Dual-redundancy fault-tolerant aeronautical electric machine drive control method and system
By constructing a multi-physics coupling model and a dynamic response and thermal safety negotiation-based aero-motor drive control method, the problems of multi-physics coupling constraints and fault tolerance under fault modes are solved, achieving refined control and hardware adaptive power allocation, thereby improving the performance and reliability of aero-motors.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHEJIANG SHITAI IND CO LTD
- Filing Date
- 2026-05-07
- Publication Date
- 2026-06-02
AI Technical Summary
Existing aviation motor drive control methods fail to effectively coordinate multi-physics field coupling constraints, dynamic response and thermal safety are difficult to coordinate in real time, fault mode fault tolerance strategies are crude, and dual-redundant hardware power allocation lacks health state adaptive capability, resulting in large performance prediction deviations and improper fault handling.
A multiphysics coupling constraint mapping model is constructed to perform flux folding iteration under thermal safety constraints, dynamic response and thermal safety game negotiation, and adaptive allocation of redundant channel power based on hardware health status to achieve fine fault-tolerant control under fault mode.
It improves the performance prediction accuracy and control response speed of aircraft motors under extreme conditions, ensures safe thrust output and vibration and noise control in failure mode, and enhances both system mission reliability and lifespan.
Smart Images

Figure CN122137287A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of aviation motor drive control technology, specifically to a dual-redundant fault-tolerant aviation motor drive control method and system. Background Technology
[0002] Against the backdrop of rapid development in avionics electric propulsion systems and multi-electric / all-electric aircraft technology, the performance of avionics motors and their drive control systems directly affects the safety and reliability of aircraft. In actual operation, avionics motors face multiple challenges, including high power density, strong coupling of multiple physical fields, harsh thermal environments, and the risk of sudden failures. To improve system fault tolerance, dual-redundant and even multi-redundant motor topologies are widely adopted. However, existing control methods often model and optimize electrical, magnetic, thermodynamic, and mechanical dynamics separately, neglecting the nonlinear coupling and dynamic constraint transmission between these physical fields. This leads to significant deviations in motor performance prediction under extreme conditions. Furthermore, traditional control strategies struggle to coordinate and balance the dynamic response speed of the current loop and the thermal safety boundaries of power devices within milliseconds when dealing with sudden load increases and decreases during high-maneuver flight. This can easily lead to overheating failure due to control pulse width overshoot or insufficient thrust due to response lag.
[0003] In existing technologies, some solutions use offline calibrated voltage vector feasible regions for drive control. However, these boundaries are relatively static and cannot adapt to the varying DC bus voltage utilization and back EMF characteristics within the flight envelope. When local faults occur, such as stator winding inter-turn short circuits or position sensor failures, traditional fault-tolerance strategies typically employ simple derating or direct disconnection of the faulty phase. These strategies lack a mechanism for fine-tuning and mapping of remaining thrust capacity and vibration / noise levels to minimum control corrections. This results in excessively large or small flight safety margins in fault modes, making a smooth transition from normal to fault modes difficult. Furthermore, in dual-redundant drive systems, the power allocation between primary and backup inverters is often based on fixed ratios or simple rotation strategies, failing to dynamically optimize based on the real-time health status of power devices, thus limiting the overall system lifespan and mission reliability. Summary of the Invention
[0004] To overcome the problems of fragmented multi-physics coupling constraints, difficulty in real-time coordination of dynamic response and thermal safety, coarse fault-tolerant strategies for fault modes, and lack of health-state adaptive capability in dual-redundant hardware power allocation in existing technologies, this invention provides a dual-redundant fault-tolerant aero-motor drive control method and system. It achieves dynamic balance between thermal limits and thrust requirements under all flight conditions, fine fault tolerance with minimum correction for flight safety under fault modes, and adaptive allocation of redundant channel power based on hardware health status. This significantly improves the overall control quality and mission reliability of aero-motor drive systems under multi-physics coupling, dynamic disturbance, and sudden failure conditions.
[0005] The technical solution of this application specifically includes: According to one aspect of this application, a dual-redundant fault-tolerant aircraft motor drive control method is provided, comprising: Collect aircraft motor parameters to establish a multiphysics field coupled constraint mapping model and set the model boundary. Combine the DC bus effective voltage utilization rate and the motor back electromotive force to determine the feasible region of the initial voltage vector. Based on the feasible region of the initial voltage vector, magnetic flux folding iteration based on thermal safety constraints is performed to determine the optimal magnetic flux trajectory; Based on the simulation of large-scale mobile load conditions using the optimal magnetic flux trajectory, pulse width variation is detected. Based on this, magnetic flux is re-folded or the feasible region of the initial voltage vector is adjusted to determine the pulse width parameters that satisfy dynamic response and thermal limit. Based on the pulse width parameter, inject inter-turn short circuit or position sensor failure fault signal, check the remaining thrust and vibration noise, determine the minimum control correction amount and combine it with the normal mode parameter to form a comprehensive control parameter; The comprehensive control parameters are mapped to the hardware, and the power output ratio of the main and backup inverters in the dual-channel redundant drive is dynamically allocated according to the real-time health status. The control boundary parameters are fixed in the flight control computer, and the operation data is collected in real time. When the data deviates from the model boundary, the magnetic flux folding is automatically triggered until the switching control signal that meets the requirements of thermal safety and dynamic performance is output.
[0006] As a further option of the method of the present invention, the step of establishing the multiphysics coupling constraint mapping model includes: Establish an electrical constraint sub-model to describe Axis voltage equation The relationship between shaft voltage equation and current limiting; Establish a magnetic confinement sub-model to describe Axial flux linkage equation, The nonlinear relationship between the axial flux linkage equation and the current, as well as the saturation characteristics, are obtained by offline table lookup or online identification of the d-axis and q-axis inductance parameters that vary with the current. A thermally constrained sub-model is established, and a lumped parameter thermal network equation is used to describe the junction temperature dynamics and winding temperature dynamics of the power device. The thermal network equation includes the device thermal capacity, winding thermal capacity, the sum of the switching loss and conduction loss of the power device, the winding copper loss, and three sets of thermal resistance parameters. Establish a mechanical dynamics constraint sub-model to describe the dynamic equations of the motor shaft system, including rotational inertia, load torque, and damping coefficient; The model boundary conditions include: The electrical boundary is formed by the allowable fluctuation range of DC bus voltage and the peak value of phase current; the magnetic boundary is formed by taking 90% of the critical value of magnetic circuit saturation and the minimum magnetic flux corresponding to the thrust requirement; the thermal boundary is formed by the upper limit of the junction temperature safety of power devices, the upper limit of the temperature resistance of winding insulation and the thermal safety margin; and the mechanical boundary is formed by the maximum allowable torque pulsation and the maximum allowable speed fluctuation. Define the range of cross-coupling coefficients between the four sub-models, including the influence coefficient of temperature on resistance, the influence coefficient of temperature on flux linkage, and the transfer coefficient of current to loss and thus to temperature rise.
[0007] As a further option of the method of the present invention, the method for determining the feasible region of the initial voltage vector includes: For the current flight phase, obtain the measured value of DC bus voltage and motor speed, and calculate the DC bus voltage utilization rate. The calculation formula is: ,in For the reference voltage vector magnitude, This is the DC bus voltage; Calculate the back electromotive force amplitude The calculation formula is: ,in The back electromotive force constant is... It is the mechanical angular velocity; Determining the feasible region of the voltage vector based on DC bus voltage utilization. The constraint formula for the feasible region of the voltage vector is expressed as follows: ,in , for , shaft voltage, This is the DC bus voltage; By combining the back EMF amplitude constraint, the actual feasible region is further restricted to a set of points that satisfy the voltage vector feasible region constraint formula, and the actual feasible region is discretized into several candidate voltage vector points. The voltage utilization rate and the corresponding current prediction value and torque prediction value of each candidate voltage vector point are recorded.
[0008] As a further option of the method of the present invention, the optimal magnetic flux trajectory determination step includes: Set the initial upper limit, initial lower limit, convergence accuracy, and maximum number of iterations for flux folding; Within the current folding interval, intermediate candidate flux linkage amplitudes are selected. The gradient descent method is used to solve for the optimal voltage vector within the feasible region of the initial voltage vector. The objective function is the absolute value of the difference between the output electromagnetic torque and the required torque. The constraints are that the flux linkage amplitude does not exceed the candidate flux linkage amplitude and the optimal voltage vector lies within the feasible region of the initial voltage vector. During the solution process, calculations are performed based on the current using a magnetic constraint sub-model. Shaft inductance and Shaft inductance, and substitute it into the electromagnetic torque calculation formula. Calculate electromagnetic torque ,in , for , Axial magnetic flux, , for , shaft current, It is the extreme logarithm; The obtained optimal voltage vector is substituted into the thermal constraint sub-model, and the steady-state junction temperature and winding temperature rise are calculated using the thermal network equation. Calculate thermal safety margin The formula for calculating the thermal safety margin function is: ,in, , These are the upper limits of junction temperature and winding temperature for power devices, respectively. For power device junction temperature, For winding temperature; If the thermal safety margin is less than the preset threshold, then folding upwards is performed to reduce the flux linkage amplitude; if the thermal safety margin is greater than or equal to the preset threshold and the deviation between the output electromagnetic torque and the required torque exceeds the allowable value, then folding downwards is performed to increase the flux linkage amplitude; if both thermal safety and thrust requirements are met, then the current candidate flux linkage amplitude is taken as the candidate optimal flux linkage amplitude. The iteration terminates when the difference in flux linkage amplitude between two consecutive iterations meets the convergence accuracy or the rate of change of thermal safety margin between two consecutive iterations is less than a preset threshold, and the optimal flux linkage amplitude and the corresponding optimal flux trajectory time series are output.
