Train control on-board subsystem reliability analysis method, system, equipment and medium
By combining Weibull distribution, virtual age, and β-factor models with the Monte Carlo method of stochastic Petri nets, the reliability of the train control vehicle subsystem is analyzed. This solves the problem that existing technologies fail to fully consider switching strategies, common-cause failures, and human factors, thereby improving the accuracy of reliability assessment and the overall reliability of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- LANZHOU JIAOTONG UNIV
- Filing Date
- 2026-02-27
- Publication Date
- 2026-04-24
AI Technical Summary
Existing technologies, when analyzing the reliability of train control vehicle subsystems, fail to effectively consider the impact of switching strategies on system reliability, especially the impact of active switching strategies on cold standby redundancy structures. They also fail to fully consider the impact of common causes of failure and human factors on system reliability, resulting in inaccurate reliability assessment results.
The reliability model of the vehicle system is established by using the Weibull distribution to model the unit lifetime, introducing virtual age analysis to analyze the active switching strategy, combining the β factor model to consider common cause failure, analyzing the probability of human error through event tree analysis, and using the Monte Carlo method of stochastic Petri nets to simulate the failure process.
It improves the accuracy of reliability assessment, enhances the reliability of cold standby units through proactive switching strategies, identifies system weaknesses, and optimizes reliability analysis results.
Smart Images

Figure CN121920113A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of reliability analysis technology, and in particular to a method, system, equipment and medium for reliability analysis of a train control vehicle subsystem. Background Technology
[0002] The CTCS-3 level train control onboard subsystem is a crucial component of high-speed railways. The onboard equipment receives and processes various data from the radio block center, transponders, and track circuits, monitoring train operation using a target distance continuous speed control mode. It is a key device for ensuring safe train operation. Therefore, researching the reliability model of the onboard subsystem can quantitatively assess the failure risk of the onboard equipment and provide theoretical support for the formulation of maintenance strategies, which is of profound significance for ensuring the safe operation of high-speed railways and improving transportation efficiency.
[0003] Current research on the reliability of vehicle-mounted equipment has yielded some results. One research method uses reliability prediction to obtain the failure rate and maintenance rate of basic units in the vehicle-mounted system. Markov processes and reliability block diagrams are then used to solve for the system's reliability and maintainability indices, determining whether the system meets operational requirements. Meanwhile, another research method transforms the fault tree of the vehicle-mounted system into a Bayesian network, establishing reliability assessment models considering two failure modes (normal operation and system failure) and three modes (normal operation, system failure, and degraded operation). The availability of two-state and three-state vehicle-mounted subsystems is calculated, and the reliability of the vehicle-mounted subsystems is evaluated.
[0004] To improve the operational reliability of in-vehicle equipment, key units of the in-vehicle subsystem employ redundant designs. Existing technologies have evaluated the operational reliability and availability of in-vehicle systems based on dynamic Bayesian networks. Research results show that redundant design enables in-vehicle systems to achieve high operational reliability and availability; after a system failure, functionality can be promptly restored by activating backup units. Therefore, considering the redundancy mechanism of the in-vehicle system, methods such as dynamic fault trees and Monte Carlo simulations were used to quantitatively and qualitatively analyze reliability parameters. The failure density curve of the in-vehicle system and the sensitivity of unit reliability parameters were analyzed, providing a basis for improving the mean time between failures (MTBF) of the in-vehicle system. While redundancy improves system reliability, it also increases the risk of common cause failure (CCF). Therefore, considering the CCF problem of the in-vehicle system, a Bayesian network fused with evidence theory was used to analyze the reliability of the in-vehicle system. The backward reasoning capability of the Bayesian network was used to analyze weak points and calculate importance, determining the degree of influence of different units on the reliability of the in-vehicle subsystem. To address the issues of cognitive uncertainty, dynamism, and common-cause failure in the reliability analysis of vehicle systems, a dynamic Bayesian network was used to analyze the reliability of vehicle systems. The results show that ignoring common-cause failure will lead to an overestimation of the analysis results.
[0005] Resilience refers to a system's ability to recover after its first failure, and is an important indicator distinct from reliability. Due to its redundant design, vehicle-mounted systems can recover after a failure by switching to a backup system; therefore, some researchers use resilience as an indicator of vehicle-mounted system reliability. This paper introduces resilience as a measure of the operational stability of vehicle-mounted subsystems, proposes a quantitative assessment method for vehicle-mounted subsystem resilience based on Bayesian networks, and constructs a resilience assessment model for the vehicle-mounted system. The results show that resilience can describe the vehicle-mounted system's ability to resist disturbances and recover from them. Existing techniques analyze the resilience of vehicle-mounted systems and the importance of each unit based on continuous-time Bayesian networks, and employ... β The factor model was used to evaluate the common-factor failure problem of the system. The results showed that considering factors such as common-factor failure can improve the accuracy of the toughness assessment of the vehicle system.
[0006] During operation, the main system and the backup system switch between each other every week. By alternating operation, the continuous working time of each system is reduced, the workload is decreased, and the system's operational reliability is improved. The above studies only consider the reliability analysis during the periodic alternation operation and cannot analyze and process the overall operation. This makes the reliability model established for vehicle equipment not closely match the actual operating conditions, resulting in inaccurate reliability assessment results. Summary of the Invention
[0007] The purpose of this invention is to address the shortcomings of the prior art by providing a reliability analysis method, system, device, and medium for train control vehicle subsystems, thereby solving the problems in the prior art.
[0008] The present invention specifically provides the following technical solution: A reliability analysis method for a train control vehicle subsystem includes: The lifetime of units in vehicle-mounted equipment is modeled based on the Weibull distribution to obtain the distribution function of each unit; the distribution function characterizes the reliability of the unit. For the cold standby structure of vehicle-mounted equipment, an active switching strategy is adopted to switch between the primary and standby systems. Based on the distribution function, the impact of the active switching strategy on the unit reliability is quantified by virtual age to obtain the unit reliability of the cold standby structure; wherein the virtual age represents the actual age of the unit after maintenance. For the hot standby structure of vehicle-mounted equipment, use β The factor model models common cause failures, considers the impact of common cause failures on redundant structures, and obtains the unit reliability of the hot standby structure based on the distribution function. The success probability of human operation is analyzed by event tree analysis as the probability of human error, and the unit reliability of human error is obtained by using the probability of human error based on the distribution function. A stochastic Petri net model of the vehicle system is established based on the fault tree. Based on the Monte Carlo method of the stochastic Petri net model and the reliability of different units, the failure process of the vehicle system is simulated through the failure transfer mechanism. The time required for unit failure and transfer is accumulated to obtain the life data of the vehicle system. The reliability parameters of the vehicle system are obtained by analyzing the life data.
[0009] Preferably, the impact of the active switching strategy quantified by virtual age on the unit reliability is specifically as follows: Obtain the unit's lifespan without considering maintenance. kd and continues to work in the unit. n Each duration is d After a certain period of time, obtain the unit's working age. nd ; After actively switching, the actual age becomes the virtual age; the specific expression for the virtual age is as follows: ; in, w ( d (This refers to a virtual age.) x For cold storage standby time, z The recovery factor is the factor where the working time and the reserve time are equal. d=x ; Failure rate function and reliability function of the unit The relationship is specifically expressed as: ; The failure rate function of the Weibull distribution is obtained from the probability density function of the unit and the reliability of the unit. The specific expression is: ; Where, is the failure rate function of the Weibull distribution, α , are the Weibull distribution parameters, t is the operating time of the unit; The reliability of the cold standby unit under the active switching strategy is obtained by combining the virtual age, the reliability of the unit, and the failure rate function of the Weibull distribution. The specific expression is: ; Where, 1 represents the unit number; t is the operating time of the unit; d is the switching time interval; n is the number of consecutive working hours of the unit; i represents the n th in the number of consecutive working hours of the unit i and is a quantity unit; is the failure rate function of the Weibull distribution; u is the integration variable; is the reliability of the cold standby unit under the active switching strategy.
