MTCS Modular Train Control System



Similar documents
Foxboro Evo Process Automation System

FAdC i FRAUSCHER Advanced Counter i

Fiessler Programmable Safety Center. Flexible Hard- and Software concept. Available with a safe bus system or/and two counter inputs

NCC Blade Network Communication Controller

Safety PLC for rolling stock Safety Controller Pluto Harsh Environment

imc BUSDAQ autonomous intelligent synchronized Field bus data acquisition - from stationary to mobile imc productive testing

applicomio Profibus-DP

Short Form Catalogue. Alarm Systems. Reliable Supervision and Control

4 non-safe digital I/O channels 2 IO-Link Master V1.1 slots. Figure 1. Figure 2. Type code. TBPN-L1-FDIO1-2IOL Ident no

Modular I/O system Rugged Modular I/O System Solutions EN certified for railway applications

ISIO 200. Binary Input/Output (I/O) Terminal with IEC Interface

EtherCAT Cutting Costs with High-speed Ethernet

ISpac isolators. the perfect system

Remote Monitoring and REC 501 Control Unit Product Guide

Programmable set for Ethernet Modbus/TCP in IP20 TI-BL20-PG-EN-8

Set for PROFINET IO in IP20 TI-BL20-EN-PN-4

Connectivity solutions for transport automation

TRACTION NETWORK MONITORING AND PROTECTION SYSTEM SMTN-3 CITY ELECTRIC TRANSPORT RAILWAYS METRO INDUSTRY

Fiessler Programmable Safety Center. Flexible Hard- and Software concept. Expandable with a safe bus system

zseries 18-Slot Chassis 18-Slot 3U PXI Express Chassis with AC Up to 8 GB/s

Programmable set for Ethernet Modbus/TCP in IP67 TI-BL67-PG-EN-2

Straton and Zenon for Advantech ADAM Copalp integrates the straton runtime into the ADAM-5550 device from Advantech

Provides one channel for Ethernet over existing

Data Sheet Fujitsu PRIMERGY BX400 S1 Blade Server

MiTraC Train ConTrol and ManaGeMenT system. Propulsion & Controls. This is a running title

Data Sheet FUJITSU Server PRIMERGY CX420 S1 Out-of-the-box Dual Node Cluster Server

TM7BDM8B expansion block - TM7 - IP67-8 DI/DO - 24V DC A - M8 connector

Using installed Fieldbus Wiring to carry Ethernet Communications

JNIOR. Overview. Get Connected. Get Results. JNIOR Model 310. JNIOR Model 312. JNIOR Model 314. JNIOR Model 410

MACHINEMATE. CNC SYSTEM Hardware SPECIFICATION

CONTROLS DATA MANAGEMENT PROCESS AUTOMATION EUROCUBE. General purpose single phase thyristors and solid state relays Product data.

MITRAC 500. Driven by Reliability. Propulsion & Controls

SuperIOr Controller. Digital Dynamics, Inc., 2014 All Rights Reserved. Patent Pending. Rev:

How To Use The Vacon 0 Machinery

Telephone- and leased line modem for industrial applications TD-36

CompactLogix Power Supplies Specifications

Overview and Applications of PROFINET. Andy Verwer Verwer Training & Consultancy Ltd

Process Alarm Solutions

ABB North America. Substation Automation Systems Innovative solutions for reliable and optimized power delivery

Bar code scanners CLV45x / CLV450 / Standard Density

Company Profile.

Ponto Series. A new concept for automation

Waveguide Access Point WGA631. Product Guide

ABB RTU560A Series CMU & Modules

THEME Competence Matrix - Electrical Engineering/Electronics with Partial competences/ Learning outcomes

Vibration analysis and monitoring Compact. Powerful. Modern technology.

