A redundancy architecture method for unmanned aerial vehicle flight control system

By implementing a four-level redundancy design and multi-mode management for the UAV flight control system, the problems of incomplete redundancy design and inability to recover fault channels online in traditional UAV flight control systems have been solved, achieving a system with no single point of failure and high-reliability flight.

CN122411575APending Publication Date: 2026-07-17SUZHOU TIANFEI HANGRUI TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SUZHOU TIANFEI HANGRUI TECHNOLOGY CO LTD
Filing Date
2026-05-28
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Traditional UAV flight control systems suffer from incomplete redundancy design, a simplistic voting mechanism, a fragile bus structure, uneven switching, and the inability to recover fault channels online, resulting in insufficient flight safety and reliability.

Method used

It adopts a four-level redundancy design, including a flight sensor system, a redundancy flight control computer system, a bus communication system, and an actuator system. Combined with a multi-mode redundancy management and dynamic reconfiguration mechanism, it uses a 1553B dual bus, FlexRay bus, and CAN bus to form a three-bus redundancy architecture, which supports automatic switching between three-mode redundancy, dual-mode redundancy, and single-mode redundancy modes, and has the function of online repair and reconnection of fault channels.

Benefits of technology

It achieves zero single point of failure across the entire system, improves communication reliability and fault tolerance, ensures flight quality and safety, and enables seamless return to base in the event of a fault.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122411575A_ABST
    Figure CN122411575A_ABST
Patent Text Reader

Abstract

This invention discloses a redundant architecture method for a UAV flight control system, relating to the field of UAV control technology. It includes redundant design for four layers: flight sensor system, redundant flight control computer system, bus communication system, and actuator system. The bus communication system employs a three-bus redundant architecture consisting of a 1553B dual-bus, FlexRay bus, and CAN bus. The redundant flight control computer system features automatic switching between three modes: triple-mode redundancy, dual-mode redundancy, and single-mode redundancy, and possesses online fault channel repair and reconnection capabilities. The actuator system includes aerodynamic control surface segment redundancy, servo electrical dual-path redundancy, and dual-path access redundancy via the CAN bus main path and RS422 backup path. This invention, using the aforementioned redundant architecture method for a UAV flight control system, achieves long-endurance, highly reliable flight control with no awareness of single faults, return capability in the event of dual faults, and no degradation due to bus faults.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of unmanned aerial vehicle (UAV) control technology, and in particular to a redundant architecture method for a UAV flight control system. Background Technology

[0002] With the widespread application of drones in military reconnaissance, precision strikes, logistics transportation and emergency support, the flight control system, as the core hub of drones, directly determines flight safety and mission success or failure through its reliability and fault tolerance.

[0003] Traditional UAV flight control systems mostly employ a single-redundant architecture, making them highly susceptible to loss of flight control should the main control unit, sensors, or communication links fail. While some improved solutions utilize dual-redundant cold or hot backups, the following common problems still persist: First, redundancy coverage is incomplete. Most solutions only implement redundancy design for the flight control computer, leaving single points of failure for sensors and actuators. When critical sensors or servos fail, the entire system will lose its normal operating capability.

[0004] Second, the voting mechanism is too simplistic. In a triple redundancy system, if the fault detection coverage is insufficient, a Byzantine Generals fault may occur, where the faulty channel outputs incorrect data, leading to incorrect voting output and rendering the redundancy design ineffective.

[0005] Third, the bus structure is fragile. When using single-bus communication, the bus itself becomes a single point of failure. Once the bus is interrupted or interfered with, all flight control channels will be unable to communicate normally.

[0006] Fourth, the handover is not smooth. During the switchover between primary and backup aircraft, the abrupt changes in control variables cause control surface impacts and airframe vibrations, which seriously affect flight quality and may even lead to loss of control.

[0007] Fifth, faulty channels cannot be restored online. Isolated channels cannot be reconnected to the system during flight, causing system reliability to continuously decline over mission duration, significantly increasing the risk of long-duration missions. Summary of the Invention

[0008] The purpose of this invention is to provide a redundant architecture method for a UAV flight control system. Redundancy design is carried out at four levels: flight sensor system, redundant flight control computer system, bus communication system, and actuator system. Combined with multi-mode redundancy management and dynamic reconfiguration mechanism, the goal of achieving no perception of single failure and return to base in case of secondary failure is achieved.

[0009] To achieve the above objectives, this invention provides a redundant architecture method for an unmanned aerial vehicle (UAV) flight control system, which implements redundant design for four layers: flight sensor system, redundant flight control computer system, bus communication system, and actuator system. The bus communication system adopts a three-bus redundant architecture consisting of 1553B dual bus, FlexRay bus and CAN bus; The redundancy flight control computer system supports automatic switching between three working modes: triple redundancy, dual redundancy, and single redundancy, and has the function of online repair and reconnection of fault channels. The actuator system includes pneumatic control surface segment redundancy, servo electrical dual-path redundancy, and dual-path access redundancy of the CAN bus main path and RS422 backup path.

[0010] Preferably, the flight sensor system adopts a multi-system, multi-frequency, non-similar redundancy scheme; Altitude information is redundantly provided by three systems: an atmospheric data system, a satellite navigation system, and a radar altimeter. The satellite navigation system is compatible with multiple constellations, including GPS, BD2, and GLONASS. Location information is redundantly provided by the satellite navigation system and the inertial navigation system, with the inertial navigation system employing a high-precision fiber optic gyroscope; Attitude information is redundantly provided by fiber optic gyroscopes and satellite dual-antenna mobile differential attitude system. The satellite dual-antenna system provides attitude information in both roll and yaw directions through carrier phase differential technology. The flight sensor system is also equipped with a weather vane angle of attack sensor, a weather vane sideslip angle sensor, a ground contact switch, an engine monitoring module, a fuel system health monitoring module, a power distribution network monitoring module, and a landing gear monitoring module; All sensor data is used after data fusion and consistency verification within the flight control computer. A single sensor failure does not affect the normal operation of the system, and cross-verification of multiple sensors can identify soft faults and data injection attacks.

[0011] Preferably, the 1553B dual bus adopts an A / B dual-channel redundant configuration, with each bus working independently and serving as a backup for the others; The flight control computer has an embedded 1553B bus controller, which can be configured to work as a bus controller, remote terminal or bus monitor. The bus controller periodically sends commands to query the status of each remote terminal. When the main bus has no response for three consecutive cycles or the status word is set to fault, the system automatically switches to the backup bus. The 1553B dual bus is used for communication between the flight control computer and avionics, weapon systems, and mission equipment; The FlexRay bus is used for high real-time synchronization and data cross-transmission between three flight control boards, supporting microsecond-level synchronization accuracy and deterministic communication; The CAN bus is used as a direct voting channel from the flight controller board to the servo, forming path redundancy with the RS422 serial bus.