[0010] Preferably, the β factor model is used to model the common cause failure, the influence of the common cause failure on the redundant structure is considered, and the unit reliability of the hot standby structure is obtained based on the distribution function. Specifically: The β factor is obtained from the proportion of the common cause failure probability in the total failure probability. The specific expression is: ; Where, is the β factor. β without subscript represents the parameter of the Weibull distribution, is the natural failure probability, is the common cause failure probability, is the parameter of the common cause failure probability expression, is the scale parameter, t is the operating time of the unit; The probability of the occurrence of the common cause failure of the system is represented by the exponential distribution, and the parameters of the common cause failure are solved through β CCF ; The specific expression of the common cause failure probability is: ; in, F CCF ( t ) represents the probability of common cause failure occurring.
[0011] Preferably, the success probability of human operation analyzed through event tree is used as the human error probability, and the unit reliability of human error is obtained based on the distribution function using the human error probability, specifically as follows: Obtain the probability of success for the speed control task. The specific expression is: ; in, , and Each represents the probability of a successful sub-action. The probability of success (HEP) for each sub-action is determined by consulting the human factors manual. This probability is used as the probability of human error, and its specific expression is as follows: ; Wherein, BHEP is the probability of error in the operator's unit action, known as the basic human error probability, and PSF is the human behavior formation factor that modifies HEP. Reliability considering natural degradation R ( t h Generate DMI unit reliability that takes into account personnel reliability. R DMI ( t The specific expression is: .
[0012] Preferably, the step of establishing a stochastic Petri net model of the vehicle system based on the fault tree specifically involves: A stochastic Petri net model of the vehicle system is established based on the fault tree; the fault tree logic gates include AND gates, OR gates, hot standby gates and cold standby gates, where the hot standby gates and cold standby gates correspond to specific SPN structures to represent the fault logic of redundant units.
[0013] Preferably, the Monte Carlo method based on the stochastic Petri net model and different unit reliability levels simulate the failure process of the vehicle system through the failure transfer mechanism, and accumulates the time required for unit failure and transfer to obtain the lifespan data of the vehicle system, specifically: Initialize variables, including the lifespan of the vehicle system. tlife Simulation times N Identifier vector M j Transition vectors X andT Minimum time tmin Correlation matrix A; Based on the aforementioned variables, when a fault occurs in the vehicle system during the fault transfer mechanism simulation, the enabling transition is determined according to the current identifier, and lifetime data that follows the cell lifetime distribution is generated for the delayed enabling transition; wherein, the transition includes delayed transition and instantaneous transition, the delayed transition corresponds to the lifetime distribution function of a specific cell, and the value generated according to this distribution represents the working lifetime of the cell, while the instantaneous transition only represents the upward transfer of the fault. Determine the minimum lifespan value and update the vehicle system status and cumulative time; Repeat the above steps until the vehicle system fails, and record the vehicle system lifespan.
[0014] Preferably, during the Monte Carlo simulation, the cause of system failure is determined based on the identification before the failure, including failure of cold standby structure, failure of hot standby structure, or failure due to common cause, and the failure frequency of each unit is counted to identify the weak link of the system.
[0015] This invention provides a reliability analysis system for a train control vehicle subsystem, comprising: The modeling module is used to model the lifetime of units in the vehicle-mounted equipment based on the Weibull distribution to obtain the distribution function of each unit; the distribution function characterizes the reliability of the unit. The virtual quantization module is used to switch between the primary and backup systems of the cold standby structure of the vehicle equipment using an active switching strategy. Based on the distribution function, it quantifies the impact of the active switching strategy on the unit reliability through virtual age to obtain the unit reliability of the cold standby structure; wherein the virtual age represents the actual age of the unit after maintenance. Common-cause failure module, used for hot standby structures of vehicle-mounted equipment, using β The factor model models common cause failures, considers the impact of common cause failures on redundant structures, and obtains the unit reliability of the hot standby structure based on the distribution function. The Human Error Probability module is used to analyze the success probability of human operations through event tree analysis, which is used as the human error probability. Based on the distribution function, the unit reliability of human error is obtained through the human error probability. The model simulation module is used to establish a stochastic Petri net model of the vehicle system based on the fault tree, and simulate the failure process of the vehicle system through the fault transfer mechanism based on the Monte Carlo method of the stochastic Petri net model and different unit reliability. The time required for unit failure and transfer is accumulated to obtain the life data of the vehicle system, and the reliability parameters of the vehicle system are obtained by analyzing the life data.
[0016] The present invention provides a computer device, including a memory and a processor. The memory stores a program, and when the program is executed by the processor, the processor performs the steps of the above-described reliability analysis method for a train control vehicle subsystem.
[0017] The present invention provides a storage medium storing a computer program thereon, wherein the computer program, when executed by a processor, implements the steps of the above-described reliability analysis method for a train control vehicle subsystem.
[0018] Compared with the prior art, the present invention has the following significant advantages: This invention models the lifespan of units in vehicle-mounted equipment using the Weibull distribution, obtaining the distribution function for each unit. For the cold and hot standby structures of vehicle-mounted equipment, a virtual age model is introduced to establish an active switching strategy model for cold standby redundant units in the vehicle subsystem. The mechanism by which active switching improves system reliability is analyzed. Considering common-cause failures and human factors, the reliability of vehicle-mounted equipment units under multiple influences is derived. Common-cause failures have a low probability of occurrence and have little impact on system reliability. However, considering the success rate of human operation, the system reliability decreases. Based on the active switching strategy, the reliability of cold standby units can be improved, thereby enhancing the overall system reliability. Using the Monte Carlo method of the stochastic Petri net model and different unit reliability levels, the time required for unit failure and transfer is accumulated to obtain system lifespan data. Lifespan data analysis yields reliability parameters for the vehicle-mounted system. Faulty units causing system failures are considered and statistically analyzed to identify frequently failing units and weak points in the system, improving the accuracy of reliability assessment results. Attached Figure Description
[0019] Figure 1 This is a diagram illustrating the passive switching strategy in an embodiment of the present invention; Figure 2 This is a diagram of the active switching strategy in an embodiment of the present invention; Figure 3 This is a unit reliability diagram under different switching strategies in the embodiments of the present invention; Figure 4 This is a diagram illustrating the mechanism of the active switching strategy in this embodiment of the invention. Figure 5 This is a reliability block diagram of the CCF in an embodiment of the present invention; Figure 6 This is a DMI speed control event tree diagram in an embodiment of the present invention; Figure 7 This is a model diagram of the vehicle-mounted subsystem FTA in an embodiment of the present invention; Figure 8 This is a transformation diagram of the AND-OR gate in an embodiment of the present invention; Figure 9This is a diagram showing the SPN representation of the hot standby door in an embodiment of the present invention; Figure 10 This is an SPN representation diagram of the cold standby door in an embodiment of the present invention; Figure 11 This is an SPN model diagram of the vehicle-mounted subsystem in an embodiment of the present invention; Figure 12 Figure 1 shows the simplified SPN model in this embodiment of the invention; Figure 13 This is a diagram illustrating the SPN-MC program simulation steps in an embodiment of the present invention; Figure 14 Figure 2 shows the simplified SPN model in this embodiment of the invention; Figure 15 This is a lifetime data distribution diagram in an embodiment of the present invention; Figure 16 This is a reliability diagram of the vehicle-mounted subsystem in an embodiment of the present invention; Figure 17 This is a reliability comparison chart under different conditions in the embodiments of the present invention; Figure 18 This is a diagram showing the distribution of fault units in an embodiment of the present invention; Figure 19 This is the structure of the vehicle-mounted subsystem in the embodiments of the present invention; Figure 20 The present invention provides a flowchart of a reliability analysis method for a train control vehicle subsystem. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0021] Existing technologies fail to consider the impact of switching strategies on system reliability. Passive switching in this field refers to initial use of only the primary component, with the backup component only commencing operation after the primary component fails. In contrast, active switching strategies involve alternating between the primary and backup systems at fixed time intervals. Active switching does not affect the operation of hot-standby redundancy structures, but research shows that periodic alternation of primary and backup units can improve the reliability of cold-standby redundancy structures. In onboard equipment, the human-machine interface (HMI), transponder information receiving unit, and transponder receiving antenna are cold-standby redundancies; therefore, it is necessary to consider the impact of active switching strategies on system reliability. Furthermore, drivers control train operation through the HMI; therefore, when a driver incorrectly inputs an operating command, a DMI malfunction can be considered as causing a system failure. Therefore, based on active switching strategies and common-factor failures, the impact of human factors on the reliability of onboard equipment is considered, and a reliability model for onboard equipment is established.
