WO2017107665A1 - Safety computer system for use in train control - Google Patents

Safety computer system for use in train control Download PDF

Info

Publication number
WO2017107665A1
WO2017107665A1 PCT/CN2016/103931 CN2016103931W WO2017107665A1 WO 2017107665 A1 WO2017107665 A1 WO 2017107665A1 CN 2016103931 W CN2016103931 W CN 2016103931W WO 2017107665 A1 WO2017107665 A1 WO 2017107665A1
Authority
WO
WIPO (PCT)
Prior art keywords
module
data
processing module
input
output
Prior art date
Application number
PCT/CN2016/103931
Other languages
French (fr)
Chinese (zh)
Inventor
王奇
代飞
颜光
朱晖
彭扶权
贺建国
喻文冲
易红
单勇腾
罗永升
昝壮
Original Assignee
湖南中车时代通信信号有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 湖南中车时代通信信号有限公司 filed Critical 湖南中车时代通信信号有限公司
Publication of WO2017107665A1 publication Critical patent/WO2017107665A1/en

Links

Images

Classifications

    • BPERFORMING OPERATIONS; TRANSPORTING
    • B61RAILWAYS
    • B61LGUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
    • B61L27/00Central railway traffic control systems; Trackside control; Communication systems specially adapted therefor
    • GPHYSICS
    • G05CONTROLLING; REGULATING
    • G05BCONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
    • G05B23/00Testing or monitoring of control systems or parts thereof
    • G05B23/02Electric testing or monitoring
    • G05B23/0205Electric testing or monitoring by means of a monitoring system capable of detecting and responding to faults
    • G05B23/0208Electric testing or monitoring by means of a monitoring system capable of detecting and responding to faults characterized by the configuration of the monitoring system
    • G05B23/0213Modular or universal configuration of the monitoring system, e.g. monitoring system having modules that may be combined to build monitoring program; monitoring system that can be applied to legacy systems; adaptable monitoring system; using different communication protocols
    • GPHYSICS
    • G05CONTROLLING; REGULATING
    • G05BCONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
    • G05B23/00Testing or monitoring of control systems or parts thereof
    • G05B23/02Electric testing or monitoring
    • GPHYSICS
    • G05CONTROLLING; REGULATING
    • G05BCONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
    • G05B2219/00Program-control systems
    • G05B2219/20Pc systems
    • G05B2219/24Pc safety
    • G05B2219/24182Redundancy

