An electric rudder

CN122837327APending Publication Date: 2026-09-29SHANG HAI SHEN TUO ZHI ZAO ZHUANG BEI YOU XIAN GONG SI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611068722.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-17
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0004]然而,上述现有方案在实际应用中仍存在以下不足

Benefits of technology

第一,通过设置包含三种不同通信协议的第一通信接口、第二通信接口和第三通信接口,从物理层和协议层上避免了因单一协议栈共性缺陷导致的共因故障,提高了通信可靠性和抗干扰能力;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122837327A_ABST
    Figure CN122837327A_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of steering engines, and discloses an electric steering engine, which comprises a driving module, a reduction module detachably mounted on the top of the driving module, and a control module detachably mounted on the bottom of the driving module. The control module comprises a heterogeneous redundant communication interface module, and the controller is internally provided with a communication arbitration unit, an identification judgment unit and a redundant identification storage module. The redundant identification storage module comprises three first ID storage units, a second ID storage unit and a third ID storage unit, which are different in physical address and store the same unique communication ID data of the steering engine. The communication arbitration unit detects the communication quality state of each interface in real time, determines the current effective communication interface according to the preset priority, and controls the driving module to operate accordingly. The electric steering engine realizes the in-depth defense of the communication link layer, the information management layer and the physical structure layer through the three-mode heterogeneous redundant communication, the triple-redundant ID storage and the majority voting, and the three-layer modular structure, thereby improving the reliability and the maintenance convenience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of servo motor technology, and in particular to an electric servo motor. Background Technology

[0002] Servo systems are key actuators in servo control systems, widely used in aerospace, underwater vehicles, drones, and robotics. Their core function is to receive rudder deflection commands from a host computer, overcome load torque to drive the control surfaces to deflect at a specified angle, thereby achieving attitude stability and control of the equipment. With the increasing demands for reliability and safety in these fields, the fault tolerance of servo systems in complex electromagnetic environments and harsh operating conditions has become a crucial factor determining mission success or failure.

[0003] Currently, to improve the reliability of servo systems, the following solutions are mainly adopted in existing technologies. One typical solution is to use an electrically dual-redundant servo control system, which communicates between the two servos via a CAN bus. When one redundancy channel fails, it switches to the other redundancy channel to continue operation. Another solution is a dual-redundant electric servo control system, including a primary redundancy, a secondary redundancy, an MCU, and a dual-redundant motor. When a fault is detected in the primary redundancy or the motor, control switches from the primary redundancy to the secondary redundancy. A further solution is a scalable distributed multi-redundant electric servo servo drive method, which uses multiple servo drivers to perform redundancy drive control based on fault information and servo driver status.

[0004] However, the existing solutions mentioned above still have the following shortcomings in practical applications.

[0005] First, most existing redundancy solutions use the same communication protocol to form dual redundant channels, such as both channels being CAN bus interfaces. While this architecture can solve hardware-level failures of a single channel, it carries the risk of both redundant channels failing simultaneously when faced with common-cause failures caused by strong electromagnetic interference, differences in device compatibility, or defects in the bus protocol layer. This indicates a significant weakness in the system's ability to withstand common-cause failures.

[0006] Second, existing fault-switching mechanisms typically rely solely on a simple binary judgment based on the current connectivity status of the communication link, lacking continuous assessment of communication quality and autonomous recovery capabilities. When the main channel experiences a brief interruption due to transient interference rather than a permanent fault, the system often performs an irreversible degradation switch, causing the servo motor to operate in a suboptimal communication state for an extended period. This prevents it from autonomously switching back after the main channel returns to normal, resulting in unnecessary losses in system performance and reliability.

[0007] Third, the device identifier of a servo motor is a crucial parameter in the control system used to distinguish between different servos and ensure correct command routing. Existing servos typically store their identifiers in a single Flash memory area of ​​the microcontroller. When the system is powered on unstable, experiences abnormal voltage fluctuations, or when the Flash memory cells age and cause bit flips, the identifier data is highly susceptible to errors in reading or abnormal tampering. This can lead to identifier conflicts between different servos, causing chaotic control command routing and seriously threatening system security. Current bus-based dynamic identifier allocation schemes focus on the initial allocation and conflict correction of identifiers, without addressing redundant verification of the correctness of stored identifier data or fault-tolerant recovery mechanisms. Therefore, they cannot effectively address data corruption caused by physical failure of the storage medium itself.

[0008] Fourth, in existing redundant communication schemes, when heterogeneous communication interfaces are used to form redundancy, if the third link uses pure physical layer signals such as PWM that do not have a frame structure, the existing technology lacks a link quality assessment method for such frameless interfaces and a mechanism for unified arbitration with frame-based digital bus interfaces, and cannot realize dynamic weight arbitration and link self-healing management in heterogeneous three-link scenarios.

[0009] Fifth, existing servo systems typically employ an integrated design, with the drive motor, reduction gear, and control circuitry all housed within the same casing. While this structure is compact, field maintenance and fault replacement often require complete disassembly of the servo system. This makes it difficult to quickly replace individual functional modules, resulting in insufficient maintainability and supportability. Consequently, it fails to meet the demands of large-scale, mass-produced equipment for rapid battlefield repairs and reduced life-cycle maintenance costs.

[0010] Therefore, an electric servo motor is proposed. Summary of the Invention

[0011] The purpose of this invention is to overcome the above-mentioned defects of the prior art and provide an electric servo motor. This electric servo motor has a three-mode heterogeneous redundant communication architecture, an autonomous arbitration and link self-healing management mechanism based on real-time communication quality detection, a high-reliability management mechanism for device identification based on multiple redundant storage and majority voting, and a three-layer modular detachable structure. It can achieve in-depth defense against multiple fault modes at the communication link layer, information management layer and physical structure layer, significantly improving the overall reliability and maintenance convenience of the servo motor system.

[0012] To achieve the above objectives, the present invention adopts the following technical solution.

[0013] An electric servo motor includes a drive module, a reduction gear module detachably mounted on the top of the drive module, and a control module detachably mounted on the bottom of the drive module. The control module includes a circuit board and a heterogeneous redundant communication interface module. The heterogeneous redundant communication interface module is used to receive servo deflection commands from an external source. The heterogeneous redundant communication interface module includes a first communication interface, a second communication interface, and a third communication interface, each with a different communication protocol. A controller is integrated on the circuit board, and the heterogeneous redundant communication interface module is electrically connected to the controller. The controller includes a communication arbitration unit, an identification decision unit, and a redundant identification storage module. The communication arbitration unit is used to detect each communication interface in real time. The system determines the communication quality status of the communication interface and selects a currently valid communication interface from the heterogeneous redundant communication interface modules according to a preset communication priority order. The data transmitted through this communication interface is used as the command to control the operation of the drive module. The redundant identifier storage module includes three physical address-different first ID storage units, second ID storage units, and third ID storage units. The first ID storage unit, second ID storage unit, and third ID storage unit are all used to store the unique communication ID data of the servo motor. The identifier decision unit is used to read data from the first ID storage unit, second ID storage unit, and third ID storage unit respectively during system initialization and determine the unique valid device identifier of the servo motor system by majority voting.

[0014] Furthermore, the first communication interface is a CAN bus interface, the second communication interface is an RS485 interface, and the third communication interface is a PWM signal interface. The preset communication priority order is: the first communication interface has a higher priority than the second communication interface, which in turn has a higher priority than the third communication interface.