[0022] In summary, by introducing the concept of virtual age, the reliability of cold standby units in the vehicle subsystem under the active switching strategy is analyzed. Considering both the CCF of the vehicle equipment and human factors, the lifespan of the unit does not satisfy the exponential distribution under the influence of multiple factors, making the traditional Markov method unusable. Therefore, the Monte Carlo method based on stochastic Petri nets (SPN-MC) is adopted to solve the problem, analyze the reliability and weak points of the vehicle subsystem, and improve the SPN-MC method by optimizing the solution steps.
[0023] The Chinese Train Control System (CTCS) is a crucial piece of equipment in my country's railway system used to control train operation and improve transportation efficiency. CTCS ensures safe train operation by monitoring train speed and intervals, employing a target distance continuous speed control mode and prioritizing equipment braking, and utilizes a tiered approach to meet the specific needs of different lines.
[0024] like Figure 19 As shown, the CTCS-3 level train control onboard subsystem is an important component of the train control system. The onboard equipment consists of a Vital Computer (VC), a Track Circuit Information Receiver (TCR) unit, a Balise Transmission Module (BTM) and transponder antennas, a Driver Machine Interface (DMI), a Train Interface Unit (TIU), and a Speed and Distance Processing Unit (SDU).
[0025] In the onboard subsystem, the VC comprises two control units: the China Train Control System Level 2 Control Unit CTCS-2 (C2-CU) and the China Train Control System Level 3 Control Unit CTCS-3. These units respectively handle the logic processing functions of CTCS-2 and CTCS-3. The VC is responsible for determining and switching the onboard equipment's operating mode and outputting braking commands, serving as the core of the onboard equipment control. A dynamic monitoring module is also included to monitor both CTCS-2 and CTCS-3 control units. The TCR, a component of the VC, is responsible for reading circuit signal codes from the track circuit antenna and decoding them to obtain the carrier frequency and low-frequency information of the circuit. The BTM transmits signals to the ground via its antenna. When the train passes a ground transponder, it activates the ground transponder and... The stored information is sent to the BTM; the DMI includes DMI-1 and DMI-2, which display various information to the driver through sound, images, etc., prompting the driver to take corresponding actions. The driver can input data or make necessary interventions in the train operation through the DMI; the TIU can complete the input and output of signals such as braking commands and isolating switch signal acquisition; the SDU includes a speed measurement and distance processing unit and speed sensors, which are installed on both sides of the axle at both ends of the train. It collects the rotational speed signals of the axles and provides them to the on-board host after processing by the speed measurement and distance measurement module; it also includes a wireless communication (management) module, including a general encryption unit and a communication interface unit, which connects to an external GSM-R radio (Railway Integrated Digital Mobile Communication System) and transmits data with other units. Overall, the CTCS-3 level train control on-board equipment mainly completes the real-time calculation of train speed and position, and generates dynamic speed monitoring curves based on the train control model to ensure the safe operation of the train.
[0026] like Figure 20 As shown in this embodiment, a reliability analysis method for a train control onboard subsystem includes: Step S1: Model the lifetime of the vehicle-mounted equipment unit based on the Weibull distribution to obtain the distribution function of each unit; the distribution function characterizes the unit reliability.
[0027] In current reliability studies of vehicle-mounted equipment, the distribution type of the unit lifetime is assumed to be either exponential or Weibull distribution. The characteristic of exponential distribution is that the failure rate is constant, and the failure rate can be directly solved by Markov chain assuming that the unit follows an exponential distribution. However, in actual operation, the components of the vehicle-mounted system will all experience natural wear and tear due to continuous use, which makes the unit failure rate gradually increase over time. Therefore, compared with exponential distribution, Weibull distribution is more suitable for representing the process of system performance degradation. Therefore, this invention assumes that the unit lifetime of the vehicle-mounted equipment unit follows a Weibull distribution. The specific probability density function (1) and reliability function (2) of the unit are shown below, and the parameters are shown in Table 1.
[0028] (1); (2); Table 1. Weibull distribution parameters Step S2: For the cold standby structure of the vehicle-mounted equipment, an active switching strategy is adopted to switch between the primary and standby systems. Based on the distribution function, the impact of the active switching strategy on the unit reliability is quantified by virtual age to obtain the unit reliability of the cold standby structure; where virtual age represents the actual age of the unit after maintenance.
[0029] The active switching strategy of the vehicle subsystem refers to the switching between the primary and backup systems at one-week intervals during actual operation. This working mode can improve the service life of the cold standby unit. In hot standby redundancy, both the primary and backup components are fully activated during operation. Therefore, there is no switching strategy issue between the primary and backup systems in hot standby redundancy. The switching strategy considered in this invention is only for cold standby structures.
[0030] Modeling proactive switching strategies requires the use of the concept of virtual age, which is proposed based on system maintenance: assuming that the lifespan of a unit is [value missing] when maintenance is not considered. kd That is, when the unit continues to work n Each duration is d After a certain period of time, the working age of the unit can be considered as [missing information]. nd (0≤) n ≤ k ),when n = k The unit will eventually fail due to reaching its lifespan. It is generally believed that maintenance can restore the unit's performance to a better level when the unit's service life is [not specified]. nd If maintenance is performed in a timely manner, the cell's performance will be restored after maintenance, thus the cell's actual age will become less than [a certain value]. nd A certain value (called virtual age) will obviously mean that the actual working time of the unit after maintenance will be greater than [the virtual age]. kd In actual operation, the cold standby redundancy structure can effectively extend its service life through active switching. Referring to virtual age, the following explanation is offered: If the system's components operate in a periodic, discontinuous mode, their performance will recover to a better level after a period of inactivity. Passive switching and active switching modes are as follows... Figure 1 and Figure 2 As shown; where the horizontal axis t represents the unit's running time, T represents the state time, and T1 and T2 represent the working state times of different units, respectively. Figure 2 In this context, Y represents the state time of all standby units, and X represents the state time of the primary unit after a standby unit failure.
[0031] The unit's continuous working time (working age) is d After the active switch was initiated, the unit performance recovered to a better state, and the actual age became the virtual age. w ( d The relationship between virtual age and working age can be described as follows: (3); If the unit's rest period after the first work session is x Then in the second d Before starting, virtual age equals d +( z -1) x In equation (3), z (0≤) z ≤1) is the recovery factor. x For the cold storage standby time, the working time and storage time of a typical unit are equal, therefore equation (3) can be expressed as: (4); at this time d This is the time interval between switching points.
