WO2024029211A1 - 自律制御システムおよび安全監視システム - Google Patents
自律制御システムおよび安全監視システム Download PDFInfo
- Publication number
- WO2024029211A1 WO2024029211A1 PCT/JP2023/022282 JP2023022282W WO2024029211A1 WO 2024029211 A1 WO2024029211 A1 WO 2024029211A1 JP 2023022282 W JP2023022282 W JP 2023022282W WO 2024029211 A1 WO2024029211 A1 WO 2024029211A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- safety
- autonomous control
- control system
- rules
- layer
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B9/00—Safety arrangements
- G05B9/02—Safety arrangements electric
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B25—HAND TOOLS; PORTABLE POWER-DRIVEN TOOLS; MANIPULATORS
- B25J—MANIPULATORS; CHAMBERS PROVIDED WITH MANIPULATION DEVICES
- B25J19/00—Accessories fitted to manipulators, e.g. for monitoring, for viewing; Safety devices combined with or specially adapted for use in connection with manipulators
- B25J19/06—Safety devices
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B25—HAND TOOLS; PORTABLE POWER-DRIVEN TOOLS; MANIPULATORS
- B25J—MANIPULATORS; CHAMBERS PROVIDED WITH MANIPULATION DEVICES
- B25J9/00—Program-controlled manipulators
- B25J9/16—Program controls
- B25J9/1674—Program controls characterised by safety, monitoring, diagnostic
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B60—VEHICLES IN GENERAL
- B60W—CONJOINT CONTROL OF VEHICLE SUB-UNITS OF DIFFERENT TYPE OR DIFFERENT FUNCTION; CONTROL SYSTEMS SPECIALLY ADAPTED FOR HYBRID VEHICLES; ROAD VEHICLE DRIVE CONTROL SYSTEMS FOR PURPOSES NOT RELATED TO THE CONTROL OF A PARTICULAR SUB-UNIT
- B60W60/00—Drive control systems specially adapted for autonomous road vehicles
- B60W60/001—Planning or execution of driving tasks
- B60W60/0015—Planning or execution of driving tasks specially adapted for safety
-
- G—PHYSICS
- G08—SIGNALLING
- G08G—TRAFFIC CONTROL SYSTEMS
- G08G1/00—Traffic control systems for road vehicles
- G08G1/16—Anti-collision systems
Definitions
- the present invention relates to an autonomous control system and a safety monitoring system.
- Patent Document 1 Japanese Patent Publication No. 2022-516559
- the publication states, ⁇ The present invention relates to a novel approach to managing the operation of autonomous vehicles.More specifically, the present invention provides a novel approach to managing the operation of autonomous vehicles.
- the present invention relates to a method and system for improving the permissiveness of an autonomous vehicle, truck, aircraft, or other similar vehicle by implementing a computer-based system that alleviates safety constraints in certain situations. Are listed.
- Another background technology is International Publication No. 2022/009900 (Patent Document 2).
- the purpose is to provide an automatic driving device and a vehicle control method that can reduce the risk of confusing the user.
- An example of an automatic driving device to achieve this purpose is is an automatic driving device that uses map data to create a control plan for autonomously driving a vehicle, which includes a map management unit that determines the acquisition status of map data, and a control unit that uses map data to create a control plan. and a planning section, and the control planning section is configured to change the content of the control plan according to the map data acquisition status determined by the map management section.''
- the autonomous control system of the present invention includes a mobile body control system that controls the operation (e.g., movement, transportation, etc.) of a mobile body such as an automobile, a railway vehicle, a construction machine, an automatic guided vehicle, or a robot, and a field in which the mobile body operates.
- This system is communicably connected to the safety monitoring system to be monitored.
- Devices such as mobile objects controlled by autonomous control systems may coexist with people (for example, workers, pedestrians, etc.) in the environment in which they are used. To ensure human safety in such an environment, it is necessary for people and equipment (moving objects) to follow safety rules (e.g., stop temporarily when entering an intersection, obey traffic lights, come within a certain distance of equipment). If the autonomous control system understands the safety rules and performs control, it will be possible to ensure the safety of each operation.
- safety rules it is best to set safety rules with sufficient leeway to accommodate the addition of equipment or changes in usage (for example, ensuring a wide space around the equipment), and as a result, each equipment It places unnecessary constraints on people and can reduce efficiency.
- safety rules are set that are limited to the current equipment or intended use (for example, ensuring a minimum amount of space around the equipment based on the operating speed of the equipment), it may be difficult to add equipment or change the intended use. Failure to do so would require a large amount of man-hours to make changes, such as redesigning the system in response to a review of safety rules.
- the present invention has been made in view of the above problems, and provides an autonomous control system that can appropriately reconstruct safety rules in accordance with the changed situations and design conditions even when various situations of the autonomous control system change. and safety monitoring system.
- one embodiment of the present invention may use the technical idea described in the claims, for example. That is, one embodiment of the present invention includes a first safety layer that monitors and controls the safety of equipment based on safety rules in the field, and a first safety layer that detects deviations from system preconditions within design assumptions and and a second safety layer that performs reconfiguration.
- the present invention it is possible to quickly and appropriately reconstruct safety in response to changes in the environment of an autonomous control system (e.g., evolution, change in use, etc.), and when various situations of the autonomous control system change.
- safety rules can be appropriately restructured to suit changing circumstances and design conditions.
