Systems and methods for authorizing and executing safe semi-autonomous engagement of safety-critical devices

The system addresses the challenge of safe semi-autonomous engagement of safety-critical launchers by employing a human-machine interface with multiple signal channels and hardware barriers, ensuring compliance and safety in robotic combat vehicle operations.

JP2025535001APending Publication Date: 2025-10-22KONGSBERG DEFENCE & AEROSPACE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2025518264
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-10-03
Filing Date
2023-10-02
Publication Date
2025-10-22

AI Technical Summary

Technical Problem

Existing systems fail to provide a safe and versatile solution for authorizing and executing semi-autonomous engagement of safety-critical launchers at operational autonomy levels 4 and 5, which require strict ethical and regulatory compliance, especially in scenarios involving robotic combat vehicles.

Method used

A system with a human-machine interface and control unit utilizing three distinct signal communication channels - launch control, authorization, and arming control - over high-availability wireless networks, ensuring diversity and fail-safe operation by using hardware safety barriers and closed-loop communication, allowing human operators to authorize and monitor robotic systems.

Benefits of technology

Ensures safe and compliant operation at levels 4 and 5 by maintaining human oversight and preventing unintentional launches through diverse signal channels and continuous monitoring, adhering to ethical and regulatory requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025535001000001_ABST
    Figure 2025535001000001_ABST
Patent Text Reader

Abstract

A system and method for authorizing and executing safe semi-autonomous engagements of a safety-critical launcher at a remote location. The system includes a human-machine interface at a nearby location with an input means, the human-machine interface including at least one hardware safety barrier and a hardware barrier communication means with an interface connected to a network providing at least three different signal communication channels, including a first signal communication channel for carrying a launch control signal (PALM), a second signal communication channel for carrying an authorization signal, and a third signal communication channel for carrying an arming control signal (ARM). The system further includes a control unit and a robot operator server at a remote location connected to the launch control system of the safety-critical launcher and to the network. the control unit is adapted to receive a launch control signal (PALM) carried on a first signal communication channel, the control unit including at least one hardware safety barrier and a hardware barrier communication means with an interface connected to a network; the third signal communication channel is a closed-loop signal communication channel between the human-machine interface and the hardware safety barrier of the control unit, and forwards an arming control signal (ARM) to a launch control system of the safety-critical launcher via the control unit; the robot operator server includes software SW that detects and locks on an attack target, provides authorization information to the human-machine interface via the second signal communication channel of the network, and forwards a trigger signal (TRIG) to the launch control system when approval for engagement is confirmed by the operator via the control panel; and activates the safety-critical launcher when all of the launch control signal (PALM), arming control signal (ARM), and trigger signal (TRIG) are present in the launch control system.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a system and method for authorizing and executing safe semi-autonomous engagement of safety-critical launchers in remote locations. [Background technology]

[0002] The safe operation of safety-critical equipment is crucial. For remotely controlled operations, several measures are being standardized and required to operate safety-critical equipment. This is especially true in the defense industry, where malfunctioning weapons can have deadly consequences. The industry is moving toward standardized platforms and infrastructures for safely operating remote safety-critical equipment from nearby locations. On these platforms, all systems must interoperate through packet-based networks. Operator locations become multipurpose operator locations shared among multiple systems. Thus, the interface between the systems and the operator locations changes.

[0003] Applicant has previously developed a solution for controlling safety-critical operations at a remote location (far end) at a local location (near end) via a non-safety network and a local Control Panel Interface (CPI). The CPI interface provides a secure communications tunnel through the non-safety network. This solution, described in Applicant's own U.S. Patent Application Publication No. 2006 / 0129999, which is incorporated herein by reference, provides a secure method for enabling and controlling the operation of safety-critical equipment at a remote location.

[0004] Safety-critical equipment may include, for example, weapon launch and / or weapon movement circuitry located at a remote location, which is operated from a nearby location.

[0005] The non-secure communication network may be a packet-based communication network such as an Internet Protocol (IP) network. The secure communication tunnel may be an IPsec tunnel for barrier control signals. The IPsec tunnel may be configured in an integrity-only mode, in which the IPsec receiver authenticates the barrier control signals sent by the IPsec sender and ensures that the data has not been modified during transmission. The barrier circuit may further be configured with a configurable or fixed IP addressing scheme. The configurable scheme may be a dynamic scheme. Higher security is achieved by encapsulating the barrier with fixed IP addressing.