[0032] The reliability expression for a unit can be represented as: (5); The formula for calculating the failure rate function is: (6); From equations (1), (2), and (6), the failure rate function of the Weibull distribution can be obtained as follows: (7); in, Let be the failure rate function of the Weibull distribution. , For the parameters of the Weibull distribution, t This represents the runtime of the unit.
[0033] From equations (4), (5), and (7), the reliability of the cold standby unit under the active switching strategy can be obtained as follows: (8); In equation (8), 1 represents the unit number; t This refers to the unit's runtime. d This is the switching time interval; z The recovery factor indicates the recovery effect; n This refers to the duration of continuous operation of the unit. i Indicates the duration of continuous operation of the unit. n The first ini is a unit of quantity; is the failure rate function of the Weibull distribution in Equation (7); u is the integration variable; is the reliability of the cold standby unit under the active switching strategy.
[0034] The switching time is one week, and the on-vehicle subsystem works 18 hours per day on average. Therefore, the switching time interval d = 126h; According to the reliability of the on-vehicle subsystem under different switching strategies, the average recovery factor z is obtained, and then the influence of different switching strategies on the operation reliability of on-vehicle equipment can be analyzed.
[0035] The reliability curves of the cold standby unit under the active and passive switching strategies are as shown in Figure 3 the figure.
[0036] The intuitive explanation for the active switching strategy to improve the unit reliability is as follows: During the continuous operation of the system, the workload accumulates. By stopping work for a period of time, the continuous working time of the system in a high-stress environment can be reduced, thus extending the entire life cycle of the working unit. The active switching enables a certain recovery of the unit's performance state, which is reflected by the failure rate. That is, when restarting after the cold standby state, the failure rate of the unit is lower than that at the end of the previous operation.
[0037] According to the relationship between the reliability function and the failure rate function (Equation (5)), it can be known that to solve the reliability, the failure rate function of the unit needs to be integrated within the working period. As shown in Figure 4 the figure, assume that a unit with cold standby redundancy works according to the active switching strategy mode, and the unit operation time is 2 d , where, when running to d time, the cold standby state lasts for a duration d , and then continues to work until 2 d . Then, when calculating the reliability of the unit, the failure rate curve can be kept unchanged and integrated within 0 - 2 d ; or the integration interval can be fixed within 0 - d , and the curve can be segmented (i.e., segmented into L 1, L 2) and translated to the selected interval for batch integration (the active switching model adopts the second calculation method). After introducing the recovery factor z , the failure rate function λ ( u ) becomes λ ( u + zd ); The two switching models are explained separately: 1. In the passive switching mode, the line segment L 2 will be moved to the line segment L3 and 0- d Points (in) Figure 4 (Represented by dashed lines in the middle), 2. In active switching mode, after adding the recovery factor, the line segment... L 2. Move to line segment L The position of 4 (in) Figure 4 (represented by solid lines in the middle), it can be seen from equation (5) that the active switching strategy can improve the reliability of the unit.
[0038] The above analysis shows that when the lifetime of a unit follows an exponential distribution (with a constant failure rate), the switching strategy does not affect the unit's performance. The active switching strategy, in particular, can improve the operational reliability of the onboard subsystem, further illustrating that, compared to an exponential distribution, the lifetime of onboard equipment units tends to follow a Weibull distribution.
[0039] Step S3: For the hot standby structure of the vehicle equipment, use β The factor model models common factor failures, considers the impact of common factor failures on redundant structures, and obtains the unit reliability of the hot standby structure based on the distribution function.
[0040] Common cause failure is one of the factors affecting the reliability of redundant structures. It refers to the phenomenon that multiple redundant components or systems fail simultaneously due to a single cause (such as design flaws, environmental stress, operational errors, etc.). β Factor modeling is the most commonly used method for common-cause failure modeling. This method assumes that the overall failure probability of a unit consists of two parts: the natural failure rate and the common-cause failure probability. β The factor refers to the proportion of the probability of failure due to common factors in the total probability of failure, and can be expressed as: (9); in, for β Factors (excluding subscripts) β (representing the parameters of the Weibull distribution) This represents the probability of natural failure. The probability of failure due to common factors. These are the parameters in the expression for the probability of failure due to common factors. For scale parameters, t This refers to the unit's runtime. The probability of system failure due to common cause is represented by an exponential distribution, and then... β CCF Solve for the parameters of failure due to common cause; the specific expression for the probability of failure due to common cause is: ; in, F CCF ( t ) represents the probability of common cause failure.
[0041] The common cause failure of the system is described by the exponential distribution (Equation (10)); β CCF Take 0.1%, and t = 5 × 10⁻⁶. 3 h, based on equation (9), the parameters of common cause failure are calculated, and the results are shown in Table 2.
[0042] Table 2. Parameters of Exponential Distribution When a common cause failure occurs, the same reason causes both the primary and backup components to fail simultaneously. Therefore, a common cause failure can be considered as a unit connected in series with the redundant structure. When the common cause event occurs, the redundant structure fails directly. The reliability block diagram of CCF is as follows: Figure 5 As shown.
[0043] Step S4: Consider the impact of human operation on system reliability. Analyze the success probability of human operation through event tree analysis as the probability of human error. Based on the distribution function, obtain the unit reliability of human error through the probability of human error.
[0044] Train drivers adjust train speed through a human-machine interface (HMI) unit to ensure safe operation; therefore, the reliability of the HMI is affected by human operation. The main operations for drivers to control train operation through the HMI can be divided into three steps, and the HMI can only function properly when all three steps are correct. Therefore, an event tree for HMI-controlled train operation can be established, such as... Figure 6 As shown.
[0045] Figure 6 In the diagram, "+" indicates successful execution; "-" indicates a failed execution step; "S" indicates the speed control task succeeded; and "F" indicates the speed control task failed. Therefore, the probability of the speed control task succeeding is:
[0046] (11); The reliability of the human-computer interface considering natural degradation is R(t h Then, considering the reliability of personnel, the reliability of the DMI unit is... R DMI ( t )for: (12); The resilience of the vehicle-mounted equipment was analyzed based on the reliability data related to personnel operation provided in the personnel reliability analysis manual. Figure 6 The probability of success for a given action (called the Human Error Probability, HEP) can be determined by consulting a human factors manual. The formula for calculating HEP is:
[0047] (13); In the formula, BHEP is the probability of error in the operator's operation of the unit, which is called the Basic Human Error Probability; PSF is the Performance Shaping Factors that correct HEP, and the values of PSF are shown in Table 3.
[0048] Table 3. PSF values under different stress levels Step S5: Establish a stochastic Petri net model of the vehicle system based on the fault tree, and simulate the failure process of the vehicle system through the fault transfer mechanism based on the Monte Carlo method of the stochastic Petri net model and the reliability of different units. Accumulate the time required for unit failure and transfer to obtain the life data of the vehicle system, and obtain the reliability parameters of the vehicle system through life data analysis.
[0049] Traditional Markov methods become unusable when considering the influence of multiple factors on the unit based on the Weibull distribution. The Monte Carlo method based on stochastic Petri nets simulates the system's failure process through the system's fault transfer mechanism, accumulating the time required for unit failures and transfers to obtain system lifetime data, and then analyzing the system's reliability parameters. This method is applicable when the system units follow arbitrary distributions. Therefore, this invention solves the model by combining the SPN model of the vehicle subsystem with the Monte Carlo method.
[0050] Random Petri nets: SPN is defined as a 7-tuple: Σ=( P , T , F , K , W , M 0, Λ ),in: 1) P ={ p 1, p 2,…, p} is a finite set of places; 2) T ={ t 1, t 2,…, t} is a finite set of changes; 3) F ⊆( P × T )∪( T × P ) indicates a directed arc; 4) K : P →{1,2,3,…} represents the capacity function of the storage area; 5)W : F →{1,2,3,…} represents the weight function; 6) M : P →{0,1,2,…} is the identifier for the net, and ∀ p ∈ P : M ( p )≤ K ( p ), M 0 is the initial identifier; 7) Λ ={ λ 1, λ 2,…, λ} is the set of change-induced rates. λᵢ ( i =1,2,…, m ) indicates the first i The rate at which a change is triggered.
