Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

20 results about "Safety critical application" patented technology

Ambiguity deviation vector classification and probability decoupling collaborative protection level construction method and device

The invention discloses an ambiguity deviation vector classification and probability decoupling collaborative protection level construction method and device, and belongs to the technical field of integrity monitoring. The method comprises the following steps: firstly, constructing a model of a positioning error under a fixed solution, then constructing an initial protection level model based on a Bayesian formula, then performing protection level parameter decoupling by utilizing an ambiguity deviation vector probability, classifying deviation vectors according to a modulus length, calculating a modulus length boundary value, and finally obtaining a protection level parameter; and finally, calculating a final protection level based on decoupling and classification results. According to the method, the influence of ambiguity error fixation on the protection level can be quantified, and the requirements of safety critical applications on reliability and interpretability are met.
Owner:HARBIN ENG UNIV

Methods and articles of manufacture for hosting a safety critical application on an uncontrolled data processing device

Methods and articles of manufacture for hosting a safety critical application on an uncontrolled data processing device are provided. Various checks and combinations of checks including installation, functional, host integrity, coexistence, interoperability, power management, and environment checks are performed at various times to determine if the safety critical application operates properly on the device. The operation of the SCA on the UDPD may be controlled accordingly.
Owner:ABBOTT DIABETES CARE INC

System and method for integrity monitoring of heterogeneous system-on-a-chip (SoC) based systems

A system and method for integrity monitoring on a heterogeneous system-on-a-chip (SoC) processing environment provides sets of dynamic input data to integrity applications running on one or more application cores (e.g., where safety critical applications are hosted) which generate an integrity output according to function / instruction sets. The dynamic input data is also provided to an integrity monitor running on a dissimilar integrity core (e.g., different architecture and / or other core type than the application cores) which receives the integrity output from the application cores and generates its own integrity result based on the same function sets and the same dynamic input data. The integrity monitor compares the local integrity result to the integrity outputs received from the application cores. If the integrity outputs deviate from the integrity result, the integrity core initiates a fault response, which may include resetting the deviant application core, all application cores, or the full SoC environment.
Owner:ROCKWELL COLLINS INC

System identification of industrial robot dynamics for safety-critical applications

Embodiments of the present invention provide automated robotic system identification and stopping time and distance estimation, significantly improving on existing ad-hoc methods of robotic system identification. Systems and methods in accordance herewith can be used by end users, system integrators, and the robot manufacturers to estimate the dynamic parameters of a robot on an application-by-application basis.
Owner:VEO ROBOTICS INC

Voltage sensor with in-range check for safety-critical applications

Aspects of the disclosure are directed to voltage sensing for safety-critical applications. In accordance with one aspect, the disclosure includes a multi-phase ring oscillator (RO) configured to operate in a first voltage domain; a frequency counter coupled to the multi-phase RO, the frequency counter configured to accumulate a plurality of phase cycles from the multi-phase RO over a time duration to generate a digital count word; an alarm processor coupled to the frequency counter, the alarm processor configured to receive an alarm state signal from the frequency counter; and a heartbeat detector coupled to the multi-phase RO, the heartbeat detector configured to operate in a second voltage domain and configured to detect a periodic recurrence of a heartbeat pulse to determine an integrity of the sensor function as a whole and alarm state signal in particular.
Owner:QUALCOMM INC

Temporal buffering of integrity comparison data

ActiveUS20250328408A1Fault responseProcessing coreCommon mode failure
A system-on-chip may include application processing cores which execute safety critical applications and an integrity application. The system-on-chip may also include integrity processing cores which execute an integrity monitor. The integrity monitor may compare integrity application outputs and integrity monitor outputs to detect if the processing cores have experienced a common mode fault. The integrity processing cores may perform temporal monitoring to accommodate time-asynchronization's between the application processing cores and the integrity processing cores.
Owner:ROCKWELL COLLINS INC

Method and apparatus for operating a control unit for safety-critical applications in a motor vehicle

