Control method for rail transport facility control system and rail transport facility control system

By employing commercially available terminals and secure communication protocols, the control system for rail transportation equipment addresses the cost and security challenges of existing systems, achieving a more economical and reliable solution.

JP2025517481APending Publication Date: 2025-06-05HITACHI RAIL STS SPA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024569300
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-24
Filing Date
2023-05-23
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Existing control systems for rail transportation equipment are costly due to the need for proprietary terminals that ensure SIL security requirements, while commercially available COTS devices like LCD monitors and tablets cannot be directly connected to central units for security reasons.

Method used

A control method and system that allows the use of commercially available terminals, such as LCD monitors and handheld devices, at peripheral post stations and for maintenance operators, ensuring high reliability and security by encrypting display messages and using secure communication protocols.

Benefits of technology

This solution reduces the cost and complexity of rail transportation control systems while maintaining high security and reliability standards, enabling the use of standard commercial devices in secure and controlled environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025517481000001_ABST
    Figure 2025517481000001_ABST
Patent Text Reader

Abstract

A control method for a control system of a railway transportation facility (1), the control system (10) comprising a preferably mobile or fixed terminal (300), the method comprising the following steps: receiving a first command from an operator via the terminal (300), executing the first command, sending at least one display message (MV) containing information for the operator to the terminal (300), and displaying on a screen (301) of the terminal (300) a screen showing information of the at least one display message (MV), in particular at least the information contained in the display message (MV).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] This patent application claims priority to Italian Patent Application No. 102022000010823, filed May 24, 2022, the entire disclosure of which is incorporated herein by reference.

[0002] The present invention relates to a control method for a control system for rail transportation equipment and a control system for rail transportation equipment.

[0003] As a result, the technical field of the invention is control systems for rail transport installations. [Background technology]

[0004] In particular, in rail transport installations comprising at least one central control post, also called central post, an operator monitors and / or drives and / or controls and / or acts on the control system. In the central control post, there is a graphic interface showing information, preferably all information, related to the rail network. Furthermore, the central control post has an input interface with a command device for receiving input commands from the operator.

[0005] The control system comprises at least one central unit, which manages the passage of trains on the railway network based on loaded instructions and commands from an operator at the central post. Furthermore, the control system comprises peripheral control posts staggered along the path of the track and / or near stations or transfer areas. All communications between the central unit, the peripheral control posts and the countryside or field devices controlled by the central unit must have a high level of security, in particular certified SIL 1 to SIL 4. Currently, the terminals communicating with the central unit, e.g. the peripheral post terminals, are expensive devices, as they are proprietary rather than commercial, which increases the cost of the control system.

[0006] One drawback of the prior art is that commercially available devices freely available on the market, known as Commercial Off the Shelf (COTS), e.g. commercial LCD monitors, tablets, palmtops, etc., usually cannot be connected to a central unit as they do not ensure the necessary SIL security requirements. Summary of the Invention [Problem to be solved by the invention]

[0007] Generally, one object of the present invention is to provide a control method for a control system of a railway transportation equipment which reduces the drawbacks of the prior art highlighted herein and which is, for example, simpler and / or more economical to manufacture while at the same time ensuring high reliability. [Means for solving the problem]

[0008] According to the present invention, there is provided a control method for a control system for railway transportation equipment, as set forth in claim 1.

[0009] Another object of the present invention is to provide a control system for rail transportation equipment that reduces the disadvantages of the prior art.

[0010] According to the present invention, there is provided a control system for railway transportation equipment as set forth in claim 16.

[0011] Using the present invention, commercially available terminals, for example commercially available LCD monitors, can be used at peripheral post stations, and also commercially available handheld terminals or tablets or palmtops can be given to wayside maintenance operators for their management, or to drivers who run trains that do not have screens or when all the information the driver needs cannot be displayed on the train's screen (e.g. very old trains). [Brief description of the drawings]

[0012] Further features and advantages of the present invention will become apparent from the following description of non-limiting embodiments, with reference to the accompanying drawings.

[0013] [Figure 1] FIG. 1 is a schematic diagram of a rail transport facility. [Diagram 2] FIG. 2 is a schematic diagram of the procedure of the control system for rail transportation equipment. [Diagram 3] FIG. 3 is a diagram of a terminal of the control system. [Figure 4] Figure 4 shows the screen of the control system terminal. [Diagram 5] FIG. 5 shows the procedure for encrypting a display message. [Figure 6] FIG. 6 shows a procedure for encrypting multiple display messages. [Figure 7] FIG. 7 shows a procedure for displaying multiple messages to multiple terminals. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0014] With reference to Figure 1, reference numeral 1 denotes a rail transport facility comprising a rail network 2 comprising tracks 3 extending along a number of routes P, passenger or freight stations (not shown), and trains moving along the rail network.

[0015] Throughout this description, the term "railroad" also means "streetcar". As a consequence, "railroad system" also means "streetcar system", "rail transport facility" also means "streetcar transport facility" and "train" also means "streetcar".

[0016] In one optional non-limiting embodiment of the present invention, line 3 is divided into multiple sections of line 3, particularly from a logic and control perspective.

[0017] The rail transport installation 1 comprises a control system 10 configured to activate and control a rail network 2, in particular the operation of trains along the rail network 2 being activated and controlled by the control system 10. Furthermore, the rail network 2 comprises countryside devices or field devices.

[0018] The control system 10 comprises at least one central computerized device 100 configured to control the railway network 2, in particular to control the operation of trains on the railway network 2, and which is monitored and / or driven and / or controlled and / or acted upon by an operator.

[0019] In one embodiment, the control system 10 includes multiple central units 100, particularly for redundancy and / or disaster recovery capabilities.

[0020] In one optional, non-limiting embodiment, the control system 10 comprises multiple devices 100 defining a distributed system, ie, several devices 100 that are geographically distributed.

[0021] The central device 100 comprises a graphic interface 101 which shows information relating to the railway network, in particular information selected from the group comprising the occupancy of each section of track 3 by each train 5, the sections of track 3 on which trains are permitted to travel and the sections of track 3 on which trains are prohibited to travel, the status of countryside or field devices of the railway network 2 and / or information on the coding of the track circuits and / or freedom and travel indications on the routes assigned to trains.