[0006] The communication through the secure communication tunnel may use a protocol that includes time stamping of the data, as described in the above-referenced patent application WO 2007 / 024990 and also applies to the new solution disclosed herein.

[0007] In a particular embodiment, the operation input device may include a video session information device, and the safety-critical device may be a video verification device. In this embodiment, the system may further include a video distribution device.

[0008] A video distribution device may be provided at the safety-critical device to provide a video signal that is transmitted over the non-secure communication network and displayed on a near-end display screen. Additionally, the near-end video session information device may be configured to extract video session information from the video signal and transmit the video session information over the secure communication tunnel. Additionally, the video verification device may be configured to verify the authenticity of the video signal transmitted over the non-secure communication network. These aspects of the video session information device are described in detail in the above-referenced patent application WO 2007 / 024990.

[0009] When delivering data requiring high bandwidth, such as video, stable and high-quality wireless communication cannot be easily guaranteed, and signal transmission is relatively short distance compared to wireless communication using lower bandwidth.

[0010] Signal transmission to perform safety-critical operations, such as controlling the movement and firing of remote weapon stations, does not require high bandwidth, so this can be performed through a hardware (HW) barrier, while video can be transferred through a different channel.

[0011] Authorisation to Proceed (AtP) for weapon systems using autonomy and artificial intelligence (AI) is linked to ethical principles, making it an absolute requirement that humans monitor and shut down malfunctioning AI systems.

[0012] The U.S. Department of Defense (DoD) has recommended a set of guidelines for the use of autonomous weapons systems, one of which is that the systems must be manageable, meaning that the design of AI features must perform their intended functions while providing the ability to detect and avoid unintended consequences and to disarm or shut down deployed systems that exhibit unintended behavior.

[0013] The operational levels are defined as follows: 1. Remotely operated man-in-the-loop, where safety-critical equipment is controlled from a remote operator location. 2. Assisted man-in-the-loop, where safety-critical equipment is controlled from a remote operator location. The operator is assisted by support functions to enhance operation. 3. Semi-autonomous Target Acquisition (TA) Man-in-the-Loop: Safety-critical equipment performs autonomous surveillance and target acquisition (TA). The safety-critical equipment prepares the system for inspection and / or target engagement (TE) by a human operator. 4. Semi-autonomous TE Man-in-the-Loop. Safety-critical equipment performs autonomous surveillance and target acquisition. Target engagement is authorized by the operator location based on information provided by the safety-critical equipment. 5. Pre-authorized TE, Supervised Man-on-the-Loop. Safety-critical equipment is authorized for limited engagement while retaining human supervision. This can be defined, for example, by the class of objects within a given area. The safety-critical equipment performs autonomous surveillance, targeting, and engagement within the defined perimeter.

[0014] In scenarios involving robotic combat vehicles (RCVs), authorization to proceed is given by one or more operators. Therefore, it is crucial that there is a fail-safe method for granting authorization and monitoring and terminating initiated operations. This is especially true in scenarios where initiated operations are performed by artificial intelligence (AI) capabilities on the remote device.

[0015] The above system for operating safety-critical equipment over a non-safety network transfers safety barriers and signals over an IP / Ethernet network and provides remote control functionality, i.e., a suitable solution for systems that manually control safety-critical equipment using available wireless communications. Remote control is a solution compliant with Levels 1 to 3 above.

[0016] While all levels require safe operation, levels 4 and 5 are associated with stricter ethical aspects and regulations and require different solutions with even higher safety, since launch must be initiated by a remote robotic operator.

[0017] The US Department of Defense has established clear rules for the ethical use of Remote Combat Vehicles (RCVs), which mandate the possibility of monitoring and disrupting malfunctioning weapon systems. This means that radio communication to the RCV must be present at all times, i.e., have high availability, e.g., UHF.

[0018] The dual radio solution concept is a result of the recognition that high bandwidth radios do not provide sufficient geographic coverage and that increased RCV autonomy levels are necessary to reduce the demands on radio communications. In a dual radio solution, operational autonomy levels 1-3 can be performed on the high bandwidth radio, while operational autonomy levels 4 and 5, which require authorization to engage, are performed on the high availability radio.