[0009] As a further option of the method of the present invention, the determination of the pulse width parameter that satisfies the dynamic response and thermal limit, including detecting pulse width variations and evaluating thermal constraint violations and dynamic performance deficiencies, includes: The three-phase pulse width modulation duty cycle of the inverter output is acquired during each current loop control cycle, and the pulse width variation is calculated. The calculation formula is: ,in, For the current loop control cycle, For a moment The pulse width modulation duty cycle, For a moment Pulse width modulation duty cycle; Substitute the current pulse width into the thermal constraint sub-model, use the thermal network equation to predict the junction temperature peak within a set time in the future. If the junction temperature peak is greater than the difference between the upper limit of the junction temperature safety of the power device and the thermal safety margin, then the thermal constraint is determined to be in violation and the thermal constraint violation flag is set to 1; otherwise, the thermal constraint violation flag is set to 0. The recovery time from the start of a load step change to the torque recovering to 90% of its steady-state value is measured. If the recovery time is greater than the allowable recovery time threshold, the dynamic performance is determined to be insufficient, and the dynamic performance insufficient flag is set to 1; otherwise, the dynamic performance insufficient flag is set to 0.
[0010] As a further option of the method of the present invention, in determining the pulse width parameter that satisfies the dynamic response and thermal limit, triggering flux folding or feasible region adjustment includes: If the thermal constraint violation flag is 1 and the dynamic performance deficiency flag is 0, then return to perform the flux folding iteration and temporarily increase the preset threshold of thermal safety margin by 10%. If the thermal constraint violation flag is 0 and the dynamic performance deficiency flag is 1, then return to the adjustment of the initial voltage vector feasible region, increasing the upper limit of voltage utilization by 5% to 10%. If the thermal constraint violation flag is 1 and the dynamic performance deficiency flag is 1, then the flux folding iteration is performed first to handle thermal safety, and the dynamic performance is re-evaluated based on the new flux trajectory after folding. If the thermal constraint violation flag is 0 and the dynamic performance deficiency flag is 0, then a multi-round negotiation phase is entered. The dynamic response index and the thermal safety index are treated as two game participants. A total cost function containing dynamic response weights and thermal safety weights is defined. Within the feasible region, a particle swarm optimization algorithm is used to search for the pulse width parameter that minimizes the total cost function. After each round of negotiation, the dynamic response weights and thermal safety weights are adjusted according to the change in the total cost function to simulate a concession strategy. After a maximum of 10 rounds of negotiation, the pulse width parameter on the Pareto optimal boundary is obtained.
[0011] As a further option of the method of the present invention, the step of determining the minimum control correction amount includes: When the motor is operating under steady-state conditions, inject a short circuit fault between turns of the stator winding or a position sensor failure fault. By slowly increasing the load command until the current reaches the protection threshold or a loss of synchronism occurs, the torque value at this time is recorded and the remaining thrust coefficient is calculated. The vibration spectrum is obtained by performing a fast Fourier transform on the vibration acceleration signal, the total vibration intensity is calculated, and the vibration intensity in the fault mode and normal mode is compared to obtain the vibration increment. If the thrust corresponding to the remaining thrust coefficient is less than the minimum thrust threshold required for flight safety, then the minimum correction amount is determined to include the current amplitude limit and the phase compensation angle corresponding to the optimal current angle that minimizes torque ripple. If the vibration increment is greater than the upper limit of the allowable vibration noise increment, the minimum correction amount is determined to include a switching frequency derating factor of 0.6 to 0.8 and a dead time adjustment value of +0.5μs to +2μs. If both thrust and vibration requirements are not met, linear programming is used to solve the objective function that minimizes the weighted sum of each correction. The constraints are that the corrected thrust is not lower than the minimum thrust threshold required for flight safety and the vibration increment does not exceed the upper limit of the allowable vibration noise increment.
[0012] As a further option of the method of the present invention, the comprehensive control parameter formation step includes: Map the current amplitude limit to the upper limit of the pulse width modulation duty cycle; The phase compensation angle is mapped to the spatial vector sector switching condition, the sector boundary angle is modified, and a prohibited area is added near the faulty phase. Map the switching frequency derating factor to carrier period adjustment and adjust the current loop control parameters accordingly. The dead time adjustment value is directly written into the dead time register of the inverter driver chip; A priority scheduling strategy is adopted to integrate the normal mode pulse width parameter and the fault mode executable constraints: the normal mode pulse width parameter is used when there is no fault. When there is a fault and the pulse width parameter in normal mode conflicts with the fault executable constraint, the fault executable constraint boundary value shall be used. When there is a fault and all normal mode pulse width parameters are within the fault-executable constraint range, the normal mode pulse width parameters are used.
[0013] As a further option of the method of the present invention, the dynamic allocation of the power output ratio of the primary and backup inverters in the dual-channel redundant drive according to the real-time health status includes: During each control cycle, the junction temperature, on-state voltage drop increment, and switching loss of each channel power device are collected; Calculate the health coefficient for each channel. : ,in, This is the upper limit of the junction temperature of power devices. This is the current junction temperature of the power device. For the current conduction voltage drop, This represents the current switching loss, with the index 0 indicating the initial value. These are the weighting coefficients, and the sum of the three is 1; Calculate the power output ratio : ,in This represents the health coefficient of the first channel. This refers to the health coefficient of the second channel. The channel with the higher health coefficient is designated as the primary channel, which bears the power output calculated according to the power output ratio, while the other channel is designated as the backup channel.
[0014] As a further option of the method of the present invention, the step of dynamically allocating the power output ratio of the primary and backup inverters in the dual-channel redundant drive according to the real-time health status further includes: When the channel health coefficient changes by more than 5%, a transition process is triggered, and the power output ratio is updated by linear interpolation during the transition period. Set a fixed role rotation cycle. After each role rotation cycle, switch the main and backup channel roles, promote the original backup channel to the main channel, and demote the original main channel to the backup channel. Perform a smooth transition by linear interpolation when switching roles. The final determined power output ratio is output to the inverter drive unit to adjust the current reference value distribution of each channel in real time.
[0015] As a further option of the method of the present invention, the control boundary parameters are fixed in the flight control computer, and the operation data is collected in real time. When the data deviates from the model boundary, magnetic flux folding is automatically triggered until a switching control signal that meets the requirements of thermal safety and dynamic performance is output, including: The integrated control parameters, multiphysics model boundaries, flux folding convergence threshold, and negotiated weight coefficients are written into the non-volatile memory of the flight control computer. Calculate the normalized deviation of the real-time acquired runtime data relative to the model boundary reference values; When any of the following conditions are met and last for more than three consecutive sampling cycles, the flux folding re-optimization process is triggered: DC bus voltage drops by more than 15% of the rated value, winding temperature change rate exceeds the set threshold, power device junction temperature exceeds the difference between the safety upper limit and the thermal safety margin, back EMF total harmonic distortion rate increases by more than 8%, and vibration intensity exceeds 1.5 times the normal mode reference value. In the re-optimization process, real-time data is used as a new boundary condition, which doubles the convergence accuracy of flux folding iteration, increases the thermal safety weight in dynamic negotiation to 0.7 and reduces the dynamic response weight to 0.3. If the re-optimization process is not completed within 5 milliseconds, the safe and conservative parameters from the previous cycle will be used as the emergency output. Once the real-time data regresses within the model boundary and remains stable for more than 10 seconds, the system automatically switches back to the control boundary parameters stored in non-volatile memory and stores the event type that triggered the re-optimization, timestamp, real-time data snapshot, and new parameters into the black box.
[0016] Another aspect of this application provides a dual-redundant fault-tolerant aircraft motor drive control system, the system comprising: The initial voltage vector feasible region construction module is used to collect aircraft motor parameters, establish a multi-physics field coupling constraint mapping model and set the boundary, and determine the initial voltage vector feasible region by combining the DC bus effective voltage utilization rate and the motor back electromotive force. The optimal magnetic flux trajectory determination module is used to determine the optimal magnetic flux trajectory by performing magnetic flux folding iteration based on thermal safety constraints based on the feasible region of the initial voltage vector. The pulse width parameter multi-round negotiation module is used to simulate large-scale dynamic load conditions based on the optimal magnetic flux trajectory, detect pulse width changes, and accordingly re-fold the magnetic flux or adjust the feasible region of the initial voltage vector to determine the pulse width parameter that satisfies the dynamic response and thermal limit. The integrated control parameter generation module is used to inject inter-turn short circuit or position sensor failure fault signals based on pulse width parameters, check the remaining thrust and vibration noise, determine the minimum control correction amount, and combine the minimum control correction amount with the normal mode parameters to form integrated control parameters. The dual-channel redundant power dynamic allocation module is used to map the comprehensive control parameters to the hardware and dynamically allocate the power output ratio of the main and standby inverters in the dual-channel redundant drive according to the real-time health status. The flux folding closed-loop trigger control module is used to embed control boundary parameters into the flight control computer, collect operational data in real time, and automatically trigger flux folding when the operational data deviates from the model boundary until a switching control signal that meets the requirements of thermal safety and dynamic performance is output.
