A method for checking the security of message data in a train control center
Patent Information
- Application Number
- CN202311631990.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-30
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2043-11-30
AI Technical Summary
[0003]列控中心设备作为CTCS-2级轨旁设备中控制列车安全运行的核心单元之一,而有源应答器报文又是列控中心的核心功能之一,其作为列车正常运行的控车输入信息之一,能够快速、有效的向列车提供位置、限速、进路等信息,由此可见有源应答器报文的有效性和安全性尤为重要,目前可通过报文扰码及解扰后的关键数据进行对比实现防护,但对于扰码前的原始应答器用户报文的可靠性和安全性,及在不同场景下原始应答器用户报文与场景的一致性,无法通过报文扰码和解扰对比进行保障
[0031]1.具备独立的安全检查模块(即报文独立安全检查单元),不影响列控系统的安全完整性等级,不改变既有功能模块的逻辑处理,具备一定的独立性;
Smart Images

Figure CN117749651B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of rail transit, and specifically relates to a method for checking the security of message data in a train control center. Background Technology
[0002] With the continuous development of my country's social economy, the demand for railway transportation is also constantly increasing. The CTCS-2 level train control system is currently one of the most widely used train control systems in China. Among them, the train control center equipment, as an important component of the CTCS-2 level train control system, is also the core of the ground safety equipment, playing a crucial role in the smoothness and safety of train operation.
[0003] As one of the core units for controlling the safe operation of trains in the CTCS-2 level trackside equipment, the train control center equipment, and the active transponder message, is one of the core functions of the train control center. As one of the control input information for the normal operation of the train, it can quickly and effectively provide the train with information such as position, speed limit, and route. Therefore, the effectiveness and security of the active transponder message are particularly important. At present, protection can be achieved by comparing the key data after message scrambling and descrambling. However, the reliability and security of the original transponder user message before scrambling, as well as the consistency between the original transponder user message and the scenario in different scenarios, cannot be guaranteed by comparing message scrambling and descrambling. Summary of the Invention
[0004] The purpose of this invention is to provide a method for checking the security of message data in a train control center. For different scenarios and different attributes of the transponder's output message data, consistency verification with the scenario is performed. Independent security verification is combined with the train control center's logical processing. When the train control center finds that the output message data of the active transponder is inconsistent with the scenario verification, the system determines that there is a security logic problem in the current transponder message. The system then actively guides the security side to process the message, setting the current transponder message as a default message or a stop message for external transmission, thereby realizing the security check of the message data and ensuring train operation safety.
[0005] To achieve the above objectives, the present invention provides a method for checking the security of message data in a train control center, comprising: acquiring static data of an active transponder corresponding to the message data to be output; the static data includes standard message data and transponder attribute data; the active transponder includes an entrance transponder, an exit transponder, a first arrival / departure track transponder, a second arrival / departure track transponder, a large-number turnout transponder, a first shunting transponder, a second shunting transponder, a C0 exit transponder, and a relay station transponder;
[0006] The output message data is checked based on the temporary speed limit initialization status of the train control center and the standard message data of the active transponder. If the temporary speed limit initialization is not completed, the active transponder type corresponding to the output message data is determined based on the transponder attribute data, and the index number of the output message data is determined based on the first scenario condition to see if it matches the index number of the standard message data of the corresponding active transponder.
[0007] If the temporary speed limit initialization is completed, determine whether the active transponder type corresponding to the message data to be output is any active transponder except for the exit transponder, C0 exit transponder and large number turnout transponder, based on the transponder attribute data, and determine whether the index number of the message data to be output is consistent with the index number of the standard message data of the corresponding active transponder under the second scenario condition.
[0008] If, under either the first or second scenario condition, the index number of the message data to be output matches the index number of the standard message data of the corresponding active transponder, then the current active transponder is allowed to output the message data to be output.
[0009] Preferably, if the index number of the message data to be output is inconsistent with the index number of the corresponding standard message data under the first scenario condition or the second scenario condition, the train control center will redirect to the safety side and send the message data to be output as the default message or the parking message.
[0010] Preferably, if the temporary speed limit initialization of the train control center is completed, and the message data to be output is the transponder speed limit message data that allows multiple speed limits to be sent, then it is determined whether the number of temporary speed limits in the message data to be output is less than the number of temporary speed limits contained in the speed limit message data; if the number of temporary speed limits in the message data to be output is less than the number of temporary speed limits within the jurisdiction of the transponder message issued and executed by the temporary speed limit server, then the sending of the message data to be output is prohibited, and the train control center is redirected to the safety side.
