Safety Program Evaluation System for Functional Safety Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing safety program evaluation methods lack a systematic approach to verify if safety programs for safety controllers operate as designed, particularly after the design phase, to ensure functional safety in manufacturing environments.

Innovation Solution

An evaluation system that includes a processing execution means to compute output signals based on input signals, a setting means to receive evaluation conditions, and determination means to compare actual output values with expected values, ensuring safety operations are maintained by assessing changes in input signals and output signals across different states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a safety program is designed for a safety controller, then the safety controller can execute safety operations, but there is no method to inspect or evaluate whether the designed program operates as intended

Engineering Contradiction:
Improvefunctional safety of safety programVSAvoidevaluation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing safety evaluations before the safety program is deployed to actual safety-critical operations. The evaluation system executes the safety program under test conditions, comparing actual outputs against expected outputs to verify correctness before real-world deployment, thereby preventing potential safety failures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating a virtual or simulated environment that replicates the safety controller's operation. Instead of testing on actual safety-critical hardware, the system copies the safety program's logic and executes it in a controlled evaluation environment, comparing results against predefined expected behaviors to verify safety functionality.

Inventive Principle:
Principle #26Copying

2Reliability

If comprehensive safety evaluation is performed to ensure functional safety, then reliability improves, but the complexity of the evaluation system increases

Engineering Contradiction:
Improvesafety operation correctnessVSAvoidevaluation system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the safety evaluation process into distinct modular components: input signal generation, program execution, output signal comparison, and evaluation result generation. Each component handles a specific aspect of the evaluation, making the overall system more manageable and easier to verify while maintaining comprehensive safety checking.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies universality by designing an evaluation system that can assess multiple different safety programs and various safety scenarios using a single unified framework. The system handles different input conditions, executes different safety program variants, and compares results against multiple expected output sets, providing versatile safety verification without requiring separate evaluation systems for each case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10545471B2Evaluation system, safety controller, computer readable storage medium, and evaluation method
Publication Date: 2020.01.28 OMRON CORP
  • US10545471B2 patent drawing
  • US10545471B2 patent drawing
  • US10545471B2 patent drawing

AI summary

An evaluation system includes: processing execution means for executing computation in accordance with a safety program; setting means for receiving an input signal of an evaluation target and an expected output value; first determination means for determining whether or not a first output value of an output signal decided by the processing execution means coincides with the expected output value based on reception of a change in the value of the input signal from a first input value to a second input value from an input device; second determination means for determining whether or not a second output value of an output signal decided by the processing execution means coincides with the first output value based on reception of returning of the value of the input signal from the second input value to the first input value from the input device; and output means for outputting determination results.