STPA-based multi-control-surface aircraft control distribution function design method and device
By designing aircraft control allocation functions based on the STPA method, the problem of poor safety in traditional methods is solved, and higher safety and airworthiness are achieved.
Patent Information
- Application Number
- CN202510037207.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-01-09
AI Technical Summary
Traditional dynamic control allocation methods lack risk-based design in aircraft control systems, resulting in poor safety.
The STPA-based approach is used to design the control allocation function of the aircraft. Through mathematical modeling, control law design, classification of unsafe control behaviors and identification of potential dangerous behaviors, the control allocation is adjusted to avoid dangerous causes.
It improves aircraft safety, reduces potential hazards, and meets airworthiness safety requirements.
Smart Images

Figure CN120010536B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of aircraft design, for example to a STPA-based multi-control surface aircraft control allocation function design method and device. BACKGROUND
[0002] The three-axis control of an aircraft refers to the stability and maneuvering of pitch, roll and yaw, and is a key function of the flight control system of an aircraft. In the early stage, this function was realized by mechanical linkages, with ailerons controlling roll, elevators controlling pitch and rudders controlling heading. With the development of aviation technology and the demand for application, the control and maneuvering of aircrafts have become more complex, and the flight control system has also changed from mechanical to fly-by-wire, which can adapt to more complex aircraft types. In order to solve the problems of driving maneuvering and coupling between maneuvering axes of some aircrafts, the control allocation function is introduced into the fly-by-wire flight control system. Dynamic control allocation can optimize the allocation of control commands to different actuators while considering position and speed limitations. Common control allocation methods include allocation algorithms based on generalized inverse, allocation algorithms based on reachable sets of actuators, and control allocation methods based on optimization methods.
[0003] Dynamic control allocation methods were early applied to military aircrafts such as F-16, X-35B, F-35, etc. For civil aircrafts, the introduction of dynamic control allocation function not only enhances the maneuverability and flight performance, but also increases the fault tolerance. Through calculation and analysis, it is shown that many civil aviation accidents in history, such as United Airlines Flight 191, Japan Airlines Flight JL123, United Airlines Flight 427, United Airlines Flight 585, etc. can be avoided by integrating and allocating the remaining control ability. In addition, some new civil aircrafts such as distributed electric propulsion aircrafts and electric vertical take-off and landing aircrafts also need dynamic control allocation function.
[0004] For civil aviation aircrafts, when introducing new functions into the flight control system, the corresponding airworthiness safety clauses need to be met. For transport category aircrafts, in addition to the requirement that the system design must ensure that the intended function can be completed under various expected operating conditions, it is also required to show that the design of the aircraft system and related components, when considered individually and in combination with other systems, the probability of any failure state that would prevent the aircraft from continuing to fly and land safely is extremely unlikely. Therefore, when introducing dynamic control allocation function into the flight control system, sufficient analysis and evaluation need to be carried out to meet the airworthiness requirements before putting into operation, so as to avoid catastrophic accidents.
[0005] Hazard analysis process is an important means to ensure the adequacy of airworthiness certification basis. Common methods include function hazard analysis, hazard and operability analysis, and system theory process analysis. Among them, STPA is proposed by Nancy Leveson and others, aiming to evaluate relatively complex safety systems and determine safety constraints and requirements. Compared with traditional hazard analysis methods, STPA can consider software and human factors in the analysis process, and the analysis process is not limited to failure analysis, but can analyze system function deficiency problems (or weaknesses), which is suitable for risk identification of novel design features of aircraft. In the field of aviation, STPA has been widely applied. Based on the STPA method, the aircraft air management system is analyzed, and through a structured and systematic process, the emergency behavior caused by the interaction between system components is successfully captured. The STPA is applied to the neural network control system under the running time guarantee constraint. The safety constraint identification and running time guarantee development problem of the deep reinforcement learning tactical autopilot using neural network control system are considered. A civil aircraft system safety analysis method based on improved FRAM-STPA is proposed to identify key system safety and provide quantitative indicators. Based on STPA, the TOPAZ method is used to quantitatively describe the influence degree of dangerous causation factors on the safety of flight control system, and this method is applied to the safety analysis of unmanned aerial vehicle conflict resolution.