Definitions

  • This invention relates to train control systems, and more particularly to a secure computer system for train control.
  • the safety computer is a computer and communication-based train control system, which realizes the real-time control and safety protection of the train operation, ensuring that the train runs within the allowable range according to the design route and the desired speed. Therefore, the reliability and security of a secure computer system are particularly important.
  • System reliability refers to the ability to perform a specified function within a specified time and under specified conditions.
  • Safety is the ability to ensure system output safety in the event of a system failure within a specified time and under specified conditions. In the prior art, security and reliability often cannot be both.
  • the present invention adopts a specific system architecture to greatly improve the reliability and security of the security computer system.
  • the host processing module uses the main system output, and the backup system does not output, which reduces the amount of system communication data while ensuring reliability and security.
  • the present invention provides a secure computer system for train control.
  • the secure computer system includes a first system and a second system, the first system and the second system being mutually redundant, wherein:
  • the first system includes a first system input module, a first system transmission module, a first system processing module, and a first system output module;
  • the second system includes a second system input module, a second system transmission module, and a second system.
  • Department processing module The second system is an output module; one of the first system processing module and the second system processing module is a main processing module, and the other is a standby processing module.
  • the first system input module and the second system input module are each configured to acquire an external signal to obtain input data and perform two-vote voting on the input data.
  • each input module passes The corresponding transmission module sends the input data to the main processing module and the standby processing module; when the two votes are not passed, the operation is stopped.
  • the input data refers to a digital analog input and a communication input.
  • the main processing module and the standby processing module are each configured to process input data from the same transmission module and perform two-vote voting.
  • the two-vote voting of the main processing module fails, the The main processing module stops working, and switches to the standby processing module that has passed the second vote for subsequent processing, and the standby processing module is now converted to the main processing module.
  • the main processing module is configured to select, according to requirements, data transmitted by any one of the first system transmission module and the second system transmission module as main data, and transmit data transmitted by another transmission module.
  • the backup data when the main data is unavailable, the standby data can be used to continue processing in time, and the main processing module simultaneously outputs the processed data to the first system transmission module and the second system transmission module;
  • the standby processing module is configured to process the same primary data as the primary processing module and use data transmitted by another transmission module as backup data to enable timely use of the primary data when the primary data is unavailable.
  • the data continues to be processed, and the standby processing module does not output the processed data to any of the transmission modules.
  • the first system output module and the second system output module are each configured to perform validity verification on the data processed by the main processing module and perform two-vote and two-vote, and when two or two votes are not passed, stop working.
  • the first system input module includes a first system input unit A and a first system input unit B.
  • the first system input unit A is configured to acquire the external portion to obtain an acquired digital analog input.
  • the first system input unit B is configured to acquire the same external portion to obtain an acquired digital analog input.
  • the first system input unit A and the first system input unit B are each configured to exchange and compare the digital analog input signals collected by the two parties. If they are the same, the first system input module will The collected digital analog input is sent to the first transmission module; if different, the first input module stops working, and if the second input module stops working, the security The computer system enters a safe state.
  • the second system input module includes a second system input unit A and a second system input unit B.
  • the second system input unit A is configured to acquire the external portion to obtain an acquired digital analog input.
  • the second line input unit B is configured to acquire the same external portion to obtain an acquired digital analog input.
  • the second system input unit A and the second system input unit B are each configured to exchange and compare the digital analog input signals collected by the two parties. If they are the same, the second system input module will The collected digital analog input is sent to the second transmission module; if different, the second input module stops working, and if the first input module stops working, the security The computer system enters a safe state.
  • the first system transmission module is configured to aggregate the digital analog input and the communication input and transmit it directly or indirectly to the main processing module and the standby processing module;
  • the first system transmission module is further configured to split the data processed by the main processing module into digital analog output and communication output and directly or indirectly to the first system output module.
  • the second system transmission module is configured to aggregate the digital analog input and the communication input and transmit it directly or indirectly to the main processing module and the standby processing module;
  • the second system transmission module is further configured to split the data processed by the main processing module into digital analog output and communication output and directly or indirectly to the second system output module.
  • the main processing module includes a main processing unit A and a main processing unit B.
  • the main processing unit A is configured to process the primary data and store the standby data to enable the standby data to be processed in time when the primary data is unavailable.
  • the main processing unit B is configured to process the main data and store the backup data so that the backup data can be used in time to continue processing when the main data is unavailable.
  • the main processing unit A and the main processing unit B respectively exchange and compare the data processed by the two parties. If they are the same, the main processing module sends the processed data to the first transmission.
  • a module and the second system transmission module wherein the data processed by the main processing module is periodically synchronized with the standby processing module; if not, the operation is stopped, and the operation is switched to the standby processing module.
  • the standby processing module also stops working, and the secure computer system enters a secure state.
  • the backup processing module includes a backup processing unit A and a standby processing unit B.
  • the standby processing unit A is configured to process the primary data and store the standby data to enable the standby data to be processed in time when the primary data is unavailable.
  • the standby processing unit B is configured to process the primary data and store the standby data to enable the standby data to be processed in a timely manner when the primary data is unavailable.
  • the data processed by the standby processing module is not output to any transmission module, and the standby processing unit A and the standby processing unit B exchange and compare the data processed by the two parties. If they are the same, the standby processing module will The processed data is periodically synchronized with the main processing module; if not, the operation is stopped.
  • the first system output module includes a first system output unit A and a first system output unit B.
  • the first system output unit A is configured to verify validity of the digital analog output from the main processing module.
  • the first system output unit B is configured to verify the validity of the same digital analog output.
  • the first system output unit A and the first system output unit B exchange and compare the data verified by the two parties. If they are the same, the verified data is output to the first system output execution device; If not, the work is stopped, and if the second system output module also stops working, the secure computer system enters a safe state.
  • the second system output module includes a second system output unit A and a second system output unit B.
  • the second system output unit A is configured to verify validity of the digital analog output from the main processing module.
  • the second system output unit B is configured to verify the validity of the same digital analog output.
  • the second system output unit A and the second system output unit B exchange and compare the data verified by the two parties. If they are the same, the verified data is output to the second system output execution device; If not, the work is stopped. If the first system output module also stops working, the secure computer system enters a safe state.
  • the first transmission unit and the second transmission unit use an Ethernet switch for data transmission or a FlexRay bus for direct data transmission.
  • the first system input module, the first system transmission module, the first system processing module, the first system output module, the second system input module, and the second The transmission module, the second system processing module, and the second system output module are in the form of a plug-in.
  • the primary data unavailability indicates that one or more of the input module and the transmission module of the system corresponding to the primary data cease to function (or fail).
  • FIG. 1 shows a secure computer system in accordance with an embodiment of the present invention
  • FIG. 2 shows a block diagram of a specific architecture of a secure computer system in accordance with an embodiment of the present invention.
  • redundancy In order to improve the security and reliability of a secure computer system, redundancy must be designed as a secure computer system.
  • dual-mode redundancy is the first choice for many secure computer systems with its high reliability and low hardware cost.
  • dual-machine comparison and dual-system hot backup are two more commonly used solutions, but each has its own advantages and disadvantages. Any failure of the two-machine comparison system will directly lead to shutdown and lead to the safe side, which has high safety, but the reliability of the system is low.
  • the dual-system hot standby system brings reliability while reducing the security of the system. Reliability and security become irreconcilable contradictions in these two structures.
  • the security computer system of the present invention adopts a specially designed two-by-two-two structure, which can be configured as a fail-safe redundant system from software and hardware, has high security, and basically satisfies reliability. Requirements.
  • the input module, the processing module and the output module of the secure computer system of the invention are connected via a FlexRay bus or a fast Ethernet.
  • the security-related input plug-ins (such as secure digital input, frequency input, etc.) are sent to the host through the scheduling control of the host under the guarantee of the two-vote voting security policy and the secure communication protocol; the host is parsed by the protocol, Processing such as logic/arithmetic operation, output voting, etc., finally sends the output command to the output module through the communication bus, and the output module executes the output.
  • the secure computer system has multiple interfaces for external communication capabilities, and the system outside the system can interact with the host through the communication plug-in. Through the configuration of hardware, the secure computer system of the present invention can be used for safety related equipment such as rail transit vehicle ATP, computer interlock, train control center/area controller.
  • FIG. 1 illustrates a secure computer system in accordance with an embodiment of the present invention.
  • the secure computer system of the present invention includes a first system (I-Series) 101 and a second system (II-based) 102.
  • the system structures of the first system 101 and the second system 102 are the same, and are mutually redundant systems.
  • Each system includes an input module, a transmission module, a processing module, and Output modules, which can all exist as plug-ins.
  • the first system 101 includes a first system input module 103, a first system transmission module 113, a first system processing module 104, and a first system output module 105.
  • the second system includes a second system input module 106, a second system transmission module 114, a second system processing module 107, and a second system output module 108.
  • the modules of the first system are redundant with the respective modules of the second system.
  • One of the first processing module 104 of the first system 101 of the present invention and the second processing module 107 of the second system 102 can be used as a main processing module and the other as a standby processing module.
  • the main processing module fails, It can be switched to the standby processing module, and the standby processing module becomes the main processing module.
  • the main input module and the output module of the two-line input module and the output module of the present invention may be arbitrarily selected according to actual conditions.
  • the first system processing module 104 when the first system processing module 104 functions as a main processing module, it can select the first system input module as its input module and process its input data, and use the input data of the second system input module as the standby data;
  • the second system input module can be selected as its input module and its input data can be processed, and the input data of the first system input module can be used as the standby data.
  • Input module (103, 106)
  • the input modules 103, 106 of the secure computer system of the present invention periodically acquire external signals, such as relay signals or sensor signals.
  • the safety-related signals are collected by digital or analog input channels, and are processed by two-to-two voting to form secure input data, which is sent to the host (for example, processing module) via the communication link under the guarantee of the secure communication protocol for the host to process.
  • Non-safety related signals are collected directly by a single CPU.
  • the input modules 103, 106 of the two systems are hot standby with each other.
  • the host adopts any system (the default is I system) to collect data and transmit it to the application development software or provide the collected data of the specified system according to the requirements of the application development software.
  • the secure computer system When the input modules of the two systems fail, are not inserted, or are not activated, the secure computer system enters a safe state.
  • the communication modules 113, 114 of the secure computer system of the present invention operate primarily in two parts.
  • Data transmission can be done in Ethernet mode or FlexRay mode.
  • the data collected by the input module is sent to the processing module via the communication module and the Ethernet switch; for FlexRay mode, the input module sends the data directly from the FlexRay bus to the processing module.
  • the external device of the secure computer platform sends the data to the communication module by means of communication, and then the communication module forwards it to the processing module via Ethernet or FlexRay bus.
  • the data of the processing module is sent to the output module or an external device.
  • Data transmission can be done in Ethernet mode or FlexRay mode.
  • the data processed by the processing module is sent to the output module through the Ethernet switch and the communication module; for the FlexRay mode, the processing module directly sends the data to the output module through the FlexRay bus.
  • the processing module sends the data from the Ethernet or FlexRay bus to the communication module, which in turn forwards it to the external device.
  • the security of the internal data transmission of the secure computer platform is guaranteed by the platform security communication protocol and meets the requirements of the IEC62280-1:2002 standard.
  • system uses serial communication to facilitate system expansion.
  • the processing module (or the host) 104, 107 acquires the input data or status of the internal module of the secure computer platform through the secure communication protocol, and obtains the input data of the external device of the secure computer platform through the communication protocol (determined by the application development user), and processes the data or status. After being transmitted to the application development software through the application development software interface, and processing the control command or state of the application development software, the output module is output to the internal module of the secure computer platform or an external device.
  • the two-system processing module receives input data from all platform internal modules and external devices simultaneously and processes them. Under normal circumstances, only the main processing module outputs data, and the standby processing module does not output data; the processing modules (hosts) of the two systems have inter-system synchronization and active/standby switching functions; when the main processing module (host) fails, the system is prepared. The processing module (host) will become the processing module (host) of the main system and output data. If the two processing modules fail at the same time, the system enters a safe state.
  • the output modules 105, 108 receive the control commands of the processing module (host), perform security verification on the data validity, and output the output through the output.
  • the safety digital output monitors the correctness of the output through the feedback circuit.
  • the two-line output module simultaneously receives the control commands of the processing module (host) and outputs them simultaneously.
  • the system outputs are connected in parallel with redundant output modules to increase system availability.
  • FIG. 2 shows a block diagram of a specific architecture of a secure computer system in accordance with an embodiment of the present invention.
  • the first system input module 103 includes a first system input unit A and a first system input unit B.
  • the first system input module 103 collects digital analog input inputs by the first system input unit A and the first system input unit B in two ways, and each performs two and two votes.
  • the first system input unit A is configured to periodically acquire an external signal, such as a relay signal or a sensor signal. These signals are acquired via digital or analog input channels and are used as digital analog inputs for the first system input module.
  • the digital analog input includes a safety related signal (eg, an acquired speed sensor signal, a current sensor signal, a voltage sensor signal, a relay signal).
  • the first system input unit B is configured to perform the same periodic acquisition of the same external signal to obtain a digital analog input.
  • the first system input module 103 also receives communication inputs.
  • the communication input is an input indicating a communication method (for example, Ethernet, CAN, RS485), and the communication input can be directly transmitted to the first transmission module 113.
  • the first system input unit A and the first system input unit B respectively perform two-two voting on the collected two digital analog input (for example, safety-related signals) to form safety input data. That is, the first system input unit A and the first system input unit B exchange data collected by both parties. The first system input unit A and the first system input unit B then compare the data collected by themselves with the exchanged data in the respective input units. If the comparison result is the same (that is, the data collected by the two input units A, B is the same, and the two votes are passed), the collected digital analog input is transmitted to the first transmission module 113.
  • the two are different (that is, the data collected by the two input units A and B are not the same, and the two-vote is not taken), it indicates that the first-line input module 103 is faulty and needs to stop working. If the main processing module and the standby processing module are using the data of the first system input module as the main data for processing, then it is necessary to switch to the standby data using the second system input module for subsequent processing. If the second system input module 106 of the second system 102 also fails to take two votes, the entire secure computer system enters a secure state.
  • the first system input module 103 can include one or more input plug-ins for acquiring the digital analog input.
  • the second system input module 106 includes a second system input unit A and a second system input unit B.
  • the second system input module 106 collects digital analog input inputs by the second system input unit A and the second system input unit B in two ways, and each performs two and two voting.
  • the second series input unit A is configured to periodically acquire an external signal, such as a relay signal or a sensor signal. These signals are acquired via digital or analog input channels and are used as digital analog inputs for the second system input module.
  • the digital analog input includes a safety related signal (eg, an acquired speed sensor signal, a current sensor signal, a voltage sensor signal, a relay signal).
  • the second line input unit B is configured to be paired The same external signal is subjected to the same periodic acquisition to obtain a digital analog input.
  • the second line input module 106 also receives communication inputs.
  • the communication input is an input representing a communication method (e.g., Ethernet, CAN, RS485), and the communication input can be directly transmitted to the second transmission module 114.
  • the second system input unit A and the second system input unit B respectively perform two-two voting on the collected two digital analog input (for example, safety-related signals) to form safety input data. That is, the second system input unit A and the second system input unit B exchange data collected by both parties.
  • the second line input unit A and the second line input unit B then compare the data collected by themselves with the exchanged data in the respective input units. If the comparison result is the same (that is, the data collected by the two input units A, B is the same, and the two votes are passed), the collected digital analog input is transmitted to the second transmission module 114.
  • the two are not the same (that is, the data collected by the two input units A, B are not the same, failing to take two votes), it indicates that the second-line input module 106 is faulty and needs to stop working. If the main processing module and the standby processing module are processing the data of the second system input module as the main data, then it is necessary to switch to the standby data using the first system input module for subsequent processing. If the first system input module 103 of the first system 101 also fails to take two votes, the entire secure computer system enters a secure state.
  • the second series input module 106 can include one or more input plug-ins for acquiring the digital analog input.
  • the first system input module 103 of the first system 101 and the second system input module 106 of the second system 102 are redundant hot standby. That is, the two input modules work simultaneously, and the data provided by one input module is processed by the main processing module and the standby processing module as main data, and the data provided by the other input module is used by the main processing module and the standby processing module as spare data.
  • the input module providing the main data fails, the data provided by the other input module is converted from the standby data into the main data for processing by the main processing module and the standby processing module. If the first system input module 103 and the second system input module 106 fail, are not inserted, or are not activated at the same time, the entire secure computer system enters a secure state.
  • the first system transmission module 113 aggregates the digital analog input and the communication input and directly or indirectly transmits to the main processing module and the standby processing module.
  • the first system transmission module 113 also splits the data processed by the main processing module into digital analog output and communication output, and directly or indirectly transmits to the first system output module.
  • the first system transmission module 113 can transmit data in an Ethernet mode or a FlexRay mode.
  • the first system output module 113 sends the summarized input data directly to the main processing module and the standby processing module through the FlexRay bus, and directly transmits the split digital analog output and communication output to the FlexRay bus to the The first system is the output module.
  • the first system output module 113 will The summarized input data is indirectly sent to the main processing module and the standby processing module through the Ethernet switch, and the split digital analog output and the communication output are indirectly transmitted to the first system output module through the Ethernet switch.
  • the benefit of the first-line transmission module 113 also distributing the aggregated input data to the backup processing module is that the primary processing module and the standby processing module use the same data under normal conditions (eg, from the same transmission module). The data is processed. Once the main processing module fails, the main processing module can directly switch to the standby processing module to achieve seamless switching.
  • the first system transmission module 113 can be a communication card.
  • the second system transmission module 114 aggregates the digital analog input and the communication input and transmits it directly or indirectly to the main processing module and the standby processing module.
  • the second system transmission module 114 also splits the data processed by the main processing module into digital analog output and communication output, and directly or indirectly transmits to the second system output module.
  • the second system transmission module 114 can transmit data in an Ethernet mode or a FlexRay mode.
  • the second system output module 114 sends the summarized input data directly to the main processing module and the standby processing module through the FlexRay bus, and directly transmits the split digital analog output and communication output to the FlexRay bus to the The second system is an output module.
  • the second system output module 114 sends the summarized input data to the main processing module and the standby processing module indirectly through the Ethernet switch, and passes the split digital analog output and communication output through the Ethernet switch. Indirect transmission to the second system output module.
  • the second system transmission module 114 also distributes the aggregated input data to the backup processing module because the main processing module and the standby processing module use the same data under normal conditions (for example, from the same transmission module). The data is processed. Once the main processing module fails, the main processing module can directly switch to the standby processing module to achieve seamless switching.
  • the second system transmission module 114 can be a communication card.
  • the first system processing module 104 acquires input data transmitted by the two-line transmission modules 113, 114, selects input data transmitted by one of the transmission modules for processing, such as logic control, protocol analysis, etc., and stores input transmitted by another transmission module. The data is used as a backup.
  • the first system processing module 104 includes a first system processor A and a first system processor B, each performing data processing and two-vote voting.
  • the second system processing module 107 acquires the input data transmitted by the two-system transmission modules 113, 114, selects the input data transmitted by one of the transmission modules for processing, such as logic control, protocol analysis, etc., and stores the input transmitted by another transmission module. The data is used as a backup.
  • the second system processing module 107 includes a second system processor A and a second system processor B, each performing data processing and two-vote voting.
  • one of the first processing module 104 and the second processing module 107 can function as a primary processing module and the other as a backup processing module.
  • the main processing module simultaneously receives data transmitted by the first system transmission module and the second system transmission module.
  • the main processing module can select, as the main data, data transmitted by any one of the first system transmission module and the second system transmission module as required, such as logic control, protocol analysis, and the like. And the data transmitted by the other transmission module is used as the backup data, so that the standby data can be continuously processed in time when the main data is unavailable, and the main processing module simultaneously outputs the processed data to the first system transmission module and the second system transmission module. For the first system output module and the second system output module for subsequent security verification.
  • the standby processing module simultaneously receives data transmitted by the first system transmission module and the second system transmission module. After the main processing module determines which data is transmitted by the transmission module as the main data, the standby processing module also processes the same main data. That is, the main processing module and the standby processing module process data from the same system (or the same transmission module) at the same time. At the same time, the standby processing module uses the data transmitted by the other transmission module as the standby data, so that the standby data can be continuously processed in time when the main data is unavailable, and the standby processing module does not output the processed data to any transmission module.
  • the unavailability of the master data mentioned here means that one or more of the input module and the transmission module of the system corresponding to the master data are stopped or malfunctioning (for example, two votes are not passed).
  • the main processing module includes a main processing unit A and a main processing unit B.
  • the main processing unit A processes the main data and stores the spare data so that the standby data can be used for subsequent processing when the main data is unavailable.
  • the main processing unit B processes the same main data and stores the spare data so that the standby data can be used for subsequent processing when the main data is not available.
  • the main processing unit A and the main processing unit B also each perform two votes. That is, the main processing unit A and the main processing unit B each exchange the processed data and compare them. If they are the same, the main processing module sends the processed data to the first system transmission module and the second system transmission module, and simultaneously The processed data of the processing module is periodically synchronized with the standby processing module; if it is different, the operation is stopped, and the operation is switched to the standby processing module. If the standby processing module also stops working, the secure computer system enters a safe state.
  • the standby processing module includes a standby processing unit A and a standby processing unit B.
  • the standby processing unit A processes the same main data and stores the spare data so that the standby data can be used in time to continue processing when the main data is unavailable.
  • the standby processing unit B processes the same main data and stores the spare data so that the standby data can be used in time to continue processing when the main data is unavailable.
  • the standby processing unit A and the standby processing unit B each perform two votes. That is, the standby processing unit A and the standby processing unit B each exchange and compare the data processed by the two parties. If they are the same, the standby processing module periodically synchronizes the processed data with the main processing module. If they are not the same, stop working. It should be noted here that the data processed by the standby processing module is not output to any transmission module.
  • the main processing module outputs data, and the standby processing module does not output data.
  • the purpose of this design is that the reliability of the entire secure computer system is fully guaranteed due to the design of the three modules of input, transmission and processing. Therefore, the processing output of one system can be reduced in the output module stage (for example, standby). The processing module no longer has an output) to reduce the amount of communication data for the entire secure computer system.
  • the main processing module and the standby processing module perform inter-system synchronization in real time to ensure that the main processing module fails (for example, when two or two voting fails), the standby processing module can obtain synchronous and just processed security in time. The latest data is transferred to the main processing module for subsequent processing. If the two processing modules fail at the same time, the secure computer system enters a safe state.
  • the first system output module 105 includes a first system output unit A and a first system output unit B.
  • first system output unit A and the first system output unit B For digital analog outputs (eg, safety related signal outputs), both the first system output unit A and the first system output unit B perform safety verification of their effectiveness.
  • the first system output unit A and the first system output unit B exchange safety-verified data with each other and compare the data in the respective output units. If the two are the same, the digital analog output can be output through the output actuator. . If the two are not the same (ie, failing to take two votes), the first output module stops working. If the second system output module 108 of the second system 102 also fails to take two votes, the entire secure computer system enters a secure state.
  • the first system collects the output for feedback to the feedback circuit for determining the correctness of the output.
  • the second system output module 108 includes a second system output unit A and a second system output unit B.
  • digital analog outputs eg, safety related signal outputs
  • both the second system output unit A and the second system output unit B perform safety verification of their effectiveness.
  • the second system output unit A and the second system output unit B exchange safety-verified data with each other and compare them in respective output units. If the two are the same, the digital analog output can be output through the execution device. If the two are not the same (ie, failing to take two votes), the second output module stops working. At this time, if the first system output module 105 also fails, the entire secure computer system enters a safe state.
  • the second system collects the output for feedback to the feedback circuit for determining the correctness of the output.
  • the safety computer system of the invention is a specially designed two-by-two-two system, which not only has the advantages of high reliability and high safety, but also has the characteristics of loose coupling, and the two-system input and output modules respectively collect and output respectively. They are highly independent of each other and do not affect each other. For example, if there is a problem with any one or more of the input module, transmission module, processing module, and output module of the main system, the system can work normally as long as it is not a module that collects or drives the same object.

