Safety interlocking control method, system and device of rail transit system and storage medium

By switching control permissions in the rail transit system through a safety interlocking operation device and combining it with anti-misoperation verification, the safety risks in the event of a main control system failure are resolved, and safe and reliable permission switching and operation control are achieved, thereby improving the system's safety and maintenance efficiency.

CN121573036APending Publication Date: 2026-02-27ZHUHAI UNITECH POWER TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511651172.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-12
Publication Date
2026-02-27

AI Technical Summary

Technical Problem

In rail transit systems, the lack of an effective access control mechanism when the main control system fails leads to increased personal safety risks and low maintenance efficiency.

Method used

Access control and operation management are achieved through a safety interlocking device. The first and second authorization verification units switch control permissions when the main control system fails, including direct control and indirect control. Combined with a false alarm verification mechanism, the safety and reliability of operation are ensured.

Benefits of technology

It effectively prevents misoperation and unauthorized operation, ensures the safety of operators and equipment, and improves the safe operation and maintenance efficiency of the rail transit system under fault conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121573036A_ABST
    Figure CN121573036A_ABST
Patent Text Reader

Abstract

The invention relates to a safety interlocking control method, system and device for a rail transit system and a storage medium, and the method comprises the steps: obtaining a working state of a main control device, and generating a corresponding working state signal according to the working state; when the working state signal indicates that the main control device is in the fault state, the control authority of the safety interlocking operation device to the target equipment is confirmed; whether a first authorization verification unit of the safety interlocking operation device is in an unlocking state or not is judged, and if the first authorization verification unit is in the unlocking state, a first operation instruction is sent to target equipment; if the first authorization verification unit is not in the unlocking state, whether a second authorization verification unit of the safety interlocking operation device is in the unlocking state or not is judged, and if the second authorization verification unit is in the unlocking state, a first authorization instruction is sent to the field control equipment. According to the application, safe and reliable permission switching and operation control can be realized when the main control system fails, and misoperation and unauthorized operation are effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of rail transit control, and in particular to a safety interlocking control method, system and device for a rail transit system, and a storage medium. BACKGROUND

[0002] At present, urban rail transit has generally adopted an automatic grounding maintenance system, which replaces the traditional manual grounding wire connection mode by using an isolation knife switch device and a visual DC voltage detection grounding device. In the automatic grounding process, a system workstation as a control core is responsible for executing complex logic locking functions, effectively ensuring the safety of operating personnel in a high-voltage environment.

[0003] However, when the system workstation has a program error or hardware failure, on-site personnel are still required to perform local operations, and there is a lack of effective permission control mechanism for emergency operations of the system workstation in a fault state, which increases the risk of personal safety. SUMMARY

[0004] To solve or partially solve the problems in the related art, the present application provides a safety interlocking control method, system, device and storage medium for a rail transit system, which can realize safe and reliable permission switching and operation control when the main control system fails, effectively prevent misoperation and unauthorized operation, ensure the safety of operating personnel and equipment, and improve the safety operation and maintenance efficiency of the rail transit system in a fault state.

[0005] The first aspect of the present application provides a safety interlocking control method for a rail transit system, which is applied to a rail transit control system including a main control device and a safety interlocking operation device. The method comprises: acquiring a working state of the main control device, and generating a corresponding working state signal according to the working state; when the working state signal indicates that the main control device is in a fault state, confirming the control permission of the safety interlocking operation device to the target device; judging whether a first authorization verification unit of the safety interlocking operation device is in an unlocked state, and if the first authorization verification unit is in the unlocked state, sending a first operation instruction to the target device, the first operation instruction being used to control the working state of the target device; if the first authorization verification unit is not in the unlocked state, judging whether a second authorization verification unit of the safety interlocking operation device is in the unlocked state, and if the second authorization verification unit is in the unlocked state, sending a first authorization instruction to a field control device, the first authorization instruction being used to instruct the field control device to control the target device.

[0006] In a possible implementation manner of the first aspect, the method further includes: obtaining a working state signal of the main control system, the working state signal including at least a normal working signal and a fault signal; determining whether the first authorization verification unit or the second authorization verification unit of the safety interlocking operation device is in an unlocked state when the working state signal is the fault signal; confirming the control right of the safety interlocking operation device over the target device when the first authorization verification unit or the second authorization verification unit is in the unlocked state; receiving a first generation instruction when the working state signal is the normal working signal, the first generation instruction being used to indicate whether the main control system generates a second authorization instruction; controlling the main control system to generate the second authorization instruction and send the second authorization instruction to the field control device if the first generation instruction indicates that the main control system generates the second authorization instruction, where the second authorization instruction is used to instruct the field control device to control the target device.

[0007] In a possible implementation manner of the first aspect, after the main control system is controlled to generate the second authorization instruction and send the second authorization instruction to the field control device, the method further includes: receiving a second operation instruction sent by the field control device, where the second operation instruction is used to instruct the field control device to control the working state of the target device; and controlling the main control system to send a first right confirmation instruction based on the second operation instruction, where the first right confirmation instruction is used to indicate whether to confirm the operation right of the second operation instruction.

