Secure computer system having two main control modules

By introducing a dual main control module structure in a secure computer system, the main control module and the secondary main control module communicate through an internal security bus, real-time computing power sharing is achieved, the computing speed and real-time performance is improved, the failure probability and development difficulty are reduced, and the system expansion and compatibility are enhanced.

WO2025179853A1PCT designated stage Publication Date: 2025-09-04CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/121141
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-26
Filing Date
2024-09-25
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

The existing single-main control module security computer systems have low computing efficiency when facing large amounts of data, high hardware cost, and high software development difficulty, and limited system scalability and compatibility.

Method used

The dual main control module structure is adopted, in which the main control module and the secondary main control module communicate through an internal security bus, the main control module interacts with the first external device to perform the first type of control function, the secondary main control module interacts with the second external device to perform the second type of control function, and the secondary main control module is designed as a functional board to reduce development difficulty and hardware costs.

Benefits of technology

It improves the computing speed of a secure computer system and the real-time processing of communication data, reduces the probability of failure, and reduces the complexity of software and hardware costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024121141_04092025_PF_FP_ABST
    Figure CN2024121141_04092025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present invention is a secure computer system having two main control modules. The system comprises a main control module and a secondary main control module, wherein the main control module communicates with the secondary main control module by means of an internal secure bus; the main control module is configured to exchange data with the secondary main control module and a plurality of first external devices, and execute a first-type control function on the basis of the exchanged data; and the secondary main control module is configured to exchange data with the main control module and a plurality of second external devices, and execute a second-type control function on the basis of the exchanged data. By means of the technical solution, computing power can be shared with a main control module, the operation speed of a secure computer system is effectively increased, and the real-time performance of communication data processing is enhanced; and the function division between the main control module and a secondary main control module is clear and explicit, so that the software complexity is reduced, and the probability of failure of the secure computer system is also reduced to a certain extent.
Need to check novelty before this filing date? Find Prior Art

Description

A secure computer system with dual main control modules Technical Field

[0001] The present invention relates to the field of computer security technology, and in particular to a secure computer system with dual main control modules. Background Art

[0002] A secure computer system refers to a system that ensures the confidentiality, integrity and availability of the computer system and the information it stores, processes and transmits by taking a series of technical and management measures. It can effectively prevent unauthorized access, tampering, destruction or leakage of information in the system, while protecting the system from normal operation and service provision.

[0003] Currently, mainstream security computer systems generally adopt a single-master control method. The computing power and performance indicators of single-master control security computer systems are determined after the design and development are finalized, without fully considering the scalability of the system hardware and software, which limits the system's versatility and compatibility.

[0004] In existing technologies, to increase the computing power of a secure computer system, technicians often choose to add a complete secure computer system and migrate some of the communication functions of the main control module to share the computing power and communication pressure. However, this expansion method has high hardware costs and increases the difficulty of software and hardware development.

[0005] Summary of the Invention

[0006] The present invention provides a secure computer system with dual main control modules. Based on the existing single main control module, the system can share computing power with the main control module, effectively improving the computing speed of the secure computer system and enhancing the real-time performance of processing communication data. The main control module and the sub-main control module have clear functional divisions, which reduces software complexity and, to a certain extent, also reduces the probability of overall machine failure.

[0007] According to one aspect of the present invention, a secure computer system with dual main control modules is provided, comprising a main control module and a sub-main control module; wherein the main control module and the sub-main control module communicate via an internal secure bus;

[0008] The main control module is used to exchange data with the sub-main control module and multiple first external devices, and execute the first type of control function according to the interaction data;

[0009] The sub-main control module is used to perform data interaction with the main control module and a plurality of second external devices, and execute the second type of control function according to the interaction data.

[0010] Optionally, the main control module includes a main system first computing unit, a backup system first computing unit, and a plurality of first communication units;

[0011] Wherein, the first computing unit of the main system is connected to the first computing unit of the backup system;

[0012] The main system first operation unit and the backup system first operation unit are respectively connected to the first communication units; the first communication units are used to communicate with the first external device.