- FIG. 1 is a diagram showing a configuration example of an autonomous control system including a safety monitoring system and a vehicle system according to a first embodiment.
- 1 is a diagram showing an example of the overall configuration of an autonomous control system according to a first embodiment;
- FIG. 3 is a diagram illustrating a processing flow in the safety monitoring system according to the first embodiment.
- FIG. 3 is an explanatory diagram of an example of parameters of system prerequisites. It is a relationship diagram of a system prerequisite pattern and a safety design change pattern. It is a figure showing an example of composition of a safety rule.
- FIG. 3 is a diagram illustrating a configuration example of a main functional layer and a first safety layer. It is a figure which shows the example of a structure of a 2nd safety layer.
- FIG. 7 is a diagram illustrating a processing flow when updating a safety rule according to a second embodiment.
- FIG. 7 is a diagram illustrating a configuration example of a second safety layer according to a third embodiment.
- This example mainly describes an autonomous control system consisting of a safety monitoring system that monitors and controls the vehicle control system, and a vehicle system equipped with the vehicle control system.
- a safety monitoring system that monitors and controls the vehicle control system
- vehicle system equipped with the vehicle control system a vehicle system equipped with the vehicle control system.
- the present invention is suitable for implementation in a safety monitoring system, it does not preclude application to autonomous control systems including other than vehicle control systems.
- the vehicle system in the case of a warehouse transport system, the vehicle system is replaced with a forklift or goods transport equipment, and the object is replaced with a warehouse worker; in the case of an industrial system, the vehicle system is replaced with a work robot, and the object is replaced with a line worker.
- a similar effect can be expected even if it is replaced with .
- vehicle systems even if they are replaced with aviation equipment such as drones.
- the objects to be controlled by this system are assumed to be robots in factories, existing systems such as railways, and three-dimensional moving objects such as air mobility.
- FIG. 1 shows an overview of the field in which the autonomous control system according to the first embodiment is implemented.
- the autonomous control system 100 includes a safety monitoring system 101, a vehicle system 102, and an information transmission device 105.
- a safety monitoring system 101 a safety monitoring system
- vehicle system 102 a vehicle system
- information transmission device 105 an information transmission device
- peripheral devices, people, etc. that are not controlled by the autonomous control system 100 (non-communication vehicle system 103, object 104).
- the safety monitoring system 101 communicates with multiple control systems, such as a vehicle control system, and monitors a field that includes the vehicle system 102 and other objects (described below).
- the vehicle system 102 includes a communication device and the like, and includes a vehicle control system that operates while communicating with the safety monitoring system 101 .
- the non-communication vehicle system 103 is a vehicle system that does not have a communication device or the like and does not communicate with the safety monitoring system 101.
- the object 104 is a pedestrian, a light vehicle (such as a bicycle), or the like.
- the information transmission device 105 is a communication device such as a signal for controlling traffic or a smartphone, and transmits information to the object 104 such as a pedestrian and confirms the response thereof.
- the safety monitoring system 101 includes a communication device 111 and a monitoring device 112.
- the communication device 111 communicates with the vehicle control system, the information transmission device 105, and the like.
- the monitoring device 112 is a sensor such as a camera, radar, or lidar that monitors the field.
- FIG. 2 shows the overall architecture of the autonomous control system according to the first embodiment.
- the autonomous control system 100 has a main functional layer 201, a first safety layer 202, a second safety layer 203, a third safety layer 204, and an object 205 as a logical structure.
- the main function layer 201 is, for example, a part of the vehicle control system, and operates the vehicle system 102 in cooperation with other safety layers 202, 203, and 204.
- the first safety layer 202 detects abnormalities in the main functional layer 201 and the field and performs control to maintain a safe state or transition to a safe state, according to safety rules in the field.
- the second safety layer 203 detects deviations in system preconditions (described later) and that the deviations are within the design assumption range (in other words, deviations from the system preconditions within the design assumptions), and rewrites the corresponding safety rules. Performs configuration and overrides of controls performed by vehicle system 102.
- the third safety layer 204 detects deviations in system preconditions and the fact that the deviations are outside the design range (in other words, deviations from system preconditions outside of design assumptions), and redesigns the corresponding safety rules. , implements an override of control of vehicle system 102.
- the object 205 interacts with the respective safety layers 202, 203, 204 or the main functional layer 201, receives safety rule information transmission, and returns a response to the transmission. Furthermore, information such as motion and position of the object 205 is collected from the safety layers 202, 203, and 204 and the main function layer 201.
- the system architecture in FIG. 2 is a logical structure, and the arrangement of each function in the physical configuration is not necessarily one-to-one.
- the main functional layer 201 is arranged in the vehicle system 102 and the first to third safety layers 202, 203, and 204 are arranged in the safety monitoring system 101.
- information is transmitted from each of the layers 201, 202, 203, and 204 to the object 205 via the information transmission device 105, for example.
- a portion of the first safety layer 202 (vehicle fault diagnosis and safety functions) is located in the vehicle system 102.
- reaction speed is improved because processing for failures does not involve communication, and functions related to vehicle failures can be integrated with the vehicle, making it easy to reuse the vehicle system 102 and safety monitoring system 101. becomes.
- a system precondition deviation detection function in a safety layer (which is part of the functions of the safety layer) to be described later may be arranged in equipment such as the vehicle system 102. This eliminates the need to send data (sensing data, etc.) for determining system precondition deviation from the vehicle system 102, etc. to the safety monitoring system 101, and instead only sends information that a system precondition deviation has occurred. becomes possible. This can be expected to reduce the processing load on the safety layer and the network load.
