Automatic train supervision system
By utilizing server clusters and container cloud technologies, the system achieves efficient resource utilization of the automatic train monitoring system, solving the problem of low resource utilization in existing technologies, meeting the primary and backup redundancy requirements of the signaling system, and improving data processing speed and communication security.
Patent Information
- Application Number
- CN202211523843.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-30
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2042-11-30
AI Technical Summary
The current deployment method of the automatic train monitoring system results in low resource utilization and increases the financial costs of the line.
The system employs a server cluster deployment, including a management node and multiple worker nodes, secure worker nodes and insecure worker nodes. Through container cloud technology and Kubernetes orchestration tools, it achieves load balancing and efficient resource utilization.
It saves time and space costs, improves resource utilization, meets the redundancy requirements of the signal system, and ensures data processing speed and communication security.
Smart Images

Figure CN118107632B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of rail transit technology, and in particular to an automatic train monitoring system. BACKGROUND
[0002] In the prior art, the automatic train monitoring system is deployed by using PAAS deployment, and each line needs a complete set of server hardware resources. When multiple lines are deployed and operated, a complete set of hardware resources is needed for each line to run the automatic train monitoring system. This method has low resource utilization and increases the financial cost of the line. SUMMARY
[0003] The present application provides an automatic train monitoring system.
[0004] The automatic train monitoring system of the present application comprises a server cluster, the server cluster comprises a management node and a plurality of working nodes, and at least two of the plurality of working nodes can run simultaneously.
[0005] The management node is used for network health monitoring of the working nodes.
[0006] The working nodes comprise safe working nodes and non-safe working nodes.
[0007] The non-safe working nodes are used for running the front-end software, the back-end software and the first interface software of the automatic train monitoring system.
[0008] The safe working nodes are used for data analysis services and running safe working node interface software, and each safe working node corresponds to a train line.
[0009] The automatic train monitoring system described above can save time and space costs and server resources when a train line is added by adding a safe working node and allocating part of the resources of the non-safe working nodes.
[0010] In some embodiments, the working nodes provide a minimum resource management component, which is used for running the front-end software, the back-end software, the first interface software, the data analysis service and the safe working node interface software of the automatic train monitoring system, and two minimum resource management components running the same service are respectively arranged on two working nodes.
[0011] In some embodiments, the load distribution strategy of the minimum resource management component is a round-robin mode.
[0012] In some embodiments, the first interface software comprises an external interface software, and the non-secure working node is configured to:
[0013] receive the data transmitted by the non-signal system;
[0014] process the data transmitted by the non-signal system and send to a preset device.
[0015] In some embodiments, the secure working node is configured to communicate with a signal system through a secure network, and when the signal system transmits information to the secure working node through the secure network, the secure working node is configured to:
[0016] receive the information and perform a security check;
[0017] if the security check is successful, send the information to the non-secure working node;
[0018] the non-secure working node is configured to:
[0019] receive the information transmitted by the secure working node and perform a security check;
[0020] if the security check is successful, process the information and send to a display interface of the automatic train supervision system for display.
[0021] In some embodiments, the first interface software comprises an internal interface software, and the secure working node interface software and the internal interface software communicate after a successful security check.
[0022] In some embodiments, the automatic train supervision system further comprises a terminal device;
[0023] the terminal device is configured to display the data transmitted by the working node and receive a user instruction and send the user instruction to the signal system through the working node.
[0024] In some embodiments, when the terminal device sends the user instruction to the working node, the non-secure working node is configured to:
[0025] receive the user instruction and perform a security check;
[0026] if the security check is successful, send the user instruction to the secure working node;
[0027] the secure working node is configured to:
[0028] receive the user instruction transmitted by the non-secure worker node and perform security check;
[0029] in case of successful security check, send the user instruction to the signal system.
[0030] In some embodiments, the server cluster is composed of local server resources, or composed of cloud platform uniformly managing server resources to satisfy the amount.
[0031] In some embodiments, the management node comprises a main management node and a backup management node, the main management node is used for network health monitoring of the worker node, and the main management node is used for switching to the backup management node in case of main management node device failure or monitoring of the management node and the worker node network failure.
