A redundancy management method for dual-redundancy discrete signals of an airborne equipment

By synchronizing the time of the dual-redundant channels and monitoring the fault counter, the problem of fault location and recovery of dual-redundant signals was solved, improving the reliability of airborne equipment and the utilization rate of redundancy resources, and enhancing the robustness of the system.

CN119376228BActive Publication Date: 2025-10-24LEIHUA ELECTRONICS TECH RES INST AVIATION IND OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411370480.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-29
Publication Date
2025-10-24
Estimated Expiration
2044-09-29

AI Technical Summary

Technical Problem

In existing technologies, fault handling for dual-redundant discrete signals lacks effective monitoring and recovery mechanisms, resulting in low signal availability and wasted redundancy resources. Furthermore, it may provide erroneous signals in scenarios with continuous signal changes.

Method used

By performing time synchronization processing on the dual-redundant channels, setting fault counters and recovery counters, monitoring the validity of channel data, and restoring channel use when the number of faults exceeds the threshold, accurate fault location and recovery can be achieved.

Benefits of technology

It improves the mission reliability and redundancy resource utilization of airborne equipment, reduces voter false triggering caused by signal transitions, and enhances system robustness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119376228B_ABST
    Figure CN119376228B_ABST
Patent Text Reader

Abstract

The application provides a kind of redundancy management method for dual-redundancy discrete signal of airborne equipment, belongs to the technical field of civil aircraft redundancy management, specifically includes that two channels of dual-redundancy are synchronized with time to the data received by receiving end according to the sending cycle of data sending end, judge the validity of two channel data, compare and monitor and vote according to the data validity of two channels for two data with same time label;The record and determination of instantaneous fault and continuous fault of channel, for the channel that has been determined as continuous fault, continue to monitor, according to the number of times of channel data recovery effective, select to re-enable channel. Through the processing scheme of the application, the problem that the dual-redundancy discrete input signal in the current airborne equipment cannot be well positioned and recovered fault is solved, the reliability of one-time fault safety task can be realized, and the utilization rate of redundancy resource is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of civil aircraft redundancy management, in particular to a redundancy management method for dual-redundancy discrete signals of an airborne equipment. BACKGROUND

[0002] Dual-redundancy management refers to selecting a signal for equipment operation from two homonymic signals through monitoring and voting to improve the mission reliability and safety of the airborne equipment. Discrete signals are signals composed of more than two discrete values, such as flight phases, alarm feedbacks, and equipment operation modes.

[0003] In related technologies, dual-redundancy signals are compared and monitored, and a voting value is selected as the output according to a voting principle. When two valid signals are inconsistent and the cumulative number exceeds the threshold of a fault counter, both signals are determined as permanent faults and isolated, and at this time, the last cycle value is usually taken as the fault safety value output to ensure the minimum safety performance of the system.

[0004] This fault handling method of isolating permanent faults and no longer monitoring lacks a monitoring and recovery mechanism for fault signals, thereby limiting the availability of the signals and causing waste of redundancy resources. In addition, selecting the last cycle value as the fault safety value output is difficult to adapt to the scenario of continuous signal changes and may provide an error signal for other related systems. SUMMARY

[0005] Therefore, the present application provides a redundancy management method for dual-redundancy discrete signals of an airborne equipment, which solves the problem that dual-redundancy discrete input signals in the current airborne equipment cannot be well positioned and recovered from faults, and can realize one-time fault safety mission reliability and improve the utilization rate of redundancy resources.

[0006] The redundancy management method for dual-redundancy discrete signals of an airborne equipment provided by the present application adopts the following technical solution:

[0007] A redundancy management method for dual-redundancy discrete signals of an airborne equipment includes the following steps:

[0008] The data received by the receiving end is time-synchronized according to the sending period of the data sending end for the two channels of dual-redundancy, and the data of the same sending period is given the same time label;

[0009] The validity of the data of the two channels is judged;

[0010] The two data with the same time label are compared and monitored and voted according to the validity of the data of the two channels;

[0011] If the data of both channels are valid, compare the two data, if equal, take the equal value as the voting value through comparison monitoring; if not equal, take the data of one channel as the fail-safe value, and record the other channel as comparison monitoring transient fault, and count the number of comparison monitoring transient faults, when the number exceeds the threshold, record both channels as comparison monitoring persistent fault;

[0012] If only one channel has valid data, take the data of the valid channel as the voting value, and record the other channel as self-monitoring transient fault, and count the number of self-monitoring transient faults, when the number exceeds the threshold, record the channel as self-monitoring persistent fault;

[0013] If both channels have no valid data, take one channel as the fail-safe value, and record both channels as self-monitoring transient fault, and count the number of self-monitoring faults, when the number exceeds the threshold, record both channels as self-monitoring persistent fault;

[0014] For the channel that has been determined as persistent fault, continue to monitor, and according to the number of times of data recovery, select to re-enable the channel.

