Monitoring Sensor Release Logic for Safety-Critical Machine Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems require manual visual inspection to release safety-critical machines after detecting risks, which is inefficient and may lead to erroneous reactivation due to malfunctions or operator unavailability.
Innovation Solution
A method and system that utilize monitoring sensors to detect risks, combine sensor signals with identifiers to form messages, and verify these messages using cryptographic signatures to ensure safe reactivation of safety-critical functions, including periodic updates to account for changing conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual visual inspection is required to release the machine after detecting a risk, then safety is maintained through human verification, but operational efficiency deteriorates due to prolonged downtime and operator unavailability
Solution Approach 1:
The system performs self-verification by automatically checking sensor signals and cryptographic messages to determine when the safety-critical area is clear, eliminating the need for manual operator inspection. The machine can autonomously transition from stopped state to operational state based on verified sensor data, thereby maintaining safety while improving operational efficiency.
Solution Approach 2:
The manual visual inspection process is replaced with an automated electronic verification system that uses sensor networks, cryptographic message authentication, and automated decision-making algorithms. This substitution of manual mechanical inspection with electronic automation resolves the contradiction by providing both safety verification and operational efficiency.
2Productivity
If the machine is released after a single risk detection and visual inspection, then operational efficiency improves, but safety deteriorates due to potential erroneous reactivation from sensor malfunctions or undetected risks
Solution Approach 1:
The system performs preliminary verification by continuously monitoring sensor signals and validating cryptographic messages before allowing machine release. Multiple verification steps are executed in advance - including checking message authenticity, verifying risk absence, and confirming area clearance - before the machine transitions to operational state, thereby preventing erroneous reactivation while maintaining efficiency.
Solution Approach 2:
The system implements continuous feedback loops where sensor data is constantly monitored, cryptographic messages are validated, and machine state transitions are controlled based on verified information. This feedback mechanism ensures that safety is maintained through automated verification while enabling efficient operational recovery when risks are genuinely absent.
3Reliability
If cryptographic verification and message authentication are implemented for machine release, then reliability of safety-critical function release improves, but device complexity increases
Solution Approach 1:
The patent introduces cryptographic messages as intermediaries that carry authenticated information between the monitoring system and the machine control system. These messages serve as mediators that verify risk absence and authorize machine release without requiring direct complex interaction between monitoring components and control logic, thereby managing system complexity while maintaining high release accuracy.
4Reliability
If periodic sensor updates and chronological verification are performed, then safety against changing conditions improves, but loss of time in message processing increases
Solution Approach 1:
The system implements periodic sensor updates and message transmissions at optimized intervals, balancing the need for current safety information with the time cost of processing. By updating sensors and validating messages periodically rather than continuously, the system maintains reliability for detecting changing conditions while minimizing unnecessary processing time and computational overhead.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a method for enabling a safety-critical function of a machine (1), wherein a monitoring system (2) monitors a safety-critical area of the machine (1), wherein the monitoring system (2) comprises at least one monitoring sensor (3), wherein the safety-critical function is disabled if the monitoring system (2) detects a first risk in a signal (4) from the monitoring sensor (3), wherein a first signal (4) from the monitoring sensor (3) is combined with a first identifier at a first time (t1, t4) to produce a first message (6), wherein the first message (6) is sent by the monitoring system (2) to an enabling unit (7), wherein a second message (8) containing an enable signal and the first identifier is received by the monitoring system (2) at a second time (t5, t8), wherein the second message (8) is checked by the monitoring system (2), wherein the safety-critical function is enabled by the monitoring system (2) if the check on the second message (8) is successful.