WO2022100232A1 - 一种分布式车载安全计算机系统 - Google Patents
一种分布式车载安全计算机系统 Download PDFInfo
- Publication number
- WO2022100232A1 WO2022100232A1 PCT/CN2021/116147 CN2021116147W WO2022100232A1 WO 2022100232 A1 WO2022100232 A1 WO 2022100232A1 CN 2021116147 W CN2021116147 W CN 2021116147W WO 2022100232 A1 WO2022100232 A1 WO 2022100232A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- safety
- standby
- state
- computer
- main
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F15/00—Digital computers in general; Data processing equipment in general
- G06F15/16—Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
- G06F15/161—Computing infrastructure, e.g. computer clusters, blade chassis or hardware partitioning
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/0703—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
- G06F11/079—Root cause analysis, i.e. error or fault diagnosis
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/30—Monitoring
- G06F11/3058—Monitoring arrangements for monitoring environmental properties or parameters of the computing system or of the computing system component, e.g. monitoring of power, currents, temperature, humidity, position, vibrations
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F15/00—Digital computers in general; Data processing equipment in general
- G06F15/16—Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
- G06F15/163—Interprocessor communication
- G06F15/173—Interprocessor communication using an interconnection network, e.g. matrix, shuffle, pyramid, star, snowflake
- G06F15/17337—Direct connection machines, e.g. completely connected computers, point to point communication networks
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/27—Replication, distribution or synchronisation of data between databases or within a distributed database system; Distributed database system architectures therefor
Definitions
- the invention particularly relates to a distributed vehicle-mounted safety computer system.
- the calculation is mainly performed by ground equipment, and the vehicle-mounted safety computer is used as the execution unit to realize automatic operation control.
- the vehicle's on-board safety computer sends information such as its own status and position to the ground equipment, and the ground equipment not only receives the vehicle's own status and position information, but also receives the information of all vehicles managed by the ground equipment.
- Feedback information (such as speed limit) is sent to the vehicle's on-board safety computer, and the on-board safety computer controls the operation of the vehicle according to the feedback information (such as speed limit).
- feedback information (such as speed limit) is sent to the vehicle's on-board safety computer, and the on-board safety computer controls the operation of the vehicle according to the feedback information (such as speed limit).
- the feedback information such as speed limit
- the low interaction efficiency may cause the vehicle to fail to adjust its operation according to the speed limit information in time.
- a single ground equipment manages multiple on-board safety computers.
- a single ground equipment manages up to 10 on-board safety computers.
- a single ground equipment needs to perform calculations according to the ground The information sent by all rail transit vehicles managed by the equipment and in operation is carried out. For example, there are 8 rail transit vehicles managed by the ground equipment in the running state. In each control cycle, the ground equipment needs to Sending information to calculate, the amount of calculation is large, which affects the calculation efficiency, thereby affecting the feedback time of the feedback information, and further affecting the interaction efficiency.
- the traditional on-board safety computer generally adopts a single-chassis design of 6U and above, and the mechanical size is large, which is not convenient for the flexible configuration and function expansion of the on-board safety computer. Configuration and scaling are even more impactful.
- the purpose of the present invention is to, in view of the problem of low information exchange efficiency due to the long information exchange path between ground equipment and on-board safety computer in the above-mentioned prior art, and the problem that the large size of the on-board safety computer system affects its configuration and function expansion, to provide a kind of
- the distributed vehicle-mounted safety computer system has the advantages of miniaturization, high performance, high safety, and flexible installation and configuration.
- the technical scheme adopted in the present invention is:
- a distributed vehicle-mounted safety computer system is characterized in that it includes two sets of safety computers with a two-out-two structure with the same structure and function.
- the communication bus realizes data synchronization;
- the main-standby switch board is used to control one set of the two sets of safety computers to work in the main system state and the other set to work in the standby system state, or to control the two sets of safety computers according to the working data and set logic of the two sets of safety computers.
- Two sets of safety computers are working in the standby system state; among them, working in the main system state means that the safety computer is used to receive and output data externally, and working in the standby system state means that the safety computer is only used to receive data externally and not used for external data. Export data externally.
