Decentralised, digital railway interlocking system
A decentralized railway interlocking system with SIL4-qualified controllers and rail-based power supply addresses the limitations of centralized systems, enhancing safety and reducing costs by enabling local control and fault tolerance with standardized interfaces.
Patent Information
- Application Number
- PCT/IB2025/058684
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-09-02
- Filing Date
- 2025-08-28
- Publication Date
- 2026-03-05
AI Technical Summary
Existing railway safety systems face limitations in achieving decentralized control functions with unified, rail-based power supply architecture and high Safety Integrity Level (SIL4) compliance, leading to potential central failures and high costs.
A decentralized railway interlocking system with field devices connected via a high-speed communication network, utilizing SIL4-qualified controllers and a rail-based power supply, enabling local control and decision-making, with redundant power and self-diagnostic capabilities, ensuring deterministic data exchange and fault tolerance.
The system achieves high safety and reliability with reduced costs by eliminating central IT systems, ensuring fault tolerance, scalability, and compliance with SIL4 standards, while simplifying installation and maintenance through standardized interfaces and uniform hardware/software platforms.
Smart Images

Figure IB2025058684_05032026_PF_FP_ABST
Abstract
Description
[0001] Decentralised, digital railway interlocking system
[0002] The subject of the invention is a decentralised, digital, 8-layer level railway interlocking safety system, which includes among others decentralised field execution devices, power supply, timetable server, but does not include a central computer system, although, it is capable of connecting to an existing centre.
[0003] Railway safety systems aim to prevent train collisions, derailments, and other accidents, while protecting passengers and crew. They include signalling systems, train control systems (e.g., ETCS, ATP), track and switch monitoring, and communication networks. These systems are in general centralised, where a central control centre supervises and manages traffic over a large area (such as modem traffic control centres), but sometimes local redundancy is maintained for safety reasons. The traffic management and safety monitoring are concentrated in one or a few large regional control centres. Train positions, speeds, routes, and track conditions are monitored in real time, while signals and switches are operated remotely from control panels. Spot data transmission devices, as balises placed along the track, act as transponders that communicate fixed or variable data to passing trains — such as location references, speed restrictions, or signal aspects. In systems like ETCS, they provide accurate positional information that complements continuous radio-based supervision, ensuring the train’ s onboard computer has up-to-date safety data. The drawback is that a central failure (such as a communication outage or power loss) can disrupt a large area’s traffic, which is why redundant communication links and backup control facilities are critical.
[0004] Patent application No. US 20090143928A1 discloses a distributed semiconductor-based railway safety interlocking system in which the interlocking logic is allocated to intelligent signalling peripherals connected via a high-speed data network, each processing real-time status data and controlling its own operation. The application does not include a rail-based power supply, does not ensure that all outdoor components comply with the SIL4 safety integrity level, and does not provide that the general hardware and software platform in each outdoor component, in itself, complies with the highest safety integrity level (SIL4). Patent application No. EP 3176049A1 describes a device and method for controlling or monitoring decentralised functional units in a railway network, enabling safety functions to be shifted from a central system to outdoor units, reducing or eliminating the indoor central system.
[0005] Patent No. US 11021178B2 relates to an autonomous railway control system comprising multiple independently operating elements, each managing a designated track area under predefined rules, exchanging operational data, and negotiating track allocation based on assigned priorities.
[0006] Patent No. JP 7313845B2 discloses a railway control system with multiple processing units located at different stations, each storing information about others and independently deciding its primary or secondary status to maintain operation without a single central unit.
[0007] Patent application No. US 6032905A represents earlier railway safety system designs employing centralised control, where interlocking and signalling functions are concentrated in a central supervisory unit. The main difference between the cited patent and the patent application is that, in the present invention, all control functions are implemented within the trackside elements, namely the sensors and actuators — rather than in separate control units, as in the cited patent.
[0008] The above patent applications present solutions that implement various levels of decentralized execution of control functions in railway signalling systems. However, the knowledge obtainable from the disclosed documents and their combinations, as well as the obligatory knowledge of an electrical engineer experienced in the design of railway systems and in communications, is not sufficient to create a system that implements all functions of the distributed system according to the present invention, particularly with regard to the unified, rail-based power supply architecture and the high SIL4 safety integrity level of all subunits forming the system, as well as the generic hardware and software platforms of these subunits.
