Asymmetric input / output redundancy architecture implementation method, equipment and medium
By employing an asymmetric input/output redundancy architecture, the number of VIOM devices is reduced, the cost of the rail transit signaling system is lowered, and safety and availability are ensured, achieving redundancy in master/slave state switching and normal system operation.
Patent Information
- Application Number
- CN202510986987.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-17
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-07-17
AI Technical Summary
In existing rail transit signaling systems, the use of a large number of redundant devices to ensure safety leads to increased costs. How to reduce the number of VIOM devices while ensuring safety and availability has become an urgent problem to be solved.
An asymmetric input/output redundancy architecture is adopted, including a primary and a backup system. One system contains a high-power safety output board. Through acquisition, processing, verification word check and dual-channel comparison, the primary system outputs the results to the safety and non-safety output boards. The output is connected in parallel at both ends to ensure the safety and availability of the EB and reduce the number of high-power safety output boards.
While ensuring system security and availability, the number of hardware devices has been reduced, system costs have been lowered, and redundancy is provided by ensuring that the system can still operate normally after a series of failures through master-slave state switching.
Smart Images

Figure CN120902789A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a rail transit signal system, in particular to an asymmetric input and output redundant architecture implementation method, device and medium. BACKGROUND
[0002] In the rail transit signal control system, the input and output subsystem is the basis for the implementation of all business function modules, generally implemented by the acquisition board, control board and output board to realize the safe connection with the vehicle and the interaction with other subsystems. Among them, the input and output subsystem is referred to as VIOM, which is the safety input and output subsystem of the ATC (Automatic Train Control) system. It collects the status of the train head activation, the driver's selected driving mode, the train door status, whether the emergency brake is applied, etc. through the safety acquisition board, and outputs the calculation results of the CPM to the vehicle. The output is divided into two parts. One part is the ATP (Automatic Train Protection) safety-related digital output part, mainly including EB (Emergency Brake) output, door opening enable, train zero speed status, and the other part is the ATO (Automatic Train Operation) non-safety-related part output, mainly including train traction enable, brake enable, door opening and closing command and train traction brake force size, etc. Among them, traction enable, brake enable and door opening and closing command belong to digital output, and traction brake force size belongs to analog output. For safety considerations, VIOM is generally composed of two systems. The outputs of the two systems are subjected to 2-to-2 redundant operation and then used as the final output to drive the vehicle. Each VIOM subsystem includes acquisition, control, safety output, non-safety output and other devices. There are two VIOMs at each end of the vehicle, and each vehicle has four VIOMs. The number of VIOM devices on each vehicle is large, and the cost of the vehicle increases significantly. Therefore, how to reduce the number of VIOM devices while ensuring safety and availability has a great influence on reducing the cost of the vehicle.
[0003] After searching, the Chinese patent publication No. CN110361979A discloses a safety computer platform in the field of railway signals, specifically discloses that the safety computer platform is composed of a main control layer and an execution layer; the main control layer is composed of a main control module and has a main backup system; the execution layer is composed of a certain number of expandable execution modules, each module is divided into a safety-related module and a non-safety-related module; the safety computer platform adopts a module-level redundant bus architecture; and the main control layer and the execution layer communicate through a double-redundant bus. In order to further improve safety, the existing patent uses a large number of redundant devices, resulting in an increase in cost.
[0004] Therefore, there is less research on how to reduce the number of devices while ensuring safety in the prior art, and how to reduce the number of VIOM devices while ensuring safety and availability has become a technical problem to be solved. SUMMARY
[0005] The purpose of this invention is to overcome the defects of the prior art by providing a method, device and medium for implementing an asymmetric input-output redundancy architecture.
[0006] The objective of this invention can be achieved through the following technical solutions:
[0007] According to a first aspect of the present invention, a method for implementing an asymmetric input / output redundancy architecture is provided. The asymmetric input / output redundancy architecture includes two systems: a primary system and a backup system. Each system includes at least a control board, a data acquisition board, a non-safety output board, and a low-power safety output board. One of the two systems includes a high-power safety output board. The implementation method includes the following steps:
[0008] Step S1: Collect the vehicle's code position status using the acquisition board;
[0009] Step S2: The control panel processes the safety and non-safety messages sent by the automatic control ATP and automatic operation ATO.
