Flight control-based safety disaster recovery system and method
Through the non-similar redundant architecture of three flight controls, distributed position deployment and intelligent switching algorithm, combined with the multi-channel linkage control mechanism, the defects of the existing flight control system in terms of reliability and emergency response are solved, and the high disaster recovery reliability and safety of the load-loaded aircraft are achieved.
Patent Information
- Application Number
- CN202510539582.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-27
AI Technical Summary
The existing flight control systems have significant flaws in reliability, redundant architecture and emergency response, making it difficult for load-loaded aircraft to ensure safety in special circumstances.
The three flight control non-similar redundant architecture, distributed position deployment and intelligent switching algorithm are adopted, combined with the multi-channel linkage control mechanism, and a comprehensive safety architecture is established to ensure the high disaster recovery reliability of the flight control system, and to ensure the safe parachute opening of the aircraft under special circumstances.
It realizes high disaster recovery reliability of the flight control system, reduces the risk of system crash caused by single point of failure, and ensures the safety and reliability of the load-loaded aircraft in special circumstances.
Smart Images

Figure CN120065686A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of disaster tolerance technology for the flight control system (FCS) of large-load aircraft, and particularly relates to a safety disaster tolerance system and method based on flight control. Background Art
[0002] With the development of urban air mobility (UAM) and heavy logistics drones, the existing flight control systems have significant defects in terms of reliability, redundant architecture, and emergency response. Single flight control systems (such as CN111338377A) have a very high risk of single-point failure due to the lack of redundant design. Typical cases include the out-of-control accidents of Boeing 737MAX caused by a single sensor failure. Traditional dual-redundant architectures (such as CN106774367A) use homogeneous hardware designs and have a risk of systematic failure. For example, in the case of Airbus A330, three flight control computers failed simultaneously due to a common-mode problem, and the software logic coupling degree is too high, resulting in frequent problems of misjudging the attitude angle synchronously by the primary and backup systems in strong crosswind scenarios. The emergency parachute control system (such as CN111338377A) relies on a single flight control command to trigger, and has a relatively high mis-triggering rate in complex urban airflows (such as mis-opening the parachute due to the failure of the barometric pressure sensor caused by turbulence), and lacks the ability of multi-modal data fusion. These defects seriously restrict the commercialization process of urban low-altitude logistics and manned eVTOL. Summary of the Invention
[0003] The purpose of the present invention is to solve the system disaster tolerance problem of large-load aircraft, especially manned aircraft. Through a three-flight-control non-similar redundant architecture, distributed location deployment, and intelligent switching algorithms, high disaster tolerance reliability of the flight control system is achieved, and a multi-channel linkage control mechanism with the parachute system is established to ensure the safe opening of the parachute under special circumstances. Thus, a comprehensive safety architecture integrating non-similar hardware redundancy, physical location isolation, multi-level communication redundancy, hierarchical switching algorithms, and emergency parachute opening collaborative control is proposed, which is applicable to aircraft with strict safety requirements such as manned electric vertical takeoff and landing aircraft (eVTOL) and dangerous goods transportation drones.
[0004] To achieve the purpose of the present invention, the present invention discloses a safety disaster tolerance system based on flight control. The system first constructs three independent flight control units through heterogeneous computing resources, and deploys the flight control units at different positions to achieve spatial redundancy protection and avoid system collapse caused by single-point failure; each flight control unit transmits heartbeat signals and control commands in real time through a communication redundant network; the main control system runs a hierarchical switching algorithm to achieve smooth transition output of commands under redundant control, and at the same time reports the fault status; the output of the parachute opening command integrates the fault status sent by the flight control and the fault status of the parachute dedicated sensor, and is uniformly voted by a voter.
[0005] Further, the system adopts a three-flight-control hardware non-similar redundant architecture, where: The A-core flight control is ARM Cortex-A7 + Xilinx Zynq UltraScale FPGA; The M-core flight control is ARM Cortex-M7 + Microchip PolarFire FPGA; The A / M hybrid-core flight control is dual ARM-core heterogeneous cooperation Cortex-A8 + Cortex-M4; Build basic computing power redundancy through differential hardware design to provide heterogeneous computing resources for subsequent steps.