[0013] Optionally, the secondary main control module includes a main system second computing unit, a backup system second computing unit, a main system second communication unit, and a backup system second communication unit;

[0014] The second computing unit of the main system is connected to the second computing unit of the backup system;

[0015] The main system second operation unit and the backup system second operation unit are respectively connected to the second communication units; the second communication units are used to communicate with the second external devices.

[0016] Optionally, the first operation unit is specifically configured to:

[0017] Performing data exchange with the first communication unit and the second computing unit, and executing the first type of control function according to the exchanged data;

[0018] The second operation unit is specifically used for:

[0019] The second communication unit and the first operation unit interact with each other and perform the second type of control function according to the interaction data.

[0020] Optionally, the first communication unit communicates with the first external device via a universal input / output interface;

[0021] The communication mode between the second communication unit and the second external device includes at least Ethernet communication, CAN (Controller Area Network) bus communication and RS422 bus communication.

[0022] Optionally, the safety computer system is an onboard safety platform in a train control system.

[0023] Optionally, the first type of control function is an ATP (Automatic Train Protection) function, and the second type of control function is an ATO (Automatic Train Operation) function; the first external device includes an ATS (Automatic Train Supervision) system;

[0024] The main control module is further configured to forward the ATS-related data to the ATS upon receiving the ATS-related data sent by the sub-main control module.

[0025] Optionally, the first type of control functions include train safety-related functions, and the second type of control functions include at least generating electronic maps, forwarding data at the head and tail of the train, and IP (Internet Protocol) queries.

[0026] Optionally, the main control module is a safety board and the sub-main control module is a functional board;

[0027] The safety integrity level of the main control module and the sub-main control module is SIL4.

[0028] The technical solution of the embodiment of the present invention is to configure a main control module and a sub-main control module in a security computer system with dual main control modules. The main control module and the sub-main control module communicate with each other through an internal security bus. The main control module is used to interact with the sub-main control module and the first external device for data exchange and to perform a first type of control function according to the interaction data. The sub-main control module is used to interact with the main control module and the second external device for data exchange and to perform a second type of control function according to the interaction data. In this way, the computing power can be shared with the main control module on the basis of the existing single main control module, the computing speed of the security computer system can be effectively improved, and the real-time processing of communication data can be enhanced. The functions of the main control module and the sub-main control module are clearly divided, the software complexity is reduced, and the failure probability of the security computer system is also reduced to a certain extent. By designing the sub-main control module as a functional board card, the difficulty of software and hardware development and the hardware cost can be reduced on the basis of the existing security computer system.

[0029] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0031] FIG1 is a schematic structural diagram of a secure computer system with dual main control modules provided in accordance with a first embodiment of the present invention;

[0032] FIG2 is a schematic structural diagram of a main control module provided according to an embodiment of the present invention;

[0033] FIG3 is a schematic structural diagram of a secondary main control module provided according to an embodiment of the present invention;

[0034] FIG4 is a schematic structural diagram of another secure computer system with dual main control modules provided according to an embodiment of the present invention. DETAILED DESCRIPTION

[0035] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0036] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0037] Example 1

[0038] FIG1 shows a secure computer system with dual main control modules provided in a first embodiment of the present invention, including a main control module 100 and a sub-main control module 200 .

[0039] The main control module 100 and the sub-main control module 200 communicate via an internal safety bus.

[0040] The main control module 100 is used to perform data interaction with the sub-main control module 200 and a plurality of first external devices, and execute a first type of control function according to the interaction data.

[0041] The sub-main control module 200 is used to perform data interaction with the main control module 100 and a plurality of second external devices, and execute the second type of control function according to the interaction data.

[0042] Optionally, the main control module 100 is a security board, and the sub-main control module 200 is a functional board.

