Refueling station control system

The multi-controller system addresses the challenge of costly regulatory re-approvals by using a pre-approved failsafe controller to verify operations controller outputs, ensuring safety and efficiency in gas filling stations.

WO2026006324A1PCT designated stage Publication Date: 2026-01-02HEXAGON PURUS NORTH AMERICA HOLDINGS INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/US2025/035063
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-27
Filing Date
2025-06-24
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

Safety regulations and protocols for gas filling stations require extensive and costly re-approval of controller data each time modifications are made, hindering efficient updates and increasing deployment difficulties.

Method used

A multi-controller system with a failsafe controller and an operations controller, where the failsafe controller is pre-approved by regulatory bodies and verifies the outputs of the operations controller, allowing data manipulation without re-approval, ensuring compliance while reducing regulatory reviews.

Benefits of technology

The system enhances safety and flexibility by minimizing regulatory approvals, reducing costs, and improving the efficiency of updating and managing gas filling stations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025035063_02012026_PF_FP_ABST
    Figure US2025035063_02012026_PF_FP_ABST
Patent Text Reader

Abstract

Systems and techniques are provided for using multiple controllers to control operations of a gas fuel system. An example method can include receiving, from a failsafe controller, a portion of pre-approved data programmed on the failsafe controller, the failsafe controller having a restriction that requires the pre-approved data to be re-approved by a regulatory entity if the pre-approved data is modified; sending, to the failsafe controller, an output generated based on the portion of the pre-approved data, the output identifying a proposed operation for the gas filling station and / or a parameter associated with the proposed operation; receiving, from the failsafe controller, a signal indicating whether the proposed operation and / or parameter complies with a safety constraint; and based on the signal, approving / rejecting the proposed operation and / or parameter.
Need to check novelty before this filing date? Find Prior Art

Description

REFUELING STATION CONTROL SYSTEMBACKGROUNDCROSS-REFERENCE TO RELATED APPLICATIONS

[0001] The present application claims the benefit of U.S. Provisional Application No. 63 / 665,210 filed on June 27, 2024, which is hereby incorporated by reference in its entirety.1. Technical Field

[0002] The present disclosure generally relates to a control system and architecture for managing and controlling operations and parameters of systems used to transfer or dispense fuel such as gas filling stations and other fuel transportation and transfer systems.2. Introduction

[0003] Gas-powered vehicles have become an important or even integral part of transportation systems and economies around the world. The widespread use of gas-powered vehicles and other power-generation systems has created increasing demands for refueling systems, stations, and technologies used to fuel / refuel the gas-powered vehicles and other power-generation systems. Moreover, the increasing demands for refueling systems, stations, and technologies have fueled efforts to deploy better, safer, and more efficient refueling systems and stations, such as gas filling stations. However, the combustibility, volatility, flammability and other properties of typical gas fuel sources, such as hydrogen, create a number of safety issues for refueling systems, stations, and procedures. Consequently, safety regulations, standards, and practices have emerged to address the various safety issues associated with refueling systems, stations, and procedures. Nevertheless, the safety regulations, standards, and practices, as well as the demands for better safer, and more efficient refueling systems and stations have created difficult challenges in deploying or updating refueling systems and stations, managing refueling systems and stations, and dispensing gas to gas-powered systems and vehicles.BRIEF DESCRIPTION OF THE DRAWINGS

[0004] The various advantages and features of the present technology will become apparent by reference to specific implementations illustrated in the appended drawings. A person ofordinary skill in the art will understand that these drawings only show some examples of the present technology and would not limit the scope of the present technology to these examples. Furthermore, the skilled artisan will appreciate the principles of the present technology as described and explained with additional specificity and detail through the use of the accompanying drawings in which:

[0005] FIG. 1A illustrates an example gas filling station for a vehicle, according to some examples of the present disclosure;

[0006] FIG. IB illustrates an example of transportable gas filling station, according to some examples of the present disclosure;

[0007] FIG. 2 illustrates an example control system for managing and controlling operations and parameters of a gas filling station, according to some examples of the present disclosure;

[0008] FIGs. 3A and 3B are flow diagrams illustrating example processes for using a first controller of a gas filling station to perform a plausibility check on outputs from a second controller of the gas filling station, according to some examples of the present disclosure;

[0009] FIG. 4 is a flowchart illustrating an example method for managing and controlling operations and parameters of a gas filling station using a multi-controller system, according to some examples of the present disclosure; and

[0010] FIG. 5 illustrates an example processor-based system architecture for implementing certain aspects of the present disclosure.DETAILED DESCRIPTION

[0011] The detailed description set forth below is intended as a description of various configurations of the subject technology and is not intended to represent the only configurations in which the subject technology can be practiced. The appended drawings are incorporated herein and constitute a part of the detailed description. The detailed description includes specific details for the purpose of providing a more thorough understanding of the subject technology. However, it will be clear and apparent that the subject technology is not limited to the specific details set forth herein and may be practiced without these details. In some instances, structures andcomponents are shown in block diagram form in order to avoid obscuring the concepts of the subject technology.

[0012] As previously explained, gas-powered vehicles have become an important or even integral part of transportation systems and economies around the world. The widespread use of gas-powered vehicles and other power-generation systems has created increasing demands for refueling systems, stations, and technologies used to fuel / refuel the gas-powered vehicles and other power-generation systems, as well as buffers used to transport and distribute stored gas. Moreover, the increasing demands for refueling systems, stations, and technologies have fueled efforts to deploy better, safer, and more efficient refueling systems and stations, such as gas filling stations. However, the combustibility, volatility, flammability and other properties of typical gas fuel sources as well as the risks of overpressure and overtemperature of systems (e.g., cylinders, buffers, etc.) used to transport and / or transfer gas fuel sources, create a number of safety issues for refueling systems, stations, and procedures as well as other systems used to transport and transfer gas fuel sources. Consequently, safety regulations, standards, and practices have emerged to address the various safety issues associated with refueling systems, stations, and procedures. For example, refueling methods and regulations for compressed gas, such as hydrogen, have been created to address safety issues associated with gas filling stations (also referred to as refueling stations) and associated operations.

[0013] Moreover, fueling protocols have been established to increase the safety of gas filling stations and associated operations. For example, the society of automotive engineers (SAE) has established standard fueling protocols that define refueling guidelines and safety parameters. In some cases, applicable regulations designed to improve the safety of gas filling stations and associated operations may adopt or incorporate a standard fueling protocol(s) and / or aspects of a standard fueling protocol(s) such as refueling guidelines, limits, and / or safety parameters. While safety regulations, standards, and practices can improve the safety profile of gas filling stations and gas dispensing operations, they can also increase the difficulty, cost, and amount of time in deploying or updating gas filling stations, managing gas filling stations, and dispensing gas to gas- powered systems and vehicles.

[0014] For example, in some cases, a gas filling station can include a controller used to execute, manage, and / or control operations to dispense gas to vehicles. The controller and associated data used to execute, manage, and / or control the operations of the gas filling station,such as gas dispensing operations, may be subject to safety regulations that require the code and data used by the controller to be reviewed and approved by a regulating body (or an associated entity or agent). In some cases, the safety regulations may require such code and data to be reviewed and re-approved each time any modification is made to the code and / or the data. To illustrate, when an operation(s) and / or associated code of a controller is / are modified or updated, the safety regulations may require the entire code of the controller to be reviewed and re-approved, even if the changes to the operation(s) and / or code are minor. However, the review and approval process can be costly, time consuming, and inefficient. Moreover, the requirement to review and re-approve the code of the controller each time a modification or update is made can significantly increase the cost, time, and difficulty of implementing any changes to the controller (e.g., to the associated code and data), and may even dissuade a gas filling station operator from updating the controller.

[0015] Systems, apparatuses, processes (also referred to as methods), and computer-readable media (collectively referred to as “systems and techniques”) are described herein for controlling operations and parameters of a system used to store, transport, and / or transfer / dispense gas fuel sources, such as a gas filling station, which uses a multi-controller system that complies with safety regulations and reduce or avoids some or all of the previously-noted challenges and difficulties, including regulatory challenges and difficulties. For example, the systems and techniques described herein can use a multi-controller system to execute, manage, and / or control the operations and parameters of a gas filling station (or any other system used to store, transport, and / or transfer / dispense gas fuel sources), where a first controller (e.g., a failsafe controller) of the multi-controller system is programmed with data reviewed and approved by a regulatory body (or an associated entity or agent) and used to verify data, instructions, and decisions generated by a second controller (e.g., an operations controller) of the multi-controller system. In this example, the second controller can obtain, from the first controller, data pertaining to gas filling operations and use the data to determine proposed operations and / or parameters for the gas filling station. The second controller can also use the data to perform various calculations, including calculations that the first controller is unable to, or prohibited from, performing, and can modify / update the data as needed without requiring re-approved of the data by the regulatory body.

[0016] On the other hand, the first controller can use the data programmed on the first controller to verify, validate, and / or check outputs from the second controller, such as outputsidentifying controller determinations / calculations, proposed operations, proposed parameters, proposed instructions, proposed decisions, etc. Since the first controller is subject to a regulatory requirement that the data programmed on the first controller be re-approved by the regulatory body any time such data is modified / updated, the first controller can maintain its data without changes to avoid having to obtain such re-approval, and instead use such data to perform plausibility checks of outputs from the second controller. If the multi-controller system needs to modify or manipulate any of the data programmed on the first controller, to avoid having to obtain re-approval of the first controller’s data, the second controller of the multi-controller system can obtain a copy of such data from the first controller and modify / manipulate the data as needed since, unlike the first controller, the second controller is not subject to regulations requiring re-approval of its data any time the data is modified / updated.

[0017] For example, the multi-controller system can include a failsafe controller and an operations controller. The failsafe controller and the operations controller can be part of or implemented by separate controller devices or a same controller device (e.g., as different portions of a same controller device). The failsafe controller can be programmed with data reviewed and approved by a regulatory body (or an associated entity or agent), and can be subject to a regulatory requirement that the data programmed on the failsafe controller be re-approved by the regulatory body any time such data is modified / updated, which the operations controller may not be subject to. The failsafe controller can avoid modifying / updating its data, and instead use its data to verify outputs from the operations controller. To verify the outputs from the operations controller, the failsafe controller can use the data programmed on the failsafe controller to check that the outputs from the operations controller comply with one or more safety requirements (e.g., are within one or more safety limits, thresholds, parameters, protocols, values, and / or ranges). If the failsafe controller determines that an output from the operations controller does not comply with a safety requirement, the failsafe controller can prevent or stop such output from being implemented / used by the gas filling station. Otherwise, the failsafe controller can approve the output and allow the gas filling station to implement the output.

