Vehicle domain control system, method and train

By using a master domain controller and slave domain controller architecture and flexibly configuring standard boards, the problem of hardware and software bundling in traditional rail transit vehicle control systems has been solved, enabling the simplification and intelligent upgrade of the control system and improving passenger experience and operational efficiency.

CN119975426BActive Publication Date: 2025-12-02CRRC QINGDAO SIFANG CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510245381.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-12-02
Estimated Expiration
2045-03-03

AI Technical Summary

Technical Problem

Traditional rail transit vehicle control systems lack hardware-based design with replaceable functional units when undergoing intelligent upgrades, resulting in heavy hardware and software integration and a poor riding experience.

Method used

It adopts a master domain controller and slave domain controller architecture, and enables flexible configuration through standard boards. It realizes centralized processing of data flow and logical operations, breaks the hardware and software binding, reduces the number of controllers, and improves system security through load protection mechanisms and redundancy design.

Benefits of technology

The system architecture has been simplified, equipment costs have been reduced, the utilization rate of the vehicle's interior space and passenger experience have been improved, and more efficient train operation and intelligent control have been achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119975426B_ABST
    Figure CN119975426B_ABST
Patent Text Reader

Abstract

This disclosure provides a vehicle domain control system applicable to the field of rail transit technology. The control system includes: a master domain controller configured to generate control commands based on the control logic and equipment status information of a train car; and slave domain controllers configured to receive control commands sent by the master domain controller and execute control actions according to the commands. Each of the master and slave domain controllers includes a standard board conforming to preset specifications and interface standards. The configuration information of the master domain controller is determined based on the control requirements of the train car spatial domain or the control requirements of the functional domain. Multiple slave domain controllers are included, and the master domain controller is connected to the multiple slave domain controllers via communication links. This disclosure also provides a vehicle domain control method and a train.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of rail transit technology, and more specifically to a vehicle domain control system, method, and train. Background Technology

[0002] The control system of rail transit vehicles is a highly integrated and complex system. Its core objective is to ensure the safe and efficient operation of trains through the coordinated work of multiple modules (such as power supply, traction, braking, and communication). Traditional rail transit vehicle control systems are communication-based train control systems, consisting of automatic train monitoring, data communication systems, area controllers, and onboard controllers.

[0003] While traditional hierarchical control systems can achieve basic automation, they face challenges when upgrading to intelligent systems. They lack hardware design based on replaceable functional units, and the various control devices in the vehicle suffer from problems such as heavy hardware and software bundling, device-based functionality, and a low level of passenger experience. Summary of the Invention

[0004] In view of the above problems, this disclosure provides a vehicle domain control system, method and train.

[0005] According to a first aspect of this disclosure, a vehicle domain control system is provided, comprising: a master domain controller configured to generate control commands based on the control logic of a train car and the equipment status information of the train car; and a slave domain controller configured to receive the control commands sent by the master domain controller and execute control actions according to the control commands; wherein the master domain controller and the slave domain controller each include a standard board, the standard board conforming to preset specifications and interface standards, the configuration information of the master domain controller is determined based on the control requirement information of the train car spatial domain or the control requirement information of the functional domain, and there are multiple slave domain controllers, with the master domain controller and the multiple slave domain controllers connected through communication links.

[0006] According to embodiments of this disclosure, the spatial domain includes a driving domain, a passenger compartment domain, a roof domain, and an under-vehicle domain. The master domain controller selects the domain controller corresponding to the largest control demand information from multiple control demand information by comparing the control demand information of the driving domain, the passenger compartment domain, the roof domain, and the under-vehicle domain. The master domain controller meets the preset conditions for computing resources and communication bandwidth.

[0007] According to embodiments of this disclosure, the functional domains include a traction functional domain, a braking functional domain, an air conditioning functional domain, a door functional domain, a lighting functional domain, and a control logic domain; the master domain controller is used to control the control logic domain, and the slave domain controllers are used to control the traction functional domain, the braking functional domain, the air conditioning functional domain, the door functional domain, and the lighting functional domain.

[0008] According to embodiments of this disclosure, the standard board is further configured to update the control algorithm, hardware configuration, and communication protocol of the standard board based on the control signals of the train carriage, thereby obtaining an updated board.

[0009] According to embodiments of this disclosure, the standard board is also configured to accommodate non-standard control signals through interface design and modular design to allow access to non-standard boards.

[0010] According to embodiments of this disclosure, the standard board is further configured to meet preset safety standards through a load protection mechanism; the load protection mechanism includes at least one of the following: the standard board employs an overcurrent protection device to perform a disconnection operation when the current exceeds a preset threshold; overload protection and disconnection operations are performed between the sub-channels and the main channel within the standard board through a multi-channel analog-to-digital converter and a baseboard management chip; and overload protection is performed between the standard board and the sub-boards using a power management chip.

