Automatic pulling method and system for turnout leading to safety line
By adding a safety line turnout business module to the CTC system, the system automatically monitors the route sequence status and sends a triggering command to the interlocking system when the conditions are met. This solves the problem of relying on manual operation for safety line turnouts, realizes automated, safe and reliable triggering control, and improves the level of intelligence in railway transportation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SIGNAL & COMM RES INST OF CHINA ACAD OF RAILWAY SCI
- Filing Date
- 2026-03-23
- Publication Date
- 2026-05-12
AI Technical Summary
In the existing technology, the operation of turning switches leading to the safety line mainly relies on manual monitoring and operation, which results in a large workload. The timing of the turnout operation depends on manual judgment, which may lead to the turnout not being reset in time, posing a safety hazard. Moreover, it does not conform to the trend of automation and intelligent development of railway transportation.
In the station self-regulatory machine subsystem of the CTC system, by adding a safety line turnout business module, the route sequence status is automatically monitored and a switching command is sent to the interlocking system when the conditions are met. Combined with logic such as "delay confirmation after turnout clearance" and "judgment of the next plan trigger time interval", automatic switching is realized, and alarm information is generated in abnormal situations.
It achieves automated operation, reduces manual labor intensity, accurately grasps the timing of operation, improves operating efficiency and equipment lifespan, establishes a complete abnormal handling and safety redundancy mechanism, optimizes human-machine interaction, reduces invalid alarm interference, and adapts to reliable operation under high-density operating conditions.
Smart Images

Figure CN122009282A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method and system thereof, and more particularly to an automatic switching method and system for turnouts leading to safety lines, belonging to the field of railway traffic dispatching and control technology. Background Technology
[0002] Turnouts are crucial equipment in the construction of railway networks and stations, densely arranged in the "throat areas" of stations, connecting arrival / departure tracks, marshalling tracks, and freight tracks. Their core function is to guide locomotives and rolling stock from one track to another, enabling trains to enter different platforms and tracks for operations. Turnouts are fundamental to the branching control of railway traffic routes, providing operational functions such as train switching, marshalling, passing, and overtaking. They are one of the most critical and basic pieces of equipment on railway lines. Turnouts control the direction of traffic by changing the position of the switch rails, i.e., the fixed and reverse opening positions of the turnout. The fixed position of the turnout refers to the position where the turnout is normally open, usually the path for trains to pass in a straight line; the reverse position refers to the other open position temporarily switched to as needed, usually the path for trains to pass through a curve. The principles for setting turnout positions include straight track priority, safety guidance, and operational standards. In some stations, the primary consideration for setting turnout positions is the protective function under the safety guidance.
[0003] To prevent trains from overstepping station exit signals, entering other occupied tracks, or running off track, a dead-end line, also known as a safety line or refuge line, is installed at the end of a railway line or in a throat area. The turnout leading to this safety line is called a "safety line turnout." These turnouts are positioned with safety as the guiding principle and should normally be open in the direction leading to the safety line (positioning). This allows trains or trainsets that cannot stop safely on the main line to be guided to the designated safe line, preventing more serious accidents. Safety line turnouts are commonly found at station entrances on steep downhill slopes, on complex hub lines or marshalling yards, and on turnouts leading to important facilities or special sections. They are an important manifestation of the in-depth defense safety concept in railway transportation organization.
[0004] The Centralized Train Control (CTC) system, acting as a train operation command and control system, allows operators to centrally control turnouts to arrange train routes in daily operations. The CTC system and turnouts form a "brain and arm" relationship, automating and intelligently controlling train operations through the station's computer interlocking system. In daily transport, turnouts leading to the safety line need to be switched to the reverse position at specific times according to the route sequence generated by the phased plan to open the permission signal; after the train departs, the turnout should be returned to the correct position (safety line direction) according to station rules and safety regulations. This frequent switching between the correct and reverse positions currently relies primarily on manual operation.
[0005] In existing technologies, the following technical means are mainly adopted for the operation of switching turnouts leading to the safety line: Existing technology 1: The operator constantly monitors the "safety line turnout not in position" warning light status set by the interlocking system. After a train passes and clears the route, the turnout is in the reverse position and the warning light illuminates. The operator manually operates the turnout to return it to the correct position at an appropriate time. This solution relies entirely on manual operation, and the process needs to be repeated for each train. On busy lines, the operator's workload is heavy, and the timing of the operation depends entirely on manual judgment. Relying solely on the warning light can easily lead to insufficient attention, resulting in the turnout not being reset in time, posing a safety hazard.
[0006] Existing technology two: Based on technology one, the CTC system monitors the status of interlocking alarm lights and converts them into more prominent text and voice alarms to enhance the alert effect. However, subsequent turnout operation is still performed manually. Although this solution improves the visibility of alarms, it does not change the underlying logic of relying on manual operation. In stations with high traffic volume, alarm information is easily buried among numerous traffic alarms, which may still lead to delays or omissions in turnout operation, and safety hazards still exist.
[0007] Existing research solutions: Relevant literature such as "Analysis of Safety Line Configuration Conditions in Urban Rail Transit", "Discussion on Equipment Layout of Passenger Dedicated Line Stations", and "Research on the Interface between Railway Station and Signaling Engineering Design" mainly focus on the layout conditions of safety lines, station equipment design, or the interface between station and signaling engineering, without addressing the automatic control of turnouts leading to safety lines. "Discussion on Safety Line Turnout Design" proposes a solution from the perspective of circuit design and safety linkage of protective turnouts, but still clearly states that under the 6502 interlocking system, it must be manually operated by the duty officer to the correct position; "Electric Control Modification of Turnout No. 14 at Lulou Station" only changes the on-site manual turnout operation to indoor button control, and the timing and operation of the operation still rely entirely on manual intervention.
[0008] In summary, none of the existing research and implementation solutions mentioned above address the automatic operation of turnouts leading to the safety line. They primarily rely on manual monitoring and operation, which has the following drawbacks: 1. Manual operations are highly repetitive and have a heavy workload, which can easily lead to operator fatigue and negligence on busy lines; 2. The timing of the switch operation relies on manual judgment, and the prompting methods are limited or easily overlooked, which can easily lead to untimely or missed switch resets. 3. The uncontrollability of manual intervention increases the risk to train operation safety, which is inconsistent with the development trend of automation and intelligence in railway transportation.