[0008] In a possible implementation manner of the first aspect, if the first authorization verification unit is in the unlocked state, the first operation instruction is sent to the target device, and the method further includes: receiving a first touch instruction for the safety interlocking operation device if the first authorization verification unit is in the unlocked state; generating the first operation instruction according to the first touch instruction; performing an anti-misoperation check on the first operation instruction to determine whether the first operation instruction meets a preset safety condition; sending the first operation instruction to the target device if the first operation instruction passes the anti-misoperation check, where the first operation instruction is used to control the target device to close or open; and not sending the first operation instruction to the target device if the first operation instruction does not pass the anti-misoperation check.

[0009] With reference to the first aspect, in a possible implementation manner of the first aspect, the method further includes: if the target operation instruction fails the anti-misoperation check or state feedback information of the target device is not received within a preset time, determining whether the second authorization verification unit is in an unlocked state; if the second authorization verification unit is in the unlocked state, receiving a second touch instruction for the safety interlocking operation device; displaying real-time state of the target device on a separate state display area of the safety interlocking operation device based on the second touch instruction; and generating alarm information corresponding to the target device according to the real-time state of the target device.

[0010] With reference to the first aspect, in a possible implementation manner of the first aspect, if the first authorization verification unit is not in the unlocked state, determining whether a second authorization verification unit of the safety interlocking operation device is in the unlocked state, and if the second authorization verification unit is in the unlocked state, sending a first authorization instruction to the field control device includes: receiving a third operation instruction sent by the field control device; performing an anti-misoperation check on the third operation instruction to determine whether the third operation instruction meets a preset safety condition; if the third operation instruction passes the anti-misoperation check, receiving a third touch instruction for the safety interlocking operation device; and generating the first authorization instruction based on the third touch instruction and sending the first authorization instruction to the field control device.

[0011] With reference to the first aspect, in a possible implementation manner of the first aspect, the method further includes: obtaining state information associated with the target device, where the state information at least includes split-closing state information of an associated isolating switch of the target device located in the same track, train occupation state information of the track, and live-line detection state information of a catenary corresponding to the track; when the operation instruction indicates to control a grounding cabinet to close, determining whether the state information meets a preset safety condition; where the preset safety condition includes that the isolating switch is in the split state, the track is not occupied by a train, and the catenary is in the no-live state; and if the preset safety condition is met, controlling the grounding cabinet to close based on the operation instruction.

[0012] The second aspect of the application provides a safety interlocking control system of a rail transit system, comprising a server, a main control device, a safety interlocking operation device, a target device and a field control device; the server acquires a working state of the main control device and generates a corresponding working state signal according to the working state; when the working state signal indicates that the main control device is in a fault state, the server confirms a control authority of the safety interlocking operation device on the target device; the server judges whether a first authorization verification unit of the safety interlocking operation device is in an unlocked state, if the first authorization verification unit is in the unlocked state, the safety interlocking operation device sends a first operation instruction to the target device, and the first operation instruction is used to control a working state of the target device; if the first authorization verification unit is not in the unlocked state, the server judges whether a second authorization verification unit of the safety interlocking operation device is in the unlocked state, if the second authorization verification unit is in the unlocked state, the safety interlocking operation device sends a first authorization instruction to the field control device, and the first authorization instruction is used to instruct the field control device to control the target device.

[0013] The third aspect of the application provides a safety interlocking operation device, comprising a first control area, a second control area, the first control area comprising a knife switch control panel and a first authorization verification unit, the knife switch control panel being used to control a target device through the knife switch control panel when the first authorization verification unit is unlocked, and the knife switch control panel being further used to display state information of the target device; the second control area comprising a second authorization verification unit, a track state display panel, a track selection panel and an authorization instruction generation panel, the track display panel being used to display state information of a track, the track selection panel being used to select a track corresponding to the target device, and the authorization instruction generation panel being used to generate a preset authorization instruction.

[0014] The fourth aspect of the application provides a computer readable storage medium, which stores executable codes, when the executable codes are executed by a processor of an electronic device, the processor executes the method as described above.

[0015] The technical scheme provided by the application can have the following beneficial effects: The safety interlocking control method, system, device and storage medium of the rail transit system of the present application are applied to a rail transit control system comprising a main control device and a safety interlocking operation device. The method comprises: obtaining the working state of the main control device and generating a corresponding working state signal according to the working state; when the working state signal indicates that the main control device is in a fault state, confirming the control authority of the safety interlocking operation device on the target equipment; judging whether the first authorization verification unit of the safety interlocking operation device is in an unlocked state, and if the first authorization verification unit is in the unlocked state, sending a first operation instruction to the target equipment, the first operation instruction being used to control the working state of the target equipment; if the first authorization verification unit is not in the unlocked state, judging whether the second authorization verification unit of the safety interlocking operation device is in the unlocked state, and if the second authorization verification unit is in the unlocked state, sending a first authorization instruction to the field control equipment, the first authorization instruction being used to instruct the field control equipment to control the target equipment. The safety interlocking control method, system, device and storage medium of the rail transit system of the present application can realize safe and reliable authority switching and operation control when the main control system fails, effectively prevent misoperation and unauthorized operation, protect the safety of the operating personnel and equipment, and improve the safety operation and maintenance efficiency of the rail transit system in the fault state.

