Automation Firmware Modules for Incremental Safety-Critical Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing automation devices require complete rechecking and re-approval by authorities for even minor changes or additions, leading to significant financial and logistical burdens, especially in safety-critical applications, due to the need for replacing the entire firmware.
Innovation Solution
The automation device separates program functions from the application program, storing them in a digital program memory with unique function pointers, allowing for dynamic calling and updating without affecting the entire firmware, enabling incremental upgrades and additions without re-approval of the entire system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the entire firmware is replaced to add new sensors, actuators or improve the application program, then new functionalities can be implemented, but the entire automation system must be rechecked and approved by an auditing agency or examining authority, creating enormous financial consequences
Solution Approach 1:
The patent segments the firmware into a stable kernel portion and replaceable module portions. The kernel contains core system functions that remain unchanged, while modules can be independently added, removed, or updated. This segmentation allows new functionalities to be implemented through module replacement without requiring changes to the certified kernel, thus avoiding comprehensive re-approval while maintaining system adaptability.
Solution Approach 2:
The patent extracts specific functional components into separate replaceable modules that can be independently managed. By taking out these modules from the monolithic firmware structure, the system enables selective updates of only the necessary components without affecting the certified core system, thereby eliminating the need for complete system re-approval.
2Adaptability or versatility
If the entire firmware is replaced to implement changes, then new program features and support for new sensors and actuators can be provided, but the service life and operational continuity of the automation system are disrupted
Solution Approach 1:
The patent implements a dynamic firmware architecture where modules can be loaded, unloaded, and replaced during system operation without requiring a complete firmware replacement. This dynamic approach allows the system to adapt to new requirements while maintaining continuous operation, thus preserving service life and operational continuity while enabling new functionalities.
Solution Approach 2:
The patent prepares replacement modules in advance and validates them independently before integration. This preliminary action ensures that module updates can be performed with minimal disruption to ongoing operations, maintaining service continuity while enabling timely implementation of new features and support.
3Adaptability or versatility
If safety-critical applications use complete firmware replacement for system improvements, then new functionalities are achieved, but the obligation to have the entire system rechecked and approved creates significant financial burden
Solution Approach 1:
The patent segments the firmware into a certified kernel and uncertified modules. The kernel maintains safety-critical functions with established certification, while modules handle non-critical or adaptable functionalities. This segmentation allows system improvements through module replacement without triggering comprehensive re-certification, thus reducing financial burden while maintaining safety standards.
Solution Approach 2:
The patent applies different quality and certification requirements to different parts of the system. Safety-critical kernel functions maintain strict certification standards, while replaceable modules have flexible quality requirements appropriate to their specific functions. This local quality approach enables system improvements without requiring uniform re-certification of the entire system.
Data Source
AI summary
An automation device, having an input for receiving input signals and/or an output for outputting output signals of a process, and an electronic data processing unit, which is adapted to run an application program during operation of the automation device and to process data contained in the input and/or output signals by means of a program function, characterized in that in a digital program memory, a plurality of program functions is stored separately to the application program, which are each uniquely addressable via a function pointer, wherein during operation of the automation device, based on a predetermined function selection, the application program is configured to determine the function pointer of the program function corresponding to the predetermined function selection from a functions reference list stored in a digital data memory and, by means of the determined function pointer, to run the program function corresponding to the predetermined function selection for processing the data contained in the input and/or output signals.