Abstract

A safety computer system for use in train control, comprising a first system (101) and a second system (102) that are mutually redundant. One of two system processing modules (104 and 107) serves as a primary processing module, while the other one serves as a backup processing module. Two system input modules (103 and 106) respectively are configured to capture an external signal, to perform a two out of two voting, and to stop working when the two out of two voting did not pass. The primary processing module and the backup processing module respectively are configured to process input data coming from a same system and to perform a two out of two voting, when the two out of two voting of the primary processing module did not pass, then the primary processing module stops working and switches over to the backup processing module having passed the two out of two voting for subsequent processing, and the backup processing module thence becomes the primary processing module. Two system output modules (105 and 108) respectively are configured to verify the validity of the data processed by the primary processing module, to perform a two out of two voting, and to stop working when the two out of two voting did not pass.

Description

一种用于列车控制的安全计算机系统A safety computer system for train control 技术领域Technical field
本发明涉及列车控制系统,尤其涉及用于列车控制的安全计算机系统。This invention relates to train control systems, and more particularly to a secure computer system for train control.
背景技术Background technique
随着技术的不断进步和轨道交通系统对安全、可靠以及自动化程度要求日益的提高,信号系统作为轨道交通系统的核心领域,已经变得越来越重要,并且其技术复杂度也越来越高。而对于轨道交通信号系统车载控制设备以及地面设备,无论是城市轨道交通信号系统还是干线铁路信号系统,都存在一个共同的保证列车安全运行的核心关键技术,就是铁路信号安全计算机技术。With the continuous advancement of technology and the increasing requirements for safety, reliability and automation of rail transit systems, signal systems have become more and more important as the core areas of rail transit systems, and their technical complexity is also increasing. . For the on-board control equipment and ground equipment of the rail transit signal system, whether it is the urban rail transit signal system or the trunk railway signal system, there is a common key technology to ensure the safe operation of the train, which is the railway signal security computer technology.
安全计算机是以计算机、通信为基础的列车控制系统,其具体实现列车运行的实时控制和安全防护,确保列车按照设计路线和期望速度在允许的范围内运行。因此,安全计算机系统的可靠性、安全性显得尤为重要。The safety computer is a computer and communication-based train control system, which realizes the real-time control and safety protection of the train operation, ensuring that the train runs within the allowable range according to the design route and the desired speed. Therefore, the reliability and security of a secure computer system are particularly important.
系统可靠性是指在规定的时间内、规定的条件下完成规定功能的能力。安全性是在规定的时间内、规定的条件下,在系统发生故障时也保证系统输出安全的能力。现有技术中,安全性和可靠性往往不能两者兼得。System reliability refers to the ability to perform a specified function within a specified time and under specified conditions. Safety is the ability to ensure system output safety in the event of a system failure within a specified time and under specified conditions. In the prior art, security and reliability often cannot be both.
因此,亟需一种可靠性佳、安全性高、且能适当控制通讯数据量的安全计算机系统。Therefore, there is a need for a secure computer system that is highly reliable, highly secure, and capable of properly controlling the amount of communication data.
发明内容Summary of the invention
为了解决传统的安全计算机的输入模块、通信模块、处理模块、输出模块可靠性和安全性不高的技术问题,本发明采用特定的系统架构大幅提升安全计算机系统的可靠性和安全性,同时,主机处理模块采用主系输出,备系不输出,在保证可靠性和安全性的同时,降低了系统通信数据量。In order to solve the technical problems of the input module, the communication module, the processing module, the output module reliability and the security of the traditional security computer, the present invention adopts a specific system architecture to greatly improve the reliability and security of the security computer system. The host processing module uses the main system output, and the backup system does not output, which reduces the amount of system communication data while ensuring reliability and security.
本发明提供了一种用于列车控制的安全计算机系统。The present invention provides a secure computer system for train control.
所述安全计算机系统包括第一系统和第二系统,所述第一系统和所述第二系统互为冗余,其中:The secure computer system includes a first system and a second system, the first system and the second system being mutually redundant, wherein:
所述第一系统包括第一系输入模块、第一系传输模块、第一系处理模块、第一系输出模块;所述第二系统包括第二系输入模块、第二系传输模块、第二系处理模块、 第二系输出模块;所述第一系处理模块和所述第二系处理模块中的一个为主处理模块,另一个为备用处理模块。The first system includes a first system input module, a first system transmission module, a first system processing module, and a first system output module; the second system includes a second system input module, a second system transmission module, and a second system. Department processing module, The second system is an output module; one of the first system processing module and the second system processing module is a main processing module, and the other is a standby processing module.
所述第一系输入模块和所述第二系输入模块各自被配置成采集外部信号以获得输入数据并对所述输入数据进行二取二表决,当二取二表决通过时,各输入模块通过其对应的传输模块将所述输入数据发送至所述主处理模块和所述备用处理模块;当二取二表决不通过时,则停止工作。The first system input module and the second system input module are each configured to acquire an external signal to obtain input data and perform two-vote voting on the input data. When two votes are passed, each input module passes The corresponding transmission module sends the input data to the main processing module and the standby processing module; when the two votes are not passed, the operation is stopped.
其中,所述输入数据指的是数字量模拟量输入和通信输入。Wherein, the input data refers to a digital analog input and a communication input.
所述主处理模块和所述备用处理模块各自被配置成对来自同一传输模块的输入数据进行处理并进行二取二表决,当所述主处理模块的二取二表决不通过时,则所述主处理模块停止工作,并切换至二取二表决通过的所述备用处理模块进行后续处理,所述备用处理模块此时转为所述主处理模块。The main processing module and the standby processing module are each configured to process input data from the same transmission module and perform two-vote voting. When the two-vote voting of the main processing module fails, the The main processing module stops working, and switches to the standby processing module that has passed the second vote for subsequent processing, and the standby processing module is now converted to the main processing module.
所述主处理模块被配置成可根据需求选择所述第一系传输模块和所述第二系传输模块中任一个所传输的数据作为主数据进行处理,并将另一个传输模块所传输的数据作为备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理,所述主处理模块将处理后的数据同时输出至所述第一系传输模块和第二系传输模块;The main processing module is configured to select, according to requirements, data transmitted by any one of the first system transmission module and the second system transmission module as main data, and transmit data transmitted by another transmission module. As the backup data, when the main data is unavailable, the standby data can be used to continue processing in time, and the main processing module simultaneously outputs the processed data to the first system transmission module and the second system transmission module;
所述备用处理模块被配置成处理与所述主处理模块相同的所述主数据,并将另一个传输模块所传输的数据作为备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理,所述备用处理模块不将处理后的数据输出至任何传输模块。The standby processing module is configured to process the same primary data as the primary processing module and use data transmitted by another transmission module as backup data to enable timely use of the primary data when the primary data is unavailable. The data continues to be processed, and the standby processing module does not output the processed data to any of the transmission modules.
所述第一系输出模块和所述第二系输出模块各自被配置成对所述主处理模块处理后的数据进行有效性验证并进行二取二表决,当二取二表决不通过时,则停止工作。The first system output module and the second system output module are each configured to perform validity verification on the data processed by the main processing module and perform two-vote and two-vote, and when two or two votes are not passed, stop working.
在一个实施例中,所述第一系输入模块包括第一系输入单元A、第一系输入单元B。In one embodiment, the first system input module includes a first system input unit A and a first system input unit B.
所述第一系输入单元A被配置成对所述外部进行采集,获得采集后的数字量模拟量输入。The first system input unit A is configured to acquire the external portion to obtain an acquired digital analog input.
所述第一系输入单元B被配置成对所述同样的外部进行采集,获得采集后的数字量模拟量输入。The first system input unit B is configured to acquire the same external portion to obtain an acquired digital analog input.
所述第一系输入单元A和所述第一系输入单元B各自还被配置成对双方所采集后的数字量模拟量输入进行交换和比较,若相同,则所述第一系输入模块将所述采集后的数字量模拟量输入发送至所述第一系传输模块;若不同,则所述第一系输入模块停止工作,若所述第二系输入模块也停止工作,则所述安全计算机系统进入安全状态。The first system input unit A and the first system input unit B are each configured to exchange and compare the digital analog input signals collected by the two parties. If they are the same, the first system input module will The collected digital analog input is sent to the first transmission module; if different, the first input module stops working, and if the second input module stops working, the security The computer system enters a safe state.
在一个实施例中,所述第二系输入模块包括第二系输入单元A、第二系输入单元B。 In one embodiment, the second system input module includes a second system input unit A and a second system input unit B.
所述第二系输入单元A被配置成对所述外部进行采集,获得采集后的数字量模拟量输入。The second system input unit A is configured to acquire the external portion to obtain an acquired digital analog input.
所述第二系输入单元B被配置成对所述同样的外部进行采集,获得采集后的数字量模拟量输入。The second line input unit B is configured to acquire the same external portion to obtain an acquired digital analog input.
所述第二系输入单元A和所述第二系输入单元B各自还被配置成对双方所采集后的数字量模拟量输入进行交换和比较,若相同,则所述第二系输入模块将所述采集后的数字量模拟量输入发送至所述第二系传输模块;若不同,则所述第二系输入模块停止工作,若所述第一系输入模块也停止工作,则所述安全计算机系统进入安全状态。The second system input unit A and the second system input unit B are each configured to exchange and compare the digital analog input signals collected by the two parties. If they are the same, the second system input module will The collected digital analog input is sent to the second transmission module; if different, the second input module stops working, and if the first input module stops working, the security The computer system enters a safe state.
在一个实施例中,所述第一系传输模块被配置成将所述数字量模拟量输入与通信输入进行汇总并直接或间接地传输至所述主处理模块和所述备用处理模块;所述第一系传输模块还被配置成将所述主处理模块处理后的数据拆分成数字量模拟量输出和通信输出,并直接或间接地传输至所述第一系输出模块。In one embodiment, the first system transmission module is configured to aggregate the digital analog input and the communication input and transmit it directly or indirectly to the main processing module and the standby processing module; The first system transmission module is further configured to split the data processed by the main processing module into digital analog output and communication output and directly or indirectly to the first system output module.
在一个实施例中,所述第二系传输模块被配置成将所述数字量模拟量输入与通信输入进行汇总并直接或间接地传输至所述主处理模块和所述备用处理模块;所述第二系传输模块还被配置成将所述主处理模块处理后的数据拆分成数字量模拟量输出和通信输出,并直接或间接地传输至所述第二系输出模块。In one embodiment, the second system transmission module is configured to aggregate the digital analog input and the communication input and transmit it directly or indirectly to the main processing module and the standby processing module; The second system transmission module is further configured to split the data processed by the main processing module into digital analog output and communication output and directly or indirectly to the second system output module.
在一个实施例中,所述主处理模块包括主处理单元A、主处理单元B。In one embodiment, the main processing module includes a main processing unit A and a main processing unit B.
所述主处理单元A被配置成对所述主数据进行处理,并且存储所述备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理。The main processing unit A is configured to process the primary data and store the standby data to enable the standby data to be processed in time when the primary data is unavailable.
所述主处理单元B被配置成对所述主数据进行处理,并且存储所述备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理。The main processing unit B is configured to process the main data and store the backup data so that the backup data can be used in time to continue processing when the main data is unavailable.
所述主处理单元A和所述主处理单元B各自对双方所处理后的数据进行交换和比较,若相同,则所述主处理模块将所述处理后的数据发送至所述第一系传输模块和所述第二系传输模块,同时所述主处理模块处理后的数据与所述备用处理模块进行周期性地同步;若不同,则停止工作,并切换至所述备用处理模块工作,若所述备用处理模块也停止工作,则所述安全计算机系统进入安全状态。The main processing unit A and the main processing unit B respectively exchange and compare the data processed by the two parties. If they are the same, the main processing module sends the processed data to the first transmission. a module and the second system transmission module, wherein the data processed by the main processing module is periodically synchronized with the standby processing module; if not, the operation is stopped, and the operation is switched to the standby processing module. The standby processing module also stops working, and the secure computer system enters a secure state.
在一个实施例中,所述备用处理模块包括备用处理单元A、备用处理单元B。In one embodiment, the backup processing module includes a backup processing unit A and a standby processing unit B.
所述备用处理单元A被配置成对所述主数据进行处理,并且存储所述备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理。 The standby processing unit A is configured to process the primary data and store the standby data to enable the standby data to be processed in time when the primary data is unavailable.
所述备用处理单元B被配置成对所述主数据进行处理,并且存储所述备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理。The standby processing unit B is configured to process the primary data and store the standby data to enable the standby data to be processed in a timely manner when the primary data is unavailable.
