Railway interlocking

The onboard train interlocking system simplifies and decentralizes railway interlocking by using vehicle readers to manage track reservations and issue movement authorities, addressing the challenges of traditional centralized systems with complex, custom-designed processors.

GB2635352APending Publication Date: 2025-05-14UNIVERSAL SIGNALLING LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
GB2023017138
Authority / Receiving Office
GB · GB
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-08
Publication Date
2025-05-14

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A train interlocking system 20 located onboard a rail vehicle 40 comprises vehicle readers 24a,b having respective fixed positions at a front and rear of the rail vehicle. As the first reader passes a
Need to check novelty before this filing date? Find Prior Art

Description

Field The present invention relates to railway signalling and train control, and relates particularly, but not exclusively, to the portion of a railway signalling system that ensures safety. This portion of a railway signalling system is commonly referred to as interlocking. The present invention thus primarily relates to methods and systems for railway interlocking. Background Signalling is the part of a railway system which performs some or all of the following functions: • Grants rail vehicles permission to move. • Prevents rail vehicles coming into contact (i.e. colliding), unless desired (i.e. coupling up). • Routes vehicles to their destinations. • Provides information to the driver (operator of an individual vehicle) and signaller (operator of the railway) regarding the state of the system. • Prevents vehicles from travelling at a speed greater than the infrastructure or infrastructure / vehicle combination allows. Signalling is not fitted to every railway infrastructure in the world, but it is fitted to nearly every passenger railway in some guise, as it is the subsystem which assures the safety of operations, and therefore the safety of life. The oldest signalling systems are typically mechanical systems. In such systems a signaller uses levers connected to cables and rods to move points and signals, and vehicle drivers observe the mechanical lineside signal positions and drive accordingly. Such mechanical systems are largely considered to be obsolete, and are gradually being replaced by electrical and / or digital signalling systems. In an electrical signalling system, a signaller pushes buttons on a panel orclicks on icons on a computer workstation. Points and level crossings then move electromechanically, and coloured lights turn on and off at the trackside based upon the signaller’s decisions and / or detected train positions. Drivers observe the lineside coloured lights and drive accordingly. A digital signalling system is similar in that points and level crossings move electro-mechanically. However, such a system differs in that the signaller clicks on icons on a computer workstation, or a computer automates common actions. Rather than needing to observe trackside signals, permission to move is transmitted directly to the cab of a train for the driver to interpret. This potentially allows the possibility to shortcut the driver and allow Automatic Train Operation (ATO) - i.e. the train drives itself. All of these signalling systems include some form of interlocking, which is a safety measure designed to prevent signals and points / switches from being changed in an improper sequence. For example, the interlocking may operate to prevent a signal from being changed to indicate a train may proceed through a crossing, unless any appropriate barriers have been lowered and any necessary points have been changed first. As another example, the interlocking may prevent a signal from being changed to permit a train to proceed onto a section of track which is in use by another train until that other train has moved on. The form of interlocking may vary between systems. For instance, in a mechanical system the interlocking may include one or more mechanical switch arrangements which physically prevent movement of a conflicting switch once a switch has been activated, or which can only be activated in a predefined sequence. In an electromechanical system, such mechanical switches may be replaced by hardwired logic circuits and relays, whilst in a digital system software logic may take the place of physical restrictions on the switching equipment. In all cases however, the interlocking acts as a restriction on the routing of vehicles on the railway, in that it will not permit certain movements that are considered unsafe. The output of an interlocking is a Movement Authority (MA). An MA is a permission for a vehicle driver to move their vehicle a given distance. In mechanical systems, MAs are transmitted to drivers via semaphore signals; in electrical systems they are transmitted by coloured lights; and in digital systems they are transmitted by a message wirelessly communicated to the train and displayed on an in-cab console. Summary In a traditional digital interlocking, one big monolithic lineside processor takes in information about the state of the railway it protects. It then presents that information to a signaller in a lineside control room. The signaller makes decisions based upon the presented information and commands the interlocking to perform actions. The software logic comprising the interlocking will only perform these actions if it is safe to do so - i.e. the signaller is prevented from making basic human errors to which all humans are prone from time to time. If the signaller’s commands are accepted, an MA is issued to the driver, who may then move their train (or continue moving) in accordance with the MA. This architecture is effective from a safety point of view, but can pose implementation challenges. Railway infrastructure is typically highly varied between different locations, meaning there is limited scope to standardise design. This means that in practice each signalling system must be custom designed, built, tested and assured according to local geography. This custom design means that signalling projects, and in particular re-signalling projects, take a very long time from inception to deployment. Long projects, with a lot of complexity and many engineers working on custom safety-critical designs, are expensive. Furthermore, if the protection rules for a geographical area are hard-wired or programmed into the safety logic, changes to that area can quickly become very complex, time-consuming and expensive, through having to redesign, redeploy, reassure and retest that area. In addition, interfaces (known as ‘fringes’ in the signalling world), where trains must be handed over from one signalling system to a neighbouring signalling system managing the next part of the infrastructure, can pose problems, as compatibility between the differing neighbouring systems needs to be considered. The present invention aims to address at least some of the above problems. According to a first aspect of the invention we provide a method of operating a train interlocking system located on board a rail vehicle, the method comprising: obtaining, by a first vehicle reader having a first vehicle position at a front of the rail vehicle that is fixed with reference to the rail vehicle, first information associated with a first track location that is fixed with reference to the track as the first vehicle reader passes the first track location; sending second information to a lineside server, the second information comprising an indication that the first track location is occupied by the rail vehicle; obtaining, by a second vehicle reader having a second vehicle position at a rear of the rail vehicle that is fixed with reference to the rail vehicle, third information associated with the first track location as the second vehicle reader passes the first track location; and sending fourth information to the lineside server, the fourth information comprising an indication that the first track location is unoccupied by the rail vehicle. As discussed above, traditional interlocking systems include a centralised processor which is used by a signaller to issue movement authorities (MAs) to the drivers of all trains in the area protected by the interlocking system. In contrast, the method described above differs from in that it is implemented onboard a vehicle, such as a train, and is operable to protect that vehicle alone. Such a system may be significantly simpler than a conventional system, as it transfers decision making responsibility to an entity which requires far fewer inputs. A centralised processor of the type used in prior art interlocking systems requires information concerning the state of an entire geographic area to correctly issue MAs, and so potentially can have trillions of possible states. It is complex, time-consuming, expensive and inflexible to have such an architecture as safety protection. In contrast, an onboard interlocking system, referred to herein as a train interlocking system, only needs to know the state of the track immediately ahead of the vehicle in order to issue an MA - all other information can be considered irrelevant and ignored. To this end, the train interlocking system makes use of two separate vehicle readers located on the rail vehicle, which are each operable to determine a fixed location with reference to the track (e.g. the first track location) at an instantaneous time. The fixed location may be defined in terms of a physical geolocation and elevation. The information obtained by each of the vehicle readers is used indicate to other actors within the railway system that have access to the lineside server (such as other train interlocking systems or human actors such as a signaller or a maintenance engineer) that a specified portion of track (e.g. the first track location) is occupied by the rail vehicle as the rail vehicle passes over that portion of track. The first vehicle reader is located towards the forward end of the rail vehicle, for example at or adjacent a front of the vehicle, whilst the second vehicle reader is located towards the rear end of the rail vehicle, for example at or adjacent a rear of the vehicle. In this way, the train interlocking system may operate to identify a portion of track as being occupied as the front of the rail vehicle passes the first track location, and to immediately release that portion of the track for occupation by other actors within the system after the rear of the rail vehicle has passed the first track location. The first track location may be obtained by the first and second vehicle readers from a satellite positioning system, such as GPS. Alternatively, the first track location may be associated with a first trackside beacon, and the first track location may be obtained by the first and second vehicle readers from the first trackside beacon. Thus, the first vehicle reader may be termed a first beacon reader, and the second vehicle reader may alternatively be termed a second beacon reader. The first trackside beacon may, for example, be a passive RFID transceiver, and the first and second beacon readers may