Mobile body traffic control system and process handover method in the system
A redundant mobile traffic control system with a primary and secondary control base ensures control continuity and processing by allowing the secondary base to take over application processing upon failure detection, addressing the challenges of performance degradation and large internal state sizes.
Patent Information
- Application Number
- JP2023202750
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-30
- Publication Date
- 2025-06-11
AI Technical Summary
Existing vehicle traffic control systems face challenges in maintaining control continuity and processing when the primary control base becomes unusable, particularly due to performance degradation and large internal state sizes, which can lead to safety issues and system failures.
A redundant mobile traffic control system is implemented with a primary and secondary control base, where application devices and gateways share important status data. If a failure is detected, the secondary control base takes over the application processing, ensuring continuity by matching important status data and handling inconsistencies through data updates and new application device creation.
This solution enables the maintenance of control continuity and processing even when the primary control base becomes unusable, without significant changes to the existing application structure, thus ensuring safety and system availability.
Smart Images

Figure 2025088204000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a vehicle traffic control system for vehicles such as buses and a method for transferring processing in the system.
Background Art
[0002] As a method for achieving both improved usability and guaranteed determinacy required for a control system, cluster management software such as RAFT (distributed consensus algorithm) is utilized. Here, RAFT (distributed consensus algorithm) is a technology that provides a general-purpose means for distributing state machines across an entire cluster of a computing system. Here, when using the mechanism of RAFT, the input data stored in the log and the snapshot of the internal state of the application stored at the latest checkpoint are shared.
[0003] Also, Patent Document 1 discloses a data synchronization method using a plurality of tracking control devices. Specifically, when a tracking control device detects an abnormality in another tracking control device, the planned data synchronization unit of the tracking control device copies the planned data other than the planned data used in the most recent control of the other tracking control device stored in the auxiliary storage device of the tracking control device to the main storage device of the tracking control device to synchronize the planned data of the other tracking control device.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] When applying the method using the above-described mechanism of RAFT to a traditional control application, there are the following problems. First, the amount of modification to the application increases. Since part of the internal state of the control application is in the heap area within the program, it is impossible to take a snapshot from the outside. Therefore, if the entire control application is lifted to shared memory, it is necessary to additionally prepare a transaction mechanism, which increases the amount of modification. In addition, performance degradation occurs due to transaction management, and furthermore, the internal state of the control application is large in size, so it takes time to share the snapshot.
[0006] Second, the continuity of control cannot be maintained. For example, when the controlled object is a moving body, if it takes time to match the input data stored in the log with the state from the snapshot of the internal state of the application stored at the latest checkpoint, it becomes difficult to perform control involving a rapid state change of the controlled object. Specifically, for example, if the existing control base becomes unusable after giving a green signal to a traffic signal, the red display instruction will not reach and the green display will remain. Therefore, if suddenly changing from a green signal to a red signal, a sudden brake will be applied to the moving body, so it is not always possible to immediately display red for safety reasons.
[0007] On the other hand, in the technology disclosed in Patent Document 1, since the area equipped with facilities and the tracking control device are linked one-to-one, when both the tracking control device and the facility interface (facility I / F) are missing, the operation cannot continue. Also, when detecting a failure through mutual monitoring between tracking control devices and performing handover of processing, there remains a problem that although the tracking control devices are not communicating with each other, if they can communicate with the facility interface (facility I / F), they will both become the main systems.
[0008] Therefore, an object of the present invention is to provide a system that can maintain the continuity of control and continue processing even when the existing control base becomes unusable, without changing the structure of the existing application as much as possible, and is particularly suitable for a traffic control system or the like that constitutes a redundant system.
Means for Solving the Problems
[0009] In order to solve the above problems, one of the typical mobile traffic control systems according to the present invention is a mobile traffic control system that forms a redundant system with a main first control base and a subordinate second control base to control the traffic of mobile bodies. Each of the first control base and the second control base includes at least one or more application devices that remotely control a mobile body control device that controls at least the running of a mobile body, and includes a plurality of GWs (gateways) that mediate between the application device and the mobile body control device via a network. The application device and the GW share data regarding the latest position of the mobile body as important status data. If a GW arranged outside the first control base and the second control base detects a failure of the first control base, the GW notifies the application device included in the second control base of the failure. The application device included in the second control base that has received the failure notification determines whether the important status data matches or does not match between the second control base and the GW that notified the failure. If they match, it takes over the application processing that the main application device included in the first control base has been performing.