[0018] To generate outputs such as proposed operations and / or parameters for the gas filling station, the operations controller can obtain relevant data from the failsafe controller and use such data to generate the outputs. The operations controller can perform various calculations, including one or more calculations that the failsafe controller may be unable to perform (or may be prohibitedfrom performing). The operations controller can revise any of its data, including data obtained from the failsafe controller, without requiring such data to be reviewed and approved by the regulatory body. This way, if a portion of data programmed on the failsafe controller needs to be revised or manipulated in a way that would trigger a regulatory requirement to have such data reviewed and approved by the regulatory body, instead of revising the data on the failsafe controller, the failsafe controller can send such data to the operations controller, which can revise and / or manipulate such data as needed without requiring re-approval of such data from the regulatory body (and without requiring the data programmed on the failsafe controller to be reapproved by the regulatory body since the failsafe controller can avoid revising its data), as the operations controller is not subject to that same regulatory requirement.

[0019] Thus, the architecture of the multi-controller system, including the failsafe and operations controllers, can allow data at the operations controller, including a copy of any data from the failsafe controller, to be manipulated and revised without requiring re-approval of such data by the regulatory body, thereby avoiding such manipulations and revisions to be performed directly on the data programmed on the failsafe controller which would otherwise trigger the regulatory requirement to have the data on the failsafe controller re-approved by the regulatory body. Moreover, the failsafe controller can use its data to perform safety / plausibility checks of outputs from the operations controller, as previously explained. Accordingly, the architecture of the multi-controller system can ensure compliance with safety regulations while providing added flexibilities and functionalities, reducing the number of regulatory reviews and approvals of controller data, avoiding unnecessary regulatory reviews and approvals of controller data, and reducing costs associated with regulatory reviews and approvals of controller data.

[0020] Moreover, the architecture of the multi-controller system can, through the use of the failsafe and operations controllers, increase the safety and reliability of a system implementing the multi-controller system to store, transport, and / or dispense / transfer gas fuel sources such as gas filling stations. For example, the multi-controller system, including the use of the failsafe and operations controllers, can increase the difficulty of malicious manipulation of the code, parameters, and / or operations of a system implementing the multi-controller system to store, transport, and / or dispense / transfer gas fuel sources. Moreover, hardware failures of the failsafe controller can be detected by the operations controller and vice versa. The multi-controller system can also detect and / or correct errors during runtime, and the use of the failsafe controller can allowthe system to obtain necessary regulatory approvals. For instance, safety requirements and protocols, including safety integrity level (SIL) loops, often require known reliability scores and / or probabilities of failure of all components in the system, such as sensors, transmitters, valves, controllers, digital / analog outputs, etc. The multi-controller system described herein can ensure that such safety requirements and protocols are satisfied and correct any potential issues that emerge or have a certain likelihood of emerging.

[0021] FIG. 1 A depicts an example gas filling station 100 for a vehicle 120, according to some examples of the present disclosure. The gas filling station 100 can be configured similar to, or substantially as, a gas station. For example, the vehicle 120 can use the gas filling station 100 to refuel, as shown in FIG. 1A. In this example, the gas filling station 100 includes a gas dispenser 110 configured to dispense gas, such as hydrogen gas, to vehicles such as the vehicle 120. The gas dispenser 110 can include a re-fueling hose 114 with a nozzle 112 configured to detachably connect to a filling port 122 of the vehicle 120. The filling port 122 can be connected to an internal fuel tank (not shown in FIG. 1 A) of the vehicle 120. Thus, the gas from the gas filling station 100 can flow from the gas dispenser 110 to the re-fueling hose 114 and the nozzle 112 connected to the filling port 122 of the vehicle 120. The gas can travel from the nozzle 112 and the filling port 122 of the vehicle 120 to the internal fuel tank of the vehicle 120 to refill the internal fuel tank of the vehicle 120.

[0022] While the example gas filling station 100 is described with respect to vehicle 120 (e.g., a car), the gas filling station 100 can be deployed for refueling any applicable vehicle or gas-fueled system / device such as, for example and without limitation, a movable platform, a truck, a commercial vehicle, an industrial vehicle, a passenger vehicle, an aircraft, an aerial vehicle, a train, a boat or ship, a lawnmower, a motorcycle, a motorized tool or device, a subway vehicle, a watercraft, a locomotive, farm equipment, a construction vehicle, and / or a warehouse vehicle, among others. Moreover, while the gas filling station 100 is described as a refueling station, the gas filling station 100 can include or represent any system(s) and / or device(s) for storing, transporting, and / or transferring / dispensing fuel (and the concepts described herein can apply to any such system(s) and / or device(s)) such as, for example and without limitation, a mobile refueling station and / or unit, a stationary refueling station, a multi-element gas container, a buffer for transporting and / or storing fuel, an electrolyzer and buffer storage system, a fuel distributionsystem, a gas module, and / or any other system(s) and / or device(s) for storing, transporting, and / or transferring / dispensing fuel.

[0023] In some examples, the source of gas dispensed by the gas filling station 100 can be or include one or more tanks storing the gas. For example, in some cases involving hydrogen gas, the source of the hydrogen dispensed by the gas filling station 100 can be or include one or more tanks holding the hydrogen at a lower pressure (e.g., around 100 bar) relative to a desired delivery pressure (e.g., 600-900 bar). In some examples, the source of the hydrogen can be or include a hydrogen generator providing hydrogen gas at near ambient pressure.

[0024] In some examples, the gas filling station can be configured as a mobile refueling station (e.g., a mobile hydrogen refueling station (MHRS)), such as the mobile gas filling station 125 illustrated in FIG. IB. For example, the gas filling station can be configured as a transportable self- contained module or system suitable for re-fueling gas-powered systems (e.g., vehicles, etc.) at remote locations or as part of a temporary installation (e.g., a construction site, a port, an airport, etc.). In other examples, the gas filling station can be configured as a module of a larger installation, such as a re-fueling station for air vehicles installed on a ship. In some cases, the gas filling station can include a multi-element gas container (MEGC) and / or a mobile refueling unit. Moreover, in some cases, the gas filling station can include an electrolyzer, a buffer storage, and / or a gas fuel distribution system. In some examples, gas fuel associated with the gas filling station can be transferred from an electrolyzer to a buffer storage and / or distribution system of the gas filling station.

[0025] FIG. IB illustrates an example mobile gas filling station 125 for refueling vehicles (e.g., a truck, a bus, a rail-bound vehicle, etc.). In this example, the mobile gas filling station 125 can include a detachable tank container 130 and a mobile refueler 140. In some cases, the tank container 130 can be mounted on a chassis of a vehicle (not shown) used to transport the tank container 130, such as a truck, which allows the tank container 130 to be transportable, disconnected from the mobile refueler 140, and / or filled separately.

[0026] The tank container 130 (also referred to as a gas storage unit) can be configured to store any gas, such as hydrogen gas. The size of the tank container 130 can vary depending on the storage capacity desired. In some examples, the tank container 130 can include a control unit 132 for monitoring and / or controlling the status of the tank container 130.

[0027] In some aspects, the mobile refueler 140 (also referred to as a buffer tank or a buffer unit) can include a control panel 142 with a nozzle 144, a buffer storage unit (e.g., a pressure tank) (not shown), a hydrogen compressor (not shown), and / or any applicable control unit. In some examples, the mobile refueler 140 can include a hydrogen pre-cooling unit to facilitate rapid refueling.

[0028] Gas stored in the tanks of the mobile gas filling station 125 (e.g., the tank container 130, the mobile refueler 140) can be dispensed to vehicles (and / or any other systems or devices) from a nozzle, such as nozzle 144. The mobile gas filling station 125 can include a network of pipes between the nozzle and any of the tanks of the mobile gas filling station 125. In some examples, the mobile gas filling station 125 can include one or more process elements (e.g., operation and / or safety elements) along one or more pipe paths. For example, the mobile gas filling station 125 can include one or more pressure relief valves (PRVs) along a pipe path to allow gas to vent (e.g., to release gas to the atmosphere) as needed.

[0029] Moreover, the mobile gas filling station 125 (and the gas filling station 100 shown in FIG. 1 A) can include operations elements (not shown) used to manage the gas in the tanks, control refueling operations, provide safety / failsafe mechanisms for safe containment and dispensing of fuel (e.g., hydrogen etc.), etc. For example, the mobile gas filling station 125 (and the gas filling station 100 shown in FIG. 1 A) can include one or more PRVs, one or more actuators, one or more switches, one or more tamper detection devices, one or more transmitters and / or transceivers, one or more sensors, one or more cooling components, one or more safety devices (e.g., valves, etc.), one or more flow metering and / or control devices, one or more leak detection devices, one or more gas (e.g., hydrogen) flow measurement devices, one or more emergency shutdown systems, one or more gauges, one or more fire-suppression mechanisms, one or more gas distribution and pressure management systems, one or more computing components (e.g., controllers, processors, computers, etc.), one or more compressors, etc. Non-limiting examples of a sensor that can be included or implemented by a gas filling station can include a temperature sensor, a pressure sensor, a fire sensor, a gas sensor, a flame detector, a leakage sensor, a flow sensor, a valve position sensor (e.g., sensor to detect if a valve is open or closed), an impedance sensor, an accelerometer, a gyroscope, an inertial measurement unit (IMU), a motion sensor, a position sensor, animage / camera sensor, a nuclear magnetic resonance (NMR) detector / spectrometer, a location sensor, and / or any other sensor device.

[0030] FIG. 2 illustrates an example control system 200 for a gas filling station, according to some examples of the present disclosure. The control system 200 can be used to manage and control operations and parameters of a gas filling station, such as gas filling station 100 shown in FIG. 1 A or mobile gas filling station 125 shown in FIG. IB. Moreover, the control system 200 can be used to determine and / or implement outputs associated with the gas filling station, such as calculations, operations, tasks, instructions, decisions, settings, values, parameters, etc. Nonlimiting examples of calculations, operations, tasks, decisions, parameters, data, and / or other outputs determined and / or implemented by the control system 200 can include fueling / refueling / operations (e.g., gas dispensing operations), safety / failsafe operations, monitoring operations, containment operations, processing tasks, management operations (e.g., data management, device management, process management, gas management, etc.), compute operations (e.g., calculations, outputs, interpolations, parameter determinations, operation determinations / selections, decision making, prediction estimations, etc.), configuration operations, data collection operations, plausibility checks, control operations, and / or data processing / preprocessing operations, among others.

[0031] The control system 200 can represent a single device or multiple devices. In some cases, the control system 200 can represent a controller system such as, for example, a programmable logic controller (PLC), a system-on-chip (SoC), a single board computer (SBC), an integrated circuit, a processor system (e.g., a central processing unit (CPU), a graphics processing unit (GPU), a digital signal processor (DSP), an accelerated processing unit (APU), a processor core, etc.), a computer, and / or any other processing device(s). In other cases, the control system 200 can represent multiple controller systems such as, for example, multiple PLCs, SoCs, SBCs, integrated circuits, FPGAs, ASICs, computers, and / or any other processing device(s).