[0019] The applicant has developed a dual wireless communication solution using a hardware safety barrier to operate safety-critical equipment over a non-safety network and provide release of the safety-critical equipment, which complies with operational autonomy levels 3-5 and is referred to as the E-stop solution. This solution is disclosed in U.S. Patent No. 6,239,999, which is incorporated herein by reference. [Prior art documents] [Patent documents]

[0020] [Patent Document 1] U.S. Patent No. 10,063,522 [Patent Document 2] US Patent Application Publication No. 2023 / 0229794 Summary of the Invention [Problem to be solved by the invention]

[0021] To fully comply with operational autonomy levels 4 and 5, various options have been evaluated and discarded. One is to separate the different software (SW) tasks representing the safety process steps on the Extended Capability Computer (ECC), while the Robot Operator Server (RO-S) detects and identifies attack targets and controls the operation of safety-critical equipment based on this. Another option was to use a separate HW card (CPI Interface Safety Client, CISC) connected to the ECC to provide the safety interface to the launch control system (MPU). The weakness of the various options evaluated is that there is only one decision point for the robot operator, and true diversity cannot be easily established.

[0022] The objective of this invention is to provide a system and method that complies with Operational Levels 4 and 5 by providing a versatile and safe solution for a human operator to authorize a Robot Operator (RO) to fire a weapon. A secondary objective is to allow the safety-approved launch control SW on the safety-critical device's Main Processing Unit (MPU) to remain unaffected by the RO's use and to maintain a consistent safety architecture by treating the RO as any other operator in a multi-user configuration. The MPU provides the launch control system for the safety-critical launch device.

[0023] This solution therefore enables safe launch operations from ROs operating according to Levels 4 and 5 without introducing significant architectural changes to the launch control systems of safety-critical devices.

[0024] The above solution provides true versatility and meets the stringent safety requirements associated with operational autonomy levels 4 and 5, where safety-critical equipment performs autonomous surveillance and target acquisition. For level 4, target engagement is permitted via high-availability radio from a nearby operator location based on information provided to the operator by the safety-critical equipment. [Means for solving the problem]

[0025] The present invention relates to a system and method for authorizing and executing safe semi-autonomous engagement of remotely located safety-critical launchers.

[0026] This system is a human-machine interface provided in a nearby location and having input means, the human-machine interface including at least one hardware safety barrier and a hardware barrier communication means having an interface connected to a network, the network providing at least three different signal communication channels, namely a first signal communication channel for carrying activation control signals (PALM), a second signal communication channel for carrying authorization signals, and a third signal communication channel for carrying arming control signals (ARM); a control unit and a robot operator server provided at a remote location and connected to a launch control system of a safety-critical launcher and to a network, the control unit adapted to receive an activation control signal (PALM) carried on a first signal communication channel, the control unit including at least one hardware safety barrier and a hardware barrier communication means having an interface connected to the network, and a third signal communication channel as a closed-loop signal communication channel between the human-machine interface and the hardware safety barrier of the control unit, for forwarding an arming control signal (ARM) to the launch control system of the safety-critical launcher via the control unit, the robot operator server including software (SW) for detecting and locking on an attack target, providing authorization information to the human-machine interface via a second signal communication channel of the network, and forwarding a trigger signal (TRIG) to the launch control system when authorization to engage is confirmed by an operator via a control panel; Activate the safety-critical launcher when the launch control signal (PALM), armed control signal (ARM) and trigger signal (TRIG) are all present in the launch control system.

[0027] The various devices and units included in the system allow for diversity by providing three different signal communication channels, one for each of the activation signals, i.e. PALM signal, Clear to Proceed signal, and ARM signal.

[0028] In one embodiment, the network is a high availability wireless network, which ensures availability of safety-critical signals between the human machine interface and the safety-critical devices.

[0029] In one embodiment, the connection between the control unit controlling the Authorization to Proceed (AtP) and the launch control system (MPU) is a wired connection.

[0030] In one embodiment, the system further comprises an additional wireless communication channel that provides high bandwidth wireless signals for manually monitoring and controlling the operation of the safety-critical launcher.

[0031] In one embodiment, the system further comprises a switch connected to the hardware barrier of the human machine interface for connecting or disconnecting the closed loop signal communication channel between the hardware safety barrier of the control panel and the control unit.

[0032] The present invention is further defined by a method for authorizing and conducting safe semi-autonomous engagement of a remotely located safety-critical launcher.

