STPA-based multi-control-surface aircraft control distribution function design method and device
The design of aircraft control and allocation function through the STPA-based method solves the problem of poor safety in traditional methods and achieves higher safety and airworthiness.
Patent Information
- Application Number
- CN202510037207.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-01-09
AI Technical Summary
The traditional dynamic control allocation method lacks a risk factor-based design in the aircraft control system, resulting in poor safety.
The aircraft control allocation function design is used based on STPA. Through mathematical modeling, control law design, division of unsafe control behaviors and identification of potential dangerous behaviors, control allocation is adjusted to avoid dangerous causes.
Improves the safety of the aircraft, reduces potential dangers, and meets airworthiness safety requirements.
Smart Images

Figure CN120010536A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of aircraft design, and for example, to a method and device for designing control allocation functions of a multi-control surface aircraft based on STPA. Background Art
[0002] Aircraft three-axis control refers to the stability and maneuverability of pitch, roll, and yaw, and is a key function of the aircraft flight control system. In the early days, this function was implemented by mechanical linkages, with ailerons controlling roll, elevators controlling pitch, and rudders controlling heading. With the promotion of application needs and the development of aviation technology, the control and manipulation of aircraft have become more complex, and the flight control system has also changed from mechanical to fly-by-wire, which can adapt to more complex aircraft configurations. In order to solve some aircraft drive control and control axis coupling problems, the control allocation function was introduced into the fly-by-wire flight control system. Dynamic control allocation can optimize the allocation of control instructions to different actuators while considering position constraints and speed constraints. Common control allocation methods include allocation algorithms based on generalized inverse, allocation algorithms based on actuator reachable sets, and control allocation methods based on optimization methods.
[0003] The dynamic control allocation method was first applied to military aircraft, such as the F-16, X-35B, and F-35. For civil aircraft, the introduction of dynamic control allocation can not only enhance maneuverability and flight performance, but also increase a certain degree of fault tolerance. Computational analysis shows that many civil aviation accidents in history, such as the American Airlines Flight 191 accident, the Japan Airlines Flight JL123 accident, the American Airlines Flight 427, and the United Airlines Flight 585 accident, can be avoided by integrating and allocating the remaining control capabilities. In addition, some new configurations of civil aircraft also require dynamic control allocation functions, such as distributed electric propulsion aircraft and electric vertical take-off and landing aircraft.
[0004] For civil aircraft, the introduction of new functions in the flight control system needs to meet the corresponding airworthiness safety clauses. For transport aircraft, in addition to stipulating that the system design must ensure that the intended functions can be completed under various foreseeable operating conditions, Article 25.1309 also states that the design of the aircraft system and related components, when considered alone or together with other systems, the probability of any failure state that prevents the aircraft from continuing to fly and land safely is extremely unlikely. Therefore, the introduction of dynamic control allocation functions in the flight control system requires sufficient analysis and evaluation, and it can only be put into operation if it meets airworthiness requirements to avoid catastrophic accidents.
[0005] The hazard analysis process is an important means to ensure that the basis for airworthiness certification is sufficient. Common methods include functional hazard analysis, hazard and operability analysis, and system theory process analysis. Among them, STPA was proposed by Nancy Leveson et al., which aims to evaluate relatively complex safety systems and determine safety constraints and requirements. Compared with traditional hazard analysis methods, STPA can take into account software and human factors in the analysis process, and the analysis process is not limited to failure analysis, but can analyze the problem of insufficient system function (or weakness), which is suitable for the risk identification of novel design features of aircraft. In the aviation field, STPA has a wide range of applications. Based on the STPA method, the aircraft air management system is analyzed, and the emergency behavior caused by the interaction between system components is successfully captured through a structured and systematic process. STPA is applied to neural network control systems under runtime guarantee constraints. The safety constraint identification and runtime guarantee development problems of deep reinforcement learning tactical autopilots using neural network control systems are considered. A civil aircraft system safety analysis method based on improved FRAM-STPA is proposed to identify key system safety and provide quantitative indicators. Based on STPA, the TOPAZ method is used to quantitatively describe the impact of risk factors on the safety of flight control systems, and this method is applied in the safety analysis of UAV conflict resolution.
