EP2036800A2 - Commande d'élément de signal électronique et sûre destinée à l'exécution d'une marche de véhicules sur rail - Google Patents
Commande d'élément de signal électronique et sûre destinée à l'exécution d'une marche de véhicules sur rail Download PDFInfo
- Publication number
- EP2036800A2 EP2036800A2 EP08011454A EP08011454A EP2036800A2 EP 2036800 A2 EP2036800 A2 EP 2036800A2 EP 08011454 A EP08011454 A EP 08011454A EP 08011454 A EP08011454 A EP 08011454A EP 2036800 A2 EP2036800 A2 EP 2036800A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- level
- computer system
- secure computer
- safe
- elements
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 230000011664 signaling Effects 0.000 title description 6
- 238000000034 method Methods 0.000 claims abstract description 132
- 230000008569 process Effects 0.000 claims abstract description 109
- 238000004891 communication Methods 0.000 claims abstract description 31
- 238000012544 monitoring process Methods 0.000 claims description 33
- 238000012360 testing method Methods 0.000 claims description 16
- 230000004913 activation Effects 0.000 claims description 14
- 230000001960 triggered effect Effects 0.000 claims description 14
- 230000005540 biological transmission Effects 0.000 claims description 10
- 238000005516 engineering process Methods 0.000 claims description 9
- 238000012546 transfer Methods 0.000 claims description 4
- 230000007246 mechanism Effects 0.000 claims description 3
- 230000006870 function Effects 0.000 description 10
- 230000003287 optical effect Effects 0.000 description 9
- 230000007547 defect Effects 0.000 description 7
- 230000009471 action Effects 0.000 description 5
- 230000007257 malfunction Effects 0.000 description 5
- 230000002950 deficient Effects 0.000 description 4
- 238000012545 processing Methods 0.000 description 4
- RYGMFSIKBFXOCR-UHFFFAOYSA-N Copper Chemical compound [Cu] RYGMFSIKBFXOCR-UHFFFAOYSA-N 0.000 description 3
- 230000008859 change Effects 0.000 description 3
- 229910052802 copper Inorganic materials 0.000 description 3
- 239000010949 copper Substances 0.000 description 3
- 230000000694 effects Effects 0.000 description 3
- 239000003990 capacitor Substances 0.000 description 2
- 239000003795 chemical substances by application Substances 0.000 description 2
- 125000004122 cyclic group Chemical group 0.000 description 2
- 238000013461 design Methods 0.000 description 2
- 238000011161 development Methods 0.000 description 2
- 230000018109 developmental process Effects 0.000 description 2
- 238000005286 illumination Methods 0.000 description 2
- 238000004445 quantitative analysis Methods 0.000 description 2
- 230000004044 response Effects 0.000 description 2
- 241000859095 Bero Species 0.000 description 1
- 206010000210 abortion Diseases 0.000 description 1
- 230000006978 adaptation Effects 0.000 description 1
- 230000008901 benefit Effects 0.000 description 1
- 230000000052 comparative effect Effects 0.000 description 1
- 230000009849 deactivation Effects 0.000 description 1
- 230000001419 dependent effect Effects 0.000 description 1
- 230000004907 flux Effects 0.000 description 1
- 230000005283 ground state Effects 0.000 description 1
- 238000007689 inspection Methods 0.000 description 1
- 238000009434 installation Methods 0.000 description 1
- 238000009413 insulation Methods 0.000 description 1
- 238000002955 isolation Methods 0.000 description 1
- 238000012806 monitoring device Methods 0.000 description 1
- 230000007935 neutral effect Effects 0.000 description 1
- 238000001208 nuclear magnetic resonance pulse sequence Methods 0.000 description 1
- 238000005192 partition Methods 0.000 description 1
- 238000004886 process control Methods 0.000 description 1
- 230000009291 secondary effect Effects 0.000 description 1
- 239000004065 semiconductor Substances 0.000 description 1
Images
Classifications
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B61—RAILWAYS
- B61L—GUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
- B61L21/00—Station blocking between signal boxes in one yard
- B61L21/04—Electrical locking and release of the route; Electrical repeat locks
Definitions
- the invention relates to a method and a device for fail-safe electronic control of elements that guide and secure the operation of rail vehicles.
