Method for securing functionalities of a passenger car
By transmitting status information to a communication link for centralized control command management, the method addresses high maintenance costs in railway passenger cars, reducing hardware and software expenses and enabling efficient software updates.
Patent Information
- Application Number
- PCT/EP2025/055834
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-18
- Filing Date
- 2025-03-04
- Publication Date
- 2025-10-23
AI Technical Summary
Existing railway passenger cars incur high costs for maintenance and operation due to the need to maintain redundant control systems that are rarely used, as they are designed for rare or non-existent failures.
A method where the primary vehicle control system continuously transmits status information to a communication link, which requests redundant control commands from a fixed control point upon detecting a fault, and executes these commands via a communication link, allowing centralized software updates and reducing the need for on-board hardware and maintenance.
This approach reduces hardware and software costs per passenger car, enables easy and cost-effective software updates, and eliminates the need for manual maintenance, while ensuring passenger safety and well-being by maintaining essential functions.
Smart Images

Figure EP2025055834_23102025_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Procedure for securing the functionalities of a passenger car
[0003] The invention relates to a method for securing the functionalities of a passenger car in rail transport.
[0004] Introduction and state of the art
[0005] In railway technology, passenger cars must have a particularly high level of technical availability in order to ensure essential functions during operation of the passenger car.
[0006] These include, in particular, controls that influence the well-being and safety of passengers, namely the control of lighting, power supply and air conditioning in the passenger car.
[0007] A primary vehicle control system is provided in the passenger car, which takes over the control of the essential functions of the passenger car during normal operation.
[0008] In the passenger car, a secondary vehicle control system is provided for emergency operation. This system takes over control of the car's essential functions if the primary vehicle control system malfunctions or fails completely.
[0009] The secondary vehicle control system enables at least a limited technical operation of the passenger car within the framework of a “redundancy control system, RSG”, for example by taking over a simplified control of the lighting, the power supply and a simplified control of a consumer circuit of the passenger car.
[0010] FIG 3 shows a schematic representation of a passenger car PW constructed and protected in this way according to the known state of the art.
[0011] The following functionalities are provided in the passenger car PW:
[0012] 1 - a primary vehicle control,
[0013] 2 - a redundancy control as secondary vehicle control,
[0014] 3 - control elements, 4 - a first I / O system (“input / output system”),
[0015] 5 - a second I / O system (“Input / Output system”),
[0016] 6 - an energy supply,
[0017] 7 - (at least) one consumer group and
[0018] 8 - a lighting.
[0019] The connections between the functionalities shown here are logical connections realized through data traffic. Associated data is transmitted via a common vehicle bus (e.g., Ethernet, MVB, CAN, etc.).
[0020] During normal operation, the primary vehicle control 1 continuously controls all necessary functions of the passenger car PW.
[0021] The vehicle control system 1 uses the first I / O system 4 to send respective control commands to assigned functionalities, namely in particular to the power supply 6, to the consumer circuit 7 and to the lighting 8.
[0022] Accordingly, the primary vehicle control 1 receives the respective signals of the aforementioned functionalities with the aid of the first I / O system 4.
[0023] The first I / O system 4 also receives control commands from the control elements 3, with which train personnel can carry out operating actions (e.g. switching lights on or off or dimming, etc.).
[0024] Redundancy control 2 is activated in the described normal operation, but does not itself control the functionalities via control commands.
[0025] The redundancy control 2 continuously monitors the function of the primary vehicle control 1 or the function of the first I / O system 4 with the help of appropriate sensors.
[0026] If the redundancy control 2 detects a fault, it takes over control of the functionalities considered important in fault mode.
[0027] In this case, the redundancy controller 2 deactivates the primary vehicle controller 1 and transmits control commands to the functionalities deemed essential using the second I / O system 5. In this example, the redundancy controller 2 ensures the correct functioning of the power supply 6, the consumer circuit 7, and the lighting 8.
[0028] The disadvantage here is that the required software, the secondary redundancy control and the second I / O system as well as the data bus required for the connection are kept in reserve for a fault that rarely or never occurs during the life cycle of a passenger car.
[0029] This results in correspondingly high costs for the operation and maintenance of the aforementioned functionalities in each individual passenger car.
[0030] Task
[0031] It is therefore the object of the invention described below to provide a method for a cost-effective and simply constructed safeguarding of functionalities of a passenger car in rail transport.