Effects of the Invention
[0010] According to the present invention, even when an existing control base becomes unusable, it is possible to maintain the continuity of control and enable the continuation of processing without changing the structure of the existing application as much as possible. Problems, configurations, and effects other than those described above will be clarified by the description in the following embodiments for implementation.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Mode for Carrying Out the Invention
[0012] Hereinafter, with reference to the drawings, examples will be described as embodiments of the present invention. Note that the present invention is not limited by this example. Also, in the description of the drawings, the same parts are denoted by the same reference numerals.
Example
[0013] FIG. 1 is a block diagram showing an example of the configuration of a moving body traffic control system. Specifically, it is an example of the configuration of a moving body traffic control system centered on a traffic control center related to the operation control of moving bodies such as buses.
[0014] As shown in FIG. 1, the mobile traffic control system according to an embodiment of the present invention constitutes a redundant system to improve availability, and includes a traffic control center 1, which is an existing first control site, as the main (primary system), and a cloud 2, which is a second control site (backup site), as the sub (secondary system). The traffic control center 1, the cloud 2, and in addition, the urban sub-center 3 are each connected to a control network 6.
[0015] The traffic control center 1 includes at least a plurality of application (AP) devices (hereinafter, may be simply referred to as "AP devices") (in FIG. 1, AP device A and AP device B) 4, a plurality of GWs (gateways) (in FIG. 1, GW-a and GW-b) 5, and a console 9, each of which is connected to the control network 6.
[0016] The cloud 2 includes at least an application (AP) device C 4, a console 9, and a man-machine 10, each of which is connected to the control network 6.
[0017] The urban sub-center 3 includes at least GW-c 5, and this GW-c 5 is connected to the control network 6.
[0018] On the other hand, connected to the signal network 7 are GW-a 5 and GW-b 5 of the traffic control center 1, GW-c 5 of the urban sub-center 3, and a plurality of terminal corresponding devices 8 corresponding to device terminals related to mobile body control and signal control, which perform signal transmission and reception with each other. That is, GW-a to GW-c of the GW 5 can be said to be devices that mediate between the previous application devices (AP devices A to C) 4 and the terminal corresponding devices 8 corresponding to the above-mentioned device terminals.
[0019] Here, each of the application devices (AP devices A to C) 4 is an important component in each control site, and includes a device management unit, an application unit, and a storage unit that stores system management information, plan data, route data, and important status data.
[0020] In addition, each of the GWs (GW-a to GW-c) 5 is connected to each of the control network 6 and the signal network 7, and includes a device management unit and a storage unit that stores schedule data, important status data, and the history of the mobile control device status.
[0021] Furthermore, the terminal support device 8 is connected to the mobile control device 11 that controls the mobile body 12 and the signal controller 13 that controls traffic signals, and sends instructions from the previous control base to these devices and sends necessary signals from these devices to the control base.
[0022] FIG. 2 is a diagram showing a route and a table showing the data of the route. Specifically, it is a diagram showing a route of a bus or the like using links and nodes, a table summarizing the route data in terms of the relationship between nodes and links, and a table summarizing management points in terms of the relationship between links and nodes.
[0023] In the operation control associated with the bus operation plan, bus stops, bus depots, etc. on the bus route are regarded as nodes (represented by ○ marks, and the numbers inside ○ indicate node numbers), the routes between these nodes are represented by links, and a plurality of points on these links are treated as management points.
[0024] In FIG. 2, nodes 1 to 11 are shown, and links 1 to 10 connecting these nodes are shown. Also, points A to C are management points, among which, point A and point C are management points involved in the important status, and point B is a management point not involved in the important status. Here, examples of the management points involved in the important status include bus stops.
[0025] The upper table in FIG. 2 explains the links, and shows the two end nodes of the link and the link length. For example, link 1 connects node 1 and node 3, and the link length is 1000 m. Links 2 to 10 are shown in the same way.
[0026] The table below Figure 2 describes the management locations, showing the existing links, starting nodes, and distances from the starting nodes. For example, location A exists on Link 1, which has a starting node of Node 1 and a distance of 600 m from this starting node. Locations B and C are shown in a similar manner.
