Abstract: In conventional signal safety systems there is room for improvement of the processing of cases in which a telegram has been lost due to some reason such as a device malfunction or an abnormality in wireless communications. In order to solve the abovementioned problem the present invention provides a telegram recovery device for generating safety telegrams in a signal safety system wherein a safety telegram including for example occupancy right information for travel paths is shared between trains by circulating the safety telegram sequentially between trains present on a travel path composed of one or more blocks for which occupancy right information is set and wherein occupancy rights for each block of a travel path are set in the trains the device being characterized in that: upon detecting an abnormality in the circulation of a safety telegram information requesting information relating to the occupancy rights for each block is transmitted to trains present on the travel path; information relating to the occupancy rights for each block on the travel path is received from the trains present on the travel path; and a new safety telegram is prepared on the basis of the received information and transmitted to the trains present on the travel path.
TECHNICAL FIELD
[0001]
The present invention relates to a signaling safety system.
5
BACKGROUND ART
[0002]
Patent Literature 1 discloses a signaling safety system which has as a technical
problem "the track circuit device detects a short circuit between rails by a train by electrically
10 isolating the rails and connecting a power supply to one end thereof and a relay to the other end
on the opposite side thereof, but involves high maintenance costs" and the like, (see [0006] in
Patent Literature 1) and as the solution thereof "there is provided a signaling safety system
wherein the security of trains traveling in a predetermined section is secured based on a
telegram, wherein the section is divided into a plurality of blocks, each of which may have an
15 occupancy right to occupy a train, and the telegram circulates in the trains and railway devices
existing in a predetermined section and each telegram includes information on the occupancy
right to the block" and the like (see [0010] in Patent Literature 1).
CITATION LIST
20 PATENT LITERATURE
[0003]
PATENT LITERATURE 1: JP-A-2006-232106
SUMMARY OF INVENTION
25 TECHNICAL PROBLEM
[0004]
However, the signaling safety system disclosed in Patent Literature 1 has room
for improvement in the process in cases in which the telegram has been lost for some reasons
such as a device failure and an abnormality in wireless communication.
30
SOLUTION TO PROBLEM
3
[0005]
In order to solve the above problem, for example, the configuration described in
the claims is adopted.
The present application includes a plurality of means for solving the above
problem, but an example of the means is a telegram recovery 5 device generating a signaling
telegram in a signaling safety system wherein the signaling telegram is shared among trains by
sequentially circulating the signaling telegram containing occupancy right information on a
travel path among the trains present on the travel path divided into one or more blocks to each of
which the occupancy right information is set, and the occupancy right to each block of the travel
10 path is set to each train, wherein when an abnormality is detected during circulation of the
signaling telegram, the telegram recovery device transmits information requesting information
related to the occupancy right to each block to the trains present on the travel path; receives the
information related to the occupancy right to each block on the travel path from the trains present
on the travel path; and based on the received information, generates a new signaling telegram
15 and transmits the signaling telegram to the trains present on the travel path.
ADVANTAGEOUS EFFECTS OF INVENTION
[0006]
The above-described means can safely recover the signaling safety system even if
20 the telegram has been lost for some reasons such as a device failure and an abnormality in
wireless communication. The problems, configurations, and effects other than those described
above will be clarified by the description of the following embodiments.
BRIEF DESCRIPTION OF DRAWINGS
25 [0007]
[FIG. 1] FIG. 1 is a schematic view of a configuration of a signaling safety system according to a
first embodiment.
[FIG. 2] FIG. 2 is a view illustrating a format of a signaling telegram according to the first
embodiment.
30 [FIG. 3] FIG. 3 is a view illustrating a state transition of the signaling safety system according to
the first embodiment.
[FIG. 4] FIG. 4 is a view illustrating a behavior of the signaling safety system according to the
first embodiment.
[FIG. 5] FIG. 5 is a view illustrating a behavior in a monitoring state of the signaling safety
4
system according to the first embodiment.
[FIG. 6] FIG. 6 is a view illustrating a behavior in a recovery execution state of the signaling
safety system according to the first embodiment.
[FIG. 7] FIG. 7 is a view illustrating a state transition of a train control processing unit according
5 to the first embodiment.
[FIG. 8] FIG. 8 is a flowchart illustrating a process in the monitoring state of the train control
processing unit according to the first embodiment.
[FIG. 9] FIG. 9 is a flowchart illustrating a process in a wait state of the train control processing
unit according to the first embodiment.
10 [FIG. 10] FIG. 10 is a view illustrating a state transition of a central processing unit of a recovery
device unit according to the first embodiment.
[FIG. 11] FIG. 11 is a flowchart illustrating a process in a recovery standby state of the central
processing unit of the recovery device unit according to the first embodiment.
[FIG. 12] FIG. 12 is a flowchart illustrating a process in a recovery execution state of the central
15 processing unit of the recovery device unit according to the first embodiment.
[FIG. 13] FIG. 13 is a timing chart when the signaling safety system according to the first
embodiment re-issues the signaling telegram.
[FIG. 14] FIG. 14 is a schematic view of a configuration of a signaling safety system according
to a second embodiment.
20 [FIG. 15] FIG. 15 is a view illustrating a format of a signaling telegram according to the second
embodiment.
[FIG. 16] FIG. 16 is a view illustrating a state transition of a central processing unit of a recovery
device according to the second embodiment.
[FIG. 17] FIG. 17 is a flowchart illustrating a process in a recovery standby state of the central
25 processing unit of the recovery device according to the second embodiment.
[FIG. 18] FIG. 18 is a flowchart illustrating a process in a recovery execution state of the central
processing unit of the recovery device according to the second embodiment.
DESCRIPTION OF EMBODIMENTS
30 [0008]
A train signaling safety system has been devised to circulate a telegram among
trains and points present in a control area divided into a plurality of blocks, share information
such as an occupancy right to each block, a point state, and a point orientation instruction, and
perform interval control, exclusive control, course configuration control on the trains in the
5
control area.
[0009]
However, if the telegram circulating among the trains and points is lost due to a
device failure or an abnormality in wireless communication, the information such as the
occupancy right t 5 o the block shared among the trains and points cannot be updated, and thus the
system stops. In that case, it can be considered to recover the system in such a manner that an
operating staff or a station staff confirms all the train positions in that section and re-issues the
telegram reflecting the current state, which takes manpower and time, and thus reduces
operability.
10 [0010]
Meanwhile, if the telegram is re-issued without confirming the current state, the
interval control, exclusive control, course configuration control on the trains implemented by a
single signaling telegram may be destroyed.
[0011]
15 In view of this, when an abnormality is detected during circulation of the
signaling telegram, the present embodiment causes a member device such as a train and a point
to stop changing the safety information contained in the signaling telegram, and then collects the
safety information stored in the member devices to configure new safety information so as to
generate a new signaling telegram containing the information, and then circulates the newly
20 generated signaling telegram among the member devices.
[0012]
Hereinafter, embodiments of the present invention will be described in more
detail with reference to the drawings.
25 FIRST EMBODIMENT
[0013]
FIG. 1 is a schematic view of a signaling safety system according to the present
embodiment, illustrating a line shape of a target track section (area) and a system configuration
including devices provided therein and the control portions thereof. In this track section, iron
30 tracks are laid in a form including branches by point devices 103, 105, and 107. An iron track
is divided into a plurality of blocks including a block 118. Each block serves as a basic unit
(block) which a series of trains can exclusively enter.
[0014]
In FIG. 1, a train 101 is present in this track section. Not only the train 101 but
6
also other trains can be present in this track section, but for the sake of simplicity, the description
will focus on a situation where only the train 101 is present. When the train 101 runs on this
track section, so as not to be collided with any other train entering this track section, it must be
guaranteed for safety that the block that the train 101 has entered or attempts to enter is
exclusively occupied and 5 the points controlling branches present in the travel path is oriented
and fixed (locked) in the right direction.
[0015]
For the purpose of guaranteeing this, the signaling safety system of the present
embodiment comprises: a signaling telegram 109 containing a member list registering
10 information identifying vehicles and points present in a track section and safety-related
information (hereinafter collectively referred to as "safety information") including a block
occupancy right, a point orientation direction and a lock state; a train control processing unit 102
provided in the train 101; and point control processing units 104, 106, and 108 provided in the
point devices 103, 105, and 107 respectively, wherein the signaling telegram 109 is shared by
15 being circulated among the train control processing unit 102 and the point control processing
units 104, 106, and 108.
[0016]
The signaling safety system using circulation of the telegram is a mechanism in
which the train control processing unit installed in the train secures an occupancy right to a
20 course that the train attempting to enter and instructs the point to orient the direction by
circulating the telegram among the trains and the points, and updating information in the
circulated telegram.
