• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Recent signalling failures.

Status
Not open for further replies.

MarkyT

Established Member
Joined
20 May 2012
Messages
7,553
Location
Torbay
With encrypted connections and proper identification of the sender and recipient, this is quite easy to implement securely. ETCS L2 also uses encrypted over-the-air connections.
...and data error detection/correction/integrity checking (basically you assume the links are not 100% reliable and design the overall system/protocols to deal with that). All everyday stuff in modern electronic communication links, be they physical or 'over the ether'.
I think making the messsaging system secure is not the problem with the best techniques available today. The challenge is making it resistant to bombardment with torrents of junk messages in a DoS attack. Non of those messages would be able to change anything in the field unsafely, but if the object controller processors were so busy verifying and rejecting incoming messages they hadn't got time to execute the legitimate system commands, they'd have no option but to default to a failsafe state where everything goes red.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

bahnause

Member
Joined
30 Dec 2016
Messages
1,010
Location
bülach (switzerland)
I think making the messsaging system secure is not the problem with the best techniques available today. The challenge is making it resistant to bombardment with torrents of junk messages in a DoS attack. Non of those messages would be able to change anything in the field unsafely, but if the object controller processors were so busy verifying and rejecting incoming messages they hadn't got time to execute the legitimate system commands, they'd have no option but to default to a failsafe state where everything goes red.
There have already been more than enough cases of signal cables being damaged, causing disruption to operations, whether maliciously or otherwise. I wouldn't necessarily assume that transmitting data over the air would perform worse.
 

saismee

Established Member
Joined
20 Oct 2023
Messages
1,702
Location
UK
There have already been more than enough cases of signal cables being damaged, causing disruption to operations, whether maliciously or otherwise. I wouldn't necessarily assume that transmitting data over the air would perform worse.
You can't send enough power to operate points machines or signals over the air, so it's certainly not an option.
 

saismee

Established Member
Joined
20 Oct 2023
Messages
1,702
Location
UK
And that's why I wrote "transmitting data".
You said that you wouldn't assume that data over the air would perform worse but it introduces a new attack vector while still leaving valuable cabling for power. I was also generally replying to the whole chain of quotes, not just your exact message, I should've made that clearer.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,553
Location
Torbay
You said that you wouldn't assume that data over the air would perform worse but it introduces a new attack vector while still leaving valuable cabling for power. I was also generally replying to the whole chain of quotes, not just your exact message, I should've made that clearer.
There can be diverse routing for signalling power as well as data, usually in troughs either side of the railway, fed in from both ends of a section. Even if thieves took lengths from both sides, only equipment in the immediate area cables were removed should be isolated, with any other equipment the wrong side of the break from its feed end reconnected to the feed from the opposite direction. That became common in UK SSI schemes from the late 80s. Initially, a tech may have had to visit several sites in the field to reconfigure around a fault while it was fixed, but later projects introduced SCADA systems to monitor and switch supplies. Further resilience can be purchased by installing backup batteries at every object controller, with sufficient power to last an operational day. Points remain a challenge, particularly large busy junctions with many switch movements. In relay days, junction interlockings often had a point battery, as much to deal with the dramatic current peaks in motoring multiple heavy switches simultaneously as for backup. The SSI era moved away from that, preferring a supply line and source specified for all possible simultaneous field loads. Point batteries and other distributed backup sources might be reintroduced more widely as part of a resilience drive.
 
Last edited:

Annetts key

Established Member
Joined
13 Feb 2021
Messages
3,794
Location
West is best
On a more practical note, why would Network Rail use the internet/WWW when they have their own telecom network? Where there are railway lines that don't have a suitable telecom network, Network Rail currently uses a "private link" via the BT company telecoms network.