[0011] Preferably, the transponder speed limit messages that allow multiple speed limits include departure messages from the mainline active transponder at the exit, arrival messages from the entry transponder, and relay station transponder messages.
[0012] Preferably, when the temporary speed limit in the train control center is not initialized, the first scenario conditions include:
[0013] Condition D1-1: Communication failure between the active transponder and the interlocking system;
[0014] Condition D1-2: The active transponder communicates normally with the interlocking system, but the interlocking system has not arranged the train route;
[0015] Condition D1-3: The active transponder communicates normally with the interlocking system, and the interlocking system arranges train routes normally and opens route signals.
[0016] Preferably, under condition D1-1, the first standard message data corresponding to the entrance transponder, exit transponder, first arrival / departure track transponder, and second arrival / departure track transponder are all TCC default messages; under condition D1-2, the second standard message data corresponding to the entrance transponder, first arrival / departure track transponder, and second arrival / departure track transponder are all stop messages, and the second standard message data of the exit transponder is a TCC default message.
[0017] Preferably, the open route signal described in conditions D1-3 includes the following situations: Situation 1, the inbound signal is open and the outbound signal is open; Situation 2, the inbound signal is open and the outbound signal is closed; Situation 3, the inbound signal is closed and the outbound signal is open.
[0018] Preferably, the third standard message data corresponding to the entrance transponder includes: in case 1 or case 2, when the train route at the entrance is a direct route, the third standard message data is the TCC default message; or when the train route at the entrance is a side route, the third standard message data is the 45km / h speed limit route message; in case 3, the third standard message data is the stop message.
[0019] Preferably, the fourth standard message data corresponding to the exit gate transponder is the TCC default message in any of cases 1 to 3.
[0020] Preferably, the fifth standard message data corresponding to the transponder of the first arrival / departure track used for reverse departure includes: in case 1 or case 3, when the train route of the first arrival / departure track is lateral departure, the fifth standard message data is a warning message; or when the train route of the first arrival / departure track is straight departure, the fifth standard message data is a stop message; in case 2, the fifth standard message data is a stop message.
[0021] Preferably, the sixth standard message data corresponding to the second arrival / departure track transponder used for forward departure includes: in case 1 or case 3, the sixth standard message data is the TCC default message; in case 2, the sixth standard message data is the stop message.
[0022] Preferably, when the temporary speed limit initialization of the train control center is completed, the second scenario conditions include: condition D2-1, communication failure between the active transponder and the interlocking system; condition D2-2, normal communication between the active transponder and the interlocking system, but no train route has been arranged.
[0023] Preferably, under condition D2-1, the seventh standard message data corresponding to the entrance transponder, the first arrival / departure track transponder, the second arrival / departure track transponder, the first shunting transponder, and the second shunting transponder is the TCC default message; under condition D2-2, the eighth standard message data corresponding to the entrance transponder, the first arrival / departure track transponder, the second arrival / departure track transponder, and the first shunting transponder is the stop message, and the ninth standard message data corresponding to the second shunting transponder is the shunting danger message; wherein, the first shunting transponder is located on a non-train route, and the second shunting transponder is located on a train route.
[0024] Preferably, under condition D2-1 or condition D2-2, the tenth standard message data corresponding to the large number turnout transponder is an allow-pass message.
[0025] Preferably, if the active transponder type corresponding to the message data to be output is determined to be a large-number turnout transponder based on the transponder attribute data, and the temporary speed limit initialization of the train control center is completed and communication with the interlocking system is normal, then the message data to be output is checked according to condition D3; the message data to be output should meet condition D3; condition D3 includes:
[0026] Condition D3-1: The permitted length of the route exceeds the braking distance inspection range;
[0027] Condition D3-2: There are no temporary speed limits lower than the lateral allowable speed of large number turnouts within the lateral approach range and the braking distance of the departure section;
[0028] Condition D3-3: All block sections between the block section where the large-number turnout transponder is located and the signal of the large-number turnout are idle;
[0029] If the data to be output does not meet any of the conditions D3-1 to D3-3, the large-number turnout transponder sends a permission message.
