Multi-flight-control coordinated control method and system for aerospace system
By introducing a self-recommended election mechanism and voting mechanism in the multi-flight control node system, the coordination problem of coordinators after downtime in the multi-flight control node system is solved, distributed redundant control and efficient node election are realized, ensuring system stability and redundancy capabilities.
Patent Information
- Application Number
- CN202510481228.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-04-16
AI Technical Summary
The space systems with multiple flight control nodes in the prior art lack an effective coordination and synchronization decision-making mechanism, and the coordinator cannot automatically select a new coordinator when the coordinator goes down, resulting in insufficient system redundancy control.
By introducing a self-recommended election mechanism in the multi-flight control node system, using a fixed solution cycle and start message, the participating nodes allow themselves to elect new coordination points when the start message is not received, and the coordination points are determined through the voting mechanism to ensure that the system can automatically select nodes with the latest status to continue working when the coordinator goes down.
Distributed redundant control of multi-flight control node systems is realized, ensuring that the system can still operate effectively after a single node is abnormally downtime, avoiding network conflicts, and improving election efficiency and system stability.
Smart Images

Figure CN120386249A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of aerospace flight control, and in particular, to a multi-flight control coordinated control method and system for an aerospace system Background Art
[0002] Traditionally, only one flight control computer is deployed on a space launch vehicle. With the progress of technology, it has now become the mainstream technology to use multiple flight control nodes simultaneously on the flight control system of a launch vehicle for parallel multi-flight control calculations. In the prior art, multi-mode flight control systems are currently being deployed in various launch vehicle models, but no effective control models have been formed at the software and algorithm levels. The existing three-mode redundant on-board computer architecture for launch vehicles targets the redundancy of hardware interfaces and the two-out-of-three control logic, or a three-mode redundant control system relying on a specific hardware architecture, and realizes three-mode redundant control through a combination of software and hardware
[0003] In the process of implementing the present invention, the applicant found that there are at least the following problems in the prior art
[0004] How to achieve coordinated synchronous decision-making of multiple flight control nodes based on communication between multiple flight control nodes, and how to automatically select a new coordinator when the current coordinator fails Summary of the Invention
[0005] Embodiments of the present invention provide a multi-flight control coordinated control method and system for an aerospace system to solve the problems of how to achieve coordinated synchronous decision-making of multiple flight control nodes based on communication between multiple flight control nodes, and how to automatically select a new coordinator when the current coordinator fails
[0006] To achieve the above object, on the one hand, an embodiment of the present invention provides a multi-flight control coordinated control method for an aerospace system, which is adopted by a system composed of multiple flight control nodes, including
[0007] In response to the start of the current solution cycle, if a flight control node with a participating role does not receive a start message, the flight control nodes with a participating role that do not receive the start message conduct self-recommendation elections at different times to elect a flight control node from the flight control nodes with a participating role that do not receive the start message as the flight control node with a coordinating role in the current solution cycle
[0008] If all flight control nodes with a participating role receive the start message or a flight control node with a coordinating role in the current solution cycle is elected, the flight control node with a coordinating role in the current solution cycle coordinates and controls the flight control nodes with a participating role to complete the solution and execution of the flight control commands corresponding to the current solution cycle
[0009] Among them, the solution period is continuously triggered periodically at a fixed solution period interval; the start message is sent by the flight control node with the coordination role in the previous solution period continuing as the flight control node with the coordination role in the current solution period without failure, and in response to the start of the current solution period, it is sent to all flight control nodes with the participating role; all flight control nodes in the system except the flight control node with the coordination role are defaulted to flight control nodes with the participating role at the start of the solution period.
[0010] On the other hand, an embodiment of the present invention provides a multi-flight control coordination control system for a space system. The system includes: a plurality of flight control nodes; the roles of each flight control node include a coordination role, a participating role, and a candidate role;
[0011] The flight control node with the participating role is used to, in response to the start of the current solution period, if it does not receive the start message, conduct self-recommendation elections time-divisionally to elect a flight control node from the flight control nodes with the participating role that have not received the start message as the flight control node with the coordination role in the current solution period;
[0012] The flight control node with the coordination role in the current solution period is used to coordinately control the flight control nodes with the participating role to complete the solution and execution of the flight control commands corresponding to the current solution period;
[0013] Among them, the solution period is continuously triggered periodically at a fixed solution period interval; the start message is sent by the flight control node with the coordination role in the previous solution period continuing as the flight control node with the coordination role in the current solution period without failure, and in response to the start of the current solution period, it is sent to all flight control nodes with the participating role; all flight control nodes in the system except the flight control node with the coordination role are defaulted to flight control nodes with the participating role at the start of the solution period.
[0014] The above technical solution has the following beneficial effects: a redundant control method for distributed control is realized by conducting elections and coordination in a space control system with multiple flight control nodes. The coordinated control of multi-mode flight control nodes is realized by assigning roles to flight control nodes, supporting that after a single node crashes abnormally, the remaining system can still rely on the existing method for effective redundant control, and supporting the coordinated control of a distributed redundant flight control system with three modes or more. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1 is a flowchart of a multi-flight control coordination control method for a space system according to one embodiment of the present invention;
[0017] Figure 2 is an architecture diagram of a multi-flight control coordination control system for a space system according to one embodiment of the present invention;
[0018] Figure 3 is a schematic diagram of the role conversion of a flight control node according to one embodiment of the present invention;
[0019] Figure 4 is a schematic diagram of seven elements of a flight control node according to one embodiment of the present invention;
[0020] Figure 5 is a schematic diagram of the data message type and format between different roles according to one embodiment of the present invention;
[0021] Figure 6 is another flowchart of a multi-flight control coordination control method for a space system according to one embodiment of the present invention. Detailed implementation manners
[0022] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0023] On the one hand, as Figure 1 shown, an embodiment of the present invention provides a multi-flight control coordination control method for a space system, which is adopted by a system composed of multiple flight control nodes, including:
[0024] Step S10, in response to the start of the current solution period, if the flight control nodes participating in the role do not receive the start message, the flight control nodes participating in the role that do not receive the start message conduct self-recommendation elections time-sharingly to elect a flight control node from the flight control nodes participating in the role that do not receive the start message as the flight control node of the coordination role in the current solution period;
[0025] Step S11, if all the flight control nodes participating in the role receive the start message or the flight control node of the coordination role in the current solution period is elected, the flight control node of the coordination role in the current solution period coordinates and controls the flight control nodes participating in the role to complete the solution and execution of the flight control command corresponding to the current solution period;
[0026] Among them, the solution period is continuously triggered periodically at a fixed solution period interval; the start message is sent by the flight control node in the coordination role in the previous solution period to continue as the flight control node in the coordination role of the current solution period without failure, and in response to the start of the current solution period, it is sent to all flight control nodes in the participating roles; all flight control nodes in the system except the flight control node in the coordination role are defaulted to be flight control nodes in the participating roles at the start of the solution period.
[0027] In some embodiments, the solution cycles in the system are continuously triggered periodically at fixed solution cycle time intervals, and the solution cycle time intervals can be preset according to the real-time requirements of specific solutions. The solution cycles can be triggered by a unified external hardware signal, and the hardware signal arrives at all flight control nodes synchronously; thus, each flight control node can respond to this hardware signal simultaneously to respond to the start of the solution cycle at the same time. In the initial state when the system is powered on, all flight control nodes are defaulted to participating roles. Based on the reliable communication link between flight control nodes in the embodiments of the present invention, that is, when there are no self-failures in the mutually communicating flight control nodes, after a flight control node sends a message, the message will surely reach other flight control nodes in the system through the communication link. If within a certain time after the start of the solution cycle, there is a flight control node that does not receive the start message, then in the case that the flight control node that does not receive the start message has no self-failure, there should be no flight control node with an effective coordination role in the system. The reason may be the initial system reset state, or the flight control node that was the coordination role in the previous solution cycle has failed, so the failed coordination role flight control node cannot continue to work in the current solution cycle. If within a certain time after the start of the solution cycle, there is a flight control node that does not receive the start message, then the flight control node that does not receive the start message will conduct a self-recommendation election at different times. The self-recommendation election is that the flight control node that does not receive the start message recommends itself to other flight control nodes in the system as the flight control node with the coordination role. If other flight control nodes return consent, then the self-recommending flight control node will be the flight control node with the coordination role in the current solution cycle. If it is rejected, the next flight control node that does not receive the start message will continue to execute the self-recommendation election until a flight control node with the coordination role is elected. Usually, during the self-recommendation election, other flight control nodes need to judge whether the status of the self-recommending flight control node is the latest. When the status of the self-recommending flight control node is the latest, other flight control nodes will return consent to the self-recommending flight control node, otherwise they will return rejection to the self-recommending flight control node. The flight control node with the coordination role in the previous solution cycle can continue to be the flight control node with the coordination role in the current solution cycle without failure, and other flight control nodes are defaulted to participating roles at the start of each solution cycle. The flight control nodes with participating roles will conduct the self-recommendation election at different times when they do not receive the start message, which can avoid communication conflicts in the system caused by all flight control nodes with participating roles conducting the self-recommendation election simultaneously. Moreover, in the initial state of the system, there has not yet been a flight control node with the coordination role, and all are flight control nodes with participating roles. And at this time, the statuses of all flight control nodes with participating roles are the initial states. As long as the first flight control node with the participating role that executes the election process method conducts the self-recommendation election, it will be elected as the flight control node with the coordination role, thus significantly improving the efficiency of the system in electing the flight control node with the coordination role.At the beginning of each solution cycle, the states of each participating role are synchronized through the start message. The flight control nodes of the participating roles without faults can all receive the start message normally, so as to unify the states of the flight control nodes of the participating roles and the flight control nodes of the coordination role. In a state other than the initial state of the system, assuming that the flight control node of the coordination role in the previous solution cycle fails, then at the beginning of the current solution cycle, there is no available flight control node of the coordination role. However, at the beginning of the previous solution cycle, the states of each participating role have been synchronized. Therefore, at this time, by the flight control nodes of the participating roles self-recommending and electing a new flight control node of the coordination role, it is still possible to select the flight control node with the latest state in one or a few times. Thus, the embodiments of the present invention can select the flight control node with the latest state in the current system as the flight control node of the coordination role after a limited number of times, that is, usually without all the flight control nodes of the participating roles performing self-recommending and electing. In the current solution cycle, once there is a flight control node of the coordination role, the flight control node of the coordination role in the current solution cycle coordinates and controls the flight control nodes of the participating roles to complete the solution and execution of the flight control commands corresponding to the current solution cycle.
