A rail transit signal security cloud deployment method supporting hybrid demanding and faulty operation characteristics

By setting up multiple independent private cloud areas in the rail transit signal security cloud, supporting signal applications of different demanding levels, and realizing regional mode conversion and upgrading in the case of failure, the problem of failing to effectively support the mixed demanding and fault operation characteristics in the existing technology is solved, and efficient and secure cloud deployment of the rail transit signal system is achieved.

CN115914265BActive Publication Date: 2025-05-13BEIJING JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211607655.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-14
Publication Date
2025-05-13
Estimated Expiration
2042-12-14

AI Technical Summary

Technical Problem

When the existing technology migrates the rail transit signal system to the cloud computing platform, it fails to effectively support the hybrid demands and fault operation characteristics, which may lead to cloud computing failures that cause large-scale or global paralysis of rail transit.

Method used

A rail transit signal security cloud deployment method that supports mixed demanding and fault operation characteristics is proposed. By setting the rail transit signal security cloud into multiple independent private cloud areas, each area including active area, passive backup area and other active areas, it adopts different management, computing and storage node architectures to support signal applications of different demanding levels, and realizes the conversion and upgrading of regional modes in the event of failure.

Benefits of technology

It effectively improves the processing performance of rail transit signal safety, meets the requirements of safety standards such as IEC61508 or EN50126, EN50128, EN50129 and third-party safety assessment, and ensures the stability and safety of rail transit signal systems in the case of mixed demands and fault operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115914265B_ABST
    Figure CN115914265B_ABST
Patent Text Reader

Abstract

The present invention provides a method for deploying a rail transit (railway transit) signal safety cloud that supports hybrid demanding and faulty operation characteristics. The method includes: setting the rail transit signal safety cloud to multiple areas, each area is an independent private cloud, the private cloud includes a first activity area PAZ, a passive backup area PSZ and other activity areas OAZ, setting the rail transit signal safety cloud to support different demanding level requirements, each demanding level requirement corresponds to a variety of different signal applications, and each area uses an independent management node, computing node and storage node architecture. The demanding levels include SIL4, SIL2 and SIL0, and the other activity areas OAZ include the second activity area SAZ, the third activity area TAZ and the fourth activity area QAZ. The present invention provides a deployment method for a rail transit signal safety cloud that supports hybrid demanding and faulty operation characteristics, so that the rail transit signal safety cloud can meet the requirements of safety standards such as IEC61508 or EN50126, EN50128, EN50129 and third-party safety assessments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of rail transit (railway transportation) signal systems, and in particular to a rail transit signal security cloud deployment method supporting hybrid demanding and faulty operation characteristics. Background Art

[0002] The traditional rail transit signal system structure is based on the superposition principle. Different signal subsystems, different signal control functions, and even signal subsystems in different locations are superimposed to form the entire rail transit signal system. This brings a benefit: failures in local signal subsystems and subsystems generally have little impact on the overall operation of rail transit. If different signal subsystems, different signal control functions, and signal subsystems in different locations are simply migrated to the cloud, cloud computing failures may cause large-scale or even global paralysis of rail transit.

[0003] At present, relevant manufacturers or institutions at home and abroad are studying how to deploy traditional rail transit signal applications on cloud computing platforms. For example, there are solutions in the existing technology that propose a "next-generation signal system based on cloud platform", a rail transit train operation control system based on cloud computing, a method for implementing edge security nodes of train control systems based on cloud computing, a method for edge security nodes to logically monitor programs deployed and running on the cloud, and a method for edge security nodes to time monitor programs deployed and running on the cloud.

[0004] The disadvantages of the above-mentioned solutions in the prior art include: these solutions only discuss the support issues of SIL4 and the details of safety assurance, and do not emphasize the support of mixed demanding characteristics, and do not discuss the problem of fault operation. Summary of the invention

[0005] An embodiment of the present invention provides a rail transit signal safety cloud deployment method that supports mixed demanding and faulty operation characteristics, so as to effectively improve the processing performance of rail transit signal safety.

[0006] In order to achieve the above object, the present invention adopts the following technical scheme.