[0032] In FIG. 2, the control system 200 includes an operations controller 210, a failsafe controller 220, and hardware elements 230. The operations controller 210 and the failsafe controller 220 can include one or more hardware and / or software processing devices such as, for example and without limitation, one or more PLCs, CPUs, GPUs, ASICs, FPGAs, SoCs, SBCs, integrated circuits, DSPs, APUs, virtual machines (VMs), software containers, processor cores,server computers, datacenters, and / or any other processing device(s). In some examples, the operations controller 210 and the failsafe controller 220 can include, use, or be implemented by a same processor(s) and / or processor-based system(s). In other examples, the operations controller 210 and the failsafe controller 220 can include, use, or be implemented by different / separate processors and / or processor-based systems. For example, the operations controller 210 and the failsafe controller 220 can represent, be part of, or be implemented by a same computing system or different computing systems.

[0033] In one illustrative example, the operations controller 210 and the failsafe controller 220 can be part of or implemented by a same processor-based controller, such as a PLC. To illustrate, the operations controller 210 can represent a portion or section of a PLC, and the failsafe controller 220 can represent another portion or section of the PLC. Here, the operations controller 210 and the failsafe controller 220 can have or use different memory devices or different memory spaces / regions, and can either share one or more processor units (e.g., one or more CPUs, GPUs, DSPs, APUs, processor cores, etc.) or use / include different and / or dedicated processor units. In another illustrative example, the operations controller 210 and the failsafe controller 220 can be part of or implemented by different / separate processor-based controllers, such as different / separate PLCs.

[0034] The hardware elements 230 can be used to implement, manage, and / or control operations, conditions, states, and / or actions associated with the gas filling station. For example, the hardware elements 230 can be used to sensor / measure conditions, collect data, control a flow of gas, manage conditions in / of the gas filling station, dispense gas (and / or control aspects thereof such as how much gas is dispensed, a rate in which the gas is dispensed, starting / stopping the dispensing of gas, etc.), control conditions (e.g., pressure, temperature, density, mass flow or mass flow rate, etc.) of one or more components of the gas filling station (e.g., of the gas, a tank, a dispenser, a hose, an actuator, a door, a pipe, a pathway or line, etc.), etc. Moreover, the hardware elements 230 can include any hardware, software, mechanical, and / or electrical component used to sense / collect data and / or implement / execute tasks, functions, operations, instructions, and / or decisions associated with the gas filling station. Non-limiting examples of hardware elements 230 can include valves (e.g., PRVs, gas valves, emergency and / or safety valves, control valves, etc.), actuators, switches, tamper detection devices, transmitters, transceivers, pumps, motors, coolingcomponents / sy stems, safety devices, tanks, dispensers, hoses, lines, flow metering / measuring devices, flow control devices, emergency shutdown systems, gauges, fire-suppression systems, gas distribution systems, pressure management systems, computing components or systems (e.g., controllers, processors, computers, memories, storages, buffers, displays, peripherals, integrated circuits, etc.), pipes, sensors (e.g., temperature sensors, pressure sensors, fire sensors, gas sensors, flame detectors, leakage sensors, flow sensors, valve position sensors, impedance sensors, accelerometers, gyroscopes, IMUs, motion sensors, position sensors, encoders, fans, inlets / outlets, image / camera sensors, NMR detectors / spectrometers, location sensors, etc.), tools, gates, hoses, and / or any other equipment, devices, and / or components.

[0035] In some examples, the hardware elements 230 (or a portion thereof) can be used to obtain sensor data and measurements associated with conditions or properties of the gas filling station and / or any components thereof. For example, the hardware elements 230 can collect sensor data 250A-B used to monitor and manage the gas filling station (and / or any components thereof), control the gas filling station (and / or associated operations), make decisions and / or determinations associated with the gas filling station, analyze aspects of the gas filling station (e.g., components, conditions, operations, etc.), etc. The sensor data 250A-B can include, for example and without limitation, temperature measurements, pressure measurements, flow measurements, valve position measurements, motion measurements, gas sensor measurements, fire sensor measurements, leakage measurements, position measurements (e.g., location, orientation, etc.), tank fullness measurements, etc. In some aspects, the hardware elements 230 can control operations and / or conditions of the gas filling station via, for example, actuators, valves, cooling components / sy stems, switches, hoses, pipes, lines, motors, gates, nozzles, dispensers, pumps, compressors, sensors / meters / detectors, and / or any other component of the hardware elements 230.

[0036] The failsafe controller 220 can include controller data 240A programmed on the failsafe controller 220. For example, the failsafe controller 220 can include controller data 240A stored on a memory device of, or dedicated to, the failsafe controller 220 and / or a space of memory (e.g., memory location(s), memory region(s), memory unit(s), memory segment(s), etc.) of, or dedicated to, the failsafe controller 220. The failsafe controller 220 can use the controller data 240A to perform calculations, make decisions, determine and / or implement operations, determine and / or implement parameters, check and / or validate data and / or operations, verify regulatorycompliance, verify safety requirements / settings / limits, etc. In some aspects, the failsafe controller220 can use the controller data 240A to perform plausibility checks as further described herein.

[0037] The controller data 240A can include data reviewed and approved by a regulatory body (e.g., entity, agency, organization, etc.) and / or agent thereof. For example, the controller data 240A (and the failsafe controller 220) can be subject to a regulatory constraint / requirement that provides that if any portion of the controller data 240A on or corresponding to the failsafe controller 220 is modified / updated, any or all of the data of the failsafe controller 220 (e.g., the modified / updated version of the controller data 240A) needs to be reviewed and approved again by the regulatory body (and / or an agent thereof). In some examples, the controller data 240A can include logic programmed on the failsafe controller 220, operations data 245, sensor data 250A, and any other data.

[0038] The operations data 245 can include and / or define any safety, functional, operational and / or system / component parameters, settings, guidelines, standards, limits, thresholds, ranges, values, tables, code, and / or data. In some aspects, the operations data 245 can include, for example and without limitation, fueling tables and / or associated values, safety values (e.g., pressure limits / thresholds / ranges such as tank pressure limits / thresholds / ranges, gas pressure limits / thresholds / ranges, temperature limits / thresholds / ranges such as ambient temperature and / or gas temperature limits / thresholds / ranges, average pressure ramp rate (APRR) limits / thresholds / ranges, flow rate limits / thresholds / ranges, device limits / thresholds / ranges, restrictions, etc.), software logic / code, algorithms, artificial intelligence (Al) or machine learning (ML) models, parameters, settings, properties of substances / materials and / or components (e.g., temperature, pressure, mass, density, viscosity, state, volume, weight, geometry, etc.), and / or any other data associated with the gas filling station.

[0039] The sensor data 250A can include any sensor data collected from the hardware elements 230 and / or any other sensors, such as sensors implemented by or integrated into the operations controller 210 and / or the failsafe controller 220. In some aspects, the sensor data 250A can include, for example and without limitation, temperature measurements, pressure measurements, flow measurements, gas measurements, substance measurements, valve position measurements, image data (e.g., sensed video frames and / or still images), content and / or fullness measurements, motion measurements, and / or any other sensor data.

[0040] The operations controller 210 can be programmed with controller data 240B, which can include software logic / code of the operations controller 210, sensor data 250B from the failsafe controller 220 (and / or the hardware elements 230), and operations data 215. The sensor data 250B can include sensor data from the failsafe controller 220, the hardware elements 230, and / or any other sensors such as sensors implemented by the operations controller 210 and / or the failsafe controller 220. In some cases, the sensor data 250B can include all or some of the sensor data 250A of the failsafe controller 220. In some examples, the sensor data 250B can include sensor data that is not included in the sensor data 250A of the failsafe controller 220. In some aspects, the sensor data 250B can include, for example and without limitation, temperature measurements, pressure measurements, flow measurements, gas measurements, substance measurements, valve position measurements, image data (e.g., sensed video frames and / or still images), content and / or fullness measurements, motion measurements, and / or any other sensor data.

[0041] The operations controller 210 can use the controller data 240B to determine one or more actions / operations to be performed by the gas filling station (and / or any components thereof), control any fueling / refueling operations, control any of the hardware elements 230, perform calculations, generate outputs, make decisions, implement parameters, execute code, generate instructions, etc. For example, the operations controller 210 can use the controller data 240B to generate a controller output 255 that includes and / or identifies one or more parameters, operations, tasks, instructions, decisions, steps, commands, settings, requests, data items, fueling tables, and / or values determined, implemented, and / or initiated by the operations controller 210.

[0042] In some examples, the operations data 215 can include a portion or a copy of the operations data 245 programmed on the failsafe controller 210. For example, the operations controller 210 can be configured to receive and process a copy or portion of the controller data 240 A from the failsafe controller 220 and store such data (and any other data generated from such data) as the operations data 215 from the controller data 240B of the operations controller 210. In some cases, the operations data 215 can optionally include other data such as input data, data from any of the hardware elements 230, and / or any other data.

[0043] The failsafe controller 220 can check and / or confirm any information in the controller output 255 from the operations controller 210, such as decisions made by the operations controller 210, steps (e.g., actions, tasks, etc.) determined or proposed by the operations controller 210,instructions generated by the operations controller 210, operations proposed or selected by the operations controller 210, parameters and / or values in the controller output 255, requests in the controller output 255, calculations in the controller output 255, variables in the controller output 255, commands in the controller output 255, and / or any other data in the controller output 255. The failsafe controller 220 can also generate one or more actions, operations, and / or tasks in response to the controller output 255. For example, based on or in response to the controller output 255, the failsafe controller 220 can initiate / execute or stop / prevent steps (e.g., actions / operations, tasks, instructions, etc.) from the operations controller 210 and the controller output 255, supervise conditions and / or operations (e.g., rules, limits, thresholds, parameters, etc.) associated with the gas filling station, control operations of the gas filling station (and / or components thereof), etc.

[0044] In some aspects, the failsafe controller 220 can obtain the controller output 255 from the operations controller 210, and perform a plausibility check on the controller output 255. The plausibility check can check, validate, approve / disapprove, and / or verify information in the controller output 255. For example, the plausibility check can check and / or verify that any values, parameters, operations, instructions, and / or data in the controller output 255 is / are within a safety, desired, predetermined, required, and / or imposed limit, range, threshold, parameter, guideline, and / or standard.

[0045] For example, the operations controller 210 can use the controller data 240B (or a portion thereof) to determine what operations and / or associated parameters should be initiated, executed, implemented, stopped / aborted, prevented / prohibited, and / or performed by the gas filling station such as, for example and without limitation, how fast to dispense gas (e.g., how fast to fill a tank of a vehicle connected to the gas filling station), when to stop dispensing gas, how much gas to dispense, a dispensing flow and / or speed, a gas or gas delivery temperature, a target pressure of the gas, a target temperature of the gas, a top-off or end pressure, a top-off or end temperature, an APRR, an initial pressure of a tank, etc. To illustrate, the operations controller 210 can obtain, from the controller data 240B, a fueling table(s) (and / or associated fueling values), an ambient temperature, and an initial pressure of a tank of a vehicle refueling at (e.g., connected to) the gas filling station, and use such information (and any other information, such as sensor data 250B) to determine how fast to dispense gas to the vehicle, determine one or more operations for the gas filling station, and / or determine (e.g., interpolate) one or more parameters for the gas and / or gasdispensing operation, such as a target pressure, a target temperature, an APRR, etc. The operations controller 210 can then generate the controller output 255, which can include any of such information (and any other information described herein), and provide the controller output 255 to the failsafe controller 220 for checking / verification (e.g., via a plausibility check).

