Secure Runtime Layer for Platform-Independent Safety Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current automation systems for safety-critical processes face challenges in achieving high diagnostic coverage and fail-safety without being processor-dependent, especially when using standard CPUs, which require complex and costly code generation and hardware-related background tests.

Innovation Solution

A safe automation system that employs a secure runtime environment to execute user programs independently of the platform, using a fail-safe peripheral assembly and two diverse user programs to implement safety functions, thereby encapsulating safety-critical features and providing secure resources that are platform-independent.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If standard CPUs are used in safety-critical automation systems, then hardware cost and flexibility are improved, but processor-dependent fault tolerance proof and diagnostic coverage become excessively complex and costly

Engineering Contradiction:
Improvehardware costVSAvoidfault tolerance proof complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent introduces a runtime environment as an intermediary layer between the standard CPU and the safety-critical application. This runtime environment provides platform-independent abstractions and manages safety-relevant resources, thereby decoupling the application from processor-specific details and eliminating the need for complex processor-dependent fault tolerance proofs while maintaining safety integrity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the automation system into distinct layers: a platform-independent safety application layer, a runtime environment layer, and a hardware layer. This segmentation allows each layer to be developed and verified independently, with the runtime environment handling processor-specific concerns and the safety application focusing on safety logic, thereby reducing overall system complexity

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If processor-independent safety concepts are implemented, then adaptability across different platforms is improved, but implementation complexity increases due to lack of hardware-specific optimizations

Engineering Contradiction:
Improveplatform independenceVSAvoidimplementation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The runtime environment serves as an intermediary that handles platform-specific adaptations and hardware interactions, allowing safety applications to remain processor-independent while still benefiting from hardware capabilities through standardized interfaces provided by the runtime environment

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If diverse architecture with redundant CPUs is used to achieve SIL 3, then safety integrity is improved, but system cost and complexity increase significantly

Engineering Contradiction:
Improvesafety integrityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses software-based redundancy through virtual machines that execute safety applications in isolated environments. Instead of requiring multiple physical redundant CPUs, the system creates virtual copies of the safety application in a runtime environment, achieving the necessary redundancy and fault tolerance through software virtualization while reducing hardware complexity

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3841438B1Automation system for monitoring a safety-critical process
Publication Date: 2023.02.15 PILZ GMBH & CO KG
  • EP3841438B1 patent drawingFigure 1
  • EP3841438B1 patent drawingFigure 2
  • EP3841438B1 patent drawingFigure 3

AI summary

The invention relates to an automation system (10) for monitoring a safety-critical process, comprising a platform (12) for carrying out user programs (24, 26) and comprising a fail-safe peripheral assembly (20), via which the safety-critical process can be coupled to the user programs (24, 26). A first user program and a second user program which is diverse redundant to the first user program together produce a safety function (28). The automation system (10) additionally has a secure run-time environment which is implemented on the platform (12) independently of the user programs (24, 26) and is additionally designed to provide the user programs (24, 26) with secure resources (30) that are independent of the platform (12).