Fully-automatic safe batch switching apparatus for new and old rail transit control systems, and method

WO2026199843A1PCT designated stage Publication Date: 2026-10-01CASCO SIGNAL LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/120075
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-24
Filing Date
2025-09-09
Publication Date
2026-10-01

Smart Images

  • Figure CN2025120075_01102026_PF_FP_ABST
    Figure CN2025120075_01102026_PF_FP_ABST
Patent Text Reader

Abstract

A fully-automatic safe batch switching apparatus for new and old rail transit control systems, and a method. The apparatus is separately connected to system devices and controlled devices. The switching apparatus comprises: consoles which are used for operating and monitoring the whole switching process; switching servers which are communicatively connected to the consoles and used for processing data and control signals in the switching process; and switching terminals which are communicatively connected to the switching servers, respectively connected to new and old system devices and the controlled devices, and used for receiving and verifying switching commands from the switching servers, executing switching operations by means of a mechanical apparatus, thereby dynamically switching between new and old systems, and monitoring the switching state and feeding back same to the switching servers. The efficiency and safety of switching between new and old systems are improved, thereby implementing safe and high-speed switching between systems based on different standards.
Need to check novelty before this filing date? Find Prior Art

Description

Automatic Safety Switching Device and Method for New and Old Rail Transit Control Systems Technical Field

[0001] This invention relates to rail transit signaling systems, and more particularly to a fully automatic, safe switching device and method for batch switching between old and new rail transit control systems. Background Technology

[0002] Rail transit control systems are the core technology ensuring the safe and efficient operation of rail transit. With the rapid development of the rail transit industry, its control systems are constantly evolving. Early rail transit control systems mainly relied on manual operation and simple signaling systems. With the development of automation technology, Automatic Train Control (ATC) systems were gradually introduced, including functions such as Automatic Train Protection (ATP), Automatic Train Operation (ATO), and Automatic Train Monitoring (ATS). In recent years, with the further development of information technology, intelligent fully automated operation systems (iFAO) have emerged in rail transit control systems. Based on traditional fully automated operation systems (FAO), iFAO expands the scope and depth of automation control, enabling functions such as online dynamic fully automated train operation and intelligent dynamic scheduling. However, during the upgrading and replacement of rail transit control systems, the switching problem between old and new systems has gradually become prominent.

[0003] A search of Chinese Patent Publication No. CN117104312A reveals a signal system switching method and system. This method is based on active shadow mode and full-time quality monitoring. The method includes: S1, the signal system is started, and the working state is set to the old system working and the new system shadow operation state; S2, when the signal system is officially in operation, the old system performs normal operation control, and the new system acquires the line and train operation data; S3, the automatic data collection module provides the operation data acquired by the new system to the trackside line data pool, and the line data pool provides the operation data to the central data lake; S4, the quality monitoring subsystem QMS automatically analyzes the operation quality based on the operation data in the central data lake and transmits the results to the panoramic cockpit HMS; S5, when the signal system is being debugged, the working state is set to the new system working state. However, this existing patent does not address the combination of "batch switching" and "safe switching".

[0004] Therefore, the existing switching methods have the following main drawbacks:

[0005] 1. Insufficient security: During the commissioning phase of a new system, data interaction and control switching between the old and new systems may pose security risks. For example, insufficient security and real-time performance of the system's communication architecture may lead to data transmission errors or delays, thereby affecting the safe operation of the train.

[0006] 2. Low switching efficiency: Traditional switching methods are mostly manual or semi-automatic, requiring a lot of human intervention, which is not only time-consuming and labor-intensive, but also prone to switching failure due to human error.

[0007] 3. Significant disruption to operations: During the switching process, it is often necessary to suspend the operation of some or all lines, which will cause significant disruption to the normal operation of rail transit and reduce operational efficiency. Summary of the Invention

[0008] The purpose of this invention is to overcome the defects of the prior art by providing a fully automatic and safe switching device and method for batch switching between old and new rail transit control systems, which can improve the efficiency and safety of switching between old and new systems and enable safe and high-speed switching between different systems.

[0009] The objective of this invention can be achieved through the following technical solutions:

[0010] According to a first aspect of the present invention, a fully automatic batch safety switching device for new and old rail transit control systems is provided. The device is connected to both system equipment and controlled equipment, and the switching device includes:

[0011] The console is used to operate and monitor the entire handover process;

[0012] The server is switched over and interacts with the console to handle data and control signals during the switching process.

