Redundant Processor Safe State Preservation via Non-Volatile Memory Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic safety-relevant systems for railway signalling equipment face challenges in automatically restoring safety-relevant activity after a failure without human intervention, and risk unauthorized termination of the safe state due to hardware or software limitations, leading to reduced reliability and increased costs.

Innovation Solution

The method involves storing safety-relevant information in non-volatile memory, rewriting it to volatile memory for processing, and encrypting it with authentication, ensuring that only authorized redundant processor parts can restore the safe state, preventing unauthorized use and enabling automatic restoration after power return.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If safety-relevant information is stored in volatile operating memory for quick access, then processing speed is improved, but the safe state cannot be preserved after power loss or system re-initialisation

Engineering Contradiction:
Improveprocessing speedVSAvoidsafe state preservation
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The invention applies preliminary action by storing safety-relevant information in non-volatile memory before any failure or power loss occurs. This pre-stored information ensures that when the system restarts after power loss or re-initialisation, the safe state can be immediately restored without requiring rapid processing of external data, thus resolving the contradiction between processing speed and safe state preservation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If safety-relevant information is stored in non-volatile memory for persistent storage, then safe state preservation is improved, but processing speed deteriorates due to memory access time

Engineering Contradiction:
Improvesafe state preservationVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs preliminary action by pre-loading safety-relevant information from non-volatile memory into volatile operating memory during normal operation. This allows the system to maintain fast processing speeds using volatile memory while ensuring that non-volatile memory contains the authoritative copy for safe state preservation, thus resolving the speed-reliability contradiction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention uses volatile operating memory as an intermediary between non-volatile memory and the processing units. Safety-relevant information is transferred from non-volatile memory to volatile memory for rapid processing, while the non-volatile memory serves as the persistent storage medium. This intermediary approach allows the system to benefit from both the speed of volatile memory and the persistence of non-volatile memory.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hardware resources are used to terminate safety-relevant activity, then transition to safe state is reliable, but automatic restoration after failure is not possible without human intervention

Engineering Contradiction:
Improvesafe state transitionVSAvoidautomatic restoration
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The invention applies self-service by enabling the system to automatically restore safety-relevant activity after a failure without requiring human intervention. The redundant processor part that remains operational automatically detects the failure, transfers control to itself, and restores the safe state using the pre-stored safety-relevant information in its non-volatile memory, thus achieving both reliable safe state transition and automatic restoration.

Inventive Principle:
Principle #25Self-service

4Extent of automation

If software resources are used to terminate safety-relevant activity, then automatic restoration is possible, but the risk of unauthorized termination of safe state increases

Engineering Contradiction:
Improveautomatic restorationVSAvoidsafe state protection
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The invention applies segmentation by dividing the processor into multiple redundant processor parts with distinct roles. One processor part is designated as the primary processor for normal operation, while another is designated as a standby processor with safety-relevant information pre-stored in its non-volatile memory. This segmentation ensures that only the authorized standby processor can initiate safe state transition, preventing unauthorized termination while enabling automatic restoration through the standby processor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention uses the non-volatile memory in the standby processor as an intermediary that stores authenticated safety-relevant information. This intermediary mechanism ensures that only the authorized standby processor with the correct pre-stored information can initiate safe state transition, preventing unauthorized termination while enabling automatic restoration. The non-volatile memory acts as a trusted intermediary that validates the authority to terminate or restore the safe state.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP1979815B1Method of preserving the safe state of a redundant processor after occurence of a failure
Publication Date: 2010.05.19 AZD PRAHA SRO

AI summary

The invention concerns the method of retention a safe state after a failure of electronic safety- relevant equipment and systems, in which processor technology with the use of principles of composite fail-safety is used in order to ensure a safety- relevant activity. This safe state is preserved after a failure so that the safety-relevant information that is necessary for performing the safety-relevant activity of the redundant processor part of the electronic safety-relevant equipment is transferred from the non-volatile memory to the volatile operating memory of the redundant processor part of the electronic safety- relevant equipment after initiating the activity and corrupted from the given non- volatile memory. When the redundant processor part of the electronic safety-relevant equipment transits to a safe state after a failure the appropriate safety-relevant information stored in the volatile operating memory is encrypted, which ensures that it is no longer possible to restore this safety-relevant information, thus continuing in the safety-relevant activity, even in the event that the redundant processor part of the electronic safety-relevant equipment is re-initialised.