Safety-Critical Rail Control Platform

One Modular System for Onboard and Trackside Rail Automation

The duagon SAFE CONTROL (d-SC) is a modular, safety-certified railway control platform built for functional safety in rail automation. It complies with EN 50126, EN 50128, and EN 50129, with all components certified up to SIL 4.

Its modular configuration enables the system to communicate with other train systems like service or diagnosis units via any type of wired or wireless interface. Additionally, fieldbus interfaces like MVB, CAN, Profinet and more, can be implemented to connect into other networks. This makes it easy to integrate into a TCN network as well as into regionally different train control systems such as ETCS, CTCS, ATCS, PTC or Klub-U.

The COTS safe controller supports QNX out-of-the-box using the provided safety certified board support package (BSP). Additionally, duagon offers various software packages e.g., process data synchronization (SNYCH), modular I/O framework (PACY) or high availability software (HA-SW) which enables customer applications to use two redundant d-SC systems in a Hot-standby setup.

The d-SC system

The d-SC system is designed to operate in safety-critical onboard applications such as Automatic Train Operation (ATO) and Automatic Train Protection (ATP) as well as in wayside applications like level-crossing or computer-based interlocking systems. 

The modular system consists of the safe controller (1oo2, 2oo2), the safe I/O functions, and the communication interfaces to the "outside" world.

The robust and rail-ready components comply with the railway standards for environmental and EMC conditions EN 50155 (rolling-stock) and EN 50125-3 / EN 50121-4 (signalling/trackside).

Download: Cyber Secure Products & Service Packages

Pre-certified, modular open systems for long-term use

Certified Functional Safety

Save Cost, Time and Risk with Pre-Certification
duagon’s safety-related components come with certification packages for the hardware and the relevant platform software based on QNX. No matter what final application, the parts are already certified and will speed up your overall certification process.

Get Synergies for all Safety-Critical Applications
As a modular safe platform, with flexible I/O configuration and extension options, this system can be used in all safety-related applications onboard and trackside: from single functions like signal and level-crossing control up to complex systems for Automatic Train Operation or Protection (ATO/ATP).

Certification

  • EN 50126: The Specification and Demonstration of Reliability, Availability, Maintainability and Safety (RAMS)

  • EN 50128: Communication, signaling and processing systems - Software for railway control and protection systems

  • EN 50129: Communications, signaling and processing systems – safety-related electronic systems for signaling

Modularity in I/O Configuration and Software

Flexible Configuration for Controller Unit or Complete Network
The duagon SAFE CONTROL system is based on the modular 19” CompactPCI standard, making a scalable plug-and-play-like system configuration easy, enabling communication with other train functions like service or diagnosis, and supporting integration in existing train bus networks:

  • The MH50C controller can be configured with the exact number of required safe channels, and non-safe functions based on standard CompactPCI boards.

  • Up to 63 remote Safe I/O modules (with four to eight boards per device) can be connected to a single MH50C controller, saving wiring cost and increasing the operation stability.

Modularity in Terms of Software
Since all software functions (SYNCH, EXCH) are independent of each other, only the parts that are really needed can be configured in the system.
The PACY I/O framework is also modular in itself, so that functions such as new I/O modules, new bus systems or new safety protocols can be easily added.

Independency from Suppliers

Avoid Vendor Lock-In and Keep Control!
As an open and modular platform, the duagon SAFE CONTROL system makes rail service suppliers and rail operators independent of a platform supplier, giving them full control over their project.

Standards Based:

Standard CompactPCI industry standard and x86 host controller

  • Standard operating system (QNX, Linux)

  • Standard EtherCAT with safety protocol FSoE

  • Standard communication interfaces to TCN network, MVB, CANopen, ProfiNet, etc.

  • Standard POSIX programming interface for ‘‘C“

  • „C“ code generation, e.g. with model based code generation tools, such as ANSYS' SCADE or MathWorks' Simulink.

Long-Term Availability

Protect Your Investments From Discontinuation!
The system is exclusively based on open industry standards in hardware, software and communication with broad acceptance on the market. This guarantees alternatives for every function, so the end user is protected from obsolescence issues.