Syslogic Product Overview. Embedded Computer HMI Systems Single Board Computer Railway Computer

EP2002 Distributed Brake Control

Motherboard- based Servers versus ATCA- based Servers

Energy Depot GmbH PRODUCT AND APPLICATION GUIDE. Total Monitoring Solution for PV. Delivering Solutions for Energy Management

evm Virtualization Platform for Windows

PROCESS AUTOMATION REMOTE I/O SYSTEMS RPI REMOTE PROCESS INTERFACE IN THE SAFE AREA OR IN ZONE 2

Scout 1U Rackmount Computer

Provides one channel for Ethernet over existing

sigpod Press ASSEMBLY PRESS-FIT MONITORING SYSTEM BENEFITS FEATURES

HSP GmbH Zum Handwerkerhof Wendelstein Tel / Fax: / Web: HSP@hsshsp.de NTG-3000.

S-series DC to DC Power Supply

Optimize your simple machines... Modicon M218 Selection Guide

STRATO LED Drivers 70W, Single output

/ Our accessories complement all PV systems, simplify installation and ensure that the system meets the required safety standards.

Philips remote monitoring and control systems

High Availability and Safety solutions for Critical Processes

DeltaV SISnet Repeater

Cisco Communication Media Module

RTM X42 Multi-Channel Radio Transmission Tension Monitoring and Control System

Data Sheet FUJITSU Storage ETERNUS LT260 Tape System

Power network telecommunication


SAN Conceptual and Design Basics

Current valve. for AC 24 V pulse/pause control of electrical loads up to 30 kw

Set for Profibus DPV1 in IP20 TI-BL20-DPV1-8

Wireless Field Data Backhaul

Data Sheet FUJITSU Server PRIMERGY CX400 M1 Multi-Node Server Enclosure

Power over Ethernet technology for industrial Ethernet networks

MICROSENS. Central 48 V DC Power Supplies for PoE-Components. Description. Features

Rack mounted telephone- and leased line modem for industrial applications

AS-i 3.0 Gateways, PROFIsafe via PROFIBUS or PROFINET

DCS Data and communication server

Series Six Plus Programmable Controller

UNIVERSAL TRAFFIC CONTROLLER

NEW GENERATION PROGRAMMABLE AUTOMATION CONTROLLER

FM4100 USER MANUAL V1.4

FLEET MANAGEMENT & CAR SECURITY SYSTEM GPRS/GPS

WANic 800 & or 2 HSSI ports Up to 52 Mbps/port. WANic 850 & or 2 T3 or E3 ports Full-speed CSU/DSU. WANic 880.

MITRAC Driven by Reliability. Propulsion & Controls

StruxureWareTM for Buildings

RISH EM 3490 DS Dual Source Energy Meter RISH EM 3490 DS. Application : Product Features:

Data Sheet Fujitsu PRIMERGY BX600 S3 Blade Server

TK800-Series Industrial GPRS / UMTS / LTE Router

Compact multiprotocol I/O module for Ethernet 8 digital PNP inputs and 8 digital PNP outputs 2 A TBEN-L1-8DIP-8DOP

Early Warning Fire Detection and Integrated Security Solution. System Overview

Digital input modules

Product overview brochure. ABB Medium Voltage Products Our one-stop approach for every medium voltage application

The Intel NetStructure SIU520 Signaling Interface

Safety compliance. Energy management. System architecture advisory services. Diagnostics. Network topologies. Physical and functional partitioning

LNG Monitoring. Fiber-Optic Leakage Detection System. Pipeline leakage detection. Regasification and liquefaction monitoring

SNMP-1000 Intelligent SNMP/HTTP System Manager Features Introduction Web-enabled, No Driver Needed Powerful yet Easy to Use

Transcription:

MTCS Modular Train Control System SIL 4 Railway Computer for Rolling Stock and Wayside Applications In Accordance with: EN 50155 EN 50121-4 EN 50129 EN 50126 EN 50128