[0007] A rail transit signal safety cloud deployment method supporting mixed demanding and faulty operation characteristics, comprising:

[0008] The rail transit signal safety cloud is set to multiple areas, each area is an independent private cloud, the private cloud includes the first activity area PAZ, the passive backup area PSZ and the other activity area OAZ, and the rail transit signal safety cloud is set to support different demanding level requirements, each demanding level requirement corresponds to a variety of different signal applications, and each area adopts an independent management node, computing node and storage node architecture;

[0009] The demanding levels include SIL4, SIL2 and SIL0, and the other active areas OAZ include a second active area SAZ, a third active area TAZ and a fourth active area QAZ.

[0010] Preferably, the PAZ and OAZ not only start the cloud and virtual machine software, but also start the signal application. The signal application supported by PAZ has output; OAZ supports the signal application with output or without output depending on the specific configuration; PSZ only starts the cloud and virtual machine software, does not start the signal application, and the supported signal application has no output.

[0011] Preferably, each zone is in one of the three modes of PAZ, OAZ and PSZ respectively. After a failure occurs in the PAZ mode or the OAZ mode and the PAZ mode or the OAZ mode is restarted, the PAZ mode or the OAZ mode is converted to the PSZ mode.

[0012] When a failure occurs in PAZ mode or OAZ mode, PSZ mode is upgraded to PAZ mode or OAZ mode;

[0013] After a failure occurs in the PAZ mode, the OAZ mode is upgraded to the PAZ mode.

[0014] Preferably, each computing node in the different regions starts a corresponding number of virtual machines VM according to the number of signal applications of different demanding levels SIL4, SIL2, and SIL0 supported, and each VM is configured with a Guest OS, a secure computer platform software, and a signal application software controlled by it;

[0015] When the VM on the computing node supports a SIL4 or SIL2 signal application, a fixed resource allocation principle is adopted, which includes that the virtual CPU and memory resources must not be over-allocated, a SIL4 or SIL2 signal application is physically bound to the virtual CPU and memory resources allocated to it, the private cloud is not allowed to perform dynamic allocation, and the automatic migration function of the virtual machine of the private cloud must be turned off;

[0016] When the VM on the computing node supports the signal application of SIL0, the private cloud resource dynamic allocation principle is adopted. The private cloud resource dynamic allocation principle includes: virtual CPU and memory resources can be over-allocated, a SIL0 signal application is not physically bound to the virtual CPU and memory resources allocated to it, the private cloud is allowed to perform dynamic allocation, and the automatic migration function of the private cloud virtual machine is supported.

[0017] Preferably, when the rail transit signal safety cloud supports signal applications with demanding level SIL4, a configuration scheme of 1 PAZ+1 SAZ+1 PSZ is adopted; or, a configuration scheme of 1 PAZ+1 SAZ+1 TAZ+1 PSZ is adopted; or, a configuration scheme of 1 PAZ+1 SAZ+1 TAZ+1 QAZ+1 PSZ is adopted. The above configuration schemes all require external dedicated voters, and the voters are respectively connected to the dual redundant external network interfaces and the signal communication network of the corresponding areas. Communication between voters and communication with SIL4 independent signal equipment are completed through the signal communication network.

[0018] Preferably, when the rail transit signal safety cloud supports signal applications with demanding level SIL2, a configuration scheme of 1 PAZ+1 SAZ+1 PSZ is adopted. The configuration scheme requires an external dedicated fault-tolerant and safety manager FTSM. The FTSM is respectively connected to the dual redundant external network interface and the signal communication network of the corresponding area. The communication between the FTSMs and the communication with other related signal equipment are completed through the signal communication network.

[0019] Preferably, when the signal safety cloud supports SIL0 signal applications, if the SIL0 signal application allows application interruption for a long time, a configuration scheme of 1 PAZ+1 PSZ is adopted; if the SIL0 signal application does not allow application interruption for a long time, a configuration scheme of 1 PAZ+1 SAZ+1 PSZ is adopted.

