Daisy-chain Safety Systems for Railway Data Throughput
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional fault-tolerant failsafe computer systems in railway and similar safety-critical systems face challenges in handling increasing data throughput and validating instructions to prevent erroneous commands due to hardware or software faults, leading to potential safety risks.
Innovation Solution
A fault-tolerant failsafe computer system is designed with multiple interconnected computers and an active determining module that generates health signals to manage communication channels, enabling or disabling output ports based on health status signals to ensure safe operation and prevent faulty instructions from being executed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional fault-tolerant failsafe computer systems are used, then system safety is maintained, but the I/O capacity is insufficient to handle increasing data throughput
Solution Approach 1:
The system is divided into multiple independent computer systems (first computer system, second computer system) that operate in parallel. Each computer system has its own processing capacity and I/O channels, allowing the overall system to handle increased data throughput while maintaining fault tolerance through redundancy. The segmentation enables scalable expansion of I/O capacity without compromising safety.
2Productivity
If multiple computers are interconnected to increase I/O capacity, then data throughput is improved, but system complexity increases
Solution Approach 1:
The active computer system determining module serves multiple functions: it determines which computer system is active, monitors health signals from multiple computers, and controls the enabling/disabling of output ports across different computer systems. This multi-functional approach reduces the need for separate control mechanisms for each computer, thereby managing complexity while handling increased I/O capacity.
3Reliability
If health signals are monitored to prevent erroneous commands, then system safety is improved, but communication overhead increases
Solution Approach 1:
The active computer system determining module continuously monitors health signals from all computer systems without interruption. This continuous monitoring ensures that any faulty computer is immediately detected and its output ports disabled, preventing erroneous commands from being executed. The continuous action eliminates the need for periodic sampling or redundant verification protocols, optimizing the balance between safety validation and communication overhead.
Data Source
AI summary
A system includes a first computer, a second computer, and an active computer system determining module. The first computer receives a second computer health signal from the second computer indicating a fault in the second computer and generates a first computer system health signal indicating a fault in the first and/or second computer. The active computer system determining module receives the first computer system health signal and generates a standby signal based on the first computer system health signal. The second computer receives the standby signal and disables one or more of its output ports based on the standby signal.


