Railway signalling controller for trackside assets
A distributed object controller with separated vital and non-vital subsystems addresses the complexity of railway signalling systems, enhancing reliability and maintainability by integrating safety and diagnostic functions efficiently.
Patent Information
- Application Number
- PCT/PL2024/050035
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-21
- Publication Date
- 2025-11-27
AI Technical Summary
Current railway signalling systems for trackside assets, particularly point machines, are complex and expensive due to the integration of vital and non-vital subsystems, leading to increased complexity and maintenance challenges, with a need for an optimized solution that separates safety-related and non-safety-related functions while ensuring high maintainability and reliability.
A distributed architecture for an object controller comprising a main unit and extender units, with vital and non-vital subsystems independent of each other, connected via a communication system, allowing for secure and redundant communication and power supply, ensuring safety and diagnostic functions are separated and integrated efficiently.
The solution reduces system complexity, cabling, and device count, while enhancing reliability, maintainability, and cybersecurity, ensuring both vital and non-vital subsystems operate independently, with secure communication and increased availability.
Smart Images

Figure PL2024050035_27112025_PF_FP_ABST
Abstract
Description
[0001] Railway signalling controller for trackside assets
[0002] Technical field
[0003] The present invention relates to a railway signalling controller, and in particular to an object controller having a distributed architecture, which finds application in the domain of railway signalling for controlling and monitoring trackside assets such as points, signals, axle counters or generic I / O devices. The present invention relates furthermore to an object controller system including the object controller of the present invention and trackside assets connected thereto.
[0004] Background art
[0005] Railway signalling controllers for trackside assets also known as object controllers are broadly used in the railway signalling domain as a part of the railway signalling system responsible for connectivity of interlocking devices with field devices such as point machines, end position controllers, signals, or level crossing barriers etc.
[0006] In most cases the object controllers are located together with an interlocking system or installed as a group of the object controllers in a separate location. The connection of an object controller with the interlocking system is arranged through legacy methods developed by the manufacturers of complete signalling solutions. On the other hand, field devices are directly controlled by the relevant object controller through a cable transferring signals to and from the track assets. In the above cases there are no intelligent devices equipped with processors embedded in the track assets.
[0007] With the growing digitalisation of railways there is a tendency to build more distributed architectures of the railway signalling with the object controllers located nearby the field devices and connected with the interlocking system through a standard communication network using safe and secure protocols. Such solution is presented, e.g., in the European patent application no. EP4101727A1. In some cases a distributed architecture of the object controllers is used with many units arranged in different locations and connected through a communication link.
[0008] In addition, there is a tendency to build redundant communication networks to increase the availability of the system with special devices to manage data collection from functional units located along the track and next to the field devices. Such solution is presented, e.g., in the European patent no. EP2301202B1.
[0009] Problems arising from prior art
[0010] A point, also known as a turnout or a railroad switch, is one of the important track assets in the railway system, and is responsible for changing the direction of moving railway vehicles to different tracks. Depending on the controllable point position, railway vehicles are directed to one of the different tracks, enabling the control over the railway route travelled by the railway vehicles, e.g. trains. There are many different types of points, such as: simple points, double slip points, single slip points, moveable switch diamond crossings or derailers. They are equipped with field devices such as actuators called point machines for driving the movement of the point, and control devices called end position controllers indicating the position of moving parts of the point. With the increasing speed of trains and increasing curves of railway tracks, the railway points become quite extensive technical systems that need an advanced signalling subsystem to be controlled and to ensure the safety of the operation. The movement of the turnout is ensured by a drive and a setting system with the number of actuators increasing as a function of the turnout length. For example, a turnout with a length of 1200 m designed for a speed of 250 km / h for a straight track and 100 km / h for a deviating track needs 1 to 3 point machines to change the position of a switch and 1 to 2 point machines for crossing. For longer turnouts even more than 10 point machines would be needed. This makes the control of such turnouts very complex. In addition, the required proper position of turnout elements is controlled continuously by a dedicated control subsystem (end position control) whose complexity also grows with the length of the turnout.
[0011] The complexity of the point system described above leads to a relatively complicated and expensive vital signalling subsystem with many field devices responsible for the point. At the same time, high requirements related to maintainability lead to the installation of non- vital monitoring systems with many different sensors that are independent from the signalling part and introduce additional complexity.
[0012] Currently, with respect to the control system, two common approaches are used for the point machine control in points. According to the first one, for every field device such as point machine, an individual object controller is provided, wherein the object controllers are controlled directly by the interlocking system in such a way that point machines driving the same point are working in a synchronised way. According to the second approach, a module responsible for controlling object controllers is integrated or co-located together with a group of the object controllers in one separate rack or cabinet.
[0013] To ensure detection of the switch position at a given time, the currently used solutions include devices connected in series with simple cabling, but with difficult troubleshooting in case of failure, or devices connected in parallel with extensive cabling, but with simplified troubleshooting. There is also known an approach with intelligent controllers of position connected in series through a digital bus (disclosed e.g. in EP 3 623 255 Bl) that leads to savings in cabling needs and with simplified troubleshooting.
[0014] In order to improve the maintenance process, monitoring and diagnostic systems for point machines are used that measure, using different sensor technologies, various quantities such as, e.g., currents, voltages, power of the point machine electric motor, pressure and oil level in the hydraulic modules in electrohydraulic point machines, vibration inside the point machine, etc., to estimate the operating and / or technical condition of the point machines and the whole turnout. Those systems are in most cases non-vital and installed separately from the vital part of the control system.
[0015] Taking into consideration the above-mentioned issues and problems in the prior art resulting from the significant complexity of currently used systems used for controlling trackside assets such as turnouts, there is a need in the art to provide an optimised technical solution of combined vital (drive, position detecting) and non-vital (diagnostic, maintenance, security) subsystems to cover the safety needs of turnouts and other trackside assets and to ensure high maintainability. It is therefore an object of the present invention to provide such optimised solution which solves or at least alleviates the above-mentioned problems.
[0016] The present invention provides an object controller for controlling and monitoring railway trackside assets, comprising one or more field devices based on communication with external systems and is characterised in that it comprises at least one main unit and one or more extender units connected to each other by means of a connection scheme enabling mutual communication. The main unit is configured for communicating with at least one of the external systems, and the one or more extender units are each configured for connecting with assigned field devices of the trackside assets. The object controller comprises at least the following subsystems, each distributed among the main and external units: at least one vital subsystem for implementing safety-related functions of the object controller; at least one non-vital subsystem for implementing non-safety-related functions of the object controller; wherein the at least one vital subsystem and the at least one non-vital subsystem are independent from each other; a communication subsystem for providing internal communication within each of the main and external units and between them, as well as communication with the external systems.
[0017] According to one preferred implementation of the object controller, at least one vital subsystem includes a safety subsystem responsible for safety related logic of the object controller, and at least one non-vital subsystem includes a diagnostic and maintenance subsystem responsible for monitoring and diagnostics.
