Dual-Processor Safety Architecture for Complex Sensor Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional safety processors in industrial safety systems lack the processing power to perform complex computations required for monitoring hazardous environments, making it difficult to meet stringent safety rating criteria, especially in dynamic and heterogeneous settings with unpredictable human and hazard interactions.

Innovation Solution

A dual-processor architecture combining a safety processor (SP) with a non-safety multi-processor computation module (MPCM) that allows for sophisticated processing and analysis of sensor data, enabling the system to generate safety-rated signals and meet safety requirements while performing complex operations beyond the scope of conventional safety-rated components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional safety processors are used, then safety certification can be obtained, but processing power is insufficient for complex computations

Engineering Contradiction:
Improvesafety certificationVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The system divides processing functions into two segments: a safety processor dedicated to safety-critical functions and certification compliance, and a separate compute processor for complex computations. This segmentation allows each processor to be optimized for its specific purpose while maintaining overall system safety through controlled communication interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A safety communication interface acts as an intermediary between the safety processor and compute processor. This intermediary enforces safety constraints on data exchange, ensuring that complex computations do not compromise safety guarantees while enabling the system to leverage powerful computation for advanced safety applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If deterministic algorithms are used, then safety response time is guaranteed, but flexibility in algorithm selection is limited

Engineering Contradiction:
Improvesafety response timeVSAvoidalgorithm flexibility
Core Design Contradiction:
Loss of timeVSAdaptability or versatility

Solution Approach 1:

The system segments algorithms into deterministic components executed by the safety processor for time-critical safety responses, and non-deterministic components executed by the compute processor for complex analysis. This allows the system to use flexible, sophisticated algorithms while guaranteeing deterministic safety response times through the safety processor's controlled execution.

Inventive Principle:
Principle #1Segmentation

3Reliability

If redundant safety circuits are used, then safety reliability is improved, but system complexity and cost increase

Engineering Contradiction:
Improvesafety reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system replaces traditional mechanical and electrical redundant safety circuits with a computational architecture using multiple processors and software-based safety mechanisms. This substitution reduces physical complexity while maintaining or improving safety reliability through more flexible and programmable safety logic.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11543798B2System architecture for safety applications
Publication Date: 2023.01.03 SYMBOTIC LLC
  • US11543798B2 patent drawing
  • US11543798B2 patent drawing
  • US11543798B2 patent drawing

AI summary

Control systems for industrial machinery (e.g., robots) or other devices such as medical devices utilize a safety processor (SP) designed for integration into safety applications and computational components that are not necessarily safety-rated. The SP monitors performance of the non-safety computational components, including latency checks and verification of identical outputs. One or more sensors send data to the non-safety computational components for sophisticated processing and analysis that the SP cannot not perform, but the results of this processing are sent to the SP, which then generates safety-rated signals to the machinery or device being controlled by the SP. As a result, the system may qualify for a safety rating despite the ability to perform complex operations beyond the scope of safety-rated components.