[0043] It is understandable that in existing security computer systems, the main computing tasks can generally be undertaken by the main control module. However, with the development of science and technology, in most application fields, the amount of computing data is gradually increasing. The security computer system using a single main control module is difficult to undertake a large number of computing tasks and has low computing efficiency. Technical personnel can generally share the computing power with the main control module by adding a set of security computer systems. However, after adding a new security computer system, the existing security computer system and other equipment in the application scenario need to be modified, which makes development difficult. In addition, the hardware cost of the security computer system is also high, the development cycle is long, and the development difficulty is high.

[0044] The present invention takes into account that in existing security computer systems, the main control module is generally a security board, and the main control module can communicate with multiple functional boards through an internal security bus to achieve different functions. Therefore, the present invention applies the sub-main control module 200 in the form of a functional board. A functional board can be expanded in the security computer system and developed, so that the functional board can be used as the sub-main control module 200.

[0045] Optionally, the sub-master control module 200 can be single, but as data continues to grow and the demand for computing power increases, in order to achieve more functions, multiple sub-master control modules 200 can also be set in the secure computer system to establish a secure computer system with multiple master control modules.

[0046] Optionally, compared to security boards, the software and hardware development difficulty of functional boards is relatively low, and the hardware cost is lower. By using the functional board as a sub-master control module 200, the development cost can be effectively reduced and the scalability, versatility and compatibility of the security computer system can be improved.

[0047] Optionally, the sub-main control module 200 may also use a safety board, or a board that has both safety board and functional board attributes. The board attributes may be determined according to actual development requirements.

[0048] Optionally, the security computer system described in the present invention is designed based on a general platform environment and can be used in various scenarios such as the financial field, medical field, e-commerce field, education field, rail transit field, etc. For example, in the education field, the security computer system provided by the present invention can be used to query and manage academic papers; in the e-commerce field, the security computer system provided by the present invention can be used to display and trade goods; in the rail transit field, the security computer system provided by the present invention can be used to control vehicle safety, etc. This is only an illustrative explanation and does not limit the specific application scenarios of the security computer system proposed by the present invention.

[0049] Optionally, the first type of control function may be the primary control function of the secure computer system, and the second type of control function may be an auxiliary control function within the secure computer system. The main control module 100 has relatively high computing power and a more secure computing process, and can generally undertake more important tasks, such as payment processing, vehicle safety control, and information security assurance. The sub-main control module 200 can serve as an auxiliary control module, performing tasks such as product display and reference information generation. The specific first and second type of control functions depend on the specific application scenarios of the secure computer system, and are not listed here one by one. The functions are not limited to the control functions listed in the above examples.

[0050] Optionally, the first external device may refer to a device connected to the main control module 100, and the second external device may refer to a device connected to the sub-main control module 200. The main control module 100 may obtain data from the first external device or the sub-main control module 200 for calculation, and may also send the calculation result data to the first external device or the sub-main control module 200. Similarly, the sub-main control module 200 may also obtain data from the second external device or the main control module 100 for calculation, and may also send the calculation result data to the second external device or the main control module 100.

[0051] Optionally, when the application scenarios of the secure computer system are different, the device information of the first external device and the second external device may also be different. In one optional example, if in an e-commerce scenario, the main control module 100 performs payment processing tasks, the first external device may be a bank's transaction inquiry platform, etc., and if the sub-main control module 200 performs product display tasks, the second external device may be an e-commerce display platform, etc. This is merely an example and does not limit the specific device information of the first and second external devices.

[0052] FIG2 is a schematic diagram of the structure of a main control module provided by an embodiment of the present invention. As shown in FIG2 , the main control module 100 includes a main system first computing unit 110 , a backup system first computing unit 120 , and a plurality of first communication units 130 .

[0053] The main system first computing unit 110 is connected to the backup system first computing unit 120 .

[0054] The master system first computing unit 110 and the backup system first computing unit 120 are respectively connected to the first communication units 130 .

[0055] The first communication unit 130 is used to communicate with a first external device.

