Software Update Coordination for Time-Critical Control Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing software update processes for time-critical applications in transport or access-related apparatuses, such as elevators, require system downtime or compromise safety, due to the need for manual intervention and potential human errors.
Innovation Solution
A control device and method that conducts a hardware self-test, checks the result against predetermined criteria, and initiates a software update without completing a further hardware self-test if the criteria are met, ensuring compatibility and integrity, allowing for on-the-fly updates without interrupting the system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hardware self-test procedure is conducted before every software update, then system safety and reliability are improved, but update time and system downtime increase
Solution Approach 1:
The hardware self-test is performed in advance before the software update is applied, and the result is stored. This preliminary action allows the update process to skip redundant testing, reducing update time while maintaining safety verification through the pre-conducted self-test.
Solution Approach 2:
Instead of conducting a full hardware self-test during every update, the system uses a stored partial test result from previous operations. This partial action approach reduces the testing burden during updates while still ensuring adequate safety verification.
2Reliability
If manual software update procedures are used, then system safety can be verified, but labor intensity and human error risk increase
Solution Approach 1:
The system performs software updates automatically using stored hardware self-test results without requiring manual intervention. The control device autonomously verifies safety conditions and applies updates, eliminating human error risks and reducing labor intensity while maintaining safety verification through automated checks.
3Productivity
If software updates are performed during system operation, then system availability is improved, but risk of compromising safety increases
Solution Approach 1:
The hardware self-test is completed in advance before the software update is applied during operation. This preliminary safety verification ensures that the system can safely transition to new software without compromising safety integrity, while maintaining system availability throughout the update process.
Solution Approach 2:
The system uses feedback from stored hardware self-test results to determine whether it is safe to proceed with the software update. This feedback mechanism ensures that safety conditions are met before allowing updates during operation, maintaining both availability and safety integrity.
Data Source
AI summary
A control apparatus (120) including a control device (110); an update coordination device (111); and a memory; wherein, when the update coordination device (111) receives a new program version of a program to be updated in the control device (110), the update coordination device (111) is configured to instruct the control device (110) to conduct a hardware self-test procedure, the control device (110) is configured to conduct the hardware self-test procedure and to store a result of the hardware self-test procedure in the memory; the control device (110) is configured to check, when the update coordination device (111) initiates a software update of the program to be updated to the new program version, whether the result of the hardware self-test procedure fulfills predetermined criteria, wherein the new program version is installed and started at the control device (110) without conducting, or before completing, a further hardware self-test procedure when the check of the stored result of the hardware self-test procedure indicates that the result fulfills the predetermined criteria, when switching over to the new program version.