[0017]
A predetermined section in which the telegram circulates is divided into a
25 plurality of blocks. The telegram contains identification information of a train whose
occupancy right is set to each of the plurality of blocks. The train to which the occupancy right
is set is only one to each block. Only the train to which the occupancy right to the block is set
is allowed to enter the block. Note that the telegram may be configured to contain information
instructing a direction of a point, and then the point may control the direction based on
30 information in the received telegram. Note also that the telegram may be configured to contain
a member list including the trains and the points to which the telegram should be circulated.
When the telegram is received, the train or the point determines the trains and points to which
the telegram is transmitted, based on the member list in the received telegram.
[0018]
7
Assume that a train attempts to enter a block. When the telegram is received, the
train updates the telegram so as to cause the occupancy right to the block to be set to its own
train, and transmits the updated telegram to a following train or point. However, if the
occupancy right to the block has already been set to another train in the received telegram, the
train cannot update the telegram so as to ca 5 use the occupancy right to the block to be set to its
own train, and thus cannot enter the block until the occupancy right to the block set to the other
train is released.
[0019]
When the train having the occupancy right to the block has passed through the
10 block and then receives a telegram, the train updates the telegram so as to cause the occupancy
right to the block set to its own train to be released, and then transmits the updated telegram to a
following train or point.
[0020]
The above method can implement safety using circulation of the telegram. Note
15 that a more detailed description of the mechanism for implementing safety by this method is
disclosed in Patent Literature 1.
[0021]
Note that the present embodiment is configured such that the member list is
contained in the signaling telegram, but the member list may be managed by another method.
20 [0022]
In the following description, the control units for devices subjected to signal
safety control using the signaling telegram 109 in the area of the present embodiment such as the
train control processing unit 102 and the point control processing units 104, 106, and 108 are
collectively referred to as a "member device". If all or any of them need to be particularly
25 distinguished, the ones or one shall be specified each time.
[0023]
The train control processing unit 102 executes software programs for
implementing not only a telegram processing unit 119 for performing a process of implementing
a basic mechanism for safety using circulation of the telegram but also a telegram monitoring
30 unit 113 to be described later. Therefore, the train control processing unit 102 includes a CPU,
a memory, and other elements and devices commonly required to execute the software programs.
[0024]
The telegram monitoring unit 113 confirms whether or not the signaling telegram
109 can continue to circulate, by checking an event that the signaling telegram 109 has not been
8
circulated even after a specified time has elapsed, an event that data of the received signaling
telegram 109 has been broken, and an event that the signaling telegram 109 cannot be
transmitted next. If such an event is detected, the telegram monitoring unit 113 notifies a
recovery device 110 to be described later of the event. This notice is transmitted in a form of
communication information of "recovery 5 request" as described later.
[0025]
The point control processing units 104, 106, and 108 also have a similar
configuration to that of the train control processing unit 102. In other words, the point control
processing units 104, 106, and 108 perform a similar process to that of the telegram monitoring
10 unit 113. In the following description of this process, unless the member device performing the
process of the telegram monitoring unit 113 needs to be particularly specified, the telegram
monitoring unit 113 is simply used instead.
[0026]
The signaling safety system of the present embodiment includes a recovery device
15 110. The recovery device 110 is different from the member device in issuing a new signaling
telegram when the signaling telegram 109 cannot normally circulate. The recovery device 110
includes a communication control unit 112 having a wireless communication function to and
from each member device. The recovery device 110 can transmit and receive data to and from
each member device through the communication control unit 112.
20 [0027]
Note that the member device also has wireless communication means for
communicating with the recovery device 110. Using this means also as wireless
communication means, for example, to circulate the signaling telegram 109 can reduce the
number of communication devices, though this is not particularly specified. The protocol used
25 for communication between the recovery device 110 and the member device is not particularly
specified. For example, a protocol used for communication-based train control (CBTC) is
relatively reliable and proven. Alternatively, a general-purpose wireless protocol may be used
as long as the communication quality sufficient for application can be secured. This method
may relatively reduce the need to allocate special resources for communication.
30 [0028]
Herein, the location in which the recovery device 110 is installed is not
particularly limited. If the recovery device 110 is installed in an environment where the
communication control unit 112 can ensure the communication quality or in a location whose
communication environment can be easily improved later, it can be expected to reduce the
9
number of communication error retries and to quickly and reliably implement a series of
processes of re-issuing the signaling telegram using a communication as described later.
[0029]
When installed in an operations room, the recovery device 110 can be accessed
relatively easily by an operating staff and a 5 technical staff, and thus it is expected to be able to
respond to and recovery from a device failure in a short time. In addition, when also used as an
existing wayside device such as an operation management device, the recovery device 110 can
eliminate the need to install a new device and thus can be easily physically introduced.
[0030]
10 The recovery device 110 includes a central processing unit 111. The central
processing unit 111 executes software programs implementing the process of the recovery device
110 of the present embodiment, including the processes of an information collection unit 115, a
failure identification unit 116, and a telegram generation unit 117 to be described later.
Therefore, the central processing unit 111 includes a CPU, a memory, and other elements and
15 devices commonly required to execute the software programs.
[0031]
Herein, the description will focus on the architecture of the central processing unit
111.
[0032]
20 In general, a signaling safety system for passenger rail is a safety-critical system
for human life, and thus the processing unit thereof includes a safety computer having a special
architecture that can maintain the system in a safe state without losing control even if an
accidental device failure occurs.
[0033]
25 Although the specific method will be described later, the central processing unit
111 preferably includes a safety computer similar to that of the member device to re-issue the
signaling telegram for the same purpose as the recovery device 110. This is because if the
central processing unit 111 issues a signaling telegram containing incorrect information such as
the occupancy right information on the block on which the train already exists being "free", the
30 member device performing safety control based on the signaling telegram cannot exclude the
risk of train collision in the block.
[0034]
In general, the control device in the signaling safety system may use a redundant
configuration to ensure the intended operability. In consideration of this need, the central
10
processing unit 111 may also use a redundant configuration, but assuming that the same
hardware as that of control device for the member device is used, the redundant configuration of
the central processing unit 111 has less effect of improving operability than the redundant
configuration of the control device in the member device. This is because the central
processing unit 111 should operate 5 from when an abnormality is detected in the signaling
telegram 109 until recovery as described later, and thus while the signaling telegram 109 is
normal (normal operation), any failure may not affect the normal operation of the signaling
safety system.
[0035]
10 Even if the central processing unit 111 configured as a single system (nonredundant
system) fails during normal operation, repair or replacement can be made during
normal operation. Such a device configuration and operation can be provided without
compromising operability of the signaling safety system. As exemplified above, if the recovery
device 110 is provided, for example, in an operations room that can be accessed easily by an
15 operating staff and a technical staff, and further has self-failure diagnosis and failure notification
functions, the notified technical staff can complete repair and replacement of the central
processing unit 111 during normal operation with higher possibility.
[0036]
Now, the description will return to the central processing unit 111. As described
20 above, the central processing unit 111 includes the information collection unit 115, the failure
identification unit 116, and the telegram generation unit 117 as the software programs.
Hereinafter, these will be described.
[0037]
When the recovery request is received from one of the member devices, the
25 information collection unit 115 transmits to all the member devices a request (wait request) to
send the safety information stored therein and acquires the safety information. As used herein,
the recovery request refers to communication information indicating that when an abnormality
event related to the signaling telegram is detected, the telegram monitoring unit 113 notifies the
recovery device 110 of the event as described in the description of the telegram monitoring unit
30 113. In addition, it is assumed that every member device stores the safety information
contained in the last processed signaling telegram, in the storage area.
[0038]
Of the member devices, the failure identification unit 116 identifies a member
device from which a response to the wait request cannot be obtained, as a failure. This failure
11
information is obtained to be used for the purpose of excluding the failed device from the
member list for a new signaling telegram in the telegram generation unit 117 to be described
later. The failure may be identified such that, for example, when a response to the wait request
cannot be obtained from a member device after a predetermined time has elapsed or a response
to the wait request cannot be obta 5 ined from a member device after the wait request has been
transmitted a predetermined number of times, then the member device is identified as a failed
device.
[0039]
The process of the telegram generation unit 117 follows the processes of the
10 information collection unit 115 and the failure identification unit 116. The telegram generation
unit 117 uses the safety information acquired by the information collection unit 115 to compose
new safety information, to generate a new signaling telegram containing the new safety
information, and then to transmit (issue) the new signaling telegram to any one of the devices so
as to circulate among the devices in the member list contained in the new safety information.
15 [0040]
As used herein, the member list contained in the new safety information is
composed by excluding the device identified as the failed device by the failure identification unit
116 from the member devices. Although the member list is composed by including the device
identified as the failed device, the signaling telegram can be re-issued. However, circulation of
20 the signaling telegram may be disrupted again at the device identified as the failed device, which
may reduce operability of the signaling safety system depending on the way of failure. In
contrast to this, it is expected to suppress the reduction in operability by excluding the device
identified as the failed device from the member list.