[0015] Furthermore, the communication arbitration unit includes a communication quality monitoring subunit and a degradation switching control subunit. The communication quality monitoring subunit is used to verify the data frames received by the current interface, detect the reception interval of the verified data frames, and if it is detected that the current communication interface has not received the verified data frames after exceeding the first time threshold, it outputs a link fault indication signal. The degradation switching control subunit is used to receive the link fault indication signal transmitted by the communication quality monitoring subunit and determine the next priority communication interface as the current valid communication interface according to the preset communication priority order.

[0016] Furthermore, the communication arbitration unit also includes a background monitoring subunit and a link recovery subunit. The background monitoring subunit is used to determine the priority of the currently valid communication interface. If the priority of the current communication interface is not the highest priority communication interface, it continues to receive and verify data frames for all communication interfaces with higher priority than the current communication interface. If any higher priority communication interface is detected to have received a preset first number of valid data frames with consecutive frame counts and passing verification, it outputs a link recovery indication signal. The link recovery subunit is used to receive the link recovery indication signal output by the background monitoring subunit and determine the higher priority communication interface as the currently valid communication interface.

[0017] Furthermore, when the currently valid communication interface is the third communication interface, i.e. the PWM signal interface, the background monitoring subunit only receives and verifies data frames for the first and second communication interfaces, and does not perform the judgment of continuous frame counting and qualified verification for the third communication interface itself; the third communication interface serves as a pure physical layer backup channel and does not participate in the link self-healing back-off.

[0018] Furthermore, the identification decision unit includes a data reading subunit and a comparison voting subunit. The data reading subunit is used to simultaneously read three sets of servo unique communication ID data from the first ID storage unit, the second ID storage unit, and the third ID storage unit during system initialization. The comparison voting subunit is used to compare these three sets of servo unique communication ID data pairwise. If at least two sets of servo unique communication ID data have the same content, then the matching servo unique communication ID data is determined as the unique valid device identifier of the servo system. Otherwise, the controller does not respond to any bus commands with device identifiers.

[0019] Furthermore, the controller is also equipped with an identifier writing control unit. When the identifier writing control unit receives an externally sent device identifier writing command, it writes the same set of unique communication ID data of the servo motor to be written into the first ID storage unit, the second ID storage unit, and the third ID storage unit in whole frame form according to a preset time interval.

[0020] Furthermore, the control module also includes a third housing, the heterogeneous redundant communication interface module is fixedly embedded on one side of the third housing, the controller is fixedly installed inside the third housing, the bottom of the third housing is open, a second cover plate is detachably installed on the bottom of the third housing, a terminal female assembly is fixedly embedded on the bottom of the second cover plate, and the terminal female assembly is electrically connected to the controller.

[0021] Furthermore, the drive module includes a drive motor, a position sensor, a male terminal assembly, and a first housing. A first mounting base and a second mounting base are fixedly connected to the upper interior of the first housing. The drive motor is fixedly mounted on the first mounting base. A first splined shaft is fixedly connected to the drive motor's rotating shaft. A shaft of a second splined shaft is rotatably mounted on the second mounting base. The lower end of the second splined shaft passes through the bottom of the second mounting base. A third mounting base is fixedly connected to the bottom of the first housing. The male terminal assembly is fixedly embedded in the third mounting base. The detection element of the position sensor is fixedly mounted on the lower end of the shaft. The position sensor is fixed to the bottom of the second mounting base. The electrical control terminal of the drive motor and the position sensor are both electrically connected to the male terminal assembly. After the control module is installed at the bottom of the drive module, the female terminal assembly is electrically connected to the male terminal assembly.

[0022] Furthermore, the reduction module includes a second housing with an open bottom. A first cover plate is detachably mounted on the bottom of the second housing. An input shaft, a first transmission shaft, a second transmission shaft, a third transmission shaft, and an output shaft are rotatably mounted inside the second housing. An input gear is fixedly mounted on the input shaft, and a first spline groove is formed at the bottom of the input gear. A first-stage reduction gear set is fixedly mounted on the first transmission shaft, a second-stage reduction gear set is fixedly mounted on the second transmission shaft, a third-stage reduction gear set is fixedly mounted on the third transmission shaft, and a fourth-stage reduction gear is fixedly mounted on the output shaft. The input gear meshes with the first-stage reduction gear set. The first-stage reduction gear set meshes with the second-stage reduction gear set, the second-stage reduction gear set meshes with the third-stage reduction gear set, and the third-stage reduction gear set meshes with the fourth-stage reduction gear set. The upper end of the output shaft rotates through the top of the second housing and is fixedly mounted with a connecting gear. The bottom of the output shaft has a second spline groove. The bottom of the first cover plate has a first through hole and a second through hole for the first spline shaft and the second spline shaft to pass through. After the second housing is installed on the top of the first housing, the first spline shaft can be inserted into the first spline groove that matches it, and the second spline shaft can be inserted into the second spline groove that matches it.

[0023] Furthermore, the top and bottom of the first housing are both open, and the four corners of the inner wall of the first housing are provided with first threaded holes. The third housing is installed on the first housing by a first screw. The stud of the first screw passes through the third housing and is threaded inside the first threaded hole at the end away from the second housing. The second housing is installed on the first housing by a second screw. The stud of the second screw passes through the second housing and is threaded inside the first threaded hole at the end away from the third housing.

[0024] Furthermore, sealing grooves are provided at the top and bottom of the first housing, and sealing rings are provided in the sealing grooves.

[0025] Furthermore, both the outer wall of the third housing and the outer wall of the second housing are fixedly connected with mounting ears.

[0026] Furthermore, the outer wall of the first housing is provided with a plurality of heat dissipation grooves at equal intervals from top to bottom.

[0027] The electric servo motor provided by this invention has the following beneficial effects: First, by setting up a first communication interface, a second communication interface, and a third communication interface that include three different communication protocols, common faults caused by common defects in a single protocol stack are avoided from the physical layer and the protocol layer, thereby improving communication reliability and anti-interference capability. Second, through the communication quality monitoring subunit and degradation switching control subunit built into the communication arbitration unit, automatic and seamless degradation switching based on real-time communication quality detection is realized, ensuring the continuity of control. Third, through the background monitoring subunit and the link recovery subunit, the intelligent self-healing and recovery function of the link is realized, avoiding the system from staying in a suboptimal communication state for a long time. Fourth, by using the three physically independent ID storage units (first ID storage unit, second ID storage unit, and third ID storage unit) in the redundant identifier storage module, combined with the majority voting mechanism of the identifier decision unit, data errors caused by physical failure of storage units are effectively prevented. Fifth, through a three-layer modular detachable stacking structure, combined with spline plug-in and terminal plug-in connection design, the independent disassembly and replacement of each module is realized, improving maintainability and reliability; Sixth, considering the frameless structure of the PWM signal interface as the third communication link, it is configured as a pure physical layer backup channel that does not participate in the calculation of Q and S factors in the dynamic weighting equation. The availability of the link is determined only by detecting the pulse width change and level amplitude of the PWM signal. This avoids the problem of insufficient disclosure of frame-related parameters due to the lack of frame structure in the PWM signal, while retaining the redundant function of PWM as the last hardware-level security guarantee. Attached Figure Description

[0028] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 This is a block diagram illustrating the control principle of the present invention; Figure 2 This is a schematic diagram of the controller of the present invention; Figure 3 This is a block diagram illustrating the principle of the communication arbitration unit of the present invention. Figure 4 This is a block diagram illustrating the principle of the identification and decision unit of this invention; Figure 5 This is a schematic diagram of the heterogeneous redundant communication interface module of the present invention. Figure 6 This is a schematic diagram of the redundant identifier storage module of the present invention; Figure 7 This is a schematic diagram of the structure of the present invention; Figure 8 This is a structural schematic diagram from another perspective of the present invention; Figure 9 This is a schematic diagram of the exploded structure of the present invention; Figure 10 This is a cross-sectional structural diagram of the present invention; Figure 11 This is an exploded structural diagram of the control module of the present invention; Figure 12 This is a schematic diagram of the structure of the driving module of the present invention; Figure 13 This is a structural schematic diagram of the driving module of the present invention from another perspective; Figure 14 This is a schematic diagram of the deceleration module of the present invention.

