Resource manager control system
Through the redundant architecture of multiple resource managers and advanced data synchronization technology, the problem of insufficient scalability and flexibility of existing resource manager control systems is solved, high availability and low cost railway operations are achieved, and train safety and system reliability are ensured.
Patent Information
- Application Number
- CN202510219473.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-07-04
Smart Images

Figure CN120246044A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of rail transit, and in particular to a resource manager control system. Background Art
[0002] In the field of rail transit, the interlocking controller system (Locking Control System, LCS), which can be called a resource manager, mainly includes control systems such as an interlocking program, a zone controller (ZC) program, and an objective controller (OC) program. In the railway signal system, ensuring the safe operation and efficient dispatching of trains is crucial. In the railway signal system, the reliability and scalability of the resource manager are key factors for ensuring the safe operation and efficient dispatching of trains. With the continuous expansion and complexity of the railway network, higher requirements are put forward for the resource manager control system, including higher system availability, flexible deployment methods, and lower operating costs. Therefore, a resource manager control system that can achieve high availability, flexible expansion, and seamless switching is needed to meet the needs of modern railway operations.
[0003] Currently, the resource manager control system in the railway signal system usually adopts a 1+1 hot standby redundancy scheme, that is, a set of primary equipment and a set of standby equipment. The primary equipment is responsible for signal control and train management functions, and the standby equipment takes over its functions when the primary equipment fails. Although this scheme can improve the reliability of the system to a certain extent, there are still some limitations in actual applications.
[0004] The resource manager control systems in the prior art usually only support the configuration of a set of primary equipment and a set of standby equipment, and it is difficult to expand flexibly. When new centralized stations or lines need to be added, additional physical equipment needs to be added and the system needs to be reconfigured, which not only increases the cost, but also makes it difficult to meet the needs of large-scale deployment, restricting the efficiency and flexibility of railway operations.
[0005] In view of this, there is an urgent need to provide a resource manager control system that supports multiple redundancy and scalability to ensure the safe operation of trains and meet the requirements of modern railway operations for high availability and low cost. Summary of the Invention
[0006] The present invention provides a resource manager control system to solve the defects of poor scalability, low resource utilization rate, and cumbersome switching in the resource manager control system in the prior art, and to achieve the purpose of improving flexibility and scalability and reducing operating costs.
[0007] The present invention provides a resource manager control system, which mainly includes: multiple sets of resource managers, including at least one set of primary devices and one set of standby devices. Multiple application program instances are deployed on the standby devices, and each application program instance corresponds to the signal control and train management functions of one set of the primary devices; Each set of the primary devices and the standby devices synchronize information through a first channel; Each set of the primary devices and the standby devices respectively perform data interaction with external devices through physically independent second channels; When it is determined that any one of the primary devices is a faulty primary device, the second channel of the faulty primary device is closed, and the application program instance corresponding to the faulty primary device in the standby device is activated to execute the signal control and train management functions of the faulty primary device.
[0008] According to the resource manager control system provided by the present invention, the first channel is a UDP / IP redundant channel, and the second channel is a full electronic IO channel.
[0009] According to the resource manager control system provided by the present invention, when any primary device and the standby device synchronize information through the first channel, byte stream compression and decompression technologies are used to transmit application layer security data.
[0010] According to the resource manager control system provided by the present invention, when any primary device and the standby device synchronize information through the first channel, after the any primary device sends a data packet to the standby device, it decides whether to re-send the data packet to the standby device according to whether it receives the reception confirmation information returned by the standby device.
[0011] According to the resource manager control system provided by the present invention, when any primary device and the standby device synchronize information through the first channel, a sequence number will be marked for each data packet, and the sequence number is used to identify the sending order of the data packet; If the standby device determines that the sequence numbers of the received data packets are not continuous, it requests the any primary device to re-send the lost data packets.
[0012] According to the resource manager control system provided by the present invention, when any primary device and the standby device synchronize information through the first channel, the standby device verifies the data packets sent by the any primary device based on the cyclic redundancy check algorithm.
[0013] According to a resource manager control system provided by the present invention, when any primary device and the standby device perform information synchronization through the first channel, the standby device calculates the transmission duration of the data packet according to the timestamp information carried by the data packet; if the transmission duration is greater than a preset duration threshold, it requests the any primary device to resend the data packet.
[0014] According to a resource manager control system provided by the present invention, the primary device and the standby device are deployed in different locations.
[0015] According to a resource manager control system provided by the present invention, synchronization of switching control information and inter-device information is performed between the primary device and the standby device; The switching control information includes device version information, device role information, and device status information; The inter-device information includes key variables of the primary device and logical operation status information of the primary device.