[0006] In the prior art, dynamic control allocation focuses on algorithm innovation and performance improvement, but does not design the control allocation function of the aircraft based on risk factors. Summary of the invention
[0007] In order to provide a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. The summary is not an extensive review, nor is it intended to identify key / critical components or delineate the scope of protection of these embodiments, but rather serves as a prelude to the detailed description that follows.
[0008] Traditional dynamic control allocation focuses on algorithm innovation and performance improvement, but lacks a method to design the control allocation function of the aircraft based on risk factors. Therefore, the traditional dynamic control allocation design method has the problem of poor safety.
[0009] In some embodiments, a method for designing a multi-control surface aircraft control allocation function based on STPA is provided, the method comprising:
[0010] Performing mathematical modeling on the target aircraft to obtain a mathematical modeling of the target aircraft;
[0011] Mathematical modeling of the target aircraft is used to design control laws and control allocation;
[0012] The types of unsafe control actions are divided according to the STPA analysis method, and potential dangerous actions are identified according to the type of each unsafe control action. The potential dangerous actions are represented by flight status influencing factors or control quality influencing factors.
[0013] Analyze the risk factors corresponding to potential risk scenarios;
[0014] Adjust control allocation based on hazard causes.
[0015] Preferably, there are four specific types of unsafe control behaviors divided according to the STPA analysis method, including: UCA1, no control action is provided; UCA2, providing control action leads to harm; UCA3, providing control action too early, too late or in the wrong time sequence; UCA4, control action lasts too long or ends too early.
[0016] Preferably, the flight status influencing factors include: any one or more parameters of speed, roll, sideslip, and disturbed deviation.
[0017] Preferably, the factors affecting the distribution quality are controlled: any one or more parameters of the distribution space, distribution error, and instruction time.
[0018] Preferably, UCA1, which does not provide a control action, includes any one or more of approaching a stall, approaching a rolling airworthy range, approaching a sideslip airworthy range, and being disturbed and deviating from the trim state.
[0019] Preferably, UCA2 provides control actions that cause hazards, including: allocating instructions beyond the reachable set, allocating instructions with too large an error that results in failure to meet control allocation requirements, and control causing the aircraft to exceed operating boundaries and flight envelopes, any one or more of the following.
[0020] Preferably, UCA3 provides control actions that are too early, too late or in the wrong time sequence, including: allocation instructions are updated too late / delayed.
[0021] Preferably, UCA4, the control action lasts too long or ends too early, includes any one or more of: the distribution instruction lasts too long and the distribution instruction ends too early.
[0022] Preferably, to adjust the control allocation, including:
[0023] Perform limiting error identification, perform data preprocessing, improve fault detection and isolation performance, and increase weight scheduling based on flight status, or any one or more of the above.
[0024] In some embodiments, a multi-control surface aircraft control allocation function design device based on STPA is disclosed, comprising:
[0025] A mathematical modeling module is configured to perform mathematical modeling on the target aircraft to obtain a mathematical modeling of the target aircraft;
[0026] An aircraft design module configured to perform control law design and control allocation for mathematical modeling of a target aircraft;
[0027] The STPA analysis module is configured to classify the types of unsafe control behaviors according to the STPA analysis method, and identify potential dangerous behaviors according to the type of each unsafe control behavior, wherein the potential dangerous behaviors are represented by flight state influencing factors or control quality influencing factors;
[0028] A risk cause analysis module is configured to analyze risk causes corresponding to potential risk scenarios;
[0029] The control allocation adjustment module is configured to adjust the control allocation according to the risk cause.
