Switching method and switching system of aircraft control system, equipment and medium
By defining state value mutex logic and strict switching conditions in the aircraft control system, using hardware logic circuits and closed-loop self-checking and repair verification, the conflicts and out of control risks in the switching of the main and standby system are solved, and high reliability and safety master and standby switching is achieved.
Patent Information
- Application Number
- CN202510565550.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-05
AI Technical Summary
The switching logic of the main and standby system in the existing aircraft control system lacks a strict interlocking mechanism, which causes the main and standby system to output control instructions at the same time or not output instructions, causing system conflicts. The backup system does not clearly define the real-time status, which poses a risk of out of control.
By defining the state value mutual exclusion logic of the first system board and the second system board and the strict dual switching conditions, the state of the main and standby system is separated, and only switches when the main and use system is abnormal and the standby system is in place and working normally. The hardware logic circuit is used to force constraints on the state value mutual exclusion, and through the request-confirm interaction mechanism and closed-loop self-check and repair verification, the reliability and security of the switching are ensured.
It realizes high-reliability master-stop switching of the aircraft control system, avoids command conflicts in parallel output of dual systems, prevents missed switching and forced takeover in case of abnormal backup systems, and improves control continuity and operational safety.
Smart Images

Figure CN120428693A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of aircraft control technology, and in particular to a switching method, switching system, equipment and medium of an aircraft control system. Background Art
[0002] In the field of aircraft control, active-standby redundant systems are an important means of improving reliability. Existing technologies typically employ dual system board backup solutions, but these solutions present the following challenges in practice: The active-standby switching logic lacks a strict interlocking mechanism, which can cause the active and standby systems to simultaneously output control commands or neither to output commands, leading to system conflicts. Furthermore, the switching conditions do not clearly define the real-time status of the standby system (such as its presence and operational integrity), leading to the risk of aircraft loss of control by switching even when the standby system itself is faulty.
[0003] Therefore, there is an urgent need for a switching method for aircraft control systems that can strictly verify the availability of the backup system when the main system is abnormal, and ensure the separation of the main and backup system states through a logical value interlocking mechanism, thereby overcoming the risk of loss of control caused by switching conflicts and unavailability of the backup system. Summary of the Invention
[0004] In view of this, the present invention provides a switching method, switching system, equipment and medium for an aircraft control system to solve the problem of switching failure caused by logical conflicts between the main and backup systems and unavailability of the backup system in the prior art. The technical solution is as follows.
[0005] In a first aspect, the present invention provides a method for switching an aircraft control system, wherein the aircraft control system includes a first system board and a second system board that serve as backups for each other, the method comprising:
[0006] Setting the state value of the first system board to a first logic value and the state value of the second system board to a second logic value; the first logic value causes the corresponding system board to output a control instruction to the aircraft, and the second logic value causes the corresponding system board not to output a control instruction;
[0007] When it is detected that the first system board is in an abnormal state and the second system board is in place and working normally, the state value of the second system board is updated to a first logic value so that the second system board outputs a control instruction, and the state value of the first system board is updated to a second logic value so that the first system board stops outputting a control instruction.
[0008] The switching method of the aircraft control system provided by the present invention realizes high-reliability master-slave switching of the aircraft control system by defining the mutually exclusive logic of the state values of the first system board and the second system board and strict dual switching conditions. Specifically, first, by setting the state values of the main system (first system board) and the backup system (second system board) to the first logical value and the second logical value respectively, the states of the two are forced to be separated, ensuring that the main system has exclusive control instruction output authority, and completely avoiding instruction conflicts caused by the parallel output of the dual systems; secondly, only when the main system is abnormal and the backup system meets the "in place" and "working normally" conditions at the same time, the main and backup state value exchange is triggered, which not only prevents invalid switching caused by the main system misjudging the fault, but also eliminates the risk of forcibly taking over control when the backup system itself is abnormal; finally, the authority transfer is completed based on the main system's own state judgment and the backup system availability verification, which simplifies the timing control of the switching logic and reduces the system complexity. The above design enables the aircraft to quickly and safely switch to the available backup system when the main system fails, significantly improving control continuity and operational safety.
