Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

32 results about "Safety Integrity Level" patented technology

Safety integrity level (SIL) is defined as a relative level of risk-reduction provided by a safety function, or to specify a target level of risk reduction. In simple terms, SIL is a measurement of performance required for a safety instrumented function (SIF).

Imaging sensor

ActiveUS12535589B2Electromagnetic wave reradiationTime of flight sensorSafety Integrity Level
The invention relates to imaging 3-D time-of-flight sensors that are particularly suitable for the detection of objects and individuals in three-dimensional space. This capability results from the basic principle. In each image point of the sensor, the distance to the object located in the observation space is determined by using the propagation time (time of flight) of light pulses. The sensor therefore supplies a three-dimensional image, which can be analyzed by means of suitable processing algorithms. In specific applications, in particular in the interaction of human and machine, machine and machine, or machine and space, it is necessary that the detection is carried out safely. The level of safety is classified in various standards into safety integrity levels.
Owner:IRIS GMBH INFRARED & INTELLIGENT SENSORS

Controller system and method for vehicle, and computer readable storage medium

The embodiment of the invention provides a vehicle controller system and method and a computer readable storage medium, and the system comprises an application processing unit which is used for executing application software based on a quality management level corresponding to a vehicle industry standard; the software monitoring processing unit is used for monitoring the software running state of the application software based on the first security level; the hardware monitoring processing unit is used for monitoring the first hardware running state of the application processing unit and the second hardware running state of the software monitoring processing unit based on the second security level; wherein the first safety level and the second safety level meet a target function safety level corresponding to the controller system through level decomposition and superposition, and the first safety level, the second safety level and the target function safety level are selected from a plurality of safety integrity levels corresponding to the vehicle industry standard. The technical problem that the flexibility of a controller system of a vehicle is poor is solved.
Owner:CHERY AUTOMOBILE CO LTD

Escalator remote function safety device based on safety PLC and control method

The invention provides an escalator remote function safety device based on a safety PLC and a control method, and relates to the technical field of elevator safety control, and the escalator remote function safety device based on the safety PLC comprises an AI abnormal behavior detection module; a master control room monitoring and output module; a signal transmission module; an escalator control cabinet detection module; and a safety loop control module. By means of AI behavior recognition, safety PLC closed-loop control and remote signal transmission, remote emergency stopping of the escalator under the abnormal working condition is achieved, the SIL2 safety integrity level requirement of the IEC61508 standard is met, and the system is suitable for escalators and moving sidewalks in crowded places such as shopping malls, subway stations and airports.
Owner:CANNY ELEVATOR

Rail transit monitoring and decision-making method and device based on image recognition and artificial intelligence

The invention discloses a rail transit monitoring and decision-making method and device based on image recognition and artificial intelligence. The rail transit monitoring and decision-making method based on image recognition and artificial intelligence comprises the following steps: acquiring an ATS interface frame image with a timestamp acquired by an external camera device or a video acquisition card; performing information extraction on the ATS interface frame image to obtain a structured real-time information set; obtaining abnormal event detail information according to the obtained structured real-time information set; generating suggested operation instruction information according to the abnormal event detail information; and displaying the suggested operation instruction information and carrying out multi-channel pushing. The ATS interface image is acquired through the external camera or the video acquisition card, direct data interaction with software and hardware of the ATS system is avoided, interference on the SIL (security integrity level) of the ATS system is avoided, the ATS interface image acquisition device can adapt to the ATS systems of different manufacturers and different versions, and compatibility risks and potential safety hazards caused by traditional intrusive interface modification are solved.
Owner:BEIJING JIAOTONG UNIV

Method for fault detection in safety mechanisms

Safety mechanisms are embedded into a System on a Chip (SoC) and are operable to detect faults present in the logic circuitry in the SoC. Various types of faults in logic circuitry can occur, for example, a bit stuck at 0 or 1, or a transient or temporary fault due to radiation impacting the SoC. SoC devices are required to meet certain automotive safety integrity standards. The most stringent automotive safety integrity level requires that 90% of random latent faults are detected in all relevant logic, including all safety mechanism. Examples disclosed include hardware based checkers and hardware or software based pattern generation methods that achieve high online fault coverage in safety mechanism circuitry used for functional safety. A hardware based safety mechanism monitors the logic circuitry during operation. Any time the safety mechanism detects any faults in the logic circuitry, a fault notification is propagated to upstream logic.
Owner:XILINX INC