[0017] The beneficial effects of this application are as follows: This invention overcomes the limitations of traditional multiphysics independent modeling and static control boundaries. By constructing a dynamic collaborative optimization mechanism under thermal-dynamic coupling constraints, it significantly improves the performance prediction accuracy and control response speed of aero-motors under extreme conditions. It effectively solves the contradiction between dynamic response and thermal safety in high-maneuver flight, which is difficult to coordinate at the millisecond level, and ensures that the re-optimization process is completed within 5 milliseconds. At the fault-tolerant operation level, it abandons the traditional crude cut-off strategy and ensures that a safe thrust output of no less than 60% of the rated torque is maintained in the fault mode and the vibration and noise increment is suppressed to within 3dB through refined verification and minimum correction mapping. At the same time, based on the redundant power adaptive balancing strategy of hardware health status, it achieves a dual improvement in system mission reliability and life cycle. Attached Figure Description
[0018] Figure 1 Overall schematic diagram of a dual-redundant fault-tolerant aircraft motor drive control method; Figure 2 Flowchart of S100, a dual-redundant fault-tolerant aircraft motor drive control method; Figure 3 Flowchart of S200, a dual-redundant fault-tolerant aircraft motor drive control method; Figure 4 Flowchart of S300 dual-redundant fault-tolerant aircraft motor drive control method; Figure 5 Flowchart of S400 dual-redundant fault-tolerant aircraft motor drive control method; Figure 6 Flowchart of S500 dual-redundant fault-tolerant aircraft motor drive control method; Figure 7 Flowchart of S600, a dual-redundant fault-tolerant aircraft motor drive control method. Detailed Implementation
[0019] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0020] Dual-redundant fault-tolerant aero-engine drive control methods face several technical bottlenecks, including strong coupling of multiple physics fields, real-time conflicts between dynamic response and thermal safety, coarse-grained fault-tolerance strategies, and a lack of adaptive health-state power allocation for redundant hardware. Traditional methods model electrical, magnetic, thermodynamic, and mechanical dynamics separately, neglecting the nonlinear constraint transmission between these physics fields. The fixed-boundary voltage vector feasible region cannot adapt to the dynamic changes in DC bus voltage utilization and back EMF characteristics within the flight envelope. Simply derating or cutting off the faulty phase after a fault leads to insufficient utilization of remaining thrust or excessive safety margin. To address these issues, this invention proposes a comprehensive control method integrating multi-physics constraint modeling, thermal safety flux folding iteration, dynamic response-thermal safety game negotiation, fine-grained fault tolerance, and adaptive health-state allocation.
[0021] The theoretical foundation of this invention is built upon four pillars: multiphysics coupling constraint mapping theory, thermal safety-driven flux folding iteration theory, dynamic response-thermal safety game negotiation theory, and dual-redundant hardware health state dynamic allocation theory. By constructing a coupled model incorporating four types of constraints—electrical, magnetic, thermal, and mechanical dynamics—and setting cross-boundaries, it performs flux folding iteration based on thermal safety constraints to find the optimal flux trajectory between thermal constraints and thrust requirements. Simulating high-maneuver load conditions, it conducts multiple rounds of negotiation between dynamic response and thermal safety to determine the optimal pulse width parameters. Fault signals are injected to verify remaining capacity and map minimum control corrections to form comprehensive control parameters. Finally, based on real-time health status, it dynamically allocates dual-channel drive power and solidifies control boundaries to achieve closed-loop self-triggered optimization of operational data. This achieves dynamic balance between thermal limits and thrust requirements under all flight conditions, fine-grained fault tolerance with minimum corrections for flight safety in fault modes, and adaptive allocation of redundant channel power based on hardware health status.
[0022] The definitions of core variables and the derivation of important formulas are as follows: Define the state vector of the motor drive system as follows: ,in , for , shaft current, , for , Axial magnetic flux, For power device junction temperature, For winding temperature, For mechanical angular velocity, Let the electric angle be denoted as . Define the control input vector as . ,in , for , shaft voltage, For switching frequency, This represents the duty cycle.
[0023] Formula 1 - Voltage Utilization Rate and Back EMF: The DC bus voltage utilization rate is defined as... ,in For the reference voltage vector magnitude, This is the DC bus voltage. The formula for calculating the back electromotive force amplitude is: , is the back electromotive force constant.
[0024] Formula 2 - Initial Voltage Vector Feasible Region: Without considering dynamic disturbances and faults, the voltage vector feasible region is expressed as follows: .
[0025] Formula 3 - Torque Equation: The formula for calculating electromagnetic torque is as follows: ,in It is an extreme logarithm.
[0026] Formula 4 - Thermal Safety Margin: The thermal safety margin function is defined as follows: ,in , These are the upper limits of junction temperature and winding temperature for power devices, respectively.
[0027] Formula 5 - Pulse Width Variation: The pulse width variation is defined as follows: , For the current loop control cycle, For a moment The pulse width modulation duty cycle.
[0028] Formula 6 - Health Coefficient: Channel The formula for calculating the health index is: ,in This is the current junction temperature of the power device. For the current conduction voltage drop, This represents the current switching loss, with the index 0 indicating the initial value. These are the weighting coefficients, and their sum is 1.
[0029] Formula 7 - Power Distribution Ratio: The power output ratio is based on... The calculation shows that the transition between primary and backup channels is smoothed by linear interpolation during the primary / backup channel role rotation cycle.
[0030] The specific embodiments of the present invention will be described in detail below.
[0031] Example 1: Please see Figure 1 , Figure 1 This diagram illustrates an overall flowchart of a dual-redundant fault-tolerant aircraft motor drive control method provided by an embodiment of the present invention. The method includes: S100: Acquisition of aircraft motor parameters and construction of feasible region for initial voltage vector; S200: Flux Folding Iteration and Optimal Flux Trajectory Determination Based on Thermal Safety Constraints; S300: Simulation of high-speed operation conditions and multi-round negotiation of control signal pulse width; S400: Fault signal injection and minimum control correction mapping; S500: Integrated control parameter physical mapping and dual-channel redundant power dynamic allocation; S600: Control boundary parameter solidification and real-time flux folding closed-loop triggering.
[0032] The specific implementation methods of the above steps are described in detail below with reference to the accompanying drawings.
[0033] Please refer to Figure 2 , Figure 2 A detailed flowchart of stage S100 in an exemplary embodiment of this application is shown, which includes stages S110 to S140.
[0034] The S100 acquires key physical parameters of the aircraft's electrical system, establishes a constraint mapping model that includes four types of physical fields—electrical, magnetic, thermal, and mechanical dynamics—and their cross-coupling relationships, and calculates the feasible domain of the initial voltage vector under different flight stages based on this model, providing accurate constraint boundaries for subsequent flux folding and dynamic negotiation.
[0035] S110: Deploy multiple types of sensors at critical locations in the aircraft motor drive system. Critical locations include, but are not limited to: motor winding ends, power module substrate, heat sink surface, motor shaft extension ends, and both ends of the inverter DC bus capacitor.
[0036] In one possible implementation of this embodiment, a Hall current sensor is used to collect the phase currents of the three-phase windings for calculation. , Shaft current component. The rotor position angle and mechanical angular velocity are acquired via a rotary transformer or encoder. The winding temperature is measured in real time using thermocouples or thermistors. junction temperature of power devices The DC bus voltage is collected using a voltage sensor. and the inverter output phase voltage.
[0037] S120: In this embodiment, a coupled constraint mapping model containing four sub-models is established based on the collected parameters.
[0038] In one possible implementation of this embodiment, the establishment of the multiphysics coupling constraint mapping model includes: S121: Electrical constraint sub-model, used to describe the relationship between the voltage equation and current limiting. The voltage equation is expressed as follows: and ,in For stator resistance, , for , Shaft inductor, Electric angular velocity, It is a permanent magnet flux linkage. The current limiting condition is... .
[0039] S122: Magnetic confinement sub-model, describing the nonlinear relationship between flux linkage and current and its saturation characteristics. The flux linkage equation is expressed as follows: and ,inductance , As the current changes, the data can be obtained through offline table lookup or online identification.
[0040] S123: Thermally constrained sub-model, using lumped-parameter thermal network equations to describe the dynamics of junction and winding temperatures in power devices. The junction temperature dynamic equation is as follows: The winding temperature dynamic equation is: ,in , For heat capacity, This is the sum of the switching losses and conduction losses of the power device. For winding copper loss, , , This is the thermal resistance.
