METHODS AND SYSTEMS FOR VITAL BUS ARCHITECTURE
First Claim
1. A high integrity safety critical bus system for communicating data in a control system, said bus system comprising:
- a plurality of data communication buses configured in a multiple redundant orientation;
at least one safety supervisor module communicatively coupled to and associated with at least two of said plurality of data communication buses, said safety supervisor comprising a database including a plurality of logic rules, said logic rules programmed to;
receive data from the at least two of said plurality of data communication buses;
determine the validity of the received data from each bus using one or more of the plurality of the logic rules;
if the received data is determined to be invalid, restore the validity of the data using one or more of the plurality of the logic rules;
if the data can not be restored transmit an alert to the control system; and
transmit the validated data to an intended destination.
2 Assignments
0 Petitions
Accused Products
Abstract
Methods and systems for a vital bus system for communicating data in a control system are provided. The system includes a plurality of data communication buses configured in a multiple redundant orientation and at least one safety supervisor module including a database including a plurality of logic rules. The logic rules are programmed to receive data from the plurality of data communication buses and to determine the validity of the received data from each bus using one or more of the plurality of the logic rules. If the received data is invalid, the logic rules are programmed to restore the validity of the data using one or more of the plurality of the logic rules. If the data can not be restored the logic rules are programmed to transmit an alert to the control system. Otherwise, the logic rules are programmed to transmit the validated data to an intended destination.
44 Citations
20 Claims
-
1. A high integrity safety critical bus system for communicating data in a control system, said bus system comprising:
-
a plurality of data communication buses configured in a multiple redundant orientation; at least one safety supervisor module communicatively coupled to and associated with at least two of said plurality of data communication buses, said safety supervisor comprising a database including a plurality of logic rules, said logic rules programmed to; receive data from the at least two of said plurality of data communication buses; determine the validity of the received data from each bus using one or more of the plurality of the logic rules; if the received data is determined to be invalid, restore the validity of the data using one or more of the plurality of the logic rules; if the data can not be restored transmit an alert to the control system; and transmit the validated data to an intended destination. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A method of implementing safety critical control of a vehicle, said method comprising:
-
determining an operational state of a plurality of redundant vehicle control devices using at least one of a plurality of logic rules, the vehicle control devices configured to control a function of the vehicle; blocking the operation of ones of the plurality of redundant vehicle control devices that are determined to be in an abnormal state; and transmitting control signals to a selected one of the plurality of redundant vehicle control devices. - View Dependent Claims (10, 11, 12)
-
-
13. A vehicle including a control system comprising:
-
a plurality of low-integrity systems configured to detect operating conditions of the vehicle, at least some of said plurality of low-integrity systems configured to control operation of the vehicle; and a safety supervisor module communicatively coupled to and associated with at least one of a control device and an input device associated with each low-integrity system, said safety supervisor module configured to monitor the state of each device using one or more logic rules, said safety supervisor module configured to remove control from a device determined to be in an abnormal state wherein supervision of the plurality of low-integrity systems by the safety supervisor module permits operation of the control system as a high-integrity system. - View Dependent Claims (14, 15, 16, 17, 18, 19, 20)
-
Specification