A vehicle-mounted signal system of a SIL2 safety level and a control method thereof
Through the system architecture of the safety computing core, CLU3 module and input/output VDU module, a low-cost and highly adaptable SIL2 safety level on-board signaling system is realized, which solves the problem of high cost of existing SIL4 level systems. It is suitable for rail transit scenarios where drivers are the main users, and improves the economy and reliability of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CASCO SIGNAL LTD
- Filing Date
- 2025-10-31
- Publication Date
- 2026-07-24
AI Technical Summary
Existing rail transit onboard signaling systems are costly and complex at the SIL4 safety level, making them unsuitable for cost-sensitive, driver-centric rail transit scenarios. Furthermore, the SIL4 level functional overflow problem has not been effectively resolved.
The system architecture, which adopts a safety computing core, CLU3 module and input/output VDU module, achieves SIL2 safety level through dual-channel data comparison and fault diagnosis. The final safety control is performed by the external system or the driver, eliminating complex circuits and reducing costs.
It realizes a low-cost, highly adaptable SIL2 safety level on-board signaling system, which improves the system's economy and reliability, reduces the hardware failure rate, and is suitable for rail transit scenarios where drivers are the main users.
Smart Images

Figure CN121425302B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of rail transit train operation control technology, and in particular to an on-board signaling system with SIL2 safety level and its control method. Background Technology
[0002] Currently, mainstream rail transit onboard signaling systems with automatic driving functions must meet the SIL4 safety level. To meet the SIL4 requirements, complex designs are needed in terms of fault-oriented safety, including a very high degree of detection for each component, a complete fault-oriented safety design, and the need for isolation and protection. This means that more components and more complex circuit designs are required, which increases the hardware cost and complexity. The complex circuit design will increase the number of failure points and lead to an increase in hardware failure rate, reducing the reliability of the system.
[0003] For other rail transit systems operated primarily by drivers, such as trams, freight yard shunting systems, and various types of rail transit within enclosed areas, the safety functions of SIL4 level will be undertaken by the vehicle control system and the trackside interlocking system. If the SIL4 level on-board signaling system is still used, on the one hand, there will be functional performance overflow of the SIL4 system, and on the other hand, such rail transit is more sensitive to cost and requires a lower-cost system.
[0004] A search revealed Chinese patent publication CN110466564A, which discloses an LKJ logic processing unit based on a dual-CPU safety architecture. This solution achieves high-level train operation monitoring by dividing the dual CPUs into a safety core and a business core, and by comparing the consistency of input and output data between the two CPUs. However, this solution is a highly integrated and tightly coupled board-level design. Its design goal is to achieve high-level active control, which requires fault-oriented safety disconnection. This results in a complex and costly system, making it unsuitable for cost-sensitive rail transit scenarios with low to medium safety requirements where driver involvement is crucial.
[0005] Therefore, how to provide a cost-optimized and reliable SIL2-level on-board signaling system for rail transit scenarios where drivers are the main users is a technical problem that needs to be solved. Summary of the Invention
[0006] The purpose of this invention is to overcome the defects of the prior art and provide a vehicle signaling system with a SIL2 safety level and its control method.
[0007] The objective of this invention can be achieved through the following technical solutions: According to a first aspect of the present invention, a vehicle signaling system with a SIL2 safety level is provided, comprising a safety computing core, a CLU3 module, and an input / output VDU module; The secure computing core includes a CLU1 module and a CLU2 module, which are used to execute the system's security functions, perform dual-channel data comparison and internal self-test; The VDU module is connected to the secure computing core and the CLU3 module respectively, and is used to perform secure input acquisition and secure output control. When the VDU module detects an internal fault, its secure output channel enters and maintains a no-output state, and reports the fault information. The CLU3 module is physically independent of the secure computing core and is used to execute non-secure functions of the system. The security computing core performs fault diagnosis and security level classification based on its internal self-test results, dual-channel data comparison results, and fault information reported by the VDU module. Based on the classified security level, it generates corresponding external alarm information. The CLU3 module receives the external alarm information and generates an alarm signal corresponding to the safety level of the fault, which is then output to the external system or the driver for safety control of the train's operating equipment by the external system or the driver.
[0008] As a preferred technical solution, the security level includes high-security-level faults and low-security-level faults; the high-security-level faults include failure of the secure computing core self-test, inconsistency of dual-channel computing output within a preset time, and internal faults of the VDU module; the low-security-level faults include abnormal input data from a single sensor connected to the VDU module, occasional communication errors between the CLU3 module and non-secure external devices, and potential hardware performance degradation warnings identified based on periodic self-test data from the CLU1 module, CLU2 module, or VDU module.