[0028] The embodiments of the present invention have the following technical effects: when there is no available flight control node of the coordination role in the system, the flight control nodes of each participating role can perform self-recommending and electing in a time-sharing manner, so as to support that after a single node crashes abnormally, the remaining system can still rely on the existing method for effective redundant control and support the coordinated control of a distributed redundant flight control system with three or more modes. And the flight control nodes perform in a time-sharing manner, so as to avoid the flight control nodes initiating election operations at the same time, avoid network communication conflicts, and improve the election efficiency.
[0029] Further, in response to the start of the current solution cycle, if the flight control node of the participating role does not receive the start message, the flight control node of the participating role that does not receive the start message performs self-recommending and electing in a time-sharing manner to elect a flight control node from the flight control nodes of the participating roles that do not receive the start message as the flight control node of the coordination role in the current solution cycle, including:
[0030] In response to the start of the current solution cycle, if the flight control node of the participating role does not receive the start message within its respective start message timeout period, then in the case where the start message timeout period corresponding to it times out, the flight control node of the participating role that times out switches its own role to a candidate role and becomes a flight control node of the candidate role;
[0031] The flight control node of the candidate role sets the status information in the candidate message according to the locally recorded status information and sends the candidate message to all the flight control nodes of the participating roles;
[0032] All the flight control nodes of the participating roles receive the candidate message;
[0033] The flight control nodes of each participating role compare the status information in the candidate message with the status information of the flight control nodes of the participating role. If the status information of the flight control nodes of the participating role is newer than the status information in the candidate message, the flight control nodes of the participating role generate a vote message with a vote result of rejection; otherwise, they generate a vote message with a vote result of approval and send the vote message to the flight control nodes of the candidate role.
[0034] The flight control nodes of the candidate role collect the vote messages of all the flight control nodes of the participating roles and count the number of vote messages with a vote result of approval. If the number of vote messages with a vote result of approval exceeds half of the number of all the flight control nodes of the participating roles, the flight control nodes of the candidate role set their own role as the coordination role to obtain the flight control nodes of the coordination role in the current solution cycle; otherwise, the flight control nodes of the candidate role switch their own role to the participating role and become the flight control nodes of the participating role again.
[0035] Among them, the start message timeout times corresponding to each flight control node are different, and all the start message timeout times are greater than the time required for the flight control node of the coordination role to respond to the start of the solution cycle and send the start message, and the time difference between any two start message timeout times is greater than the time required to perform a self-recommendation election.
[0036] Preferably, the time required for the flight control node of the coordination role to respond to the start of the solution cycle and send the start message is 0.5 milliseconds.
[0037] In some embodiments Figure 3The figure shows the state transition diagram of the flight control node among different roles. After the start of each solution cycle, if a flight control node of each participating role (i.e., the participant) does not receive the start message within its corresponding start message timeout period, it will switch its own role to the candidate role and become a flight control node with the candidate role (i.e., the candidate). The flight control node with the candidate role will send a candidate message to the flight control nodes of the participating roles in the system and wait for the flight control nodes of the participating roles to return the voting message. If more than half of the participating roles return voting messages with the voting result of approval to the flight control node with the candidate role, the flight control node with the candidate role will switch its own role to the coordination role and become a flight control node with the coordination role; if the flight control node with the candidate role does not receive the voting messages from more than half of the flight control nodes of the participating roles within the preset candidate waiting time after sending the candidate message, a candidate timeout occurs, and the candidate message is resent. Under the condition of the reliable communication link in the embodiment of the present invention, generally, the flight control node with the candidate role that has a candidate timeout has a fault itself. If the flight control node with the candidate role receives the voting messages returned by more than half of the flight control nodes of the participating roles and more than half of the voting results are rejection, the flight control node with the candidate role is not selected and switches its own role to the participating role and becomes a flight control node with the participating role again. For the flight control node that has already become the coordination role, additional fault tolerance judgment is provided. When the flight control node with the coordination role receives the solution result from the flight control node with the participating role, it will also receive the status locally recorded by the flight control node with the participating role at the same time. The solution result obtained in the current solution cycle is still an effective solution result for the space flight data in the current cycle and can be used by the flight control node with the coordination role in the current solution cycle to continue generating the flight control command and execute the flight control command. If the flight control node with the coordination role discovers a flight control node with updated status through the status locally recorded by the received flight control node with the participating role, it will switch its own role back to the participating role, which will result in the absence of a flight control node with the coordination role in the next solution cycle, and thus a new election will start to elect the flight control node with the latest status as the flight control node with the coordination role in the next solution cycle. By comparing the old and new relationships between various status information locally recorded by each flight control node with the participating role and the corresponding status information recorded in the candidate message, when the various status information locally recorded is older than the corresponding status information recorded in the candidate message, the flight control node with the candidate role that agrees to send the candidate message is elected as the flight control node with the coordination role. When the flight control node with the candidate role that is agreed by more than half of the flight control nodes with the participating role to send the candidate message is elected as the flight control node with the coordination role, the flight control node with the candidate role that sends the candidate message will modify its own role to the coordination role. If more than half of the flight control nodes with the participating role reject, the flight control node with the candidate role that sends the candidate message will switch back to the flight control node with the participating role again.Each flight control node is set with its own start message timeout. All flight control nodes respond to the start of the same solution cycle and calculate the start message timeout from the same moment. However, the start message timeouts corresponding to each flight control node are different. Therefore, in the case of not receiving the start message, the flight control nodes in the participating role will become candidate nodes sequentially at different times, and there will not be two or more flight control nodes switching from the participating role to the candidate role simultaneously. The election process method refers to the process where a flight control node starts from switching from the participating role to the candidate role, sends a candidate message in the candidate role, receives voting messages from more than half of the flight control nodes in the participating role, and updates its own role of the flight control node that sent the candidate message to the coordinator role or the participating role according to the received voting messages. That is, in the embodiment of the present invention, in response to the start of the current solution cycle, if any one or more flight control nodes in the participating role do not receive the start message within their respective start message timeouts, then the flight control nodes in the participating role that do not receive the start message within the corresponding start message timeouts will switch their own roles to the candidate role. The steps from the flight control node that becomes the candidate role to the candidate role flight control node collecting the voting messages of all the flight control nodes in the participating role and counting the number of voting messages with the voting result of consent. If the number of voting messages with the voting result of consent exceeds half of the number of all the flight control nodes in the participating role, then the candidate role flight control node sets its own role to the coordinator role to obtain the flight control node in the coordinator role in the current solution cycle. Otherwise, the candidate role flight control node switches its own role to the participating role and becomes a flight control node in the participating role again.
[0038] The embodiment of the present invention has the following technical effects: by setting different start message timeout times corresponding to different flight control nodes, in order to enable the flight control nodes of each participating role to switch to the candidate role in a time-sharing manner when the start message is not received, thereby avoiding multiple flight control nodes from becoming candidate roles at the same time, thereby avoiding the occurrence of sending candidate messages at the same time, resulting in communication conflicts within the system, and avoiding the complex situation where the flight control nodes of the participating roles need to handle candidate messages from multiple sources that appear at the same time. The start message timeout time is greater than the time required for the flight control node of the coordinating role to respond to the start of the solution cycle and send the start message, which can ensure that when the start message can be sent normally, the start message can reach the flight control nodes of each participating role in time within the start message timeout time of the flight control nodes of each participating role, thereby avoiding the competition problem between the arrival of the start message and the start message timeout judgment of the flight control nodes of the participating roles. The time difference between any two start message timeouts is greater than the time required to perform a self-nomination election. This ensures that when each flight control node that enters the candidate role performs the self-nomination election, no other flight control node accidentally switches from the participating role to the candidate role. This avoids two or more flight control nodes in the candidate role from performing the self-nomination election at the same time, reduces the complexity of the candidate process, and improves the predictability, stability, and maintainability of the system behavior.