[0056] Optionally, in the example shown in FIG2 , three first communication units 130 are shown, and each first communication unit 130 is connected to the main system first operation unit 110 and the backup system first operation unit 120. However, when actually designing a secure computer system, the number of first communication units 130 is not limited, and can be 1, 2, or more. This is only an example. In the example shown in FIG2 , the first external device can refer to a single external device or a plurality of the same or different external devices. When there are multiple external devices, each first communication unit 130 can be connected to one first external device, multiple first external devices, or no first external device. Moreover, the first external device connected to each first communication unit 130 can be the same or different. This is only an example, and does not specifically limit the connection method between the first communication unit 130 and the first external device.

[0057] Optionally, the primary system first computing unit 110 and the backup system first computing unit 120 perform the same function. In an optional example, the primary system first computing unit 110 and the backup system first computing unit 120 can simultaneously perform the same function, forming a primary-backup relationship with each other. In this case, the primary system first computing unit 110 and the backup system first computing unit 120 can both receive or send the same data. When sending data, the data recipient can select one of the primary system first computing unit 110 and the backup system first computing unit 120 for use. In this case, if one of the first computing units fails, the other first computing unit can still perform the same task, without affecting the normal operation of the secure computer system.

[0058] In another optional example, the main system first computing unit 110 and the backup system first computing unit 120 can select one of them to perform the task. For example, the main system first computing unit 110 is selected to perform the task, and the backup system first computing unit 120 can monitor the working status of the main system first computing unit 110 in real time. When it is determined that the main system first computing unit 110 fails according to the working status, the backup system first computing unit 120 can obtain real-time cached data within a specified time period in the main system first computing unit 110, and take over the main system first computing unit 110 to continue to perform the task based on the real-time cached data. At this time, when the main system first computing unit 110 fails, the backup system first computing unit 120 can still perform the same task without affecting the normal operation of the security computer system.

[0059] FIG3 is a schematic diagram of the structure of a secondary main control module provided by an embodiment of the present invention. As shown in FIG3 , the secondary main control module 200 includes a primary second computing unit 210 , a backup second computing unit 220 , a primary second communication unit 230 , and a backup second communication unit 240 .

[0060] The main system second computing unit 210 is connected to the backup system second computing unit 220 .

[0061] The master system second computing unit 210 and the backup system second computing unit 220 are respectively connected to the second communication units.

[0062] The second communication unit is used to communicate with each second external device.

[0063] Optionally, in the example shown in Figure 3, the main system second computing unit 210 is connected to the main system second communication unit 230 and the backup system second communication unit 240, respectively, the backup system second computing unit 220 is connected to the main system second communication unit 230 and the backup system second communication unit 240, respectively, and the main system second communication unit 230 and the backup system second communication unit 240 are both connected to the second external device.

[0064] Optionally, the second external device can be a single device or multiple devices, determined according to actual usage requirements and usage scenarios, and is not restricted here. The second external device connected to the main system second communication unit 230 and the backup system second communication unit 240 is the same, and the second external device can send the same data information to the main system second communication unit 230 and the backup system second communication unit 240 at the same time.

[0065] Optionally, the primary system second computing unit 210 and the backup system second computing unit 220 perform the same function. In one optional example, the primary system second computing unit 210 and the backup system second computing unit 220 can simultaneously perform the same function, forming a primary-backup relationship with each other. In this case, the primary system second computing unit 210 and the backup system second computing unit 220 can both receive or send the same data. When sending data, the data recipient can select one of the primary system second computing unit 210 and the backup system second computing unit 220 for use. In this case, if one of the second computing units fails, the other second computing unit can still perform the same task, without affecting the normal operation of the secure computer system.