[0012] Preferably, the redundant flight control computer adopts a homogeneous architecture, with the three flight control boards having identical hardware and program functions, differing only in bus ID and driver, thus forming similar redundancy; Each flight controller board is based on a domestic SoC chip and FPGA chip, and integrates a 1553B bus controller, dual-port random access memory, FlexRay bus interface, CAN bus interface, RS422 serial interface, independent power supply module and watchdog timer. The three flight control boards communicate with each other through dual-port random access memory. Each SoC communicates with the 1553B bus via a bus controller, and the data bus uses a transformer coupling method. The redundant flight control computer adopts a three-level synchronization mechanism; The first level is hardware synchronization, where each flight control board receives the same second pulse signal to achieve microsecond-level synchronization. The second level is bus synchronization, which achieves sub-microsecond synchronization through FlexRay bus periodic synchronization; The third level is software timed synchronization, and the process is as follows: After the start of this cycle, each flight control board sends a handshake signal to the other two aircraft, waits to receive the handshake signal or waits for a timeout. If a signal is not received from a certain aircraft after a timeout, it is determined that the aircraft has lost synchronization. If the loss of synchronization continues for more than three cycles, the aircraft is determined to be faulty.

[0013] Preferably, in the triple redundancy mode, the three flight control boards collect the same sensor data, each calculates the control law to obtain control surface commands, and the control surface commands are output after voting to isolate single-machine failures. In dual-mode redundancy mode, the servo end or interface board determines the current flight controller based on the fault status indicated by each flight controller board and the order of the flight controller board numbers. It drives the servo according to the control surface commands of the current flight controller board and no longer votes on the control surface commands. At the same time, it determines the secondary faulty board based on the heartbeat signal and the board self-test information. If necessary, it activates single-mode mode. In single-mode mode, when the aircraft malfunctions again in dual-mode redundancy mode, the control surface commands or interface board will switch the duty to the normal single aircraft, which will then independently complete the flight control. The mode switching logic is as follows: in normal state, after detecting a single-machine failure, it enters dual-mode state; in dual-mode state, after detecting a second machine failure, it enters single-mode state.

[0014] Preferably, fault detection and localization employ a combination of heartbeat detection and cross-comparison detection. Heartbeat detection uses a push mode. Each flight control board reverses its own heartbeat signal in each mission cycle. Other boards monitor the heartbeat signal. If no heartbeat change is detected for three consecutive cycles, the board is considered to be dead. Cross-comparison detection is implemented through dual-port random access memory. The three machines exchange sensor data collected in the current cycle and perform pairwise comparisons. When the deviation exceeds the threshold and the comparison partner's self-test is normal, it is determined that the acquisition of its own machine is faulty. When the pairwise comparison results of the three machines are inconsistent, the faulty board is located through the built-in self-test program. By comprehensively applying heartbeat detection, cross-comparison detection, and built-in self-test, the fault detection coverage can reach over 0.95.

[0015] Preferably, the online repair and reconnection function for faulty channels includes the following steps: The first step is to isolate the faulty board and switch it to background monitoring mode, and then stop controlling the output; The second step is for the faulty board to perform self-test and self-repair in the background. For recoverable faults, it will automatically reset and recover; for unrecoverable hardware faults, it will be permanently isolated and an alarm will be triggered. The third step is to enter the listening and training mode after the repair is completed. It receives sensor data and output instructions from the health channel, performs control law calculations synchronously, and compares the results with the state of the machine before the fault. The fourth step is to send a request to join the other two aircraft when the deviation between the calculated value and the output of the aircraft on duty is less than the threshold for N consecutive cycles. The value of N depends on the aircraft model and is typically 30 to 50 cycles. Fifth, after receiving the request, the other two machines confirm that there is no conflict, and then re-include the board in the voting group, and the system resumes the three-mode redundancy mode.

[0016] Preferably, in the aerodynamic control surface segmentation redundancy, the aileron and V-tail control surfaces are each divided into inner and outer sections. The four control surfaces closer to the fuselage are called the inner control surfaces, and the four control surfaces farther from the fuselage are called the outer control surfaces. When the inner servo malfunctions and causes the control surface to jam, the inner control surface on that side is locked, and the control torque is compensated by the outer control surface on the same side. When one side fails completely, asymmetric output limitation is applied, and torque compensation is performed by the other side's control surface.

[0017] Preferably, in the dual-path redundancy of the CAN bus main path and the RS422 backup path, the key servo motor is simultaneously connected to both control paths. The main path is the CAN bus. The three flight control boards are directly connected to the servos via the CAN bus, and the median value is voted on at the servo end. The backup path is the RS422 bus. The interface board collects the control surface commands of the three flight control boards through the FlexRay bus, and after median voting, converts them into RS422 commands for input to the servos. During normal operation, the CAN main path is used. When the CAN bus fails or there is no valid data for three consecutive cycles, it switches to the RS422 backup path. When the backup path also fails, the servo maintains the current position and sends a fault alarm. Non-critical servos are driven only by pulse width modulation or analog signals after the interface board votes. Non-critical servos include throttle servos, propeller speed control servos, and front wheel steering servos.

[0018] Therefore, the present invention employs the above-mentioned redundant architecture method for UAV flight control system, which has the following beneficial effects: (1) Achieve no single point of failure in the entire system. The present invention implements redundant design for four layers: flight sensor system, redundant flight control computer system, bus communication system and actuator system, thereby eliminating the risk of single point of failure in sensors and actuators in traditional solutions.

[0019] (2) The three-bus redundancy architecture improves communication reliability. The three-bus redundancy architecture is composed of 1553B dual bus, FlexRay bus and CAN bus. The system does not degrade when a single bus fails, and it can still work when both buses fail, which significantly improves the reliability of bus communication.

[0020] (3) The hierarchical voting algorithm improves fault tolerance. The digital input adopts a 3-out-of-2 logic, and the analog input adopts a hierarchical difference discrimination algorithm, which can accurately locate the fault channel and output the effective value, thus avoiding the Byzantine Generals fault.

[0021] (4) Smooth switching between primary and backup ensures flight quality. The backup aircraft tracks the output of the current aircraft in real time through a cross link. During the switch, the transition is smooth, starting from the last output value of the current aircraft. There are no jumps in control surface commands and no abnormal shaking of the aircraft attitude.

[0022] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0023] Figure 1 This is a block diagram of the flight control system composition according to an embodiment of the redundant architecture method for a UAV flight control system of the present invention; Figure 2 This is a diagram illustrating the three-bus redundancy architecture and connection relationships of an embodiment of a redundant architecture method for an unmanned aerial vehicle (UAV) flight control system according to the present invention. Figure 3 This is a diagram of the internal structure of a redundant flight control computer in an embodiment of a redundant architecture method for a UAV flight control system according to the present invention. Detailed Implementation

[0024] The technical solution of the present invention will be further described below with reference to the accompanying drawings and embodiments.