- the elements of the outside installation of the signal box such as Signals, switches, level crossings, block facilities, etc. must be safely controlled and monitored by the interlocking logic signal, that is, the elements of the outdoor facilities are sufficiently likely to be arbitrarily assumed errors in the system in a state that the safety of Driving operation is not endangered.
- Signaling safety of positioning and monitoring devices is realized by means of safety-related components, whereby all components involved in the positioning and monitoring processes are checked accordingly.
- an automation platform which comprises a plurality of modules, in particular CPU, power supply, module for safety-related signal processing, module for non-safety-related signal processing, communication module, connected via special interfaces with safety-related and non-safety-relevant components of the railway safety system.
- the automation platform is a programmable logic controller (PLC).
- PLC programmable logic controller
- the predetermined software structure of the automation platform is usually arranged in such a modular or hierarchical manner that the logistics of the railway safety system, in particular the interlocking logistics, can be organized in function-specific software programs.
- each load circuit at least two in series, regardless Having controllable each other, not technically safe switch for opening / closing of the circuit has.
- the two switches can be controlled by independent computer channels of a secure computer system.
- Each wire of the circuit contains one of the two switches.
- At least one detector is provided for detecting a test voltage derived from a feed or test current flowing via the consumer or at least indirectly applied by the consumer and dependent on the operating state of the consumer. An inadequately closed or opened switch changes the voltage in a marked manner compared to the test voltage which is established when the switch position is correct.
- the detector output signals are evaluated by the two computer channels of the secure computer system, and the computer system detects an untimely open / closed at least one of the switches from the occurrence of not expected at this time detector output signals.
- Dependencies are stored in one or more non-signal-secure commercial computers.
- the signal-technically secure computer generates from the commands and messages supplied to it processing jobs that are transmitted to the or the commercial computer and there at least twice processed independently.
- the resulting results or intermediate results are transmitted back to the secure computer where they are signal-technically tested for consistency.
- the system architecture is based on the proven industrial level model, consisting of an operating and monitoring level, a backup level and a process level.
- a fully graphic system based on market standards represents the operating and monitoring level.
- the backup level is formed by a secure computer system.
- the components of the various levels communicate via corresponding data transmission devices.
- the safety-related checks and algorithms for ensuring process security are performed exclusively by the secure computer system of the security level, whereas the computers or other components of the operating and monitoring level as well as the process level can meet lower security requirements.
- the method is based on safety technology on a variant of the known process assurance, wherein according to the invention, the backup procedures, although consistently at the endpoints (source and sink) take the actions, the intermediate and final results, however, are checked only in the safe interlocking core.
- the method allows for low cost, industry standard components that meet a lower level of security.
- a major advantage of the method is that the high cost of secure software design, secure programming and testing, and secure hardware is only required at one point in the secure interlocking core.
- Claim 2 describes how the method reliably triggers commands for controlling elements of the process level. A distinction must be made between the way in which commands are issued to the process level.
- commands When commands are entered by the operator input at the operating and monitoring level, they are transmitted with a data transmission device to the secure computer system in the security level, where they are checked for plausibility. Plausible commands are re-coded and transmitted back to the control and monitoring levels. In the at least one computer of the operating and monitoring level of the newly coded command of the secure computer system is also checked for plausibility and the Transfer the result of the plausibility check in the final encoded form to the secure computer system in the backup level.
- the command to control the element can be triggered by the secure computer.
- the control is triggered directly by the secure computer system of the security level.
- Claim 3 describes how the activation event generated by the command triggered in accordance with claim 2 is reliably monitored by signal technology.