[0016] According to a resource manager control system provided by the present invention, it further includes a primary-standby switching management device, and the primary-standby switching management device performs the following operations: Receives a switching instruction input by the user and determines the target primary device to be switched according to the switching instruction; In response to the switching instruction, closes the second channel of the target primary device and activates the application program instance corresponding to the target primary device in the standby device.
[0017] For the resource manager control system provided by the present invention, only one set of physical devices is required for the standby device, and application program instances of multiple centralized stations can be expanded with the expansion quantity basically not limited. It can be flexibly deployed and managed, which is beneficial to the line segment opening construction and the time-sharing transformation of the reconstructed line. Without changing the physical device connection, it can be seamlessly compatible and reconstructed and upgraded. At the same time, virtualized applications allow a higher degree of concentration of application functions, which can save the number of centralized stations required for railway operation, thus saving the expenditure cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0019] Figure 1 It is one of the structural schematic diagrams of the resource manager control system provided by the present invention.
[0020] Figure 2It is the second structural schematic diagram of the resource manager control system provided by the present invention. Detailed implementation manners
[0021] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without making creative efforts shall fall within the protection scope of the present invention.
[0022] It should be noted that in the description of the present invention, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitations, an element defined by the phrase "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the element. The orientation or positional relationship indicated by the terms "upper", "lower", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus cannot be construed as a limitation to the present invention. Unless otherwise clearly defined and limited, the terms "mount", "connect", "couple" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection or an integral connection; it may be a mechanical connection, an electrical connection or a communication connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the internal connection of two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0023] The terms "first", "second", etc. in the present invention are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of the same category, and the number of objects is not limited. For example, the first object may be one or multiple.
[0024] For the control solution of the signal system ground equipment in the rail transit field, the existing technical solution is to deploy corresponding standby equipment for each set of primary equipment in a single set of safety control systems, and perform equipment status synchronization and switching between them. If any primary equipment in this set of safety control systems fails to output due to a fault (such as the primary equipment crashing), the standby equipment will be promoted to the primary equipment.
[0025] However, if there is a power outage, flood, fire, or overall hardware failure of the equipment room where the safety control system is located (such as hardware damage due to excessive temperature), the entire safety control system will fail to output due to the fault. There is also another situation. For example, if an external input condition causes a fault in the primary equipment within the safety control system, when the standby equipment is promoted to the primary equipment, the primary equipment and the standby equipment within the same safety control system have a common input due to a common mode reason, resulting in the standby equipment in the safety control system crashing for the same reason. This will lead to the situation that even if the switching between the primary and standby equipment is carried out within the safety control system, the safety control system will still crash and be unable to output externally.
[0026] Among them, the common mode reason may be caused by various factors. For example: the same power supply failure (such as the primary and standby equipment sharing the same power supply, when the power supply fails, the primary and standby equipment will fail simultaneously), the same environmental factors (such as excessive environmental temperature or abnormal humidity, causing the electronic components inside the primary and standby equipment to be damaged simultaneously), and the same installation error (such as using the same incorrect installation method or materials during the installation of the primary and standby equipment, resulting in them failing simultaneously under the same conditions), etc.
[0027] It can be seen from this that the existing control solutions for signal system ground equipment generally have the following disadvantages: 1) If the safety control system encounters a power outage, flood, fire, or overall hardware failure of the equipment room, it will cause the entire safety control system to fail and be unable to output externally.
[0028] 2) If an external input condition causes a fault in the primary equipment within the entire safety control system and switches to the standby equipment, the standby equipment will crash for the same common mode reason. For example, if the primary and standby equipment receive the same input, it will cause the standby equipment to crash for the same reason. This will lead to the situation that even if the redundant switching between the primary and standby equipment is carried out, the entire safety control system will still crash and be unable to output externally.
[0029] In summary, the existing control scheme for signal system ground equipment will cause a complete communication interruption between the train and the ground Zone Controller (ZC) in the above two cases, and will also cause a complete communication interruption between the trackside signal equipment and the ground equipment interlocking, resulting in train degradation, as well as the loss of interlocking control and signal status indication for signal lights and switch machines, leading to train operation delays and posing safety hazards to line operation.
[0030] The following will describe the resource manager control system provided by the present invention in conjunction with Figure 1 - Figure 2 The application number of the expandable LCS of the resource manager control system provided by the present invention can vary from 1 to N, and N is only limited by the interface capacity of the trackside radio electronic system, rather than the capacity of the safety computer carrying the LCS application program. Since virtualized applications allow a higher degree of application function concentration, it is possible to save the number of data centers required for future railway operations, thereby saving capital expenditure and operating expenditure.