[0009] Therefore, there is an urgent need for a technical solution that can automatically monitor and operate turnouts leading to safety lines within a CTC system, in order to improve operational efficiency, reduce manual labor intensity, enhance train operation safety, and adapt to reliable operation under high-density train operation conditions. This invention is proposed against this backdrop. Summary of the Invention
[0010] To address the shortcomings of existing technologies, this invention discloses an automatic switching method for turnouts leading to safety lines, the technical solution of which is as follows: An automatic switching method for turnouts leading to safety lines, applied to the station autonomous machine subsystem of a centralized railway traffic control (CTC) system, is characterized by the following steps: S1: Monitor the status of the route sequence associated with the turnout leading to the safety line; S2: In response to determining that the route sequence has been cleared, initiate the monitoring and switching logic for the turnout leading to the safety line; S3: During a preset monitoring period after the route sequence is cleared, continuously check whether the conditions for moving the turnout to the safety line to the safe position are met. S4: When all the aforementioned turning conditions are met simultaneously, send a single-operation command to the interlocking system to turn the turnout leading to the safety line to the safe position; S5: Monitor the execution result of the single operation command or monitor whether the toggle operation is successfully executed within the preset monitoring period; S6: When the single operation command times out or the trigger operation is not performed by the end of the preset monitoring period, an alarm message is generated to prompt manual intervention.
[0011] This invention also discloses a station self-regulating machine subsystem of a CTC system that implements the above-described automatic triggering method, characterized in that it includes: The driving control module is used to generate and process route sequence status; The display control module is used to cache and provide station display data, including the status data of the turnout leading to the safety line; The safety line turnout service module is used to realize the automatic monitoring and operation functions of the turnout leading to the safety line; The safety line turnout service module is isolated from the train control module and the display control module, and only receives route sequence status data from the train control module and station display data from the display control module in one direction. The safety line turnout service module determines whether the operating conditions are met based on the received data, and generates turnout single operation command data when the conditions are met. Beneficial effects
[0012] 1. Automated operation is achieved, significantly reducing manual labor intensity and operational risks: This invention adds an independent safety line turnout business module to the station's automated control subsystem. This module automatically monitors the route sequence status and turnout position, and automatically sends a command to the interlocking system to move the turnout to its designated position when safety conditions are met. This completely changes the existing technology's reliance on manual monitoring, judgment, and operation by operators, freeing them from repetitive and mechanical monitoring and turning tasks. It directly reduces their workload and mental stress, avoiding problems such as "missed turns, late turns, and incorrect turns" caused by human fatigue, negligence, or oversight, fundamentally improving operational safety and reliability.
[0013] 2. Precise timing of switching operations improves train operation efficiency and equipment lifespan: The switching condition logic proposed in this invention introduces two key time parameters: "CleanSec confirmation after turnout clearing" and "Next plan trigger time interval judgment (NextRepTime)". The former ensures that switching is performed only after the turnout state is stable, avoiding command failures or equipment conflicts caused by state transitions; the latter can intelligently judge subsequent train plans and merge unnecessary frequent switching operations during peak train operation periods. This not only ensures smooth and continuous train operation and avoids the efficiency problem of subsequent route arrangement being affected by turnout switching, but also greatly reduces the number of unnecessary turnsout movements between fixed and reverse positions, effectively extending the service life of turnout switching equipment and reducing maintenance costs.
[0014] 3. A complete anomaly handling and safety redundancy mechanism has been constructed to ensure the robustness of the solution: This invention designs a dual protection mechanism of "command timeout monitoring" and "state timeout monitoring". Whether the command timeout is caused by an abnormality in the interlocking system or the state timeout is caused by the failure of the CTC system's logical judgment to trigger the switch, the system can promptly detect and automatically escalate it to a clear alarm requiring manual intervention. This design ensures that the safety hazard of "the switch leading to the safety line not being reset in time" will not be silently ignored in any abnormal scenario. The system can always provide a final safety backup measure, realizing closed-loop safety management of the entire operation process and greatly improving the reliability and coverage of the entire solution.
[0015] 4. Minimal impact on system modification, high integration, and ease of implementation and promotion: The technical solution of this invention strictly adheres to the principle of "no large-scale modification to the core structure and data flow of the existing CTC system." It only requires adding a safety line turnout business module with independent business logic and a unidirectional data interface within the station's autonomous control subsystem. This module is securely isolated and functionally decoupled from the core train control module, ensuring that existing safety operations are unaffected. This modular and loosely coupled design makes the construction and upgrade of this solution convenient and quick, with minimal interference to existing operations and low economic and time costs. Furthermore, this design has strong adaptability and scalability, and can be easily integrated into various existing centralized dispatch control systems, facilitating rapid promotion within the railway industry and improving the overall intelligence level of railway transportation command.
[0016] 5. Optimized human-machine interaction and reduced interference from invalid alarms: By adapting and modifying the monitoring logic of the original interlocking "safety line turnout not in position" alarm light in the CTC system (such as disabling the upper-level alarms triggered by it), this invention, after implementing the automatic activation function, can effectively reduce repetitive and inefficient alarm information based on this alarm light that interferes with the operator on the control panel. This allows the operator to focus more on other critical train operation alarms and abnormal situations, optimizing the human-machine interface and improving monitoring efficiency. Attached Figure Description
[0017] Figure 1. Structure of the station's self-regulating machine system; Figure 2. Flowchart of the automatic turnout switching scheme leading to the safety line. Detailed Implementation Example 1
[0018] See Figure 1-2 As shown, the automatic switching method for turnouts leading to safety lines provided by the present invention is implemented through the following steps. Each step incorporates specific technical designs to address key deficiencies in the prior art and achieve automated, safe, and reliable switching control.
[0019] S1: Monitor the status of the route sequence associated with the turnout leading to the safety line.
[0020] The monitored object is the "route sequence," which is generated and maintained by the train control module in the station automation subsystem of the CTC system. Based on the train operation phase plan issued by the dispatch center, the train control module automatically creates the corresponding route sequence data object. Each route sequence is a structured logical entity, whose core data fields include: a unique sequence identifier, associated planned train number information, a route description defining the planned train route (clearly listing the starting signal, ending signal, all involved track sections, and turnout equipment numbers), and a key state variable. This state variable is a discrete enumeration value used to precisely indicate the stage of the route sequence in its execution lifecycle. Typical states include: "Waiting for trigger," indicating that the plan has been generated but the execution time has not yet arrived; "Triggered," indicating that the autonomous machine has made a judgment based on the plan logic and sent a route arrangement command to the station computer interlocking system; "Occupied," indicating that the train has entered the route and the relevant track section and switches have been locked by the interlocking system; and "Cleared," indicating that the train has completely left the route, all sections are now free, and the interlocking has been released. Therefore, the monitoring in this step is essentially a continuous state tracking of these dynamically changing logical objects within the train control module that are strictly bound to the execution of the train plan.