[0025] Unless otherwise defined, the technical or scientific terms used in this invention shall have the ordinary meaning understood by one of ordinary skill in the art to which this invention pertains. The terms "first," "second," and similar terms used in this invention do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are used only to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0026] Example Please see Figures 1-3 This invention provides a redundant architecture method for a UAV flight control system, which consists of four main parts: a flight sensor system, a redundant flight control computer system, a redundant bus communication system, and an actuator system.

[0027] The system adopts a three-bus integrated architecture consisting of 1553B dual bus, FlexRay bus and CAN bus, with key data being cross-transmitted on redundant buses.

[0028] Redundancy design of flight sensors: The flight sensor system employs a multi-system, multi-frequency, and non-similar redundancy scheme to avoid common-cause failures.

[0029] Altitude information is redundantly provided by three systems: an atmospheric data system, a satellite navigation system, and a radar altimeter. The satellite navigation system is compatible with multiple constellations, including GPS, BD2, and GLONASS.

[0030] Position information is redundantly provided by both the satellite navigation system and the inertial navigation system. The inertial navigation system uses high-precision fiber optic gyroscopes, enabling the UAV to deliver terminally guided bombs with high accuracy.

[0031] Attitude information is redundantly provided by a fiber optic gyroscope and a satellite dual-antenna mobile differential attitude system. The satellite dual-antenna system provides attitude information in both roll and yaw directions through carrier phase differential technology.

[0032] In addition, the system is equipped with a wind vane angle of attack / sideslip angle sensor, a ground contact switch, and auxiliary sensors such as engine monitoring, fuel system health monitoring, power distribution network monitoring, and landing gear monitoring.

[0033] All sensor data is fused and validated for consistency within the flight control computer before use. A single sensor failure does not affect the normal operation of the system, while cross-validation of multiple sensors can identify soft faults and data injection attacks.

[0034] Redundant Bus Communication System Design: This invention adopts a three-bus redundant architecture, as detailed below: First, the 1553B dual-bus architecture employs an A / B dual-channel redundant configuration, with each bus operating independently and serving as a backup for the others. The flight control computer embeds a 1553B bus controller, which can be configured to operate as a bus controller, remote terminal, or bus monitor. The bus controller periodically sends commands to query the status of each remote terminal. When the main bus fails to respond for three consecutive cycles or the status word is set to fault, the system automatically switches to the backup bus. This bus is primarily used for communication between the flight control computer and avionics, weapon systems, and mission equipment.

[0035] Second, the FlexRay bus. Used for high real-time synchronization and data cross-transmission between the three flight controller boards, supporting microsecond-level synchronization accuracy and deterministic communication.

[0036] Third, the CAN bus. This is used as a direct voting channel from the flight controller board to the servo motors, creating path redundancy with the RS422 serial bus.

[0037] The bus-level fault isolation strategy is as follows: In the event of a single bus failure, the system automatically switches to another bus without degradation; in the event of a dual bus failure, the system is degraded to use FlexRay or CAN bus for core control command transmission.

[0038] Redundancy management of the 1553B dual-bus system is achieved through status words and mode codes. Bit 9 of the status word indicates a data word error, bit 16 indicates the bus is busy, bit 18 is used for dynamic bus control reception, and bit 19 indicates a terminal fault. The mode code "00000" works in conjunction with bit 18 of the status word to manage the scheduling of the redundant bus controller, while the mode codes "00100 / 00101" manage the switching between the dual-redundancy bus routes.

[0039] Redundancy design of flight control computer: Hardware architecture: The flight control computer adopts a homogeneous redundant structure. The three flight control boards have identical hardware and program functions, with only differences in bus ID and driver, forming similar redundancy.

[0040] Each flight controller board is based on a domestically produced SoC chip and FPGA chip, and integrates the following functional modules: The 1553B bus controller can be configured as a bus controller, remote terminal, or bus monitor. Dual-port random access memory for cross-communication between three machines; FlexRay bus interface, CAN bus interface and RS422 serial interface; Independent power supply module and watchdog timer.

[0041] The three flight control boards communicate with each other via dual-port random access memory for information exchange. Each SoC communicates with the 1553B bus via a bus controller, and the data bus uses a transformer coupling method.

[0042] This invention employs a three-level synchronization strategy: The first level is hardware synchronization. Each flight control board receives the same second pulse signal, achieving microsecond-level synchronization.

[0043] The second level is bus synchronization. Sub-microsecond synchronization is achieved through FlexRay bus periodic synchronization.

[0044] The third level is software-timed synchronization. The specific process is as follows: After the start of this cycle, each flight control board sends a handshake signal to the other two aircraft, and then waits to receive the handshake signals from the other two aircraft or waits for a timeout. If no signal is received from an aircraft within the timeout period, that aircraft is considered out of sync. If the out-of-sync condition persists for more than three consecutive cycles, the aircraft is considered faulty.

[0045] Redundancy working mode, supports three working modes, automatically switching according to the fault condition: First, the triple redundancy mode. When all three flight control boards are functioning normally, the system operates in triple redundancy mode. The three flight control boards collect the same sensor data and each calculates its own control law to obtain control surface commands. These control surface commands are then output after a vote, effectively isolating single-unit failures.

[0046] Second, dual-mode redundancy. When a single-unit fault is detected, the system switches to dual-mode redundancy. The servo terminal or interface board determines the current flight controller based on the fault indications from each flight controller board, according to the order of the flight controller board numbers. It then drives the servos according to the control surface commands of the current flight controller board, without voting on the control surface commands. At the same time, it identifies secondary faulty boards based on heartbeat signals and board self-test information, and activates single-mode if necessary.

[0047] Third, single-mode mode. In dual-mode redundancy mode, if the aircraft on duty experiences another malfunction, the control surface commands or interface board will switch the duty control to the normal single aircraft, which will then independently complete the flight control.

[0048] The mode switching logic is as follows: in normal state, after detecting a single-machine failure, it enters dual-mode state; in dual-mode state, after detecting a second machine failure, it enters single-mode state.

[0049] The voting algorithm for switch-to-control voting uses a 3-out-of-2 logic, expressed as follows: It can be implemented by FPGA hardware logic or software.

[0050] The analog voting process employs a hierarchical difference discrimination algorithm, with the following specific steps: The first step is to sort the three signals and determine the maximum value. Median Minimum value .

[0051] The second step is to calculate the difference. , .

[0052] The third step is to set the threshold. The threshold can be configured according to the type of control variable. For example, the attitude angle threshold can be set to... Angular velocity threshold set to The control surface command threshold is set to .