[0027] Figure 3 is a table showing the management information of the devices included in the mobile traffic control system. For the application (AP) devices (AP devices A to C) 4 and GWs (GW-a to GW-c) 5 included in the traffic control system shown in Figure 1, it shows the installation location, role of the cluster, master-slave role, and status of the devices.
[0028] Regarding the application (AP) devices 4, the AP devices A to C form an application cluster. The AP device A in traffic control center 1 functions as the primary (main system), and the remaining AP device B in traffic control center 1 and the AP device C in cloud 2 function as secondary (subordinate systems).
[0029] Also, regarding the GWs 5, the GW-a to GW-c form a GW cluster. The GW-a in traffic control center 1 functions as the primary (main system), and the remaining GW-b in traffic control center 1 and the GW-c in urban sub-center 3 function as secondary (subordinate systems).
[0030] Figure 4 is a table showing the planned data of the traveling vehicles, and as the planned data, it shows the planned passing times when the traveling vehicles pass through the management locations. It shows the planned passing times of the management locations (A to C) for two vehicles X and Y traveling on the route. For example, the planned passing time of vehicle X at location A is 9:56. This planned passing time (planned data) is used, for example, to recover the delay by signal control or the like when the traveling vehicle is running behind schedule.
[0031] Figure 5 is a table showing the important status data. Here, the important status data records the data regarding the latest position for each traveling vehicle. In the table shown in FIG. 5, as the important state data, the latest position for each traveling vehicle is indicated by the final update time when the traveling vehicle passed the nearest management point.
[0032] FIG. 6 is a table showing the state history of the moving body. Specifically, the time when the traveling vehicle (moving body) passed a predetermined point on the route is recorded as the state history by the movement control device 11. In the table shown in FIG. 6, for vehicle X, it is shown that the vehicle passes through points P → Q → R → A → B → C at times 9:53 → 9:54 → 9:55 → 9:56 → 9:58 → 10:00 (final update: FIG. 5) respectively, and for vehicle Y, it is shown that the vehicle passes through points P → Q → R → A at times 9:55 → 9:56 → 9:58 → 10:00 (final update: FIG. 5) respectively. Here, points P, Q, and R are located on the starting point (node 1) side of the management point A shown in FIG. 2.
[0033] FIG. 7 is a diagram showing an example of the processing sequence according to the embodiment. Specifically, it shows the processing sequences in the traffic control center 1 which is the existing first control base (main system), the cloud 2 which is the second control base (subordinate system), and the city sub - center 3, all of which are connected to the control network 6. Also, the processing sequence consists of a normal - time sequence (constant - period execution sequence) executed at a fixed period and a sequence at the time of failure of the existing first control base (sequence at the time of failure of the existing first control base).
[0034] As the constant - period execution sequence, the AP device A4 which is an application device of the traffic control center 1 periodically instructs the AP device C4 of the cloud 2, the GW - a5 in the traffic control center 1, and the GW - c5 of the city sub - center 3 to save this important state data (data regarding the latest position for each traveling vehicle shown in FIG. 5) in order to share the important state data.
[0035] The sequence at the time of failure of the existing first control base consists of the following five steps. In Step 1, GW-c5 of Urban Sub-center 3 detects the disconnection of AP device A4 and GW-a5 of Traffic Control Center 1, which is the existing primary control center (main system).
[0036] In Step 2, GW-c5 of Urban Sub-center 3 notifies the failure detected in Step 1 to Cloud 2, which is the secondary control center (subordinate system).
[0037] In Step 3, AP device C4 of Cloud 2, which is the secondary control center (subordinate system) that has received the failure notification, activates the handover process from Traffic Control Center 1, which is the existing primary control center (main system). This handover process will be described next with reference to Figure 8.
[0038] Figure 8 is a diagram showing the flowchart of the handover process by AP device C4 of Cloud 2, which is the secondary control center (subordinate system). The execution entity of the following processing steps is AP device C4, but the description of this entity is omitted in each of the following steps. The steps of this handover process are executed at a fixed number of seconds interval.
[0039] In Step S301, it is determined whether handover is possible. This determination is made based on whether the important status data is the same between AP device C4 of Cloud 2, which is the secondary control center (subordinate system), and GW-c5 of Urban Sub-center 3.
