A control system and control method for an airborne air management system controller
By using CAN bus and RS422 bus to connect the left and right AMSC devices in the AMSC control system and adopting redundant backup design, the development difficulty and common mode failure caused by the FPGA hardware platform in the prior art are solved, and higher system reliability and security are achieved.
Patent Information
- Application Number
- CN202510376861.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-03-28
AI Technical Summary
The existing AMSC control system is based on the FPGA hardware platform, which leads to high development difficulty, high hardware airworthiness certification cost, and long development cycle. At the same time, single bus status monitoring and data synchronization are prone to common mode failures, which cannot improve the safety and reliability of civil aircraft airborne systems.
The CAN bus and RS422 bus are used to connect the left and right AMSC devices, and information interaction is performed through data synchronization and status bit counting. The redundant backup design is used to improve system reliability and security, and the FPGA hardware platform is abandoned to reduce airworthiness difficulty and R&D costs.
The startup management, data synchronization and status monitoring functions of the left and right controllers of the AMS system are realized, which improves the reliability and security of the system and reduces the development difficulty and development cycle.
Smart Images

Figure CN119872896B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of civil aircraft, and particularly to a control system and a control method for an airborne air management system controller. Background Art
[0002] The AMSC (Air Management System Controller, hereinafter referred to as AMSC, the air management system controller) is the control core of the AMS (Air Management System, hereinafter referred to as AMS, the air management system). It mainly realizes engine bleed air by controlling the air source system and adjusts the temperature and pressure of compressed air, controls the anti-icing system to complete hot air anti-icing; controls the environmental control system to realize fresh air flow control; realizes the control of the environmental temperature in the cockpit and the cabin, and the control of the recirculation fan; realizes the ventilation control of the cabin, the galley and the lavatory; controls the cabin pressure system to realize the control of the cabin pressure altitude and the change rate.
[0003] Currently, the domestic civil aircraft AMSC controller installation equipment mainly imports and supports foreign products. It mainly adopts the architecture of DSP (High-speed Digital Signal Process, high-speed digital signal processor) plus PPC (PowerPC, Performance Optimization With Enhanced RISC-Performance Computing, a central processing unit with a reduced instruction set architecture) and the logical control of FPGA (Field Programmable Gate Array, hereinafter referred to as FPGA, field programmable logic gate array) as the hardware technology solution, and at the same time conducts airworthiness certification in accordance with the civil aircraft airworthiness standards.
[0004] The existing AMSC controllers mainly have the following problems:
[0005] 1. The existing control system of AMSC is usually based on the hardware platform of FPGA (Field Programmable Gate Array, field programmable logic gate array). Therefore, the development difficulty is large, the hardware airworthiness certification cost is high, and the development cycle is long.
[0006] 2. Most of the existing AMSCs use a single bus for status monitoring and data synchronization, which is prone to common mode failures and cannot further improve the safety and reliability of the civil aircraft airborne system, especially cannot meet the requirements of the A-level civil aircraft airborne system equipment. Summary of the Invention
[0007] To solve the problems in the prior art, the present invention provides a control system and a control method for an airborne air management system controller, which can realize functions such as start management, data synchronization, and status monitoring of the left and right side controllers of the AMS system. At the same time, both the internal and external monitoring and control mechanisms of the AMS system adopt redundant backup design, effectively supporting the improvement of the reliability and security of the system, and can be applicable to the definition of the status data format of the interactive monitoring mechanism. By improving the hardware platform architecture design of the AMSC controller, the FPGA is abandoned to reduce the airworthiness difficulty and R & D cost, which can reduce the development difficulty and shorten the development cycle.
[0008] To achieve the above object, the present invention provides the following technical solutions: A control system for an airborne air management system controller, which includes a local AMSC device and a remote AMSC device; the hardware of the local AMSC device and the remote AMSC device is exactly the same. The local AMSC device is connected to the remote AMSC device through the CAN bus and the RS422 bus, and information interaction is carried out between the internal devices of the local AMSC device, the internal devices of the remote AMSC device, and between the local AMSC device and the remote AMSC device by means of data synchronization and status bit counting, so as to realize information interaction between the two control objects and meet the safety technical requirements of different levels and functions of the system.
[0009] Both the local AMSC device and the remote AMSC device are respectively connected to an external motor system, an airborne power supply system, and an avionics system, and both the local AMSC device and the remote AMSC device are connected with a debugging interface through the RS232 bus; the debugging interface is used for software debugging, software upgrade, software data loading, and transceiver control; the airborne power supply system is used to provide DC power for the local AMSC device and the remote AMSC device; the motor system respectively conducts analog signal interaction, digital signal interaction, discrete signal interaction, and optocoupler signal interaction with the local AMSC device and the remote AMSC device; the avionics system respectively conducts data transmission interaction with the local AMSC device and the remote AMSC device through the ARINC429 bus.
[0010] In a preferred technical solution, both the local AMSC device and the remote AMSC device respectively include: an A channel module, a B channel module, an S channel module, a motherboard module, and a connector module;
[0011] The hardware of the A channel module and the B channel module is exactly the same, and adopts the DSP hardware architecture. The A channel module and the B channel module are backup to each other, and the CAN bus synchronization circuit is used to work the state.
[0012] The S-channel module adopts the hardware architecture of the MCU, and the hardware of the S-channel module is independent and non-similar to the hardware of the A-channel module and the B-channel module; the S-channel module is a safety channel, and uses the I2C bus (Inter-Integrated Circuit, abbreviated as I2C bus, also known as: two-wire serial bus) to monitor the status of the A-channel module and the B-channel module at all times; if both the A-channel module and the B-channel module fail, the S-channel module takes over all control functions to achieve stable and safe output and interaction with the motor system;
[0013] The motherboard module is used to supply the electricity transmitted by the airborne power system to the A-channel module, the B-channel module, the S-channel module, and the connector module respectively, and is also used for signal isolation, signal buffering of each interface, and distributing signals to each channel;
[0014] The connector module is used as an external interface.
[0015] In a preferred technical solution, if ultra-low voltage power supply occurs, the S-channel module takes over all control functions to achieve stable and safe output and interaction with the motor system.
