Multi-Mode Hierarchical Fault Reconfiguration Method
The multi-mode fault reconstruction method in helicopter cockpit systems addresses simultaneous display unit failures by using health monitoring and reverse traversal to ensure at least one unit remains operational, enhancing pilot safety and reducing complexity and costs.
Patent Information
- Application Number
- CN202211617367.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-15
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-12-15
AI Technical Summary
In the prior art, when the main and co-pilot display units of the double-person parallel helicopter cockpit fail to effectively deal with the failure of different types of modules at the same time, resulting in display problems and inefficient efficiency.
The multi-mode level fault reconstruction method is adopted, and the status of the main and secondary health monitoring logic is monitored. The main and secondary fault levels are judged. The data cross-transmission path is planned through the reverse traversal exploration method to ensure that at least one display unit works normally, and data packet exchange is realized using the main and secondary data reconstruction channels.
It realizes that when the main and co-pilot display units fail at the same time, quickly find the unique transmission path, ensure the safe and reliable and efficient operation of the display system, and reduces hardware costs and system scheduling complexity.
Smart Images

Figure CN116089338B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of helicopter avionics cockpit display systems, and particularly relates to a multi-mode hierarchical fault reconstruction method. Background Art
[0002] The integrated display control system is an important part of the helicopter avionics cockpit display system and is a key system for human-machine interaction between the pilot and the airborne equipment. The pilot can view the data sent by each airborne equipment through the flight display in the integrated display control system and can send control commands externally to control the operating state of the equipment.
[0003] In a tandem two-seat helicopter cockpit, usually the pilot and co-pilot display units are designed with the same structure and are respectively installed in the pilot and co-pilot positions. A redundant data bus is used between the image display modules to ensure that when other modules fail, the data processed by the data processing module of the normally operating display unit can be synchronized to the image processing module of the faulty display unit, so as to ensure that the pilot and co-pilot display units display simultaneously, forming a primary and standby form. However, this design does not consider the display problem when different types of module failures occur simultaneously in the two display units, and does not consider the handling of different levels of faults, resulting in low utilization efficiency. Summary of the Invention
[0004] In view of this, the embodiments of the present disclosure provide a multi-mode hierarchical fault reconstruction method for solving the problem of different types of module failures in the pilot and co-pilot display units, and performing data cross-transmission path planning and management on the premise of ensuring that at least one display unit works normally, so as to provide a safe and reliable display control environment for the pilot.
[0005] A multi-mode hierarchical fault reconstruction method applicable to data reconstruction of a homogeneous integrated display system, characterized by including: a pilot display unit and a co-pilot display unit, and the co-pilot display unit serves as a hot backup of the pilot display unit. The pilot display unit includes a main health monitoring logic, a main fault level adjudication logic, a main data cross-transmission path planning and management, and a main data reconstruction channel. The co-pilot display unit includes a secondary health monitoring logic, a secondary fault level adjudication logic, a secondary data cross-transmission path planning and management, and a secondary data reconstruction channel, wherein:
[0006] The main and secondary health monitoring logics are used to monitor the working states of each module in the pilot and co-pilot display units and generate fault codes, and report the module fault codes to the system management in the primary and standby display units respectively through the monitoring bus;
[0007] The main and secondary fault level adjudication logics are used to report the software and hardware faults that occur in the system, and adjudicate the faults as primary system-level faults or secondary partial acquisition circuit faults according to the fault spread degree parameter;
[0008] Based on the fault codes reported by the health monitoring logic unit, the master and slave data cross - transmission path planning management takes the principle of ensuring that at least one display unit can display normally after reconstruction. By using the reverse traversal search method, it realizes the online planning of transmission paths for multi - mode faults and opens or closes the data reconstruction channel through the monitoring bus notification module.
[0009] The master and slave data reconstruction channels are used for the exchange of reconstructed data packets and are transmitted in a bus mode. Brief Description of the Drawings
[0010] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following will briefly introduce the drawings required for the embodiments. Obviously, the drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0011] Figure 1 This is the content of the invention included in the present invention;
[0012] Figure 2 This is the flowchart of module reconstruction;
[0013] Figure 3 This is the schematic diagram of multi - module faults of the driver and co - driver display units;
[0014] Figure 4 This is the transmission path of the display data on the display screen.
