Level Crossing Safety System Using Diverse Single-Channel Component Computers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing level crossing protection systems require high Safety Integrity Level (SIL) certification, which is costly and complex, especially when using two-channel signal-technically safe designs for component computers.
Innovation Solution
Assigning component computers with diverse single-channel hardware and a secure control computer to monitor and control components, ensuring signaling safety through independent energization verification and comparison, allowing for a reduction in overall system SIL level while maintaining SIL4 certification, and simplifying hardware and verification processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If two-channel signal-technically safe component computers are used, then signaling safety is ensured, but hardware costs and device complexity increase
Solution Approach 1:
The component computer is segmented into two separate single-channel computers (first computer and second computer) with diverse hardware. Each computer independently determines component energization and sends read-back results to the control computer, which compares the results to verify safety. This segmentation allows use of simpler, less expensive single-channel computers while maintaining SIL4 safety through the comparison mechanism.
Solution Approach 2:
Different parts of the system have different safety requirements. The control computer maintains full SIL4 signaling safety certification, while the component computers can be simpler SILO computers with diverse single-channel hardware. The safety verification is performed locally at the control computer through comparison of read-back results from the two component computers.
2Reliability
If two-channel signal-technically safe component computers are used, then signaling safety is ensured, but hardware costs increase
Solution Approach 1:
The invention replaces expensive signal-technically safe component computers with cheaper single-channel SILO computers that have diverse hardware. The cost reduction is achieved by using commercial off-the-shelf computers instead of specialized safety-certified component computers, while maintaining overall system safety through the control computer's comparison of independent read-back results.
3Ease of manufacture
If single-channel diverse hardware computers are used for components, then hardware costs are reduced, but signaling safety may be compromised
Solution Approach 1:
The control computer receives independent read-back results from both the first and second component computers and compares them to verify correct operation. This feedback mechanism ensures that even though the component computers use simpler single-channel hardware, the overall system maintains SIL4 signaling safety through continuous verification of component energization states.
Solution Approach 2:
The control computer performs preliminary safety verification by comparing read-back results from the two component computers before allowing system operation to proceed. This preliminary check ensures that the diverse single-channel computers are functioning correctly and that the system maintains required safety levels.
4Reliability
If two-channel safe design is used for component computers, then safety is ensured, but space requirements increase
Solution Approach 1:
The component computer functionality is segmented across two separate single-channel computers with diverse hardware, each occupying less space than a single two-channel safe computer. The control computer coordinates these distributed components through a communication ring, achieving the same safety function in a more space-efficient manner.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a level crossing safety system having a control device for roadside components (3a, 3b; 4a, 4b, 4c, 4d), in particular gates (3a, 3b) and light signals (4a, 4b, 4c, 4d). In order to be able to replace computers which are secure in terms of signalling with computers which are not secure in terms of signalling, provision is made for the control device to have a control computer (6) which is secure in terms of signalling and for component computers (8a; 8b) which are not secure in terms of signalling to be associated with the components (4a; 4b), wherein the component computers (8a; 8b) each comprise a first and a second single-channel computer (10a, 11a; 10b, 11b) having diverse hardware, and for the control computer (6) and the component computers (8a, 8b) to have means for controlling and monitoring the components (4a; 4b) with the following sequence: - the control computer (6) transmits an actuating command to the first computers (10a; 10b) which control the component (4a; 4b) associated therewith, - the first and second computers (10a, 11a; 10b, 11b) of the component (4a; 4b) independently determine the energization of the component (4a; 4b) and transmit this read-back result to the control computer (6) and - the control computer (6) compares the actuating command thereof with the read-back results from the components (4a; 4b) and compares the read-back results with one another, in which case a safety response is triggered if at least one of the comparison results does not match.