[0016] In a preferred technical solution, the information interaction between the local AMSC device and the opposite AMSC device adopts the method of data synchronization and status bit counting to realize the information interaction between two control objects. The specific process to meet the safety technical requirements of different levels and functions of the system is as follows:
[0017] 1. Before the local AMSC device communicates with the opposite AMSC device, it first judges whether the working status of each other is normal;
[0018] When the following conditions are met simultaneously, the local AMSC device determines that the working status of the opposite AMSC device is normal, otherwise it is abnormal;
[0019] a) The local AMSC device monitors that the discrete interface status of the opposite AMSC device is "open";
[0020] b) The local AMSC device monitors that the synchronization status monitoring data of the opposite AMSC device is normal;
[0021] Similarly, when the following conditions are met simultaneously, the opposite AMSC device determines that the working status of the local AMSC device is normal, otherwise it is abnormal;
[0022] a) The opposite AMSC device monitors that the discrete interface status of the local AMSC device is "open";
[0023] b) The opposite AMSC device monitors that the synchronization status monitoring data of the local AMSC device is normal;
[0024] 2) When the working status of the local AMSC device and the remote AMSC device is mutually determined to be normal, the following communication processing mechanism is adopted:
[0025] a) Periodically send synchronization status monitoring data to each other;
[0026] b) Continuously monitor the discrete interface status of each other;
[0027] c) Continuously monitor the synchronization status monitoring data sent by each other;
[0028] 3) When the working status of one of the local AMSC device and the remote AMSC device is mutually determined to be abnormal, the following communication processing mechanism is adopted:
[0029] If the discrete interface of the abnormal AMSC device is "closed" as monitored by the normal AMSC device, then:
[0030] a) The normal AMSC device stops processing any data sent by the abnormal AMSC device;
[0031] b) The normal AMSC device stops sending any data to the abnormal AMSC device;
[0032] c) The normal AMSC device records the fault event of the abnormal AMSC device being turned off;
[0033] If the discrete interface of the abnormal AMSC device is "open" and the synchronization status monitoring data is abnormal as monitored by the normal AMSC device, then the following communication processing mechanism is adopted:
[0034] a) The normal AMSC device stops processing other data sent by the abnormal AMSC device except for the synchronization status monitoring data until the synchronization status monitoring data is normal;
[0035] b) The normal AMSC device stops sending any data other than the synchronization status monitoring data to the abnormal AMSC device;
[0036] c) The normal AMSC device records the fault event corresponding to the abnormal synchronization status monitoring data of the abnormal AMSC device;
[0037] d) The normal AMSC device continuously monitors the synchronization status monitoring data of the abnormal AMSC device;
[0038] e) The normal AMSC device gives a prompt for the fault of the abnormal AMSC device.
[0039] Preferred technical solution: When the normal AMSC device continuously monitors that the synchronization status monitoring data sent by the abnormal AMSC device is normal for eight consecutive cycles, re-determine the corresponding abnormal AMSC device as a normal working state, and restart the communication processing mechanism when the working state is normal.
[0040] Preferred technical solution: The internal devices of the local AMSC device use data synchronization and status bit counting for information interaction to achieve information interaction between two control objects. The specific processes to meet the security technical requirements of different levels and functions of the system are as follows:
[0041] 1. The A-channel module and the B-channel module have functions of mutual monitoring, mutual control, mutual switching, and mutual redundant backup; first, the A-channel module and the B-channel module mutually judge whether the working states of each other are normal;
[0042] When the following conditions are met simultaneously, the A-channel module determines that the working state of the B-channel module is normal, otherwise it is abnormal;
[0043] a) The A-channel module monitors that the discrete interface state of the B-channel module is "open";
[0044] b) The A-channel module monitors that the synchronization status monitoring data of the B-channel module is normal;
[0045] Similarly, when the following conditions are met simultaneously, the B-channel module determines that the working state of the A-channel module is normal, otherwise it is abnormal;
[0046] a) The B-channel module monitors that the discrete interface state of the A-channel module is "open";
[0047] b) The B-channel module monitors that the synchronization status monitoring data of the A-channel module is normal;
[0048] 2. When the A-channel module and the B-channel module mutually determine that the working states are normal, the following communication processing mechanism is adopted:
[0049] a) Periodically send synchronization status monitoring data to each other;
[0050] b) Continuously monitor the discrete interface states of each other;
[0051] c) Continuously monitor the synchronization status monitoring data sent by each other;
[0052] 3. When the A-channel module and the B-channel module mutually determine that the working state of one of them is abnormal, the following communication processing mechanism is adopted:
[0053] If the normal channel module monitors that the discrete interface of the abnormal channel module is "closed", then:
[0054] a) The normal channel module stops processing any data sent by the abnormal channel module;
[0055] b) The normal channel module stops sending any data to the abnormal channel module;
[0056] c) The normal channel module records the fault event of the shutdown of the abnormal channel module;
[0057] If the discrete interface of the abnormal channel module monitored by the normal channel module is "on" and the synchronization status monitoring data is abnormal, the following communication processing mechanism is adopted:
[0058] a) Start a three-second timer. The normal channel module stops processing other data sent by the abnormal channel module except the synchronization status monitoring data until the synchronization status monitoring data is normal;
[0059] b) The normal channel module stops sending any data other than the synchronization status monitoring data to the abnormal channel module;
[0060] c) The normal channel module records the fault event corresponding to the abnormal synchronization status monitoring data of the abnormal channel module;
[0061] d) The normal channel module continuously monitors the synchronization status monitoring data of the abnormal channel module;
[0062] e) When the three-second timer is completed, if the synchronization status monitoring data is normal, the communication processing mechanism with the working state of normal is adopted; otherwise, the normal channel module gives a prompt of the fault of the abnormal channel module.
[0063] In a preferred technical solution, the S channel module serves as a safety channel. When the S channel module monitors that both the A channel module and the B channel module are abnormal, the S channel module takes over all control functions to achieve stable and safe output and interaction with the motor system; otherwise, the S channel module does not perform any processing.
