A powerlink-based launch vehicle communication network system

By using a Powerlink-based launch vehicle communication network system, a through-bus architecture was designed with triple redundancy arbitration and master-slave communication mode. This solved the bandwidth and topology flexibility problems of traditional launch vehicle communication networks, achieved high real-time and reliable data transmission, and supported the switching of the master station role in reusable scenarios.

CN122457409APending Publication Date: 2026-07-24BEIJING LANDSPACETECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING LANDSPACETECH CO LTD
Filing Date
2026-06-26
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Traditional launch vehicle communication network systems face problems such as insufficient bandwidth, poor topology flexibility, limited scalability, high cost, and insufficient real-time performance and stability. In particular, in reusable scenarios, the bus architecture is difficult to support the dynamic switching of the master station role.

Method used

A Powerlink-based launch vehicle communication network system is adopted, including a second-stage star network, an interstage star network, a first-stage tail-stage star network, and a through-type Powerlink backbone bus. Combined with three independent Powerlink hardware channels and an arbitration unit, triple redundancy arbitration is achieved. A master-slave communication mode and fixed-cycle scheduling are adopted, and a redundant master station switching strategy is designed.

Benefits of technology

It achieves high real-time and high reliability data transmission, solves the problems of real-time and stability of data transmission during rocket flight, and supports dynamic switching of the master station role in reusable scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122457409A_ABST
    Figure CN122457409A_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of launch vehicle electronic information system, and particularly relates to a launch vehicle communication network system based on Powerlink. The system comprises a two-stage star network of a launch vehicle, an inter-stage star network, a first-stage tail star network and a main bus adopting a Powerlink bus; a plurality of terminal slave nodes in the two-stage section access a two-stage network repeater through a star topology communication link, a master node and the two-stage network repeater are connected in series to the main bus through a two-stage interface; a plurality of terminal slave nodes in the inter-stage section access an inter-stage network repeater through a star topology communication link, a redundant master node and the inter-stage network repeater are connected in series to the main bus through an inter-stage interface; a plurality of terminal slave nodes in the first-stage tail section access a first-stage tail network repeater through a star topology communication link, and are connected to the main bus through a first-stage tail interface. The system has high real-time performance and high reliability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of electronic information system technology for launch vehicles, and particularly relates to a launch vehicle communication network system based on Powerlink. Background Technology

[0002] With the increasing complexity of medium and large launch vehicle systems, the amount of system terminal equipment and system data that need to be processed has increased exponentially compared to traditional rockets. In particular, reusable launch vehicles cover more complex mission scenarios, which places higher demands on the bandwidth, real-time performance, reliability, and synchronization accuracy of communication network data.

[0003] Traditional launch vehicles widely use system communication buses such as the 1553B bus, which are technologically mature but face bottlenecks such as insufficient bandwidth, poor topology flexibility, limited scalability, and high cost. The 1Mbps bandwidth of traditional buses is insufficient to meet the high-bandwidth data transmission requirements of next-generation launch vehicles, such as high-definition image transmission, high-frequency vibration monitoring, and multi-channel servo control. Furthermore, various bus protocol standards are incompatible, preventing data exchange between different bus products. In reusable launch vehicle scenarios, the communication architecture needs to be reconfigured after stage separation, and the existing bus architecture cannot support the dynamic switching of the master station role. High-speed Ethernet has been introduced into the industrial and aerospace fields due to its high bandwidth, unified standards, and cost advantages. However, standard Ethernet uses a non-deterministic communication mode (CSMA / CD), facing network communication conflicts and communication cycle uncertainties, which cannot guarantee the real-time performance and stability of data transmission during rocket flight.

[0004] Powerlink, as a real-time industrial Ethernet protocol, achieves microsecond-level deterministic communication on the basis of standard Ethernet through a time slot mechanism, with a communication rate of up to 100Mbps. However, the existing technology lacks a Powerlink bus architecture specifically designed for the reusable scenario of launch vehicles. Summary of the Invention

[0005] The purpose of this invention is to provide a Powerlink-based launch vehicle communication network system to solve the problem that the real-time performance and stability of data transmission during rocket flight cannot be guaranteed.

[0006] This invention provides a Powerlink-based launch vehicle communication network system, including a second-stage star network, an interstage star network, a first-stage tail star network, and a backbone bus using a through-type Powerlink bus. The secondary segment star network includes a master station management node, several terminal slave nodes within the secondary segment, a network repeater within the secondary segment, and a Powerlink interface for the secondary segment. The several terminal slave nodes within the secondary segment are connected to the network repeater within the secondary segment via a Powerlink communication link in a star topology. The master station management node and the network repeater within the secondary segment are connected in series to the backbone bus through the Powerlink interface for the secondary segment. The inter-level segment star network includes redundant master nodes, several terminal slave nodes within the inter-level segment, network repeaters within the inter-level segment, and an inter-level segment Powerlink interface. The several terminal slave nodes within the inter-level segment are connected to the network repeaters within the inter-level segment via Powerlink communication links in a star topology. The redundant master nodes and the network repeaters within the inter-level segment are connected in series to the backbone bus through the inter-level segment Powerlink interface. The first-level tail segment star network includes several terminal slave nodes within the first-level tail segment, a network repeater within the first-level tail segment, and a first-level tail segment Powerlink interface; the several terminal slave nodes within the first-level tail segment are connected to the network repeater within the first-level tail segment via a Powerlink communication link in a star topology, and the network repeater within the first-level tail segment is connected to the backbone bus through the first-level tail segment Powerlink interface; Both the Powerlink bus and the Powerlink communication link adopt three independent Powerlink hardware channels. The master station management node, the redundant master station node, and the terminal slave station node are all equipped with arbitration units to perform triple redundancy arbitration on the input and output data of the three independent Powerlink hardware channels.

[0007] In some embodiments, the three independent Powerlink hardware channels each include an independent PHY chip, isolation transformer, common mode choke, and shielded twisted pair cable for physical transmission medium; The triple redundancy arbitration for input and output data of the three independent Powerlink hardware channels includes: When data is input to the three independent Powerlink hardware channels, the master station management node simultaneously sends the same data frame to the terminal slave node through the three independent Powerlink hardware channels. When outputting data to the three independent Powerlink hardware channels, the three independent Powerlink hardware channels of the terminal slave node receive the data independently, and the arbitration unit performs a two-out-of-three voting process on the data received by the three independent Powerlink hardware channels based on a preset three-redundancy arbitration strategy.