- FIG. 3 shows an overview of the processing of the safety monitoring system 101 according to the first embodiment.
- the safety monitoring system 101 monitors the state of the field (including the state of equipment and objects) via, for example, the monitoring device 112 or the communication device 111 that the safety monitoring system 101 has, and detects a deviation (trigger) from the system preconditions. This flow is executed when the vehicle system 102 or the like receives information indicating that a trigger has been detected from the vehicle system 102 or the like.
- the safety monitoring system 101 determines that the control target of the autonomous control system 100 and the surrounding environment do not deviate from the system preconditions (determination method will be described later) (no in S301). , no particular processing is performed (S302). If it is determined that the content of the trigger deviates from the system prerequisites (S301: yes), then it is determined whether the deviation of the system prerequisites is within the expected design range (determination method will be described later) (S303 ). As a result of the determination, if the deviation of the system preconditions is within the expected design range (S303: YES), the safety rules are reconfigured (S304), which will be described later.
- the safety rules are redesigned (S305), which will be described later. In this way, the safety monitoring system 101 updates (reconfigures or redesigns) the safety rules according to the situation of the autonomous control system 100.
- FIG. 4 shows an example of parameters for system prerequisites.
- 401 shows an example of a parameter of an (autonomous control) device
- 402 shows an example of a parameter of an object related to the autonomous control system 100
- 403 shows an example of a parameter of an environment (context) in which the autonomous control system 100 is used.
- examples of device parameters include device performance (moving/rotational speed, sensor detection range (including area shape), communication speed (throughput/latency), and safety-related performance (Fail-safe and Fail). -operational, presence or absence of safety mechanisms, etc.), features (equipment weight, size (height, width, depth), hardness (changes in risk of collision)), movable parts (shape, output strength of control operation) , the type of the device (vehicle type, etc.), the number of passengers (including 0), etc.
- examples of objects include, for example, workers who cooperate with the autonomous control system 100 or pedestrians in the field, and as shown in 402, examples of the parameters include attributes (skill level (duration of work experience, position), etc.). , knowledge of safety rules, level of compliance with safety rules (whether the person is easy to follow), reaction speed to various instructions and situations (sound, video, light), various movement abilities (speed (movement, rotation), warning time) These include reaction movement speed), physical condition, material to be carried (weight and visibility), presence and location of protective equipment, etc.
- examples of environmental parameters include area conditions (presence or absence of people, presence or absence of traffic lights, presence or absence of blind spots, speed limit), road surface conditions (road resistance, road surface type), and environmental conditions (weather, amount of light). , wind volume, snowfall, rainfall, noise), etc.
- each table a combination of multiple tables may be used depending on the existing equipment, the type of assumed object, and the environment that the autonomous control system 100 supports (for example, assuming both outdoors and indoors).
- one system prerequisite That is, the system prerequisites have information that affects safety design regarding equipment, people, and the environment, and each of the equipment, people, and environment information has a scope.
- These parameters are parameters that are assumed when performing safety analysis and design, and are assumed to be parameters that, if changed, require changes in the results of safety analysis and design. For example, if the safety design is based on the assumption that the autonomous control system 100 will move at a low speed, and a new device that moves at high speed is added to the field, the expected risks will change and the risks will be reduced. As changes occur, safety analysis and design results may change. The same applies to changes in people or the environment, and in such cases, the autonomous control system 100 needs to perform safe control in accordance with the changes in the situation.
- ⁇ Definition of inside and outside the expected design range> a method for determining whether or not it is within the design expected range will be explained using FIG. 5.
- a plurality of patterns (A to C in this case) are designed for the system preconditions.
- a corresponding safety design change pattern (here ⁇ to ⁇ ) is also designed. That is, as shown in FIG. 5, combinations of two or more system prerequisite patterns and corresponding safety design change patterns are designed as a table.
- the parameters have a range (value range or list) (see FIG. 4), and if it is within that range, it is assumed that the system preconditions have not changed.
- the parameter of the changed system precondition is included within the range of the system precondition parameter of another pattern (for example, if it is included within the range of the parameter of C). If the parameter of the changed system precondition is included within the range of the system precondition parameter of another pattern (for example, if it is included within the range of the parameter of C), it is determined that it is within the designed range. In other words, if the current system preconditions match the conditions of the system precondition pattern, it is determined that the system is within the expected design range. If the changed parameter of the system precondition is not included within the range of the parameter of the system precondition of another pattern, it is determined that the parameter is outside the designed range. In other words, a case where the current system preconditions do not match the conditions of the system precondition pattern is determined to be outside the design range.
- safety design change pattern ⁇ is used to ensure safety as described below. Perform rule reconfiguration.
- the safety design change pattern is constructed by a designer or the like performing safety analysis based on the system prerequisite pattern, performing hazard analysis and risk assessment under the system prerequisite conditions, and implementing safety design.
- the system prerequisite pattern or safety design change pattern is held, for example, in the reconfiguration trigger determination unit 2031 (FIG. 8) or the redesign trigger determination unit 2041 (FIG. 9) for determination.
- the second safety layer 203 or the third safety layer 204 may make an inquiry to an external database or the like regarding this information each time. By doing so, it becomes possible to reduce memory and easily update the information to the latest information (by updating the external database).