[0020] It can be seen from the technical solutions provided by the above-mentioned embodiments of the present invention that the present invention provides a deployment method for a rail transit signal safety cloud that supports mixed requirements and fault operation characteristics, so that the rail transit signal safety cloud can meet the requirements of safety standards such as IEC61508 or EN50126, EN50128, EN50129 and third-party safety assessments.

[0021] Additional aspects and advantages of the present invention will be given in part in the following description, which will become obvious from the following description, or may be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0023] Figure 1 A schematic diagram of the area structure included in a rail transit signal safety cloud provided in an embodiment of the present invention;

[0024] Figure 2 A possible logical architecture diagram of a private cloud used in each region provided in an embodiment of the present invention;

[0025] Figure 3 A conceptual diagram of the principle of signal application of a computing node (cluster) supporting different demanding levels provided by an embodiment of the present invention;

[0026] Figure 4 A schematic diagram of a configuration scheme of 1 PAZ+1 SAZ+1 PSZ when a signal safety cloud supports SIL4 signal application provided by an embodiment of the present invention;

[0027] Figure 5 A schematic diagram of a configuration scheme of 1 PAZ+1 SAZ+1 TAZ+1 PSZ when a signal safety cloud supports SIL4 signal application provided by an embodiment of the present invention;

[0028] Figure 6 A schematic diagram of a configuration scheme of 1 PAZ+1 SAZ+1 TAZ+1 QAZ+1 PSZ for a signal safety cloud supporting SIL4 signal application provided by an embodiment of the present invention;

[0029] Figure 7 A schematic diagram of a configuration scheme of 1 PAZ+1 SAZ+1 PSZ for a signal safety cloud supporting SIL2 signal applications provided by an embodiment of the present invention;

[0030] Figure 8 A schematic diagram of a configuration scheme of 1 PAZ + 1 PSZ when a signal security cloud supports SIL0 signal application provided by an embodiment of the present invention;

[0031] Fig. 9 A schematic diagram of a configuration scheme of 1 PAZ+1 SAZ+1 PSZ is provided for a signal security cloud supporting SIL0 signal applications in an embodiment of the present invention. DETAILED DESCRIPTION

[0032] The embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and cannot be interpreted as limiting the present invention.

[0033] It will be understood by those skilled in the art that, unless expressly stated, the singular forms "one", "said", and "the" used herein may also include plural forms. It should be further understood that the term "comprising" used in the specification of the present invention refers to the presence of the features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. It should be understood that when we refer to an element as being "connected" or "coupled" to another element, it may be directly connected or coupled to the other element, or there may be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or coupling. The term "and / or" used herein includes any unit and all combinations of one or more associated listed items.

[0034] It will be understood by those skilled in the art that, unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as those generally understood by those skilled in the art in the art to which the present invention belongs. It should also be understood that terms such as those defined in common dictionaries should be understood to have meanings consistent with the meanings in the context of the prior art, and will not be interpreted with idealized or overly formal meanings unless defined as herein.

[0035] To facilitate understanding of the embodiments of the present invention, several specific embodiments will be further explained below with reference to the accompanying drawings, and each embodiment does not constitute a limitation on the embodiments of the present invention.

[0036] The rail transit signal safety cloud supports signal applications with different criticality levels, thereby supporting mixed-criticality characteristics. Each criticality level requirement can correspond to a variety of different signal applications, and the preferred criticality levels include SIL4, SIL2, and SIL0. In order to meet the fail-operational characteristics, the rail transit signal safety cloud sets up multiple areas, each of which is an independent private cloud. The private cloud includes a primary active zone (PAZ), a passive standby zone (PSZ), and a corresponding number of other active zones (OAZ) configured according to the different level requirements of SIL4, SIL2, and SIL0, such as: a second active zone (SAZ), a third active zone (TAZ), a fourth active zone (QAZ), etc.

[0037] A schematic diagram of the area structure included in a rail transit signal safety cloud provided by an embodiment of the present invention is as follows: Figure 1 As shown in the figure, PAZ and OAZ not only start the cloud and virtual machine software, but also start the signal application. The signal application supported by PAZ has output; OAZ can support signal applications with or without output according to the specific configuration; PSZ only starts the cloud and virtual machine software, but does not start the signal application, and the signal application it supports has no output.

