Method and apparatus for determining to stop transmitting a redundant clear-to-run
By constructing a multi-dimensional correlation matrix to determine the risk of the track section where the train is located, the problem of redundant train operation permits being unable to be stopped in a timely manner in high-risk scenarios is solved, thus achieving effective protection of railway transportation safety.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-09
- Publication Date
- 2026-04-14
AI Technical Summary
The existing redundant train operation permit function cannot be stopped in time in high-risk scenarios, which may cause trains to pass through faulty sections, leading to safety accidents such as derailment and collision, and posing a hidden danger to railway transportation safety.
By receiving multi-source operational information, a multi-dimensional correlation matrix is constructed to determine whether the track section where the train is located is in a special scenario such as superimposed fault risks, mismatch between train position and safety, or coverage of disaster impact. If so, redundant train operation permits are stopped from being sent to the temporary speed limit server.
Accurately identify complex risks, avoid misjudgments, directly cut off the authorization for trains to pass through faulty block sections, prevent safety accidents, and improve railway transportation safety.
Smart Images

Figure CN121291545B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of train control technology, and in particular to a method and device for determining when to stop sending redundant train operation permits. Background Technology
[0002] In the CTCS-2 level train control system, when a non-train-occupied red light band fault occurs in the track circuit of a section (such as equipment malfunction or track malfunction), the train control center will control the block section behind the fault to send a stop code, forcing subsequent trains to stop. The fault needs to be handled on-site by the equipment management unit and cleared before the track can be restored. During the handling period, trains need to repeat the process of stopping and waiting for the clearing, which reduces traffic efficiency and is prone to congestion and delays during peak hours.
[0003] To alleviate this problem, existing technologies introduce a redundant train operation permit function. After the dispatcher manually confirms that there is no fatal risk in the faulty section (such as no rail breakage or foreign object intrusion), the train control center generates a redundant train operation permit based on the axle idle status and the real-time position of the train, and sends it to the temporary speed limit server. The temporary speed limit server then forwards it to the onboard equipment through the vehicle-to-ground wireless link, so that subsequent trains can pass through the faulty section without having to stop repeatedly.
[0004] However, the existing logic for stopping redundant train operation permits only ceases sending them to the temporary speed limit server when the train control center receives a stop order from the centralized dispatching system for the axle-counting section corresponding to the fault. For more complex and risky scenarios in actual operation, the existing logic cannot achieve timely stopping of redundant train operation permits. If a train still holds authorization to pass through a faulty section in a high-risk scenario, it may lead to derailments, collisions, or an inability to respond to sudden disasters, thus posing a safety hazard to railway transportation. Summary of the Invention
[0005] In view of the above problems, this application provides a method and device for determining when redundant driving permits are stopped from being sent.
[0006] To solve the above-mentioned technical problems, this application proposes the following solution:
[0007] Firstly, this application provides a method for determining when to stop sending redundant train operation permits. The method includes: receiving multi-source operational association information, which is used to indicate operational data related to faults, target trains, communications, disasters, and track sections; constructing a multi-dimensional association matrix based on the multi-source operational association information to establish the association relationship between each information dimension and the operational safety of the target train; determining whether the track section where the target train is located is in a preset special scenario based on the multi-dimensional association matrix, which includes at least a fault risk superposition scenario, a train position and safety mismatch scenario, and a disaster impact coverage scenario; if so, stopping the sending of redundant train operation permits for the target train to the temporary speed limit server, whereby the redundant train operation permits are used to authorize the target train to pass through the fault block section.
[0008] Secondly, this application provides a device for determining when redundant driving permits are stopped from being sent. The device for determining when redundant driving permits are stopped from being sent includes:
[0009] The receiving module is used to receive multi-source operational correlation information, which is used to indicate operational data related to faults, target trains, communications, disasters, and track sections.
[0010] The association module is used to construct the association relationship between each information dimension and the target train operation safety based on multi-source operational association information, forming a multi-dimensional association matrix;
[0011] The judgment module is used to determine whether the track section where the target train is located is in a preset special scenario based on a multi-dimensional correlation matrix. The preset special scenarios include at least the fault risk superposition scenario, the train position and safety mismatch scenario, and the disaster impact coverage scenario.
[0012] The instruction module is used to, if so, stop sending redundant train passes for the target train to the temporary speed limit server. Redundant train passes are used to authorize the target train to pass through the fault block section.
[0013] To achieve the above objectives, according to a third aspect of this application, a storage medium is provided, the storage medium including a stored program, wherein, when the program is executed, the device where the storage medium is located is controlled to execute the determination method for stopping the transmission of redundant driving permits described in the first aspect.
[0014] To achieve the above objectives, according to a fourth aspect of this application, an electronic device is provided, the device including at least one processor, and at least one memory and bus connected to the processor; wherein the processor and memory communicate with each other through the bus; the processor is used to call program instructions in the memory to execute the determination method for stopping the transmission of redundant driving permits described in the first aspect.
[0015] By employing the above-described technical solution, the technical solution provided in this application has at least the following advantages:
[0016] This application first transforms fragmented operational data into a logical correlation between various information dimensions and train operation safety. This correlation logic is achieved by quantifying the coupling relationship between individual risk factors and overall safety, enabling precise identification of complex risks that are difficult to detect using traditional technologies, effectively avoiding misjudgments due to single indicator compliance but overall risk exceeding limits. Based on this, relying on a multi-dimensional correlation matrix, it can further accurately identify whether the track section where the target train is located is in one of three high-risk scenarios: scenarios with overlapping fault risks, scenarios where train position and safety are mismatched, and scenarios where disaster impacts are widespread. The core risk of these scenarios is that if the train continues to hold redundant operating permits, it is highly likely to cause safety accidents such as derailment, collisions, or inability to cope with disasters. When a train is determined to be in any of the above high-risk scenarios, the train control center will immediately stop sending redundant operating permits for that train to the temporary speed limit server, directly cutting off the authorization basis for the train to pass through the fault block section. By preventing the train from entering the dangerous area under risk conditions during the operating authorization process, the potential safety hazards of railway transportation are ultimately avoided.
[0017] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0018] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:
[0019] Figure 1 A flowchart illustrating a method for determining when redundant driving permits are stopped from being sent, as provided in an embodiment of this application, is shown.
[0020] Figure 2 This illustration shows a schematic diagram of a device for determining the suspension of redundant driving permits according to an embodiment of this application.
[0021] Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of this application is shown. Detailed Implementation
[0022] Exemplary embodiments of the present application will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this application will be thorough and complete, and will fully convey the scope of the present application to those skilled in the art.
[0023] In this application, the term "at least one" means one or more, and the term "multiple" means two or more.
[0024] It should also be understood that the term “if” can be interpreted as “when” or “upon”, or “in response to determination” or “in response to detection”. Similarly, depending on the context, the phrase “if determination…” or “if detection [the stated condition or event]” can be interpreted as “when determination…” or “in response to determination…” or “when detection [the stated condition or event]” or “in response to detection [the stated condition or event]”.
[0025] This application provides a method for determining when redundant train permits are stopped from being sent. The method for determining when redundant train permits are stopped from being sent will now be described in detail with reference to the accompanying drawings. Figure 1 This is a flowchart illustrating a method for determining when to stop sending redundant driving permits, as provided in this application. Specifically, it includes the following steps:
[0026] Step 110: Receive multi-source operation association information.
[0027] The method for determining when to stop sending redundant train operation permits in this application is applied to the train control center. Multi-source operational information includes at least: operational data related to faults, target trains, communications, disasters, and track sections.
[0028] Step 120: Based on multi-source operational information, construct the correlation between each information dimension and the target train operation safety to form a multi-dimensional correlation matrix.
[0029] When constructing the correlation between each information dimension and the target train's operational safety based on the multi-source operational correlation information received in step 110, the core impact dimensions are first decomposed, and four types of sub-correlation are specifically constructed to achieve hierarchical analysis. These are: fault axle counting sub-correlation, train fault sub-correlation, location communication sub-correlation, and disaster zone sub-correlation. Among them, the fault axle counting sub-correlation focuses on the accurate identification and risk quantification of track facility faults. Its core function is to filter out effective fault objects that have a direct impact on operational safety from multi-source information and calculate the risk level of these objects. The train fault sub-correlation revolves around the interaction between the target train and the fault zone. By analyzing parameters such as train position, speed, and braking capacity, it determines the safety warning level of the target train, intuitively reflecting the degree of direct safety threat currently faced by the train. The location communication sub-correlation focuses on positioning reliability and communication stability, used to determine the risk level of position mismatch. This level not only indicates the degree of deviation between the position information reported by the target train and the actual position, but also quantifies the degree of risk posed by such deviation to train operational safety, avoiding safety misjudgments caused by inaccurate positioning. The disaster section sub-association focuses on the impact assessment of the external environment on the line, and is used to determine the degree of impact of disasters (such as rainstorms, mudslides, etc.) on the track section, and to clarify the disaster coverage, expansion trend and damage risk to key facilities.
