SIL4 Router Isolating Live Railway Traffic for Safe Remote Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for installing, testing, and commissioning trackside railway network equipment are laborious, inefficient, and potentially hazardous, requiring on-site tests and failing to maintain the required safety separation between live and test equipment.

Innovation Solution

A SIL4 Capable Router with multiple processor cores and a hot-swap 2oo3 system, utilizing Virtual Private Networks (VPNs) and VLANs to logically isolate test and real equipment, allowing remote commissioning and testing while ensuring safety integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If on-site testing and commissioning is performed following conventional methods, then equipment functionality can be verified, but the process becomes laborious, time-consuming, and potentially hazardous to engineers

Engineering Contradiction:
Improveequipment functionality verificationVSAvoidcommissioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a virtual copy of the production network environment within the router's processor cores. Test equipment can be commissioned remotely by creating virtual representations of the network topology, allowing validation without physical presence at the site. This copying approach maintains reliability of functionality verification while eliminating the need for time-consuming on-site testing phases.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The router acts as an intermediary between test equipment and the live production network. By using virtual private networks (VPNs) and virtual local area networks (VLANs) within the router's processor cores, the system mediates testing activities, allowing remote commissioning while maintaining safety separation. This intermediary approach enables functionality verification without requiring engineers to be physically present at hazardous test sites.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If on-site testing is performed to verify equipment functionality, then safety requirements can be assessed, but safety separation between test and live equipment is compromised

Engineering Contradiction:
Improvesafety integrityVSAvoidsafety risk to engineers
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network processing into distinct processor cores, with each core handling specific virtual private networks (VPNs) or virtual local area networks (VLANs). This segmentation creates logical isolation between test equipment and live production equipment within the same physical router. Engineers can assess safety requirements remotely without physical exposure to hazardous test environments, maintaining safety integrity while eliminating direct safety risks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The router's virtual networking capabilities serve as an intermediary layer between test equipment and the live production network. By routing test traffic through virtual networks in isolated processor cores, the system mediates safety assessments without requiring engineers to physically interact with live equipment. This intermediary approach maintains safety integrity through virtual separation while removing engineers from harmful test environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple VPNs are maintained in separate processor cores with hot-swap capability, then safety separation is maintained, but device complexity increases

Engineering Contradiction:
Improvesafety separationVSAvoidrouter architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple virtual private networks (VPNs) and virtual local area networks (VLANs) into a single physical router device, with each processor core handling specific virtual networks. This merging approach maintains safety separation through logical isolation while consolidating hardware resources. The hot-swap capability between processor cores provides redundancy without requiring multiple separate physical devices, thus maintaining safety separation while managing device complexity through resource consolidation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The router is designed with universal processor cores that can handle multiple different VPNs and VLANs through software configuration. Each processor core can be dynamically assigned to different virtual networks, providing multi-functionality within a single device. This universality maintains safety separation through configurable logical isolation while reducing device complexity compared to dedicated hardware for each network, as the same physical router can serve multiple safety-critical functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If remote commissioning is enabled through virtual network isolation, then engineering resources are reduced, but configuration and validation complexity increases

Engineering Contradiction:
Improvecommissioning efficiencyVSAvoidconfiguration management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates virtual copies of network configurations and topologies within the router's processor cores, enabling remote commissioning without physical site presence. By copying network structures into virtual environments, engineers can validate configurations remotely, improving productivity by eliminating travel and on-site setup time. The configuration and validation complexity is managed through automated virtual network creation and standardization of virtualization protocols.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system enables self-service commissioning through automated virtual network configuration and validation. The router's virtual networking capabilities automatically establish isolated test environments, perform validation checks, and manage configuration states without requiring manual on-site intervention. This self-service approach improves productivity by allowing remote automated commissioning while the standardized virtualization framework manages configuration complexity through automation rather than manual processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3539258B1Safety-critical router
Publication Date: 2020.08.19 SIEMENS MOBILITY LTD
  • EP3539258B1 patent drawingFigure 1~2
  • EP3539258B1 patent drawingFigure 3
  • EP3539258B1 patent drawingFigure 4~5

AI summary

A method which facilitates testing and commissioning of new network equipment in the live railway without interference to the working of the live railway environment. A multi- core router (100) is provided to manage existing, live equipment (10, 11, 12, 13) and new test equipment (15, 16, 17, 18) under test, in respective VPNs (14, 19). Master and Standby lanes are provided in the router to allow hot-swapping from one VPN configuration to another. This provides the means of testing the installed new railway network equipment within a live railway environment, whilst maintaining the required safety separation of the test and live equipment. This invention adds the flexibility of testing from a remote location with fewer resources.