== Doublepost prevention - post automatically merged: ==

There can be diverse routing for signalling power as well as data, usually in troughs either side of the railway, fed in from both ends of a section. Even if thieves took lengths from both sides, only equipment in the immediate area cables were removed should be isolated, with any other equipment the wrong side of the break from its feed end reconnected to the feed from the opposite direction. That became common in UK SSI schemes from the late 80s. Initially, a tech may have had to visit several sites in the field to reconfigure around a fault while it was fixed, but later projects introduced SCADA systems to monitor and switch supplies. Further resilience can be purchased by installing backup batteries at every object controller, with sufficient power to last an operational day. Points remain a particular challenge, particularly large busy junctions with many switch movements. In relay days, junction interlockings often had a point battery, as much to deal with the dramatic current peaks in motoring multiple heavy switches simultaneously as for backup. The SSI era moved away from that, preferring a supply line and source specified for all possible simultaneous field loads. Point batteries and other distributed backup sources might be reintroduced more widely as part of a resilience drive.
What is possible and what the railway is prepared to pay for are rather different things. On parts of the area where I worked, the 650V distribution system was completely renewed with provision for automatic power switching. But said equipment was not fitted. And as far as I know, has not been fitted. Further, 650V cables only run along one side of the track.

Meanwhile, elsewhere, for a signalling scheme, the 650V feeds to the signal location cupboards have no provision for this automatic switching equipment...

Where conventional point machines or HPSS/ HPSA are used on a SSI scheme, or sometimes where there are multiple RCPLs in one location, such at at a junction, a point battery is still used.
 
Last edited:

MarkyT

Established Member
Joined
20 May 2012
Messages
7,553
Location
Torbay
On a more practical note, why would Network Rail use the internet/WWW when they have their own telecom network? Where there are railway lines that don't have a suitable telecom network, Network Rail currently uses a "private link" via the BT company telecoms network.
BR used audio frequency reed equipment for linking token instruments over BT private wires on the Central Wales Line. Fairly expensive, I recall, as there were many individual links, but apparently still cost-effective versus new dedicated cabling along the trackside for the whole ~90 mile route. One section has been piloting the new Park Signalling digital token machine that works over an IP link, potentially over public networks or using the NR FTN. Note the device still uses conventional physical key tokens!
 

Harpo

Established Member
Joined
21 Aug 2024
Messages
3,780
Location
Newport
One section has been piloting the new Park Signalling digital token machine that works over an IP link, potentially over public networks or using the NR FTN. Note the device still uses conventional physical key tokens!
Dai Bloc for Wales surely?
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,553
Location
Torbay
What is possible and what the railway is prepared to pay for are rather different things. On parts of the area where I worked, the 650V distribution system was completely renewed with provision for automatic power switching. But said equipment was not fitted. And as far as I know, has not been fitted. Further, 650V cables only run along one side of the track.

Meanwhile, elsewhere, for a signalling scheme, the 650V feeds to the signal location cupboards have no provision for this automatic switching equipment...
It's also not really practical to retrofit in 40+ year old systems with cabinets in poor condition with insufficient space, etc.
Where conventional point machines or HPSS/ HPSA are used on a SSI scheme, or sometimes where there are multiple RCPLs in one location, such at at a junction, a point battery is still used.
I think reality faced by application engineers caused a backtrack from the original ideals. Without point batteries, some feeders to further flung junctions would have needed much larger and more expensive conductors to preserve voltage levels for peak loads present only for a few seconds every 30 minutes or so on a lightly used line.

When I started in the mid-80s, everything was going to be clamplocks in the future! That's why the SSI points module was designed to only directly drive that style of actuator from its outputs. A relay interface and some custom logic in the data was required for a conventional point machine. The clamp lock proved unreliable in its original form, though modern bearer-enclosed versions are much better I understand, not least because all the cables and hoses are much better protected. Many area engineers, particularly on the Southern Region, fought against clamp locks for new schemes, preferring to stick with their favourite GEC/Alstom HW machines that were already well-supported by spares and expertise in their districts. For many years, they were largely successful in resisting them.
 
Last edited:

Annetts key

Established Member
Joined
13 Feb 2021
Messages
3,794
Location
West is best
It's also not really practical to retrofit in 40+ year old systems with cabinets in poor condition with insufficient space, etc.
I think you misunderstand. That 650V scheme had brand new 650V cabinets that were installed next to the existing signalling cupboards. These new cabinets were almost shed sized... Brand new cables, new transformers (the feed to the signal locs was 110V AC) and brand new switch gear.