[0016] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory and are not restrictive of the application. BRIEF DESCRIPTION OF DRAWINGS

[0017] The above and other objects, features and advantages of the present application will become more apparent from the following detailed description when taken in conjunction with the accompanying drawings in which like reference characters refer to like parts throughout and in which:

[0018] Figure 1 is a flowchart of the safety interlocking control method of the rail transit system shown in the embodiments of the present application; Figure 2 is a structural diagram of the safety interlocking control system of the rail transit system shown in the embodiments of the present application; Figure 3 is a structural diagram of the safety interlocking control device shown in the embodiments of the present application; Figure 4 is a specific structural diagram of the safety interlocking control system of the rail transit system shown in the embodiments of the present application; Figure 5 is a structural diagram of the internal communication connection of the safety interlocking control device shown in the embodiments of the present application; Figure 6 is a structural diagram of the input of the measurement and control device of the safety interlocking control device shown in the embodiments of the present application; Figure 7Fig. 1 is a structural schematic diagram of a measurement and control device of a safety interlocking control device shown in an embodiment of the present application. DETAILED DESCRIPTION

[0019] Embodiments of the present application will be described in more detail with reference to the drawings. Although embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided so that the present application is more thorough and complete, and to fully convey the scope of the present application to those skilled in the art.

[0020] The terms used in the present application are merely for the purpose of describing specific embodiments and are not intended to limit the present application. The singular forms "a", "an" and "the" used in the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.

[0021] It should be understood that although the terms "first", "second", "third", etc. can be used in the present application to describe various information, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, the first information can also be referred to as the second information, and similarly, the second information can also be referred to as the first information without departing from the scope of the present application. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present application, the meaning of "a plurality of" is two or more, unless otherwise specifically limited.

[0022] In the related art, in the conventional existing rail transit automated grounding maintenance system, the system workstation as the core control center realizes remote control of the device through programmed logic, but when the software of the system workstation abnormally or the hardware of the system workstation fails, the control instruction transmission link is interrupted, so that the background cannot obtain the real-time state of the device or issue operation instructions. At this time, the on-site operation of the operator is generally required, but this is easy to endanger the safety of the on-site operator and affects the reliability of the rail transit power supply system and the efficiency of the maintenance operation.

[0023] In view of the above problems, the embodiments of the present application provide a safety interlocking control method, system and device of a rail transit system and a storage medium, which can realize safe and reliable permission switching and operation control when the main control system fails, effectively prevent misoperation and unauthorized operation, protect the safety of the operator and the device, and improve the safety operation and maintenance efficiency of the rail transit system in the fault state.

[0024] The technical solutions of the embodiments of the present application will be described in detail below with reference to the drawings.

[0025] Figure 1 is a flowchart of a safety interlocking control of a rail transit system.

[0026] Referring to Figure 1 , Figures 4-7 A safety interlocking control method of a rail transit system is applied to a rail transit control system comprising a main control device and a safety interlocking operation device, and the method comprises the following steps. S110: obtaining the working state of the main control device and generating a corresponding working state signal according to the working state.

[0027] Specifically, the rail transit system can comprise a DCC layer and a field device layer, the DCC layer can comprise a main control device such as a system workstation, a server screen cabinet and a safety interlocking operation device such as a safety interlocking operation console, and the field device layer can comprise a convergence switch and a target control device such as a station-level operation terminal. The main control device is used to control the field device in a normal working state, and the safety interlocking operation device is used to provide backup control when the main control system fails. The working state of the main control device can be obtained in real time, and the working state of the main control device can represent the running condition of the main control device in the rail transit control system, including two states of normal operation and failure. The working state signal can correspond to the normal operation working state and the failure state respectively.

[0028] In a possible implementation, the method further comprises: obtaining a working state signal of the main control system, the working state signal comprising at least a normal working signal and a failure signal; when the working state signal is the failure signal, determining whether the first authorization verification unit or the second authorization verification unit of the safety interlocking operation device is in an unlocked state; when the first authorization verification unit or the second authorization verification unit is in the unlocked state, confirming the control right of the safety interlocking operation device to the target device; when the working state signal is the normal working signal, receiving a first generation instruction, the first generation instruction being used to indicate whether the main control system generates a second authorization instruction; if the first generation instruction indicates that the main control generates the second authorization instruction, controlling the main control system to generate the second authorization instruction and sending the second authorization instruction to the field control device; wherein the second authorization instruction is used to indicate that the field control device controls the target device.

[0029] Specifically, the first authorization verification unit is a hardware device for verifying whether the operator has the right to directly control the target device, and the second authorization verification unit is a hardware device for verifying whether the operator has the right to indirectly control the target device through the field control device. The authorization verification unit can be a mechanical key switch, an electronic lock, a face recognition device, etc. When the authorization verification unit is a mechanical key switch, the operator can operate by inserting the key into the switch to make the authorization verification unit in the unlocked state. At this time, the relay in the safety interlock operating device is closed, the control loop of the safety interlock operating device is powered on, and the safety interlock operating device can have control authority. When the working state signal is a fault signal, it can be judged whether the first authorization verification unit or the second authorization verification unit is in the unlocked state at this time. When the authorization verification unit is in the unlocked state, it can be confirmed that the safety interlock operating device has direct control authority or indirect control authority over the target device. When the working state signal is a normal working signal, the main control system can send a first generated instruction. The main control system determines whether a second authorization instruction needs to be generated according to the first generated instruction. When the first generated instruction indicates that the operation of the field control device is allowed, the main control system generates a second authorization instruction and sends it to the field control device. After the field control device receives the second authorization instruction, it can operate and control the target device, that is, the main control system can delegate the operation authority to the field control device through the second authorization instruction, which can improve the flexibility of operation and avoid the risk of multi-source control.