[0013] The switching terminal interacts with the switching server and connects to both the old and new system devices and the controlled devices. It receives and verifies the switching commands from the switching server, executes the switching operation through mechanical devices, realizes dynamic switching between the old and new systems, and monitors the switching status and feeds it back to the switching server.

[0014] As a preferred technical solution, the console is provided in two sets, namely a first console and a second console that independently perform switching functions.

[0015] As a preferred technical solution, the switching server is provided in two sets, including a first switching server and a second switching server, which respectively receive control instructions from the first console and the second console, generate corresponding switching commands, and send them to the switching terminal through a secure communication protocol.

[0016] As a preferred technical solution, the number of switching terminals is configured according to the number of system devices that need to be switched.

[0017] As a preferred technical solution, the switching terminal includes:

[0018] The transmit and receive processing module is responsible for processing the transmitted and received signals;

[0019] The verification output module, connected to the transmit and receive processing module, is used to verify the received signal;

[0020] The mechanical execution module, connected to the verification output module, is used to perform corresponding mechanical operations based on the received signals.

[0021] The system switching module connects to both the old and new system equipment and the controlled equipment, and is responsible for switching signals between different system equipment.

[0022] The reverse connection status acquisition module is connected to the system reverse connection module and is used to collect status information during the reverse connection process;

[0023] The status processing module is connected to both the reverse connection status acquisition module and the transmit / receive processing module. It is used to process the received reverse connection status and feed it back to the switching server through the transmit / receive processing module.

[0024] As a preferred technical solution, the transmitting and receiving processing module has two channels, which are respectively connected to the verification output module.

[0025] As a preferred technical solution, the verification output module performs security verification on the two received signals. Only when the two signals are consistent will a switching command be generated and output to the mechanical actuator. If they are inconsistent, a switching failure message will be generated and fed back to the sending and receiving processing module.

[0026] As a preferred technical solution, the mechanical operation of the mechanical execution module does not intrude on existing old system equipment or new system equipment.

[0027] As a preferred technical solution, the mechanical execution module adopts a non-circuit-intrusive mechanical switching, which realizes electrical isolation from existing old system equipment and new system equipment.

[0028] As a preferred technical solution, the system switching module allows the system to flexibly switch between old and new equipment.

[0029] According to a second aspect of the present invention, a method for using the aforementioned fully automatic safety switching device for both new and old rail transit control systems is provided, comprising the following steps:

[0030] Step S1: The console sends a switch command to the switch server;

[0031] Step S2: The switching server processes the received switching command and sends it to the network;

[0032] Step S3: The first and second transmitting and receiving processing modules of the switching terminal independently receive the switching command and decode the switching command; the verification output module checks whether the switching command received by the transmitting and receiving processing module is consistent. If they are consistent, step S4 is executed; otherwise, the verification output module generates a "failed to switch" status information to the status processing module.

[0033] Step S4: The verification output module sends a valid switching command to the mechanical execution module, and the mechanical execution module performs the switching action.

[0034] Step S5: The system switching module completes the switching operation between the old and new system equipment;

[0035] Step S6: The reverse connection status acquisition module acquires the reverse connection status information and sends it to the status processing module. The status processing module processes the reverse connection status information and then sends it to the sending and receiving processing module.

[0036] Step S7: The sending and receiving processing module sends feedback on the switching status to the switching server.

[0037] As a preferred technical solution, step S1 specifically includes:

[0038] The first operator sends a switching command through the first console, and the second operator sends a switching command through the second console. The first operator and the second operator are different operators, and the operation time is within the specified time.

[0039] As a preferred technical solution, step S2 specifically includes:

[0040] Step S201: The switching server checks the validity of the switching command received from the console;

[0041] Step S202: The switching server encodes the valid switching command using a security protocol;

[0042] Step S203: The switching server adds an information security protection layer to the encoded switching command before sending it.

[0043] As a preferred technical solution, the verification output module checking process in step S3 includes: whether the switching command sequence number is the same, and whether the command time of the first sending and receiving processing module and the second sending and receiving processing module is within the validity period. If all conditions are met, it is determined to be consistent.

