Rail transit interlocking system safety requirement construction method and device, medium and product
By using the STPA method and the XSTAMPP tool, the safety requirements of the rail transit interlocking system are constructed, which solves the problem of difficulty in extracting safety requirements in complex rail transit interlocking systems, realizes the automatic generation and refinement of safety requirements, and improves the safety and reliability of the system.
Patent Information
- Application Number
- CN202410928359.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-11
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-07-11
AI Technical Summary
Existing technologies make it difficult to effectively construct the safety requirements of complex rail transit interlocking systems, which makes it difficult to extract safety requirements and affects the safety and reliability of the system.
The STPA method is used to conduct system-level analysis of the rail transit interlocking system to identify dangerous control behaviors. The specific station safety requirements of the complex rail transit interlocking system are obtained through process model variable refinement, and the formal safety requirements are automatically generated using the XSTAMPP tool.
It reduces the difficulty of extracting safety requirements, improves the safety and reliability of the rail transit interlocking system, ensures the safety and stability of train operation, and reduces accident risks and economic losses.
Smart Images

Figure CN118529096B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of rail transit interlocking system safety requirements, and in particular to a rail transit interlocking system safety requirement establishment method, device, medium and product. Background Art
[0002] With the accelerating pace of urbanization, rail transit, as a key mode of urban public transportation, is experiencing rapid development and expansion. However, with the increasing complexity of transportation systems and the widespread application of information technology, rail transit safety issues are gradually emerging. A safe, efficient, and reliable rail transit system is crucial to the sustainable development of cities. Against this backdrop, developing comprehensive and accurate rail transit interlocking system safety requirements is particularly important.
[0003] First and foremost, the rail transit interlocking system is one of the core systems that ensures train safety. A comprehensive rail transit interlocking system ensures safe train operation and prevents serious accidents such as collisions and derailments. Passenger safety is paramount, and the correctness and completeness of safety requirements are directly related to passenger safety.
[0004] Secondly, rationally defining and strictly enforcing safety requirements can ensure the stable operation of rail transit systems. As a vital component of urban transportation, rail transit failures can paralyze traffic and disrupt the normal operation of the city. Therefore, by clearly defining safety requirements, we can reduce accident risks and improve the reliability and stability of the transportation system.
[0005] Furthermore, an economic perspective highlights the importance of developing comprehensive and accurate safety requirements for rail transit interlocking systems. Rail transit accidents often result in significant economic losses, including compensation, equipment repairs and upgrades, and traffic disruptions. By formulating reasonable safety requirements, the probability of accidents can be effectively reduced, minimizing economic losses and conserving valuable resources for sustainable urban development.
[0006] Currently, there are many methods for developing safety requirements for rail transit interlocking systems, including manual analysis methods based on FTA (Fault Tree Analysis), FMEA (Failure Modes and Effects Analysis), and STPA (System-Theorty Process Analysis) techniques, as well as automated methods for constructing formal models based on these methods. Compared to traditional manual analysis methods, automated methods for constructing formal models can improve the reliability and efficiency of rail transit interlocking systems, reduce human errors and failures, and ensure the safety and stability of railway transportation. However, this method also suffers from the complexity of extracting safety requirements due to the large number of variables and the excessive number of variable values in the constructed formal model, making it difficult to apply to rail transit interlocking systems on railways with complex stations. Summary of the Invention
[0007] The purpose of the present invention is to provide a method, device, medium and product for constructing safety requirements of a rail transit interlocking system, which can provide safety requirements for complex stations in the design of rail transit interlocking systems and reduce the difficulty of extracting safety requirements.
[0008] To achieve the above object, the present invention provides the following solutions:
[0009] A method for constructing safety requirements for a rail transit interlocking system, comprising:
[0010] Analyze the rail transit interlocking system to determine system-level accidents and system-level hazards of the rail transit interlocking system;
[0011] Establishing an interlocking system hierarchical control structure of the rail transit interlocking system according to system-level accidents and system-level hazards of the rail transit interlocking system and track resource information of each route controller in the rail transit interlocking system; the track resource information includes a starting signal light, an end signal light, a section, and a turnout;
[0012] The STPA method is used to identify the control behaviors in the rail transit interlocking system to obtain dangerous control behaviors, and the dangerous control behaviors are analyzed to obtain abstract station safety requirements;
[0013] The specific station safety requirements of the rail transit interlocking system are determined according to the interlocking system hierarchical control structure and the abstract station safety requirements.
