Collaborative iterative design method for multiple tasks in a scene under single pilot driving mode
By constructing a surface operation task collaboration architecture and DiCluster algorithm for a single-pilot driving mode, combined with scenario modeling and system models, the problem of multi-task collaboration safety during airport surface operations under a single-pilot driving mode was solved, and improvements in safety analysis and iterative design were achieved.
Patent Information
- Application Number
- CN202211424548.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-15
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2042-11-15
AI Technical Summary
Under the single-pilot driving mode, the workload of airport surface operations is heavy and the accident rate is high. Existing technologies make it difficult to effectively conduct safety analysis and iterative design of multi-task collaboration.
By constructing a single-pilot driving mode scene operation task collaborative architecture, using Prepar3D and MagicDraw software for scenario modeling and system model construction, combining the DiCluster algorithm for time interval sequence mining, building a fault tree and performing iterative design, and establishing a simulation verification platform for safety analysis.
It improves the safety of airport surface operations in single-pilot driving mode, reduces pilot workload through decision-making hierarchy and collaborative decision-making, and improves the accuracy of the system's safety analysis and iterative design.
Smart Images

Figure CN115660374B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a technology in the field of aircraft safety design, specifically an iterative design method for multi-task collaboration during the operation of a single pilot driving mode scene. Background Art
[0002] The single-pilot operation (SPO) radically changes the traditional dual-pilot model. Without a second captain to complement their capabilities, interactive decision-making, and status confirmation, safety becomes a primary concern for the single-pilot operation. Surface operations are a crucial component of the flight phase under the single-pilot operation. Surface operations carry a heavy workload and a high accident rate. Therefore, safety analysis and iterative design of multi-task coordination on the ground are particularly important for the single-pilot operation. Summary of the Invention
[0003] In response to the safety issues caused by the multi-task collaboration in the existing single-pilot driving mode scene operation process, the present invention proposes an iterative design method for the multi-task collaboration of the scene under the single-pilot driving mode. By building a simulation verification platform, the scene operation architecture and process of the single-pilot driving mode are iteratively designed, ultimately improving its safety.
[0004] The present invention is achieved through the following technical solutions:
[0005] The present invention relates to a method for collaborative iterative design of multiple tasks in a scene under a single-pilot driving mode, comprising the following steps:
[0006] 1. Construct a collaborative framework for single-pilot flying mode field operations;
[0007] Second, the scenario modeling software Prepar3D was used to model the nominal process of the scene, and the nominal tasks required to be performed during the single pilot driving mode scene operation and the time information of key points were derived;
[0008] 3. Set up a variety of non-nominal tasks to form the final single pilot driving mode scene operation scenario;
[0009] 4. Use the system modeling software MagicDraw to construct a system model of the scene operation scenario;
[0010] 5. Extract the time interval data of nominal flight process and non-nominal flight process during the single pilot driving mode scene operation, and construct the fault tree;
[0011] Six, the time interval sequence mining algorithm DiCluster algorithm is used to mine and analyze the time interval sequence of the above data, and iterative design is carried out based on the mining and analysis results, and the above process is repeated.
[0012] Seven, the safety index comparison analysis of the before and after design is carried out.
[0013] The application relates to a single pilot driving mode scene operation simulation verification platform for realizing the above method, which comprises a scene operation analysis unit, a flight simulation design unit, a model data extraction unit and a time interval sequence algorithm mining unit, wherein: the scene operation analysis unit completes modeling of the internal operation process of the system through system modeling software; the flight simulation design unit designs and models the scene operation scene through flight scene simulation software scene modeling software; linkage simulation of the system modeling software and the scene modeling software can be realized through the development of middleware, the scene modeling software transmits flight state information to the system modeling software, triggers the operation of the internal model, and the system modeling software feeds back key variables or flight instructions to drive the simulation of the scene model; the model data extraction unit extracts time interval data of nominal flight processes and non-nominal flight processes in the single pilot driving mode scene operation process from the model, and constructs a fault tree; the time interval sequence algorithm mining unit uses a difference time sequence double clustering mining algorithm, namely a time interval sequence mining algorithm DiCluster algorithm, to carry out maximum double clustering mining, and carries out joint verification and iterative design of the model based on the mining results when potential hazard modes are mined.
