Industrial Safety Program Updates with Sandbox Compatibility Checks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for updating security programs in industrial systems pose a risk of compromising safety, as they do not adequately assess the compatibility and safety of update information before application.

Innovation Solution

An industrial system with a sensor, actuator, and update device that evaluates update information through a sandbox procedure, automated acceptance tests, and digital signatures to ensure safety before applying updates to the security program.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If update information is applied directly to the security program without evaluation, then update speed is improved, but safety reliability deteriorates

Engineering Contradiction:
Improveupdate speedVSAvoidsafety reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by evaluating update information in a sandbox environment before applying it to the live security program. The update is first tested in a virtualized sandbox system that mimics the production environment, allowing validation of safety and functionality before deployment. This preliminary testing phase resolves the contradiction by ensuring safety reliability is maintained while enabling rapid updates through automated evaluation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The sandbox environment serves as an intermediary between the update information and the live security program. This intermediate testing layer allows updates to be evaluated without directly impacting the running safety-critical system. The sandbox acts as a buffer that enables fast updates while protecting the reliability of the actual security program through isolated testing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive safety checks are performed before applying updates, then safety reliability is improved, but update time increases

Engineering Contradiction:
Improvesafety reliabilityVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a copy of the security program environment in the form of a sandbox - a virtualized replica that mirrors the production system. This copy allows comprehensive safety checks to be performed on update information without affecting the live system. By testing on the copied environment, the patent achieves thorough safety validation while minimizing impact on update timing, as the sandbox evaluation can run in parallel or be rapidly executed.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

Comprehensive safety checks are performed as preliminary actions in the sandbox environment before updates are applied to the live system. The evaluation process includes checking update information against safety requirements, testing in the virtualized environment, and validating compatibility. These preliminary checks ensure safety reliability is improved while the automated nature of the process minimizes time loss.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the system is stopped to apply security updates, then safety reliability is improved, but productivity deteriorates

Engineering Contradiction:
Improvesafety reliabilityVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The sandbox evaluation performs all necessary safety checks and validations as preliminary actions before the update is applied to the running system. This ensures that when the update is deployed to the live security program, it has already been verified for safety, maintaining reliability without requiring system shutdown. The preliminary validation in the sandbox enables continuous operation during the evaluation phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic update application where the security program can be updated while the industrial system continues to operate. The sandbox environment allows the update to be prepared and validated dynamically, and the actual application can be performed with minimal or no disruption to system availability. This dynamic approach maintains both safety reliability and productivity by allowing updates during normal operation.

Inventive Principle:
Principle #15Dynamics

4Reliability

If a sandbox environment is used for testing updates, then safety reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesafety reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The sandbox serves as an intermediary layer that adds safety validation capability without fundamentally altering the core security program or industrial control system. This intermediate virtualized environment provides comprehensive safety testing while maintaining a clear separation from the live system, thus improving reliability with controlled complexity addition.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The sandbox environment is designed as a universal testing platform that can evaluate multiple types of updates across different security programs and configurations. This multi-functional sandbox reduces the need for separate testing infrastructures for each update scenario, thereby improving safety reliability while managing device complexity through a consolidated testing environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4703823A1Industrial systems and methods for updating a security program
Publication Date: 2026.03.04 SICK AG
  • EP4703823A1 patent drawingFigure 1
  • EP4703823A1 patent drawingFigure 2
  • EP4703823A1 patent drawingFigure 3

AI summary

An industrial system comprises: a sensor and/or an actuator; a safety device configured to execute a safety program to control the sensor and/or the actuator; and an update device configured to: receive update information; evaluate the update information; based on the evaluation, determine whether the update information can be applied to the safety program; and based on the determination, either apply the update information to the safety program or discard the update information.