EP2849986B1 - Procédé et système pour commander une installation technique - Google Patents
Procédé et système pour commander une installation technique Download PDFInfo
- Publication number
- EP2849986B1 EP2849986B1 EP13733994.1A EP13733994A EP2849986B1 EP 2849986 B1 EP2849986 B1 EP 2849986B1 EP 13733994 A EP13733994 A EP 13733994A EP 2849986 B1 EP2849986 B1 EP 2849986B1
- Authority
- EP
- European Patent Office
- Prior art keywords
- computer
- operator workstation
- workstation computer
- secure
- operator
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B61—RAILWAYS
- B61L—GUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
- B61L21/00—Station blocking between signal boxes in one yard
- B61L21/04—Electrical locking and release of the route; Electrical repeat locks
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B61—RAILWAYS
- B61L—GUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
- B61L19/00—Arrangements for interlocking between points and signals by means of a single interlocking device, e.g. central control
- B61L19/06—Interlocking devices having electrical operation
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B61—RAILWAYS
- B61L—GUIDING RAILWAY TRAFFIC; ENSURING THE SAFETY OF RAILWAY TRAFFIC
- B61L27/00—Central railway traffic control systems; Trackside control; Communication systems specially adapted therefor
- B61L27/30—Trackside multiple control systems, e.g. switch-over between different systems
Definitions
- the invention relates to an arrangement for controlling a technical system, in particular a railway track system, wherein the arrangement comprises an interlocking computer, which can cause a changeover of the technical system, and at least two operator station computer, with which operating commands can be generated and transmitted to the interlocking computer.
- any arbitrary operating station computer for example a standard PC
- a given level of security need not be achieved, since the interlocking computer located between the operator station computer and the technical system can reject dangerous operator actions.
- precautions must be taken to reliably prevent a dangerous situation in the technical system.
- the patent DE 36 39 788 C1 shows an arrangement for controlling a railway track system, in which all information about a signal-technically safe part of an input device upstream signal-technically non-secure part are entered, and that all information and commands are automatically checked in the fail-safe part to secure signal relevance.
- the invention has for its object to provide an arrangement for controlling a technical system, which can be implemented inexpensively and still ensures a high safety standard.
- At least one operator station computer of the operator station computers a safer
- An operator console computer whose security level reaches a predetermined minimum standard and at least one operator station computer is an insecure operator computer whose security level falls below the predetermined minimum standard
- the secure operator computer is connected to the interlocking computer via a secure data connection which ensures a predetermined transmission security
- the at least one unsafe operating computer is indirectly connected to the interlocking computer, namely via the secure operator's computer, and the operating commands of the insecure computer to the secure operator's computer and transmitted via this and the secure data connection to the interlocking computer.
- a significant advantage of the arrangement according to the invention is that in this uncertain computer can also be used to generate safety-related commands.
- the connection of the insecure computers to the interlocking computer is not provided directly, but indirectly via at least one secure computer; This ensures that operating commands, in particular those that are security-relevant, can only be transmitted directly from a secure computer to the interlocking computer, not directly from an insecure computer. In this way, it is possible to check the operating commands coming from the insecure computer for plausibility and / or executability, before they are forwarded to the interlocking computer for final implementation.
- the inventive idea therefore consists in enabling the integration of insecure operator station computers by interposing secure operator computers.
- the technical system descriptive record is stored centrally and the insecure terminal computer is programmed so that it generates user-specific display control signals using the stored in the secure terminal computer record and a predetermined by the operator of the unsafe computer display mode, the user-defined display of the defined by the record Condition of the technical system on a connected to the insecure terminal computer display lead. Due to the central storage of the state of the technical system descriptive record ensures that always always consider all operator's computer and all connected to the operator computers display devices always the same data. The accuracy of the data is ensured by the fact that these are managed and updated in the secure computer.
- the secure operator computer comprises at least two redundantly operated memory areas, in each of which the data describing the state of the technical system record is stored.