[0008] In some embodiments, both the master station management node and the terminal slave node include a heterogeneous hardware platform and a physical layer interface; the heterogeneous hardware platform includes a processing system PS terminal and an editable logic PL terminal; The processing system PS terminal is used to run application software; the application software includes a real-time operating system, application layer processing of the Powerlink protocol stack, object dictionary management, service data object (SDO) configuration, and data parsing application. The programmable logic (PL) terminal is used to run the Powerlink communication IP core and implement the data link layer function of the Powerlink communication protocol in hardware logic. The data link layer function includes precise timing control, frame processing, cyclic redundancy check (CRC) and clock synchronization logic. The physical layer interface is used to transmit and receive underlying Ethernet data frames through the PHY chip to support physical layer connections; wherein, the PHY chip is connected to the programmable logic (PL) terminal through the MII / RMII interface, and is also connected to the Powerlink interface through the isolation transformer and the common mode choke.

[0009] In some embodiments, the arbitration unit performs a two-out-of-three voting process on the data received from the three independent Powerlink hardware channels based on a preset triple-redundancy arbitration strategy, including: The arbitration unit is equipped with a data receiving program independent of the main program. The data receiving program monitors and receives three redundancy data. After receiving the first redundancy data, the timing starts. If three redundancy data are received, the current cycle of receiving is stopped and the main program is reported. If the data receiving time exceeds a preset cycle, the receiving is stopped and the received data is reported. The main program performs an integrity check on the reported data: if the reported data consists of three redundant data points received periodically and is complete, then the three redundant data points are cleaned to obtain cleaned data; otherwise, the reported data is discarded and the data is re-received through the data receiving program. The main program determines the number of valid data sets in the cleaned data: if the number of valid data sets is greater than or equal to 2, the cleaned data is averaged and a functional model is applied before outputting two out of three data sets; otherwise, the cleaned data is cleared and the data is re-received through the data receiving program.

[0010] In some embodiments, the data cleaning of the three redundancy data includes: The three redundancy data are judged to be in the same frame based on the frame number or time stamp, so as to clear the data in different frames and obtain the data in the same frame. The validity of the same-shot data is verified to remove the data that failed the verification and obtain the data that succeeded in the verification. The successfully verified data are subjected to correlation difference verification, and data whose absolute value of correlation difference meets the preset correlation difference threshold range are retained; If the three redundancy data are status command data, then a consistency comparison is performed, and consistent status command data is retained.

[0011] In some embodiments, the master station management node exclusively holds the unified scheduling rights for the entire network communication and sends polling request frames to the entire network using a fixed-period scheduling mode; After receiving the polling request frame sent by the master station management node, each of the terminal slave nodes replies with a polling response frame within a predetermined time window.

[0012] In some embodiments, the communication period of the fixed-period scheduling mode is fixed at 1ms, and each communication period is divided into an isochronous synchronous domain and an asynchronous domain, and the isochronous synchronous domain and the asynchronous domain are isolated from each other in time; wherein, the isochronous synchronous domain transmits periodic real-time data; and the asynchronous domain transmits non-periodic data.

[0013] In some embodiments, the process of transmitting periodic real-time data in the isochronous synchronization domain is as follows: The master station management node sends an IdentRequest frame to the entire network, and each of the terminal slave nodes responds with an IdentResponse frame. The main station management node automatically establishes and dynamically maintains a list of active nodes based on the IdentResponse frame response. In the isochronous synchronization domain of each communication cycle, the master station management node sends polling request frames to each of the terminal slave nodes in sequence according to the active node list, and each of the terminal slave nodes replies with a polling response frame by allocating a fixed time slot; wherein, the length of the time slot is pre-calculated based on the amount of data of each of the terminal slave nodes.

[0014] In some embodiments, the redundant master station node employs the following switching strategy based on the launch vehicle's flight profile, including: During the pre-launch preparation and first-stage ascent phase of the launch vehicle, when the master station management node sends the period start SoC frame to the entire network, it schedules the communication of each terminal slave node and sets the redundant master station node to work in slave mode. After the stage separation of the launch vehicle, the redundant master station node switches from slave mode to master mode to serve as the master station management node for the first stage return segment.

[0015] In some embodiments, the workflow of the redundant master node switching from slave mode to master mode to serve as the master management node of the first-level return segment includes: When the redundant master node receives an inter-stage separation signal or detects that the Powerlink bus has not received a SoC frame for a duration longer than a preset continuous period, it automatically initiates a switching process to switch the redundant master node from slave mode to master mode and become the master management node of the first-level return segment. After the switchover is completed, the redundant master node begins to send periodic start SoC frames to the primary return segment network to rebuild the communication scheduling of the primary return segment network in order to manage several terminal slave nodes in the primary tail segment. The switching process is completed within 1ms, and during the switching period, several terminal slave nodes in the first-level tail segment remain in a waiting state.

[0016] This invention provides a Powerlink-based launch vehicle communication network system. The system includes a second-stage star network, an inter-stage star network, a first-stage tail-end star network, and a backbone bus using the Powerlink bus architecture. Within the second stage, several terminal slave nodes connect to network repeaters in a star topology via Powerlink communication links. The master station management node and the network repeaters in the second stage are connected in series to the backbone bus via the second-stage Powerlink interface. Similarly, within the inter-stage, several terminal slave nodes connect to network repeaters in a star topology via Powerlink communication links. A redundant master station node and the network repeaters in the inter-stage are connected in series to the backbone bus via the inter-stage Powerlink interface. Finally, within the first-stage tail-end, several terminal slave nodes connect to network repeaters in a star topology via Powerlink communication links and are connected to the backbone bus via the first-stage tail-end Powerlink interface. This Powerlink-based launch vehicle communication network system possesses high real-time performance and high reliability. Attached Figure Description

[0017] Figure 1 This is a block diagram of a Powerlink-based launch vehicle communication network system according to an embodiment of the present invention. Figure 2 This is a flowchart of the triple redundancy arbitration strategy according to an embodiment of the present invention. Detailed Implementation

[0018] Various embodiments and features of this application are described herein with reference to the accompanying drawings.

[0019] It should be understood that various modifications can be made to the embodiments described herein. Therefore, the above description should not be considered as limiting, but merely as an example of embodiments. Other modifications within the scope and spirit of this application will be apparent to those skilled in the art.

[0020] The accompanying drawings, which are included in and form part of this specification, illustrate embodiments of the present application and, together with the general description of the present application given above and the detailed description of the embodiments given below, serve to explain the principles of the present application.

[0021] These and other features of this application will become apparent from the following description of preferred forms of embodiments given as non-limiting examples, with reference to the accompanying drawings.

[0022] It should also be understood that although this application has been described with reference to some specific examples, those skilled in the art can certainly implement many other equivalent forms of this application.