[0030] The present disclosure provides a method and device for designing a multi-control surface aircraft control allocation function based on STPA, which can achieve the following technical effects:
[0031] The disclosed embodiment uses the STPA analysis method to infer potential dangerous behaviors, and then analyzes the dangerous causes corresponding to the potential dangerous scenarios, and adjusts the control allocation from the perspective of avoiding the dangerous causes. Therefore, the potential dangers of the aircraft are reduced from the design aspect, and the safety of the aircraft is improved.
[0032] The above general description and the following description are exemplary and explanatory only and are not intended to limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] One or more embodiments are exemplarily described by corresponding drawings, which do not limit the embodiments. Elements with the same reference numerals in the drawings are shown as similar elements, and the drawings do not constitute a scale limitation, and wherein:
[0034] Figure 1 is a flow chart of a method for designing a multi-control surface aircraft control allocation function based on STPA provided by an embodiment of the present disclosure;
[0035] Figure 2 is a schematic diagram of a control surface of a multi-control surface aircraft provided by an embodiment of the present disclosure;
[0036] Figure 3 is a schematic diagram of a flight control structure provided by an embodiment of the present disclosure;
[0037] Figure 4 is a schematic diagram of a dynamic inverse algorithm framework provided by an embodiment of the present disclosure;
[0038] Figure 5 is a control structure diagram of a flight control system provided by an embodiment of the present disclosure;
[0039] Figure 6 This is a schematic diagram of the proportion of virtual control instruction allocation space provided by an embodiment of the present disclosure;
[0040] Figure 7 is a schematic diagram of possible risk-causing factors provided by an embodiment of the present disclosure;
[0041] Figure 8-a It is a schematic diagram of inaccurate modeling data provided by an embodiment of the present disclosure;
[0042] Figure 8-b is another schematic diagram of inaccurate modeling data provided by an embodiment of the present disclosure;
[0043] Figure 9-a This is a schematic diagram of abnormal data reception provided by an embodiment of the present disclosure;
[0044] Figure 9-b is another schematic diagram of abnormal received data provided by an embodiment of the present disclosure;
[0045] Figure 10-a This is a schematic diagram of unreasonable weight setting provided by an embodiment of the present disclosure;
[0046] Figure 10-b This is another schematic diagram of unreasonable weight setting provided by an embodiment of the present disclosure;
[0047] Figure 11-a is a schematic diagram of a control efficiency matrix error provided by an embodiment of the present disclosure;
[0048] Figure 11-b is another control efficiency matrix error schematic diagram provided by an embodiment of the present disclosure;
[0049] Figure 12-a This is a schematic diagram of an extreme deviation fault provided by an embodiment of the present disclosure;
[0050] Figure 12-b is another extreme deviation fault schematic diagram provided by an embodiment of the present disclosure;
[0051] Figure 13-a is a schematic diagram of external wind interference provided by an embodiment of the present disclosure;
[0052] Figure 13-b is another schematic diagram of external wind interference provided by an embodiment of the present disclosure;
[0053] Fig.14It is a schematic diagram of a multi-control surface aircraft control allocation function design device based on STPA provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0054] In order to be able to understand the features and technical contents of the embodiments of the present disclosure in more detail, the implementation of the embodiments of the present disclosure is described in detail below in conjunction with the accompanying drawings. The attached drawings are for reference only and are not used to limit the embodiments of the present disclosure. In the following technical description, for the convenience of explanation, a full understanding of the disclosed embodiments is provided through multiple details. However, one or more embodiments can still be implemented without these details. In other cases, to simplify the drawings, well-known structures and devices can be simplified for display.