[0022] "Countryside or field device" means any device selected from the group of devices including light signal devices, switch actuators, switch stops, foot switches, track circuits, crossing barriers, and pickets. In all cases, the list of countryside or field devices is not to be considered as limiting.

[0023] Additionally, the apparatus 100 includes an input user interface 102 that includes a command device for receiving input commands from an operator located at a central control post.

[0024] In an alternative embodiment, the graphic interface 101 and the input user interface 102 may be implemented from a single device, for example via a touch screen.

[0025] The central unit 100 comprises at least one data processing assembly 104. The processing assembly 104 is secure.

[0026] In particular, the processing assembly 104 has a secure and redundant architecture.

[0027] In one optional non-limiting embodiment, the secure processing assembly 104 is a 2on2 (2oo2) architecture.

[0028] In one optional, non-limiting architecture, the central unit 100 comprises at least two processing assemblies 104, in particular secure processing assemblies.

[0029] In one optional, non-limiting version, the processing assembly 104 preferably comprises at least two identical processing units 104a and 104b, which preferably communicate with each other. In some optional cases, there are three or more identical processing units.

[0030] In particular, in one optional, non-limiting embodiment, each input to the processing assembly 104 is processed, preferably simultaneously, by at least two processing units 104a and 104b. In other words, each input is duplicated and each copy of this input is given as input to at least two processing units 104a and 104b, preferably in the same time interval. The output of each processing unit 104a and 104b is verified by the processing assembly 104 to control whether the data received by the output of each processing unit 104a and 104b in the same time interval coincide with each other, and if so, the processing assembly 104 provides as output the data received by one of the two inputs. If the outputs of the at least two processing units 104a and 104b do not coincide, the processing assembly 104 issues an error signal and disables the operation of the railway network 3 and safely stops the trains moving thereon, in particular according to a predetermined procedure.

[0031] In one embodiment, at least two identical processing units 104a and 104b communicate with each other, each processing unit 104a and 104b receives an output from the other processing unit 104b and 104a, each processing unit 104a and 104b checks that its output is equal to the output of the other processing unit 104b and 104a in the same time interval, and if they are equal, the processing assembly 104 or at least one of the at least two processing units 104 and 104b provides processed data as output, and if they are not equal, issues an error signal, disabling operation of the railway network 2 and safely stopping trains moving on the railway network, in particular according to a predetermined procedure.

[0032] In another alternative embodiment to the previous optional non-limiting embodiment of the invention, the processing assembly 104 comprises a comparison module 104c connected to the at least two processing units 104a and 104b to receive the outputs of the at least two processing units 104a and 104b. The outputs of each processing unit 104a and 104b are verified by the comparison module 104c to check whether the data received by the outputs of each processing unit 104a and 104b match each other in the same time interval, and in case of match, the processing assembly 104 provides as output the data received by at least one of the two inputs. If the outputs of the at least two processing units 104a and 104b do not match, the comparison module 104c issues an error signal and disables the operation of the railway network 2, and safely stops trains moving on the railway network, in particular according to a predetermined procedure.

[0033] Furthermore, in a preferred embodiment, the processing assembly 104 comprises an inherently secure monitoring block 104d, called a "watchdog", which communicates with the at least two processing units 104a and 104b and checks the correct operation of said at least two processing units 104a and 104b. If the monitoring block 104d determines a malfunction of at least one of the at least two processing units 104a and 104b, it issues an error signal and the processing assembly 104 disables the operation of the rail network 2 and safely stops the trains moving thereon, in particular according to a predefined procedure.

[0034] In particular, the monitoring block 104d is configured to detect one or more malfunctions selected from a group of malfunctions, namely, a stall of at least one of the at least two processing units 104a and / or 104b, an infinite calculation cycle, or other malfunction causing an inaccurate result of at least one of the at least two processing units 104a and / or 104b.

[0035] In an alternative embodiment, the monitoring block 104d is omitted and each processing unit 104a and 104b monitors at least one other processing unit 104a and 104b to detect one or more malfunctions selected from the group of: abnormal operation of at least one of the at least two processing units 104a and / or 104b, infinite calculation cycles, or other malfunctions causing inaccurate results of at least one of the at least two processing units 104a and / or 104b. If at least one of the at least two processing units 104b and 104a detects a malfunction, it issues an error signal and the processing assembly 104 disables the operation of the rail network and safely stops all trains moving thereon, in particular according to a predetermined procedure.

[0036] Furthermore, in one embodiment, the processing assembly 104 comprises at least one local communication network (not shown), and the at least two processing units 104a and 104b are coupled to each other via this local communication network.

[0037] In embodiments including a comparison module 104c, the comparison module 104c is communicatively coupled to the at least two processing units 104a and 104b via a local communications network.

[0038] In embodiments including a monitor block 104d, the monitor block 104d is communicatively coupled to the at least two processing units 104a and 104b via a local communications network.

[0039] Additionally, the apparatus 100, and in particular the processing assembly 104, includes a memory 104e.

[0040] In particular, the memory 104e is communicatively coupled to the at least two processing units 104a and 104b via a local communication network.

[0041] Furthermore, the processing assembly 104 comprises a communication module 104f connected to a local communication network and connected to the processing units 104a and 104b via the communication network for exchanging data with the outside of the processing assembly 104.

[0042] In one optional, non-limiting embodiment, each processing unit 104a and 104b implements or comprises a communications module.

[0043] In one embodiment, the memory 104e of the processing assembly 104 can be loaded with a set of instructions for managing a rail network by connecting an external device. In an alternative embodiment, the instructions can be loaded remotely into the memory 104e via the communication module 104f.

[0044] In an alternative embodiment, the processing assembly 104 comprises at least two identical memories (not shown in the accompanying figures), one for each processing unit 104a and / or 104b, and the at least two memories are loaded with the same data, and in particular with the same set of instructions for managing the railway network.

