receiving a first command from an operator via the terminal; executing the first command; sending to the terminal at least one display message containing information for the operator; displaying on a screen of the terminal the information of the at least one display message, in particular a screen illustrating the information contained in the at least a display message. A control method for a control system for a railway transport facility, wherein the control system comprises a terminal, preferably of a mobile or fixed type; the method comprising the steps of:
Legal claims defining the scope of protection, as filed with the USPTO.
1 10 100 2 2 300 300 100 300 receiving a first, preferably vital, command from an operator by the terminal (); executing the first command; 300 300 100 sending to the terminal () at least a display message (MV) containing information for the operator, wherein the terminal preferably () receives the display message from the apparatus (); 301 300 displaying on a screen () of the terminal () the information of the at least one display message (MV), in particular a screen illustrating the information contained in the display message (MV); 300 2 preferably receiving second commands from the terminal () comprising a command relating to the actuation of at least one countryside or field device of the railway network (), preferably the at least one countryside or field device is selected in a group of countryside or field devices comprising: light signalling devices, turnout actuators, turnout stops, foot switches, track circuits, level crossing barriers, pickets and operating said countryside or field device; 2 301 300 2 preferably the display message (MV) comprising information relating to the status of the at least one operated countryside or field device and preferably the status of other countryside or field devices of the railway network (); preferably displaying on the screen () of the terminal () a graphic symbol or graphic symbols showing the information of the display message (MV), in particular a graphic symbol or graphic symbols showing the status of said operated countryside or field device and preferably the status of other countryside or field devices of the railway network (). the method comprising the steps of: . A control method for a control system for a railway transport facility (), wherein the control system () preferably comprises an apparatus () configured to control a railway network (), in particular to control the train operation on said railway network (), preferably the apparatus is a safety and/or vital apparatus type; and a terminal (), preferably of a mobile or fixed type, preferably the terminal () being coupled in communication with the apparatus ();
claim 1 wherein the step of executing the first command comprises the step of actuating or releasing the possession zone, in particular of inhibiting or enabling train traffic to the area identified by the first command; wherein the information for the operator contained in the display message (MV) comprises an indication about the status of the possession zone, in particular the status of the area inhibited or enabled for train traffic and preferably an indication of the status of at least one other area of the railway network; 301 300 301 2 wherein showing on the screen () of the terminal () the information of the display message (MV) comprises showing on the screen () through a graphical representation the status of the activated or released possession zone, in particular the status of the area inhibited or enabled for rail traffic and preferably the status of at least one other area of the railway network (). the first command comprises a request for a possession zone, in particular a request indicating an area of the railway network to be inhibited or enabled for train traffic, in particular the area of the railway network comprises at least a portion of at least a track of the railway network to be inhibited or enabled for train traffic; . The control method of, wherein
300 300 claim 2 . The control method of, wherein the first command is a command to require a possession zone to be released; the method comprises the step of checking whether the terminal () from which the command of releasing a possession zone came is the same terminal () from which it had received the activation of said possession zone, and releasing said possession zone only if this checking is successful.
300 claim 2 . The method of, wherein the first command is a command of activating a possession zone from the terminal (); the method comprising the step of receiving at least a second command relating to operating a countryside or field device, and checking whether said at least a second command relates to a countryside or field device located within said possession zone; the method comprises the step of executing said at least a second command and only if said checking is successful.
300 claim 1 300 300 300 300 100 100 300 300 300 300 the method comprising the step of showing an error message on the terminal () or of disabling the operation of the terminal () in the event that the checking of the correct operation of the terminal () has failed, in particular in the event that one or more of the diagnostic tests have failed, and preferably of sending an alarm message to trains circulating in an area around the terminal () preferably so as to limit the speed of the trains or stop the train traffic, in particular in an area defined by a radius of a first value preferably configurable; in particular comprising the step of sending cyclically to the apparatus () the result of the diagnostic testing and preferably the apparatus () supervises the result of the diagnostic tests and in the event of an incorrect operation of the terminal (), it sends an error message to the terminal () or disables the operation of the terminal () and preferably of sending the alarm message to the trains circulating in the area around the terminal (). . The method of, cyclically performing the checking of the correct operation of the terminal () by performing at least a diagnostic test, in particular cyclically checking the correct operation of at least one of the terminal components selected in the group of terminal components: video memory; RAM; terminal software; terminal hardware; communication block; in particular cyclically performing at least a diagnostic test selected in the group of diagnostic testing: SW and data diversity check, forced video refreshing, video memory runtime test, offline/runtime graphics library test, check flow checking, status check sum, vitality;
1 100 1 200 300 100 200 210 200 104 100 claim 1 f . The method of, the method comprising the step of encrypting, preferably with a respective private key (KPR), the display message (MV) according to a first encryption procedure and obtaining a first encrypted display message (MVC), and preferably sending the respective private key (KPR), preferably the first encryption procedure is performed by the apparatus (); preferably the method comprising the step of providing a second encrypted display message by applying a second encryption procedure to the first encrypted display message (MVC) to meet the communication protocol requirements of a communication network assembly () and/or part thereof coupling the terminal () to the apparatus (), in particular, the communication network assembly () comprises at least one communication network () of a commercial type, preferably WI-FI with password, WI-FI MAX with password, GSM, GSM-R, TETRA, UMTS, LTE, GPRS, EDGE, and wherein preferably the second encryption procedure is defined according to the type of communication network assembly () and/or part thereof; preferably the second encryption procedure is performed by a communication module () of the apparatus ().
