Safety devices and vehicles

JP7927970B2Active Publication Date: 2026-10-01HITACHI LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2025500651
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-02-14
Filing Date
2023-10-31
Publication Date
2026-10-01
Estimated Expiration
2043-10-31

AI Technical Summary

Benefits of technology

【0015】 本発明によれば、要求される信頼性の異なるタスクを実行しても、それぞれのタスクに要求される信頼性を満たすことができる保安装置を提供することができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007927970000001
    Figure 0007927970000001
  • Figure 0007927970000002
    Figure 0007927970000002
  • Figure 0007927970000003
    Figure 0007927970000003
Patent Text Reader

Abstract

The purpose of the present invention is to provide a security device that even if tasks requiring high reliability and other tasks are processed in parallel using a single thread, can satisfy the reliability required for each task. To achieve this purpose, one representative security device of the present invention comprises a multitask execution unit that executes at least one task, and a multitask control unit that periodically carries out the monitoring, management, and control of one or a plurality of tasks. The multitask control unit includes a task information management unit that manages attribute information differing for each of the tasks, and stops output from the task, a task execution order control unit that controls the execution order of the tasks on the basis of priority managed by the task information management unit, and a task switching unit that performs a switching instruction of the tasks in accordance with a control command from the task execution order control unit.
Need to check novelty before this filing date? Find Prior Art

Description

[[Technical Field]]

[0001] The present invention relates to a security device and a vehicle. [[Background Art]]

[0002] A railway security device that performs safety management for vehicles, signals, and the like includes a control board mounted with an arithmetic processing device such as a CPU (Central Processing Unit), and integrates various functions.

[0003] A railway security device executes both a security function that requires high reliability (hereinafter referred to as a security task) and a non-security function that requires lower reliability compared to the security task (hereinafter referred to as a non-security task). Conventionally, since security tasks and non-security tasks require different levels of reliability, they are not executed by the same railway security device, but are processed using a plurality of independent devices. These devices are then integrated to realize a single railway security device.

[0004] However, since railway security devices also need to execute non-security tasks that require different levels of reliability, it has been necessary to separately prepare a device for executing non-security tasks.

[0005] On the other hand, in the case of general control devices, a multi-thread method is often adopted from the perspective of software design in order to improve the responsiveness of the device and the utilization efficiency of the CPU. In a device adopting the multi-thread method, processing that requires a long processing time and allows a slow response is executed in combination with processing that requires a short processing time and a fast response.

[0006] For example, as a technique for adopting a multi-thread method in a railway security device, Patent Document 1 discloses the following information processing device that can improve performance and reliability while achieving cost reduction. "In an information processing device 100 comprising processor A210 and processor B220, the device includes a control unit that performs non-safety functions and safety functions. The control unit divides the non-safety functions into multiple sub-processes and alternately repeats parallel processing, in which processor A210 and processor B220 each execute each of the multiple sub-processes without overlap, and multiple processing, in which processor A210 and processor B220 each execute the safety functions."

[0007] However, multithreaded systems are considered unsuitable for railway safety devices, which require a high level of reliability compared to general equipment, because they result in complex software structures that are prone to bugs, and bug analysis by reproducing abnormal events is extremely difficult. Furthermore, since the device requires the installation of multiple CPUs, there are disadvantages such as increased costs and larger device size.

[0008] Therefore, conventional railway safety devices employ a single-threaded approach, sacrificing responsiveness and CPU utilization efficiency. The single-threaded architecture is a method of executing a program by sequentially executing threads on a single CPU. The single-threaded approach simplifies the software structure, making it less likely for bugs to be implemented. When a bug does manifest as an abnormal event, tasks such as reproducing the event, identifying the cause, and fixing the bug can be easily carried out. Furthermore, a single-threaded architecture eliminates the need for multiple CPUs, which is effective in reducing costs and the overall size of the system.

[0009] For example, Patent Document 2 discloses the following as a security processing device that maintains conventional responsiveness, is low-cost, and has a simple software structure. "CPU1 uses the first memory 21 to execute the first thread at predetermined first cycles T1, while using the second memory 22 to execute the second thread 12 at predetermined second cycles T2 that are shorter than the first cycle, with priority over the first thread 11. The first and second threads 11 and 12 include input operations 111 and 121 to read data stored in the third memory 3, arithmetic operations 112 and 122 to perform calculations based on that data without repeating the input operations, and output operations 113 and 123 to write the data obtained by the arithmetic operations to the third memory 3. Each thread 11 and 12 is restricted from accessing the memories 21 and 22 used by the other thread, and since the input operations are not repeated, the data does not change during the arithmetic operations, and the threads do not interfere with each other."

[0010] According to Patent Document 2, a technique is disclosed that allows for pseudo-multitasking by employing a single thread while simultaneously executing multiple single threads. [Prior art documents] [Patent Documents]

[0011] [Patent Document 1] Japanese Patent Publication No. 2015-176292 [Patent Document 2] Japanese Patent Publication No. 2013-058228 [Overview of the project] [Problems that the invention aims to solve]

[0012] However, as described in Patent Document 2, it is difficult to perform functions that were previously implemented by multiple independent railway safety devices, such as safety tasks like ATC (Automatic Train Control) threads and ATP (Automatic Train Protection) threads, and non-safety tasks like ATO (Automatic Train Operation) threads and TASC (Train Automatic Stop-position Controller) threads, using a single railway safety device (hereinafter referred to as "railway safety device") from the standpoint of device availability and reliability.