[0018] According to another preferred implementation of the object controller, the subsystems distributed among the main and external units further include at least one of a configuration subsystem responsible for configuring local subsystems of the main and extender units, and a power supply subsystem responsible for supplying power to local subsystems of the main and extender units.
[0019] According to still another preferred implementation of the object controller, the distributed vital safety subsystem of the object controller comprises a main unit safety subsystem and one or more extender unit safety subsystems connected physically and logically via the distributed communication subsystem, wherein the main unit safety subsystem is configured to ensure the safe operation of the trackside assets by: sending command signals to the extender unit safety subsystems configured to directly control the assigned field devices of the trackside assets, which command signals are evaluated by the extender unit safety subsystem, wherein said sending and evaluating are carried out according to safety and / or security rules, and receiving feedback information from the extender unit safety subsystems configured to monitor the assigned field devices of the trackside assets, which feedback information is evaluated by the main unit safety subsystem, wherein said sending and evaluating are carried out according to safety and / or security rules.
[0020] According to still another preferred implementation of the object controller, the distributed non-vital diagnostic and maintenance subsystem of the object controller comprises a main unit diagnostic and maintenance subsystem and one or more extender unit diagnostic and maintenance subsystems connected physically and logically via the communication subsystem, wherein the main unit diagnostic and maintenance subsystem is configured to collect and process diagnostic and monitoring information related to the trackside assets from the extender unit diagnostic and maintenance subsystems configured to directly monitor the assigned field devices of the trackside asset and to store and send monitoring data concerning the assigned field devices of the trackside asset to the main unit diagnostic and maintenance subsystem. According to still another preferred implementation of the object controller, the distributed communication subsystem of the object controller comprises a main unit communication subsystem and one or more extender unit communication subsystems, wherein the communication subsystems are physically connected using a connection scheme enabling mutual communication, and wherein each of the communication subsystems is connected to other subsystems within the unit it belongs to.
[0021] According to still another preferred implementation of the object controller, the main unit communication subsystem comprises: at least one communication processing unit; at least one crypto module connected to or integrated in the communication processing unit; at least one switching communication module for external communication and at least one switching communication module for internal communication. The switching communication module for external communication and the switching communication module for internal communication of the main unit communication subsystem are connected to the communication processing unit individually or as one integrated switching communication module. Each extender unit communication subsystem comprises at least one communication processing unit; at least one crypto module connected to or integrated in the communication processing unit, and at least one switching communication module for internal communication connected to the communication processing unit.
[0022] According to still another preferred implementation of the object controller, the internal connection scheme of the object controller is selected from a serial connection scheme, a cascade topology, a ring topology, a bus topology and a double bus topology.
[0023] According to still another preferred implementation of the object controller, the object controller comprises two or more redundant main units, each of which is connected to the external systems and implements functional redundancy by performing the same functions on both main units, wherein each of the redundant main units is configured to independently provide operability of the object controller and / or internal power supply for the extender units.
[0024] According to still another preferred implementation of the object controller, the internal connection scheme of the object controller is a ring topology and information between the main unit safety subsystem and one or more extender unit safety subsystems is exchanged through a ring connection in such a way that: every information sent from the main unit safety subsystem to the particular extender unit safety subsystem or from the particular extender unit safety subsystem to the main unit safety subsystem is duplicated and simultaneously sent in two opposite directions of the ring connection, and the duplicated information which arrives first to the destined safety subsystem is processed by this safety subsystem, while the duplicated information which arrives later is discarded by it.
[0025] According to still another preferred implementation of the object controller, the main unit safety subsystem comprises at least two processing units connected to each other according to the safety rules and connected to the communication processing unit of the main unit communication subsystem.
[0026] According to still another preferred implementation of the object controller, each extender unit safety subsystem comprises at least two processing units connected to each other according to the safety rules and connected to the communication processing unit of the extender unit communication subsystem within the same extender unit, and connectable to the field device of the trackside asset assigned to this extender unit. According to still another preferred implementation of the object controller, the main unit diagnostic and maintenance subsystem comprises at least one processing unit connected to the communication processing unit of the main unit communication subsystem.
[0027] According to still another preferred implementation of the object controller, each extender unit diagnostic and maintenance subsystem comprises at least one processing unit connected to the communication processing unit of the extender unit communication subsystem within the same extender unit, and connectable to the field device of the trackside asset assigned to this extender unit.
[0028] The present invention further provides an object controller system comprising the object controller as defined in any one of the above-described implementations; one or more railway trackside assets whose field devices are assigned and connected to respective extender units of the object controller in order to be controlled and monitored by the object controller, wherein the field devices of the trackside assets are selected from: point machines and end position detectors of a point; signal lights; and railway signalling infrastructure devices comprising any of digital inputs, digital outputs, analog inputs or analog outputs, or combination thereof.
[0029] According to one preferred implementation of the object controller system, the main unit and / or at least one extender unit is embedded into the trackside asset or its component, or embedded into a connection box thereof.
[0030] The architecture of the object controller according to the present invention is based on an idea of providing a main unit with multiple extender units implemented as SIL4 certified hubs placed in or close to the field devices being the part of track assets to be controlled and monitored along the track, wherein all functions are divided into vital and non-vital subsystems, connected by an integrated transmission system which covers both vital and non- vital communication.
[0031] In the context of the present invention, a vital (sub)system is to be understood as any (sub)system, the function of which affects the safety of train operations. On the other hand, in the context of the present invention, a non-vital (sub)system is to be understood as any (sub)system, the function of which does not affect the safety of train operation. Therefore, whenever the terms "vital" or "non-vital" are used in the present disclosure, with reference to systems, parts, functionalities, logic, circuits or any other elements, they should be respectively interpreted or construed in relation to their impact on the safety of train and railway system operation.
[0032] Whenever used in this specification and claims, the term "safety" as used above means freedom from unacceptable risk. In railway systems the (sub)system safety is classified into five safety integrity levels (SIL), where 0 is the lowest level, and 4 is the highest level. Safety integrity is defined by standards as "ability of safety-related system to achieve its required safety functions under all the stated conditions within a stated operational environment and within a stated duration" (EN 50126-1). In railway systems, the vital subsystem requires most often SIL3 up to SIL4, and the non-vital subsystem requires SILO (basic Integrity) up to SIL2. However, one skilled in the art will understand that the indicated gradation of safety levels and their classification or allocation to the vital and non-vital subsystems is only one possible implementation and does not limit the scope of the present invention. For instance, some different safety scales could be used including more or less safety levels, and / or the allocation (or specific division) of particular levels between the vital and non-vital subsystems could be defined differently according to the particular requirements.
[0033] On the other hand and in contrast to the term "safety", the term "security" is to be understood in the following meaning: a (sub)system or service is considered to be secure to the extent that its users can rely on that it functions (or will function) in the intended way.