- a check of the records stored in the two redundantly operated memory areas for agreement is preferably carried out by a comparison block. Accordingly, it is considered advantageous if a comparison block is arranged between the secure and the insecure operating station computer and the comparison block is designed such that it data of the state of the technical system descriptive record for the purpose of transmission to the unsafe operating computer from each of the at least two redundantly operated Read out and compare memory areas and forward the data read out to the insecure workstation computer only if they match, and otherwise block forwarding.
- the comparison block is preferably a separate component that is not implemented in any of the operator station computers.
- the comparison block can also be integrated in the secure operator station computer.
- the secure operator computer includes at least two redundantly operating computer units that send at least two redundantly operating computer units of the secure operator's computer after receiving a security-related operating command of the insecure operator's computer each a confirmation request to the insecure terminal operator, and
- the comparison block is configured such that it compares the confirmation prompts of at least two redundantly operating computer units of the secure operator's computer and forwarded to the insecure terminal computers only if they match, and otherwise blocked forwarding.
- the requirement of the confirmation prompts ensures that the comparison block can check and intervene in the activity of the two redundantly operating computer units if it can be seen from the confirmation prompts of the two redundantly operating computer units that they produce mutually differing results.
- the comparison block also monitors the interface between the interlocking computer and the secure operator's computer. Accordingly, it is considered advantageous if the comparison block control signals that would cause a change of the technical system, the at least two redundant working computer units of the secure operator's computer compares with each other and to the interlocking computer only then forward or forward if they match, and otherwise block forwarding.
- the invention also relates to a method for controlling a technical system, in particular a railway track system, being generated with an operator's computer operating commands and transmitted to a communicating with the technical system interlocking computer and the interlocking computer, a changeover of the technical system is prompted.
- the operating commands with an insecure operating station computer whose security level falls below a predetermined minimum standard generated and transmitted to the interlocking computer via a secure operator's computer whose security level reaches the predetermined minimum standard.
- a data record describing the state of the technical system is stored centrally in the secure operator station, with the insecure operator station computer using the data set stored in the secure operator station and a display mode predetermined by the operator of the insecure computer an operator-specific display of the state of the technical system defined by the data set, and the display control signals are displayed on a display device connected to the insecure console computer.
- the data describing the state of the technical system record is stored redundantly in at least two memory areas and read data of the state of the technical system descriptive record for the purpose of transmission to the unsafe computer from each of the at least two memory areas and compared and the read-out data are forwarded to the insecure console computer only if they match, and otherwise a forwarding is blocked.
- FIG. 1 an arrangement 10 for controlling a technical system 20, which is, for example, at a railway track can act.
- the arrangement 10 comprises an interlocking computer 25, a secure operator station computer 30 and two insecure operator station computers 40 and 50.
- the three operator station computers 30, 40 and 50 each have a display device 60, 70 or 80 in conjunction.
- the two insecure operating station computers 40 and 50 are connected via a comparison block 90 with the secure operator station computer 30 in conjunction; An indirect connection between the two insecure operating station computers 40 and 50 and the interlocking computer 25 is possible via the comparison module 90.
- FIG. 1 shows by way of example the structure of the secure operator station computer 30 in more detail. It can be seen two memory areas 100 and 110, which are intended for storing a state of the technical system 20 descriptive record DS.
- the data record DS is thus stored twice or redundantly in the secure operator station computer 30, both in the memory area 100 and in the memory area 110.
- the secure operator station computer 30 has two redundantly operating computer units 120 and 130, which are in communication with the comparison module 90.
- the two computer units 120 and 130 may be formed by physically separate processors or processor devices; Alternatively, it is possible to image or simulate the two computer units 120 and 130 merely by software and to implement them by separate software modules running on one and the same processor device.
- a display software module ASM is provided in the safe operator station computer 30 and in the two non-secure operator computer computers 40 and 50, which allows the state of the technical system 20 to be displayed on the respective downstream display device 60, 70 or 80.
- the display software module ASM of the secure workstation computer 30 is stored in a separate memory area 140; Alternatively, the display software module ASM may also be stored in the memory area 100 or the memory area 110.
- the display software module ASM of the secure operator computer 30 can be executed, for example, by a separate computer unit 150, as shown in FIG FIG. 1 is indicated. Alternatively, the display software module ASM of the secure operator computer 30 can also be executed by one of the two computer units 120 or 130 or redundantly by both computer units 120 and 130.
