SYSTEM FOR CONTROLLED RAPID START AND OPERATION OF A REDUNDANTLY DESIGNED ENERGY BUS INTENDED FOR THE FAILURE-PROOF SUPPLY OF AN ELECTRICAL CONSUMER
Patent Information
- Application Number
- DE502021009625
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-01-29
- Filing Date
- 2021-03-16
- Publication Date
- 2026-02-12
- Estimated Expiration
- 2041-03-16
AI Technical Summary
Existing systems for the rapid start and fail-safe operation of a redundantly designed energy bus in industrial plants, particularly in railway networks, take too long to restart due to the sequential dependency on operating system boot times of network node units, leading to prolonged downtime in case of failures.
Implementing an operating system-less logic unit, such as an FPGA, to perform basic checks on the power bus independently and control switches immediately upon voltage application, allowing the energy bus to be quickly activated while the operating system-based computer unit boots, followed by transitioning control to the CPU once operational.
Enables rapid startup of the energy bus within seconds, reducing downtime by allowing immediate basic checks and voltage application to network node units, even before the CPU is fully operational, thus ensuring quick fail-safe power supply to decentralized functional units.
Description
[0001] The present invention relates to a system for the controlled rapid start and operation of a redundantly designed energy bus intended for the fail-safe supply of an electrical consumer.
[0002] Electrical consumers, such as decentralized functional units in rail transport, are used particularly in rail networks, where they control and monitor vehicle-influencing and / or vehicle-monitoring units, monitor their functionality, and collect process data and report it back to a central control and / or monitoring center, such as a control center or signal box. Examples of train-influencing units, which give instructions to the driver or even directly intervene in the vehicle control system or directly set a safe route, include signals, points, balises, track conductors, track magnets, and the like, as well as sensors for recording process variables of the moving train, such as power consumption, speed, and the like.Units that monitor trains and track sections can include balises and line conductors, as well as axle counters, track circuits, and other track occupancy detection systems. However, the present invention fundamentally relates to all industrial plants in which functional units are distributed over longer distances and yet must be centrally controlled. This central control can be performed by a stationary control center or by a non-stationary virtual control center.
[0003] From the Sinet® project of Siemens Mobility AG, Wallisellen, Switzerland, and the corresponding European patent application EP 2 301 202 A1, a device and a method for controlling and / or monitoring decentralized functional units arranged along a transport network are known, which include the following key points: a) a higher-level control system that exchanges information with the decentralized functional units by means of data telegrams, b) a data transport network with a number of network access points, wherein the higher-level control system is connected to the data transport network via at least one network access point; c) communication units, each connected to a network access point, wherein: d) the decentralized functional units are grouped into subgroups, each with its own subnetwork; and wherein e) the subnetwork of each of the subgroups is connected to the data transport network at each of its two ends via a communication unit and a network access point.
[0004] In this way, a digital data transport network can be used for connecting the decentralized functional units, which is robust in every way against a simple fault event, yet allows a very clever use of copper cables widely used in railway technology, for example existing signaling cables, and finally requires only a comparatively small number of network access points.
[0005] Such a system is particularly advantageous for use in a railway network. Consequently, it is then expedient to connect traffic monitoring and control units, such as signals, points, axle counters, track circuits, and point and line train control elements, to the data transport network by means of decentralized functional units.
[0006] The design of technical systems, especially in railway infrastructure, is geared towards robustness and reliability due to over 100 years of industrial plant construction and railway engineering. In the original design, the external elements of railway signaling systems were connected via relatively heavy-duty cables to ensure reliable detection of switching states over defined distances. This means the system is designed with sufficient reserves to handle peak loads. The switching process of the external elements also transmits information via the energy supply. Consequently, the detectable energy flow limits the possible distances.From today's perspectives of flexibility, cost and resource policy, these established concepts, in addition to the communication structure disclosed by EP 2 301 202 A1, urgently need to be innovated in the area of energy supply as well, in order to dissolve the previous coupling of information and energy.
[0007] To address the decentralized energy supply of decentralized functional units, international patent application WO 2013 / 013908 A1 discloses a solution within the framework of the Sigrid® product from Siemens Mobility AG, Switzerland. This solution provides a device and a method for operating decentralized functional units arranged in an industrial plant, comprising: a) a higher-level control system that exchanges information with the decentralized functional units via data telegrams; b) a data transport network with a number of network access points, wherein the higher-level control system is connected to the data transport network via at least one network access point; c) communication units connected to a network access point that provide the decentralized functional units with access to the data transport network; and d) a power transport network to which the decentralized functional units are connected and which supplies the decentralized functional units with electrical energy. In this way, the power transport network is now also completely decoupled from a signal box.
