Machine Safety Architecture Using Supervised Non-Safe Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing safety systems for machines, such as robots and automated guided vehicles, are limited by the computing power of sensor safe processing units, restricting the dynamic evaluation of measurement data and transmission of safety-related results to the machine control system.
Innovation Solution
A safety system utilizing a non-safe computing module to perform complex safety and self-diagnostic functions, with a safe diagnostic module supervising these functions to maintain safety standards, allowing for computationally intensive evaluations and error detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a safe computing module is used to perform safety functions, then safety standards are met, but computing power is limited
Solution Approach 1:
The system divides safety-related computations into two segments: complex safety functions are executed on a non-safe computing module with high computing power, while critical self-diagnosis functions are executed on a safe computing module. This segmentation allows the system to leverage the computing power of non-safe modules while maintaining safety through verification by safe modules.
Solution Approach 2:
A safe I/O module acts as an intermediary between the non-safe computing module and the safe computing module. It receives control data from both modules, performs plausibility checks, and transmits data to the machine control system. This intermediary ensures that even if the non-safe module fails, safety is maintained through the safe module's verification.
2Reliability
If self-diagnosis functions are performed on a safe computing module, then safety is maintained, but complex safety functions cannot be executed
Solution Approach 1:
The system segments diagnostic functions into two categories: self-diagnosis functions (executed on non-safe modules) and supervision functions (executed on safe modules). The non-safe module performs computationally intensive self-diagnosis, while the safe module performs supervision and plausibility checks, allowing both complex functionality and safety monitoring to coexist.
Solution Approach 2:
The safe computing module receives control data and self-diagnosis results from the non-safe module, performs plausibility checks, and provides feedback by accepting or rejecting the control data. This feedback mechanism ensures that complex safety functions can be executed with appropriate safety verification.
3Power
If a non-safe computing module is used, then computing power increases, but safety standards cannot be met
Solution Approach 1:
The safe I/O module serves as an intermediary that bridges the non-safe computing module and the safety-critical machine control system. It performs plausibility checks on control data from both non-safe and safe modules, ensuring that safety standards are met even when using high-power non-safe computing hardware.
Solution Approach 2:
Different parts of the system have different safety requirements. The non-safe computing module handles computationally intensive tasks where full safety certification is not required, while the safe I/O module and safe computing module handle safety-critical functions. This local differentiation of quality allows the system to meet safety standards overall while utilizing high-power components where appropriate.
4Adaptability or versatility
If safety functions are executed on a non-safe module, then complex evaluations are possible, but error detection capability is reduced
Solution Approach 1:
Error detection is segmented into two layers: self-diagnosis functions executed on the non-safe module detect local errors, while supervision functions executed on the safe module detect errors in the self-diagnosis results. This layered segmentation allows complex safety functions to be executed with multiple levels of error detection.
Solution Approach 2:
The safe computing module receives self-diagnosis results from the non-safe module and performs plausibility checks, providing feedback on whether the self-diagnosis results are acceptable. This feedback mechanism enhances error detection capability by adding a second layer of verification for complex safety functions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a safety system (18) for a machine, comprising at least one sensor (4) which generates sensor data. Furthermore, the safety system comprises a non-safety computing module (8) configured to perform at least one safety function (20) based on the sensor data and to perform at least one self-diagnostic function directed towards the safety function, as well as a safe diagnostic module (10) configured to check the at least one self-diagnostic function by means of a supervisor (16) implemented on the safe diagnostic module.