EP2643198A1 - Method for securing a control system of a reconfigurable multi-unit vehicle, and secured control system - Google Patents

Method for securing a control system of a reconfigurable multi-unit vehicle, and secured control system

Info

Publication number
EP2643198A1
EP2643198A1 EP11757325.3A EP11757325A EP2643198A1 EP 2643198 A1 EP2643198 A1 EP 2643198A1 EP 11757325 A EP11757325 A EP 11757325A EP 2643198 A1 EP2643198 A1 EP 2643198A1
Authority
EP
European Patent Office
Prior art keywords
unit
computer
identity
unit vehicle
vehicle
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
EP11757325.3A
Other languages
German (de)
French (fr)
Other versions
EP2643198B1 (en
Inventor
Eric Chenu
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Siemens SAS
Original Assignee
Siemens SAS
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Siemens SAS filed Critical Siemens SAS
Priority to EP11757325.3A priority Critical patent/EP2643198B1/en
Publication of EP2643198A1 publication Critical patent/EP2643198A1/en
Application granted granted Critical
Publication of EP2643198B1 publication Critical patent/EP2643198B1/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • BPERFORMING OPERATIONS; TRANSPORTING
    • B61RAILWAYS
    • B61LGUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
    • B61L15/00Indicators provided on the vehicle or vehicle train for signalling purposes ; On-board control or communication systems
    • B61L15/0072On-board train data handling
    • BPERFORMING OPERATIONS; TRANSPORTING
    • B61RAILWAYS
    • B61LGUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
    • B61L15/00Indicators provided on the vehicle or vehicle train for signalling purposes ; On-board control or communication systems
    • BPERFORMING OPERATIONS; TRANSPORTING
    • B61RAILWAYS
    • B61LGUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
    • B61L15/00Indicators provided on the vehicle or vehicle train for signalling purposes ; On-board control or communication systems
    • B61L15/0018Communication with or on the vehicle or vehicle train
    • B61L15/0036Conductor-based, e.g. using CAN-Bus, train-line or optical fibres

Definitions

  • the present invention relates to a method of securing a steering system of a multi-unit vehicle and a sys tem ⁇ safety control of said multi-unit vehicle, according to the preambles of claims 1 and 7.
  • the present invention relates to the field of multi-unit reconfigurable vehicles, ie able to be composed of several units and whose configuration or composition of said units of said multi-unit vehicle is variable, or in other words likely to be modified or re ⁇ configured.
  • the present invention relates to multi-unit vehicles whose operation of a control system, in particular automatic, is correlated to the composition of the multi-unit vehicle.
  • Said multi-unit vehicle belongs especially to do ⁇ maine rail.
  • a train can be formed of several units, e.g. several motorcyc ⁇ res and / or locomotives coupled or coupled to each other and successively forming a first train of said train.
  • the composition of said train, and therefore of said first train can then vary, e.g. by scindage or coupling said first string to form a second train compo ⁇ EDC to at least part of the units of said first train, which can be hitched to other units.
  • composition of a multi-unit vehicle can vary according to a change of a disposition or a distribution of said units forming said multi-unit vehicle, as well as by addition, and / or respectively withdrawal, of at least one audit unit, and / or respectively said multi-unit vehicle.
  • composition data from said multi-unit vehicle eg the number of units the component, the characteristics of said units, the relations between these units, their coupling or coupling to one or two other units, are known pilo ⁇ stage system for driving said multi-unit vehicle.
  • This control system generally comprises a computer connected to the I / O modules for a particular acqui ⁇ sition and a transmission operation of data ⁇ rela tive to the steering of multi-unit vehicle.
  • the computer is thus capable pilot, via inputs / outputs of modules, ⁇ the said multi-unit vehicle, in particular according to an automated that mode, or according to a manual mode wherein the control system, and thus the computer, is able to be controlled by a driver or control center.
  • the operating data is in particular exchanged, via the input / output modules, between said computer and devices included in at least a part of the units com ⁇ posing said multi-unit vehicle to ensure its func ⁇ tioning.
  • Said exchange of operating data can for example be implemented by means of a bidi ⁇ rectional connection between the computer and said devices via said input / output modules.
  • the calculator and mo ⁇ dules / O are thus designed to enable and ensure the control of the multi-unit vehicle, or otherwise work correctly (move, stop, door openings, ...), based on the composition data of said multi-unit vehicle and on operating data ⁇ relating to control exchangeable with said disposi ⁇ tifs of at least a portion of said units.
  • said composition data must be updated so that the control system, in particular its computer, is informed of said configuration change and is able to correlate the change composition of said multi-unit vehicle with a change of operating data relating pilo ⁇ tage.
  • the computer may misinterpret the operating data of the units which have been uncoupled from the multi-unit vehicle.
  • the driving system of the multi-unit vehicle must in particular be characterized by a high degree of functional safety in order to prevent any event that may affect said multi-unit vehicle or passengers or goods transported by said multi-unit vehicle.
  • the safety of such control systems can be characterized by means of safety standards.
  • IEC 61508 SIL challenge ⁇ nes (Security Integrity Level), that is to say the level of safety integrity that should have a system to ensure adequate protection against the risks that may arise during operation of said system.
  • a SIL4 security system provides a risk reduction of between 10 8 to 10 9 in the continuous mode of operation, whereas for an SIL1 system, this reduction is between 10 5 to 10 6 only.
  • control system computer knows exactly the composition and configuration of said multi-unit vehicle (for example, which units make up a train and according to what order of formation are they ordered, or in other words, in what order they are coupled or coupled) so that it can exchange with the units of multi-unit vehicle all the operating data necessary for piloting said vehi ⁇ multi-unit cule.
  • the control system computer in the case of a change in the composition of a multi-unit vehicle, for example, when a train is divided into several parts, the control system computer must be promptly informed of said composition change by example in order to allow oneself to no longer take into account operating data of units that have been detached from the train during its splitting, and so as not to fall into a state of safety resulting in a warning of a center for monitoring a vehicle network multi-unit or even activation of a secu rity ⁇ formatting process, as an emergency braking of said multi-unit vehicle.
  • steering systems whether in or ⁇ tomatiques manuals and safety (SIL 4), known to the art are essentially based on calculated ⁇ tors "closed" for which the perimeter / O is not reconfigurable, ie the computer is connected to a fixed set of I / O modules of in ⁇ Trees / outputs, these I / O fixedly connecting the computer devices to certain functional units managed by said computer, and thus not being reconfigu ⁇ rable when changing the configuration of the vehicle mul ⁇ ti-unit.
  • functional device reference is made to any device interacting with the control system so as to enable said multi-unit vehicle to be piloted. This is for example of braking, opening doors, or devices for monitoring the moving ⁇ said multi-unit vehicle, etc.
  • the management of a multi-unit vehicle generally implements several computers each managing a part of the multi-unit vehicle, each computer being connected to subscribers. trés / Outputs connecting them in a fixed manner to certain functional dis ⁇ positive or the unit it manages.
  • the composition of the multi-unit vehicle is well known by overlapping information from each computer, the design of the steering system has the structuriavan ⁇ duty floor manage functions spread over the dif ⁇ ent calculators, including requiring algorithms synchronization of said computers, whose complexity aug ⁇ mente with the number of units constituting the multi-unit vehicle.
  • composition or constitution of a multi-unit vehicle is thus generally deduced from cross-checks of several application information exchanged between the different computers of said vehicle.
  • This information app ⁇ cant is information from other devices of the multi-unit vehicle not having all task for pre ⁇ Mière determining the composition of said multi-guided vehicle.
  • This is, for example, the location data of the head and the tail of the multi-unit vehicle transmitted to the computer by on-board or ground locating devices, or the state of the equipment of the units, or multi-unit vehicles transmitted to the calculated ⁇ tor by an autopilot ground not embedded in said multi-unit vehicle.
  • An object of the present invention is to propose a method of securing a system for driving a reconfigurable multi-unit vehicle and a secure control system that are simple, safe, reliable and efficient, capable of automatic updating and autonomous of a composition of the multi-unit vehicle, while having a security SIL4 ⁇ tion.
  • the present invention aims to automatically determine and update the composition of the multi-unit vehicle, independently of application information, in order to safely guarantee the multi-unit vehicle control system.
  • the present invention provides a steering system of a security method for fitting and control a vee ⁇ vehicle reconfigurable multi-unit comprising in particular at least two attelables units one after the other, said method being characterized in that it comprises: - an autonomous determination, and preferably cyclic and automatic, of a composition of the multi-unit vehicle by a device for determining the composition of said multi-unit vehicle correlated to a generation, preferably ⁇ by said determination device, a composition data of said multi-unit vehicle;
  • the present invention also provides a secure, and preferably automatic, pilo ⁇ system for a reconfigurable multi-unit vehicle, comprising for example at least two towable units one after the other, ca ⁇ characterized in that said system comprises:
  • a device for determining a composition of the multi-unit vehicle capable of determining autonomous manner the composition of the multi-unit vehicle and ⁇ gen erate a given composition correlatable to said compo sition ⁇ said multi-unit vehicle said determination being in particular autonomous in that it is independent of any application information;
  • At least one computer comprising at least a security module
  • said computer being designed to equip at least one unit of the multi-unit vehicle, each calculated ⁇ tor being connectable by means of at least one connection and via a network, of a part to a set of En- I / O module outputs / outputs intended to equip one or more units, and secondly to said device for determining the composition of the multi-unit vehicle, in order to exchange via each input / output module data unit operation and / or multi-unit vehicle, and to acquire said determining device, a composition of the ⁇ given said multi-unit vehicle, said network being in particular intended to permit communication between each identity generating device and each computer, between each computer and each input / output module, and between each computer between them;
  • each computer may include a security module according to the invention.
  • the method according to the invention is a formula ⁇ securing method, preferably automatically and particularly SIL4 securing, of a steering system of a multi-unit vehicle able to determine at any ⁇ ins as and reliably, the composition of the multi-unit vehicle, and to ensure, at all times, a coherence between the composition of the multi-unit vehicle and data func ⁇ steering system tioning of the multi-unit vehicle, the combination of at least one computer with said set of inputs / outputs correlated to said composition vee ⁇ vehicle multi-unit.
  • the method according to the invention is characterized in particular by a cyclic check, in particular of random or fixed frequency, but in all cases a sufficiently frequent check (for example, at least one verification per time interval less than or equal to 100 milliseconds), particularly by means of the security module, a coherence between the connection of each element of said set of elements with said set of inputs / outputs and said composition data.
  • the present invention is characterized in that said set of elements comprises or is a group of computers that can be distributed in each unit of said multi-unit vehicle.
  • the steering system according to the invention preferably comprises said group of computers that can be composed of several identical cal ⁇ culados, each computer may in particular be distributed in a unit of the multi-unit vehicle, so that each unit is likely to be equipped by at least one computer.
  • the sécurisa- tion module is in particular able to assign exclusively to connection to said set of trees In ⁇ / outputs, including at each entrance / exit of said ensem ⁇ ble / O, to a single computer of said group of computers, the other computers of said group of computers being excluded from said connection or in other words, prohibited access to said set of Inputs / Outputs.
  • the method according to the invention may include a securing mechanism and prioritization of connecting at least one computer of said calculators tors group with said set of I / O capable of attri ⁇ exclusively to said computer said connection to said set of Inputs / Outputs.
  • the elected computer ie having the exclusive access to the set of inputs / outputs is called the master computer.
  • at least one other computer of said group calculator is in particular associable to the master computer as cal ⁇ culateur said redundant master computer.
  • the control system according to the invention is particularly capable not only ⁇ to select a master computer from the calculator group but also to appoint a redundant computer of said computer group.
  • the redundant computer is able to perform the same operations as the master computer, to acquire the same composition and operating data as the master computer for the purposes of verifying and securing the control system. In the event of failure of the master computer, the redundant computer is able to replace said master computer and to name a new redundant computer.
  • said security and prioritization mechanism comprises a generation of an encoded association token able to lock said connection of at least one computer of said group of computers with said set of Inputs / Outputs, and a generation of a key déverrouil- spinning adapted to unlock said connection of at least one of said computers cal ⁇ culateur group with said set of inputs / outputs.
  • at least one control system of the computer may in particular be equipped with a mo dule ⁇ securing ca- pable comprising a locking module for locking each computer connection with each of the Inputs / Outputs of said set of Inputs / Outputs.
  • This locking module comprises in particular a combination ⁇ genera tor encoded token capable of generating, in particular cyclically, first said encoded combination token to lock each connection of said computer with each of the inputs / outputs of said set 'Inputs / Outputs, and secondly said unlocking key able to unlock ⁇ ler at least one connection of said computer with at least one of the inputs / outputs of said set of inputs / outputs.
  • the method according to the invention is characterized in that said autonomous determination comprises a successive and ordered addition to a list, according to a composition order of said multi-unit vehicle, of at least one piece of identity data of each unit.
  • said multi-unit vehicle fa ⁇ con that a sequence of the identity data comprised in said list is correlated to the order of com ⁇ units digit of said multi-unit vehicle, each identity data being specific to a single unit of the multi-unit vehicle, and said list being able to be encapsulated in said composition datum.
  • the identity data includes at least a time data, a iden tifying ⁇ unit, constant coding and at least one identifier of an appliance of said unit.
  • the steering system according to the in vention ⁇ is especially characterized in that its device for determining a composition of the multi-unit vehicle comprises at least an ID generation device, each generating device identity détermi ⁇ nation device being designed to equip a unit of the vehicle multi-unit, so that each unit can be equipped with a single identity Generator device, each identity generation device being capable of generating the identity of the unit it is intended to equip.
  • the method according to the invention is thus characterized in particular by equipping each unit of said multi-unit vehicle with said identical identity generating device capable of generating said identity data for determining the composition.
  • each unit of the multi-unit vehicle may comprise a device genera ⁇ identical identity, each identity Generator device being connectable or couplable to at least one other identification generating device, so as to form a chain of identity generation devices equipping cha ⁇ cun a unit of said multi-unit vehicle and coupled one after the other.
  • said identity generation device which is on the one hand intended to allow the determination of a composition of the multi-unit vehicle comprising at least one unit, and secondly capable of equipping said control system. of said multi-unit vehicle, is characterized in that it comprises:
  • an identity data generator able to gen erate ⁇ said identity data of the unit that the Identity Generator device is intended to equip, the said identity data being intended to allow an identification of said unit;
  • connection detector adapted to detect a presence or absence of said coupling Identity Generator device with at least one other available ⁇ ID generation operative part
  • a list generator capable of creating a list of elements intended to include elements able to be ordered and added successively;
  • serialization component capable of adding another element to said list, either following a last element of a list of controllable elements successively intended to be received by the ⁇ said identity generating device, either as the first element of the list of elements that can be created by the list generator, said other element comprising said identity data;
  • a list of transmitter capable of transmitting ⁇ said list of elements comprising the other element or to another identification generating device, or at least one computer, comprising said particular security module of the control system of the multi vehicle -unity, after encapsulation of the ⁇ said list in a given composition of said vee ⁇ vehicle multi-unit.
  • said determination of the composition of the multi-unit vehicle is carried out by means of said identity generating device according to the following steps:
  • each Identity Generator device of each unit of the multi-unit vehicle of said identity data to enable an identification of the unit as said team generating device, said generating being above ⁇ ceptible to be carried out by said identity data generator;
  • connection detector for each identity generating device, a presence or absence of coupling of said identity generating device with at least one other identity generating device
  • com ⁇ takes the following substeps:
  • said method comprises a design, by the list generator genera said device Identity ⁇ characterized by said absence of coupling with another identity generating device, a list of elements for com ⁇ to take successively ordered elements, ⁇ said list comprising a first element, said pre ⁇ first element comprising said identity data of the unit intended to be equipped by said identity generating device characterized by said ab ⁇ sence of coupling with another device for gené ⁇ ration of identity, said first element being the first element of the list created by the list generator, said creation being followed by a encap ⁇ sulation of said list in said data of
  • the determination of the composition of the multi-unit vehicle can be achieved by means of a device internal to the system.
  • Steering tem ie by means of or devices ⁇ gen eration identity determination device of com ⁇ position of the multi-unit vehicle, independently of other external devices to the control system that would acquire des- Tines said application information.
  • Each identity generation device equipping each uni ⁇ t of the multi-unit vehicle is thus connectable to one or two identical identity generation devices so as to form a chain of identity generation devices capable of being transmitted successively. said list.
  • each identity generation device com ⁇ takes at least two connectors, respectively a first and a second connector, each intended for coupling said identity generating device ⁇ with the other identity generation device, ie one of its neighbors in said chain of identity generation devices.
  • Said list can be created by the list generator of one of the two, see two, ID generation devices located at the end of said chain when the vehicle ⁇ mul ti-unit comprises more than two units.
  • the die device ⁇ termination of said composition thus comprises as many Identity Generator device of the multi-unit vehicle comprises units.
  • Each generation identity tion devices is capable of generating the identity data of the unit it is fitted and to transmit to the one or respecti vely ⁇ any of its neighbors, said list after the latter transmitted to him by the other, respectively one of his neighbors.
  • said list generator is in particular able to cyclically create said list.
  • said list generator is capable of creating said list when said connection detector detects said coupling presence of said identity generating device with only one other identity generating device or with no other generation device. identity.
  • identity the creation of said list by the list generator of at least one of the identity generation devices located at the end of the chain, allows a control and a continual update of the composition of the multi-unit vehicle when the latter is composed of at least two units, since the list may be continuously transmitted to the calculated ⁇ tor via said given composition when said list has passed through the whole chain of iden- tity generating devices.
  • each unit comprising said steering system is capable of being autonomous, ie it is able to move, to manage its movement and its operation independently of any other steering system external to said unit.
  • control system that can be associated with an autonomous unit is able to control and manage the movement of other units that can be coupled or coupled to it, that these other units comprise at least one other autonomous unit and / or at least one other unit.
  • non-autonomous unit is a unit which comprises only a part of the control system, in particular at least one identity generating device, each of these devices being connectable to the network of said unit, it being even connectable to the network of other units that are likely to be coupled or hitched to form the network of the multi-unit vehicle.
  • an ⁇ ton unit will be able to embark said control system according to the invention, and a non-autonomous unit will refer to a unit that does not have the entirety of said em ⁇ barking control system. .
  • a multi-unit vehicle is then likely to be formed of at least one autonomous unit that can be coupled, or not, to one or more autonomous or non-autonomous units.
  • a computer of one of the autonomous units will be in particular responsible for the management of the control and operation of the multi-unit vehicle.
  • the master calcu ⁇ tor of one of the autonomous units is intended to control the multi-unit vehicle.
  • An automatic designation of the master computer for controlling said multi-unit vehicle is feasible as a function, for example, of the formation order of the multi-unit vehicle deductible from said composition datum that can be acquired by each calculator of each unit. .
  • the security module of the control system is on the one hand able to connect each computer to said set of inputs / outputs to allow an exchange operating data between each computer and the functional devices of the units of the multi-unit vehicle, but also, and secondly, to prioritize the connection of said automatically designated master computer to said set of inputs / outputs and to associate a calculator redundant.
  • priority it is in particular referred to the attributed exclusive ⁇ tion of the connection with said set of trees In ⁇ / output to a computer, preferably a single cal ⁇ culateur, for example said master computer, or the - says master calculator with redundant sound.
  • the set of trees In ⁇ / O modules I / O of the pi system ⁇ secure lotage connects each computer vee ⁇ vehicle multi-functional unit devices of said vehi ⁇ cule multi-unit via the network multi-unit vehicle, said network being common to all calculators of the vehicle mul ⁇ ti-unit.
  • the control system is able to choose at least one computer from all the computers distributed on the network of said vehicle so that it acts as master computer to be directly associated, by connection to said set of trees in ⁇ / outputs, the inputs / outputs of said modules to drive the vehicle, for example automatically.
  • the computer acting as a master computer driver said vehicle the other computers of said vehicle ⁇ wind in particular be in a standby state, so that only the computer chosen as master computer by the security module controls the steering of said vehicle. Examples of embodiments and applications provided with the aid of the following figures will help to better understand this invention.
  • FIG. 2 exemplary embodiment according to the invention of an identity generation device.
  • FIG. 3 example of a mechanism for securing a security and prioritization mo ⁇ module according to the invention.
  • Figure 1 shows a safety controller adapted for controlling a multi-unit vehicle re ⁇ configurable comprising three units 1, 2, 3.
  • the control system comprises at least one device for generating identity 4, each identity generation device 4 is designed to equip a unit 1, 2, 3.
  • each uni ⁇ tee 1, 2, 3 is adapted to include said device genera ⁇ ID 4.
  • Each identity generation device 4 is connectable to its neighbors in order to form a chain of identity generation devices. Said chain of identity generation devices connectable one after the other form said device for determining a com ⁇ position of the multi-unit vehicle according to the invention.
  • Said secure control system further comprises at least one computer 5 intended to equip each autonomous unit 1, 2 of the multi-unit vehicle, at least one input / output module 91, and at least one of said computers 5 of the pilosebaceous system ⁇ secure floor comprising at least one security module 6, optionally included in the computer 5.
  • at least one computer 5 intended to equip each autonomous unit 1, 2 of the multi-unit vehicle, at least one input / output module 91, and at least one of said computers 5 of the pilosebaceous system ⁇ secure floor comprising at least one security module 6, optionally included in the computer 5.
  • particu ⁇ bind several computers 5 are distributed in several independent units 1, 2, and several modules / O 91 are distributed in several units, whether or not the ⁇ tonomes autonomous.
  • a network 8 of the multi-unit vehicle is used to connect the computers 5, the secu ⁇ authorization modules 6, the device for determining the composition of the multi-unit vehicle, modules I / O 91, and the functional devices 7 from each unit to each other so that they can communicate and exchange information, such as composition data and operating data, with each other.
  • the I / O modules 91 of the control system allow the connection, via the network 8, of the calcu ⁇ latters to a set of inputs / outputs, each input / output being able to connect at least one functional device 7 to at least one computer 5.
  • Each computer 5 is in particular dynamically reconfigurable on the basis of the composition data supplied by the device for determining the composition of the multi-unit vehicle, in order to maintain in real time a connection with said I / O coher ⁇ annuity with the composition of said multi-unit vehicle.