[0013] The objective is to provide a safety device that can satisfy the reliability requirements for each task, even when processing tasks requiring high reliability and other tasks in parallel using a single thread. [Means for solving the problem]

[0014] To solve the above-mentioned problems, one representative safety device of the present invention comprises a multitask execution unit that performs at least one task, and a multitask control unit that periodically monitors, manages, and controls one or more tasks. The multitask control unit further comprises a task information management unit that manages different attribute information for each task and stops the output from the task, a task execution order control unit that controls the execution order of the tasks based on the priority managed by the task information management unit, and a task switching unit that issues a task switching instruction in response to a control command from the task execution order control unit. [Effects of the Invention]

[0015] According to the present invention, it is possible to provide a safety device that can satisfy the reliability requirements for each task, even when performing tasks with different reliability requirements. [Brief explanation of the drawing]

[0016] [Figure 1]FIG. 1 is a diagram showing an example of the configuration of a railway safety device. [Figure 2] FIG. 2 is a diagram showing an example of a task combination model in a case where a safety task and a non-safety task are combined without changing their structures to be formed into tasks. [Figure 3] FIG. 3 is a diagram showing an example of a task combination model in a case where independent tasks are constructed for each function. [Figure 4] FIG. 4 is a diagram showing an example of a task combination model in a case where tasks sharing some functions are constructed. [Figure 5] FIG. 5 is a diagram showing an example of a task combination model in a case where functions are further subdivided to construct independent tasks. [Figure 6] FIG. 6 is a diagram showing an example of the correspondence between a physical address space and a virtual address space. MODE FOR CARRYING OUT THE INVENTION

[0017] Hereinafter, embodiments of the present invention will be described with reference to the drawings. The present invention is not limited by these embodiments. In the description of the drawings, the same parts are denoted by the same reference numerals. When there are a plurality of components having the same or similar functions, description may be given by adding different suffixes to the same reference numeral. In addition, when it is not necessary to distinguish between the plurality of these components, the suffix may be omitted in the description. Positions, sizes, shapes, ranges, and the like of respective components shown in the drawings may not represent actual positions, sizes, shapes, ranges, and the like in order to facilitate understanding of the invention. Therefore, the present invention is not necessarily limited to the positions, sizes, shapes, ranges, and the like disclosed in the drawings.

[0018] [Embodiment] First, a railway safety device 100 according to an embodiment will be described with reference to FIG. 1. FIG. 1 is a diagram showing an example of the configuration of the railway safety device 100. The railway safety device 100 is a device that ensures the safe operation of transportation equipment running on tracks, such as electric trains, even if a problem occurs.

[0019] The railway safety device 100 is a device that performs safety tasks and non-safety tasks, and its standard function is, for example, a detection function that detects train accidents and malfunctions. Furthermore, the railway safety device 100 mainly includes a multitasking execution unit 1, a control unit 2, a CPU 3, a memory 4, and an MMU (Memory Management Unit) 5.

[0020] <Multitasking Execution Unit> The multitasking execution unit 1 is a processing unit that executes security tasks or non-security tasks using a single-threaded method. Furthermore, the multitasking execution unit 1 executes threads one by one in sequence and does not execute multiple threads in parallel as in a multithreaded system. Furthermore, the multitasking execution unit 1 receives instructions from the control unit 2 regarding the order in which to execute the threads, and executes the threads one by one in order according to those instructions. The order in which the multitasking execution unit 1 executes the threads does not have to be a group of threads included in the task. For example, the order in which the multitasking execution unit 1 executes threads may be such that threads included in the security task are executed first, followed by threads included in the non-security task, even if there are remaining threads included in the security task.

[0021] As a result, the multitasking execution unit 1 can execute tasks in a manner similar to a multitasking system, where multiple tasks are executed in parallel, by executing threads belonging to different tasks across tasks. In the following description, tasks are executed in a single-threaded manner, even if they appear to be running in parallel as in a multi-threaded manner.

[0022] <Department Head> The control unit 2 provides the multitasking execution unit 1 with standard functions of the railway safety device 100 and also performs hardware control. Furthermore, the control unit 2 mainly includes a multitasking control unit 21 and a memory control unit 22.

[0023] The multitasking control unit 21 mainly includes a task switching unit 211, a task execution order control unit 212, a task unit time limit monitoring unit 213, and a task information management unit 214, and determines the order of the threads of the tasks to be executed by the multitasking execution unit 1 and instructs the multitasking execution unit 1 to use that order. The execution order is determined based on the priority of each thread, regardless of the task in which the thread is included. In other words, threads of higher-priority tasks are determined to be executed preferentially in the multitasking execution unit 1.

[0024] The task switching unit 211, based on control commands from the task execution order control unit 212, uses a context switch to instruct the multitasking execution unit 1 to switch tasks. The task switching unit 211 issues a switching instruction on a thread-by-thread basis when switching tasks. At this time, even if there are tasks currently running, it issues a switching instruction if it is possible to switch on a thread-by-thread basis. Furthermore, the task switching unit 211 may instruct the multitasking execution unit 1 to switch multiple tasks and threads together. For example, you could switch tasks for specific attribute information, as described later, all at once.