[0011] According to embodiments of this disclosure, the primary domain controller is further configured to process the same input signal in parallel through at least two independent channels, generate respective output results, and compare multiple output results. If multiple output results are the same, the output result is taken as the final output to meet the redundancy configuration requirements. The secondary domain controller is further configured to meet the security level requirements through hardware isolation strategy, software space independence strategy, and software time independence strategy.

[0012] According to embodiments of this disclosure, the standard board meets preset specifications and interface standards by: determining the interface standards, communication design, power supply design, board size, and connector type of the standard board.

[0013] According to embodiments of this disclosure, the master domain controller and the slave domain controller are further configured to employ multiple independent power boards, each power board including a power connector, wherein the physical interface and interface definition of the power connectors of the multiple power boards are identical.

[0014] The second aspect of this disclosure provides a vehicle domain control method applied to a vehicle domain control system. The method includes: a master domain controller generating control commands based on the control logic of a train car and the equipment status information of the train car; and a slave domain controller receiving the control commands sent by the master domain controller and executing control actions according to the control commands. Each of the master and slave domain controllers includes a standard board conforming to preset specifications and interface standards. The configuration information of the master domain controller is determined based on the control requirements information of the train car spatial domain or the control requirements information of the functional domain. Multiple slave domain controllers are included, and the master domain controller is connected to the multiple slave domain controllers via communication links.

[0015] A third aspect of this disclosure provides a train, comprising: a carriage; and a vehicle domain control system according to any of the preceding claims.

[0016] A fourth aspect of this disclosure provides an electronic device comprising: one or more processors; and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors perform the methods described above.

[0017] A fifth aspect of this disclosure also provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the methods described above.

[0018] A sixth aspect of this disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0019] According to the vehicle domain control system, method, and train provided in this disclosure, redundant control of key control functions is achieved through a master domain controller and slave domain controllers, realizing centralized processing of data flow and logical operations, thus avoiding redundancy and complexity of controllers. Because the master and slave domain controllers are flexibly configured based on replaceable unit-standard boards, the problems of hardware and software bundling and function bundling are broken, reducing the number of vehicle controllers, simplifying the control system architecture, and reducing equipment costs. Through integrated design, the vehicle's electronic system is more compact, better adapting to the limited space inside the vehicle, and improving the passenger experience. Attached Figure Description

[0020] The above and other objects, features and advantages of this disclosure will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0021] Figure 1 The diagram illustrates an application scenario of a vehicle domain control system, method, and train according to embodiments of the present disclosure.

[0022] Figure 2 A schematic block diagram of a vehicle domain control system according to an embodiment of the present disclosure is shown.

[0023] Figure 3A The diagram schematically illustrates example diagrams of controllers and related equipment corresponding to a train space domain according to embodiments of the present disclosure, wherein (3A-1) shows an example diagram of the distribution of the space domain, and (3A-2) shows an example diagram of controllers and related equipment.

[0024] Figure 3B A schematic diagram illustrating an extended topology between a master domain controller and a slave domain controller according to an embodiment of the present disclosure is provided.

[0025] Figure 4The schematic diagram shows the chassis dimensions of the master domain controller and the slave domain controller according to an embodiment of the present disclosure, wherein (4a) is a front view and (4b) is a top view.

[0026] Figure 5 A schematic diagram of the system architecture of a master domain controller and a slave domain controller according to an embodiment of the present disclosure is shown.

[0027] Figure 6 A flowchart illustrating a vehicle domain control method according to an embodiment of the present disclosure is shown schematically. Detailed Implementation

[0028] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0029] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0030] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0031] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).

[0032] In the technical solution disclosed herein, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, necessary confidentiality measures have been taken, and they do not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse.

[0033] Traditional rail transit vehicle control systems face challenges when undergoing intelligent upgrades. They lack hardware design based on replaceable functional units, and the various control devices in the vehicle suffer from problems such as heavy hardware and software bundling, device-based functionality, and a low level of passenger experience.

[0034] In view of this, this disclosure utilizes a master domain controller and slave domain controllers to provide redundant control over critical control functions, achieving centralized processing of data flow and logical operations, and avoiding redundancy and complexity in the controllers. By flexibly configuring the master and slave domain controllers based on replaceable unit-standard boards, the issues of hardware / software bundling and function bundling are broken, reducing the number of vehicle controllers, simplifying the control system architecture, and reducing equipment costs. Through integrated design, the vehicle's electronic systems are more compact, better adapting to the limited space inside the vehicle, and further enhancing the passenger experience.

[0035] This disclosure provides a vehicle domain control system, method, and train. The vehicle domain control system includes: a master domain controller configured to generate control commands based on the control logic of a train car and the equipment status information of the train car; and slave domain controllers configured to receive the control commands sent by the master domain controller and execute control actions according to the control commands. Each of the master domain controller and the slave domain controller includes a standard board conforming to preset specifications and interface standards. The configuration information of the master domain controller is determined based on the control requirements information of the train car spatial domain or the control requirements information of the functional domain. Multiple slave domain controllers are included, and the master domain controller is connected to the multiple slave domain controllers via communication links.