[0051] The triggering rules and state transition equations for the model's transitions are shown in equations (14) and (15): (14); (15); The system's stochastic Petri net is constructed based on the fault tree. First, the fault tree of the onboard subsystem is given as follows: Figure 7 As shown, the onboard subsystem is obtained through AND gates between the bus, speed and distance measurement unit, onboard safety computer, transponder information receiving unit, transponder receiving antenna, and human-machine interface. The onboard safety computer is obtained through an OR gate between the C2-level and C3-level onboard safety computers; the C2-level onboard safety computer is obtained through an OR gate between the C2-level primary and C2-level backup onboard safety computers; and the C3-level onboard safety computer is obtained through an OR gate between the C3-level primary and C3-level backup onboard safety computers. The C2-level primary and backup onboard safety computers are both obtained through AND gates between the C2-level control unit, track circuit information reader, and train interface unit; the C3-level primary and backup onboard safety computers are both obtained through AND gates between the train interface unit, C3-level control unit, GSM-R antenna, wireless management module, and radio station. The names of each underlying event are shown in Table 4, and the meanings of the FTA logic gates are shown in Table 5. The Petri net representation of the fault tree logic gates is shown in [Table 5]. Figures 8 to 10 ,exist Figure 8 In this context, the AND (or OR) gate is represented using a Petri net. The AND gate is formed by connecting the libraries... p 1Hekusuo p 2. Through change t 1. Obtain the warehouse p3. OR gate, which is to pass through the warehouse p 1Hekusuo p 2. Through a transition respectively t 1 or t 2. Obtain the warehouse p 3; while Figure 9 In this approach, various states are added to the AND-OR gates. The working state P1 transitions to the fault state P1 after transition T1. The fault state P1 and the reserve state P2, after transitions, are passed through an AND gate to obtain the working state P2. The transitioned reserve state P2 and the working state P2 are then passed through an OR gate to obtain the fault state P2. This process is repeated to obtain the fault state P. n The final fault state P is obtained by passing all fault states through an AND gate. s .exist Figure 10 The diagram in the middle represents the SPN (Special Processing Number) of a cold standby door. It shows how the fault state P1 is obtained directly from the operating state P1 through transition T1, and then through transition T... k The fault status P2 is obtained.
[0052] Table 4. FTA Bottom Event Names Table 5. Meaning of FTA Logic Gates SPN-MC simulates the failure process of a system and generates random numbers based on the lifetime distribution of its components to obtain the system's lifetime data. Therefore, it is suitable for solving the reliability problems of systems whose constituent components follow arbitrary distributions. Generating reliability data following a specific distribution typically employs the inverse method. This method, based on probability integral transformation theory, can convert uniformly distributed random numbers into random variables following any target probability distribution. The core idea of the inverse method is to utilize the inverse function of the cumulative distribution function. F -1 ( X This method maps uniformly distributed random numbers to a target distribution, ensuring that the generated random numbers strictly adhere to the required statistical properties. The simulation flowchart of the SPN-MC program in the prior art is shown below. Figure 13 As shown.
[0053] In the SPN-MC program simulation, variables are initialized, and it is determined whether the simulation will terminate in the Nth simulation. If it does not terminate, enable transitions are determined, the trigger times of all transitions are updated, the triggered transitions are determined, the current time is updated, the trigger times of all enable transitions are updated, and the number of flags is updated until the system lifetime sample of the Nth simulation is obtained when the simulation terminates. The simulation ends when all simulations are completed. If the simulation is not completed, the number of simulations is increased and the simulation process is repeated.
[0054] Figure 13Based on an AC power system (SPN consisting of 6 places and 5 transitions, with an association matrix of dimension 6×5), a SPN-MA solution method is presented. However, this method suffers from computational complexity when solving systems with a large number of elements. If the vehicle-mounted equipment adopts... Figure 13 The method described above results in an SPN model correlation matrix with a dimension of 71×70 without considering CCF. However, when CCF is considered, the size of the correlation matrix increases to 80×79, which is not conducive to program writing and modification. Therefore, this invention provides a simplified method for SPN.
[0055] The failure process of a system can be considered as a gradual transfer of unit failures within the system, eventually leading to system failure. The calculation principle of SPN-MC is to obtain the overall system lifetime sample by accumulating the time of each failure transfer, and then calculate the reliability parameters. In the model, the transition representing a unit failure is a delayed transition (i.e., the token needs a certain amount of time to transition to the next state), while the process of subsequent reactions after the failure occurs is instantaneous, corresponding to the instantaneous transitions in SPN. Obviously, the system lifetime is only affected by delayed transitions. Therefore, for the generation of system lifetime data, some instantaneous transitions in SPN do not affect the analysis results of system reliability.
[0056] Based on the fault tree, establish the SPN model of the on-board equipment as follows: Figure 11 As shown, Figure 11 and Figure 7 The structural units correspond one-to-one, where, p i For the first i One warehouse, among which i =1,2,3,...,71; t j For the first j One change, among which j =1,2,3,...,70 p 71 The part to which it belongs refers to the vehicle subsystem. p 70 The part in question represents the human-computer interface. p 69 The part in question refers to the transponder receiving antenna. p 68 The part in question refers to the transponder information receiving unit. p 67 The part in question refers to the vehicle's safety computer. p 66 The part in question refers to the speed and distance measurement unit. P 65 The part to which it belongs indicates the bus. p 64 The part in question refers to a Class C2 vehicle safety computer. p63 The part in question refers to a C3-level vehicle safety computer. P 56 The part in question refers to a C3-level backup vehicle safety computer. p 55 The part in question refers to the C3 level primary vehicle safety computer. p 54 The part in question refers to a C2-level backup vehicle safety computer. p 53 The part in question refers to the C2 level primary vehicle safety computer. P 42 The part in question indicates a C2-level control unit. p 41 The part in question refers to the track circuit information reader. p 40 The part in question refers to the train interface unit. p 39 The part in question indicates a C3 level control unit. p 38 The part in question refers to the GSM-R antenna. p 37 The part in question refers to the wireless management module. p 36 The part to which it belongs indicates a radio station. Figure 11 In this example, taking the C2-CU (a C2-level control unit) as an example (C2-CU is the warehouse unit) p 42 This section describes the SPN model of the vehicle subsystem; the transitions that generate the unit lifetime data are time-delay transitions. t 1. t 2 and t 4. After both hot standby units fail, Token will retrieve from the warehouse. p 42 In the middle, after changes t 36 , t 49 , t 60 as well as t 68 Finally, it arrives at the warehouse indicating a system failure. p 71 These transitions occur in zero time and do not affect the system's lifetime value. Therefore, these transitions can be removed to reduce the dimension of the correlation matrix and decrease computational complexity. Furthermore, analysis shows that the vehicle subsystem consists of 3 sets of cold standby and 9 sets of hot standby structures. Lifetime data for the same structure can be calculated multiple times by changing parameters of a single structure, further reducing the size of the SPN. Based on the above analysis, a simplification principle for SPN in SPN-MC is proposed:
[0057] 1. Remove instantaneous changes that do not affect the system's lifetime from the resource transfer path; 2. Represent the same structure with a set of models, and further reduce the dimension of the correlation matrix by increasing the number of loops in a simulation.
[0058] The simplified SPN model of the vehicle subsystem is as follows: Figure 12 As shown. In Figure 12 Based on this, considering the common cause failure of the hot standby structure and according to the simplified model of rule 2, as follows: Figure 14 As shown, only one set of hot standby and one set of cold standby considering CCF are included. The simulation of the remaining structures is completed by changing parameters and increasing the number of cycles.