[0006] In the prior art, the focus of dynamic control allocation is on algorithm innovation and performance improvement, but there is no design based on risk factors for the control allocation function of the aircraft. SUMMARY
[0007] To provide a basic understanding of some aspects of the disclosed embodiments, a simplified summary is given below. The summary is not an extensive overview of the embodiments nor is it intended to identify key / critical elements of the embodiments or to delineate the scope of the embodiments. The sole purpose of the summary is to present some concepts of the embodiments in a simplified form as a prelude to the more detailed description that is presented later.
[0008] The traditional dynamic control allocation focuses on algorithm innovation and performance improvement, but lacks a method of designing the control allocation function of the aircraft based on risk factors. Therefore, the traditional dynamic control allocation design method has the problem of poor safety.
[0009] In some embodiments, a STPA-based multi-control surface aircraft control allocation function design method is provided, the method comprising:
[0010] Mathematical modeling of the target aircraft is performed to obtain the mathematical modeling of the target aircraft;
[0011] Control law design and control allocation are performed on the mathematical modeling of the target aircraft;
[0012] According to the STPA analysis method, the types of unsafe control behaviors are divided, and potential dangerous behaviors are identified according to each type of unsafe control behavior, wherein the potential dangerous behaviors are represented by flight state influence factors or control quality influence factors.
[0013] The dangerous causes corresponding to the potential dangerous scenarios are analyzed.
[0014] According to the dangerous causes, the control allocation is adjusted.
[0015] Preferably, the specific types of the types of unsafe control behaviors divided according to the STPA analysis method are four, including: UCA1, no control action is provided; UCA2, the control action provided causes harm; UCA3, the control action is provided too early, too late or in a wrong time sequence; and UCA4, the control action lasts too long or ends too early.
[0016] Preferably, the flight state influence factors include any one or more of the following parameters: speed, roll, sideslip, and disturbance deviation.
[0017] Preferably, the control allocation quality influence factors include any one or more of the following parameters: allocation space, allocation error, and command time.
[0018] Preferably, UCA1, no control action provided, includes any one or more of the following: approaching stall, approaching roll envelope, approaching sideslip envelope, and trim state deviating from disturbance.
[0019] Preferably, UCA2, the control action provided causes harm, includes any one or more of the following: allocation command exceeding the reachable set, allocation command having too large error to meet the control allocation requirement, and control causing the aircraft to exceed the operating boundary and flight envelope.
[0020] Preferably, UCA3, the control action is provided too early, too late or in a wrong time sequence, includes: allocation command update is too late / delayed.
[0021] Preferably, UCA4, the control action lasts too long or ends too early, includes any one or more of the following: allocation command lasts too long and allocation command ends too early.
[0022] Preferably, the control allocation is adjusted, including:
[0023] Any one or more of the following is performed: limit error identification, data preprocessing, improving fault detection and isolation performance, and increasing weight value scheduling according to flight state.
[0024] In some embodiments, a STPA-based multi-control surface aircraft control allocation function design device is disclosed, comprising:
[0025] a mathematical modeling module configured to perform mathematical modeling on the target aircraft to obtain a mathematical modeling of the target aircraft;
[0026] an aircraft design module configured to perform control law design and control allocation on the mathematical modeling of the target aircraft;
[0027] an STPA analysis module configured to divide types of unsafe control behaviors according to an STPA analysis method, and identify potential dangerous behaviors according to each type of unsafe control behaviors, wherein the potential dangerous behaviors are represented by flight state impact factors or control quality impact factors;
[0028] an analysis dangerous cause module configured to analyze a dangerous cause corresponding to a potential dangerous scenario;
[0029] an adjusted control allocation module configured to adjust the control allocation according to the dangerous cause.
[0030] The STPA-based multi-control-surface aircraft control allocation function design method and device provided by the embodiments of the present disclosure can achieve the following technical effects:
[0031] The embodiments of the present disclosure use the STPA analysis method to deduce potential dangerous behaviors, and then analyze a dangerous cause corresponding to a potential dangerous scenario, so as to adjust the control allocation from the perspective of avoiding the dangerous cause. Therefore, the potential danger of the aircraft is reduced from the design aspect, and the safety of the aircraft is improved.