[0039] Furthermore, each flight control node is preset with a different unique number;
[0040] The start message timeout time corresponding to each flight control node is randomly generated according to the following formula (1):
[0041] time=(T+k*Span+k*rand) (1)
[0042] Among them, time is the start message timeout period corresponding to the flight control node; T is the time required for the flight control node of the coordination role to respond to the start of the solution cycle and send a start message; Span represents the time required for the flight control node of the candidate role to perform a self-recommendation election; k is the unique number of the flight control node; rand is a random number.
[0043] In some embodiments, each flight control node presets a different unique number. Preferably, the unique number is a numerical value. The time T required for the flight control node with the coordination role to send a start message in response to the start of the solution cycle can be obtained through multiple tests and statistics. For example, the maximum value of the required time obtained from multiple tests can be taken, or a margin can be added on the basis of the maximum value. The setting of Span is based on the time required for a flight control node with a candidate role to complete a self-recommendation election. For example, through multiple tests and statistics, the maximum value of the time required to complete a self-recommendation election can be determined, and this maximum value can be used as the value of Span, or a margin can be added on the basis of this maximum value as the value of Span. Preferably, the value of T is 0.5 milliseconds. Preferably, the value of Span is 0.1 milliseconds; preferably, rand is a random number greater than zero.
[0044] The embodiments of the present invention have the following technical effects: The start message timeout is controlled to be greater than T milliseconds, so that the flight control node with the coordination role that already exists at the start of each solution cycle can complete the sending of the start message, and to prevent any flight control node participating in the role from entering the candidate role. k*span can ensure that the time between each flight control node participating in the role entering the candidate state is at least separated by span milliseconds, so as to prevent more than one flight control node with a candidate role from starting a self-recommendation election at the same time, and to prevent another flight control node with a candidate role from starting a self-recommendation election during the period when the previous flight control node with a candidate role is performing a self-recommendation election. After the flight control node that entered the candidate state earlier selects the coordination node, the new coordination node has time to send a sampling message. k*rand can further randomly increase the time interval between flight control nodes participating in the role entering the candidate state, increasing the safety margin.
[0045] Furthermore, the status information locally recorded by the flight control node includes: the locally recorded coordination ID, the consistent command ID, and the individual command ID;
[0046] The flight control node with the candidate role sets the status information in the candidate message according to the locally recorded status information, including:
[0047] The flight control node with the candidate role uses the locally recorded consistent command ID as the consistent command ID in the candidate message, the locally recorded individual command ID as the individual command ID in the candidate message, and calculates the coordination ID in the candidate message according to the following formula to obtain the candidate message:
[0048] ID 报 =(floor(ID 本 ÷N)+1)*N+k (2)
[0049] where ID 报is the coordination ID in the candidate message; floor() is the floor function; ID 本 is the coordination ID locally recorded by the flight control node of the candidate role; N is the total number of flight control nodes in the system; k is the unique number of the flight control node of the candidate role;
[0050] The flight control node of the candidate role setting its own role to the coordination role further includes:
[0051] The flight control node of the candidate role updates the locally recorded coordination ID with the new coordination ID calculated using the following formula, and sets the locally recorded individual command ID and consensus command ID to 0:
[0052] ID 新 =(floor(ID 本 ÷N)+1)*N+k (3)
[0053] where, ID 新 is the new coordination ID; floor() is the floor function; ID 本 is the coordination ID locally recorded by the flight control node of the candidate role; N is the total number of flight control nodes in the system; k is the unique number of the flight control node of the candidate role;
[0054] where, the fields of the candidate message include: the coordination ID, the consensus command ID, and the individual command ID in the candidate message;
[0055] Each flight control node is preset with a unique number that is different from each other. The initial value of the coordination ID locally recorded by each flight control node is set to the unique number of the flight control node; the consensus command ID locally recorded by each flight control node is initialized to 0 when the flight control node switches from the candidate role to the coordination role, and is incremented by the flight control node of the coordination role when generating a flight control command, and is synchronized to the flight control nodes of the participating roles through the start message; the individual command ID locally recorded by each flight control node is used as the unique identifier of the spaceflight data during the current coordination role of the flight control node of the coordination role; the spaceflight data is obtained by the flight control node of the coordination role collecting the on-board sensors in each solution cycle.
[0056] In some embodiments, each flight control node is preset with a unique and different number, and the initial value of the coordination ID recorded locally by each flight control node is set to the unique number of the flight control node. Before a flight control node in the candidate role sends a candidate message to other flight control nodes, it generates the coordination ID in the candidate message based on the coordination ID recorded locally according to formula (2). If the flight control node in the candidate role is finally agreed to become a flight control node in the coordination role, then the flight control node in the candidate role will calculate a new coordination ID based on the coordination ID recorded locally according to formula (3), and use the new coordination ID to update the coordination ID recorded locally. Formula (2) and formula (3) are the same, only used at different times, and both calculate the coordination ID in the candidate message and the new coordination ID based on the same coordination ID recorded locally by the same flight control node in the candidate role. The coordination ID in the candidate message sent by the flight control node in the candidate role is essentially the same as the new coordination ID calculated after being agreed to become the coordination role. The coordination ID increments by N when a flight control node changes from the candidate role to the coordination role. In the case of 32-bit unsigned integer representation, it increments once per resolution cycle (for example, increments once every 10 milliseconds), and it takes 497 / N days to overflow and roll over, where N is the total number of flight control nodes in the system.
[0057] Further, the status information recorded locally by each flight control node includes: the coordination ID recorded locally, the consistent command ID, and the individual command ID;
[0058] Each flight control node in the participating role compares the status information in the candidate message with the status information of the flight control node in the participating role. If the status information of the flight control node in the participating role is newer than the status information in the candidate message, then the flight control node in the participating role generates a vote message with a vote result of rejection; otherwise, it generates a vote message with a vote result of approval, including:
[0059] The flight control node in the participating role compares the size of the coordination ID recorded locally with the coordination ID in the candidate message, the size of the consistent command ID recorded locally with the consistent command ID in the candidate message, and the size of the individual command ID recorded locally with the individual command ID in the candidate message;
[0060] If the coordination ID in the candidate message is greater than the coordination ID locally recorded by the flight control node of the participating role, and the consensus command ID in the candidate message is greater than or equal to the consensus command ID locally recorded by the flight control node of the participating role, and the individual command ID in the candidate message is greater than or equal to the individual command ID locally recorded by the flight control node of the participating role, then the flight control node of the participating role updates the coordination ID locally recorded by the flight control node of the participating role with the coordination ID in the candidate message, sets both the locally recorded consensus command ID and individual command ID to 0, and encapsulates the values of the locally recorded coordination ID, consensus command ID, and individual command ID into a voting message, and sets the voting result of the voting message to agree; otherwise, the flight control node of the participating role encapsulates the values of the locally recorded coordination ID, consensus command ID, and individual command ID into a voting message, and sets the voting result of the voting message to reject;
[0061] Among them, the fields of the voting message include: the coordination ID, consensus command ID, individual command ID, and voting result in the voting message;
[0062] Each flight control node is preset with a unique number that is different from each other. The initial value of the coordination ID locally recorded by each flight control node is set to the unique number of the flight control node; the consensus command ID locally recorded by each flight control node is initialized to 0 when the flight control node switches from the candidate role to the coordination role, and is incremented by the flight control node in the coordination role when generating a flight control command, and is synchronized to the flight control nodes in the participating role through a start message; the individual command ID locally recorded by each flight control node is used as the unique identifier of the spaceflight data during the current coordination role of the flight control node in the coordination role; the spaceflight data is obtained by the flight control node in the coordination role by collecting on-board sensors in each solution cycle.
[0063] Further, the status information locally recorded by each flight control node includes: the coordination ID, consensus command ID, individual command ID, and local command ID locally recorded;
[0064] The flight control node in the coordination role in the current solution cycle coordinates and controls the flight control nodes in the participating role to complete the solution and execution of the flight control command corresponding to the current solution cycle, including:
[0065] The flight control node with the coordination role in the current solution cycle collects space flight data, uses the value of the local command ID + 1 as the individual command ID corresponding to the collected space flight data, takes the collected space flight data as the space flight data in the collection message, takes the individual command ID corresponding to the collected space flight data as the individual command ID in the collection message, and takes the coordination ID locally recorded by the flight control node with the coordination role in the current solution cycle as the coordination ID in the collection message, to obtain the collection message;
[0066] The flight control node with the coordination role in the current solution cycle sends the collection message to all flight control nodes with participating roles;
[0067] Each flight control node with a participating role receives the collection message, obtains the individual command ID and the space flight data in the collection message, updates the individual command ID and the local command ID locally recorded using the individual command ID in the collection message, and solves the space flight data to obtain the solution result corresponding to the space flight data and the navigation guidance control process parameters;
[0068] Each flight control node with a participating role assigns the coordination ID, the individual command ID from the collection message, the navigation guidance control process parameters, and the solution result locally recorded respectively to the coordination ID, the individual command ID, the navigation guidance control process parameters, and the solution result in the result message to obtain the corresponding result message;
[0069] Each flight control node with a participating role sends its corresponding result message to the flight control node with the coordination role in the current solution cycle;
[0070] After the flight control node with the coordination role in the current solution cycle receives the result messages corresponding to more than half of the flight control nodes with participating roles, it obtains the navigation guidance control process parameters and the solution result from the received result messages;
[0071] According to the obtained navigation guidance control process parameters and the solution result, generate the flight control command corresponding to the current solution cycle, execute the flight control command, increment the local command ID locally recorded by the flight control node with the coordination role in the current solution cycle by 1, and assign the value of the incremented locally recorded local command ID to the consistent command ID and the individual command ID locally recorded;
[0072] Among them, the fields of the collection message include: the coordination ID, the individual command ID, and the space flight data in the collection message;
[0073] Each flight control node is preset with a unique number that is different from others. The initial value of the 0 coordination ID locally recorded by each flight control node is set to the unique number of the flight control node; the consistent command ID locally recorded by each flight control node is initialized to 0 when the flight control node switches from a candidate role to a coordination role, and is incremented by the flight control node in the coordination role when generating a flight control command, and is synchronized to the flight control nodes in the participating roles through a start message; the individual command ID locally recorded by each flight control node is used to identify the space flight data solved by the flight control node.