[0030] In constructing the fault axle counting sub-association, data related to faults and axle counting sections is first extracted from multi-source operational association information. This data specifically includes fault zone codes, a list of block sections under the jurisdiction of the axle counting section, the operational status of the axle counting section, equipment health, section function type, historical fault frequency, and the fault type and fault propagation trend of the fault zone. The fault zone code uniquely identifies each faulty block section, and its coding rules are consistent with the block section numbering system of the track section, ensuring accurate spatial location of the fault. The list of block sections under the jurisdiction of the axle counting section records the correspondence between all block sections managed by each axle counting section, clearly indicating the mapping relationship between the axle counting section number and the corresponding block section codes. The operational status of the axle counting section indicates whether the section is currently in normal working condition. Only axle counting sections in the operational status have the ability to monitor and control their assigned block sections; data related to axle counting sections in the deactivated status will not be included in subsequent analysis. Equipment health is an indicator derived from a comprehensive evaluation of the operating parameters, maintenance records, and fault repair status of the axle counting section equipment. It reflects the current operating condition of the equipment; a higher health rating indicates a lower probability of equipment failure. Section function type is categorized based on the axle counting section's role in the track. Examples include mainline operating sections, auxiliary passing sections, and maintenance / standby sections. Different function types have varying importance to train operation safety, and their fault impact range and handling priorities also differ. Historical fault frequency is the number of times a fault has occurred in the axle counting section over a certain period (e.g., 12 months). Frequency data reflects the stability of the section equipment, with sections experiencing high-frequency faults requiring close monitoring. Fault type for fault zones specifies the concrete manifestation of the fault, such as axle counter signal loss, track circuit short circuit, and abnormal block zone boundary signals. Different types of faults pose varying degrees of threat to train operation. The fault propagation trend is determined by analyzing the changes in the affected area over a period of time (e.g., 30 minutes) after the fault occurs. It is used to determine whether there is a possibility that the fault will spread to the surrounding block sections. The faster the fault spreads, the greater the potential risk to train safety.
[0031] After data extraction, the fault partition codes are matched with the list of block sections under the jurisdiction of the axle counting section to determine the axle counting section corresponding to each fault partition. During the matching process, based on the structural characteristics of the fault partition codes, the axle counting section record containing the fault partition code is searched in the list of block sections under the jurisdiction of the axle counting section. For example, if the fault partition code is "L01-Q03-B05" (where L01 represents the line number, Q03 represents the section number, and B05 represents the block section number), then the axle counting section number (such as "J03-02") that governs the block section "L01-Q03-B05" is selected from the list. Through this matching action, the scattered fault partitions are associated with the axle counting sections with management authority.
[0032] Based on the activation status, equipment health, section function type, and historical fault frequency of axle counting sections, axle counting sections meeting preset conditions are selected, and the corresponding fault zones of these axle counting sections are identified as valid fault targets. The preset conditions are designed around train operation safety. For example, regarding activation status, only activated axle counting sections are selected, excluding those that are out of service or under maintenance. Regarding equipment health, a health threshold is set, retaining only axle counting sections with health levels above the threshold. Regarding section function type, priority is given to mainline operating sections, with auxiliary sections further evaluated based on line operation conditions; maintenance standby sections are excluded if not in use. Regarding historical fault frequency, a frequency upper limit is set (e.g., 5 times / year), and only axle counting sections with historical fault frequencies below this limit are included in the selection scope. After this multi-dimensional screening, the remaining axle counting sections are the key sections with a direct impact on train operation safety, and their corresponding fault zones are thus identified as valid fault targets requiring focused attention, excluding fault zones with minimal impact on current operational safety.
[0033] After identifying valid fault objects, a hierarchical mapping is established between the filtered axle counting sections and their corresponding fault zones to clarify the primary fault zone and associated zones within each axle counting section. The establishment of this hierarchical mapping considers factors such as the chronological order of fault occurrence, fault severity, and the scope of fault impact. For example, within the same axle counting section, the fault zone that first experiences a fault with the widest impact and highest severity is designated as the primary fault zone. Fault zones adjacent to the primary fault zone, which may be affected by the primary fault and potentially lead to secondary faults or have their fault scope extended to it, are designated as associated zones. By establishing this hierarchical relationship, the association logic between different fault zones within the same axle counting section can be clearly presented, and the potential paths of fault propagation can be identified.
[0034] Finally, based on the relationship between the main fault zone and related zones, the fault type of the fault zone, the fault propagation trend, and the equipment health of the corresponding axle counting section, a fault risk assessment model is constructed to calculate the risk level of the effective fault objects. When constructing the fault risk assessment model, each input parameter is first quantified. For example, regarding the relationship between the main fault zone and related zones, if the main fault zone has multiple related zones (e.g., 3 or more), the risk quantification value for this dimension increases. Regarding fault types, different fault types are assigned values according to their threat level. For example, a track circuit short circuit is assigned 90 points, axle counter signal loss is assigned 60 points, and an abnormal signal at the block section boundary is assigned 40 points (higher scores indicate higher risk). Regarding the fault propagation trend, different scores are set according to the propagation speed. For example, propagating one or more block sections per hour is assigned 80 points, propagating one block section every 2-3 hours is assigned 50 points, and no propagation trend is assigned 20 points. The equipment health of the axle counting section directly uses the previously assessed health score, which is then converted into a risk-related score through reverse processing. For example, a health score of 80 corresponds to a risk score of 20, and a health score of 60 corresponds to a risk score of 40. Then, weights are assigned to each quantified parameter, with the weight allocation determined based on the parameter's impact on fault risk. For instance, the weight for fault propagation trend is set at 30%, fault type at 25%, primary correlation partition relationship at 25%, and equipment health at 20%. Finally, a weighted summation method is used to calculate the comprehensive risk score for each valid fault object, and the risk level is classified according to the score range. For example, 90-100 points indicates extremely high risk, 70-89 points indicates high risk, 50-69 points indicates medium risk, and below 50 points indicates low risk, thus completing the calculation of the risk level for valid fault objects.
[0035] In constructing the train fault sub-association, data related to the target train and the faulty section are extracted from multi-source operational association information. This data specifically includes the target train's real-time location, operating speed, braking performance parameters, block section code, historical operating trajectory, as well as the boundary parameters and fault section code of the faulty section. The real-time location of the target train is obtained collaboratively through the onboard Global Positioning System (GPS) and ground transponders along the track. The positioning result is presented in the form of track mileage coordinates (e.g., K105+320, representing 320 meters above the 105 km mark), ensuring accurate correspondence to the physical location within the track section. The operating speed is collected in real-time by onboard speed sensors at a frequency of 10 times per second. After collection, a moving average algorithm is used to remove instantaneous fluctuations to obtain a stable actual operating speed value. Braking performance parameters include the target train's maximum braking deceleration, braking response time, and braking system operating pressure. Maximum braking deceleration is calculated using the train's speed change rate under emergency braking conditions. Braking response time is the time interval between the onboard control system issuing a braking command and the braking actuator generating braking force. The braking system operating pressure is directly monitored by onboard pressure sensors. These parameters collectively determine the train's braking capability. The block section code adopts the same coding rules as the track section block sections (e.g., line number-section number-section number, such as L02-Q04-B12), used to identify the current block section the train is in. Historical operating trajectory records the target train's position-time series data over the past 24 hours, reflecting the train's operating patterns and stopping habits. The boundary parameters of the fault section define the start and end positions of the fault section using mileage coordinates (e.g., K106+100 to K106+800), clearly defining the spatial range of the fault's impact. The fault section code is consistent with the coding rules of the target train's block section.
[0036] After data extraction, the shortest distance between the target train and the fault zone is determined based on the real-time location of the target train and the boundary parameters of the fault zone. The calculation first clarifies the relationship between the real-time mileage coordinates of the target train and the mileage range of the fault zone boundary parameters. If the real-time mileage coordinates of the train are outside the mileage range of the fault zone boundary parameters, and the train's direction of travel is towards the fault zone, then the shortest distance is the difference between the real-time mileage of the train and the mileage of the fault zone boundary closest to the train. If the train's direction of travel is away from the fault zone, then the shortest distance is the difference between the real-time mileage of the train and the mileage of the fault zone boundary furthest from the train. If the real-time mileage coordinates of the train are within the mileage range of the fault zone boundary parameters, then the shortest distance is determined to be 0. For example, if the real-time location of the target train is K105+320, the fault zone boundary parameters are from K106+100 to K106+800, and the train's direction of travel is the direction of increasing mileage (i.e., towards K107), then the shortest distance is the difference between K106+100 and K105+320, which is calculated to be 780 meters. If the train is traveling in the direction of decreasing mileage, the shortest distance is the difference between K105+320 and K106+800 (take the absolute value), which is calculated to be 1480 meters.