- the in the FIG. 1 illustrated three memory areas 100, 110 and 140 of the secure operator's computer 30 may be located in physically separate memories; alternatively, they can also be located in sections of the same physical memory.
- an operator can input an operating signal BS3 to the insecure operating station computer 50 with which the display software module ASM is given or described a user-specific representation of the state of the technical system 20.
- the display software module ASM evaluates the operating signal BS3 and generates on the output side an operator-specific display control signal AS3, with which the display device 80 is activated and the state of the technical system 20 is displayed in accordance with the specifications of the operator. For example, with the operating signal BS3, the zoom factor or on the display device 80 section can be changed user-individually.
- the data D originate from the data set DS, which is stored in a redundant manner in the two memory areas 100 and 110 of the secure operator station computer 30.
- the data D from the two memory areas 100 and 110 is checked for identity by the comparison block 90.
- the comparison block 90 becomes the data D which consists of the two data sets DS of the two memory areas 100 and 110 come, first compare and then forward only to the display software module ASM the unsafe operating computer 50 if the data D are identical.
- the state of the technical system 20 can be displayed on the display devices 60 and 70 by inputting corresponding operating signals BS1 or BS2 into the secure operator station computer 30 or the insecure operator station computer 40 and generating corresponding display control signals AS1 and AS2.
- Both operator station computers 30 and 40 are each equipped with a display software module ASM, which evaluates the respectively present operating signal BS1 or BS2 and displays the state of the technical system 20 on the respective display device 60 or 70 on the basis of the operator-desired display mode.
- the same data sets DS are always used, which are also utilized by the operator station computer 50 as described above; with others Words, the data sets DS, which contain the data D about the state of the technical system 20, are stored and managed exclusively centrally and transmitted from a central point to the display software modules ASM of the respective operator station computers 30, 40 and 50.
- the data D which are displayed by the display software modules ASM of the workstation computer 30 or of the workstation computer 40, are also checked for correctness by the comparison module 90, as has already been described in connection with the workstation computer 50 above. This means that even when the display software modules ASM of the two workstation 30 and 40 of the comparison block 90 when reading the data D from the two memory areas 100 and 110 performs a verification of the data for identity and only if the data D from the two memory areas 100th and 110, will forward the data to the respective display software modules ASM.
- FIG. 2 shows by way of example the mode of operation of the arrangement 10 according to FIG. 1 if with the aid of one of the two insecure operating station computers 40 and 50, a safety-relevant operating command BB is generated, with which a conversion of the technical system 20 by the interlocking computer 25 is to take place.
- the two computer units 120 and 130 After receiving the security-relevant operating command BB, the two computer units 120 and 130 evaluate the operating command and generate a confirmation request BSA and send it via the comparison module 90 to the non-secure operator station computer 50.
- the comparison module 90 will check the confirmation prompts BSA of the two computer units 120 and 130 for identity or content match and only if the two confirmation prompts BSA match, make a forwarding to the non-secure operator station computer 50.
- the comparison block 90 becomes a Prevent forwarding. In this way, it is ensured that the execution of a safety-relevant operating command BB can only take place if the two computer units 120 and 130 understand the safety-relevant operating command BB in the same way and acknowledge with the same confirmation prompts BSA.
- the two computer units 120 and 130 will implement a conversion of the safety-relevant operating command BB and generate a control signal STB which is transmitted to the interlocking computer 25.
- the control signal STB the interlocking computer 25 is informed that the technical system 20 should be converted.
- the conversion of the technical system 20 is then made by the interlocking computer 25.
- the data transmission of the control signal STB from the secure operator station computer 30 to the interlocking computer 25 takes place via a secure data connection 200 in order to avoid a falsification of the command.
- the comparison module 90 will block the generation or propagation of the control signal STB via the secure data connection 200 if the two computer units 120 and 130 provide different results and different control signals STB.
- FIG. 3 shows a second embodiment of an arrangement 10 for controlling a technical system 20.
- two display devices 60 and 61 are connected, which are each controlled by an associated adosrsoftwaremodul ASM.