所述备用处理模块所处理的数据并不输出给任何传输模块,所述备用处理单元A和备用处理单元B对双方所处理后的数据进行交换和比较,若相同,则所述备用处理模块将处理后的数据与所述主处理模块进行周期性地同步;若不相同,则停止工作。The data processed by the standby processing module is not output to any transmission module, and the standby processing unit A and the standby processing unit B exchange and compare the data processed by the two parties. If they are the same, the standby processing module will The processed data is periodically synchronized with the main processing module; if not, the operation is stopped.
在一个实施例中,所述第一系输出模块包括第一系输出单元A、第一系输出单元B。In one embodiment, the first system output module includes a first system output unit A and a first system output unit B.
所述第一系输出单元A被配置成对来自所述主处理模块的所述数字量模拟量输出进行有效性验证。The first system output unit A is configured to verify validity of the digital analog output from the main processing module.
所述第一系输出单元B被配置成对同样的所述数字量模拟量输出进行有效性验证。The first system output unit B is configured to verify the validity of the same digital analog output.
所述第一系输出单元A和所述第一系输出单元B对双方所验证后的数据进行交换和比较,若相同,则将所述验证后的数据输出至第一系输出执行器件;若不同,则停止工作,若所述第二系输出模块也停止工作,则所述安全计算机系统进入安全状态。The first system output unit A and the first system output unit B exchange and compare the data verified by the two parties. If they are the same, the verified data is output to the first system output execution device; If not, the work is stopped, and if the second system output module also stops working, the secure computer system enters a safe state.
在一个实施例中,所述第二系输出模块包括第二系输出单元A、第二系输出单元B。In one embodiment, the second system output module includes a second system output unit A and a second system output unit B.
所述第二系输出单元A被配置成对来自所述主处理模块的所述数字量模拟量输出进行有效性验证。The second system output unit A is configured to verify validity of the digital analog output from the main processing module.
所述第二系输出单元B被配置成对同样的所述数字量模拟量输出进行有效性验证。The second system output unit B is configured to verify the validity of the same digital analog output.
所述第二系输出单元A和所述第二系输出单元B对双方所验证后的数据进行交换和比较,若相同,则将所述验证后的数据输出至第二系输出执行器件;若不同,则停止工作若所述第一系输出模块也停止工作,则所述安全计算机系统进入安全状态。The second system output unit A and the second system output unit B exchange and compare the data verified by the two parties. If they are the same, the verified data is output to the second system output execution device; If not, the work is stopped. If the first system output module also stops working, the secure computer system enters a safe state.
在一个实施例中,所述第一系传输单元以及所述第二系传输单元采用以太网交换机进行数据传输或者采用FlexRay总线方式直接进行数据传输。In one embodiment, the first transmission unit and the second transmission unit use an Ethernet switch for data transmission or a FlexRay bus for direct data transmission.
在一个实施例中,所述第一系输入模块、所述第一系传输模块、所述第一系处理模块、所述第一系输出模块、所述第二系输入模块、所述第二系传输模块、所述第二系处理模块、所述第二系输出模块采用插件形式。In one embodiment, the first system input module, the first system transmission module, the first system processing module, the first system output module, the second system input module, and the second The transmission module, the second system processing module, and the second system output module are in the form of a plug-in.
在一个实施例中,所述主数据不可用表示所述主数据所对应的系统的输入模块和传输模块中的一者或多者停止工作(或出现故障)。In one embodiment, the primary data unavailability indicates that one or more of the input module and the transmission module of the system corresponding to the primary data cease to function (or fail).
附图说明 DRAWINGS
本发明的以上发明内容以及下面的具体实施方式在结合附图阅读时会得到更好的理解。需要说明的是,附图仅作为所请求保护的发明的示例。在附图中,相同的附图标记代表相同或类似的元素。The above summary of the present invention and the following detailed description of the invention will be better understood. It should be noted that the drawings are only illustrative of the claimed invention. In the drawings, the same reference numerals indicate the same or similar elements.
图1示出根据本发明的一实施例的安全计算机系统;以及1 shows a secure computer system in accordance with an embodiment of the present invention;
图2示出根据本发明的一实施例的安全计算机系统的具体构架框图。2 shows a block diagram of a specific architecture of a secure computer system in accordance with an embodiment of the present invention.
具体实施方式detailed description
为了提高安全计算机系统的安全性和可靠性,必须对作为安全计算机系统进行冗余设计。在冗余系统中,双模冗余以其较高的可靠性以及较低的硬件成本成为众多安全计算机系统的首选。在双模冗余系统中,双机比较及双机热备又是较常用的两种方案,但都有其各自的优缺点。双机比较系统的任何故障都会直接导致停机并导向安全侧,具有很高的安全性,但系统的可靠性较低。而双机热备系统则相反,带来可靠性的同时却降低了系统的安全性,可靠性和安全性在这两种结构中成为不可调和的矛盾。In order to improve the security and reliability of a secure computer system, redundancy must be designed as a secure computer system. In redundant systems, dual-mode redundancy is the first choice for many secure computer systems with its high reliability and low hardware cost. In the dual-mode redundant system, dual-machine comparison and dual-system hot backup are two more commonly used solutions, but each has its own advantages and disadvantages. Any failure of the two-machine comparison system will directly lead to shutdown and lead to the safe side, which has high safety, but the reliability of the system is low. The dual-system hot standby system, on the other hand, brings reliability while reducing the security of the system. Reliability and security become irreconcilable contradictions in these two structures.
不同于现有技术,本发明的安全计算机系统采用特别设计的二乘二取二结构,可以从软件和硬件上配置成基于故障安全的冗余系统,具有高安全性,也基本满足了可靠性的要求。Different from the prior art, the security computer system of the present invention adopts a specially designed two-by-two-two structure, which can be configured as a fail-safe redundant system from software and hardware, has high security, and basically satisfies reliability. Requirements.
本发明的安全计算机系统的输入模块、处理模块以及输出模块间通过FlexRay总线或快速以太网连接。安全相关输入插件(如安全数字输入、频率量输入等)在二取二表决安全策略和安全通信协议的保证下,通过主机的调度控制,将采集到的数据送至主机;主机经过协议解析、逻辑/算术运算、输出表决等处理,最终将输出命令通过通信总线发送至输出模块,由输出模块执行输出。安全计算机系统同时具有多种接口对外通信能力,系统外设备可通过通信插件与主机进行数据交互。通过硬件的配置,本发明的安全计算机系统可以用于轨道交通车载ATP、计算机联锁、列控中心/区域控制器等安全相关设备。The input module, the processing module and the output module of the secure computer system of the invention are connected via a FlexRay bus or a fast Ethernet. The security-related input plug-ins (such as secure digital input, frequency input, etc.) are sent to the host through the scheduling control of the host under the guarantee of the two-vote voting security policy and the secure communication protocol; the host is parsed by the protocol, Processing such as logic/arithmetic operation, output voting, etc., finally sends the output command to the output module through the communication bus, and the output module executes the output. The secure computer system has multiple interfaces for external communication capabilities, and the system outside the system can interact with the host through the communication plug-in. Through the configuration of hardware, the secure computer system of the present invention can be used for safety related equipment such as rail transit vehicle ATP, computer interlock, train control center/area controller.
以下在具体实施方式中详细叙述本发明的详细特征以及优点,其内容足以使任何本领域技术人员了解本发明的技术内容并据以实施,且根据本说明书所揭露的说明书、权利要求及附图,本领域技术人员可轻易地理解本发明相关的目的及优点。The detailed features and advantages of the present invention are described in detail in the Detailed Description of the Detailed Description of the Detailed Description. The objects and advantages associated with the present invention will be readily understood by those skilled in the art.
图1示出根据本发明的一实施例的安全计算机系统。本发明的安全计算机系统包括第一系统(I系)101和第二系统(II系)102。其中,第一系统101和第二系统102的系统构架相同,且互为冗余系统。每个系统包括输入模块、传输模块、处理模块和 输出模块,这些模块均可以以插件的形式存在。其中,第一系统101包括第一系输入模块103、第一系传输模块113、第一系处理模块104和第一系输出模块105。第二系统包括第二系输入模块106、第二系传输模块114、第二系处理模块107和第二系输出模块108。第一系统的各模块与第二系统的相应各模块互为冗余。FIG. 1 illustrates a secure computer system in accordance with an embodiment of the present invention. The secure computer system of the present invention includes a first system (I-Series) 101 and a second system (II-based) 102. The system structures of the first system 101 and the second system 102 are the same, and are mutually redundant systems. Each system includes an input module, a transmission module, a processing module, and Output modules, which can all exist as plug-ins. The first system 101 includes a first system input module 103, a first system transmission module 113, a first system processing module 104, and a first system output module 105. The second system includes a second system input module 106, a second system transmission module 114, a second system processing module 107, and a second system output module 108. The modules of the first system are redundant with the respective modules of the second system.
本发明的第一系统101的第一系处理模块104和第二系统102的第二系处理模块107中的一个处理模块可作为主处理模块,另一个作为备用处理模块,当主处理模块故障时,可切换至备用处理模块,此时的备用处理模块变为主处理模块。One of the first processing module 104 of the first system 101 of the present invention and the second processing module 107 of the second system 102 can be used as a main processing module and the other as a standby processing module. When the main processing module fails, It can be switched to the standby processing module, and the standby processing module becomes the main processing module.
本发明的两系的输入模块、输出模块之间可以没有主、备之分,主处理模块可以根据实际情况进行任意选择。例如,当第一系处理模块104作为主处理模块时,其可以选择第一系输入模块作为其输入模块并对其输入数据进行处理,而将第二系输入模块的输入数据作为备用数据;也可以选择第二系输入模块作为其输入模块并对其输入数据进行处理,而将第一系输入模块的输入数据作为备用数据。There may be no distinction between the main input module and the output module of the two-line input module and the output module of the present invention, and the main processing module may be arbitrarily selected according to actual conditions. For example, when the first system processing module 104 functions as a main processing module, it can select the first system input module as its input module and process its input data, and use the input data of the second system input module as the standby data; The second system input module can be selected as its input module and its input data can be processed, and the input data of the first system input module can be used as the standby data.
输入模块(103,106)Input module (103, 106)
本发明的安全计算机系统的输入模块103、106对外部信号(如继电器信号或传感器信号)进行周期性的采集。安全相关信号经数字或模拟输入通道采集,经过二取二的表决处理,形成安全输入数据,在安全通信协议的保证下经通信链路发送至主机(例如,处理模块),供主机处理。非安全相关信号由单一CPU直接采集。The input modules 103, 106 of the secure computer system of the present invention periodically acquire external signals, such as relay signals or sensor signals. The safety-related signals are collected by digital or analog input channels, and are processed by two-to-two voting to form secure input data, which is sent to the host (for example, processing module) via the communication link under the guarantee of the secure communication protocol for the host to process. Non-safety related signals are collected directly by a single CPU.
两系(即第一系统和第二系统)的输入模块103、106互为热备。主机采用任意一系(默认为I系)采集数据传送至应用开发软件或者根据应用开发软件的要求提供指定系别的采集数据。The input modules 103, 106 of the two systems (ie, the first system and the second system) are hot standby with each other. The host adopts any system (the default is I system) to collect data and transmit it to the application development software or provide the collected data of the specified system according to the requirements of the application development software.
两系的输入模块同时故障、未插入或未激活时,则安全计算机系统进入安全状态。When the input modules of the two systems fail, are not inserted, or are not activated, the secure computer system enters a safe state.
通信模块(113,114)Communication module (113, 114)
本发明的安全计算机系统的通信模块113,114主要进行两部分工作。The communication modules 113, 114 of the secure computer system of the present invention operate primarily in two parts.
第一,将输入数据发送至主机。数据发送可采用以太网模式或FlexRay模式。First, send the input data to the host. Data transmission can be done in Ethernet mode or FlexRay mode.
对于以太网模式,输入模块采集的数据经通信模块和以太网交换机发送至处理模块;对于FlexRay模式,输入模块直接将数据由FlexRay总线发送至处理模块。安全计算机平台外部设备通过通信方式将数据发送至通信模块,再由通信模块通过以太网或FlexRay总线转发至处理模块。 For Ethernet mode, the data collected by the input module is sent to the processing module via the communication module and the Ethernet switch; for FlexRay mode, the input module sends the data directly from the FlexRay bus to the processing module. The external device of the secure computer platform sends the data to the communication module by means of communication, and then the communication module forwards it to the processing module via Ethernet or FlexRay bus.
第二,将处理模块的数据发送至输出模块或外部设备。数据发送可采用以太网模式或FlexRay模式。Second, the data of the processing module is sent to the output module or an external device. Data transmission can be done in Ethernet mode or FlexRay mode.
对于以太网模式,经处理模块处理后的数据通过以太网交换机、通信模块,发送至输出模块;对于FlexRay模式,处理模块直接将数据通过FlexRay总线发送至输出模块。对于安全计算机平台外部设备,处理模块将数据由以太网或FlexRay总线发送至通信模块,再由通信模块转发至外部设备。For the Ethernet mode, the data processed by the processing module is sent to the output module through the Ethernet switch and the communication module; for the FlexRay mode, the processing module directly sends the data to the output module through the FlexRay bus. For secure computer platform external devices, the processing module sends the data from the Ethernet or FlexRay bus to the communication module, which in turn forwards it to the external device.
安全计算机平台内部数据传输的安全性通过平台安全通信协议保证,并符合IEC62280-1:2002标准的要求。The security of the internal data transmission of the secure computer platform is guaranteed by the platform security communication protocol and meets the requirements of the IEC62280-1:2002 standard.
此外,系统采用串行通信的方式,有利于系统扩展。In addition, the system uses serial communication to facilitate system expansion.
处理模块(104,107)Processing module (104, 107)
处理模块(或称主机)104、107通过安全通信协议获取安全计算机平台内部模块输入数据或状态,通过通信协议(由应用开发用户确定)获取安全计算机平台外部设备输入数据,将数据或状态进行处理后通过应用开发软件接口传送至应用开发软件,并将应用开发软件的控制命令或状态进行处理后,经传输模块输出至安全计算机平台内部模块或外部设备。The processing module (or the host) 104, 107 acquires the input data or status of the internal module of the secure computer platform through the secure communication protocol, and obtains the input data of the external device of the secure computer platform through the communication protocol (determined by the application development user), and processes the data or status. After being transmitted to the application development software through the application development software interface, and processing the control command or state of the application development software, the output module is output to the internal module of the secure computer platform or an external device.