[0041]
25 The format of the signaling telegram 109 is described with reference to FIG. 2.
FIG. 2 illustrates a configuration example of the information contained in the signaling telegram
109. Note that the specific value of the information contained in the signaling telegram 109
illustrated as an example of an area number, member identification information, block
identification information, point lock position instruction, and point position status is not
30 specified to correspond to which in the configuration in FIG. 1.
[0042]
The area identification 201 contains an ID number identifying the area managed
by the signaling telegram 109.
[0043]
12
A member list 202 contains information identifying the device added to
circulation of the signaling telegram 109 and the order of circulation.
[0044]
The block occupancy right 203 contains identification information of each block
constituting a track section of an area and the occupancy 5 right information of each block. In the
configuration example of FIG. 2, at least blocks 1 to 6 are present in area 2, block 1 and block 2
are not occupied, and the blocks from block 3 to block 6 are occupied by train A.
[0045]
The point lock position instruction 204 contains information indicating the
10 orientation direction of each point in the area. In the configuration example of FIG. 2, every
point is indicated to be oriented in a normal direction. Alternatively, a point may be indicated
to be oriented in a reverse direction paired with this direction.
[0046]
The point position status 205 contains information indicating in which direction
15 each point in the area is fixed. In the configuration example of FIG. 2, it is understood that all
the points are fixed (locked) in a normal direction. Alternatively, a point can be locked in a
reverse direction paired with this direction or can take a state (NON-LOCK) which is neither
normal nor reverse.
[0047]
20 The above pieces of information 201 to 205 are used in a method of implementing
signal safety by circulating the above-described signaling telegram.
[0048]
In the present embodiment, the signaling telegram 109 further contains a telegram
issue number 206 and a telegram update number 207.
25 [0049]
The value contained in the telegram issue number 206 is incremented each time
the recovery device 110 re-issues the signaling telegram as described in FIG. 1. Assume that
the device in the train and the point receives the signaling telegram. If the value of the received
signaling telegram is greater than the value of the signaling telegram circulated so far, then the
30 received signaling telegram can be identified as a new signaling telegram. Alternatively, if the
value of the telegram issue number in the received signaling telegram is less than the value of the
telegram issue number in the signaling telegram circulated so far, then the received signaling
telegram can be identified as an old signaling telegram and can be discarded.
[0050]
13
The value contained in the telegram update number 207 is incremented each time
the signaling telegram circulates among the devices. A combination of this value with the value
contained in the telegram issue number 206 can be used to know how many times a signaling
telegram has circulated.
5 [0051]
The basic operation of the signaling safety system according to the present
embodiment will be described with reference to FIG. 3. FIG. 3 illustrates the system operation
in the form of transition between the two states: a monitoring state 302 and a recovery execution
state 303. Note that the state transition in FIG. 3 is distinguished from that of an individual
10 member device and recovery device. Each state thereof will be described later.
[0052]
When signal safety due to circulation of the signaling telegram starts at a starting
point 301, the system transits to the monitoring state 302.
[0053]
15 The monitoring state 302 is a state of monitoring the soundness of the signaling
telegram 109. This state is maintained until an abnormality of the signaling telegram 109 is
detected (that is, during normal circulation). When an abnormality of the signaling telegram
109 is detected, the system transits to the recovery execution state 303 to be described later.
[0054]
20 Herein, in the present embodiment, the abnormality of the signaling telegram is
defined as a state in which circulation of the signaling telegram stops in the middle. This state
can be detected when communication for circulating the signaling telegram reaches a timeout as
described later. Note that the type of the state in which the signaling telegram is abnormal is
not limited to this, and the method of detecting the abnormality is not limited to this, either. For
25 example, assuming that the signaling telegram contains a check code, if a mismatch between the
check code and data is detected, the abnormality may be identified.
[0055]
The recovery execution state 303 refers to a state in which the recovery device
110 is executing a series of processes until a new signaling telegram is issued. The detail of the
30 series of processes will be described later. When completing re-issuing the signaling telegram,
the system transits to the monitoring state 302.
[0056]
As described above, the signaling safety system of the present embodiment goes
back and forth between the two states 302 and 303 related to the state of soundness of the
14
signaling telegram 109.
[0057]
The outline of the series of processes to be performed in the recovery execution
state 303 is described with reference to FIG. 4. A starting point 401 indicates the starting point
of the process, which proceeds to a 5 process 403 and a process 404. There is no restriction on
the order of these processes. After both the processes are completed, the process may proceed
to a process 405. Note that as illustrated in FIG. 12 later, for convenience of implementation,
the present embodiment illustrates an example in which the process 404 is executed immediately
before the process 405.
10 [0058]
The process 404 identifies a failed device from among the member devices. The
information on the failed device is used to determine the circulation destination (member list)
when a new signaling telegram is generated by the process 405 later. In the present
embodiment, this process detects a communication disabled state as a failure. In the
15 communication disabled state, the signaling telegram cannot be circulated and thus is not subject
to control of the signaling safety system according to the present embodiment. Therefore, the
process 405 may be set to exclude a failed device from the circulation destination of the new
signaling telegram so as to allow the signaling telegram to circulate soundly among the
remaining devices.
20 [0059]
Note that herein the detected failure is not limited to the inability of
communication. For example, such a train as being subject to a self-run disabled failure only
prevents another member device from securing a new course even if communication is enabled
and a new course in the area can be secured. Thus, a failure of such a type as a train cannot run
25 by itself may also be included in the detection target here. In that case, failure information may
be included in the response to the wait command to be transmitted.
[0060]
The process 403 invalidates the signaling telegram circulating in the member
device and causes the recovery device to collect the safety information stored therein. This
30 process inputs the safety information in the process 405 that generates a new signaling telegram
later.
[0061]
At this time, it is not enough to simply obtain safety information from any one of
the member devices and input the safety information in the process 405 as is, but it is basically
15
necessary to select information capable of implementing safety from the safety information
stored in all the member devices. The reason for this is that because of the nature that the
member devices share the safety information while circulating the signaling telegram, the safety
information stored in each member device does not always match with each other at a certain
point of time. For this reason, for example, b 5 y referring to the telegram update number 207 in
the format of the signaling telegram described in FIG. 2, the safety information in the signaling
telegram with the largest number (that is, the latest signaling telegram) may be used.
[0062]
Alternatively, the information in the current state (information in the locked state
10 for the point, or information on the occupied block for the train) may be newly collected again
from all the member devices. If the safety information has insufficient information but the
insufficient information can be defined on a safe side, the information may be used for the
moment. For example, unless the point state is locked in either normal or reverse state, the
course including the point cannot be secured and the train cannot enter the course, and thus
15 NON-LOCK is on a safe side.
[0063]
The process 405 generates a new signaling telegram containing the safety
information obtained above, and transmits the new signaling telegram to any of the member
devices to be newly circulated. At this time, the failed device identified by the process 404 is
20 excluded from the new member list. This process proceeds to an ending point 406 of the
process.
[0064]
Hereinbefore, the description has focused on the outline of the process of reissuing
the signaling telegram in the signaling safety system of the present embodiment.
25 Hereinafter, the processes of the member device and the central processing unit 111 of the
recovery device (hereinafter simply referred to as "recovery device") for implementing this will
be described with each process distinguished. First, each processing request is illustrated in
FIGS. 5 and 6. In FIG. 5, of the states of the signaling safety system described in FIG. 3, the
monitoring state 302 is divided into that of the member device and the recovery device with each
30 content of the process distinguished. Note that the member device comprises a plurality of
member devices, and processes 501 to 507 are performed by each of the member devices as
described later. Of the processes, the process 507 transmits a signal (recovery request) to the
recovery device 110. A series of processes of the monitoring state 302 ends at an ending point
509 following a process 508 of the recovery device 110 after a signal (recovery request) is
16
received from the member device, but this signal may be a signal (recovery request) from any of
the member devices.
[0065]
The monitoring state 302 starts at the starting point 501 followed by the process
503. The process 503 confirms receipt 5 of the signaling telegram. If "receipt is confirmed",
the process proceeds to the process 505. Herein, even if the signaling telegram is received but
the signaling telegram is identified as an old signaling telegram, as the telegram issue number
206 is described in FIG. 2, the signaling telegram is discarded and is not treated as "receipt is
confirmed". Unless "receipt is confirmed", the process proceeds to the process 506.
10 [0066]
The process 505 performs safety control using the signaling telegram and
circulation of the signaling telegram. This process corresponds to the telegram processing unit
119 in FIG. 1. The process 505 returns to the process 503 to wait until the signaling telegram
circulates again.
15 [0067]
The process 506 determines (timeout) whether or not the state without receipt of
the signaling telegram has exceeded a predetermined time. If the state has not exceeded a
predetermined time (no timeout occurs), the process returns to the process 503. If the state has
exceeded a predetermined time, the process proceeds to the process 507.