[0033] This method is providing a human-machine interface at a nearby location, the human-machine interface comprising at least one hardware safety barrier with input means and hardware barrier communication means with an interface connected to a network providing at least three different signal communication channels; providing a control unit at the remote location, connecting the control unit to the launch control system of the safety-critical launcher and to the network, the control unit including at least one hardware safety barrier and a hardware barrier communication means having an interface connected to the network, forming a closed-loop signal communication channel carried over the network between the human-machine interface and the hardware safety barrier of the control unit; transmitting control signals carried on a first signal communication channel of the network from the human machine interface to the control unit, the signals including a launch control signal (PALM) for launching a safety-critical launch device; Transferring a launch control signal (PALM) from the control unit to the launch control system of the safety-critical device; When activated, the safety-critical launcher executes the integrated attack target detection SW on the robot operator server, detects and locks onto the attack target, provides authorization information carried on a second signal communication channel of the network to the human-machine interface, and requests authorization to engage; transmitting an arming control signal (ARM) from the human-machine interface to the control unit over a third signaling communication channel carried on the closed-loop signaling communication channel of the network when authorization to engage is confirmed by the operator via the human-machine interface; Arming the selected launcher by transmitting an Arming Control Signal (ARM) from the control unit to the launch control system of the safety-critical device; If authorization is given via the Armed Control Signal (ARM) and the locked-on target is consistent, transmitting a Trigger Signal (TRIG) from the robot operator server to the Fire Control System; the launch control system receiving a launch control signal (PALM) and an arm control signal (ARM) from the control unit as authorization from the operator, and activating the safety-critical device when the following criteria are met: authorization is confirmed and the launch control system receives a trigger signal (TRIG) from the robot operator server.

[0034] In one embodiment, the control signals are transmitted over a network that provides a highly available wireless signal.

[0035] In one embodiment, the confidence level of the locked target is increased during the period between when the authorization is requested and when the authorization is confirmed, thereby ensuring that the authorization given to the RO is used to engage the same target for which the authorization request was given.

[0036] In one embodiment, the authorization information provided by the robot operator server to the human machine interface includes information presented on a map showing the location of its own forces, locked targets, and safety-critical launchers.

[0037] In one embodiment, the damage assessment information is transmitted from the robot operator server to the human machine interface via a second signal communication channel of the network.

[0038] In one embodiment, a configuration signal (Config RO) to configure the SW that controls the safety-critical launch device is sent to the robot operator server via the human machine interface.

[0039] In one embodiment, an Armament Control Signal (ARM) is instantiated, with one instance specifying which weapon to arm, i.e., the operator can select the appropriate weapon based on the type of target locked on.

[0040] In one embodiment, manual control of the safety-critical launcher is performed via high bandwidth radio signals. [Brief explanation of the drawings]

[0041] [Figure 1] FIG. 1 is a schematic block diagram showing a previously developed E-stop system used in safety-critical equipment. [Figure 2] FIG. 1 illustrates various launch barriers communicated over a highly available wireless interface. [Figure 3] FIG. 10 is a diagram illustrating an example of a permission sequence. DETAILED DESCRIPTION OF THE INVENTION

[0042] The present invention will be described in detail below with reference to the drawings showing embodiments.

[0043] As noted in the Background of the Invention section above, a solution is needed that complies with the safety requirements for operating safety-critical equipment at Operational Levels 4 and 5. To that end, the solution provides:

[0044] -High availability radios that are always present for communication between safety-critical equipment and operators authorizing engagement. -Operating safety-critical equipment over a non-safety network and using an E-stop solution with dual wireless safety protocol communication with a hardware safety barrier to provide release of operation of the safety-critical equipment. -True versatility in safety barriers. -The MPU launch control system on the MPU is not affected by the introduction of RO. -Permit information and procedures. -Monitoring and disruption solutions.

[0045] To provide fail-safe operation levels 4 and 5, three different signal communication channels are applied: one for the launch control signal (PALM), one for the authorization signal, and one for the arming control signal (ARM). These signals are carried as different signal communication channels, preferably over high-availability radio with limited available bandwidth. Each communication channel is continuously diagnosed for connection failures and transmission errors, and any critical failures will place the system in a safe state through the deactivation of the associated barrier carrying the signal.

[0046] The new solution includes a hardware (HW) barrier for carrying the arming control signal (ARM). For this, the CPI interface described above is used to provide closed-loop control over the network and, through this, reliable transmission of the HW barrier signal from the operator to the MPU. The CPI interface is used as an example of a usable HW barrier, but other HW barrier solutions are also feasible. Reliable activation / deactivation of one of the barriers for operation of safety-critical equipment is performed by actuating a physical switch. However, additional features are implemented in the new solution to provide an even higher level of safety, complying with Level 4 and 5 operation.