[0008] Building upon today's signal box architecture with decentralized stations but point-to-point power supply, this represents a new, innovative approach. The current cable- and labor-intensive point-to-point connections for the power supply of peripheral elements along the track (also called element controllers or decentralized functional units) are replaced by cable-saving and easy-to-install bus or ring lines.
[0009] The solution disclosed in WO 2013 / 013908 A1 is by no means limited to the described application of railway signal box architecture, but extends far beyond it. Future examples include energy management for buildings or for large-scale plants in the manufacturing or processing industries based on decentralized energy supply.
[0010] When the power bus is laid between two signal boxes or other facilities connected to the power supply networks, the connected consumers (decentralized functional units) can be supplied from both sides. This creates a previously unavailable redundancy in the power supply. The decentralized functional units (also called element controllers or ECs) are connected to the data bus and the power bus by network node units (also called bus couplers or SNDs - smart node devices), which can perform control, monitoring, and diagnostic functions. For example, the SNDs can interrupt or switch the power bus, as well as measure currents and voltages within the power bus.
[0011] Simple defects, such as short circuits or open circuits, in the power bus do not immediately lead to the failure of any components if handled correctly due to redundancy. In the event of a failure of one supply side, the supply to all decentralized functional elements would be taken over by the second supply side. A method and system for the appropriate handling and prevention of short circuits in the power bus are known from European patent application EP 3 109 128 A1. The control mechanisms and network node units are central to this system, as they can selectively disconnect the power bus to each of the two input sides in the event of a fault.
[0012] To perform their function, the network node units have a computing unit, which is usually based on an operating system such as Windows or similar. Therefore, in the event of a power bus failure or a restart, the power bus can only be put back into operation correctly once... uaThe short-circuit monitoring in the network node units must also have commenced operation, i.e., once the logic programs, including the operating system, have been started. Since several network node units are connected sequentially in the energy bus, the time required for each network node unit to start up is of great importance. In the aforementioned Sigrid® product, a maximum of 16 network node units can be arranged between the two feed-in points. However, in the case of a temporary, one-sided feed-in, this may mean that the restart of all 16 network node units must be awaited before the energy bus is properly restarted.Even assuming a start-up time of 30 seconds per network node unit, the restart of the energy bus takes approximately 8 minutes until the energy bus voltage has been switched through to the last of the 16 network node units, since the energy bus is only switched through to the next network node unit in the chain once the previously ordered network node unit has been correctly put into operation and has successfully completed its basic bus test functions, such as voltage measurement and detection of any fault currents.
[0013] However, it is naturally in the interest of the railway operator that the energy bus can be restarted as quickly as possible after a restart or in the event of malfunctions.
[0014] The present invention therefore aims to provide a system for the controlled rapid start and operation of a redundantly designed energy bus intended for the fail-safe supply of an electrical consumer, in which the restart of the energy bus can be carried out in a comparatively short time and yet it is ensured that the necessary elementary bus tests can be successfully completed.
[0015] This task is accomplished according to the invention by a system for the controlled rapid start and operation of a redundantly designed energy bus intended for the fail-safe supply of an electrical consumer, via which decentralized functional units arranged in an industrial plant, in particular a railway plant, can be characterized as electrical consumers and supplied with electrical energy, wherein: a) a number of network node units are arranged sequentially between two power supply points of a ring-shaped power bus, providing the decentralized functional units with access to the power bus and optionally also to a data bus (CB), b) at least one of these network node units has a controllable switching module comprising a first switch, a second switch, and a third switch, wherein the first and second switches control an electrical supply access to the two power supply points and the third switch controls an electrical supply access to the decentralized functional unit, c) the first of these network node units comprises an operating system-based computer unit and an operating system-less logic unit, d) the operating system-less logic unit is equipped,e) during the startup of the operating system-based computer unit and / or during a malfunction of the operating system-based computer unit, to perform a basic check of the power bus and to control at least the first and second switches depending on the result of the basic check of the power bus, and e) after a successful startup and / or when its utility is functioning correctly, the operating system-based computer unit controls the three switches instead of the non-operating logic unit.
[0016] In this way, a quick start of the energy bus can be performed because the operating system-less logic unit can immediately perform the basic checks upon receiving the energy bus voltage. A suitable logic unit for this purpose is, for example, an FPGA, which can check the bus voltage and the presence of fault currents, such as... .It can also detect short-circuit currents reliably and quickly. Once this basic test is successfully completed, the bus voltage can be applied to the nearest network node unit on the power bus by controlling the first and second switches, even while the computer unit is still booting up the operating system and therefore cannot yet correctly control the switching module. This results in a significant time saving when starting up the power bus.