[0053] The fourth step is to vote based on the difference: like Less than and Less than If all three values ​​are valid, the median value will be output. like Greater than or equal to and Less than If the maximum value channel fails, the average value of the remaining two channels will be output. like Less than and Greater than or equal to If the minimum value channel fails, the average value of the remaining two channels will be output. like Greater than or equal to and Greater than or equal to If all three values ​​are inconsistent, the fault location process will begin.

[0054] Step 5: Full Fault Protection. When none of the three channels can output a valid value, the system outputs a preset safety value, such as a zeroing command for the control surface or a hovering command.

[0055] The flight control system employs two voting modes based on the different voting points for critical aerodynamic control surface control commands. The first is the servo-end value voting mode, where control surface commands are transmitted to the servo via the CAN bus, and a midpoint vote is performed at the servo end before driving the aerodynamic control surfaces. The second is the interface board voting mode, where the interface board receives control surface commands via the FlexRay bus, performs a midpoint vote, and then sends them to the servo via RS422. When the servo's CAN bus fails or loses signal, RS422 data commands are used instead. The two voting modes are redundant, ensuring triple redundancy of control surface commands even after a single failure.

[0056] This invention introduces a smooth switching mechanism between primary and backup modes in dual-mode redundancy.

[0057] The priority is set as follows: Flight controller A has the highest priority, followed by flight controller B, and flight controller C has the lowest priority.

[0058] During normal operation, the on-duty unit outputs control surface commands. The backup unit synchronously calculates the control commands and receives the output values ​​from the on-duty unit in real time via a cross-communication link, recording the deviation between the calculated values ​​and the on-duty unit's output values.

[0059] When a fault is detected in the current machine and a switchover is required, the backup machine starts from the last output value of the current machine and smoothly transitions to the calculated value of the backup machine within a preset number of cycles using a linear or exponential curve. The preset number of cycles is configurable depending on the machine model, with a typical value of 50 to 100 control cycles.

[0060] This mechanism ensures that there are no jumps in control surface commands and no abnormal vibrations in the aircraft's attitude.

[0061] Fault detection and localization utilize a push-based heartbeat detection mode. Each flight control board reverses its own heartbeat signal during each mission cycle, and other boards monitor this heartbeat signal. If no heartbeat change is detected for three consecutive cycles, the board is considered to have crashed.

[0062] Cross-comparison testing is implemented using a dual-port random access memory. The three sensors exchange sensor data collected in the current cycle and compare them pairwise. If the deviation exceeds a threshold and the compared sensor's self-test is normal, a fault is determined in the sensor's own data acquisition. If the pairwise comparison results of the three sensors are inconsistent, the faulty board is located using a built-in self-test program.

[0063] By comprehensively applying heartbeat detection, cross-comparison detection, and built-in self-test, the fault detection coverage can reach over 0.95.

[0064] Online recovery of faulty channels: This invention supports online repair and reconnection of faulty channels. The specific process is as follows: After the faulty board is isolated, it enters background monitoring mode and no longer controls the output. The faulty board performs self-test and self-repair in the background. For recoverable faults, such as momentary interruption of bus communication or watchdog reset, the system automatically resets and recovers; for unrecoverable hardware faults, the system permanently isolates the fault and issues an alarm.

[0065] After repair, the faulty board enters the monitoring and training mode. In this mode, the faulty board receives sensor data and output commands from the healthy channel, synchronously performs control law calculations, and compares them with the pre-fault state of the machine. When the calculated value deviates from the output of the current machine for N consecutive cycles by less than a threshold, it sends a request to join the other two machines. The value of N varies depending on the machine model, with a typical value of 30 to 50 cycles.

[0066] After receiving the request, the other two machines confirmed that there was no conflict and reinstated the board into the voting group, restoring the system to tri-mode redundancy.

[0067] Redundancy design of actuators: Aerodynamic control surface segmentation redundancy: The ailerons and V-tail control surfaces are each divided into inner and outer sections. The four control surfaces closer to the fuselage are called the inner control surfaces, and the four control surfaces farther from the fuselage are called the outer control surfaces.

[0068] The fault handling strategy is as follows: When the inner servo malfunctions and causes the control surface to jam, the inner control surface on that side is locked, and the control torque is compensated by the outer control surface on the same side to safely bring the aircraft back. When both sides fail, asymmetric output limitation is applied, and the torque is compensated by the control surface on the other side.

[0069] Servo electrical redundancy: Each servo controller contains two completely independent control circuits, designated A and B. Under normal operation, the A circuit output signal is valid, while the B circuit serves as a hot backup. The system detects faults through output monitoring and self-testing. If the A circuit fails, it switches to the B circuit within 50 microseconds. If both circuits fail, the system reports a fault, and the servo surfaces return to center or lock their current position according to safety protocols.

[0070] Actuator bus access redundancy: Key servos include the aileron servo and the V-tail servo, which are connected to two control paths simultaneously: The primary path is the CAN bus, with the three flight control boards directly connected to the servos via the CAN bus, where median voting is performed. The backup path is the RS422 bus, where the interface board acquires control surface commands from the three flight control boards via the FlexRay bus, converts them into RS422 commands after median voting, and inputs them to the servos, with one RS422 command per servo.

[0071] The switching logic is as follows: During normal operation, the CAN primary path is used. If the CAN bus fails or there is no valid data for three consecutive cycles, the system switches to the RS422 backup path. If the backup path also fails, the servo maintains its current position and sends a fault alarm.

[0072] Non-critical servos include throttle servos, windshield servos, propeller speed control servos, and front wheel steering servos, which are driven only by pulse width modulation or analog signals after the interface board votes.

[0073] Example Hardware configuration (a) Flight control computer configuration The flight control computer adopts a homogeneous triple redundancy architecture and is equipped with three flight control boards, referred to as flight control board A, flight control board B and flight control board C.

[0074] Each flight controller board is based on a domestically produced SoC chip and FPGA chip. The SoC chip uses a domestically produced multi-core processor for main control calculations and control law computation; the FPGA chip uses a domestically produced programmable logic array for hardware voting and interface expansion. Each board embeds a 1553B bus controller, model BU-61580, which can be configured as a bus controller, remote terminal, or bus monitor. The board integrates a 1MB x 32-bit dual-port random access memory for data cross-transmission between the three flight controller boards. In addition, each board integrates a FlexRay bus interface, a CAN bus interface, and an RS422 serial interface, as well as an independent power supply module and a watchdog timer.

