Method for assessing an operating state of a machine for maintaining a railway line
Patent Information
- Application Number
- EP2023805485
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-11-07
- Filing Date
- 2023-11-06
- Publication Date
- 2025-09-17
AI Technical Summary
Current methods for evaluating the operating condition of machines used to maintain railway lines are subjective and prone to manipulation, lacking objective verification of the machine's state and certificate validity, which can lead to unsafe operating conditions due to potential changes or expired certificates.
A method utilizing digital signatures to create and compare component identifiers, certificate information, and energy consumption signatures at delivery and execution times, ensuring integrity and objective assessment of the machine's operating state, thereby preventing unauthorized modifications and ensuring valid certificates.
This approach provides an objective and tamper-proof evaluation of the machine's operating state, ensuring safe operation by detecting any changes or expired certificates, thus maintaining operational safety and integrity of the railway line maintenance process.
Smart Images

Figure 1.1
Abstract
Description
[0001] Method for assessing the operating condition of a machine for the maintenance of a railway line
[0002] The invention relates to a method according to the preamble of claim 1.
[0003] The invention relates to a method for determining the safe operation of a machine at a time t2. The machine is used to maintain a railway line. The railway line includes, for example, the superstructure of a track, the track, and the infrastructure facilities connected to the railway line.
[0004] The machine comprises a computing unit, at least one electronic component, a component control unit and an internal database.
[0005] An electronic component can, for example, be a sensor for recording a measured value. The sensor control unit, as the component control unit, controls the sensor to record at least one measured value. In the simplest case, the sensor control unit activates the sensor to determine the measured value.
[0006] An electronic component (hereinafter also referred to as a component) can also be a network unit such as a router, a switch, or generally any electronic component for establishing a data connection. The component control unit controls the network unit.
[0007] One or more machine certificates with a certificate time stamp are stored in the internal database. The certificates can relate to the machine as a whole or to an individual component of the machine, such as the sensor. A certificate includes a certificate time stamp. The certificate time stamp defines up to which point in time or within which period the machine or a component of the machine, such as the sensor, can be used. The machine may not be used outside of or after the defined period. The internal database can be designed as a single internal database or as several internal databases arranged physically or logically with the individual components of the machine. The computing unit can retrieve one or more certificates from the one or more internal databases.
[0008] The external database and the internal database may have time-based and / or user-specific restrictions on read and write access.
[0009] Data connections exist between the aforementioned machine units, such as the processing unit, sensor, sensor control unit, and the at least one internal database and the external database. The data connections may be subject to user-specific and / or time-based access restrictions.
[0010] The machine can be in a delivery condition at a delivery time t1, a safe operating condition at a test time t2, or an unsafe operating condition. The delivery time t1 occurs before the test time t2. According to standard practice, the operating conditions are assessed by a person and documented in an acceptance document. This person can be guided by standards or instructions.
[0011] Acceptance documents prepared according to standard practice can be manipulated.
[0012] EP3907119A1 discloses a method for creating a safety-relevant acceptance certificate. In the EPO's communication of January 23, 2023, EP3907119A1 is criticized for being unclear. Due to this lack of clarity, EP3907119A1 is also considered incompletely described, which is why EP3907119A1 does not constitute relevant prior art.
[0013] The method according to the invention solves the problem of creating a tamper-proof log file as a replacement for the acceptance certificate known from conventional teaching. The assessment of the current operating status is to be carried out automatically using a technical process and is free from any subjective human assessment.
[0014] The method according to the invention in a first embodiment is characterized by the following method steps:
[0015] - at the delivery time tl, the computing unit determines a first component identifier of a first component,
[0016] - the computing unit creates a first component identification signature based on the first component identification using a digital signature procedure,
[0017] - the computing unit stores the first component identification signature in the internal database and in the external database,
[0018] - at the execution time t2, the computing unit queries a second component identifier of a second component,
[0019] - the second component sends a data record to the
[0020] Component control unit, which data record includes the second component identifier,
[0021] - the computing unit stores the second component identifier in the internal database,
[0022] - the processing unit creates a second component identification signature based on the second component identification using the digital signature procedure,
[0023] - the computing unit compares the first component identification signature with the second component identification signature,
[0024] - the processing unit determines a safe operating state if the first component identification signature and the second component identification signature match,
[0025] - The computing unit determines an unsafe operating state if the first component identification signature and the second component identification signature do not match. The first embodiment of the method according to the invention focuses on the evaluation of an operating state depending on the first sensor installed in the machine at execution time t1 and the second sensor installed in the machine at execution time t2.
[0026] According to current theory, it is possible to read a sensor's unique identifier and thus uniquely identify the sensor. The sensor identifier can be defined by the sensor manufacturer and / or the machine manufacturer. The sensor identifier is usually stored in a memory integrated into the sensor.
[0027] The method according to the invention allows the unambiguous determination of whether the first sensor and the second sensor are the same sensor and thus the machine has not been changed with respect to the sensor between the execution time t1 and the execution time t2.
[0028] The method according to the invention is further based on the creation of signatures of the processed values, namely the first sensor identifier and the second sensor identifier, using digital signature methods, so that the processed values are protected from unauthorized modification. The method is therefore integrity-based.
[0029] The method according to the invention in a second embodiment is characterized by the following method steps:
[0030] - at the delivery time tl, the processing unit compares the certificate time with the delivery time tl,
[0031] - the processing unit creates a positive first check if the certificate time includes the delivery time tl, or otherwise a negative first check if the certificate time does not include the delivery time tl,
[0032] - the processing unit creates a first verification signature based on the first verification according to the digital signature procedure,
[0033] - the processing unit stores the first verification signature in the internal database and in the external database,
[0034] - at the execution time t2, the processing unit compares the certificate time with the execution time t2, the processing unit creates a positive second check if the certificate time includes the execution time t2, or otherwise a negative second check if the certificate time does not include the execution time t2,
[0035] - the processing unit creates a second verification signature based on the second verification according to the digital signature procedure,
[0036] - the processing unit compares the first test signature with the second test signature, - the processing unit determines a safe operating state if the first test signature and the second test signature match,
[0037] - the computing unit detects an unsafe operating state if the first test signature and the second test signature do not match.
[0038] The second embodiment of the method according to the invention focuses on the evaluation of an operating condition depending on the presence of a valid certificate. A first test report with the first test information can be created at execution time t1, and a second test report with the second test information can be created at execution time t2.
[0039] The mentioned verification information (the first verification information or the second verification information) can be a positive verification information if the certificate is valid for a specific time. The positive verification information can be, for example, "Machine with a valid certificate, 00:00." The positive verification information can be limited to the valid certificate. The positive verification information can include a time specification by which the certificate time specification has been exceeded at the execution time t2.
[0040] The aforementioned verification information can be a negative verification information if the certificate is not valid and has therefore expired. The negative verification information could, for example, be "Machine without a valid certificate, 01:00." The negative verification information can also be limited to a time specification, indicating the time by which the certificate's validity has expired.
[0041] The test statement can include a text with a numerical value or a range specification.
[0042] The method according to the invention is further based on the creation of signatures of the processed values, namely the first verification information and the second verification information, using digital signature methods, so that the processed values are protected from unauthorized modification. The method is therefore integrity-based.
[0043] The method according to the invention in a third embodiment is characterized by the following method steps:
[0044] - the computing unit creates a certificate time range comprising the delivery time tl and the certificate time specification,
[0045] - the computing unit creates a series of different standardised certificate time specifications within the certificate time range, which certificate time specifications have a uniform time format, whereby each time difference between the individual certificate time specifications is greater than or equal to the smallest unit of the time format,
[0046] - the processing unit creates certificate time signatures based on the standardized certificate time according to the digital signature procedure,
[0047] - the processing unit stores the certificate time signatures in the internal database and in the external database, - the processing unit creates a delivery time specification having the time format, which delivery time specification describes the delivery time tl,
[0048] - the processing unit creates a delivery time signature based on the standardized delivery time,
[0049] - the processing unit compares the delivery time signature with the certificate time signatures,
[0050] - the processing unit determines a secure operating state if the delivery time signature matches a certificate time signature,
[0051] - the processing unit detects an unsafe operating state if the delivery time signature does not match any certificate time signature.