[0045] The secure processing assembly 104 manages the traffic of trains on the rail network based on instructions loaded in the memory 104e and / or commands received from the input interface 102 and / or data received via the communication module 104f.

[0046] The processing assembly 104 manages the vital tasks and information of the rail network 2, in particular those tasks and information that may have an impact on safety.

[0047] The device 100 ensures proper management of train operations, ensuring that only one train is on a particular section of track and that other trains are prevented from passing.

[0048] The apparatus 100, and in particular the processing assembly 104, ensures this functionality and has as input instructions in a memory (also called railway logic to be executed) and / or the state of countryside or field devices and / or commands at the input interface 102, and provides outputs to the countryside or field devices of the railway network 2, or more generally to the components of the railway network 2, preferably all components of the railway network 2.

[0049] In a preferred embodiment, the device 100 comprises a non-vital processing assembly 105 and a non-vital communication module 106 for managing non-vital tasks and information, ie tasks and information that do not impact safety.

[0050] The control system 10 comprises a communication network assembly 200. The communication network assembly 200 is preferably different from the local communication network defined above.

[0051] In particular, the communication network assembly 200 comprises a vital network 201 and / or a non-vital network 202, preferably of the Ethernet and / or wired type.

[0052] In particular, in one preferred but non-limiting embodiment, the communication network assembly 200 comprises a normal network and a redundant network.

[0053] In particular, networks that enable connections and communications between vital devices, i.e. devices that contribute to the implementation of functions that may affect the safety of operators or people using rail transport equipment, are defined as vital networks.

[0054] In general, a vital function of control system 10 is a function that may affect the safety of an operator or people using or coming into contact with rail transportation equipment 1 .

[0055] Additionally, in one particularly optional non-limiting embodiment, the communication network assembly comprises at least one commercial wireless communication network 210 .

[0056] As non-limiting examples, the wireless communication network 210 may be WI-FI and / or WI-FI MAX and / or GSM and / or GSM-R and / or TETRA and / or LTE and / or GPRS and / or UMTS and / or EDGE.

[0057] In a preferred but non-limiting embodiment, wireless communication network 210 is preferably connected in series with vital network 201 and / or non-vital network 202, and is preferably connected to device 100 via vital network 201 and / or non-vital network 202.

[0058] In another optional non-limiting embodiment, wireless communication network 210 is preferably connected in parallel to vital network 201 and / or non-vital network 202, and preferably wireless communication network 210 is connected to device 100 without using vital network 201 and / or non-vital network 202.

[0059] The control system 10 comprises at least one terminal 300, in particular a commercially available terminal freely available on the market, in particular a terminal of the commercial off-the-shelf type, also called COTS.

[0060] In one embodiment, the terminal 300 is, for example, a fixed terminal connected to a commercially available screen, such as an LCD screen or a plasma screen, and a commercially available keyboard and / or touch screen.

[0061] In another embodiment, the terminal 300 is a commercially available mobile terminal, for example a tablet or a palmtop, in particular small enough to be held in the hand (in English called a hand-held terminal).

[0062] In particular, the terminal 300 is communicatively coupled to the device 100 via the communication network assembly 200 .

[0063] When the terminal 300 is mobile, the terminal 300 is preferably communicatively coupled to a wireless network 210 .

[0064] When the terminal 300 is fixed, the terminal 300 is preferably communicatively coupled to the vital network 201 and / or the non-vital network 202 and / or the wireless network 210 .

[0065] The terminal 300 comprises a screen 301 for displaying information and an input user interface 302, for example a keyboard, to enable an operator to enter commands or instructions and generally to transmit data.

[0066] In one embodiment, the screen 301 and the input user interface 302 are defined by a single device, for example a touch screen.

[0067] The terminal 300 and the device 100 communicate with each other via a communication network assembly 200 .

[0068] The terminal 300 is configured to receive a first command from an operator via the input interface 302 and to transmit the first command to the device 100, which is configured to execute the first command.

[0069] The first command is preferably a vital command, in particular a type of command that affects a vital function of the control system 10. In other words, the first command is a command that affects a function that may affect the safety of operators or people using or in the vicinity of the rail transportation equipment 1.

[0070] Furthermore, the device 100 is adapted to send to the terminal 300 at least one display message MV containing information to be shown to the operator via the screen 301 .

[0071] In a preferred, but non-limiting embodiment of the present invention, the terminal 300 receives a second command from the operator, the second command including a command, preferably different from the first command, relating to the operation of any one of the countryside devices or field devices defined above.

[0072] The terminal 300 transmits these second commands to the apparatus 100, which operates the countryside or field devices.

[0073] Furthermore, the control system 10 authenticates different operators with different activation codes and enables a specific first or second command based on the activation code used. In other words, the device 100 contains different activation codes in memory to enable different operators. When an operator wants to start an operation, he must insert the activation code into the terminal 300 to log on. The device 100 selectively enables the request of a specific first or second command via the terminal 300 based on the activation code used by the operator to log on.

[0074] In a preferred embodiment, the display message MV received by the terminal 300 contains information relating to the status of the activated countryside or field device and preferably the status of other countryside or field devices of the rail network. The terminal 300 then displays on the screen 301 one or more graphic symbols indicating the information of the display message, in particular the status of the activated countryside or field device and preferably the status of other countryside or field devices of the rail network.

[0075] In one optional non-limiting embodiment of the present invention, the control system 10 is configured such that the execution of the first command is performed only if there is another operator, preferably an operator at a central post or an operator at a peripheral post different from the maintenance operator, who is able to execute the first command. In this embodiment, after receiving the first command from the terminal, the device 100 asks the other operator to enable the execution of the first command before executing the first command. In particular, the device 100 sends an enablement request to the other operator via the input interface 102 of the device 100 and waits to receive a third command via the user interface for enabling the execution of the first command via the user interface of the device 100. The device 100 is configured to execute the first command only after being enabled to execute the first command, in particular via the third command.