[0009] As a preferred technical solution, the external system or driver's safety control of the train's operating equipment specifically includes: For the high-safety-level faults, the VDU module enters a no-output state and, in conjunction with the guiding alarm signal output by the CLU3 module, the external system or the driver performs safety control on the train's operating equipment. For the aforementioned low-safety-level fault, the CLU3 module outputs a downgraded operation warning alarm, and after obtaining confirmation from the external system or the driver, the safety calculation core controls the train to enter the speed-limited downgraded operation mode.
[0010] As a preferred technical solution, the VDU module detects faults in the following manner: Perform periodic self-tests on its own CPU and peripheral circuits; Real-time monitoring of the status of mutual exclusion relays in the safety output channel; The voltage or current of the input acquisition circuit is monitored to identify open circuit or short circuit faults; Verify the consistency of control commands and check words from the CLU1 and CLU2 modules.
[0011] As a preferred technical solution, the CLU3 module is also used to take over the external communication function of the faulty channel when a permanent fault is detected in a single channel of the CLU1 module or the CLU2 module, and instruct the remaining normal channels to increase the diagnostic frequency of their periodic self-tests, while the system switches to a speed-limited and downgraded operation mode.
[0012] As a preferred technical solution, the CLU1 module, CLU2 module and CLU3 module are implemented using boards with identical hardware structures.
[0013] As a preferred technical solution, the CLU1 module and the CLU2 module interact and compare data through two heterogeneous communication channels, including an RS422 serial communication channel and an Ethernet communication channel.
[0014] As a preferred technical solution, the input acquisition channel of the VDU module can be configured by software to a secure acquisition mode or a non-secure acquisition mode; when configured to secure acquisition mode, a 2oo2 architecture is used for acquisition and comparison.
[0015] As a preferred technical solution, the CLU3 module uses Joint Transmission Coding (JTC) to encode, merge, and verify the external alarm information from the CLU1 and CLU2 modules before sending it externally.
[0016] According to a second aspect of the present invention, a control method based on the vehicle-mounted signal system is provided, the method comprising: The VDU module performs a self-test and reports fault information when an internal fault is detected. By monitoring the operating status of the security computing core monitoring system, fault diagnosis and security level classification are performed based on internal self-test information, dual-channel comparison information and fault information from the VDU module, and corresponding external alarm information is generated. The CLU3 module receives external alarm information from the security computing core and generates and outputs alarm signals corresponding to the fault level accordingly. If it is a high-safety-level fault, the VDU module enters and maintains a no-output state. Combined with the alarm signal output by the CLU3 module, the external system or the driver will perform safety control on the train. If the fault is of a low safety level, the CLU3 module will output a degraded operation warning alarm. After receiving confirmation from the driver or external system, the safety computing core will control the train to enter the speed-limited degraded operation mode.
[0017] Compared with the prior art, the present invention has the following advantages: 1. This invention, through a system architecture consisting of a safety computing core, an independent CLU3 module, and an input / output VDU module, realizes fault diagnosis and safety level classification based on multi-source information, and can trigger graded safety responses corresponding to fault levels. Thus, it provides a safe and reliable SIL2 level solution for rail transit scenarios with drivers as the main body, effectively solving the problems of functional overflow and excessive cost of existing SIL4 level systems.
[0018] 2. The safety output channel of the VDU module of this invention maintains a no-output state in the event of a system failure. Through highly reliable fault detection and external alarm, the final safety control is completed by an external system or the driver, thereby eliminating the need for complex circuits to ensure timely and reliable disconnection and significantly reducing costs.
[0019] 3. The input acquisition channel of the VDU module of this invention supports flexible configuration to secure or insecure modes via software, realizing flexible adaptation to different application requirements on fixed hardware, and improving the economy and applicability of the system.
[0020] 4. This invention uses CLU boards with identical hardware structures to implement the different functions of CLU1, CLU2, and CLU3 modules, effectively reducing the hardware development, production, and maintenance costs of the system.
