• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Following the Bedford incident, should TPWS - or something providing an equivalent level of protection - be fitted to all remaining unfitted signals?

HSTEd

Veteran Member
Joined
14 Jul 2011
Messages
20,265
Please explain.

If you mean that it can be much more easily interfaced to existing non ETCS compatible signalling systems, then I would agree. But that comes at a cost, of every signal needing its own local interface. In the UK, such retrofitting would these days come at a very high cost, high disruption, and probably long timescales, due to the constraints on trackside working.

Trackside work is expensive and disruptive, yes. But it does not require wholesale redesign of the enormous array of legacy signalling systems.
Many interlockings are SSI, true, but a great many are not, and the resources necessary to resignal them all simply do not exist.

It is most likely possible to design a single unit that can accept current-transformer connections from the aspects of a signal and which contains a balise controller and radio infill unit.
Attaching such a unit to every signal in the country would certainly be tedious, as would fixing the relevant balises, but resignalling requires a great deal more than simply installing new equipment on the trackside.

As such systems would be "transparent" to the signalling system unless faulty, they could conceptually be installed in whatever order is convenient.

By contrast, resignalling requires major design resources and a complex commissioning plan to move stepwise from the old to the new system without closing the railway for months.
 
Last edited:
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

bahnause

Member
Joined
30 Dec 2016
Messages
1,010
Location
bülach (switzerland)
The mainline operators need to look closely at ZBMS, which, according to this article, is at heart a level 1 LS system using many ETCS components and protocols. The main difference operationally is a lack of cab signals, suggesting it monitors silently in the background until an intervention, like TPWS.
Every system relying on outside signals should minimize any interaction between driver and the display. ETCS L1LS already falls short with its confusing, changing and generally unpredictable release speeds and the absolute abysmal way such data is presented (or often not presented...) to the driver.
This is good news. Hopefully lessons learned will also be noted by other national implementations.
Too little, too late... We've already ended up with an overpriced system "burdened" by far too many local variations. Wasn't the whole point to standardise?
Although is there much point installing an ATP system that, almost by definition, has to know what the speed limit and distance-to-stop is, and then not using it as a cab signalling interface?
There is a significant difference between a system that monitors conditions in the background while responsibility remains with the driver, and a system that is responsible for ensuring safety. We are talking SIL0 versus SIL4.
It is most likely possible to design a single unit that can accept current-transformer connections from the aspects of a signal and which contains a balise controller and radio infill unit.
Good luck with ensuring the radio infill unit addresses the correct train and there is enough time to establish a connection at all. This is on of the main tasks of the RBC and highly critical. We had incidents in ETCS L2 where a movement authority was sent to the wrong train. At least in one case the driver had to stop the train to avoid an incident.
 
Last edited:

MisterT

Member
Joined
12 Oct 2014
Messages
449
Location
The Netherlands
Is there any public report from that last incident you mentioned? Because I'd be really interested to learn how that happened, as every train needs its exact position to be known before a MA can be received. If a train truly receives an MA not intended for it, than something really went wrong.

I know from an incident in The Netherlands where, due to specific circumstances, the old MA was not removed when a locomotive changed directions and was able to pass an SMB without authorisation (and then being tripped because it updated the position), but that is something different than actually receiving a valid MA.
 

Annetts key

Established Member
Joined
13 Feb 2021
Messages
3,787
Location
West is best
A big problem in the UK is that doing work trackside is extremely constrained, you effectively need a full line possession to do most trackside work. Getting such possessions is difficult, and hence anything needing trackside work (such as to connect balises to trackside equipment cases) becomes very time consuming and expensive. Thankfully TPWS was rolled out before things became so restrictive, god knows how long the TPWS rollout would have taken and how much it would have cost under today's constraints.

I understand that ETCS L2 is being rolled out between Heathrow and Paddington relatively easily (and I accept that the relatively there is doing some heavy lifting!), because it requires relatively little trackside work. The interface between the ETCS and the conventional signalling is being done at interlocking level. That is the big advantage of L2. You don't need to do work trackside to retrofit it, other than just fit simple dumb positioning balises.

The big disadvantage is that you need an ETCS compatible interlocking to do it. Fortunately in the UK, our national standard interlocking SSI is compatible with ETCS (okay, you have to replace the actual interlocking cubicle with a more modern cubicle, but it runs the same data and talks to the same trackside equipment). And fortunately the line between Heathrow and Paddington was signalled with SSI.

I can well understand that countries and railways where the existing interlockings are not ETCS compatible have a much bigger problem. They will probably have to do a full resignalling to fit L2. And if it is also much easier for them to fit active trackside equipment, such as for L1, then the balance of cost effectiveness probably swings differently.