[0010] Step S3: The security message is verified by the control board, and a dual-channel security comparison is performed.
[0011] In step S4, the control board sends the calculated results to the automatic control ATP and the automatic operation ATO.
[0012] Step S5: The primary system sends the primary / standby status message to the peer system;
[0013] In step S6, the control board outputs the calculated value to the safety output board and the non-safety output board, and drives the vehicle load.
[0014] As a preferred technical solution, the code position status in step S1 includes external secure input data and external non-secure input data.
[0015] As a preferred technical solution, the external safety input data includes the cab activation status, mode selection status, door status, parking brake status, train integrity, and driver controller bypass data. The external non-safety input data includes the door control mode, departure button status, BM button status, driver controller zero position, EB relay status, driver-selected driving mode, and door command acquisition data.
[0016] As a preferred technical solution, the control board in step S2 communicates with the Automatic Control Program (ATP) through a secure communication protocol, transcodes the received data, and performs security verification and timeliness checks on the messages.
[0017] As a preferred technical solution, the control board in step S2 communicates with the automatically running ATO via a non-secure communication protocol and checks the integrity and timeliness of the messages.
[0018] As a preferred technical solution, step S3 specifically includes:
[0019] Each cycle, a check word is performed on the memory for secure input, secure output, secure communication parameters, Boolean expression operations, application data storage, and dual-channel data interaction.
[0020] Simultaneously, dual-channel processing is used for data processing. Data from both channels is compared, and only data that matches the comparison is used.
[0021] As a preferred technical solution, in step S4, the control board communicates with the automatic control ATP through a secure communication protocol and sends the calculation results to the ATP through secure data packets. The control board also communicates with the automatic operation ATO through a non-secure communication protocol and sends non-secure data to the ATO.
[0022] As a preferred technical solution, step S5 specifically includes:
[0023] The primary system sends primary / standby status messages to the peer system via an insecure communication protocol, and updates its own primary / standby status based on the peer system's primary / standby status messages; if communication is interrupted, the primary system is set to primary and the peer system is set to a crashed state.
[0024] As a preferred technical solution, step S6 specifically includes:
[0025] The control board outputs a request EB via a high-power safety output board.
[0026] The control board outputs a safety parking brake request, door permission, door closing, zero speed information, and forward traction enable safety amount through a low-power safety output board.
[0027] The control board outputs non-safe digital quantities such as door opening command, locomotive activation, traction, braking, ATO mode availability, ATB mode availability, traction and braking command, and mode indicator light through the non-safe output board FDB, and outputs non-safe analog quantities such as actual train speed and speed command through the non-safe output board FAB.
[0028] As a preferred technical solution, the control board checks the status of the output board and the consistency of data retrieval every cycle, every two weeks, or every three cycles; for EB requests, the vehicle will only EB if both ends request EB through the parallel output of the vehicle lines at both ends and through the Boolean logic configuration of the data.
[0029] According to a second aspect of the present application, there is provided an electronic device comprising a memory having a computer program stored thereon and a processor which, when executing the program, implements the method.
[0030] According to a third aspect of the present application, there is provided a computer-readable storage medium having a computer program stored thereon, the program, when executed by a processor, implementing the method.
[0031] Compared with the prior art, the present application has the following advantages:
[0032] 1) The present application can reduce the number of hardware devices while ensuring safety and usability, thereby reducing system cost;
[0033] 2) The present application reduces a series of high-power safety output boards, and can reduce the hardware cost of the system on the basis of ensuring system usability through a two-end parallel output architecture;
[0034] 3) The safety communication mode, calculation transcoding and check word checking designed in the present application can ensure the timeliness of the interactive messages with the train control and operation software, and the messages communicated and the messages stored in the memory cannot be tampered with;
[0035] 4) The master-slave state switching function designed in the present application ensures that the system can run normally after switching to another series when one series is down, and has redundancy. BRIEF DESCRIPTION OF DRAWINGS
[0036] Figure 1 is a flowchart of the method of the present application;
[0037] Figure 2 is a schematic diagram of the asymmetric input-output redundancy architecture of the present application. DETAILED DESCRIPTION
[0038] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work should fall within the scope of protection of the present application.
