• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Thameslink core ATO into use

Status
Not open for further replies.

Bald Rick

Veteran Member
Joined
28 Sep 2010
Messages
35,687
The Cambrian Coast also uses ETCS level 2, as is also installed in the core, but the rolling stock doesn't have ATO.

The Cambrian isn’t quite the same system; a different supplier (Ansaldo STS) and a different (much earlier) version of the software. But the principles are the same.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

pt_mad

Established Member
Joined
26 Sep 2011
Messages
2,960
If the train has had the correct messages, and does something wrong, then it’s the train’s fault.

I’d be interested to know how many ‘SPADs’ (equivalent) there have been on the Victoria, Central, Northern, Jubilee and DLR lines when in ATO since those lines were commissioned as such. I suspect it’s non-zero, but also suspect I won’t run out of fingers to count them on.

By the way ETCS (which is what is on Cambrian) is digital signalling.

Although society won't accept an unnaned entity (the train) can take the blame if there was an accident. The public and stakeholders will probably want some tangible blame if there is a near miss or accident and couldnt tell the public 'sorry, the triain got it wrong, we will just scrap that individual train'. Liability usually has to lead to a person, persons or organisation.

Hence the debate about these driverless cars. Questions are being asked about who insures them, how much insurance should cost considering the chances of an accident are supposed to be nill, and who would take the blame if someone was killed. The manufacturer, software developer, etc. Would they be withdrawn or recalled? Etc etc.

If there are exceptional circumstances, like say wheelslip or autumn mulch residue on the line which isn't detected until the train brakes at the last possible minute, is that train guaranteed to stop at a safe distance considering by the time the driver has realised they're not braking fast enough or early enough he/she can't do anything?

Obviously the underground probably has less problems with adverse weather.
 
Last edited:

ComUtoR

Established Member
Joined
13 Dec 2013
Messages
9,562
Location
UK
If the train has had the correct messages, and does something wrong, then it’s the train’s fault.

I'm not sure about this and I have tried, and failed, to get a complete response.

If the unit is about to do 'something wrong' then it is still the Drivers responsibility to prevent it. If the train was about to overshoot the platform then the Driver has a responsibility to override the system and apply the brake. Same with it about to go through an signal/speed etc. That is still the role of the person up the pointy end. I I let the unit carry out any such action that was unsafe then I would be held responsible. As far as I have been able to understand, we are ultimately responsible still and there is no waving of responsibility or liability.
 

AlexNL

Established Member
Joined
19 Dec 2014
Messages
1,714
Another thought, if the technology makes an error, or there is wheelslip or leaf mulch on the line in ATO which couldn't be visually seen, and the brakes are either applied too late or don't stop the train in time of an obstruction such as a bay, and contact is made, who is liable? The driver? The train manufacturers? The software systems? The signallers?

If a train gets dangerously close to the one in front and the driver realises the brake hasn't applied, two seconds pass while his brain processes and presses the brake but the train is already too close and it's like a spad in the traditional sense, who gets the blame? The train?

In theory, it should not be possible for an ETCS supervised train to pass a signal at danger as the ETCS braking curve ends with the end of the train's movement authority. The ETCS braking curve is calculated in a somewhat conservative manner, as it's impossible for the train to know about railhead conditions. The braking curve is not calculated with a "sunny spring day" in mind.

In practice, however, it is possible that a train can't brake in line with its braking curve due to extremely poor railhead conditions. If an ETCS controlled train SPADs, I would assume that it is dealt with in the same way as today under conventional signalling. Even while running under ETCS Full Supervision, a driver should always apply their professional driving skills to safely operate the train. This means not driving "to the braking curve", but adapting their driving style to the conditions outside.

If a train running under ATO performs a SPAD while a driver is on board, I assume that it would still be the driver who is held accountable for the SPAD. While under ATO, the driver is there to supervise the machine and to intervene if the situation so required.
 

Domh245

Established Member
Joined
6 Apr 2013
Messages
8,426
Location
nowhere
Im really hoping there’s a type of bus called a Beeching MkII!

Styled to look like a train (some sort of reverse pacer of sorts!) for maximum irony?

