ETCS Odometry Unit Testing via Decoupled Secure Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is no straightforward method to test new versions of odometry software for ETCS vehicle devices in real railway operating environments without affecting safety, disturbing the engineer, or impairing the monitoring ETCS device functionality, and existing methods require approval and are not easily adaptable to various vehicle types.

Innovation Solution

A method and odometry unit that utilize a non-secure computing unit with a secure computing unit to process data from distance measuring devices and radars, allowing for non-reactive data transmission and recording, which includes a decoupling box and converter for immunity to electromagnetic interference, enabling testing without operational restrictions and using a portable 19-inch standard rack design for flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a new version of odometry software is tested in real railway operations, then testing capability and data collection are improved, but safety risks and operational disruptions increase

Engineering Contradiction:
Improvetesting capabilityVSAvoidsafety
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system is divided into a secure computing unit (EVC) that maintains approved software for safety-critical operations and a separate odometry unit with a test computing unit that runs the new software version. This segmentation allows independent testing without compromising the safety of the main ETCS system, resolving the contradiction between testing capability and safety reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A non-secure computing unit acts as an intermediary between the secure EVC and the test environment. It receives data from the secure unit, processes it with the test software version, and records results without affecting the original safety-critical system. This intermediary structure enables testing while maintaining safety boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If X-Traces are activated for testing on a specific vehicle type, then data verification is improved, but operational restrictions and approval requirements increase

Engineering Contradiction:
Improvedata verificationVSAvoidoperational restrictions
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The odometry unit autonomously collects, processes, and records test data without requiring external activation or approval for each testing scenario. The system self-manages the testing process by automatically receiving data from distance measuring devices and radars, processing it through the test software version, and storing results in the non-secure computing unit, eliminating the need for manual X-Trace activation and expert approval.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The odometry unit is designed as a universal testing platform that can test new odometry software versions across different vehicle types and ETCS levels without requiring vehicle-specific configurations or approvals. The system universally receives data from various distance measuring devices and radars, making it adaptable to multiple vehicle types while maintaining ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If testing is conducted in laboratory and on test tracks, then safety is maintained, but testing realism and operational applicability deteriorate

Engineering Contradiction:
ImprovesafetyVSAvoidtesting realism
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The non-secure computing unit serves as an intermediary that bridges the secure safety-critical system and the real-world operating environment. It enables the collection and processing of real operational data from distance measuring devices and radars while maintaining the safety boundaries of the approved EVC system, thus achieving both safety and testing realism simultaneously in actual railway operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If odometry unit is remotely mounted with independent power supply, then driver disturbance is eliminated, but system complexity increases

Engineering Contradiction:
Improvedriver disturbanceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The odometry unit is extracted from the driver's cab and remotely mounted in a location that does not disturb the driver during operations. The unit includes an independent power supply that is taken out from the main vehicle electrical system, connected via a cable to a power source elsewhere in the vehicle. This extraction eliminates driver disturbance while the modular design keeps the added system complexity manageable and isolated from critical systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3753803B1Method and odometry unit for testing an etcs odometry software version
Publication Date: 2023.07.26 SIEMENS MOBILITY GMBH
  • EP3753803B1 patent drawingFigure 1
  • EP3753803B1 patent drawingFigure 2

AI summary

A method is proposed for testing an odometry software version for an ETCS on-board unit (3) of a vehicle operating on an ETCS track. This method can be used in real-world railway operations without requiring re-certification of the equipment. For this purpose, an odometry unit (1) is added to an existing ETCS on-board unit (3) and is connected to the monitoring ETCS on-board unit (3) without any feedback effect. An approved software version is stored and executable on the ETCS computer (36) of the ETCS on-board unit. The odometry unit contains an identical, secure computer unit (16) on which the odometry software version to be tested is stored and executable.For later evaluation, the data transmitted to the secure computer unit (16) without effect and the data generated by the secure computer unit (16) are recorded by a non-secure computer unit (15) in a non-volatile memory.