Sunday, July 19, 2009

Need of Electronic Interlocking System (EIS) for Indian Railways

Indian Railway is in acute need of Electronic Interlocking System for many reasons. The design and the verification process of these signalling systems needs to be inline with the (European Standards) CENELEC standards, which over the time have proven their usefulness in dealing with vital equipment. Apart from all these, the Indian railway has its own needs, which are quite different from other countries.  There has to be indigenous solution to these problems. The below points try to describe the attributes of an indigenous developed EIS

 

  1. To improve the safety standards and increase the revenue by increased line speeds.
  2. To invest less in maintenance of signalling infrastructure and thereby increase the profits.
  3. To decrease the installation and commissioning time compared to RRI.
  4. To give the flexibility in changing the software, whenever there is change in the yard layout.
  5. To give flexibility of centralized control from operations control centre , instead of localized control panels
  6. To decrease the burden on operators and maintenance staff by giving warnings about the signalling equipment due for replacement.
  7. To give more flexibility for the maintainer to sit at his desk and monitor the yard.
  8. To eventually move from localized operations to Computer aided dispatch systems (CAD)
  9. To support a supervisory control centre, to look at movement of trains.
  10. To support coded track circuits in future for ATP operations in locomotive.
  11. To eliminate the use of separate data and event loggers.
  12. To support the interface to web browsers to supervisory activities.
  13. To eventually support CAB signalling to communicate with trains.
  14. To support delivery of automated messages to control centers in case of device malfunctions.

 

 

Saturday, May 16, 2009

What is ERTMS - Introduction

The European Railway Traffic Management System (ERTMS) is a major industrial project developed by six UNIFE members – Alstom Transport, Ansaldo STS, Bombardier Transportation, Invensys Rail Group, Siemens Mobility and Thales – in close cooperation with the European Union, railway stakeholders and the GSM-R industry.

ERTMS has two basic components:

  • ETCS, the European Train Control System, is an automatic train protection system (ATP) to replace the existing national ATP-systems;
  • GSM-R, a radio system for providing voicGSM-R, a radio system for providing voice and data communication between the track and the train, based on standard GSM using frequencies specifically reserved for rail application with certain specific and advanced functions.

ERTMS aims at replacing the different national train control and command systems in Europe. The deployment of ERTMS will enable the creation of a seamless European railway system and increase European railway's competitiveness.

Why does Europe need ERTMS?

Currently there are more than 20 train control systems across the European Union. Each train used by a national rail company has to be equipped with at least one system but sometimes more, just to be able to run safely within that one country.

Each system is stand-alone and non-interoperable, and therefore requires extensive integration, engineering effort, raising total delivery costs for cross-border traffic. This restricts competition and hampers the competitiveness of the European rail sector vis-à-vis road transport by creating technical barriers to international journeys. For instance, the Thalys train sets running between Paris-Brussels-Cologne and Amsterdam have to be equipped with 7 different types of train control systems, which brings considerable costs.

A unique train control system for Europe and beyond

As a unique European train control system, ERTMS is designed to gradually replace the existing incompatible systems throughout Europe. This will bring considerable benefits to the railway sector as it will boost international freight and passenger transport.

In addition, ERTMS is arguably the most performant train control system in the world and brings significant advantages in terms of maintenance costs savings, safety, reliability, punctuality and traffic capacity. This explains why ERTMS is increasingly successful outside Europe, and is becoming the train control system of choice for countries such as China, India, Taiwan, South Korea and Saudi Arabia.

By making the rail sector more competitive, ERTMS helps to level the playing field with road transport and ultimately provides significant environmental gains.

 

