Graphic Interface Command Verification for Safety-Critical Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current command control systems in critical environments, such as avionics, face challenges in maintaining high operating safety levels when using graphic interfaces, particularly due to the risk of incorrect or untimely commands leading to hazardous or catastrophic events, and existing physical control devices are limited by ergonomics, complexity, and cost.
Innovation Solution
A control system comprising multiple computing modules that acquire and verify interaction data from a graphic interface, ensuring compatibility with operational contexts to generate confirmation signals, thereby consolidating command signals for safe system operation, with redundancy for high availability and safety.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical control devices are used, then operating safety is maintained, but ergonomics and device complexity worsen
Solution Approach 1:
The control system is divided into multiple independent control subsystems (first control subsystem, second control subsystem, third control subsystem), each handling specific aspects of command processing. This segmentation allows the system to maintain high safety through distributed verification while providing a simplified unified graphic interface to the operator, resolving the contradiction between safety and ergonomics.
Solution Approach 2:
The invention introduces an intermediary verification mechanism where the second control subsystem acts as a mediator between the operator's command input (first subsystem) and the final execution (third subsystem). This intermediary layer verifies command compatibility with operational context, ensuring safety while allowing the operator to interact through a simplified graphic interface.
2Reliability
If physical control devices are used, then operating safety is maintained, but device complexity and cost increase
Solution Approach 1:
The invention replaces physical mechanical control devices with a software-based graphic interface system. The control subsystems are implemented as computing modules that process commands digitally, eliminating the need for physical buttons, switches, and rotator controls. This substitution reduces device complexity and cost while maintaining safety through software-based verification mechanisms.
3Ease of operation
If virtualization of control devices is implemented, then ergonomics improve, but operating safety deteriorates
Solution Approach 1:
The second control subsystem performs preliminary verification of commands before they are executed. It checks command compatibility with the operational context in advance, preventing incorrect or untimely commands from reaching the execution stage. This preliminary action ensures that virtualized graphic interface commands maintain the same safety level as physical devices.
Solution Approach 2:
The system implements a feedback mechanism where the second control subsystem verifies commands and provides confirmation to the third subsystem. This feedback loop ensures that only compatible commands are executed, maintaining operating safety while allowing the benefits of virtualized graphic interface for ergonomics.
4Reliability
If multiple control subsystems are implemented, then operating safety improves, but system complexity increases
Solution Approach 1:
Each control subsystem is designed with multi-functionality to reduce overall system complexity. The second control subsystem, for example, performs multiple functions including acquiring command signals, verifying compatibility with operational context, and generating confirmation signals. This universal design approach allows the multiple subsystems to work together efficiently without proportionally increasing system complexity.
Data Source
AI summary
This control subsystem comprises a first control subsystem comprising a first computing module able to acquire interaction data describing the interactions of the operator, associate these interaction data with a command, and generate a command signal corresponding to this command. The system further comprises a second control subsystem comprising a first computing module able to acquire the command signal, verify the compatibility of the command corresponding to the command signal with an operational context and, when the command is compatible with the operational context, generate a confirmation signal, and a third control subsystem able to acquire the command signal and the confirmation signal, and consolidate these signals to command the commanded system.


