Train doors require GPS signal to open despite stations being underground (2014)
ciras.org.uk
ciras.org.uk
So... we added GPS to the trains so that doors could only be opened at stations. Then, we realised that this was a terrible idea and probably against safety regulations, so we added a function to do this anyways but buried it in menus so it couldn't be accessed in a real emergency.
Sounds like a manglement-directed idea if I ever heard one.
Edit: To clarify, I meant that if there is a manual release for the doors... what's the point of the GPS system?
I guess that in an emergency you can open all the doors with a big red open button in the train driver cabin, and that in each wagon there is another red button (protected by a breakable glass, to prevent pranks).
Was there some epidemic of doors being opened outside stations that I missed? This smacks of a solution looking for a problem
I'm assuming that the edge of the platform will always match the edge of a car, and that it is not possible to board off-platform cars (otherwise they wouldn't be off-platform), and that there will be no people in the "off-platform" cars. Otherwise, how would they get off? It seems extremely inefficient to start the train just to move it half its length, then stop it again.
The difficulty arises when doors are accidentally opened for all cars at 4-car platforms.
No, the train does not move forwards by 4 cars, it simply stops, passengers board and alight from the front four (including a rush of passengers frommthe back four cars who forgot that their station is a four-car stop), then the train leaves.
I don't have data showing it, but I think making the driver's work duller can make things less safe for his passengers.
Actually, cattle may get treated better...
If it's really a problem why not use the speedometer to figure out if the train is moving? Or why not use something like the MTA's wheel rotation sensors? The guy who wrote the signal code for MTA said that they use wheel rotations to calculate when to play audio messages in-train and in-station... those "There is a queens-bound train N stations away". It's a simple idea.
The real, less trivial problem is only opening the doors of train cars that actually fit on the platform.
GPS was just a poor choice of positioning system. There are already widely deployed systems where what is essentially an RFID tag sits at a fixed point on the track between the rails and, when scanned, tells the train exactly where it is.
On the underground, particularly during rush hour, doors opening on the wrong side, or in the wrong place, could cause people to fall out of the train onto the tracks, in the dark, and risk serious injury or even death (especially with electrified rails).
And using GPS and repeaters in the few spots where the signal's poor sounds like a practical and cost-effective approach. Given the issues, perhaps they should've implemented it some other way, but it's hardly the ridiculous solution you're all making it out to be.
As superuser2 mentions below, there's even a non-safety reason for this feature: long trains in short stations. https://news.ycombinator.com/item?id=9203351
And as someone mentioned below, there is already a solution for this exact problem; https://en.wikipedia.org/wiki/Balise
It's also the case that most of the raspberries are aimed at the idea that it doesn't work very well, which is a failure regardless of the apparent reasonableness of the implementation.
The train stopped in the station, but the doors didn't open for a good 5 minutes. The driver issued a statement stating that there'd be a slight delay before the doors opened.
I recall thinking: what possible reason could there be for not opening the doors? Congestion? Electric failure?
Well, turns out it's the most ludicrous one.
Somebody else decided that having doors controlled by location was a good idea here, and didn't think somebody would specify a system that doesn't work at some stations.
At some point during procurement and installation of the equipment you'd think somebody would have raised a red flag. Unless, of course, they were simply told to install GPS equipment, and not why. Or they were told why but nobody listened to them when they explained why it wouldn't work right.
Sounds to me more like bad organization than bad design, although of course it's hard to tell from this distance.
The only sensible reason for this is that someone responsible had a friend that sold GPS-beacons.
And they can be quite cheap.
Someone tell Bruce Schneier his new movie plot terror threat[1] is here: someone homebrews a GPS signal transmitter to open all the train doors at rush hour ... preferably on the wrong side.
[1] https://www.schneier.com/essays/archives/2005/09/terrorists_...
And obviously they would be 10000x louder than the gps signal, so you couldnt lose it unless someone was purposefully interfering with the signal.
Peter G. Neumann has been moderating this publication online for almost 30 years now. Always interesting reading.
RISKS Digest: http://en.wikipedia.org/wiki/RISKS_Digest
Current Issue and Archives: http://catless.ncl.ac.uk/Risks/
1994 Book: http://www.amazon.com/Computer-Related-Risks-Peter-G-Neumann...
Nope. No thanks. Do not need my trains to be so "smart" that the only way to get them working properly is CTL-ALT-DELETE.
Seriously.
This happened while driving at 160 km/h and if we had not seen the messages on the screen, nobody would have known.
That was seriously impressive and I wish I could do something like this. Not only did it properly detect the failure, it also rebooted and then came up correctly and still was aware of all the state needed to drive on.
If software works like that, I can live with it being used more and more.
Also, isn't the first objection to GPS anything usually "it doesn't work well in buildings or around buildings"?
I can see the need and advantage of a system to make sure that only the appropriate doors open at certain stations, but surely this could have been done with information at the local level. Barcodes, NFC, RFID ... to go with sats hundreds of miles in the sky augmented by repeaters is overly complex.