[0025] The task switching unit 211 may also issue an instruction to stop the currently running thread. As a result, tasks containing threads that have received a stop command are stopped, while the reliability of other tasks, such as normal tasks, is ensured. This allows the railway safety device 100 to continue operating in a reduced-function state.

[0026] The task switching unit 211 stops the railway safety device 100 if, for example, the second requirement is met by the task unit time limit monitoring unit 213, which will be described later. Let You may give instructions. Here, the second requirement is, for example, when the task-unit time limit monitoring unit 213 detects a serious failure, such as when an abnormality occurs in a security task or when a hardware malfunction occurs. Stopping the railway safety device 100 means stopping the CPU 3, which in turn stops the multitasking execution unit 1 and causes an emergency shutdown of the system related to the railway safety device 100.

[0027] The task switching unit 211 may further improve the reliability of tasks other than those that have been stopped, i.e., normal tasks, through the cooperation of software and hardware. For example, under normal conditions, the system may include a mechanism in which the output circuit on the output terminal side is driven only when a signal current flows to the input terminal of a relay, such as a photoMOS relay, due to a periodic survival signal output from the task. In other words, if a task is not alive, a mechanism may be provided to prevent its input / output functions from operating.

[0028] At this time, if the task switching unit 211 determines that an abnormality has occurred in a task, it stops the function of that task, the periodic survival signal from the abnormal task is interrupted, and the signal current to the input terminal of the photoMOS relay is also interrupted. As a result, the circuit on the output terminal side will not be driven in conjunction, thus preventing abnormal input / output operation at the hardware level and further improving reliability.

[0029] The task execution order control unit 212 determines the order in which tasks are executed based on priority at specific intervals. The task execution order control unit 212 transmits the determined order as a control command to the task switching unit 211. The specific period during which the task execution order control unit 212 operates is, for example, 1 ms.

[0030] The task execution order control unit 212 may determine the order in which tasks are executed on a task-by-task basis, or on a thread-by-thread basis. For example, the task execution order control unit 212 determines the order in which threads are executed on a task-by-task basis. continuous Alternatively, the decision may be made based on the priority of all threads, regardless of the task in which the thread in question is involved.

[0031] The task-unit time limit monitoring unit 213 monitors tasks and determines whether any abnormalities have occurred. The task-unit time limit monitoring unit 213 determines that an abnormality exists if the first requirement is met. Here, the first requirement is that the task execution time or execution waiting time is equal to or greater than the threshold.

[0032] The task-unit time limit monitoring unit 213 may determine that an abnormality exists if only a specific thread among the running tasks satisfies the first requirement.

[0033] Here, the threshold for the first requirement is the expected time from when the task starts to when it finishes, or the task execution waiting time. Furthermore, different threshold values ​​may be set for task execution and task waiting.

[0034] The task-unit time limit monitoring unit 213 notifies the task switching unit 211 of any tasks in which it has determined an abnormality has occurred. Upon receiving the notification, the task switching unit 211 issues an instruction to transition the task where the abnormality occurred to a stopped state. The task switching unit 211 excludes the stopped task from execution order control and separates it from all subsequent multitasking control.

[0035] In this case, the task-unit time limit monitoring unit 213 also functions as a notification unit that notifies the details of the determination that an abnormality has occurred, but a separate notification unit may also be provided. Furthermore, while the notification of an abnormality will include the name of the task in which the abnormality occurred, other details may also be provided.

[0036] The task-unit time limit monitoring unit 213 may notify the task switching unit 211 on a thread-by-thread basis about tasks in which it has determined an abnormality has occurred. In this embodiment, the task-unit time limit monitoring unit 213 is included in the multitask control unit 21, but it may be included in other elements as long as it can monitor the tasks being executed. For example, the task-unit time limit monitoring unit 213 may be included in an external device connected to the railway safety device 100.

[0037] Task anomaly detection may be performed by a unit other than the task-specific time limit monitoring unit 213. For example, if the MMU5 detects an anomaly in unauthorized access to a task, or if it detects other anomalies caused by the task, it may be determined that an anomaly has occurred in the task.

[0038] The task information management unit 214 manages the status information and attribute information of tasks. Here, task status information refers to operational states such as start, pause, resume, and stop. Task attribute information refers to information such as priority, processing time limit, and the number of threads included in the task. The task information management unit 214 manages status information and attribute information for each task, but it may also manage information for each thread. For example, it may manage status information and attribute information for each thread.

[0039] The multitasking control unit 21 manages the tasks to be executed based on the information managed by the task information management unit 214. For example, if a high-priority task enters a standby state, it can switch to the next highest-priority task. This enables multitasking control that prevents high-priority tasks from being unnecessarily delayed, even when tasks are executed using a single-threaded method.

[0040] The memory control unit 22 controls the MMU 5. The multiple tasks controlled by the multitasking control unit 21 are deployed in the physical address space of memory 4. The memory control unit 22 ensures independence between tasks for multiple tasks controlled by the multitasking control unit 21, thereby preventing unauthorized access.

