Safety-Critical Function Enabling With Verified Sensor Messaging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for enabling safety-critical functions in machines require manual visual inspection after detection of risks, necessitating human presence and lacking efficient communication protocols for ensuring accurate and secure re-enablement.
Innovation Solution
A method involving a monitoring system with sensors that detects risks, combines sensor signals with identifiers to form messages, and verifies enabling signals from an enabling unit to securely and automatically re-enable safety-critical functions, using cryptographic signatures and timestamps to ensure chronological order and authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual visual inspection is used to enable safety-critical functions, then human presence is required for verification, but this increases the complexity of the enabling process and requires human intervention
Solution Approach 1:
The patent replaces manual visual inspection with an automated image recognition system using sensors and computing units. The monitoring system captures images, processes them through algorithms to detect risks, and automatically generates enabling signals without requiring human presence in the safety-critical region, thus substituting mechanical human inspection with an automated electronic system
Solution Approach 2:
The monitoring system performs self-verification by automatically analyzing sensor data, detecting risks, and generating enabling signals based on predefined criteria. The system serves itself by autonomously completing the verification process that previously required human intervention, reducing the need for external human input while maintaining safety standards
2Ease of operation
If sensor signals are transmitted without cryptographic verification, then the enabling process is simpler, but this allows incorrect enabling due to malfunctions or temporal inconsistencies
Solution Approach 1:
The patent implements a feedback mechanism where the monitoring system sends sensor signals with timestamps to a remote enabling unit, which verifies the signals against chronological order and cryptographic signatures before sending enabling commands back. This closed-loop feedback ensures that only valid, time-ordered signals trigger enabling actions, preventing incorrect activation while maintaining operational simplicity through automated verification
Solution Approach 2:
The system performs preliminary cryptographic signing and timestamping of sensor signals before transmission. The monitoring system prepares the data with verification mechanisms in advance, so that when signals reach the enabling unit, they are already authenticated and ready for chronological verification, reducing the computational burden during the actual enabling process while ensuring reliability
3Ease of operation
If remote enabling is implemented without cryptographic signatures, then the system is easier to operate, but this compromises the authenticity and security of enabling signals
Solution Approach 1:
The patent introduces cryptographic signatures and timestamps as intermediary verification elements between the monitoring system and enabling unit. These intermediaries act as trusted mediators that authenticate the origin and timing of signals without requiring complex human verification procedures, enabling secure remote operation while maintaining signal authenticity through automated cryptographic validation
Data Source
AI summary
A method for enabling a safety-critical function of a machine includes monitoring a safety-critical region of the machine using a monitoring system. The monitoring system includes at least one monitoring sensor. The method further includes blocking the safety-critical function upon detecting by the monitoring system a first risk in a first signal of the monitoring sensor, combining the first signal of the monitoring sensor at a first point in time with a first identifier to form a first message, sending the first message by the monitoring system to an enabling unit, receiving by the monitoring system from the enabling unit, at a second point in time, a second message with an enabling signal and the first identifier, verifying the second message by the monitoring system, and enabling the safety-critical function by the monitoring system if the verification of the second message is successful.