[0044] As a preferred technical solution, the switching server verifies the switching status of the switching terminal based on the received reverse connection status information.

[0045] As a preferred technical solution, if all switching terminals report successful switching, the switching server will send a "successful switching" status to the console for display.

[0046] If any terminal reports a failed switch, the switch server will send a "switching failed" status to the console for display and trigger an audible and visual alarm.

[0047] Compared with the prior art, the present invention has the following advantages:

[0048] 1) High-efficiency switching technology: This invention adopts a fully automated switching method, which can realize fast and uninterrupted switching between old and new systems, greatly improving switching efficiency; by optimizing the switching process and algorithm, manual intervention is reduced, and the risk of switching failure due to human error is reduced.

[0049] 2) Safety mechanism innovation: By introducing an advanced safety control mechanism, the switching device adopts a non-circuit-intrusive mechanical switching, which realizes electrical isolation from the existing old system and the new system. After the switching, the mechanical device is disconnected to achieve physical isolation, which greatly improves safety. At the same time, the use of redundant design and fault detection technology can monitor the system status in real time and ensure the safe operation during the switching process.

[0050] 3) Minimize operational disruption: This invention enables batch switching between old and new systems without affecting normal operations; through reasonable scheduling and control strategies, it ensures that train operation is not affected during the switching process, thereby minimizing disruption to rail transit operations. Attached Figure Description

[0051] Figure 1 is a schematic diagram of the reverse connection device of Embodiment 1 of the present invention;

[0052] Figure 2 is a schematic diagram of the switching terminal in Embodiment 1 of the present invention;

[0053] Figure 3 is a flowchart of the reverse connection method of Embodiment 2 of the present invention. Detailed Implementation

[0054] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0055] Example 1

[0056] This invention proposes a fully automatic, safe switching device for batch operation of new and old rail transit control systems, which aims to solve the aforementioned problems in the existing technology. It can effectively solve the problems of insufficient safety, low switching efficiency, and significant interference with operation in the existing technology, and provides strong support for the technological upgrading and safe operation of the rail transit industry.

[0057] As shown in Figure 1, the new and old rail transit control system batch safety fully automatic switching device of the present invention includes:

[0058] Consoles: Includes a first console and a second console, used to operate and monitor the entire switching process.

[0059] Switching servers: including the first switching server and the second switching server, are responsible for processing data and control signals during the switching process.

[0060] Switching Terminal: Configure the number of switching terminals according to the number of system devices to be switched. The switching terminal is used to connect the controlled device and the old and new system devices, execute switching commands, and monitor the switching status.

[0061] in:

[0062] Interaction between the console and the switching server: The first and second consoles are dual, independently operating workstations responsible for issuing switching commands and monitoring the switching process. The use of two sets ensures the system's security level reaches SIL2. The first and second switching servers receive these commands and generate corresponding switching commands, sending them via a secure communication protocol. This design allows operators to remotely control the switching process while ensuring the accuracy and reliability of the switching operation.

[0063] System equipment and switching terminal connection: System 1 - Equipment 1, System 2 - Equipment 1, etc., represent different equipment in the old and new rail transit control systems. These devices are connected to controlled equipment 1, controlled equipment 2, etc., through switching terminals 1-n, switching terminal 2, etc. The function of the switching terminal is to receive and verify the switching commands from the switching server, execute the switching operation through mechanical devices, realize the dynamic switching between the old and new systems, transfer control of the controlled equipment, and monitor the control switching status and feed it back to the switching server.

[0064] Control of controlled equipment: Controlled equipment 1, controlled equipment 2, etc., represent actual rail transit equipment, such as trains and signal lights. Through switching terminals, these devices can receive control signals from different system equipment, realizing rapid and safe switching between old and new systems.

[0065] As shown in Figure 2, the switching terminal of the present invention executes switching commands to realize the switching operation between the old and new systems and monitors the switching status in real time. It mainly consists of the following modules:

[0066] The first and second transmit / receive processing modules are responsible for processing transmitted and received signals to ensure the accuracy and integrity of commands.

[0067] Verification output module: Verifies the received two signals to ensure their correctness.

[0068] Status processing module: processes the received signal status and feeds it back to the console and switching server.

[0069] Mechanical Actuation Module: Performs corresponding mechanical operations based on the received signals.

[0070] System switching module: responsible for switching signals between different system devices.