[0041] <cpu> The CPU3, also known as the central processing unit, is a device within a computer that controls other devices and circuits and performs data calculations. In this embodiment, it functions as a computing device that performs tasks.

[0042] In this embodiment, the CPU3 is a general central processing unit, but it may be any other type of device as long as it can handle multiple tasks and software such as a control unit. For example, it could be an MPU (Micro Processing Unit) or a DSP (Digital Signal Processor).

[0043] <memory> Memory 4 is a storage device that is directly connected to the computer's main bus, also known as the main memory unit. Memory 4 stores software programs and data, and temporarily stores information necessary for CPU 3 to perform processing. Memory 4 includes, for example, SRAM (Static Random Access Memory) and SDRAM (Synchronous Dynamic Random Access Memory). Memory 4 may be a single device, as in this embodiment, or it may be a group of devices.

[0044] <mmu> The MMU5, also known as the Memory Management Unit, is a device that processes memory access requests from the CPU3. The MMU5, in cooperation with the control unit 2, can perform memory management (the function of converting virtual addresses to physical addresses, i.e., virtual memory management) without mutual exclusion. The MMU5 is controlled by the memory control unit 22. In other words, it controls memory access based on commands from the memory control unit 22. In this embodiment, the memory control unit 22 and the MMU 5 are separate components, but they may be configured as a single unit.

[0045] The MMU5 allocates a virtual address space for each task. The MMU5 then assigns tasks to virtual addresses within the allocated virtual address space. Next, the MMU5 maps the assigned virtual address to the physical address of memory 4.

[0046] In other words, a task only recognizes the virtual address space associated with the MMU5, and does not notify tasks that are not associated with the virtual address space of the virtual address space or the physical address of memory 4. For example, when Task A and Task B are running, Task A is prevented from obtaining information about the virtual address in the virtual address space associated with Task B, and the physical address associated with that virtual address.

[0047] As a result, a task cannot recognize other tasks that are deployed in the same physical address space of memory 4.

[0048] When MMU5 maps the assigned virtual address to the physical address of memory 4, it may also set access permissions. This allows the MMU5 to automatically detect any unauthorized access attempts to physical addresses that should not be recognized, protecting other tasks' programs and data without complex mutual exclusion controls.

[0049] Furthermore, when the multitask control unit 21 is notified of an unauthorized access attempt, it will, as described above, shut down only the abnormal task that attempted the unauthorized access and isolate it from further system operation. This further improves the availability of the device.

[0050] <Other> The railway safety device 100 includes an API and system calls, which are interfaces between the multitasking execution unit 1 and the control unit 2; standard functions of the control unit 2, such as timer control, interrupt control, storage control, system bus control, self-diagnosis, and device driver control; and a group of device drivers (logging, communication, DI (Digital Input) / DO (Digital Output), etc.), which are interfaces between the hardware and the control unit 2. However, since these are similar to publicly known technologies, a detailed description is omitted.

[0051] Next, with reference to Figure 2, the task coupling model implemented by the railway safety device 100 will be described. Figure 2 is a diagram showing an example of a task coupling model in which safety tasks and non-safety tasks are combined into tasks without changing their structure. In the railway safety device 100, if only a single function needs to be operated, it is sufficient to divide the railway safety device 100 into functions according to the level of responsiveness required. However, the railway safety device 100, which performs safety tasks and non-safety tasks, has different criteria for when its functions should be integrated and when they should be kept separate, not only in terms of the responsiveness required for each task, but also in terms of the difficulty and efficiency of task development, the difficulty of debugging and testing, future reusability, and CPU load. Therefore, a task coupling model is needed to separate security tasks from non-security tasks.

[0052] The following describes the integration of security tasks and non-security tasks, but other tasks and devices may also be combined. For example, this could be a safety task (ATS) and a safety task (ATC), or a non-safety task (ATO) and a non-safety task (TASC). For example, this could involve integrating devices with similar required reliability levels.

[0053] Note that the following will describe two devices. Integrate The following explanation will be given, but the same approach can be applied when integrating at least two or more devices.

[0054] First, we will explain a task combination model for combining security tasks and non-security tasks without changing their structure. In the task coupling model shown in Figure 2, tasks can be coupled while maintaining the same design philosophy as before, thus reducing the difficulty of developing the programs on which the tasks run.

[0055] The security + non-security main task 103 is a task that combines the conventional security task 101 and the conventional non-security task 102. Security task 101 includes programs such as the main program, a speed pattern calculation program, and a database access program. Similarly, non-security task 102 also includes the main program.

[0056] The security subtask 104 is a task that utilizes the speed pattern calculation program and functions as a subtask of the security + non-security main task 103. Furthermore, the security subtask 104 calculates a speed pattern based on the input information received from the security + non-security main task 103, and outputs the calculation result to the security + non-security main task 103.

[0057] Security subtask 105 is a task that repurposes the database access program and functions as a subtask of the security + non-security main task 103. Furthermore, the security subtask 105 calculates database access based on the input information received from the security + non-security main task 103, and outputs the calculation result to the security + non-security main task 103.

