Sub-System Requirements
Specification: TCAS
Lalit Patil
[Link]@[Link]
1. System Overview & Scope
The Vehicle Control Unit (VCU) serves as the primary processing and interfacing hub for the
onboard TCAS/ATP (Automatic Train Protection) sub-system. From the VCU
implementation perspective, the VCU must execute speed/distance monitoring (SDM),
evaluate dynamic brake curves, process movement authorities (MA), and enforce automatic
braking if target speeds or movement limits are exceeded.
2. Hardware Interface Requirements for VCU
Below is the complete hardware interface breakdown required by the VCU to integrate with
TCAS sensors, communication units, and train actuation lines.
VCU Data
Interface Physical Protocol / Flow & Purpose /
Name Port / Media Standard Signal Description
Type
Receives
Movement
Dual Authorities (MA),
Redundant Bi- track profile data
TCAS TRDP / CIP /
M12 Ethernet directional from Radio
Radio / TCP/IP (EN
(100Base-TX : Digital Modem (GSM-
DMI Bus 50159)
/ 1000Base- Packets R/LTE-R) and
T) Driver Machine
Interface (DMI)
inputs.
Communicates
Dual CAN / Bi- operational
Train Bus MVB directional modes, throttle
CANopen /
/ Vehicle (Multifunctio : Control & status, and fault
IEC 61375
Network n Vehicle Status diagnostics with
Bus) frames main locomotive
control units.
VCU Data
Interface Physical Protocol / Flow & Purpose /
Name Port / Media Standard Signal Description
Type
Receives Doppler
radar speed
Input:
Isolated RS- metrics and pulse
Odometry Differential
422 / Serial Proprietary / counts from
/ Radar Pulse /
(or Frequency NMEA 0183 wheel encoders
Interface Serial
inputs) for wheel-slide
Stream
protected speed
calculation.
Receives
RFID / trackside
RS-422 / Input:
Balise EN 50155 / RFID/Balise
Serial or Digital
Reader Standard Serial location updates
Ethernet Telegrams
(BTM) to reset odometry
error margins.
Directly trips the
Output:
train line
Emergenc Hardwired Fail-Safe Relay De-
Emergency Brake
y Brake Relays (24V Discrete I/O energizatio
valve upon TCAS
(EB) Loop – 110V DC) (SIL-4) n (Current
overspeed or
Loop)
system failure.
Drives
Digital PWM proportional
Service Output:
/ Analog Analog service brake
Brake Analog
Output (0– Current/Voltag application to
(SB) Control
20mA / 0– e Loop bring train down
Actuation Signal
10V) to allowed speed
curve smoothly.
VCU Data
Interface Physical Protocol / Flow & Purpose /
Name Port / Media Standard Signal Description
Type
Drops main
power contractor
Traction Dry Contact Output:
Fail-Safe / cuts propulsion
Cut-off Relay / Digital
Discrete I/O torque when
Loop Optocoupler High/Low
TCAS initiates
brake application.
Provides global
GPS / positioning, clock
RS-232 / RS- NMEA 0183 / Input:
GNSS synchronization,
422 UBX Serial Data
Module and backup speed
estimation.
Sends time-
stamped log data
(speed, target
Output:
Event EN 62625-1 distance, braking
Ethernet / Serial /
Recorder (Black Box commands,
RS-485 Packet
(JRU) Protocol) operator
Stream
acknowledgments
) for legal
logging.
Accepts primary
locomotive DC
Dual power supply
Power 110V DC (EN
Redundant Input: DC with surge
Supply 50155 Class
Terminal Power suppression,
Interface S2)
Block hold-up time
(20ms), and
isolated grounds.
3. Detailed Sub-System Requirements
1. 3.1 Functional Requirements
• SRS-VCU-01 (Speed & Distance Monitoring): The VCU shall continuously
calculate the instantaneous train speed, deceleration distance, and safe target braking
curve based on wheel encoder inputs, radar data, and RFID balise position tags.
• SRS-VCU-02 (Movement Authority Enforcement): The VCU shall issue a
visual/audible warning to the operator via DMI when actual speed exceeds the
permissible speed curve by $+2\text{ km/h}$.
• SRS-VCU-03 (Automatic Service Brake Application): If the speed exceeds the
ceiling speed curve by $+4\text{ km/h}$, the VCU shall output a proportional signal
to the Service Brake interface to reduce speed below safe thresholds.
• SRS-VCU-04 (Emergency Brake Application): If the speed exceeds the ceiling
speed curve by $+6\text{ km/h}$ or if a Red Aspect (SPAD avoidance) limit is
reached, the VCU shall immediately break the 110V Emergency Brake relay loop.
• SRS-VCU-05 (Propulsion Interlock): Whenever a brake command (Service or
Emergency) is commanded by TCAS, the VCU shall assert the Traction Cut-off
digital output to disable engine/motor propulsion.
2. 3.2 Non-Functional & Safety Requirements
• SRS-VCU-06 (Safety Integrity Level): All safety-critical hardware interfaces
(Emergency Brake, Speed calculation, Balise processing) and execution threads on
the VCU shall meet SIL-4 compliance according to CENELEC EN 50126, EN
50128, and EN 50129.
• SRS-VCU-07 (Latency & Response Time): The time delay between TCAS
overspeed detection and VCU Emergency Brake output assertion shall not exceed $\le
100\text{ ms}$.
• SRS-VCU-08 (Fail-Safe Default): In the event of a total loss of power, processor
fault, or loss of communication with the TCAS radio/radar for $>500\text{ ms}$, the
VCU discrete outputs shall default to a de-energized (brake applied) state.
• SRS-VCU-09 (Environmental Standards): The VCU hardware chassis and
connectors shall conform to EN 50155 for railway rolling stock (vibration, shock,
temperature range $-40^\circ\text{C}$ to $+70^\circ\text{C}$, and humidity).
• SRS-VCU-10 (Electromagnetic Compatibility): Hardware interfaces must meet EN
50121-3-2 standards for EMC compliance to prevent interference from traction
motors and high-voltage catenary lines.
4. Key Implementation Risks & Mitigation Strategies
1. Wheel Slip / Slide Error:
o Risk: In adverse weather, wheel locking distorts speed/distance calculations.
o Mitigation: VCU cross-references wheel tachometers with Doppler radar and
GPS data using a Kalman filter algorithm.
2. Signal Noise & EMI in Cable Runs:
o Risk: Electrical switching noise from locomotive traction converters triggering
false emergency brake applications.
o Mitigation: All low-level sensor inputs (encoders, serial lines) must use
shielded twisted pairs (STP) and galvanic isolation up to $1.5\text{ kV}$
RMS on VCU interface boards.