[0036] Figure 1 The diagram illustrates an application scenario of a vehicle domain control system, method, and train according to embodiments of the present disclosure.

[0037] like Figure 1As shown, the application scenario according to this embodiment may include a master domain controller 101, a slave domain controller 102, a network 103, and a vehicle compartment 104. The network 103 serves as a medium for providing a communication link between the master domain controller 101 and the slave domain controller 102. The network 103 may include various connection types, such as wired or wireless communication links or fiber optic cables. It is understood that the master domain controller 101 and the slave domain controller 102 can be configured inside the vehicle compartment 104 according to actual conditions; their specific locations are not limited here.

[0038] The master domain controller 101 can be used to acquire train status information and send control commands to slave domain controllers based on the overall operating status and control logic of the vehicle. For example, the master domain controller 101 can collect real-time equipment status information, train operating status information, and cabin environment information.

[0039] The slave domain controller 102 can feed back the status information of the execution module to the master domain controller. For example, after receiving the instruction from the master controller 101, the slave domain controller 102 executes the instruction through the air conditioning control module to control the on / off of the air conditioning system and adjust the temperature and fan speed.

[0040] The master domain controller 101 and the slave domain controller 102 can cooperate to achieve complex functions of the train. For example, in the automatic driving function, the master domain controller 101 (e.g., the driving domain controller) and the slave domain controller (e.g., the off-board domain controller) cooperate to ensure that the vehicle can respond quickly in dangerous conditions.

[0041] For example, the master domain controller 101 can send braking, acceleration, or steering commands to the slave domain controller 102. For example, the slave domain controller 102 can transmit information such as braking system pressure and motor speed to the master domain controller in real time.

[0042] It should be noted that, Figure 1 The number of slave domain controllers and networks can be multiple, depending on actual needs.

[0043] Figure 2 A schematic block diagram of a vehicle domain control system according to an embodiment of the present disclosure is shown.

[0044] like Figure 2 As shown, the vehicle domain control system of this embodiment includes a master domain controller 101 and a slave domain controller 102.

[0045] The main domain controller 101 is configured to generate control commands based on the control logic of the train carriages and the equipment status information of the train carriages.

[0046] Domain controller 102 is configured to receive control commands sent by the primary domain controller and execute control actions according to the control commands.

[0047] Preferably, the master domain controller 101 and the slave domain controller 102 each include a standard board, which conforms to preset specifications and interface standards. The configuration information of the master domain controller is determined based on the control requirements information of the train carriage space domain or the control requirements information of the functional domain. There are multiple slave domain controllers, and the master domain controller and the multiple slave domain controllers are connected through communication links.

[0048] In the embodiments of this disclosure, the functional domain of the train car can be an architecture that divides the train according to different functional modules; the spatial domain can be an architecture that divides the vehicle according to its physical space. Standard boards can adopt a modular design for easy expansion and maintenance.

[0049] For example, the main domain controller 101 can collect real-time equipment status information within the train carriages through various types of sensors and communication interfaces. The main domain controller 101 can also analyze and process the collected status information according to preset control logic. Preset control logic includes, but is not limited to, safety logic, operational logic, and comfort logic. The main domain controller 101 can also generate specific control commands based on the processing results of the control logic. Control commands include, but are not limited to, equipment control commands, operational control commands, and safety control commands.

[0050] For example, the master domain controller 101 can send the generated control commands to the slave domain controller 102 or other relevant devices via a communication link. Upon receiving the commands, the slave domain controller 102 can execute the corresponding operations and feed the execution results back to the master domain controller 101. Furthermore, the master domain controller 101 can further adjust the control logic and commands based on the execution results fed back by the slave domain controller 102. This process is dynamic, and through the coordinated control of the master domain controller 101 and the slave domain controller 102, the train can be ensured to operate in its optimal state.

[0051] For example, the slave domain controller 102 can be used to execute the instructions of the master domain controller 101 and feed back the execution results to the master domain controller 101, thereby realizing real-time control and dynamic adjustment of the train equipment.

[0052] For example, the standard boards in the master domain controller 101 and slave domain controller 102 can be configured with standardized communication interfaces. The communication interface is located on the first side of the board, facilitating communication with other boards. The standard boards are pluggable, facilitating insertion and removal, and promoting standardized design and maintenance. The standard boards can support various hardware and storage interfaces to meet the needs of different functional modules; they also support multiple communication protocols to ensure compatibility between different devices; and they can comply with specific power management standards to ensure stable system operation.

[0053] According to embodiments of this disclosure, redundant control of critical control functions is achieved through a master domain controller and slave domain controllers, enabling centralized processing of data flow and logical operations, thus avoiding redundancy and complexity in the controllers. Because the master and slave domain controllers are flexibly configured based on replaceable unit-standard boards, the issues of hardware / software bundling and function bundling are broken, reducing the number of vehicle controllers, simplifying the control system architecture, and reducing equipment costs. Through integrated design, the vehicle's electronic systems are more compact, better adapting to the limited space inside the vehicle, further enhancing the passenger experience.