[0075] Three flight control boards are mounted inside the VPX chassis. The chassis contains two power boards responsible for converting external primary power to 12V secondary power, providing surge protection, and supplying power to the flight control boards and interface boards via the baseboard. The chassis also houses an interface board that simultaneously acquires information from the three flight control boards via the FlexRay bus, performs median voting, and converts the data into RS422, DA, or PWM signal outputs. The chassis also includes a communication baseboard, a communication backplane, and three aviation connectors. The three flight control boards communicate with each other via dual-port random access memory (RAM). Each SoC communicates with the 1553B bus via a bus controller, and the data bus uses transformer coupling.

[0076] The three flight control boards have identical hardware and program functions, differing only in bus ID and bus driver, forming a similar redundant architecture.

[0077] (ii) Bus system configuration The bus system adopts a three-bus redundant architecture, which includes the following three parts.

[0078] First, the 1553B dual-bus architecture. It employs a dual-channel redundant configuration with channels A and B, each operating independently and serving as a backup for the others. The dual buses connect to various terminal devices via multi-port couplers. The 1553B bus controller embedded in the flight control computer can be configured as a bus controller, remote terminal, or bus monitor. This dual-bus architecture is primarily used for communication between the flight control computer and avionics equipment, weapon systems, and mission equipment.

[0079] Second, the FlexRay bus. Used for high real-time synchronization and data cross-transmission between the three flight controller boards, supporting microsecond-level synchronization accuracy and deterministic communication.

[0080] Third, the CAN bus. This is used as a direct voting channel from the flight controller board to the servo motors, creating path redundancy with the RS422 serial bus.

[0081] (III) Sensor Configuration The flight sensor system adopts a multi-system, multi-frequency, and non-similar redundancy scheme.

[0082] The inertial navigation system employs high-precision fiber optic gyroscopes, enabling the UAV to deliver terminally guided bombs with high accuracy. The satellite navigation system uses a dual-antenna BD2 GPS-compatible receiver, supporting moving differential attitude calculation and providing attitude information in both roll and yaw directions through dual-antenna moving differential technology. The atmospheric data system is equipped with an atmospheric data computer, providing information such as barometric altitude and airspeed. Altitude measurement utilizes a radar altimeter, providing radio altitude information. Aerodynamic angle measurement employs a wind vane angle of attack sensor and a wind vane sideslip angle sensor. Ground condition detection includes a ground contact switch to determine the landing gear's grounding status.

[0083] In addition, the system is also equipped with an engine monitoring module, a fuel system health monitoring module, a power distribution network monitoring module, and a landing gear monitoring module to monitor the health status of each subsystem.

[0084] All sensor data is fused and validated for consistency within the flight control computer before use. A single sensor failure does not affect the normal operation of the system, while cross-validation of multiple sensors can identify soft faults and data injection attacks.

[0085] Regarding altitude information, the atmospheric data system, satellite navigation system, and radar altimeter form redundancy. Regarding position information, the satellite navigation system and inertial navigation system form redundancy. Regarding attitude information, fiber optic gyroscopes and satellite dual-antenna moving differential attitude system form redundancy.

[0086] (iv) Configuration of implementing agencies The actuator system includes the following servos: four aileron servos, two on each side, driving the inner and outer aileron control surfaces on the left and right sides respectively; four V-tail servos, two on each side, driving the inner and outer V-tail control surfaces on the left and right sides respectively; in addition, it is equipped with one front wheel steering servo, one throttle servo, one throttle servo and one propeller speed control servo.

[0087] The ailerons and V-tail control surfaces are each divided into inner and outer sections. The four control surfaces closer to the fuselage are called the inner control surfaces, and the four control surfaces farther from the fuselage are called the outer control surfaces. During normal cruise, the inner and outer control surfaces work together to provide the required aerodynamic torque. When an inner control surface malfunctions and becomes stuck, the system locks the inner control surface on that side, and the outer control surface on the same side compensates for the control torque, bringing the aircraft back safely. When both sides fail, the system applies asymmetric output limitation, and the other control surface compensates for the torque.

[0088] Each critical servo, including the aileron servo and V-tail servo, has two completely independent control circuits internally, designated as circuit A and circuit B. During normal operation, circuit A outputs a valid signal, while circuit B is in hot backup mode. The system detects faults through output monitoring and self-testing. When circuit A fails, the system switches to circuit B within 50 microseconds. When both circuits fail, the system reports a fault, and the control surfaces return to center or lock their current position according to safety strategies.

[0089] The key servos are connected to two control paths simultaneously. The primary path is the CAN bus, through which the three flight control boards are directly connected to the servos. After median voting at the servo end, the aerodynamic control surfaces are driven. The backup path is the RS422 bus, through which the interface board collects the control surface commands from the three flight control boards via the FlexRay bus. After median voting, the commands are converted into RS422 commands and input to the servos. Each servo corresponds to one RS422 signal.

[0090] During normal operation, the system uses the CAN primary path. If the CAN bus fails or there is no valid data for three consecutive cycles, the system automatically switches to the RS422 backup path. If the backup path also fails, the servo motor maintains its current position and sends a fault alarm.

[0091] Non-critical servos include throttle servos, windshield servos, propeller speed control servos, and front wheel steering servos, which are driven only by pulse width modulation or analog signals after the interface board votes.

[0092] II. Software Configuration and Parameter Settings The flight control cycle is set to 20 milliseconds.

[0093] The parameters for the three-level synchronization are configured as follows: Hardware synchronization uses a second pulse signal with a synchronization accuracy of 1 microsecond. The FlexRay bus periodic synchronization accuracy is 0.5 microseconds. The software timed synchronization has a synchronization wait window of ±500 microseconds, and a fault is determined after three consecutive cycles of out-of-synchronization.

[0094] The thresholds for analog voting are configured as follows: attitude angle deviation threshold is set to 1 degree, angular rate deviation threshold is set to 0.5 degrees per second, and control surface command deviation threshold is set to 0.5 degrees. The preset safety values ​​output during full-fault protection include control surface zeroing commands or hovering commands.

[0095] The preset number of cycles for smooth switching between primary and backup is set to 80 control cycles, or 1.6 seconds. During switching, the backup machine starts from the last output value of the current machine and smoothly transitions to the calculated value of the primary machine according to a linear curve.

[0096] The online recovery parameter configuration is as follows. After the faulty board is repaired, it enters the monitoring and training mode, with the number of monitoring and training cycles set to 30 cycles. Before reconnection, the deviation between the calculated value and the output of the current machine for 30 consecutive cycles must be less than a threshold.

[0097] The flight controller priority is set as follows: Flight controller A has the highest priority, followed by Flight controller B, and Flight controller C has the lowest priority.

[0098] III. Work Process (a) System startup and synchronization After the system powers on, the three flight controller boards start synchronously. First, hardware synchronization is performed: each flight controller board receives the same one-second pulse signal, aligning its local clock to microsecond precision. Then, bus cycle synchronization is performed via the FlexRay bus, achieving sub-microsecond synchronization. At the beginning of each control cycle, software timed synchronization is executed: each flight controller board sends a handshake signal to the other two aircraft, then waits to receive the handshake signal or waits for a timeout. If no signal is received from any aircraft within the timeout period, that aircraft is considered out of sync. If the out-of-sync condition persists for more than three consecutive cycles, that aircraft is considered faulty.