[0064] In a preferred technical solution, the internal devices of the opposite AMSC device use data synchronization and status bit counting methods for information interaction to achieve information interaction between two control objects. The specific processes to meet the safety technical requirements of different levels and functions of the system are as follows:
[0065] I. The A channel module and the B channel module have functions of mutual monitoring, mutual control, mutual switching, and mutual redundant backup; first, the A channel module and the B channel module mutually judge whether each other's working state is normal;
[0066] When the following conditions are met simultaneously, the A channel module determines that the working state of the B channel module is normal; otherwise, it is abnormal;
[0067] a) The discrete interface status of Channel B module monitored by Channel A module is "open";
[0068] b) The synchronization status monitoring data of Channel B module monitored by Channel A module is normal;
[0069] Similarly, when the following conditions are met simultaneously, Channel B module determines that the working status of Channel A module is normal, otherwise it is abnormal;
[0070] a) The discrete interface status of Channel A module monitored by Channel B module is "open";
[0071] b) The synchronization status monitoring data of Channel A module monitored by Channel B module is normal;
[0072] II. When Channel A module and Channel B module mutually determine that the working status is normal, the following communication processing mechanism is adopted:
[0073] a) Periodically send synchronization status monitoring data to each other;
[0074] b) Continuously monitor the discrete interface status of each other;
[0075] c) Continuously monitor the synchronization status monitoring data sent by each other;
[0076] III. When Channel A module and Channel B module mutually determine that the working status of one party is abnormal, the following communication processing mechanism is adopted:
[0077] If the discrete interface of the abnormal channel module monitored by the normal channel module is "closed", then:
[0078] a) The normal channel module stops processing any data sent by the abnormal channel module;
[0079] b) The normal channel module stops sending any data to the abnormal channel module;
[0080] c) The normal channel module records the fault event of the abnormal channel module being turned off;
[0081] If the discrete interface of the abnormal channel module monitored by the normal channel module is "open" and the synchronization status monitoring data is abnormal, then the following communication processing mechanism is adopted:
[0082] a) Start a three-second timer. The normal channel module stops processing other data sent by the abnormal channel module except the synchronization status monitoring data until the synchronization status monitoring data is normal;
[0083] b) The normal channel module stops sending any data other than the synchronization status monitoring data to the abnormal channel module;
[0084] c) The normal channel module records the fault events corresponding to the anomalies in the synchronization status monitoring data of the abnormal channel module;
[0085] d) The normal channel module continuously monitors the synchronization status monitoring data of the abnormal channel module;
[0086] e) When the three - second timing is completed, if the synchronization status monitoring data is normal, a communication processing mechanism with a normal working state is adopted; otherwise, the normal channel module gives a prompt for the fault of the abnormal channel module.
[0087] In a preferred technical solution, the data stream format definitions of all synchronization status monitoring data all adopt the following standards:
[0088] Data Byte 1 and Data Byte 2 are byte frame headers, and the data is designed as 0x55, indicating the start of the data stream;
[0089] Data Bytes 3 to 14 are byte status monitoring data. Only one byte in the data is 1. The data stream shifts step by step from the low byte to the high byte in a cycle. When it offsets to the 14th byte, it starts to offset again from the 9th byte;
[0090] Data Bytes 15 and 16 are byte frame tails, and the data is designed as 0xAA, indicating the end of the data stream.
[0091] Another object of the present invention is to provide a control method for an airborne air management system controller, which includes the following steps:
[0092] First, initialization and self - inspection are performed; during the initialization and self - inspection process, a ten - second time window is set. During this ten - second time window, the following processing is continuously performed:
[0093] 1) Before the local AMSC device communicates with the opposite - side AMSC device, first mutually determine whether the working states of each other are normal;
[0094] When the following conditions are simultaneously met, the local AMSC device determines that the working state of the opposite - side AMSC device is normal; otherwise, it is abnormal;
[0095] a) The local AMSC device monitors that the discrete interface state of the opposite - side AMSC device is "open";
[0096] b) The local AMSC device monitors that the synchronization status monitoring data of the opposite - side AMSC device is normal;
[0097] Similarly, when the following conditions are simultaneously met, the opposite - side AMSC device determines that the working state of the local AMSC device is normal; otherwise, it is abnormal;
[0098] a) The discrete interface status of the local AMSC device monitored by the opposite - side AMSC device is "open";
[0099] b) The synchronization status monitoring data of the local AMSC device monitored by the opposite - side AMSC device is normal;
[0100] II. When the local AMSC device and the opposite - side AMSC device mutually determine that their working states are normal, the following communication processing mechanism is adopted:
[0101] a) Periodically send synchronization status monitoring data to each other;
[0102] b) Continuously monitor the discrete interface status of the other party;
[0103] c) Continuously monitor the synchronization status monitoring data sent by the other party;
[0104] III. When the local AMSC device and the opposite - side AMSC device mutually determine that one of them has an abnormal working state, the following communication processing mechanism is adopted:
[0105] If the discrete interface of the abnormal AMSC device monitored by the normal AMSC device is "closed", then:
[0106] a) The normal AMSC device stops processing any data sent by the abnormal AMSC device;
[0107] b) The normal AMSC device stops sending any data to the abnormal AMSC device;
[0108] c) The normal AMSC device records the fault event of the abnormal AMSC device being turned off;
[0109] If the discrete interface of the abnormal AMSC device monitored by the normal AMSC device is "open" and the synchronization status monitoring data is abnormal, then the following communication processing mechanism is adopted:
[0110] a) The normal AMSC device stops processing other data sent by the abnormal AMSC device except for the synchronization status monitoring data until the synchronization status monitoring data is normal;
[0111] b) The normal AMSC device stops sending any data other than the synchronization status monitoring data to the abnormal AMSC device;
[0112] c) The normal AMSC device records the fault event corresponding to the abnormal synchronization status monitoring data of the abnormal AMSC device;
[0113] d) The normal AMSC device continuously monitors the synchronization status monitoring data of the abnormal AMSC device;
[0114] e) The normal AMSC device gives a prompt for the failure of the abnormal AMSC device;
[0115] f) When the normal AMSC device continuously monitors that the synchronization status monitoring data sent by the abnormal AMSC device is normal for eight consecutive cycles, re-determine the corresponding abnormal AMSC device to be in a normal working state, and restart the communication processing mechanism when the working state is normal.