[0052] For example, a certificate can be valid until the certificate time 08.11.22. Let the delivery time tl be 06.11.22, for example, at which delivery time tl the machine has a valid certificate. The processing unit creates a certificate time range from 06.11.22 (delivery time tl) to the certificate time 08.11.22.
[0053] The processing unit then creates a series of different certificate time specifications, each of which has the format of the delivery time tl and the certificate time. The certificate time specifications differ by the smallest unit of the time format. The smallest unit of the time format can be specified by the maximum accuracy of the time format.
[0054] In the example discussed here, the time format is dd.mm.yy. The maximum accuracy of this time format and the smallest unit is the day (dd). If the times and time specifications mentioned above and below have different formats, the method according to the invention can include the step of converting these times and time specifications into a uniform, standardized format.
[0055] The series of different certificate time specifications of the certificate range in the example discussed here is 06.11.22, 07.11.22 and 08.11.22.
[0056] The processing unit creates a certificate time signature for each individual certificate time using the digital signature procedure. Thus, one certificate time signature is created based on 06.11.22, another certificate time signature is created based on 07.11.22, and another certificate time signature is created based on 08.11.22.
[0057] The processing unit creates a delivery time signature for the delivery time tl, which delivery time tl is present as a delivery time in the time format. The delivery time signature based on the delivery time 06.11.22 corresponds to the certificate time signature based on 06.11.22. Since the aforementioned signatures are identical, the processing unit determines a secure operating state at the delivery time tl. The fourth embodiment of the method according to the invention is characterized by the following method steps:
[0058] - the computing unit creates a certificate time range comprising the delivery time tl and the certificate time specification,
[0059] - the computing unit creates a series of certificate time specifications of the certificate time range, which certificate time specifications have a uniform time format, whereby each time difference between the individual certificate time specifications is greater than or equal to the smallest unit of the time format,
[0060] - the processing unit creates certificate time signatures based on the standardized certificate time according to the digital signature procedure,
[0061] - the computing unit creates an execution time specification having the time format, which execution time specification describes the execution time tl,
[0062] - the processing unit creates an execution time signature based on the execution time,
[0063] - the processing unit compares the execution time signature with the certificate time signatures,
[0064] - the processing unit determines a safe operating state if the execution time signature matches a certificate time signature,
[0065] - the processing unit detects an unsafe operating state if the execution time signature does not match any certificate time signature.
[0066] The above example is discussed further. The execution time t2 and the execution time specification, which specifies the execution time t2 in the mentioned time format, are 09.11.22. An execution time specification signature based on 09.11.22 does not match any of the certificate time specification signatures. The processing unit detects an unsafe operating state because the certificate has expired at the execution time t2, 09.11.22.
[0067] The method according to the invention in the fifth embodiment is characterized by the following method steps:
[0068] - at the delivery time tl, the computing unit determines a first component identifier of a first sensor as the first component,
[0069] - the computing unit creates a first component identification signature based on the first component identification using a digital signature procedure,
[0070] - the computing unit stores the first component identification signature in the internal database and in the external database,
[0071] - at the execution time t2, the computing unit queries a second component identifier of a second sensor as the second component or the component control unit controls the second sensor to determine a measurement data set,
[0072] - the second sensor sends a measurement data set to the component control unit in response to this query or in response to this control, which measurement data set comprises a measured value and the second sensor identifier,
[0073] - the processing unit stores the second sensor identification in the internal database,
[0074] - the processing unit creates a second sensor identification signature based on the second sensor identification using the digital signature method,
[0075] - the computing unit compares the first sensor identification signature with the second sensor identification signature
[0076] - the processing unit determines a safe operating state if the first sensor identification signature and the second sensor identification signature match,
[0077] - the computing unit detects an unsafe operating state if the first sensor identification signature and the second sensor identification signature do not match.
[0078] According to the prior art, a sensor can output a data set comprising a measured value and the sensor identifier. This particular property is taken into account by the above-mentioned embodiment of the method according to the invention.
[0079] The method according to the invention in the sixth embodiment is characterized by the following method steps:
[0080] - at a delivery time tl, the sensor processing unit controls the sensor to measure a first energy consumption of a motor of the machine, which motor executes the movement specified by the sensor processing unit,
[0081] - the sensor determines the first energy consumption of a drive of the machine in response to this control,
[0082] - the computing unit creates a positive first energy value if the first energy consumption lies within a predetermined first energy consumption range, or otherwise a negative first energy value if the first energy consumption does not lie within a predetermined first energy consumption range,
[0083] - the computing unit creates a first energy information signature based on the first energy information using a digital signature procedure,
[0084] - at an execution time t2, the sensor processing unit controls the sensor for measuring a second energy consumption of a motor of the machine, which motor executes the movement specified by the sensor processing unit,
[0085] - the sensor determines the second energy consumption of a drive of the machine in response to this control,
[0086] - the computing unit creates a positive second energy value if the second energy consumption is within a predefined second energy consumption range, or otherwise a negative second energy value if the second energy consumption is not within a predefined second energy consumption range,
[0087] - the computing unit determines a second energy indication signature based on the first energy consumption using a digital signature procedure,
[0088] - the computing unit compares the first energy indication signature with the second energy indication signature,
[0089] - the computing unit determines a safe operating state if the first energy indication signature and the second energy indication signature match,
[0090] - the computing unit detects an unsafe operating condition if the first energy indication signature and the second energy indication signature do not match.
[0091] The sensor control unit can control the sensor to determine the energy consumption of a component when performing a specified movement. The specified movement could, for example, be the lifting of a tamping unit, where the tamping unit is driven by the motor. The drive power of the motor thus causes the tamping unit to be raised. Instead of lifting the tamping unit, the user can specify other movements of other parts of the machine.
[0092] The specified movement is executed at the delivery time t1 and at the execution time t2. The energy consumption is determined for each of the specified movements. Thus, the first energy consumption for executing the specified movement is determined at the delivery time t1. Furthermore, the second energy consumption for executing the specified movement at the execution time t2 is determined.
[0093] Similar to the above-described embodiments of the method according to the invention, a first energy consumption signature and a second energy consumption signature are determined. The computing unit compares the energy consumption signatures to determine a safe operating state or an unsafe operating state.
[0094] Energy intake may be subject to normal fluctuations. The determined energy intake is compared with an energy intake range, and a positive energy value is generated if the energy intake is within the energy intake range, or a negative energy value is generated otherwise.
[0095] At the time of delivery tl, a positive first energy value is usually given, since the energy consumption complies with the standard.
[0096] At the execution time t2, a positive second energy value is created if the determined second energy consumption lies within the second energy consumption range.
[0097] The second energy absorption range may correspond to the first energy absorption range. Alternatively, the second energy absorption range may correspond to the first energy absorption range modified by a factor to account for wear on the machine and / or a changed energy consumption of the motor. The changed energy consumption of the motor occurs when a first energy consumption of the motor at the delivery time t1 differs from a second energy consumption of the motor at the implementation time t2.
[0098] A positive second energy value may be an indication that no part of the machine, such as a tamping unit, has been changed between the delivery time tl and the execution time t2.
[0099] A positive energy statement may be limited to the statement of the positive energy value.
[0100] A negative energy value may include an indication of the extent to which the determined energy intake differs from the energy intake range.
[0101] A seventh embodiment of the method according to the invention may comprise the following method steps:
[0102] - at the time of delivery tl, the processing unit creates a first user authorization signature based on a first positive user authorization according to the digital signature procedure,
[0103] - the processing unit stores the first user authorization signature in the internal database and in the external database,
[0104] - at the execution time t2, the sensor reads the user’s authorization time,
[0105] - the processing unit compares an authorization time specification of the user with the execution time t2 and the processing unit creates a second positive user authorization if the authorization time specification includes the execution time t2, or alternatively a second negative user authorization,
[0106] - the processing unit creates a second user authorization signature based on the second user authorization according to the digital signature procedure and
[0107] - the processing unit compares the second user authorization signature with the first user authorization signature of the internal database and / or the external database,
[0108] - Processing unit a secure operating state if the first user authorization signature and the second user authorization signature match, or otherwise an unsafe
[0109] Operating state if the first user authorization signature and the second user authorization signature do not match.
[0110] The authorization time can be stored on a card, which is read by a card reader. The card can store the authorization time, which indicates when a person is permitted to operate the machine.
