Multistage redundant servo control system and control method
Through multi-stage redundancy design and decoupling technology, the single point of failure of the decision-making layer and sensing feedback link in the existing servo control system is solved, achieving higher system reliability and stability, and making it easier to maintain.
Patent Information
- Application Number
- CN202511073853.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-01
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2045-08-01
AI Technical Summary
Although the redundant design of the existing servo control system improves the reliability of the execution channel, there is a risk of single point failure of the control decision layer and the sensing feedback link, resulting in insufficient overall system reliability.
A multi-stage redundancy design is adopted, including parallel residual control module, servo control module and position acquisition module. Each module is composed of at least two independent branches. Through the master-slave election mechanism, it ensures that there is no single point of failure in the decision-making layer, and the reliability of position feedback is ensured through the decoupling design.
It effectively eliminates the single point of failure risk at the decision-making level, ensures that the system can still obtain accurate position feedback when any branch fails, improves the reliability and stability of the overall system, and facilitates maintenance.
Smart Images

Figure CN120578035A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of servo control technology, and in particular to a multi-level redundant servo control system and a control method. Background Art
[0002] The servo control system for electric motors is a core component in aerospace, all-electric ships, submarines, electric vehicles, high-speed rail, and other fields. Failure in this system can cause severe loss of life and property, necessitating significant attention to its reliability. Since single-redundant servo control systems are often cascaded, maintaining the proper functioning of the entire system requires the stable operation of all components. Failure in any single component can lead to failure of the entire servo control system.
[0003] It can be seen from this that the reliability of the single-redundancy servo control system is low.
[0004] To address this issue, the industry has proposed a redundant design approach. This involves setting up redundant channels in parallel. When the primary operating channel fails, the system can switch to the backup channel to continue executing. For example, Chinese invention patent application CN111371349A discloses such a servo control system (hereinafter referred to as "CN111371349A patent application"). Specifically, the technical solution in CN111371349A patent application includes a single "redundancy management controller" that manages multiple parallel "channels." Each "channel" consists of a motor controller, a motor, and a position sensor. The redundancy management controller selects a healthy "channel" to operate based on status information reported by the motor controllers within each channel. If a fault occurs in the selected "channel," the redundancy management controller disconnects it and attempts to activate another backup channel.
[0005] However, the inventors discovered during their research that, while the redundant structure disclosed in patent application CN111371349A solves the single point failure problem of the execution channel, its design itself introduces new, higher-level systemic risks, and its reliability level remains insufficient, specifically as follows: 1. Single point of failure risk in central control: The entire system's decision-making and management relies entirely on a single "redundancy management controller." If this core controller suffers hardware damage, software lockup, or a power failure, the entire redundant switching logic will immediately fail, paralyzing the entire system. Furthermore, the architecture connects only to a single "host computer," creating a single point of failure for the command source.
[0006] 2. The coupled execution and sensing design has inherent flaws: In this solution, the position sensor's signal acquisition, processing, and channel status determination are all performed by the "motor controller" within the channel. This tightly coupled design leads to a serious problem: if a "motor controller" fails, the upper-level "redundancy management controller" not only loses the ability to drive that channel, but also loses the ability to obtain the actual motor position information from that channel. System administrators will be unable to accurately determine the current status of the faulty actuator, which brings great difficulty and uncertainty to subsequent fault diagnosis, safety assessment, and system maintenance.
[0007] Therefore, although the existing technology improves the redundancy of the execution layer through parallel channels, there is still a gap in the redundant protection of the control decision layer, instruction input layer and sensor feedback link. Summary of the Invention
[0008] The embodiments of the present application provide a multi-level redundant servo control system and a control method, which can form a servo control system with better redundancy and effectively increase the stability and reliability of the servo control system operation.
[0009] The multi-level redundant servo control system of the present application includes: A redundancy control module, configured to receive control commands from one or more host computers and output servo control instructions, wherein the redundancy control module includes at least two redundancy controllers connected in parallel, and the at least two redundancy controllers communicate with each other and are electrically connected; a steering gear control module, configured to execute the steering gear control instructions to drive the motor to rotate, the steering gear control module comprising at least two steering gear control branches connected in parallel, each of the steering gear control branches comprising a steering gear controller, a motor controller, and a motor, wherein the steering gear controller is connected to the motor controller to drive the motor to operate; A position acquisition module, configured to acquire the actual position of the servo to provide position data, wherein the position acquisition module comprises at least two position acquisition branches connected in parallel; Wherein, each of the at least two redundancy controllers is communicatively connected with each of the servo controllers in the servo control module and the corresponding communication unit in the position acquisition module via a communication network; The at least two redundancy controllers determine one of the redundancy controllers as a master redundancy controller based on a first selection mechanism; The main redundancy controller is configured to: Determining a target control command from input commands sent by one or more host computers according to a second selection mechanism; Determining target position data from the position data acquired by the at least two position acquisition branches according to a third selection mechanism; Determine a target steering gear control branch from the at least two steering gear control branches according to a fourth selection mechanism; and Based on the target control command and the target position data, control information is generated and sent to the target steering gear control branch, so that the target steering gear control branch controls the operation of its corresponding motor.
[0010] In one embodiment, the first selection mechanism comprises: Setting a unique machine number for each of the at least two redundancy controllers, and sorting all the machine numbers according to a preset priority and storing them in each redundancy controller; During system initialization or normal operation, the at least two redundancy controllers communicate with each other and select the redundancy controller corresponding to the machine number with the highest priority from all redundancy controllers in normal working state according to the preset priority sorting as the master redundancy controller; and The working status of the master redundancy controller is verified in real time, and when a failure of the master redundancy controller is detected, the redundancy controller with the highest priority is reselected from the remaining slave redundancy controllers in normal working state according to the preset priority sorting to be upgraded to the new master redundancy controller.