- the on-board safety computer system of the vehicle only needs to receive the data of the adjacent vehicles in front of and behind the vehicle, and calculate according to the data of the adjacent vehicles in front and back and its own data, and then directly control according to the calculation results.
- the system In the operation of the vehicle, there is no information interaction between the system and the ground equipment in each operation control cycle.
- the system only exchanges information with the adjacent vehicles before and after it, which greatly shortens the information interaction path, improves the information interaction efficiency, and enables the vehicle to adjust its operation in time.
- the system of the present invention only needs to calculate the data of the adjacent vehicles before and after, which greatly reduces the amount of data, thereby reducing the calculation It improves the computing efficiency, further improves the interaction efficiency, and enables the vehicle to adjust its running state in a more timely manner.
- the data synchronization rules between the two sets of security computers include:
- the two sets of safety computers send heartbeat frames to each other. If the safety computer in the standby system judges that its data state is different from that of the safety computer in the main system state according to the heartbeat frame, the safety computer in the standby system state sends synchronization.
- the request frame is sent to the security computer in the main system state, and the security computer in the main system state sends the synchronization data to the security computer in the standby system state after receiving the synchronization request frame.
- each set of safety computers includes two main control boards, one voting board, at least one IO board and several communication boards;
- two main control boards are connected to realize data synchronization in a single machine.
- the main control board, IO board, and communication board are all connected to the voting board, and the voting board is connected to the main and standby switching boards. ;
- the voting boards of the two sets of safety computers are connected through a communication bus.
- the synchronization data of the two main control boards passes through the voting board. Output to a secure computer working in a standby state.
- the two main control boards perform data synchronization only when it is judged that the data received by the two main control boards are consistent.
- the logic for the active and standby switch boards to control the safety computer to work in the main system state or the standby system state includes: after the active and standby switch boards receive the level signals sent by the two sets of safety computers after power-on, according to the obtained The order of the level signals sent by the two sets of safety computers, the working state of the safety computer that sends the level signal first is the main system state, and the working state of the safety computer that sends the level signal after locking is the standby system state; The safety computer determines its own working state through the signal collected from the main and standby switch boards.
- the logic for the active and standby switching boards to control the safety computer to work in the main system state or the standby system state includes: when the safety computer in the main system state fails and stops sending level signals to the active and standby switching boards, the main The standby switch board locks the working state of the security computer originally in the main system state to the standby system state, and locks the working state of the security computer originally in the standby system state to the main system state; The recovered signal determines its own working state.
- the safety computer used to work in the main system state when receiving a high-level signal sent by the main and standby switch boards; used when receiving a low-level signal sent by the main and standby switch boards , working in the standby state;
- the logic of the active/standby switchboard to control the safety computer to work in the main system state or the standby system state also includes:
- the safety computer originally in the standby state switches to the main system state, which was originally in the state of the main system.
- the safety computer in the main system state is switched to the standby system state; if the safety computer originally in the standby system state returns to the high-level signal sent by the main and standby switching boards, but the data between the two sets of safety computers is not synchronized, then the two sets of safety computers All computers enter the standby system state; if both sets of safety computers fail, both sets of safety computers enter the standby system state.
- the logic of the active/standby switchboard controlling the security computer to work in the main system state or the standby system state further includes:
- the safety computer of this set will be downgraded to the standby system state when the safety computer is in the main system state; Restart the system when the computer is in the standby state;
- the security computer of this set will be downgraded to the standby system state when the security computer is in the main system state; Reboot the system when the security computer is in the standby state.
- the safety computer of this set will be downgraded to the standby system state when the safety computer is in the main system state, and the dynamic circuit will be released and the other system will be released.
- a set of security computers is upgraded to the main system state; the system is restarted when this set of security computers is in the standby system state.
