Safety Controller Program Checksum Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Safety controllers for automated installations require frequent re-approval from supervisory authorities for changes to user programs, especially when diagnosis instructions are updated, leading to increased time and cost due to the need for comprehensive verification, which restricts flexibility in programming and development.
Innovation Solution
A method and apparatus for generating user programs that ignore diagnosis instructions when determining checksums, allowing changes to diagnosis instructions without affecting the safety-related checksum, thus avoiding the need for re-approval and enhancing flexibility in programming safety controllers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If diagnosis instructions are updated in the user program, then the diagnostic capability is improved, but re-approval from supervisory authority is required which increases time and cost
Solution Approach 1:
The patent segments the user program into safety-related code and non-safety-related code (diagnosis instructions). The checksum is calculated only for the safety-related code, allowing the diagnosis instructions to be modified independently without affecting the safety verification status. This segmentation enables updates to diagnostic capabilities without triggering re-approval requirements.
Solution Approach 2:
The patent extracts the diagnosis instructions from the safety-critical portion of the program. By placing diagnosis instructions in a separate, non-safety-related section that is excluded from checksum calculation, the system allows these instructions to be updated without impacting the safety verification, thereby avoiding re-approval processes.
2Adaptability or versatility
If diagnosis instructions are updated in the user program, then the diagnostic capability is improved, but the cost of re-approval process increases
Solution Approach 1:
The patent segments the user program into safety-related code and non-safety-related code (diagnosis instructions). The checksum is calculated only for the safety-related code, allowing the diagnosis instructions to be modified independently without affecting the safety verification status. This segmentation enables updates to diagnostic capabilities without triggering re-approval processes.
Solution Approach 2:
The patent extracts the diagnosis instructions from the safety-critical portion of the program. By placing diagnosis instructions in a separate, non-safety-related section that is excluded from checksum calculation, the system allows these instructions to be updated without impacting the safety verification, thereby avoiding re-approval processes.
3Reliability
If comprehensive verification is performed for any program change, then safety is ensured, but flexibility in programming is restricted
Solution Approach 1:
The patent segments the user program into safety-related code and non-safety-related code (diagnosis instructions). The checksum is calculated only for the safety-related code, allowing the diagnosis instructions to be modified independently without affecting the safety verification status. This segmentation enables updates to diagnostic capabilities without triggering re-approval processes.
Solution Approach 2:
The patent applies different verification requirements to different parts of the program. Safety-related code undergoes comprehensive verification with checksum calculation, while diagnosis instructions are excluded from this process. This local differentiation of quality requirements maintains safety where needed while enabling flexibility in non-critical areas.
Data Source
AI summary
A safety controller designed to control an automated installation having a plurality of sensors and a plurality of actuators. A method for generating a user program for the safety controller comprises the step of generating a source code having a number of control instructions for controlling the actuators and having a number of diagnosis instructions for producing diagnosis reports. Safety-related program variables are processed in failsafe fashion during execution of the control instructions. A machine code is generated on the basis of the source code. At least one checksum is determined for at least some of the machine code. The diagnosis instructions are ignored for the determination of the checksum.


