Rail transit train control system
By centrally managing core logic operations and resource allocation through the safety train control cloud platform, the problems of complex architecture and incompatibility of equipment in traditional CBTC systems have been solved, enabling efficient train control and rapid expansion.
Patent Information
- Application Number
- CN201911219278.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-12-03
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2039-12-03
AI Technical Summary
Traditional CBTC systems are complex in architecture, have many types of equipment, and are not interchangeable, which makes installation and maintenance difficult. Software and data management are scattered, making it difficult to achieve efficient integration and expansion.
The safety train control cloud platform is adopted, including the cloud controller CiC, the line resource manager LRM, and the train registration and allocation controller TRAC. The core logic operation and resource allocation are centrally managed in the cloud, reducing the number of field devices and achieving efficient train-to-ground communication and redundancy backup.
It reduced maintenance complexity, improved system response speed and scalability, enhanced disaster resilience, and enabled rapid software and data upgrades.
Smart Images

Figure CN110920696B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of rail transit, in particular to a rail transit train control system. BACKGROUND
[0002] The current widely used communication-based train control system (CBTC) mainly consists of a zone controller (ZC) located on the trackside, a computer interlocking (CI), an automatic train supervision system (ATS) and a carborne controller (CC) installed on the train. The basic principle is to take the zone controller ZC as the core, obtain the basic state of the line through the computer interlocking CI, and communicate with the carborne controller to obtain the train state, so as to calculate the train movement authorization, and control the train operation according to the carborne controller. The system is mature and reliable, and can provide safe and efficient services for the operation of urban rail transit.
[0003] However, the traditional CBTC system has the following defects:
[0004] 1) The existing CBTC architecture is complex, and the efficiency is low when executing functions involving multiple subsystems. Due to the asynchronous clock between subsystems, a request-confirmation mechanism and a safety delay are needed, which makes it difficult to further improve the system efficiency.
[0005] 2) The existing CBTC devices are of many types, and their hardware architectures are different. In particular, the trackside ZC, CI and other safety computer platforms use hardware boards provided by each supplier, which are not compatible with each other. Therefore, it is necessary to rely on the spare parts provided by each supplier, which increases the installation and maintenance difficulties.
[0006] 3) Each subsystem of the existing CBTC system bears important logical operation functions. The interface definition between the subsystems is complex, involving the internal function division and timing logic of each supplier from top to bottom. It is difficult to realize the integration of a large system provided by different suppliers. On the one hand, it is difficult to greatly reduce the on-site test workload, and on the other hand, the same supplier's products must be used for the extension line, car increase and other subsequent projects of the existing project.
[0007] 4) The existing CBTC system needs to install, debug and guide the cutting of new specific hardware devices when implementing car increase, line extension and transformation, which is relatively cumbersome.
[0008] 5) The software and data of each subsystem are respectively stored in ZC, CI, CC and ATS, without unified management, and a large amount of manpower is consumed for software and data upgrading;
[0009] In recent years, many manufacturers have proposed a train control system concept centered on the vehicle, which simplifies the CI and ZC on the track side into a resource controller, mainly responsible for the allocation of trackside resources such as switches. And the logic operation function such as moving authorization is moved to the vehicle, which depends on the communication with the front train to obtain the moving authorization and monitor accordingly. This system combines the trackside equipment, reduces the communication link, and can be said to represent the evolution direction of the system towards more integration and complexity reduction, but it does not completely solve the above problems. SUMMARY
[0010] The purpose of the present application is to overcome the defects of the prior art and provide a rail transit train control system.
[0011] The purpose of the present application can be achieved by the following technical solutions:
[0012] A rail transit train control system, comprising:
[0013] A safe train control cloud platform, comprising a cloud controller CiC for implementing core train control logic operation, a line resource manager LRM for implementing line resource allocation and management, and a train registration and distribution controller TRAC for implementing the correspondence processing between the cloud controller and the vehicle multifunctional IO;
[0014] A wayside IO unit Wayside-IO deployed on the track side for realizing the state acquisition and instruction issuing of the trackside equipment;
[0015] A multifunctional IO unit Multi-IO deployed at the train end for realizing the communication between the cloud controller and the vehicle.
[0016] Preferably, the safe train control cloud platform comprises a plurality of different multi-core servers for implementing 2-to-2 combination fault safety comparison, and each multi-core server isolates different cores and maps them as independent CPUs to run safety application software.
[0017] The servers of the safe train control cloud platform can be deployed in the main center and the backup center.