- the present invention has the following beneficial effects:
- the vehicle-mounted safety computer system of the present invention only needs to receive the data of the adjacent vehicles, there is no information exchange between the vehicle and the ground equipment, the information exchange path is short, and the information exchange efficiency is high;
- the calculation speed is fast, which further improves the interaction efficiency, enables the vehicle to adjust the running state in time, and avoids the occurrence of safety accidents.
- the vehicle-mounted safety computer system of the present invention is composed of two sets of distributed two-for-two safety computers.
- the two sets of safety computers can be installed in a centralized cabinet or in a distributed installation mode, and can be flexibly installed according to different vehicle conditions. , with the advantages of miniaturization and flexible installation and configuration.
- the main-standby switching between the two sets of safety computers of the present invention is carried out through an independent main-standby switch board to ensure that only one set of safety computers is in the main system state at any time, and the main system state can be switched according to the working data of the two sets of safety computers. and standby system status, high performance and security.
- FIG. 1 is a combined architecture diagram of the present invention.
- FIG. 2 is a structural block diagram of the present invention.
- FIG. 3 is an architecture diagram of a security computer with a single set of two out of two structures.
- Figure 4 is a flow chart of the active and standby selection of two sets of security computers.
- Figure 5 is a flow chart of the master-slave switchover of two sets of safety computers.
- Figure 6 is a data flow diagram of a single set of secure computers.
- the distributed vehicle-mounted safety computer system of the present invention includes two sets of safety computers A and B with the same structure and function of two out of two structures, and the two sets of safety computers are connected through the main and standby switching boards. , and the two sets of safety computers realize data synchronization through the communication bus.
- the main-standby switch board is used to control one of the two sets of safety computers to work in the main system state and the other set to work in the standby system state, or to control two sets of safety computers according to the working data and set logic of the two sets of safety computers.
- the two sets are working in the standby system state; among them, working in the main system state means that the safety computer is used to receive and output data externally, and working in the standby system state means that the safety computer is only used to receive data externally but not externally output. data.
- external refers to outside the distributed vehicle-mounted safety computer system.
- each set of safety computers includes two main control boards, two 110V or 24V power boards, one voting board, at least one IO board and several communication boards; the power boards are selected according to the specific installation carrier. For example, the subway train selects 110VDC, the tram selects 24VDC, and the trolleybus selects 24VDC.
- the actual installation requires two independent power supplies; the communication boards include MVB communication boards, CAN+485 communication boards, and Ethernet communication boards. Choose MVB communication board, CAN+485 communication board, Ethernet communication board according to the actual situation, and configure the appropriate number of IO modules according to the actual digital input and output requirements, which has strong flexibility.
- the two main control boards are connected to realize data synchronization in the single machine.
- the main control board, IO board, and communication board are all connected to the voting board, and the voting board is connected to the main and standby switching boards.
- the voting boards of the two sets of safety computers are connected through the communication bus, that is, the voting boards and the main and standby switching boards are connected by hard wires, and the voting boards of the two sets of safety computers are connected by the communication bus.
- the active/standby switch board is a separate 1U device, or the active/standby switch board can be integrated into the safety computer A or the safety computer B in the form of a plug-in board.
- U stands for the abbreviation of the unit of the external dimension of the standard case, 1U is 4.445cm, 3U is 4.445 ⁇ 3cm.
- Safety computer A, safety computer B, and active/standby switch boards are designed as vehicle-mounted equipment. According to the project, the integrated upper and lower cabinets, left and right side-by-side installations can be used, or they can be installed in different vehicles or different cabinets as required, which is convenient and flexible. It is especially suitable for vehicles with tight installation space such as track and trackless trains.
- the distributed on-board safety computer system of the present invention is not only applicable to the SIL4 high safety equipment requirements of urban rail transit vehicles, such as subways, trams, trolleybuses, etc., but also applicable to other systems on vehicles with safety function requirements.
- the present invention includes the following parts:
- the distributed vehicle-mounted safety computer system of the present invention is composed of two sets of distributed two-out-two safety computers, each independent safety computer is called a system, composed of two main control boards to form a two-out-two structure, and includes two redundant It consists of a power supply board, a voting board, several IO boards (the number of boards can be configured according to the requirements of IO points) and communication boards (including MVB communication boards, CAN+485 communication boards, and Ethernet communication boards). Between the two sets of distributed safety computers, there is an inter-system synchronization channel and the master-standby switch board communicate with each other.