[0030] For example, the authorization verification unit includes a key switch, and the key switch is connected in series with the incoming power circuit of the measurement and control device of the safety interlock operating device. When the key switch is in the "locked" position, the incoming power circuit of the measurement and control device is disconnected, and the authorization verification unit is in the locked state. When the key switch is rotated to the "release" position, the incoming power circuit of the measurement and control device is connected, and the authorization verification unit is in the unlocked state. When the measurement and control device receives a working state signal indicating that the main control device is in a fault state, and detects that the key switch is in the "release" position, it is confirmed that the safety interlock operating device has control authority over the target device. Therefore, the safety interlock operating device can receive the button signal of the operation panel and control the target device according to the button signal. Through the double protection of the working state signal and the authorization verification unit, the occurrence of misoperation is avoided, and the reliability and safety are effectively improved.

[0031] In a possible implementation, after the control main control system generates the second authorization instruction and sends it to the field control device, the method further includes: receiving a second operation instruction sent by the field control device; the second operation instruction is used to instruct the field control device to control the working state of the target device; based on the second operation instruction, the control main control system sends a first authority confirmation instruction; the first authority confirmation instruction is used to indicate whether to confirm the operation authority of the second operation instruction.

[0032] Specifically, after the control authority is delegated to the field control device, if the field control device needs to control the target device, the main control system still needs to determine whether the control can be performed. The second operation instruction is an operation request signal generated by the field control device and sent to the main control system. The main control system can receive the second operation instruction sent by the field control device in real time. After the main control system receives the corresponding second operation instruction, the operator can determine whether to allow the field control device to operate and control the working state of the target device according to the actual situation. If allowed, the control main control system sends a first authority confirmation instruction. After the field control device receives the first authority confirmation instruction, the field control device can perform specific control operation on the target device according to the second operation instruction. The main control system can determine before each operation execution and perform secondary verification on the operation authority, preventing security risks caused by misoperation or unauthorized operation, and further improving the reliability and safety of the entire control process.

[0033] For example, after the main control system sends the second authorization instruction to the field control device, if the field control device needs to control the target device to perform grounding closing operation, the field control device sends a second operation instruction to the main control system. After the main control system receives the instruction, the main control system generates a first authority confirmation instruction and sends it to the field control device. The field control device determines whether to perform grounding closing operation according to the confirmation result. If the confirmation result is allowed, the field control device performs grounding closing operation on the target device.

[0034] S120: When the working state signal indicates that the main control device is in a fault state, confirming the control authority of the safety interlocking operation device on the target device.

[0035] Specifically, when the working state signal indicates that the main control device is in a fault state, the safety interlocking operation device needs to be used for backup control. At this time, the control authority of the safety interlocking control device on the target device is started. The target device can be a device in the work site, such as an isolation switch, a grounding cabinet, etc. The control authority of the safety interlocking operation device can be used to directly control the target device or generate an instruction to authorize the control of the target device.

[0036] S130: determining whether the first authorization verification unit of the safety interlocking operation device is in an unlocked state, and if the first authorization verification unit is in the unlocked state, sending a first operation instruction to the target device, the first operation instruction being used to control the working state of the target device.

[0037] Specifically, the first operation instruction is a remote control instruction for the target device. When the first authorization verification unit is in the unlocked state, it indicates that the control right of the target device is transferred from the main control device to the safety interlocking operation device. Then, the staff can generate the first operation instruction through the safety interlocking operation device, and send the first operation instruction to the target device through the server. After receiving the first operation instruction, the target device can perform relevant operations according to the content of the first operation instruction, such as closing operation.

[0038] In a possible implementation, if the first authorization verification unit is in the unlocked state, a first touch instruction for the safety interlocking operation device is received; a first operation instruction is generated according to the first touch instruction; the first operation instruction is subjected to an anti-misoperation check to determine whether the first operation instruction meets a preset safety condition; if the first operation instruction passes the anti-misoperation check, the first operation instruction is sent to the target device; the first operation instruction is used to control the target device to close or open; and if the first operation instruction does not pass the anti-misoperation check, the first operation instruction is not sent to the target device.

[0039] Specifically, when the first authorization verification unit is in the unlocked state, the staff can generate the first touch instruction by touching the safety interlocking operation device. The first touch instruction can be a control request signal input by the user through an operation interface, such as touch screen clicking, physical button pressing, etc. The safety interlocking control device generates a corresponding first operation instruction according to the first touch instruction, and then subjects the first operation instruction to an anti-misoperation check. The anti-misoperation check is a process of verifying the safety of the operation instruction, which can prevent dangerous operations on the target device when the safety condition is not met. The preset safety condition is a safety condition that must be met by the device operation, which can include device state parameters, environmental monitoring data or system running conditions, etc., to ensure that the operation corresponding to the target operation instruction is safe. If the first operation instruction passes the anti-misoperation check, the first operation instruction can be sent to the target device. If the first operation instruction does not pass the anti-misoperation check, it indicates that the operation corresponding to the first operation instruction is dangerous, and the first operation instruction is not sent to the target device.

