External Platform Interface Data Filter for Safety-Critical Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data processing systems in safety-critical environments, such as military systems, face challenges in effectively separating and handling safety critical and non-safety critical data due to the complexity of software interactions and the risk of data corruption from environmental upsets, leading to high certification costs and potential system failures.

Innovation Solution

An integrated subsystem with smart filter logic in an external platform interface monitors designated sub-addresses and transfers safety critical data directly to a safety critical interface, while blocking non-safety critical data from interacting with the local subsystem processor, using a non-reconfigurable ASIC or FPGA to ensure fixed configurations and reduce certification requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If external computer and software are used for filtering logic, then data processing flexibility is improved, but certification difficulty and cost increase

Engineering Contradiction:
Improvedata processing flexibilityVSAvoidcertification complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments data processing into two distinct paths: a safety-critical path handled by dedicated hardware filter logic and a non-critical path handled by software. This segmentation allows the hardware filter to be certified once and reused, reducing overall certification complexity while maintaining flexibility through software for non-critical operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary hardware filter logic component that sits between the data source and the processor. This intermediary performs the critical filtering function in hardware, isolating the safety-critical path from software complexity and making certification more manageable while still allowing software to handle non-critical data processing flexibly.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If software interactions are used for data handling, then processing adaptability is improved, but data corruption risk from environmental upsets increases

Engineering Contradiction:
Improveprocessing adaptabilityVSAvoiddata corruption risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system separates data handling into hardware-based safety-critical processing and software-based non-critical processing. The hardware segment handles safety-critical data with fixed, radiation-hardened logic that is immune to environmental upsets, while the software segment handles non-critical data where adaptability is needed but corruption risk is acceptable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces software-based filtering logic with hardware-based filter logic for safety-critical data paths. This substitution eliminates the vulnerability of software to environmental upsets (radiation, noise) while maintaining processing adaptability through the hardware's fixed deterministic behavior and separate software path for non-critical operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If extensive testing is performed for safety critical data handling, then system reliability is improved, but certification cost increases

Engineering Contradiction:
Improvesafety critical data handling reliabilityVSAvoidcertification cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a dedicated hardware copy of the filtering logic that is specifically designed for safety-critical data paths. This hardware copy can be certified once and then reused across multiple applications, reducing the overall certification cost compared to extensively testing and certifying software for each application.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system changes the fundamental parameter of how filtering is implemented - from software-based to hardware-based. This parameter change enables the use of radiation-hardened logic and fixed configurations that require less extensive testing and certification, thereby reducing certification costs while maintaining or improving reliability for safety-critical operations.

Inventive Principle:
Principle #35Parameter changes

4Device complexity

If fixed configuration hardware is used, then certification requirements are reduced, but processing flexibility decreases

Engineering Contradiction:
Improvecertification requirementsVSAvoidprocessing flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system segments processing flexibility needs into hardware and software portions. The hardware segment provides fixed, easily certifiable logic for safety-critical filtering, while the software segment provides flexibility for non-critical operations, configuration, and adaptation. This segmentation allows the overall system to achieve both reduced certification requirements and maintained processing flexibility.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8984205B2Data filter
Publication Date: 2015.03.17 RAYTHEON CO
  • US8984205B2 patent drawing
  • US8984205B2 patent drawing
  • US8984205B2 patent drawing

AI summary

A system includes an interface with a plurality of sub-addresses. The interface receives critical data and non-critical data. The critical data are received only at more specific sub-addresses of the interface. The interface transfers the critical data received at the sub-addresses to a critical processor, such that the critical data avoids being received by or being processed by a non-critical processor. The interface transfers the non-critical data from the interface to the non-critical processor. The configuration of the interface is hard-coded such that the configuration of the interface is fixed at power up of the interface and is non-changeable by the non-critical processor. The interface includes an external platform interface that is external to the critical processor, the non-critical processor, and a local controller. The external platform interface includes a limited ability to store the critical and non-critical data.