[0009] In an optional implementation, detecting that the first system board is in an abnormal state includes:
[0010] When the fault signal of the first system board continues to exceed a preset time threshold, or the cumulative number of instantaneous faults exceeds a set threshold, it is determined that the first system board is in an abnormal state.
[0011] The switching method for an aircraft control system provided by the present invention avoids erroneous switching due to occasional instantaneous interference by setting dual judgment conditions of fault signal duration and number of instantaneous faults, while ensuring accurate identification of persistent or cumulative faults and improving the reliability of abnormal state judgment.
[0012] In an optional embodiment, the method further includes:
[0013] When it is detected that the first system board is in an abnormal state, a master / slave switch request signal is sent to the second system board, and a state value update is performed after a confirmation response from the second system board is received.
[0014] The switching method of the aircraft control system provided by the present invention ensures that the backup system is in a takeover state before switching through a request-confirmation interaction mechanism between the primary and backup systems, avoids switching failures caused by the backup system not being ready or communication anomalies, and enhances the coordination and controllability of the primary and backup switching.
[0015] In an optional embodiment, the status values of the first system board and the second system board are mutually exclusive through a NAND gate logic circuit, and the dominance of the status value change of the system board whose status value is the first logic value belongs to its own logic unit.
[0016] The switching method of the aircraft control system provided by the present invention prevents dual-master control conflicts by forcibly constraining the mutual exclusivity of the master and backup state values (they cannot be the first logical value at the same time) through a hardware logic circuit. That is, when the state value of the first system board is the first logical value, the state value of the second system board can only be the second logical value, and vice versa. At the same time, the master system leads the switching process to prevent the backup system from arbitrarily seizing control authority, thereby ensuring the certainty and security of the switching logic.
[0017] In an optional embodiment, the method further includes:
[0018] After the state value of the first system board is updated to the second logic value, a self-check and repair process is entered;
[0019] After the repair is completed, the system applies to the second system board for permission recovery, and after verification by the second system board, it re-participates in the active / standby status competition.
[0020] The switching method of the aircraft control system provided by the present invention ensures that the original main system has fully recovered to normal before re-participating in the main-backup competition through self-check repair and authority recovery verification mechanism, avoids the risk of secondary switching due to unrepaired residual faults, and improves the operating stability of the system after self-repair.
[0021] In an optional embodiment, the method further includes:
[0022] Acquire a fault signal of the first system board, and periodically verify a presence signal and a working status signal of the second system board;
[0023] When it is detected that the fault signal of the first system board lasts for more than a threshold time, and the presence signal of the second system board is valid and the working status signal is normal, a switching instruction is sent to the second system board, so that the second system board updates its own state value to the first logic value through the NAND gate logic circuit, and reversely triggers the first system board to update its state value to the second logic value;
[0024] After the switch is completed, the state value of the second system board is locked to the first logic value, and the first system board is prohibited from requesting the state value to be written back before the fault repair is completed;
[0025] When the first system board is repaired, a permission recovery request is sent to the second system board. After verification, the first system board re-enters the active / standby competition process.
[0026] The switching method of the aircraft control system provided by the present invention ensures that the switching action is only executed when the conditions are strictly met, and the system state cannot be reversibly tampered after the switch through state monitoring, switching triggering, logical locking and repair verification, thereby ensuring the integrity and ultimate consistency of the control authority transfer and avoiding interruption of the switching process or repeated oscillation of authority.