[0111] The authorization time specification can specify a period of time during which a person is authorized to perform an action.
[0112] It may be necessary for the user to insert the card into the card reader at specified intervals to read the authorization time. This can prevent the user registered with the card from leaving the machine or another user from operating the machine. An authorization time that specifies the card reading at intervals does not include the execution time t2 if the card cannot be read at the specified time. Such an authorization time includes the execution time t2 if the card can be read at the specified time.
[0113] The positive user authorization can be limited to a specification of the positive user authorization. A negative user authorization can include a time value by which the authorization time specification differs from the execution time t2.
[0114] The first positive user authorization can be created by programming.
[0115] An eighth embodiment of the method according to the invention may comprise the following method steps:
[0116] - the sensor as a component is subjected to a calibration value,
[0117] - the sensor determines a measured value,
[0118] - the computing unit creates a measured value in a specified numerical format from the measured value,
[0119] - the computing unit creates a measured value signature based on the measured value information,
[0120] - the calculation unit creates a maximum series of different tolerance value specifications from a given tolerance range, which tolerance value specifications have the numerical format, whereby the difference between the individual tolerance value specifications is greater than or equal to the smallest unit of the numerical format,
[0121] - the calculation unit creates tolerance value signatures based on the tolerance value specifications,
[0122] - the computing unit stores the tolerance value signatures in the internal database and in the external database,
[0123] - the computing unit compares the measured value signature with the tolerance value signatures,
[0124] - the computing unit determines a safe operating state if the measured value signature matches a tolerance signature,
[0125] - the computing unit detects an unsafe operating condition if the measured value signature does not match any tolerance value signature.
[0126] For example, a first measured value determined by a sensor can be 2.51. The first measured value can be determined at the delivery time t1. By rounding the first measured value, this first measured value is converted into a first measured value, which first measured value has a predefined numerical format. For example, the predefined numerical format includes one decimal place; the measured value is thus 2.5.
[0127] For example, the tolerance range is 2.4 to 2.6. This therefore includes the tolerance values 2.4 and 2.5, as well as 2.6 in the specified numeric format. A first measured value signature based on the measured value 2.5 corresponds to the tolerance value signature of 2.5. The processing unit determines a safe operating condition at the delivery time tl.
[0128] The sensor can determine a second measured value of 2.93 at a time t2. The second measured value is 2.9. The second measured value signature based on the second measured value of 2.9 corresponds neither to the tolerance value signature based on 2.4 nor to the tolerance value signature based on 2.5 nor to the tolerance value signature based on 2.6. The processing unit therefore detects an unsafe operating condition.
[0129] The method according to the invention may comprise at least two embodiments from the mentioned first embodiment, the mentioned second embodiment, the mentioned third embodiment, the mentioned fourth embodiment, the mentioned fifth embodiment, the mentioned sixth embodiment, the mentioned seventh embodiment and the mentioned eighth embodiment and may further be characterized by the following steps:
[0130] - the processing unit determines an unsafe operating state if the first component identification signature and the second component identification signature or the first test specification signature and the second test specification signature or if the delivery time signature does not match any certificate time signature and the execution time signature does not match any certificate time signature, the first sensor identification signature and the second sensor identification signature or the first energy specification signature and the second energy specification signature or the measured value signature does not match any tolerance value signature.
[0131] In summary and general terms, the method according to the invention can provide that, at a delivery time t1, the first test data is collected depending on the validity of the certificate, a first identifier of a part of the machine, such as the first sensor, and an energy consumption for a specified movement. A first signature is created based on the first test data, the first sensor identifier, and the first energy consumption using a digital signature method.
[0132] Furthermore, at a time t2, the second test data is collected depending on the validity of the certificate, the second identifier of a part of the machine, such as the second sensor, and a second energy consumption for a given movement. A second signature is created based on the second test data, the second sensor identifier, and the second energy consumption.
[0133] The second signature is created exclusively based on values that are unchangeable between the delivery time t1 and the execution time t2, assuming the machine's state remains unchanged. This excludes, for example, measured values created at the execution time t2.
[0134] Since the same signature processes are used to create the first and second signatures, the signatures are comparable, allowing a change in the machine, a negative validity of a certificate, or a change in energy consumption to be detected. If a change in the machine is detected based on the comparison of the signatures, this state of the machine is objectively considered an unsafe operating condition. Otherwise, a machine's operating condition is objectively assessed as safe if the signatures are assessed as identical.
[0135] At the delivery time t1, the machine is in a first state created by a first person. The first person can be a machine manufacturer. In the method according to the invention, the first state is described by the first sensor identifier and the first certificate validity.
[0136] At execution time t2, the machine may be in a second state determined by a second person. The second state may be different from the first state. The second person may be another machine builder. The second state is incorporated into the method according to the invention in the form of the second sensor identifier and the second certificate validity.
[0137] A change in the machine that can be detected using this method can be a sensor replacement or a change in the validity of a certificate, in particular a certificate expiration. The method according to the invention also allows the detection of a replacement of moving parts by determining the energy consumption required to perform the movement.
[0138] The method according to the invention can be characterized in that
[0139] - at the time of delivery tl, the processing unit creates a first common signature based on at least two pieces of information from the first component identifier and the first test information and the first sensor identifier and the first energy information and the first user authorization according to the digital signature procedure,
[0140] - at the execution time t2, the processing unit creates a second common signature based on at least two relevant pieces of information from the second component identifier and the second test information and the second sensor identifier and the second energy information and the second user authorization according to the digital signature procedure,
[0141] - the computing unit compares the first common signature and the second common signature,
[0142] - the processing unit determines a safe operating state if the first common signature and the second common signature match,
[0143] - the computing unit determines an unsafe operating state if the first common signature and the second common signature do not match. The method according to the invention can be characterized in that
[0144] - at the time of delivery tl, the processing unit creates the first component identification signature exclusively based on the first component identification and the first test specification signature exclusively based on the first test specification and the first sensor identification signature exclusively based on the first sensor identification and the first energy specification signature exclusively based on the first energy specification and the first user authorization signature exclusively based on the first user authorization according to the digital signature procedure,
[0145] - at the execution time t2, the computing unit creates the second component identification signature based exclusively on the second
[0146] Component identification and the second test specification signature are created exclusively based on the second test specification and the second sensor identification signature are created exclusively based on the second sensor identification and the energy specification signature is created based on the second energy specification and the second user authorization signature is created exclusively based on the second user authorization according to the digital signature procedure,
[0147] - the processing unit compares the first component identification signature and the second component identification signature as well as the first test specification signature and the second test specification signature as well as the first sensor identification signature and the second sensor identification signature as well as the first energy specification signature and the second energy specification signature as well as the first user authorization signature and the second user authorization signature,
[0148] - the processing unit determines a safe operating state if the first component identification signature and the second component identification signature, as well as the first test specification signature and the second test specification signature, as well as the first sensor identification signature and the second sensor identification signature, as well as the first energy specification signature and the second energy specification signature, as well as the first user authorization signature and the second user authorization signature match,
[0149] - the computing unit determines an unsafe operating state if the first component identification signature and the second component identification signature, or the first test information signature and the second test information signature, or the first sensor identification signature and the second sensor identification signature, or the first energy information signature and the second energy information signature, or the first user authorization signature and the second user authorization signature do not match. The method according to the invention can be characterized in that the computing unit recognizes an operating state of the machine as a safe operating state and the computing unit outputs a protocol with an indication of the safe operating state.
[0150] The method according to the invention can be characterized in that the computing unit recognizes the operation of a machine as an unsafe operating state and outputs a protocol with an indication of the unsafe operating state.
[0151] The method according to the invention is preferably implemented as a computer-implemented method. The protocol can be created in the form of a log file.
[0152] A safe operating condition of the machine may require that the machine is operated, for example, by a person with authorization.
[0153] The method according to the invention can be characterized in that the component control unit sends to the sensor as a component a command file for controlling the sensor as a component, which command file comprises a sensor command, and the component control unit controls the sensor to determine the measured value at a measuring location and / or a measuring time according to the sensor command.