[0047] 1 is a schematic block diagram illustrating one embodiment of a system with a HW barrier, where one HW barrier is used for arming control signals (ARM) conveyed to a safety-critical device 160 via a secure communication channel 142 of a non-secure network 140 and to provide secure engagement and disengagement of arming operations of the safety-critical device 160 by actuating a physical switch 120, i.e., an ARM switch. The safety-critical device 160 may be, for example, a robotic combat vehicle (RCV) equipped with a weapon station (WS).

[0048] The HW barrier at the nearby location where the operator is located includes a first control panel interface 100 connected to an input device 120. The input device 120 is an arming control device for enabling an arming control signal (ARM).

[0049] The HW barrier is adapted to transmit an arming control signal (ARM) to a remote safety-critical device 160. The first control panel interface 100 includes a hardware barrier communication means 106 and a hardware safety barrier 102 with a safety barrier interface. The figure shows an example in which an operator input device 120 is connected to the hardware safety barrier 102. The hardware safety barrier 102 is further connected to the hardware barrier communication means 106 for secure communication over a non-secure network 140.

[0050] The state of the circuits in the Launch Control Unit (MPU) that receive the Armament Control Signal (ARM) is sampled and signaled back to the local operator location, allowing the user to see the actual state of the ARM circuits on the MPU.

[0051] The non-secure communication network 140 may be a packet-based communication network, such as an Internet Protocol (IP) network.

[0052] The HW barrier further includes a second control panel interface 150 adapted to connect to the remote safety-critical device 160 and to receive arming control signals (ARM) from the first control panel interface 100. The second control panel interface 150 includes at least a hardware safety barrier 152 with a hardware barrier communication means 156 and a safety barrier interface connected to the hardware barrier communication means 156 for communication over the non-safety network 140.

[0053] The figure also shows an embodiment further comprising a switch 115 connected to the first and second hardware safety barriers 102, 104 of the first control panel interface 100, where the switch 115 controls Hi and Lo signal inputs on the hardware safety barriers, with the Hi signal input to the first hardware safety barrier 102 and the Lo signal input to the second hardware safety barrier 104, and vice versa, respectively, to enable and disable the safety-critical device 160. FIG. 1 also shows an embodiment in which a light source 117 is connected to the first and second hardware safety barriers 102, 104 of the first control panel to indicate the state of the safety-critical device 160. The function of the HW barriers, including the switch 115 and light source 117, referred to as E-stops, is described in detail in the aforementioned patent document 2.

[0054] FIG. 2 illustrates a dual-radio solution in which safety-critical signals controlling engagement of safety-critical equipment 200, which may be operated by a robot operator (RO), are carried over a high-availability radio interface with the RO, while other signals are carried over a high-bandwidth radio. The RO typically includes several different modules, such as modules for threat acquisition, target acquisition, an authentication server, and a robot fire controller. The dual-radio solution meets the requirements associated with all operational autonomy levels 1 through 5. Signals for operational autonomy levels 1 through 3 are carried over a high-bandwidth radio, while signals for operational autonomy levels 4 and 5 are carried over a high-availability radio. Safety-critical equipment 200 may include a robotic combat vehicle (RCV) 210 with a weapon station (WS) 220.

[0055] The operator of the human-machine interface 260 can seamlessly switch between autonomous operation of the safety-critical equipment 200 by confirming permission to proceed and manual movement control of the robotic combat vehicle 210 and manual control of the weapon station 220 by manipulating the input means 270 connected to the human-machine interface 260.

[0056] The main component of the solution is the Control Unit 250, which is an Advance Permission Unit (AtPU), which may include a CPI solution that interfaces to a highly available wireless connection and may also provide E-Stop functionality.

[0057] The operator enables the autonomous mobility and operation of the safety-critical device 200 by enabling the RO of the safety-critical device 200 and taking control. The launch control system 230 (MPU) arbitrates based on PALM signals from the AtPU to the MPU. This means that handover of control to the RO does not require special adjustments to the launch control SW, and the operator can take control at any time if high-bandwidth radio is available. The operator can return to manual control by disabling the RO. In this way, the launch control system 230 is adapted to arbitrate between the robot operator and the human operator.

[0058] In this solution, the Armament Control Signal (ARM) is carried on a separate signal communication channel through the HW barrier, and signals can be connected or disconnected, thereby enabling or disabling the Armament Control Signal (ARM) sent to the Launch Control System 230 (MPU).

[0059] To obtain the necessary diversity for weapon station 220 launches, i.e., to comply with Operational Levels 4 and 5, a separate signal communication channel is provided for activating and enabling (PALM) safety-critical equipment 200, and another signal communication channel for authorization to engage.