[0074] In some embodiments, the flight control node in the coordination role collects space flight data and sends the space flight data to all other flight control nodes for solution. Using multiple flight control nodes for solution is to prevent the problem that the data in the storage units in a small number of flight control nodes is abnormally changed due to ray interference during space flight, resulting in the final solution result being unavailable. Different flight control nodes may be interfered with, resulting in calculation errors in some nodes. Since the flight control nodes that are in error due to interference from space rays are usually in the minority, the results calculated by multiple flight control nodes are voted on by the majority, and the result with the majority advantage is selected to ensure the correctness of the final solution result used to the greatest extent.
[0075] Further, after the flight control node in the coordination role in the current solution cycle receives the result messages corresponding to more than half of the flight control nodes in the participating roles, it obtains the navigation guidance and control process parameters and the solution result from the received result messages, including:
[0076] The flight control node in the coordination role in the current solution cycle selects, from the received result messages corresponding to multiple flight control nodes in the participating roles, the result message whose coordination ID is equal to the coordination ID locally recorded by the flight control node in the coordination role in the current solution cycle and whose individual command ID is greater than the local command ID locally recorded by the flight control node in the coordination role in the current solution cycle as the candidate result message;
[0077] The flight control node in the coordination role in the current solution cycle performs similarity screening on the solution results in the obtained multiple candidate result messages, and uses the navigation guidance and control process parameters and the solution results in one or more candidate result messages whose similarity exceeds the preset similarity threshold as the navigation guidance and control process parameters and the solution results obtained from all the result messages.
[0078] In some embodiments, when performing calculations, the flight control nodes of each participating role, in addition to using the spaceflight data from the flight control nodes of the coordinating role, also use some data collected by the flight control nodes of the participating role themselves. There may be deviations in the collected results of this part of the data among the flight control nodes, which may lead to differences in the calculation results and the navigation, guidance, and control process parameters obtained by the flight control nodes of different participating roles. However, this kind of difference is normally relatively small. By methods such as similarity screening or clustering analysis, the calculation results and the navigation, guidance, and control process parameters with large deviations or outliers can be excluded, so as to retain the most correct calculation results and the navigation, guidance, and control process parameters for generating flight control commands.
[0079] Further, the method further includes:
[0080] If the flight control node of the candidate role receives the acquisition message sent by the flight control node of the coordinating role, and the coordinating ID recorded locally by the flight control node of the candidate role is less than or equal to the coordinating ID in the acquisition message, then the flight control node of the candidate role switches itself to the flight control node of the participating role;
[0081] Wherein, the acquisition message is formed by the flight control node of the coordinating role collecting spaceflight data, encapsulating the spaceflight data and the locally recorded coordinating ID, and is sent by the flight control node of the coordinating role to the flight control node of the candidate role.
[0082] In some embodiments, since each flight control node operates independently, after the flight control node of the candidate role elected through self-checking becomes the coordinating role, before the flight control node of the new coordinating role sends the acquisition message, it is possible that other flight control nodes of the participating role become the flight control nodes of the candidate role because they reach the corresponding start message timeout. If the flight control node of the candidate role receives the acquisition message and the coordinating ID in the acquisition message is greater than the coordinating ID recorded locally by the flight control node of the candidate role, then the flight control node of the candidate role should recognize the flight control node of the coordinating role and switch to the flight control node of the participating role, obtain data from the acquisition message to perform calculations, and generate calculation results.
[0083] The embodiments of the present invention have the following technical effects: After obtaining the flight control node of the coordinating role, if the flight control node of the coordinating role has the latest status in the system, by sending the acquisition message, the flight control nodes that simultaneously become the candidate role during this period can be switched back to the participating role, ensuring the consistency of the cooperation among the flight control nodes of the system, and preventing the situation where some flight control nodes calculate data under the coordination of the flight control node of the coordinating role while another or some flight control nodes are still trying to elect.
[0084] Further, the method further includes:
[0085] If the flight control node of the candidate role receives the acquisition message sent by the flight control node of the coordination role, and the coordination ID recorded locally by the flight control node of the candidate role is greater than the coordination ID in the acquisition message, then the flight control node of the coordination role switches to the flight control node of the participating role.
[0086] In some embodiments, if the coordination ID recorded locally by the flight control node of the candidate role is greater than the coordination ID in the acquisition message, it indicates that the flight control node of the coordination role self-recommended by the previous flight control node of the candidate role is not the latest. At this time, in order to keep the overall state of the system up-to-date, the current flight control node of the coordination role needs to abandon the coordination role and switch to the participating role. Since the current flight control node of the candidate role is in the candidate role, it will continue to self-recommend and be elected as the flight control node of the new coordination role, so as to keep the overall state of the system up-to-date.
[0087] On the other hand, as Figure 2 shown, the embodiment of the present invention provides a multi-flight control coordination control system for a space system, and the system includes: a plurality of flight control nodes; the roles of each flight control node include a coordination role, a participating role, and a candidate role;
[0088] The flight control node of the participating role is used to, in response to the start of the current solution cycle, if it does not receive the start message, conduct self-recommendation and election at different times to elect a flight control node from the flight control nodes of the participating role that have not received the start message as the flight control node of the coordination role in the current solution cycle;
[0089] The flight control node of the coordination role in the current solution cycle is used to coordinately control the flight control nodes of the participating role to complete the solution and execution of the flight control commands corresponding to the current solution cycle;
[0090] Wherein, the solution cycle is continuously triggered periodically at a fixed solution cycle interval; the start message is a message sent by the flight control node of the coordination role in the previous solution cycle that continues to be the flight control node of the coordination role in the current solution cycle and in response to the start of the current solution cycle to all flight control nodes of the participating role; all flight control nodes in the system except the flight control node of the coordination role are defaulted to be flight control nodes of the participating role at the start of the solution cycle.
[0091] Further, the flight control node of the participating role is specifically used to, in response to the start of the current solution cycle, if it does not receive the start message within the respective start message timeout period, then when the start message timeout period corresponding to it times out, the flight control node of the participating role that times out switches its own role to the candidate role and becomes the flight control node of the candidate role;
[0092] The flight control node of the candidate role is used to set the status information in the candidate message according to the locally recorded status information and send the candidate message to the flight control nodes of all participating roles;
[0093] The flight control nodes of all participating roles are used to receive the candidate message;
[0094] The flight control node of each participating role is further used to compare the status information in the candidate message with the status information of the flight control node of the participating role. If the status information of the flight control node of the participating role is newer than the status information in the candidate message, the flight control node of the participating role generates a voting message with a voting result of rejection. Otherwise, it generates a voting message with a voting result of approval and sends the voting message to the flight control node of the candidate role;
[0095] The flight control node of the candidate role is used to collect the voting messages of the flight control nodes of all participating roles and count the number of voting messages with a voting result of approval. If the number of voting messages with a voting result of approval exceeds half of the number of flight control nodes of all participating roles, the flight control node of the candidate role sets its own role as the coordination role to obtain the flight control node of the coordination role in the current solution cycle. Otherwise, the flight control node of the candidate role switches its own role to the participating role and becomes the flight control node of the participating role again;
[0096] Among them, the start message timeout times corresponding to each flight control node are different, and all start message timeout times are greater than the time required for the flight control node of the coordination role to respond to the start of the solution cycle and send the start message, and the time difference between any two start message timeout times is greater than the time required to execute a self-recommendation election.
[0097] Preferably, the time required for the flight control node of the coordination role to respond to the start of the solution cycle and send the start message is 0.5 milliseconds.
[0098] Further, each flight control node is preset with a unique number that is different from each other;
[0099] The start message timeout times corresponding to the flight control nodes are randomly generated according to formula (1).