1 104 104 1 1 300 301 300 1 1 100 claim 6 f . The method of, preferably comprising the step of performing a procedure of decrypting the second encrypted display message in accordance with the second encryption procedure and thereby obtaining the first encrypted display message (MVC), preferably the procedure of decrypting the second encrypted display message is performed by a communication module () of the terminal (); the method comprising the steps of carrying out a decryption procedure of the first encrypted display message (MVC) in accordance with the first encryption procedure, preferably after receiving the respective private key (KPR) and with the respective private key, preferably the decryption procedure of the first encrypted display message (MVC) is carried out by a terminal processing unit (); checking whether the decryption of the first encrypted display message has been successful; and the step of displaying on the screen () of the terminal () the display message if the decryption of the first encrypted display message (MVC) has been successful, preferably the step of decrypting the first encrypted display message (MVC) and checking the outcome of the decryption step is carried out by the terminal ().
1 300 1 1 300 claim 6 . The method of, wherein the first encryption procedure comprises a first sub-step of encrypting the display message (MV) with a message private key (KPR) to obtain the first encrypted display message (MVC), preferably by means of a symmetric encryption procedure, in particular by means of the Advanced Encryption Standard (AES) protocol; and preferably a second sub-step of encrypting the message private key (KPR) with a public key (KPB) associated with said terminal (), preferably by means of an asymmetric encryption procedure, in particular through the RSA protocol and sending the preferably encrypted private key (KPB[KPR]) together with the first encrypted display message (MVC); wherein the procedure of decrypting the first encrypted display message (MVC) preferably comprises a first sub-step of decrypting the encrypted private key of the message (KPB[KPR]) with the private key (KPT) associated with said terminal (); and a second sub-step of decrypting the first encrypted display message with the private key of the message (KPR) that has been decrypted.
10 300 300 300 300 300 100 300 300 300 300 300 300 300 300 300 300 300 300 300 claim 8 1 m 1 m i 1 m i r r i i i 1 m 1 m i i i i i i i i i i 1 n i . The method of, wherein the control system () comprises a plurality of terminals (-) comprising said terminal (), in particular one or more or all of the terminals of the plurality of terminals are mobile terminals, preferably the plurality of terminals (-) being coupled in communication with the apparatus (); wherein each terminal () of the plurality of terminals (-) is associated with a respective public key (KPB) different from each public key (KPB) of each other terminal (); and each terminal () has a private key (KPT) of the terminal () associated with its own public key (KPB) which is stored; preferably the method comprising the step of sending display messages (MV-MV) to the different terminals (-) and of using the respective public key (KPB) associated with the respective terminal () during the second sub-step of encrypting the private key (KPR) of the respective display message (MV) addressed to said respective terminal () and preferably to use for each terminal () the private key (KPT) stored by the respective terminal () to decrypt the encrypted private key (KPB[KPR]) of the display message (MV) of the respective terminal ().
300 301 300 1 1 1 1 1 1 1 301 300 claim 6 1 n n i n 1 n n 1 n i i i i i . The method of, further comprising the step of cyclically sending display messages (MV-MV) to said terminal () to update the information to be displayed on the screen () of said terminal (), and wherein the step of encrypting comprises the step of cyclically creating different message private keys (KPR) and encrypting each display message (MV) with a respective message private key (KPR), and thus cyclically creating first encrypted display messages (MVC-MVC) with the respective message private key (KPR); the method includes cyclically sending the first encrypted display messages (MVC-MVC) and the respective private key of the message (KPR) for each first encrypted display message (MVC); preferably the method comprising the steps of performing a decryption procedure for each first encrypted display message (MVC) received via the respective private key of the message (KPR); checking for each first encrypted display message (MVC) whether the decryption was successful and the step of displaying on the screen () of the terminal () the display message (MV) until the decryption of the first display message with the respective private key of the message is successful, preferably the decryption step of each first encrypted display message is carried out by the respective terminal
300 () in particular by a processing unit of the terminal ().
300 300 300 claim 5 i . The method of, wherein in the event that the step of checking the correct operation of the terminal (), by performing the at least one diagnostic test, is unsuccessful, the disabling of the operation of the terminal () is carried out by the step of interrupting the sending of the respective private message key (KPR), preferably encrypted with the public key of the terminal, so that the terminal () cannot decrypt the respective display message (MV).
1 100 2 1 100 300 300 100 1 100 100 100 100 claim 1 . The method of, wherein the step of sending the first command comprises the step of sending a first instruction (I), which identifies the action to be performed, preferably the instruction of a request or a release of a possession zone; preferably receiving, preferably from the apparatus (), a second instruction (I) containing the first instruction sent (I) and a code (C) preferably generated by the apparatus (), preferably the code (C) is formed by a plurality of digits and/or letters and/or characters and/or symbols and/or figures, in particular generated randomly; preferably displaying on the terminal () the second instruction received; preferably sending, from the terminal () to the apparatus (), the code (C) received and again the first instruction (I) received preferably if the first instruction which was sent the first time coincides with the first instruction which was received; the method comprising the step of checking whether the first instruction which was received, preferably from the apparatus (), the first time coincides with the first instruction which was received, preferably from the apparatus, the second time and whether the code which was sent, preferably from the apparatus (), coincides with the code which was received, preferably from the apparatus (), and if so, executing the first command, in particular said checking and/or said executing of the first command is carried out by the apparatus ().
1 302 300 301 300 1 100 1 302 300 301 300 claim 12 . The method of, wherein the operator enters the first instruction on the terminal (I) via an input user interface () of the terminal (); displaying on a screen () of the terminal () the first instruction (I) which was received together with the code (C) preferably received from the apparatus (); entering the code (C) which was received and again the first instruction (I) via the input user interface () of the terminal (); receiving confirmation that the first command has been executed on the screen () of the terminal ().
303 300 claim 1 . The method of, further comprising the step of detecting the position of the operator preferably by means of a location device (); and defining the display message (MV) to be sent to said terminal () based on the detected position, in particular the information contained in the display message (MV) is inherent to an area defined by a surrounding of the detected position; preferably the method comprises the step of checking whether the first command and/or the second command which was received from the terminal is related to said area and enables the execution of said first command and/or said second command only if the checking is successful.