- the two display software modules ASM can be stored in the memory area 100 and / or the memory area 110 or else in individual memory areas.
- the two display software modules ASM are respectively stored in individual memory areas 140 and 141 and executed by computer units 150 and 151.
- the safe operating station computer 30 By equipping the safe operating station computer 30 with two display software modules ASM, it is possible to provide different representations of the state of the technical system 20 on the two display devices 60 and 61, in which different operating signals BS1 and BS1 'are entered into the display software modules ASM. In this way, it is possible for an operator, for example, to check the correctness of the operation of the display software modules ASM.
- the data D from the two memory areas 100 and 110 are not transmitted directly to the display software modules ASM, but only indirectly via the comparison block 90. Only if the data D from the two memory areas 100 and 110 match, the comparison block 90 will forward the data D to the two display software modules ASM in the secure terminal computer 30, so that only then an indication on the two Display devices 60 and 61 can be done.
- the mode of operation corresponds to the arrangement 10 according to FIG. 3 thus the arrangement 10 according to FIG. 1 , so that reference is made to the above statements.
- FIG. 4 shows a third embodiment of an arrangement 10 for controlling a technical system 20.
- the arrangement 10 according to FIG. 4 essentially corresponds to the embodiment according to FIG. 3 with the difference that the comparison block 90 is not a separate component, but instead is integrated in the secure operator station computer 30.
- the comparison module 90 can be realized in the form of a software module that is executed by one of the two computer units 120 or 130.
- the comparison block 90 may be formed by a separate hardware component provided in the secure console computer 30.
Landscapes
- Engineering & Computer Science (AREA)
- Mechanical Engineering (AREA)
- Train Traffic Observation, Control, And Security (AREA)
- Electric Propulsion And Braking For Vehicles (AREA)
- Safety Devices In Control Systems (AREA)
Claims (9)
- Agencement (10) de commande d'une installation (20) technique, notamment d'une installation de voie de chemin de fer, l'installation (10) comprenant un ordinateur (25) de poste d'aiguillage, qui peut provoquer un renversement de l'installation (20) technique, et au moins deux ordinateurs (30, 40, 50) d'emplacement de service, par lesquels des instructions (BB) de service peuvent être produites et être transmises à l'ordinateur (25) du poste d'aiguillage, dans lequel- parmi les ordinateurs (30, 40, 50) d'emplacement de service, au moins un ordinateur (30) d'emplacement de service est un ordinateur (30) d'emplacement de service sécurisé, dont le niveau de sécurité atteint une norme minimum donnée à l'avance, et au moins un ordinateur (40, 50) d'emplacement de service est un ordinateur (40, 50) d'emplacement de service, dont le niveau de sécurité est inférieur à la norme minimum donnée à l'avance,- l'ordinateur (30) d'emplacement de service sécurisé est relié à l'ordinateur (25) du poste d'aiguillage par une liaison (200) de données sécurisée, qui assure une sécurité de transmission donnée à l'avance et- le au moins un ordinateur (40, 50) d'emplacement de service non sécurisé est relié indirectement à l'ordinateur (25) du poste d'aiguillage, à savoir par l'intermédiaire de l'ordinateur (30) d'emplacement de service sécurisé et les instructions (BB) de service de l'ordinateur (40, 50) d'emplacement de service non sécurisées sont transmises à l'ordinateur (30) d'emplacement de service sécurisé et par celui-ci et par la liaison (200) de données sécurisée à l'ordinateur (25) du poste d'aiguillage.