[0029] Explanation of icon numbers: 1. Control Module; 101. Controller; 1011. Communication Arbitration Unit; 10111. Communication Quality Monitoring Subunit; 10112. Degradation Switching Control Subunit; 10113. Background Monitoring Subunit; 10114. Link Recovery Subunit; 1012. Identifier Decision Unit; 10121. Data Reading Subunit; 10122. Comparison Voting Subunit; 1013. Identifier Writing Control Unit; 1014. Redundant Identifier Storage Module; 10141. First ID Storage Unit; 10142. Second ID Storage Unit; 10143. Third ID Storage Unit; 102. Heterogeneous Redundant Communication Interface Module; 1021. First Communication Interface; 1022. Second Communication Interface; 1023. Third Communication Interface; 103. Terminal Header Group; 104. Third Housing; 1041. Second Cover Plate; 105. Circuit Board; 2. Drive module; 201. Drive motor; 2011. First splined shaft; 202. Position sensor; 203. Terminal male connector assembly; 204. First housing; 2041. First mounting base; 2042. Second mounting base; 2043. Third mounting base; 2044. First threaded hole; 205. Second splined shaft; 3. Reduction module; 301. Second housing; 302. Input shaft; 3021. Input gear; 3022. First spline groove; 303. First drive shaft; 3031. First stage reduction gear set; 304. Second drive shaft; 3041. Second stage reduction gear set; 305. Third drive shaft; 3051. Third stage reduction gear set; 306. Output shaft; 3061. Fourth stage reduction gear; 3062. Second spline groove; 3063. Connecting gear; 307. First cover plate; 3071. First through hole; 3072. Second through hole; 4. Install ear; 5. Sealing ring; 6. First screw; 7. Second screw. Detailed Implementation

[0030] The following will describe in detail the implementation of this application with reference to the accompanying drawings and embodiments, so that the implementation process of how this application uses technical means to solve technical problems and achieve technical effects can be fully understood and implemented accordingly.

[0031] Please refer to Figures 1 to 14 As shown, this embodiment provides an electric servo motor, including a drive module 2. A reduction module 3 is detachably mounted on the top of the drive module 2, and a control module 1 is detachably mounted on the bottom of the drive module 2. The control module 1 includes a circuit board 105 and a heterogeneous redundant communication interface module 102. The heterogeneous redundant communication interface module 102 is used to receive servo deflection commands from the outside. The heterogeneous redundant communication interface module 102 includes a first communication interface 1021, a second communication interface 1022, and a third communication interface 1023. The communication protocols between the first communication interface 1021, the second communication interface 1022, and the third communication interface 1023 are different. The circuit board 105 integrates a controller 101, and the heterogeneous redundant communication interface module 102 is electrically connected to the controller 101. The controller 101 is equipped with a communication arbitration unit 1011, an identification decision unit 1012, and a redundant identification storage module 1014. The communication arbitration unit 1011 is used to detect the communication quality status of each communication interface in real time, and determine a currently valid communication interface from the heterogeneous redundant communication interface module 102 according to the preset communication priority order, and use the data transmitted by the communication interface as the instruction to control the operation of the drive module 2. The redundant identifier storage module 1014 includes three physical addresses: a first ID storage unit 10141, a second ID storage unit 10142, and a third ID storage unit 10143. The first ID storage unit 10141, the second ID storage unit 10142, and the third ID storage unit 10143 are all used to store the unique communication ID data of the servo motor. The identification decision unit 1012 is used to read data from the first ID storage unit 10141, the second ID storage unit 10142 and the third ID storage unit 10143 respectively during system initialization, and determine the unique and valid device identifier of the servo system by majority voting.

[0032] By adopting the above technical solution, the deceleration module 3 is detachably installed on the top of the drive module 2, and the control module 1 is detachably installed on the bottom of the drive module 2, forming a three-layer modular stacked structure. The heterogeneous redundant communication interface module 102 in the control module 1 receives rudder deflection commands from the outside through the first communication interface 1021, the second communication interface 1022, and the third communication interface 1023, respectively. Since the communication protocols of the three communication interfaces are different, common-cause failures caused by defects in a single protocol stack are avoided at the physical and protocol layers. The heterogeneous redundant communication interface module 102 transmits the received rudder deflection commands to the controller 101. The communication arbitration unit 1011 in the controller 101 monitors the communication quality status of each communication interface in real time, determines a currently valid communication interface from the heterogeneous redundant communication interface module 102 according to the preset communication priority order, and uses the data transmitted by the communication interface as the command to control the operation of the drive module 2. The first ID storage unit 10141, the second ID storage unit 10142, and the third ID storage unit 10143 in the redundant identifier storage module 1014 are located in three storage areas with different physical addresses, and each stores the same unique communication ID data for the servo motor. During system initialization, the identifier decision unit 1012 reads data from the first ID storage unit 10141, the second ID storage unit 10142, and the third ID storage unit 10143 respectively, and uses a majority voting method to determine the unique and valid device identifier of the servo motor system. When at least two of the three data sets are consistent, the identifier with the majority consistency is used; when the three data sets are inconsistent pairwise, the identifier is set to an invalid state.

[0033] In this embodiment, the controller 101 uses a microcontroller chip, and its on-chip Flash memory is divided into three non-overlapping storage blocks, which serve as the first ID storage unit 10141, the second ID storage unit 10142, and the third ID storage unit 10143, respectively. The address spacing between the three storage blocks is not less than the size of one erase sector of the Flash memory, effectively preventing simultaneous damage to adjacent storage units due to a single voltage anomaly. The on-chip Flash memory of the controller 101 is pre-programmed with the factory default identifier 0xFF. Before the formal ID programming is completed, the servo system does not respond to any bus commands with device identifiers.

[0034] In this embodiment, the first communication interface 1021 is a CAN bus interface, the second communication interface 1022 is an RS485 interface, and the third communication interface 1023 is a PWM signal interface. The preset communication priority order is: the priority of the first communication interface 1021 is greater than the priority of the second communication interface 1022, which is greater than the priority of the third communication interface 1023.