20 [0068]
As described above, the process 507 transmits a signal (recovery request) to the
recovery device 110. According to the present embodiment, for the purpose of notifying the
recovery device of all the member devices, the process 507 transmits the signal (recovery
request) containing the member list.
25 [0069]
The process 508 of the recovery device 110 receives the recovery request
transmitted from the process 507. After the recovery request is received, the process proceeds
to the ending point 509, and transits from the monitoring state 302 to the recovery execution
state 303 in FIG. 3.
30 [0070]
Note that the series of processes 503 and 506 corresponds to the process of the
telegram monitoring unit 113 in FIG. 1.
[0071]
The description continues with reference to FIG. 6. In FIG. 6, of the states of
17
the signaling safety system described in FIG. 3, the recovery execution state 303 is divided into
that of the member device and the recovery device with each content of the process
distinguished. The recovery execution state 303 starts at a starting point 601 following the
ending point 509 of the monitoring state illustrated in FIG. 5.
5 [0072]
The starting point 601 of the recovery execution state 303 proceeds to a process
604. The process 604 transmits a command (wait command) to all the member devices to be
notified of the safety information.
[0073]
10 A process 605 of the member device receives the wait command, and then
proceeds to a process 606. From then on, the process 606 prevents the signaling telegram
circulated so far from being received. As a specific method thereof, there can be considered a
method of incrementing the value (latest issue number) of the received telegram issue number
(see 206 in FIG. 2). More specifically, each time a signaling telegram is received, the telegram
15 issue number is compared with the latest issue number. If the telegram issue number is less
than the latest issue number, the signaling telegram is discarded. This method can prevent the
signaling telegram circulated so far from being received again. Then, the process proceeds to a
process 607.
[0074]
20 The process 607 transmits the stored safety information to the recovery device in
response to the wait command.
[0075]
A process 608 of the recovery device receives the safety information from the
member device. Here, in principle, the process 608 receives the safety information from all of
25 the plurality of member devices and passes the plurality of pieces of safety information to a
following process 609. In a case in which any one of the member devices fails, it cannot be
expected to receive the safety information from all the member devices. Thus, in reality, there
is provided a condition to end the process that a timeout time is provided or if a failed device can
be detected among the member devices, the failed device is excluded using the information.
30 The process 608 proceeds to the process 609 that composes one safety information from the
plurality of pieces of safety information, and a process 610 that registers a device without
response to the wait indication as a failed device. The processes 609 and 610 may be executed
in whichever order. When both the processes complete, the process proceeds to a process 611.
[0076]
18
Note that the processes 604, 608, and 609 from when the wait command is
transmitted until the safety information is collected and composed correspond to the process of
the information collection unit 115 illustrated in FIG. 1. The process 610 corresponds to the
processes of the information collection unit 115 and the failure identification unit 116 illustrated
5 in FIG. 1.
[0077]
The process 611 generates a new signaling telegram from the information
obtained by the processes 609 and 610. The format thereof is illustrated in FIG. 2. At this
time, a value (incremented value) matching the latest issue number set by the aforementioned
10 process 606 is set to the telegram issue number 206. Note that an initial value (e.g., 0) has been
set to the telegram update number. The member list 202 is composed by excluding the failed
device identified by the process 610.
[0078]
A process 612 transmits a new signaling telegram generated by the process 611, to
15 any one of the member devices contained in the member list. Note that the transmission
destination at this time may be any as long as the number of transmission destinations does not
exceed two or more. Herein, the processes 611 and 612 correspond to the telegram generation
unit 117 illustrated in FIG. 1.
[0079]
20 The process 612 proceeds to an ending point 613 which returns again to the
monitoring state 302. In other words, the process proceeds to the starting point 501 in FIG. 5.
[0080]
Hereinbefore, the description has focused on the processing request of each of the
member device and the recovery device with reference to FIGS. 5 and 6. Now, with reference
25 to FIGS. 7 to 12, the description will focus on how each processing request is implemented.
FIGS. 7 to 9 illustrate the process of the member device, and FIGS. 10 to 12 illustrate the process
of the recovery device.
[0081]
FIG. 7 defines the state of each member device related to recovery means of the
30 signaling telegram. Two states 702 and 703 are referred to as a monitoring state and a wait
state respectively. When signal safety due to circulation of the signaling telegram starts at a
starting point 701, the system transits to the monitoring state 702.
[0082]
When a wait command is received from the recovery device 110, the monitoring
19
state 702 returns a wait response and transits to the wait state 703. When a signaling telegram
(new signaling telegram) re-issued by the recovery device 110 is received, the wait state 703
transits to the monitoring state 702. In other words, the monitoring state 702 and the wait state
703 are repeated in the member device.
5 [0083]
FIG. 8 is a flowchart illustrating a process executed in the monitoring state 702.
The process of this flowchart is repeatedly executed. More specifically, the process starts at a
start process 801, reaches an end process 809, and then returns to the start process 801. Note
that if a condition for transition to the wait state is established in the middle, the end process 809
10 proceeds to a process flow in the wait state to be described later.
[0084]
The timing at which the process is executed repeatedly from the start process 801
in this process flow is a matter of implementation. More specifically, the timing may be
periodic or may be a certain time after the end process 809 has been reached. For the sake of
15 convenience, the present embodiment assumes the latter. In other words, the present
embodiment considers that a series of process flows will not be interrupted in the middle.
[0085]
The starting point 801 proceeds to a process 802 which determines whether or not
the wait command is received. As described in the process 604 in FIG. 6, the wait command is
20 a command transmitted from the recovery device for the purpose of notifying the safety
information stored in the member device. If the wait command is received, the process
proceeds to a process 803; and if the wait command is not received, the process proceeds to a
process 804. Note that when the process proceeds to the process 803, a timeout counter is reset
as described in a process 807 later.
25 [0086]
The process 803 is executed when the wait command is received. The process
803 increments the issue number (latest issue number) of the signaling telegram which is stored
therein and should be accepted, transmits the safety information to the recovery device, and then
proceeds to the wait state. This flowchart does not specify the process of confirming whether
30 or not the transmitted safety information has reached the recovery device. In order to ensure
more reliability, there may be added another process of waiting for an acknowledgement
response (hereinafter referred to as ACK) from the recovery device and continuing to re-transmit
the safety information when ACK is not obtained. The process transits to a wait mode and then
proceeds to the end process 809. In other words, the process proceeds to a flowchart in the wait
20
state to be described later.
[0087]
The process 804 determines whether or not the signaling telegram is received. If
the signaling telegram is received, the process proceeds to a process 805; and if the signaling
telegram is not received, the process pro 5 ceeds to the process 807. Note that in the description
of the process 503 in FIG. 5, if the received signaling telegram is old, the signaling telegram is
not treated as "receipt is confirmed". Unlike this, herein, the process 804 determines whether or
not the signaling telegram is received regardless whether the received signaling telegram is old
or not. This is because the process 805 is newly added to specifically specify whether the
10 signaling telegram is old or not.
[0088]
If the signaling telegram is received, the process 804 proceeds to the process 805
which determines whether the received signaling telegram is old or not. More specifically, if
the telegram issue number (see 206 in FIG. 2) of the received signaling telegram is equal to or
15 greater than the currently stored latest issue number, this is determined as true.
[0089]
If the determination result is true, the process proceeds to a process 806. At this
time, a timeout counter is reset as described later in the process 807. If the determination result
is not true (false), the process discards this signaling telegram and proceeds to the process 807.
20 The reason for discarding the signaling telegram is that, as described in the process 611 in FIG.
6, because of the nature that the telegram issue number is incremented each time the signaling
telegram is issued, if a false condition is established, it is considered that an old signaling
telegram is circulated after staying somewhere and has already lost its effectiveness. Note that
if the telegram issue number is greater than the latest issue number, this is determined as true,
25 and at the same time, the stored latest issue number is updated to the telegram issue number.
[0090]
The process 806 performs control of the signaling telegram and circulation of the
signaling telegram. The process 806 corresponds to the telegram processing unit 119 in FIG. 1
and the process 505 in FIG. 5 to implement signal safety during circulation of the signaling
30 telegram. When this process completes, the process proceeds to the end process 809.
[0091]
The process 807 increments the timeout counter and determines whether or not
the value is greater than a "specified value". The purpose for this determination is that during
the period from when a signaling telegram is transmitted for circulation until the signaling
21
telegram is next received, the elapsed time is greater than the specified time, and then it is
considered that the signaling telegram is lost in the middle of the circulation and timeout is
detected. When the signaling telegram is received and then transmitted to a next member
device or once timeout is detected, the timeout counter is reset. If neither condition is satisfied,
the timeout counter is incremented. The 5 "specified value" for use in this comparison is a
numerical value for determining the time length until timeout occurs. The longer the specified
value is, the longer the time until timeout occurs. This value may be determined, for example,
by adding some extra amount of time to the average time required for a signaling telegram to
circulate around. If the value of the timeout counter is greater than the "specified value", that
10 is, if timeout is detected, the timeout counter is reset, and the process proceeds to a process 808.