[0066] In another optional example, the main system second computing unit 210 and the backup system second computing unit 220 can select one of them to perform the task. For example, the main system second computing unit 210 is selected to perform the task, and the backup system second computing unit 220 can monitor the working status of the main system second computing unit 210 in real time. When it is determined that the main system second computing unit 210 fails according to the working status, the backup system second computing unit 220 can obtain the real-time cached data within a specified time period in the main system second computing unit 210, and take over the main system second computing unit 210 to continue to perform the task based on the real-time cached data. At this time, when the main system second computing unit 210 fails, the backup system second computing unit 220 can still perform the same task without affecting the normal operation of the security computer system.

[0067] Figure 4 is a schematic diagram of the structure of another secure computer system with dual master control modules provided by the present invention. As shown in Figure 4, the master system second computing unit 210 is connected to the master system first computing unit 110 and the backup system first computing unit 120 in the master control module, and the backup system second computing unit 220 is connected to the master system first computing unit 110 and the backup system first computing unit 120 in the master control module.

[0068] Optionally, when any first operating unit in the main control module 100 fails, the other first operating unit can receive the data information sent by the second operating unit in the sub-main control module 200. Similarly, when any second operating unit in the sub-main control module 220 fails, the other second operating unit can receive the data information sent by the first operating unit in the main control module 100.

[0069] Optionally, data interaction between the main control module 100 and the sub-main control module 200 can be achieved through data interaction between the first operation unit and the second operation unit. Data interaction between the first operation unit and the second operation unit can be carried out through the internal security bus to effectively ensure data security.

[0070] Optionally, the first operation unit may be specifically configured to:

[0071] Performing data exchange with the first communication unit and the second operation unit, and executing the first type of control function according to the exchanged data;

[0072] The second operation unit can be specifically used for:

[0073] The second communication unit and the first operation unit interact with each other and perform the second type of control function according to the interaction data.

[0074] Optionally, the first operation unit may select a designated first communication unit 130 for data interaction according to data requirements, and the second operation unit may interact with the second communication unit for data interaction.

[0075] Optionally, the first communication unit 130 and the first external device may communicate via a general purpose input and output interface (GPIO);

[0076] The communication mode between the second communication unit and the second external device includes at least Ethernet communication, CAN bus communication and RS422 bus communication.

[0077] Optionally, the first communication unit 130 selects a universal input / output interface for communication, which can support data communication with more devices, thereby obtaining more data for the main control module 100 to implement various types of calculations.

[0078] Optionally, the first communication unit 130 may also communicate via a CAN bus, Ethernet, MVB (Multifunction Vehicle Bus), TRDP (Train Real-time Data Protocol) or other communication methods.

[0079] Optionally, the second communication unit generally limits the calculation content it performs during development. Therefore, the second external device connected to the second communication unit can be determined based on its actual calculation requirements, and then a matching communication method can be selected based on the second external device.

[0080] Optionally, in addition to Ethernet communication, CAN bus communication, and RS422 bus communication, the second communication unit may also perform data exchange with the second external device through other communication methods, which are not described one by one here.

[0081] Optionally, the safety integrity level of the main control module 100 and the sub-main control module 200 may be SIL4.

[0082] Optionally, in an existing safety computer system, the safety integrity level of the main control module can generally be SIL4. It can be understood that when a sub-main control module is added, the safety integrity level of the sub-main control module can be consistent with that of the main control module, thereby ensuring the safety of the safety computer system.

[0083] The technical solution of the embodiment of the present invention is to configure a main control module and a sub-main control module in a security computer system with dual main control modules. The main control module and the sub-main control module communicate with each other through an internal security bus. The main control module is used to interact with the sub-main control module and the first external device for data exchange and to perform a first type of control function according to the interaction data. The sub-main control module is used to interact with the main control module and the second external device for data exchange and to perform a second type of control function according to the interaction data. In this way, the computing power can be shared with the main control module on the basis of the existing single main control module, the computing speed of the security computer system can be effectively improved, and the real-time processing of communication data can be enhanced. The functions of the main control module and the sub-main control module are clearly divided, the software complexity is reduced, and the failure probability of the security computer system is also reduced to a certain extent. By designing the sub-main control module as a functional board card, the difficulty of software and hardware development and the hardware cost can be reduced on the basis of the existing security computer system.