[0032] Additional aspects and advantages of the present application will be given in part in the following description, become apparent from the following description, or be learned by practice of the present application. BRIEF DESCRIPTION OF DRAWINGS
[0033] The above and / or additional aspects and advantages of the present application will become apparent and more readily appreciated from the following description, taken in conjunction with the following drawings, of embodiments of the present application, in which:
[0034] Fig. 1 is a system architecture schematic diagram of an automatic train supervision system of an embodiment of the present application;
[0035] Fig. 2 is a server deployment schematic diagram of an automatic train supervision system of an embodiment of the present application;
[0036] Fig. 3 is a system flowchart of an automatic train supervision system of an embodiment of the present application. DETAILED DESCRIPTION
[0037] Embodiments of the present application are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the accompanying drawings are exemplary, only for explaining the embodiments of the present application, and cannot be understood as limiting the embodiments of the present application.
[0038] The following disclosure provides many different embodiments, or examples, for implementing different structures of embodiments of the application. For the purpose of simplifying the disclosure of embodiments of the application, the components and arrangements of specific examples are described below. Of course, they are only examples, and the purpose is not to limit the application. Embodiments of the application can refer to reference numbers and / or reference letters in different examples, and such repetition is for the purpose of simplification and clarity, which does not indicate the relationship between the various embodiments and / or arrangements discussed. In addition, embodiments of the application provide examples of various specific processes and materials, but those skilled in the art can realize the application of other processes and / or the use of other materials.
[0039] Referring to Figs. 1-2 , the embodiments of the application provide an automatic train monitoring system 100, the automatic train monitoring system 100 is deployed with a server cluster, the server cluster includes a management node 12 and a plurality of working nodes 14, at least two of the plurality of working nodes 14 can run simultaneously, the management node 12 is used for network health monitoring of the working node 14, the working node 14 includes a safe working node 16 and a non-safe working node 18, the non-safe working node 18 is used for running front-end software, back-end software and first interface software of the automatic train monitoring system 100, the safe working node 16 is used for data analysis service and running safe working node interface software 17, each safe working node 16 corresponds to a train line.
[0040] The above-mentioned automatic train monitoring system 100, when increasing the train line, the corresponding safe working node 16 is increased, and part of the resources of the non-safe working node 18 is allocated, which saves the time and space cost and server resources.
[0041] Specifically, the automatic train supervision (Automatic Train Supervision) system is an important subsystem of the automatic train control (Automatic Train Control) system, which is a set of modern data communication, computer, network and signal technology, distributed real-time supervision and control system. The ATS subsystem cooperates with other subsystems in the ATC system to complete the management and control of subway operation trains and signal equipment.
[0042] The automatic train monitoring system 100 provided by the application is designed and deployed by using container cloud technology, and the server cluster is deployed by using container orchestration tool kubernetes, the server cluster includes a management node 12 and a plurality of working nodes 14, at least two of the plurality of working nodes 14 can run simultaneously.
[0043] The working node 14 includes a secure working node 16 and a non-secure working node 18, the secure working node 16 is used for running a secure application service, and the non-secure working node 18 is used for performing a non-secure application service, both of which are independent two-part namespaces, the secure working node 16 is in a cluster network, and is connected to a secure network through an external security firewall, and is used for information interaction with other subsystems of a signal system: a computer interlocking (CI), a zone controller (ZC) and a vehicle on-board controller (VOBC), and the secure working node 16 runs a CI-related data analysis service, a ZC-related data analysis service, a VOBC data analysis service and a secure working node interface software 17, and the secure working node interface software 17 provides a security check and load balancing service.
[0044] The non-secure working node 18 runs an automatic train supervision system 100 front-end and back-end software and a first interface software, the back-end software provides: a train identification tracking service, a route handling service, a running adjustment service, a train operation control service, a train operation management service, an alarm service, a record and playback service and a system maintenance service, the front-end software includes: a station yard diagram display module, a running diagram display module, a playback display module, an alarm display module and a maintenance interface display module, the first interface software is used for information interaction and security check during information interaction, and the first interface software includes internal interface software 30 and external interface software 28, the external interface software 28 is interface software for information interaction with a non-signal system, and the internal interface software 30 is interface software for information interaction with the secure working node 16.
[0045] When the train line is expanded, because the secure network of each line is isolated by using different firewalls, when a line is added, the secure working node 16 of the corresponding line needs to be correspondingly added, and part of the resources of the non-secure working node 18 of the newly added line can be allocated. When multiple lines are operated, the secure working node 16 of each line needs to be deployed on different servers for physical isolation, and the non-secure working node 18 can allocate resources through a cloud platform to form multiple non-secure working nodes 18, and the multiple non-secure working nodes 18 are isolated by namespaces, that is, virtual isolation is performed in the cloud platform, so that time and space costs and server resources can be saved, and maximum utilization of resources is realized.