[0011] In one embodiment, the system is configured to perform the second selected mechanism by at least one of the following modes: Master-slave mode of the host computer: a preset priority is set for each command input channel that receives input commands; the redundancy controller monitors the status of all command input channels in real time and, based on the preset priority, selects the input command received from the command input channel with the highest priority that is currently in normal operation as the target control command; and, when it is detected that the command input channel with the highest priority has a fault or communication timeout has occurred, the redundancy controller automatically selects the input command received from the command input channel with the second highest priority that is currently in normal operation as the new target control command; Host computer multi-master mode: The master redundancy controller receives input commands sent from all host computers in normal working state, and uses the last received valid input command as the target control command.
[0012] In one embodiment, the path for the main redundancy controller to receive the input command includes one of the following: Receive input commands from one or more host computers directly connected to it; Receive input commands forwarded by other slave redundancy controllers and received by the slave redundancy controller from the host computer to which it is connected.
[0013] In one embodiment, the system is configured to perform the third selected mechanism by at least one of the following modes: Position data master-slave mode: A unique branch number is set for each position acquisition branch and stored according to a preset priority order; the master redundancy controller determines the master position acquisition branch based on the preset priority, and when the data of the master position acquisition branch meets the preset normal working conditions, its position data is adopted as the target position data; when the data of the master position acquisition branch does not meet the normal working conditions, the master redundancy controller selects the next highest position acquisition branch from the remaining position acquisition branches in normal working state according to the preset priority as the new master position acquisition branch, and adopts its position data; Position data optimal mode: The master redundancy controller selects the optimal branch from all position acquisition branches in normal working condition in real time according to a preset optimal branch judgment algorithm, and uses the position data of the optimal branch as the target position data; wherein, the optimal branch judgment algorithm is based at least on the error between the position data of each position acquisition branch and the command position, and the branch with the smaller error is preferentially selected as the optimal branch. The algorithm can further comprehensively consider multiple dimensions such as the freshness (timestamp), historical stability (jitter variance), and health status flag of each branch data, and make a comprehensive judgment through a weighted scoring model; Position data common mode: The position data from multiple position acquisition branches in normal working conditions are processed through a preset data fusion algorithm to generate a fused target position data; The data fusion algorithm is executed in any of the following ways: Method 1: The master redundancy controller receives all position data and executes the data fusion algorithm to generate the target position data; Method 2: The multiple position acquisition branches communicate with each other to exchange their respective position data, collaboratively execute the data fusion algorithm to generate the target position data locally, and then uniformly upload the generated target position data to the main redundancy controller.
[0014] In one embodiment, the fourth selection mechanism comprises: The main redundancy controller receives and processes the verification signal uploaded by each steering gear control branch in real time to determine whether each steering gear control branch is in a normal working state; The master redundancy controller determines one or more steering gear control branches as the target steering gear control branches from all steering gear control branches in normal working state according to a preset control strategy; Furthermore, any steering gear control branch in an abnormal working state is excluded from the target steering gear control branch.
[0015] In one embodiment, each of the servo control branches further includes a detection module, which is used to monitor the motor operation of the branch in which it is located to obtain motor status data, and transmit the motor status data to the servo controller of the branch, and the servo controller uploads the motor status data as the verification signal to the redundancy controller; the servo controller is also used to: based on the servo control instructions from the main redundancy controller and in combination with the motor status data from the detection module, perform closed-loop operations to generate an electric control signal, and send the electric control signal to the motor controller of the branch to control the motor operation.
[0016] In one embodiment, the steering gear controller is further configured to: When it does not receive the motor status data transmitted from the detection module within a preset time threshold, it is determined that the steering gear control branch in which it is located has a fault; Furthermore, a second fault tag is generated for the failed steering gear control branch, and the second fault tag is uploaded to the redundancy controller.
[0017] In one embodiment, the location manager in each location collection branch is further configured to perform local data verification, including: receiving real-time location data from its corresponding location sensor and comparing the real-time location data with a preset location threshold; If the real-time position data does not exceed the preset position threshold, uploading the position data to the master redundancy controller; If the real-time position data exceeds the preset position threshold, the position data is discarded, and a first fault tag is generated for the position acquisition branch, and the first fault tag is uploaded to the redundancy controller.
[0018] In one embodiment, each of the position acquisition branches includes a position manager and a position sensor. The position manager is connected to the position sensor to obtain position data and is responsible for communication and address management of the position acquisition branch.
[0019] In one embodiment, the system further includes a power supply module, the power supply module being electrically connected to the redundancy control module, the steering gear control module, and the position acquisition module, and supplying power thereto; The power supply module includes at least two independent power supply circuits, each of which is configured to be connected to an independent external input power supply to achieve power redundancy.
[0020] This application has the following beneficial effects: This application fundamentally eliminates the risk of single-point failure at the decision-making layer by setting up multiple "redundancy controllers" in parallel and establishing a master-slave election mechanism (a first-selection mechanism). Furthermore, by physically and logically decoupling the "position acquisition module" from the "servo control module," the system's decision-making layer can still obtain accurate and reliable position feedback even if any execution branch fails completely. This provides a key basis for subsequent safety handling and task reconstruction, improving the reliability of the entire system. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, a brief introduction will be given below to the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0022] Figure 1 Schematic diagram of the structure of a multi-level redundant servo control system according to an embodiment of the present application.
[0023] Figure 2 FIG. 1 is a flow chart of a multi-stage redundant servo control method according to an embodiment of the present application.
[0024] Figure numbers: 10, redundancy control module; 11, redundancy controller; 20, servo control module; 21, servo controller; 22, motor controller; 23, motor; 30, position acquisition module; 31, position manager; 32, position sensor; 40, host computer. DETAILED DESCRIPTION
[0025] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0026] The terms used in the examples of this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms "a," "the," and "the" used in the examples of this application and the appended claims are also intended to include plural forms, and unless the context clearly indicates otherwise, "a plurality" generally includes at least two.
