Method for checking and updating computing instances of rail vehicle

EP4724324A1Pending Publication Date: 2026-04-15SIEMENS MOBILITY GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
SIEMENS MOBILITY GMBH
Filing Date
2023-10-20
Publication Date
2026-04-15

AI Technical Summary

Technical Problem

The challenge lies in efficiently updating and ensuring operational safety of software on freight wagons, which are frequently recombined and have varying software versions and digital certificates, making it difficult to maintain compatibility and security within rail vehicle groups.

Method used

A method for checking computing instances on rail vehicles, where a locomotive or freight wagon establishes communication with other vehicles to assess software and hardware properties, generating messages on up-to-dateness and digital certificate validity, enabling quick determination of compatibility and necessitating updates if required, and allowing for automatic software and certificate updates via a central server.

Benefits of technology

This method ensures that rail vehicle groups are operationally ready by determining compatibility and updating software and certificates, enhancing operational safety and efficiency in rail-bound freight traffic by reducing manual updates and maintaining compatibility across different vehicle combinations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2023079356_16012025_PF_FP_ABST
    Figure EP2023079356_16012025_PF_FP_ABST
Patent Text Reader

Abstract

The invention comprises the following subject matter: a method for checking computing instances (RI) of rail vehicles, wherein programs installed on the computing instances (RI) and / or configurations stored in the computing instances (RI) are checked, of said rail vehicles, a first rail vehicle (FZ1), which is a locomotive (LV) or a goods carriage (GW), forms a coupled vehicle group (FV) with at least one second rail vehicle (FZ2), which is a goods carriage (GW), the computing instances (RI) in the vehicle group (FV) are checked by the first rail vehicle (FZ1), a communication connection is established between the computing instance (RI) of the first rail vehicle (FZ1) and the computing instance (RI) at least of the second rail vehicle (FZ2) via a first interface (S1), the computing instance (RI) of the first rail vehicle (FZ1) receives, via the communication connection, data from at least the computing instance (RI) of the second rail vehicle (FZ2) about the software properties of the programs and / or stored configurations present on the rail vehicles concerned, on the basis of the received data a message is generated which relates to an up-to-dateness of the software properties and / or configurations and the validity of a digital certificate for operation of the programs. On the basis of this message, a simple software update can also be performed advantageously for goods carriages (GW). The invention also relates to a goods carriage (GW) and locomotive (LV), and to a computer program.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] PROCEDURE FOR CHECKING AND UPDATING COMPUTING INSTANCES OF RAIL VEHICLES

[0003] Technical area

[0004] The invention further comprises a method for checking computing instances of rail vehicles. The invention further comprises a locomotive. The invention further comprises a freight car. The invention further comprises a computer program. The invention further comprises a computer-readable storage medium.

[0005] Technical background

[0006] According to the state of the art, it is known that communication between freight wagons needs to be improved. For this purpose, the digital automatic coupling (DAK) is being developed in Europe. This, among other things, also provides a communication interface so that the freight wagons can communicate with each other by connecting them and to a locomotive via cable.

[0007] The digital automatic coupling is currently being tested. Vehicle convoys consisting of locomotives and freight wagons that are coupled together via the digital automatic coupling have hardware that forms a computing instance on each freight wagon and on the locomotive. The hardware therefore has at least one computer, also known as an onboard unit (OBU), per vehicle, on which the necessary software is installed in the form of programs. These programs must be kept up to date, with updates being carried out manually by test project employees connecting directly to the computers to be updated. Each freight wagon forms an independent unit, as required by the standards IEC 61375-1 and IEC 61375-2-5. The Ethernet Train Backbone (ETB) is to be provided as the software protocol for communication between the locomotive and freight wagons and the freight wagons themselves.An alternative is the Wire Train Bus (WTB).

[0008] The current state of the art presents the problem that the functionalities implemented on freight wagons must meet different operational safety requirements. For this purpose, reliable safety management must be implemented. This includes software updates and digital certificates that regulate access to the software and prevent unauthorized external interference.

[0009] Software updates for passenger trains are generally known and are carried out in xMUs (so-called motor units, also called multiple units), where they can be performed at xMU level. These software updates are only carried out in certain modes, i.e. the xMU (or at least the system to be updated) is brought into a certain state (e.g. maintenance mode) in which the update can be carried out safely. Before the xMU is put back into service, the validity and correct functioning of the newly installed software is checked so that safe operation is possible. The fully updated xMU can then be put back into service.

[0010] However, this technology cannot simply be transferred to updating freight trains. A further problem arises from the fact that, unlike passenger trains, freight wagons are re-combined in rapid succession during operation, for example on sequence systems. This complicates the task of keeping the software of a particular freight train (vehicle combination) up-to-date, as new combinations of freight wagons (i.e. different vehicle combinations) are constantly being created. On the other hand, it can happen that a freight wagon is not in use for an extended period. If such a freight wagon is put back into service, there is a risk that the software available for this freight wagon will be out of date.