- Agencement (10) suivant la revendication 1,
caractérisé en ce que- un jeu (DS) de données décrivant l'état de l'installation (10) technique est mémorisé de manière centrale dans l'ordinateur (30) d'emplacement de service sécurisé et- l'ordinateur (40, 50) d'emplacement de service non sécurisé est programmé de manière à produire, en tirant parti du jeu (DS) de données mémorisé dans l'ordinateur (30) d'emplacement de service sécurisé et d'un mode de représentation donné à l'avance par l'opérateur de l'ordinateur (40, 50) d'emplacement de service non sécurisé, des signaux (AS1 à AS3) de commande d'affichage individuels à l'opérateur, qui donnent un affichage individuel à l'opérateur, de l'état, défini par le jeu (DS) de données, de l'installation (20) technique à un dispositif (70, 80) d'affichage relié à l'ordinateur (40, 50) d'emplacement de service non sécurisé. - Agencement (10) suivant la revendication 2,
caractérisé en ce que l'ordinateur (30) d'emplacement de service sécurisé comprend au moins deux zones (100, 110) de mémoire fonctionnant de manière redondante, dans lesquelles est mémorisé respectivement le jeu (DS) de données décrivant l'état de l'installation (20) technique. - Agencement (10) suivant la revendication 3,
caractérisé en ce que- un module (90) de comparaison est disposé entre l'ordinateur (30) d'emplacement de service sécurisé et l'ordinateur (40, 50) d'emplacement de service non sécurisé et- le module (90) de comparaison est conformé de manière à déchiffrer des données du jeu (DS) de données décrivant l'état de l'installation (20) technique en vue de la transmission à l'ordinateur 40, 50) d'emplacement de service non sécurisé respectivement à partir de chacune des au moins deux zones (100, 110) de mémoire fonctionnant de manière redondante et à les comparer entre elles et à acheminer les données (D) déchiffrées à l'ordinateur (40, 50) d'emplacement de service non sécurisé, seulement si elles coïncident, et sinon à empêcher un acheminement. - Agencement (10) suivant l'une des revendications précédentes,
caractérisé en ce que- l'ordinateur (30) d'emplacement de service sécurisé comprend au moins deux unités (120, 130) d'ordinateur fonctionnant de manière redondante,- les au moins deux unités (120, 130) d'ordinateur fonctionnant de manière redondante de l'ordinateur (30) d'emplacement de service sécurisé envoie, après avoir reçu une instruction (BB) de service pertinente du point de vue de la sécurité de l'ordinateur (40, 50) d'emplacement de service non sécurisé, respectivement une demande (BSA) de confirmation à l'ordinateur (40, 50) d'emplacement de service non sécurisé et cela par l'intermédiaire du module (90) de comparaison et- le module (90) de comparaison est conformé de manière à comparer entre elles les demandes (BSA) de confirmation des au moins deux unités (120, 130) d'ordinateur fonctionnant de manière redondante de l'ordinateur (30) d'emplacement de service sécurisé et à les acheminer à l'ordinateur (40, 50) d'emplacement de service non sécurisé, seulement si elles coïncident, sinon à empêcher un acheminement. - Agencement (10) suivant l'une des revendications précédentes, caractérisé en ce que
le module (90) de comparaison compare entre eux des signaux (STB) de commande, qui auraient provoqué un renversement de l'installation (20) technique, des au moins deux unités (120, 130) d'ordinateur fonctionnant de manière redondante de l'ordinateur (30) d'emplacement de service sécurisé et les achemine ou les laisse s'acheminer à l'ordinateur (25) du poste d'aiguillage, seulement s'ils coïncident, et sinon empêchent un acheminement. - Procédé de commande d'une installation (20) technique, notamment d'une installation de voie de chemin de fer, dans lequel,
par un ordinateur (30, 40, 50) d'emplacement de service, on produit des instructions (BB) de service et on les transmet à un ordinateur (25) de poste d'aiguillage en liaison avec l'installation (20) technique et on provoque un renversement de l'installation (20) technique par l'ordinateur (25) du poste d'aiguillage,
dans lequel
on produit les instructions (BB) de service par un ordinateur (40, 50) d'emplacement de service non sécurisé, dont le niveau de sécurité est inférieur à une norme minimum donnée à l'avance, et on les transmet à l'ordinateur (25) du poste d'aiguillage par l'intermédiaire d'un ordinateur (30) d'emplacement de service sécurisé, dont le niveau de sécurité atteint la norme minimum donnée à l'avance. - Procédé suivant la revendication 7,