两系的处理模块同时接收所有平台内部模块和外部设备的输入数据并进行处理。正常情况下,只有主处理模块输出数据,备用处理模块不输出数据;两系的处理模块(主机)具有系间同步与主备切换功能;主系的处理模块(主机)故障时,备系的处理模块(主机)将成为主系的处理模块(主机)并输出数据。若两系的处理模块同时故障,系统进入安全状态。The two-system processing module receives input data from all platform internal modules and external devices simultaneously and processes them. Under normal circumstances, only the main processing module outputs data, and the standby processing module does not output data; the processing modules (hosts) of the two systems have inter-system synchronization and active/standby switching functions; when the main processing module (host) fails, the system is prepared. The processing module (host) will become the processing module (host) of the main system and output data. If the two processing modules fail at the same time, the system enters a safe state.
输出模块(105,108)Output module (105,108)
输出模块105、108接收处理模块(主机)的控制命令,对数据有效性进行安全验证后通过输出执行器件输出。安全数字量输出通过反馈电路监督执行输出的正确性。两系输出模块同时接收处理模块(主机)的控制命令,并同时输出。The output modules 105, 108 receive the control commands of the processing module (host), perform security verification on the data validity, and output the output through the output. The safety digital output monitors the correctness of the output through the feedback circuit. The two-line output module simultaneously receives the control commands of the processing module (host) and outputs them simultaneously.
系统输出采用冗余输出模块并联方式,以提高系统可用性。The system outputs are connected in parallel with redundant output modules to increase system availability.
两系互为冗余的安全输出模块同时故障、未插入或未激活时,系统进入安全状态。When the two series of redundant safety output modules fail, are not inserted or are not activated, the system enters a safe state.
图2示出根据本发明的一实施例的安全计算机系统的具体构架框图。 2 shows a block diagram of a specific architecture of a secure computer system in accordance with an embodiment of the present invention.
第一系输入模块103包括第一系输入单元A和第一系输入单元B。第一系输入模块103分两路分别由第一系输入单元A和第一系输入单元B采集数字量模拟量输入,各自进行二取二表决。The first system input module 103 includes a first system input unit A and a first system input unit B. The first system input module 103 collects digital analog input inputs by the first system input unit A and the first system input unit B in two ways, and each performs two and two votes.
第一系输入单元A被配置成对外部信号,例如继电器信号或者传感器信号,进行周期性地采集。这些信号经数字或模拟输入通道被采集并作为第一系输入模块的数字量模拟量输入。该数字量模拟量输入包括安全相关信号(例如经采集的速度传感器信号、电流传感器信号、电压传感器信号、继电器信号)。第一系输入单元B被配置成对该同一外部信号,进行同样地周期性采集,获得数字量模拟量输入。此外,第一系输入模块103还接收通信输入。通信输入是一种表示通信方式(例如以太网、CAN、RS485)的输入,通信输入可被直接传送至第一系传输模块113。The first system input unit A is configured to periodically acquire an external signal, such as a relay signal or a sensor signal. These signals are acquired via digital or analog input channels and are used as digital analog inputs for the first system input module. The digital analog input includes a safety related signal (eg, an acquired speed sensor signal, a current sensor signal, a voltage sensor signal, a relay signal). The first system input unit B is configured to perform the same periodic acquisition of the same external signal to obtain a digital analog input. In addition, the first system input module 103 also receives communication inputs. The communication input is an input indicating a communication method (for example, Ethernet, CAN, RS485), and the communication input can be directly transmitted to the first transmission module 113.
第一系输入单元A和第一系输入单元B分别对采集后的两路数字量模拟量输入(例如安全相关信号)进行二取二表决,形成安全输入数据。即第一系输入单元A和第一系输入单元B互相交换双方所采集的数据。随后第一系输入单元A和第一系输入单元B在各自的输入单元中将自身采集的数据与交换而来的数据进行比较。若比较结果相同(即两个输入单元A、B所采集的数据相同,二取二表决通过),则将采集到的数字量模拟量输入传送至第一系传输模块113。若两者不相同(即两个输入单元A、B所采集的数据不相同,未通过二取二表决),则表示第一系输入模块103发生故障,需停止工作。若主处理模块和备用处理模块正采用该第一系输入模块的数据作为主数据进行处理的,则此时需要切换到采用第二系输入模块的备用数据进行后续处理。若第二系统102的第二系输入模块106也未通过二取二表决,则整个安全计算机系统进入安全状态。The first system input unit A and the first system input unit B respectively perform two-two voting on the collected two digital analog input (for example, safety-related signals) to form safety input data. That is, the first system input unit A and the first system input unit B exchange data collected by both parties. The first system input unit A and the first system input unit B then compare the data collected by themselves with the exchanged data in the respective input units. If the comparison result is the same (that is, the data collected by the two input units A, B is the same, and the two votes are passed), the collected digital analog input is transmitted to the first transmission module 113. If the two are different (that is, the data collected by the two input units A and B are not the same, and the two-vote is not taken), it indicates that the first-line input module 103 is faulty and needs to stop working. If the main processing module and the standby processing module are using the data of the first system input module as the main data for processing, then it is necessary to switch to the standby data using the second system input module for subsequent processing. If the second system input module 106 of the second system 102 also fails to take two votes, the entire secure computer system enters a secure state.
在一个实施例中,第一系输入模块103可以包括一个或多个输入插件,用于采集该数字量模拟量输入。In one embodiment, the first system input module 103 can include one or more input plug-ins for acquiring the digital analog input.
第二系输入模块106包括第二系输入单元A、第二系输入单元B。第二系输入模块106分两路分别由第二系输入单元A和第二系输入单元B采集数字量模拟量输入,各自进行二取二表决。The second system input module 106 includes a second system input unit A and a second system input unit B. The second system input module 106 collects digital analog input inputs by the second system input unit A and the second system input unit B in two ways, and each performs two and two voting.
第二系输入单元A被配置成对外部信号,例如继电器信号或者传感器信号,进行周期性地采集。这些信号经数字或模拟输入通道被采集并作为第二系输入模块的数字量模拟量输入。该数字量模拟量输入包括安全相关信号(例如经采集的速度传感器信号、电流传感器信号、电压传感器信号、继电器信号)。第二系输入单元B被配置成对 该同一外部信号,进行同样地周期性采集,获得数字量模拟量输入。此外,第二系输入模块106还接收通信输入。通信输入是一种表示通信方式(例如以太网、CAN、RS485)的输入,通信输入可被直接传送至第二系传输模块114。The second series input unit A is configured to periodically acquire an external signal, such as a relay signal or a sensor signal. These signals are acquired via digital or analog input channels and are used as digital analog inputs for the second system input module. The digital analog input includes a safety related signal (eg, an acquired speed sensor signal, a current sensor signal, a voltage sensor signal, a relay signal). The second line input unit B is configured to be paired The same external signal is subjected to the same periodic acquisition to obtain a digital analog input. In addition, the second line input module 106 also receives communication inputs. The communication input is an input representing a communication method (e.g., Ethernet, CAN, RS485), and the communication input can be directly transmitted to the second transmission module 114.
第二系输入单元A和第二系输入单元B分别对采集后的两路数字量模拟量输入(例如安全相关信号)进行二取二表决,形成安全输入数据。即第二系输入单元A和第二系输入单元B互相交换双方所采集的数据。随后第二系输入单元A和第二系输入单元B在各自的输入单元中将自身采集的数据与交换而来的数据进行比较。若比较结果相同(即两个输入单元A、B所采集的数据相同,二取二表决通过),则将采集到的数字量模拟量输入传送至第二系传输模块114。若两者不相同(即两个输入单元A、B所采集的数据不相同,未通过二取二表决),则表示第二系输入模块106发生故障,需停止工作。若主处理模块和备用处理模块正采用该第二系输入模块的数据作为主数据进行处理的,则此时需要切换到采用第一系输入模块的备用数据进行后续处理。若第一系统101的第一系输入模块103也未通过二取二表决,则整个安全计算机系统进入安全状态。The second system input unit A and the second system input unit B respectively perform two-two voting on the collected two digital analog input (for example, safety-related signals) to form safety input data. That is, the second system input unit A and the second system input unit B exchange data collected by both parties. The second line input unit A and the second line input unit B then compare the data collected by themselves with the exchanged data in the respective input units. If the comparison result is the same (that is, the data collected by the two input units A, B is the same, and the two votes are passed), the collected digital analog input is transmitted to the second transmission module 114. If the two are not the same (that is, the data collected by the two input units A, B are not the same, failing to take two votes), it indicates that the second-line input module 106 is faulty and needs to stop working. If the main processing module and the standby processing module are processing the data of the second system input module as the main data, then it is necessary to switch to the standby data using the first system input module for subsequent processing. If the first system input module 103 of the first system 101 also fails to take two votes, the entire secure computer system enters a secure state.
在一个实施例中,第二系输入模块106可以包括一个或多个输入插件,用于采集该数字量模拟量输入。In one embodiment, the second series input module 106 can include one or more input plug-ins for acquiring the digital analog input.
第一系统101的第一系输入模块103和第二系统102的第二系输入模块106互为冗余热备。即,两个输入模块同时工作,其中一个输入模块提供的数据供主处理模块和备用处理模块作为主数据进行处理,另一个输入模块提供的数据供主处理模块和备用处理模块作备用数据。当提供主数据的这个输入模块出现故障时,则另一输入模块所提供的数据由备用数据转变为主数据,供主处理模块和备用处理模块进行处理。若第一系输入模块103和第二系输入模块106同时故障、未插入或未激活,则整个安全计算机系统进入安全状态。The first system input module 103 of the first system 101 and the second system input module 106 of the second system 102 are redundant hot standby. That is, the two input modules work simultaneously, and the data provided by one input module is processed by the main processing module and the standby processing module as main data, and the data provided by the other input module is used by the main processing module and the standby processing module as spare data. When the input module providing the main data fails, the data provided by the other input module is converted from the standby data into the main data for processing by the main processing module and the standby processing module. If the first system input module 103 and the second system input module 106 fail, are not inserted, or are not activated at the same time, the entire secure computer system enters a secure state.
第一系传输模块113将数字量模拟量输入与通信输入进行汇总并直接或间接地传输至主处理模块和备用处理模块。第一系传输模块113还将主处理模块处理后的数据拆分成数字量模拟量输出和通信输出,并直接或间接地传输至第一系输出模块。The first system transmission module 113 aggregates the digital analog input and the communication input and directly or indirectly transmits to the main processing module and the standby processing module. The first system transmission module 113 also splits the data processed by the main processing module into digital analog output and communication output, and directly or indirectly transmits to the first system output module.
第一系传输模块113传输数据的方式可采用以太网模式或者FlexRay模式。对于FlexRay模式,第一系输出模块113将汇总后的输入数据通过FlexRay总线直接发送至主处理模块和备用处理模块,并将拆分后的数字量模拟量输出和通信输出通过FlexRay总线直接传输至第一系输出模块。对于以太网模式,第一系输出模块113将 汇总后的输入数据通过以太网交换机间接发送至主处理模块和备用处理模块,并将拆分后的数字量模拟量输出和通信输出通过太网交换机间接传输至第一系输出模块。The first system transmission module 113 can transmit data in an Ethernet mode or a FlexRay mode. For the FlexRay mode, the first system output module 113 sends the summarized input data directly to the main processing module and the standby processing module through the FlexRay bus, and directly transmits the split digital analog output and communication output to the FlexRay bus to the The first system is the output module. For Ethernet mode, the first system output module 113 will The summarized input data is indirectly sent to the main processing module and the standby processing module through the Ethernet switch, and the split digital analog output and the communication output are indirectly transmitted to the first system output module through the Ethernet switch.
值得注意的是,第一系传输模块113将汇总后的输入数据还分发至备用处理模块的好处在于,由于主处理模块和备用处理模块在正常状态下是采用相同的数据(例如来自同一传输模块的数据)进行处理的,一旦主处理模块出现故障,主处理模块可以直接切换到备用处理模块,以实现无缝切换。It is worth noting that the benefit of the first-line transmission module 113 also distributing the aggregated input data to the backup processing module is that the primary processing module and the standby processing module use the same data under normal conditions (eg, from the same transmission module). The data is processed. Once the main processing module fails, the main processing module can directly switch to the standby processing module to achieve seamless switching.
在一个实施例中,第一系传输模块113可以是一通信插件。In one embodiment, the first system transmission module 113 can be a communication card.
第二系传输模块114将数字量模拟量输入与通信输入进行汇总并直接或间接地传输至所述主处理模块和所述备用处理模块。第二系传输模块114还将主处理模块处理后的数据拆分成数字量模拟量输出和通信输出,并直接或间接地传输至第二系输出模块。The second system transmission module 114 aggregates the digital analog input and the communication input and transmits it directly or indirectly to the main processing module and the standby processing module. The second system transmission module 114 also splits the data processed by the main processing module into digital analog output and communication output, and directly or indirectly transmits to the second system output module.
第二系传输模块114传输数据的方式可采用以太网模式或者FlexRay模式。对于FlexRay模式,第二系输出模块114将汇总后的输入数据通过FlexRay总线直接发送至主处理模块和备用处理模块,并将拆分后的数字量模拟量输出和通信输出通过FlexRay总线直接传输至第二系输出模块。对于以太网模式,第二系输出模块114将汇总后的输入数据通过以太网交换机间接发送至主处理模块和备用处理模块,并将拆分后的数字量模拟量输出和通信输出通过太网交换机间接传输至第二系输出模块。The second system transmission module 114 can transmit data in an Ethernet mode or a FlexRay mode. For the FlexRay mode, the second system output module 114 sends the summarized input data directly to the main processing module and the standby processing module through the FlexRay bus, and directly transmits the split digital analog output and communication output to the FlexRay bus to the The second system is an output module. For the Ethernet mode, the second system output module 114 sends the summarized input data to the main processing module and the standby processing module indirectly through the Ethernet switch, and passes the split digital analog output and communication output through the Ethernet switch. Indirect transmission to the second system output module.