[0011] Summary of the invention

[0012] The object of the invention is to eliminate the described problems in the prior art. In particular, it is an object to provide a method for checking computing instances of rail vehicles which is suitable for the operation of freight wagons and can be implemented with high efficiency. Furthermore, it is an object of the invention to provide a locomotive or a freight wagon with which the method can be implemented. Finally, it is an object of the invention to provide a computer program or a computer-readable storage medium which is suitable for carrying out the said method.

[0013] According to a first aspect of the invention, a method is described for checking computing instances of rail vehicles, wherein a) programs installed on the computing instances and / or configurations stored in the computing instances are checked, b) of these rail vehicles, a first rail vehicle, which is a locomotive or a freight car, forms a coupled vehicle combination with at least one second rail vehicle, which is a freight car. To avoid misunderstandings, it should be noted at this point that individual claim features are numbered consecutively with lower case Latin letters, without taking the claim numbering into account. This means that each letter occurs only once in the entire set of claims, which enables the relevant claim features to be addressed unambiguously without mentioning the claim number.Therefore, the order of the letters is not important.

[0014] The first rail vehicle can be a locomotive or a freight car. The first rail vehicle does not have to be at the front of the vehicle convoy. The first rail vehicle is only defined by its property that the checking method according to the invention is carried out by this first rail vehicle. The vehicle convoy is formed by the first rail vehicle and at least one further rail vehicle, namely the second rail vehicle. However, the vehicle convoy can of course also have further rail vehicles, i.e. a third rail vehicle, a fourth rail vehicle and so on, which fulfil the same function as the second rail vehicle within the meaning of the invention.

[0015] According to the invention, the checking of the computing instances in the vehicle assembly is carried out by the first rail vehicle, wherein c) a communication connection is established between the computing instance of the first rail vehicle and the computing instance of at least the second rail vehicle (possibly also of other rail vehicles) via a first interface, d) the computing instance of the first rail vehicle receives data about the software properties of the programs and / or stored configurations on the relevant rail vehicles from at least the computing instance of the second rail vehicle (possibly also from other rail vehicles) via the communication connection, e) a message is generated on the basis of the data received, which message concerns the up-to-dateness of the software properties and / or configurations and the validity of a digital certificate for the operation of the programs.

[0016] The programs to be checked consist of applications that are to be executed on the rail vehicle. The programs can be installed on a computer that is made available to the computing instance of the rail vehicle in question. The configurations to be checked can be hardware configurations or software configurations. Hardware configurations are understood to be specifications that affect the hardware, for example which hardware components the computing instance consists of and / or how the computing instance uses the hardware available to it. Software configurations are understood to be specifications that regulate the operation of the program in question. These are, for example, specifications that define or influence the execution of the program in question.The configurations are preferably stored as configuration data and the programs are preferably stored as program data on a storage unit used by the relevant computing instance.

[0017] One advantage of the invention is that the method for checking the computing instances can be used to determine at any time whether a vehicle convoy consisting of freight wagons, which may also include a locomotive, is ready for operation. This addresses the problem that vehicle convoys consisting of freight wagons are separated and reassembled much more frequently than is the case with passenger cars. There is therefore a high probability that by combining new vehicle convoys, freight wagons will be combined which are equipped with different versions of programs and different certificates for their operation. Due to the inventive generation of a message concerning this information, it is advantageously possible to quickly determine whether the different versions of the programs orConfigurations of these programs and the computing instances used on the freight wagons are compatible with each other and thus the functionalities provided by the computing instances are available for the vehicle convoy in question. If this is not the case, further measures must be carried out before the vehicle convoy in question is used (more on this below). For example, railway staff could specifically update only freight wagons whose operation would otherwise not be possible in the vehicle convoy in question. This saves the railway staff's working time, which is why the method according to the invention contributes to an increase in rail-bound freight transport.

[0018] The generated message concerns the up-to-dateness of the software properties. The software properties are determined, for example, by the version of the program installed on the computing instance. It is possible that the program in a computing instance does not correspond to the current version, but is compatible with the current version and therefore does not interfere with the functionalities that are to be implemented in the vehicle assembly. In this case, updating the program would be optional. However, if certain functionalities of the computing instance in question cannot be implemented within the vehicle assembly, updating the program is a mandatory prerequisite for implementing these functionalities in the computing instance in question. The message also concerns the validity of a digital certificate for operating the programs.Certificates can be used to increase operational safety (safety) when executing programs. They can ensure that a specific program is used only for its intended purpose. A certificate can also improve security against external attacks. The message can therefore be used to determine whether the prerequisite for the safe operation of the vehicle convoy is met or not.

[0019] A device is computer-aided or computer-implemented if it has at least one computer or processor, or a method if at least one computer or processor carries out at least one method step of the method.

[0020] A computing environment is an IT infrastructure consisting of components such as processors, memory units, programs, and data to be processed by the programs, which are used to execute at least one application that has to perform a task. The IT infrastructure can also consist of a network of these components.

[0021] Computing instances (or instances for short) form functional units within a computing environment that can be assigned to applications (given, for example, by a number of program modules) and can execute them. These functional units form self-contained physical (e.g., computer, processor) and / or virtual (e.g., program module) systems when the application is executed.