each comprise an RFID transceiver operable to read data stored on the first trackside beacon. Obtaining the first track location from a physical beacon mounted on or adjacent the track may be more accurate that utilising a satellite positioning system. The first trackside beacon may have stored thereon a first beacon identifier, and the step of obtaining the first information may comprises reading, by the first vehicle reader, the first beacon identifier from the first trackside beacon. The step of obtaining the third information may also comprise reading, by the second vehicle reader, the first beacon identifier from the first trackside beacon. The method may comprise, prior to sending the second information, sending a first request to the lineside server, the first request comprising a request for reservation of the first track location and / or the first trackside beacon. By reserving the first track location (e.g. as represented by the first trackside beacon) before physically occupying the first track location, safety may be improved. In particular, the reservation of the first track location / first trackside beacon by the train interlocking system may serve as a notification to other actors within the railway system of the intent of the train interlocking system to occupy the first track location. Preferably, the train interlocking system may not be permitted to occupy the first track location if the first track location / first trackside beacon has not previously been reserved. The train interlocking system may be located on board a rail vehicle having a known speed, and the method may further comprise calculating, using the known speed, a required length of track ahead of the rail vehicle. The first track location may be selected based on the required length of track. In this context, the “required length of track” may refer to a length that is sufficient to permit the rail vehicle to brake from its known speed to come safely to a stop. The first location may be a selected distance forward of the rail vehicle, which may be equal to the required length of track. In this way safety may be improved, by ensuring that a safe stopping distance ahead of the rail vehicle is reserved for sole occupation by the rail vehicle. The train interlocking system may be located on board a rail vehicle having a known speed, and the method may further comprise calculating, using the known speed, a required number of trackside beacons. The “required number” may, in this context, refer to a number of trackside beacons necessary to ensure that the portion of track protected by those trackside beacons has a length that is sufficient to permit the rail vehicle to brake from its known speed to come to a stop. Thus, for any given speed, the required number of trackside beacons may vary in dependence on the beacon spacing along the track, as well as on the weather conditions, the track conditions, and the expected braking distance of the vehicle on which the train interlocking system is located. The first request may comprise a request for reservation of the first trackside beacon and a number of further trackside beacons forward of the first trackside beacon, the number being selected to ensure that, in total, reservation of the required number of trackside beacons is requested at the lineside server. By reserving the required number of trackside beacons before the first trackside beacon is occupied by the train, safety may be further improved. In particular, the reservation of the required number of trackside beacons by the train interlocking system may serve as a notification to other actors within the railway system of the length of track necessary to permit the vehicle on which the train interlocking system is located to come to a stop in an emergency situation. The method may further comprise, in response to the first request, receiving, from the lineside server, fifth information, the fifth information comprising an indication that the first track location is reserved by the train interlocking system. For example, the method may further comprise, in response to the first request, receiving, from the lineside server, fifth information, the fifth information comprising an indication that the first trackside beacon and the number of further trackside beacon(s) are reserved by the train interlocking system. In response to receipt of the fifth information, the method may comprise generating a movement authority for the train. The movement authority may comprise a permission for the vehicle on which the train interlocking system is located to occupy the reserved beacons. In this way, the train interlocking system may not issue a movement authority for the rail vehicle until it receives confirmation that its request has been accepted, and that the requested length of track is reserved for its exclusive occupation. Since the driver of a vehicle cannot move the vehicle without a movement authority, this further improves safety by ensuring that the vehicle on which the train interlocking system is located is not permitted to move to occupy the first trackside beacon unless the train interlocking system has received confirmation that the track ahead of the vehicle is clear of other actors for at least a safe braking distance. The method may further comprise sending a second request to the lineside server, the second request comprising a request for reservation of at least one further track location (for example, as represented by at least one further trackside beacon), the at least one further track location being forward of any track locations already reserved by the train interlocking system or occupied by the rail vehicle. The train interlocking system may periodically request reservation of track locations / trackside beacons ahead of the rail vehicle, whilst at the same time releasing the track locations I trackside beacons which have been passed by the rear of the vehicle for reservation by other actors (by sending the fourth information). The method may further comprise, in response to the second request, receiving, from the lineside server, sixth information, the sixth information comprising an indication that one or more of the at least one further track locations / trackside beacons is not reserved for the train interlocking system; and, denying a movement authority for the rail vehicle. The one or more of the least one further track locations I trackside beacons may not be reserved for the train interlocking system because that location / beacon is not available for reservation, for example because it is reserved or occupied by another actor. By denying a movement authority for the rail vehicle in situations where a request to reserve a track location / trackside beacon is not accepted by the lineside server, a driver is prevented from moving the rail vehicle to an unsafe location, such as a location where another actor is present on the track immediately ahead. The first request may include an encryption key associated with the train interlocking system, and may also include other information such as an actor identifier associated with the train interlocking system. The encryption key may be unique to the train interlocking system, and may be used at the lineside server to encrypt a data record associated with the first track location / first trackside beacon, so as to prevent that record from being modified (e.g. marked as reserved or occupied by other actors) until it is subsequently decrypted. The first request may additionally include information identifying the first trackside beacon, such as the first beacon identifier. Subsequent requests for reservation of track locations / trackside beacons, such as the second request, may similarly include the encryption key together with, optionally, the beacon identifier(s) of the trackside beacons which are the subject of the reservation request and / or other information such as the actor identifier associated with the train interlocking system. The fourth information may include a decryption key associated with the train interlocking system, and may also include other information such as the actor identifier associated with the train interlocking system. The decryption key may be unique to the train interlocking system, and may be used at the lineside server to decrypt the data record associated with the first track location I first trackside beacon, so as to permit that record to be modified (e.g. marked as reserved or occupied by other actors). The second information may additionally include information identifying the first trackside beacon, such as the first beacon identifier. Subsequent information sent by the train interlocking system comprising an indication that a track location / trackside beacon is no longer required (e.g. is unoccupied) by the rail vehicle may similarly include the decryption key and, optionally, other information such as the actor identifier associated with the train interlocking system and / or the beacon identifier(s) of the trackside beacons which are no longer required. The train interlocking system may be associated with a rail vehicle having an expected length, and the method may further comprise using a time between obtaining the first information (e.g. by reading the first beacon identifier by the first train beacon reader) and obtaining the third information (e.g. by reading the first beacon identifier by the second train beacon reader) to calculate a length of the rail vehicle. The method may further comprise comparing the calculated length with the expected length. In this way the train interlocking system is able to determine an integrity of the rail vehicle. In particular, if the calculated length does not match the expected length, this may indicate that there has been damage to the rail vehicle. In such a situation the train interlocking system may be operable to issue an alert to the driver and / or to a remote location, such as a signalling system. The method of the first aspect of the invention may be implemented in a train interlocking system according to a second aspect of the invention. The train interlocking system may comprise: a driver system having a processor storing interlocking software, and a first transceiver operable to communicate with a lineside server of a track interlocking system; a first vehicle reader having a first vehicle position at a front of the rail vehicle that is fixed with reference to the rail vehicle; and a second vehicle reader having a second vehicle position at a rear of the rail vehicle that is fixed with reference to the rail vehicle. The first vehicle reader may comprise a first train beacon reader comprising a first RFID transceiver, and may further comprise a second transceiver operable to communicate with the lineside server. The second vehicle reader may comprise a second train beacon reader comprising a second RFID transceiver, and may further comprise a third transceiver operable to communicate with the lineside server. The train interlocking system may be located on a rail vehicle, such as a train, and may be operable to issue movement authorities for the rail vehicle in accordance with the method described above in connection with the first