[0116] Compared with the prior art, the beneficial effects of the control system and method of an airborne air management system controller of the present invention are:
[0117] 1. The present invention can realize functions such as start management, data synchronization, and status monitoring of the left and right side controllers of the AMS system. At the same time, both the internal and external monitoring and control mechanisms of the AMS system adopt redundant backup designs, effectively supporting and enhancing the reliability and safety of the system, and can be applicable to the definition of the status data format of the interactive monitoring mechanism. By improving the hardware platform architecture design of the AMSC controller, the FPGA is abandoned to reduce the airworthiness difficulty and R & D cost, and the development difficulty can be reduced and the development cycle can be shortened.
[0118] 2. The bus of the present invention has multiple modules, and different data communication forms are adopted by different modules for status monitoring and data synchronization, which can further improve the reliability and safety indexes of airborne equipment.
[0119] 3. Different architectures are adopted between the processing boards of the AMSC controller of the present invention, such as different forms of DSP architecture and MCU architecture, so that the reliability and safety indexes of the system of the present invention are improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0120] Figure 1 It is a schematic diagram of external interaction of a control system of an airborne air management system controller according to Embodiment 1 of the present invention.
[0121] Figure 2 It is a schematic diagram of internal interaction of a control system of an airborne air management system controller according to Embodiment 1 of the present invention.
[0122] Figure 3 It is a schematic diagram of the data flow format of synchronization status monitoring data in Embodiment 1 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0123] Refer to Figures 1-3 To further describe the control system and control method of an airborne air management system controller of the present invention.
[0124] Embodiment 1
[0125] Such as Figure 1Shown: A control system for an airborne air management system controller, including the local AMSC device and the opposite AMSC device; the hardware of the local AMSC device and the opposite AMSC device is exactly the same. The local AMSC device is connected to the opposite AMSC device via the CAN bus and the RS422 bus. Moreover, information interaction is carried out among the internal devices of the local AMSC device, the internal devices of the opposite AMSC device, and between the local AMSC device and the opposite AMSC device by means of data synchronization and status bit counting, so as to realize information interaction between the two control objects and meet the safety technical requirements of different levels and functions of the system.
[0126] Both the local AMSC device and the opposite AMSC device are respectively connected to the external motor system, airborne power supply system, and avionics system. And both the local AMSC device and the opposite AMSC device are connected with a debugging interface via the RS232 bus; the debugging interface is used for software debugging, software upgrade, software data loading, and transceiver control; the airborne power supply system is used to provide DC power for the local AMSC device and the opposite AMSC device; the motor system conducts analog signal interaction, digital signal interaction, discrete signal interaction, and optocoupler signal interaction with the local AMSC device and the opposite AMSC device respectively; the avionics system conducts data transmission interaction with the local AMSC device and the opposite AMSC device respectively via the ARINC429 bus.
[0127] The external cross-linking relationship of the control system of this airborne air management system controller is as Figure 1 shown. The local AMSC device and the opposite AMSC device are respectively connected to the electromechanical system via analog interfaces, discrete interfaces, and digital bus interfaces, connected to the airborne power supply system via DC power interfaces, and connected to the avionics system via the ARINC429 bus (digital information transmission system interface bus); the local AMSC device and the opposite AMSC device are connected to each other via the CAN bus (Controller Area Network AMSC, device local area network bus) and the RS422 bus (balanced voltage digital interface bus).
[0128] The main function design of the control system of this airborne air management system controller is as follows:
[0129] a) Signal acquisition function: Receive analog signals, optocoupler signals, and discrete signals from other system devices such as motors and sensors through analog interfaces and discrete interfaces, and realize signal digitization and storage through analog-to-digital circuit conversion.
[0130] b) Digital bus communication control function: The local AMSC device and the opposite AMSC device communicate with the motor system and the avionics system respectively via the CAN, RS422, and ARIINC429 digital buses, and transmit data through the transceiver bus.
[0131] c) Motor control function: The analog interface outputs the motor drive analog signal and the status indication discrete signal through the digital-to-analog conversion circuit, realizing the motor-related control functions.
[0132] d) Software loading and debugging function: It has the function of receiving and sending control and software loading data through the RS232 bus interface, realizing functions such as software debugging and software upgrade.
[0133] The hardware platform of the local AMSC device or the opposite AMSC device adopts a hardware architecture of DSP plus DSP architecture with MCU, and the internal communication of the device is carried out through the redundant backup method of the CAN bus and the I2C bus. For the specific architecture design, see Figure 2 As shown, the main functions of each component module of the local AMSC device or the opposite AMSC device are as follows:
[0134] a) A-channel module / B-channel module: The hardware designs of the A-channel module and the B-channel module are exactly the same, adopting the DSP hardware architecture, mainly realizing the control functions under normal conditions. The A-channel module and the B-channel module are backup to each other, and the CAN bus is used to synchronize the working states. As long as there is no hardware failure in one of the channels, the device can work normally.
[0135] b) S-channel module: The S-channel module adopts the hardware architecture design of MCU, which is independent and non-similar to the hardware of the A-channel module / B-channel module, and can effectively avoid common-mode failures. The S-channel module is a safety channel, and it monitors the status of the A-channel module / B-channel module through the I2C bus data at all times. If both the A-channel module and the B-channel module fail or extreme conditions such as ultra-low supply voltage occur, the S-channel module takes over all control functions, realizing the stable and safe output of the control signal of the motor system, and ensuring that no extreme situations such as unconventional, incorrect, and out-of-bounds occur.
[0136] c) Motherboard module: It is mainly used for signal isolation, caching of each interface, and distributing signals or instructions to each channel, and at the same time supplying power to the circuits of each channel.
[0137] d) Connector module: It is used as an external interface.
[0138] The interaction monitoring and processing principle between the local AMSC device and the opposite AMSC device is as follows:
[0139] The interaction between the local AMSC device and the opposite AMSC device, the internal interaction of the local AMSC device, or the internal interaction of the opposite AMSC device all adopt the synchronous status monitoring mechanism to achieve. The so-called synchronous status monitoring mechanism is to adopt the method of data synchronization and status bit counting to realize the information interaction between two control objects, meeting the safety technical requirements of different levels and functions of the system.
