Safety Code Determination for Mixed SIL Automation Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automation networks with subscribers having different safety integrity levels face safety-related issues due to data traffic problems, where a subscriber with a low safety integrity level can generate valid data packets for a higher level subscriber, leading to potential misdirection and compliance issues, and require reconfiguration when expanding, complicating address allocation.

Innovation Solution

Implementing different safety code determination methods for each subscriber group based on their safety integrity level, using distinct safety code generator polynomials to ensure reliable data transmission and prevent misdirection, allowing for independent data traffic management and address allocation without affecting safety.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single safety code determination method is used for all subscribers in the automation network, then the network structure is simple and address allocation is easy, but data transmission between subscribers with different safety integrity levels becomes unsafe and reliable misdirection detection is not possible

Engineering Contradiction:
Improvesafety of data transmissionVSAvoidcomplexity of safety code determination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The automation network is segmented into multiple safety groups based on safety integrity levels (SIL). Each safety group uses its own dedicated safety code determination method with unique safety codes. This segmentation ensures that data transmission within each group maintains the required safety integrity level while preventing unsafe interactions between groups with different SIL levels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different safety code determination methods are applied locally to different safety groups according to their specific safety integrity level requirements. Each group has tailored safety codes and determination methods suited to its SIL level, rather than using a uniform approach across the entire network. This local customization ensures optimal safety for each group while managing overall system complexity.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If subscribers with different safety integrity levels are allowed to communicate freely in the automation network, then network versatility and ease of operation are improved, but safety compliance cannot be ensured and misdirection detection becomes unreliable

Engineering Contradiction:
Improveability to mix different SIL levelsVSAvoidcompliance with safety integrity levels
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network is divided into separate safety groups corresponding to different SIL levels (e.g., SIL1, SIL2, SIL3, SIL4). Each group operates with its own safety code determination method, allowing subscribers of different SIL levels to coexist in the same physical network while maintaining logical separation. This enables versatile network composition without compromising safety compliance within each group.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Safety codes act as intermediaries that mediate data transmission between subscribers of different SIL levels. The master subscriber uses the appropriate safety code determination method based on the target safety group, ensuring that data transmission maintains the required safety integrity level while enabling communication across different SIL levels.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the automation network is configured to maintain strict safety integrity levels for all subscribers, then safety compliance is ensured, but network expansion becomes complex and requires reconfiguration

Engineering Contradiction:
Improvesafety integrity level complianceVSAvoidease of network expansion
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The network is organized into independent safety groups that can be expanded independently. When new subscribers are added, they are assigned to appropriate existing safety groups or new groups are created without requiring reconfiguration of other groups. This modular approach maintains safety integrity level compliance while simplifying network expansion.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The master subscriber is designed with universal capability to handle multiple safety code determination methods corresponding to different SIL levels. This allows the master subscriber to communicate with any safety group using the appropriate method, enabling network expansion without requiring specialized hardware or software for each SIL level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If different safety code determination methods are implemented for different safety groups, then reliable misdirection detection is achieved and safety compliance is ensured, but the system complexity increases

Engineering Contradiction:
Improvemisdirection detection capabilityVSAvoidcomplexity of safety code management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each safety group self-identifies its SIL level and uses the corresponding safety code determination method automatically. The master subscriber automatically selects the appropriate safety code based on the target safety group without requiring manual configuration or complex decision logic. This self-service approach reduces overall system complexity while maintaining reliable misdirection detection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Safety codes and determination methods are pre-configured for each safety group based on their SIL level. When data transmission is initiated, the appropriate safety code is already in place and ready for use, eliminating the need for runtime decisions about which safety method to apply. This preliminary preparation simplifies the operational complexity of managing multiple safety code determination methods.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10732594B2Method for operating safety control in an automation network, and automation network having such safety control allowing mixed safety integrity levels
Publication Date: 2020.08.04 BECKHOFF AUTOMATION GMBH
  • US10732594B2 patent drawing
  • US10732594B2 patent drawing
  • US10732594B2 patent drawing

AI summary

A method operates a safety control in an automation network having a master subscriber which carries out the safety control, at least one first slave subscriber which is assigned a first safety integrity level, and at least one second slave subscriber which is assigned a second safety integrity level. The first safety integrity level and the second safety integrity level differ from each other. A first safety code determination method is assigned to the first slave subscriber and a second safety code determination method is assigned to the second slave subscriber. The first safety code determination method and the second safety code determination method differ from each other. The master subscriber and the first slave subscriber use the first safety code determination method for interchanging a safety data block. The master subscriber and the second slave subscriber use the second safety code determination method for interchanging a safety data block.