[0154] The method according to the invention may comprise
[0155] - the sensor is subjected to a calibration value,
[0156] - the computing unit compares the measured value measured by the sensor with a calibration value,
[0157] - the computing unit determines a measurement deviation of the sensor, by which measurement deviation the measured value differs from the calibration value,
[0158] - the computing unit assesses the operating condition as unsafe if the measurement deviation exceeds a specified tolerance.
[0159] The comparison of the measured value with a calibration value described here can be performed at the execution time t1 and / or at the execution time t2. The user can follow the specifications of standards, etc.
[0160] The aforementioned calibration can be performed by the sensor, which is subjected to a calibration value, producing a measured value, which is then compared with the calibration value. This checks whether the sensor is producing a measured value correctly.
[0161] The method according to the invention can be characterized in that
[0162] - at the time of delivery tl the sensor is subjected to a calibration value,
[0163] - the computing unit compares the measured value measured by the sensor with a calibration value,
[0164] - the computing unit determines a first measurement deviation of the sensor, by which first measurement deviation the measured value differs from the calibration value, - at the time t2 the sensor is subjected to a calibration value,
[0165] - the computing unit compares the measured value measured by the sensor with a calibration value,
[0166] - the computing unit determines a second measurement deviation of the sensor, by which second measurement deviation the measured value differs from the calibration value,
[0167] - at a delivery time tl, the processing unit creates a first positive sensor measurement status if a first measurement deviation is within the tolerance, or a first negative sensor measurement status if a first measurement deviation is outside the tolerance,
[0168] - the computing unit creates a first sensor measurement status signature based on the first sensor measurement status according to the digital signature procedure,
[0169] - the processing unit stores the first sensor measurement status signature in the internal database and in the external database,
[0170] - at an execution time t2, the computing unit creates a second positive sensor measurement status if a second measurement deviation is within the tolerance, or a second negative sensor measurement status if a second measurement deviation is outside the tolerance,
[0171] - the processing unit creates a second sensor measurement status signature based on the second sensor measurement status according to the digital signature procedure,
[0172] - the computing unit evaluates an operating state as safe if the first sensor measurement status signature and the second sensor measurement status signature match, or as unsafe if the first sensor measurement status signature and the second sensor measurement status signature do not match.
[0173] The positive sensor measurement status may be limited to an indication of the positive sensor measurement status.
[0174] The negative sensor measurement status can include the measured deviation in the form of a numerical value or a tolerance violation. The tolerance violation is the measurement deviation minus the tolerance.
[0175] The negative sensor measurement status may include an indication of the negative sensor measurement status.
[0176] The method according to the invention can be characterized in that the computing unit sends a command to the sensor control unit to determine the measured value at the delivery time t1 and / or at the execution time t2.
[0177] A machine sensor is exposed to various environmental influences, which can reduce the sensor's accuracy. It may therefore be necessary to check the sensor's accuracy at the time t1, with the sensor's accuracy at the delivery time t2 serving as the reference state.
[0178] The calibration value mentioned can also be a range specification. The measurement status can be a binary value.
[0179] It is also conceivable for the computing unit to compare a measured value and a calibration value at the delivery time t1 and at the execution time t2. The computing unit can also calculate a digital reference signature and a digital signature of a deviation between the measured value and the calibration value, or similar. Such a form of the method according to the invention would be conceivable, but less advantageous, since even a small, irrelevant change in the deviation would lead to a negative sensor measurement status unless compensated for by complex mathematical measures.
[0180] The method according to the invention can be characterized in that the computing unit sends a command for determining a measured value or measurement data at a time preceding the delivery time t1 or the execution time t2 and a further command for determining a further measured value or further measurement data at a time following the delivery time t1 or the execution time t2 to the sensor control unit.
[0181] In particular, the accuracy of a sensor can be checked immediately before and immediately after maintenance work has been performed. The accuracy check of a sensor mentioned here and above can also include a check of the sensor's functionality.
[0182] The method according to the invention can be characterized in that
[0183] - the sensor determines the measured value,
[0184] - the sensor processing unit creates a measured value signature based on the measured value output by the sensor using the digital signature method,
[0185] - the computing unit creates a measurement report containing the measured value,
[0186] - the processing unit creates a log file signature based on the measured value contained in the log file using the digital signature procedure,
[0187] - the processing unit creates the log file comprising a positive report status if the measured value signature and the log file signature match, or otherwise a negative report status if the measured value signature and the log file signature do not match,
[0188] - the computing unit outputs the report status in the log file.
[0189] This prevents the measured values from being documented exclusively in the documentation file, which also makes these measured values easily tamperable. For this reason, a digital signature of the measured value is created immediately after the sensor sends the measured value to the sensor processing unit, and before the user is aware of the measured value's existence. The signature is thus created at a time when manipulation of the measured value is unthinkable.
[0190] The additional digital signature is created when the measured value is prepared for display. The second signature is thus created at a time when the user has the opportunity to change the measured value in violation of regulations. Such a change can be detected by comparing the digital signatures.
[0191] The invention is further explained with reference to the following embodiments shown in the figures: Fig. 1 shows the method steps of the method according to the invention at the time of delivery,
[0192] Fig. 2 shows the process steps of the process according to the invention at a point in time of implementation.
[0193] The embodiments shown in the figures merely illustrate possible embodiments. It should be noted at this point that the invention is not limited to these specifically illustrated embodiments. Combinations of the individual embodiments with one another and a combination of an embodiment with the general description above are also possible. These further possible combinations do not need to be explicitly mentioned, since these further possible combinations are within the skill of the person skilled in this technical field based on the teaching of technical action based on the present invention.
[0194] The scope of protection is determined by the claims. However, the description and drawings must be used to interpret the claims. Individual features or combinations of features from the various embodiments shown and described may represent independent inventive solutions. The problem underlying these independent inventive solutions can be derived from the description.
[0195] Figure 1 and Figure 2 illustrate the method according to the invention comprising the above-mentioned first embodiment and the above-mentioned second embodiment.
[0196] Figure 1 basically illustrates the method steps of the delivery time t1. Figure 2 basically shows the method steps of the implementation time t1. The method according to the invention can comprise the method steps illustrated in Figure 1 and Figure 2.
[0197] The method according to the invention disclosed here addresses the task of determining whether a machine for repairing a track - also referred to here as a repair machine - when carrying out repair work by a user at a time t2 of execution has the state in which the machine was delivered by the machine manufacturer at the delivery time tl.
[0198] Machines used in the railway industry are often modified by third parties without the knowledge or consent of the machine manufacturer. The operation of a modified machine is generally considered an unsafe operating condition; the operation of an unmodified machine is considered a safe operating condition with regard to operational safety and the results of the work carried out with the machine.
[0199] The method disclosed herein is carried out as a computer-implemented method.
[0200] The machine comprises a computing unit, at least one sensor for recording at least one measured value from a track, and a sensor control unit. The computing unit can be considered a central control unit for controlling the machine. The computing unit includes a timer.
[0201] The aforementioned timer can be the sole timer of the machine, and machine components, such as a sensor, can request a time value from the sole timer if a control of the components requires a time value. This ensures that the control of the components is based on a single time value specified by the single timer. In particular, this ensures that a point in time is described by only a single time value and not by a multitude of time values that must be synchronized with one another.
[0202] The sensor control unit controls the sensor to record the at least one measured value. The sensor can be controlled in such a way that the sensor control unit specifies a measurement location and / or a measurement time for determining the measured value, independent of the timing or any other property of the sensor, as is known in the art.
[0203] The machine also includes an internal database. A certificate for the machine or a part of the machine, such as a sensor, is stored in the internal database. The certificate includes a certificate time stamp, which clearly defines the date until which a certificate is valid.
[0204] Data connections exist between the aforementioned units, the internal database, and an external database. The data connections and the databases can have different read and write permissions.
[0205] The method according to the invention is based on a definition of three possible states of the machine.
[0206] A state of the machine is the delivery state of the machine created by the machine manufacturer and thus handed over to a customer as user at a delivery time tl.
[0207] The other states are operating states in which the machine is under the responsibility of the customer as user.
[0208] Another state of the machine is the safe operating state of the machine during operation at a time t2. The safe operating state of the machine essentially corresponds to the delivery state, and the certificates are valid.
[0209] In contrast to a safe operating condition, an unsafe operating condition can also exist. An unsafe operating condition exists when the machine or parts of the machine have been modified compared to the delivery condition and / or a certificate has expired.