[0140] 1) Monitoring and Processing Mechanism for the Status of the Opposite - side AMSC Device
[0141] Before the local - side AMSC device communicates with the opposite - side AMSC device, it needs to first determine the working status of the opposite - side device.
[0142] When the following conditions are met simultaneously, the local - side AMSC device determines that the working status of the opposite - side AMSC device is normal:
[0143] a) The local - side AMSC device monitors that the discrete interface status of the opposite - side AMSC device is "on", indicating that the opposite - side AMSC device has been powered on;
[0144] b) The local - side AMSC device monitors that the synchronization status monitoring data sent by the opposite - side AMSC device is normal.
[0145] Similarly, when the following conditions are met simultaneously, the opposite - side AMSC device determines that the working status of the local - side AMSC device is normal; otherwise, it is abnormal;
[0146] a) The opposite - side AMSC device monitors that the discrete interface status of the local - side AMSC device is "on";
[0147] b) The opposite - side AMSC device monitors that the synchronization status monitoring data of the local - side AMSC device is normal.
[0148] When any of the following situations occurs, the local - side AMSC device determines that the opposite - side AMSC device is abnormal (similarly applicable to the opposite - side AMSC device's determination of the local - side AMSC device):
[0149] a) The local - side AMSC device monitors that the discrete interface status of the opposite - side AMSC device is "off", indicating that the opposite - side AMSC device has been powered off;
[0150] b) The local - side AMSC device monitors that the synchronization status monitoring data of the opposite - side AMSC device is abnormal.
[0151] The switching conditions for the local - side AMSC device to determine the opposite - side AMSC device as normal or abnormal are as follows:
[0152] When the following situations occur simultaneously, the local - side AMSC device can switch the status of the abnormal opposite - side AMSC device to the normal state (similarly applicable to the opposite - side AMSC device's determination of the local - side AMSC device):
[0153] a) The local - side AMSC device monitors that the discrete interface status of the opposite - side AMSC device is "on";
[0154] b) The local - side AMSC device receives at least 8 consecutive cycles of correct synchronization status monitoring data continuously transmitted from the opposite - side AMSC device.
[0155] When any of the following situations occurs, the local AMSC device can switch the status of the normal peer AMSC device to the abnormal status (similarly applicable to the determination of the local AMSC device by the peer AMSC device):
[0156] a) The local AMSC device monitors that the discrete interface status of the peer AMSC device is "off";
[0157] b) The local AMSC device monitors that all the synchronization status monitoring data sent by the peer AMSC device is 0;
[0158] c) The local AMSC device monitors that the positions of "1" in the synchronization status monitoring data sent by the peer AMSC device are incorrect;
[0159] d) The local AMSC device monitors that there are multiple "1"s in the synchronization status monitoring data sent by the peer AMSC device;
[0160] e) The local AMSC device does not receive the synchronization status monitoring data sent by the peer AMSC device for three consecutive seconds.
[0161] The communication processing mechanism between the local AMSC device and the peer AMSC device in the normal state is as follows:
[0162] In the normal synchronization status, the local AMSC device should:
[0163] a) The local AMSC device periodically sends synchronization status monitoring data to the peer AMSC device;
[0164] b) The local AMSC device continuously monitors the discrete interface status of the peer AMSC device;
[0165] c) The local AMSC device continuously monitors the periodic synchronization status monitoring data sent by the peer AMSC device.
[0166] The communication processing mechanism between the local AMSC device and the peer AMSC device in the abnormal situation is as follows:
[0167] First of all, if the discrete interface status of the peer AMSC device is "off" (i.e., the peer AMSC device has been shut down), the local AMSC device should:
[0168] a) The local AMSC device stops processing any data of the peer AMSC device;
[0169] b) The local AMSC device stops sending any data to the peer AMSC device;
[0170] c) The local AMSC device records the "peer AMSC device shutdown" fault event;
[0171] d) The local AMSC device continuously monitors the discrete interface status of the remote AMSC device.
[0172] Secondly, when the local AMSC device monitors that the discrete interface status of the remote AMSC device is "on" (i.e., the remote AMSC device is not shut down), but the monitored synchronization status monitoring data of the remote AMSC device is abnormal, the local AMSC device shall:
[0173] a) The local AMSC device stops processing other data sent by the remote AMSC device except for the synchronization status monitoring data until the synchronization status monitoring data is normal;
[0174] b) The local AMSC device stops sending any data to the remote AMSC device except for the synchronization status monitoring data;
[0175] c) The local AMSC device records the fault event corresponding to the abnormal synchronization status monitoring data of the remote AMSC device;
[0176] d) The local AMSC device continuously monitors the synchronization status monitoring data of the remote AMSC device;
[0177] e) The local AMSC device gives a prompt for the fault of the remote AMSC device.
[0178] As Figure 2 shown, the hardware of the local AMSC device and the remote AMSC device is exactly the same. Both the local AMSC device and the remote AMSC device respectively include: A channel module, B channel module, S channel module, motherboard module, connector module (since Figure 2 the internal hardware of the remote AMSC device in Figure 2 is exactly the same as the internal hardware of the local AMSC device, so
[0179] I). There are functions of mutual monitoring, mutual control, mutual switching, and mutual redundant backup between the A channel module and the B channel module; First, the A channel module and the B channel module mutually judge whether the working status of each other is normal;
[0180] When the following conditions are simultaneously met, the A channel module determines that the working status of the B channel module is normal, otherwise it is abnormal;
[0181] a) The A channel module monitors that the discrete interface status of the B channel module is "on";
[0182] b) The A channel module monitors that the synchronization status monitoring data of the B channel module is normal;
[0183] Similarly, when the following conditions are met simultaneously, the B-channel module determines that the working state of the A-channel module is normal; otherwise, it is abnormal.
[0184] a) The B-channel module monitors that the discrete interface state of the A-channel module is "open".
[0185] b) The B-channel module monitors that the synchronization status monitoring data of the A-channel module is normal.
