A multi-channel redundant trigger circuit and method with fault-tolerant design
By designing a multi-channel redundant trigger circuit with fault-tolerant design, and using the cooperation between fault-tolerant circuits and processors, the abnormal trigger signal is shielded, the problem of false triggering of multiple redundant trigger circuits is solved, and the reliability and security of the system are improved.
Patent Information
- Application Number
- CN201911009223.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-10-23
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2039-10-23
AI Technical Summary
The multi-channel redundant trigger circuit is triggered by mistake due to failure of some devices, which reduces the reliability and security of the system.
A multi-channel redundant trigger circuit with fault-tolerant design is designed. The enable signal is received and the fault-tolerant signal is output. After the system security is released, the processor outputs an effective control signal. The detonating circuit outputs an effective detonating signal based on the received effective fault-tolerant signal and the effective control signal, thereby realizing the shielding of the abnormal trigger signal.
It improves the reliability and security of the system, reduces the probability of false triggering of multiple redundant trigger circuits, and ensures the normal operation of the system under complex junction conditions.
Smart Images

Figure CN110727194B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of explosive device detonation fuses, and in particular to a multi-channel redundant trigger circuit and method with a fault-tolerant design. Background Art
[0002] The fuze is an important component of ammunition. Its definition is: a device that uses environmental information, target information or platform information to implement detonation control of ammunition according to a predetermined strategy while ensuring service and launch safety. The trigger (or impact) fuze uses information about the impact with the target to ignite, such as the reaction force when impacting the target or the forward inertia force generated by the deceleration of the projectile. The detonation circuit module is a functional module that converts the mechanical environmental excitation of the impact target into an electrical detonation control signal.
[0003] In order to adapt to various complex conditions of missile-target intersection on the battlefield and improve operational reliability, sensitive devices in the detonation circuit usually adopt a multi-channel redundant design. However, once any sensor fails, the device fails, or accidental factors cause the detonation signal to be output in advance, it will cause false triggering, so the probability of false triggering of the detonation circuit with a multi-channel redundant design increases. In actual design, problems such as excess metal in the piezoelectric sensor, failure of the converter open-drain output MOS tube, and short circuit of the explosion switch wire can all lead to the erroneous output of the detonation signal in advance.
[0004] In order to improve combat efficiency, all kinds of ammunition are required to be stored in complete packages. After the fuze is loaded, it is generally not powered on for safety reasons. If a piezoelectric sensor or explosion switch circuit fails to output an error signal in advance during service processing or long-term storage, the entire system will not work properly. Summary of the invention
[0005] The embodiments of the present application provide a multi-channel redundant trigger circuit and method with a fault-tolerant design, which can shield the trigger signal in abnormal situations, is suitable for a variety of complex missile-target rendezvous application scenarios, and can solve the problem of false triggering of the detonation circuit involved in the multi-channel redundancy due to the failure of some components, thereby improving the reliability of the system and having good safety.
[0006] The embodiments of the present application are implemented in the following manner:
[0007] A multi-channel redundant trigger circuit with a fault-tolerant design includes: receiving an enable signal through the fault-tolerant circuit, when the enable signal is valid, the fault-tolerant circuit outputs a fault-tolerant signal, after the system insurance is released, the processor outputs a valid control signal, and the detonation circuit outputs a valid detonation signal according to the received valid fault-tolerant signal and the valid control signal, wherein the enable signal is an enable signal output by the processor after detecting the received trigger signal. This solution can perform power-on detection on multiple trigger signals. When a trigger signal input on a certain channel fails, it can be directly shielded by controlling the enable signal, thereby improving the reliability of the system. Beneficial effects:
[0008] 1) This solution sets up a fault-tolerant circuit and performs power-on detection on multi-channel sensor signals and explosion switch signals. When a certain input signal fails, it can be directly shielded through the control signal. The circuit can still complete the main functions of the system, thereby improving the system reliability; (relative to the general multi-channel redundant design, the reliability is improved).