[0099] (II) Data Collection and Input Voting During each control cycle, the three flight control boards independently acquire sensor data. Each flight control board sends the data it acquires to the other two flight control boards via a dual-port random access memory, and simultaneously reads the data sent by the other two boards.

[0100] After data exchange is completed, the system performs input voting. For digital signals, a 2-out-of-3 logic is used, with the expression X equal to AB, AC, or BC, implemented by FPGA hardware logic. For analog signals, a hierarchical difference discrimination algorithm is used. The specific steps are as follows: sort the three signals to determine the maximum, median, and minimum values; calculate the difference between the maximum and median values, and the difference between the median and minimum values; compare the two differences with a preset threshold; if both differences are less than the threshold, all three values ​​are valid, and the median value is output; if the difference between the maximum and median values ​​is greater than or equal to the threshold, but the difference between the median and minimum values ​​is less than the threshold, the maximum value channel is faulty, and the average of the remaining two channels is output; if the difference between the maximum and median values ​​is less than the threshold, but the difference between the median and minimum values ​​is greater than or equal to the threshold, the minimum value channel is faulty, and the average of the remaining two channels is output; if both differences are greater than or equal to the threshold, all three values ​​are inconsistent, and the fault location process begins; when none of the three channels can output a valid value, the system outputs a preset safety value.

[0101] (III) Control Law Solution After the input voting is completed, each flight control board independently calculates the control law and obtains the control surface commands. The three flight control boards run the same control law algorithm, but different bus drivers are used to avoid common-cause failures. After each flight control board completes its calculation, it sends its control surface commands to the other two flight control boards via a dual-port random access memory, while simultaneously reading the control surface commands from the other two boards.

[0102] (iv) Output voting and instruction sending After the control surface command exchange is completed, the system enters the output voting process. The flight control system has two voting modes based on the different voting points for key aerodynamic control surface commands; these two modes are redundant.

[0103] The first type is the servo motor-side value voting mode. The control surface command is directly transmitted to the servo motor via the CAN bus, and the aerodynamic control surface is driven after the median value is voted on at the servo motor end.

[0104] The second method is the interface board voting mode. The interface board obtains the control surface commands from the three flight control boards through the FlexRay bus, performs a median vote, and then sends them to the servos via RS422.

[0105] When the servo's CAN bus fails or loses signal, the system automatically switches to RS422 data commands. After a failure, the control commands for the servo surfaces still have triple redundancy.

[0106] (v) Redundancy Management and Mode Switching The system monitors the status of each flight control board in real time and automatically switches the working mode according to the fault situation.

[0107] When all three flight control boards are functioning normally, the system operates in tri-mode redundancy. The three flight control boards collect the same sensor data, each calculates its own control law to obtain control surface commands, and these commands are output after a voting process, thus isolating single-unit failures.

[0108] Upon detecting a single-unit fault, the system switches to dual-mode redundancy. The servo terminal or interface board, based on the fault indications from each flight control board and according to the order of the flight control board numbers, determines the current flight control unit and drives the servos according to the control surface commands of that unit, without further voting on control surface commands. Simultaneously, it identifies secondary faulty boards based on heartbeat signals and board self-test information, and activates single-mode if necessary.

[0109] In dual-mode redundancy, the on-duty unit outputs control surface commands normally. The backup unit synchronously calculates control commands and receives the on-duty unit's output values ​​in real time via a cross-communication link, recording the deviation between its own calculated values ​​and the on-duty unit's output values. When a fault is detected in the on-duty unit requiring a switchover, the backup unit starts from the last output value of the on-duty unit and smoothly transitions to its own calculated values ​​along a linear curve within 80 control cycles, completing the handover of control.

[0110] In dual-mode redundancy mode, if the aircraft on duty experiences another malfunction, the control surface commands or interface board will switch the duty authority to the normal single aircraft, which will then independently complete the flight control, thus entering single-mode mode.

[0111] The mode switching logic is as follows: in normal state, after detecting a single-machine failure, it enters dual-mode state; in dual-mode state, after detecting a second machine failure, it enters single-mode state.

[0112] (vi) Fault detection and location The system uses a combination of heartbeat detection and cross-comparison detection for fault detection and location.

[0113] Heartbeat detection uses a push-based mode. Each flight control board reverses its own heartbeat signal during each mission cycle, and other boards monitor this heartbeat signal. If no heartbeat change is detected for three consecutive cycles, the board is considered to be frozen.

[0114] Cross-comparison testing is implemented using a dual-port random access memory. The three sensors exchange sensor data collected in the current cycle and perform pairwise comparisons. When the deviation exceeds a threshold and the compared sensor's self-test is normal, a fault is determined in the sensor's own data acquisition. When the pairwise comparison results of the three sensors are inconsistent, the faulty board is located using a built-in self-test program.

[0115] By comprehensively applying heartbeat detection, cross-comparison detection, and built-in self-test, the fault detection coverage in this implementation can reach over 0.95.

[0116] (vii) Online recovery of faulty channels This implementation method supports online repair and reconnection of faulty channels. The specific process is as follows.

[0117] The first step is to isolate the faulty board and switch it to background monitoring mode, and then stop controlling the output.

[0118] The second step involves the faulty board performing self-tests and self-repairs in the background. For recoverable faults, such as momentary interruptions in bus communication or watchdog resets, the system automatically resets and recovers; for unrecoverable hardware faults, the system permanently isolates the fault and issues an alarm.

[0119] Third, after the repair is completed, the faulty board enters the monitoring and training mode. In this mode, the faulty board receives sensor data and output commands from the healthy channel, synchronously performs control law calculations, and compares them with the state of the machine before the fault.

[0120] The fourth step is that when the deviation between the calculated value and the output of the machine on duty is less than the threshold for 30 consecutive cycles, the fault board sends a request to join the other two machines.

[0121] Fifth, after receiving the request, the other two machines confirm that there is no conflict, and then re-include the board in the voting group, and the system resumes the three-mode redundancy mode.

[0122] (viii) Bus redundancy management Redundancy management of the 1553B dual bus is implemented through status words and mode codes.

[0123] The bus controller periodically sends mode commands to query the status of each remote terminal. Bit 9 of the status word indicates a data word error, bit 16 indicates the bus is busy, bit 18 is used for dynamic bus control reception, and bit 19 indicates a terminal fault. Mode code 00000, in conjunction with bit 18 of the status word, enables the scheduling management of the redundant bus controller, while mode codes 00100 and 00101 enable the switching management of dual-redundant bus routes.

