Control system of mobile work machine and method for controlling mobile work machine

WO2026190414A1PCT designated stage Publication Date: 2026-09-17艾派克公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/FI2026/050104
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-10
Filing Date
2026-03-09
Publication Date
2026-09-17

Smart Images

  • Figure FI2026050104_17092026_PF_FP_ABST
    Figure FI2026050104_17092026_PF_FP_ABST
Patent Text Reader

Abstract

In the presented solution a control system of a mobile work machine comprises a user application. The user application is programmable to receive inputs and to produce outputs (30) for controlling the operation of the mobile work machine. The control system also comprises a safety related firmware having a safety function part (24) comprising configurable safety parameters (51). The configurable safety parameters (51) comprise information regarding safety related inputs (27) and safety related outputs (28). The user application is arranged to feed the configurable safety parameters (51) to the safety function part (24) of the firmware. In the presented solution the safety functions are implemented in the safety function part (24) of the firmware.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CONTROL SYSTEM OF MOBILE WORK MACHINE AND METHOD FOR CONTROLLING MOBILE WORK MACHINE

[0002] BACKGROUND

[0003] The invention relates to mobile work machines and a method as well as a control system for controlling the mobile work machine.

[0004] Mobile work machines are quite complex apparatuses. Therefore their control systems are rather versatile and complicated. Mobile work machines also may provide a danger or hazard to themselves and to their environment. Therefore the safety systems of the mobile work machines must be reliable and easily implemented.

[0005] BRIEF DESCRIPTION OF THE INVENTION

[0006] It is thus an object to provide a new control system and a method. The solution of the invention is characterized by what is stated in the independent claims. Embodiments of the invention are disclosed in the dependent claims.

[0007] In the presented solution a control system of a mobile work machine comprises a user application. The user application is programmable to receive inputs and to produce outputs for controlling the operation of the mobile work machine. The control system also comprises a safety related firmware having a safety function part comprising configurable safety parameters. The configurable safety parameters comprise information regarding safety related inputs and safety related outputs. The user application is arranged to feed the configurable safety parameters to the safety function part of the firmware. In the presented solution the safety functions are implemented in the safety function part of the firmware. Thus, in some embodiments only this safety related firmware part must be safety certified. The user application may be partly or totally non-safety related. Therefore, in some embodiments there is no need to get the user application safety certified. Because the safety related firmware part comprises configurable safety parameters it is rather simple and easy to modify the safety functions. For modifying the safety functions configuring safety parameters is sufficient but no programming, for example, is needed. Software is a set of programs and applications that run on a device and can usually be easily updated, installed, or removed by the user. On the other hand, firmware is a special type of software that is embedded into hardware components to control how they operate. It sits between hardware and higher-level software. The invention is based on the principle that the operation of the work machine is controlled by the user application, which is programmable,multifunctional, and complicated. The user application is the higher-level software. Having a safety related firmware including safety cut-off logic enables most of the user application software in the control system to be non-safety related. If need be, the control unit produces a safety related output de-energizing an output of the user application controlling the operation of the work machine. This safety related output is produced by the firmware. The user application and the firmware producing the safety function are separate entities.

[0008] The user may easily configure which control unit outputs belong to a safety cut-off group, for example. The user may also easily configure which of the control unit inputs will be used for safety related switches. The user may also configure if there is a reset input which enables resetting the safety cut-off without rebooting the control unit. In some embodiments, if there are a plurality of control units in the safety system, the user may configure at system level which control units have safety inputs and which do not. The user may also configure at system level which control units have safety outputs and which do not.

[0009] The solution may also be called a safety cut-off. The safety cut-off means that on the basis of the safety related input the control unit produces the safety related output that controls operation of the work machine. The safety related output may control the operation of the work machine directly or the safety related output may be used for de-energizing an output controlling the operation of the work machine. Safety cut-off is a built-in feature within a control unit firmware. According to an embodiment the safety cut-off may work locally with-in one control unit independent of other control units in the system. In some embodiments the safety cut-off can additionally be also commanded via a bus by a programmable safety master application.

[0010] The firmware is configured, and the configuration includes information which output belongs to which cut-off groups. There may be multiple groups. One group represents typically one system level safety function.

[0011] In the firmware there is a built-in logic to allow / de-energize necessary outputs control depending if the cut-off group is enabled / disabled. Output group enable / disable information is received from bus (from safety master) but it is also possible to configure that some of the local inputs of the control unit will be used as condition to disable certain output group. The safety cut-off feature itself works locally with-in one control unit or in system level if it is commanded by safety master.

[0012] The safety cut-off feature enables to form a distributed cut-offfunctionality. The distributed cut-off functionality is based on the safety cut-off functionality added with a capability in control unit firmware which enables individual control units to exchange information about the cut off groups statuses with each other without a need for customer application development, but only control unit configuration is required. Safety cut-off is basically a feature as its own but works at the same time as a building block for the distributed cut-off functionality.

[0013] This added capability in control unit firmware level to exchange information about the safety cut-off statuses enables to build a system level distributed safety functions without a need of safety master or customer safety related application programming.