[0210] The method according to the invention is designed to determine whether the machine is in a safe or unsafe operating state at an execution time t2 occurring after the delivery time t1. The following method steps are required to implement the method according to the invention. The order of the method steps is predetermined only by specifying the respective times, such as execution time t1 and execution time t2, and is otherwise free.
[0211] Figure 1 illustrates the method steps of the method according to the invention at the time of delivery t1.
[0212] At the delivery time t1, the processing unit determines a first sensor identifier of the first sensor present at the delivery time t1. Using state-of-the-art methods, a sensor identifier of a sensor in general—here, the first sensor identifier of the sensor—can be queried. The first sensor transmits its first sensor identifier in response to this query.
[0213] The first sensor identifier can be a multi-digit code used by the sensor or machine manufacturer to uniquely identify the respective sensor. Such sensor identification codes are well known in the art.
[0214] The processing unit can store the first sensor identification in an internal database.
[0215] At execution time tl, the processing unit creates a first sensor identification signature based on the first sensor identification using a digital signature method. The processing unit stores the first signature in the internal database and in the external database.
[0216] The external database can be, for example, a cloud database.
[0217] At the delivery time tl, the processing unit compares the certificate time of a certificate stored in the internal database with the delivery time tl. The processing unit creates a positive initial verification result if the certificate time includes the delivery time tl, or alternatively, a negative initial verification result.
[0218] A test report prepared according to standard practice may include such a test statement. A positive test statement may be limited to the positive test statement, such as "certificate OK." A negative test statement may include the time value by which the certificate time exceeds the execution time tl.
[0219] Since usually only one machine is delivered with a valid signature, the first test result is usually positive.
[0220] It is also conceivable that the first positive test result is created by programming.
[0221] The processing unit creates an initial verification signature based on the first verification information using the digital signature procedure. The processing unit stores the verification signature in the internal database and the external database.
[0222] At the delivery time t1, a sensor is used to determine the first energy consumption of a motor. The sensor mentioned may be the first sensor. The first energy consumption may be necessary for the motor to initiate a specified movement of a mechanical part at the delivery time t1.
[0223] The initial energy requirement is compared with an initial energy consumption range. Since it can generally be assumed that the machine meets the specified requirements at the time of delivery tl, a positive initial energy value is established.
[0224] The above description includes information about the content of a positive energy value and a negative energy value. The positive energy value can, for example, include the statement "energy intake OK" or a numerical value such as "100."
[0225] The processing unit, in turn, creates a first energy specification signature based on the first energy specification. The energy specification signature is stored in the internal database and the external database.
[0226] In summary, the method according to the invention offers the machine manufacturer the possibility of documenting the condition of the delivered machine at the time of delivery t1 on the basis of the first sensor identification, on the basis of the first certificate time indication and on the basis of the first energy consumption for carrying out a specified movement.
[0227] Preferably, only the machine manufacturer has the necessary write and read rights on the internal database and the external database in order to document the condition of the machine based on the first sensor identification and the certificate validity in the respective database.
[0228] Figure 2 illustrates the method steps of the method according to the invention at the execution time t2, which execution time t2 occurs after the delivery time t1. The method steps at the execution time t2 essentially relate to the operation of the machine on the railway line.
[0229] At the execution time t2, the second sensor identifier of the second sensor is collected.
[0230] The second sensor identification of the second sensor at execution time t2 can be performed by the computing unit querying the second sensor identification of the second sensor from the second sensor itself or, equivalently, from a data storage device. Alternatively or additionally, the sensor control unit can control the second sensor to determine a measured value.
[0231] The second sensor sends a measurement data set to the sensor control unit in response to the query or in response to the control of the computing unit.
[0232] The measurement data set includes the measured value and the second sensor identifier. When the second sensor identifier is requested as mentioned above, the measured value is usually zero. When the control method is used as described above, the measured value is the quantity determined by the second sensor.
[0233] The processing unit can store the second sensor identifier in the internal database. The second sensor identifier can be stored as part of the measurement data set or separately. The processing unit creates a second sensor identifier signature based on the second sensor identifier using the same digital signature method used to create the first sensor identifier signature.
[0234] The sensor identification signature is not created based on the measured value using the digital signature method.
[0235] At execution time t2, the processing unit compares the certificate time with the execution time t2. The processing unit generates a positive second verification result if the certificate time includes the execution time t2, or alternatively, a negative second certificate validity result.
[0236] The second test statement can also be part of a test report. The second test statement is created according to the same principle as the first test statement.
[0237] The positive second test statement can only include the positive second test statement. Examples for the positive first test statement are provided above, and these examples apply to the second test statement.
[0238] The negative second test result may include a time value indicating the time by which the execution time t2 exceeds the certificate time. Additionally, the negative second test result may include the indication "certificate not valid."
[0239] A certificate can be valid for a defined period of time starting from the delivery time t1. Within the scope of the disclosure of the method according to the invention, the delivery time t1 can be the time at which the machine is handed over from the factory or on the railway line by the machine manufacturer to the user after an overhaul for maintenance work.
[0240] The certificate time is a point in time within the specified period during which the certificate is valid, and thus defines the point in time at which the machine has a valid certificate. By comparing the certificate time with the delivery time t1 or the execution time t2, it is determined whether the machine has a valid certificate at the delivery time t1 or the execution time t2.
[0241] The second test result created at execution time t2 can be stored by the processing unit in an internal database.
[0242] Furthermore, a second verification signature will be created based on the second verification signature using the digital signature method used to create the first verification signature.
[0243] It is particularly noted that the digital signature method for creating the sensor identification signatures and the digital signature method for creating the test data signatures do not have to be the same signature method. At the time of execution, the second energy consumption of the motor for performing a specified movement of a part of the machine is determined. A second energy consumption that differs from the first energy consumption is an indication of a replacement or modification of the part of the machine.
[0244] The second energy consumption is compared with a second energy consumption range. The second energy consumption range is a range specification of the first energy consumption range modified by a factor. This prevents a normal modification of the machine and a related change in energy demand from leading to the incorrect assumption that the mentioned part of the machine was replaced between the delivery time tl and the implementation time.
[0245] A positive or negative second energy rating is then created, as sufficiently disclosed in the description. The negative second energy rating can include a variable value dependent on the determined energy consumption. The negative second energy rating can, for example, include "energy consumption not acceptable, exceeded by 10%."
[0246] A second energy specification signature is created for the second energy specification. The second energy specification signature is stored in the internal database and the external database.
[0247] The method according to the invention may include the step of creating a log file. The log file may represent an output of the measurement data over a period of time encompassing the execution time t2. The log file may include the output of multiple measurement data sets created at successive execution times.
[0248] Since the method according to the invention is a computer-implemented method, the log file is available as a single file. In addition, the contents of the log file can also be printed out and thus be available in paper form.
[0249] The method according to the invention allows the determination of a safe operating state of the machine at the time t2.
[0250] The first signatures are the first sensor identification signature, the first test specification signature, and the first energy specification signature. The first signatures describe the condition of the machine at the time of delivery tl.
[0251] The second sensor identification signature, the second test specification signature, and the second energy specification signature are also present as second signatures. The second signatures describe the state of the machine at execution time t2.
[0252] The assessment of the operating state as a safe operating state or as a secure operating state is based on a comparison of the first signatures with the second signatures.
[0253] The creation of the first and second signatures is designed such that the first and second signatures are identical if the machine at delivery time t1 corresponds to the machine at execution time t2. The first and second signatures are created exclusively based on values that are identical for the same machine at delivery time t1 and delivery time t2.
[0254] If there is an active data connection between the processing unit and the external database, the processing unit compares the first signature stored in the external database and created at the delivery time tl with the second digital signature created at the execution time t2.
[0255] It may be the case that there is no data connection between the computing unit and the external database. This can be the case, for example, if the machine is located in a tunnel and the external database is a cloud storage.
[0256] If the data connection between the processing unit and the external database is not maintained, the processing unit compares the first signatures stored in the internal database and created at the delivery time tO with the signature created at the execution time t2.
[0257] The method according to the invention can also comprise a two-stage comparison of the digital signatures. In a first comparison step, the second signatures are compared with the first signatures stored in the internal database, and in a second comparison step, they are compared with the first signature stored in the external database. The second comparison step can be performed independently of or dependent on the result of the first comparison step.
