• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Wrong-side signalling failure at Wingfield

Status
Not open for further replies.

Tomnick

Established Member
Joined
10 Jun 2005
Messages
5,933
As per the RAIB, it is my understanding that the first train had the signal revert to danger on approach, hence they stopped. The second train was then cautioned.
Almost, but it didn't revert on approach, it was red all along. Obviously it took a bit of a distance to stop from 110mph! The second train wasn't cautioned in the Rule Book sense, just advised that they might be brought down to a red.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

baz962

Established Member
Joined
8 Jun 2017
Messages
3,664
Almost, but it didn't revert on approach, it was red all along. Obviously it took a bit of a distance to stop from 110mph! The second train wasn't cautioned in the Rule Book sense, just advised that they might be brought down to a red.
So did it have a single yellow or was it just a spad.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,551
Location
Torbay
Almost, but it didn't revert on approach, it was red all along. Obviously it took a bit of a distance to stop from 110mph! The second train wasn't cautioned in the Rule Book sense, just advised that they might be brought down to a red.
Ah, so the first train might have had an incorrect aspect sequence with a green or double yellow reading to a red instead of yellow (depending on whether a 3 or 4 asp), so would have applied full braking at sighting but had little chance of coming to a stand before passing the signal. It's unlikely the signal has TPWS as it's on plain line with no junctions or station platforms in section. From the RAIB photo it looks like it has the old horizontal black line on white background plate above the signal number denoting 'auto'.
 

skyhigh

Established Member
Joined
14 Sep 2014
Messages
6,848
From the RAIB photo it looks like it has the old horizontal black line on white background plate above the signal number denoting 'auto'.
I apologise for taking this off topic, but when you say 'old', do you mean the sign is no longer applied to new installations?
 

plugwash

Established Member
Joined
29 May 2015
Messages
1,990
So if i'm understanding the (suspected) scenario correctly.

red and yellow are swapped.

* Driver of the First train sees a false red aspect at the faulty signal, and slams on the emergency brakes.
* Due to it's speed, first train gets far enough past the faulty signal before stopping that the signal prior to the faulty signal clears.
* This allows a second train to approach the faulty signal and encounter a false yellow aspect.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,551
Location
Torbay
I apologise for taking this off topic, but when you say 'old', do you mean the sign is no longer applied to new installations?
That's correct. Although the sign is still described in the rule book as denoting an automatic signal there is no longer any provision to self authorise passing one if communication with the signaller is not available. The assumption is with cab radios and trackside phones, communication will always be possible. Hence in new schemes, although many plain line signals will normally operate in automatic mode, there is no longer any need to specially identify them to drivers.
 

Nottingham59

Established Member
Joined
10 Dec 2019
Messages
3,330
Location
Nottingham
So if i'm understanding the (suspected) scenario correctly.

red and yellow are swapped.

* Driver of the First train sees a false red aspect at the faulty signal, and slams on the emergency brakes.
* Due to it's speed, first train gets far enough past the faulty signal before stopping that the signal prior to the faulty signal clears.
* This allows a second train to approach the faulty signal and encounter a false yellow aspect.
I think so. Only to add, if your scenario is correct, that the second train would have seen a single yellow at the previous signal, so would have been approaching DY586 at low speed, expecting to stop there.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,551
Location
Torbay
So if i'm understanding the (suspected) scenario correctly.

red and yellow are swapped.

* Driver of the First train sees a false red aspect at the faulty signal, and slams on the emergency brakes.
* Due to it's speed, first train gets far enough past the faulty signal before stopping that the signal prior to the faulty signal clears.
* This allows a second train to approach the faulty signal and encounter a false yellow aspect.
It's possible the second train was verbally cautioned at the signal prior to the faulty one as that was displaying the incorrect aspect for approaching a red as experienced by the previous driver but then when the faulty signal was encountered it was at yellow incorrectly so was initially obeyed normally until the obstruction ahead was sighted.
 

zwk500

Veteran Member
Joined
20 Jan 2020
Messages
18,458
Location
Northampton
It's possible the second train was verbally cautioned at the signal prior to the faulty one as that was displaying the incorrect aspect for approaching a red as experienced by the previous driver but then when the faulty signal was encountered it was at yellow incorrectly so was initially obeyed normally until the obstruction ahead was sighted.
If only the Lamp outputs had been swapped then would the Signaller's Workstation be displaying the Red correctly? And if so, would they receive a SPAD alarm when the 2nd train passed what they saw to be a legitimate Yellow signal?