[0034] Furthermore, in the context of the present invention, terms such as "trackside assets", "track assets", and the like are to be understood as functional items located in the railway track or in its vicinity and comprising or using one or more field devices. A track asset can be a complex item, such as a point ensuring the possibility of changing the direction of moving trains, that is equipped with dedicated field devices such as, e.g., point machines and end position controllers. In such case, a group of field devices could be seen as forming one track asset. On the other hand, a track asset could be also a relatively simple item or device and could comprise or consist of only one field device such as a signal light informing the train driver, using the predetermined light aspects, whether or not the train can proceed to the next track section. The terms "trackside assets" or "track assets" can be used interchangeably in the present disclosure and include, e.g., turnouts, signals, axle counters, level crossings, etc. One skilled in the art will be aware of further examples not specifically mentioned here but encompassed by the above definition. Similarly, the field devices that are parts of or constitute the exemplary track assets explained above are merely few illustrative examples, and the invention is not limited thereto. One skilled in the art will be aware of various other field devices not specifically mentioned here that could be used individually or in combination in a variety of track(side) assets in connection with the present invention.
[0035] The term "external systems" used in this specification and claims refers to any types of supervisory or higher-level systems that control or monitor the operation of trackside assets, field devices or other railway equipment by means of the object controller according to the present invention with regard to its particular functionalities or subsystems. Some examples of the external systems include an interlocking system, a maintenance management system, a security management system, a configuration management system, etc. As such, particular subsystems included within main and external units of the object controller and performing particular functions may communicate (e.g., receive instructions and send messages) with particular ones of the external systems in order to ensure proper operation of the assigned trackside assets, field devices or other railway equipment.
[0036] The solution according to the present invention provides a number of advantages. First of all, the object controller according to the present invention is a smart solution highly integrating vital and non-vital functionalities, thereby significantly reducing complexity, cabling, and the number of required devices. In this context, smart integration means that the separation of vital and non-vital functionalities is ensured by the novel architecture of the object controller, thereby providing flexibility in increasing the performance of diagnostic, maintenance and security. At the same time, improvements in the non-vital part do not affect the vital part, which is beneficial due to the fact that both parts are independent from each other, and even when the vital part is affected, and a very complicated and expensive procedure of „safety case" is needed, the non-vital part remains undisturbed, and vice-versa. On the other hand, the secure communication to the upstream systems, such as interlocking or maintenance management systems, could be implemented safely using one physical network. As a result, higher reliability, higher availability, and better maintainability are achieved with regard to the overall architecture and operation of the object controller according to the present invention.
[0037] Finally, additional benefits arise from the integrated internal communication system. Firstly, the present invention provides advantages in terms of cybersecurity by the fact that the integrated communication system developed as secure by design enables a high level of cybersecurity of both vital and non-vital subsystems. As a result, secure communication is ensured and the remote upload of software or configuration parameters is secure. Secondly, an increased level of system availability is achieved with an internal cascade forming a ring architecture and communication protocol ensuring that all internal messages between the main and extender units could be sent at the same time through 2 paths using an appropriate redundancy protocol.
[0038] Further features and advantages of the present invention will become apparent after reading a more detailed description of exemplary embodiments presented below in connection with the attached drawing, in which:
[0039] Fig. 1 is a schematic diagram illustrating an architecture of an object controller according to the present invention;
[0040] Fig. 2 in an example of internal logical architecture of main and extender communication subsystems.
[0041] Fig. 3 is an example of an object controller configuration for a turnout equipped with 3 point machines;
[0042] Figs. 4a and 4b are schematic diagrams illustrating possible spatial configurations of main and extender units.
[0043] Fig. 5 is an example of an object controller configuration for railway signal lights.
[0044] Fig. 6 is an example of an object controller configuration for main unit redundancy.
[0045] Fig. 1 illustrates an architecture of an object controller according to an embodiment of the invention. The object controller comprises a main unit OC_Main and one or more extender units OC_Extl, OC_Ex2, OC_ExtN, wherein the main unit OC_Main and the extender units OC_Extl, OC_Ext2, OC_ExtN communicate with each other based on one adopted communication scheme, which is a cascade topology in the present example, however, other communication schemes are also possible, as will be explained further herein. Each of the extender units OC_Extl, OC_Ext2, OC_ExtN is assigned and connected to a respective one of field devices TrackObjectl, TrackObject2, ..., TrackObjectN in order to control and monitor them. One or more of the field devices TrackObjectl, TrackObject2, ..., TrackObjectN shown in the figure can be part of or form a track asset. For example, multiple field devices in the form of point machines may form a track asset in the form of a point, or a track asset can consist of only one field device such as a signal light. Specific embodiments of various combinations are also provided further below in this disclosure.
[0046] The main unit OC_Main comprises a safety subsystem MSA, a diagnostic and maintenance subsystem MSB, a communication subsystem MCom, a configuration subsystem MCFG and a power supply subsystem MPS. The communication subsystem MCom has the function of and is designed for providing internal communication between the main unit OC_Main and the extender units OC_Extl, OC_Ext2, OC_ExtN. Additionally, the communication subsystem MCom has the function of and is designed for providing communication to external systems such as an interlocking system, a maintenance management system, a security management system, a configuration management system or other supervisory or higher-level systems, by means of an external network NET, that in most cases would be a redundant network implemented as two independent networks NET1 and NET2 shown in Fig. 1. The preference for redundancy of the network NET is seen when a high level of availability of the communication is required. In such a case, when one of the networks NET1, NET2 fails, the remaining one is still operational and the overall communication is not affected, enabling continued operation of the object controller without interruption. The other mentioned subsystems are explained in detail further below in this disclosure.
[0047] As can be seen in Fig. 1, besides the above-described main unit OC_Main, the object controller comprises a number of the extender units, wherein three extender units OC_Extl, OC_Ext2 and OC_ExtN, each delineated by a dashed line, connected respectively to the field devices TrackObjectl, TrackObject2 and TrackObjectN have been illustrated. One skilled in the art will understand, however, that the object controller may comprise more or less extender units, depending on specific requirements and needs. Furthermore, as can be easily understood from the figure, each of the extender units OC_Extl, OC_Ext2 and OC_ExtN has a structure of internal subsystems that is analogous to that of the main unit OC_Main, wherein the reference numerals used for subsystems of each of the extender units are provided by adding an appropriate prefix ("E" for extender units as an analogy to "M" for the main unit) and an appropriate suffix, i.e. 1, 2, N for the extender units OC_Extl, OC_Ext2 and OC_ExtN, respectively. As an example, ECom2 denotes a communication subsystem of the second (suffix "2") extender unit (prefix "E"), ESBN denotes a diagnostic and maintenance subsystem of the N-th (suffix "N") extender unit (prefix "E"), and so on. For this reason, only one extender unit OC_Extl is described in detail below, and in case of the rest (OC_Ext2 and OC_ExtN) or possibly further (additional) extender units the reference is to be made to this detailed description, in an analogous manner, unless otherwise specified in the present specification.
[0048] In accordance with the above-defined terminology, the extender unit OC_Extl comprises a safety subsystem ESAI, a diagnostic and maintenance subsystem ESB1, a communication subsystem EComl, a configuration subsystem ECFG1 and a power supply subsystem EPSI. The communication subsystem EComl has the function of and is designed for providing internal communication between the main unit OC_Main and the extender unit OC_Extl. Additionally, when a cascade communication topology is used, the communication subsystem EComl provides communication to the next extender unit, i.e. OC_Ext2 in Fig. 1.