[0014] Distributed cut-off functionality in this context means that an input affecting to some safety function may be located in different control unit than the output and therefore some safety related communication is needed to exchange information. When the control unit has distributed cut-off functionality the firmware has more advanced logic to be able communicate to other control units about the cut-off groups statuses and also receive cut-off group statuses from other control units and act based on that information (de-energize outputs). Safety related communication protocol to exchange this information is built-in in firmware level and doesn’t require any customer application development, only configuration of the control units.

[0015] BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In the following the invention will be described in greater detail by means of some embodiments with reference to the accompanying drawings, in which

[0017] Figure 1 shows a forwarder;

[0018] Figure 2 shows a harvester;

[0019] Figure 3 shows schematically an example of a system architecture of a mobile work machine;

[0020] Figures 4a, 4b, 4c, 4d, and 4e show schematically principles of systems employing centralized intelligence;

[0021] Figure 5 shows schematically a virtual safety cut-off group principle in a control unit in systems employing centralized intelligence;

[0022] Figure 6 shows schematically a master application - safety related responder firmware configuration interface in systems employing centralizedintelligence;

[0023] Figures 7a and 7b show schematically principles of systems employing distributed intelligence;

[0024] Figure 8 shows schematically a virtual safety cut-off group principle in a control unit in systems employing distributed intelligence;

[0025] Figure 9 shows schematically a user application - safety related firmware configuration interface in systems employing distributed intelligence;

[0026] Figure 10 shows an example a flow chart of a safety cut-off logic; and Figure 11 shows schematically a control system corresponding to the principle described in connection with Figure 5.

[0027] DETAILED DESCRIPTION OF THE INVENTION

[0028] With reference to Figures 1 and 2, Figures 1 and 2 show examples of mobile work machines in which the presented solution can be applied. A mobile work machine may be, for example, a mobile forest work machine, such as a forwarder as in Figure 1, a harvester as in Figure 2, or another forest machine, such as a drive machine of another type suitable for carrying a load, or a combination of a forwarder or harvester, or another mobile work machine such as a mining machine or excavator.

[0029] Figure 1 is a schematic view of a forwarder 1 which constitutes a mobile forest work machine in which the presented solution can be applied. Figure 2 is a schematic view of a harvester 2 which constitutes another mobile forest work machine in which the presented solution can be applied. The forwarder 1 shown in Figure 1 and the harvester 2 shown in Figure 2 are articulated steer forest work machines, but the above-described solution can also be applied in other ways, such as e.g. mobile work machines controllable via steerable wheels. Next, as for characteristics or embodiments examined in this description, the forwarder 1 of Figure 1 and the harvester 2 of Figure 2 can be referred to by their common name forest work machine, if said characteristic or embodiment being examined is not solely applicable to either the forwarder 1 or the harvester 2.

[0030] The forest work machines of Figures 1 and 2 comprise a chassis 3, which comprises a first frame part 4 and a second frame part 5, which are connected to each other via a link 6 such that the first frame part 4 and the second frame part 5 can rotate in relation to each other via the link 6, whereby the forest work machines in question are so-called articulated steer forest work machines. Into connection with the chassis 3 are arranged moving means 7, by means ofwhich, the forest work machines can move in relation to their work surface. Said moving means 7 are wheels in Figures 1 and 2, but generally said moving means can comprise at least one of the following: wheels arranged on an axle, wheels arranged on a bogie, a track system or some other means known as such to provide the movement of the forest work machine and to possible change the direction of the movement of the forest work machine in relation to its work surface or work environment. Said moving means can further comprise one or more braking devices for decelerating the driving speed of the forest work machine or for stopping the drive of the forest work machine totally.

[0031] The forwarder 1 of Figure 1 further includes a load space 8 arranged into connection with the second frame part 5 for taking a load to be transported by the forwarder 1. Typically, the forwarder 1 is used for transporting parts of a tree trunk typically cut to size, which are typically called logs or blocks but, in alternative use situations of the forwarder, said load can also comprise harvesting or thinning waste produced in connection with timber harvesting or forest thinning. The harvester 2 of Figure 2 does not include said load space, the harvester 2 of Figure 2 being thus solely intended for implementing the felling, delimbing and / or debarking of the tree and its cutting into parts of desired length.

[0032] The forest work machines of Figures 1 and 2 further comprise a power source 9, which in the forwarder 1 of Figure 1 is arranged to be supported by the first frame part 4 and in the harvester 2 of Figure 2 to be supported by the second frame part 5. The power source 9 can comprise e.g. a combustion engine, one or more electric motors and sets of batteries and / or a generator or different combinations of these for generating the required power for providing the movement of the forest work machine, for increasing its movement speed and for operating the devices arranged in the forest work machine.

[0033] The forest work machines of Figures 1 and 2 further comprise a cabin 10, which in the forest work machines of Figures 1 and 2 is arranged to be supported by the first frame part 4.

[0034] The forest work machines of Figure 1 and 2 further comprise a boom 11. The boom 11 can be supported e.g. on the chassis 3 or a separate tilting base or some other part of the machine frame. The cabin 10 and / or boom 11 can be arranged foldably and / or rotatably in relation to the chassis 3. The outmost end of the boom 11 typically includes a tool 19 of the forest work machine, whereby the outmost end of the boom 11 and the tool 19 arranged to it constitute a tip of the boom. In the forwarder 1 of Figure 1, said tool 19 typically comprises a liftingmeans, such as e.g. a grab or some other gripper and, in the harvester 2 of Figure 2, said tool 19 typically comprises a wood handling tool, such as e.g. a harvester head.

