An asymmetric input-output redundancy architecture implementation method, device and medium

By adopting an asymmetric input/output redundancy architecture, the number of VIOM devices in the rail transit signaling system is reduced, the system cost is lowered, and safety and availability are guaranteed at the same time. It realizes the switching between primary and backup states and the redundancy design, ensuring the timeliness of communication and the normal operation of the system.

CN120902789BActive Publication Date: 2026-07-21CASCO SIGNAL LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CASCO SIGNAL LTD
Filing Date
2025-07-17
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

In existing rail transit signaling systems, the use of a large number of redundant devices to ensure safety leads to increased costs. How to reduce the number of VIOM devices while ensuring safety and availability has become an urgent problem to be solved.

Method used

An asymmetric input/output redundancy architecture is adopted, including two systems: primary and backup. Each system contains a control board, a data acquisition board, a non-safety output board, and a low-power safety output board. One system contains a high-power safety output board. Through the acquisition, processing, verification, and output process, the primary/backup status switching and parallel output are realized, reducing the number of high-power safety output boards.

Benefits of technology

While ensuring security and availability, the number of hardware devices was reduced, system costs were lowered, and redundant design ensured normal system operation and timely communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120902789B_ABST
    Figure CN120902789B_ABST
Patent Text Reader

Abstract

The application relates to an asymmetric input-output redundancy architecture implementation method, equipment and medium, the input-output redundancy architecture comprises two systems of a main system and a backup system, one system of the two systems contains a high-power safety output board, the implementation method comprises the following steps: S1, collecting the code state of a vehicle through a collection board; S2, processing the safety and non-safety messages sent by automatic control ATP and automatic operation ATO through a control board; S3, checking the words of the safety messages through the control board and performing safety comparison in double channels; S4, sending the calculated result to the automatic control ATP and the automatic operation ATO by the control board; S5, sending the main backup state message to the opposite system by the main system; and S6, outputting the calculated value to the safety output board and the non-safety output board by the control board. Compared with the prior art, the application has the advantages of reducing the number of hardware devices, reducing the system cost and the like while ensuring safety and availability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to rail transit signaling systems, and more particularly to a method, device, and medium for implementing an asymmetric input-output redundancy architecture. Background Technology

[0002] In rail transit signal control systems, the input / output subsystem is the foundation for all functional modules. It typically consists of acquisition boards, control boards, and output boards that enable secure connections to the vehicle and interaction with other subsystems. The input / output subsystem, hereinafter referred to as VIOM, is the safety input / output subsystem of the ATC (Automatic Train Control) system. It acquires information such as the train's head activation status, the driver's selected driving mode, the train's door status, and whether emergency braking is applied through the safety acquisition board. Simultaneously, it outputs the CPM calculation results to the vehicle. The output is divided into two parts: one is the ATP (Automatic Train Protection) safety-related digital output, mainly including EB (Emergency Braking) output, door opening enable, and train zero-speed status; the other is the ATO (Automatic Train Operation) non-safety-related output, mainly including train traction enable, braking enable, door opening / closing commands, and train traction braking force magnitude. Traction enable, braking enable, and door opening / closing commands are digital outputs, while the traction braking force magnitude is an analog output. For safety reasons, a VIOM (Visibility Module) typically consists of two systems. The outputs of these two systems undergo a 2-out-of-2 redundancy operation before being used as the final output to drive the vehicle. Each VIOM subsystem includes multiple devices such as data acquisition, control, safety outputs, and non-safety outputs. With two VIOM systems at each end of the vehicle, each vehicle has four VIOM systems. The large number of VIOM devices on each vehicle significantly increases vehicle costs. Therefore, reducing the number of VIOM devices while ensuring safety and availability has a significant impact on reducing vehicle costs.