[0059] MC simulation steps optimization: based on Figure 14 The specific steps of the Monte Carlo simulation are given.
[0060] Input item: Vehicle system lifespan tlife Simulation count N ;Identifier vector M j Transition vectors X , T Minimum time tmin ; Correlation matrix A. Wherein, M j It is an 11-dimensional column vector, with elements ( p 1, p 2, p 3, …, p 11 ) represents all the warehouses; T It is a 10-dimensional column vector, with elements ( t 1, t 2, t 3…, t 10 ) represents all changes; X It is a 10-dimensional column vector, with elements ( x 1, x 2, x 3, …, x 10 () indicates the number of times each transition occurs.
[0061] Initial assignment of loop variable: tmin =0; tlife =0; N =1; Initial identifier M 0 = (1, 0, 1, 1, 0, 0, 1, 1, 0, 0, 0); t i =0; X 0 = 0; j =0.
[0062] Step 1: According to M j Sure X The value is determined according to the following rules: in, x 1 = 1 if and only if p 1 ≠ 0, otherwise x 1 = 0; x 2 = 1 if and only if p 3 ≠ 0, otherwise x 2 = 0; x 3 = 1 if and only if p 2≠0 and p 3 ≠ 0, otherwise x 3 = 0; x4 = 1, if and only if p 4 ≠ 0, otherwise x 4 = 0; x 5 = 1 if and only if p 2≠0 and p 5 ≠ 0, otherwise x 5 = 0; x 6 = 1 if and only if p 7 ≠ 0, otherwise x 6 = 0; x 7 = 1 if and only if p 6 ≠ 0, otherwise x 7 = 0; x 8 = 1 if and only if p 8 ≠ 0, otherwise x 8 = 0; x 9 = 1 if and only if p 9≠0, otherwise x 9 = 0; x 10 =1, if and only if p 10 ≠0, otherwise x 10 =0.
[0063] Step 2: X elements x i correspond T elements t i Based on the value determined in the first step, the value is 1. x i The value is determined to be 1. x i corresponding t i .
[0064] Step 3: Check each one in step 2. t The value of the element; ift ≠0, then t = t - tmin If the value of t does not change in this iteration; t If the value is 0, proceed to the next step.
[0065] Step 4: In step 3, the value is 0. t Each element generates a random number representing its lifetime based on the distribution it follows.
[0066] Step 5: Assign the random number generated in step 4 to the corresponding... t i .
[0067] Step 6: In step 5 t Compare the elements and determine the one with the smallest value. t element" t m " and will t m value assigned to tmin .
[0068] Step 7: Confirm t m corresponding x m Elements, and make x m Equals 1, all others x All elements are 0; (if the smallest) t m If there are multiple, then the corresponding x m All = 1).
[0069] Step 8: Calculation: M (j+1) = M j +AX .
[0070] Step 9: tlife = tlife + tmin .
[0071] Step 10: Determine M (j+1) The 11th element p 11 If the value is not equal to 0, the program ends and outputs "". tlife Output all M Output all X Output all tmin ;if M (j+1) The 11th element p 11If the value is 0, then j = j +1; X All elements according to M (j+1) Re-determine.
[0072] Step 11: Assuming the program ends M vector is M j At this point, make the following judgment:
[0073] Step (1): If M (j-1) middle, p 10 If =1, then output "DMI-CSP=1"; the program ends. p 10 If =0, then proceed to step (2).
[0074] Step (2): In M (j-1) In the middle, if p 6=1, p If 7=0, then output "ATPCU-CCF=1"; the program ends; if p 6=1, p If 7=1, then the output will be "ATPCU-HSP=1", and the program will end. The number of simulations N remains unchanged, and we return to the first step.
[0075] The above steps complete a set of simulations considering both hot standby and cold standby of the CCF. Based on the above steps, the parameters are changed and the code is looped until the simulation of all units is completed.
[0076] Based on variables, when a fault occurs in a vehicle-mounted system simulating a fault transfer mechanism, the enabling transition is determined according to the current identifier, and lifetime data following the cell lifetime distribution is generated for the delayed enabling transition. The transitions include delayed and instantaneous transitions. Delayed transitions correspond to the lifetime distribution function of a specific cell, and the values generated based on this distribution represent the cell's operational lifetime. Instantaneous transitions only represent the upward transfer of the fault and do not involve the cell's lifetime. The number of tokens (black dots in the storage area) required for a transition is always 1. Therefore, when a token exists in a storage area, the transition corresponding to its arrow path is an enabling state, and the enabling state transition can transfer the token from the previous storage area to the next.
[0077] After acquiring lifetime data for all redundant subsystems, the minimum value is taken to obtain the system's lifetime value, i.e., determining the minimum lifetime value. The vehicle system status and accumulated time are then updated. The above steps are repeated until the vehicle system fails, at which point the vehicle system lifetime is recorded. This reduces the dimension of the correlation matrix compared to... Figure 13The advantages of the solution method of this invention, as described in the calculation steps, include three parts:
[0078] 1. When determining whether data needs to be generated for a transition, Figure 13 By defining a Boolean variable E j (Right now Figure 13 The present invention determines the sequence of occurrence of transitions by identifying the variables initialized in the Petri net, and directly determines whether the corresponding transition needs to generate data based on the sequence of occurrence of transitions. This fully utilizes the basic concepts in Petri nets and reduces the number of variables.
[0079] 2. Determine the enabling transition: Figure 13 The method is based on equation (14), observing whether the tokens in the input places meet the requirements of the weight function during the transition, and considering whether the output places have sufficient capacity to determine whether the corresponding transition occurs. However, in practical applications of Petri nets, it is generally not necessary to limit the capacity of the places, and whether a transition can occur can be determined solely by the number of tokens in the input places. Therefore, the transitions enabled in the current state can be determined solely by the state transition identifier. See step 1 for details.
[0080] 3. Figure 13 The proposed method only considers how to obtain system lifetime data, without analyzing the causes of system failures within that data. Statistical analysis of the failure frequency of each unit can identify units with high-frequency failures and pinpoint the system's weak points. Different units cause different transfer paths in the token when the system fails; therefore, the cause of each system failure can be determined based on identifying the faulty components. Figure 14 It can be seen that in the previous step of the final identification: if the repository p 10 If there is a token, the system failure is caused by the failure of the cold standby structure; if the warehouse... p There is a token in 6, and at the same time, the treasury. p If Token is not present in 7, then the system failure is due to a common cause failure of the hot standby structure; when p 6. p 7. If a token is also present, the system failure is caused by the failure of the hot standby structure. The method of this invention considers and statistically analyzes the faulty units that cause system failures, as detailed in step 11.
[0081] Program verification: Figure 14The correctness of the calculation is illustrated by taking the process of generating a set of lifetime data using the ATP-CU (Master Control Unit) and DMI as examples. For ease of analysis, the lifetime data (h) generated by all delay transitions in this simulation are given first: ATP-CU main component lifetime is 14888.15, spare component lifetime is 67088.70; ATP-CU common cause failure occurrence time is 34556893.02; DMI main component lifetime is 64941.78, spare component lifetime is 4682.67.
[0082] Substitute the data Figure 14 It can be seen that when the system starts working, the first batch of units put into use includes the primary and backup ATP-CU, the primary DMI unit, and the CCF; among them, HSP (Hot Standby Pattern) is the hot standby admittance circle, and CSP (Cold Standby Pattern) is the cold standby unit. Analysis shows that if both hot standby units fail, or if the CCF occurs, the system will fail directly. When the primary DMI unit fails (if the system is not yet failed at this time), the DMI backup unit is put into use in the second batch. Based on the generated unit lifetime values, it can be seen that among the units put into operation in the first batch, the ATP-CU primary unit has the shortest lifetime and will fail first. After the failure, the ATP-CU backup unit continues to work, and the system operates normally. At this time, the system (all units put into use in the first batch) has been running for 14888.15 hours.