[0009] In railway safety systems, the hardware (HW) platform comprises the physical computing infrastructure, including industrial controllers or embedded processors, memory and storage units, input / output interfaces, redundant power supplies, and communication modules adapted for railway protocols, all designed to meet environmental and electromagnetic standards such as EN 50155 and, where required, Safety Integrity Level 4 (SIL 4) under EN 50126 / 50716 / 50129. SIL 4 represents the highest defined level of safety integrity in railway applications, corresponding to a probability of dangerous failure per hour in the range of 10“9to 10“8. The software platform (SW) constitutes the execution environment for safety applications, typically including a real-time or embedded operating system, signalling protocol stacks, certified safety libraries, and supporting frameworks, developed in accordance with standards such as EN 50128 or EN 50716, with development rigour aligned to SIL 4 requirements. Together, the hardware and software platforms form a certified basis for implementing safety-critical railway functions.
[0010] The purpose of the invention is to eliminate limitations in the prior art, as outlined above. The foregoing and other objects are achieved by the features of the independent claims. The inventive step is based on the recognition that by decentralizing individual functions, extreme fault tolerance can be achieved, as each local system element can take over the failed function of another. Moreover, this also results in significant cost savings, which is also one of our goals.
[0011] At this railway interlocking system the functions of the central computer, or a network thereof is allocated to the controls of the field elements (signalling devices, switches, barrier machines, axle counters, track circuits, etc.). Controllers are all connected to a high-speed, encrypted communication network. This distributed system takes over the functions of the centralised railway control. Field elements are controlled locally, at least one of them realising all classical automation layers of a traditional railway safety control system. Every controller in the system is SIL 4 qualified (acc. to EN 50126, EN 50 129 and EN 50 716), realising both high safety and overall system reliability, availability. Unified system architecture makes it also possible to provide a common user interface for every controller. Power supply is also simplified, by a new, rail-based architecture.
[0012] According to the above purpose, the most general implementation form of the solution according to the invention is described in claim 1. The individual implementation forms are described in the sub-claims. In general, the solution is a decentralised railway interlocking system, which includes decentralised field devices, power supply, timetable server. The invention is characterized by the followings: it consists at least one network with the field devices, each field device connected to a controller, the controllers are connected to the network via a wire or an optical cable, with two-way data transfer connection and at least one of the controllers is suitable for control any field device of any network and the controller has a safety level of SIL-4.
[0013] Another implementation form may be where the networks are connected to each other via routers. Each field device consists one of the followings: a point machine, a railway signal, an axle counter sensor, a track circuit, a key cabinet, an ETCS balise, an RFID reader, a level crossing signal, a barrier machine.
[0014] It may be another feature that it has a human machine interface and a log server, moreover, the power supply is provided via a rail bus.
[0015] The invention is presented in more detail by examples of implementation, using drawings.
[0016] Figure 1 is an exemplary circuit diagram of the system,
[0017] Figure 2 is a schematic layout of a simplified embodiment.
[0018] The example on figure 1 shows a geographically distributed, self-organising railway interlocking system consisting of several logically overlapping high-speed serial communication networks 13A, 13B, 13C, 13D. This example consists of four, time-triggered optical networks 13A, 13B, 13C, 13D, with only a few numbers of interlocking system elements, that means field devices 17 with controllers 16 on each network 13A, 13B, 13C, 13D. In reality, the number of networks 13A, 13B, 13C, 13D is unlimited and the number of field devices 17 is restricted only by the bandwidth of the network 13A, 13B, 13C, 13D used and the prescribed message delivery time between field devices. All field devices 17 are connected to a network 13 A, 13B, 13C, 13D and their routers 14 communicate with other via messages on the network 13A, 13B, 13C, 13D. There is no restriction, in which order controllers 16 are connected to the network 13A, 13B, 13C, 13D.
[0019] If an interlocking system element controller 16 on a network 13A, 13B, 13C, 13D wants to communicate with another interlocking system element controller 16 on a different network 13A, 13B, 13C, 13D, e.g. controller 16 of the barrier machine 9 on network 13A with one of the two railway signal’s 2 controller 16, on network 13B, it happens trough the router 14.
[0020] The role of routers 14 is to relay the necessary information from one network 13A, 13B, 13C, 13D to the other, using a proper information filtering mechanism. This filtering mechanism makes it possible that:
[0021] • information between controllers 16, physically close to each other, but belonging to a neighbouring network, or
[0022] • information, which is relevant for multiple networks 13A, 13B, 13C, 13D or on system level e.g. central timetable server 11 or human machine interface 10, operator level central visualisation is relayed to the adjacent network, or be distributed systemwide. On the other hand, information of the certain controllers 16, which is already irrelevant for the next network(s), is filtered out from the communication stream, to decrease network load.