[0040] Exemplarily, when the first authorization verification unit of the safety interlocking operation device adopts a physical key switch and is in an unlocked position, an operator inputs a first touch instruction through a touch screen; the system generates a first operation instruction according to the touch instruction, and performs an anti-misoperation check on the first operation instruction, if the control operations corresponding to the first operation instruction all satisfy preset safety conditions, the first operation instruction is sent to a target device to control the target device to close or open, if the anti-misoperation check fails, the first operation instruction is not sent to the target device, effectively avoiding the closing or opening operation when the device state is abnormal or the environmental risk is not eliminated, reducing the device damage risk and personnel safety accidents caused by misoperation, and improving the operation safety and reliability of the rail transit system.

[0041] In a possible implementation, the method further includes: if the target operation instruction fails the anti-misoperation check or no state feedback information of the target device is received within a preset time, determining whether a second authorization verification unit is in an unlocked state; if the second authorization verification unit is in the unlocked state, receiving a second touch instruction for the safety interlocking operation device; displaying a real-time state of the target device on an independent state display area of the safety interlocking operation device based on the second touch instruction; and generating alarm information corresponding to the target device according to the real-time state of the target device.

[0042] Specifically, the preset time can be set in advance and can be set according to the type of the target device, for example, the preset time of the grounding cabinet is usually set to 5 to 10 seconds, and the preset time of the disconnector is usually set to 3 to 5 seconds. The independent state display area specifically refers to a display area on the safety interlocking operation device that is specially used to display the state of the device, for example, it can be an array of LED indicator lights or a specific partition of an LCD display screen. For example, a red indicator light of the independent state display area is always on, prompting the operator to check the state of the device. The alarm information can be in the form of text, icons or sound broadcast, and is used to prompt the operator about the specific abnormal situation of the target device.

[0043] Exemplarily, when the safety interlocking operation device detects that the closing instruction for the target device fails the anti-misoperation check, it is determined whether the second authorization verification unit is in the unlocked state, if the second authorization verification unit is in the unlocked state, the operator selects a target track by touching a track selection panel of the safety interlocking operation device, and then clicks a state query button on an authorization instruction generation panel. At this time, a track display panel of the safety interlocking operation device immediately displays the opening and closing state of the disconnector associated with the track, the train occupation state and the contact net electricity test state. If the disconnector is in the closed state and the operation instruction requires closing the grounding cabinet, an alarm information of “disconnector not opened” is generated, and a red warning light of the track display panel flashes to prompt the operator, which can enable the operator to confirm the safety problem in time and avoid the risk of misoperation.

[0044] In a possible implementation, state information associated with the target device is acquired, where the state information at least includes state information of the associated isolating switch in the same track, state information of train occupation of the track, and state information of the electric test of the overhead contact system corresponding to the track; when the operation instruction indicates to control the grounding cabinet to close, it is determined whether the state information meets a preset safety condition; where the preset safety condition includes that the isolating switch is in an open state, the track is not occupied by a train, and the overhead contact system is in a de-energized state; if yes, the grounding cabinet is controlled to close through the operation instruction.

[0045] Specifically, when the safety interlocking operation device receives the grounding cabinet closing instruction, the state information of the target device is first displayed on the track display panel, for example, train occupation state data is acquired, it is determined whether there is train occupation in the track, it is determined that the overhead contact system is in a de-energized state when the overhead contact system voltage is lower than a preset threshold, if the isolating switch open signal is true, the train occupation signal is false, and the overhead contact system de-energized signal is true, a control signal allowing closing is generated and sent to the target device to control the target device to perform the closing action. If any of the preset safety conditions is not met, the corresponding fault indicator light is displayed on the track display panel, and the safety of the grounding cabinet closing operation is ensured by comprehensively judging the multiple state information associated with the target device, thereby improving the reliability and safety of the rail transit system.

[0046] S140: If the first authorization verification unit is not in the unlocked state, it is determined whether the second authorization verification unit of the safety interlocking operation device is in the unlocked state, and if the second authorization verification unit is in the unlocked state, a first authorization instruction is sent to the field control device, where the first authorization instruction is used to instruct the field control device to control the target device.

[0047] Specifically, if the first authorization verification unit is not in the unlocked state, it indicates that the safety interlocking operation device cannot directly generate the related operation instruction, at this time, it is determined whether the second authorization verification unit is in the unlocked state, if the second authorization verification unit is in the unlocked state, it indicates that the safety interlocking operation device can indirectly control the target device, the first authorization instruction can be generated, and the first authorization instruction is sent to the field control device through the server, after the field control device receives the first authorization instruction, the target device can be controlled according to the content of the first authorization instruction, through the multi-level authorization mechanism, the backstage remote operation is realized, and the hierarchical control demand of the field operation is met, thereby improving the flexibility and safety of the entire control system.