Railway vehicle monitoring and signalling system and method

A railway vehicle monitoring and signaling system 30 includes trackside devices (e.g. track circuits 36 and signals Sx, Sy) for reporting Safety Integrity Level 2 (SIL2) data regarding the presence or
Owner:SIEMENS MOBILITY LTD

SIS safety integrity level dynamic verification method and system considering uncertainty

ActiveCN120524526BDigital data protectionArtificial lifeSafety instrumented systemFuzzy uncertainty
This invention belongs to the technical field of Safety Integrity Level (SIL) verification for Safety Instrumented Systems (SIS), specifically disclosing a dynamic verification method and system for SIL considering uncertainty. Addressing the uncertainty issues in SIL verification, this invention introduces stochastic uncertainty theory and fuzzy uncertainty theory, combining stochastic uncertainty theory with LSTM networks and fuzzy uncertainty theory with fuzzy logic to propose a novel dynamic SIL verification method. It also performs source tracing analysis on the SIL verification results and uses a random forest method for feature importance analysis. The SIL level is dynamically updated as data is updated. This invention solves the problems of uncertainty and static lag in traditional SIL verification, eliminates the fuzzy uncertainty of expert judgment and the static nature of field data, and enables the final verification results to be dynamic and up-to-date.
Owner:CHINA UNIV OF PETROLEUM (EAST CHINA)

Escalator remote function safety device based on safety PLC and control method

This invention provides a remote functional safety device and control method for escalators based on a safety PLC, relating to the field of elevator safety control technology. The remote functional safety device for escalators based on a safety PLC includes: an AI abnormal behavior detection module; a main control room monitoring and output module; a signal transmission module; an escalator control cabinet detection module; and a safety loop control module. Through AI behavior recognition, safety PLC closed-loop control, and long-distance signal transmission, it enables remote emergency stopping of the escalator under abnormal operating conditions, meeting the SIL2 safety integrity level requirements of the IEC61508 standard. It is suitable for escalators and moving walkways in densely populated places such as shopping malls, subway stations, and airports.
Owner:CANNY ELEVATOR

Railway vehicle monitoring and signalling system and method

ActiveGB2641130BRailway traffic control systemsSafety Integrity LevelSignaling system
A railway vehicle monitoring and signaling system 30 includes trackside devices (e.g. track circuits 36 and signals Sx, Sy) for reporting Safety Integrity Level 2 (SIL2) data regarding the presence or
Owner:SIEMENS MOBILITY LTD

Satellite system software integrity guarantee design method based on DO-278A

PendingCN121389081AError detection/correctionProgram/content distribution protectionFault tolerant architectureSafety Integrity Level
The invention discloses a design method for ensuring the integrity of satellite system software based on DO-278A. The method comprises the following steps: defining a satellite dedicated software security integrity level SSIL and mapping the satellite dedicated software security integrity level SSIL with a software integrity level SWIL of a DO-278A standard; constructing a satellite-ground cooperative dual V model containing a ground development V model and an on-orbit maintenance V model; designing a space software fault-tolerant architecture and carrying out a fault injection test; and establishing an on-orbit software health state monitoring and evidence collection closed-loop process. According to the method provided by the invention, the full life cycle of the satellite software is covered, the fault-tolerant capability and on-orbit maintainability of the satellite software are improved, the blank of an integrity guarantee scheme of the satellite exclusive software in the prior art is filled, and long-period and high-reliability operation of the satellite software is guaranteed.
Owner:SHANGHAI LANJIAN HONGQING TECH CO LTD