[0015] Advantageous Effects
[0016] Starting from the terminal module (the end point of the data flow direction), reverse traversal search is carried out. When a secondary module fault is encountered during traversal, it is routed to the secondary module of another display unit; otherwise, the traversal of the current unit module continues, and so on until the last module is traversed, planning a complete data flow path. At the same time, the system management notifies the module to open the reconstruction channel through the monitoring bus to complete the reconstruction. The beneficial effect of reverse traversal path planning is that the forward path calculation is large, the hardware cost is high, and the system scheduling is complex. Through reverse traversal, the unique transmission path can be quickly found. Specific Embodiments
[0017] The following will describe the embodiments of the present disclosure in detail with reference to the drawings.
[0018] The following specific examples illustrate the embodiments of the present disclosure. Those skilled in the art can easily understand the other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific embodiments. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts belong to the scope of protection of the present disclosure.
[0019] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of the aspects described herein can be used to implement the device and / or practice the method. Additionally, this device and / or this method can be implemented using other structures and / or functionality in addition to one or more of the aspects described herein.
[0020] As Figure 1 shown, the multi-mode hierarchical fault reconstruction method is applicable to data reconstruction of a homogeneous integrated display system, including: a driver display unit and a co-driver display unit, and the co-driver display unit serves as a hot backup of the driver display unit. The driver display unit includes a main health monitoring logic, a main fault level adjudication logic, a main data cross-transmission path planning management, and a main data reconstruction channel. The co-driver display unit includes a secondary health monitoring logic, a secondary fault level adjudication logic, a secondary data cross-transmission path planning management, and a secondary data reconstruction channel, where:
[0021] The main and secondary health monitoring logics are used to monitor the working states of each module in the driver and co-driver display units, generate fault codes, and report the module fault codes to the system management in the primary and backup display units respectively through the monitoring bus;
[0022] The main and secondary fault level adjudication logics are used to report the software and hardware faults that occur in the system, and adjudicate the faults as primary system-level faults or secondary partial acquisition circuit faults according to the fault spread degree parameter;
[0023] Based on the fault codes reported by the health monitoring logic unit, the master and slave data cross - transmission path planning management takes the principle of ensuring the normal display of at least one reconstructed display unit. By using the reverse traversal search method, it realizes the online planning of transmission paths for multi - mode faults and opens or closes the data reconstruction channel through the monitoring total notification module.
[0024] The master and slave data reconstruction channels are used for the exchange of reconstructed data packets and are transmitted in a bus manner.
[0025] The simultaneous failure of corresponding modules in the driver's display unit and the co - driver's display unit belongs to an accident and is not the situation handled by the present invention. When some modules in the driver's display unit and the co - driver's display unit fail, a transmission path for display data is provided for the driver, that is, the internal modules of the driver's and co - driver's display units randomly combine fault modes to form a data path.
[0026] As a specific implementation provided in this case, health monitoring is also used to integrate health monitoring logic inside each module of the driver's and co - driver's display units, collect different fault states of the same type of modules in the driver's and co - driver's display units, at least collect whether the circuits of each module in the driver's and co - driver's display units are invalid, whether the watchdog times out, the watchdog circuits, periodic self - check errors are installed in each sub - module of the driver's and co - driver's display units, periodic self - check circuits and whether the power supply of each module drops are installed in each sub - module of the driver's and co - driver's display units, the external power supply supplies power to each sub - module of the driver's and co - driver's display units, and the fault codes generated by each sub - module are reported to the system management, and the system management conducts management for the airborne integrated display system.
[0027] As a specific implementation provided in this case, the fault level adjudication is to receive the fault codes of each module through the monitoring bus. According to the fault spread range, at least the faults caused by watchdog timeout and periodic self - check error that lead to module crash are adjudicated as first - level system - level faults. For first - level system - level faults, a reconstruction mechanism is triggered to plan the data cross - transmission path; for second - level system - level circuit faults, after receiving the fault code, the fault is displayed on the display, and the pilot can actively select the display data source through the data control terminal according to his own needs.
[0028] As a specific implementation provided in this case, the fault code refers to the pre - classification of each fault. The length of the fault code is 1 byte. Among them, bit 0 represents the driver's and co - driver's display units, and bits 1 - 3 represent the module type, with a total of 6 types. Figure 3 Among them, one module is reserved, and bits 4 - 7 represent the fault type, indicating 16 preset types of faults, such as power - off and watchdog timeout.
[0029] As a specific implementation provided in this case, for the management of data cross - transmission path planning, after parsing the fault code, path planning management is carried out on the premise of ensuring that at least one display unit works normally. The planning starts from the terminal module (the end point of data flow) and traverses backward. When a secondary module fault is encountered during traversal, it is routed to the secondary module of another display unit; otherwise, the traversal of the current unit module continues until the last module is traversed, forming a complete data flow path. After the path planning is completed, the corresponding module is controlled through the monitoring bus to open or close the channel.