[0046] In some embodiments, the worker node 14 provides a minimum resource management component, which is used to run the front-end software, the back-end software, the first interface software, the data parsing service and the safety worker node interface software 17 of the automatic train monitoring system 100, and two minimum resource management components running the same service are respectively run on two worker nodes 14.
[0047] In this way, the design mode of signal system main / standby redundancy can be met, and the main / standby servers can be balancedly run.
[0048] Specifically, the minimum resource management component (Pod) is the minimum unit in the container orchestration tool Kubernetes, which contains a group of containers and can support services running therein. In an example, when the server cluster initializes the worker node 14, the preset minimum number of Pods is preset to be 2, and two Pods running the same service are respectively run on two different physical machine resources, so that each physical machine can completely run all services related to the automatic train monitoring system 100. At this time, the two physical machines can serve as a main server and a standby server running at the same time, so that the requirement of the signal system for simultaneously having a main server and a standby server can be met, and the two physical machines serving as the main / standby servers can receive and process data, so that the main / standby servers can be balancedly run.
[0049] In some embodiments, the load distribution strategy of the minimum resource management component is a round robin mode.
[0050] In this way, when the data processing demand is large during the peak period of train operation and the minimum resource management component is freely expanded, the data processing speed can be effectively improved.
[0051] Specifically, the Kubernetes provides two load distribution strategies, which are a round robin mode (Round Robin) that forwards requests to each Pod, and a mode of session affinity based on IP addresses (Session Affinity) that forwards the request initiated by a certain IP address to a certain Pod for the first time, and then forwards the request initiated from the same IP address to the same Pod. Using the round robin mode, when the data processing demand is large during the peak period of train operation, the data processing speed can be accelerated when the Pod is freely expanded to meet the data processing demand.
[0052] When the Pod is free to scale, in one example, the preset minimum number of Pods is preset to 2, one Pod is configured with a dual-core CPU and 4G memory, a CPU and memory utilization threshold is preset for the Pod, when the CPU or memory utilization exceeds the preset utilization threshold, the Pod will automatically scale, if the load decreases and the number of Pods is higher than the configured minimum value, the number of Pods will be reduced, but the minimum number of Pods is 2, which still makes two Pods running the same service run on two different physical machine resources.
[0053] In some embodiments, the first interface software includes external interface software 28, when the non-signal system transmits data to the external interface software 28, the non-safety working node 18 is configured to: receive the data transmitted by the non-signal system; process the data transmitted by the non-signal system and send it to the preset device.
[0054] In this way, the non-safety working node 18 and the non-signal system can interact with each other.
[0055] Specifically, the first interface software running in the non-safety working node 18 includes external interface software 28, which is configured to interact with the non-signal system, when the external interface software 28 receives data information from the non-signal system, the data type is judged and processed by the backend software in the non-safety working node 18, and then the processed data is sent to the terminal device or the non-signal system, such as the ground charging system, the ground station broadcasting system, etc.
[0056] In one example, the non-signal system transmits uplink state data to the non-safety working node 18, such as the state of the charging system, the state of the power system and the state of the broadcasting system, etc., at this time, after the external interface software 28 receives the data, the backend software processes the data, and then sends the processed data to the front-end software for rendering, and finally displays the relevant data on the terminal device. The downlink data of the non-signal system is received and processed by the backend software, and then the information is sent to the communication system or other non-signal system through the external interface software 28, the downlink data of the non-signal system includes the arrival and departure information of the passenger information system and the arrival and departure information of the passenger broadcasting system.
[0057] In some embodiments, the safety working node 16 is configured to interact with the signal system through the safety network, when the signal system transmits information to the safety working node 16 through the safety network, the safety working node 16 is configured to: receive the information and perform safety check; in the case of successful safety check, send the information to the non-safety working node 18; the non-safety working node 18 is configured to: receive the information transmitted by the safety working node 16 and perform safety check; in the case of successful safety check, process the information and send it to the display interface of the automatic train monitoring system 100 for display.
[0058] Thus, the signal system and the safety worker node 16 can realize information interaction through the safety network.