Passengers are not cattle. I don't see why they cannot have local door control when the train is stopped for more than 5/10/15 minutes. The risk of death by idiot openign wrong door surely is less than the risk of death by fire/poison gas/axe murderer, all of which have happened on trains.
The old system of windows that slide down with a handle on the outside of the carriage seemed to work pretty well - hypothetically you could open the door and push people out or fall on the track. Wonder how many times that happened?
Or were masses of people trapped in cars in the decades of operation prior to this, because the operator couldn't figure out where he was and wouldn't/couldn't open the doors?
We'll see more positive train control as the technology gets cheaper:
http://en.wikipedia.org/wiki/Positive_train_control
It doesn't replace operators, but instead enforces speed limits and stops. It hasn't been implemented in more trains mostly because it's expensive.
http://www.labsat.co.uk/index.php/en/
lol
Which explains why they want it to be location dependent, it doesn't excuse the poor implementation.
SDO, CSDE: Firstly, some platforms are too short to fit all of the doors on, especially with the lengths of trains being extended. Thus at some platforms it is necessary to ensure that the first or last doors of the train, or both, are not unlocked.
The London Underground has its own system to do this (https://en.wikipedia.org/wiki/Selective_Door_Operation ). Here it appears they decided to use GPS, but the LU almost certainly uses a much simpler (and more reliable system).
Of course, if a GPS fix isn't obtained, you don't know whether you're at a short platform or not, so you can't assume anything.
A related safety issue is whether drivers open the doors on the right side of the train (!). Yes, believe it or not, they sometimes get this wrong. When the London Underground moved to one-man train operation (meaning that the doors were controlled by the driver, rather than by a separate guard), they had some issues with this happening. They responded by introducing a simple, low-level system called "Correct Side Door Enable", which uses an electrical loop by the side of the track in platforms, which is detected by the train and allows the train to determine that a) it is in a station and b) which side the platform is on. This prevents the driver from opening the doors in error.
You can find some information on CSDE here: http://www.trainweb.org/districtdave/html/correct_side_door_...
I would guess that the LU's SDO system uses some similar or even interrelated mechanism.
Metro vs. Rail: Note that on metro trains (e.g. the majority of London Underground trains) the doors usually open automatically, whereas on other trains you have to press a button to open the doors once it illuminates. This makes the potential consequences of accidentally opening the doors on the wrong side worse on tube trains, especially when you consider how packed they can get. Whereas with a train like the class 377, a driver would have to unlock the door on the wrong side and then the passenger would have to accidentally open the door on the wrong side. So the consequences of accidentally unlocking the doors on the wrong side is not -that- severe, which makes the apparent difficulty and obscurity of the overrides available to the driver (plus the implication that the drivers aren't properly trained on their operation) all the more ridiculous.
(A particularly curious variant is found on some trains of the Paris metro; the doors try and open as soon as the driver tells them to, but a mechanical latch on the doors prevents it. A passenger has to move up the latch before the doors can open. The latches were probably retrofitted, perhaps to mitigate unnecessary heat loss, but it also serves as a safety measure. This system has the advantage over a button-based system that a malfunctioning microcontroller cannot randomly open a door at inopportune times, though this is a rather academic advantage given that I am unaware of such cases.)
I have myself ridden the 377, and on one occasion I did notice an unusual delay before the doors unlocked, of about a minute, which involved the "door out of order" lamp momentarily flashing on and off a few times, perhaps suggesting some sort of train reboot.
I find the term 'GPS repeater' strange. The nature of GPS would lead me to believe that 'repeating' GPS would be rather difficult, though I could be mistaken. It seems more likely that by 'GPS repeater' what they actually mean is some sort of overriding 'you are at station #27' signal, perhaps implemented much like the LU's CSDE system. The Wikipedia page for SDO seems to confirm this (https://en.wikipedia.org/wiki/Selective_door_operation - note that 'Thameslink' and 'First Capital Connect' are effectively synonymous).
The idea that not being able to quickly open the doors is a safety issue seems quite peculiar to me. On the 377 and all non-metro trains, all doors are fitted with passenger-operable emergency releases. There are also somewhat anonymous emergency releases which could be operated from outside the train by platform staff. Both such releases are mandated and governed by railway standard GM/RT2473 (which can be found here, along with some rail accident reports referencing it: https://www.google.co.uk/search?q=gm/rt2473 )
That said, there is one way in which the Class 377's doors are implemented in an obviously deficient way: if you hold down the open button before the doors are unlocked, the doors will not open when they are. You then have to release and re-depress the button. In other words, whoever programmed the door erroneously chose an edge-triggered behaviour rather than a level-triggered one. This is in contrast to the buttons on the Class 319 (which the Class 377 is replacing), which behave correctly. I previously ranted about this here: http://www.devever.net/~hl/train377
Since when that default solution to any problem of any device embedded with CPU, is to reboot?
Welcome to the digital age!
[yes, completely made up, but corresponds to what's happening daily in other, probably slightly less safety critical, industrial automation systems]
People generally don't notice because the system doesn't beep or display a boot message (if it even has a display).