[0037] Furthermore, based on the target train's operating speed and braking performance parameters, the safe braking distance of the target train is determined. The calculation of the safe braking distance comprehensively considers two parts: the train's travel distance within the braking response time and the train's deceleration distance during braking execution. The travel distance within the braking response time is the product of the target train's actual operating speed and the braking response time; the deceleration distance during braking execution is calculated using a kinematic formula, i.e., the square of the target train's actual operating speed divided by (twice the maximum braking deceleration). Adding these two distances together yields the target train's safe braking distance. For example, if the target train's actual operating speed is 80 km / h (approximately 22.22 m / s), the braking response time is 0.6 seconds, and the maximum braking deceleration is 0.8 m / s... 2 Therefore, the travel distance during the braking response time is approximately 13.33 meters (22.22 m / s × 0.6 seconds), and the braking deceleration distance is (22.22 m / s). 2 ÷ (2 × 0.8 m / s) 2 The distance is approximately 308.64 meters. The safe braking distance is approximately 321.97 meters (13.33 meters + 308.64 meters), which is rounded up to 322 meters.
[0038] Based on the calculated relationship between the shortest distance and the safe braking distance, the safety warning level of the target train is determined. The preset safety warning levels are divided into three tiers: low risk, medium risk, and high risk. The judgment rules are as follows: When the shortest distance is greater than 1.5 times the safe braking distance, it is judged as a low-risk level, indicating that the train has sufficient braking space and can stop smoothly even in the event of an emergency. When the shortest distance is between 1.0 and 1.5 times the safe braking distance, it is judged as a medium-risk level, indicating that the train's braking space is relatively tight, and close monitoring of the train's operating status and changes in the fault zone is necessary. When the shortest distance is less than 1.0 times the safe braking distance, it is judged as a high-risk level, indicating that the train's current braking space is insufficient, and if the operating status is not adjusted in time, it may not be able to stop safely before the fault zone. Taking a safe braking distance of 322 meters as an example, if the shortest distance is 780 meters (780÷322≈2.42>1.5), the safety warning level is low risk; if the shortest distance is 450 meters (450÷322≈1.40, between 1.0 and 1.5), the safety warning level is medium risk; if the shortest distance is 280 meters (280÷322≈0.87<1.0), the safety warning level is high risk.
[0039] Next, the block section code of the target train is compared with the fault section code, and its position within a preset time period is predicted based on the target train's historical trajectory to achieve position attribution verification. During code comparison, if the two codes match perfectly, it indicates that the target train is currently in the fault section; if they do not match, the train's direction of travel is considered to further determine whether the train is moving towards the fault section. The average speed and direction of travel of the train within the same time period and section in the historical trajectory are analyzed. If the train's operating status is stable (no frequent acceleration, deceleration, or stops), the current speed is multiplied by a preset time period (e.g., 5 minutes, 10 minutes), and combined with the current real-time position and direction of travel, the predicted position within the preset time period is calculated. The block section code corresponding to this predicted position is then determined as the predicted section. For example, if the target train's current block section code is L02-Q04-B12, the fault section code is L02-Q04-B13, the train's direction of travel is towards section B13, and historical trajectory data shows the train's average speed in this section is 60 km / h (i.e., 1 km / min), and the preset prediction period is 5 minutes, then the train will travel 5 km in the next 5 minutes. Its current real-time position is K105+320, and its predicted position is K110+320, corresponding to the block section code L02-Q04-B13, which matches the fault section code. The position attribution verification result indicates that the train will enter the fault section within the preset future time period. If the block section code corresponding to the predicted position is inconsistent with the fault section code, the verification result indicates that the train will not enter the fault section within the preset future time period.
[0040] Finally, the safety warning level of the target train is adjusted based on the location attribution verification results. If the location attribution verification result indicates that the target train is currently within the fault zone, then regardless of the previously determined safety warning level, it is adjusted to a high-risk level, and an emergency braking warning is triggered. If the verification result indicates that the train will enter the fault zone within a preset time period, further adjustments are made based on the current warning level: if the current level is low-risk, it is adjusted to medium-risk; if the current level is medium-risk, it is adjusted to high-risk; if the current level is high-risk, it remains unchanged, and the interval between location attribution verifications is shortened (e.g., from once every 5 minutes to once every 2 minutes). If the verification result indicates that the train will not enter the fault zone within a preset time period, adjustments are made based on changes in the shortest distance and safe braking distance: if the shortest distance shows an increasing trend, it can be adjusted from a medium-risk level to a low-risk level, and from a high-risk level to a medium-risk level; if the shortest distance shows a decreasing trend but still does not enter the fault zone, the current warning level remains unchanged. For example, if the previous safety warning level was low risk, and the location verification result indicates that the train will enter the fault zone within the next 5 minutes, then it will be adjusted to a medium risk level; if the previous safety warning level was medium risk, and the verification result indicates that the train is currently in the fault zone, then it will be adjusted to a high risk level; if the previous safety warning level was high risk, and the verification result indicates that the train will not enter the fault zone in the future and the shortest distance is gradually increasing, then it will be adjusted to a medium risk level.
[0041] In constructing the location communication sub-association, data related to the target train's location, communication status, and safety warnings are extracted from multi-source operational association information. This data specifically includes the target train's current operating speed, the length of the block section within the axle counting section, the communication link parameters between the temporary speed limit server and the target train, the target train's location update cycle, and the safety warning level. The target train's current operating speed is collected in real-time by onboard speed sensors. For example, if five consecutive speed values are collected (81 km / h, 79 km / h, 80 km / h, 82 km / h, and 78 km / h), a moving average is applied to determine the current operating speed as 80 km / h, ensuring that the speed data stably reflects the train's actual operating status. The length of the block section within the axle counting section is extracted from the track section basic database. This length is determined based on track line design standards and the function of the axle counting section. For example, the block section length of the mainline operating section is typically set to 1000 meters, while the block section length of the auxiliary access section can be set to 800 meters. Furthermore, the length data of each block section is bound to the corresponding axle counting section code to ensure accurate matching of the target train's location within the section. The communication link parameters between the temporary speed limit server and the target train are obtained through communication network monitoring equipment. These parameters specifically include communication bandwidth, transmission latency, bit error rate, and link connection status. Communication bandwidth reflects data transmission capacity; transmission latency is the time interval between data transmission from the server to the train's onboard terminal; the bit error rate is the ratio of erroneous bits in the transmitted data to the total number of bits; and the link connection status is determined through periodic heartbeat packet detection (a link interruption is determined if three consecutive heartbeat packet responses are not received). The target train's position update cycle is a parameter preset by the train control center and dynamically adjusted according to the train's operating speed. For example, the update cycle is set to 2 seconds when the train's operating speed is below 60 km / h, and shortened to 1 second when it is above 60 km / h, to ensure that the location information update frequency matches the train's position change rate. The safety warning level is a result determined during the previous construction of the train fault sub-association, divided into three levels: low risk, medium risk, and high risk.
[0042] Furthermore, based on the target train's current operating speed, block section length, and position update cycle, the dynamic validity period of the train's position information is determined. This dynamic validity period is used to clarify the time range within which the position information reported by the train accurately reflects its actual position. The calculation process combines the train's position change pattern with the block section's tolerance for position deviation. First, the current operating speed is converted to meters per second (e.g., 80 km / h is approximately 22.22 m / s), and then the distance the train can travel within one position update cycle is calculated. For example, with an update cycle of 1 second, the travel distance is 22.22 m / s × 1 second = 22.22 meters. Subsequently, a position deviation allowable threshold is set based on the block section length, typically 10% of the block section length. For example, if the block section length is 1000 meters, the allowable threshold is 100 meters. This threshold represents that when the position information deviation is within this range, the position information can still be considered to effectively support a safety judgment. Finally, the position deviation allowable threshold is divided by the current operating speed to obtain the dynamic validity period. For example, 100 meters ÷ 22.22 m / s ≈ 4.5 seconds. Taking this calculation result as an example, the dynamic effective time limit is 4.5 seconds, which means that within 4.5 seconds after the train reports its location information, the deviation between its actual location and the reported location will not exceed 100 meters, and the location information still has accuracy. If the location information is not updated within 4.5 seconds, the deviation may exceed the allowable threshold, and the reference value of the location information will be reduced.