[0100] Further, the status information locally recorded by the flight control node includes: the locally recorded coordination ID, consistent command ID, and individual command ID;
[0101] The flight control node of the candidate role is further used to use the locally recorded consistent command ID as the consistent command ID in the candidate message, the locally recorded individual command ID as the individual command ID in the candidate message, and calculate the coordination ID in the candidate message according to formula (2) to obtain the candidate message;
[0102] The flight control node of the candidate role is also used to update the coordinated ID recorded locally with the new coordinated ID calculated using formula (3), and set the individual command ID and the consensus command ID recorded locally to 0;
[0103] Among them, the fields of the candidate message include: the coordinated ID, the consensus command ID, and the individual command ID in the candidate message;
[0104] N is the total number of flight control nodes in the system; each flight control node is preset with a unique number that is different from each other, and the initial value of the coordinated ID recorded locally by each flight control node is set to the unique number of the flight control node; the consensus command ID recorded locally by each flight control node is initialized to 0 when the flight control node switches from the candidate role to the coordinated role, and is incremented by the flight control node in the coordinated role when generating a flight control command, and is synchronized to the flight control nodes in the participating role through the start message; the individual command ID recorded locally by each flight control node is used as the unique identifier of the spaceflight data during the current coordinated role of the flight control node in the coordinated role; the spaceflight data is obtained by the flight control node in the coordinated role by collecting the on-board sensors in each solution cycle.
[0105] Furthermore, the status information recorded locally by each flight control node includes: the coordinated ID, the consensus command ID, and the individual command ID recorded locally;
[0106] The flight control node in the participating role is also used to compare the coordinated ID recorded locally with the coordinated ID in the candidate message, as well as the consensus command ID recorded locally with the consensus command ID in the candidate message, and the individual command ID recorded locally with the individual command ID in the candidate message; if the coordinated ID in the candidate message is greater than the coordinated ID recorded locally by the flight control node in the participating role, and the consensus command ID in the candidate message is greater than or equal to the consensus command ID recorded locally by the flight control node in the participating role, and the individual command ID in the candidate message is greater than or equal to the individual command ID recorded locally by the flight control node in the participating role, then the flight control node in the participating role uses the coordinated ID in the candidate message to update the coordinated ID recorded locally by the flight control node in the participating role, sets both the consensus command ID and the individual command ID recorded locally to 0, and encapsulates the values of the coordinated ID, the consensus command ID, and the individual command ID recorded locally into a voting message, and sets the voting result of the voting message to agree; otherwise, the flight control node in the participating role encapsulates the values of the coordinated ID, the consensus command ID, and the individual command ID recorded locally into a voting message, and sets the voting result of the voting message to reject;
[0107] Among them, the fields of the voting message include: the coordination ID, the consensus command ID, the individual command ID, and the voting result in the voting message;
[0108] Each flight control node is preset with a unique and different number. The initial value of the coordination ID locally recorded by each flight control node is set to the unique number of the flight control node; the initial value of the consensus command ID locally recorded by each flight control node is initialized to 0 when the flight control node switches from the candidate role to the coordination role, and is incremented by the flight control node in the coordination role when generating the flight control command, and is synchronized to the flight control nodes in the participating roles through the start message; the individual command ID locally recorded by each flight control node is used as the unique identifier of the spaceflight data during the current coordination role of the flight control node in the coordination role; the spaceflight data is obtained by the flight control node in the coordination role by collecting on-board sensors in each solution cycle.
[0109] Furthermore, the status information locally recorded by each flight control node includes: the coordination ID, the consensus command ID, the individual command ID, and the local command ID locally recorded;
[0110] The flight control node in the coordination role in the current solution cycle is used to collect spaceflight data, use the value of local command ID + 1 as the individual command ID corresponding to the collected spaceflight data, use the collected spaceflight data as the spaceflight data in the collection message, use the individual command ID corresponding to the collected spaceflight data as the individual command ID in the collection message, and use the coordination ID locally recorded by the flight control node in the coordination role in the current solution cycle as the coordination ID in the collection message to obtain the collection message; and send the collection message to all flight control nodes in the participating roles;
[0111] Each flight control node in the participating role is further used to receive the collection message, obtain the individual command ID and the spaceflight data in the collection message, update the individual command ID and the local command ID locally recorded using the individual command ID in the collection message, and solve the spaceflight data to obtain the solution result and the navigation guidance and control process parameters corresponding to the spaceflight data;
[0112] Each flight control node in the participating role is further used to assign the coordination ID, the individual command ID from the collection message, the navigation guidance and control process parameters, and the solution result locally recorded by each to the coordination ID, the individual command ID, the navigation guidance and control process parameters, and the solution result in the result message respectively to obtain the corresponding result message;
[0113] Each flight control node in the participating role is further used to send the corresponding result message to the flight control node in the coordination role in the current solution cycle;
[0114] The flight control node with the coordination role in the current solution cycle is also used to obtain the navigation guidance control process parameters and solution results from the received result messages after receiving the result messages corresponding to more than half of the flight control nodes with the participating roles; generate the flight control command corresponding to the current solution cycle according to the obtained navigation guidance control process parameters and solution results, execute the flight control command, increment by 1 the local command ID locally recorded by the flight control node with the coordination role in the current solution cycle, and assign the value of the incremented locally recorded local command ID to the locally recorded consistent command ID and individual command ID;
[0115] Among them, the fields of the acquisition message include: the coordination ID, individual command ID, and space flight data in the acquisition message;
[0116] Each flight control node is preset with a unique number that is different from each other. The initial value of the coordination ID locally recorded by each flight control node is set to the unique number of the flight control node; the consistent command ID locally recorded by each flight control node is initialized to 0 when the flight control node switches from the candidate role to the coordination role, and is incremented by the flight control node with the coordination role when generating the flight control command, and is synchronized to the flight control nodes with the participating roles through the start message; the individual command ID locally recorded by each flight control node is used to identify the space flight data calculated by the flight control node.
[0117] Further, the flight control node with the coordination role in the current solution cycle is also used to select, from the received result messages corresponding to multiple flight control nodes with the participating roles, the result message whose coordination ID is equal to the coordination ID locally recorded by the flight control node with the coordination role in the current solution cycle and whose individual command ID is greater than the local command ID locally recorded by the flight control node with the coordination role in the current solution cycle as the candidate result message;
[0118] The flight control node with the coordination role in the current solution cycle is also used to perform similarity screening on the solution results in the obtained multiple candidate result messages, and use the navigation guidance control process parameters and solution results in one or more candidate result messages whose similarity exceeds the preset similarity threshold as the navigation guidance control process parameters and solution results obtained from all the result messages.
[0119] Further, the flight control node with the candidate role is also used to, if it receives the acquisition message sent by the flight control node with the coordination role and the coordination ID locally recorded by the flight control node with the candidate role is less than or equal to the coordination ID in the acquisition message, then the flight control node with the candidate role switches itself to the flight control node with the participating role;
[0120] Among them, the collected message is encapsulated by the flight control node with the coordination role by collecting space flight data and combining the space flight data with the coordination ID recorded locally, and is sent by the flight control node with the coordination role to the flight control node with the candidate role.
[0121] Further, the flight control node with the candidate role is further configured to, if receiving the collected message sent by the flight control node with the coordination role and the coordination ID recorded locally by the flight control node with the candidate role is greater than the coordination ID in the collected message, switch the flight control node with the coordination role to the flight control node with the participating role.
[0122] For the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the partial description of the method embodiment.
[0123] The above technical solutions of the embodiments of the present invention will be described in detail below in conjunction with specific application examples. For technical details not introduced during the implementation process, reference can be made to the relevant descriptions above.
[0124] The multi-flight control coordination control method provided by the embodiments of the present invention is based on the fixed flight control solution period commonly used in the space system (for example, with a fixed solution period of 10 ms). Within one period, the flight control node needs to complete basic operation steps such as sensor data acquisition, flight control solution (including navigation, guidance, and attitude control operations), and control output. The embodiments of the present invention propose a multi-flight control coordination control method, which solves the problem of coordination and synchronization decision-making between multiple flight control nodes, ensures that multiple flight controls can elect a coordinator for unified execution scheduling, and can timely elect a new coordinator for periodic scheduling and command when the coordinator has errors such as downtime.
[0125] The roles of the flight control nodes in the embodiments of the present invention will be described below. At the beginning of each period of the coordination control method provided by the embodiments of the present invention, each flight control node can receive the same hardware interrupt signal for synchronizing the solution periods of all nodes. The existence of the hardware signal is to ensure that the 10-ms periods of all participants are synchronized. Each flight control node needs to act as different roles such as a participant, a candidate, and a coordinator during the algorithm operation. The descriptions of the roles are as follows:
[0126] Participant (flight control node with the participating role): The default role of each flight control node is a participant. The participant responds to the commands of the candidate and the coordinator and gives responses to various requests. At the beginning of each solution period, if the participant does not receive the "start" message from the coordinator within the specified time, the role will change to "candidate";
[0127] Candidate (flight control node with the candidate role): The candidate is an intermediate role elected from the "participants" to the "coordinator";
[0128] Coordinator (the flight control node in the coordination role): Only a "candidate" approved by more than half of the participants can become the coordinator during a round of election. The coordinator is responsible for the rhythm control of each calculation cycle. In each cycle, the coordinator needs to notify all participants of the start of the cycle, collect all sensor data and rocket body status on the rocket, and forward them to all participants. After all participants have completed their calculations, the coordinator aggregates the calculation results of this round, issues control instructions to the control equipment of the rocket body, and notifies the status of the instructions in the previous cycle while notifying all participants of the start of the next calculation cycle.
