Redundant Watchdog for Safety Controller Clock Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial safety systems with single clock source CPUs lack a method to independently verify the accuracy of their clock sources, which can lead to inaccurate safety reaction times, potentially compromising operator safety due to drift in quartz-based oscillators used for clock generation.
Innovation Solution
A dual-CPU safety device configuration where each CPU has a single clock source, with a communication link and integrated circuit to receive fault indicator signals, synchronize processors, and validate Coordinate System Time (CST) messages to ensure accurate clock source verification, disabling I/O communications if the CST is outside predetermined values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single clock source is used in each CPU to reduce device complexity and cost, then device complexity is reduced, but clock source accuracy cannot be independently verified leading to potential safety reaction time drift
Solution Approach 1:
The patent introduces a safety partner controller as an intermediary system that independently verifies the clock source accuracy of the primary safety controller. The partner controller receives timestamped safety I/O messages from the primary controller, compares the timestamps against its own independently generated timestamps, and validates whether the time difference falls within acceptable ranges. This intermediary verification mechanism enables accurate clock source validation without adding complexity to the primary controller's internal architecture.
Solution Approach 2:
The patent divides the safety control function into two separate controllers: a primary safety controller that executes safety logic and a safety partner controller that performs clock source verification. This segmentation allows each controller to have simplified individual architectures while collectively achieving high reliability through mutual verification. The primary controller focuses on safety task execution while the partner controller specializes in timestamp validation.
2Reliability
If redundant verification systems are implemented to ensure clock source accuracy, then reliability is improved, but device complexity increases due to additional processing units and communication infrastructure
Solution Approach 1:
The safety partner controller is designed with multi-functionality to minimize overall system complexity. It not only verifies clock source accuracy through timestamp comparison but also monitors communication link status, detects faults in the primary controller, and can take over safety control functions if needed. This universal design consolidates multiple safety functions into a single controller rather than requiring separate specialized components for each function.
Solution Approach 2:
The primary safety controller generates its own timestamped safety I/O messages using its internal clock source, and the safety partner controller uses its own independently generated timestamps for verification. Each controller serves itself by providing the verification data it needs without requiring external reference clocks or complex synchronization infrastructure. The controllers independently maintain their own time references and use these for mutual validation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
This disclosure provides an automation controller method, system and apparatus including a redundant watchdog utilizing a safety partner controller. According to an exemplary controller, the controller includes a first processing unit, a second processing unit, and an integrated circuit configured to receive as inputs fault indicator signals from the first and second processing units, and the integrated circuit configured to disable I/O communications for a fault condition detected by the first or second processing units.