The MTCS Approach... 4» MTCS Modular Train Control System» Safety Compliance with EN 5012x» Environmental Compliance with EN 50155» Long-Term Availability MTCS Architecture...8» Safe MTCS Controller» Safe MTCS Remote I/O Box» Safe MTCS CPU Component» Safe MTCS I/O Components» MTCS Configuration Examples» Safe MTCS Real-Time Ethernet Topology» MTCS Software Architecture» MTCS Safety Guaranteed by TÜV Certificate MTCS Application Areas... 18» Rolling Stock» Wayside MTCS Benefits Summary... 20 The governments of many countries have increased their safety standards in mass transit and freight transport and / or work on nationwide traffic regulation programs, e.g.:» SIRF stage 2 (Germany)» PTC Positive Train Control (USA)» ETCS European Train Control System» CTCS Chinese Train Control System» KLUB-U Russian Train Control System

The MTCS Approach MTCS is an open and modular railway computer platform based exclusively on standard hardware and software. It is certifiable up to SIL 4 in all its single parts and complies completely with the EN 50155 and EN 50121-4 railway standards. MTCS is designed to operate in rolling-stock applications such as Automatic Train Control (ATO) and Automatic Train Protection (ATP) as well as in wayside applications like interlocking systems. MTCS consists of the safe controller, the safe I/O functions and the communication interfaces to the outside world. The final safety level of MTCS is scalable and as such solely determined by the application requirements resulting in an optimum price / performance. MTCS Modular Train Control System MTCS is the first computer system ever in the history of the railway industry that separates the control electronics the computer hardware from the real control function the application software. Unlike existing solutions that are proprietary and show a fixed hardware/software configuration which is closed to the access of the end user, MTCS opens up the essential interfaces between the control electronics and the application. MTCS is therefore the first and only railway computer that is based on defined open standards for hardware, software and communication. Its modularity makes it configurable for every control function inside and outside the train and scalable to any required SIL level. MTCS comes with certification packages from TÜV Süd, drastically reducing the time of the certification process. The SIL 4 certifiable and real-time capable kernel supports the partitioning of the application dependent on the required safety level, thus reducing the software development effort. The non-safe and Linux based part for communication and service is completely separated. It guarantees that the system is open towards the external world. The data transfer of the inputs and outputs is realized via a safe real-time Ethernet. Based again on an industry standard, also the safety of the I/O communication is proven by TÜV Süd. Being a totally open platform concerning software and hardware, MTCS is the first and only railway computer that offers a separation of the rail service from the electronic control system behind. This unique feature allows railway system suppliers to concentrate on their core business. It also facilitates the market entry for small and medium-size companies. And it enables rail operators to become their own general contractor, keeping full transparency of their project at any time. 4 5