[0058] As shown in Figure 2, when the security + non-security main task 103 receives input, it requests calculations from the security subtask 104 and the security subtask 105. Security subtask 104 and security subtask 105 send the calculation results to the security + non-security main task 103. The security + non-security main task 103 performs calculations based on the received security subtask 104 and security subtask 105, and outputs the results.

[0059] If an abnormality occurs in security subtask 104 or security subtask 105, the task switching unit 211 stops the task. In this situation, the security + non-security main task 103 cannot receive the calculation results of the security subtask 104 or the security subtask 105, but the security + non-security main task 103 itself, being a normal remaining task, can continue to operate and perform degraded operation.

[0060] On the other hand, the task switching unit 211 may respond in a way other than stopping the task in question. For example, if an abnormality occurs in the security + non-security main task 103, the railway safety device 100 will not be able to perform its expected functions. At this point, the task switching unit 211 determines that the railway safety device 100 cannot continue operating and issues an instruction to stop the CPU 3, thereby emergency-stopping the railway safety device 100.

[0061] Next, referring to Figure 3, we will explain the task coupling model when constructing independent tasks for each function. Figure 3 shows an example of a task coupling model when independent tasks are constructed for each function. The task coupling model in Figure 3 differs from the task coupling model in Figure 2 in that the security main task 107, which is entrusted with all input and output operations, distributes input information to each task and aggregates output information from each task, thereby ensuring that there is no impact on input / output arbitration or operation timing. The railway safety device 100 is a safety device that performs a non-safety main task 106, a safety main task 107, a safety subtask 108, and a safety subtask 109.

[0062] The non-security main task 106 is a non-security task that performs the main calculations, performing calculations based on the input information and outputting the calculation results.

[0063] The security main task 107 is the main security task that performs calculations based on the input information and outputs the calculation results. Furthermore, since the security main task 107 is a security task and the non-security main task 106 is a non-security task, the security main task 107 requires a higher level of reliability.

[0064] The security subtask 108 is a task that utilizes the speed pattern calculation program and functions as a subtask of the security main task 107. Furthermore, the security subtask 108 calculates a speed pattern based on the input information received from the security main task 107 and outputs the calculation result to the security main task 107.

[0065] Security subtask 109 is a task that utilizes a database access program and functions as a subtask of security main task 107. Furthermore, the security subtask 109 calculates database access based on the input information received from the security main task 107 and outputs the calculation result to the security main task 107.

[0066] If an abnormality occurs in security subtask 108 or security subtask 109, the task switching unit 211 stops the task. In this situation, the security main task 107 cannot receive the calculation results of the security subtask 108 or security subtask 109, but the security main task 107 itself, being a normal remaining task, can continue to operate and perform degraded operation.

[0067] If an abnormality occurs in the non-security main task 106, the task switching unit 211 stops the task. In this situation, the security main task 107 cannot aggregate the output information of the non-security main task 106, but the security main task 107 itself, being a normal remaining task, can continue to operate and perform degraded operation.

[0068] On the other hand, the task switching unit 211 may respond in a way other than stopping the task in question. For example, if an abnormality occurs in the main safety task 107, the railway safety device 100 will not be able to perform its expected functions. At this point, the task switching unit 211 determines that the railway safety device 100 cannot continue operating and issues an instruction to stop the CPU 3, thereby emergency-stopping the railway safety device 100.

[0069] Next, referring to Figure 4, we will explain the task coupling model when building tasks that share some functionality. Figure 4 shows an example of a task coupling model when building tasks that share some functionality. The task coupling model in Figure 4 differs from the task coupling model in Figure 2 in that it has multiple tasks with computational functions, but also has a shared input task and a shared output task. In this task coupling model, tasks are generally independent and do not involve functional coupling. This reduces the likelihood of collisions with identifiers such as function names, improving development efficiency and increasing the possibility of future reuse. For example, it is possible to easily extract only the ATC-related tasks from an already developed integrated ATC and ATO system and reuse them in an integrated ATC and ATS system.

[0070] The railway safety device 100 is a safety device that performs a non-safety main task 110, a safety main task 111, a safety subtask 112, a safety subtask 113, an input task 114, and an output task 115.

[0071] The non-security main task 110 is a security task that performs the main calculations. It performs calculations based on the input information received from the input task 114 and outputs the calculation results to the output task 115.

[0072] The security main task 111 is a non-security task that performs the main calculations. It performs calculations based on the input information received from the input task 114 and outputs the calculation results to the output task 115. Furthermore, since the security main task 111 is a security task and the non-security main task 110 is a non-security task, the security main task 111 requires a higher level of reliability.

[0073] The security subtask 112 is a task that utilizes the speed pattern calculation program and functions as a subtask of the security main task 111. Furthermore, the security subtask 112 calculates a speed pattern based on the input information received from the security main task 111 and outputs the calculation result to the security main task 111.

[0074] Security subtask 113 is a task that repurposes the database access program and functions as a subtask of security main task 107. Furthermore, the security subtask 113 calculates database access based on the input information received from the security main task 111 and outputs the calculation result to the security main task 111.

[0075] The input task 114 is a task for distributing input information, and distributes the input information received by the railway safety device 100 to the non-safety main task 110 and the safety main task 111. This allows for input adjustments and ensures that the timing of operations is not affected.