[0035] By adopting the above technical solution, the heterogeneous redundant communication interface module 102 integrates three physical interfaces using different communication protocols: a CAN bus interface, an RS485 interface, and a PWM signal interface. The CAN bus interface features differential signal transmission and a hardware arbitration retransmission mechanism; the RS485 interface features differential balanced transmission and long-distance anti-interference capability; and the PWM signal interface is a direct level signal control method independent of the communication protocol stack. These three interfaces achieve full coverage from complex protocol buses to simple physical signals. The preset communication priority order provides a clear arbitration benchmark for the communication arbitration unit 1011: the CAN bus interface has the highest priority, followed by the RS485 interface, and the PWM signal interface has the lowest priority. The system defaults to prioritizing the CAN bus interface, which has the best communication performance, for data interaction.

[0036] The PWM signal interface is configured to respond directly to incoming PWM signals without distinguishing between device identifiers. The duration of the high level of the PWM signal represents the servo deflection angle command value, with 1.5ms representing 0 degrees and 1µs representing 0.1 degrees. In extreme cases where both the CAN bus interface and RS485 interface fail simultaneously and cannot be recovered, the host computer can still directly control the servo deflection via the PWM signal interface as a last-line hardware-level safety guarantee.

[0037] In this embodiment, the communication arbitration unit 1011 includes a communication quality monitoring subunit 10111 and a downgrade switching control subunit 10112. The communication quality monitoring subunit 10111 is used to verify the data frames received by the current interface, detect the reception interval of the data frames that pass the verification, and output a link fault indication signal if it is detected that the current communication interface has not received the data frames that pass the verification after exceeding the first time threshold. The downgrade switching control subunit 10112 is used to receive the link fault indication signal transmitted by the communication quality monitoring subunit 10111, and determine the next priority communication interface as the current valid communication interface according to the preset communication priority order.

[0038] When the currently valid communication interface is the third communication interface 1023, i.e. the PWM signal interface, the background monitoring subunit 10113 only receives and verifies data frames for the first communication interface 1021 and the second communication interface 1022, and does not perform the judgment of continuous frame counting and qualified verification for the third communication interface 1023 itself; the third communication interface 1023 serves as a pure physical layer backup channel and does not participate in the link self-healing back-off.

[0039] By adopting the above technical solution, the communication quality monitoring subunit 10111 continuously performs integrity verification on the data frames received by the currently valid communication interface and monitors the reception interval between qualified data frames. When the communication quality monitoring subunit 10111 detects that the current communication interface has not received a qualified data frame after exceeding a first time threshold, it determines that the communication link has failed and outputs a link fault indication signal. After receiving the link fault indication signal, the degradation switching control subunit 10112 automatically switches the next priority communication interface to the currently valid communication interface according to the preset communication priority order, realizing seamless degradation switching and ensuring that the servo system can continue to work when the main communication link is interrupted.

[0040] In this embodiment, the first duration threshold is set to 250ms. When the CAN bus interface is the currently valid communication interface, the communication quality monitoring subunit 10111 continuously verifies the CAN data frames. If no valid CAN data frames are received within 250ms, the degradation switching control subunit 10112 automatically switches the RS485 interface to the currently valid communication interface. Similarly, if the RS485 interface does not receive valid data frames for 250ms, it is further degraded to the PWM signal interface.

[0041] In this embodiment, the communication arbitration unit 1011 further includes a background monitoring subunit 10113 and a link recovery subunit 10114. The background monitoring subunit 10113 is used to determine the priority of the current valid communication interface. If the priority of the current communication interface is not the highest priority communication interface, it continues to receive and verify data frames for all communication interfaces with higher priority than the current priority communication interface. If it is detected that any higher priority communication interface has continuously received a preset first number of valid data frames with continuous frame count and qualified verification, it outputs a link recovery indication signal. The link recovery subunit 10114 is used to receive a link recovery indication signal output by the background monitoring subunit 10113 and determine the higher priority communication interface as the current valid communication interface.

[0042] By adopting the above technical solution, during the operation of the servo system using a lower-priority communication interface after degradation, the background monitoring subunit 10113 first determines whether the currently valid communication interface is the highest priority interface. If not, it continuously monitors all communication interfaces with higher priority, receiving and verifying the data frames of these interfaces. When the background monitoring subunit 10113 detects that any higher-priority communication interface has continuously received a preset first number of valid data frames with continuous frame counts and passing verification, it determines that the communication quality of the higher-priority communication link has returned to normal and outputs a link recovery indication signal. After receiving the link recovery indication signal, the link recovery subunit 10114 autonomously switches the higher-priority communication interface to the currently valid communication interface, realizing the link self-healing function and restoring the system from the degradation state caused by transient interference to the optimal communication state.

[0043] For example, the preset first quantity is set to 25 frames. When the servo system is currently running on the downgraded RS485 interface, the background monitoring subunit 10113 continuously monitors the data reception status of the CAN bus interface. When the CAN bus interface continuously receives 25 valid data frames with a consecutive frame count and passing verification, the background monitoring subunit 10113 outputs a link recovery indication signal, and the link recovery subunit 10114 re-determines the CAN bus interface as the current valid communication interface, and the system automatically switches back to the highest priority CAN bus communication.

[0044] In this embodiment, the identification decision unit 1012 includes a data reading subunit 10121 and a comparison voting subunit 10122. The data reading subunit 10121 is used to read three sets of servo unique communication ID data from the first ID storage unit 10141, the second ID storage unit 10142 and the third ID storage unit 10143 respectively during system initialization. The comparison voting subunit 10122 is used to compare the three sets of servo unique communication ID data pairwise. If there are at least two sets of servo unique communication ID data with the same content, the matching servo unique communication ID data is determined as the unique valid device identifier of the servo system. Otherwise, the controller 101 does not respond to any bus commands with device identifiers.

[0045] By adopting the above technical solution, when the servo system is powered on and initialized, the data reading subunit 10121 simultaneously reads three unique servo communication ID data from the first ID storage unit 10141, the second ID storage unit 10142, and the third ID storage unit 10143. The comparison and voting subunit 10122 performs pairwise comparisons of the three read data to execute majority voting: if the three data are completely identical, or if two data are identical but the third is inconsistent, then the data with the majority of identical data is determined as the unique and valid device identifier of the servo system, and the system operates normally, automatically masking single-data storage errors; if the three data are mutually different and cannot form a majority, then the controller 101 does not respond to any bus commands with device identifiers, and the system enters a safe failure state, fundamentally eliminating the risk of command misrouting due to severely corrupted ID data.

[0046] In this embodiment, when the comparison voting subunit 10122 determines that the three sets of data are inconsistent pairwise, it also sets the valid device identifier to the default invalid identifier 0xFF and outputs a bus command masking signal to the controller 101. In this state, the servo system only responds to direct control commands from the PWM signal interface and does not respond to any ID-related commands from the CAN bus interface or RS485 interface. Once the operator successfully reissues the ID write command via the CAN bus interface through ground maintenance equipment, the servo system resumes normal operation.

[0047] In this embodiment, the controller 101 is also provided with an identifier writing control unit 1013. The identifier writing control unit 1013 is used to write the same servo unique communication ID data to be written into the first ID storage unit 10141, the second ID storage unit 10142 and the third ID storage unit 10143 in the form of a whole frame according to a preset time interval when it receives the device identifier writing instruction sent from the outside.