[0129] There are the following conversion relationships among the three different roles, as Figure 3 shown. All nodes are in the role of participants. Even if elected as the coordinator, they still need to perform the basic role functions of participants. At the beginning of each operation cycle, the participants wait for a certain period of time. The length of the waiting time needs to be randomly calculated according to the attributes of the nodes. To ensure that each participant can determine timeout at different times and perform corresponding timeout handling, at the beginning of each cycle, if there is a coordinator among the nodes, it will immediately send a start message to all participants to prevent participants from timing out. When any participant times out, that participant will become a candidate and start sending candidate requests to other participants within this cycle. After sending the candidate request, the candidate starts waiting for the responses from each participant. When the candidate receives the consent result messages from more than half of the participants, the candidate becomes the coordinator and proceeds with subsequent coordination control operations. Otherwise, when the candidate learns that it has not been elected successfully, it needs to resume the role of a participant. If no valid response is received, the candidate will maintain its candidate role and still perform candidate operations. If there are faults in all flight control nodes, resulting in multiple coordinators, since the coordinator itself is a participant, when it learns from the messages sent by other coordinators that its coordination ID is less than the coordination ID in the message, it will immediately change its role from coordinator to participant to resolve role conflicts.
[0130] Data format description: Each flight control node includes a calculation unit and a storage unit. The calculation unit is used for performing mathematical operations such as flight control GNC (Navigation, Guidance, Control), as Figure 4 shown. The storage unit needs to store at least seven elements: coordination ID, command ID, input (space flight data), calculation parameters, output (calculation results), individual command ID, and consensus command ID.
[0131] Coordinated ID: A unique auto-incrementing ID used when running for the coordinator. It is recommended to use a 32-bit unsigned integer. If a vote is held in each flight control calculation cycle (incrementing every 10 ms), it takes 497 / N days to overflow, where N is the total number of flight control nodes in the system. The coordinated ID is incremented by N by the candidate during each coordinator election;
[0132] Command ID: Here, "command" refers to the command instructions sent by the flight control to the execution mechanism of the space system within a flight control calculation cycle. The command ID is used to represent a certain command number ID executed during a coordinator's tenure. Together with the coordinator ID, a certain command can be uniquely determined. The command ID starts from 0 and increments by 1 in each calculation cycle within the same coordinator's tenure (i.e., command ID = command ID + 1). It is recommended to use a 32-bit unsigned integer. The command ID is data stored by each flight control node itself, which is different from the individual command ID and the consistent command ID introduced below;
[0133] Input: Various sensor information collected by the coordinator from the rocket, such as control input data from inertial measurement units, satellite navigation, air pressure, vibration, liquid level, current, voltage, etc.;
[0134] Calculation parameters: Data parameters during the calculation process after the flight control computer obtains the input data, such as process data such as the position, velocity, acceleration, angular velocity, and elevation of the rocket obtained by calculation;
[0135] Output: Output data calculated by the flight control computer in each calculation cycle, such as control output data such as servo rudder swing instructions, engine adjustment depth, and tank pressurization instructions;
[0136] Individual command ID: Used to record the currently completed command ID. Whether it is the coordinator or the participant, after a round of calculation cycles, set the individual command ID = local command ID; the local command ID is reset to 0 after a vote is completed, and the initial value is 0.
[0137] Consistent command ID: Commands have two states: "consistent" and "individual". When the coordinator receives the calculation results from more than half of the participants, assign the coordinator's local command ID to the "consistent command ID". In the next calculation cycle, the coordinator needs to distribute its own "consistent command ID" to all participants through the consistent command ID in the start message. When the participant receives the "start (coordinator ID, consistent command ID)" data message with the (coordinator ID, consistent command ID), set the local consistent command ID = the consistent command ID in the start message.
[0138] Message type description: As Figure 5 shown, the data message types and formats between different roles.
[0139] Start Message: At the beginning of each flight control calculation cycle, the coordinator sends a start message to all participants. In the message content, the coordination ID is the local coordination ID of the coordinator, and the consensus command ID is the value of the last command ID that has reached the "consensus" state recorded by the current coordinator. When a participant finds that both the coordination ID and the consensus command ID in the start message are greater than or equal to the local recorded coordination ID and consensus command ID, it updates the local consensus command ID, local command ID, and individual command ID with the consensus command ID in the start message.
[0140] Acquisition Message: The coordinator distributes the collected sensor data and various states of the rocket body to all participants in the form of input. The coordination ID in this message is the local coordination ID of the coordinator, and the individual command ID is the new command ID for this calculation cycle, that is, individual command ID = local command ID + 1 (note that when encapsulating the acquisition message, the local command ID itself is not incremented, but only the value of local command ID + 1 is assigned to the individual command ID in the acquisition message. Because after receiving the result message, it is necessary to compare that the individual command ID in the result message is greater than the local command ID to consider the result message legal. The local command ID is recalculated from 0 within each coordinator tenure and will repeat). After receiving the acquisition message, the participant updates the local local command ID and individual command ID with the individual command ID in the message and changes the local command status to "individual"; the data to be calculated is tracked through the individual command ID. When it is returned to the coordinator, the coordinator can know whether the received calculation result is the calculation result of the space flight data that the current coordinator wants. After the coordinator receives result messages from more than half of the participants, it increments the local command ID recorded locally by the coordinator itself and assigns the incremented local command ID to the consensus command ID recorded locally.
[0141] Result Message: After completing the flight control calculation for this cycle, the participant combines the GNC process parameters (navigation, guidance, and control process parameters) and outputs (i.e., the calculation results) used in the calculation process with the local coordination ID and the individual command ID obtained from the acquisition message (at this time, the participant has already stored the individual command ID in the acquisition message in the local individual command ID recorded by the participant, so the local recorded individual command ID can also be directly obtained here) to form a result message;
[0142] Candidate message: A message sent by a candidate to a participant. The candidate hopes to be elected as the coordinator and sends the coordination ID for the current coordination process to the participant (the calculation method is formula (2). Note that when sending the candidate message, the candidate only uses the value of the coordination ID calculated by formula (2) as the coordination ID in the candidate message, but the candidate does not change the value of the coordination ID recorded locally at this time; when the candidate obtains the consent of the majority of participants and can become the coordinator, the candidate will update the coordination ID recorded locally to the new coordination ID value calculated by formula (3), and will also set the last command ID that has been "agreed" confirmed locally (i.e., the agreed command ID recorded locally) to 0; the last command ID that has been "agreed" confirmed locally is the agreed command ID obtained by the coordinator in the previous resolution cycle. If the current coordinator is a newly elected coordinator in the current resolution cycle, the agreed command ID is set to 0 when switching from candidate to coordinator).
[0143] Vote message: The participant votes according to the voting and election decision method introduced below. If the participant agrees to the candidate's candidacy request, the participant updates its own coordination ID (if the participant agrees to the candidate's candidacy request, the participant updates its own coordination ID to the value of the coordination ID in the candidate message), and sets its own command ID, agreed command ID, and individual command ID to 0, and sets the result in the vote message to agree. Otherwise, the participant sends its current coordination ID, agreed command ID, and individual command ID, and sets the result to reject;
[0144] The algorithm operation flowchart is as Figure 6 shown; Figure 6 The operation flowchart of, which details all the operation processes that each flight control node needs to complete in a flight control resolution cycle. The leftmost column of the process represents the operations that need to be performed by the coordinator in one cycle, and the remaining right part lists the process descriptions of the candidate and voting processes as a participant and a possible candidate.
[0145] Timeout period description: Each non-coordinator flight control node needs to wait for a certain period of time at the beginning of the cycle to receive the start message from the coordinator. The waiting time for each node is different from each other. In the embodiment of the present invention, it is recommended to set a unique number k (0 ≤ k < N, where N is the number of flight control nodes) for each flight control node. The timeout time time = (0.5 + k * 0.1 + k * rand) milliseconds, where rand represents a random floating point number in the range of (0 to 0.1). This timeout time can ensure that the timeout times of each flight control node are different, avoiding multiple participants becoming candidates at the same time and causing collisions in the election process. The initial 0.5 milliseconds of the timeout time is because the coordinator can surely complete the start notification to all participants within 0.5 milliseconds.
[0146] Voting and election decision algorithm: Among the seven elements recorded by participants, there are a coordination ID, a consensus command ID, and a separate command ID, which are used for voting and election. If the coordination ID of the candidate message received by a participant > the local coordination ID, and the consensus command ID of the candidate message ≥ the local consensus command ID, and the separate command ID ≥ the local separate command ID (indicating that the command ID stored by the candidate being voted for is not older than the command ID of this participant, that is, this candidate is more qualified to be the coordinator than this participant), the participant can elect the current candidate as the coordinator. The participant updates its own coordination ID = the coordination ID of the candidate message, command ID = 0, separate command ID = 0, and consensus command ID = 0. After the candidate receives voting messages with the result of consent sent by more than half of the participants, it modifies its own coordination ID.
[0147] The embodiments of the present invention have the following technical effects: A redundant control method for realizing distributed control through election coordination in a multi-flight control node aerospace control system. The coordinated control of multi-mode flight control nodes is realized by assigning roles to flight control nodes, supporting that after a single node crashes abnormally, the remaining system can still perform effective redundant control relying on the existing method, and supporting the coordinated control of a distributed redundant flight control system with three modes or more. The embodiments of the present invention only rely on the flight control nodes themselves to achieve triple modular redundancy, which is realized by software and algorithms and does not rely on other hardware and systems on the rocket. The control logic is to select a leader from the three modes as the core of decision-making, and the other modules only provide data providers. When the leader fails, the remaining modules re-elect and can still achieve redundant control, supporting multi-mode systems with more than three modes.