[0022] Computers are electronic devices with data processing capabilities. Computers can be clients, servers, handheld computers, communications devices, and other electronic data processing devices that may include processors and memory units and may also be connected to a network via interfaces.

[0023] Processors can be, for example, converters, sensors for generating measurement signals, or electronic circuits. A processor can be a central processing unit (CPU), a microprocessor, a microcontroller, or a digital signal processor, possibly combined with a memory unit for storing program instructions and data. A processor can also be a virtualized processor or a soft CPU.

[0024] Storage units can be implemented as computer-readable memory in the form of a working memory (Random-Access Memory, RAM) or data storage (hard disk or data carrier).

[0025] Program modules are individual software functional units that enable a program sequence of method steps according to the invention. These software functional units can be implemented in a single computer program or in several computer programs that communicate with each other. The interfaces implemented in this way can be implemented in software within a single processor or in hardware if multiple processors are used.

[0026] Interfaces can be implemented in hardware, for example wired or as a radio connection, or in software, for example as interaction between individual program modules of one or more computer programs. According to a further aspect of the invention, a locomotive with a computer and a first interface is described. The locomotive and its computer are suitably prepared to carry out the method. According to one variant, the aspects of the invention explained above are determined in that the computer is set up to carry out a method according to one of the preceding claims. When the locomotive is used, the advantages described in connection with the method according to the invention are achieved.

[0027] According to a further aspect of the invention, a freight car with a computer and a first interface is described. The freight car, with its computer, is suitably prepared for carrying out the method. According to a variant, the above-explained aspects of the invention are determined by the fact that the computer is configured to carry out a method according to one of claims 1-11. When the freight car is used, the advantages described in connection with the method according to the invention are achieved.

[0028] According to a further aspect of the invention, a computer program is described, comprising program instructions which, when the program is executed by the locomotive or by the freight car, cause a computer to carry out the method described here.

[0029] According to the invention, a computer program containing program modules with program instructions is described, wherein the method according to the invention and / or its embodiments can be carried out by means of the computer program, and the described advantages are achieved by the implementation. According to a further aspect of the invention, a computer-readable storage medium is described on which the above-described computer program product is stored.

[0030] Furthermore, according to a further aspect of the invention, a provision device for storing and / or providing the computer program in the form of a computer-readable storage medium is described. The provision device is, for example, a storage unit that stores and / or provides the computer program. Alternatively or additionally, the provision device is a network service, a computer system, a server system, in particular a distributed, for example cloud-based, computer system or virtual computer system, which stores the computer program on a computer-readable storage medium and preferably provides it in the form of a data stream.

[0031] The provision takes place in the form of program data sets as a file, in particular as a download file, or as a data stream, in particular as a download data stream, of the computer program.

[0032] The computer program is transferred, for example, into a computing environment using the provision device, so that the method according to the invention can be executed in a computing instance of this computing environment.

[0033] General embodiments of the invention

[0034] Variants describing further developments of the invention are explained below without limiting the basic idea of ​​the invention.

[0035] According to one variant, the aspects of the invention explained above are determined in that f) in addition to the programs installed on the computing instances and / or the configurations stored in the computing instances, at least one computer forming the computing instance is checked, g) the computing instance of the first rail vehicle receives data about the hardware properties of the at least one computer on the relevant rail vehicles from at least the computing instance of the second rail vehicle (if necessary also from other rail vehicles) via the communication connection, h) on the basis of the data received, a message is generated which concerns the up-to-dateness of the hardware properties and the validity of a digital certificate for the operation of the at least one computer.

[0036] Since the computing instances in the locomotive or freight cars must be independent of one another, each freight car or locomotive must have at least one computer that forms the hardware environment for the computing instance. This hardware environment, which can also consist of multiple computers and / or processors and / or sensors, must therefore meet minimum requirements to enable the method according to the invention to be implemented. Hardware components can be defective or even become obsolete due to technological advances.

[0037] If the computer is also tested using the method according to the invention, it is advantageously possible to determine the hardware requirements for carrying out the method according to the invention on the freight car or locomotive in question. Outdated hardware can make it impossible to carry out the method according to the invention. This can be determined, for example, based on the validity of digital certificates for operating the computer. The generated message can be evaluated in this regard and, in case of doubt, provides information as to why the method cannot be carried out on a particular vehicle convoy. The reason can advantageously be determined even if there are problems with the hardware rather than the software.

[0038] According to a variant, the aspects of the invention explained above are determined in that the first interface is formed by a Wire Train Bus or Ethernet Train Backbone.

[0039] These are advantageously the standardized communication interfaces already mentioned above, which advantageously simplifies the possibility of implementing the method according to the invention in existing systems.

[0040] According to a variant, the aspects of the invention explained above are determined in that the first rail vehicle and at least the second rail vehicle are coupled to one another via a digital automatic coupling.

[0041] As already mentioned, digital automatic coupling will, at least in Europe, enable communication between freight wagons and with the locomotive in the foreseeable future. It is particularly advantageous to embed the process in a communications infrastructure provided by the freight wagons and the locomotive.