[0059] Specifically, the safety worker node 16 is connected to the safety firewall safety network within the cluster network, and is used to interact with other subsystems of the signal system, including the computer interlocking (CI), the zone controller (ZC), and the vehicle on-board controller (VOBC). The uplink state data of the signal system, such as the state information frame of the train, the route opening information of the interlocking, and the state of the turnout, is transmitted to the safety worker node 16 through the safety network. After the data is verified by the safety verification and load balancing service module provided by the safety worker node interface software 17, the data is sent to the corresponding subsystem data analysis service, such as the CI data analysis service, the ZC data analysis service, and the VOBC data analysis service, for analysis. After the analysis is completed, the data is sent to the non-safety module through the safety verification and load balancing service provided by the safety worker node interface software 17, and is processed by the backend software. Then, the data is rendered by the front-end software, and is finally displayed on the display interface of the terminal device, thereby realizing information interaction between the signal system and the safety worker node 16. In an embodiment, the display interface can be displayed by a browser running on the terminal device.
[0060] In an example, the CI uplink track section state information is transmitted to the safety worker node 16 through the safety network. After receiving the data, the safety verification and load balancing service module provided by the safety worker node interface software 17 determines that the data comes from the CI subsystem according to the sender identifier in the data. According to the protocol version number (V3.1) of the CI subsystem and the automatic train monitoring system 100 and the electronic map data (0X676E324), the CRC value is calculated and is consistent with the CRC value in the state information. After verifying the consistency of the values, it is considered that the data is valid. The data is sent to the CI data analysis service for data analysis. After the analysis is completed, the data is sent to the non-safety module through the safety verification and load balancing service provided by the safety worker node interface software 17, is processed by the backend software, and is finally displayed on the display interface of the terminal device.
[0061] In some embodiments, the first interface software includes the internal interface software 30, and the safety worker node interface software 17 and the internal interface software 30 communicate after the safety verification is successful.
[0062] Thus, the security and stability of the communication connection can be ensured.
[0063] Specifically, the internal interface software 30 running in the non-secure working node 18 is configured to establish communication with the secure working node interface software 17 for information exchange. The communication between the internal interface software 30 and the secure working node interface software 17 is in the websocket mode, which enables the internal interface software 30 and the secure working node interface software 17 to complete a handshake when establishing a communication connection, and a persistent connection can be directly created between the two for bidirectional data transmission. Before the initial establishment of the connection communication, the secure working node 16 continuously and actively sends a heartbeat packet to the internal interface software 30, and the heartbeat packet includes a CRC value of the secure working node 16 under the current line version, which is generated according to the version number and time of the software version release. In an example, when the automatic train supervision system 100 is upgraded and deployed on a certain line, the communication connection between the secure working node 16 and the non-secure working node 18 is automatically disconnected. When the non-secure working node 18 is upgraded first and the secure working node 16 is not upgraded, the old version of the secure working node 16 actively and continuously sends a heartbeat packet to the non-secure working node 18. Since the communication domain name of the software module configuration does not change, the CRC value changes due to the version upgrade, and therefore the websocket connection fails each time. When the secure working node 16 is upgraded, the CRC values of the secure working node 16 and the non-secure working node 18 are consistent, and the communication is successfully established. After the secure working node interface software 17 and the internal interface software 30 establish communication, the secure working node 16 continuously and actively sends a heartbeat packet to the internal interface software 30 to detect whether the communication connection is in a normal state. Before the internal interface software 30 and the secure working node interface software 17 establish a communication connection, a security check is performed, and the communication connection is established when the security check is passed, which ensures the security of the communication connection. In addition, the heartbeat packet is continuously sent after the communication connection is established, which ensures the stability of the communication connection.
[0064] In some embodiments, the automatic train supervision system 100 further includes a terminal device.
[0065] The terminal device is configured to display data transmitted by the working node 14 and receive user instructions and send the user instructions to the signal system through the working node 14.
[0066] Thus, the automatic train supervision system 100 can perform human-computer interaction through the terminal device.
[0067] Specifically, in the Automatic Train Monitoring System 100, users obtain the current status information of the station and trains through the display interface of the terminal device, and issue commands to the software running in the work node 14 through the terminal device. Users can operate the pages provided by the front-end software through the display interface of the terminal device, including the station map display module, train schedule display module, playback display module, alarm display module, and maintenance interface display module in the front-end software. Through the terminal device's display interface, users can obtain station map information, train schedule information, alarm information, etc., and simultaneously issue commands to the software running in the work node 14 through the terminal device. Deploying the front-end software on a container cloud eliminates the need to install the front-end software on the workstation's terminal device in advance; users only need to open the terminal device to perform scheduling and control, making it convenient for users and reducing workstation configuration.
