Slide 11
Slide 11 text
30th anniversary of the research group
Design of safety-critical systems
Results
Safe Driver-Machine Interface
for ERTMS Based Train Control
• Architecture
design: reactive
safety (SIL 2) with
error detection
• Verifying
requirements:
analytical models,
simulation,
testing
11
On-board
control
computer
LCD DISPLAY
SAFE DMI
EXCLUSION LOGIC
LCD
lamp
Vcc
………
Keyboard
Speaker
ERTMS TRAINBORNE
SYSTEMS
commercial field bus
wireless
interface 2,0E-07
3,0E-07
4,0E-07
5,0E-07
6,0E-07
7,0E-07
8,0E-07
9,0E-07
1,0E-06
1,1E-06
0,5 0,6 0,7 0,8 0,9
Control flow checking coverage
Hazard rate
min
mean value
max