[0017] As explained above, once the operating system-less logic unit has successfully completed the basic power bus test, it can switch the power bus voltage to the nearest network node unit on the power bus. Thus, the first and second switches are controlled by this logic unit, typically well before the operating system-based computer unit has been started up, for example, during a power bus restart.
[0018] The basic testing of the energy bus can sensibly include testing the voltage applied to the network node unit and / or testing for fault currents, such as a short-circuit current.
[0019] For the correct functioning of the power bus with the execution of the complete program of the computer unit, it is advisable if the operating system-supported computer unit (CPU) disconnects the operating system-less logic unit from its power supply or from its control accesses to the first and second switches after a successful start-up and / or when its utility program is functioning properly.
[0020] Further advantageous embodiments of the present invention can be found in the remaining dependent claims.
[0021] Advantageous embodiments of the present invention are explained in more detail with reference to the drawing. These show: Figure 1 shows a schematic view of a signal box architecture with a data bus and a power bus; and Figure 2 shows a schematic view of a network node unit for connecting a decentralized functional unit to the data bus and power bus.
[0022] Figure 1The diagram schematically depicts an interlocking architecture with a system (Sys) that includes, among other things, an interlocking unit (STW), a redundant data backbone (NB1, NB2), a data bus (CB), and a power bus (EB) with two power supply points (PS1 and PS2). The interlocking unit (STW) controls train traffic on a track section (G) containing signals (S), points (W), a level crossing (Bue), and axle counters (AC). These train protection and train control components are each connected to the data bus (CB) and the power bus (EB) via a decentralized functional unit (E). The decentralized functional units (E) are connected to the ring-shaped data bus (CB) in such a way that each side of the ring-shaped data bus (CB) provides access to either the data backbone (NB1) or the data backbone (NB2). The data bus (CB) connects to the respective data backbone (NB1, NB2) via corresponding routers / switches (SW).Furthermore, the sequential connection of the Element Controller Unit E to the ring-shaped energy bus ensures that each Element Controller Unit E can be supplied with electrical energy from both sides and thus redundantly.
[0023] Figure 2 Figure 1 schematically shows the data and power supply connection of the Element Controller Unit E of a train control component, for example a switch W, to the data bus CB and the power bus EB. Such a connection point comprises a network node unit SND and the actual Element Controller EC. The network node unit SND includes a communication unit SCU for data exchange via both branches of the data bus CB. On the power side, the network node unit SND is designed to connect to both branches EB1 and EB2 of the power bus EB, thus ensuring access to both feed-in points PS1 and PS2 at all times, possibly via other network node units SND (as shown in Figure 1). Figure 1shown).
[0024] The network node unit SND also features an operating system-based computer unit (CPU) that controls a switching module (S) and simultaneously monitors the state of the power bus (EB) connected to the network node unit. Specifically, the CPU detects current overcurrents and / or voltage dips within the power bus (EB) and / or at the connected load (SPU with EC) and evaluates this data for a possible short circuit.
[0025] Thus, the network node unit SND is always supplied with electrical energy redundantly from two sides and therefore has, within the switching module S, a left switch S1 and a right switch S2 as well as a load switch S3 for the supply unit SPU of the element controller EC.
[0026] The network node unit SND also supplies power to the communication unit SCU and can exchange data with it via an Ethernet connection, thus integrating it into the data bus CB (e.g., activating manual operation of the network node unit SND via remote access and actuation of switches S1 to S3, transmitting diagnostic data to the interlocking system STW or a higher-level service and diagnostic system, querying current voltages, currents, energy and power values, parameterizing the network node unit SND, data for charging an energy storage device (not shown here), or registering future power requirements). The power supply unit SPU, which converts the voltage of the energy bus EB to the input voltage required for the element controller EC, is integrated into the network node unit SND via switch S3.
[0027] Furthermore, a data connection is provided between the switching module S of the network node unit SND and the power supply unit SPU, e.g., in the form of a serial RS 422 or Ethernet connection. A typical power supply configuration here is, for example, a three-phase connection with 400 VAC. The Element Controller EC controls and supplies the... Figure 2 In this case, the switch W. The Element Controller EC receives data telegrams from a higher-level interlocking computer (CPU) via an Ethernet connection from the communication unit (SCU) and sends the feedback to the interlocking computer via this communication unit (SCU). R. The interlocking computer R can also represent a corresponding evaluation module that evaluates the received data as intended. Alternatively, it is also possible to equip the CPU unit on the network node unit SND to process a large portion of the further oh to be able to perform the aforementioned tasks directly on the network node unit SND.