[0038] Each area can be in one of the three modes: PAZ, OAZ, and PSZ, and the mode conversion can be performed depending on the specific situation: if a failure occurs in PAZ or OAZ mode, it can be changed to PSZ mode after restart; if a failure occurs in PAZ or OAZ mode, PSZ can be upgraded to PAZ or OAZ mode.

[0039] Mode conversion between PAZ or OAZ mode: If PAZ fails, OAZ will be upgraded to PAZ. Timed mode conversion between PAZ, OAZ and PSZ is performed under human control to prevent hidden faults caused by long-term mode non-conversion.

[0040] Each area is an independent private cloud, using an independent management node, computing node, and storage node architecture. The computing nodes and storage nodes are scalable. The embodiment of the present invention provides a possible logical architecture of a private cloud used in each area as follows: Figure 2 As shown, the external network interface of each area (connected through a service switch) preferably has a dual redundant connection mode.

[0041] 2. Each computing node (cluster) in the different areas starts a corresponding number of virtual machines according to the number of signal applications of different demanding levels SIL4, SIL2, and SIL0 supported. Each virtual machine (VM) is configured with a Guest OS, a secure computer platform software, and one signal application software controlled by it. Figure 3A conceptual diagram of the principle of a computing node (cluster) supporting signal applications of different demanding levels provided by an embodiment of the present invention. When a virtual machine on a computing node supports a SIL4 or SIL2 signal application, a fixed resource allocation principle is adopted to meet the deterministic requirements necessary for functional safety. The fixed resource allocation principle is that virtual CPU (vCPU) and memory resources must not be over-allocated (exceeding the number of physical vCPUs and physical memory capacity when allocating resources), and the server cluster size of the computing node should be expanded if resources are insufficient. A SIL4 or SIL2 signal application is physically bound to the virtual CPU (vCPU) and memory resources allocated to it (especially for vCPU, a SIL4 or SIL2 signal application should be bound to a specific one or more cores of a specific central processing unit CPU of a specific server), and the private cloud is not allowed to be dynamically allocated, and the automatic migration function of the virtual machine of the private cloud must be turned off.

[0042] When the virtual machine on the computing node supports the signal application of SIL0, the general private cloud resource dynamic allocation principle is adopted: the virtual CPU (vCPU) and memory resources can be over-divided, and the signal application of a SIL0 is not physically bound to the virtual CPU (vCPU) and memory resources allocated to it, allowing the private cloud to perform dynamic allocation and support the automatic migration function of the private cloud virtual machine.

[0043] Preferably, the virtual machines on the computing nodes that support SIL4 or SIL2 signal applications are reinforced in real time, and measures include but are not limited to: installing real-time patches or kits on the Host and Guest OS; dividing the virtual machine software into groups of different priorities according to the level of demandingness and the control cycle; allocating the same priority to virtual machines corresponding to signal applications of the same level of demandingness and control cycle, etc.

[0044] 3. When the rail transit signal safety cloud supports the signal application of the demanding level SIL4, a configuration scheme of 1 PAZ+1 SAZ+1 PSZ, or a configuration scheme of 1 PAZ+1 SAZ+1 TAZ+1 PSZ, or a configuration scheme of 1 PAZ+1 SAZ+1 TAZ+1 QAZ+1 PSZ should be adopted. The above configuration schemes all require external dedicated voters (Voter), and the Voters are respectively connected to the dual redundant external network interface and the signal communication network of the corresponding area. The signal communication network preferably adopts a dual redundant setting. Communication between Voters and communication with SIL4 independent signal equipment (such as: object controller (OC)) can be completed through the signal communication network.

[0045] (i) The dedicated voter (Voter) should be implemented based on an embedded secure computer platform with a MooN (N≥2, N≥M) logical architecture. Preferably, the Voter is implemented based on an embedded secure computer platform with a 2-out-of-2 or 3-out-of-2 architecture.