[0043] Next, the communication status between the temporary speed limit server and the target train is evaluated based on the communication link parameters, and the dynamic validity period is adjusted according to the evaluation results. Clear criteria are set for the communication status evaluation: when the communication bandwidth is ≥2Mbps, the transmission delay is ≤50ms, and the bit error rate is ≤10... -7 When the link connection is normal, the communication status is considered good; when the communication bandwidth is between 1-2 Mbps, the transmission delay is between 50-100 ms, and the bit error rate is between 10... -7 -10 -6 When the link connection is stable, the communication status is considered normal; when the communication bandwidth is <1Mbps, the transmission delay is >100ms, and the bit error rate is >10... -6When the link connection is intermittently interrupted, it is considered a poor communication status; when the link connection is interrupted, it is considered a communication interruption. The adjustment rules for different communication statuses are as follows: When the communication status is good, the original dynamic validity period remains unchanged (e.g., 4.5 seconds); when the communication status is average, the dynamic validity period is shortened by 20% (e.g., 4.5 seconds × 0.8 = 3.6 seconds); when the communication status is poor, the dynamic validity period is shortened by 50% (e.g., 4.5 seconds × 0.5 = 2.25 seconds); when the communication status is interrupted, the dynamic validity period is shortened by 80% (e.g., 4.5 seconds × 0.2 = 0.9 seconds). The core of this adjustment logic is that the worse the communication status, the more difficult it is to guarantee the timeliness and accuracy of location information transmission. Therefore, by shortening the dynamic validity period, the risk of location information failure due to communication problems is reduced.
[0044] The multi-source positioning information of the target train is then fused and compared with the reported real-time location to determine the reliability of the location information. The multi-source positioning information includes onboard GPS positioning information, transponder positioning information along the track, and onboard odometer positioning information. A weighted average algorithm is used during the fusion process, assigning weights based on the accuracy of different positioning methods. For example, if the transponder positioning weight is set to 40%, the GPS positioning weight to 30%, and the odometer positioning weight to 30%, and the transponder positioning mileage is K105+321, the GPS positioning mileage is K105+320, and the odometer positioning mileage is K105+319, the fused positioning mileage after weighted calculation is (321×0.4+320×0.3+319×0.3)=320.1 meters, i.e., K105+320.1. The fused positioning mileage is compared with the real-time location mileage reported by the train (e.g., K105+320), and the deviation value is calculated to be 0.1 meters. The preset confidence threshold is: a deviation value < 2 meters is judged as high confidence, a deviation value between 2 and 5 meters is judged as medium confidence, and a deviation value > 5 meters is judged as low confidence. Therefore, the confidence of the location information in this example is high confidence.
[0045] Finally, based on the target train's location update status within the dynamic validity period, the reliability of the location information, and the safety warning level, the location mismatch risk level is determined. Location update status is categorized into three types: on-time update (location reporting completed within the dynamic validity period), overdue update (location reporting not completed beyond the dynamic validity period), and no update (no location reporting data received within the dynamic validity period). Location information reliability is categorized into three levels: high, medium, and low. Safety warning level is categorized into three levels: low, medium, and high. Location mismatch risk is classified into three levels: low risk, medium risk, and high risk. The specific judgment rules are as follows: When the location update status is timely, the credibility is high, and the security warning level is low risk, it is judged as low risk; when the location update status is timely, the credibility is high, and the security warning level is medium risk, or when the update status is timely, the credibility is medium, and the security warning level is low risk, it is judged as medium risk; when the location update status is timed out or not updated, or the credibility is low, or the security warning level is high risk, it is judged as at least medium risk; when the location update status is not updated and the credibility is low, or the update status is timed out and the security warning level is high risk, it is judged as high risk. For example, if the target train's dynamic effective time limit is 3.6 seconds, and the position is updated within the time limit (update status is updated on time), the credibility is high, and the safety warning level is medium risk, then the position mismatch risk level is determined to be medium risk; if the train does not update its position for more than 3.6 seconds (update status is updated after timeout), the credibility is low, and the safety warning level is high risk, then it is determined to be high risk.
[0046] In constructing sub-associations for disaster zones, data related to disasters and track sections are extracted from multi-source operational information. Disaster types are obtained by connecting to meteorological disaster early warning systems, geological disaster monitoring stations, and video surveillance equipment along the track. These are specifically categorized into meteorological disasters (such as heavy rain, strong winds, heavy snow, and high temperatures), geological disasters (such as mudslides, landslides, and earthquakes), and track environment disasters (such as track icing, overhead contact line icing, and foreign object intrusion). The impact mechanisms and risk levels of different types of disasters on track sections vary. For example, heavy rain primarily threatens the stability of the track subgrade, while strong winds can easily cause overhead contact line swaying or foreign object intrusion into the line. The disaster impact area is recorded in two forms: spatial coordinates and track mileage range. Spatial coordinates are defined by a rectangular area of latitude and longitude (e.g., 116.32°-116.35°E, 39.92°-39.95°N), while track mileage range directly corresponds to the line mileage (e.g., K100+500 to K102+300). The two forms can be converted between each other through a track geographic information system (GIS) to ensure accurate location of the track section covered by the disaster. The disaster expansion rate is calculated by continuously monitoring changes in the disaster impact area. For example, if disaster impact range data is collected every 30 minutes, and the affected mileage is from K101+000 to K101+500 in the first 30 minutes, and expands to K100+800 to K101+800 in the next 30 minutes, then the expansion rate is ((101800-100800)-(101500-101000))÷0.5 hours = 1000 meters / hour. This rate reflects the speed of disaster spread. The physical range parameters of the track section are retrieved from the track line basic database, including the starting mileage, ending mileage, track width (usually the track width corresponding to a 14.35-meter standard gauge, approximately 20 meters), curve radius, and gradient. For example, a track section has a starting mileage of K100+000, an ending mileage of K105+000, a track width of 20 meters, a maximum curve radius of 800 meters, and a maximum gradient of 3%. The key facility distribution information covers the specific locations (marked by mileage coordinates, such as the signal located at K101+200 and the turnout located at K102+500) and facility types of signals, turnouts, bridges, tunnels, catenary supports, and axle counters within the section.
[0047] Spatially comparing the disaster impact area with the physical range of the track section determines the overlapping area and its proportion. During spatial comparison, if the disaster impact area is presented in latitude and longitude coordinates, it is first converted to the corresponding track mileage range using the track GIS system, and then overlaid with the track section's mileage range (from the starting point to the ending point). If the disaster impact area is already within the track mileage range, overlay is performed directly. The determination of the overlapping area follows the intersection principle, i.e., segments simultaneously located within both the disaster impact area and the track section's physical range. For example, if the disaster impact area is from K101+000 to K101+800, and the track section's physical range is from K100+500 to K102+300, then the overlapping area is from K101+000 to K101+800. If the disaster impact area is from K103+000 to K103+500, and the track section's physical range is from K100+500 to K102+300, then there is no overlapping area. The overlap ratio is calculated based on the effective length of the track section, which is the difference between the endpoint mileage and the starting mileage. For example, if the effective length from K100+500 to K102+300 is 1800 meters, the overlap ratio = (Ending mileage of the overlapping area - Starting mileage of the overlapping area) ÷ Effective length of the track section × 100%. For instance, if the length of the overlapping area from K101+000 to K101+800 is 800 meters, and the effective length of the track section is 1800 meters, then the overlap ratio = 800 ÷ 1800 × 100% ≈ 44.4%. If there is no overlapping area, the overlap ratio is 0%.
[0048] Furthermore, by combining the disaster expansion rate, the expansion trend of the disaster's impact area within a preset time period is predicted. The preset time period is flexibly set according to the disaster type and expansion rate, typically divided into three levels: 1 hour, 2 hours, and 4 hours. For example, when the disaster expansion rate is fast (e.g., 2000 m / h) or the disaster type risk is high (e.g., mudslide), the preset time period is 1 hour. When the expansion rate is moderate (e.g., 1000 m / h) or the disaster type risk is moderate (e.g., heavy rain), the preset time period is 2 hours. When the expansion rate is slow (e.g., 500 m / h) or the disaster type risk is low (e.g., light blizzard), the preset time period is 4 hours. The prediction process employs a linear expansion model, assuming the disaster spreads uniformly to the surrounding area at the current expansion rate. If the current impact area is from K101+000 to K101+800, the expansion rate is 1000 meters per hour, and the expansion direction is bidirectional (both increasing and decreasing in mileage, such as rainstorms spreading to both sides of the track), then the predicted impact area for the next hour is from K100+500 (101000-500 meters) to K102+300 (101800+500 meters). If the expansion direction is only increasing in mileage (such as mudslides spreading downstream along the track), then the predicted impact area for the next hour is from K101+000 to K102+800 (101800+1000 meters). Simultaneously, the prediction process incorporates corrections based on the physical boundaries of the track section (such as tunnel entrances and bridge endpoints). If the predicted expansion area exceeds the track section endpoint mileage K102+300, then K102+300 is used as the prediction endpoint to avoid meaningless extrapolation.