[0048] By adopting the above technical solution, when the host computer sends a device identifier write command through the bus interface, the identifier write control unit 1013 receives the command and writes the same servo unique communication ID data to be written in the form of a complete data frame, sequentially at preset time intervals, to the first ID storage unit 10141, the second ID storage unit 10142, and the third ID storage unit 10143. Writing in whole frames ensures that the data in each storage area has a complete frame structure and verification information. Sequential writing at time intervals effectively avoids the risk of simultaneous corruption of all three data sets due to a single system-level power fluctuation or momentary interference during the write operation, ensuring the reliability and consistency of the data write.

[0049] For example, the preset time interval is a configurable value between 10ms and 50ms. After each write operation, the identification write control unit 1013 performs a readback check, comparing the written data with the original data to ensure correctness. If the readback check fails after a write operation, the identification write control unit 1013 re-executes the write operation on that storage area, retrying up to three times. If all three attempts fail, a write failure status message is returned to the host computer.

[0050] In this embodiment, the control module 1 further includes a third housing 104, a heterogeneous redundant communication interface module 102 is fixedly embedded on one side of the third housing 104, and a controller 101 is fixedly installed inside the third housing 104. The bottom of the third housing 104 is open, and a second cover plate 1041 is detachably installed on the bottom of the third housing 104. A terminal female connector group 103 is fixedly embedded on the bottom of the second cover plate 1041, and the terminal female connector group 103 is electrically connected to the controller 101.

[0051] By adopting the above technical solution, the third housing 104 of the control module 1 provides enclosed protection for the controller 101. The heterogeneous redundant communication interface module 102 is fixedly embedded on one side of the third housing 104, directly facing the outside, facilitating interface with the multi-core electrical connector of the host computer. The bottom opening of the third housing 104 is provided and detachably sealed by the second cover plate 1041. The terminal female assembly 103 fixedly embedded at the bottom of the second cover plate 1041 is electrically connected to the controller 101, serving as the electrical interface between the control module 1 and the drive module 2. By removing the second cover plate 1041, the controller 101 can be maintained and replaced, improving maintainability.

[0052] In this embodiment, the third housing 104 is made of aluminum alloy with an anodized outer surface and has a positioning slot and fixing post inside for mounting the controller 101. The heterogeneous redundant communication interface module 102 uses a J30J series 9-pin micro rectangular electrical connector, which is embedded in the mounting hole on the side wall of the third housing 104 and waterproofed by sealant, achieving an IP67 protection level.

[0053] In this embodiment, the drive module 2 includes a drive motor 201, a position sensor 202, a male terminal assembly 203, and a first housing 204. A first mounting base 2041 and a second mounting base 2042 are fixedly connected to the upper interior of the first housing 204. The drive motor 201 is fixedly mounted on the first mounting base 2041. A first splined shaft 2011 is fixedly connected to the shaft of the drive motor 201. A shaft of a second splined shaft 205 is rotatably mounted on the second mounting base 2042. The lower end of the shaft of the second splined shaft 205 passes through the second mounting base 2042. At the bottom of the mounting base 2042, the bottom of the first housing 204 is fixedly connected to the third mounting base 2043. The male terminal assembly 203 is fixedly embedded in the third mounting base 2043. The detection element of the position sensor 202 is fixedly installed at the lower end of the shaft. The position sensor 202 is fixed at the bottom of the second mounting base 2042. The electrical control terminal of the drive motor 201 and the position sensor 202 are both electrically connected to the male terminal assembly 203. After the control module 1 is installed at the bottom of the drive module 2, the female terminal assembly 103 is electrically connected to the male terminal assembly 203.

[0054] By adopting the above technical solution, the drive motor 201 is fixed inside the first housing 204 of the drive module 2 via the first mounting base 2041, and the second spline shaft 205 is rotatably mounted via the second mounting base 2042. The shaft of the drive motor 201 outputs high-speed, low-torque mechanical energy upward through the first spline shaft 2011, and the second spline shaft 205 is used to transmit the angular position movement of the output end of the reduction module 3. The body of the position sensor 202 is fixed to the bottom of the second mounting base 2042, and its detection element is fixed to the lower end of the shaft of the second spline shaft 205, used to detect the rotation angle of the second spline shaft 205. The electrical control end of the drive motor 201 and the signal end of the position sensor 202 are both led out through the male terminal group 203. When the control module 1 is installed at the bottom of the drive module 2, the female terminal group 103 and the male terminal group 203 automatically plug into each other to achieve electrical connection, without the need for additional cable connection, making installation convenient and the electrical connection reliable.

[0055] In this embodiment, the position sensor 202 is a magnetic encoder, and the detection element is a radially magnetized magnet.

[0056] In this embodiment, the reduction module 3 includes a second housing 301 with an open bottom. A first cover plate 307 is detachably mounted on the bottom of the second housing 301. An input shaft 302, a first drive shaft 303, a second drive shaft 304, a third drive shaft 305, and an output shaft 306 are rotatably mounted inside the second housing 301. An input gear 3021 is fixedly mounted on the input shaft 302, and a first spline groove 3022 is provided on the bottom of the input gear 3021. A first-stage reduction gear set 3031 is fixedly mounted on the first drive shaft 303, a second-stage reduction gear set 3041 is fixedly mounted on the second drive shaft 304, a third-stage reduction gear set 3051 is fixedly mounted on the third drive shaft 305, and a fourth-stage reduction gear 3061 is fixedly mounted on the output shaft 306. The input gear 3021 and the first-stage reduction gear set 3031 are connected. The gears are meshed in three stages: the first-stage reduction gear set 3031 meshes with the second-stage reduction gear set 3041, the second-stage reduction gear set 3041 meshes with the third-stage reduction gear set 3051, and the third-stage reduction gear set 3051 meshes with the fourth-stage reduction gear set 3061. The upper end of the output shaft 306 rotates through the top of the second housing 301 and is fixedly installed with a connecting gear 3063. The bottom of the output shaft 306 is provided with a second spline groove 3062. The bottom of the first cover plate 307 is provided with a first through hole 3071 and a second through hole 3072 for the first spline shaft 2011 and the second spline shaft 205 to pass through. After the second housing 301 is installed on the top of the first housing 204, the first spline shaft 2011 can be inserted into the first spline groove 3022 that is adapted to it, and the second spline shaft 205 can be inserted into the second spline groove 3062 that is adapted to it.

[0057] By adopting the above technical solution, the second housing 301 of the reduction module 3 contains a four-stage spur gear reduction transmission chain formed by five rotatably mounted shafts. After the second housing 301 is installed on top of the first housing 204, the first splined shaft 2011 passes through the first through hole 3071 and is inserted into the first spline groove 3022 at the bottom of the input gear 3021. The torque of the drive motor 201 is transmitted to the input shaft 302 through the spline connection. The input gear 3021 drives the first-stage reduction gear set 3031 to rotate, the first-stage reduction gear set 3031 drives the second-stage reduction gear set 3041 to rotate, the second-stage reduction gear set 3041 drives the third-stage reduction gear set 3051 to rotate, and the third-stage reduction gear set 3051 drives the fourth-stage reduction gear 3061 to rotate. After four stages of reduction and torque amplification, the low-speed, high-torque output is sent to the external control surface by the connecting gear 3063 at the upper end of the output shaft 306. Meanwhile, the second splined shaft 205 passes through the second through hole 3072 and is inserted into the second spline groove 3062 at the bottom of the output shaft 306. The angular position movement of the output shaft 306 is transmitted to the second splined shaft 205 through the spline connection, and then detected by the position sensor 202 to achieve precise closed-loop feedback of the control surface output angle.