[0014] A computer device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-mentioned method for establishing safety requirements for a rail transit interlocking system.
[0015] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the above-mentioned method for establishing safety requirements for a rail transit interlocking system.
[0016] A computer program product includes a computer program, which, when executed by a processor, implements the steps of the above-mentioned method for establishing safety requirements for a rail transit interlocking system.
[0017] According to specific embodiments provided by the present invention, the present invention discloses the following technical effects: The present invention provides a method, device, medium, and product for constructing safety requirements for a rail transit interlocking system. The method analyzes the rail transit interlocking system to determine system-level accidents and system-level hazards of the rail transit interlocking system; establishes a hierarchical control structure for the rail transit interlocking system based on the system-level accidents, system-level hazards, and track resource information of each route controller in the rail transit interlocking system; the track resource information includes starting signals, end signals, sections, and switches; utilizes the STPA method to identify control behaviors in the rail transit interlocking system to obtain dangerous control behaviors, and analyzes these dangerous control behaviors to obtain abstract station safety requirements; and determines specific station safety requirements for the rail transit interlocking system based on the interlocking system hierarchical control structure and the abstract station safety requirements. The method utilizes the STPA method to obtain the abstract safety requirements of the rail transit interlocking system, and then refines the process model variables to obtain an analysis method for the specific station safety requirements of a complex rail transit interlocking system. This method, applied to real physical stations, provides safety requirements for the design of rail transit interlocking systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0019] Figure 1 A schematic flow chart of a method for establishing safety requirements for a rail transit interlocking system according to embodiment 1 of the present invention;
[0020] Figure 2 A schematic diagram of the security requirements acquisition process provided in Example 1 of the present invention;
[0021] Figure 3 This is a schematic diagram of the route provided in Example 1 of the present invention;
[0022] Figure 4 A control structure diagram of a rail transit interlocking system with a process model provided in Example 1 of the present invention;
[0023] Figure 5 A schematic diagram of the state transition of the route mode provided in Example 1 of the present invention;
[0024] Figure 6 A schematic diagram of a process model control structure in XSTAMPP provided in Example 1 of the present invention;
[0025] Figure 7 A schematic diagram of the formalized safety requirements for the rail transit interlocking system provided in Example 1 of the present invention;
[0026] Figure 8 The specific station map provided in Example 1 of the present invention;
[0027] Figure 9 This is a diagram of the internal structure of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0028] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0029] A rail transit interlocking system refers to a signal safety system used in transportation systems such as railways and subways. Its primary function is to ensure the safety and smooth operation of trains and prevent conflicts and accidents between trains. Extracting safety requirements is crucial to system safety and must be clearly defined during the system design and development phase. The most important requirement for determining the safety requirements of a rail transit interlocking system is to ensure that trains do not collide or derail. Extracting the safety requirements for complex rail transit interlocking systems is difficult due to the complexity of the system's stations and the high complexity of requirements extraction. Therefore, we propose to conduct a safety analysis of rail transit interlocking systems using the STPA method, based on approaches and abstractions. This approach aims to obtain the formalized safety requirements for the abstract rail transit interlocking system and then transform these abstract rail transit interlocking system safety requirements into requirements for a complex rail transit interlocking system.
[0030] For specific stations, the development of rail transit interlocking systems must be tailored to the specific station's actual conditions. This requires generating corresponding safety requirements for all station components and equipment under corresponding control behaviors. Generally, the safety requirements of rail transit interlocking systems consider the status of all station components and their corresponding control behaviors, and convert them into safety requirements based on whether they pose a danger. However, using STPA to extract safety requirements in this way can be difficult due to the large scale of the rail transit interlocking system's stations. While this method is suitable for small stations, it is not suitable for large stations.
[0031] The purpose of the present invention is to provide a method, device, medium and product for constructing safety requirements of rail transit interlocking systems. The method aims to use the STPA method to obtain the abstract level safety requirements of rail transit interlocking systems, and to obtain an analysis method for the specific station safety requirements of complex rail transit interlocking systems through process model variable refinement. The method acts on real physical stations and provides safety requirements for the design of rail transit interlocking systems.
