Burner Controller Timing Validation for Safety
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Modbus protocol does not meet safety standards for data transfer in fuel burner systems, particularly under varying conditions, and lacks immunity against device malfunctions, posing safety risks.
Innovation Solution
A controller with a communication module, processing module, and timing module manages message exchanges between burner system devices, identifies issues, and locks out non-operational devices or units that violate timing requirements, ensuring safety control by monitoring message integrity and timing compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Modbus protocol is used for communication between burner system devices, then ease of operation and device compatibility are improved, but safety reliability deteriorates due to lack of immunity against device malfunctions
Solution Approach 1:
The system applies preliminary anti-action by implementing preemptive safety measures through timing requirements and message validation rules before malfunctions can cause harm. The controller proactively monitors communication patterns, validates message integrity, and enforces timing constraints to prevent unsafe operations rather than merely reacting to failures after they occur.
Solution Approach 2:
The controller acts as an intermediary between communicating devices, mediating all message exchanges to ensure safety compliance. It validates messages against timing requirements, checks for proper formatting and sequencing, and controls the communication flow to prevent unsafe interactions while maintaining the ease of use benefits of the Modbus protocol.
2Reliability
If comprehensive message monitoring and validation is implemented, then safety reliability is improved, but device complexity increases
Solution Approach 1:
The system implements preliminary action by pre-defining timing requirements, message formats, and validation rules before runtime communication occurs. These safety parameters are established in advance, allowing the controller to efficiently validate messages against predetermined criteria rather than performing complex real-time analysis, thus improving safety while managing complexity.
Solution Approach 2:
The system manages complexity by parameterizing safety requirements through configurable timing values and message validation thresholds. These parameters can be adjusted to match specific application needs, allowing the same communication management framework to adapt to different safety levels and device configurations without requiring complete system redesign.
3Reliability
If timing requirements are enforced for message exchanges, then safety reliability is improved, but loss of time increases due to validation overhead
Solution Approach 1:
The system applies partial action by implementing selective validation based on message types and communication contexts. Not all messages require the same level of validation scrutiny - the system applies appropriate validation depth based on the specific message content and safety criticality, reducing unnecessary validation overhead while maintaining safety for critical communications.
Solution Approach 2:
The system uses periodic action by implementing time-based validation intervals and timeout mechanisms. Messages are validated at predetermined time intervals, and the system periodically checks compliance with timing requirements. This periodic approach ensures safety monitoring without continuous overhead, allowing efficient time management while maintaining reliable safety control.
Data Source
AI summary
A controller for managing communication of a burner system. The controller may comprise a communication module to manage the exchange of messages between devices of the burner system. The controller may also incorporate a processing module to compose the messages that are exchanged between the devices, identify issues regarding the messages, determine that devices may not be operating properly, and lock-out the devices in response. The controller may also incorporate a timing module having a set of timing requirements and being configured to lock-out devices in response to violation of a timing requirement.