Braking device and method for performing emergency braking of a rail vehicle

The invention relates to a brake system for performing emergency braking of a rail vehicle, comprising: at least one brake cylinder (14); a pressure regulating device (12) for providing a brake cylinder pressure (Pb) to the brake cylinder (14); and a control device (16) for actuating the pressure regulating device (12). In order to enable flexible adaptation of the brake pressure even during emergency braking, the control device (16) comprises a control system (16i) and at least one further control system (16ii), each for actuating the pressure regulating device (12), wherein the different control systems (16i, 16ii) of the control device (16) are designed according to different safety integrity levels.
Owner:KNORR BREMSE SYST FUR SCHIENENFAHRZEUGE GMBH

Equipment remote control method and device, equipment and storage medium

InactiveCN121441979ATotal factory controlSecuring communicationSafety Integrity LevelAnomaly detection
The invention provides an equipment remote control method and device, equipment and a storage medium, and the method comprises the steps: carrying out the layered wake-up processing of subway maintenance equipment after receiving a remote control request, and obtaining a wake-up confirmation signal and a network delay compensation parameter; performing dynamic allocation on the maintenance equipment operation authority according to an awakening confirmation signal and a delay compensation parameter in combination with a subway safety integrity level requirement to obtain an authority level and a hierarchical control channel; aiming at maintenance operation time window limitation, performing optimization generation on the control instruction according to the authority level and the hierarchical control channel to obtain a remote control instruction and an execution timing schedule; and performing closed-loop monitoring on the execution process of the remote control instruction according to the execution timing schedule, adjusting the execution process through state estimation and anomaly detection, and starting an emergency processing mechanism when an anomaly is detected. According to the invention, accurate remote control of maintenance equipment can be realized in a complex subway tunnel network environment, and the control efficiency and safety are improved.
Owner:SHENZHEN COSUN SIGN ENG CO LTD +1

Dual hand button synchronous interlock safety control module and control method

PendingCN122652928AHemt circuitsInternal feedback
The application relates to the technical field of industrial safety control, and discloses a double-hand button synchronous interlocking safety control module and a control method. The module comprises two input channels, a cross fault detection circuit, a synchronism detection circuit, a redundant output unit and an internal feedback monitoring circuit. The cross fault detection circuit continuously monitors the electrical isolation state between the channels during operation, and disconnects the output when an abnormality is found. The synchronism detection circuit measures the time difference when the two input signals become valid, and only allows the output when the time difference is not greater than a preset synchronization time window. The redundant output unit is composed of at least two series-connected forced direction switching elements, and cooperates with the feedback monitoring to ensure that the safety circuit can still be cut off under single-point fault. The application improves the safety and reliability and the response speed through real-time channel isolation monitoring, pure hardware synchronization judgment and redundant output fault-tolerant design, meets the requirements of high safety integrity level, and is suitable for safety application scenarios of various double-hand button control.
Owner:SHENZHEN YIPUXING TECH CO LTD

Functionally safe high speed fail-safe counter module

A failsafe counter module includes a controller that includes a processor and memory and circuitry for failsafe counting. The failsafe counter module also includes computer readable safety rating support code stored in the memory that, when executed by the processor, causes the controller to provide an international standard level of safety rating, such as Safety Integrity Level (SIL) 3, Category (CAT) 4, Performance Level (PL) e. The failsafe counter module also includes computer readable "safety monitoring" function code stored in the memory that, when executed by the processor, causes the controller to work with a user interface to select and configure a "safety monitoring" function. The failsafe counter module is a functional safety rated device with the intended rating for SIL 3, CAT 4, PL e applications and is designed to calculate position and / or speed with an external quadrature encoder sensor that produces a waveform that allows counting of specific electrical pulses.
Owner:SIEMENS AG

Independent safety monitoring of an automated driving system

An automated driving system includes a security companion subsystem to access data generated at a compute subsystem of the automated driving system, which indicates a determination by the compute subsystem associated with an automated driving task. The security companion subsystem determines whether the determination is safe based on the data. The security companion subsystem is configured to realize a higher safety integrity level than the compute subsystem.
Owner:INTEL CORP