[0055] The following description and accompanying drawings fully illustrate specific embodiments of the present invention so that those skilled in the art can practice them. Other embodiments may include structural, logical, electrical, process and other changes. The examples represent possible changes only. Unless explicitly required, separate components and functions are optional, and the order of operations may vary. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. The scope of the embodiments of the present invention includes the entire scope of the claims, and all available equivalents of the claims. In this application, each embodiment may be represented individually or generally by the term "invention", which is only for convenience, and if more than one invention is disclosed in fact, it is not intended to automatically limit the scope of the application to any single invention or inventive concept. In this application, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, without requiring or implying any actual relationship or order between these entities or operations. Moreover, the terms "comprises", "includes" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method or device. In the absence of further restrictions, the elements defined by the sentence "including a ..." do not exclude the presence of other identical elements in the process, method or device including the elements. In this application, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments, and the same and similar parts between the embodiments can be referred to each other. For the methods, products, etc. disclosed in the embodiments, since they correspond to the method part disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method part description.
[0056] Traditional dynamic control allocation focuses on algorithm innovation and performance improvement, but lacks a method to design the control allocation function of the aircraft based on risk factors. Therefore, the traditional dynamic control allocation design method has the problem of poor safety.
[0057] In order to solve the problems existing in the related art, the embodiments of the present disclosure provide a method and device for designing the control allocation function of a multi-control surface aircraft based on STPA. The STPA analysis method is used to infer the potential dangerous behavior, and then the dangerous causes corresponding to the potential dangerous scenes are analyzed, and the control allocation is adjusted from the perspective of avoiding the dangerous causes. Therefore, the potential dangers of the aircraft are reduced from the design aspect, and the safety of the aircraft is improved.
[0058] Combination Figure 1 As shown, the embodiment of the present disclosure provides a flow chart of a method for designing a control allocation function of a multi-control surface aircraft based on STPA, including:
[0059] S100, performing mathematical modeling on the target aircraft to obtain a mathematical modeling of the target aircraft.
[0060] A multi-control surface aircraft is taken as the research object. The aircraft control surface layout is as follows Figure 2 As shown, the aircraft is equipped with 4 pieces / two pairs of ailerons, 4 pieces / two pairs of elevators, 2 rudders and 1 horizontal stabilizer.
[0061] The linear state space mathematical model of the aircraft is shown in equation (1).
[0062]
[0063] Where x∈R n is the system state vector; u∈R m is the system input vector; y∈R n is the system output; A∈R n×n is the system matrix; B∈R n×m is the control efficiency matrix, C∈R n ,D∈R n×m is the control input matrix. Where x can be expressed as:
[0064] x=[pqr V T αβφθψ] T (2)
[0065] In formula (2), p, q, r are the roll angular velocity, pitch angular velocity, and yaw angular velocity respectively; V T is the airspeed; α, β are the angle of attack and sideslip angle respectively; φ, θ, ψ are the roll angle, pitch angle and yaw angle respectively. u in formula (1) can be expressed as:
[0066] u=[δaor δ aol δ air δ ail δ eor δ eol δ eir δ eil δ ih δ ur δ dr ] T (3)
[0067] In the above formula, δ aor ,δ aol They are the right and left outboard ailerons respectively; δ air ,δ ail are the right and left inner chord ailerons respectively; δ eor ,δ eol are the right and left outboard elevators respectively; δ eir ,δ eil are the right and left inboard elevators respectively; δ ih is the horizontal stabilizer, δ ur ,δ dr They are the up and down rudder respectively.
[0068] S200, mathematical modeling of the target aircraft is used to perform control law design and control allocation.
[0069] Specifically, according to the above mathematical model, the flight control structure is designed as follows: Figure 3 shown.
[0070] The control law is designed as follows: the input generates the required virtual control instructions, the control distributor distributes the virtual instructions to the aircraft control surfaces, and finally the fault detection module is responsible for detecting whether the flight control system has a fault. Once detected, the system effectiveness matrix will be estimated in real time and fed back to the control distributor in time to reallocate the control surfaces.
[0071] The control law design is based on the dynamic inverse algorithm, as shown in equation (4):
[0072]
[0073] In the formula is a virtual control instruction, u0 is the system input at the previous moment, Δu is the input difference that the system needs to increase at this time, and the instruction is generated by the PI control law.