[0009] 2) After the system is completely released, the response to the multi-channel sensor signals and the explosion switch signals is completely controlled by the logic gate hardware. Compared with the method of directly inputting all signals into the control computer for software control (10μs level), it has a high instantaneousness (ns level) and can be used in occasions with high requirements for instantaneousness; (Compared with the solution of using software for signal processing to achieve fault tolerance and redundancy, it has a faster response)
[0010] 3) Using the time from system power-on to complete release of the insurance (related to the trajectory, usually a few seconds or minutes), the system autonomously completes the detection of multiple trigger input signals without affecting the normal release process of the system; (For the failure mode of the multi-channel trigger circuit erroneously outputting the detonation signal in advance, the detection is automatically completed online after power-on, without the need for human intervention, and using the time window from power-on to complete release of the insurance, without occupying additional hardware resources and without affecting other functions of the system)
[0011] 4) This scheme is a multi-channel redundant design trigger scheme, which can adapt to a variety of complex missile-target rendezvous conditions (it is also a multi-channel redundant design and has the general advantages of multi-channel redundant design);
[0012] This solution has the function of controlling the release state. After the system has released the insurance, it will respond to the signals of various sensors and explosion switches, which has good safety. (The detonation signal is associated with the release state of the system, which is an additional layer of insurance).
[0013] Preferably, the detonation circuit outputs a valid detonation signal according to the received valid fault-tolerant signal and valid control signal. The specific process is: the input end of the OR gate receives and outputs the integrated fault-tolerant signal; the two input ends of the AND gate respectively receive the integrated fault-tolerant signal and the control signal output by the processor; when the fault-tolerant signal and the control signal are valid at the same time, the AND gate outputs a valid detonation signal. The detonation circuit includes an OR gate and an AND gate. This method combines the validity of the control signal and the enable signal to determine the validity of the output detonation signal, which can provide a second layer of protection for the circuit module and further improve the safety of the system.
[0014] Preferably, before the system insurance is released, the processor outputs a failure control signal, and the detonation circuit outputs an invalid detonation signal according to the received failure control signal. This solution can shield the trigger signal with abnormal conditions. Before the system insurance is released, no matter whether the enable signal is valid or not, as long as the processor outputs a failure control signal, the detonation signal is in an invalid state, protecting some sensors from false triggering operations due to power-on failure setting high.
[0015] Preferably, the fault-tolerant circuit refers to n parallel AND gates, the two input ends of the AND gates are respectively input with the trigger signal and the enable signal corresponding to the trigger signal, and the AND gate outputs a fault-tolerant signal, wherein the enable signal is an enable signal output after the trigger signal is judged abnormal by the processor, n∈[1,10]. This scheme can detect each trigger signal separately, greatly reducing the probability of false triggering of multi-channel redundant detonation circuits. It can detect multi-channel detonation circuits and can be applied in various complex projectile-target intersection scenarios.
[0016] Preferably, the trigger signal includes a trigger signal generated by an X-path sensor and / or a switch signal generated by a Y-path switch signal circuit; when the trigger signal includes a trigger signal generated by an X-path sensor and a switch signal generated by a Y-path switch signal circuit, n=X+Y; when the trigger signal is a trigger signal generated by an X-path sensor, n=X; when the trigger signal includes a switch signal generated by a Y-path switch signal circuit, n=Y, wherein X, Y, X+Y∈[1,10].
[0017] A multi-channel redundant trigger circuit with fault-tolerant design, comprising:
[0018] The fault-tolerant circuit receives an enable signal and outputs a fault-tolerant signal when the enable signal is valid. The processor outputs a valid control signal after the system safety is released. The detonation circuit outputs a valid detonation signal according to the received valid fault-tolerant signal and the valid control signal. The enable signal is an enable signal output by the processor after detecting the received trigger signal.