[0041] S124: Mechanical dynamics constraint sub-model, describing the dynamics of the motor shaft system, the equations are as follows: ,in For rotational inertia, For load torque, is the damping coefficient.
[0042] The cross-coupling coefficients between the four sub-models include: the coefficient of temperature effect on resistance. The effect coefficient of temperature on magnetic flux The transfer coefficient of current to losses and thus to temperature rise .
[0043] S130: In this embodiment, the upper and lower boundary values and their cross-coupling coefficient ranges of each sub-model are set according to the aircraft motor design specifications and airworthiness standards.
[0044] In one possible implementation of this embodiment, the model boundary setting includes: S131: Electrical boundary, DC bus voltage Allowable fluctuation range is The peak phase current does not exceed .
[0045] S132: Magnetic boundary, flux linkage magnitude upper limit Take 90% of the critical value for magnetic circuit saturation, lower limit Find the minimum flux linkage corresponding to the thrust requirement.
[0046] S133: Thermal boundary, the safe upper limit of junction temperature for power devices. Upper limit of winding insulation temperature resistance thermal safety margin .
[0047] S134: Mechanical boundary, maximum permissible torque ripple Maximum permissible speed fluctuation .
[0048] S135: Cross-coupling coefficient range, temperature coefficient of resistance Temperature coefficient of magnetic flux .
[0049] S140: In this embodiment, the established constraint mapping model is used to calculate the effective voltage utilization rate of the DC bus for different flight stages, and the feasible region of the initial voltage vector is determined by combining the back electromotive force characteristics.
[0050] In one possible implementation of this embodiment, the calculation of the feasible region of the initial voltage vector includes: For the current flight phase, obtain the measured value of the DC bus voltage. and motor speed The voltage utilization rate is calculated using Formula 1. ,in The back electromotive force amplitude is determined by the reference voltage output from the current regulator. Formula 1 is used to calculate this amplitude. .
[0051] Formula 2 is used to determine the feasible region of the voltage vector. Based on this, and considering the back electromotive force constraint, the practically feasible region is further restricted to satisfying... The point set. The voltage is discretized into several candidate voltage vector points, and the voltage utilization rate and corresponding current and torque prediction values of each point are recorded as inputs to S200.
[0052] Please refer to Figure 3 , Figure 3 A detailed flowchart of stage S200 in an exemplary embodiment of this application is shown, which includes stages S210 to S250.
[0053] Based on the feasible region of the initial voltage vector, S200 uses thermal safety constraints as an active folding factor to iteratively compress the range of the magnetic flux trajectory until it finds the optimal magnetic flux trajectory that simultaneously satisfies the requirements of thermal safety margin and thrust response time.
[0054] S210: In this embodiment, the feasible region of the initial voltage vector is obtained from S100. and model boundaries. Set the initial upper limit for flux folding. Initial lower limit Convergence accuracy Maximum number of iterations .
[0055] S220: In this embodiment, during the current folding interval... Within, take the intermediate candidate flux linkage amplitude. .based on Search for the corresponding voltage vector point within the feasible region, such that the output torque... As close as possible to the required torque .
[0056] In one possible implementation of this embodiment, the execution of single-step iteration includes: The optimal voltage vector is solved using the gradient descent method. The objective function is the absolute value of the difference between the output torque and the required torque, and the constraint is that the flux linkage amplitude does not exceed [a certain value]. And the voltage vector is located at Internally, during the solution process, calculations are performed based on the current using a magnetic confinement sub-model. , Then, the electromagnetic torque is calculated using Formula 3. .
[0057] After obtaining the candidate voltage vector, it is substituted into the thermally constrained sub-model, and the steady-state junction temperature is calculated using the thermal network equation. With winding temperature rise .
[0058] S230: In this embodiment, based on the thermal response result calculated in step S220, the current magnetic flux amplitude is evaluated to determine whether it meets the thermal safety constraints, and the folding direction is determined.
[0059] In one possible implementation of this embodiment, the thermal safety margin calculation and folding direction determination include: Calculate the thermal safety margin using Formula 4. ,in , These are the upper limit of the junction temperature of the power device and the upper limit of the winding temperature set in step S130, respectively.
[0060] like If the value is less than the preset threshold, it indicates insufficient thermal safety margin, requiring a reduction in flux amplitude to decrease losses, and folding upwards should be performed. , .
[0061] like Greater than or equal to the threshold but output torque With demand torque The deviation exceeds the allowable value This indicates insufficient thrust, requiring an increase in flux amplitude to boost torque, and folding downwards. , .
[0062] If both thermal safety and thrust requirements are met simultaneously, then currently... This is the candidate optimal flux linkage amplitude, proceed to step S240.
[0063] S240: In this embodiment, check whether the convergence condition is met or the maximum number of iterations is reached.
[0064] The convergence condition is defined as: Or, the rate of change of thermal safety margin in two consecutive iterations is less than a preset threshold.
[0065] If the convergence condition is met, the optimal flux linkage magnitude is output. And record the corresponding optimal magnetic flux trajectory. As a time series. If it does not satisfy and Then let Then return to step S220 to continue the iteration.
[0066] S250: In this embodiment, the optimal flux linkage amplitude obtained in step S240 is... The information, including the corresponding voltage vector sequence, current trajectory, and thermal safety margin, is encapsulated into an optimal flux trajectory data structure, which serves as the input for the S300 stage.
[0067] Please refer to Figure 4 , Figure 4 A detailed flowchart of stage S300 in an exemplary embodiment of this application is shown, which includes stages S310 to S360.
[0068] The S300 simulates the sudden loading and unloading conditions of an aircraft during high-maneuver flight based on the optimal magnetic flux trajectory. It detects the pulse width variation caused by the current loop response speed in real time and determines the pulse width parameter that meets the dynamic response requirements without exceeding the thermal limit through multiple rounds of negotiation.
[0069] S310: In this embodiment, a high-maneuver load condition simulator is built in a simulation environment or hardware-in-the-loop platform. The simulator generates load torque based on the flight mission profile. The time series.
[0070] In one possible implementation of this embodiment, the high-load operation includes: S311: Sudden load application, specifically: increasing the load torque from 10% of the rated value to 100% of the rated value within 0.05 seconds.
[0071] S312: Sudden load relief, specifically: within 0.05 seconds, the load torque is stepped from 100% of the rated value to 10% of the rated value.
[0072] S313: Periodic maneuver, specifically: reciprocating loading at a frequency of 1Hz with 50% of the rated torque.
[0073] The load condition simulator outputs load torque commands to the motor model, and simultaneously receives the pulse width modulation duty cycle signal output by the current loop.
[0074] S320: In this embodiment, the three-phase pulse width modulation duty cycle of the inverter output is acquired within each current loop control cycle. The pulse width variation is calculated using Formula 5. ,in Take the average value of the three-phase duty cycle.
[0075] Simultaneously record the rate of change of pulse width. .
[0076] S330: In this embodiment, based on the pulse width variation detected in step S320, it is evaluated whether thermal constraint violation is triggered and whether dynamic performance is insufficient.
[0077] In one possible implementation of this embodiment, the thermal constraint violation assessment includes: Current pulse width Substitute the thermal constraint sub-model established in step S120 into the thermal network equation to predict the future. peak junction temperature over time .like If this is not the case, the thermal constraint is deemed to be in violation, and the flag will be set. ;otherwise .in The thermal safety margin set for step S130.
[0078] Dynamic performance deficiencies assessment includes measuring the time from the onset of a load step to the torque recovering to 90% of its steady-state value. .like If so, the dynamic performance is deemed insufficient, and the flag is set. ;otherwise .
[0079] S340: In this embodiment, the corresponding action is performed based on the evaluation result of step S330: like and That is, if an increase in pulse width causes a thermal constraint violation, then flux folding is re-executed: return to step S200, and the thermal safety margin threshold is set. A temporary increase of 10% was made in order to seek a more conservative flux trajectory.
[0080] like and That is, if the pulse width reduction leads to insufficient dynamic performance, it triggers the adjustment of the initial voltage vector feasible domain: return to step S100, and set the upper limit of voltage utilization. Increase by 5% to 10% to expand the feasible area.
[0081] like and That is, if thermal violations and dynamic insufficiency occur simultaneously, thermal safety is prioritized, flux folding is performed, and dynamic performance is re-evaluated based on the new flux trajectory after folding.
[0082] like and If the current pulse width parameter meets the requirements, proceed to step S350.
[0083] S350: In this embodiment, if step S340 does not trigger the adjustment action, the process enters a multi-round negotiation phase. The goal of the negotiation is to find the pulse width parameter solution on the Pareto optimal boundary. .
[0084] In one possible implementation of this embodiment, the execution of multi-round negotiation includes: Dynamic response indicators thermal safety indicators As two participants in a game, define the total cost function. ,in Initially take .
