Machine Safety Architecture Using Supervised Non-Safe Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing safety systems for machines, such as robots and automated guided vehicles, are limited by the computing power of sensor safe processing units, restricting the dynamic evaluation of measurement data and transmission of safety-related results to the machine control system.

Innovation Solution

A safety system utilizing a non-safe computing module to perform complex safety and self-diagnostic functions, with a safe diagnostic module supervising these functions to maintain safety standards, allowing for computationally intensive evaluations and error detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a safe computing module is used to perform safety functions, then safety standards are met, but computing power is limited

Engineering Contradiction:
Improvesafety function reliabilityVSAvoidcomputing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The system divides safety-related computations into two segments: complex safety functions are executed on a non-safe computing module with high computing power, while critical self-diagnosis functions are executed on a safe computing module. This segmentation allows the system to leverage the computing power of non-safe modules while maintaining safety through verification by safe modules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A safe I/O module acts as an intermediary between the non-safe computing module and the safe computing module. It receives control data from both modules, performs plausibility checks, and transmits data to the machine control system. This intermediary ensures that even if the non-safe module fails, safety is maintained through the safe module's verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If self-diagnosis functions are performed on a safe computing module, then safety is maintained, but complex safety functions cannot be executed

Engineering Contradiction:
Improvesafety monitoring capabilityVSAvoidsafety function complexity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments diagnostic functions into two categories: self-diagnosis functions (executed on non-safe modules) and supervision functions (executed on safe modules). The non-safe module performs computationally intensive self-diagnosis, while the safe module performs supervision and plausibility checks, allowing both complex functionality and safety monitoring to coexist.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The safe computing module receives control data and self-diagnosis results from the non-safe module, performs plausibility checks, and provides feedback by accepting or rejecting the control data. This feedback mechanism ensures that complex safety functions can be executed with appropriate safety verification.

Inventive Principle:
Principle #23Feedback

3Power

If a non-safe computing module is used, then computing power increases, but safety standards cannot be met

Engineering Contradiction:
Improvecomputing powerVSAvoidsafety standard compliance
Core Design Contradiction:
PowerVSReliability

Solution Approach 1:

The safe I/O module serves as an intermediary that bridges the non-safe computing module and the safety-critical machine control system. It performs plausibility checks on control data from both non-safe and safe modules, ensuring that safety standards are met even when using high-power non-safe computing hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Different parts of the system have different safety requirements. The non-safe computing module handles computationally intensive tasks where full safety certification is not required, while the safe I/O module and safe computing module handle safety-critical functions. This local differentiation of quality allows the system to meet safety standards overall while utilizing high-power components where appropriate.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If safety functions are executed on a non-safe module, then complex evaluations are possible, but error detection capability is reduced

Engineering Contradiction:
Improvesafety function capabilityVSAvoiderror detection capability
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

Error detection is segmented into two layers: self-diagnosis functions executed on the non-safe module detect local errors, while supervision functions executed on the safe module detect errors in the self-diagnosis results. This layered segmentation allows complex safety functions to be executed with multiple levels of error detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The safe computing module receives self-diagnosis results from the non-safe module and performs plausibility checks, providing feedback on whether the self-diagnosis results are acceptable. This feedback mechanism enhances error detection capability by adding a second layer of verification for complex safety functions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4478138B1Safety system for a machine and corresponding method
Publication Date: 2025.07.30 SICK AG
  • EP4478138B1 patent drawingFigure 1
  • EP4478138B1 patent drawingFigure 2
  • EP4478138B1 patent drawingFigure 3

AI summary

The invention relates to a safety system (18) for a machine, comprising at least one sensor (4) which generates sensor data. Furthermore, the safety system comprises a non-safety computing module (8) configured to perform at least one safety function (20) based on the sensor data and to perform at least one self-diagnostic function directed towards the safety function, as well as a safe diagnostic module (10) configured to check the at least one self-diagnostic function by means of a supervisor (16) implemented on the safe diagnostic module.