Language selection

Search

Patent 2467972 Summary

Third-party information liability

Some of the information on this Web page has been provided by external sources. The Government of Canada is not responsible for the accuracy, reliability or currency of the information supplied by external sources. Users wishing to rely upon this information should consult directly with the source of the information. Content provided by external sources is not subject to official languages, privacy and accessibility requirements.

Claims and Abstract availability

Any discrepancies in the text and image of the Claims and Abstract are due to differing posting times. Text of the Claims and Abstract are posted:

  • At the time the application is open to public inspection;
  • At the time of issue of the patent (grant).
(12) Patent Application: (11) CA 2467972
(54) English Title: METHOD FOR CONTROLLING A SAFETY-CRITICAL RAILROAD OPERATING PROCESS AND DEVICE FOR CARRYING OUT SAID METHOD
(54) French Title: PROCEDE DE COMMANDE D'UN PROCESSUS D'EXPLOITATION FERROVIAIRE CRITIQUE ET DISPOSITIF DESTINE A LA MISE EN OEUVRE DE CE PROCEDE
Status: Dead
Bibliographic Data
(51) International Patent Classification (IPC):
  • B61L 21/00 (2006.01)
  • G06F 11/16 (2006.01)
(72) Inventors :
  • GOERICKE, VOLKER (Germany)
  • PRADE, BERND (Germany)
  • SCHIWASINSKE, RALF (Germany)
(73) Owners :
  • SIEMENS AKTIENGESELLSCHAFT (Germany)
(71) Applicants :
  • SIEMENS AKTIENGESELLSCHAFT (Germany)
(74) Agent: FETHERSTONHAUGH & CO.
(74) Associate agent:
(45) Issued:
(86) PCT Filing Date: 2001-11-22
(87) Open to Public Inspection: 2003-06-12
Examination requested: 2006-07-18
Availability of licence: N/A
(25) Language of filing: English

Patent Cooperation Treaty (PCT): Yes
(86) PCT Filing Number: PCT/DE2001/004485
(87) International Publication Number: WO2003/047937
(85) National Entry: 2004-05-20

(30) Application Priority Data: None

Abstracts

English Abstract




The invention relates to a method for controlling a safety-critical railway
operating process in which the programme necessary for the above is divided
into a system software (V,PMS) and a software (BO) specific for railway
management. External commands (K) and messages (M), which affect the control,
are recorded and transmitted to commercial computers (R1,R2) in which the
actual process control runs, by means of the system software running in one or
several secure signalling computers (SR*), as defined by the relevant railway
operating condition. The processing of the programme specific for railway
management can occur in two channels, parallel or serially, whereby the
monitoring of whether the commercial computers have reached the same result is
carried out in the secure signalling computers. The output (SB) to the process
(BA) for control also occurs from there, so long as the secure comparison
recognises that the commercial computers have provided the corresponding
process result at least twice, otherwise the signalling connection to the
process elements (W,S) is securely cut. The advantage of the invention is that
the same software can always be used for the secure signalling computers and
the railway management software can be separately developed and checked
without being linked to the system software. Significant cost and time savings
can thus be made relative to the state of the art without affecting safety.


French Abstract

L'invention concerne un procédé de commande d'un processus d'exploitation ferroviaire critique consistant à séparer les programmes requis en un logiciel système (V, PMS) et en un logiciel spécifique à la gestion ferroviaire (BO). Le logiciel système exécuté dans un ou plusieurs ordinateurs surs (SR*) permet d'enregistrer les instructions (K) et messages (M) agissant extérieurement sur la commande, et de les transmettre à des ordinateurs commerciaux (R1, R2) supportant la commande de processus à proprement parler, telle qu'elle est spécifiée par les conditions d'exploitation ferroviaire correspondantes. L'exécution des programmes spécifiques à la gestion ferroviaire est effectuée sur deux canaux, en parallèle ou en série, le contrôle visant à déterminer si les ordinateurs commerciaux sont parvenus au même résultat étant effectué dans les ordinateurs surs. Lesdits ordinateurs surs effectuent également l'émission (SB) vers le processus à commander (BA) tant que la comparaison sure indique que les ordinateurs commerciaux ont fourni le même résultat au moins deux fois, la connexion vers les éléments de processus (W, S) étant coupée de façon sure dans le cas contraire. De manière avantageuse, le même logiciel système peut être employé pour l'ordinateur sûr et le logiciel spécifique à la gestion ferroviaire peut être développé et contrôlé indépendamment du logiciel système. Ainsi, il est possible de réduire les coûts et le temps par rapport aux systèmes antérieurs, sans réduire le niveau de sécurité.