[0085] Searching within the feasible region makes smallest The particle swarm optimization algorithm is used, with 30 particles and 50 iterations. After each round of negotiation, if... If it's less than the previous round, then update. Otherwise, adjust the weighting coefficients. , This simulates a concession strategy in a game. After a maximum of 10 rounds of negotiation, the pulse width parameter on the Pareto optimal boundary is obtained. .
[0086] S360: In the steps of this embodiment, the negotiated... and the corresponding duty cycle change rate limit Steady-state duty cycle These parameters are encapsulated into a pulse width parameter set, which serves as the input for the S400 stage.
[0087] Please refer to Figure 5 , Figure 5 A detailed flowchart of stage S400 in an exemplary embodiment of this application is shown, which includes stages S410 to S460.
[0088] Based on the pulse width parameter determined in step S300, S400 injects typical fault signals, verifies the remaining thrust capability and vibration noise level under fault mode, determines the minimum control correction amount and maps it to an executable constraint, and finally merges it with the normal mode parameters to form comprehensive control parameters.
[0089] S410: In this embodiment, typical fault signals are injected through a fault simulation device or software. Fault types include stator winding inter-turn short circuits and position sensor failure.
[0090] In one possible implementation of this embodiment, the fault injection method is as follows: S411: Stator winding inter-turn short circuit fault. Three short-circuit fault levels are set in the motor A-phase winding: 5%, 10%, and 15% of the total number of turns. The short-circuit resistance is set to... The short-circuit effect is achieved by modifying the phase resistance matrix in the electrical sub-model.
[0091] S412: Position sensor failure, with three modes: analog resolver signal loss, encoder pulse loss, and signal offset.
[0092] S413: The fault injection time is selected when the motor is operating under steady-state conditions, and the duration is 10 seconds.
[0093] S420: In this embodiment, after the fault is injected, the output torque, speed, three-phase current and vibration acceleration signals of the motor are collected in real time.
[0094] In one possible implementation of this embodiment, the remaining thrust capability verification includes: Measuring the maximum torque that the motor can continuously output under fault conditions Slowly increase the load command until the current reaches the protection threshold or a loss of synchronism occurs, and record the torque value at this point. Define the residual thrust coefficient. .
[0095] In one possible implementation of this embodiment, the vibration noise level verification includes: Perform a Fast Fourier Transform on the vibration acceleration signal to obtain the vibration spectrum. Calculate the total vibration intensity. ,in , Compare the vibration intensity under fault mode with that under normal mode. The vibration increment is obtained. .
[0096] S430: In this embodiment, based on the verification result of step S420, the minimum control correction amount under the premise of maintaining flight safety is determined. .
[0097] In one possible implementation of this embodiment, determining the minimum control correction amount includes: Minimum thrust threshold required for flight safety Take 60% of the rated torque. Maximum allowable increase in vibration and noise. Take 3dB.
[0098] like In this case, the current amplitude must be increased or the current phase adjusted. Minimum corrections include: current amplitude limits. Phase compensation angle ,in The optimal current angle to minimize torque ripple.
[0099] like To suppress vibration, reduce the switching frequency or increase the dead time. Minimum corrections include: switching frequency derating factor. The value ranges from 0.6 to 0.8; dead time adjustment value. Take a time of +0.5μs to +2μs.
[0100] If both thrust and vibration requirements are not met simultaneously, the two corrections are superimposed, but the total correction cost must be minimized. A linear programming approach is used to solve this problem, with the objective function being the weighted sum of the corrections. The constraints are that the corrected thrust is not lower than the safety threshold and the vibration increment does not exceed the upper limit.
[0101] S440: In this embodiment, the minimum control correction amount obtained in step S430 is... Convert into hardware constraints that can be directly executed by the inverter.
[0102] In one possible implementation of this embodiment, the mapping rules include: The current amplitude limit is mapped to the upper limit of the pulse width modulation duty cycle. .
[0103] Phase compensation angle Mapping to spatial vector sector switching conditions: Modify sector boundary angles and add prohibited areas near the faulty phase.
[0104] Switching frequency derating is mapped to carrier period adjustment: At the same time, the current loop control parameters are adjusted accordingly.
[0105] The dead time adjustment value is directly written into the dead time register of the inverter driver chip.
[0106] S450: In this embodiment, the control pulse width parameter of the normal mode is... Integrate with the executable constraints of the fault mode to form comprehensive control parameters. .
[0107] In one possible implementation of this embodiment, the fusion strategy employs priority scheduling: in fault mode, fault executable constraints have higher priority than normal mode parameters. Specifically, if there is no fault, normal mode parameters are used; if there is a fault and the normal mode parameters conflict with the fault constraints, the fault mode constraint boundary values are used; if there is a fault and both are compatible, the normal mode parameters are used. The compatibility criterion is whether all normal mode parameters are within the range of fault mode executable constraints.
[0108] S460: In this embodiment, the integrated control parameters are fused together. It is encapsulated as a data structure, including a normal mode pulse width parameter table, a fault mode constraint table, and a fault type-correction amount mapping table, and output to the S500 stage.
[0109] Please refer to Figure 6 , Figure 6 A detailed flowchart of stage S500 in an exemplary embodiment of this application is shown, which includes stages S510 to S540.
[0110] The S500 maps integrated control parameters onto the physical hardware structure of the aircraft motor, monitors the health status of each power device in the dual-channel redundant drive in real time, and dynamically allocates the power output ratio of the main and backup inverters based on the health coefficient.
[0111] S510: In this embodiment, the hardware configuration parameters of the dual-channel redundant drive system are read. The dual-redundant topology includes two completely independent inverters, each driving a set of complementary windings. The two sets of windings are spatially separated by 30° electrical angles to reduce torque ripple.
[0112] In one possible implementation of this embodiment, the hardware parameters include: power device model, rated current, rated voltage, thermal resistance parameter, and initial on-state voltage drop for each channel. Initial switching losses .
[0113] S520: In this embodiment, the junction temperature of each channel power device is collected during each control cycle. , conduction voltage drop And calculate switching losses .
[0114] In one possible implementation of this embodiment, health status monitoring includes: S521: Junction temperature measurement, which uses the internal thermistor of the power device or an external thermocouple, with a sampling frequency of 1kHz, and takes the average value of the sliding window.
[0115] S522: On-state voltage drop measurement, which measures the collector-emitter voltage using a differential amplifier during device conduction. The increment is obtained by subtracting the initial value.
[0116] S523: Switching loss calculation, i.e., based on switching frequency. DC bus voltage and phase current The estimation is done by looking up the switching energy in a table and then multiplying it by the switching frequency.
[0117] S530: In this embodiment, based on the real-time data collected in step S520, the health coefficient of each channel is calculated using Formula 6. The weighting coefficient is taken as , , The calibration was performed through experiments. The value ranges from [0,1], and the larger the value, the better the health status.
[0118] Calculate the power output ratio using Formula 7. ,satisfy Set primary and backup roles: Designate the channel with the higher health coefficient as the primary channel, responsible for... One channel is for power output; the other is for backup.
[0119] S540: In this embodiment, to avoid torque shocks caused by sudden changes in power ratio, a linear transition method is used to adjust the power output ratio. Simultaneously, a role rotation cycle is set to prevent a single channel from operating at high load for extended periods.
[0120] In one possible implementation of this embodiment, smooth transition and role rotation include: S541: When the health coefficient changes by more than 5%, a transition process is triggered. Transition time. During the transition period, Update using linear interpolation.
[0121] S542: Set rotation cycle Every time I pass by The primary and backup channels are swapped. Even if the health coefficient remains unchanged, the original backup channel is promoted to the primary channel, and the original primary channel is demoted to the backup channel, and a smooth transition is performed again. The rotation mechanism ensures that the aging of the two channels is balanced.
[0122] S543: The final determined power ratio The output is sent to the inverter drive unit to adjust the current reference value distribution of each channel in real time.
[0123] Please refer to Figure 7 , Figure 7 A detailed flowchart of stage S600 in an exemplary embodiment of this application is shown, which includes stages S610 to S650.
[0124] The S600 integrates control parameters and model boundaries into the flight control computer, collects real-time data during the actual operation of the aircraft motor, and automatically triggers flux folding when the real-time data deviates from the model boundary until a switching control signal that meets the requirements of thermal safety and dynamic performance is output.
[0125] S610: In this embodiment, the comprehensive control parameters determined in steps S100 to S500 are... Multiphysics model boundary, magnetic flux folding convergence threshold Parameters such as negotiation weighting coefficients are written to the non-volatile memory of the flight control computer. The fixed parameters are automatically loaded each time the system is powered on.
[0126] S620: In this embodiment, during the actual operation of the aircraft motor, real-time data is continuously collected at the sampling rate. The collected data vectors include: DC bus voltage, three-phase current, rotor position, rotational speed, power device junction temperature, winding temperature, vibration acceleration amplitude, and back electromotive force harmonic content.
[0127] S630: In this embodiment, the real-time data is compared with the model boundary to calculate the deviation.
[0128] In one possible implementation of this embodiment, the deviation calculation and trigger condition determination include: For each variable, the normalized deviation is calculated as the absolute value of the difference between the real-time value and the model boundary reference value, divided by the allowable deviation range.
