Dual Safety Controller Architecture for Fast Fail-Safe Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing safety control systems face challenges in efficiently and reliably processing complex safety functions with high performance while ensuring error-free operation and compliance with safety standards like IEC 61508 and ISO 10218, particularly in applications requiring dynamic monitoring and flexible production.

Innovation Solution

A dual-controller system is employed, where a first safety device handles less complex tasks using coded processing and a second safety device, optimized for complex tasks, executes safety sub-functions with hardware redundancy and uncoded methods, ensuring secure communication between them via protocols like PROFIsafe.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If coded processing is used to meet safety requirements, then safety reliability is improved, but processing performance and cycle time are reduced

Engineering Contradiction:
Improvesafety reliabilityVSAvoidprocessing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The control system is divided into two distinct control devices: a first safety control device that handles standard safety functions using coded processing, and a second safety control device that handles complex safety sub-functions using uncoded processing. This segmentation allows each device to be optimized for its specific function, maintaining safety reliability while improving overall processing performance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Complex safety sub-functions that require high processing performance are extracted from the first safety control device and assigned to the second safety control device. This extraction allows the complex functions to be processed using uncoded methods, which provide better performance, while the first device continues to ensure safety through coded processing of other functions.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If hardware redundancy is implemented to ensure safety, then safety reliability is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesafety reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system replaces traditional hardware redundancy with a dual-controller software architecture. Instead of using redundant hardware components, the invention uses two control devices with different processing modes (coded and uncoded) that work together to provide safety, thereby reducing hardware complexity while maintaining safety reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the processing parameter from coded to uncoded for specific safety sub-functions. By allowing uncoded processing in the second control device for complex functions, the system achieves better performance without requiring additional hardware redundancy, thus reducing overall device complexity.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If uncoded processing is used for complex safety sub-functions, then processing performance is improved, but safety verification becomes more difficult

Engineering Contradiction:
Improveprocessing performanceVSAvoidsafety verification difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The first safety control device acts as an intermediary that verifies the safety of uncoded processing performed by the second control device. The second device executes uncoded processing for complex functions, while the first device monitors and validates the results, ensuring safety requirements are met without compromising processing performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the first safety control device receives and validates output from the second control device. This feedback loop ensures that uncoded processing results are verified against safety requirements, making safety verification manageable despite the use of uncoded processing.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4462201B1Control system and method for controlling a device or plant
Publication Date: 2026.04.01 SIEMENS AG
  • EP4462201B1 patent drawingFigure 1~2
  • EP4462201B1 patent drawingFigure 3~4

AI summary

The invention relates to a control system (C) for controlling a device or system, wherein at least one safety function (F) is provided for the control of the device or system, wherein the at least one safety function has at least one safety sub-function (F'), wherein the control system comprises a first safety-oriented control device (F-PLC) and a second safety-oriented control device (F-CP), wherein the first safety-oriented control device and the second safety-oriented control device are communicatively coupled via a safety-oriented communication link (P), wherein the first safety-oriented control device is designed and configured to execute the at least one safety function.wherein the second safety-related control device is based on a processor unit and is designed and configured to execute the at least one safety sub-function using input data received from the first safety-related control device via the safety-related communication link. The invention further relates to an associated method for controlling a device or system.