[0006] Furthermore, the system adopts a position redundancy deployment scheme, deploying the flight control units in different spaces to ensure that regional failures will not cause cascading failures; the flight control units are distributed in the nose shielding compartment, the fireproof compartment at the wing root or the root of the arm, and the independent cavity of the tail beam, with a spacing of 15%-25% of the fuselage length.
[0007] Furthermore, the communication redundancy network adopts a dual independent CAN bus parallel deployment, with each node equipped with dual CAN controllers and transceivers; a hybrid topology is adopted, and the communication signal quality and transmission delay are optimized through repeaters; bus terminal matching resistors are used to suppress signal reflection, and optocoupler isolation is used to achieve electrical isolation between nodes; the cable uses double-shielded twisted pair, combined with a magnetic ring filter to suppress common-mode interference.
[0008] Furthermore, the main control system runs a hierarchical switching algorithm. Through sequential switching of A→B→C, it ensures that a more reliable flight control is adopted each time, achieving safe disaster tolerance for flight control switching; when sequentially switching to flight control C as the main flight control, continuously monitor the recovery of flight control A / B to ensure that the main flight control C at this time still has a backup flight control.
[0009] Furthermore, the fault switching logic adopts a hierarchical progressive design, with the heartbeat signal as the core trigger condition; in the main switching logic, the main flight control A broadcasts an encrypted heartbeat packet. If the heartbeat is lost twice in a row, the primary backup flight control B immediately takes over the control right and starts sending the heartbeat; if the flight control B also has a heartbeat anomaly, the secondary backup flight control C takes over; during the takeover process, the backup flight control dynamically fuses and outputs based on the cached instructions of the previous 5 cycles and real-time sensor data to ensure smooth transition of instructions; the recovery detection module continuously detects the recovery status of flight control A / B: when flight control C also fails, if the heartbeat of any node returns to normal, the system switches back to the flight control with a higher priority and re-enters the main logic loop; if all nodes fail, trigger the ultimate fault alarm and start the emergency response; The redundant flight control system achieves clock synchronization through a handshaking method; the primary flight control A broadcasts an encrypted heartbeat packet every 20 ms, which includes a timestamp, control instructions, and power status; the first-level standby flight control B continuously monitors the heartbeat packet of A. If it loses the packet twice in a row, it immediately initiates a request to take over control; the second-level standby flight control C normally monitors the heartbeat packet of B. When B is upgraded to the primary controller, it switches to directly monitoring B and takes over control when it detects the loss of its heartbeat.
[0010] Furthermore, the hierarchical switching algorithm adopts a seamless switching guarantee mechanism, specifically: the standby flight control caches the control instructions of the primary flight control in the most recent 5 cycles (100 ms) in real time, and fuses new / old data during the switch to complete a gradual transfer of control authority; The form of the control instruction cache is: First-order difference Δθ: Stores the difference in control amounts between adjacent cycles, representing the instantaneous change rate of control instructions at adjacent timestamps; ;
[0011] Second-order difference Δ²θ: Stores the change in the difference, reflecting the change acceleration of the first-order difference, and is used to capture sudden changes in trends during high-dynamic maneuvers; ;
[0012] If the change rate of the flight control instructions is small (hover state, cruise state, low-speed climb / descent state), it is more direct to store the original θ value; if the instructions are dynamically intense (maneuvering flight state, obstacle avoidance task state), store the second-order difference Δ²θ to compress the data volume and highlight the trend; Historical data reverse synthesis formula: ; In the formula, t 0 is the earliest timestamp of the cache window, t 5 is the latest timestamp of the cache window, β is the dynamic correction coefficient (dimensionless, and the value is related to the scenario);