[0049] As presented in Fig. 1, an overall safety subsystem of the object controller is distributed among its constituent units and includes the safety subsystem MSA of the main unit OC_Main and safety subsystems ESAI, ESA2, ..., ESAN of the particular extender units. The MSA, ESAI, ESA2, ...,ESAN subsystems each comprises at least two processing units connected to each other according to the safety rules (not illustrated in Fig. 1), working in accordance with one of the safety architecture e.g. 2oo2, 2oo3. The safety subsystem MSA communicates with the external interlocking system via the communication subsystem MCom and has the function of taking and performing safety related commands from the external interlocking system and sending safety related messages to the external interlocking system (collectively denoted as "External Systems" in Fig. 1) via the network NET, i.e. using at least one of the redundant networks NET1 and NET2. The mentioned safety related commands can relate to, e.g., performing a predetermined operation by one or more selected field devices, such as a request for moving to a given position a point controlled and monitored by the object controller in one possible scenario; whereas the mentioned safety related messages can relate to, e.g., a confirmation that the requested operation has been completed, e.g., the point is in the requested position, when considering the same scenario. The realisation of the above commands is performed through communication of the safety subsystem MSA (main unit) to the safety subsystems ESAI, ESA2, ... ESAN (extender units), wherein the vital communication can be implemented by an internal bus, which can also be provided redundantly in order to improve reliability. Additionally, automatized safety checks (e.g. distance measurement) as a part of safety inspections of track assets (e.g. point) can be performed. The safety subsystems ESAI, ESA2, ... ESAN are connected through dedicated vital interfaces to the respective field devices TrackObjectl, TrackObject2, TrackObjectN, e.g., actuators being parts of the controlled track asset, and control them directly in a safe manner. In other words, in the embodiment presented in Fig. 1, the safety subsystem MSA (main unit) together with the safety subsystems ESAI, ESA2, ... ESAN (extender units) constitute the overall safety subsystem and implement safety (vital) logic of the object controller. The safety subsystem is a vital subsystem in the context of the present invention, as defined earlier in this specification.
[0050] An overall diagnostic and maintenance subsystem of the object controller is distributed among its constituent units and includes the diagnostic and maintenance subsystem MSB of the main unit OC_Main and the diagnostic and maintenance subsystems ESB1, ESB2, ..., ESBN of the particular extender units. Each of the subsystems MSB, ESB1, ESB2, ..., ESBN comprises at least one processing unit. The diagnostic and maintenance subsystem MSB communicates, via the communication subsystem MCom and the network NET, i.e. using at least one of the redundant networks NET1 and NET2, with external diagnostic systems and external maintenance systems (collectively denoted as "External Systems" in Fig. 1) in order to provide the external diagnostic and maintenance systems with the information or data related to the technical condition of the track asset (its field devices connected to the extender units), and has the function of collecting and processing the information and data provided by the diagnostic and maintenance subsystems ESB1, ... ESBN. The realisation of the above is performed through communication to the diagnostic and monitoring subsystems ESB1, ESB2 ... ESBN (extender units) that are connected through dedicated non-vital interfaces to the respective field devices TrackObjectl, TrackObject2, TrackObjectN being parts of the controlled track asset, and monitor them directly. As such, the diagnostic and maintenance subsystem MSB (main unit) together with the diagnostic and maintenance subsystems ESB1, ESB2, ... ESBN (extender units) constitute the overall diagnostic and maintenance subsystem and implement non-safety (non-vital) logic of the object controller in the embodiment presented in Fig. 1. The diagnostic and maintenance subsystem is a non-vital subsystem in the context of the present invention, as defined earlier in this specification.
[0051] An overall configuration subsystem of the object controller is distributed among its constituent units and includes the configuration subsystem MCFG of the main unit OC_Main and configurations subsystems ECFG1, ECFG2, ..., ECFGN of the particular extender units. The configuration subsystem MCFG communicates, via the communication subsystem MCom and the network NET, i.e. using at least one of the redundant networks NET1 and NET 2, with external configuration management systems (collectively denoted as "External Systems") in order to obtain the required configuration information defining the object controller functionality. The configuration subsystem MCFG stores the configuration information after receiving it from the external configuration management systems. The configuration subsystem MCFG communicates with all internal subsystems of the object controller and shares the specific configuration data with them. As a result, all subsystems of the main unit OC_Main and of the extender units OC_Extl, OC_Ext2, ... OC_ExtN obtain the respective configuration data. The realisation of the above is performed through the communication subsystems MCom (main unit) and EComl, ECom2, ... EComN (extender units), respectively. The configuration subsystems ECFG1, ECFG2 ... ECFGN store the information about the identity of the respective ones of the extender units OC_Extl, OC_Ext2, OC_ExtN they belong to, in order to communicate properly with the main unit OC_Main. In addition, the configuration subsystems ECFG1, ECFG2, ... ECFGN of the extender units obtain the configuration information from the configuration subsystem MCFG of the main unit and share it with their local subsystems (ESA, ESB, ECom). As such, the configuration subsystem MCFG of the main unit together with the configuration subsystems ECFG1, ECFG2, ..., ECFGN constitute the overall configuration subsystem and implement the configuration logic of the object controller in the embodiment presented in Fig. 1.
[0052] An overall communication subsystem of the object controller is distributed among its constituent units and includes the communication subsystem MCom of the main unit OC_Main and communication subsystems EComl, ECom2, ..., EComN of the particular extender units. The main function of the communication subsystem MCom is to ensure communication between the object controller and the external systems, such as the interlocking system, maintenance management system, security management system, configuration management system etc. (collectively denoted as "External Systems"), which is implemented by one or both of the redundant networks NET1 and NET2 according to the present embodiment illustrated in Fig. 1. Communication between the subsystems (e.g. MSA, MSB) of the main unit OC_Main via the communication subsystem MCom and with the above- mentioned external systems and possibly other external systems not specifically mentioned in the present embodiment can be implemented by any suitable secure communication technology or technique, including wired, wireless, and optical (fiber) communication, however, one skilled in the art will be also aware of other possible secure communication technologies or techniques, e.g., communication encryption, secure updates, cryptography, key management, time synchronisation, etc.
[0053] Additionally, the communication subsystem MCom ensures internal communication to the subsystems in the main unit OC_Main and, together with the communication subsystems EComl, ECom2, ... EComN, internal communication to the subsystems in the extender units OC_Extl, OC_Ext2, ..., OC_ExtN. The communication subsystem EComl provides communication between the extender unit OC_Extl and the main unit OC_Main (its communication subsystem MCom, which in turn can provide communication to the external systems, as described earlier) as well as the neighbouring extender unit OC_Ext2 (its communication subsystem ECom2) and possibly provides communication with other extender units, e.g. directly (not specifically shown in Fig. 1) or indirectly using a cascade / ring scheme or topology.
