Perhaps you could tell us when the last fatal accident was that could have been prevented by ATP but AWS/TPWS would have been/was ineffective?
I don’t know the answer to that. But I do know of some of the holes in AWS and TPWS.
Not all signals are fitted with TPWS. Indeed, there are as many if not significantly more signals that are not fitted with TPWS compared to those that are fitted. This is partly why TPWS costs less compared to a “standard” ATP system (where all main signals are fitted).
Hence if a train stops for any reason in a section that is protected by a signal that is not fitted with TPWS (such as the vast majority of signals on plain line), then on a non-ATP fitted line, or with a non-ATP fitted train, apart from the driver of the next train obeying the signal aspects, there is only AWS that can intervene (assuming that the driver does not acknowledge it and continues on).
Secondly, TPWS is only considered effective for speeds up to 75MPH. TPWS+ increases this to 100MPH (105MPH for some trains). For higher speed lines, “double blocking” (two consecutive red signals, both of which are fitted with TPWS) are one option.
TPWS+ and “double blocking” of course increases the system cost significantly.
TPWS+ requires not only extra loops and associated TPWS equipment, but also normally extra location cases/cupboards and often extra lineside cables to the location cases/cupboards where the signal control circuitry is located.
And all TPWS and TPWS+ installations require changes to the interlocking (GWML ATP for relay based interlocking does not need changes, as it can use APLITS instead).
GWML ATP of course can cope with all speeds used on the lines it’s fitted to, including 125MPH lines with no extra equipment other than the normal ATP installation.
TPWS can only spot supervise speed restrictions where it has been specifically provided. Again, just like TPWS+, extra equipment is required for each and every speed restriction.
Again, this is standard on ATP, with normally no extra equipment being needed (occasionally if there are multiple speed and/or junction speed limits, an extra beacon may be needed). Plus ATP provides continuous speed limit supervision, not just spot supervision.
And as hinted at above, GWML ATP does supervise junction speed limits.
I agree, and have to add that IMHO TPWS is one of the greatest single improvements in rail safety since interlocking of signalling.
Totally disagree. I would say that route relay interlocking is the one thing that brought a lot of technologies together to form a very safe system, that virtually eliminates incidents caused by signaller error (during normal operation) and which helped to reduce the accident rate substantially. Of course the difficulty is that you can’t prove a negative. Because route relay interlocking prevents accidents and incidents, it’s impossible to know how many have been prevented…
Apart from the limitations of TPWS that I listed above, the second problem with TPWS, is that the location case/cupboard/relay room equipment is not actually very reliable.
Hence there is an almost continuous stream of TPWS faults reported by signallers every week. Compared to the the location case/cupboard and trackside equipment for GWML ATP where faults are better described as occasional. Although I can’t comment on what the situation is with cab/train faults.
I'd put the track circuit above TPWS, personally. TPWS is great for what it is, but it does leave some important problems - it cannot cope with different speeds on diverging routes, it cannot adjust to different speed profiles, and it provides no advance warning before tripping the brakes. I also have it in the back of my mind that it's not fail-safe, as the grids require power to activate.
TPWS is a safety system but is not fail safe. There is no way for the equipment on the train to know where the TPWS loops are located, hence if for any reason, either or both of the loops do not transmit their fixed frequency, the on train equipment will not trigger the brakes or generate any error indication.
ATP is a considered a fail safe system (although it’s unlikely it would meet modern ideas on this). The reason being that the on-train equipment does know where the next ATP beacon is supposed to be located. If within a set tolerance, the on-train equipment does not receive a valid ATP message, the driver will be alerted via a five second brake application and an error code. The system will then go from full supervision to partial supervision.
In principle it ought to be possible to trigger different TPWS loops at the approach to a junction depending on the route set. This information is readily available in the interlocking but would need to be passed to the loops via a new control to the trackside. I assume this didn't happen at Peterborough because of the difficulty in modifying a 1970s-era relay interlocking, but does anyone know if it is done on newer signalling schemes elsewhere?
I don’t recall seeing this. There are AWS that become active for lower speed junctions on the approach to the junction.