300 claim 1 . The method of, wherein the terminal () is a mobile terminal of a commercial type and freely available commercially, in particular a COTS (Commercial Off-the-Shelf Component) mobile terminal, preferably of a size such that it can be hand held, preferably a tablet in particular of a commercial type.
1 10 100 2 2 300 300 100 10 300 receive a first command, preferably vital, from an operator by the terminal (); execute the first command; 300 send to the terminal () at least a display message (MV) containing information for the operator; 301 300 display on a screen () of the terminal () the information of the at least one display message (MV), in particular a screen illustrating the information contained in the display message (MV); 300 2 preferably receive second commands from the terminal () comprising a command relating to the actuation of the at least one field or countryside device of the railway network (), preferably the at least one field or countryside device is selected from the group of field or countryside devices comprising: luminous signalling devices, turnout actuators, turnout stops, pedals, track circuits, level crossing barriers, pickets, and operate said field or countryside device; preferably the at least one display message (MV) comprising information about the status of the at least one operated field or countryside device and preferably the status of other field or countryside devices of the railway network preferably displaying on the terminal screen a graphic symbol or graphic symbols showing the information of the display message (MV), in particular a graphic symbol or graphic symbols showing the status of said operated countryside or field device and preferably the status of other countryside or field devices of the railway network. . A control system for a railway transport system (), wherein the control system () preferably comprises an apparatus () configured to control a railway network (), in particular to control the train operation on said railway network (), preferably the apparatus is a safety and/or vital apparatus type; and a terminal (), preferably of a mobile or fixed type, preferably the terminal () being coupled in communication with the apparatus (); the control system () being configured to:
2 claim 16 . A railway transport system comprising the control system ofand the railway network (), and preferably trains.
Complete technical specification and implementation details from the patent document.
1020220000 10823 This Patent Application claims priority from Italian Patent Application No.filed on May 24, 2022 the entire disclosure of which is incorporated herein by reference.
This invention concerns a control method for a control system of a railway transport facility and said control system of said railway transport facility.
As a result, the technical field of this invention is that of control systems for railway transport facilities.
In particular, railway transport facilities comprising at least one central control post, also called central post, wherein an operator monitors and/or drives and/or controls and/or acts on the control system. In central control posts, there is a graphic interface that illustrates the information, preferably all the information, that concerns the railway network. In addition, in central control posts, there is an input interface that comprises a command device for receiving input commands from an operator.
The control system comprises at least one central apparatus that manages the passages of trains on the railway network based on the instructions loaded and the commands from the operator in the central post. In addition, the control system comprises peripheral control posts staggered along the path of the tracks and/or near the stations or near transfer areas. All the communications between the central apparatus, the peripheral control posts, and the countryside or field devices controlled by the central apparatus must have a high level of security, in particular SIL 1 to SIL 4 certified. In the current state, the terminals that communicate with the central apparatus, for example peripheral post terminals, are expensive devices since they are proprietary and not commercial; this increases the costs of the control system.
One drawback of the prior art is that the commercial devices freely available on the market, called Commercial Off the Shelf (COTS) in English, for example commercial LCD monitors or tablets or palmtops, usually cannot connect to the central apparatus because they would not ensure the necessary SIL security requirements.
In general, one purpose of this invention is to provide a control method for a control system for a railway transport facility that reduces the drawbacks, highlighted here, in the prior art, for example it is simpler to produce and/or more economical, ensuring, at the same time, a high degree of reliability.
1 According to this invention, a control method for a control system for a railway transport facility, in accordance with claim, is provided.
Another purpose of this invention is to provide a control system for a railway transport facility that reduces the drawbacks of the prior art.
16 According to this invention, a control system for a railway transport facility, in accordance with claim, is provided.
Thanks to this invention, it is possible to use commercial terminals, for example LCD commercial monitors in the peripheral post stations. In addition, it is possible to use mobile commercial terminals or tablets or palmtops to give to operators who carry out maintenance along the line to manage or to give to train drivers who travel on trains without a screen or in cases where the screen of the train (for example very old trains) do not show all the information that train drivers need.
1 FIG. 1 2 3 With reference to o, the reference numberdenotes a railway transport facility comprising a railway networkthat, in turn, comprises tracksthat extend along multiple paths P and passenger or goods stations (not illustrated); trains that move along the railway network.
In the whole discussion in this text, the term “railway” also means “tram”; as a result, “railway network” also means a “tram network”, and “railway transport facility” also means a “tram transport facility” and “trains” also means “trams”.
3 3 In one optional, non-limiting embodiment of this invention, the tracksare divided, in particular in terms of logics and control, into multiple tracksections.
1 10 2 2 10 2 The railway transport facilitycomprises a control systemconfigured for activating and controlling the railway network, in particular the train traffic along the railway networkis activated and controlled by the control system. In addition, the railway networkcomprises the countryside or field devices.
10 100 2 2 100 The control systemcomprises at least one central, computerised apparatusconfigured to control the railway network, in particular to control train traffic on said railway networkand wherein an operator monitors and/or drives and/or controls and/or acts on the central apparatus.
10 100 In one embodiment, the control systemcomprises more than one central apparatus, in particular for redundancy and/or disaster recovery functions.
10 100 100 In one optional, non-limiting embodiment, the control systemcomprises several apparatusesthat define a distributed system, i.e., several apparatusesthat are geographically distributed.
100 101 3 5 3 3 2 The central apparatuscomprises a graphic interfacethat illustrates the information that concerns the railway network, in particular information selected from a group comprising: the occupation of each tracksection by a respective train, the tracksections that are enabled for being travelled on by a train and the tracksections that are prohibited from being travelled on by a train, the status of a countryside or field device of the railway networkand/or information relating to the codifying of the track circuits and/or indications of freedom and travel on the route assigned to a train.
“Countryside or field device” means any device selected from the group of devices comprising: light signalling devices, turnout actuators, turnout stops, foot switches, track circuits, level crossing barriers, and pickets. In all cases, the list of countryside or field devices is not to be considered limiting.