[0076] In a preferred embodiment of the present invention, the sending of the first command is performed in the following procedure: the operator inputs, via the input user interface 302 of the terminal 300, a first instruction I specifying the action to be taken. 1 The device 100 transmits a first command I 1 and a first command I transmitted by the terminal 300 to the device 100. 1 and a second instruction I including the code C generated by the device 100. 2 to the terminal 300, preferably the code C being composed of a number of numbers and / or letters and / or letters and / or symbols and / or figures, in particular generated randomly. Furthermore, the terminal 300 transmits the received second command I 2 The operator displays the received code C and the received first command I again if the first command sent initially matches the first command received. 1 The device 100 transmits the first command I 1 and the first command I received the second time 1and whether the transmitted code C generated by the device 100 and the code C received by the device 100 match. If the check is successful, the device 100 activates the first command and, preferably, the device 100 transmits on the screen 302 of the terminal 300 a confirmation that the first command has been executed.

[0077] One of the functions performed by the control system 10 is the management of the request or release of so-called occupation zones in order to define maintenance areas. More specifically, when maintenance work needs to be carried out on the railway network 2, it is necessary to delimit the maintenance area, i.e. the area in which personnel have to carry out their work and in which train operations must therefore be temporarily excluded.

[0078] Consequently, the terms "occupied zone" or "occupied area", or "maintenance zone" or "maintenance area", refer to areas of a rail network where train operations are temporarily prohibited.

[0079] In other words, an occupied zone consists of one or more portions of track, even if non-contiguous, over which train operations are prohibited for the time period requested by the operator, and therefore from the time the operator makes an occupied zone request until the time the operator makes an occupied zone release request, and preferably only one authorized operator can perform certain actions.

[0080] The terminal 300, in particular when it is mobile, is used to define the occupation zone. In this embodiment, the first command comprises a request or release of an occupation zone, i.e. information indicating the area of ​​the railway network 2 in which the operation of trains is prohibited or allowed (request or release of occupation zone). As a result, the device 100, when receiving a request or release of an occupation zone, prohibits or allows the operation of trains in the area identified by the first command. In this embodiment, the display message MV comprises an indication of the status of the occupation zone, i.e. an indication of the area in which the operation of trains is prohibited or allowed, and preferably an indication of the status of at least one other area of ​​the railway network, so that the terminal 300 shows, via a graphic display, on the screen 301, the status of the activated or released occupation zone, i.e. the status of the area in which the operation of trains is prohibited or allowed, and preferably the status of at least one other area of ​​the railway network. In particular, it shows the status of the area in which the operation of trains is prohibited or allowed in a first color and the status of the at least one other area of ​​the railway network in a second color or by other graphic means (Fig. 4).

[0081] Furthermore, when the device 100 receives a first command from the terminal 300 requesting the release of the occupied zone, it checks whether the terminal 300 that sent the command to release the occupied zone is the same terminal 300 that sent the activation of the occupied zone, and releases the occupied zone only if this check is successful.

[0082] In particular, the device 100 stores the requested occupancy zone when it is requested and associates it with the identification code of the terminal 300 which requested it.

[0083] In particular, the device 100 therefore has in its memory a list of each occupied zone that is currently activated and, for each activated occupied zone, an identification code associated with the terminal 300 that requested it.

[0084] When the device 100 receives a first command from the terminal 300 requesting the release of an occupied zone, it checks whether the terminal 300 from which the request to release the occupied zone was sent has the same identification code present in its memory associated with the occupied zone that is requested to be released, and if this check is successful, the device 100 releases the occupied zone.

[0085] In this way, it is possible to prevent an operator other than the one who requested the occupied zone from releasing this occupied zone, thus improving the safety of the operators working in the occupied zone.

[0086] Furthermore, in a preferred embodiment, the control system 10 is configured in such a way that when a particular mobile terminal 300 requests an occupation zone through a first command, it is possible for that mobile terminal 300 to request a second command relating only to field devices or systems located within that occupation zone. In other words, when the device 100 receives a second command from the terminal 300, it checks whether this second command relates to countryside devices or field devices located within the occupation zone requested by that terminal, and only if so, the device 100 executes this second command.

[0087] If the terminal 300 is mobile, in one optional non-limiting embodiment of the present invention, the control system 10 includes a locator device 303 for determining the location of the terminal 300. The locator device is preferably a satellite locator device of the terminal 300. Alternatively, the terminal 300 includes an RFID that communicates its location to the locator device 303 of the control system.

[0088] The control system 10 detects the operator's position via the locator device 303 and defines, based on the detected position, a display message MV to be sent to the terminal 300, in particular the information contained in the display message MV is specific to an area defined by the perimeters of the detected position, these perimeters can preferably be set, for example the perimeters define an area extending 15 km, 10 km, 5 km or 3 km around the detected position. In other words, the terminal 300 displays on its screen the area around the detected position and / or the information related to the countryside or field devices in that area. In an optional embodiment, the control system 10 checks whether the first and / or second command received from the terminal is related to its area and allows the execution of said first and / or second command only if the check is successful.

[0089] For example, if the first command is to request or release an occupied zone, the control system 10, and in particular the device 100, checks whether the occupied zone is within the area before activating it.

[0090] The control system 10 includes the step of causing the terminal 300, or a part thereof, to perform at least one diagnostic test or part of a diagnostic test to periodically check the correct operation of the terminal 300.

[0091] In a preferred embodiment, the terminal 300 periodically checks the correct operation of at least one of the terminal components selected from the group of terminal components: video memory, RAM, terminal software, terminal hardware or communication block. In particular, the terminal periodically executes at least one diagnostic test selected from the group of diagnostic tests: SW and data diversity check, forced video refresh, video memory runtime test, graphics library runtime / offline test, control flow check, state checksum or vitality. The terminal 300 transmits the results of the checks, in particular the results of the at least one diagnostic test, to the device 100. If the check of the correct operation of the terminal is not successful, in particular if at least one diagnostic test is not successful, an error message is displayed on the terminal 300 or the operation of the terminal 300 is disabled.

[0092] In particular, the terminal 300 itself may cause an error message to be displayed or the device 100 may send an error message to the terminal 300 and / or disable operation of the terminal 300 .