Otherwise, the process proceeds to the end process 809.
[0092]
Hereinbefore, it has been described that the "specified value" is determined based
on the usually considered time required for a signaling telegram to circulate around, but the time
15 required for a signaling telegram to circulate around depends on the number of member devices.
The more the number of member devices is present in the area, the longer the average time
required for the signaling telegram to circulate around. In accordance with this, also an
increase in "specified value" can prevent unnecessary timeout from occurring. The number of
member devices present in the area changes every moment, and accordingly the "specified
20 value" may be dynamically changed.
[0093]
When timeout is detected, the process 808 is performed. The process 808
transmits a recovery request to start to re-issue the signaling telegram, to the recovery device.
At this time, the process 808 transmits also the member list for the purpose of notifying the
25 recovery device which train and which point are currently involved in circulation of the signaling
telegram as a member device. When this process completes, the process proceeds to the end
process 809.
[0094]
Hereinbefore, the process of the monitoring state 702 has been described.
30 Hereinafter, the description will focus on the process flow of the wait state 703 with reference to
FIG. 9.
[0095]
FIG. 9 is a flowchart illustrating the process in the wait state 703. A series of
processes from a start process 901 to an end process 906 are repeated unless a state transition
22
occurs.
[0096]
The start process 901 proceeds to the process 902 which determines whether the
signaling telegram is received or not. If the signaling telegram is received, the process proceeds
to the process 903; and if the signaling 5 telegram is not received, the process proceeds to the
process 906. This process is the same as the process described for the process 804 in FIG. 8.
[0097]
If the telegram issue number (see 206 in FIG. 2) of the received signaling
telegram is equal to or greater than the stored latest issue number, the process 903 determines it
10 as true. If true, the process proceeds to the process 904, and if false, the process proceeds to the
end process 906. This process is the same as the process described for the process 805 in FIG.
8. If the telegram issue number is greater than the latest issue number, this is determined as
true, and at the same time, the stored latest issue number is updated to the telegram issue number.
[0098]
15 The process 904 performs control and circulation of the signaling telegram in the
same manner as the process 804 in FIG. 8.
[0099]
The process 904 proceeds to the process 905 which performs a process of
transition to the monitoring state 702. This process proceeds to the end process 906 which
20 proceeds to the start process 801 in the flowchart of the already described monitoring state 702.
[0100]
Hereinbefore, the description has focused on the two states and the process flow
of each state of the member device. Hereinafter, the description will focus on the process of the
recovery device.
25 [0101]
FIG. 10 defines the state of the recovery device related to recovery means of the
signaling telegram. Two states 1002 and 1003 are referred to as a recovery standby state and a
recovery execution state respectively. When signal safety due to circulation of the signaling
telegram starts at a starting point 1001, the system transits to the recovery standby state 1002.
30 [0102]
When a recovery request is received from the member device, the recovery
standby state 1002 transits to the recovery execution state 1003. When completing issuing a
new signaling telegram, the recovery execution state 1003 transits to the recovery standby state
1002. In other words, the recovery standby state 1002 and the recovery execution state 1003
23
are repeated in the recovery device.
[0103]
FIG. 11 is a flowchart illustrating a process executed in the recovery standby state
1002. The process of this flowchart is repeatedly executed. More specifically, the process
starts at a start process 1101, re 5 aches an end process 1105, and then returns to the start process
1101. Note that if a condition for transition to the recovery execution state is established in the
middle, the end process 1105 proceeds to a process flow in the recovery execution state to be
described later.
[0104]
10 The starting point 1101 proceeds to a process 1102 which determines whether or
not the recovery request is received. As described in the process 602 in FIG. 6, the recovery
request is a request transmitted from the member device for the purpose of requesting to transit
to a procedure of re-issuing the signaling telegram. If this is received, the process proceeds to a
process 1103, and if this is not received, the process proceeds to the end process 1105.
15 [0105]
The process 1103 reads and stores the member list received together with the
recovery request. This information is used for a process in a recovery execution state to be
described later. It has been described for the process 808 in FIG. 8 that the member list is
transmitted together with the recovery request.
20 [0106]
The process 1103 proceeds to a process 1104 which performs a process of
transition to the recovery execution state. This process proceeds to the end process 1105 which
proceeds to a process flow in the recovery execution state to be described later.
[0107]
25 Hereinbefore, the process of the recovery standby state 1002 has been described.
Hereinafter, the description will focus on the process flow of the recovery execution state 1003
with reference to FIG. 12.
[0108]
FIG. 12 is a flowchart illustrating the process in the recovery execution state
30 1003. A series of processes from a start process 1201 to an end process 1207 is repeated unless
a state transition occurs.
[0109]
The start process 1201 proceeds to the process 1202 which broadcasts the wait
command to all the member devices in the area. As described for the processes 802 and 803 in
24
FIG. 8, when the wait command is received, the member device transmits the safety information.
This process also waits for and receives this.
[0110]
When all the member devices return the safety information, the process proceeds
to the process 1203. It can be 5 known from the member list obtained by the process 1103
described in the recovery standby state whether or not the safety information can be obtained
from all the member devices. Considering a case where communication fails permanently in
any one of the member devices, not all the member devices respond to return the safety
information. Thus, there is also provided a condition such that when some time has elapsed, the
10 process unconditionally proceeds to the next process 1203. This process manages and stores
the number of times the wait command is transmitted, to be used for a later process.
[0111]
The process 1203 determines whether or not the response to the wait command
transmitted by the process 1202 can be obtained from all the member devices. If the response
15 cannot be obtained from all the member devices, the process proceeds to the process 1204, and if
obtained, the process proceeds to the process 1206.
[0112]
The process 1204 determines whether or not the managed and stored value of the
number of times the wait command was transmitted exceeds a "specified number of times". If
20 exceeding, the process proceeds to the process 1205, and if not, the process proceeds to the
process 1207. If the value does not exceed the specified number of times, the process proceeds
to the process 1207, which returns to the process 1201 which starts processing again, and then
proceeds to the process 1202 which broadcasts the wait command again.
[0113]
25 Herein, the "specified number of times" is provided to give an opportunity for
retransmission to a member device that failed to transmit the response to the wait command to
the recovery device due to an accidental cause such as noise. The more the specified number of
times, the longer the time until the signaling telegram is re-issued because the member device
tries retransmission many times. Conversely, if the value is too small, even if the response
30 cannot be transmitted due to an accidental cause, the member device is immediately determined
as a failure and is excluded from the member list for the re-issued signaling telegram as
described later. In the present embodiment, the value is set to 1, which means only one
retransmission, but may be a value other than 1.
[0114]
25
When the number of times the wait command is transmitted exceeds a "specified
number of times", the process 1205 is executed. If no response to the wait command is
obtained, the process 1205 registers the member device as a failed device, and then proceeds to
the process 1206.
5 [0115]
The process 1206 generates and re-issues a new signaling telegram from the
safety information obtained by the process 1202 and, as necessary, registration information of the
failed device identified by the process 1205. The safety information comprises a plurality of
pieces of safety information obtained from a plurality of member devices. Thus, as described
10 for the process 403 in FIG. 4, the safety information may be determined by selecting the largest
telegram update number (see 207 in FIG. 2). If there is information that cannot be determined,
information on the safety side can be tentatively contained, as described in FIG. 13 later.
[0116]
Then, a new signaling telegram is generated using the thus determined safety
15 information and a new member list excluding the member device registered as a failed device.
As described for the process 611 in FIG. 6, the format of the signaling telegram in this case
conforms to that described in FIG. 2. More specifically, an incremented value is set to the
telegram issue number 206 so as to be used for the process determined by the processes 805 and
903 on the aforementioned member device side. In addition, the telegram update number 207 is
20 set to an initial value (e.g., 0). The thus generated new signaling telegram is transmitted to any
one of the devices in the member list. Herein, the transmission destination may be any device
in the member list on condition that the number of devices does not exceed two. When the
above completes, the system transits to a recovery standby state, and the process proceeds to the
end process 1207.
25 [0117]
Hereinbefore, the description has focused on the two states and the process flow
of each state of the recovery device. Hereinafter, the description will focus on an example of a
system behavior when the signaling telegram cannot circulate with reference to FIG. 13.
[0118]
30 FIG. 13 is a sequence diagram illustrating an example of a recovery process of the
signaling telegram. The upper most portion of the figure illustrates processing units related to
recovery of the signaling telegram including the central processing unit 111, the train control
processing device 102, the point control processing devices 104, 106, and 108 of the recovery
device listed from the left to the right. The process sequence of each unit evolves from top to
26
bottom. For convenience of explanation, the leftmost portion of the figure illustrates specific
times t1 to t7 along with the time axis going from top to bottom. In addition, the central
processing unit 111 and the point control processing unit 108 representing the member devices
illustrate state names along the sequence, each corresponding to a specific time. Hereinafter,
5 the sequence will be described in order.