100 102 In addition, the apparatuscomprises an input user interfacethat comprises a command device for receiving input commands from an operator located in the central control post.
101 102 In one alternative embodiment, the graphic interfaceand the input user interfacemay be implemented from a single device, for example via a touch screen.
100 104 104 The central apparatuscomprises at least one data processing assembly. The processing assemblyis secure.
104 In particular, the processing assemblyhas a secure and redundant architecture.
104 In one optional and non-limiting embodiment, the secure processing assemblyis a 2 on 2(2oo2) architecture.
100 104 In one optional and non-limiting architecture, the central apparatuscomprises at least two processing assemblies, in particular secure ones.
104 104 104 a b In one optional and non-limiting version, the processing assemblypreferably comprises at least two identical processing unitsand, which preferably communicate with each other. In some optional cases, there are three or four or more identical processing units.
104 104 104 104 104 104 104 104 104 104 104 104 104 104 3 a b a b a b a b a b In particular, in one optional and non-limiting embodiment, each input to the processing assemblyis processed, preferably contemporaneously, by at least two processing unitsand; in other words, each input is replicated and each copy of this input is given as input to the at least two processing unitsand, preferably in the same interval of time. The outputs of each processing unitandare verified by the processing assemblyto control whether in the same time interval the data received by the outputs of each processing unitandcoincide with each other and, if they do, the processing assemblyprovides as output the data received by one of the two inputs. If the outputs of the at least two processing unitsanddo not coincide, the processing assemblyissues an error signal and disables the operation of the railway network, making the trains that are moving on it stop, safely, in particular in accordance with a predetermined procedure.
104 104 104 104 104 104 104 104 104 104 104 104 104 2 a b a b b a a b b a b In one embodiment, the at least two identical processing unitsandcommunicate with each other and each processing unitandreceives the outputs from the other processing unitandand each processing unitandchecks that its output is equal to the output of the other processing unitandin the same time interval and, if they are, the processing assemblyor at least one of the at least two processing unitsandprovides, as output, the data processed or, if they are not, issues an error signal and disables the operation of the railway network, making the trains that are moving on it stop, safely, in particular in accordance with a predetermined procedure.
104 104 104 104 104 104 104 104 104 104 104 104 104 104 104 2 c a b a b a b c a b a b c In another, alternative embodiment to the previous optional and non-limiting embodiment of this invention, the processing assemblycomprises a comparison moduleconnected with the at least two processing unitsandto receive the outputs of the at least two processing unitsand. The outputs of each processing unitandare verified by the comparison moduleto check whether in the same time interval the data received by the outputs of each processing unitandcoincide with each other and, if they do, the processing assemblyprovides as output the data received by at least one of the two inputs. If the outputs of the at least two processing unitsanddo not coincide, the comparison moduleissues an error signal and disables the operation of the railway network, making the trains that are moving on it stop, safely, in particular in accordance with a predetermined procedure.
104 104 104 104 104 104 104 104 104 104 2 d a b a b a b d In addition, in one preferred embodiment, the processing assemblycomprises a supervision blockthat is intrinsically secure, called a “watchdog”, which is in communication with the at least two processing unitsandand checks the correct operation of said at least two processing unitsand; if it determines a malfunction of at least one of the at least two processing unitsand, the supervision blockissues an error signal and the processing assemblydisables the operation of the railway network, making the trains that are moving on it stop, safely, in particular in accordance with a predetermined procedure.
104 104 104 104 104 d a b a b. In particular, the supervision blockis configured to detect one or more malfunctions selected from the group of malfunctions: stall of at least one of the at least two processing unitsand/or; infinite calculation cycle or other malfunctions that give rise to imprecise results of at least one of the at least two processing unitsand/or
104 104 104 104 104 104 104 104 104 104 104 104 d a b a b a b a b b a In one alternative embodiment, the supervision blockis omitted and each processing unitandsupervises the at least one other processing unitandto detect one or more malfunctions selected from the group of: stall of at least one of the at least two processing unitsand/or; infinite calculation cycle or other malfunctions that give rise to imprecise results of at least one of the at least two processing unitsand/or. If at least one of the at least two processing unitsanddetects a malfunction, it issues an error signal and the processing assemblydisables the operation of the railway network, making all the trains that are moving on it stop, safely, in particular in accordance with a predetermined procedure.
104 104 104 a b In addition, in one embodiment, the processing assemblycomprises at least one local communication network (not illustrated) and the at least two processing unitsandare coupled together via said local communication network.
104 104 104 104 c c a b In the embodiment comprising the comparison module, said comparison moduleis coupled in communication with the at least two processing unitsandvia the local communication network.
104 104 104 104 d d a b In the embodiment with the supervision block, said supervision blockis coupled in communication with the at least two processing unitsandvia the local communication network.
100 104 104 e. In addition, the apparatus, in particular the processing assembly, comprises a memory
104 104 104 e a b In particular, the memoryis coupled in communication with the at least two processing unitsandvia the local communication network.
104 104 104 104 104 f a b In addition, the processing assemblycomprises a communication moduleconnected to the local communication network and with the processing unitsandvia the communication network to exchange data with the outside of the processing assembly.
104 104 a b In one optional and non-limiting embodiment, each processing unitandimplements or comprises a communication module.
104 104 104 104 e e f In one embodiment, on the memoryof the processing assembly, a series of instructions for managing the railway network may be loaded by connecting an external device. In one alternative embodiment, the instructions may be loaded in the memoryvia the communication moduleremotely.
104 104 104 a b In one alternative embodiment, the processing assemblycomprises at least two identical memories (not illustrated in the attached figures), one for each processing unitand/orand wherein the same data are loaded in the at least two memories, in particular the same series of instructions for managing the railway network are loaded.
104 104 102 104 e f. The secure processing assemblymanages the transits of the trains on the railway network based on the instructions loaded in the memoryand/or the commands received from the input interfaceand/or the data received via the communication module
104 2 The processing assemblymanages the vital tasks and information of the railway network, in particular the tasks and information that may have an impact on safety.
