Door opening safety protection method and device for TACS system and medium
By designing an A/B token mechanism in the TACS system, the mutual exclusion of onboard controller tokens is ensured, which solves the door opening security problem in platform parking scenarios, achieves safe stopping and stabilization in communication interruption and train degradation scenarios, and avoids the risk of abnormal door opening.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-09
- Publication Date
- 2026-03-31
AI Technical Summary
In the TACS system, the onboard controller based on the redundancy architecture at both ends has difficulty in ensuring that the calculation results at both ends are consistent. This results in one end outputting a door opening command and the other end outputting a traction command in the platform parking scenario, which poses a risk of abnormal opening of the train doors/platform doors after the train departs.
The design incorporates an A/B token mechanism, where primary and backup vehicle controllers interact to ensure token exclusivity and prevent one end from outputting a door opening command while the other outputs a traction command. WRC safety authorization is employed to guarantee token uniqueness during communication interruptions.
Technically, it eliminates the risk of abnormal platform door opening, ensures the safety of trains when they stop at the platform, takes into account the safety and stability requirements in scenarios of communication interruption and train degradation, and does not require additional hardware equipment and communication interfaces.
Smart Images

Figure CN121757221A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to rail transit signaling systems, and more particularly to a door opening safety protection method, device, and medium for TACS systems. Background Technology
[0002] For the TACS system architecture, the train controller has evolved from the initial single onboard controller CC and trackside controller WTC to a redundant onboard controller (main onboard controller NCC and backup onboard controller BCC) and trackside controller WTC. The new system architecture not only minimizes the impact of a single onboard controller failure on online train operation and safety protection, but also minimizes the huge impact on operational efficiency caused by the trackside controller controlling the train.
[0003] For the new TACS system based on a front-to-back redundancy architecture, since the onboard controllers at both ends operate independently, it is difficult to guarantee that the calculation results of the onboard controllers at both ends are completely consistent. In the scenario of the train stopping at the platform, there may be a dangerous situation where one onboard controller outputs a door opening command and the other onboard controller outputs a traction command, resulting in the abnormal opening of the train doors / platform doors after the train departs.
[0004] A search revealed Chinese Patent Publication No. CN118182590A, which discloses a platform screen door control method, device, and medium for a TACS system. Specifically, it discloses that the trackside resource manager (WRC) allocates platform entry and door opening authorizations to the train control system (CC) on a first-come, first-served basis according to the order of train requests. This patent achieves the independence and uniqueness of platform screen door control for different trains through information exchange between the CC and WRC. However, it does not address how to ensure safe door opening for onboard controllers based on a front-to-back redundancy architecture.
[0005] To address the aforementioned issues, the currently known mature technology involves the onboard controllers at both ends transmitting calculated door-opening commands over a network. If either onboard controller calculates the door-opening command, neither end will allow the train to move, thus ensuring door-opening safety. However, this technology relies on the scenario where the onboard controllers at both ends are communicating normally. When communication is lost, to ensure the availability of a single onboard controller, the controller no longer knows whether the other end has output a door-opening command. Therefore, in scenarios where communication is lost, the dangerous situation of abnormally opening train / platform doors after train departure still exists and has not been completely eliminated technically.
[0006] Therefore, for TACS systems that adopt a redundancy architecture, how to completely eliminate the scenario of abnormal platform door opening from a technical perspective, thereby ensuring the safety of platform door opening, has become a technical problem that needs to be solved. Summary of the Invention
[0007] The purpose of this invention is to overcome the defects of the prior art by providing a door opening safety protection method, device and medium for TACS system, ensuring that when one on-board controller outputs a door opening command, the other on-board controller will not output a traction command at the same time, completely eliminating the situation of abnormal door opening on the platform, thereby ensuring the safety of trains opening doors on the platform.
[0008] The objective of this invention can be achieved through the following technical solutions: According to a first aspect of the present invention, a door opening safety protection method for a TACS system is provided, the TACS system including a primary on-board controller (NCC) and a backup on-board controller (BCC) located at both ends of a train, the protection method being: the primary on-board controller (NCC) and the backup on-board controller (BCC) interact with their respective A tokens or B tokens, making the A tokens or B tokens of the on-board controllers at both ends mutually exclusive, wherein the A token is a necessary condition for authorizing train movement, and the B token is a necessary condition for authorizing door opening.