[0027] As used herein, the words "if" and "if" may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to the determination" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)," depending on the context.
[0028] Generally, servo control systems have problems such as poor operational reliability and difficulty in maintenance. The embodiment of the present application provides a multi-level redundant servo control system, which can form a servo control system with better redundancy, effectively increase the stability and reliability of system operation, and facilitate the update and maintenance of various modules of the system.
[0029] like Figure 1 As shown, the multi-level redundant servo control system of the present embodiment includes a redundancy control module 10, a servo control module 20, and a position acquisition module 30. The system can be connected to one or more host computers 40 for receiving control commands. Furthermore, the system includes a power supply module (not shown) that supplies power to all modules.
[0030] The core design concept of this invention is to establish redundant fault-tolerant mechanisms at every key level of the system, including control decision-making, execution, sensor feedback, and energy supply. Specifically, the redundancy control module 10, the steering gear control module 20, the position acquisition module 30, and the power supply module are each internally composed of at least two independently operating units or branches connected in parallel, greatly improving the overall reliability of the system.
[0031] Key nodes between modules, such as the redundancy controller 11, servo controller 21, and position manager 31, exchange information via a flexible communication network. This communication network can be a fieldbus such as CAN, EtherCAT, or other wired or wireless connection methods. In a preferred embodiment, to further enhance communication reliability, the physical links within the network can also be redundant. For example, at least two parallel communication lines can be deployed between key controllers to prevent single-point communication link failure.
[0032] Redundancy control module 10 The redundancy control module 10 is the core decision-making and management center of the servo system. Its core function is to act as a highly reliable control brain, performing a series of decision-making and management tasks. It is responsible for receiving control commands from one or more host computers 40, integrating feedback data from the position acquisition module 30, and ultimately outputting precise servo control instructions to the servo control module 20.
[0033] In order to fundamentally eliminate the risk of single point failure in the control decision layer, such as Figure 1 As shown, the redundancy control module 10 is structurally composed of at least two parallel-connected redundancy controllers 11. These at least two redundancy controllers 11 are electrically connected and synchronized via a high-speed interactive communication bus, ensuring their collaborative operation and seamless failover in the event of a failure. For example, each redundancy controller broadcasts its status in real time via heartbeat messages, which can include information such as health status, current load, and whether it is the master controller. At the same time, the master redundancy controller periodically broadcasts key decision results, such as the "target control command" and "target position data," to all slave redundancy controllers. This ensures that if the master redundancy controller fails, the new master redundancy controller can instantly take over, achieving a "hot backup" of the control state.
[0034] Each of the at least two redundancy controllers 11 is connected to each of the servo controllers in the servo control module and a corresponding communication unit in the position acquisition module via a communication network. The corresponding communication unit can be an independent position manager or a sensor with this function integrated.
[0035] The master redundancy controller is the core executor of all arbitration functions. These arbitration functions are defined and executed by a series of carefully selected mechanisms, including: 1. First Selection Mechanism (Master-Slave Election) The first-selection mechanism is designed to ensure that there is one and only one master redundant controller (master) in the system at all times, while the other redundant controllers serve as slave redundant controllers (slave controllers) in hot standby mode. This ensures the unique source of control commands and avoids system conflicts caused by multiple controllers issuing commands simultaneously.
[0036] In one embodiment, the mechanism is implemented based on a preset priority, and its specific workflow is as follows: (1) A unique machine number is set for each redundancy controller 11 (for example, controller A is number 1, controller B is number 2), and all numbers are stored in each redundancy controller according to a preset priority (for example, the smaller the number, the higher the priority).
[0037] (2) During system initialization or normal operation, the at least two redundancy controllers communicate with each other and select the redundancy controller corresponding to the machine number with the highest priority from all the redundancy controllers in normal working state according to the preset priority sorting as the main redundancy controller.
[0038] (3) Verify the working status of the master redundant controller in real time, and when it is detected that the master redundant controller has failed (such as failing to send a heartbeat message within a preset time, a key calculation unit (CRC) check error, or a self-test program reporting a serious error, etc.), reselect the redundant controller with the highest priority from the remaining slave redundant controllers in normal working condition according to the preset priority sorting to upgrade to the new master redundant controller. The failed master redundant controller is downgraded to a slave redundant controller or is no longer used. Usually, only the master redundant controller is in working condition and performing control tasks at the same time, and the other slave redundant controllers are in standby state.
[0039] In a preferred embodiment, to accurately identify and manage each redundant controller, the system employs a hierarchical address allocation scheme. Each redundant controller is assigned a unique device address. This device address can consist of two parts: a servo address, which identifies the macro-object served by the group of redundant controllers (e.g., a specific servo or actuator); and a multi-redundancy number, which uniquely identifies each redundant controller within the group (e.g., controllers 1 and 2).
[0040] Furthermore, to enable efficient synchronous control or global command distribution, this address allocation scheme can also include a broadcast mechanism. For example, a specific "redundancy number" (such as "0") can be predefined as a broadcast identifier. When the host computer or master redundancy controller sends a command with an address containing the broadcast identifier, all redundancy controllers belonging to that "servo address" will receive and process the command. This supports advanced system features such as batch configuration and synchronized reset.
[0041] 2. Second selection mechanism (command source ruling) The second selection mechanism processes control commands from one or more host computers 40 and determines a unique, valid target control command. As a fundamental principle, all bidirectional communication of commands adheres to a pre-defined communication protocol, which includes data validation. Only valid data packets that pass validation are accepted by the system for subsequent processing; any data packets with validation errors are discarded.
[0042] In one embodiment, the system can be configured in a host computer master-slave mode or a host computer multi-master mode to execute the second selection mechanism: Host computer master-slave mode: This mode is suitable for scenarios where multiple independent host computers are connected and a master command source needs to be designated. The connection method is: the host computer designated as the master has its corresponding command source signal port connected to the input channel of the master redundancy controller of this system; the host computer designated as the slave has its corresponding command source signal port connected to the input channel of the slave redundancy controller of this system.