Or was the fault slightly deeper into the interlocking?
 

Tim M

Member
Joined
9 Jul 2016
Messages
204
Absolutely this - and the potential errors may be hidden in specialist software that only a few people in the world know how to interrogate.
A couple of points:
1) Please wait for the formal report from the RAIB before making any conclusions.
2) U.K. developed interlockings are not simply ‘specialist software’, there are two parts, the operating system and the site specific data.
3) The RAIB report says that there was a disconnection [I assume in the wiring of the location case illustrated], suggesting that the problem was not in the interlocking, this assumption will only be proved or disproved by the RAIB.
4) Computer Based Interlockings (SSI and derivatives Westlock and Smartlock) have been in service for over 30 years, the designs for hardware, software including data design and testing, will all be well documented up to and including multiple Safety Cases, i.e. ready for competent engineers to ‘interrogate’.
 

Tomnick

Established Member
Joined
10 Jun 2005
Messages
5,933
If only the Lamp outputs had been swapped then would the Signaller's Workstation be displaying the Red correctly? And if so, would they receive a SPAD alarm when the 2nd train passed what they saw to be a legitimate Yellow signal?

Or was the fault slightly deeper into the interlocking?
There were no indications at all on the panel when it was in Derby PSB (as was common for runs of auto signals on plain line sections) - I'd be surprised if this wasn't replicated on the workstation that it was recontrolled to.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,551
Location
Torbay
There were no indications at all on the panel when it was in Derby PSB (as was common for runs of auto signals on plain line sections) - I'd be surprised if this wasn't replicated on the workstation that it was recontrolled to.
I suspect you're right as it looks like older relay equipment in the cabinet in the RAIB picture. The workstation should still get full track circuit indications through the area though, like the old panel before it, from which signal stop/proceed status might be inferred by signallers.
 

Chris M

Member
Joined
4 Feb 2012
Messages
1,060
Location
London E14
A couple of points:
1) Please wait for the formal report from the RAIB before making any conclusions.

But will there be be a formal report? The RAIB news item just says that a Safety Digest will be issued.

Without a doubt a formal report will be issued.
I think you might be using different meanings of "formal report".
The RAIB have indicated that they will be issuing a safety digest, which is a type of formal report but is not the same thing as what the RAIB term a "report", e.g.
My guess, and I stress that it is just a guess, is that any recommendations that would have resulted from this incident will be fully covered by those made in the report into Dalwhinnie. RAIB do not make recommendations more than once if they judge that there has been insufficient time for them to have been fully implemented; that time typically being measured in years whereas this incident took place only 1 month after publication of the Dalwhinnie report. Indeed paragraph 196 of that report states that revisions to the signalling maintenance testing handbook is ongoing and expected to be complete by December this year. I don't know whether those revisions will be at all relevant to this incident, but it seems plausible they might be.
 

Nicholas Lewis

Established Member
Joined
9 Aug 2019
Messages
7,996
Location
Surrey
I think you might be using different meanings of "formal report".
The RAIB have indicated that they will be issuing a safety digest, which is a type of formal report but is not the same thing as what the RAIB term a "report", e.g.
My guess, and I stress that it is just a guess, is that any recommendations that would have resulted from this incident will be fully covered by those made in the report into Dalwhinnie. RAIB do not make recommendations more than once if they judge that there has been insufficient time for them to have been fully implemented; that time typically being measured in years whereas this incident took place only 1 month after publication of the Dalwhinnie report. Indeed paragraph 196 of that report states that revisions to the signalling maintenance testing handbook is ongoing and expected to be complete by December this year. I don't know whether those revisions will be at all relevant to this incident, but it seems plausible they might be.
RAIB have determined a safety digest is adequate as im surmising the cause is understood and had existing processes been followed it would have been prevented. The SMTH (signalling maintenance testing handbook) controls working on the existing signalling system and consists of specific modules detailing precisely what to do when disconnecting cables in this instance. A SMTH test plan would be prepared before the works detailing tasks and modules involved and competent SMTH personnel would be pre identified. There should have been a wire count to the location case diagrams before job started, tagging of cables if they aren't identified , then a wire count to reconfirm the right cables had been reconnected then aspect sequence testing should have been undertaken. The tester should have been a separate person doing the reconnections.