[0003] A search revealed that Chinese Patent Publication No. CN110361979A discloses a safety computer platform in the field of railway signaling. Specifically, it discloses a platform consisting of a main control layer and an execution layer. The main control layer comprises main control modules, with a primary and backup system. The execution layer consists of a certain number of expandable execution modules, each further divided into safety-related and non-safety-related modules. The safety computer platform employs a module-level redundancy bus architecture. The main control layer and the execution layer communicate using dual redundant buses. This existing patent, in order to further improve security, uses a large number of redundant devices, resulting in increased costs.

[0004] Therefore, there is relatively little research on how to reduce the number of devices while ensuring security in existing technologies. How to reduce the number of VIOM devices while ensuring security and availability has become a technical problem that needs to be solved. Summary of the Invention

[0005] The purpose of this invention is to overcome the defects of the prior art by providing a method, device and medium for implementing an asymmetric input-output redundancy architecture.

[0006] The objective of this invention can be achieved through the following technical solutions:

[0007] According to a first aspect of the present invention, a method for implementing an asymmetric input / output redundancy architecture is provided. The asymmetric input / output redundancy architecture includes two systems: a primary system and a backup system. Each system includes at least a control board, a data acquisition board, a non-safety output board, and a low-power safety output board. One of the two systems includes a high-power safety output board. The implementation method includes the following steps:

[0008] Step S1: Collect the vehicle's code position status using the acquisition board;

[0009] Step S2: The control panel processes the safety and non-safety messages sent by the automatic control ATP and automatic operation ATO.

[0010] Step S3: The security message is verified by the control board, and a dual-channel security comparison is performed.

[0011] In step S4, the control board sends the calculated results to the automatic control ATP and the automatic operation ATO.

[0012] Step S5: The primary system sends the primary / standby status message to the peer system;

[0013] In step S6, the control board outputs the calculated value to the safety output board and the non-safety output board, and drives the vehicle load.

[0014] As a preferred technical solution, the code position status in step S1 includes external secure input data and external non-secure input data.

[0015] As a preferred technical solution, the external safety input data includes the cab activation status, mode selection status, door status, parking brake status, train integrity, and driver controller bypass data. The external non-safety input data includes the door control mode, departure button status, BM button status, driver controller zero position, EB relay status, driver-selected driving mode, and door command acquisition data.

[0016] As a preferred technical solution, the control board in step S2 communicates with the Automatic Control Program (ATP) through a secure communication protocol, transcodes the received data, and performs security verification and timeliness checks on the messages.

[0017] As a preferred technical solution, the control board in step S2 communicates with the automatically running ATO via a non-secure communication protocol and checks the integrity and timeliness of the messages.

[0018] As a preferred technical solution, step S3 specifically includes:

[0019] Each cycle, a check word is performed on the memory for secure input, secure output, secure communication parameters, Boolean expression operations, application data storage, and dual-channel data interaction.

[0020] Simultaneously, dual-channel processing is used for data processing. Data from both channels is compared, and only data that matches the comparison is used.

[0021] As a preferred technical solution, in step S4, the control board communicates with the automatic control ATP through a secure communication protocol and sends the calculation results to the ATP through secure data packets. The control board also communicates with the automatic operation ATO through a non-secure communication protocol and sends non-secure data to the ATO.

[0022] As a preferred technical solution, step S5 specifically includes:

[0023] The primary system sends primary / standby status messages to the peer system via an insecure communication protocol, and updates its own primary / standby status based on the peer system's primary / standby status messages; if communication is interrupted, the primary system is set to primary and the peer system is set to a crashed state.

[0024] As a preferred technical solution, step S6 specifically includes:

[0025] The control board outputs a request EB via a high-power safety output board.

[0026] The control board outputs a safety parking brake request, door permission, door closing, zero speed information, and forward traction enable safety amount through a low-power safety output board.

[0027] The control board outputs non-safe digital quantities such as door opening command, locomotive activation, traction, braking, ATO mode availability, ATB mode availability, traction and braking command, and mode indicator light through the non-safe output board FDB, and outputs non-safe analog quantities such as actual train speed and speed command through the non-safe output board FAB.