[0083] After the initial failure, the remaining lifespan of all operational units is calculated by subtracting 14888.15 hours from their total lifespan. Comparing this to the remaining lifespan of the first batch of operational units, the DMI main unit was the second to fail (with the shortest remaining lifespan of 50053.63 hours), meaning the system continued operating for 50053.63 hours after the initial failure. After the failure, DMI spare parts were put into service in the second batch, and the system continued to operate normally.
[0084] The units that continued to operate after the second failure were the ATP-CU spare and the DMI spare. At this time, the remaining lifespan of the ATP-CU spare was: 67088.70-14888.15-50053.63=2146.92 hours; the remaining lifespan of the DMI spare was 4682.67 hours since it had just been put into use. Obviously, the unit that failed for the third time was the ATP-CU spare. Therefore, the system's operating time after the second failure was 2146.92 hours, and the entire system failed after the third failure.
[0085] In summary, the system lifespan is: 14888.15 + 50053.63 + 2146.92 = 67088.7 h.
[0086] The program operation process of the above analysis is as follows: ; Combination Figure 14 The program begins execution. Initial flags. M At 0, the enabling transitions are: t1, t2, t4, t6, and t8. These transitions generate random numbers representing the cell lifetime based on a distribution they follow. The transition with the smallest value (t1) will have the privilege of occurring. M Transition sequence under 0 X 0 is:
[0087] ; According to equation (15), we can obtain: ; The system accumulated 14888.15 hours of operation in the first step, but the program termination condition was not met, so the second step was initiated. The program iterated until a system failure occurred (in the library p). 11 (When the fault occurs), the time elapsed after the system failure is recorded. Figure 14 The shown is a lifetime value for the subsystem. Starting from the initial flag, the system undergoes 6 failovers. The transition sequence for each flag group is as follows:
[0088] ; The system state after each transfer is as follows: ; The time required for each step is: tmin =(14888.15, 0, 50053.63, 2146.92, 0, 0) T ; Output the calculation results: tlife = =67088.70; ATPCU-HSP=1.
[0089] It can be seen that the lifespan of the simulation system is 67088.7 hours, and the cause of the system failure is the failure of the hot standby structure ATPCU.
[0090] The above analysis proves the correctness of the program. By changing the parameters and analyzing the lifetime data generated by the remaining units one by one, the minimum value is taken from the data generated in each loop, thus obtaining the lifetime data of a system. It should be noted that the initial identifier remains unchanged in the first three simulations, but changes to the initial identifier in the fourth simulation (because the three sets of cold standby structures have already completed the simulation, therefore the identifier is changed). p 8. Tokens no longer occur, meaning the system no longer fails due to the cold standby structure. Starting from the fourth cycle, only one set of lifetime data for the hot standby structure is generated each time. Cycle count. NUsing 1000 as an example, the reliability analysis of the vehicle subsystem can be performed based on the obtained data.
[0091] The distribution of lifetime data obtained through SPN-MC is as follows: Figure 15 As shown, where Figure 15 The frequencies on the ordinate represent relative frequencies, indicating the probability that the lifetime falls within a certain range. The data sample is fitted using a Weibull distribution, and the results are as follows: Figure 16 As shown.
[0092] Analysis results considering only natural degradation, human factors, and simultaneously considering human factors and proactive switching strategies are as follows: Figure 17 As shown in the figure. Based on natural degradation, the system reliability decreases after considering human factors; adopting an active switching strategy can improve the system's operational reliability. While obtaining system lifetime data, the units with high failure frequencies were statistically analyzed, and the statistical results were compared with field statistics. The results are shown in the figure. Figure 18 As shown.
[0093] In summary, the lifespan distribution of the CTCS-3 level train control onboard subsystem of the EMU is mainly related to natural degradation. The success rate of personnel operation and the switching strategy of cold standby units can both affect the system's reliability; however, they do not affect the distribution type of the onboard system's reliability. Considering various factors, the onboard equipment follows a Weibull distribution with shape and dimensional parameters of 3.34 and 22071.12, respectively. Radio timeout is the most common type of failure; after a radio timeout occurs, the system will degrade its operation.
[0094] discuss: 1. Different structures are affected by different factors. Hot standby redundancy structures consider common cause failures; personnel reliability affects the human-machine interface; active switching strategies affect the reliability of cold standby redundancy structure units.
[0095] 2. Wireless timeout is the most common type of failure because failures in multiple units (Radio Management Unit, GSM-R antenna, Radio Station RSS) and the Radio Block Center (RBC) can prevent the system from operating in CTCS-3 mode. However, it can also be caused by non-fault reasons (entering a non-CTCS-3 section), resulting in degraded operation. In this case, the system can recover after leaving the section. In actual operation, it is necessary to distinguish between these causes.
[0096] 3. On-site statistical data recorded the number of driver misoperations, but research on the human-factor reliability of onboard equipment is limited, making it impossible to provide a probabilistic model for human factors. Only the probability of successful operation considering driver proficiency and environmental stress levels was calculated and applied to the reliability of the human-machine interface. The reliability of human operation is a crucial factor; the experience and condition of personnel can both affect normal operation.
[0097] This invention proposes a reliability analysis system for a train control vehicle subsystem, comprising: The system comprises several modules: a modeling module for modeling the lifespan of units in the vehicle-mounted equipment based on the Weibull distribution, obtaining the distribution function for each unit; the distribution function characterizes the unit reliability; a virtual quantization module for the cold standby structure of the vehicle-mounted equipment, employing an active switching strategy to switch between the primary and backup systems, and based on the distribution function, using virtual age quantification to obtain the unit reliability of the cold standby structure; where virtual age represents the actual age of the unit after maintenance; and a common-cause failure module for the hot standby structure of the vehicle-mounted equipment, using... β The factor model models common-cause failures, considers the impact of common-cause failures on redundant structures, and obtains the unit reliability of the hot standby structure based on the distribution function. The human error probability module is used to analyze the success probability of human operation through event tree analysis as the human error probability, and obtains the unit reliability of human error based on the human error probability using the distribution function. The model simulation module is used to build a stochastic Petri net model of the vehicle system based on the fault tree, and simulates the failure process of the vehicle system through the fault transfer mechanism based on the Monte Carlo method of the stochastic Petri net model and different unit reliability. The time required for unit failure and transfer is accumulated to obtain the life data of the vehicle system, and the reliability parameters of the vehicle system are obtained by analyzing the life data.
[0098] The present invention also provides a computer device, including a memory and a processor, wherein the memory stores a program, and when the program is executed by the processor, the processor performs the steps of a reliability analysis method for a train control vehicle subsystem.
[0099] According to the disclosed embodiments, the computer device can communicate with one or more external devices (e.g., keyboard, pointing device, Bluetooth communication, etc.) or with any device that enables the computing device to communicate with one or more other computing devices (e.g., router, demodulator, etc.).
[0100] The present invention also provides a storage medium storing a computer program thereon, characterized in that the computer program, when executed by a processor, implements the steps of a reliability analysis method for a train control vehicle subsystem.
[0101] According to the disclosed embodiments, the storage medium can be a non-volatile computer-readable storage medium, such as, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this invention, the storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0102] The above description, in conjunction with specific preferred embodiments, provides a more detailed explanation of the present invention. For those skilled in the art, various simple deductions or substitutions can be made without departing from the concept of the present invention, and all such deductions or substitutions should be considered to fall within the scope of protection of the present invention.