[0076] The output task 115 is a task that aggregates the output information of tasks, and aggregates and outputs the output information of the non-security main task 110 and the security main task 111. This allows for adjustments to the output and ensures that the timing of operation is not affected.

[0077] If an abnormality occurs in security subtask 112 or security subtask 113, the task switching unit 211 stops the task. In this situation, the security main task 111 cannot receive the calculation results of the security subtask 112 or security subtask 113, but the security main task 111 itself, being a normal remaining task, can continue to operate and perform degraded operation.

[0078] If an abnormality occurs in the non-security main task 110, the task switching unit 211 stops the task. In this situation, the security main task 111 cannot aggregate the output information of the non-security main task 110, but the security main task 111 itself, being a normal remaining task, can continue to operate and perform degraded operation.

[0079] If an abnormality occurs in input task 114, the task switching unit 211 stops the task. At this time, the safety main task 111 and the non-safety main task 110 will not receive any newly input information from the railway safety device 100, but they will continue to perform calculations on the already input information, and the output task 115 will output the results.

[0080] If an abnormality occurs in output task 115, the task switching unit 211 stops the task. At this time, the output task 115 cannot aggregate the output information of the non-security main task 110 and the security main task 111, but the security main task 111 and the non-security main task 110 can continue their calculations based on the information input from the input task 114.

[0081] On the other hand, the task switching unit 211 may respond in a way other than stopping the task in question. For example, if an abnormality occurs in the main safety task 111, the railway safety device 100 will not be able to perform its expected functions. At this point, the task switching unit 211 determines that the railway safety device 100 cannot continue operating and issues an instruction to stop the CPU 3, thereby emergency-stopping the railway safety device 100.

[0082] Next, referring to Figure 5, we will explain a task coupling model for when functions are further subdivided to create independent tasks. Figure 5 shows a task coupling model when functions are further subdivided to create independent tasks. The task coupling model in Figure 5 differs from the task coupling model in Figure 3 in that the granularity of the functions is further subdivided.

[0083] The task coupling model in Figure 5 further subdivides the functions of the railway safety device 100, such as input function, calculation function, and output function, into tasks. In this task coupling model, tasks are finely divided and independent, and in the event of an anomaly, the functional degradation is minimal, thus improving availability. Furthermore, by making each task smaller, it becomes easier to narrow the scope of impact. This makes it easier to understand, develop, test, debug, and parallelize tasks, and thus improves development efficiency by making them easier to scale up. Furthermore, by making each task smaller, it becomes easier to develop tasks and combinations of tasks that are suitable for each purpose, thereby improving reusability.

[0084] The railway safety device 100 is a safety device that performs the following tasks: speed monitoring task 116, display control task 117, position recognition task 118, fault detection task 119, automatic train operation (ATO) task 120, brake arbitration task 121, message analysis and generation task 122, speed-distance calculation task 123, fault management task 124, DI / DO task 125, communication task 126, and pulse acquisition task 127.

[0085] The speed monitoring task 116, the display control task 117, the position recognition task 118, the fault detection task 119, and the automated driving (ATO) task 120 are tasks classified into functional layers. Here, the functional layer is a layer that summarizes the tasks related to the functions of safely operating the railway safety device 100.

[0086] The brake arbitration task 121, the message analysis and generation task 122, the speed-distance calculation task 123, and the fault management task 124 are tasks classified under the data management layer. Here, the data management layer is a layer related to the function of analyzing data acquired by the railway safety device 100.

[0087] The DI / DO task 125, the communication task 126, and the pulse acquisition task 127 are tasks classified as input / output layers. Here, the input / output layer is the layer that manages the information input and output by the railway safety device 100.

[0088] If an abnormality occurs in any of the tasks of the railway safety device 100, the task switching unit 211 will stop the task in question. In this situation, tasks other than the one experiencing the malfunction can continue operating and can run in a degraded state.

[0089] Furthermore, although the above description described a case where the railway safety device consists of only one device, it may also consist of at least two or more devices. The following describes the case where the railway safety device 200 is a redundant system consisting of at least two or more single railway safety devices.

[0090] In this case, the railway safety device 200 is composed of the 1-series and 2-series railway safety devices 100. The railway safety device 100 is a redundant system, whether it is a parallel redundant system or a standby redundant system, but in either case, its availability is improved compared to a system consisting of a single device.

[0091] The railway safety device 100 can take a wide range of actions when it detects a task abnormality, including when the railway safety device 100 is composed of only one unit. For example, in the railway safety device 200 where the tasks of the task coupling model in Figure 2 are executed, there is a safety + non-safety main task 103 executed in the first railway safety device 100, and a safety + non-safety main task 103 executed in the second railway safety device 100.

[0092] Regardless of whether it is system 1 or system 2, if an abnormality occurs in the security subtask 104 or security subtask 105, the task switching unit 211 will stop the task in the same manner as if it were composed of a single device.

[0093] If an abnormality occurs in the security + non-security main task 103 of system 1, the task switching unit 211 stops the task. At this time, the railway safety device 100 of the first series determines that continued operation is impossible and shuts down the CPU 3, thereby emergency-stopping the railway safety device 100 of the first series. In this case, the railway safety device 200 is operating with the railway safety device 100 of the 2 series, and can operate in reduced capacity using only the railway safety device 100 of the 2 series.