  • Each identity generation device 4 is connectable, in particular by means of a bidirectional differential connection at low speed serial to at least one other genera device ⁇ identity 4a, 4b identical, especially two ⁇ identical identity generation devices 4a, 4b as shown in FIG. 2.
  • Each identity generating device 4, 4a, 4b comprises an identical data generator 41, a connection detector 42, a signal generator list 43, a serialization component 44, a list transmitter 45, and at least two connectors, respectively a first connector 46a and a second connector 46b, for the acquisition and transmission of the list.
  • a third connector 47 may in particular connect the identity generating device to the network of the unit or the multi-unit vehicle.
  • connection detector of the identity generation device is particularly characterized in that it is able to guarantee in safety that a list has an input on the first connector 46a or the se ⁇ cond connector respectively. 46b and intended to be acquired by said identity generating dis ⁇ positive, can not be found by crosstalk or any other coupling on the second 46b or respec ⁇ tively the first connector 46a.
  • connection detector connectable to said connectors 46b, 46a, may in particular comprise at least one electrically isolated differential buffer, in particular a first buffer 422 connectable to the first connector and a second buffer connectable to the second connector, as well as receivers opto-couplers, in particular a first optocoupler receiver connectable to the first connector and a second opto-coupler receiver 421 connectable to the second connector.
  • protection components against disturbances and surten ⁇ ⁇ tions can be added to said detection device, as well as filters to ensure safe isola ⁇ tion between the first and second connector 46a, 46b.
  • said serialization component 44 may comprise two separate digital components 441, 442, for example FPGAs, capable of performing functions sé ⁇ Serialization and de-serialization of an item in said list, and the add function another element after the last element of that list, in particular in order to safe firing a list can not cross the dispo ⁇ ID generation operative part of the connector 46a to the connector 46b, or vice versa, without having been enriched with the identity data of said identification generating device.
  • two separate digital components 441, 442 for example FPGAs
  • the identity data generator 41 is partly ⁇ ticular, to generate a polarization information, said bias information to, optionally to propagate the list comprising said identity data only to one and only one of said first or second 46a connectors or 46b.
  • said identity data can advantageously comprise various information allows ⁇ as an identification of the unit which it is fitted, such as a device number or a unit number of the uni ⁇ ty it equips.
  • the list of transmitter 45 is able to act as an interface between the network, eg an IP Ethernet network, the multi-unit vehicle and the gen ⁇ eration identity device. To this end, it may possibly under- stand a digital component such as a logic circuit ⁇ grammable FPGA.
  • is a coding constant of sufficiently large value, expressed on, for example, 48 bits of information, in order to guarantee the security objective SIL4 such that the sequence of ⁇ 1 presents a pseudo-random distribution;
  • I di is the identity data of the unit i of the multi-unit vehicle
  • Data ⁇ is a data characterizing at least one equipment of the unit i or an identification number of the unit
  • the control system according to the invention is thus able to ensure that at least one computer, preferably the master computer is associated consistently seems to ⁇ functional devices of the multi-unit vehicle to ensure driving said multi-unit vehicle.
  • the security module associates, preferably exclusively, a connection to a set of distributed I / O on the network of said multi-unit vehicle with a computer. in particular with a master computer, said inputs / outputs being intended to connect said calculator to the functional devices of the units that make up said multi-unit vehicle.
  • each cal ⁇ culateur is coupled to a security module according to the invention, and each security module according to the invention is adapted, in dependence on said data to composition ⁇ trate into an idle mode or in a active mode, so that a single securing module is active for the multi-unit vehicle.
  • at least one condition pre ⁇ definable in each of said secure modules per- makes each of security modules to determine its own operating mode, ie either said active mode or said inactive mode.
  • Said predefinable condition can for example be correlated to a position within the multi-unit vehicle of the unit equipped with a computer comprising said security module.
  • FIG. 3 shows an exemplary mechanism for securing the association of at least one computer of a control system according to the invention with a set of inputs / outputs of input / output modules intended to equip the vehicle. multi-unit.
  • the secu ⁇ authorization module comprises in particular an encoded association token generator capable of generating an encoded association token comprising in particular a unique identification code of the computer or computers group allowed to be connected to inputs / outputs of said modules ⁇ Trees In / Out.
  • the locking module of the security module is capable of transmitting said token to all inputs / outputs of modules whose I / O must be connected to said computer or group of calcu ⁇ freezer in order to be consistent with said data composi ⁇ multi-unit vehicle, and to allow
  • Don ⁇ born composition allows particularly security module to determine which I / O modules to which Inputs / Outputs must be controlled by the computer or computer group to operate the multi-unit vehicle, therefore determine which trees in ⁇ / O must be connected to said computer or computer group.
  • Each I / O module receiving said asso ciation ⁇ encoded token is in particular able, during a response phase, periodically transmitting or sufficiently frequently a confirmation message capable of confirming the connection of said computer with I / O said module In- puts / outputs, and to transmit said message confirmed ⁇ said computer, in particular to said security module of said computer of the safety controller.
  • Said confirmation message may for example be transmitted periodically to pe ⁇ a transmission period whose value temporal links, ie its length, may be predefined.
  • the response phase may be preceded by a phase of ini ⁇ tialisation 1 allowing generation and initialization of the confirmation message.
  • the duration of this phase initiali sation ⁇ is in particular greater than the duration of said pe- transmission period to ensure that the safe securing mechanism has time to detect that a calculated ⁇ tor or a group of computers previously connected to an input / output of an input / output module a or have per ⁇ said connection with said input / output before another calculator or another group of calculator has had the time to connect to said Input / Output.
  • This duration of the initialization phase greater than the transmission period may be for example guaranteed by a pseudo random generator ⁇ toire to operate continuously during said initialization phase of the confirmation message.
  • a confirmation message initialized 2 is generated by the module ⁇ Trees In / Out.
  • the input / output module is able to associate, during an association phase 4, said token of coded association to said initialized confirmation message.
  • said 5 confirmation message is ready to be sent periodically to secu ⁇ authorization module.
  • this confirmation message following said step of association, comprises firstly said donation ⁇ born identification of the computer or computer group, but also on the other hand, identification of In- puts / Outputs input / output module connected to said computer or group of computers, and a tempo ⁇ real data to verify a freshness of the confirmation message ⁇ tion.
  • the confirmation message is then sent, in particular ⁇ cyclically during the response phase 6, at least au said security module that issued the coded token combination.
  • the locking module said security module is in particular able to decode the message confirmed ⁇ order to control the inputs / outputs of said module I / O are connected to said computer or said computer group, and not of other calculators.
  • the I / O module As long as an I / O module is connected to a computer or computer group via its inputs / outputs, said I / O module generates, in particular cyclically, said transmission period confirmation message and no other calculator can be connected to it.
  • the Association token generating said verrouil- spinning module is capable of generating a desti unlocking key ⁇ born to be transmitted by the locking module to ensem ⁇ ble modules I / O whose connections with the computer or the computer group are to be cut.
  • the I / O module Upon receipt of such an unlocking key 7, the I / O module is particularly adapted to disassociate the coded association token from the initial confirmation message in order to restore said initialized confirmation message 2.
  • the I / O module is able to reset by returning to the initialization phase of the confirmation message in order to allow, for example, a combination of encoded token from another computer is capable of being associated with said initiali confirmation message ⁇ sé.
  • the response phase 6 for sending, in particular cyclically, in the security module confirmation via said confirmation message that the inputs / outputs of said module I / O are connected and controlled by the calcu ⁇ freezer, for example the master computer, or by a group of computers, for example the master computer and its redundant.
  • Said security module is thus able to bind particu ⁇ continuously check consistency of the computer connection with each module I / O for which it has received said confirmation message and said given composition, thereby ensuring the safe connecting a calculator to said set of Inputs / Outputs.
  • Figure 4 discloses an automatic coupling a first vehi ⁇ cule multi-unit 1 with a second multi-unit vehicle 2 com- each taking a safety control system according to the inven ⁇ to form a new vehicle multi- unit.
  • the two multi-unit vehicle such as a first train with three cars and a second train with two cars each include a distributed safety control of their own, said secure control sys ⁇ tems of each multi-unit vehicles being independent of one another.
  • the first vehi ⁇ cule multi-unit 1 comprises in particular three units
  • the second multi-unit vehicle 2 comprises in turn two units.
  • the control system of the first multi-unit vehicle 1 com ⁇ takes in particular at least three computers 51, 52, 53 and at least three I / O modules 91, 92, 93, linked by a first network 81, for example Ethernet, PLC, Wi-Fi.
  • the second multi-unit vehicle 2 comprises in particular at least two computers 54, 55, and at least two I / O modules 94, 95, connected by a second network 82.
  • at least one computer and at least one module I / O of the safety controller are designed to equip a unit, so that each unit comprises at least one calcu ⁇ freezer and at least one I / O module. So, in this example, each unit is an autonomous unit.
  • the first and second multi-unit vehicle could equally comprise one or more non-autonomous units, each non-autonomous unit comprising for example at least one module / O device and a gen ⁇ eration identity .
  • One of the computers 51, 52, 53 of the first multi-unit vehicle 1 is chosen to be the master computer of the first multi-unit vehicle 1, for example the computer 51 capable of being positioned at one end of said first multi-unit vehicle 1, and possibly another of the computers 51, 52, 53 of the first multi-unit vehicle 1 is chosen to be its redundant, for example the computer 53 positionable at the other end of the first multi-unit vehicle 1.
  • one of the computers 54, 55 of the second multi-unit vehicle 2 is chosen to be the master computer of the second multi-unit vehicle 2, for example the computer 54 posi ⁇ tionable at one end of the second multi-unit vehicle 2, and possibly another of ECUs 54, 55 of the second multi-unit vehicle 2 is selected to be its redundant, for example the computer 55 positionable other Extremists ⁇ mite second multi-unit vehicle 2.
  • the Sécuri control system ⁇ comprises in particular a master computer positioned itself ⁇ ble, particularly in a self-contained unit, to one end of the multi-unit and a computer vehicle placed in redundancy ⁇ said master computer , ie its redundant, positionable, especially in an autonomous unit, at the other end of said multi-unit vehicle, to allow efficient splitting of said multi-unit vehicle.
  • the other computers of the first multi-unit vehicle 1, respectively of the second multi-unit vehicle 2 are in an inactive state, such as, for example, the computer 52 of the first multi-unit vehicle 1.
  • the choice the master computer and its redundant may be based on a choice algorithm using a numbering, such as an IP address or a computer number, or a determination of a position of the computers in the multi-unit vehicle, said position being for example a po- central position, a position at the head or tail of multi-unit vehicle, the position of a calculator being deductible from said composition data.
  • At least one securing mechanism and priorisa ⁇ a security module of a steering system of the computer is adapted to select said master computer and its redundant, and therefore allows a prioritization calcu ⁇ freezer master, or in other words, an exclusive connection of the master computer with I / O modules of in ⁇ Trees / outputs of the multi-unit vehicle, so that only the master computer is able to control the inputs / outputs of the modules I / O for providing said vehi ⁇ multi-unit cule.
  • the redundant computer is able to take control of said inputs / outputs in the event of failure of the master computer.
  • said security module capable of performing said securing and prioritization mechanism can optionally be selected automatically according to said given composition for each of said multi-unit vehicles.
  • the security module is able to choose as master computer via its mechanism of securing and prioritizing the computer that it is intended to equip.
  • the security module is preferably able to prioritize the computer that it equips.
  • a security module 6 of the first multi-unit vehicle 1 is able to select said computer 51 as master computer to enable the master computer to control the inputs / outputs of the I / O modules 91, 92 93, of the first multi-unit vehicle 1 via the first network 81.
  • a security module 6 of the se ⁇ multi-unit vehicle 2 is able to choose said calculator 54 ⁇ as master computer to him to control the inputs / outputs of the modules of En- 94, 95 of the second multi-unit vehicle 2 via the second network 82.
  • each computer according to the invention when it is the redundant computer of a master computer, is particularly capable of checking a state of synchronization of its context with a context of said master computer.
  • the master computer and its re ⁇ dondant when the context of the latter is checked synchro to that of the master computer, are able to be connected to the input / output of the input / output modules that are associable.
  • the module sé ⁇ curisation 6 of the master computer is able to Lock ⁇ l, by means of an association encoded token, the du- connection said master computer and its redundant with said ⁇ Trees in / outputs.
  • the steering system of the first multi-unit vehicle 1 is further characterized in that it comprises at least one provi ⁇ tif Identity Generator, in particular three provisions ⁇ tive of Identity Generator 41, 42, 43, each of which is intended to equip a unit of the first multi-unit vehicle 1.
  • the control system of the second multi-unit vehicle comprises two identity generation devices intended to equip, each, a unit of said second multi-unit vehicle. 2.
  • a first identity generation device 41, a second identity generation device 42 and a third identity generation device 43 equip each of them.
  • a unit of the first multi-unit vehicle 1 and a first identification generating device 44 and a second provi ⁇ tif Identity Generator equip said second multi-unit vehicle.
  • the identity generating devices 41, 42, 43 of the first multi-unit vehicle 1, respectively those of the second multi-unit vehicle 2, are connectable one after the other in order to form a first dispo chain.
  • Each identity generation device is capable of communicating and exchanging data, including said list according to the invention, with its neighbor (s).
  • communication may be established from one end of the chain of identity generating devices to another, or in other words one end to the other of the multi-unit vehicle, either in a first direction of the head to the tail of the multi-unit vehicle, for example the genera device ⁇ identity 41 located at the head of the vehicle multi- unit identity Generator device 43 located at the tail of said multi-unit vehicle, or conversely, from the tail to the head of the multi-unit vehicle, for example the genera device ⁇ identity 43 queue at the identity generation device 41 at the head, or even in both directions at the same time.
  • the identity generating devices 44, 45 of the second multi-unit vehicle are examples of the second multi-unit vehicle.
  • At least one of the identity generation devices 41, 42, 43 of the first multi-unit vehicle 1, res ⁇ respectively of the second multi-unit vehicle 2, in particular located at the end of the first chain, respectively of the second string, is able to initialize said list according to the invention, for example a first list for the control system of the first multi-unit vehicle 1, and a second list for the second multi-unit vehicle 2.
  • Each of these lists preferably comprises a time data, for example a date , and allows an encoding of the composition of the multi-unit vehicle for which it was generated.
  • the first list is adapted to be initialized for the pre ⁇ Mier multi-vehicle unit 1 by one of its devices ⁇ gen eration of identity and enable an encoding of the composition of said first multi-unit vehicle 1, and a second list will be able to be initialized for the second multi-unit vehicle 2 by one of its iden ⁇ tite generation devices, and will also allow encoding of its composition.
  • Each identity generation device 41, 42, 43 of the first multi-unit vehicle 1, respectively each Identity Generator device 44, 45 of the second vehicle ⁇ mul ti-unit 2, is able to accumulate or add an identity datum in said first list, respectively is ⁇ list after the last element (for example following the last identity data) added in said first, respectively second list by the preceding identity generation device .
  • the identity generation device located at the other end of said first chain, or second chain, ie located at the end of the chain, is in particular able to transmit, in particular cyclically, said first list, respectively second list, encapsulated in a given composition, the calculated ⁇ tor master 51 and its redundant 53 via said first network 81 in the case of the first multi-unit vehicle 1, and the cal ⁇ culateur master 54 and its redundant 55, via said second network 82 in the case of the second multi-unit vehicle 2.
  • the identity Generator device capable of receiving the first list by one of its connectors and the second list by another of its connec ⁇ tors is in particular able to create a new list comprising the elements of the first list, which is added first the identity data created by said device - generation tif capable of receiving the first and ⁇ count list, and then the second list elements.
  • the new list thus includes the identity data of all the units comprising the multi-unit vehicle.
  • the Identity Generator device capable of receiving the first list by one of its connectors and the second list by another of its connectors is capable of selecting either the first list or the second list, ie only one of the two lists, in order to transmit it to an identity generation device located at the end of the chain.
  • one and only one of the two lists is adapted to propagate towards one and only one Identity Generator device located extremi ⁇ side chain, intended to support the creation of the list complete identity data of all the units composing the multi-unit vehicle.
  • the Identity Generator device that created said nou ⁇ velle list is further capable of encapsulating said new list in said given composition so that it is transmitted, in particular cyclically, with at least one computer, for example to all the computers equipping each of the vehi cles ⁇ multi-unit or preferably to the master computer 51 and its redundant 53.
  • the first network 81 and second network 82 are connectable to one another to form a new network 83, said new network 83 being a meeting of the first network 81 and the second network 82.
  • the new device for determining the composition of the new multi-unit vehicle 3, consisting of devices ⁇ gen eration identity of the first and second multi-unit vehicle, is able to transmit via said new network 83, said data composition the new multi-vehicle unit 3, to all computers of the new multi-unit vehicle 3, in particular to at least one secu ⁇ authorization module receives said given composition.
  • each pilo ⁇ tage system is capable, by means of said unlocking key transmitted by their respective security modules, to cut the connection of at least one of its cal ⁇ culators, especially all its calculators, auditing ⁇ appear I / O as soon as detection of a variation of ⁇ said composition data.
  • the security module of the control system according to the invention is able to detect said variation of the composition data and to cut the connection of at least one computer with said set of inputs / outputs, in particular the connection of the master computer and its redundant, to allow a new master computer and its redundant to take control of said inputs / outputs by connecting.
  • a new security module 6, chosen for example according to the composition data of the new multi-unit vehicle 3, determines said new master computer and its redundant.
  • the new master computer is located at one end of the new vehi ⁇ cule multi-unit 3, for example the computer 51, and re ⁇ dondant at the other end, for example the computer 55.
  • the other computers 52, 53, 54 of the new multi-unit vehicle 3 are preferably in an inactive state.
  • the new security module 6 of the control system of the new multi-unit vehicle 3 is then able, on the basis of said composition data, to connect at least one computer, in particular said new master computer and its redundant, to the set of inputs / outputs of the I / O modules 91 to 95 of the new multi-unit vehicle 3.
  • the security module 6 is able to validate a coherence between the inputs / outputs associated with the computers and the composition data
  • the pilo system ⁇ floor of the new multi-vehicle unit 3 is adapted to take control of said I / O for controlling the said functional ⁇ positive the new multi-unit vehicle allows ⁇ as his driving.
  • Figure 4 also helps explain a scindage a vehi ⁇ cule multi-unit equipped with a safety control system ⁇ lon the invention.
  • a multi-unit vehicle for example of said new multi-unit vehicle 3, into two or more other multi-unit vehicles, for example into a first multi-unit vehicle 1 and a second multi-unit vehicle 2
  • said new identity generation device chain of said new multi-unit vehicle formed of the identity generating dis ⁇ positives 41 to 45 is broken, separated into two parts, for example into said first chain of identity generation devices 41 to 43 of the first multi-unit vehi ⁇ cule 1, and said second chain provi ⁇ tive Identity Generator 44, 45 of the second vehicle ⁇ mul ti-unit 2.
  • the network 83 of the new multi-unit vehicle 3 is separated into a first network 81 of the first multi-unit vehicle 1 and into a second network 82 of said second multi-unit vehicle 2.
  • each of the two parts of the positive dis- chain identity of the new multi-unit vehicle 3 is ca pable ⁇ generate independently and automatically a given nou ⁇ velle composition respectively characterizing the first multi-unit vehicle 1, and the second multi-unit vehicle 2.
  • the new composition data is in particular able to cause generation by at least one security module of the unlocking key allows ⁇ as a disconnection of each of the computers, with the inputs / outputs to which they were previously connected in the configuration of said new multi-unit vehicle 3.
  • said release key is likely to be transmitted to each security module via a safety control system according to the invention, so that each security ⁇ mo dule is able to disconnect a calculators tor its connection with the least one entrance / exit when ⁇ scindage said.
  • the connection of the master computer 51 and its redundant 55 with the inputs / outputs of their I / O modules 91 to 95 is able to be cou ⁇ pe by means of said unlocking key adapted to be provided by the security module, either during said detection of the variation of the composition data during the splitting, or during a prior process of notification of the splitting to said control system of said new multi-unit vehicle.
  • connection loss can be construed ⁇ ted by said module securing and the Entry / Exit module as a failure which may in particular result in a reset of the confirmation message.
  • This reset of the confirmation message will make it possible to connect a new master computer chosen after splitting for each of the first and second multi-unit vehicles to the inputs / outputs of the input / output modules equipping their units.
  • the present invention makes it possible, during a splitting or a coupling, to automatically correlate the new composition of the multi-unit vehicle with all the inputs / outputs to be taken into consideration by the master computer, so that a loss of a connection of the master computer with a part of its inputs / outputs does not result in an activation of an emergency procedure of the control system.
  • At least one calculator among all the calculators distributed on the network of said vehicle is suitable for act as a master computer to control said vehicle and to be directly associated, by connection to said ⁇ I / O set, to the input / output modules of said vehicle.
  • the computer acting as said vehicle driver master computer other calculated ⁇ tors said vehicle can in particular be in the standby state, so that only the computer identified as cal ⁇ culateur master by the security module controls the pi ⁇ preferably, the security module identifies the computer that it equips as the master computer.
  • the present invention allowed to describe a safety control sys- tem able to discover so ⁇ tonome the composition of a multi-unit vehicle such as a train, and verify proper connection the safety of at least one the computer control system with a set of trees in ⁇ / modules outputs I / O distributed on the network of said multi-unit vehicle.
  • composition data from said multi-unit vehicle capable ⁇ describe a set of characteristics of the units that compose said multi-unit vehicle, and a set of possible configurations of said multi-unit vehicle may be used as reference control, particularly cyclic, coherence between all the inputs / outputs able to be connected and locked with said computer and the composition of the multi-unit vehicle.
  • the present invention allows a validation of the integrity of a free multi-unit vehicle from the use of application-level information, such as located it ⁇ for example, and providing greater genericity treatment with direct access to all the trees ⁇ in / out multi-unit vehicle and the ability to centralize software treatments related to the security of the control system on a single computer.
  • the method and securing a sys tem control system ⁇ according to the invention have several advan ⁇ tages compared to exis control methods and systems ⁇ as in that:
  • the securing and prioritization mechanism allows an exclusive assignment of the connection of a set of I / O with at least one computer, in par ticular ⁇ a single computer, and is used to associate security, directly a master computer with safe exits. This allows the realization of a dynamically reconfigurable distributed architecture, and thus a centralization of operating data and greater flexibility of deployment;
  • composition data is compa ⁇ tible with the transmission period of the confirmation message ⁇ tion to refresh the inputs / outputs connected to the master computer;
  • centralizing information to a computer simplifies the complexity of the pilosebaceous system ⁇ automatic floor and reduces the complexity of the security ana ⁇ lysis.
  • the control of the multi-unit vehicle by a computer via the I / O modules is thus secure;