[0027] In summary, the switching method of the aircraft control system provided by the present invention, first, by defining the logical permissions of the primary and standby system status values (the first logical value controls enablement, the second logical value controls disablement) and the dual conditions of abnormality detection (continuous faults and instantaneous faults cumulatively exceed the limit), it ensures the uniqueness of the primary and standby system permissions and avoids erroneous switching due to occasional interference or the standby system not being ready. Secondly, by combining the request-confirmation interaction mechanism with the hardware-level NAND gate logic circuit, the mutual exclusivity of the primary and standby status values is forced to be constrained, eliminating the risk of dual-master conflict from a physical level, and at the same time, through the post-switching state locking and repair verification process, the atomicity and final consistency of the authority transfer are ensured. In addition, the closed-loop self-check repair and authority recovery verification mechanism effectively eliminates the interference of residual faults of the original main system on the secondary switching, and the periodic state monitoring, switching triggering, logical locking and repair verification of the entire process further ensure the continuous output of control instructions and the self-repair capability of the system in complex environments. It solves the problems of logical ambiguity, state conflict, high erroneous switching rate and lack of repair verification in traditional primary and standby switching, and significantly improves the robustness and operational safety of the aircraft control system under abnormal working conditions.
[0028] In a second aspect, the present invention provides an aircraft switching system, which includes a first system board and a second system board that back up each other. The system is used to execute the switching method of the aircraft control system of the first aspect or any corresponding embodiment thereof.
[0029] In an optional embodiment, the system includes a first system board and a second system board that back up each other, a backplane, and a master-slave switching module;
[0030] The first system board and the second system board are connected via a backplane, the backplane including a first slot and a second slot. In an initial state, the first system board inserted into the first slot is a primary board, and the second system board inserted into the second slot is a backup board.
[0031] Both the master and backup boards contain independent logic control units, which are used to achieve state interlocking through logic circuits. The master board's logic control unit monitors the fault signals of the system board and the presence and working status signals of the backup board in real time.
[0032] The master-slave switching module is used to trigger the master-slave switching when an abnormality occurs in the first system board and the second system board is in normal status; the master-slave status is identified by mutually exclusive logical values, and when switching, the second system board is updated to the first logical value to take over the control instruction output, and the first system board is updated to the second logical value to release the control authority; after the switching is completed, the status value of the second system board is locked, and the first system board is prohibited from writing back the control authority.
[0033] In a third aspect, the present invention provides a switching device for an aircraft control system, wherein the aircraft control system includes a first system board and a second system board that serve as backup for each other, and the device includes:
[0034] an initial setting module, configured to set a state value of a first system board to a first logic value, and a state value of a second system board to a second logic value; the first logic value causes the corresponding system board to output a control instruction to the aircraft, and the second logic value causes the corresponding system board not to output a control instruction;
[0035] The switching module is used to update the status value of the second system board to a first logic value so that the second system board outputs a control instruction, and to update the status value of the first system board to a second logic value so that the first system board stops outputting the control instruction when it is detected that the first system board is in an abnormal state and the second system board is in place and working normally.
[0036] In a fourth aspect, the present invention provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to execute the method for switching the aircraft control system of the first aspect or any corresponding embodiment thereof.
[0037] In a fifth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the method for switching an aircraft control system according to the first aspect or any corresponding embodiment thereof.
[0038] In a sixth aspect, the present invention provides a computer program product comprising computer instructions for causing a computer to execute the method for switching an aircraft control system according to the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0040] Figure 1 is a flow chart of a method for switching an aircraft control system according to an embodiment of the present invention;
[0041] Figure 2 is a schematic structural diagram of an eVTOL flight control system according to an embodiment of the present invention;
[0042] Figure 3 This is a schematic diagram of active / standby switching according to an embodiment of the present invention;
[0043] Figure 4 is a structural block diagram of a switching device for an aircraft control system according to an embodiment of the present invention;
[0044] Figure 5 Schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0045] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present invention.
