Method and apparatus for converting multichannel messages into a single-channel safe message
First Claim
1. A method for the coupling of a safety-critical process from a safe environment, which has at least two redundant processing channels, to an environment which is unsafe or to an environment which is safe but has fewer processing channels, said method comprising:
- processing a data record which is relevant to the safety-critical process, to form a respective safe protocol (14, 24) using the at least two redundant processing channels (1, 2) in accordance with identical laws; and
forming a common safe protocol, taking into account at least two redundant safe coupling protocols (14, 24), by accessing a common (buffer) register (30) using each of the processing channels (1, 2), in which case a write authorization is allocated only once for each register location;
wherein, when writing at least elements (14′
) of the common safety-based protocol using a processing channel (1) with write authorization, at least one further processing channel (2) is first of all used to check (25) whether these elements (14′
) are identical to one another, and access to the common register for the purpose of storing these elements is enabled only when they are identical to one another.
1 Assignment
0 Petitions
Accused Products
Abstract
The invention relates to a method and to an apparatus, which has been adapted to carry out the method, for the coupling of a safety-critical process from a safe environment, which has at least two redundant processing channels, to an environment which is not safe or to an environment which is safe but has fewer processing channels. To this end, provision is made of a method which processes a data record which is relevant to the safety-critical process, in particular on a protocol-specific basis, to form a respective safe protocol (14, 24) using at least two redundant processing channels (1, 2) in accordance with identical laws, and forms a common safe protocol taking into account at least two redundant safe coupling protocols (14, 24), to be precise by accessing a common (buffer) register (30) using each of the processing channels (1, 2), in which case a write authorization is allocated only once for each register location, and, when writing at least elements (14′) of the common safety-based protocol using a processing channel (1) with write authorization, at least one further processing channel (2) is first of all used to check (25) whether these elements (14′) are identical to one another, and access to the common buffer register for the purpose of storing these elements is enabled only when they are identical to one another.
22 Citations
28 Claims
-
1. A method for the coupling of a safety-critical process from a safe environment, which has at least two redundant processing channels, to an environment which is unsafe or to an environment which is safe but has fewer processing channels, said method comprising:
-
processing a data record which is relevant to the safety-critical process, to form a respective safe protocol (14, 24) using the at least two redundant processing channels (1, 2) in accordance with identical laws; and
forming a common safe protocol, taking into account at least two redundant safe coupling protocols (14, 24), by accessing a common (buffer) register (30) using each of the processing channels (1, 2), in which case a write authorization is allocated only once for each register location;
wherein, when writing at least elements (14′
) of the common safety-based protocol using a processing channel (1) with write authorization, at least one further processing channel (2) is first of all used to check (25) whether these elements (14′
) are identical to one another, and access to the common register for the purpose of storing these elements is enabled only when they are identical to one another. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14)
-
-
15. An apparatus for the coupling of a safety-critical process from a safe environment, which has at least two redundant processing channels, to an environment which is not safe or to an environment which is safe but has fewer processing channels, said apparatus comprising :
-
at least two redundant computers (11, 21) for the processing of an identical input data record to form a respective safe protocol (14, 24) using identical laws; and
a circuit arrangement for connecting each computer (11, 21) to a common buffer register (30) in such a manner that write access is given to only a respective one of the computers for each register location in the buffer register (30), and access to the common buffer register for the purpose of storing the elements to be written in is locked until the elements to be written in have been verified by at least one further computer. - View Dependent Claims (16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28)
-
Specification