[0049] Based on the disaster type and the distribution information of key facilities in the track section, the impact level of the disaster on the track facilities is determined. The impact level is divided into three levels: low impact, medium impact, and high impact. The determination is based on a comprehensive consideration of the degree of damage to the facility's function and the importance of the facility. For meteorological disasters, heavy rain (24-hour rainfall ≥ 50 mm) covering the track subgrade section, and where there are no protective structures such as bridges or tunnels within the section, is determined to be of medium impact. If heavy rain covers key facilities such as switches and signals, resulting in a probability of water ingress of the facilities ≥ 60%, it is determined to be of high impact. Light rain (24-hour rainfall < 10 mm) only covering non-critical sections (such as subgrade sections without facilities) is determined to be of low impact. Strong winds (wind force ≥ 8) affecting the catenary section, causing the catenary to sway by ≥ 0.5 meters, are determined to be of medium impact. If the wind force ≥ 10, it may cause the catenary to break or foreign objects to intrude, and covers a section with dense catenary supports, it is determined to be of high impact. Wind force < 6 has no significant impact on the facilities and is determined to be of low impact. For geological hazards, mudslides are classified as having a medium impact if their affected area covers the edge of the track section but does not directly impact the track. If they directly cover the track, turnouts, axle counters, and other facilities, they are classified as having a high impact. Small-scale landslides that do not intrude into the track boundary are classified as having a low impact. For track environmental hazards, track icing thickness ≥ 5mm covering braking sections (sections where train braking relies on track friction) is classified as having a medium impact. Icing thickness ≥ 10mm covering turnout sections and causing difficulties in turnout switching is classified as having a high impact. Icing thickness < 3mm covering only non-braking, non-turnout sections is classified as having a low impact.
[0050] Finally, by integrating the overlapping areas, overlap ratios, expansion trend predictions, and impact levels, the degree of disaster impact within the orbital section is calculated. The degree of disaster impact is quantified using a percentage system, with the following pre-set weights and scoring criteria for each indicator: Overlap ratio weight 30% (0% overlap = 0 points, 1%-30% = 10 points, 31%-60% = 20 points, 61%-100% = 30 points); Expansion trend prediction weight 25% (no expansion within the pre-set timeframe = 5 points, expansion increasing the overlap ratio by 1%-30% = 10 points, increasing by 31%-60% = 15 points, increasing by more than 61% or covering the entire interval = 25 points); Impact level weight 45% (low impact = 10 points, medium impact = 25 points, high impact = 45 points). The scores for each indicator are added together: a total score < 20 points indicates a low impact, 20-45 points indicates a medium impact, and > 45 points indicates a high impact. For example, in a case where the overlap ratio is 44.4% (20 points), the predicted expansion trend indicates that the overlap ratio will increase to 88.9% (an increase of 44.5%, 15 points) within the next hour, and the impact level is high (45 points), then the total score is 20 + 15 + 45 = 80 points, classifying it as a high impact. If the overlap ratio is 10% (10 points), the expansion trend shows no significant change (5 points), and the impact level is low (10 points), the total score is 25 points, classifying it as a medium impact. Through this quantitative integration, the overall impact level of a disaster on the orbital section can be accurately reflected.
[0051] Furthermore, the sub-associations for axle counting, train faults, location communication, and disaster zones are integrated to form a multi-dimensional association matrix. First, the core data outputs and association dimensions of each sub-association are clarified to ensure accurate data correspondence and logical consistency during the integration process. Specifically, the core outputs of the axle counting sub-association include the identifier of the valid fault object, the risk level of the valid fault object, and auxiliary parameters supporting this risk level (axle counting section activation status, equipment health, fault type, and fault propagation trend). The core output of the train fault sub-association is the safety warning level of the target train, with auxiliary parameters including the shortest distance between the target train and the fault zone, the safe braking distance, and the location attribution verification result. The core output of the location communication sub-association is the location mismatch risk level, with auxiliary parameters covering the communication status between the temporary speed limit server and the target train, the dynamic validity period of train location information, and the reliability of location information. The core output of the disaster zone sub-association is the degree of disaster impact on the track section, with auxiliary parameters including the overlap ratio between the disaster impact area and the track section, the disaster expansion rate, and the impact level of the disaster on track facilities.
[0052] To achieve effective data integration, the output data of each sub-association is first standardized, transforming qualitative descriptions into quantifiable values to avoid integration gaps caused by inconsistent data formats. The specific standardization rules are as follows: Risk level parameters (effective fault object risk level, safety warning level, and location mismatch risk level) are uniformly mapped to integers from 1 to 3, where low risk corresponds to 1, medium risk to 2, and high risk to 3; communication status parameters are mapped to integers from 1 to 4, where good corresponds to 1, average to 2, poor to 3, and interrupted to 4; location information reliability is mapped to integers from 1 to 3, where high reliability corresponds to 1, medium reliability to 2, and low reliability to 3; disaster impact degree is mapped to integers from 1 to 3, where low impact corresponds to 1, medium impact to 2, and high impact to 3; the activation status of the axle counting section is represented by binary values, with 1 corresponding to activation and 0 corresponding to non-activation; fault types are converted to integers according to preset coding rules (e.g., axle counter signal loss corresponds to 1, track circuit short circuit corresponds to 2, and block section boundary signal abnormality corresponds to 3); numerical parameters such as shortest distance, safe braking distance, and dynamic effective time limit retain their original units of measurement (meters, meters, and seconds, respectively) and are rounded to one decimal place; overlap ratio is rounded to one decimal place in percentage form; and disaster expansion rate is rounded to an integer in meters per hour.
[0053] Subsequently, the row and column dimensions of the multi-dimensional association matrix were defined. The row dimension of the matrix was set as a combination identifier of the target train number and the axle counting section number. This identifier can uniquely identify the operating scenario of a specific target train within a specific axle counting section, avoiding data confusion between different trains and different sections. For example, when the target train number is T001 and the axle counting section number is J03-02, the row identifier is recorded as T001-J03-02, ensuring that each row corresponds to a specific train-section scenario. The column dimension of the matrix is divided into two main categories: core indicator columns and auxiliary parameter columns. The core indicator columns directly correspond to the core output standardized values of the four sub-associations, including the effective fault object, risk level, safety warning level, location mismatch risk level, and disaster impact degree. The auxiliary parameter columns contain the standardized values of key parameters supporting the core indicators in each sub-association, specifically the axle counting section activation status, the shortest distance for fault type coding, the safe braking distance, the dynamic effective time limit of communication status, the overlap ratio of location information credibility, and the disaster expansion rate.
[0054] In the data filling stage, based on the correspondence between train and section scenarios, matching data is extracted from each sub-association and filled into the corresponding cells of the matrix. For example, for row T001-J03-02, the risk level (e.g., 2, i.e., medium risk), axle counting section activation status (1, i.e., activated), and fault type code (2, i.e., track circuit short circuit) of the valid fault object corresponding to axle counting section J03-02 are filtered from the fault counting sub-association; the safety warning level (3, i.e., high risk), shortest distance (450.0 meters), and safe braking distance (322.0 meters) of the target train T001 within axle counting section J03-02 are extracted from the train fault sub-association. ); Obtain the location mismatch risk level (2, i.e., medium risk), communication status (2, i.e., normal), dynamic effective time limit (3.6 seconds), and location information credibility (1, i.e., high credibility) in this scenario from the location communication sub-association; extract the disaster impact degree (1, i.e., low impact), overlap ratio (10.0%), and disaster expansion rate (500 m / h) of the axle section J03-02 from the disaster interval sub-association, and fill these data into the corresponding column cells one by one to form a complete data record for the row.
[0055] After data filling is completed, logical verification of the data within the matrix is performed to ensure that there are no contradictions between the data in each column, further guaranteeing the reliability of the multi-dimensional association matrix. The verification logic is based on the inherent correlation between each sub-association. For example, if the axle section activation status column is 0 (not activated), then the effective fault object risk level column should be 0 (no effective fault object). If a non-zero value appears, it is judged as a data contradiction. If the safety warning level column is 3 (high risk), then the shortest distance column value should be less than the safe braking distance column value. If the former is greater than or equal to the latter, the calculation process of the train fault sub-association is traced back. If the communication status column is 4 (interrupted), then the dynamic effective time limit column value should be significantly less than the value when the communication status is 1 (good). If no shortening trend is shown, the dynamic effective time limit adjustment logic of the position communication sub-association is checked. If the disaster impact degree column is 1 (low impact), then the overlap ratio column value should be less than 30.0%. If it exceeds this, the disaster impact degree calculation results of the disaster interval sub-association are re-evaluated.