[0018] Preferably, all servers of the safe train control cloud platform are configured according to M hot standby+N warm standby, when a server failure is detected, the hot standby device takes over the failed server without disturbance, and then the warm standby device is put into operation to restore M heavy hot standby redundancy, and the system is restored to a fully usable state in a short time.
[0019] Preferably, the cloud controller CiC implements the core logic operation required for train control, including safety protection curve calculation, movement authorization, line resource such as turnout, platform door state request and control.
[0020] Preferably, the cloud controller CiC has a corresponding relationship with the multifunctional IO unit at the train end, which is not fixed and can be matched according to the instructions of the train registration and distribution controller, and the corresponding train configuration parameters and electronic map are loaded according to the train information informed by the multifunctional IO unit.
[0021] The cloud controller CiC performs ultra-low latency communication with the multifunctional IO unit at the train end through wireless, obtains the current information of the train, and issues control commands including emergency braking and ATO control commands.
[0022] The cloud controller CiC obtains the line turnout position and platform door state information through the LRM, and obtains the CiC information of the front train through the LRM, and communicates with the corresponding CiC of the front train for calculating the movement authorization.
[0023] The cloud controller CiC obtains the CiC deployed on the same train through the TRAC, establishes communication with it to realize master-slave management, and determines which CiC to control the train.
[0024] Preferably, the train registration and distribution controller TRAC runs in the safe train control cloud platform, allocates multifunctional IO and CiC resources on demand, and monitors the working state of the CiC.
[0025] When a new train is put into operation, the train registration and distribution controller TRAC allocates the corresponding CiC to it, including informing the two CiCs located in the same train that they are in a redundant relationship.
[0026] The train registration and distribution controller TRAC monitors the working state of the CiC, and if a CiC fails, it can request the safe train control cloud platform to cut off the server where the faulty CiC is located and replace it with a backup server.
[0027] When the train registration and distribution controller TRAC receives the logout request of the multifunctional IO unit, it will release the corresponding CiC resources, which can be used for matching other multifunctional IO units.
[0028] Preferably, the line resource manager LRM runs in the safe train control cloud platform to realize the management and distribution of line resources and the sorting of line trains.
[0029] The line resource manager LRM obtains real-time state information of the wayside equipment through low-latency communication with the wayside IO unit, and sends a switch rotation or platform door opening and closing instruction from the CiC to the wayside IO unit;
[0030] The line resource manager LRM receives a request and a control command of the CiC on the state of the wayside equipment, when receiving a resource request of the CiC, the LRM judges whether the resource is occupied by other CiC, if not, the resource is divided to the requesting CiC, when the CiC no longer uses the resource, the LRM sets the resource as idle;
[0031] The line resource manager LRM maintains the state of all corresponding CiC of the train in the line, knows the arrangement order thereof on the line, and feeds back to all CiC;
[0032] The line resource manager LRM also needs to maintain the temporary speed limit of the whole line, and is responsible for the software and data management function of each equipment.
[0033] Preferably, the multi-functional IO unit Multi-IO is used for realizing communication with the train and a hard-wire interface, a man-machine interface display, and obtaining information of a speed sensor, a transponder antenna and a Doppler radar equipment installed on the bottom of the train.
[0034] Preferably, the multi-functional IO unit Multi-IO transmits the pulse change amount read from the speed sensor, the pulse change amount read from the Doppler radar, the transponder message, the door state and the cab activation state to the CiC in the cloud in real time and low latency, and accepts the traction and braking command of the emergency braking or automatic driving of the CiC;
[0035] The multi-functional IO unit Multi-IO obtains a control command from the CiC periodically, if the control command is not received within a set time, the Multi-IO automatically applies emergency braking to prohibit the train from moving;
[0036] The multi-functional IO unit Multi-IO has no control logic, does not store any pre-configured information, and is only a collection and control terminal of the CiC at the train control cloud platform end;
[0037] The multi-functional IO unit Multi-IO is redundantly arranged on the train.
[0038] Preferably, the wayside IO unit Wayside-IO is used for collecting the state of the wayside basic signal equipment, sending to the line resource manager located in the cloud, and informing the equipment of the control instruction of the switch action, the signal lamp on-off or the platform door opening and closing of the line resource management.
[0039] Compared with the prior art, the present application has the following advantages:
[0040] Advantage one: there are only IO devices for state collection and instruction execution in the field, which are connected to the column control system cloud through IP addresses and receive control instructions from the cloud. Since the types of field devices and boards are reduced, the complexity of maintenance is reduced.