== Doublepost prevention - post automatically merged: ==


Please explain.

If you mean that it can be much more easily interfaced to existing non ETCS compatible signalling systems, then I would agree. But that comes at a cost, of every signal needing its own local interface. In the UK, such retrofitting would these days come at a very high cost, high disruption, and probably long timescales, due to the constraints on trackside working.
If an ETCS L1 system could use current transformers like the GWML ATP does to get the signalling data, and mounts balises on bars/mountings that attach to the rail clips (like TPWS loops), then once the new location cupboard containing the ETCS has been provided, it should be possible to install and power up the system in around two hours or less. Certainly far quicker than installing a TPWS installation.

Getting the new location cupboard to site and construction of the base for it should be similar to provision of any conventional location cupboard. In that getting the materials to site is best done in a T3 engineering occupation/block.
 

bahnause

Member
Joined
30 Dec 2016
Messages
1,010
Location
bülach (switzerland)
Is there any public report from that last incident you mentioned? Because I'd be really interested to learn how that happened, as every train needs its exact position to be known before a MA can be received. If a train truly receives an MA not intended for it, than something really went wrong.

I know from an incident in The Netherlands where, due to specific circumstances, the old MA was not removed when a locomotive changed directions and was able to pass an SMB without authorisation (and then being tripped because it updated the position), but that is something different than actually receiving a valid MA.
There is an english report available:

Safety incidents on ETCS Level 2 lines in Switzerland on April 16th and June 27th 2019
 

HSTEd

Veteran Member
Joined
14 Jul 2011
Messages
20,265
Good luck with ensuring the radio infill unit addresses the correct train and there is enough time to establish a connection at all.
The Radio Infill Unit doesn't really address anyone, the connection is made on the initiative of the train using information it obtained from a balise in the track. This would still be fundamentally an ETCS Level 1 system, not a level 2 one.

If the train can't establish a connection the train just proceeds with the aspect it obtained from the balise at the start of the signal section.
Unless the signaller puts the next signal back against them after they are in section there is no safety issue, and that is obviously a.... not-ordinary safe operation in any case.

If that happens you are still no worse than with a visual signal which the driver can no longer see (because they've passed it).

EDIT:

If we assume the balises are placed correctly, which is obviously checkable by commissioning testing, in order to get an incorrect connection you'd have to have an undetected misread of the 16 digit subscriber number as well as an undetected misread of the country code and RIU number (which just happen to escape the data checksum etc) and which just happen to correspond to another valid radio infill unit.
That seems unlikely.

Assuming the connection is made to the correct radio infill unit, that infill unit will only know the aspect of the correct signal, so its unlikely to pass the wrong information.
 
Last edited:

MarkyT

Established Member
Joined
20 May 2012
Messages
7,548
Location
Torbay
The Radio Infill Unit doesn't really address anyone, the connection is made on the initiative of the train using information it obtained from a balise in the track. This would still be fundamentally an ETCS Level 1 system, not a level 2 one.

If the train can't establish a connection the train just proceeds with the aspect it obtained from the balise at the start of the signal section.
Unless the signaller puts the next signal back against them after they are in section there is no safety issue, and that is obviously a.... not-ordinary safe operation in any case.

If that happens you are still no worse than with a visual signal which the driver can no longer see (because they've passed it).

EDIT:

If we assume the balises are placed correctly, which is obviously checkable by commissioning testing, in order to get an incorrect connection you'd have to have an undetected misread of the 16 digit subscriber number as well as an undetected misread of the country code and RIU number (which just happen to escape the data checksum etc) and which just happen to correspond to another valid radio infill unit.
That seems unlikely.

Assuming the connection is made to the correct radio infill unit, that infill unit will only know the aspect of the correct signal, so its unlikely to pass the wrong information.
As I understand, if a train fails to receive valid infill messages from an expected radio unit or track loop, the onboard equipment reverts to using the release speed method on approach to the next signal. That speed must be low enough for the trainstop response at the signal balise to arrest the train before the end of the overlap. It's incorrect to say radio infill does away with release speed. It will override it if working correctly, but release speed remains as a backup.
 

HSTEd

Veteran Member
Joined
14 Jul 2011
Messages
20,265
As I understand, if a train fails to receive valid infill messages from an expected radio unit or track loop, the onboard equipment reverts to using the release speed method on approach to the next signal. That speed must be low enough for the trainstop response at the signal balise to arrest the train before the end of the overlap. It's incorrect to say radio infill does away with release speed. It will override it if working correctly, but release speed remains as a backup.
My understanding is that the movement authority encoded on the previous balise would be followed in the absence of a connection to the RIU.