[0093] In one embodiment, the transmission of the display message MV is made in encrypted form, in particular the display message is encrypted based on a first encryption procedure, thus obtaining a first encrypted display message 1MVC, preferably the first encryption procedure being performed by the device 100. In this embodiment, the terminal 300 receives the first encrypted message 1MVC and performs a procedure for decrypting the first encrypted display message 1MVC according to the first encryption procedure, in particular the procedure for decrypting the first encrypted display message 1MVC being performed by a processing unit of the terminal 300. The terminal 300 checks whether the decryption of the first encrypted display message 1MVC is successful and allows the display of the display message on the screen 301 only if the decryption of the first display message 1MVC is successful. In particular the decryption step of the first display message 1MVC and the checking of the result of the decryption step are performed by the terminal 300.

[0094] In particular, with reference to Fig. 5, the first encryption procedure includes a first sub-step of encrypting the display message MV with the message private key KPR, preferably via a symmetric encryption procedure, in particular via the AES (Advanced Encryption Standard) protocol, to obtain a first encrypted display message 1MVC, a second step of encrypting the message private key with the public key KPB associated with the terminal 300, preferably via an asymmetric encryption procedure, in particular via the RSA protocol, and a step of transmitting the encrypted private key KPB[KP] together with the first encrypted display message 1MVC. The procedure of decrypting the first encrypted display message 1MVC preferably includes a first step of decrypting the encrypted private key KPB[KP] of the message with the private key KPT associated with the terminal, and a second step of decrypting the first encrypted display message 1MVC with the decrypted message private key KPR.

[0095] Encrypting the private key with the public key of the terminal 300 also makes it possible to ensure that the message can only be decrypted by the terminal 300 for which it was created, thus avoiding it being decrypted by another terminal 300 to which it was mistakenly delivered (in the case of an embodiment in which there are multiple terminals 300). Using this mechanism it is ensured that a terminal 300 will only display a display message MV prepared and sent for this terminal 300, increasing the reliability of the displayed image.

[0096] In one embodiment in which the control system 10 has only one terminal 300, in an optional, non-limiting embodiment, the step of encrypting the private key KPR with the public key KPB and the next step of decrypting the private key encrypted with the public key KPB[KPR] may be omitted.

[0097] In a preferred embodiment, with reference to FIG. 6, the device 100 transmits display messages MV to the terminal 300 in order to update the information displayed on the screen 301 of the terminal 300, in particular to update the status and / or other vital information of the countryside or field devices displayed on the screen 301. 1 ~Mvn n In this embodiment, the first encryption substep periodically transmits different messages MV 1 ~Mvn n private key KPR 1 ~KPR n and periodically creating each display message MV 1 ~Mvn n The corresponding message private key KPR 1 ~KPR n and therefore the corresponding message 1 ~KPR n The corresponding encrypted display message MV 1 ~Mvn n The first encrypted display message obtained by 1MVC 1 ~1MVC n and periodically creating a

[0098] The device 100 generates each first encrypted display message 1MVC 1 ~1MVC n About the first encrypted display message 1MVC 1 ~1MVC n and the corresponding message private key KPR 1 ~KPR n is periodically transmitted to the terminal 300.

[0099] The terminal 300 receives each first encrypted display message 1MVC i , the received corresponding message private key KPR i The terminal 300 performs a decryption procedure via each first encrypted display message 1MVC i Check whether decryption is successful for the corresponding message private key KPR iFirst encrypted display message using 1MVC i Until the decryption of Mv is successful, the display on the screen of the terminal 300 is updated with the updated display message Mv i Preferably, each first encrypted display message is updated with 1MVC i The decoding step is performed by the corresponding terminal 300. i According to the invention, each display message MV i Different message secret keys KPR i Considering that the data is encrypted with , it is certain that the screen 301 of the terminal 300 is constantly updated.

[0100] In a preferred embodiment, the control system 10 includes a plurality of terminals 300 communicatively coupled to the device 100. 1 ~300 m In particular, the plurality of terminals 300 1 ~300 m One or some or all of the terminals 300 are mobile terminals. 1 ~300 m Each terminal 300 i The other terminal 300 1 ~300 m Public key of KPB 1 ~KPB m The corresponding public key KPB is different from i and each terminal 300 i is its public key, KPB i and the private key KPT of the terminal 300 associated with i is stored in memory.

[0101] The device 100 stores, in particular in the memory 104e, 1 ~300 m Public key of KPB 1 ~KPB m In particular, the device 100 stores the 1 ~300 m Display message MV 1 1 ~MV n mIn particular, each terminal 300 i The terminal 300 i 300 other terminals r A display message MV is sent periodically to 1 r ~Mv n r A display message MV that may be different or equal to 1 i ~MV n i However, terminal 300 i It is transmitted periodically for

[0102] In this embodiment, the first encryption procedure is performed by each terminal 300. i Regarding each terminal 300 i Each display message MV for i i but preferably via an asymmetric encryption procedure, in particular via the AES (Advanced Encryption Standard) protocol, to obtain the corresponding private key KPR i i Then, the corresponding message is encrypted using the private key KPR i i However, preferably via an asymmetric encryption procedure, in particular via the RSA protocol, each terminal 300 i The public key KPB associated with i It is encrypted using

[0103] Furthermore, the control system 10, and in particular the devices 100, each store a respective encrypted private key KPB i [KPR] i , the corresponding first encrypted display message 1MVC i i At the same time, each terminal 300 i periodically.

[0104] Each encrypted display message is 1MVC i i The procedure for decrypting the message preferably involves using the corresponding encrypted private key KPB i [KPRi ] to terminal 300 i The private key KPT associated with i The first step is to decrypt and display the first encrypted message in 1MVC i i The encrypted message is stored as a private key KPR. i i and therefore the message MV i i By using the present invention, each terminal 300 i Display message displayed on MV i i is constantly updated, and each terminal 300 i and ensures that there were no errors in the delivery of the display message.