[0054] According to embodiments of this disclosure, the spatial domain includes a driving domain, a passenger compartment domain, a roof domain, and an under-vehicle domain. The master domain controller selects the domain controller corresponding to the largest control demand information from multiple control demand information by comparing the control demand information of the driving domain, the passenger compartment domain, the roof domain, and the under-vehicle domain. The master domain controller meets the preset conditions for computing resources and communication bandwidth.

[0055] Figure 3A The diagram schematically illustrates example diagrams of controllers and related equipment corresponding to a train space domain according to embodiments of the present disclosure, wherein (3A-1) shows an example diagram of the distribution of the space domain, and (3A-2) shows an example diagram of controllers and related equipment.

[0056] like Figure 3A As shown in Figure (3A-1), the spatial domain of the train may include the driving domain 301, the interior domain 302, the roof domain 303, and the undercarriage domain 304. For example... Figure 3A As shown in Figure (3A-2), the related equipment corresponding to the spatial domain may include a control console 31, a Passenger Information System (PIS) 32, doors 33, air conditioning equipment 34, traction equipment 35, braking equipment 36, data acquisition equipment 37, and front cabin equipment 38. The controller corresponding to the driving domain 301 is the driving domain controller 3011, the controller corresponding to the interior domain 302 is the interior domain controller 3021, and the controller corresponding to the under-vehicle domain 304 is the under-vehicle domain controller 3041.

[0057] In the embodiments of this disclosure, before selecting the domain controller corresponding to the maximum control demand information as the primary domain controller, the maximum demand information can be determined first. The determination process may include: defining the control demand information of each functional domain by defining a quantitative standard for the control demand information, determining the maximum demand information by comparing the control demand information, and then determining the domain controller corresponding to the maximum control demand information as the primary domain controller.

[0058] For example, specific quantitative indicators for the control requirements of each functional domain should be defined. Control requirements can be quantified based on factors such as task complexity, resource consumption, and priority. Each domain controller can generate a control requirement value based on its own task requirements. Control requirement information is collected from the domain controllers in the driving, passenger compartment, roof, and under-vehicle domains. The collected control requirement information is then compared to identify the domain controller with the highest control requirement value, and this domain controller is designated as the primary domain controller.

[0059] In one feasible embodiment, after determining the primary domain controller, considering that the vehicle's operating environment and task requirements may change dynamically, the selection of the primary domain controller can be configured to have dynamic adjustment capabilities. This allows for periodic reassessment of the control requirements of each domain, and the selection of a new primary domain controller based on the latest information. Dynamically adjusting the primary domain controller based on the latest control requirements information allows for more rational allocation of computing resources, communication bandwidth, and energy, avoiding resource waste.

[0060] According to embodiments of this disclosure, the functional domains include a traction functional domain, a braking functional domain, an air conditioning functional domain, a door functional domain, a lighting functional domain, and a control logic domain; the master domain controller is used to control the control logic domain, and the slave domain controllers are used to control the traction functional domain, the braking functional domain, the air conditioning functional domain, the door functional domain, and the lighting functional domain.

[0061] In the embodiments of this disclosure, a master-slave architecture based on a master domain controller and slave domain controllers enables collaborative management of functional modules. The master domain controller corresponds to the control logic domain and is responsible for global control policies, operating mode management, fault diagnosis and recovery, and data aggregation and analysis. The hardware requirements of the master domain controller may include a high-performance multi-core processor, redundancy design (e.g., dual-machine hot standby or a three-out-of-two voting mechanism), and support for multiple communication interfaces (e.g., Ethernet). The software requirements of the master domain controller may include a real-time operating system, integrated artificial intelligence algorithms for predictive maintenance, and support for over-the-air (OTA) upgrades.

[0062] For example, the traction domain in the slave domain controller can execute motor control algorithms (such as vector control and direct torque control); the braking domain can dynamically allocate electric braking and mechanical braking forces, responding to deceleration commands from the master domain; the air conditioning domain can adjust the power of the air valves and compressor based on temperature sensor data; the door domain can control door opening and closing, integrating safety interlock logic; and the lighting domain can adjust the cabin lighting according to ambient light and operating status. The hardware requirements for the slave domain controller may include embedded microcontrollers, dedicated sensor interfaces, and low-latency communication modules (such as Ethernet).

[0063] In one feasible embodiment, the master-slave architecture based on the master domain controller and slave domain controller may also include communication protocols and data interaction, functional collaborative design, redundancy and fault tolerance design, fault diagnosis and self-healing, and deployment and verification.

[0064] According to embodiments of this disclosure, through a master-slave architecture of a master domain controller and a slave domain controller, rail transit vehicles have achieved an upgrade from hardware stacking to software definition, taking into account real-time performance, reliability and intelligence, and further realizing a higher standard of fully automated operation.

[0065] According to embodiments of this disclosure, the standard board is further configured to update the control algorithm, hardware configuration, and communication protocol of the standard board based on the control signals of the train carriage, thereby obtaining an updated board.