[0046] In the field of aircraft control, active-standby redundancy design is an important means to improve system reliability, especially for scenarios with high safety requirements such as manned electric vertical take-off and landing aircraft (eVTOL), it is necessary to ensure the accuracy and stability of active-standby system switching. In the existing technology, active-standby switching solutions are mostly based on single fault signal triggering or manual intervention, such as directly switching to the standby system through power failure of the main control system or software error reporting. However, this type of method has significant defects. First, the determination of the abnormal state of the main system lacks multi-dimensional condition constraints (such as not distinguishing between transient interference and continuous faults), which can easily lead to erroneous switching or missed switching; second, the in-place status and working status of the standby system are not verified in real time, and the switching failure may be caused by the abnormality of the standby system itself. In addition, the traditional solution does not enforce the mutual exclusion of the active-standby status through hardware logic. After the switch, there may be a conflict problem of the dual systems outputting control instructions at the same time, and the permission release and repair verification of the original active system lack closed-loop management, and there is a risk of residual fault interference or permission rollback.
[0047] Taking a typical flight control system as an example, some solutions rely on software-level state judgment to implement active / standby switching. This response delay and logic vulnerabilities can lead to command interruption during the switching process. Other solutions, while incorporating a backup control unit, fail to achieve hardware-level coordination through state value interlocking and NOT gate logic, making it difficult to meet the stringent control command continuity and safety requirements of high-density urban airspace. These issues have led to existing technologies facing bottlenecks in practical applications, such as insufficient switching reliability and poor system robustness.
[0048] Therefore, an embodiment of the present invention provides a master-slave switching method based on strict switching conditions, hardware logic interlocking and closed-loop repair verification to solve core problems in the prior art such as switching logic ambiguity, state conflict and lack of repair verification.
[0049] An embodiment of the present invention provides a method for switching an aircraft control system, wherein the aircraft control system includes a first system board and a second system board that back up each other. The process of the method is as follows: Figure 1 As shown, the following steps are included.
[0050] S101 , setting a state value of a first system board to a first logic value, and setting a state value of a second system board to a second logic value.
[0051] Specifically, the first system board and the second system board that back up each other refer to two electronic control units (system boards) with exactly the same functions, respectively referred to as the "main board" (first system board) and the "backup board" (second system board). The hardware and software configurations of the two are consistent, but the initial states are different, forming a redundant backup relationship. The first logical value indicates that the system board has control authority and can output control instructions to the aircraft (such as attitude adjustment, power output, etc.). The specific form of the logical value can be a binary signal (for example, logical 1) or a specific level signal. The second logical value indicates that the system board has no control authority and is prohibited from outputting control instructions. The logical value form is complementary to the first logical value (for example, logical 0). The setting of the status value can be achieved through hardware registers or logic circuits to ensure the exclusivity of the main and standby system permissions.
[0052] The first logic value causes the corresponding system board to output control commands to the aircraft, while the second logic value prevents the corresponding system board from outputting control commands. Outputting control commands means that the system board sends commands to the aircraft's actuators (such as motors and servos) via a bus or signal line to drive the aircraft to perform its flight mission. For example, when the status value is the first logic value, the main board continuously publishes waypoints or adjusts flight attitude.
[0053] In step S101, the initial state is to set the status value of the first system board (the primary board) to a first logical value, continuously outputting control commands. The status value of the second system board (the backup board) is set to a second logical value, entering a silent state and not participating in outputting control commands. This definition of logical values clarifies the authority boundaries between the primary and backup systems, preventing conflicts caused by simultaneous command output from both systems.
[0054] S102. When it is detected that the first system board is in an abnormal state and the second system board is in place and working normally, the state value of the second system board is updated to a first logic value so that the second system board outputs a control instruction, and the state value of the first system board is updated to a second logic value so that the first system board stops outputting the control instruction.
[0055] Specifically, an abnormal state refers to a state in which the main board cannot perform control functions normally due to hardware failure (such as sensor failure, processor crash) or software error (such as control algorithm crash, communication interruption). The determination of the abnormal state can be achieved through fault signals (such as hardware error codes) or loss of heartbeat signals. The in-place state means that the backup board has been correctly installed in the system backplane or slot, and establishes communication with other aircraft modules (such as sensors, actuators) through physical connections (such as pins, buses). The in-place state can be verified by in-place signals (such as slot detection levels). Normal operation means that the backup board has no hardware or software failures, can receive and process data, and has the ability to take over control authority. The working status can be confirmed through self-test programs (such as memory verification, sensor calibration) or periodic status reports.