[0032] The general description above and the following description below are exemplary and explanatory only and are not intended to be limiting of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0033] One or more embodiments are illustrated by way of example in the accompanying drawings, which are not intended to be limiting of the present disclosure, in which like reference numerals refer to like elements in the various figures, the drawings are not necessarily to scale, and in which:
[0034] Figure 1 is a flowchart of an STPA-based multi-control-surface aircraft control allocation function design method provided by the embodiments of the present disclosure;
[0035] Figure 2 is a control surface schematic diagram of a multi-control-surface aircraft provided by the embodiments of the present disclosure;
[0036] Figure 3 is a flight control structure schematic diagram provided by the embodiments of the present disclosure;
[0037] Figure 4 is a dynamic inverse algorithm framework schematic diagram provided by the embodiments of the present disclosure;
[0038] Figure 5 is a control structure schematic diagram of a flight control system provided by an embodiment of the present disclosure;
[0039] Figure 6 is a virtual control instruction allocation space ratio schematic diagram provided by an embodiment of the present disclosure;
[0040] Figure 7 is a possible dangerous cause type schematic diagram provided by an embodiment of the present disclosure;
[0041] Figure 8-a is a modeling inaccurate data schematic diagram provided by an embodiment of the present disclosure;
[0042] Figure 8-b is another modeling inaccurate data schematic diagram provided by an embodiment of the present disclosure;
[0043] Figure 9-a is a received data abnormality schematic diagram provided by an embodiment of the present disclosure;
[0044] Figure 9-b is another received data abnormality schematic diagram provided by an embodiment of the present disclosure;
[0045] Figure 10-a is a weight setting unreasonable schematic diagram provided by an embodiment of the present disclosure;
[0046] Figure 10-b is another weight setting unreasonable schematic diagram provided by an embodiment of the present disclosure;
[0047] Figure 11-a is a control efficiency matrix error schematic diagram provided by an embodiment of the present disclosure;
[0048] Figure 11-b is another control efficiency matrix error schematic diagram provided by an embodiment of the present disclosure;
[0049] Figure 12-a is an extreme deviation fault schematic diagram provided by an embodiment of the present disclosure;
[0050] Figure 12-b is another extreme deviation fault schematic diagram provided by an embodiment of the present disclosure;
[0051] Figure 13-a is an external wind interference schematic diagram provided by an embodiment of the present disclosure;
[0052] Figure 13-b is another external wind interference schematic diagram provided by an embodiment of the present disclosure;
[0053] Figure 14The device is a STPA-based multi-control surface aircraft control allocation function design device schematic diagram provided by the embodiment of the present disclosure. DETAILED DESCRIPTION
[0054] In order to enable a more detailed understanding of the features and technical contents of the embodiments of the present disclosure, the implementation of the embodiments of the present disclosure will be described in detail below, and the attached drawings are only used for reference and do not limit the embodiments of the present disclosure. In the following technical description, in order to facilitate explanation, a plurality of details are provided to provide a full understanding of the disclosed embodiments. However, one or more embodiments can still be implemented without these details. In other cases, well-known structures and devices can be simplified to facilitate the drawings.
[0055] The following description and drawings sufficiently illustrate specific embodiments of the application to enable those skilled in the art to practice them. Other embodiments can include structural, logical, electrical, process, and other changes. The embodiments are merely representative of possible variations. Individual components and functions are optional unless specifically required, and the order of operations can be changed. Parts and features of some embodiments can be included or replaced by parts and features of other embodiments. The scope of the embodiments of the present application includes the entire scope of the claims and all available equivalents of the claims. In this application, each embodiment can be individually or collectively referred to as the term "invention", which is merely for convenience and does not automatically limit the scope of the application to any single invention or inventive concept if more than one invention is actually disclosed. In this application, relationship terms such as first and second are used only to distinguish one entity or operation from another entity or operation, and do not require or imply any actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of additional identical elements in the process, method or device including the element. In this application, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments, and the same or similar parts between each embodiment can be referred to each other. For the method, product, etc. disclosed by the embodiments, since it corresponds to the method part disclosed by the embodiments, the description is relatively simple, and the relevant part can be referred to the method part description.
[0056] Traditional dynamic control allocation focuses on algorithm innovation and performance improvement, but lacks a method designed based on risk factors for control allocation function of the aircraft.
[0057] To solve the problems in the related art, the embodiment of the present disclosure provides a STPA-based multi-control surface aircraft control allocation function design method and device. The STPA analysis method is used to deduce the potential dangerous behavior, and the corresponding dangerous cause of the potential dangerous scene is analyzed again, and the control allocation is adjusted from the perspective of avoiding dangerous causes. Therefore, the potential danger of the aircraft is reduced from the design aspect, and the safety of the aircraft is improved.