[0023] On Figure 1, three pc routers 14 are depicted, where:
[0024] • one router 14 (on top, right) connects regional networks 13A and 13B,
[0025] • one router 14 (on the middle, left) connects all regional networks 13A 13B, 13C and 13D,
[0026] • one router 14 (on the middle, right) connects regional networks 13B and 13D.
[0027] Every controller 16 unit of a field device 17, e.g. that of an axle counter sensor 3, point machine 1, railway signal 2, barrier machine 9, etc. is connected to the high-speed network 13A, 13B, 13C, 13D, described in the previous paragraph. The type of interlocking system element to be connected to the regional network 13A, 13B, 13C, 13D is determined by the task, the interlocking system has to carry out.
[0028] Every interlocking system element consists of two parts:
[0029] • Electronic control unit, described next
[0030] • The actual, “physical” field devices 17, e.g. signalling device, with its mechanic frame, lighting elements, cables, etc, or barrier machine, with its barrier, motor, switches, cables, control cabinet, etc.
[0031] The controllers 16 consist of two parts:
[0032] 1. A unified, common control unit, containing: a. A redundant, SIL4 (the highest safety integrity level) graded hardware, with proper self-diagnostic capability, b. Communication capability via a high speed, time triggered serial link, e.g. Ethernet, c. A real-time kernel, to run both the system tasks (self- diagnosis, communication, etc.) and the application, i.e. the interlocking system related tasks (layer 1-8), d. Software stack, realising layers 2-8 of the interlocking system.
[0033] 2. A device specific subsystem, consisting of: a. Physical input and output circuits of the field device, the controller 16 is connected to part of layer 1.
[0034] These field device 17 specific circuits contain for example: i. in case of a signalling device, the driver circuits of the lighting bodies, LEDs, feedback signals from the lighting bodies, LEDs to make sure that the turn on / off commands have been properly carried out. ii. In case of an axle counter sensor controller 3, the sensor interfaces to the main control board and the test circuitry to test the sensors, iii. In case of a switch, the driver circuits of the electro-hydraulic or electro-mechanic actuators moving the mechanics and the feedback signals of the mechanics’ actual position iv. In case of a barrier machine, the outputs, driving the hydraulic / electric motors, and the inputs, handling the feedback signals from the barrier machine;
[0035] Every device finds its exact place within the entire system automatically, without manual intervention or configuration.
[0036] In Figure 1, network 13 A consists of the following field devices 17: two pc point machines 1, two pc axle counter sensors 3, RFID reader 7, barrier machine 9, level crossing signal 8, key cabinet 5. The log server 12 also connects to the network 13A. The network 13B consist two pc point machines 1, three pc railway signals 2, an axle counter sensor 3, and two pc track circuit 4. The regional network 13 A is connected to regional network 13B via router 14. Similarly, the spot transmission device, like ETCS balise 6 connects to the network 13D. The human machine interface 10 and the timetable server 11 are also shown in the figure 1. Power supply for all interlocking system elements, controllers 16 are realised via the electric power rail bus 15.
[0037] The interlocking system elements’ controllers 16 independent from the device it is controlling, serve as a controller 16, controlling the operation of the railway, and connecting road traffic in its neighbourhood, with its specialised, device dependent task. In other words, it means that a decision, which will be carried out by every control unit, will be made by a device itself (see also next two paragraphs). The device in question collects the necessary information from other controllers 16, which have impact on the local situation (sensor values, statuses, etc.) sent on the serial link then it makes the decision, using its local, device and location dependant parameters and / or local logic. To reach a very high safety, general decision-making mechanism is that for all controllers 16, which are to decide a possible new state of the equipment it controls, e.g. a combination of lights of a signalling device, a position of a point machine 1, to up / down state of a barrier machine 9, etc., decision is always made by multiple controllers 16.
[0038] The set of information, which serves as a base for the decision making, is evaluated in parallel by different controllers 16 connected to the same optical network 13A, 13B, 13C, 13D. These controllers 16 will also use the parameters and consider the same logic, which is relevant for the control unit, implementing the decision. The decision of the controllers 16 being involved in the decision-making process (e.g. to set the right combination of lights in a signalling device, to maintain or change the track of a point machine 1, to lift, or lower the barrier, etc.) is communicated with the device’s control unit, that will act upon the decision. Depending on the possible impact of the decision, several decision-making rules can be applied, like:
[0039] • all controllers 16 should evaluate the situation in the same way and only in this case does the controller 16 turn the lamps on / off in a way that train is free to proceed, or
[0040] • majority vote of the controllers 16 is accepted.