Abstract

The invention relates to a method for securing a control system of a multi-unit vehicle, and to a secured control system of said multi-unit vehicle, said control system being characterised in that it comprises: a device for determining a composition of the multi-unit vehicle, that can autonomously determine the composition of the multi-unit vehicle and generate composition data that can be correlated with the composition of the multi-unit vehicle; at least one calculator for at least one unit (1, 2, 3) of the multi-unit vehicle, each calculator (5) being connectable, by means of at least one connection and via a network, to an inlet/outlet set of inlet/outlet modules (91) for at least one unit, and to said device for determining the composition of the multi-unit vehicle, in order to exchange operating data of the unit (1, 2, 3) and/or the multi-unit vehicle with each inlet/outlet module (91), and in order to acquire data relating to the composition of the multi-unit vehicle from said determination device; and at least one module (6) for dynamically securing said exclusive connection of each calculator to the inlet/outlet set, provided for at least one calculator (5), said securing module (6) being able to determine, from said composition data, the validity of said inlet/outlet set, and to control, cyclically or sufficiently frequently, a coherence between each connection of each calculator (5) to said inlet/outlet set.

Description

Méthode de sécurisation d'un système de pilotage d'un véhicule multi-unité recon igurable et système de pilotage sécurisé . Method for securing a control system of a reconfigurable multi-unit vehicle and secure steering system.
La présente invention concerne une méthode de sécurisation d'un système de pilotage d'un véhicule multi-unité et un sys¬ tème de pilotage sécurisé dudit véhicule multi-unité, selon les préambules des revendications 1 et 7. The present invention relates to a method of securing a steering system of a multi-unit vehicle and a sys tem ¬ safety control of said multi-unit vehicle, according to the preambles of claims 1 and 7.
En particulier, la présente invention se rapporte au domaine des véhicules multi-unités reconfigurables, i.e. aptes à être composés de plusieurs unités et dont une configuration ou composition desdites unités dudit véhicule multi-unité est variable, ou autrement dit susceptible d'être modifiée ou re¬ configurée. De manière préférentielle, la présente invention se rapporte aux véhicules multi-unités dont un fonctionnement d'un système de pilotage, notamment automatique, est corréla- ble à la composition du véhicule multi-unité. In particular, the present invention relates to the field of multi-unit reconfigurable vehicles, ie able to be composed of several units and whose configuration or composition of said units of said multi-unit vehicle is variable, or in other words likely to be modified or re ¬ configured. Preferably, the present invention relates to multi-unit vehicles whose operation of a control system, in particular automatic, is correlated to the composition of the multi-unit vehicle.
Ledit véhicule multi-unité appartient en particulier au do¬ maine ferroviaire. Il s'agit par exemple d'un train pouvant être formé de plusieurs unités, par exemple plusieurs voitu¬ res et/ou locomotives couplées ou attelées successivement les unes aux autres et constituant une première rame dudit train. La composition dudit train, et donc de ladite première rame, peut alors varier, par exemple par scindage ou couplage de ladite première rame, afin de former une seconde rame compo¬ sée d'au moins une partie des unités de ladite première rame, auxquelles peuvent être attelées d'autres unités. Ainsi, la composition d'un véhicule multi-unité peut varier en fonction d'un changement d'une disposition ou d'une distribution desdites unités formant ledit véhicule multi-unité, ainsi que par ajout, et/ou respectivement retrait, d'au moins une unité audit, et/ou respectivement dudit, véhicule multi-unité. Afin de garantir en sécurité de tels véhicules multi-unités composés de plusieurs unités disposées selon un ordre de for¬ mation, il est en particulier nécessaire que des données de composition dudit véhicule multi-unité, par exemple le nombre d'unités le composant, les caractéristiques desdites unités, les relations entre ces unités, leur couplage ou attelage à une ou deux autres unités, soient connues du système de pilo¬ tage destiné à piloter ledit véhicule multi-unité. Ce système de pilotage comprend généralement un calculateur connecté à des modules d'Entrées/Sorties permettant notamment une acqui¬ sition et une transmission de données de fonctionnement rela¬ tives au pilotage du véhicule multi-unité. Le calculateur est ainsi capable piloter, via les modules d'Entrées/Sorties, le¬ dit véhicule multi-unité, notamment selon un mode automati- que, ou encore selon un mode manuel dans lequel le système de pilotage, et donc le calculateur, est apte à être commandé par un conducteur ou un centre de commande. En effet, les données de fonctionnement sont en particulier échangées, via les modules d'Entrées/Sorties, entre ledit calculateur et des dispositifs compris dans au moins une partie des unités com¬ posant ledit véhicule multi-unité afin d'assurer son fonc¬ tionnement. Ledit échange des données de fonctionnement peut par exemple être mis en œuvre au moyen d'une connexion bidi¬ rectionnelle entre le calculateur et lesdits dispositifs via lesdits modules d'Entrées/Sorties. Le calculateur et les mo¬ dules d'Entrées/Sorties sont ainsi destinés à permettre et assurer le pilotage du véhicule multi-unité, ou autrement dit son fonctionnement correcte (déplacement, arrêt, ouvertures de portes, ...), en se basant sur les données de composition dudit véhicule multi-unité et sur les données de fonctionne¬ ment relatives au pilotage échangeables avec lesdits disposi¬ tifs d'au moins une partie desdites unités. Lors d'un change¬ ment de la configuration dudit véhicule multi-unité (scin- dage, couplage avec d'autres unités), lesdites données de compositions doivent être mises à jour afin que le système de pilotage, en particulier son calculateur, soit informé dudit changement de configuration et soit apte à corréler le chan- gement de composition dudit véhicule multi-unité avec un changement des données de fonctionnement relatives au pilo¬ tage. En effet, si le calculateur n'est pas informé d'un changement de la composition du véhicule multi-unité, il ris- que d'interpréter une non-réception des données de fonctionnement des unités qui auront été dételées du véhicule multi- unités (et qui ne peuvent donc plus transmettre de données de fonctionnement relatives au pilotage) comme un risque en sé¬ curité pour ledit véhicule multi-unité, pouvant résulter dès lors en une activation d'une procédure de mise en sécurité du véhicule multi-unité, comme par exemple un freinage d'ur¬ gence . Said multi-unit vehicle belongs especially to do ¬ maine rail. This is for example a train can be formed of several units, e.g. several motorcyc ¬ res and / or locomotives coupled or coupled to each other and successively forming a first train of said train. The composition of said train, and therefore of said first train, can then vary, e.g. by scindage or coupling said first string to form a second train compo ¬ EDC to at least part of the units of said first train, which can be hitched to other units. Thus, the composition of a multi-unit vehicle can vary according to a change of a disposition or a distribution of said units forming said multi-unit vehicle, as well as by addition, and / or respectively withdrawal, of at least one audit unit, and / or respectively said multi-unit vehicle. In order to guarantee security of such multi-unit vehicles consisting of several units arranged in an order of for ¬ mation, it is particularly necessary that composition data from said multi-unit vehicle, eg the number of units the component, the characteristics of said units, the relations between these units, their coupling or coupling to one or two other units, are known pilo ¬ stage system for driving said multi-unit vehicle. This control system generally comprises a computer connected to the I / O modules for a particular acqui ¬ sition and a transmission operation of data ¬ rela tive to the steering of multi-unit vehicle. The computer is thus capable pilot, via inputs / outputs of modules, ¬ the said multi-unit vehicle, in particular according to an automated that mode, or according to a manual mode wherein the control system, and thus the computer, is able to be controlled by a driver or control center. Indeed, the operating data is in particular exchanged, via the input / output modules, between said computer and devices included in at least a part of the units com ¬ posing said multi-unit vehicle to ensure its func ¬ tioning. Said exchange of operating data can for example be implemented by means of a bidi ¬ rectional connection between the computer and said devices via said input / output modules. The calculator and mo ¬ dules / O are thus designed to enable and ensure the control of the multi-unit vehicle, or otherwise work correctly (move, stop, door openings, ...), based on the composition data of said multi-unit vehicle and on operating data ¬ relating to control exchangeable with said disposi ¬ tifs of at least a portion of said units. During a change ¬ tion of the configuration of said multi-unit vehicle (scintillation, coupling with other units), said composition data must be updated so that the control system, in particular its computer, is informed of said configuration change and is able to correlate the change composition of said multi-unit vehicle with a change of operating data relating pilo ¬ tage. In fact, if the computer is not informed of a change in the composition of the multi-unit vehicle, it may misinterpret the operating data of the units which have been uncoupled from the multi-unit vehicle. (and which therefore can no longer transmit operating data relating to the piloting) as a risk in se ¬ curity for said multi-unit vehicle, which may result in an activation of a procedure for securing the multi-unit vehicle , such as a braking ur ¬ gence.
Le système de pilotage du véhicule multi-unité doit notamment être caractérisé par un haut degré de sécurité fonctionnelle afin d'empêcher tout événement pouvant porter atteinte audit véhicule multi-unité ou à des passagers ou marchandises transportés par ledit véhicule multi-unité. La sécurité de tels systèmes de pilotage peut être caractérisée au moyen de normes de sécurité. En particulier, la norme IEC 61508 défi¬ nit le SIL (Security Integrity Level), c'est-à-dire le niveau d' intégrité de la sécurité que doit avoir un système afin d'assurer une protection adéquate contre les risques pouvant survenir lors du fonctionnement dudit système. Plus le SIL a une valeur élevée, plus la réduction du risque est impor¬ tante. Par exemple, un système de sécurité SIL4 apporte une réduction de risque comprise entre 108 à 109 en mode continu d'opération, alors que pour un système SIL1, cette réduction est comprise entre 105 à 106 seulement. The driving system of the multi-unit vehicle must in particular be characterized by a high degree of functional safety in order to prevent any event that may affect said multi-unit vehicle or passengers or goods transported by said multi-unit vehicle. The safety of such control systems can be characterized by means of safety standards. In particular, IEC 61508 SIL challenge ¬ nes (Security Integrity Level), that is to say the level of safety integrity that should have a system to ensure adequate protection against the risks that may arise during operation of said system. The higher the SIL has a high value, the higher the risk reduction is impor ¬ aunt. For example, a SIL4 security system provides a risk reduction of between 10 8 to 10 9 in the continuous mode of operation, whereas for an SIL1 system, this reduction is between 10 5 to 10 6 only.
Afin de pouvoir garantir en sécurité le pilotage du véhicule multi-guidé, il faut pouvoir s'assurer que le calculateur du système de pilotage connaît exactement la composition et la configuration dudit véhicule multi-unité (par exemple, quels sont les unités composant un train et selon quel ordre de formation sont-elles ordonnées, ou autrement dit, dans quel ordre sont-elles couplées ou attelées), afin qu'il puisse échanger avec les unités du véhicule multi-unité toutes les données de fonctionnement nécessaires au pilotage dudit véhi¬ cule multi-unité. In order to guarantee the safe operation of the multi-guided vehicle, it must be ensured that the control system computer knows exactly the composition and configuration of said multi-unit vehicle (for example, which units make up a train and according to what order of formation are they ordered, or in other words, in what order they are coupled or coupled) so that it can exchange with the units of multi-unit vehicle all the operating data necessary for piloting said vehi ¬ multi-unit cule.
De plus, dans le cas d'un changement de la composition d'un véhicule multi-unité, par exemple, lorsqu'un train est scindé en plusieurs parties, le calculateur du système de pilotage doit être rapidement informé dudit changement de composition, par exemple afin de s'autoriser à ne plus prendre en compte des données de fonctionnement d'unités ayant été dételées du train lors de son scindage, et afin de ne pas tomber dans un état de sécurité ayant pour conséquence une mise en alerte d'un centre de surveillance d'un réseau de véhicules multi- unité ou même une activation d'un processus de mise en sécu¬ rité, comme un freinage d'urgence dudit véhicule multi-unité. Moreover, in the case of a change in the composition of a multi-unit vehicle, for example, when a train is divided into several parts, the control system computer must be promptly informed of said composition change by example in order to allow oneself to no longer take into account operating data of units that have been detached from the train during its splitting, and so as not to fall into a state of safety resulting in a warning of a center for monitoring a vehicle network multi-unit or even activation of a secu rity ¬ formatting process, as an emergency braking of said multi-unit vehicle.
Malheureusement, les systèmes de pilotage, qu'ils soient au¬ tomatiques ou manuels et de sécurité (SIL4), connus de l'homme du métier sont essentiellement basés sur des calcula¬ teurs "fermés" pour lesquels le périmètre d'Entrées/Sorties n'est pas reconfigurable, i.e. le calculateur est connecté à un ensemble fixe d'Entrées/Sorties de modules d'En¬ trées/Sorties, ces Entrées/Sorties connectant fixement le calculateur à certains dispositifs fonctionnels des unités gérées par ledit calculateur, et n'étant ainsi pas reconfigu¬ rables lors d'un changement de configuration du véhicule mul¬ ti-unité. Par dispositif fonctionnel, il est fait référence à tout dispositif interagissant avec le système de pilotage afin de permettre le pilotage dudit véhicule multi-unité. Il s'agit par exemple de dispositifs de freinage, d'ouverture de portes, de dispositifs permettant ou surveillant le déplace¬ ment dudit véhicule multi-unité, etc. Dès lors, la gestion d'un véhicule multi-unité met généralement en œuvre plusieurs calculateurs gérant chacun une partie du véhicule multi- unité, chaque calculateur étant connecté à des En- trées/Sorties les connectant de manière fixe à certains dis¬ positifs fonctionnels des ou de l'unité qu'il gère. Bien que la composition du véhicule multi-unité soit ainsi connue par recoupement des informations provenant de chaque calculateur, cette conception du système de pilotage présente le désavan¬ tage de devoir gérer des fonctions réparties sur les diffé¬ rents calculateurs, nécessitant notamment des algorithmes de synchronisation desdits calculateurs, dont la complexité aug¬ mente avec le nombre d'unités constituant le véhicule multi- unité. Unfortunately, steering systems, whether in or ¬ tomatiques manuals and safety (SIL 4), known to the art are essentially based on calculated ¬ tors "closed" for which the perimeter / O is not reconfigurable, ie the computer is connected to a fixed set of I / O modules of in ¬ Trees / outputs, these I / O fixedly connecting the computer devices to certain functional units managed by said computer, and thus not being reconfigu ¬ rable when changing the configuration of the vehicle mul ¬ ti-unit. By functional device, reference is made to any device interacting with the control system so as to enable said multi-unit vehicle to be piloted. This is for example of braking, opening doors, or devices for monitoring the moving ¬ said multi-unit vehicle, etc. Therefore, the management of a multi-unit vehicle generally implements several computers each managing a part of the multi-unit vehicle, each computer being connected to subscribers. trés / Outputs connecting them in a fixed manner to certain functional dis ¬ positive or the unit it manages. Although the composition of the multi-unit vehicle is well known by overlapping information from each computer, the design of the steering system has the désavan ¬ duty floor manage functions spread over the dif ¬ ent calculators, including requiring algorithms synchronization of said computers, whose complexity aug ¬ mente with the number of units constituting the multi-unit vehicle.
Actuellement, la composition ou la constitution d'un véhicule multi-unité est ainsi généralement déduite de recoupements de plusieurs informations applicatives échangées entre les dif- férents calculateurs dudit véhicule. Ces informations appli¬ catives sont des informations provenant d'autres dispositifs du véhicule multi-unité n'ayant pas toutes pour tâche pre¬ mière la détermination de la composition dudit véhicule mul- ti-guidé. Il s'agit par exemple de données de localisation de la tête et de la queue du véhicule multi-unité transmises au calculateur par des dispositifs de localisations embarqués ou au sol, ou des données d'état des attelages des unités, ou des listes de véhicules multi-unités transmises au calcula¬ teur par un pilote automatique au sol non embarqué dans ledit véhicule multi-unité. Le recoupement de ces informations ap¬ plicatives a le désavantage d'être compliqué et lent, et di¬ minue ainsi les performances de pilotage dudit véhicule mul¬ ti-unité. En effet, la complexité de l'échange d'informations applicatives entre les calculateurs introduit une perte de performance du système de pilotage, ainsi qu'une plus grande complexité de réalisation dudit système de pilotage, et par conséquence, une plus grande difficulté à démontrer et main¬ tenir la sécurité dudit système de pilotage. De plus, ces in¬ formations applicatives peuvent être différentes d'un projet à l'autre ce qui nuit à la généricité des algorithmes. Un but de la présente invention est de proposer une méthode de sécurisation d'un système de pilotage d'un véhicule multi- unité reconfigurable et un système de pilotage sécurisé qui soient simples, sûrs, fiables et efficaces, capables d'une actualisation automatique et autonome d'une composition du véhicule multi-unité, tout en ayant une capacité de sécurisa¬ tion SIL4. En effet, la présente invention a pour objectif une détermination et une actualisation automatique de la composition du véhicule multi-unité, indépendamment d'informa- tions applicatives, afin de garantir en sécurité le système de pilotage du véhicule multi-unité. Currently, the composition or constitution of a multi-unit vehicle is thus generally deduced from cross-checks of several application information exchanged between the different computers of said vehicle. This information app ¬ cant is information from other devices of the multi-unit vehicle not having all task for pre ¬ Mière determining the composition of said multi-guided vehicle. This is, for example, the location data of the head and the tail of the multi-unit vehicle transmitted to the computer by on-board or ground locating devices, or the state of the equipment of the units, or multi-unit vehicles transmitted to the calculated ¬ tor by an autopilot ground not embedded in said multi-unit vehicle. The overlapping of this information ap ¬ plicative has the disadvantage of being complicated and slow, and di ¬ minue and driving performance of said vehicle mul ¬ ti-unit. Indeed, the complexity of the exchange of application information between the computers introduces a loss of performance of the control system, as well as a greater complexity of implementation of said control system, and consequently, a greater difficulty to demonstrate. ¬ hand and hold the safety of such control system. In addition, these application in¬¬ formations may be different from one project to another which affects the genericity of the algorithms. An object of the present invention is to propose a method of securing a system for driving a reconfigurable multi-unit vehicle and a secure control system that are simple, safe, reliable and efficient, capable of automatic updating and autonomous of a composition of the multi-unit vehicle, while having a security SIL4 ¬ tion. Indeed, the present invention aims to automatically determine and update the composition of the multi-unit vehicle, independently of application information, in order to safely guarantee the multi-unit vehicle control system.
Dans ce but, une méthode de sécurisation d'un système de pi¬ lotage, un système de pilotage sécurisé et un dispositif d'aide à la détermination de la composition d'un véhicule multi-unité sont proposés par le contenu des revendications 1, 7 et 12. Un ensemble de sous-revendications présente éga¬ lement des avantages de l'invention. La présente invention propose une méthode de sécurisation d'un système de pilotage destiné à équiper et piloter un vé¬ hicule multi-unité reconfigurable, comprenant en particulier au moins deux unités attelables l'une à la suite de l'autre, ladite méthode étant caractérisée en ce qu'elle comprend: - une détermination autonome, et de préférence cyclique et automatique, d'une composition du véhicule multi-unité par un dispositif de détermination de la composition dudit véhicule multi-unité corrélée à une génération, de préfé¬ rence par ledit dispositif de détermination, d'une donnée de composition dudit véhicule multi-unité; For this purpose, a method of securing a system of pi ¬ lotage, a safety controller and a device for assisting in determining the composition of a multi-unit vehicle are proposed by the content of Claims 1, 7 and 12. A set of subclaims Ega present ¬ LEMENT advantages of the invention. The present invention provides a steering system of a security method for fitting and control a vee ¬ vehicle reconfigurable multi-unit comprising in particular at least two attelables units one after the other, said method being characterized in that it comprises: - an autonomous determination, and preferably cyclic and automatic, of a composition of the multi-unit vehicle by a device for determining the composition of said multi-unit vehicle correlated to a generation, preferably ¬ by said determination device, a composition data of said multi-unit vehicle;
- une transmission, de préférence cyclique et automatique, de ladite donnée de composition à un ensemble d'éléments du système de pilotage, au moins un élément desdits élé¬ ments dudit ensemble d'éléments étant un calculateur dudit système de pilotage; - une détermination, de préférence cyclique et automatique, par ledit calculateur et au moyen de ladite donnée de com¬ position, d'un ensemble d'Entrées/Sorties d'au moins un module d'Entrée/Sortie destiné à équiper le véhicule mul- ti-unité, ledit module d'Entrées/Sorties équipant par exemple une unité dudit véhicule multi-unité et permettant une communication et un échange de données entre le calcu¬ lateur et des dispositifs fonctionnels de ladite unité, notamment afin de les contrôler et d'assurer leur fonc- tionnement correct; - a transmission cyclically and preferably automatic, of said given composition to a set of steering system components, at least one element of said ele ments ¬ said set of elements being a computer of said control system; a determination, preferably cyclic and automatic, by said computer and by means of said com ¬ position data, of a set of inputs / outputs of at least one input / output module intended to equip the vehicle - ti-unit, said module I / O equipping e.g. a unit of said multi-unit vehicle and allowing communication and data exchange between the calcu ¬ freezer and functional devices of said unit, in particular to control and to ensure their correct operation;
- une connexion de chaque élément dudit ensemble d'éléments, et donc dudit calculateur, audit ensemble d'En¬ trées/Sorties, en particulier chaque élément dudit ensem¬ ble d'éléments est connectable à chaque Entrée/Sortie du- dit ensemble d'Entrées/Sorties. - a connection of each element of said set of elements, and therefore said calculator, said set of trees ¬ In / Out, especially each element of said ensem ¬ ble elements is connectable to each input / output of said set 'Entries exits.
La présente invention propose également un système de pilo¬ tage sécurisé, et préférentiellement automatique, d'un véhi- cule multi-unité reconfigurable, comprenant par exemple au moins deux unités attelables l'une à la suite de l'autre, ca¬ ractérisé en ce que ledit système comprend: The present invention also provides a secure, and preferably automatic, pilo ¬ system for a reconfigurable multi-unit vehicle, comprising for example at least two towable units one after the other, ca ¬ characterized in that said system comprises:
- un dispositif de détermination d'une composition du véhicule multi-unité, capable de déterminer de manière auto- nome ladite composition du véhicule multi-unité et de gé¬ nérer une donnée de composition corrélable à ladite compo¬ sition dudit véhicule multi-unité, ladite détermination étant notamment autonome en ce qu'elle est indépendante de toute information applicative; - a device for determining a composition of the multi-unit vehicle, capable of determining autonomous manner the composition of the multi-unit vehicle and ¬ gen erate a given composition correlatable to said compo sition ¬ said multi-unit vehicle said determination being in particular autonomous in that it is independent of any application information;
- au moins un calculateur comprenant au moins un module de sécurisation, ledit calculateur étant destiné à équiper au moins une unité du véhicule multi-unité, chaque calcula¬ teur étant connectable au moyen d'au moins une connexion et via un réseau, d'une part à un ensemble d'En- trées/Sorties de modules d'Entrées/Sorties destinés à équiper une ou plusieurs unités, et d'autre part audit dispositif de détermination de la composition du véhicule multi-unité, afin d'échanger via chaque module d'En- trées/Sorties des données de fonctionnement de l'unité et/ou du véhicule multi-unité, et afin d'acquérir dudit dispositif de détermination, une donnée de composition du¬ dit véhicule multi-unité, ledit réseau étant notamment destiné à permettre une communication entre chaque dispo- sitif de génération d'identité et chaque calculateur, entre chaque calculateur et chaque module d'Entrées/Sorties, et entre chaque calculateur entre eux; - at least one computer comprising at least a security module, said computer being designed to equip at least one unit of the multi-unit vehicle, each calculated ¬ tor being connectable by means of at least one connection and via a network, of a part to a set of En- I / O module outputs / outputs intended to equip one or more units, and secondly to said device for determining the composition of the multi-unit vehicle, in order to exchange via each input / output module data unit operation and / or multi-unit vehicle, and to acquire said determining device, a composition of the ¬ given said multi-unit vehicle, said network being in particular intended to permit communication between each identity generating device and each computer, between each computer and each input / output module, and between each computer between them;
- ledit module de sécurisation dynamique de ladite connexion de chaque calculateur avec ledit ensemble d'En- trées/Sorties, ledit module de sécurisation étant destiné à équiper au moins un calculateur, et étant capable de dé¬ terminer, à partir de ladite donnée de composition, ledit ensemble d'Entrées/Sorties susceptibles d'être connectées à chaque calculateur, de connecter chaque calculateur au- dit ensemble d'Entrées sorties, notamment à chaque En¬ trée/Sortie dudit ensemble d'Entrées/Sorties, et de contrôler, cycliquement ou suffisamment fréquemment (par exemple, au moins un contrôle par intervalle de temps in¬ férieur ou égal à 100 millisecondes), une cohérence entre chaque connexion de chaque calculateur audit ensemble d'Entrées/Sorties, notamment une cohérence entre chaque connexion de chaque calculateur avec chacune desdites En¬ trées/Sorties dudit ensemble d'Entrées/Sorties et ladite donnée de composition. En particulier, chaque calculateur est susceptible de comprendre un module de sécurisation selon l'invention. - said dynamic security module of said connecting each computer with said set of In- puts / outputs, said security module being intended to equip at least one computer, and being capable of de ¬ conclusion, from said data composition, said set of inputs / outputs may be connected to each computer, to connect each computer au said set of inputs and outputs, including in each tree ¬ / output of said set of inputs / outputs, and control cyclically or sufficiently frequently (e.g., at least one time interval by control in ¬ férieur or equal to 100 milliseconds), a consistency between each connection calculator each said set of inputs / outputs, in particular a consistency between each connection each computer with each of said trees in ¬ / outputs of said set of inputs / outputs and said given composition. In particular, each computer may include a security module according to the invention.