Wednesday, January 28, 2009

Bombardier Unveils First Contactless Tram

In a bid to improve energy use and create a more aesthetically pleasing railway, Bombardier has introduced its first completely contactless and catenary-free operating tram. The new train, which uses a contactless power supply and no overhead power lines, incorporates Bombardier's PRIMOVE inductive power transfer technology as well as the integrated MITRAC Energy Saver, which provides cost reductions by recharging energy. Director of advanced technology development at Bombardier, Dr Carsten Struve, said that unique technology used in the tram would provide energy savings and eradicate ugly overhead power lines. "The catenary-free operation offers an entirely new prospect, particularly for trams operating in historic city centres where impressive cityscapes can now exist unencumbered by visual pollution from overhead lines," Struve said. "Combined with the new Bombardier MITRAC Energy Saver technology, the PRIMOVE system can also save additional energy." The PRIMOVE technology system uses principles found in transformer technology with electric power components hidden under the vehicle and beneath the tracks to produce energy for the tram's operation. This makes the system easier to install, eliminates the effect of weather conditions, reduces wear on component parts, and allows the tram to operate with lower noise levels and fewer emissions. The vehicle is equipped with pick-up coils underneath the vehicle, which are connected to the tram's traction system through a cable. The vehicle is only energised when the connected ground segments are fully covered by the vehicle, ensuring safe operation in areas such as pedestrian zones.  The MITRAC energy saver uses a pair of innovative capacitors, which store the energy released each time the vehicle brakes and reuse it during acceleration or operation. The system, which attaches to the tram's roof, been proven to save up to 30% of energy, reducing emissions as well as costs. The PRIMOVE technology system is part of the BOMBARDIER ECO4 portfolio of technologies launched by the company last year.

Saturday, January 24, 2009

Challenges in using Wireless Sensor Networks in Railway Signalling

The use of Wireless Sensor Networks in a safety critical Domain like Railways signalling poses challenges in implementation and Operation. Some of the issues and challenges are discussed in this chapter.

 

  1. Sensor network communications must prevent disclosure and undetected modification of exchanged messages. Due to the fact that individual sensor nodes are anonymous and that communication among sensors is via wireless links, sensor networks are highly vulnerable to security attacks.

 

  1. The gateway nodes are prone to failures just like any sensor node, and they consume significantly more energy since they transmit over longer distances compared with sensor-to-sensor links. Failure of a Gateway node results to catastrophic results because, there not information regarding the yard status to the base station

 

  1. Sensor nodes have limited computing power and memory sizes. This restricts the amount of intermediate result a node can hold, also the type of data processing algorithm on a Sensor node.

 

  1. Signals detected at physical sensors might have errors. Malfunction sensors might repeatedly generate false signals, also there could be bias caused by the placement of the sensor.

 

  1. Sensor Nodes, Driver Node and Gate Way node have to work in High EMI Environment. Since sensor networks can be deployed in different situations, wireless medium can be greatly affected by noisy environments, and thus the signal attenuates in regard to the noise. Note that an adversary can intentionally interfere and cause enough noise to affect the communication. It is vital to ensure that communication is on time to respond to emergencies.

 

  1. Wireless sensor networks at times may add delay in sending data to the base station due to the routing algorithms, etc, but Railway Signalling is very time critical job, any delay in receiving the data leads to Catastrophic results.

 

  1. If a sensor node fails due to a technical problem or consumption of its battery, the rest of the network must continue its operation without a problem. Researchers must design adaptable protocols so that new links are established in case of node failure or link congestion. Furthermore, appropriate mechanisms should be designed to update topology information immediately after the environment changes so as to minimize unnecessary power consumption. 

 

  1. The network should be scalable and flexible to the enlargement of the network's size. The communication protocols must be designed in such a way that deploying more nodes in the network does not affect routing and clustering. Rather, the protocols must be adapted to the new topology and behave as expected. In other words, the network must preserve its stability. Furthermore, introducing more nodes into the network means that additional communication messages will be exchanged, so that these nodes are integrated into the existing network. This must be done in a way that a minimum number of messages need to be exchanged among the sensor nodes, and thus battery is not wasted unreasonably.

 

  1. As in Wireless Sensor Networks Both Ground based signalling (Way Side Signalling) and On-Board Signalling (Cab Signalling) get merged, so there is the complexity of linking the ground based control laws to the inputs received from the On-Board Sensors in the train

 

  1. Design and development of failsafe, fault tolerant and energy saving  network routing algorithms is a complex design

 

Saturday, November 22, 2008

Automatic Train Protection (ATP)