[0043] Host computer multi-master mode: In this mode, the master redundancy controller receives valid input commands from all command sources in normal working state and uses the last valid input command received as the current target control command. Specifically, the process of "the master redundancy controller receiving input commands" covers the following two physical paths: 1. Direct reception: The master redundancy controller can receive input commands directly from the host computer connected to its own input channel.
[0044] 2. Forward reception: When a slave redundancy controller receives a command from the host computer from its connected input channel, it will immediately forward the command to the current master redundancy controller through the internal communication bus between the redundancy controllers.
[0045] Therefore, this flexible internal command routing mechanism ensures that no matter which physical port the host computer is connected to the system, its instructions can be effectively aggregated to the main redundancy controller for unified decision processing.
[0046] As an alternative arbitration scheme, the master redundancy controller can also adjudicate all host computer commands received during each control cycle. If multiple commands are received during the same cycle, the command with the highest priority is selected as the target control command based on the preset host computer priority (i.e., the redundancy controller's own port priority). If only one command is received during the cycle, it is directly adopted.
[0047] The master redundant controller has a flexible path for receiving commands from the host computer. It can receive commands directly from the connected host computer, or it can receive commands forwarded by a slave redundant controller from its connected host computer. This design ensures that no matter which redundant controller the host computer is connected to, its commands are effectively passed to the master controller for processing.
[0048] The system architecture of the present invention is highly flexible and can support a variety of host computer configurations and usage scenarios.
[0049] In one scenario (Scenario 1), a host computer can be connected in parallel to at least two (or more) redundancy controller interfaces of the system through one or more of its ports. In this case, the system recognizes these connection ports from the same host computer as a unified command source.
[0050] In another scenario (Scenario 2), multiple independent host computers can be connected to different redundancy controller interfaces. In this case, if the host computer itself has differentiated priorities, it is recommended to connect them according to the priority of the redundancy controller command input channels, so that the master redundancy controller can distinguish and manage them. This multi-host configuration, combined with the "host computer master-slave mode" or "host computer multi-master mode" described above, can provide redundancy at the command source level for the system, greatly improving system reliability.
[0051] 3. Third Selection Mechanism (Location Data Decision) The third selection mechanism is responsible for processing at least two parallel paths of position data from the position acquisition module 30 to determine the most reliable target position data. In one embodiment, the system is configured to execute the third selection mechanism in at least one of the following modes: Position data master-slave mode: a unique branch number is set for each position acquisition branch, and the branches are stored according to a preset priority order; the master redundancy controller determines the master position acquisition branch according to the preset priority, and when the data of the master position acquisition branch meets the preset normal working conditions, its position data is adopted as the target position data; when the data of the master position acquisition branch does not meet the normal working conditions, the master redundancy controller selects the next highest one from the remaining position acquisition branches in normal working state according to the preset priority as the new master position acquisition branch, and adopts its position data.
[0052] Position data optimal mode: The main redundancy controller selects the optimal branch from all position acquisition branches in normal working state in real time according to a preset optimal branch judgment algorithm, and uses the position data of the optimal branch as the target position data; wherein, the optimal branch judgment algorithm is based at least on the error between the position data of each position acquisition branch and the command position, and the branch with smaller error is preferentially selected as the optimal branch.
[0053] Position Data Common Mode: This mode does not select data from any single branch. Instead, it uses data fusion technology to create virtual data that is more accurate and reliable than any single source. It integrates position data from multiple normally operating branches, effectively smoothing out random noise or transient jumps from individual sensors, significantly improving the signal-to-noise ratio and robustness of position feedback. Specific implementation methods for this mode include: Method 1 (Central Fusion): The master redundant controller serves as the fusion center. It receives location data uploaded by all healthy location acquisition branches and then executes a pre-set data fusion algorithm within the master redundant controller (for example, weighted averaging of individual data or averaging after removing outliers) to calculate the final fused target location data.
[0054] Method 2 (Distributed Collaboration): Each position acquisition branch performs collaborative fusion. In this architecture, multiple functioning position acquisition branches exchange their collected position data via intercommunication links. They collaboratively execute a common data fusion algorithm locally, generating unified, fused target position data without intervention from the master redundant controller. Finally, one (or all) of the branches transmits this unique fusion result to the master redundant controller. This method effectively reduces the computational burden on the master redundant controller.
[0055] 4. The fourth selection mechanism (execution branch selection) The fourth selection mechanism is responsible for determining which branches in the steering gear control module 20 the final generated control information is sent to. In one embodiment, the fourth selection mechanism includes: The main redundancy controller receives and processes the verification signal (usually motor status data including current, voltage, temperature and other information) uploaded by each steering gear control branch in real time to determine whether each steering gear control branch is in normal working condition; The master redundancy controller determines one or more steering gear control branches as the target steering gear control branches from all steering gear control branches in normal working state according to a preset control strategy.
[0056] The preset control strategies include the following: Under one strategy, the system can be configured as a single-channel master mode, that is, only the healthy branch with the highest priority is selected as the target to execute instructions, and the remaining healthy branches serve as hot backups.
[0057] Alternatively, the system can be configured in multi-channel shared control mode. In this mode, all healthy branches with an "OK" feedback status can receive control commands and jointly drive the load. This can be used for load sharing or smoother redundant switchover.
[0058] Any fault branch with a feedback status of "ERR" will be excluded and will not receive any control command, or will not be executed even if it receives one.