[0084] Example 2

[0085] This embodiment provides a specific application example of a security computer system with dual main control modules in the field of rail transportation.

[0086] The security computer system described in the embodiment of the present invention may be an on-board security platform in a train control system.

[0087] The on-board safety platform is an important component responsible for ensuring the safety of train operation. It can be used to perform various functions such as train operation and monitoring, fault detection and analysis, emergency braking control, communication and data transmission, safety authentication and protection, event recording and analysis. Through the monitoring, diagnosis and control functions of the on-board safety platform, the train control system can timely perceive the operating status of the train, quickly respond to faults and abnormal situations, and ensure the safe operation of the train.

[0088] When the safety computer system is an in-vehicle safety platform, the first type of control function may be an ATP function, and the second type of control function may be an ATO function.

[0089] Among them, ATP is a system used for train overspeed protection or train speed supervision. It can protect trains from overspeed, monitor safety-related equipment in real time, realize train position detection, speed and distance measurement, thereby ensuring safe train intervals and ensuring that trains run at a safe speed. At the same time, it can complete functions such as signal display, fault alarm, degradation prompt, and input of train parameters and line parameters. It can be seen that when the main control module 100 executes the ATP function, it assumes the main safety protection of the train.

[0090] In an optional embodiment, when the main control module 100 executes the ATP function, the first operation unit can obtain line information, distance information, allowed speed and other information from the interlocking equipment and the operating level through the first communication unit, and monitor the train speed in real time. When the train speed exceeds the speed indicated by the first operation unit, a braking command can be sent to the train through the first communication unit, thereby slowing down the train.

[0091] Among them, ATO can use ground information to realize operational control of train traction, braking, coasting and automatic reversal. On the premise of ensuring the safety of train operation, based on the operation plan, it comprehensively considers goals such as punctuality, comfort, energy saving, and parking accuracy, and adjusts train operation in real time to improve passenger comfort and train punctuality, shorten the operation time interval, improve transportation efficiency and save energy.

[0092] Optionally, the ATP function is a security function in a secure computer system and is the main function, so the main control module 100 needs to execute the ATP function, while the ATO function is an auxiliary function and can be taken over manually when necessary, so the sub-main control module 200 can execute the ATO function.

[0093] Optionally, when the main control module 100 performs the ATP function, the main control module 100 is connected to the sub-main control module 200 that performs the ATO function, and can also be connected to the ATS through the first communication unit. In another optional embodiment, the ATS can also be connected to the main control module 100 through an internal security bus in the form of a functional board.

[0094] In an optional embodiment, when the sub-main control module 200 performs the ATO function, it can receive speed instructions, actual train speed, train travel distance, ATS operation plan and other information sent by the main control module 100 through data interaction with the main control module 100. The sub-main control module 200 can formulate a detailed operation plan based on the ATS operation plan and the actual train speed, and automatically adjust the train's travel direction, speed, acceleration and other information according to the train's operation conditions to achieve automatic driving of the train.

[0095] Optionally, the first external device may include an ATS;

[0096] The main control module 100 may also be configured to forward the ATS-related data to the ATS upon receiving the ATS-related data sent by the sub-main control module 200 .

[0097] Optionally, ATS is an automatic train monitoring system that can realize functions such as automatic control of train operation routes, editing and modification of timetables, control and adjustment of train operation diagrams, etc.

[0098] In an optional example, when the sub-main control module 200 realizes automatic train driving, if the train's arrival time point is calculated, the arrival time point can be sent to the main control module 100, and then the main control module 100 sends the arrival time point to the ATS, so that the ATS can modify the timetable according to the arrival time point.

[0099] Optionally, when the safety computer system is an on-board safety platform, the first type of control function may also include train safety-related functions, and the second type of control function may include functions such as generating electronic maps, forwarding data at the head and tail of a train, and IP query.