[0031] As an alternative embodiment, the resource manager control system provided by the present invention mainly includes, but is not limited to: Multiple sets of resource managers, including at least one primary device and one standby device. The primary device can be denoted as the primary LCS, and the standby device can be denoted as the standby LCS. Multiple application program instances are deployed on the standby device, and each application program instance corresponds to the signal control and train management functions of one set of the primary devices; Each set of the primary device and the standby device performs information synchronization through the first channel; Each set of the primary device and the standby device respectively performs data interaction with external devices through physically independent second channels; When it is determined that any one of the primary devices is a faulty primary device, the second channel of the faulty primary device is closed, and the application program instance corresponding to the faulty primary device in the standby device is activated to execute the signal control and train management functions of the faulty primary device.
[0032] On the one hand, in the resource manager control system provided by the present invention, information interaction is carried out between each set of primary devices and standby devices through the first channel, which can timely synchronize the device status and logical operation status of the primary and standby devices.
[0033] On the other hand, in the resource manager control system provided by the present invention, each set of primary device and standby device respectively performs data interaction with external devices, such as Vehicle On-Board Controller (VOBC), Automatic Train Supervision (ATS), Electronic Equipment Unit (EEU), Local Electronic Unit (LEU), control display, and maintenance machine, through physically independent second channels.
[0034] On another hand, in the resource manager control system provided by the present invention, multiple primary devices communicate externally using valid identities, but only one set of physical devices is required for the standby device, which runs application program instances of all the centralized stations where the primary devices are located. That is, each application program instance corresponds to the signal control and train management functions of one set of primary devices. For example, when there are N sets of primary devices, N application program instances are deployed on the standby device, respectively corresponding to the functions of N sets of primary devices. The standby device uses a virtual identity and only receives external data through physically independent network ports without sending data externally.
[0035] In this way, in the case of a failure of the primary device at any centralized station, it is only necessary to close the external port of the primary device, run the corresponding application program example in the standby device, and read the data configuration of the primary device, then it can quickly replace the valid identity of the primary device to communicate externally and execute the corresponding signal control and train management functions to achieve seamless switching.
[0036] Figure 1 is one of the schematic structural diagrams of the resource manager control system provided by the present invention. As Figure 1 shown, for the convenience of description, first take the hot standby redundancy mode composed of one set of primary device and one set of standby device in the resource manager control system as an example to elaborate on the actual working principle of the resource manager control system in detail.
[0037] In this embodiment, two sets of resource managers LCS are redundant to each other. The two sets of LCS run the same software and adopt the same configuration. The two sets of LCS communicate periodically to manage the primary and standby states between each other. When it is determined that this set of LCS is the primary LCS, it will send interface information to external devices through the second channel. When this set of LCS is the standby LCS, it will not send interface information to external devices. When the standby LCS determines that the primary LCS device is unavailable, the standby LCS will automatically upgrade to the primary LCS to quickly switch to establish data interaction with external devices.
[0038] When the resource manager control system starts up normally, it first configures two sets of LCS devices as the primary LCS and the standby LCS respectively by reading the configuration file. After the resource manager control system runs normally, it operates in the initial working state according to the configuration file. Then, it performs fault detection based on the interface information sent by external devices and the interface information sent between the primary LCS and the standby LCS, and judges the operating status of each LCS device according to the fault detection situation to determine whether the unit switching condition is met. If the switching condition is met, a state transition is performed. Finally, the primary LCS controls the output interface information according to its own working state. Both the primary LCS and the standby LCS periodically receive the input information of external devices and perform state management and synchronization through the first channel. The standby device sends a heartbeat message to the primary LCS through the first channel to indicate that it is in a normal working state.
[0039] Furthermore, when a fault occurs in the primary LCS, the standby LCS detects the communication interruption of the primary LCS through the first channel and confirms the status of the primary device through the synchronization information received through the first channel. After the standby LCS confirms the fault of the primary LCS, the standby LCS closes the second channel of the faulty primary LCS and activates the application program instance corresponding to the faulty primary LCS. The standby LCS uses this application program instance to take over the signal control and train management functions of the faulty primary LCS and performs data interaction with external devices through the second channel. During the switching process, the standby LCS will use the previously synchronized key variables and logical operation status information to ensure that it can seamlessly continue to execute the functions of the faulty primary LCS using a virtual identity after taking over, avoiding affecting train operation and signal control.
[0040] The resource manager control system provided by the present invention only requires one set of physical devices for the standby device, can expand the application program instances of multiple centralized stations with the expansion quantity basically unrestricted, can be flexibly deployed and managed, is beneficial to the sectional opening construction of the line and the time-sharing transformation of the reconstructed line, does not need to change the physical device connection, is seamlessly compatible and can be reconstructed and upgraded. At the same time, virtualized applications allow a higher degree of concentration of application functions, can save the number of centralized stations required for railway operation, and thus save expenditure costs.