[0048] In a possible implementation, if the first authorization verification unit is not in the unlocked state, it is determined whether the second authorization verification unit of the safety interlocking operation device is in the unlocked state, and if the second authorization verification unit is in the unlocked state, a first authorization instruction is sent to the field control equipment, including: receiving a third operation instruction sent by the field control equipment; performing an anti-misoperation check on the third operation instruction to determine whether the third operation instruction meets a preset safety condition; if the third operation instruction passes the anti-misoperation check, receiving a third touch instruction for the safety interlocking operation device; generating the first authorization instruction based on the third touch instruction, and sending the first authorization instruction to the field control equipment.

[0049] Specifically, the third operation instruction is an operation request instruction sent by the field control equipment, for example, a grounding closing or opening instruction. After receiving the third operation instruction, the server performs an anti-misoperation check on the third operation instruction to verify whether the preset safety condition is met. When the anti-misoperation check passes, the third touch instruction for the safety interlocking operation device is received to perform manual confirmation, and then the first authorization instruction is generated according to the third touch instruction and sent to the field control equipment, so that the field control equipment has the operation permission of the target equipment. Through the double verification mechanism combining automatic check and manual confirmation, the safety and reliability of the field device operation are ensured.

[0050] Specifically, after receiving the third operation instruction sent by the field control equipment, if the third operation instruction passes the anti-misoperation check, it can be displayed at the corresponding position of the safety interlocking operation device that the instruction has passed, for example, the corresponding display lamp is turned on. Then the operator touches the corresponding position of the safety interlocking operation device, for example, the operator presses the “permission down” button on the safety interlocking operation device, and then the corresponding third touch instruction is generated. The safety interlocking operation device generates the first authorization instruction according to the third touch instruction and sends it to the field control equipment.

[0051] For example, after the on-site personnel press the "grounding cabinet closing" button of the on-site control device of the track 5 and then press the "permission application" button of the on-site control device, after receiving the grounding cabinet closing instruction, the track 5 button light of the safety interlocking operation device starts to flash to indicate that the operation request of the track 5 is received. After the operator presses the track 5 corresponding button light on the safety interlocking operation device, the track 5 button light becomes constant at this time. The "grounding closing confirmation" and "grounding closing refusal" button lights of the safety interlocking operation device start to flash, and the indicator light of the track display panel of the safety interlocking operation device displays the state of the track at this moment. The operator judges whether the preset safety conditions are met through the indicator light on the panel, that is, whether the disconnector is in the open state, whether the track has a vehicle, the electric test result and other conditions are comprehensively judged. If the preset safety conditions are met at this time, the operator presses the "grounding closing confirmation" button, the "grounding closing confirmation" button becomes constant at this time and generates the first permission confirmation instruction, the "grounding closing refusal" button light is extinguished, and the "permission delegation" button light starts to flash. The operator needs to press the "permission delegation" button light again to generate the first authorization instruction to ensure that there is no misoperation at this time. The "permission delegation" button light becomes constant, the target device receives the instruction and starts to perform the grounding closing operation. After the closing operation is completed, the safety interlocking operation device receives the closing completion information returned by the target device, and after 5s, all the indicator lights and button lights on the safety interlocking operation device are extinguished to restore the initial state. If the operation request does not meet the preset safety conditions, the operator directly presses the "grounding closing refusal" button light. At this time, the track 5 corresponding button light and the "grounding closing refusal" button light are in constant state, and the "grounding closing confirmation" button light is extinguished. The safety interlocking operation device does not issue any instruction. After 10s, the buttons and indicator lights on the safety interlocking operation device are all extinguished to restore the initial state, avoiding the error operation of the target device when the safety conditions are not met, reducing the risk of equipment damage and personnel safety accidents, and improving the operation safety of the rail transit system in the fault state.

[0052] The safety interlocking control method of the rail transit system provided in the application is applied to a rail transit control system comprising a main control device and a safety interlocking operation device, and the method comprises the following steps: obtaining the working state of the main control device and generating a corresponding working state signal according to the working state; when the working state signal indicates that the main control device is in a fault state, confirming the control authority of the safety interlocking operation device over a target device; judging whether a first authorization verification unit of the safety interlocking operation device is in an unlocked state, and if the first authorization verification unit is in the unlocked state, sending a first operation instruction to the target device, the first operation instruction being used to control the working state of the target device; if the first authorization verification unit is not in the unlocked state, judging whether a second authorization verification unit of the safety interlocking operation device is in the unlocked state, and if the second authorization verification unit is in the unlocked state, sending a first authorization instruction to a field control device, the first authorization instruction being used to instruct the field control device to control the target device. The safety interlocking control method of the rail transit system provided in the application can realize safe and reliable authority switching and operation control when the main control system fails, effectively prevent misoperation and unauthorized operation, ensure the safety of operating personnel and equipment, and improve the safety operation and maintenance efficiency of the rail transit system in a fault state.

[0053] Corresponding to the foregoing application function implementation method embodiments, the application further provides a safety interlocking control system of a rail transit system, a safety interlocking operation device, and corresponding embodiments.

[0054] Figure 2 FIG. 1 is a structural schematic diagram of a safety interlocking control system 200 of a rail transit system according to an embodiment of the application.