PendingCN122374211AControl cellSecure state
The present invention relates to a computer-implemented method for operating a vehicle system (1), the method comprising the following steps: - when a security objective (S1) is violated, a security mechanism (S2) is invoked; - when a fault (S4) is detected during the execution of the security mechanism, a backup security mechanism assigned to the security objective is invoked; - when a fault is detected in the backup security mechanism, the vehicle system is brought into a safe state; - according to an activation restriction description associated with the violated security objective, the invocation of the backup security mechanism is prevented (S12).
Owner:ROBERT BOSCH GMBH

Method and system for executing security critical applications

A method of executing a security critical application (150) on a hardware platform (100) is presented. The method comprises: executing a virtual machine monitoring program (120) having a monitoring component (130) for a security critical application (150) on a hardware platform (100); instantiating at least one virtual machine (140) by a privilege level of the virtual machine monitoring program (120) hardware platform that is lower than the privilege level of the virtual machine monitoring program (120); a list of one or more predefined actions is provided that, when executed by the processor core (112a, 112b), have relevance to the integrity and / or operation of the safety critical application (150). The method further comprises instructing, by the virtual machine monitoring program (120), the processor core (112a, 112b) to divert the control flow towards a respective handler (132) in the monitoring component (130) for the action to be performed when the action to be performed is about to be performed on the list; and executing at least the security critical application (150) over the guest operating system (142) in the at least one virtual machine (140). Further, a check of whether the action is allowed or not allowed may be performed, and / or at least one preparation for the action to be performed may be performed.
Owner:ELEKTROBIT AUTOMOTIVE GMBH

SYSTEM AND METHOD FOR INTEGRITY MONITORING OF HETEROGENEOUS SYSTEM-ON-A-CHIP (SoC) BASED SYSTEMS

A system and method for integrity monitoring on a heterogeneous system-on-a-chip (SoC) processing environment provides sets of dynamic input data to integrity applications running on one or more application cores (e.g., where safety critical applications are hosted) which generate an integrity output according to function / instruction sets. The dynamic input data is also provided to an integrity monitor running on a dissimilar integrity core (e.g., different architecture and / or other core type than the application cores) which receives the integrity output from the application cores and generates its own integrity result based on the same function sets and the same dynamic input data. The integrity monitor compares the local integrity result to the integrity outputs received from the application cores. If the integrity outputs deviate from the integrity result, the integrity core initiates a fault response, which may include resetting the deviant application core, all application cores, or the full SoC environment.
Owner:ROCKWELL COLLINS INC

Method and system for executing security critical applications

A method of executing a security critical application on a hardware platform (100) is presented. The method comprises: executing a safety critical application (130) in a first execution environment (120); executing a supervisor component (150) for the safety critical application in a second execution environment (140); at least a transition of control flow between the safety critical application (130) and other software (125, 125a, 125b) running in the first execution environment (120) is detected by the supervisor component (150). The method further includes, in response to detecting that the control flow is transitioning from the security critical application (130) to the other software (125, 125a, 125b), disabling, by the supervisor component (150), at least one mode of access to and / or capturing a state of at least one resource (114), and, in response to detecting that the control flow is transitioning from the other software (125, 125a, 125b), disabling, by the supervisor component (150), at least one mode of access to and / or capturing a state of the at least one resource (114). 125b) back to the security critical application (130), allowing re-access to the at least one resource (114) and / or verifying the state.
Owner:ELEKTROBIT AUTOMOTIVE GMBH

Voltage sensor with in-range check for safety-critical applications

Aspects of the disclosure are directed to voltage sensing for safety-critical applications. In accordance with one aspect, the disclosure includes generating an alarm state signal from a digital count word and a comparator state signal; generating a heartbeat signal by dividing down one of a plurality of multi-phase ring oscillator (RO) output waveforms; and generating an error interrupt signal and a warning interrupt signal in a voltage domain based on the alarm state signal and the heartbeat signal.
Owner:QUALCOMM INC

Methods and articles of manufacture for hosting a safety critical application on an uncontrolled data processing device

ActiveEP4087196B2Fault responseDigital data processing detailsSoftware engineeringSafety critical application
Methods and articles of manufacture for hosting a safety critical application on an uncontrolled data processing device are provided. Various combinations of installation, functional, host integrity, coexistence, interoperability, power management, and environment checks are performed at various times to determine if the safety critical application operates properly on the device. The operation of the SCA on the UDPD may be controlled accordingly.
Owner:ABBOTT DIABETES CARE INC