100 The apparatusensures the management of correct train traffic, ensuring that on a certain segment of tracks, there is only one train and the transit of another train is prevented.
100 104 102 2 2 2 The apparatus, in particular the processing assembly, ensures this function, having as input the instructions in the memory (also called railway logic to be executed) and/or the status of the countryside or field devices and/or the commands of the input interface, and providing the outputs to the countryside or field devices of the railway networkor, more generally, to the components of the railway network, preferably to all the components of the railway network.
100 105 106 In one preferred embodiment, the apparatuscomprises a non-vital processing assemblyand a non-vital communication moduleto manage non-vital tasks and information, i.e., that do not impact safety.
10 200 200 The control systemcomprises a communication network assembly. The communication network assemblyis, preferably, different to the local communication network defined above.
200 201 202 In particular, the communication network assemblycomprises a vital networkand/or a non-vital network, preferably of the Ethernet and/or wired type.
In particular, in one preferred, but non-limiting embodiment, it comprises a normal network and a redundant one.
In particular, a network that enables the connection and communication between vital devices, i.e., those that contribute to implementing functions that, potentially, impact the safety of the operators or people that use the railway transport facility, is defined as a vital network.
10 1 In general, a vital function of the control systemis a function that potentially has an impact on the safety of the operators or of the people who use or are in contact with the railway transport facility.
210 In addition, in particular, in one optional and non-limiting embodiment, the communication network assembly comprises at least one commercial wireless communication network.
210 As non-limiting examples, the wireless communication networkmay be: WI-FI and/or WI-FI MAX and/or GSM and/or GSM-R and/or TETRA and/or LTE and/or GPRS and/or UMTS and/or EDGE.
210 201 202 100 201 202 In one preferred, but non-limiting embodiment, the wireless communication networkis preferably connected in series to the vital networkand/or to the non-vital network, preferably it is connected to the apparatusthrough the vital networkand/or to the non-vital network.
210 201 202 100 201 202 In one other optional and non-limiting embodiment, the wireless communication networkis preferably connected in parallel to the vital networkand/or to the non-vital network, preferably it is connected to the apparatuswithout using the vital networkand/or to the non-vital network.
10 300 The control systemcomprises at least one terminal, in particular a commercial terminal that is freely available on the market, in particular of the Commercial Off the Shelf type, also called COTS.
300 In one embodiment, the terminalis a terminal fixed to, for example, a commercial PC connected to a commercial screen, for example an LCD or plasma screen, and to a commercial keyboard and/or with a touch screen.
300 In another embodiment, the terminalis a commercial, mobile terminal, for example a tablet or palmtop, in particular small enough that it can be held in the hand (called a Hand-held terminal in English).
300 100 200 In particular, the terminalis coupled in communication with the apparatusvia the communication network assembly.
300 210 When the terminalis of the mobile type, it is preferably coupled in communication with the wireless network.
300 201 202 210 When the terminalis of the fixed type, it is preferably coupled in communication with the vital networkand/or the non-vital networkand/or the wireless network.
300 301 302 The terminalcomprises a screenfor displaying information and an input user interface, for example a keyboard, SO that an operator can insert commands or instructions or, in general, send data.
301 302 In one embodiment, the screenand the input user interfacemay defined by a single device, for example a touch screen.
300 100 200 The terminaland the apparatusare in communication with each other via the communication network assembly.
300 302 100 100 The terminalis configured to receive a first command from an operator via the input interfaceand send said first command to the apparatus, in turn the apparatusis configured to execute the first command.
10 1 The first command is preferably a vital command, in particular a type of command that acts on vital functions of the control system. In other words, it is a command that acts on functions that, potentially, may have impacts on the safety of the operators or of the people who use or are near the railway transport facility.
100 301 300 In addition, the apparatusis configured to send at least one display message MV containing information to show to the operator via the screento the terminal.
300 In one preferred, but non-limiting, embodiment of this invention, the terminalreceives second commands from an operator, wherein the second commands comprise a command relating to the action of any one of the countryside or field devices as defined above, preferably different to the first command.
300 100 100 The terminalsends these second commands to the apparatusand the apparatusactions said countryside or field device.
10 100 300 100 300 In addition, the control systemauthenticates different operators with different enabling codes and the enabling of certain first or second commands based on the enabling code that has been used. In other words, the apparatuscomprises different enabling codes in the memory to enable different operators. The operator must insert an enabling code in the terminalto log on when they wish to start operating. The apparatusselectively enables the request for certain first or second commands via the terminalbased on the enabling code used by the operator to log on.
300 300 301 In one preferred embodiment, the display message MV received by the terminalcomprises information relating to the status of a countryside or field device activated and, preferably, to the status of other countryside or field devices of the railway network. As a result, the terminalshows a graphic symbol or graphic symbols on the screenthat show/s the information of the display message, in particular a graphic symbol or graphic symbols that show the status of said countryside or field device activated and, preferably, the status of other countryside or field devices of the railway network.
10 100 100 102 100 100 100 In one optional and non-limiting embodiment of this invention, the control systemis configured so that the implementation of the first command only occurs if there is another operator who is enabled to execute this first command, preferably an operator of the central post or an operator of a different peripheral post to the maintenance operator. In this embodiment, the apparatusafter having received the first command from the terminal and before executing the first command, asks the other operator to enable the execution of the first command; in particular, the apparatussends the enabling request via the input interfaceof the apparatusto the other operator and waits to receive a third command via the user interface to enable the execution of the first command via the user interface f the apparatus. The apparatusis configured to execute the first command only after being enabled to execute the first command, in particular via the third command.