- Safety computer A and safety computer B are independent 3U miniaturized chassis. The two devices can be placed in a distributed or centralized manner, and the installation is flexible, especially suitable for trams and other situations where space is tight.
- the master-slave switch board can be used as an independent device, mainly to realize the master-slave switching of safety computer A and safety computer B, to ensure that only one of the two sets of safety computers is the master device at any time, ensuring the safety of vehicle operation control.
- the data synchronization between the two computers is realized through the communication bus between the safety computer A and the safety computer B, which ensures the safety of the vehicle operation control.
- the distributed safety computer system has flexible configuration and many application scenarios. Two sets of safety computers are combined to form a two-by-two architecture, which meets the requirements of high safety levels (such as SIL4); a separate set of two-out-two safety computers can As a general control platform to meet the requirements of lower safety levels of vehicles (eg SIL2 level).
- control chip on the main control board can not only ensure the realization of functions, but also reduce power consumption and cost.
- Data synchronization is performed between the two sets of safety computers through the communication bus, and the main system state and the standby system state are switched according to the synchronization state:
- safety computer A and the safety computer B When one set of safety computers in safety computer A and safety computer B is in the main system state and the other set of safety computers is in the standby system state, the safety computer A and the safety computer B periodically send heartbeat frames to each other, such as verification data .
- the standby system When the standby system finds that its data status is inconsistent with the data state of the main system according to the heartbeat frame, the standby system sends a synchronization request frame, and then the main system receives the synchronization request frame and sends the synchronized data state to the standby system to realize the standby system. Synchronize the data status with the master system.
- the data status synchronized by the master system to the backup system is first compared through the two main control boards of the main system. When the data states of the two main control boards are consistent, the data state is output to the backup system.
- the data state synchronization is performed to ensure that the status of the backup system is always consistent with the data state of the main system. Realize uninterrupted switchover between active and standby.
- both the safety computer A and the safety computer B are in the standby state, since both are in a degraded state, neither will output data externally, and there is no need to synchronize the data state.
- Safety computer A and safety computer B operate with redundant equipment.
- Safety computer A and safety computer B are respectively connected to the active and standby switch boards through hard wires, and the interlock circuit of the active and standby switch boards ensures that only one safety computer is in the main system at the same time.
- Status including active/standby working device selection (see Figure 4) and active/standby switchover (see Figure 5):
- the master-standby switch board judges the master-slave according to the order in which the safety computers A and B send the level signals.
- the working state of the safety computer that sends the level signal first is the system state, and then the safety computer that sends the level signal works.
- the state is the standby state; and the switching state is locked.
- the voting boards of safety computers A and B respectively retrieve the electrical signals of the master and standby switching boards through hard wires to obtain their own master-slave status. When the high-level signal is retrieved, it is the main system, and when the low-level signal is retrieved, it is the standby system. .
- the main system When the main system detects a fault, it stops sending level signals, and the main and standby switch boards switch and lock the A and B devices; at the same time, the voting board of the main system safety computer performs software logic between the main system and the standby system. Working status switch.
- the original working standby system picks up the high-level signal, and the data status of the active and standby systems is synchronized, the standby system is upgraded to the main system state, and the safety computer originally in the main system state is switched to the standby system state; when the standby system detects the main system state. If the data states of the systems are out of sync, both sets of safety computers will enter the standby system state; if both sets of safety computers fail, both sets of safety computers will enter the standby system state.
- a single set of safety computer includes two main control boards, one voting board, several IO boards and several communication boards.
- the number of IO boards is configured according to the needs of the actual application.
- the communication board can be configured with MVB communication board, CAN+RS485 communication board as required. board and Ethernet communication board.
- the data flow diagram of each board card of a single set of computer is shown in Figure 6.