[0023] Traditional communication methods, such as the 1553B bus, suffer from insufficient bandwidth, poor topology flexibility, limited scalability, and high cost. Standard Ethernet, employing a nondeterministic (CSMA / CD) communication mode, faces issues of network communication conflicts and communication cycle uncertainty. Considering the master station role switching requirements after stage separation in reusable launch vehicles, a launch vehicle communication architecture design based on the Powerlink network is proposed to resolve these contradictions.

[0024] Figure 1 A block diagram of a Powerlink-based launch vehicle communication network system is provided as an embodiment of the present invention, as follows: Figure 1 As shown, a Powerlink-based launch vehicle communication network system includes a second-stage star network, an interstage star network, a first-stage tail star network, and a backbone bus using a through-type Powerlink bus. The secondary segment star network includes a master station management node, several terminal slave nodes within the secondary segment, a network repeater within the secondary segment, and a Powerlink interface for the secondary segment. The several terminal slave nodes within the secondary segment are connected to the network repeater within the secondary segment via a Powerlink communication link in a star topology. The master station management node and the network repeater within the secondary segment are connected in series to the backbone bus through the Powerlink interface for the secondary segment. The inter-level segment star network includes redundant master nodes, several terminal slave nodes within the inter-level segment, network repeaters within the inter-level segment, and an inter-level segment Powerlink interface. The several terminal slave nodes within the inter-level segment are connected to the network repeaters within the inter-level segment via Powerlink communication links in a star topology. The redundant master nodes and the network repeaters within the inter-level segment are connected in series to the backbone bus through the inter-level segment Powerlink interface. The first-level tail segment star network includes several terminal slave nodes within the first-level tail segment, a network repeater within the first-level tail segment, and a first-level tail segment Powerlink interface; the several terminal slave nodes within the first-level tail segment are connected to the network repeater within the first-level tail segment via a Powerlink communication link in a star topology, and the network repeater within the first-level tail segment is connected to the backbone bus through the first-level tail segment Powerlink interface; Both the Powerlink bus and the Powerlink communication link adopt three independent Powerlink hardware channels. The master station management node, the redundant master station node, and the terminal slave station node are all equipped with arbitration units to perform triple redundancy arbitration on the input and output data of the three independent Powerlink hardware channels.

[0025] Specifically, the overall system architecture is as follows: Figure 1 As shown, a launch vehicle communication architecture design based on the Powerlink network includes: ① Second-stage star network: The master station management node is located in the second stage of the rocket and acts as the master station (MN) of the Powerlink bus. It is responsible for generating the system synchronization clock, scheduling the bus cycle, and maintaining the list of active nodes. The terminal slave nodes (second-stage controller, second-stage servo system and other terminal slave nodes of this segment) in the second-stage (module) are connected to the network repeater of this segment in a star topology and connected to the backbone bus through the Powerlink interface to form the second-stage star network.

[0026] ② Inter-class segment star network: The terminal slave nodes (redundant onboard computer, inter-class segment controller and other terminal slave nodes of this segment) in the inter-class segment (module) are connected to the network repeater of this segment in a star topology and connected to the backbone bus through the Powerlink interface to form an inter-class segment star network.

[0027] ③ Primary tail section star network: The terminal slave nodes (primary controller, primary servo system and other terminal slave nodes of this section) in the primary tail section are connected to the network repeater of this section in a star topology and connected to the backbone bus through the Powerlink interface to form a primary tail section star network.

[0028] In this embodiment of the invention, the backbone bus adopts a through-type Powerlink bus, which sequentially connects the master station management node and each regional network repeater to form a cross-section communication backbone.

[0029] Compared with existing technologies, the technical solution of this invention is designed with the Powerlink bus architecture for reusable launch vehicle scenarios, which can ensure the real-time performance and stability of data transmission during rocket flight.

[0030] Based on the above embodiments, each of the three independent Powerlink hardware channels includes an independent PHY chip, isolation transformer, common mode choke, and shielded twisted pair cable for physical transmission medium. Specifically, for the triple redundant hardware channel configuration, the system uses three independent Powerlink hardware channels, each channel is configured completely independently, including an independent PHY chip, isolation transformer, common mode choke and physical transmission medium shielded twisted pair cable.

[0031] The triple redundancy arbitration for input and output data of the three independent Powerlink hardware channels includes: When data is input to the three independent Powerlink hardware channels, the master station management node simultaneously sends the same data frame to the terminal slave node through the three independent Powerlink hardware channels. When outputting data to the three independent Powerlink hardware channels, the three independent Powerlink hardware channels of the terminal slave node receive the data independently, and the arbitration unit performs a two-out-of-three voting process on the data received by the three independent Powerlink hardware channels based on a preset three-redundancy arbitration strategy.

[0032] That is, when sending data, the master station management node sends the same data frame to each terminal slave node simultaneously through three independent Powerlink hardware channels. When receiving data, each terminal slave node receives data independently through its three independent Powerlink hardware channels.

[0033] In other words, the system adopts a triple-redundant communication mechanism, which combines a triple-redundant hardware channel with a triple-redundant arbitration strategy to ensure the reliability of system communication.

[0034] Based on the above embodiments, both the master station management node and the terminal slave node include a heterogeneous hardware platform and a physical layer interface; the heterogeneous hardware platform includes a processing system PS terminal and an editable logic PL terminal; The processing system PS terminal is used to run application software; the application software includes a real-time operating system, application layer processing of the Powerlink protocol stack, object dictionary management, service data object (SDO) configuration, and data parsing application. The programmable logic (PL) terminal is used to run the Powerlink communication IP core and implement the data link layer function of the Powerlink communication protocol in hardware logic. The data link layer function includes precise timing control, frame processing, cyclic redundancy check (CRC) and clock synchronization logic. The physical layer interface is used to transmit and receive underlying Ethernet data frames through the PHY chip to support physical layer connections; wherein, the PHY chip is connected to the programmable logic (PL) terminal through the MII / RMII interface, and is also connected to the Powerlink interface through the isolation transformer and the common mode choke.

[0035] It should be noted that the master-slave node hardware platform design is as follows: 1) Both the master station management node and the terminal slave nodes (such as secondary controllers) use Xilinx Zynq 7000 series processors as the core processing units to build a PS+PL heterogeneous hardware platform: ①PS End: Runs a real-time operating system, implementing software functions such as the Powerlink application layer protocol stack, control algorithms, telemetry framing, and data parsing. The PS end exchanges data at high speed with the PL end via the AXI bus, and is responsible for sending, receiving, parsing, and processing Powerlink application data.

[0036] ②PL end: Embedded Powerlink communication IP core, implementing the data link layer functions of the Powerlink communication protocol in hardware logic, including: Time synchronization: Based on a precise time protocol, microsecond-level clock synchronization between master and slave nodes is achieved through hardware timestamps.

