Dual Security Channels With License Validation for SIL Diagnostics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing safety systems for high SIL levels, particularly in low-demand applications, face challenges in detecting systematic failures that remain undetected for long periods, leading to potential unsafe operational states due to inadequate diagnostic methods.
Innovation Solution
A safety system with dual channels, each comprising a license key management unit, execution protection unit, execution monitoring unit, and secure processing unit, ensures that only authorized safety functions are executed and monitored, transitioning to a safe state if errors occur, with cryptographic hash functions for tamper-proof security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If hard-coded safety functions are used in traditional safety systems, then the system structure is simple and easy to implement, but the system cannot detect systematic failures that remain undetected for long periods, leading to inadequate diagnostic capability
Solution Approach 1:
The patent segments the safety system into multiple independent channels (first safety channel and second safety channel), each with its own execution monitor and diagnostic capabilities. This segmentation allows each channel to independently detect failures without being affected by systematic errors in other channels, thereby improving diagnostic capability while maintaining implementation simplicity through modular design.
Solution Approach 2:
The patent introduces an intermediary mechanism - the cross-channel comparison logic that compares execution results between independent safety channels. This intermediary layer detects systematic failures by identifying discrepancies between channels, enhancing diagnostic capability without complicating the core safety function implementation.
2Ease of operation
If traditional execution monitoring is used without license key management, then the system is easier to operate, but the system lacks protection against unauthorized or tampered safety functions, reducing security
Solution Approach 1:
The patent implements preliminary action by requiring license keys to be validated before safety functions are executed. The license key management unit verifies authenticity in advance, preventing unauthorized or tampered functions from being loaded or executed. This maintains operational simplicity through automated verification while ensuring security integrity through cryptographic validation.
3Adaptability or versatility
If safety functions are activated without license key validation, then the system is more adaptable to different applications, but the system becomes vulnerable to tampering and unauthorized modifications, compromising safety
Solution Approach 1:
The patent uses cryptographic hash functions to create immutable copies of license key data stored in read-only memory. These cryptographic copies serve as tamper-proof references that validate the authenticity of safety functions. The system maintains adaptability by allowing different licensed functions to be activated while preventing tampering through cryptographic verification of function integrity against stored hash values.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Security system (4) with a first security channel (5.1) for executing and managing security functions (6), wherein the first security channel (5.1) comprises a license key management unit (7) for licenses for security functions (6), and a first security memory (1.1) for security functions (6), wherein the first security channel (5.1) comprises a first execution protection unit (2.1) for security functions (6) and a first execution monitoring unit (3.1) for security functions (6) and a first secure processing unit (8.1) for outputting a security status.