Movatterモバイル変換


[0]ホーム

URL:


EP3395643A1 - Method for checking safety requirements of ssi-based data used in an interlocking control system - Google Patents

Method for checking safety requirements of ssi-based data used in an interlocking control system
Download PDF

Info

Publication number
EP3395643A1
EP3395643A1EP17305477.6AEP17305477AEP3395643A1EP 3395643 A1EP3395643 A1EP 3395643A1EP 17305477 AEP17305477 AEP 17305477AEP 3395643 A1EP3395643 A1EP 3395643A1
Authority
EP
European Patent Office
Prior art keywords
unsafe
data
interlocking
constraint violation
application data
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
EP17305477.6A
Other languages
German (de)
French (fr)
Other versions
EP3395643B1 (en
Inventor
Cydney Minkowitz
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alstom Transport Technologies SAS
Original Assignee
Alstom Transport Technologies SAS
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alstom Transport Technologies SASfiledCriticalAlstom Transport Technologies SAS
Priority to EP17305477.6ApriorityCriticalpatent/EP3395643B1/en
Priority to AU2018202873Aprioritypatent/AU2018202873B2/en
Publication of EP3395643A1publicationCriticalpatent/EP3395643A1/en
Application grantedgrantedCritical
Publication of EP3395643B1publicationCriticalpatent/EP3395643B1/en
Activelegal-statusCriticalCurrent
Anticipated expirationlegal-statusCritical

Links

Images

Classifications

Definitions

Landscapes

Abstract

Method for checking safety requirements of SSI-based data used in an interlocking control system for controlling an interlocking equipment, the method comprising the steps of:
a) obtaining (2) application data representative of interlocking logic operations of the interlocking equipment;
b) preparing (4) a constraint violation file containing data representative of a plurality of constraint violation conditions, said data describing a plurality of unsafe scenarios of the interlocking equipment;
for each constraint violation condition of the plurality of constraint violation conditions:
c) selecting (6) data of the application data according to the constraint violation condition, said selected data corresponding to a predetermined unsafe scenario of the plurality of unsafe scenarios defined in the constraint violation file;
d) determining (7) at least one predetermined context associated to said unsafe scenario, said context comprising a plurality of paths through the application data;
e) initializing (8) variables that define all possible states of said scenario, thus obtaining a predetermined initial state, said variable being representative of the scenario from the point of view of settings of the interlocking equipment;
f) executing (10), starting from said initial state, all possible paths of the context in the application data, thus obtaining respective resulting states;
g) at an end of each path, determining (12) if an unsafe state has been reached by comparing a respective resulting state with the data of the constraint violation file;
h) if no unsafe state has been detected, determining (12) if the resulting state has not been reached;
-i) repeating steps f), g) and h), starting, for each path, from the respective resulting state, until unsafe states or no new states are reached.

Description

Claims (4)

  1. Method for checking safety requirements of SSI-based data used in an interlocking control system for controlling an interlocking equipment, the method comprising the steps of:
    a) obtaining (2) application data representative of interlocking logic operations of the interlocking equipment;
    b) preparing (4) a constraint violation file containing data representative of a plurality of constraint violation conditions, said data describing a plurality of unsafe scenarios of the interlocking equipment;
    for each constraint violation condition of the plurality of constraint violation conditions:
    c) selecting (6) data of the application data according to the constraint violation condition, said selected data corresponding to a predetermined unsafe scenario of the plurality of unsafe scenarios defined in the constraint violation file;
    d) determining (7) at least one predetermined context associated to said unsafe scenario, said context comprising a plurality of paths through the application data;
    e) initializing (8) variables that define all possible states of said unsafe scenario, thus obtaining a predetermined initial state, said variables being representative of the scenario from the point of view of settings of the interlocking equipment;
    f) executing (10), starting from said initial state, all possible paths of the context in the application data, thus obtaining respective resulting states;
    g) at an end of each path, determining (12) if an unsafe state has been reached by comparing a respective resulting state with the data of the constraint violation file;
    h) if no unsafe state has been detected, determining (12) if the resulting state has not been reached;
    -i) repeating steps f), g) and h), starting, for each path, from the respective resulting state, until unsafe states or no new states are reached.
EP17305477.6A2017-04-282017-04-28Method for checking safety requirements of ssi-based data used in an interlocking control systemActiveEP3395643B1 (en)

Priority Applications (2)

Application NumberPriority DateFiling DateTitle
EP17305477.6AEP3395643B1 (en)2017-04-282017-04-28Method for checking safety requirements of ssi-based data used in an interlocking control system
AU2018202873AAU2018202873B2 (en)2017-04-282018-04-26Method for checking safety requirements of SSI-based data used in an interlocking control system

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
EP17305477.6AEP3395643B1 (en)2017-04-282017-04-28Method for checking safety requirements of ssi-based data used in an interlocking control system

Publications (2)

Publication NumberPublication Date
EP3395643A1true EP3395643A1 (en)2018-10-31
EP3395643B1 EP3395643B1 (en)2020-03-11