[0037] Frame processing: Hardware parses Ethernet frames, identifies Powerlink-specific frame types (SoC, PollRequest, PollResponse, IdentRequest, IdentResponse, etc.), and interrupts the PS end only when application layer processing is required.

[0038] Timing control: Independent of the PS end's running state, it precisely controls the switching of time windows between the isochronous and asynchronous phases to ensure communication determinism.

[0039] 2) Physical layer interface design: ①PHY chip: An aerospace-grade Ethernet PHY chip is selected to realize 100BASE-TX physical layer encoding and decoding, automatic negotiation and media access control.

[0040] ② Interface connection: The PHY chip is connected to the PL terminal through the MII / RMII interface, and connected to the network interface through an isolation transformer and a common mode choke to meet the electromagnetic compatibility requirements of the rocket.

[0041] Based on the above embodiments, such as Figure 2 As shown, the arbitration unit performs a two-out-of-three voting process on the data received from the three independent Powerlink hardware channels based on a preset triple-redundancy arbitration strategy, including: The arbitration unit is equipped with a data receiving program independent of the main program. The data receiving program monitors and receives three redundancy data. After receiving the first redundancy data, the timing starts. If three redundancy data are received, the current cycle of receiving is stopped and the main program is reported. If the data receiving time exceeds a preset cycle, the receiving is stopped and the received data is reported. The main program performs an integrity check on the reported data: if the reported data consists of three redundant data points received periodically and is complete, then the three redundant data points are cleaned to obtain cleaned data; otherwise, the reported data is discarded and the data is re-received through the data receiving program. The main program determines the number of valid data sets in the cleaned data: if the number of valid data sets is greater than or equal to 2, the cleaned data is averaged and a functional model is applied before outputting two out of three data sets; otherwise, the cleaned data is cleared and the data is re-received through the data receiving program.

[0042] Specifically, the system master and slave nodes are equipped with an arbitration unit to arbitrate the input and output data of the three hardware channels, combined with... Figure 2 As shown, the implementation process using a triple-redundancy arbitration strategy includes: ① Data Reception: A data reception program independent of the main program is set up to monitor three redundancy data points. Timing begins upon receiving the first redundancy data point (excluding the previous frame). If three redundancy data points are received, reception for the current cycle stops and the main program is notified; otherwise, data reception times out if the timing exceeds one cycle. If t (variable parameters) is not found, then receiving will stop and the received data will be reported. ② Data Cleaning: Based on the "frame sequence number" or "time stamp," determine if the received data is from the same timeframe and remove data from different timeframes; perform data validity verification and remove data that fails verification; perform correlation difference verification and set a correlation difference threshold*. d (variable parameters) retains data whose absolute value of the correlation difference meets the threshold range. If it is status instruction data, a consistency comparison is performed, and consistent instruction data is retained. ③ Data application: After the above-mentioned processing steps, if the number of remaining valid data sets is ≥2, the valid analog data will be averaged and the results will be used by the application model of the closed-loop system.

[0043] Based on the above embodiments, combined with Figure 2 As shown, the data cleaning of the three redundancy data includes: The three redundancy data are judged to be in the same frame based on the frame number or time stamp, so as to clear the data in different frames and obtain the data in the same frame. The validity of the same-shot data is verified to remove the data that failed the verification and obtain the data that succeeded in the verification. The successfully verified data are subjected to correlation difference verification, and data whose absolute value of correlation difference meets the preset correlation difference threshold range are retained; If the three redundancy data are status command data, then a consistency comparison is performed, and consistent status command data is retained.

[0044] Based on the above embodiments, the master station management node exclusively has the unified scheduling right of the entire network communication, and sends polling request frames to the entire network using a fixed period scheduling mode; After receiving the polling request frame sent by the master station management node, each of the terminal slave nodes replies with a polling response frame within a predetermined time window.

[0045] In other words, in this embodiment of the invention, the system communication adopts a master-slave communication mode, with the master station having exclusive scheduling rights, including: ① The master station management node has the sole communication scheduling authority in the entire network. The master station performs unified scheduling, while the slave stations respond passively. ② No terminal slave node has the right to actively send any data frame. Only after receiving the Preq (polling request) frame sent by the master station can it reply with the Pres (polling response) frame within the specified time window. The centralized control of channel access permissions in this embodiment of the invention fundamentally eliminates the possibility of multiple nodes transmitting simultaneously and completely eliminates bus conflicts.

[0046] Based on the above embodiments, the fixed-cycle scheduling mode has a fixed communication cycle duration of 1ms. Each communication cycle is divided into an isochronous synchronous domain and an asynchronous domain, and the isochronous synchronous domain and the asynchronous domain are isolated from each other in time. The isochronous synchronous domain transmits periodic real-time data, and the asynchronous domain transmits non-periodic data.

[0047] Based on the above embodiments, the process of transmitting periodic real-time data in the isochronous synchronization domain is as follows: The master station management node sends an IdentRequest frame to the entire network, and each of the terminal slave nodes responds with an IdentResponse frame. The main station management node automatically establishes and dynamically maintains a list of active nodes based on the IdentResponse frame response. In the isochronous synchronization domain of each communication cycle, the master station management node sends polling request frames to each of the terminal slave nodes in sequence according to the active node list, and each of the terminal slave nodes replies with a polling response frame by allocating a fixed time slot; wherein, the length of the time slot is pre-calculated based on the amount of data of each of the terminal slave nodes.

[0048] Specifically, the system adopts a 1ms fixed-period scheduling mode, and each communication cycle is divided into: ①Isochronous synchronization domain: The duration is configurable (typical value 800μs) and is used to transmit periodic real-time data.

[0049] During the system power-on initialization phase, the master management node discovers nodes across the entire network by sending IdentRequest frames. Each network repeater and terminal slave node responds with an IdentResponse frame, reporting its own node ID, device type, object dictionary configuration, and other information. The master management node automatically creates and dynamically maintains a list of active nodes based on the response results.

[0050] During the isochronous phase of each communication cycle, the master station management node sends poll request frames sequentially to each terminal slave node according to the dynamically maintained list of active nodes. The system employs Poll Request Chaining (PRC) technology. After the master station sends a Preq frame to a node, that node broadcasts a Procedural Data Object (PDO) via a Pres frame. Upon receiving the Pres frame or after a timeout, the master station immediately sends a Preq frame to the next node, and so on. This tightly coupled "request-response" chain mechanism reduces handshake overhead on the bus and improves communication efficiency.

[0051] ② Asynchronous Domain: Configurable duration (typically 200μs), used for transmitting non-periodic data. SDO data frames are transmitted during software uploads, fault log downloads, or ground test commands.

