Software Verification Controller for Automatic Train Operation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing automatic train operation systems lack a mechanism to verify and ensure the use of preapproved software configurations across multiple types and versions of software running on different subsystems, potentially leading to unsafe operation if unauthorized software is used.
Innovation Solution
A software verification controller is implemented to identify and authorize specific software configurations by checking against preapproved databases, ensuring that only approved combinations of software are allowed to run on the locomotive's subsystems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple types and versions of software are used across different subsystems to achieve functional versatility, then the adaptability and functionality of the automatic train operation system are improved, but the reliability and safety are worsened due to the inability to verify proper software combinations
Solution Approach 1:
The system performs preliminary verification of software configurations before allowing the locomotive to operate. The software verification controller checks whether the detected software configuration matches an approved configuration in the database before authorizing operation, preventing unsafe software combinations from being used.
Solution Approach 2:
A software verification controller is introduced as an intermediary component between the multiple control systems and the operation authorization. This controller detects software identifiers from different control systems, verifies the configuration against pre-approved databases, and determines whether to authorize operation, thus ensuring safety across diverse software configurations.
2Reliability
If a software verification mechanism is implemented to ensure safety by checking preapproval of software configurations, then the reliability and safety are improved, but the device complexity increases due to additional verification controllers and databases
Solution Approach 1:
The software verification controller serves multiple functions: it detects software identifiers from different control systems, stores approved software configurations in a database, verifies detected configurations against the database, and authorizes or prevents operation. This multi-functionality reduces the need for separate verification components for each control system.
Solution Approach 2:
The verification system combines the database of approved configurations and the verification logic into a single integrated software verification controller that interfaces with all control systems. This consolidation simplifies the overall system architecture compared to having separate verification mechanisms for each control system.
3Adaptability or versatility
If version control is implemented for software updates across different devices, then the adaptability to software improvements is improved, but the reliability is worsened due to lack of coordination between multiple software types and versions
Solution Approach 1:
Before allowing software updates to be deployed, the system pre-approves specific combinations of software configurations through the verification controller. This preliminary approval process ensures that updated software versions maintain proper coordination across different control systems and subsystems.
Solution Approach 2:
The software verification controller continuously detects software identifiers from control systems and provides feedback by verifying whether the current configuration is approved. This feedback mechanism ensures that software updates are properly coordinated across multiple subsystems by confirming compatibility before authorization.
Data Source
AI summary
An automatic train operation system includes a first control system configured to run a first software for controlling a first vehicle subsystem and a second control system configured to run a second software for controlling a second vehicle subsystem. The automatic train operation system also includes a software verification controller. The software verification controller is configured to identify a first identifier of the first software and a second identifier of the second software as a software configuration and determine whether the software configuration is preapproved. The software verification controller is also configured to, if the software configuration is preapproved, authorize the first control system and the second control system to run the first and second software.