Signalling used on high density metro (or subway) routes is based on the same principles as main line signalling. The line is divided into blocks and each block is protected by a signal but, for metros, the blocks are shorter so that the number of trains using the line can be increased. Originally, metro signalling was based on the simple 2-aspect (red/green) system as shown above (click for full size view). Speeds are not high so three-aspect signals were not necessary and yellow signals were only put in as repeaters where sighting was restricted.
Many metro routes are in tunnels and it has long been the practice of some operators to provide a form of enforcement of signal observation by installing additional equipment. This became known as automatic train protection (ATP). It can be either mechanical or electronic.
The London Underground, for example, uses both types on its lines, depending on the age of the installation. The older, mechanical version is the train stop, the electronic version depends on the manufacturer. The trainstop consists of a steel arm mounted alongside the track and which is linked to the signal. If the signal shows a green or proceed aspect, the trainstop is lowered and the train can pass freely. If the signal is red the trainstop is raised and, if the train attempts to pass it, the arm strikes a "tripcock" on the train, applying the brakes and preventing motoring.
Electronic ATP involves track to train transmission of signal aspects and (sometimes) their associated speed limits. On-board equipment will check the train's actual speed against the allowed speed and will slow or stop the train if any section is entered at more than the allowed speed.
The Overlap
If a line is equipped with a simple ATP which automatically stops a train if it passes a red signal, it will not prevent a collision with a train in front if this train is standing immediately beyond the signal. There must be room for the train to brake to a stop. This is known as a "safe braking distance" and space is provided beyond each signal to accommodate it. In reality, the signal is placed in rear of the entrance to the block and the distance between it and the block is called the "overlap". Signal overlaps are calculated to allow for the safe braking distance of the trains using this route. Of course, lengths vary according to the site; gradient, maximum train speed and train brake capacity are all used in the calculation.
Simple Overlap used with ATP
This diagram (left, click to enlarge) shows the arrangement of signals on a metro where signals are equipped with trainstops (mechanical ATP) and each signal has an overlap whose length is calculated on the safe braking distance for that location. Signals are placed a safe braking distance in advance of the entrances to blocks. Signal A2 shows the condition of Block A2, which is occupied by Train 1. If Train 2 was to overrun Signal A2, the raised trainstop (shown here as a "T" at the base of the signal) would trip its emergency brake and bring it to a stand within the overlap of Signal A2.
Overlaps are often provided on main line railways too. In the UK, it is the practice to provide a 200 yard (185 m) overlap beyond each main line signal in a colour light installation. In the US, the overlap is considered so important that a whole block is provided as the overlap. We will see more about this in Automatic Train Protection below.
Track-Circuited Overlaps
Normal Overlap
Nothing in life is as simple as it seems and so it is with overlaps. A line which uses overlaps and has close headways could have a situation as shown here (click for full size view) where the train in the overlap of Signal A1 has a green signal showing behind it. Although it is protected by Signal A2 showing red, the driver of Train 2 may see the green signal A1 behind Train 1 and could "read through" or be confused under the "stop and proceed" rule.

Track Circuited Overlap
So, where there is a possibility of a green signal being visible behind a train, overlaps are track circuited as shown left. Although there is no train occupying the block protected by Signal A1, the signal is showing a red aspect because the train is occupying the overlap track circuit. This will give rise to two red signals showing behind a train whilst the train is in the overlap.