[0021] 5. This invention constructs a combined fault safety mechanism by cross-comparing data from the dual channels of the CLU1 and CLU2 modules and performing full-cycle self-testing, combined with the dual-channel verification and rapid fault response of the VDU module. It also supports fault classification processing, effectively reducing hardware failure rate and improving system reliability and operational continuity. Attached Figure Description
[0022] Figure 1 This is a diagram of the core architecture of the system of the present invention; Figure 2 This is a schematic diagram of the rear interface of the system of the present invention; Figure 3 This is the output architecture of the VDU module of the present invention; Figure 4 This is the input architecture of the VDU module of the present invention; in, Figure 1In this context, "Antenna" refers to the antenna, "Antenna Cable" refers to the antenna cable, "Ethernet" refers to the Ethernet interface, "RS422," "RS232," and "RS485" are all serial communication interface standards, "CAN1" and "CAN2" are controller area network bus interfaces, "SIL2PF_BP" is a backplane that meets SIL2 safety requirements, "BTM" is the transponder transmission module, and "Odometer" is the odometer. Detailed Implementation
[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0024] Example 1: This embodiment provides a vehicle signaling system with a SIL2 safety level. Instead of emphasizing absolute safety cut-off capability, it ensures safety through the overall system architecture. When the system detects an internal fault, it reliably outputs an alarm signal, allowing for final safety intervention by an external system or the driver.
[0025] like Figure 1 As shown, the system consists of the following modules, which are electrically connected and communicate via a backplane SIL2PF_BP. All modules are integrated within the product's chassis, and the layout meets the isolation and insulation requirements of the EN50129 standard: The core logic unit consists of three identical CLU boards: CLU1, CLU2, and CLU3. Each board is equipped with a 400MHz CPU, 128MB of memory, and interfaces including one RS422 port, four RS232 ports, three RS485 ports, two 10 / 100Mbps Ethernet ports. It also integrates a watchdog timer, a safety clock, a speed measurement circuit (for receiving odometer signals), a temperature sensor, and a DATAPLUG interface.
[0026] Input / output VDU module: adopts a dual-channel, dual-microcontroller structure, providing 2 safe outputs, 5 safe inputs (or 10 unsafe inputs), 6 unsafe outputs, 6 TTL acquisition interfaces and 4 CAN ports.
[0027] Backplane SIL2PF_BP: All modules are plugged into this backplane, which provides all electrical connections and communication routing between modules and meets the insulation requirements of EN50129.
[0028] GPS substrate: A commercial Beidou positioning and communication module is installed on this substrate, and a GPS antenna is connected to it through the TNC interface on the board.
[0029] like Figure 2 As shown, all formal interfaces of the system, except for the front panel debugging interface, are designed to be routed to the rear and are concentrated on the rear panel. These include power interfaces, various network and serial communication interfaces (such as NET1, NET2, 422 / 485, 232), input / output interfaces (such as TTL, V_O, F_I / O), and odometer interfaces (ODO1, ODO2), etc. The interface type descriptions are shown in Table 1.
[0030] Table 1 Implementation of module functions and security architecture: CLU1 and CLU2 modules: CLU1 and CLU2 modules constitute the system's 2oo2 dual-channel safety core. Both run identical software, exchanging data only for clock synchronization and data comparison. All messages comply with the safety protocol requirements for closed systems in EN50159. They are responsible for safety function calculations, including acquiring input information from the VDU and odometer, performing logical processing, and generating safety commands. CLU1 and CLU2 acquire input information from the VDU and odometer respectively, interacting and comparing data through two heterogeneous communication channels (RS422 and Ethernet). Only data that matches is used for subsequent safety calculations. Before sending a command to the VDU, CLU1 and CLU2 calculate the CRC checksum of the command and compare it interactively; only if the CRC matches is output allowed. Based on their internal self-test results, dual-channel data comparison results, and fault information reported by the VDU module, CLU1 and CLU2 perform fault diagnosis and safety level classification, generating corresponding safety control commands and external alarm information accordingly.
[0031] CLU3 module: The CLU3 module is physically independent of CLU1 and CLU2, responsible for handling all non-safety logic. As the system's unified communication interface, it communicates with external devices via its RS232, RS422, RS485, and network interfaces. It communicates with the GPS substrate via RS232 to obtain location information. External alarm messages from CLU1 and CLU2 are sent to CLU3. CLU3 uses the JTC principle to encode and merge these messages before sending them out, ensuring the security and integrity of the communication process. The CLU3 module receives external alarm messages from the safety computing core and generates guiding alarm signals corresponding to the fault level. For example, it outputs an emergency braking alarm for high-safety-level faults and a degraded operation prompt for low-safety-level faults, indicating speed limitation.