[0041] In both cases, the controllers 16 “voting” against the majority vote is reported to a service centre for further consideration. Considering that all controllers 16 by themselves are SIL 4 graded, plus in every decision, multiple, also SIL4 graded control units are involved, it results in a very high safety and reliability on system level, at minimum cost.
[0042] Point machines 1 route the trains in a way, that every point machine 1 calculates the optimum route for the train, that is going to pass through it. The destination of the train to be routed comes from the time-table or the overcontrol layer, so an optimisation task is carried out at every point machine 1, considering the current and the future traffic situation. Railway network is described by a 3D graph, i.e. by a mathematical structure, consisting of nodes and edges, so according to the type of train, current or future traffic situation, cost considerations, optimisation criteria can be:
[0043] • Minimum time to reach the destination
[0044] • Minimum cost
[0045] • A balanced infrastructure utilisation
[0046] • A combination of the above criteria
[0047] • Other criteria, which is relevant in a real traffic situation On Figure 1, e.g., when timetable server 11 on network 13C instructs the interlocking system to move a train from a track controlled by network 13 A to a track, which is controlled by network 13B, the following happens:
[0048] • The responsible controller 16 on network 13A is the level crossing signal’s 8 (this assignment had been made before train approached track on network 13 A), hands over the operation control, by a load balancing algorithm to e.g. the controller 16 of a track circuit, on network 13B, which will be the master controller 16 for this certain train. The same algorithm also selects other controllers 16, e.g. the two point machines’ 1 controllers 16, and one of the track circuit 4 controllers 16, to act as slave controllers 16, for this train in question.
[0049] • The master controller 16 and the slave controllers 16 determine the route of the train from the information received by the time table server 11, the current traffic situation, the status of the different interlocking system elements, the physical architecture of the rail network and the instructions of the traffic control, which tracks the train will move. After finishing the calculation the master and slave controllers 16, vote. If the result is unequivocal, the master controller 16 instructs the necessary interlocking system elements, that means field devices 17 in our case e.g. one of the point machines 1 and one of the railway signals 2, to change their actual status to a new one. If there is a controller 16, voting against the majority vote, it is excluded and this resolution is submitted to the nearest service station.
[0050] • The above instructions will be carried out by the certain interlocking system element. In case of an actuation error, e.g. the mechanism of the barrier machine 9 is stuck, the certain interlocking system element is brought to a safe state, furthermore it is excluded from operation and this information is submitted to the nearest service station.
[0051] • The same procedure is carried out on the track controlled by the network 13B, along the route of the train, involving the necessary interlocking system elements.
[0052] • When the train leaves to a track controlled by another network, e.g. 13C, master voter hands over the control to another master and multiple slaves, belonging the new network. In our case they can be e.g. track circuit 4 as a master, and controllers 16 of other field devices 17 with item number 1, 2, 3, 9 on network 13C. All interlocking system elements have a unified user interface 18, which is a device and vendor specific user interface, so authorised service and maintenance personnel can immediately have detailed and precise information both at site and in a service centre, about:
[0053] • The controlled interlocking system’s internal states, statuses, errors, warning, logs, etc.
[0054] • The interlocking system’s actual states, ongoing processes, events, logs, etc.
[0055] According to the authorisation level of the person logging-in the system, the type of interlocking system element, its location in the graph, the complexity of the site, different services are available:
[0056] • to monitor the interlocking system element’s internal states and its history,
[0057] • to bring the interlocking system element into a safe state (e.g. to change the signals’ lights to stop, to lower the barrier mechanism, etc.),
[0058] • to change the state of the interlocking system element to a non-safe state, partially or completely.
[0059] The interlocking system element specific information can also be shared via the network with the service centres, where the same information can be processed in real-time, so, e.g. decision can be immediately made on the repair of a faulty field device, device utilisation data can be stored and evaluated to establish maintenance decisions, etc.
[0060] All interlocking system elements provide unified train control as a system service, that is based on the current track occupation information, providing:
[0061] • signalling and movement grant signals
[0062] • maximum speed
[0063] • route data.
[0064] • This function controls the balises to submit the information to the train and receives the information (e.g. exact position, speed, etc.) from the train.