[0066] In the embodiments of this disclosure, in order to improve the safety performance and operational efficiency of the train and optimize the hardware and communication protocols, the updated board can be obtained by updating the control algorithm, hardware configuration and communication protocol of the standard board.

[0067] For example, updating the control algorithm of a standard board can include: analyzing the shortcomings of the existing control algorithm based on the control signal requirements of the train carriages and designing a new control algorithm; compiling the updated control algorithm into a software package and deploying it to the standard board through remote or on-site updates, using a secure version update authorization mechanism to ensure the reliability of the update process; and building a whole vehicle logic circuit control system on the ground to conduct tests under extreme conditions such as simulated faults and control disturbances to ensure the safety and reliability of vehicle control, and collecting updated data for performance evaluation and optimization.

[0068] For example, hardware configuration for standard circuit boards can include hardware selection and integration, hardware installation and debugging, and performance testing. Suitable hardware modules, such as sub-boards, can be selected based on new control requirements. Sub-boards with different functions can be integrated into a standard chassis, eliminating manual wiring and improving system reliability and production efficiency. Installing new hardware modules and performing intelligent batch debugging ensures hardware and software compatibility and improves debugging efficiency. Furthermore, updated hardware configurations can be tested, including functional, performance, and reliability tests, allowing for optimization and adjustments based on test results to ensure the hardware configuration meets train operation requirements.

[0069] According to embodiments of this disclosure, the operating efficiency and safety of a train are improved by updating the control algorithm, hardware configuration, and communication protocol of a standard board based on the control signals from the train carriages.

[0070] Figure 3B A schematic diagram illustrating an extended topology between a master domain controller and a slave domain controller according to an embodiment of the present disclosure is provided.

[0071] like Figure 3B As shown, the distributed system architecture may include a master domain controller 101 and slave domain controllers 102. The master domain controller 101 includes a switch board 105a, and the slave domain controllers include switch boards 105b. There are multiple slave domain controllers 102, such as slave domain controller 102a, slave domain controller 102b, and slave domain controller 102c. The master domain controller 101 and the slave domain controllers 102 can connect and exchange data through the switch boards. Each slave domain controller 102 includes multiple types of boards, such as a master control board 1021, an I / O board 1022, and a converged board 1023. The master control board 1021 can be used for the control and management of the slave domain controllers 102, the I / O board 1022 can be used for input / output operations, and the converged board 1023 can be used for data fusion processing. This topology can improve the scalability and reliability of the system; by adding slave domain controllers, the system's processing capacity and number of interfaces can be expanded. It should be noted that the number of domain controllers, switching boards, main control boards, converged boards, and I / O boards shown in the diagram is for illustrative purposes only, and the specific number can be determined according to actual needs.

[0072] Figure 4 The schematic diagram shows the chassis dimensions of the master domain controller and the slave domain controller according to an embodiment of the present disclosure, wherein (4a) is a front view and (4b) is a top view.

[0073] like Figure 4 As shown in Figure (4a), the total length of the master domain controller and slave domain controller chassis is 482mm, and the height is 132mm. Figure 4As shown in Figure (4b), the net length of the chassis is 445mm and the width is 250mm. It should be noted that the specific dimensions of the chassis can be determined according to relevant standards and actual needs. The dimensions shown in the figure are only examples and are not limited here.

[0074] According to embodiments of this disclosure, the standard board is also configured to accommodate non-standard control signals through interface design and modular design to allow access to non-standard boards.

[0075] According to embodiments of this disclosure, non-standard control signals can characterize signals that do not meet standardization mechanisms. Considering the use of non-standard signals in complex automated equipment for control and monitoring, this disclosure processes non-standard control information signals through signal conversion, interface design, and modular design.

[0076] For example, non-standard signals can be converted into standard signals using signal conversion devices to ensure compatibility with existing systems; standardized interfaces can be designed to allow non-standard boards to be connected to the system via adapters or conversion modules; and modular design can be adopted to integrate hardware modules with different functions into the system, thereby improving the system's flexibility and scalability.

[0077] According to embodiments of this disclosure, the standard board allows for flexible configuration and access to third-party boards (non-standard boards), enabling the integration of control functions and standard hardware board configuration. For example, the board can be flexibly configured based on the vehicle's control signals, allowing third-party boards to access specific, limited non-standard signals. This reduces the development costs of special boards, and the flexible board configuration facilitates the implementation of hardware standardization, reduces the types of spare parts, and lowers operation, maintenance, and repair costs.

[0078] According to embodiments of this disclosure, the standard board is further configured to meet preset safety standards through a load protection mechanism; the load protection mechanism includes at least one of the following: the standard board employs an overcurrent protection device to perform a disconnection operation when the current exceeds a preset threshold; overload protection and disconnection operations are performed between the sub-channels and the main channel within the standard board through a multi-channel analog-to-digital converter and a baseboard management chip; and overload protection is performed between the standard board and the sub-boards using a power management chip.