aspect of the invention. The driver system may be located in a cab of the rail vehicle, the first train beacon reader may be located at or adjacent a front of the rail vehicle, and the second train beacon reader may be located at or adjacent a rear of the rail vehicle. Each of the first and second RFID transceivers may be operable to read data stored on one or more trackside beacons. The train interlocking system of the second aspect of the invention may be operable to carry out any of the method steps discussed above in connection with the first aspect of the invention, and may optionally comprise any of the features discussed below in the detailed description. The method of the first aspect of the invention may be operated in tandem with a method of operating a trackside interlocking system according to a third aspect of the invention, wherein the method of operating a trackside interlocking system comprises, at a lineside server: receiving second information from a train interlocking system located on board a rail vehicle, the second information comprising an indication that a first track location is occupied by the rail vehicle associated with the train interlocking system; changing a state of a first process running on the lineside server to indicate that the first track location is occupied, the first process being uniquely associated with the first track location; receiving fourth information from the train interlocking system, the fourth information comprising an indication that the first track location is unoccupied by the rail vehicle; and changing the state of the first process running on the lineside server to indicate that the first track location is unreserved. As discussed above, in contrast to conventional interlocking systems, in the methods and systems described herein, the part of the interlocking which makes decisions about whether or not it is safe for a rail vehicle to move is located onboard the vehicle itself - this is the train interlocking system described above in connection with the first and second aspects of the invention. The train interlocking system makes decisions based upon information that is held in a complementary trackside interlocking system. The trackside interlocking system does not itself make decisions, but instead responds in a predefined manner to requests and / or information received from actors within the railway system, such as the train interlocking system described above. The trackside interlocking system may thus be considered a lineside store of information, which is accessible by actors within the railway system, but which cannot itself issue movement authorities. An advantage of such an arrangement is that the trackside interlocking system may be implemented using simple binary logic, rather than requiring complex combinatorial logic, as in more traditional systems. Each track location, as defined, for example, by a trackside beacon, within the railway system may be represented in the lineside server by a simple, replicable software unit (referred to herein as a “process”), which has a limited number of states. The state of the process may be altered in accordance with predefined rules in response to requests and / or information received from actors within the railway system. The processes thus function as switches operable to indicate whether a piece of track, for example as identified by a trackside beacon, is clear, or is occupied or reserved by an actors, such as the train interlocking system. The method may further comprise, prior to receiving the first information: receiving a first request from the train interlocking system, the first request comprising a request for reservation of the first track location / first trackside beacon; changing the state of the first process running on the lineside server to indicate that the first track location I first trackside beacon is reserved by the train interlocking system; and sending, to the train interlocking system, fifth information, the fifth information comprising an indication that the first track location I first trackside beacon is reserved by the train interlocking system. The first request may comprise a request for reservation of the first trackside beacon and a number of further trackside beacons forward of the first trackside beacon, and the method may additionally comprise, for each respective further trackside beacon, changing a state of a respective process uniquely associated with the respective further trackside beacon to indicate that the respective further trackside beacon is reserved for the train interlocking system. The fifth information may additionally comprise an indication that the furthertrackside beacons are reserved by the train interlocking system (as well as the first trackside beacon). The method may further comprise receiving a second request from the train interlocking system, the second request comprising a request for reservation of at least one further track location I trackside beacon, the at least one further track location / trackside beacon being forward of any track locations I trackside beacons already reserved by the train interlocking system or occupied by the rail vehicle; and determining a state of a respective process uniquely associated with each at least one further track location / trackside beacon. If the state of the process of one or more of the at least one further track locations I trackside beacons indicates that the one or more of the at least one further track location I trackside beacons is reserved or occupied by an actor other than the train interlocking system, the method may comprise sending sixth information to the train interlocking system, the sixth information comprising an indication that at least one of the further track locations / trackside beacons has not been reserved by the train interlocking system. Otherwise, if the state of the process of each of the at least one further track locations I trackside beacons indicates that each of the at least one further track locations / trackside beacons is not reserved or occupied by an actor other than the train interlocking system, the method may comprise sending seventh information to the train interlocking system, the seventh information comprising an indication that the further track locations / trackside beacons have been reserved by the train interlocking system. The first request may include an encryption key associated with the train interlocking system and may further include a first beacon identifier associated with the first trackside beacon. Changing the state of the first process to reserved and / or occupied by the train interlocking system may comprise encrypting the first process using the encryption key. The fourth information may include a decryption key associated with the train interlocking system and may further include the first beacon identifier. Changing the state of the first process to unoccupied by the train interlocking system may comprise decrypting the encrypted first process using the decryption key. The method may further comprise, priorto changing the state of the first process to occupied, determining whether the state of the first process indicates that the first track location / trackside beacon is reserved by the train interlocking system. If the state indicates that the first track location / trackside beacon is reserved by the train interlocking system, the method may further changing the state of the first process to occupied; or if the state indicates that the first track location / trackside beacon is not reserved by the train interlocking system, the method may comprise issuing an alert. The method of the third aspect of the invention may be implemented in a trackside interlocking system according to a fourth aspect of the invention, the trackside interlocking system comprising: a lineside server, comprising: a memory storing, for each one of a plurality of track locations, a unique location record comprising a (unique) process, wherein the process comprises at least a first state indicating that the location associated with that process is reserved, a second state indicating that the location associated with that process is occupied, and a third state indicating that the location associated with that process is unreserved. Each location record may be associated with a unique trackside beacon, and the location record may further comprise a beacon identifier of that trackside beacon, and may additionally comprise an identifier of one or more adjacent beacons. The trackside interlocking system may additionally comprise the plurality of trackside beacons, each trackside beacon comprising a passive RFID transceiver, each passive beacon RFID transceiver being operable to transmit the beacon identifier associated with that beacon when energised by an appropriate reader, such as a vehicle reader comprising an RFID transceiver. Each trackside beacon may, in use, be located on or adjacent a section of railway track at a known physical geolocation and elevation, which may be stored in the beacon record as the beacon location. The trackside beacons may, in use, be located at predefined intervals along the railway track, such as 20 metre intervals, 15 metre intervals, 10 metre intervals, 8 metre intervals or 6 metre intervals. The trackside interlocking system of the fourth aspect of the invention may be operable to carry out any of the method steps discussed above in connection with the third aspect of the invention, and may optionally comprise any of the features discussed below in the detailed description. It will be appreciated that the methods of the first and third aspects of the invention are complementary, and that a request that is transmitted according to the first aspect of the invention may be received and accepted / rejected according to the third aspect of the invention. The third aspect of the invention may include any of the optional features discussed above in connection with the first aspect of the invention, mutatis mutandis. The methods of the first and third aspects of the invention together define a method of operating a railway interlocking system, which may be implemented in a railway interlocking system comprising the technical features of the systems of the second and fourth aspects of the invention. According to a fifth aspect of the invention we provide a method of speed supervision in a train interlocking system located onboard a rail vehicle, the method comprising: reading, by a vehicle beacon reader, first information associated with a first trackside beacon as the vehicle beacon reader passes the first trackside beacon, the first trackside beacon having a first fixed track location; determining, using the first information, a recommended speed for the first fixed track location; and displaying the recommended speed to a driver of the rail vehicle. Railways have line speeds. These are equivalent to speed limits on roads and are chosen at design time, according to various factors. It can be undesirable to drive a train at the maximum line speed. One reason for this is that trains have long braking distances (potentially measured in miles), and so cannot stop quickly. If a train has a