[0056] Step 130: Determine whether the track section where the target train is located is in a preset special scenario based on the multi-dimensional correlation matrix.
[0057] The multi-dimensional correlation matrix in step 120 has integrated the core data of fault axle sub-correlation, train fault sub-correlation, location communication sub-correlation, and disaster section sub-correlation. Subsequently, based on the multi-dimensional correlation matrix, it is determined whether the track section where the target train is located meets the judgment conditions of the preset special scenario. The specific judgment logic is as follows:
[0058] When determining whether the track section where the target train is located is in a scenario of overlapping fault risks, the criteria for determining the activation status of the axle counting section are first clarified. This status information comes from the previously constructed fault axle counting sub-association, which uses binary identifiers to distinguish between activated and inactivated sections. A value of 1 represents activated, meaning that the section has normal fault monitoring and control functions. Only axle counting sections in an activated state will have their corresponding fault zones included in the subsequent judgment scope. If the axle counting section is in an inactivated state, even if a fault zone exists, the basic conditions for a scenario of overlapping fault risks are not met. Next, unconfirmed fault zones with a fault confirmation status of "fault confirmation incomplete" are selected from the valid fault objects. The fault confirmation status is determined by the feedback results of the operation and maintenance management system. When the system does not receive manual confirmation records (such as fault cause verification, temporary handling measures entry) submitted by operation and maintenance personnel for a fault zone, it is determined that manual confirmation has not been completed. These unconfirmed fault zones are key targets for attention because the scope of fault impact and potential risks are not yet clear. Next, it is verified whether the risk level of the unconfirmed fault zone is greater than the preset fault threshold. The preset fault threshold is set based on track operation safety standards and combined with the risk level classification (low risk, medium risk, high risk) in the fault axle counting sub-association. Usually, the preset fault threshold is set to medium risk, meaning that the condition is met only if the risk level of the unconfirmed fault zone reaches high risk. The determination of the high risk level is based on a comprehensive consideration of the fault type (such as track circuit short circuit is a high-risk fault type), the fault propagation trend (rapid propagation trend corresponds to high risk), and the health of the equipment in the axle counting section (health score below 60 points aggravates the risk level). Finally, it is confirmed whether the safety warning level of the target train is the preset high-risk level. This safety warning level comes from the train fault sub-association. The criterion for determining the preset high-risk level is that the shortest distance between the target train and the fault zone is less than the safe braking distance. For example, if the safe braking distance of the target train is 320 meters, and its shortest distance to the unconfirmed fault zone is 280 meters, and the location verification confirms that the train is traveling towards the fault zone, then the safety warning level is determined to be high risk. Only when all four conditions are met simultaneously—the axle counting section is activated, the valid fault objects include unconfirmed fault sections, the risk level of the unconfirmed fault sections exceeds the preset threshold, and the safety warning level is high risk—can the target train be indicated to be in a fault risk superposition scenario.
[0059] When determining the mismatch between train position and safety, the first scenario is to determine whether the target train has crossed the fault zone based on the position attribution verification result. The position attribution verification result comes from the code comparison and position prediction in the train fault sub-association. Specifically, it is achieved through real-time comparison of the block section code to which the target train belongs and the fault zone code, as well as future position prediction based on historical operating trajectories. For example, if the fault zone code is L02-Q04-B13, and the corresponding mileage range is K106+100 to K106+800, if the target train's current block zone code is reported as L02-Q04-B13 by the onboard terminal, and its real-time location mileage is K106+350 (within the fault zone mileage range), or if it is predicted through historical trajectory (based on the average speed of 60km / h in the same section over the past 24 hours, the current location is K106+000, and the predicted location in 5 minutes is K107+000, which has exceeded the fault zone's end mileage K106+800), then the location attribution verification result shows that the target train has crossed the fault zone. This indicates that the train is in a situation of mismatch between train location and safety, because the train has entered or is about to exceed the fault area, and the original safety control logic is adjusted to avoid risks.
[0060] The second scenario for determining train position and safety mismatch is based on a combination of communication link parameter evaluation results and train position update duration. The communication link parameter evaluation results are derived from the position communication sub-association. An interruption is defined as three consecutive heartbeat packets not being received, a communication bandwidth below 1 Mbps, and a transmission delay exceeding 100 ms. In this case, effective data exchange between the temporary speed limit server and the target train is impossible, and train position information cannot be uploaded in a timely manner. The train position update duration refers to the time interval from the last successful reception of train position information to the current moment. The preset duration is set in conjunction with the dynamic effective time limit in the position communication sub-association and is typically 1.5 times the dynamic effective time limit. For example, if the dynamic effective time limit is adjusted to 0.9 seconds when communication is interrupted, the preset duration is set to 1.35 seconds. If the communication link parameter evaluation result is interrupted, and the train position update duration reaches 1.4 seconds (exceeding the preset duration of 1.35 seconds), it indicates that the train's current position information is invalid, and the actual train position cannot be accurately determined. This indicates a train position and safety mismatch scenario, triggering emergency control measures.
[0061] When assessing the coverage of a disaster impact scenario, the first step is to determine the affected area, including the region in front of the fault section of the track section where the target train is currently located and the axle counting section where the target train is currently located. The region in front of the fault section is defined starting from the end mileage of the fault section and extending along the direction of travel of the target train to 1-2 adjacent block sections. For example, if the fault section mileage is from K101+000 to K101+800, and the target train is traveling in the direction of increasing mileage, then the region in front of the fault section is from K101+800 to K102+600 (the length of one block section); if the train is traveling in the direction of decreasing mileage, then the region in front is from K100+200 to K101+000. The axle counting section where the target train is currently located is determined based on the axle counting section number corresponding to the train's real-time position. For example, if the train's real-time position mileage is K101+350, and this position belongs to axle counting section J03-02, then the current axle counting section is J03-02. Whether the disaster impact area covers the aforementioned objects is determined through spatial comparison in the sub-association of disaster intervals. This involves overlaying the mileage range of the disaster impact area with the mileage range of the area in front of the fault zone and the current axle counting section. If there is an intersection, it is considered a coverage. Subsequently, it is confirmed whether the coverage status represents a disaster impact level reaching a preset disaster impact standard. The preset disaster impact standard is based on the disaster impact level classification in the sub-association of disaster intervals, typically set to medium impact or above. Medium impact is determined by an overlap ratio of 31%-60%, a disaster expansion rate of 1000-2000 meters per hour, and a medium impact level on track facilities (e.g., minor water accumulation on the roadbed due to heavy rain). High impact corresponds to an overlap ratio of over 61%, a rapid expansion rate, and a high impact level (e.g., debris flow covering the track line). When the disaster impact area covers the area in front of the fault zone or the current axle counting section, and the disaster impact level corresponding to the coverage status reaches medium impact or above, it can be indicated that the area is in a disaster impact coverage scenario.
[0062] Step 140: Stop sending redundant train permission requests for the target train to the temporary speed limit server.
[0063] When the track section where the target train is located is determined to be in a preset special scenario (any one of the following scenarios: superimposed fault risk scenario, train position and safety mismatch scenario, or disaster impact coverage scenario) based on a multi-dimensional correlation matrix, the train control center will trigger the operation to stop sending redundant train operation permits to the temporary speed limit server for that target train. The redundant train operation permit, as a train operation authorization signal under a specific scenario, has the core function of authorizing the target train to pass through a fault block section. Here, a fault block section refers to a block section where normal passage conditions are impaired due to equipment failure, disaster impact, or other factors, but the line is not completely blocked. The issuance of redundant train operation permits is premised on the premise that the risk of the fault block section is controllable and the safety of train operation can be guaranteed. Once it is determined to be in a preset special scenario, it means that the risk of the fault block section has exceeded the safety threshold, and continuing to issue redundant train operation permits would pose a safety hazard; therefore, the transmission is immediately stopped.
[0064] It is understood that, in order to achieve the functions in the above embodiments, the computer device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, based on the units and method steps described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.
