Level Crossing Safety System Using Diverse Single-Channel Component Computers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing level crossing protection systems require high Safety Integrity Level (SIL) certification, which is costly and complex, especially when using two-channel signal-technically safe designs for component computers.

Innovation Solution

Assigning component computers with diverse single-channel hardware and a secure control computer to monitor and control components, ensuring signaling safety through independent energization verification and comparison, allowing for a reduction in overall system SIL level while maintaining SIL4 certification, and simplifying hardware and verification processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-channel signal-technically safe component computers are used, then signaling safety is ensured, but hardware costs and device complexity increase

Engineering Contradiction:
Improvesignaling safetyVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The component computer is segmented into two separate single-channel computers (first computer and second computer) with diverse hardware. Each computer independently determines component energization and sends read-back results to the control computer, which compares the results to verify safety. This segmentation allows use of simpler, less expensive single-channel computers while maintaining SIL4 safety through the comparison mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different parts of the system have different safety requirements. The control computer maintains full SIL4 signaling safety certification, while the component computers can be simpler SILO computers with diverse single-channel hardware. The safety verification is performed locally at the control computer through comparison of read-back results from the two component computers.

Inventive Principle:
Principle #3Local quality

2Reliability

If two-channel signal-technically safe component computers are used, then signaling safety is ensured, but hardware costs increase

Engineering Contradiction:
Improvesignaling safetyVSAvoidhardware cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The invention replaces expensive signal-technically safe component computers with cheaper single-channel SILO computers that have diverse hardware. The cost reduction is achieved by using commercial off-the-shelf computers instead of specialized safety-certified component computers, while maintaining overall system safety through the control computer's comparison of independent read-back results.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of manufacture

If single-channel diverse hardware computers are used for components, then hardware costs are reduced, but signaling safety may be compromised

Engineering Contradiction:
Improvehardware costVSAvoidsignaling safety
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The control computer receives independent read-back results from both the first and second component computers and compares them to verify correct operation. This feedback mechanism ensures that even though the component computers use simpler single-channel hardware, the overall system maintains SIL4 signaling safety through continuous verification of component energization states.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The control computer performs preliminary safety verification by comparing read-back results from the two component computers before allowing system operation to proceed. This preliminary check ensures that the diverse single-channel computers are functioning correctly and that the system maintains required safety levels.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If two-channel safe design is used for component computers, then safety is ensured, but space requirements increase

Engineering Contradiction:
Improvesignaling safetyVSAvoidspace requirement
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The component computer functionality is segmented across two separate single-channel computers with diverse hardware, each occupying less space than a single two-channel safe computer. The control computer coordinates these distributed components through a communication ring, achieving the same safety function in a more space-efficient manner.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3046825B1Level crossing safety system
Publication Date: 2020.06.17 SIEMENS MOBILITY GMBH
  • EP3046825B1 patent drawingFigure 1
  • EP3046825B1 patent drawingFigure 2

AI summary

The invention relates to a level crossing safety system having a control device for roadside components (3a, 3b; 4a, 4b, 4c, 4d), in particular gates (3a, 3b) and light signals (4a, 4b, 4c, 4d). In order to be able to replace computers which are secure in terms of signalling with computers which are not secure in terms of signalling, provision is made for the control device to have a control computer (6) which is secure in terms of signalling and for component computers (8a; 8b) which are not secure in terms of signalling to be associated with the components (4a; 4b), wherein the component computers (8a; 8b) each comprise a first and a second single-channel computer (10a, 11a; 10b, 11b) having diverse hardware, and for the control computer (6) and the component computers (8a, 8b) to have means for controlling and monitoring the components (4a; 4b) with the following sequence: - the control computer (6) transmits an actuating command to the first computers (10a; 10b) which control the component (4a; 4b) associated therewith, - the first and second computers (10a, 11a; 10b, 11b) of the component (4a; 4b) independently determine the energization of the component (4a; 4b) and transmit this read-back result to the control computer (6) and - the control computer (6) compares the actuating command thereof with the read-back results from the components (4a; 4b) and compares the read-back results with one another, in which case a safety response is triggered if at least one of the comparison results does not match.