[0058] In this embodiment, the parameters of each gear pair are as follows: the input gear 3021 meshes with the first-stage reduction gear set 3031 to form the first-stage reduction, with a module of 0.3mm and 12 and 88 teeth respectively; the second-stage reduction gear set 3041 meshes with the first-stage reduction gear set 3031 and the third-stage reduction gear set 3051 respectively, forming the intermediate transmission for the second and third stages of reduction; the fourth-stage reduction gear 3061 meshes with the third-stage reduction gear set 3051 to form the fourth-stage reduction, with a module of 0.5mm and 21 and 52 teeth respectively. The total reduction ratio is 304.876, and the total transmission efficiency of the four stages is not less than 0.815. The gear material is chromium-molybdenum alloy tempered steel, and the tooth surface is flame-hardened to a surface hardness of HRC52 to HRC56.

[0059] In this embodiment, the top and bottom of the first housing 204 are both open, and the four corners of the inner wall of the first housing 204 are provided with first threaded holes 2044. The third housing 104 is installed on the first housing 204 by a first screw 6. The stud of the first screw 6 passes through the third housing 104 and is threaded into the end of the first threaded hole 2044 away from the second housing 301. The second housing 301 is installed on the first housing 204 by a second screw 7. The stud of the second screw 7 passes through the second housing 301 and is threaded into the end of the first threaded hole 2044 away from the third housing 104.

[0060] By adopting the above technical solution, the first housing 204 serves as the main frame of the drive module 2, with open structures at both the top and bottom, facilitating structural docking and electrical connection with the upper deceleration module 3 and the lower control module 1. The four first threaded holes 2044 at the four corners of the inner wall of the first housing 204 are through threaded holes, with the two ends of the same threaded hole used to fix the upper and lower modules respectively. During installation, the first screw 6 passes through the third housing 104 from below and is screwed into the lower end of the first threaded hole 2044, fixing the control module 1 to the bottom of the first housing 204; the second screw 7 passes through the second housing 301 from above and is screwed into the upper end of the first threaded hole 2044, fixing the deceleration module 3 to the top of the first housing 204. This structural design, with the two ends of the first threaded hole 2044 respectively fastened, allows for independent disassembly of the upper and lower modules, eliminating the need to disassemble the other module when repairing or replacing any one module.

[0061] Furthermore, sealing grooves are provided at the top and bottom of the first housing 204, and sealing rings 5 ​​are provided in the sealing grooves.

[0062] By adopting the above technical solution, the sealing ring 5 provided in the sealing groove at the top of the first housing 204 forms a radial seal between the first housing 204 and the second housing 301, preventing external dust and moisture from entering from the mating surface of the drive module 2 and the reduction module 3. The sealing ring 5 provided in the sealing groove at the bottom of the first housing 204 forms a seal between the first housing 204 and the third housing 104, preventing external contaminants from entering from the mating surface of the drive module 2 and the control module 1. Through the double-layer sealing design at the top and bottom, the cleanliness and protection performance of the actuators and control circuits inside the servo system are ensured.

[0063] Furthermore, mounting ears 4 are fixedly connected to the outer wall of the third outer shell 104 and the outer wall of the second outer shell 301.

[0064] By adopting the above technical solution, the mounting ears 4 on the outer wall of the third housing 104 and the mounting ears 4 on the outer wall of the second housing 301 provide a fixed interface between the servo system and the mounting base. Through the through holes opened on the mounting ears 4, the servo system can be bolted to the servo mounting bracket of the aircraft, vehicle, or robot.

[0065] In this embodiment, the outer wall of the first housing 204 is provided with a plurality of heat dissipation grooves at equal intervals from top to bottom.

[0066] By adopting the above technical solution, the drive motor 201 in the drive module 2 generates heat during operation. The heat dissipation grooves opened on the outer wall of the first housing 204 increase the contact area between the first housing 204 and the external air, which is conducive to natural convection heat dissipation, accelerates the conduction and dissipation of internal heat to the external environment, reduces the internal temperature rise of the drive module 2, and ensures the long-term stable operation of the drive motor 201 and the position sensor 202.

[0067] In this embodiment, the communication arbitration unit determines the currently valid communication interface through the dynamic arbitration weight equation of the three-mode heterogeneous link. The dynamic arbitration weight equation of the three-mode heterogeneous link is as follows: In the formula: is the dynamic arbitration weight coefficient of the i-th communication interface, which is dimensionless. The higher the weight coefficient, the higher the arbitration priority of the corresponding interface. The communication arbitration unit always selects the communication interface with the largest weight coefficient as the current valid communication interface. Here, i=1 corresponds to the first communication interface, i=2 corresponds to the second communication interface, and i=3 corresponds to the third communication interface. is the static inherent priority factor of the i-th communication interface, which is dimensionless and corresponds one-to-one with the preset communication priority order; Let be the real-time communication quality factor of the i-th communication interface, which is dimensionless and ranges from [0,1]. The calculation formula is as follows: in, This represents the number of valid data frames received by the i-th interface per unit time. The total number of data frames received by the i-th interface per unit time. Let be the time interval between the most recent successful reception of a valid data frame by the i-th interface. The preset first duration threshold; Let be the link stability factor of the i-th communication interface, which is dimensionless and ranges from [0,1]. The calculation formula is as follows: in, This is the number of consecutive, valid data frames that have passed verification and are continuously received by the i-th interface. This is the preset first quantity; Let be the fault penalty factor for the i-th communication interface, which is dimensionless and ranges from [0,1]. The calculation formula is as follows: in, This represents the number of link failures occurring on the i-th interface within a preset statistical period. This is the preset threshold for the number of faults.

[0068] For the third communication interface, namely the PWM signal interface, since it lacks a frame structure, it is impossible to obtain... and Frame-related parameters, therefore in this dynamic weight arbitration equation and Always equal to 0, that is The PWM signal interface does not participate in dynamic weight competition based on frame quality; it serves only as a pure physical layer backup channel independent of the communication protocol stack. When both the CAN bus interface and the RS485 interface fail, the communication arbitration unit directly selects the PWM signal interface as the currently valid communication interface.

[0069] To further improve the engineering feasibility and logical rigor of the dynamic arbitration weight equation for the three-mode heterogeneous link and adapt it to the actual working scenarios of the servo motor, the following optimizations are added: , The unit of time referred to is clearly defined as a fixed sliding window (e.g., 100ms) synchronized with the servo control cycle, to avoid weight calculation errors caused by ambiguity in the statistical period; The preset statistical period is clearly defined as a 60-second sliding time window to prevent the permanent accumulation of historical faults from causing excessive penalties and to ensure the rationality of the fault penalty mechanism; a zero-frame reception boundary condition is added, whereby the real-time communication quality factor is adjusted when N=0, i.e., when the corresponding communication interface does not receive any data frames. By directly assigning a value of 0, the extreme no-signal scenario is completely covered, ensuring the integrity and accuracy of the weight calculation.

[0070] Example: Basic preset parameters Preset first duration threshold Preset first quantity Frame; Preset fault count threshold Times; Statistical period: 10s; Static inherent priority factor: , , Typical scenario calculation example: Scenario 1: Under normal operating conditions, the main link CAN is functioning normally. CAN interface (i=1): , , , ;calculate: ; ; ; ; RS485 interface (i=2): Under the same operating conditions ; PWM interface (i=3): Under the same operating conditions ; Arbitration Result: The CAN interface was selected as the valid interface, which is completely consistent with the preset priority of this application.