[0015] Optionally, the method for counting the number of comparison monitoring transient faults, when the number exceeds the threshold, recording both channels as comparison monitoring persistent fault, comprises:

[0016] Setting a comparison monitoring fault counter to count the number of comparison monitoring transient faults, sending the data each time, when the comparison monitoring transient fault occurs, the comparison monitoring fault counter is increased by 1, when the comparison monitoring transient fault does not occur, the comparison monitoring fault counter is decreased by 1, when the count of the comparison monitoring fault counter exceeds the first preset value, recording both channels as comparison monitoring persistent fault.

[0017] Optionally, the self-monitoring transient fault comprises communication transient fault and data verification transient fault; the method for judging the validity of the channel data comprises:

[0018] Monitoring the receiving frequency of the receiving end to judge whether the channel data has communication transient fault;

[0019] Verifying the received data to judge whether the received data has data verification transient fault;

[0020] The channel has no communication transient fault and the data has no verification transient fault, and the channel data is valid.

[0021] Optionally, communication fault counters and verification fault counters are set in both channels;

[0022] The communication fault counter counts the communication transient fault of the channel, and the communication fault counter is increased by 1 when the receiving end does not receive data after the sending end sends data each time, the communication fault counter is decreased by 1 when the receiving end normally receives data, and the channel is recorded as a communication persistent fault when the count of the communication fault counter exceeds a second preset value.

[0023] The check fault counter counts the data check transient fault, the check fault counter is increased by 1 when the receiving end receives data and the data check transient fault occurs, the check fault counter is decreased by 1 when the receiving end normally receives data, and the channel is recorded as a data check persistent fault when the count of the communication fault counter exceeds a third preset value.

[0024] Optionally, for the channel that has been determined as a persistent fault, the step of reenabling the channel includes the following steps:

[0025] A first fault recovery counter is arranged for each channel, the first fault recovery counter is increased by 1 when the receiving end normally receives data, the first fault recovery counter is decreased by 1 when the receiving end does not receive data, and the communication persistent fault is cancelled when the first fault recovery counter exceeds a fourth preset value.

[0026] A second fault recovery counter is arranged for each channel, the second fault recovery counter is increased by 1 when the data received by the receiving end passes the data check, the second fault recovery counter is decreased by 1 when the data received by the receiving end does not pass the data check, and the data check persistent fault is cancelled when the second fault recovery counter exceeds a fifth preset value.

[0027] A third fault recovery counter is arranged for each channel, the third fault recovery counter is increased by 1 when the channel passes the comparison monitoring, the third fault recovery counter is decreased by 1 when the channel has a comparison transient monitoring fault, and the comparison monitoring persistent fault is cancelled when the fault recovery counter exceeds a sixth preset value.

[0028] Optionally, the first fault recovery counter, the second fault recovery counter and the third fault recovery counter are not decreased when the values thereof are 0.

[0029] Optionally, the time is the end moment of the sending cycle when the same time label is assigned to the data.

[0030] In summary, the present application has the following beneficial technical effects:

[0031] The present application provides a redundancy management method for an airborne device receiving a dual-redundancy signal, and the method can timely switch to another effective state channel when a single signal fault occurs, that is, the task reliability of one-time fault safety can be realized.

[0032] The application is directed to self-monitoring and comparing monitoring possible faults, and a fault counter is arranged for monitoring each fault, which can effectively avoid frequent mis-triggering of the voter caused by signal jump, improve the robustness of the system while accurately locating the fault.

[0033] The application cancels the traditional method of isolating permanent faults, and proposes to judge the channel whose fault number exceeds the fault counter as a continuous fault and continuously monitor it, and the monitoring means is a fault recovery counter, and the channel is re-enabled after the channel is recovered effectively, which improves the availability of the redundant signal. BRIEF DESCRIPTION OF DRAWINGS

[0034] In order to more clearly illustrate the technical solutions of the embodiments of the application, the drawings needed in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can be obtained without creative labor based on these drawings.

[0035] Figure 1 The figure is a comparison monitoring flowchart in the embodiment of the application.