Safety Compliance with EN 5012x MTCS complies with the requirements of the EN 5012x family of railway standards developed by CENELEC, based on IEC 61508 (Functional Safety of Electrical / Electronic / Programmable Electronic Safety-related Systems):» EN 50126: Railway Applications The Specification and Demonstration of Reliability, Availability, Maintainability and Safety (RAMS)» EN 50128: Railway Applications Communications, signaling and processing systems» EN 50129: Railway Applications Communications, signaling and processing systems Safety related electronic systems for signaling MTCS components come with SIL 4 certification packages for the hardware, with complete support for the safe operating system QNX (PikeOS on request), including safe protocols, CST layer, I/O transfer layer etc. Long-Term Availability MEN guarantees long-term availability of all parts of the MTCS for a minimum period of 10 years. After this period it might happen that single chips or electronic components can be made obsolete by one of our suppliers. In the worst case, this might result in the exchange of one or the other board in the MTCS system. As all these boards are standards-based, the application itself will remain untouched to a great extent. If it becomes necessary to exchange such a standard board, MEN delivers a change effect analysis together with the redesign. This ensures that the effort for re-porting of the application as well as for a potential re-certification will be reduced to a minimum. Using an open system like MTCS means that product obsolescence management can be limited to single standardized parts of a train control system or interlocking system. It will never again affect and endanger the complete train or wayside function. Environmental Compliance with EN 50155 MTCS also complies with the EMC regulations of EN 50121-4: Railway Applications Electromagnetic compatibility. (Emission and immunity of the signaling and telecommunications apparatus). 6 Linux E SCAD ANSY S PLC General Purpose User Software Sof t» Operating temperature class Tx: 40 to +70 C (10 minutes up to +85 C) with qualified components» Shock: 50 m/s², 30 ms (EN 50155 (12.2.1 1) / EN 61373)» Vibration (function): 1 m/s², 5 Hz 150 Hz (EN 50155 (12.2.1 1) / EN 61373)» Vibration (lifetime): 7.9 m/s², 5 Hz 150 Hz (EN 50155 (12.2.1 1) / EN 61373)» Humidity, dust: conformal coating» PSU class 2 hold-up times with just one wide range PSU 14.4 to 154 V» 14.4 to 154 V also supported by I/O components» EMC regulations:» EN 50121-3-2 (tables 5 and 6) / EN 55011 (radio disturbance)» EN 50121-3-2 (table 9) / IEC 61000-4-6 (ESD)» EN 50121-3-2 (table 9) / IEC 61000-4-3 (electromagnetic field immunity)» EN 50121-3-2 (table 8) / IEC 61000-4-4 (burst)» EN 50121-3-2 (table 8) / IEC 61000-4-6 (conducted disturbances) Sa Appl fe User i ca t io n C MTCS complies with all environmental requirements of EN 50155 (Railway Applications Electronic equipment used on rolling stock) for in-vehicle operation: QNX MTCS Hardware 7

MTCS Architecture The heart of the MEN Train Control System is the MTCS controller which delivers state-of-the art computing performance based on x86 PC technology. The MTCS controller consists of a safe part and what is called an unsafe (general purpose) part. The MTCS controller can be used as a standalone device and in combination with up to 63 remote I/O boxes. Safe MTCS Controller The communication inside the MTCS system between the safe MTCS controller, safe I/O boards and safe remote I/O boxes is based exclusively on a safe standard real-time Ethernet. Its modular configuration enables the MTCS system to communicate with other train systems like service or diagnosis units via any type of wired or wireless interface. Additionally, fieldbus interfaces can be implemented to connect into other networks like MVB, CAN, Profinet etc. This makes it easy to integrate into a TCN network as well as into regionally different Train Control Systems like PTC, ETCS, CTCS, ATCS or Klub-U. MTCS is an application-ready platform, allowing the immediate start of the application development and giving the user complete control over the functionality of the whole system. While the unsafe part of the application runs under a Linux operating system, the safe part of the application runs in a safe kernel of the real-time operating system QNX. The safe application can either be directly programmed with the Posix standard C language or optionally Flexisafe safe PLC. MTCS is SIL 4 certifiable and comes with pre-certified hardware in combination with pre-certified software and corresponding certificates from TÜV Süd.» The high level of modularity of the hardware and the software of the MTCS system allows to use MTCS as the sole platform for a multitude of varying rail applications.» As the whole MTCS system is based on standards, also the life-cycle cost of each rail project can be drastically reduced.» The pre-certification of the MTCS hardware and software results in significant cost and time savings during computerization of the train, whether a vehicle is new or is being refurbished. The MH50C MTCS controller supports a modular built-to-order configuration and consists of:» Certifiable safe CPU board with local redundancy» Up to 6 I/O boards:» Either certifiable safe I/O boards» Or interface boards to Ethernet, WiFi, GPS, COMs, CAN, MVB etc.» Or a combination of both» 14.4 to 154 V DC wide-range voltage supply» QNX safe real-time operating system» Linux unsafe operating system» SIL 4 certification packages by TÜV Süd To raise availability of the safe MTCS system, the functionality of two MTCS controllers can be clustered in one enclosure. MH50C comes in a compact half 19" housing based on the established CompactPCI standard. The CPU board and I/O boards comply with the robust 3U Eurocard format. The system can be wall or rackmounted and supports forced air cooling. 8 9