Claims

Note: Claims are shown in the official language in which they were submitted.



-12-


claims

1. A method for controlling a safety-critical
railroad operating process using at least one
computer which is reliable in terms of signaling
technology and which outputs to process elements
in a way which is reliable in terms of signaling
technology control instructions produced reliably
in terms of signaling technology from incoming
commands in accordance with a set of railroad
operating rules, and feeds messages originating
from said process elements to a process state
monitoring system and process control system,
characterized in that only one system software
package (V, PMS), whose programs enable the
reliable computer to perform inputting/outputting
which is reliable in terms of signaling technology
and the data comparison which is reliable in terms
of signal technology, is stored in the reliable
computer (SR*), and in that the railroad
administration-specific software (BO) which
includes the conditions and dependencies
predefined for the railroad operating process by a
railroad administration by means of its set of
railroad operating rules, is stored in at least
one commercial computer (R1, R2) which is not
reliable in terms of signaling technology, in that
processing orders (A) are generated from the
computer which is reliable in terms of signaling
technology, from the commands (K) and the messages
(M) fed to it, and are transmitted to the
commercial computer or computers, in that the
processing orders are processed there
independently from one another, at least twice,
in that the results (E) which are produced in the
process and/or intermediate results are
transmitted to the reliable computer and checked
there for correspondence of their contents in a


-12a-


way which is reliable in terms of signaling
technology,
the reliable computer accepting only those results
and/or intermediate results and outputting to the
process (BA), in a way which is reliable in terms
of signaling technology, only those


-13-


control instructions (SB) derived therefrom, which
have been made available by the commercial
computer in such a way that they correspond on at
least two occasions.
2. The method as claimed in claim 1, characterized in
that identical or differing software is used for
the at least two-fold execution of processing
orders in the commercial computer.
3. The method as claimed in claim 1 or 2,
characterized in that the time events which occur
during the execution of the railroad
administration-specific software (BO) are
synchronized by the computer (SR*) which is
reliable in terms of signaling technology, at the
request of the commercial computers.
4. The method as claimed in one of claims 1 to 3,
characterized in that the results and/or
intermediate results which are determined by the
commercial computer are transmitted to the
reliable computer by means of communication
channels which are not reliable in terms of
signaling technology.
5. The method as claimed in one of claims 1 to 4,
characterized in that transmission of data in
telegrams is provided, and in that the telegrams
have signatures added to them, from which the
respective receiving computer can detect whether
these telegrams have been transmitted in a non-
falsified form.
6. The method as claimed in one of claims 1 to 5,
characterized


-14-


in that a transmission of data in telegrams is
provided, and in that the telegrams have
signatures added to them from which the computer
which is reliable in terms of signaling technology
can detect whether falsifications have occurred in
the program memories and the data memories of the
commercial computers, or whether the CPU of a
commercial computer is no longer operating
correctly.
7. The method as claimed in one of claims 1 to 6,
characterized in that the processing orders are
processed essentially simultaneously in at least
two commercial computers (R1, R2) in each case or
are processed in a chronologically serial fashion
in just one single computer, and in that the
results and/or intermediate results which are
obtained are fed to the reliable computer in each
case in pairs for the purpose of comparison.
8. The method as claimed in claim 7, characterized in
that telegrams have identifiers added to them,
from which the reliable computer can detect
whether these telegrams have actually been
produced separately.
9. The method as claimed in claim 7, characterized in
that the reliable computer detects, by reference
to the result messages of the commercial computers
which are fed to it via different inputs, whether
these telegrams originate from different
computers.
10. The method as claimed in one of claims 1 to 9,
characterized in that systematic errors in the
operating system software (BO) of the commercial
computers are prevented by using differing


