IP Library Granted Patent US 12,210,870
Granted Patent B2
US 12,210,870 · App. 17/332,626 · Granted Jan 28, 2025

Ensuring functional safety requirement satisfaction using fault-detectable microcontroller identifiers

Inventor: Kerfegar Khurshed Katrak (Fenton, MI)
Assignee: Fort Robotics, Inc.
G06F9/226G05B9/02G05B19/048G05B23/0235H03M13/09G06F7/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,210,870
App. No.
17/332,626
Granted
Jan 28, 2025
Kind
B2
Abstract

An application processor receives first and safety state information from first and second microcontrollers, and respective first and second sets of bytes forming a first identifier of the first microcontroller and a second identifier of the second microcontroller. The processor concatenates a safety message including the first and second safety state information, the safety message including the first set of bytes and the second set of bytes. The processor transmits the safety message to a second application processor of a safety controller, which separates, the first set of bytes and the second set of bytes, compares at least one of the first set of bytes and the second set of bytes to a data structure of known microcontroller identifiers, and verifies the safety state information based on identifying a match.

Claims (81)

1. A method comprising:

receiving, by a first application processor from a first microcontroller of a safety module, a first set of safety state information and a first set of bytes corresponding to a first identifier of the first microcontroller;

receiving, by the first application processor from a second microcontroller of the safety module, a second set of safety state information and a second set of bytes corresponding to a second identifier of the second microcontroller;

generating, by the first application processor, a safety message comprising the first set of safety state information, the second set of safety state information, the first set of bytes, and the second set of bytes;

transmitting, by the first application processor, the safety message to a second application processor of a safety controller;

extracting, by the second application processor, the first set of bytes and the second set of bytes from the safety message;

by a third microcontroller of the safety controller:

accessing a first encoded value corresponding to the first identifier of the first microcontroller; and

verifying the first safety state information in response to detecting a match between the first set of bytes and the first encoded value; and

by a fourth microcontroller of the safety controller:

accessing a second encoded value corresponding to the second identifier of the second microcontroller;

generating a command that causes a device to transition to a safety mode in response to detecting a difference between the second set of bytes and the second encoded value; and

transmitting the command to the device.

2. The method of claim 1 , wherein generating the safety message comprises generating the safety message comprising:

the first set of bytes corresponding to the first identifier, in a set of unique identifiers, uniquely identifying the first microcontroller; and

the second set of bytes corresponding to the second identifier, in the set of unique identifiers, uniquely identifying the second microcontroller.

3. The method of claim 1 , wherein generating the safety message comprises generating the safety message comprising:

the first set of bytes comprising two bytes corresponding to the first identifier exhibiting a length of one word; and

the first set of bytes comprising two bytes corresponding to the second identifier exhibiting a length of one word.

4. The method of claim 3 , wherein generating the safety message comprises generating the safety message comprising the first set of bytes corresponding to the first identifier and the second set of bytes corresponding to the second identifier, the second identifier exhibiting a hamming distance greater than or equal to four from the first identifier.

5. The method of claim 1 , further comprising:

loading the first set of bytes and the first encoded value into a memory device; and

detecting the match between the first set of bytes and the first encoded value by the third microcontroller comparing the first set of bytes and the first encoded value loaded into the memory device.

6. The method of claim 1 , further comprising:

loading the second set of bytes and the second encoded value into a memory device; and

detecting the difference between the second set of bytes and the second encoded value by the fourth microcontroller comparing the second set of bytes and the second encoded value loaded into the memory device.

7. The method of claim 1 , wherein verifying the first safety state information comprises:

detecting absence of a bit-line error associated with the first set of bytes in response to detecting the match between the first set of bytes and the first encoded value; and

verifying the first safety state information in response to absence of the bit-line error associated with the first set of bytes.

8. The method of claim 1 , wherein generating the command comprises:

detecting a bit-line error associated with the second set of bytes in response to detecting the difference between the second set of bytes and the second encoded value; and

generating the command that causes the device to transition to the safety mode in response to detecting the bit-line error associated with the second set of bytes.

9. The method of claim 1 , wherein accessing the first encoded value comprises accessing the first encoded value comprising:

a first set of bits selected from an even hamming set; and

a second set of bits selected from an odd hamming set.

10. The method of claim 9 , wherein accessing the first encoded value comprises accessing the first encoded value comprising:

the first set of bits selected from the even hamming set and corresponding to “0011”; and

the second set of bits selected from the odd hamming set and corresponding to “0100”.

11. The method of claim 1 , wherein accessing the second encoded value comprises accessing the second encoded value comprising:

a first set of bits selected from an even hamming set; and

a second set of bits selected from the even hamming set.