[0021] To obtain the status information of the aforementioned route sequences, this invention adds an independent safety line turnout service module within the station's automated control subsystem. This module continuously acquires route sequence status data from the train control module through a predefined and unidirectional internal data communication interface. The data interaction can be implemented using either an event-driven or periodic query mode. In event-driven mode, when the status of any route sequence it maintains changes, the train control module proactively notifies the safety line turnout service module of an event message containing the sequence identifier and the new status. In periodic query mode, the safety line turnout service module sends requests to the train control module at fixed short intervals (e.g., every second) to obtain the latest status snapshot of all active route sequences. Regardless of the mode used, the technical essence lies in the safety line turnout service module acting as a data consumer, continuously receiving or retrieving processed route sequence status information provided by the authoritative source, the train control module.
[0022] Upon receiving the route sequence data stream, the safety line turnout service module immediately executes a parsing and matching process. Internally, the module accesses its configuration file, which pre-stores a set of device numbers defined as "leading to the safety line turnout." The module parses the path description field of each received route sequence, comparing the included turnout numbers with this predefined set. Only when the parsing reveals that a route sequence contains at least one turnout number belonging to this predefined set is the route sequence identified as "related" to the safety line turnout and formally added to the internal monitoring list maintained by the safety line turnout service module for subsequent continuous status tracking and conditional judgment.
[0023] The core difference between this approach and existing technologies, and its innovativeness, lies in its choice to monitor the route sequence status generated and maintained by the train control module, rather than directly monitoring the physical position information of the turnouts fed back by the interlocking system. Existing solutions, whether relying on manual observation of warning lights on the control console or the CTC system converting warning light status into more prominent alarms, essentially rely on the real-time physical position of the turnouts as the underlying data source for monitoring and judgment. This direct monitoring mode has an inherent flaw: the system cannot distinguish whether the turnout being in the reverse position is due to automatic interlocking switching during train scheduling or due to manual operation by the operator during equipment maintenance, testing, or other unplanned tasks. If automatic switching decisions are made based on this raw state information that cannot distinguish intent, incorrect switching commands may be issued during legitimate maintenance operations (such as switching the turnout to the reverse position for maintenance). Such erroneous actions not only lead to command execution failures but also interfere with normal maintenance work and may even pose a safety threat to on-site personnel, while also violating the safety principle of prioritizing manual operation.
[0024] This step effectively avoids the aforementioned problems by monitoring the status of a higher-level "route sequence" that is strictly tied to the train operation plan. A route sequence is a logical object automatically generated and managed by the CTC system to execute a specific train operation plan, and its state transitions strictly correspond to a planned train operation process. Therefore, marking a route sequence as "triggered" or "occupied" clearly means that the turnout leading to the safety line in that sequence path was moved from its original position due to a planned train operation requirement. Conversely, if a turnout is reversed due to manual operation, no associated route sequence will be in a "triggered" or "occupied" state indicating a train operation. In this way, the safety line turnout business module achieves precise filtering of business scenarios at the data source level, ensuring that its subsequent automatic turning logic only targets those situations requiring reset due to normal train operation. This fundamentally avoids accidental activation of turnouts due to unplanned manual operation, thus strictly guaranteeing the safety and accuracy of operation while achieving automation. This technological approach, designed to enable the automatic triggering function to intelligently recognize operational intentions, is key to achieving high reliability and distinguishing this method from existing pure condition monitoring solutions, demonstrating significant advancements.
[0025] Step S2: In response to determining that the route sequence has been cleared, the monitoring and switching logic for the turnout leading to the safety line is initiated, and the specific implementation is as follows.
[0026] The triggering basis for this step comes from the continuous tracking of the relevant route sequence status by the safety line turnout service module in step S1. When the safety line turnout service module obtains an update of the status variable of a monitored "relevant route sequence" through its data interface with the train control module, and the value of the status variable changes from "occupied" to "cleared", it completes an operation of "determining that the route sequence has been cleared". The "cleared" status is a clear logical signal, which is generated and issued by the train control module after making a logical judgment based on the track section occupancy information fed back by the interlocking system. The establishment of this status means, at the business level, that the train of the corresponding scheduled number has completely left the route, and at the safety level, it indicates that the interlocking system has released the lock on the route, and all track sections and turnouts under the jurisdiction of the route (including turnouts leading to the safety line in the path) have been released from train occupancy, restoring the conditions for operation.
[0027] Once a "route sequence has been cleared" determination is made, the safety line turnout service module immediately initiates an independent "monitoring and activation logic" for one or more turnouts leading to the safety line associated with that specific route sequence. The activation of this logic does not immediately execute the activation operation; rather, it signifies that the system has entered a dedicated processing flow to prepare for automatic activation. The specific software-level implementation of this activation operation can be: creating an independent logic processing instance or task for the route sequence, or setting a specific "to be monitored and activated" flag for the sequence and its associated turnouts in its internal status table. Simultaneously, the system records or generates a timestamp corresponding to the moment this logic is activated. This timestamp serves as the absolute reference point for calculating various time intervals (such as turnout clearing duration and monitoring period) in subsequent steps.
[0028] Using "routes sequence clearing" as the sole and mandatory prerequisite for initiating subsequent automatic switching logic is an inevitable choice based on the fundamental principles of railway signal safety and existing operating procedures. According to station rules and safety regulations, switches leading to the safety line should normally be switched to their designated position after a train has departed. Technically, the interlocking system only allows switch conversion operations on switches within a route after the route has been "cleared." If the switching logic is attempted while the route is still in an "occupied" locked state, or only in a "triggered" state before the train has fully passed, any issued switch conversion command will be directly rejected by the interlocking system's safety logic. This is because the switch is still locked by the train route, and forced conversion would lead to a serious traffic safety accident. Therefore, using "routes sequence clearing" as the initiation trigger is not a simple timing choice, but rather a strict limitation of the automatic switching function to the safe operating time window allowed by the interlocking system. This ensures that the automation logic is built upon an existing, mature safety system framework from the outset, avoiding conflicts with underlying safety interlocking principles.
[0029] If "routes sequence clearing" is not explicitly defined as a trigger condition, the automatic triggering logic will lose its fundamental safety timing benchmark. For example, if the system is designed to begin monitoring and waiting for triggering as soon as the routes sequence is "triggered" or a train enters, it will face the problem of being unable to accurately perceive the actual operating status of the train or determine when the safety operation window opens. This could easily lead to the generation of invalid or even dangerous commands at incorrect times, resulting in functional failure or safety risks. Therefore, the purpose of this step is to establish a safe, clear, and compliant "logical starting point" and "timing benchmark" for the entire automatic triggering method, ensuring that all subsequent judgments and operations are carried out under the premise that safety conditions have been met. This is the cornerstone for ensuring the overall safety and feasibility of the solution.