[0094] Next, referring to Figure 6, we will explain data sharing between tasks executed by the multitasking execution unit 1. Figure 6 shows an example of the correspondence between the physical address space and the virtual address space. Tasks executed by the multitasking execution unit 1 are loaded into memory 4. At this time, the tasks executed by the multitasking execution unit 1 are deployed to separate virtual address spaces for each task. Each task has its own independent virtual address space, which is then mapped and associated with the physical address space of memory 4 by the MMU5.

[0095] Furthermore, the MMU5 prevents tasks executed by the multitasking execution unit 1 from obtaining information about the physical address space to which other independent virtual address spaces are mapped. This allows tasks executed by the multitasking execution unit 1 to have independent virtual address spaces, thereby improving reliability.

[0096] In Figure 6, virtual address space 70, virtual address space 80, and virtual address space 90 are expanded.

[0097] For example, virtual address space 70 is associated with physical address space 71. Similarly, virtual address space 80 is associated with non-shared address space 83 and physical address space 84.

[0098] Virtual address space 70 and virtual address space 80 are independent of each other. In this embodiment, a task in which the virtual address space 70 is expanded is, for example, prevented by the memory control unit 22 from recognizing anything other than the virtual address space reserved for that task. This prevents the system from recognizing other tasks deployed in memory 4 and is therefore unaffected by other tasks, thus improving reliability and availability.

[0099] Furthermore, the virtual address space associated with a task may be accessed by other tasks. The following section describes the case where virtual address space 80 and virtual address space 90 share a portion of the physical address space.

[0100] The virtual address space 80 includes the non-shared address space 81 and the shared address space 82. Similarly, the virtual address space 90 includes the shared address space 91 and the non-shared address space 92.

[0101] The non-shared address space 81 is associated with the non-shared address space 83 of memory 4. Similarly, the non-shared address space 92 is associated with the non-shared address space 93 of memory 4.

[0102] Shared address space 82 and shared address space 91 are associated with the same physical address space 84. In other words, the shared address space 82 and the shared address space 91 can share data via the physical address space 84. In this state, the shared address space 82 and the shared address space 91 function as a virtual data sharing area, enabling data sharing via the physical address space 84, which is the same physical data area. In other words, data can be shared between multiple tasks that are independent in the virtual address space, without the need for dedicated main memory.

[0103] Furthermore, the memory control unit 22 can set different access rights when mapping the shared address space 82 and the shared address space 91 to the physical address space 84. For example, when the memory control unit 22 maps the shared address space 82 to the physical address space 84, it sets a "write-enabled" access right that allows it to write to the physical address space 84. For example, when the memory control unit 22 maps the shared address space 91 to the physical address space 84, it sets a "read-only" access right that allows it to read only the contents of the physical address space 84.

[0104] This makes it possible to determine, for each task, the operating mode (e.g., whether or not to have functional limitations) and whether or not to request the allocation of the virtual data sharing area to memory 4, thereby protecting the data in the virtual data sharing area. Furthermore, by managing and monitoring the operating mode, such as whether it is read-only or read-write, for each task, it becomes possible to prevent unauthorized rewriting, even for tasks belonging to parties authorized to request allocation of the virtual data sharing area.

[0105] Furthermore, once the allocation of the virtual data sharing area is complete, a dedicated handle is provided to the task, and procedures and steps are required to present the dedicated handle when accessing it, thereby preventing unauthorized access by third parties through the task. This allows for protections based on operating modes and prescribed procedures and steps regarding the allocation and access of data sharing areas, thereby improving the reliability of task programs and data.

[0106] The data protection methods described above may be other than those mentioned above. For example, depending on the required level of reliability, protection may be limited to the operating mode only, or to specific procedures or steps only. Furthermore, the data sharing method is not limited to sharing the physical address space of memory 4. It may also be a data sharing method using a FIFO queue in which the receiving task receives transmitted data from the sending task sequentially in the order in which the data was transmitted, or a data sharing method using an override queue in which transmitted data from the sending task is always overwritten, allowing the receiving task to receive the latest data.

[0107] As described above, the railway safety device 100 of this embodiment can perform two types of tasks with different reliability requirements. In other words, even if two different tasks are executed using the same multitasking execution unit, they can be executed in a way that meets the required reliability. This allows two types of the task to be performed with the same device, resulting in lower costs and a smaller device size.