[0079] In embodiments of this disclosure, the load protection mechanism of the standard board may include overcurrent and overload protection from the standard board to the load, overload protection and cutoff actions between the sub-channels and the main channel within the standard board, and overload protection and cutoff actions between the sub-board and the backplane. A power management chip is used for power distribution and protection between the standard board and the sub-boards.

[0080] For example, in terms of overcurrent protection, the following can be included: a protection current value can be set by a setting module, such as 6A, 10A, 12A, etc.; a current detection module monitors the current in the circuit in real time and transmits the data to the control module; the control module compares the monitored current value with the set protection current value; when the current exceeds the set threshold and the duration reaches the set time threshold, the control module cuts off the circuit by controlling the switching module.

[0081] It should be noted that, considering the different overload protection requirements of various load types in trains, this disclosure can also flexibly set the overcurrent protection current value according to different load types and application scenarios. By using high-precision detection elements such as current transformers, the accuracy of current monitoring can be ensured.

[0082] For example, overload protection and cut-off operations between sub-channels and main channels can be implemented using a multi-channel analog-to-digital converter and a substrate management chip. This can include: real-time acquisition of current and voltage signals from the main channel and sub-channels via multiple channels, and conversion of these signals into digital signals; the substrate management chip reading the digital signals converted by the multi-channel analog-to-digital converter and determining whether an overload has occurred based on a preset threshold; and the substrate management chip activating a protection mechanism when the current or voltage exceeds the preset threshold. The substrate management chip can also cut off the power supply to the overloaded channel by controlling a relay or other cutting-off device.

[0083] For example, the power management chip can monitor the power current of the sub-board in real time through the built-in current sensor. When the current exceeds the preset threshold, the chip can trigger the protection mechanism. The power management chip can also send a signal to control the relay to cut off the power supply to the sub-board. When the overload is relieved, the power management chip can automatically restore the power supply.

[0084] According to embodiments of this disclosure, through various load protection mechanisms of standard boards, the power management chip can monitor the current in real time. When the current exceeds a preset threshold, it automatically cuts off the power supply to prevent equipment damage caused by overload. By controlling the opening and closing of loads, it optimizes power distribution and reduces energy consumption.

[0085] According to embodiments of this disclosure, the primary domain controller is further configured to process the same input signal in parallel through at least two independent channels, generate respective output results, and compare multiple output results. If multiple output results are the same, the output result is taken as the final output to meet the redundancy configuration requirements. The secondary domain controller is further configured to meet the security level requirements through hardware isolation strategy, software space independence strategy, and software time independence strategy.

[0086] In the embodiments of this disclosure, based on an open control architecture of master and slave domain controllers, the master domain controller can meet security integrity level requirements through dual redundancy design. The slave domain controllers can achieve flexible combinations of SIL2 to SIL0 certifications under different security level requirements by combining different hardware and software strategies.

[0087] For example, the primary domain controller can contain two completely independent hardware systems, each with its own power supply, processor, input / output modules, etc. For the primary domain controller's software system, the two processing units within each subsystem can run the same software logic but execute tasks independently. A comparison mechanism ensures the consistency of output results to achieve software redundancy. The system can monitor the status of each processing unit in real time, and when a unit failure is detected, it can automatically switch to the backup unit to ensure continuous system operation.

[0088] For example, hardware isolation strategies for domain controllers can include independent power supplies, physical isolation, and interface isolation. For instance, independent power supplies can be provided for modules with different security levels to prevent power failures or interference from affecting other modules; hardware components with different security levels can be physically separated to reduce electromagnetic interference and common-cause failures; and isolated interfaces (such as optocouplers or isolation converters) can be used to connect modules with different security levels to ensure the independence of signal transmission.

[0089] For example, a software space independence strategy from a domain controller can employ hardware-supported memory protection units to prevent unauthorized access or tampering of the memory space of high-security software by low-security software; or it can use an operating system that supports memory protection to further enhance the independence of the memory space through software mechanisms; ensuring that data from low-security software does not flow to high-security software and avoiding data corruption.

[0090] For example, a software time independence policy from a domain controller could include: the operating system allocating deterministic time slices to software tasks with different security levels, ensuring that each task receives processing resources within its predetermined time. Higher priority is assigned to tasks with higher security levels, ensuring that these tasks are executed first during resource contention. Alternatively, by monitoring the execution time of software tasks, the system can terminate a task if it exceeds its predetermined execution time to prevent it from posing a potential risk to system security.

[0091] In the embodiments disclosed herein, except for SIL4 level which requires the main domain controller architecture to meet the 2×2oo2 requirement, SIL2 to SIL0 certifications can be configured through flexible combinations without changing the chassis architecture. This increases the signal density per unit volume, better meets vehicle control requirements, and saves space and weight occupied by the vehicle control system.

[0092] According to embodiments of this disclosure, through flexible configuration, the master domain controller and slave domain controller can be flexibly configured according to different security level requirements by combining different hardware and software strategies, thereby optimizing system cost and complexity while meeting security requirements.

