Dual-Processor Safety Architecture for Complex Sensor Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional safety processors in industrial safety systems lack the processing power to perform complex computations required for monitoring hazardous environments, making it difficult to meet stringent safety rating criteria, especially in dynamic and heterogeneous settings with unpredictable human and hazard interactions.
Innovation Solution
A dual-processor architecture combining a safety processor (SP) with a non-safety multi-processor computation module (MPCM) that allows for sophisticated processing and analysis of sensor data, enabling the system to generate safety-rated signals and meet safety requirements while performing complex operations beyond the scope of conventional safety-rated components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional safety processors are used, then safety certification can be obtained, but processing power is insufficient for complex computations
Solution Approach 1:
The system divides processing functions into two segments: a safety processor dedicated to safety-critical functions and certification compliance, and a separate compute processor for complex computations. This segmentation allows each processor to be optimized for its specific purpose while maintaining overall system safety through controlled communication interfaces.
Solution Approach 2:
A safety communication interface acts as an intermediary between the safety processor and compute processor. This intermediary enforces safety constraints on data exchange, ensuring that complex computations do not compromise safety guarantees while enabling the system to leverage powerful computation for advanced safety applications.
2Loss of time
If deterministic algorithms are used, then safety response time is guaranteed, but flexibility in algorithm selection is limited
Solution Approach 1:
The system segments algorithms into deterministic components executed by the safety processor for time-critical safety responses, and non-deterministic components executed by the compute processor for complex analysis. This allows the system to use flexible, sophisticated algorithms while guaranteeing deterministic safety response times through the safety processor's controlled execution.
3Reliability
If redundant safety circuits are used, then safety reliability is improved, but system complexity and cost increase
Solution Approach 1:
The system replaces traditional mechanical and electrical redundant safety circuits with a computational architecture using multiple processors and software-based safety mechanisms. This substitution reduces physical complexity while maintaining or improving safety reliability through more flexible and programmable safety logic.
Data Source
AI summary
Control systems for industrial machinery (e.g., robots) or other devices such as medical devices utilize a safety processor (SP) designed for integration into safety applications and computational components that are not necessarily safety-rated. The SP monitors performance of the non-safety computational components, including latency checks and verification of identical outputs. One or more sensors send data to the non-safety computational components for sophisticated processing and analysis that the SP cannot not perform, but the results of this processing are sent to the SP, which then generates safety-rated signals to the machinery or device being controlled by the SP. As a result, the system may qualify for a safety rating despite the ability to perform complex operations beyond the scope of safety-rated components.


