SiCore Dynamics

Artículo wiki · Colección 11

Seguridad Funcional

Referencia técnica sobre Seguridad Funcional para el diseño, integración e implementación de sistemas de energía inalámbrica.

6 minArtículo 01/10Seguridad
Functional Safety — educational diagram
Fig.: Diagrama educativo de “Functional Safety”.

Functional safety ensures that safety-related systems reduce risk to an acceptable level when equipment operates correctly and when faults occur. SiCore wireless charging docks and onboard receivers participate in the safety chain between facility mains, high-power resonant inverters, vehicle batteries, and autonomous navigation systems — any undetected fault in power transfer, field control, or interlock logic can expose personnel, vehicles, and infrastructure to electric shock, thermal runaway, or unintended vehicle motion during charge sessions.

SiCore applies IEC 61508 and IEC 61511 concepts adapted to WPT product architecture: hazard and risk assessment (HARA) identifies scenarios including misaligned charging, foreign object heating, loss of communication with fleet manager, and stuck-on power output. Safety functions — emergency stop response, foreign-object detection shutdown, over-temperature derating, and isolation verification — are allocated to hardware, firmware, or both with defined diagnostic coverage and proof-test intervals.

01Safety functions in WPT systems

  • Power transfer inhibition: prevent inverter energization when alignment, FOD, or interlock preconditions are not satisfied.
  • Safe state on fault: transition to zero net power output within defined time when any safety-related sensor or communication path fails.
  • Redundant interlock paths: hardware E-stop and software-monitored safety IO with diverse implementation where SIL targets require.
  • Diagnostic coverage: periodic self-tests on ADC references, gate-driver fault feedback, and coil current sense plausibility.
  • Safe torque-off coordination: interface with AGV/AMR motion controllers to inhibit drive enable during unsafe charge states.
Functional Safety — supporting diagram
Fig.: Ilustración de apoyo para “Functional Safety”.

02Architecture and independence

SiCore separates safety-related microcontroller domains from general-purpose control and telemetry processors where architecture demands — shared power supplies and clock sources are analyzed for common-cause failure. Gate-driver disable paths bypass software when hardware comparators detect overcurrent or overvoltage beyond absolute limits. Safety firmware runs cyclic tasks at bounded intervals with watchdog supervision; non-safety features (OTA updates, data logging) cannot block safety task execution.

AGV receivers integrate with customer safety PLCs and ISO 3691-4 AGV safety requirements — SiCore documents safety interface contracts: which signals are safety-rated, expected response times, and fault reaction when CAN or Ethernet links drop mid-charge. Functional safety is a system property — dock, receiver, vehicle controller, and facility E-stop network must be validated together during site acceptance.

03Lifecycle and evidence

Safety cases accumulate evidence across design, verification, production, and field operation: FMEA and FTA link failure modes to safety requirements; hardware-in-the-loop tests inject sensor faults and communication loss; production functional tests verify interlock continuity and E-stop response on every unit. Firmware changes trigger impact analysis against the safety requirements specification — field OTA for safety-related code follows controlled release with rollback capability and fleet audit trails.