[0058] In combination Figure 1 with the above, the embodiment of the present disclosure provides a STPA-based multi-control surface aircraft control allocation function design method flowchart, comprising:
[0059] S100, the target aircraft is mathematically modeled to obtain the mathematical modeling of the target aircraft.
[0060] Taking a multi-control surface aircraft as the research object, the aircraft control surface arrangement is as shown in Figure 2 The aircraft is equipped with 4 / 2 pairs of ailerons, 4 / 2 pairs of elevators, 2 rudders and 1 horizontal stabilizer.
[0061] The linear state space mathematical model of the aircraft is shown in the following formula (1).
[0062]
[0063] In the formula, x∈R n is the system state vector; u∈R m is the system input vector; y∈R n is the system output; A∈R n×n is the system matrix; B∈R n×m is the control efficiency matrix, C∈R n ,D∈R n×m is the control input matrix. Wherein x can be represented as:
[0064] x=[p q r V T αβφθψ] T (2)
[0065] In formula (2), p, q and r are roll angular velocity, pitch angular velocity and yaw angular velocity respectively; V T is the airspeed; α and β are the angle of attack and the angle of sideslip respectively; φ, θ and ψ are the roll angle, the pitch angle and the yaw angle respectively. u in formula (1) can be represented as:
[0066] u=[δaor δ aol δ air δ ail δ eor δ eol δ eir δ eil δ ih δ ur δ dr ] T (3)
[0067] In the above formula, δ aor , δ aol are right and left outboard ailerons, respectively; δ air , δ ail are right and left inboard ailerons, respectively; δ eor , δ eol are right and left outboard elevators, respectively; δ eir , δ eil are right and left inboard elevators, respectively; δ ih is the horizontal stabilizer, and δ ur , δ dr are upper and lower rudders, respectively.
[0068] S200, control law design and control allocation for the mathematical modeling of the target aircraft.
[0069] Specifically, for the above mathematical model, a flight control structure is designed as shown in Figure 3 .
[0070] The control law design generates the required virtual control command as input, the control allocator allocates the virtual command to the aircraft control surfaces, and finally the fault detection module is responsible for detecting whether the flight control system has failed. Once detected, the system performance matrix is estimated in real time, and timely feedback is given to the control allocator to re-allocate the control surfaces.
[0071] The control law design is based on the dynamic inverse algorithm, as shown in the following formula (4):
[0072]
[0073] In the formula, cv is the virtual control command, u0 is the system input at the previous time, and Δu is the input difference value that needs to be added to the system at this time, which is generated by the PI control law.
[0074]
[0075] Using the data at the previous time and the computer offline storage model CB, the current control variable cv nom can be known.
[0076] cvnom = CAx + CBu0 (6)
[0077] Finally, the gain matrix P is introduced to calculate the actuator deflection to achieve the control allocation, as shown in the following equation. The calculation of P will be given in 1.2.3.
[0078]
[0079] Dynamic control allocation is designed, pseudo-inverse method is widely used in the field of aviation due to its simplicity and practicality, but it cannot handle the physical limitations of actuators. The allocation algorithm based on optimization can better handle the constraint problem, but the operation amount is large and cannot guarantee real-time performance, and the uncertainty of the algorithm does not meet the airworthiness certification requirements at present. Therefore, a weighted pseudo-inverse allocation method based on a quadratic cost function is adopted in the application. This method can find a unique control input combination that can meet the required control effect and make the cost function optimal, and the algorithm is shown in equation (8) as follows.
[0080]
[0081] Equation (8) Δup is the selected value of the deflection increment to reduce the calculation amount of the optimization function, and Δd is the increment of the desired control command. W p is the weight of the actuator, and the control efficiency matrix directly reflects the relationship between the control surface deflection angle and the generated control moment. Because the deflection rate of different control surfaces of the aircraft is limited, different weights are given to different control surfaces, and the actuator deflection limit is introduced
[0082]
[0083] Then the solution of the gain matrix P when the flight control system is overdriven is
[0084] P = (Wp T ) -1 B T (B(Wp T ) -1 B T ) -1 (10)
[0085] In summary, the entire flight control system algorithm framework is shown in Figure 4 .