I was involved in the early days of TPWS circa 1994, when some colleagues analysed the accident reports back to around 1968 to assess whether the accident would have been less severe, or would not have happened at all, if a TPWS-like system had been fitted at the time. This also allowed for the fact that the older rolling stock involved in many of these accidents would now be replaced by newer and more survivable designs. The conclusion was that TPWS would avert about 70% of the casualties that an ATP system would, which was noted with some skepticism by Uff-Cullen but borne out some years later in an analysis by Stanley Hall in Modern Railways magazine. TPWS+ has probably improved this further since then. Even then the predicted cost was near the maximum that the expected casualty reduction would justify, and the cost later increased due to measures such as proving the system operational.
But that ignores where we could have been today if ATP had been a requirement for all new rolling stock and all new signalling schemes (or relock schemes, or substantial alterations) from say 1990 onwards.
The lack of failsafe was known and agreed at the time by senior people in BR and Railtrack (who unlike some of their successors actually had both technical knowledge and influence within the organisation). To cause a SPAD-related accident it is necessary for the TPWS to fail but also for some other event to occur such as the driver misinterpreting the signal or braking too late. Both of these should be very unusual circumstances so the chance of both at the same time is infinitesimal - provided TPWS failures are promptly identified and remedied so they don't remain as latent faults. It's worth noting that a modern safety integrity analysis wouldn't consider AWS to be failsafe either.
and
It is not fail-safe, but it is protected somewhat by the fact that a power failure, or the majority of other fault conditions, will lead to the proving contacts for the TPWS circuitry not making. This will alert the signaller of the failure and prevent the signal in rear from clearing whilst the signal associated with the defective TPWS is at danger. It doesn't make it impossible for all the holes in the analogical Swiss cheese to line up, but it does add a few more layers to it.
The trouble is, with the number of TPWS failures that occur, I would say that the risk is not infinitesimal. Especially as the current climate in busy locations/lines is to keep trains running until a suitable line block can be arranged later during the night.
Okay, if the signal that is protecting the signal that has a failed TPWS also, itself is fitted with TPWS, then the risk may be considered reasonable. But not all are (sorry, I can’t provide any numbers).
Interesting, could you expand on why? I thought the magnet being suppressed with an electromagnet was a fail-safe design.
The big problem with AWS has and still is, the on train equipment. The track mounted equipment (and the control equipment) is considered fail-safe. If power is lost, or a “right side” failure occurs (where suppressed permanent magnets are used), the permanent magnet will still “generate” a magnetic field that the on-train equipment can detect.
Unfortunately, it appears that the on-train equipment is not fail safe. But you would have to get input from a train fitter or other suitable person who knows about the on-train equipment.
In terms of reliability, the track mounted equipment (and the control equipment) is generally reliable. The modern suppressed permanent magnets appear at the moment to be the most unreliable part (although they fail safe side).
The biggest problem with AWS failures, is that many drivers don’t report the problem. I’ve experienced failures (that cause the electro-magnet to not be energised, hence the driver gets a horn instead of a bell, i.e. code 2 fault) where one train reports the problem, but none of the other drivers reports the problem. Yet it’s obvious when the signal technician locates the problem, that it must have been faulty for hours, possibly days…
Now, before anyone piles in to make the case for TPWS, or to explain why ATP was not considered cost effective, may I point out that all this has already been discussed to death in another thread. I don’t think it’s worthwhile going over this again.
However, I am very disappointed that ERTMS/ETCS has not been brought in as originally intended to cover our high speed lines (where TPWS is not as effective). On the GWML, the existing ATP was supposed to have been replaced with ERTMS/ETCS by now according to one briefing that I received many, many years ago. And the GWML was apparently not first in the list…
So, from my point of view, what we should be discussing is why it’s taking so long for our railways to introduce ERTMS/ETCS?
I understand that level 1 or level 2 (mixed operation/overlay) is considered not to be value for money. But, again, if from say a couple of years after the Cambrian line was deemed fully operational, where could we have been today if it had been a requirement for all new rolling stock and all new signalling schemes (or relock schemes, or substantial alterations) to be fitted?