[0186] II. When the A-channel module and the B-channel module mutually determine that the working state is normal, the following communication processing mechanism is adopted:
[0187] a) Periodically send synchronization status monitoring data to each other.
[0188] b) Continuously monitor the discrete interface state of the other party.
[0189] c) Continuously monitor the synchronization status monitoring data sent by the other party.
[0190] III. When the A-channel module and the B-channel module mutually determine that the working state of one of them is abnormal, the following communication processing mechanism is adopted:
[0191] If the normal channel module monitors that the discrete interface of the abnormal channel module is "closed", then:
[0192] a) The normal channel module stops processing any data sent by the abnormal channel module.
[0193] b) The normal channel module stops sending any data to the abnormal channel module.
[0194] c) The normal channel module records the fault event of the abnormal channel module being turned off.
[0195] If the normal channel module monitors that the discrete interface of the abnormal channel module is "open" and the synchronization status monitoring data is abnormal, then the following communication processing mechanism is adopted:
[0196] a) Start a three-second timer. The normal channel module stops processing other data sent by the abnormal channel module except for the synchronization status monitoring data until the synchronization status monitoring data is normal.
[0197] b) The normal channel module stops sending any data other than the synchronization status monitoring data to the abnormal channel module.
[0198] c) The normal channel module records the fault event corresponding to the abnormal synchronization status monitoring data of the abnormal channel module.
[0199] d) The normal channel module continuously monitors the synchronization status monitoring data of the abnormal channel module.
[0200] e) When the three - second timing is completed, if the synchronization status monitoring data is normal, a communication processing mechanism with a normal working state is adopted; otherwise, the normal channel module gives a prompt of abnormal channel module failure.
[0201] Generally, in this embodiment, the B channel module serves as the backup channel of the A channel module. If the B channel module detects that the discrete interface status of the A channel module is "off", the B channel module takes over the control channel function.
[0202] The S channel module serves as the safety channel of the A channel module and the B channel module. If the S channel module detects that the discrete interface statuses of both the A channel module and the B channel module are "off", it directly determines that both the A channel module and the B channel module are abnormal, and the S channel module takes over the control channel function; otherwise, the S channel module does not perform any processing.
[0203] As Figure 3 shown, the core interaction information of the control system of the airborne air management system controller of the present invention is realized through the monitoring data stream transmitted by the designed bus. The monitoring data stream is generated by each channel with its own status data commonality to its own channel, and after being processed by the channel with the current control authority, it is collected and distributed to the motherboard module (main board) for transmission through the connector interface. The data stream format definition standard for all the synchronization status monitoring data in the above - mentioned synchronization status monitoring process is as follows:
[0204] a) Byte frame header
[0205] Bytes 1 and 2 of the synchronization status monitoring data are the byte frame header, and the data is designed as 0x55, indicating the start of the data stream.
[0206] b) Byte status monitoring data
[0207] Bytes 3 to 14 of the synchronization status monitoring data are the status monitoring data, and only one byte in the data is 1. The data stream gradually offsets from the low - order byte to the high - order byte in a cycle; when the offset reaches the 14th byte, it starts to re - offset from the 9th byte.
[0208] For example, when the local AMSC device receives the synchronization status monitoring data of any cycle transmitted from the remote AMSC device, it can know the synchronization status monitoring data that the remote AMSC device will send in the next cycle, and accordingly can track and monitor whether the remote AMSC device is working properly.
[0209] c) Byte frame tail
[0210] Bytes 15 and 16 of the synchronization status monitoring data are the byte frame tail, and the data is designed as 0xAA, indicating the end of the data stream.
[0211] The above is the working process of the control system of the airborne air management system controller during normal operation. When the control system of the airborne air management system controller is powered on, since the entire control system takes a certain amount of time for initialization and self-check, during this period, the synchronization status monitoring data output by either the local AMSC device or the opposite-side AMSC device may be abnormal. Therefore, a power-on initialization self-check window period needs to be set for the entire control system. In this embodiment, a time window of a special processing mechanism during power-on with a length of ten seconds will be set. Within this ten-second time window, the local AMSC device will continuously monitor the opposite-side AMSC device, and the opposite-side AMSC device will also continuously monitor the local AMSC device. If abnormalities are detected within the time window period, prompts will be given to each other and monitoring will continue until the ten-second window period ends. If the monitoring is still abnormal, a fault alarm prompt will be given; if the monitoring is normal when the ten-second window period ends, it will directly enter the aforementioned normal processing mechanism.
[0212] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. It should be noted that any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be included within the protection scope of the present invention.