[0035] The boom 11 can also be described as having, as its successive boom parts, a ring base to be rigidly connected to the forest work machine, a foot section of the boom rotatably pivoted to the ring base, a first boom pivoted to the foot section, a second boom pivoted to the first boom, and a possible telescopic arrangement in the second boom. Additionally, the boom 11 and the tool 19 arranged at its end comprise actuators, which are obvious to those skilled in the art, for using each successive boom part, i.e. for either rotating by means of said pivoting or for shortening or lengthening by means of the possible telescopic arrangement, or for using or rotating the tool and, further obvious to those skilled in the art, a sensor arrangement comprising one or more sensors for determining the attitude and / or state of motion of the boom parts of the boom and for determining the attitude and / or state of motion of the tool, wherein the state of motion of the boom part or the tool describes the speed, acceleration and / or angular velocity of the movement of the boom part or tool in question. The attitude and / or state of motion of the boom parts and / or the tool can be determined independently or in relation to a part of the boom 11 or the forest work machine frame. Said actuators can in turn be e.g. above-mentioned cylinders or other cylinders or various motors, and said sensors can be e.g. various position sensors, motion speed sensors, sensors measuring attitude, acceleration or angular velocity, pressure sensors, sensors sensing the direction of a magnetic field, or radars based on e.g. radio waves or optics, or cameras.

[0036] The forest work machines comprise required control means 20, by means of which, the operator of the forest work machine can control the drive of the forest work machine and the devices arranged in it for performing control commands to be given via said control means 20. Said control means 20 are shown very schematically in Figures 1 and 2 and they can be positioned in the cabin 10. The control means 20 can comprise e.g. one or more manually controllable control means, such as e.g. a control lever, and / or one or more foot-controllable control means, such as e.g. a pedal. Said control means 20 are connected to one or more forest work machine control units 21 very schematically shown in Figures 1 and 2. The control unit 21 is arranged to control the drive of the forest work machine and the devices arranged in it by controlling the operation of actuators for performing the desired function. Said control unit 21 can be e.g. a computer or some other device or means comprising a microprocessor or some other microcontroller that isobvious to those skilled in the art.

[0037] The forest work machines also comprise one or more safety related switches 22. The safety related switch 22 may be any analog or digital input device or sensor which produces a safety related input 27 to the control unit 21. Examples of safety related switches 22 are a door switch, a dead man switch, a sensor detecting the exterior nearby the forest work machine, and an emergency stop button.

[0038] The data from the safety related switches 22 is lead to the control unit 21 as a safety related input 27. The control unit 21 then provides a safety related output 28 or outputs. The safety related inputs 27 and the safety related outputs 28 are used for implementing safety functions of the work machine. As an example, if a door switch indicates that the door is open the control unit 21 may control the forest work machine to stop moving. As another example, if a sensor detecting the exterior nearby the forest work machine detects that moving the boom 11 may cause danger to someone near the forest work machine the control unit 21 may prevent the boom from moving.

[0039] The forest work machines of Figures 1 and 2 are typically forest work machines operating based on the active control of the operator of the forest work machine. However, it is also possible to apply the presented arrangement in both semi-autonomously operating forest work machines, whereby the forest work machine can operate at least part of the time without the active control of the operator, and in substantially totally autonomously operating forest work machines, whereby the operator does not actively contribute to the control of the forest work machine operations without a special reason. Said special reason could be e.g. such an exceptional operating situation of the forest work machine which the control unit 21 controlling the operations of the forest work machine cannot perform autonomously. In connection with semi-autonomously operating forest work machines and totally autonomously operating forest work machines, the means used for controlling the forest work machine can be located separate from the forest work machine, whereby the forest work machine does not necessarily comprise an actual cab and the control of the machine is implemented by remote control or automatically.

[0040] It will be obvious for a person skilled in the art that the mobile work machine can comprise numerous additional structural and functional structure parts and entities different from the above examples, depending on the intended use and the type of the mobile work machine. The mobile work machine can include e.g. one or more frames, where are arranged e.g. a load space, a boom and atool attached to it, a power source, a powertrain, control means, and moving means. The moving means can comprise e.g. a variable number of axles, the axle can be rigid, swinging or a bogie axle, to the axle or the bogie can be arranged wheels or rollers.

[0041] Figure 3 shows schematically a system architecture of a mobile work machine. Figure 3 schematically shows a cabin 10, a front frame 4, and a rear frame 5 of mobile work machine. A control unit 21 is positioned in connection with the cabin 10. Two control units 23a and 23b are positioned in connection with the front frame 4. In this example embodiment one control unit 23c is positioned in connection with the rear frame 5.

[0042] The control unit 21 in connection with the cabin 10 may be a master unit and the other units 23a, 23b, and 23c may be slave units. Slave units may also be called responders. In such case the master unit may comprise a more advanced logic than the slave units and the master unit may control the operation of the slave units. Thus, in such case the master unit may be freely programmable by the user and the slave units comprise a pre-certified slave firmware. According to an embodiment all the control units 21, 23a, 23b, and 23c may be equally advanced. Thus, in such case all the units may be freely programmable by the user. In such case all the control units may be electronic control units (ECU), for example.