[0071] Reverse connection status acquisition module: Collects status information during the reverse connection process and feeds it back to the status processing module.

[0072] in:

[0073] Transmit / Receive Processing Modules: The first and second transmit / receive processing modules are responsible for processing the transmitted and received signals, respectively. These modules ensure the accuracy and integrity of the data, providing a foundation for subsequent signal processing.

[0074] The output verification module performs a security check on the two received signals. Only if the two signals match will a switching command be generated and output to the subsequent actuators. If they do not match, a switching failure message will be generated and fed back to the transmitting and receiving processing module. This module ensures the correctness of the signals. This step is crucial for preventing the propagation of erroneous signals and helps improve system reliability.

[0075] Status processing module: This module processes the received switchover status and, after secure encoding by the verification module, sends it to the send / receive processing module, which then feeds it back to the console and the switchover server. This allows operators to monitor the switchover process in real time and adjust their operational strategies accordingly.

[0076] Mechanical Actuation Module: The mechanical actuation module performs corresponding mechanical operations based on received signals. This operation does not intrude on the existing or new system and is crucial for achieving physical switching, ensuring the safe and efficient execution of the switching operation. The switching device adopts a non-circuit-intrusive mechanical switching method, achieving electrical isolation from both the existing and new systems. After switching, the mechanical device disengages, achieving physical isolation and greatly improving safety.

[0077] System Switching Module: This module is responsible for switching signals between different system devices. Its design allows for flexible switching between old and new devices, enabling a smooth transfer of control.

[0078] Switchover Status Acquisition Module: This module collects status information during the switchover process and feeds it back to the console and switchover server via the status processing module. This helps operators fully understand the switchover process and ensures a smooth switchover operation.

[0079] Example 2

[0080] As shown in Figure 3, a fully automated, safe, batch switching method for new and old rail transit control systems includes the following steps:

[0081] Step 1: Send Command

[0082] Operator 1 sends the command "Switch from System 1 to System 2" from the first console.

[0083] Operator 2 sends the same command from the second console.

[0084] Operator 1 and Operator 2 must be authorized switchover personnel and cannot be the same person. The operation time must be within the specified time to ensure the authenticity and validity of the switchover command.

[0085] Step 2: Command validity check

[0086] The first switching server checks the validity of the switching command received from the first console.

[0087] The second switching server checks the validity of the switching command received from the second console.

[0088] Step 3: Security Protocol Encoding

[0089] The first switching server uses a security protocol to encode commands.

[0090] The second switching server also uses a security protocol to encode commands.

[0091] Step 4: Information Security Protection

[0092] The first switch server adds an information security protection layer.

[0093] The second switch server adds an information security protection layer.

[0094] Step 5: Send the command to the network

[0095] The first switching server sends the encoded command to the network.

[0096] The second switching server sends the encoded command to the network.

[0097] Step 6: Command Reception and Verification

[0098] The sending / receiving processing modules 1 and 2 of the switching terminals 1-n independently receive commands and decode them.

[0099] The verification output module of the switching terminal 1-n checks whether the commands of the sending / receiving processing module 1 and module 2 are consistent, whether the command sequence numbers are the same, and whether the command times of the two modules are within the validity period, in order to determine the validity of the command.

[0100] Step 7: Command Validity Check

[0101] If the command is valid, the mechanical execution modules of switching terminals 1-n perform the switching action. The switching device adopts a non-circuit-intrusive mechanical switching, achieving electrical isolation from both the existing old and new systems. After the switching, the mechanical device disengages, achieving physical isolation and greatly improving safety.

[0102] If the command is invalid, the verification output module of the switching terminal 1-n generates a "reverse connection failure" status message and sends it to the status processing module.

[0103] Step 8: Perform the reverse connection action

[0104] The system switching module for terminals 1-n completes the action of "switching from system 1 to system 2".

[0105] Step 9: Reverse Connection Status Acquisition and Processing

[0106] The reverse connection status acquisition module of the switching terminal 1-n is used to collect the reverse connection status.

[0107] The status processing module of the switching terminal 1-n processes the reverse status information and sends it to the sending / receiving processing module 2.

[0108] Step 10: Send Status Information

[0109] The status sending / receiving processing module 2 of the switching terminals 1-n sends the reverse connection status to the second switching server.