So the train would only come to a halt (or release speed) before the overlap of the next signal if it was already planning to stop there. In other words if the previous balise was showing the equivalent to single yellow.
 

MisterT

Member
Joined
12 Oct 2014
Messages
449
Location
The Netherlands
Thanks, but that doesn't read like an issue in ETCS itself or anything relevant to the discussion.
If I understand correctly, the position of the train was incorrect due to a configuration error on board the train. So the RBC responded correctly based on the position received, which is also explicitly stated in the report.
So the lesson learned is: make sure the on-board systems are configured correctly before the train is released for service.
The additional advised sanity check for position is obviously a nice addition on top of that, but it shouldn't really be necessary and is truly a backup in case humans fail.
 
Last edited:

bahnause

Member
Joined
30 Dec 2016
Messages
1,010
Location
bülach (switzerland)
Thanks, but that doesn't read like an issue in ETCS itself. If I understand correctly, the position of the train was incorrect due to a configuration error on board the train. So the RBC responded correctly based on the position received, which is also explicitly stated in the report.
So the lesson learned is: make sure the on-board systems are configured correctly before the train is released for service.
The result is the same: it is a problem that shifts the risk from the train driver to the maintenance department. Inaccurate odometry repeatedly leads to similar problems, even when the settings on the trains are correct.
As a result of the track-side monitoring of trains on ETCS Level 2 lines, which began following the incidents in Flüelen and Vevey, it was found that several incidents had occurred involving trains fitted with Altstom ETCS in accordance with SRS 2.3.0d, in which the actual front of the train was at times either ahead of or behind the odometry confidence interval.
 

MisterT

Member
Joined
12 Oct 2014
Messages
449
Location
The Netherlands
Why do you think the risk would lie with the driver in the first place?
They are just the operators of the train. They don't configure the on-board systems or perform maintenance.

I don't know if it's any different in Switzerland, but when we have a technical issue with a safety system, regardless whether it's a legacy system or ETCS, it's never our problem in the Netherlands. Once we notice it, the only thing we can do is take measures to make sure the train arrives safely at the next station and have the train taken out of service for repairs/reconfiguration. Nothing more.
 

bahnause

Member
Joined
30 Dec 2016
Messages
1,010
Location
bülach (switzerland)
What I meant to say was: whilst with external signalling there is a risk that the train driver might make a mistake and cause an SPAD, with ETCS L2 there is a risk that an odometry error might cause an SPAD. This can be caused by human error (eg maintenance) or by technical malfunctions and may or may not be detectable by the driver. The frequently expressed assumption that a SPAD is not possible under ETCS is not entirely accurate.
 

MisterT

Member
Joined
12 Oct 2014
Messages
449
Location
The Netherlands
Of course a SPAD is possible with ETCS. It's just less likely to occur compared with most lagacy systems, and if it occurs, the safety margins should prevent most dire accidents from happening, but even that is obviously never a given.

An accident like at Bedford, where this topic started with, would very likely have been prevented had ERTMS been used.

Also: with external signalling, it is also perfectly possible to have technical issues with misconfigured on-board legacy safety systems and have a SPAD because of it. That doesn't change with ERTMS. Just the way the information is received by the driver is different.
 

bahnause

Member
Joined
30 Dec 2016
Messages
1,010
Location
bülach (switzerland)
Also: with external signalling, it is also perfectly possible to have technical issues with misconfigured on-board legacy safety systems and have a SPAD because of it. That doesn't change with ERTMS. Just the way the information is received by the driver is different.
However, there is a significant difference between the two cases. In the first case, a dangerous situation would be caused by two errors: one by the driver and one by the safety system, which was designed only to meet SIL 0 standards for background monitoring. The likelihood of these circumstances occurring simultaneously is very low.

In the case of ETCS Level 2, however, we're talking about a SIL 4 system, in which such scenarios should be ruled out from the outset. In Level 2, not only is a SPAD not prevented, but a movement authority is actively granted to the train.
 

MisterT

Member
Joined
12 Oct 2014
Messages
449
Location
The Netherlands
However, there is a significant difference between the two cases. In the first case, a dangerous situation would be caused by two errors: one by the driver and one by the safety system, which was designed only to meet SIL 0 standards for background monitoring. The likelihood of these circumstances occurring simultaneously is very low.
I wouldn't say that driver error is necessary. I've had it happen that a unit was just fresh out of maintenance, and they swapped the wheels on the bogie with the odometer (see where this is going?).
Both the speedometer and the safety systems relied on that odometer to be calibrated correctly, which hadn't happen.
When I was cruising at line speed, I was actually driving around 20 km/h faster than was displayed on both my speedometer and the legacy safety system. In the end, an incident didn't occur because the way the train behaved felt off and I went to investigate the issue, but it could well have been the cause of someone driving a bit less defensive and not noticing the increased speed, and a SPAD could have occurred because of it. It wouldn't be a driver error in that case, simply because the driver didn't have the expected braking performance.
So, very low, yes, but not impossible.