[0030] As a specific implementation provided in this case, as Figure 2 shown, the driver's display unit and the co - driver's display unit also include a first module A and a second module B. A main data reconstruction channel is set in the first module, and a negative data reconstruction channel is set in the first module. The data of the first module is fed back to the main health monitoring logic, and the data of the second module is fed back to the secondary health monitoring logic. The first module includes a first power supply, a first interface module, a first data processing module, a first image processing module, and a main display that are connected to each other, forming a first path; the second module includes a second power supply, a second interface module, a second data processing module, a second image processing module, and a co - driver's display that are connected to each other, forming a second path.
[0031] When a secondary module fault is encountered during traversal, it is routed to the secondary module of another display unit; otherwise, the traversal of the current unit module continues until the last module is traversed, forming a complete data flow path, including:
[0032] Data cross - transmission path planning management means that the system management explores backward from the terminal module (the end point of data flow) according to the fault information reported by each health monitoring logic. When a secondary module fault is encountered during traversal, it is routed to the secondary module of another display unit; otherwise, the traversal of the current unit module continues, and so on, until the last module is traversed, planning a complete data flow path. At the same time, the system management notifies the module to open the reconstruction channel through the monitoring bus to complete the reconstruction. Specifically:
[0033] As Figure 3As shown, the end performs reverse traversal to detect the status of the main display and the auxiliary display. If both are in normal status, the working status of the first image processing module and the second image processing module of the previous level is judged. If only one of the main display and the auxiliary display is in normal working status, the working status of the first image processing module of the previous level corresponding to the path of the normally working display is judged. If the first image processing module is normal, the first data processing module on the first path where the first image processing module is located is judged. If the first image processing module fails, the second image processing module is used for image processing. In this case, the content displayed on the main display is the data processed by the second image processing module. Then, the second data processing module on the second path where the second image processing module is located is judged. When a module on the path fails, the module corresponding to the other path is used, and the cycle is repeated to form a complete data flow path. Assume that a complex fault occurs, such as Figure 4 As shown, the detailed fault reconstruction of the system is as follows:
[0034] a. The main display unit system management has not received the heartbeat signal of the main display unit interface module and the auxiliary display unit display for a period of time, and the system determines that the main display unit interface module and the auxiliary display unit display have a primary system-level fault such as power failure; and at the same time, it receives the fault code 11000000 (periodic self-test error) issued by the image processing module of the main display unit and the fault code 001000001 (watchdog timeout) issued by the data processing module of the auxiliary display unit, and the system determines that the two modules have a primary system-level fault;
[0035] b. The main display unit system management determines that the display of this unit is working normally, and performs reverse traversal and exploration starting from the display of this unit;
[0036] c. If the secondary module is an image processing module and a fault occurs, the module is routed to the image processing module of the co-pilot display unit;
[0037] d. If it is determined that the image processing module of the co-pilot display unit is working properly, then continue to determine the data processing of the secondary module of the co-pilot display unit;
[0038] e. If it is determined that the co-pilot display unit module is faulty, the process will jump to determine the main driver display unit data processing module;
[0039] f. If it is determined that the data processing module of the main driver display unit is working properly, the main driver display unit interface module will be determined;
[0040] g. If the main driver's display unit interface module is judged to be faulty, the process will jump to judging the co-driver's display unit interface module;
[0041] h. Determine that the co-pilot display unit interface module is working properly, and a complete data transmission path is planned;
[0042] i. The system management of the driver's display unit notifies the display of this unit through the monitoring bus to turn on the data reconstruction channel and close the data channel from the faulty module of this unit;
[0043] j. For other normally operating modules, issue the same channel switching instruction, and the data reconstruction is completed.
[0044] Beneficial effects of reverse traversal path planning: The forward path calculation is computationally intensive, the hardware cost is high, and the system scheduling is complex. By reverse traversal, the unique transmission path can be quickly found.
[0045] As described above, it is only the specific implementation manner of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present disclosure should be covered by the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure shall be subject to the protection scope of the claims.