[0032] This problem is solved by the features of patent claim 1. Advantageous further developments are specified in the dependent patent claims.
[0033] Description of the invention
[0034] The invention relates to a method for safeguarding the functionalities of a passenger car in rail transport. The functionalities of the passenger car are controlled by a primary vehicle control system in the passenger car, with the primary vehicle control system sending respective control commands to the functionalities.
[0035] During normal operation, the primary vehicle control system transmits status information to a communication link in the passenger car. This status information transmits functional information that signals the technical status of the functionalities and the primary vehicle control system.
[0036] The communication link examines the status information. If a fault in the primary vehicle control system is detected, the communication link requests redundant control commands for the functionalities from a fixed control point. The redundant control commands are transmitted from the fixed control point to the communication link. The redundant control commands are transmitted to the functionalities via the communication link when the primary vehicle control system is deactivated, and are executed by them.
[0037] The communication link monitors communication between the communication link and the stationary control point. If a communication failure is detected, a failover function stored in the passenger car is executed via the communication link (9), which sets the functionalities to be controlled to a predefined state or default state.
[0038] In a beneficial further training, the functionalities influence the well-being and safety of passengers in passenger cars.
[0039] In an advantageous further development, the functionalities are used to control a power supply and / or a controlled consumer circuit and / or a control of lighting in the passenger car.
[0040] In an advantageous further development, the communication connection uses the status information transmitted by the vehicle control system to continuously and cyclically create a process image that contains the functional information on the functionalities.
[0041] In an advantageous further development, the process image is transferred to the control point and evaluated there in order to create the redundant control commands.
[0042] Advantages:
[0043] The present invention saves hardware and software costs per passenger car.
[0044] Changes to the redundancy control software are made centrally via the landside and transmitted to assigned passenger cars via remote data transmission (e.g. via mobile phone).
[0045] The present invention allows changes to the redundancy control software to be transferred to all passenger cars in a fleet, or to address only a single car or a group of cars. The present invention enables changes to the redundancy control software to be implemented easily and cost-effectively.
[0046] The present invention eliminates the need for maintenance personnel to perform manual work on passenger cars.
[0047] The present invention makes it possible to make functional adaptations of the control software to different vehicle types or types of passenger cars via the land side.
[0048] Character description:
[0049] The invention is explained in more detail below with the aid of a drawing.
[0050] It shows:
[0051] FIG 1 shows a schematic diagram of a passenger car with a protection device according to the invention,
[0052] FIG 2 in an overview and related to FIG 1 land-based software elements, and
[0053] FIG 3 shows the passenger car described in the introduction as an example of the known state of the art.
[0054] FIG 1 shows a schematic diagram of a passenger car PW1 with a protection device according to the invention.
[0055] The following functionalities are provided in the PW1 passenger car:
[0056] I - a primary vehicle control,
[0057] 3 - Control elements,
[0058] 4 - a first I / O system (“input / output system”),
[0059] 5 - a second I / O system (“Input / Output system”),
[0060] 6 - an energy supply,
[0061] 7 - one or more consumer groups,
[0062] 8 - a lighting,
[0063] 9 - a communication connection,
[0064] 10 - a process image PROAB,
[0065] II - a failure function, and
[0066] 13 - a GPS receiver. The following functionalities are provided in a fixed control point designated as a landside (LS):
[0067] ITSYS - an IT system and
[0068] 15 - a redundancy control.
[0069] The landside LS and the passenger car PW1 are connected to each other via the respective “remote communication with antennas” functionalities 12 and 14, which are preferably part of a mobile radio system.
[0070] The connections between the functionalities shown here are logical connections realized through data traffic. Associated data is transmitted via a common vehicle bus (e.g., Ethernet, MVB, CAN, etc.).
[0071] During normal operation, the primary vehicle control 1 continuously controls all necessary functions of the passenger car PW1.
[0072] The vehicle control system 1 uses the first I / O system 4 to send respective control commands to assigned functionalities, namely in particular to: the power supply 6, the consumer circuit 7 and the lighting 8.
[0073] Accordingly, the primary vehicle control 1 receives the respective signals and information of the aforementioned functionalities with the aid of the first I / O system 4.
[0074] The first I / O system 4 also receives control commands from the control elements 3 at the primary vehicle control 1, with which a train crew can perform an operating action (e.g. switching lights on or off or dimming, etc.).
[0075] During normal operation, the primary vehicle control unit 1 cyclically and continuously sends status information to the communication connection 9.
