EP3448735B1 - Dispositif serveur exécutant un logiciel de commande d'une fonction d'un système sur rail de protection du transport - Google Patents
Dispositif serveur exécutant un logiciel de commande d'une fonction d'un système sur rail de protection du transport Download PDFInfo
- Publication number
- EP3448735B1 EP3448735B1 EP17720733.9A EP17720733A EP3448735B1 EP 3448735 B1 EP3448735 B1 EP 3448735B1 EP 17720733 A EP17720733 A EP 17720733A EP 3448735 B1 EP3448735 B1 EP 3448735B1
- Authority
- EP
- European Patent Office
- Prior art keywords
- software
- server
- server device
- processes
- srv
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 claims description 145
- 230000008569 process Effects 0.000 claims description 129
- 238000007726 management method Methods 0.000 claims description 5
- 238000007405 data analysis Methods 0.000 claims description 2
- 238000011156 evaluation Methods 0.000 claims description 2
- 238000013508 migration Methods 0.000 claims 1
- 230000005012 migration Effects 0.000 claims 1
- FFBHFFJDDLITSX-UHFFFAOYSA-N benzyl N-[2-hydroxy-4-(3-oxomorpholin-4-yl)phenyl]carbamate Chemical compound OC1=C(NC(=O)OCC2=CC=CC=C2)C=CC(=C1)N1CCOCC1=O FFBHFFJDDLITSX-UHFFFAOYSA-N 0.000 description 15
- 238000004364 calculation method Methods 0.000 description 11
- 230000006870 function Effects 0.000 description 9
- 238000000926 separation method Methods 0.000 description 7
- 238000012360 testing method Methods 0.000 description 4
- 238000011161 development Methods 0.000 description 2
- 238000010586 diagram Methods 0.000 description 2
- 238000005286 illumination Methods 0.000 description 2
- 230000003137 locomotive effect Effects 0.000 description 2
- 238000012423 maintenance Methods 0.000 description 2
- 238000012545 processing Methods 0.000 description 2
- 238000004422 calculation algorithm Methods 0.000 description 1
- 230000007547 defect Effects 0.000 description 1
- 230000001934 delay Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 230000010354 integration Effects 0.000 description 1
- 230000007257 malfunction Effects 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 230000011664 signaling Effects 0.000 description 1
- 230000000007 visual effect Effects 0.000 description 1
Images
Classifications
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B61—RAILWAYS
- B61L—GUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
- B61L19/00—Arrangements for interlocking between points and signals by means of a single interlocking device, e.g. central control
- B61L19/06—Interlocking devices having electrical operation
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B61—RAILWAYS
- B61L—GUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
- B61L27/00—Central railway traffic control systems; Trackside control; Communication systems specially adapted therefor
- B61L27/30—Trackside multiple control systems, e.g. switch-over between different systems
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B61—RAILWAYS
- B61L—GUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
- B61L19/00—Arrangements for interlocking between points and signals by means of a single interlocking device, e.g. central control
- B61L19/06—Interlocking devices having electrical operation
- B61L2019/065—Interlocking devices having electrical operation with electronic means
Definitions
- the invention relates to a server device operating a software for controlling a function of a rail-bound transport securing system, the software operating at least two processes physically separate from one another, the results of which are compared with one another in order to carry out the control of the function.
- Rail-bound transport security systems are increasingly automated via computers.
- the aim is to ensure a high degree of reliability, availability, maintainability and safety of persons (so-called RAMS requirements; R eliability A vailability M aintainability S afety).
- RAMS requirements R eliability A vailability M aintainability S afety
- software errors programming errors
- hardware errors in particular the failure of individual components, such as transistors
- Such hardware faults must be identified in good time so that rail-bound transport security does not endanger people (locomotive drivers, passengers) and preferably not valuable resources (locomotives, wagons) or cargo.
- Software from the field of rail-bound transport security systems is usually installed on individual devices where the physical separation of processes can be easily ensured.
- the software and the device architecture are suitably coordinated.
- the virtualization of applications means that the provision of individual devices can be dispensed with in many cases, and software development and integration are also simplified.
- the virtualization of a train control system is, for example, in the WO 2015/126529 A1 been proposed.