[0046] (ii) The computing nodes should support heterogeneous architectures, and the computing node heterogeneity preferably adopts a physical CPU / Guest OS heterogeneous mode; the computing nodes are responsible for providing virtual computing resources, that is, each computing node starts i virtual machines according to the number i of SIL4 signal applications supported; an N out of M (MooN, N≥2, N≥M) logical architecture is constructed based on N heterogeneous computing nodes, so that all N computing nodes start a total of N*i virtual machines, and the N*i virtual machines started by the N computing nodes constitute i N out of M logical architectures, and it is preferred that each N out of M logical architecture of the N*i virtual machines is used in conjunction with a dedicated voter.

[0047] Preferably, if Figure 2 As shown, the computing nodes select servers based on ARM and X86 CPU respectively, so that a 2-out-of-2 logical architecture is formed based on two heterogeneous processors (ARM architecture and X86 architecture). Considering that each computing node starts i virtual machines according to the number of signal applications i supported, the above two computing nodes start a total of 2*i virtual machines. Each 2-out-of-2 logical architecture in the 2*i virtual machines is used in conjunction with a dedicated voter (Voter), and a total of i Voters need to be set up. The Voter is implemented based on an embedded security computer platform that adopts a 2-out-of-2 or 3-out-of-2 architecture.

[0048] The principle block diagram of a signal safety cloud supporting SIL4 signal application using 1 PAZ+1 SAZ+1 PSZ is as follows: Figure 4 When using Figure 4In the configuration scheme of 1 PAZ+1 SAZ+1 PSZ shown in the figure, for each signal application, the N signal application virtual machines of PAZ constitute an N out of M logical architecture, and the N signal application virtual machines of SAZ also constitute an N out of M logical architecture. PSZ only starts the cloud and virtual machine software, and does not start the signal application. It is actually a warm backup (Warm Backup) configuration mode. In this way, the configuration mode of 1 PAZ+1 SAZ+1 PSZ is actually equivalent to a 2 times N out of M+1 warm backup (preferably 2 times 2 out of 2+1 warm backup). At this time, PAZ, SAZ, and PSZ are respectively in the active or hot backup mode, hot backup or active mode, and warm backup mode. The active mode and hot backup mode can be converted to each other. If a problem occurs in PAZ or SAZ, the virtual machine can be restarted to enter the warm backup mode and become PSZ. PSZ can also be upgraded to the active mode or hot backup mode and become PAZ or SAZ. PAZ, SAZ, and PSZ also support timed mutual conversion mode to avoid mode switching failure.

[0049] (Four) Figure 5 A schematic diagram of a signal safety cloud supporting SIL4 signal application using 1 PAZ+1 SAZ+1 TAZ+1 PSZ configuration scheme provided in an embodiment of the present invention. Figure 5 In the configuration scheme of 1 PAZ+1 SAZ+1 TAZ+1 PSZ shown in the figure, for each signal application, the N signal application virtual machines of PAZ constitute an N-out-of-M logical architecture, the N signal application virtual machines of SAZ also constitute an N-out-of-M logical architecture, and the N signal application virtual machines of TAZ also constitute an N-out-of-M logical architecture. PSZ only starts the cloud and virtual machine software, and does not start the signal application. It is actually a warm backup (WarmBackup) configuration mode. In this way, the configuration mode of 1 PAZ+1 SAZ+1 TAZ+1 PSZ is actually equivalent to a 3 times N-out-of-M+1 warm backup (preferably 3 times 2-out-of-2+1 warm backup). At this time, PAZ, SAZ, TAZ, and PSZ are in the active mode, active mode, active mode, and warm backup mode, respectively. If problems occur in PAZ, SAZ, and TAZ, the virtual machine can be restarted to enter the warm backup mode and become PSZ. PSZ can also be upgraded to the active mode and become PAZ, SAZ, and TAZ. PAZ, SAZ, TAZ, and PSZ also support timed conversion modes to avoid mode switching failure.