[0039] As shown in Figure 1 , an asymmetric input-output redundancy architecture implementation method, the asymmetric input-output redundancy architecture comprising two series of master and backup, wherein each series comprises at least a control board, a collection board, a non-safety output board and a low-power safety output board, one of the two series comprising a high-power safety output board, the implementation method comprising the following steps:
[0040] Step S1, collecting the code bit state of the vehicle through the acquisition board;
[0041] Step S2, processing the safety and non-safety messages sent by the automatic control ATP and the automatic operation ATO through the control board;
[0042] Step S3, checking the word verification of the safety message through the control board, and performing safety comparison in double channels;
[0043] Step S4, sending the calculated result to the automatic control ATP and the automatic operation ATO by the control board;
[0044] Step S5, sending the master and standby state message to the opposite system by the master system;
[0045] Step S6, outputting the calculated value to the safety output board and the non-safety output board by the control board, and driving the vehicle load.
[0046] In the application, the outputs of the two systems are connected in parallel, the high-power safety output of one system is output through the parallel output of the two ends, the final EB output is output by the OR logic of the calculation results of the two ends, and the safety of the EB output is ensured, and the redundancy of the two ends still exists, and the load can be driven by the output of the other end after one end is down.
[0047] The asymmetric input and output redundancy architecture described in the application is based on the original symmetric input and output architecture, the high-power safety output board of one system is reduced, the safety and availability of the EB output are ensured through the redundancy of the two ends of the vehicle, and the cost of the whole signal system can be reduced by reducing the number of hardware devices.
[0048] Reference Figure 1 The input and output data processing flowchart of the application is introduced, including the processes of data acquisition, data processing and data output.
[0049] Reference Figure 2 The device diagram of the asymmetric input and output redundancy architecture of the application is introduced, including the schematic diagrams of each board card.
[0050] In combination with the application, the data processing flow of Figure 1 is referred to, and the following steps are implemented:
[0051] Step S1: collecting the code bit state of the vehicle through the acquisition board, collecting the safety data such as the cab activation state, mode selection state, door state, parking brake state, train integrity and driver controller bypass through the first VDI acquisition board, and collecting the non-safety data such as the door control mode, start button state, BM button state, driver controller zero position, EB relay state, driver selected driving mode and door command acquisition through the second VDI acquisition board;
[0052] Step S2: process the safety and non-safety messages sent by the automatic control ATP and the automatic operation ATO through the control board, process the messages from the automatic control ATP and the automatic operation ATO through the VIOC software in the VIOC control board, the safety information interaction between the VIOC software and the ATP needs to pass through the coded and decoded safety communication protocol, prevent information disorder and tampering, the non-safety information interaction between the VIOC software and the ATO passes through the conventional UDP transmission, and at the same time, the application layer needs to check the message validity;
[0053] Step S3: check the word check of the safety message through the interface control software embedded in the control board, and perform safety comparison through double channels, check the word check of the message from the ATP software through the VIOC software, and check the word check of the memory of the safety input, the memory of the safety output, the memory of the safety communication parameter, the memory of the Boolean expression operation, the memory of the application data storage, and the memory of the double-channel data interaction every period, prevent the data in the memory from not being refreshed or being tampered with, and at the same time, the VIOC software adopts double-channel processing for data processing, the data of the double channels need to be compared, and only the consistent data can be used;
[0054] Step S4: send the calculated result to the automatic control ATP and the automatic operation ATO for data processing, calculate the collected data, the received external data, the configured Boolean expression data, etc. through the VIOC software, and send the calculated result to the automatic control ATP and the automatic operation ATO for data processing;
[0055] Step S5: send the main and standby state to the input and output subsystem, the VIOC software processes the state of the system and the opposite system every period, compares the health degrees of the two systems, sets the system with high health degree as the main system, and sets the system with low health degree as the standby system; if the communication between the two systems is interrupted or the opposite system is in a downtime state, set the state of the system as the main system, and the opposite system as the downtime state; through the main and standby state calculation every period, the redundancy between the two systems is ensured, and the abnormal state of the input and output system due to the downtime of a system is avoided;
[0056] Step S6: the interface control software outputs the calculated value to the safe and non-safe output board, and drives the vehicle load, the VIOC software outputs the request EB through the high-power safe output board PSB board, outputs the safe parking brake request, the door permission, the door closing, the zero speed information, the forward traction enablement and the like safe quantities through the low-power safe output board DSB board; outputs the door opening command, the head activation, the traction, the brake, the ATO mode available, the ATB mode available, the traction brake command, the mode indicator and the like non-safe digital quantity through the non-safe output board FDB board, outputs the actual speed of the train, the speed command and the like non-safe analog quantity through the non-safe output board FAB; at the same time, the VIOC software checks the state and data back sampling consistency of the output board card every cycle or every two weeks or every three cycles, checks the fault condition of the system and the hardware; for the EB request, the parallel output through the two ends of the vehicle line, and through the Boolean logic configuration of the data, the EB of the vehicle is caused only when the EB is requested by both ends, which can not only ensure the safety, but also take into account the availability, and can reduce a series of high-power safe output boards.