- the command for triggering an element of the process level After the command for triggering an element of the process level has been triggered by the secure computer system of the security level, it is transmitted via a data transmission device to the appropriate element in the process level.
- the effect of this command results in at least one control event, the result of which is monitored by suitable sensors and reported back to the secure computer system in the backup level.
- the results of each triggering event must be checked several times for the required logical and timely sequence. Since only one secure computer system is available in the safe interlocking core, all tests must be carried out there as well. This is realized by multiple, but time-delayed checks in the single secure computer system, so that for each result multiple dialogues arise, which are led to the final result.
- an advantageous embodiment of the invention is that the secure computer system of the security level consists of a modular system for industrial automation systems. This eliminates the previously required costly special developments for railway operations.
- a decentralizable process level is described, which is connected via a data network with the backup level.
- logically passive components are used at the process level, which convert the transmitted data into digital input / output bits in a process-protected manner.
- the decentralized process element converts only network telegrams of the safe interlocking core into digital outputs and reports changes to the digital inputs event-controlled or, on request, from the safe interlocking core, also via the communications network.
- mechanisms triggered and monitored by the security level must cyclically check the communication in the process chain as well as the function of the elements in the process level. In the event of an error, at least the power supply to the associated element of the process level is reliably switched off by the fuse level.
- the signal supply voltage is additionally separated in such a way that in the event of a fault only the elements belonging to the signal term "stop" are supplied with voltage.
- the system architecture is based on the proven industrial level model, consisting of an operating and monitoring level, a backup level and a process level.
- a fully graphic system based on market standards represents the operating and monitoring level.
- the backup level is formed by a secure computer system.
- the components of the various levels communicate via corresponding data transmission devices.
- a secure computer system is only in the backup level. It performs the safety-related checks and algorithms to ensure process security, whereas the computers or other components of the operating and monitoring level as well as the process level meet lower safety requirements.
- the device is based on safety technology on a variant of the known process assurance, wherein according to the invention, the backup procedures, although consistently at the endpoints (source and sink) take the actions, the intermediate and final results, however, are checked only in the safe interlocking core.
- the backup procedures although consistently at the endpoints (source and sink) take the actions, the intermediate and final results, however, are checked only in the safe interlocking core.
- all components outside the safe interlocking core that is, both for communication and for the process level, are industry standard components that satisfy a lower level of security.
- a data communication device transmits the command to the secure computer system at the backup level.
- the secure computer system checks the command for plausibility. Plausible commands are re-coded and transmitted back to the operating and monitoring level.
- the at least one computer of the operating and monitoring level of the newly coded command of the secure computer system is also checked for plausibility and transfer the result of the plausibility check in final coded form to the secure computer system in the backup level.
- a separate communication path ensures that the operation is explicitly desired in this form.
- a doubled or non-equivalent contact must be concluded by the operator, and / or additionally coded digital addresses are read in and checked.
- the secure computer triggers the command to control the element.
- the secure computer system aborts the control of elements of the process level with a corresponding error message.
- Claim 9 describes how the secure computer system reliably monitors the activation event generated by the command triggered in accordance with claim 8.
- the command for triggering an element of the process level After the command for triggering an element of the process level has been triggered by the secure computer system of the security level, it is transmitted via a data transmission device to the appropriate element in the process level.
- the effect of this command results in at least one control event, the result of which is monitored by suitable sensors and reported back to the secure computer system in the backup level.
- suitable sensors for example, the feedback from optical sensors in the connection of light signals or the use of magnetic sensors, such as. industrial beros for monitoring the mechanically correct circulation of a switch in question.
- the secure computer system After a positive check of all results for the triggering events, the secure computer system starts from a successful element control and reveals this. If the examination of at least one result of the triggering events contradicts the required logical and timely sequence, then the secure computer system assumes and also reveals a faulty element control.