[0110] Step 11: Switch Status Verification

[0111] The second switching server verifies the switching status of switching terminals 1-n.

[0112] Step 12: Switching Result Feedback

[0113] If all switching terminals report a successful switch, the second switching server will send a "successful switch" status to the second console for display.

[0114] If any terminal reports a failed switch, the second switch server will send a "switching failed" status to the second console for display and trigger an audible and visual alarm.

[0115] Through the above steps, the system achieves a safe and automated switch from System 1 to System 2, ensuring the stability and reliability of the rail transit control system. Simultaneously, through status feedback and alarm mechanisms, the system can respond promptly to potential problems during the switchover process, improving system safety and maintainability.

[0116] Example 3

[0117] The following example illustrates the process of upgrading a CBTC (Communication-Based Train Control System) to a TACS (Train Autonomous Control System Based on Vehicle-to-Vehicle Communication). The relevant principles and logic also apply to the switching between other new and old control systems.

[0118] Implementation steps

[0119] 1. Preparation stage:

[0120] Ensure that the CBTC and TACS systems are installed and functioning correctly at all sites.

[0121] Configure the first and second switch servers to ensure they can handle commands from the first and second consoles.

[0122] 2. Command transmission:

[0123] The operator simultaneously sends the command "Switch from System 1 to System 2" on the first console and the second console, with the time difference between the two commands not exceeding 1 minute.

[0124] 3. Command verification and encoding:

[0125] After receiving the command, the first and second switching servers perform a validity check and encode the command using a security protocol to add a layer of information security protection.

[0126] 4. Command transmission:

[0127] The encoded commands are sent over the network to the switching terminals (switching terminals 1-n) at each site.

[0128] 5. Command execution:

[0129] After receiving the command at the new terminal, the validity of the command is verified. If valid, the switchover action is executed, transferring control from the CBTC system to the TACS system.

[0130] 6. Status Acquisition and Feedback:

[0131] After the switching terminal completes the connection change, the connection change status is collected, and the status information is sent to the second switching server through the send / receive processing module.

[0132] The second switching server verifies the status of all switching terminals to confirm whether the switching of all sites was successful.

[0133] 7. Results Feedback:

[0134] If the switching of all sites is successful, the second switching server will send a "switching successful" status to the second console for display.

[0135] If any site switching fails, the second switching server will send a "switching unsuccessful" status to the second console for display and trigger an audible and visual alarm.

[0136] Specific data:

[0137] Switching time: The switching time for each site should be controlled within 4 seconds.

[0138] Switching success rate: 99.99% success rate.

[0139] Number of terminals to be switched: No less than 200 terminals to be switched at each site.

[0140] advantage:

[0141] 1. High Security: Secure protocol coding and information security protection layers ensure data security and integrity during the handover process. The handover device employs a non-circuit-intrusive mechanical handover, achieving electrical isolation from both the existing and new systems. After the handover, the mechanical device disengages, achieving physical isolation and significantly enhancing security.

[0142] 2. High efficiency: The automated handover process reduces manual intervention and improves handover efficiency, with the handover time for each site controlled within 5 seconds.

[0143] 3. High reliability: Through status acquisition and feedback mechanisms, the switching process can be monitored in real time to ensure the reliability of the switching.

[0144] 4. Reduced operational disruption: The rapid and automated switching process reduces disruption to normal rail transit operations.

[0145] 5. Easy to maintain: The centralized switching server and distributed switching terminal design facilitates system maintenance and upgrades.

[0146] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A new and old rail transit control system batch safety full-automatic reverse connection device, the device is connected with system equipment and controlled equipment respectively, characterized in that, The switching device includes: The console is used to operate and monitor the entire handover process; The server is switched over and interacts with the console to handle data and control signals during the switching process. The switching terminal interacts with the switching server and connects to both the old and new system devices and the controlled devices. It receives and verifies the switching commands from the switching server, executes the switching operation through mechanical devices, realizes dynamic switching between the old and new systems, and monitors the switching status and feeds it back to the switching server.

2. The batch safety full-automatic reverse connection device for new and old rail transit control systems according to claim 1, characterized in that, The console is provided in two sets, namely a first console and a second console that perform switching functions independently of each other.