[0076] This status information contains functional information on the functionalities controlled by the primary vehicle control 1, namely
[0077] - for energy supply 6,
[0078] - to consumer circuit 7, - to lighting control 8,
[0079] - to the control elements 3, as well as
[0080] - to primary vehicle control 1 and
[0081] - to the first I / O system 4.
[0082] The functional information of functionalities 3, 6, 7, 8 allows a statement to be made about the (technical) status of the respective functionality, for example in the form of diagnostic information.
[0083] The functional information of functionalities 1 and 4 allows a statement to be made as to whether these two functionalities are operating smoothly or whether there is a malfunction.
[0084] The status information also contains a so-called “live byte” with which communication failures between sending and receiving functionalities, i.e. failures in data traffic or in the vehicle bus, can be detected.
[0085] Using the status information transmitted by the vehicle control system 1, the communication link 9 continuously and cyclically generates a so-called process image PROAB in a unit 10, which contains the functional information for the following functionalities:
[0086] Energy supply 6,
[0087] - Consumer group 7,
[0088] Lighting control 8,
[0089] Control elements 3, primary vehicle control 1, first I / O system 4.
[0090] The process image PROAB is provided with time information, location information and a suitable checksum in order to detect data corruption.
[0091] The location information preferably comes from the GPS receiver 13, which can also be used to determine the time information if necessary. The process image PROAB is transmitted to the IT system ITSYS on the landside LS using a secure data transmission method (e.g., using VPN tunnel technology) and via remote communication 12 and 14.
[0092] The IT system ITSYS receives and evaluates the process image PROAB based on the transmitted checksum and based on the transmitted time information.
[0093] If the process image PROAB is deemed valid, it is forwarded to further processing onshore. Using the IT system ITSYS, a functional evaluation of the vehicle control system 1 and the first I / O system 4 is performed using the respective functional information transmitted in the process image PROAB.
[0094] If it is determined onshore that the vehicle control system 1 or the first I / O system 4 is malfunctioning, the redundancy control system 15 is activated. Based on the process image PROAB, this system generates suitable control commands with the aim of replacing the malfunctioning primary vehicle control system 1.
[0095] The control commands are generated cyclically and continuously by the redundancy controller 15.
[0096] When generating the control commands, the redundancy controller 15 may also use the location information of the GPS receiver 13 contained in the process image PROAB in order to take local conditions (e.g. upcoming tunnel passages) into account when controlling the functionalities.
[0097] The control commands of the redundancy controller 15 are addressed to the following functionalities:
[0098] Energy supply 6,
[0099] - Consumer circuit 7, and lighting 8.
[0100] If a fault in the vehicle control system 1 or the first I / O system 4 is detected onshore, the onshore IT system ITSYS sends corresponding information along with the control commands from the redundancy control system 15 to the communication link 9. The communication link 9 distributes the control commands from the redundancy control system 15 to the aforementioned functionalities via the second I / O system 5. This ensures at least limited operation of the passenger car PW1.
[0101] The control commands of the redundancy control 15 are again securely transmitted to the passenger car PW1 and checked for their validity via the communication connection 9.
[0102] A special case of the described procedure is the situation when a total failure of the primary vehicle control 1 occurs on the vehicle side. This total failure is directly detected by the communication connection 9 because the status information and "live bytes" normally sent by the primary vehicle control 1 are simply missing in this case.
[0103] In this case, the communication connection 9 requests the creation and retransmission of the control commands of the redundancy control 15 from the land-based IT system ITSYS via the remote communication 12 and 14.
[0104] Further details of the invention are briefly described below:
[0105] For both the transmission path from the passenger car PW1 to the landside and the transmission path back, the receiving unit ignores or discards received signal content if an error or corruption is detected during transmission.
[0106] In this case, the last signal content received and considered valid remains active until an error-free transmission is achieved.
[0107] Both the landside LS and the communication link 9 send back an acknowledgment upon receipt of a valid signal content. This allows the transmitting unit to recognize that new commands or information have arrived and are waiting to be processed.
[0108] If communication between passenger car PW1 and the landside LS is permanently disrupted, a corresponding diagnostic note is displayed on passenger car PW1 and a warning is sent to the driver or train crew. A corresponding diagnostic note is then made on the landside, and landside personnel are informed.