[0036] Figure 2 The figure is a fault counter processing flowchart in the application.

[0037] Figure 3 The figure is a self-monitoring flowchart in the embodiment of the application.

[0038] Figure 4 The figure is an example diagram of the receiving time of two channel signals in the application. DETAILED DESCRIPTION

[0039] The embodiments of the application will be described in detail below with reference to the drawings.

[0040] The embodiments of the application will be described in detail below with reference to the drawings.

[0041] It is to be understood that the embodiments described hereinbelow within the scope of the appended claims. It will be apparent to one of ordinary skill in the art that aspects described herein can be implemented in a wide variety of forms, and that any specific structure and / or function described herein is merely illustrative. An aspect described herein can be implemented alone or in combination with any other aspect(s). Further, the aspects described herein can be implemented using any number of techniques, whether currently available or not.

[0042] It is also to be understood that the diagrams provided in the following embodiments are only schematic and that the drawings are only intended to aid in the understanding of the application. In reality, the parts shown in the drawings can differ considerably from the shapes, positions and dimensions as shown in the drawings, which are depicted by way of illustration only.

[0043] In addition, in the following description, numerous specific details are set forth in order to provide a thorough understanding of the examples. However, it will be apparent to one of ordinary skill in the art that the aspects described herein can be practiced without these specific details.

[0044] The embodiment of the application provides a redundancy management method of dual-redundancy discrete signals of an airborne equipment.

[0045] A redundancy management method of dual-redundancy discrete signals of an airborne equipment comprises the following steps:

[0046] As shown in Figure 1 , time synchronization processing is performed on the data received by the receiving end according to the sending period of the data sending end for the two channels of the dual-redundancy, and the data of the same sending period is given the same time label.

[0047] The validity of the data of the two channels is judged.

[0048] The two data with the same time label are compared and monitored and voted according to the validity of the data of the two channels.

[0049] If the data of the two channels are both valid, whether the two data are equal is compared, if equal, the comparison monitoring is passed, and the equal value is taken as the voting value; if not equal, the data of one channel is selected as the fail-safe value, and the other channel is recorded as comparison monitoring transient fault, and the number of comparison monitoring transient faults of the channel is counted, and when the number exceeds the threshold, both channels are recorded as comparison monitoring persistent fault.

[0050] If only one channel data is valid, the data of the valid channel is taken as the voting value; the other channel is recorded as self-monitoring transient fault, and the number of self-monitoring transient faults of the channel is counted; when the number of faults exceeds the threshold, the channel is recorded as self-monitoring persistent fault.

[0051] If both channel data are invalid, one of the channels is selected as the fault safety value, and both channels are recorded as self-monitoring transient fault, and the number of self-monitoring channel faults is counted; when the number exceeds the threshold, both channels are recorded as self-monitoring persistent fault.

[0052] For the channel that has been determined as persistent fault, continue to monitor, and according to the number of times of data recovery of the channel, select to re-enable the channel.

[0053] Specifically:

[0054] As shown in Figure 2 , the method for recording both channels as comparison monitoring persistent fault when the number of comparison monitoring transient faults exceeds the threshold comprises: setting a comparison monitoring fault counter to record the number of comparison monitoring transient faults, and sending the data each time the sending end sends data, and then the comparison monitoring fault counter is increased by 1 when comparison monitoring transient fault occurs, and the comparison monitoring fault counter is decreased by 1 when there is no comparison monitoring transient fault, and when the count of the comparison monitoring fault counter exceeds the first preset value, both channels are recorded as comparison monitoring persistent fault.

[0055] The self-monitoring transient fault includes communication transient fault and data verification transient fault; the method for judging the validity of channel data comprises: monitoring the receiving frequency of the receiving end to determine whether there is communication transient fault in the channel data; verifying the received data to determine whether there is data verification transient fault in the received data; and the channel data is valid when there is no communication transient fault in the channel and no verification transient fault in the data.

[0056] As shown in Figure 3 , the data verification transient fault is determined by CRC check bit, function state bit, parity check and SSM, the validity of ARINC 664 bus signal is monitored and determined, and the specific steps are as follows:

[0057] S1, CRC verification: first determine whether the signal belongs to the message containing CRC check bit, if not, the function state bit of the data set is determined: if the function state of the data set of the signal is "NO" or "FT", the signal satisfies the self-determination of validity, and step S2 is entered; if it is "ND" or "NCD", the bit data verification transient fault is determined. If it contains CRC check bit, it is further determined whether the CRC check is passed, which is divided into two cases: 1) if the CRC check is not passed, the signal is determined to be faulty, and theFigure 2 the fault counter determines whether it belongs to a transient fault or a persistent fault; 2) if the CRC check passes, the functional status bit of the data set is determined. The functional status bit definition is shown in Table 1.