[0059] 5. Instruction Generation and Information Processing Mode The master redundancy controller can be configured to operate in two core modes: Method 1: Instruction Generation Mode In this mode, the master redundant controller acts as a "senior commander." It not only receives and determines upper-level commands and position feedback but also proactively performs complex calculations. Specifically, based on the motor status data it receives from each branch and the global control objectives, the master redundant controller directly generates specific servo control instructions (such as PWM signals with precise timing and amplitude, or low-level drive instructions similar to "throttle signals") to drive the motors. This instruction is then sent to the selected target servo control branch for execution and can be simultaneously uploaded to the host computer for monitoring.
[0060] Method 2: Information forwarding mode In this mode, the master redundant controller acts as an "information hub and decision-maker." It adjudicates commands and data but does not generate underlying control instructions. It packages the adjudicated target control command and target position data into a control packet and sends it downstream to the target servo control branch. Simultaneously, it aggregates only the raw motor status data collected from each branch and uploads it to the host computer. In this mode, the specific generation of the "throttle signal" is performed locally by the servo controller.
[0061] Servo control module 20 The steering engine control module 20 is used to execute the steering engine control instruction to drive the motor 23 to rotate. Figure 1 As shown, the steering gear control module 20 includes at least two steering gear control branches connected in parallel to achieve redundancy at the execution level. Each steering gear control branch is an independent control execution unit, including a steering gear controller 21, a motor controller 22 and a motor 23.
[0062] The servo controller 21 is a control unit based on a high-performance MCU or DSP. The motor controller 22 is a motor drive chipset or module with power drive capabilities and hardware protection. The branch circuit also includes detection modules for monitoring motor conditions such as current, voltage, and temperature. These modules include current sensors, voltage sensors, temperature sensors, and their signal conditioning circuits. These detection modules are electrically connected to the analog or digital input interfaces of the servo controller 21. The control signals (such as PWM signals) from the servo controller 21 are output to the control input terminals of the motor controller 22. A communication interface circuit is used to communicate with the redundancy control module 10.
[0063] Each servo control branch receives servo control commands and target position data from the redundancy control module 10. Based on this information and the motor status data monitored by the detection module, the servo controller 21 employs a closed-loop control algorithm to generate an electrical control signal, which it sends to the motor controller 22. Based on the received electrical control signal, the motor controller 22 drives the motor 23 to move along the desired trajectory. Each servo control branch's motor 23 is connected to a main output shaft (not shown), which in turn is connected to various loads (such as propellers).
[0064] The detection module is used to monitor the operation of the motor 23 to obtain motor status data (operating voltage, operating current, etc.) and transmit the motor status data to the steering gear controller 21. The steering gear controller 21 uploads the motor status data as a status verification signal to the redundancy controller 11 in the redundancy control module 10.
[0065] Each servo control branch features both software and hardware protection. Software protection is implemented by the servo controller 21. It compares motor status data obtained by the detection module with preset protection levels (warning and shutdown levels) and initiates corresponding actions (such as output limiting and shutdown) and provides feedback (such as uploading a warning signal). Hardware protection is implemented by the motor controller 22 and the protection circuitry on the circuit board. These include a reverse power supply protection circuit, overcurrent protection (such as a fuse), and internal motor driver protection for overvoltage, undervoltage, overtemperature, short circuit, and phase loss. Parameters tested by the software protection include voltage, current, and temperature.
[0066] The servo controller 21 is configured to perform self-test and fault diagnosis functions. For example, the servo controller 21 monitors the communication status of the detection module. If the detection module fails to transmit motor status data for a predetermined time threshold, the servo controller 21 determines that the detection module or the servo control branch in which it resides has failed, generates a second fault tag, and uploads this fault tag to the redundancy controller 11 in the redundancy control module 10. Each servo controller 21 is assigned a servo branch number, which is stored in each redundancy controller 11 according to a predetermined priority order.
[0067] Position acquisition module 30 The position acquisition module 30 is used to acquire the actual position of the steering gear and provide position data. Figure 1 As shown, the position acquisition module 30 includes multiple position acquisition branches connected in parallel to achieve redundancy at the position feedback level. Each position acquisition branch is an independent position information acquisition unit. Each position acquisition branch includes a position manager 31 and a position sensor 32. The position manager 31 is a circuit board based on an MCU or a dedicated signal processing chip, which is used to receive the raw data from the position sensor 32 and perform preprocessing (such as signal amplification, filtering, and calibration). The position sensors 32 in the multiple position acquisition branches are all used to measure the rotation or displacement of the main output shaft. For example, they can be high-precision encoders, rotary transformers, grating scales, etc. The position manager 31 uploads the processed position data to the redundancy control module 10 via the communication interface circuit. The parameters of key electronic components such as the position manager chip and position sensor are selected based on the required control accuracy, motion range, environmental conditions, reliability level, and communication rate.
[0068] The location manager 31 of each location acquisition branch receives real-time location data uploaded by the corresponding location sensor 32 and processes the data. The processed location data is compared with a preset location threshold. Data that does not exceed the threshold is marked as valid and uploaded to the redundancy control module 10; data that exceeds the threshold is marked as invalid and discarded. A first fault tag is generated for the location acquisition branch and uploaded to the redundancy controller 11 in the redundancy control module 10. The first fault tag can be a fault code (e.g., exceeding the threshold, data jump, signal loss, etc.). The location manager 31 also has a self-test function. When it detects a fault, it generates a location branch self-test fault tag and uploads it to the redundancy controller 11 in the redundancy control module 10. Each location acquisition branch is assigned a unique branch number, and the location manager 31 is assigned the same branch number as the location acquisition branch. All location branch numbers are stored in each redundancy controller 11 in order of priority.
[0069] It should be understood that the location manager's function is to process raw data from the location sensors, perform communication, and manage addresses. In some embodiments, the location manager can be a separate hardware unit. In other embodiments, if the selected location sensors already have integrated communication and address management functions, or if these functions are directly handled by the redundancy controller, the location manager may not exist as a separate physical entity.