[0019] Preferably, the input end of the detonation circuit is respectively connected to the output end of the fault-tolerant circuit and the processor, for receiving a fault-tolerant signal and a control signal, and outputting a detonation signal; the detonation circuit includes an OR gate and an AND gate; the OR gate is used to receive and output an integrated fault-tolerant signal through the input end of the OR gate; the AND gate is used to receive the integrated fault-tolerant signal and the control signal output by the processor through the two input ends of the AND gate; when the fault-tolerant signal and the control signal are valid at the same time, the AND gate outputs a valid detonation signal.
[0020] Preferably, before the system safety is released, the processor outputs a failure control signal, and the detonation circuit outputs an invalid detonation signal according to the received failure control signal.
[0021] Preferably, the fault-tolerant circuit refers to n parallel AND gates, the two input ends of the AND gate respectively input the trigger signal and the enable signal corresponding to the trigger signal, and the AND gate outputs a fault-tolerant signal, wherein the enable signal is an enable signal output after the trigger signal is judged to be abnormal by the processor, n∈[1,10].
[0022] Preferably, the trigger signal includes a trigger signal generated by an X-path sensor and / or a switch signal generated by a Y-path switch signal circuit; when the trigger signal includes a trigger signal generated by an X-path sensor and a switch signal generated by a Y-path switch signal circuit, n=X+Y; when the trigger signal is a trigger signal generated by an X-path sensor, n=X; when the trigger signal includes a switch signal generated by a Y-path switch signal circuit, n=Y, wherein X, Y, X+Y∈[1,10]. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0024] Figure 1 A schematic diagram of a circuit module provided in an embodiment of the present application;
[0025] Figure 2 A schematic diagram of the working process of the circuit module provided in the embodiment of the present application;
[0026] Icon: 1-processor; 2-fault-tolerant circuit; 3-detonation circuit. DETAILED DESCRIPTION
[0027] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings in the embodiments of the present application.
[0028] 1. Relevant definitions:
[0029] 1. The present invention avoids false triggering of the fault-tolerant trigger circuit of the detonation control by coordinating three-level signals, namely, the safety state, the enable signal and the control signal. Among them, the enable signal is a signal output by the processor according to the trigger signal, and the control signal is a signal output by the processor according to the system safety state. Specifically, the enable signal refers to the processor judging whether the trigger signal is a normal start signal of the entire detonation circuit according to the trigger signal. The enable signal is valid when the trigger signal is a normal start signal. The valid control signal refers to the signal output by the processor that enables the detonation circuit to work normally after the system safety state is released.
[0030] 2. The fault-tolerant signal refers to the signal output by the fault-tolerant circuit after receiving the enable signal and the trigger signal. The effective fault-tolerant signal refers to the signal output by the fault-tolerant circuit when the enable signal is valid, and its signal waveform is consistent with the trigger signal.
[0031] 3. An effective detonation signal refers to the signal output by the detonation circuit when both the fault-tolerant signal and the control signal are valid, and its signal waveform is consistent with the effective fault-tolerant signal. An invalid detonation signal refers to the signal output by the detonation circuit when either the fault-tolerant signal or the control signal is invalid, and its signal is usually at a low level.
[0032] 4. System safety release means that the fuze safety control circuit (the fuze safety control circuit is not a hardware component of the present invention) senses the ballistic environment stimulus, completes the release of all insurances (at least two), and is in a ready-to-fire state. The processor of the present invention reads the system safety status, and the fault-tolerant initiation circuit used for initiation control has its insurance released and can be triggered normally. Before the system safety is released, it means that the fuze safety control circuit has not completely released its insurance, and the fault-tolerant initiation circuit used for initiation control does not work, and is forcibly protected by insurance.