[0014] Technical effects
[0015] The application makes a decision on the single pilot driving mode scene operation process system decision logic, and makes a decision based on the conflict occurrence time; a new difference time sequence double clustering mining algorithm, namely a time interval sequence mining algorithm DiCluster algorithm, is designed, the combination mode of the single pilot ability on the plane, the airborne automatic system ability and the ground operator ability under the demand of multiple task execution is mined and analyzed, a foundation is laid for air-to-ground task coordination safety analysis, and iterative design is carried out based on the mining results; a fault tree is introduced as an evaluation index of the single pilot driving mode scene operation process before and after design, and is used for qualitative and quantitative safety analysis.
[0016] The application adopts collaborative simulation verification of model-driven visual development software and scene simulation modeling software, connects the flight scene space domain and the system architecture logic domain, completes time and space state synchronization and action sequence synchronization and dynamic verification of the single pilot driving mode scene operation stage, and finally completes safety analysis and iterative design of the single pilot driving mode scene operation process. BRIEF DESCRIPTION OF DRAWINGS
[0017] Figure 1 Flow chart of the method of the present invention;
[0018] Figure 2 Schematic diagram of the platform of the present invention;
[0019] Figure 3 A diagram of the task coordination architecture for single pilot driving mode scene operation;
[0020] Figure 4 It is a decision logic diagram of the single pilot driving mode scene operation process system;
[0021] Figure 5 This is a simulation rendering of the nominal flight process of a single pilot driving mode scene;
[0022] Figure 6 It is a simulation effect diagram of multi-mission airport scene operation scenario;
[0023] Figure 7 This is the airport surface operation process model diagram;
[0024] Figure 8 This is the information transfer model diagram;
[0025] Figure 9 Run model diagrams for internal systems of runway conflicts;
[0026] Figure 10 This is the original fault tree model diagram;
[0027] Figure 11 This is the flow chart of the DiCluster algorithm for time interval series mining;
[0028] Figure 12 Call relationship diagram between time interval sequences;
[0029] Figure 13 This is the new fault tree model diagram. DETAILED DESCRIPTION
[0030] This embodiment relates to a safety analysis method for multi-task collaboration during a single pilot driving mode scenario, including the following steps:
[0031] The first step, such as Figure 3 As shown in the figure, a collaborative architecture for single-pilot flying mode surface operations is constructed, including a single-pilot aircraft, ground stations, and airport automation. During the airport surface operations phase, to further reduce the workload of the single pilot on board, airport automation provides monitoring, control, routing, and guidance functions. Ultimately, a single-pilot flying mode air-ground mission collaborative system architecture based on system decision logic is formed, consisting of a single-pilot aircraft, ground stations, and airport automation.
[0032] The single-pilot aircraft includes a more advanced and intelligent onboard automated system and a single pilot. The automated system is responsible for collecting traffic information, organizing flight status, and executing flight operations. It completes the nominal flight process according to the aircraft's standard flight procedures. This entire process is automated, eliminating the need for human decision-making and thus reducing the pilot's workload. When encountering non-nominal flight conditions, the aircraft switches to manual flight mode, with the single pilot responsible for flight control and decision-making in these non-nominal situations, ensuring flight safety.
[0033] The ground station is equipped with a control console and a ground operator. Due to the bandwidth limitation of the air-ground communication link, the onboard video will not be transmitted directly to the ground station. Instead, the received data will be visualized through ground simulation software to enable the ground operator to make collaborative decisions.
[0034] The airport automation described above provides functions such as target monitoring, conflict monitoring, taxi routing, and taxi guidance. Target monitoring uses multiple sensors to locate and identify moving targets and obstacles, ensuring that controllers can promptly learn about the operational status of the airport. Conflict monitoring monitors and warns of conflicts that may arise during taxiing, enabling conflict prediction and avoidance, as well as conflict detection and resolution. Taxi routing automatically provides aircraft with conflict-free taxiing tracks. Taxi guidance uses improved visual aids to reliably guide aircraft taxiing on the airport.
[0035] like Figure 4 As shown, the system decision logic includes monitoring, identification, decision and action.