- the EP 1 085 415 A2 which is considered to be the closest prior art, discloses a program module and a method for increasing the security of a software-controlled system, in particular an electronic signal box for railway signaling technology.
- a computer network comprising computers R8, R9, R10, R11 and a comparator V3 is used.
- the computers R8 and R9 are connected in series, and the computers R10 and R11 are connected in series.
- the computers R10 and R11 are connected in parallel to the computers R8 and R9.
- the first program part of a program module is installed on computers R8 and R10, and the second program part of the program module is installed on computers R9 and R11. Both computers R8 and R10 receive the same input data.
- the output data of the computers R9 and R11 are checked by the comparator V3; a route is only enabled if the output data of the computers R9 and R11 match.
- the US 2003/0018927 A1 describes a cluster server system with high availability.
- the cluster comprises several physical servers / individual servers referred to as “nodes”.
- One or more software programs, called “virtual servers”, run on each node. If a node fails, an affected virtual server is transferred to another node.
- the invention has for its object to provide a server device in which an improved availability of a software application can be guaranteed with high operational reliability of train traffic.
- the invention makes the increased availability in server clusters accessible to a software application, but on the other hand ensures that processes whose results have to be compared with one another in order to maintain operational security run physically separate from one another.
- the server device used to operate the software is set up with at least two server clusters.
- Each of the server clusters of the server device comprises at least two individual servers allow each other to migrate processes in the event of a single server failure (high availability cluster). This ensures high availability (operational readiness).
- the software is split into at least two parts, which are distributed among the at least two server clusters. Part of the software, and thus one of the processes, is permanently assigned to one of the server clusters.
- the processes, the results of which are compared can be special test processes that run in addition to the control function of the software application (such as the calculation of check digits / checksums), or main processes that are themselves used for the control function (such as the calculation of a track diagram).
- the processes to be compared with one another perform the same arithmetic operations in the same order in order to obtain the respective process result (identical processes).
- the same process results generally indicate that the server device is functioning correctly; uneven process results generally indicate a malfunction.
- One of the processes whose results are to be compared is, for example, a master process and a second process a slave process. If the result of the slave process deviates from the previously determined result of the master process, the status of the software application is set to "not safe” (unsafe) (for example by the software part of the master process and / or the software part of the Slave process and / or another software part for the comparison process), and none the results of the processes become more familiar. In the case of an interlocking application, for example, all of the signals concerned can be set to "Halt" as a precaution.
- Virtualization makes it possible to operate the software largely independently of any local, available hardware. In particular, it is easily possible to exchange individual components (such as individual servers within one of the server clusters).
- the software is a signal box application. Due to the architecture of the server device according to the invention, a high level of security, as is usually required for interlocking applications, can be guaranteed. The high availability is also advantageous in order to avoid or minimize delays in the operational flow of train traffic.
- the software is an application for operating the user interface of a computer-controlled signal box, in particular with a functionality for connecting mobile devices Operator terminals.
- HIS HIS server application
- MPT m obile p ossession t erminal
- HHT h and h eld t erminal
- the server architecture according to the invention has proven particularly useful in this application. Calculated track diagrams can be used here as the processes to be compared and their results, which are displayed on operator terminals, in particular mobile operator terminals (such as tablet computers). Since the user can temporarily assume responsibility for the release of track sections, a high security standard should be available here, which the invention can offer
- the software is a train protection application. Due to the architecture of the server device according to the invention, a high level of security, as is also usually required for train protection applications, can be guaranteed. Train protection applications can include, for example, emergency braking systems when passing "stop" signals.
- An embodiment is also advantageous in which the software is set up according to safety integrity level 2 (SIL2) or higher.
- This security level SIL2 is sufficient for many applications of rail-based transport security systems, and is easy to achieve with the server architecture according to the invention, while an increased availability can be made possible at the same time.
- the safety integrity level (SIL) is determined in accordance with EN 61508 (in particular EN 50128 and EN 50129) in the version valid on April 4th, 2016.
- the software can be a HIS server application, for example.
