发明名称 RAILWAY SAFETY CRITICAL SYSTEMS WITH TASK REDUNDANCY AND ASYMMETRIC COMMUNICATIONS CAPABILITY
摘要 A railway safety critical application system substitutes commercial off-the-shelf (COTS) hardware and/or software for railway-domain specific product components, yet is validated to conform to railway safety critical system failure-free standards. The safety critical system uses a pair of tasks executed on a controller of a COTS personal computer or within a virtual environment with asymmetric communications capability. Both tasks receive and verify safety critical systems input message data and security code integrity and separately generate output data responsive to the input message. The first task has sole capability to send complete safety critical system output messages, but only the second task has the capability of generating the output security code. A failure of any of systems hardware, software or processing capability results failure to transmit a safety critical system output message or an output message that cannot be verified by other safety critical systems.
申请公布号 US2016082994(A1) 申请公布日期 2016.03.24
申请号 US201514958213 申请日期 2015.12.03
申请人 Siemens Industry, Inc. 发明人 Weber Claus;Egel Zoltan
分类号 B61L27/04 主分类号 B61L27/04
代理机构 代理人
主权项 1. A control system for a railway safety critical application system, comprising: at least one controller executing first and second tasks; the first task having an external bilateral communications interface capable of sending and receiving a safety critical systems message within a railway safety critical application system, the message including a security code and safety critical data; the second task having an external communications interface capable of receiving a safety critical systems message, but incapable of sending a safety critical systems message that is generated within the second task, the second task having a security code generator; and an inter-task communications pathway coupling the first and second tasks; wherein the first and second tasks respectively receive an input safety critical systems message including input safety critical systems data and an input security code, verify the input message integrity and generate output safety critical systems data, the second task generates an output security code and sends it to the first task, and the first task sends an output safety critical systems message including the output safety critical systems data and the second task output security code for use within the railway safety critical application system.
地址 Alpharetta GA US