[0108] Furthermore, the present invention can also take the following forms. (Aspect 1) A multitasking execution unit that performs at least one task, It comprises a multitask control unit that periodically monitors, manages, and controls one or more tasks, The multitask control unit includes a task information management unit that manages different attribute information for each task and stops output from the task, A task execution order control unit controls the execution order of the tasks based on the priority managed by the task information management unit, The system includes a task switching unit that issues a task switching instruction in response to a control command from the task execution sequence control unit. Security device. (Aspect 2) A safety device according to Embodiment 1, The system includes a task-unit time limit monitoring unit that monitors the time required to process the task and determines that there is an abnormality in a running task that satisfies a first requirement, where the execution time or execution waiting time of the task is greater than or equal to a threshold, The task switching unit stops the task that the task unit time limit monitoring unit has determined to be abnormal, and transitions it to an operating state in which it is excluded from control by the task execution order control unit. Security device. (Aspect 3) A safety device according to embodiment 1 or 2, The multitasking execution unit executes security tasks that require high reliability for execution and non-security tasks that do not require high reliability for execution. Security device. (Aspect 4) A safety device according to embodiment 3, The task switching unit further stops at least one or more tasks having the same attribute information as the stopped task. Security device. (Appendix 5) A safety device according to embodiment 3 or 4, The task switching unit stops the multitasking execution unit if the task meets the second requirement of being a serious failure. Security device. (Aspect 6) A safety device described in any one of embodiments 3 to 5, It comprises at least two of the aforementioned multitasking execution units, When the task is stopped, the task switching unit switches its operation to a different multitasking execution unit than the one executing the task. Security device. (Aspect 7) A safety device described in any one of embodiments 2 to 6, The aforementioned task-unit time limit monitoring unit includes a notification unit that notifies the user of any abnormalities it has determined. Security device. (Pattern 8) A safety device described in any one of embodiments 1 to 7, The main memory unit deploys the tasks to be executed by the multitasking execution unit, The system comprises a memory control unit that assigns the aforementioned tasks to the main memory unit. The memory control unit reserves a virtual data sharing area for each task, and the virtual data sharing areas for tasks that require data sharing are set to the same physical data area. Security device. (Aspect 9) A safety device described in aspect 8, The memory control unit sets access rights to the physical data area only for the task associated with the virtual data sharing area. Security device. (Pattern 10 ) Appearance 1 to 9 Equipped with any one of the safety devices described above. vehicle. [Explanation of Symbols]

[0109] 100 Railway safety devices 1. Multitasking execution unit 101 Security Tasks 102 Non-security tasks 103 Security + Non-Security Main Tasks 104, 105 Security Subtasks 106 Non-security main tasks 107, 111 Security Main Tasks 108, 109 Security Subtasks 110. Non-security main task 112, 113 Security Subtasks 114 Input Tasks 115 Output Tasks 116 Speed ​​Monitoring Task 117 Display Control Task 118 Location recognition task 119 Fault detection task 120 Autonomous Driving (ATO) Tasks 121 Brake Mediation Task 122 Message Analysis and Generation Task 123 Speed-to-Distance Calculation Task 124 Fault Management Tasks 125 DI / DO tasks 126 Communication Tasks 127 Pulse acquisition task 2 Control Unit 21 Multitasking Control Unit 211 Task switching section 212 Task Execution Order Control Unit 213 Task-based time limit monitoring unit 214 Task Information Management Department 22 Memory Control Unit 3 CPU 4 memory 5 MMU 70, 80, 90 virtual address spaces 71 Physical Address Space 81, 83, 92, 93 Non-shared address space 82, 91 Shared Address Space< / mmu> < / cpu>

Claims

1. A multitasking execution unit that performs at least one task, A security device comprising a multitask control unit that periodically monitors, manages, and controls one or more tasks, The multitask control unit, Different attribute information is managed for each of the aforementioned tasks, A task information management unit that stops the output from the aforementioned task, A task-unit time limit monitoring unit monitors the time required to process the task and determines that there is an abnormality in a running task that satisfies the first requirement, where the execution time or execution waiting time of the task is greater than or equal to a threshold; A task execution order control unit controls the execution order of the tasks based on the priority managed by the task information management unit, A task switching unit that issues a task switching instruction in response to a control command from the task execution sequence control unit, Equipped with, The task switching unit stops the task that the task unit time limit monitoring unit has determined to be abnormal, and transitions it to an operating state in which it is excluded from control by the task execution order control unit. The multitasking execution unit executes security tasks that require high reliability for execution and non-security tasks that do not require high reliability for execution. A safety device characterized by the following features.

2. A safety device according to claim 1, The task switching unit further stops at least one more tasks having the same attribute information as the stopped task. Security device.

3. A safety device according to claim 1, The task switching unit stops the multitasking execution unit if the task meets the second requirement of being a serious failure. Security device.

4. A safety device as described in claim 1, It comprises at least two of the aforementioned multitasking execution units, When the task is stopped, the task switching unit switches its operation to a different multitasking execution unit than the one executing the task. Security device.

5. A safety device as described in claim 1, The aforementioned task-unit time limit monitoring unit includes a notification unit that notifies the user of any abnormalities it has determined. Security device.

6. A safety device as described in claim 1, The main memory unit deploys the tasks to be executed by the multitasking execution unit, The system comprises a memory control unit that assigns the aforementioned tasks to the main memory unit. The memory control unit reserves a virtual data sharing area for each task, and the virtual data sharing areas for tasks that require data sharing are set to the same physical data area. Security device.

7. A safety device according to claim 6, The memory control unit sets access rights to the physical data area only for the task associated with the virtual data sharing area. Security device.

8. A vehicle equipped with the safety device described in claim 1.

Citation Information

Patent Citations

  • Multitask monitoring management system

    CN101464811A

  • Multi-task management method combining time slice rotation with extended interruption

    CN112596891A

  • Device and method for managing task execution

    JP1996022396A

  • Security processing device

    JP2013058228A

  • Information processing apparatus, information processing method, and program

    JP2015176292A