[0042] According to one variant, the aspects of the invention explained above are determined in that the first rail vehicle i) in the event that the software version is not up to date, carries out an update of the software in the computing instance of at least the second rail vehicle and / or j) in the event that a certificate cannot be verified, carries out an update of the certificate in the computing instance of at least the second rail vehicle. The first rail vehicle must meet the technical requirements for updating the software or the certificate. This requires at least that the first rail vehicle has access to the data and rights required for an update.For this purpose, the necessary data and rights must either be stored in the computing instance used in the first rail vehicle or be able to be requested from it (more on this below).

[0043] The option that the first rail vehicle can update other rail vehicles, such as the second rail vehicle (with regard to both the software version and the certificates), creates the possibility of bringing vehicle convoys whose rail vehicles have inconsistent software versions and certificates to a uniform version and / or certificate status. In particular, rail vehicles whose software version is outdated, particularly due to a lack of compatibility with newer versions, or whose certificates have expired, can be functionally integrated into the vehicle convoy after the update, without operating personnel having to carry out a manual update of the affected freight wagons. This advantageously increases the economic efficiency of rail-based freight transport.It is particularly advantageous if all rail vehicles are brought up to the latest standard. However, this is not absolutely necessary if there is compatibility between different versions (more on this below).

[0044] According to one variant, the aspects of the invention explained above are determined in that the first vehicle has a second interface via which update data for updating the software or updating the certificate can be obtained from a server. In other words, the second interface enables the first vehicle, which is suitable for updating certificates or software, to request current versions of the software or certificates from a central server. This is preferably possible if the first vehicle is a locomotive. The computing instance of the locomotive usually also contains interfaces via which data can be transmitted from outside.

[0045] However, it is also possible to equip freight wagons with additional hardware so that they can form a second interface. In this case, it is not necessary for all freight wagons in a vehicle convoy to be able to use this additional option. It is only necessary that one of the freight wagons in a vehicle convoy can use a second interface. This will advantageously always have the option of having the latest software and the latest certificates available by using the second interface and is therefore always suitable as the first rail vehicle in a vehicle convoy to carry out the method according to the invention.

[0046] This has the advantage that the latest software and the latest certificates for a vehicle convoy can be made available at any time via the second interface. If the first rail vehicle is a freight wagon, there is the additional advantage that a vehicle convoy can also be updated when it is not currently coupled to a locomotive. For example, vehicle convoys that have been put together in a processing system can be brought up to date in the directional track while they wait to be pulled from the directional track by a locomotive. If the locomotive couples the vehicle convoy in the directional track at a later time, it will already be updated and will be immediately ready for use. This saves time, which improves the cost-effectiveness of the method according to the invention.

[0047] According to a variant, the aspects of the invention explained above are determined in that a freight wagon is selected as the first rail vehicle in the vehicle convoy, wherein before the selection it is checked whether the programs installed on the computing instances can be executed and the digital certificates are valid.

[0048] For the first rail vehicle to be able to check the other rail vehicles and update them if necessary, it must have executable software and a valid certificate. Both can then be transferred to other rail vehicles as part of an update if necessary. This does not have to be the latest software or certificates. Older software versions and certificates may still be valid or compatible with newer versions of the software, and thus be executable.

[0049] As already mentioned, the most recent software and the most recent certificate can be made available by using the second interface. If a second interface is not available on the first rail vehicle, for example a freight car, executable older software and / or a still valid certificate can however also be transferred to other rail vehicles if the latter have no longer executable software and / or a no longer valid certificate. Under these circumstances, a vehicle convoy without a locomotive can advantageously be updated even if none of the freight cars is equipped with a second interface. According to one variant, the aspects of the invention explained above are determined by selecting the freight car or cars having the most recent version of the installed programs from among the freight cars in the vehicle convoy.

[0050] In this variant of the invention, it is provided that the rail vehicles of the vehicle convoy can communicate with one another in such a way that it can be determined which of the rail vehicles can be the first rail vehicle to transmit the most recent version of the software to the other rail vehicles. If one of the rail vehicles is equipped with a second interface, this rail vehicle will generally be able to make the current and therefore the most recent software version available. Otherwise, a query among the rail vehicles involved makes it possible to make a version that is locally optimal for the vehicle convoy available to all rail vehicles in the vehicle convoy without using the second interface.

[0051] According to a variant, the aspects of the invention explained above are determined by the fact that the digital certificate contains a permission to use.

[0052] This advantageously facilitates rights management. Furthermore, the digital certificate provides protection against unauthorized and abusive access by third parties.

[0053] According to one variant, the above-explained aspects of the invention are determined by the digital certificate proving the integrity and / or validity of the software. The software can also be provided with a certificate. This ensures that outdated software can no longer be used once the certificate is no longer valid. In this way, compatibility problems between individual software versions of the programs installed on the freight wagons can be advantageously and reliably ruled out.

