Data , w hich has a direct bearing on the correct realization of computer interlocking function , is relat‐ed to the safety integrity level of the entire railway signaling system . The verification of data safety is a critical task in the development and application of computer interlocking in urban railway signaling .Starting from the role of data safety in system safety ,the idea of data safety verification was elaborated first .Based on the mod‐eling of computer interlocking data structures in urban railway signaling , the key rules of the safety restrictions between the data were derived . The interlocking data safety verification algorithms based on the point‐point , point‐line and line‐line relations were proposed and proved in this paper . A typical Nanjing Metro Line was used to verify the correctness of this method as a case study . Compared to the traditional manual verification process , the verification efficiency of this method significantly improved .
In order to manage the hazards in the phase of train control system design and safety assessment , the quantitative safety analysis of train control system is crucial . T he results of the quantitative analysis can be used to judge and compare the pros and cons of the prototype designs , to evaluate the probabilistic risks of haz‐ards and to determine w hether hidden dangers can be controlled within the acceptable range with the risk miti‐gation measures taken . In this paper , a Markov Decision Process based modelling method was proposed to build system behavior model of the two consecutive trains in the train control system , to integrate the normal behaviours and failure behaviours of the system and to put forward Comprehensive Behaviour Model (CBM ) . The dangerous failure probability of the hazard was calculated under the probabilistic model checking tool PRISM . The methodology of quantitative safety analysis for train control system was presented .
When right side failures and wrong side failures of the track circuits occur ,the train control center cannot judge the exact states of track occupancy in sections according to the states of track circuit relays ,cau-sing the so-called"red light strip" and"train occupancy loss" on the screen of the train control center ,posing potential safety risks . .In order to reduce the operation risks ,four logic states of track occupancy were pro-posed first ,and an occupancy checking logic layer was added into the software design of the train control cen-ter ,to deal with the unsafe state information of track circuit relays ,and to transfer the safety track occupancy logic states to the centralized train control center .Markov Decision Processes were used to formally present the logic state processing models ,and four colors were employed to present the track occupation states .This re-search enhanced the inapplicable situations of the restrictions in the design specifications . Finally , through quantitative calculation ,the derived dangerous failure probability of single trip was 2 .120 × 10-10 ,which proved the acceptable range of the hazard risks of the design .
In order to perform the quantitative safety analysis of Chinese Train Control System level 3, Markov Decision Process(MDP) is employed as the foundation of system behavior modelling. The non-deterministic behaviors and stochastic behaviors in physical behavior model, normal behavior model and fault behavior models are all expressed in MDPs. The quantitative analysis results produced by probabilistic model checker PRISM can be used to judge and compare the prototype designs and evaluate the probabilistic risk of hazards. The conclusions show that comprehensive behavior model and PRISM can automatically consider all the paths of the dynamic system behaviors in System of Systems, which makes the behavior model more accurate and complete. The methodology manifests that it is applicable for the safety analysis of CTCS3 and other train control systems.
轨道电路能够传递列车行车许可、检查轨道占用,有效地保证了列车安全高效的运行.轨道电路的钢轨阻抗决定了轨道电路的传输性能,研究钢轨阻抗变化具有重要意义.本文提出一种基于电磁场模型的钢轨阻抗研究方法.首先分析轨道电路中钢轨阻抗的分布原理,确定钢轨阻抗的计算方法;然后建立模型,计算比较有砟轨道和无砟轨道钢轨阻抗在不同环境和频率下的变化;最后仿真验证无砟轨道钢轨阻抗优化方法的正确性.结果表明电磁场模型可以很好的模拟轨道电路,分析不同环境下钢轨阻抗的变化规律,验证了加高距离和绝缘方法对于优化无砟轨道钢轨阻抗的正确性.
The balise is a point-type transmission device based on electromagnetic coupling and it is easy to be af-fected by surrounding metal objects . So the balise installed beside guardrails may be interfered by the guard-rails . Up to now , there has been no literature on interference from guardrail to balise . Therefore , the re-search in this respect has become essential . In this paper , the balise was modelled and simulated by Software FEKO and teats were made for verification . Then the model of guardrail was incorporated into the balise model to simulate the influence of guardrail on balise . The slotting length of guardrail was subjected to the process of optimization and the most rational slotting length of guardrail was found . The research results show as fol-lows :The guardrail mainly interferes in the crosstalk area of balise ;under ideal conditions , the slotting lengths not less than 2 mm can meet the requirement of an uniform field strength ;the longer the slotting length of guardrail , the smaller the interference in the balise , however , when the slotting length reaches a certain value , further lengthening the slotting length will impose very much limited effect on reducing the in-terference of guardrail in balise .