[0055] Referring to Figure 2 The safety interlocking control system 200 of the rail transit system comprises a server 210, a main control device 220, a safety interlocking operation device 230, a target device 240, and a field control device 250. The server 210 obtains the working state of the main control device 220 and generates a corresponding working state signal according to the working state. When the working state signal indicates that the main control device 220 is in a fault state, the server 210 confirms the control authority of the safety interlocking operation device 230 over the target device 240. The server 210 judges whether a first authorization verification unit of the safety interlocking operation device 230 is in an unlocked state, and if the first authorization verification unit is in the unlocked state, the safety interlocking operation device 230 sends a first operation instruction to the target device 240, the first operation instruction being used to control the working state of the target device 240. If the first authorization verification unit is not in the unlocked state, the server 210 judges whether the second authorization verification unit of the safety interlocking operation device 230 is in the unlocked state, and if the second authorization verification unit is in the unlocked state, the safety interlocking operation device 230 sends a first authorization instruction to the field control device 250, and the first authorization instruction is used to instruct the field control device 250 to control the target device 240.

[0056] The safety interlocking control system of the rail transit system provided in the present application comprises a server, a main control device, a safety interlocking operation device, a target device, and a field control device. The server acquires the working state of the main control device and generates a corresponding working state signal according to the working state. When the working state signal indicates that the main control device is in a fault state, the server confirms the control authority of the safety interlocking operation device over the target device. The server judges whether a first authorization verification unit of the safety interlocking operation device is in an unlocked state, and if the first authorization verification unit is in the unlocked state, the safety interlocking operation device sends a first operation instruction to the target device, and the first operation instruction is used to control the working state of the target device. If the first authorization verification unit is not in the unlocked state, the server judges whether a second authorization verification unit of the safety interlocking operation device is in the unlocked state, and if the second authorization verification unit is in the unlocked state, the safety interlocking operation device sends a first authorization instruction to the field control device, and the first authorization instruction is used to instruct the field control device to control the target device. The safety interlocking control system can realize safe and reliable authority switching and operation control when the main control system fails, effectively prevent misoperation and unauthorized operation, ensure the safety of operating personnel and equipment, and improve the safety operation and maintenance efficiency of the rail transit system in the fault state.

[0057] As to the apparatus in the above-mentioned embodiments, the specific manners in which various modules perform operations have been described in details in the embodiments relating to the method, and thus will not be described in details here.

[0058] The present application also provides a safety interlocking operation device. Figure 3 The present application also provides a hardware structure schematic diagram of an embodiment of the safety interlocking operation device. The safety interlocking operation device comprises a first control area, a second control area, a first authorization verification unit, a knife switch control panel, a track state display panel, a track selection panel, and an authorization instruction generation panel. The first control area comprises the first authorization verification unit and the knife switch control panel. The knife switch control panel is used to control the target device through the knife switch control panel when the first authorization verification unit is unlocked, and is also used to display the state information of the target device. The second control area comprises the second authorization verification unit, the track state display panel, the track selection panel, and the authorization instruction generation panel. The track display panel is used to display the state information of the track, the track selection panel is used to select the track corresponding to the target device, and the authorization instruction generation panel is used to generate the preset authorization instruction.

[0059] In addition, in combination with the safety interlocking control method of the rail transit system in the above embodiments, the embodiments of the present application can provide a computer readable storage medium for implementation. The computer readable storage medium has executable codes stored thereon, and the executable codes are executed by a processor to implement any one of the safety interlocking control methods of the rail transit system in the above embodiments.

[0060] The present application is not limited to the particular configurations and processes described above and shown in the drawings. For the sake of brevity, detailed descriptions of known methods are omitted. In the above embodiments, several specific steps are described and shown as examples. However, the method processes of the present application are not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order of the steps, after understanding the spirit of the present application.

[0061] The functional blocks shown in the above structural block diagrams can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, etc. When implemented in software, the elements of the present application are program or code segments used to perform the required tasks. The program or code segments can be stored in a machine readable medium or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. The "machine readable medium" can include any medium capable of storing or transmitting information. Examples of the machine readable medium include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segments can be downloaded via a computer network such as the Internet, an intranet, etc.

[0062] It should also be noted that the exemplary embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiments, or in an order different from the embodiments, or several steps can be performed simultaneously.

[0063] The above is only a specific implementation of the present application, and those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above described systems, modules and units can refer to the corresponding processes in the foregoing method embodiments, which will not be described here. It should be understood that the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be covered within the protection scope of the present application.

Claims

1. A safety interlocking control method for a rail transit system, characterized in that, The method, applied in a rail transit control system that includes a main control unit and a safety interlocking operation device, comprises: The operating status of the main control device is obtained, and a corresponding operating status signal is generated based on the operating status. When the working status signal indicates that the main control device is in a fault state, the control authority of the safety interlock operation device over the target device is confirmed. Determine whether the first authorization verification unit of the safety interlock operation device is in an unlocked state. If the first authorization verification unit is in an unlocked state, send a first operation command to the target device. The first operation command is used to control the working state of the target device. If the first authorization verification unit is not in the unlocked state, it is determined whether the second authorization verification unit of the safety interlocking operation device is in the unlocked state. If the second authorization verification unit is in the unlocked state, a first authorization instruction is sent to the field control device. The first authorization instruction is used to instruct the field control device to control the target device.

