Safety Controller Program Checksum Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Safety controllers for automated installations require frequent re-approval from supervisory authorities for changes to user programs, especially when diagnosis instructions are updated, leading to increased time and cost due to the need for comprehensive verification, which restricts flexibility in programming and development.

Innovation Solution

A method and apparatus for generating user programs that ignore diagnosis instructions when determining checksums, allowing changes to diagnosis instructions without affecting the safety-related checksum, thus avoiding the need for re-approval and enhancing flexibility in programming safety controllers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If diagnosis instructions are updated in the user program, then the diagnostic capability is improved, but re-approval from supervisory authority is required which increases time and cost

Engineering Contradiction:
Improvediagnostic capabilityVSAvoidre-approval time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent segments the user program into safety-related code and non-safety-related code (diagnosis instructions). The checksum is calculated only for the safety-related code, allowing the diagnosis instructions to be modified independently without affecting the safety verification status. This segmentation enables updates to diagnostic capabilities without triggering re-approval requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the diagnosis instructions from the safety-critical portion of the program. By placing diagnosis instructions in a separate, non-safety-related section that is excluded from checksum calculation, the system allows these instructions to be updated without impacting the safety verification, thereby avoiding re-approval processes.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If diagnosis instructions are updated in the user program, then the diagnostic capability is improved, but the cost of re-approval process increases

Engineering Contradiction:
Improvediagnostic capabilityVSAvoidprogramming cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent segments the user program into safety-related code and non-safety-related code (diagnosis instructions). The checksum is calculated only for the safety-related code, allowing the diagnosis instructions to be modified independently without affecting the safety verification status. This segmentation enables updates to diagnostic capabilities without triggering re-approval processes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the diagnosis instructions from the safety-critical portion of the program. By placing diagnosis instructions in a separate, non-safety-related section that is excluded from checksum calculation, the system allows these instructions to be updated without impacting the safety verification, thereby avoiding re-approval processes.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If comprehensive verification is performed for any program change, then safety is ensured, but flexibility in programming is restricted

Engineering Contradiction:
ImprovesafetyVSAvoidprogramming flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the user program into safety-related code and non-safety-related code (diagnosis instructions). The checksum is calculated only for the safety-related code, allowing the diagnosis instructions to be modified independently without affecting the safety verification status. This segmentation enables updates to diagnostic capabilities without triggering re-approval processes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different verification requirements to different parts of the program. Safety-related code undergoes comprehensive verification with checksum calculation, while diagnosis instructions are excluded from this process. This local differentiation of quality requirements maintains safety where needed while enabling flexibility in non-critical areas.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8910131B2Method and apparatus for generating an application program for a safety-related control unit
Publication Date: 2014.12.09 PILZ GMBH & CO KG
  • US8910131B2 patent drawing
  • US8910131B2 patent drawing
  • US8910131B2 patent drawing

AI summary

A safety controller designed to control an automated installation having a plurality of sensors and a plurality of actuators. A method for generating a user program for the safety controller comprises the step of generating a source code having a number of control instructions for controlling the actuators and having a number of diagnosis instructions for producing diagnosis reports. Safety-related program variables are processed in failsafe fashion during execution of the control instructions. A machine code is generated on the basis of the source code. At least one checksum is determined for at least some of the machine code. The diagnosis instructions are ignored for the determination of the checksum.