值得注意的是,第二系传输模块114还将汇总后的输入数据分发至备用处理模块的好处在于,由于主处理模块和备用处理模块在正常状态下是采用相同的数据(例如来自同一传输模块的数据)进行处理的,一旦主处理模块出现故障,主处理模块可以直接切换到备用处理模块,以实现无缝切换。It is worth noting that the second system transmission module 114 also distributes the aggregated input data to the backup processing module because the main processing module and the standby processing module use the same data under normal conditions (for example, from the same transmission module). The data is processed. Once the main processing module fails, the main processing module can directly switch to the standby processing module to achieve seamless switching.
在一个实施例中,第二系传输模块114可以是一通信插件。In one embodiment, the second system transmission module 114 can be a communication card.
第一系处理模块104获取两系传输模块113、114传输的输入数据,选择其中一个传输模块所传输的输入数据进行处理,例如逻辑控制、协议解析等,并存储另一个传输模块所传输的输入数据作为备用。该第一系处理模块104包括第一系处理器A、第一系处理器B,各自进行数据处理和二取二表决。The first system processing module 104 acquires input data transmitted by the two- line transmission modules 113, 114, selects input data transmitted by one of the transmission modules for processing, such as logic control, protocol analysis, etc., and stores input transmitted by another transmission module. The data is used as a backup. The first system processing module 104 includes a first system processor A and a first system processor B, each performing data processing and two-vote voting.
第二系处理模块107获取两系传输模块113、114传输的输入数据,选择其中一个传输模块所传输的输入数据进行处理,例如逻辑控制、协议解析等,并存储另一个传输模块所传输的输入数据作为备用。该第二系处理模块107包括第二系处理器A、第二系处理器B,各自进行数据处理和二取二表决。 The second system processing module 107 acquires the input data transmitted by the two- system transmission modules 113, 114, selects the input data transmitted by one of the transmission modules for processing, such as logic control, protocol analysis, etc., and stores the input transmitted by another transmission module. The data is used as a backup. The second system processing module 107 includes a second system processor A and a second system processor B, each performing data processing and two-vote voting.
如前所述,第一系处理模块104和第二系处理模块107中的一个处理模块可作为主处理模块,另一个作为备用处理模块。As described above, one of the first processing module 104 and the second processing module 107 can function as a primary processing module and the other as a backup processing module.
主处理模块同时接收第一系传输模块和第二系传输模块所传来的数据。主处理模块可以根据需求选择第一系传输模块和第二系传输模块中任一个所传输的数据作为主数据进行处理,例如逻辑控制、协议解析等。并将另一个传输模块所传输的数据作为备用数据,以便当主数据不可用时能及时采用备用数据进行继续处理,主处理模块将处理后的数据同时输出至第一系传输模块和第二系传输模块,供第一系输出模块和第二系输出模块进行后续的安全性验证。The main processing module simultaneously receives data transmitted by the first system transmission module and the second system transmission module. The main processing module can select, as the main data, data transmitted by any one of the first system transmission module and the second system transmission module as required, such as logic control, protocol analysis, and the like. And the data transmitted by the other transmission module is used as the backup data, so that the standby data can be continuously processed in time when the main data is unavailable, and the main processing module simultaneously outputs the processed data to the first system transmission module and the second system transmission module. For the first system output module and the second system output module for subsequent security verification.
所述备用处理模块同时接收第一系传输模块和第二系传输模块所传来的数据。在主处理模块确定了选择哪一系的传输模块所传输的数据作为主数据后,备用处理模块也对该同样的主数据进行处理。即,主处理模块和备用处理模块在同一时间处理的是来自同一个系统(或者同一个传输模块)的数据。同时,备用处理模块将另一个传输模块所传输的数据作为备用数据,以便当主数据不可用时能及时采用备用数据进行继续处理,备用处理模块不将处理后的数据输出至任何传输模块。The standby processing module simultaneously receives data transmitted by the first system transmission module and the second system transmission module. After the main processing module determines which data is transmitted by the transmission module as the main data, the standby processing module also processes the same main data. That is, the main processing module and the standby processing module process data from the same system (or the same transmission module) at the same time. At the same time, the standby processing module uses the data transmitted by the other transmission module as the standby data, so that the standby data can be continuously processed in time when the main data is unavailable, and the standby processing module does not output the processed data to any transmission module.
这里提到的主数据不可用指的是主数据所对应的系统的输入模块和传输模块中的一者或多者停止工作或出现故障(例如二取二表决未通过)。The unavailability of the master data mentioned here means that one or more of the input module and the transmission module of the system corresponding to the master data are stopped or malfunctioning (for example, two votes are not passed).
主处理模块包括主处理单元A、主处理单元B。The main processing module includes a main processing unit A and a main processing unit B.
主处理单元A对主数据进行处理,并且存储备用数据,以便当主数据不可用时能及时采用备用数据进行后续处理。The main processing unit A processes the main data and stores the spare data so that the standby data can be used for subsequent processing when the main data is unavailable.
主处理单元B对同样的主数据进行处理,并且存储备用数据,以便当主数据不可用时能及时采用备用数据进行后续处理。The main processing unit B processes the same main data and stores the spare data so that the standby data can be used for subsequent processing when the main data is not available.
主处理单元A和主处理单元B还各自进行二取二表决。即,主处理单元A和主处理单元B各自交换双方处理后的数据并进行比较,若相同,则主处理模块将处理后的数据发送至第一系传输模块和第二系传输模块,同时主处理模块处理后的数据与备用处理模块进行周期性地同步;若不同,则停止工作,并切换至备用处理模块工作,若备用处理模块也停止工作,则安全计算机系统进入安全状态。The main processing unit A and the main processing unit B also each perform two votes. That is, the main processing unit A and the main processing unit B each exchange the processed data and compare them. If they are the same, the main processing module sends the processed data to the first system transmission module and the second system transmission module, and simultaneously The processed data of the processing module is periodically synchronized with the standby processing module; if it is different, the operation is stopped, and the operation is switched to the standby processing module. If the standby processing module also stops working, the secure computer system enters a safe state.
备用处理模块包括备用处理单元A、备用处理单元B。The standby processing module includes a standby processing unit A and a standby processing unit B.
备用处理单元A对同样的主数据进行处理,并且存储备用数据,以便当主数据不可用时能及时采用备用数据进行继续处理。 The standby processing unit A processes the same main data and stores the spare data so that the standby data can be used in time to continue processing when the main data is unavailable.
备用处理单元B对同样的主数据进行处理,并且存储备用数据,以便当主数据不可用时能及时采用备用数据进行继续处理。The standby processing unit B processes the same main data and stores the spare data so that the standby data can be used in time to continue processing when the main data is unavailable.
备用处理单元A和备用处理单元B各自进行二取二表决。即,备用处理单元A和备用处理单元B各自对双方所处理后的数据进行交换和比较,若相同,则备用处理模块将处理后的数据与主处理模块进行周期性地同步。若不相同,则停止工作。此处需要注意的是,备用处理模块所处理的数据并不输出给任何传输模块。The standby processing unit A and the standby processing unit B each perform two votes. That is, the standby processing unit A and the standby processing unit B each exchange and compare the data processed by the two parties. If they are the same, the standby processing module periodically synchronizes the processed data with the main processing module. If they are not the same, stop working. It should be noted here that the data processed by the standby processing module is not output to any transmission module.
从以上描述可以知道,在正常情况下,只有主处理模块输出数据,备用处理模块不输出数据。这样设计的目的在于,由于输入、传输、处理这三个模块的设计使得整个安全计算机系统的可靠性已经有了充分的保证,因此,在输出模块阶段可以减少一个系统的处理输出(例如,备用处理模块不再有输出),以降低整个安全计算机系统的通信数据量。As can be seen from the above description, under normal circumstances, only the main processing module outputs data, and the standby processing module does not output data. The purpose of this design is that the reliability of the entire secure computer system is fully guaranteed due to the design of the three modules of input, transmission and processing. Therefore, the processing output of one system can be reduced in the output module stage (for example, standby). The processing module no longer has an output) to reduce the amount of communication data for the entire secure computer system.
此外,主处理模块和备用处理模块实时进行系间同步,以确保主处理模块出现故障(例如出现二取二表决不通过的情况)时,备用处理模块能及时获得同步的且刚经过安全处理的最新数据并转而作为主处理模块来进行后续处理。若两系的处理模块同时故障,则安全计算机系统进入安全状态。In addition, the main processing module and the standby processing module perform inter-system synchronization in real time to ensure that the main processing module fails (for example, when two or two voting fails), the standby processing module can obtain synchronous and just processed security in time. The latest data is transferred to the main processing module for subsequent processing. If the two processing modules fail at the same time, the secure computer system enters a safe state.
第一系输出模块105包括第一系输出单元A、第一系输出单元B。对于数字量模拟量输出(例如安全相关信号输出),第一系输出单元A和第一系输出单元B均对其有效性进行安全验证。第一系输出单元A和第一系输出单元B互相交换安全验证后的数据并在各自输出单元中对该数据进行比较,若两者相同,则可将数字量模拟量输出通过输出执行器件输出。若两者不相同(即未通过二取二表决),则第一系输出模块停止工作。若第二系统102的第二系输出模块108也未通过二取二表决,则整个安全计算机系统进入安全状态。The first system output module 105 includes a first system output unit A and a first system output unit B. For digital analog outputs (eg, safety related signal outputs), both the first system output unit A and the first system output unit B perform safety verification of their effectiveness. The first system output unit A and the first system output unit B exchange safety-verified data with each other and compare the data in the respective output units. If the two are the same, the digital analog output can be output through the output actuator. . If the two are not the same (ie, failing to take two votes), the first output module stops working. If the second system output module 108 of the second system 102 also fails to take two votes, the entire secure computer system enters a secure state.
在一个实施例中,第一系统对输出进行采集以反馈到反馈电路中,用来判断输出的正确性。In one embodiment, the first system collects the output for feedback to the feedback circuit for determining the correctness of the output.
第二系输出模块108包括第二系输出单元A、第二系输出单元B。对于数字量模拟量输出(例如安全相关信号输出),第二系输出单元A和第二系输出单元B均对其有效性进行安全验证。第二系输出单元A和第二系输出单元B互相交换安全验证后的数据并在各自输出单元中对其进行比较,若两者相同,则可将数字量模拟量输出通过执行器件输出。若两者不相同(即未通过二取二表决),则第二系输出模块停止工作。此时,若第一系输出模块105也出现故障,则整个安全计算机系统进入安全状态。 The second system output module 108 includes a second system output unit A and a second system output unit B. For digital analog outputs (eg, safety related signal outputs), both the second system output unit A and the second system output unit B perform safety verification of their effectiveness. The second system output unit A and the second system output unit B exchange safety-verified data with each other and compare them in respective output units. If the two are the same, the digital analog output can be output through the execution device. If the two are not the same (ie, failing to take two votes), the second output module stops working. At this time, if the first system output module 105 also fails, the entire secure computer system enters a safe state.
在一个实施例中,第二系统对输出进行采集以反馈到反馈电路中,用来判断输出的正确性。In one embodiment, the second system collects the output for feedback to the feedback circuit for determining the correctness of the output.
本发明的安全计算机系统是一个特殊设计的二乘二取二系统,其不但同时具有可靠性高以及安全性高的优点,其还具有松散耦合的特点,两系输入输出模块各自采集、各自输出,相互间独立性较高,不互相影响。例如,主系的输入模块、传输模块、处理模块、输出模块中任何一个或多个模块出现问题,只要不是采集或驱动同一对象的模块故障系统都能正常工作。The safety computer system of the invention is a specially designed two-by-two-two system, which not only has the advantages of high reliability and high safety, but also has the characteristics of loose coupling, and the two-system input and output modules respectively collect and output respectively. They are highly independent of each other and do not affect each other. For example, if there is a problem with any one or more of the input module, transmission module, processing module, and output module of the main system, the system can work normally as long as it is not a module that collects or drives the same object.
这里采用的术语和表述方式只是用于描述,本发明并不应局限于这些术语和表述。使用这些术语和表述并不意味着排除任何示意和描述(或其中部分)的等效特征,应认识到可能存在的各种修改也应包含在权利要求范围内。其他修改、变化和替换也可能存在。相应的,权利要求应视为覆盖所有这些等效物。The terms and expressions employed herein are for illustrative purposes only and the invention is not limited to the terms and expressions. The use of these terms and expressions is not intended to be exhaustive or to limit the scope of the invention. Other modifications, changes, and replacements may also exist. Accordingly, the claims are to be construed as covering all such equivalents.
同样,需要指出的是,虽然本发明已参照当前的具体实施例来描述,但是本技术领域中的普通技术人员应当认识到,以上的实施例仅是用来说明本发明,在没有脱离本发明精神的情况下还可做出各种等效的变化或替换,因此,只要在本发明的实质精神范围内对上述实施例的变化、变型都将落在本申请的权利要求书的范围内。 Also, it should be noted that although the present invention has been described with reference to the present embodiments, it will be understood by those skilled in the art that Various equivalent changes or substitutions may be made in the case of the spirit, and it is intended that the changes and modifications of the above-described embodiments within the scope of the spirit of the present invention fall within the scope of the claims of the present application.