[0041] Advantage two: core control logic, configuration data, etc. are only stored in the cloud space, separated from the underlying physical devices, and system debugging can be completed in a laboratory environment. Software and data upgrades only need to be performed in the cloud control end.
[0042] Advantage three: realize on-demand resource allocation, when extending the line, increasing trains, only need to allocate or increase computing, network and storage resources in the cloud, only increase IO devices without control logic in the field.
[0043] Advantage four: strong adaptability to different car types, because the physical models of different trains are deployed in the cloud, which can be adjusted through parameter configuration and mathematical model, and the configuration is adapted to different car types.
[0044] Advantage five: the core control unit is in the cloud, which avoids the problem that higher frequency on-board controllers cannot be selected due to hardware power consumption, heat dissipation and size limitations. The computing unit in the cloud uses faster CPUs to perform more complex calculations in a shorter time, thereby reducing the execution cycle of train control, improving system response speed, and improving train travel speed.
[0045] Advantage six: strong disaster resistance, because the control plane and user plane are completely separated, in the event of a major disaster, it can be switched between multiple cloud centers.
[0046] Advantage seven, through the M hot standby+N warm standby configuration of the cloud server, the fault recovery speed is fast, and the on-board controller with fault can be cut off in the cloud and replaced by the warm standby server, so as to recover the hot standby redundancy in a short time, avoid train emergency braking or passenger off-line.
[0047] Advantage eight, since all train control application related data and software are deployed in the cloud data center, software and data upgrade is fast and convenient, and once the upgrade fails, it can be quickly rolled back. BRIEF DESCRIPTION OF DRAWINGS
[0048] Figure 1 The figure is a schematic diagram of the overall architecture of the train control system in the embodiment of the present application;
[0049] Figure 2 The figure is a schematic diagram of the existing CBTC system architecture;
[0050] Figure 3 The figure is a layered architecture diagram of the software-defined train control system in the embodiment of the present application;
[0051] Figure 4 A schematic diagram of a multi-core server-based secure train control cloud platform in an embodiment of the present application;
[0052] Figure 5 A train registration and allocation controller (TRAC) working schematic diagram in an embodiment of the present application;
[0053] Figure 6 A line resource manager working module schematic diagram in an embodiment of the present application;
[0054] Figure 7 A vehicle-mounted multifunctional IO module architecture schematic diagram in an embodiment of the present application;
[0055] Figure 8 A cloud controller working module schematic diagram in an embodiment of the present application;
[0056] Figure 9 A train power-on and running sequence schematic diagram in an embodiment of the present application. DETAILED DESCRIPTION
[0057] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work should fall within the protection scope of the present application.
[0058] The present application proposes a software-defined train control (SDTC) system, which is a train control system scheme designed according to the idea of separating train control applications, control platforms and hardware devices, including: a cloud controller (CiC) deployed in a secure train control cloud platform, which implements core train control logic operation; a line resource manager (LRM) which implements line resource allocation and management; a train registration and allocation controller (TRAC) which implements the correspondence processing between the cloud controller and the vehicle-mounted multifunctional IO; a wayside IO unit (Wayside-IO) deployed at the trackside, which is used to implement the trackside device state acquisition and instruction issuing of devices such as turnouts, signal machines and platform doors; a multifunctional IO (Multi-IO) deployed at the train end, which is used to interface with the IO and information system of the vehicle, and forward speed sensor information; and train-ground communication is realized through a train-ground wireless communication network with ultra-wideband, low latency and large bandwidth.
[0059] The safe train control cloud platform refers to a virtualized safe platform running on a commercial multi-core server, which can isolate different cores on a multi-core processor and map them as independent CPUs to run safe application software.
[0060] Between different servers of the safe train control cloud platform, 2-to-2 combination fault safety comparison can be realized to solve the problem of random failure.
[0061] Between different servers of the safe train control cloud platform, multiple redundancies can be realized to improve system reliability.
[0062] The servers used by the safe train control cloud platform are configured according to M hot standby+N warm standby. When a server failure is detected, the hot standby device takes over the failed server without disturbance, and then the warm standby device is put into service to restore M hot standby redundancy, so that the system can be restored to a fully usable state in a short time.
[0063] The servers of the safe train control cloud platform can be deployed in the main center and the standby center, thereby realizing off-site disaster recovery redundancy.