[0046] The failsafe controller 220 can receive the controller output 255 from the operations controller 210 and perform a plausibility check to verify that the controller output 255 (and / or an operation and / or parameter associated with the controller output 255) complies with a safety constraint (e.g., requirement, preference, etc.), such as a safety limit, threshold, range, protocol, etc. For example, the failsafe controller 220 can perform the plausibility check to determine whether any operation(s), instruction(s), parameter(s), and / or information in the controller output 255 is allowed and / or within an acceptable or required limit, threshold, range, standard, parameter, protocol, and / or value associated with a safety constraint. To illustrate, the plausibility check can determine whether any operation(s), information, and / or parameter(s) in the controller output 255 is / are within a safety limit / threshold / range defined in the controller data 240A programmed on the failsafe controller 220 (e.g., in the operations data 245) and / or allowed by any safety rules (e.g., regulatory limits / ranges, safety standards, etc.) defined in the controller data 240A. In an illustrative example, the plausibility check can determine whether a target pressure, a target temperature, an APRR, and / or fuel delivery rate identified or included in the controller output 255 is / are within a respective limit, threshold, and / or range associated with a safety constraint defined in the controller data 240A.

[0047] If the failsafe controller 220 determines that the controller output 255 (e.g., an associated operation(s), parameter(s), etc.) passes the plausibility check, the failsafe controller 220 can allow the operations controller 210 to initiate or execute an operation(s) identified / included in the controller output 255 and / or implement a parameter(s) in the controller output 255. If the failsafe controller 220 determines that the controller output 255 does not pass the plausibility check, the failsafe controller 220 can trigger the gas filling station to stop or prevent a fueling operation, parameter, and / or decision in the controller output 255. For example, the failsafe controller 220 can send a signal to the operations controller 210 configured to prevent the operations controller 210 (or instructing the operations controller 210 to prevent) from initiating or executing a fueling operation indicated in the controller output 255 if the fueling operation hasnot already been initiated / executed, or that instructs (and / or triggers) the operations controller 210 to abort the fueling operation if such operation has already been initiated. As another example, the failsafe controller 220 can send a signal to the operations controller 210 indicating that a parameter(s) and / or decision(s) from the controller output 255 is disapproved / rejected by the failsafe controller 220 (e.g., because it does not pass the plausibility check) and thus should not be implemented. As yet another example, the failsafe controller 220 can send a signal to one or more of the hardware elements 230 to stop or prevent one or more operations associated with the controller output 255. To illustrate, the failsafe controller 220 can send a signal to one or more valves from the hardware elements 230 configured to trigger the one or more valves to close and thus prevent gas from being dispensed by the gas filling station.

[0048] As described herein, the controller data 240A of the failsafe controller 220 can be subject to safety regulations that require such data to be reviewed and approved by a regulatory body (or an associated entity or agent) prior to being used (e.g., prior to being implemented by the failsafe controller 220). In such cases, any time the controller data 240A of the failsafe controller 220 is modified or updated, the regulations may require the controller data 240A to be reviewed and re-approved by the regulating body (or an associated entity or agent). Accordingly, in some aspects, the controller data 240A of the failsafe controller 220 can be protected from tampering and / or unauthorized modifications, or the control system 200 can avoid or prevent modifications to the controller data 240A.

[0049] For example, the controller data 240A of the failsafe controller 220 can be stored in a memory device or a memory space that is protected from tampering, has certain permissions (e.g., read only permissions, edit access limited to a specific user(s), etc.) limiting modifications by all or certain users (and / or modifications without prior authorization), is only accessible by the failsafe controller 220, and / or has a stored checksum or hash (e.g., calculated from the controller data 240A) that may be used to detect if / when the controller data 240A is modified. In some examples, to use the stored checksum or hash to check if the controller data 240A of the failsafe controller 220 has been modified, the stored checksum or hash can be compared with a new checksum or hash generated from a latest version of the controller data 240A. If there is a mismatch between the stored checksum / hash and the new checksum / hash, it means that the latest version of the controller data 240A associated with the new checksum / hash has been modified since the storedchecksum / hash was generated. In such cases, the controller data 240 A (e.g., the controller code in the controller data 240A) would have to be reviewed and re-approved by the regulatory body (or an associated entity or agent) before it can be implemented / used again by the failsafe controller 220.

[0050] Moreover, in some cases, the failsafe controller 220 can have certain limitations, which the operations controller 210 may not have. For example, the failsafe controller 220 may be limited in the operations that the failsafe controller 220 may be able or allowed to perform. To avoid modifications to the controller data 240A of the failsafe controller 220 after the controller data 240A has been reviewed and approved by the regulatory body (and thus prevent having to have the controller data 240A reviewed again and re-approved) and to allow the control system 200 to perform calculations that the failsafe controller 220 may be unable (or not allowed) to perform, the operations controller 210 can be used to perform such calculations, modify any portion of the controller data 240B of the operations controller 210 (e.g., which can include a copy or portion of the controller data 240A of the failsafe controller 220 as previously explained), generate associated outputs, etc., without having to modify the controller data 240A of the failsafe controller 220.

[0051] For example, the operations controller 210 can obtain the controller data 240B, which can include a portion or copy of the controller data 240A from the failsafe controller 220 such as a copy or portion of the sensor data 250A (e.g., temperature measurements, pressure measurements, etc.) and the operations data 245 (e.g., fueling tables, fueling values, operating values, parameters, etc.), and use the controller data 240B to calculate one or more parameters for a fueling operation(s) even if the failsafe controller 220 is unable to make such calculation (e.g., because of limitations of the failsafe controller 220) or modify the controller data 240B (e.g., including any portion or copy of the controller data 240A of the failsafe controller 220) to add the one or more parameters (or revise other parameters based on the one or more parameters) without requiring another review and approval of the controller data 240A triggered by the calculation or the data modification.

[0052] To illustrate, the operations controller 210 can use the controller data 240B to interpolate a target temperature, a target pressure, and an APRR (e.g., (e.g., which the operations controller 210 can include in the controller output 255) for a gas dispensing operation, even if the failsafe controller 220 is unable to interpolate such data (e.g., because of limitations of the failsafecontroller 220) and even if the failsafe controller 220 is unable to add to the controller data 240A or otherwise needs to obtain another review and approval of the controller data 240A by the regulatory body if such data is added to the controller data 240A of the failsafe controller 220, used to modify the controller data 240A, and / or implemented by the failsafe controller 220. Accordingly, by using the operations controller 210 to perform such calculation instead of the failsafe controller 220, the control system 200 can perform such calculation, modify the controller data 240B based on the resulting data, and use the resulting data without having to obtain a costly, inefficient, inconvenient, and time-consuming review and approval of the controller data 240A by the regulatory body (or an associated entity or agent).

[0053] While, in some cases, the operations controller 210 can perform calculations that the failsafe controller 220 may not be able to do (or may be prohibited from doing) and can make modifications to data associated with the gas filling station such as the controller data 240B programmed on the operations controller 210, the failsafe controller 220 can perform plausibility checks to verify the safety and compliance of any operations, calculations, and / or parameters from the operations controller 210, such as operations and / or data in the controller output 255, to ensure safety and compliance of the data. In some examples, before the controller output 255 (e.g., operations, parameters, decisions, instructions, values, data, commands, etc.) from the operations controller 210 is implemented by the control system 200 (e.g., via the operations controller 210 or the failsafe controller 220) and the gas filling station, the failsafe controller 220 can perform a plausibility check as previously explained.

[0054] For example, before implementing a target temperature, target pressure, and APRR calculated by the operations controller 210 in the previous example and included in the controller output 255, the failsafe controller 220 can perform a plausibility check to determine whether the target temperature, the target pressure, and the APRR are within any limits, thresholds, and / or ranges in a safety constrain defined by the controller data 240A of the failsafe controller 220. This way, the operations controller 210 can be used to perform calculations, operations, and data manipulations that the failsafe controller 220 is otherwise unable to perform or prohibited from performing (at least without requiring re-approval of the controller data 240A of the failsafe controller 220), and the failsafe controller 220 can be used to check such data from the operations controller 210 to ensure safety and compliance with associated regulations, protocols, guidelines,parameters, limits, thresholds, ranges, etc. Thus, by using the operations controller 210 (as opposed to using the failsafe controller 220) to perform such calculations and manipulate data included in the controller data 240B (instead of directly manipulating the controller data 240A programmed on the failsafe controller 220), the control system 200 can save a significant amount of time and costs that would otherwise be needed / used to obtain review and re-approval of the controller data 240A of the failsafe controller 220 if the controller data 240A of the failsafe controller 220 were modified (e.g., if the code of the failsafe controller 220 is modified). The control system 200 can also perform operations, such as interpolations and other operations, that other failsafe controllers and associated systems cannot perform.

[0055] FIG. 3A is a flow diagram illustrating an example process 300 for a plausibility check performed by the failsafe controller 220, according to some examples of the present disclosure. In this example, the plausibility check is used to check / confirm and approve an operation(s) determined by the operations controller 210 (e.g., an operation(s) from the controller output 255). However, in other examples, the process 300 can be used to perform a plausibility check of any other information determined by the operations controller 210 such as, for example, a param eter(s), a decision(s), a task(s), a value(s), configuration data, etc.

[0056] As shown, the failsafe controller 220 first sends to the operations controller 210 a copy or portion of the controller data 240A programmed on the failsafe controller 220. The operations controller 210 can store that copy or portion of the controller data 240 A in the controller data 240B of the operations controller 210. As previously explained, the controller data 240B of the operations controller 210 can include operations data 215 such as, for example, fueling tables (and associated values), fueling values, operation parameters, decisions, calculated / interpolated data, proposed operations, instructions, commands, proposed actions / steps, and / or any other information. The controller data 240B can also include sensor data (e.g., sensor data 250B), such as temperature measurements, pressure measurements, flow measurements, gas measurements, sensed conditions, etc.

[0057] The operations controller 210 can use the controller data 240B generated or modified based on the controller data 240A to determine (302) an operation(s) for a gas filling station (e.g., gas filling station 100, mobile gas filling station 125), such as a fueling / dispensing operation for example. The operations controller 210 can send to the failsafe controller 220 an output 304identifying the operation(s). In some cases, the output 304 can additionally include other information about the operation(s) such as, for example, a parameter(s) and / or value(s) for the operation(s), an instruction(s) associated with the operation(s), a description of the operation(s), a command(s) that can be used to trigger or initiate the operation(s), a condition(s) associated with the operation(s), a configuration(s) of the operation(s), and / or any other data associated with the operation(s).