- the system is designed so that there is always at least one safety design change pattern that corresponds to the system prerequisite pattern, but if it does not exist, it is determined that it is outside the design range.
- the same safety design change pattern may be used in multiple system prerequisite patterns.
- the same safety design change pattern ⁇ is used (designed) in two system prerequisite patterns A and B. In that case, there is no need to change the safety design pattern due to the transition between these system prerequisite patterns, the process of reconfiguring safety rules can be omitted, and unnecessary safety control implementation and processing load can be reduced. It becomes possible.
- Figure 6 shows the structure of the safety rule.
- the leftmost part of FIG. 6 shows an example of a hierarchy of safety rules, and control is performed so that higher-order safety rules have priority.
- ⁇ no collisions'' is the highest safety rule, and in order to achieve this, ⁇ safety even in abnormal situations'' becomes a necessary safety rule.
- the structure on the right in FIG. 6 is the content of the safety rule "safety even in abnormal situations" broken down.
- the safety rule of "safety even in abnormal situations” the safety rule of "occlusion control” which basically ensures safety by preventing multiple objects from entering the same area
- the safety rule of "remote OR (override) It is configured to include a safety rule that ensures safety by forcibly controlling the device remotely (for example, decelerating and stopping) if an object or the like that violates the occlusion control exists.
- the safety rules for “occlusion control” include the safety rule “do not enter the secured area”, the safety rule “the size of the area is x1 [m]”, and the safety rule “the size of the area becomes xx [m] when condition yy” It consists of safety rules. Normally, it is controlled by these parameters.
- the safety rules are updated and reconfigured. From then on, the entire autonomous control system 100 performs processing in accordance with the updated safety rules.
- the safety rules updated by reconfiguration are transmitted to the main functional layer 201 and the first safety layer 202 logically, and physically to the entire device or object in the field by communication or other methods (by the information transmission device 105). notifications).
- ⁇ Redesign of safety rules> If the changed system preconditions are not included within the range of the system precondition patterns, the safety rules will need to be redesigned. Redesigning safety rules is facilitated by notifying which parameters of changes in system prerequisites were out of range. In other words, the configuration is such that information about mismatch in system prerequisites is transmitted as a trigger for redesigning safety rules. As a result of this redesign, new system prerequisite patterns and safety design change patterns are added. By performing safety rule reconfiguration processing using these parameters, it becomes possible to safely control the autonomous control system 100 based on the new safety rules.
- the main function layer 201 includes a recognition unit 2011 that creates a map showing the situation of a field, such as the vicinity of a device, based on information received from sensors, communication equipment, etc.; There is a judgment unit 2012 that creates an action plan and a control plan for the equipment, an operation unit 2013 that outputs signals to control actuators, etc. based on the action plan and control plan output from the judgment unit 2012, and a control unit 2013 that outputs signals for controlling actuators etc. It is comprised of an intervention control unit 2014 that receives an override instruction from the outside and intervenes in the control executed by the operation unit 2013 when the object falls into a dangerous state. Each part of the main function layer 201 receives notification of the safety rules for the main function layer 201 and performs corresponding control. For example, the control plan generated by the determination unit 2012 is generated so as not to violate safety rules.
- the intervention control unit 2014 performs an important function for safety, it is placed in a highly reliable device (safety microcomputer), etc. among the installed devices.
- Override involves controlling the vehicle to decelerate and stop, depending on the situation, steering the vehicle to avoid it, or temporarily stopping the system or standing still to maintain a low-risk state. The same applies to overrides during safety control below.
- the first safety layer 202 diagnoses abnormalities in the main function layer 201 or non-safety events in the field (safety rule violations, etc.) by combining safety rules with information obtained via the monitoring device 112, communication device 111, etc.
- the functional safety control unit 2021 includes a diagnostic unit 2022 and a functional safety control unit 2021 that performs corresponding control such as an override instruction on the main function layer 201 based on the diagnosis result of the diagnostic unit 2022.
- the diagnosis unit 2022 receives safety rule update information from the second safety layer 203 or the third safety layer 204 regarding the updated safety rules, and performs diagnosis based on the updated safety rules. Implement.
- the second safety layer 203 uses the method described in the above-mentioned reconfiguration of safety rules to determine deviations from system preconditions and judgments within and outside of the design assumption range.
- a reconfiguration trigger determination unit 2031 performs a determination based on the current system preconditions detected using communication with the functional layer 201 and the monitoring device 112, and performs safety control (override, etc.) during reconfiguration using the determination result.
- the third safety layer 204 uses the method described above to communicate with the main function layer 201, system precondition patterns and safety design change patterns that hold system precondition deviations and judgments within and outside of the design assumption range. and a redesign trigger determination unit 2041 that makes a determination based on the current system preconditions detected using the monitoring device 112, and a redesign safety control unit 2042 that performs safety control (override, etc.) during redesign using the determination result. and a safety rule redesign unit 2043 that redesigns safety rules using the determination results and the method described above, and notifies devices and objects in the field about the updated safety rules.
- Example 2 Next, a method for maintaining safety control of the system until the deployment of safety rules is completed will be described using FIG. 10. This flow is implemented by the second safety layer 203 or the third safety layer 204. Here, the implementation procedure in the second safety layer 203 will be explained.