[0105] Furthermore, in a preferred embodiment, the terminal 300 is adapted to perform at least one diagnostic test. i If the above steps for checking the correct operation of MV are not successful, a corresponding display message MV i i The corresponding message private key Kpr i i , preferably the corresponding encrypted private key KPB i [KPR i ], the terminal 300 i In particular, the device 100 disables the operation of the terminal 300. i If at least one diagnostic test fails, the corresponding message secret key Kpr i i , preferably an encrypted message and a private key KPB i [KPR i ] to terminal 300 i to stop transmitting to

[0106] In one optional, non-limiting embodiment, terminal 300 1 ~300 m A display message MV is sent at the nth time intervali 1 ~MV i m In this embodiment, the secret key Kpr i 1 ~Kpr i m are equal.

[0107] In a preferred embodiment, the display message MV traverses a wireless communication network 210 during transmission from the device 100 to the terminal 300, which in a preferred embodiment uses a transmission protocol with data encryption, for example one or more of the following networks: WI-FI with password, WI-FI MAX with password, GSM, GSM-R, TETRA, UMTS, LTE, GPRS, EDGE, etc. In this case, each first encrypted display message 1MVC is encrypted by a second encryption procedure defined based on the type of wireless communication network 210 and / or part thereof, in order to meet the encryption requirements of the communication protocol of the wireless communication network 210 coupling the terminal 300 to the device 100. In this embodiment, when the second encrypted display message arrives at the mobile terminal 300, a procedure of decrypting the second encrypted display message is performed according to the second encryption procedure, thus obtaining the first encrypted display message 1MVC. In a preferred embodiment, the procedure of decrypting the second encrypted display message is executed by a communication module of the terminal 300.

[0108] Furthermore, in a preferred embodiment, the terminal 300 transmits the first command and / or the second command to the vital signs processing assembly 104 and receives the display message MV from the vital signs processing assembly 104 .

[0109] Furthermore, the terminal 300 exchanges non-vital data with the non-vital processing assembly 105, preferably without performing the encryption described for the display message MV.

[0110] Furthermore, the control system 10 comprises a number of peripheral control posts, not shown, each of which is arranged in a staggered manner along the path of the track or in the vicinity of a station or preferably in the vicinity of a transfer area with a peripheral operator station. The terminal 300 may be a terminal of the peripheral control post showing information of an area of ​​the railway network to an operator of the peripheral control post. For example, through a screen 301 of the terminal 300, the operator of the peripheral post can see the state of the railway network adjacent to his peripheral control post. Furthermore, through the terminal 300, the operator can see the state of the railway network 3, preferably the state of a part of the railway network 3 adjacent to his peripheral control post.

[0111] As mentioned above, the advantage of using the mobile terminal 300 is to manage the occupation zones in order to carry out the maintenance of the countryside or field devices and / or the subsystems of the central and peripheral posts. The system thus allows different operators to carry out the management of the maintenance area through the corresponding mobile terminal 300 and to operate locally for the maintenance of the components of the control system 10 directly through the applications present on the terminal provided. Furthermore, through the mobile terminal 300 the operator is able to send commands for taking possession of the maintenance area and, more generally, to have a mobile command post from which it is possible to send specific commands for the diagnosis and monitoring of the countryside or field devices. This solution does not require special associated security requirements (open network) and allows the use of existing or new network infrastructures.

[0112] An operator can request management of an occupied zone via the mobile terminal 300 and, after confirmation, proceed with the specific operation. Similarly, release of an occupied zone can be requested and confirmed by the device 100. In particular, release of an occupied zone can only be requested via the terminal 300 that requested the management.

[0113] In general, when the terminal 300 is equipped with a touch screen, the terminal 300 can be used as a tool to send and receive commands through the ability of an operator to directly select objects represented on the terminal, and in particular on the touch screen of the terminal, and send commands in a simple and intuitive manner.

[0114] The control system 10 allows to place configured commands and to support the operator for graphic selection of countryside or field devices. In the terminal 300, especially in a mobile terminal, the second command may be a diagnostic controller command for the components of the peripheral post equipment (supply diagnostics, area controller, device controller, cable insulation check, fan diagnostics). This tool allows to operate locally by sending diagnostic commands through the mobile terminal to perform specific operations. This application allows to reduce recovery times, since maintenance operations can be managed all locally near the field device or system (without the need to communicate with the cabin). On the terminal, it is also possible to monitor the status of the system alarms in real time, with the advantage that the status of the system can be immediately known during maintenance / repair operations. This allows to display alarms in the immediate vicinity of the equipment to be maintained, thus reducing the time required for problem solving and recovery.

[0115] There are additional advantages both in terms of sharing the responsibilities of different departments on the same line and in terms of safety: for example, only maintenance workers who are physically present on site operate the switches, reducing the risks of remote communication and therefore the possibility of endangering people on site by operating them from the cabin.

[0116] In another embodiment, for example when operating a train without a screen or when not all the information the train driver needs is displayed on the train's screen (e.g. a very old train), the mobile terminal 300 can be handed over to the train driver on board the train. In this case, the train driver can receive from the mobile terminal 300 all the updated information related to the part of the rail network 2 on which he is travelling. In this case, an embodiment with a satellite locator device, in which the apparatus 100 processes the display messages MV sent to the terminal 300, including based on the position detected by the terminal 300, can be very useful. To this end, in an optional non-limiting embodiment, the mobile terminal 300 is preferably only used to display the display messages MV and not to execute the first and second commands.

[0117] Finally, it will be apparent that modifications and variations can be made to the apparatus and methods described herein without departing from the scope of the invention as set forth in the appended claims.