[0064] The cloud controller CiC runs in the safe train control cloud platform and realizes the core logic operation required for train control, including safe protection curve calculation, movement authorization, line resource such as turnout and platform door state request and control, etc.
[0065] The correspondence between the cloud controller and the train-side multifunctional IO is not fixed, and can be matched according to the instructions of train registration and controller allocation, and the corresponding train configuration parameters and electronic map can be loaded according to the train information informed by the multifunctional IO.
[0066] The cloud controller performs ultra-low latency communication with the multifunctional IO module installed on the train through wireless communication, obtains the current information of the train, and issues control commands including emergency braking, ATO vehicle control instructions, etc.
[0067] The cloud controller obtains information such as turnout position and platform door state through LRM, and obtains the CiC information of the front train through LRM, and communicates with the front train CiC for calculating movement authorization.
[0068] The cloud controller obtains the CiC deployed on the same train as itself through TRAC, establishes communication with it to realize master-slave management, and determines which CiC to control the train.
[0069] As a cloud application, the CiC runs on a commercial server, and its execution speed is much higher than that of the vehicle-mounted controller under the traditional CBTC architecture, so the execution cycle can be greatly shortened and the train travel speed can be improved.
[0070] The train registration and distribution controller runs in the safe train control cloud platform, distributes multifunctional IO and CiC resources on demand, and monitors the working state of the CiC.
[0071] When a new train is put into operation, the TRAC assigns a corresponding CiC to it, including informing two CiCs located in the same train of the redundancy relationship with each other.
[0072] The train registration and distribution controller monitors the working state of the CiC, and if a CiC fails, it can request the safe train control cloud platform to cut off the server where the faulty CiC is located and replace it with a backup server, thereby improving the availability of the entire system.
[0073] If the train registration and distribution controller receives a registration request from the multifunctional IO, it will release the corresponding CiC resources, which can be used for matching other multifunctional IOs.
[0074] The line resource manager LRM runs in the safe train control cloud platform, realizes the management and distribution of line resources, and the sorting of line trains.
[0075] The line resource manager obtains real-time state information of trackside devices such as switch position and platform door state through low-latency communication with trackside IO, and sends switch rotation or platform door opening and closing instructions from the CiC to the trackside IO.
[0076] The line resource manager receives requests and control commands from the CiC for the state of the trackside devices, and when it receives a resource request from the CiC, it determines whether the resource is occupied by other CiCs, and if not, it allocates the resource to the requesting CiC; when the CiC no longer uses the resource, the LRM sets the resource as idle.
[0077] The line resource manager maintains the state of all CiCs corresponding to the trains on the line, knows their arrangement order on the line, and feeds back to all CiCs.
[0078] The line resource manager also needs to maintain temporary speed limits on the entire line, and is responsible for software and data management of various devices.
[0079] The multifunctional IO is deployed on the train to realize communication with the train, hard-wired interface, human-machine interface display, and acquisition of information from devices installed on the train floor such as speed sensors, transponder antennas, and Doppler radars.
[0080] The multifunctional IO transmits real-time and low-latency pulse change from the speed sensor, pulse change from the radar, transponder ID, door status, cab activation status, etc. to the cloud-side CiC, and accepts its emergency braking or automatic driving traction and braking commands, etc.
[0081] The multifunctional IO acquires control commands from the CiC cycle, and if no control command is received within a certain time, the MultiIO automatically applies emergency braking to prohibit train movement.
[0082] The multifunctional IO does not have control logic and does not store any information such as a preconfigured line map, and is only a collection and control terminal of the CiC at the train control cloud platform end, so that the running cycle is controlled within 20 milliseconds or less.
[0083] The multifunctional IO device is redundantly arranged on the train to improve the reliability of the system.
[0084] The wayside IO is installed on the device on the wayside, and is used to realize communication with basic signal devices such as a turnout controller, a signal machine, and a platform door.
[0085] The wayside IO is used to collect the states of the wayside basic signal devices, and send the states to the line resource manager located in the cloud, and inform the devices of the control instructions of the line resource manager, such as turnout action, signal machine on-off or platform door opening and closing.
[0086] The vehicle-ground communication ultra-wideband, low-latency, and ultra-reliable vehicle-ground wireless communication network is used to realize low-latency communication of IP end-to-end, and the communication delay time of the key system is determined and known, and is controlled within 20 milliseconds.