[0032] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0033] Example 1
[0034] like Figure 1 and Figure 2 As shown, a method for constructing safety requirements for a rail transit interlocking system in this embodiment includes:
[0035] S1: Analyze the rail transit interlocking system to determine system-level accidents and system-level hazards of the rail transit interlocking system.
[0036] S2: Establishing an interlocking system hierarchical control structure of the rail transit interlocking system according to system-level accidents, system-level hazards of the rail transit interlocking system and track resource information of each route controller in the rail transit interlocking system; the track resource information includes starting signal lights, end signal lights, sections and switches.
[0037] S3: Use the STPA method to identify the control behaviors in the rail transit interlocking system to obtain dangerous control behaviors, and analyze the dangerous control behaviors to obtain abstract station safety requirements.
[0038] S4: Determine specific station safety requirements of the rail transit interlocking system according to the interlocking system hierarchical control structure and the abstract station safety requirements.
[0039] The first step of the STPA method for the analysis of the research object is to perform a system-level analysis. For the interlocking system, first, the system-level accidents of the interlocking system are determined. The interlocking system is one of the important systems for controlling the safe operation of trains on the track. In order to ensure the safe operation of trains and avoid long delays, the system-level accidents are determined as train derailment, train collision, and long delay. Next, the system-level hazards that cause the system-level accidents are determined. After determining the system-level hazards, they are listed in a table corresponding to a specific system-level accident, indicating that a certain system-level hazard will cause a specific system-level accident. Next, the control structure of the interlocking system is studied to determine how the system-level hazards are generated.
[0040] Step S1 specifically includes: performing a system-level analysis on the rail transit interlocking system to determine system-level accidents and hazards. Specifically, for the rail transit interlocking system, system-level accidents are serious malfunctions or failures that occur during train operation, causing the system to fail to function normally or fail to achieve the expected function. System-level accidents of the rail transit interlocking system can be divided into two major categories: derailment and collision, as well as long delays on the line.
[0041] The specific process is: system-level accidents are caused by corresponding system-level hazards, which are triggered by corresponding hazard control behaviors. In order to determine the safety requirements related to control behaviors in the system, it is necessary to first define and analyze the system-level accidents of the rail transit interlocking system to obtain the related system-level hazards, thereby establishing the relationship between potential hazard control behaviors and system-level accidents.
[0042] Accidents in the rail transit interlocking system mainly occur during the train operation phase. The main system-level accidents in this phase are: A-1 train derailment; A-2 train-to-train collision; A-3 long delay of the train (long delay of the train indicates that the delay time of the train is greater than a predetermined threshold range). The system-level hazards of the rail transit interlocking system are: H-1 two trains occupying the same section; H-2 the turnout in the route range is not in the correct position when the train is running; H-3 the turnout in the route range changes when the train is running; H-4 system component control failure. The accident and related system-level hazard analysis mapping relationship is shown in Table 1 below:
[0043] Table 1 System-level accidents and hazards of the interlocking system
[0044]
[0045] Step S2 is used to establish a hierarchical control structure of the interlocking system based on the route form (i.e., the interlocking system hierarchical control structure). Specifically, according to the composition of the interlocking system and the process of the route controller controlling the train operation, an interlocking system hierarchical control structure diagram is constructed.
[0046] The hierarchical control structure of an interlocking system is a layered system model, encompassing controllers, sensors, actuators, control processes, feedback and control action flows, environmental disturbances, system inputs, and system outputs. First, the components involved in the interlocking system control process, such as signals and switches, and their associated controllers, are analyzed. The route controller is identified as the core controller in the control structure diagram. Modeling the interlocking system control structure using the route controller provides a clearer picture of the interlocking system's control details. When constructing the control structure diagram, route and conflict route controllers are incorporated, along with process models and process model variables for each component, paving the way for the formal extraction of interlocking system safety requirements. Next, the values of the process model variables are determined, with a focus on the route mode conversion model for process model variables. Finally, a control structure diagram for the interlocking system, based on the route formalization, is generated. The resulting control structure is then plotted in the XSTAMPP tool for subsequent safety requirements generation.
[0047] This diagram shows the interlocking system control structure based on routes. A route is a group of adjacent signaling devices (such as signals and switches) that are combined under certain conditions to ensure the safe passage of trains along a specific path. Routes are designed to control train trajectories and prevent conflicts and accidents. Routes can be thought of as dividing the large interlocking system into multiple smaller segments, each of which is a route.