[0013] The fusion formula is: ;
[0014] Cached interpolation instruction is generated by cubic spline interpolation based on historical data within the cache window; the real-time calculation instruction , and the standby flight control calculates it independently based on current sensor data; the mixing weight , is a dynamic weight coefficient that decays with time; The weight decay function is: Adopts an exponential decay curve to balance smoothness and response speed: ;
[0015] In the formula, t 0 is the switching trigger time (such as the start of the 8th cycle), T transition is the total transition duration (5 cycles); when t = t 0 + T transition it is considered that the attenuation is completed; Table 1 Example table of flight control switching cycle During the fusion process, the flight control switching cycle is shown in Table 1. Period Output flight control Data source Fusion operation 1-5 Main flight control Real-time sensor data None 6-7 Main flight control No output 8 Standby flight control Cache data of cycles 1 - 5 + real-time sensor data Hybrid interpolation 9 Standby flight control Cache data of cycles 2 - 5 + data of cycle 8 + real-time data Hybrid interpolation 10 Standby flight control Cache data of cycles 3 - 5 + data of cycles 8 - 9 + real-time data Hybrid interpolation 11 Standby flight control Cache data of cycles 4 - 5 + data of cycles 8 - 10 + real-time data Hybrid interpolation 12 Standby flight control Cache data of cycle 5 + data of cycles 8 - 11 + real-time data Hybrid interpolation 13 Standby flight control Real-time data None During the fusion process, the flight control switching cycle is shown in Table 1.
[0016] Furthermore, the parachute controller integrates three optocoupler isolation input channels, and the flight controls A / B / C send parachute-opening instructions through independent RS-422 links; the parachute controller adds a barometer and an IMU dedicated to the parachute; through the voting between the redundant flight controls and the dedicated sensors, if more than two instructions require parachute opening, the parachute opening is triggered; the parachute-opening instruction embeds a CRC-32 check code and a timestamp to prevent error codes caused by electromagnetic interference; a safety interlock function is added, and the parachute-opening function is unlocked when the GPS speed < 50 m / s and the altitude > 100 m.
[0017] Compared with the prior art, the remarkable progress of the present invention lies in: 1) The fault tolerance ability of the whole system has been improved; non-similar redundant architecture: the heterogeneous design of the three flight control hardwares combined with dual-channel isolation eliminates the risk of common-mode faults, and the system function has a high preservation rate under single-point faults; dual-power redundancy: the main power supply (DCDC step-down) + backup battery power supply mode ensures the continuous power supply ability under extreme working conditions; the space anti-destruction ability has been improved: the flight control modules are placed separately in the nose, wing root, and tail beam isolation cabins, combined with a carbon fiber shielding layer (60 dB attenuation) and a six-degree-of-freedom vibration isolation platform, greatly reducing the probability of synchronous failure; 2) The communication real-time performance and stability have been broken through; dual CAN bus redundant network: through the hybrid topology, repeater extension, and double-layer shielded cable design, the error rate and communication delay are reduced; 3) Seamless switching and state continuity are guaranteed; clock synchronization correction: through a high-precision clock synchronization module, the timing consistency of multiple flight control instructions is ensured, avoiding logical conflicts; hierarchical heartbeat detection: the main flight control broadcasts an encrypted heartbeat packet every 20 ms, and the standby flight control realizes the smooth transition of instructions during the control right switching through the incremental instruction cache and interpolation algorithm; sequential switching strategy: avoiding the residual state of the faulty flight control from contaminating the backup system; 4) High-reliability and fast-response parachute-opening control; optocoupler isolation input channel (HCPL-072L) and RS-422 independent link design, integrating the instruction priority of the main flight control and the state confidence of the standby flight control, dynamically optimizing the parachute-opening trigger threshold, and avoiding premature / too-late parachute opening caused by single-node misjudgment.