[0036] Monitoring refers to the acquisition of situational information on the scene by the onboard automated system, including flight plans, scene traffic, and weather conditions. Flight plan information includes the aircraft's own flight plan and partial flight plan information of other aircraft obtained from air traffic control (including only flight status information and not commercially confidential). Scene traffic information can be obtained through Automatic Dependent Surveillance-Broadcast (ADS-B) and Traffic Information Service-Broadcast (TIS-B). Meteorological information can be obtained through weather radar and from air traffic control. This information is then fused and processed to ultimately determine the scene situation.
[0037] Identification refers to the identification and analysis of targets based on the situation. Based on different conflict prediction times, conflict scenarios are divided into long-term conflicts (more than several hours), medium-term conflicts (10 to 30 minutes), and short-term conflicts (less than 5 minutes).
[0038] The decision-making mentioned above refers to the air-ground collaborative decision-making between a single pilot on board, ground operators, onboard automatic systems and air traffic control. According to the different types of conflicts mentioned above, air-ground collaborative decision-making is divided into three levels, namely long-term collaborative decision-making, medium-term collaborative decision-making and short-term collaborative decision-making, and the division of functions at different levels is also different.
[0039] Long-term collaborative decision-making addresses potential conflicts occurring more than several hours in the future. Each mobile unit on the airport grounds reports status information to air traffic control, which then analyzes the overall situation. When a long-term conflict is detected, air traffic control coordinates a resolution. If the aircraft itself requires involvement, the pilots on board, provided they have no other non-standard circumstances to address, handle the long-term non-standard situation within their workload. If the pilots have other non-standard matters to attend to, the situation is handled by ground operators, who then engage in a one-on-one collaborative model. Because the situation is long-term, ground operators can combine historical and current scenario data for situational awareness and analysis, collaborating with the pilots on board to make decisions.
[0040] Mid-term collaborative decision-making targets potential conflicts within the next 10 to 30 minutes. Compared to longer-term scenarios, decision-making and processing time are shorter. To reduce workload onboard pilots, ground operators are immediately notified, transitioning to a one-on-one collaborative model. Onboard automated systems provide assistance and transmit critical information to ground stations via air-ground data links. Ground operators, aided by ground equipment, combine historical and current scenario data, and work with pilots to conduct situational awareness and analysis, collaborating with them to reach decisions. Any necessary interaction with air traffic control is also handled by the ground operators.
[0041] Near-term collaborative decision-making, described as potentially occurring within the next five minutes, is a more urgent situation and is typically handled by the pilot. Onboard automated systems, such as the Traffic Collision Avoidance System (TCAS), issue warnings and provide conflict resolution guidance, supporting pilots in emergency maneuvers (such as collision avoidance). In the event of pilot incapacitation or excessive workload, ground operators are notified and the onboard automated system's level of autonomy is increased, assisting the pilot in ensuring safe aircraft operations within a short period of time.
[0042] The actions described above refer to the handling and resolution of conflicts through the collaborative efforts of multiple parties including onboard automatic systems, onboard pilots, ground operators, and air traffic control.
[0043] The second step is to model the nominal process of the scene using the scenario modeling software Prepar3D, and export the nominal tasks required to be performed during the single pilot driving mode scene operation and the time information of key points;
[0044] like Figure 5As shown, the single pilot driving mode scene operation process includes:
[0045] 1. 30 minutes before departure time (PDT), the taxi management automation program generates the expected taxi clearance for flight ABC and automatically uploads it to the taxi navigation display (TND) for displaying the taxi route and traffic flow constraint point information.
[0046] 2. At the expected rollback time, the ramp controller issues a rollback clearance, and the pilot taxis to the designated location. When the aircraft arrives at the designated location, the safety monitor automatically detects its arrival and notifies ATC. ATC's automated compliance monitoring system continuously compares Flight ABC's current position with its expected position from that time until the aircraft reaches the takeoff runway alignment.
[0047] 3. Following the guidance, flight ABC arrives at traffic flow constraint point #1. As flight ABC approaches the traffic flow constraint point, the airport automation surveillance system detects the aircraft's presence. It determines that flight ABC has arrived within the designated window and that all other sequencing constraints have been met (e.g., flight XYZ has already passed the point). Before flight ABC begins to decelerate, the airport automation system sends a clearance to the next traffic flow constraint point, providing the required time of arrival (RTA) for the second traffic flow constraint point.