[0054] As can be easily understood based on the above-explained example of the extender unit OC_Extl, by way of the communication between the main unit OC_Main and the extender unit OC_Extl (and each of the further or additional extender units), specifically between the respective communication units MCom and EComl, the functionalities of each subsystem of the main unit OC_Main is extended or expanded onto the extender unit OC_Extl which provides these functionalities to the assigned field device TrackObjectl. Using the same principle, more extender units can be provided for further field devices (extender units OC_Ext2, OC_ExtN for field devices TrackObject2, TrackObjectN, respectively, in this example) in order to handle more complex or extensive trackside asset systems.
[0055] As described earlier herein, the embodiment of the invention presented in Fig. 1 uses the cascade topology, according to which the communication unit MCom is connected to the communication unit EComl, which in turn is connected to the communication unit ECom2, and so on, until the communication unit EComN (of the last extender unit OC_ExtN), which is connected back to the communication unit MCom. As the communication units form a closed loop, this connection scheme can be also referred to as a ring topology. The mentioned ring topology can also comprise additional nodes included in the ring sequence, e.g., in the form of additional units, such as a redundant main unit, as will be explained in more detail later in this disclosure with reference to Fig. 6. In case of ring communication using one or two main units, it can be advantageous when every information sent from the main unit to the particular extender or from the particular extender to the main unit is duplicated and simultaneously sent in two opposite directions of the ring connection. The duplicated information which arrives first to its destination, i.e. target safety subsystem, is processed by this safety subsystem, while the duplicated information which arrives later is discarded. In other words, the fastest / shortest path is used for effective communication. Thanks to the use of static redundancy, the above solution is beneficial due to zero network switching time, zero network unavailability time, and prevention of delays in one of the networks. Furthermore, even when the ring is interrupted in one point, this redundant communication scheme can still be effective, because in such situation the target safety subsystem remains reachable in one of the two directions, ensuring high reliability of the object controller.
[0056] However, the present invention is not limited to the presented example and other connections schemes or topologies are possible as well. For example, according to one possible modification, a ring topology combined with the ability of the nodes (i.e. main and extender units) to communicate in two directions between each other could also be provided in order to improve the availability of the system that will not be affected in case when one of the connections between the units is broken due to the fact that every unit has two paths for communication. In addition, when justified, the cascade / ring topology could be replaced by a bus technology. In addition, the extender units can be powered through a power supply bus, that could be doubled in order to increase the availability of the whole system. According to one possible modification, a power supply for one or more units could be provided through the communication network between the nodes (i.e. main and extender units), e.g. as Power over Ethernet (PoE).
[0057] With reference to the above, internal connections between the main unit and one or more extender units and / or between the individual extender units can be implemented using any suitable scheme or technology, with the adequate methods to ensure availability and security of the connection. In the physical layer, e.g., a cascade with a double or single Ethernet pair or a bus with RS485, CAN or other multipoint technology can be used. In order to achieve high availability, a ring connection supported by a specialised protocol such as PRP (Parallel Redundancy Protocol) would be advantageous. One skilled in the art will be aware of further schemes or technologies not specifically mentioned here but suitable for implementing in the mentioned internal connections. As shown in Fig. 2, in one possible implementation, the main unit communication subsystem MCom may comprise at least one communication processing unit, at least one crypto module (e.g. comprising a storage to store cryptographic keys, a dedicated engine to calculate hashes and / or other cryptographic functions) connected to the communication processing unit, at least one switching communication module for external communication (e.g. Ethernet switch) connected to the communication processing unit and in communication with external systems, and at least one switching communication module for internal communication (e.g. TIL switch) connected to the communication processing unit. Similarly, the extender unit communication subsystem EComl, ECom2, EComN (from which only EComl presented in Fig. 2 as an example) may each comprise at least one communication processing unit, at least one crypto module (e.g. comprising a storage to store cryptographic keys, a dedicated engine to calculate hashes and / or other cryptographic functions) connected to the communication processing unit and at least one switching communication module for internal communication (e.g. TIL switch) connected to the communication processing unit, wherein the switching modules for internal communication are connected to each other for implementing internal communication between the communication subsystems MCom and EComl. Although not specifically shown in Fig. 2, it will be understood that the switching module for internal communication of the communication subsystems MComl is connected to a switching module for internal communication of the further communication subsystem (ECom2), and so on, such that internal communication between the communication subsystems (or more generally between the main and extender units) can be effected. It should be noted that the above description refers to the logical architecture of MCom and EComl subsystems, while a physical implementation can integrate multiple units and modules into one, e.g., the crypto module can be integrated with the processing unit and / or the switching module for external communication with the switching module for internal communication. In all cases, additional units and / or modules may be provided as required.
[0058] An overall power supply subsystem of the object controller is distributed among its constituent units and includes the power supply subsystem MPS of the main unit OC_Main and power supply subsystems EPSI, EPS2, ..., EPSN of the particular extender units. The power supply subsystem MPS provides electrical energy supply for all the subsystems of the main unit OC_Main. If needed, it could provide also the extender units with the electrical power supply, e.g., by means of a suitable wiring. Alternatively, the extender units can be powered independently from the main unit OC_Main. The power supply subsystems EPSI, EPS2, ..., EPSN provide electrical energy supply for all the subsystems of the extender units OC_Extl, OC_Ext2, ...OC_ExtN, respectively. Furthermore, power supply of the main and extender units could be also provided using a doubled bus or, as mentioned earlier, additionally using Power over Ethernet (PoE). Consequently, one skilled in the art will understand that communication and power supply in the object controller according to the present invention can be implemented integrally (e.g. using PoE) or separately and various combinations of each of these functions are possible.
[0059] The object controller provided with the proposed architecture in accordance with the present invention may be used in many configurations both in terms of functionality and the way it is installed. As indicated below, a number of various functionality scenarios is possible for the inventive object controller:
[0060] Object controller for a single track asset including one or more field devices.
[0061] Object controller for multiple track assets of the same kind (e.g. points). • Object controller for multiple track assets of different kind (e.g. points mixed with signals).
[0062] From the installation perspective there are many possibilities, as examples below:
[0063] • OC_Main and OC_Ext units are installed in one location (e.g. in a container or a cabinet).
[0064] • OC_Main and OC_Ext units are installed in different locations, e.g. OC_Main in a location with easy access to the transmission network and OC_Ext in a location close to the field devices.
[0065] • As in the above example but with some units (both main unit and extender units) installed inside a field device (e.g. in a point machine) so that the overall robustness of the object controller is improved, e.g., by providing its waterproofness and easy connections between the units and particular field devices.
