EP3652920A1 - Verfahren und vorrichtung für ein signaltechnisch sicheres system - Google Patents
Verfahren und vorrichtung für ein signaltechnisch sicheres systemInfo
- Publication number
- EP3652920A1 EP3652920A1 EP18753076.1A EP18753076A EP3652920A1 EP 3652920 A1 EP3652920 A1 EP 3652920A1 EP 18753076 A EP18753076 A EP 18753076A EP 3652920 A1 EP3652920 A1 EP 3652920A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- safe
- fail
- signal
- secure
- computing unit
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B61—RAILWAYS
- B61L—GUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
- B61L27/00—Central railway traffic control systems; Trackside control; Communication systems specially adapted therefor
- B61L27/30—Trackside multiple control systems, e.g. switch-over between different systems
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/10—Protocols in which an application is distributed across nodes in the network
Definitions
- the invention relates to a method for increasing a computing power of a fail-safe system and to a corresponding signal-technically secure system.
- safe signaling is to be understood in the context of the present invention in accordance with relevant industry standards, such as IEC 61508.
- Signaling Safety is usually achieved by carrying out redundant calculations. Redundancy may be at the hardware or software level. It is also possible to provide redundancy at hardware and software level.
- SIL safety requirements or safety integration levels
- processors were developed with multiple CPU cores working in parallel. This can be effective for conventional use, but not if a fail-safe calculation must be ensured. Because multi-core processors unite the CPU cores on a chip with shared memory and are therefore not suitable for fail-safe calculations without further measures.
- Signal-wise secure computers e.g. in railway engineering, in aircraft construction, or in power plant engineering, consist of two or more separate, independent computers that monitor each other.
- the object is to provide a fail safe Sys tem ⁇ with increased computing power.
- a fail safe system is provided riding loading
- the invention which comprises a first safe for signaling purposes Re ⁇ unit area and at least one coupled to the first fail-safe processing unit signally second si ⁇ chere computing unit.
- the first signally Siche ⁇ re computing unit and the at least one second secure processing unit signally this case each comprise signal ⁇ technically safe input and output units.
- Examples of safe signaling input and output units eg in the Railway technology, are a safe relay output, a Baiisenempftuler, or various train buses.
- the method according to the invention for increasing a computing performance of a fail-safe system basically comprises the following steps:
- Provision of a first fail-safe computing unit which technically safe input and output units comprises, and coupling the first signal-saving processor with at least one second secure signal processing unit, which also signal technically si ⁇ chere input and output units, to a fail-safe system .
- the basic idea of the invention is thus to discrete single fail-safe computing units as fail-safe components discrete to a fail-safe system analogous to a multi-core computer, the respective fail-safe input and output hardware of the respective computing units can be used directly.
- the invention offers a number of advantages:
- the signal-technically safe input and output capacities required for the fail-safe system bring intrinsically the signal-processing units used to construct this system. It is therefore no longer necessary to add a separate fail-safe input and output computer.
- Signaling-safe computing units such as the first and second arithmetic units used according to the invention, are known per se from the prior art. However, these are used there individually, and are specially designed for the lower Preisseg ⁇ ment. If one then uses a combination of such secure signal processing units with signal technology safe input and output units, the Divide tasks to be managed security processes on these multiple computing units. Application-specific required safe input and output units (eg sensors / actuators) can then be partially mounted to the system where they are needed.
- the computing power of the resulting fail-safe system can be precisely scaled by the number of such fail-safe computing units.
- the fail-safe processing units may be small computers that have roughly the computing power of a currently handelsüb ⁇ union smartphones.
- the first fail-safe computing unit and the at least one second fail-safe computing unit each satisfy a predetermined security requirement level, for example a security requirement level according to Standard 61508 of the International Electrotechnical Commission, particularly preferably the security requirement level SIL-4.
- signaltech ⁇ cally safe system of the invention particularly preferably satisfies a predetermined safety requirement level, for example, a safety requirement level according to the 61508 standard of the International Electrotechnical Commission, the safety integrity level SIL. 4
- a predetermined safety requirement level for example, a safety requirement level according to the 61508 standard of the International Electrotechnical Commission, the safety integrity level SIL. 4
- the first signal-technically safe processing unit and the at least one second secure processing unit signally formed standardized ⁇ Siert. This can ensure that the coupling of the individual fail-safe computing units to the fail-safe system can be done easily and without any adaptation effort.
- the first fail-safe computing unit and the at least one second fail-safe computing unit are preferably coupled such that they form a local area network (LAN).