[0040] If the important status data matches between AP device C4 of the subordinate Cloud 2 and GW-c5 of Urban Sub-center 3 and the handover is possible (Y), the handover process ends, and AP device C4 of Cloud 2 becomes the main system and takes over the process.
[0041] On the other hand, if the important status data does not match between AP device C4 of the subordinate Cloud 2 and GW-c5 of Urban Sub-center 3 and the handover is not possible (N), it proceeds to Step S302.
[0042] In step S302, it is determined whether the inconsistent state of the important state data is within a certain number of seconds. If it is within the certain number of seconds (Y), the process proceeds to step S303. On the other hand, if it exceeds the certain number of seconds (N), the process proceeds to step S304.
[0043] In step S303, the important state data of GW-c5 is updated with the input data from GW-c5 of urban sub-center 3, and the determination of the transferability is continued.
[0044] In step S304, it is notified to GW-c5 of urban sub-center 3 that the transfer is not possible, and the transfer process is terminated. This step S304 corresponds to step 4 (Step4) in FIG. 7 described later.
[0045] Returning to the sequence of FIG. 7, assuming that the transfer is not possible, in step 4 (Step4), as shown in step S304 of the above-described transfer process, the AP device C4 notifies GW-c5 of urban sub-center 3 that the transfer is not possible.
[0046] In step 5 (Step5), GW-c5 of urban sub-center 3 instructs the moving body to slow down. At this time, the slow-down instruction issued by GW-c5 of urban sub-center 3 to the signal network 7 shown in FIG. 1 is notified to the moving body 12 via the terminal corresponding device 8 and the movement control device 11 shown in FIG. 1. This slow-down instruction is for ensuring the safety of the movement of the moving body under the condition that the transfer is not possible.
[0047] In step 6 (Step6), GW-c5 of urban sub-center 3 deletes the legacy AP device C4 of the cloud 2 which is the second control site (slave system), and instructs the new AP device D4 as the alternative system to start up.
[0048] In step 7 (Step7), the AP device D4 of the cloud 2 that has received the start-up instruction as the alternative system attempts to construct the device as an application.
[0049] In Step 8, the AP device D4 of Cloud 2 executes an update process as the application device 4 based on the planned data, important status data, and the status history of the movement control device (movement control device 11 shown in FIG. 1) transmitted from the GW-c5 of the urban sub-center 3. The following will explain this update process with reference to FIG. 9.
[0050] FIG. 9 is a diagram showing a flowchart of the update process by the new AP device D4 of Cloud 2, which is the secondary control site (slave system). The execution entity of the following processing steps is the AP device D4, but the description of this entity is omitted in each of the following steps.
[0051] In step S801, the planned data (FIG. 4) and the important status data (FIG. 5) are acquired from the GW-c5 of the urban sub-center 3.
[0052] In step S802, following the previous step S801, the status history (FIG. 6) of the movement control device 11 after the creation time of the latest important status data is acquired from the GW-c5 of the urban sub-center 3.
[0053] In step S803, a loop process is executed for the status history of the movement control device 11 after the creation time of the latest important status data.
[0054] In step S804, a periodic process is executed as a loop process to update the important status data. By the steps up to here, the updates possessed by the GW-c5 of the urban sub-center 3 are restored all at once up to the situation of the communication failure detection in Step 1.
[0055] In step S805, the status history of the movement control device 11 added during the periodic processes in steps S803 and 804 is acquired from the GW-c5 of the urban sub-center 3.
[0056] In step S806, the latest value of the important status data is estimated from the latest value of the status history of the movement control device 11, which is the transition target of the important status data.
[0057] In step S807, loop processing is executed for the state history of the movement control device 11 after the latest important state data creation time.
[0058] In step S808, it is determined whether the important state data updated for each loop process in step S807 is the same as the latest value of the estimated important state data. If they are the same (Y), the process proceeds to step S810; if they are not the same (N), the process proceeds to step S809.
[0059] In step S809, the delay is set to 0 to set the normal control cycle, and the process proceeds to step S813.
[0060] In step S810, a value shorter than the control cycle is set for the delay, and the process proceeds to step S811.
[0061] In step S811, it is determined whether there is a certain time or more until the next update of the important state data. If there is a certain time or more (Y), the process proceeds to step S812; if it is less than the certain time (N), the process directly proceeds to step S813.