[0054] According to one variant, the aspects of the invention explained above are determined in that a whitelist of all permissible versions for installed programs and of all permissible certificates is present on the first rail vehicle and / or a blacklist of all impermissible versions for installed programs and of all impermissible certificates is present, on the basis of which a check is made as to whether the program installed on at least the second rail vehicle may be executed in the existing version and / or whether the at least one digital certificate available on at least the second rail vehicle is valid. By comparing it with a whitelist and / or blacklist, it can be determined very reliably and in a very short time whether a specific software or a specific certificate, which is transmitted to the first rail vehicle by the second rail vehicle or further rail vehicles, can be accepted or not.This advantageously improves the reliability as well as the performance of the method according to the invention (more information on the exact procedure for evaluating a whitelist and / or blacklist is provided below).

[0055] Furthermore, according to a further aspect of the invention, a computer program containing program modules with program instructions for carrying out the said method according to the invention and / or its embodiments is described, wherein the method according to the invention and / or its embodiments can be carried out by means of the computer program.

[0056] Furthermore, according to a further aspect of the invention, a provision device for storing and / or providing the computer program in the form of a computer-readable storage medium is described. The provision device is, for example, a storage unit that stores and / or provides the computer program. Alternatively and / or additionally, the provision device is, for example, a network service, a computer system, a server system, in particular a distributed, for example cloud-based computer system and / or virtual computer system, which stores and / or provides the computer program preferably in the form of a data stream.

[0057] The provision takes place in the form of a program data set as a file, in particular as a download file, or as a data stream, in particular as a download data stream, of the computer program. This provision can also take place, for example, as a partial download consisting of several parts. Such a computer program is transferred, for example, using the provision device into a computing environment, so that the method according to the invention can be executed in a computing instance.

[0058] Exemplary examples of the drawing

[0059] Further details of the invention are described below with reference to the drawings. Identical or corresponding elements in the individual figures are provided with the same reference symbols and are explained several times only to the extent that differences arise between the individual figures.

[0060] The exemplary embodiments explained below are preferred embodiments of the invention. In the exemplary embodiments, the described components of the embodiments each represent individual variants of the invention that can be considered independently of one another. Each of these variants also develops the invention independently of one another and is therefore to be considered a component of the invention, either individually or in a combination other than that shown. Furthermore, the described components can also be combined with the variants of the invention described above.

[0061] Regardless of the grammatical gender of the terms concerned, persons with male, female or other gender identities are equally included.

[0062] Figure 1 shows an embodiment of the devices according to the invention, namely rail vehicles designed as locomotives or freight cars, with their functional relationships schematically.

[0063] Figure 2 shows an exemplary embodiment of a computing environment for the devices according to Figure 1 as a block diagram, wherein the individual computing instances execute program modules which can each run in one or more of the computers shown as examples and wherein the interfaces shown can accordingly be implemented in software in one computer or in hardware between different computers.

[0064] Figure 3 shows an embodiment of the method according to the invention as a flow chart, wherein the method steps shown can be implemented individually or in groups by program modules and wherein the computing instances and interfaces according to Figure 2 are indicated by way of example.

[0065] Detailed description of the drawing

[0066] In a computing environment, the computing instances RI used according to Figure 1 and Figure 2 and their and other functional components, namely a first functional component F1, a second functional component F2 and a third functional component F3 are connected by a first interface S1, by a second interface S2, by a third interface S3, by a fourth interface S4 and by a fifth interface S5. The first functional component, the second functional component and the third functional component are only indicated by way of example. These can each be one or more functional units which can be formed, for example, by computers, processors or sensors. The functional components contribute to the functions to be implemented in the freight cars or locomotives, which functions are known in themselves and will not be explained further here.In the context of this invention, computers, processors, sensors and other functional units are also referred to as end devices or ED for short.

[0067] According to Figure 2, in particular in the computing environment, in a first computer CI, a first processor PI is connected to a first memory unit SE1 by an eleventh interface S11, in a second computer C2, a second processor P2 is connected to a second memory unit SE2 by a twelfth interface S12, in a third computer C3, a third processor P3 is connected to a third processor P3 and to a third memory unit SE3 by a thirteenth interface S13, in a fourth computer C4, a fourth processor P4 is connected to a fourth memory unit SE4 by a fourteenth interface S14, wherein the above-mentioned first to fourth computers C4 are referred to jointly as computers, the above-mentioned first to fourth processors P4 are referred to jointly as processors, and the above-mentioned first to fourth memory units SE4 are referred to jointly as memory units.The respective computers can accomplish the tasks of the method according to the invention. The respective storage units are also intended, among other things, to store programs in the form of program data and certificates in the form of certificate data so that they can be called up by the computers when needed.

[0068] Figures 1 and 2 also show that a connection can be established between the locomotive LV and a data center RZ via the second interface S2, which is a radio interface. The locomotive LV according to Figure 1 is coupled to three freight wagons GW and together form a vehicle convoy FV. The individual freight wagons GW and the locomotive LV are each coupled to one another via a digital automatic coupling DAK. The vehicle convoy FV, which according to Figure 1 is a freight train, is shown standing on a track GL.