- the reconfiguration trigger determining unit 2031 determines a trigger for reconfiguring safety rules. If it is determined that the safety rules need to be reconfigured, the entire autonomous control system 100 is notified of the safety rules (S1001). Specifically, the reconfiguration trigger determination unit 2031 instructs the safety rule reconfiguration unit 2033 to reconfigure the safety rule and notify the entire field of the safety rule update. Thereafter, the reconfiguration trigger determination unit 2031 instructs the reconfiguration safety control unit 2032 to execute safety control (override, etc.) (S1002).
- the reconfiguration trigger determination unit 2031 confirms that the safety rules have been transmitted and received from each device in the autonomous control system 100 (for example, the vehicle system 102, the non-communication vehicle system 103) and the object 104.
- the confirmation method is based on communication responses, human behavior (response signs), etc. In other words, it is checked whether agreement has been obtained from the entire autonomous control system 100. As a result, if responses have not been received from all devices or objects in the entire field (no in S1003), the safety control state is maintained. If responses can be received from all devices and objects (S1003: yes), the safety control state is canceled (S1004), and then the entire autonomous control system 100 is controlled in accordance with the updated safety rules. That is, the response of each device and object to the safety rule update notification is checked, and control based on the new safety rule is implemented.
- FIG. 11 shows the configuration of the second safety layer 203 according to the third embodiment.
- the second safety layer 203 in this embodiment includes a prerequisite difference determining unit 2034 that detects differences in system prerequisites related to grasping the safety rules of objects, and a prerequisite difference determining unit 2034 that detects differences in system prerequisites related to grasping safety rules of objects, and differences determined by the prerequisite difference determining unit 2034 (object safety a safety rule transmitting unit 2035 that transmits a safety rule (for example, a safety rule to stop at an intersection when the object does not know the rule for stopping at an intersection) for resolving the difference in understanding conditions of the rule; , has.
- a safety rule for example, a safety rule to stop at an intersection when the object does not know the rule for stopping at an intersection
- the reconfiguration trigger determination unit 2031 in the second safety layer 203 determines that the deviation of the system preconditions (object A's parameters (understanding safety rules) is based on the current system preconditions). conditions) and reconfigure the safety rules as described above.
- the premise difference determination unit 2034 which has received the information regarding the deviation of the system preconditions (the system preconditions before the change and the system preconditions after the change) from the reconfiguration trigger determination unit 2031, determines that the object A is By understanding the safety rules that are the differences, it is determined that the system preconditions satisfy the system preconditions before the change. As a result, the premise difference determining unit 2034 instructs the safety rule transmitting unit 2035 to notify the safety rule of the difference to object A, and the safety rule transmitting unit 2035 transmits the safety rule to object A. Notice.
- object A grasps the safety rules, and the reconfiguration trigger determination unit 2031 confirms that the system preconditions have changed again, and reconfigures the safety rules again. That is, in this embodiment, safety rule information is notified to object A that does not know the safety rules, and the safety rules are reconfigured based on the result.
- the processing of the reconfiguration trigger determination unit 2031 is transferred to the reconfiguration trigger determination unit 2041, and the reconfiguration safety control unit 2032
- the processing of the safety rule reconfiguration unit 2033 is replaced with the safety rule redesign unit 2043, and the premise difference determination unit 2034 and the safety rule transmission unit are replaced with the third safety layer 204.
- the same can be achieved by arranging 2035.
- Example 4 Next, an example in which the present invention is applied to industrial equipment will be described.
- an autonomous control system including a transportation robot in a factory by replacing the vehicle system with a transportation robot and assuming a worker etc. as an object, safety rules can be observed as described in Examples 1 to 3. Control based on safety rules is possible through reconfiguration and redesign.
- industrial equipment uses a large amount of energy, resulting in a high risk value, so careful safety design is required.
- the system prerequisites include the robot arm's movable range, speed, sensor range, communication and response speed, and safety performance (presence or absence of a fail-safe mechanism, etc.), and the parameters of the worker as an object include skill level and safety rules. These include whether or not the object is grasped, height (location and possibility of contact), etc.
- safety rules include maintaining a distance to prevent collisions, and the parameters for this distance are set according to the above conditions.
- the first safety layer 202 maintains the distance described above through sensing and fault diagnosis, and the second safety layer 203 and the third safety layer 204 carry out the reconfiguration and redesign of safety rules as described above.
- the first safety layer 202 monitors and controls the safety of equipment based on safety rules in the field, and detects deviations from system prerequisites within design assumptions and reproduces the safety rules.
- the second safety layer 203 that performs configuration makes it possible to reconfigure the system to conform to the safety rules within the design assumptions and safely continue control even if the system premise conditions are deviated from.
- the third safety layer 204 detects deviations from system preconditions that are not expected in the design and redesigns the safety rules. It becomes possible to redesign rules.
- the amount of information transmitted can be reduced. becomes possible.
- the safety rules can be easily redesigned.
- a prerequisite difference determination unit 2034 that detects a difference in system prerequisite conditions related to grasping the safety rule, and transmits the difference in the grasping condition of the safety rule determined based on the difference.
- a safety rule transmitting unit 2035 to notify the safety rule information to objects that do not know the safety rule, and based on the result, reconfigure or redesign the safety rule. This makes it possible for the entire autonomous control system 100 to operate under efficient system preconditions based on the understanding of safety rules.
- the present invention is not limited to the above embodiments, and includes various modifications.
- the embodiments described above are described in detail to explain the present invention in an easy-to-understand manner, and the present invention is not necessarily limited to having all the configurations described.
