31.01.2014 Views

Ph.D. - geht es zur Homepage der Informatik des Fachbereiches 3 ...

Ph.D. - geht es zur Homepage der Informatik des Fachbereiches 3 ...

Ph.D. - geht es zur Homepage der Informatik des Fachbereiches 3 ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 10. openETCS Model<br />

0<br />

(CONST)<br />

double<br />

double<br />

> Current Train Speed<br />

bool<br />

Do not allow negative speed valu<strong>es</strong>.<br />

Emergency Brake Value<br />

Figure 10.15.: Reverse movement protection as gSubFunctionBlock graph<br />

In contrast to the supervision of train speed in r<strong>es</strong>pect to a constant top or ceiling speed<br />

in Unfitted or Staff R<strong>es</strong>ponsible, here the speed is additionally controlled corr<strong>es</strong>ponding to<br />

the end of the current valid MA. Furthermore, the allowed speed at the end of a MA must<br />

not always be 0. This supervision corr<strong>es</strong>ponds to a typically braking curve supervision [67,<br />

pp. 95-97] and is repr<strong>es</strong>ented in the model by an oBrakingToTargetSpeed (BTS) object (see<br />

Subsection 7.3.2). “Current V_LOA” (v loa ) holds the speed that is currently permitted at<br />

the end / limit of authority, and “Distance of EoA” is the absolute position of the end of the<br />

authority. In the case that v loa > 0 and the train has overpassed the end of authority, it can<br />

move with v loa until a certain overlap distance [89, pp. 35-47] is passed. In this case, the Mode<br />

is switched to Trip, which is modelled by the “c12” oModeGuard object in Figure 10.16.<br />

10.2.6. Trip Mode<br />

Trip Mode is always activated if an operational 4 failure occurs that requir<strong>es</strong> the train fully to<br />

stop. This can be, for example, the case for an overpassed stop signal and a corr<strong>es</strong>ponding<br />

balise telegram or if the balise linking supervision (see Subsection 10.2.4) fails.<br />

According to the ETCS SRS, Trip is not available in Application Level 0 [88, p. 23] but in<br />

all other levels. This is in conflict with the fact that Trip is also reachable from Unfitted [88,<br />

p. 37] (see Figure 10.1 for the corr<strong>es</strong>ponding model). Furthermore, succ<strong>es</strong>sor Mod<strong>es</strong> of Trip<br />

can only be Post Trip (oModeGuard “c62”) and Unfitted (oModeGuard “c7”) while condition<br />

62 or rather oModeGuard object “c62” is defined as<br />

(the driver acknowledg<strong>es</strong> the train trip) AND (the train is at standstill) AND (the<br />

ERTMS/ETCS level is 0) [88, p. 58]<br />

Since this is in conflict with definition of available Application Levels for Unfitted in the<br />

SRS [88, p. 23], Unfitted is also modelled for Level 0 in this case study.<br />

The main functionality in Trip is to stop the train by applying emergency brak<strong>es</strong> until the<br />

train is fully stopped.<br />

4 Compared to system failur<strong>es</strong>, operational failur<strong>es</strong> are related to the train operations and not to the train<br />

control system.<br />

194

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!