Now there are probably contributory factors here that may have lead to this situation and NR's own internal investigation will addess those if they exist but this report will never be placed in the public domain.
Did the first train stop because of a TPWS triggering?
Very much doubt if this signal is fitted with TPWS as its on plain line and looks like its an auto
 

Wilts Wanderer

Established Member
Joined
21 Nov 2016
Messages
3,199
A couple of points:
1) Please wait for the formal report from the RAIB before making any conclusions.
2) U.K. developed interlockings are not simply ‘specialist software’, there are two parts, the operating system and the site specific data.
3) The RAIB report says that there was a disconnection [I assume in the wiring of the location case illustrated], suggesting that the problem was not in the interlocking, this assumption will only be proved or disproved by the RAIB.
4) Computer Based Interlockings (SSI and derivatives Westlock and Smartlock) have been in service for over 30 years, the designs for hardware, software including data design and testing, will all be well documented up to and including multiple Safety Cases, i.e. ready for competent engineers to ‘interrogate’.

To reply to 1) - why? All I did was reply to and expand on pdeaves’ observation about the complexity of ultra-modern signalling design.

The remainder of your points I acknowledge and agree with.
 

Tim M

Member
Joined
9 Jul 2016
Messages
204
To reply to 1) - why? All I did was reply to and expand on pdeaves’ observation about the complexity of ultra-modern signalling design.
Simple, the RAIB doesn’t mention the type of signalling involved. The interlocking might be relay based or a Computer Based Interlocking such as SSI. By the way SSI has been in use since the 1980’s, hardly ‘ultra-modern’, even its derivatives Westlock and Smartlock have been in use for well over a decade. The complexity is not really in the system being used (the design of which is fixed) but in the application of the signalling and interlocking principles.
 

Wilts Wanderer

Established Member
Joined
21 Nov 2016
Messages
3,199
Simple, the RAIB doesn’t mention the type of signalling involved. The interlocking might be relay based or a Computer Based Interlocking such as SSI. By the way SSI has been in use since the 1980’s, hardly ‘ultra-modern’, even its derivatives Westlock and Smartlock have been in use for well over a decade. The complexity is not really in the system being used (the design of which is fixed) but in the application of the signalling and interlocking principles.

But the comment wasnt specifically talking about the Wingfield signalling, it was discussing the future (ETCS?) option of removing lineside equipment, by which time all the things to potentially go wrong would be entirely hidden and only detectable to signalling software engineers.
 

Tim M

Member
Joined
9 Jul 2016
Messages
204
But the comment wasnt specifically talking about the Wingfield signalling, it was discussing the future (ETCS?) option of removing lineside equipment, by which time all the things to potentially go wrong would be entirely hidden and only detectable to signalling software engineers.
Not hidden, all changes of state in a Computer Based Interlocking and AFAIK ETCS Block Processors are logged for analysis by competent signalling engineers, who by the way are not necessarily software engineers. Following an incident about 25 years ago (no safety implications in this instance) one of my project delivery team engineers successfully and quickly analysed an interlocking log to understand what had happened, neither of us would pretend to be software engineers. Such data logging may also be used on a simulator to replay what happened. Note I was a signalling engineer for 38 years delivering signalling solutions in the U.K. and for export. This required me to work in close conjunction with R&D engineers on the development (software, hardware, design tools etc.) of new signalling and train control products and systems.
 

Annetts key

Established Member
Joined
13 Feb 2021
Messages
3,793
Location
West is best
I honestly can't understand how this was allowed to happen. Surely testing should ensure that the aspect displayed is correct, at the very least?
Yes, any signalling equipment that has been disconnected and then reconnected should be tested to the SMTH document. If two wires were crossed, two different tests/checks that should have been done should have picked up this mistake.

If the SMTH handbook (Signal Maintenance Testing Handbook) is followed this shouldn't happen. This is why its a RAIB digest nothing significantly new to learn.
Agreed. It could well be a failure to correctly follow existing procedures for some reason or reasons rather than an equipment fault or an omission in the existing procedures.

Each investigation will be different. Each incident will be different. Whilst there should be some industry level learning, the human error factors are hard to remove. Miss-communication, out of date documents, lack of training, fatigue, etc. are all potential factors. The learning part is easy. Implementing change is very different.
Network Rail is already aware of many problems. Consultation with the unions on changing the competence system took place before COVID19. The cause here may or may not be a new problem. We will have to wait to see what the investigation finds/has found.

Did the first train stop because of a TPWS triggering?