-15-


operating systems on the computers (R1 to Rn)
involved.
11. The method as claimed in one of claims 1 to 10,
characterized in that systematic errors in the
hardware of the commercial computers are prevented
by using differing computer components
(motherboard, CPU, memory) on the computers (R1 to
Rn) involved.
12. A device for carrying out a method for controlling
a safety-critical railroad operating process using
at least one computer which is reliable in terms
of signaling technology and which outputs to
process elements in a way which is reliable in
terms of signaling technology control instructions
produced reliably in terms of signal technology
from incoming commands in accordance with a set of
railroad operating rules, and feeds messages
originating from said process elements to a
process state monitoring system and process
control system, characterized in that only a
system software package whose programs enable the
reliable computer to perform the
inputting/outputting (K,E,M,A,SB) in a way which
is reliable in terms of signaling technology and
the data comparison which is reliable in terms of
signaling technology is then implemented in the
computer (SR*) which is reliable in terms of
signaling technology, and in that at least one
commercial computer (R1, R2) is provided which is
not reliable in terms of signaling technology and
in which the railroad administration-specific
software which includes the conditions and
dependencies for the control of the railroad
operating process which are predefined by a
railroad administration by means of its railroad
operating rules (BO) is implemented, in that the


-15a-


reliable computer and the commercial computer are
connected to a communications system (BUS) via
which the reliable computer transmits processing
orders (A) to the commercial


-16-


computer and receives results (E) and/or
intermediate results from it, the commercial
computer being designed to execute each processing
order independently of one another at least twice,
in that the reliable computer checks the results
and/or intermediate results which are transmitted
to it at least in pairs in each case by the
commercial computer for correspondence between
their contents in a way which is reliable in terms
of signaling technology and derives therefrom
control instructions (SB) for process elements (W,
S) as a function of the check result and causes
them to be output to the process via drivers
provided for this purpose.
13. The device as claimed in claim 12, characterized
in that it is also the case that only programs
(BO) whose functionality has been proven are
installed in the commercial computer.
14. The device as claimed in claim 12 or 13,
characterized in that the commercial computer
executes the processing orders with identical or
differing software at least twice in each case.
15. The device as claimed in one of claims 12 to 14,
characterized in that at least two commercial
computers which execute the same processing orders
in pairs independently of one another are
provided.
16. The device as claimed in one of claims 12 to 15,
characterized


-17-


in that, in order to process different
functionalities or sub-functionalities or to
control and monitor different equipment parts, in
each case a plurality of commercial computers (R1,
R2) are provided in single-computer or
multicomputer designs.
17. The device as claimed in one of claims 12 to 16,
characterized in that the at least one commercial
computer is an operating console computer via
which commands (K) can be input into the reliable
computer and messages (M) can be displayed.
18. The device as claimed in one of claims 12 to 17,
characterized in that the reliable computer is an
m v n computer system.
19. The device as claimed in one of claims 12 to 18,
characterized in that the reliable computer is
designed to detect, from identifiers which are
added to the results and/or intermediate results
which are transmitted by the at least one
commercial computer, whether these results and/or
intermediate results originate from different
processing processes.

20. The device as claimed in claim 12, characterized
in that the reliable computer outputs any control
instructions to the process on two channels.

Description

Note: Descriptions are shown in the official language in which they were submitted.