12. The method of claim 1 , wherein receiving the second set of bytes comprises receiving the second set of bytes comprising:

a first set of bits selected from an odd hamming set; and

a second set of bits selected from the odd hamming set.

13. The method of claim 12 , wherein receiving the second set of bytes comprises receiving the second set of bytes comprising the first set of bits and the second set of bits, the second set of bits exhibiting a minimum hamming distance of two from the first set of bits.

14. The method of claim 1 , wherein generating the safety message comprises generating the safety message comprising:

the first set of safety state information;

the second set of safety state information;

the first set of bytes corresponding to the first identifier of the first microcontroller; and

the second set of bytes corresponding to the second identifier of the second microcontroller, the second set of bytes corresponding to a ones complement of the first set of bytes.

15. The method of claim 1 , wherein generating the command comprises:

generating a word based on the second set of bytes;

detecting the difference between the word and the second encoded value; and

generating the command that causes the device to transition to the safety mode in response to detecting the difference between the word and the second encoded value.

16. A method comprising:

by a first application processor of a safety module:

receiving, from a first microcontroller of the safety module, a first set of safety state information and a first set of bytes corresponding to a first identifier of the first microcontroller;

receiving, from a second microcontroller of the safety module, a second set of safety state information and a second set of bytes corresponding to a second identifier of the second microcontroller;

generating a safety message comprising the first set of safety state information, the second set of safety state information, the first set of bytes, and the second set of bytes; and

transmitting the safety message to a safety controller; and

by a third microcontroller of the safety controller:

accessing a first encoded value corresponding to the first identifier of the first microcontroller;

generating a command that causes a device to transition to a safety mode in response to detecting a difference between the first set of bytes and the first encoded value; and

transmitting the command to the device.

17. The method of claim 10 , further comprising, by a fourth microcontroller of the safety controller:

accessing a second encoded value corresponding to the second identifier of the second microcontroller; and

verifying the second safety state information in response to detecting a match between the second set of bytes and the second encoded value.

18. The method of claim 10 , wherein generating the safety message comprises generating the safety message comprising the first set of bytes corresponding to the first identifier and the second set of bytes corresponding to the second identifier, the second identifier exhibiting a minimum hamming distance from the first identifier.

19. A method comprising:

by a first application processor of a safety module:

receiving, from a first microcontroller of the safety module, a first set of safety state information and a first set of bytes corresponding to a first identifier of the first microcontroller;

receiving, from a second microcontroller of the safety module, a second set of safety state information and a second set of bytes corresponding to a second identifier of the second microcontroller;

generating a safety message comprising the first set of safety state information, the second set of safety state information, the first set of bytes, and the second set of bytes; and

transmitting the safety message to a safety controller; and

by a third microcontroller of the safety controller:

accessing a first encoded value corresponding to the first identifier of the first microcontroller; and

verifying the first safety state information in response to detecting a match between the first set of bytes and the first encoded value.

20. The method of claim 13 , further comprising, by a fourth microcontroller of the safety controller:

accessing a second encoded value corresponding to the second identifier of the second microcontroller;

generating a command that causes a device to transition to a safety mode in response to detecting a difference between the second set of bytes and the second encoded value; and

transmitting the command to the device.

Assignments (2)
SECURITY INTEREST Recorded Apr 3, 2024
From: FORT ROBOTICS, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY (SUCCESSOR BY PURCHASE TO THE FEDERAL DEPOSIT INSURANCE CORPORATION AS RECEIVER FOR SILICON VALLEY BRIDGE BANK, N.A. (AS SUCCESSOR TO SILICON VALLEY BANK)
Reel/Frame 066992/0121 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2021
From: KATRAK, KERFEGAR KHURSHED
To: FORT ROBOTICS, INC.
Reel/Frame 056454/0461 →
Continuity (1)
Related Publication 20220382543A1 · Dec 1, 2022
References Cited (10)
US 7046700B1 · Roberts · 2006 [cited by examiner]
US 20080104674A1 · Sherkin et al. · 2008 [cited by applicant]
US 20140032970A1 · Hovi · 2014 [cited by examiner]
US 20150045915A1 · Schmidt · 2015 [cited by examiner]
US 20180329848A1 · Kattainen · 2018 [cited by examiner]
US 20190026103A1 · Maas · 2019 [cited by applicant]
US 20190114860A1 · Eckelmann-Wendt · 2019 [cited by examiner]
US 20220158983A1 · Schmid · 2022 [cited by examiner]
WO 2014082051A1 · 2014 [cited by applicant]
International Search Report received in PCT/US22/30961 dated Nov. 22, 2022. [cited by applicant]