[0129] The trigger condition is defined as any of the following conditions being met and lasting for more than three consecutive sampling periods: the DC bus voltage drops by more than 15% of the rated value; the winding temperature change rate exceeds... The junction temperature of power devices exceeds the safety limit minus the margin; the total harmonic distortion rate of back electromotive force increases by more than 8%; the vibration intensity exceeds 1.5 times the normal mode reference value.
[0130] If any trigger condition is met, the flux folding re-optimization process is triggered; otherwise, normal monitoring continues.
[0131] S640: In this embodiment, when the triggering condition is met, the flight control computer automatically interrupts the current control task, saves the field state, and re-executes steps S200 to S300 with the current real-time data as the new boundary condition.
[0132] In one possible implementation of this embodiment, the re-optimization process includes: The temperature, voltage, and current values in the real-time data are used as new thermal and electrical boundaries.
[0133] When re-executing the flux folding iteration of S200, the convergence accuracy The speed was temporarily doubled to ensure a safe solution was found quickly.
[0134] When re-performing dynamic negotiation of S300, thermal safety weights will be applied. Temporarily increased to 0.7, dynamic response weight. Reduce it to 0.3, prioritizing thermal safety.
[0135] The re-optimization process should be completed within 5 milliseconds to avoid affecting flight safety. If the timeout occurs, the conservative parameters from the previous cycle will be used as the emergency output.
[0136] S650: In this embodiment, after re-optimization, a new switching control signal is output to drive the aircraft motor. Simultaneously, the newly obtained control parameters temporarily replace the fixed parameters until the deviation event disappears. Once the real-time data returns to the model boundary and remains stable for more than 10 seconds, the system automatically switches back to the original fixed parameters.
[0137] The event type, timestamp, real-time data snapshot, and new parameters that trigger each re-optimization are stored in a black box for post-event analysis and model iteration optimization.
[0138] Example 2: This invention has been deployed and flight-verified in the dual-redundant fault-tolerant aero-motor drive control system of a certain type of electric vertical takeoff and landing (EVTOL) aircraft. The aircraft has a maximum takeoff weight of 2500 kg and a cruise power of 150 kW. It uses a dual-redundant permanent magnet synchronous motor as the main propulsion motor, with a rated power of 200 kW and a rated speed of 3000 rpm. The drive system consists of two independent inverters forming a dual-channel redundant topology. The flight control computer adopts a dual-core ARM Cortex-R5 architecture with a control cycle of 50 μs.
[0139] The system configuration parameters are shown in Table 1, which lists the main hardware configuration and software parameters of the verification system.
[0140] Table 1 During the ground test bench phase, takeoff, cruise, maneuvering, and fault injection conditions were tested respectively. Table 2 shows the key performance indicators for each condition.
[0141] Table 2 The data in Table 2 show that, under all flight conditions, the thermal safety margin is greater than 0.09 (i.e., the junction temperature margin is greater than 9%), and the torque response time is less than 10ms, which meets the design specifications.
[0142] The method of this invention is compared with two traditional control methods: Method A is fixed-boundary PID control, and Method B is model predictive control based on offline calibration. Table 3 shows the comparison results of the three methods under the same maneuvering conditions.
[0143] Table 3 As can be seen from Table 3, the method of the present invention reduces the number of thermal safety violations by 92%, shortens the torque response time by 47%, reduces junction temperature fluctuation by 57%, and significantly improves voltage utilization.
[0144] Three types of faults were injected: inter-turn short circuit in phase A, position sensor signal offset, and resolver signal loss. Table 4 shows the remaining thrust capacity and vibration / noise levels under the fault modes, as well as the minimum control correction.
[0145] Table 4 In Table 4, for the 10% short circuit condition in phase A, the remaining thrust coefficient of 0.66 is higher than the safety threshold of 0.6, and the vibration increment of 2.1 dB is lower than the allowable upper limit of 3 dB. Therefore, after applying the minimum control correction, the motor can still maintain safe flight. For the 15% short circuit condition in phase A, the remaining thrust coefficient is lower than the safety threshold, and further derating is required.
[0146] A continuous 2-hour flight mission test was conducted, with the health coefficients and power allocation ratios of the two channels recorded every 15 minutes. Table 5 presents the time-series data.
[0147] Table 5 As shown in Table 5, after rotation and dynamic allocation, the health of the two channels tended to be equal after 2 hours, and the initial difference was effectively balanced. The power ratio transitioned smoothly throughout the process, and no torque surge occurred.
[0148] Closed-loop self-triggered flux folding test; Three triggering events were simulated during flight tests: instantaneous cooling system failure, sudden load increase causing junction temperature to approach its upper limit, and grid fluctuation causing DC bus voltage drop. Table 6 shows the response data for each triggering event.
[0149] Table 6 The data in Table 6 shows that all trigger events were re-optimized within 5 milliseconds, with an average re-optimization time of 3.02 milliseconds. After re-optimization, the junction temperature returned to a safe range, and no thermal shutdown or loss of synchronization occurred.
[0150] Table 7 provides the cumulative statistics for 200 hours of ground bench testing and 50 hours of flight verification.
[0151] Table 7 Typical success stories; Case 1: During a sudden load increase caused by a strong wind shear, the system completed dynamic negotiation within 9 milliseconds, adjusting the pulse width parameter from 0.85 to 0.79, folding the flux linkage from 0.142 Wb to 0.131 Wb, and reducing the predicted peak junction temperature from 151℃ to 144℃, successfully avoiding the risk of power device overheating and shutdown. The aircraft successfully completed the maneuver, and the motors did not lose synchronism.
[0152] Case 2: After operating in a high salt spray environment for a week, the system triggered verification based on cumulative events, identifying a weak cluster of acoustic emission signals at the winding end of channel B. After observation and confirmation by the extended sub-cycle, it was determined to be early interface degradation. The system issued a level-two warning and performed capillary injection and implantation of a micro-corrosion sensor. After repair, continuous monitoring for 30 days showed no further abnormal signals, and the corrosion sensor readings remained stable within the baseline range.
[0153] Case 3: During a flight, a momentary malfunction in the cooling system caused a winding temperature change rate of 6.2℃ / ms, triggering a closed-loop self-healing process. Within 2.8 milliseconds, the system completed flux folding re-optimization, reducing the flux linkage from 0.142Wb to 0.128Wb, the duty cycle from 0.78 to 0.71, and the peak junction temperature from 148℃ to 135℃. After the cooling system recovered, the system automatically switched back to its original parameters, with continuous thrust output throughout the process, and the pilot did not perceive any abnormalities.
[0154] Summary of implementation results; Through the above verification, the method of the present invention achieves the following quantitative improvements compared with traditional fixed-boundary PID control and simple fault derating methods: (1) The number of thermal safety violations decreased by 92%.
[0155] (2) The dynamic response time is 8.2ms on average under the load step condition, which is 47% shorter.
[0156] (3) The utilization rate of remaining thrust in failure mode increased from 60% to 88%.
[0157] (4) The difference in lifespan between dual-redundant channels was reduced from the initial 30% to 8%.
[0158] (5) The average completion time of closed-loop self-triggered re-optimization is 3.02 milliseconds, and it successfully avoids 5 emergency deduction events caused by thermal over-limit.
[0159] (6) The system availability reaches 99.7%, and the success rate of safe flight in failure mode is 100%.
[0160] The accumulated 250 hours of operational data have been used to further optimize the multiphysics model parameters and negotiate weight coefficients, forming a continuously iteratively improving intelligent control closed loop. The robustness and practicality of the method in this invention under extreme conditions have been fully verified.
[0161] Example 3: A navigation guide to the six core interfaces of a dual-redundant fault-tolerant aircraft motor drive control system, including: The cockpit interface centrally displays real-time motor parameters, voltage feasible range, dual-channel health status, and thermal trends, providing global operational status monitoring.
[0162] The flux linkage optimization interface drives flux folding iteration through thermal safety constraints, automatically searching for the optimal flux linkage trajectory to balance thermal margin and thrust requirements.
[0163] The maneuver negotiation interface simulates high maneuver load conditions, dynamically evaluates pulse width variations, performs multi-round game negotiation, and outputs Pareto optimal pulse width parameters.
[0164] The fault-tolerant injection interface, in case of short circuit in the injection winding or sensor failure, verifies the remaining thrust and vibration level, automatically maps the minimum control correction amount and generates fault-tolerant constraints.
[0165] The redundancy allocation interface monitors the health of both channels in real time, dynamically allocates power ratios, and performs a smooth transition between primary and backup channels.
[0166] The boundary self-healing interface solidifies the control boundary and model parameters, monitors the deviation of running data in real time, automatically triggers flux folding re-optimization, and records black box logs.