[0043] One or more safety related switches 22 may be connected to each of the control units. It is also possible that for one or more control units no safety related switch 22 is connected. In the example embodiment at least one safety related switch 22 is connected to the control unit 21 in connection with the cabin 10, to the first control unit 23a in connection with the front frame 4, and to the control unit 23c in connection with the rear frame 5 but no safety related switch 22 is connected to the second control unit 23b in connection with the front frame 4.

[0044] Each control unit 21, 23a, 23b, 23c is provided with a firmware having a safety function part 24. The structure and operation relating to the firmware and the safety function part 24 is explained in detail later in this description.

[0045] The safety related switches 22 provide safety related inputs 27 for the control units. Each control unit may have one or more safety related outputs 28. It is also possible that one or more control units have no safety related outputs 28. In the example embodiment at least one safety related output 28 is implemented in the control unit 21 in connection with the cabin 10, in the first control unit 23a in connection with the front frame 4, and in the second control unit 23b in connection with the front frame 4 but no safety related outputs 28 is implemented in thecontrol unit 23c in connection with the rear frame 5.

[0046] According to an embodiment the safety related output 28 controls an actuator 25 of the work machine. The actuator 25 may be an electrically controlled actuator such as a hydraulic valve, relay, electric motor, or any other corresponding actuator, for example.

[0047] The control units 21, 23a, 23b, 23c are connected to each other by a bus 26. The bus 26 may be a CAN bus or an Ethernet bus, for example. The bus takes care of data transfer between the control units. The normal i.e. non-safety related commands and other data may be transferred by the bus 26. Also, status of safety inputs and status of safety outputs, for example, may be communicated between the units using the same bus 26. Thus, according to the example embodiment the bus 26 transfers both non-safety related data and safety related data.

[0048] Figures 4a, 4b, 4c, 4d, and 4e show schematically principles of systems employing centralized intelligence. Thus, in Figures 4a, 4b, 4c, 4d, and 4e the control units 21, 21a, and 21b are master units and control units 23a, 23b, 23c, and 23d are responders. Safety function parts 24 of firmware in responders are illustrated with a hatching. Safety related inputs are denoted with reference numeral 1 and safety related outputs are denoted with reference numeral 28. Correspondingly non-safety related inputs are denoted with reference numeral 29 and non-safety related outputs are denoted with reference numeral 30. Non-safety related inputs and non-safety related outputs relate to the normal working of the mobile work machine without safety related issues.

[0049] In the embodiment shown in Figure 4a the control unit 21 comprises a non-safety related master application 40 and a safety related master application 41. Thus the non-safety related master application 40 and the safety related master application 41 are in the same device using common backbone. The non-safety related master application 40 and the safety related master application 41 are visible to the bus 26 as two separate devices although they are only two separate applications in the same physical device. The responders, i.e. the control units 23a, 23b, 23c, and 23d, are able to monitor commands from two separate master applications which are thus two separate devices visible in the bus 26.

[0050] The safety related master application 41 comprises safety related intelligence, which may also be called safety cut-off intelligence. The safety related intelligence in the safety related master application 41 includes the intelligence regarding which safety related outputs or safety cut-off groups are enabled and which safety related outputs or safety cut-off groups are disabled based on thesafety related inputs and a logic defined by a user. In some embodiments the control unit 23a, 23b, 23c, 23d may comprise a local safety cut-off logic that is independent of the safety related master application 41.

[0051] The bus 26 transfers both non-safety related data and safety related data. The bus 26 transfers non-safety related data between the non-safety related master application 40 in the control unit21 and the control units 23a, 23b, 23c, and 23d, for example. The bus 26 transfers safety related data between the safety related master application 41 in the control unit 21 and the control units 23a, 23b, 23c, and 23d, for example.

[0052] Safety related data is transferred using safety related messages or safety related protocol messages. If CANopen protocol stack, for example, is used the safety related data may be transferred using Safety Related Data Object (SRDO) messages. Non-safety related data is transferred using non-safety related messages or non-safety related protocol messages. If CANopen protocol stack, for example, is used the non-safety related data may be transferred using Process Data Object (PDO) protocol.

[0053] In the embodiment shown in Figure 4b the control unit 21 comprises only a non-safety related master application 40 and a non-safety related backbone. The safety cut-off intelligence is in certain responders. Thus, each responder that is used for safety operations has its own local cut-off logic. Thereby the safety cutoff works even without the master unit. If the responders do not exchange safety related messages between them the bus 26 is a non-safety bus and data is transferred using non-safety related messages, only.

[0054] In the embodiment shown in Figure 4c, also, the control unit 21 comprises only a non-safety related master application 40 and a non-safety related backbone. The safety cut-off intelligence is in certain responders. Thus, each responder that is used for safety operations has its own local cut-off logic. The control unit 23c receives at least one safety related input 27. However, the control unit 23c does not produce any safety related output 28, but the information regarding the at least one safety related input 27 is transferred to at least one of the control units 23a and 23d. The bus 26 transfers safety related data between the control units 23a, 23b, 23c, and 23d. Safety related data is transferred using safety related messages.