302 300 100 300 300 100 100 300 302 300 100 100 100 100 100 302 300 1 1 2 1 2 1 1 1 In one preferred embodiment of this invention, sending the first command occurs through the following procedure, the operator sends through the input user interfaceof the terminala first instruction Ithat identifies the action to take; the apparatusreceives the first instruction Iand sends to the terminala second instruction Icontaining the first instruction Isent by the terminalto the apparatusand a code C generated by the apparatus, preferably the code C is made up of multiple digits and/or letters and/or characters and/or symbols and/or figures, in particular generated randomly. In addition, the terminaldisplays the second instruction Ireceived on the screen; the operator sends the code received C and, again, the first instruction Ireceived, if the first instruction sent the first time coincides with the first instruction received, through the input interfaceof the terminal. The apparatuschecks whether the first instruction Ireceived the first time coincides with the first instruction Ireceived the second time and whether the code sent C generated by the apparatuscoincides with the code C received by the apparatus. If the check is successful, the apparatusactuates the first command and, preferably, the apparatussends a confirmation that the first command has been executed on the screenof the terminal.
10 2 One of the functions executed by the control systemis the management of the so-called request or release of possession zones for delimiting a maintenance area. More specifically, when it is necessary to carry out maintenance works on the railway network, you need to delimit a maintenance area, i.e., an area where workers will need to work and that, therefore, must be temporarily excluded from train traffic.
As a result, the term “possession zone” or “possession area” or “maintenance zone” or “maintenance area” means an area of the railway network that has been temporarily prohibited to train traffic.
In other words, a possession zone consists of one or more portions of track, even not contiguous, wherein train traffic is disabled for the time that the operator requests and, therefore, from when they make the possession zone request until when they make the request to release the possession zone and wherein, preferably, only one authorised operator can perform specific actions.
300 2 100 300 301 41 4 FIG. The terminal, in particular when it is of the mobile type, is used to define the possession zone. In this embodiment, the first command comprises a request or a release of a possession zone, i.e., information indicating an area of the railway networkwhere train traffic is prohibited or enabled (possession zone request or release). As a result, the apparatus, when it receives the possession zone request or release, prevents or enables train traffic in the area identified by the first command. In this embodiment, the display message MV comprises the indication of the status of the possession zone, i.e. the indication of the area where railway traffic is prohibited or enabled, and, preferably, the indication of the status of at least one other area of the railway network and, as a result, the terminalshows on the screenvia a graphic representation the status of the possession zone enabled or released, i.e. the status of the area where railway traffic is prohibited or enabled, and, preferably, the status of at least one other area of the railway network; in particular, showing the statusthe area where railway traffic is prohibited or enabled via a first colour and the status of at least one other area of the railway network via a second colour or with other graphic means ().
100 300 300 300 In addition, when the apparatusreceives from the terminala first command for requesting the release of a possession zone, it checks whether the terminal, from which the command to release a possession zone came, is the same terminalfrom which it had received the activation of that possession zone, and releases the possession zone only if this check is successful.
100 300 In particular, the apparatus, when a possession zone is requested, stores the possession zone that has been requested and associates said possession zone with an identification code of the terminalthat requested it.
100 300 In particular, the apparatus, thus, has in its memory the list of each possession zone currently activated and for each possession zone activated it has the identification code associated with the terminalthat requested it.
100 300 100 300 100 When the apparatusreceives from the terminala first command for requesting the release of a possession zone, the apparatuschecks whether the terminalfrom which the possession zone release request arrived has the same identification code that is present in the memory associated with said possession zone for which the release was requested; if this check is successful, the apparatusreleases the possession zone.
In this way, you prevent a different operator to the operator that requested the possession zone from releasing this possession zone. In this way, the safety of the operator who works in a possession zone is improved.
10 300 300 100 300 In addition, in one preferred embodiment, the control systemis configured so that when a certain mobile terminalhas requested, through the first command, the possession zone, said mobile terminalis enabled to request second commands relating only to the field devices or system that are positioned within said possession zone. In other words, the apparatuswhen it receives a second command from the terminalchecks whether this second command concerns a countryside or field device that is within the possession zone requested by said terminal and only if so, does it execute this second command.
300 10 303 300 300 300 303 If the terminalis mobile, in one optional and non-limiting embodiment of this invention, the control systemcomprises a locator devicefor locating the terminal. The locator device is, preferably, a satellite locator device of the terminal. Alternatively, the terminalcomprises an RFID that communicates its position to the locator deviceof the control system.
10 303 300 300 10 The control systemdetects the position of the operator via the locator device; and defines the display message MV to be sent to said terminalbased on the position detected, in particular the information contained in the display message MV is inherent to an area defined by the surroundings of the position detected, these surroundings can preferably be configured, for example the surroundings define an area that extends for 15 km, 10 km, 5 km, 3 km around the position detected. In other words, the terminalshows said area around the position detected and/or the information relating to the countryside or field devices of said area on the screen. In one optional embodiment, the control systemverifies whether the first command and/or the second command received from the terminal relates to said area and enables the execution of said first command and/or said second command only if the check is successful.
10 100 For example, if the first command is the possession zone request or release, the control system, in particular the apparatus, before activating the possession zone, checks whether said possession zone is inside said area.
10 300 300 The control systemcomprises the step of cyclically checking the correct operation of the terminalmaking the terminal, or part thereof, execute at least one diagnostic test or part of a diagnostic test.
300 300 100 300 300 In one preferred embodiment, the terminalcyclically checks the correct operation of at least one of the components of the terminal selected from the group of terminal components: video memory; RAM; terminal software; terminal hardware; or communication block. In particular, the terminal cyclically executes at least one diagnostic test selected from the group of diagnostic tests: SW and data diversity check, forced video refresh, video memory runtime test, graphics library runtime/offline test, control flow check, status check sum, or vitality. The terminalsends the outcome of the check and, in particular, of the at least one diagnostic test to the apparatus. An error message appears on the terminalor the operation of the terminalis disabled in the event that the check of the correct operation of the terminal is not successful, in particular if the at least one diagnostic test is not successful.
300 100 300 300 In particular, the terminalitself makes an error message appear or the apparatussends an error message to the terminaland/or disables the operation of the terminal.
