IP Library Granted Patent US 11,543,798
Granted Patent B2
US 11,543,798 · App. 16/800,429 · Granted Jan 3, 2023

System architecture for safety applications

Inventors: Scott Denenberg (Newton, MA); Clara Vu (Cambridge, MA); Patrick Sobalvarro (Harvard, MA); Lev Persits (Cambridge, MA); Ilya A. Kriveshko (Boxborough, MA); Elliot Simon (Arlington, MA); Alberto Moel (Cambridge, MA); Patrick J. Foy (Reading, MA); Justin Bronder (Littleton, MA)
Assignee: VEO ROBOTICS, INC.
G05B19/4061B25J9/1676G06T17/00G05B2219/40339G05B2219/50193
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,543,798
App. No.
16/800,429
Granted
Jan 3, 2023
Kind
B2
Abstract

Control systems for industrial machinery (e.g., robots) or other devices such as medical devices utilize a safety processor (SP) designed for integration into safety applications and computational components that are not necessarily safety-rated. The SP monitors performance of the non-safety computational components, including latency checks and verification of identical outputs. One or more sensors send data to the non-safety computational components for sophisticated processing and analysis that the SP cannot not perform, but the results of this processing are sent to the SP, which then generates safety-rated signals to the machinery or device being controlled by the SP. As a result, the system may qualify for a safety rating despite the ability to perform complex operations beyond the scope of safety-rated components.

Claims (37)

1. A control system comprising:

a plurality of sensors configured to produce sensor outputs;

a plurality of non-safety computation modules, the non-safety computation modules each including a processor and being simultaneously responsive to the sensor outputs and executing a safety analysis, the non-safety computation modules producing control signals in response to detection of a safety condition by the safety analysis; and

a safety processor configured to receive the control signals from the computation modules and generate therefrom safety-rated signals for controlling a device.

2. The control system of claim 1 , wherein the safety processor is further configured to monitor performance of the computation modules including latency checks and verification of identical outputs.

3. The control system of claim 1 , wherein the safety processor is further configured to monitor intermediate results or data structures and error-correcting codes thereof.

4. The control system of claim 1 , wherein the safety analysis includes execution of an algorithm with non-deterministic or varying run times.

5. The control system of claim 1 , wherein the sensors are 3D time-of-flight cameras.

6. The control system of claim 5 , wherein the computation modules are configured to perform image capture from the time-of-flight camera data, identification, and classification in real time with low latency.

7. The control system of claim 5 , wherein the computation modules are configured to analyze occupancy and occlusion of a monitored space by:

registering the sensors with respect to each other so that the images obtained by the sensors collectively represent the workspace;

generating a three-dimensional representation of the workspace as a plurality of volumes;

for each sensor pixel having an intensity level above a threshold value, preliminarily marking as unoccupied volumes intercepted by a line-of-sight ray path through the pixel and terminating at an estimated distance from the associated sensor of an occlusion, marking as occupied the volumes corresponding to a terminus of the ray path, and marking as unknown any volumes beyond the occlusion along the ray path;

for each sensor pixel having an intensity level below the threshold value, preliminarily marking as unknown all voxels intercepted by a line-of-sight ray path through the pixel and terminating at a boundary of the workspace; and

finally marking as unoccupied volumes that have been preliminarily marked at least once as unoccupied.

8. The control system of claim 5 , wherein the computation modules are configured to evaluate safety conditions in a monitored space by:

registering the sensors with respect to each other so that the images obtained by the sensors collectively represent the workspace;

generating a three-dimensional representation of the workspace as a plurality of volumes; and

generating a volumetric representation of all points reachable by movable machinery in the workspace within a specified time period.

9. The control system of claim 1 , wherein the device is at least one robot.

10. The control system of claim 1 , wherein the plurality of computation modules are two dual-processor computation modules.

11. The control system of claim 1 , wherein the plurality of computation modules are configured to generate a 3D representation of a workcell monitored by the sensors.

12. The control system of claim 1 , wherein the safety analysis comprises speed and separation monitoring in accordance with at least one of ISO/TS 15066 or ISO 10218-2.

13. The control system of claim 1 , wherein the safety analysis comprises protective separation distance monitoring in accordance with at least one of ISO/TS 15066 or ISO 10218-2.

14. The control system of claim 1 , wherein the plurality of computation modules are configured to sequentially trigger operation of the sensors so as to prevent crosstalk thereamong.

15. The control system of claim 1 , wherein the plurality of computation modules are configured to receive latency tags issued by the safety processor.

16. The control system of claim 1 , wherein the safety processor is configured to generate and transmit latency tags to the sensors for return to the computation modules with sensor outputs.

17. The control system of claim 15 , wherein the safety processor is configured to receive and analyze latency tags returned by the computation modules to determine whether a duration associated with processing by the plurality of computation modules exceeds a predetermined maximum interval.

18. The control system of claim 1 , wherein the safety processor is configured to receive and analyze intermediate values returned by the computation modules to determine whether a processing error by the plurality of computation modules has occurred.

19. The control system of claim 1 , wherein the safety processor is configured to verify that the plurality of computation modules operate substantially simultaneously in accordance with a latency criterion.

20. The control system of claim 1 , wherein the safety processor is configured to verify that commands issued substantially simultaneously by the plurality of computation modules agree with each other.

21. The control system of claim 20 , wherein the computation modules perform identical computations.

22. The control system of claim 20 , wherein the computation modules perform different computations.

23. The control system of claim 1 , wherein the safety processor is configured to cause execution by the controlled device of commands issued substantially simultaneously by the plurality of computation modules following verification that (a) the plurality of computation modules operate substantially simultaneously in accordance with a latency criterion and (b) the commands issued substantially simultaneously by the plurality of computation modules agree with each other.

24. The control system of claim 1 , wherein the safety processor is configured to verify that clock and timing signals are consistent with independent redundant reference signals.

25. The control system of claim 1 , wherein the computation modules are identical.

26. The control system of claim 1 , wherein the computation modules are different in terms of at least one of a processor, an architecture, or an operating system.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2024
From: VEO ROBOTICS, INC.
To: SYMBOTIC LLC
Reel/Frame 068839/0710 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2022
From: DENENBERG, SCOTT; VU, CLARA; SOBALVARRO, PATRICK; PERSITS, LEV; KRIVESHKO, ILYA A.; SIMON, ELLIOT; MOEL, ALBERTO; FOY, PATRICK J.; BRONDER, JUSTIN
To: VEO ROBOTICS, INC.
Reel/Frame 061656/0035 →
Continuity (2)
Provisional Application 62811070 · Feb 27, 2019
Related Publication 20200272123A1 · Aug 27, 2020
Cited By (1)
US 12,449,546