Although society won't accept an unnaned entity (the train) can take the blame if there was an accident. The public and stakeholders will probably want some tangible blame if there is a near miss or accident and couldnt tell the public 'sorry, the triain got it wrong, we will just scrap that individual train'. Liability usually has to lead to a person, persons or organisation.

It'd depend on what exactly went wrong I would think. If the train received the correct messages from the signalling system but for some reason these weren't processed properly, then it'd be the fault of the company that wrote the ATO software. If the software responded correctly but the hardware didn't (ie an error between the software output and the train's controls) then it'd be the train manufacturer's fault. However, I think that in this case, train builder, software writer, and signalling supplier are all in fact Siemens Mobility, although naturally it'll be different departments of it responsible for each area.
 

AlexNL

Established Member
Joined
19 Dec 2014
Messages
1,714
It'd depend on what exactly went wrong I would think. If the train received the correct messages from the signalling system but for some reason these weren't processed properly, then it'd be the fault of the company that wrote the ATO software. If the software responded correctly but the hardware didn't (ie an error between the software output and the train's controls) then it'd be the train manufacturer's fault. However, I think that in this case, train builder, software writer, and signalling supplier are all in fact Siemens Mobility, although naturally it'll be different departments of it responsible for each area.
Not gonna happen.

These components are all rated safety critical and failures should never result in incidents (fail safe). If the track<>train interface goes haywire, the train is brought to a standstill. If the software<>hardware interface goes haywire, the train is brought to a standstill as well.

There isn't "one" computer which can fail, there are multiple systems which have to be in agreement with each other. Track<>train data exchanges don't happen without verifying message integrity (checksum calculation, redundant connections), and software<>hardware interfaces are built in such a way that the systems which verify if everything is behaving as it should aren't the same as the ones sending the commands.
 

HLE

Established Member
Joined
27 Dec 2013
Messages
1,421
Wow, one train operates under ATO for a small section in the middle of the London core and suddenly people are plotting the demise of train drivers. Gotta love this forum at times.

Indeed. Why spend billions/trillions making the UK Rail Network fully ATO when it’s likely someone will still be employed to sit up front.

Waste of money.
 

Bald Rick

Veteran Member
Joined
28 Sep 2010
Messages
35,687
Not gonna happen.

These components are all rated safety critical and failures should never result in incidents (fail safe). If the track<>train interface goes haywire, the train is brought to a standstill. If the software<>hardware interface goes haywire, the train is brought to a standstill as well.

There isn't "one" computer which can fail, there are multiple systems which have to be in agreement with each other. Track<>train data exchanges don't happen without verifying message integrity (checksum calculation, redundant connections), and software<>hardware interfaces are built in such a way that the systems which verify if everything is behaving as it should aren't the same as the ones sending the commands.

Exactly.

I’m not quite sure why the integrity of the system is being questioned. Similar systems have been in service on railways for 5 decades and in the air (autoland) for over 40.
 
Last edited:

pt_mad

Established Member
Joined
26 Sep 2011
Messages
2,960
I'm not sure about this and I have tried, and failed, to get a complete response.

If the unit is about to do 'something wrong' then it is still the Drivers responsibility to prevent it. If the train was about to overshoot the platform then the Driver has a responsibility to override the system and apply the brake. Same with it about to go through an signal/speed etc. That is still the role of the person up the pointy end. I I let the unit carry out any such action that was unsafe then I would be held responsible. As far as I have been able to understand, we are ultimately responsible still and there is no waving of responsibility or liability.

But that's where this is flawed. If as has been said the automated system is designed at brake at the last possible minute in which it would be possible to stop in time, and the brake doesn't apply, and the driver thinks crap apply the brake, which would take a second, in theory surely it's already too late.

Posters above had said well the system wont fail. But how many times does LICC fail, or CCF freezes, or announcements stop, or tops doesn't report, or windows freezes on your works or home computer. Surely these were designed to never fail. But computer often says no. There are train crashes all over the world. Are people series saying this system can't and won't ever make mistakes? That be true why not roll the whole thing out right now and be done with it as it's zero errors 100 percent safety Vs that of a human if this is true.
 