[0058] Table 1 Functional status bit definition

[0059]

[0060] S2, parity check and SSM bit determination: for the 429-word signal type, parity check and SSM bit determination are performed in sequence. When the parity check passes and the SSM bit determination is valid, it is considered that the channel data is a valid signal, otherwise it is determined as a data check transient fault.

[0061] A communication fault counter and a check fault counter are set for each channel. The communication fault counter counts the communication transient faults of the channel. After the sending end sends data each time, the communication fault counter is increased by 1 when the receiving end does not receive data, and the communication fault counter is decreased by 1 when the receiving end normally receives data. When the count of the communication fault counter exceeds a second preset value, the channel is recorded as a communication persistent fault. The check fault counter counts the data check transient faults. After the sending end sends data each time, the check fault counter is increased by 1 when the receiving end receives data that is a data check transient fault, and the check fault counter is decreased by 1 when the data received by the receiving end is normal. When the count of the communication fault counter exceeds a third preset value, the channel is recorded as a data check persistent fault.

[0062] For the channel that has been determined as a persistent fault, continue to monitor, and according to the number of times the channel data is recovered effectively, the steps of selecting to re-enable the channel include:

[0063] A first fault recovery counter is set for each channel. From the next sending period when the channel is determined as a communication persistent fault, the communication fault counter stops running, and the first fault recovery counter is enabled. The first fault recovery counter is increased by 1 when the receiving end normally receives data, and the first fault recovery counter is decreased by 1 when the receiving end does not receive data. When the first fault recovery counter exceeds a fourth preset value, the communication persistent fault is cancelled.

[0064] A second fault recovery counter is set for each channel. From the next sending period when the channel is determined as a communication persistent fault, the check fault counter stops running, and the second fault recovery counter is enabled. The second fault recovery counter is increased by 1 when the data received by the receiving end passes the data check, and the second fault recovery counter is decreased by 1 otherwise. When the second fault recovery counter exceeds a fifth preset value, the data check persistent fault is cancelled.

[0065] A third fault recovery counter is set for each channel. Starting from the next sending cycle when the channel is judged to be a continuous communication fault, the comparison monitoring fault counter stops running and the third fault recovery counter is enabled. When the channel passes the comparison monitoring, the third fault recovery counter is increased by 1. When a comparison instantaneous monitoring fault occurs in the channel, the third fault recovery counter is reduced by 1. When the fault recovery counter exceeds the sixth preset value, the comparison monitoring continuous fault is cancelled.

[0066] In the embodiment of the present application, the first preset value, the second preset value, the third preset value, the fourth preset value, the fifth preset value, and the sixth preset value are all 10. In other embodiments, the preset values ​​can be set as needed. When the values ​​of the comparison monitoring fault counter, the communication fault counter, the verification fault counter, the first fault recovery counter, the second fault recovery counter, and the third fault recovery counter are 0, only incrementing is performed, not decrementing.

[0067] like Figure 4 As shown, when the data are assigned the same time label, the time is taken as the end moment of the sending cycle; the redundancy signal received by the airborne equipment usually has no time label. In order to compare and vote between signals, the received redundancy signal should be synchronized. The present application uses the redundancy signal sending period as the time window to group the redundancy signals. Usually in the data sending process, the sending end sends data to the receiving end with a fixed sending period, and the sending periods of the two channels are the same and synchronized, such as, the first period: the signals received in the first sending period are defined as the first group of signals, and the same time label is assigned, and the time is taken as the end moment of the first sending period; the second period: the signals received in the second sending period are defined as the second group of signals, and the same time label is assigned, and the time is taken as the end moment of the second sending period; according to this rule, the time label is updated periodically, and the time is taken as the end moment of the period.

[0068] The method of the present application can be used for redundancy management of dual-redundancy signals of airborne equipment connected to an aircraft data network via an ARINC 664 bus, such as a flight control system, an integrated monitoring system, a flight management system, etc.