[0058] The failsafe controller 220 can receive the output 304 and perform a plausibility check to check, verify / validate, and / or approve / reject the operation(s) associated with the output 304. In some examples, the failsafe controller 220 can perform the plausibility check for the operation(s) based on the output 304 and information in the controller data 240A of the failsafe controller 220, such as safety limits, thresholds, ranges, standards, protocols, parameters, settings, and / or requirements associated with the operation(s), as defined / specified in the controller data 240 A of the failsafe controller 220.

[0059] In this example, the plausibility check results in approval of the operation(s). Thus, in response to the plausibility check, the failsafe controller 220 approves the operation(s) and sends an approval signal 308 to the operations controller 210. The approval signal 308 can indicate that the operation(s) is approved, confirmed, and / or validated. The operations controller 210 can receive the approval signal 308 and execute the operation(s) based on the approval signal 308. In this example, executing the operation(s) can include initiating the operation(s) or, if the operation(s) was previously initiated, allowing the operation(s) to execute / complete (or continue execution) or approving continued execution of the operation(s).

[0060] FIG. 3B is a flow diagram illustrating another example process 320 for a plausibility check performed by the failsafe controller 220, according to some examples of the present disclosure. In this example, the plausibility check is used to check and reject an operation(s) determined by the operations controller 210 (e.g., an operation(s) from the controller output 255). However, in other examples, the process 300 can be used to perform a plausibility check of any other information determined by the operations controller 210 such as, for example, a param eter(s), a decision(s), a task(s), a value(s), configuration data, etc.

[0061] As shown, the failsafe controller 220 first sends to the operations controller 210 a copy or portion of the controller data 240A programmed on the failsafe controller 220. The operationscontroller 210 can use the copy or portion of the controller data 240 A to generate or modify the controller data 240B of the operations controller 210. The operations controller 210 can then use the controller data 240B to determine (322) an operation(s) for a gas filling station (e.g., gas filling station 100, mobile gas filling station 125), such as a fueling / dispensing operation for example. The operations controller 210 can send to the failsafe controller 220 an output 324 identifying the operation(s). In some cases, the output 324 can additionally include other information about the operation(s) such as, for example, a parameter(s) and / or value(s) for the operation(s), an instruction(s) associated with the operation(s), a description of the operation(s), a command(s) that can be used to trigger or initiate the operation(s), a condition(s) associated with the operation(s), a configuration(s) of the operation(s), and / or any other data associated with the operation(s).

[0062] The failsafe controller 220 can receive the output 324 and perform a plausibility check to check, verify / validate, and / or approve / reject the operation(s) associated with the output 324. In some examples, the failsafe controller 220 can perform the plausibility check for the operation(s) based on the output 324 and information in the controller data 240A of the failsafe controller 220, such as safety limits, thresholds, ranges, parameters, protocols, settings, values, standards, and / or requirements associated with the operation(s) as defined / specified by a safety constraint in the controller data 240A of the failsafe controller 220. In FIG. 3B, the plausibility check results in the operation(s) being rejected by the failsafe controller 220. Thus, in response to the plausibility check, the failsafe controller 220 sends a rejection signal 328 to the operations controller 210. The rejection signal 328 can indicate that the operation(s) is rejected by the failsafe controller 220 (e.g., because it failed to pass the plausibility check). The operations controller 210 can receive the rejection signal 328 and reject the operation(s) based on the rejection signal 328. In some examples, rejecting the operation(s) can include deciding not to initiate / execute the operation(s) or, if the operation(s) was previously initiated, aborting / stopping the operation(s). In some examples, rejecting the operation(s) can additionally or alternatively include closing one or more valves to stop or prevent a gas fueling operation.

[0063] FIG. 4 is a flowchart illustrating an example method 400 for managing and controlling operations of a gas filling station, according to some examples of the present disclosure. At block 402, the method 400 can include receiving, by an operations controller (e.g., operations controller 210) associated with a gas filling station (e.g., gas filling station 100, mobile gas filling station125), a portion of pre-approved data programmed on a failsafe controller (e.g., failsafe controller 220) associated with the gas filling station. In some cases, the operations controller and the failsafe controller can be part of or implemented by a same controller device, such as a PLC. In other cases, the operations controller and the failsafe controller can be part of or implemented by different / separate controller devices, such as different PLCs. Moreover, the failsafe controller and / or the pre-approved data programmed on the failsafe controller can have a restriction that requires at least a portion of the pre-approved data programmed on the failsafe controller to be reapproved by a regulatory entity (or an entity or agent thereof) any time that the pre-approved data (or a portion of the pre-approved data) programmed on the failsafe controller is modified. For example, in some cases, the pre-approved data can include data used by the failsafe controller, such as code, that has a restriction requiring such data to be re-approved by a regulatory entity (or an entity or agent thereof) any time that such data is modified. However, the pre-approved data can also include other data which may or may not have such restriction requiring re-approval if modified.

[0064] The pre-approved data from the failsafe controller can include or be the same as the controller data 240A shown in FIG. 2 and previously described with respect to FIG. 2. In some examples, the pre-approved data can include sensor data (e.g., sensor data 250A) and operations data (e.g., operations data 245), such as a fueling table (and associated values), one or more values associated with an operation, condition, and / or system of the gas filling station, such as values representing and / or provided in the safety constraint. In some cases, such values can include a range of acceptable values (e.g., a range of safety values), one or more threshold values, and / or one or more limits associated with the proposed operation and / or the one or more parameters described below.

[0065] The portion of the pre-approved data can include or be the same as the controller data 240B (or a portion thereof) shown in FIG. 2 and previously described with respect to FIG. 2. For example, in some cases, the portion of the pre-approved data can include sensor data (e.g., sensor data 250B) and operations data (e.g., operations data 215), such as a fueling table (and associated values), one or more fueling values, one or more operations parameters, one or more settings, one or more system parameters, and / or any other data as described herein. In some cases, the portion of the pre-approved data can include any data from the failsafe controller and can optionallyinclude any other data. Moreover, the portion of the pre-approved data may or may not include a copy of any data of the failsafe controller that has a restriction requiring that such data be reapproved by a regulatory entity (or an entity or agent thereof) any time that such data at the failsafe controller is modified. However, in such cases, while the data on the failsafe controller may require re-approval if modified, any copy of such data included (if included) in the portion of the preapproved data at the operations controller may not need to be re-approved by the regulatory entity (or an entity or agent thereof) if such copy of the data is modified, as the data of the operations controller may not have the same restriction as the data of the failsafe controller.

[0066] In some examples, the sensor data in the pre-approved data and / or the portion of the pre-approved data can include one or more temperature measurements, pressure measurements, flow measurements, gas measurements, density measurements, image data, and / or any other sensor data. For example, the sensor data can include an ambient temperature, a temperature of a tank of a vehicle connected to the gas filling station, a temperature of a tank of the gas filling station, a pressure in the tank of the gas filling station, a pressure of the gas in the tank of the gas filling station, a pressure of the tank of the vehicle (and / or contents thereof), a precooling temperature of a gas in a tank, a gas delivery temperature, and / or any other sensor data.

[0067] In some implementations, the gas filling station can include a transportation module. The transportation module can include, for example and without limitation, a storage configured to store gas of the gas filling station, a dispenser configured to dispense the gas to one or more targets (e.g., vehicles, etc.) connected to the dispenser, one or more compressors, one or more buffer tanks, and / or a set of valves and pipes configured to couple the one or more compressors with the one or more buffer tanks.

[0068] At block 404, the method 400 can include sending, to the failsafe controller, an output (e.g., controller output 255) generated by the operations controller based on the portion of the preapproved data from the failsafe controller. The output can identify a proposed operation for the gas filling station and / or one or more parameters associated with the proposed operation. For example, the output can identify a proposed gas dispensing operation and / or one or moreparameters for the dispensing gas. In some cases, the output can include other information, such as other parameters, other operations, one or more instructions, one or more values, one or more tables, and / or any other information.

[0069] In some cases, the portion of the pre-approved data can include a fueling table, one or more values from a set of values associated with the safety constraint, an ambient temperature, a precooling temperature of a gas in a first tank of the gas filling station, a gas delivery temperature, and / or a pressure of a second tank of a vehicle connected to the gas filling station. Here, the proposed operation can include, for example, a gas dispensing operation, and the one or more parameters associated with the proposed operation can include an ambient temperature, an APRR, a temperature limit, a pressure limit, a target temperature, and / or a target pressure.

[0070] At block 406, the method 400 can include receiving, by the operations controller and from the failsafe controller, a signal indicating whether the proposed operation and / or the one or more parameters complies with a safety constraint specified in the pre-approved data. In some cases, the safety constraint can include, for example and without limitation, a safety requirement, a safety limit, a safety threshold, a safety range, a safety protocol, a safety value, a safety setting, a safety instruction, and / or a safety parameter.

[0071] At block 408, the method 400 can include approving or rejecting the proposed operation and / or the one or more parameters based on the signal from the failsafe controller. In some examples, approving or rejecting the proposed operation and / or the one or more parameters can include approving the proposed operation and / or the one or more parameters, and approving the proposed operation and / or the one or more parameters can include generating, based on the proposed operation and / or the one or more parameters approved (e.g., approved by the failsafe controller), an instruction configured to adjust a respective operation of one or more hardware elements (e.g., hardware elements 230) of the gas filling station. In some cases, the one or more hardware elements can include a valve, an actuator, a sealing component, a pump, a gate, a door, a cooling component, a dispenser, a compressor, a gas nozzle, a sensor, a switch, and / or an electrical component.

[0072] In some aspects, the method 400 can include based on a plausibility check performed by the failsafe controller to check the output generated by the operations controller, determining that the proposed operation and / or the one or more parameters is / are within an acceptable range of values defined by the safety constraint in the pre-approved data; in response to determining that the proposed operation and / or the one or more parameters is / are within the acceptable range of values, determining, by the failsafe controller, that the proposed operation and / or the one or moreparameters complies with the safety constraint; and sending, by the failsafe controller, the signal to the operations controller in response to determining that the proposed operation and / or the one or more parameters complies with the safety constraint. In this example, the signal can indicate that the proposed operation and / or the one or more parameters complies with the safety constraint.

[0073] In some cases, the method 400 can include approving the proposed operation and / or the one or more parameters, and approving the proposed operation and / or the one or more parameters can include initiating or executing the proposed operation, allowing the proposed operation to execute or continue executing, implementing the one or more parameters, and / or generating an instruction configured to cause the gas filling station to implement (e.g., via the operations controller 210 or the failsafe controller 220) the proposed operation and / or the one or more parameters.