[0052] ③ The isochronous synchronous domain and the asynchronous domain are strictly isolated in time and do not interfere with each other. Each slave station is assigned a fixed time slot for replying to data, and the length of the time slot is pre-calculated and determined based on the amount of data at that station. Fixed period and fixed time slot eliminate temporal randomness, making the timing of sending each frame of data precisely predictable.

[0053] Furthermore, a variable-length frame optimization strategy is employed for each transmitted data frame, meaning the system configures differentiated frame lengths for different message types. By dynamically adjusting the maximum frame length configuration of each terminal slave node, bus utilization is improved by approximately 15% to 20%. Typical values ​​are as follows: ① Control command messages: These have small data volumes and high real-time requirements, and are configured as short frame lengths (64 bytes).

[0054] ②Servo status feedback message: The data volume is moderate, and it is configured with a standard frame length (256 bytes).

[0055] ③ Telemetry data packets and image data: The data volume is large, and it is configured as a long frame length (1024 bytes).

[0056] Based on the above embodiments, the redundant master station node adopts the following switching strategy based on the flight profile of the launch vehicle, including: During the pre-launch preparation and first-stage ascent phase of the launch vehicle, when the master station management node sends the period start SoC frame to the entire network, it schedules the communication of each terminal slave node and sets the redundant master station node to work in slave mode. After the stage separation of the launch vehicle, the redundant master station node switches from slave mode to master mode to serve as the master station management node for the first stage return segment.

[0057] Based on the above embodiments, the workflow of the redundant master station node switching from slave mode to master mode to serve as the master station management node of the first-level return segment includes: When the redundant master node receives an inter-stage separation signal or detects that the Powerlink bus has not received a SoC frame for a duration longer than a preset continuous period, it automatically initiates a switching process to switch the redundant master node from slave mode to master mode and become the master management node of the first-level return segment. After the switchover is completed, the redundant master node begins to send periodic start SoC frames to the primary return segment network to rebuild the communication scheduling of the primary return segment network in order to manage several terminal slave nodes in the primary tail segment. The switching process is completed within 1ms, and during the switching period, several terminal slave nodes in the first-level tail segment remain in a waiting state.

[0058] Specifically, the redundant master station node switching mechanism is designed for the flight profile of reusable launch vehicles, and the system master station switching process is as follows: ①Phase One (Pre-launch preparation and first stage ascent): The onboard computer acts as the primary management node (MN_primary), sending SoC frames to the entire network and scheduling communication between network repeaters and terminal slave nodes. The redundant primary node (set in the inter-level segment, MN_backup) runs in slave mode, continuously monitoring the bus status and receiving heartbeat messages.

[0059] ② Phase Two (Interstage Separation Moment): After the interstage separation command is triggered, the onboard computer (MN_primary) continues to control the second substage after separating from the first substage. The redundant master node (MN_backup) automatically initiates the master switchover process when it detects a separation signal or a bus silence timeout (no SoC frame received for 5 consecutive cycles).

[0060] ③ Phase Three (Level 1 Return Segment): The redundant master node (MN_backup) switches from slave mode to master mode, becoming the master management node of the first-level return segment. After the switchover is complete, MN_backup begins sending SoC frames, re-establishes communication scheduling for the return segment, and manages the terminal slave nodes such as controllers and servo systems within the first-level tail segment.

[0061] In this embodiment of the invention, the master station switching process is completed within 1ms. During the switching, the terminal slave node remains in a waiting state, and communication returns to normal after the switching.

[0062] In this embodiment of the invention, the overall architecture of the launch vehicle communication architecture based on the Powerlink network revolves around the following five core technical directions: triple redundancy communication mechanism and arbitration processing, master-slave communication mode and redundant master station switching strategy, fixed communication cycle scheduling and variable length frame processing, Powerlink network engineering application, and master-slave station hardware configuration and processing.

[0063] Direction 1: Triple Redundancy Communication Mechanism and Arbitration Processing. The system employs a triple redundancy communication mechanism to ensure the reliability of Powerlink network communication, specifically including: 1) Three-channel hardware redundancy: The Powerlink communication link uses three independent hardware channels for parallel transmission, including the first channel, the second channel, and the third channel. Each channel is independent at both the physical layer and the data link layer, and is configured with an independent PHY chip, isolation transformer, common mode choke, and shielded twisted pair cable. The failure of any one channel will not affect the normal operation of the other channels.

[0064] 2) Triple Redundancy Arbitration Mechanism: The system is equipped with an arbitration unit that receives data or status signals from three channels and votes according to the "two out of three" principle. When at least two channels output the same result, the arbitration unit outputs the result as the valid output.

[0065] Direction Two: Master-Slave Communication Mode and Redundant Master Station Switching. The master-slave mechanism ensures deterministic communication. This invention adopts a master-slave communication mode, fundamentally solving the problems of network conflicts and latency uncertainty, including: 1) Unified scheduling and management by the master station: The master station management node acts as the communication master station to perform unified scheduling across the entire network. The slave stations respond passively. The slave stations can only reply with a Pres frame within a specified time window after receiving the Preq frame sent by the master station.

[0066] 2) Node Discovery and Active Node List Maintenance: During system power-on initialization, the master management node discovers nodes across the entire network by sending IdentRequest frames. Each network repeater and terminal slave node responds with an IdentResponse frame, reporting its own node ID, device type, object dictionary configuration, and other information. The master management node automatically builds and dynamically maintains an active node list based on the response results, serving as the basis for scheduling subsequent periodic communications. When a node's online status changes (e.g., node failure or recovery), the master management node detects and updates the active node list through a heartbeat mechanism, achieving dynamic adaptive communication scheduling.

[0067] 3) Deterministic polling sequence: The master station polls each slave station in a fixed order according to the dynamically maintained list of active nodes. PRC technology is used. After the master station sends a Preq to node N, node N immediately replies with a Pres. After receiving the Pres, the master station immediately sends the next Preq to node N+1, forming a strict time chain.

[0068] Redundant master station switching strategy: For the flight profile of reusable launch vehicles, the system is designed with a redundant master station switching mechanism: 1) The pre-launch process and the onboard computer during the ascent phase act as the master station management node (MN_primary), sending SoC frames to the entire network and scheduling the communication of each terminal slave node. The redundant master station node (MN_backup) works in slave mode. 2) After the inter-level separation, the redundant master station node (MN_backup, set in the inter-level segment) switches from slave mode to master mode and serves as the master station management node of the first-level return segment; 3) The handover process involves the redundant master station receiving an inter-level separation signal or detecting a bus silence timeout (no SoC frame received for 5 consecutive cycles) after receiving the inter-level separation signal. It then automatically initiates master station handover, switching from slave mode to master mode and beginning to send SoC frames to the primary network, thus reconstructing the communication scheduling of the primary network in the return segment. The handover process is completed within 1ms, during which the terminal slave nodes remain in a waiting state.