In the case of ETCS Level 2, however, we're talking about a SIL 4 system, in which such scenarios should be ruled out from the outset. In Level 2, not only is a SPAD not prevented, but a movement authority is actively granted to the train.
See the case mentioned above. I don't see the difference between the misconfigured odometer on a legacy system or on an ETCS system. In both cases, the systems behaved exactly like they should have, given the information that was known.
 

bahnause

Member
Joined
30 Dec 2016
Messages
1,010
Location
bülach (switzerland)
See the case mentioned above. I don't see the difference between the misconfigured odometer on a legacy system or on an ETCS system. In both cases, the systems behaved exactly like they should have, given the information that was known.
The misconfigured odometer was just the tip of the iceberg. It turned out there where other such cases with all the systems in spec no one really noticesd or paid attention to.
I wouldn't say that driver error is necessary. I've had it happen that a unit was just fresh out of maintenance, and they swapped the wheels on the bogie with the odometer (see where this is going?).
Having the speedometer and the safety system in SIL 0 using the same reference speed is bad design. I don't thinks our specs allow for such a configuration.
 

MisterT

Member
Joined
12 Oct 2014
Messages
449
Location
The Netherlands
The misconfigured odometer was just the tip of the iceberg. It turned out there where other such cases with all the systems in spec no one really noticesd or paid attention to.
While we're going really off topic here, that sounds like a systematic issue in Switzerland then, which might need a cultural shift in human behaviour then, in the way those safety systems are being maintained.
An incident might happen, but when it happens regularly, it seems rooted in something different. Not enough time to perform all the maintenance? Too much pressure on the people to hit performance targets?

Having the speedometer and the safety system in SIL 0 using the same reference speed is bad design. I don't thinks our specs allow for such a configuration.
That's the thing with old trains. Designs never meet the current safety standards :)
 

bahnause

Member
Joined
30 Dec 2016
Messages
1,010
Location
bülach (switzerland)
While we're going really off topic here, that sounds like a systematic issue in Switzerland then, which might need a cultural shift in human behaviour then, in the way those safety systems are being maintained.
An incident might happen, but when it happens regularly, it seems rooted in something different. Not enough time to perform all the maintenance? Too much pressure on the people to hit performance targets?
:)
This has nothing to do with human behavior or a lack of maintenance. Despite its redundancy, the ETCS odometry system cannot cope with real-world conditions when they are poor. The radar systems, speed sensors, and acceleration sensors all struggle significantly when poor track conditions and snow occur simultaneously. Often, snow alone is enough. This is particularly evident with heavy trains that are operated at the adhesion limit for extended periods.
 

MisterT

Member
Joined
12 Oct 2014
Messages
449
Location
The Netherlands
Sounds more like there aren't enough balises to recalibrate the position if that's happening so often.
I've been driving with ETCS (mainly level 2, and a little bit of level 1) almost daily for more than a decade now, and I don't think I've ever had real issues with the odometers, even in snow and low adhesion conditions.
Yes, a warning might pop-up that the odometers might be out of sync because of wheelslip or a radar error, but it has never led to issues and has always corrected itself, thanks to the position recalibration.

Edit: in addition: in the worst case, the train should be automatically stopped when the position is unreliable for too long. It hasn't happened to me personally yet, but I know from colleagues that it has happened to them in a few really rare cases. It is really weird if something like that doesn't happen in Switzerland.
 
Last edited:

bahnause

Member
Joined
30 Dec 2016
Messages
1,010
Location
bülach (switzerland)
Sounds more like there aren't enough balises to recalibrate the position if that's happening so often.
I've been driving with ETCS (mainly level 2, and a little bit of level 1) almost daily for more than a decade now, and I don't think I've ever had real issues with the odometers, even in snow and low adhesion conditions.
Yes, a warning might pop-up that the odometers might be out of sync because of wheelslip or a radar error, but it has never led to issues and has always corrected itself, thanks to the position recalibration.
The ETCS specifications clearly stipulate:
  1. Where balises can and must be installed.
  2. The required accuracy of the odometry.
A problem with point two cannot be resolved by making an (unapproved) adjustment to point one.