[0041] It should be noted that the redundant hot standby technical solution implemented by the primary LCS and the standby LCS in the resource manager control system provided by the present invention mainly involves the following key technologies: (1) Regarding the primary and standby state allocation and data interface. The working states of the primary LCS and the standby LCS are divided into three types: primary, standby, and initialization. The primary LCS and the standby LCS are connected through a redundant first channel for data.
[0042] As an alternative embodiment, the first channel is a redundant channel built based on the User Datagram Protocol / Internet Protocol (UDP / IP), simply referred to as the first channel; the second channel is a full electronic IO channel.
[0043] Optionally, switching control information and device - to - device information are synchronized between each primary LCS and standby LCS; the switching control information includes device version information, device role information, and device status information; the device - to - device information includes the key variables of the primary device and the logical operation status information of the primary device.
[0044] Specifically, there are mainly two types of information exchanged between the primary LCS and the standby LCS: switching control information and device - to - device information, and the two types of information are sent through a single data packet.
[0045] Among them, the device version information involved in the switching control information mainly includes the version information of this device, the device role information includes the current role of this device and the current role of the related device, and the device status information also includes the working status of this device and the working status of the related device. The device - to - device information mainly includes the key variables of the primary LCS and the logical operation status information of the primary LCS, etc.
[0046] (2) The primary LCS and the standby LCS use a dedicated UDP / IP channel for interaction, mainly to achieve the transfer of device - to - device information. In this process, the following technical means can be adopted to ensure the smooth progress of the hot standby redundancy switch: 2.1) Use serial numbers to ensure timing and timeliness, that is, configure a serial number for each data packet of the communication interaction.
[0047] 2.2) Use the Secure Cyclic Redundancy Check (CRC) algorithm to ensure data consistency and security, so as to ensure the correctness and security of data packets during the information interaction process.
[0048] 2.3) Adopt byte - stream compression and decompression technologies to transfer application - layer security data, reducing network data traffic and CPU load.
[0049] 2.4) Synchronize data once every preset period to ensure data consistency between the primary LCS and the standby LCS.
[0050] 2.5) Adopt synchronous confirmation technology on the premise that both the primary LCS and the standby LCS have life signals, that is, when the primary LCS synchronizes synchronous data to the standby LCS, the primary LCS can continue to operate and output externally only after the standby LCS sends a reception confirmation message, preventing inconsistent external control after the primary - standby switch.
[0051] (3) Regarding the safety switching mechanism: The all - electronic IO channel (i.e., the second channel) adopted by the present invention can be used to detect the health status of the primary LCS and the standby LCS respectively, so as to complete seamless switching.
[0052] 3.1) After the primary LCS and the standby primary are both powered on normally, the LCS configured as the primary device in the configuration file is upgraded to the primary primary, and the remaining set of LCS is converted to the standby primary.
[0053] 3.2) When the primary primary and the standby primary are working normally, the primary LCS sends the system status of this system to the all - electronic module, and the standby LCS sends heartbeat information. When the standby LCS receives that the logical part status of the all - electronic module is the primary, but the communication with the primary LCS is interrupted, the standby LCS initializes to prevent inconsistent logical data after the failure of standby synchronization.
[0054] 3.3) When the primary LCS and the standby LCS are working normally, when the standby LCS detects that the communication with the primary LCS is interrupted, and the standby LCS receives that the logical part status of the all - electronic module is non - primary, the standby LCS will take over the primary LCS, and the system switching time should meet the safety requirements.
[0055] Through the above - mentioned key technologies, the dual - redundant resource manager control system composed of a set of primary device and a set of standby device can meet the safety integrity level 4 (Safety Integrity Level 4, SIL4) fail - safe principle. In the case of unknown system status, initialization and fault status, its output is shielded, guiding the system to the safe side, and the scenario of "dual primaries" can be avoided.
[0056] Next, continue to explain the specific working principle of the hot - standby redundant resource manager control system composed of N sets of primary devices and a set of standby devices.
[0057] Figure 2 is the second schematic diagram of the structure of the resource manager control system provided by the present invention, as Figure 2 shown, external devices such as ATP\ATS\EEU (all - electronic IO) are connected through the external switch in the N + 1 redundant network, and the primary LCSs (LCS 1, LCS 2...LCS N, etc.) of each centralized station are connected through the internal switch in the N + 1 redundant network. The external switch and the internal switch together constitute the access points of the redundant network, ensuring that external devices and internal devices can communicate seamlessly with the primary LCS and the standby LCS. When the primary LCS fails, the standby LCS can quickly take over to maintain the normal operation of the system and ensure the continuity and reliability of data interaction.
