Djinious
Industrial roboticsManufacturing & robotics

Kronos Robotic Work Cell

A six-axis robotic work cell modelled end to end in ELANG as an audited reference — roughly a thousand lines carrying a functional-safety design to ISO 13849-1 Performance Level d, with every safeguard traced to the hazard it mitigates.

DjiniousEngineering
An ELANG source model in the DjiniousEngineering editor, shown on the Kestrel-SAR III payload: the project, its actors and its requirements, each with an acceptance criterion and a verification method.
ISO 13849-1 performance level
PL dISO 13849-1 performance levelELANG reference model
system code
KRNSsystem codeManufacturing cell

A safeguard is only real if it traces to a hazard and a test

On a machine that can injure, the hard part is not drawing the guarding — it is proving that every hazard has a safeguard, every safeguard a means of detection, a responsible actor and a lifecycle gate.

The Kronos model is the reference for that closure: the WHY pillar’s hazards and safeguards are wired to the HOW pillar’s tests and the WHO/WHEN pillar’s gates.

Recipe and standards

Driven by the production machine / manipulator recipe.

ISO 10218

Carried as a standard the recipe honours for this class.

ISO 13849-1 (PL d)

The functional-safety design the reference model carries.

ISO 230

Carried as a standard the recipe honours for this class.

Machine recipe over the baseline lifecycle

Model a work cell whose functional-safety case is complete and traceable, to ISO 13849-1 PL d, with the safety chain checkable rather than asserted.

  1. Frame

    Frame the cell’s capabilities and the environment it operates in.

  2. Hazards

    Enumerate hazards and the safeguards that mitigate them.

  3. Close the chain

    Tie each safeguard to a detection means, a responsible actor and a gate.

    WFR-9
  4. Allocate

    Allocate the safety functions onto components and interfaces.

  5. Verify

    Close the verification matrix and reach L2 conformance.

TRR — Test Readiness Review

Before test, the safety case and the models have to line up.

Replica correlation

The digital replica correlates with the analytical models.

Safety cases

Abort criteria and safety cases are agreed.

Safeguards

Every hazard has a safeguard with an assigned verification.

Procedures

Test procedures exist for every safety function.

ELANG’s well-formedness rules refuse to call the model complete while an obligation lacks an implementation, a test, an actor or a gate.