Claims
1. A reliability analysis method for a train control vehicle subsystem, characterized in that, include: The lifetime of units in vehicle-mounted equipment is modeled based on the Weibull distribution to obtain the distribution function of each unit; the distribution function characterizes the reliability of the unit. For the cold standby structure of vehicle-mounted equipment, an active switching strategy is adopted to switch between the primary and standby systems. Based on the distribution function, the impact of the active switching strategy on the unit reliability is quantified by virtual age to obtain the unit reliability of the cold standby structure; wherein the virtual age represents the actual age of the unit after maintenance. For the hot standby structure of vehicle-mounted equipment, use β The factor model models common cause failures, considers the impact of common cause failures on redundant structures, and obtains the unit reliability of the hot standby structure based on the distribution function. The success probability of human operation is analyzed by event tree analysis as the probability of human error, and the unit reliability of human error is obtained by using the probability of human error based on the distribution function. A stochastic Petri net model of the vehicle system is established based on the fault tree. Based on the Monte Carlo method of the stochastic Petri net model and the reliability of different units, the failure process of the vehicle system is simulated through the failure transfer mechanism. The time required for unit failure and transfer is accumulated to obtain the life data of the vehicle system. The reliability parameters of the vehicle system are obtained by analyzing the life data.
2. The reliability analysis method for a train control onboard subsystem as described in claim 1, characterized in that, The impact of the active switching strategy based on virtual age quantization on unit reliability is as follows: Obtain the unit's lifespan without considering maintenance. kd and continues to work in the unit. n Each duration is d After a certain period of time, obtain the unit's working age. nd ; After actively switching, the actual age becomes the virtual age; the specific expression for the virtual age is as follows: ; in, w ( d (This refers to a virtual age.) x For cold storage standby time, z The recovery factor is the factor where the working time and the reserve time are equal. d=x ; Failure rate function and reliability function of the unit The relationship is specifically expressed as: ; The failure rate function of the Weibull distribution of the cell is obtained by combining the probability density function and the reliability of the cell. The specific expression is as follows: ; in, Let be the failure rate function of the Weibull distribution. α , For the parameters of the Weibull distribution, t This refers to the unit's runtime. The reliability of a cold standby cell under an active switching strategy is obtained by combining virtual age, cell reliability, and the failure rate function of the Weibull distribution. The specific expression is as follows: ; Among them, 1 represents the unit serial number; t is the running time of the unit; d is the switching time interval; n is the number of continuous working hours of the unit; i represents the number of continuous working hours of the unit n in the i th, which is a quantity unit; is the failure rate function of the Weibull distribution; u is the integration variable; is the reliability of the cold standby unit under the active switching strategy.
3. The reliability analysis method for a train control onboard subsystem as described in claim 1, characterized in that, The use β The factor model models common-factor failures, considers the impact of common-factor failures on redundant structures, and obtains the unit reliability of the hot standby structure based on the distribution function. Specifically: Obtained by the proportion of failure probability due to common causes in the total failure probability. β The factor, specifically expressed as: ; in, for β Factors, without subscripts β The parameters representing the Weibull distribution, This represents the probability of natural failure. For the probability of failure due to common factors, These are the parameters in the expression for the probability of failure due to common factors. For scale parameters, t This refers to the unit's runtime. The probability of system failure due to common cause is represented by an exponential distribution, and then... β CCF Solve for the parameters of failure due to common cause; the specific expression for the probability of failure due to common cause is: ; in, F CCF ( t ) represents the probability of common cause failure occurring.
4. The reliability analysis method for a train control onboard subsystem as described in claim 1, characterized in that, The success probability of human operation is analyzed through event tree analysis as the probability of human error, and based on the distribution function, the unit reliability of human error is obtained through the probability of human error, specifically as follows: The probability of successfully obtaining speed control tasks The specific expression is: ; in, , and Each represents the probability of a successful sub-action. The probability of success (HEP) for each sub-action is determined by consulting the human factors manual. This probability is used as the probability of human error, and its specific expression is as follows: ; Wherein, BHEP is the probability of error in the operator's unit action, known as the basic human error probability, and PSF is the human behavior formation factor that modifies HEP. Reliability considering natural degradation R ( t h Generate DMI unit reliability that takes into account personnel reliability. R DMI ( t The specific expression is: 。 5. The reliability analysis method for a train control onboard subsystem as described in claim 1, characterized in that, The establishment of a stochastic Petri net model for the vehicle system based on the fault tree is specifically as follows: A stochastic Petri net model of the vehicle system is established based on the fault tree; the fault tree logic gates include AND gates, OR gates, hot standby gates and cold standby gates, where the hot standby gates and cold standby gates correspond to specific SPN structures to represent the fault logic of redundant units.
6. The reliability analysis method for a train control onboard subsystem as described in claim 1, characterized in that, The Monte Carlo method based on the stochastic Petri net model and different unit reliability levels simulate the failure process of the vehicle system through the failure transfer mechanism, and obtain the vehicle system's lifetime data by accumulating the time required for unit failure and transfer. Specifically: Initialize variables, including the lifespan of the vehicle system. tlife Simulation times N Identifier vector M j Transition vectors X and T Minimum time tmin Correlation matrix A; Based on the aforementioned variables, when a fault occurs in the vehicle system during the fault transfer mechanism simulation, the enabling transition is determined according to the current identifier, and lifetime data that follows the cell lifetime distribution is generated for the delayed enabling transition; wherein, the transition includes delayed transition and instantaneous transition, the delayed transition corresponds to the lifetime distribution function of a specific cell, and the value generated according to this distribution represents the working lifetime of the cell, while the instantaneous transition only represents the upward transfer of the fault. Determine the minimum lifespan value and update the vehicle system status and cumulative time; Repeat the above steps until the vehicle system fails, and record the vehicle system lifespan.
7. The reliability analysis method for a train control onboard subsystem as described in claim 1, characterized in that, During Monte Carlo simulation, the causes of system failures are determined based on the indicators before the failure, including failure of cold standby structures, failure of hot standby structures, or failure due to common factors. The failure frequency of each unit is also counted to identify the weak points of the system.
8. A reliability analysis system for a train control onboard subsystem, characterized in that, include: The modeling module is used to model the lifetime of units in the vehicle-mounted equipment based on the Weibull distribution to obtain the distribution function of each unit; the distribution function characterizes the reliability of the unit. The virtual quantization module is used to switch between the primary and backup systems of the cold standby structure of the vehicle equipment using an active switching strategy. Based on the distribution function, it quantifies the impact of the active switching strategy on the unit reliability through virtual age to obtain the unit reliability of the cold standby structure; wherein the virtual age represents the actual age of the unit after maintenance. Common-cause failure module, used for hot standby structure of vehicle equipment, using β The factor model models common cause failures, considers the impact of common cause failures on redundant structures, and obtains the unit reliability of the hot standby structure based on the distribution function. The Human Error Probability module is used to analyze the success probability of human operations through event tree analysis, which is used as the human error probability. Based on the distribution function, the unit reliability of human error is obtained through the human error probability. The model simulation module is used to establish a stochastic Petri net model of the vehicle system based on the fault tree, and simulate the failure process of the vehicle system through the fault transfer mechanism based on the Monte Carlo method of the stochastic Petri net model and different unit reliability. The time required for unit failure and transfer is accumulated to obtain the life data of the vehicle system, and the reliability parameters of the vehicle system are obtained by analyzing the life data.
9. A computer device, characterized in that, The system includes a memory and a processor, wherein the memory stores a program that, when executed by the processor, causes the processor to perform the steps of the reliability analysis method for a train control vehicle subsystem as described in any one of claims 1 to 7.
10. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the reliability analysis method for a train control vehicle subsystem according to any one of claims 1 to 7.