Automation Firmware Modules for Incremental Safety-Critical Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing automation devices require complete rechecking and re-approval by authorities for even minor changes or additions, leading to significant financial and logistical burdens, especially in safety-critical applications, due to the need for replacing the entire firmware.

Innovation Solution

The automation device separates program functions from the application program, storing them in a digital program memory with unique function pointers, allowing for dynamic calling and updating without affecting the entire firmware, enabling incremental upgrades and additions without re-approval of the entire system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the entire firmware is replaced to add new sensors, actuators or improve the application program, then new functionalities can be implemented, but the entire automation system must be rechecked and approved by an auditing agency or examining authority, creating enormous financial consequences

Engineering Contradiction:
Improveability to add new sensors, actuators or improve application programVSAvoidcomplexity of rechecking and re-approval process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the firmware into a stable kernel portion and replaceable module portions. The kernel contains core system functions that remain unchanged, while modules can be independently added, removed, or updated. This segmentation allows new functionalities to be implemented through module replacement without requiring changes to the certified kernel, thus avoiding comprehensive re-approval while maintaining system adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts specific functional components into separate replaceable modules that can be independently managed. By taking out these modules from the monolithic firmware structure, the system enables selective updates of only the necessary components without affecting the certified core system, thereby eliminating the need for complete system re-approval.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If the entire firmware is replaced to implement changes, then new program features and support for new sensors and actuators can be provided, but the service life and operational continuity of the automation system are disrupted

Engineering Contradiction:
Improveability to implement new program features and supportVSAvoidservice life and operational continuity
Core Design Contradiction:
Adaptability or versatilityVSDuration of action of stationary object

Solution Approach 1:

The patent implements a dynamic firmware architecture where modules can be loaded, unloaded, and replaced during system operation without requiring a complete firmware replacement. This dynamic approach allows the system to adapt to new requirements while maintaining continuous operation, thus preserving service life and operational continuity while enabling new functionalities.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent prepares replacement modules in advance and validates them independently before integration. This preliminary action ensures that module updates can be performed with minimal disruption to ongoing operations, maintaining service continuity while enabling timely implementation of new features and support.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If safety-critical applications use complete firmware replacement for system improvements, then new functionalities are achieved, but the obligation to have the entire system rechecked and approved creates significant financial burden

Engineering Contradiction:
Improveability to improve automation systemVSAvoidsafety certification and approval requirements
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the firmware into a certified kernel and uncertified modules. The kernel maintains safety-critical functions with established certification, while modules handle non-critical or adaptable functionalities. This segmentation allows system improvements through module replacement without triggering comprehensive re-certification, thus reducing financial burden while maintaining safety standards.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality and certification requirements to different parts of the system. Safety-critical kernel functions maintain strict certification standards, while replaceable modules have flexible quality requirements appropriate to their specific functions. This local quality approach enables system improvements without requiring uniform re-certification of the entire system.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10983491B2Automation device and method for operating an automation device
Publication Date: 2021.04.20 WAGO VERW GMBH
  • US10983491B2 patent drawing
  • US10983491B2 patent drawing

AI summary

An automation device, having an input for receiving input signals and/or an output for outputting output signals of a process, and an electronic data processing unit, which is adapted to run an application program during operation of the automation device and to process data contained in the input and/or output signals by means of a program function, characterized in that in a digital program memory, a plurality of program functions is stored separately to the application program, which are each uniquely addressable via a function pointer, wherein during operation of the automation device, based on a predetermined function selection, the application program is configured to determine the function pointer of the program function corresponding to the predetermined function selection from a functions reference list stored in a digital data memory and, by means of the determined function pointer, to run the program function corresponding to the predetermined function selection for processing the data contained in the input and/or output signals.