Automatic Train Protection
To adapt metro signalling to modern, electronic ATP, the overlaps are incorporated into the block system. This is done by counting the block behind an occupied block as the overlap. Thus, in a full, fixed block ATP system, there will be two red signals and an unoccupied, or overlap block between trains to provide the full safe braking distance, as shown here (click for full size view). As an aside, remember that, although I have shown signals here, many ATP equipped systems do not have visible lineside signals because the signal indications are transmitted directly to the driver's cab console (cab signalling).
On a line equipped with ATP as shown above, each block carries an electronic speed code on top of its track circuit. If the train tries to enter a zero speed block or an occupied block, or if it enters a section at a speed higher than that authorised by the code, the on-board electronics will cause an emergency brake application. This is the system used by London Underground for the Victoria Line from 1968 - the first fully automatic, passenger carrying railway ( more information here). It was a simple system with only three speed codes - normal, caution and stop. Many systems built since are based on it but improvements have been added.
ATP Speed Codes
A train on a line with a modern version of ATP needs two pieces of information about the state of the line ahead - what speed can it do in this block and what speed must it be doing by the time it enters the next block. This speed data is picked up by antennae on the train. The data is coded by the electronic equipment controlling the track circuitry and transmitted from the rails. The code data consists of two parts, the authorised speed code for this block and the target speed code for the next block. The diagram below shows how this works.
In this example (left), a train in Block A5 approaching Signal A4 will receive a 40 over 40 code (40/40) to indicate a permitted speed of 40 km/h in this block and a target speed of 40 km/h for the next. This is the normal speed data. However, when it enters Block A4, the code will change to 40/25 because the target speed must be 25 km/h when the train enters the next Block A3. When the train enters Block A3, the code changes again to 25/0 because the next block (A2) is the overlap block and is forbidden territory, so the speed must be zero by the time train reaches the end of Block A3. If the train attempts to enter Block A2, the on-board equipment will detect the zero speed code (0/0) and will cause an emergency brake application. As mentioned above, Block A2 is acting as the overlap or safe braking distance behind the train occupying Block A1.
Operating with ATP
Trains operating over a line equipped with ATP can be manually or automatically driven. To allow manual driving, the ATP codes are displayed to the driver on a panel in his cab. In our example below, he would begin braking somewhere around the brake initiation point because he would see the 40/25 code on his display and would know, from his knowledge of the line, where he will have to stop. If signals are not provided, the signal positions will normally be indicated by trackside block marker boards to show drivers the entrances to blocks.
If the train is installed with automatic driving (ATO - Automatic Train Operation), brake initiation for the reduced target speed can be by either a track mounted electronic "patch" or "beacon" placed at the brake initiation point or, more simply, by the change in the coded track circuit. Both systems are used by different manufacturers but, in both, the train passes through a series of "speed steps" to the signalled stop.
When the first train clears Block A1, the codes in Blocks A2, A3 and A4 will change to the next speed up and any train passing through them will receive immediately a new permitted speed and a new target speed for the next block. This allows an instant response to changing conditions and helps to keep trains moving.
Distance-to-Go
The next stage of ATP development was an attempt to eliminate the space lost by the empty overlap block behind each train. If this could be eliminated, line capacity could be increased by up to 20%, depending on block lengths and line speed. In this diagram, the train in Block A1 causes a series of speed reduction steps behind it so that, if a following train enters Block A6, it will get a reduced target speed. As it continues towards the zero speed block A2, it gets a further target speed reduction at each new block until it stops at the end of Block A3. It will stop before entering Block A2, the overlap block. The braking curve is shown here in brown as the "standard" braking curve.
To remove the overlap section, it is simply a question of moving the braking curve forward by one block. The train will now be able to proceed a block closer (A5 instead of A6) to the occupied block, before it gets a target speed reduction. However, to get this close to the occupied block requires accurate and constant checking of the braking by the train, so an on-board computer calculates the braking curve required, based on the distance to go to the stopping point and using a line map contained in the computer's memory. The new curve is shown in blue in the diagram. A safety margin of 25 metres or so is allowed for error so that the train will always stop before it reaches the critical boundary between Blocks A2 and A1. Note that the braking curve should reduce (or "flare out") at the final stopping point in order to give the passengers a comfortable stop.
Speed Monitoring
Both the older, speed step method of electronic ATP and "distance-to-go" require the train speed to be monitored. In Fig 8 above, we can see the standard braking curve of the speed step system always remains inside the profile of the speed steps. The train's ATP equipment only monitors the train's speed against the permitted speed limit within that block. If the train goes above that speed, an emergency brake application will be invoked. The standard braking curve made by the train is not monitored.
For the distance-to-go system, the development of modern electronics has allowed the brake curve to be monitored continuously so that the speed steps become unnecessary. When it enters the first block with a speed restriction in the code, the train is also told how far ahead the stopping point is. The on-board computer knows where the train is now, using the line "map" embedded in its memory, and it calculates the required braking curve accordingly. As the train brakes, the computer checks the progress down the curve to check the train never goes outside it. To ensure that the wheel revolutions used to count the train's progression along the line have not drifted due to wear, skidding or sliding, the on-board map of the line is updated regularly during the trip by fixed, track-mounted beacons laid between the rails.
Operation with Distance-to-Go
Distance-to-go ATP has a number of advantages over the speed step system. As we have seen, it can increase line capacity but also it can reduce the number of track circuits required, since you don't need frequent changes of steps to keep adjusting the braking distance. The blocks are now just the spaces to be occupied by trains and are not used as overlaps as well. Distance-to-go can be used for manual driving or automatic operation.
Systems vary but often, several curves are provided for the train braking profile. This example shows three: One is the normal curve within which the train should brake, the second is a warning curve, which provides a warning to the driver (an audio-visual alarm or a service brake application depending on the system) and the third is the emergency curve which will force an emergency brake if the driver does not reduce speed to within the normal curve.
Why doesn't everyone use distance-to-go? Partly because the systems used by many operators were installed before distance-to-go became available. Also, some operators require the safety margin, particularly in the US where they insist on an extra margin, known as the "lurch" factor, to allow for a train which decides to "motor" instead of "brake", as once happened in San Francisco.