- an advantageous embodiment of the invention is that the secure computer system of the backup level consists of a fail-safe programmable logic controller (PLC).
- PLC fail-safe programmable logic controller
- the logic implemented on the PLC is programmed according to DIN EN 61131 and is therefore easy to port to other PLC systems.
- a decentralizable process level is described, which is connected via a LAN (Local Area Network) with the backup level.
- standard ET electronic disconnect bar
- small PLC systems act as logically passive converters for the data transmitted via Ethernet or another standardized data network technology, so that there are digital input / output bits behind the converters.
- the process level is the multiplier for the LST, the main cost and LCC share.
- ETs are standard products of industrial automation and are offered with a similar range of services by many companies.
- consistent decentralization places standard components close to the target object and controls them via LAN connections (copper cables or fiber-optic cables) from the safe interlocking core. This results in very short cable lengths and protected cable routes within the outdoor area. Thus, significantly lower induced voltages for safety and protection considerations on the cables are to be assumed.
- watchdogs triggered and monitored by the protection level cyclically check the communication in the process chain and the function of the elements in the process level.
- the fuse level safely disconnects at least the power supply to the associated element of the process level.
- the signal supply voltage is additionally separated in such a way that in the event of an error only the elements belonging to the signal term "stop" are supplied with voltage.
- the system architecture of an electronic interlocking for carrying out the driving operation of rail vehicles is divided into three levels of operation / monitoring, the fuse and the process elements
- the fuse level (2) is formed by a secure computer system that can be used as a fail-safe PLC, such as a PLC.
- a SIMATIC S7-F is formed.
- process level (4) are the elements to be controlled outdoor facilities and other signaling devices, such as neighboring interlocking, level crossings, etc. For reasons of clarity, only the process element "signal" is named. The other process elements of the process level are only indicated by the dashed representation of the Ethernet.
- the data is exchanged, for example, in an Ethernet LAN (5) between the security level (2) and the decentrally placed elements (6) of the process level (4).
- This results in very short cable lengths and protected cable routes within the outdoor area.
- significantly lower induced voltages are assumed on the cables.
- Cable faults can be easily revealed, since only small ohmic resistances are to be assumed for the short cable paths.
- Ground faults are only relevant as double faults due to galvanic isolation of the supply voltage and are revealed in terms of hardware and process safety.
- simple earth faults can be detected by earth fault detectors.
- ET Electronic interfaces
- the interlocking core (3) triggers a data telegram in the first PLC cycle which resets a digital output (DA, 9) from the ET (7) of the addressed signal process element.
- This reset controls a positively driven relay K1 (16).
- K1 (16) has a normally closed contact in the circuit of the signal lamp.
- the potential of the signal lamp voltage is passed to the normally open contact of the electronic relay (ELR, 17).
- This potential is now detected by a digital input (8) of the process element and transmitted via the ET (7) via network (5) to the safe PLC (3).
- the safe PLC (3) expects just this reaction (change of the status of the corresponding DE bits from 0 to 1) for triggering the next process step, namely the control of another digital output (9) of the process element.
- This DA (9) now drives the ELR (17).
- the ELR closes the circuit consisting of current source (10), NC contact relay K1 (16), NO contact of the ELR (17) and lamp filament (20). Since the relay contact of the K1 (16) is already closed, this is conserved, which significantly increases the life of the relay. A corresponding sequence when deleting the signal term also serves to protect the relay contact. The lifetime of the ELR (17), however, is not affected by the number of switching operations.
- the safe interlocking core (3) can check for logical sequence and also evaluate the timely result of the optical feedback in a defined time window. After a positive check, the safe interlocking logic can proceed from a correct procedure and take into account the signal optics (20) operating in accordance with the regulations in the central lane logic.
- non-signal-safe components only control the untimely display of a driving signal image with a THR of> 10 exp -4 per hour.