[0028] As a preferred technical solution, the control board checks the status of the output board and the consistency of data retrieval every cycle, every two weeks, or every three cycles; for EB requests, the vehicle will only EB if both ends request EB through the parallel output of the vehicle lines at both ends and through the Boolean logic configuration of the data.

[0029] According to a second aspect of the present invention, an electronic device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the program to implement the method described thereon.

[0030] According to a third aspect of the present invention, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the method described thereon.

[0031] Compared with the prior art, the present invention has the following advantages:

[0032] 1) This invention can reduce the number of hardware devices and lower system costs while ensuring security and usability;

[0033] 2) This invention reduces the number of high-power safety output boards and can reduce the hardware cost of the system while ensuring system availability through an architecture with parallel output at both ends;

[0034] 3) The secure communication method, computational transcoding, and verification word checking designed in this invention can ensure the timeliness of messages exchanged with train control and operation software, and the messages transmitted in communication and stored in memory will not be tampered with;

[0035] 4) The master / standby state switching function designed in this invention ensures that the system can operate normally after switching to another system after one system fails, thus providing redundancy. Attached Figure Description

[0036] Figure 1 This is a flowchart of the method of the present invention;

[0037] Figure 2 This is a schematic diagram of the asymmetric input-output redundancy architecture of the present invention. Detailed Implementation

[0038] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0039] like Figure 1 As shown, an asymmetric input / output redundancy architecture implementation method is provided. The asymmetric input / output redundancy architecture includes two systems: a primary system and a backup system. Each system includes at least a control board, a data acquisition board, a non-safety output board, and a low-power safety output board. One of the two systems includes a high-power safety output board. The implementation method includes the following steps:

[0040] Step S1: Collect the vehicle's code position status using the acquisition board;

[0041] Step S2: The control panel processes the safety and non-safety messages sent by the automatic control ATP and automatic operation ATO.

[0042] Step S3: The security message is verified by the control board, and a dual-channel security comparison is performed.

[0043] In step S4, the control board sends the calculated results to the automatic control ATP and the automatic operation ATO.

[0044] Step S5: The primary system sends the primary / standby status message to the peer system;

[0045] In step S6, the control board outputs the calculated value to the safety output board and the non-safety output board, and drives the vehicle load.

[0046] In this invention, the outputs of the two systems are connected in parallel. The high-power safety output of one system is output through the parallel output of the two ends, so that the final EB output is output by the "OR" logic of the calculation results of the two ends, thereby ensuring the safety of the EB output. At the same time, the redundancy of the two ends still exists, and the load can be driven by the output of the other end after one end fails.

[0047] The asymmetric input-output redundancy architecture described in this invention, as described above, reduces the number of high-power safety output boards in one of the original symmetric input-output architectures. Redundancy at both ends of the vehicle ensures the safety and availability of the EB output. By reducing the number of hardware devices, the cost of the entire signal system can be reduced.

[0048] refer to Figure 1 This invention introduces a flowchart of the input and output data processing, including the process of data acquisition, data processing, and data output.

[0049] refer to Figure 2 This is a device diagram of the asymmetric input / output redundancy architecture of the present invention, including schematic diagrams of each board.

[0050] In conjunction with the present invention, refer to Figure 1 The data processing workflow is implemented according to the following steps:

[0051] Step S1: Collect the vehicle's code position status through the acquisition board. Collect safety data such as cab activation status, mode selection status, door status, parking brake status, train integrity, and driver controller bypass through the first VDI acquisition board. Collect non-safety data such as door control mode, departure button status, BM button status, driver controller zero position, EB relay status, driver selected driving mode, and door command acquisition through the second VDI acquisition board.