- SIL4 safety integrity level 4
- EN 61508 in particular EN 50128 and EN 50129
- RBC Radio Block Center
- SCM s afe c ommunication m odule
- An embodiment is also advantageous in which the software operates exactly two processes, physically separated from one another, on exactly two different server clusters.
- the setup of two server clusters for only two (in a respective test process) two processes to be compared is comparatively easy to set up, but increases security considerably while at the same time being highly available.
- the server device comprises three physically separate server clusters
- the software comprises at least three parts that are installed on different ones of the server clusters, so that the software operates three processes on different ones of the three server clusters, and that the Results of the processes are evaluated as part of a 2-out-of-3 decision for the control of the function of the rail-bound transport securing system.
- the 2-out-of-3 decision it is possible to identify correct process results even if one hardware fails (here an error on one of the server clusters), which further increases availability.
- the server device controls at least one further software for controlling a further function of a operates rail-bound transport securing system, and that the at least one additional software is installed and operated on only one of the server clusters.
- the respective additional software is not broken down into different parts that have to be installed on different server clusters; this significantly simplifies the operation of the other software.
- the other software is typically set up according to SILO.
- one or more individual, further software applications are typically installed and operated on each of the server clusters.
- the present invention is based on the distribution of processes of a software control of a rail-bound transport security system in a virtual operating level to different server clusters.
- the processes can be migrated to the individual servers in their server cluster to ensure high availability in the event of the failure of individual individual servers.
- the processes are similar and the results of the processes are compared for security purposes.
- the distribution of the processes across different server clusters ensures that the processes always run on different individual servers, so that individual hardware errors lead to different process results that can easily be uncovered in the course of security checks.
- HIS Human machine interface for Interlocking Systems
- SIL2 Safety Integrity Level 2
- CENELEC EN 50128 CENELEC EN 50128 standard. It essentially has the function of the user interface of an electronic signal box (ESTW) and can be designed in different forms for different markets or applications in order to take into account particular characteristics.
- ESTW electronic signal box
- HIS server which essentially serves to supply connected operator terminals with the calculated illuminations or states of the signal box elements.
- the HIS architecture In order to meet the requirements of SIL2 from the EN 50128 standard, the HIS architecture must be designed in such a way that the master process and a slave process run on different (hardware) processors. With multi-core processors, this can be achieved by firmly binding the processes to certain processor cores (core binding; processor affinity). This ensures that a computing error in a processor (or a processor core) can never lead to the same, wrong result in the master and slave processes (simultaneous double errors are excluded from the standard).
- server clusters can be formed from server computers (individual servers), which offer the advantages of a virtual operating level (high availability, redundancy) and at the same time ensure a physical separation of processes.
- server computers individual servers
- the master process can run on one server cluster and the slave process on the other server cluster. While it cannot be predicted which processor (core) in the server cluster is currently being used by a process, it can be excluded that the processes on the different server clusters will ever use the same processor (core).
- FIG. 1 A first embodiment of a server device 1 according to the invention with two server clusters SC1, SC2 will be described in more detail.
- the server device 1 is also referred to as a virtual cluster.
- the server device 1 here includes a first server cluster SC1 and a second server cluster SC2, which are spatially separated from one another, which is shown in FIG Fig. 1 is illustrated by a physical limit 2.
- spatially separated it is meant that the server computers (SRV) of the two server clusters SC1, SC2 do not consist of the same hardware, but are separate computers.
- the spatial separation can thus be carried out both by building the server clusters SC1, SC2 in the same frame in a server room or in different frame in the same or different server rooms, as well as at different locations with a distance of several kilometers.
- the limiting factor for the maximum distance between the server clusters SC1, SC2 is the speed and latency of the network in between for the synchronization of the server clusters SC1, SC2.
- Network connections are in Fig. 1 represented by simple connecting lines.
- first server cluster SC1 at least two server computers (individual servers) SRV-1-1, SRV-1-2 are combined to form a cluster.
- second server cluster SC2 at least two server computers (individual servers) SRV-2-1, SRV-2-2 are also combined to form a cluster.
- the server device 1 has a common cluster control 18 and a common storage control 19 for both server clusters SC1, SC2.