[0087] The software-defined train control system provided by the application virtualizes the CiC, LRM, TRAC and other systems that realize core operation functions of train control into the cloud, realizes core logic operation functions on the safe train control cloud platform, abstracts hardware devices into virtual resources, breaks the time and space limits and the barriers between systems through high-speed communication means, realizes control of all signal systems through high-reliability and high-safety cloud virtual machines, and can realize on-demand allocation of resources. Such a system can meet the high reliability and maintainability requirements of users, is easy to expand and modify, and can also reduce costs. Specific embodiments
[0089] Figure 1 The software-defined train control (SDTC) system overall architecture schematic diagram provided by the application is shown. As shown in the figure, Figure 1 As shown, the SDTC system of the embodiment of the application includes a vehicle-mounted cloud controller CiC, a line resource management controller LRM, a train registration and allocation controller TRAC arranged in a safe train control cloud platform, and a multifunctional IO unit MultiIO arranged on a train, and a wayside IO unit WaysideIO arranged on a wayside. The applications in the safe train control cloud platform can realize implementation control of the multifunctional IO on the train through low-latency and high-reliability high-speed wireless communication.
[0090] The safety control cloud platform is a virtualized safety platform running on commercial multi-core servers. Different CPU cores can be isolated on multi-core processors to run different applications. Different servers can be compared according to the implementation of 2-to-2 combination fault safety, and multiple redundancies. The control cloud platform can be deployed in the main and standby center, thereby realizing off-site disaster recovery redundancy.
[0091] The cloud controller is a software that performs core train control functions. It runs in the safety control cloud platform and implements all core logic operations required for train control, including safety protection curve calculation, movement authorization, line resource state request and control of switches, platform doors, etc. The cloud controller communicates with the multi-functional IO module installed on the train through wireless communication, obtains the current information of the train, and issues emergency braking or ATO control commands.
[0092] The train registration and distribution controller is used to realize two functions. One is to match the multi-functional IO installed on the train and the CiC located in the cloud, that is, to allocate a corresponding CiC to a new train when it is put into operation, including informing the two CiCs located in the same train that they are in a redundant relationship. The second is to monitor the working state of the CiC. If a CiC fails, it can request the safety control cloud platform to cut off the server where the faulty CiC is located and replace it with a standby server, thereby improving the availability of the entire system.
[0093] The line resource manager realizes the management and distribution of line resources. The line resource manager obtains real-time information of trackside devices such as switch position and platform door state through communication with trackside IO; at the same time, it receives requests and control commands from the CiC for the state of trackside devices and forwards them to the trackside devices; the line resource manager also needs to maintain temporary speed limits on the entire line and perform device version management and other functions.
[0094] The multi-functional IO is installed on the train to realize communication with the train and hard-wired interface, human-machine interface display, and acquisition of information from devices installed on the train floor such as speed sensors, transponder antennas, and Doppler radars. The multi-functional IO does not require complex logic operation functions, but can only communicate with various devices on the train and collect sensor state information in a short period of time, and send them to the CiC in the cloud; and send control instructions from the cloud controller to the train for execution or to the human-machine interface for display.
[0095] The trackside IO is installed on trackside devices to realize communication with basic signal devices such as switch controllers, signals, and platform doors. The state of trackside basic signal devices is collected and sent to the line resource manager located in the cloud, and control instructions for line resource management such as switch action, signal on / off, or platform door opening / closing are notified to these devices.
[0096] Figure 2 The CBTC system architecture is shown in the figure. The CBTC system architecture is mainly divided into three subsystems, namely, an ATC, an interlocking, and an ATS. Each of the subsystems has dedicated devices, including software (containing an operating system, an application, a communication protocol, etc.) and hardware (a server, a safety platform, a dedicated board, etc.). The dedicated devices in the subsystems often use internal non-standard interfaces, and the software and the hardware are tightly coupled. The safety platforms in the subsystems are often different, which brings complexity in implementation and maintenance.
[0097] However Figure 3 The figure is a layered concept diagram of the software-defined train control system in the embodiment of the present application. The software-defined train control realizes a three-layer structure of a train control application layer, a platform control layer, and an infrastructure layer, and realizes relative independence of train control system operation, control, and management. The separation of functional applications and physical devices, and the use of programmable standard interfaces between different levels, enable the infrastructure layer to interact with the platform control layer through the interfaces, and the train control application layer to interact with the platform control layer through the interfaces.