[0069] Just like the locomotive LV, the freight cars GW, which are shown in Figure 1, can also operate the second interface S2 in a manner not shown. For this purpose, the locomotive LV and the freight cars GW, as well as a data center RZ housing a server SV, are equipped with antennas AT. Not shown, but equally possible, is that not all of the freight cars GW have an antenna AT, whereby only freight cars GW that have an antenna AT can download current software or current certificates from the data center RZ via the second interface S2. Freight cars GW with an antenna AT can also advantageously be used as the first rail vehicle FZ1. The function of the first rail vehicle FZ1, the second rail vehicle FZ2 and the third rail vehicle is shown in Figure 2.The first rail vehicle can be, as shown in Figure 1, a locomotive LV, or alternatively a freight wagon GW. In the latter case, the vehicle convoy FV is formed, in particular, by a convoy of freight wagons GW that are not connected to a locomotive LV, such as can be formed, for example, after running off on a directional track of a run-off facility (not shown in detail).

[0070] As can be seen from Figure 1, the first interface S1 is a bus system, which can be implemented, in particular, by an Ethernet Train Backbone (ETB) or a Wire Train Bus (WTB). The Ethernet Train Backbone (ETB) is routed via the digital automatic couplings (DAK).

[0071] As can be seen from Figure 2, each of the rail vehicles (irrespective of whether these vehicles are a locomotive LV or a freight car GW) forms its own computing instance RI. These computing instances RI also each contain a node of the communication network formed by the first interface S 1, so that communication can be regulated via the first interface S 1. The first rail vehicle FZ 1 forms a control node or controlling node (not shown in more detail), which takes on a controlling or, in other words, leading function with regard to checking the computing instances RI of the other rail vehicles and, if necessary, a subsequent software update or update of the certificates.The nodes and also the control node of the first rail vehicle FZ 1 are connected via so-called Ethernet Train Backbone Nodes ETBN to the first interface S 1, implemented as an Ethernet Train Backbone ETB. In the following, a software update and management mechanism (hereinafter referred to as SW) for the freight wagons GW and, if necessary, also for the locomotives LV is described in detail. This consists of the following main steps, some of which are optional—i.e., they can be performed by other means without affecting the remaining steps of the invention:

[0072] Step 1 (IGI for short): In a vehicle convoy FV with or without a locomotive LV (hereinafter referred to as train for short), a control node is set up as part of the computing instance RI, preferably on a locomotive LV. The computing instances RI of the rail vehicles each form an Ethernet Consist Network (hereinafter referred to as ECN) per rail vehicle. Each ECN is connected via an Ethernet Train Backbone Node ETBN (hereinafter referred to as ETBN) to an Ethernet Train Backbone ETB, which forms the first interface S 1. In the case of multiple traction, in which more than one locomotive LV is connected to the Ethernet Train Backbone ETB (hereinafter referred to as ETB), a locomotive LV is selected to host the control node. Preferably, this should be the one with the occupied driver's cab, but other selection mechanisms are also possible (such as, but not limited to, the leading train formation or the highest / lowest UIC number).

[0073] Step 2 (INF for short): Transmission of the SW version of the ETBN and (optionally) of the end devices (ED) that can be reached and updated via this ETBN, such as computers, processors or sensors (which together form the computing instance RI of the vehicle in question), via the ETB. Optionally, software and hardware information such as identifiers, including revision, version and status information as well as digital certificates are also transmitted. This information is then used by the control node to determine whether the train, which is represented by all the connected ETBNs, is in a safe operating condition. This requires an extension of the series of standards IEC 61375, in particular -1 (General Architecture), -2-5 (ETB) and -2-8 (TCN Conformity Tests).

[0074] Step 3 (called VAL for short): In addition to transmitting the identification information (version, secure hashes, signatures), the system provides a mechanism that enables the control node to cryptographically validate the software version using digital certificates, so that it can detect unauthorized software on an ETBN (and / or ED). This is the mechanism that ensures that, based on the received data, a message is generated concerning the up-to-dateness of the software properties and / or configurations as well as the validity of a digital certificate for the operation of the programs of the other computing instances RI and, optionally, based on the received data, a message is generated concerning the up-to-dateness of the hardware properties and the validity of a digital certificate for the operation of the computer, optionally also of processors and / or sensors of the other computing instances RI.This is preferably done in steps 4 and 5 described below.

[0075] Step 4 (LST for short): The SV server maintains an up-to-date list of software versions and certificates (more on this in Step 5). This list is transferred to the control node as needed.

[0076] Step 5 (CHK for short): The control node updates the list of software versions (including all information required to validate the cryptographic version information, e.g. digital certificates) to determine whether the software versions used across the train are valid. This list can be a. whitelist, where software on this whitelist is safe to operate and no further action is required (although an update to a newer version can still be carried out, see below), or b. blacklist, where the software on the blacklist is considered outdated, incompatible and / or unsafe to operate and remedial action must be taken (e.g.

[0077] B. Updating the software and / or notifying the personnel responsible for train integrity testing / validation, as explained above). With a pure blacklist approach, any software not on this blacklist is considered safe to operate and treated as described above for the whitelist.

[0078] In addition, it may be a combination of blacklist and whitelist, where a software version detected but not listed in either list triggers notification of the staff responsible for checking train integrity and requires explicit confirmation of the operational safety of the train composition. SW versions that are either whitelisted or blacklisted are treated as described above, with the exception of automatic whitelisting when using the pure blacklist approach.