En d'autres termes, la méthode selon l'invention est une mé¬ thode de sécurisation, préférentiellement automatique et en particulier de sécurisation SIL4, d'un système de pilotage d'un véhicule multi-unité capable de déterminer à tout ins¬ tant et de manière fiable, la composition du véhicule multi- unité, et de garantir, à tout instant, une cohérence entre la composition du véhicule multi-unité et les données de fonc¬ tionnement du système de pilotage du véhicule multi-unité, par l'association d'au moins un calculateur avec ledit ensemble d'Entrées/Sorties corrélable à ladite composition du vé¬ hicule multi-unité. Avantageusement, la méthode selon 1 ' in- vention est en particulier caractérisée par une vérification cyclique, notamment de fréquence aléatoire ou fixe, mais dans tous les cas une vérification suffisamment fréquente (par exemple, au moins une vérification par intervalle de temps inférieur ou égal à 100 millisecondes), notamment au moyen du module de sécurisation, d'une cohérence entre la connexion de chaque élément dudit ensemble d'éléments avec ledit ensemble d'Entrées/Sorties et ladite donnée de composition. In other words, the method according to the invention is a mé ¬ securing method, preferably automatically and particularly SIL4 securing, of a steering system of a multi-unit vehicle able to determine at any ¬ ins as and reliably, the composition of the multi-unit vehicle, and to ensure, at all times, a coherence between the composition of the multi-unit vehicle and data func ¬ steering system tioning of the multi-unit vehicle, the combination of at least one computer with said set of inputs / outputs correlated to said composition vee ¬ vehicle multi-unit. Advantageously, the method according to the invention is characterized in particular by a cyclic check, in particular of random or fixed frequency, but in all cases a sufficiently frequent check (for example, at least one verification per time interval less than or equal to 100 milliseconds), particularly by means of the security module, a coherence between the connection of each element of said set of elements with said set of inputs / outputs and said composition data.
En particulier, la présente invention est caractérisée en ce que ledit ensemble d'éléments comprend ou est un groupe de calculateurs susceptibles d'être distribués dans chaque unité dudit véhicule multi-unité. En d'autres termes, le système de pilotage selon l'invention comprend préférentiellement ledit groupe de calculateurs pouvant être composé de plusieurs cal¬ culateurs identiques, chaque calculateur pouvant notamment être distribué dans une unité du véhicule multi-unité, de sorte que chaque unité soit susceptible d'être équipée par au moins un calculateur. Avantageusement, le module de sécurisa- tion selon l'invention est en particulier capable d'attribuer de façon exclusive la connexion audit ensemble d'En¬ trées/Sorties, notamment à chaque Entrée/Sortie dudit ensem¬ ble d'Entrées/Sorties, à un seul calculateur dudit groupe de calculateurs, les autres calculateurs dudit groupe de calcu- lateurs étant exclus de ladite connexion ou autrement dit, interdits d'accès audit ensemble d'Entrées/Sorties. A cette fin, la méthode selon l'invention est susceptible de comprendre un mécanisme de sécurisation et de priorisation de la connexion d'au moins un calculateur dudit groupe de calcula- teurs avec ledit ensemble d'Entrées/Sorties, capable d'attri¬ buer de façon exclusive audit calculateur ladite connexion audit ensemble d'Entrées/Sorties. Le calculateur élu, i.e. ayant l'exclusivité d'accès à l'ensemble d'Entrées/Sorties est appelé le calculateur maître. De manière avantageuse, au moins un autre calculateur dudit groupe de calculateur est en particulier associable au calculateur maître en tant que cal¬ culateur redondant dudit calculateur maître. Le système de pilotage selon l'invention est notamment capable non seule¬ ment de choisir un calculateur maître parmi le groupe de calculateur, mais aussi de nommer un calculateur redondant parmi ledit groupe de calculateur. Le calculateur redondant est apte à effectuer les mêmes opérations que le calculateur maître, à acquérir les mêmes données de composition et de fonctionnement que le calculateur maître à des fins de véri- fication et de sécurisation du système de pilotage. En cas de défaillance du calculateur maître, le calculateur redondant est apte à remplacer ledit calculateur maître et à nommer un nouveau calculateur redondant. De manière préférentielle, ledit mécanisme de sécurisation et de priorisation comprend une génération d'un jeton d'association codé apte à verrouiller ladite connexion d'au moins un calculateur dudit groupe de calculateurs avec ledit ensemble d'Entrées/Sorties, et une génération d'une clé de déverrouil- lage apte à déverrouiller ladite connexion d'au moins un cal¬ culateur dudit groupe de calculateurs avec ledit ensemble d'Entrées/Sorties. A cette fin, au moins un calculateur du système de pilotage peut en particulier être équipé d'un mo¬ dule de sécurisation comprenant un module de verrouillage ca- pable de verrouiller chaque connexion du calculateur avec chacune des Entrées/Sorties dudit ensemble d'Entrées/Sorties. Ce module de verrouillage comprend en particulier un généra¬ teur de jeton d'association codé apte à générer, notamment cycliquement , d'une part ledit jeton d'association codé afin de verrouiller chaque connexion dudit calculateur avec chacune des Entrées/Sorties dudit ensemble d'Entrées/Sorties, et d'autre part ladite clé de déverrouillage apte à déverrouil¬ ler au moins une connexion dudit calculateur avec au moins une des Entrées/Sorties dudit ensemble d'Entrées/Sorties. In particular, the present invention is characterized in that said set of elements comprises or is a group of computers that can be distributed in each unit of said multi-unit vehicle. In other words, the steering system according to the invention preferably comprises said group of computers that can be composed of several identical cal ¬ culateurs, each computer may in particular be distributed in a unit of the multi-unit vehicle, so that each unit is likely to be equipped by at least one computer. Advantageously, the sécurisa- tion module according to the invention is in particular able to assign exclusively to connection to said set of trees In ¬ / outputs, including at each entrance / exit of said ensem ¬ ble / O, to a single computer of said group of computers, the other computers of said group of computers being excluded from said connection or in other words, prohibited access to said set of Inputs / Outputs. To this end, the method according to the invention may include a securing mechanism and prioritization of connecting at least one computer of said calculators tors group with said set of I / O capable of attri ¬ exclusively to said computer said connection to said set of Inputs / Outputs. The elected computer, ie having the exclusive access to the set of inputs / outputs is called the master computer. Advantageously, at least one other computer of said group calculator is in particular associable to the master computer as cal ¬ culateur said redundant master computer. The control system according to the invention is particularly capable not only ¬ to select a master computer from the calculator group but also to appoint a redundant computer of said computer group. The redundant computer is able to perform the same operations as the master computer, to acquire the same composition and operating data as the master computer for the purposes of verifying and securing the control system. In the event of failure of the master computer, the redundant computer is able to replace said master computer and to name a new redundant computer. Preferably, said security and prioritization mechanism comprises a generation of an encoded association token able to lock said connection of at least one computer of said group of computers with said set of Inputs / Outputs, and a generation of a key déverrouil- spinning adapted to unlock said connection of at least one of said computers cal ¬ culateur group with said set of inputs / outputs. To this end, at least one control system of the computer may in particular be equipped with a mo dule ¬ securing ca- pable comprising a locking module for locking each computer connection with each of the Inputs / Outputs of said set of Inputs / Outputs. This locking module comprises in particular a combination ¬ genera tor encoded token capable of generating, in particular cyclically, first said encoded combination token to lock each connection of said computer with each of the inputs / outputs of said set 'Inputs / Outputs, and secondly said unlocking key able to unlock ¬ ler at least one connection of said computer with at least one of the inputs / outputs of said set of inputs / outputs.
De plus, la méthode selon l'invention est en particulier caractérisée en ce que ladite détermination autonome comprend un ajout successif et ordonné à une liste, selon un ordre de composition dudit véhicule multi-unité, d'au moins une donnée identitaire de chaque unité dudit véhicule multi-unité de fa¬ çon à ce qu'un ordre de succession des données identitaires comprises dans ladite liste soit corrélable à l'ordre de com¬ position des unités dudit véhicule multi-unité, chaque donnée identitaire étant spécifique à une unique unité du véhicule multi-unité, et ladite liste étant apte à être encapsulée dans ladite donnée de composition. En particulier, la donnée identitaire comprend au moins une donnée temporelle, un iden¬ tifiant de l'unité, une constante de codage, et au moins un identifiant d'un équipement de ladite unité. In addition, the method according to the invention is characterized in that said autonomous determination comprises a successive and ordered addition to a list, according to a composition order of said multi-unit vehicle, of at least one piece of identity data of each unit. said multi-unit vehicle fa ¬ con that a sequence of the identity data comprised in said list is correlated to the order of com ¬ units digit of said multi-unit vehicle, each identity data being specific to a single unit of the multi-unit vehicle, and said list being able to be encapsulated in said composition datum. In particular, the identity data includes at least a time data, a iden tifying ¬ unit, constant coding and at least one identifier of an appliance of said unit.
De manière préférentielle, le système de pilotage selon l'in¬ vention est notamment caractérisé en ce que son dispositif de détermination d'une composition du véhicule multi-unité comprend au moins un dispositif de génération d'identité, chaque dispositif de génération d'identité du dispositif de détermi¬ nation étant destiné à équiper une unité du véhicule multi- unité, de sorte que chaque unité puisse être équipée d'un seul dispositif de génération d'identité, chaque dispositif de génération d'identité étant capable de générer la donnée identitaire de l'unité qu'il est destiné à équiper. Egale- ment, la méthode selon l'invention est ainsi en particulier caractérisée par un équipement de chaque unité dudit véhicule multi-unité par ledit dispositif de génération d'identité identique capable de générer ladite donnée d'identité desti- née à la détermination de la composition dudit véhicule mul¬ ti-unité, de façon à ce que chaque unité du véhicule multi- unité est susceptible de comprendre un dispositif de généra¬ tion d'identité identique, chaque dispositif de génération d'identité étant connectable ou couplable à au moins un autre dispositif de génération d'identité, de sorte à former une chaîne de dispositifs de génération d'identité équipant cha¬ cun une unité dudit véhicule multi-unité et couplés l'un à la suite de l'autre. En particulier, ledit dispositif de génération d'identité, qui est d'une part destiné à permettre la détermination d'une composition du véhicule multi-unité comprenant au moins une unité, et d'autre part susceptible d'équiper ledit système de pilotage dudit véhicule multi-unité, est caractérisé en ce qu'il comprend: Preferably, the steering system according to the in vention ¬ is especially characterized in that its device for determining a composition of the multi-unit vehicle comprises at least an ID generation device, each generating device identity détermi ¬ nation device being designed to equip a unit of the vehicle multi-unit, so that each unit can be equipped with a single identity Generator device, each identity generation device being capable of generating the identity of the unit it is intended to equip. Equal- Accordingly, the method according to the invention is thus characterized in particular by equipping each unit of said multi-unit vehicle with said identical identity generating device capable of generating said identity data for determining the composition. said vehicle ¬ mul ti-unit, so that each unit of the multi-unit vehicle may comprise a device genera ¬ identical identity, each identity Generator device being connectable or couplable to at least one other identification generating device, so as to form a chain of identity generation devices equipping cha ¬ cun a unit of said multi-unit vehicle and coupled one after the other. In particular, said identity generation device, which is on the one hand intended to allow the determination of a composition of the multi-unit vehicle comprising at least one unit, and secondly capable of equipping said control system. of said multi-unit vehicle, is characterized in that it comprises:
- un générateur de données identitaires capable de gé¬ nérer ladite donnée identitaire de l'unité que le dispositif de génération d'identité est destiné à équiper, ladite donnée identitaire étant destinée à permettre une identification de ladite unité; - an identity data generator able to gen erate ¬ said identity data of the unit that the Identity Generator device is intended to equip, the said identity data being intended to allow an identification of said unit;
- un détecteur de connexion apte à détecter une présence ou une absence de couplage dudit dispositif de génération d'identité avec au moins un autre dispo¬ sitif de génération d'identité; - a connection detector adapted to detect a presence or absence of said coupling Identity Generator device with at least one other available ¬ ID generation operative part;
- un générateur de liste capable de créer une liste d'éléments destinée à comprendre des éléments aptes à être ordonnés et ajoutés successivement;  a list generator capable of creating a list of elements intended to include elements able to be ordered and added successively;
- un composant de sérialisation capable d'ajouter un autre élément à ladite liste, soit à la suite d'un dernier élément d'une liste d'éléments ordonnables successivement destinée à être réceptionnée par le¬ dit dispositif de génération d'identité, soit comme premier élément de la liste d'éléments susceptible d'être créée par le générateur de liste, ledit autre élément comprenant ladite donnée identitaire; a serialization component capable of adding another element to said list, either following a last element of a list of controllable elements successively intended to be received by the ¬ said identity generating device, either as the first element of the list of elements that can be created by the list generator, said other element comprising said identity data;
- un transmetteur de liste capable de transmettre la¬ dite liste d'éléments comprenant ledit autre élément soit à un autre dispositif de génération d'identité, soit à au moins un calculateur, comprenant notamment ledit module de sécurisation du système de pilotage du véhicule multi-unité, après encapsulation de la¬ dite liste dans une donnée de composition dudit vé¬ hicule multi-unité. - a list of transmitter capable of transmitting ¬ said list of elements comprising the other element or to another identification generating device, or at least one computer, comprising said particular security module of the control system of the multi vehicle -unity, after encapsulation of the ¬ said list in a given composition of said vee ¬ vehicle multi-unit.
Préférentiellement , ladite détermination de la composition du véhicule multi-unité est réalisée au moyen dudit dispositif de génération d'identité selon les étapes suivantes: Preferably, said determination of the composition of the multi-unit vehicle is carried out by means of said identity generating device according to the following steps:
- une génération par chaque dispositif de génération d'identité de chaque unité du véhicule multi-unité de ladite donnée identitaire destinée à permettre une identification de l'unité que ledit dispositif de génération équipe, ladite génération étant sus¬ ceptible d'être réalisée par ledit générateur de donnée identitaire; - generation by each Identity Generator device of each unit of the multi-unit vehicle of said identity data to enable an identification of the unit as said team generating device, said generating being above ¬ ceptible to be carried out by said identity data generator;
- une détection, par ledit détecteur de connexion, pour chaque dispositif de génération d'identité, d'une présence ou d'une absence de couplage dudit dispositif de génération d'identité avec au moins un autre dispositif de génération d'identité; detecting, by said connection detector, for each identity generating device, a presence or absence of coupling of said identity generating device with at least one other identity generating device;
- en cas de détection pour au moins un dispositif de génération d'identité dudit véhicule multi-unité de ladite présence de couplage avec un seul autre dis¬ positif de génération d'identité susceptible de lui être accouplé, ladite méthode selon l'invention com¬ prend les sous-étapes suivantes: in case of detection for at least one device for generating identity of said multi-unit vehicle of said coupling presence with a single other identity generating dis ¬ positive capable of it to be coupled, said method according to the invention com ¬ takes the following substeps:
a. une création, par ledit générateur de liste dudit dispositif de génération d'identité caractérisé par ladite présence de couplage avec un seul au¬ tre dispositif de génération d'identité, d'une liste d'éléments destinée à comprendre des élé¬ ments ordonnables successivement, ladite liste comprenant un premier élément, ledit premier élé¬ ment comprenant ladite donnée identitaire de l'unité destinée à être équipée par ledit dispo¬ sitif de génération d'identité caractérisé par ladite présence de couplage avec un seul autre dispositif de génération d'identité, ledit pre¬ mier élément étant le premier élément de la liste créée par le générateur de liste, ladite création étant suivie d'une transmission de ladite liste par le dispositif de génération d'identité carac¬ térisé par ladite présence de couplage avec un seul autre dispositif de génération d'identité audit autre dispositif de génération d'identité; b. pour chaque dispositif de génération d'identité pour lequel ladite détection est susceptible de détecter ladite présence de couplage avec deux autres dispositifs de génération d'identité, une réception de ladite liste transmissible par l'un des deux autres dispositifs de génération d'iden¬ tité, un ajout à ladite liste d'un autre élément à la suite du dernier élément de ladite liste et une transmission de ladite liste à l'autre des deux autres dispositifs de génération d'identité, ledit autre élément comprenant la donnée identi¬ taire de l'unité destinée à être équipée par le¬ dit dispositif de génération d'identité pour le¬ quel ladite détection est susceptible de détecter ladite présence de couplage avec lesdits deux au¬ tres dispositifs de génération d'identité; c. et pour chaque réception de ladite liste par un dispositif de génération d'identité pour lequel ladite détection est susceptible de détecter la¬ dite présence de couplage avec un unique autre dispositif de génération d'identité, ladite ré¬ ception est suivie dudit ajout à ladite liste d'un élément final à la suite du dernier élément de ladite liste, puis d'une encapsulation de la¬ dite liste dans ladite donnée de composition; en cas de détection, pour un dispositif de généra¬ tion d'identité, de ladite absence de couplage avec un autre dispositif de génération d'identité, ladite méthode selon l'invention comprend une création, par le générateur de liste dudit dispositif de généra¬ tion d'identité caractérisé par ladite absence de couplage avec un autre dispositif de génération d'identité, d'une liste d'éléments destinée à com¬ prendre des éléments ordonnables successivement, la¬ dite liste comprenant un premier élément, ledit pre¬ mier élément comprenant ladite donnée identitaire de l'unité destinée à être équipée par ledit dispositif de génération d'identité caractérisé par ladite ab¬ sence de couplage avec un autre dispositif de géné¬ ration d'identité, ledit premier élément étant le premier élément de la liste créée par le générateur de liste, ladite création étant suivie d'une encap¬ sulation de ladite liste dans ladite donnée de com¬ position . at. creation, by said list generator of the Identity Generator device characterized by said presence of coupling with one ¬ be Identity Generator device of a list of elements intended to include ele ments ¬ orderable successively , said list including a first member, said first ele ¬ comprising said identity data of the unit to be fitted by said dispo ¬ ID generation operative part characterized by said presence of coupling with one another generating device identity, said pre ¬ Mier element being the first element of the list created by the list generator, said generating being followed by a transmission of said list by the identity generator device charac terized by said ¬ presence of coupling with an only another identity generating device to said other identity generation device; b. for each identity generation device for which said detection is capable of detecting said presence of coupling with two other identity generation devices, reception of said transmittable list by one of the two other iden generating devices ¬ tite, an addition to said list of another element following the last element of said list and a transmission of said list to the other of the two other identity generation devices, said other element comprising the data identi ¬ silent of the unit to be equipped by the ¬ said identity Generator device for ¬ which said detection is capable of detecting said presence of coupling with said two to ¬ very identity generating devices; vs. and for each receiving said list by an Identity Generator device for which said detection is capable of detecting the presence of said ¬ coupling with a single other identity generation device, said re ¬ reception is followed of said addition to said list of a final element after the last element of said list, and an encapsulation of the ¬ said list in said given composition; upon detection, for genera device ¬ identity, said absence of coupling with another Identity Generator device, said method according to the invention comprises a design, by the list generator genera said device Identity ¬ characterized by said absence of coupling with another identity generating device, a list of elements for com ¬ to take successively ordered elements, ¬ said list comprising a first element, said pre ¬ first element comprising said identity data of the unit intended to be equipped by said identity generating device characterized by said ab ¬ sence of coupling with another device for gené ¬ ration of identity, said first element being the first element of the list created by the list generator, said creation being followed by a encap ¬ sulation of said list in said data of co m ¬ position.
Ainsi, la détermination de la composition du véhicule multi- unité est réalisable au moyen d'un dispositif interne au sys- tème de pilotage, i.e. au moyen du ou des dispositifs de gé¬ nération d'identité du dispositif de détermination de la com¬ position du véhicule multi-unité, indépendamment d'autres dispositifs externe au système de pilotage qui seraient des- tinés à acquérir lesdites informations applicatives. Chaque dispositif de génération d'identité équipant chacune des uni¬ tés du véhicule multi-unité est ainsi connectable à un ou deux dispositifs de génération d'identité identiques de façon à former une chaîne de dispositifs de génération d'identité capable de se transmettre successivement ladite liste. En particulier, chaque dispositif de génération d'identité com¬ prend au moins deux connecteurs, respectivement un premier et un second connecteur, chacun destiné au couplage dudit dispo¬ sitif de génération d'identité avec un autre dispositif de génération d'identité, i.e. un de ses voisins dans ladite chaîne de dispositifs de génération d'identité. Thus, the determination of the composition of the multi-unit vehicle can be achieved by means of a device internal to the system. Steering tem, ie by means of or devices ¬ gen eration identity determination device of com ¬ position of the multi-unit vehicle, independently of other external devices to the control system that would acquire des- Tines said application information. Each identity generation device equipping each uni ¬ t of the multi-unit vehicle is thus connectable to one or two identical identity generation devices so as to form a chain of identity generation devices capable of being transmitted successively. said list. In particular, each identity generation device com ¬ takes at least two connectors, respectively a first and a second connector, each intended for coupling said identity generating device ¬ with the other identity generation device, ie one of its neighbors in said chain of identity generation devices.
Ladite liste peut être créée par le générateur de liste d'un des deux, voir des deux, dispositifs de génération d'identité situés en extrémité de ladite chaîne dès que le véhicule mul¬ ti-unité comprend plus de deux unités. Le dispositif de dé¬ termination de ladite composition comprend ainsi autant de dispositif de génération d'identité que le véhicule multi- unité comporte d'unités. Chacun de ces dispositifs de généra- tion d'identité est capable de générer la donnée identitaire de l'unité qu'il équipe et de transmettre à l'un ou respecti¬ vement l'autre de ses voisins, ladite liste après que cette dernière lui ait été transmise par l'autre, respectivement l'un de ses voisins. Seuls les dispositifs de génération d'identité situés en bout de chaîne et ayant un unique voi¬ sin, i.e. les dispositifs de génération d'identité pour les¬ quels est détectée la présence de couplage avec un seul autre dispositif de génération d'identité, sont autorisés à générer la liste et/ou à encapsuler une liste reçue de leur unique voisin dans ladite donnée identitaire, afin que ladite liste soit transmise, en fin de chaîne, à au moins un module de sé¬ curisation d'au moins un calculateur du système de pilotage au moyen de ladite donnée de composition. Said list can be created by the list generator of one of the two, see two, ID generation devices located at the end of said chain when the vehicle ¬ mul ti-unit comprises more than two units. The die device ¬ termination of said composition thus comprises as many Identity Generator device of the multi-unit vehicle comprises units. Each generation identity tion devices is capable of generating the identity data of the unit it is fitted and to transmit to the one or respecti vely ¬ any of its neighbors, said list after the latter transmitted to him by the other, respectively one of his neighbors. Only the identity generation devices located at the chain end and having a single voi ¬ sin, ie identity generating devices for ¬ which is detected the presence of coupling with one another Identity Generator device, are allowed to generate the list and / or to encapsulate a list received from their unique neighbor in said identity data, so that said list is transmitted, the end of the chain, at least one module sé ¬ curisation of at least one computer of the control system by means of said given composition.
Avantageusement, ledit générateur de liste est en particulier capable de créer cycliquement ladite liste. Préférentielle- ment, ledit générateur de liste est capable de créer ladite liste lorsque ledit détecteur de connexion détecte ladite présence de couplage dudit dispositif de génération d'identi- té avec un seul autre dispositif de génération d'identité ou avec aucun autre dispositif de génération d'identité. Ainsi, la création de ladite liste par le générateur de liste d'au moins un des dispositifs de génération d'identité situés en bout de chaîne, permet un contrôle et une continuelle actua- lisation de la composition du véhicule multi-unité lorsque ce dernier est composé d'au moins deux unités, étant donné que ladite liste peut être continuellement transmise au calcula¬ teur via ladite donnée de composition dès que ladite liste a traversé toute la chaîne de dispositifs de génération d'iden- tité. Egalement, la création de ladite liste par le généra¬ teur de liste d'un dispositif de génération d'identité couplé avec aucun autre dispositif de génération d'identité permet ledit contrôle et la continuelle actualisation de la composi¬ tion du véhicule multi-unité lorsque ce dernier est composé d'une seule unité. De plus, ledit générateur de données iden¬ titaires est en particulier capable de générer une donnée de polarisation capable d'autoriser la transmission de ladite liste d'éléments au moyen d'un seul des deux connecteurs du¬ dit dispositif de génération d'identité, de sorte que ladite liste parcourt ladite chaîne de dispositifs de génération d'identité selon un sens priorisé définissable par ladite po¬ larisation . Selon la présente invention, chaque unité comprenant ledit système de pilotage est susceptible d'être autonome, i.e. elle est apte à se déplacer, à gérer son déplacement et son fonctionnement indépendamment de tout autre système de pilo- tage externe à ladite unité. De plus, le système de pilotage associable à une unité autonome est apte à commander et gérer le déplacement d'autres unités qui peuvent lui être attelées ou couplées, que ces autres unités comprennent au moins une autre unité autonome et/ou au moins une autre unité non auto- nome. Une unité non autonome, par opposition à ladite unité autonome, est une unité qui comprend seulement une partie du système de pilotage, en particulier au moins un dispositif de génération d'identité, chacun de ces dispositifs étant connectables au réseau de ladite unité, lui même connectable au réseau d'autres unités qui sont susceptibles de lui être couplées ou attelées afin de former le réseau du véhicule multi-unité. Ainsi, dans la suite du document, une unité au¬ tonome sera apte à embarquer ledit système de pilotage selon l'invention, et une unité non autonome fera référence à une unité n'ayant pas l'intégralité dudit système de pilotage em¬ barqué . Advantageously, said list generator is in particular able to cyclically create said list. Preferably, said list generator is capable of creating said list when said connection detector detects said coupling presence of said identity generating device with only one other identity generating device or with no other generation device. identity. Thus, the creation of said list by the list generator of at least one of the identity generation devices located at the end of the chain, allows a control and a continual update of the composition of the multi-unit vehicle when the latter is composed of at least two units, since the list may be continuously transmitted to the calculated ¬ tor via said given composition when said list has passed through the whole chain of iden- tity generating devices. Also, creating said list by the genera tor ¬ list of identity generation device coupled with any other Identity Generator device allows said control and continual updating of the composi ¬ multi-unit vehicle when the latter is composed of a single unit. In addition, said data generator iden ¬ titaires is in particular capable of generating a bias data capable of allowing the transmission of said list of members by means of one of the two connectors ¬ said Identity Generator device , such that said list traverses said chain of identity generation devices according to a priority sense definable by said po ¬ larization. According to the present invention, each unit comprising said steering system is capable of being autonomous, ie it is able to move, to manage its movement and its operation independently of any other steering system external to said unit. In addition, the control system that can be associated with an autonomous unit is able to control and manage the movement of other units that can be coupled or coupled to it, that these other units comprise at least one other autonomous unit and / or at least one other unit. non-autonomous unit. A non-autonomous unit, as opposed to said autonomous unit, is a unit which comprises only a part of the control system, in particular at least one identity generating device, each of these devices being connectable to the network of said unit, it being even connectable to the network of other units that are likely to be coupled or hitched to form the network of the multi-unit vehicle. Thus, in the rest of the document, an ¬ ton unit will be able to embark said control system according to the invention, and a non-autonomous unit will refer to a unit that does not have the entirety of said em ¬ barking control system. .
