CONTROL OF SAFETY CRITICAL OPERATIONS
First Claim
Patent Images
1. A system comprising:
- an operative portion for performing a safety critical operation, a command portion remote from the operative portion for controlling performance of the safety critical operation, and low integrity transmission means for transmitting a control command from the command portion to the operative portion, wherein the control command comprises a plurality of keywords generated in a high integrity control command generation part of the command portion which are outputted only in response to a correct command from an operator, and the operative portion comprises a plurality of high integrity key safe switches which operate to compare the keywords received from the command portion via the low integrity transmission means, the performance of the safety critical operation being effected only in the event of a correct comparison by the key safe switches.
1 Assignment
0 Petitions
Accused Products
Abstract
A system wherein control of a safety-critical system operation is effected by sending a plurality of keywords via a low integrity transmission means.
-
Citations
23 Claims
-
1. A system comprising:
- an operative portion for performing a safety critical operation, a command portion remote from the operative portion for controlling performance of the safety critical operation, and low integrity transmission means for transmitting a control command from the command portion to the operative portion, wherein the control command comprises a plurality of keywords generated in a high integrity control command generation part of the command portion which are outputted only in response to a correct command from an operator, and the operative portion comprises a plurality of high integrity key safe switches which operate to compare the keywords received from the command portion via the low integrity transmission means, the performance of the safety critical operation being effected only in the event of a correct comparison by the key safe switches.
- View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 20, 21)
-
10. A system comprising:
- an operative portion for performing a safety critical operation, a command portion remote from the operative portion for controlling performance of the safety critical operation, and low integrity transmission means for transmitting a control command from the command portion to the operative portion, wherein the control command comprises a plurality of decrypt keys generated in a high integrity control command generation part of the command portion which are outputted only in response to a correct command from an operator, and the operative portion comprises a high integrity store for storing a plurality of keywords generated only on receipt of the decrypt keys received from the command portion via the low integrity transmission means and a plurality of high integrity key safe switches which operate to compare the generated keywords, the performance of the safety critical operation being effected only in the event of a correct comparison by the key safe switches.
- View Dependent Claims (11, 12, 13, 14, 15, 16, 17, 18, 19, 23)
-
22. An unmanned aerial vehicle comprising:
- an operative portion for performing a safety critical operation in response to a control command received from a command portion remote from the vehicle via low integrity transmission means, wherein the control command comprises a plurality of keywords generated in a high integrity control command generation part of the command portion which are outputted only in response to a correct command from an operator, and the operative portion comprises a plurality of high integrity key safe switches which operate to compare the keywords received from the command portion via the low integrity transmission means, the performance of the safety critical operation being effected only in the event of a correct comparison by the key safe switches.
Specification