[0018] To more clearly illustrate the functional characteristics and structural parameters of the present invention, the following further explains in conjunction with the accompanying drawings and specific embodiments. Description of the Drawings
[0019] The drawings described herein are used to provide a further understanding of the present invention and form a part of this application. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings: Figure 1 is a schematic diagram of the overall architecture of a safety disaster tolerance system based on flight control; Figure 2 is a flowchart of hierarchical heartbeat detection and switching. Specific Embodiments
[0020] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments; based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0021] As Figure 1 shown, Figure 1 is the overall system architecture diagram, which reveals the architecture of the safety disaster tolerance system based on flight control, including hardware redundancy, location redundancy, communication redundancy, hierarchical switching algorithm, and parachute control voting mechanism. Its core process covers hardware redundancy, dynamic switching, and emergency protection mechanism. The system first constructs three independent flight control units through heterogeneous computing resources and deploys them at different locations to achieve spatial redundancy protection and avoid system crashes caused by single-point failures. Each flight control unit transmits heartbeat signals and control instructions in real time through a communication redundancy network. The main control system runs a hierarchical switching algorithm to achieve smooth transition output of instructions under redundant control and simultaneously reports the fault status. The output of the parachute opening instruction is integrated with the fault status sent by the flight control and the fault status of the parachute dedicated sensor, and is voted by the voter.
[0022] As Figure 2 shown, Figure 2 is the flowchart of hierarchical heartbeat detection and switching, which mainly describes the switching logic between three redundant flight controls. Through sequential switching of A→B→C, it ensures that a more reliable flight control is adopted each time, achieving safety disaster tolerance for flight control switching. When sequentially switching to flight control C as the main flight control, continuously monitor the recovery of flight controls A / B to ensure that the main flight control C still has standby flight controls at this time.
[0023] The fault switching logic of this system adopts a hierarchical progressive design with the heartbeat signal as the core trigger condition. In the main switching logic, the main flight control A broadcasts encrypted heartbeat packets. If the heartbeat is lost continuously twice, the primary standby flight control B immediately takes over the control right and starts sending heartbeats. If the flight control B also has abnormal heartbeat, the secondary standby flight control C takes over. During the takeover process, the standby flight control dynamically fuses and outputs based on the cached instructions of the previous 5 cycles (generated by cubic spline interpolation) and real-time sensor data to ensure smooth transition of the instructions. The recovery detection module continuously detects the recovery status of flight control A / B: after flight control C also fails, if the heartbeat of any node returns to normal, the system switches back to the flight control with higher priority and re-enters the main logic loop; if all nodes fail, it triggers the ultimate fault alarm and starts the emergency response (such as the vote for the parachute opening instruction).
[0024] Embodiment
[0025] The present invention proposes an implementation method of a flight control system that deeply integrates a multi-level redundant architecture and a dynamic cooperation mechanism. Through the comprehensive application of heterogeneous hardware, space anti-interference deployment, and intelligent fault-tolerant algorithms, a full-dimensional fault-tolerant system covering hardware, data, environment, and communication is constructed. The system uses an A / M hybrid-core flight control (cooperation between ARM Cortex-A / M series processors and FPGA) to achieve hierarchical computing power scheduling. Combined with parallel power supply of the main and standby power supplies and space redundant deployment, it ensures high availability at the physical level. At the communication level, a hybrid topology network based on dual independent CAN buses, combined with optocoupler isolation and double-layer shielded cables, forms a redundant transmission channel resistant to electromagnetic interference, and realizes seamless switching between the main and standby flight controls through an incremental caching mechanism and a cubic spline interpolation algorithm. The emergency module constructs a multi-level protection barrier through redundant instruction voting (CRC-32 check + UTC timestamp) of three optocoupler isolation input channels and safety interlock conditions (GPS speed < 50m / s and altitude > 100m) to ensure reliable parachute opening response under abnormal conditions. This solution innovatively deeply integrates heterogeneous hardware dynamic scheduling, space anti-interference optimization, and data-driven fault tolerance, providing an all-round reliability guarantee for UAV control in high-dynamic and strong-interference scenarios, specifically as follows: 1. Three-flight-control hardware non-similar redundant architecture Heterogeneous hardware configuration: A-core flight control: ARM Cortex-A7 + Xilinx Zynq UltraScale FPGA M-core flight control: ARM Cortex-M7 + Microchip PolarFire FPGA A / M hybrid-core flight control: Dual ARM-core heterogeneous cooperation (Cortex-A8 + Cortex-M4) Each flight control unit reports its health status in real time (such as heartbeat signal, computing load rate, sensor verification code). The watchdog circuit is used to detect processor crashes; the Kalman filter residual analysis is used to detect abnormal control biases.