Extend your Project Life Cycle!
The lifetime is extendable by its family concept and a corresponding life-cycle management behind. After the guaranteed minimum availability of 10 years for all parts, duagon will provide its customers with all necessary steps and documents (e.g. change effect analysis, redesign) for possible successors.

duagon guarantees:

  • Delivery of identical duagon boards per project: 10 years

  • Technical support per project: 25 years

  • Delivery of functionality: unlimited in time

Safe Control (d-SC) Hardware

System Example

The heart of the modular duagon SAFE CONTROL system is the MH50C controller. It is based on the SIL 4-certified Intel CPU board F75P. The safe part can be extended by non-vital I/O functions without effecting the safety of the system. It can be used as a standalone device and in combination with up to 63 remote I/O boxes.

Real-Time Ethernet Communication

The communication inside the duagon SAFE CONTROL (d-SC) system – between the safe d-SC controller, safe I/O boards and safe remote I/O boxes – is based completely on a standardized safe real-time Ethernet, using EtherCAT and FSoE (Fail Safe over EtherCAT).


The application can therefore treat all I/O functions in the same way. All remote I/O boxes are connected to the controller in a ring topology, which tolerates single failures. For example, in case of a broken cable, the system is still fully operational, as all I/O boxes can still be reached from the other end of the ring.

Software Architecture

Separation between Safe and Non-Vital Domains

The d-SC software distinguishes between the safe and the non-vital domain in order to save cost and time for application development and certification. This separation allows to develop non-vital applications separately from safe applications. Non-vital applications cannot influence safe applications because they are executed on a separate processor running a standard Linux operating system.

The safe application runs in a safe kernel of the QNX real-time operating system and can either be directly programmed with standard "C" language, offering POSIX compliant APIs.

Safe Application Interface

As d-SC is an open general-purpose hardware platform for different kinds of safe applications, the software programmer needs an interface to get full access to the control electronics. The PACY safety I/O framework provides easy and modular access to the safe I/O boards. PACY also includes a safe communication layer (Fail Safe over EtherCat, FSoE).

Safe Communication

In order to guarantee appropriate communication between the safe controller and the safe I/O functions via real-time Ethernet, the black channel approach is applied. The requirements to transport safe data over untrusted communication are defined by EN 50159 and realized using the FSoE safe communication protocol (Fail Safe over EtherCat).

Products

Quad Fast Ethernet & Real-Time Ethernet
3U CompactPCI Interface Board

The F305 is a 3U CompactPCI 100-Mbit/s networking controller with a strong focus on railway applications. It comes in a compact 4 HP, one-slot width even with its rugged M12 connectors.

8 Safe Digital Outputs
High-Side Switching for d-SC, SIL 2 to SIL 4 Modular Train Control System I/O Board

The K1 is a safe digital output card for use in the duagon SAFE CONTROL (d-SC) System. The d-SC platform performs safe train control functions in rolling stock applications like Automated Train Protection (ATP) or CBTC (Communications Based Train Control).

16 Safe Digital Inputs for d-SC
SIL 2 to SIL 4 Modular Train Control System I/O Board

The K2 is a safe digital input card for use in the duagon SAFE CONTROL (d-SC) System. The d-SC platform performs safe train control functions in rolling stock applications like Automated Train Protection (ATP) or CBTC (Communications Based Train Control).

Low-Side Switching for d-SC
8 Safe Digital Outputs, Low-Side Switching for d-SC SIL 2 to SIL 4 Modular Train Control System I/O Board

The K7 is a safe digital output card for use in the duagon SAFE CONTROL (d-SC) System. The d-SC platform performs safe train control functions in rolling stock applications like Automated Train Protection (ATP) or CBTC (Communications Based Train Control).

d-SC Remote I/O Extension for 8 Cards
Modular Train Control System for Safe Applications in Transportation

KT8 is a safe, remote I/O box inside the duagon SAFE CONTROL (d-SC) System.The modular system platform d-SC is usable for safety-critical train applications like train control, automatic train operation (ATO) and automatic train protection (ATP) up to SIL 4 (EN5012x) or SIL 3 (IEC61508).

Vital System Controller
duagon SAFE CONTROL Vital System Controller. Modular Train Control System for Safe Applications in Transportation

MH50C is a central controller of the duagon SAFE CONTROL (d-SC) System. It is a modular system platform usable for safety-critical train applications like train control, automatic train operation (ATO) and automatic train protection (ATP) up to SIL 4 (EN5012x) or SIL3 (IEC61508).

