Protocol Converter Segmentation for Safety-Critical Network Interfacing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing automation systems face challenges in cost-effectively implementing safety-certified fieldbus protocols for secure message transmission across different networks, as they often require two-channel hardware or software solutions, which increase hardware and software costs.
Innovation Solution
A protocol converter with a single-channel interface and a two-channel security module that enables message conversion between different security communication protocols, allowing for integrated protocol conversion of both security-relevant and non-security-relevant messages, using a cost-effective microcontroller with minimal memory requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dual-channel hardware is used for safety-certified fieldbus protocols, then safety performance and reliability are improved, but hardware costs increase
Solution Approach 1:
The patent segments the protocol converter functionality into two distinct modules: a single-channel interface device for general message routing and a dual-channel security module specifically for safety-relevant message conversion. This segmentation allows the system to apply dual-channel processing only where safety certification is required, rather than throughout the entire hardware architecture, thereby reducing overall hardware costs while maintaining safety performance.
2Reliability
If dual-channel software is used for safety-certified fieldbus protocols, then safety performance is improved, but microprocessor power and memory requirements increase
Solution Approach 1:
The patent separates safety-critical software functions into a dedicated dual-channel security module that runs independently on the microprocessor, while non-safety functions execute in a single channel. This segmentation allows the microprocessor to allocate computational resources efficiently, running intensive dual-channel safety protocols only when needed, thereby reducing overall power consumption and memory requirements compared to a fully dual-channel software architecture.
3Ease of manufacture
If a single-channel protocol converter is used, then hardware and software costs are reduced, but safety performance for cross-network message transmission deteriorates
Solution Approach 1:
The patent applies local quality by making the security module dual-channel specifically for safety-relevant message conversion, while the rest of the protocol converter remains single-channel. This localized dual-channel implementation ensures that safety performance is maintained for critical communications without incurring the full costs of a completely dual-channel system, achieving an optimal balance between cost and safety performance.
4Reliability
If separate gateways are used for safety-relevant and non-safety-relevant messages, then safety performance is improved, but device complexity increases
Solution Approach 1:
The patent merges the safety gateway and non-safety gateway functionalities into a single integrated protocol converter device. The device contains both a single-channel interface device for non-safety message routing and a dual-channel security module for safety message conversion, allowing both types of communications to be handled by one unified system rather than requiring separate physical gateways, thereby reducing device complexity while maintaining safety performance.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An automation system has provision between a first network (10) and a second network (20) for a protocol converter (30) for converting security-relevant messages between the first and second networks (10, 20), which use different network protocols for message exchange. In the protocol converter (30), a single-channel filter module device connected to a single-channel interface device ascertains messages using a first security communication protocol from messages received by the interface device via the first network (10), and messages using a second security communication protocol from messages received via the second network (20). An at least two-channel security module connected to the filter module device then converts the messages using the first security communication protocol that have been ascertained by the filter module device into messages using the second security communication protocol, and the messages using the second security communication protocol that have been ascertained by the filter module device into messages using the first security communication protocol.