[0058] When operating normally, the LCS 1, LCS 2... LCS N of each centralized station, etc., are the primary devices (assuming there are N centralized stations), communicate externally using valid identities, and there is only one set of physical devices as backup, running multiple LCS application program instances of centralized stations. The backup LCS uses a virtual identity and a physically independent network port to only receive external data and does not send data externally.
[0059] During the process of railway construction or renovation, the line is usually divided into multiple sections and gradually constructed and opened. For example, a subway line may be opened in part first, and then other parts are gradually opened later. The scalability of LCS N allows, without changing the connection of existing physical devices, to support new line sections through software configuration or upgrade. This means that during the construction or renovation process, there is no need to rewire or replace hardware devices, and only the software configuration or upgrade of LCS N is required. LCS N can seamlessly be compatible with the existing railway signal system, ensuring compatibility and interoperability between the old and new systems. This enables the already opened line sections to operate normally during the staged opening construction process, while the newly constructed line sections can be gradually connected to the system.
[0060] Suppose a subway line is under construction and planned to be opened in sections: First stage: The first half of the line is opened, and LCS N supports the signal control of the first half through software configuration.
[0061] Second stage: LCS N is software-upgraded at night to expand its function to support the signal control of the second half.
[0062] Final stage: After the entire line is opened, LCS N has, through staged software upgrades and configurations, supported the signal control of the entire line, and there is no need to change the connection of physical devices during the whole process.
[0063] This design greatly improves the flexibility and maintainability of the railway signal system, and reduces the costs and risks of construction and renovation.
[0064] Next, specifically analyze the resource manager control system adopted by the present invention. The reason for the expandable resource manager LCS N to be able to achieve staged opening construction of the line and time-sharing renovation of the renovated line, without changing the connection of physical devices, seamless compatibility, and the effect of renovation and upgrade will be analyzed.
[0065] First of all, the resource manager control system provided by the present invention adopts software-defined resource management technology, enabling LCS N to support new line sections or functions through software upgrade or configuration adjustment without changing the connection of physical devices.
[0066] In the railway signal system, many functions are implemented through software rather than relying on the physical connections of hardware. The LCS N (Scalable Resource Manager) provided by the present invention adopts a software-defined architecture, which means that its functions can be adjusted through software configuration and upgrade without the need to modify the physical hardware. At the same time, LCS N utilizes virtualization technology to abstract the signal control functions of multiple centralized stations into application program instances. These application program instances run on a general hardware platform, and resources and functions are allocated through software configuration. For example, as a standby LCS, a set of physical devices can run multiple virtual application program instances simultaneously, and each application program instance corresponds to the function of the primary LCS in a centralized station.
[0067] Secondly, the resource manager control system provided by the present invention adopts a flexible network architecture, enabling LCS N to quickly adapt to new line segments or functions through software configuration during the process of sectional opening and time-sharing transformation without the need for reconnection of physical devices.
[0068] In Figure 2 In the N+1 multi-hot standby redundant resource manager control system as shown, LCS N communicates with other primary LCSs through a dedicated first channel (such as a UDP / IP channel). This network design allows the adjustment of network topology and communication path through software configuration without changing the physical connection.
[0069] LCS N supports dynamic configuration functions and can adjust its communication and control logic through software instructions during operation. For example, when a new line segment is connected to the resource manager control system, new devices or functions can be added to the existing redundant network through software configuration without the need for rewiring or hardware replacement.
[0070] Thirdly, the resource manager control system provided by the present invention adopts a highly modular design scheme, enabling LCS N to flexibly support sectional opening of lines and time-sharing transformation, and adapt to new requirements by independently upgrading or expanding modules without changing the connection of physical devices.
[0071] LCS N adopts a modular design, encapsulating different signal control functions (such as signal control, switch machine control, etc.) into independent software modules. These modules can be combined and expanded through software configuration to meet the requirements of different line segments. Each module can run independently without affecting each other. This means that when a certain module is upgraded or expanded, it will not affect the normal operation of other modules. For example, when the function of a centralized station needs to be expanded, only the corresponding module needs to be upgraded without making large-scale changes to the entire resource manager control system.
[0072] In addition, the resource manager control system provided by the present invention adopts compatibility and interoperability designs, enabling the LCS N to seamlessly integrate with the existing railway signal system during the segmented commissioning and time-sharing transformation processes, ensuring the normal operation of the system.
[0073] The LCS N adopts standardized communication interfaces and protocols, enabling seamless compatibility with the existing railway signal system. This means that during the segmented commissioning and time-sharing transformation processes, new devices or functions can be seamlessly connected to the existing resource manager control system without the need for large-scale modifications.
[0074] The LCS N supports interoperability with other systems (such as ATP, ATS, EEU, etc.), ensuring that data interaction and functional collaboration between the old and new systems can proceed normally during the transformation process. For example, when the functions of a centralized station need to be expanded, the LCS N can communicate with the existing ATP system through a standardized interface to ensure the safety and reliability of train operation.