[0048] 4. The single pilot presses "Accept" and updates the flight status in the electronic flight strip. At traffic restriction point #2, the emergency hold on the traffic restriction point is not automatically released. The captain remains at this point and checks the TND. He finds his takeoff order is #2. He watches aircraft #1 pass through the traffic restriction point for immediate takeoff.
[0049] 5. After the aircraft is cleared for takeoff, ATCo clears flight ABC to the runway for immediate takeoff and updates the electronic flight strip.
[0050] Based on the above process, the nominal tasks and time information of key points are derived as shown in Table 1:
[0051] Table 1
[0052] Serial number Key event Required time of arrival (s) 1 Pushback 1 2 Departure roll 20 3 Roll to intersection 1 50 4 Roll to intersection 2 / traffic flow constraint point #1 85 5 Roll to intersection 3 125 6 Roll to intersection 4 150 7 Roll to traffic flow constraint point #2 180 8 Runway roll 200 9 Takeoff 250
[0053] The third step is to set up a variety of non-standard tasks to analyze the safety of scene operations under multiple tasks and form the final single pilot driving mode scene operation scenario.
[0054] The non-standard tasks include runway conflict, intersection conflict, following conflict, and forced runway emergency waiting.
[0055] The following conflict is described as follows: Aircraft A is taxiing on the gama taxiway (at a speed of 15 kts) while following the flight path. Shortly thereafter, an aircraft D turns to the gama taxiway ahead of aircraft A, while aircraft D is taxiing at a speed of 10 kts.
[0056] The intersection conflict is described as follows: ATC receives status information from all parties. Aircraft B experiences a medical emergency, and the pilot submits a high-priority request to the controller for intersection N. The controller determines the priority based on the flight status of each aircraft on the scene, ultimately granting high priority to aircraft B at intersection N and modifying its own flight path.
[0057] The runway conflict is described as follows: Based on the scene situation information obtained by the onboard monitoring system, the flight management system (FMS) analyzes and finds that a conflict will occur on the alaph runway with aircraft C that is not flying according to the flight plan, and generates an alarm.
[0058] The mandatory runway holding maneuver is described as follows: The aircraft arrives at the runway within the RTA window. The TND indicates that Flight C is about to land on Runway 05 and warns the pilot that the runway is occupied. Flight XYZ stops crossing and remains near the runway according to the holding procedure.
[0059] The various non-nominal tasks are set as follows: setting a following conflict (medium term) when taxiing to intersection 1, setting a following conflict (short term), intersection conflict (medium term) and runway conflict (long term) when taxiing to traffic flow constraint point 1, setting a forced runway emergency waiting (medium term) and a following conflict (short term) when taxiing to traffic flow constraint point 2, thereby forming the final multi-task airport scene operation scenario, such as Figure 6 shown.
[0060] The fourth step is to construct a system model of the scene operation scenario through the system modeling software MagicDraw;
[0061] The system model includes an airport surface operation process model, an information transmission model and an internal system operation model of a specific task.
[0062] like Figure 7 As shown, the airport surface operation process model is constructed through a state diagram, which includes a nominal flight process and a designed non-nominal operation process.
[0063] like Figure 8 As shown, the information transfer model is constructed through an internal module diagram to describe the interaction between the onboard automatic system, the single pilot on board, the ground station, the airport automation and the tower control.
[0064] like Figure 9As shown in the figure, taking the runway conflict as an example, the internal system operation model of a specific task is constructed through an activity diagram, describing the interactive process from runway discovery to conflict to negotiated resolution.
[0065] The fifth step is to extract the time interval data of the nominal flight process and non-nominal flight process during the single pilot driving mode scene operation, and construct a fault tree.
[0066] The time interval data refers to the multi-task-multi-function call time zone matrix under the airport surface operation scenario designed above.
[0067] The task list consists of nominal and non-nominal tasks during the single pilot flying mode scene operation, as shown in Table 2:
[0068] Table 2
[0069]
[0070]
[0071] The function list is composed of airborne system functions, single pilot functions, ground station functions and ATC functions, as shown in Table 3:
[0072] Table 3
[0073]
[0074]
[0075] The fault tree is used for subsequent qualitative and quantitative safety analysis. Taking the runway conflict mission failure as an example, the fault tree constructed is as follows: Figure 10 shown.