Safe MTCS Remote I/O Box Safe MTCS CPU Component The central element of MTCS is the safe CPU board F75P, a standard CompactPCI board that is designed to execute safety-critical applications as well as unsafe applications and comes with a dedicated certification package: An extension of the MTCS system by remote I/O boxes (KT4, KT6, KT8) becomes necessary if:» The I/O functions required exceed the capabilities of the MTCS controller» The actors and sensors are located far away from the MTCS controller Each MTCS remote I/O box consists of:» Up to 4, 6, or 8 certifiable safe I/O boards» Real-time Ethernet interface with chassis configuration switch» 14.4 to 154 V DC wide-range PSU» Certification packages by TÜV Süd for the safe I/O The remote I/O boxes are based on 19" technology, with a reduced depth of less than 160 mm to provide a compact space-saving packaging. They can be either wall mounted or installed on DIN rail mechanics.» 2 redundant Intel processors to execute safety logic» 3rd Intel CPU as general purpose and I/O communication processor» Independent supervisors for each block» Fail-safe and fail-silent board architecture» Hot or cold stand-by» Clustering of two F75P to raise availability» Event logging with intelligent board management controller In the MTCS standard configuration and as such included in the certification packages available, the two independent control processors run the safe deterministic real-time operating system QNX Neutrino, while the unsafe general purpose processor operates under Linux. Other MTCS configurations can also work with safe real-time operating systems such as PikeOS, Integrity or VxWorks even in a combination of different safe operating systems to support optional diversity in software on both kernels. 10 11

Safe MTCS I/O Components MTCS Configuration Examples MTCS System Controller: MH50C Configuration Example 1 Option slots populated with safe I/O» 8 digital outputs, SIL 4 (each using 2 pins)» 16 digital inputs, SIL 4 (each using 2 pins)» 8 frequency input channels, SIL 4 The SIL 4 certified safe I/O boards comprise the typical functions required for railway applications and come with dedicated certification packages:» K1 8 binary outputs» K2 16 binary inputs» K3 safety relay outputs in preparation» K4 4 frequency inputs, used to measure the speed of the train via wheel sensors» K5 analog outputs in preparation» K6 analog inputs in preparation All I/O components connect via spring cage terminal blocks for fast installation thanks to reduced wiring. They are fully isolated and support the full voltage range from 14.4 to 154 V DC. Generally a single K board can be used to reach SIL 2. Two combined boards are required to reach SIL 3 and SIL 4. This scalable approach reduces cost in case a lower SIL level is sufficient. The safe MTCS I/O cards are designed to be used inside the MH50C MTCS controller as well as to configure the MTCS remote I/O boxes:» MH50C accommodates up to 6 safe I/O cards» KT8 accommodates up to 8 safe I/O cards» Further remote I/O boxes will be able to accommodate smaller numbers of safe I/O cards for installation areas with very limited space. MH50C Configuration Example 2 Option slots populated with safe I/O» 8 digital outputs, SIL2» 16 digital inputs, SIL 2» 4 frequency input channels, SIL 2» MVB master» 2 slots reserved for future use This configuration targets SIL 2 safe I/O applications: each safe I/O card is only assembled once. Both configuration examples are based on the barebone configuration, which includes the safe F75P CPU board, real-time Ethernet card connecting distributed safe I/O, a wide-range PSU and system supervision. 12 13