stop planned in the near future, e.g. to drop off passengers at a station, it is necessary for the driver to apply the brakes before getting there in order to be able to safely stop in time. Similarly, if there is a chance that the train could be directed from a high speed line onto a low speed line, the driver needs to slow the train in advance of the junction in order to be prepared to do that safely. For the above reasons, drivers are trained to build up “route knowledge” over time, so they can meet the balance between keeping a safe speed, but not causing delays by braking too early or not making use of the full line speed where they can. This is complicated by signalling, which may be used by a signaller to indicate transient track situations to a driver, such as the presence of a train on the line ahead. A driver must obey the signals, whilst at the same time not causing unnecessary delays to the train. Many countries, such as the UK do not mandate the speed the driver chooses to drive at any particular moment beyond setting the top line speeds. If a driver forgets where they are, or misses a sign etc, this can pose a significant safety risk. The method of the fifth aspect of the invention mitigates this problem by indicating to the driver, in realtime, a recommended speed for the portion of the track on which the train is currently located. Beacons may be located at regular intervals along the track, allowing speed information to be obtained more regularly and with great granularity than via trackside signage. The recommended speed may be stored on the first trackside beacon, and / or may be stored in a database in a unique record associated with that trackside beacon. On reading the beacon to obtain the first information, the train beacon reader is thus able to determine, either directly from the first information (which may, for example, comprise the recommended speed), or indirectly from the first information (which may, for example, comprise a beacon identifier permitting the train interlocking system to look up the recommended speed, e.g. in an onboard database or from a record associated with the trackside beacon held in a lineside server) the speed at which it is recommended the train should be travelling at that location. This recommended speed may be the same as the line speed, or may be different to, and in particular lower than, the line speed. Thus, the recommended line speed may take into account other factors which are not accounted for in the line speed, such as proximity to a station or crossing. The recommended speed may be dependent on the route of the train. For example, each trackside beacon may be associated with more than one recommended speed. The speed which is displayed to the driver may be selected from the plurality of recommended speeds taking into account the planned route of the train. For example, if the route includes a planned stop at an upcoming station then the displayed recommended speed may be lower than if the route plans to pass through the station without making a stop. The recommended speed may be dependent on the availability of one or more trackside beacons forward of the train. For example, the recommended speed may be lower if one or more trackside forward of the train is unavailable for reservation by the train in accordance with the first aspect of the invention. Thus the method of speed supervision of the fifth aspect of the invention may work in tandem with the method of operating an interlocking system discussed above. The method may further comprise automatically (i.e. by the train interlocking system) restricting (i.e. placing an upper limit on) or reducing a speed of the rail vehicle in accordance with the recommended speed. In this way, safety may be improved by preventing a driver from inadvertently exceeding the recommended speed. The fifth aspect of the invention may be implemented in a speed supervision system according to a sixth aspect of the invention. The speed supervision system may comprise: a driver system having a processor storing speed supervision software, and a first transceiver operable to communicate with a lineside server of a track interlocking system; a first vehicle beacon reader having a first vehicle position at a front of the rail vehicle that is fixed with reference to the rail vehicle; and a plurality of trackside beacons. The speed supervision system may comprise any of the features described above with reference to the second and fourth aspects of the invention. Brief description of the drawings The invention will now be described, by way of example only, with reference to the accompanying drawings in which like features are denoted with like reference numerals. Figure 1 is a schematic diagram of a railway interlocking system including a train interlocking system and a trackside interlocking system; Figure 2 is a schematic diagram illustrating the architecture of the railway interlocking system of Figure 1; Figure 3 schematically illustrates a train beacon reader; Figure 4 schematically illustrates a driver system; Figure 5 is a process diagram illustrating a method of operating a railway interlocking system. Detailed description Figure 1 schematically illustrates a railway interlocking system 100. The railway interlocking system 100 includes a trackside interlocking system 10, and at least one train interlocking system 20. The railway interlocking system 100 is implemented in a railway network, which includes railway infrastructure of a conventional type, including one or more tracks 30 having points, crossings, derailleurs, etc, on which one or more rail vehicles, such as trains 40, may run. Although Figure 1 shows only one train 40 present in the railway network, it will be appreciated that in reality multiple trains 40 may operate within the railway network, each train having its own train interlocking system 20. The trackside interlocking system 10 includes, as a minimum, a lineside server 12. The lineside server 12 includes and / or is in signal communication with a memory 14, as well as one or more processors 16 and a transceiver 18 operable to communicate with actors within the railway interlocking system 100. The trackside interlocking system 10 further includes a plurality of trackside beacons 50. Each trackside beacon 50 includes a transceiver, which in the example shown in Figure 1 is a passive RFID transceiver 52. The beacons 50 are placed regularly along the tracks 30 of the railway network, and in the example shown are placed at least every 20 metres, for example every 12 metres, or every 6 metres. Each beacon 50 is directly affixed to a sleeper of the track 30, and has a known geolocation and elevation and a unique beacon identifier. Each trackside beacon is therefore associated with a unique track location. The lineside server 12 is operable to store, for each one of the plurality of trackside beacons 50, a unique beacon record 54 in the memory 14 accessible to the processor 16. Each beacon record 54 includes an indication of the beacon location (being the precise geolocation and elevation of the physical beacon associated with that record), the unique beacon identifier for that specific beacon (such as a unique ID number assigned to that beacon at manufacture or installation), and a beacon process. The beacon record may also store additional information relating to the environment of the beacon, such as beacon identifiers for one or more adjacent beacons in an up track and / or down track direction, which may be used by an actor to identify the next beacon to expect after passing the subject beacon. As used herein, a “beacon process” refers to a software process running in the memory of the lineside server that is uniquely associated with a specified track location, as exemplified by a unique physical trackside beacon 50. Each beacon process comprises at least a first state indicating that the beacon (and so the location) associated with that process is reserved, a second state indicating that the beacon associated with that process is occupied, and a third state indicating that the beacon associated with that process is unreserved (and thus available for reservation). As discussed in more detail below, each process is responsible for regulating the reservation and occupation of its respective beacon, and can be thought of as being analogous to a “software switch”. The process for each beacon is entirely independent, meaning there is no combinational logic performed - each beacon’s process looks after that beacon and that beacon only, and the state of adjacent beacons is irrelevant. Turning now to Figures 3 and 4, the train interlocking system 20 includes a driver system 22, which is located in a cab of the train 40, and at least two train beacon readers 24. In the example of Figure 1, the train interlocking system 20 includes a first train beacon reader 24a and a second train beacon reader 24b, with the first train beacon reader 24a being located at or adjacent the front of the train and the second train beacon reader 24b being located at or adjacent the rear of the train. The driver system 22 includes a processor 26 in communication with a memory storing interlocking software 28. The driver system is operable to send requests to the lineside server 12 of the track interlocking system 10, and to receive information from the lineside server 12 of the track interlocking system 10, using a driver system transceiver 32. The driver system transceiver 32 may utilise any conventional wireless communication standard, such as 4G, to communicate with the track interlocking system 10 via an actor gateway 19 in communication with the lineside transceiver 18. The driver system 22 may additionally include a user interface 34. The user interface 34 may be utilised by a driver 36 of the train to input commands to the driver system 22, and may be operable to display information to the driver 36, such as movement authorities, messages or alerts. As will be discussed in more detail below, the driver system 22, and in particular, the interlocking software 28 executable by the processor 26 of the driver system 22, is operable to issue and / or deny movement authorities for the train. Each train beacon reader 24 is operable to obtain first information associated with a fixed track location. In the example shown in Figures 1 and 3, the train beacon readers 24 are operable to obtain the first information from the trackside beacons. Each train beacon reader 24 is operable to read, and in particular, to communicate with the trackside beacons 50. To this end, each train beacon reader includes a first transceiver 42 that is operable to communicate with the trackside beacons 50. Each train beacon reader 24 may further be operable to communicate with one or both of the lineside server 12 and the driver system 22. For this purpose, the train beacon readers 24 additionally include an optional second transceiver 44 operable to communicate with one or both of the lineside server 12 and the driver system 22. Two distinct transceivers are used in the example shown in Figures 1 and 3, because the trackside beacons 50 utilise a different communication standard to that used by the lineside server 