- the data synchronization principle of a single set of security computers is as follows:
- External data is input through the communication board.
- the communication board sends data to the voting board through the communication bus.
- the voting board sends the same data to the two main control boards respectively through the communication bus.
- Periodic data synchronization is performed between the two main control boards through UART serial communication or backplane bus:
- the synchronization duration of the two main control boards exceeds the set operation cycle, the calculation exceeds the accumulated time.
- the synchronization duration of the two main control boards in consecutive N cycles exceeds the set operation cycle , when the security computer of this set is in the state of the main system, it is downgraded to the state of the standby system; when the security computer of this set is in the state of the standby system, the system is restarted.
- the two main control boards send the calculated data to the voting board, and the voting board uses FPGA to vote on the data (compare the data sent by the two main control boards to the voting board for consistency). If the data is consistent, it will output The result is sent to the communication board, which in turn sends the data to the external system, improving security.
- the main control board of the vehicle-mounted safety computer system of the present invention realizes self-fault diagnosis at two levels of software and hardware:
- the software judges faults such as illegal data, abnormal communication, pointer out-of-bounds and task timeout. Once a fault occurs and the data of the two main control boards is inconsistent, it will be actively downgraded, and if it cannot be downgraded, it will be restarted.
- the dynamic circuit refers to the circuit used to generate the level signal on the main control board.
- the dynamic circuit When the main system is downgraded to the standby system, the dynamic circuit is released, so that the main control board of the security computer originally working in the main system state generates a low level signal. level (that is, no high-level signal will be sent), and sent to the main-standby switch board to ensure the main-standby switch.
- level that is, no high-level signal will be sent
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Mathematical Physics (AREA)
- Software Systems (AREA)
- Computing Systems (AREA)
- Databases & Information Systems (AREA)
- Quality & Reliability (AREA)
- Data Mining & Analysis (AREA)
- Health & Medical Sciences (AREA)
- Biomedical Technology (AREA)