[0050] (five) Figure 6 A schematic diagram of a signal security cloud supporting SIL4 signal application using 1 PAZ+1 SAZ+1 TAZ+1 QAZ+1 PSZ configuration scheme provided in an embodiment of the present invention. Figure 6In the configuration scheme of 1 PAZ+1 SAZ+1 TAZ+1 QAZ+1 PSZ shown in the figure, for each signal application, the N signal application virtual machines of PAZ constitute an N out of M logical architecture, the N signal application virtual machines of SAZ also constitute an N out of M logical architecture, the N signal application virtual machines of TAZ also constitute an N out of M logical architecture, and the N signal application virtual machines of QAZ also constitute an N out of M logical architecture. PSZ only starts the cloud and virtual machine software, and does not start the signal application. It is actually a warm standby (Warm Standby). Backup) configuration mode, so the configuration mode of 1 PAZ+1 SAZ+1 TAZ+1 QAZ+1 PSZ is actually equivalent to a 4 times N take M+1 warm standby (preferably 4 times 2 take 2+1 warm standby), at this time PAZ, SAZ, TAZ, QAZ, PSZ are in active mode, active mode, active mode, active mode, warm standby mode respectively, among which, if PAZ, SAZ, TAZ, QAZ have problems, the virtual machine can be restarted to enter warm standby mode and become PSZ, PSZ can also be upgraded to active mode and become PAZ, SAZ, TAZ, QAZ. PAZ, SAZ, TAZ, QAZ, PSZ also support timed mutual conversion mode to avoid mode switching failure.

[0051] 4. Figure 7 This is a schematic diagram of a signal safety cloud supporting SIL2 signal applications using 1 PAZ+1 SAZ+1 PSZ configuration scheme provided by an embodiment of the present invention. When the rail transit signal safety cloud supports the application of demanding level SIL2 signals, the following should be used: Figure 7 The configuration scheme of 1 PAZ+1 SAZ+1 PSZ shown in the figure requires an external dedicated fault tolerance and safety manager (FTSM), which is respectively connected to the dual redundant external network interface and signal communication network of the corresponding area. The signal communication network is preferably a dual redundant setting mode, and the communication between the FTSMs and the communication with other related signal equipment can be completed through the signal communication network.

[0052] (i) The dedicated fault-tolerant and safety manager (FTSM) is implemented based on an embedded safety computer platform that meets the SIL2 safety performance index.

[0053] (ii) The computing node is responsible for providing virtual computing resources, that is, each computing node starts i virtual machines according to the number i of SIL2 signal applications supported, and preferably each of the i SIL2 signal applications supported by the i virtual machines is used in conjunction with a dedicated fault tolerance and safety manager (FTSM).

[0054] (III) For each signal application, PAZ and SAZ both support active signal applications, while PSZ only starts the cloud and virtual machine software, not the signal application, which is actually a warm backup configuration mode. In this way, the configuration mode of 1 PAZ+1 SAZ+1 PSZ is actually equivalent to a 2x+1 warm backup. At this time, PAZ, SAZ, and PSZ are respectively in active or hot backup mode, hot backup or active mode, and warm backup mode. The active mode and hot backup mode can be converted to each other. If a problem occurs in PAZ or SAZ, the virtual machine can be restarted to enter the warm backup mode and become PSZ. PSZ can also be upgraded to active mode or hot backup mode and become PAZ or SAZ. PAZ, SAZ, and PSZ also support timed conversion modes to avoid mode switching failure.

[0055] 5. Figure 8 This is a schematic diagram of a signal safety cloud supporting SIL0 signal applications using 1 PAZ + 1 PSZ configuration scheme provided by an embodiment of the present invention. When the rail transit signal safety cloud supports the application of demanding level SIL0 signals, if the SIL0 signal application allows a long application interruption (more than tens of seconds), the following can be used Figure 8 For the configuration scheme of 1 PAZ + 1 PSZ shown in the figure, if the SIL0 signal application does not allow the application to be interrupted for a long time (more than tens of seconds), the following configuration scheme should be adopted: Fig. 9 The configuration scheme shown is 1 PAZ + 1 SAZ + 1 PSZ.