[0148] It should be understood that the specific order or hierarchy of steps in the disclosed process is an example of an exemplary method. Based on design preferences, it should be understood that the specific order or hierarchy of steps in the process can be rearranged without departing from the scope of the present disclosure. The appended method claims present the elements of the various steps in an exemplary order and are not intended to be limited to the specific order or hierarchy described.
[0149] In the above detailed description, various features are combined in a single embodiment to simplify the present disclosure. This method of disclosure should not be construed as reflecting an intention that the embodiments of the claimed subject matter require more features than are clearly recited in each claim. On the contrary, as reflected in the appended claims, the present invention lies in a state with fewer features than all the features of the disclosed single embodiment. Therefore, the appended claims are hereby expressly incorporated into the detailed description, where each claim stands alone as a separate preferred embodiment of the present invention.
[0150] The above-described embodiments have been presented for the purpose of enabling any person skilled in the art to make or use the present invention. For those skilled in the art, various modifications to these embodiments will be readily apparent, and the general principles defined herein may be applied to other embodiments without departing from the spirit and scope of the present disclosure. Thus, the present disclosure is not limited to the embodiments given herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed in this application.
[0151] The above description includes examples of one or more embodiments. Of course, it is not possible to describe all possible combinations of components or methods for the purpose of describing the above embodiments, but those of ordinary skill in the art should recognize that the various embodiments can be further combined and arranged. Thus, the embodiments described herein are intended to cover all such changes, modifications, and variations that fall within the scope of the appended claims. Additionally, with respect to the term "comprising" used in the specification or claims, the word is intended to be construed in a manner similar to the term "including". Further, any use of the term "or" in the specification or claims is intended to mean "non-exclusive or".
[0152] Those skilled in the art will also appreciate that the various illustrative logical blocks, units, and steps listed in the embodiments of the present invention may be implemented by electronic hardware, computer software, or a combination of both. To clearly show the interchangeability of hardware and software, the various illustrative components, units, and steps have been generally described in terms of their functionality. Whether such functionality is implemented by hardware or software depends upon the particular application and design constraints of the overall system. Those skilled in the art may implement the described functionality in various ways for each particular application, but such implementation should not be construed as departing from the scope of the embodiments of the present invention.
[0153] The various illustrative logical blocks or units described in the embodiments of the present invention may be implemented or operated by a general-purpose processor, a digital signal processor, an application specific integrated circuit (ASIC), a field programmable gate array or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described. A general-purpose processor may be a microprocessor, or, optionally, the general-purpose processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented by a combination of computing devices, such as a digital signal processor and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a digital signal processor core, or any other similar configuration.
[0154] In the embodiments of the present invention, the steps of the methods or algorithms described may be directly embedded in hardware, software modules executed by a processor, or a combination of the two. The software modules may be stored in a RAM memory, a flash memory, a ROM memory, an EPROM memory, an EEPROM memory, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium in the art. Exemplarily, the storage medium may be connected to the processor so that the processor can read information from the storage medium and write information to the storage medium. Optionally, the storage medium may also be integrated into the processor. The processor and the storage medium may be provided in an ASIC, and the ASIC may be provided in a user terminal. Optionally, the processor and the storage medium may also be provided in different components of the user terminal.
[0155] In one or more exemplary designs, the above-described functions in the embodiments of the present invention may be implemented in hardware, software, firmware, or any combination of the three. If implemented in software, these functions may be stored on a computer-readable medium or transmitted on a computer-readable medium in the form of one or more instructions or codes. The computer-readable medium includes a computer storage medium and a communication medium that facilitates the transfer of a computer program from one place to another. The storage medium may be any available medium accessible by a general or special computer. For example, such a computer-readable medium may include, but is not limited to, RAM, ROM, EEPROM, CD-ROM, or other optical disk storage, magnetic disk storage, or other magnetic storage devices, or any other medium that can be used to carry or store program code in the form of instructions or data structures and other forms readable by a general or special computer, or a general or special processor. In addition, any connection may be appropriately defined as a computer-readable medium. For example, if software is transmitted from a website, a server, or other remote resources through a coaxial cable, a fiber optic cable, a twisted pair, a digital subscriber line (DSL), or wirelessly, such as infrared, wireless, and microwave, it is also included in the defined computer-readable medium. The disks and discs include compact disks, laser disks, optical discs, DVDs, floppy disks, and Blu-ray discs. Disks usually reproduce data magnetically, while discs usually reproduce data optically by laser. The above combinations may also be included in the computer-readable medium.
[0156] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A multi-flight control coordinated control method for a space system, characterized in that, Adopted by a system composed of multiple flight control nodes, including: In response to the start of the current solution cycle, if a flight control node of a participating role does not receive a start message, the flight control nodes of the participating roles that have not received the start message conduct self-recommendation elections at different times to elect a flight control node from the flight control nodes of the participating roles that have not received the start message as the flight control node of the coordination role in the current solution cycle; If all flight control nodes of the participating roles receive the start message or the flight control node of the coordination role in the current solution cycle is elected, the flight control node of the coordination role in the current solution cycle coordinates and controls the flight control nodes of the participating roles to complete the solution and execution of the flight control commands corresponding to the current solution cycle; Among them, the solution cycle is continuously triggered periodically at a fixed solution cycle interval; the start message is sent by the flight control node of the coordination role in the previous solution cycle that continues to be the flight control node of the coordination role in the current solution cycle and, in response to the start of the current solution cycle, sends it to all flight control nodes of the participating roles to update the status of all flight control nodes of the participating roles to the latest message; all flight control nodes in the system except the flight control node of the coordination role are defaulted to flight control nodes of the participating roles at the start of the solution cycle.
2. The multi-flight control coordinated control method for the aerospace system according to claim 1, wherein, The step that in response to the start of the current solution cycle, if a flight control node of a participating role does not receive a start message, the flight control nodes of the participating roles that have not received the start message conduct self-recommendation elections at different times to elect a flight control node from the flight control nodes of the participating roles that have not received the start message as the flight control node of the coordination role in the current solution cycle, includes: In response to the start of the current solution cycle, if a flight control node of a participating role does not receive a start message within its respective start message timeout period, when the corresponding start message timeout period expires, the flight control node of the participating role that has timed out switches its own role to a candidate role and becomes a flight control node of the candidate role; The flight control node of the candidate role sets the status information in the candidate message according to the locally recorded status information and sends the candidate message to all flight control nodes of the participating roles; All flight control nodes of the participating roles receive the candidate message; Each flight control node of the participating role compares the status information in the candidate message with the status information of the flight control node of the participating role. If the status information of the flight control node of the participating role is newer than the status information in the candidate message, the flight control node of the participating role generates a vote message with a vote result of rejection, otherwise generates a vote message with a vote result of approval, and sends the vote message to the flight control node of the candidate role; The flight control node of the candidate role collects the voting messages of the flight control nodes of all participating roles, and counts the number of voting messages with the voting result of approval. If the number of voting messages with the voting result of approval exceeds half of the number of flight control nodes of all participating roles, the flight control node of the candidate role sets its own role as the coordination role to obtain the flight control node of the coordination role in the current solution cycle. Otherwise, the flight control node of the candidate role switches its own role to the participating role and becomes the flight control node of the participating role again; Among them, the start message timeout times corresponding to each flight control node are different, and all start message timeout times are greater than the time required for the flight control node of the coordination role to respond to the start of the solution cycle and send a start message, and the time difference between any two start message timeout times is greater than the time required to perform a self-recommendation election.
3. The multi-flight control coordinated control method for the aerospace system according to claim 2, characterized in that Each flight control node is preset with a unique number that is different from each other; The start message timeout times corresponding to each flight control node are randomly generated according to the following formula: time=(T + k*Span + k*rand) Where time is the start message timeout time corresponding to the flight control node; T is the time required for the flight control node of the coordination role to respond to the start of the solution cycle and send a start message, Span represents the time required for the flight control node of the candidate role to perform a self-recommendation election, k is the unique number of the flight control node, and rand is a random number.
4. The multi-flight control coordinated control method for the aerospace system according to claim 2, characterized in that, The status information recorded locally by the flight control node includes: the coordination ID, the consensus command ID, and the individual command ID recorded locally; The flight control node of the candidate role sets the status information in the candidate message according to the status information recorded locally, including: The flight control node of the candidate role uses the consensus command ID recorded locally as the consensus command ID in the candidate message, the individual command ID recorded locally as the individual command ID in the candidate message, and calculates the coordination ID in the candidate message according to the following formula to obtain the candidate message: ID 报 =(floor(ID 本 ÷N)+1)*N + k Among them, ID 报 is the coordination ID in the candidate message; floor() is the floor function; ID 本 is the coordination ID locally recorded by the flight control node of the candidate role; N is the total number of flight control nodes in the system; k is the unique number of the flight control node of the candidate role; The flight control node of the candidate role setting its own role as the coordination role further includes: The flight control node of the candidate role updates the coordination ID recorded locally with the new coordination ID calculated by the following formula, and sets the individual command ID and the consensus command ID recorded locally to 0: ID 新 =(floor(ID 本 ÷N)+1)*N + k Among them, ID 新 is the new coordinated ID; floor() is the floor function; ID 本 is the coordinated ID locally recorded by the flight control node of the candidate role; N is the total number of flight control nodes in the system; k is the unique number of the flight control node of the candidate role; Among them, the fields of the candidate message include: the coordination ID, the consensus command ID, and the individual command ID in the candidate message; N is the total number of flight control nodes in the system; each flight control node is preset with a unique and different number, and the initial value of the coordination ID locally recorded by each flight control node is set to the unique number of the flight control node; the initial value of the consensus command ID locally recorded by each flight control node is initialized to 0 when the flight control node switches from the candidate role to the coordination role, and is incremented by the flight control node in the coordination role when generating a flight control command, and is synchronized to the flight control nodes in the participating role through the start message; the individual command ID locally recorded by each flight control node is used as the unique identifier of the spaceflight data during the current coordination role of the flight control node in the coordination role; the spaceflight data is obtained by the flight control node in the coordination role by collecting on-board sensors in each solution cycle.