[0055] In the embodiment shown in Figure 4d the control unit 21a comprises the non-safety related master application 40 and the control unit 21b comprises the safety related master application 41. Thus, the non-safety related masterapplication 40 and the safety related master application 41 are in separate devices. The non-safety related master application 40 and the safety related master application 41 also use different buses. The non-safety related master application 40 uses the non-safety bus 26a and data is transferred using non-safety related messages. The safety related master application 41 uses the safety bus 26b and data is transferred using safety related messages.

[0056] The safety related master application 41 comprises safety cut-off intelligence. The safety cut-off intelligence in the safety related master application 41 includes the intelligence regarding which safety related outputs or safety cut-off groups are enabled and which safety related outputs or safety cut-off groups are disabled based on the safety related inputs and a logic defined by a user.

[0057] In the embodiment shown in Figure 4e, also, the control unit 21a comprises the non-safety related master application 40 and the control unit 21b comprises the safety related master application 41. Thus, the non-safety related master application 40 and the safety related master application 41 are in separate devices. The non-safety related master application 40 and the safety related master application 41 also use different buses. The non-safety related master application 40 uses the non-safety bus 26a and data is transferred using non-safety related messages. The safety related master application 41 uses the safety bus 26b and data is transferred using safety related messages.

[0058] The safety related master application 41 comprises safety cut-off intelligence. The safety cut-off intelligence in the safety related master application 41 includes the intelligence regarding which safety related outputs or safety cut-off groups are enabled and which safety related outputs or safety cut-off groups are disabled based on the safety related inputs and a logic defined by a user.

[0059] In the embodiment shown in Figure 4e not all the responders handle safety related issues. Also, all the responders are not necessarily connected to the same safety related bus.

[0060] In the embodiments shown in Figures 4d and 4e the control unit 23a, 23b, 23c, 23d may be commanded via two separate physical buses. Thus, the safety related communication may be transferred using the safety bus 26b which is a bus separate from the non-safety bus 26a via which the non-safety related communication is transferred. These two separate buses may two CAN buses, two ethernet buses, or a CAN bus and an ethernet bus, for example.

[0061] Figure 5 shows a virtual safety cut-off group principle in systems employing centralized intelligence. In Figure 5 the control unit 23a is a responder. Aresponder product as such and as a whole may be safety certified and safety capable including the responder application. However, if the master application controlling the responder is a non-safety related master application 40, as it is in the example embodiment of Figure 5, the system as a whole does not meet any safety level. Therefore, in the example embodiment of Figure 5 the firmware of the responder 23a comprises a non-safety function part 42 and a safety function part 24.

[0062] The non-safety function part 42 of the firmware comprises a normal responder logic 43. The non-safety related master application 40 communicates with the normal responder logic 43. The non-safety related master application 40 sends normal non-safety related output control requests, for example, to the normal responder logic 43. In this connection normal logic and normal output control requests refer to the complicated control of the mobile work machine. In this connection the control may comprise controlling the tip of the boom by a joystick, for example. Thus, normal control may comprise controlling the movement of an actuator moving the work machine or a part of the work machine, for example. The control signal of the normal control may be an analog signal or typically a complicated digital signal, for example. Thus, typically the non-safety related master application 40 and the normal responder logic 43 are multifunctional and complicated.

[0063] The safety function part 24 comprises a safety cut-off logic 44. The safety cut-off logic 44 de-energizes an output when needed. The safety related master application 41 determines for each output group when its control is ena-bled / disabled. Outputs in cut-off groups are also de-energized if communication timeouts to safety related master application 41 exist, or due to some other safety related message communication error, for example. The operation of the safety cutoff logic 44 is explained in detail with reference to Figure 10. The safety related master application 41 is quite simple when compared to the safety related master application 40. The safety related master application 41 controls the safety function by controlling the safety cut-off logic 44. The safety related master application 41 and the safety cut-off logic 44 together form the safety functionality. The safety functionality is based on enabling / disabling outputs 30 that are otherwise controlled by the non-safety related master application 40. Therefore the safety related master application 41 maybe rather simple.

[0064] All the outputs 30 are treated as non-safety related by the normal responder logic 43. Thereby they can be controlled by the non-safety master application 40 using non-safety related messages. The safety cut-off logic 44 has always the possibility to de-energize the outputs in the cut-off groups no matter what thenon-safety related master application 40 requests. The safety cut-off logic 44 includes a software function block 45 which either enables or disables the output 30. Thus, the software control block 45 either allows a control signal to pass or prevents the control signal from passing meaning that the output 30 is de-energized which is the safe state. In Figure 5 the safety cut-off logic 44 and the software function block 45 are shown separately. However, Figure 5 is only illustrative and does not depict the exact software architecture of the device.

[0065] The outputs 30 control the actuators 25 of the work machine. Thus, in this embodiment the safety related output 28 does not control the actuator 25 of the work machine directly but is an input for the software control block 45.

[0066] The safety related master application 41 determines for each output group in the safety cut-off logic 44 when its control is enabled / disabled. This data may be communicated to the responder 23a as a safety related message or as safety related status information. The responder 23a sends safety related input statuses and values to the safety related master application 41. The communication from the safety related master application 41 to the responder 23a and from the responder 23a to the safety related master application 41 is performed via the bus 26 using safety related messages.