[0056] The status value can be updated by modifying the status register or logic circuit output of the system board, switching the status value of the standby board from the second logic value to the first logic value (obtaining control authority), and at the same time switching the status value of the main board from the first logic value to the second logic value (releasing authority).
[0057] In the above step S102, the master-slave switching is triggered only when the main board is abnormal and the backup board is ready. The status values of the main and backup systems are updated synchronously, the main board stops outputting instructions, and the backup board immediately takes over the control authority. The reliability and continuity of the transfer of control authority are guaranteed through strict switching condition restrictions and atomic status updates. Among them, the main board abnormality needs to exclude misjudgment caused by instantaneous interference (such as signal noise), and a duration threshold or a fault count accumulation mechanism can be introduced. The standby board's ready status and normal operation need to be verified in real time to ensure that the standby system can take over seamlessly.
[0058] The switching method of the aircraft control system provided in the embodiment of the present application realizes high-reliability master-slave switching of the aircraft control system by defining the mutually exclusive logic of the state values of the first system board and the second system board and strict dual switching conditions. Specifically, first, by setting the state values of the main system (first system board) and the backup system (second system board) to the first logical value and the second logical value respectively, the states of the two are forced to be separated, ensuring that the main system has exclusive control instruction output authority, and completely avoiding instruction conflicts caused by the parallel output of the dual systems; secondly, only when the main system is abnormal and the backup system meets the "in place" and "working normally" conditions at the same time, the main and backup state value exchange is triggered, which not only prevents invalid switching caused by the main system misjudging the fault, but also eliminates the risk of forced control when the backup system itself is abnormal; finally, the authority transfer is completed based on the main system's own state judgment and the backup system availability verification, which simplifies the timing control of the switching logic and reduces the system complexity. The above design enables the aircraft to quickly and safely switch to the available backup system when the main system fails, significantly improving control continuity and operational safety.
[0059] Optionally, in step S102, detecting that the first system board is in an abnormal state includes determining that the first system board is in an abnormal state when a fault signal of the first system board persists for more than a preset time threshold, or when a cumulative number of transient faults exceeds a set threshold. When the first system board is detected to be in an abnormal state, sending a master / slave switch request signal to the second system board, and updating the state value after receiving a confirmation response from the second system board.
[0060] Optionally, in the above method, the status values of the first and second system boards are mutually exclusive via a NAND gate logic circuit, and the system board with the first logic value has the initiative to change its status value owned by its own logic unit. After the first system board's status value is updated to the second logic value, it enters a self-check and repair process; after the repair is complete, it applies to the second system board for permission restoration and, after verification by the second system board, re-enters the competition for the primary and backup status.
[0061] Optionally, the above method further includes:
[0062] Acquire the fault signal of the first system board, and periodically verify the presence signal and working status signal of the second system board; when it is detected that the fault signal of the first system board continues to exceed the threshold time, and the presence signal of the second system board is valid and the working status signal is normal, send a switching instruction to the second system board, so that the second system board updates its own status value to the first logic value through the NAND gate logic circuit, and reversely triggers the first system board to update the status value to the second logic value; after the switching is completed, the status value of the second system board is locked to the first logic value, and the first system board is prohibited from requesting the status value to be written back before the fault repair is completed; when the first system board is repaired, initiate a permission recovery request to the second system board, and after verification, the first system board re-enters the master-slave competition process.