[0167] A dual-redundant fault-tolerant aircraft motor drive control system includes: The initial voltage vector feasible region construction module is used to collect aircraft motor parameters, establish a multi-physics field coupling constraint mapping model and set the boundary, and determine the initial voltage vector feasible region by combining the DC bus effective voltage utilization rate and the motor back electromotive force. The optimal magnetic flux trajectory determination module is used to determine the optimal magnetic flux trajectory by performing magnetic flux folding iteration based on thermal safety constraints based on the feasible region of the initial voltage vector. The pulse width parameter multi-round negotiation module is used to simulate large-scale dynamic load conditions based on the optimal magnetic flux trajectory, detect pulse width changes, and accordingly re-fold the magnetic flux or adjust the feasible region of the initial voltage vector to determine the pulse width parameter that satisfies the dynamic response and thermal limit. The integrated control parameter generation module is used to inject inter-turn short circuit or position sensor failure fault signals based on pulse width parameters, check the remaining thrust and vibration noise, determine the minimum control correction amount, and combine the minimum control correction amount with the normal mode parameters to form integrated control parameters. The dual-channel redundant power dynamic allocation module is used to map the comprehensive control parameters to the hardware and dynamically allocate the power output ratio of the main and standby inverters in the dual-channel redundant drive according to the real-time health status. The flux folding closed-loop trigger control module is used to embed control boundary parameters into the flight control computer, collect operational data in real time, and automatically trigger flux folding when the operational data deviates from the model boundary until a switching control signal that meets the requirements of thermal safety and dynamic performance is output.
[0168] Those skilled in the art will understand that the embodiments of this application are provided as methods, systems, or computer program products. Therefore, this application takes the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application takes the form of a computer program product implemented on one or more computer storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer program code. The solutions in the embodiments of this application are implemented using various computer languages, exemplified by the object-oriented programming language Java and the interpreted scripting language JavaScript.
[0169] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, as well as combinations of blocks in the flowchart illustrations and / or block diagrams, are implemented by computer program instructions. These computer program instructions are provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams.
[0170] These computer program instructions are also stored in a computer read-memory that can direct a computer or other programmed data processing device to operate in a particular manner, such that the instructions stored in the computer read-memory produce an article of manufacture including instruction means that implement the functions specified in the flowchart or multiple flowcharts and / or block diagram blocks or multiple block diagrams.
[0171] These computer program instructions are also loaded onto a computer or other programming data processing device to cause a series of operational steps to be performed on the computer or other programming device to produce a computer-implemented process, such that the instructions, which execute on the computer or other programming device, provide steps for implementing the functions specified in the flowchart flow or multiple flows and / or the block diagram blocks or multiple blocks.
[0172] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0173] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A dual-redundant fault-tolerant aircraft motor drive control method, characterized in that, include: Collect aircraft motor parameters to establish a multiphysics field coupled constraint mapping model and set the model boundary. Combine the DC bus effective voltage utilization rate and the motor back electromotive force to determine the feasible region of the initial voltage vector. Based on the feasible region of the initial voltage vector, magnetic flux folding iteration based on thermal safety constraints is performed to determine the optimal magnetic flux trajectory; Based on the simulation of large-scale mobile load conditions using the optimal magnetic flux trajectory, pulse width variation is detected. Based on this, magnetic flux is re-folded or the feasible region of the initial voltage vector is adjusted to determine the pulse width parameters that satisfy dynamic response and thermal limit. Based on the pulse width parameter, inject inter-turn short circuit or position sensor failure fault signal, check the remaining thrust and vibration noise, determine the minimum control correction amount and combine it with the normal mode parameter to form a comprehensive control parameter; The comprehensive control parameters are mapped to the hardware, and the power output ratio of the main and backup inverters in the dual-channel redundant drive is dynamically allocated according to the real-time health status. The control boundary parameters are fixed in the flight control computer, and the operation data is collected in real time. When the data deviates from the model boundary, the magnetic flux folding is automatically triggered until the switching control signal that meets the requirements of thermal safety and dynamic performance is output.
2. The dual-redundant fault-tolerant aircraft motor drive control method according to claim 1, characterized in that, The steps for establishing the multiphysics coupling constraint mapping model include: Establish an electrical constraint sub-model to describe Axis voltage equation The relationship between shaft voltage equation and current limiting; Establish a magnetic confinement sub-model to describe Axial flux linkage equation, The nonlinear relationship between the axial flux linkage equation and the current, as well as the saturation characteristics, are obtained by offline table lookup or online identification of the d-axis and q-axis inductance parameters that vary with the current. A thermally constrained sub-model is established, and a lumped parameter thermal network equation is used to describe the junction temperature dynamics and winding temperature dynamics of the power device. The thermal network equation includes the device thermal capacity, winding thermal capacity, the sum of the switching loss and conduction loss of the power device, the winding copper loss, and three sets of thermal resistance parameters. Establish a mechanical dynamics constraint sub-model to describe the dynamic equations of the motor shaft system, including rotational inertia, load torque, and damping coefficient; The model boundary conditions include: The electrical boundary is formed by the allowable fluctuation range of DC bus voltage and the peak value of phase current; the magnetic boundary is formed by taking 90% of the critical value of magnetic circuit saturation and the minimum magnetic flux corresponding to the thrust requirement; the thermal boundary is formed by the upper limit of the junction temperature safety of power devices, the upper limit of the temperature resistance of winding insulation and the thermal safety margin; and the mechanical boundary is formed by the maximum allowable torque pulsation and the maximum allowable speed fluctuation. Define the range of cross-coupling coefficients between the four sub-models, including the influence coefficient of temperature on resistance, the influence coefficient of temperature on flux linkage, and the transfer coefficient of current to loss and thus to temperature rise.
3. The dual-redundant fault-tolerant aircraft motor drive control method according to claim 2, characterized in that, The method for determining the feasible region of the initial voltage vector includes: For the current flight phase, obtain the measured value of DC bus voltage and motor speed, and calculate the DC bus voltage utilization rate. The calculation formula is: ,in For the reference voltage vector magnitude, This is the DC bus voltage; Calculate the back electromotive force amplitude The calculation formula is: ,in The back electromotive force constant is... It is the mechanical angular velocity; Determining the feasible region of the voltage vector based on DC bus voltage utilization. The constraint formula for the feasible region of the voltage vector is expressed as follows: ,in , for , shaft voltage, This is the DC bus voltage; By combining the back EMF amplitude constraint, the actual feasible region is further restricted to a set of points that satisfy the voltage vector feasible region constraint formula, and the actual feasible region is discretized into several candidate voltage vector points. The voltage utilization rate and the corresponding current prediction value and torque prediction value of each candidate voltage vector point are recorded.
4. The dual-redundant fault-tolerant aircraft motor drive control method according to claim 1, characterized in that, The steps for determining the optimal magnetic flux trajectory include: Set the initial upper limit, initial lower limit, convergence accuracy, and maximum number of iterations for flux folding; Within the current folding interval, intermediate candidate flux linkage amplitudes are selected. The gradient descent method is used to solve for the optimal voltage vector within the feasible region of the initial voltage vector. The objective function is the absolute value of the difference between the output electromagnetic torque and the required torque. The constraints are that the flux linkage amplitude does not exceed the candidate flux linkage amplitude and the optimal voltage vector lies within the feasible region of the initial voltage vector. During the solution process, calculations are performed based on the current using a magnetic constraint sub-model. Shaft inductance and Shaft inductance, and substitute it into the electromagnetic torque calculation formula. Calculate electromagnetic torque ,in , for , Axial magnetic flux, , for , shaft current, It is the extreme logarithm; The obtained optimal voltage vector is substituted into the thermal constraint sub-model, and the steady-state junction temperature and winding temperature rise are calculated using the thermal network equation. Calculate thermal safety margin The formula for calculating the thermal safety margin function is: ,in, , These are the upper limits of junction temperature and winding temperature for power devices, respectively. For power device junction temperature, For winding temperature; If the thermal safety margin is less than the preset threshold, then folding upwards is performed to reduce the flux linkage amplitude; if the thermal safety margin is greater than or equal to the preset threshold and the deviation between the output electromagnetic torque and the required torque exceeds the allowable value, then folding downwards is performed to increase the flux linkage amplitude; if both thermal safety and thrust requirements are met, then the current candidate flux linkage amplitude is taken as the candidate optimal flux linkage amplitude. The iteration terminates when the difference in flux linkage amplitude between two consecutive iterations meets the convergence accuracy or the rate of change of thermal safety margin between two consecutive iterations is less than a preset threshold, and the optimal flux linkage amplitude and the corresponding optimal flux trajectory time series are output.
5. The dual-redundant fault-tolerant aircraft motor drive control method according to claim 1, characterized in that, The determination of pulse width parameters that satisfy dynamic response and thermal limit includes detecting pulse width variations and evaluating thermal constraint violations and dynamic performance deficiencies, such as: The three-phase pulse width modulation duty cycle of the inverter output is acquired during each current loop control cycle, and the pulse width variation is calculated. The calculation formula is: ,in, For the current loop control cycle, For a moment The pulse width modulation duty cycle, For a moment Pulse width modulation duty cycle; Substitute the current pulse width into the thermal constraint sub-model, use the thermal network equation to predict the junction temperature peak within a set time in the future. If the junction temperature peak is greater than the difference between the upper limit of the junction temperature safety of the power device and the thermal safety margin, then the thermal constraint is determined to be in violation and the thermal constraint violation flag is set to 1; otherwise, the thermal constraint violation flag is set to 0. The recovery time from the start of a load step change to the torque recovering to 90% of its steady-state value is measured. If the recovery time is greater than the allowable recovery time threshold, the dynamic performance is determined to be insufficient, and the dynamic performance insufficient flag is set to 1; otherwise, the dynamic performance insufficient flag is set to 0.