Un véhicule multi-unité est alors susceptible d'être formé d'au moins une unité autonome pouvant être couplée, ou non, à une ou plusieurs unités autonomes ou non-autonomes. Dans tous les cas, un calculateur d'une des unités autonomes sera en particulier charger de la gestion du pilotage et du fonctionnement du véhicule multi-unité. Préférentiellement le calcu¬ lateur maître d'une des unités autonomes est destiné à pilo- ter le véhicule multi-unité. Une désignation automatique du calculateur maître destiné à piloter ledit véhicule multi- unité est réalisable en fonction par exemple de l'ordre de formation du véhicule multi-unité déductible de ladite donnée de composition susceptible d'être acquise par chaque calcula- teur de chaque unité. Le module de sécurisation du système de pilotage est d'une part apte à connecter chaque calculateur audit ensemble d'Entrées/Sorties afin de permettre un échange de données de fonctionnement entre chaque calculateur et les dispositifs fonctionnels des unités du véhicule multi-unité, mais aussi, et d'autre part, à prioriser la connexion dudit calculateur maître désigné automatiquement audit ensemble d'Entrées/Sorties et à lui associer un calculateur redondant. Par prioriser, il est notamment fait référence à l'attribu¬ tion exclusive de la connexion avec ledit ensemble d'En¬ trées/Sorties à un calculateur, de préférence à un seul cal¬ culateur, par exemple ledit calculateur maître, ou encore le- dit calculateur maître avec son redondant. L'ensemble d'En¬ trées/Sorties des modules d'Entrées/Sorties du système de pi¬ lotage sécurisé permet de connecter chaque calculateur du vé¬ hicule multi-unité aux dispositifs fonctionnels dudit véhi¬ cule multi-unité via le réseau du véhicule multi-unité, ledit réseau étant commun à tous les calculateurs du véhicule mul¬ ti-unité. Ainsi, les données de compositions et de fonction¬ nements peuvent être facilement et rapidement centralisées vers un même calculateur, i.e. ledit calculateur maître, via ledit réseau, afin d'être traitées, ce qui a l'avantage de garantir une rapidité de traitement. A multi-unit vehicle is then likely to be formed of at least one autonomous unit that can be coupled, or not, to one or more autonomous or non-autonomous units. In any case, a computer of one of the autonomous units will be in particular responsible for the management of the control and operation of the multi-unit vehicle. Preferably, the master calcu ¬ tor of one of the autonomous units is intended to control the multi-unit vehicle. An automatic designation of the master computer for controlling said multi-unit vehicle is feasible as a function, for example, of the formation order of the multi-unit vehicle deductible from said composition datum that can be acquired by each calculator of each unit. . The security module of the control system is on the one hand able to connect each computer to said set of inputs / outputs to allow an exchange operating data between each computer and the functional devices of the units of the multi-unit vehicle, but also, and secondly, to prioritize the connection of said automatically designated master computer to said set of inputs / outputs and to associate a calculator redundant. By priority, it is in particular referred to the attributed exclusive ¬ tion of the connection with said set of trees In ¬ / output to a computer, preferably a single cal ¬ culateur, for example said master computer, or the - says master calculator with redundant sound. The set of trees In ¬ / O modules I / O of the pi system ¬ secure lotage connects each computer vee ¬ vehicle multi-functional unit devices of said vehi ¬ cule multi-unit via the network multi-unit vehicle, said network being common to all calculators of the vehicle mul ¬ ti-unit. Thus, the data of compositions and function ¬ events can be easily and quickly centralized to the same computer, ie said master computer, via said network, to be processed, which has the advantage of guaranteeing a processing speed.
Ainsi, pour un véhicule multi-unité comprenant plusieurs uni¬ tés autonomes, le système de pilotage selon l'invention est capable de choisir au moins un calculateur parmi l'ensemble des calculateurs distribués sur le réseau dudit véhicule afin qu'il agisse en tant que calculateur maître destiné à être associé directement, par connexion audit ensemble d'En¬ trées/Sorties, aux modules d'Entrées/Sorties dudit véhicule afin de le piloter, par exemple automatiquement. Lorsque le calculateur agissant en tant que calculateur maître pilote ledit véhicule, les autres calculateurs dudit véhicule peu¬ vent en particulier être en état de veille, de sorte que seul le calculateur choisi comme calculateur maître par le module de sécurisation commande le pilotage dudit véhicule. Des exemples de réalisations et d'applications fournis à l'aide des figures suivantes aideront à mieux comprendre présente invention. Figure 1 exemple de réalisation selon l'invention Thus, for a multi-unit vehicle comprising several uni ¬ tés autonomous, the control system according to the invention is able to choose at least one computer from all the computers distributed on the network of said vehicle so that it acts as master computer to be directly associated, by connection to said set of trees in ¬ / outputs, the inputs / outputs of said modules to drive the vehicle, for example automatically. When the computer acting as a master computer driver said vehicle, the other computers of said vehicle ¬ wind in particular be in a standby state, so that only the computer chosen as master computer by the security module controls the steering of said vehicle. Examples of embodiments and applications provided with the aid of the following figures will help to better understand this invention. FIG. 1 embodiment according to the invention
système de pilotage sécurisé.  secure steering system.
Figure 2 exemple de réalisation selon l'invention d'un dispositif de génération d'identité. FIG. 2 exemplary embodiment according to the invention of an identity generation device.
Figure 3 exemple de mécanisme de sécurisation d'un mo¬ dule de sécurisation et priorisation selon 1 ' invention . Figure 4 exemple de réalisation selon l'invention d'un couplage/scindage automatique d'unités d'un véhicule multi-unité. FIG. 3 example of a mechanism for securing a security and prioritization mo ¬ module according to the invention. Figure 4 embodiment according to the invention of an automatic coupling / splitting of units of a multi-unit vehicle.
A titre d'exemple, la figure 1 montre un système de pilotage sécurisé adapté à un pilotage d'un véhicule multi-unité re¬ configurable comprenant trois unités 1, 2, 3. Le système de pilotage comprend au moins un dispositif de génération d'identité 4, chaque dispositif de génération d'identité 4 étant destiné à équiper une unité 1, 2, 3. Ainsi, chaque uni¬ té 1, 2, 3 est apte à comprendre ledit dispositif de généra¬ tion d'identité 4. Chaque dispositif de génération d'identité 4 est connectable à ses voisins afin de former une chaîne de dispositifs de génération d'identité. Ladite chaîne de dispo- sitifs de génération d'identité connectables l'un à la suite de l'autre forme ledit dispositif de détermination d'une com¬ position du véhicule multi-unité selon l'invention. Ledit système de pilotage sécurisé comprend de plus au moins un calculateur 5 destiné à équiper chaque unité autonome 1, 2 du véhicule multi-unité, au moins un module d'Entrées/Sorties 91, et au moins un desdits calculateurs 5 du système de pilo¬ tage sécurisé comprenant au moins un module de sécurisation 6, éventuellement inclus dans le calculateur 5. En particu¬ lier, plusieurs calculateurs 5 sont distribués dans plusieurs unités autonomes 1, 2, et plusieurs modules d'Entrées/Sorties 91 sont distribués dans plusieurs unités, qu'elles soient au¬ tonomes ou non autonomes. Un réseau 8 du véhicule multi-unité permet de connecter les calculateurs 5, les modules de sécu¬ risation 6, le dispositif de détermination de la composition du véhicule multi-unité, les modules d'Entrées/Sorties 91, et les dispositifs fonctionnels 7 de chaque unité les uns aux autres afin qu'ils puissent communiquer et échanger des informations, comme par exemple les données de composition et les données de fonctionnement, les uns avec les autres. En particulier, les modules d'Entrées/Sorties 91 du système de pilotage permettent la connexion, via le réseau 8, des calcu¬ lateurs à un ensemble d'Entrées/Sorties, chaque Entrée/Sortie étant apte à connecter au moins un dispositif fonctionnel 7 à au moins un calculateur 5. Chaque calculateur 5 est en parti- culier dynamiquement reconfigurable sur la base de la donnée de composition fournie par le dispositif de détermination de la composition du véhicule multi-unité, afin de maintenir en temps réel une connexion avec lesdites Entrées/Sorties cohé¬ rente avec la composition dudit véhicule multi-unité. For example, Figure 1 shows a safety controller adapted for controlling a multi-unit vehicle re ¬ configurable comprising three units 1, 2, 3. The control system comprises at least one device for generating identity 4, each identity generation device 4 is designed to equip a unit 1, 2, 3. Thus, each uni ¬ tee 1, 2, 3 is adapted to include said device genera ¬ ID 4. Each identity generation device 4 is connectable to its neighbors in order to form a chain of identity generation devices. Said chain of identity generation devices connectable one after the other form said device for determining a com ¬ position of the multi-unit vehicle according to the invention. Said secure control system further comprises at least one computer 5 intended to equip each autonomous unit 1, 2 of the multi-unit vehicle, at least one input / output module 91, and at least one of said computers 5 of the pilosebaceous system ¬ secure floor comprising at least one security module 6, optionally included in the computer 5. In particu ¬ bind several computers 5 are distributed in several independent units 1, 2, and several modules / O 91 are distributed in several units, whether or not the ¬ tonomes autonomous. A network 8 of the multi-unit vehicle is used to connect the computers 5, the secu ¬ authorization modules 6, the device for determining the composition of the multi-unit vehicle, modules I / O 91, and the functional devices 7 from each unit to each other so that they can communicate and exchange information, such as composition data and operating data, with each other. In particular, the I / O modules 91 of the control system allow the connection, via the network 8, of the calcu ¬ latters to a set of inputs / outputs, each input / output being able to connect at least one functional device 7 to at least one computer 5. Each computer 5 is in particular dynamically reconfigurable on the basis of the composition data supplied by the device for determining the composition of the multi-unit vehicle, in order to maintain in real time a connection with said I / O coher ¬ annuity with the composition of said multi-unit vehicle.
La figure 2 présente un exemple de réalisation d'un disposi¬ tif de génération d'identité 4 selon l'invention. Chaque dispositif de génération d'identité 4 est connectable, notamment au moyen d'une connexion différentielle bidirectionnelle en série à bas débit, à au moins un autre dispositif de généra¬ tion d'identité 4a, 4b identique, en particulier à deux au¬ tres dispositifs de génération d'identité 4a, 4b identiques tel que présenté en Fig. 2. Chaque dispositif de génération d'identité 4, 4a, 4b, comprend un générateur de données iden- titaires 41, un détecteur de connexion 42, un générateur de liste 43, un composant de sérialisation 44, un transmetteur de liste 45, et au moins deux connecteurs, respectivement un premier connecteur 46a et un second connecteur 46b, destiné à l'acquisition et la transmission de la liste. Un troisième connecteur 47 peut en particulier connecter le dispositif de génération d'identité au réseau de l'unité ou du véhicule multi-unité . 2 shows an embodiment of a provi ¬ ID generation tif 4 according to the invention. Each identity generation device 4 is connectable, in particular by means of a bidirectional differential connection at low speed serial to at least one other genera device ¬ identity 4a, 4b identical, especially two ¬ identical identity generation devices 4a, 4b as shown in FIG. 2. Each identity generating device 4, 4a, 4b comprises an identical data generator 41, a connection detector 42, a signal generator list 43, a serialization component 44, a list transmitter 45, and at least two connectors, respectively a first connector 46a and a second connector 46b, for the acquisition and transmission of the list. A third connector 47 may in particular connect the identity generating device to the network of the unit or the multi-unit vehicle.
De plus, le détecteur de connexion du dispositif de généra- tion d'identité est en particulier caractérisé en ce qu'il est capable de garantir en sécurité qu'une liste présente en entrée sur le premier connecteur 46a ou respectivement le se¬ cond connecteur 46b et destinée à être acquise par ledit dis¬ positif de génération d'identité, ne peut pas se trouver par diaphonie ou tout autre couplage sur le second 46b ou respec¬ tivement le premier connecteur 46a. A cette fin, le détecteur de connexion, couplable audits connecteurs 46b, 46a, peut en particulier comprendre au moins un buffer différentiel isolé électriquement, notamment un premier buffer 422 connectable au premier connecteur et un second buffer connectable au second connecteur, ainsi que des récepteurs à opto-coupleurs , notamment un premier récepteur opto-coupleur connectable au premier connecteur et un second récepteur opto-coupleur 421 connectable au second connecteur. Eventuellement, des compo- sants de protection contre des perturbations et des surten¬ sions peuvent être ajoutés audit dispositif de détection, ainsi que des filtres afin d'assurer en sécurité une isola¬ tion entre le premier et second connecteur 46a, 46b. Préférentiellement , ledit composant de sérialisation 44 peut comprendre deux composants numériques distincts 441, 442, par exemple des FPGAs, capables de réaliser des fonctions de sé¬ rialisation et dé-sérialisation d'un élément de ladite liste, ainsi que la fonction d'ajout d'un autre élément à la suite du dernier élément de ladite liste, notamment afin de garan- tir en sécurité qu'une liste ne peut pas traverser le dispo¬ sitif de génération d'identité du connecteur 46a vers le connecteur 46b, ou inversement, sans avoir été enrichie avec la donnée identitaire dudit dispositif de génération d'iden- tité. In addition, the connection detector of the identity generation device is particularly characterized in that it is able to guarantee in safety that a list has an input on the first connector 46a or the se ¬ cond connector respectively. 46b and intended to be acquired by said identity generating dis ¬ positive, can not be found by crosstalk or any other coupling on the second 46b or respec ¬ tively the first connector 46a. To this end, the connection detector, connectable to said connectors 46b, 46a, may in particular comprise at least one electrically isolated differential buffer, in particular a first buffer 422 connectable to the first connector and a second buffer connectable to the second connector, as well as receivers opto-couplers, in particular a first optocoupler receiver connectable to the first connector and a second opto-coupler receiver 421 connectable to the second connector. Optionally, protection components against disturbances and surten¬ ¬ tions can be added to said detection device, as well as filters to ensure safe isola ¬ tion between the first and second connector 46a, 46b. Preferably, said serialization component 44 may comprise two separate digital components 441, 442, for example FPGAs, capable of performing functions sé ¬ Serialization and de-serialization of an item in said list, and the add function another element after the last element of that list, in particular in order to safe firing a list can not cross the dispo ¬ ID generation operative part of the connector 46a to the connector 46b, or vice versa, without having been enriched with the identity data of said identification generating device.
De plus, le générateur de donnée identitaire 41 est en parti¬ culier capable de générer une information de polarisation, ladite information de polarisation permettant, éventuellement de propager la liste comprenant ladite donnée identitaire uniquement vers un et un seul desdits premier ou second connecteurs 46a ou 46b. Finalement, ladite donnée identitaire peut avantageusement comprendre diverses informations permet¬ tant une identification de l'unité qu'elle équipe, comme par exemple un numéro d'équipement ou un numéro d'unité de l'uni¬ té qu'elle équipe. Le transmetteur de liste 45 est apte à servir d'interface entre le réseau, par exemple un réseau Ethernet IP, du véhicule multi-unité et le dispositif de gé¬ nération d'identité. A cette fin, il peut éventuellement com- prendre un composant numérique, tel un circuit logique pro¬ grammable FPGA. Furthermore, the identity data generator 41 is partly ¬ ticular, to generate a polarization information, said bias information to, optionally to propagate the list comprising said identity data only to one and only one of said first or second 46a connectors or 46b. Finally, said identity data can advantageously comprise various information allows ¬ as an identification of the unit which it is fitted, such as a device number or a unit number of the uni ¬ ty it equips. The list of transmitter 45 is able to act as an interface between the network, eg an IP Ethernet network, the multi-unit vehicle and the gen ¬ eration identity device. To this end, it may possibly under- stand a digital component such as a logic circuit ¬ grammable FPGA.
Dans le cas d'un véhicule multi-unité comportant n unités, numérotées successivement selon l'ordre de formation dudit véhicule multi-unité de 1 à n, l'indice 1 caractérisant l'unité positionnée à une extrémité du véhicule multi-unité et l'indice n l'unité positionnée à l'autre extrémité, un exemple de liste susceptible d'être créée par ajout successif de la donnée identitaire caractérisant chaque unité composant ledit véhicule multi-unité est donné par: In the case of a multi-unit vehicle comprising n units, numbered successively according to the order of formation of said multi-unit vehicle from 1 to n, the index 1 characterizing the unit positioned at one end of the multi-unit vehicle and the index n the unit positioned at the other end, an example of list likely to be created by successive addition of the identity data characterizing each unit of said multi-unit vehicle is given by:
Liste = Η1·τ2η+1 + τ - I di + τ2η_1 -Id2 +...+ τ 2(η-1+1) -idi +...+ τ2 -Idn avec Idi = pol± + Data±A pour i = 1,..., n et où List = Η1 · τ 2η + 1 + τ - I di + τ 2η_1 -Id 2 + ... + τ 2 (η - 1 + 1) -idi + ... + τ 2 -Id n with Idi = pol ± + Data ± A for i = 1, ..., n and or
Hl une donnée temporelle caractérisant la création la liste;  There is a temporal data characterizing the creation of the list;
τ est une constante de codage de valeur suffisamment grande, exprimé sur, par exemple, 48 bits d' informa tion, afin de garantir l'objectif de sécurité SIL4 telle que la suite des τ1 présente une distribution pseudo aléatoire; τ is a coding constant of sufficiently large value, expressed on, for example, 48 bits of information, in order to guarantee the security objective SIL4 such that the sequence of τ 1 presents a pseudo-random distribution;
I di est la donnée identitaire de l'unité i du véhicule multi-unité ;  I di is the identity data of the unit i of the multi-unit vehicle;
poli une donnée caractérisant la polarité de l'unité la polarité indiquant simplement si l'unité i est attelée en marche avant ou marche arrière à l'unité i-1; polishes a data characterizing the polarity of the unit the polarity simply indicating whether the unit i is hitched forward or backward to the unit i-1;
Data± est une donnée caractérisant au moins un équipement de l'unité i ou un numéro d'identification de l'unité Data ± is a data characterizing at least one equipment of the unit i or an identification number of the unit
Le système de pilotage selon l'invention est ainsi capable de garantir qu'au moins un calculateur, préférentiellement le calculateur maître, est associé de manière cohérente à l'en¬ semble des dispositifs fonctionnels du véhicule multi-unité afin d'assurer le pilotage dudit véhicule multi-unité. Le dispositif de détermination de la composition du véhicule multi-unité permet de découvrir ladite composition par propa¬ gation de ladite liste d'une unité à une autre unité compo¬ sant ledit véhicule multi-unité. Sur la base de la donnée de composition apte à encapsuler ladite liste, le module de sé- curisation associe, préférentiellement de façon exclusive, une connexion à un ensemble d'Entrées/Sorties distribuées sur le réseau dudit véhicule multi-unité avec un calculateur, en particulier avec un calculateur maître, lesdites Entrées/Sorties étant destinées à connecter ledit calculateur aux dispositifs fonctionnels des unités qui composent ledit véhicule multi-unité. De manière préférentielle, chaque cal¬ culateur est couplé à un module de sécurisation selon l'invention, et chaque module de sécurisation selon l'invention est apte, en fonction de ladite donnée de composition à en¬ trer dans un mode inactif ou dans un mode actif, de sorte qu'un unique module se sécurisation est actif pour le véhicule multi-unité. En particulier, au moins une condition pré¬ définissable dans chacun desdits modules de sécurisation per- met à chacun des modules de sécurisation de déterminer son propre mode de fonctionnement, i.e. soit ledit mode actif, soit ledit mode inactif. Ladite condition prédéfinissable pouvant par exemple être corrélée à une position, au sein du véhicule multi-unité, de l'unité équipée d'un calculateur comprenant ledit module de sécurisation. The control system according to the invention is thus able to ensure that at least one computer, preferably the master computer is associated consistently seems to ¬ functional devices of the multi-unit vehicle to ensure driving said multi-unit vehicle. The device for determining the composition of the multi-unit vehicle to discover said composition propa gation ¬ said list from one unit to another unit compo ¬ sant said multi-unit vehicle. On the basis of the composition datum able to encapsulate said list, the security module associates, preferably exclusively, a connection to a set of distributed I / O on the network of said multi-unit vehicle with a computer. in particular with a master computer, said inputs / outputs being intended to connect said calculator to the functional devices of the units that make up said multi-unit vehicle. Preferably, each cal ¬ culateur is coupled to a security module according to the invention, and each security module according to the invention is adapted, in dependence on said data to composition ¬ trate into an idle mode or in a active mode, so that a single securing module is active for the multi-unit vehicle. In particular, at least one condition pre ¬ definable in each of said secure modules per- makes each of security modules to determine its own operating mode, ie either said active mode or said inactive mode. Said predefinable condition can for example be correlated to a position within the multi-unit vehicle of the unit equipped with a computer comprising said security module.
La figure 3 présente un exemple de mécanisme de sécurisation de l'association d'au moins un calculateur d'un système de pilotage selon l'invention avec un ensemble d'Entrées/Sorties de modules d'Entrées/Sorties destinés à équiper le véhicule multi-unité. Une fois que la donnée de composition du véhi¬ cule multi-unité a été créée, la méthode selon l'invention est caractérisée en ce qu'un module de sécurisation est choi¬ si, par exemple en fonction de ladite donnée de composition, afin de sécuriser la connexion d'un calculateur ou d'un groupe de calculateur, par exemple un calculateur maître et son calculateur redondant, avec un ensemble d'Entrées/Sorties de modules d'Entrées/Sorties. A cette fin, le module de sécu¬ risation comprend en particulier un générateur de jeton d'as- sociation codé capable de générer un jeton d'association codé comprenant en particulier un code d'identification spécifique du calculateur ou du groupe de calculateurs autorisés à être connecté aux Entrées/Sorties desdits modules d'En¬ trées/Sorties. Le module de verrouillage du module de sécuri- sation est en particulier capable de transmettre ledit jeton à tous les modules d'Entrées/Sorties dont les Entrées/Sorties doivent être connectées audit calculateur ou groupe de calcu¬ lateur afin de rester cohérent avec ladite donnée de composi¬ tion du véhicule multi-unité, et afin de permettre un FIG. 3 shows an exemplary mechanism for securing the association of at least one computer of a control system according to the invention with a set of inputs / outputs of input / output modules intended to equip the vehicle. multi-unit. Once the vehi composition data ¬ multi-unit cule was created, the method according to the invention is characterized in that a security module is choi ¬ if, for example as a function of said given composition, to to secure the connection of a computer or a computer group, for example a master computer and its redundant computer, with a set of inputs / outputs of input / output modules. To this end, the secu ¬ authorization module comprises in particular an encoded association token generator capable of generating an encoded association token comprising in particular a unique identification code of the computer or computers group allowed to be connected to inputs / outputs of said modules ¬ Trees In / Out. In particular, the locking module of the security module is capable of transmitting said token to all inputs / outputs of modules whose I / O must be connected to said computer or group of calcu ¬ freezer in order to be consistent with said data composi ¬ multi-unit vehicle, and to allow