1 100 300 1 1 1 300 300 1 301 1 1 300 In one embodiment, sending the display message MV occurs in encrypted form, in particular the display message is encrypted based on a first encryption procedure and you thus obtain a first encrypted display messageMVC, preferably the first encryption procedure is carried out by the apparatus. In this embodiment, the terminalreceives the first encrypted messageMVC and implements a procedure of decrypting the first encrypted display messageMVC in accordance with the first encryption procedure, in particular the procedure of decrypting the first encrypted display messageMVC is carried out by a processing unit of the terminal. The terminalchecks whether the decryption of the first encrypted display messageMVC was successful and enables the display of the display message on the screenonly if the decryption of the first display messageMVC was successful. In particular, the decryption step of the first display messageMVC and checking the outcome of the decryption step is carried out by the terminal.
5 FIG. 1 300 1 1 1 In particular, with reference to, the first encryption procedure comprises first sub-step of encrypting the display message MV with a message private key KPR to obtain the first encrypted display messageMVC, preferably via a symmetric encryption procedure, in particular via the Advanced Encryption Standard (AES) protocol; and preferably a second step of encrypting the message private key with a public key KPB associated with said terminal, preferably via an asymmetric encryption procedure, in particular via the RSA protocol; and sending the encrypted private key KPB[KP] together with the first encrypted display messageMVC. Wherein, the procedure of decrypting the first encrypted display messageMVC comprises, preferably, a first step of decrypting the encrypted private key KPB[KP] of the message with the private key KPT associated with said terminal and a second step of decrypting the first encrypted display messageMVC with the message private key KPR that has been decrypted.
300 300 300 300 300 300 Encrypting the private key with the public key of the terminalalso makes it possible to be sure that the message will only be decrypted by the terminalfor which it was created, thus avoiding that said message may be decrypted by another terminal(in the embodiment in which multiple terminalsare present) to which it was erroneously delivered. Thanks to this mechanism, there is the certainty that the terminalwill only display the display message MV prepared and directed for said terminal, increasing the reliability of the image displayed.
10 300 In one embodiment, wherein the control systemcomprises just one terminal, in an optional and non-limiting embodiment, you can omit the step of encrypting the private key KPR with the public key KPB and the following step of decrypting the private key encrypted with the public key KPB[KPR].
6 FIG. 100 1 300 301 300 301 1 1 n 1 n 1 n 1 n 1 n 1 n 1 n 1 n In one preferred embodiment, with reference to, the apparatuscyclically sends display messages MVMvnto said terminalto update the information to be displayed on the screenof said terminal, in particular to update the status of the countryside or field devices displayed on the screenand/or other vital information. In this embodiment, the first encryption sub-step involves the step of cyclically creating different message MV-Mvnprivate keys KPR-KPRand encrypting each display message MV-Mvnwith a corresponding message private key KPR-KPRand thus cyclically creating first encrypted display messagesMVC-MVCobtained by corresponding encrypted display messages MV-Mvnwith the corresponding message private key KPR-KPR.
100 300 1 1 1 1 1 n 1 n 1 n The apparatuscyclically sends to the terminalthe first encrypted display messagesMVC-MVCand the corresponding message private key KPR-KPRfor each first encrypted display messageMVC-MVC.
300 1 1 300 1 1 300 301 300 1 i i i i i i i i i The terminalcarries out a procedure of decrypting each first encrypted display messageMVCreceived through the corresponding message private key received KPR; it checks for each first encrypted display messageMVCwhether the decryption was successful; and updates the display on the screen of the terminalwith the updated display message MVuntil the decryption of the first encrypted display messageMVCwith the corresponding message private key KPRis successful, preferably the decryption step of each first encrypted display messageMVCis carried out by the corresponding terminal. Thanks to this invention, it is certain that the screenof the terminalis always updated given that each display message MVcyclically sent is encrypted with a different message private key KPR.
10 300 300 100 300 300 300 300 300 300 300 300 300 1 m 1 m i 1 m i 1 m 1 m i i i In one preferred embodiment, the control systemcomprises multiple terminals-coupled in communication with the apparatus. In particular, one or some or all the terminals of the multiple terminals-are mobile terminals. In this embodiment, each terminalof the multiple terminals-is associated with a corresponding public key KPBthat is different to the public key KPB-KPBof the other terminals-and each terminalpossesses, in its memory, a private key KPTof the terminalassociated with its public key KPB.
100 104 300 300 100 300 300 300 300 300 300 e 1 m 1 m 1 m 1 m i i i i r r r i 1 n 1 n 1 n The apparatushas stored, in particular in the memory, the public keys KPB-KPBof each terminal-. In particular, the apparatuscyclically sends display messages MV-MVto the different terminals-, in particular to each terminaldisplay messages MV-MVare cyclically sent for said terminalthat may be different or equal to the display messages MV-MVcyclically sent to another terminalother than said terminal.
300 300 300 i i i i i i i i i i In this embodiment, the first encryption procedure stipulates that, for each terminal, each display message MVdirected to each terminalis first encrypted with the corresponding private key KPR, preferably via an asymmetric encryption procedure, in particular via the Advanced Encryption Standard (AES) protocol; and, subsequently, the corresponding message private key KPRis encrypted with the public key KPBassociated with each terminal, preferably via an asymmetric encryption procedure, in particular via the RSA protocol.
10 100 1 300 i i i i i In addition, the control system, in particular the apparatus, cyclically sends the respective encrypted private key KPB[KPR]together with the corresponding first encrypted display messageMVCto each terminal.
1 300 1 300 300 i i i i i i i i i i i i i i i i The procedure of decrypting each encrypted display messageMVCcomprises, preferably, a first step of decrypting the corresponding encrypted private key KPB[KPR] of the message with the private key KPTassociated with said terminaland a second step of decrypting the first encrypted display messageMVCwith the message private key KPRthat was encrypted and, thus, obtain the message MV. Thanks to this invention, it is certain that the display message MVdisplayed on each terminalis always updated and is the one directed to each terminaland there was no error in the delivery of the display message.