[0048] In step S2, an interlocking system hierarchical control structure of the rail transit interlocking system is established according to the system-level accidents and system-level hazards of the rail transit interlocking system and the track resource information of each route controller in the rail transit interlocking system, specifically including:
[0049] Using the XSTAMPP tool, the interlocking system hierarchical control structure of the rail transit interlocking system is established based on the system-level accidents, system-level hazards, track resource information of each route controller in the rail transit interlocking system, and process model variables. The specific process is as follows:
[0050] By analyzing the role of routes in train control, we determine the control relationships within the control structure diagram and establish a hierarchical control structure diagram based on the route format. A route is a specific path that the interlocking system authorizes a train to pass through. Each route consists of track segments connected in a topological order, including adjacent signal equipment (such as signals and switches). The route controller assists the interlocking system in controlling the safe operation of trains. Controlling train operation is primarily divided into three stages: route setting, route locking, and route release. A simple representation of a route on a station yard is shown below: Figure 3As shown in the figure, the track resources included in route R1 can be seen in interlocking table 2, including sections, signal lights and other components. Conflicting routes refer to the overlapping track resources of two routes. If a conflicting route exists when a route is opened, it cannot be successfully opened, otherwise it will cause a safety accident. When establishing a route, the information in the interlocking table will be referred to to determine whether the conditions for setting the route are met (R2 and R3 are not in Figure 3 listed in ).
[0051] Table 2 Interlocking table
[0052]
[0053] The route controllers, switches, signal lights, and sections in the above analysis are incorporated into the route-based hierarchical control structure, and route controllers and conflicting route controllers are introduced. The interlocking system control structure with process model variables is used to reflect the control situation of the system, where the process model is a model of the assumed state of the controlled process of each controller in the control structure diagram.
[0054] Process model variables are key variables that indicate the controller's state. The values of all process model variables reflect the current controller state. In this embodiment, these process model variables include: Route Mode, Protective Signal State, Source Signal State, Point Position, Section State, and a variable for determining whether a conflicting route exists (i.e., the conflicting route determination variable).
[0055] The variables Conflict route and Right position take the values {YES, NO}, which are used to indicate whether there is a conflicting route and whether the switch is in the correct position; the values of Source signal and Protective signal are both {Green, Red}, which indicate the color of the signal light; Route mode takes the values {Free, Dispatched, Allocated, Locked, Occupied}, which indicates the mode of the current route; Section state takes the values {Vacant, EXLCK, Occupied}, which indicates the current section status; Point state {Unlock, Locked}, which indicates the current switch locking status. A Section state value of Vacant indicates that the section is idle; EXLCK indicates that the section is specially prepared for a certain route and is in a locked state; Occupied indicates that a train has occupied this section.
[0056] According to the above information, a hierarchical control structure of the interlocking system based on the route can be constructed, such as Figure 4 As shown. The Interlocking Panel / ATS is the automatic train monitoring system. Otherwise, it sends a route request to the interlocking controller. The route mode is " <route>The state transition of the "Mode" is shown as Figure 5
[0057] Specifically, in the above-mentioned route mode Route mode, Free indicates that the route is in an idle state, and the conversion of the route mode is as follows:
[0058] After receiving a request for the route from the Free state, it is detected whether the section is idle. If it is idle, the route is converted to Dispatched;
[0059] If there is no conflicting route detected from the Dispatched state, and the section state is Free and the protection signal is Red, the state is converted to Allocated;
[0060] If all switches are confirmed to be moved to the specified position and locked, and the signal lamp is set correctly from the Allocated state, the state is converted to Locked;
[0061] When the Source signal is green from the Locked state and the train enters the section, the state is converted to Occupied;
[0062] If the section state in the route range is Vacant from the Occupied state, the state is converted to Free;
[0063] Based on the system-level analysis and the constructed interlocking system control structure diagram in the above steps, the interlocking system control structure with a process model is established using the XSTAMPP tool. Specifically, according to the above analysis and the constructed control structure diagram, the interlocking system control structure based on the route is established on the XSTAMPP tool, and the established interlocking system control structure based on the route is as shown in Figure 6
[0064] The interlocking system control structure with a process model constructed using the XSTAMPP tool can obtain the safety requirements of the abstract level of the interlocking system in combination with related control behaviors.