- Each server cluster SC1, SC2 has its own high availability control (HA) 20a, 20b, with which processes of the applications between the individual computers SRV-1-1, SRV-1-2 or SRV-2-1, SRV-2-2 can be moved within the respective server cluster SC1 or SC2, especially if a defect should occur in a single computer.
- HA high availability control
- each server cluster SC1, SC2 each has its own storage (Storage Vol 1, Storage Vol2) 21a, 21b, which can be used by the individual servers of the respective cluster SC1, SC2.
- the HIS server software 11 is divided into two parts: the HIS master process 11a is implemented on the first server cluster SC1, and the HIS slave process 11b (which is identical to the HIS master process 11a) implemented on the second server cluster SC2.
- the HIS master process 11a will therefore always run on one of the individual servers SRV-1-1 or SRV-1-2 of the first server cluster SC1, but not on the individual servers of the second server cluster SC2.
- the HIS slave process 11b will always run on one of the individual servers SRV-2-1 or SRV-2-2 of the second server cluster SC2, but not on the individual servers of the first server cluster SC1. This ensures that the HIS master process 11a and the HIS slave process 11b are always physically separate from one another. If the process results match, the matching process result can be trusted.
- the similar processes 12a and 12b of the interlocking control software 12 are physically separated from one another, and the similar processes 13a and 13b of the train protection control software 13 are physically separated from one another; in the case of matching process results, the matching process result can in turn be trusted.
- the other software applications 14, 15, 16, 17 or their processes here are each without a similar counterpart to the other server clusters SC1, SC2, so they are only carried out simply on one of the server clusters SC1, SC2. This is primarily intended for non-safety-related applications.
- FIG. 2 An embodiment of a server device (virtual cluster) 30 according to the invention is shown, which has three server clusters SC1, SC2, SC3.
- the structure of the server device 30 with three server clusters SC1, SC2, SC3 largely corresponds to the structure with two server clusters of Fig. 1 , so that only the main differences are explained below.
- a criterion for approval according to the EN 50128 standard for the 2oo3 systems is that the individual processes run on different hardware. This can be ensured by the server device 30 according to the invention (virtual cluster), which is based on three server clusters SC1, SC2, SC3 separated by physical limits 2.
- the interlocking application processes for example, run embedded in a virtual machine VM distributed over the three server clusters and thus never use the same processors or processor cores.
- the safety standard according to SIL4 can also be achieved with 2003 systems.
- the similar processes 31a, 31b, 31c or associated parts of the operating software 31 are distributed among the three server clusters SC1, SC2, SC3, so that the processes 31a, 31b, 31c are never on the same processor or run on the same hardware, and thus their process results cannot be wrong in the same way due to a single hardware fault.
Landscapes
- Engineering & Computer Science (AREA)
- Mechanical Engineering (AREA)
- Hardware Redundancy (AREA)
- Train Traffic Observation, Control, And Security (AREA)
- Safety Devices In Control Systems (AREA)
Claims (10)
- Dispositif serveur (1 ; 30) exploitant un logiciel pour commander une fonction d'un système de sécurité des transports ferroviaires, dans lequel le logiciel (11, 12, 13 ; 31, 32, 33) exploite au moins deux processus (11a-11b ; 12a-12b ; 13a-13b ; 31a-31c ; 32a-32c ; 33a-33c) physiquement séparés l'un de l'autre, dont les résultats sont comparés entre eux pour effectuer la commande de la fonction,
caractérisé en ce
que le logiciel (11, 12, 13 ; 31, 32, 33) est exploité à un niveau d'exploitation virtuel du dispositif serveur (1 ; 30),
que le dispositif serveur (1 ; 30) comprend au moins deux grappes de serveurs physiquement séparées l'une de l'autre (SC1, SC2, SC3), chacune des grappes de serveurs (SC1, SC2, SC3) du dispositif serveur (1 ; 30) comprenant au moins deux serveurs individuels (SRV-1-1, SRV-1-2, SRV-2-1, SRV-2-2, SRV-3-1, SRV-3-2) qui permettent entre eux une migration de processus (11a-11b ; 12a-12b ; 13a-13b ; 31a-31c ; 32a-32c ; 33a-33c) en cas de défaillance d'un serveur individuel (SRV-1-1, SRV-1-2, SRV-2-1, SRV-2-2, SRV-3-1, SRV-3-2),
lesdits au moins deux processus (11a-11b ; 12a-12b ; 13a-13b ; 31a-31c ; 32a-32c ; 33a-33c) s'exécutant sur des machines virtuelles (VM),
et que le logiciel (11, 12, 13 ; 31, 32, 33) comprend au moins deux parties qui sont installées sur des grappes de serveurs différentes parmi lesdites au moins deux grappes de serveurs (SC1, SC2, SC3), de sorte que lesdits au moins deux processus (11a-11b ; 12a-12b ; 13a-13b ; 31a-31c ; 32a-32c ; 33a-33c) sont exploités sur des grappes de serveurs différentes parmi lesdites au moins deux grappes de serveurs (SC1, SC2, SC3). - Dispositif serveur (1 ; 30) selon la revendication 1, caractérisé en ce que le logiciel (11, 12, 13 ; 31, 32, 33) est une application de poste d'aiguillage.