[0056] Under the two configuration schemes described above, the computing node is responsible for providing virtual computing resources, that is, each computing node starts i virtual machines according to the number of SIL0 signal applications i supported. No external dedicated equipment is required, and network isolation equipment such as routers or three-level switches can be set between the dual redundant external network interface and the signal communication network of the corresponding area. The signal communication network preferably adopts a dual redundant setting mode.

[0057] When using the configuration scheme of 1 PAZ + 1 PSZ, the virtual machines in the PAZ must support the automatic migration function. For each signal application, the PAZ supports the active signal application, while the PSZ only starts the cloud and virtual machine software, not the signal application. It is actually a warm backup configuration mode. In this way, the configuration mode of 1 PAZ + 1 PSZ is actually equivalent to a +1 warm backup. At this time, the PAZ and PSZ are in the active mode and warm backup mode respectively. If a problem occurs in the PAZ, the virtual machine can be restarted to enter the warm backup mode and become the PSZ. The PSZ can also be upgraded to the active mode and become the PAZ. PAZ and PSZ also support timed conversion modes to avoid mode switching failure.

[0058] In the above configuration scheme of 1 PAZ + 1 PSZ, the virtual machines in the PAZ need to support the automatic migration function, but automatic migration generally takes a long time (tens of seconds), and it takes even longer for the PSZ to upgrade to the primary mode. If the SIL0 signal application does not allow the application to be interrupted for such a long time, the following should be used Fig. 9 The configuration scheme of 1 PAZ+1 SAZ+1 PSZ is shown. At this time, for each signal application, PAZ and SAZ both support active signal applications, while PSZ only starts the cloud and virtual machine software, not the signal application, which is actually a warm backup configuration mode. In this way, the configuration mode of 1 PAZ+1 SAZ+1 PSZ is actually equivalent to a 2x+1 warm backup. At this time, PAZ, SAZ, and PSZ are respectively in active or hot backup mode, hot backup or active mode, and warm backup mode. The active mode and hot backup mode can be converted to each other. If there is a problem with PAZ or SAZ, the virtual machine can be restarted to enter the warm backup mode and become PSZ. PSZ can also be upgraded to active mode or hot backup mode and become PAZ or SAZ. PAZ, SAZ, and PSZ also support timed mutual conversion mode to avoid mode switching failure.

[0059] In summary, the embodiments of the present invention provide a deployment method for a rail transit signal safety cloud that supports mixed-criticality and fail-operational characteristics, so that the rail transit signal safety cloud can meet the requirements of safety standards such as IEC61508 or EN50126, EN50128, EN50129 and third-party safety assessments.

[0060] The method of the present invention provides a deployment method for a rail transit (rail transit) signal security cloud that supports mixed-criticality and fail-operational characteristics while first meeting the security requirements and also meeting the reliability, availability, and maintainability requirements. Taking into account our authorized invention patent 201910250258, X (a rail transit train operation control system based on cloud computing) and 3 published invention patent application documents 202110104354, 0 (a method for implementing an edge security node of a train control system based on cloud computing), 202110105675, 2 (a method for edge security nodes to logically monitor programs deployed and running on the cloud), and 202110104352, 1 (a method for edge security nodes to time monitor programs deployed and running on the cloud), plus the comprehensive coverage of this application, our intellectual property protection for rail transit (rail transit) signal security cloud is more complete.

[0061] Those skilled in the art can understand that the accompanying drawings are only schematic diagrams of an embodiment, and the modules or processes in the accompanying drawings are not necessarily required to implement the present invention.

[0062] It can be known from the description of the above implementation methods that those skilled in the art can clearly understand that the present invention can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which can be stored in a storage medium such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present invention or certain parts of the embodiments.

[0063] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments.

[0064] In particular, for the device or system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments. The device and system embodiments described above are only exemplary, wherein the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units.

[0065] Part or all of the modules may be selected according to actual needs to achieve the purpose of solution 0 of this embodiment. A person skilled in the art may understand and implement the invention without creative work.

[0066] The above description is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can

[0067] Any changes or substitutions that can be easily thought of should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention 5 should be based on the protection scope of the claims.