Temporal buffering of integrity comparison data

ActiveUS12468596B2Redundant hardware error correctionProcessing coreCommon mode failure
A system-on-chip may include application processing cores which execute safety critical applications and an integrity application. The system-on-chip may also include integrity processing cores which execute an integrity monitor. The integrity monitor may compare integrity application outputs and integrity monitor outputs to detect if the processing cores have experienced a common mode fault. The integrity processing cores may perform temporal monitoring to accommodate time-asynchronization's between the application processing cores and the integrity processing cores.
Owner:ROCKWELL COLLINS INC

Control unit having a secure software component

PCT designated stageWO2026078108A1Safety arrangmentsComputer controlSecurity softwareSoftware engineering
The invention relates to a control unit having a secure software component (12a) and a hardware component (14) for carrying out control and / or monitoring functions for security-critical applications in automation technology, wherein the hardware component (14) is designed to output functional and diagnostic information. The hardware component (14) is not secure, in particular is not certified or checked, wherein the secure software component (12a) has a secure interface (16) and secure functional modules (FB-s) in order to communicate with the non-secure hardware component (14) and to read out the functional and diagnostic information, wherein the secure functional modules (FB-s) are designed to check the functional information for errors using the diagnostic information and to output security-related functional information in order to form a security controller (15a) for securely carrying out the control and / or monitoring functions.
Owner:IFM ELECTRONIC GMBH

Method and system for executing a safety-critical application

A method of executing a safety-critical application (150) on a hardware platform (100) is proposed. The method includes executing, on the hardware platform (100), a hypervisor (120) with a monitoring component (130) for the safety-critical application (150), instantiating, by the hypervisor (120), at least one virtual machine (140) on a lower privilege level of the hardware platform than a privilege level of the hypervisor (120), providing a list of one or more predefined actions that, when executed by the processor core (112a, 112b), have a relevancy for an integrity and / or a functioning of the safety-critical application (150). The method further includes instructing, by the hypervisor (120), the processor core (112a, 112b) to when about to execute a to-be-performed action on the list, divert the control flow towards a respective handler (132) for this to-be-performed action in the monitoring component (130), and executing, in the at least one virtual machine (140), at least the safety-critical application (150) on top of a guest operating system (142). Further, a check whether to allow or disallow the action can be performed and / or at least one preparation for the to-be-performed action may be performed.
Owner:ELEKTROBIT AUTOMOTIVE GMBH

Split Lock Architecture of Multi-Core Processor

Each core of a multi-core processor is capable of running both safety-critical and non-safety-critical applications. The first core is configured to send a request to the second core to enter into a lock mode to execute the safety-critical application in parallel with the first core. A comparator receives inputs from the first core and the second core and compares the inputs. The second core drives the comparator into a transition state; stops execution of a first application running on the second core; saves data from the second core to memory associated with the second core; and sends an acknowledgment back to the first core in response to the request. The first core, in response to receiving the acknowledgement signal, is further configured to enable the execution of the safety-critical application by both cores in lock mode by configuring the memory and the comparator.
Owner:IMAGINATION TECH LTD

System and method for verifiable, ethical arbitration and immutable auditing of autonomous decisions using constrained execution environments

A system and method for creating a verifiable, non-repudiable audit log of an autonomous system's ethical decision-making, solving the “black-box” problem for safety-critical applications. The system integrates a Trusted Execution Environment (TEE) with a Hierarchical Constraint Logic Processor (HCLP). The TEE's integrity is verified using a decentralized remote attestation (RA) state measurement incorporating a measurement from an intrinsic Physically Unclonable Function (PUF), which provides a hardware root of trust. The HCLP applies tiered constraints to select a control maneuver with the lowest calculated harm score from a set of potential outcomes. The system generates a novel, verifiable log entry that cryptographically binds the RA state measurement to the calculated harm scores of all rejected control maneuvers. This counterfactual log is immutably anchored into a Cryptographic Audit Log Service using a Merkle Tree, generating a non-repudiable Cryptographic Audit Certificate (CAC) for definitive, post-facto regulatory verification.
Owner:MITCHELL RICHARD JOSEPH