- Dispositif serveur (1 ; 30) selon la revendication 2, caractérisé en ce que le logiciel (11, 12, 13 ; 31, 32, 33) est une application pour l'exploitation de l'interface utilisateur d'un poste d'aiguillage commandé par ordinateur, en particulier avec une fonctionnalité permettant la connexion de terminaux d'exploitation mobiles.
- Dispositif serveur (1 ; 30) selon la revendication 1, caractérisé en ce que le logiciel (11, 12, 13 ; 31, 32, 33) est une application de protection des trains.
- Dispositif serveur (1 ; 30) selon l'une des revendications précédentes, caractérisé en ce que le logiciel (11, 12, 13 ; 31, 32, 33) est conçu selon le niveau d'intégrité de sécurité 2 (SIL2) ou supérieur.
- Dispositif serveur (1 ; 30) selon l'une des revendications précédentes, caractérisé en ce que le logiciel (11, 12, 13 ; 31, 32, 33) est conçu selon le niveau d'intégrité de sécurité 4 (SIL4).
- Dispositif serveur (1 ; 30) selon l'une des revendications 1 à 6, caractérisé en ce que le logiciel (11, 12, 13) exploite exactement deux processus (11a-11b ; 12a-12b ; 13a-13b), physiquement séparés l'un de l'autre, sur exactement deux grappes de serveurs différentes (SC1, SC2).
- Dispositif serveur (1 ; 30) selon l'une des revendications 1 à 7, caractérisé en ce que le dispositif serveur (30) comprend trois grappes de serveurs (SC1, SC2, SC3) physiquement séparées les unes des autres, que le logiciel (31, 32, 33) comprend au moins trois parties qui sont installées sur des grappes de serveurs différentes parmi les grappes de serveurs (SC1, SC2, SC3), de sorte que le logiciel (31, 32, 33) exploite trois processus (31a-31c ; 32a-32c ; 33a-33c) sur différentes grappes de serveurs parmi les trois grappes de serveurs (SC1, SC2 ; SC3), et que les résultats des processus (31a-31c ; 32a-32c 33a-33c) sont évalués dans le cadre d'une décision 2 sur 3 pour la commande de la fonction du système de sécurité des transports ferroviaires.
- Dispositif serveur (1 ; 30) selon l'une des revendications précédentes, caractérisé en ce que le dispositif serveur (1 ; 30) exploite au moins un autre logiciel (14-17 ; 34-39) pour commander une autre fonction d'un système de sécurité des transports ferroviaires, et que ledit au moins un autre logiciel (14-17 ; 34-39) est installé et exploité sur une seule des grappes de serveurs (SC1, SC2, SC3).
- Dispositif serveur (1 ; 30) selon la revendication 9, caractérisé en ce que ledit au moins un autre logiciel (14-17 ; 34-39) comprend une ou plusieurs des applications logicielles suivantes :- système de planification des horaires, en particulier Aramis-D ;- système de gestion des numéros de train et de commande des trains, en particulier ARAMIS-C ;- système d'analyse des données et de métriques (Business Intelligence) ;- système de maintenance des trains (Maintenance Centre) ;- système d'acquisition et de contrôle des données des trains (Checkpoint Master Node) ;- système d'acquisition et d'évaluation des composants d'exploitation (Service Management Tool).
