Train Safety Bypass Authentication via Transaction Code

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing automatic safety systems in train protection systems often allow unauthorized bypassing of safety measures, leading to potential accidents due to lack of verification of technical or operational faults, and existing solutions either cause delays or require significant technical effort.

Innovation Solution

A method requiring user contact with an authorized person, verification of the necessity of the safety measure, generation and transmission of a transaction number, and comparison with a locally generated comparison number using independent authentication devices to enable bypass, ensuring a two-person assessment before deactivating the safety measure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the driver contacts the dispatcher to clarify the circumstances before bypassing a safety measure, then the safety system can prevent unauthorized bypassing, but this causes additional delays in train operations

Engineering Contradiction:
Improveprevention of unauthorized bypassingVSAvoidoperational delays
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

An automatic recognition system acts as an intermediary between the driver and the dispatcher. The system automatically transmits the current situation data to the dispatcher, who then sends back a recognition code. This automated intermediary process eliminates the need for manual phone calls while maintaining the safety verification requirement, thus preventing unauthorized bypassing without causing operational delays.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a time-limited restart block is provided after PZB safety measure, then the driver is given time to reflect and contact dispatcher, but this causes additional delays in train operations

Engineering Contradiction:
Improvedriver reflection timeVSAvoidoperational delays
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables the driver to independently obtain a recognition code through automatic transmission of situation data to the dispatcher. The driver does not need to wait for a predetermined time block or manually initiate a phone call. The system self-services the verification process by automatically preparing and transmitting the situation data, allowing the driver to quickly obtain authorization when needed.

Inventive Principle:
Principle #25Self-service

3Reliability

If an automatic connection to the dispatcher is provided after PZB security measure, then unauthorized bypassing is prevented, but this requires significant technical effort

Engineering Contradiction:
Improveprevention of unauthorized bypassingVSAvoidtechnical effort
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The recognition code system serves multiple functions: it verifies driver authorization, transmits situation data to the dispatcher, and provides a bypass authorization mechanism. By using a universal code-based approach rather than dedicated automatic connection hardware, the system achieves reliable prevention of unauthorized bypassing with minimal technical complexity, utilizing existing communication infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3272618B1Method and apparatuses for de-activating a security measure of an automatic security system
Publication Date: 2020.03.18 THALES MANAGEMENT & SERVICES DEUTSCHLAND GMBH
  • EP3272618B1 patent drawingFigure 1~2

AI summary

A method for operating an automatic security system (2) within a safety-critical system (1), wherein the security measure can be deactivated by a user (3), is characterized in that the security measure can only be deactivated if all of the following procedural steps have been carried out: • Contacting an authorized person (6); • Verification by the authorized person (6) as to whether a fault exists that necessitates the security measure; • If it is determined that no fault exists that necessitates the security measure: Generation of a transaction number (ID) by the authorized person (6); • Transmission of the transaction number (ID) to the user; • Entry of the transaction number (ID) into a local authentication device (9), which provides information regarding theThe algorithm used to generate the transaction number (ID) is used; • The authentication device (9) determines a comparison number; • The entered transaction number (ID) is compared with the comparison number; • If the transaction number (ID) and comparison number match: the bypass option is enabled. This easily prevents unauthorized circumvention of a security measure initiated by the automatic security system.