12. In particular, the transceiver 18 of the lineside server 12, like the driver system transceiver 32, may utilise a wireless communication standard such as 4G, whilst the trackside beacons may utilise a short range communication standard, such as a passive communication standard, such as RFID. An advantage of this arrangement is that the trackside beacons 50 need not be powered, and may instead be operable to transmit information only when energised by an external reader, such as a train beacon reader 24. The operation of each train beacon reader 24 is governed by a local microcontroller 46. Each train beacon reader may further include an independent power source, such as a battery 48. The railway interlocking system 100 is optionally further configured to permit interaction with actors other than rail vehicles 40, such as human operators 60. For example, a first human operator 60 may interact directly with trackside beacons 50 using a handheld device 70 having a first transceiver (in this example an RFID transceiver) operable to read data from the trackside beacons. The handheld device also includes a second transceiver (in this example a 4G transceiver) operable to communicate with the lineside store 12. The handheld device may operate to reserve and occupy beacons in a similar way to the train interlocking system, for example in order to carry out maintenance on a section of track. Additionally or alternatively, a second human operator 60 may interact with the trackside interlocking system 10 via a signalling system 80. The signalling system may be operable to set routes or destinations for rail vehicles, and to input, view and / or amend beacon data in the lineside server. In this regard, it should be noted that a “route” differs from a movement authority - a route indicates the planned future locations of a rail vehicle, whereas a movement authority constitutes a permission to move to a specified location (e.g. permission to follow a route). Referring nowto Figure 5, a method of operating the railway interlocking system of Figures 1-4 is shown. In step 101, the train interlocking system 20, and in particular the driver system 22 of the train interlocking system 20, sends a first request to the lineside server 12. The first request comprises a request for reservation of a first trackside beacon 50a. In the illustrated example, the first request includes an identifier for the first trackside beacon 50a and an encryption key associated with the train interlocking system. As discussed above, trackside beacons (and in particular, their associated software processes) can have three states: ‘unreserved’, ‘reserved’ or ‘occupied’. The rules governing beacon occupation may be simplified as follows: • Each train can only occupy a beacon it has previously reserved. Even if a beacon is unoccupied, a train must ask to reserve it by sending a reservation request (such as the first request mentioned above) to the lineside server before it occupies it physically. • Each beacon can only be reserved by one actor. A second actor asking to reserve a beacon will be denied such privilege until such a time as the beacon is released by the actor which has currently reserved it. When asking to reserve a beacon, an actor reserves that beacon for itself and only itself. • Each beacon can only be released to unoccupied by the actorthat reserved it. Except in certain emergency situations, no actor can cancel a beacon reservation other than the one which originally reserved it. • As a further safety measure, the system may require that a beacon can only allow itself to be reserved by a train if safe to pass. Particularly applicable to beacons associated with points, level crossings or derailers, a reservation cannot be granted unless the associated asset is safe. • In the event that any of the above rules are not complied with (e.g. if a beacon is occupied from unreserved state, or occupied over someone else’s occupation), an emergency state is declared for the actors involved and nearby. This would bring vehicles to a halt and / or alert on-track teams, as this should never happen. On receiving the first request from the train interlocking system, the trackside interlocking system 10 (and in particular the processor 16 of the lineside server 12) first determines, in step 103, a state of the beacon process process uniquely associated with the first trackside beacon 50a. In accordance with the above rules, if the state of the process representing the first trackside beacon in the data store indicates that the first trackside beacon is available for reservation (i.e. is not reserved or occupied by an actor other than the train interlocking system), then, in step 105, the lineside server changes the state of the first beacon process to indicate that the first beacon 50a is reserved by the train interlocking system 20. Changing the state of the first process to reserved is achieved by the lineside server encrypting the first beacon process using the encryption key provided by the train interlocking system 20 in the first request. Since only the train interlocking system possesses the corresponding decryption key, the encrypted beacon process now cannot be modified (e.g. reserved) by other actors within the railway system, and so is reserved for the exclusive use of the train interlocking system 20. At step 107, the lineside server 12 sends a message to the driver system 22. The message contains information indicating that the first trackside beacon 50a is reserved by the train interlocking system, as requested. Put another way, in step 107 the lineside server 12 sends to the driver system 22 an indication that the first reservation request has been accepted. If, on the other hand, in step 103 the state of the first beacon process had indicated that the first trackside beacon was already reserved or occupied by an actor other than the train interlocking system 20 which sent the request, then the lineside server 12 would have denied the first request. That is, the lineside server 12 would have taken no action to alter the state of the first beacon process in step 105, and would instead send a message to the driver system 22 indicating that the first trackside beacon was not reserved as requested. It will be appreciated that, if the first beacon process had been reserved or occupied by another actor, that beacon process would have been encrypted using an encryption key supplied by that other actor. Thus the lineside server would not be able to decrypt the first beacon process in order to reserve it for the train interlocking system 20, because the train interlocking system 20 does not possess the decryption key that corresponds to the encryption key supplied by the other actor. Once the driver system has confirmation that the first trackside beacon 50a is reserved for its exclusive use, the train interlocking system 20 (and in particular, the interlocking software running on the processor of the driver system 22) generates, at step 109, a movement authority for the train. The driver is then able to move the train in accordance with the movement authority. As the train approaches the first trackside beacon 50a, the first train beacon reader 24a comes within reading distance of the first trackside beacon 50a first, before the second train beacon reader 24b. The trackside beacons utilise passive RFID in the example shown in the Figures, and thus the reading distance may be short, for example 1-2 metres, or less than 1 metre. When the first train beacon reader 24a comes into range of the first trackside beacon 50a, the first train beacon reader is operable to obtain first information associated with a first track location that is fixed with reference to the track. More specifically, the first train beacon reader is operable to read the first beacon identifier associated with the first trackside beacon from the first trackside beacon 50a. This may occur, for example, as the first train beacon reader 24a passes the first trackside beacon 50a while the train drives over the sleeper on which the first trackside beacon 50a is mounted. In particular, the first beacon reader 24a may energise and / or poll the first trackside beacon at step 111, which may return its beacon identifier in response at step 113. The train interlocking system is then operable to send, at step 115, a message to the lineside server 12. The message includes (second) information indicating that the first trackside beacon 50a is occupied by the train. For example, the message may include the beacon identifier of the first trackside beacon. The message may additionally include the encryption key of the train interlocking system, and an identifier of the train interlocking system. The message may be sent directly by the first train beacon reader, as illustrated in Figure 4, or may instead be sent indirectly via the driver system 22. In a similar manner to that described above, the lineside server 12 may determine whether the state of the first process indicates that the first trackside beacon 50a is already reserved by the train interlocking system. In the present example, the first trackside beacon 50a was reserved in steps 101-107, and so the lineside server 12 is operable to change the state of the first process to occupied in step 117. The train continues to move along the track in a forward direction, and soon the second train beacon reader 24b comes into range of the first trackside beacon 50a. The second train beacon reader 24b is then operable to obtain third information associated with the first track location. More specifically, the first train beacon reader is operable to read the first beacon identifier associated with the first trackside beacon from the first trackside beacon 50a in the same manner as described above in relation to the first train beacon reader 24a. In particular, the second beacon reader 24b may energise and / or poll the first trackside beacon 50a at step 119, which may return its beacon identifier in response at step 121. The second train beacon reader 24b is then operable to send, at step 123, a message to the lineside server 12. The message includes (fourth) information indicating that the first trackside beacon 50a is no longer occupied by the train (and thus is unoccupied, and available for reservation by other actors). In this particular example, the message includes the first beacon identifier and a decryption key associated with the train interlocking system. The lineside server 12 is then operable, in step 125, to change the state of the first process to unoccupied. This may be achieved by decrypting the encrypted first process using the decryption key. For the sake of simplicity, the method above has been described from the point of view of a train passing over a single trackside beacon, namely the first trackside beacon 50a. In practice however, a train may pass over multiple trackside beacons in quick succession as the train moves at speed. The method may thus include a preliminary step 127 in which the train interlocking system, and in particular the interlocking software included in the driver system, determines a required number of beacons for which a movement authority is desired. The