[0062] In step S812, an instruction is issued to relax the slow travel of the moving body that is the control target, which was instructed in the previous step 5 (Step5), and the process proceeds to step S813.
[0063] In step S813, periodic processing is executed as loop processing, and the important state data is updated.
[0064] The processing steps from step S810 to step S812 described above can accelerate the arrival at the transition destination (management point) involved in the important state data and speed up the update from the latest state history of the movement control device 11 and the important state data of the management point.
[0065] Next, with reference to FIGS. 10 to 13, the operating states and the like of the system in the normal state and the abnormal state will be described. Figure 10 is a diagram showing the system operation state, device list, and messages in the normal state.
[0066] In the normal state, the application (AP) device A4 of the traffic control center 1 is primary, and the remaining application (AP) device B4 and the application (AP) device C4 of the cloud 2 are secondary. Also, the GW-a5 of the traffic control center 1 is primary, and the remaining GW-b5 and the GW-c5 of the urban sub-center 3 are secondary, and all are in a normal state.
[0067] Also, as an example of the output message in the normal state, "Operating normally." is displayed on, for example, the console 9.
[0068] Figure 11 is a diagram showing the system operation state, device list, and messages when an abnormal state occurs. The abnormal state is an example when a site abnormality occurs at the traffic control center 1, which is the existing primary control site.
[0069] When a site abnormality occurs at the traffic control center 1, which is the existing primary control site, the application (AP) device A4, application (AP) device B4, GW-a5, and GW-b5 of the traffic control center 1 become inoperable (abnormal state). On the other hand, the application (AP) device C4 of the cloud 2 and the GW-c5 of the urban sub-center 3, which are the secondary control sites, remain in the normal state but are secondary.
[0070] Also, as an example of the output message at the time of the occurrence of the abnormal state, "The traffic control center is down. Transferring the process to the secondary control site." is displayed on, for example, the console 9.
[0071] Figure 12 is a diagram showing the system operation state, device list, and messages when the process transfer from the abnormal state fails. It is an example when the process transfer fails after the occurrence of the site abnormality at the traffic control center 1, which is the existing primary control site shown in Figure 11.
[0072] When the traffic control center 1, which is the existing first control point, fails to transfer the process after the occurrence of a site abnormality, the application (AP) device A4, application (AP) device B4, GW-a5, and GW-b5 of the traffic control center 1 and the application (AP) device C4 of the cloud 2, which is the second control point, are inoperable (abnormal state). On the other hand, the application (AP) device D4 newly started in the cloud 2, which is the second control point, is in a normal state but is secondary, and the GW-c5 of the urban sub-center 3 is primary in the normal state.
[0073] Also, as an example of the output message at this point in the abnormal state, "The process could not be taken over at the second control point. A slowdown instruction is issued to all vehicles, and a new application device is started." is displayed on, for example, the console 9.
[0074] Figure 13 is a diagram showing the system operation state, device list, and message when the process takeover from the abnormal state is completed. This is an example where the process takeover is restored by the application (AP) device D4 newly started in the cloud 2 after the process takeover failure shown in Figure 12.
[0075] When the traffic control center 1, which is the existing first control point, completes the process takeover after the occurrence of a site abnormality, the application (AP) device A4, application (AP) device B4, GW-a5, and GW-b5 of the traffic control center 1 and the application (AP) device C4 of the cloud 2, which is the second control point, are inoperable (abnormal state). On the other hand, the application (AP) device D4 newly started in the cloud 2, which is the second control point, functions as primary in the normal state, and the GW-c5 of the urban sub-center 3 is primary in the normal state.
[0076] Also, as an example of the output message at the time of completion of the process takeover, "The recovery of the application device of the second control has been completed. The process is started." is displayed on, for example, the console 9.
[0077] According to the above-described embodiments, the present invention includes at least the following aspects. <Aspect 1> A mobile traffic control system that constitutes a redundant system with a primary first control point and a secondary second control point to perform traffic control of a mobile body. Each of the first control point and the second control point includes at least one or more application devices that remotely control a mobile body control device that controls at least the running of the mobile body, and includes a plurality of GWs (gateways) that mediate between the application device and the mobile body control device via a network. The application device and the GW share data regarding the latest position of the mobile body as important status data. If a GW arranged outside the first control point and the second control point detects a failure of the first control point, the GW notifies the application device provided in the second control point of the failure. The application device provided in the second control point that has received the failure notification determines whether the important status data matches or does not match between the second control point and the GW that notified the failure. If they match, it takes over the application processing being performed by the main application device provided in the first control point.