[0030] Step S3: During a preset monitoring period after the route sequence is cleared, continuously check whether the conditions for switching the turnout leading to the safety line to a safe position are met.
[0031] In this step, during a preset monitoring period after the route sequence is cleared, it is continuously checked whether the conditions for switching the turnout leading to the safety line to the safe position are met. This is specifically implemented in the following way.
[0032] This step begins with the logic and time baseline established in step S2. After confirming the route sequence is cleared and initiating the monitoring and triggering logic, the safety line turnout service module enters a preset, finite time window to continuously assess a set of complex conditions for the turnouts leading to the safety line associated with the route sequence, either cyclically or through event triggering. This preset monitoring period (e.g., starting from the time the route sequence is cleared and continuing for 120 seconds thereafter) is a configurable time boundary. Its purpose is to provide a reasonable operating window for automatic decision-making and prevent the system from being suspended indefinitely due to prolonged non-compliance of individual conditions.
[0033] The core of continuous monitoring is a multi-parameter collaborative trigger condition judgment logic. All conditions must be met simultaneously before the system can execute subsequent automatic trigger commands. These conditions and their technical implementation details are as follows: The first condition is determining whether the turnout leading to the safety line is currently in a safe position. This check is achieved by the safety line turnout service module receiving real-time station display data from the display control module. This display data contains the real-time position information (fixed / reverse) of all turnouts in the station. The safety line turnout service module extracts the position status of the target turnout from this data. If it is already in the correct position (i.e., in the safety line direction), it determines that no action is required, and the monitoring process ends. This check is a fundamental prerequisite, ensuring that the automatic function is activated only when the turnout has actually deviated from the safe position.
[0034] The second condition requires that the turnout leading to the safety line has been physically cleared for more than a first preset time threshold (CleanSec, e.g., 6 seconds). This check introduces a crucial delay confirmation mechanism. Its implementation principle is as follows: the safety line turnout service module not only obtains the logical position of the turnout but also the occupancy status of its track section. "Physically cleared" means that the track section where the turnout is located has been confirmed as idle by the interlocking system. Timing begins when the safety line turnout service module first detects from the station display data that the target turnout section status has changed from "occupied" to "idle". The system will continuously time and determine whether the duration of this idle state has exceeded the CleanSec value set in the configuration file (the value range is, for example, 3-180 seconds). This mechanism is designed to address the possible brief state fluctuations or response delays that may occur in track circuit equipment after the train wheelset leaves. If a sufficient stabilization period (CleanSec) is not waited for after the turnout section becomes idle, and instead an attempt is made to switch immediately at the moment of the state change, the interlocking system is very likely to refuse to execute the switching command because it detects that the section is "instantaneously occupied" or "unstable," resulting in operation failure. The introduction of the CleanSec parameter ensures that the system considers the turnout section to be in a truly safe and switchable physical state only after it has experienced a configurable and stable idle period. This greatly improves the success rate of automatic turnout commands and avoids invalid operations and system disturbances caused by equipment response characteristics.
[0035] The third condition is to confirm that there are no single-lock, single-seal, or other equipment restrictions preventing the turnout from being operated. This check is also based on real-time station display data obtained from the display control module. The interlocking system reflects the single-lock (for maintenance protection, prohibiting any switching) and single-seal (for construction, etc., prohibiting operation) restrictions imposed on the turnout in real time in the display information. The safety line turnout business module verifies whether the target turnout is marked with such a restriction in each condition check cycle. If any restriction is detected, the automatic operation logic for that turnout in this round is immediately stopped. This condition demonstrates absolute respect for the priority of manual operation on site and the safety status of the equipment. On the railway site, a single-lock or single-seal turnout usually means that maintenance personnel are working on the track. In this case, any automatic operation attempt from the system is not only ineffective but may also pose a serious threat to the personal safety of on-site personnel and interfere with the established maintenance plan. By making this condition a mandatory check item, we ensure that the automated logic can proactively and safely exit when it encounters a clear scenario requiring human intervention, and completely return control to the on-site personnel. This is the core guarantee for achieving safe human-machine collaboration.
[0036] The fourth condition is that the time interval between the trigger time of the next planned route sequence using the turnout to the safety line and the time interval between the trigger time and the trigger time is greater than the second preset time threshold (NextRepTime, e.g., 180 seconds). This check reflects the intelligent optimization and foresight of the solution. Its implementation relies on the route sequence data provided by the train control module. The safety line turnout service module needs to access all generated route sequence plans for a future period (e.g., the next 10 minutes). It filters out subsequent route sequences that contain the current target turnout and are in the "waiting to trigger" state. Then, it calculates the time difference between the current time and the planned trigger time of the most recent one among these subsequent sequences. If this time difference is less than or equal to the NextRepTime value in the configuration file, this condition is not met. The fundamental reason for introducing this condition is to deal with periods of high train traffic. If the turnout is mechanically switched back to its original position immediately after each train clears, and subsequent trains are planned to pass through this turnout again in a short period of time (e.g., tens of seconds later), this will cause the turnout to perform an ineffective reciprocating action of "reversed → positioned → reversed" in a very short time. Frequent mechanical switching not only exacerbates wear and tear on equipment such as turnout switch machines, shortening their service life and increasing maintenance costs, but more importantly, it may cause command conflicts during the automatic turning and positioning of the turnout, potentially leading to route triggering for subsequent trains. This can result in route scheduling failures or delays, directly impacting train operation efficiency. The NextRepTime parameter setting allows the system to anticipate future needs for reuse within a short period. When reuse is anticipated, the system temporarily keeps the turnout in the reverse position, merging two consecutive switching requests. This avoids meaningless equipment actions and potential train interference, significantly improving equipment utilization and operational smoothness while ensuring safety.
[0037] In summary, this step constructs a decision-making core that balances security (conditions one, two, and three), reliability (condition two), and intelligent efficiency (condition four) by continuously and cyclically making joint judgments on the above four conditions within a preset monitoring period. The design of this composite condition judgment logic is the key technology that enables this method to replace manual operation and achieve safe, reliable, and efficient automatic operation.
[0038] S4: When all the aforementioned turning conditions are met simultaneously, a single-operation command is sent to the interlocking system to turn the turnout leading to the safety line to the safe position.
[0039] This step is triggered by a positive logic judgment obtained by the safety line turnout service module after continuously cyclically checking the four activation conditions described in step S3 within its preset monitoring period. Once the module confirms within a certain inspection cycle that the target turnout leading to the safety line is not currently in a safe position, has been physically cleared for more than the first preset time threshold, does not have any single lock or single seal equipment restrictions, and the time interval between the trigger time of the next planned route sequence is greater than the second preset time threshold, the module immediately terminates the cyclical inspection process and enters the command generation and issuance stage.