- a coupling can be done for example via I 2 C, Ethernet or SPI.
- Alternative types of Kop ⁇ peins, for example, a parallel coupling or proprietary solutions are possible.
- Secure input units or secure output units of the first fail-safe computing unit or the at least one second fail-safe computing unit can also be arranged application-specifically to the fail-safe system. In this way, the fail-safe system is optimal and adaptable to the respective use with minimal effort.
- the term "or” can also be understood as inclusive "or”.
- a safe for signaling purposes input unit of the signal ⁇ technically secure processing units may for example be designed as a sensor.
- a signal technically safe output unit of one of the signal-technically secure computing units to be designed as an actuator.
- the computing power of the signal-technically secure system can be scaled by the number of second signal-technically secure arithmetic units coupled to the first signal processing-safe computing unit. It is thereby possible Anlagenpas by simple coupling or decoupling individual ones of the second fail-safe processing units, the capacity of the fail-safe system ⁇ sen.
- fractions of a secure application to be executed on the fail-safe system e.g. individual so-called “tasks", to which the first signal processing-safe computing unit and the at least one second fail-safe computing unit are distributed, without losses due to virtualization or emulation.
- FIG. 3 shows a preferred embodiment of a method according to the invention for increasing the computing power of a fail-safe system.
- FIG. 1 shows a signal-technically safe system 50 according to the prior art.
- the system 50 includes a conventional multi-core personal computer 20. On the processor cores run diverse emulators 30, 31. Different shares
- the system 50 includes a connection 11 with the personnel for secure input and output Computer 20 coupled fail-safe input and output computer 15 with fail-safe input and output units 12, 13.
- a preferred embodiment of a signal ⁇ technically secure system 60 is shown according to the present invention.
- the inventive system 60 comprises a first safe for signaling purposes computing unit 10 signally Siche ⁇ re input and output units 12, including 13, and at least one with the first fail-safe processing unit 10 via a coupling 11, 111 coupled second signal technically secure arithmetic unit 110 which likewise includes signal input secure input and output units 112, 113.
- the fail-safe system 60 may include a plurality of second secure signaling units 110, 210, 310, which are directly or indirectly coupled to the first fail-safe computing unit 10, for example in a so-called "local area network Also, individual ones of the second fail-safe computing units 110, 210, 310 can be coupled directly to each other (not shown).
- the fail-safe computing units 10, 110, 210, 310 correspond to the safety requirement level SIL-4 according to IEC61508.
- Individual components A and B, 40, 41 of a redundant calculation to ⁇ nenden application can thereby be distributed to different ones of the signal-technically safe ⁇ computing units 10, 110th
- the fail-safe processing units 10, 110, 210, 310 are standardized in the example shown trained and can therefore overall without technical problems, and decoupled ⁇ to, making the computing power of the fail-safe system 60 is substantially exactly with the number of signal ⁇ technically safe Arithmetic units 10, 110, 210, 310 are scaled.
- FIG. 3 shows by way of example steps of a preferred embodiment of a method for increasing the computing power of a fail-safe system.
- a first safe for signaling purposes arithmetic unit almost as output system 10 provides simplifiege ⁇ which signally safe inputs and Ausgabeein- units 12, comprises. 13
- the first signal technically secure arithmetic unit is coupled to at least a second signal ⁇ fail-safe processing unit 110 10, which likewise safe for signaling purposes input and output units 112, comprises 113th
- a signal technology Siche ⁇ res system 60 is formed, which provides a computing power ⁇ that is substantially the sum of the processing power of the coupled signal-related processing units 10, corresponds to the 110th
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Health & Medical Sciences (AREA)
- Computing Systems (AREA)
- General Health & Medical Sciences (AREA)
- Medical Informatics (AREA)
- Mechanical Engineering (AREA)