[0074] In some aspects, the method 400 can include determining, based on a plausibility check performed by the failsafe controller to check the output generated by the operations controller, that the proposed operation and / or the one or more parameters is / are outside of an acceptable range of values defined by the safety constraint in the pre-approved data; in response to the determining that the proposed operation and / or the one or more parameters is / are outside of the acceptable range of values, determining, by the failsafe controller, that the proposed operation and / or the one or more parameters does not comply with the safety constraint; and sending, by the failsafe controller, the signal to the operations controller. Here, the signal can indicate that the proposed operation and / or the one or more parameters does not comply with the safety constraint.

[0075] In some examples, the method 400 can include, based on the signal, rejecting the proposed operation and / or the one or more parameters, and rejecting the proposed operation and / or the one or more parameters can include preventing or rejecting execution of the proposed operation, aborting or stopping the proposed operation (e.g., if such operation was previously initiated and is currently executing), rejecting the one or more parameters, and / or preventing implementation of the proposed operation and / or the one or more parameters. For example, the operations controller can receive the signal indicating that the proposed operation and / or the one or more parameters does not comply with the safety constraint and, based on the signal, the operations controller can reject the proposed operation and / or the one or more parameters by preventing or rejecting execution of the proposed operation, aborting or stopping the proposedoperation if the operation is running, disapproving or blocking the one or more parameters, and / or otherwise preventing the proposed operation and / or the one or more parameters from being implemented / used by the gas filling station.

[0076] In some cases, in addition to or in lieu of sending the signal to the operations controller, the failsafe controller can prevent the operation and / or the one or more parameters from being implemented by the gas filling station (e.g., via the operations controller 210 or the failsafe controller 220). For example, if the proposed operation was previously initiated (and is executing) and the failsafe controller determines that the proposed operation and / or the one or more parameters associated with the proposed operation does / do not comply with the safety constraint, the failsafe controller can stop / abort the operation or prevent (e.g., stop, disapprove, unauthorize, block, etc.) the one or more parameters from being implemented for the operation. The failsafe controller can stop / abort the operation or prevent the one or more parameters from being implemented in addition to or in lieu of, sending to the operations controller the signal indicating that the operation and / or the one or more parameters does / do not comply with the safety constraint.

[0077] FIG. 5 illustrates an example processor-based system 500 that can be used to implement some or all aspects of the subject technology. For example, processor-based system 500 can be used to implement the operations controller 210, the failsafe controller 220, and / or any component thereof.

[0078] The processor-based system 500 can include a connection 505 used by components of the system to communicate with each other. The connection 505 can be or include a physical connection via a bus, or a direct connection into processor 510, such as in a chipset architecture. Connection 505 can also be a virtual connection, networked connection, or logical connection.

[0079] The example system 500 includes at least one processing unit (CPU or processor) 510 and connection 505 that couples various system components including system memory 515, such as read-only memory (ROM) 520 and random-access memory (RAM) 525 to processor 510. Computing system 500 can include a cache of high-speed memory 512 connected directly with, in close proximity to, and / or integrated as part of processor 510.

[0080] Processor 510 can include any general-purpose processor and a hardware service or software service, such as services 532, 534, and 536 stored in storage device 530, configured tocontrol processor 510 as well as a special-purpose processor where software instructions are incorporated into the actual processor design. Processor 510 may essentially be a completely self- contained computing system, containing multiple cores or processors, a bus, memory controller, cache, etc. A multi-core processor may be symmetric or asymmetric.

[0081] To enable user interaction, computing system 500 can include an input device 545, which can represent any number of input mechanisms, such as a microphone for speech, a touch- sensitive screen for gesture or graphical input, keyboard, mouse, motion input, etc. Computing system 500 can also include output device 535, which can be one or more of a number of output mechanisms known to those of skill in the art. In some instances, multimodal systems can enable a user to provide multiple types of input / output to communicate with computing system 500. Computing system 500 can include communications interface 540, which can generally govern and manage the user input and system output.

[0082] The communication interface may perform or facilitate receipt and / or transmission wired or wireless communications via wired and / or wireless transceivers, including those making use of an audio jack / plug, a microphone jack / plug, a universal serial bus (USB) port / plug, an Apple® Lightning® port / plug, an Ethernet port / plug, a fiber optic port / plug, a proprietary wired port / plug, a BLUETOOTH® wireless signal transfer, a BLUETOOTH® low energy (BLE) wireless signal transfer, an IBEACON® wireless signal transfer, a radio-frequency identification (RFID) wireless signal transfer, near-field communications (NFC) wireless signal transfer, dedicated short range communication (DSRC) wireless signal transfer, 502.11 Wi-Fi wireless signal transfer, wireless local area network (WLAN) signal transfer, Visible Light Communication (VLC), Worldwide Interoperability for Microwave Access (WiMAX), Infrared (IR) communication wireless signal transfer, Public Switched Telephone Network (PSTN) signal transfer, Integrated Services Digital Network (ISDN) signal transfer, 3G / 4G / 5G or higher and / or LTE cellular data network wireless signal transfer, ad-hoc network signal transfer, radio wave signal transfer, microwave signal transfer, infrared signal transfer, visible light signal transfer, ultraviolet light signal transfer, wireless signal transfer along the electromagnetic spectrum, or some combination thereof.

[0083] Communications interface 540 may also include one or more Global Navigation Satellite System (GNSS) receivers or transceivers that are used to determine a location of thecomputing system 500 based on receipt of one or more signals from one or more satellites associated with one or more GNSS systems. GNSS systems include, but are not limited to, the USbased Global Positioning System (GPS), the Russia-based Global Navigation Satellite System (GLONASS), the China-based BeiDou Navigation Satellite System (BDS), and the Europe-based Galileo GNSS. There is no restriction on operating on any particular hardware arrangement, and therefore the basic features here may easily be substituted for improved hardware or firmware arrangements as they are developed.

[0084] Storage device 530 can be a non-volatile and / or non-transitory computer-readable memory device and can be a hard disk or other types of computer readable media which can store data that are accessible by a computer, such as magnetic cassettes, flash memory cards, solid state memory devices, digital versatile disks, cartridges, a floppy disk, a flexible disk, a hard disk, magnetic tape, a magnetic strip / stripe, any other magnetic storage medium, flash memory, memristor memory, any other solid-state memory, a compact disc read only memory (CD-ROM) optical disc, a rewritable compact disc (CD) optical disc, digital video disk (DVD) optical disc, a blu-ray disc (BD) optical disc, a holographic optical disk, another optical medium, a secure digital (SD) card, a micro secure digital (microSD) card, a Memory Stick® card, a smartcard chip, a EMV chip, a subscriber identity module (SIM) card, a mini / micro / nano / pico SIM card, another integrated circuit (IC) chip / card, random access memory (RAM), static RAM (SRAM), dynamic RAM (DRAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash EPROM (FLASHEPROM), cache memory (L1 / L2 / L3 / L4 / L9 / L#), resistive random-access memory (RRAM / ReRAM), phase change memory (PCM), spin transfer torque RAM (STT-RAM), another memory chip or cartridge, and / or a combination thereof.

[0085] Storage device 530 can include software services, servers, services, etc., that when the code that defines such software is executed by the processor 510, causes the system to perform a function. In some examples, a hardware service that performs a particular function can include the software component stored in a computer-readable medium in connection with the necessary hardware components, such as processor 510, connection 505, output device 535, etc., to carry out the function.

[0086] As understood by those of skill in the art, machine-learning techniques can vary depending on the desired implementation. For example, machine-learning schemes can utilize one or more of the following, alone or in combination: hidden Markov models; recurrent neural networks; convolutional neural networks (CNNs); deep learning; Bayesian symbolic methods; general adversarial networks (GANs); support vector machines; image registration methods; applicable rule-based system. Where regression algorithms are used, they may include including but are not limited to: a Stochastic Gradient Descent Regressor, and / or a Passive Aggressive Regressor, etc.

[0087] Machine learning classification models can also be based on clustering algorithms (e.g., a Mini-batch K-means clustering algorithm), a recommendation algorithm (e.g., a Miniwise Hashing algorithm, or Euclidean Locality-Sensitive Hashing (LSH) algorithm), and / or an anomaly detection algorithm, such as a Local outlier factor. Additionally, machine-learning models can employ a dimensionality reduction approach, such as, one or more of: a Mini-batch Dictionary Learning algorithm, an Incremental Principal Component Analysis (PCA) algorithm, a Latent Dirichlet Allocation algorithm, and / or a Mini-batch K-means algorithm, etc.

[0088] Aspects within the scope of the present disclosure may also include tangible and / or non-transitory computer-readable storage media or devices for carrying or having computerexecutable instructions or data structures stored thereon. Such tangible computer-readable storage devices can be any available device that can be accessed by a general purpose or special purpose computer, including the functional design of any special purpose processor as described above. By way of example, and not limitation, such tangible computer-readable devices can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other device which can be used to carry or store desired program code in the form of computer-executable instructions, data structures, or processor chip design. When information or instructions are provided via a network or another communications connection (either hardwired, wireless, or combination thereof) to a computer, the computer properly views the connection as a computer-readable medium. Thus, any such connection is properly termed a computer-readable medium. Combinations of the above should also be included within the scope of the computer-readable storage devices.

[0089] Computer-executable instructions include, for example, instructions and data which cause a general-purpose computer, special-purpose computer, or special-purpose processing device to perform a certain function or group of functions. By way of example, computerexecutable instructions can be used to implement perception system functionality for determining when sensor cleaning operations are needed or should begin. Computer-executable instructions can also include program modules that are executed by computers in stand-alone or network environments. Generally, program modules include routines, programs, components, data structures, objects, and the functions inherent in the design of special-purpose processors, etc. that perform tasks or implement abstract data types. Computer-executable instructions, associated data structures, and program modules represent examples of the program code means for executing steps of the methods disclosed herein. The particular sequence of such executable instructions or associated data structures represents examples of corresponding acts for implementing the functions described in such steps.

[0090] Other examples of the disclosure may be practiced in network computing environments with many types of computer system configurations, including personal computers, hand-held devices, multi-processor systems, microprocessor-based or programmable consumer electronics, network PCs, minicomputers, mainframe computers, and the like. Aspects of the disclosure may also be practiced in distributed computing environments where tasks are performed by local and remote processing devices that are linked (either by hardwired links, wireless links, or by a combination thereof) through a communications network. In a distributed computing environment, program modules can be located in both local and remote memory storage devices.

[0091] The various examples described above are provided by way of illustration only and should not be construed to limit the scope of the disclosure. For example, the principles herein apply equally to optimization as well as general improvements. Various modifications and changes may be made to the principles described herein without following the example aspects and applications illustrated and described herein, and without departing from the spirit and scope of the disclosure.

[0092] Claim language or other language in the disclosure reciting “at least one of’ a set and / or “one or more” of a set indicates that one member of the set or multiple members of the set (in any combination) satisfy the claim. For example, claim language reciting “at least one of A and B” or“at least one of A or B” means A, B, or A and B. In another example, claim language reciting “at least one of A, B, and C” or “at least one of A, B, or C” means A, B, C, or A and B, or A and C, or B and C, or A and B and C. The language “at least one of’ a set and / or “one or more” of a set does not limit the set to the items listed in the set. For example, claim language reciting “at least one of A and B” or “at least one of A or B” can mean A, B, or A and B, and can additionally include items not listed in the set of A and B.