[0258] A log file created upon implementation of the method according to the invention may include an indication of whether the operating state of the machine is considered safe or unsafe. Compared to prior art methods, the method according to the invention has the advantage that this assessment is based exclusively on objective criteria.
[0259] By definition, a safe operating state exists if, at execution time t2, the second state of the machine corresponds to the first state of the machine and the certificates are valid for a specific period of time. Using the method according to the invention, such a safe operating state can be clearly identified if the first signatures correspond to the second signatures. This statement from this comparison is achieved by creating the signatures from values that do not change in a safe operating state between the delivery time t1 and the execution time t2. This includes ensuring that no sensors on the machine have been modified and that a valid certificate is available.
[0260] A safe operating state exists if the first sensor identification signature and the second sensor identification signature, as well as the first test information signature and the second test information signature, and the first energy information signature and the second energy information signature are identical. The processing unit determines this identicalness by comparing the aforementioned signatures.
[0261] Alternatively, an unsafe operating condition can be detected. An unsafe operating condition exists if a sensor on the machine has been modified or the certificate is no longer valid. An unsafe operating condition exists if the first sensor identification signature and the second sensor identification signature, or the first test information signature and the second test information signature, or the first energy information signature and the second energy information signature are not the same. The processing unit determines this inequality by comparing the aforementioned signatures.
[0262] The method according to the invention can be extended to determine user authorization.
[0263] The measured value determined by the sensor can be a measured value describing a user. The machine can include a sensor for reading user data. The sensor can, for example, include a card reader for reading user data.
[0264] The method according to the invention can comprise the computing unit creating a user authorization signature based on a first positive user authorization according to the digital signature method at the delivery time t1. The computing unit stores the first user authorization signature in the internal database and in the external database.
[0265] The first positive user authorization can be programmed.
[0266] At execution time t2, the processing unit compares the user's authorization time with the execution time t2. The processing unit creates a second positive user authorization if the authorization time includes the execution time t1, or otherwise creates a second negative user authorization if the authorization time does not include the execution time t1.
[0267] The aforementioned authorization time information can be stored on a card, which card is read with a card reader comprising the sensor.
[0268] The processing unit creates a second user authorization signature based on the second user authorization. The same encryption method is used as for the creation of the first user authorization signature.
[0269] To evaluate the operating state, the processing unit compares the first user authorization signature with the second user authorization signature of the internal database and / or the external database. A secure operating state exists if the first user authorization signature corresponds to the second user authorization and the above conditions for a secure operating state are also met. Otherwise, the operating state is assessed as unsafe if a first signature and a second signature are not the same.
[0270] The method according to the invention may also include evaluating the operation with respect to a valid sensor measurement status of the sensor.
[0271] For example, the relevant standards suggest applying a calibrated measurement value to the sensor, determining the measured value, and comparing it with a calibration value. The sensor sends the measured value to the processing unit. The processing unit compares the measured value with the calibration value and creates a positive sensor measurement status if the measured value corresponds to the calibration value, or alternatively, a negative sensor measurement status.
[0272] The positive sensor measurement status can be limited to the positive sensor measurement status. The negative sensor measurement status can include a deviation specification, indicating the amount by which the measured value differs from the calibration value. The deviation specification can be a numerical value or a range specification.
[0273] This process of determining the sensor measurement status can be determined at the delivery time tl. Since only a machine that complies with the standards may be delivered, a first positive sensor measurement status is created at the delivery time tl. The processing unit creates a first sensor measurement status signature based on the measurement status using a digital signature process. The signature of the first sensor measurement status is stored in the internal database and / or the external database.
[0274] A positive sensor measurement status can also be created through programming at the time of delivery. However, this has the disadvantage that the sensor's accuracy is not verified.
[0275] Analogous to the determination of the first sensor measurement status, the second sensor measurement status can also be determined at the execution time t2. A sensor measurement status can also be determined at a time preceding the execution time t2 and / or at a time following the execution time t2.
[0276] The computing unit creates a second sensor measurement status signature based on the second sensor measurement status according to the digital signature method.
[0277] To evaluate the operating state, the computing unit compares the first measurement status signature with the second sensor measurement status signature from the internal database and / or the external database. A safe operating state exists if the first sensor measurement status signature matches the second sensor measurement status signature and the above conditions for a safe operating state are also met. Otherwise, the operating state is assessed as unsafe if the first signature and the second signature are not the same.
[0278] Figure 3 illustrates, in particular, a part of the method according to the invention, which part is handled after or during the execution time t2, in a form different from the representation in Figure 2. The assessment of the operating state as safe or unsafe based on a property of the machine is generally explained.
[0279] The property of the machine considered below is, in the most general case, described by a value, which is referred to below as the property value. The property value can—with reference to the above description—be an identifier or a time specification.
[0280] The computing unit determines a first property value of a first part of the machine at a delivery time t1. The computing unit can store the first property value in the internal database. The first property value from the internal database can be read as such by other units of the machine for further processing, such as performing a comparison with another value. This is not considered in Figure 3.
[0281] The processing unit creates a first signature based on the first property value of the first unit of the machine using a digital signature process. The first signature of the first property value is created in order to be able to compare a second property value determined at a subsequent execution time t2 with the first property value using a secure, integrity-based process.
[0282] The processing unit stores the first signature of the first property value in an external database, such as a cloud. The external database is located outside the machine. This ensures that the documentation of the first property value is within the control of the machine manufacturer. The first signature can only be retrieved from the external database if a data connection exists between the machine and the external database.
[0283] The processing unit stores the first signature of the first property value in an internal database. This should enable a comparison of the property values if there is no data connection between the machine and the external database.
[0284] The computing unit determines the second property value of a second part of the machine at an execution time t2.
[0285] The computing unit determines a second signature based on the second property value according to the digital encryption method used to create the first signature.
[0286] If a data connection is established between the computing unit and the external database, the computing unit retrieves the first signature of the first property value from the external database. Alternatively or additionally, the computing unit can retrieve the first signature of the first property value from the internal database. Figure 3 shows the external database and the internal database unified as a single database. The representation in Figure 3 does not differentiate between the aforementioned databases.
[0287] The processing unit compares the first signature with the second digital signature. If the digital signatures are identical, the operating state is considered secure. If the first signature and the second signature do not match, the operating state is considered unsafe.
[0288] In addition to an assessment of the operation as unsafe, the repair process can also be stopped.
[0289] In a safe operating condition, at least one measured value is determined with at least one sensor.
[0290] The method according to the invention can comprise a definition of conditions under which a measured value can be determined by means of a sensor in an unsafe operating state.
[0291] The method according to the invention can be characterized in that the sensor processing unit creates a signature of the measured values output by the sensor and / or received by the sensor processing unit using a digital signature method. Thus, a first signature of the measured values is created before the measured values can be altered by a person in a manner not specified here.
[0292] The processing unit creates an additional signature for the measured values included in a log file using a digital signature process. A positive report status is recorded in the log file if the digital signature of the measured values and the additional digital signature of the measured values match. A negative report status is created in the log file if the digital signature of the measured values and the additional digital signature of the measured values do not match.
[0293] This prevents the measured values listed in the log file from differing from the measured values (actually) determined by the sensor due to unauthorized manipulation. The report status can be generated in parallel with the creation of the log file.