[0079] Step 6.1 and 6.2 (shortly called UPD_ETBN and UPD_ED): These steps form the basis for the software to be updated in the computing instance RI of at least the second and further rail vehicles in the event that the software version is not up to date and / or for the certificate to be updated in the computing instance RI of at least the second and further rail vehicles in the event that a certificate cannot be verified.

[0080] For this purpose, a software update mechanism is introduced, in particular by means of the ETB via the so-called e-coupler contacts of the Digital Automatic Coupling DAK. a. This is optional for the entire invention, so it can, for example, also be carried out wirelessly or via the aforementioned Wireless Train Bus WTB. i. If not implemented, no software distribution via the coupler is possible. Software updates must then be carried out by the wagon, e.g. via a wireless connection on each wagon or via a local service connection SV. ii. If it is implemented as a proprietary solution (and therefore incompatible between manufacturers), only certain wagons can be updated in this way by a specific locomotive LV, which can be ensured, for example, by digital certificates. iii. When extending the IEC 61375 series, in particular -1 (General Architecture), -2-5 (ETB) and -2-8 (TCN-

[0081] Conformity tests), it can be provided that software updates of the ETBN and the connected EDs (terminals) are enabled in a standardized manner. Manufacturer-specific certificates would not be required under these conditions. b. If option (see below) is not selected, a two-stage approach is pursued, in which the ETBN itself is updated first, followed by the EDs.

[0082] Step 6.1: The ETBN is updated first. As mentioned, the first interface S1 can be used for this. - The ETBN receives a software update request from a control node in the leadership group.

[0083] - The ETBN authenticates the control node

[0084] - The ETBN retrieves the new SW package from the controlling node (or the controlling node pushes the SW); once the SW is received, the ETBN installs the SW autonomously, if it is safe to do so (or it waits for the controlling node's instruction to install the SW).

[0085] Optionally, the ETBN can perform additional compatibility checks for a successful update (comparison with the current software and hardware revision).

[0086] - Once the update is completed, the ETBN reports the new SW version to the controlling node.

[0087] Step 6 . 2 : The updated ETBN updates the connected EDs

[0088] - The ETBN reports the EDs accessible via this ETBN (which are capable of a software update by informing the ETBN of this capability) to the controlling node in the leadership group. The current software and hardware versions, as well as status information, are reported for each ED.

[0089] - The controlling node checks whether the ED needs a SW update (see above: general rules for updating).

[0090] - The control node, also called controlling node, passes the SW update package for the ED to the ETBN and instructs the ETBN to perform the update (provided the system is in a state that allows such an update). Alternatively, the ETBN can act only as a gateway and the control node performs the update directly on the ED (with the ETBN as GW between ETB and ECN).

[0091] - The ETBN only initiates an update of an ED if it receives the instruction to do so and is itself in a state where doing so is safe. - The ED checks whether a software update is safe in the current state before initiating the software update.

[0092] - The ED performs the update and reports the then running version to the controlling node via the ETBN.

[0093] Option: A variant is also possible in which the SW for the ETBN and all connected EDs is contained in a single package (not shown in Figure 3). c. General rules for the update strategy: Since the update must be automated, the following rules apply

[0094] - If a SW with a newer version is available for a specific ETBN / ED on or for the controlling node, an update is performed (if the system is in good condition)

[0095] - If the current SW version of an ETBN / ED on the controlling node is blacklisted and another ( valid , non - blacklisted ) SW is available on or for the controlling node , an update will be performed even if this downgrades the SW of the ETBN / ED .

[0096] - If the current SW version of an ETBN on the controlling node is on a blacklist and no other (valid, non-blacklisted) SW is available on or for the controlling node, the ETBN is set to "defective" mode and not used.

[0097] - If the current SW version of an ED is on the blacklist of the controlling node and no other (valid, non-blacklisted) SW is available on or for the controlling node, the ETBN controlling this ED is informed to put the ED into "defective" mode.

[0098] - If ETBNs or EDs cannot be updated for any reason, the controlling node must inform the driver / train controller / wagon manager / railway company so that the situation can be remedied. d. Furthermore, a local SW update must be possible at any time when the train is in a safe state.

[0099] - To support the update mechanism, the control node provides access to one or more trackside repositories from which the latest software can be retrieved for each ETBN / ED node that needs to be updated. In addition, the controlling node can provide local storage for some or all of these software packages to avoid having to retrieve them multiple times over a wireless / mobile network. Optionally, additional information is provided with each image on how often it is used, so that when the storage capacity in the control node is exhausted, a decision can be made as to which image to discard.