[0069] Direction 3: Fixed communication cycle scheduling and variable length frame processing, fixed period time slot division: 1) The system adopts a fixed-cycle communication mode with a fixed communication cycle of 1ms. Each communication cycle is strictly divided into an isochronous synchronous domain (transmitting periodic real-time data such as control commands and telemetry data) and an asynchronous domain (transmitting non-periodic large data such as software uploads and fault log downloads).

[0070] 2) Within each cycle, the time windows of the isochronous synchronous domain and the asynchronous domain are strictly predefined and proceed in a fixed time sequence; each slave station is assigned a fixed time slot for replying to data, and the length of the time slot is pre-calculated and determined based on the amount of data at that station.

[0071] In addition, a variable-length frame optimization strategy is implemented: different frame lengths are configured for different message types to improve bus utilization. Control command messages have high real-time requirements and are configured with short frame lengths (64 bytes), while telemetry data packets and image data have large amounts of data and are configured with long frame lengths (1024 bytes).

[0072] Option 4: In a hybrid topology based on Powerlink networks, the system adopts a hybrid topology structure of "backbone bus + regional star". 1) Deployment of the master station management node: A master station management node is set up in the second stage of the rocket as the master station (MN) of the Powerlink bus, which is responsible for generating the system synchronization clock, scheduling the bus cycle, and maintaining the "active node list".

[0073] 2) Backbone Bus: A network repeater is deployed in each section of the rocket body, including the second-stage section, inter-stage section, and first-stage section. All network repeaters are connected in series with the master station management node via Powerlink interfaces, forming a Powerlink backbone bus that runs throughout the entire rocket. The backbone bus is responsible for high-speed data exchange and global clock synchronization across sections and regions.

[0074] 3) Regional Star Network: Within the second-level segment, network repeaters connect key terminal slave nodes such as controllers and servo systems in a star topology. Within the inter-level segment, network repeaters connect redundant onboard computers, controllers, and other terminal slave nodes in a star topology. Within the first-level tail segment, network repeaters connect key terminal slave nodes such as controllers and servo systems in a star topology. All terminal slave nodes access the system backbone bus via the network repeater of their respective segment, enabling communication with the onboard computer and nodes in other segments.

[0075] Direction 5: Hardware Configuration and Processing. On the master-slave node hardware platform, both the system's master management node and terminal slave nodes use Zynq 7000 series processors as the core processing unit, constructing a heterogeneous hardware platform. 1) PS (Processing System): Runs application software, including a real-time operating system, application layer processing of the Powerlink protocol stack, object dictionary management, Service Data Object (SDO) configuration, and data parsing applications. The PS is responsible for sending and receiving Powerlink application data and processing and parsing data.

[0076] 2) PL (Programmable Logic): Runs the Powerlink communication IP core, implementing the data link layer functions of the Powerlink communication protocol in hardware logic, including precise timing control, frame processing, cyclic redundancy check (CRC), and clock synchronization logic. The PL ensures microsecond-level communication determinism through hardware-level time-slice scheduling.

[0077] 3) Physical Layer Interface: A PHY chip is used to transmit and receive underlying Ethernet frames, supporting 100BASE-TX physical layer connections. The PHY chip is connected to the PL terminal via the MII / RMII interface, and connected to the network interface via an isolation transformer and a common-mode choke.

[0078] Furthermore, it features three redundant hardware channels: each of the three hardware channels is independently configured, with each channel containing an independent PHY chip, isolation transformer, common-mode choke, and shielded twisted-pair cable. During data transmission, the master station management node simultaneously sends the same data frame to the slave station through all three channels; during data reception, the slave station's three hardware channels receive data independently, and the arbitration unit processes the data received by the three hardware channels according to a customized arbitration strategy.

[0079] The technical solution of this invention focuses on protecting the following innovative aspects: 1) The engineering application of Powerlink bus in launch vehicles solves the problem of bandwidth limitation of traditional buses, and increases the communication rate to 100Mbps, a 100-fold increase; 2) The system uses a fixed-period communication mode to resolve communication conflicts and communication delay uncertainties in standard Ethernet. 3) Based on the Powerlink network architecture and deployment implementation described in this paper, a strategy of switching the redundant master station after the stage separation is adopted. After the stage separation of the rocket is reused, the original master station continues to perform the orbit insertion mission, and the redundant master station switches to the first-level master station to take over the first-level network communication management. The switching time is <1ms, covering the launch vehicle return operation. 4) The communication network architecture adopts a hybrid topology of "backbone bus + regional star topology", which simplifies the complexity of cross-cabin wiring of traditional bus and reduces the impact of single point failure on global communication; 5) Based on hardware platform innovation, the Zynq7000 heterogeneous platform realizes protocol stack hard core (the application layer runs on the PS side + the Powerlink IP core runs on the PL side), hardware-level timing control, reduced CPU load, and significantly improved determinism; 6) By adopting a comprehensive optimization strategy of variable-length frames, multiple application cycles, and time slot isolation, the bus utilization rate is improved by 15%~20%, balancing real-time performance and flexibility.

[0080] It should be noted that the present invention has the following advantages over the prior art: 1) High reliability: Through a triple-redundant communication mechanism (three independent hardware channels and a triple-redundant arbitration strategy) and a hybrid topology, it ensures that a single point of failure does not affect the communication of the entire rocket, nor does it affect the normal communication of other nodes in this section and the main bus, thus meeting the rocket's fault tolerance requirements; 2) High bandwidth real-time performance: Powerlink communication speed can reach 100Mbps, which is 100 times higher than the bandwidth rate of traditional bus, meeting the high bandwidth data transmission requirements of high-definition images, high-frequency vibration and multi-channel servo. 3) High determinism: Employing a master-slave communication mode, the master station has exclusive scheduling rights, ensuring that only one node transmits data across the entire network at any given time, eliminating bus conflicts. Combined with a fixed 1ms period and fixed time slots, the transmission timing and transmission window length of each node are strictly predefined, providing the system with a stable sampling and control cycle. 4) Flexibility and scalability: The standard Ethernet frame structure and Powerlink protocol facilitate the access of various standard-compliant devices, and the star subnet facilitates the addition or removal of devices within the module without modifying the backbone bus structure, which is conducive to the modular design and assembly of the launch vehicle. 5) Supports reusability: Through a redundant master station dynamic switching mechanism, the smooth migration of the communication master station after interstage separation is realized, ensuring the independent operation of the first-stage return segment communication network and providing reliable communication support for the recovery of launch vehicle substages; 6) Optimize cabling and reduce weight: By using a hybrid topology of "backbone bus + regional star", the weight of the entire Arrow cable network is reduced by 20%~30%; 7) High resource utilization: Through variable frame length optimization strategy (64B~1024B dynamic configuration) and PRC polling request chain technology, network utilization is improved by 15%~20%.