[0067] The non-safety master application 40 sends normal non-safety related output control requests to the responder 23a. The responder 23a sends all non-safety related input statuses and safety related input statuses and values as well as statuses of the safety cut-off groups to the non-safety related master application 40. The communication from the non-safety related master application 40 to the responder 23a and from the responder 23a to the non-safety related master application 40 is performed via the bus 26 using safety related messages.

[0068] As explained before the non-safety related master application 40 and the safety related master application 41 may be in the same or different physical device. Also, the non-safety related master application and the safety related master application 41 may use a common bus or there may a separate non-safety related bus and a separate safety related bus. It is possible to configure the used physical communication interface separately for safety related and non-safety related communication depending if the non-safety related master application 40 and the safety related master application 41 are in the same or different physical device.

[0069] Figure 11 shows schematically a control system corresponding to the principle described in connection with Figure 5. A control input 81 is supplied to the non-safety related master application 40. The control input 81 may beproduced by a control device 80. The control device 80 may be a joystick controlling the movement of the boom of the mobile work machine or any other control means giving control commands for controlling the operation of the mobile work machine.

[0070] The control input 81 may be supplied directly to the non-safety related master application 40. Alternatively, the control input 81 may be supplied to a responder unit 23b and the responder unit 23b forwards the input values to the nonsafety related master application 40.

[0071] The non-safety related master application 40 sends normal non-safety related output control requests, for example, to the normal responder logic 43. This is in Figure 11 denoted with control signal 82. Thus, the normal control of the mobile work machine is executed in the non-safety application. The control of the work machine movements, for example, is performed with non-safety logic and communication independents of the safety logic.

[0072] Safety related input 1 is supplied to the safety related master application 41. The safety related master application 41 determines for each output group in the safety cut-off logic 44 when its control is enabled / disabled. The safety related master application 41 monitors safety inputs 27 and controls safety cut-off groups accordingly. Line 83 in Figure 11 denotes a safety related signal between the safety related master application 41 and the safety cut-off logic 44.

[0073] The responder 23a receives the normal control signal 82 and controls accordingly the actuators 25. However, the safety cut-off logic may prevent the control.

[0074] Figure 6 shows a master application - safety related responder firmware configuration interface in systems employing centralized intelligence. The safety function part 24 comprises a configuration table 50. The configuration table 50 comprises configuration parameters 51. The configuration parameters 51 are used to configurate the safety cut-off function, so that the responder knows which outputs are part of which output groups. One output group may comprise several outputs. There may be several output groups and one output may belong to one or more output groups simultaneously.

[0075] The non-safety related master application 40 comprises a non-safety related initialization function 52. A configuration tool may be used to write the configuration parameters 51 into the non-safety related initialization function 52. The configuration parameters 51 may also be created to be part of the source code of the master application. From the non-safety related initialization function 52 theconfiguration parameters 51 are fed to the configuration table 50 in the safety function part 24 of the firmware.

[0076] A checksum 53 may be calculated over the configuration parameters 51 to enable configuration data validation in the responder. The safety function part comprises a consistency check block 54. In the consistency check block 54 the checksum is compared to the configuration parameters 51 to detect if there has been any fault which might have been altered some of the parameters 51. The safety cut-off logic 44 uses the validated parameter values in the safety cut-off logic function.

[0077] The safety function might consist of several inputs and / or outputs distributed to several responder units. The non-safety related master application 40 or the safety related master application 41 shall check the consistency of the whole system using, for example, a system level checksum 55 written to each safety related firmware part 24.

[0078] Figures 7a and 7b show principles of systems employing distributed intelligence. In the example embodiments of Figures 7a and 7b all the control units 21 are customer or user programmable. The control units 21 may be electronic control units (ECU), for example. If the control unit 21 has safety related tasks it has a safety function part 24 of firmware.

[0079] In the embodiment shown in Figure 7a each control unit 21 has its own local safety cut-off logic. Virtual cut-off works independently of other control units 21. The user application may be completely non-safety related. The safety related cutoff functionality is in firmware level in the safety function parts 24.

[0080] In the embodiment shown in Figure 7b the cut-off logic is fully or partly distributed to several control units 21. For example, there may be a safety related input 27 in one control unit 21 and safety related output or outputs 28 in another control unit 21.This employs a so called distributed cut-off functionality. The user application may be completely non-safety related. The safety related distributed cut-off functionality is in firmware level in the safety related firmware parts 24.

[0081] Distributed cut-off functionality in this context means that an input affecting to some safety function may be located in different control unit than the output and therefore some safety related communication is needed to exchange information. When the control unit has distributed cut-off functionality the firmware has more advanced logic to be able communicate to other control units about the cut-off groups statuses and also receive cut-off group statuses from other control units and act based on that information (de-energize outputs). Safety relatedcommunication protocol to exchange this information is built-in in firmware level and doesn’t require any customer application development, only configuration of the control units.

[0082] Figure 8 shows a virtual safety cut-off group principle in systems employing distributed intelligence. Thus, in the example embodiment of Figure 8 the control unit 21 is customer or user programmable. The control unit 21 may be an electronic control unit (ECU), for example.