[0033] 2. The present invention provides a multi-path redundant triggering method with a fault-tolerant design, comprising:
[0034] An enable signal is received through the fault-tolerant circuit 2, and when the enable signal is valid, the fault-tolerant circuit 2 outputs a fault-tolerant signal;
[0035] After the system insurance is released, the processor 1 outputs a valid control signal;
[0036] The detonation circuit 3 outputs a valid detonation signal according to the received valid fault-tolerant signal and the valid control signal;
[0037] The enable signal is an enable signal that is output by the processor 1 after detecting the received trigger signal.
[0038] The trigger signal includes a trigger signal generated by an X-path sensor and / or a switch signal generated by a Y-path switch signal circuit; when the trigger signal includes a trigger signal generated by an X-path sensor and a switch signal generated by a Y-path switch signal circuit, n=X+Y; when the trigger signal is a trigger signal generated by an X-path sensor, n=X; when the trigger signal includes a switch signal generated by a Y-path switch signal circuit, n=Y.
[0039] Example 1: Please refer to Figure 1 and Figure 2 In the embodiment of the present invention, the trigger signal includes three sensor signals, and the specific connection relationship is as follows: the processor 1 includes an input end and a first output end and a second output end, and the three sensor signals are connected to the input end of the processor 1, and the processor 1 detects them respectively. The input end of the fault-tolerant circuit 2 is respectively connected to the three sensor signals and the first output end of the processor 1. The input end of the detonation circuit 3 is respectively connected to the output end of the fault-tolerant circuit 2 and the second output end of the processor.
[0040] The principle of the whole working process is as follows: taking a sensor signal as an example, before the system insurance is released, the sensor signal is transferred to the processor 1, and the processor 1 detects it. When it is considered that the sensor signal is abnormal (for example, when the sensor fails to be powered on, it will also output a high level), the first output end of the processor 1 outputs an invalid enable signal, that is, the corresponding enable signal level is set low. After the fault-tolerant circuit 2 receives the invalid enable signal, no matter whether the input trigger signal is high or low, the output of the fault-tolerant circuit 2 is an invalid fault-tolerant signal, that is, the fault-tolerant signal is often low. It can also be understood that the fault-tolerant circuit no longer responds to the changes in the input sensor signal, thereby shielding the abnormal sensor signal. When the sensor signal is detected to be normal, the first output end of the processor 1 outputs a valid enable signal, that is, the corresponding enable signal level is set high. After receiving the valid enable signal, the fault-tolerant circuit 2 outputs a valid fault-tolerant signal, and its waveform is consistent with the trigger signal.
[0041] After the system safety is released, the second output terminal of the processor 1 outputs a valid control signal, that is, the control signal level is set high. After receiving the valid fault-tolerant signal and the valid control signal, the detonation circuit 3 outputs a valid detonation signal.
[0042] It should be understood that when there are multiple sensor signal inputs, the above method can be used to detect abnormalities on each sensor signal and shield the abnormal sensor signals.
[0043] Example 2: Based on Example 1, please refer to Figure 1 and Figure 2In the embodiment of the present invention, the trigger signal may also include 3-way switch signals (the switch signal may be a collision switch signal; the collision switch signal is a pulse signal formed when the collision switch installed inside the projectile body senses the inertial force and closes when the projectile collides with the projectile), and the specific connection relationship is as follows: the processor 1 includes an input end and a first output end and a second output end, and the 3-way switch signals are connected to the input end of the processor 1 through an optical coupler, and the processor 1 detects them respectively. The input end of the fault-tolerant circuit 2 is respectively connected to the 3-way sensor signal and the first output end of the processor 1. The input end of the detonation circuit 3 is respectively connected to the output end of the fault-tolerant circuit 2 and the second output end of the processor.