Claims
1. A control system for an onboard air management system controller, characterized in that: It includes an AMSC device on this side and an AMSC device on the opposite side; the AMSC device on this side and the AMSC device on the opposite side are respectively connected to an external motor system, an airborne power system, and an avionics system, and the AMSC device on this side and the AMSC device on the opposite side are connected to a debugging interface through an RS232 bus; the debugging interface is used for software debugging, software upgrading, software data loading, and transceiver control; the airborne power system is used to provide a DC power supply to the AMSC device on this side and the AMSC device on the opposite side; the motor system performs analog signal interaction, digital signal interaction, discrete signal interaction, and optical coupler signal interaction with the AMSC device on this side and the AMSC device on the opposite side; the avionics system performs data transmission interaction with the AMSC device on this side and the AMSC device on the opposite side through an ARINC429 bus; The hardware of the AMSC device on this side is completely consistent with that of the AMSC device on the opposite side. The AMSC device on this side is connected to the AMSC device on the opposite side using the CAN bus and the RS422 bus. The internal devices of the AMSC device on this side, the internal devices of the AMSC device on the opposite side, and the AMSC device on this side and the AMSC device on the opposite side all use data synchronization and status bit counting to exchange information, thereby realizing information exchange between the two control objects and meeting the security technical requirements of different levels and functions of the system. The specific process is as follows: 1) Before the local AMSC device communicates with the opposite AMSC device, they first determine whether the working status of each other is normal; When the following conditions are met at the same time, the AMSC device on this side determines that the working status of the AMSC device on the other side is normal, otherwise it is abnormal; a) The AMSC device on the local side monitors that the discrete interface status of the AMSC device on the opposite side is "open"; b) The synchronization status monitoring data of the AMSC device on the local side monitored by the AMSC device on the opposite side is normal; Similarly, when the following conditions are met at the same time, the AMSC device on the other side determines that the working status of the AMSC device on the local side is normal, otherwise it is abnormal; a) The AMSC device on the other side monitors that the discrete interface status of the AMSC device on the local side is "open"; b) The synchronization status monitoring data of the AMSC device on the opposite side monitored by the AMSC device on the local side is normal; 2) When the local AMSC device and the opposite AMSC device determine that the working status is normal, the following communication processing mechanism is adopted: a) Periodically send synchronization status monitoring data to each other; b) continuously monitor each other's discrete interface status; c) Continuously monitor the synchronization status monitoring data sent by each other; 3) When the local AMSC device and the opposite AMSC device mutually determine that one of them is in an abnormal working state, the following communication processing mechanism is adopted: If the normal AMSC device detects that the discrete interface of the abnormal AMSC device is "off", then: a) The normal AMSC equipment stops processing any data sent by the abnormal AMSC equipment; b) The normal AMSC equipment stops sending any data to the abnormal AMSC equipment; c) The normal AMSC equipment records the fault event of the abnormal AMSC equipment shutting down; If the normal AMSC device detects that the discrete interface of the abnormal AMSC device is "on" and the synchronization status monitoring data is abnormal, the following communication processing mechanism is adopted: a) The normal AMSC equipment stops processing other data except the synchronization status monitoring data sent by the abnormal AMSC equipment until the synchronization status monitoring data becomes normal; b) The normal AMSC equipment stops sending any data except synchronization status monitoring data to the abnormal AMSC equipment; c) The normal AMSC device records the fault event corresponding to the abnormal synchronization status monitoring data of the abnormal AMSC device; d) The normal AMSC equipment continuously monitors the synchronization status monitoring data of the abnormal AMSC equipment; e) The normal AMSC equipment gives a prompt of abnormal AMSC equipment failure.
2. The control system of an onboard air management system controller according to claim 1, characterized in that: The local AMSC device and the opposite AMSC device respectively include: an A channel module, a B channel module, an S channel module, a motherboard module, and a connector module; The hardware of the A channel module and the B channel module are completely consistent, and adopt the DSP hardware architecture. The A channel module and the B channel module back up each other and adopt the CAN bus synchronization circuit working state; The S channel module adopts the hardware architecture of MCU, and the hardware of the S channel module is independent and dissimilar to the hardware of the A channel module and the B channel module; the S channel module is a safety channel, and uses the I2C bus to monitor the status of the A channel module and the B channel module at all times; if both the A channel module and the B channel module fail, the S channel module takes over all control functions to achieve stable and safe output and interaction of the motor system; The motherboard module is used to provide the power delivered by the onboard power system to the A channel module, the B channel module, the S channel module, and the connector module, and is also used for signal isolation and signal buffering of each interface and signal distribution to each channel; The connector module is used as an external interface.
3. The control system of an onboard air management system controller according to claim 2, characterized in that: If an ultra-low voltage power supply occurs, the S channel module takes over all control functions and provides stable and safe output and interaction to the motor system.
4. The control system of the onboard air management system controller according to claim 3, characterized in that: When the normal AMSC device continuously monitors that the synchronization status monitoring data sent by the abnormal AMSC device is normal for eight consecutive cycles, it re-determines that the corresponding abnormal AMSC device is in a normal working state and restarts the communication processing mechanism when the working state is normal.
5. The control system of the onboard air management system controller according to claim 4, characterized in that: The internal devices of the AMSC device on this side use data synchronization and status bit counting to exchange information, realize information exchange between two control objects, and meet the security technical requirements of different levels and functions of the system. The specific process is as follows: 1) The A channel module and the B channel module have the functions of mutual monitoring, mutual control, mutual switching, and mutual redundancy backup; first, the A channel module and the B channel module determine whether each other's working status is normal; When the following conditions are met at the same time, the A channel module determines that the working status of the B channel module is normal, otherwise it is abnormal; a) The discrete interface status of the A channel module monitoring the B channel module is "open"; b) The synchronization status monitoring data of the A channel module to the B channel module is normal; Similarly, when the following conditions are met at the same time, the B channel module determines that the working status of the A channel module is normal, otherwise it is abnormal; a) The B channel module monitors the discrete interface status of the A channel module as "open"; b) The synchronization status monitoring data of the A channel module monitored by the B channel module is normal; 2) When the A channel module and the B channel module mutually determine that the working status is normal, the following communication processing mechanism is adopted: a) Periodically send synchronization status monitoring data to each other; b) continuously monitor each other's discrete interface status; c) Continuously monitor the synchronization status monitoring data sent by each other; 3) When the A channel module and the B channel module mutually determine that the working status of one of them is abnormal, the following communication processing mechanism is adopted: If the normal channel module detects that the discrete interface of the abnormal channel module is "off", then: a) The normal channel module stops processing any data sent by the abnormal channel module; b) The normal channel module stops sending any data to the abnormal channel module; c) The normal channel module records the fault event of the abnormal channel module being shut down; If the normal channel module detects that the discrete interface of the abnormal channel module is "open" and the synchronous status monitoring data is abnormal, the following communication processing mechanism is adopted: a) Start the three-second timer, and the normal channel module stops processing other data except the synchronization status monitoring data sent by the abnormal channel module until the synchronization status monitoring data is normal; b) The normal channel module stops sending any data except synchronization status monitoring data to the abnormal channel module; c) The normal channel module records the fault event corresponding to the abnormal synchronization status monitoring data of the abnormal channel module; d) The normal channel module continuously monitors the synchronization status monitoring data of the abnormal channel module; e) When the three-second timing is completed, if the synchronization status monitoring data is normal, the communication processing mechanism with normal working status is adopted, otherwise, the normal channel module gives a prompt of abnormal channel module failure.