Family

ID=58701568

Family Applications (1)

Application NumberTitlePriority DateFiling Date
EP17305477.6AActiveEP3395643B1 (en)2017-04-282017-04-28Method for checking safety requirements of ssi-based data used in an interlocking control system

Country Status (2)

CountryLink
EP (1)EP3395643B1 (en)
AU (1)AU2018202873B2 (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN116187104A (en)*2023-04-272023-05-30华侨大学 Method and device for safety analysis and development of rail transit interlocking system
CN117670630A (en)*2024-02-022024-03-08华侨大学 A safety analysis method, system, equipment and medium for high-speed railway interlocking system
WO2024060377A1 (en)*2022-09-192024-03-28卡斯柯信号有限公司Formal verification method and system for interlocking data security
CN118363368A (en)*2024-06-202024-07-19华侨大学 A modeling method and system for safety-oriented railway interlocking system

Citations (1)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
WO2006111469A2 (en)*2005-04-212006-10-26Alstom Ferroviaria S.P.A.Control system for railway signalling network

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
WO2006111469A2 (en)*2005-04-212006-10-26Alstom Ferroviaria S.P.A.Control system for railway signalling network

Non-Patent Citations (4)

* Cited by examiner, † Cited by third party
Title
MICHAEL HUBER; STEVE KING: "Towards an Integrated Model Checker for Railway Signalling Data", 2002, SPRINGER-VERLAG BERLIN, pages: 20
N N: "signalling solutions -Smartlock 400", SIGNALLING SOLUTIONS LTD., 31 August 2010 (2010-08-31), Hertfordshire, pages 1 - 16, XP055419677, Retrieved from the Internet <URL:https://signallingsolutions.com/wp-content/uploads/SSL-A4-SL400-Bro.pdf> [retrieved on 20171027]*
SIMON BUSARD ET AL: "Verification of railway interlocking systems", ELECTRONIC PROCEEDINGS IN THEORETICAL COMPUTER SCIENCE, vol. 184, 1 January 2015 (2015-01-01), pages 19 - 31, XP055419704, DOI: 10.4204/EPTCS.184.2*
SIMON BUSARD; QUENTIN CAPPART; CHRISTOPHE LIMBREE; CHARLES PECHEUR; PIERRE SCHAUS: "Verification of railway interlocking systems", PROCEEDINGS ESSS, 2015

Cited By (5)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
WO2024060377A1 (en)*2022-09-192024-03-28卡斯柯信号有限公司Formal verification method and system for interlocking data security
CN116187104A (en)*2023-04-272023-05-30华侨大学 Method and device for safety analysis and development of rail transit interlocking system
CN117670630A (en)*2024-02-022024-03-08华侨大学 A safety analysis method, system, equipment and medium for high-speed railway interlocking system
CN117670630B (en)*2024-02-022024-04-30华侨大学Safety analysis method, system, equipment and medium for high-speed railway interlocking system
CN118363368A (en)*2024-06-202024-07-19华侨大学 A modeling method and system for safety-oriented railway interlocking system

Also Published As

Publication numberPublication date
EP3395643B1 (en)2020-03-11
AU2018202873A1 (en)2018-11-15
AU2018202873B2 (en)2022-05-19

Similar Documents

PublicationPublication DateTitle
AU2018202873B2 (en)Method for checking safety requirements of SSI-based data used in an interlocking control system
Könighofer et al.Shield synthesis
ES2307954T3 (en) METHOD AND DEVICE FOR GENERATING LOGIC CONTROL UNITS FOR ESSENTIAL COMPUTER APPLIANCES BASED ON RAILWAY STATIONS.
Comptier et al.Safety analysis of a CBTC system: a rigorous approach with Event-B
Song et al.Validation, verification and evaluation of a train to train distance measurement system by means of colored petri nets
Comptier et al.Property-based modelling and validation of a CBTC zone controller in Event-B
US20170132054A1 (en)Method and apparatus for generating a fault tree
Cuer et al.A formal framework for the safe design of the autonomous driving supervision
James et al.On modelling and verifying railway interlockings: Tracking train lengths
Mitsch et al.Formal verification of train control with air pressure brakes
Macedo et al.Compositional model checking of interlocking systems for lines with multiple stations
JP6773782B2 (en) Control device
Khan et al.On the real time modeling of interlocking system of passenger lines of Rawalpindi Cantt train station
Xie et al.Safety and reliability estimation of automatic train protection and block system
Ortmeier et al.Formal failure models
Ferrari et al.Product line engineering applied to CBTC systems development
Xu et al.Safety requirement verification of train-centric CBTC by integrating STPA with coloured Petri net
RU2470339C2 (en)Method for certification of monitoring/control system and monitoring/control system certified using said method
Hudon et al.Development of control systems guided by models of their environment
Schaber et al.Towards a Novel Approach to Railway Safety Using STPA and Promise Theory
Issad et al.A model-based methodology to formalize specifications of railway systems
Tarasyuk et al.Quantitative verification of system safety in Event-B
ItoMethod of evaluating the influence factor of safety in the automated driving system: the chasm between SAE level 2 and level 3
WO2021038826A1 (en)State transition model constructing device and autonomous system
Raghavan et al.Property-driven runtime resolution of feature interactions

