System and method for operating a safety-critical device over a non-secure communication network
Abstract
In a system and method for operating, at a near location, a remote safety-critical device, the system includes a first operating input device operated at the near location, providing a first barrier control signal; and a second operating input device to be operated at the near location, providing a second barrier control signal. The first barrier control signal is communicatively connected to a near end of a first secure communication tunnel, and the second barrier control signal is communicatively connected to a near end of a second secure communication tunnel, both through the non-secure communication network. Far ends of the first and second secure communication tunnels are communicatively connected to activating inputs of first and second barrier circuits, respectively. The first and second barrier circuits enable operation of the safety-critical device when both are activated.
Claims
exact text as granted — not AI-modified1 . System for operating, at a near location, a safety-critical device located at a far location, the system comprising
a first operating input device to be operated at the near location by an operator, providing a first barrier control signal; a second operating input device to be operated at the near location by an operator, providing a second barrier control signal; the first barrier control signal being communicatively connected to a near end of a first secure communication tunnel through the non-secure communication network; the second barrier control signal being communicatively connected to a near end of a second secure communication tunnel through the non-secure communication network; a far end of the first secure communication tunnel being communicatively connected to an activating input of a first barrier circuit; a far end of the second secure communication tunnel being communicatively connected to an activating input of a second barrier circuit; the first and second barrier circuits being configured to enable operation of the safety-critical device when both the first and second barrier circuits are activated.
2 . System according to claim 1 ,
wherein separate hardware circuits are used for implementing the first and second barrier circuits.
3 . System according to claim 1 ,
further comprising
a third operating input device to be operated at the near location by an operator, providing a third barrier control signal;
the third barrier control signal being connected to a near end of a third secure communication tunnel through the non-secure communication network;
a far end of the third secure communication tunnel being connected to an activating input of a third barrier circuit;
the first, second and third barrier circuits are configured to enable operation of the safety-critical device when both the first, second and third barrier circuits are activated.
4 . System according to claim 1 , for operating, at a near location, a plurality of safety-critical devices located at the far location, the system further comprising
a first multiplexer, multiplexing a plurality of first barrier control signals onto the first secure communication tunnel through the non-secure communication network; a second multiplexer, multiplexing a plurality of second barrier control signals onto the second secure communication tunnel through the non-secure communication network; the first barrier circuit including a first demultiplexer; and the second barrier circuit including a second demultiplexer.
5 . System according to claim 1 , wherein
the non-secure communication network is a packet based communication network.
6 . System according to claim 5 , wherein the non-secure communication network is an IP network and the secure communication tunnel is an IPsec tunnel, e.g. configured in an integrity only mode.
7 . System according to claim 5 , wherein
the communication through the secure communication tunnel employs a protocol which includes time-stamping of data.
8 . System according to claim 6 , wherein
the system is configured with a fixed IP addressing scheme.
9 . System according to claim 1 , wherein
the safety-critical device includes at least one of a weapon firing circuitry, a weapon movement circuitry, and a video confirmation device.
10 . System according to claim 1 , wherein
the at least one operating input device includes at least one of: a weapon fire control device, a weapon movement control device, and a video session information device.
11 . System according to, claim 1 , wherein
the operating input device includes a video session information device, and the safety-critical device includes a video confirmation device, the system further comprising a video distribution device providing a video signal, the video signal being transferred through the non-secure communication network and displayed on a screen at the near end; the video session information device being configured to derive video session information from the video signal and transfer the video session information through the secure communication tunnel, the video confirmation device being configured to confirm the authenticity of the video signal transferred through the non-secure communication network.
12 . Method for operating, at a near location, a safety-critical device located at a far location, the method comprising
providing a first barrier control signal from a first operating input device to be operated at the near location by an operator; providing a second barrier control signal from a second operating input device to be operated at the near location by an operator; communicating the first barrier control signal to a near end of a first secure communication tunnel through the non-secure communication network; communicating the second barrier control signal to a near end of a second secure communication tunnel through the non-secure communication network; communicating, from a far end of the first secure communication tunnel a signal to an activating input of a first barrier circuit; communicating, from a far end of the second secure communication tunnel, a signal to an activating input of a second barrier circuit;
enabling, by the first and second barrier circuits, operation of the safety-critical device when both the first and second barrier circuits are activated.
13 . Method according to claim 12 ,
wherein separate hardware circuits are used for implementing the first and second barrier circuits.
14 . Method according to claim 12 , further comprising
providing a third barrier control signal by a third operating input device to be operated at the near location by an operator, communicating the third barrier control signal being to a near end of a third secure communication tunnel through the non-secure communication network; communicating, from a far end of the third secure communication tunnel, a signal to an activating input of a third barrier circuit; enabling, by the first, second and third barrier circuits, operation of the safety-critical device when both the first, second and third barrier circuits are activated.
15 . Method according to claim 12 , for operating, at a near location, a plurality of safety-critical devices located at the far location, the method further comprising multiplexing, by a first multiplexer, a plurality of first barrier control signals onto the first secure communication tunnel through the non-secure communication network;
multiplexing, by a second multiplexer, a plurality of second barrier control signals onto the second secure communication tunnel through the non-secure communication network; and wherein the first barrier circuit including a first demultiplexer; and the second barrier circuit including a second demultiplexer.
16 . Method according to claim 12 , wherein
the non-secure communication network is a packet based communication network.
17 . Method according to claim 16 , wherein the non-secure communication network is an IP network and
the secure communication tunnel is an IPsec tunnel, e.g. configured in an integrity only mode.
18 . Method according to claim 16 , wherein the communication through the secure communication tunnel employs a protocol which includes time-stamping of data.
19 . Method according to claim 17 , wherein
the method employs a fixed IP addressing scheme.
20 . Method according to claim 12 , wherein
the safety-critical device includes at least one of a weapon firing circuitry, a weapon movement circuitry, and a video confirmation device.
21 . Method according claim 12 , wherein
the at least one operating input device includes at least one of: a weapon fire control device, a weapon movement control device, and a video session information device.
22 . Method according to claim 12 , wherein
the operating input device includes a video session information device, and the safety-critical device includes a video confirmation device, the method further comprising
providing, by a video distribution device, a video signal;
transferring the video signal being through the non-secure communication network;
displaying the video signal on a screen at the near end;
deriving, by the video session information device, video session information from the video signal;
transferring the video session information through the secure communication tunnel; and
confirming, by the video confirmation device, the authenticity of the video signal transferred through the non-secure communication network.Join the waitlist — get patent alerts
Track US2014304799A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.