CA 02467972 2004-05-20
WO 03/047937 PCT/DE01/04485
Description
Method for controlling a safety-critical railroad
operating process and device for carrying out said
method
The invention relates to a method according to the
preamble of patent claim 1, and to a device for
carrying out this method according to the preamble of
patent claim 12.
Railroad operating processes are processes which are
safety - critical because any malfunctions which happen
not to be detected in good time and whose effect on the
process is not prevented, can lead to considerable
damage to property and possibly also place people in
danger. For this reason, hitherto, devices which are
reliable in terms of signaling technology have been
used for controlling such processes, the objective of
said devices being to detect malfunctions both within
the process to be controlled and within the process
control system itself and to subsequently place the
process in a safe state, or leave it in such a state.
Such control systems which are reliable in terms of
signaling technology can be embodied in different
technologies, for example using relay technology or
electronic technology. In process control which is
reliable in terms of signal technology using computers,
hither to expensive special computers have been used
which process the waiting/queued processing orders on
two channels and continuously compare, by means of
signaling technology, processing sequences for
correspondence in terms of contents. Control
instructions which are produced are output to the
process elements of the process to be controlled only
if both processing channels have each arrived at the
same result; otherwise, the connection to the process
is interrupted, unless there



CA 02467972 2004-05-20
WO 03/047937 - 2 - PCT/DE01/04485
is at least one backup computer which can take over,
and actually takes over, the functions of the failed
computer.
The abovementioned functions of the reliable inputting
and outputting of data and the comparison of data with,
if appropriate, reliable shutting down of process
elements are brought about by the system software of
the reliable computers. In addition, the reliable
computers have hitherto also contained the railroad
administration-specific software for the actual process
control, for example the signaling cabin operations.
The railroad administration-specific software is
determined by the operating rules of the respective
railroad administration and it describes, for example,
the dependencies, predefined by it, of the setting and
release of the routes (Signal+Draht [Signal and Wire],
77 (1985) 12, pp. 259-265). The railroad
administration-specific software does not only differ
from railroad administration to railroad administration
but also at least partially from one piece of equipment
to another in the same railroad administration. This
means that the software which is to be loaded into a
computer which is reliable in terms of signaling
technology and runs on said computer differs from one
application case to another, it being necessary to
prove or make credible the freedom from faults of the
loaded software by means of a safety certificate for
each application case. As a result of the proliferation
of the system software and of the railroad
administration-specific software in each computer, this
leads to complex software packets which are difficult
to manage and which are time-consuming and costly to
produce and to test.
The object of the present invention is to disclose a
method for controlling a safety-critical railroad
operating process in accordance with the preamble of



CA 02467972 2004-05-20
WO 03/047937 - 2a - PCT/DE01/04485
patent claim 1 and whose programs, which are necessary
for the reliable



CA 02467972 2004-05-20
WO 03/04?93? - 3 - PCT/DE01/04485
process control, are less costly to produce and which
makes it possible to react quickly and cost-effectively
to any changed requirements of a railroad operator with
respect to the process control system. The object of
the invention is also to disclose a device for carrying
out this method.
The invention achieves this object by means of the
features of claim 1 and/or of claim 12. The basic idea
of the invention consists in exporting the railroad
administration-specific software from the computer or
computers which are reliable in terms of signaling
technology to commercial computers which process the
data there at least twice in each case and test it
reliably for correspondence before outputting it to the
process in the computers which are reliable in terms of
signaling technology. The computers which are reliable
in terms of signaling technology have not only the
function of performing data comparison but essentially
also the function of reliably acquiring the incoming
messages and commands, and transmitting them to the
commercial computers as well as reliably acting on the
process elements and in the event of a fault
interrupting the connection to the process elements in
a way which is reliable in terms of signaling
technology.
Advantageous embodiments and developments of the method
according to the invention and the device according to
the invention are disclosed in the subclaims.
The invention is explained in more detail below with
reference to the exemplary embodiment illustrated in
the drawing, in which:
Figure 1 is a schematic view of the structure of the
device according to the invention for



CA 02467972 2004-05-20
WO 03/047937 - 3a - PCT/DE01/04485
controlling a safety - critical railroad operating
process and
Figure 2 shows the structure of a corresponding device
which is embodied according to the prior art.