- it is possible to replace a part of the configuration of one embodiment with the configuration of another embodiment and it is also possible to add the configuration of another embodiment to the configuration of one embodiment.
- each of the above-mentioned configurations, functions, processing units, processing means, etc. may be partially or entirely realized by hardware, for example, by designing an integrated circuit. Further, each of the above-mentioned configurations, functions, etc. may be realized by software by a processor interpreting and executing a program for realizing each function. Information such as programs, tapes, and files that implement each function can be stored in a memory, a recording device such as a hard disk, an SSD (solid state drive), or a recording medium such as an IC card, SD card, or DVD.
- a recording device such as a hard disk, an SSD (solid state drive), or a recording medium such as an IC card, SD card, or DVD.
- control lines and information lines are shown that are considered necessary for explanation, and not all control lines and information lines are necessarily shown in the product. In reality, almost all components may be considered to be interconnected.
Landscapes
- Engineering & Computer Science (AREA)
- Mechanical Engineering (AREA)
- Robotics (AREA)
- Automation & Control Theory (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Human Computer Interaction (AREA)
- Transportation (AREA)
- Traffic Control Systems (AREA)
- Manipulator (AREA)
- Safety Devices In Control Systems (AREA)
- Control Of Position, Course, Altitude, Or Attitude Of Moving Bodies (AREA)
Abstract
Description
<システム概要>
図1に、実施例1にかかる自律制御システムを実装したフィールドの概要を示す。自律制御システム100は、安全監視システム101、車両システム102、情報伝達装置105から構成される。フィールド内には、自律制御システム100の制御対象とならない周辺機器や人などがさらに存在する(非通信車両システム103、オブジェクト104)。
図2に、実施例1にかかる自律制御システムの全体アーキテクチャを示す。自律制御システム100は、論理構造として、主機能レイヤ201、第1の安全レイヤ202、第2の安全レイヤ203、第3の安全レイヤ204、オブジェクト205から構成される。
図2のシステムアーキテクチャは論理的な構造であり、それぞれの機能の物理構成への配置は一対一とは限らない。機能配置の一例では、主機能レイヤ201は車両システム102に、第1から第3の安全レイヤ202、203、204は安全監視システム101に配置される。また、それぞれのレイヤ201、202、203、204からオブジェクト205への情報の伝達は、例えば情報伝達装置105を介して実施される。
次に実施例1にかかる安全監視システム101の処理の概要について図3に示す。安全監視システム101は、例えば安全監視システム101が有する監視装置112または通信装置111を介してフィールドの状態(機器およびオブジェクトの状態を含む)を監視し、システム前提条件の逸脱(トリガ)を検出した場合、または車両システム102等からトリガを検出した情報を受信した場合に本フローを実施する。
図4に、システム前提条件のパラメータ例を示す。401は(自律制御)機器のパラメータ例、402は自律制御システム100と関連するオブジェクトのパラメータ例、403は自律制御システム100が使用される環境(コンテキスト)のパラメータ例を示す。
次に設計想定範囲内か否かの判定方法について図5を用いて説明する。まず、本実施例にかかる自律制御システム100を設計する場合には、前記システム前提条件について複数のパターン(ここではAからC)を設計する。また、それに対応する安全設計変更パターン(ここではαからβ)も設計する。すなわち、図5に示すように、システム前提条件パターンを2以上と、対応する安全設計変更パターンの組合せをテーブルとして設計する。それぞれのシステム前提条件パターンでパラメータは範囲(値域またはリスト)を持ち(図4参照)、その範囲内であればシステム前提条件は変化していないとみなす。一方で前記システム前提条件の範囲を逸脱した場合、その他のシステム前提条件パターン(例えばこの例でシステム前提条件パターンAを逸脱した場合、BまたはC)のパラメータ範囲に含まれるかを確認する。他のパターンのシステム前提条件のパラメータの範囲内に、前記変化したシステム前提条件のパラメータが含まれる場合(例えばCのパラメータの範囲内に含まれる場合)、ここでは設計想定範囲内と判定する。つまり、システム前提条件パターンの条件に現在のシステム前提条件が一致する場合を設計想定範囲内と判定する。他のパターンのシステム前提条件のパラメータの範囲内に、前記変化したシステム前提条件のパラメータが含まれない場合には、設計想定範囲外と判定する。つまり、システム前提条件パターンの条件に現在のシステム前提条件が一致しない場合を設計想定範囲外と判定する。
図6に、安全ルールの構造を示す。図6の一番左は安全ルールの階層例を示しており、上位の安全ルールが優先となるように制御を行う。まず“衝突しない”ことが最上位の安全ルールであり、それを実現する中で、“異常時も安全”ということが安全ルールの中で必要になってくる。それらを満たしている上で、“最高速でタスクを実行する”という安全ルールに従い、安全性を維持した上で効率の良い作業を行う安全ルールが構成可能となる。