- Hardware Redundancy (AREA)
Abstract
Description
Claims (10)
- 一种分布式车载安全计算机系统,其特征在于,包括结构和功能完全相同的二取二结构的两套安全计算机,两套安全计算机之间通过主备切换板相连,且两套安全计算机之间通过通信总线实现数据同步;其中,主备切换板用于根据两套安全计算机的工作数据和设定的逻辑,控制两套安全计算机中的一套工作在主系状态而另一套工作在备系状态,或者控制两套安全计算机中的两套均工作在备系状态;其中,工作在主系状态是指安全计算机用于对外接收和输出数据,工作在备系状态是指安全计算机仅用于对外接收数据而不用于对外输出数据。
- 如权利要求1所述的分布式车载安全计算机系统,其特征在于,对于两套安全计算机中的一套工作在主系状态而另一套工作在备系状态,两套安全计算机之间的数据同步规则包括:两套安全计算机之间互相发送心跳帧,若处于备系状态的安全计算机根据心跳帧判断自身的数据状态不同于处于主系状态的安全计算机的数据状态,则处于备系状态的安全计算机发送同步请求帧至处于主系状态的安全计算机,处于主系状态的安全计算机接收到同步请求帧后即发送同步数据至处于备系状态的安全计算机。
- 如权利要求1或2所述的分布式车载安全计算机系统,其特征在于,每一套安全计算机均包括两块主控板、一块表决板、至少一块IO板和若干通信板;针对单套安全计算机,两主控板相连以用于实现单机内的数据同步,所述主控板、IO板、通信板均与表决板相连,所述表决板与主备切换板相连;两套安全计算机的表决板之间通过通信总线相连。
- 如权利要求3所述的分布式车载安全计算机系统,其特征在于,对于工作在主系状态的安全计算机,两主控板在进行同步数据比较之后并判断两主控板的同步数据一致的情况下,两主控板的同步数据通过表决板输出至工作在备系状态的安全计算机。
- 如权利要求3所述的分布式车载安全计算机系统,其特征在于,对于工作在备系状态的安全计算机,判断两主控板接收到的数据一致的情况下,两主控板才进行数据同步。
- 如权利要求1所述的分布式车载安全计算机系统,其特征在于,主备切换板控制安全计算机工作在主系状态或备系状态的逻辑包括:主备切换板在接收到两套安全计算机在上电后发送的电平信号后,根据获得的两套安全计算机发送的电平信号的先后顺序,锁定先发送电平信号的安全计算机的工作状态为主系状态,锁定后发送电平信号的安全计算机的工作状态为备系状态;两套安全计算机通过从主备切换板回采的信号确定自身的工作状态。
- 如权利要求1所述的分布式车载安全计算机系统,其特征在于,主备切换板控制安全计算机工作在主系状态或备系状态的逻辑包括:当处于主系状态的安全计算机出现故障并停止向主备切换板发送电平信号时,主备切换板将原本处于主系状态的安全计算机的工作状态锁定为备系状态,并将原本处于备系状态的安全计算机的工作状态锁定为主系状态;两套安全计算机通过从主备切换板回采的信号确定自身的工作状态。
- 如权利要求6或7所述的分布式车载安全计算机系统,其特征在于,安全计算机:用于在接收到主备切换板发送的高电平信号时,工作在主系状态;用于在接收到主备切换板发送的低电平信号时,工作在备系状态;主备切换板控制安全计算机工作在主系状态或备系状态的逻辑还包括:若原本处于备系状态的安全计算机回采到主备切换板发送的高电平信号,且两套安全计算机之间的数据同步,则原本处于备系状态的安全计算机切换至主系状态,原本处于主系状态的安全计算机切换至备系状态;若原本处于备系状态的安全计算机回采到主备切换板发送的高电平信号,但两套安全计算机之间的数据不同步,则两套安全计算机均进入备系状态;若两套安全计算机均出现故障,则两套安全计算机均进入备系状态。
- 如权利要求3所述的分布式车载安全计算机系统,其特征在于,主备切换板控制安全计算机工作在主系状态或备系状态的逻辑还包括:针对单套安全计算机,若两个主控板在连续N个周期内的同步时长均超过设定的运算周期,则在本套安全计算机处于主系状态时降级为备系状态;在本套安全计算机处于备系状态时重启系统;针对单套安全计算机,若一主控板在连续N个周期内均未收到另一主控板的有效数据,则在本套安全计算机处于主系状态时降级为备系状态;在本套安全 计算机处于备系状态时重启系统。
- 如权利要求1所述的分布式车载安全计算机系统,其特征在于,针对单套安全计算机,还设有硬件看门狗,在喂狗失败时,则在本套安全计算机处于主系状态时降级为备系状态,并释放动态电路且将另一套安全计算机升级为主系状态;在本套安全计算机处于备系状态时重启系统。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202011267117.8 | 2020-11-13 | ||
| CN202011267117.8A CN112395236A (zh) | 2020-11-13 | 2020-11-13 | 一种分布式车载安全计算机系统 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022100232A1 true WO2022100232A1 (zh) | 2022-05-19 |
Family
ID=74599366
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2021/116147 Ceased WO2022100232A1 (zh) | 2020-11-13 | 2021-09-02 | 一种分布式车载安全计算机系统 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN112395236A (zh) |
| WO (1) | WO2022100232A1 (zh) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116257389A (zh) * | 2023-05-16 | 2023-06-13 | 北京城建智控科技股份有限公司 | 基于全电子联锁系统的二乘二取二平台的同步方法 |