Claims

1. A rail transit signal safety cloud deployment method supporting hybrid demanding and faulty operation characteristics, characterized in that: include: The rail transit signal safety cloud is set to multiple areas, each area is an independent private cloud, the private cloud includes the first activity area PAZ, the passive backup area PSZ and the other activity area OAZ, and the rail transit signal safety cloud is set to support different demanding level requirements, each demanding level requirement corresponds to a variety of different signal applications, and each area adopts an independent management node, computing node and storage node architecture; The demandingness levels include SIL4, SIL2 and SIL0, and the other active areas OAZ include a second active area SAZ, a third active area TAZ and a fourth active area QAZ; The PAZ and OAZ start the cloud and virtual machine software, start the signal application, and the signal application supported by PAZ has output; OAZ supports the signal application with output or without output according to the specific configuration; PSZ only starts the cloud and virtual machine software, does not start the signal application, and the supported signal application has no output; Each area is in one of the three modes: PAZ, OAZ and PSZ. After a failure occurs in the PAZ mode or OAZ mode and the mode is restarted, the PAZ mode or OAZ mode is converted to the PSZ mode. When a failure occurs in PAZ mode or OAZ mode, PSZ mode is upgraded to PAZ mode or OAZ mode; When a failure occurs in PAZ mode, OAZ mode is upgraded to PAZ mode; Each computing node in different areas starts a corresponding number of virtual machines (VMs) according to the number of signal applications with different demanding levels (SIL4, SIL2, and SIL0) supported. Each VM is configured with a Guest OS, a secure computer platform software, and a signal application software controlled by it. When the VM on the computing node supports a SIL4 or SIL2 signal application, a fixed resource allocation principle is adopted, which includes that the virtual CPU and memory resources must not be over-allocated, a SIL4 or SIL2 signal application is physically bound to the virtual CPU and memory resources allocated to it, the private cloud is not allowed to perform dynamic allocation, and the automatic migration function of the virtual machine of the private cloud must be turned off; When the VM on the computing node supports the signal application of SIL0, the private cloud resource dynamic allocation principle is adopted. The private cloud resource dynamic allocation principle includes: virtual CPU and memory resources can be over-allocated, a SIL0 signal application is not physically bound to the virtual CPU and memory resources allocated to it, the private cloud is allowed to perform dynamic allocation, and the automatic migration function of the private cloud virtual machine is supported.

2. The method according to claim 1, characterized in that When the rail transit signal safety cloud supports signal applications with demanding level SIL4, a configuration scheme of 1 PAZ + 1 SAZ + 1 PSZ is adopted; or a configuration scheme of 1 PAZ + 1 SAZ + 1 TAZ + 1 PSZ is adopted; or a configuration scheme of 1 PAZ + 1 SAZ + 1 TAZ + 1 QAZ + 1 PSZ is adopted. The above configuration schemes all require external dedicated voters, and the voters are respectively connected to the dual redundant external network interfaces and the signal communication network of the corresponding areas. The communication between voters and the communication with the SIL4 independent signal equipment are completed through the signal communication network.

3. The method according to claim 1 or 2, characterized in that: When the rail transit signal safety cloud supports signal applications with demanding level SIL2, a configuration scheme of 1 PAZ + 1 SAZ + 1 PSZ is adopted. The configuration scheme requires an external dedicated fault-tolerant and safety manager FTSM. The FTSM is connected to the dual redundant external network interface and signal communication network of the corresponding area respectively. The communication between the FTSMs and the communication with other related signal equipment are completed through the signal communication network.

4. The method according to claim 1 or 2, characterized in that: When the rail transit signal safety cloud supports SIL0 signal applications, if the SIL0 signal application allows application interruptions for a long time, a configuration scheme of 1 PAZ + 1 PSZ is adopted. If the SIL0 signal application does not allow application interruptions for a long time, a configuration scheme of 1 PAZ + 1 SAZ + 1 PSZ is adopted.

Citation Information

Patent Citations

  • Rail transit train control system

    CN110920696A

  • Method and system for keeping network port safe output of SIL4 equipment and electronic device

    CN113395256A