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PL17720733T PL3448735T3 (pl) | 2016-04-25 | 2017-04-24 | Urządzenie serwerowe obsługujące oprogramowanie do sterowania funkcją szynowego systemu bezpieczeństwa transportu |
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
DE102016206988.8A DE102016206988A1 (de) | 2016-04-25 | 2016-04-25 | Servereinrichtung betreibend eine Software zur Steuerung einer Funktion eines schienengebundenen Transportsicherungssystems |
PCT/EP2017/059631 WO2017186629A1 (fr) | 2016-04-25 | 2017-04-24 | Dispositif serveur exécutant un logiciel de commande d'une fonction d'un système sur rail de protection du transport |
Publications (2)
Publication Number | Publication Date |
---|---|
EP3448735A1 EP3448735A1 (fr) | 2019-03-06 |
EP3448735B1 true EP3448735B1 (fr) | 2020-04-29 |
Family
ID=58664667
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
EP17720733.9A Active EP3448735B1 (fr) | 2016-04-25 | 2017-04-24 | Dispositif serveur exécutant un logiciel de commande d'une fonction d'un système sur rail de protection du transport |
Country Status (8)
Country | Link |
---|---|
EP (1) | EP3448735B1 (fr) |
DE (1) | DE102016206988A1 (fr) |
DK (1) | DK3448735T3 (fr) |
ES (1) | ES2795015T3 (fr) |
PL (1) | PL3448735T3 (fr) |
PT (1) | PT3448735T (fr) |
SA (1) | SA518400293B1 (fr) |
WO (1) | WO2017186629A1 (fr) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2023020807A1 (fr) * | 2021-08-18 | 2023-02-23 | Siemens Mobility GmbH | Détection et correction automatiques d'erreurs de mémoire dans un ordinateur multicanal sécurisé |
Families Citing this family (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109783103B (zh) * | 2019-03-19 | 2021-04-16 | 北京邮电大学 | 一种轨道交通列控系统人机界面实现方法和装置 |
WO2021048772A1 (fr) | 2019-09-12 | 2021-03-18 | Thales Canada Inc. | Dispositif de protection contre la survitesse |
Family Cites Families (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US6243825B1 (en) * | 1998-04-17 | 2001-06-05 | Microsoft Corporation | Method and system for transparently failing over a computer name in a server cluster |
DE19942981A1 (de) * | 1999-09-09 | 2001-03-22 | Alcatel Sa | Programmodul und Verfahren zum Erhöhen der Sicherheit eines softwaregesteuerten Systems |
US6944785B2 (en) * | 2001-07-23 | 2005-09-13 | Network Appliance, Inc. | High-availability cluster virtual server system |
EP2884392B1 (fr) * | 2013-12-13 | 2018-08-15 | Thales | Architecture tolérante aux fautes basée sur une triple redondance logicielle |
US9718487B2 (en) | 2014-02-18 | 2017-08-01 | Nabil N. Ghaly | Method and apparatus for a train control system |
-
2016
- 2016-04-25 DE DE102016206988.8A patent/DE102016206988A1/de not_active Withdrawn
-
2017
- 2017-04-24 PT PT177207339T patent/PT3448735T/pt unknown
- 2017-04-24 DK DK17720733.9T patent/DK3448735T3/da active
- 2017-04-24 ES ES17720733T patent/ES2795015T3/es active Active
- 2017-04-24 PL PL17720733T patent/PL3448735T3/pl unknown
- 2017-04-24 WO PCT/EP2017/059631 patent/WO2017186629A1/fr active Application Filing
- 2017-04-24 EP EP17720733.9A patent/EP3448735B1/fr active Active
-
2018
- 2018-10-23 SA SA518400293A patent/SA518400293B1/ar unknown
Non-Patent Citations (1)
Title |
---|
None * |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2023020807A1 (fr) * | 2021-08-18 | 2023-02-23 | Siemens Mobility GmbH | Détection et correction automatiques d'erreurs de mémoire dans un ordinateur multicanal sécurisé |
Also Published As
Publication number | Publication date |
---|---|
DE102016206988A1 (de) | 2017-10-26 |
WO2017186629A1 (fr) | 2017-11-02 |
ES2795015T3 (es) | 2020-11-20 |
DK3448735T3 (da) | 2020-06-22 |
PL3448735T3 (pl) | 2020-11-02 |
PT3448735T (pt) | 2020-07-07 |
EP3448735A1 (fr) | 2019-03-06 |
SA518400293B1 (ar) | 2021-10-21 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
DE102009054157B3 (de) | Steuerungssystem zum Steuern von sicherheitskritischen und nichtsicherheitskritischen Prozessen | |
EP2445771B1 (fr) | Procede de creation d'un poste d'aiguillage electronique pour remplacer un poste d'aiguillage existant | |
EP3448735B1 (fr) | Dispositif serveur exécutant un logiciel de commande d'une fonction d'un système sur rail de protection du transport | |
EP1860564A1 (fr) | Procédé et dispositif destinés à l'échange de données sur la base du protocole de communication OPC entre des composants redondants d'un système d'automatisation | |