[0026] 2. Power supply method Parallel power supply is adopted by the main and backup power supplies. The main power supply is a high-voltage battery, which outputs 5V / 3.3V through a DCDC buck module. The backup power supply uses an independently configured lithium thionyl chloride battery, which supports a 72-hour standby.
[0027] 3. Location redundancy deployment scheme The redundant flight controls are respectively deployed in the nose shielding compartment, the fireproof compartment at the wing root (or the root of the arm) and the independent cavity of the tail beam. The spacing reaches 15%-25% of the fuselage length, reducing the impact of space failure. A physical barrier is constructed in three-dimensional space to ensure that regional failures will not cause cascading failures.
[0028] Interference resistance: The temperature is controlled in cooperation with a thermoelectric cooler (TEC1-12706) and a PTC heating film, and the temperature range covers -55°C to 105°C; orthogonal wiring + double-layer shielded cable (tinned copper mesh + aluminum foil) is used to reduce electromagnetic crosstalk.
[0029] 4. Communication redundant network architecture Two independent CAN buses (main bus and redundant bus) are deployed in parallel. Each node is equipped with two CAN controllers (STM32F4 series chips) and transceivers (SN65HVD230DR); a hybrid topology (star and bus) is adopted, and the communication signal quality and transmission delay are optimized through a repeater (CTM1051KT); bus terminal matching resistors are used to suppress signal reflection, and optocoupler isolation (HCPL-072L) is used to achieve electrical isolation between nodes; the cable uses double-layer shielded twisted pair (outer layer tinned copper mesh + aluminum foil), combined with a magnetic ring filter to suppress common-mode interference.
[0030] 5. Hierarchical switching of flight control The redundant flight controls achieve clock synchronization through a handshake method. Main flight control (A): Broadcast an encrypted heartbeat packet every 20ms, including timestamp, control instructions and power status; Primary backup (B): Continuously monitor the heartbeat packet of A. If it loses the packet twice in a row (40ms timeout), immediately initiate a request for takeover of control; Secondary backup (C): Normally monitor the heartbeat packet of B. When B is upgraded to the main controller, it switches to directly monitor B and takes over control when its heartbeat is lost.
[0031] Seamless switching guarantee mechanism: The backup flight control caches the control instructions of the main flight control in the last 5 cycles (100ms) in real time, and smoothly transitions based on the cubic spline interpolation algorithm during switching.
[0032] 1) Incremental cache type First-order difference (Δθ): Stores the difference in control quantities between adjacent cycles, such as
[0033] Second-order difference (Δ²θ): Stores the change in the difference, such as
[0034] If the change rate of the flight control command is small (such as in the hover state), it is more direct to store the original θ value; if the command is dynamically intense (such as in maneuvering flight), storing the second-order difference Δ²θ can compress the data volume and highlight the trend.
[0035] 2) Historical data reverse synthesis formula
[0036] : t 0 : The earliest timestamp of the cache window; t 5 : The latest timestamp of the cache window; β : Dynamic correction coefficient (dimensionless, value related to the scenario).
[0037] 3) Fusion formula
[0038] Cached interpolation command: , generated by cubic spline interpolation based on historical data within the cache window; Real-time calculation command: , independently calculated by the standby flight control based on current sensor data; Hybrid weight: , a dynamic weight coefficient that decays with time.
[0039] 4) Weight decay function Adopts an exponential decay curve to balance smoothness and response speed:
[0040] t 0 : Switch trigger moment (such as the start of the 8th cycle); T transition : Total transition duration (5 cycles); When t = t 0 + T transition At that time, (regarded as decay completed).