[0030] In summary, compared with the prior art, the method for checking the security of train control center message data provided by the present invention has the following beneficial effects:
[0031] 1. It has an independent security inspection module (i.e., an independent message security inspection unit), which does not affect the security integrity level of the train control system, does not change the logic processing of existing functional modules, and has a certain degree of independence;
[0032] 2. The security of the original transponder user message data is checked, not only by relying on message scrambling and comparison of key data after descrambling, but also by combining its own logical operations and verification process to further verify the security of the transponder user message data and ensure train operation safety.
[0033] 3. For transponder user message data that fails the inspection, an alarm is triggered through the maintenance terminal, which can pinpoint the specific reason for the failure and the direction of troubleshooting, making it easier for maintenance personnel to locate the faulty equipment and conduct inspections. Attached Figure Description
[0034] Figure 1 This is a schematic diagram of the module connection of the train control system based on the present invention;
[0035] Figure 2 This is a flowchart illustrating the method for checking the security of message data in the train control center according to the present invention.
[0036] Figure 3 This is a data flow diagram of the train control center message data security inspection method of the present invention. Detailed Implementation
[0037] The following will be combined with the appendix in the embodiments of the present invention. Figure 1 ~Attached Figure 3 The technical solutions, structural features, objectives and effects achieved in the embodiments of the present invention will be described in detail.
[0038] It should be noted that the accompanying drawings are in a very simplified form and use non-precise proportions. They are only used to facilitate and clarify the purpose of illustrating the embodiments of the present invention, and are not intended to limit the implementation conditions of the present invention. Therefore, they have no substantial technical significance. Any modifications to the structure, changes in the proportional relationship, or adjustments to the size should still fall within the scope of the technical content disclosed in the present invention, provided that they do not affect the effects and objectives that the present invention can produce.
[0039] It should be noted that, in this invention, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only the expressly listed elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus.
[0040] like Figure 1The diagram shows a schematic of the train control system on which the train control center message data security inspection method of the present invention is based. The system includes a train control center (TCC) 100, which is communicatively connected to an external interface device 200. The train control center 100 includes a logic operation terminal 101 and a maintenance terminal 102, which are communicatively connected. The logic operation terminal 101 includes an existing logic operation unit 111 and a message independent security inspection unit 112. The existing logic operation unit 111 is used to receive data information sent by the external interface device 200. The external interface device 200 includes a neighboring station train control center (TCC) 201, an interlocking system (CBI) 202, a temporary speed limit server (TSRS) 203, and a trackside electronic unit (LEU) 204. The data information received by the existing logic operation unit 111 includes the initialization status information of the temporary speed limit server 203 and the open route signal sent by the interlocking system 202.
[0041] Furthermore, such as Figure 1 The active transponder 300 includes an entrance transponder 301, an exit transponder 302, a first arrival / departure track transponder 303, a second arrival / departure track transponder 304, a large-number turnout transponder 305, a first shunting transponder 306, a second shunting transponder 307, a C0 exit transponder 308, and a relay station transponder 309; wherein, the first arrival / departure track transponder 303 is used for reverse exit; the second arrival / departure track transponder 304 is used for forward exit; the first shunting transponder 306 is located on a non-train route, and the second shunting transponder 307 is located on a train route.
[0042] Based on the aforementioned train control system, this invention provides a method for checking the security of message data in a train control center. When the train control center 100 is powered on, and the existing logic operation unit 111 and the independent message security check unit 112 are in normal operation and connected normally to the external interface device 200, the independent message security check unit 112 is independent of the existing logic operation unit 111. The independent message security check unit 112 does not affect the operation results of the existing logic operation unit 111, but the final check result of the independent message security check unit 112 will affect the output result of the train control system. Based on whether the check result passes, it is determined whether the train control center 100 should redirect the process to the security side.