Claims
Patent claims 1. A method for determining a safe operating state of a machine for maintaining a railway line at an execution time t2, which machine comprises a computing unit with a timer, at least one electronic component, a component control unit, and an internal database, which component control unit controls the component, in which internal database a certificate of the machine with a certificate time specification is stored, wherein data connections exist between the mentioned units and the internal database and / or an external database, which machine can alternatively be in a delivery state at a delivery time t1, a safe operating state at an execution time t2, or an unsafe operating state, which timer outputs the delivery time t1 and the execution time t2, which delivery time t1 lies before the execution time t2,which procedure is characterized by the following steps:, - at the delivery time tl, the computing unit determines a first component identifier of a first component, - the computing unit creates a first component identification signature based on the first component identification using a digital signature procedure, - the computing unit stores the first component identification signature in the internal database and in the external database, - at the execution time t2, the computing unit queries a second component identifier of a second component, - the second component sends a data record to the component control unit in response to this query, which data record includes the second component identifier, - the computing unit stores the second component identifier in the internal database, - the processing unit creates a second component identification signature based on the second component identification using the digital signature procedure, - the computing unit compares the first component identification signature with the second component identification signature, - the processing unit determines a safe operating state if the first component identification signature and the second component identification signature match, - the computing unit determines an unsafe operating state if the first component identification signature and the second component identification signature do not match. A method for determining a safe operating state of a machine for maintaining a railway line at an execution time t2, which machine comprises a computing unit with a timer, at least one electronic component, a component control unit, and an internal database, which component control unit controls the component, in which internal database a certificate of the machine with a certificate time specification is stored, wherein data connections exist between the mentioned units and the internal database and / or an external database, which machine can alternatively be in a delivery state at a delivery time t1, a safe operating state at an execution time t2, or an unsafe operating state,which timer outputs the delivery time tl and the execution time t2, which delivery time tl is before the execution time t2, which method is characterized by the following steps:, - at the delivery time tl, the processing unit compares the certificate time with the delivery time tl, - the processing unit creates a positive first check if the certificate time includes the delivery time tl, or otherwise a negative first check if the certificate time does not include the delivery time tl, - the processing unit creates a first verification signature based on the first verification according to the digital signature procedure, - the processing unit stores the first verification signature in the internal database and in the external database, - at the execution time t2, the processing unit compares the certificate time with the execution time t2, the processing unit creates a positive second check if the certificate time includes the execution time t2, or otherwise a negative second check if the certificate time does not include the execution time t2, - the processing unit creates a second verification signature based on the second verification according to the digital signature procedure, - the arithmetic unit compares the first verification signature with the second verification signature, - the processing unit determines a safe operating state if the first test signature and the second test signature match, - the computing unit determines an unsafe operating state if the first test signature and the second test signature do not match. A method for determining a safe operating state of a machine for maintaining a railway line at an execution time t2, which machine comprises a computing unit with a timer, at least one electronic component, a component control unit, and an internal database, which component control unit controls the component, in which internal database a certificate of the machine with a certificate time is stored, wherein data connections exist between the mentioned units and the internal database and / or an external database, which machine can alternatively be in a delivery state at a delivery time t1, a safe operating state at an execution time t2, or an unsafe operating state,which timer outputs the delivery time tl and the execution time t2, which delivery time tl is before the execution time t2, which method is characterized by the following steps:, - the computing unit creates a certificate time range comprising the delivery time tl and the certificate time specification, - the computing unit creates a series of certificate time specifications within the certificate time range, which certificate time specifications have a uniform time format, whereby each time difference between the individual certificate time specifications is greater than or equal to the smallest unit of the time format, - the processing unit creates certificate time signatures based on the certificate time according to the digital signature procedure, - the processing unit stores the certificate time signatures in the internal database and in the external database, - the computing unit creates a delivery time specification having the time format, which delivery time specification describes the delivery time tl, - the processing unit creates a delivery time signature based on the standardized delivery time, - the processing unit compares the delivery time signature with the certificate time signatures, - the processing unit determines a secure operating state if the delivery time signature matches a certificate time signature, - the computing unit determines an unsafe operating state if the delivery time signature does not match any certificate time signature. A method for determining a safe operating state of a machine for maintaining a railway line at an execution time t2, which machine comprises a computing unit with a timer, at least one electronic component, a component control unit, and an internal database, which component control unit controls the component for recording the at least one measured value, in which internal database a certificate of the machine with a certificate time is stored, wherein data connections exist between the mentioned units and the internal database and / or an external database, which machine is alternatively in a delivery state at a delivery time t1,at an execution time t2 can be in a safe operating state or an unsafe operating state, which timer outputs the delivery time tl and the execution time t2, which delivery time tl is before the execution time t2, which method is characterized by the following steps:, - the computing unit creates a certificate time range comprising the delivery time tl and the certificate time specification, - the computing unit creates a series of certificate time specifications within the certificate time range, which certificate time specifications have a uniform time format, whereby each time difference between the individual certificate time specifications is greater than or equal to the smallest unit of the time format, - the processing unit creates certificate time signatures based on the uniform certificate time according to the digital signature procedure, - the computing unit creates an execution time specification in the time format, which execution time specification describes the execution time tl, - the processing unit creates an execution time signature based on the execution time, - the processing unit compares the execution time signature with the certificate time signatures, - the processing unit determines a secure operating state if the execution time signature matches a certificate time signature, - the computing unit determines an unsafe operating state if the execution time signature does not match any certificate time signature. A method for determining a safe operating state of a machine for maintaining a railway line at an execution time t2, which machine comprises a computing unit with a timer, at least one electronic component, a component control unit, and an internal database. The component control unit controls the component, in which internal database a certificate of the machine with a certificate time is stored, wherein data connections exist between the mentioned units and the internal database and / or an external database. The machine can alternatively be in a delivery state at a delivery time t1, a safe operating state at an execution time t2, or an unsafe operating state.which timer outputs the delivery time tl and the execution time t2, which delivery time tl is before the execution time t2, which method is characterized by the following steps:, - at the delivery time tl, the computing unit determines a first component identifier of a first sensor as the first component, - the computing unit creates a first component identification signature based on the first component identification using a digital signature procedure, - the computing unit stores the first component identification signature in the internal database and in the external database, - at the execution time t2, the computing unit queries a second component identifier of a second sensor as the second component or the component control unit controls the second sensor to determine a measurement data set, - the second sensor sends a measurement data set to the component control unit in response to this query or in response to this control, which measurement data set comprises a measured value and the second sensor identifier, - the processing unit stores the second sensor identification in the internal database, - the processing unit creates a second sensor identification signature based on the second sensor identification using the digital signature method, - the computing unit compares the first sensor identification signature with the second sensor identification signature - the processing unit determines a safe operating state if the first sensor identification signature and the second sensor identification signature match, - the computing unit determines an unsafe operating state if the first sensor identification signature and the second sensor identification signature do not match. A method for determining a safe operating state of a machine for maintaining a railway line at an execution time t2, which machine comprises a computing unit with a timer, at least one electronic component, a component control unit, and an internal database, which component control unit controls the component, in which internal database a certificate of the machine with a certificate time specification is stored, wherein data connections exist between the mentioned units and the internal database and / or an external database, which machine can alternatively be in a delivery state at a delivery time t1, a safe operating state at an execution time t2, or an unsafe operating state,which timer outputs the delivery time tl and the execution time t2, which delivery time tl is before the execution time t2, which method is characterized by the following steps:, - at a delivery time tl, the component control unit controls the sensor as a component for measuring a first energy consumption of a motor of the machine, which motor executes a movement specified by the component control unit, - the component determines the first energy consumption of the motor in response to this control, - the computing unit creates a positive first energy value if the first energy consumption is within a predetermined first energy consumption range, or otherwise a negative first energy value if the first energy consumption is not within a predetermined first energy consumption range, - the computing unit creates a first energy information signature based on the first energy information using a digital signature procedure, - at an execution time t2, the component control unit controls the sensor as a component for measuring a second energy consumption of the motor of the machine, which motor executes a movement specified by the component control unit, - the sensor determines the second energy consumption of the motor in response to this control, - the computing unit creates a positive second energy value if the second energy consumption is within a second predefined energy consumption range, or otherwise a negative second energy value if the second energy consumption is not within a predefined second Energy absorption range, - the computing unit determines a second energy indication signature based on the first Energy absorption according to a digital signature procedure, - the computing unit compares the first energy indication signature with the second energy indication signature, - the computing unit determines a safe operating state if the first energy indication signature and the second energy indication signature match, - the computing unit determines an unsafe operating state if the first energy specification signature and the second energy specification signature do not match. A method for determining a safe operating state of a machine for maintaining a railway line at an execution time t2, which machine comprises a computing unit with a timer, at least one electronic component, a component control unit, and