caractérisé en ce que- on mémorise de manière centrale dans l'ordinateur (30) d'emplacement de service sécurisé un jeu (DS) de données décrivant l'état de l'installation (20) technique,- on produit par l'ordinateur (40, 50) d'emplacement de service non sécurisé, en tirant parti du jeu (DS) de données mémorisées dans l'ordinateur (30) d'emplacement de service sécurisé et d'un mode de représentation donné à l'avance par l'opérateur de l'ordinateur non sécurisé, des signaux (AS1 à AS3) de commande d'affichage individuels à l'opérateur, qui donne un affichage individuel à l'opérateur, de l'état, défini par le jeu (DS) de données, de l'installation (20) technique et- on affiche les signaux (AS1 à AS3) de commande d'affichage sur un dispositif (70, 80) d'affichage relié à l'ordinateur (40, 50) d'emplacement de service non sécurisé. - Procédé suivant le revendication 8,
caractérisé en ce que- on mémorise le jeu (DS) de données décrivant l'état de l'installation (20) technique d'une manière redondante dans au moins deux zones (100, 110) de mémoire et- on déchiffre et on compare entre elles des données (D) du jeu (DS) de données décrivant l'état de l'installation (20) technique en vue de la transmission à l'ordinateur (40, 50) d'emplacement de service non sécurisé respectivement de chacune des au moins deux zones (100, 110) de mémoire et on achemine les données (D) déchiffrées à l'ordinateur (40, 50) d'emplacement de service non sécurisé, seulement si elles coïncident, et sinon on empêche un acheminement.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102012211273.1A DE102012211273A1 (de) | 2012-06-29 | 2012-06-29 | Verfahren und Anordnung zum Steuern einer technischen Anlage |
| PCT/EP2013/063098 WO2014001235A2 (fr) | 2012-06-29 | 2013-06-24 | Procédé et système pour commander une installation technique |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| EP2849986A2 EP2849986A2 (fr) | 2015-03-25 |
| EP2849986B1 true EP2849986B1 (fr) | 2016-04-27 |
Family
ID=48746454
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP13733994.1A Active EP2849986B1 (fr) | 2012-06-29 | 2013-06-24 | Procédé et système pour commander une installation technique |
Country Status (4)
| Country | Link |
|---|---|
| EP (1) | EP2849986B1 (fr) |
| CN (1) | CN104411564B (fr) |
| DE (1) | DE102012211273A1 (fr) |
| WO (1) | WO2014001235A2 (fr) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102016205119A1 (de) * | 2016-03-29 | 2017-10-05 | Siemens Aktiengesellschaft | System zur Steuerung von Stellwerken im Bahnverkehr |
Family Cites Families (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE2036505C3 (de) * | 1970-07-23 | 1978-10-05 | Bayer Ag, 5090 Leverkusen | Kationische Farbstoffe, Verfahren zu deren Herstellung und deren Verwendung |
| DE3639788C1 (en) * | 1986-11-21 | 1988-03-03 | Licentia Gmbh | Method and arrangement for input of information into computer systems with secure signalling |
| DE10053023C1 (de) * | 2000-10-13 | 2002-09-05 | Siemens Ag | Verfahren zum Steuern eines sicherheitskritischen Bahnbetriebsprozesses und Einrichtung zur Durchführung dieses Verfahrens |
| DE10116244C2 (de) * | 2001-03-28 | 2003-05-08 | Siemens Ag | Verfahren zum Betreiben einer Bedienplatzeinrichtung |
| AU2002224742A1 (en) * | 2001-11-22 | 2003-06-17 | Siemens Aktiengesellschaft | Method for controlling a safety-critical railway operating process and device for carrying out said method |
| DE102007004917B4 (de) * | 2007-01-26 | 2010-09-30 | Siemens Ag | Verfahren und Anordnung zur Ansteuerung und Überwachung von Feldelementen |
| DE102007043053B4 (de) * | 2007-09-11 | 2020-07-30 | Db Netz Ag | Signaltechnisch sichere elektronische Elementansteuerung zum Durchführen eines Fahrbetriebs von Schienenfahrzeugen |
-
2012
- 2012-06-29 DE DE102012211273.1A patent/DE102012211273A1/de not_active Withdrawn
-
2013
- 2013-06-24 CN CN201380029120.8A patent/CN104411564B/zh not_active Expired - Fee Related
- 2013-06-24 WO PCT/EP2013/063098 patent/WO2014001235A2/fr not_active Ceased
- 2013-06-24 EP EP13733994.1A patent/EP2849986B1/fr active Active
Also Published As
| Publication number | Publication date |
|---|---|
| CN104411564A (zh) | 2015-03-11 |
| EP2849986A2 (fr) | 2015-03-25 |
| WO2014001235A2 (fr) | 2014-01-03 |
| CN104411564B (zh) | 2017-01-18 |
| WO2014001235A3 (fr) | 2014-06-19 |
| DE102012211273A1 (de) | 2014-01-02 |
| HK1208013A1 (en) | 2016-02-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE60309928T2 (de) | Verfahren zur erhöhung der sicherheitsintegritätsstufe eines kontrollsystems | |
| EP3709106A1 (fr) | Mise en sécurité d'une machine | |
| EP2731849B1 (fr) | Calculateur de poste d'aiguillage | |
| EP3355230A1 (fr) | Procédé et dispositif de fabrication assistée par ordinateur et d'exécution d'une fonction de commande | |