[0075] Most importantly, the resource manager control system provided by the present invention adopts a hot standby redundancy mechanism, enabling the LCS N to achieve seamless switching and dynamic adjustment through software configuration during the segmented commissioning and time-sharing transformation processes without changing the connection of physical devices.
[0076] In the N+1 multiple redundancy scheme, the LCS N supports the hot standby redundancy mechanism. When the primary LCS fails, the standby LCS can seamlessly take over its functions, ensuring the continuity and reliability of the resource manager control system.
[0077] During the segmented commissioning and time-sharing transformation processes, the application program instances on the standby LCS can dynamically adjust their functions and resource allocations through software configuration. For example, when the functions of a centralized station need to be expanded, the corresponding application program instances on the standby LCS can be pre-configured to ensure seamless takeover in case of a primary LCS failure.
[0078] Finally, the resource manager control system provided by the present invention is configured with the support of management software, enabling the LCS N to quickly adapt to new requirements through software configuration during the segmented commissioning and time-sharing transformation processes without the need for reconnection of physical devices.
[0079] The LCS N is equipped with dedicated management software for managing and adjusting the system configuration and primary / standby redundancy switching. Through the configuration management software, operators can perform system configuration and function expansion through a software interface without changing the connection of physical devices.
[0080] Optionally, the management software supports an automated configuration function that can automatically adjust the configuration of the resource manager control system according to preset rules and templates. For example, when a new line segment is connected to the system, the management software can automatically identify and configure the corresponding functional modules to ensure the normal operation of the system.
[0081] Next, a brief introduction will be given to Figure 2 the processing methods and steps of the N+1 multiple redundant resource manager control system shown in the communication management, voting management, hot standby switching, and application layer data synchronization phases.
[0082] Data interaction between each set of primary LCS and standby LCS can be achieved not only through a dedicated UDP / IP redundant channel but also through a full electronic I / O channel. When using a dedicated UDP / IP redundant channel for data interaction, some feasible means can be adopted to ensure the reliability and security of the data synchronization and switching process between the primary LCS and the standby LCS, which will be specifically described below.
[0083] As an alternative embodiment, the resource manager control system provided by the present invention realizes network switching during the switching between the primary LCS and the standby LCS through the management software.
[0084] The primary LCS and the standby LCS can quickly switch when a fault occurs. The management software is responsible for monitoring the status of the primary LCS and triggering the switch when a fault is detected. When the switch occurs, the management software will update the network configuration of the standby LCS to the network configuration of the primary LCS to ensure that the standby LCS can seamlessly take over the functions of the primary LCS, including updating network parameters such as IP addresses, port numbers, and routing information, so that the standby LCS can immediately communicate with external devices (such as ATP, ATS, EEU, etc.).
[0085] Suppose in a railway signal system, the primary LCS 1 is responsible for controlling the signal equipment of a certain section of the railway. If the primary LCS1 fails, the management software will detect this situation and update the network configuration of the standby LCS to the configuration of the primary LCS 1. For example, the IP address of the primary LCS1 is 192.168.1.10, and the IP address of the standby LCS is 192.168.1.20. After the switch, the IP address of the standby LCS will be updated to 192.168.1.10 to ensure that the communication with external devices is not affected.
[0086] As an alternative embodiment, when any primary device and the standby device synchronize information through the first channel, byte stream compression and decompression technologies are used to transmit application layer security data to reduce network data traffic and CPU load.
[0087] The data transmitted between the primary LCS and the standby LCS can be very large, especially when it comes to complex signal control logic and real-time data. To reduce network bandwidth occupancy and CPU load, the resource manager control system adopts byte stream compression technology, which can compress the data to a smaller size, thereby reducing transmission time and resource consumption. The decompression technology is used to restore the original data at the receiving end.
[0088] For example, in a railway signal system, the primary LCS needs to synchronize information such as the signal lamp status and the switch machine position to the standby LCS. This data may contain a large amount of status information and logical operation results. Through the byte stream compression technology of the present invention, this data can be compressed to a smaller size, such as from 1MB to 100KB, thereby reducing transmission time and CPU load. After receiving the compressed data, the standby LCS restores the original data through the decompression technology.
[0089] As an alternative embodiment, when any primary device and the standby device synchronize information through the first channel, after the any primary device sends a data packet to the standby device, it decides whether to re-send the data packet to the standby device according to whether it receives the reception confirmation information returned by the standby device.