[0057] In this example, one of the asymmetric input and output redundant architectures is reduced by the parallel output before the two ends of a series of high-power safe output boards PSB boards, and two PSB board cards can be reduced for each train. According to the financial estimation of the product, more than 20,000 yuan can be saved for each train, and the cost of the signal system is greatly reduced for the project with a large number of vehicles.
[0058] The above is the introduction of the method embodiment, and the scheme of the present application is further described through the electronic device and storage medium embodiments.
[0059] The electronic device provided by the embodiment of the present application further includes a central processing unit (CPU), which can execute various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) or computer program instructions loaded from a storage unit into a random access memory (RAM). In the RAM, various programs and data required for device operation can also be stored. The CPU, the ROM and the RAM are connected to each other through a bus. An input / output (I / O) interface is also connected to the bus.
[0060] A plurality of components in the device are connected to the I / O interface, including: an input unit such as a keyboard, a mouse, etc.; an output unit such as various types of displays, a loudspeaker, etc.; a storage unit such as a magnetic disk, an optical disk, etc.; and a communication unit such as a network card, a modem, a wireless communication transceiver, etc. The communication unit allows the device to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0061] The processing units perform the various methods and processes described above, such as methods S1-S6. For example, in some embodiments, methods S1-S6 can be implemented as a computer software program tangibly embodied in a machine readable medium, such as a storage unit. In some embodiments, portions or all of the computer program can be loaded and / or installed onto the device via the ROM and / or the communication unit. When the computer program is loaded onto the RAM and executed by the CPU, one or more of the steps of methods S1-S6 described above can be performed. Alternatively, in other embodiments, the CPU can be configured to perform methods S1-S6 by any other suitable means, such as by way of firmware.
[0062] The functionality described above in this document can be performed, at least in part, by one or more hardware logic components. For example, and without limitation, illustrative types of hardware logic components that can be used include Field-programmable Gate Arrays (FPGAs), Application-specific Integrated Circuits (ASICs), Application-specific Standard Products (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), etc.
[0063] Program code for carrying out methods of the present application can be written in any combination of one or more programming languages. This program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, causes the machine to perform the functions / acts specified in the flowcharts and / or block diagrams. The program code can be executed entirely on a machine, partially on a machine, partially on a machine and partially on a remote machine or entirely on a remote machine or server.
[0064] In the context of the present application, a machine-readable medium can be a tangible medium that can contain or store program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable storage media can include, without limitation, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media can include one or more lines of a system, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0065] The above merely illustrates the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any skilled person in the art can easily think of various equivalent modifications or replacements within the technical range disclosed by the present application, and these modifications or replacements shall be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A method for implementing an asymmetric input / output redundancy architecture, comprising: The asymmetric input-output redundancy architecture comprises a primary system and a backup system, wherein each system comprises at least a control board, a collection board, a non-safety output board and a low-power safety output board, one of the two systems contains a high-power safety output board, and the implementation method comprises the following steps: In step S1, the code state of the vehicle is collected by the collection board; In step S2, the safety and non-safety messages sent by the automatic control ATP and the automatic operation ATO are processed by the control board; In step S3, the control board checks the word of the safety message and performs safety comparison in double channels; In step S4, the control board sends the calculated result to the automatic control ATP and the automatic operation ATO; In step S5, the primary system sends the primary-backup state message to the opposite system; In step S6, the control board outputs the calculated value to the safety output board and the non-safety output board, and drives the vehicle load.