[0063] In summary, the switching method of the aircraft control system provided by the embodiment of the present invention, first, by defining the logical permissions of the primary and standby system status values (the first logical value controls enablement, the second logical value controls disablement) and the dual conditions of abnormality detection (continuous fault and instantaneous fault cumulative limit), ensures the uniqueness of the primary and standby system permissions, and avoids erroneous switching due to accidental interference or the standby system not being ready. Secondly, by combining the request-confirmation interaction mechanism with the hardware-level NAND gate logic circuit, the mutual exclusivity of the primary and standby state values is enforced, eliminating the risk of dual master control conflict from the physical level, and at the same time, through the post-switching state locking and repair verification process, ensures the atomicity and final consistency of the permission transfer. In addition, the closed-loop self-check repair and permission recovery verification mechanism effectively eliminates the interference of residual faults of the original primary system on the secondary switching, and the periodic state monitoring, switching triggering, logical locking and repair verification of the entire process further ensure the continuous output of control instructions and the system self-repair capability in complex environments. It solves the problems of logical ambiguity, state conflict, high erroneous switching rate and lack of repair verification in traditional primary and standby switching, and significantly improves the robustness and operational safety of the aircraft control system under abnormal working conditions.
[0064] Based on the switching method of the aircraft control system provided in the above embodiment, an embodiment of the present invention also provides an aircraft switching system, which includes a first system board and a second system board that back up each other. The system is used to execute the switching method of the aircraft control system of the above first aspect or any corresponding embodiment thereof.
[0065] The aircraft switching system includes a first system board and a second system board that back up each other, a backplane, and a master-slave switching module;
[0066] The first system board and the second system board are connected via a backplane, the backplane including a first slot and a second slot. In an initial state, the first system board inserted into the first slot is a primary board, and the second system board inserted into the second slot is a backup board.
[0067] Both the master and backup boards contain independent logic control units, which are used to achieve state interlocking through logic circuits. The master board's logic control unit monitors the fault signals of the system board and the presence and working status signals of the backup board in real time.
[0068] The master-slave switching module is used to trigger the master-slave switching when an abnormality occurs in the first system board and the second system board is in normal status; the master-slave status is identified by mutually exclusive logical values, and when switching, the second system board is updated to the first logical value to take over the control instruction output, and the first system board is updated to the second logical value to release the control authority; after the switching is completed, the status value of the second system board is locked, and the first system board is prohibited from writing back the control authority.
[0069] For example, the above-mentioned aircraft switching system will be described below using a specific example.
[0070] This example takes eVTOL (Electric Vertical Take-off and Landing) as an example and provides an eVTOL flight control system. eVTOL is a new type of aircraft that uses electricity as a power source and has both vertical take-off and landing capabilities and the advantages of fixed-wing cruise.
[0071] The structure of the eVTOL flight control system is as follows Figure 2 As shown, the system includes a multi-redundant flight control computer, a perception and avoidance module, a wireless communication module, an integrated navigation module, a sensor module, a battery management module, and a power module. The power module communicates with the flight control computer via bus 3, while the other modules communicate with the flight control computer via bus 1. Each module reports its own operational fault information to the CPLD register via bus 2. CPLDs (Complex Programmable Logic Devices) are highly flexible digital integrated circuits widely used in system boards (such as server motherboards, embedded development boards, and industrial control boards), performing key functions such as logic control, interface management, and system monitoring.
[0072] The system is designed with two identical system boards, one as the active board and the other as the standby board. The two system boards communicate and interact through the backplane. The interactive information includes: active-standby switching signal MS, in-position signal Online, and working status signal Work.
[0073] The backplane consists of two slots, slot 0 and slot 1. Two system boards can be inserted into each slot respectively. The board inserted into slot 0 is called board 0, and the board inserted into slot 1 is called board 1. Initially, the board inserted into slot 0 is the primary board, and the board inserted into slot 1 is the backup board.
[0074] Both the main board and the standby board can operate independently, but in this design, the standby board does not output control instructions.
[0075] If the active board detects a module fault, the active board's CPLD outputs the active / standby switchover signal ACT to switch system boards. After the switchover, the standby board in slot 1 becomes the active board and takes over control of the eVTOL product. Simultaneously, the active board in slot 0 becomes the standby board, releasing control authority and no longer issuing control commands.
[0076] The active and standby boards use their respective CPLDs to perform logic processing and exchange data, thereby completing active / standby switching. Furthermore, the active board leads or initiates the active / standby switching process.