[0070] Power Module The power module is configured to be electrically connected to the redundancy control module 10, the servo control module 20 and the position acquisition module 30, and to provide them with the electrical energy required for operation. The power module is intended to provide high reliability and redundancy to avoid system failure due to power failure. In one embodiment, the power module includes at least one or more power supply units. Each power supply unit is configured to receive electrical energy from different input power sources, such as external power supply 1 and external power supply 2, and convert it into the DC working voltage required by the system through circuits such as rectification, filtering, and voltage stabilization. The power module provides independent power outputs to the redundancy control module 10, the servo control module 20 and the position acquisition module 30 to achieve power redundancy. This independent power output structure ensures that the power conversion or load failure of one unit or branch will not directly affect the power supply of other units or branches. By adopting multiple power supply units and connecting them to different input power sources, and providing independent power outputs for each unit and branch, multiple redundancy at the power supply level is achieved.
[0071] like Figure 1 As shown, the signal flow of the servo control system according to the embodiment of the present application is as follows: 1. Control command input: The host computer 40 generates a control command and sends it to each redundancy controller 11 of the redundancy control module 10 through the communication network.
[0072] 2. Redundancy control module processing: Each redundancy controller 11 receives and stores control commands. The master redundancy controller adjudicates these commands according to the second selection mechanism and generates target control commands.
[0073] 3. Location Data Collection and Upload: Each location data collection branch of the location acquisition module 30 simultaneously collects location data. The location manager 31 locally processes the data, determines its validity, and marks it as a fault (a first fault tag). It then uploads the valid data to the redundancy controllers 11 of the redundancy control module 10.
[0074] 4. Position data determination: The master redundancy controller receives position data from multiple position acquisition branches and determines the target position data according to a third selection mechanism (position data master-slave mode, position data optimal mode, or position data common mode).
[0075] 5. Uploading of Status Verification Signals for Servo Control Branches: Each servo control branch in the servo control module 20 acquires motor status data through the detection module. The servo controller 21 then uploads this data as a status verification signal to the redundancy controllers 11 in the redundancy control module 10. If a servo controller 21 detects a fault during self-diagnosis, it generates and uploads a second fault tag.
[0076] 6. Selection of steering gear control branch: The main redundancy controller selects one or more target steering gear control branches based on the fourth selection mechanism and the status verification signal uploaded by the steering gear control branch.
[0077] 7. Control Information Generation and Transmission: The "control information" generated by the master redundancy controller can take, but is not limited to, the following two forms: Mode 1 (Command Generation Mode): The "control information" is a servo control command directly generated by the master redundancy controller based on the target control command and target position data, which drives the motor. Mode 2 (Information Forwarding Mode): The "control information" is a data packet containing at least the determined target control command and target position data. This data packet is transmitted to the target servo control branch. The servo controller in that branch generates the final motor drive signal based on this information and its own state.
[0078] 8. Servo Control Execution: The selected target servo control branch receives control information. Based on the control information and motor status data, the servo controller 21 generates an electrical control signal to drive the motor 23. When the main redundancy controller selects multiple servo control branches to work together, the control information it sends (whether instructions or data packets) can be the same or different for each branch. However, the servo controller in each target servo control branch will perform independent closed-loop calculations based on the received control information and its own real-time monitored motor status data (such as current, voltage, temperature, etc.) to generate differentiated motor drive signals to achieve load balancing or precise coordinated control. This demonstrates the intelligent collaborative capabilities of this system at the execution level.
[0079] 9. Status Feedback and Fault Reporting: The redundancy control module 10 aggregates system status information, fault tags (primary and secondary fault tags), and self-test fault information, generating feedback data and uploading it to the host computer 40. After the master and slave redundancy controllers are determined, the master redundancy controller generates master-slave status information and uploads it to the host computer 40.
[0080] The servo control system of the embodiment of the present application works as follows: 1. Power-on initialization: Power on the entire control system. The power module starts working and provides power to each unit and branch. Each redundancy controller 11, each servo control branch, and position acquisition branch performs initialization processes such as hardware self-test, parameter loading, and communication link establishment synchronously or according to a preset timing. The various redundancy controllers 11 in the redundancy control module 10 communicate with each other and determine the master redundancy controller based on the first selection mechanism. The master redundancy controller sends the judged servo feedback data to each slave redundancy controller 11 at a time (the data may be empty during the initialization phase). The slave redundancy controller 11 receives the servo feedback data and saves it in the cache for query by the host computer 40. At the same time, the input command sent by the host computer 40 is transmitted to the master redundancy controller.
[0081] 2. Control cycle loop: After initialization is completed, the system enters the control cycle loop. The main redundancy controller receives multiple sets of position data and determines the target position data according to the third selection mechanism. The main redundancy controller receives input commands from each host computer 40 and determines the target control command according to the second selection mechanism. The main redundancy controller selects one or more target servo control branches based on the fourth selection mechanism and the status verification signal uploaded by the servo control branch. The main redundancy controller generates a servo control instruction and sends it to the selected target servo control branch. The selected target servo control branch receives the instruction and drives the motor to move. At the same time, the redundancy control module 10 summarizes the system status and fault information, forms feedback data and uploads it to the host computer 40.
[0082] 3. Redundancy fault tolerance: During the entire control process, the redundancy mechanisms in the redundancy control module 10, the servo control module 20, and the position acquisition module 30 continue to work. If the main redundancy controller fails (for example, self-test failure, communication interruption), the other slave redundancy controllers automatically take over according to the preset priority. If the target servo control branch or position acquisition branch fails (for example, motor overcurrent, sensor data abnormality), the branch will be marked as a fault, and the other normal branches will take over according to the preset plan and selected mechanism, thereby ensuring that the entire servo control system can operate normally and has high operational reliability. During the entire control process, if the main redundancy controller fails, the slave redundancy controller will take over and replace the original main redundancy controller; if the target servo control branch fails, the other servo control branches will take over; if the target position acquisition branch fails, the other position acquisition branches will take over, thereby ensuring that the entire servo control system can operate normally and has high operational reliability.
