Monitoring Sensor Release Logic for Safety-Critical Machine Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems require manual visual inspection to release safety-critical machines after detecting risks, which is inefficient and may lead to erroneous reactivation due to malfunctions or operator unavailability.

Innovation Solution

A method and system that utilize monitoring sensors to detect risks, combine sensor signals with identifiers to form messages, and verify these messages using cryptographic signatures to ensure safe reactivation of safety-critical functions, including periodic updates to account for changing conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual visual inspection is required to release the machine after detecting a risk, then safety is maintained through human verification, but operational efficiency deteriorates due to prolonged downtime and operator unavailability

Engineering Contradiction:
ImprovesafetyVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs self-verification by automatically checking sensor signals and cryptographic messages to determine when the safety-critical area is clear, eliminating the need for manual operator inspection. The machine can autonomously transition from stopped state to operational state based on verified sensor data, thereby maintaining safety while improving operational efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual visual inspection process is replaced with an automated electronic verification system that uses sensor networks, cryptographic message authentication, and automated decision-making algorithms. This substitution of manual mechanical inspection with electronic automation resolves the contradiction by providing both safety verification and operational efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If the machine is released after a single risk detection and visual inspection, then operational efficiency improves, but safety deteriorates due to potential erroneous reactivation from sensor malfunctions or undetected risks

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsafety
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary verification by continuously monitoring sensor signals and validating cryptographic messages before allowing machine release. Multiple verification steps are executed in advance - including checking message authenticity, verifying risk absence, and confirming area clearance - before the machine transitions to operational state, thereby preventing erroneous reactivation while maintaining efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where sensor data is constantly monitored, cryptographic messages are validated, and machine state transitions are controlled based on verified information. This feedback mechanism ensures that safety is maintained through automated verification while enabling efficient operational recovery when risks are genuinely absent.

Inventive Principle:
Principle #23Feedback

3Reliability

If cryptographic verification and message authentication are implemented for machine release, then reliability of safety-critical function release improves, but device complexity increases

Engineering Contradiction:
Improverelease accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces cryptographic messages as intermediaries that carry authenticated information between the monitoring system and the machine control system. These messages serve as mediators that verify risk absence and authorize machine release without requiring direct complex interaction between monitoring components and control logic, thereby managing system complexity while maintaining high release accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If periodic sensor updates and chronological verification are performed, then safety against changing conditions improves, but loss of time in message processing increases

Engineering Contradiction:
ImprovesafetyVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic sensor updates and message transmissions at optimized intervals, balancing the need for current safety information with the time cost of processing. By updating sensors and validating messages periodically rather than continuously, the system maintains reliability for detecting changing conditions while minimizing unnecessary processing time and computational overhead.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP4487049B1Method and system for enabling a safety-critical function of a machine
Publication Date: 2025.11.19 TRUMPF WERKZEUGMASCHINEN GMBH & CO KG
  • EP4487049B1 patent drawingFigure 1
  • EP4487049B1 patent drawingFigure 2
  • EP4487049B1 patent drawingFigure 3

AI summary

The present invention relates to a method for enabling a safety-critical function of a machine (1), wherein a monitoring system (2) monitors a safety-critical area of the machine (1), wherein the monitoring system (2) comprises at least one monitoring sensor (3), wherein the safety-critical function is disabled if the monitoring system (2) detects a first risk in a signal (4) from the monitoring sensor (3), wherein a first signal (4) from the monitoring sensor (3) is combined with a first identifier at a first time (t1, t4) to produce a first message (6), wherein the first message (6) is sent by the monitoring system (2) to an enabling unit (7), wherein a second message (8) containing an enable signal and the first identifier is received by the monitoring system (2) at a second time (t5, t8), wherein the second message (8) is checked by the monitoring system (2), wherein the safety-critical function is enabled by the monitoring system (2) if the check on the second message (8) is successful.