CA 02467972 2004-05-20
WO 03/047937 - 4 - PCT/DEOlj04485
Figure 2 shows a known computer SR which is reliable in
terms of signaling technology, for executing a process
by means of preferably identical processing programs in
two independent processing channels K1, K2. The
reliable computer SR stands for any desired number of
computers which are reliable in terms of signaling
technology; their number is determined essentially by
the magnitude of the process to be controlled. The
process to be controlled is a railroad operating
process with which a railroad system BA is to be acted
on. As representatives for the process elements of the
railroad system, a railroad switch W and a signal S are
indicated in the drawing. The control and the
monitoring of the process elements is carried out by
means of control and monitoring circuits which have
been developed for that purpose, which are not
explicitly illustrated in the drawing and via which
control instructions SB are output by the reliable
computer SR to the process elements and messages M are
input into the reliable computer from said process
elements.
The computer SR which is reliable in terms of signaling
technology outputs the messages M transmitted to it by
the process to an input and display computer EAR via a
communications bus KB. Said input and display computer
EAR serves, inter alia, for monitoring the railroad
operating process according to representation rules
defined in the respective railroad operating rules; it
is preferably embodied as a computer which is process-
protected in terms of signaling technology. Using the
input and display computer EAR, the commands K for
controlling the railroad operating process are also
generated and transmitted to the computer SR which is
reliable in terms of signaling technology. The
inputting can be carried out here by an operator, for
example a stationmaster, or else by means of an



CA 02467972 2004-05-20
WO 03/047937 - 4a - PCT/DE01/04485
automatic system, for example for automatic points
changing or the transit mode.



CA 02467972 2004-05-20
WO 03/047937 - 5 - PCT/DE01/04485
The messages and commands are processed in the computer
which is reliable in terms of signaling technology, on
two channels in accordance with the conditions and
dependencies which are defined in the respective
operating rules of a railroad operator. The data,
addresses and control signals which are respectively
present on the buses of the two processing systems are
continuously compared with one another in a way which
is reliable in terms of signaling technology in order
to be able to detect immediately any discrepancies.
Test programs ensure that the input/output register of
the reliable computer and its program memories and main
memories as well as its address registers are checked
within predefined minimum time periods to determine
whether their memories can assume either the one state
or the other. Any malfunctions are thus detected in an
event-controlled or time-controlled fashion and lead to
the external equipment being reliably shut down:
control instructions to railroad switches can then no
longer be output and the signals go to the Stop
setting.
By virtue of the fact that the conditions and
dependencies which are predefined by the respective
operating rules of a railroad administration and are
represented in the drawing by elliptical place markers
B0, are stored in the program memories of the reliable
computer SR and mixed up with the system software, the
software which is stored in the reliable computers in
order to control the railroad operating process is
individual software which is very complex and
extraordinarily costly both to produce and test.
In the device according to the invention (illustrated
in Figure 1) for controlling a railroad operating
process there is also at least one computer SR* which
is reliable in terms of signaling technology and has
two processing channels Kl* and K2* which are preferably



CA 02467972 2004-05-20
WO 03/047937 - 5a - PCT/DE01/04485
both structured and operated identically. The function
of said computer SR* is,