2. The method according to claim 1, characterized in that, Also includes: Acquire the operating status signal of the main control system, wherein the operating status signal includes at least a normal operating signal and a fault signal; When the working status signal is the fault signal, determine whether the first authorization verification unit or the second verification authorization unit of the safety interlock operation device is in the unlocked state. When the first authorization verification unit or the second verification authorization unit is in the unlocked state, the control authority of the security interlocking operation device over the target device is confirmed. When the working status signal is the normal working signal, a first generation instruction is received, which is used to instruct the main control system whether to generate a second authorization instruction. If the first generation instruction instructs the main control to generate a second authorization instruction, then the main control system is controlled to generate the second authorization instruction and send it to the field control device; wherein, the second authorization instruction is used to instruct the field control device to control the target device.

3. The method according to claim 1, characterized in that, Also includes: The system receives a second operation instruction sent by the field control device; wherein the second operation instruction is used to instruct the field control device to control the working status of the target device. Based on the second operation instruction, the main control system is controlled to send a first permission confirmation instruction; wherein the first permission confirmation instruction is used to indicate whether to confirm the operation permission of the second operation instruction.

4. The method according to claim 1, characterized in that, The step of sending a first operation command to the target device if the first authorization verification unit is in an unlocked state further includes: If the first authorization verification unit is in an unlocked state, it receives a first touch command for the security interlocking operation device; Generate the first operation instruction based on the first touch instruction; The first operation instruction is checked for error prevention to determine whether the first operation instruction meets the preset safety conditions. If the first operation instruction passes the anti-misoperation verification, the first operation instruction is sent to the target device; the first operation instruction is used to control the target device to close or open the circuit breaker. If the first operation instruction fails the error prevention check, the first operation instruction will not be sent to the target device.

5. The method according to claim 4, characterized in that, Also includes: If the target operation command fails the anti-misoperation verification or if no status feedback information from the target device is received within a preset time, it is determined whether the second authorization verification unit is in an unlocked state. If the second authorization verification unit is in the unlocked state, it receives a second touch command for the security interlock operation device; Based on the second touch command, the real-time status of the target device is displayed in the independent status display area of ​​the safety interlock operation device; Based on the real-time status of the target device, generate alarm information corresponding to the target device.

6. The method according to claim 1, characterized in that, If the first authorization verification unit is not in an unlocked state, it is determined whether the second authorization verification unit of the safety interlocking operation device is in an unlocked state. If the second authorization verification unit is in an unlocked state, a first authorization command is sent to the field control device, including: Receive the third operation command sent by the field control device; The third operation instruction is subjected to error prevention verification to determine whether the third operation instruction meets the preset security conditions. If the third operation command passes the anti-misoperation verification, then a third touch command for the safety interlock operation device is received; Based on the third touch command, the first authorization command is generated and sent to the field control device.

7. The method according to claim 4 or 6, characterized in that, Also includes: Obtain the status information associated with the target device, wherein the status information includes at least the opening and closing status information of the associated disconnecting switch of the target device located on the same track, the train occupancy status information of the track, and the voltage detection status information of the contact network corresponding to the track; When the operation command instructs the control grounding cabinet to close, it is determined whether the status information meets the preset safety conditions; wherein, the preset safety conditions include: the disconnecting switch is in the open state, there is no train occupying the track, and the contact wire is in a de-energized state; If the conditions are met, the grounding cabinet will be closed by controlling the operation command.

8. A safety interlocking control system for a rail transit system, characterized in that, include: Server, main control device, safety interlocking operation device, target equipment, field control equipment; The server obtains the working status of the main control device and generates a corresponding working status signal based on the working status. When the working status signal indicates that the main control device is in a fault state, the server confirms the control authority of the safety interlock operation device over the target device; The server determines whether the first authorization verification unit of the safety interlock operation device is in an unlocked state. If the first authorization verification unit is in an unlocked state, the safety interlock operation device sends a first operation instruction to the target device. The first operation instruction is used to control the working state of the target device. If the first authorization verification unit is not in the unlocked state, the server determines whether the second authorization verification unit of the safety interlock operation device is in the unlocked state. If the second authorization verification unit is in the unlocked state, the safety interlock operation device sends a first authorization instruction to the field control device. The first authorization instruction is used to instruct the field control device to control the target device.

9. A safety interlocking operation device, characterized in that, include: The first control area includes a knife switch control panel and a first authorization verification unit. The knife switch control panel is used to control the target device when the first authorization verification unit is unlocked. The knife switch control panel is also used to display the status information of the target device. The second control area includes a second authorization verification unit, a track status display panel, a track selection panel, and an authorization instruction generation panel. The track display panel is used to display track status information, the track selection panel is used to select the track corresponding to the target device, and the authorization instruction generation panel is used to generate preset authorization instructions.

10. A computer-readable storage medium, characterized in that, It stores executable code that, when executed by a processor of an electronic device, causes the processor to perform the method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Control right grabbing method and device, electronic equipment and computer program product

    CN114701546A

  • Wireless locomotive signal dual-engine warm standby control method

    CN1775606A

  • Maintenance work support system of electric railway facility

    JP2011128865A