[0100] In a specific example, the second communication unit can be connected to the end of the train and TSRS (temporary speed limit server), and communicate wirelessly with ground equipment such as TSRS through the GPRS network to achieve two-way information communication, and complete functions such as electronic maps, forwarding of train head and tail data, and IP query.

[0101] Among them, the GPRS network is a network implemented based on the existing GMS (Global Mobile Communications System) network.

[0102] The technical solution of the embodiment of the present invention, by using the safety computer system as the on-board safety platform in the train control system, using the main control module to perform the ATP function, and using the sub-main control module to perform the ATO function, can improve the computing power of the on-board safety platform in the existing train control system while making minor changes to the existing on-board safety platform, share the computing power of the main control module, and enable the two control modules to perform different control functions, effectively ensuring the operational safety of the rail transit system, effectively improving the computing speed of the on-board safety platform, ensuring the real-time nature of communication data in rail transit, and reducing the failure probability of the on-board safety platform.

Claims

1. A secure computer system with dual main control modules, characterized in that: It includes a main control module and a sub-main control module; wherein the main control module and the sub-main control module communicate through an internal safety bus; The main control module is used to exchange data with the sub-main control module and multiple first external devices, and execute the first type of control function according to the interaction data; The sub-main control module is used to perform data interaction with the main control module and a plurality of second external devices, and execute the second type of control function according to the interaction data.

2. The system according to claim 1, wherein: The main control module includes a main system first computing unit, a backup system first computing unit and a plurality of first communication units; Wherein, the first computing unit of the main system is connected to the first computing unit of the backup system; The main system first operation unit and the backup system first operation unit are respectively connected to the first communication units; the first communication units are used to communicate with the first external device.

3. The system according to claim 2, characterized in that The secondary main control module includes a main system second computing unit, a backup system second computing unit, a main system second communication unit and a backup system second communication unit; The second computing unit of the main system is connected to the second computing unit of the backup system; The main system second operation unit and the backup system second operation unit are respectively connected to the second communication units; the second communication units are used to communicate with the second external devices.

4. The system according to claim 3, characterized in that The second operation unit of the main system is connected to the first operation unit of the main system and the first operation unit of the backup system in the main control module respectively, and the second operation unit of the backup system is connected to the first operation unit of the main system and the first operation unit of the backup system in the main control module respectively.

5. The system according to claim 4, characterized in that The first operation unit is specifically used for: Performing data exchange with the first communication unit and the second operation unit, and executing the first type of control function according to the exchanged data; The second operation unit is specifically used for: The second communication unit and the first operation unit interact with each other and perform the second type of control function according to the interaction data.

6. The system according to claim 4, characterized in that The first communication unit communicates with the first external device via a universal input and output interface; The communication mode between the second communication unit and the second external device includes at least Ethernet communication, control area network CAN bus communication and RS422 bus communication.

7. The system according to claim 1, wherein: The safety computer system is an onboard safety platform in a train control system.

8. The system according to claim 7, characterized in that The first type of control function is the automatic train protection ATP function, and the second type of control function is the automatic train operation ATO function; the first external device includes the automatic train monitoring system ATS; The main control module is further configured to forward the ATS-related data to the ATS upon receiving the ATS-related data sent by the sub-main control module.

9. The system according to claim 7, wherein: The first type of control functions include train safety related functions, and the second type of control functions include at least the generation of electronic maps, forwarding of data at the head and tail of the train, and Internet Protocol IP queries.

10. The system according to claim 1, wherein: The main control module is a safety board, and the sub-main control module is a functional board; The safety integrity level of the main control module and the sub-main control module is SIL4.

Citation Information

Patent Citations

  • Security computer platform in the field of railway signals

    CN110361979A

  • Distributed vehicle-mounted safety computer system

    CN112395236A

  • Railway safety computer platform communication board card configuration management method and system

    CN114546499A

  • Secure computer system with double main control modules

    CN118069579A

  • System and method for controlling train

    KR1020150052398A