前記システム前提条件のパターンの範囲内に、変化した後のシステム前提条件が含まれていない場合には、安全ルールの再設計が必要になる。安全ルールの再設計については、システム前提条件の変化のどのパラメータが範囲外であったかを通知することで、再設計を容易とする。すなわち、安全ルールの再設計のトリガとして、システム前提条件の不一致の情報を伝達する構成とする。この再設計を行った結果、新たにシステム前提条件のパターンと安全設計変更パターンが追加される。それらのパラメータを用いて安全ルールの再構成処理を実施することで、新たな安全ルールに基づき自律制御システム100の制御を安全に実施することが可能となる。
次に図7を用いて、主機能レイヤ201および第1の安全レイヤ202の概要について説明する。
第2の安全レイヤ203の概要について図8を用いて説明する。
第3の安全レイヤ204の概要について図9を用いて説明する。
次に、安全ルールの展開が完了するまでシステムの安全制御を維持する方法について、図10を用いて説明する。本フローは、第2の安全レイヤ203または第3の安全レイヤ204により実施される。ここでは第2の安全レイヤ203での実施手順について説明する。
次に、新規の機器や人がフィールドに参加した場合に、安全ルールを効率よく更新する方法について説明する。実施例3にかかる第2の安全レイヤ203の構成について図11に示す。
次に、本発明を産業機器に適用した場合の例について説明する。まず工場内の搬送ロボなどを含む自律制御システムへの適用については、前記車両システムを搬送ロボに置き換え、オブジェクトとして作業員などを想定することにより、実施例1から3に記載の通り安全ルールの再構成および再設計による安全ルールに基づく制御が可能となる。一方で、産業機器は機器のエネルギーが大きく、結果としてリスク値が高くなるため、留意した安全設計が必要となる。
以上説明した実施例によれば、フィールド内の安全ルールに基づき機器の安全を監視して制御する第1の安全レイヤ202と、設計想定内のシステム前提条件逸脱を検出し、前記安全ルールの再構成を行う第2の安全レイヤ203により、システム前提条件を逸脱した場合でも設計想定内で対応した安全ルールに再構成を行い、安全に制御を継続することが可能になる。
101 安全監視システム
102 車両システム
103 非通信車両システム
104 オブジェクト
105 情報伝達装置
111 通信装置
112 監視装置
201 主機能レイヤ
202 第1の安全レイヤ
203 第2の安全レイヤ
204 第3の安全レイヤ
401 システム前提条件(機器)
402 システム前提条件(オブジェクト)
403 システム前提条件(環境)
2011 認知部
2012 判断部
2013 操作部
2014 介入制御部
2021 機能安全制御部
2022 診断部
2031 再構成トリガ判定部
2032 再構成安全制御部
2033 安全ルール再構成部
2041 再設計トリガ判定部
2042 再設計安全制御部
2043 安全ルール再設計部
2034 前提差分判定部
2035 安全ルール送信部
Claims (13)
- 機器を動作させる主機能レイヤと、
フィールド内の安全ルールに基づき前記機器の安全を監視し、対応する制御を前記主機能レイヤに実施する第1の安全レイヤと、
設計想定内のシステム前提条件逸脱を検出し、前記安全ルールの再構成を行い、再構成により更新された前記安全ルールを通知する第2の安全レイヤと、を有する自律制御システム。 - 請求項1に記載の自律制御システムにおいて、
設計想定外のシステム前提条件逸脱を検出し、前記安全ルールの再設計を行う第3の安全レイヤをさらに有する自律制御システム。 - 請求項2に記載の自律制御システムにおいて、
システム前提条件逸脱を検出し、前記安全ルールの再構成または再設計を行う際に、前記フィールドの安全性を維持するための制御を実施することを特徴とした自律制御システム。 - 請求項1に記載の自律制御システムにおいて、
システム前提条件パターンを2以上と、対応する安全設計変更パターンの組合せをテーブルとして有し、前記システム前提条件パターンの条件に現在のシステム前提条件が一致することを設計想定内と判定することを特徴とした自律制御システム。 - 請求項4に記載の自律制御システムにおいて、
前記システム前提条件は、機器および人および環境に関して安全設計に影響を与える情報を持ち、前記情報のそれぞれが範囲を有することを特徴とした自律制御システム。 - 請求項2に記載の自律制御システムにおいて、
前記安全ルールの再設計のトリガとして、前記システム前提条件の不一致の情報を伝達することを特徴とした自律制御システム。 - 請求項3に記載の自律制御システムにおいて、
前記安全ルールの更新通知に対する機器およびオブジェクトの応答を確認し、新規安全ルールでの制御を実施することを特徴とした自律制御システム。 - 請求項2に記載の自律制御システムにおいて、
前記第2の安全レイヤまたは前記第3の安全レイヤの機能の一部であるシステム前提条件逸脱の検出機能が、前記機器に実装されることを特徴とした自律制御システム。 - 請求項2に記載の自律制御システムにおいて、
前記安全ルールの把握に関わるシステム前提条件の差分を検出する前提差分判定部と、前記差分により判定された前記安全ルールの把握条件の差分について送信する安全ルール送信部と、を有し、前記安全ルールを把握していないオブジェクトに対して前記安全ルールの情報通知を行い、その結果を受けて前記安全ルールの再構成または再設計を実施することを特徴とした自律制御システム。 - 請求項2に記載の自律制御システムにおいて、
システム前提条件パターンを2以上と、対応する安全設計変更パターンの組合せをテーブルとして有し、前記システム前提条件パターンの条件に現在のシステム前提条件が一致しないことを設計想定外と判定することを特徴とした自律制御システム。 - フィールド内の安全ルールに基づき機器の安全を監視して制御する第1の安全レイヤと、
設計想定内のシステム前提条件逸脱を検出し、前記安全ルールの再構成を行う第2の安全レイヤと、を有する安全監視システム。 - 請求項11に記載の安全監視システムにおいて、
設計想定外のシステム前提条件逸脱を検出し、前記安全ルールの再設計を行う第3の安全レイヤをさらに有する安全監視システム。 - 請求項12に記載の安全監視システムにおいて、
システム前提条件逸脱を検出し、前記安全ルールの再構成または再設計を行う際に、前記フィールドの安全性を維持するための制御を実施することを特徴とした安全監視システム。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US18/870,848 US20250370414A1 (en) | 2022-08-03 | 2023-06-15 | Autonomous control system and safety monitoring system |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2022-124006 | 2022-08-03 | ||
| JP2022124006A JP2024021284A (ja) | 2022-08-03 | 2022-08-03 | 自律制御システムおよび安全監視システム |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024029211A1 true WO2024029211A1 (ja) | 2024-02-08 |
Family
ID=89848793
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2023/022282 Ceased WO2024029211A1 (ja) | 2022-08-03 | 2023-06-15 | 自律制御システムおよび安全監視システム |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20250370414A1 (ja) |
