Vital Bus Architecture with Safety Supervisor Module
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing control systems in safety-critical applications, such as nuclear power plants and aircraft, require rigorous and costly testing for component qualification, making retro-fitting of safety-related systems in existing equipment, like locomotives, prohibitively expensive and impractical for achieving high reliability and zero-man-crew operations.
Innovation Solution
A high integrity safety critical bus system with multiple redundant data communication buses and an independent safety supervisor module that applies logic rules to validate and restore data, allowing low-integrity equipment to be supervised for high-integrity operation without necessitating all components to be vital.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rigorous testing and certification of all components is implemented to achieve high reliability, then system safety and reliability are improved, but system cost and complexity increase significantly
Solution Approach 1:
The system divides components into two categories: vital components that require high integrity and rigorous testing, and non-vital components that can be legacy or low-integrity equipment. The safety supervisor module monitors and manages this segmentation, allowing only the necessary portion of the system to meet stringent safety requirements while permitting other components to remain simpler and less expensive.
Solution Approach 2:
An independent safety supervisor module is introduced as an intermediary between the control system and the equipment. This supervisor module validates data from multiple redundant buses and equipment sources, restoring validity when inconsistencies are detected. This intermediary allows low-integrity equipment to operate within a high-integrity system by providing the necessary validation and supervision layer.
2Reliability
If rigorous testing and certification of all components is implemented to achieve high reliability, then system safety is improved, but system cost increases prohibitively
Solution Approach 1:
The system divides components into two categories: vital components that require high integrity and rigorous testing, and non-vital components that can be legacy or low-integrity equipment. The safety supervisor module monitors and manages this segmentation, allowing only the necessary portion of the system to meet stringent safety requirements while permitting other components to remain simpler and less expensive.
Solution Approach 2:
The system permits the use of legacy equipment and low-integrity components in non-vital positions, replacing the need for expensive certified components in those locations. By concentrating safety supervision and validation functions in the independent safety supervisor module, the system allows cost-effective legacy equipment to be used throughout the system while maintaining overall high integrity through targeted supervision.
3Reliability
If all existing control equipment is replaced to achieve zero-man-crew operations, then operational safety is improved, but implementation cost becomes prohibitive
Solution Approach 1:
An independent safety supervisor module is introduced as an intermediary between the control system and the equipment. This supervisor module validates data from multiple redundant buses and equipment sources, restoring validity when inconsistencies are detected. This intermediary allows low-integrity equipment to operate within a high-integrity system by providing the necessary validation and supervision layer.
Solution Approach 2:
The system dynamically supervises and validates data from equipment with varying integrity levels. Rather than requiring all equipment to be statically high-integrity, the system adapts by continuously monitoring and validating data streams, restoring validity when inconsistencies are detected. This dynamic approach allows the system to achieve high operational safety while accommodating a mix of equipment integrity levels.
Data Source
AI summary
Methods and systems for a vital bus system for communicating data in a control system are provided. The system includes a plurality of data communication buses configured in a multiple redundant orientation and at least one safety supervisor module including a database including a plurality of logic rules. The logic rules are programmed to receive data from the plurality of data communication buses and to determine the validity of the received data from each bus using one or more of the plurality of the logic rules. If the received data is invalid, the logic rules are programmed to restore the validity of the data using one or more of the plurality of the logic rules. If the data can not be restored the logic rules are programmed to transmit an alert to the control system. Otherwise, the logic rules are programmed to transmit the validated data to an intended destination.