Last edited:

transmanche

Established Member
Joined
27 Feb 2011
Messages
6,021
But that's where this is flawed. If as has been said the autonaaut atsten is designed at brake at the last oissposs minute in which it would be possible to stop in time, and the brake doesn't apply, and the driver think crap apply the brake, which would take a second, in theory surely it's already too late.

Posters above had said well the system wont fail. But how many times does LICC fail, or CCF freezes, or announcements stop, or tops doesn't report, or windows freezes on your works or gone computer. Surely these were designed to never fail. But computer often says no.
But how often have these situations occurred on the Victoria, Central, Northern and Jubilee lines or the DLR? The Victoria line is now on its second generation of ATO and you really can see the difference - trains approach stations (and accelerate) much faster than on the first generation ATO.
 

AlexNL

Established Member
Joined
19 Dec 2014
Messages
1,714
But that's where this is flawed. If as has been said the autonaaut atsten is designed at brake at the last oissposs minute in which it would be possible to stop in time, and the brake doesn't apply, and the driver think crap apply the brake, which would take a second, in theory surely it's already too late.
That's why safety margins are taken into account when braking curves etc. are being calculated. It's not "brake at the last possible second" but instead the system assumes "brake at a reasonably late position, but take into account that circumstances may be less than optimal".

If conditions are really poor then this might not be enough, but it's not as if these trains run without a competent member of staff behind the controls.

Posters above had said well the system wont fail. But how many times does LICC fail, or CCF freezes, or announcements stop, or tops doesn't report, or windows freezes on your works or gone computer. Surely these were designed to never fail. But computer often says no.
Signalling centre failures are rare, but if they do happen then the system chooses the safe default: don't run trains. Signals go to red (or black), trains are stopped.

CCF isn't safety critical. Announcements aren't safety critical. TOPS isn't safety critical. None of those systems come with a risk of injury or loss of life when a failure occurs.
 

ComUtoR

Established Member
Joined
13 Dec 2013
Messages
9,562
Location
UK
Because incidents like the current one under investigation tend to worry people.
 

ComUtoR

Established Member
Joined
13 Dec 2013
Messages
9,562
Location
UK
https://www.railforums.co.uk/thread...speed-restrictions-raib-investigating.161035/

During the morning of Friday 20 October 2017, a train driver travelling on the Cambrian coast line in North Wales reported that long standing temporary speed restrictions were not indicated on their in-cab display. As signalling staff at the control centre in Machynlleth investigated this report, they became aware that this failure applied to several trains under their control. The temporary speed restrictions were required on the approach to level crossings so that people crossing the line had sufficient warning of an approaching train

We both play trains for a living and understand the system but we both also understand that things can, and do, go wrong. As you and I have both mentioned. This is part of the reason why there is still, and will be for a very long time, a Driver up the front.
 

pt_mad

Established Member
Joined
26 Sep 2011
Messages
2,960
That's why safety margins are taken into account when braking curves etc. are being calculated. It's not "brake at the last possible second" but instead the system assumes "brake at a reasonably late position, but take into account that circumstances may be less than optimal".

If conditions are really poor then this might not be enough, but it's not as if these trains run without a competent member of staff behind the controls.


Signalling centre failures are rare, but if they do happen then the system chooses the safe default: don't run trains. Signals go to red (or black), trains are stopped.

CCF isn't safety critical. Announcements aren't safety critical. TOPS isn't safety critical. None of those systems come with a risk of injury or loss of life when a failure occurs.

What about when lineside signals fail or show wrong detection etc? Surely these systems were designed to be totally free of error or failure but they aren't.

Cars, buses and lorry's are safety critical and their systems fail and were presumably designed not to.

Also, it's been reported that on the ERTMS in Wales, messages regarding temporary speed restrictions were displayed as sending at the signalling centre, but they were not processed by the train for a period of time. And aren't these systems designed to be 100 percent error free?


I think it will come down to like has been alluded to above. Drivers will be allocated overall responsibility and if the train failed to brake and the driver couldn't stop in time it would likely be put onto the driver. As they are the easiest party to blame and this puts little liability onto the overall system or the TOCs etc. It's easier than having to shelve the whole thing if a mistake occurs or admit it can make an error.

