Sandboxed Runtime for Platform-Independent Safety Program Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Safety-related application programs in industrial plants are often platform-specific, making it difficult to switch between manufacturers and integrating new components is time-consuming and error-prone.

Innovation Solution

A platform-independent method for executing safety-related application programs using a sandboxed runtime environment that defines execution rules, allowing the program code to be executed across different processor architectures and operating systems, with features like lock-step CPUs and redundant execution to detect errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If platform-specific application programs are used, then safety-related control systems can be designed and executed according to manufacturer-specific standards, but switching between manufacturers becomes difficult and integration of new components is time-consuming and error-prone

Engineering Contradiction:
Improvesafety levelVSAvoidplatform independence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a sandboxed runtime environment as an intermediary layer between the platform-specific application program and the underlying hardware. This runtime environment acts as a mediator that translates platform-specific instructions into a unified execution model, enabling cross-platform compatibility while preserving safety guarantees. The sandbox provides a controlled execution context that isolates the application from platform-specific vulnerabilities and complexities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal runtime environment that can execute application programs written for different manufacturers' platforms. This single runtime infrastructure serves multiple functions: it provides sandboxing for safety, handles platform-specific optimizations, manages the execution context, and enables seamless switching between different controller manufacturers. The runtime environment becomes a multi-functional platform that eliminates the need for separate execution environments for each manufacturer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If manufacturer-specific controllers are used, then safety requirements can be met through dedicated hardware and firmware testing, but integrating components from different manufacturers increases complexity and time

Engineering Contradiction:
Improvesafety certificationVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the control system into distinct layers: the platform-specific hardware/firmware layer, the universal sandboxed runtime environment layer, and the application program layer. This segmentation allows safety-critical functions to be isolated in the runtime environment, which can be independently tested and certified. The segmentation separates concerns so that hardware changes in one manufacturer's system do not affect software components from other manufacturers, reducing integration complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The sandboxed runtime environment serves as an intermediary that standardizes the interface between hardware components and application programs. By routing all hardware access through this standardized intermediary layer with predefined rules and interfaces, the system achieves consistent behavior across different manufacturers' hardware while maintaining safety guarantees. This intermediary layer abstracts away the complexities of direct hardware access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If sandboxing with predefined rules and interfaces is implemented, then manipulation and errors are protected against, but execution environment complexity increases

Engineering Contradiction:
Improveerror detectionVSAvoidruntime environment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The sandboxed runtime environment implements self-service mechanisms where the execution rules and interfaces are automatically enforced by the runtime itself without requiring external monitoring or complex validation logic. The sandbox self-manages the execution context, automatically enforcing security policies and predefined interfaces. This self-service approach reduces the need for additional complexity in error detection and manipulation prevention mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4671978A1Method, system for processing data, computer program product and computer readable medium
Publication Date: 2025.12.31 SIEMENS AG
  • EP4671978A1 patent drawing
  • EP4671978A1 patent drawing
  • EP4671978A1 patent drawing

AI summary

The invention relates to a method, in particular a computer-based method, for executing a safety-related application program on a computer system, particularly in a platform-independent manner, comprising the following steps: - generating a program code (2) which contains safety-related instructions; - executing the program code (2) in a runtime environment (3), wherein the runtime environment (3) contains a sandbox (4) by which rules for the execution of the program code (2) are defined.