[0065] Step S3 is used to identify the dangerous control behavior of the interlocking system and to realize the detailed analysis of the dangerous control behavior, and the safety requirements of the abstract level of the interlocking system are determined according to the analysis results. Specifically, the STPA method is used to identify the dangerous control behavior first, then the detailed analysis of the dangerous control behavior is realized by using the process model variable combination, and finally the safety requirements of the abstract interlocking system are obtained.
[0066] The specific process is as follows: First, the control actions in the interlocking system are identified. The main control actions of the interlocking system during the train's operating cycle include setting the signal light to red or green, unlocking or locking the switch, and rotating the switch. Next, using the STPA method, dangerous situations resulting from unsafe control actions are categorized into four categories: ① No control provided; ② Control provided; ③ Control provided at the wrong time or in the wrong sequence; and ④ The control action lasts too long or is terminated prematurely. To illustrate the application of the STPA method in a general interlocking system, the control action of setting the signal light to green is analyzed and evaluated as an example. The dangerous control actions are shown in Table 3, and Table 4 lists the safety constraints for these dangerous control actions.
[0067] Table 3 Hazard Control Behavior Table
[0068]
[0069] Table 4 Safety requirements for hazard control behaviors
[0070]
[0071] The STPA method is used to identify the dangerous control behaviors at the abstract level of the interlocking system. These control behaviors will lead to system-level hazards. Then, in order to analyze the causes of the hazards, the dangerous control behaviors will be analyzed in detail. The detailed analysis is achieved through the combination of process model variables obtained in the control structure diagram. The safety requirements of the interlocking system at the abstract level will be obtained through the detailed analysis of the control behaviors. Then, according to the above analysis method, the safety requirements will be expressed through the XSTAMPP tool. This requirement is different from the requirements expressed in natural language. It is expressed in a formal form. This requirement is the basis for obtaining the safety requirements of complex interlocking systems.
[0072] In step S3, the risk control behavior is analyzed, specifically including:
[0073] combining the process model variables to obtain a process model variable combination;
[0074] The hazard control behavior is analyzed based on the process model variable combinations. This is used to further refine the hazard control behavior, providing a more comprehensive understanding of how hazard control behaviors arise and deriving more detailed interlock system safety requirements. Refining hazard control behaviors is achieved through the combination of process model variables. For each control behavior, a manual assessment is performed to determine whether each combination of process model states results in a hazard. The evaluation results obtained using some process model variable combinations are shown in Table 5.
[0075] Table 5 Context table based on process model variables
[0076]
[0077] By analyzing each combination of identified unsafe behaviors and eliminating non-hazardous situations, we obtain refined hazardous control behaviors. For example, when the protective signal is green, the route is in the Free state, the section is idle, and the switch is unlocked, opening the route signal is hazardous. Refined analysis of the control behavior of setting the signal to green yields related refined hazardous control behaviors. This results in a partial list of refined safety requirements, namely, the abstract station safety requirements, as shown in Table 6.
[0078] Table 6 Detailed safety requirements of the interlocking system
[0079]
[0080] The safety requirements obtained in the above steps are expressed in natural language, and the analysis process is less automated. The XSTAMPP tool can improve the analysis efficiency and automate the analysis process. In step S2 above, the control structure diagram of the interlocking system has been obtained using the XSTAMPP tool. After importing the control behavior, the formal safety requirements of the interlocking system can be automatically generated. The safety requirements obtained using this tool are as follows: Figure 7 shown.
[0081] Step S4 is used to use the process model variable refinement to determine the safety requirements of the specific station field of the interlocking system (i.e., the specific station field safety requirements). Specifically, there is a connection between the specific station field and the abstract station field. The states of multiple components of the same type in the specific station field are mapped to the states in the abstract station field, and then the variable values in the abstract station field are replaced with the variables of the specific station field to obtain the safety requirements of the specific station field. The specific process is as follows: First, the process model variable refinement is used to establish a corresponding relationship between the specific station field component variables and the abstract station field component variables. In view of the connection between the complex station field and the abstract station field, the method provided in this embodiment is specifically described below using a specific station field as an example. The schematic diagram of the station field is shown as follows. Figure 8 shown.
[0082] The specific station diagram contains four routes, R1, R2, R3, and R4, multiple signals such as SG10 and SG11, and multiple sections, such as L11, L12, and L13. The station diagram serves as the foundation for STPA analysis within the specific station. Multiple components of the same type within the route range on the diagram will be included in the analysis. For example, for route R4, the status of sections L11, L12, and L13, signals SG10 and SG11, and switches P12 and P13 all need to be considered in the requirements analysis.