[0086] S300, according to the STPA analysis method, the types of unsafe control behaviors are divided, and potential dangerous behaviors are identified according to each type of unsafe control behavior, wherein the potential dangerous behaviors are represented by flight state influencing factors or control quality influencing factors.
[0087] It should be understood that the specific types of unsafe control actions classified according to the STPA analysis method are 4 types, including: UCA1, no control action is provided; UCA2, providing a control action leads to a hazard; UCA3, providing a control action too early, too late or in a wrong time sequence; and UCA4, a control action lasts too long or ends too early.
[0088] The control algorithm itself adopts a functional control structure for STPA analysis, and the STPA control structure of the flight control system is as shown in Figure 5 In Figure 5 , a pseudo-control instruction is introduced to separate the design of the pilot instruction tracking and the control allocation, the task of tracking the pilot instruction is to generate a desired virtual control instruction by the control law module, and then the control input required by the actuator can be generated according to the desired virtual control instruction.
[0089] From the aircraft level and the control system level, unacceptable behaviors are defined. The corresponding influencing factors are flight state influencing factors and control allocation quality influencing factors.
[0090] The flight state influencing factors include any one or more of the following parameters: speed, roll, sideslip, and disturbance deviation. There are clear limits on flight performance and stability characteristics, including:
[0091] Stall state: must be able to quickly prevent stall and change from stall with normal control.
[0092] Roll overrun: the aircraft needs to meet the roll attitude limit under certain conditions, such as the roll cannot exceed 45° in the critical engine failure state.
[0093] Sideslip overrun: the aircraft needs to meet the sideslip limit under certain conditions, such as the sideslip angle should be maintained within 15° under non-low-speed landing or non-high-wind environment.
[0094] Trim state: after the aircraft is trimmed, it should be able to maintain the trimmed state without receiving other control instructions.
[0095] Control allocation quality influencing factors: any one or more of the following parameters: allocation space, allocation error, instruction time.
[0096] Specifically, from the control allocation function and algorithm, the following allocation qualities should be met:
[0097] Allocation error: the norm of the difference between the expected control instruction and the actual output, including angle error and length error.
[0098] e = || Bu-v des || (11)
[0099] Allocation space: a set of control commands, the size of the set is measured by the ratio between the reachable set and the set of control commands, the algorithm allocates space as shown in Figure 6
[0100] Allocation time: the time consumed by the algorithm to calculate the control commands after the flight control system gives the desired moment, specifically the online calculation time.
[0101] The acceptable degree of the actuator command generated by the control allocation is constrained by the control quality requirements of the entire control loop, and the acceptable control quality is defined as follows:
[0102] Steady-state error: e ss ≤0.01 rad / s
[0103] Tracking error: max(e track )≤0.02 rad / s
[0104] Rise time: t r ≤2s.
[0105] The starting point of the identification knowledge analysis of unsafe control behavior in STPA is to identify all scenarios that may lead to corresponding unsafe control actions. The specific scenarios of the analysis correspond to Table 1 below.
[0106] Table 1
[0107]
[0108]
[0109] Through simulation, the UCA that fails to meet the system performance indicators is shown in Table 2. Table 2 summarizes the dangerous control actions identified, and once unsafe control behavior is identified, it can be converted into constraints.
[0110] Table 2
[0111]
[0112]
[0113] S400, analyze the hazard causal factor corresponding to the potential hazard scenario.
[0114] After determining the UCA that may occur in the control allocation part, further analysis of the hazard causal factor HCF (Hazard Casual Factor) that causes the corresponding action is needed to fully guide the design to eliminate or suppress potential dangerous behavior. Referring to Figure 7 , a schematic diagram of a possible type of hazard causal factor, wherein, Figure 7 The numbers in are the serial numbers of typical hazard causal factors.
[0115] UCA1 Risk Causation Analysis: For UCA1, the control allocation solution of the multi-actuator control may have a singular problem of inversion, resulting in no solution to the algorithm and the inability to generate allocation commands based on the algorithm.
[0116] UCA2 Risk Causation Analysis: The calculation of control allocation depends on the control command input, while the calculation of the dynamic inverse control law depends on the accuracy of the model. When the allocation module can only return the solution closest to the optimization goal. Figure 8-a and Figure 8-b The display is not accurate for flight control system modeling, for example, the system matrix A is not accurate, and the virtual control command is obviously out of the reachable set range.