CA 02467972 2004-05-20
WO 03/047937 - 6 - PCT/DE01/04485
similarly to the conventional computer SR which is
reliable in terms of signaling technology, to reliably
acquire, and feed to the processing means, all the
messages M and commands K which are fed to it. In
addition, its function is to output control
instructions SB, produced reliably in terms of
signaling technology, to the process elements W, S of
the respective railroad equipment BA and to ensure that
the outputting of such control instructions is
prohibited, in a way which is reliable in terms of
signaling technology, in the event of a fault. The
processing of the conditions and dependencies, defined
by the respective railroad operating rules BO, for
controlling and monitoring the railroad operating
process does not take place, in contrast to the prior
art, in the computer or computers SR* which is/are
reliable in terms of signaling technology but rather in
commercial computers R1, R2, ... Rn in which the
equipment-specific data for controlling the railroad
operating process is also stored; the computers R1, R2
are representative of one or more computer pairs, each
computer also being able to belong to more than one
pair; three computer pairs can therefore be formed from
three computers. They each carry out processing orders
A fed to them by the reliable computer SR*
independently of the respective other computer in
accordance with the conditions and dependencies defined
for the process control in the respective railroad
operating rules BO. The two computers of each
commercial computer pair R1, R2 transmit their working
results to the computer SR* which is reliable in terms
of signaling technology, the chronologically first
computer R1 or R2 bringing about a waiting point with
time monitoring, at which point the system waits for
the working result of the other computer or computers,
or in the event of the time being exceeded a fault
procedure is carried out. Test mechanisms PM for the
plausibility of the messages fed to the commercial



CA 02467972 2004-05-20
WO 03/047937 - 6a - PCT/DE01/04485
computer pairs Rl, R2, and of the signatures of the
outputs and memory areas produced by them are indicated
schematically in Figure 1. The commands K which are fed
to the reliable computer SR* via the input and display
computer



CA 02467972 2004-05-20
WO 03/047937 - 7 - PCT/DE01/04485
EAR are converted by said computer SR* into processing
orders A and transferred to the commercial computers
R1, R2 in the form of telegrams; they bring about the
processing therein in accordance with the conditions
and dependencies of the respective railroad operating
rules B0.
Tn the event of program points which provide for the
programs to be further processed only after a
predefined waiting time being reached by the commercial
computers during the processing of the railroad
administration-specific software by said computers, the
computer which is reliable in terms of signaling
technology ensures, in response to a corresponding
request by the commercial computers, synchronization of
the processing programs of the commercial computers for
further processing of the programs after the expiry of
the waiting time. For example, after the expiry of a
waiting time of several seconds a sensor message which
is determined by the commercial computers will be read
in and evaluated.
The processing results E which are determined by the
commercial computer pair R1, R2 are fed as telegrams to
the computer SR* which is reliable in terms of
signaling technology, distributed there between the two
processing channels K1*, K2* in a way which is reliable
in terms of signaling technology and compared for
correspondence in a way which is reliable in terms of
signaling technology. The function block V represents
in the drawing the reliable distribution of messages
and the reliable comparison of the results produced by
the commercial computers R1, R2, the programs which
relate to the above being stored as system software in
said function block V. The test mechanisms PMS of the
computer which is reliable in terms of signaling
technology are embodied in a way which is reliable in
terms of signaling technology, in contrast to the test



CA 02467972 2004-05-20
WO 03/047937 - 7a - PCT/DE01/04485
mechanisms PM of the commercial computers R1, R2.



CA 02467972 2004-05-20
WO 03/047937 - 8 - PCT/DE01/04485
The particular advantage of the device according to the
invention in comparison with a corresponding device
embodied according to the prior art is that only the
functions of the reliable inputting and outputting and
of the reliable data comparison are to be implemented
in the computer which is reliable in terms of signaling
technology, and this is done independently of the
requirements and conditions respectively defined by the
operating rules of the individual railroad
administrations. In this way, not only is the system
software which runs in the reliable computer or
reliable computers simple and easy to manage but it is
also the same for all application cases, that is to say
no longer has to be produced newly from case to case
and subjected to approval testing. The railroad
administration-specific software which is determined by
the different operating rules of the individual
railroad administrations runs in the commercial
computers. Its interaction with the system software of
the reliable computers does not need to be tested.
Instead, all that is necessary is to comply with the
specified interface between the computer which is
reliable in terms of signaling technology and the
commercial computer and to test the functionality of
the actual railroad administration-specific software
which is to be implemented in the commercial computers,
i.e. to test whether certain inputs actually lead to
certain outputs. This functionality testing takes place
separately from the testing of the system software and
is, in contrast to the prior art, no longer integrated
into the system software of the reliable computers,
which is itself also easier to manage than in the prior
art.
The production of the railroad administration-specific
software does not necessarily have to take place at the
manufacturer of the computers which are reliable in