[0093] Illustrative examples of the disclosure include:

[0094] Aspect 1. A method comprising: receiving, by an operations controller associated with a gas filling station, a portion of pre-approved data programmed on a failsafe controller associated with the gas filling station, the failsafe controller having a restriction that requires the pre-approved data to be re-approved by a regulatory entity any time that the pre-approved data programmed on the failsafe controller is modified; sending, to the failsafe controller, an output generated by the operations controller based on the portion of the pre-approved data from the failsafe controller, the output identifying at least one of a proposed operation for the gas filling station and one or more parameters associated with the proposed operation; receiving, by the operations controller from the failsafe controller, a signal indicating whether the at least one of the proposed operation and the one or more parameters complies with a safety constraint included or defined in the preapproved data; and in response to the signal, approving or rejecting the at least one of the proposed operation and the one or more parameters.

[0095] Aspect 2. The method of Aspect 1, wherein the pre-approved data comprises at least one of sensor data, a fueling table, and a set of values associated with the safety constraint, and wherein the set of values comprises at least one of a range of acceptable values, one or more threshold values, and one or more limits associated with at least one of the proposed operation and the one or more parameters.

[0096] Aspect 3. The method of Aspect 2, wherein the portion of the pre-approved data comprises at least one of the fueling table, one or more values from the set of values, an ambient temperature, a precooling temperature of a gas in a first tank of the gas filling station, a gas delivery temperature, and a pressure of a second tank of a vehicle associated with the gas filling station, wherein the proposed operation comprises a gas dispensing operation, and wherein the one or moreparameters associated with the proposed operation comprises at least one an average pressure ramp rate (APRR), a temperature limit, a pressure limit, a target temperature, and a target pressure.

[0097] Aspect 4. The method of any of Aspects 1 to 3, further comprising: based on a plausibility check performed by the failsafe controller to check the output generated by the operations controller, determining that at least one of the proposed operation and the one or more parameters is within an acceptable range of values defined by the safety constraint in the preapproved data; in response to the determining that the at least one of the proposed operation and the one or more parameters is within the acceptable range of values, determining, by the failsafe controller, that the at least one of the proposed operation and the one or more parameters complies with the safety constraint; and sending, by the failsafe controller, the signal to the operations controller, the signal indicating that the at least one of the proposed operation and the one or more parameters complies with the safety constraint.

[0098] Aspect 5. The method of Aspect 4, further comprising approving the at least one of the proposed operation and the one or more parameters, and wherein approving the at least one of the proposed operation and the one or more parameters comprises at least one of initiating or executing the proposed operation, allowing the proposed operation to execute or continue executing, implementing the one or more parameters, and generating an instruction configured to cause the gas filling station to implement at least one of the proposed operation and the one or more parameters.

[0099] Aspect 6. The method of any of Aspects 1 to 5, further comprising: based on a plausibility check performed by the failsafe controller to check the output generated by the operations controller, determining that at least one of the proposed operation and the one or more parameters is outside of an acceptable range of values defined by the safety constraint in the preapproved data; in response to the determining that the at least one of the proposed operation and the one or more parameters is outside of the acceptable range of values, determining, by the failsafe controller, that the at least one of the proposed operation and the one or more parameters does not comply with the safety constraint; and sending, by the failsafe controller, the signal to the operations controller, the signal indicating that the at least one of the proposed operation and the one or more parameters does not comply with the safety constraint.

[0100] Aspect 7. The method of Aspect 6, further comprising rejecting the at least one of the proposed operation and the one or more parameters, and wherein rejecting the at least one of the proposed operation and the one or more parameters comprises at least one of preventing or rejecting execution of the proposed operation, aborting or stopping the proposed operation, rejecting the one or more parameters, and preventing implementation of the at least one of the proposed operation and the one or more parameters.

[0101] Aspect 8. The method of any of Aspects 1 to 7, wherein approving or rejecting the at least one of the proposed operation and the one or more parameters comprises approving the at least one of the proposed operation and the one or more parameters, wherein approving the at least one of the proposed operation and the one or more parameters comprises, based on the at least one of the proposed operation and the one or more parameters being approved, generating an instruction configured to adjust a respective operation of one or more elements of the gas filling station, and wherein the one or more operation elements comprise at least one of a valve, an actuator, a sealing component, a cooling component, a dispenser, a compressor, a gas nozzle, a sensor, a switch, and an electrical component.

[0102] Aspect 9. The method of any of Aspects 1 to 8, wherein the operations controller and the failsafe controller are part of a same programmable logic controller (PLC) or different PLCs.

[0103] Aspect 10. The method of any of Aspects 1 to 9, wherein at least one of the operations controller and the failsafe controller associated with the gas filling station is configured to prevent malicious manipulation of the pre-approved data programmed on the failsafe controller, detect errors during runtime, correct errors encountered during runtime, provide compliance with safety parameters, obtain and maintain regulatory approval, and detect a hardware failure of at least one of the operations controller and the failsafe controller.

[0104] Aspect 11. A system comprising: an operations controller associated with a gas filling station, the operations controller comprising memory and one or more processors coupled to the memory, wherein the one or more processors are configured to: receive, from a failsafe controller associated with the gas filling station, a portion of pre-approved data programmed on the failsafe controller, the failsafe controller having a restriction that requires the pre-approved data to be reapproved by a regulatory entity any time that the pre-approved data programmed on the failsafe controller is modified; send, to the failsafe controller, an output generated based on the portion ofthe pre-approved data, the output identifying at least one of a proposed operation for the gas filling station and one or more parameters associated with the proposed operation; receive, from the failsafe controller, a signal indicating whether the at least one of the proposed operation and the one or more parameters complies with a safety constraint included or defined in the pre-approved data; and in response to the signal, approve or reject the at least one of the proposed operation and the one or more parameters.

[0105] Aspect 12. The system of Aspect 11, wherein the pre-approved data comprises at least one of sensor data, a fueling table, and a set of values associated with the safety constraint, and wherein the set of values comprises at least one of a range of acceptable values, one or more threshold values, and one or more limits associated with at least one of the proposed operation and the one or more parameters.

[0106] Aspect 13. The system of Aspect 12, wherein the portion of the pre-approved data comprises at least one of the fueling table, one or more values from the set of values, an ambient temperature, a temperature of a gas in a first tank of the gas filling station, and a pressure of a second tank of a vehicle associated with the gas filling station, wherein the proposed operation comprises a gas dispensing operation, and wherein the one or more parameters associated with the proposed operation comprises at least one an average pressure ramp rate (APRR), a target temperature, and a target pressure.

[0107] Aspect 14. The system of any of Aspects 11 to 13, further comprising the failsafe controller, wherein the failsafe controller comprises memory and at least one processor coupled to the memory, wherein the at least one processor is configured to: based on a plausibility check used to check the output generated by the operations controller, determine that at least one of the proposed operation and the one or more parameters is within an acceptable range of values defined by the safety constraint in the pre-approved data; in response to the determining that the at least one of the proposed operation and the one or more parameters is within the acceptable range of values, determine that the at least one of the proposed operation and the one or more parameters complies with the safety constraint; and send the signal to the operations controller, the signal indicating that the at least one of the proposed operation and the one or more parameters complies with the safety constraint.

[0108] Aspect 15. The system of Aspect 14, wherein the one or more processors of the operations controller are further configured to approve the at least one of the proposed operation and the one or more parameters based on the signal, and wherein approving the at least one of the proposed operation and the one or more parameters comprises at least one of initiating or executing the proposed operation, allowing the proposed operation to execute or continue executing, implementing the one or more parameters, and generating an instruction configured to cause the gas filling station to implement at least one of the proposed operation and the one or more parameters.

[0109] Aspect 16. The system of any of Aspects 11 to 15, further comprising the failsafe controller, wherein the failsafe controller comprises memory and at least one processor coupled to the memory, wherein the at least one processor is configured to: based on a plausibility check performed to check the output generated by the operations controller, determine that at least one of the proposed operation and the one or more parameters is outside of an acceptable range of values defined by the safety constraint in the pre-approved data; in response to the determining that the at least one of the proposed operation and the one or more parameters is outside of the acceptable range of values, determine that the at least one of the proposed operation and the one or more parameters does not comply with the safety constraint; and send the signal to the operations controller, the signal indicating that the at least one of the proposed operation and the one or more parameters does not comply with the safety constraint.

[0110] Aspect 17. The system of Aspect 16, wherein the one or more processors of the operations controller are further configured to reject the at least one of the proposed operation and the one or more parameters based on the signal, and wherein rejecting the at least one of the proposed operation and the one or more parameters comprises at least one of preventing or rejecting execution of the proposed operation, aborting or stopping the proposed operation, rejecting the one or more parameters, and preventing implementation of the at least one of the proposed operation and the one or more parameters.

[0111] Aspect 18. The system of any of Aspects 11 to 17, wherein approving or rejecting the at least one of the proposed operation and the one or more parameters comprises approving the at least one of the proposed operation and the one or more parameters, and wherein approving the at least one of the proposed operation and the one or more parameters comprises, based on the atleast one of the proposed operation and the one or more parameters being approved, generating an instruction configured to adjust a respective operation of one or more elements of the gas filling station.

[0112] Aspect 19. The system of Aspect 18, wherein the one or more operation elements comprise at least one of a valve, an actuator, a sealing component, a cooling component, a dispenser, a compressor, a gas nozzle, a switch, an electrical component, and a sensor, and wherein the sensor comprises at least one of a temperature sensor, a pressure sensor, a flow sensor, a gas sensor, a motion sensor, and an inertial measurement unit.

[0113] Aspect 20. The system of any of Aspects 11 to 19, wherein the operations controller and the failsafe controller are part of a same programmable logic controller (PLC) or different PLCs, and wherein the system further comprises the failsafe controller and a transportation module of the gas filling station, the transportation module comprising at least one of: a storage configured to store gas for the gas filling station; a dispenser configured to dispense the gas to one or more targets connected to the dispenser; one or more compressors; one or more buffer tanks; and a plurality of valves and pipes configured to couple the one or more compressors with the one or more buffer tanks.

[0114] Aspect 21. The system of any of Aspects 1 to 20, further comprising the failsafe controller, wherein at least one of the operations controller and the failsafe controller associated with the gas filling station is configured to prevent malicious manipulation of the pre-approved data programmed on the failsafe controller, detect errors during runtime, correct errors encountered during runtime, provide compliance with safety parameters, obtain and maintain regulatory approval, and detect a hardware failure of at least one of the operations controller and the failsafe controller.

[0115] Aspect 22. A non-transitory computer-readable medium having stored thereon instructions which, when executed by an operations controller of a gas filling station, cause the operations controller to perform a method according to any of Aspects 1 to 10.