[0090] The synchronization confirmation technology is used to ensure the reliability and consistency of the data synchronization process between the primary LCS and the standby LCS. When the primary LCS sends synchronization data to the standby LCS, the standby LCS must send a reception confirmation message indicating that the data packet has been successfully received and processed. If the standby LCS does not send a confirmation message, the primary LCS will re-send the data to ensure the reliability of data synchronization. This mechanism can prevent inconsistent external control information after the primary-standby switch, thereby avoiding potential security risks.
[0091] Suppose the primary LCS 1 is controlling the display status of the signal lamp and synchronizes this status information to the standby LCS. After the primary LCS 1 sends the synchronization data, the standby LCS will send a confirmation message. If the standby LCS does not send a confirmation message (for example, due to network failure or data loss), the primary LCS 1 will re-send the data to ensure that the standby LCS can correctly receive and process this information. Adopting this mechanism ensures that when the primary LCS 1 fails, the standby LCS can take over seamlessly and the external control information remains consistent.
[0092] As an alternative embodiment, when any primary device and the standby device synchronize information through the first channel, a sequence number will be marked for each data packet, and the sequence number is used to identify the sending order of the data packet; if the standby device determines that the sequence numbers of the received data packets are not continuous, it requests the any primary device to re-send the lost data packets.
[0093] Each time the primary LCS sends synchronization data, a sequence number is attached. The sequence number is used to identify the sending order of data packets, ensuring that the standby LCS can correctly identify the timing of the data. If the standby LCS detects that the sequence numbers are not consecutive (for example, a certain data packet is lost), it will request the primary LCS to resend the lost data packet.
[0094] In the railway signal system, the primary LCS 1 sends the signal machine status information to the standby LCS. Each data packet is attached with a sequence number, such as 1, 2, 3, 4, etc. If the standby LCS receives data packets with sequence numbers 1, 2, 4 but does not receive the data packet with sequence number 3, it will request the primary LCS 1 to resend the data packet with sequence number 3.
[0095] Adopting this mechanism ensures that the standby LCS can correctly receive and process all data, effectively preventing data loss and timing chaos, and ensuring the integrity and consistency of the data.
[0096] As an alternative embodiment, when any primary device and the standby device perform information synchronization through the first channel, the standby device checks the data packets sent by the any primary device based on the Cyclic Redundancy Check (CRC) algorithm.
[0097] The secure CRC algorithm generates a check code and appends it to the end of the data packet. The receiving end calculates the check code through the same algorithm and compares it with the received check code. If the check codes are consistent, it indicates that the data packet has not been tampered with or damaged during transmission; if the check codes are inconsistent, it indicates that there may be a problem with the data packet and it needs to be resent.
[0098] In the railway signal system, the primary LCS 1 sends the signal machine status information to the standby LCS, and attaches a secure CRC check code to each data packet. After receiving the data packet, the standby LCS calculates the check code through the same CRC algorithm and compares it with the received check code. If the check codes are consistent, the standby LCS confirms the integrity and security of the data; if the check codes are inconsistent, the standby LCS will request the primary LCS 1 to resend the data packet.
[0099] As an alternative embodiment, when any primary device and the standby device perform information synchronization through the first channel, the standby device calculates the transmission duration of the data packet according to the timestamp information carried by the data packet; if the transmission duration is greater than the preset duration threshold, it requests the any primary device to resend the data packet.
[0100] The timestamp mechanism is used to record the sending and receiving times of data packets. Each data packet is attached with a timestamp for calculating the transmission duration of the data packet in the network. Through the timestamp, the resource manager control system can detect network latency and anomalies. If the transmission duration of a data packet exceeds a preset duration threshold, corresponding measures can be taken, such as resending the data packet or triggering an alarm.
[0101] For example, the primary LCS 1 sends the signal machine status information to the standby LCS, and each data packet is attached with a timestamp to record the sending time of the data packet. After receiving the data packet, the standby LCS calculates the transmission duration of the data packet (the duration between the receiving time and the sending time). If the transmission duration exceeds a preset threshold (e.g., 100 milliseconds), the standby LCS will request the primary LCS 1 to resend the data packet to ensure the timeliness of the data.
[0102] As an alternative embodiment, for the resource manager control system provided by the present invention, the primary LCS and the standby LCS are deployed in different locations.
[0103] Specifically, for the resource manager control system provided by the present invention, when any set of devices fails, or when the communication data of the external input conditions of any set of devices fails, it can perform a seamless hot standby switchover to another set of devices with remote redundancy, maintaining the same logical operation state, and at the same time avoiding being affected by common mode failures, thereby improving the availability of the safety control system in the signal system.
[0104] Generally speaking, this multiple redundancy system can be placed in a central station of the resource manager control system, or can be separately deployed in the machine rooms of central stations at other geographical locations within the urban rail transit or the dispatching centers of the lines, forming a redundant backup function for the signal control system geographically between central stations and between central stations and dispatching centers.