[0078] <Aspect 2> The mobile traffic control system described in the above Aspect 1, wherein the application device provided in the second control point determines that they do not match if the time when the important status data does not match exceeds a predetermined time, and repeats the determination of whether they match or not when the important status data possessed by the GW arranged outside the first control point and the second control point is updated within the predetermined time.
[0079] <Aspect 3> The mobile traffic control system described in the above Aspect 1 or the above Aspect 2, wherein when the important status data does not match and it is impossible to take over the application processing by the application device provided in the second control point, the GW arranged outside the first control point and the second control point instructs the mobile body control device to slow down the mobile body.
[0080] <Aspect 4> The mobile body traffic control system described in the above Aspect 3, when the important state data is inconsistent and it is impossible to transfer the application processing by the application device provided in the second control site, the GW arranged outside the first control site and the second control site instructs the second control site to delete the application device provided in the second control site and create a new application device in the second control site. The new application device acquires the important state data and the data necessary for the application processing from the GW that notified the communication failure and completes the transfer.
[0081] <Aspect 5> The mobile body traffic control system described in the above Aspect 4, wherein the new application device acquires the state history of the mobile body control device as the data necessary for the application processing, and when executing the update process of the important state data from the state history, for the state history added during the update process, the control cycle is shortened and the update process is executed.
[0082] <Aspect 6> The mobile body traffic control system described in the above Aspect 5, wherein the new application device estimates the latest value of the important state data from the latest state history used for the update process of the important state data, compares the estimated latest value with the updated important state data, and shortens the control cycle when both are the same.
[0083] <Aspect 7> The mobile body traffic control system described in the above Aspect 5 or the above Aspect 6, wherein when there is a predetermined time or more until the execution of the next update process after shortening the control cycle, the new application device gives an instruction to relax the deceleration of the mobile body.
[0084] <Aspect 8> A method for transferring processing in a mobile body traffic control system that constitutes a redundant system with a primary control point of a primary system and a secondary control point of a secondary system to perform traffic control of a mobile body. An application device provided with at least one or more of the primary control point and the secondary control point remotely controls at least a mobile body control device that controls the running of the mobile body. A plurality of GWs (gateways) mediate between the application device and the mobile body control device via a network. The application device and the GW share data regarding the latest position of the mobile body as important status data. When a GW arranged other than the primary control point and the secondary control point detects a failure of the primary control point, it notifies the application device provided in the secondary control point of the failure. When the application device provided in the secondary control point receives the failure notification, it determines whether the important status data matches or does not match between the secondary control point and the GW that notified the failure. If they match, it takes over the application processing being performed by the main application device provided in the primary control point.
[0085] <Aspect 9> A method for transferring processing in the mobile body traffic control system described in the above Aspect 8. When the time during which the important status data does not match exceeds a predetermined time, the application device provided in the secondary control point determines that they do not match. When it is within the predetermined time, it repeatedly determines whether they match or do not match based on the important status data of the GW arranged other than the primary control point and the secondary control point being updated.
[0086] <Aspect 10> A method for transferring processing in the mobile body traffic control system described in the above Aspect 8 or the above Aspect 9. When the important status data does not match and it is impossible to take over the application processing by the application device provided in the secondary control point, the GW arranged other than the primary control point and the secondary control point instructs the secondary control point to delete the application device provided in the secondary control point and create a new application device in the secondary control point. The new application device obtains the important status data and the data necessary for the application processing from the GW that notified the failure to complete the takeover.
[0087] As described above, the embodiments of the present invention have been explained. However, the present invention is not limited to the above-described embodiments, and various modifications can be made without departing from the gist of the present invention.