[0083] Process model variable refinement also includes refining the value range of abstract variables to make the process model more complete. Some examples of process model variable refinement are as follows:
[0084] Conflict route { YES , NO}
[0085] R2Mode { Free , Dispatched , Allocated , Locked , Occupied}
[0086] R4Mode { Free , Dispatched , Allocated , Locked , Occupied}
[0087] R4Mode { Free , Dispatched , Allocated , Locked , Occupied}
[0088] Section state {Vacant, Exlck, Occupied}
[0089] L11 state { Vacant , Exlck , Occupied}
[0090] L12 state { Vacant , Exlck , Occupied}
[0091] L13 state { Vacant , Exlck , Occupied}
[0092] Point state {Unlock, Locked}
[0093] P12 state {Unlock, Locked}
[0094] P13 state {Unlock, Locked}
[0095] Point position { Right , Wrong}
[0096] P12 position {Normal, Reverse, Mediate}
[0097] P13 position{Normal, Reverse, Mediate}
[0098] Taking the section as an example, the correspondence between specific station component variables and abstract variables is illustrated, as shown in Table 7.
[0099] Table 7 Correspondence between abstract variables and specific station variables
[0100]
[0101] The first row in Table 7 shows the abstract variable Section state and its three possible values. The value of Section state is determined by the values of L11, L12, and L13 in each column. Section state can only be Exlck when L11, L12, and L13 are all Exlck; Section state can only be Vacant when L11, L12, and L13 are all Vacant. When Section state is Occupied, it is quite special and needs to be combined with the specific route on the specific interlocking station. For example, in the R4 route, if the train occupies all sections within the route range, the first two sections, the last two sections, or only one of the three sections, these are all cases where Section state is Occupied. Other occupancy situations are abnormal because trains cannot occupy multiple sections. The corresponding relationship between abstract stations and complex stations can be used to express the safety requirements of complex stations. Taking a formalization of the safety requirements on the abstract station as an example, the corresponding safety requirements of the complex station are expressed as follows:
[0102] ((route mode == occupied)&& (P12 state == Locked&&P13 state ==Locked)&& (P12 position == Normal&&P13 position == Normal)&& (SG10 ==red)&& (L11state ==Vacant&&L12 state ==Vacant&&L13 state ==Vacant)&& (SG11 ==red) ->!(controlAction==setfhsignalgreen)) is explained as follows in natural language: When the route mode is Occupied, switches P12 and P13 in the section are both in the Locked state and in Normal, the protective signal SG10 is Red, sections L11, L12, and L13 are all Vacant, and the route signal SG11 is Red, the proceeding signal cannot be opened, that is, SG10 cannot be set to Red.
[0103] To translate the safety requirements of the interlocking system at the abstract level into the safety requirements of specific stations, we first need to identify a specific station. Based on this specific station, we then establish a refined relationship between abstract component variables and specific station component variables. This relationship is represented through variables, i.e., the variable refinement of the process model. A single abstract variable may correspond to multiple similar components, and these corresponding relationships are then expressed. The next step is to replace the abstract variable values in the safety requirements at the interlocking system abstract level with the variable values corresponding to the specific station, and combine them with relevant control actions to obtain the safety requirements for the specific station. This process is implemented using the XSTAMPP tool software, ultimately resulting in the safety requirements for the specific stations of the complex interlocking system.
[0104] This embodiment can obtain the safety requirements of specific stations in a complete complex interlocking system. The requirements are expressed in a formalized manner, thus completing the extraction of safety requirements of specific stations in the complex interlocking system.
[0105] This embodiment constructs an STPA safety requirements construction method based on the approach form. By matching the safety requirements of the rail transit interlocking system at the abstract level with the complex station components, the safety requirements of the complex rail transit interlocking system are successfully extracted. This greatly alleviates the problem of difficulty in extracting safety requirements due to the complexity of the station when constructing a formal model to automatically generate the safety requirements of the rail transit interlocking system. In terms of rail transit interlocking system design, it can provide the safety requirements of complex stations and reduce the difficulty of safety requirement extraction.