[0119]
At a time t1, the train control processing unit 102 transmits a signaling telegram,
which passes through the point control processing units 104, 106, and 108, in sequence and then
returns to the train control processing unit 102 to circulate again. During this time, the central
10 processing unit 111 is in the recovery standby state, and the point control processing unit 108 is
in the monitoring state. At a time t2, a permanent failure in a communication function of the
point control processing unit 104 is assumed to occur in the middle of the circulation.
[0120]
Then, there continues a state in which the signaling telegram does not circulate to
15 the point control processing unit 106 for a while. Eventually, at a time t3, for the first time, the
point control processing unit 106 detects a timeout and transmits a recovery request to the central
processing unit 111. In response to this, the central processing unit 111 transits to the recovery
execution state. Note that the central processing unit 111 also receives a member list together
with this.
20 [0121]
The present embodiment provides the same timeout time as that of the point
control processing unit 106 also to the train control processing unit 102 and the point control
processing unit 108. Thus, the central processing unit 111 successively receives a recovery
request from these units, but after transition to the recovery execution state, performs no
25 processing though the requests are received.
[0122]
At a time t4, first, the central processing unit 111 in the recovery execution state
broadcasts a wait command. Then, the train control processing unit 102 and the point control
processing units 106 and 108 receive this wait command, increment the latest issue number so as
30 not to receive the circulated signaling telegram from then on, return the stored safety
information, and transit to the wait state. However, the point control processing unit 104
neither receives the wait command nor returns the safety information due to the inability of
communication function. Then, at a time t5 when a predetermined time has elapsed, the central
processing unit 111 resultantly detects that the safety information of all the member devices has
27
not yet been received in the receive buffer, and then broadcasts the wait command again.
[0123]
The wait command reaches again the train control processing unit 102 and the
point control processing units 106 and 108, but these member devices have already entered the
wait state, and thus do not perform any processing 5 on the received wait command. The point
control processing unit 104 cannot receive the wait command again due to the inability of
communication function. At a time t6 when a predetermined time has elapsed, the central
processing unit 111 still detects that the wait command has not yet been received from all the
member devices. Since the number of times the wait command is retransmitted has reached the
10 upper limit, the point control processing unit 104 that has not returned the safety information is
registered as a failed device.
[0124]
Then, the central processing unit 111 selects the largest telegram update number
(see 207 in FIG. 2) from within the safety information obtained from the train control processing
15 unit 102 and the point control processing units 106 and 108 and then generates a new signaling
telegram using the largest telegram update number.
[0125]
Then, the member list is composed with the train control processing unit 102 and
the point control processing units 106 and 108 excluding the point control processing unit 104
20 registered as the failed device. Then, a signaling telegram is generated by containing the thus
generated safety information and incrementing the telegram issue number (see 206 in FIG. 2).
Then, at a time t7, the signaling telegram is transmitted as a new signaling telegram to the train
control processing device 102.
[0126]
25 Note that when the safety information of the new signaling telegram is
determined, it is assumed that a point 103 includes the point control processing device 104
registered as a failed device. If the locked state is unknown, "NON-LOCK" may be contained
in the information of the point 103 as information on the safe side with the point lock position
instruction information as "being failed". Thus, a course including a block having the point 103
30 therein cannot be newly secured. Even if the point is not locked, it is expected to maintain
safety.
[0127]
Alternatively, in a case where it is certain that the point 103 is locked in the state
in which the signaling telegram is lost, the state information of the point is locked in a normal or
28
inverse position according to the actual state, and if the block including the point is not occupied,
the state remains as is. Then, a new course including the point can be secured though it is only
in the locked direction. The present embodiment assumes that the control device of a point
fails. If the control device of a train fails, the block occupied by the train remains "occupied" as
is. Then, even if the train continues to run with c 5 ommunication disabled, safety can be secured.
[0128]
At a time t7, the central processing unit 111 transmits the new signaling telegram
and then returns to the recovery standby state. When the circulation of the new signaling
telegram is received, each of the train control processing unit 102 and the point control
10 processing units 106 and 108 resumes the circulation and returns to the monitoring state. In this
manner, the re-issue of the signaling telegram is implemented.
[0129]
Note that the point control processing unit 104 has failed only in communication
function. Thus, after a timeout time has elapsed since time t2, the point control processing unit
15 104 attempts to repeatedly transmit a recovery request. Therefore, when the communication
function eventually recovers, the recovery request reaches the central processing unit 111.
Then, the central processing unit 111 enters the recovery execution state and starts to re-issue the
signaling telegram again. As a result, all the member devices start to participate in the
circulation of the new signaling telegram.
20 [0130]
As described above, the signaling safety system of the present embodiment is a
signaling safety system which implements exclusive control by circulating a signaling telegram
among the trains and points in the area and can re-issue the signaling telegram when the
circulation of the signaling telegram is stuck due to a communication function failure and other
25 causes. In this case, the device causing the stuck circulation of the signaling telegram is
identified as a failed device and the signaling telegram circulates only among the member
devices excluding the failed device. Then, a new course can be secured as long as the course
includes the block without interfered by the failed device. Thus, the operation can be continued
within the range.
30 [0131]
According to the present embodiment, the telegram monitoring unit 113 is
installed in the trains and points, but may be installed in the recovery device 110. In this case,
the soundness of the signaling telegram 109 may be determined in such a manner that, for
example, the central processing unit 111 periodically makes an inquiry to any one of the member
29
devices, and if the telegram update number 207 contained in the signaling telegram 109 has not
increased, an abnormality is determined to occur. In this case, the period of the inquiry may be
relatively long regardless of the period of the circulation of the signaling telegram.
Alternatively, there may be provided a mechanism in which the member device always notifies
the recovery device when transmitting the signaling telegram. 5 Then, the recovery device can
detect the abnormality in the circulation of the signaling telegram by monitoring the interruption
of the notification.
[0132]
The present embodiment has considered only a single area controlled by one
10 signaling telegram 109. If there is another area subject to a similar control, such as an area
adjacent to this area, the recovery device 110 may apply the process described in the present
embodiment to a plurality of areas. As long as the signaling telegram circulates soundly, the
process of the recovery device 110 only waits for a recovery request in the recovery standby state
described in FIG. 11, which does not require high processing load. Thus, the plurality of areas
15 can be relatively easily administered. If during the recovery process in an area, the recovery
device 110 receives a recovery request from another area, the recovery process received later
may be handled later. Although the operability of the train operation in the area is reduced, but
the cost of the entire signaling safety system can be reduced without impairing safety as its
primary objective.
20 [0133]
Note that the present embodiment has described that the recovery device 110 is
installed separately from the member device along the wayside, but for example, the member
device may have the same function as this. In this case, the process of the control processing
unit of the member device becomes more complex and larger-scale, but there is no need to install
25 a new device for recovery, allowing that much hardware to be saved in terms of cost.
According to the present embodiment, the recovery device 110 is installed separately from the
member device along the wayside. As described above, the present embodiment provides
advantages in that the recovery device can be relatively easily maintained and replaced even
during train operation and a plurality of areas can be administered by being configured to be
30 communicable with the trains and points in the plurality of areas.
SECOND EMBODIMENT
[0134]
Hereinafter, the second embodiment will be described. The second embodiment
30
is greatly different from the first embodiment in providing a dedicated means for managing a
member list for use in determining the destination and order of circulation of the signaling
telegram in the area.
[0135]
Now, the description will focus on t 5 he configuration of the signaling safety
system of the second embodiment with reference to FIG. 14. The configuration and process
content of a train 1401, a train control processing unit 1402, points 1403, 1405, and 1407, point
control processing units 1404, 1406, and 1408, a telegram monitoring unit 1413, a telegram
processing unit 1419, a recovery device 1410, a central processing device 1411, an information
10 collection unit 1415, and a telegram generation unit 1417 are the same as those of the train 101,
the train control processing unit 102, the points 103, 105, and 107, the point control processing
units 104, 106, and 108, the telegram monitoring unit 113, the telegram processing unit 119, the
recovery device 110, the central processing device 111, the information collection unit 115, and
the telegram generation unit 117 in the first embodiment (FIG. 1).
15 [0136]
As to the processing for specifying the member list, which is performed by the
train control processing unit 1402, the point control processing units 1404, 1406, and 1408, and
the central processing unit 1411, the first embodiment implements this process by reading from
and writing to the information contained in the signaling telegram 109, while the present
20 embodiment implements this process by providing each processing unit with a memory area for
storing the member list, wherein each processing unit receives the member list from an operation
management device 1420 to be described later, and writes and reads the information to and from
the memory area. The portion implementing this process corresponds to a member list storage
unit 1423 which is provided for each of the train control processing unit 1402 and the point
25 control processing units 1404, 1406, and 1408.