- a watchdog (11) is used. This must be controlled in a defined pulse / pause ratio by a digital output (9) of the ET (7). If the pulse remains off in a defined time window, the watchdog (11) passivates the power supply (10). The impulse is generated by the safe interlocking core.
- the digital output (9) of the ET (7) is not cyclically requested to output the watchdog pulse.
- the pulse remains off, and the watchdog (11) interrupts the power supply (10).
- the cyclic pulse and the required pulse / pause ratio, which the watchdog (11) expects, are very likely absent or pending in another pulse sequence.
- the watchdog (11) detects this and interrupts the power supply (10).
- the watchdog (11) itself switches the supply voltage of the ET (7) via the closer of a positively driven small relay (12). If the pulse remains off, the positively driven relay (12) drops out, and the supply voltage is interrupted.
- the safe interlocking core (3) detects this by the absence of the Ethernet telegrams.
- the watchdog pulse from the safe interlocking core (3) is briefly exposed.
- the supply voltage at a DE of the ET is then expected via the NC contact of the positively driven relay (12). If the relay contacts are welded or there is another error in the communication chain of the watchdog pulse, this reveals itself in the test cycle.
- the ET supply voltage is buffered behind the watchdog relay via a capacitor (13).
- Each action on an element (6) of the process level (4) is initiated via the associated ET (7).
- the deactivation of the DA (9) for relay 16 is not carried out. So also no feedback of the upcoming potential at the ELR (17) arrives.
- the safe interlocking core (3) detects the error.
- the safe interlocking core (3) detects the error.
- control is sufficiently controllable by suitable positioning and protection of the sensor (15) from extraneous light.
- the watchdog (11) is integrated into the overall chain of communication. As a result, errors in communication reveal promptly.
- a base connection (burn main and secondary thread) is detected by triggering the fuse (22) and by the DE (8) on the ELR (17).
- the optical sensor gives no positive feedback after connection. It can be triggered a switch to the secondary thread. In addition, information is sent to the dispatcher (main thread, for example, "red N1" is defective).
- a decentralized process element KF (release command not shown) is installed on the operator station system via a separate communication path in conjunction with a pushbutton / key switch with a duplicated contact. This maps the KF operator dialog with the safe interlocking core.
Landscapes
- Engineering & Computer Science (AREA)
- Mechanical Engineering (AREA)
- Safety Devices In Control Systems (AREA)
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102007043053.3A DE102007043053B4 (de) | 2007-09-11 | 2007-09-11 | Signaltechnisch sichere elektronische Elementansteuerung zum Durchführen eines Fahrbetriebs von Schienenfahrzeugen |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| EP2036800A2 true EP2036800A2 (fr) | 2009-03-18 |
| EP2036800A3 EP2036800A3 (fr) | 2009-09-30 |
Family
ID=39956131
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP08011454A Withdrawn EP2036800A3 (fr) | 2007-09-11 | 2008-06-24 | Commande d'élément de signal électronique et sûre destinée à l'exécution d'une marche de véhicules sur rail |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP2036800A3 (fr) |
| DE (1) | DE102007043053B4 (fr) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2014001235A3 (fr) * | 2012-06-29 | 2014-06-19 | Siemens Aktiengesellschaft | Procédé et système pour commander une installation technique |