6. The control system of the onboard air management system controller according to claim 5, characterized in that: The S channel module serves as a safety channel. When the S channel module detects that both the A channel module and the B channel module are abnormal, the S channel module takes over all control functions to achieve stable and safe output and interaction of the motor system. Otherwise, the S channel module does not perform any processing.
7. The control system of the onboard air management system controller according to claim 6, characterized in that: The internal devices of the opposite AMSC device use data synchronization and status bit counting to perform information exchange, realize information exchange between the two control objects, and meet the security technical requirements of different levels and functions of the system. The specific process is as follows: 1) The A channel module and the B channel module have the functions of mutual monitoring, mutual control, mutual switching, and mutual redundancy backup; first, the A channel module and the B channel module determine whether each other's working status is normal; When the following conditions are met at the same time, the A channel module determines that the working status of the B channel module is normal, otherwise it is abnormal; a) The discrete interface status of the A channel module monitoring the B channel module is "open"; b) The synchronization status monitoring data of the A channel module to the B channel module is normal; Similarly, when the following conditions are met at the same time, the B channel module determines that the working status of the A channel module is normal, otherwise it is abnormal; a) The B channel module monitors the discrete interface status of the A channel module as "open"; b) The synchronization status monitoring data of the A channel module monitored by the B channel module is normal; 2) When the A channel module and the B channel module mutually determine that the working status is normal, the following communication processing mechanism is adopted: a) Periodically send synchronization status monitoring data to each other; b) continuously monitor each other's discrete interface status; c) Continuously monitor the synchronization status monitoring data sent by each other; 3) When the A channel module and the B channel module mutually determine that the working status of one of them is abnormal, the following communication processing mechanism is adopted: If the normal channel module detects that the discrete interface of the abnormal channel module is "off", then: a) The normal channel module stops processing any data sent by the abnormal channel module; b) The normal channel module stops sending any data to the abnormal channel module; c) The normal channel module records the fault event of the abnormal channel module being shut down; If the normal channel module detects that the discrete interface of the abnormal channel module is "open" and the synchronous status monitoring data is abnormal, the following communication processing mechanism is adopted: a) Start the three-second timer, and the normal channel module stops processing other data except the synchronization status monitoring data sent by the abnormal channel module until the synchronization status monitoring data is normal; b) The normal channel module stops sending any data except synchronization status monitoring data to the abnormal channel module; c) The normal channel module records the fault event corresponding to the abnormal synchronization status monitoring data of the abnormal channel module; d) The normal channel module continuously monitors the synchronization status monitoring data of the abnormal channel module; e) When the three-second timing is completed, if the synchronization status monitoring data is normal, the communication processing mechanism with normal working status is adopted, otherwise, the normal channel module gives a prompt of abnormal channel module failure.
8. A control system of an onboard air management system controller according to any one of claims 1 to 7, characterized in that: The data stream format definition of all synchronization status monitoring data adopts the following standards: Data byte 1 and data byte 2 are byte frame headers, and the data is designed to be 0x55, indicating the start of the data stream; Data byte 3 to data byte 14 are byte status monitoring data. Only one byte in the data is 1. The data stream gradually decreases from the low byte to the high byte in a cycle. When it shifts to the 14th byte, it shifts again from the 9th byte. Data byte 15 and data byte 16 are the byte frame tail, and the data is designed to be 0xAA, indicating the end of the data stream.
9. A control method for an onboard air management system controller, characterized in that: It includes the following steps: First, perform initialization and self-test. During the initialization and self-test process, a ten-second time window is set. During this ten-second time window, the following processing is continuously performed: 1) Before the local AMSC device communicates with the opposite AMSC device, they first determine whether the working status of each other is normal; When the following conditions are met at the same time, the AMSC device on this side determines that the working status of the AMSC device on the other side is normal, otherwise it is abnormal; a) The AMSC device on the local side monitors that the discrete interface status of the AMSC device on the opposite side is "open"; b) The synchronization status monitoring data of the AMSC device on the local side monitored by the AMSC device on the opposite side is normal; Similarly, when the following conditions are met at the same time, the AMSC device on the other side determines that the working status of the AMSC device on the local side is normal, otherwise it is abnormal; a) The AMSC device on the other side monitors that the discrete interface status of the AMSC device on the local side is "open"; b) The synchronization status monitoring data of the AMSC device on the opposite side monitored by the AMSC device on the local side is normal; 2) When the local AMSC device and the opposite AMSC device determine that the working status is normal, the following communication processing mechanism is adopted: a) Periodically send synchronization status monitoring data to each other; b) continuously monitor each other's discrete interface status; c) Continuously monitor the synchronization status monitoring data sent by each other; 3) When the local AMSC device and the opposite AMSC device mutually determine that one of them is in an abnormal working state, the following communication processing mechanism is adopted: If the normal AMSC device detects that the discrete interface of the abnormal AMSC device is "off", then: a) The normal AMSC equipment stops processing any data sent by the abnormal AMSC equipment; b) The normal AMSC equipment stops sending any data to the abnormal AMSC equipment; c) The normal AMSC equipment records the fault event of the abnormal AMSC equipment shutting down; If the normal AMSC device detects that the discrete interface of the abnormal AMSC device is "on" and the synchronization status monitoring data is abnormal, the following communication processing mechanism is adopted: a) The normal AMSC equipment stops processing other data except the synchronization status monitoring data sent by the abnormal AMSC equipment until the synchronization status monitoring data becomes normal; b) The normal AMSC equipment stops sending any data except synchronization status monitoring data to the abnormal AMSC equipment; c) The normal AMSC device records the fault event corresponding to the abnormal synchronization status monitoring data of the abnormal AMSC device; d) The normal AMSC equipment continuously monitors the synchronization status monitoring data of the abnormal AMSC equipment; e) Normal AMSC equipment gives a prompt of abnormal AMSC equipment failure; f) When the normal AMSC device continuously monitors that the synchronization status monitoring data sent by the abnormal AMSC device is normal for eight consecutive cycles, it re-determines that the corresponding abnormal AMSC device is in a normal working state, and restarts the communication processing mechanism when the working state is normal.
Citation Information
Patent Citations
Environmental control integrated controller and control method
CN112666864A
Redundant design valve control system and control method thereof
CN114484056A