Ultimately the only way to avoid this sort of thing is to remove the signal heads from the equation.

The fewer components there are in the signalling chain to go wrong the better.
Unlikely TPWS was fitted. This is one of the weaknesses of the majority of signals not being provided with TPWS. TPWS is a mitigation against the worst case scenario of a collision at a junction or a level crossing.

Seems a rather similar scenario to Clapham, where the driver noted an irregular aspect and stopped at the next signal to report it. The first signal then gave a false proceed aspect to the following train.
It may appear similar, but the cause looks to be different. Clapham was caused by a track circuit relay contact having been bypassed by a wire that should have been removed or properly insulated. The part of the circuitry concerned was the interlocking and control circuit for the signal.

Here, from the sparse information available, it appears to be the wiring or cable from the control system to the signal head itself. So after the interlocking and control circuit.

If only the Lamp outputs had been swapped then would the Signaller's Workstation be displaying the Red correctly? And if so, would they receive a SPAD alarm when the 2nd train passed what they saw to be a legitimate Yellow signal?

Or was the fault slightly deeper into the interlocking?
If the signaller actually has indications (unlikely if this is a relay interlocking automatic signal), the signallers aspect indications are driven off the control relay or the module in the relevant equipment location case or interlocking relay room or equivalent. So if there is a wiring fault between the equipment location case and the signal head, this would not affect the indications provided to the signaller.

For the same reason, there would be no SPAD alarm even if one was provided (which is unlikely if this is an automatic signal in a relay interlocking area).

Given that the signal was disconnected and reconnected due to planned track maintenance work, that implies that the multicore cable from the equipment location case to the signal head was disconnected and pulled clear of the track. This is done so that track work does not damage the cable. As I say above, this is after all the interlocking and control circuitry.

On the subject of removing physical signal heads, or fewer components in the signalling system, that does not really change the risk by any significant amount. There were far fewer complex signalling systems in the past and the accident/incident rate was higher. Signalling and interlocking systems have become more complex to try to prevent human error at all points of the system. The number of actual unprotected wrong side failures where the signalling equipment was found to be at fault (regardless of the how/when/who) is extremely small. Compared to the number of items of signalling equipment (including, but not limited to signal heads, equipment location case, connection boxes/junction boxes, track circuits, axle counters, point operating equipment, interlocking equipment and wiring, relays, lever/switch electrical connections etc.) and the number of trains run each day, the percentage is astonishing small.

Human factors and human error vastly outweigh unprotected wrong side failures of signalling equipment.

Hence why I’ve always been of the opinion that ATP should have been introduced rather than the “quick win” of TPWS. But that’s a debate that has already been had and is now irrelevant. Or rather if ERTMS had been introduced to a time line as originally intended, it should have been.

If this signal had been fitted with the GWML ATP system or TPWS, because this equipment would have been controlled from the equipment location case, the train would have received a brake application IF the signal was supposed to be red. This would not have made any difference to the first train in this incident. But it would likely have applied the brakes for the second train.
 
Last edited:

Taunton

Veteran Member
Joined
1 Aug 2013
Messages
12,236
But the comment wasn't specifically talking about the Wingfield signalling, it was discussing the future (ETCS?) option of removing lineside equipment, by which time all the things to potentially go wrong would be entirely hidden and only detectable to signalling software engineers.
One has to be very cautious not to throw away two centuries of signalling experience. The German Maglev accident was an unfortunate outcome of feeling standards of signalling, line clearance, watertight procedures, and so on (and indeed, crashworthiness) are not applicable with the brilliant new technology.
 

Nicholas Lewis

Established Member
Joined
9 Aug 2019
Messages
7,996
Location
Surrey
There were no indications at all on the panel when it was in Derby PSB (as was common for runs of auto signals on plain line sections) - I'd be surprised if this wasn't replicated on the workstation that it was recontrolled to.
Indeed only controlled signals were indicated on most PSBs but they were added for autos when SSI's came into use as effectively every signal was controlled by the SSI and data acquisition from the lineside almost came for free compared to all the extra cabling and non vital systems that would have been need to implement it on PSBs . In this situation the lineside signalling was calling for a single yellow at DY586, thus panel would have shown green (signal off) as the same relay drives the panel indication, but driver is confronted by a RED and SPAD's but has stopped beyond DY586 overlap thus allowing DY584 to show a yellow. So we have driver of first train now onto the signaller reporting the incident and probably thinking there dealing with a track circuit failure, also DY586 would now show red on panel as lineside signalling would have had the HR relay down thus displaying a Red aspect (but its connected to Yellow), meanwhile train in rear has sighted DY586 and its showing a yellow vice a red (they would receive same AWS warning of course) and continues past and the last line of defence the rear tail lights have come into play fortunately.