Friday, January 18, 2008

Computer Based Interlocking Systems

Challenges faced by Computer based Interlocking Systems

 

  1. The wiring from the field object such as Signals, Points and tracks to the SSI Rack is still done using Copper cables which amounts to huge costs
  2. The hardware reliability and availability  factor is low compared to the system availability given by RRI
  3. The fail safe mechanisms employed  in processor based equipment is not standard and often get untested during V&V activities
  4. Lack of formal methods in developing the control algorithms (Interlocking Logic)
  5. Lack of domain Knowledge in Signalling and Traditional Route Relay Interlocking Systems, This creates a technological gap between the software programmers and the Domain consultants. This leads to Errors in software, which might lead to unsafe failures of the system
  6. Extending the working scope of the Interlocking systems  for monitoring and  other non-Interlocking functions, which leads to degraded performance of the system
  7. Employing Non-Formal Interlocking principles instead of traditional RRI Principles leads to software complexity. For Ex: The Geographical method needs every system that is installed for new Yard needs validation, which is not practicable.
  8. Since the software and hardware is so complex, complete test of the system is not possible and most of the faults are revealed at the field Installation stage or during normal working of the system in field.
  9. The software is to be changed for every yard, the software structure should be in a generic form, but we seldom see a generic form and at this stage errors creep in.
  10. The lack of standardization in the railway working principles and the core Interlocking principles, the software developers are forced to do changes in the software for every yard in Different railway zones.
  11. Increase in the complexity of the software leads to difficulty in testing, since most of the Interlocking systems are sequential machines they are error prone and are very difficult to test.

With Increasing speed of trains, there needs to be a direct communication with the on board computer of the train (Engine), so that there is less human involvement and thus less human errors. But Interlocking systems are mostly not capable of sending commands to the on board computer of the train (Engine).

 

Any queries mail me at sandeep.patalay@cmcltd.com



DISCLAIMER "The information contained in this e-mail message and/or attachments to it may contain confidential or privileged information. If you are not the intended recipient, any dissemination, use, review, distribution, printing or copying of the information contained in this e-mail message and/or attachments to it are strictly prohibited. If you have received this communication in error, please notify us by reply e-mail or telephone and immediately and permanently delete the message and any attachments. Thank you"

Thursday, January 3, 2008

Relay Interlocking

Historical Overview of  V&V of Relay Interlockings:

 

In the past relay interlockings were designed, installed and tested not only under the responsibility of a railway company but were actually carried out by the staff of this railway company. The people involved were educated and trained within the company, often by a training institute which also belonged to this same company. There was on the job training with a strong ‘father to son’ relationship and it took many years before an engineer was given the final responsibility of testing an installation. Common practice was that people required at least 7 to 10 years experience before they were allowed to take this responsibility. There was no official certification of engineers; it was well known who had the capability and experience to be responsible for such a job.

 

The design of a relay interlocking was carried out by a group of engineers and under the responsibility of an independent senior engineer a complete verification of the design took place. For these activities a set of design rules was available, which hardly changed for decades. After the approval of this design the installation was built on site, after which all wires and components were checked. After the completion of the installation, a test was carried out where not only the behaviour of the installation itself was tested, but also the correspondence with the outside elements (signals, point machines, track circuits, ATP-code, level crossings, bridges etc.) was checked.

 

This testing was the validation of the design; it was proven that the behaviour of the installations was in accordance to the (often implicitly) defined requirements for that location. The basis of these tests were not standardised; it was the experience and the knowledge of the senior tester in charge that assured the completeness and correctness of the test and therefore the quality of the final result.

 

Any queries mail me at sandeep.patalay@cmcltd.com

 



DISCLAIMER "The information contained in this e-mail message and/or attachments to it may contain confidential or privileged information. If you are not the intended recipient, any dissemination, use, review, distribution, printing or copying of the information contained in this e-mail message and/or attachments to it are strictly prohibited. If you have received this communication in error, please notify us by reply e-mail or telephone and immediately and permanently delete the message and any attachments. Thank you"

Sunday, December 30, 2007

Design principles in Safety Technology

Design principles in Safety Technology

In safety technology, several basic design principles are applied. Two of them are briefly described in the following.