Regarding the most severe cases: The regulatory authority and the operators concluded that, from the perspective of the overall system, it is unacceptable that a data entry error on the part of the rolling stock could lead to such a risk in the overall system and does not meet the requirements for a safety-critical system. There were quite a few change requests regarding these cases, that might have found their way into the ETCS specs by now.
 

MisterT

Member
Joined
12 Oct 2014
Messages
449
Location
The Netherlands
You seem to keep changing your story, which doesn't really make for a great discussion, so I will refrain from posting here after this comment.

Yes, it's a safety risk when people are entering ETCS data incorrectly, which is also why it's really important that people are trained to input all data correctly at every moment.
I don't know if it's in the official specs, but at least with our trains, all ETCS implementations with Baseline 3 R1/ SRS 3.4.0 and higher set a traction block when the entered value is different from the detected value and must be manually overridden if necessary (when towing a dead MU for example).
Obviously this only works for fixed-length units (or combination of units), and I don't know how this could be solved for loco hauled trains. Maybe the new automatic coupler together with devices for train integrity could solve that issue, but that seems to be in the more distant future.
 

Belperpete

Established Member
Joined
17 Aug 2018
Messages
3,584
Trackside work is expensive and disruptive, yes. But it does not require wholesale redesign of the enormous array of legacy signalling systems.
Many interlockings are SSI, true, but a great many are not, and the resources necessary to resignal them all simply do not exist.
Agreed that a full resignalling is expensive and also requires considerable work trackside. However, a relock doesn't. This is when only the interlocking is replaced, and the trackside equipment kept as-is. A number of interlockings have been replaced by SSI in this way, because of wire degradation in the interlocking, but the trackside equipment is still okay. This approach means that the only work required trackside is at the central interlocking, not at every signal location.

Such schemes have suffered in the past through being designed as one-offs. However, with ETCS rollout requiring a significant number of interlockings replaced, this should allow standard designs to be developed. In addition, using the latest SSI-compatible interlockings and their associated object controllers should take up considerably less space than traditional SSI and trackside modules.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,548
Location
Torbay
Agreed that a full resignalling is expensive and also requires considerable work trackside. However, a relock doesn't. This is when only the interlocking is replaced, and the trackside equipment kept as-is. A number of interlockings have been replaced by SSI in this way, because of wire degradation in the interlocking, but the trackside equipment is still okay. This approach means that the only work required trackside is at the central interlocking, not at every signal location.

Such schemes have suffered in the past through being designed as one-offs. However, with ETCS rollout requiring a significant number of interlockings replaced, this should allow standard designs to be developed. In addition, using the latest SSI-compatible interlockings and their associated object controllers should take up considerably less space than traditional SSI and trackside modules.
Yes the space required for TFMs could be a challenge.
 

80073

Member
Joined
1 Oct 2022
Messages
25
Location
Chelmsford
The Telegraph has reported the following:


(Apologies if this is the wrong thread.)


Today's Telegraph has a correction:
An article "Chiefs blocked extra rail signals near crash" (June, 29) suggested that Network Rail had rejected the Rail Safety Standards Board (RSSB) recommendation to install extra signals at key locations on the Midland Main Line and that this decision "raises questions about whether the crash [in Bedford] could have been avoided". The article was inaccurate and has been withdrawn. We apologise for these errors.

What a surprise!
 

HSTEd

Veteran Member
Joined
14 Jul 2011
Messages
20,265
Agreed that a full resignalling is expensive and also requires considerable work trackside. However, a relock doesn't. This is when only the interlocking is replaced, and the trackside equipment kept as-is. A number of interlockings have been replaced by SSI in this way, because of wire degradation in the interlocking, but the trackside equipment is still okay. This approach means that the only work required trackside is at the central interlocking, not at every signal location.

Such schemes have suffered in the past through being designed as one-offs. However, with ETCS rollout requiring a significant number of interlockings replaced, this should allow standard designs to be developed. In addition, using the latest SSI-compatible interlockings and their associated object controllers should take up considerably less space than traditional SSI and trackside modules.
Does that really reduce the amount of critical path-signalling work though?

Are relay interlocking wiring diagrams or control tables kept in a format allowing rapid and accurate translation to SSI interlocking data?
If not, you still need a huge amount of highly specialised labour to do the translation work, or to redevelop the interlocking from scratch given the constraints of reusing existing trackside equipment.

It might be somewhat cheaper, but I am sceptical it is much more amenable to rapid roll out than resignalling is.

Is the ability to do trackside work truly the limit that is slowing down resignalling, or is the other specialised knowledge and design work?