[0093] According to embodiments of this disclosure, the standard board meets preset specifications and interface standards by: determining the interface standards, communication design, power supply design, board size, and connector type of the standard board.

[0094] In the embodiments of this disclosure, considering other intranet forms in conventional technologies, such as controller area networks (CANs), the number of nodes is generally required to be no more than 40, and the longer the communication distance, the slower the communication speed. If the length of the communication cable in the carriage exceeds 50 meters, the communication speed will be less than 1 Mbps. Ethernet has a faster communication speed and is not limited by the number of nodes or distance. The communication design of the standard board in this disclosure can use 100 Mbps Ethernet, and its communication speed is not affected (the typical carriage application wiring length does not exceed 100 meters).

[0095] For example, in the power supply design of standard boards, considering the impact of power board failure, the main domain controller can use two independent power boards (Power Board A / B) for redundant power supply. Each power board has one power connector, and the physical interface form and interface definition of the power connectors on both power boards are the same. For example, other interface designs may include definitions for 5V, 24V power supply, power failure signals, slot signals, Ethernet, address encoding, etc.

[0096] According to embodiments of this disclosure, by clearly defining the interface, signal, and power design requirements of the backplane, and standardizing the board size and connector model, the needs of high-performance computing and embedded systems can be met.

[0097] According to embodiments of this disclosure, the master domain controller and the slave domain controller are further configured to employ multiple independent power boards, each power board including a power connector, wherein the physical interface and interface definition of the power connectors of the multiple power boards are identical.

[0098] In the embodiments of this disclosure, the master domain controller and slave domain controllers are each configured with independent power boards. These power boards can operate independently without interfering with each other. Redundant power is provided through multiple power boards to ensure that the system can still operate normally even if one power board fails. Regarding power connectors, the power connectors on the power boards can adopt a standardized design to ensure consistency of physical interfaces. The interface definitions of the power connectors can follow relevant standards to ensure consistency in electrical characteristics and signal definitions between different power boards. Through standardized interface definitions, the power boards can perform unified power management with other components in the system.

[0099] In one feasible embodiment, based on the combination of the train functional domain and the physical space domain, the domain controller corresponding to the driving domain can be a separate independent architecture controller, which can adopt a 2×2oo2 (Two out of Two) architecture with SIL4 certification (some signals can also be SIL2 level); the under-vehicle domain, as an important signal control area for train traction and braking, can also adopt a safety certification architecture, with the main domain controller completing the vehicle operation command control, while collecting sensor information through the distributed slave domain controllers to facilitate the main domain controller to make decision commands.

[0100] In one feasible embodiment, graphical programming software that meets relevant standards (such as IEC 61131 standard) can be used. The underlying software configuration of the daughterboard can be configured by address recognition and pre-writing. When the daughterboard is inserted into the corresponding card slot, the card type can be determined by the backplane identification number, thereby reading the relevant card configuration. There is no need to perform separate program flashing, which saves the flexibility of debugging and use.

[0101] Figure 5 A schematic diagram of the system architecture of a master domain controller and a slave domain controller according to an embodiment of the present disclosure is shown.

[0102] like Figure 5 As shown, the system architecture of the master domain controller and slave domain controllers can adopt an architecture including the underlying driver 501, the operating system 502, the platform software 503, and the logic function program 104. The platform software 503 can support modular encapsulation and user secondary development, and uses programming software that conforms to relevant standards to meet the requirements of intuitiveness and operability.

[0103] The underlying driver 501 can include various hardware controllers, such as Flash controllers, serial port controllers, I2C controllers (Inter-Integrated Circuit Controllers), CAN controllers (Controller Area Network Controllers), SPI controllers (Serial Peripheral Interface Controllers), I / O controllers (Input / Output Controllers), and Ethernet controllers. These controllers are responsible for interacting directly with the hardware and providing basic hardware operation functions.

[0104] Operating system 502 can use real-time operating system 5021 and board support package 5022. Real-time operating system 5021 may include kernel libraries, file system, I / O system, and user libraries. Board support package 5022 may include various drivers, such as Flash driver, serial port driver, I2C driver, CAN driver, SPI driver, I / O driver, and Ethernet driver, which provide the operating system with interfaces for interacting with hardware.

[0105] Platform software 503 can include functional modules such as application configuration, program update, configuration file management, fault diagnosis, redundancy management, power failure protection, chassis management, PTU interaction (maintenance system software functions), and programming software. These modules can provide system-level software functions to support the operation and management of applications.

[0106] The logic function program 504 may include functions such as digital input acquisition (DI acquisition), digital output (DO output), fault reporting, data recording, and train operation data communication. These programs can implement the specific business logic and functions of the system.

[0107] According to embodiments of this disclosure, by adopting a safe computer architecture suitable for rail transit vehicle applications, flexible hardware and software configuration and design are implemented. By replacing some relays with contactless control technology, the hard-wired logic circuits of the vehicle are software-based, simplifying the control logic and enabling flexible design of circuit control logic. Based on the control requirements and functional requirements of each subsystem of the vehicle, independent controllers are replaced with safe computer function boards, and control data is integrated. This can improve the intelligence and digitalization level of rail transit vehicle controllers and further improve the operating efficiency of trains.

