Modular Safety Controller Verification Using Subconfiguration Checksums
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current verification methods for device configurations are complex and error-prone, requiring complete knowledge of the entire system, which makes them difficult to implement correctly and prone to errors.
Innovation Solution
A modular verification method that subdivides device configurations into partial configurations, allowing verification by different users with knowledge only of their respective partial configurations, using checksums to confirm integrity and security-relevant parameters, and employing access encryption for secure authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the entire device configuration is verified by selected persons with complete understanding of the entire configuration, then verification reliability is improved, but verification complexity and difficulty increase significantly
Solution Approach 1:
The patent divides the device configuration into multiple partial configurations (e.g., input unit configuration, output unit configuration, control unit configuration). Each partial configuration can be verified independently by different users who only need knowledge of their specific area, rather than requiring complete system knowledge. This segmentation reduces verification complexity while maintaining reliability through modular verification.
2Reliability
If the entire device configuration is verified by selected persons with complete understanding of the entire configuration, then verification reliability is improved, but ease of operation deteriorates
Solution Approach 1:
By segmenting the verification task into partial configurations, the patent enables different users to verify only their area of expertise. This makes verification easier to operate since users don't need comprehensive system knowledge, while still achieving reliable verification of the entire device through the combination of partial verifications.
Solution Approach 2:
The patent introduces checksums as intermediary verification values that automatically verify the consistency of parameters between partial configurations. This intermediary mechanism reduces the operational burden on users by providing automated verification of parameter consistency, making the verification process easier while maintaining reliability.
3Device complexity
If partial configurations are verified by different users with knowledge only of their respective partial configurations, then verification complexity is reduced, but verification reliability may deteriorate due to potential errors in parameter consistency
Solution Approach 1:
The patent introduces checksums as intermediary verification values that automatically verify the consistency of parameters between partial configurations. When a parameter is changed in one partial configuration, the corresponding checksum is updated and must match the checksum in the other partial configuration. This intermediary mechanism ensures verification reliability while allowing different users to verify partial configurations independently.
Solution Approach 2:
The patent implements a feedback mechanism where checksums provide immediate verification feedback on parameter consistency between partial configurations. If a parameter change causes checksum mismatch, the system provides feedback indicating the verification error, allowing users to correct the inconsistency. This feedback loop maintains verification reliability while keeping the process simple.
Data Source
Figure 1
Figure 2
AI summary
To ensure simple and secure verification of a device, in particular a safety controller, a method for verifying a device configuration, in particular a safety controller, is provided, comprising the steps of: dividing the device configuration into at least two sub-configurations to be verified; assigning the sub-configurations to at least one sub-configuration sequence, specifying a dependency for verifying the sub-configurations on each other; determining parameters of each sub-configuration, wherein the parameters are used to verify the respective sub-configurations; and calculating a unique checksum for each sub-configuration that reflects the verification of the sub-configurations.wherein, when verifying a subsequent subconfiguration in the subconfiguration sequence, the individual checksum of a preceding subconfiguration is recalculated, and if the individual checksums match, the verification of the preceding subconfiguration is confirmed, and wherein the configuration of the device is verified when, for each subconfiguration sequence (TF1, TF2), the last subconfiguration (T4) is verified.