| WO2007131603A1 (fr) | Procédé et système pour la modification de données de sécurité pour un dispositif de commande | |
| DE102007032805A1 (de) | Verfahren und Systemarchitektur zur sicheren einkanaligen Kommunikation zum Steuern eines sicherheitskritischen Bahnbetriebsprozesses | |
| EP2726357B1 (fr) | Dispositif de commande | |
| DE102004018857A1 (de) | Sicherheitssteuerung | |
| EP3794769B1 (fr) | Modification du contenu d'une mémoire pour des certificats racines | |
| DE102013017951A1 (de) | Elektronische Steuervorrichtung und Verfahren zum Überprüfen einer Rücksetzfunktion | |
| EP4385676B1 (fr) | Validation de la pose d'un robot et des données d'un capteur se déplaçant avec le robot | |
| AT402909B (de) | Verfahren zur gewährleistung der signaltechnischen sicherheit der benutzeroberfläche einer datenverarbeitungsanlage | |
| DE10053023C1 (de) | Verfahren zum Steuern eines sicherheitskritischen Bahnbetriebsprozesses und Einrichtung zur Durchführung dieses Verfahrens | |
| EP3499324B1 (fr) | Procédé de vérification modulaire d'une configuration d'un appareil | |
| EP2849986B1 (fr) | Procédé et système pour commander une installation technique | |
| EP2405317B1 (fr) | Procédé de paramétrage assuré sûr d'un appareil | |
| EP1683016B1 (fr) | Acquisition fiable de donnees d'entree | |
| DE19942981A1 (de) | Programmodul und Verfahren zum Erhöhen der Sicherheit eines softwaregesteuerten Systems | |
| WO2014128036A1 (fr) | Procédé de découverte d'erreurs dans un système informatique de poste d'aiguillage et système informatique de poste d'aiguillage | |
| DE102008012953A1 (de) | Überprüfung von Anzeigesystemen in Schienenfahrzeugen | |
| WO2011113405A1 (fr) | Groupement d'appareils de commande | |
| DE102015205607A1 (de) | Verfahren zum Überwachen einer Netzwerkkomponente sowie Anordnung mit einer Netzwerkkomponente und einer Überwachungs-Einrichtung | |
| EP1220094B1 (fr) | Procédure de programmation pour un système redondant à sécurité critique | |
| DE102012212780A1 (de) | Bedieneinrichtung zur Eingabe von Bedienbefehlen zur Steuerung einer technischen Anlage | |
| DE102013211582A1 (de) | Verfahren zur sicheren Parametrierung einer Automatisierungskomponente |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20141216 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAX | Request for extension of the european patent (deleted) | ||
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| INTG | Intention to grant announced |
Effective date: 20151117 |
|
| GRAS | Grant fee paid |
Free format text: ORIGINAL CODE: EPIDOSNIGR3 |
|
| GRAA | (expected) grant |
Free format text: ORIGINAL CODE: 0009210 |
|
| AK | Designated contracting states |
Kind code of ref document: B1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| REG | Reference to a national code |
Ref country code: GB Ref legal event code: FG4D Free format text: NOT ENGLISH |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: EP Ref country code: CH Ref legal event code: NV Representative=s name: SIEMENS SCHWEIZ AG, CH |
|
| REG | Reference to a national code |
Ref country code: AT Ref legal event code: REF Ref document number: 794411 Country of ref document: AT Kind code of ref document: T Effective date: 20160515 |
|
| REG | Reference to a national code |
Ref country code: IE Ref legal event code: FG4D Free format text: LANGUAGE OF EP DOCUMENT: GERMAN |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R096 Ref document number: 502013002826 Country of ref document: DE |
|
| REG | Reference to a national code |
Ref country code: RO Ref legal event code: EPE |
|
| REG | Reference to a national code |
Ref country code: NL Ref legal event code: FP |
|
| REG | Reference to a national code |
Ref country code: LT Ref legal event code: MG4D |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: NO Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160727 Ref country code: LT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: FI Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: PL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: GR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160728 Ref country code: ES Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: PT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160829 Ref country code: RS Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: LV Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: HR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: SE Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: IT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: BE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20160630 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R097 Ref document number: 502013002826 Country of ref document: DE |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: DK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: MC Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: SK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: CZ Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: EE Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: SM Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 |