[0068] Terminal devices constitute the workstations of the automatic train monitoring system 100. The terminal devices used in the automatic train monitoring system 100 may include, but are not limited to, personal computers, smartphones, tablets, wearable smart devices, etc.
[0069] In some implementations, when the terminal device sends a user instruction to the working node 14, the non-secure working node 18 is used to: receive the user instruction and perform security verification; if the security verification is successful, send the user instruction to the secure working node 16; the secure working node 16 is used to: receive the user instruction transmitted by the non-secure working node 18 and perform security verification; if the security verification is successful, send the user instruction to the signal system.
[0070] This enables users to transmit commands securely and accurately via their terminal devices.
[0071] Specifically, such as Fig. 3 As shown, a user issues a command through a terminal device. This command includes the current time, command type, and command parameters. After receiving the command, the internal interface software 30 generates a CRC value based on these three parameters and the current line version. This CRC value is then sent as the fourth parameter of the command to the security working node interface software 17 within the security working node 16. The security verification and load balancing service of the security working node interface software 17 performs a consistency check based on the command parameters and the CRC value. If the security check passes, the target system for the command is determined based on the command type and parameters. A CRC value is generated based on the protocol version number between the current automatic train monitoring system 100 and other subsystems, as well as electronic map data. This CRC value is added to the command, and the command is then sent to other subsystems of the signaling system. If the security check fails, the command is considered invalid and will not be sent again. By performing security verification on the sent commands, the secure and accurate transmission of commands issued by the user through the terminal device can be ensured.
[0072] In one example, the user issues a train emergency brake relief confirmation command on the terminal device, the command is issued to the non-safety working node 18, and the internal interface software 30 generates a CRC value 0X89ED35 according to the three parameters of the command time (15:30), the command type (0X56), and the command parameter (101) and the current line version (V1.3.3) through a unified algorithm, takes the CRC value as the fourth parameter of the command, and issues the command to the safety check and load balancing service of the safety working node interface software 17. After the service accepts the command, it calculates the CRC value according to the first three parameters, and the calculated CRC value 0X89ED35 is consistent with the CRC value in the issued command, so the command is considered valid. After confirming the parameters, it is judged that the command is a command sent to the train 101, and according to the protocol version number (V3.2) between the current automatic train monitoring system 100 and the VOBC subsystem and the electronic map data (0X49CA35), a CRC value is generated, which is added to the command and the command is issued.
[0073] In some embodiments, the server cluster is composed of local server resources, or composed of cloud platforms that allocate server resources that meet the amount of resources.
[0074] In this way, the deployment method of the server cluster can be selected as needed.
[0075] Specifically, when deploying the server cluster, local servers can be arranged in different regions according to the geographical differences of the line, and this deployment method can ensure the effective transmission of data. Alternatively, a server can be deployed in a selected location, and server resources that meet the amount of resources can be allocated to lines in different regions through a cloud platform, which reduces the use of hardware and space resources and makes the deployment of the server cluster more simple and convenient.
[0076] In some embodiments, the management node 12 includes a main management node 24 and a backup management node 26, the main management node 24 is used for network health monitoring of the working node 14, and the main management node 24 is used for switching to the backup management node 26 when the main management node 24 device fails or the main management node 24 and the working node 14 network fails.
[0077] In this way, the reliability and stability of the automatic train monitoring system 100 can be ensured.
[0078] Specifically, the management node 12 is divided into a primary management node 24 and a backup management node 26, in a normal working state, the internal components in the primary management node 24 perform network health monitoring on the secure working nodes 16 in the working nodes 14, when the primary management node 24 device fails or the primary management node 24 and the secure working nodes 16 network fails are monitored, the internal components switch the primary management node 24 to the backup management node 26, after switching, the original primary management node 24 replicates the current settings of all services and moves to the backup management node 26. Through the switching of the primary management node 24 and the backup management node 26, the automatic train monitoring system 100 can be ensured to run reliably and stably.