[0074]
[0075] Using the data from the last moment and the computer offline storage model CB, we can know the current control variable cv nom .
[0076] cvnom =CAx+CBu0 (6)
[0077] Finally, the gain matrix P is introduced to calculate the actuator deflection to achieve control allocation, as shown in the following equation. The calculation of P will be given in 1.2.3.
[0078]
[0079] The dynamic control allocation is designed as follows: The pseudo-inverse method is widely used in the aviation field due to its simplicity and practicality, but it cannot handle the physical limitations of the actuator. The allocation algorithm based on optimization can better handle the constraint problem, but the large amount of calculation cannot guarantee real-time performance, and the uncertainty of the algorithm currently does not meet the airworthiness certification requirements. Therefore, this application adopts a weighted pseudo-inverse allocation method based on a quadratic cost function. This method can find a unique control input combination that can not only meet the required control effect, but also optimize the cost function. The algorithm is shown in equation (8).
[0080]
[0081] In formula (8), Δup is the selected value of the deflection increment to reduce the amount of calculation of the optimization function, and Δd is the increment of the desired control command. p The control efficiency matrix directly reflects the relationship between the deflection angle of the control surface and the control torque that can be generated. Since the deflection rate limits of different control surfaces of the aircraft are different, given different weights of the control surfaces, the actuator deflection limit is introduced to obtain
[0082]
[0083] Then the solution of the gain matrix P when the flight control system is overdriven is
[0084] P=(Wp T ) -1 B T (B(Wp T ) -1 B T ) -1 (10)
[0085] In summary, the entire flight control system algorithm framework is as follows Figure 4 shown.
[0086] S300, classifying the types of unsafe control behaviors according to the STPA analysis method, and identifying potential dangerous behaviors according to the type of each unsafe control behavior, wherein the potential dangerous behaviors are represented by flight state influencing factors or control quality influencing factors.
[0087] It should be understood that there are four specific types of unsafe control behaviors classified according to the STPA analysis method, including: UCA1, no control action is provided; UCA2, providing control action leads to hazards; UCA3, providing control action too early, too late or in the wrong time sequence; UCA4, control action lasts too long or ends too early.
[0088] The control algorithm itself uses the functional control structure for STPA analysis. The STPA control structure of the flight control system is as follows: Figure 5 As shown. Figure 5 In the present invention, pseudo control instructions are introduced to separate the tracking of pilot instructions from the control allocation. The task of tracking pilot instructions is generated by the control law module to generate the expected virtual control instructions, and the control input required by the actuator can be generated according to the expected virtual control instructions.
[0089] Unacceptable behaviors are defined at the aircraft level and the control system level. The corresponding influencing factors are flight status influencing factors and control allocation quality influencing factors.
[0090] The factors affecting the flight status include: any one or more parameters of speed, roll, sideslip, and disturbance deviation. The corresponding flight performance and control stability characteristics have clear restrictions, including:
[0091] Stalling Conditions: It must be possible to quickly prevent and recover from a stall with normal control.
[0092] Roll over limit: The aircraft must meet roll attitude limits under certain conditions, such as the roll cannot exceed 45° in the event of a critical engine failure.
[0093] Sideslip limit: The aircraft must meet the sideslip limit under certain conditions. For example, in non-low-speed landing or non-high wind conditions, the sideslip angle should be maintained within 15°.
[0094] Trim state: After the aircraft is trimmed, it should be able to maintain the trim state without receiving other control commands.
[0095] Control the factors affecting the allocation quality: any one or more parameters of allocation space, allocation error, and instruction time.
[0096] Specifically, starting from the control allocation function and algorithm, the following allocation qualities should be met:
[0097] Distribution error: The norm of the difference between the expected control command and the actual output, including angle error and length error.