[0043] Specifically, such as Figure 2 As shown, the method for checking the security of message data includes the following steps:
[0044] The train control center 100 generates the message data to be output and sends it to the message independent security check unit 112 through the existing logic operation unit 111; the message independent security check unit 112 obtains the static data of the active transponder 300 corresponding to the message data to be output; the static data includes standard message data and transponder attribute data; the transponder attribute data includes transponder name, number, location and other information;
[0045] The system verifies the output message data based on the temporary speed limit initialization status of the train control center 100 and the standard message data of the active transponder 300. If the temporary speed limit initialization of the train control center 100 is not completed (i.e., the temporary speed limit server 203 has not completed initialization), it determines the type of the active transponder 300 corresponding to the output message data based on the transponder attribute data, and then obtains the standard message data corresponding to the active transponder 300. Based on the first scenario condition, it determines whether the index number of the output message data is consistent with the index number of the standard message data of the corresponding active transponder 300. If, under the first scenario condition, the index number of the output message data is consistent with the index number of the standard message data of the corresponding transponder, then the current active transponder 300 is allowed to output the output message data.
[0046] Conversely, such as Figure 3 As shown, if the index number of the message data to be output is inconsistent with the index number of the corresponding standard message data under the first scenario condition, the train control center 100 will redirect to the safety side, set the message data to be output as the default message or the stop message and send it to the outside, and output the alarm and the reason for the verification failure to the maintenance terminal 102.
[0047] Specifically, as shown in Table 1, when the temporary speed limit of the train control center 100 is not initialized, the first scenario conditions include: Condition D1-1, the active transponder 300 and the interlocking system 202 have a communication failure; Condition D1-2, the active transponder 300 and the interlocking system 200 communicate normally, but the interlocking system 200 does not arrange train routes (i.e., the entry and exit signals are both closed); Condition D1-3, the active transponder 300 and the interlocking system 200 communicate normally, and the interlocking system 200 arranges train routes normally and opens the route signals.
[0048]
[0049] Table 1: Correspondence Table of First Scenario Conditions, Open Route Signal, and Standard Message Data of Each Transponder
[0050] As shown in Table 1, under condition D1-1, the first standard message data corresponding to the entrance transponder 301, the exit transponder 302, the first arrival / departure track transponder 303, and the second arrival / departure track transponder 304 are all TCC default messages; under condition D1-2, the second standard message data corresponding to the entrance transponder 301, the first arrival / departure track transponder 303, and the second arrival / departure track transponder 304 are all stop messages, and the second standard message data corresponding to the exit transponder 302 is a TCC default message.
[0051] Furthermore, as shown in Table 1, the open route signal described in conditions D1-3 includes the following situations: Situation 1, both the inbound and outbound signals are open; Situation 2, both the inbound and outbound signals are closed; Situation 3, both the inbound and outbound signals are closed.
[0052] As shown in Table 1, the third standard message data corresponding to the entrance transponder 301 includes: in case 1 or case 2, when the train route at the entrance is a direct route, the third standard message data is the TCC default message; or when the train route at the entrance is a side route, the third standard message data is the 45km / h speed limit route message; in case 3, the third standard message data is the stop message.
[0053] As shown in Table 1, the fourth standard message data of the exit transponder 302 is the TCC default message in any of the cases 1 to 3.
[0054] As shown in Table 1, the fifth standard message data corresponding to the transponder 303 of the first arrival / departure track used for reverse departure includes: in case 1 or case 3, when the train route of the first arrival / departure track is lateral departure, the fifth standard message data is a warning message; or when the train route of the first arrival / departure track is straight departure, the fifth standard message data is a stop message; in case 2, the fifth standard message data is a stop message.
[0055] As shown in Table 1, the sixth standard message data corresponding to the second arrival / departure track transponder 304 used for forward departure includes: in case 1 or case 3, the sixth standard message data is the TCC default message; in case 2, the sixth standard message data is the stop message.
[0056] Based on the various first scenario conditions in Table 1, the independent security check unit 112 verifies all active transponders 300 by checking whether the index number in the output message data generated by the train control center 100 is the same as the index number in the standard message data of the corresponding active transponder 300 in Table 1. If they are the same, it means that the output message data has passed the verification, and the active transponder 300 sends the output message data to the external device LEU (trackside electronic unit) 204. If they are not the same, it means that the output message data has failed the verification. When the verification fails, the current active transponder 300 should send a default message or a stop message and output an alarm and the reason for the verification failure to the maintenance terminal 102 (such as the entrance transponder 301 not sending a stop message when the entrance signal is closed). In one specific embodiment, the index number of the TCC default message is 253. If the index number of the message data to be output is 253, it can be determined that the message data to be output is the default message. For example, the index number of the parking message is 255. The parking message contains the CTCS-5 identifier. If the index number of the message data to be output is 255 and contains the CTCS-5 identifier, it can be determined that the message to be output is the parking message.