[0052] Step S2: The control board processes the security and non-security messages sent by the Automatic ATP and Automatic Execution ATO. The VIOC software in the VIOC control board processes the messages from the Automatic ATP and Automatic Execution ATO. The security information exchange between the VIOC software and the ATP requires a secure communication protocol that uses encoding and decoding to prevent information from being out of order or tampered with. The non-security information exchange between the VIOC software and the ATO uses conventional UDP transmission, and the application layer also needs to check the validity of the messages.

[0053] Step S3: The security message is checked by the interface control software embedded in the control board, and a dual-channel security comparison is performed. The check word of the message from the ATP software is checked by the VIOC software. At the same time, the check word of the memory for security input, security output, security communication parameters, Boolean expression operation, application data storage, and dual-channel data interaction is checked every cycle to prevent the data in memory from not being refreshed or being tampered with. At the same time, the data processing in the VIOC software adopts dual-channel processing. The data in the two channels need to be compared. Only data that matches the comparison can be used.

[0054] Step S4: Send the calculated results to the Automatic Control ATP and Automatic Operation ATO for data processing. The VIOC software is used to calculate the collected data, received external data, and configured Boolean expression data, and the calculated results are sent to the Automatic Control ATP and Automatic Operation ATO for data processing.

[0055] Step S5: Send the primary / backup status to the input / output subsystem of the sending system. The VIOC software processes the status of the system and the sending system every cycle, compares the health of the two systems, and sets the system with the higher health status as the primary system and the system with the lower health status as the backup system. If the communication between the two systems is interrupted or the sending system is down, the status of the system is set to primary and the sending system is set to down. The redundancy between the two systems is ensured by calculating the primary and backup status every cycle, so that the downtime of one system will not cause the status of the entire input / output system to be abnormal.

[0056] Step S6: The interface control software outputs the calculated values ​​to the safety and non-safety output boards and drives the vehicle load. The VIOC software outputs EB requests through the high-power safety output board PSB board and safety quantities such as safety stop braking requests, door permission, door closing, zero speed information, and forward traction enable through the low-power safety output board DSB board. It outputs non-safety digital quantities such as door opening commands, locomotive activation, traction, braking, ATO mode availability, ATB mode availability, traction braking commands, and mode indicator lights through the non-safety output board FDB board. It outputs non-safety analog quantities such as actual train speed and speed commands through the non-safety output board FAB board. At the same time, the VIOC software checks the status of the output boards and the consistency of data retrieval every cycle, every two weeks, or every three cycles, and checks for system and hardware faults. For EB requests, the parallel output of the vehicle lines at both ends is used, and the Boolean logic configuration of the data ensures that EB requests from both ends will trigger EB for the vehicle. This ensures both safety and availability, and also reduces the number of high-power safety output boards in the first series.

[0057] In this example, one series of the asymmetric input / output redundancy architecture reduces the number of high-power safety output boards (PSBs) by using parallel outputs at both ends, thus reducing the number of PSBs per train by two. Based on the product's financial estimates, this can save over 20,000 yuan per train, significantly reducing signaling system costs for projects with a large number of vehicles.

[0058] The above is an introduction to the method embodiments. The following embodiments using electronic devices and storage media will further illustrate the solution of the present invention.

[0059] This invention also provides an electronic device including a central processing unit (CPU), which can perform various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) or loaded from a storage unit into a random access memory (RAM). The RAM may also store various programs and data required for device operation. The CPU, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.

[0060] Multiple components in the device are connected to the I / O interface, including: input units such as keyboards and mice; output units such as various types of displays and speakers; storage units such as disks and optical discs; and communication units such as network interface cards (NICs), modems, and wireless transceivers. The communication unit allows the device to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0061] The processing unit executes the various methods and processes described above, such as methods S1 to S6. For example, in some embodiments, methods S1 to S6 may be implemented as computer software programs tangibly contained in a machine-readable medium, such as a storage unit. In some embodiments, part or all of the computer program may be loaded and / or installed on the device via ROM and / or a communication unit. When the computer program is loaded into RAM and executed by the CPU, one or more steps of methods S1 to S6 described above may be performed. Alternatively, in other embodiments, the CPU may be configured to execute methods S1 to S6 by any other suitable means (e.g., by means of firmware).