[0100] Reference symbol list

[0101] RI computing instances

[0102] Fl first functional component

[0103] F2 second functional component

[0104] F3 third functional component

[0105] 51 first interface

[0106] 52 second interface

[0107] 53 third interface

[0108] 54 fourth interface

[0109] 55 fifth interface

[0110] CI first computer

[0111] PI first processor

[0112] SEI first storage unit

[0113] 511 an eleventh interface

[0114] C2 second computer

[0115] P2 second processor

[0116] SE2 of a second storage unit

[0117] 512 a twelfth interface

[0118] C3 third computer

[0119] P3 third processor

[0120] SE3 third storage unit

[0121] 513 a 13th interface

[0122] C4 fourth computer

[0123] P4 fourth processor

[0124] SE4 fourth storage unit

[0125] 514 14 . Interface

[0126] LV locomotive

[0127] RZ data center

[0128] GW freight wagons

[0129] FV Vehicle Association

[0130] DAK digital automatic coupling

[0131] GL track

[0132] SV Server

[0133] AT antenna

[0134] FZ 1 first rail vehicle FZ2 second rail vehicle

[0135] ETB Ethernet Train Backbone

[0136] WTB Wire Train Bus

[0137] ETBN Ethernet Train Backbone Nodes

Claims

Patent claims 1. A method for checking computing instances (RI) of rail vehicles, wherein a) programs installed on the computing instances (RI) and / or configurations stored in the computing instances (RI) are checked, b) of these rail vehicles, a first rail vehicle (FZ1), which is a locomotive (LV) or a freight wagon (GW), forms a coupled vehicle assembly (FV) with at least one second rail vehicle (FZ2), which is a freight wagon (GW), characterized in that the checking of the computing instances (RI) in the vehicle assembly (FV) is carried out by the first rail vehicle (FZ1), wherein c) a communication connection is established between the computing instance (RI) of the first rail vehicle (FZ1) and the computing instance (RI) of at least the second rail vehicle (FZ2) via a first interface (S1),d) the computing instance (RI) of the first rail vehicle (FZ1) receives data about the software properties of the programs and / or stored configurations existing on the rail vehicles in question via the communication connection from at least the computing instance (RI) of the second rail vehicle (FZ2), e) a message is generated on the basis of the data received, which indicates that the software properties and / or configurations as well as the validity of a digital certificate for the operation of the programs.

2. Method for checking according to claim 1, characterized in that f) in addition to the programs installed on the computing instances (RI) and / or to the configurations stored in the computing instances (RI), at least one computer forming the computing instance (RI) is checked, g) the computing instance (RI) of the first rail vehicle (FZ1) receives data about the hardware properties of the at least one computer on the relevant rail vehicles from at least the computing instance (RI) of the second rail vehicle (FZ2) via the communication connection, h) on the basis of the data received, a message is generated which relates to the up-to-dateness of the hardware properties and the validity of a digital certificate for the operation of the at least one computer.

3. Method for checking according to claim 1 or 2, characterized in that the first interface (S1) is formed by a Wire Train Bus (WTB) or Ethernet Train Backbone (ETB).

4. Method for checking according to one of the preceding claims, characterized in that the first rail vehicle (FZ1) and at least the second Rail vehicle (FZ2) are coupled together via a digital automatic coupling (DAK).

5. Procedure for checking according to any of the preceding Claims, characterized in that the first Rail vehicle (FZ1) i) in the event that the software version is not up to date, carries out an update of the software in the computing instance (RI) of at least the second rail vehicle (FZ2) and / or j) in the event that a certificate cannot be verified, carries out an update of the certificate in the computing instance (RI) of at least the second rail vehicle (FZ2).

6. A method for checking according to one of the preceding claims, characterized in that the first vehicle has a second interface (S2) via which update data for updating the software or updating the certificate can be obtained from a server (SV).

7. Method for checking according to one of the preceding claims, characterized in that a freight wagon (GW) is selected as the first rail vehicle (FZ1) in the vehicle convoy (FV), wherein before the selection it is checked whether the programs installed on the computing instances (RI) can be executed and the digital certificates are valid.

8. Method for checking according to claim 7, characterized in that among the freight wagons (GW) of the vehicle convoy (FV) the one or one of those freight wagons (GW) is selected which has the latest version of the installed programs.

9. A verification method according to any one of the preceding claims, characterized in that the digital certificate contains a usage authorization.

10. A method for checking according to one of the preceding claims, characterized in that the digital certificate proves the integrity and / or validity of the software.

11. Method for checking according to one of the preceding claims, characterized in that a whitelist of all permissible versions for installed programs and all permissible certificates is present on the first rail vehicle (FZ1) and / or a blacklist of all non-permissible versions for installed programs and all non-permissible certificates is present, based on which it is checked whether the program installed on at least the second rail vehicle (FZ2) may be executed in the existing version and / or the at least one program installed on at least the second rail vehicle (FZ2) available digital certificate is valid.

12. Locomotive with a computer and a first interface (S1), characterized in that the computer is configured to carry out a method according to one of the preceding claims.

13. Freight wagon with a computer and a first interface (S1), characterized in that the computer is configured to carry out a method according to one of claims 1-11.

14. Computer program, comprising program instructions which, when the program is executed by the locomotive (LV) according to Claim 12 or by the freight wagon (GW) according to claim 13, cause a computer to carry out the method according to one of claims 1 - 11.

15. Computer-readable storage medium on which the Computer program product according to the last preceding claim.