration. For example, an external device may be connected to the robot control device 50 using two connection points: a connection point for safety signals and a connection point for non-safe signals. When the CPC signal is ON, the external device sends a safety signal to the robot control device 50 using the connection point for safety signals, and when the CPC signal is OFF, it sends a non-safe signal to the robot control device 50 using the connection point for non-safe signals. With such a configuration, it is also possible to switch whether the signal from the external device is used as a safety signal or a non-safe signal depending on the CPC signal. In this case as well, the device configuration for notifying the external device of the switching between safety signals and non-safe signals from the robot control device 50 can be one of the above-described configurations: notification via PLC, notification via network, or notification using the connection point for non-safe signals.
[0071] As described above, according to this embodiment, when increasing the number of connection points for both safety signals and non-safety signals, it is possible to eliminate the need to add additional hardware of both safety I / O devices and normal I / O devices, thereby reducing the cost of the robot system in such cases.
[0072] The above-described embodiment relates to a configuration in which the robot control device can switch, as an internal function, whether to use two signals connected to the connection point of a safety signal of a safety I / O device as a safety signal or as two non-safe signals. The above-described effect realized by this configuration can also be achieved by a configuration in which the robot control device can switch, as an internal function, whether to use two signals connected to the two input points (or two output points) of a normal I / O device as two non-safe signals or as a redundant safety signal. In this case, when increasing the number of connection points for both safety and non-safe signals, it is sufficient to provide a normal I / O device, and there is no need to provide a separate safety I / O device for safety signals. The two signals input to the two input points of a normal I / O device are denoted as signal 1 and signal 2. Signals 1 and 2 are stored in a predetermined memory area within the robot control device 50 and are accessible from the CPU 51. Therefore, even in this case, the CPU 51 can process signals 1 and 2 stored in the memory area as either a safety signal or as two non-safe signals. Therefore, it is possible to configure the robot control device 50 to allow switching as an internal function whether the two signals connected to the two input points (or two output points) of a normal I / O device are used as two non-safety signals or as a redundant safety signal.
[0073] The configuration of the above-described embodiment relates to a configuration that realizes a "safety signal / non-safety signal switching function" in a robot control device. The "safety signal / non-safety signal switching function" can be applied not only to robot control devices but also to control devices of various industrial machines such as machine tool control devices (numerical control devices).
[0074] The program that performs the processing to realize the "safe signal / unsafe signal switching function" in the above-described embodiment can be recorded on various computer-readable recording media (for example, semiconductor memory such as ROM, EEPROM, and flash memory, magnetic recording media, optical discs such as CD-ROM and DVD-ROM).
[0075] While this disclosure has been described in detail, it is not limited to the individual embodiments described above. These embodiments can be added, replaced, modified, partially deleted, etc., in any way that does not depart from the gist of this disclosure or from the spirit of this disclosure derived from the claims and their equivalents. Furthermore, these embodiments can be implemented in combination. For example, the order of operations and processes in the embodiments described above are shown as examples only and are not limited thereto. The same applies when numerical values or mathematical formulas are used in the description of the embodiments described above.
[0076] The following additional notes are provided with respect to the above embodiments and modified examples. (Note 1) A control device (50) for an industrial machine (10), comprising: a safety signal control unit (152, 152a) that handles duplicated safety signals; a non-safety signal control unit (151) that handles non-safety signals; and a switching unit (153) that can switch whether one or more signals input to or output from the control device (50) are handled as safety signals by the safety signal control unit (152, 152a) or as non-safety signals by the non-safety signal control unit (151). (Note 2) The control device (50) according to Note 1, wherein the safety signal control unit (152) has a function to perform a predetermined diagnosis on safety signals. (Note 3) The control device (50) according to Note 1, comprising a safety signal diagnostic unit (157) having a function to perform a predetermined diagnosis relating to safety signals, wherein the safety signal control unit (152a) treats one or more signals as safety signals based on the results of the predetermined diagnosis when the switching unit (153) enables the execution of the predetermined diagnosis by the safety signal diagnostic unit (157), and the non-safety signal control unit (151) treats one or more signals as non-safety signals when the switching unit disables the execution of the predetermined diagnosis by the safety signal diagnostic unit (157). (Note 4) The control device (50) according to Note 2 or 3, wherein the predetermined diagnosis includes at least one of detecting the match or mismatch of duplicated safety signals or detecting a stuck failure of duplicated safety signals. (Note 5) The control device (50) according to any one of Notes 1 to 4, wherein the switching unit (153) switches whether one or more of the signals are handled as safety signals by the safety signal control unit (152, 152a) or as non-safety signals by the non-safety signal control unit (151) according to user operation. (Note 6) The control device (50) according to any one of Notes 1 to 4, wherein the switching unit (153) switches whether one or more of the signals are handled as safety signals by the safety signal control unit (152, 152a) or as non-safety signals by the non-safety signal control unit (151) according to predetermined setting information.(Note 7) The control device (50) according to Note 6, comprising a setting unit (154) that accepts user operations to set the setting information, wherein the setting unit (154) requests the input of a password when a user operation to change the setting information is performed, and makes the changed setting information applicable when the input password matches a password that has been registered in advance. (Note 8) The control device (50) according to any one of Notes 1 to 4, comprising a storage unit (53) that stores setting information that defines whether, for each of a plurality of connection points for redundant safety signals, two signals input or output through each connection point are to be handled by the safety signal control unit (152, 152a) as safety signals or by the non-safety signal control unit (151) as non-safety signals, wherein the switching unit (153) switches whether, for each of the plurality of connection points, two signals input or output are to be handled by the safety signal control unit (152, 152a) as safety signals or by the non-safety signal control unit (151) as non-safety signals, according to the setting information. (Note 9) The control device (50) according to Note 8, further comprising a setting unit (154) that accepts a user operation to set the setting information stored in the storage unit (53). (Note 10) The control device (50) according to Note 9, wherein the setting unit (154) requests the input of a password when a user operation is made to change the setting information stored in the storage unit (53), and makes the changed setting information applicable when the input password matches a password that has been registered in advance. (Note 11) The control device according to any one of Notes 5 to 10, further comprising a switching diagnostic unit (158) that diagnoses whether the switching by the switching unit regarding whether to treat a signal input to or output from the control device as a safe signal or as a non-safe signal has been successful or failed. (Note 12) The control device according to Note 11, wherein the switching diagnostic unit (158) operates so that the instruction or setting for the switching to the switching unit is not applied when it is diagnosed that the switching by the switching unit has failed.(Note 13) The control device (50) according to any one of Notes 1 to 4, wherein the switching unit (153) switches whether one or more of the signals are handled as safety signals by the safety signal control unit (152, 152a) or as non-safety signals by the non-safety signal control unit (151) depending on the state of a specific signal. (Note 14) The control device (50) according to Note 13, wherein the specific signal is a safety signal that is switched when the robot (10) as the industrial machine (10) enters or exits a specific area in the work space.