[0066] Fig. 3 illustrates an example of an object controller configuration for a turnout equipped with 3 point machines. Here, the turnout is one example of track assets, whereas the point machines are examples of field devices. In this exemplary embodiment, the object controller comprises one main unit OC_Main and three extender units OC_Extl, OC_Ext2, OC_Ext3 connected in a cascade. Internal power supply is provided from the main unit OC_Main to each one of the extender units OC_Extl, OC_Ext2, OC_Ext3, as indicated by solid branched arrows. It is to be noted that the reference signs used in Fig. 3 are similar to the ones used in Fig. 1 which means that the architecture of the object controller presented in Fig. 3 corresponds to what has been already explained in detail above with reference to the embodiment from Fig. 1. However, for the sake of transparency, the detailed internal structure (particular subsystems) is omitted here. The extender units are each assigned to respective point machines, i.e., Point Machine 1, Point Machine 2 and Point Machine 3, designed for driving the turnout. To this end, the point machines synchronously push or pull predetermined moving parts (switch rails) of the turnout between two end positions to ensure that moving trains are directed to one of the two tracks (straight one or right one in Fig.3). In order to fulfil its function, each point machine is equipped with, among others, an electric motor and a drive mechanism to provide mechanical motion of the switch rails, as well as with sensors or detectors that monitor the position of the switch rails. Point machines are well- known in the art, therefore further detailed description is here omitted. It is the role of the object controller to ensure proper operation of the turnout by controlling and monitoring all its point machines. The main unit OC_Main performs all the interfaces to the interlocking, diagnostic and maintenance related supervision systems, collectively indicated as External Systems in Fig. 3. In addition, the main unit OC_Main provides the extender units OC_Extl, OC_Ext2, OC_Ext3 with power supply and communication. The extender units OC_Extl, OC_Ext2, OC_Ext3 connected to the main module OC_Main perform the control (vital) and diagnostic (non-vital) interface to the point machines (drives, detectors, sensors). For the sake of transparency and as mentioned above, detailed internal structure of the main and extender units is here omitted and in this respect reference should be made to Fig. 1 and the corresponding description.
[0067] The extender units OC_Extl, OC_Ext2, OC_Ext3 are each connected to the particular ones of the point machines, as schematically indicated by dashed lines. These connections to the point machines ensure, on one hand, the realisation of vital functions, such as moving the turnout or controlling the position of the turnout switch, and separately, on the other hand, the realisation of diagnostic (non-vital functions) such as sensing the voltage and current drawn by the electric motor, or the pressure and oil level inside an hydraulic driving unit in case where an electrohydraulic point machine is applied instead of an electric one. The logic embedded into the main unit OC_Main can control, through the extender units OC_Extl, OC_Ext2, OC_Ext3, all point machines independently, ensuring a proper sequencing of movement of each point machine. Although not specifically illustrated in Fig. 3, the connections indicated by the dashed lines are to be understood as including at least two separate connection lines, as presented in Fig. 1 (i.e. ESA and ESB subsystems separately connected to the field devices).
[0068] The extender units OC_Extl, OC_Ext2, OC_Ext3 are each connected to an external power supply, as schematically indicated by dotted lines. These connections ensure power supply of track objects (point machines in this example) which is switched and controlled by extender units and can be connected in a bus, star or other form. Depending on the particular type of track objects, this power supply can be AC, DC with different voltage and frequency levels.
[0069] The object controller, in a similar way as in Fig. 3, can be configured to be applicable in numerous vital applications, such as:
[0070] • single point machine and single or multiple end position detectors connected in series;
[0071] • single point machine and multiple end position detectors with individual connections;
[0072] • multiple point machine and multiple end position detectors; and others - as required by the specific installation scenario.
[0073] At the same time, the non-vital subsystem responsible for diagnostics (e.g. subsystems MSB, ESB1, ESB1, ESBN explained with reference to Fig. 1) can be configured to measure different signals providing information about the technical condition of the point machines and the whole turnout. For example, this information about the technical condition may include the current and voltage of electric motors in the point machines, the oil pressure and level in the electrohydraulic units, the temperature of rail, the vibration or / and shocks inside or outside the point machine, etc.
[0074] Figs. 4a and 4b are schematic diagrams illustrating possible spatial configurations of an object controller. Similarly to the diagram illustrated in Fig. 3, the object controller comprises in both figures one main unit OC_Main and three extender units OC_Extl, OC_Ext2, OC_Ext3. The main and extender units are connected by means of mutual connections illustrated in the figures in the form of thick two-sided arrows. The main unit OC_Main is also connected to external systems. Furthermore, in addition to communication lines, in both configurations internal power supply is provided from the main unit OC_Main to each one of the extender units OC_Extl, OC_Ext2, OC_Ext3, as indicated by solid branched arrows. Moreover, the extender units OC_Extl, OC_Ext2, OC_Ext3 are each connected to an external power supply, as schematically indicated by dotted lines (see also explanation in reference to Fig. 3). For the sake of transparency, particular field devices are not illustrated but only a collective block of trackside assets is presented. Although not specifically illustrated in Figs. 4a and 4b, the connections indicated by the dashed lines between the extender units and the trackside assets are to be understood as including at least two separate lines, as presented in Fig. 1 (i.e. ESA and ESB subsystems separately connected to the field devices). After describing common features, below differences between both configurations in Figs. 4a and 4b are explained. In an embodiment presented in Fig. 4a, the main and extender units are connected in a cascade and create a ring, i.e. the main unit OC_Main is connected to the first extender unit OC_Extl, which in turn is connected to the second extender unit OC_Ext2 and so on, until the last extender unit OC_Ext3 which is connected back to the main unit OC_Main, thereby forming a connection ring. Connections between units are implemented by a reliable and advanced interface - Ethernet TIL, which is specifically designed for long-distance Ethernet connections. The configuration of the object controller enables a distributed connection between units, with a maximum distance of 1000 m between each unit.
[0075] In the configuration presented in Fig. 4a, the main unit OC_Main and the extender units OC_Extl, OC_Ext2, OC_Ext3 are connected in a cascade and are installed in different locations, e.g. the main unit OC_Main is installed in a location with easy access to the transmission network, what is indicated by a first area delineated by a dashed line, and the extender units OC_Extl, OC_Ext2, OC_Ext3 are installed in a location close to the field devices, what is indicated by a second area delineated by a dashed line. In special cases, the extender units OC_Extl, OC_Ext2, OC_Ext3 could be installed inside a field device, e.g. inside a point machine. In this configuration the costs of cabling between the extender units and field devices, e.g. points, are reduced.
[0076] In the configuration presented in Fig. 4b, a centralized approach is used, where the main and extender units are arranged in the same location, e.g. in the same rack or cabinet, what is indicated by an area delineated by a dashed line and encompassing all the units of the object controller.
[0077] Each configuration can be customized individually based on the relevant application and the available physical transmission network and power supply. For example, in one object controller some extender units could be installed in the same location with the main unit and some in a remote location or locations, e.g., embedded into a field device such as point machine.
[0078] It is should be noted that physical topology does not affect the operation of the object controller. Both configurations (centralized and distributed) has identical principle of operation.