Claims

1. A method for controlling a control system of a rail transport installation (1), said control system (10) preferably comprising an apparatus (100) configured for controlling a rail network (2), in particular for controlling the operation of trains on said rail network (2), said apparatus being preferably of the safety and / or vitals type, and a terminal (300), preferably of the mobile or fixed type, said terminal (300) being preferably communicatively coupled to said apparatus (100), The method comprises the following steps: - receiving, by said terminal (300), a first, preferably vital, command from an operator; - executing said first command; - sending at least a display message (MV) containing information for said operator to said terminal (300), said terminal (300) preferably receiving said display message from said device (100); displaying, on a screen (301) of said terminal (300), a screen showing said information of said at least one display message (MV), in particular said information contained in said display message (MV); - receiving, preferably from said terminal (300), a second command comprising a command for the activation of at least one countryside or field device of said rail network (2) and operating said countryside or field device, preferably said at least one countryside or field device being selected from the group of countryside or field devices comprising: light signalling devices, switch actuators, switch stops, foot switches, track circuits, railroad crossing barriers, pickets; - preferably said display message (MV) contains information relating to the status of the at least one operated countryside or field device and preferably to the status of other countryside or field devices of the rail network (2), preferably displaying on the screen (301) of the terminal (300) one or more graphic symbols indicating said information of said display message (MV), in particular one or more graphic symbols indicating the status of the operated countryside or field device and preferably to the status of other countryside or field devices of the rail network (2); A control method comprising:

2. said first command comprises a request for an occupation zone, in particular a request indicating an area of ​​the railway network in which train operation is to be prohibited or permitted, in particular said area of ​​the railway network comprising at least a part of at least a track of the railway network in which train operation is to be prohibited or permitted, said step of executing said first command comprises activating or releasing said occupation zone, in particular prohibiting or enabling the operation of trains in said area identified by said first command, the information intended for the operator contained in the display message (MV) comprises an indication of the status of the occupied zone, in particular of the areas in which train operations are prohibited or allowed, and preferably of the status of at least one other area of ​​the railway network, - displaying the information of the display message (MV) on the screen (301) of the terminal (300) comprises showing on the screen (301) by means of a graphical representation the status of the activated or released occupation zones, in particular the status of the areas in which train operations are prohibited or allowed, and preferably the status of at least one other area of ​​the railway network (2), The control method according to claim 1

3. 3. The control method according to claim 2, wherein the first command is a command requesting the release of an occupied zone, the method comprising the steps of checking whether the terminal (300) from which the command to release an occupied zone is sent is the same terminal (300) from which the activation of the occupied zone is received, and releasing the occupied zone only if this check is successful.

4. 4. The method according to claim 2 or 3, wherein the first command is a command to activate an occupation zone from the terminal (300), the method comprising the steps of receiving at least a second command relating to the operation of a countryside device or a field device, and checking whether the at least second command relates to a countryside device or a field device located within the occupation zone, and the method comprising the steps of executing the at least second command only if the check is successful.

5. Periodically performing the check of correct operation of the terminal (300) by executing at least diagnostic tests, in particular periodically checking the correct operation of at least one of the terminal components selected from the group of terminal components: video memory, RAM, terminal software, terminal hardware, communication block, and in particular periodically performing at least diagnostic tests selected from the group of diagnostic tests: SW and data diversity check, forced video refresh, video memory runtime test, offline / runtime graphics library test, checkflow check, state checksum, vitality, the method providing an error message to the terminal (300) if the check of correct operation of the terminal (300) fails, in particular if one or more of the diagnostic tests fail. or disabling the operation of the terminal (300), preferably sending an alarm message to trains circulating in an area around the terminal (300), in particular an area defined by a radius of a preferably configurable first value, to limit the speed of the train or to stop the operation of the train, in particular periodically sending the result of the diagnostic test to the device (100), preferably the device (100) monitoring the result of the diagnostic test and, in case of incorrect operation of the terminal (300), sending an error message to the terminal (300) or disabling the operation of the terminal (300), preferably sending the alarm message to the trains circulating in the area around the terminal (300).

6. The method comprises the steps of encrypting said display message (MV) according to a first encryption procedure, preferably using a respective private key (KPR), to obtain a first encrypted display message (1MVC), and transmitting the respective private key (KPR), preferably the first encryption procedure being performed by said device (100), preferably the method comprises the step of providing a second encrypted display message by applying a second encryption procedure to said first encrypted display message (1MVC) in order to meet the communication protocol requirements of a communication network assembly (200) and / or parts thereof coupling said terminal (300) to said device (100), in particular when said communication network assembly (200) is connected to at least one communication network (210) of commercial type, preferably WiFi with password, ... MAX, GSM, GSM-R, TETRA, UMTS, LTE, GPRS, EDGE, preferably said second encryption procedure is defined according to the type of communication network assembly (200) and / or part thereof, preferably said second encryption procedure is performed by a communication module (104f) of said device (100).

7. Preferably, the method includes a step of performing a procedure for decrypting the second encrypted display message according to the second encryption procedure, thereby obtaining a first encrypted display message (1MVC), preferably the step of decrypting the second encrypted display message is performed by a communication module (104f) of the terminal (104), the method further comprising the steps of performing a decryption procedure of the first encrypted display message (1MVC) according to the first encryption procedure, preferably after receiving the respective private keys (KPR), using the respective private keys, preferably the step of decrypting the first encrypted display message (1MVC) according to the first encryption procedure, 7. The method according to claim 6, further comprising the steps of: the decryption procedure of the first encrypted display message (1MVC) being executed by a terminal processing unit (300); checking whether the decryption of the first encrypted display message (1MVC) is successful; and displaying the display message on the screen (301) of the terminal (300) if the decryption of the first encrypted display message (1MVC) is successful, and preferably the steps of decrypting the first encrypted display message (1MVC) and checking the result of the decryption step are executed by the terminal (100).

8. The first encryption procedure is preferably carried out by a symmetric encryption procedure, in particular AES (Advanced Encryption Standards Track [AES]).

8. The method according to claim 6 or 7, comprising a first sub-step of encrypting the display message (MV) with a message private key (KPR) according to the Standard protocol to obtain the first encrypted display message (1MVC), and a second sub-step of preferably encrypting the message private key (KPR) with a public key (KPB) associated with the terminal (300), preferably by an asymmetric encryption procedure, in particular by the RSA protocol, and transmitting the preferably encrypted private key (KPB[KPR]) together with the first encrypted display message (1MVC), wherein the procedure of decrypting the first encrypted display message (1MVC) preferably comprises a first sub-step of decrypting the encrypted private key (KPB[KPR]) of the message with the private key (KPT) associated with the terminal (300), and a second sub-step of decrypting the first encrypted display message using the private key (KPR) of the decrypted message.