[0009] As a preferred technical solution, the vehicle controller needs to meet the following conditions to possess the A token: a1) The current vehicle controller has control over the vehicle; a2) Failed to inform the peer vehicle controller that it did not have an A token; a3) Obtain the B token from the other end of the vehicle controller, or the current driving mode is manual mode (RM), or you have WRC security authorization.
[0010] As a preferred technical solution, the vehicle controller needs to meet the following conditions to possess the B token: b1) The current vehicle controller has control over the vehicle; b2) Failed to inform the other end of the vehicle controller that it did not have a B token; b3) The current driving mode is not Manual (RM) mode; b4) Obtain the A token from the other end's vehicle controller, or have WRC security authorization.
[0011] As a preferred technical solution, the controller determination is specifically as follows: when the local vehicle controller is performing a task, or when the health of the local vehicle controller is higher than the health of the remote vehicle controller and the remote controller is not performing a task, the local vehicle controller is considered to have the right to control the vehicle.
[0012] As a preferred technical solution, the prerequisite for informing the peer vehicle controller that it does not have an A token is that it currently does not possess an A token and the local vehicle controller does not have vehicle control rights.
[0013] As a preferred technical solution, the prerequisite for informing the other end vehicle controller that it does not have a B token is that it currently does not possess a B token and the local vehicle controller does not have the right to control the vehicle.
[0014] As a preferred technical solution, it is considered that the A token of the peer vehicle controller has been obtained only when a message of no A token is received from the peer vehicle controller. It is considered that the B token of the other end vehicle controller has been obtained only when a message without B token is received from the other end vehicle controller.
[0015] As a preferred technical solution, the WRC safety authorization is calculated and allocated by the trackside resource manager WRC, and is unique among the primary on-board controller NCC, the backup on-board controller BCC, and the trackside controller WTC.
[0016] As a preferred technical solution, when the local vehicle controller does not have an A token, the remote vehicle controller is executed by default when the remote vehicle controller is executing the door opening command, and the local vehicle controller does not calculate the movement authorization.
[0017] As a preferred technical solution, emergency braking EBRD and holding braking ZVRD are permitted only when the onboard controller has an A token and the safety conditions of the train are met, thereby authorizing the train to move.
[0018] As a preferred technical solution, door or platform door opening authorization is allowed only when the on-board controller has a B token and meets the security conditions for opening the door.
[0019] As a preferred technical solution, if the local on-board controller has a B token, it means that the remote on-board controller has not obtained the local B token, the current train is not in RM mode, and the local device has WRC security authorization or has obtained the remote on-board controller's A token.
[0020] As a preferred technical solution, when communication between the two on-board controllers is interrupted, the end with WRC security authorization can possess the B token.
[0021] As a preferred technical solution, when the train is in RM mode, the on-board controller can have A token, but cannot have B token.
[0022] According to a second aspect of the present invention, an electronic device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the program to implement the method described thereon.
[0023] According to a third aspect of the present invention, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the method described thereon.