Fail safe

The fail safe principle requires that upon failure of a safety relevant system or component, it enters a safe state. A main precondition for the application of this principle is the existence of a safe state. For the railway this is a state, where all trains are at standstill in a certain track. If such a state exists, technical systems can be designed to enter it when they fail. A typical example is the train protection system.. However, the fail safe principle cannot always be applied.

Safe life

A system that does not have a safe state is e.g. the airplane. Then, the safe life principle has to be applied. It requires application of redundant and high reliable components to make sure, that the system always functions.

 



DISCLAIMER "The information contained in this e-mail message and/or attachments to it may contain confidential or privileged information. If you are not the intended recipient, any dissemination, use, review, distribution, printing or copying of the information contained in this e-mail message and/or attachments to it are strictly prohibited. If you have received this communication in error, please notify us by reply e-mail or telephone and immediately and permanently delete the message and any attachments. Thank you"

Friday, December 28, 2007

HALT and HASS Testing: Learning to Handle the Big Guns

 

A lack of standards for the correct implementation of the stress test techniques known as HALT and HASS has resulted in widespread confusion. When implemented correctly, HALT and HASS provide a fast, cost-effective path to greater product reliability and customer satisfaction, as well as reduced warranty costs.

Since they were first introduced in the early 1980s, Highly Accelerated Life Testing (HALT) and Highly Accelerated Stress Screening (HASS) have been successfully adopted for a host of high-performance applications, such as mission-critical avionics equipment. With their promise of quickly providing valuable information about the reliability of a new or modified design, and the ability to monitor production and prevent component variations from causing latent field reliability issues, HALT and HASS techniques are ideal for designing and manufacturing with commercial-grade components.

Both test methods use direct inject, high flow rate liquid nitrogen cooling, tens of kilowatts of heating and powerful, multi-axis broad-spectrum vibration. Although these aggressive test methods are very different from standard life testing, design verification testing (DVT) and end-of-production testing, there are no published industry standards that define these powerful test methods. Since they deploy extreme stresses designed to rapidly precipitate flaws and force them to failure, misapplications or misinterpretations of these tests can easily result in damaged products, wasted money and frustrated engineers.

HALT is used as part of the new product design process and is typically performed on pilot or pre-production units. During HALT testing, the product is subjected to increasing stresses until weak points in the design emerge. Failure modes are identified and analyzed, and the product design is modified based on the results of that analysis. A typical HALT test will take three to five days. HASS, on the other hand, is a production screen, and typically tests 100% of production units. HASS uses similar stresses to those used in HALT, but at lower levels based on the limits identified in HALT. HALT must be completed before HASS can be implemented, and HALT is the most widely used of the two tests.

HALT and DVT

Although HALT may appear similar to DVT, it has different goals, uses different stresses and provides different results. The goal of DVT is to demonstrate whether a product will function in its intended environment and meet its specifications. The purpose of HALT, however, is to subject the product to environmental overstress, effectively forcing failure modes to emerge by accelerating mechanical fatigue. HALT quickly identifies a particular product's set of failure modes by applying the same environmental stresses that occur in the field, but at much higher levels. DVT and life testing can sometimes identify those failures, but this rarely occurs because the required time and number of units in test would be extreme.

One of the most significant characteristics of HALT is that it is not a pass/fail test. There are no pre-established limits. The test concludes when product destruct limits have been reached or the engineers determine that no more useful information can be gained. A final HALT test report includes detailed data on the product's operating margin, destruct margin and design flaws, along with what the new margins will be if each of the design flaws is eliminated.

When HALT is used, it is performed before DVT, so failure modes are exposed quickly and inexpensively before DVT begins. At that point, they can be analyzed and corrected without the pressure of a looming release date. If this is not done, many products will exhibit multiple failures during DVT. This can initiate costly and time-consuming redesign/retest cycles. But as a product nears its scheduled release date, the pressure to pass DVT can be intense. Too often, dealing with these critical failures may be postponed until after product launch, resulting in even greater losses and customer dissatisfaction.

The HALT Test Method

The stresses used in HALT are applied beginning with the least destructive and ending with the most destructive. A test sequence starts with cold step stressing and proceeds to hot step, rapid thermal ramps and vibration. It ends with a combined environment of vibration and rapid thermal ramps, dwelling at both temperature extremes. Other stresses include input voltage variations, loading, clock frequency variations and mechanical loading, if appropriate. Combining stresses will often reveal failure modes that individual stresses cannot.