6. The dual-redundant fault-tolerant aircraft motor drive control method according to claim 5, characterized in that, Among the pulse width parameters that satisfy the dynamic response and thermal limit, triggering flux folding or feasible region adjustment includes: If the thermal constraint violation flag is 1 and the dynamic performance deficiency flag is 0, then return to perform the flux folding iteration and temporarily increase the preset threshold of thermal safety margin by 10%. If the thermal constraint violation flag is 0 and the dynamic performance deficiency flag is 1, then return to the adjustment of the initial voltage vector feasible region, increasing the upper limit of voltage utilization by 5% to 10%. If the thermal constraint violation flag is 1 and the dynamic performance deficiency flag is 1, then the flux folding iteration is performed first to handle thermal safety, and the dynamic performance is re-evaluated based on the new flux trajectory after folding. If the thermal constraint violation flag is 0 and the dynamic performance deficiency flag is 0, then a multi-round negotiation phase is entered. The dynamic response index and the thermal safety index are treated as two game participants. A total cost function containing dynamic response weights and thermal safety weights is defined. Within the feasible region, a particle swarm optimization algorithm is used to search for the pulse width parameter that minimizes the total cost function. After each round of negotiation, the dynamic response weights and thermal safety weights are adjusted according to the change in the total cost function to simulate a concession strategy. After a maximum of 10 rounds of negotiation, the pulse width parameter on the Pareto optimal boundary is obtained.
7. The dual-redundant fault-tolerant aircraft motor drive control method according to claim 1, characterized in that, The step of determining the minimum control correction amount includes: When the motor is operating under steady-state conditions, inject a short circuit fault between turns of the stator winding or a position sensor failure fault. By slowly increasing the load command until the current reaches the protection threshold or a loss of synchronism occurs, the torque value at this time is recorded and the remaining thrust coefficient is calculated. The vibration spectrum is obtained by performing a fast Fourier transform on the vibration acceleration signal, the total vibration intensity is calculated, and the vibration intensity in the fault mode and normal mode is compared to obtain the vibration increment. If the thrust corresponding to the remaining thrust coefficient is less than the minimum thrust threshold required for flight safety, then the minimum correction amount is determined to include the current amplitude limit and the phase compensation angle corresponding to the optimal current angle that minimizes torque ripple. If the vibration increment is greater than the upper limit of the allowable vibration noise increment, the minimum correction amount is determined to include a switching frequency derating factor of 0.6 to 0.8 and a dead time adjustment value of +0.5μs to +2μs. If both thrust and vibration requirements are not met, linear programming is used to solve the objective function that minimizes the weighted sum of each correction. The constraints are that the corrected thrust is not lower than the minimum thrust threshold required for flight safety and the vibration increment does not exceed the upper limit of the allowable vibration noise increment.
8. The dual-redundant fault-tolerant aircraft motor drive control method according to claim 7, characterized in that, The steps for forming the comprehensive control parameters include: Map the current amplitude limit to the upper limit of the pulse width modulation duty cycle; The phase compensation angle is mapped to the spatial vector sector switching condition, the sector boundary angle is modified, and a prohibited area is added near the faulty phase. Map the switching frequency derating factor to carrier period adjustment and adjust the current loop control parameters accordingly. The dead time adjustment value is directly written into the dead time register of the inverter driver chip; A priority scheduling strategy is adopted to integrate the normal mode pulse width parameter and the fault mode executable constraints: the normal mode pulse width parameter is used when there is no fault. When there is a fault and the pulse width parameter in normal mode conflicts with the fault executable constraint, the fault executable constraint boundary value shall be used. When there is a fault and all normal mode pulse width parameters are within the fault-executable constraint range, the normal mode pulse width parameters are used.
9. The dual-redundant fault-tolerant aircraft motor drive control method according to claim 1, characterized in that, The dynamic allocation of the power output ratio of the primary and backup inverters in the dual-channel redundant drive based on real-time health status includes: During each control cycle, the junction temperature, on-state voltage drop increment, and switching loss of each channel power device are collected; Calculate the health coefficient for each channel. : ,in, This is the upper limit of the junction temperature of power devices. This is the current junction temperature of the power device. For the current conduction voltage drop, This represents the current switching loss, with the index 0 indicating the initial value. These are the weighting coefficients, and the sum of the three is 1; Calculate the power output ratio : ,in This represents the health coefficient of the first channel. This refers to the health coefficient of the second channel. The channel with the higher health coefficient is designated as the primary channel, which bears the power output calculated according to the power output ratio, while the other channel is designated as the backup channel.
10. The dual-redundant fault-tolerant aircraft motor drive control method according to claim 9, characterized in that, The method of dynamically allocating the power output ratio of the primary and backup inverters in the dual-channel redundant drive based on real-time health status also includes: When the channel health coefficient changes by more than 5%, a transition process is triggered, and the power output ratio is updated by linear interpolation during the transition period. Set a fixed role rotation cycle. After each role rotation cycle, switch the main and backup channel roles, promote the original backup channel to the main channel, and demote the original main channel to the backup channel. Perform a smooth transition by linear interpolation when switching roles. The final determined power output ratio is output to the inverter drive unit to adjust the current reference value distribution of each channel in real time.
11. The dual-redundant fault-tolerant aircraft motor drive control method according to claim 1, characterized in that, The control boundary parameters are embedded in the flight control computer, and operational data is collected in real time. When the data deviates from the model boundary, magnetic flux folding is automatically triggered until a switching control signal that meets the requirements of thermal safety and dynamic performance is output, including: The integrated control parameters, multiphysics model boundaries, flux folding convergence threshold, and negotiated weight coefficients are written into the non-volatile memory of the flight control computer. Calculate the normalized deviation of the real-time acquired runtime data relative to the model boundary reference values; When any of the following conditions are met and last for more than three consecutive sampling cycles, the flux folding re-optimization process is triggered: DC bus voltage drops by more than 15% of the rated value, winding temperature change rate exceeds the set threshold, power device junction temperature exceeds the difference between the safety upper limit and the thermal safety margin, back EMF total harmonic distortion rate increases by more than 8%, and vibration intensity exceeds 1.5 times the normal mode reference value. In the re-optimization process, real-time data is used as a new boundary condition, which doubles the convergence accuracy of flux folding iteration, increases the thermal safety weight in dynamic negotiation to 0.7 and reduces the dynamic response weight to 0.
3. If the re-optimization process is not completed within 5 milliseconds, the safe and conservative parameters from the previous cycle will be used as the emergency output. Once the real-time data regresses within the model boundary and remains stable for more than 10 seconds, the system automatically switches back to the control boundary parameters stored in non-volatile memory and stores the event type that triggered the re-optimization, timestamp, real-time data snapshot, and new parameters into the black box.
12. A dual-redundant fault-tolerant aircraft motor drive control system according to any one of claims 1-11, characterized in that the system include: The initial voltage vector feasible region construction module is used to collect aircraft motor parameters, establish a multi-physics field coupling constraint mapping model and set the boundary, and determine the initial voltage vector feasible region by combining the DC bus effective voltage utilization rate and the motor back electromotive force. The optimal magnetic flux trajectory determination module is used to determine the optimal magnetic flux trajectory by performing magnetic flux folding iteration based on thermal safety constraints based on the feasible region of the initial voltage vector. The pulse width parameter multi-round negotiation module is used to simulate large-scale dynamic load conditions based on the optimal magnetic flux trajectory, detect pulse width changes, and accordingly re-fold the magnetic flux or adjust the feasible region of the initial voltage vector to determine the pulse width parameter that satisfies the dynamic response and thermal limit. The integrated control parameter generation module is used to inject inter-turn short circuit or position sensor failure fault signals based on pulse width parameters, check the remaining thrust and vibration noise, determine the minimum control correction amount, and combine the minimum control correction amount with the normal mode parameters to form integrated control parameters. The dual-channel redundant power dynamic allocation module is used to map the comprehensive control parameters to the hardware and dynamically allocate the power output ratio of the main and standby inverters in the dual-channel redundant drive according to the real-time health status. The flux folding closed-loop trigger control module is used to embed control boundary parameters into the flight control computer, collect operational data in real time, and automatically trigger flux folding when the operational data deviates from the model boundary until a switching control signal that meets the requirements of thermal safety and dynamic performance is output.
Citation Information
Patent Citations
Six-winding high-voltage frequency conversion speed regulation control method and system
CN120675462A
Adaptive control method based on multi-physical modeling
CN121187135A
Aviation permanent magnet synchronous motor control architecture based on master-slave redundancy and model prediction
CN121664041A