[0098] Through the layered architecture, the software-defined train control system has more flexible and easier-to-maintain characteristics than the traditional CBTC architecture. When new functions need to be added, the platform control layer and the infrastructure layer do not need to be changed, and only new applications need to be deployed or upgraded. When a line needs to be extended or a train needs to be added, only new devices need to be added to the infrastructure layer, and the control layer can allocate them to the existing application for management. Therefore, the software-defined train control system is more easily expanded in terms of functions and devices than the traditional CBTC system. Moreover, the resources in the cloud are allocated on demand, and there is no need to invest too much in the early stage. The resources can be increased as the system expands.
[0099] Figure 4 The figure is a safety train control cloud platform based on a multi-core server in the embodiment of the present application. The safety train control cloud platform is located in the platform control layer shown in the figure. Figure 3 The platform control layer is used to implement safety operations on commercial servers, avoid operation errors through a multi-core voting mechanism, and thus support execution of SIL4-level functional applications.
[0100] The figure shows four multi-core servers #1, #2, #x, and #y, each of which has multiple cores. Through a virtualization management software (Hypervisor) that can achieve SIL4 level, different cores are separated and mapped as independent CPUs to run respective virtual machine applications. On the virtual machine, a real-time operating system and corresponding train control application programs (such as CiC, LRM, and TRAC) are run to implement corresponding functions. The servers are connected through a high-speed network to implement 2-vote comparison.
[0101] Taking the on-board controller CiC as an example, as shown in the figure, Figure 4Between servers #1 and #2, and between #x and #y, the virtual machines corresponding to their respective server kernels form a 2-out-of-2 architecture onboard controller, enabling safe computation with SIL4 level functionality. Furthermore, the onboard controllers running on the two server pairs can be deployed on the same train, forming a 2x2 redundancy architecture. If one server fails, the CiC application running on the other server can control the train, preventing situations such as emergency braking that could disrupt operations.
[0102] Because the layered architecture separates the application layer from the control layer, backup servers can be located in the same data center or in a remote standby center, connected via a high-speed network and transparent to the application. This allows for migration between multiple cloud centers in the event of a major disaster, minimizing the impact on system operations.
[0103] Figure 5 This is a schematic diagram of the Train Registration and Allocation Controller (TRAC) according to an embodiment of the present invention. TRAC is used to match CiC applications in the cloud with multi-function I / O modules on the train. The TRAC application itself runs within a secure cloud platform, maintaining the correspondence between CiC applications and multi-function I / O modules. When TRAC receives registration information from the multi-function I / O module, it determines whether a corresponding CiC already exists. If not, it allocates and creates a new CiC, providing its ID for binding. Simultaneously, TRAC also manages which two CiCs are deployed on the same train and informs them of their redundancy relationships.
[0104] When TRAC determines that a CiC is down or a server is malfunctioning (e.g., CiCx-1 on server #x is malfunctioning), it needs to apply to the security control cloud platform to disconnect server #x containing that CiC and activate the backup server. Figure 5 In the process of removal and replacement, the CiC on servers #1 and #2 will operate independently, and will not cause emergency braking or other events that affect operation. After all the applications in server #z have replaced the CiC applications in the faulty server #x, the CiC of trains 1 and 2 will be restored to a 2x2 redundant architecture.
[0105] With the configuration of M hot standby + N warm standby servers, the redundancy recovery process can be completed within tens of seconds without affecting normal functions, without affecting the normal operation of the line, and without the need to remove passengers from the faulty train, thus achieving higher availability than the existing CBTC on-board system.
[0106] Figure 6The figure is a schematic diagram of a line resource manager (LRM) working module of an embodiment of the present application. The LRM runs in a secure train control cloud platform, and is responsible for managing the states of various devices (resources) on a line, the resources occupied by various trains on the line, and the sequencing relationship of the trains on the line. The states of the devices on the line are obtained through communication with trackside IOs, including the states of switch positions, signal machines, platform doors, platform emergency shutdown buttons, garage doors, etc.; and also include temporary speed limit information of the line obtained through communication with an ATS. When a resource request of a CiC is received, the LRM determines whether the resource is occupied by other CiC, and if not, the resource is allocated to the requesting CiC; and listens to the instructions of the CiC, such as controlling the actions of corresponding switches, or opening and closing platform doors, etc. When the CiC no longer uses the resource, the LRM sets the resource as idle. In addition, the LRM also maintains the sequence relationship of the trains on the line, and informs all CiCs of the sequence.