[0098] e=||Bu-v des || (11)
[0099] Allocation space: The set of control instructions, the size of the set is measured by the ratio between the reachable set and the algorithm allocation space is as follows Figure 6 shown.
[0100] Allocation time: After the flight control system gives the desired torque, the time consumed by the algorithm to calculate the control instructions, specifically refers to the online calculation time.
[0101] The acceptability of the actuator commands generated by the control assignment is constrained by the control quality requirements of the entire control loop. The acceptable control quality is defined as follows:
[0102] Steady-state error: e ss ≤0.01rad / s
[0103] Tracking error: max(e track )≤0.02rad / s
[0104] Rise time: t r ≤2s.
[0105] The identification of unsafe control actions in STPA is the beginning of knowledge analysis, and the ultimate goal is to identify all scenarios that may lead to corresponding unsafe control actions. The specific scenarios analyzed correspond to the following Table 1.
[0106] Table 1
[0107]
[0108]
[0109] Through simulation, the UCAs that failed to achieve the system performance indicators are shown in Table 2. Table 2 summarizes the identified dangerous control actions. Once unsafe control actions are identified, they can be converted into constraints.
[0110] Table 2
[0111]
[0112]
[0113] S400: Analyze the risk factors corresponding to the potential risk scenario.
[0114] After determining the possible UCA in the control allocation part, it is necessary to further analyze the Hazard Casual Factor (HCF) that causes the corresponding action, so as to fully guide the design to eliminate or suppress potential dangerous behaviors. Figure 7 , is a schematic diagram of possible risk factors, where: Figure 7 The numbers in are the serial numbers of typical hazard cause types.
[0115] Analysis of the causes of UCA1 hazards: For UCA1, the control allocation solution of multi-actuator control may encounter a singular problem of inversion, resulting in no solution to the algorithm and inability to generate allocation instructions based on the algorithm.
[0116] UCA2 Hazard Cause Analysis: The calculation of control allocation depends on the control command input, while the calculation of the dynamic inverse control law depends on the accuracy of the model. The allocation module can only return the solution closest to the optimization target. Figure 8-a and Figure 8-b It is shown that the flight control system modeling is inaccurate. Taking the inaccurate system matrix A as an example, it is obvious that the virtual control instructions exceed the reachable set range.
[0117] Data anomalies will prevent the allocation algorithm from obtaining the normal aircraft status, causing the generated virtual control instructions to exceed the upper and lower limits of the reachable set. Figure 9-a and Figure 9-b A simulation diagram showing the situation where the data received by the control law module is interfered by non-command signals.
[0118] Due to inappropriate weight setting, the control surface with high operating efficiency enters saturation prematurely, which leads to the inconsistency between the virtual control command output and the expected control command direction. Figure 10-a and Figure 10-b Taking the simulation in Figure 2 as an example, the unreasonable increase in the proportion of the horizontal stabilizer in the weight makes the proportion of the elevator / rudder too low when the allocation algorithm is allocated, and the expected control instructions cannot be achieved.
[0119] The uncertainty of the control efficiency matrix comes from the uncertain state of the aircraft, the change of parameters, the interference of the external environment, etc., which will cause the control efficiency matrix to be inconsistent with the actual situation, thus causing allocation errors. Figure 11-a and Figure 11-b The display shows the control surface allocation error that occurs when the control efficiency matrix is inconsistent with the model.
[0120] UCA3 hazard cause analysis: Real-time performance cannot be guaranteed when there is a delay in fault detection, which leads to delayed instruction allocation. Figure 12-a and Figure 12-b When an extreme deflection failure occurs on the center control surface, with the right outer elevator deflected to 17° / -23° and the right outer aileron deflected to -12° / 15°, the flight control system cannot detect the control surface failure in time, so there may be a delay in allocating instructions.