Application Areas

Rolling Stock

The duagon SAFE CONTROL platform is well suited for control of all safety-related functions in new train models as well as for refurbishment of trains. Thanks to its modularity, it is easy to install and retrofit automation functions in combination with other parts of already existing train control equipment as well.

  • Installation as the heart of the any train protection and/or automation system
  • Increase in efficiency of already existing ATO, ATP and ATS functions as the central computer
  • Step-by-step replacement of older equipment, resulting in one standardized general-purpose platform for all safe applications
  • Remote control sitting directly at the door, at the wheel, at the gear
  • All-in-one safe control system and non-vital communication system – safely separated through strict partitioning
  • Interfacing to all existing train communication with Ethernet and MVB, CAN bus etc.
  • Interfacing to the driver cab display
  • Interfacing to wireless communication with the outside world through GSM-R, GPS, WLAN etc.
  • Decrease in life cycle cost through easy maintenance of standard components
  • Longer operating life by using standardized technologies.
Trackside

The duagon SAFE CONTROL system is well suited for control of CBI (Computer Based Interlocking), vital telemetry for train management, trackside devices such as switches, signals, or level crossings. Being a modular platform, it can be used in new interlocking systems as well as for a soft modernization and automation of older relay interlockings. Existing outside facilities can be preserved and adapted. The extremely compact inside facility of an interlocking system is clearly separated and forms the safe platform (SIL) for the control and automation layer.

  • Introduction of ETCS L2/L3 for optimization of safety and track load
  • Halving of the resulting opportunity cost for relay interlocking systems
  • Increase in performance of the interlocking systems
  • Low cabling cost thanks to standardized Ethernet technology
  • Avoidance of the costly total replacement by CBIs (incl. outside facilities)
  • Installation of simpler, smaller and standardized inside facilities
  • Longer operating life of the outside facilities
  • Lower cost for the expansion of total capacities
  • Decrease in life cycle cost through easy maintenance of standard components
  • Reduction of dependence on single suppliers, resulting in a growing service offer

Frequently Asked Questions

Is the duagon Safe Control (D-SC) system interoperable with already existing systems, and how can it be integrated?

Yes. Thanks to its modularity, d-SC is easy to install and retrofit safety and automation functions in any type of older rail vehicles.

d-SC can also be used for a soft modernization and automation of older electronic interlocking equipment, supporting installation of simpler, smaller and standardized inside facilities.

The modular CompactPCI hardware architecture allows to extend the MH50C controller with further communication and interface cards, using also standard PCI Express Mini Cards and similar state of the art devices:

  • Connection to existing TCN network via MVB & WTB railway fieldbus interface boards
  • Connection to existing train devices via CAN, ProfiNet and other fieldbus interface boards
  • Connection to standard switches and routers via Ethernet
  • Connection to all popular in vehicle and external communication interfaces via Wi Fi, radio, GPS, RS485 etc.
Why is duagon SAFE CONTROL (d-SC) called an open system?

d-SC is exclusively based on open industry standards in hardware, software and communication, allowing the end user to stay vendor independent and protected against obsolescence issues:

  • Standard PC hardware architecture with state of the art x86 host controller
  • Standard 19” CompactPCI industry standard
  • Standard operating systems (QNX, Linux)
  • Standard Ethernet communication with safe real time EtherCAT
  • Standard communication interfaces to TCN network, MVB, CANopen , ProfiNet etc.
  • Standard POSIX programming interface for “C”

d-SC separates the control electronics (the computer hardware) from the control function (the application software).

d-SC opens up the essential interfaces between the control electronics and the application.

As a totally open platform, d-SC is the first railway computer that makes rail service suppliers and rail operators independent from a solution provider, giving them full control over their project.

Why is the duagon SAFE CONTROL (d-SC) called a modular system?

d-SC is modular in terms of hardware based on its proven 19” CompactPCI technology:

  • The MH50C controller can be configured with the exact number of required safe I/O channels, and non-safe functions based on standard CompactPCI boards.

d-SC is modular in terms of I/O location:

  • Up to 63 remote I/O boxes (with four to eight boards per device) can be connected to one MH50C controller, saving huge wiring cost and increasing the operation stability.

d-SC is modular in terms of software:

  • Ready to integrate all state-of-the-art real-time operating system BSPs, with QNX being used as the standard operating system

  • Ready to mix and match RTOS for safe functions with Linux for non-safe functions

  • Ready to communicate via the EtherCAT standard real-time variant of standard Ethernet

  • Ready to start programming based on different standard environments

d-SC is modular in terms of certification:

  • As the complete d-SC solution may contain “safe” and “non-safe” parts, different SIL 4 certification packages are provided.