| JP (1) | JP2024021284A (ja) |
| WO (1) | WO2024029211A1 (ja) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2003067045A (ja) * | 2001-08-27 | 2003-03-07 | Toshiba Corp | プラント自動制御装置 |
| JP2009026063A (ja) * | 2007-07-19 | 2009-02-05 | Yokogawa Electric Corp | 安全制御システム |
| JP2021117935A (ja) * | 2020-01-29 | 2021-08-10 | 株式会社日立製作所 | 系統制約調整支援装置および方法 |
| WO2022009900A1 (ja) * | 2020-07-08 | 2022-01-13 | 株式会社Soken | 自動運転装置、車両制御方法 |
| JP2022516559A (ja) * | 2019-01-03 | 2022-02-28 | エッジ ケース リサーチ,インコーポレイテッド | 自律運転ビークルの安全性を確保しつつ許容性を向上させる方法及びシステム |
-
2022
- 2022-08-03 JP JP2022124006A patent/JP2024021284A/ja active Pending
-
2023
- 2023-06-15 US US18/870,848 patent/US20250370414A1/en active Pending
- 2023-06-15 WO PCT/JP2023/022282 patent/WO2024029211A1/ja not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2003067045A (ja) * | 2001-08-27 | 2003-03-07 | Toshiba Corp | プラント自動制御装置 |
| JP2009026063A (ja) * | 2007-07-19 | 2009-02-05 | Yokogawa Electric Corp | 安全制御システム |
| JP2022516559A (ja) * | 2019-01-03 | 2022-02-28 | エッジ ケース リサーチ,インコーポレイテッド | 自律運転ビークルの安全性を確保しつつ許容性を向上させる方法及びシステム |
| JP2021117935A (ja) * | 2020-01-29 | 2021-08-10 | 株式会社日立製作所 | 系統制約調整支援装置および方法 |
| WO2022009900A1 (ja) * | 2020-07-08 | 2022-01-13 | 株式会社Soken | 自動運転装置、車両制御方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| JP2024021284A (ja) | 2024-02-16 |
| US20250370414A1 (en) | 2025-12-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN111874001A (zh) | 自动驾驶汽车的安全控制方法、电子设备及存储介质 | |
| Vanderhaegen | A non-probabilistic prospective and retrospective human reliability analysis method—application to railway system | |
| CN113619576B (zh) | 车辆控制方法、装置、设备、存储介质及自动驾驶车辆 | |
| Lynas et al. | Human factor issues with automated mining equipment | |
| US8125109B2 (en) | Modular safety switching system and method | |
| CN102455704B (zh) | 使用可疑事件图进行航空器系统诊断辅助的方法、装置 | |
| CN109116777A (zh) | 汽车电子系统体系架构 | |
| CN104950740A (zh) | 具有冗余计算机的用于交通工具的系统 | |
| Johnson | A review of fault management techniques used in safety-critical avionic systems | |
| JP2019180005A (ja) | 通信遮断システム、通信遮断方法及びプログラム | |
| CN112286220B (zh) | 用于自主监测高度自动化的交通工具操作的系统和方法 | |
| Linz | Testing autonomous systems | |
| JP5119892B2 (ja) | 電子制御システム | |
| CN114872717A (zh) | 自动驾驶车辆的控制系统、方法、装置及自动驾驶车辆 | |
| Dreany et al. | A cognitive architecture safety design for safety critical systems | |
| Ishimoto et al. | Safety concept and architecture for autonomous haulage system in mining | |
| WO2024029211A1 (ja) | 自律制御システムおよび安全監視システム | |
| CN113119994A (zh) | 用于运行自动驾驶车辆的方法和设备 | |
| EP3738113B1 (en) | System and method for providing a digital intersection | |
| Johnsen et al. | Risk-based regulation and certification of autonomous transport systems | |
| Chronopoulos et al. | Is smartness risky? A framework to evaluate smartness in cyber-physical systems | |
| JP4755473B2 (ja) | 信号制御システム | |
| CN115830897B (zh) | 一种自动驾驶系统的冗余实现方法、系统及车辆 | |
| KR102416612B1 (ko) | 고립된 사용자컴퓨팅부를 갖는 제어시스템 및 그 제어방법 | |
| Lachter et al. | Thinking outside the box: the human role in increasingly automated aviation systems |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23849771 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 18870848 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 23849771 Country of ref document: EP Kind code of ref document: A1 |
|
| WWP | Wipo information: published in national office |
Ref document number: 18870848 Country of ref document: US |