[0117] Data anomalies can prevent the allocation algorithm from obtaining normal aircraft state, resulting in virtual control command output exceeding the upper and lower limits of the reachable set. Figure 9-a and Figure 9-b The simulation shows that the data received by the control law module is disturbed by non-command signals.
[0118] Due to inappropriate weight settings, the control surface with high operating efficiency enters saturation too early, resulting in the virtual control command output being inconsistent with the expected control command direction. For example, Figure 10-a and Figure 10-b In the simulation, unreasonable increase in the proportion of the horizontal stabilizer in the weight causes the allocation algorithm to allocate too low a proportion of the elevator / rudder, making it impossible to achieve the expected control command.
[0119] The uncertainty of the control efficiency matrix comes from the uncertain state of the aircraft, changes in parameters, external environmental disturbances, etc., which can cause the control efficiency matrix to be inconsistent with the actual one, resulting in allocation errors, Figure 11-a and Figure 11-b The display shows the allocation error of the control surface when the control efficiency matrix is inconsistent with the model.
[0120] UCA3 Risk Causation Analysis: Fault detection cannot guarantee real-time performance in the presence of delays, resulting in delayed allocation commands. For example, Figure 12-a and Figure 12-b When the control surface has an extreme deflection fault, the right outer elevator is deflected to 17° / -23° and the right outer aileron is deflected to -12° / 15°, the flight control system cannot detect the control surface fault in time, so the allocation command may be delayed.
[0121] UCA4 Risk Causation Analysis: The flight control system is subjected to external wind disturbance, and the flight control system cannot converge under external environmental disturbance, requiring continuous allocation of control allocation commands to make the flight control system approach stable. For example, Figure 13-a and Figure 13-bThe simulation diagram with the Delton turbulence model added.
[0122] Based on the above analysis, the dangerous causes of UCA are shown in Table 3. It should be noted that the typical dangerous cause types in Table 3 correspond to the serial numbers of the typical dangerous cause types in Figure 7
[0123] Table 3
[0124]
[0125] Based on the results in Table 3, the fly-by-wire flight control system can focus on the dangerous causes that may lead to UCA from the initial introduction of the control allocation algorithm.
[0126] S500, adjusting the control allocation according to the dangerous causes.
[0127] The adjusting the control allocation includes any one or more of the following: performing error limit identification, performing data preprocessing, improving fault detection and isolation performance, and increasing weight scheduling according to flight states.
[0128] For example, in order to adapt to sudden external environmental changes, the control allocation needs to be adjusted to be more robust.
[0129] Figure 14 The device for designing a control allocation function of a multi-control-surface aircraft based on STPA according to an embodiment of the present application is shown, and the device includes:
[0130] The mathematical modeling module is configured to perform mathematical modeling on the target aircraft to obtain a mathematical modeling of the target aircraft.
[0131] The aircraft design module is configured to perform control law design and control allocation on the mathematical modeling of the target aircraft.
[0132] The STPA analysis module is configured to divide the types of unsafe control behaviors according to an STPA analysis method, and identify potential dangerous behaviors according to each type of unsafe control behavior, wherein the potential dangerous behaviors are represented by flight state influencing factors or control quality influencing factors.
[0133] The analysis of dangerous causes module is configured to analyze the dangerous causes corresponding to the potential dangerous scenarios.
[0134] The adjusting control allocation module is configured to adjust the control allocation according to the dangerous causes.
[0135] Traditional dynamic control allocation focuses on algorithm innovation and performance improvement, but lacks design of control allocation functions of an aircraft based on risk factors. Therefore, traditional dynamic control allocation has the problem of poor safety.
[0136] The above description and drawings are illustrative of embodiments of the present disclosure and are not intended to be limiting. Other embodiments can include structural, logical, electrical, process, and other changes. Embodiments are merely representative of possible variations. Individual components and functions are optional unless explicitly required, and the order of operations can be varied. Portions and features of some embodiments can be included or replaced in or by other embodiments. Also, words used in this application are words of description, not limitation. As used in the description of the embodiments and the claims, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. Similarly, the term "and / or" as used in the application refers to any and all possible combinations of one or more elements, i.e., it represents a disjunctive, and the conjunction "or" has the same meaning as "and / or". Additionally, the term "comprising" as used in this application means the open inclusion of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. Without more limitations, an element defined by the phrase "comprising a..." does not exclude the presence of additional identical elements in the process, method, article of manufacture, or apparatus including the element. In this application, each embodiment can focus on the differences from other embodiments, and the same or similar parts between embodiments can be referred to each other. For the method, product, etc. disclosed by the embodiments, if it corresponds to the method part of the embodiments, the relevant part can be referred to the description of the method part.
