Bidirectional Connection Identification for Functional Safety
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for functionally safe communication in industrial settings, such as PROFIsafe, are limited to unidirectional connections and require pre-planned address relationships, making them inadequate for flexible and dynamic communication scenarios like those in Industry 4.0, where bidirectional communication is necessary and communication partners may change frequently.
Innovation Solution
A method that uses a computation rule to generate and verify unique identifiers for bidirectional connections, allowing for functionally safe data interchange by mapping consumer IDs to provider IDs and using these identifiers to protect both unidirectional connections, enabling flexible and safe communication in systems like OPC UA with TCP/IP or time-sensitive networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-planned address relationships are used for functionally safe communication, then data integrity and authenticity are guaranteed, but adaptability to dynamic communication scenarios is lost
Solution Approach 1:
The patent applies dynamics by enabling runtime generation and verification of authenticity codes for bidirectional connections. Instead of static pre-planned address relationships, the system dynamically creates connection-specific authenticity codes during operation, allowing the communication system to adapt to changing partners while maintaining safety. The code generation occurs at connection establishment time rather than during system configuration.
Solution Approach 2:
The patent changes the parameter of connection identification from fixed pre-planned addresses to dynamically generated authenticity codes. This parameter change allows the system to maintain functional safety through cryptographic verification while adapting to dynamic communication scenarios. The authenticity code becomes a runtime parameter rather than a configuration-time constant.
2Ease of operation
If unidirectional connections with pre-assigned authenticity codes are used, then connection identification is simple, but bidirectional communication flexibility is limited
Solution Approach 1:
The patent segments the bidirectional communication into two unidirectional connections, each with its own authenticity code verification. This segmentation allows each direction to be independently verified while maintaining overall bidirectional safety. The first connection uses one authenticity code generation rule, and the second connection uses another rule, enabling flexible partner changes in both directions.
Solution Approach 2:
The patent makes the authenticity code assignment dynamic by generating codes at runtime based on the actual connection partners. Instead of static pre-assigned codes for all possible connections, the system generates appropriate codes when connections are established, enabling flexible bidirectional communication while maintaining simple verification procedures.
3Reliability
If all potential communication partners are pre-configured with unique authenticity codes, then functional safety is ensured, but system complexity increases with n·(n−1) connections
Solution Approach 1:
The patent applies universality by using a single computation rule that can generate authenticity codes for any connection pair. Instead of maintaining separate pre-configured codes for each of the n·(n−1) potential connections, the system uses one universal rule that works for all possible bidirectional connections, dramatically reducing configuration complexity while maintaining functional safety.
Solution Approach 2:
The patent enables self-service by allowing the system to automatically generate and verify authenticity codes without manual pre-configuration. The computation rules are applied automatically during connection establishment, and the system self- verifies the codes without requiring external configuration management. This eliminates the need for manual setup of numerous authenticity codes.
Data Source
AI summary
Apparatus and method for functionally securely transfer data in a two-sided data exchange of safety-related data between two communication partners (A, B), wherein a mapping is defined, which assigns to a consumer ID a provider ID of the same end point in the case of each bidirectional connection, and the mapping is made known to the two end points a priori, where the mapping could consist of the one's complement or alternatively of the two's complement, and wherein the connection between the data provider and the data consumer is established as described, the data consumer receives the address identification of the data provider via an additional side channel, for example, and after the connection has been established, the identification of the data provider can be securely checked.