[0076] The sixth step is to use the time interval series mining algorithm DiCluster algorithm to mine and analyze the above data, perform iterative design based on the mining and analysis results, and repeat the above process.
[0077] The time interval sequence mining algorithm described above mines and analyzes the combination patterns of the capabilities of a single pilot on board, the capabilities of the onboard automatic system, and the capabilities of the ground operator under the requirements of multiple mission execution. Through mining, the time zone double clustering can be called with the maximum difference to determine in which time intervals tasks and functions can be run collaboratively, and in which time intervals there are functional deficiencies when tasks are coordinated. This lays the foundation for the safety analysis of air-ground mission collaboration and conducts iterative design based on the mining results.
[0078] like Figure 11 As shown, the DiCluster algorithm process of the time interval sequence mining algorithm is as follows:
[0079] 1) Scan the initial task-function using the time interval matrix and store the original data in the form of a linked list in the memory.
[0080] 2) Calculate the intersection of the call relationship time interval sequences under each task and generate a task-task weight graph.
[0081] The call relationship time interval is a four-tuple e=(T, F, t s , t e ), where T∈Ω, F∈Σ, corresponds to a task to be executed and the function it calls, t s , t e This corresponds to the start time and end time of this call relationship.
[0082] The call relationship time interval sequence is a set of call relationship time intervals E = {e1, ...e n}.
[0083] The calling relationship between the time interval sequences is as follows: Figure 12 As shown, including follows, meets, overlaps, contains, matches, leftmatches, rightmatches.
[0084] Each vertex of the task-task weight graph represents a task. When there is an edge between a pair of vertices, it means that there is a difference in the use of time interval functions under the two tasks represented by this pair of vertices. The weight on each edge is the set of functions and time intervals that meet the different call time zones under the two tasks connected to this edge.
[0085] The difference in calling the time zone function refers to the function F1 in multiple tasks {T1, ..., T m} in the time interval {f1, ..., f n} only has follows or meets relationship, then the function F1 in the task {T1, ..., T m} in the time interval {f1, ..., f n} is the difference call time zone function.
[0086] 3) Task expansion is performed based on the weight graph to mine the maximum difference calling time zone biclusters.
[0087] The difference is called time zone biclustering: in a set of tasks {T1, ..., T m There exists a set of functions {F1, ..., F} that satisfy the time zone of the difference call n}, such a task-function combination is called differential call time zone biclustering.
[0088] The maximum difference call time zone biclustering means: when there is no function or task superset in the bicluster that satisfies the difference call time zone, it is called the maximum difference call time zone biclustering, and the function call relationship time interval can be called by as many tasks as possible.
[0089] The task expansion is achieved through cyclic recursion, specifically including:
[0090] A. First, loop through the horizontal head node chain of the weight graph, and then access the extended node chain under each head node in turn. When constructing a double cluster of the head node-extended node-weight according to the judgment rules and pruning strategy, copy the information of the weight graph to the current double cluster, otherwise access the next extended node.
[0091] The judgment rule is: if the task of the head node is smaller than that of the extension node, construct it; otherwise, do not construct it.
[0092] The pruning strategy is: assume that P is the current extended differential usage time interval bicluster, M is the candidate task set of P, and N is the predecessor task set of P. When for the candidate task M i (M i For any function Fj in ∈M), when there is a predecessor candidate task N j (N j ∈N), in N j There is also a function F j , and in task M i and N j Next, function F j The usage time interval (excluding the same interval) is a follows or meets relationship, then M i Function F in j Can be composed of the predecessor candidate function N j Expanded.
[0093] B. Search the horizontal head node chain of the weight graph to find the predecessor and candidate nodes of the current double cluster, update their weights according to the theorem, and determine whether to output them according to the pruning output strategy.
[0094] C. Loop through the candidate nodes of the current bicluster, update the task nodes of the current bicluster to (head node - expansion node 1 - expansion node 2...), and return to step B for recursive mining until the current expansion node has reached the maximum depth and no longer proceeds.
