Dual-Core Security System for Emergency Shutdown
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In electrical systems, particularly those requiring SIL4 level reliability, there is a risk of undetected system failures and failure to trigger emergency shutdowns due to defects in controlling microprocessors, necessitating a more reliable method for securing electronic systems controlling critical components like train brakes and platform doors.
Innovation Solution
A dual-core security system with two calculation programs in each core, capable of performing identical operations, compares results to detect anomalies and implements emergency shutdowns, ensuring redundancy and reliability by iteratively checking static elements and clock offsets to prevent faulty operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single control microprocessor is used to manage secure components, then the device complexity is reduced, but the reliability deteriorates due to undetected system failures and inability to trigger emergency shutdowns
Solution Approach 1:
The patent applies local quality by differentiating the roles of the two cores: one core (primary) handles normal control operations while the other core (secondary) performs verification and safety monitoring. This functional differentiation ensures that safety-critical functions have higher reliability without requiring the entire system to be overly complex
Solution Approach 2:
The patent introduces an intermediary mechanism where the secondary core acts as a mediator that verifies the correctness of the primary core's operations through checksum validation and clock synchronization monitoring. This intermediary layer detects anomalies without directly interfering with normal operations, resolving the contradiction between reliability and complexity
2Reliability
If redundancy is increased by adding multiple cores and verification programs, then the reliability improves, but the device complexity increases
Solution Approach 1:
The patent segments the security system into distinct functional modules: two calculation programs per core, separate verification mechanisms (checksum comparison, clock offset monitoring), and dedicated emergency shutdown logic. This segmentation allows each component to be simple and well-defined while achieving high overall reliability through their coordinated operation
Solution Approach 2:
The patent implements partial verification by performing checksum comparisons and clock synchronization checks only on critical safety functions rather than all system operations. This partial action approach provides sufficient reliability for emergency shutdown functions without the excessive complexity of verifying every system component
3Reliability
If continuous monitoring and verification are performed, then the reliability improves, but the productivity deteriorates due to iterative checking operations
Solution Approach 1:
The patent implements periodic verification through iterative loops that check checksums and clock offsets at regular intervals rather than continuously. The system performs verification operations in periodic cycles, allowing normal operations to proceed at full speed while reliability is maintained through rhythmic monitoring and validation
Solution Approach 2:
The patent applies preliminary anti-action by pre-calculating checksum values and storing them for comparison. The system prepares verification data in advance and performs quick comparisons during operation, preventing the need for complex real-time calculations that would reduce productivity while maintaining system integrity
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a method for emergency shutdown of a safety component of a safety assembly. The method, executed by a safety system comprising two cores and two identical programs per core, comprises: - a first step of performing operations resulting in a first result on each of the two programs of the first core, - a first step of comparing the first two results, an anomaly of the first core being detected if the first two results differ, - a first step of deducing the state of the safety system, - a second step of performing operations on the two second programs of the second core resulting in a second result on each of the two programs of the first core, - a second step of comparing the two second results, an anomaly of the second core being detected if the two second results differ, - a second step of deducing the state of the system (4).The first and second steps are iterated until any anomaly is detected.