contrôle, par le calculateur ou le groupe de calculateur, des dispositifs fonctionnels du véhicule multi-unité. Ladite don¬ née de composition permet en particulier au module de sécurisation de déterminer quelles Entrées/Sorties de quels modules d'Entrées/Sorties doivent être contrôlées par le calculateur ou groupe de calculateur afin d'assurer le fonctionnement du véhicule multi-unité, et donc de déterminer quelles En¬ trées/Sorties doivent être connectées audit calculateur ou groupe de calculateur. Chaque module d'Entrées/Sorties recevant ledit jeton d'asso¬ ciation codé est en particulier capable, durant une phase de réponse, d'émettre périodiquement ou suffisamment fréquemment un message de confirmation capable de confirmer la connexion dudit calculateur avec les Entrées/Sorties dudit module d'En- trées/Sorties , et de transmettre ledit message de confirma¬ tion audit calculateur, en particulier audit module de sécurisation dudit calculateur du système de pilotage sécurisé. Ledit message de confirmation peut par exemple être émis pé¬ riodiquement à une période d'émission dont la valeur tempo- relie, i.e. sa durée, peut-être prédéfinie. Avantageusement, la phase de réponse peut être précédée par une phase d'ini¬ tialisation 1 permettant la génération et l'initialisation du message de confirmation. La durée de cette phase d'initiali¬ sation est en particulier supérieure à la durée de ladite pé- riode d'émission afin de garantir en sécurité que le mécanisme de sécurisation ait le temps de détecter qu'un calcula¬ teur ou un groupe de calculateurs préalablement connectés à une Entrée/Sortie d'un module d'Entrées/Sorties a ou ont per¬ du ladite connexion avec ladite Entrée/Sortie avant qu'un au- tre calculateur ou un autre groupe de calculateur ait eu le temps de se connecter à ladite Entrée/Sortie. Cette durée de la phase d'initialisation supérieure à la période d'émission peut être par exemple garantie par un générateur pseudo aléa¬ toire obligé à fonctionner en permanence durant ladite phase d'initialisation du message de confirmation. control, by the computer or the computer group, of the functional devices of the multi-unit vehicle. Said Don ¬ born composition allows particularly security module to determine which I / O modules to which Inputs / Outputs must be controlled by the computer or computer group to operate the multi-unit vehicle, therefore determine which trees in ¬ / O must be connected to said computer or computer group. Each I / O module receiving said asso ciation ¬ encoded token is in particular able, during a response phase, periodically transmitting or sufficiently frequently a confirmation message capable of confirming the connection of said computer with I / O said module In- puts / outputs, and to transmit said message confirmed ¬ said computer, in particular to said security module of said computer of the safety controller. Said confirmation message may for example be transmitted periodically to pe ¬ a transmission period whose value temporal links, ie its length, may be predefined. Advantageously, the response phase may be preceded by a phase of ini ¬ tialisation 1 allowing generation and initialization of the confirmation message. The duration of this phase initiali sation ¬ is in particular greater than the duration of said pe- transmission period to ensure that the safe securing mechanism has time to detect that a calculated ¬ tor or a group of computers previously connected to an input / output of an input / output module a or have per ¬ said connection with said input / output before another calculator or another group of calculator has had the time to connect to said Input / Output. This duration of the initialization phase greater than the transmission period may be for example guaranteed by a pseudo random generator ¬ toire to operate continuously during said initialization phase of the confirmation message.
Ainsi, à la fin de la phase d'initialisation 1, un message de confirmation initialisé 2 est généré par le module d'En¬ trées/Sorties. Lors de la réception 3 d'un jeton d'associa- tion codé transmis par le module de sécurisation du système de pilotage, le module d'Entrées/Sorties est apte à associer, durant une phase d'association 4, ledit jeton d'association codé audit message de confirmation initialisé. A la fin de cette phase d'association, ledit message de confirmation 5 est prêt pour être transmis périodiquement au module de sécu¬ risation. Avantageusement, ce message de confirmation, suite à ladite phase d'association, comprend d'une part ladite don¬ née d'identification du calculateur ou groupe de calculateur, mais aussi d'autre part, une identification des En- trées/Sorties du module d'Entrées/Sorties connectées audit calculateur ou groupe de calculateurs, et une donnée tempo¬ relle afin de vérifier une fraîcheur du message de confirma¬ tion. Le message de confirmation est ensuite envoyé, notam¬ ment cycliquement , durant la phase de réponse 6, au moins au- dit module de sécurisation ayant émis le jeton d'association codé. Le module de verrouillage dudit module de sécurisation est en particulier capable de décoder le message de confirma¬ tion afin de contrôler que les Entrées/Sorties dudit module d'Entrées/Sorties sont connectées audit calculateur ou audit groupe de calculateur, et non à d'autres calculateurs. Thus, at the end of the initialization phase 1, a confirmation message initialized 2 is generated by the module ¬ Trees In / Out. Upon receipt of a coded association token transmitted by the security module of the control system, the input / output module is able to associate, during an association phase 4, said token of coded association to said initialized confirmation message. At the end of this phase of association, said 5 confirmation message is ready to be sent periodically to secu ¬ authorization module. Advantageously, this confirmation message, following said step of association, comprises firstly said donation ¬ born identification of the computer or computer group, but also on the other hand, identification of In- puts / Outputs input / output module connected to said computer or group of computers, and a tempo ¬ real data to verify a freshness of the confirmation message ¬ tion. The confirmation message is then sent, in particular ¬ cyclically during the response phase 6, at least au said security module that issued the coded token combination. The locking module said security module is in particular able to decode the message confirmed ¬ order to control the inputs / outputs of said module I / O are connected to said computer or said computer group, and not of other calculators.
Avantageusement, tant qu'un module d'Entrées/Sorties est connecté à un calculateur ou groupe de calculateur via ses Entrées/Sorties, ledit module d'Entrées/Sorties génère, no- tamment cycliquement, à ladite période d'émission ledit mes- sage de confirmation et aucun autre calculateur ne peut y être connecté. Afin de libérer le module d'Entrées/Sorties de sa connexion avec un calculateur ou groupe de calculateur, le générateur de jeton d'association dudit module de verrouil- lage est capable de générer une clé de déverrouillage desti¬ née à être transmise par le module de verrouillage à l'ensem¬ ble des modules d'Entrées/Sorties dont les connexions avec le calculateur ou le groupe de calculateur doivent être coupées. A la réception d'une telle clé de déverrouillage 7, le module d'Entrées/Sorties est en particulier apte à désassocier le jeton d'association codé du message de confirmation initiali- sé afin de restaurer ledit message de confirmation initialisé 2. En cas de défaillance 9, par exemple en cas de perte de connexion ou de communication avec le module de sécurisation ou le calculateur, le module d'Entrées/Sorties est capable de se réinitialiser en retournant à la phase d'initialisation du message de confirmation afin de permettre, par exemple, qu'un jeton d'association codé d'un autre calculateur soit susceptible d'être associé audit message de confirmation initiali¬ sé . Advantageously, as long as an I / O module is connected to a computer or computer group via its inputs / outputs, said I / O module generates, in particular cyclically, said transmission period confirmation message and no other calculator can be connected to it. In order to release the module I / O of its connection with a computer or computer group, the Association token generating said verrouil- spinning module is capable of generating a desti unlocking key ¬ born to be transmitted by the locking module to ensem ¬ ble modules I / O whose connections with the computer or the computer group are to be cut. Upon receipt of such an unlocking key 7, the I / O module is particularly adapted to disassociate the coded association token from the initial confirmation message in order to restore said initialized confirmation message 2. In case 9, for example in case of loss of connection or communication with the security module or the computer, the I / O module is able to reset by returning to the initialization phase of the confirmation message in order to allow, for example, a combination of encoded token from another computer is capable of being associated with said initiali confirmation message ¬ sé.
La phase de réponse 6 permet d'envoyer, notamment cyclique- ment, au module de sécurisation la confirmation, via ledit message de confirmation, que les Entrées/Sorties dudit module d'Entrées/Sorties sont connectées et contrôlées par le calcu¬ lateur, par exemple le calculateur maître, ou par un groupe de calculateurs, par exemple le calculateur maître et son re- dondant . Ledit module de sécurisation est ainsi en particu¬ lier capable de vérifier en permanence une cohérence de la connexion du calculateur avec chaque module d'Entrées/Sorties pour lequel il a reçu ledit message de confirmation et ladite donnée de composition, garantissant ainsi en sécurité la connexion d'un calculateur audit ensemble d'Entrées/Sorties. La figure 4 décrit un couplage automatique d'un premier véhi¬ cule multi-unité 1 avec un second véhicule multi-unité 2 com- prenant chacun un système de pilotage sécurisé selon l'inven¬ tion, afin de former un nouveau véhicule multi-unité. Avant le couplage, les deux véhicules multi-unités , par exemple un premier train comprenant trois voitures et un second train comprenant deux voitures, comprennent chacun un système de pilotage sécurisé distribué qui leur est propre, lesdits sys¬ tèmes de pilotage sécurisés de chacun des véhicules multi- unités étant indépendants l'un de l'autre. Le premier véhi¬ cule multi-unité 1 comprend en particulier trois unités, et le second véhicule multi-unité 2 comprend quant à lui deux unités. The response phase 6 for sending, in particular cyclically, in the security module confirmation via said confirmation message that the inputs / outputs of said module I / O are connected and controlled by the calcu ¬ freezer, for example the master computer, or by a group of computers, for example the master computer and its redundant. Said security module is thus able to bind particu ¬ continuously check consistency of the computer connection with each module I / O for which it has received said confirmation message and said given composition, thereby ensuring the safe connecting a calculator to said set of Inputs / Outputs. Figure 4 discloses an automatic coupling a first vehi ¬ cule multi-unit 1 with a second multi-unit vehicle 2 com- each taking a safety control system according to the inven ¬ to form a new vehicle multi- unit. Prior to coupling, the two multi-unit vehicle, such as a first train with three cars and a second train with two cars each include a distributed safety control of their own, said secure control sys ¬ tems of each multi-unit vehicles being independent of one another. The first vehi ¬ cule multi-unit 1 comprises in particular three units, and the second multi-unit vehicle 2 comprises in turn two units.
Le système de pilotage du premier véhicule multi-unité 1 com¬ prend en particulier au moins trois calculateurs 51, 52, 53 et au moins trois modules d'Entrées/Sorties 91, 92, 93, re- liés par un premier réseau 81, par exemple Ethernet, CPL, Wi- Fi . Similairement , le second véhicule multi-unité 2 comprend en particulier au moins deux calculateurs 54, 55, et au moins deux modules d'Entrées/Sorties 94, 95, reliés par un second réseau 82. Pour chacun des deux véhicules multi-unités, au moins un calculateur et au moins un module d'Entrées/Sorties du système de pilotage sécurisé sont destinés à équiper une unité, de sorte que chaque unité comprenne au moins un calcu¬ lateur et au moins un module d'Entrées/Sorties. Ainsi, dans cet exemple, chaque unité est une unité autonome. Cependant, lesdits premier et second véhicules multi-unités pourraient tout aussi bien comprendre une ou plusieurs unités non- autonomes, chaque unité non-autonome comprenant par exemple au moins un module d'Entrées/Sorties et un dispositif de gé¬ nération d'identité. Un des calculateurs 51, 52, 53 du premier véhicule multi- unité 1 est choisi pour être le calculateur maître du premier véhicule multi-unité 1, par exemple le calculateur 51 apte à être positionné à une extrémité dudit premier véhicule multi- unité 1, et éventuellement un autre des calculateurs 51, 52, 53 du premier véhicule multi-unité 1 est choisi pour être son redondant, par exemple le calculateur 53 positionnable à l'autre extrémité du premier véhicule multi-unité 1. Similai- rement, un des calculateurs 54, 55 du second véhicule multi- unité 2 est choisi pour être le calculateur maître du second véhicule multi-unité 2, par exemple le calculateur 54 posi¬ tionnable à une extrémité du second véhicule multi-unité 2, et éventuellement un autre des calculateurs 54, 55 du second véhicule multi-unité 2 est choisi pour être son redondant, par exemple le calculateur 55 positionnable à l'autre extré¬ mité du second véhicule multi-unité 2. De manière générale, il est toujours préférable que le système de pilotage sécuri¬ sé comprenne en particulier un calculateur maître positionna¬ ble, notamment dans une unité autonome, à une extrémité du véhicule multi-unité et un calculateur mis en redondance du¬ dit calculateur maître, i.e. son redondant, positionnable, notamment dans une unité autonome, à l'autre extrémité dudit véhicule multi-unité, afin de permettre un scindage efficace dudit véhicule multi-unité. The control system of the first multi-unit vehicle 1 com ¬ takes in particular at least three computers 51, 52, 53 and at least three I / O modules 91, 92, 93, linked by a first network 81, for example Ethernet, PLC, Wi-Fi. Similarly, the second multi-unit vehicle 2 comprises in particular at least two computers 54, 55, and at least two I / O modules 94, 95, connected by a second network 82. For each of the two multi-unit vehicles, at least one computer and at least one module I / O of the safety controller are designed to equip a unit, so that each unit comprises at least one calcu ¬ freezer and at least one I / O module. So, in this example, each unit is an autonomous unit. However, the first and second multi-unit vehicle could equally comprise one or more non-autonomous units, each non-autonomous unit comprising for example at least one module / O device and a gen ¬ eration identity . One of the computers 51, 52, 53 of the first multi-unit vehicle 1 is chosen to be the master computer of the first multi-unit vehicle 1, for example the computer 51 capable of being positioned at one end of said first multi-unit vehicle 1, and possibly another of the computers 51, 52, 53 of the first multi-unit vehicle 1 is chosen to be its redundant, for example the computer 53 positionable at the other end of the first multi-unit vehicle 1. Similarly, one of the computers 54, 55 of the second multi-unit vehicle 2 is chosen to be the master computer of the second multi-unit vehicle 2, for example the computer 54 posi ¬ tionable at one end of the second multi-unit vehicle 2, and possibly another of ECUs 54, 55 of the second multi-unit vehicle 2 is selected to be its redundant, for example the computer 55 positionable other Extremists ¬ mite second multi-unit vehicle 2. man General st, it is still preferable that the Sécuri control system ¬ comprises in particular a master computer positioned itself ¬ ble, particularly in a self-contained unit, to one end of the multi-unit and a computer vehicle placed in redundancy ¬ said master computer , ie its redundant, positionable, especially in an autonomous unit, at the other end of said multi-unit vehicle, to allow efficient splitting of said multi-unit vehicle.
Les autres calculateurs du premier véhicule multi-unité 1, respectivement du second véhicule multi-unité 2, sont dans un état inactif, tel que par exemple, le calculateur 52 du pre- mier véhicule multi-unité 1. De manière générale, le choix du calculateur maître et de son redondant peut être basé sur un algorithme de choix utilisant une numérotation, comme par exemple une adresse IP ou un numéro de calculateur, ou bien une détermination d'une position des calculateurs dans le vé- hicule multi-unité, ladite position étant par exemple une po- sition centrale, une position en tête ou en queue de véhicule multi-unité, la position d'un calculateur étant déductible de ladite donnée de composition. Préférentiellement , pour chacun des systèmes de pilotage du premier et second véhicule multi- unité, au moins un mécanisme de sécurisation et de priorisa¬ tion d'un module de sécurisation d'un calculateur du système de pilotage est apte à choisir ledit calculateur maître et son redondant, et permet dès lors une priorisation du calcu¬ lateur maître, ou autrement dit, une connexion exclusive du calculateur maître avec les Entrées/Sorties des modules d'En¬ trées/Sorties du véhicule multi-unité, de sorte que seul le calculateur maître soit apte à contrôler les Entrées/Sorties des modules d'Entrées/Sorties destinés à équiper ledit véhi¬ cule multi-unité. Le calculateur redondant est quant à lui apte à prendre le contrôle desdites Entrées/Sorties en cas de défaillance du calculateur maître. Pour chaque véhicule mul¬ ti-unité, ledit module de sécurisation apte à réaliser ledit mécanisme de sécurisation et priorisation peut éventuellement être choisi automatiquement en fonction de ladite donnée de composition pour chacun desdits véhicules multi-unités . De manière préférentielle, le module de sécurisation est apte à choisir comme calculateur maître via son mécanisme de sécurisation et priorisation le calculateur qu'il est destiné à équiper. Ainsi, le module de sécurisation est apte à priori- ser préférentiellement le calculateur qu'il équipe. The other computers of the first multi-unit vehicle 1, respectively of the second multi-unit vehicle 2, are in an inactive state, such as, for example, the computer 52 of the first multi-unit vehicle 1. In general, the choice the master computer and its redundant may be based on a choice algorithm using a numbering, such as an IP address or a computer number, or a determination of a position of the computers in the multi-unit vehicle, said position being for example a po- central position, a position at the head or tail of multi-unit vehicle, the position of a calculator being deductible from said composition data. Preferably, for each of the control systems of the first and second multi-unit vehicle, at least one securing mechanism and priorisa ¬ a security module of a steering system of the computer is adapted to select said master computer and its redundant, and therefore allows a prioritization calcu ¬ freezer master, or in other words, an exclusive connection of the master computer with I / O modules of in ¬ Trees / outputs of the multi-unit vehicle, so that only the master computer is able to control the inputs / outputs of the modules I / O for providing said vehi ¬ multi-unit cule. The redundant computer is able to take control of said inputs / outputs in the event of failure of the master computer. For each vehicle ¬ mul ti-unit, said security module capable of performing said securing and prioritization mechanism can optionally be selected automatically according to said given composition for each of said multi-unit vehicles. Preferably, the security module is able to choose as master computer via its mechanism of securing and prioritizing the computer that it is intended to equip. Thus, the security module is preferably able to prioritize the computer that it equips.
Ainsi, un module de sécurisation 6 du premier véhicule multi- unité 1 est apte à choisir ledit calculateur 51 en tant que calculateur maître afin de permettre à ce dernier de contrô- 1er les Entrées/sorties des modules d'Entrées/Sorties 91, 92, 93 du premier véhicule multi-unité 1 via le premier réseau 81. De manière similaire, un module de sécurisation 6 du se¬ cond véhicule multi-unité 2 est apte à choisir ledit calcula¬ teur 54 en tant que calculateur maître afin de lui permettre de contrôler les Entrées/Sorties des modules d'En- trées/Sorties 94, 95 du second véhicule multi-unité 2 via le second réseau 82. Thus, a security module 6 of the first multi-unit vehicle 1 is able to select said computer 51 as master computer to enable the master computer to control the inputs / outputs of the I / O modules 91, 92 93, of the first multi-unit vehicle 1 via the first network 81. Similarly, a security module 6 of the se ¬ multi-unit vehicle 2 is able to choose said calculator 54 ¬ as master computer to him to control the inputs / outputs of the modules of En- 94, 95 of the second multi-unit vehicle 2 via the second network 82.
Avantageusement, chaque calculateur selon l'invention, lors- qu'il est le calculateur redondant d'un calculateur maître, est en particulier capable de vérifier un état de synchronisation de son contexte avec un contexte dudit calculateur maître. Préférentiellement , le calculateur maître et son re¬ dondant, lorsque le contexte de ce dernier est vérifié syn- chrone à celui du calculateur maître, sont aptes à être connectés aux Entrées/Sorties des modules d'Entrées/Sorties qui leurs sont associables. En particulier, le module de sé¬ curisation 6 du calculateur maître est capable de verrouil¬ ler, au moyen d'un jeton d'association codé, la connexion du- dit calculateur maître et de son redondant avec lesdites En¬ trées/Sorties. Préférentiellement , lorsqu'un calculateur maî¬ tre et son redondant sont connectés via une connexion ver¬ rouillée à un ensemble d'Entrées/Sorties, seul le calculateur maître est autorisé à commander les dispositifs fonctionnels du véhicule multi-unité, alors que le calculateur redondant est apte à vérifier des opérations effectuées par le calcula¬ teur maître et à remplacer ledit calculateur maître en cas de défaillance de ce dernier. Le système de pilotage du premier véhicule multi-unité 1 est de plus caractérisé en ce qu'il comprend au moins un disposi¬ tif de génération d'identité, en particulier trois disposi¬ tifs de génération d'identité 41, 42, 43, chacun destiné à équiper une unité du premier véhicule multi-unité 1. Egale- ment, le système de pilotage du second véhicule multi-unité comprend deux dispositifs de génération d'identité destinés à équiper, chacun, une unité dudit second véhicule multi-unité 2. Ainsi, un premier dispositif de génération d'identité 41, un second dispositif de génération d'identité 42 et un troi- sième dispositif de génération d'identité 43 équipent chacun une unité du premier véhicule multi-unité 1, et un premier dispositif de génération d'identité 44 et un second disposi¬ tif de génération d'identité équipent ledit second véhicule multi-unité. Les dispositifs de génération d'identité 41, 42, 43 du premier véhicule multi-unité 1, respectivement ceux du second véhicule multi-unité 2, sont connectables l'un à la suite de l'autre afin de former une première chaîne de dispo¬ sitif de génération d'identité, respectivement une seconde chaîne de dispositifs de génération d'identité, chacune des- dites chaînes étant en d'autres termes un premier, respecti¬ vement second, dispositif de détermination de la composition du véhicule multi-unité selon l'invention. Chaque dispositif de génération d'identité est capable de communiquer et d'échanger des données, notamment ladite liste selon 1 ' inven- tion, avec son ou ses voisins. De manière identique pour le système de pilotage du premier ou du second véhicule multi- unité, une communication peut être établie d'une extrémité à l'autre de sa chaîne de dispositifs de génération d'identité, ou en d'autres termes, d'une extrémité à l'autre du véhicule multi-unité, soit dans un premier sens de la tête à la queue du véhicule multi-unité, par exemple du dispositif de généra¬ tion d'identité 41 situé à la tête du véhicule multi-unité au dispositif de génération d'identité 43 situé à la queue dudit véhicule multi-unité, soit à l'inverse, de la queue à la tête du véhicule multi-unité, par exemple du dispositif de généra¬ tion d'identité 43 en queue au dispositif de génération d'identité 41 en tête, ou bien même, dans les deux sens à la fois. Il en va de même pour les dispositifs de génération d'identité 44, 45 du second véhicule multi-unité. Advantageously, each computer according to the invention, when it is the redundant computer of a master computer, is particularly capable of checking a state of synchronization of its context with a context of said master computer. Preferably, the master computer and its re ¬ dondant, when the context of the latter is checked synchro to that of the master computer, are able to be connected to the input / output of the input / output modules that are associable. In particular, the module sé ¬ curisation 6 of the master computer is able to Lock ¬ l, by means of an association encoded token, the du- connection said master computer and its redundant with said ¬ Trees in / outputs. Preferably, when a computer Maî ¬ be redundant and are connected via a connection worm ¬ rusty to a set of I / O, only the master computer is permitted to control the functional devices of the multi-unit vehicle, so that the computer redundant is able to verify operations performed by the master calculator ¬ and to replace said master computer in case of failure of the latter. The steering system of the first multi-unit vehicle 1 is further characterized in that it comprises at least one provi ¬ tif Identity Generator, in particular three provisions ¬ tive of Identity Generator 41, 42, 43, each of which is intended to equip a unit of the first multi-unit vehicle 1. Equally, the control system of the second multi-unit vehicle comprises two identity generation devices intended to equip, each, a unit of said second multi-unit vehicle. 2. Thus, a first identity generation device 41, a second identity generation device 42 and a third identity generation device 43 equip each of them. a unit of the first multi-unit vehicle 1, and a first identification generating device 44 and a second provi ¬ tif Identity Generator equip said second multi-unit vehicle. The identity generating devices 41, 42, 43 of the first multi-unit vehicle 1, respectively those of the second multi-unit vehicle 2, are connectable one after the other in order to form a first dispo chain. ¬ ID generation operative part, respectively a second chain of identity generation devices, each des- said chains being in other words a first, respecti vely ¬ second device for determining the composition of the multi-unit vehicle according to the invention. Each identity generation device is capable of communicating and exchanging data, including said list according to the invention, with its neighbor (s). Similarly for the control system of the first or second multi-unit vehicle, communication may be established from one end of the chain of identity generating devices to another, or in other words one end to the other of the multi-unit vehicle, either in a first direction of the head to the tail of the multi-unit vehicle, for example the genera device ¬ identity 41 located at the head of the vehicle multi- unit identity Generator device 43 located at the tail of said multi-unit vehicle, or conversely, from the tail to the head of the multi-unit vehicle, for example the genera device ¬ identity 43 queue at the identity generation device 41 at the head, or even in both directions at the same time. The same is true for the identity generating devices 44, 45 of the second multi-unit vehicle.
Avantageusement, au moins un des dispositifs de génération d'identité 41, 42, 43 du premier véhicule multi-unité 1, res¬ pectivement du second véhicule multi-unité 2, en particulier situé en extrémité de la première chaîne, respectivement de la seconde chaîne, est apte à initialiser ladite liste selon l'invention, par exemple une première liste pour le système de pilotage du premier véhicule multi-unité 1, et une seconde liste pour le second véhicule multi-unité 2. Chacune de ces listes comprend de préférence une donnée temporelle, par exemple une date, et permet un encodage de la composition du véhicule multi-unité pour lequel elle a été générée. Ainsi, la première liste sera apte à être initialisée pour le pre¬ mier véhicule multi-unité 1 par un de ses dispositifs de gé¬ nération d'identité et permettra un encodage de la composi- tion dudit premier véhicule multi-unité 1, et une seconde liste sera apte à être initialisée pour le second véhicule multi-unité 2 par un de ses dispositifs de génération d'iden¬ tité, et permettra aussi un encodage de sa composition. Pour chacun des systèmes de pilotage du premier et du second véhi- cule multi-unité, une fois la première, respectivement se¬ conde, liste initialisée à une extrémité de ladite première chaîne, respectivement seconde chaîne, ladite première liste, respectivement seconde liste, est transmise à un autre dispo¬ sitif de génération d'identité en direction de l'autre extré- mité de ladite première, respectivement seconde, chaîne de façon à ce qu'elle parcourt toute ladite première, respecti¬ vement seconde, chaîne de dispositifs de génération d'identi¬ té. Chaque dispositif de génération d'identité 41, 42, 43 du premier véhicule multi-unité 1, respectivement chaque dispo- sitif de génération d'identité 44, 45 du second véhicule mul¬ ti-unité 2, est capable d'accumuler ou ajouter une donnée identitaire dans ladite première liste, respectivement se¬ conde liste, à la suite du dernier élément (par exemple à la suite de la dernière donnée identitaire) ajouté dans ladite première, respectivement seconde, liste par le dispositif de génération d'identité précédent. Le dispositif de génération d'identité situé à l'autre extrémité de ladite première chaîne, respectivement seconde chaîne, i.e. situé en fin de chaîne, est en particulier apte à transmettre, notamment cy- cliquement, ladite première liste, respectivement seconde liste, encapsulée dans une donnée de composition, au calcula¬ teur maître 51 et à son redondant 53 via ledit premier réseau 81 dans le cas du premier véhicule multi-unité 1, et au cal¬ culateur maître 54 et à son redondant 55, via ledit second réseau 82 dans le cas du second véhicule multi-unité 2. Advantageously, at least one of the identity generation devices 41, 42, 43 of the first multi-unit vehicle 1, res ¬ respectively of the second multi-unit vehicle 2, in particular located at the end of the first chain, respectively of the second string, is able to initialize said list according to the invention, for example a first list for the control system of the first multi-unit vehicle 1, and a second list for the second multi-unit vehicle 2. Each of these lists preferably comprises a time data, for example a date , and allows an encoding of the composition of the multi-unit vehicle for which it was generated. Thus, the first list is adapted to be initialized for the pre ¬ Mier multi-vehicle unit 1 by one of its devices ¬ gen eration of identity and enable an encoding of the composition of said first multi-unit vehicle 1, and a second list will be able to be initialized for the second multi-unit vehicle 2 by one of its iden ¬ tite generation devices, and will also allow encoding of its composition. For each of the control systems of the first and second multi-unit vehi- cule, once the first, respectively when ¬ count, list initialized at one end of said first channel, second channel respectively, said first list, respectively second list, is transmitted to another available ¬ operative part direction identity Generator each other extré- moth said first respectively second string so that it travels throughout said first, respecti vely ¬ second chain of devices generating identity ¬ té. Each identity generation device 41, 42, 43 of the first multi-unit vehicle 1, respectively each Identity Generator device 44, 45 of the second vehicle ¬ mul ti-unit 2, is able to accumulate or add an identity datum in said first list, respectively is ¬ list after the last element (for example following the last identity data) added in said first, respectively second list by the preceding identity generation device . The identity generation device located at the other end of said first chain, or second chain, ie located at the end of the chain, is in particular able to transmit, in particular cyclically, said first list, respectively second list, encapsulated in a given composition, the calculated ¬ tor master 51 and its redundant 53 via said first network 81 in the case of the first multi-unit vehicle 1, and the cal ¬ culateur master 54 and its redundant 55, via said second network 82 in the case of the second multi-unit vehicle 2.