[0109] The passenger car PW1 is designed in such a way that software or transmission errors on the landside LS cannot cause a dangerous situation, and the vehicle's own safety features are appropriate. Optionally, the communication connection 9 can directly access the first I / O system 4. This makes it possible to dispense with the second I / O system 5 if necessary.
[0110] In addition to the above example, a failure function 11 is provided on the part of the passenger car PW1, which controls the functions of the components
[0111] Energy supply 6,
[0112] - Consumer group 7, and
[0113] Lighting control 8 is set to a predefined state or basic state in the event of a fault.
[0114] The failure function 11 is used when the communication between communication connection 9 and the landside LS fails completely or the communication is disrupted.
[0115] The failure function 11 cannot be influenced by the vehicle control 1 or by the communication connection 9.
[0116] The failure function 11 can be updated or influenced by the landside (LS) as long as the associated communication is stable and available.
[0117] FIG 2 shows an overview of land-based software elements related to FIG 1.
[0118] On the land side LS, a software container SW1, SW2, SW3 is stored for each vehicle or for each individual passenger car PW1, PW2, PW3,
[0119] The software container SW1 contains the control commands SB1, which are provided for the passenger car PW1 via the redundancy control 15.
[0120] The software container SW2 contains the control commands SB2, which are provided for the passenger car PW2 via the redundancy control 15.
[0121] The software container SW3 contains the control commands SB3, which are provided for the passenger car PW3 via the redundancy control 15.
[0122] The software container SW1 contains the process image PROAB of the passenger car PW1.
[0123] The software container SW2 contains the process image PROAB of the passenger car PW2. The software container SW3 contains the process image PROAB of the passenger car PW3.
[0124] The software containers SW1 to SW3 are designed so that they cannot negatively influence each other. This ensures that in the event of a software error in a software container for a first passenger car, the control of other passenger cars is not affected.
Claims
Patent claims 1. Procedure for safeguarding functionalities (6,7,8) of a passenger car (PW1) in rail transport, - in which the functionalities (6, 7, 8) of the passenger car (PW1) are controlled by a primary vehicle control (1) in the passenger car (PW1), wherein the primary vehicle control (1) sends respective control commands to the functionalities (6, 7, 8), - in which the primary vehicle control (1) transmits status information to a communication connection (9) of the passenger car (PW1) during normal operation, - in which the status information transmits functional information which signals a technical status of the functionalities and the primary vehicle control (1), - in which the communication connection (9) examines the status information and, in the event of a detected fault in the primary vehicle control (1): o the communication connection (9) requests redundant control commands for the functionalities (6, 7, 8) from a fixed control point (LS), o the redundant control commands are transmitted from this to the communication connection (9), o the redundant control commands are transmitted to the functionalities (6, 7, 8) via the communication connection (9) when the primary vehicle control (1) is deactivated and are executed by them, and - in which the communication connection (9) monitors the communication between the communication connection (9) and the fixed control point (LS) and, in the event of a detected disruption of the communication via the communication connection (9), executes a failure function (11) stored in the passenger car (PW1), with which the functionalities to be controlled are put into a predefined state.
2. Method according to claim 1, wherein the functionalities (6,7,8) influence the well-being and safety of passengers in the passenger car (PW1).
3. Method according to claim 1 or 2, wherein the functionalities (6, 7, 8) control a power supply (6) and / or a consumer circuit (7) and / or a lighting (8) in the passenger car (PW1).
4. Method according to claim 1, wherein the communication link (9) using the status information transmitted by the vehicle control (1) continuously and cyclically creates a process image (PROAB) that contains the functional information about the functionalities.
5. Method according to claim 4, wherein the process image (PROAB) is transmitted to the control point (LS) and evaluated there in order to create the redundant control commands.
6. Method according to one of the preceding claims, in which the fixed control point (LS) provides redundant control commands assigned to a large number of passenger cars (PW1), which are preferably kept in separate software containers and independently of one another.
7. Method according to claim 6, in which the fixed control point (LS) carries out a fleet-wide Verification of functionalities (6,7,8) of the large number of passenger cars (PW1) is carried out.
8. Method according to one of the preceding claims, in which the failure function (11) is adapted to operational conditions by the fixed control point (LS) as needed, as long as communication to the communication connection (9) exists.
Citation Information
Patent Citations
FAO remote driving system based on 5G technology
CN114604300A
Replacement resource for a defective computer channel of a rail vehicle
DE102014206078A1
Transfer of vehicle control system and method
US20180196426A1