A trackside ETCS Level 1 solution can, naively, be deployed by doing the same thing over and over - bolt the lineside equipment unit (LEU)/radio infill unit to the signal mast, put current transformers in the signal lamp feeds and bolt the balise to the track. The bulk of the work is probably ensuring that each signal has access to a 110V supply for the LEU, although you might be able to parasitically draw off lamp feeds still designed for incandescent lamps.

I know it won't be quite that simple in practice, but to me it still seems much more tractable than trying to rapidly reverse engineer SSI data from decades old design documentation. Are lost documents ever a problem on such projects?
 
Last edited:

Annetts key

Established Member
Joined
13 Feb 2021
Messages
3,787
Location
West is best
Does that really reduce the amount of critical path-signalling work though?

Are relay interlocking wiring diagrams kept in a format allowing rapid and accurate translation to SSI interlocking data?
If not, you still need a huge amount of highly specialised labour to do the translation work, or to redevelop the interlocking from scratch given the constraints of reusing existing trackside equipment.

It might be somewhat cheaper, but I am skeptical it is much more amenable to rapid roll out than resignalling is.

A trackside ETCS Level 1 solution can, naively, be deployed by doing the same thing over and over - bolt the lineside equipment unit (LEU)/radio infill unit to the signal mast, put current transformers in the signal lamp feeds and bolt the balise to the track. The bulk of the work is probably ensuring that each signal has access to a 110V supply for the LEU, although you might be able to parasitically draw off lamp feeds still designed for incandescent lamps.

I know it won't be quite that simple in practice, but still seems much more tractable than trying to rapidly reverse engineer SSI data from ancient wiring diagrams.
In theory, the relay interlocking is supposed to have been designed using the control tables (a detailed table listing all the conditions that apply for each function, be it the signal aspect controls, the point operating controls, the route calling / locking / approach locking controls etc.) and standard principles. However, in practice, due to poor record keeping in the past, the control tables and the wiring diagrams may not accurately reflect the actual wiring.

So before any "relock" work can start, a full correlation should be done (this means comparing the actual wiring to the diagrams to confirm that the diagrams actually show how the existing interlocking is wired).

This itself is a lot of work, and if the existing wiring is in poor condition, the operation has to be extra careful that the degraded insulation is not disturbed and thus further damaged.

And the existing interlocking design may not include all current interlocking design principles or may have design issues that were not picked up when originally designed, installed and tested. As an example, apparently on one line at Bristol Temple Meads, one part of one of the signal routes did not include all of the required opposing locking... Had been like that since the original commissioning in 1970.

Incidentally, the term "relock" is itself a bit of a vague term. If replacing a route relay interlocking, are you just replacing the actual interlocking in a relay room but not the rest of the circuitry that exists in the location cupboards and the corresponding multicore lineside cables or are you replacing the location cupboards and the corresponding multicore lineside cables with new location cupboards and data links, but retaining the existing signals, point operating equipment and track circuits?

If the latter, are you renewing the tail cables to said signals, point operating equipment and track circuits?
 

Belperpete

Established Member
Joined
17 Aug 2018
Messages
3,584
A relock is generally taken to mean just replacing the interlocking, retaining all the external cabling, location cases, etc. When you replace the location cases and associated cabling as well, that is usually called a resignalling, even if you retain some of the existing point machines and signals. And a recontrol is when you transfer control of an existing interlocking to a new control centre.

== Doublepost prevention - post automatically merged: ==

Does that really reduce the amount of critical path-signalling work though?

Are relay interlocking wiring diagrams or control tables kept in a format allowing rapid and accurate translation to SSI interlocking data?
If not, you still need a huge amount of highly specialised labour to do the translation work, or to redevelop the interlocking from scratch given the constraints of reusing existing trackside equipment.

It might be somewhat cheaper, but I am sceptical it is much more amenable to rapid roll out than resignalling is.

Is the ability to do trackside work truly the limit that is slowing down resignalling, or is the other specialised knowledge and design work?

A trackside ETCS Level 1 solution can, naively, be deployed by doing the same thing over and over - bolt the lineside equipment unit (LEU)/radio infill unit to the signal mast, put current transformers in the signal lamp feeds and bolt the balise to the track. The bulk of the work is probably ensuring that each signal has access to a 110V supply for the LEU, although you might be able to parasitically draw off lamp feeds still designed for incandescent lamps.

I know it won't be quite that simple in practice, but to me it still seems much more tractable than trying to rapidly reverse engineer SSI data from decades old design documentation. Are lost documents ever a problem on such projects?
However you do it, an ETCS rollout is going to require a significant increase in S&T resource. It depends on whether you want it done by a small team of mainly office based staff, or a large army of trackside staff.

