Virtualized Server Clusters for Rail Safety Hardware Error Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In rail-bound transport safety systems, hardware errors can go undetected when software operates on a virtualized server level, as processes are randomly assigned to hardware, potentially leading to incorrect calculations and compromised operational safety.

Innovation Solution

A server device with at least two physically separate server clusters, allowing process migration and ensuring that critical processes run on different hardware, with software split into parts across these clusters to maintain physical separation and detect hardware errors through result comparison.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of stationary object

If software is operated on a virtualized operating level of a server cluster, then availability is improved through process migration capability, but hardware error detection capability deteriorates due to random process assignment to hardware

Engineering Contradiction:
ImproveavailabilityVSAvoidhardware error detection capability
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The invention divides the server cluster into multiple physically separate server clusters, each running identical safety-critical processes. This segmentation ensures that processes are isolated on different hardware platforms, preventing a single hardware error from affecting multiple process instances simultaneously, thus maintaining hardware error detection capability while enabling availability through controlled process migration within the segmented architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention creates identical copies of safety-critical processes on separate server clusters. These process copies execute the same safety functions independently on different hardware, allowing comparison of results to detect hardware errors while maintaining high availability through failover capability between the copied process instances.

Inventive Principle:
Principle #26Copying

2Ease of operation

If processes are randomly assigned to individual computers in a virtualized server cluster, then ease of operation and maintenance is improved, but operational safety deteriorates due to undetectable hardware errors

Engineering Contradiction:
Improveprocess management flexibilityVSAvoidoperational safety
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The invention segments the virtualized environment into multiple physically separate server clusters, each maintaining independent hardware. This segmentation preserves the operational flexibility of virtualization while ensuring that safety-critical processes run on isolated hardware platforms, preventing undetectable hardware errors from compromising operational safety.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces a coordination mechanism that acts as an intermediary between the virtualized process management system and the physically separate server clusters. This intermediary ensures that process migration and assignment operations maintain the invariant that safety-critical processes run on different hardware platforms, reconciling operational flexibility with safety requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If multiple processes run on the same hardware in a virtualized environment, then device complexity is reduced, but measurement precision of hardware errors deteriorates

Engineering Contradiction:
Improvesystem architecture complexityVSAvoidhardware error detection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The invention segments the system into multiple physically separate server clusters, each running identical safety-critical processes. This segmentation increases hardware diversity while maintaining manageable system complexity through standardized process designs and automated coordination, thereby improving hardware error detection precision without excessive complexity increase.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3448735B1Server device operating a piece of software for controlling a function of a rail transport safety system
Publication Date: 2020.04.29 THALES MANAGEMENT & SERVICES DEUTSCHLAND GMBH
  • EP3448735B1 patent drawingFigure 1
  • EP3448735B1 patent drawingFigure 2

AI summary

A server device (1; 30), operating a piece of software for controlling a function of a rail transport safety system, wherein the software (11, 12, 13; 31, 32, 33) operates at least two processes (11a-11b; 12a-12b; 13a-13b; 31a-31c; 32a-32c; 33a-33c) physically separately from one another, the results of which are compared with one another in order to perform control of the function, is characterized in that the software (11, 12, 13; 31, 32, 33) is operated on a virtual operating level of the server device (1; 30), in that the server device (1; 30) comprises at least two physically separate server clusters (SC1, SC2, SC3), and in that the software (11, 12, 13; 31, 32, 33) comprises at least two parts that are installed on different server clusters from the at least two server clusters (SC1, SC2, SC3), so that the at least two processes (11a-11 b; 12a-12b; 13a- 13b; 31a-31c; 32a-32c; 33a-33c) are operated on different server clusters from the at least two server clusters (SC1, SC2, SC3). The invention provides a server device in which improved availability of a software application can be ensured amid simultaneously high dependability of the rail transport.