[0137]
The member list storage unit 1423 receives the member list from an operation
management device 1420 to be described later via communication and stores the information
therein. The telegram processing unit 1419 performs control using the signaling telegram 1409
30 and circulation of the signaling telegram 1409, and in this case, the destination and the order of
circulation of the signaling telegram 1409 is determined using the information read from the
member list storage unit 1423. Note that the configuration of the point control processing units
1404, 1406, and 1408 is the same as that of the train control processing unit 1402.
[0138]
31
The present embodiment is different from the first embodiment in the path related
to the communication between the member device and the recovery device 1410. According to
the present embodiment, the operation management device 1420 includes a communication
control unit 1412 for wireless communication to and from the member device and
communication means 1422 for 5 communication to and from the recovery device 1410.
Therefore, the member device can communicate with the recovery device 1410 via the operation
management device 1420. Here, the communication means 1422 may be wireless or wired as
long as it can transmit as much information as the amount of the signaling telegram 1409.
[0139]
10 The operation management device 1420 is a device constituting an operation
management system, commonly known in railway systems, having functions to know linear
information of an area, the positions of trains and points present in the area, have an operation
plan, and direct the course of the train according to the operation plan.
[0140]
15 The operation management device 1420 of the present embodiment includes a
central processing unit 1426 having a CPU and a memory capable of executing software
programs for implementing the purpose of operation management, and a member list
management unit 1421 as one of the functions to be implemented on this. The member list
management unit 1421 is a processing unit providing the aforementioned member list storage
20 unit 1423 with information on the member device present in the area and information on the
order of circulation of the signaling telegram. The member list management unit 1421
preliminarily stores linear information of the area and information identifying the point in the
area. In addition, the member list management unit 1421 tracks and knows which train is
where, by regularly communicating with the train in operation.
25 [0141]
Thus, the member list management unit 1421 knows that the train 1401 and the
points 1403, 1405, and 1407 are present in the area in FIG. 14 considered in the present
embodiment and can uniquely determine the order of circulation of the signaling telegram 1409
among those devices. Note that the circulation of the signaling telegram 1409 may be
30 determined in any order.
[0142]
The operation management device 1420 further includes a failure identification
unit 1416 as another function to be implemented on the central processing unit 1426. Like the
failure identification unit 116 of the first embodiment, the failure identification unit 1416
32
registers the member device that has not responded to a command via communication, as a failed
device, but, without being limited to this, the failed device may be identified using device
information, if any, which the operation management device 1420 obtains for the purpose of
operation management.
5 [0143]
The member list management unit 1421 composes the member list by excluding
the device registered as the failed device by the failure identification unit 1416 when the member
list is transmitted to the member list storage unit 1423.
[0144]
10 With the communication configuration as described above in mind, the process of
the central processing unit 1411 will be described. In the central processing unit 111 of the first
embodiment, the information collection unit 115 and the telegram generation unit 117 first
determine the member device serving as the communication destination by the member list
received from the member device together with the recovery request, while each of the
15 information collection unit 1415 and the telegram generation unit 1417 of the present
embodiment does not manage the member device serving as the communication destination, but
the member list management unit 1421 in the operation management device 1420 located on the
communication path with the member device appropriately controls the communication
destination between the central processing unit 1411 and the member device based on the
20 member list held therein.
[0145]
The present embodiment will consider the relationship between an area
(hereinafter particularly referred to as a reference area) including a plurality of blocks such as the
block 118 considered in the first embodiment and an area 1424 adjacent to this area. The
25 adjacent area 1424 includes a train 1425 which attempts to enter the reference area. The train
1425 includes wireless communication means for communicating with the operation
management device 1420. When an entry request is received from the train 1425, the member
list management unit 1421 can use this communication means to newly add the train 1425 to the
member device in the reference area. Alternatively, regardless of whether or not the entry
30 request is received, the operation management device 1420 may add a train to the member list by
predicting the entry of the train from the information on the device obtained for the purpose of
operation management.
[0146]
Note that in FIG. 14, the operation management device 1420 and the recovery
33
device 1410 have been described as different devices, but may be constituted by one device.
For example, the process of the present embodiment may be implemented by a recovery device
including a central processing unit capable of implementing the processes of the member list
management unit 1421, the failure identification unit 1416, the information collection unit 1415,
and the te 5 legram generation unit 1417; and the communication control unit 1412.
[0147]
Hereinbefore, the configuration in FIG. 14 has been described with an emphasis
on the devices and processes other than the signaling telegram 1409. Hereinafter, the
description will focus on the configuration of the signaling telegram 1409 with reference to FIG.
10 15.
[0148]
FIG. 15 illustrates the format of the signaling telegram 1409. The format of the
signaling telegram 1409 excludes the member list 202 from the format of the signaling telegram
109 of the first embodiment illustrated in FIG. 2. The information corresponding to the
15 member list 202 is implemented by the member list management unit 1421 and the member list
storage unit 1423 which have already been described with reference to FIG. 14 instead.
Hereinafter, the description will focus on the state and the process of the central processing unit
1411.
[0149]
20 FIG. 16 illustrates the state definition and transition conditions of the central
processing unit 1411. This is the same as FIG. 10 illustrating those of the central processing
unit 111 of the first embodiment. More specifically, when a recovery request is received in a
recovery standby state 1602, the state transits to a recovery execution state 1603. When
completing issuing a new signaling telegram in the recovery execution state 1603, the state
25 transits to the recovery standby state 1602.
[0150]
The process of the recovery standby state 1602 is described with reference to FIG.
17. In the recovery standby state, a series of processes from a start process 1701 as the starting
point to an end process 1705 as the ending point are periodically executed.
30 [0151]
The start process 1701 proceeds to a process 1702 which checks the receive
buffer of the communication means 1422 to determine whether or not a recovery request is
received from the operation management device 1420. If the recovery request is received, the
process proceeds to a process 1704; and if the recovery request is not received, the process
34
proceeds to the end process 1705. Herein, the recovery request is originally transmitted from
the member device. When the recovery request is received, the operation management device
1420 relays the recovery request to the recovery device 1410 via the communication means
1422.
5 [0152]
The process 1704 is a process of transition to the recovery execution state. This
processes proceeds to the end process 1705 which further proceeds to the process flow in the
recovery execution state to be described in FIG. 18.
[0153]
10 The process flow in the recovery execution state 1603 will be described with
reference to FIG. 18. In FIG. 18, processes 1801 to 1805 correspond to the process content in
the recovery execution state 1603, but the process of the operation management device 1420
related to the processes 1801 to 1805 is also described. The process of the central processing
unit 1426 is illustrated on the right-hand side of a partition 1806. In FIG. 18, the dotted arrows
15 indicate data flow, which will be described together with the related processes as needed.
[0154]
In FIG. 18, particularly in the process of the central processing unit 1426, in order
to clarify the data flow of the portion related to knowing and managing member devices, there is
specified a memory area 1813 storing the member list, in the member list management unit.
20 The memory area 1813 stores not only information in the member list but also at least
information indicating the presence or absence of a device failure specified in the member list
and thus provides means of reading and writing the information. When the means attempts to
read the member list and finds that a failed device is contained in the member list, the means
composes a new member list by excluding the failed device and passes the new member list to
25 the device on the reading side. In FIG. 18, an arrow indicating an output from the memory area
1813 indicates reading the member list, and an arrow indicating an input to the memory area
1813 indicates writing failure information on the identified device to the member list.
[0155]
Now, the description will return to the process of the recovery execution state
30 1603, continuing in order with the start process 1801. The start process 1801 proceeds to the
process 1802 which transmits the wait command to the operation management device 1420. At
this time, there is no need to specify the member device as the destination. The process 1802
proceeds to the process 1803 which waits to receive the safety information from the operation
management device 1420.
35
[0156]
Meanwhile, the description will proceed to the central processing unit 1426 of the
operation management device 1420. When this wait command is received, a process 1807
broadcasts the wait command to all the member devices in the area where the device originating
the recovery request is located. The 5 description continues with the central processing unit
1426. The process 1807 proceeds to a process 1808 which checks whether or not the safety
information is received from all the member devices. If not, the process proceeds to a process
1809 which checks whether or not the number of times the wait command is transmitted exceeds
a specified number of times. If not, the process returns to the process 1807 which transmits the
10 wait command again, and later, if the process 1808 determines that the wait response is received
from all the member devices, the process proceeds to a process 1811.
[0157]
Alternatively, if the process 1809 determines that the number of times the wait
command is transmitted exceeds a specified number of times, the process proceeds to a process
15 1810 which registers the device that has not returned the wait response, as a failed device.
Then, the process proceeds to the process 1811. Herein, the process 1808 uses the member list
read from the memory area 1813. In addition, the process 1810 writes information on the
device determined as failed, to the memory area 1813. The process 1811 transmits the safety
information received from the member device together with the acknowledgement response, to
20 the recovery device 1410.
[0158]
Note that the processes 1807 to 1811 of the central processing unit 1426 described
above correspond to the processes 1202 to 1205 of the first embodiment described in FIG. 12.