| CN118410495A (zh) * | 2024-06-26 | 2024-07-30 | 中国铁道科学研究院集团有限公司通信信号研究所 | 一种基于tsn的车载安全计算机平台及其数据处理方法 |
| WO2025232068A1 (zh) * | 2024-05-10 | 2025-11-13 | 北京全路通信信号研究设计院集团有限公司 | 安全计算系统的消息处理方法、装置、电子设备及存储介质 |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112395236A (zh) * | 2020-11-13 | 2021-02-23 | 中车株洲电力机车有限公司 | 一种分布式车载安全计算机系统 |
| CN113778751A (zh) * | 2021-08-31 | 2021-12-10 | 通号城市轨道交通技术有限公司 | 基于通用平台环境下的安全计算机系统及运行方法 |
| CN113848950A (zh) * | 2021-10-21 | 2021-12-28 | 广州文远知行科技有限公司 | 一种控制器控制方法、装置、交通工具及存储介质 |
| CN114124481A (zh) * | 2021-11-08 | 2022-03-01 | 北京许继电气有限公司 | 双级配网安全模块终端系统 |
| CN116534083B (zh) * | 2023-06-25 | 2025-08-19 | 哈尔滨市科佳通用机电股份有限公司 | 机车信号设备双系降级切换方法 |
| CN118069579A (zh) * | 2024-02-26 | 2024-05-24 | 北京全路通信信号研究设计院集团有限公司 | 一种具有双主控模块的安全计算机系统 |
Citations (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1484681A2 (de) * | 2003-04-29 | 2004-12-08 | Siemens Aktiengesellschaft | Rechnersystem mit einem Mastersystem, einem Slavesystem, und einer Datensychronisierungseinrichtung |
| CN102945221A (zh) * | 2012-10-18 | 2013-02-27 | 上海亨钧科技有限公司 | 一种全电子安全计算机联锁系统 |
| CN102951182A (zh) * | 2012-10-18 | 2013-03-06 | 上海亨钧科技有限公司 | 一种铁路专用安全计算机的工作方法 |
| CN105159863A (zh) * | 2015-09-09 | 2015-12-16 | 株洲南车时代电气股份有限公司 | 一种用于轨道交通的安全计算机平台 |
| CN105388890A (zh) * | 2015-12-21 | 2016-03-09 | 株洲南车时代电气股份有限公司 | 一种用于列车控制的安全计算机系统 |
| CN111645724A (zh) * | 2020-06-11 | 2020-09-11 | 湖南中车时代通信信号有限公司 | 一种车载安全计算机系统 |
| CN112395236A (zh) * | 2020-11-13 | 2021-02-23 | 中车株洲电力机车有限公司 | 一种分布式车载安全计算机系统 |
Family Cites Families (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7130703B2 (en) * | 2003-04-08 | 2006-10-31 | Fisher-Rosemount Systems, Inc. | Voter logic block including operational and maintenance overrides in a process control system |
| CN105739299B (zh) * | 2016-04-29 | 2020-01-07 | 固安信通信号技术股份有限公司 | 基于二乘二取二安全冗余系统的控制装置 |
| CN107885695B (zh) * | 2016-12-23 | 2019-02-26 | 比亚迪股份有限公司 | 基于轨道交通的计算机平台 |
| CN110095974A (zh) * | 2018-01-31 | 2019-08-06 | 株洲中车时代电气股份有限公司 | 一种地面过分相双冗余控制方法及控制系统 |
| CN110095978A (zh) * | 2019-05-06 | 2019-08-06 | 杭州耘新科技有限公司 | 一种2乘2取2系统及其安全诊断方法 |
| CN110708683B (zh) * | 2019-10-30 | 2022-12-16 | 湖南中车时代通信信号有限公司 | 列车运行控制方法和装置、计算机可读介质 |
| CN110979406A (zh) * | 2019-12-26 | 2020-04-10 | 天津津航计算技术研究所 | 一种交叉复用的信号系统安全计算平台 |
-
2020
- 2020-11-13 CN CN202011267117.8A patent/CN112395236A/zh active Pending
-
2021
- 2021-09-02 WO PCT/CN2021/116147 patent/WO2022100232A1/zh not_active Ceased
Patent Citations (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1484681A2 (de) * | 2003-04-29 | 2004-12-08 | Siemens Aktiengesellschaft | Rechnersystem mit einem Mastersystem, einem Slavesystem, und einer Datensychronisierungseinrichtung |