required number may be selected based on the known speed of the train (and associated stopping distance) and the known beacon spacing, which together may be used to calculate the number of beacons falling within the minimum stopping distance of the train. A request for reservation may thus identify a desired number of beacons for reservation, the desired number being chosen so that, in total, at least the required number of beacons are reserved for the train interlocking system forward of the train. In essence, the train interlocking system issues its own movement authority (MA) only if it sees enough software units directly in front of itself are safe to occupy. It then reserves the track it needs for braking and occupation by changing the state of those units to reserved. The rear of the train ‘un-reserves’ each software element as it passes, leaving the track behind free for other trains to reserve. The train interlocking system 20 may send subsequent requests for reservation at regular intervals, and for example may request reservation of a second trackside beacon 50b (or third beacon, or nth beacon 50n) as soon as the first trackside beacon becomes unoccupied. Thus the train interlocking system may operate to ensure that at least the required number of beacons are always reserved forward of the train. In the event that the required number of beacons cannot be reserved, the train interlocking system is operable to deny a movement authority for the train, and the driver must then bring the train to a halt. In this way, decision making as regards authority to move (e.g. to follow a route) is devolved from a signaller to the driver system 22 of a train interlocking system 20 on board a train 40. An advantage of this arrangement is that the lineside server does not need to operate in accordance with complex combinatorial logic - instead it behaves as a store of information, and need not be custom to each piece of railway. Instead, the lineside server may be made up of simple, replicable software units which can easily be added to or altered as track is added or reconfigured, by adding or amending beacon data in the memory of the lineside server. All trains within the railway interlocking system have access to the lineside server, and so have access to up-to-date real-time information concerning the current availability of the infrastructure, as indicated by the beacon processes running in the lineside server. After reading a trackside beacon, as discussed above, a train beacon reader (or the driver system) messages the lineside server to mark that beacon as either occupied or unoccupied. In response to such a message the lineside server may return beacon data to the train beacon reader (or driver system) from the beacon record stored in the lineside database. The beacon data may include the beacon location, which may be used by the train interlocking system to determine the exact position, speed and acceleration of the beacon readers at the front and rear of each train. By comparing the numbers determined for the first beacon reader with the numbers determined for the second beacon reader, the driver system of the train interlocking system can determine whether the train is in one piece (known as train or consist integrity). As an alternative, beacon location data may be stored in a memory of the beacon itself, and may be provided to a beacon reader together with the beacon identifier when the beacon is read. The train interlocking system may use this beacon data to determine train integrity in the way described above, without the need to consult the lineside server. The train interlocking system, knowing the vehicle’s position from reading the beacons, can also see the status of the wider track in the area by referring to the beacon records in the lineside database. Those records may contain allowable speeds and gauging information for each beacon, allowing the driver system to indicate information to the driver, such as safe speeds and braking points. As the train moves, the train interlocking system continues to look further ahead, providing up-to-date and assured information to the driver via the user interface in the cab of the vehicle. Essentially, the systems and methods described herein allow a train to ‘see’ the track ahead, including track geometry, speed limit, occupation state, gauge clearance and more. As noted above, trackside beacons are located at regular intervals, for example every 6 metres. Spacing beacons closely means that failures (whether a failure to read, or a failed beacon) do not stop the system working. Failure of up to 90% of the beacons still yields an accurate and assured train position every (approximately) 60 metres, which far exceeds current systems. As protection decisions are made onboard a train, interaction at fringes of a railway network may be simplified. The train interlocking system simply decides, at any given location, whether that location is protected by the onboard train interlocking system (because a corresponding track interlocking system and beacon network is available) ora legacy interlocking system. In areas with traditional signalling, the onboard train interlocking system may indicate to the driver, via the user interface, that the driver should ‘listen to lineside signalling’, and in that case, movement authorities will not be granted for the train by the train interlocking system -those authorities must instead be granted by a signaller in a traditional manner. This enables a rolling programme of signalling upgrades / renewals to be performed, which would not easily possible with a lineside interlocking architecture. It should be noted that the interlocking systems and methods described herein constitute a ‘safety layer’ within a railway system, and are not responsible for routing or driving trains -those functions are abstracted to a higher layer which must act through the interlocking in order to bring about the outcomes desired. The interlocking operates to prevent such actions being carried out if they are unsafe. If required however, the responsibility for routing may also be devolved to the train interlocking system. In a conventional system, a signaller decides the ultimate destination of a train, and plans the route for the train to reach that destination in detail. The driver is thus provided by the signaller with turn-by-turn instructions for the route. In contrast, using the system described herein, a signaller may instead only need to provide the driver system with the ultimate destination of the train and any waypoints through which the train must pass (e.g. stations at which the train should stop at a specified time). The driver system may then utilise the information stored in the lineside server to plan a route for the train, which may be displayed to the driver of the train via the user interface onboard the train. It should be noted that the routing operation is separate from and restricted by the interlocking, whether or not the route is provided by a signaller or by the driver system. In particular, the route refers to the planned future locations of the train, whilst a movement authority refers to the portion of a route that is reserved for sole occupation by the train. The infrastructure employed for a train interlocking system of the type described above may additionally, or alternatively, be utilised in a speed supervision system. Many countries, such as the UK do not mandate the speed the driver chooses to drive at any particular moment beyond setting the top line speeds. If a driver forgets where they are, or misses a sign etc, this can pose a significant safety risk. The infrastructure described above can be used to mitigate this problem by indicating to the driver, in real time, a recommended speed for the portion of the track on which the train is currently located. More specifically, a speed supervision system may be operable to read, using a first train beacon reader, first information associated with a first trackside beacon as the vehicle beacon reader passes the first trackside beacon, the first trackside beacon having a first fixed track location. The system may further be operable to determine, using the first information, a recommended speed for the first fixed track location, and to display the recommended speed to a driver of the rail vehicle. The system may additionally be operable to automatically restrict (i.e. place an upper limit on) or reduce a speed of the rail vehicle in accordance with the recommended speed. The speed restriction or reduction may be implemented by the driver system. The recommended speed may be stored on the first trackside beacon, and / or may be stored in a database (e.g. in the lineside server or in a memory of the driver system) in a record associated with that trackside beacon. On reading the beacon to obtain the first information, the speed supervision system is thus able to determine, either directly from the first information (which may, for example, comprise the recommended speed), or indirectly from the first information (which may, for example, comprise a beacon identifier permitting the system to look up the recommended speed, e.g. in an onboard database or from a record associated with the trackside beacon held in a lineside server) the speed at which it is recommended the train should be travelling at that location. This recommended speed may be the same as the line speed, or may be different to, and in particular lower than, the line speed. The recommended speed, particularly if stored on a lineside server, may be updated in real time to take into account current track conditions, such as the location of other actors within the system. Although exemplary embodiments have been described in the preceding paragraphs, it should be understood that various modifications may be made to those embodiments without departing from the scope of the appended claims. Thus, the breadth and scope of the claims should not be limited to the above-described exemplary embodiments. In particular, the above example has been described with respect to vehicle readers operable to obtain first (and third) information via RFID from trackside beacons. However, the vehicle readers may be operable to obtain said information via any other means capable of ascertaining a fixed location for the reader with respect to the track on which the train is moving. For example, the vehicle readers may comprise a satellite transceiver and the first information may be obtained via a satellite positioning system such as GPS. Alternatively, the vehicle readers may comprise optical readers, such as cameras, and first information may be read from optical indicia located on or adjacent the track. When beacons are employed, other types of wireless communication between a vehicle reader and a trackside beacon may be utilised than RFID, such as Bluetooth®. In a speed supervision system which does not also operate as an interlocking system, no second vehicle reader may be required. Any combination of the above-described features in all possible variations thereof is 5 encompassed by the present disclosure unless otherwise indicated herein or otherwise clearly contradicted by context.