[0024] Compared with the prior art, the present invention has the following advantages: 1) This invention designs two tokens, A and B. By having mutually exclusive A and B tokens at both ends of the on-board controller, it ensures that when one on-board controller outputs a door opening command in a platform parking scenario, the other on-board controller will not release the train braking authorization traction, thus technically guaranteeing the safety of platform door opening. 2) This invention considers the scenario where communication between the two onboard controllers is interrupted. It ensures the mutual exclusion of A / B tokens between the two onboard controllers by using the uniqueness of WRC security authorization, thereby ensuring the security of platform door opening in the scenario where communication between the two onboard controllers is interrupted. 3) This invention also takes into account the scenario of train degradation. At this time, the on-board controller can have the A token, but cannot have the B token. On the one hand, it solves the problem of door opening security when the system cannot ensure safe stopping in RM mode. On the other hand, it also meets the requirements of moving the train in RM mode in degradation scenarios such as interruption of communication between the train and the outside world or loss of train positioning. 4) This invention is implemented through software logic, requiring no additional hardware devices or communication interfaces; 5) This invention is completed automatically by the system without human intervention. Attached Figure Description
[0025] Figure 1 This is a schematic diagram of a dangerous scenario where the TACS system platform door is opened based on a head-and-tail redundancy architecture in an embodiment of the present invention. Figure 2 This is a flowchart illustrating the process of the vehicle controller calculating the A token in an embodiment of the present invention. Figure 3 This is a flowchart illustrating the process of the vehicle controller calculating the B token in an embodiment of the present invention. Detailed Implementation
[0026] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0027] like Figure 1 The diagram shown is a schematic of a dangerous scenario involving the opening of a platform door in a TACS system based on a front-to-back redundancy architecture, as described in an embodiment of the present invention. Scenario 1: The primary onboard controller (NCC) is in ATP mode, with control of the train and WRC safety authorization. After stopping at the platform, it does not meet the conditions for opening the doors due to large positioning errors, and both the train doors and platform doors are closed and locked at this time. Therefore, the movement authorization is valid, and a traction command is output to the train. The backup onboard controller (BCC) is in ATP mode, without control of the train or WRC safety authorization. After stopping at the platform, it meets the conditions for opening the doors, and therefore outputs a door opening command to the train and platform doors. If the vehicle traction response delay is very short, it will lead to a dangerous scenario where the train doors / platform doors open abnormally after the train departs.
[0028] Scenario 2: The primary onboard controller (NCC) is in ATP mode, with control of the train and WRC safety authorization. After stopping at the platform, it meets the conditions for opening the doors and therefore outputs a door opening command to the train and platform doors. On the other end, the driver switches to manual mode (RM), which means that the safe stopping of the train cannot be guaranteed. If the primary onboard controller (NCC) continues to output door opening commands, but the driver is unaware that the doors are about to open, it will lead to a dangerous scenario where the rear doors / platform doors of the RM mode train open abnormally.
[0029] The following section of this invention will describe how to avoid the dangerous scenario of abnormal opening of the train doors / platform doors after the train departs when the TACS system with a front-to-back redundancy architecture outputs a door opening command at one end and a traction command at the other end during a platform parking scenario.
[0030] This invention discloses a door opening safety protection method for a TACS system. The method includes the onboard controller calculating two tokens: an A token and a B token. The A token is a necessary condition for authorizing train movement, and the B token is a necessary condition for authorizing door opening. The onboard controllers at both ends of the train exchange their respective A / B tokens, achieving mutual exclusion between the A / B tokens of the two onboard controllers. This ensures that when one onboard controller outputs a door opening command, the other onboard controller will not simultaneously output a traction command, thereby guaranteeing the safety of train door opening at the platform.
[0031] like Figure 2 The diagram shown is a flowchart illustrating the process of the vehicle controller calculating the A token in an embodiment of the present invention.
[0032] There are three ways to obtain an A token for the vehicle controller: a1) The current vehicle controller has control over the vehicle and has not informed the other vehicle controller that it does not have an A token, but has obtained the other vehicle controller's B token. a2) The current vehicle controller has control over the vehicle and has not informed the other vehicle controller that it does not have an A token, and it has WRC security authorization. a3) The current vehicle controller has control of the vehicle and has not informed the other vehicle controller that it does not have an A token, and the current driving mode is manual mode (RM). The current vehicle controller has vehicle control rights, determined by the following logic: either the local vehicle controller is executing a task, or the health of the local vehicle controller is higher than that of the remote vehicle controller and the remote controller is not executing a task. When communication between the two vehicle controllers is interrupted, the health of the remote vehicle controller is assumed to be 0, indicating that the remote controller is not executing a task. Therefore, in the scenario of communication interruption, both vehicle controllers have vehicle control rights.
[0033] The logic for informing the other end of the vehicle controller that it does not have an A token is as follows: it does not currently possess an A token and the vehicle controller does not have the right to control the vehicle.
[0034] The WRC safety authorization is calculated and allocated by the trackside resource manager WRC, and is unique among the primary on-board controller NCC, the backup on-board controller BCC, and the trackside controller WTC. There will be no situation where multiple controllers have WRC safety authorization at the same time.
[0035] The phrase "obtaining the B token from the peer vehicle controller" means receiving a message from the peer vehicle controller that no B token was received.
[0036] When the local vehicle controller does not have an A token, the remote controller will execute the door opening command by default, and the local controller will not calculate the movement authorization.