[0062] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0063] The program code used to implement the methods of the present invention can be written in any combination of one or more programming languages. This program code can be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code can be executed entirely on the machine, partially on the machine, as a standalone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0064] In the context of this invention, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0065] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for implementing an asymmetric input-output redundancy architecture, characterized in that, The asymmetric input / output redundancy architecture includes two systems: a primary system and a backup system. Each system includes at least a control board, a data acquisition board, a non-safety output board, and a low-power safety output board. One of the two systems includes a high-power safety output board. The implementation method includes the following steps: Step S1: Collect the vehicle's code position status using the acquisition board; Step S2: The control panel processes the safety and non-safety messages sent by the automatic control ATP and automatic operation ATO. Step S3: The security message is verified by the control board, and a dual-channel security comparison is performed. In step S4, the control board sends the calculated results to the automatic control ATP and the automatic operation ATO. Step S5: The primary system sends the primary / standby status message to the peer system; In step S6, the control board outputs the calculated value to the safety output board and the non-safety output board, and drives the vehicle load. The code position status in step S1 includes external secure input data and external non-secure input data; Step S3 specifically involves: Each cycle, a check word is performed on the memory for secure input, secure output, secure communication parameters, Boolean expression operations, application data storage, and dual-channel data interaction. Simultaneously, dual-channel processing is used for data processing, and the data from both channels is compared. Only data that matches the comparison can be used. Step S6 specifically involves: The control board outputs a request EB via a high-power safety output board. The control board outputs a safety parking brake request, door permission, door closing, zero speed information, and forward traction enable safety amount through a low-power safety output board. The control board outputs non-safe digital quantities such as door opening command, locomotive activation, traction, braking, ATO mode availability, ATB mode availability, traction and braking command, and mode indicator light through the non-safe output board FDB, and outputs non-safe analog quantities such as actual train speed and speed command through the non-safe output board FAB. The control board checks the status of the output board and the consistency of data retrieval every cycle, every two weeks, or every three cycles. For EB requests, the vehicle will only EB if both ends request EB through the parallel output of the vehicle lines at both ends and through the Boolean logic configuration of the data.

2. The method for implementing an asymmetric input-output redundancy architecture according to claim 1, characterized in that, The external safety input data includes the cab activation status, mode selection status, door status, parking brake status, train integrity, and driver controller bypass data. The external non-safety input data includes the door control mode, departure button status, BM button status, driver controller zero position, EB relay status, driver-selected driving mode, and door command acquisition data.

3. The method for implementing an asymmetric input-output redundancy architecture according to claim 1, characterized in that, In step S2, the control board communicates with the Automatic Control Platform (ATP) via a secure communication protocol, transcodes the received data, and performs security verification and timeliness checks on the messages.

4. The method for implementing an asymmetric input-output redundancy architecture according to claim 1, characterized in that, In step S2, the control board communicates with the automatically running ATO via a non-secure communication protocol and checks the integrity and timeliness of the messages.

5. The method for implementing an asymmetric input-output redundancy architecture according to claim 1, characterized in that, In step S4, the control board communicates with the automatic control ATP through a secure communication protocol and sends the calculation results to the ATP via secure data packets. The control board also communicates with the automatic operation ATO through a non-secure communication protocol and sends non-secure data to the ATO.

6. The method for implementing an asymmetric input-output redundancy architecture according to claim 1, characterized in that, Step S5 specifically involves: The primary system sends primary / standby status messages to the peer system via an insecure communication protocol, and updates its own primary / standby status based on the peer system's primary / standby status messages; if communication is interrupted, the primary system is set to primary and the peer system is set to a crashed state.

7. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the program, it implements the method as described in any one of claims 1 to 6.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1 to 6.