  • All certificates are available either for the hardware only or as a bundle together with the safe components of the QNX real-time operating system.

Which kind of rolling-stock applications can be covered with duagon SAFE CONTROL (d-SC)?
  • d-SC is the central computer platform for on-board ATO and ATP (Automated Train Operation and Protection) functions.
  • d-SC can be the heart of a CBTC (Communication Based Train Control) system.
  • d-SC interfaces to all existing train communication standards such as MVB, WTB, CAN etc.
  • d-SC interfaces to the outside world via wireless communication using GSM-R, GPS, WLAN etc
Which kind of trackside applications can be covered with duagon SAFE CONTROL (d-SC)?
  • d-SC is compliant with the EN 50121-4 standard for wayside EMC regulations describing the emission and immunity of the signalling and telecommunications apparatus.
  • d-SC is the central computer platform for electronic interlocking in signalling control systems.
  • d-SC can be used as central computer in ATO/ATP applications e.g., Zone Controller, platform screen door controller, etc.
  • d-SC can be used to as control unit for any kind of trackside assets such as level-crossings, signals, LEU, etc.
  • d-SC covers a part of the functions of the European ETCS as well as, e.g., CTCS, ATMS, PTC or Klub-U.
What are the safety configuration possibilities of duagon SAFE CONTROL (d-SC)?
  • d-SC consists of SIL 4 hardware and software components pre-certified according to EN 50126, EN 50128 and EN 50129, leading to a significant time and cost saving for the end application.
  • A single F75P (safe CPU board) or MH50C (safe d-SC controller) is already a 2oo2 unit according to EN 50129. 2oo2
  • The MH50C is designed to be fail-safe.
  • It supports double execution of software on two redundant processors.
  • It supports cross-checking between two redundant processors.
  • The safe communication with the I/O is based on safety protocols.
Why choose QNX as the safe standard operating system for duagon SAFE CONTROL (d-SC)?

The QNX real-time operating system is well established on an international level and offers a broad range of development tools.

The safe QNX Neutrino microkernel supports partitioning of the application. Partitioning saves cost and development time by:

  • Separating safe and non-safe functions on the same platform
  • Combining different SILs on one platform, e.g., SIL 2 for ATO and SIL 4 for ATP

In addition, the microkernel structure allows to separate application processes from protocol stacks and drivers.

QNX also supports message passing, allowing the application to cross processor boundaries.

d-SC can be used together with other safe operating systems, too:

  • d-SC is prepared to support GreenHills Integrity, Sysgo PikeOS and Wind River VxWorks 7 Safety Profile.
  • A demo BSP for PikeOS is available from Sysgo.
  • Integrity and VxWorks 7 Safety Profile will be made available on request.
What would be the operating system of choice for the non-safe parts of the application?
  • Linux – because it is open source, independent of the hardware platform, it offers a huge variety of freely available development tools as well as peripheral drivers and is used worldwide. 
Why does it make sense to separate the safe from the non-safe applications at all?
  • The combination of two operating systems – QNX and Linux – on one hardware platform – d-SC – limits the effort of application programming to the safe parts. This makes the software development and the subsequent certification easier and faster, resulting in significantly reduced overall cost.
  • Thanks to the abstraction of the periphery, the application can make use of the broad offering of peripheral Linux driver support.
Why does duagon SAFE CONTROL (d-SC) use EtherCAT for the communication?

EtherCAT is a real-time Ethernet standard based on open Ethernet that fulfills the conditions to make communication between d-SC components safe:

  • EtherCAT is deterministic, with cycle times ≤ 5 ms.
  • EtherCAT is able to operate without switches.
  • EtherCAT supports a ring topology which provides a continuity in service in the case of broken cable or the loss of power on one remote I/O.
  • The safety communication layer of EtherCAT (FSoE) establishes an end-to-end protection to the safe I/O board.
  • Any packet that leaves the safe domain is encapsulated in an envelope that is checked by the receiver of the packet (the safe I/O board). With this method, failures like packet duplication, loss, wrong sequence, corruption, wrong addressing etc. are covered.
  • FSoE covers the requirements of EN 50159.