an internal database, which component control unit controls the component, in which internal database a certificate of the machine with a certificate time specification is stored, wherein data connections exist between the mentioned units and the internal database and / or an external database, which machine can alternatively be in a delivery state at a delivery time t1, a safe operating state at an execution time t2, or an unsafe operating state,which timer outputs the delivery time tl and the execution time t2, which delivery time tl is before the execution time t2, which method is characterized by the following steps:, - at the time of delivery tl, the processing unit creates a first user authorization signature based on a first positive user authorization according to the digital signature procedure, - the processing unit stores the first user authorization signature in the internal database and in the external database, - at the execution time t2, the sensor reads the user’s authorization time, - the processing unit compares an authorization time specification of the user with the execution time t2 and the processing unit creates a second positive user authorization if the authorization time specification includes the execution time t2, or alternatively a second negative user authorization, - the processing unit creates a second user authorization signature based on the second user authorization according to the digital signature procedure and - the processing unit compares the second user authorization signature with the first user authorization signature of the internal database and / or the external database, - The computing unit determines a safe operating state if the first user authorization signature and the second user authorization signature match, or otherwise an unsafe operating state if the first user authorization signature and the second user authorization signature do not match. A method for determining a safe operating state of a machine for maintaining a railway line at a time t2, which machine comprises a computing unit with a timer, at least one electronic component, a component control unit, and an internal database, which component control unit controls the component, in which internal database a certificate of the machine with a certificate time specification is stored, wherein data connections exist between the mentioned units and the internal database and / or an external database,which machine can alternatively be in a delivery state at a delivery time tl, a safe operating state at an execution time t2, or an unsafe operating state, which timer outputs the delivery time tl and the execution time t2, which delivery time tl is before the execution time t2, which method is characterized by the following steps: - the sensor as a component is subjected to a calibration value, - the sensor determines a measured value, - the computing unit creates a measured value in a specified numerical format from the measured value, - the computing unit creates a measured value signature based on the measured value information, - the calculation unit creates a series of tolerance value specifications from a given tolerance range, which tolerance value specifications have the numerical format, whereby the difference between the individual tolerance value specifications is greater than or equal to the smallest unit of the numerical format, - the calculation unit creates tolerance value signatures based on the standardized tolerance value specifications, - the computing unit stores the tolerance value signatures in the internal database and in the external database, - the computing unit compares the measured value signature with the tolerance value signatures, - the computing unit determines a safe operating state if the measured value signature matches a tolerance signature, - the computing unit determines an unsafe operating condition if the measured value signature does not match any tolerance value signature. Method according to at least two of claims 1 to 8, which method is further characterized by the following steps: - the processing unit determines a safe operating state if the first component identification signature and the second component identification signature as well as the first test specification signature and the second test specification signature as well as the delivery time signature and one of the certificate time signatures as well as the execution time signature with a certificate time signature, the first sensor identification signature and the second sensor identification signature as well as the first energy specification signature and the second energy specification signature as well as the measured value signature and one of the tolerance value signatures match, - the computing unit determines an unsafe operating state if the first component identification signature and the second component identification signature, or the first test specification signature and the second test specification signature, or the delivery time signature and the certificate time signature, or the execution time signature and the certificate time signature, the first sensor identification signature and the second sensor identification signature, or the first energy specification signature and the second energy specification signature, or the measured value signature do not match any tolerance value signature. Method according to one of claims 1 to 9, characterized in that - at the time of delivery tl, the processing unit creates a first common signature based on at least two pieces of information from the first component identifier and the first test information and the first sensor identifier and the first energy information and the first user authorization according to the digital signature procedure, - at the execution time t2, the processing unit creates a second common signature based on at least two relevant pieces of information from the second component identifier and the second test information and the second sensor identifier and the second energy information and the second user authorization according to the digital signature procedure, - the computing unit compares the first common signature and the second common signature, - the processing unit determines a safe operating state if the first common signature and the second common signature match, - the computing unit detects an unsafe operating state if the first common signature and the second common signature do not match. Method according to one of claims 1 to 9, characterized in that - at the time of delivery tl, the processing unit creates the first component identification signature exclusively based on the first component identification and the first test specification signature exclusively based on the first test specification and the first sensor identification signature exclusively based on the first sensor identification and the first energy specification signature exclusively based on the first energy specification and the first user authorization signature exclusively based on the first user authorization according to the digital signature procedure, - at the execution time t2, the computing unit creates the second component identification signature exclusively based on the second component identification and the second test information signature exclusively based on the second test information and the second sensor identification signature exclusively based on the second sensor identification and the energy information signature based on the second energy information and the second user authorization signature exclusively based on the second user authorization according to the digital signature method, - the processing unit compares the first component identification signature and the second component identification signature as well as the first test specification signature and the second test specification signature as well as the first sensor identification signature and the second sensor identification signature as well as the first energy specification signature and the second energy specification signature as well as the first user authorization signature and the second user authorization signature, - the processing unit determines a safe operating state if the first component identification signature and the second component identification signature as well as the first test specification signature and the second test specification signature as well as the first sensor identification signature and the second sensor identification signature as well as the first energy specification signature and the second energy specification signature and the first user authorization signature and the second user authorization signature match, - the computing unit determines an unsafe operating state if the first component identification signature and the second component identification signature, or the first test information signature and the second test information signature, or the first sensor identification signature and the second sensor identification signature, or the first energy information signature and the second energy information signature, or the first user authorization signature and the second user authorization signature do not match. Method according to one of claims 1 to 11, characterized in that the computing unit recognizes an operating state of the machine as a safe operating state, and the computing unit outputs a log with an indication of the safe operating state. Method according to one of claims 1 to 12, characterized in that the computing unit recognizes operation of a machine as an unsafe operating state and outputs a log with an indication of the unsafe operating state.Method according to one of claims 3 or 10 to 13, characterized in that the component control unit sends a command file to the sensor as a component for controlling the sensor as a component, which command file comprises a sensor command, and the component control unit controls the sensor to determine the measured value at a measuring location and / or a measuring time according to the sensor command. Method according to one of claims 3 or 10 to 14, characterized in that. - the sensor is subjected to a calibration value, - the computing unit compares the measured value measured by the sensor with a calibration value, - the computing unit determines a measurement deviation of the sensor, by which measurement deviation the measured value differs from the calibration value, - the computing unit evaluates the operating state as unsafe if the measurement deviation exceeds a predetermined tolerance. Method according to claim 15, characterized in that - at the time of delivery tl the sensor is subjected to a calibration value, - the computing unit compares the measured value measured by the sensor with a calibration value, - the computing unit determines a first measurement deviation of the sensor, by which first measurement deviation the measured value differs from the calibration value, - at the time t2 the sensor is subjected to a calibration value, - the computing unit compares the measured value measured by the sensor with a calibration value, - the computing unit determines a second measurement deviation of the sensor, by which second measurement deviation the measured value differs from the calibration value, - at a delivery time tl, the processing unit creates a first positive sensor measurement status if a first measurement deviation is within the tolerance, or a first negative sensor measurement status if a first measurement deviation is outside the tolerance, - the computing unit creates a first sensor measurement status signature based on the first sensor measurement status according to the digital signature procedure, - the processing unit stores the first sensor measurement status signature in the internal database and in the external database, - at an execution time t2, the computing unit creates a second positive sensor measurement status if a second measurement deviation is within the tolerance, or a second negative sensor measurement status if a second measurement deviation is outside the tolerance, - the processing unit creates a second sensor measurement status signature based on the second sensor measurement status according to the digital signature procedure, - the computing unit evaluates an operating state as safe if the first sensor measurement status signature and the second sensor measurement status signature match, or as unsafe if the first sensor measurement status signature and the second sensor measurement status signature do not match. Method according to one of claims 3 or 10 to 16, characterized in that the computing unit sends the sensor command for determining the measured value to the component control unit at the delivery time t1 and / or at the execution time t2.Method according to one of claims 3 or 10 to 17, characterized in that the computing unit sends the sensor command for determining a measured value or measurement data at a time preceding the delivery time t1 or the execution time t2 and a further command for determining a further measured value or further measurement data at a time following the delivery time t1 or the execution time t2 to the component control unit. Method according to one of claims 3 or 11 to 18, characterized in that. - the sensor determines the measured value, - the component control unit creates a measured value signature based on the measured value output by the sensor using the digital signature method, - the computing unit creates a measurement report containing the measured value, - the processing unit creates a log file signature based on the measured value contained in the log file using the digital signature procedure, - the processing unit, including the log file, gives a positive report status if the measured value signature and the log file signature match, or a negative report status otherwise Report status, if the measured value signature and the log file signature do not match, created, - the computing unit outputs the report status in the log file.