Do driver's on these current trial services have to sign to say they remain fully responsible over and above the auto system and take the full responsibility? Suspect they may do.
 

AlexNL

Established Member
Joined
19 Dec 2014
Messages
1,714
https://www.railforums.co.uk/thread...speed-restrictions-raib-investigating.161035/

We both play trains for a living and understand the system but we both also understand that things can, and do, go wrong. As you and I have both mentioned. This is part of the reason why there is still, and will be for a very long time, a Driver up the front.
Ah, that incident. Thanks for reminding me, I had read about it but it escaped my mind.

It is indeed a worrying incident (especially as no cause has been found) and a thorough investigation is required.

Furthermore, it underlines the fact that competent staff is still required - while ETCS might be the next generation of train protection systems, it is by no means perfect and a competent driver is still required. Unattended mainline operation under ETCS is still many miles away.

Somewhat offtopic: I don't play with trains for a living, I have a career in software engineering and I know a couple of things about the design of security critical systems. :)
 

LNW-GW Joint

Veteran Member
Joined
22 Feb 2011
Messages
21,904
Location
Mold, Clwyd
Indeed. Why spend billions/trillions making the UK Rail Network fully ATO when it’s likely someone will still be employed to sit up front.
Waste of money.

The money is in the ETCS installation (track and train), which eliminates much lineside signalling and detection equipment (lights on sticks).
Norway has just decided to roll out ETCS level 2 over its whole network over the next 20 years.
http://www.railwaygazette.com/news/...ew/norways-ertms-programme-moves-forward.html
The BaneNOR board agreed on March 14 to award the NKr5·5bn trackside installation contract to Siemens. This will see the implementation of ETCS Level 2 across the entire 4 200 km network over the next two decades.
It will enable the elimination of the current legacy signalling equipment dating from the 1950s, which has become obsolete and increasingly expensive to maintain
 

ComUtoR

Established Member
Joined
13 Dec 2013
Messages
9,562
Location
UK
Oh I though you were our resident driver from overseas. :/ I may have been thinking about a different forumite.
 

pt_mad

Established Member
Joined
26 Sep 2011
Messages
2,960
Ah, that incident. Thanks for reminding me, I had read about it but it escaped my mind.

It is indeed a worrying incident (especially as no cause has been found) and a thorough investigation is required.

Furthermore, it underlines the fact that competent staff is still required - while ETCS might be the next generation of train protection systems, it is by no means perfect and a competent driver is still required. Unattended mainline operation under ETCS is still many miles away.

Somewhat offtopic: I don't play with trains for a living, I have a career in software engineering and I know a couple of things about the design of security critical systems. :)

But who's prepared to let a system that is ''by no means perfect" drive a passenger train in an indefensible manor? I.e. incautiously performing an action later than is usually done by a person.
 

AlexNL

Established Member
Joined
19 Dec 2014
Messages
1,714
What about when lineside signals fail or show wrong detection etc? Surely these systems were designed to be totally free of error or failure but they aren't.
Lineside signals aren't made to be "free or error or failure" as that is impossible to guarantee. After all, they are positioned outside and thus are susceptible to external influences.

The systems are designed in such a way that if a failure does happen, the system will choose a safe mode of failure: signals will turn red, level crossing will remain closed, traffic lights will go into hazard mode (flashing yellow aspects).

Wrong-side failures are incredibly rare, and are nearly always caused by external factors which prohibit the normal systems operation. Three incidents spring to mind:
  • The 1988 Clapham Junction crash, in which stray wires caused false information to be fed into the signalling system
  • The 2011 Zevenaar ICE crash: thieves had cut away a lot of copper around the Zevenaar junction, and had done so in such a way that the signalling system was not aware of it.
  • The 2014 TER-TGV crash: rodents had eaten through signalling cables on a rural line in France, which caused the train occupation detection system to fail in an unsafe way.
Cars, buses and lorry's are safety critical and their systems fail and were presumably designed not to.
Those are not safety critical systems.
Also, it's been reported that on the ERTMS in Wales, messages regarding temporary speed restrictions were displayed as sending at the signalling centre, but they were not processed by the train for a period of time. And aren't these systems designed to be 100 percent error free?
Yes, and this is an issue which is being investigated (see the post mentioned earlier).