Claims (13)

  1. 一种用于列车控制的安全计算机系统,其特征在于,所述安全计算机系统包括第一系统和第二系统,所述第一系统和所述第二系统互为冗余,其中:A secure computer system for train control, characterized in that the secure computer system comprises a first system and a second system, the first system and the second system being mutually redundant, wherein:
    所述第一系统包括第一系输入模块、第一系传输模块、第一系处理模块、第一系输出模块;所述第二系统包括第二系输入模块、第二系传输模块、第二系处理模块、第二系输出模块;所述第一系处理模块和所述第二系处理模块中的一个为主处理模块,另一个为备用处理模块;The first system includes a first system input module, a first system transmission module, a first system processing module, and a first system output module; the second system includes a second system input module, a second system transmission module, and a second system. a processing module, a second system output module; one of the first system processing module and the second system processing module is a main processing module, and the other is a standby processing module;
    所述第一系输入模块和所述第二系输入模块各自被配置成采集外部信号以获得输入数据并对所述输入数据进行二取二表决,当二取二表决通过时,各输入模块通过其对应的传输模块将所述输入数据发送至所述主处理模块和所述备用处理模块;当二取二表决不通过时,则停止工作;The first system input module and the second system input module are each configured to acquire an external signal to obtain input data and perform two-vote voting on the input data. When two votes are passed, each input module passes The corresponding transmission module sends the input data to the main processing module and the standby processing module; when the two votes are not passed, the operation is stopped;
    所述主处理模块和所述备用处理模块各自被配置成对来自同一传输模块的所述输入数据进行处理并进行二取二表决,当所述主处理模块的二取二表决不通过时,则所述主处理模块停止工作,并切换至二取二表决通过的所述备用处理模块进行后续处理,所述备用处理模块此时转为所述主处理模块;The main processing module and the standby processing module are each configured to process the input data from the same transmission module and perform two-vote and two-vote. When the two-vote voting of the main processing module fails, the The main processing module stops working, and switches to the standby processing module that passes through two votes for subsequent processing, and the standby processing module is converted to the main processing module at this time;
    所述第一系输出模块和所述第二系输出模块各自被配置成对所述主处理模块处理后的数据进行有效性验证并进行二取二表决,当二取二表决不通过时,则停止工作。The first system output module and the second system output module are each configured to perform validity verification on the data processed by the main processing module and perform two-vote and two-vote, and when two or two votes are not passed, stop working.
  2. 如权利要求1所述的安全计算机系统,其特征在于,所述第一系输入模块包括第一系输入单元A、第一系输入单元B;The secure computer system according to claim 1, wherein the first system input module comprises a first system input unit A and a first system input unit B;
    所述第一系输入单元A被配置成对所述外部进行采集,获得采集后的数字量模拟量输入;The first system input unit A is configured to collect the external, and obtain the digital analog input after the acquisition;
    所述第一系输入单元B被配置成对所述同样的外部进行采集,获得采集后的数字量模拟量输入;The first system input unit B is configured to collect the same external, and obtain the collected digital analog input;
    所述第一系输入单元A和所述第一系输入单元B各自还被配置成对双方所采集后的数字量模拟量输入进行交换和比较,若相同,则所述第一系输入模块将所述采集后的数字量模拟量输入发送至所述第一系传输模块;若不同,则所述第一系输入模块停止工作,若所述第二系输入模块也停止工作,则所述安全计算机系统进入安全状态。 The first system input unit A and the first system input unit B are each configured to exchange and compare the digital analog input signals collected by the two parties. If they are the same, the first system input module will The collected digital analog input is sent to the first transmission module; if different, the first input module stops working, and if the second input module stops working, the security The computer system enters a safe state.
  3. 如权利要求1所述的安全计算机系统,其特征在于,所述第二系输入模块包括第二系输入单元A、第二系输入单元B;The secure computer system according to claim 1, wherein said second system input module comprises a second system input unit A and a second system input unit B;
    所述第二系输入单元A被配置成对所述外部进行采集,获得采集后的数字量模拟量输入;The second system input unit A is configured to collect the external, and obtain the digital analog input after the acquisition;
    所述第二系输入单元B被配置成对所述同样的外部进行采集,获得采集后的数字量模拟量输入;The second system input unit B is configured to collect the same external, and obtain the collected digital analog input;
    所述第二系输入单元A和所述第二系输入单元B各自还被配置成对双方所采集后的数字量模拟量输入进行交换和比较,若相同,则所述第二系输入模块将所述采集后的数字量模拟量输入发送至所述第二系传输模块;若不同,则所述第二系输入模块停止工作,若所述第一系输入模块也停止工作,则所述安全计算机系统进入安全状态。The second system input unit A and the second system input unit B are each configured to exchange and compare the digital analog input signals collected by the two parties. If they are the same, the second system input module will The collected digital analog input is sent to the second transmission module; if different, the second input module stops working, and if the first input module stops working, the security The computer system enters a safe state.
  4. 如权利要求2所述的安全计算机系统,其特征在于,所述第一系传输模块被配置成将所述数字量模拟量输入与通信输入进行汇总并直接或间接地传输至所述主处理模块和所述备用处理模块;所述第一系传输模块还被配置成将所述主处理模块处理后的数据拆分成数字量模拟量输出和通信输出,并直接或间接地传输至所述第一系输出模块。The secure computer system of claim 2 wherein said first system transmission module is configured to aggregate said digital analog input and communication input and directly or indirectly transmit to said main processing module And the standby processing module; the first system transmission module is further configured to split the data processed by the main processing module into a digital analog output and a communication output, and directly or indirectly transmit to the A series of output modules.
  5. 如权利要求3所述的安全计算机系统,其特征在于,所述第二系传输模块被配置成将所述数字量模拟量输入与通信输入进行汇总并直接或间接地传输至所述主处理模块和所述备用处理模块;所述第二系传输模块还被配置成将所述主处理模块处理后的数据拆分成数字量模拟量输出和通信输出,并直接或间接地传输至所述第二系输出模块。The secure computer system of claim 3 wherein said second system transmission module is configured to aggregate said digital analog input and communication input and transmit directly or indirectly to said main processing module And the standby processing module; the second system transmission module is further configured to split the data processed by the main processing module into a digital analog output and a communication output, and directly or indirectly transmit to the Second-line output module.
  6. 如权利要求1所述的安全计算机系统,其特征在于:The secure computer system of claim 1 wherein:
    所述主处理模块被配置成可根据需求选择所述第一系传输模块和所述第二系传输模块中任一个所传输的数据作为主数据进行处理,并将另一个传输模块所传输的数据作为备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理,所述主处理模块将处理后的数据同时输出至所述第一系传输模块和第二系传输模块; The main processing module is configured to select, according to requirements, data transmitted by any one of the first system transmission module and the second system transmission module as main data, and transmit data transmitted by another transmission module. As the backup data, when the main data is unavailable, the standby data can be used to continue processing in time, and the main processing module simultaneously outputs the processed data to the first system transmission module and the second system transmission module;
    所述备用处理模块被配置成处理与所述主处理模块相同的所述主数据,并将另一个传输模块所传输的数据作为备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理,所述备用处理模块不将处理后的数据输出至任何传输模块。The standby processing module is configured to process the same primary data as the primary processing module and use data transmitted by another transmission module as backup data to enable timely use of the primary data when the primary data is unavailable. The data continues to be processed, and the standby processing module does not output the processed data to any of the transmission modules.
  7. 如权利要求6所述的安全计算机系统,其特征在于,所述主处理模块包括主处理单元A、主处理单元B;The secure computer system according to claim 6, wherein the main processing module comprises a main processing unit A and a main processing unit B;
    所述主处理单元A被配置成对所述主数据进行处理,并且存储所述备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理;The main processing unit A is configured to process the main data and store the standby data to enable the standby data to be processed in time when the main data is unavailable;
    所述主处理单元B被配置成对所述主数据进行处理,并且存储所述备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理;The main processing unit B is configured to process the main data, and store the backup data to enable the standby data to be processed in time when the main data is unavailable;
    所述主处理单元A和所述主处理单元B各自对双方所处理后的数据进行交换和比较,若相同,则所述主处理模块将所述处理后的数据发送至所述第一系传输模块和所述第二系传输模块,同时所述主处理模块处理后的数据与所述备用处理模块进行周期性地同步;若不同,则停止工作,并切换至所述备用处理模块工作,若所述备用处理模块也停止工作,则所述安全计算机系统进入安全状态。The main processing unit A and the main processing unit B respectively exchange and compare the data processed by the two parties. If they are the same, the main processing module sends the processed data to the first transmission. a module and the second system transmission module, wherein the data processed by the main processing module is periodically synchronized with the standby processing module; if not, the operation is stopped, and the operation is switched to the standby processing module. The standby processing module also stops working, and the secure computer system enters a secure state.
  8. 如权利要求6所述的安全计算机系统,其特征在于,所述备用处理模块包括备用处理单元A、备用处理单元B;The secure computer system according to claim 6, wherein said standby processing module comprises a standby processing unit A and a standby processing unit B;
    所述备用处理单元A被配置成对所述主数据进行处理,并且存储所述备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理;The standby processing unit A is configured to process the primary data and store the standby data to enable the standby data to be processed in time when the primary data is unavailable;
    所述备用处理单元B被配置成对所述主数据进行处理,并且存储所述备用数据,以便当所述主数据不可用时能及时采用所述备用数据进行继续处理;The standby processing unit B is configured to process the primary data and store the standby data to enable the standby data to be processed in time when the primary data is unavailable;
    所述备用处理模块所处理的数据并不输出给任何传输模块,所述备用处理单元A和备用处理单元B对双方所处理后的数据进行交换和比较,若相同,则所述备用处理模块将处理后的数据与所述主处理模块进行周期性地同步;若不相同,则停止工作。The data processed by the standby processing module is not output to any transmission module, and the standby processing unit A and the standby processing unit B exchange and compare the data processed by the two parties. If they are the same, the standby processing module will The processed data is periodically synchronized with the main processing module; if not, the operation is stopped.
  9. 如权利要求6所述的安全计算机系统,其特征在于,所述第一系输出模块包括第一系输出单元A、第一系输出单元B;The secure computer system according to claim 6, wherein the first system output module comprises a first system output unit A and a first system output unit B;
    所述第一系输出单元A被配置成对来自所述主处理模块的所述数字量模拟量输出进行有效性验证; The first system output unit A is configured to verify validity of the digital analog output from the main processing module;
    所述第一系输出单元B被配置成对同样的所述数字量模拟量输出进行有效性验证;The first system output unit B is configured to perform validity verification on the same digital analog output;
    所述第一系输出单元A和所述第一系输出单元B对双方所验证后的数据进行交换和比较,若相同,则将所述验证后的数据输出至第一系输出执行器件;若不同,则停止工作,若所述第二系输出模块也停止工作,则所述安全计算机系统进入安全状态。The first system output unit A and the first system output unit B exchange and compare the data verified by the two parties. If they are the same, the verified data is output to the first system output execution device; If not, the work is stopped, and if the second system output module also stops working, the secure computer system enters a safe state.
  10. 如权利要求7所述的安全计算机系统,其特征在于,所述第二系输出模块包括第二系输出单元A、第二系输出单元B;The secure computer system according to claim 7, wherein said second system output module comprises a second system output unit A and a second system output unit B;
    所述第二系输出单元A被配置成对来自所述主处理模块的所述数字量模拟量输出进行有效性验证;The second system output unit A is configured to verify validity of the digital analog output from the main processing module;
    所述第二系输出单元B被配置成对同样的所述数字量模拟量输出进行有效性验证;The second system output unit B is configured to perform validity verification on the same digital analog output;
    所述第二系输出单元A和所述第二系输出单元B对双方所验证后的数据进行交换和比较,若相同,则将所述验证后的数据输出至第二系输出执行器件;若不同,则停止工作若所述第一系输出模块也停止工作,则所述安全计算机系统进入安全状态。The second system output unit A and the second system output unit B exchange and compare the data verified by the two parties. If they are the same, the verified data is output to the second system output execution device; If not, the work is stopped. If the first system output module also stops working, the secure computer system enters a safe state.
  11. 如权利要求4或5所述的安全计算机系统,其特征在于,所述第一系传输单元以及所述第二系传输单元采用以太网交换机进行数据传输或者采用FlexRay总线方式直接进行数据传输。The secure computer system according to claim 4 or 5, wherein the first transmission unit and the second transmission unit use an Ethernet switch for data transmission or a FlexRay bus for direct data transmission.
  12. 如权利要求1所述的安全计算机系统,其特征在于,所述第一系输入模块、所述第一系传输模块、所述第一系处理模块、所述第一系输出模块、所述第二系输入模块、所述第二系传输模块、所述第二系处理模块、所述第二系输出模块采用插件形式。The secure computer system according to claim 1, wherein said first system input module, said first system transmission module, said first system processing module, said first system output module, said The second system input module, the second system transmission module, the second system processing module, and the second system output module are in the form of a plug-in.
  13. 如权利要求8所述的安全计算机系统,其特征在于,所述主数据不可用表示所述主数据所对应的系统的输入模块和传输模块中的一者或多者停止工作。 The secure computer system of claim 8 wherein said primary data unavailability indicates that one or more of an input module and a transmission module of a system corresponding to said primary data ceases to function.
PCT/CN2016/103931 2015-12-21 2016-10-31 Safety computer system for use in train control WO2017107665A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510961136.3 2015-12-21
CN201510961136.3A CN105388890A (en) 2015-12-21 2015-12-21 Safety computer system for train control