[0095] Recursively return to step A and visit the next expansion node. If the end of the expansion node chain of the current head node is reached, then jump out of the loop and visit the next head node until the head node chain ends.
[0096] The mining analysis includes:
[0097] At the communications level, ground operators receive information from both onboard automated systems and Air Traffic Control (ATC). ATC transmits airport traffic information to ground stations via the ground network, while onboard systems transmit aircraft status information to ground stations via air-ground data links. However, delays in air-ground data links can pose potential risks. For example, when a T6 following conflict (short), a T7 intersection conflict (medium), and a T8 runway conflict (far) occur simultaneously, air-ground data link resources are scarce. For example, in the case of a following conflict, it takes 55 seconds for the onboard automated system to transmit information to the ground station, and 58 seconds for the ground station to establish surveillance of the traffic environment. Link transmission delays during multi-tasking can pose potential safety risks. Therefore, expanding links or adopting dedicated, high-speed, high-bandwidth air-ground data links can address this shortcoming.
[0098] At the monitoring level, the ground operator needs to replace the original co-pilot to monitor the scene traffic environment information. ATC transmits the airport traffic information to the ground station through the ground network, and then uses the ground simulation software to visualize and simulate it for the ground operator to monitor. However, when multiple tasks are executed at the same time, the traffic information that the ground operator needs to monitor is too much and too complicated, which will bring some potential hazards. For example, when tasks T6, T7, and T8 occur at the same time, function F 22 There is a lot of surface traffic information that needs to be monitored at the ground station, which brings security risks. Therefore, when transmitting surface traffic information, ATC can consider transmitting relevant data based on different threat levels, thereby reducing the workload of ground operators.
[0099] In terms of workload, the nominal process can basically be completed by the onboard automatic system, thereby reducing the workload of the onboard pilot. However, in non-nominal situations, the onboard pilot and the ground operator need to make collaborative decisions. When multiple non-nominal situations occur at the same time, the ground operator will be overwhelmed and may cause potential hazards. For example, when intersection conflict T7 and runway conflict T8 occur at the same time, function F 25 Ground operator collaborative decision making, function F 27 The collaborative interaction between air traffic control and ground operators may cause conflicts. Therefore, it is possible to consider setting up a backup ground operator to assist the collaborative interaction with air traffic control when the original ground operator has a heavy workload.
[0100] The iterative design mentioned above refers to the iterative design of the scene operation architecture and process of the single pilot driving mode, such as adding a dedicated air-to-ground data transmission link, transmitting surveillance information based on the threat level, adding backup ground operators, etc., re-analyzing and improving the time interval algorithm until the design model meets the given safety requirements.
[0101] The seventh step is to conduct a comparative analysis of the safety indicators of the before and after designs.
[0102] The safety index comparison includes qualitative and quantitative analysis of the fault tree. Taking the runway conflict as an example, the newly constructed fault tree is as follows: Figure 13 When the air-ground communication link is replaced with a dedicated communication link, the link blocking failure probability increases from 1*10 -7 Reduced to 1*10 -8 , which improves safety to a certain extent. In addition, after the backup pilot is set, the minimum cut set (part) of the fault tree changes from {work overload}, {physical disability} to {work overload #1, work overload #2}, {work overload #1, physical disability #2}, {physical disability #1, work overload #2}, {physical disability #1, physical disability #2}, and the minimum cut set increases from a single event to a double event. Assuming that the failure value of the basic event is 1×10 -9 , the standard exposure time is 100h, then the failure probability will be 1*10 -7 Reduced to 1*10 -14 , improving the safety of scene operations in single-pilot driving mode.
[0103] This invention comprehensively addresses the safety issues associated with multi-task coordination during the single-pilot flight mode scenario operation phase and proposes a safety iterative design method and simulation verification platform. This invention utilizes collaborative simulation verification using model-driven visualization development software and scenario simulation modeling software, connecting the spatiotemporal domain of the flight scenario with the logical domain of the system architecture to achieve spatiotemporal state synchronization and action sequence synchronization, as well as dynamic verification, during the single-pilot flight mode scenario operation phase.