[0040] The core technology for command generation and issuance involves assembling a complete turnout single-operation command data packet according to a predetermined, standard turnout control command data format, and then transmitting it to the interlocking system via the existing data processing and communication links within the station's automated control subsystem. The specific process is as follows: First, the safety line turnout service module generates the raw data content for the command. Based on its configuration information and current inspection results, this module determines the turnout equipment number requiring operation (e.g., turnout #1) and the target position (location) it needs to switch to. Then, following the structured data format defined within the automated control subsystem—the same format used by the train control module when generating manual operation commands—the module assembles a command data object containing key fields such as command type identifier (turnout operation), target equipment identifier, target position, and timestamp. This step ensures that the automatically generated command has consistent semantics and format at the data level with manually triggered commands, laying the foundation for subsequent compatibility processing.
[0041] Secondly, the generated raw command data objects are submitted to the basic data module within the station's automated control system for processing. The basic data module is responsible for data formatting, conversion, and protocol encapsulation. This processing includes serializing the internal data objects into a byte stream conforming to the underlying communication protocol requirements, and adding necessary frame headers, checksums, session identifiers, and other information according to the application layer protocol agreed upon with the interlocking system, forming a complete application layer protocol data unit suitable for network transmission. This conversion process is crucial, as it ensures that the control intentions generated by the new business modules can be adapted to the existing, mature standard communication protocol between the CTC system and the interlocking system.
[0042] Finally, the encapsulated protocol data unit is passed to the underlying communication module. The underlying communication module is responsible for network layer communication management. It sends the data unit to the station extension server through existing, physically and logically independent communication channels (such as dedicated network interfaces) according to a preset communication sequence and interaction process (such as request-response mode), and the extension server then forwards it to the target interlocking system. The entire command issuance path reuses the existing, securely authenticated, and long-term proven command issuance channels of the CTC system, without involving the construction of new physical links or modifications to the underlying protocol.
[0043] The key design element of this step is the adoption of a standard "single-operation command" format and its issuance through existing channels. The interlocking system is designed with mature logic for receiving and processing such commands. Upon receiving this command, the interlocking system's safety computer will initiate a rigorous set of interlocking condition checks, just as it would for a single-operation command manually issued by a CTC operator. These checks include, but are not limited to: reconfirming that the target turnout section is free, that the turnout is not locked by the route, that the turnout is not manually locked or sealed, and that the command conforms to the safety interlocking logic of the current station status. Only after passing all internal safety checks will the interlocking system drive the corresponding turnout switch machine to perform the physical conversion action. This design means that the ultimate execution authority and safety verification responsibility for the automatic switching function implemented in this invention still rest entirely with the interlocking system, which has the highest safety integrity. The newly added safety line turnout business module only plays the role of an "intelligent decision source," responsible for generating operational suggestions (i.e., commands) that conform to business logic at the appropriate time. Whether to execute them and how to execute them safely are determined and guaranteed by the existing, non-bypassable safety system (interlocking system).
[0044] Without adopting this technical approach, such as attempting to design a new interface or protocol for automatic operation that is independent of the existing single-operation command system and directly connected to the interlocking, significant technical risks and engineering complexity would arise. This would not only require major modifications and recertification of the interlocking system's interface and internal processing logic, compromising the integrity and stability of the existing safety system, but also introduce new communication links and protocols, increasing system failure points and maintenance costs. More seriously, this "starting from scratch" approach could potentially create a path to bypass existing safety verification procedures, contradicting the fundamental principles of "fail-safety" and "redundancy verification" in railway signaling systems. Therefore, this invention, by reusing the standard single-operation command interface, achieves the smooth embedding of automation functions while minimizing modifications to the existing core safety system. This ensures the effectiveness of new functions while strictly maintaining the basic safety architecture of the entire control system, demonstrating the high feasibility and security of the solution.
[0045] S5: Monitor the execution result of the single operation command or monitor whether the toggle operation is successfully executed within the preset monitoring period.
[0046] This step is implemented through the following parallel and complementary monitoring paths to ensure closed-loop operation and reliable status confirmation.
[0047] After sending a single-operation command to the interlocking system in S4, the system does not end the processing of this automatic switching task, but immediately enters the active monitoring state of this step. The design of step S5 is based on a core principle: the system must be responsible for the results of its initiated control actions and confirm the final state of the operating environment, and cannot remain in an open-loop state of "issuing commands but not verifying." Therefore, the safety line turnout service module simultaneously initiates two independent but consistent monitoring logics.
[0048] The first monitoring path: Command execution result monitoring (command timeout monitoring) This path specifically tracks the execution process of a particular single-operation command issued by step S4. Its technical implementation begins with the safety line turnout service module starting a separate "command execution timeout timer" for that command instance at the same time the command is issued. The timeout limit of this timer is a preset fixed value or a configurable parameter, representing the maximum reasonable time window for the system to wait for interlocking execution and feedback of results.
[0049] The monitored data consists of real-time station data fed back from the interlocking system, specifically focusing on the position and status of the target turnout leading to the safety line. The safety line turnout service module continuously compares the latest position information of the turnout obtained from the display control module with the target position (safety positioning) required in the command.
[0050] The judgment logic is as follows: If the turnout position is detected to have changed to a safe position before the "command execution timeout timer" expires, it is determined that the single-operation command has been successfully received and executed by the interlocking system. At this time, the safety line turnout business module records the operation as successful and clears all timers and monitoring statuses related to the command, and the automatic switching process ends normally. This path monitors the integrity and timeliness of the link from "command issuance to completion of execution by the interlocking system".
[0051] The second monitoring path: Monitoring successful operations within a preset monitoring period (status timeout monitoring). This path is independent of whether a command is issued; it is a status monitoring of the fundamental objective: whether the turnout leading to the safety line eventually returns to a safe position. Its time base is the "preset monitoring period" (e.g., 120 seconds) established in step S2, starting from the clearing of the route sequence. Throughout this entire period, this monitoring logic continues to run regardless of whether the safety line turnout service module has issued a single-operation command.
[0052] The monitored content is also the real-time position status of the target turnout. Its judgment logic is more inclusive: as long as the turnout is detected to be in a safe position at any time before the end of the preset monitoring period, it is considered a "successful execution of the switching operation." "Successful execution" here includes not only single-operation commands issued by step S4 of this system, but also manual intervention by the operator via the CTC terminal or other means to switch the turnout back to its original position. If the turnout is still not in a safe position by the end of the preset monitoring period, a "status timeout" is triggered. This path monitors whether the ultimate goal of the operation (turnout reset) is achieved within the allowed time window, without specifying the method of achievement.