[0079] In summary, the automatic train monitoring system 100 based on the container cloud platform uses the container orchestration tool kubernetes to deploy the server cluster, the server cluster includes the management node 12 and multiple working nodes 14, wherein when the server cluster initializes the working nodes 14, the minimum Pod number is set to 2, and the two Pods running the same service are respectively running on two different physical machine resources, which can meet the requirement of the automatic train monitoring system 100 needing to have primary and backup servers at the same time, and at the same time, the primary and backup servers can be balancedly run; the interface software is run on the secure working nodes 16 and the non-secure working nodes 18 in the working nodes 14 for transmitting data, and at the same time, security verification is performed when transmitting data through the interface software, to ensure the security of data transmission; the automatic train monitoring system 100 performs human-computer interaction through the terminal device, the data in other systems is processed by the working nodes 14 and finally displayed on the display interface of the terminal device, at the same time, the user issues a command through the terminal device, which is processed by the working nodes 14 and transmitted to the corresponding system; the secure working nodes 16 interact with other subsystems in the signal system through the external secure firewall security network, and isolate between lines, when increasing the lines, by correspondingly increasing the secure working nodes 16 and allocating part of the resources of the non-secure working nodes 18, it is not necessary to reconfigure the hardware servers and workstations and other resources.
[0080] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "exemplary embodiment", "example", "specific example" or "some examples" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the exemplary description of the above terms does not necessarily mean the same embodiment or example. Moreover, the described specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0081] Although the embodiments of the present application have been shown and described above, it is understood that the above-described embodiments are exemplary and are not to be construed as limiting the present application, and that variations, modifications, substitutions and changes can be made by those skilled in the art without departing from the scope of the present application.
Claims
1. An automatic train supervision system, characterized in that The automatic train supervision system is deployed with a server cluster, the server cluster comprises a management node and a plurality of working nodes, at least two of the plurality of working nodes are capable of running simultaneously; The management node is used for network health monitoring of the working nodes; The working nodes comprise safe working nodes and non-safe working nodes; The non-safe working nodes are used for running front-end software, back-end software and first interface software of the automatic train supervision system; The safe working nodes are used for data analysis services and running safe working node interface software, each of the safe working nodes corresponds to a train line; The safe working nodes are used for information interaction with a signal system through a safe network, when the signal system transmits information to the safe working nodes through the safe network, the safe working nodes are used for: Receiving the information and performing security check; In the case of successful security check, sending the information to the non-safe working nodes; The non-safe working nodes are used for: Receiving the information transmitted by the safe working nodes and performing security check; In the case of successful security check, processing the information and sending to a display interface of the automatic train supervision system for display.
2. The automatic train supervision system according to claim 1, characterized in that The working nodes provide minimum resource management components, the minimum resource management components are used for running front-end software, back-end software, first interface software, data analysis services and running safe working node interface software of the automatic train supervision system, two minimum resource management components running the same service are respectively running on two working nodes.
3. The automatic train supervision system according to claim 2, characterized in that The load distribution strategy of the minimum resource management components is a round robin mode.
4. The automatic train supervision system of claim 1, wherein The first interface software comprises external interface software, the external interface software is used for information interaction with a non-signal system, when the non-signal system transmits data to the external interface software, the non-safe working nodes are used for: Receiving the data transmitted by the non-signal system; Processing the data transmitted by the non-signal system and sending to a preset device.
5. The automatic train supervision system of claim 1, wherein The first interface software comprises internal interface software, the safe working node interface software and the internal interface software communicate after successful security check.
6. The automatic train supervision system of claim 1, wherein, The automatic train supervision system further comprises a terminal device; The terminal device is used for displaying data transmitted by the working nodes and receiving user instructions and sending the user instructions to the signal system through the working nodes.
7. The automatic train supervision system according to claim 6, characterized in that When the terminal device sends the user instructions to the working nodes, the non-safe working nodes are used for: Receiving the user instructions and performing security check; In the case of successful security check, sending the user instructions to the safe working nodes; The safe working nodes are used for: Receiving the user instructions transmitted by the non-safe working nodes and performing security check; In the case of successful security check, sending the user instructions to the signal system.
8. The automatic train supervision system of claim 1, wherein, The server cluster is composed of local server resources, or composed of cloud platforms uniformly managing server resources satisfying a certain amount.
9. The automatic train supervision system of claim 1, wherein, The management node comprises a primary management node and a backup management node, the primary management node is used for network health monitoring of the worker node, and the primary management node is used for switching to the backup management node when the primary management node device fails or the primary management node and the worker node network fail are monitored.
Citation Information
Patent Citations
Server multi-center real-time hot standby switching device of automatic train monitoring system
CN106945691A
Security enhancement equipment for security gateway of rail transit signal system
CN108183886A