[0069] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A method for redundancy management of dual-redundancy discrete signals of an airborne equipment, characterized in that, The method comprises the following steps: Time synchronization processing is performed on the data received by the receiving end according to the sending period of the data sending end for the two channels of the dual-redundancy, and the data of the same sending period is given the same time label; The validity of the data of the two channels is judged; The two data with the same time label are compared and monitored and voted according to the validity of the data of the two channels; If the data of the two channels are both valid, the two data are compared, if the two data are equal, the equal value is taken as the voting value through the comparison and monitoring, if the two data are not equal, the data of one channel is taken as the fault safety value, and the other channel is recorded as the comparison and monitoring transient fault, and the number of comparison and monitoring transient faults of the channel is counted, and when the number exceeds a threshold value, the two channels are recorded as comparison and monitoring persistent faults; If only the data of one channel is valid, the data of the valid channel is directly taken as the voting value, and the other channel is recorded as the self-monitoring transient fault, and the number of self-monitoring transient faults of the channel is counted, and when the number of faults exceeds a threshold value, the channel is recorded as the self-monitoring persistent fault; If the data of the two channels are both invalid, one channel is selected as the fault safety value, and the two channels are recorded as the self-monitoring transient fault, and the number of self-monitoring channel faults is counted, and when the number exceeds a threshold value, the two channels are recorded as the self-monitoring persistent fault; For the channel which has been judged as the persistent fault, the channel is continuously monitored, and the channel is selected to be re-enabled according to the number of times that the data of the channel is recovered to be valid.

2. The method of claim 1, wherein the method further comprises: The method for counting the number of comparison and monitoring transient faults of the channel, and when the number exceeds a threshold value, the two channels are recorded as comparison and monitoring persistent faults, comprises the following steps: A comparison and monitoring fault counter is set to count the number of comparison and monitoring transient faults, after the data is sent by the sending end each time, if the comparison and monitoring transient fault occurs, the comparison and monitoring fault counter is added by 1, if the comparison and monitoring transient fault does not occur, the comparison and monitoring fault counter is reduced by 1, and when the count of the comparison and monitoring fault counter exceeds a first preset value, the two channels are recorded as comparison and monitoring persistent faults.

3. The method of claim 1, wherein the method further comprises: The self-monitoring transient fault comprises a communication transient fault and a data check transient fault, and the method for judging the validity of the channel data comprises the following steps: The receiving frequency of the receiving end is monitored to judge whether the channel data has the communication transient fault; The received data is checked to judge whether the received data has the data check transient fault; The channel data is valid when the channel has no communication transient fault and the data has no check transient fault.

4. The method of claim 3, wherein the method further comprises: Communication fault counters and check fault counters are set in the two channels; The communication transient fault of the channel is counted by the communication fault counter, after the data is sent by the sending end each time, if the data is not received by the receiving end, the communication fault counter is added by 1, if the data is normally received by the receiving end, the communication fault counter is reduced by 1, and when the count of the communication fault counter exceeds a second preset value, the channel is recorded as the communication persistent fault; The check failure counter counts the data check transient failure. After the sending end sends data, the receiving end receives the data and stores the data check transient failure, the check failure counter is added by 1. When the receiving end receives the data normally, the check failure counter is reduced by 1. When the communication failure counter exceeds the third preset value, the channel is recorded as the data check continuous failure.

5. The method of claim 4, wherein, For the channel which has been judged as the continuous failure, the step of continuing to monitor and selecting the step of re-enabling the channel according to the number of times of the data recovery of the channel includes: The first failure recovery counter of each channel is set. When the receiving end receives the data normally, the first failure recovery counter is added by 1. When the receiving end does not receive the data, the first failure recovery counter is reduced by 1. When the first failure recovery counter exceeds the fourth preset value, the communication continuous failure is cancelled. The second failure recovery counter of each channel is set. When the receiving end receives the data which passes the data check, the second failure recovery counter is added by 1. Otherwise, the second failure recovery counter is reduced by 1. When the second failure recovery counter exceeds the fifth preset value, the data check continuous failure is cancelled. The third failure recovery counter of each channel is set. When the channel passes the comparison monitoring, the third failure recovery counter is added by 1. When the channel has the comparison transient monitoring failure, the third failure recovery counter is reduced by 1. When the failure recovery counter exceeds the sixth preset value, the comparison monitoring continuous failure is cancelled.

6. The method of claim 5, wherein the method further comprises: The values of the first failure recovery counter, the second failure recovery counter and the third failure recovery counter are 0, only added but not reduced.

7. The method of claim 1, wherein the method further comprises: When the same time label is given to the data, the time is taken at the end of the sending period.

Citation Information

Patent Citations

  • Monitoring voting method of double redundancy radio altimeters

    CN106595575A

  • Double-redundancy input signal twice monitoring voting method

    CN118034016A