Functional safety high-speed fail-safe counter module

A fail-safe counter module comprises a controller including a processor and a memory and circuitry for fail-safe counting. The fail-safe counter module further comprises computer-readable safety rating support code stored in the memory which, when executed by the processor, causes the controller to provide safety rating to International Standard levels such as Safety Integrity Level (SIL) 3, Category (CAT) 4, Performance Level (PL) e. The fail-safe counter module further comprises computer-readable ā€œSafety Monitoringā€ functions code stored in the memory which, when executed by the processor, causes the controller to work with a user interface to select and configure the ā€œSafety Monitoringā€ functions. The fail-safe counter module is a functional safety-rated device with an expected rating for SIL 3, CAT 4, PL e applications and is engineered to calculate position and / or speed utilizing an external quadrature encoder sensor that generates waveforms which permits counting of specific electrical pulses.
Owner:SIEMENS AG

Fail operational steering angle sensor

A Steering Angle Sensor (SAS), equipped with a redundancy system to allow the bypass of any failing part, keeping all functionalities intact, while ensuring all the required safety integrity levels is provided. The proposed fail operational redundant steering angle sensor (100) has two functional blocks (70) responsible to determine the absolute angle between at least two angling sensing devices, detecting systematic failures of the devices.
Owner:BOSCH CAR MULTIMEDIA PORTUGAL SA +1

Independent safety monitoring of an automated driving system

An automated driving system includes a security companion subsystem to access data generated at a compute subsystem of the automated driving system, which indicates a determination by the compute subsystem associated with an automated driving task. The security companion subsystem determines whether the determination is safe based on the data. The security companion subsystem is configured to realize a higher safety integrity level than the compute subsystem.
Owner:INTEL CORP

Vehicle system fault diagnosis method, controller and vehicle system

PendingCN121050221ASafety arrangmentsDiagnostic dataSafety Integrity Level
The invention discloses a vehicle system fault diagnosis method, a controller and a vehicle system.The method is applied to the vehicle system, the vehicle system comprises a master controller, a first controller and a second controller, and the method comprises the steps that the first controller sends a diagnosis request to the second controller, the second controller obtains diagnosis data according to the diagnosis request; the first controller performs fault diagnosis according to the first data and received diagnosis data sent by the second controller or the master controller; the first controller determines that the vehicle system has a fault in a case where the first data is not the same as the diagnostic data. Fault diagnosis is carried out through the first controller according to whether the collected data are the same or not, the diagnosis coverage rate of the system can be improved, faults in the system can be comprehensively detected, measures are taken under the condition that the faults exist, accidents are prevented, and it is guaranteed that the vehicle system has the high safety integrity level.
Owner:BYD CO LTD

Automobile safety integrity grade decomposition device and method

PendingCN120743369AHardware monitoringProgram loading/initiatingSafety Integrity LevelTesting Methods
The invention provides an automobile safety integrity grade decomposition device and method, and the device comprises a first function layer which obtains a second signal through calculation according to a first signal of a first grade; the second functional layer calculates a third signal according to the first signal; the merging module is used for merging the second signal and the third signal to obtain a fourth signal of a second level; wherein the first function layer and the second function layer are used for calculating the same physical quantity, the calculation modes are different, the first signal is utilized in a time-sharing mode, the first function layer and the second function layer are developed according to the first level, and the safety level of the second level is higher than that of the first level. The common cause failure is avoided by using the first signal in a time-sharing manner, so that the safety levels of the second signal and the third signal obtained by processing the two functional layers are the same as those of the first signal, and then the second signal and the third signal are combined, so that a fourth signal with a higher safety level can be obtained according to an ASIL decomposition method; and a higher ASIL function security target is realized by ingeniously utilizing low development cost.
Owner:UNITED AUTOMOTIVE ELECTRONICS SYST

Automatic measurement and control device and control method for deuterium-tritium fuel circulation system of magnetic confinement fusion reactor