I think reality faced by application engineers caused a backtrack from the original ideals. Without point batteries, some feeders to further flung junctions would have needed much larger and more expensive conductors to preserve voltage levels for peak loads present only for a few seconds every 30 minutes or so on a lightly used line.
The reality was the cost of the copper cables...

When I started in the mid-80s, everything was going to be clamplocks in the future! That's why the SSI points module was designed to only directly drive that style of actuator from its outputs. A relay interface and some custom logic in the data was required for a conventional point machine. The clamp lock proved unreliable in its original form, though modern bearer-enclosed versions are much better I understand, not least because all the cables and hoses are much better protected. Many area engineers, particularly on the Southern Region, fought against clamp locks for new schemes, preferring to stick with their favourite GEC/Alstom HW machines that were already well-supported by spares and expertise in their districts. For many years, they were largely successful in resisting them.
Nope, in-bearer clamp locks and especially hi-drives are just as rubbish in terms of reliability. And are much harder to work on.

At one time, one of the railway magazines published a league table of which point operating equipment was the most reliable vs. the most unreliable. IIRC, all clamp lock variants and HPSS/HPSA were some of the least reliable. HWs were some of the most reliable.
 

Mugby

Established Member
Joined
25 Nov 2012
Messages
2,128
Location
Derby
When a major signalling failure occurs, does Network Rail have it's own directly employed technicians to deal with the problem or does it need to call upon contractors to attend whatever the situation may be?
 

Harpo

Established Member
Joined
21 Aug 2024
Messages
3,780
Location
Newport
When a major signalling failure occurs, does Network Rail have it's own directly employed technicians to deal with the problem or does it need to call upon contractors to attend whatever the situation may be?
In house maintenance staff. There was an initial period of privatisation though when maintenance was outsourced.
 

Bald Rick

Veteran Member
Joined
28 Sep 2010
Messages
35,677
When a major signalling failure occurs, does Network Rail have it's own directly employed technicians to deal with the problem or does it need to call upon contractors to attend whatever the situation may be?

Yes in house. The exception is for brand new signalling kit where the installation contractor may be required to provide support for a short period of time after commissioning.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,553
Location
Torbay
I think you misunderstand. That 650V scheme had brand new 650V cabinets that were installed next to the existing signalling cupboards. These new cabinets were almost shed sized... Brand new cables, new transformers (the feed to the signal locs was 110V AC) and brand new switch gear.
That's a practical way to do it and might be worth it for improving a 'middle-aged' installation but if the signalling is already very old, the value of all that reengineering could be poor if it all gets replaced again after a few years.
Nope, in-bearer clamp locks and especially hi-drives are just as rubbish in terms of reliability. And are much harder to work on.
Disappointing. All to avoid the extended timbers to mount a traditional point machine to the side.
At one time, one of the railway magazines published a league table of which point operating equipment was the most reliable vs. the most unreliable. IIRC, all clamp lock variants and HPSS/HPSA were some of the least reliable. HWs were some of the most reliable.
When I was at Waterloo, the area engineers were unanimous in their preference for HWs. More reliable and easier to fix. They got their wish on a number of schemes I was involved with in the 2000s.
 

Annetts key

Established Member
Joined
13 Feb 2021
Messages
3,794
Location
West is best
When a major signalling failure occurs, does Network Rail have it's own directly employed technicians to deal with the problem or does it need to call upon contractors to attend whatever the situation may be?
Short history:

Under British Rail, all signalling and telecommunications came under each regions own Signalling and Telecommunications (S&T) Department. The S&T department was subdivided into signalling maintenance, signalling new works, telecom maintenance and telecom new works.

But there was also a central/national S&T organisation that set overall standards. All routine maintenance was done in house, as were minor and some major new signalling schemes.

Privatisation split all this up. Railtrack took over the role of setting the standards. Each regions S&T department was split up. The telecoms side became the BRT (British Rail Telecoms) company. The signalling was mated with the P.Way and other engineering disciplines to became an infrastructure maintenance company. These were then sold. In my area, Amey bought the company that I worked for.