One person can work fairly efficiently on their own in an office. Whereas I understand that trackside workers are only something like 20% efficient, by the time you take into account travelling time, time to set up protection, not being allowed to work alone, production of site risk assesment and method of works, having to work unsocial hours in challenging weather conditions, etc etc.

Agreed that a relock would require the interlocking to be correlated. But that is done under cover, in one usually reasonably accessible location. Whereas trackside modifications would require every affected location case to be correlated, working out in the open, often far from the nearest access point.

SSI-type data these days is largely produced by automatic data preparation tools. There are standard data constructs for relocks, all you would need do is set up the auto data prep to generate relock-type data. You certainly wouldn't start by trying to reverse engineer the existing or attempting to convert the existing interlocking circuits into data. All you would need an experienced engineer to do would be to review the existing interlocking for any quirks. I had the job of reviewing existing SSI data for several relocks, and it didn't take long, and was done in parallel with data design.

The big advantage of relocks is that they use proven, type-approved equipment, that any of the major signalling suppliers could provide off-the-shelf. Whereas developing a novel non-standard UK-specific trackside system as being discussed here, how long would that take before you even got it to trial stage? At least with TPWS, they started with a proven product.

And if it requires a local radio link to the trains, would that require all the stock that had already been ETCS fitted to go back in for retrofit?

And having spent billions of pounds and a decade or more rolling it out, what would you have got? You still wouldn't have a system that protects against over speed accidents, for example. It would be a hard sell to justify the investment. I can understand why continental railways might look at such systems, as they are under political pressure to roll out ETCS for compatability. But that pressure doesn't exist in the UK. Here any system is going to have to be justified by the safety improvements and operational benefits it offers. As far as I can see, such a level 1 system offers only limited additional safety and no operational benefits whatsoever.
 
Last edited:

HSTEd

Veteran Member
Joined
14 Jul 2011
Messages
20,265
However you do it, an ETCS rollout is going to require a significant increase in S&T resource. It depends on whether you want it done by a small team of mainly office based staff, or a large army of trackside staff.

One person can work fairly efficiently on their own in an office. Whereas I understand that trackside workers are only something like 20% efficient, by the time you take into account travelling time, time to set up protection, not being allowed to work alone, production of site risk assesment and method of works, having to work unsocial hours in challenging weather conditions, etc etc.

Agreed that a relock would require the interlocking to be correlated. But that is done under cover, in one usually reasonably accessible location. Whereas trackside modifications would require every affected location case to be correlated, working out in the open, often far from the nearest access point.

Do you have to go near the location boxes though?
Can't you just trace the conductors from the signal head and place the current transformer there?

One could conceive of a single integrated unit that could be affixed to the signal post that is placed in the final loop to the lamps and contains all necessary equipment to control a balise, which is connected by a short length of suitable cable to the track adjacent to the signal.
The Lineside equipment doesn't really care why the signal is yellow or green or why that diverging route indicator is set, it only cares that it is. It then serves up the correct speed profile and stopping distance to the train, for example: "60kph for 800m, then 2000m at 100kph max before stop".


The big advantage of relocks is that they use proven, type-approved equipment, that any of the major signalling suppliers could provide off-the-shelf. Whereas developing a novel non-standard UK-specific trackside system as being discussed here, how long would that take before you even got it to trial stage? At least with TPWS, they started with a proven product.
Well ETCS transparent balise controllers that interpret existing circuits using current transformers are approved products in Europe. Siemens in particular makes a whole range of them under the 'Trainguard Trackside' range. They even come with things like integrated flashing detection on the lamp circuits.

Thousands have been deployed in Switzerland and elsewhere.
And if it requires a local radio link to the trains, would that require all the stock that had already been ETCS fitted to go back in for retrofit?
Conceptually no, since this is already integrated into the ETCS specification.
Instead of the training having a "phone" call to the radio block controller, it dials the number of the next radio interface unit provided it to be a balise on the track, possibly the same balise group that provided the previous signal aspect.
That's the magic of GSM-R after all, any end point can connect to any endpoint in the numbering plan.

Of course knowing the mess that is the ETCS rollout, some trains may require software modifications because they didn't bother to implement that part of the specification for whatever reason.
And having spent billions of pounds and a decade or more rolling it out, what would you have got? You still wouldn't have a system that protects against over speed accidents, for example. As far as I can see, such a level 1 system offers only limited additional safety and no operational benefits whatsoever.
Why wouldn't it?
If the signal is set for a restrictive aspect or for a slow diverging route, the ETCS equipment knows it and can impose the relevant speed restriction, and impose it continuously until the actual divergence point.