[0107] Figure 7 The figure is a schematic diagram of a vehicle-mounted multifunctional IO module architecture of an embodiment of the present application. The multifunctional IO device is installed on a train, and one set is installed at each train head and tail. The multifunctional IO device includes a network communication unit, a hibernation wakeup unit, a safety IO, a speed measurement and positioning module, a train identification plug, a human-machine interface located in the driver's cab, a speed sensor located under the vehicle body, a transponder unit, and a Doppler radar, etc. The multifunctional IO does not have complex logic operation functions, and only realizes sending the collected train IO and TCMS information, the driver's operation, and the information of the underbody sensor to the corresponding CiC in the cloud, and executing the control instructions of the cloud controller to each device on the train. The multifunctional IO obtains its corresponding relationship with the CiC through TRAC, and periodically communicates with the CiC, and when it cannot communicate with the CiC for a certain period of time, the instructions to the train are set to a full restriction state. Since there is no complex logic operation function, the operation period of the multifunctional IO device is less than 20 milliseconds, so that the execution efficiency is much higher than the 100-200 millisecond main period of the vehicle-mounted controller under the traditional CBTC architecture.
[0108] Figure 8 The figure is a schematic diagram of a cloud controller application of an embodiment of the present application. The cloud controller application runs in a secure train control cloud platform, and realizes safe logic operation and ATO train control functions through the platform.
[0109] The cloud controller obtains the train and multifunctional IO device information corresponding to itself through the TRAC, and communicates with the train to establish a train control relationship. The train state, speed measurement and balise information collected by the multifunctional IO are matched with the built-in configuration data and electronic map to obtain the positioning of the train. After obtaining the positioning, the cloud controller registers in the LRM and requests the front line resources from the LRM, and obtains the front train information according to the train sequence informed by the LRM. The CiC calculates its own movement authorization through the line resources from the LRM and the position of the front train obtained by communicating with the front train, and calculates the traction and braking instructions through the ATO train control module, and sends the instructions to the multifunctional IO for controlling the train operation. If a dangerous situation such as train overspeed or sudden opening of the front platform door is detected, the CiC sends an emergency braking instruction to the multifunctional IO to stop the train and ensure the safety of the train. In addition, the cloud controller obtains the CiC deployed on the same train as itself through the TRAC, establishes communication with the CiC to realize master-slave management, and determines which CiC to control the train.
[0110] Since the cloud controller is executed on a multi-core server and is not limited by power consumption and heat dissipation, the main frequency is generally above 3 GHz, and the operation speed is much higher than the tens to hundreds of MHz of the embedded board of the traditional CBTC architecture. Therefore, the control period of the cloud controller can be shortened from 100-200 ms of the traditional on-board controller to 20 ms, thereby obtaining a faster response time and improving the train travel speed.
[0111] Figure 9 The figure shows the power-on operation sequence of the train of the embodiment of the application. After the multifunctional IO deployed on the train is powered on, the train ID and its own IP and other information are obtained according to the train identification plug, and the TRAC is registered. The TRAC allocates the correspondence between the multifunctional IO and the CiC to establish the train control relationship between the two. After the CiC establishes communication with the multifunctional IO, the multifunctional IO reports the train state, speed sensor information, read balise information, etc. to the CiC, and the CiC establishes positioning and registers with the LRM. The CiC obtains the line resources such as switch state and front train information from the LRM, calculates its own movement authorization and ATO train control instructions, and sends the control instructions to the multifunctional IO to realize normal operation of the train. After the operation is completed, the train returns to the warehouse, and if it is to be powered off, the CiC sends a sleep instruction to the multifunctional IO to turn off the train power. At the same time, the multifunctional IO and the CiC are unregistered with the TRAC to cancel the binding relationship between them.
