“CBTC.valid” —A New Method to Validate Complex Train Control Architectures
Joerg Schuette · 2018
Train control systems have developed over the last decades into complex HW/SW-systems that control CBTC-operations or even unmanned train operations in mass transit. Functional testing has become itself a complex part of the projects. Besides straightforward technical testing most relevant validation cases origin today mainly from safety and functional analyses nested into the V-Model and are performed during the integration test phases. These thousands of test cases show mostly that the system behaves as intended, but rarely evaluate the much larger number of possible unintended system states. In order to reach more a controlled and à priori complete test and integration program, a new method (“CBTC.valid”) has been developed at the University of Technology in Dresden together with industrial partners (TÜV Süd, Siemens) and tested in field projects. It is based on the concept, that a train control system is ultimately represented by a large but finite set of input and output signals, and any combination of the latter represents a technical system state in which the system may sooner or later find itself. From a concurrently engineered top down perspective, the method defines an operational state model broken down into more and more detailed operational states. Several paradigms had been developed to control the sheer complexity of the combinatorial signal state space without compromising “completeness”, and the test cases are generated as an artefact of the “complete” state machine. The validation state machine is implemented today in Stateflow/MATLAB and has been applied to a GOA4 train control system. The paper presents the idea, method, and architecture of CBTC.valid and discusses experience return from field application.