[0081] Further improvements and modifications to the above technical solutions are also within the scope of protection of this invention, such as, but not limited to: 1. System topology changes, including: In addition to the "backbone bus + regional star" topology, the system network can also be modified according to the rocket body structure layout in practical engineering applications, such as: ring backbone topology, double ring backbone topology, tree backbone topology, daisy chain topology and other topologies.

[0082] 2. The evolution and variations of redundancy mechanisms, including: 1) A variant with triple redundancy: This embodiment of the invention employs three hardware channels for a two-out-of-three voting process. Depending on different reliability levels and cost constraints, the following variations are possible: ① Dual redundancy degradation: For non-critical subsystems (such as telemetry acquisition), dual redundant channels + two-out-of-one voting can be used to reduce hardware costs.

[0083] ② Five-redundancy expansion: For critical systems with extremely high reliability requirements (such as escape command transmission), it can be expanded to five channels + two out of three or three out of five voting to further improve fault tolerance.

[0084] ③ Heterogeneous redundancy: The three channels can use different physical media (such as shielded twisted pair for channel A, fiber optic for channel B, and wireless for channel C) to resist common cause failures in different fault modes.

[0085] ④ Dynamic redundancy: Under normal circumstances, all three channels work simultaneously; when the performance of a certain channel deteriorates (such as an increase in the bit error rate) rather than a complete failure, the system dynamically adjusts the arbitration weight of that channel instead of directly blocking it.

[0086] 2) Variations of the arbitration algorithm: The two-out-of-three arbitration algorithm can be modified as follows depending on the application scenario: ① Weighted arbitration: Different weights are assigned to different channels (e.g., the main channel has a high weight and the backup channel has a low weight). When the results of the three channels are inconsistent, the result of the channel with the higher weight is given priority.

[0087] ② Historical Arbitration: Arbitration is conducted based on the channel's historical reliability record. Channels with higher historical reliability enjoy higher priority in arbitration.

[0088] ③ Adaptive Arbitration: The arbitration strategy is dynamically adjusted based on the data type. For example, control commands use a strict 3-out-of-2 approach, while telemetry data can use a 3-out-of-2 approach with fault tolerance (allowing single-channel data deviation).

[0089] ④ Time Arbitration: Consider the timestamp of the data and give priority to the channel data with the latest timestamp to avoid data inconsistency caused by differences in channel delay.

[0090] 3. The evolution and transformation of hardware platforms, including: 1) Processor platform variations: This embodiment of the invention uses the Zynq 7000 series processor, which can be modified as follows according to performance requirements and supply chain conditions: ① Upgrade to a higher performance series processor: For scenarios requiring higher performance (such as processing higher rate image data), it provides stronger PS-side processing capabilities and PL-side logic resources.

[0091] ② Discrete solution: For cost-sensitive scenarios, a discrete solution of independent CPU + independent FPGA can be adopted (such as ARM Cortex-A series CPU + Spartan series FPGA), which has the same function but lower cost.

[0092] ③ Domestic substitution: For the aerospace industry's need for independent control, domestic FPGAs and processors can be used as substitutes to achieve a fully domestic solution.

[0093] 2) Deformation of the physical layer: ①Speed ​​Upgrade: Upgrade from 100BASE-TX (100Mbps) to 1000BASE-T (1Gbps) or 10GBASE-R (10Gbps) to meet higher bandwidth requirements.

[0094] ② Diverse media: In addition to shielded twisted pair, fiber optic (strong anti-interference ability, light weight), coaxial cable (good vibration resistance) or wireless (suitable for detachable components) can be selected.

[0095] 4. Evolution and variations of deployment strategies, including: variations in the main station deployment location. In this embodiment of the invention, the main station management node is deployed in the second stage. Depending on the rocket configuration, the following variations can be made: ① First stage deployment: For rockets with a configuration of one and a half stages (such as boosters + core stage), the main station can be deployed on the core stage.

[0096] ② Upper stage deployment: For rockets with an upper stage, the master station can be deployed on the upper stage, and continue to manage the communication of the payload segment after the upper stage separates.

[0097] ③ Distributed master station: For super-large rockets, multiple master stations can be set up (such as primary master station and secondary master station), and cross-regional communication management can be achieved through the coordination mechanism between master stations.

[0098] ④ Ground Master Station: During the ground testing phase before launch, the ground testing system can temporarily serve as the master station, and the onboard nodes can serve as slave stations, to achieve joint ground-onboard testing.

[0099] 5. Expanding application scenarios to other spacecraft and other fields: The core architecture of this invention is not only applicable to launch vehicles, but can also be extended to other spacecraft, such as manned spacecraft, space stations, satellites, and deep space probes, and can also be extended to other fields such as aviation, shipbuilding, rail transportation, and industrial automation.

[0100] Those skilled in the art will understand that all or part of the steps of the methods described above can be implemented by a program instructing related hardware. The program can be stored in a readable storage medium, and when executed, the program includes one or a combination of the steps of the method implementation.

[0101] In the various embodiments of this application, the functional units can be integrated into a single processing module, or each unit can exist physically separately, or two or more units can be integrated into a single module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a readable storage medium. The storage medium can be a read-only memory, a disk, or an optical disk, etc.

[0102] In the description of this specification, the references to terms such as "one embodiment / mode," "some embodiments / modes," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment / mode or example is included in at least one embodiment / mode or example of this application. Furthermore, the described specific features, structures, materials, or characteristics may be combined in any suitable manner in one or more embodiments / modes or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments / modes or examples described in this specification, as well as the features of different embodiments / modes or examples.

[0103] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0104] Those skilled in the art should understand that the above embodiments are merely for illustrative purposes and are not intended to limit the scope of this application. Those skilled in the art can make other changes or modifications based on the above disclosure, and these changes or modifications still fall within the scope of this application.