3. The batch safety full-automatic reverse connection device for new and old rail transit control systems according to claim 2, characterized in that, The switching server is provided in two sets, including a first switching server and a second switching server, which respectively receive control instructions from the first console and the second console, generate corresponding switching commands, and send them to the switching terminal through a secure communication protocol.

4. The batch safety full-automatic reverse connection device for new and old rail transit control systems according to claim 1, characterized in that, The number of switching terminals is configured according to the number of system devices that need to be switched.

5. The batch safety full-automatic reverse connection device for new and old rail transit control systems according to claim 1, characterized in that, The switching terminal includes: The transmit and receive processing module is responsible for processing the transmitted and received signals; The verification output module, connected to the transmit and receive processing module, is used to verify the received signal; The mechanical execution module, connected to the verification output module, is used to perform corresponding mechanical operations based on the received signals. The system switching module connects to both the old and new system equipment and the controlled equipment, and is responsible for switching signals between different system equipment. The reverse connection status acquisition module is connected to the system reverse connection module and is used to collect status information during the reverse connection process; The status processing module is connected to both the reverse connection status acquisition module and the transmit / receive processing module. It is used to process the received reverse connection status and feed it back to the switching server through the transmit / receive processing module.

6. The batch safety full-automatic reverse connection device for new and old rail transit control systems according to claim 5, characterized in that, The transmitting and receiving processing module has two channels, which are respectively connected to the verification output module.

7. The batch safety full-automatic reverse connection device for new and old rail transit control systems according to claim 6, characterized in that, The verification output module performs a security verification on the two received signals. Only when the two signals are consistent will a switching command be generated and output to the mechanical actuator. If they are inconsistent, a switching failure message will be generated and fed back to the sending and receiving processing module.

8. The batch safety full-automatic reverse connection device for new and old rail transit control systems according to claim 5, characterized in that, The mechanical operation of the mechanical execution module does not intrude on existing old system equipment or new system equipment.

9. The batch safety full-automatic reverse connection device for new and old rail transit control systems according to claim 5, characterized in that, The mechanical actuation module employs a non-circuit-intrusive mechanical switching method, achieving electrical isolation from both existing and new system equipment.

10. The batch safety full-automatic reverse connection device for new and old rail transit control systems according to claim 5, characterized in that, The system's reverse connection module allows for flexible switching between old and new equipment.

11. A method for using the new and old rail transit control system batch safety full-automatic reverse connection device according to any one of claims 1-10, characterized in that, Includes the following steps: Step S1: The console sends a switch command to the switch server; Step S2: The switching server processes the received switching command and sends it to the network; Step S3: The first and second transmitting and receiving processing modules of the switching terminal independently receive the switching command and decode the switching command. The verification output module checks whether the switching command received by the sending and receiving processing module is consistent. If it is consistent, step S4 is executed; otherwise, the verification output module generates a "reverse connection failure" status message to the status processing module. Step S4: The verification output module sends a valid switching command to the mechanical execution module, and the mechanical execution module performs the switching action. Step S5: The system switching module completes the switching operation between the old and new system equipment; Step S6: The reverse connection status acquisition module acquires the reverse connection status information and sends it to the status processing module. The status processing module processes the reverse connection status information and then sends it to the sending and receiving processing module. Step S7: The sending and receiving processing module sends feedback on the switching status to the switching server.

12. The method of claim 11, wherein, Step S1 specifically involves: The first operator sends a switching command through the first console, and the second operator sends a switching command through the second console. The first operator and the second operator are different operators, and the operation time is within the specified time.

13. The method of claim 11, wherein, Step S2 specifically involves: Step S201: The switching server checks the validity of the switching command received from the console; Step S202: The switching server encodes the valid switching command using a security protocol; Step S203: The switching server adds an information security protection layer to the encoded switching command before sending it.

14. The method of claim 11, wherein, The verification output module check process in step S3 includes: whether the switching command sequence number is the same, and whether the command time of the first sending and receiving processing module and the second sending and receiving processing module is within the validity period. If all of these conditions are met, the modules are considered to be consistent.

15. The method of claim 11, wherein, The switching server verifies the switching status of the switching terminal based on the received reverse connection status information.

16. The method of claim 11, wherein, If all switching terminals report a successful switch, the switching server will send a "successful switch" status to the console for display. If any terminal reports a failed switch, the switch server will send a "switching failed" status to the console for display and trigger an audible and visual alarm.