[0104] The above-mentioned specific implementation can be partially adjusted in different ways by those skilled in the art without departing from the principles and purpose of the present invention. The scope of protection of the present invention shall be based on the claims and shall not be limited by the above-mentioned specific implementation. All implementation schemes within its scope shall be subject to the constraints of the present invention.
Claims
1. A method for collaborative iterative design of multiple tasks in a single-pilot driving mode, characterized by: The following steps are involved: Step 1: Build a single pilot driving mode scene operation task coordination architecture; The single-pilot flying mode surface operation task coordination architecture includes: a single-pilot flying aircraft, a ground station, and airport automation, wherein the airport automation provides monitoring, control, routing, guidance and other functions, ultimately forming a single-pilot flying mode air-ground task coordination system architecture based on system decision logic, which is composed of a single-pilot flying aircraft, a ground station, and airport automation. The single-pilot aircraft includes: a more advanced and intelligent onboard automatic system and a single pilot on board, wherein: the onboard automatic system is responsible for collecting surface traffic information, organizing flight status, and executing flight operations, completing the nominal flight process according to the aircraft's standard flight procedures. The entire process is executed according to the automated procedures, without the need for human participation in decision-making, thereby reducing the pilot's workload; when encountering non-nominal flight processes, the aircraft will switch to manual flight mode, and the single pilot on board will be responsible for driving operations and decision-making in non-nominal situations, and is responsible for flight safety; The ground station is equipped with a control console and a ground operator. Due to bandwidth limitations of the air-to-ground communication link, the onboard video is not transmitted directly to the ground station. Instead, the received data is visualized through ground simulation software to facilitate collaborative decision-making by the ground operator. The airport automation system provides functions such as target monitoring, conflict monitoring, taxi routing, and taxi guidance. Target monitoring uses multiple sensors to locate and identify moving targets and obstacles, ensuring that controllers are informed of the operational status of the airport ground. Conflict monitoring monitors and warns of potential conflicts encountered during taxiing, enabling conflict prediction and avoidance, as well as conflict detection and resolution. Taxi routing automatically provides aircraft with conflict-free taxiing trajectories. Taxi guidance uses improved visual aids to reliably guide aircraft taxiing on the ground. Step 2: Model the nominal process of the scene using scenario modeling software, and derive the nominal tasks that need to be performed during the single pilot driving mode scene operation and the time information of key points; Step 3: Set up multiple non-nominal tasks to form the final single pilot driving mode scene operation scenario; Step 4: Use system modeling software to construct a system model for the scene operation scenario; The system model includes: an airport surface operation process model, an information transfer model, and an internal system operation model for a specific task. The airport surface operation process model is constructed using a state diagram, including the nominal flight process and the designed non-nominal operation process; the information transfer model is constructed using an internal module diagram, describing the interaction between the onboard automatic system, the single pilot on board, the ground station, airport automation, and tower control; and the internal system operation model for a specific task is constructed using an activity diagram, describing the interaction process from discovery to conflict to negotiated resolution. Step 5: Extract the time interval data of the nominal flight process and the non-nominal flight process during the single pilot driving mode scene operation, and construct a fault tree; Step 6: Use the DiCluster algorithm to mine and analyze the time interval series of the above data. Iterate the design based on the mining and analysis results and repeat the above process, including: 1) Scan the initial task-function time interval matrix and store the original data in the memory in the form of a linked list; 2) Find the intersection of the call relationship time interval sequences between each task and generate a task-task weight graph; The call relationship time interval is a four-tuple ,in , , corresponding to a task being executed and the function it calls, , This corresponds to the start time and end time of this call relationship; The call relationship time interval sequence is a collection of call relationship time intervals ; The calling relationships between the time interval sequences include follows, meets, overlaps, contains, matches, leftmatches, and rightmatches; Each vertex of the task-task weight graph represents a task. When an edge exists between a pair of vertices, it means that the two tasks represented by the pair of vertices have different time interval functions. The weight of each edge is the set of functions and time intervals that meet the different call time zones of the two tasks connected by this edge. The difference in calling the time zone function refers to function F1 in multiple tasks The following time interval There is only a follows or meets relationship, then the function F1 in the task The following time interval Inside is the difference call time zone function; 3) Task expansion based on weight graph to mine the maximum difference calling time zone biclusters; The difference is called time