Claims

1. A launch vehicle communication network system based on Powerlink, characterized in that, This includes the second-stage star network, the interstage star network, the first-stage tail star network of the launch vehicle, and the backbone bus using a through-type Powerlink bus; The secondary segment star network includes a master station management node, several terminal slave nodes within the secondary segment, a network repeater within the secondary segment, and a Powerlink interface for the secondary segment. The several terminal slave nodes within the secondary segment are connected to the network repeater within the secondary segment via a Powerlink communication link in a star topology. The master station management node and the network repeater within the secondary segment are connected in series to the backbone bus through the Powerlink interface for the secondary segment. The inter-level segment star network includes redundant master nodes, several terminal slave nodes within the inter-level segment, network repeaters within the inter-level segment, and an inter-level segment Powerlink interface. The several terminal slave nodes within the inter-level segment are connected to the network repeaters within the inter-level segment via Powerlink communication links in a star topology. The redundant master nodes and the network repeaters within the inter-level segment are connected in series to the backbone bus through the inter-level segment Powerlink interface. The first-level tail segment star network includes several terminal slave nodes within the first-level tail segment, a network repeater within the first-level tail segment, and a first-level tail segment Powerlink interface; the several terminal slave nodes within the first-level tail segment are connected to the network repeater within the first-level tail segment via a Powerlink communication link in a star topology, and the network repeater within the first-level tail segment is connected to the backbone bus through the first-level tail segment Powerlink interface; Both the Powerlink bus and the Powerlink communication link adopt three independent Powerlink hardware channels. The master station management node, the redundant master station node, and the terminal slave station node are all equipped with arbitration units to perform triple redundancy arbitration on the input and output data of the three independent Powerlink hardware channels.

2. The system according to claim 1, characterized in that, Each of the three independent Powerlink hardware channels includes an independent PHY chip, isolation transformer, common mode choke, and shielded twisted pair cable for physical transmission medium. The triple redundancy arbitration for input and output data of the three independent Powerlink hardware channels includes: When data is input to the three independent Powerlink hardware channels, the master station management node simultaneously sends the same data frame to the terminal slave node through the three independent Powerlink hardware channels. When outputting data to the three independent Powerlink hardware channels, the three independent Powerlink hardware channels of the terminal slave node receive the data independently, and the arbitration unit performs a two-out-of-three voting process on the data received by the three independent Powerlink hardware channels based on a preset three-redundancy arbitration strategy.

3. The system according to claim 2, characterized in that, Both the master station management node and the terminal slave node include a heterogeneous hardware platform and a physical layer interface; the heterogeneous hardware platform includes a processing system PS terminal and an editable logic PL terminal; The processing system PS terminal is used to run application software; the application software includes a real-time operating system, application layer processing of the Powerlink protocol stack, object dictionary management, service data object (SDO) configuration, and data parsing application. The programmable logic (PL) terminal is used to run the Powerlink communication IP core and implement the data link layer function of the Powerlink communication protocol in hardware logic. The data link layer function includes precise timing control, frame processing, cyclic redundancy check (CRC) and clock synchronization logic. The physical layer interface is used to transmit and receive underlying Ethernet data frames through the PHY chip to support physical layer connections; wherein, the PHY chip is connected to the programmable logic (PL) terminal through the MII / RMII interface, and is also connected to the Powerlink interface through the isolation transformer and the common mode choke.

4. The system according to claim 2, characterized in that, The arbitration unit performs a two-out-of-three voting process on the data received from the three independent Powerlink hardware channels based on a preset triple-redundancy arbitration strategy, including: The arbitration unit is equipped with a data receiving program independent of the main program. The data receiving program monitors and receives three redundancy data. After receiving the first redundancy data, the timing starts. If three redundancy data are received, the current cycle of receiving is stopped and the main program is reported. If the data receiving time exceeds a preset cycle, the receiving is stopped and the received data is reported. The main program performs an integrity check on the reported data: if the reported data consists of three redundant data points received periodically and is complete, then the three redundant data points are cleaned to obtain cleaned data; otherwise, the reported data is discarded and the data is re-received through the data receiving program. The main program determines the number of valid data sets in the cleaned data: if the number of valid data sets is greater than or equal to 2, the cleaned data is averaged and a functional model is applied before outputting two out of three data sets; otherwise, the cleaned data is cleared and the data is re-received through the data receiving program.

5. The system according to claim 4, characterized in that, The data cleaning of the three redundancy data includes: The three redundancy data are judged to be in the same frame based on the frame number or time stamp, so as to clear the data in different frames and obtain the data in the same frame. The validity of the same-shot data is verified to remove the data that failed the verification and obtain the data that succeeded in the verification. The successfully verified data are subjected to correlation difference verification, and data whose absolute value of correlation difference meets the preset correlation difference threshold range are retained; If the three redundancy data are status command data, then a consistency comparison is performed, and consistent status command data is retained.

6. The system according to claim 1, characterized in that, The master station management node exclusively controls the unified scheduling of the entire network communication and sends polling request frames to the entire network using a fixed-period scheduling mode. After receiving the polling request frame sent by the master station management node, each of the terminal slave nodes replies with a polling response frame within a predetermined time window.

7. The system according to claim 6, characterized in that, The fixed-cycle scheduling mode has a fixed communication cycle duration of 1ms. Each communication cycle is divided into an isochronous synchronous domain and an asynchronous domain, and the isochronous synchronous domain and the asynchronous domain are isolated from each other in time. The isochronous synchronous domain transmits periodic real-time data, and the asynchronous domain transmits non-periodic data.

8. The system according to claim 7, characterized in that, The process for transmitting periodic real-time data in the isochronous synchronization domain is as follows: The master station management node sends an IdentRequest frame to the entire network, and each of the terminal slave nodes responds with an IdentResponse frame. The main station management node automatically establishes and dynamically maintains a list of active nodes based on the IdentResponse frame response. In the isochronous synchronization domain of each communication cycle, the master station management node sends polling request frames to each of the terminal slave nodes in sequence according to the active node list, and each of the terminal slave nodes replies with a polling response frame by allocating a fixed time slot; wherein, the length of the time slot is pre-calculated based on the amount of data of each of the terminal slave nodes.

9. The system according to claim 1, characterized in that, The redundant master station nodes employ the following switching strategy based on the launch vehicle's flight profile: During the pre-launch preparation and first-stage ascent phase of the launch vehicle, when the master station management node sends the period start SoC frame to the entire network, it schedules the communication of each terminal slave node and sets the redundant master station node to work in slave mode. After the stage separation of the launch vehicle, the redundant master station node switches from slave mode to master mode to serve as the master station management node for the first stage return segment.

10. The system according to claim 9, characterized in that, The workflow for the redundant master station node to switch from slave mode to master mode, serving as the master station management node for the first-level return segment, includes: When the redundant master node receives an inter-stage separation signal or detects that the Powerlink bus has not received a SoC frame for a duration longer than a preset continuous period, it automatically initiates a switching process to switch the redundant master node from slave mode to master mode and become the master management node of the first-level return segment. After the switchover is completed, the redundant master node begins to send periodic start SoC frames to the primary return segment network to rebuild the communication scheduling of the primary return segment network in order to manage several terminal slave nodes in the primary tail segment. The switching process is completed within 1ms, and during the switching period, several terminal slave nodes in the first-level tail segment remain in a waiting state.