[0044] The principle of the entire working process is as follows: taking a switch signal as an example, before the system insurance is released, the switch signal is optically isolated by an optical coupler, and then transferred to processor 1, which detects it. When it is considered that the switch signal is abnormal, the first output end of processor 1 outputs an invalid enable signal, that is, the corresponding enable signal level is set low. After the fault-tolerant circuit 2 receives the invalid enable signal, no matter whether the input switch signal is high or low, the output of the fault-tolerant circuit 2 is an invalid fault-tolerant signal, that is, it will no longer respond to changes in the input switch signal, thereby shielding the abnormal switch signal. When the switch signal is detected to be normal, the first output end of the processor 1 outputs a valid enable signal, that is, the corresponding enable signal level is set high. After receiving the valid enable signal, the fault-tolerant circuit 2 outputs a valid fault-tolerant signal.
[0045] After the system insurance is released, the second output terminal of the processor 1 outputs a valid control signal, that is, the control signal level is set high. After receiving the valid fault-tolerant signal and the valid control signal, the detonator 3 outputs a valid detonation signal.
[0046] It should be understood that when there are multiple switch signals input, the above method can be used to detect abnormalities on each switch signal and shield the abnormal switch signals.
[0047] Embodiment 3: Based on Embodiments 1 and 2, the detonation circuit 3 includes an OR gate and an AND gate. The input end of the OR gate is connected to the output end of the fault-tolerant circuit, and receives and outputs the integrated fault-tolerant signal. Here, integration means that as long as at least one of the fault-tolerant signals input to the OR gate is valid, the OR gate outputs a valid fault-tolerant signal. If all the fault-tolerant signals input to the OR gate are invalid, the OR gate outputs an invalid fault-tolerant signal. The two input ends of the AND gate are respectively connected to the output end of the OR gate and the processor, and are used to receive the integrated fault-tolerant signal and the control signal output by the processor. The output end of the AND gate is the output end of the detonation circuit 3. After receiving the valid fault-tolerant signal, the OR gate in the detonation circuit 3 integrates it into a valid fault-tolerant signal and inputs it to one input end of the AND gate. The other input end of the AND gate receives the control signal sent by the processor. Only when the fault-tolerant signal and the control signal are valid at the same time, the AND gate outputs a valid detonation signal, and its waveform is consistent with the valid fault-tolerant signal.
[0048] Example 4: Based on Examples 1 to 3, please continue to refer to Figure 1 and Figure 2 Before the system insurance is released, the second output terminal of the processor 1 outputs an invalid control signal, that is, the control signal level is low. At this time, no matter whether the fault-tolerant signal is valid or not, as long as the processor 1 outputs a failure control signal, the detonation signal is invalid, thereby protecting some sensors from false triggering operations due to power-on failure setting high.
[0049] Example 5: Based on Examples 1 to 4, please continue to refer to Figure 1 , the fault-tolerant circuit 2 refers to n parallel AND gates, the two input ends of the AND gates are respectively input with the trigger signal and the enable signal corresponding to the trigger signal, and the AND gate outputs a fault-tolerant signal, wherein the enable signal is the enable signal output after the trigger signal is judged abnormal by the processor, n∈[1,10]. When the enable signal is valid, even if the enable signal is at a high level, the AND gate outputs a valid fault-tolerant signal, and the waveform of the fault-tolerant signal is consistent with the waveform of the trigger signal. For example: when the enable signal is invalid, even if the enable signal is at a low level, the AND gate outputs an invalid fault-tolerant signal which is always at a low level. It should be understood that when there are multiple trigger signals input externally, the fault-tolerant circuit 2 includes multiple parallel AND gates, the number of which is the same as the number of multiple trigger signals, and each trigger signal has a corresponding enable signal.
[0050] Embodiment 6: Based on Embodiments 1 to 5, after the system is powered on, multiple trigger signals are connected to the processor 1, and the detection time of the processor 1 is greater than or equal to 1s. When a trigger signal continuously outputs a high level within 1s after power-on, the trigger signal is determined to be abnormal; otherwise, the trigger signal is determined to be normal.
[0051] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.