DE19509150C2 (de) | Verfahren zum Steuern und Regeln von Fahrzeug-Bremsanlagen sowie Fahrzeug-Bremsanlage | |
DE102017109886A1 (de) | Steuerungssystem zum Steuern von sicherheitskritischen und nichtsicherheitskritischen Prozessen mit Master-Slave-Funktionalität | |
DE102018118243A1 (de) | Techniken zur Bereitstellung eines abgesicherten Steuerungsparameters zur mehrkanaligen Steuerung einer Maschine | |
DE102005023296B4 (de) | Zugbeeinflussungssystem | |
EP3201774B1 (fr) | Système informatique en temps réel réparti et unité de répartition à commande temporelle | |
DE102006012042A1 (de) | Steuervorrichtung zur fehlersicheren Steuerung einer Maschine | |
DE10053023C1 (de) | Verfahren zum Steuern eines sicherheitskritischen Bahnbetriebsprozesses und Einrichtung zur Durchführung dieses Verfahrens | |
EP2868547A1 (fr) | Architecture de poste d'aiguillage et de commande pour voies ferrées | |
DE202005016151U1 (de) | Einrichtung zur Fernsteuerung eines Relais-Stellwerks unter Verwendung von hochverfügbaren diversitären Steuerungen | |
EP2279480B1 (fr) | Procédé et système de surveillance d'un système relatif à la sécurité | |
DE102013223101A1 (de) | Bahnübergangssicherungssystem | |
EP0473834B1 (fr) | Système de commande d'un poste d'aiguillage électronique organisé suivant le principe de commande à ordinateur local | |
EP2864845B1 (fr) | Reconfiguration automatisée d'un circuit de réglage à événements discrets | |
EP3565752B1 (fr) | Commutation entre contrôleurs d'éléments pendant le fonctionnement d'une voie de chemin de fer | |
EP4160845B1 (fr) | Système de démarrage contrôlé et de fonctionnement d'un bus d'énergie redondant | |
WO2011113405A1 (fr) | Groupement d'appareils de commande | |
DE102005049217A1 (de) | Verfahren und Einrichtung zur Fernsteuerung eines Relais-Stellwerks unter Verwendung von hochverfügbaren Steuerungen | |
CH654260A5 (en) | Computer-controlled signal box | |
EP3172671B1 (fr) | Procédé de traitement de données en parallèle dans un système de calcul comportant une pluralité d'unités de calcul et système de calcul comportant une pluralité d'unités de calcul | |
DE19531923B4 (de) | Einrichtung zur Realisierung von safe-life-Funktionen | |
DE102006029851A1 (de) | Sicheres Verfahren für sicherheitsrelevante Eingaben |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
17P | Request for examination filed |
Effective date: 20181126 |
|
AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
AX | Request for extension of the european patent |
Extension state: BA ME |
|
DAV | Request for validation of the european patent (deleted) | ||
DAX | Request for extension of the european patent (deleted) | ||
GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: GRANT OF PATENT IS INTENDED |
|
INTG | Intention to grant announced |
Effective date: 20191212 |
|
GRAS | Grant fee paid |
Free format text: ORIGINAL CODE: EPIDOSNIGR3 |
|
GRAA | (expected) grant |
Free format text: ORIGINAL CODE: 0009210 |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE PATENT HAS BEEN GRANTED |
|
AK | Designated contracting states |
Kind code of ref document: B1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
REG | Reference to a national code |
Ref country code: GB Ref legal event code: FG4D Free format text: NOT ENGLISH |
|
REG | Reference to a national code |
Ref country code: CH Ref legal event code: EP |
|
REG | Reference to a national code |
Ref country code: DE Ref legal event code: R096 Ref document number: 502017005029 Country of ref document: DE |
|
REG | Reference to a national code |
Ref country code: AT Ref legal event code: REF Ref document number: 1262873 Country of ref document: AT Kind code of ref document: T Effective date: 20200515 |
|
REG | Reference to a national code |
Ref country code: IE Ref legal event code: FG4D Free format text: LANGUAGE OF EP DOCUMENT: GERMAN |
|
REG | Reference to a national code |
Ref country code: CH Ref legal event code: NV Representative=s name: RIEDERER HASLER AND PARTNER PATENTANWAELTE AG, CH |
|
REG | Reference to a national code |
Ref country code: DK Ref legal event code: T3 Effective date: 20200617 |
|
REG | Reference to a national code |
Ref country code: PT Ref legal event code: SC4A Ref document number: 3448735 Country of ref document: PT Date of ref document: 20200707 Kind code of ref document: T Free format text: AVAILABILITY OF NATIONAL TRANSLATION Effective date: 20200630 |
