Safety Controller Verification ID for Time-Limited Test Runs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a method to validate and verify safety control programs in industrial controllers that ensures compliance with safety standards, preventing the risk of inappropriate configuration jeopardizing human life and machine integrity, while allowing flexible software configuration.

Innovation Solution

An industrial controller with an interface for uploading and verifying safety control programs, using a verification ID (VID) to limit execution of unverified programs and indicate unverified run mode, with a timer to stop unverified program execution and a process for assigning a VID through computer-readable media instructions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a safety control program is configured using software editor program, then flexibility in configuration is improved, but the risk of inappropriate configuration compromising safety requirements increases

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidsafety compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a test run mode that executes the safety control program before final deployment to identify configuration errors in advance. This preliminary execution allows validation of safety logic, detection of programming mistakes, and verification of safety requirements compliance before the program is activated in the actual safety-critical system, thus resolving the contradiction between configuration flexibility and safety reliability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a newly configured safety control program is allowed to operate for testing, then performance validation is improved, but the risk of unverified program execution increases

Engineering Contradiction:
Improveperformance validationVSAvoidunverified program risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a dynamic operational state system where the safety control program can transition between different modes: test run mode for validation and active mode for operational use. The controller dynamically adjusts its behavior based on the validation status, allowing controlled testing when unverified while preventing unauthorized execution of potentially harmful unvalidated programs, thus balancing performance validation needs with safety risk mitigation.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If operation is limited to predetermined period for unverified programs, then safety risk is reduced, but the ability to validate performance is constrained

Engineering Contradiction:
Improvesafety riskVSAvoidvalidation time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent implements a periodic test run mechanism where unverified safety control programs are executed in controlled time-limited test cycles. The controller automatically manages test run durations, allowing sufficient time for comprehensive safety validation while enforcing periodic interruptions or termination to prevent excessive exposure to unverified code. This periodic action pattern ensures both adequate validation opportunity and safety risk containment.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3076291B1Method for assignment of verification numbers
Publication Date: 2022.05.25 ROCKWELL AUTOMATION GERMANY
  • EP3076291B1 patent drawingFigure 1
  • EP3076291B1 patent drawingFigure 2A~2C
  • EP3076291B1 patent drawingFigure 3A

AI summary

An industrial safety controller (100) is disclosed. The controller (100) comprises an interface (110) for downloading of a safety control program into a memory (120) and at least one processing unit (130) for executing a safety control program (122). The at least one processing unit (130) is configured to determine whether a safety control program (122) is verified and to limit an execution of an unverified safety control program according to an unverified run mode. An indicator (140) is configured to indicate the execution of an unverified safety control program. A method (300) of assigning a verification ID to an industrial controller comprises steps of configuring (320) and downloading (340) a safety control program, validating (360) the configured safety control program for the target industrial controller, and assigning (380) a verification ID. Execution of the configured safety control program is limited before the verification ID is assigned.