[0065] • The data received from the train is used to update the current information about the state of the whole network 13. This information is used:
[0066] • by layer three to calculate the smallest allowable train distances
[0067] • to optimise traffic in the existing infrastructure to establish future infrastructure development decisions
[0068] It means that if trains are equipped with a suitable receiver, any train control decision, e.g. speed, made by the interlocking system, carried out by the calculation and voting method described; will be transmitted, e.g. by ETCS balises 6, to the train. In our example, it can be done only at one point on network 13D.
[0069] Overcontrol enables human operators to intervene in the system, obeying a predefined set of railway safety rules. In order that human operators can intervene in the system, operators’ workstations are installed (not depicted on Figure 1) and connected to the network 13. Depending on the authentication level of the operator, for example the following activities can be carried out:
[0070] To visualize the status of the system, or a part of it
[0071] To exclude railway tracks from traffic
[0072] To set signalling lights to Stop position / to lower barrier
[0073] To decrease the speed or stop the train via train control function
[0074] To change the route of a train or multiple trains
[0075] To change the priority of a train or multiple trains
[0076] To operate a point machine to change the track of a train
[0077] To lift a barrier
[0078] To change signalling lights to free to move position
[0079] To enable the movement of a train via the train control system
[0080] All operator activities are logged. For each command it can be defined, whether the authentication of a certain person is enough to carry out the command, or supervisor’s approval is also required. Depending on the authorisation of the operator, he / she can intervene either in certain device in a geographically localised area, (e.g. within a certain station or yard), or just within a part of it, or the operator can instruct field elements of a larger area (e.g. along a track connecting two railway hubs). Since all devices are connected to the high-speed network, operators’ workstations can be anywhere, where network connection is available. In another words, workstations do not have to be in the vicinity of the area, operators are controlling. The way, operators control a certain device remotely, is as follows:
[0081] All of the controllers 16 control each other in a previously described way, using different commands. The last command is stored in the device, which must carry out the certain command. As an example, when a point machine 1 directs a train to a certain track, signals and barrier machines 9 are also commanded either by the point machine 1 controller 16 or by the track circuits’ 4 / axle counter sensors’ 3 controllers 16. In this case, if the operator has the proper authentication, he / she may overcontrol the smart elements’ command. First operation mode will be set to manual then instruction is sent to the given controller 16, which instruction remains valid until operator sets back the operation mode of the certain device / devices, to automatic.
[0082] On our Figure 1, an authorised person, using ‘Human machine interface 10, on network 13C, may control the operation either just a few elements on its own network e.g. point machine 1 controller 16 and railway signal 2 controller 16, or, in case of proper authorisation, other elements on other networks 13 A.
[0083] Timetable control is also realised by the controllers 16, which means, that it guarantees that trains run according to a predefined timetable and route. This service provides the set values to the operations’ control functionality, described it before. It prescribes, which train must move on which route, according to which schedule. Beyond timing, stops en route, destination, and priority information is also assigned to each train. This information is retrieved in the system in a way, that all controllers 16, which utilise this information, have access to it.
[0084] Automatic train control, provided as a controller 16, is a service that protects trains, by intervening in their speed, if traffic situation affords it. This may happen for example if driver does not react a signal at danger. In this case the system instructs the train to carry out an emergency brake command.
[0085] In this way, on the Figure 1, controller 16 may instruct trains, using the ETCS balises 6 controller 16, to increase / decrease their speed, or changing their route. Considering all system information, controller 16 may detect that the actual speed should be decreased because of a traffic jam ahead of the train, or even may stop the train, in case of an emergency.
[0086] All unified, common control units and the device specific subsystems are SIL 4 compliant, according to actual railway standards (which are currently EN 50 126, EN 50 129 and EN 50 716).
[0087] A simplified, general example is shown in Figure 2. We have indicated the following items: network 13, rail bus 15, controllers 16, field devices 17 and the unified user interface 18. To each field device 17 can belong a unified user interface 18, with unified window structure and functionality, which connected to the appropriate controller 16 of the field device 17.
[0088] The presented system has numerous advantages. The most important advantage of the invention is that the proposed digital railway interlocking system operates in a fully decentralised manner, eliminating the need for any central IT system, computer, or programmable logic controller (PLC). This architecture significantly enhances system robustness, scalability, and fault tolerance by removing single points of failure. A further benefit lies in the complete decentralisation of outdoor element control, which allows each unit to function independently, maintaining operational integrity even if other elements are impaired. The invention also provides a communication method between outdoor elements using serial transmission, for example via Ethernet, predominantly in a time-triggered mode, ensuring deterministic and predictable data exchange while still permitting event-driven messaging where needed. An additional merit of the system is that all data transmission is performed over fibre optic cables, granting high bandwidth capacity, long-distance reach, and immunity to electromagnetic interference common in railway environments.