[0065] Furthermore, as a response to the above Figure 1 The implementation of the method embodiment shown in this application provides a determination device for stopping the transmission of redundant driving permits. The embodiment of this device corresponds to the foregoing method embodiment. For ease of reading, this embodiment will not repeat the details of the foregoing method embodiment, but it should be understood that the device in this embodiment can implement all the contents of the foregoing method embodiment. Specifically, as shown... Figure 2 As shown, the determination device 200 for stopping redundant driving permit transmission includes:
[0066] The receiving module 210 is used to receive multi-source operation association information, which is used to indicate operation data related to faults, target trains, communications, disasters, and track sections.
[0067] The association module 220 is used to construct the association relationship between each information dimension and the target train operation safety based on multi-source operation association information, forming a multi-dimensional association matrix;
[0068] The judgment module 230 is used to determine whether the track section where the target train is located is in a preset special scenario based on a multi-dimensional correlation matrix. The preset special scenarios include at least the fault risk superposition scenario, the train position and safety mismatch scenario, and the disaster impact coverage scenario.
[0069] The instruction module 240 is used to, if so, stop sending redundant train permission to the temporary speed limit server for the target train, which is used to authorize the target train to pass through the fault block section.
[0070] Furthermore, such as Figure 2 As shown, the association module 220 is specifically used to construct fault axle sub-associations, train fault sub-associations, location communication sub-associations, and disaster section sub-associations based on multi-source operational association information. The fault axle sub-association is used to determine the effective fault objects and their risk levels. The train fault sub-association is used to determine the safety warning level of the target train. The location communication sub-association is used to determine the location mismatch risk level, which indicates the degree of deviation between the location information reported by the target train and the actual location, as well as the degree of risk posed by the deviation to train operation safety. The disaster section sub-association is used to determine the degree of impact of the disaster on the track section. The fault axle sub-association, train fault sub-association, location communication sub-association, and disaster section sub-association are integrated to form a multi-dimensional association matrix.
[0071] Furthermore, such as Figure 2 As shown, the association module 220 is specifically used to extract fault partition codes, a list of block partitions under the jurisdiction of axle counting sections, the activation status, equipment health, section function type, historical fault frequency, and fault type and fault propagation trend of axle counting sections from multi-source operation association information; match the fault partition codes with the list of block partitions under the jurisdiction of axle counting sections to determine the axle counting section corresponding to each fault partition; based on the activation status, equipment health, section function type, and historical fault frequency of axle counting sections, filter out axle counting sections that meet preset conditions, and determine the fault partitions corresponding to the axle counting sections as valid fault objects; establish a hierarchical mapping between the filtered axle counting sections and the corresponding fault partitions, and clarify the main fault partitions and associated partitions under the axle counting sections; construct a fault risk judgment model based on the relationship between the main fault partitions and associated partitions, the fault type of the fault partitions, the fault propagation trend, and the equipment health of the corresponding axle counting sections, and calculate the risk level of the valid fault objects.
[0072] Furthermore, such as Figure 2As shown, the association module 220 is specifically used to extract the real-time location, operating speed, braking performance parameters, block section code, historical operating trajectory, boundary parameters and fault section code of the target train from multi-source operational association information; determine the shortest distance between the target train and the fault section based on the real-time location of the target train and the boundary parameters of the fault section; determine the safe braking distance of the target train based on the operating speed and braking performance parameters of the target train; determine the safety warning level of the target train based on the relationship between the shortest distance and the safe braking distance; compare the block section code of the target train with the fault section code, and predict its position within a preset time period based on the historical operating trajectory of the target train to achieve position attribution verification; and adjust the safety warning level of the target train based on the position attribution verification result.
[0073] Furthermore, such as Figure 2 As shown, the association module 220 is specifically used to extract the target train's current operating speed, block section length within the axle counting section, communication link parameters between the temporary speed limit server and the target train, the target train's position update cycle, and safety warning level from multi-source operational association information; determine the dynamic validity period of the train's position information based on the target train's current operating speed, block section length, and position update cycle. The dynamic validity period indicates the time range within which the position information reported by the train accurately reflects its actual position; evaluate the communication status between the temporary speed limit server and the target train based on the communication link parameters, and adjust the dynamic validity period according to the evaluation results; compare the multi-source positioning information of the target train after fusion processing with the reported real-time position to determine the reliability of the position information; and determine the position mismatch risk level based on the target train's position update status within the dynamic validity period, the reliability of the position information, and the safety warning level.
[0074] Furthermore, such as Figure 2 As shown, the association module 220 is specifically used to extract disaster type, disaster impact range, disaster expansion rate, as well as physical range parameters and key facility distribution information of the track section from multi-source operational association information; spatially compare the disaster impact range with the physical range parameters of the track section to determine the overlapping area and overlap ratio; predict the expansion trend of the disaster impact range within a preset time period based on the disaster expansion rate; determine the impact level of the disaster on the track facilities based on the disaster type and key facility distribution information of the track section; and integrate the overlapping area, overlap ratio, expansion trend prediction results and impact level to calculate the degree of disaster impact of the track section.
[0075] Furthermore, such as Figure 2As shown, the judgment module 230 is specifically used to indicate a fault risk superposition scenario when the axle counting section is enabled, the effective fault objects include unconfirmed fault zones whose fault confirmation status is not yet manually confirmed, the risk level of the unconfirmed fault zone is greater than the preset fault threshold, and the safety warning level of the target train is the preset high-risk level; when the location attribution verification result shows that the target train has crossed the fault zone, it indicates a train position and safety mismatch scenario; when the evaluation result based on communication link parameters is interrupted, and the train position update time is greater than the preset time, it indicates a train position and safety mismatch scenario. When the disaster impact range covers the area in front of the fault zone in the track section where the target train is currently located, or covers the axle counting section where the target train is currently located, and the coverage status represents the degree of disaster impact reaching the preset disaster impact standard, it indicates a disaster impact coverage scenario.
[0076] Optionally, the device for determining whether to stop sending redundant driving permits may be an electronic device with data processing capabilities, or a functional module within that electronic device; there is no limitation on this.
[0077] For example, the electronic device can be a server, which can be a single server or a server cluster consisting of multiple servers. As another example, the electronic device can be a mobile phone, tablet computer, desktop computer, laptop computer, handheld computer, notebook computer, ultra-mobile personal computer (UMPC), netbook, as well as cellular phone, personal digital assistant (PDA), augmented reality (AR), virtual reality (VR) device, and other terminal devices. Furthermore, the electronic device can also be a recording device, video surveillance device, etc. This application does not impose any special limitations on the specific form of the electronic device.
[0078] The following example uses an electronic device as an example to determine whether redundant driving permits are stopped from being sent. Figure 3 As shown, Figure 3 The hardware structure of an electronic device 300 provided in this application.
[0079] like Figure 3 As shown, the electronic device 300 includes a processor 310, a communication line 320, and a communication interface 330.
[0080] Optionally, the electronic device 300 may also include a memory 340. The processor 310, memory 340, and communication interface 330 can be connected via a communication line 320.
[0081] The processor 310 can be a central processing unit (CPU), a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 310 can also be any other device with processing capabilities, such as a circuit, device, or software module, without limitation.
[0082] In one example, processor 310 may include one or more CPUs, for example Figure 3 CPU0 and CPU1 in the CPU.
[0083] As an optional implementation, the electronic device 300 may include multiple processors, for example, in addition to processor 310, it may also include processor 370. A communication line 320 is used to transmit information between the components included in the electronic device 300.
[0084] Communication interface 330 is used for communication with other devices or other communication networks. These other communication networks can be Ethernet, Radio Access Network (RAN), Wireless Local Area Networks (WLAN), etc. Communication interface 330 can be a module, circuit, transceiver, or any device capable of enabling communication.
[0085] The memory 340 is used to store instructions. These instructions can be computer programs.
[0086] The memory 340 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and / or instructions; it may also be a random access memory (RAM) or other type of dynamic storage device capable of storing information and / or instructions; it may also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, etc., without limitation.
[0087] It should be noted that the memory 340 can exist independently of the processor 310, or it can be integrated with the processor 310. The memory 340 can be used to store instructions, program code, or some data, etc. The memory 340 can be located inside or outside the electronic device 300, without restriction.
[0088] The processor 310 is configured to execute instructions stored in the memory 340 to implement the communication method provided in the following embodiments of this application. For example, when the electronic device 300 is a terminal or a chip in a terminal, the processor 310 can execute instructions stored in the memory 340 to implement the steps performed by the sending end in the following embodiments of this application.
[0089] As an optional implementation, the electronic device 300 also includes an output device 350 and an input device 360. The output device 350 can be a display screen, speaker, or other device capable of outputting data from the electronic device 300 to the user. The input device 360 can be a keyboard, mouse, microphone, joystick, or other device capable of inputting data into the electronic device 300.