[0053] Reasons, principles and effects of adopting dual parallel monitoring paths 1. Coverage of diverse fault scenarios: Single monitoring paths have blind spots. If only command execution monitoring is available, it cannot cover scenarios where "a single-operation command never reaches the interlock due to a communication failure" or "an internal module logic error fails to trigger the issuance of the S4 command." In these cases, the system may mistakenly assume nothing has happened because it doesn't receive failure feedback. If only status monitoring is available, when a command fails to execute (such as an internal interlock drive failure), the system can only trigger an alarm after the preset monitoring period ends, resulting in a slow response. Dual monitoring provides redundant coverage, ensuring that any anomaly can be captured by at least one path.
[0054] 2. Respect and Compatibility with Human Intervention: The status monitoring path design acknowledges and respects the operator's ultimate control. During or after the automated system's condition assessment and command generation, experienced operators may manually reset the switches in advance based on a more holistic perspective. The status monitoring path can recognize this "success" and gracefully terminate the automated process, avoiding the system's futile waiting or sending duplicate commands after manual operation, achieving harmonious coexistence and seamless integration between automated logic and manual operation.
[0055] 3. Clear Anomaly Location: Timeouts triggered by the two paths point to different abnormal links. "Command Execution Timeout" primarily indicates an anomaly in command response or execution on the interlocking system side (such as communication interruption, interlocking equipment failure, or command verification failure), facilitating maintenance personnel to quickly locate the interlocking or communication link. "Status Timeout," on the other hand, indicates that on the CTC (Center Control Center) side, the conditions for automatic triggering are consistently not met (such as a turnout being continuously locked by a single switch, or excessively dense subsequent schedules), or that no attempt was made to trigger the command at all, prompting checks on the station operation plan, equipment blocking status, or CTC logic. This differentiated alarm information greatly assists in fault diagnosis and emergency handling.
[0056] Without this comprehensive and parallel monitoring mechanism, the system will revert to the unreliable state of "open-loop control." If the automatic switching command fails to take effect for any reason, the turnout leading to the safety line will remain in an unsafe reversed position, while the control center will receive no effective alarm. This severely deviates from the fundamental principles of "fail-safe" and "observable status" in railway safety systems, leaving significant safety hazards. Therefore, step S5, by implementing dual and parallel monitoring of commands and status, adds a crucial "safety closed loop" and "anomaly detection" safeguard to the entire automatic switching method. This is a key technical step to ensure the reliability and availability of the solution and ultimately realize its safety value.
[0057] S6: When the single operation command times out or the trigger operation is not performed by the end of the preset monitoring period, an alarm message is generated to prompt manual intervention.
[0058] In step S6, when the single-operation command times out or the triggering operation is not performed by the end of the preset monitoring period, an alarm message is generated to prompt manual intervention. This is implemented in the following way.
[0059] This step is the final safety assurance and anomaly handling stage of the automatic triggering method, and its triggering is directly derived from the negative output results of the two parallel monitoring paths in step S5. Specifically, there are two independent scenarios that trigger S6: Scenario 1: Command execution timeout triggers alarm. This scenario corresponds to the detection result of the "Command execution result monitoring (command timeout monitoring)" path in step S5. After the safety line turnout service module sends a single-operation command to the interlocking system in step S4, it starts the command execution timeout timer. If, within the time limit set by this timer (this time limit is a preset fixed value, such as 30 seconds, representing the maximum reasonable time for the system to wait for interlocking response and execution), the module fails to detect the target turnout switching to the safe position by continuously comparing the station display data, it is determined that "single-operation command execution timeout" has occurred. At this time, the safety line turnout service module immediately generates a corresponding alarm message.
[0060] Scenario 2: Status Timeout Triggers Alarm. This scenario corresponds to the detection result of the "Successful Monitoring of Operation within the Preset Monitoring Period (Status Timeout Monitoring)" path in step S5. The preset monitoring period, which starts timing from step S2 (e.g., 120 seconds after the route sequence is cleared), is a global time boundary. If, at the expiration of this period, the safety line turnout service module checks and finds that: 1) the target turnout leading to the safety line is still not in a safe position; and 2) the module itself has never successfully issued a single-operation command in this monitoring process (i.e., it failed to enter S4 because the activation conditions were never met), then it is determined to be a "status timeout". At this time, the module also immediately generates a corresponding alarm message.
[0061] The generation, content, and reporting process of alarm information are as follows: Once any of the above timeout conditions are met, the safety line turnout service module will construct a structured alarm event. This event data will include at least the following key information: alarm type (clearly distinguishing between "command execution timeout" and "status timeout"), alarm object (clearly indicating the turnout number where the anomaly occurred, such as "1# safety line turnout"), associated route sequence or train number information (to facilitate tracing the source of the problem), alarm level (defined as "Level 2 alarm" requiring manual intervention), and alarm occurrence time.
[0062] After an alarm event is generated, the safety line turnout business module transmits the event to the module responsible for alarm processing and logging (such as the auxiliary log module) through the data interaction mechanism within the autonomous control machine subsystem. Ultimately, a clear, unambiguous, and highly targeted text alarm message will be displayed on the human-machine interface of the CTC operating terminal used by the dispatcher or station duty officer. This message is typically presented with a prominent color, flashing icon, or combined with sound prompts to ensure timely attention from the operator.
[0063] The reasons for adopting this technical approach, its principles, and the resulting safety effects: 1. Achieving a Closed-Loop Safety System and Fault-Oriented Safety: The fundamental principle of this step is the core "fault-safe" principle of railway signaling systems. Automated systems must acknowledge their capability boundaries. When automated logic fails to complete a predetermined task due to equipment malfunction, communication anomalies, unmet conditions, or unforeseen scenarios, the system cannot "silently fail" or wait indefinitely. Instead, it must proactively and explicitly report the fault and transfer control to the person with the highest decision-making and handling capabilities. Step S6 is a concrete manifestation of this principle. It ensures that the automated chain from "monitoring" to "judgment" to "execution" inevitably leads to one of two definite states: either "successful completion" or "an explicit alarm requesting manual intervention." This eliminates the dangerous situation at the system design level where safety line switches remain in an unsafe state for extended periods due to automated malfunctions without anyone being aware of it, achieving full coverage and closed-loop processing of safety management.