[0060] The trigger signal (TRIG) is generated by the ROSW on the Extended Capabilities Computer (ECC) of the Robot Operator Server 240, which is connected to the Main Processing Unit (MPU) of the Fire Control System 230, which is connected to the Weapon Station 220. The ECC is a rugged Military Off-the-Shelf (MOTS) computer that hosts the RO-S (Robot Operator Server SW), which includes the Authorization Server SW, which processes authorization requests and confirmations.

[0061] The trigger signal is generated based on provisioning of authorization from a human operator (ARM).

[0062] The various units included in the system and how they control the various signals are as follows:

[0063] Human Machine Interface 260 (HMI): The arming control signal (ARM) is controlled through the HW barrier, the enabling signal (PALM) is controlled by separate enabling client SW (EN-C) and enabling server SW (EN-S), and the authorization signal (TRIG) is controlled by separate robot operator client SW (RO-C) and robot operator server SW (RO-S).

[0064] Control Unit 250 (AtPU): The arming control signal (ARM) is a HW signal transmitted transparently through the AtPU, the enabling signal (PALM) is controlled by another SW to activate the HW signal, and the enabling signal (TRIG) is transmitted transparently through the AtPU.

[0065] Robot Operator Server 240 (ECC): Armed Control Signal (ARM) is not applicable, only status is received from Launch Control System 230 (MPU), Enable Signal (PALM) is not applicable, only status is received from Launch Control System 230 (MPU), Authorization Signal (TRIG) is controlled by another SW for activating HW signals.

[0066] The launch control system 230 (MPU) includes a standard safety design with ARM, PALM, and TRIG applied as individual safety barriers.

[0067] This means that regardless of any errors that may occur, the two additional units for controlling the launch ensure that no unintentional launch occurs.

[0068] If an error occurs in the human machine interface 260 (HMI), three independent units must fail within the same time interval that the ECC requests permission.

[0069] If an error occurs in the control unit 250 (AtPU), two independent units must fail within the same time interval that the ECC requests permission, and this also applies to the robot operator server 240 (ECC).

[0070] The operation of the launch control system 230 (MPU) remains unchanged with respect to normal operation.

[0071] Figure 3 shows how the above HW interact to provide an authorization sequence compliant with Secure Operation Levels 4 and 5.

[0072] This diagram shows the signal flow between the various HW devices involved in the system. As shown, signals are transferred between the Weapon Station 220 (WS) Human Machine Interface 260 (HMI), Control Unit 250 (AtPU), Robot Operator Server 240 (ECC), and Fire Control System 230 (MPU). The thick black lines indicate signals that can be disconnected by the E-stop.

[0073] The first stage is a system setup stage where a configuration signal (Config RO) is transferred from the human machine interface 260 to the robot operator server 240. The SW may include, for example, detection rules, firing rules, target lock rules, etc. that apply to the area in which the safety-critical device 200 is operating.

[0074] During the handover phase, the safety-critical device 200 is activated to act as a robot operator (RO) and an enable signal (EN) is sent from the human machine interface 260 via a first signal communication channel provided by a secure SW communication channel via CPI signaling to the control unit 250, which forwards it as a launch control signal (PALM) to the launch control system 230.

[0075] Once activated, the RO initiates the threat detection phase, Automatic Target Recognition (ATR), and performs a sector scan for threat detection, typically according to detection rules controlled by SW installed on the robot operator server 240.

[0076] The Robot Operator (RO) threat detection algorithm, typically a convolutional neural network, is configured to report threats above a predetermined confidence level. The time between requesting authorization and granting authorization increases the confidence level for maintaining target track. It is paramount to ensure that the authorization provided to the RO is used to engage the same target for which the authorization request was granted. This authorization check, which ensures authorization validity, requires maintained / uninterrupted target track, authorization timeout, and possibly even target location boundaries.

[0077] Video of the detected threat is captured by the safety-critical device 200 and forwarded to the launch control system 230, which forwards it to the robot operator server 240, which executes SW that defines the detection rules, etc.

[0078] Once a threat is detected, the target acquisition phase begins, with the robot operator server 240 evaluating and interpreting the captured video, possibly optimizing target acquisition before locking onto the target. These control signals are sent to the launch control system 230.