[0083] In the above technical solution of this embodiment, by adding multiple parallel redundancy controllers to the servo control system, the control system no longer relies on the control of a single redundancy controller, thereby improving the redundancy capability of the control system and improving the stability and reliability of the control system; each redundancy controller 11 is provided with multiple upper ports, which can be connected to multiple host computers 40 through multiple upper ports. When a certain host computer 40 fails and cannot be controlled, other host computers 40 can replace it, further improving the stability and reliability of the servo control system; in addition, the position acquisition branch is independently set. When the motor controller 22 fails, the redundancy control module 10 and the host computer 40 can still obtain the signal collected by the position sensor 32, and know the current status of the motor 23 in time, which brings convenience to the maintenance of the servo control system and improves the reliability of the overall system.
[0084] Furthermore, each module determines the only controller or independent branch involved in the work based on the corresponding selection mechanism, so that as long as there is one controller or independent branch in the entire control system operating normally, the normal operation of the product can be guaranteed, thereby improving the stability and reliability of the entire servo control system.
[0085] Furthermore, the position acquisition module 30 and the steering gear control module 20 also have a self-checking function, which can detect their own faults in time and stop working, so that other branches can take over the corresponding work in time, and the intelligence is further enhanced.
[0086] Furthermore, the servo control system is also provided with multiple independently arranged power supply circuits, each power supply circuit being connected to a different input power supply to achieve power supply redundancy, thereby further ensuring the working stability of the entire servo control system.
[0087] Accordingly, the present application also provides a multi-level redundant servo control method, which can be implemented based on the system in any of the aforementioned embodiments. Figure 2 As shown, the specific process of the method may include the following steps: Step S1: System Initialization and Master Controller Election. After the system is powered on, at least two redundancy controllers 11 in the redundancy control module 10 communicate with each other. Each redundancy controller 11 executes a first selection mechanism based on a pre-stored priority ranking based on unique identifiers. From among all redundancy controllers in normal operation, a single master redundancy controller with the highest priority is selected. The remaining redundancy controllers serve as slaves.
[0088] Step S2: Determination of target control command: After entering the control cycle, the master redundancy controller executes a second selection mechanism to determine the target control command from the input commands from one or more command input channels.
[0089] Step S3: Determine target position data. The master redundancy controller executes a third selection mechanism. It receives position data uploaded by at least two position acquisition branches from the position acquisition module 30 and determines target position data based on a preset mode (e.g., position data master-slave mode, optimal mode, or position data shared mode).
[0090] Step S4: Selection of target execution branch: The master redundancy controller selects one or more target steering gear control branches from at least two steering gear control branches according to the fourth selection mechanism.
[0091] Step S5: Generate and send control information. The master redundancy controller generates and sends corresponding control information to the one or more target servo control branches based on the target control command and target position data according to a preset control mode (command generation mode or information forwarding mode) to control the operation of the corresponding motors.
[0092] Step S6: Status Feedback and Fault Reporting. The system aggregates the status information and fault tags of each module. The master redundancy controller generates feedback data and uploads it to the host computer. This step also requires different reporting content depending on the control mode (command generation / information forwarding).
[0093] For the sake of clarity, those skilled in the art should understand that terms such as "redundancy controller," "servo controller," "position manager," and "motor controller" described in the specification and claims refer to functional modules or logic units with specific functions. These modules can be implemented through independent physical hardware (such as separate chips or circuit boards) or integrated into one or more programmable chips (such as system-on-chips (SoCs), FPGAs, or multi-core microcontrollers (MCUs)) through software, firmware, or programming in hardware description languages. Therefore, these terms are logical layer concepts for ease of understanding and should not be limited to independent physical entities.
[0094] Note that the above are only preferred embodiments of the present application and the technical principles employed. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and that various obvious changes, readjustments, and substitutions can be made by those skilled in the art without departing from the scope of protection of the present application. Therefore, although the present application has been described in more detail through the above embodiments, the present application is not limited to the above embodiments and may include many other equivalent embodiments without departing from the scope of the present application. The scope of the present application is determined by the scope of the appended claims.
Claims
1. Multi-level redundant servo control system, characterized in that, include: A redundancy control module, configured to receive control commands from one or more host computers and output servo control instructions, wherein the redundancy control module includes at least two redundancy controllers connected in parallel, and the at least two redundancy controllers communicate with each other and are electrically connected; a steering gear control module, configured to execute the steering gear control instructions to drive the motor to rotate, the steering gear control module comprising at least two steering gear control branches connected in parallel, each of the steering gear control branches comprising a steering gear controller, a motor controller, and a motor, wherein the steering gear controller is connected to the motor controller to drive the motor to operate; A position acquisition module, configured to acquire the actual position of the servo to provide position data, wherein the position acquisition module comprises at least two position acquisition branches connected in parallel; Wherein, each of the at least two redundancy controllers is communicatively connected with each of the servo controllers in the servo control module and the corresponding communication unit in the position acquisition module via a communication network; The at least two redundancy controllers determine one of the redundancy controllers as a master redundancy controller based on a first selection mechanism; The main redundancy controller is configured to: Determining a target control command from input commands sent by one or more host computers according to a second selection mechanism; Determining target position data from the position data acquired by the at least two position acquisition branches according to a third selection mechanism; Determine a target steering gear control branch from the at least two steering gear control branches according to a fourth selection mechanism; and Based on the target control command and the target position data, control information is generated and sent to the target steering gear control branch, so that the target steering gear control branch controls the operation of its corresponding motor.