Safe MTCS Real-Time Ethernet Topology MTCS Remote I/O Boxes: Configuration of a KT8 providing» 8 SIL 4 outputs (each using 2 pins) + 8 SIL 2 outputs» 16 SIL 4 inputs (each using 2 pins) + 16 SIL 2 inputs» 4 SIL 4 frequency input channels (using 2 separate frequency counters) MTCS Controller Real-Time Ethernet Master BC Configuration of a KT4 providing MTCS Controller MTCS I/O MTCS I/O BC BC I/O Boards I/O Boards Real-Time Ethernet Master BC» 8 SIL4 outputs (each using 2 pins)» 16 SIL2 inputs» 4 SIL2 frequency input channels I/O Boards MTCS System Controller in Combination with Remote I/O Boxes: MTCS Controller I/O Boards The complete MTCS I/O no matter whether it is part of the MH50C controller or located in the remote I/O boxes is connected via real-time Ethernet. Thus, the application can treat all I/O functions in the same way. All remote I/O boxes are connected to the controller in a ring topology, which tolerates single failures. For example, in case of a broken cable, the system is still fully operational, as all I/O boxes can still be reached from the other end of the ring. MTCS Remote I/O 14 MTCS Remote I/O MTCS Remote I/O 15

MTCS Software Architecture MTCS Safety Guaranteed by TÜV Certificate Safe Domain (CPU Board) User Safety Application User Safety Application Safety Communication Layer Compare Safety Communication Layer Compare Safe QNX/Safe BSP Safe QNX/Safe BSP TÜV Certificate TÜV Assessment Report Safety Case Safety User Guide Communication (Shared RAM, Virtual Ethernet) I/O Domain (CPU Board) Black Channel F75P QNX BSP None-Safe Application Communication Diagnosis, Services Driver Libraries Linux (Soft Real-Time) QNX Drivers External Interfaces Safe Domain (I/O Board) Safety Communication Layer The MTCS software distinguishes between the safe and the unsafe domain in order to save cost and time for application development and certification. This separation allows to develop unsafe ty relevant applications separately from safe applications. Unsafe applications cannot influence safe applications because they are executed on a separate processor running a standard Linux operating system. In order to guarantee appropriate communication between the safe controller and the safe I/O functions via real-time Ethernet, the so called black channel approach is applied. The method to transport safe data over untrusted communication is defined by EN 50159. 16 The complete MTCS solution may contain safe and unsafe parts. For the safe parts of the system two certification packages are provided:» For the F75P CPU board of the MH50C system controller including QNX Board Support Package» For the I/O cards including QNX drivers Each SIL 4 railway certification package according to EN 5012x includes a number of documents:» Safety User Guide including the safety-relevant application requirements, a detailed description of the hardware and instructions for appropriate operation» Safety Case describing the concepts for reaching functional safety as well as all safety and quality-relevant processes and measures to meet the SIL 4 requirements» Assessment report and SIL 4 certificate from TÜV SÜD (German Technical Inspection Agency) 17

MTCS Application Areas Wayside Rolling Stock Gear Control Fuel Control Wheelslip Control Driver Display Driver Cab Controls/Indicators MTCS Controller MTCS Remote I/O Valves, Relays, Sensors MTCS is both well suited for use in new interlocking systems and for a soft modernization and automation of older relay interlockings. Existing outside facilities can be preserved and adapted. The extremely compact inside facility of an interlocking system is clearly separated and forms the safe platform (SIL) for the control and automation layer. MTCS is compact, safe and robust in accordance with EN 50155 and EN 50121-4 (EMC). MTCS enables: Brakes Ethernet Train Bus (MVB, CAN) I/O Bus (CAN, Profibus) MTCS is well suited for use in new train models as well as for refurbished trains. Thanks to its modularity, it is easy to install and retrofit safety and automation functions with MTCS in any type of older rail vehicle as well.» Introduction of ETCS (European Train Control System) L2/L3 for optimization of safety and track load» Halving of the resulting opportunity cost for relay interlocking systems» Reduction of dependence from single suppliers, resulting in a growing service offer» Increase of the performance of the interlocking systems» Decrease of life cycle cost» Avoidance of the costly total replacement by electronic interlocking systems (incl. outside facilities)» Installation of simpler, smaller and standardized inside facilities» Longer operating life of the outside facilities» Lower cost for the increase of total capacities» Low cabling cost thanks to standardized Ethernet technology MTCS is:» Compact, safe and robust in accordance with EN 50155» A versatile, consistent, open and safe platform for all functions like ATO, ATP, PTC, ETCS» Safe control system plus communication system all in one, but strictly partitioned» Fully compatible with EN50155 (incl. all temperature and voltage ranges)» Safe remote I/O, connected via redundant, real-time Ethernet» The interface to all existing train communication such as MVB, WTB, CAN» The wireless communication interface to the outside world through GSM-R, GPS, WLAN 18 19