[0137] Those skilled in the art can understand that the units and algorithm steps of the examples described in combination with the embodiments disclosed in the present application can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods for each specific application to implement the described functions, but such implementation should not be considered beyond the scope of the embodiments of the present disclosure. The skilled person can clearly understand that, for the convenience and brevity of description, the specific working process of the above-described devices, apparatuses and units can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.
[0138] The diagrams of the flow and block diagrams show the possible implementation architecture, function and operation of the apparatus, method and computer program product according to the embodiments of the present disclosure. In this regard, each block in the flow or block diagram can represent a module, a program segment or a part of code containing one or more executable instructions for implementing the specified logic function. In some alternative implementations, the functions annotated in the blocks can also occur in an order different from that annotated in the diagrams. For example, two consecutive blocks can actually be executed substantially in parallel, and sometimes they can also be executed in reverse order, depending on the functions involved. In the description corresponding to the flow and block diagrams in the diagrams, the operations or steps corresponding to different blocks can also occur in an order different from that disclosed in the description, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps can actually be executed substantially in parallel, and sometimes they can also be executed in reverse order, depending on the functions involved. Each block in the block diagram and / or flow diagram, and the combination of blocks in the block diagram and / or flow diagram, can be implemented by a dedicated hardware-based device performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
Claims
1. A method for STPA-based design of control allocation function for a multi-control surface aircraft, characterized in that, The method comprises: The target aircraft is mathematically modeled to obtain a mathematical model of the target aircraft, and a linear state space mathematical model of the aircraft is as shown in formula (1), (1) wherein is the system state vector; is the system input vector; is the system output quantity; is the system matrix; is the control efficiency matrix, is the control input matrix, where is represented as: (2) In formula (2) respectively, roll angular velocity, pitch angular velocity and yaw angular velocity; respectively, roll angle, pitch angle and yaw angle; and respectively, angle of attack and sideslip angle; respectively, roll angle, pitch angle and yaw angle; and is expressed as: (3) In the above formula right and left outboard ailerons, respectively; right and left inboard ailerons, respectively; right and left outboard elevators, respectively; right and left inboard elevators, respectively; horizontal stabilizer, upper and lower rudders, respectively; The mathematical model of the target aircraft is designed for control law and control allocation, the control law design generates a virtual control instruction required by input, the control allocator allocates the virtual instruction to the aircraft control surface, the fault detection module is responsible for detecting whether the flight control system fails, if detected, the system performance matrix is estimated in real time, and the control allocator is fed back in time to re-allocate the control surface; The control law design is based on a dynamic inverse algorithm, as shown in formula (4): (4) In the formula is a virtual control instruction, is the system input at the previous time, is the input difference value calculated at this time, which is generated by a PI control law. (5) Using last time data and computer offline storage model , current control variable ; (6) Introducing the gain matrix The control allocation is achieved by computing the actuator deflections as shown in equation (7); (7) The dynamic control allocation is designed to find a unique control input combination by using a weighted pseudo-inverse allocation method based on a quadratic cost function, and the algorithm is as shown in formula (8); (8) Formula (8) is a selected value of the deflection increment to reduce the amount of optimization function calculation, is an increment of the expected control instruction, is an actuator weight, and the control efficiency matrix directly reflects the relationship between the control surface deflection angle and the generated control moment. According to the STPA analysis method, the types of unsafe control behaviors are divided, and potential dangerous behaviors are identified according to each type of unsafe control behavior, wherein the potential dangerous behaviors are represented by flight state influence factors or control quality influence factors; The dangerous causes corresponding to the potential dangerous scenarios are analyzed; According to the dangerous causes, the control allocation is adjusted.
2. The STPA-based multi-control surface aircraft control allocation function design method of claim 1, wherein, The specific types of dividing the types of unsafe control behaviors according to the STPA analysis method are four, including: UCA1, no control action is provided; UCA2, providing a control action leads to harm; UCA3, providing a control action too early, too late or a wrong time sequence; UCA4, the control action lasts too long or ends too early.