Publications (1)

Publication Number Publication Date
WO2017107665A1 true WO2017107665A1 (en) 2017-06-29

Family

ID=55421264

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/103931 WO2017107665A1 (en) 2015-12-21 2016-10-31 Safety computer system for use in train control

Country Status (2)

Country Link
CN (1) CN105388890A (en)
WO (1) WO2017107665A1 (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107942820A (en) * 2017-12-19 2018-04-20 卡斯柯信号有限公司 The analog quantity redundant output device and method of a kind of high reliability
CN111874049A (en) * 2020-08-06 2020-11-03 北京交大思诺科技股份有限公司 Brake control system for safety computer of train control

Families Citing this family (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105388890A (en) * 2015-12-21 2016-03-09 株洲南车时代电气股份有限公司 Safety computer system for train control
CN108243023B (en) * 2016-12-23 2021-01-19 比亚迪股份有限公司 Computer platform based on rail transit
CN108008366B (en) * 2017-12-01 2020-08-04 北京润科通用技术有限公司 Radar target echo simulation method and system
CN108241359B (en) * 2017-12-15 2021-06-01 中国航空工业集团公司西安飞行自动控制研究所 Safety fault output method based on safebus bus
CN110095975A (en) * 2018-01-31 2019-08-06 株洲中车时代电气股份有限公司 A kind of redundancy control system
CN110406563A (en) * 2018-04-27 2019-11-05 比亚迪股份有限公司 Computer interlock system and its method for handover control, equipment, storage medium
CN110412862B (en) * 2018-04-27 2022-01-07 比亚迪股份有限公司 Computer interlocking system and switching control method, equipment and storage medium thereof
CN108829015A (en) * 2018-07-27 2018-11-16 卡斯柯信号有限公司 A kind of the universal input output safety platform and method in railway signal field
CN109677468A (en) * 2019-03-04 2019-04-26 中车青岛四方车辆研究所有限公司 Train logic control element and logic control method
CN110351174B (en) * 2019-07-19 2021-11-12 北京交大思诺科技股份有限公司 Module redundancy safety computer platform
CN110554978B (en) * 2019-08-30 2022-02-15 北京交大思诺科技股份有限公司 Safety computer platform realized by universal I/O module
CN110758489A (en) * 2019-11-13 2020-02-07 通号城市轨道交通技术有限公司 Automatic protection system of train
CN112395236A (en) * 2020-11-13 2021-02-23 中车株洲电力机车有限公司 Distributed vehicle-mounted safety computer system
CN114348057B (en) * 2021-12-14 2024-03-19 青岛海信微联信号有限公司 Main and standby decision control equipment and system and rail traffic control area controller

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101700783A (en) * 2009-11-11 2010-05-05 北京全路通信信号研究设计院 Train control center system platform
CN201941780U (en) * 2010-11-29 2011-08-24 北京交大微联科技有限公司 Automatic train protection (ATP) vehicle-mounted double 2-vote-2 system based on TMS570
CN103678031A (en) * 2012-09-10 2014-03-26 西门子信号有限公司 Double 2-vote-2 redundant system and method
CN103713959A (en) * 2013-12-31 2014-04-09 北京和利时系统工程有限公司 Task synchronization method
US20150007000A1 (en) * 2013-07-01 2015-01-01 Lisa Fredrickson Additional Error Correction Apparatus and Method
CN105388890A (en) * 2015-12-21 2016-03-09 株洲南车时代电气股份有限公司 Safety computer system for train control

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5086499A (en) * 1989-05-23 1992-02-04 Aeg Westinghouse Transportation Systems, Inc. Computer network for real time control with automatic fault identification and by-pass
CN201293929Y (en) * 2008-11-13 2009-08-19 南京恩瑞特实业有限公司 Universal safety type input-output controller for subway
US7877627B1 (en) * 2008-12-18 2011-01-25 Supercon, L.L.C. Multiple redundant computer system combining fault diagnostics and majority voting with dissimilar redundancy technology
CN102103532B (en) * 2011-01-26 2013-08-14 中国铁道科学研究院通信信号研究所 Safety redundancy computer system of train control vehicle-mounted equipment
CN105159863A (en) * 2015-09-09 2015-12-16 株洲南车时代电气股份有限公司 Secure computer platform used for rail transit

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101700783A (en) * 2009-11-11 2010-05-05 北京全路通信信号研究设计院 Train control center system platform
CN201941780U (en) * 2010-11-29 2011-08-24 北京交大微联科技有限公司 Automatic train protection (ATP) vehicle-mounted double 2-vote-2 system based on TMS570
CN103678031A (en) * 2012-09-10 2014-03-26 西门子信号有限公司 Double 2-vote-2 redundant system and method
US20150007000A1 (en) * 2013-07-01 2015-01-01 Lisa Fredrickson Additional Error Correction Apparatus and Method
CN103713959A (en) * 2013-12-31 2014-04-09 北京和利时系统工程有限公司 Task synchronization method
CN105388890A (en) * 2015-12-21 2016-03-09 株洲南车时代电气股份有限公司 Safety computer system for train control

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107942820A (en) * 2017-12-19 2018-04-20 卡斯柯信号有限公司 The analog quantity redundant output device and method of a kind of high reliability
CN107942820B (en) * 2017-12-19 2024-03-29 卡斯柯信号有限公司 High-reliability analog quantity redundant output device and method
CN111874049A (en) * 2020-08-06 2020-11-03 北京交大思诺科技股份有限公司 Brake control system for safety computer of train control

Also Published As

Publication number Publication date
CN105388890A (en) 2016-03-09

Similar Documents

Publication Publication Date Title
WO2017107665A1 (en) Safety computer system for use in train control
CN110361979B (en) Safety computer platform in railway signal field
CN107187465B (en) ATO system architecture of unit-level hot standby redundancy
CN110351174B (en) Module redundancy safety computer platform
US9625894B2 (en) Multi-channel control switchover logic
CN107942820B (en) High-reliability analog quantity redundant output device and method
CN110376876B (en) Double-system synchronous safety computer platform
CN102955903B (en) A kind of disposal route of safety critical information of rail transit computer control system
EP3699764B1 (en) Redundant ethernet-based secure computer system
TWI579667B (en) Programmable logic controller module and programmable logic controller
RU2679706C2 (en) Two-channel architecture
US9367375B2 (en) Direct connect algorithm
US11904918B2 (en) Computer interlocking system and switching control method for the same, device, and storage medium
CN103825791A (en) Method for controlling parallel redundancy of MVB master
WO2018113763A1 (en) Computer platform based on rail transit
CN109634171B (en) Dual-core dual-lock-step two-out-of-two framework and safety platform thereof
CN111874049B (en) Brake control system for safety computer of train control
CN106627668A (en) Train monitoring server system based on double-two-out-of-two framework and control method
WO2015152167A1 (en) Redundant control device and system switching method
CN110412862B (en) Computer interlocking system and switching control method, equipment and storage medium thereof
CN110758489A (en) Automatic protection system of train
KR20080052711A (en) System and signal processing method for railway control network by means of switched ethernet
JP5706347B2 (en) Redundant control system
US9003067B2 (en) Network and method for operating the network
US9002480B2 (en) Method for operation of a control network, and a control network

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16877476

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16877476

Country of ref document: EP

Kind code of ref document: A1