[0079] Fig. 5 illustrates an example of an object controller configuration for railway signal lights. In this exemplary embodiment, the object controller comprises one main unit OC_Main and two extender units OC_Extl, OC_Ext2 connected in a cascade. Internal power supply is provided from the main unit OC_Main to each one of the extender units OC_Extl, OC_Ext2, OC_Ext3, as indicated by solid branched arrows. It is to be noted that the reference signs used in Fig. 5 are similar to the ones used in Fig. 1 which means that the architecture of the object controller presented in Fig. 5 corresponds to what has been already explained in detail above with reference to the embodiment from Fig. 1. However, for the sake of transparency, the detailed internal structure (particular subsystems) is omitted here. Moreover, the extender units OC_Extl, OC_Ext2 are each connected to an external power supply, as schematically indicated by dotted lines (see also explanation in reference to Fig. 3). Although not specifically illustrated in Fig. 5, the connections indicated by the dashed lines between the extender units and the trackside assets (Sigi, Sig2 in this example) are to be understood as including at least two separate lines, as presented in Fig. 1 (i.e. ESA and ESB subsystems separately connected to the field devices Sigi, Sig2). In this embodiment, the extender units OC_Extl, 0C_Ext2 are each assigned and connected to respective railway signal lights Sigi, Sig2 which constitute one possible example of field devices connectable to the object controller according to the present invention. Such signal lights are commonly used along railway tracks and inform train drivers, using the predetermined light aspects, e.g. whether or not the train can proceed to the next track section, or provide other important information.
[0080] The main unit OC_Main is connected to external systems and performs all the interfaces to the interlocking, security, diagnostic and maintenance related supervision systems (collectively indicated as external systems). In addition, it provides the extender units with power supply and communication. The extender units OC_Extl, OC_Ext2 connected to the main module perform the control (vital) and diagnostic (non-vital) interface to the railway signal lights Sigi, Sig2. The extender units OC_Extl and OC_Ext2 are connected to the railway signal lights Sigi, Sig2 and installed on signal posts or masts together with the signal lights or inside the signal lights, but are not limited thereto. For this purpose, a connection box can be provided inside the signal posts or masts, or in other suitable location enabling connection between the extender units and the signal lights. The connection between the extender units and the railway signal lights ensures the realisation of vital functions, such us light aspect change, and separately the realisation of diagnostics (non-vital functions), such us sensing the voltages and currents and drawn by the signal lights.
[0081] One skilled in the art will understand that the presented solution is scalable, and there could be more than two signal lights, for example three, four, five or more, and in such cases each further signal light would be provided with an additional extender unit assigned to it. Moreover, particular signal light could be arranged in the same location or close to each other, i.e. on the same signal post or mast or gantry, and / or in a distance from each other. It would be only needed to provide a corresponding number of extender units for each signal light or a group of signal lights, wherein the extender units could be connected one to the other, e.g. in a cascade, to enable control and monitoring / diagnostics of the whole extended group of field devices (signal lights) using only one interface to the external systems provided by the main unit.
[0082] The object controller, in the similar way as illustrated in Fig. 5, can be configured to be applicable in numerous vital applications, such as:
[0083] • one object controller for one railway signal light installed inside or outside the signal light;
[0084] • one object controller for all the signal lights in a zone of the station installed in a convenient spatial configuration. and others - as required by the specific installation scenario.
[0085] At the same time, the non-vital subsystem responsible for diagnostics can be configured to measure different signals providing information about the technical condition of signal lights e.g. temperature, current and voltage of light sources, intensity of light of signals, intensity of ambient light etc.
[0086] Fig. 6 illustrates an example of an object controller configuration for main unit redundancy. In this exemplary embodiment, the object controller comprises two main units OC_Mainl, OC_Main2 and three extender units OC_Extl, OC_Ext2, OC_Ext3 connected in a ring. As in previous examples, for internal structure of the particular units, reference is made to Fig. 1 and the associated explanation. For the sake of transparency, particular trackside objects or field devices are not illustrated in Fig. 6. Internal power supply is provided from both main units OC_Mainl and OC_Main2 to each one of the extender units OC_Extl, OC_Ext2, OC_Ext3, as indicated by solid branched arrows, consequently forming two independent power systems, indicated in Fig. 6 as "Internal power supply 1" and "Internal power supply 2", respectively. Internal communication forms a ring connecting sequentially the main unit OC_Mainl, the extender units OC_Extl, OC_Ext2, OC_Ext3, the main unit OC_Main2, and finally also the main units OC_Main2 and OC_Mainl, what is illustrated in the figure in the form of thick two-sided arrows. Each of the main units OC_Mainl and OC_Main2 is connected to External Systems via a dedicated network NET1 or NET2. In the event that one of the main units OC_Mainl, OC_Main2 fails, the remaining one can still continue performing all functions both with regard to the extender units and the External Systems (functional redundancy). In this way, the operability of the object controller is ensured with high reliability.
[0087] It should be noted that the distinction between the internal and external power supply introduced in the examples provided in the present specification (e.g., in Fig. 3, 4a, 4b, 5 and 6) is only exemplary and other implementations are also possible. The mentioned distinction is due to the fact that internal subsystems of the main and extender units typically require lower voltage compared to the trackside objects or field devices which require higher voltage. One skilled in the art will understand, however, that only one common power supply could be suitably provided and the power supply parameters could by adapted in appropriate manner, such as lowering or increasing voltage with the use of commonly known converters or other electrical circuits, in order to fulfill the power needs of particular subsystems or devices.
[0088] The principles of the invention have been explained in detail using specific embodiments presented and discussed above. It should be noted, however, that the scope of the present invention is not limited to the presented specific examples, and many different modifications and changes could be made to the invention without going beyond its scope defined by the enclosed claims. For example, one skilled in the art will understand that the inventive architecture of the object controller can be applied to any suitable field devices and / or track(side) assets including legacy devices comprising any combination of analog and digital inputs / outputs, the number of extender units can be decreased or increased in accordance with the needs, or the connection topology or scheme can be suitably adapted.
Claims
AMENDED CLAIMS received by the International Bureau on 30 July 2025 (30.07.2025)1. An object controller for controlling and monitoring railway trackside assets comprising one or more field devices (TrackObjectl, TrackObject2, TrackObjectN) based on communication with external systems, characterised in that it comprises at least one main unit (OC_Main) and one or more extender units (OC_Extl, OC_Ext2, OC_Ext3, OC_ExtN) connected to each other by means of a connection scheme enabling mutual communication, wherein the main unit (OC_Main) is configured for communicating with at least one of the external systems; wherein the one or more extender units (OC_Extl, OC_Ext2, OC_Ext3, OC_ExtN) are each configured for connecting with assigned field devices (TrackObjectl, TrackObject2, TrackObjectN) of the trackside assets; wherein the object controller comprises at least the following subsystems, each distributed among each of the main unit and the one or more extender units:- at least one vital subsystem for implementing safety-related functions of the object controller;- at least one non-vital subsystem for implementing non-safety-related functions of the object controller; wherein the at least one vital subsystem and the at least one non-vital subsystem are independent from each other;- a communication subsystem (MCom, EComl, ECom2, EComN) for providing internal communication within each of the main and extender units and between them, as well as communication with the external systems.