CA 02467972 2004-05-20
WO 03/047937 - 8a - PCT/DE01/04485
terms of signaling technology, who is responsible for
the safety of the processing events in terms of
signaling technology. Instead, it is possible to
allocate orders for the production of the programs for
the



CA 02467972 2004-05-20
WO 03/047937 - 9 - PCT/DE01/04485
commercial computers to qualified engineering offices
or the like which have to reconcile the software
produced by them with the respective railroad
administration and, for example, an approval authority
such as the Eisenbahnbundesamt (German Federal Railroad
Office). This makes it possible to adapt the programs
for controlling and monitoring a safety - critical
railroad operating process to the respective conditions
very much more quickly and economically than hitherto
without having to make any compromises in terms of
safety as a result.
In the exemplary embodiment illustrated above, the
commercial computers Rl, R2 stand for one or more
double computer systems or computer systems provided
with redundant computers in whose individual computers
in each case identical programs for processing the
conditions and dependencies predefined by the
respective railroad operating rules are to run, in
which case preferably either only specific sub-
functions of the operating rules are to be implemented
in each case by the individual commercial computers or
else only specific parts of the railroad equipment are
to be acted on in each case. However, the arrangement
can also be configured such that the commercial
computers R1, R2 are each individual computers in which
the programs, determined by the operating rules of a
railroad administration, of the railroad
administration-specific software are processed
repeatedly, and at least twice in succession,
independently of one another. The railroad
administration-specific software which is necessary for
this can be configured in different ways or else can be
identical in terms of contents for both processing
procedures.
For the transmission of the results produced by the
commercial computers to the computer or computers which



CA 02467972 2004-05-20
WO 03/047937 - 9a - PCT/DE01/04485
is/are reliable in terms of signaling technology, a
data transmission which is preferably not reliable in
terms of signaling technology



CA 02467972 2004-05-20
WO 03/047937 - 10 - PCT/DE01/04485
is preferably used, during which transmission either
the results which are produced on two channels either
serially or in parallel are transmitted to the reliable
computer or computers on two channels, or else said
results are transmitted twice in succession over just
one channel. A second or third redundant channel
increases the availability. Any data falsifications on
the transmission path from the commercial computers to
the computers which are reliable in terms of signaling
technology, and vice versa, can be detected in the
receiving computer by a signature which is entered by
the dispatching computer and which encodes the telegram
contents by means of a computing rule. During the
serial transmission of data to the reliable computers,
the data is provided with identifiers which make it
possible for the computers which are reliable in terms
of signaling technology to detect whether the
transmitted data is current and actually originates
from different computer channels of the commercial
computers and/or whether it is the result is of
different processing procedures; during the
transmission of data over separate buses, the computers
which are reliable in terms of signaling technology can
detect, from the data transmitted to them via one bus
or the other, whether or not this data also actually
originates from the one computer or the other of a
commercial computer pair.
In an advantageous embodiment of the invention, the
commercial computer or computers can be embodied as
what are referred to as operating console computers, by
means of which the commands from a railroad employee or
from an automatic system can be output for execution to
the railroad operating process and the acknowledgements
of the railroad operating process can be displayed. In
the operating console computers, the programs for
inputting and displaying commands and messages and the
programs via which the process elements are controlled



CA 02467972 2004-05-20
WO 03/047937 - l0a - PCT/DE01/04485
in accordance with the railroad operating rules then
run independently of one another. The programs for the