[0057] Furthermore, the number of temporary speed limits in the transponder speed limit messages that allow multiple speed limits is verified. Specifically, if the temporary speed limit initialization of the train control center 100 is completed (i.e., the temporary speed limit server 203 has completed initialization), and the message data to be output is the transponder speed limit message data that allows multiple speed limits, then the message data to be output is sent to the message independent security check unit 112 for judgment. Specifically, it is determined whether the number of temporary speed limits in the message data to be output is less than the number of temporary speed limits contained in the speed limit message data. If the number of temporary speed limits in the message data to be output is less than the number of temporary speed limits within the jurisdiction of the transponder message issued and executed by the temporary speed limit server 203, then the transmission of the message data to be output is prohibited, a default message is sent, and the train control center 100 is redirected to the safety side, and an alarm and the reason for the verification failure are output to the maintenance terminal 102.
[0058] The transponder speed limit messages that allow multiple speed limits include departure messages from the mainline active transponder at the exit, arrival messages from the entrance transponder, and relay station transponder messages.
[0059] Furthermore, the active transponder message data is verified against the open status of the associated interlocking route signals. Specifically, if the temporary speed limit initialization of the train control center 100 is completed, it determines whether the active transponder 300 type corresponding to the message data to be output is one of the active transponders in the main station except for the exit transponder 302, C0 exit transponder 308, and large-number turnout transponder 305, based on the transponder attribute data. The active transponder 300 type is then determined, and the standard message data corresponding to that active transponder 300 is obtained. Under the second scenario condition, it is determined whether the index number of the message data to be output matches the index number of the standard message data of the corresponding transponder. If, under the second scenario condition, the index number of the message data to be output matches the index number of the standard message data of the corresponding transponder, then the train control center 100 is allowed to output the message data to be output.
[0060] Conversely, such as Figure 3 As shown, if the index number of the message data to be output is inconsistent with the index number of the corresponding standard message data under the second scenario, the train control center 100 will redirect to the safety side, set the message data to be output as the default message or the stop message and send it to the outside, and output the alarm and the reason for the verification failure to the maintenance terminal 102.
[0061] Specifically, as shown in Table 2, when the temporary speed limit initialization of the train control center 100 is completed, the second scenario conditions include: Condition D2-1, communication failure between the active transponder 300 and the interlocking system 202; Condition D2-2, normal communication between the active transponder 300 and the interlocking system 202, but no train route is arranged (i.e., both the entry and exit signals are closed).
[0062]
[0063] Table 2: Correspondence Table of Second Scenario Conditions, Open Route Signals, and Standard Message Data for Each Transponder
[0064] As shown in Table 2, under condition D2-1, the seventh standard message data corresponding to the entrance transponder 301, the first arrival / departure track transponder 303, the second arrival / departure track transponder 304, the first shunting transponder 306, and the second shunting transponder 307 is the TCC default message.
[0065] As shown in Table 2, under condition D2-2, the eighth standard message data corresponding to the entrance transponder 301, the first arrival / departure track transponder 303, the second arrival / departure track transponder 304, and the first shunting transponder 306 is a stop message, and the ninth standard message data corresponding to the second shunting transponder 307 is a shunting danger message; wherein, the first shunting transponder 306 is located on a non-train route, and the second shunting transponder 307 is located on a train route.
[0066] As shown in Table 2, under condition D2-1 or condition D2-2, the tenth standard message data corresponding to the large number turnout transponder 305 is an allowed pass message.
[0067] Based on the various second scenario conditions in Table 2, the independent security check unit 112 verifies all active transponders 300 except for the exit transponder 302, C0 exit transponder 308, and large-number turnout transponder 305. It verifies whether the index number in the output message data generated by the train control center 100 is the same as the index number in the standard message data of the corresponding active transponder 300 in Table 2. If they are the same, the output message data passes the verification. If they are not the same, the output message data fails the verification. When the verification fails, the current active transponder 300 should send a default message or a stop message and output an alarm and the reason for the verification failure to the maintenance terminal 102 (e.g., the entrance transponder 301 did not send a TCC default message when the interlocking system 202 communication failed).
