Safe Runtime Environment for SIL 3 Process Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing safety automation systems face challenges in achieving high safety integrity levels, particularly SIL 3, due to processor-dependent fault control measures that are impractical for complex processors, and require costly and complex coded processing methods like SCP, which increase runtime and code generation complexity.

Innovation Solution

An automation system that uses a safe runtime environment to execute user programs redundantly and diversitarily, independent of the platform, providing safe resources and encapsulating safety-critical requirements, allowing for standard components and reduced complexity, while achieving high safety integrity levels without focusing on individual component fail-safety.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If processor-dependent fault control measures are implemented to achieve SIL 3, then safety integrity level is improved, but device complexity and implementation cost increase significantly

Engineering Contradiction:
Improvesafety integrity levelVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system separates safety-critical functions into a dedicated safe runtime environment that runs independently on standard hardware. This segmentation allows the safety mechanism to be isolated from the complexity of the main processor, enabling SIL 3 certification without requiring the entire system to be redesigned with specialized safe processors.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A safe runtime environment acts as an intermediary layer between the user programs and the hardware platform. This intermediary provides the safety guarantees required for SIL 3 by managing resource access, enforcing safety protocols, and isolating critical functions, thereby avoiding the need to modify or certify the underlying standard hardware processors.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If coded processing methods like SCP are used to ensure processor-independent safety, then reliability is improved, but runtime and code generation complexity increase

Engineering Contradiction:
Improvefault control effectivenessVSAvoidruntime efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system uses standard, commercially available hardware platforms instead of expensive specialized safe processors. By combining these 'cheap' standard components with a software-based safe runtime environment, the system achieves SIL 3 reliability without the high costs and performance penalties of proprietary safe hardware, effectively replacing expensive long-lived specialized components with affordable standard components.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Device complexity

If standard CPUs are used instead of specialized safe processors, then device complexity and cost are reduced, but achieving SIL 3 requires additional complex safety mechanisms

Engineering Contradiction:
Improveprocessor complexityVSAvoidfail-safety guarantee
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system changes the approach from hardware-based safety parameters to software-based safety parameters. Instead of relying on specialized hardware features built into safe processors, the safe runtime environment implements safety through software mechanisms including resource management, access control, and isolated execution contexts, thereby achieving the same reliability goals through different parameter configurations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11846923B2Automation system for monitoring a safety-critical process
Publication Date: 2023.12.19 PILZ GMBH & CO KG
  • US11846923B2 patent drawing
  • US11846923B2 patent drawing
  • US11846923B2 patent drawing

AI summary

An automation system for monitoring a safety-critical process includes a platform, a fail-safe peripheral module, and a safe runtime environment. The platform executes user programs. The user programs include a first user program and a second user program, which together implement a safety function. The second user program is diversitary with respect to the first user program. The fail-safe peripheral module couples the user programs with the safety-critical process. The safe runtime environment is implemented on the platform independently of the user programs and provides the user programs with safe resources independent of the platform.