[0064] 2. Improve Fault Diagnosis and Handling Efficiency: By distinguishing between "Command Execution Timeout" and "Status Timeout" alarm types, this step provides operators and maintenance personnel with preliminary fault location information. "Command Execution Timeout" typically indicates problems in the command reception, logic judgment, or drive execution stages on the interlocking system side, or an abnormal communication link between the CTC and the interlocking system. "Status Timeout" is more likely to indicate problems with the judgment logic on the CTC autonomous machine side (such as improper condition parameter settings), special station operation states (such as turnouts being locked by a single switch for an extended period), or abnormal planning (such as overly dense planning causing the NextRepTime condition to never be met). This differentiated alarm information significantly narrows the scope of fault investigation, enabling more targeted manual intervention, shortening emergency response time, and improving the maintainability of the entire system.
[0065] 3. Adhere to the division of labor between humans and machines and the ultimate responsibility: This step clarifies that automation functions are auxiliary tools, while humans are the ultimate bearers of safety responsibility. When an automated process cannot be completed, the system generates an alarm message, essentially issuing a clear handover request to the operator: "There is a situation here that I cannot handle; you need to make the decision and take action." This allows the operator to take over promptly and, based on the alarm message and the actual situation on site, take manual single-operation of the switches or other necessary safety measures to ensure train operation safety.
[0066] Without implementing step S6, the entire automatic turnout system would have serious safety flaws. When encountering various anomalies, the system would exhibit a "silent" state with no feedback and no output. Operators would have no way of knowing whether the automatic function had been successfully executed or had failed at some point. Switches leading to the safety line might remain in the reverse position for an extended period due to the silent failure of the automatic process; this significant safety hazard would be masked by the "calm" appearance on the system interface, completely violating the design principles of a safety system. Therefore, step S6, through mandatory timeout detection and explicit alarm information generation, constructs an indispensable final safety barrier for the entire automatic turnout method, ensuring the reliability and practicality of the solution. This is crucial for its deployment in actual operation, truly replacing inefficient manual operations and improving overall safety levels.
[0067] The technical solution constructed by the method of this invention, through a systematic design of six interconnected steps (S1 to S6), demonstrates significant creativity and achieves multiple beneficial effects. Its creativity is first reflected in the source innovation of the monitoring logic (S1): by unidirectionally monitoring the "route sequence" status of the train control module through the safety line turnout business module, rather than directly collecting the physical position of the turnout, it achieves accurate identification and intent filtering for the specific business scenario of "turnout action caused by train operation plan," fundamentally eliminating the risk of accidental manual operation of the turnout. Secondly, it is reflected in the safe and intelligent optimization of decision-making timing (S2, S3): using "route sequence clearing" as the sole safe start-up opportunity, and introducing multi-parameter collaborative operating conditions including delay confirmation (CleanSec) and planned interval prediction (NextRepTime), it ensures that the operation timing strictly complies with interlocking safety specifications, and can intelligently merge operations during periods of high train traffic, effectively improving equipment lifespan and the continuity of train operation. This is further demonstrated in the system integration compatibility design (S4): by generating standard single-operation commands and reusing existing communication channels for distribution, the automatic triggering function is fully embedded in the existing safety framework, with the interlocking system performing the final safety verification, achieving decoupling and seamless integration between the new function and the core safety system. Finally, its innovation is highlighted in the closed-loop and redundancy protection of anomaly handling (S5, S6): through the dual parallel paths of command execution monitoring and preset time period status monitoring, and the differentiated timeout alarm mechanism triggered accordingly, a closed-loop monitoring system covering the entire process from command issuance and execution to final status confirmation is constructed, ensuring that any anomaly can be detected in a timely manner and clearly prompting manual takeover, strictly adhering to the "fault-safety" principle.
[0068] This technical solution, integrating the aforementioned innovative designs, effectively addresses the safety hazards of existing technologies that rely entirely on manual monitoring, involve heavy operational loads, are prone to oversights and late switching, and cannot distinguish operational intentions. Ultimately, it achieves multiple benefits: reducing manual labor intensity, improving operational timeliness and accuracy, preventing ineffective wear and tear on turnout equipment, and ensuring ultimate safety through mandatory abnormal alarm handover. This realizes an intelligent upgrade of turnout control towards a safer future, moving from "human-based" to "technology-based" control. Example 2
[0069] Based on Embodiment 1, the CTC system station self-regulating machine subsystem involved in this invention is implemented through the collaborative working process of its internal modules. The entire subsystem, on the existing architecture, introduces a new safety line turnout business module and reconstructs the data interaction relationships between modules, forming a complete technical solution capable of automatic monitoring and operation.
[0070] This subsystem comprises multiple functional modules, and the collaborative working process and principles of these modules are as follows: The train control module, as the core safety module, continuously runs the existing train control logic, generates route sequences based on the train operation plan, and drives their states to transition from "waiting to trigger" to "triggered," "occupied," and finally "cleared." During this process, the train control module continuously and unidirectionally provides the generated route sequences and their status change data to the newly added safety line turnout service module through a data interface defined within the subsystem. Simultaneously, the display control module, as the integration and distribution center for station status, receives real-time station-wide display information from the interlocking system, including turnout positions, section occupancy, and locking status, and similarly provides this processed real-time data unidirectionally to the safety line turnout service module.
[0071] The safety line turnout service module is the core decision-making unit of the entire automation function. Upon startup, it first loads the configuration file, obtaining a list of device numbers (e.g., 1D, 7D) and control parameters (e.g., CleanSec=6 seconds, NextRepTime=180 seconds) for the safety line turnouts that need to be monitored at this station. Then, the module enters a continuous working state. It receives route sequence data streams from the bicycle control module and performs filtering: parsing the path description of each route sequence, and if it finds that it contains any pre-configured turnout number leading to the safety line, it marks the sequence as a "related sequence" and tracks it. For each tracked related route sequence, when the safety line turnout service module detects that its status changes to "cleared," it starts an independent monitoring logic instance for the turnout associated with that sequence. Within a configurable time period (preset monitoring period, such as 120 seconds), this instance works in a loop. In each loop, it comprehensively analyzes various real-time data from the display control module: checking whether the target turnout's current position is not in a fixed position, whether its track section has been continuously idle for more than CleanSec seconds, and whether the turnout is not single-locked or single-blocked. Simultaneously, it analyzes future planning data from the bicycle control module to calculate whether the planned trigger time for the next route sequence requiring the turnout exceeds NextRepTime seconds. Only when all the above conditions are simultaneously met in a single loop will the safety line turnout service module generate a formatted turnout single-operation command for the target turnout. This command includes the turnout number and the instruction to switch to a fixed position.