[0116] Aspect 23. A system comprising means for performing a method according to any of Aspects 1 to 10.

Claims

CLAIMSWHAT IS CLAIMED IS:

1. A method comprising: receiving, by an operations controller associated with a gas filling station, a portion of pre-approved data programmed on a failsafe controller associated with the gas filling station, the failsafe controller having a restriction that requires the pre-approved data to be re-approved by a regulatory entity any time that the pre-approved data programmed on the failsafe controller is modified; sending, to the failsafe controller, an output generated by the operations controller based on the portion of the pre-approved data from the failsafe controller, the output identifying at least one of a proposed operation for the gas filling station and one or more parameters associated with the proposed operation; receiving, by the operations controller from the failsafe controller, a signal indicating whether the at least one of the proposed operation and the one or more parameters complies with a safety constraint included or defined in the pre-approved data; and in response to the signal, approving or rejecting the at least one of the proposed operation and the one or more parameters.

2. The method of claim 1, wherein the pre-approved data comprises at least one of sensor data, a fueling table, and a set of values associated with the safety constraint, and wherein the set of values comprises at least one of a range of acceptable values, one or more threshold values, and one or more limits associated with at least one of the proposed operation and the one or more parameters.

3. The method of claim 2, wherein the portion of the pre-approved data comprises at least one of the fueling table, one or more values from the set of values, an ambient temperature, a precooling temperature of a gas in a first tank of the gas filling station, a gas delivery temperature, and a pressure of a second tank of a vehicle associated with the gas filling station, wherein the proposed operation comprises a gas dispensing operation, and wherein the one or more parameters associated with the proposed operation comprises at least one an averagepressure ramp rate (APRR), a temperature limit, a pressure limit, a target temperature, and a target pressure.

4. The method of claim 1, further comprising: based on a plausibility check performed by the failsafe controller to check the output generated by the operations controller, determining that at least one of the proposed operation and the one or more parameters is within an acceptable range of values defined by the safety constraint in the pre-approved data; in response to the determining that the at least one of the proposed operation and the one or more parameters is within the acceptable range of values, determining, by the failsafe controller, that the at least one of the proposed operation and the one or more parameters complies with the safety constraint; and sending, by the failsafe controller, the signal to the operations controller, the signal indicating that the at least one of the proposed operation and the one or more parameters complies with the safety constraint.

5. The method of claim 4, further comprising approving the at least one of the proposed operation and the one or more parameters, and wherein approving the at least one of the proposed operation and the one or more parameters comprises at least one of initiating or executing the proposed operation, allowing the proposed operation to execute or continue executing, implementing the one or more parameters, and generating an instruction configured to cause the gas filling station to implement at least one of the proposed operation and the one or more parameters.

6. The method of claim 1, further comprising: based on a plausibility check performed by the failsafe controller to check the output generated by the operations controller, determining that at least one of the proposed operation and the one or more parameters is outside of an acceptable range of values defined by the safety constraint in the pre-approved data; in response to the determining that the at least one of the proposed operation and the one or more parameters is outside of the acceptable range of values, determining, by the failsafecontroller, that the at least one of the proposed operation and the one or more parameters does not comply with the safety constraint; and sending, by the failsafe controller, the signal to the operations controller, the signal indicating that the at least one of the proposed operation and the one or more parameters does not comply with the safety constraint.

7. The method of claim 6, further comprising rejecting the at least one of the proposed operation and the one or more parameters, and wherein rejecting the at least one of the proposed operation and the one or more parameters comprises at least one of preventing or rejecting execution of the proposed operation, aborting or stopping the proposed operation, rejecting the one or more parameters, and preventing implementation of the at least one of the proposed operation and the one or more parameters.

8. The method of claim 1, wherein approving or rejecting the at least one of the proposed operation and the one or more parameters comprises approving the at least one of the proposed operation and the one or more parameters, wherein approving the at least one of the proposed operation and the one or more parameters comprises, based on the at least one of the proposed operation and the one or more parameters being approved, generating an instruction configured to adjust a respective operation of one or more elements of the gas filling station, and wherein the one or more operation elements comprise at least one of a valve, an actuator, a sealing component, a cooling component, a dispenser, a compressor, a gas nozzle, a sensor, a switch, and an electrical component.

9. The method of claim 1, wherein the operations controller and the failsafe controller are part of a same programmable logic controller (PLC) or different PLCs.

10. The method of claim 1, wherein at least one of the operations controller and the failsafe controller associated with the gas filling station is configured to prevent malicious manipulation of the pre-approved data programmed on the failsafe controller, detect errors during runtime, correct errors encountered during runtime, provide compliance with safety parameters, obtainand maintain regulatory approval, and detect a hardware failure of at least one of the operations controller and the failsafe controller.

11. A system comprising: an operations controller associated with a gas filling station, the operations controller comprising memory and one or more processors coupled to the memory, wherein the one or more processors are configured to: receive, from a failsafe controller associated with the gas filling station, a portion of pre-approved data programmed on the failsafe controller, the failsafe controller having a restriction that requires the pre-approved data to be re-approved by a regulatory entity any time that the pre-approved data programmed on the failsafe controller is modified; send, to the failsafe controller, an output generated based on the portion of the pre-approved data, the output identifying at least one of a proposed operation for the gas filling station and one or more parameters associated with the proposed operation; receive, from the failsafe controller, a signal indicating whether the at least one of the proposed operation and the one or more parameters complies with a safety constraint included or defined in the pre-approved data; and in response to the signal, approve or reject the at least one of the proposed operation and the one or more parameters.

12. The system of claim 11, wherein the pre-approved data comprises at least one of sensor data, a fueling table, and a set of values associated with the safety constraint, and wherein the set of values comprises at least one of a range of acceptable values, one or more threshold values, and one or more limits associated with at least one of the proposed operation and the one or more parameters.

13. The system of claim 12, wherein the portion of the pre-approved data comprises at least one of the fueling table, one or more values from the set of values, an ambient temperature, a temperature of a gas in a first tank of the gas filling station, and a pressure of a second tank of a vehicle associated with the gas filling station, wherein the proposed operation comprises a gas dispensing operation, and wherein the one or more parameters associated with the proposedoperation comprises at least one an average pressure ramp rate (APRR), a target temperature, and a target pressure.

14. The system of claim 11, further comprising the failsafe controller, wherein the failsafe controller comprises memory and at least one processor coupled to the memory, wherein the at least one processor is configured to: based on a plausibility check used to check the output generated by the operations controller, determine that at least one of the proposed operation and the one or more parameters is within an acceptable range of values defined by the safety constraint in the pre-approved data; in response to the determining that the at least one of the proposed operation and the one or more parameters is within the acceptable range of values, determine that the at least one of the proposed operation and the one or more parameters complies with the safety constraint; and send the signal to the operations controller, the signal indicating that the at least one of the proposed operation and the one or more parameters complies with the safety constraint.

15. The system of claim 14, wherein the one or more processors of the operations controller are further configured to approve the at least one of the proposed operation and the one or more parameters based on the signal, and wherein approving the at least one of the proposed operation and the one or more parameters comprises at least one of initiating or executing the proposed operation, allowing the proposed operation to execute or continue executing, implementing the one or more parameters, and generating an instruction configured to cause the gas filling station to implement at least one of the proposed operation and the one or more parameters.

16. The system of claim 11, further comprising the failsafe controller, wherein the failsafe controller comprises memory and at least one processor coupled to the memory, wherein the at least one processor is configured to: based on a plausibility check performed to check the output generated by the operations controller, determine that at least one of the proposed operation and the one or more parameters is outside of an acceptable range of values defined by the safety constraint in the pre-approved data;in response to the determining that the at least one of the proposed operation and the one or more parameters is outside of the acceptable range of values, determine that the at least one of the proposed operation and the one or more parameters does not comply with the safety constraint; and send the signal to the operations controller, the signal indicating that the at least one of the proposed operation and the one or more parameters does not comply with the safety constraint.

17. The system of claim 16, wherein the one or more processors of the operations controller are further configured to reject the at least one of the proposed operation and the one or more parameters based on the signal, and wherein rejecting the at least one of the proposed operation and the one or more parameters comprises at least one of preventing or rejecting execution of the proposed operation, aborting or stopping the proposed operation, rejecting the one or more parameters, and preventing implementation of the at least one of the proposed operation and the one or more parameters.

18. The system of claim 11, wherein approving or rejecting the at least one of the proposed operation and the one or more parameters comprises approving the at least one of the proposed operation and the one or more parameters, and wherein approving the at least one of the proposed operation and the one or more parameters comprises, based on the at least one of the proposed operation and the one or more parameters being approved, generating an instruction configured to adjust a respective operation of one or more elements of the gas filling station.

19. The system of claim 18, wherein the one or more operation elements comprise at least one of a valve, an actuator, a sealing component, a cooling component, a dispenser, a compressor, a gas nozzle, a switch, an electrical component, and a sensor, and wherein the sensor comprises at least one of a temperature sensor, a pressure sensor, a flow sensor, a gas sensor, a motion sensor, and an inertial measurement unit.

20. The system of claim 11, wherein the operations controller and the failsafe controller are part of a same programmable logic controller (PLC) or different PLCs, and wherein the systemfurther comprises the failsafe controller and a transportation module of the gas filling station, the transportation module comprising at least one of: a storage configured to store gas for the gas filling station; a dispenser configured to dispense the gas to one or more targets connected to the dispenser; one or more compressors; one or more buffer tanks; and a plurality of valves and pipes configured to couple the one or more compressors with the one or more buffer tanks.

21. The system of claim 1, further comprising the failsafe controller, wherein at least one of the operations controller and the failsafe controller associated with the gas filling station is configured to prevent malicious manipulation of the pre-approved data programmed on the failsafe controller, detect errors during runtime, correct errors encountered during runtime, provide compliance with safety parameters, obtain and maintain regulatory approval, and detect a hardware failure of at least one of the operations controller and the failsafe controller.

22. A non-transitory computer-readable medium having stored thereon instructions which, when executed by an operations controller of a gas filling station, cause the operations controller to: receive, from a failsafe controller associated with the gas filling station, a portion of preapproved data programmed on the failsafe controller, the failsafe controller having a restriction that requires the pre-approved data to be re-approved by a regulatory entity any time that the preapproved data programmed on the failsafe controller is modified; send, to the failsafe controller, an output generated based on the portion of the preapproved data, the output identifying at least one of a proposed operation for the gas filling station and one or more parameters associated with the proposed operation; receive, from the failsafe controller, a signal indicating whether the at least one of the proposed operation and the one or more parameters complies with a safety constraint included or specified in the pre-approved data; andin response to the signal, approve or reject the at least one of the proposed operation and the one or more parameters.

Citation Information

Patent Citations

  • Configurable safety system for implementation on industrial system and method of implementing same

    US20040010326A1

  • Safety Controller And Method For Loading A New Operating Program Onto The Safety Controller

    US20080010638A1

  • Gas filling system

    US20120125482A1