2. The multi-level redundant servo control system according to claim 1, characterized in that: The first selection mechanism includes: Setting a unique machine number for each of the at least two redundancy controllers, and sorting all the machine numbers according to a preset priority and storing them in each redundancy controller; During system initialization or normal operation, the at least two redundancy controllers communicate with each other and select the redundancy controller corresponding to the machine number with the highest priority from all redundancy controllers in normal working state according to the preset priority sorting as the master redundancy controller; and The working status of the master redundancy controller is verified in real time, and when a failure of the master redundancy controller is detected, the redundancy controller with the highest priority is reselected from the remaining slave redundancy controllers in normal working state according to the preset priority sorting to be upgraded to the new master redundancy controller.
3. The multi-level redundant servo control system according to claim 1, characterized in that: The system is configured to perform the second selected mechanism by at least one of the following modes: Master-slave mode of the host computer: set the preset priority for each command input channel that receives input commands; The redundancy controller monitors the status of all command input channels in real time, and selects the input command received from the command input channel with the highest priority that is currently in a normal working state as the target control command according to the preset priority; Furthermore, when it is detected that the command input channel with the highest priority fails or the communication times out, the redundancy controller automatically selects the input command received from the command input channel with the second highest priority that is currently in normal working state as the new target control command; Host computer multi-master mode: The master redundancy controller receives input commands sent from all host computers in normal working state, and uses the last received valid input command as the target control command.
4. The multi-level redundant servo control system according to claim 3, characterized in that: The path for the main redundancy controller to receive the input command includes at least one of the following: Receive input commands from one or more host computers directly connected to it; Receive input commands forwarded by other slave redundancy controllers and received by the slave redundancy controller from the host computer to which it is connected.
5. The multi-level redundant servo control system according to claim 1, characterized in that: The system is configured to execute the third selected mechanism by at least one of the following modes: Position data master-slave mode: A unique branch number is set for each position acquisition branch and stored according to a preset priority order; the master redundancy controller determines the master position acquisition branch based on the preset priority, and when the data of the master position acquisition branch meets the preset normal working conditions, its position data is used as the target position data; When the data of the main position acquisition branch does not meet the normal working conditions, the main redundancy controller selects the next highest priority from the remaining position acquisition branches in normal working state according to the preset priority as the new main position acquisition branch and adopts its position data; Position data optimal mode: The master redundancy controller selects the optimal branch from all position acquisition branches in normal working condition in real time according to a preset optimal branch judgment algorithm, and uses the position data of the optimal branch as the target position data. The optimal branch judgment algorithm is based on at least the error between the position data of each position acquisition branch and the command position, and the branch with the smaller error is preferentially selected as the optimal branch. Position data common mode: The position data from multiple position acquisition branches in normal working conditions are processed through a preset data fusion algorithm to generate a fused target position data; The data fusion algorithm is executed in any of the following ways: Method 1: The master redundancy controller receives all position data and executes the data fusion algorithm to generate the target position data; Method 2: The at least two position acquisition branches communicate with each other to exchange their respective position data, collaboratively execute the data fusion algorithm to generate the target position data locally, and then uniformly upload the generated target position data to the main redundancy controller.
6. The multi-level redundant servo control system according to claim 1, characterized in that: The fourth selection mechanism includes: The main redundancy controller receives and processes the verification signal uploaded by each steering gear control branch in real time to determine whether each steering gear control branch is in a normal working state; The master redundancy controller determines one or more steering gear control branches as the target steering gear control branches from all steering gear control branches in normal working state according to a preset control strategy.
7. The multi-level redundant servo control system according to claim 6, characterized in that: Each of the servo control branches also includes a detection module, which is used to monitor the operation of the motor in its branch to obtain motor status data, and transmit the motor status data to the servo controller of the branch, and the servo controller uploads the motor status data as the verification signal to the redundancy controller.
8. The multi-level redundant servo control system according to claim 7, characterized in that: The steering gear controller is further configured to: When it does not receive the motor status data transmitted from the detection module within a preset time threshold, it is determined that the steering gear control branch in which it is located has a fault; Furthermore, a second fault tag is generated for the failed steering gear control branch, and the second fault tag is uploaded to the redundancy controller.
9. The multi-level redundant servo control system according to claim 1, characterized in that: Each of the position acquisition branches includes a position manager and a position sensor. The position manager is connected to the position sensor to obtain position data and is responsible for communication and address management of the position acquisition branch.
10. The multi-level redundant servo control system according to claim 9, characterized in that: The location manager in each location collection branch is further configured to perform local data verification, including: receiving real-time location data from its corresponding location sensor and comparing the real-time location data with a preset location threshold; If the real-time position data does not exceed the preset position threshold, uploading the position data to the master redundancy controller; If the real-time position data exceeds the preset position threshold, the position data is discarded, and a first fault tag is generated for the position acquisition branch, and the first fault tag is uploaded to the redundancy controller.
11. A multi-level redundant servo control method, applied to a servo control system comprising at least two redundancy controllers, at least two steering gear control branches, and at least two position acquisition branches, characterized in that: The following steps are involved: Among the at least two redundancy controllers communicating with each other, determining one redundancy controller as a master redundancy controller based on a first selection mechanism; The master redundancy controller determines the target control command from the input commands from one or more command input channels according to a second selection mechanism; The main redundancy controller determines target position data from the position data acquired by the at least two position acquisition branches according to a third selection mechanism; The master redundancy controller selects one or more target steering gear control branches from the at least two steering gear control branches according to a fourth selection mechanism; as well as The main redundancy controller generates servo control information based on the target control command and the target position data, and sends the servo control information to the one or more target servo control branches, so that the target servo control branches control the operation of their corresponding motors.
Citation Information
Patent Citations
Data exchange and synchronization method and data exchange and synchronization device for three-redundancy servo controller
CN104597850A
Integrated servo mechanism
CN110609466A
Multi-redundancy electromechanical servo system for regulating liquid rocket engine and implementation method therefor
US20200362796A1
Cited By
Data processing method and system and electronic equipment
CN121143131A
Non-similar redundancy servo control method and system
CN122225943A