Claims
1. A multi-mode hierarchical fault reconstruction method, applicable to data reconstruction of a homogeneous integrated display system, characterized in that Including: The driver's display unit and the co-driver's display unit, and the co-driver's display unit serves as the hot backup of the driver's display unit. The driver's display unit includes the main health monitoring logic, the main fault level adjudication logic, the main data cross-transmission path planning management, and the main data reconstruction channel. The co-driver's display unit includes the secondary health monitoring logic, the secondary fault level adjudication logic, the secondary data cross-transmission path planning management, and the secondary data reconstruction channel. Among them: The main and secondary health monitoring logics are used to monitor the working status of each module in the driver's and co-driver's display units, generate fault codes, and report the module fault codes to the system management in the main and backup display units respectively through the monitoring bus; The main and secondary fault level adjudication logics are used to report the software and hardware faults that occur in the system, and adjudicate the faults as first-level system-level faults or second-level partial acquisition circuit faults according to the fault spread degree parameter; The main and secondary data cross-transmission path planning management, based on the fault codes reported by the health monitoring logic unit, with the principle of at least reconstructing one display unit to display normally, adopts the reverse traversal search method to realize the online planning of the transmission path for multi-mode faults, and notifies the module to open or close the data reconstruction channel through the monitoring bus; The main and secondary data reconstruction channels are used for reconstructing the exchange of data packets and transmitting them in a bus manner; It also includes data cross-transmission path planning management. Among them, after parsing the fault codes, on the premise of at least ensuring that one display unit works normally, path planning management is carried out. The planning starts from the terminal module and conducts reverse traversal search. When a secondary module fault is traversed, it is routed to the secondary module of another display unit, otherwise it continues to traverse the modules of this unit until the last module is traversed to form a complete data flow path. After the path planning is completed, the corresponding module is controlled to open or close the channel through the monitoring bus; The driver's display unit and the co-driver's display unit also include a first module and a second module. The main data reconstruction channel is set in the first module, and the negative data reconstruction channel is set in the first module. The data of the first module is fed back to the main health monitoring logic, and the data of the second module is fed back to the secondary health monitoring logic. The first module includes a first power supply, a first interface module, a first data processing module, a first image processing module and a main display connected to each other to form a first path. The second module includes a second power supply, a second interface module, a second data processing module, a second image processing module and a co-driver display connected to each other to form a second path; When traversing to a secondary module failure, it is routed to another display unit secondary module; otherwise, continue to traverse the current unit module until the last module is traversed, forming a complete data flow path, including: traversing in reverse from the end, detecting the status of the main display and the secondary display. When both are in a normal state, judge the working status of the first image processing module and the second image processing module at the upper level. If only one of the main display and the secondary display is in a normal working state, judge the working status of the first image processing module at the upper level of the path corresponding to the normally working display. If the first image processing module is normal, judge the first data processing module on the first path where the first image processing module is located. If the first image processing module fails, then use the second image processing module for image processing. Then, the content displayed on the main display is the data processed by the second image processing module. Then, judge the second data processing module on the second path where the second image processing module is located. When a module on the path fails, use the module corresponding to the other path, and cycle in turn to form a complete data flow path.
2. The method according to claim 1, wherein It includes random combination failure modes of each module inside the main and co-pilot display units to form a data path.
3. The method according to claim 1, characterized in that, The health monitoring is also used to integrate health monitoring logic inside each module of the main and co-pilot display units, collect different failure states of the same type of modules in the main and co-pilot display units, at least collect whether the circuits of each module in the main and co-pilot display units are invalid, whether the watchdog times out, the main and co-pilot display units' each sub-module is equipped with a watchdog circuit and periodic self-check error, the main and co-pilot display units' each sub-module is equipped with a periodic self-check circuit and whether the power supply of each module is powered off. The external power supply supplies power to each sub-module of the main and co-pilot display units, and the fault codes generated by each sub-module are reported to the system management, and the system management is the management for the airborne integrated display system.
4. The method according to claim 3, wherein The fault level adjudication is to receive the fault codes of each module through the monitoring bus. According to the fault spread range, at least adjudicate the faults caused by watchdog timeout and periodic self-check error leading to module crash as first-level system-level faults, trigger a reconstruction mechanism for first-level system-level faults, and plan a data cross-transmission path; For circuit fault secondary system-level faults, after receiving the fault code, display the fault on the display, and the pilot can actively select the display data source through the data control terminal according to his own needs.
5. The method according to claim 4, wherein The fault code refers to pre-classifying each fault, and the length of the fault code is 1 byte. Among them, bit 0 represents the main and co-pilot display units, bits 1-3 represent the module type, and there are 6 types in total, reserving one module. Bits 4-7 represent the fault type, representing 16 preset types of faults, at least including faults such as power-off and watchdog timeout.
Citation Information
Patent Citations
Multi-stage failure management method for use in large-sized plane comprehensive processing platform
CN104360868A
System-level reconstruction management application software master-slave switching method
CN105301955A