Safety & redundancy: no single fault as total failure

The current system concept provides separate functional paths for the main drive, the backup drive and pulmonary support. The aim of the architecture is that a single mechanical fault does not automatically turn into a complete loss of output.

Safety concept in development — none of it is validated.

Three paths, designed separately

Path 1

Main drive

Current architecture

BLDC motor with planetary roller screw for the full stroke of the main chamber in normal operation.

Drive →

Path 2

Backup drive

Under investigation

Own motor, own screw, as far as possible its own load path. Target approx. 60 ml emergency ejection for bridging operation.

Backup drive →

Path 3

Pulmonary continuous-flow pump

Under investigation

Separate micro-axial pump outside the pump body for continuous baseline flow in the pulmonary circulation.

Pulmonary support →

Compare sensors instead of trusting one value

Individual sensors can fail, drift or become fouled. The controller is therefore meant to cross-check pressure and flow signals at several points. Contradictions — for example rising pressure with falling flow, or no pressure change after a stroke — need defined responses.

The fault architecture should not jump straight from normal operation into an alarm state but respond in stages: adjust output, switch to the backup drive, raise an alarm, move to a conservative operating state. The exact stages and thresholds are not yet defined.

Failure modes that have to be tested

Derived from the critical long-term components. Every response has to be demonstrated on the bench with targeted fault injection.

  • Blocked or stiff main drivePlanned
  • Membrane rupture or leakage between blood and mechanical spacePlanned
  • Sticking or leaking valvePlanned
  • Sensor drift or sensor failurePlanned
  • Overheating of motor, electronics or energy transferPlanned
  • Failure of the pulmonary continuous-flow pumpPlanned
  • Power interruptionPlanned
Limit

Redundancy is an architectural goal here. Whether a single fault is actually contained will only be shown by fault injection on the bench — until then no safety claim is supported.