US2014304799A1PendingUtilityA1

System and method for operating a safety-critical device over a non-secure communication network

Assignee: KONGSBERG DEFENCE & AEROSPACE ASPriority: Jan 25, 2013Filed: Aug 16, 2013Published: Oct 9, 2014
Est. expiryJan 25, 2033(~6.5 yrs left)· nominal 20-yr term from priority
H04L 67/125F41A 19/58H04L 63/18H04L 63/0272F41A 17/06H04L 63/0428F41A 27/28Y04S40/18H04L 63/0869H04L 63/04H04L 63/164H04L 63/029
38
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In a system and method for operating, at a near location, a remote safety-critical device, the system includes a first operating input device operated at the near location, providing a first barrier control signal; and a second operating input device to be operated at the near location, providing a second barrier control signal. The first barrier control signal is communicatively connected to a near end of a first secure communication tunnel, and the second barrier control signal is communicatively connected to a near end of a second secure communication tunnel, both through the non-secure communication network. Far ends of the first and second secure communication tunnels are communicatively connected to activating inputs of first and second barrier circuits, respectively. The first and second barrier circuits enable operation of the safety-critical device when both are activated.

Claims

exact text as granted — not AI-modified
1 . System for operating, at a near location, a safety-critical device located at a far location, the system comprising
 a first operating input device to be operated at the near location by an operator, providing a first barrier control signal;   a second operating input device to be operated at the near location by an operator, providing a second barrier control signal;   the first barrier control signal being communicatively connected to a near end of a first secure communication tunnel through the non-secure communication network;   the second barrier control signal being communicatively connected to a near end of a second secure communication tunnel through the non-secure communication network;   a far end of the first secure communication tunnel being communicatively connected to an activating input of a first barrier circuit;   a far end of the second secure communication tunnel being communicatively connected to an activating input of a second barrier circuit;   the first and second barrier circuits being configured to enable operation of the safety-critical device when both the first and second barrier circuits are activated.   
     
     
         2 . System according to  claim 1 ,
 wherein separate hardware circuits are used for implementing the first and second barrier circuits.   
     
     
         3 . System according to  claim 1 ,
 further comprising
 a third operating input device to be operated at the near location by an operator, providing a third barrier control signal; 
 the third barrier control signal being connected to a near end of a third secure communication tunnel through the non-secure communication network; 
 a far end of the third secure communication tunnel being connected to an activating input of a third barrier circuit; 
 the first, second and third barrier circuits are configured to enable operation of the safety-critical device when both the first, second and third barrier circuits are activated. 
   
     
     
         4 . System according to  claim 1 , for operating, at a near location, a plurality of safety-critical devices located at the far location, the system further comprising
 a first multiplexer, multiplexing a plurality of first barrier control signals onto the first secure communication tunnel through the non-secure communication network;   a second multiplexer, multiplexing a plurality of second barrier control signals onto the second secure communication tunnel through the non-secure communication network;   the first barrier circuit including a first demultiplexer; and   the second barrier circuit including a second demultiplexer.   
     
     
         5 . System according to  claim 1 , wherein
 the non-secure communication network is a packet based communication network.   
     
     
         6 . System according to  claim 5 , wherein the non-secure communication network is an IP network and the secure communication tunnel is an IPsec tunnel, e.g. configured in an integrity only mode. 
     
     
         7 . System according to  claim 5 , wherein
 the communication through the secure communication tunnel employs a protocol which includes time-stamping of data.   
     
     
         8 . System according to  claim 6 , wherein
 the system is configured with a fixed IP addressing scheme.   
     
     
         9 . System according to  claim 1 , wherein
 the safety-critical device includes at least one of   a weapon firing circuitry, a weapon movement circuitry, and a video confirmation device.   
     
     
         10 . System according to  claim 1 , wherein
 the at least one operating input device includes at least one of:   a weapon fire control device, a weapon movement control device, and a video session information device.   
     
     
         11 . System according to,  claim 1 , wherein
 the operating input device includes a video session information device, and   the safety-critical device includes a video confirmation device,   the system further comprising   a video distribution device providing a video signal, the video signal being transferred through the non-secure communication network and displayed on a screen at the near end;   the video session information device being configured to derive video session information from the video signal and transfer the video session information through the secure communication tunnel,   the video confirmation device being configured to confirm the authenticity of the video signal transferred through the non-secure communication network.   
     
     
         12 . Method for operating, at a near location, a safety-critical device located at a far location, the method comprising
 providing a first barrier control signal from a first operating input device to be operated at the near location by an operator;   providing a second barrier control signal from a second operating input device to be operated at the near location by an operator;   communicating the first barrier control signal to a near end of a first secure communication tunnel through the non-secure communication network;   communicating the second barrier control signal to a near end of a second secure communication tunnel through the non-secure communication network;   communicating, from a far end of the first secure communication tunnel a signal to an activating input of a first barrier circuit;   communicating, from a far end of the second secure communication tunnel, a signal to an activating input of a second barrier circuit;   
       enabling, by the first and second barrier circuits, operation of the safety-critical device when both the first and second barrier circuits are activated. 
     
     
         13 . Method according to  claim 12 ,
 wherein separate hardware circuits are used for implementing the first and second barrier circuits.   
     
     
         14 . Method according to  claim 12 , further comprising
 providing a third barrier control signal by a third operating input device to be operated at the near location by an operator,   communicating the third barrier control signal being to a near end of a third secure communication tunnel through the non-secure communication network;   communicating, from a far end of the third secure communication tunnel, a signal to an activating input of a third barrier circuit;   enabling, by the first, second and third barrier circuits, operation of the safety-critical device when both the first, second and third barrier circuits are activated.   
     
     
         15 . Method according to  claim 12 , for operating, at a near location, a plurality of safety-critical devices located at the far location, the method further comprising multiplexing, by a first multiplexer, a plurality of first barrier control signals onto the first secure communication tunnel through the non-secure communication network;
 multiplexing, by a second multiplexer, a plurality of second barrier control signals onto the second secure communication tunnel through the non-secure communication network; and wherein   the first barrier circuit including a first demultiplexer; and   the second barrier circuit including a second demultiplexer.   
     
     
         16 . Method according to  claim 12 , wherein
 the non-secure communication network is a packet based communication network.   
     
     
         17 . Method according to  claim 16 , wherein the non-secure communication network is an IP network and
 the secure communication tunnel is an IPsec tunnel, e.g. configured in an integrity only mode.   
     
     
         18 . Method according to  claim 16 , wherein the communication through the secure communication tunnel employs a protocol which includes time-stamping of data. 
     
     
         19 . Method according to  claim 17 , wherein
 the method employs a fixed IP addressing scheme.   
     
     
         20 . Method according to  claim 12 , wherein
 the safety-critical device includes at least one of   a weapon firing circuitry, a weapon movement circuitry, and a video confirmation device.   
     
     
         21 . Method according  claim 12 , wherein
 the at least one operating input device includes at least one of:   a weapon fire control device, a weapon movement control device, and a video session information device.   
     
     
         22 . Method according to  claim 12 , wherein
 the operating input device includes a video session information device, and   the safety-critical device includes a video confirmation device,   the method further comprising
 providing, by a video distribution device, a video signal; 
 transferring the video signal being through the non-secure communication network; 
 displaying the video signal on a screen at the near end; 
 deriving, by the video session information device, video session information from the video signal; 
 transferring the video session information through the secure communication tunnel; and 
 confirming, by the video confirmation device, the authenticity of the video signal transferred through the non-secure communication network.

Join the waitlist — get patent alerts

Track US2014304799A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.