| CN118170126A (zh) * | 2024-05-16 | 2024-06-11 | 唐山百川智能机器股份有限公司 | 一种全自动折叠信标支架的控制系统及方法 |
| RU240566U1 (ru) * | 2025-09-25 | 2026-01-19 | Общество с ограниченной ответственностью "КиберТех-Сигнал" | Универсальная вычислительная платформа для управления железнодорожной автоматикой и телемеханикой |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102009033037A1 (de) | 2009-07-02 | 2011-01-05 | Deutsche Bahn Ag | Verfahren zur Datenübertragung sicherheitsrelevanter Daten von einem Controller an ein Prozesselement über ein Kommunikationsnetz |
| DE102013223101A1 (de) * | 2013-11-13 | 2015-05-13 | Siemens Aktiengesellschaft | Bahnübergangssicherungssystem |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE10053023C1 (de) | 2000-10-13 | 2002-09-05 | Siemens Ag | Verfahren zum Steuern eines sicherheitskritischen Bahnbetriebsprozesses und Einrichtung zur Durchführung dieses Verfahrens |
| DE19606894C2 (de) | 1996-02-13 | 2003-01-23 | Siemens Ag | Einrichtung zur signaltechnisch sicheren Steuerung und Überwachung elektrischer Verbraucher im Eisenbahnwesen |
| DE102005043305A1 (de) | 2005-09-07 | 2007-03-15 | Siemens Ag | System-Architektur zur Steuerung und Überwachung von Komponenten einer Eisenbahnsicherungsanlage |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP0473834B1 (fr) * | 1990-09-07 | 1994-06-22 | Siemens Aktiengesellschaft | Système de commande d'un poste d'aiguillage électronique organisé suivant le principe de commande à ordinateur local |
| DE102005013194A1 (de) | 2005-03-16 | 2006-09-21 | Siemens Ag | Bedienplatzsystem |
-
2007
- 2007-09-11 DE DE102007043053.3A patent/DE102007043053B4/de not_active Expired - Fee Related
-
2008
- 2008-06-24 EP EP08011454A patent/EP2036800A3/fr not_active Withdrawn
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE19606894C2 (de) | 1996-02-13 | 2003-01-23 | Siemens Ag | Einrichtung zur signaltechnisch sicheren Steuerung und Überwachung elektrischer Verbraucher im Eisenbahnwesen |
| DE10053023C1 (de) | 2000-10-13 | 2002-09-05 | Siemens Ag | Verfahren zum Steuern eines sicherheitskritischen Bahnbetriebsprozesses und Einrichtung zur Durchführung dieses Verfahrens |
| DE102005043305A1 (de) | 2005-09-07 | 2007-03-15 | Siemens Ag | System-Architektur zur Steuerung und Überwachung von Komponenten einer Eisenbahnsicherungsanlage |
Non-Patent Citations (7)
| Title |
|---|
| "Die Bombardier-Lösung einer neuen ESTW-Bauform bei der DB AG", SIGNAL + DRAHT 5, 2005 |
| "Sicherungs- und Telekommunikationstechnik", SIGNAL + DRAHT 3, 1997 |
| "SIMIS D", SIGNAL + DRAHT 3, 2006 |
| ANONYMOUS: "Systeme fur Signaltechnik", SCHEIDT UND BACHMAN, March 2006 (2006-03-01), pages 1 - 6, XP003024841 |
| ANONYMOUS: "Systeme fur Signaltechnik", SCHEIDT UND BACHMAN, May 2007 (2007-05-01), pages 1 - 4, XP003024840 |
| ANONYMOUS: "Systeme fur Signaltechnik", SCHEIDT UND BACHMAN, September 2005 (2005-09-01), pages 1 - 5, XP003024839 |
| ANONYMOUS: "ZSB2000 SYSTEMBESCHREIBUNG LEIT-UND BEDIENSYSTEM", ZSB2000 SYSTEMBESCHREIBUNG LEIT-UND BEDIENSYSTEM, 28 September 2006 (2006-09-28), pages 1 - 27, XP003024842 |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2014001235A3 (fr) * | 2012-06-29 | 2014-06-19 | Siemens Aktiengesellschaft | Procédé et système pour commander une installation technique |
| CN118170126A (zh) * | 2024-05-16 | 2024-06-11 | 唐山百川智能机器股份有限公司 | 一种全自动折叠信标支架的控制系统及方法 |
| RU240566U1 (ru) * | 2025-09-25 | 2026-01-19 | Общество с ограниченной ответственностью "КиберТех-Сигнал" | Универсальная вычислительная платформа для управления железнодорожной автоматикой и телемеханикой |