[0032] VDU module: The VDU module is the interface between the system and the train's actuators and sensors. The output architecture of the VDU is as follows: Figure 3 As shown, the VDU adopts a combined fail-safe output architecture compliant with 2oo2. The two channels can independently receive commands and verification words from the CLU. Only when all checks pass will the output be controlled; otherwise, it will be directed to the safe side. The status of the two CPUs is checked by a dynamic circuit. A failure of any CPU will cause the board to enter a safe state. The output device uses a mutex relay conforming to EN50205. The two CPUs can reliably detect the status of the output circuit in real time. This is also different from the SIL4 level system. The VDU cannot actively shut down the output but detects faults and abnormal states and notifies the lower-level system through alarms. This saves a lot of development and cost for ensuring safe shutdown of the output.
[0033] The input architecture of the VDU module is as follows: Figure 4 As shown, the VDU can achieve 5 channels of safe acquisition that meet SIL2 requirements or 10 channels of non-safe acquisition. All acquisitions are compatible with both 24VDC and 110VDC input voltages. All acquisition loops can be configured for safe or non-safe acquisition. When configured for safe acquisition mode, two independent acquisition circuits form a 2oo2 architecture. The two independent circuits acquire the same signal. The data is compared for consistency within the system before it is used as a valid safe input value. If the acquisition circuit detects a fault during self-test, the acquired value will be set to the safe side value.
[0034] Security mechanisms: Power-on self-test: After the system is powered on, CLU1 and CLU2 will perform integrity checks on their own FLASH, CPU (registers and instruction set), RAM, program segments, and data segments; VDU will check its CPU and peripheral circuits. If any module fails the self-test, the system cannot start and will directly enter safe mode. Online periodic self-test: During system operation, CLU1 and CLU2 will periodically perform self-tests on the CPU and RAM, and compare the consistency of data in the dual-channel secure memory area; VDU will also periodically perform self-tests on its hardware.
[0035] This invention discloses a vehicle-mounted signaling system with a SIL2 safety level. It adopts a 2oo2 architecture consisting of a dual-channel safety core (CLU1 / CLU2), an independent CLU3 module, a VDU module, a GPS baseboard, and a backplane. Through dual-channel data verification and fault diagnosis and graded response mechanisms, it is adapted to rail transit scenarios where the driver is the main operator. It does not rely on absolute safety cut-off capability, but achieves dynamic safety control through collaboration with external systems or the driver, thus realizing a low-cost and highly adaptable signaling solution.
[0036] Example 2: This invention provides a control method for an on-board signaling system based on SIL2 safety level, the method comprising: The VDU module performs a self-test and reports fault information when an internal fault is detected. By monitoring the operating status of the security computing core monitoring system, fault diagnosis and security level classification are performed based on internal self-test information, dual-channel comparison information and fault information from the VDU module, and corresponding external alarm information is generated. The CLU3 module receives external alarm information from the security computing core and generates and outputs alarm signals corresponding to the fault level accordingly. If it is a high-safety-level fault, the VDU module will enter a no-output state, and in conjunction with the alarm signal output by the CLU3 module, the external system or the driver will perform safety control on the train. If the fault is of a low safety level, the CLU3 module will output a degraded operation warning alarm. After receiving confirmation from the driver or external system, the safety computing core will control the train to enter the speed-limited degraded operation mode.
[0037] The control method provided by this invention combines a fault classification mechanism with external intervention, which satisfies the SIL2 safety level while taking into account system cost and functional adaptability, and effectively solves the signal control needs of rail transit scenarios where the driver is the main operator.
[0038] Taking the system's monitoring of train speeding as an example, the method of the present invention will be explained in detail: The CLU1 and CLU2 modules obtain speed data from the VDU module and the odometer, respectively, and perform cross-comparison to confirm the validity of the data; Based on consistent speed data, the two channels independently perform safety calculations. After diagnosis, the current fault is classified as a high-safety-level fault, and both conclude that an alarm is required and the vehicle should be slowed down. The system generates security commands through dual channels and exchanges CRC checksums to confirm consistency. Safety commands are sent to the VDU module. After the dual-channel verification commands of the VDU module are consistent, the output circuit is driven, such as illuminating the warning light in the cab. At the same time, the CLU3 sends the alarm information to the vehicle control system or displays it directly to the driver. If, during the above process, the speed data of CLU1 and CLU2 are inconsistent, or the VDU self-test detects an internal fault, then: If the VDU module's safety output channel cannot obtain a valid drive command or malfunctions, it will maintain a no-output safety state, causing the warning light to either not illuminate (if it was not illuminated before) or to immediately turn off (if it was illuminated before). The CLU3 module will immediately send a system fault alarm signal to the driver or vehicle control system; Ultimately, safety control is achieved by the driver or vehicle control system based on alarm information. If the system diagnoses a low-safety-level fault, such as an intermittent error in communication with a single sensor, the CLU3 module outputs a system downgrade message to the driver, suggesting speed-limited operation. After the driver confirms, the system will continue to operate in speed-limited mode.