[0089] From an infrastructure standpoint, the use of a rail bus 15 based power supply simplifies installation, reduces external cabling requirements, and ensures reliable, continuous power delivery. In terms of human-machine interaction, display units may be connected to any outdoor element, providing a standardised user interface while offering dedicated functional windows tailored to the specific connected device. The solution further distinguishes itself by incorporating the complete, eight-layer traditional railway automation architecture within each outdoor element’s software, enabling the full functional spectrum to be present locally rather than centrally. Safety is elevated by the fact that all outdoor elements achieve the highest Safety Integrity Level (SIL4) in compliance with EN 50 126, EN 50 716 and EN 50 129, ensuring rigorous adherence to established railway safety requirements. A noteworthy feature is that both the hardware and software platforms are uniform across all outdoor elements and independently meet SIL4 certification, resulting in interoperability, streamlined maintenance, and reduced system complexity. Moreover, the system architecture supports specific application software for each outdoor element, allowing the same generic, safety-certified platform to be adapted precisely to its intended function.
[0090] Additional technical advantages:
[0091] • The whole interlocking system is extremely resilient to attacks, as all interlocking system elements realise all interlocking system functions. In this way, eliminating just a few of them will not bring the whole system to a halt. On contrary, in case of current systems, based on central computer(s), the whole system can be stopped by eliminating the central computer(s) or cutting it / them from communication with interlocking system elements;
[0092] • The whole system can be kept on the same software level by a simultaneous software upgrade;
[0093] • UI can be unified for all elements thus service / maintenance personal’s task can be made very easy;
[0094] • The entire system can be managed from a limited number of operation centres.
[0095] Additional economic advantages
[0096] • The absence of a central computer can save up to 30-40% of project costs;
[0097] • The rail bus based power supply method can save further 15-20% of the project cost;
[0098] • As all control units are identical in all interlocking system elements, the number of spare parts to be kept on stock, is minimal;
[0099] • Thanks to the intensive diagnostic capabilities, repairing errors in interlocking system elements can be very effective.
[0100] Moreover, it is advantageous and economical that the system can be connected to an existing centralized, central computer system, partially taking over its tasks and making it more economical. Reliability is further enhanced through comprehensive self-diagnostic and remote-diagnostic functions, which facilitate rapid fault identification and corrective action. The communication protocol is optimised so that safety-critical data are given absolute priority, guaranteeing their prompt and secure delivery even under heavy network load. Finally, the entire interlocking system can be upgraded in a single coordinated action by downloading and flashing new software to each device, enabling rapid modernisation with minimal disruption to railway operations.
[0101] In addition to the above examples, the invention may be implemented in other forms and with other manufacturing procedures within the scope of invention as defined in the appended claims.
Claims
CLAIMS1. Decentralised, digital railway interlocking system, which includes decentralised field devices (17), power supply, timetable server (11), characterized in that it consists at least one network (13, 13A, 13B, 13C, 13D) with the field devices (17), each field device (17) connected to a controller (16), the controllers (16) are connected to the network (13, 13 A, 13B, 13C, 13D) via a wire or an optical cable, with two-way data transfer connection and at least one of the controllers (16) is suitable for control any field device (17) of any network (13, 13A, 13B, 13C, 13D) and the controller (16) has a safety level of SIL-4.
2. The system according to claim 1, characterized in that the networks (13A, 13B, 13C, 13D) are connected to each other via routers (14).
3. The system according to claim 1 or 2, characterized in that each field device (17) consists one of the followings- a point machine (1),- a railway signal (2),- an axle counter sensor (3),- a track circuit (4),- a key cabinet (5),- an ETCS balise (6),- an RFID reader (7),- a level crossing signal (8),- a barrier machine (9).
4. The system according to any one of claims 1 to 3, characterized in that the power supply is provided via a rail bus (15).
5. The system according to any one of claims 1 to 4, characterized in that the controller (16) has a unified user interface (18).
6. The system according to any one of claims 1 to 5, characterized in that it has a human machine interface (10) and a log server (12).
Citation Information
Patent Citations
Device and method for the control and / or monitoring of decentralised intelligent functional units in a rail traffic network
EP3176049A1
Railway Control Systems
JP7313845B2
Method and apparatus for autonomous train control system
US11021178B2
System for distributed automatic train supervision and control
US6032905A
Redundancy method for a specialised data network
EP2613476B1