[0106] Compared with the existing method of extracting safety requirements for specific stations of complex interlocking systems, this embodiment can avoid directly incorporating all components and controllers in the specific station into the safety analysis during the safety analysis phase. Instead, the STPA method is first used to analyze the abstract level of the interlocking system in the form of an approach. After obtaining the safety requirements at the abstract level of the interlocking system, the process model variable refinement is used to convert the abstract safety requirements of the interlocking system into the safety requirements of the specific station. This can be achieved through the XSTAMPP tool. This method of indirectly extracting the safety requirements of the specific station of a complex interlocking system can greatly reduce the difficulty of analyzing and extracting the requirements.
[0107] This embodiment constructs a control structure diagram of the interlocking system in the form of an approach, accurately depicts the control details of the interlocking system, proposes abstract processing of components and introduces process model variables and related values, which is conducive to reducing the difficulty of obtaining the safety requirements of the interlocking system. This is because the state space of multiple similar components is much larger than the state space represented by a single abstract component variable, which makes it easier to obtain safety requirements and reduces the analysis difficulty.
[0108] Finally, the refined relationship between the abstract variables and the specific station variables of the complex interlocking system is obtained by refining the process model variables, and then the abstract safety requirements of the interlocking system can be converted into the safety requirements of the specific station of the complex interlocking system.
[0109] Example 2
[0110] A computer device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor executes the computer program to implement the steps of a method for constructing safety requirements for a rail transit interlocking system in Example 1.
[0111] Example 3
[0112] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of a method for constructing safety requirements for a rail transit interlocking system in Example 1.
[0113] Example 4
[0114] A computer program product includes a computer program, which, when executed by a processor, implements the steps of a method for establishing safety requirements for a rail transit interlocking system in Example 1.
[0115] Example 5
[0116] A computer device, which may be a database, may have an internal structure as shown in FIG. Figure 9 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store pending transactions. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a method for constructing safety requirements for a rail transit interlocking system in Example 1.
[0117] It should be noted that the object information (including but not limited to object device information, object personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in the present invention are all information and data authorized by the object or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.
[0118] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the above-described method embodiments. Any reference to memory, database, or other media used in the embodiments provided herein may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, and the like.
[0119] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0120] This document uses specific examples to illustrate the principles and implementation methods of the present invention. The above examples are only intended to help understand the method and core concept of the present invention. At the same time, those skilled in the art will find that the specific implementation methods and application scopes may vary based on the concept of the present invention. In summary, the contents of this specification should not be construed as limiting the present invention.< / route>
Claims
1. A method for constructing safety requirements for a rail transit interlocking system, characterized in that: include: Analyze the rail transit interlocking system to determine system-level accidents and system-level hazards of the rail transit interlocking system; The interlocking system hierarchical control structure of the rail transit interlocking system is established according to the system-level accidents and system-level hazards of the rail transit interlocking system and the track resource information of each route controller in the rail transit interlocking system, specifically including: Using the XSTAMPP tool, a hierarchical control structure of the rail transit interlocking system is established based on system-level accidents and system-level hazards of the rail transit interlocking system, track resource information of each route controller in the rail transit interlocking system, and process model variables; the track resource information includes starting signal lights, end signal lights, sections, and switches; the process model variables include route mode, route signal status, protection signal status, switch position, section status, switch status, and conflict route judgment variables; The STPA method is used to identify the control behaviors in the rail transit interlocking system to obtain dangerous control behaviors, and the dangerous control behaviors are analyzed to obtain abstract station safety requirements; Analyzing the risk control behavior specifically includes: combining the process model variables to obtain a process model variable combination; analyzing the risk control behavior according to the process model variable combination The specific station safety requirements of the rail transit interlocking system are determined according to the interlocking system hierarchical control structure and the abstract station safety requirements.
2. A rail transit interlocking system safety requirement construction method according to claim 1, characterized in that: System-level incidents include train derailments, train-to-train collisions, and long train delays.
3. A computer device comprising: A memory and a processor are provided with a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of a method for constructing safety requirements for a rail transit interlocking system as described in any one of claims 1-2.
4. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for constructing safety requirements for a rail transit interlocking system described in any one of claims 1-2 are implemented.
5. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method for constructing safety requirements for a rail transit interlocking system described in any one of claims 1-2 are implemented.
Citation Information
Patent Citations
Function security hazard and information security threat analysis method based on STPA model
CN110008607A
Safety interlocking system development method based on fault tree analysis
CN115544463A