[0083] A part of the control unit 21 is a safety related firmware. Other part or parts of the control unit 21 may be safety related or non-safety related. In the example embodiment of Figure 8 the control unit 2 Icomprises a non-safety function part 62 of the firmware and a safety function part 24 of the firmware.

[0084] The non-safety function part 62 comprises a normal logic 63. The control means 20 sends normal non-safety related output control requests, for example, to the normal logic 63. The normal logic 63 is implemented using a user application 60. In this connection normal logic and normal output control requests refer to the complicated control of the mobile work machine. In this connection the control may comprise controlling the tip of the boom by a joystick, for example. Thus, normal control may comprise controlling the movement of an actuator moving the work machine or a part of the work machine, for example. The control signal of the normal control may be an analog signal or typically a complicated digital signal, for example. Typically the user application 60 and the normal logic 63 are multifunctional and complicated.

[0085] The safety function part 24 comprises a safety cut-off logic 44. The safety cut-off logic 44 de-energizes an output when needed. The safety cut-off functionality is implemented in firmware level. The operation of the safety cut-off logic 44 is explained in detail with reference to Figure 10.

[0086] The user application 60 may be fully non-safety related application because the safety cut-off logic 44 is implemented in the safety function part 24 of the firmware. The safety cut-off logic 44 has always the possibility to de-energize the outputs in the cut-off groups no matter what the user application 60 requests. The safety cut-off logic 44 includes a software function block 45 which either enables or disables the output 30. Thus, the software control block 45 either allows a control signal to pass or prevents the control signal from passing meaning that the output 30 is de-energized which is the safe state. In Figure 8 the safety cut-off logic 44 and the software function block 45 are shown separately. However, Figure 8 is only illustrative and does not depict the exact software architecture of the deviceThe outputs 30 control the actuators 25 of the work machine. Thus, in this embodiment the safety related output 28 does not control the actuator 25 of the work machine directly but is an input for the software control block 45.

[0087] The user application 60 may be fully non-safety related or it may be safety related and include also other safety functions which operates in parallel with the safety cut-off. The user application 60 configures the safety cut-off feature in firmware level. This doesn’t not make the user application 60 safety related since the configuration is static and not generated by the application. Static in this context means that the non-safety related application does not generate the configuration but only transfers or feeds the configuration to the to the configuration table 50 in the safety function part 24 of the firmware. By using the checksum it is ensured that the non-safety related application has not amended the configuration and that there is no error in the communication or storage, for example. Cut-off group statuses are provided from the safety cut-off logic 44 to the user application 60 for diagnostics purposes.

[0088] Figure 9 shows a user application - safety related firmware configuration interface in systems employing distributed intelligence in a control unit. The safety function part 24 comprises a configuration table 50. The configuration table 50 comprises configuration parameters 51. The configuration parameters 51 are used to configurate the safety cut-off function, so that it knows which outputs are part of which output groups. One output group may comprise several outputs. There may be several output groups and one output may belong to one or more output groups simultaneously.

[0089] The non-safety related user application 60 comprises a non-safety related initialization function 52. A configuration tool may be used to write the configuration parameters 51 into the non-safety related initialization function 52. The configuration parameters 51 may also be created to be part of the source code of the master application. From the non-safety related initialization function 52 the configuration parameters 51 are fed to the configuration table 50 in the safety function part 24 of the firmware.

[0090] A checksum 53 may be calculated over the configuration parameters 51 to enable configuration data validation. The safety function part 24 comprises a consistency check block 54. In the consistency check block 54 the checksum is compared to the configuration parameters 51 to detect if there has been any fault which might have been altered some of the parameters 51. The safety cut-off logic 44 uses the validated parameter values in the safety cut-off logic function.Figure 10 shows an example of a flow chart of the safety cut-off logic 44. First in block 70 it is determined for each output if the output is a part of the safety function or not. Thus, it is determined is the output mapped to some cut-off group or not. If the output is mapped to some cut-off group then it is continued to block 71.

[0091] In block 71 it is determined are the input statuses valid or not. Thus, it is determined is the redundant cut-off inputs status invalid. If the status is invalid then the process continues to block 72. In block 72 the firmware de-energizes the output when it is mapped to a cut-off group which is disabled.

[0092] If in block 71 it is determined that the input status is not invalid the process continues to block 73. In block 73 it is determined is the cut-off group disabled via local inputs or not. Thus, it is determined has the local safety related switch 22 provided a need to de-energize an output. An example of such need is that an emergency stop button has been pushed. If the cut-off group is disabled via a local input then the process continues to block 72. In block 72 the firmware de-energizes the output when it is mapped to a cut-off group which is disabled.

[0093] If in block 73 it is determined that the cut-off group is not disabled via a local input the process continues to block 74. In block 74 it is determined is the cutoff group disabled via a bus or not. Thus, it is determined is there a need and a request in another control unit connected to the system by a bus to de-energize an output. If the cut-off group is disabled via a bus then the process continues to block 72. In block 72 the firmware de-energizes the output when it is mapped to a cut-off group which is disabled.