The invention discloses an automatic measurement and control device for a deuterium-tritium fuel circulation system of a magnetic confinement fusion reactor and a control method, and belongs to the technical field of industrial control, the device comprises an OCS industrial optical bus control system and an SIS safety interlocking system which are dispatched by an intelligent production scheduling system, the OCS industrial optical bus control system and the SIS safety interlocking system are of three-level structures, and the OCS industrial optical bus control system and the SIS safety interlocking system are connected with the intelligent production scheduling system. Comprising a field level, a control level and a monitoring level. The control level of the OCS industrial optical bus control system is connected with the field level through an optical bus, and software definition of signal types is realized by adopting a general I / O module; the SIS safety interlocking system operates independently based on the SIL3 safety integrity level. The OCS industrial optical bus control system is adopted to replace a traditional DCS / PLC architecture, and the problems of electromagnetic interference, poor system collaboration and the like are solved through the optical bus and the universal I / O module; the safety and the redundancy capability are improved through an independent SIS safety interlocking system; meanwhile, intelligent production scheduling control is integrated, and the production efficiency is remarkably improved.
Owner:MATERIAL INST OF CHINA ACADEMY OF ENG PHYSICS

Method and Controller for Determining a Safety Integrity Level for a Safety-Related Vehicle Function of a Motor Vehicle

PendingUS20260001562A1External condition input parametersProgram controlSafety Integrity LevelData signal
A computer-implemented method for determining a safety integrity level of a safety-related vehicle function of a motor vehicle, includes providing at least one infrastructure and / or vehicle sensor data signal, which represents infrastructure and / or vehicle sensor data, which are intended for the safety-related vehicle function provided by the motor vehicle. The method further includes determining a safety integrity level of the safety-related vehicle function based on the infrastructure and / or vehicle sensor data signal provided; and allocating a calculation of the safety-related vehicle function to an in-vehicle and / or an off-vehicle system, taking into account a predetermined safety integrity of the in-vehicle and / or the off-vehicle system.
Owner:ROBERT BOSCH GMBH

Method and system for checking a trajectory for collision-free operation

ActiveDE102024210920A1Anti-collision systemsCharacter and pattern recognitionSafety Integrity LevelSimulation
The invention relates to a method for checking a planned trajectory (T) of a vehicle (1) for collision-free travel based on an environment model (2, 2') comprising a plurality of cells (Z), wherein the cells each correspond to an environmental area in the vicinity of the vehicle (1) and each cell (Z) is assigned information indicating whether the environmental area represented by the cell (Z) can be traversed without collision, wherein the first environment model (2) is provided by a first processor (P1) having a first safety integrity level that is lower than a safety level required for checking the trajectory (T) for collision-free travel, wherein the first processor (P1) determines at least one trajectory (T) to be checked for collision-free travel based on the first environment model (2), wherein the first environment model (2) or a different environment model (2) is used to determine the trajectory (T) to be checked for collision-free travel.a second, information-reduced environment model (3) is generated from the first environment model (2) or the further environment model (2') by reducing the first environment model (2) or the further environment model (2') to information relevant for the collision check of the trajectory (T), and wherein a second processor (P2), which has a second safety integrity level that is at least equivalent to the safety integrity level required for checking the trajectory (T) for collision-free operation, performs a collision check of the trajectory (T) based on the second, information-reduced environment model (3).
Owner:AUMOVIO AUTONOMOUS MOBILITY GERMANY GMBH

QM actuators with an ASIL-D domain controller

A method for controlling an actuator in a domain controller architecture in a vehicle includes receiving, at a domain controller, data related to operation of the actuator. The data includes information indicative of outputs of an actuator controller configured to control the actuator. The domain controller is configured to operate in accordance with a first safety integrity level among a plurality of safety integrity levels. The actuator controller is configured to operate in accordance with a second safety integrity level below the first safety integrity level. The method includes selectively supplying, from the domain controller based on the received data, a disable signal to a hardware component of the actuator controller to disable control of the actuator by the actuator controller. The disable signal is generated in accordance with the first safety integrity level and the hardware component is configured to operate in accordance with the first safety integrity level.
Owner:STEERING SOLUTIONS IP HOLDING CORP

Rail transit signal safety system based on public cloud platform and deployment method thereof