Each time a failure occurs it is carefully documented and, if possible, a quick work-around is identified. Testing concludes when multiple failures occur simultaneously or fundamental design or technology limits have been reached for individual and combined stresses.

The potential benefits from HALT are significant. A single failure mode, caught before it becomes an issue that requires field rework, can save millions of dollars and help maintain a company's reputation and likelihood of getting future contracts. In addition, using HALT helps DVT go smoothly, so products are more likely to be released on time.

HALT may be considered successful when DVT and product launch proceed without last-minute design changes caused by late detection of failures. Success is further characterized by a lack of field issues in the weeks and months following launch. But a successful HALT also requires other conditions. The development team must accept ownership of the process from the beginning. HALT must be applied as early as practical in the design process, and failure analysis must be fast and accurate. It is imperative that failures are not overlooked or explained away, and the product development team must apply solid judgment when deciding which failure modes to eliminate.

The vibration stress used in HALT can be another source of confusion, since it deploys a type of shaker system different from that used in DVT. The Electro-Dynamic (ED) shakers deployed in DVT can be carefully controlled to provide exactly the stimulus needed for an analysis of the product's vibration response. They provide this stimulation in only one axis at a time. In HALT, rapid fatigue, not analysis, is the goal, and Repetitive Shock (RS) systems are used. These systems (Figure 1) can stimulate a product with a much wider range of frequencies, in all three axes and the rotations about these axes simultaneously. This stimulation will rapidly drive a poor solder joint or weak mechanical connection to failure.

HASS Production Screening

Once a product has been ruggedized with HALT, the question of production testing arises. Manufacturing variations and vendor changes can mean disaster, whether in a high-dollar, low-volume product, or one to be used in critical applications where failure can be very expensive or dangerous. Companies often use long burn-in tests to reduce these risks, only to discover that burn-in failures are rare, yet warranty issues are still a problem.

This is where the HASS production screen comes in. It applies stresses similar to those used in HALT, but at substantially reduced levels, based on the limits identified in HALT for each of the applied stresses. HASS provides continuous verification that additional failure modes, resulting from manufacturing or component variations, have not crept into the product.

Unlike HALT, HASS is a pass/fail test. A HASS screen consists of a “precipitation” phase that may exceed operating limits. This is followed by a detection phase in which the stresses are reduced to within operating limits and the product is monitored for failures. The test usually requires from 30 minutes to two hours, and in many cases eliminates the need for 24 or 48 hours of largely ineffective burn-in. The potential lot-to-lot variations that have been introduced with commercial-grade components mean the risk of a component change, which could introduce a new field failure mode that would be undetected by functional testing or a few days of burn-in. HASS applies combined stresses to precipitate these failure modes and then detect them via a change in the operating margins or a hard failure.

Many engineers have expressed the concern that HASS can damage products and may actually cause field failures. However, proper implementation of the HASS Proof of Screen provides a clear understanding of screen effectiveness and ensures that there is no effect on product life or performance. Proof of Screen includes repetitive application of the HASS stress profile to a small population of production samples. HASS is only implemented after it has been proven that all “good” samples can withstand from 20 to 50 repeated HASS cycles without damage or wear.

Conclusion:

HALT and HASS chambers are expensive, but the cost is minimal compared to what many companies pay in direct costs and lost business if failures occur in the field. Furthermore, most companies approach HALT and HASS carefully, in stages. The first stage might consist of using HALT on a single new product and conducting the tests in an established commercial test lab. As more products follow and confidence increases, it may become cost-effective to purchase a chamber. After additional time and solid experience with HALT, many companies are making the move to HASS.

When designing with commercial-grade components, there is always a valid concern about potential degradation of product life and performance. With adequate training, the right equipment and a clear commitment from the organization, the powerful tools of HALT and HASS can very effectively reduce those risks.

 

 

 

 

 

 



DISCLAIMER "The information contained in this e-mail message and/or attachments to it may contain confidential or privileged information. If you are not the intended recipient, any dissemination, use, review, distribution, printing or copying of the information contained in this e-mail message and/or attachments to it are strictly prohibited. If you have received this communication in error, please notify us by reply e-mail or telephone and immediately and permanently delete the message and any attachments. Thank you"