[0124] When the main bus fails to respond for three consecutive cycles or the status word fault is set, the system automatically switches to the backup bus. In the event of a single bus failure, the system does not degrade; in the event of a dual bus failure, the system degrades and uses FlexRay or CAN bus for core control command transmission.

[0125] The backup bus continuously monitors the status of the main bus. When the main bus resumes communication and there are no error codes for 10 consecutive cycles, the system automatically switches back to the main bus.

[0126] IV. Experimental Verification A semi-physical simulation testing environment was built to verify the above implementation scheme. The testing environment included a physical flight control computer, physical servo motors, a simulation computer, a fault injection device, and a helicopter simulation system. The simulation computer ran a helicopter dynamics model to simulate data such as three-axis acceleration, angular velocity, position and attitude, and air-to-ground speed during flight. The fault injection device was used to simulate various fault scenarios.

[0127] The following typical fault injection tests were performed.

[0128] The first issue was a power failure in flight control board A. During flight simulation, flight control board A was completely powered off using a fault injection device. The system detected a loss of heartbeat signal from flight control board A within two control cycles, automatically determining a fault in the board and switching the system from tri-mode redundancy to dual-mode redundancy. Based on priority, flight control board B became the active-duty board, and flight control board C served as the backup. Test results showed that attitude fluctuations during the switchover were less than 0.5 degrees, the UAV showed no abnormal responses, and there were no significant jumps in control surface commands.

[0129] The second issue was an interruption fault in the 1553B bus A channel. During flight simulation, a fault injection device completely interrupted the 1553B bus A channel. After the bus controller did not receive a status response from the A channel for three consecutive cycles, it automatically switched communication to the B channel. Test results showed that the switching process was completed within three cycles, communication was uninterrupted, no data was lost, and data exchange between the flight control system and avionics and weapon systems was unaffected.

[0130] The third issue was a stuck inner left aileron servo. During flight simulation, a fault injection device caused the inner left aileron servo to get stuck in its current position. After detecting the abnormal response of the inner left aileron control surface, the system automatically locked the inner control surface on that side, and the outer left aileron provided torque compensation. Test results showed that the roll torque loss was less than 15%, the UAV remained controllable, and its attitude was stable.

[0131] The fourth test involved fault recovery and reconnection testing of Flight Controller Board C. First, a fault injection was used to induce a fault state in Flight Controller Board C. The system then isolated it and downgraded it to dual-mode redundancy. Subsequently, a fault repair simulation was performed, putting Flight Controller Board C into monitoring and training mode. Flight Controller Board C continuously received health channel data for 30 cycles for synchronous calculation, and the deviation between the calculated values ​​and the output of the aircraft on duty was less than the threshold. Then, Flight Controller Board C sent a request to join Flight Controller Boards A and B. After confirmation, it was re-integrated into the voting group, and the system restored tri-mode redundancy. The entire recovery process had no impact on flight control.

[0132] The fifth test involved simultaneous failure of both flight controllers. During flight simulation, both flight controllers A and B were simultaneously malfunctioned. Upon detecting the dual-plane failure, the system automatically switched to single-mode control, with flight controller C taking over independent control. Test results showed that flight controller C successfully completed the preset return-to-home mission, and the drone landed safely.

[0133] The sixth test involved CAN bus failure and RS422 backup path switching. During flight simulation, the CAN bus was interrupted via a fault injection device. After failing to receive valid data from the CAN bus for three consecutive cycles, the servo automatically switched to the RS422 backup path to receive control surface commands from the interface board after voting. The test results showed that there was no significant fluctuation in the control surface position during the switching process, and the UAV's attitude remained stable.

[0134] The seventh test was a smooth transition test during primary / backup computer switching. In dual-mode redundancy, the flight control board A of the active-duty aircraft was malfunctioned. Flight control board B, acting as a backup, started from the last output value of flight control board A during the switchover and smoothly transitioned to the locally calculated value within 80 control cycles along a linear curve. The test results showed no jumps in control surface commands, no abnormal jitter in servo motors, and stable attitude changes for the UAV.

[0135] The above experimental results demonstrate that the redundant architecture method for the UAV flight control system described in this invention can ensure flight safety under single-fault, dual-fault, bus fault, and actuator fault conditions. The master / slave switching is smooth and shock-free, and the online fault channel recovery mechanism effectively extends the high-reliability operating time. The automatic switching logic for the three operating modes—triple-mode redundancy, dual-mode redundancy, and single-mode redundancy—is correct and reliable, fault detection and location are accurate, and the voting algorithm effectively isolates fault channels. All experimental results verify the feasibility and effectiveness of this invention.

[0136] V. Summary of Application Results After adopting the above embodiments, the reliability index of the UAV flight control system is significantly improved.

[0137] At the sensor level, height, position, and attitude information all have triple or dual redundant sources. A single sensor failure does not affect the normal operation of the system, and multi-sensor cross-verification can effectively identify soft faults and data injection attacks.

[0138] At the bus level, the 1553B dual bus, FlexRay bus and CAN bus form a three-bus redundancy architecture. The system does not degrade when a single bus fails, and the core control functions can still be maintained when both buses fail.

[0139] At the flight control computer level, the automatic switching between three working modes—triple redundancy, dual redundancy, and single redundancy—combined with a smooth primary / backup switching mechanism and online fault recovery function, achieves the goal of being imperceptible to single faults and enabling return to base in the event of secondary faults.

[0140] At the actuator level, pneumatic control surface segment redundancy, servo electrical dual-path redundancy, and dual-path access redundancy of the CAN bus main path and RS422 backup path eliminate the risk of single point of failure in the actuator.

[0141] This embodiment employs a similar redundancy architecture and industrial-grade COTS devices, which effectively controls costs while ensuring high reliability. It has good engineering promotion value and is particularly suitable for medium- and high-altitude long-endurance and reconnaissance-strike integrated UAV platforms.

[0142] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the technical solutions of the present invention, and these modifications or equivalent substitutions cannot cause the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for redundant architecture of an unmanned aerial vehicle (UAV) flight control system, characterized in that: Redundancy design is implemented for four levels: flight sensor system, redundant flight control computer system, bus communication system, and actuator system. The bus communication system adopts a three-bus redundant architecture consisting of 1553B dual bus, FlexRay bus and CAN bus; The redundancy flight control computer system includes three working modes: triple redundancy, dual redundancy, and single redundancy, which can be automatically switched. It also has the function of online repair and reconnection of fault channels. The actuator system includes pneumatic control surface segment redundancy, servo electrical dual-path redundancy, and dual-path access redundancy of the CAN bus main path and RS422 backup path.

