Dual Safety Controller Architecture for Complex Real-Time Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional fail-safe control systems face challenges in efficiently processing complex safety requirements in real-time, particularly in industrial automation, where dynamic processes demand more sophisticated safety solutions that balance performance and flexibility.
Innovation Solution
A control system comprising two safety-oriented control devices communicatively coupled via a safety-oriented communication link, where one device executes safety functions using coded processing and the other handles complex safety sub-functions using optimized processor units, implementing on-chip redundancy and secure communication to ensure high-performance and fail-safe operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If conventional coded processing is used for safety functions, then hardware redundancy is eliminated and solution consistency is provided, but processing performance for complex safety requirements deteriorates
Solution Approach 1:
The safety control system is segmented into multiple independent processor units, each capable of executing safety functions. This segmentation allows the system to distribute complex safety processing across multiple units, thereby maintaining high processing performance while eliminating the need for complete hardware redundancy of a single processor.
Solution Approach 2:
A communication interface acts as an intermediary between multiple processor units, enabling them to exchange safety-relevant data and coordinate their operations. This intermediary mechanism allows processed data from one unit to be verified by another, providing safety assurance without requiring identical hardware redundancy.
2Ease of manufacture
If lockstep processors with on-chip redundancy are used, then cost-effectiveness is improved, but processing flexibility for diverse safety requirements deteriorates
Solution Approach 1:
Each processor unit is designed with universal capabilities to execute various safety functions and programs. The processor units can be configured to handle different types of safety requirements through software programming, providing adaptability and versatility without requiring specialized hardware for each safety function.
Solution Approach 2:
The system allows dynamic configuration and parameter adjustment of processor units to adapt to different safety requirements. By changing operational parameters and software configurations rather than hardware architecture, the system maintains cost-effectiveness while achieving the needed flexibility for diverse safety applications.
3Reliability
If two processor units are used for non-coded execution, then safety requirements are met, but device complexity and costs increase
Solution Approach 1:
The system uses multiple processor units that execute and verify safety-relevant processed data against each other. Rather than requiring complete hardware redundancy with identical components, the system uses copied verification mechanisms where processed data is validated across multiple units, providing safety assurance with reduced overall complexity.
4Loss of time
If complex safety sub-functions are processed in real-time, then response time is improved, but processing resources are consumed
Solution Approach 1:
The system performs preliminary processing of safety data in parallel across multiple processor units before final verification is needed. By pre-processing safety-relevant data and having multiple units ready with processed results, the system achieves fast real-time response without consuming excessive resources during critical verification moments.
Data Source
AI summary
A method and control system for controlling an apparatus or system, wherein at least one safety function is provided with regard to the control of the apparatus or system, where the at least one safety function has at least one safety sub-function, the control system comprises a first safety-oriented controller and a second safety-oriented controller, the first safety-oriented controller and the second safety-oriented controller are communicatively coupled via a safety-oriented communication link, the first safety-oriented controller is configured to perform the at least one safety function, and the second safety-oriented controller function as a processor and is configured to perform the at least one safety sub-function using input data received via the safety-oriented communication link from the first safety-oriented controller.