MTCS Benefits Summary Safety Open Hardware Standard Safety levels SIL 4, SIL 3, SIL 2, SIL 1, SIL 0 Redundancy Fail-silent Fail-safe Fail-operational Flexible configuration of safety levels results in optimum price/performance Provides safety by means of 2 control processors on a single CPU board The system provides the correct service or remains silent. The system will not endanger lives or property when it fails. Clustering of hardware components if the system must stay operational Standard PC hardware architecture Main controller with Intel CPU board architecture CompactPCI State-of-the-art X86 host controller» Safety execution with 2 redundant processors» 1 general purpose processor» Independent supervisors for each block Robust industry-proven backplane and computer board standard 19" systems Well-known enclosure standard 3U Eurocard format Robust board standard Open Safe Platform I/O connectivity Spring-cage terminal blocks make connection easy and reduce cabling Safe API (Application Interface) QNX Real-time Operating System» POSIX compliant» C programming language Partitioning of the application for different safety levels 14.4 to 154 V DC wide-range PSU International railway compliance with just one system Open Communication Extensions Open General Purpose Platform Railway fieldbusses Connection to existing TCN network via MVB & WTB interface boards Linux Operating System Development of unsafe part of the application in familiar standard software environment Other fieldbusses Connection to existing train devices via CAN, ProfiNet etc. interface boards Ethernet Connection to standard switches and routers Open I/O Ethernet communication Real-time Ethernet communication Functional safety over Ethernet» Makes use of standard cabling, line interfaces» Connects main control system and remote I/O boxes Guarantees deterministic behavior on standard communication protocol Black channel for safe TÜV certified I/O communication WIFI, radio, GPS, RS485 Functionality Open API for C or safe PLC Connection to all popular in-vehicle and external communication interfaces Freely programmable or Flexisafe PLC software environment Safe modular railway I/O up to SIL 4» Digital inputs/outputs (wide range EN 50155 compliant)» Analog inputs/outputs (wide range EN 50155 compliant)» Frequency inputs (detection of hold, frequency, period, pulse width, direction distance, encoder supply)» Relay outputs (wide range EN 50155 compliant) Safe programming Physical software separation between safe and unsafe domain» In C language» Or based on Soft SPS» Or ANSYS SCADE model-based Saves time and cost for application development and certification LInux For general purpose and open communication 20 21

Standards Compliance EN50155 & EN 50121-4 Fully proven for rolling stock and wayside railway environments EN 50126/128/129 (based on IEC 61508) Developed for functional safety from SIL 0 to SIL 4 SIL 4 certification packages with TÜV Süd certificate Modular hardware/software packages make certification of the final application easy and fast Customer Support Long-term availability Life-cycle management 10 years guaranteed to save time and cost investment of the project Secures overall operability of the application when single components need to be substituted Development services Environmental test services Worldwide sales support Consultancy Experienced supplier of reliable embedded computer solutions Defining the appropriate solution together with the customer IRIS certified partner of the railway industry for many years February 2015 Copyright MEN Micro Inc. / MEN Mikro Elektronik GmbH / MEN Mikro Elektronik SAS All rights reserved. 22

www.men.de www.men-france.fr www.menmicro.com