9. The control system (10) includes a plurality of terminals (300) including the terminal (300). 1 ~300 m ), in particular, one or more or all of the terminals of the plurality of terminals are mobile terminals, and preferably, the plurality of terminals (300 1 ~300 m ) is communicatively coupled to the device (100), and the plurality of terminals (300 1 ~300 m ) each terminal (300 i ) to each of the other terminals (300 r ) public keys (KPB r ) and each public key (KPB i ) and each terminal (300 i ) is stored in the database and used to create its public key (KPB i ) and the private key (KPT i ), and preferably, the method comprises: 1 ~300 m ) Display message (MV 1 1 ~M.V. n m ) addressed to each of the terminals (300), i i ) of the private key (KPR i During a second sub-step of encrypting the i ) associated with each of said public keys (KPB i ) and preferably each of said terminals (300 i The encrypted private key (KPB) of the display message (MV) of i [KPR i ]) to decode the i ) stored by the private key (KPT i 9. The method according to claim 8, further comprising the step of:

10. A display message (MV) is displayed on the terminal (300) to update the information displayed on the screen (301) of the terminal (300). 1 ~M.V. n ), wherein the encrypting step uses different message private keys (KPR n ) is created periodically and each display message (MV i ) to each message private key (KPR n ) and thus encrypts each of the messages with the respective message private keys (KPR n ) to generate a first encrypted display message (1MVC 1 ~1MVC n ), the method comprising the step of periodically creating each first encrypted representation message (1MVC i ) for the first encrypted display message (1MVC 1 ~1MVC n ) and the respective private keys (KPR i ) periodically transmitting Preferably, the method further comprises: i ) via the first encrypted display message (1MVC i ) and performing a decryption procedure on each first encrypted representation message (1MVC i 10. The method according to claim 6, further comprising the steps of: checking whether the decryption has been successful for each first encrypted display message (MV) of the first display message (MV) and displaying the display message (MV) on the screen (301) of the terminal (300) until the decryption of the first display message using the respective private key of the message is successful, preferably wherein the decryption step of each first encrypted display message is performed by the respective terminal (300), in particular by a processing unit of the terminal (300).

11. If the step of checking the correct operation of the terminal (300) by executing the at least one diagnostic test is unsuccessful, the disabling of the operation of the terminal (300) is preferably performed by decrypting the respective private message key (KPR) encrypted with the public key of the terminal so that the terminal (300) cannot decrypt the respective display message (MV). i 10. The method according to claim 5, wherein the method is performed by interrupting the transmission of

12. said step of transmitting said first command comprises a step of transmitting a first instruction (I1) specifying an operation to be performed, preferably an instruction for requesting or releasing an occupied zone, preferably receiving from said device (100) a second instruction (I2) comprising said transmitted first instruction (I1) and a code (C) preferably generated by said device (100), preferably said code (C) being formed by a plurality of numbers and / or alphabets and / or letters and / or symbols and / or figures, in particular randomly generated; preferably displaying said received second instruction on said terminal (300); preferably when said first instruction transmitted for the first time matches said received first instruction. The method according to any one of claims 1 to 11, further comprising the steps of: transmitting, preferably from the terminal (300) to the device (100), the received code (C) and again the received first command (I1); the method further comprising the steps of checking whether the first command, preferably received a first time from the device (100), preferably matches the first command, preferably received a second time from the device (100), and whether the code, preferably transmitted from the device (100), preferably matches the code received from the device (100); and, in case of a match, executing the first command, in particular the checking and / or the execution of the first command, are performed by the device (100).

13. 13. The method according to claim 12, wherein the operator inputs the first command (I1) on the terminal (300) via an input user interface (302) of the terminal (300), displays the received first command (I1) on a screen (301) of the terminal (300), preferably together with the code (C) received from the device (100), inputs the received code (C) and again the first command (I1) via the input user interface (302) of the terminal (300), and receives a confirmation on the screen (301) of the terminal (300) that the first command has been executed.

14. The method according to any one of claims 1 to 13, further comprising the steps of detecting the location of the operator, preferably by means of a location device (303), and defining the display message (MV) to be sent to the terminal (300) based on the detected location, in particular the information contained in the display message (MV) being specific to an area defined by a periphery of the detected location, preferably wherein the method comprises the step of checking whether the first command and / or the second command received from the terminal are related to said area and only allowing the execution of the first command and / or the second command if the check is successful.

15. The method according to any one of claims 1 to 14, wherein the terminal (300) is a commercially available mobile terminal, in particular a COTS (Commercial Off-The-Shelf) mobile terminal, preferably of a size such that it can be held in the hand, preferably a tablet, in particular of a commercially available type.

16. A control system for a rail transport system (1), said control system (10) preferably comprising an apparatus (100) configured for controlling a rail network (2), in particular for controlling the operation of trains on said rail network (2), said apparatus preferably being of the safety and / or vitals type, and a terminal (300), preferably of mobile or fixed type, said terminal (300) preferably being communicatively coupled to said apparatus (100), The control system (10) receiving, by said terminal (300), a first, preferably vital, command from an operator; Executing the first command; and sending at least one display message (MV) containing information for said operator to said terminal (300); displaying on a screen (301) of said terminal (300) a screen showing said information of said at least one display message (MV), in particular said information contained in said display message (MV); receiving, preferably from said terminal (300), a second command comprising a command for the operation of at least one field device or countryside device of said rail network (2), preferably said at least one field device or countryside device being selected from the group of field devices or countryside devices comprising: light signalling devices, switch actuators, switch stops, pedals, track circuits, railroad crossing barriers, pickets, and operating said field device or countryside device; Preferably, said at least one display message (MV) contains information about the state of said at least one operated field or countryside device and preferably about the state of other field or countryside devices of the railway network, and preferably displaying on a screen of said terminal (300) one or more graphic symbols showing said information of said display message (MV), in particular one or more graphic symbols showing the state of said operated countryside or field device and preferably about the state of other countryside or field devices of the railway network; A control system configured to:

17. A rail transport system comprising a control system according to claim 16 and a rail network (2), preferably a train.