These infrastructure maintenance companies had contracts with Railtrack to carry out routine maintenance of Railtrack's infrastructure. They also bid for contracts for new infrastructure work or alterations etc.

When Network Rail bought Railtrack, they started taking the maintenance back in house to reduce costs (apart from for telecoms where it's more complex). Eventually all routine maintenance was returned as the maintenance contracts finished.

So now, Network Rail is responsible for and carries out all routine maintenance of signalling equipment including attendance to failures. This is normally by using it's own employees. However, in some places, direct contract labour may be used to assist due to a lack of employed staff.

As Bald Rick says, new equipment may also be covered for a short period by the company that installed new signalling. Typically that's for two to six weeks.

Some second line support may also be provided by equipment manufactures or suppliers.

== Doublepost prevention - post automatically merged: ==

That's a practical way to do it and might be worth it for improving a 'middle-aged' installation but if the signalling is already very old, the value of all that reengineering could be poor if it all gets replaced again after a few years.
When the TVSC resignalling (SSI) was installed in part of this area, the vast majority (if not all) of the new 650V cabinets were retained. But, IIRC, instead of using a 110V AC feed to supply the new signalling cupboard nearby, they used a new (short length) 650V cable.

The remaining part of the area where the 650V network was renewed still feeds the remaining 1970s signalling cupboards (via 110V AC feeds).

This is because the 650V network renewal program spanned between (at the time) two different 1970s MAS schemes. One of which has since been partly replaced by the new SSI signalling controlled by TVSC.
 
Last edited:

MarkyT

Established Member
Joined
20 May 2012
Messages
7,553
Location
Torbay
When the TVSC resignalling (SSI) was installed in part of this area, the vast majority (if not all) of the new 650V cabinets were retained. But, IIRC, instead of using a 110V AC feed to supply the new signalling cupboard nearby, they used a new (short length) 650V cable.
The remaining part of the area where the 650V network was renewed still feeds the remaining 1970s signalling cupboards (via 110V AC feeds).
This is because the 650V network renewal program spanned between (at the time) two different 1970s MAS schemes. One of which has since been partly replaced by the new SSI signalling controlled by TVSC.
Good planning! Did they put in any remote power monitoring and switching in the new SSI area?
 

Annetts key

Established Member
Joined
13 Feb 2021
Messages
3,794
Location
West is best
Good planning! Did they put in any remote power monitoring and switching in the new SSI area?
I did not have a reason to open that side of most of these cubicles since the TVSC SSI was commissioned in this area. But as I said earlier as far as I know, this equipment has not been fitted.
 

Spartacus

Established Member
Joined
25 Aug 2009
Messages
3,809
From person experience I don't feel like there's a been an increase in the number of faults, just an increase in the time for them to be attended before rectification, so you might end up with a fault last for hours before it's fixed when it would have been a relativity quick job.
 

Annetts key

Established Member
Joined
13 Feb 2021
Messages
3,794
Location
West is best
From person experience I don't feel like there's a been an increase in the number of faults, just an increase in the time for them to be attended before rectification, so you might end up with a fault last for hours before it's fixed when it would have been a relativity quick job.
Well, of course, a fault is not going to be fixed if there is insufficient signalling maintenance staff on duty or, the staff that are on duty do not hold the relevant competencies. Either assistance would have to be in the form of staff from an adjacent area, a supervisor, manager or technical support staff going to site, or waiting for the next shift staff to come in duty in eight or 12 hours time.
 

Spartacus

Established Member
Joined
25 Aug 2009
Messages
3,809
Well, of course, a fault is not going to be fixed if there is insufficient signalling maintenance staff on duty or, the staff that are on duty do not hold the relevant competencies. Either assistance would have to be in the form of staff from an adjacent area, a supervisor, manager or technical support staff going to site, or waiting for the next shift staff to come in duty in eight or 12 hours time.

Exactly.
 
Status
Not open for further replies.

Top