[0105] Under extreme disaster weather conditions, before the vehicle-ground communication is completely interrupted, the dispatching center user can comprehensively judge by combining the health status of the primary device and the standby device of the signal safety control system, and proactively anticipate and manually switch the control right in advance. The healthy standby LCS with backup redundancy undertakes the external output function of the primary device, which can maintain the communication connection between the ground device Zone Controller (ZC) and the train, and maintain the control connection between the ground device interlocking and the trackside signal devices such as trackside signal machines and point machines, avoiding train degradation and preventing the trackside signal devices from losing interlocking control. This processing method minimizes the impact of failures of ground control devices such as ZC and interlocking on train operation, does not introduce safety risks, and ensures the safe operation of rail transit.
[0106] It should be noted that the handover of control rights between the primary LCS and the standby LCS in the resource manager control system provided by the present invention supports two types of fallback control methods: One is automatic fallback. When the primary LCS fails and the standby LCS detects the failure of the primary device, after the standby LCS determines that the life information of the primary LCS is interrupted, the standby LCS automatically switches to the primary LCS.
[0107] The other is manual fallback. It is manually judged by the user, and a control right handover instruction is issued to perform the fallback between the primary LCS and the standby LCS.
[0108] Specifically, the resource manager control system further includes a primary-standby handover management device, and the primary-standby handover management device performs the following operations: Receives a handover instruction input by the user and determines the target primary LCS to be handed over according to the handover instruction; In response to the handover instruction, closes the second channel of the target primary LCS and activates the application program instance corresponding to the target primary LCS in the standby LCS.
[0109] In summary, the resource manager control system based on the multiple redundancy scheme provided by the present invention has at least the following advantages: Improve system reliability and availability, and ensure operation safety; support flexible deployment and management; off-site disaster recovery to improve the system's anti-strike ability; the scalable resource manager is easy for line segment opening construction and time-sharing transformation of the line, without changing the physical device connection, and is seamlessly compatible and upgraded.
[0110] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.
[0111] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0112] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A resource manager control system, characterized in that, Including: Multiple sets of resource managers, including at least one set of primary devices and one set of standby devices. Multiple application instances are deployed on the standby devices, and each application instance corresponds to the signal control and train management functions of one set of the primary devices; Each set of the primary devices and the standby devices synchronize information through a first channel; Each set of the primary devices and the standby devices respectively perform data interaction with external devices through physically independent second channels; When it is determined that any one of the primary devices is a faulty primary device, the second channel of the faulty primary device is closed, and the application instance corresponding to the faulty primary device in the standby device is activated to execute the signal control and train management functions of the faulty primary device.
2. The resource manager control system according to claim 1, characterized in that, The first channel is a UDP / IP redundant channel, and the second channel is a full electronic IO channel.
3. The resource manager control system according to claim 1, characterized in that, When any primary device and the standby device synchronize information through the first channel, byte stream compression and decompression technologies are used to transmit application layer security data.
4. The resource manager control system according to claim 1, wherein When any primary device and the standby device synchronize information through the first channel, after the primary device sends a data packet to the standby device, it decides whether to re-send the data packet to the standby device according to whether it receives the reception confirmation information returned by the standby device.
5. The resource manager control system according to claim 1, wherein When any primary device and the standby device synchronize information through the first channel, a sequence number is marked for each data packet, and the sequence number is used to identify the sending order of the data packets; If the standby device determines that the sequence numbers of the received data packets are not continuous, it requests the primary device to re-send the lost data packets.
6. The resource manager control system according to claim 1, wherein When any primary device and the standby device synchronize information through the first channel, the standby device verifies the data packets sent by the primary device based on the cyclic redundancy check algorithm.
7. The resource manager control system according to any one of claims 4-6, characterized in that, When any primary device and the standby device synchronize information through the first channel, the standby device calculates the transmission duration of the data packets according to the timestamp information carried by the data packets; If the transmission duration is greater than a preset duration threshold, it requests the primary device to re-send the data packet.
8. The resource manager control system according to claim 1, characterized in that The primary devices and the standby devices are deployed in different locations.
9. The resource manager control system according to claim 1, characterized in that, Synchronization of switching control information and inter-device information is performed between the primary devices and the standby devices; The switching control information includes device version information, device role information, and device status information; The inter-device information includes key variables of the primary device and the logical operation status information of the primary device.
10. The resource manager control system according to claim 1, wherein It also includes a primary-standby switching management device, and the primary-standby switching management device performs the following operations: Receives a switching instruction input by the user and determines the target primary device to be switched according to the switching instruction; In response to the switching instruction, closes the second channel of the target primary device and activates the application instance corresponding to the target primary device in the standby device.