Explanation of Reference Numerals
[0088] 1…Traffic control center (existing first control base), 2…Cloud (second control base), 3…Urban sub-center, 4…Application (AP) device (AP devices A to C), 5…GW (gateway) (GW-a to c), 6…Control network, 7…Signal network, 8…Terminal corresponding device, 9…Desk (console), 10…Man-machine, 11…Mobile control device, 12…Mobile body, 13…Signal controller
Claims
1. A mobile traffic control system that constitutes a redundant system with a main first control point and a subordinate second control point to control the traffic of a mobile body, each of the first control point and the second control point includes at least one or more application devices that remotely control a mobile body control device that controls at least the running of the mobile body, and includes a plurality of GWs (gateways) that mediate between the application device and the mobile body control device via a network, the application device and the GW share data regarding the latest position of the mobile body as important status data, if the non-communication of the first control point is detected by the GW arranged outside the first control point and the second control point, the GW notifies the non-communication to the application device included in the second control point, the application device included in the second control point that has received the notification of the non-communication determines whether the important status data matches or does not match between the second control point and the GW that notified the non-communication. If they match, it takes over the application processing being performed by the main application device included in the first control point A mobile traffic control system characterized by the above.
2. The mobile traffic control system according to claim 1, if the time when the important status data does not match exceeds a predetermined time, the application device included in the second control point determines that it does not match. If it is within the predetermined time, it repeatedly determines whether the important status data possessed by the GW arranged outside the first control point and the second control point is updated to match or not match A mobile traffic control system characterized by the above.
3. The mobile traffic control system according to claim 1, when the takeover of the application processing by the application device included in the second control point is impossible due to the mismatch of the important status data, the GW arranged outside the first control point and the second control point instructs the mobile body to slow down with respect to the mobile body control device A mobile traffic control system characterized by the above.
4. The mobile traffic control system according to claim 3, When the important status data is inconsistent and it is impossible to transfer the application process by the application device provided in the second control site, the GW arranged outside the first control site and the second control site instructs the second control site to delete the application device provided in the second control site and create a new application device in the second control site. The new application device obtains the important status data and the data necessary for the application process from the GW that notified the communication failure and completes the transfer. A mobile traffic control system characterized by the above.
5. The mobile traffic control system according to claim 4, When the new application device obtains the status history of the mobile control device as the data necessary for the application process and executes the update process of the important status data from the status history, for the status history added during the update process, the control cycle is shortened and the update process is executed. A mobile traffic control system characterized by the above.
6. The mobile traffic control system according to claim 5, The new application device estimates the latest value of the important status data from the latest status history used for the update process of the important status data, compares the estimated latest value with the updated important status data, and shortens the control cycle when both are the same. A mobile traffic control system characterized by the above.
7. The mobile traffic control system according to claim 5 or 6, When there is a predetermined time or more until the execution of the next update process when the new application device shortens the control cycle, the new application device gives an instruction to relax the deceleration of the mobile body. A mobile traffic control system characterized by the above.
8. A process transfer method in a mobile traffic control system that configures a redundant system with a main first control site and a subordinate second control site to control the traffic of a mobile body, An application device provided with at least one or more of the first control site and the second control site remotely controls at least a mobile control device that controls the running of the mobile body. A plurality of GWs (gateways) mediate between the application device and the mobile control device via a network. The application device and the GW share data regarding the latest position of the moving object as important status data. If the GW arranged outside the first control point and the second control point detects the inaccessibility of the first control point, it notifies the inaccessibility to the application device included in the second control point. When the application device included in the second control point receives the notification of the inaccessibility, it determines whether the important status data matches or does not match between the second control point and the GW that notified the inaccessibility. If they match, it takes over the application processing being performed by the main application device included in the first control point. A method for process takeover in a mobile object traffic control system, characterized by the above.
9. A method for process takeover in the mobile object traffic control system according to Claim 8, wherein the application device included in the second control point determines that there is a mismatch if the time during which the important status data does not match exceeds a predetermined time, and if it is within the predetermined time, it repeatedly determines whether the important status data possessed by the GW arranged outside the first control point and the second control point is updated to match or not match. A method for process takeover in a mobile object traffic control system, characterized by the above.
10. A method for process takeover in the mobile object traffic control system according to Claim 8 or 9, wherein if the GW arranged outside the first control point and the second control point determines that the important status data does not match and it is impossible to take over the application processing by the application device included in the second control point, it instructs the second control point to delete the application device included in the second control point and create a new application device in the second control point. The new application device acquires the important status data and the data necessary for the application processing from the GW that notified the inaccessibility to complete the takeover. A method for process takeover in a mobile object traffic control system, characterized by the above.
Citation Information
Patent Citations
JP137862A