Claims

1. A method of operating a train interlocking system located on board a rail vehicle, the method comprising:obtaining, by a first vehicle reader having a first vehicle position at a front of the rail vehicle that is fixed with reference to the rail vehicle, first information associated with a first track location that is fixed with reference to the track as the first vehicle reader passes the first track location;sending second information to a lineside server, the second information comprising an indication that the first track location is occupied by the rail vehicle;obtaining, by a second vehicle reader having a second vehicle position at a rear of the rail vehicle that is fixed with reference to the rail vehicle, third information associated with the first track location as the second vehicle reader passes the first track location; andsending fourth information to the lineside server, the fourth information comprising an indication that the first track location is unoccupied by the rail vehicle.

2. The method of claim 1, wherein the first track location is associated with a first tracksidebeacon having stored thereon a first beacon identifier, and wherein:the step of obtaining the first information comprises: reading, by the first vehicle reader, the first beacon identifier from the first trackside beacon; andthe step of obtaining the third information comprises: reading, by the second vehicle reader, the first beacon identifier from the first trackside beacon.

3. The method of claim 1 or claim 2, further comprising, prior to sending the second information:sending a first request to the lineside server, the first request comprising a request for reservation of the first track location.

4. The method of claim 3, wherein the train interlocking system is located on board a rail vehicle having a known speed, and wherein the method further comprises:calculating, using the known speed, a required length of track ahead of the rail vehicle; andselecting the first track location based on the required length of track.

5. The method of claim 3 or claim 4, wherein the method further comprises, in response to the first request:receiving, from the lineside server, fifth information, the fifth information comprising an indication that the first track location is reserved by the train interlocking system; andgenerating a movement authority for the rail vehicle.

6. The method of claim 3 as dependent on claim 2, wherein the train interlocking system is located on board a rail vehicle having a known speed, and wherein the method further comprises:calculating, using the known speed, a required number of trackside beacons forward of the rail vehicle;wherein the first request comprises a request for reservation of the first trackside beacon and a number of further trackside beacons forward of the first trackside beacon, the number being selected to ensure that, in total, reservation of the required number of trackside beacons is requested at the lineside server.

7. The method of claim 6, wherein the method further comprises, in response to the first request:receiving, from the lineside server, fifth information, the fifth information comprising an indication that the first trackside beacon and the number of further trackside beacon(s) are reserved by the train interlocking system; andgenerating a movement authority for the rail vehicle.

8. The method of any preceding claim, further comprising:sending a second request to the lineside server, the second request comprising a request for reservation of at least one further track location, the at least one further track location being forward of any track locations already reserved by the train interlocking system or occupied by the rail vehicle.

9. The method of claim 8, wherein the method further comprises, in response to the second request:receiving, from the lineside server, sixth information, the sixth information comprising an indication that the at least one further track location is not reserved for the train interlocking system; anddenying a movement authority for the rail vehicle.

10. The method of any one of claims 3 to 9, wherein the first request includes an encryption key associated with the train interlocking system.

11. The method of any preceding claim, wherein the fourth information includes a decryption key associated with the train interlocking system.

12. The method of any preceding claim, wherein the train interlocking system is associated with a rail vehicle having an expected length, and wherein the method further comprises:using a time between the obtaining of the first information by the first vehicle reader and the obtaining of the third information by the second train beacon reader to calculate a length of the rail vehicle; andcomparing the calculated length with the expected length.

13. A method of operating a trackside interlocking system, wherein the method comprises, at a lineside server:receiving second information from a train interlocking system located on board a rail vehicle, the second information comprising an indication that a first track location is occupied by the rail vehicle associated with the train interlocking system;changing a state of a first process running on the lineside server to indicate that the first track location is occupied, the first process being uniquely associated with the first track location;receiving fourth information from the train interlocking system, the fourth information comprising an indication that the first track location is unoccupied by the rail vehicle; andchanging the state of the first process running on the lineside serverto indicate that the first track location is unreserved.

14. The method of claim 13, further comprising, prior to receiving the second information:receiving a first request from the train interlocking system, the first request comprising a request for reservation of the first track location;changing the state of the first process running on the lineside serverto indicate that the first track location is reserved by the train interlocking system; andsending, to the train interlocking system, fifth information, the fifth information comprising an indication that the first track location is reserved by the train interlocking system.

15. The method of claim 14, wherein the first track location is associated with a first trackside beacon, and wherein the first request comprises a request for reservation of the firsttrackside beacon and a number of further trackside beacons forward of the first trackside beacon,wherein the method additionally comprises, for each respective further trackside beacon, changing a state of a respective process uniquely associated with the respective further trackside beacon to indicate that the respective further trackside beacon is reserved for the train interlocking system, andwherein the fifth information additionally comprises an indication that the further trackside beacons are reserved by the train interlocking system.