The invention provides a rail transit signal safety system based on a public cloud platform and a deployment method thereof, and the method comprises the steps: migrating a signal safety subsystem to the public cloud platform through a virtualization technology, deploying an AVCD in a virtual machine of the public cloud platform, and enabling the AVCD to communicate with the signal safety subsystem, the security application module is used for providing an encrypted communication channel, executing secondary voting of output results of the security application and seamless smooth switching after the results are inconsistent, isolating the security application from the non-security application, providing a standardized interface and having the functions of fault diagnosis and log recording; the fixed resource pool communicates with the AVCD and stores output information of the signal safety subsystem in real time; the safety switching decision-making device communicates with the cloud platform interlock, the OCS and the regional backup interlock, monitors the communication state of the cloud platform interlock and the OCS, and controls switching to the regional backup interlock when communication is lost. According to the invention, the SIL4 safety integrity level standard limitation of the rail transit signal safety subsystem in a public cloud environment is broken through.
Owner:XINYU BOMBARDIER SIGNAL SYST CO LTD

SIS security integrity level dynamic verification method and system considering uncertainty

ActiveCN120524526ADigital data protectionArtificial lifeSafety instrumented systemFuzzy uncertainty
The invention belongs to the technical field of security integrity level verification of a security instrument system, and particularly discloses an SIS security integrity level dynamic verification method and system considering uncertainty. According to the method, for the uncertainty problem in SIL verification work, the random uncertainty theory and the fuzzy uncertainty theory are introduced, the random uncertainty theory and the LSTM network are combined, the fuzzy uncertainty theory and the fuzzy logic are combined, the new SIL dynamic verification method is provided, traceability analysis is carried out for an SIL verification result, and the SIL verification efficiency is improved. And carrying out feature importance analysis by adopting a random forest method. And when the data is updated, dynamically updating the SIL level. According to the method, the problems of uncertainty and static hysteresis in the traditional SIL verification process are solved, the fuzzy uncertainty problem of expert judgment and the static problem of field data are eliminated, and the final verification result can be dynamic and updated.
Owner:CHINA UNIV OF PETROLEUM (EAST CHINA)

Safety integrity level (SIL) verification method and device based on wind-solar coupling hydrogen production device, computer device and storage medium

The application relates to the technical field of SIL verification, and discloses a safety integrity level SIL verification method and device based on a wind-solar coupling hydrogen production device, computer equipment and a storage medium, wherein a preset database corresponding to a safety instrument function SIF loop in the wind-solar coupling hydrogen production device is determined; a SIL verification model is constructed; the SIF loop is calculated by using the SIL verification model according to the preset database; and a calculation result of the SIF loop is determined; and whether the SIF loop meets a corresponding SIL level is verified according to the calculation result. The technical scheme provided by one or more embodiments of the application can improve the system safety and reliability of the wind-solar coupling hydrogen production device by performing SIL verification on the wind-solar coupling hydrogen production device.
Owner:HUADIAN HEAVY IND CO LTD

Method and system for checking a trajectory for collision-free operation

The invention relates to a method for checking a planned trajectory (T) of a vehicle (1) for collision-free travel based on an environment model (2, 2') comprising a plurality of cells (Z), wherein the cells each correspond to an environmental area in the vicinity of the vehicle (1) and each cell (Z) is assigned information indicating whether the environmental area represented by the cell (Z) can be traversed without collision, wherein the first environment model (2) is provided by a first processor (P1) having a first safety integrity level that is lower than a safety level required for checking the trajectory (T) for collision-free travel, wherein the first processor (P1) determines at least one trajectory (T) to be checked for collision-free travel based on the first environment model (2), wherein the first environment model (2) or a different environment model (2) is used to determine the trajectory (T) to be checked for collision-free travel.a second, information-reduced environment model (3) is generated from the first environment model (2) or the further environment model (2') by reducing the first environment model (2) or the further environment model (2') to information relevant for the collision check of the trajectory (T), and wherein a second processor (P2), which has a second safety integrity level that is at least equivalent to the safety integrity level required for checking the trajectory (T) for collision-free operation, performs a collision check of the trajectory (T) based on the second, information-reduced environment model (3).
Owner:AUMOVIO AUTONOMOUS MOBILITY GERMANY GMBH