[0079] Once locked onto the threat, the next stage is the authorization stage, where the robot operator server 240 transmits authorization information carried on a second signal communication channel of the network to the human machine interface 260 for presentation to the operator, thereby requesting authorization to engage. The authorization information may include a still image, location, threat class, sufficient additional information, such as the location of the threat on a map and the location of WS and friendly forces, provided in an appropriate user interface.

[0080] The operator of human machine interface 260 can then authorize the safety-critical launcher 200 to launch based on the presented authorization information by initiating transmission of an authorization signal from human machine interface 260 to launch control system 230. The authorization signal is conveyed as a HW barrier signal, preferably over high availability radio, via control unit 250 to launch control system 230. For example, a different type of weapon to be armed, such as a gun / missile, is selected by the operator, and a corresponding arming control signal is conveyed via the HW barrier.

[0081] The Arming Control Signal (ARM) state is then sent from the launch control system 230 to the robot operator server 240 to confirm authorization and which weapons to arm. Based on this information, the RO changes state and the autonomous target engagement phase begins. The robot operator server 240 verifies authorization prior to engagement by evaluating a series of criteria, including:

[0082] -Was a high level of confidence in target lock maintained for the duration of the authorization? -Was the permission received within the allowed time? - Were all system conditions stable during the permitting phase?

[0083] If so, the robot operator can optimize target engagement (TE) parameters, such as ballistics, before firing the trigger to engage the target.

[0084] A launch notification is then sent from the robot launch controller 240 to the human machine interface 260 before forwarding a trigger signal (TRIG) to the launch control system 230 .

[0085] Launch control system engagement is performed when the launch control signal (PALM), armed control signal (ARM), and trigger signal (TRIG) are received by the launch control system 230.

[0086] In the final step, damage assessment is performed by sending information from the robot launch controller 240 to the human machine interface 260 for presentation to the operator.

[0087] The operator can then disable the authorization signal sent to the launch control system 230, which will send a disabled arm signal status to the robot operator server 240.

[0088] 3 does not show continuous operator monitoring of safety-critical equipment 200, which includes information such as platform position, movement, and status, as well as weapon system position, line of sight (LoS) direction, field of view (FoV), and status.

[0089] The solution presented here provides versatility as well as autonomous launch system (RO) initiated triggers.

[0090] This is achieved by the following steps: - The enable signal (PALM) is set by the control unit 250, ie the advance permission unit (AtPU). - Transports Armament Control Signals (ARM) through the HW barrier (via the AtPU) to the Launch Control System 230 (MPU), which provides security verification of the transmitted signals. - Have the robot operator server 240 (ECC) detect the target and request permission, which is granted, to activate the trigger by sending a trigger signal (TRIG) to the launch control system 230 (MPU). Three different signaling channels for carrying PALM, ARM, and authorization signals are continuously diagnosed for connection failures or transmission errors, and any critical faults will set the system into a safe state via the deactivation of the associated barriers.

[0091] Acronyms and Abbreviations AI artificial intelligence AtP progress allowed AtPU AtP unit ATR Automatic Target Recognition CISC CPI Interface Safety Client CPI Control Panel Interface DoD Department of Defense ECC Enhanced Computer FoV field of view HMI Human Machine Interface IOP Unmanned Ground Vehicle (UGV) Interoperability Profile IP Internet Protocol LoS line of sight MPU Main Processing Unit RCV Robot Combat Vehicle RO Robot Operator TA Attack Target Acquisition TE Target Engagement WS Weapon Station

Claims

1. 1. A system for authorizing and executing safe semi-autonomous engagement of a remotely located safety-critical launcher (200), the system comprising: a human-machine interface (260) provided at a nearby location and having an input means (270), the human-machine interface (260) including at least one hardware safety barrier and a hardware barrier communication means having an interface connected to a network (140), said network (140) providing at least three different signal communication channels: a first signal communication channel for carrying activation control signals (PALM), a second signal communication channel for carrying authorization signals, and a third signal communication channel for carrying arming control signals (ARM); a control unit (250) and a robot operator server (240) located at a remote location and connected to a launch control system (230) of the safety-critical launcher (200) and to the network (140); The control unit (250) is adapted to receive the activation control signal (PALM) carried on the first signal communication channel; the control unit (250) includes at least one hardware safety barrier and a hardware barrier communication means with an interface connected to the network (140); the third signal communication channel as a closed-loop signal communication channel between the human-machine interface (260) and the hardware safety barrier of the control unit (250) to transmit the arming control signal (ARM) to the launch control system (230) of the safety-critical launcher (200) via the control unit (250); the robot operator server (240) includes software (SW) for detecting and locking onto a target, providing authorization information to the human-machine interface (260) via the second signal communication channel of the network, and transmitting a trigger signal (TRIG) to the launch control system (230) when authorization to engage is confirmed by an operator via the control panel (260); and actuating the safety-critical launcher (200) when the activation control signal (PALM), the arming control signal (ARM), and the trigger signal (TRIG) are all present in the launch control system (230).