I think it will come down to like has been alluded to above. Drivers will be allocated overall responsibility and if the train failed to brake and the driver couldn't stop in time it would likely be put onto the driver. As they are the easiest party to blame and put little liability onto the overall system or the TOCs etc. It's easier than having to shelve the whole thing if a mistake occurs.
Isn't that basically their job?

Do driver's on these current trial services have to sign to say they remain fully responsible over and above the auto system and take the full responsibility? Suspect they may do.
On the current Thameslink route, drivers are responsible. What I understood from Geoff Marshall's video is that -upon entering the TL Core- the train is offered to run under ATO. The driver explicitly has to accept this, and has to indicate that he wishes to continue ATO running after every station stop in the Core. Upon leaving the tunnels, the driver then regains control as the ATO section ends.
 

theironroad

Established Member
Joined
21 Nov 2014
Messages
3,717
There needs to be some clear national guidelines on what happens during an incident when the train is in ATO.

The whole point of this exercise is that the computer can supposedly drive closer to and brake later than a human driver, so a human driver cannot be expected to second guess what the computer is going to do. ATO will eventually reduce drivers route knowledge in any case, so they won't necessarily know when you start braking, especially in deep fog, whereas now human route knowledge covers that.

If the computer messes up in ATO, then the computer gets put on a support anmoniyoring plans removed from driving duties if it space. The driver cannot be the fall guy for a computer says no mess up.
 

theironroad

Established Member
Joined
21 Nov 2014
Messages
3,717
Lineside signals aren't made to be "free or error or failure" as that is impossible to guarantee. After all, they are positioned outside and thus are susceptible to external influences.

The systems are designed in such a way that if a failure does happen, the system will choose a safe mode of failure: signals will turn red, level crossing will remain closed, traffic lights will go into hazard mode (flashing yellow aspects).

Wrong-side failures are incredibly rare, and are nearly always caused by external factors which prohibit the normal systems operation. Three incidents spring to mind:
  • The 1988 Clapham Junction crash, in which stray wires caused false information to be fed into the signalling system
  • The 2011 Zevenaar ICE crash: thieves had cut away a lot of copper around the Zevenaar junction, and had done so in such a way that the signalling system was not aware of it.
  • The 2014 TER-TGV crash: rodents had eaten through signalling cables on a rural line in France, which caused the train occupation detection system to fail in an unsafe way.

Those are not safety critical systems.

Yes, and this is an issue which is being investigated (see the post mentioned earlier).


Isn't that basically their job?


On the current Thameslink route, drivers are responsible. What I understood from Geoff Marshall's video is that -upon entering the TL Core- the train is offered to run under ATO. The driver explicitly has to accept this, and has to indicate that he wishes to continue ATO running after every station stop in the Core. Upon leaving the tunnels, the driver then regains control as the ATO section ends.

In which case when ATO is 'offered", then I'd politely decline unless when it offers it also says it will accept legal responsibility.....
 

AlexNL

Established Member
Joined
19 Dec 2014
Messages
1,714
Oh I though you were our resident driver from overseas. :/ I may have been thinking about a different forumite.
I would love to drive a train, but I don't think I'd pass the medical exams. Something with colours. :)

But who's prepared to let a system that is ''by no means perfect" drive a passenger train in an indefensible manor? I.e. incautiously performing an action later than is usually done by a person.
The driver is still there, in control of their train. They are trained, fully competent, and are responsible for a safe operation throughout the entire journey. ATO over ETCS in no way replaces the driver or relieves them of their duties.

There are other issues with ETCS. For example, ETCS Level 2 uses GSM-R for data communication between the trainborne equipment and the radio block centre which controls train movements. In busy areas this can be troublesome as the link is dependant on the quality of the GSM-R network, which can suffer from heavy interference from other networks. The industry is investigating if it is feasible to use LTE ("4G") networks instead.

Then there is also an issue with complicated junctions and station layouts... there are few ETCS L2 areas in the world where this works properly.
 