3. The STPA-based multi-control surface aircraft control allocation function design method of claim 2, wherein, The flight state influence factors include: any one or more parameters of speed, roll, sideslip, and disturbance deviation.
4. The STPA-based multi-control surface aircraft control allocation function design method of claim 3, wherein, The control allocation quality influence factors include: any one or more parameters of allocation space, allocation error, and instruction time.
5. The STPA-based multi-control surface aircraft control allocation function design method of claim 4, wherein, UCA1, no control action is provided, including: any one or more of approaching stall, approaching roll airworthiness range, approaching sideslip airworthiness range, and disturbance deviation trim state.
6. The STPA-based multi-control surface aircraft control allocation function design method of claim 4, wherein, UCA2, providing a control action leads to harm, including: any one or more of allocation instruction exceeding the reachable set, allocation instruction having a large error leading to failure to meet the control allocation requirement, and control leading to the aircraft exceeding the operating boundary and flight envelope.
7. The STPA-based multi-control surface aircraft control allocation function design method of claim 4, wherein, UCA3, providing a control action too early, too late or a wrong time sequence, including: allocation instruction updating too late / delayed.
8. The STPA-based multi-control surface aircraft control allocation function design method of claim 4, wherein, UCA4, the control action lasts too long or ends too early, including: any one or more of allocation instruction lasting too long and allocation instruction ending too early.
9. The STPA-based multi-surface aircraft control distribution function design method of claim 1, wherein, Adjusting the control allocation includes: Performing amplitude error identification, performing data preprocessing, improving fault detection and isolation performance, and increasing weight value scheduling according to flight state.
10. A device for STPA-based design of a control allocation function for a multi- control-surface aircraft, characterized in that It includes: The mathematical modeling module is configured to mathematically model the target aircraft to obtain a mathematical model of the target aircraft, and a linear state space mathematical model of the aircraft is as shown in formula (1), (1) wherein is the system state vector; is the system input vector; is the system output quantity; is the system matrix; is the control efficiency matrix, is the control input matrix, where is represented as: (2) In formula (2) respectively, roll angular velocity, pitch angular velocity and yaw angular velocity; for airspeed; respectively, angle of attack and sideslip angle; respectively, roll angle, pitch angle and yaw angle; in formula (1) is expressed as: (3) In the above formula right and left outboard ailerons, respectively; right and left inboard ailerons, respectively; right and left outboard elevators, respectively; right and left inboard elevators, respectively; horizontal stabilizer, upper and lower rudders, respectively; The aircraft design module is configured to control law design and control allocation for mathematical modeling of a target aircraft, the control law design generates required virtual control instructions from inputs, and the control allocator allocates the virtual instructions to aircraft control surfaces; the fault detection module is responsible for detecting whether a flight control system has a fault, and if so, estimates a system performance matrix in real time and feeds back to the control allocator in time to re-allocate the control surfaces; The control law design is based on a dynamic inverse algorithm, as shown in equation (4): (4) In the formula is a virtual control instruction, is the system input at the previous time, is the input difference value calculated at this time, which is generated by a PI control law. (5) Using last time data and computer offline storage model , current control variable ; (6) Introducing the gain matrix The control allocation is achieved by computing the actuator deflections as shown in equation (7); (7) The dynamic control allocation is designed to use a weighted pseudo-inverse allocation method based on a quadratic cost function to find a unique combination of control inputs, as shown in equation (8); (8) Formula (8) is a selected value of the deflection increment to reduce the optimization function calculation amount, is an increment of the expected control instruction, is an actuator weight, and the control efficiency matrix directly reflects the relationship between the control surface deflection angle and the generated control moment. The STPA analysis module is configured to divide the types of unsafe control behaviors according to the STPA analysis method, and identify potential dangerous behaviors according to each type of unsafe control behavior, wherein the potential dangerous behaviors are represented by flight state impact factors or control quality impact factors; The analysis of dangerous causes module is configured to analyze the dangerous causes corresponding to the potential dangerous scenarios; The adjustment control allocation module is configured to adjust the control allocation according to the dangerous causes.
Citation Information
Patent Citations
Engine failure management process and device for an aircraft turbine engine
CA2928844A1
Automatic optimization framework for safety-critical systems of interconnected subsystems
US20240231300A1