Control of safety critical operations

US9383740B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9383740-B2
Application numberUS-201113578747-A
CountryUS
Kind codeB2
Filing dateFeb 14, 2011
Priority dateFeb 13, 2010
Publication dateJul 5, 2016
Grant dateJul 5, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system wherein control of a safety-critical system operation is effected by sending a plurality of keywords via a low integrity communication path.

First claim

Opening claim text (preview).

The invention claimed is: 1. A control apparatus for triggering a safety-critical operation, the control apparatus comprising: a receiver for receiving control command signals from a remote operator; and a safety management system having a first part and at least one second part, said first part being responsive to a received control command signal to trigger operation of said at least one second part and thereby to trigger the safety-critical operation, wherein said first part transmits a plurality of keywords to said at least one second part in response to a received control command signal, and wherein said at least one second part comprises a plurality of key-safe switches, selectively responsive to the plurality of predetermined keywords, where each of said plurality of key-safe switches being configured to be activated upon receipt of a different respective one or more of the plurality of keywords, wherein the safety-critical operation is triggered in the event that at least a majority of said key-safe switches are activated. 2. The control apparatus of claim 1 , wherein said first part and said at least one second part of the safety management system are implemented according to a relatively high level of integrity, and wherein the control apparatus further comprises a communications path, implemented according to a relatively low level of integrity, to convey the plurality of keywords from said first part to said at least one second part. 3. The control apparatus according to claim 2 , wherein the communications path comprises a serial data bus. 4. The control apparatus according to claim 2 , wherein the communications path is arranged to convey a combined data and power signal to each of said plurality of key-safe switches. 5. The control apparatus according to claim 1 , wherein said plurality of key-safe switches are arranged in series with respect to a power supply or other executive signal for triggering the safety-critical operation. 6. The control apparatus according to claim 1 , wherein said plurality of key-safe switches operate in a predetermined sequence. 7. The control apparatus according to claim 6 , further comprising at least one logic gate configured such that a keyword is supplied to one of said plurality of key-safe switches via a logic gate to which an output from another of said plurality of key-safe switches is supplied, which causes said plurality of key-safe switches to operate in the predetermined sequence. 8. The control apparatus according to claim 1 , wherein each of said plurality of key-safe switches is individually addressable. 9. The control apparatus according to claim 8 , wherein the control command signals comprise an address for each of said plurality of key-safe switches and an associated one or more of said plurality of keywords and wherein said first part of said safety management system is configured to transmit each of said plurality of keywords to respectively addressed key-safe switches of said plurality of key-safe switches according to the control command signals. 10. The control apparatus according to claim 1 , wherein said first part of said safety management system comprises a high integrity storage for storing said plurality of keywords and wherein said first part is configured to release said plurality of keywords from the storage for communication to said at least one second part upon receipt of a control command signal. 11. The control apparatus according to claim 10 , wherein said plurality of keywords are stored in the high integrity storage in encrypted form and wherein the control command signal comprises a decryption key, and wherein said first part further comprises a processor for applying a predetermined decryption algorithm to said encrypted keywords using the decryption key, and wherein the results of said application of the decryption algorithm are communicated to said at least one second part. 12. The control apparatus according to claim 1 , wherein the control command signals comprise said plurality of keywords and wherein said first part of said safety management system is configured to extract said plurality of keywords from the control command signals for communication to said at least one second part. 13. The control apparatus according to claim 12 , wherein said first part of said safety management system is configured to transmit said plurality of keywords to said at least one second part of said safety management system in a sequence determined by the order in which they are received in the control command signals. 14. The control apparatus according to claim 1 , wherein said receiver is configured to receive the control command signals from the remote operator over a communications path of relatively low integrity. 15. The control apparatus according to claim 1 , wherein the control apparatus is configured for embodiment in an access control, power switching, or other form of safety-critical signalling or switching system. 16. An unmanned mobile or stationary platform or other form of autonomous or remotely controllable mobile or stationary platform carrying or associated with one or more weapon systems or other forms of countermeasure, the platform incorporating the control apparatus according to claim 1 configured to control the firing, launch or deployment of said one or more weapon systems or countermeasures.

Assignees

Inventors

Classifications

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9383740B2 cover?
A system wherein control of a safety-critical system operation is effected by sending a plurality of keywords via a low integrity communication path.
Who is the assignee on this patent?
Bennett Simon Grant, Belcher Nicholas Andrew, Parker David, and 4 more
What technology area does this patent fall under?
Primary CPC classification G05B19/0425. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jul 05 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).