ETCS Level 1 can be implemented, using semi continuous infill like radio infill units or euroloops, in a manner allowing the elimination of trackside signals, should that be desired.

EDIT:

From the European Commission Mobility and Transport website on ETCS levels:
Level 1 involves continuous supervision of train movement (i.e. the onboard computer is continuously supervising the maximum permitted speed and calculating the braking curve to the location to which the train is permitted to proceed (the end of movement authority) while non-continuous communication occurs between train and trackside, generally through Eurobalises.


Lineside signals are necessary in level 1 applications, except if a semi-continuous infill is provided (semi-continuous infill denotes the transmission of infrastructure information from the Euroloop or the Radio infill unit to the train, hereby providing the train with information on the train’s future movement. See the Radio Infill Unit and Euroloop sections below for more information). Train detection and train integrity checks (i.e. the train is complete and has not been accidentally split) are performed by the trackside equipment beyond the scope of ERTMS.

EDIT #2: cleaned up some grammar.
EDiT #3:

Do signal heads contain 2BA or similar link strips? I've found some drawings that suggest they do from at least one manufacturer but obviously that's not conclusive.

The current transformers used for GWML ATP connected across them as links and seem very small (set the picture in this thread by @Annetts key ). Is there anything to suggest they would or would not fit inside the signal head itself?
If so, we could potentially avoid touching any of the existing signal wiring at all.
 
Last edited:

Annetts key

Established Member
Joined
13 Feb 2021
Messages
3,787
Location
West is best
Do you have to go near the location boxes though?
Can't you just trace the conductors from the signal head and place the current transformer there?

One could conceive of a single integrated unit that could be affixed to the signal post that is placed in the final loop to the lamps and contains all necessary equipment to control a balise, which is connected by a short length of suitable cable to the track adjacent to the signal.
The Lineside equipment doesn't really care why the signal is yellow or green or why that diverging route indicator is set, it only cares that it is. It then serves up the correct speed profile and stopping distance to the train, for example: "60kph for 800m, then 2000m at 100kph max before stop".

Do signal heads contain 2BA or similar link strips? I've found some drawings that suggest they do from at least one manufacturer but obviously that's not conclusive.

The current transformers used for GWML ATP connected across them as links and seem very small (set the picture in this thread by @Annetts key ). Is there anything to suggest they would or would not fit inside the signal head itself?
If so, we could potentially avoid touching any of the existing signal wiring at all.

No, not all signal heads have 2BA terminals and even some that do, do not have space for current transformers or additional cables.

The cable from the location cupboard to the signal head is a multicore cable. Typically a 7 core, a 10 core or a 12 core cable. Signals that have junction or route indicators may have additional multicore cables, as will position light shunting/calling on signals.

Hence the individual wires are not accessible without cutting into the cable. To connect either a current transformer or make an electrical connection, you need access to the relevant individual wires.

Some signal structures have dis. boxes on them which act as distribution units with one (or more) large multicore cables coming in and multiple multicore cables going out to the actual signal heads. And no, these dis. boxes may have 2BA terminals, but likely won’t have enough room for current transformers.

Furthermore, not all signals are wired up the same way - the various regions had variations and the more modern signals now often have individual returns (or "neutral) for each aspect (past practice was a common return for each signal head, so a three aspect reg/yellow/green head would had a feed (or line/live) for the red, a feed for the yellow, a feed for the green and one common return for all three.

And just to make it even more complex, some colour light signals in mechanical (or former) areas use 12V DC heads, not 110V AC heads...

The current transformers used for the GWML ATP were fitted in the existing location cupboard, on to the existing 2BA (or in some cases, 0BA) link strips, which in most cases were Western Region large size or BRB style cupboards, which had enough room for them.

In addition, a cable termination (which takes up not too much space, as it's more like a telecommunications type cable and termination using terminals mounted on a standard DIN rail) is required for the cable that goes to the ATP encoder in it's own enclosure.

Many existing Western Region large size cupboards had plenty of room.

There are now additional problems, as the railway has moved away from using 2BA terminals because they have exposed live parts that can be touched. Now WAGO or other DIN rail modern terminals are used (for staff safety reasons).

Having said all that, the easiest way to add ETCS level 1 is still by using current transformers fitted in the existing location cupboards. It's just that some new wiring would be needed. By only adding a new (longer) wire that replaces an existing wire (the new longer wire goes via a current transformer), it makes the testing of the existing signal far quicker and easier than any other alteration.

And this work can be done by Network Rail's own signalling maintenance staff (a small amount of training would be required). Don't need expensive and hard to find installers and principle testers.
 

Top