AlexNL

Established Member
Joined
19 Dec 2014
Messages
1,714
There needs to be some clear national guidelines on what happens during an incident when the train is in ATO.
ATO is a supporting system.

To make the car analogy: if you're driving on the motorway and you've got your cruise control set to 70 mph, you still have to operate the vehicle in a safe manner. This also means adhering to speed limits (temporary or permanent), avoiding potholes, and braking in time.

The whole point of this exercise is that the computer can supposedly drive closer to and brake later than a human driver, so a human driver cannot be expected to second guess what the computer is going to do. ATO will eventually reduce drivers route knowledge in any case, so they won't necessarily know when you start braking, especially in deep fog, whereas now human route knowledge covers that.
The ETCS system tells the driver how much further they can go until the train reaches the end of its movement authority (because the next block is occupied, points set against train, you name it). ATO simply follows the information provided by the ETCS system.

A driver can drive just as 'agressive' as ATO: just adhere to the ETCS braking curve displayed on the screen in the cab.

If the computer messes up in ATO, then the computer gets put on a support anmoniyoring plans removed from driving duties if it space. The driver cannot be the fall guy for a computer says no mess up.
I disagree. There is a fully competent driver on board whose job it is to bring a train safely from A to B. In ATO mode this includes monitoring the machine's behaviour.

If there would be no driver on board, it would indeed be the train's responsibility if stuff goes wrong. But the driver is there, up front, and is responsible for the entire operation. Completely in line with the Rule Book, their training, and their employer's professional driving policy.

In which case when ATO is 'offered", then I'd politely decline unless when it offers it also says it will accept legal responsibility.....
A TOC's professional driving policy might see that a bit differently though. Sometimes an offer can be of the kind which you can't really refuse... :)
 

pt_mad

Established Member
Joined
26 Sep 2011
Messages
2,960
On the current Thameslink route, drivers are responsible. What I understood from Geoff Marshall's video is that -upon entering the TL Core- the train is offered to run under ATO. The driver explicitly has to accept this, and has to indicate that he wishes to continue ATO running after every station stop in the Core. Upon leaving the tunnels, the driver then regains control as the ATO section ends.

So the system 'offers' to run under ATO, and the driver then has to explicitly accept this and is aware they take full responsibility for this And yet in reality they have no choice but to accept if the train is booked ATO and when the full timetable is rolled out are they really being given a choice on that day whether to accept? It'd be a case of decline at your peril.

Exactly as said above by someone else. The computer is designed to drive closer to the wind than a person capably could. Yet the person has to second guess if the computer is going to make a wrong judgement and stop it in time, when it was close to the wind even before they realised?
 
Last edited:

Bromley boy

Established Member
Joined
18 Jun 2015
Messages
4,609
The incremental cost of ATO compared to ETCS L2 is almost negligible. It is just an extra computer on the train, plus the driver training, which naturally is relatively straightforward. Therefore on the assumption that ETCS L2 will in time become cheaper than conventional resignalling (and it is heading that way), then the prospect of ATO across a large part of the network in 20 years is quite real.

I fully admit I am no expert on these matters but:

ATO perhaps, but fully driverless? ETCS is currently a lot more expensive than conventional resignalling, as I understand it. (Article in Rail Magazine about the enormous cost of freight locos being fitted with it, versus potential savings, etc.).

ERTMS/ETCS over a good part of the network is likely in 20 years - certainly the busier bits - but how much of the total network?

As someone who clearly knows what they’re taking about... I’d be interested to know, in support of Bletchlyite’s previous comment, how much of the current mainline network do you believe will be technologically capable of being fully (DLR style) driverless within 20 years?

It's quite possible that it'll be a choice between a driverless bus and a driverless train. I know which I'd prefer, and it isn't a Beeching MkII.

Knowing our unions, I’m afraid it’ll probably be a choice between an autonomous car/bus and a manually driven train. :D
 

Bald Rick

Veteran Member
Joined
28 Sep 2010
Messages
35,687
I fully admit I am no expert on these matters but:

ATO perhaps, but fully driverless? ETCS is currently a lot more expensive than conventional resignalling, as I understand it. (Article in Rail Magazine about the enormous cost of freight locos being fitted with it, versus potential savings, etc.).

