Redundant Controller for ECP Brake Command Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional electronically-controlled pneumatic (ECP) train braking systems face safety risks due to single-point failures, such as software or hardware failures in the head end unit, which can prevent the transmission of critical brake commands, leading to unintended brake releases during penalty brake applications.
Innovation Solution
A redundant processor or computer system is implemented to verify the transmission of train brake commands on a trainline connecting the lead locomotive to railroad cars, ensuring communication redundancy and independent verification of brake commands, and automatically facilitating or preventing pneumatic emergency brake applications based on the command status.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single head end unit (HEU) is used to transmit train brake commands in conventional ECP systems, then the system structure is simple and device complexity is reduced, but the reliability deteriorates due to single-point failures that can prevent critical brake command transmission
Solution Approach 1:
The single HEU is segmented into two separate controllers: a first controller that generates and transmits train brake commands, and a second controller that independently monitors transmission status. This segmentation eliminates the single-point failure risk by distributing critical functions across multiple independent components.
Solution Approach 2:
The second controller acts as an intermediary monitoring layer that independently verifies whether brake commands are successfully transmitted to railcars. This intermediary provides redundant verification without directly interfering with the primary brake command transmission function, enhancing reliability while maintaining operational simplicity.
2Reliability
If redundant controllers are implemented to verify brake command transmission, then the reliability improves by tolerating single-point failures, but the device complexity increases due to additional controllers and monitoring systems
Solution Approach 1:
The second controller performs self-verification by autonomously monitoring its own controller's transmission output and independently determining whether brake commands reached the railcars. This self-service approach provides redundant verification capability without requiring external monitoring systems, reducing overall system complexity while maintaining high reliability.
Solution Approach 2:
The system implements feedback through the second controller's continuous monitoring of brake command transmission status. The second controller receives feedback about transmission success or failure and can automatically trigger pneumatic emergency brake applications when transmission failures are detected, creating a closed-loop safety mechanism that enhances reliability without complex manual intervention.
3Object-affected harmful factors
If the second controller automatically triggers pneumatic emergency brake applications upon detecting transmission failures, then the safety improves by ensuring brake application during failures, but the ease of operation deteriorates due to automatic override of operator control
Solution Approach 1:
The second controller is pre-programmed with safety logic that automatically counteracts transmission failures by triggering pneumatic emergency brake applications when failures are detected. This preliminary anti-action is designed to override operator control only in failure conditions, automatically neutralizing the harmful effect of transmission failures before they can cause safety incidents.
Solution Approach 2:
The system converts the potentially harmful automatic override of operator control into a beneficial safety feature by designing the second controller to trigger emergency brakes only when transmission failures are detected. The override capability, which might seem to reduce operator authority, actually transforms a harmful single-point failure into a beneficial automatic safety response that protects the train when the primary control system fails.
Data Source
AI summary
A train control system and method for use in an electronically-controlled pneumatic (ECP)-equipped train having a lead locomotive or control car, at least one railroad car and, optionally, at least one trailing locomotive or control car. A first controller or computer generates a train brake command and directly or indirectly transmit the train brake command to the at least one railroad car. A second controller or computer separate from the first controller or computer determines transmission of the train brake command to the at least one railroad car.


