Safety-Critical Architecture Mapping for Flexible Redundancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional safety critical systems face challenges in efficiently managing and maintaining safety standards due to over-implementation or degradation when design principles like redundancy, diversity, separation, and isolation are assigned to individual equipment rather than functional task categories, leading to inflexibility and increased costs in system maintenance and refitting.

Innovation Solution

A computerized monitoring system that stores equipment information in a database with task categories associated with safety functions and design principles, allowing processors to determine technical constraints for compensating failure effects by applying design principles like redundancy, diversity, separation, and isolation at a system level, rather than equipment level, thereby enabling more flexible and efficient implementation and maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If design principles like redundancy, diversity, separation, and isolation are assigned to individual equipment, then safety conditions are met at component level, but system flexibility and efficiency deteriorate due to excessive duplication and rigid replacement constraints

Engineering Contradiction:
Improvesafety conditionVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the safety management approach by introducing task categories that group multiple equipment items under common safety functions. Instead of treating each equipment item independently with its own safety conditions, the system divides safety management into hierarchical levels: task categories (e.g., reactor protection, core cooling) contain multiple equipment items, allowing safety principles to be applied at the functional level rather than individual component level. This enables more flexible system configuration while maintaining safety requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universality by allowing a single equipment item to serve multiple task categories simultaneously. An equipment item can be associated with multiple task categories, meaning one piece of equipment can contribute to multiple safety functions. This multi-functionality reduces the need for excessive duplication of equipment while ensuring that safety conditions are met across all relevant functional areas.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If design principles are assigned to individual equipment, then component-level safety is ensured, but system complexity and management difficulty increase

Engineering Contradiction:
Improvecomponent safetyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent reduces system complexity by segmenting safety management into task categories that group equipment by function. Instead of managing safety conditions for each individual equipment item separately, the system organizes equipment into logical groups (task categories) such as reactor protection, core cooling, and safe shut-down. This hierarchical organization simplifies the management of safety conditions while maintaining component-level safety assurance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple equipment items under common task categories to reduce management complexity. By combining the management of multiple equipment items into unified task categories with shared safety conditions, the system reduces the overall number of independent safety management entities. This merging approach maintains component-level safety while simplifying system-wide management.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If equipment replacement is constrained to resemble the replaced part, then safety conditions are maintained, but maintenance cost and time increase

Engineering Contradiction:
Improvesafety condition maintenanceVSAvoidmaintenance efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables more flexible equipment replacement by allowing equipment items to fulfill multiple task categories. When an equipment item is replaced, the system can identify other equipment that can assume the failed equipment's task category responsibilities, especially if the failed equipment was serving multiple functions. This universality reduces the need for exact like-for-like replacements, enabling the use of alternative equipment that may be more readily available, cost-effective, or modernized, thereby improving maintenance efficiency without compromising safety conditions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If redundancy is implemented at equipment level, then fault tolerance is improved, but energy consumption and resource usage increase

Engineering Contradiction:
Improvefault toleranceVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent optimizes redundancy implementation by segmenting it at the task category level rather than requiring redundancy for every individual equipment item. The system identifies which task categories require redundant capabilities and ensures that redundancy is provided at that functional level. This allows the system to eliminate unnecessary equipment-level redundancy while maintaining fault tolerance through task-category-level redundancy, thereby reducing energy consumption and resource usage associated with excessive duplication.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3251121B1Safety critical system
Publication Date: 2023.07.05 FORTUM OYJ
  • EP3251121B1 patent drawingFigure 1
  • EP3251121B1 patent drawingFigure 2
  • EP3251121B1 patent drawingFigure 3

AI summary

According to an example embodiment of the present invention, there is provided a method, comprising defining (510) a task category information element, the task category information element being associated with at least one functional requirement and at least one design principle, associating (520) the task category information element with at least one architecture definition information element, associating (530) each of the at least one architecture definition information element with at least one system-level information element, and verifying (540) the system described by the at least one architecture definition information element and associated system-level information elements is compliant with the at least one design principle.