Railway corridor inspection and incident response.
A railway is a machine for finding coverage holes: cuttings, tunnels and remote sections punch through any single carrier’s map — and an incident on the line burns money by the minute until someone can see it. This mission is about getting live video from the site to the control centre now, over whatever the corridor’s networks can jointly provide.
Rail infrastructure managers, incident response units, track and catenary inspection contractors.
The corridor’s geometry — cuttings, tunnels, remote sections — defeats single-carrier coverage exactly at the structures that need seeing.
Multiple carriers bonded; command duplicated; footage from dead sections queues and delivers at the next portal; a mast relay bridges the fixed hole.
The aircraft’s companion computer, the response vehicle’s box and any lineside mast node. One Linux binary, one configuration file.
The mission
An overnight storm, and a driver reports a tree on the catenary at the mouth of a cutting, forty kilometres from the nearest depot. The line is blocked; every minute of closure cascades through the morning timetable. The response unit rolls with a drone in the vehicle, and the control centre wants one thing before it commits an engineering train and a possession: live video of the site — the tree, the wires, the state of the cutting slope above it. The same corridor is flown in calmer weeks for routine inspection: earthworks, vegetation, catenary geometry, section after section. Both jobs stand or fall on the same thing — a link from the corridor to the control centre that the corridor itself keeps trying to kill.
What breaks
Railways go where the gradient is kind, which means through the terrain rather than over it. A cutting is a trench that shadows the low horizon where the cells are; a tunnel is absolute; the remote sections between towns are exactly where the carriers never built. Along any real corridor a single-carrier link is a chain of holes, and the holes line up with the structures — it is precisely in the cutting, at the portal, on the viaduct approach that the video dies. The railway’s own operational radio is engineered for train control and voice, not for streaming an inspection feed.
The classical answer is to drive someone to the site for a look, which costs the very hours the closure is burning — or to fly anyway and accept that the footage of the critical structure arrives as a memory card at end of shift, too late for the decision it existed to inform.
The architecture on this mission
The inspection aircraft — and the response vehicle that launched it — carries modems on two or three carriers, bonded into one encrypted tunnel to the control centre. The carriers’ holes are in different places along the corridor, so what defeats each of them separately rarely defeats the bond; command-and-control is duplicated across two carriers for the whole sortie, and every link is probed several times a second, with traffic reweighted away from a softening path in well under a second. The vehicle is a moving ground station running the same node, so both ends travel the corridor and neither end’s network changes are events.
Where geometry beats every carrier at once, the architecture changes shape instead of giving up. In the cutting, a mast relay on the lip — a lineside node on infrastructure the railway already owns — splits the impossible path into two short hops, and traffic routes through it automatically whenever the direct paths are gone. In the tunnel, nothing propagates through rock and nothing pretends to: footage queues store-carry-forward on board and drains, priority first, at the next portal. The control centre sees a feed that degrades and recovers, never a session that resets.
Every relay is an authenticated node that cannot read the traffic it carries, and a permanent mast node installed at a known problem section keeps paying on every future sortie — the fix is capital, once, instead of operational, every time.
How the incident response unfolds
- The call. 05:40, tree on the catenary at the cutting. The response vehicle rolls; its node brings up the bond on the move, and the control centre watches the vehicle’s position on the same tunnel the video will use.
- On scene. The aircraft launches from the access point above the cutting. Live video of the tree and the wires reaches the control centre over two bonded carriers within minutes of arrival.
- Into the shadow. The aircraft descends into the cutting to inspect the slope. One carrier’s path dies at the lip; command holds on the second, duplicated, and the video reweights onto what still works — no switchover, no operator action.
- The deep section. At the portal both carriers are gone. The survey of the tunnel approach queues on board, the command channel rides the mast relay’s two short hops, and nothing resets.
- The decision. With live and queued imagery in front of them, the engineers order single-line working and one engineering train with the right kit — before the site visit that used to be the first step has even arrived.
- The debrief artefact. The journal holds a per-carrier record of the whole sortie: where each network held and where it died. Three sorties later, that record is the business case for a permanent node at the cutting.
What each mechanism contributes
- Multi-carrier bonding with duplicated command — the corridor’s patchwork becomes one usable fabric; holes stop lining up with aborts. Shipped.
- Endpoint roaming, both ends — aircraft and vehicle both move along the corridor; sessions bind to keys, not addresses, across every cell handover. Shipped.
- Mast and vehicle relaying — lineside nodes split blocked paths into short hops; relays authenticate by key and cannot read what they carry. Shipped.
- Store-carry-forward — tunnel and dead-section footage is late, never lost; it drains priority-first at the next portal. Shipped, opt-in.
- Continuous measurement — every sortie quietly maps the corridor’s real coverage per carrier, which is exactly the evidence a relay installation needs. Shipped.
The honest boundary: Atlas contributes the link layer. The aircraft, the rail safety approvals, track access and possessions, and the engineering decisions are the operator’s — and inside a long tunnel no software makes radio pass through rock. What the mechanisms guarantee there is that nothing is lost and everything delivers at the portal; continuous coverage inside would take nodes in the tunnel itself, which the mesh accommodates but the railway must install.
What a pilot should prove
- A per-carrier coverage map of one problem section, generated from the built-in measurement alone.
- Live-video continuity across a defined cutting where each single carrier measurably fails.
- Footage completeness through a tunnel transit: one hundred percent delivered at the portal, timestamped by the journal.
- Time-to-first-video at the control centre for a staged incident, against the drive-and-look baseline the timetable currently pays for.
One section, one aircraft, one inspection week. The evaluation format covers the structure.