[0072] The generated command data is then transmitted to the basic data module. The basic data module does not handle business logic judgments; it is only responsible for data format conversion and protocol encapsulation. Its job is to serialize the internal command data structure into a bit stream conforming to the underlying communication protocol (such as the agreed application layer message format), and add necessary communication frame headers, address information, and checksums. The standardized communication message, after processing, is finally delivered to the underlying communication module. The underlying communication module is responsible for reliably sending the command message through the existing, physically isolated dedicated communication link between the station's automatic control machine and the extension server, ultimately forwarding it to the target interlocking system via the extension server. After receiving and verifying the command, the interlocking system executes the turnout switching operation, and the operation result is again fed back to the display control module through indication information, thus forming a perceptible closed loop.
[0073] Compared to existing technical solutions that rely entirely on manual observation and operation, this invention's system is characterized by the following core aspects: First, in terms of system architecture, it creatively adds a safety line turnout business module with business isolation and unidirectional data flow. This module acts solely as a "data consumer" for the train control module and display control module, acquiring information in a read-only manner and never performing any write or control operations on these two core safety modules. This strictly unidirectional data flow design and logical isolation ensures that the newly added automatic functions will not interfere with or damage the existing core train safety control logic, achieving a smooth and safe embedding of functions. Second, in terms of functional implementation, this module does not simply replicate manual judgment but integrates multi-source heterogeneous data for intelligent decision-making through software logic. It integrates and analyzes four types of information: the planning logic of the route sequence, the real-time physical status of the turnouts and sections, the manual intervention signs of equipment locking, and the future train plan timeline, forming an optimized decision-making model that surpasses the instantaneous judgment capabilities of humans, comprehensively considering safety, efficiency, and equipment lifespan. For example, its "CleanSec" mechanism overcomes the engineering problem of delayed physical response from equipment, and its "NextRepTime" mechanism solves the operational optimization problem in high-traffic scenarios—all of which are difficult to achieve systematically and standardizedly through manual operation. Finally, throughout the entire command execution chain, the system reuses and relies on existing, highly secure and intact communication and execution channels. Automatically generated commands are completely consistent with manual operation commands in terms of format, interface, and verification, and ultimately undergo the same final safety verification by the interlocking system. This means that automated decision-making is placed within the existing highest level of safety barriers, minimizing the risk of new problems.
[0074] The aforementioned system solution, by adding a safety line turnout service module with business isolation and unidirectional data flow, ensures that automatic functions are implemented without interfering with the core safety logic. This module comprehensively processes the route sequence planning logic from the bicycle control module, the real-time physical status from the display control module, and the manual locking flags, and makes optimization decisions based on the future planning timeline (via the NextRepTime parameter), forming an automated intelligent decision-making unit. All control commands are ultimately issued through the system's existing, highly secure and intact communication and execution channels, with the interlocking system completing the final safety verification and drive, achieving seamless integration and reliable operation of the new function with the existing safety system.
Claims
1. An automatic switching method for turnouts leading to safety lines, applied to the station autonomous machine subsystem of a centralized train control (CTC) system for railway traffic management, characterized in that... Includes the following steps: S1: Monitor the status of the route sequence associated with the turnout leading to the safety line; S2: In response to determining that the route sequence has been cleared, initiate the monitoring and switching logic for the turnout leading to the safety line; S3: During a preset monitoring period after the route sequence is cleared, continuously check whether the conditions for moving the turnout to the safety line to the safe position are met. S4: When all the aforementioned turning conditions are met simultaneously, send a single-operation command to the interlocking system to turn the turnout leading to the safety line to the safe position; S5: Monitor the execution result of the single operation command or monitor whether the toggle operation is successfully executed within the preset monitoring period; S6: When the single operation command times out or the trigger operation is not performed by the end of the preset monitoring period, an alarm message is generated to prompt manual intervention.
2. The automatic levering method according to claim 1, characterized in that, In step S3, the triggering conditions include all of the following: (a) The turnout leading to the safety line is not currently in a safe position; (b) The turnout leading to the safety line has been physically cleared for more than a first preset time threshold; (c) The turnout leading to the safety line is not subject to single locks, single seals, or other equipment restrictions that would prevent it from being turned; (d) The time interval between the triggering time of the next planned use of the route sequence to the safety line turnout is greater than a second preset time threshold.
3. The automatic levering method according to claim 2, characterized in that, The first preset time threshold is a configurable value within the range of 3 to 180 seconds, and the second preset time threshold is a configurable value used to combine turnout operation during periods of high traffic density.
4. The automatic levering method according to claim 1, characterized in that, In step S5, monitoring the execution result of the single-operation command specifically involves: after sending the single-operation command, starting the command timeout monitoring timer; if it is detected that the turnout leading to the safety line has been moved to the safety position within the command timeout period, then the monitoring process ends; otherwise, a command timeout alarm is triggered.
5. The automatic levering method according to claim 1, characterized in that, In step S5, monitoring whether the switching operation was successfully executed within the preset monitoring period specifically involves starting the timer after the route sequence is cleared. If, at the end of the preset monitoring period, the turnout leading to the safety line is still not in a safe position and no single-operation command has been sent to it, a status timeout alarm is triggered.
6. A CTC system station self-regulating machine subsystem implementing the automatic triggering method as described in claim 2, characterized in that, include: The driving control module is used to generate and process route sequence status; The display control module is used to cache and provide station display data, including the status data of the turnout leading to the safety line; The safety line turnout service module is used to realize the automatic monitoring and operation functions of the turnout leading to the safety line; The safety line turnout service module is isolated from the train control module and the display control module, and only receives route sequence status data from the train control module and station display data from the display control module in one direction. The safety line turnout service module determines whether the operating conditions are met based on the received data, and generates turnout single operation command data when the conditions are met.
7. The CTC system station self-regulatory machine subsystem according to claim 6, characterized in that, Also includes: The basic data module is used to format and convert the turnout single-operation command data generated by the safety line turnout business module. The underlying communication module is used to send the converted command data to the interlocking system.
8. The CTC system station self-regulatory machine subsystem according to claim 6, characterized in that, The safety line turnout service module has a built-in configuration file for setting the main function switch, the first preset time threshold, the second preset time threshold, and the set of turnouts leading to the safety line that this station needs to monitor.
9. The CTC system station self-regulatory machine subsystem according to claim 6, characterized in that, The safety line turnout service module is configured to respond only to changes in the state of the turnout leading to the safety line caused by traffic routing, while ignoring transient changes in state caused by direct manual operation of the turnout.
10. The CTC system station self-regulatory machine subsystem according to claim 6, characterized in that, The subsystem also adapts and modifies the monitoring logic for the "safety line turnout not in position" alarm light of the interlocking system. Specifically, it disables the alarm triggered by the status of this alarm light at the CTC system level, or removes the alarm light icon from the CTC system station display interface.