The actions of either driver or not an issue they are obeying signals displayed. The signaller has no information available to them to indicate there is an issue although as DY586 had been disconnected perhaps it should have prompted them to consider whether there was an issue but given the wide areas signallers cover they shouldn't be asked to question the integrity of the signalling system especially as the track circuit indications would have indicated nothing amiss.

As i say this is simply a case of not following the signal maintenance testing handbook and as to whether there are underlying or contributory factors will be the NRs investigation team to review and feedback to RAIB who may reveal more in the safety digest if they believe wider learning is necessary.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,551
Location
Torbay
Unlikely TPWS was fitted. This is one of the weaknesses of the majority of signals not being provided with TPWS. TPWS is a mitigation against the worst case scenario of a collision at a junction or a level crossing.
Sometimes a plain line signal protecting a platform is also fitted where there's a dense mix of stopping and non-stopping services that raises the risk of a rear-end collision. That's not the case here. When the system was installed originally, whether or not an individual signal was equipped was determined based on a risk score calculated for every signal in the UK that took into account train service characteristics, loadings, particulars of the track layout and collision potential. Most junction protecting signals exceeded the risk threshold for fitment easily, unless conflicts were already protected in interlocking effectively by flank protection.
Given that the signal was disconnected and reconnected due to planned track maintenance work, that implies that the multicore cable from the equipment location case to the signal head was disconnected and pulled clear of the track. This is done so that track work does not damage the cable. As I say above, this is after all the interlocking and control circuitry.
Also, there are often 'disconnection boxes' in the cabling between location cabinets and signals, points, and track circuits, especially when the cable has to cross under tracks to get to the equipment. These are small weatherproof junction boxes provided primarily to split the cable and limit the length requiring replacement if track maintenance activity damages a cable. Disconnection by the temporary removal of just the undertrack section of cable to the dis. box might be carried out prior to major track renewals. Each such terminating point in a cabling system is an opportunity for individual cores to be transposed by mistake at reconnection however, especially in older installations where dis. boxes were added later and might not be shown in official drawings.
 

Nicholas Lewis

Established Member
Joined
9 Aug 2019
Messages
7,996
Location
Surrey
Also, there are often 'disconnection boxes' in the cabling between location cabinets and signals, points, and track circuits, especially when the cable has to cross under tracks to get to the equipment. These are small weatherproof junction boxes provided primarily to split the cable and limit the length requiring replacement if track maintenance activity damages a cable. Disconnection by the temporary removal of just the undertrack section of cable to the dis. box might be carried out prior to major track renewals. Each such terminating point in a cabling system is an opportunity for individual cores to be transposed by mistake at reconnection however, especially in older installations where dis. boxes were added later and might not be shown in official drawings.
Good point although testing is still required and its a simple enough test to prove aspect sequence.

Hopefully the safety digest will reveal whether it was NR staff or contractors
 

Tim M

Member
Joined
9 Jul 2016
Messages
204
Hopefully the safety digest will reveal whether it was NR staff or contractors
Ummm. Not sure why it’s important to distinguish between NR staff and contractors. RAIB reports and digests are not designed to be in the blame game. All staff need to work together and to the same standards, irrespective of employer.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,551
Location
Torbay
its a simple enough test to prove aspect sequence.
A simple correspondence of control system output relay states to observed signal aspects would have been sufficient to catch the mistake before handing back. The cabinet in the RAIB photo looks like it has relays in it rather than SSI modules, so it should have been very easy to do.
 

HSTEd

Veteran Member
Joined
14 Jul 2011
Messages
20,281
Doesn't matter how "simple" the test is, perform it enough times and eventually something will get through.

This is why administrative controls are at the bottom of the safety prereference stack in risk assessments.....
 

Nicholas Lewis

Established Member
Joined
9 Aug 2019
Messages
7,996
Location
Surrey
Doesn't matter how "simple" the test is, perform it enough times and eventually something will get through.
OK we don't have the facts but the issue here is was the test done though? Also you need to do a wire count first before you test so theoretically two lines of defence. Anyhow we will just have to wait out safety digest and see what else RAIB reveal.
 
Status
Not open for further replies.

Top