[0052] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0053] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
Claims
1. A multi-channel redundant triggering method with fault-tolerant design, characterized in that include: An enable signal is received through a fault-tolerant circuit, and when the enable signal is valid, the fault-tolerant circuit outputs a fault-tolerant signal; After the system insurance is released, the processor outputs a valid control signal; The detonation circuit outputs a valid detonation signal according to the received valid fault-tolerant signal and the valid control signal; Wherein, the enable signal is an enable signal that the processor detects and outputs after receiving the trigger signal; The detonation circuit outputs a valid detonation signal according to the received valid fault-tolerant signal and valid control signal. The specific process is: The OR gate input terminal receives and outputs the integrated fault-tolerant signal; The two input ends of the AND gate receive the integrated fault-tolerant signal and the control signal output by the processor respectively; when the fault-tolerant signal and the control signal are both valid, the AND gate outputs a valid detonation signal; wherein the detonation circuit includes an OR gate and an AND gate; The fault-tolerant circuit refers to n parallel AND gates, the two input ends of the AND gates are respectively input with the trigger signal and the enable signal corresponding to the trigger signal, and the AND gates output a fault-tolerant signal, wherein the enable signal is an enable signal output after the trigger signal is judged to be abnormal by the processor, n∈[1,10]; The trigger signal includes a trigger signal generated by an X-path sensor and / or a switch signal generated by a Y-path switch signal circuit; when the trigger signal includes a trigger signal generated by an X-path sensor and a switch signal generated by a Y-path switch signal circuit, n=X+Y; when the trigger signal is a trigger signal generated by an X-path sensor, n=X; when the trigger signal includes a switch signal generated by a Y-path switch signal circuit, n=Y, wherein X, Y, X+Y∈[1,10].
2. A multi-path redundant triggering method with fault-tolerant design as claimed in claim 1, characterized in that Before the system safety is released, the processor outputs a failure control signal, and the detonation circuit outputs an invalid detonation signal according to the received failure control signal.
3. A multi-channel redundant trigger circuit with fault-tolerant design, characterized in that include: A fault-tolerant circuit, used for receiving an enable signal and outputting a fault-tolerant signal when the enable signal is valid; A processor, used for outputting a valid control signal after the system insurance is released; The detonation circuit is used to output a valid detonation signal according to the received valid fault-tolerant signal and the valid control signal; Wherein, the enable signal is an enable signal that the processor detects and outputs after receiving the trigger signal; The input end of the detonation circuit is respectively connected to the output end of the fault-tolerant circuit and the processor, and is used to receive the fault-tolerant signal and the control signal, and output the detonation signal; The detonation circuit includes an OR gate and an AND gate; An OR gate, used for receiving and outputting an integrated fault-tolerant signal through an OR gate input terminal; The AND gate is used to receive the integrated fault-tolerant signal and the control signal output by the processor through two input terminals of the AND gate; when the fault-tolerant signal and the control signal are both valid, the AND gate outputs a valid detonation signal; The fault-tolerant circuit refers to n parallel AND gates, the two input ends of the AND gates are respectively input with the trigger signal and the enable signal corresponding to the trigger signal, and the AND gates output a fault-tolerant signal, wherein the enable signal is an enable signal output after the trigger signal is judged to be abnormal by the processor, n∈[1,10]; The trigger signal includes a trigger signal generated by an X-path sensor and / or a switch signal generated by a Y-path switch signal circuit; when the trigger signal includes a trigger signal generated by an X-path sensor and a switch signal generated by a Y-path switch signal circuit, n=X+Y; when the trigger signal is a trigger signal generated by an X-path sensor, n=X; when the trigger signal includes a switch signal generated by a Y-path switch signal circuit, n=Y, wherein X, Y, X+Y∈[1,10].
4. A multi-way redundant trigger circuit with fault-tolerant design as claimed in claim 3, characterized in that Before the system safety is released, the processor outputs a failure control signal, and the detonation circuit outputs an invalid detonation signal according to the received failure control signal.
Citation Information
Patent Citations
Multi-channel redundancy trigger circuit with fault-tolerant design
CN210721087U