[0037] When the onboard controller has an A token and other safety conditions are met, it allows the emergency braking EBRD to be eased and the holding braking ZVRD to be maintained, thereby authorizing the train to move.
[0038] like Figure 3 The diagram shown is a flowchart illustrating the process of the vehicle controller calculating the B token in an embodiment of the present invention.
[0039] The vehicle controller can obtain a B token in the following two ways: b1) The current vehicle controller has control of the vehicle, has not informed the other vehicle controller that it does not have a B token, and the current driving mode is not manual mode (RM), and it has obtained the other vehicle controller's A token. b2) The current vehicle controller has control of the vehicle, has not informed the other vehicle controller that it does not have a B token, the current driving mode is not manual mode (RM), and it has WRC security authorization. The logic for informing the other end of the vehicle controller that it does not have a B token is as follows: it does not currently possess a B token and the vehicle controller does not have the right to control the vehicle.
[0040] The phrase "obtaining the A token from the peer vehicle controller" means receiving a message from the peer vehicle controller that no A token was received.
[0041] Door / platform door opening authorization is allowed to be calculated only when the onboard controller has a B token and other door opening security conditions are met.
[0042] according to Figure 3 When the local on-board controller has a B token, it means that the remote on-board controller has not obtained the local B token, the current train is not in RM mode, and the local controller has WRC security authorization or has obtained the remote on-board controller's A token. Therefore, none of the three ways for the remote on-board controller to obtain the A token are satisfied, thus achieving mutual exclusion of the A / B tokens of the two on-board controllers.
[0043] When communication between the two on-board controllers is interrupted, the on-board controller can... Figure 3 The second method, obtaining the B token through WRC security authorization, is not satisfied because WRC security authorization is unique. Therefore, the three methods for the remote vehicle controller to obtain the A token are also not satisfied, thus achieving mutual exclusion of the A / B tokens of the two vehicle controllers.
[0044] The method of this invention, by designing mutually exclusive A / B tokens for the two onboard controllers, ensures that when one onboard controller outputs a door opening command in a platform parking scenario, the other onboard controller will not release the train's braking authorization traction, thus technically guaranteeing the safety of platform door opening.
[0045] The method of this invention considers the scenario of train degradation (see dangerous scenario 2). When the train is degraded to RM mode, the on-board controller no longer has the B token, thereby immediately cutting off the output of the door opening command, solving the door opening safety problem when the system cannot ensure a safe stop in RM mode. At the same time, considering the need for train operation in RM mode in degraded scenarios such as interruption of train communication with the outside world or loss of train positioning, the method of this invention allows the presence of the A token in RM mode, thereby alleviating the emergency braking EBRD and holding braking ZVRD, and allowing manual operation of the train.
[0046] The above is an introduction to the method embodiments. The following embodiments using electronic devices and storage media will further illustrate the solution of the present invention.
[0047] This invention also provides an electronic device including a central processing unit (CPU), which can perform various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) or loaded from a storage unit into a random access memory (RAM). The RAM may also store various programs and data required for device operation. The CPU, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.
[0048] Multiple components in the device are connected to the I / O interface, including: input units such as keyboards and mice; output units such as various types of displays and speakers; storage units such as disks and optical discs; and communication units such as network interface cards (NICs), modems, and wireless transceivers. The communication unit allows the device to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0049] The processing unit performs the various methods and processes described above, such as the methods of the present invention. For example, in some embodiments, the methods of the present invention may be implemented as computer software programs tangibly contained in a machine-readable medium, such as a storage unit. In some embodiments, part or all of the computer program may be loaded and / or installed on the device via ROM and / or a communication unit. When the computer program is loaded into RAM and executed by the CPU, one or more steps of the methods of the present invention described above may be performed. Alternatively, in other embodiments, the CPU may be configured to execute the methods of the present invention by any other suitable means (e.g., by means of firmware).