2. The object controller according to claim 1, wherein at least one vital subsystem includes a safety subsystem (MSA, ESAI, ESA2, ESAN) responsible for safety related logic of the object controller, and at least one non-vital subsystem includes a diagnostic and maintenance subsystem (MSB, ESB1, ESB2, ESBN) responsible for monitoring and diagnostics.
3. The object controller according to claim 1 or 2, wherein the subsystems distributed among the main and extender units further include at least one of a configuration subsystem (MCFG, ECFG1, ECFG2, ECFGN) responsible for configuring localsubsystems of the main and extender units, and a power supply subsystem (MPS, EPSI, EPS2, EPSN) responsible for supplying power to local subsystems of the main and extender units.
4. The object controller according to claim 2, wherein the distributed vital safety subsystem of the object controller comprises a main unit safety subsystem (MSA) and one or more extender unit safety subsystems (ESAI, ESA2, ESAN) connected physically and logically via the distributed communication subsystem (MCom, EComl, ECom2, EComN), wherein the main unit safety subsystem (MSA) is configured to ensure the safe operation of the trackside assets by: sending command signals to the extender unit safety subsystems (ESAI, ESA2, ESAN), said extender unit safety subsystems being configured to directly control the assigned field devices of the trackside assets, which command signals are evaluated by the extender unit safety subsystem (ESA), wherein said sending and evaluating are carried out according to safety and / or security rules, and receiving feedback information from the extender unit safety subsystems (ESAI, ESA2, ESAN), said extender unit safety subsystems being configured to monitor the assigned field devices of the trackside assets, which feedback information is evaluated by the main unit safety subsystem (MSA), wherein said receiving and evaluating are carried out according to safety and / or security rules.
5. The object controller according to claim 2, wherein the distributed non-vital diagnostic and maintenance subsystem of the object controller comprises a main unit diagnostic and maintenance subsystem (MSB) and one or more extender unit diagnostic and maintenance subsystems (ESB1, ESB2, ESBN) connected physically and logically via the communication subsystem (MCom, EComl, ECom2, EComN), wherein the main unit diagnostic and maintenance subsystem (MSB) is configured to collect and process diagnostic and monitoring information related to the trackside assets from the extender unit diagnostic and maintenance subsystems (ESB1, ESB2, ESBN), said extender unit diagnostic and maintenance subsystems being configured to directly monitor the assigned field devices of the trackside asset and to store and send monitoring data concerning the assigned field devices of the trackside asset to the main unit diagnostic and maintenance subsystem (MSB).
6. The object controller according to any one of the previous claims, wherein the distributed communication subsystem of the object controller comprises a main unit communication subsystem (MCom) and one or more extender unit communication subsystems (EComl, ECom2, EComN),wherein the communication subsystems (MCom, EComl, ECom2, EComN) are physically connected using a connection scheme enabling mutual communication, and wherein each of the communication subsystems (MCom, EComl, ECom2, EComN) is connected to other subsystems within the unit it belongs to.
7. The object controller according to claim 6, wherein the main unit communication subsystem (MCom) comprises:- at least one communication processing unit,- at least one crypto module connected to or integrated in the communication processing unit,- at least one switching communication module for external communication, and- at least one switching communication module for internal communication, wherein the switching communication module for external communication and the switching communication module for internal communication of the main unit communication subsystem (MCom) are connected to the communication processing unit individually or as one integrated switching communication module, and wherein each extender unit communication subsystem (EComl, ECom2, EComN) comprises:- at least one communication processing unit,- at least one crypto module connected to or integrated in the communication processing unit, and- at least one switching communication module for internal communication connected to the communication processing unit.
8. The object controller according to any one of the previous claims, wherein the internal connection scheme of the object controller is selected from a serial connection scheme, a cascade topology, a ring topology, a bus topology and a double bus topology.
9. The object controller according to any one of the previous claims, wherein the object controller comprises two or more redundant main units (OC_Mainl, OC_Main2), each of which is connected to the external systems and implements functional redundancy by performing the same functions on both main units (OC_Mainl, OC_Main2), wherein each of the redundant main units (OC_Mainl, OC_Main2) is configured to independently provide operability of the object controller and / or internal power supply for the extender units (OC_Extl, OC_Ext2, OC_Ext3).
10. The object controller according to claim 8 or 9, wherein the internal connection scheme of the object controller is a ring topology and information between the main unit safety subsystem (MSA) and one or more extender unit safety subsystems (ESAI, ESA2, ESAN) is exchanged through a ring connection in such a way that:- every information sent from the main unit safety subsystem to the particular extender unit safety subsystem or from the particular extender unit safety subsystem to the main unit safety subsystem is duplicated and simultaneously sent in two opposite directions of the ring connection, and- the duplicated information which arrives first to the destined safety subsystem is processed by this safety subsystem, while the duplicated information which arrives later is discarded by it.
11. The object controller according to claim 4 and 7, wherein the main unit safety subsystem (MSA) comprises at least two processing units connected to each other according to the safety rules and connected to the communication processing unit of the main unit communication subsystem (MCom).
12. The object controller according to claim 4 and 7 or 11, wherein each extender unit safety subsystem (ESAI, ESA2, ESAN) comprises at least two processing units connected to each other according to the safety rules and connected to the communication processing unit of the extender unit communication subsystem (EComl, ECom2, EComN) within the same extender unit, and connectable to the field device of the trackside asset assigned to this extender unit.
13. The object controller according to claim 5 and 7, wherein the main unit diagnostic and maintenance subsystem (MSB) comprises at least one processing unit connected to the communication processing unit of the main unit communication subsystem (MCom).
14. The object controller according to claim 5 and 7 or 13, wherein each extender unit diagnostic and maintenance subsystem (ESB1, ESB2, ESBN) comprises at least one processing unit connected to the communication processing unit of the extender unit communication subsystem (EComl, ECom2, EComN) within the same extender unit, and connectable to the field device of the trackside asset assigned to this extender unit.
15. An object controller system comprisingthe object controller as defined in any one of claims 1 to 14, one or more railway trackside assets whose field devices (TrackObjectl, TrackObject2, TrackObjectN) are assigned and connected to respective extender units (OC_Extl, OC_Ext2, OC_Ext3, OC_ExtN) of the object controller in order to be controlled and monitored by the object controller, wherein the field devices of the trackside assets are selected from: point machines and end position detectors of a point; signal lights; and railway signalling infrastructure devices comprising any of digital inputs, digital outputs, analog inputs or analog outputs, or combination thereof.
16. The object controller system according to claim 15, wherein the main unit (OC_Main) and / or at least one extender unit (OC_Extl, OC_Ext2, OC_Ext3, OC_ExtN) is embedded into the trackside asset or its component, or embedded into a connection box thereof.
Citation Information
Patent Citations
Device for controlling and / or monitoring and data retrieval from local functional units along a communication network
EP2301202B1
Method and assembly for monitoring a final position of a railway switch
EP3623255B1
Method and system for processing a projected points track assembly
EP3822145A1
Smart object controller for railway tracks
EP4101727A1
System for distributed automatic train supervision and control
US6032905A