| CN102945221A (zh) * | 2012-10-18 | 2013-02-27 | 上海亨钧科技有限公司 | 一种全电子安全计算机联锁系统 |
| CN102951182A (zh) * | 2012-10-18 | 2013-03-06 | 上海亨钧科技有限公司 | 一种铁路专用安全计算机的工作方法 |
| CN105159863A (zh) * | 2015-09-09 | 2015-12-16 | 株洲南车时代电气股份有限公司 | 一种用于轨道交通的安全计算机平台 |
| CN105388890A (zh) * | 2015-12-21 | 2016-03-09 | 株洲南车时代电气股份有限公司 | 一种用于列车控制的安全计算机系统 |
| CN111645724A (zh) * | 2020-06-11 | 2020-09-11 | 湖南中车时代通信信号有限公司 | 一种车载安全计算机系统 |
| CN112395236A (zh) * | 2020-11-13 | 2021-02-23 | 中车株洲电力机车有限公司 | 一种分布式车载安全计算机系统 |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116257389A (zh) * | 2023-05-16 | 2023-06-13 | 北京城建智控科技股份有限公司 | 基于全电子联锁系统的二乘二取二平台的同步方法 |
| CN116257389B (zh) * | 2023-05-16 | 2023-08-22 | 北京城建智控科技股份有限公司 | 基于全电子联锁系统的二乘二取二平台的同步方法 |
| WO2025232068A1 (zh) * | 2024-05-10 | 2025-11-13 | 北京全路通信信号研究设计院集团有限公司 | 安全计算系统的消息处理方法、装置、电子设备及存储介质 |
| CN118410495A (zh) * | 2024-06-26 | 2024-07-30 | 中国铁道科学研究院集团有限公司通信信号研究所 | 一种基于tsn的车载安全计算机平台及其数据处理方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN112395236A (zh) | 2021-02-23 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2022100232A1 (zh) | 一种分布式车载安全计算机系统 | |
| CN107187465B (zh) | 一种单元级热备冗余的ato系统架构 | |
| EP3690657A1 (en) | Computer-based interlocking system and redundancy switching method thereof | |
| CN109946956B (zh) | 一种设备主备系同步和热备方法 | |
| CN102001348B (zh) | 基于cpci总线技术的双机热备系统切换的实现方法 | |
| CN103176870B (zh) | 一种多模式信息交互的冗余安全计算机平台 | |
| CN101337552B (zh) | 采用2x2取2架构的计轴系统 | |
| CN101580073B (zh) | 计算机联锁系统码位级冗余方法 | |
| CN106740999A (zh) | 基于执行模块冗余的全电子计算机联锁系统 | |
| WO2017107665A1 (zh) | 一种用于列车控制的安全计算机系统 | |
| CN102955903A (zh) | 一种轨道交通计算机控制系统安全苛求信息的处理方法 | |
| CN111891184B (zh) | 基于二乘二取二的列车lcu控制系统 | |
| WO2018113763A1 (zh) | 基于轨道交通的计算机平台 | |
| CN112693495A (zh) | 一种无节点分布式道岔安全驱采控制系统 | |
| CN216313114U (zh) | 一种动车组控制系统融合架构 | |
| CN116215618A (zh) | Ats主备切换方法和装置 | |
| CN113835337B (zh) | 一种列车网络冗余控制的方法与系统 | |
| CN116405342A (zh) | 通用车载综合安全监控系统及其通信冗余切换方法 | |
| CN201151415Y (zh) | 一种计算机联锁系统 | |
| CN201335974Y (zh) | 一种竞争式热备切换系统 | |
| CN110979406A (zh) | 一种交叉复用的信号系统安全计算平台 | |
| CN213149533U (zh) | 一种硬件三取二表决电路及列车lcu控制系统 | |
| RU90401U1 (ru) | Микропроцессорная система управления маршрутами на малых станциях | |
| CN116279693A (zh) | 一种双系冗余的列车运行控制系统 | |
| JP2014220863A (ja) | 列車制御システム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21890760 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21890760 Country of ref document: EP Kind code of ref document: A1 |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 06.09.2023) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21890760 Country of ref document: EP Kind code of ref document: A1 |