- Safety Devices In Control Systems (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102017214992.2A DE102017214992A1 (de) | 2017-08-28 | 2017-08-28 | Signaltechnisch sicheres System |
| PCT/EP2018/070151 WO2019042666A1 (de) | 2017-08-28 | 2018-07-25 | Verfahren und vorrichtung für ein signaltechnisch sicheres system |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3652920A1 true EP3652920A1 (de) | 2020-05-20 |
Family
ID=63168367
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP18753076.1A Withdrawn EP3652920A1 (de) | 2017-08-28 | 2018-07-25 | Verfahren und vorrichtung für ein signaltechnisch sicheres system |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP3652920A1 (de) |
| DE (1) | DE102017214992A1 (de) |
| WO (1) | WO2019042666A1 (de) |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE10011887B4 (de) * | 2000-03-07 | 2004-09-02 | Siemens Ag | Verfahren zur signaltechnisch sicheren Übermittlung von Daten zwischen signaltechnisch sicheren Rechnern sowie Einrichtung hierzu |
| DE10053023C1 (de) * | 2000-10-13 | 2002-09-05 | Siemens Ag | Verfahren zum Steuern eines sicherheitskritischen Bahnbetriebsprozesses und Einrichtung zur Durchführung dieses Verfahrens |
| DE102014206078A1 (de) * | 2014-03-31 | 2015-10-01 | Siemens Aktiengesellschaft | Ersatz-Ressource für einen defekten Rechnerkanal eines Schienenfahrzeugs |
-
2017
- 2017-08-28 DE DE102017214992.2A patent/DE102017214992A1/de not_active Withdrawn
-
2018
- 2018-07-25 WO PCT/EP2018/070151 patent/WO2019042666A1/de not_active Ceased
- 2018-07-25 EP EP18753076.1A patent/EP3652920A1/de not_active Withdrawn
Also Published As
| Publication number | Publication date |
|---|---|
| WO2019042666A1 (de) | 2019-03-07 |
| DE102017214992A1 (de) | 2019-02-28 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE102008044018B4 (de) | Verfahren zum Bestimmen einer Sicherheitsstufe und Sicherheitsmanager | |
| EP3291094A1 (de) | Prozessorsystem und verfahren zur überwachung von prozessoren | |
| EP2246756B1 (de) | Verfahren und Bediengerät zum Bedienen einer sicherheitsgerichteten industriellen Automatisierungskomponente | |
| EP2605096B1 (de) | Sicherheitsgerichtete Steuerung in Kombination mit Cloud-Computing | |
| DE69727293T2 (de) | Geteilte busarchitektur für anwendungen mit unterschiedlichen integritätsanforderungsstufen | |
| EP1743225B1 (de) | Redundantes automatisierungssystem umfassend ein master- und ein stand-by-automatisierungsgerät | |
| EP3088976B1 (de) | Verfahren zum betreiben einer automatisierungseinrichtung und automatisierungseinrichtung | |
| EP3448735B1 (de) | Servereinrichtung betreibend eine software zur steuerung einer funktion eines schienengebundenen transportsicherungssystems | |
| EP3652920A1 (de) | Verfahren und vorrichtung für ein signaltechnisch sicheres system | |
| EP1646919B1 (de) | Kopplungsvorrichtung für drei bussysteme | |
| EP3565752B1 (de) | Umschaltung zwischen element-controllern im bahnbetrieb | |
| DE102018126078A1 (de) | Verfahren zur Behandlung von Ausnahmezuständen eines Messsystems | |
| EP2876510A1 (de) | Sicherheitssteuerung zum sicheren Ein- und Ausschalten eines elektrischen Verbrauchetrs | |
| DE102013202482A1 (de) | Fehlersignalbehandlungseinheit, Gerät und Methode zur Ausgabe eines Fehlerzustandssignals | |
| EP3550748A1 (de) | Verfahren zur erkennung von datenverfälschungen bei einer datenübertragung über eine fehlersichere kommunikationsverbindung | |
| DE102006039671A1 (de) | Modulares elektronisches Flugsteuerungssystem | |
| DE102006012042A1 (de) | Steuervorrichtung zur fehlersicheren Steuerung einer Maschine | |
| DE10357797A1 (de) | Peripherieeinheit für ein redundantes Steuersystem | |
| DE102015208989A1 (de) | Ausfallsichere Verarbeitungsvorrichtung | |
| DE102005037723A1 (de) | Steuerungseinheit für Verbundbetrieb | |
| DE102007004794A1 (de) | Controllerbaustein mit einer Überwachung durch einen Watchdog | |
| EP4502738A1 (de) | Schaltungsanordnung für die steuerung einer maschine, maschinensystem, sowie verfahren zum erzeugen eines steuersignals | |
| EP1176508B1 (de) | Anordnung zur Überwachung des ordnungsgemässen Betriebes von die selben oder einander entsprechende Aktionen ausführenden Komponenten eines elektrischen Systems | |
| WO2015043903A1 (de) | Feldbusredundanz für nicht redundantes feldgerät | |
| DE112023005694T5 (de) | Gateway-vorrichtung, relaisverfahren, relaisprogramm |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20200214 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20201013 |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20210224 |