2. The redundant architecture method for a UAV flight control system according to claim 1, characterized in that: The flight sensor system adopts a multi-system, multi-frequency, non-similar redundancy scheme; Altitude information is redundantly provided by three systems: atmospheric data system, satellite navigation system, and radar altimeter; Location information is redundantly provided by the satellite navigation system and the inertial navigation system, with the inertial navigation system employing a high-precision fiber optic gyroscope; Attitude information is redundantly provided by fiber optic gyroscopes and satellite dual-antenna mobile differential attitude system. The satellite dual-antenna system provides attitude information in both roll and yaw directions through carrier phase differential technology. The flight sensor system is also equipped with a weather vane angle of attack sensor, a weather vane sideslip angle sensor, a ground contact switch, an engine monitoring module, a fuel system health monitoring module, a power distribution network monitoring module, and a landing gear monitoring module.

3. The redundant architecture method for a UAV flight control system according to claim 2, characterized in that: The 1553B dual-bus adopts an A / B dual-channel redundant configuration, with each bus working independently and serving as a backup for the others; The flight control computer has an embedded 1553B bus controller. The 1553B bus controller periodically sends commands to query the status of each remote terminal. When the main bus has no response for three consecutive cycles or the status word is set to fault, the system automatically switches to the backup bus. The 1553B dual bus is used for communication between the flight control computer and avionics, weapon systems, and mission equipment; The FlexRay bus is used for high real-time synchronization and data cross-transmission between flight controllers, supporting microsecond-level synchronization accuracy and deterministic communication; The CAN bus is used as a direct voting channel from the flight controller board to the servo, forming path redundancy with the RS422 serial bus; The flight control board includes flight control board A, flight control board B, and flight control board C.

4. The redundant architecture method for a UAV flight control system according to claim 3, characterized in that: The redundant flight control computer adopts a homogeneous architecture. Flight control board A, flight control board B, and flight control board C have identical hardware and program functions, forming similar redundancy. Each flight control board is based on a domestically produced SoC chip and FPGA chip, and integrates a 1553B bus controller, dual-port random access memory, FlexRay bus interface, CAN bus interface, RS422 serial interface, independent power supply module and watchdog timer. The three flight control boards communicate with each other through dual-port random access memory. Each SoC communicates with the 1553B bus via a bus controller, and the data bus uses a transformer coupling method. The redundant flight control computer adopts a three-level synchronization mechanism; The first level is hardware synchronization, where each flight control board receives the same second pulse signal to achieve microsecond-level synchronization; The second level is bus synchronization, which is achieved through FlexRay bus periodic synchronization to achieve sub-microsecond level synchronization; The third level is software timed synchronization, and the steps are as follows: After the start of this cycle, each flight control board sends a handshake signal to the other two aircraft, waits to receive the handshake signal or waits for a timeout. If a signal is not received from a certain aircraft after a timeout, it is determined that the aircraft has lost synchronization. If the loss of synchronization continues for more than three cycles, the aircraft is determined to be faulty.

5. The redundant architecture method for a UAV flight control system according to claim 4, characterized in that: In the three-mode redundancy mode, the three flight control boards collect the same sensor data, calculate the control law and obtain the control surface command, and output the control surface command after voting to isolate single-machine failure. In dual-mode redundancy mode, the servo end or interface board determines the current flight controller based on the fault conditions indicated by each flight controller board and the order of the flight controller board numbers. It drives the servo according to the control surface commands of the current flight controller board and no longer votes on the control surface commands. At the same time, it determines the secondary faulty board based on the heartbeat signal and the board self-test information. When the preset conditions are met, the single-mode mode is activated. In single-mode, when the on-duty aircraft malfunctions again in dual-mode redundancy, the control surface commands or interface board will switch the on-duty control to the normal single aircraft, which will then independently complete the flight control.

6. The redundant architecture method for a UAV flight control system according to claim 5, characterized in that: The fault detection and location in the online repair and reconnection function of the fault channel adopts a combination of heartbeat detection and cross-comparison detection. Heartbeat detection uses a push mode. Each flight control board reverses its own heartbeat signal in each mission cycle. Other boards monitor the heartbeat signal. If no heartbeat change is detected for three consecutive cycles, the board is considered to be dead. Cross-comparison detection is implemented through a dual-port random access memory. The three machines exchange the sensor data collected in this cycle and perform pairwise comparisons. When the deviation exceeds the threshold and the comparison partner's self-test is normal, it is determined that the data collection of the machine itself is faulty. When the pairwise comparison results of the three machines are inconsistent, the faulty board is located through the built-in self-test program.

7. A method for redundant architecture of a UAV flight control system according to claim 6, characterized in that: Online repair and reconnection function for faulty channels Includes the following steps: The first step is to isolate the faulty board and switch it to background monitoring mode, and then stop controlling the output; The second step is for the faulty board to perform self-test and self-repair in the background. For recoverable faults, it will automatically reset and recover; for unrecoverable hardware faults, it will be permanently isolated and an alarm will be triggered. The third step is to enter the listening and training mode after the repair is completed. It receives sensor data and output instructions from the health channel, performs control law calculations synchronously, and compares the results with the state of the machine before the fault. The fourth step is to send a request to join the other two machines when the deviation between the calculated value and the output of the current machine is less than the threshold for N consecutive cycles. Fifth, after receiving the request, the other two machines confirm that there is no conflict, and then re-include the board in the voting group, and the system restores the three-mode redundancy mode.

8. A method for redundant architecture of a UAV flight control system according to claim 7, characterized in that: In the aerodynamic control surface segmentation redundancy, the aileron and V-tail control surfaces are each divided into inner and outer sections. The four control surfaces closer to the fuselage are called the inner control surfaces, and the four control surfaces farther from the fuselage are called the outer control surfaces. When the inner servo motor malfunctions and causes the control surface to jam, the inner control surface on that side is locked, and the control torque is compensated by the outer control surface on the same side. When one side fails completely, asymmetric output limitation is applied, and torque compensation is performed by the other side's control surface.

9. A method for redundant architecture of a UAV flight control system according to claim 8, characterized in that: In the dual-path access redundancy of the CAN bus main path and the RS422 backup path, the key servo motor is simultaneously connected to both control paths. The main path is the CAN bus. The three flight control boards are directly connected to the servos via the CAN bus, and the median value is voted on at the servo end. The backup path is the RS422 bus. The interface board collects the control surface commands of the three flight control boards through the FlexRay bus, and after median voting, converts them into RS422 commands for input to the servos. During normal operation, the CAN main path is used. When the CAN bus fails or there is no valid data for three consecutive cycles, it switches to the RS422 backup path. When the backup path also fails, the servo maintains the current position and sends a fault alarm. Non-critical servos are driven only by pulse width modulation or analog signals after the interface board votes. Non-critical servos include throttle servos, propeller speed control servos, and front wheel steering servos.