[0071] Scenario 2: CAN failure, automatically downgrade to RS485 CAN interface (i=1): No valid frame received for 300ms consecutively. , , ; calculated ; RS485 interface (i=2): PWM interface ; Arbitration Result: It automatically downgrades to RS485, which fully matches the downgrade rules of this application.

[0072] Scenario 3: Frequent CAN failures, jitter penalty CAN interface (i=1): 6 faults occurred within 10 seconds. Although 28 valid frames were received consecutively, and other parameters were the same as under normal operating conditions; calculation: ; ; RS485 interface (i=2): ; Arbitration Result: It does not switch back to the CAN interface, effectively avoiding link jitter and solving the pain points of existing technologies.

[0073] Technical effects: It achieves an upgrade from binary qualitative to continuous quantitative arbitration, avoiding accidental degradation due to instantaneous interference; it introduces a fault penalty mechanism to fundamentally solve the problem of redundant link jitter; and it sets differentiated weights for heterogeneous protocols, perfectly adapting to the three-mode heterogeneous architecture of this application.

[0074] The working principle and process of the equation: S1 System Initialization: After the servo motor is powered on, the three communication interfaces are initialized, the threshold parameters preset in this application are loaded, and the fault statistics and frame count are cleared.

[0075] S2 Real-time Data Acquisition: The communication quality monitoring subunit and the background listening subunit collect frame verification, reception interval, number of consecutive valid frames, and number of faults from the three interfaces in real time, providing input for the equations. For the PWM signal interface, its Q and S factors are always 0, so there is no need to collect frame-related parameters.

[0076] S3 weight real-time calculation: The communication arbitration unit performs weight equation calculation every 10ms to obtain the weight values ​​of the three interfaces. The weight of the PWM signal interface is included. It is always 0.

[0077] S4 Valid Interface Arbitration: Select the interface with the highest weight as the current valid communication interface, and use the data from this interface as the servo control command.

[0078] S5 Degradation and Self-Healing Execution: When the weight of the primary link is lower than that of the secondary link, a degradation switch is automatically executed; when the weight of the high-priority link recovers to a level higher than the current interface, a switchback is automatically executed. The fault penalty factor also avoids frequent chattering of faulty links.

[0079] S6 Cycle Iteration: Repeat the above steps to achieve dynamic redundant communication arbitration throughout the entire life cycle of the servo motor.

[0080] Working principle: After the servo system is powered on, the data reading subunit 10121 of the identification decision unit 1012 reads three unique servo communication ID data from the first ID storage unit 10141, the second ID storage unit 10142, and the third ID storage unit 10143 respectively. The comparison voting subunit 10122 performs pairwise comparisons of the three data to execute majority voting. If at least two identical ID data exist, it is determined to be a valid device identifier, and the system enters normal working state.

[0081] During normal operation, the first communication interface 1021, the second communication interface 1022, and the third communication interface 1023 of the heterogeneous redundant communication interface module 102 receive rudder deflection command signals from the host computer. The communication arbitration unit 1011 defaults to determining the first communication interface 1021 with the highest priority as the current valid communication interface and uses the data transmitted through this interface as the rudder deflection command.

[0082] The communication quality monitoring subunit 10111 continuously verifies the data frames received by the currently valid communication interface and detects the reception interval. If the current communication interface fails to receive a valid data frame after exceeding the first time threshold, the communication quality monitoring subunit 10111 outputs a link fault indication signal. The downgrade switching control subunit 10112 receives the signal and switches the next priority communication interface to the currently valid communication interface according to the priority order.

[0083] During operation with a lower-priority communication interface after demotion, the background monitoring subunit 10113, after determining that the current priority is not the highest priority, continuously monitors and verifies data frames for all communication interfaces with higher priorities. When any higher-priority communication interface is detected to have received a preset first number of valid data frames with consecutive frame counts and passing verification, the background monitoring subunit 10113 outputs a link recovery indication signal. The link recovery subunit 10114 receives this signal and re-determines the higher-priority communication interface as the current valid communication interface.

[0084] When both the CAN bus interface and RS485 interface fail, the communication arbitration unit 1011 determines the PWM signal interface as the currently valid communication interface. In this state, the host computer directly controls the rudder deflection angle through the high-level duration of the PWM signal, without going through any protocol stack parsing, achieving out-of-band hardware pass-through control.

[0085] The controller 101 performs closed-loop control calculations based on the rudder deflection command received from the currently valid communication interface and the angular position signal fed back by the position sensor 202, generating a motor drive signal. The drive signal is transmitted to the drive motor 201 through the electrical connection between the female terminal block 103 and the male terminal block 203, and the shaft of the drive motor 201 drives the first spline shaft 2011 to rotate.

[0086] The first splined shaft 2011 drives the input shaft 302 and the input gear 3021 to rotate through the first spline groove 3022. The input gear 3021 sequentially drives the first-stage reduction gear set 3031, the second-stage reduction gear set 3041, the third-stage reduction gear set 3051 and the fourth-stage reduction gear 3061. After four stages of reduction and torque amplification, the low-speed, high-torque output is sent to the external rudder surface by the connecting gear 3063 at the upper end of the output shaft 306.

[0087] Meanwhile, the angular position of the output shaft 306 is transmitted to the detection element of the position sensor 202 through the spline connection between the second spline groove 3062 and the second spline shaft 205. The position sensor 202 feeds back the angle signal to the controller 101 through the male terminal group 203 and the female terminal group 103, forming a closed-loop control circuit.

[0088] The foregoing description illustrates and describes several preferred embodiments of the present invention. However, as previously stated, it should be understood that the present invention is not limited to the forms disclosed herein and should not be construed as excluding other embodiments. It can be used in various other combinations, modifications, and environments, and can be altered within the scope of the inventive concept by means of the foregoing teachings or techniques or knowledge in related fields. Any modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention should be within the protection scope of the appended claims.

Claims

1. An electric servo motor, characterized in that, The system includes a drive module (2), a deceleration module (3) is detachably mounted on the top of the drive module (2), and a control module (1) is detachably mounted on the bottom of the drive module (2). The control module (1) includes a circuit board (105) and a heterogeneous redundant communication interface module (102). The heterogeneous redundant communication interface module (102) is used to receive rudder deflection commands from the outside. The heterogeneous redundant communication interface module (102) includes a first communication interface (1021), a second communication interface (1022), and a third communication interface (1023). The communication protocols between the first communication interface (1021), the second communication interface (1022), and the third communication interface (1023) are different. The circuit board (105) integrates a controller (101), the heterogeneous redundant communication interface module (102) is electrically connected to the controller (101), and the controller (101) is provided with a communication arbitration unit (1011), an identification decision unit (1012) and a redundant identification storage module (1014).