[0121] UCA4 hazard cause analysis: The flight control system was disturbed by the external wind. The flight control system could not converge under the interference of the external environment. It was necessary to control the distribution of continuous instructions to make the flight control system close to stability. Figure 13-a and Figure 13-bThis is a simulation diagram with the Dryden turbulence model added.
[0122] Based on the above analysis, the risk factors of UCA are shown in Table 3. It should be noted that the typical risk factors in Table 3 are different from Figure 7 The serial numbers of the typical hazard cause types correspond to those in the table.
[0123] Table 3
[0124]
[0125] Based on the results in Table 3, the fly-by-wire flight control system can focus on the corresponding dangerous causes that may lead to UCA from the early stage of introducing the control allocation algorithm.
[0126] S500, adjusts control allocation according to the cause of the hazard.
[0127] To adjust the control allocation, including: any one or more of: identifying limiting errors, performing data preprocessing, improving fault detection and isolation performance, and increasing weight scheduling based on flight status.
[0128] For example, in order to adapt to sudden changes in the external environment, the control allocation needs to be adjusted to make it more robust.
[0129] Fig.14 A multi-control surface aircraft control allocation function design device based on STPA according to an embodiment of the present invention is shown, and the device includes:
[0130] A mathematical modeling module is configured to perform mathematical modeling on the target aircraft to obtain a mathematical modeling of the target aircraft;
[0131] An aircraft design module configured to perform control law design and control allocation for mathematical modeling of a target aircraft;
[0132] The STPA analysis module is configured to classify the types of unsafe control behaviors according to the STPA analysis method, and identify potential dangerous behaviors according to the type of each unsafe control behavior, wherein the potential dangerous behaviors are represented by flight state influencing factors or control quality influencing factors;
[0133] A risk cause analysis module is configured to analyze risk causes corresponding to potential risk scenarios;
[0134] The control allocation adjustment module is configured to adjust the control allocation according to the risk cause.
[0135] Traditional dynamic control allocation focuses on algorithm innovation and performance improvement, but lacks the design of aircraft control allocation function based on risk factors. Therefore, traditional dynamic control allocation has the problem of poor safety.
[0136] The above description and the accompanying drawings fully illustrate the embodiments of the present disclosure so that those skilled in the art can practice them. Other embodiments may include structural, logical, electrical, process and other changes. The embodiments represent only possible changes. Unless explicitly required, separate components and functions are optional, and the order of operation may vary. The parts and features of some embodiments may be included in or replace the parts and features of other embodiments. Moreover, the words used in this application are only used to describe the embodiments and are not used to limit the claims. As used in the description of the embodiments and the claims, unless the context clearly indicates, the singular forms of "a", "an" and "the" are intended to include plural forms as well. Similarly, the term "and / or" as used in this application refers to any and all possible combinations of listings containing one or more associated ones. In addition, when used in the present application, the term "comprise" and its variants "comprises" and / or comprising refer to the presence of stated features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or groups thereof. In the absence of further restrictions, the elements defined by the sentence "comprising a ..." do not exclude the presence of other identical elements in the process, method or device comprising the elements. In the present application, each embodiment may focus on the differences from other embodiments, and the same and similar parts between the embodiments may refer to each other. For the methods, products, etc. disclosed in the embodiments, if they correspond to the method part disclosed in the embodiments, the relevant parts may refer to the description of the method part.
[0137] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in this application can be implemented with electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software may depend on the specific application and design constraints of the technical solution. The technicians may use different methods for each specific application to implement the described functions, but such implementations should not be considered to exceed the scope of the embodiments of the present disclosure. The technicians may clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices, devices and units may refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here.
[0138] The flowchart and block diagram in the accompanying drawings show the possible architecture, functions and operations of the device, method and computer program product according to the embodiment of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. In some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, which can depend on the functions involved. In the description corresponding to the flowchart and the block diagram in the accompanying drawings, the operations or steps corresponding to different boxes can also occur in an order different from that disclosed in the description, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, which can depend on the functions involved. Each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by dedicated hardware-based devices that perform the specified functions or actions, or may be implemented by a combination of dedicated hardware and computer instructions.