2. The method of claim 1, wherein the asymmetric input / output redundancy architecture is implemented by: The code state in step S1 comprises external safety input data and external non-safety input data.
3. The method of claim 2, wherein the asymmetric input / output redundancy architecture is implemented by: The external safety input data comprises cab activation state, mode selection state, door state, parking brake state, train integrity and controller bypass data, and the external non-safety input data comprises door control mode, departure button state, BM button state, controller zero position, EB relay state, driver-selected driving mode and door command collection data.
4. The method of claim 1, wherein the asymmetric input / output redundancy architecture is implemented by: In step S2, the control board communicates with the automatic control ATP through a safety communication protocol, decodes the received data, and checks the safety of the message and the timeliness.
5. The method of claim 1, wherein the asymmetric input / output redundancy architecture is implemented by: In step S2, the control board communicates with the automatic operation ATO through a non-safety communication protocol, and checks the integrity and timeliness of the message.
6. The method of claim 1, wherein the asymmetric input / output redundancy architecture is implemented by: In step S3, the following steps are performed: The memory of the safety input, the memory of the safety output, the memory of the safety communication parameters, the memory of the Boolean expression operation, the memory of the application data storage and the memory of the double-channel data interaction are checked by word every cycle; Meanwhile, double-channel processing is adopted for data processing, and the data of the double channels are compared, and only the consistent data can be used.
7. The method of claim 1, wherein the asymmetric input / output redundancy architecture is implemented by: In step S4, the control board communicates with the automatic control ATP through a safety communication protocol, and sends the calculation result to the ATP through a safety data packet, and the control board communicates with the automatic operation ATO through a non-safety communication protocol, and sends the non-safety data to the ATO.
8. The method of claim 1, wherein the asymmetric input / output redundancy architecture is implemented by: In step S5, the following steps are performed: The primary system sends the primary-backup state message to the opposite system through a non-safety communication protocol, and updates the primary-backup state of the system according to the primary-backup state message of the opposite system; if the communication is interrupted, the system is set as the primary system, and the opposite system is set as the down state.
9. The method of claim 1, wherein the asymmetric input / output redundancy architecture is implemented by: In step S6, the following steps are performed: The control board outputs the request EB through the high-power safety output board; The control board outputs the safety parking brake request, the door permission, the door closing, the zero-speed information and the safety quantity of forward traction enable through the low-power safety output board; The control board outputs the door opening command, the head activation, the traction, the braking, the ATO mode availability, the ATB mode availability, the traction braking command, the non-safety digital quantity of the mode indicator light through the non-safety output board FDB, and outputs the non-safety analog quantity of the actual train speed and the speed command through the non-safety output board FAB.
10. The method of claim 9, wherein the asymmetric input / output redundancy architecture is implemented by: The control board checks the consistency of the state and data of the output board every cycle, every two weeks or every three cycles; for the EB request, the parallel output of the lines of the two end vehicles is realized, and the EB of the two ends is requested only through the Boolean logic configuration of the data.
11. An electronic device comprising a memory and a processor, said memory having stored thereon a computer program, characterized in that, The processor executes the program to implement the method in any one of claims 1-10.
12. A computer readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the method in any one of claims 1-10. The program is executed by the processor to implement the method in any one of claims 1-10.
Citation Information
Patent Citations
Security computer platform in the field of railway signals
CN110361979A
Railway safety critical systems with task redundancy and asymmetric communications capability
CN106414214A
Cell-level hot standby redundancy ATO system architecture
CN107187465A
Dual-system synchronous safety computer platform
CN110376876A
Method for processing train interface data of hot standby vehicle-mounted equipment
CN111003024A