Control of safety critical operations
First Claim
Patent Images
1. A control apparatus for triggering a safety-critical operation, the control apparatus comprising:
- a receiver for receiving control command signals from a remote operator; and
a safety management system having a first part and at least one second part, said first part being responsive to a receivedcontrol command signal to trigger operation of said at least one second part and thereby to trigger the safety-critical operation, wherein said first part transmits a plurality of keywords to said at least one second part in response to a received control command signal, andwherein said at least one second part comprisesa plurality of key-safe switches, selectively responsive to the plurality of predetermined keywords, where each of said plurality of key-safe switches being configured to be activated upon receipt of a different respective one or more of the plurality of keywords, wherein the safety-critical operation is triggered in the event that at least a majority of said key-safe switches are activated.
1 Assignment
0 Petitions
Accused Products
Abstract
A system wherein control of a safety-critical system operation is effected by sending a plurality of keywords via a low integrity communication path.
8 Citations
16 Claims
-
1. A control apparatus for triggering a safety-critical operation, the control apparatus comprising:
-
a receiver for receiving control command signals from a remote operator; and a safety management system having a first part and at least one second part, said first part being responsive to a received control command signal to trigger operation of said at least one second part and thereby to trigger the safety-critical operation, wherein said first part transmits a plurality of keywords to said at least one second part in response to a received control command signal, and wherein said at least one second part comprises a plurality of key-safe switches, selectively responsive to the plurality of predetermined keywords, where each of said plurality of key-safe switches being configured to be activated upon receipt of a different respective one or more of the plurality of keywords, wherein the safety-critical operation is triggered in the event that at least a majority of said key-safe switches are activated. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16)
-
Specification