2. The system of claim 1 , wherein the network is a high-availability wireless network.

3. 3. The system of claim 1, wherein the connection between the control unit (250) and the launch control system (230) is a wired connection.

4. The system of claim 1 , further comprising an additional wireless communication channel providing a high bandwidth wireless signal for manually monitoring and controlling the operation of the safety-critical launcher (200).

5. 5. The system of claim 1, further comprising a switch (275) connected to the hardware safety barrier of the human-machine interface (260) for connecting or disconnecting the closed-loop signal communication channel between the hardware safety barrier of the control panel (260) and the control unit (250).

6. 1. A method for authorizing and executing safe semi-autonomous engagement of a remote safety-critical launcher (200), comprising: providing a human-machine interface (260) at a nearby location, comprising an input means (270) and including at least one hardware safety barrier and a hardware barrier communication means with an interface connected to a network (140) providing at least three different signal communication channels; providing a control unit (250) at a remote location, connecting the control unit (250) to the launch control system (230) of the safety-critical launcher (200) and the network, the control unit (250) including at least one hardware safety barrier and a hardware barrier communication means having an interface connected to the network, forming a closed-loop signal communication channel carried over the network between the human-machine interface (260) and the hardware safety barrier of the control unit (250); transmitting a control signal carried on a first signal communication channel of the network from the human-machine interface (260) to the control unit (250), the control signal including an activation control signal (PALM) for activating the safety-critical launcher (200); transferring the activation control signal (PALM) from the control unit (250) to the launch control system (230) of the safety-critical device (200); Upon activation, the safety-critical launcher (200) executes an integrated target detection SW on a robot operator server (240) to detect and lock onto a target, and provides authorization information carried on a second signal communication channel of the network (140) to the human-machine interface (260) to request authorization to engage; transmitting an arming control signal (ARM) from the human machine interface (260) to the control unit (250) over a third signaling communication channel carried over the closed-loop signaling communication channel of the network (140) once authorization to engage is confirmed by an operator via the human machine interface (260); transmitting the arming control signal (ARM) from the control unit (250) to a launch control system (230) of the safety-critical device (200) to arm the selected launcher; If authorization is granted via the arming control signal (ARM) and the locked-on target is consistent, transmitting a trigger signal (TRIG) from the robot operator server (240) to the launch control system (230); the launch control system (230) receives the activation control signal (PALM) and the arming control signal (ARM) from the control unit (250) as authorization from the operator, and activates the safety-critical launcher (200) when the following criteria are met: authorization is confirmed, and the launch control system (230) receives the trigger signal (TRIG) from the robot operator server (240).

7. The method of claim 6 , wherein the network is a network that provides a high availability radio signal.

8. 8. The method of claim 6 or 7, wherein the confidence level of the locked target is increased during the period between when the authorization is requested and when the authorization is confirmed.

9. 9. The method of claim 6 or 8, wherein the authorization information provided by the robot operator server to the human machine interface includes information presented on a map showing the location of own forces, locked targets, and safety-critical launchers.

10. The method of any of claims 6 to 9, wherein damage assessment information is transmitted from the robot operator server (240) to the human machine interface (260) via the second signal communication channel of the network.

11. The method of any one of claims 6 to 10, wherein a configuration signal (Config RO) for configuring SW controlling the safety-critical launch device (200) is sent to the robot operator server (240) via the human machine interface (260).

12. A method according to any of claims 6 to 11, wherein the Armament Control Signal (ARM) is instantiated, one instance defining which weapon is to be armed.

13. The method of claim 6, wherein manual control of the safety-critical launcher (200) is performed via a high-bandwidth radio signal.

14. 7. The method of claim 6, comprising operating a switch (275) connected to the hardware safety barrier of the human-machine interface (260) to connect or disconnect the closed-loop signal communication channel between the hardware safety barrier of the control panel (260) and the control unit (250).

Citation Information

Patent Citations

  • System and method for operating a safety-critical device over a non-secure communication network

    US10063522B2

  • Method and system for operating a safety-critical device via a non-secure network and for providing reliable disengagement of operations of the device

    US20230229794A1