[0108] Based on the aforementioned vehicle domain control system, this disclosure also provides a vehicle domain control method. The following will be combined with... Figure 6 The method is described in detail.

[0109] Figure 6A flowchart illustrating a vehicle domain control method according to an embodiment of the present disclosure is shown schematically.

[0110] like Figure 6 As shown, the vehicle domain control method of this embodiment may include operations S610 to S620.

[0111] When operating the S610, the main domain controller generates control commands based on the control logic of the train carriages and the equipment status information of the train carriages.

[0112] When operating the S620, it receives control commands sent by the primary domain controller from the domain controller and executes control actions according to the control commands.

[0113] Preferably, the master domain controller and the slave domain controller each include a standard board, the standard board conforms to preset specifications and interface standards, the configuration information of the master domain controller is determined based on the control requirement information of the train carriage space domain or the control requirement information of the functional domain, the slave domain controller includes multiple slave domain controllers, and the master domain controller and the multiple slave domain controllers are connected through communication links.

[0114] According to embodiments of this disclosure, this disclosure also provides a train, including: a carriage; and the aforementioned vehicle domain control system.

[0115] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0116] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0117] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A vehicle domain control system, comprising: The main domain controller is configured to generate control commands based on the control logic of the train carriages and the equipment status information of the train carriages. The slave domain controller is configured to receive control commands sent by the master domain controller and execute control actions according to the control commands. The master domain controller and the slave domain controller each include a standard board that conforms to preset specifications and interface standards. The configuration information of the master domain controller is determined based on the control requirements information of the train car space domain. There are multiple slave domain controllers, and the master domain controller and the multiple slave domain controllers are connected through a communication link. The space domain includes the driving domain, the car interior domain, the roof domain, and the undercarriage domain. The primary domain controller selects the domain controller corresponding to the largest control demand information from multiple control demand information by comparing the control demand information of the driving domain, the control demand information of the passenger compartment domain, the control demand information of the roof domain, and the control demand information of the under-vehicle domain. The primary domain controller meets the preset conditions for computing resources and communication bandwidth.

2. The control system according to claim 1, wherein the standard board is further configured to update the control algorithm, hardware configuration and communication protocol of the standard board according to the control signal of the train carriage, thereby obtaining an updated board.

3. The control system according to claim 1, wherein the standard board is further configured to accommodate non-standard control signals through interface design and modular design to allow access to non-standard boards.

4. The control system according to any one of claims 1 to 3, wherein the standard board is further configured to meet a preset safety standard through a load protection mechanism; The load protection mechanism includes at least one of the following: The standard board is equipped with an overcurrent protection device that performs a disconnection operation when the current exceeds a preset threshold. The sub-channels and main channels within the standard board are connected by a multi-channel analog-to-digital converter and a baseboard management chip to perform overload protection and disconnection operations. The standard board and the sub-board use a power management chip to perform overload protection.

5. The control system according to claim 1, wherein the master domain controller is further configured to process the same input signal in parallel through at least two independent channels, generate respective output results, compare multiple output results, and, in the case that multiple output results are the same, take the output result as the final output to meet the redundancy configuration requirements, and the slave domain controller is further configured to meet the security level requirements through hardware isolation strategy, software spatial independence strategy and software temporal independence strategy.

6. The control system according to claim 5, wherein the standard board meets preset specifications and interface standards, including: Determine the interface standard, communication design, power supply design, board size, and connector type of the standard board.

7. The control system according to claim 6, wherein the master domain controller and the slave domain controller are further configured to employ multiple independent power boards, each power board including a power connector, wherein the physical interface and interface definition of the power connector of each of the multiple power boards are identical.

8. A vehicle domain control method, applied to a vehicle domain control system, the control method comprising: The main domain controller generates control commands based on the control logic of the train carriages and the equipment status information of the train carriages; Receive control commands sent by the primary domain controller from the domain controller, and execute control actions according to the control commands; The master domain controller and the slave domain controller each include a standard board, which conforms to preset specifications and interface standards. The configuration information of the master domain controller is determined based on the control requirements information of the train carriage space domain. There are multiple slave domain controllers, and the master domain controller and the multiple slave domain controllers are connected through a communication link. The method further includes: the spatial domain includes a driving domain, a passenger compartment domain, a roof domain, and an under-vehicle domain; the main domain controller selects the domain controller corresponding to the largest control demand information from multiple control demand information by comparing the control demand information of the driving domain, the passenger compartment domain, the roof domain, and the under-vehicle domain, and the main domain controller meets the preset conditions for computing resources and communication bandwidth.

9. A train, comprising: car; The vehicle domain control system as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • ARM9 core based microprocessor train control unit

    CN101055469A

  • Rail transit train control system

    CN110920696A