ERTMS/ETCS over a good part of the network is likely in 20 years - certainly the busier bits - but how much of the total network?

As someone who clearly knows what they’re taking about... I’d be interested to know, in support of Bletchlyite’s previous comment, how much of the current mainline network do you believe will be technologically capable of being fully (DLR style) driverless within 20 years?

Knowing our unions, I’m afraid it’ll probably be a choice between an autonomous car/bus and a manually driven train. :D

I can’t see any part of the current National Rail system operating in passenger service under UTO (unattended Train operation) in the next 20 years. I can see some short empty workings in UTO using auto-reverse.

What I can see is application of full ATO, with somebody in the front cab performing a similar role to LU drivers on the ATO lines there, ie responsible for station duties and customer info, with a safety critical role in the event of failure or emergency. This will happen wherever new fleets are coincident with new signalling, so my guess for the next 20 years is around 30% of the network by track mileage and 50% of passenger journeys (at some point of the journey). For example, I think I read somewhere that the new South Western suburban fleet will be fitted with ETCS from new. Wimbledon signalling centre will need renewal in the next 20 years.

A couple of caveats. Firstly, there will be a long transition period. A Weymouth to London train may only be in ATO for approx 20% of its trip, therefore the person upfront will still be driving for the majority of the trip (until the rest is resignalled)

Second, this does rely on ETCS ‘signals away’ becoming cheaper than conventional. Economy of scale is required, but also, crucially, fleet fitment from new. Both are beginning to happen

Third, This is my personal view. I don’t have visibility of the details of the digital rail programme. However I know that the ATO on Thameslink is going to be a game changer, and I predict that the pull for the product from the wider industry will be significant, and very soon.
 

Bald Rick

Veteran Member
Joined
28 Sep 2010
Messages
35,687
But who's prepared to let a system that is ''by no means perfect" drive a passenger train in an indefensible manor? I.e. incautiously performing an action later than is usually done by a person.

London Underground for a start. For almost 50 years.
 

DenmarkRail

Member
Joined
13 Jun 2016
Messages
666
I wonder if HS2 will have any elements of ATO? I mean, it should absolutely have the capability for it to be useable for the entire route, but whether or not that happens is another matter...
 

philthetube

Established Member
Joined
5 Jan 2016
Messages
4,180
I'm not sure about this and I have tried, and failed, to get a complete response.

If the unit is about to do 'something wrong' then it is still the Drivers responsibility to prevent it. If the train was about to overshoot the platform then the Driver has a responsibility to override the system and apply the brake. Same with it about to go through an signal/speed etc. That is still the role of the person up the pointy end. I I let the unit carry out any such action that was unsafe then I would be held responsible. As far as I have been able to understand, we are ultimately responsible still and there is no waving of responsibility or liability.

This was true on the underground with the old Victoria line system but this is not the case with the newer systems, I don't know what the situation is through the core but I would be surprised if the driver is expected to intervene

In theory, it should not be possible for an ETCS supervised train to pass a signal at danger as the ETCS braking curve ends with the end of the train's movement authority. The ETCS braking curve is calculated in a somewhat conservative manner, as it's impossible for the train to know about railhead conditions. The braking curve is not calculated with a "sunny spring day" in mind.

In practice, however, it is possible that a train can't brake in line with its braking curve due to extremely poor railhead conditions. If an ETCS controlled train SPADs, I would assume that it is dealt with in the same way as today under conventional signalling. Even while running under ETCS Full Supervision, a driver should always apply their professional driving skills to safely operate the train. This means not driving "to the braking curve", but adapting their driving style to the conditions outside.

If a train running under ATO performs a SPAD while a driver is on board, I assume that it would still be the driver who is held accountable for the SPAD. While under ATO, the driver is there to supervise the machine and to intervene if the situation so required.

If a train has a sped due to equipment failure the rule is the same as not, it is a spad but not attributed to the driver.

The thing I want to know is what actions are available to the driver if as he a approaches the platform there is something happening which they would normally slow down for, eg drunk on the platform. Do they have the ability to enter a platform slowly or is it full speed or stop?
 
Status
Not open for further replies.

Top