Vital Bus Architecture with Safety Supervisor Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing control systems in safety-critical applications, such as nuclear power plants and aircraft, require rigorous and costly testing for component qualification, making retro-fitting of safety-related systems in existing equipment, like locomotives, prohibitively expensive and impractical for achieving high reliability and zero-man-crew operations.

Innovation Solution

A high integrity safety critical bus system with multiple redundant data communication buses and an independent safety supervisor module that applies logic rules to validate and restore data, allowing low-integrity equipment to be supervised for high-integrity operation without necessitating all components to be vital.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rigorous testing and certification of all components is implemented to achieve high reliability, then system safety and reliability are improved, but system cost and complexity increase significantly

Engineering Contradiction:
Improvesystem safetyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides components into two categories: vital components that require high integrity and rigorous testing, and non-vital components that can be legacy or low-integrity equipment. The safety supervisor module monitors and manages this segmentation, allowing only the necessary portion of the system to meet stringent safety requirements while permitting other components to remain simpler and less expensive.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An independent safety supervisor module is introduced as an intermediary between the control system and the equipment. This supervisor module validates data from multiple redundant buses and equipment sources, restoring validity when inconsistencies are detected. This intermediary allows low-integrity equipment to operate within a high-integrity system by providing the necessary validation and supervision layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If rigorous testing and certification of all components is implemented to achieve high reliability, then system safety is improved, but system cost increases prohibitively

Engineering Contradiction:
Improvesystem safetyVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system divides components into two categories: vital components that require high integrity and rigorous testing, and non-vital components that can be legacy or low-integrity equipment. The safety supervisor module monitors and manages this segmentation, allowing only the necessary portion of the system to meet stringent safety requirements while permitting other components to remain simpler and less expensive.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system permits the use of legacy equipment and low-integrity components in non-vital positions, replacing the need for expensive certified components in those locations. By concentrating safety supervision and validation functions in the independent safety supervisor module, the system allows cost-effective legacy equipment to be used throughout the system while maintaining overall high integrity through targeted supervision.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If all existing control equipment is replaced to achieve zero-man-crew operations, then operational safety is improved, but implementation cost becomes prohibitive

Engineering Contradiction:
Improveoperational safetyVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

An independent safety supervisor module is introduced as an intermediary between the control system and the equipment. This supervisor module validates data from multiple redundant buses and equipment sources, restoring validity when inconsistencies are detected. This intermediary allows low-integrity equipment to operate within a high-integrity system by providing the necessary validation and supervision layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically supervises and validates data from equipment with varying integrity levels. Rather than requiring all equipment to be statically high-integrity, the system adapts by continuously monitoring and validating data streams, restoring validity when inconsistencies are detected. This dynamic approach allows the system to achieve high operational safety while accommodating a mix of equipment integrity levels.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8260487B2Methods and systems for vital bus architecture
Publication Date: 2012.09.04 WESTINGHOUSE AIR BRAKE TECH CORP
  • US8260487B2 patent drawing
  • US8260487B2 patent drawing
  • US8260487B2 patent drawing

AI summary

Methods and systems for a vital bus system for communicating data in a control system are provided. The system includes a plurality of data communication buses configured in a multiple redundant orientation and at least one safety supervisor module including a database including a plurality of logic rules. The logic rules are programmed to receive data from the plurality of data communication buses and to determine the validity of the received data from each bus using one or more of the plurality of the logic rules. If the received data is invalid, the logic rules are programmed to restore the validity of the data using one or more of the plurality of the logic rules. If the data can not be restored the logic rules are programmed to transmit an alert to the control system. Otherwise, the logic rules are programmed to transmit the validated data to an intended destination.