The content implemented by the process 1206 corresponds to the content implemented by the
25 processes 1811, 1803, 1804, and 1812 of the present embodiment.
[0159]
Here, the description will return to the central processing unit 1411 of the
recovery device 1410. The process 1803 receives the safety information from the operation
management device 1420 in this manner. Then, the process 1804 generates a new signaling
30 telegram based on this and transmits the new signaling telegram to the operation management
device 1420. Then, the process proceeds to the end process 1805.
[0160]
When the new signaling telegram is received, the central processing unit 1411 of
the operation management device 1420 reads the member list from the memory area 1813, and
36
distributes the member list to the identified member devices. At this time, if an entry request is
received from the train 1425 in the adjacent area 1424 (this can be known, for example, by
reading a receive buffer dedicated to entry requests), the member list is updated so as to add the
train 1425. Then, the updated member list is distributed to the member devices identified by
the updated member list. Thereafter, a new signaling 5 telegram is transmitted to a device listed
at the top of the member list, and then the new signaling telegram starts to circulate to the
member devices including the train 1425 attempting to come in from the adjacent area 1424.
[0161]
Note that when the train 1425 is added to the member list to be restructured, the
10 train 1425 may be listed in any order in the member list. For example, the train 1425 may be
added to the end of the member list. Note also that the present embodiment has described that
the transmission destination of the new signaling telegram is a device listed at the top of the
member list, but the present embodiment is not limited to this, and may be any device listed in
any order in the member list.
15 [0162]
According to the present embodiment, even if a signaling telegram is lost during
circulation, the signaling telegram can be issued again, to thereby continue the control of signal
safety and the operation of the trains. In addition, when an entry request is received from a
train in an adjacent area in the middle of the process of re-issuing the signaling telegram, the
20 train can be allowed more quickly to come in from the adjacent area by including the device in
the members to which the signaling telegram is newly issued.
REFERENCE SIGNS LIST
[0163]
25 101 Train
102 Train safety device
201, 211, 221 Point
202, 212, 222 Point safety device
301 Signaling telegram
30 401 to 404 Telegram for recovery
We claim:
[CLAIM 1] A telegram recovery device generating a signaling telegram in a
signaling safety system wherein the signaling telegram is shared among trains by
sequentially circulating the signaling telegram containing occupancy right information
on a travel path among the trains present on the travel path divided into one or more
blocks to each of which the occupancy right information is set, and the occupancy right
to each block of the travel path is set to each train, wherein
the signaling telegram contains a telegram update number indicating a
number of times the telegram is updated; and
when an abnormality is detected during circulation of the signaling
telegram, the telegram recovery device transmits information requesting information
related to the occupancy right to each block to the trains present on the travel path,
receives information in the signaling telegram received or transmitted
last by the trains as information related to the occupancy right to each block on the
travel path from the trains present on the travel path, and
generates a new signaling telegram based on information on the
signaling telegram having a largest telegram update number among the information on
the received signaling telegram and transmits the new signaling telegram to the trains
present on the travel path.
[CLAIM 2] The telegram recovery device according to claim 1, wherein
the signaling telegram contains a telegram issue number indicating the
number of times a new signaling telegram is generated, and
when the new signaling telegram is issued, the telegram recovery device
updates the telegram issue number contained in the signaling telegram.
[CLAIM 3] The telegram recovery device according to any one of claims 1 to 2,
wherein
the signaling telegram contains a member list indicating the trains to
which the signaling telegram circulates, and
when a new signaling telegram is issued, the telegram recovery device
38
excludes a train in which an abnormality is detected from the member list contained in
the new signaling telegram.
[CLAIM 4] The telegram recovery device according to any one of claims 1 to 2,
wherein
the telegram recovery device comprises a member list management unit
that manages a member list indicating the trains to which the signaling telegram
circulates, and
when a new signaling telegram is issued, the telegram recovery device
excludes a train in which an abnormality is detected from the member list managed by
the member list management unit.
[CLAIM 5] The telegram recovery device according to claim 3 or 4, wherein
the telegram recovery device treats a train that has not responded for a
predetermined time to information requesting information related to the occupancy right
to each block or a train that has not responded for a predetermined time when the
information requesting information related to the occupancy right to each block is
transmitted a predetermined number of times, as a train in which an abnormality is
detected.
[CLAIM 6] The telegram recovery device according to claim 4, wherein
when a request to enter a travel path to which an occupancy right is set
by the signaling telegram is received from a train present on another travel path adjacent
to the travel path to which the occupancy right is set by the signaling telegram, or when
a train present on another travel path adjacent to the travel path to which the occupancy
right is set by the signaling telegram is predicted to enter the travel path to which the
occupancy right is set by the signaling telegram, the telegram recovery device adds the
train to the member list.
[CLAIM 7] A signaling safety system wherein a signaling telegram is shared among
trains by sequentially circulating the signaling telegram containing occupancy right
information on a travel path among the trains present on the travel path divided into one
39
| # | Name | Date |
|---|---|---|
| 1 | Translated Copy of Priority Document [10-03-2017(online)].pdf | 2017-03-10 |
| 2 | PROOF OF RIGHT [10-03-2017(online)].pdf | 2017-03-10 |
| 3 | Priority Document [10-03-2017(online)].pdf | 2017-03-10 |
| 4 | Power of Attorney [10-03-2017(online)].pdf | 2017-03-10 |
| 5 | Form 5 [10-03-2017(online)].pdf | 2017-03-10 |
| 6 | Form 3 [10-03-2017(online)].pdf | 2017-03-10 |
| 7 | Form 18 [10-03-2017(online)].pdf_253.pdf | 2017-03-10 |
| 8 | Form 18 [10-03-2017(online)].pdf | 2017-03-10 |
| 9 | Drawing [10-03-2017(online)].pdf | 2017-03-10 |
| 10 | Description(Complete) [10-03-2017(online)].pdf_252.pdf | 2017-03-10 |
| 11 | Description(Complete) [10-03-2017(online)].pdf | 2017-03-10 |
| 12 | 201717008497.pdf | 2017-03-15 |
| 13 | Marked Copy [20-03-2017(online)].pdf | 2017-03-20 |
| 14 | Form 13 [20-03-2017(online)].pdf | 2017-03-20 |
| 15 | Description(Complete) [20-03-2017(online)].pdf_275.pdf | 2017-03-20 |
| 16 | Description(Complete) [20-03-2017(online)].pdf | 2017-03-20 |
| 17 | 201717008497-Power of Attorney-240317.pdf | 2017-03-27 |
| 18 | 201717008497-OTHERS-240317.pdf | 2017-03-27 |
| 19 | 201717008497-OTHERS-240317-.pdf | 2017-03-27 |
| 20 | 201717008497-OTHERS-240317--.pdf | 2017-03-27 |
| 21 | 201717008497-Correspondence-240317.pdf | 2017-03-27 |
| 22 | abstract.jpg | 2017-05-19 |
| 23 | 201717008497-FORM 3 [04-08-2017(online)].pdf | 2017-08-04 |
| 24 | 201717008497-FER.pdf | 2020-01-31 |
| 25 | 201717008497-Information under section 8(2) [18-03-2020(online)].pdf | 2020-03-18 |
| 26 | 201717008497-FORM 3 [18-03-2020(online)].pdf | 2020-03-18 |
| 27 | 201717008497-OTHERS [11-04-2020(online)].pdf | 2020-04-11 |
| 28 | 201717008497-FER_SER_REPLY [11-04-2020(online)].pdf | 2020-04-11 |
| 29 | 201717008497-COMPLETE SPECIFICATION [11-04-2020(online)].pdf | 2020-04-11 |
| 30 | 201717008497-CLAIMS [11-04-2020(online)].pdf | 2020-04-11 |
| 31 | 201717008497-FORM-26 [25-01-2021(online)].pdf | 2021-01-25 |
| 32 | 201717008497-Correspondence to notify the Controller [25-01-2021(online)].pdf | 2021-01-25 |
| 33 | 201717008497-Written submissions and relevant documents [02-02-2021(online)].pdf | 2021-02-02 |
| 34 | 201717008497-Response to office action [12-05-2021(online)].pdf | 2021-05-12 |
| 35 | 201717008497-PatentCertificate19-05-2021.pdf | 2021-05-19 |
| 36 | 201717008497-IntimationOfGrant19-05-2021.pdf | 2021-05-19 |
| 37 | 201717008497-US(14)-HearingNotice-(HearingDate-28-01-2021).pdf | 2021-10-17 |
| 38 | 201717008497-Power of Attorney-040321.pdf | 2021-10-17 |
| 39 | 201717008497-Correspondence-040321.pdf | 2021-10-17 |
| 40 | 201717008497-RELEVANT DOCUMENTS [21-08-2023(online)].pdf | 2023-08-21 |
| 1 | 2020-01-1714-44-08_17-01-2020.pdf |