Claims
1. A multi-control surface aircraft control allocation function design method based on STPA, characterized in that: The method comprises: Performing mathematical modeling on the target aircraft to obtain a mathematical modeling of the target aircraft; Mathematical modeling of the target aircraft is used to design control laws and control allocation; The types of unsafe control actions are divided according to the STPA analysis method, and potential dangerous actions are identified according to the type of each unsafe control action. The potential dangerous actions are represented by flight status influencing factors or control quality influencing factors. Analyze the risk factors corresponding to potential risk scenarios; Adjust control allocation based on hazard causes.
2. The multi-control surface aircraft control allocation function design method based on STPA according to claim 1 is characterized in that: According to the STPA analysis method, there are four specific types of unsafe control behaviors, including: UCA1, no control action is provided; UCA2, providing control action leads to hazards; UCA3, providing control action too early, too late or in the wrong time sequence; UCA4, control action lasts too long or ends too early.
3. The multi-control surface aircraft control allocation function design method based on STPA according to claim 2 is characterized in that: Flight status influencing factors include: any one or more parameters of speed, roll, sideslip, and disturbance deviation.
4. The multi-control surface aircraft control allocation function design method based on STPA according to claim 3 is characterized in that: Control the factors affecting the allocation quality: any one or more parameters of allocation space, allocation error, and instruction time.
5. The multi-control surface aircraft control allocation function design method based on STPA according to claim 4 is characterized in that: UCA1, no control action is provided, including: approaching stall, approaching rolling airworthiness range, approaching sideslip airworthiness range and any one or more of the disturbed deviation from the trim state.
6. The multi-control surface aircraft control allocation function design method based on STPA according to claim 4 is characterized in that: UCA2, provides control actions that cause hazards, including: the allocation of instructions exceeds the reachable set, the allocation of instructions has too large an error that causes the control allocation requirements to be unable to be met, and the control causes the aircraft to exceed the operating boundaries and flight envelope. Any one or more of the following.
7. The multi-control surface aircraft control allocation function design method based on STPA according to claim 4 is characterized in that: UCA3, provides control actions too early, too late or in the wrong time sequence, including: allocation instructions are updated too late / delayed.
8. The multi-control surface aircraft control allocation function design method based on STPA according to claim 4 is characterized in that: UCA4, the control action lasts too long or ends too early, including any one or more of: the allocation instruction lasts too long and the allocation instruction ends too early.
9. The multi-control surface aircraft control allocation function design method based on STPA according to claim 1, characterized in that: to adjust control allocation, including: Perform limiting error identification, perform data preprocessing, improve fault detection and isolation performance, and increase weight scheduling based on flight status, or any one or more of the above.
10. A multi-control surface aircraft control allocation function design device based on STPA, characterized in that: include: A mathematical modeling module is configured to perform mathematical modeling on the target aircraft to obtain a mathematical modeling of the target aircraft; An aircraft design module configured to perform control law design and control allocation for mathematical modeling of a target aircraft; The STPA analysis module is configured to classify the types of unsafe control behaviors according to the STPA analysis method, and identify potential dangerous behaviors according to the type of each unsafe control behavior, wherein the potential dangerous behaviors are represented by flight state influencing factors or control quality influencing factors; A risk cause analysis module is configured to analyze risk causes corresponding to potential risk scenarios; The control allocation adjustment module is configured to adjust the control allocation according to the risk cause.
Citation Information
Patent Citations
Engine failure management process and device for an aircraft turbine engine
CA2928844A1
STPA formal model-based security analysis method
CN108398940A
Civil aircraft heavy landing event risk inducement analysis method
CN117575305A
Automatic optimization framework for safety-critical systems of interconnected subsystems
US20240231300A1
Methods of identifying compounds that modulate protein activity
WO2004013347A2