[0041] 5) Fusion process: Table 1 Example Table of Flight Control Switching Period Period Output flight control Data source Fusion operation 1-5 Main flight control Real-time sensor data None 6-7 Main flight control No output 8 Standby flight control Cache data of cycles 1 - 5 + real-time sensor data Hybrid interpolation 9 Standby flight control Cache data of cycles 2 - 5 + data of cycle 8 + real-time data Hybrid interpolation 10 Standby flight control Cache data of cycles 3 - 5 + data of cycles 8 - 9 + real-time data Hybrid interpolation 11 Standby flight control Cache data of cycles 4 - 5 + data of cycles 8 - 10 + real-time data Hybrid interpolation 12 Standby flight control Cache data of cycle 5 + data of cycles 8 - 11 + real-time data Hybrid interpolation 13 Standby flight control Real-time data None 6. Cooperative Control for Parachute Deployment The parachute controller integrates three opto - isolator input channels. The flight controls A / B / C send parachute deployment commands via independent RS - 422 links. The parachute controller is equipped with a barometer and an IMU dedicated to the parachute. Through a vote between redundant flight controls and dedicated sensors, if more than two commands require parachute deployment, the parachute deployment is triggered. The parachute deployment command is embedded with a CRC - 32 checksum and a timestamp (UTC synchronized) to prevent error codes caused by electromagnetic interference. A safety interlock function is added to unlock the parachute deployment function when the GPS speed < 50m / s and the altitude > 100m.
[0042] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non - exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device.
[0043] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A safety disaster recovery system based on flight control, characterized in that: The system first builds three independent flight control units through heterogeneous computing resources, and deploys the flight control units in different locations to achieve spatial redundant protection to avoid system crash caused by single point failure; each flight control unit transmits heartbeat signals and control instructions in real time through a redundant communication network; the main control system runs a hierarchical switching algorithm to achieve smooth transition output of instructions under redundant control, and reports the fault status at the same time; the output of the parachute opening command integrates the fault status issued by the flight control and the fault status of the parachute-specific sensor, and is voted on uniformly by the voter.
2. A safety disaster recovery system based on flight control according to claim 1, characterized in that: The system adopts a three-flight control hardware non-similar redundant architecture, where: The A-core flight control is ARM Cortex-A7 + Xilinx Zynq UltraScale FPGA; The M-core flight control is ARM Cortex-M7 + Microchip PolarFire FPGA; The A / M hybrid core flight control is a dual ARM core heterogeneous collaborative Cortex-A8+Cortex-M4; Through differentiated hardware design, basic computing power redundancy is established to provide heterogeneous computing resources for subsequent steps.
3. A safety disaster recovery system based on flight control according to claim 1, characterized in that: The system adopts a positional redundant deployment solution, deploying the flight control units in different spaces to ensure that regional failures will not cause cascading failures; the flight control units are distributed in the nose shielded cabin, the fireproof compartments at the wing root or the root of the arm, and the independent cavity of the tail boom, with a spacing of 15%-25% of the fuselage length.
4. The safety disaster recovery system based on flight control according to claim 1, characterized in that: The communication redundant network adopts dual independent CAN buses deployed in parallel, and each node is equipped with dual CAN controllers and transceivers; a hybrid topology is adopted to optimize the quality and transmission delay of communication signals through repeaters; bus terminal matching resistors are used to suppress signal reflection, and optical coupler isolation is used to achieve electrical isolation between nodes; the cable adopts double-layer shielded twisted pair, combined with magnetic ring filters to suppress common mode interference.
5. The safety disaster recovery system based on flight control according to claim 1, characterized in that: The main control system runs a hierarchical switching algorithm, and through the sequential switching of A→B→C, it ensures that a more reliable flight control is adopted each time to achieve safe disaster recovery of flight control switching; when switching to flight control C as the main flight control, it continuously monitors the recovery of flight control A / B to ensure that the main flight control C still has a backup flight control at this time.