|
REG | Reference to a national code |
Ref country code: NO Ref legal event code: T2 Effective date: 20200429 |
|
REG | Reference to a national code |
Ref country code: NL Ref legal event code: MP Effective date: 20200429 |
|
REG | Reference to a national code |
Ref country code: LT Ref legal event code: MG4D |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: IS Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200829 Ref country code: FI Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: SE Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: LT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: GR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200730 |
|
REG | Reference to a national code |
Ref country code: ES Ref legal event code: FG2A Ref document number: 2795015 Country of ref document: ES Kind code of ref document: T3 Effective date: 20201120 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: BG Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200729 Ref country code: HR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: LV Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: RS Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: NL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: AL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: SM Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: EE Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 Ref country code: CZ Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
REG | Reference to a national code |
Ref country code: DE Ref legal event code: R097 Ref document number: 502017005029 Country of ref document: DE |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: SK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
PLBE | No opposition filed within time limit |
Free format text: ORIGINAL CODE: 0009261 |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT |
|
26N | No opposition filed |
Effective date: 20210201 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: SI Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: MC Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: LU Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20210424 |
|
REG | Reference to a national code |
Ref country code: BE Ref legal event code: MM Effective date: 20210430 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: IE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20210424 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: BE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20210430 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: CY Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: HU Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT; INVALID AB INITIO Effective date: 20170424 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: MK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |
|
PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: GB Payment date: 20240314 Year of fee payment: 8 |
|
PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: PL Payment date: 20240326 Year of fee payment: 8 Ref country code: IT Payment date: 20240326 Year of fee payment: 8 Ref country code: FR Payment date: 20240321 Year of fee payment: 8 |
|
PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: DE Payment date: 20240319 Year of fee payment: 8 |
|
PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: DK Payment date: 20240411 Year of fee payment: 8 |
|
PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: CH Payment date: 20240501 Year of fee payment: 8 |
|
PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: ES Payment date: 20240509 Year of fee payment: 8 |
|
PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: AT Payment date: 20240326 Year of fee payment: 8 |
|
P01 | Opt-out of the competence of the unified patent court (upc) registered |
Free format text: CASE NUMBER: APP_35446/2024 Effective date: 20240613 |
|
PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: RO Payment date: 20240412 Year of fee payment: 8 Ref country code: NO Payment date: 20240409 Year of fee payment: 8 |
|
PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: PT Payment date: 20240415 Year of fee payment: 8 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: MT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20200429 |