300 300 100 300 300 i i i i i i i i i i i i i i In addition, in one preferred embodiment, in the event that the above-illustrated step for checking the correct operation of the terminal, executing the at least one diagnostic test, was not successful, the operation of the terminalis disabled through the step of stopping sending the corresponding message private key Kpr, preferably the corresponding encrypted private key KPB[KPR], so as not to be able to decrypt the corresponding display message MV. In particular, the apparatuschecks the outcome of the at least one diagnostic test by the terminaland, in the event of the failure of the at least one diagnostic test, interrupts sending the corresponding message private key Kpr, preferably the encrypted message private key KPB[KPR], to the terminal.
i i i i i m th 1 m 1 m th 300 300 In one optional and non-limiting embodiment, the display messages MV-MVsent in an ninterval of time to the terminals-are equal; in this embodiment, the private keys Kpr-Kprin the ninterval are equal.
100 300 210 1 210 210 300 100 300 1 300 In one preferred embodiment, the display message MV during the journey from the apparatusto the terminalcrosses the wireless communication network, which in one preferred embodiment uses a transmission protocol that involves the encryption of data, for example one or more of the following networks: WI-FI with the use of passwords, WI-FI MAX with the use of passwords, GSM, GSM-R, TETRA, UMTS, LTE, GPRS, EDGE. In this case, then, each first encrypted display messageMVC is encrypted through a second encryption procedure defined based on the type of wireless communication networkand/or part of it to meet the encryption requirements of the communication protocol of the wireless communication networkthat couples the terminalto the apparatus. In this embodiment, once the second encrypted display message has reached the mobile terminal, a procedure of decrypting the second encrypted display message occurs, in accordance with the second encryption procedure and, thus, the first encrypted display messageMVC is obtained. In one preferred embodiment, the procedure of decrypting the second encrypted display message is carried out by a communication module of the terminal.
300 104 104 In addition, in one preferred embodiment, the terminalsends the first command and/or the second command to the vital processing assemblyand receives the display message MV from the vital processing assembly.
300 105 In addition, the terminalexchanges non-vital data with the non-vital processing assembly, preferably without carrying out the encryption described for the display message MV.
10 300 301 300 300 3 3 In addition, the control systemcomprises multiple peripheral control posts not illustrated, each of which is staggered along the path of the tracks or near the stations or near transfer areas that comprises, preferably, a peripheral operator station. The terminalmay be a terminal of the peripheral control post that shows the operator of the peripheral control post the information of an area of the railway network. For example, through the screenof the terminal, an operator of the peripheral post may see the status of the railway network adjacent to said peripheral control post. In addition, the operator, through the terminal, can see the status of the railway network, preferably the status of a portion of the railway networkadjacent to said peripheral control post.
300 300 10 300 The advantage of the use H mobile terminals, as mentioned above, is to manage the possession zones to carry out maintenance of the countryside or field devices and/or central post and peripheral post sub-systems. The system thus enables different operators to carry out the management of the maintenance areas, via the corresponding mobile terminal, and to operate locally for the maintenance of the components of the control system, directly via the applications present on the terminal provided. In addition, via the mobile terminal, the operator has a mobile command post from which it is possible to impart commands for taking possession of maintenance areas and, more generally, to send specific commands for the diagnostics and monitoring of countryside or field devices. The solution enables the use of pre-existing or new network infrastructure, without special associated security requirements (open networks).
300 100 300 Via the mobile terminal, the operator can request the management of a possession zone and, after confirmation, proceed with the specific works. In the same way, the release of the possession zone can be requested, confirmed by the apparatus. In particular, the release of the possession zone may be requested only through the terminalwith which it was requested.
300 300 In general, when the terminalcomprises the touch screen, the terminalmay be used as a tool to send and receive commands, via a functionality wherein the operator can directly select the objects represented on the terminal, in particular on the touch screen of the terminal, and send commands easily and intuitively.
10 300 The control systemmakes it possible to arrange the commands configured and support the operator for the graphic selection of the countryside or field devices. On the terminal, in particular on the mobile terminal, the second commands may also be diagnostic controller commands for the components of the Peripheral Post apparatus (supply diagnostics, Area Controller, Device Controllers, Cable Insulation Check, fan diagnostics). This tool makes it possible to operate locally by sending through the mobile terminal the diagnostic commands to carry out specific works. The use of this application makes it possible to reduce the recovery times, thanks to the management of the maintenance operations all locally near the field device or system (without the need for communication with the cabin). On the terminal, it is also possible to monitor, in real time, the status of the system alarms, to the advantage of an: immediate perception of the status of the system during the maintenance/repair operations. This enables a reduction in times for resolving problems and recovery, being able to display the alarms directly near the apparatus to be maintained.
Additional advantages both in terms of dividing the responsibilities of different divisions on the same line, and in terms of safety since, for example, a turnout will only be manoeuvred by maintenance workers physically present in the place with a reduction in the risks of remote communication and, thus, of manoeuvres made from the cabin that may put people on the spot in danger.
300 300 2 100 300 300 300 In another embodiment, the mobile terminalmay be given to a train driver on board the train who, for example, guides a train without a screen or, if the screen of the train (for example very old trains) does not show all the information the train driver needs. In this case, the train driver may receive from the mobile terminalall the updated information relating to the portion of railway networkthat it is running along. In this case, the embodiment with the satellite locator device wherein the apparatusprocesses the display messages MV to be sent to said terminal, including based on the position detected by said terminal, may be very useful. For this purpose, in one optional and non-limiting embodiment, the mobile terminalis used, preferably only to display the display messages MV and not to implement first and second commands.
Lastly, it is clear that modifications and variations may be made to the apparatus and method described herein without departing from the scope of the present invention as set forth in the claims.
Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.
May 23, 2023
July 9, 2026
Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.