[0112] The above merely illustrates the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any skilled person in the art can easily think of various equivalent modifications or replacements within the technical range disclosed by the present application, and these modifications or replacements shall be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A rail transit train control system, characterized in that, include: The safe train control cloud platform includes a cloud controller CiC for implementing core train control logic operations, a line resource manager LRM for allocating and managing line resources, and a train registration and allocation controller TRAC for processing the correspondence between the cloud controller and onboard multi-functional I / O. The Wayside-IO unit is deployed on the trackside and is used to acquire the status of trackside equipment and issue commands. Multi-IO, deployed on the train, enables communication between the cloud controller and the vehicle; The correspondence between the cloud controller CiC and the multi-functional IO unit on the train is not fixed. It can be matched according to the instructions of train registration and controller allocation, and the corresponding train configuration parameters and electronic map can be loaded according to the train information provided by the multi-functional IO unit. The cloud controller CiC communicates with the multi-functional IO unit on the train via wireless communication with ultra-low latency to obtain the current information of the train and issue control commands, including emergency braking and ATO train control instructions. The cloud controller CiC obtains track switch position and platform door status information through LRM, and obtains CiC information of the train ahead through LRM, and communicates with the CiC of the train ahead to calculate movement authorization; The cloud controller CiC learns about other CiCs deployed on the same train through TRAC, establishes communication with them to achieve master-slave management, and determines which CiC will control the train. The train registration and allocation controller TRAC runs within the safe train control cloud platform, allocating multi-functional IO and CiC resources as needed and monitoring the working status of the CiC. When a new train is put into operation, the Train Registration and Allocation Controller (TRAC) assigns it a corresponding CiC, including informing that two CiCs located on the same train are redundant. The Train Registration and Assignment Controller (TRAC) monitors the working status of CiCs. If a CiC fails, it can request the Safety Train Control Cloud Platform to disconnect the server where the failed CiC is located and replace it with a backup server. When the Train Registration and Allocation Controller (TRAC) receives a deregistration request from a multi-function I / O unit, it will release the corresponding CiC resources, which can then be used for matching with other multi-function I / O units. The aforementioned secure train control cloud platform includes multiple different multi-core servers for implementing 2-out-of-2 combination fault safety comparison. Each multi-core server isolates different cores and maps them as independent CPUs to run secure application software. The servers of the secure train control cloud platform can be deployed in the primary center and the backup center. The servers used in the aforementioned secure train control cloud platform are configured with M hot standby servers and N warm standby servers. When a server failure is detected, the hot standby devices first take over the faulty server without interruption, and then the warm standby devices are put into operation to restore M layers of hot standby redundancy, so that the system can be restored to a fully usable state in a short time. On-site, there are only I / O devices used for status acquisition and command execution. The core control unit is in the cloud, and the core control logic and configuration data are only stored in the cloud space.
2. A rail transit train control system according to claim 1, characterized in that, The cloud controller CiC performs the core logic operations required for train control, including safety protection curve calculation, movement authorization, line resource status request and control.
3. A rail transit train control system according to claim 1, characterized in that, The Line Resource Manager (LRM) runs within the safety train control cloud platform, enabling the management and allocation of line resources, as well as the sequencing of trains on the line. The Line Resource Manager (LRM) obtains real-time status information of trackside equipment through low-latency communication with the trackside I / O unit, and sends turnout rotation or platform door opening / closing commands from CiC to the trackside I / O unit. The Line Resource Manager (LRM) receives requests and control commands from CiCs regarding the status of trackside equipment. When a CiC requests a resource, the LRM determines whether the resource is occupied by another CiC. If not, the resource is allocated to the requesting CiC. When a CiC no longer uses the resource, the LRM sets the resource to idle. The Line Resource Manager (LRM) maintains the status of all CiCs corresponding to all trains on the line, knows their order of arrangement on the line, and feeds it back to all CiCs. The Line Resource Manager (LRM) also needs to maintain temporary rate limits across the entire line and is responsible for the software and data management functions of each device.
4. A rail transit train control system according to claim 1, characterized in that, The Multi-IO unit is used to realize communication with the train and hard-wired interface, human-machine interface display, and to acquire information from speed sensors, transponder antennas, and Doppler radar equipment installed under the vehicle.
5. A rail transit train control system according to claim 4, characterized in that, The Multi-IO unit transmits the pulse change readings from the speed sensor, the pulse change readings from the Doppler radar, the transponder messages, the door status, and the driver's cab activation status to the CiC in the cloud in real time with low latency, and receives traction and braking commands from the CiC for emergency braking or autonomous driving. The Multi-IO unit obtains control commands from the CiC cycle. If no control command is received within a set time, the Multi-IO automatically applies emergency braking to prevent the train from moving. The Multi-IO unit has no control logic and does not store any pre-configured information; it is simply the acquisition and control terminal of the CiC on the train control cloud platform. The aforementioned Multi-IO unit is redundantly configured on the train.
6. A rail transit train control system according to claim 1, characterized in that, The Wayside-IO unit is used to collect the status of the trackside basic signaling equipment, send it to the line resource manager located in the cloud, and inform these devices of the control commands for turnout operation, signal on / off, or platform door opening / closing of the line resource manager.
Citation Information
Patent Citations
Rail transit train control system
CN211519529U
Method & apparatus for a train control system
US20150232110A1