[0050] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0051] The program code used to implement the methods of the present invention can be written in any combination of one or more programming languages. This program code can be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code can be executed entirely on the machine, partially on the machine, as a standalone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0052] In the context of this invention, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0053] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for open door safety protection for a TACS system, said TACS system comprising a primary on-board controller NCC and a backup on-board controller BCC located at both ends of a train, characterized in that, The protection method is that the main vehicle controller NCC and the backup vehicle controller BCC interact with each other's A token or B token, so that the A token or B token of the two vehicle controllers is mutually exclusive, wherein the A token is a necessary condition for authorizing train movement, and the B token is a necessary condition for authorizing door opening.
2. The method for open door safety shielding for TACS system as claimed in claim 1 wherein, The vehicle controller needs to meet the following conditions to have the A token: a1) the current vehicle controller has the right to control the train; a2) the opposite end vehicle controller is not informed that the current vehicle controller does not have the A token; a3) the opposite end vehicle controller's B token is obtained, or the current driving mode is the manual mode RM, or there is a WRC safety authorization.
3. The method for open door safety shielding for a TACS system of claim 1 wherein, The vehicle controller needs to meet the following conditions to have the B token: b1) the current vehicle controller has the right to control the train; b2) the opposite end vehicle controller is not informed that the current vehicle controller does not have the B token; b3) the current driving mode is not the manual mode RM; b4) the opposite end vehicle controller's A token is obtained, or there is a WRC safety authorization.
4. The open door safety shield method for a TACS system according to claim 2 or 3, wherein The specific determination of the controller is that when the current vehicle controller is executing a task, or the health degree of the current vehicle controller is higher than that of the opposite end vehicle controller and the opposite end vehicle controller is not executing a task, it is considered that the current vehicle controller has the right to control the train.
5. The method for open door safety shielding for a TACS system of claim 2, wherein, The prerequisite for informing the opposite end vehicle controller that the current vehicle controller does not have the A token is that the current vehicle controller does not have the A token and the current vehicle controller does not have the right to control the train.
6. The method for open door safety shielding for a TACS system of claim 3 wherein, The prerequisite for informing the opposite end vehicle controller that the current vehicle controller does not have the B token is that the current vehicle controller does not have the B token and the current vehicle controller does not have the right to control the train.
7. The method for protecting against opening of a door in a TACS system according to claim 2 or 3, wherein Only when the opposite end vehicle controller receives the message that the current vehicle controller does not have the A token, it is considered that the opposite end vehicle controller's A token is obtained. Only when the opposite end vehicle controller receives the message that the current vehicle controller does not have the B token, it is considered that the opposite end vehicle controller's B token is obtained.
8. The method for opening door safety protection for TACS system according to claim 2 or 3, characterized in that, The WRC safety authorization is calculated and distributed by the wayside resource manager WRC, and is unique among the main vehicle controller NCC, the backup vehicle controller BCC, and the wayside controller WTC.
9. The method for open door safety shielding for a TACS system of claim 1 wherein, When the current vehicle controller does not have the A token, it is considered that the opposite end vehicle controller is executing the door opening command, and the current vehicle controller does not calculate the movement authorization.
10. The method for open door safety shielding for a TACS system of claim 1, wherein, Only when the vehicle controller has the A token and meets the safety conditions of the motor train, the emergency brake EBRD and the hold brake ZVRD are allowed to be released, thereby authorizing the train to move.
11. The method for open door safety shielding for a TACS system of claim 1, wherein, Only when the vehicle controller has the B token and meets the safety conditions of the door opening, the door opening authorization of the train door or the platform door is allowed to be calculated.
12. The method for open door safety shielding for a TACS system of claim 1, wherein, If the current vehicle controller has the B token, it is considered that the opposite end vehicle controller does not have the B token of the current vehicle controller, the current train is not in the RM mode, and the current vehicle controller has the WRC safety authorization or has the opposite end vehicle controller's A token.
13. The method for open door safety shielding for a TACS system of claim 1, wherein, When the communication between the two vehicle controllers is interrupted, the vehicle controller with the WRC safety authorization can have the B token.
14. The method for open door safety shielding for a TACS system of claim 1, wherein, When the train is in the RM mode, the vehicle controller can have the A token, but cannot have the B token.
15. An electronic device comprising a memory and a processor, said memory having stored thereon a computer program, characterized in that, The processor executes the program to implement the method in any one of claims 1-14.
16. A computer readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the method in any one of claims 1-14.
Citation Information
Patent Citations
Platform door control method and device for TACS system and medium
CN118182590A