2. The electric servo motor according to claim 1, characterized in that: The communication arbitration unit (1011) is used to detect the communication quality status of each communication interface in real time, and determine a currently valid communication interface from the heterogeneous redundant communication interface module (102) according to the preset communication priority order, and use the data transmitted by the communication interface as the instruction to control the operation of the drive module (2). The redundant identifier storage module (1014) includes three physical addresses: a first ID storage unit (10141), a second ID storage unit (10142), and a third ID storage unit (10143). The first ID storage unit (10141), the second ID storage unit (10142), and the third ID storage unit (10143) are all used to store the unique communication ID data of the servo motor. The identification decision unit (1012) is used to read data from the first ID storage unit (10141), the second ID storage unit (10142) and the third ID storage unit (10143) respectively during system initialization, and determine the unique valid device identifier of the servo system by majority voting. The first communication interface (1021) is a CAN bus interface, the second communication interface (1022) is an RS485 interface, and the third communication interface (1023) is a PWM signal interface. The preset communication priority order is: first communication interface (1021) priority > second communication interface (1022) priority > third communication interface (1023) priority.

3. An electric servo motor according to claim 2, characterized in that: The communication arbitration unit (1011) includes a communication quality monitoring subunit (10111) and a downgrade switching control subunit (10112). The communication quality monitoring subunit (10111) is used to verify the data frames received by the current interface and detect the reception interval of the data frames that pass the verification. If it is detected that the current communication interface has not received the data frames that pass the verification after exceeding the first time threshold, a link fault indication signal is output. The downgrade switching control subunit (10112) is used to receive the link fault indication signal transmitted by the communication quality monitoring subunit (10111) and determine the next priority communication interface as the current valid communication interface according to the preset communication priority order.

4. An electric servo motor according to claim 3, characterized in that: The communication arbitration unit (1011) further includes a background monitoring subunit (10113) and a link recovery subunit (10114). The background monitoring subunit (10113) is used to determine the priority of the current valid communication interface. If the priority of the current communication interface is not the highest priority communication interface, it continues to receive and verify data frames for all communication interfaces with higher priority than the current communication interface. If it is detected that any higher priority communication interface has continuously received a preset first number of valid data frames with continuous frame count and qualified verification, it outputs a link recovery indication signal. The link recovery subunit (10114) is used to receive the link recovery indication signal output by the background monitoring subunit (10113) and determine the higher priority communication interface as the current valid communication interface. When the currently valid communication interface is the third communication interface (1023), i.e. the PWM signal interface, the background monitoring subunit (10113) only receives and verifies data frames for the first communication interface (1021) and the second communication interface (1022), and does not perform the judgment of continuous frame counting and qualified verification on the third communication interface (1023) itself; the third communication interface (1023) is a pure physical layer backup channel and does not participate in the link self-healing back-off.

5. An electric servo motor according to claim 4, characterized in that: The identification decision unit (1012) includes a data reading subunit (10121) and a comparison voting subunit (10122). The data reading subunit (10121) is used to read three unique servo communication ID data from the first ID storage unit (10141), the second ID storage unit (10142), and the third ID storage unit (10143) respectively during system initialization. The comparison voting subunit (10122) is used to compare the three unique servo communication ID data pairwise. If there are at least two unique servo communication ID data with the same content, the matching unique servo communication ID data is determined as the unique valid device identifier of the servo system. Otherwise, the controller (101) does not respond to any bus command with device identifier.

6. An electric servo motor according to claim 5, characterized in that: The controller (101) is also provided with an identifier writing control unit (1013). The identifier writing control unit (1013) is used to write the same servo unique communication ID data to be written into the first ID storage unit (10141), the second ID storage unit (10142) and the third ID storage unit (10143) in whole frame form according to a preset time interval when receiving the device identifier writing instruction sent from the outside.

7. An electric servo motor according to claim 1, characterized in that: The control module (1) also includes a third housing (104), the heterogeneous redundant communication interface module (102) is fixedly embedded on one side of the third housing (104), the controller (101) is fixedly installed inside the third housing (104), the bottom of the third housing (104) is open, a second cover plate (1041) is detachably installed on the bottom of the third housing (104), a terminal female head group (103) is fixedly embedded on the bottom of the second cover plate (1041), and the terminal female head group (103) is electrically connected to the controller (101).

8. An electric servo motor according to claim 7, characterized in that: The drive module (2) includes a drive motor (201), a position sensor (202), a male terminal assembly (203), and a first housing (204). The upper part of the first housing (204) is fixedly connected to a first mounting base (2041) and a second mounting base (2042). The drive motor (201) is fixedly mounted on the first mounting base (2041). A first spline shaft (2011) is fixedly connected to the shaft of the drive motor (201). The shaft of a second spline shaft (205) is rotatably mounted on the second mounting base (2042). The lower end of the shaft of the second spline shaft (205) passes through the second mounting base (2042). At the bottom of the first housing (204), a third mounting base (2043) is fixedly connected to the bottom of the first housing (204). The male terminal assembly (203) is fixedly embedded in the third mounting base (2043). The detection element of the position sensor (202) is fixedly installed at the lower end of the shaft. The position sensor (202) is fixed at the bottom of the second mounting base (2042). The electrical control terminal of the drive motor (201) and the position sensor (202) are both electrically connected to the male terminal assembly (203). After the control module (1) is installed at the bottom of the drive module (2), the female terminal assembly (103) is electrically connected to the male terminal assembly (203).

9. An electric servo motor according to claim 7, characterized in that: The deceleration module (3) includes a second housing (301), the bottom of which is open. A first cover plate (307) is detachably installed on the bottom of the second housing (301). An input shaft (302), a first transmission shaft (303), a second transmission shaft (304), a third transmission shaft (305), and an output shaft (306) are rotatably mounted inside the second housing (301). An input gear (3021) is fixedly mounted on the input shaft (302). The bottom of the input gear (3021) is provided with a first spline groove (3022). A first-stage reduction gear set (3031) is fixedly mounted on the first drive shaft (303). A second-stage reduction gear set (3041) is fixedly mounted on the second drive shaft (304). A third-stage reduction gear set (3051) is fixedly mounted on the third drive shaft (305). A fourth-stage reduction gear (3061) is fixedly mounted on the output shaft (306). The input gear (3021) is connected to the first-stage reduction gear set (3031). The first-stage reduction gear set (3031) meshes with the second-stage reduction gear set (3041), the second-stage reduction gear set (3041) meshes with the third-stage reduction gear set (3051), and the third-stage reduction gear set (3051) meshes with the fourth-stage reduction gear set (3061). A connecting gear (3063) is fixedly installed on the upper end of the output shaft (306) after it rotates through the top of the second housing (301). A second spline groove is provided at the bottom of the output shaft (306). (3062) The bottom of the first cover plate (307) is provided with a first through hole (3071) and a second through hole (3072) for the first spline shaft (2011) and the second spline shaft (205) to pass through. After the second housing (301) is installed on the top of the first housing (204), the first spline shaft (2011) can be inserted into the first spline groove (3022) that is adapted to it, and the second spline shaft (205) can be inserted into the second spline groove (3062) that is adapted to it.

10. An electric servo motor according to any one of claims 7-9, characterized in that: The first housing (204) has openings at the top and bottom. The first housing (204) has first threaded holes (2044) at the four corners of its inner wall. The third housing (104) is mounted on the first housing (204) by a first screw (6). The stud of the first screw (6) passes through the third housing (104) and is threaded into the end of the first threaded hole (2044) away from the second housing (301). The second housing (301) is mounted on the first housing (204) by a second screw (7). The stud of the second screw (7) passes through the second housing (301) and is threaded into the end of the first threaded hole (2044) away from the third housing (104).