[0068] Furthermore, the message data of the large-number turnout transponder 305 is verified against the open status of the associated interlocking route signal, the section occupancy status, and the temporary speed limit information. Specifically, if the active transponder 300 corresponding to the message data to be output is determined to be a large-number turnout transponder 305 based on the transponder attribute data, and the temporary speed limit server 203 has completed initialization and is communicating normally with the interlocking system 202, then the message data to be output is checked according to condition D3. The message data to be output should meet condition D3. Condition D3 includes: Condition D3-1, the permitted length of the route exceeds the braking distance check range; Condition D3-2, there is no temporary speed limit lower than the lateral permitted speed of the large-number turnout within the lateral route range and the braking distance of the departure section; Condition D3-3, all block sections (routes) between the block section (excluding) where the large-number turnout transponder 305 is located and the signal of the large-number turnout are idle.
[0069] If the data to be output does not meet any of the conditions D3-1 to D3-3, the large-number turnout transponder shall be prohibited from sending the data to be output. At the same time, the large-number turnout transponder shall send a pass-through message and output an alarm and the reason for the failure of verification to the maintenance terminal 102 (such as the existence of a temporary speed limit within the route range that is lower than the lateral allowable speed of the large-number turnout).
[0070] In summary, compared with the prior art, the train control center message data security inspection method provided by the present invention checks the security of message data that is about to be sent out, avoiding security risks caused by inconsistencies between the original transponder user message and the scenario after the message scrambling and descrambling key data comparison check passes. By verifying the consistency between the original transponder user message and the scenario, the security and reliability of the system are further improved.
[0071] Although the present invention has been described in detail through the preferred embodiments above, it should be understood that the above description should not be considered as a limitation of the present invention. Various modifications and substitutions to the present invention will be apparent to those skilled in the art after reading the above description. Therefore, the scope of protection of the present invention should be defined by the appended claims.
Claims
1. A method for checking the security of message data in a train control center, characterized in that, include: Obtain the static data of the active transponder corresponding to the message data to be output; The static data includes standard message data and transponder attribute data; the active transponders include entrance transponders, exit transponders, first arrival / departure track transponders, second arrival / departure track transponders, large number turnout transponders, first shunting transponders, second shunting transponders, C0 exit transponders, and relay station transponders. The output message data is checked based on the temporary speed limit initialization status of the train control center and the standard message data of the active transponder. If the temporary speed limit initialization is not completed, the active transponder type corresponding to the output message data is determined based on the transponder attribute data, and the index number of the output message data is determined based on the first scenario condition to see if it matches the index number of the standard message data of the corresponding active transponder. If the temporary speed limit initialization is completed, determine whether the active transponder type corresponding to the message data to be output is any active transponder except for the exit transponder, C0 exit transponder and large number turnout transponder, based on the transponder attribute data, and determine whether the index number of the message data to be output is consistent with the index number of the standard message data of the corresponding active transponder under the second scenario condition. If, under either the first or second scenario condition, the index number of the message data to be output matches the index number of the standard message data of the corresponding active transponder, then the current active transponder is allowed to output the message data to be output.
2. The method for checking the security of train control center message data as described in claim 1, characterized in that, If, under either the first or second scenario condition, the index number of the message data to be output is inconsistent with the index number of the corresponding standard message data, the train control center will redirect to the safety side and send the message data to be output as a default message or a stop message.
3. The method for checking the security of train control center message data as described in claim 1, characterized in that, If the temporary speed limit initialization of the train control center is completed, and the message data to be output is the transponder speed limit message data that allows multiple speed limits to be sent, then determine whether the number of temporary speed limits in the message data to be output is less than the number of temporary speed limits contained in the speed limit message data. If the number of temporary rate limits in the pending output message data is less than the number of temporary rate limits within the jurisdiction of the transponder message issued and executed by the temporary rate limit server, then the sending of the pending output message data will be prohibited, and the train control center will be redirected to the safety side.
4. The method for checking the security of train control center message data as described in claim 3, characterized in that, The permitted multi-point speed limit transponder messages include departure messages from the mainline active transponder at the exit, arrival messages from the entrance transponder, and relay station transponder messages.
5. The method for checking the security of train control center message data as described in claim 1, characterized in that, When the temporary speed limit in the train control center is not initialized, the first scenario conditions include: Condition D1-1: Communication failure between the active transponder and the interlocking system; Condition D1-2: The active transponder communicates normally with the interlocking system, but the interlocking system has not arranged the train route; Condition D1-3: The active transponder communicates normally with the interlocking system, and the interlocking system arranges train routes normally and opens route signals.