5. The multi-flight control coordinated control method for the aerospace system according to claim 2, characterized in that, The status information locally recorded by each flight control node includes: the coordination ID, the consensus command ID, and the individual command ID locally recorded. Each flight control node in the participating role compares the status information in the candidate message with the status information of the flight control node in the participating role. If the status information of the flight control node in the participating role is newer than the status information in the candidate message, the flight control node in the participating role generates a vote message with a vote result of rejection; otherwise, it generates a vote message with a vote result of approval, including: The flight control node in the participating role compares the size of the coordination ID locally recorded with the coordination ID in the candidate message, the size of the consensus command ID locally recorded with the consensus command ID in the candidate message, and the size of the individual command ID locally recorded with the individual command ID in the candidate message. If the coordination ID in the candidate message is greater than the coordination ID locally recorded by the flight control node in the participating role, and the consensus command ID in the candidate message is greater than or equal to the consensus command ID locally recorded by the flight control node in the participating role, and the individual command ID in the candidate message is greater than or equal to the individual command ID locally recorded by the flight control node in the participating role, then the flight control node in the participating role uses the coordination ID in the candidate message to update the coordination ID locally recorded by the flight control node in the participating role, sets both the locally recorded consensus command ID and the individual command ID to 0, and encapsulates the values of the coordination ID, the consensus command ID, and the individual command ID locally recorded into the vote message, and sets the vote result of the vote message to approval; otherwise, the flight control node in the participating role encapsulates the values of the coordination ID, the consensus command ID, and the individual command ID locally recorded into the vote message, and sets the vote result of the vote message to rejection; Among them, the fields of the vote message include: the coordination ID, the consensus command ID, the individual command ID, and the vote result in the vote message; Each flight control node is preset with a unique and different number, and the initial value of the coordination ID locally recorded by each flight control node is set to the unique number of the flight control node; the consistent command ID locally recorded by each flight control node is initialized to 0 when the flight control node switches from a candidate role to a coordination role, and is incremented by the flight control node in the coordination role when generating a flight control command, and is synchronized to the flight control nodes in the participating roles through the start message; the individual command ID locally recorded by each flight control node is used as the unique identifier of the spaceflight data during the current coordination role of the flight control node in the coordination role; the spaceflight data is collected by the flight control node in the coordination role from the on-board sensors in each solution cycle.
6. The multi-flight control coordinated control method for the aerospace system according to claim 1, wherein The status information locally recorded by each flight control node includes: the coordination ID, consistent command ID, individual command ID, and local command ID locally recorded. The flight control node in the coordination role in the current solution cycle coordinates and controls the flight control nodes in the participating roles to complete the solution and execution of the flight control command corresponding to the current solution cycle, including: The flight control node in the coordination role in the current solution cycle collects spaceflight data, uses the value of local command ID + 1 as the individual command ID corresponding to the collected spaceflight data, takes the collected spaceflight data as the spaceflight data in the collection message, takes the individual command ID corresponding to the collected spaceflight data as the individual command ID in the collection message, and takes the coordination ID locally recorded by the flight control node in the coordination role in the current solution cycle as the coordination ID in the collection message, to obtain the collection message; The flight control node in the coordination role in the current solution cycle sends the collection message to all flight control nodes in the participating roles; Each flight control node in the participating role receives the collection message, obtains the individual command ID and spaceflight data in the collection message, updates the individual command ID and local command ID locally recorded using the individual command ID in the collection message, and solves the spaceflight data to obtain the solution result and navigation guidance control process parameters corresponding to the spaceflight data; Each flight control node in the participating role assigns the coordination ID, individual command ID, navigation guidance control process parameters, and solution result locally recorded to the coordination ID, individual command ID, navigation guidance control process parameters, and solution result in the result message respectively, to obtain the corresponding result message; Each flight control node in the participating role sends its corresponding result message to the flight control node in the coordination role in the current solution cycle; After the flight control node in the coordination role in the current solution cycle receives the result messages corresponding to more than half of the flight control nodes in the participating roles, it obtains the navigation guidance control process parameters and solution result from the received result messages; Based on the obtained navigation and guidance control process parameters and the solution results, generate the flight control commands corresponding to the current solution cycle, execute the flight control commands, increment by 1 the local command ID recorded locally by the flight control node of the coordination role in the current solution cycle, and assign the value of the incremented locally recorded local command ID to the locally recorded consistent command ID and individual command ID; Among them, the fields of the collected message include: the coordination ID, individual command ID, and spaceflight data in the collected message; Each flight control node is preset with a unique number that is different from each other. The initial value of the coordination ID recorded locally by each flight control node is set to the unique number of the flight control node; the initial value of the consistent command ID recorded locally by each flight control node is initialized to 0 when the flight control node switches from the candidate role to the coordination role, and is incremented by the flight control node of the coordination role when generating flight control commands, and is synchronized to the flight control nodes of the participating roles through the start message; the individual command ID recorded locally by each flight control node is used to identify the spaceflight data calculated by the flight control node.
7. The multi-flight control coordinated control method for the aerospace system according to claim 6, characterized in that After the flight control node of the coordination role in the current solution cycle receives the result messages corresponding to more than half of the flight control nodes of the participating roles, obtain the navigation and guidance control process parameters and the solution results from the received result messages, including: The flight control node of the coordination role in the current solution cycle selects, from the received result messages corresponding to multiple flight control nodes of the participating roles, the result message whose coordination ID is equal to the coordination ID recorded locally by the flight control node of the coordination role in the current solution cycle and whose individual command ID is greater than the local command ID recorded locally by the flight control node of the coordination role in the current solution cycle as the candidate result message; The flight control node of the coordination role in the current solution cycle performs similarity screening on the solution results in the obtained multiple candidate result messages, and uses the navigation and guidance control process parameters and solution results in one or more candidate result messages whose similarity exceeds the preset similarity threshold as the navigation and guidance control process parameters and solution results obtained from all the result messages.
8. The multi-flight control coordinated control method for the aerospace system according to claim 5, characterized in that The method further includes: If the flight control node of the candidate role receives the collected message sent by the flight control node of the coordination role, and the coordination ID recorded locally by the flight control node of the candidate role is less than or equal to the coordination ID in the collected message, then the flight control node of the candidate role switches itself to the flight control node of the participating role; Among them, the collected message is formed by the flight control node of the coordination role collecting spaceflight data and encapsulating the spaceflight data and the locally recorded coordination ID, and is sent by the flight control node of the coordination role to the flight control node of the candidate role.
9. The multi-flight control coordinated control method for the aerospace system according to claim 8, characterized in that The method further includes: If the flight control node of the candidate role receives the collected message sent by the flight control node of the coordination role, and the coordination ID recorded locally by the flight control node of the candidate role is greater than the coordination ID in the collected message, then the flight control node of the coordination role switches to the flight control node of the participating role.
10. A multi-flight control coordination control system for a space system, characterized in that, The system includes: multiple flight control nodes; the role of each flight control node includes a coordination role, a participating role, and a candidate role; The flight control node of the participating role is used to, in response to the start of the current solution cycle, if no start message is received, conduct self-recommendation elections at different times to elect a flight control node from the flight control nodes of the participating roles that have not received the start message as the flight control node of the coordination role in the current solution cycle; The flight control node of the coordination role in the current solution cycle is used to coordinate and control the flight control nodes of the participating roles to complete the solution and execution of the flight control commands corresponding to the current solution cycle; Among them, the solution cycle is continuously triggered periodically at a fixed solution cycle interval; the start message is a message sent by the flight control node of the coordination role in the previous solution cycle, when it continues to be the flight control node of the coordination role in the current solution cycle and in response to the start of the current solution cycle, to all flight control nodes of the participating roles; all flight control nodes in the system except the flight control node of the coordination role are defaulted to the flight control nodes of the participating roles at the start of the solution cycle.
Citation Information
Patent Citations
Multi-task self-scheduling modular flight control system and design method thereof
CN109062246A
Multi-spacecraft main and auxiliary sequence cooperative control system and method
CN112462712A
Method for generating simplified test case set of flight control airborne model
CN113900942A
Method, device and equipment for selecting credible coordinator for federal learning
CN114721789A
Comprehensive simulation rocket flight test method, device, medium and equipment
CN117193042A