[0094] If in block 74 it is determined that the cut-off group is not disabled via a bus the process continues to block 75. In block 75 it is determined is the cut-off safety message received in time and is its content valid or not. Thus, it is determined is the message data invalid. If the message data is invalid then the process continues to block 72. In block 72 the firmware de-energizes the output when it is mapped to a cut-off group which is disabled.

[0095] If in block 75 it is determined that the message data is not invalid the process goes back to block 71. Also, after block 72 the process goes back to block 71. The output or outputs remain de-energized or disabled until they are enabled again.

[0096] Naturally, the cut-off logic 44 may comprise more determination blocks than or less determination blocks than what is presented in Figure 10. Also, the order of the blocks may vary in the implementation from what is shown in Figure10, for example.

[0097] It will be obvious to a person skilled in the art that, as technology advances, the inventive concept can be implemented in various ways. The invention and its embodiments are not limited to the examples described above but may vary within the scope of the claims.

Claims

CLAIMS1. A control system of a mobile work machine, comprisingat least one control unit (21, 23a-23e) comprising a user application, the user application being programmable to receive inputs and to produce outputs (30) for controlling the operation of the mobile work machine, andthe at least one control unit (21, 23a-23e)8 also comprising a safety related firmware having a safety function part (24) comprising configurable safety parameters (51),the configurable safety parameters (51) comprising information regarding safety related inputs (27) and safety related outputs [28),wherein the user application (40, 41, 60) is arranged to feed the configurable safety parameters (51) to the safety function part (24) of the firmware, and wherein the safety function part (24) comprises a safety cut-off logic (44) which is configured to produce the safety related output (28) to de-energize certain outputs (30) for controlling the operation of the mobile work machine on the basis of the information regarding safety related inputs (27).

2. A control system as claimed in claim 1, wherein the safety related outputs (28) are configurable to belong to several safety cut-off groups simultaneously.

3. A control system as claimed in any one of the preceding claims, wherein the user application comprises a non-safety related master application (40) and a safety related master application (41) and the at least one control unit (21, 23a-23e) comprising the firmware which at least one control unit (21, 23a-23e) is able to monitor commands from the two master applications (40, 41).

4. A control system as claimed in any one of the preceding claims, wherein the control system comprises a non-safety bus (26a) via which non-safety related communication is transferred and a safety bus (26b) via which safety related communication is transferred, whereby the safety bus (26b) which is a bus separate from the non-safety bus (26a), and at least one control unit comprising the firmware which at least one control unit may be commanded via the two separate buses.

5. A control system as claimed in any one of the preceding claims, wherein the control system comprises distributed cut-off functionality such thatthe control system comprises at least two control units (21, 23a-23e) comprising the firmware which at least two control units are connected by a bus (26, 26a, 26b) whereby status of safety inputs (27) and status of safety outputs (28) are communicated between the control units (21, 23a-23e) using the bus (26, 26a, 26b).

6. A control system as claimed in claim 5, wherein the bus (26) transfers both non-safety related data and safety related data.

7. A control system as claimed in claim 5 or 6, wherein the system comprises safety related switches (22) for producing safety related inputs (27) and at least one safety related switch (22) is connected to at least one control unit (21, 23a-23e) and at least one other safety related switch (22) is connected to at least one another control unit (21, 23a-23e).

8. A control system as claimed in any one of claims 5 to 7, wherein at least one safety related output (28) is implemented in at least one control unit (21, 23a-23e) and at least one other safety related output (28) is implemented in at least one another control unit (21, 23a-23e).

9. A control system as claimed in any one of claims 5 to 8, wherein the system comprises safety related switches (22) for producing safety related inputs (27) and at least one safety related switch (22) and the safety related input (27) it produces is connected to at least one control unit (21, 23a-23e) and at least one safety related output (28) corresponding to the safety related input (27) connected to the at least one control unit (21, 23a-23e) is implemented in at least one another control unit (21, 23a-23e).

10. A method for controlling a mobile work machine the method comprisingproviding at least one control unit (21, 23a-23e) comprising a user application and a firmwarecontrolling the operation of the mobile work machine by the user application, the user application receiving inputs and producing outputs (30) for controlling the operation of the mobile work machine,collecting information regarding safety related inputs (27), collecting information regarding safety related outputs (28), forming configurable safety parameters (51) comprising information regarding safety related inputs (27) and safety related outputs (28),feeding the configurable safety parameters (51) by the user application to the firmware,storing the configurable safety parameters (51) to the firmware, andforming by the firmware a safety function by de-energizing certain outputs (30) for controlling the operation of the mobile work machine on the basis of the information regarding safety related inputs (27) and using the safety related outputs (28).11 A method as claimed in claim 10, wherein the user application comprises a non-safety related master application (40) and a safety related master application (41) and the safety related master application (41) controls the safety function.

12. A method as claimed in claim 10 or 11, comprisingmodifying the safety function by configuring the safety parameters (51).

13. A method as claimed in any one of the claims 10 to 12, comprising providing a distributed cut-off functionality by providing at least two control units (21, 23a-23e) comprising the firmware and communicating status of the safety inputs (27) and status of the safety outputs (28) between the control units (21, 23a-23e).

14. A method as claimed in claim 13, comprisingreceiving safety related inputs (27) by at least one control unit (21, 23a-23e) and producing a safety related output (28) by at least one another control unit (21, 23a-23e).