|
| PLBE | No opposition filed within time limit |
Free format text: ORIGINAL CODE: 0009261 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT |
|
| REG | Reference to a national code |
Ref country code: IE Ref legal event code: MM4A |
|
| REG | Reference to a national code |
Ref country code: FR Ref legal event code: ST Effective date: 20170228 |
|
| 26N | No opposition filed |
Effective date: 20170130 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: FR Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20160630 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: IE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20160624 Ref country code: SI Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: PCOW Free format text: NEW ADDRESS: WERNER-VON-SIEMENS-STRASSE 1, 80333 MUENCHEN (DE) |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: HU Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT; INVALID AB INITIO Effective date: 20130624 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: LU Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20160624 Ref country code: MT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: MK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: IS Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 Ref country code: CY Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: BG Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: AL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20160427 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: FR Payment date: 20180827 Year of fee payment: 11 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R081 Ref document number: 502013002826 Country of ref document: DE Owner name: SIEMENS MOBILITY GMBH, DE Free format text: FORMER OWNER: SIEMENS AKTIENGESELLSCHAFT, 80333 MUENCHEN, DE |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: PUE Owner name: SIEMENS MOBILITY GMBH, DE Free format text: FORMER OWNER: SIEMENS AKTIENGESELLSCHAFT, DE |
|
| REG | Reference to a national code |
Ref country code: AT Ref legal event code: PC Ref document number: 794411 Country of ref document: AT Kind code of ref document: T Owner name: SIEMENS MOBILITY GMBH, DE Effective date: 20190506 |
|
| REG | Reference to a national code |
Ref country code: NL Ref legal event code: PD Owner name: SIEMENS MOBILITY GMBH; DE Free format text: DETAILS ASSIGNMENT: CHANGE OF OWNER(S), ASSIGNMENT; FORMER OWNER NAME: SIEMENS AKTIENGESELLSCHAFT Effective date: 20190829 |
|
| GBPC | Gb: european patent ceased through non-payment of renewal fee |
Effective date: 20190624 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: GB Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20190624 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: RO Payment date: 20200615 Year of fee payment: 8 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: RO Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20210624 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: NL Payment date: 20240603 Year of fee payment: 12 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: TR Payment date: 20240614 Year of fee payment: 12 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: DE Payment date: 20240819 Year of fee payment: 12 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: CH Payment date: 20240903 Year of fee payment: 12 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: AT Payment date: 20250509 Year of fee payment: 13 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R119 Ref document number: 502013002826 Country of ref document: DE |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: H13 Free format text: ST27 STATUS EVENT CODE: U-0-0-H10-H13 (AS PROVIDED BY THE NATIONAL OFFICE) Effective date: 20260127 |
|
| REG | Reference to a national code |
Ref country code: NL Ref legal event code: MM Effective date: 20250701 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: NL Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20250701 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: DE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20260101 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: CH Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20250630 |