[0028] In addition to the operating system-based CPU, which can be equipped with a Windows or Linux operating system, for example, the network node unit SND also features an operating system-less logic unit FPGA, which can be designed, for example, as a hardware-coded FPGA module. This logic unit FPGA plays a special role, for example, in starting up the power bus EB. Assuming that the network node unit SND has several other network node units arranged adjacent to each other on the left branch EB1, in a string-of-pearls configuration, starting up the power bus EB might require ten or more network node units to be activated.Since the CPU can only control the switching module S once the operating system has booted and the utilities have started and are running, it takes approximately one to two minutes for the CPU to take over control of the switching module D, for example, when power is supplied only via the right branch EB2 per network node unit SND. During the startup phase, however, the FPGA logic unit performs a basic check of the power bus EB, such as voltage measurement and short-circuit testing. Therefore, if the check is successful, it can activate the left and right switches S1 and S2, respectively, to connect the power bus EB to the nearest network node unit SND within just a few milliseconds.Thus, if the operating parameters are correct, the energy bus EB is activated for all network node units integrated into it within a few seconds, and the startup of the CPU computer units on all network node units SND integrated into the energy bus EB can therefore take place largely in parallel.
[0029] Once the CPU is fully functional, it takes over control of the switching module S and effectively disables the FPGA logic unit by, for example, actively cutting its power. However, if the CPU malfunctions or fails during operation, the FPGA's power-off function also fails, and the FPGA, with its rudimentary monitoring capabilities, resumes control of at least the left and right switches S1 and S2 of the switching module. S.
[0030] Thus, the monitoring logic for the energy bus (EB) is available virtually as soon as the bus voltage is present, and the switching of the bus voltage to the other network node units (SND) can occur very quickly because the startup process for the logic functions of the network node unit is divided into two stages that run independently of each other. In the first stage, when the logic unit (FPGA) starts, the monitoring logic for the energy bus (EB) is also started on the FPGA itself. The term "operating system-less logic unit" is used to express that the FPGA logic unit functions independently of any communication with the processor of the computer unit (CPU) and also without communication with the neighboring network node units (SND).Once the logic unit has started up and successfully completed its basic check of the power bus (EB), the power bus (EB) can be switched to the nearest network node (SND). This limits the time required for a network node (SND) to switch the power bus (EB) to approximately one second. Even with a double-digit number of network nodes (SND) connected to the power bus (EB), the entire power bus can be started up and the corresponding connected element controllers (E) powered within a number of seconds corresponding to the number of network nodes. The second stage of the CPU startup process runs in parallel and starts the operating system on the processor, which is no longer a time-critical process with regard to the rapid availability of the power bus.
Claims
1. System (Sys) for the controlled quick start and operation of a redundantly designed power bus (EB) provided for fail-safe supply of an electrical consumer (E), via which decentral functional units (E, S, W, Bue, AC), which are arranged in an industrial installation, in particular a railway engineering installation, and can be characterised as electrical consumers, can be supplied with electrical energy, wherein: a) a number of network node units (SND) are arranged sequentially between two feed points (PS1, PS2) of a power bus (EB) constructed in a ring-like manner, which provide the decentral functional units (E) with access to the power bus (EB) and optionally also to a data bus (CB), b) at least a first of this number of network node units (SND) possesses a controllable switching module (S), which comprises a first switch (S1), a second switch (S2) and a third switch (S3), wherein an electrical supply access to the two feed points (PS1, PS2) can be switched with the first and the second switch (S1, S2) and an electrical supply access to the decentral functional unit (E) can be switched with the third switch (S3), characterised in that c) this first of this number of network node units (SND) has an operating system-supported computer unit (CPU) and a logic unit (FPGA) without an operating system, d) the logic unit (FPGA) without an operating system is trained to carry out a basic check of the power bus (EB) and a control of at least the first and the second switch (S1, S2) as a function of the result of the basic check of the power bus (EB) during the startup of the operating system-supported computer unit (CPU) and / or during an operational disruption of the operating system-supported computer unit (CPU), and e) the operating system-supported computer unit (CPU) is trained to control the first, second and third switches (S1 to S3), instead of the logic unit (FPGA) without an operating system, after a successful startup and / or during proper function of its utility program.
2. System according to claim 1, characterised in that the logic unit (FPGA) without an operating system is trained to interconnect the voltage of the power bus to the network node unit (SND) arranged next in the power bus after successful completion of the basic check of the power bus (EB).
3. System according to claim 1 or 2, characterised in that the basic check of the power bus comprises a check of the voltage applied to the network node unit and / or a check for fault currents, such as a short-circuit current for example.
4. System according to one of claims 1 to 3, characterised in that the operating system-supported computer unit (CPU) is trained to disconnect the logic unit without an operating system from its power supply after a successful startup and / or during proper function of its utility program.