[0077] 10 Robot 40 Teaching control panel 41 Display unit 42 Operation unit 51, 51a, 51b CPU 52a, 52b Memory 53 Storage unit 54 Servo controller 55, 56 Communication controller 57 Input / output interface 70 Safety I / O device 70a Input / output connector 71, 72 Communication controller 71a, 72a Receiver 71b, 72b Driver 80 Light curtain 85 I / O device 91, 92 Switch 100 Robot system 151 Non-safe signal control unit 152, 152a Safety signal control unit 153 Switching unit 154 Setting unit 155 Safety signal setting information 157 Safety signal diagnostic unit 158 Switching diagnostic unit 171 Motion control unit 180 Motion program 200, 220 Setting screen
Claims
1. A control device for industrial machinery, comprising: a safety signal control unit for handling duplicated safety signals; a non-safety signal control unit for handling non-safety signals; and a switching unit capable of switching whether one or more signals input to or output from the control device are handled by the safety signal control unit as safety signals or by the non-safety signal control unit as non-safety signals.
2. The control device according to claim 1, wherein the safety signal control unit has a function to perform a predetermined diagnosis on the safety signal.
3. The control device according to claim 1, comprising a safety signal diagnostic unit having a function to perform a predetermined diagnosis relating to safety signals, wherein the safety signal control unit treats one or more signals as safety signals based on the results of the predetermined diagnosis when the switching unit enables the safety signal diagnostic unit to perform the predetermined diagnosis, and the non-safety signal control unit treats one or more signals as non-safety signals when the switching unit disables the safety signal diagnostic unit to perform the predetermined diagnosis.
4. The control device according to claim 2 or 3, wherein the predetermined diagnosis includes at least one of detecting a match or mismatch of duplicated safety signals, or detecting a stuck failure of the duplicated safety signals.
5. The control device according to any one of claims 1 to 4, wherein the switching unit switches, according to user operation, whether one or more signals are handled by the safety signal control unit as safety signals or by the non-safety signal control unit as non-safe signals.
6. The control device according to any one of claims 1 to 4, wherein the switching unit switches whether one or more signals are handled by the safety signal control unit as safety signals or by the non-safety signal control unit as non-safe signals, according to predetermined setting information.
7. The control device according to claim 6, comprising a setting unit that accepts user operations to set the setting information, wherein when a user operation to change the setting information is performed, the setting unit requests the input of a password, and if the entered password matches a password that has been registered in advance, the changed setting information can be applied.
8. A control device according to any one of claims 1 to 4, comprising a storage unit that stores setting information for each of a plurality of connection points for redundant safety signals, which defines whether two signals input or output through each connection point are to be treated as safety signals by the safety signal control unit or as non-safety signals by the non-safety signal control unit, wherein the switching unit switches whether two signals input or output for each of the plurality of connection points are to be treated as safety signals by the safety signal control unit or as non-safety signals by the non-safety signal control unit, according to the setting information.
9. The control device according to claim 8, further comprising a setting unit that receives user operations to set the setting information stored in the storage unit.
10. The control device according to claim 9, wherein the setting unit requests the input of a password when a user operation is performed to change the setting information stored in the storage unit, and applies the changed setting information when the input password matches a password that has been registered in advance.
11. The control device according to any one of claims 5 to 10, further comprising a switching diagnostic unit for diagnosing whether the switching by the switching unit regarding whether to treat a signal input to or output from the control device as a safety signal or a non-safe signal has been successful or failed.
12. The control device according to claim 11, wherein the switching diagnostic unit operates in such a way that instructions or settings for the switching are not applied to the switching unit when it is diagnosed that the switching by the switching unit has failed.
13. The control device according to any one of claims 1 to 4, wherein the switching unit switches whether one or more signals are handled by the safety signal control unit as safety signals or by the non-safety signal control unit as non-safe signals, depending on the state of a specific signal.
14. The control device according to claim 13, wherein the specific signal is a safety signal that is switched when the robot, as an industrial machine, enters or exits a specific area within the workspace.