Legal Events

DateCodeTitleDescription
PUAIPublic reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text:ORIGINAL CODE: 0009012

STAAInformation on the status of an ep patent application or granted ep patent

Free format text:STATUS: THE APPLICATION HAS BEEN PUBLISHED

AKDesignated contracting states

Kind code of ref document:A1

Designated state(s):AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

AXRequest for extension of the european patent

Extension state:BA ME

STAAInformation on the status of an ep patent application or granted ep patent

Free format text:STATUS: REQUEST FOR EXAMINATION WAS MADE

17PRequest for examination filed

Effective date:20190401

RBVDesignated contracting states (corrected)

Designated state(s):AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

GRAPDespatch of communication of intention to grant a patent

Free format text:ORIGINAL CODE: EPIDOSNIGR1

STAAInformation on the status of an ep patent application or granted ep patent

Free format text:STATUS: GRANT OF PATENT IS INTENDED

INTGIntention to grant announced

Effective date:20191023

RIN1Information on inventor provided before grant (corrected)

Inventor name:MINKOWITZ, CYDNEY

GRASGrant fee paid

Free format text:ORIGINAL CODE: EPIDOSNIGR3

GRAA(expected) grant

Free format text:ORIGINAL CODE: 0009210

STAAInformation on the status of an ep patent application or granted ep patent

Free format text:STATUS: THE PATENT HAS BEEN GRANTED

AKDesignated contracting states

Kind code of ref document:B1

Designated state(s):AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

REGReference to a national code

Ref country code:GB

Ref legal event code:FG4D

REGReference to a national code

Ref country code:CH

Ref legal event code:EP

REGReference to a national code

Ref country code:AT

Ref legal event code:REF

Ref document number:1242798

Country of ref document:AT

Kind code of ref document:T

Effective date:20200315

REGReference to a national code

Ref country code:IE

Ref legal event code:FG4D

REGReference to a national code

Ref country code:DE

Ref legal event code:R096

Ref document number:602017012894

Country of ref document:DE

PG25Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code:FI

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:NO

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200611

Ref country code:RS

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

REGReference to a national code

Ref country code:NL

Ref legal event code:MP

Effective date:20200311

PG25Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code:BG

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200611

Ref country code:GR

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200612

Ref country code:HR

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:LV

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:SE

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

REGReference to a national code

Ref country code:LT

Ref legal event code:MG4D

PG25Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code:NL

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

PG25Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code:PT

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200805

Ref country code:LT

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:SK

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:RO

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:IS

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200711

Ref country code:CZ

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:EE

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:SM

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

REGReference to a national code

Ref country code:DE

Ref legal event code:R119

Ref document number:602017012894

Country of ref document:DE

REGReference to a national code

Ref country code:AT

Ref legal event code:MK05

Ref document number:1242798

Country of ref document:AT

Kind code of ref document:T

Effective date:20200311

REGReference to a national code

Ref country code:CH

Ref legal event code:PL

PG25Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code:MC

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

PLBENo opposition filed within time limit

Free format text:ORIGINAL CODE: 0009261

STAAInformation on the status of an ep patent application or granted ep patent

Free format text:STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT

PG25Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code:LU

Free format text:LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date:20200428

Ref country code:ES

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:LI

Free format text:LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date:20200430

Ref country code:CH

Free format text:LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date:20200430

Ref country code:DK

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:IT

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:DE

Free format text:LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date:20201103

Ref country code:AT

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

26NNo opposition filed

Effective date:20201214

PG25Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code:PL

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:SI

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

PG25Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code:IE

Free format text:LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date:20200428

PG25Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code:TR

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:MT

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:CY

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

PG25Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code:MK

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

Ref country code:AL

Free format text:LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date:20200311

P01Opt-out of the competence of the unified patent court (upc) registered

Effective date:20230823

REGReference to a national code

Ref country code:GB

Ref legal event code:732E

Free format text:REGISTERED BETWEEN 20250213 AND 20250219

REGReference to a national code

Ref country code:BE

Ref legal event code:PD

Owner name:ALSTOM HOLDINGS; FR

Free format text:DETAILS ASSIGNMENT: CHANGE OF OWNER(S), ASSIGNMENT; FORMER OWNER NAME: ALSTOM TRANSPORT TECHNOLOGIES

Effective date:20241025

PGFPAnnual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code:GB

Payment date:20250423

Year of fee payment:9

PGFPAnnual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code:BE

Payment date:20250418

Year of fee payment:9

PGFPAnnual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code:FR

Payment date:20250425

Year of fee payment:9


[8]ページ先頭

©2009-2025 Movatter.jp