16. The method of any one of claims 13 to 15, further comprising:receiving a second request from the train interlocking system, the second request comprising a request for reservation of at least one further track location, the at least one further track location being forward of any track locations already reserved by the train interlocking system or occupied by the rail vehicle;determining a state of a respective process uniquely associated with each at least one further track location, and,if the state of the process of one or more of the at least one further track locations indicates that the one or more of the at least one further track locations is reserved or occupied by an actor other than the train interlocking system, sending sixth information to the train interlocking system, the sixth information comprising an indication that at least one of the further track locations has not been reserved by the train interlocking system;otherwise, if the state of the process of each of the at least one further track locations indicates that each of the at least one further track locations is not reserved or occupied by an actor other than the train interlocking system, sending seventh information to the train interlocking system, the seventh information comprising an indication that the further track locations have been reserved by the train interlocking system.

17. The method of any one of claims 13 to 16, wherein:(i) the first request includes an encryption key associated with the train interlocking system, and wherein changing the state of the first process to reserved and / or occupied by the train interlocking system comprises encrypting the first process using the encryption key; and / or(ii) the fourth information includes a decryption key associated with the train interlocking system, and wherein changing the state of the first process to unoccupied by thetrain interlocking system comprises decrypting the encrypted first process using the decryption key.

18. The method of any one of claims 13 to 17, further comprising, prior to changing the state of the first process to occupied, determining whether the state of the first process indicates that the first trackside beacon is reserved by the train interlocking system, and either: if the state indicates that the first trackside beacon is reserved by the train interlocking system, changing the state of the first process to occupied; orif the state indicates that the first trackside beacon is not reserved by the train interlocking system, issuing an alert.

19. A train interlocking system, the train interlocking system comprising:a driver system having a processor storing interlocking software, and a first transceiver operable to communicate with a lineside server of a track interlocking system;a first vehicle reader having a first vehicle position at a front of the rail vehicle that is fixed with reference to the rail vehicle; anda second vehicle reader having a second vehicle position at a rear of the rail vehicle that is fixed with reference to the rail vehicle;the train interlocking system being configured to carry out the steps of the method of any one of claims 1 to 12.

20. The train interlocking system of claim 19, wherein the first vehicle reader comprises a first RFID transceiver, and the second vehicle reader comprises a second RFID transceiver.

21. A trackside interlocking system, the trackside interlocking system comprising:a lineside server, comprising:a memory storing, for each one of a plurality of track locations, a unique location record comprising a process, wherein the process comprises at least a first state indicating that the location associated with that process is reserved, a second state indicating that the location associated with that process is occupied, and a third state indicating that the location associated with that process is unreserved,the trackside interlocking system being configured to carry out the steps of the method of any one of claims 13 to 18.

22. The trackside interlocking system of claim 21, wherein each unique location record is associated with a trackside beacon, and the location record further comprises a beacon identifier and, optionally an identifier of a next beacon to expect.

23. The trackside interlocking system of claim 22, wherein the system further includes a plurality of trackside beacons, each trackside beacon preferably comprising a passive RFID transceiver operable to transmit the beacon identifier associated with that beacon when 5 energised.

24. A method of speed supervision in a train interlocking system located onboard a rail vehicle, the method comprising:reading, by a vehicle beacon reader, first information associated with a first trackside 10 beacon as the vehicle beacon reader passes the first trackside beacon, the first trackside beacon having a first fixed track location;determining, using the first information, a recommended speed for the first fixed track location; anddisplaying the recommended speed to a driver of the rail vehicle.1525. The method of claim 24, further comprising restricting or reducing, by the train interlocking system, a speed of the rail vehicle in accordance with the recommended speed.Application No: GB2317138.2Examiner: Ms Amanda MasonClaims searched: 1-12Date of search: 30 April 2024Patents Act 1977: Search Report under Section 17Documents considered to be relevant:Category Relevant to claims Identity of document and passage or figure of particular relevance X 1,3,5, 8-9 Li et al, "IEEE 25th International Conference on Intelligent Transportation Systems", published 2022, IEEE, pp.3315-3320, "Description and Analysis of Train-centric Communication based Autonomous Train Control System" A - EP 3299250 Al (KOREA RAILROAD RES INSTITUTE) See Figure 5; paragraph [0041] A - US 2006 / 0195236 Al (KATSUTA et al.) See paragraphs [0086], [0101] A - US 2022 / 0315072 Al (ZHANG et al.) See paragraphs [0006]-[0012]Categories:X Document indicating lack of novelty or inventive step A Document indicating technological background and or state of the art. Y Document indicating lack of inventive step if P Document published on or after the declared priority date but combined with one or more other documents of same category. before the filing date of this invention. & Member of the same patent family E Patent document published on or after, but with priority date earlier than, the filing date of this application.Field of Search:International Classification:Subclass Subgroup Valid From B61L 0015 / 00 01 / 01 / 2006 B61L 0023 / 12 01 / 01 / 2006 B61L 0023 / 30 01 / 01 / 2006 B61L 0027 / 40 01 / 01 / 2022Application No: GB2317138.2Examiner:Ms Amanda MasonClaims searched: 24-25Date of search: 2 October 2024Patents Act 1977Further Search Report under Section 17Documents considered to be relevant:Category Relevant to claims Identity of document and passage or figure of particular relevance v A 24-25 EP 3299250 Al (KOREA RAILROAD RES INSTITUTE) See Figure 4 and paragraphs [0041], [0053] X 24-25 US 2006 / 0195236 Al (KATSUTA et al.) See Figure 1 and paragraphs [0010]-[0018], [0059], [0066], [0080]-[0081], [0102]-[0106] v A 24-25 US 10297153 B2 (GAO et al.) See Figures 2-5, column 2: lines 4-10, col.2:31-47, col.6:25-col.7:4, col.7:62-col.8:35 X 24-25 CN 110126882 B (BEIJING HOLLYSYS CO LTD) See Figure 9 A - GB 2557623 A (MTR CORPORATION LTD) See page 3: line 20 - p.4:19, p.6:4-8, p. 12:29-p. 13:15, p 16:16-p. 17:5 A - US 2015 / 0060608 Al (CARLSON et al.) See Figure 1 and paragraph [0115] A - WO 2021 / 084542 Al (CYLUS CYBER SECURITY LTD) See paragraph [0027] A - US 2015 / 0225003 Al (MORTON) See paragraph [0004]Categories:X Document indicating lack of novelty or inventive step A Document indicating technological background and / or state of the art. Y Document indicating lack of inventive step if P Document published on or after the declared priority date but combined with one or more other documents of same category. before the filing date of this invention. & Member of the same patent family E Patent document published on or after, but with priority date earlier than, the filing date of this application.Field of Search:International Classification:Subclass Subgroup Valid From B61L 0015 / 00 01 / 01 / 2006 B61L 0023 / 12 01 / 01 / 2006 B61L 0023 / 30 01 / 01 / 2006 B61L 0027 / 40 01 / 01 / 2022

Citation Information

Patent Citations

  • Train control methods and systems and methods for calculating movement authorization

    CN110126882B

  • Onboard-based electronic interlocking system and method therefor for inter-train connection-based autonomous train control system

    EP3299250A1

  • Railway monitoring systems, apparatus and methods

    GB2557623A

  • Vehicle on-board controller centered train control system

    US10297153B2

  • Signaling system

    US20060195236A1