[0039] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A vehicle-mounted signaling system with SIL2 safety level, characterized in that, This includes a secure computing core, a CLU3 module, and input / output VDU modules; The secure computing core includes a CLU1 module and a CLU2 module, which are used to execute the system's security functions, perform dual-channel data comparison and internal self-test; The VDU module is connected to the secure computing core and the CLU3 module respectively, and is used to perform secure input acquisition and secure output control. When the VDU module detects an internal fault, its secure output channel enters and maintains a no-output state, and reports the fault information. The CLU3 module is physically independent of the secure computing core and is used to execute non-secure functions of the system. The CLU1, CLU2, and CLU3 modules are implemented using boards with identical hardware structures. The security computing core performs fault diagnosis and security level classification based on its internal self-test results, dual-channel data comparison results, and fault information reported by the VDU module. Based on the classified security level, it generates corresponding external alarm information. The security level includes high-security-level faults and low-security-level faults. High-security-level faults include failure of the secure computing core self-test, inconsistency of dual-channel computing output within a preset time, and internal faults of the VDU module. Low-security-level faults include abnormal input data from a single sensor connected to the VDU module, occasional communication errors between the CLU3 module and non-secure external devices, and potential hardware performance degradation warnings identified based on periodic self-test data from the CLU1 module, CLU2 module, or VDU module. The CLU3 module receives the external alarm information and generates an alarm signal corresponding to the safety level of the fault, which is then output to the external system or the driver. The external system or the driver then performs safety control on the train's actuators. The safety control specifically includes: For the high-safety-level faults, the VDU module enters a no-output state and, in conjunction with the guiding alarm signal output by the CLU3 module, the external system or the driver performs safety control on the train's operating equipment. For the aforementioned low-safety-level fault, the CLU3 module outputs a downgraded operation warning alarm, and after obtaining confirmation from the external system or the driver, the safety calculation core controls the train to enter the speed-limited downgraded operation mode.
2. The vehicle-mounted signaling system with SIL2 safety level according to claim 1, characterized in that, The VDU module detects faults in the following ways: Perform periodic self-tests on its own CPU and peripheral circuits; Real-time monitoring of the status of mutual exclusion relays in the safety output channel; The voltage or current of the input acquisition circuit is monitored to identify open circuit or short circuit faults; Verify the consistency of control commands and check words from the CLU1 and CLU2 modules.
3. A vehicle-mounted signaling system with SIL2 safety level according to claim 1, characterized in that, When a single channel in the CLU1 or CLU2 module experiences a permanent failure, the system switches to a speed-limited and downgraded operation mode.
4. A vehicle-mounted signaling system with SIL2 safety level according to claim 1, characterized in that, The CLU1 module and the CLU2 module exchange and compare data through two heterogeneous communication channels, including an RS422 serial communication channel and an Ethernet communication channel.
5. A vehicle-mounted signaling system with SIL2 safety level according to claim 1, characterized in that, The input acquisition channel of the VDU module can be configured by software to a secure acquisition mode or a non-secure acquisition mode; when configured to secure acquisition mode, a 2oo2 architecture is used for acquisition and comparison.
6. A vehicle-mounted signaling system with SIL2 safety level according to claim 1, characterized in that, The CLU3 module uses Joint Transmission Coding (JTC) to encode, merge, and verify the external alarm information from the CLU1 and CLU2 modules before sending it out.
7. A control method based on any one of the vehicle signaling systems described in claims 1-6, characterized in that, The method includes: The VDU module performs a self-test and reports fault information when an internal fault is detected. By monitoring the operating status of the security computing core monitoring system, fault diagnosis and security level classification are performed based on internal self-test information, dual-channel comparison information and fault information from the VDU module, and corresponding external alarm information is generated. The CLU3 module receives external alarm information from the security computing core and generates and outputs alarm signals corresponding to the fault level accordingly. If it is a high-safety-level fault, the VDU module enters and maintains a no-output state. Combined with the alarm signal output by the CLU3 module, the external system or the driver can perform safety control on the train. If the fault is of a low safety level, the CLU3 module will output a degraded operation warning alarm. After receiving confirmation from the driver or external system, the safety computing core will control the train to enter the speed-limited degraded operation mode.