zone biclustering: There exists a set of functions that satisfy the difference calling time zone ,Such task-function combinations are called differential call time zone biclustering; The maximum difference call time zone biclustering means: when there is no function or task superset in the bicluster that satisfies the difference call time zone, it is called the maximum difference call time zone biclustering, and the function call relationship time interval can be called by as many tasks as possible; The time interval sequence mining algorithm mines and analyzes the combination pattern of the single pilot capability, the onboard automatic system capability, and the ground operator capability under the requirements of multiple mission execution, specifically including: 1) Scan the initial task-function time interval matrix and store the original data in the memory in the form of a linked list; 2) Find the intersection of the call relationship time interval sequences between each task and generate a task-task weight graph; 3) Task expansion based on weight graph to mine the double clusters of the time zones with the largest difference; Step 7: Conduct a comparative analysis of safety indicators before and after the design; The task expansion is achieved through cyclic recursion, specifically including: A. First, loop through the horizontal head node chain of the weight graph, and then access the extended node chain under each head node in turn. According to the judgment rules and pruning strategy, if a bicluster of the head node, extended node, and weight is constructed, the weight graph information is copied to the current bicluster. Otherwise, the next extended node is accessed. B. Search the horizontal head node chain of the weight graph to find the predecessor and candidate nodes of the current bicluster, update their weights according to the theorem, and determine whether to output them according to the pruning output strategy; C. Loop through the candidate nodes of the current bicluster and update the task nodes of the current bicluster to head node - expansion node 1 - expansion node 2..., then return to step B and recursively mine until the current expansion node has reached the maximum depth and no further mining is done. Recursively return to step A and visit the next expansion node. If the end of the expansion node chain of the current head node is reached, then jump out of the loop and visit the next head node until the end of the head node chain. The mining analysis includes: At the communication level, the information sources for ground operators include onboard automatic systems and ATC. ATC transmits airport traffic information to the ground station through the ground network, and onboard system systems transmit aircraft status information to the ground station through air-ground data links. The links can be expanded or dedicated high-speed and high-bandwidth air-ground data links can be used. At the surveillance level, ground operators need to replace the original co-pilot and monitor the surface traffic environment information. ATC transmits airport traffic information to the ground station through the ground network, and then uses ground simulation software to visualize and provide it to the ground operators for monitoring. However, when multiple tasks are being performed simultaneously, ATC considers the transmission of surface traffic information based on different threat levels, thereby reducing the workload of ground operators. At the workload level, the nominal process is basically completed by the onboard automatic system, thereby reducing the workload of the onboard pilots. However, in non-nominal situations, the onboard pilots and ground operators are required to make air-ground collaborative decisions. When multiple non-nominal situations occur at the same time, a backup ground operator is set up to assist the original ground operator in collaborative interaction with air traffic control when the workload of the original ground operator is heavy.
2. A single pilot driving mode scenario operation simulation verification platform for the scenario multi-task collaborative iterative design method under the single pilot driving mode according to claim 1, characterized in that: include: Scenario operation analysis unit, flight simulation design unit, model data extraction unit and time interval sequence algorithm mining unit, among which: the scenario operation analysis unit completes the modeling of the system's internal operation process through the system modeling software, and the flight simulation design unit designs and models the scenario operation scenario through the flight scenario simulation software scenario modeling software; through the development of middleware, the linkage simulation of the system modeling software and the scenario modeling software can be realized, the scenario modeling software transmits flight status information to the system modeling software, triggers the operation of the internal model, and the system modeling software feeds back key variables or flight instructions to drive the simulation of the scenario model; the model data extraction unit extracts the time interval data of the nominal flight process and the non-nominal flight process during the scenario operation of a single pilot's driving mode from the model, and constructs a fault tree; the time interval sequence algorithm mining unit uses the difference time series biclustering mining algorithm-time interval sequence mining algorithm to perform maximum biclustering mining, and combines the model for safety analysis. When potential hazard patterns are mined, the model is jointly verified and iteratively designed based on the mining results.
Citation Information
Patent Citations
Single-pilot driving system and control method
CN110853411A
Aircraft complex system task reliability modeling prediction method based on fault tree
CN112668210A
Airport scene distributed operation simulation method and system based on operation rules
CN113435051A