6. A safety disaster recovery system based on flight control according to claim 5, characterized in that: The fault switching logic adopts a hierarchical and progressive design, with the heartbeat signal as the core trigger condition; In the main switching logic, the main flight controller A broadcasts an encrypted heartbeat packet. If two consecutive heartbeats are lost, the first-level backup flight controller B immediately takes over control and starts sending heartbeats. If the flight controller B also has an abnormal heartbeat, the secondary backup flight controller C will take over; During the takeover process, the standby flight control system dynamically fuses and outputs the first five cycle instructions in the cache with the real-time sensor data to ensure smooth transition of instructions. The recovery detection module continuously detects the recovery status of flight control A / B: When flight control C also fails, if the heartbeat of any node returns to normal, the system switches back to the flight control with a higher priority and re-enters the main logic loop; if all nodes fail, the ultimate fault alarm is triggered and the emergency response is initiated; Redundant flight controllers achieve clock synchronization through handshake; the main flight controller A broadcasts an encrypted heartbeat packet every 20ms, including a timestamp, control instructions, and power status; the first-level backup flight controller B continuously monitors A's heartbeat packet. If it is lost twice in a row, it immediately initiates a request to take over control; the second-level backup flight controller C normally monitors B's heartbeat packet. When B is upgraded to the main control, it switches to directly monitoring B, and takes over control when it detects that its heartbeat is lost.
7. A safety disaster recovery system based on flight control according to claim 6, characterized in that: The hierarchical switching algorithm adopts a seamless switching guarantee mechanism, specifically: the backup flight control caches the control instructions of the main flight control in the last five cycles in real time, and integrates the new / old data to complete the gradual transfer of control rights during switching; The control instruction cache format is: First-order difference Δθ: stores the difference in control quantity between adjacent cycles, indicating the instantaneous rate of change of control instructions between adjacent timestamps; ; Second-order difference Δ²θ: stores the change in the difference, reflecting the change acceleration of the first-order difference, and is used to capture sudden trend changes in high-dynamic maneuvers; ; If the flight control command change rate is small, it is more direct to store the original θ value; if the command dynamics are drastic, storing the second-order difference Δ²θ compresses the data volume and highlights the trend; Historical data reverse synthesis formula: ; In the formula, t 0 is the earliest timestamp of the cache window. t 5 is the latest timestamp of the cache window, β is the dynamic correction coefficient; The fusion formula is: ; Where, cache interpolation instruction Generated by cubic spline interpolation based on historical data in the cache window; real-time calculation instructions , the backup flight control is independently calculated based on the current sensor data; hybrid weight , a dynamic weight coefficient that decays over time; The weight decay function is: Use an exponential decay curve to balance smoothness and response speed: ; In the formula, t 0 is the switching trigger moment, T transition is the total duration of the transition; t = t 0+ T transition hour, , the decay is considered complete.
8. The safety disaster recovery system based on flight control according to claim 1, characterized in that: The parachute controller integrates three optocoupler isolated input channels, and the flight control A / B / C sends the parachute opening command through independent RS-422 links; the parachute controller adds a barometer and IMU dedicated to the parachute; through voting between the redundant flight control and the dedicated sensor, if more than two commands require the parachute to be opened, the parachute opening is triggered; the parachute opening command is embedded with a CRC-32 checksum and timestamp to prevent bit errors caused by electromagnetic interference; a safety interlock function is added, and the parachute opening function is unlocked when the GPS speed is <50m / s and the altitude is >100m.
Citation Information
Patent Citations
Redundancy control method of aircraft
CN106774367A
Aircraft, parachute control system and aircraft control system
CN111338377A
Manned aircraft parachute control method, controller system and manned aircraft
CN113815871A
Layered architecture fault tolerance method and device of aircraft flight control system
CN118795759A
Posture stabilizing device for parachute landing stage of electric vertical take-off and landing aircraft and analysis method
CN119389439A
Cited By
Flight control computer redundancy management method for preventing NAN fault from spreading
CN121455216A
A method for flight control computer redundancy management to prevent NAN failure propagation
CN121455216B