CA 02467972 2004-05-20
WO 03/047937 - 11 - PCT/DE01/04485
inputting of commands and the displaying of the process
events can also be combined with the programs for
process control, such as are respectively predefined by
the railroad operating rules.
The computer or computers which are reliable in terms
of signaling technology can also be embodied as an m of
n computer system in which the decision as to whether
control instructions, and if so which control
instructions, are to be output to the process can be
taken by majority decision by at least two intact
computers.
The outputting of the control instructions to the
process takes place on two channels; each computer has
the possibility of preventing the outputting of control
instructions when processing errors are detected.
The method according to the invention and the device
according to the invention can be used advantageously
for all safety - critical railroad operating processes.
Such an application can be, for example, the reliable
control of a railroad operation by a signal cabin or
else also, for example, the reliable control of a
railroad crossing, of an axle counting system or of
track-mounted and vehicle-mounted equipment of a
continuous automatic train control system (LZB).

Representative Drawing
A single figure which represents the drawing illustrating the invention.
Administrative Status

For a clearer understanding of the status of the application/patent presented on this page, the site Disclaimer , as well as the definitions for Patent , Administrative Status , Maintenance Fee  and Payment History  should be consulted.

Administrative Status

Title Date
Forecasted Issue Date Unavailable
(86) PCT Filing Date 2001-11-22
(87) PCT Publication Date 2003-06-12
(85) National Entry 2004-05-20
Examination Requested 2006-07-18
Dead Application 2009-11-23

Abandonment History

Abandonment Date Reason Reinstatement Date
2008-11-24 FAILURE TO PAY APPLICATION MAINTENANCE FEE

Payment History

Fee Type Anniversary Year Due Date Amount Paid Paid Date
Application Fee $400.00 2004-05-20
Maintenance Fee - Application - New Act 2 2003-11-24 $100.00 2004-05-20
Maintenance Fee - Application - New Act 3 2004-11-22 $100.00 2004-06-16
Registration of a document - section 124 $100.00 2005-05-17
Registration of a document - section 124 $100.00 2005-05-17
Maintenance Fee - Application - New Act 4 2005-11-22 $100.00 2005-10-14
Request for Examination $800.00 2006-07-18
Maintenance Fee - Application - New Act 5 2006-11-22 $200.00 2006-10-13
Maintenance Fee - Application - New Act 6 2007-11-22 $200.00 2007-10-16
Owners on Record

Note: Records showing the ownership history in alphabetical order.

Current Owners on Record
SIEMENS AKTIENGESELLSCHAFT
Past Owners on Record
GOERICKE, VOLKER
PRADE, BERND
SCHIWASINSKE, RALF
Past Owners that do not appear in the "Owners on Record" listing will appear in other documentation within the application.
Documents

To view selected files, please enter reCAPTCHA code :



To view images, click a link in the Document Description column. To download the documents, select one or more checkboxes in the first column and then click the "Download Selected in PDF format (Zip Archive)" or the "Download Selected as Single PDF" button.

List of published and non-published patent-specific documents on the CPD .

If you have any difficulty accessing content, you can call the Client Service Centre at 1-866-997-1936 or send them an e-mail at CIPO Client Service Centre.


Document
Description 
Date
(yyyy-mm-dd) 
Number of pages   Size of Image (KB) 
Abstract 2004-05-20 1 36
Claims 2004-05-20 8 249
Drawings 2004-05-20 2 41
Description 2004-05-20 20 600
Representative Drawing 2004-05-20 1 18
Cover Page 2004-07-26 2 60
Assignment 2004-05-20 2 90
PCT 2004-05-20 8 306
Correspondence 2004-07-22 1 27
Assignment 2005-05-17 18 838
Assignment 2005-05-31 1 33
Correspondence 2005-07-04 1 20
Assignment 2005-07-15 1 38
Correspondence 2005-09-21 1 13
Assignment 2005-09-21 4 206
Prosecution-Amendment 2006-07-18 1 46