6. The method for checking the security of train control center message data as described in claim 5, characterized in that, Under condition D1-1, the first standard message data corresponding to the entrance transponder, exit transponder, first arrival / departure track transponder, and second arrival / departure track transponder are all TCC default messages. Under condition D1-2, the second standard message data corresponding to the entrance transponder, the first arrival / departure track transponder, and the second arrival / departure track transponder are all parking messages, and the second standard message data of the exit transponder is the TCC default message.
7. The method for checking the security of train control center message data as described in claim 5, characterized in that, The open route signal mentioned in conditions D1-3 includes the following situations: Situation 1, both the inbound and outbound signals are open; Situation 2, the inbound signal is open and the outbound signal is closed; Situation 3, the inbound signal is closed and the outbound signal is open.
8. The method for checking the security of train control center message data as described in claim 7, characterized in that, The third standard message data corresponding to the entrance transponder includes: in case 1 or case 2, when the train route at the entrance is a direct route, the third standard message data is the TCC default message; or when the train route at the entrance is a side route, the third standard message data is the 45km / h speed limit route message; in case 3, the third standard message data is the stop message.
9. The method for checking the security of train control center message data as described in claim 7, characterized in that, The fourth standard message data corresponding to the exit transponder is the TCC default message in any of cases 1 to 3.
10. The method for checking the security of train control center message data as described in claim 7, characterized in that, The fifth standard message data corresponding to the transponder of the first arrival / departure track used for reverse departure includes: in case 1 or case 3, when the train route of the first arrival / departure track is lateral departure, the fifth standard message data is a warning message; or when the train route of the first arrival / departure track is straight departure, the fifth standard message data is a stop message; in case 2, the fifth standard message data is a stop message.
11. The method for checking the security of train control center message data as described in claim 7, characterized in that, The sixth standard message data corresponding to the second arrival / departure track transponder used for forward departure includes: in case 1 or case 3, the sixth standard message data is the TCC default message; in case 2, the sixth standard message data is the stop message.
12. The method for checking the security of train control center message data as described in claim 1, characterized in that, When the temporary speed limit initialization is completed at the train control center, the conditions for the second scenario include: Condition D2-1: Communication failure between the active transponder and the interlocking system; Condition D2-2: The active transponder communicates normally with the interlocking system, but train routes are not arranged.
13. The method for checking the security of train control center message data as described in claim 12, characterized in that, Under condition D2-1, the seventh standard message data corresponding to the entrance transponder, the first arrival / departure track transponder, the second arrival / departure track transponder, the first shunting transponder, and the second shunting transponder is the TCC default message. Under condition D2-2, the eighth standard message data corresponding to the entrance transponder, the first arrival / departure track transponder, the second arrival / departure track transponder, and the first shunting transponder is a stop message, and the ninth standard message data corresponding to the second shunting transponder is a shunting danger message; wherein, the first shunting transponder is located on a non-train route, and the second shunting transponder is located on a train route.
14. The method for checking the security of train control center message data as described in claim 12, characterized in that, Under condition D2-1 or condition D2-2, the tenth standard message data corresponding to the large number turnout transponder is an allowed pass message.
15. The method for checking the security of train control center message data as described in claim 1, characterized in that, If, based on the transponder attribute data, the active transponder type corresponding to the message to be output is determined to be a large-number turnout transponder, and the temporary speed limit initialization at the train control center is complete and communication with the interlocking system is normal, then the message to be output is checked according to condition D3; the message to be output should satisfy condition D3; condition D3 includes: Condition D3-1: The permitted length of the route exceeds the braking distance inspection range; Condition D3-2: There are no temporary speed limits lower than the lateral allowable speed of large number turnouts within the lateral approach range and the braking distance of the departure section; Condition D3-3: All block sections between the block section where the large-number turnout transponder is located and the signal of the large-number turnout are idle; If the data to be output does not meet any of the conditions D3-1 to D3-3, the large-number turnout transponder sends a permission message.
Citation Information
Patent Citations
Method and system for processing temporary speed limit in control system
CN114475725A
Method and tool for generating off-line message of active transponder and method and tool for using off-line message of active transponder
CN115257893A