En particulier, dans le cas d'une initialisation de ladite liste par chacun des dispositifs de génération d'identité si¬ tués en extrémité de chaîne, i.e. une première initialisation d'une première liste à une extrémité de la chaîne et une se¬ conde initialisation d'une seconde liste à l'autre extrémité de la chaîne, et une propagation de chacune des deux listes dans un sens opposé dans ladite chaîne de dispositifs de gé¬ nération d'identité, le dispositif de génération d'identité susceptible de recevoir la première liste par un de ses connecteurs et la seconde liste par un autre de ses connec¬ teurs est en particulier capable de créer une nouvelle liste comprenant les éléments de la première liste, auxquels est ajouté d'abord la donnée identitaire créée par ledit disposi- tif de génération susceptible de recevoir la première et se¬ conde liste, et ensuite les éléments de la seconde liste. La nouvelle liste comprend ainsi les données identitaires de toutes les unités composant le véhicule multi-unité. Alterna¬ tivement, le dispositif de génération d'identité susceptible de recevoir la première liste par un de ses connecteurs et la seconde liste par un autre de ses connecteurs est capable de choisir soit la première liste, soit la seconde liste, i.e. une seule des deux listes, afin de la transmettre vers un dispositif de génération d'identité situé en extrémité de la chaîne. Ainsi, malgré une génération de deux listes, une et une seule des deux listes est apte à se propager vers un et un seul dispositif de génération d'identité situé en extrémi¬ té de chaîne, destiné à prendre en charge la création de la liste complète des données identitaires de toutes les unités composant le véhicule multi-unité. Préférentiellement , le dispositif de génération d'identité ayant créé ladite nou¬ velle liste est de plus capable d'encapsuler ladite nouvelle liste dans ladite donnée de composition afin qu'elle soit transmise, notamment cycliquement , à au moins un calculateur, par exemple à tous les calculateurs équipant chacun des véhi¬ cules multi-unités , ou de préférence au calculateur maître 51 et à son redondant 53. In particular, in the case of an initialization of said list by each of the identity generation devices if ¬ killed at the end of the chain, ie a first initialization of a first list at one end of the string and a se ¬ initializing a second list at the other end of the chain, and a propagation of each of the two lists in an opposite direction in said string of Ge devices ¬ eration of identity, the identity Generator device capable of receiving the first list by one of its connectors and the second list by another of its connec ¬ tors is in particular able to create a new list comprising the elements of the first list, which is added first the identity data created by said device - generation tif capable of receiving the first and ¬ count list, and then the second list elements. The new list thus includes the identity data of all the units comprising the multi-unit vehicle. Alterna tively ¬, the Identity Generator device capable of receiving the first list by one of its connectors and the second list by another of its connectors is capable of selecting either the first list or the second list, ie only one of the two lists, in order to transmit it to an identity generation device located at the end of the chain. Thus, despite a generation of two lists, one and only one of the two lists is adapted to propagate towards one and only one Identity Generator device located extremi ¬ side chain, intended to support the creation of the list complete identity data of all the units composing the multi-unit vehicle. Preferably, the Identity Generator device that created said nou ¬ velle list is further capable of encapsulating said new list in said given composition so that it is transmitted, in particular cyclically, with at least one computer, for example to all the computers equipping each of the vehi cles ¬ multi-unit or preferably to the master computer 51 and its redundant 53.
Lorsque le premier véhicule multi-unité 1 et le second véhi- cule multi-unité 2 sont couplés l'un à l'autre pour former un nouveau véhicule multi-unité 3 comprenant les unités du se¬ cond véhicule multi-unité 2 attelées à la suite des unités du premier véhicule multi-unité 1, une procédure de reconfigura¬ tion automatique du système de pilotage du nouveau véhicule multi-unité 3 est automatiquement réalisable. When the first multi-unit vehicle 1 and the second multi-vehicle unit 2 are coupled to each other to form a new multi-unit vehicle 3 comprising the units are ¬ cond multi-unit vehicle 2 coupled to following the units of the first multi-unit vehicle 1, a reconfigured procedure ¬ tion automatic steering system for the new multi-unit vehicle 3 is automatically feasible.
En effet, lors d'un couplage de deux véhicules multi-unités l'un avec l'autre, les dispositifs de génération d'identité étant tous identiques et connectables les uns aux autres, il s'ensuit que les dispositifs de génération d'identité 41, 42, 43 du premier véhicule multi-unité 1 sont connectables aux dispositifs de génération d'identité 44, 45 du second véhi¬ cule multi-unité 2 afin de former une nouvelle chaîne de dis¬ positifs de génération d'identité composée de la première chaîne connectée à la seconde chaîne, et formant ainsi un nouveau dispositif de détermination de la composition du nou¬ veau véhicule multi-unité 3. Ce nouveau dispositif de déter¬ mination de la composition du nouveau véhicule multi-unité 3 est capable de déterminer automatiquement la composition du nouveau véhicule multi-unité 3 et de générer une donnée de composition encodant ladite composition du nouveau véhicule multi-unité 3. De même, lors du couplage d'un premier véhi¬ cule multi-unité 1 avec un second véhicule multi-unité 2, le premier réseau 81 et le second réseau 82 sont connectables l'un à l'autre afin de former un nouveau réseau 83, ledit nouveau réseau 83 étant une réunion du premier réseau 81 et du second réseau 82. Indeed, when a coupling of two multi-unit vehicles with each other, the identity generation devices being all identical and connectable to each other, it follows that the generation devices of ID 41, 42, 43 of the first multi-unit vehicle 1 can be connected to the ID generating devices 44, 45 of the second multi-vehi ¬ cule unit 2 to form a new channel of said positive ¬ composed identity Generator of the first channel connected to the second chain, thereby forming a new device for determining the composition of nou ¬ calf multi-unit vehicle 3. This new device deter ¬ mination of the composition of the new multi-unit vehicle 3 is capable automatically determining the composition of the new multi-unit vehicle 3 and generating a composition data encoding said composition of the new multi-unit vehicle 3. Similarly, when coupling a Emier vehi ¬ multi-cule unit 1 with a second multi-unit vehicle 2, the first network 81 and second network 82 are connectable to one another to form a new network 83, said new network 83 being a meeting of the first network 81 and the second network 82.
Le nouveau dispositif de détermination de la composition du nouveau véhicule multi-unité 3, formé des dispositifs de gé¬ nération d'identité du premier et du second véhicule multi- unité, est capable de transmettre via ledit nouveau réseau 83, ladite donnée de composition du nouveau véhicule multi- unité 3, à l'ensemble des calculateurs du nouveau véhicules multi-unités 3, notamment afin qu'au moins un module de sécu¬ risation reçoive ladite donnée de composition. En particu¬ lier, une fois cette donnée de composition acquise par les calculateurs 41 à 45 du nouveau véhicule multi-unité 3 et par les modules d'Entrées/Sorties 91 à 95 via ledit nouveau ré- seau 83, le calculateur maître 51 et son redondant 53 du pre¬ mier véhicule multi-unité 1, ainsi que le calculateur maître 54 et son redondant 55 du second véhicule multi-unité 2 sont capables, au moyen de leur module de sécurisation, de se dé¬ connecter des Entrées/Sorties des modules d'Entrées/Sorties auxquelles ils étaient connectés lorsque le premier et le se¬ cond véhicule mutli-unité étaient non couplés l'un à l'autre, i.e. indépendants. Avantageusement, chaque système de pilo¬ tage selon l'invention est capable, au moyen de ladite clé de déverrouillage transmise par leurs modules de sécurisation respectifs, de couper la connexion d'au moins un de ses cal¬ culateurs, en particulier de tous ses calculateurs, audit en¬ semble d'Entrées/Sorties dès détection d'une variation de la¬ dite donnée de composition. En particulier, le module de sécurisation du système de pilotage selon l'invention est capa- ble de détecter ladite variation de la donnée de composition et de couper la connexion d'au moins un calculateur avec ledit ensemble d'Entrées/Sorties, en particulier la connexion du calculateur maître et de son redondant, afin de permettre à un nouveau calculateur maître et à son redondant de prendre le contrôle desdites Entrées/Sorties en s'y connectant. Préférentiellement , un nouveau module de sécurisation 6, choisi par exemple en fonction de la donnée de composition du nouveau véhicule multi-unité 3, détermine ledit nouveau cal- culateur maître et son redondant. De préférence, le nouveau calculateur maître est situé à une extrémité du nouveau véhi¬ cule multi-unité 3, par exemple le calculateur 51, et son re¬ dondant à l'autre extrémité, par exemple le calculateur 55. Les autres calculateurs 52, 53, 54 du nouveau véhicule multi- unité 3 sont de préférence dans un état inactif. The new device for determining the composition of the new multi-unit vehicle 3, consisting of devices ¬ gen eration identity of the first and second multi-unit vehicle, is able to transmit via said new network 83, said data composition the new multi-vehicle unit 3, to all computers of the new multi-unit vehicle 3, in particular to at least one secu ¬ authorization module receives said given composition. In particu ¬ link, once this composition data acquired by the computers 41 to 45 of new multi-vehicle unit 3 and by the modules / O 91-95 via said new net- work 83, the master computer 51 and its redundant 53 pre ¬ Mier multi-unit vehicle 1, and the master computer 54 and its redundant 55 of the second multi-unit vehicle 2 are able, by their security module, to ¬ connect / O of I / O modules to which they were connected when the first and is ¬ cond mutli-unit vehicle were not coupled to each other, ie independent. Advantageously, each pilo ¬ tage system according to the invention is capable, by means of said unlocking key transmitted by their respective security modules, to cut the connection of at least one of its cal ¬ culators, especially all its calculators, auditing ¬ appear I / O as soon as detection of a variation of ¬ said composition data. In particular, the security module of the control system according to the invention is able to detect said variation of the composition data and to cut the connection of at least one computer with said set of inputs / outputs, in particular the connection of the master computer and its redundant, to allow a new master computer and its redundant to take control of said inputs / outputs by connecting. Preferably, a new security module 6, chosen for example according to the composition data of the new multi-unit vehicle 3, determines said new master computer and its redundant. Preferably, the new master computer is located at one end of the new vehi ¬ cule multi-unit 3, for example the computer 51, and re ¬ dondant at the other end, for example the computer 55. The other computers 52, 53, 54 of the new multi-unit vehicle 3 are preferably in an inactive state.
Le nouveau module de sécurisation 6 du système de pilotage du nouveau véhicule multi-unité 3 est ensuite capable, sur la base de ladite donnée de composition, de connecter au moins un calculateur, en particulier ledit nouveau calculateur maître et son redondant, à l'ensemble des Entrées/Sorties des modules d'Entrées/Sorties 91 à 95 du nouveau véhicule multi- unité 3. Dès que le module de sécurisation 6 est en mesure de valider une cohérence entre les Entrées/Sorties associées aux calculateurs et la donnée de composition, le système de pilo¬ tage du nouveau véhicule multi-unité 3 est apte à prendre le contrôle desdites Entrées/Sorties afin de commander les dis¬ positifs fonctionnels du nouveau véhicule multi-unité permet¬ tant son pilotage. The new security module 6 of the control system of the new multi-unit vehicle 3 is then able, on the basis of said composition data, to connect at least one computer, in particular said new master computer and its redundant, to the set of inputs / outputs of the I / O modules 91 to 95 of the new multi-unit vehicle 3. As soon as the security module 6 is able to validate a coherence between the inputs / outputs associated with the computers and the composition data the pilo system ¬ floor of the new multi-vehicle unit 3 is adapted to take control of said I / O for controlling the said functional ¬ positive the new multi-unit vehicle allows ¬ as his driving.
La Figure 4 permet aussi d'expliquer un scindage d'un véhi¬ cule multi-unité équipé d'un système de pilotage sécurisé se¬ lon l'invention. Lors du scindage d'un véhicule multi-unité, par exemple dudit nouveau véhicule multi-unité 3, en deux ou plusieurs autres véhicules multi-unités , par exemple en un premier véhicule multi-unité 1 et un second véhicule multi- unité 2, ladite nouvelle chaîne de dispositifs de génération d'identité dudit nouveau véhicule multi-unité formée des dis¬ positifs de génération d'identité 41 à 45 est rompue, séparée en deux parties, par exemple en ladite première chaîne de dispositifs de génération d'identité 41 à 43 du premier véhi¬ cule multi-unité 1, et en ladite seconde chaîne de disposi¬ tifs de génération d'identité 44, 45 du second véhicule mul¬ ti-unité 2. Pareillement, le réseau 83 du nouveau véhicule multi-unité 3 est séparé en un premier réseau 81 du premier véhicule multi-unité 1 et en un second réseau 82 dudit second véhicule multi-unité 2. Figure 4 also helps explain a scindage a vehi ¬ cule multi-unit equipped with a safety control system ¬ lon the invention. When splitting a multi-unit vehicle, for example of said new multi-unit vehicle 3, into two or more other multi-unit vehicles, for example into a first multi-unit vehicle 1 and a second multi-unit vehicle 2, said new identity generation device chain of said new multi-unit vehicle formed of the identity generating dis ¬ positives 41 to 45 is broken, separated into two parts, for example into said first chain of identity generation devices 41 to 43 of the first multi-unit vehi ¬ cule 1, and said second chain provi ¬ tive Identity Generator 44, 45 of the second vehicle ¬ mul ti-unit 2. Similarly, the network 83 of the new multi-unit vehicle 3 is separated into a first network 81 of the first multi-unit vehicle 1 and into a second network 82 of said second multi-unit vehicle 2.
Après scindage, chacune des deux parties de la chaîne de dis- positifs d'identité du nouveau véhicule multi-unité 3 est ca¬ pable de générer indépendamment et automatiquement une nou¬ velle donnée de composition caractérisant respectivement le premier véhicule multi-unité 1, et le second véhicule multi- unité 2. Comme précédemment avec le couplage de deux véhicu- les multi-unités , la nouvelle donnée de composition est en particulier capable de provoquer la génération par au moins un module de sécurisation de la clé de déverrouillage permet¬ tant une déconnexion de chacun des calculateurs, d'avec les Entrées/Sorties auxquelles ils étaient préalablement connecté dans la configuration dudit nouveau véhicule multi-unité 3.After scindage, each of the two parts of the positive dis- chain identity of the new multi-unit vehicle 3 is ca pable ¬ generate independently and automatically a given nou ¬ velle composition respectively characterizing the first multi-unit vehicle 1, and the second multi-unit vehicle 2. As previously with the coupling of two multi-unit vehicles, the new composition data is in particular able to cause generation by at least one security module of the unlocking key allows ¬ as a disconnection of each of the computers, with the inputs / outputs to which they were previously connected in the configuration of said new multi-unit vehicle 3.
Avantageusement, ladite clé de déverrouillage est susceptible d'être transmise à chaque module de sécurisation d'un système de pilotage sécurisé selon l'invention, afin que chaque mo¬ dule de sécurisation soit capable de déconnecter un calcula- teur de sa connexion avec au moins une Entrée/Sortie lors du¬ dit scindage. En particulier, la connexion du calculateur maître 51 et de son redondant 55 avec les Entrées/Sorties de leurs modules d'Entrées/Sorties 91 à 95 est apte à être cou¬ pée au moyen de ladite clé de déverrouillage apte à être fournie par le module de sécurisation, soit lors de ladite détection de la variation de la donnée de composition lors du scindage, soit lors d'un processus préalable de notification du scindage audit système de pilotage dudit nouveau véhicule multi-unité . Dans un autre cas de figure, notamment lorsque ledit scindage n'est pas notifié audit système de pilotage dudit nouveau vé¬ hicule multi-unité 3, et si le module de sécurisation 6 dé¬ tecte, avant d'avoir détecté ladite variation de ladite don- née de composition, une perte de connexion du calculateur maître avec les Entrées/Sorties du ou des modules d'En¬ trées/Sorties auxquelles il était préalablement connecté avant scindage, cette perte de connexion peut être interpré¬ tée par ledit module de sécurisation et le module d'En- trées/Sorties comme une défaillance pouvant en particulier résulter en une réinitialisation du message de confirmation. Cette réinitialisation du message de confirmation rendra possible la connexion d'un nouveau calculateur maître choisi après scindage pour chacun des premier et second véhicules multi-unités aux Entrées/Sorties des module d'Entrées/Sorties équipant leurs unités. Advantageously, said release key is likely to be transmitted to each security module via a safety control system according to the invention, so that each security ¬ mo dule is able to disconnect a calculators tor its connection with the least one entrance / exit when ¬ scindage said. In particular, the connection of the master computer 51 and its redundant 55 with the inputs / outputs of their I / O modules 91 to 95 is able to be cou ¬ pe by means of said unlocking key adapted to be provided by the security module, either during said detection of the variation of the composition data during the splitting, or during a prior process of notification of the splitting to said control system of said new multi-unit vehicle. In another case, in particular when said scindage is not notified to said control system said new vee ¬ multi-vehicle unit 3, and if the security module 6 ¬ detects, before said detected change in said Don-born composition master computer the connection loss with the inputs / outputs of the modules or of in ¬ Trees / O to which it was previously connected before scindage, the connection loss can be construed ¬ ted by said module securing and the Entry / Exit module as a failure which may in particular result in a reset of the confirmation message. This reset of the confirmation message will make it possible to connect a new master computer chosen after splitting for each of the first and second multi-unit vehicles to the inputs / outputs of the input / output modules equipping their units.
Par rapport à l'art antérieur pour lequel le calculateur maître est susceptible de tomber dans un état puits de sécurité lors de la détection d'une perte de connexion avec une partie des Entrées/Sorties des modules d'Entrées/Sorties des unités ayant été dételées, la présente invention permet, lors d'un scindage ou d'un couplage, de corréler automatiquement la nouvelle composition du véhicule multi-unité avec l'ensemble des Entrées/Sorties devant être prises en considération par le calculateur maître, de sorte qu'une perte d'une connexion du calculateur maître avec une partie de ses Entrées/Sorties ne résulte pas en une activation d'une procédure d'urgence du système de pilotage. With respect to the prior art for which the master computer is likely to fall into a safety sink state when detecting a loss of connection with a portion of the inputs / outputs of the input / output modules of the units having been uncoupled, the present invention makes it possible, during a splitting or a coupling, to automatically correlate the new composition of the multi-unit vehicle with all the inputs / outputs to be taken into consideration by the master computer, so that a loss of a connection of the master computer with a part of its inputs / outputs does not result in an activation of an emergency procedure of the control system.
Pour un véhicule multi-unité comprenant plusieurs unités au¬ tonomes, au moins un calculateur parmi l'ensemble des calcu- lateurs distribués sur le réseau dudit véhicule est apte à agir en tant que calculateur maître afin de piloter ledit véhicule et afin d'être associé directement, par connexion au¬ dit ensemble d'Entrées/Sorties, aux modules d'Entrées/Sorties dudit véhicule. Lorsque le calculateur agissant en tant que calculateur maître pilote ledit véhicule, les autres calcula¬ teurs dudit véhicule peuvent en particulier être en état de veille, de sorte que seul le calculateur identifié comme cal¬ culateur maître par le module de sécurisation commande le pi¬ lotage dudit véhicule, de préférence, le module de sécurisa- tion identifie le calculateur qu'il équipe comme calculateur maître . For a multi-unit vehicle comprising several units with ¬ tonomes, at least one calculator among all the calculators distributed on the network of said vehicle is suitable for act as a master computer to control said vehicle and to be directly associated, by connection to said ¬ I / O set, to the input / output modules of said vehicle. When the computer acting as said vehicle driver master computer, other calculated ¬ tors said vehicle can in particular be in the standby state, so that only the computer identified as cal ¬ culateur master by the security module controls the pi ¬ preferably, the security module identifies the computer that it equips as the master computer.
Finalement, la présente invention a permis de décrire un sys- tème de pilotage sécurisé capable de découvrir de manière au¬ tonome la composition d'un véhicule multi-unité tel un train, et de vérifier en sécurité la connexion correcte d'au moins un calculateur du système de pilotage avec un ensemble d'En¬ trées/Sorties de modules d'Entrées/Sorties distribués sur le réseau dudit véhicule multi-unité. Finally, the present invention allowed to describe a safety control sys- tem able to discover so ¬ tonome the composition of a multi-unit vehicle such as a train, and verify proper connection the safety of at least one the computer control system with a set of trees in ¬ / modules outputs I / O distributed on the network of said multi-unit vehicle.
La mise en sécurité du système de pilotage sécurisé est no¬ tamment réalisée en contrôlant, notamment cycliquement , la cohérence entre l'ensemble des Entrées/Sorties aptes à être connectées et verrouillées avec ledit calculateur et la com- position du véhicule multi-unité déduite de la donnée de com¬ position fournie par ledit dispositif de détermination de la composition du véhicule multi-unité. En particulier, des données de composition dudit véhicule multi-unité aptes à dé¬ crire un ensemble de caractéristiques des unités susceptibles de composer ledit véhicule multi-unité, et un ensemble de configurations possibles dudit véhicule multi-unité peuvent servir de référence au contrôle, notamment cyclique, de la cohérence entre l'ensemble des Entrées/Sorties aptes à être connectées et verrouillées avec ledit calculateur et la com- position du véhicule multi-unité. Avantageusement, la présente invention permet une validation de l'intégrité d'un véhicule multi-unité libre d'un recours à des informations de niveau applicatif, tel que la localisa¬ tion par exemple, et un apport d'une plus grande généricité de traitement grâce à un accès direct à l'ensemble des En¬ trées/Sorties du véhicule multi-unité et à la possibilité de centraliser les traitements logiciels liés à la sécurisation du système de pilotage sur un seul calculateur. En résumé, la méthode et le système de sécurisation d'un sys¬ tème de pilotage selon l'invention présentent plusieurs avan¬ tages par rapport aux méthodes et systèmes de pilotage exis¬ tant en ce que: Making safe the safety control system is no ¬ MENT achieved by controlling, in particular cyclically, the coherence between all input / output adapted to be connected and locked with said computer and com- position of the multi-unit vehicle deducted com position data provided by said device for determining the composition of the multi-unit vehicle. In particular, composition data from said multi-unit vehicle capable ¬ describe a set of characteristics of the units that compose said multi-unit vehicle, and a set of possible configurations of said multi-unit vehicle may be used as reference control, particularly cyclic, coherence between all the inputs / outputs able to be connected and locked with said computer and the composition of the multi-unit vehicle. Advantageously, the present invention allows a validation of the integrity of a free multi-unit vehicle from the use of application-level information, such as located it ¬ for example, and providing greater genericity treatment with direct access to all the trees ¬ in / out multi-unit vehicle and the ability to centralize software treatments related to the security of the control system on a single computer. In summary, the method and securing a sys tem control system ¬ according to the invention have several advan ¬ tages compared to exis control methods and systems ¬ as in that:
- ils permettent une indépendance de la sécurisation de la détermination de la composition d'un véhicule multi- unité: la détermination de la composition est indépendante de logiciels applicatifs portés par des calcula¬ teurs destinés au pilotage automatique; - they allow independence of securing the determination of the composition of a multi-unit vehicle, the determination of the composition is independent of application software carried by calculated ¬ tors for the autopilot;
- ils autorisent une modification dynamique de la composi- tion d'un train sans interruption du contrôle en sécurité de la composition dudit véhicule multi-unité;  they allow a dynamic modification of the composition of a train without interruption of the control in security of the composition of said multi-unit vehicle;
- ils permettent une utilisation en sécurité SIL4 du sys¬ tème de pilotage sécurisé, distribué et dynamiquement reconfigurable ; - they allow SIL4 safe use of the sys ¬ tem safety control, distributed and dynamically reconfigurable;
- le mécanisme de sécurisation et de priorisation permet une attribution exclusive de la connexion d'un ensemble d'Entrées/Sorties avec au moins un calculateur, en par¬ ticulier un seul calculateur, et permet d'associer en sécurité, directement un calculateur maître avec des sorties sécuritaire. Cela permet la réalisation d'une architecture distribuée dynamiquement reconfigurable, et donc une centralisation des données de fonctionnement et une plus grande souplesse de déploiement; - the securing and prioritization mechanism allows an exclusive assignment of the connection of a set of I / O with at least one computer, in par ticular ¬ a single computer, and is used to associate security, directly a master computer with safe exits. This allows the realization of a dynamically reconfigurable distributed architecture, and thus a centralization of operating data and greater flexibility of deployment;
- ils permettent de connaître en permanence la composition du véhicule multi-unité et un état de verrouillage des Entrées/Sorties avec le calculateur maître. Notamment, une actualisation de la donnée de composition est compa¬ tible avec la période d'émission du message de confirma¬ tion destiné à rafraîchir les Entrées/Sorties connectées au calculateur maître; - they make it possible to constantly know the composition of the multi-unit vehicle and a locking state of Inputs / Outputs with the master computer. In particular, an update of the composition data is compa ¬ tible with the transmission period of the confirmation message ¬ tion to refresh the inputs / outputs connected to the master computer;
la centralisation des informations vers un calculateur permet de simplifier la complexité du système de pilo¬ tage automatique et donc réduit la complexité de l'ana¬ lyse de sécurité. Le pilotage du véhicule multi-unité par un calculateur via les modules d'Entrées/Sorties est ainsi sécurisé; centralizing information to a computer simplifies the complexity of the pilosebaceous system ¬ automatic floor and reduces the complexity of the security ana ¬ lysis. The control of the multi-unit vehicle by a computer via the I / O modules is thus secure;
ils permettent l'ajout ou respectivement la suppression automatique d'une unité à ou respectivement d'un véhi¬ cule multi-unité. they allow the addition or respectively the automatic deletion of a unit or respectively a vehi ¬ multi-unit cule.

