arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

面向工业人形机器人的认证功能安全:故障被动间隙与可行性研究

Toward Certified Functional Safety for Industrial Humanoid Robots: The Fail-Passive Gap and a Feasibility Study

Caiwu Ding, Tao Cui, Lingyun Wang, Chengtao Wen

arXiv 2608.02809首次发表:更新:

发表机构

Siemens Foundational Technologies, Siemens Corporation(西门子基础技术部,西门子公司)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究针对工业人形机器人功能安全认证的故障被动间隙,通过外部安全链定位间隙,在Unitree G1 EDU上验证方法,分析人形机器人主动安全状态,将间隙定位在SDA与平衡策略的接口处。

AI 中文摘要

工业人形机器人的限制较少来自运动或操作能力,更多来自腿式平台功能安全认证的不成熟。根本难点在于腿式机器人的安全状态是主动控制状态,这违反了ISO 13849-1 / EN 60204-1的故障被动假设:切断行走双足机器人的电源会导致不受控的跌倒,因此经典的断电本身就是一种危险。我们将此称为故障被动间隙,并使用经过认证的外部安全链(光幕、急停、故障安全输入、故障安全PLC和无线PROFIsafe)作为工具来精确定位该间隙:由于外部链可通过既定方法(PFHD、DC、CCF、PL/SILCL)进行闭合和量化,因此剩余的无法认证元素被精确定位到机器人侧反应链。使用西门子故障安全S7-1500急停参考,我们表明其可认证的反应子系统是基于接触器的断电(停止类别0)——这正是平衡人形机器人无法具备的元素。我们刻意不声称实现端到端认证的PL e / SIL 3。我们在3m×1.5m半封闭工作空间内的Unitree G1 EDU取放单元上验证了该方法,并提供了针对人形机器人的主动安全状态分析(跌倒作为危险、单支撑停止边界、平衡策略残余风险、ISO 13855间距)以及带溯源标签的时序预算。在机器人上托管工业软件定义自动化(SDA)控制器,与平衡策略共处,将机器人侧PROFINET/PROFIsafe接收移至标准化IEC 61131-3接口;由于G1的板载计算硬件未达到安全等级,此端点不是经过认证的安全运行时,这强化而非解决了故障被动间隙,并将其定位在SDA到平衡策略的接口上。

英文摘要

Industrial humanoid robots are constrained less by locomotion or manipulation capability than by the immaturity of functional safety certification for legged platforms. The root difficulty is that the safe state of a legged robot is an actively-controlled state, which violates the fail-passive assumption underlying ISO~13849-1 / EN~60204-1: removing power from a walking biped causes an uncontrolled fall, so classical de-energization is itself a hazard. We term this the fail-passive gap and use a certified external safety chain (light curtain, emergency stop, fail-safe input, fail-safe PLC, and wireless PROFIsafe) as an instrument to locate it precisely: because the external chain is closed and quantifiable with established methods (PFHD, DC, CCF, PL/SILCL), the residual uncertifiable element is pinpointed to the robot-side reaction chain. Using a Siemens fail-safe S7-1500 emergency-stop reference, we show its certifiable Reaction subsystem is contactor-based power removal (Stop Category~0)---exactly the element a balancing humanoid cannot have. We deliberately do not claim end-to-end certified PL~e / SIL~3. We validate the approach on a Unitree G1 EDU pick-and-place cell in a 3m x 1.5m semi-enclosed workspace, and contribute a humanoid-specific analysis of the active safe state (fall-as-hazard, single-support stop bounds, balancing-policy residual risk, ISO~13855 separation) and a provenance-labeled timing budget. Hosting an industrial software-defined automation (SDA) controller on the robot, co-located with the balancing policy, moves robot-side PROFINET/PROFIsafe reception onto a standardized IEC~61131-3 interface; because the G1's onboard compute is not safety-rated hardware, this endpoint is not a certified safety runtime, which reinforces rather than resolves the fail-passive gap and localizes it to the SDA-to-balancing-policy interface.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