Track circuit system is an important basis and core of the train-control system. The performance of the track circuit directly influences transport efficiency and train-operation safety. Accompanied with the constant improvement of the speed, the requirements of the RAMS of track circuit system greatly improved. Given the importance of the track circuit system and the situation of its frequent malfunctions, systematically safety analysis of the track circuit system is very necessary. This paper systematically analyzed the safety of the ZPW-2000A/K track circuit system by safety analysis theory and method. We identified ten top-level hazard events of the system by FFA and FMECA and got all the possible causes and potential consequences of each hazard event by FTA and ETA method. According to the risk-evaluation matrix, we obtained the risk level of each hazard event. It provides the basis for the product design and improvement.
Commercial off-the-shelf (COTS) based computer platform is deemed as a promising candidate for application in safety critical systems. The foresight of this choice will make system transplant and software reuse efficient, and help vendors conquer the stress of development cycle and cost. Actually, it is nothing new in aviation and aerospace. However, no literature is proposed to argue the safety issues on a viewpoint of system attribute in train control system but only concentrates the behavior of COTS products themselves. System theory is the key to construct a solid and coherent safety assurance framework for the interaction between COTS sector and other parts, which will explicitly demonstrate the concept of safety on a system level. In this paper, a picture of propagation from bottom functional failures and performance degradation of COTS resource to the top-level hazardous events is depicted to show how safety analysis and risk evaluation of train control system is affected. Additionally, several experiments are carried out to support the argument.
Train control system is a typical safety critical system and it is responsible for the safety and efficiency of train operation. When safety requirements are identified in the process of system safety engineering the main task of the designer is to adopt appropriate measures to carry out the safety requirements reliably and verify it can achieve corresponding performance. Hazard analysis methods draw a clarified road map to derive these safety requirements and model verification technologies justifies that the accuracy of performance requirements are satisfied before implementation. In this paper, the derivation process of safety requirements including random failure and systematic failure of hot standby system is described and colored petri-net is used for model verification and performance analysis.
The EURORADIO system provides communication services for safety-related application processes using open network. The EURORADIO protocol controls the establishment of safety connection between on-board and trackside, and the time for establishment of safety connection is a key parameter to communication system. After describing the requirements in the EURORADIO specification, the probabilistic model checking tool PRISM is used to implement a formal analysis on the property of safety connection, combing the stochastic characters of communication channel. Verification results show that, when the protocol is applied in China Train Control System level 3 in case of 0.01 of message loss, the probability for establishment of safety connection in 8.5 seconds is 0.96059, and the probability is 0.99844 after establishing safety connection twice, it can fulfill the requirements of the specification.
When the speed of the train is 350km/h, it only takes about 7ms for the on-board antenna of BTM to pass the effective range of a balise. On-board antenna needs to accomplish a communication with balise within such a little time that it is essential for on-board antenna to have a good performance of transmitting and receiving signal. Therefore, it is significant to study the optimization of the performance of on-board antenna. This paper presents a method of optimization study about on-board antenna of BTM based on electromagnetic model. Firstly, theoretically analyse the effects that antenna's size, the conductor's diameter and form have on the Gain, Efficiency and near field of the antenna. Then design a square tubular on-board antenna of BTM, which frequency is at 27.095MHZ, and ascertain the optimal conductor's diameter of the on-board antenna; secondly, simulate and model the on-board antenna with FEKO software; thirdly, optimize the size of the established antenna model by OPTFEKO with particle swarm optimization (PSO) algorithm to ascertain the optimal size of the on-board antenna. The results show that the near field radiation of the optimized on-board antenna is much higher and steadier in effective range, and quicker weakening in side lobe zone, when compared with rectangle laminated antenna. The study of on-board antenna optimization in this paper is a good foundation for further study of transmission performance of balise system.
The magnetizing inrush current generated by auto-passing neutral section goes through busbar,wheel and rail back to substation.The Up-Link balise may be interfered by the magnetizing inrush current in this process.This interference way is receiving antenna coupling.To clearly understand their interference,it is necessary to get signal component near 4.23 MHz of the magnetizing inrush current.So the research on the high frequency signals of magnetizing inrush current is necessary.This paper uses MATLAB to simulate magnetizing inrush current,and data of magnetizing inrush current are acquired.And then this paper loads the simulation data with Labwindows/CVI and does STFT to get the signal component near 4.23 MHz.Finally,using FEKO does interference simulation of magnetizing inrush current to up-link balise.The research results show that the magnetizing inrush current contains small weight signals of 4.23 MHz,and it can not interfere with the Up-Link balise.
Railway signaling communication is a kind of safety-related processing and the information has to be delivered safely. RSSP-1 Railway Signal Safety Protocol is a safety communication protocol which aims at protecting the message transmission between railway signaling safety-related equipment in closed transmission systems. CPN is suitable for the verification of the correctness and safety characteristics of the RSSP-1 protocol. The single-channel and dual-channel models are established on the RSSP-1 safety communication protocol with Colored Petri Net (CPN) and simulated in CPN tools. After the simulation, a drawback of the protocol is found. A switch deadlock between two channels is presented and a monitoring mechanism is proposed to detect the failure, which will enhance the efficiency of the protocol.