Claims

Revendications claims
Méthode de sécurisation d'un système de pilotage destiné à équiper et piloter un véhicule multi-unité caractérisée en ce que ladite méthode comprend:  Method for securing a control system for equipping and controlling a multi-unit vehicle characterized in that said method comprises:
- une détermination autonome d'une composition d'un véhicule multi-unité par un dispositif de détermina¬ tion de la composition dudit véhicule multi-unité corrélée à une génération d'une donnée de composi¬ tion dudit véhicule multi-unité; - an autonomous determination of a composition of a multi-unit vehicle determined by a device ¬ the composition of said multi-unit vehicle correlated to a generation of a given composi ¬ said multi-unit vehicle;
- une transmission de ladite donnée de composition à un ensemble d'éléments du système de pilotage, au moins un élément dudit ensemble d'éléments étant un calculateur (5) dudit système de pilotage;  a transmission of said composition datum to a set of elements of the control system, at least one element of said set of elements being a calculator (5) of said control system;
- une détermination, par ledit calculateur (5) et au moyen de ladite donnée de composition, d'un ensemble d'Entrées/Sorties d'au moins un module d'En¬ trée/Sortie (91) destiné à équiper le véhicule mul¬ ti-unité; - a determination, by said computer (5) and by means of said data composition of a set of inputs / outputs of at least one module tree ¬ / output (91) for equipping the vehicle mul ¬ ti-unit;
- une connexion de chaque élément dudit ensemble d'éléments audit ensemble d'Entrées/Sorties.  a connection of each element of said set of elements to said set of Inputs / Outputs.
Méthode selon revendication 1, caractérisée en ce que ledit ensemble d'éléments comprend un groupe de calcula¬ teurs . Method according to Claim 1, characterized in that said assembly of elements comprises a group of calculated ¬ tors.
Méthode selon revendication 2, caractérisée par un mécanisme de sécurisation et de priorisation de la connexion d'au moins un calculateur (5) dudit groupe de calcula¬ teurs avec ledit ensemble d'Entrées/Sorties. Method according to claim 2, characterized by a securing mechanism and prioritization of connecting at least one computer (5) of said calculated group ¬ tors with said set of inputs / outputs.
Méthode selon revendication 3, caractérisée en ce que ledit mécanisme de sécurisation et priorisation comprend une génération d'un jeton d'association codé apte à verrouiller ladite connexion d'au moins un calculateur (5) dudit groupe de calculateurs avec ledit ensemble d'En¬ trées/Sorties, et une génération d'une clé de déver¬ rouillage apte à déverrouiller ladite connexion d'au moins un calculateur (5) dudit groupe de calculateurs avec ledit ensemble d'Entrées/Sorties. Method according to claim 3, characterized in that said security and prioritization mechanism comprises a generation of an encoded association token capable of locking said connection of at least one computer (5) said computers of said set of group ¬ Trees In / Out, and generating a key Dever ¬ rusting adapted to unlock said connection of at least one computer (5) of said calculators group with said set of inputs /Exits.
Méthode selon une des revendications 1 à 4, caractérisée par une vérification cyclique ou suffisamment fréquente d'une cohérence entre la connexion de chaque élément du¬ dit ensemble d'éléments avec ledit ensemble d'En¬ trées/Sorties et ladite donnée de composition. Method according to one of claims 1 to 4, characterized by a cyclic or sufficiently frequent verification of consistency between the connection of each element of said set of elements ¬ with said set of trees ¬ In / Out and said given composition.
Méthode selon une des revendications 1 à 5, caractérisée en ce que ladite détermination autonome comprend un ajout successif et ordonné à une liste, selon un ordre de composition dudit véhicule multi-unité, d'au moins une donnée identitaire de chaque unité (1, 2, 3) dudit véhicule multi-unité de façon à ce qu'un ordre de suc¬ cession des données identitaires comprises dans ladite liste soit corrélable à l'ordre de composition des uni¬ tés (1, 2, 3) dudit véhicule multi-unité, chaque donnée identitaire étant spécifique à une unique unité (1, 2, 3) du véhicule multi-unité, et ladite liste étant apte à être encapsulée dans ladite donnée de composition. Method according to one of claims 1 to 5, characterized in that said autonomous determination comprises a successive and ordered addition to a list, according to a composition order of said multi-unit vehicle, of at least one piece of identity data of each unit (1, 2, 3) of said multi-unit vehicle so that an order of suc ¬ transfer of identity data included in said list is correlatable to the order of composition uni ¬ tees (1, 2, 3) of said multi vehicle unit, each identity datum being specific to a single unit (1, 2, 3) of the multi-unit vehicle, and said list being able to be encapsulated in said composition datum.
Système de pilotage sécurisé d'un véhicule multi-unité, caractérisé en ce que ledit système comprend: Secure driving system of a multi-unit vehicle, characterized in that said system comprises:
- un dispositif de détermination d'une composition du véhicule multi-unité, capable de déterminer de manière autonome ladite composition du véhicule multi-unité et de générer une donnée de composi¬ tion corrélable à ladite composition dudit véhi¬ cule multi-unité; - a device for determining a composition of the multi-unit vehicle, capable of determining autonomously the composition of the multi-unit vehicle and generate a data composi ¬ correlated to said composition of said multi-unit vehi ¬ cule;
- au moins un calculateur (5) comprenant au moins un module de sécurisation (6), ledit calculateur (5) étant destiné à équiper au moins une unité (1, 2, 3) du véhicule multi-unité, chaque calculateur étant connectable au moyen d'au moins une at least one computer (5) comprising at least one security module (6), said computer (5) being intended to equip at least one unit (1, 2, 3) of the multi-unit vehicle, each computer being connectable by means of at least one
connexion et via un réseau (8), d'une part à un ensemble d'Entrées/Sorties de modules d'En¬ trées/Sorties (91) destinés à équiper une ou plu¬ sieurs unités (1, 2, 3), et d'autre part audit dispositif de détermination de la composition du véhicule multi-unité, afin d'échanger via chaque module d'Entrées/Sorties (91) des données de fonc¬ tionnement de l'unité (1, 2, 3) et/ou du véhicule multi-unité, et afin d'acquérir dudit dispositif de détermination, une donnée de composition dudit véhicule multi-unité; connection and via a network (8), on the one hand to a set of inputs / outputs of modules In ¬ Trees / outputs (91) intended to equip one or rained ¬ eral units (1, 2, 3), and secondly to said device for determining the composition of the multi-unit vehicle, in order to exchange via each Input / Output module (91) data ¬ func tioning of the unit (1, 2, 3) and / or the multi-unit vehicle, and in order to acquire from said determination device, a composition data of said multi-unit vehicle;
- ledit module de sécurisation (6) dynamique de la¬ dite connexion de chaque calculateur (5) avec ledit ensemble d'Entrées/Sorties, ledit module de sécurisation (6) étant capable de déterminer, à partir de ladite donnée de composition, ledit en¬ semble d'Entrées/Sorties susceptibles d'être connectées à chaque calculateur (5), de connecter chaque calculateur (5) audit ensemble d'Entrées sorties, et de contrôler une cohérence entre cha¬ que connexion de chaque calculateur (5) audit ensemble d'Entrées/Sorties. - said security module (6) dynamics ¬ said connecting each computer (5) with said set of inputs / outputs, said security module (6) being capable of determining, from said given composition, said in ¬ appear of Inputs / Outputs likely to be connected to each computer (5), to connect each calculator (5) to said set of Inputs outlets, and to control a coherence between cha ¬ that connection of each calculator (5) auditing set of Inputs / Outputs.
Système de pilotage selon revendication 7, caractérisé en ce qu'il comprend un groupe de calculateurs, et en ce que le module de sécurisation (6) est capable de priori- ser la connexion d'un seul calculateur (5) dudit groupe de calculateurs audit ensemble d'Entrées/Sorties. Control system according to claim 7, characterized in that it comprises a group of computers, and in that the security module (6) is capable of prioritizing the connection of a single computer (5) of said group of computers auditing set of Inputs / Outputs.
Système de pilotage selon une des revendications 7 ou 8, caractérisé en ce que le module de sécurisation (6) com¬ prend un module de verrouillage capable de verrouiller chaque connexion du calculateur (5) avec chacune des Entrées/Sorties dudit ensemble d'Entrées/Sorties. Control system according to one of claims 7 or 8, characterized in that the security module (6) com ¬ takes a locking module capable of locking each computer connection (5) with each of the inputs / outputs of said set of inputs / outputs.
Système de pilotage selon la revendication 8, caractérisé en ce que ledit module de verrouillage comprend un générateur de jeton d'association codé apte à générer un jeton d'association codé afin de verrouiller chaque connexion dudit calculateur (5) avec chacune des Entrées/Sorties dudit ensemble d'Entrées/Sorties et une clé de déverrouillage apte à déverrouiller au moins une connexion dudit calculateur (5) avec au moins une des Entrées/Sorties dudit ensemble d'Entrées/Sorties. Control system according to Claim 8, characterized in that the said locking module comprises an encoded association token generator capable of generating an encoded association token in order to lock each connection of the said computer (5) with each of the inputs / outputs. said set of Inputs / Outputs and an unlocking key adapted to unlock at least one connection of said computer (5) with at least one of the inputs / outputs of said set of inputs / outputs.
Système de pilotage selon une des revendications 7 à 10, caractérisé en ce que le dispositif de détermination d'une composition du véhicule multi-unité comprend au moins un dispositif de génération d'identité (4), chaque dispositif de génération d'identité (4) du dispositif de détermination étant destiné à équiper une unité du véhicule multi-unité, chaque dispositif de génération d'identité (4) étant capable de générer une donnée iden¬ titaire de l'unité (1, 2, 3) qu'il est destiné à équi¬ per . Steering system according to one of claims 7 to 10, characterized in that the device for determining a composition of the multi-unit vehicle comprises at least one identity generating device (4), each identity generating device ( 4) of the determination device being intended to equip a unit of the multi-unit vehicle, each identity generation device (4) being able to generate data iden ¬ titular unit (1, 2, 3) that it is intended to equi ¬ per.
Dispositif de génération d'identité (4) destiné à per¬ mettre une détermination d'une composition d'un véhicule multi-unité comprenant au moins une unité (1, 2, 3), le dispositif de génération d'identité (4) destiné à équi¬ per une unité (1, 2, 3) du véhicule multi-unité étant caractérisé en ce qu'il comprend: Identity Generator device (4) for per ¬ to determining a composition of a multi-unit vehicle, comprising at least one unit (1, 2, 3), the Identity Generator device (4) intended to equi ¬ a unit (1, 2, 3) of the multi-unit vehicle being characterized in that it comprises:
- un générateur de données identitaires capable de gé¬ nérer une donnée identitaire de l'unité (1, 2, 3) que le dispositif de génération d'identité est des¬ tiné à équiper, ladite donnée identitaire étant des- tinée à permettre une identification de ladite unité ( 1 , 2 , 3 ) ; - an identity data generator able to gen erate ¬ an identity data of the unit (1, 2, 3) that the Identity Generator device of ¬ Tine equip said identity data being des- designed to allow identification of said unit (1, 2, 3);
- un détecteur de connexion apte à détecter une présence ou une absence de couplage dudit dispositif de génération d'identité (4) avec au moins un autre dispositif de génération d'identité (4);  a connection detector capable of detecting a presence or absence of coupling of said identity generating device (4) with at least one other identity generating device (4);
- un générateur de liste capable de créer une liste d'éléments destinée à comprendre des éléments aptes à être ordonnés et ajoutés successivement;  a list generator capable of creating a list of elements intended to include elements able to be ordered and added successively;
- un composant de sérialisation capable d'ajouter un autre élément à ladite liste, soit à la suite d'un dernier élément d'une liste d'éléments ordonnables successivement destinée à être réceptionnée par le¬ dit dispositif de génération d'identité, soit comme premier élément de la liste d'éléments susceptible d'être créée par le générateur de liste, ledit autre élément comprenant ladite donnée identitaire; - a serialization component capable of adding another element to said list, or as a result of a last item in a list of orderable elements successively to be received by the said ¬ ID generation device or as the first element of the list of elements that can be created by the list generator, said other element comprising said identity data item;
- un transmetteur de liste capable de transmettre la¬ dite liste d'éléments comprenant ledit autre élément soit à un autre dispositif de génération d'identité (4), soit à au moins un calculateur (5) du véhicule multi-unité après encapsulation de ladite liste dans une donnée de composition dudit véhicule multi- unité . - a list of transmitter capable of transmitting ¬ said list of items comprising said other member is another Identity Generator device (4) or at least one computer (5) of the multi-unit vehicle after encapsulation said list in a composition data of said multi-unit vehicle.
Dispositif selon revendication 12, caractérisé en ce que ledit générateur de liste est capable de créer cyclique- ment ou suffisamment fréquemment ladite liste. Apparatus according to claim 12, characterized in that said list generator is capable of cyclically or frequently creating said list.
Dispositif selon une des revendication 12 à 13, caracté¬ risé en ce que le dispositif de génération d'identité (4) comprend au moins deux connecteurs, respectivement un premier et un second connecteur, chacun destiné au couplage dudit dispositif de génération d'identité (4) avec un autre dispositif de génération d'identité (4) . Device according to one of claims 12 to 13, characterized ¬ in that the identity generation device (4) comprises at least two connectors, respectively a first and a second connector, each intended for coupling said identity generating device (4) with another identity generating device (4).
Dispositif selon la revendication 14, caractérisé en ce que ledit générateur de données identitaires est capable de générer une donnée de polarisation capable d'autoriser la transmission de ladite liste d'éléments au moyen d'un seul des deux connecteurs. Device according to claim 14, characterized in that said identity data generator is capable of generating polarization data capable of authorizing transmission of said list of elements by means of only one of the two connectors.
EP11757325.3A 2010-11-23 2011-09-15 Method for securing a control system of a reconfigurable multi-unit vehicle, and secured control system Active EP2643198B1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
EP11757325.3A EP2643198B1 (en) 2010-11-23 2011-09-15 Method for securing a control system of a reconfigurable multi-unit vehicle, and secured control system

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
EP10290624 2010-11-23
PCT/EP2011/066032 WO2012069223A1 (en) 2010-11-23 2011-09-15 Method for securing a control system of a reconfigurable multi-unit vehicle, and secured control system
EP11757325.3A EP2643198B1 (en) 2010-11-23 2011-09-15 Method for securing a control system of a reconfigurable multi-unit vehicle, and secured control system

Publications (2)

Publication Number Publication Date
EP2643198A1 true EP2643198A1 (en) 2013-10-02
EP2643198B1 EP2643198B1 (en) 2017-11-01

Family

ID=44651808

Family Applications (1)

Application Number Title Priority Date Filing Date
EP11757325.3A Active EP2643198B1 (en) 2010-11-23 2011-09-15 Method for securing a control system of a reconfigurable multi-unit vehicle, and secured control system

Country Status (9)

Country Link
US (1) US8755957B2 (en)
EP (1) EP2643198B1 (en)
KR (1) KR20130140743A (en)
CN (1) CN103313902A (en)
BR (1) BR112013012848B1 (en)
CA (1) CA2818605A1 (en)
ES (1) ES2658184T3 (en)
HU (1) HUE037885T2 (en)
WO (1) WO2012069223A1 (en)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
FR2992620B1 (en) * 2012-06-27 2014-08-15 Alstom Transport Sa TRAIN AND METHOD FOR DETERMINING THE COMPOSITION OF SUCH A SAFETY TRAIN
AT515454A3 (en) * 2013-03-14 2018-07-15 Fts Computertechnik Gmbh Method for handling errors in a central control unit and control unit
CN108163012B (en) * 2017-12-27 2019-12-03 卡斯柯信号有限公司 It is a kind of that Train Dynamic is supported even to hang the control method that reconciliation is compiled
CN109441280B (en) * 2018-09-12 2020-07-14 南京康尼机电股份有限公司 Safety circuit of SI L4 safety-level rail vehicle door controller and control method thereof
CN113194472B (en) * 2021-03-31 2023-03-31 新华三技术有限公司成都分公司 AGV wireless access method, vehicle-mounted equipment, network equipment and storage medium

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6144900A (en) * 1998-04-17 2000-11-07 General Electric Company Automatic serialization of an array of wireless nodes based on coupled oscillator model
DE19929644C2 (en) * 1999-06-28 2002-02-21 Deutsche Bahn Ag System for initializing trains based on a data communication system, in which all communication participants have access to the information in the initialization phase
US8037204B2 (en) * 2005-02-11 2011-10-11 Cisco Technology, Inc. Method and system for IP train inauguration
DE102006018163B4 (en) 2006-04-19 2008-12-24 Siemens Ag Method for automatic address assignment
KR101110497B1 (en) 2007-11-30 2012-02-08 미쓰비시덴키 가부시키가이샤 Train formation recognition system and train formation recognition apparatus
GB2461386B (en) * 2007-12-21 2010-06-09 Nomad Spectrum Ltd Establishing a wireless connection between component vehicles where order/orientation information is used to issue instructions to components

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
None *
See also references of WO2012069223A1 *

Also Published As

Publication number Publication date
CA2818605A1 (en) 2012-05-31
ES2658184T3 (en) 2018-03-08
KR20130140743A (en) 2013-12-24
CN103313902A (en) 2013-09-18
US8755957B2 (en) 2014-06-17
HUE037885T2 (en) 2018-09-28
BR112013012848B1 (en) 2020-10-20
WO2012069223A1 (en) 2012-05-31
EP2643198B1 (en) 2017-11-01
US20130245865A1 (en) 2013-09-19
BR112013012848A2 (en) 2016-08-23

Similar Documents

Publication Publication Date Title
EP2643198A1 (en) Method for securing a control system of a reconfigurable multi-unit vehicle, and secured control system
EP2679466B2 (en) Method for safely determining the composition of a train
WO2014122099A1 (en) Method for routing data, computer program, network controller and network associated therewith
EP2629203A1 (en) Method of electing an active master device from two redundant master devices
EP0520877B1 (en) Method and device for managing information transmission over mains applied to a domestic network
EP2149823A1 (en) Onboard avionics system having dynamic reconfiguration and corresponding method and airplane having such a sytem onboard
EP1349078B1 (en) Installation, gateway and method for loading information between on-board equipments on an aeroplane and off-board loading means
FR2990784A1 (en) COMMUNICATION MEMBER OF A MULTI-STATE CAN FD TYPE COMMUNICATION NETWORK COMPATIBLE WITH CAN HS TYPE COMMUNICATION DEVICES
EP1304836B1 (en) Deterministic field bus and management method thereof
EP1647112B1 (en) Data transmission method and device
WO2013011101A1 (en) Information transmission network and corresponding network node
US20030187994A1 (en) Methods, systems, and computer program products for communicating using a hybrid physical network
FR3030162A1 (en) METHOD FOR EXCHANGING DIGITAL DATA FRAMES AND ASSOCIATED COMMUNICATION SYSTEM
EP3198462B1 (en) Transmission of synchronous data via a serial data bus, in particular a spi bus
FR3067192B1 (en) ELECTRONIC APPARATUS COMPRISING TWO MEMORIES AND ASSOCIATED PAIRING METHOD
EP2783485A1 (en) Data transmission network and programmable network node
FR3082960A1 (en) ELECTRONIC ARCHITECTURE OF MOTOR VEHICLE WITH REDUNDANCY OF POWER SUPPLY AND INTER-COMPUTER COMMUNICATION NETWORKS.
FR3093831A1 (en) Device for and method of data transmission
FR3002394A1 (en) ARCHITECTURE FOR TRANSMITTING INFORMATION WITH A BRIDGE, IN PARTICULAR FOR APPLICATION TO THE AIRCRAFT
US20220263662A1 (en) Techniques for updating a software component
EP4026292A1 (en) Unidirectional data transfer system and corresponding method
EP4057190A1 (en) Simplified client and associated architectures for delegating quantum calculations to a quantum server
WO2014124923A1 (en) Data transmission architecture, in particular for use in on-board avionics
FR2753551A1 (en) METHOD AND DEVICE FOR SYNCHRONIZING THE OPERATION OF AT LEAST TWO COMPUTERS OF AN ELECTRONIC SYSTEM ON BOARD ON BOARD OF A MOTOR VEHICLE
KR20200055450A (en) Key management system and method for vehicle cyber security

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20130408

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

DAX Request for extension of the european patent (deleted)
RAP1 Party data changed (applicant data changed or rights of an application transferred)

Owner name: SIEMENS S.A.S.

RAP1 Party data changed (applicant data changed or rights of an application transferred)

Owner name: SIEMENS S.A.S.

GRAP Despatch of communication of intention to grant a patent

Free format text: ORIGINAL CODE: EPIDOSNIGR1

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: GRANT OF PATENT IS INTENDED

INTG Intention to grant announced

Effective date: 20170502

RIN1 Information on inventor provided before grant (corrected)

Inventor name: CHENU, ERIC

GRAS Grant fee paid

Free format text: ORIGINAL CODE: EPIDOSNIGR3

GRAA (expected) grant

Free format text: ORIGINAL CODE: 0009210

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE PATENT HAS BEEN GRANTED

AK Designated contracting states

Kind code of ref document: B1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

REG Reference to a national code

Ref country code: GB

Ref legal event code: FG4D

Free format text: NOT ENGLISH

REG Reference to a national code

Ref country code: CH

Ref legal event code: EP

Ref country code: AT

Ref legal event code: REF

Ref document number: 941725

Country of ref document: AT

Kind code of ref document: T

Effective date: 20171115

REG Reference to a national code

Ref country code: IE

Ref legal event code: FG4D

Free format text: LANGUAGE OF EP DOCUMENT: FRENCH

REG Reference to a national code

Ref country code: DE

Ref legal event code: R096

Ref document number: 602011042929

Country of ref document: DE

REG Reference to a national code

Ref country code: NL

Ref legal event code: MP

Effective date: 20171101

REG Reference to a national code

Ref country code: ES

Ref legal event code: FG2A

Ref document number: 2658184

Country of ref document: ES

Kind code of ref document: T3

Effective date: 20180308

REG Reference to a national code

Ref country code: LT

Ref legal event code: MG4D

REG Reference to a national code

Ref country code: AT

Ref legal event code: MK05

Ref document number: 941725

Country of ref document: AT

Kind code of ref document: T

Effective date: 20171101

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: SE

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: LT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: NO

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20180201

Ref country code: NL

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: AT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: LV

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: RS

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: BG

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20180201

Ref country code: GR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20180202

Ref country code: IS

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20180301

Ref country code: HR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: EE

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: DK

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: CY

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: CZ

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: SK

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

REG Reference to a national code

Ref country code: DE

Ref legal event code: R097

Ref document number: 602011042929

Country of ref document: DE

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: PL

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: SM

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: IT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

Ref country code: RO

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

PLBE No opposition filed within time limit

Free format text: ORIGINAL CODE: 0009261

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT

REG Reference to a national code

Ref country code: FR

Ref legal event code: PLFP

Year of fee payment: 8

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

REG Reference to a national code

Ref country code: HU

Ref legal event code: AG4A

Ref document number: E037885

Country of ref document: HU

26N No opposition filed

Effective date: 20180802

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: SI

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

REG Reference to a national code

Ref country code: DE

Ref legal event code: R119

Ref document number: 602011042929

Country of ref document: DE

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MC

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

REG Reference to a national code

Ref country code: CH

Ref legal event code: PL

GBPC Gb: european patent ceased through non-payment of renewal fee

Effective date: 20180915

REG Reference to a national code

Ref country code: BE

Ref legal event code: MM

Effective date: 20180930

REG Reference to a national code

Ref country code: IE

Ref legal event code: MM4A

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: LU

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20180915

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: IE

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20180915

Ref country code: DE

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20190402

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: CH

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20180930

Ref country code: LI

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20180930

Ref country code: BE

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20180930

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: GB

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20180915

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: TR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

REG Reference to a national code

Ref country code: ES

Ref legal event code: PC2A

Owner name: SIEMENS MOBILITY SAS

Effective date: 20200507

REG Reference to a national code

Ref country code: HU

Ref legal event code: FH1C

Free format text: FORMER REPRESENTATIVE(S): SBGK SZABADALMI UEGYVIVOEI IRODA, HU

Representative=s name: SBGK SZABADALMI UEGYVIVOEI IRODA, HU

Ref country code: HU

Ref legal event code: GB9C

Owner name: SIEMENS MOBILITY SAS, FR

Free format text: FORMER OWNER(S): SIEMENS S.A.S., FR

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: PT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

REG Reference to a national code

Ref country code: FI

Ref legal event code: PCE

Owner name: SIEMENS MOBILITY SAS

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MK

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20171101

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: AL

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171101

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: FI

Payment date: 20230920

Year of fee payment: 13

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: FR

Payment date: 20230918

Year of fee payment: 13

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: ES

Payment date: 20231218

Year of fee payment: 13

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: HU

Payment date: 20231122

Year of fee payment: 13