[0090] It should be pointed out that, Figure 3 The structure shown does not constitute a limitation on the electronic device, except... Figure 3 In addition to the components shown, the electronic device may include more or fewer components than illustrated, or combine certain components, or have different component arrangements.
[0091] The determination device and application scenarios for stopping the transmission of redundant driving permits described in this application are for the purpose of more clearly illustrating the technical solutions of this application, and do not constitute a limitation on the technical solutions provided in this application. As those skilled in the art will know, with the evolution of the determination device for stopping the transmission of redundant driving permits and the emergence of new business scenarios, the technical solutions provided in this application are also applicable to similar technical problems.
[0092] This application provides a storage medium storing a program that, when executed by a processor, implements the method for determining when to stop sending redundant driving permits.
[0093] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0094] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method for determining when redundant driving permits are stopped from being sent, characterized in that, Applied to train control centers, the method includes: Receive multi-source operational correlation information, which is used to indicate operational data related to faults, target trains, communications, disasters, and track sections; Based on the multi-source operational correlation information, the correlation between each information dimension and the target train operation safety is constructed to form a multi-dimensional correlation matrix; Based on the multi-dimensional correlation matrix, it is determined whether the track section where the target train is located is in a preset special scenario. The preset special scenario includes at least a fault risk superposition scenario, a train position and safety mismatch scenario, and a disaster impact coverage scenario. If so, stop sending redundant train permission to the temporary speed limit server for the target train, which is used to authorize the target train to pass through the fault block section; Based on the aforementioned multi-source operational correlation information, a correlation matrix is constructed between each information dimension and the target train's operational safety, forming a multi-dimensional correlation matrix, including: Based on the multi-source operational association information, a fault axle association, train fault association, location communication association, and disaster section association are constructed. The fault axle association is used to determine the effective fault objects and their risk levels. The train fault association is used to determine the safety warning level of the target train. The location communication association is used to determine the location mismatch risk level, which indicates the degree of deviation between the location information reported by the target train and the actual location, as well as the degree of risk posed by the deviation to train operation safety. The disaster section association is used to determine the degree of impact of the disaster on the track section. The fault axle sub-association, the train fault sub-association, the location communication sub-association, and the disaster interval sub-association are integrated to form a multi-dimensional association matrix.
2. The method according to claim 1, characterized in that, Based on the aforementioned multi-source operational correlation information, a fault meter axle correlation is constructed, including: Extract the fault partition code, the list of block partitions under the jurisdiction of the axle counting section, the activation status, equipment health, section function type, historical fault frequency, and fault type and fault propagation trend of the fault partition from the multi-source operation association information. The fault partition code is matched with the block partition list under the jurisdiction of the axle counting section to determine the axle counting section corresponding to each fault partition; Based on the activation status, equipment health, section function type, and historical fault frequency of the axle counting section, axle counting sections that meet the preset conditions are selected, and the fault zones corresponding to the axle counting sections are determined as valid fault objects. Establish a hierarchical mapping between the filtered axle counting sections and the corresponding fault zones, and clarify the main fault zones and associated zones under the axle counting sections; Based on the relationship between the main fault partition and related partitions, the fault type of the fault partition, the fault propagation trend, and the equipment health of the corresponding axle counting section, a fault risk judgment model is constructed to calculate the risk level of the effective fault object.
3. The method according to claim 1, characterized in that, Based on the aforementioned multi-source operational correlation information, a train fault sub-correlation is constructed, including: The real-time location, speed, braking performance parameters, block section code, historical trajectory, boundary parameters and fault section code of the target train are extracted from the multi-source operational association information. Based on the real-time location of the target train and the boundary parameters of the fault zone, determine the shortest distance between the target train and the fault zone; Determine the safe braking distance of the target train based on its operating speed and braking performance parameters; The safety warning level of the target train is determined based on the relationship between the shortest distance and the safe braking distance. The location attribution is verified by comparing the block section code of the target train with the fault section code and predicting its position within a preset time period based on the historical running trajectory of the target train. The safety warning level of the target train is adjusted based on the location attribution verification results.
4. The method according to claim 1, characterized in that, Based on the multi-source operational association information, a location communication sub-association is constructed, including: Extract the target train's current operating speed, block section length within the axle counting section, communication link parameters between the temporary speed limit server and the target train, the target train's location update cycle, and safety warning level from the multi-source operation association information; Based on the target train's current operating speed, block section length, and position update cycle, the dynamic validity period of the train's position information is determined. The dynamic validity period is used to indicate the time range within which the position information reported by the train can accurately reflect its actual position. The communication status between the temporary speed limit server and the target train is evaluated based on the communication link parameters, and the dynamic effective time limit is adjusted according to the evaluation results. The multi-source positioning information of the target train is fused and compared with the reported real-time location to determine the reliability of the location information. The risk level of location mismatch is determined based on the target train's location update status within the dynamic effective time limit, the reliability of location information, and the level of safety warning.
5. The method according to claim 1, characterized in that, Based on the aforementioned multi-source operational correlation information, a disaster interval sub-correlation is constructed, including: The disaster type, disaster impact range, disaster expansion rate, physical range parameters of the track section, and key facility distribution information are extracted from the multi-source operation association information. The disaster impact range is spatially compared with the physical range parameters of the orbital section to determine the overlapping area and the overlap ratio between the two. Based on the disaster expansion rate, predict the expansion trend of the disaster's impact range within a preset time period; Based on the type of disaster and the distribution information of key facilities in the track section, the impact level of the disaster on the track facilities is determined; By integrating the overlapping areas, overlap ratios, expansion trend prediction results, and impact levels, the degree of disaster impact in the orbital section is calculated.
6. The method according to any one of claims 1-5, characterized in that, Determining whether the track section where the target train is located is within a preset special scenario based on the multi-dimensional correlation matrix includes: When the axle counting section is enabled, the valid fault objects include unconfirmed fault sections whose fault confirmation status is not completed, the risk level of the unconfirmed fault section is greater than the preset fault threshold, and the safety warning level of the target train is the preset high-risk level, it indicates that the fault risk superposition scenario is in progress. When the location attribution verification result shows that the target train has crossed the fault zone, it indicates that the train is in a mismatch between its location and safety. When the evaluation result based on the communication link parameters is interrupted, and the train position update time is longer than the preset time, it indicates that the train position and safety are in a mismatch scenario. When the disaster impact covers the area in front of the fault zone of the track section where the target train is currently located, or covers the axle counting section where the target train is currently located, and the coverage status indicates that the degree of disaster impact has reached the preset disaster impact standard, it indicates that the train is in a disaster impact coverage scenario.
7. A device for determining when redundant driving permits are stopped, characterized in that, The device includes: The receiving module is used to receive multi-source operational correlation information, which is used to indicate operational data related to faults, target trains, communications, disasters, and track sections. The association module is used to construct the association relationship between each information dimension and the target train operation safety based on the multi-source operation association information, forming a multi-dimensional association matrix; The judgment module is used to determine whether the track section where the target train is located is in a preset special scenario based on the multi-dimensional correlation matrix. The preset special scenario includes at least a fault risk superposition scenario, a train position and safety mismatch scenario, and a disaster impact coverage scenario. The instruction module is used to, if so, stop sending redundant train operation permits for the target train to the temporary speed limit server, the redundant train operation permits being used to authorize the target train to pass through the fault block section; The association module is specifically used to construct fault axle counting sub-associations, train fault sub-associations, location communication sub-associations, and disaster zone sub-associations based on the multi-source operational association information. The fault axle counting sub-association is used to determine the effective fault objects and their risk levels. The train fault sub-association is used to determine the safety warning level of the target train. The location communication sub-association is used to determine the location mismatch risk level, which indicates the degree of deviation between the location information reported by the target train and its actual location, as well as the degree of risk posed by the deviation to train operation safety. The disaster zone sub-association is used to determine the degree of impact of the disaster on the track section. The fault axle counting sub-associations, train fault sub-associations, location communication sub-associations, and disaster zone sub-associations are integrated to form a multi-dimensional association matrix.
8. A storage medium, characterized in that, The storage medium includes a stored program, wherein, when the program is executed, it controls the device where the storage medium is located to execute the determination method for stopping the transmission of redundant driving permits as described in any one of claims 1-6.
9. An electronic device, characterized in that, The device includes at least one processor, at least one memory connected to the processor, and a bus; wherein the processor and the memory communicate with each other through the bus; the processor is used to call program instructions in the memory to execute the determination method for stopping the transmission of redundant driving permits as described in any one of claims 1-6.
Citation Information
Patent Citations
Trackside global fault safety operation control method of urban mass transit
CN103895658A
Intelligent driving dispatching system and method
WO2024193091A1