Also Published As
| Publication number | Publication date |
|---|---|
| DE102007043053B4 (de) | 2020-07-30 |
| DE102007043053A1 (de) | 2009-03-12 |
| EP2036800A3 (fr) | 2009-09-30 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP0875810B1 (fr) | Méthode et dispositif de surveillance d'une installation comprenant plusieurs unités fonctionnelles | |
| EP1738382B2 (fr) | Dispositif de commutation de securite pour circuit de securite | |
| EP2720098B1 (fr) | Système de sécurité pour une installation comprenant un chemin de signal de test avec un chemin de retour | |
| DE102009042368B4 (de) | Steuerungssystem zum Steuern von sicherheitskritischen Prozessen | |
| EP2720094B1 (fr) | Système de sécurité | |
| DE3706325C2 (fr) | ||
| DE102010025675B3 (de) | Sicherheitsschaltungsanordnung zum fehlersicheren Ein- und Ausschalten einer gefährlichen Anlage | |
| EP1738383B2 (fr) | Appareil de signalisation pour circuit de protection | |
| EP1642179B1 (fr) | Dispositif pour commander de maniere automatisee le deroulement d'une operation dans une installation technique | |
| DE2817089A1 (de) | Gefahrenmeldeanlage | |
| EP2445771B1 (fr) | Procede de creation d'un poste d'aiguillage electronique pour remplacer un poste d'aiguillage existant | |
| DE2833761C3 (de) | Schaltungsanordnung zur Überwachung des Zustands von Signalanlagen, insbesondere von Straßenverkehrs-Lichtsignalanlagen | |
| EP2691969A1 (fr) | Ensemble de circuit de sécurité pour mettre sous ou hors tension de manière sécurisée une installation dangereuse | |
| DE102014100970A1 (de) | Verfahren und Vorrichtung zum sicheren Abschalten einer elektrischen Last | |
| DE102007043053B4 (de) | Signaltechnisch sichere elektronische Elementansteuerung zum Durchführen eines Fahrbetriebs von Schienenfahrzeugen | |
| EP0192120B2 (fr) | Système et dispositif de transmission de données pour commande à distance | |
| EP1202313A1 (fr) | Dispositif de sécurité pour surveiller la position des pièces de contact mécanique | |
| EP2090492B1 (fr) | Procédé de réalisation d'une technique de sécurisation de voies universelle à l'aide de composants SPS disponibles de manière industrielle | |
| EP2236389B1 (fr) | Procédé de dépôt de signalements des perturbations d'une unité de fonctionnement décentralisée dans un système de sécurisation pour trafic sur rails | |
| DE19813389A1 (de) | Sicherheitsgerichtete Ansteuerschaltung | |
| DE102009018140A1 (de) | Sichere Schalteinrichtung und modulares fehlersicheres Steuerungssystem | |
| DE102006030911B3 (de) | Schaltungsanordnung für eigenüberwachte Relaisfunktionseinheit | |
| EP2520988A1 (fr) | Dispositif de surveillance pour gardes-réseaux | |
| DE4426466A1 (de) | Anordnung und Verfahren zum Betreiben von Gefahrenmeldern | |
| DE3919558C2 (fr) |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MT NL NO PL PT RO SE SI SK TR |
|
| AX | Request for extension of the european patent |
Extension state: AL BA MK RS |
|
| TPAC | Observations filed by third parties |
Free format text: ORIGINAL CODE: EPIDOSNTIPA |
|
| PUAL | Search report despatched |
Free format text: ORIGINAL CODE: 0009013 |
|
| AK | Designated contracting states |
Kind code of ref document: A3 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MT NL NO PL PT RO SE SI SK TR |
|
| AX | Request for extension of the european patent |
Extension state: AL BA MK RS |
|
| AKX | Designation fees paid | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20100331 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: 8566 |