[0077] The active / standby switching of the two system boards can be done through two interacting NAND gates. Figure 3 Active / standby switching structure.
[0078] The relationship between the status of the system board and its status value is shown in Table 1.
[0079] Table 1
[0080]
[0081] In Table 1, CONT_0, CONT_1, ACT_0, and ACT_1 are different status signals of the main board or the standby board.
[0082] As shown in Table 1, under normal conditions, the status value of the active board is 0, the status value of the standby board is 1, and the status values of the two are interlocked and should not be 0 or 1 at the same time.
[0083] If the master board fails abnormally, CONT_0 of the master board changes from 1 to 0, and CONT_1 of the standby board changes from 0 to 1. The master and standby boards are in state 2, board 1 becomes the master, and board 0 becomes the standby, completing the master-slave switch.
[0084] The master board can initiate a master-slave switch only when the slave board is in place and the working signal is normal, and the master board has an abnormal fault.
[0085] After the switch, the backup system can seamlessly replace the original primary system, fully take over the control authority of the eVTOL product, and ensure its normal operation.
[0086] In this example, the eVTOL flight control system uses a backplane to coexist with a primary and backup board, operating simultaneously. Under normal conditions, the primary board fully controls the eVTOL product, while the backup board operates normally but does not output commands. If the primary board fails, it initiates a master-slave switchover, with the backup board becoming the primary board and fully controlling the eVTOL. The original primary board becomes the backup board, releasing control authority.
[0087] This embodiment also provides a switching device for an aircraft control system, which is used to implement the above-mentioned embodiments and preferred embodiments. Details already described will not be repeated here. As used below, the term "module" may refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.
[0088] This embodiment provides a switching device for an aircraft control system, wherein the aircraft control system includes a first system board and a second system board that back up each other, such as Figure 4 As shown, the device includes:
[0089] Initial setting module 401 is used to set the state value of the first system board to a first logic value, and set the state value of the second system board to a second logic value; the first logic value causes the corresponding system board to output a control instruction to the aircraft, and the second logic value causes the corresponding system board not to output a control instruction;
[0090] The switching module 402 is used to update the status value of the second system board to a first logic value so that the second system board outputs control instructions, and to update the status value of the first system board to a second logic value so that the first system board stops outputting control instructions when it is detected that the first system board is in an abnormal state and the second system board is in place and working normally.
[0091] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0092] The switching device of the aircraft control system in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0093] The embodiment of the present invention also provides a computer device having the above Figure 4 The switching device of the aircraft control system is shown.
[0094] See also Figure 5 , Figure 5 is a structural diagram of a computer device provided by an optional embodiment of the present invention, such as Figure 5 As shown, the computer device includes: one or more processors 10, memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in the memory or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 5 A processor 10 is taken as an example.
[0095] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.
[0096] The memory 20 stores instructions that can be executed by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.
[0097] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0098] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0099] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or a communication network.
[0100] The embodiment of the present invention also provides a computer-readable storage medium. The above-mentioned method according to the embodiment of the present invention can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.
[0101] A portion of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the form in which the computer program instruction exists in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc. Accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium that can be accessed by the computer.
[0102] Although the embodiments of the present invention have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention. Such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A method for switching an aircraft control system, characterized in that: The aircraft control system includes a first system board and a second system board that back up each other, and the method includes: Setting the state value of the first system board to a first logic value, and setting the state value of the second system board to a second logic value; the first logic value causes the corresponding system board to output a control instruction to the aircraft, and the second logic value causes the corresponding system board not to output a control instruction; When it is detected that the first system board is in an abnormal state and the second system board is in place and working normally, the state value of the second system board is updated to a first logic value so that the second system board outputs a control instruction, and the state value of the first system board is updated to a second logic value so that the first system board stops outputting a control instruction.
2. The method according to claim 1, characterized in that The detecting that the first system board is in an abnormal state includes: When the fault signal of the first system board continues to exceed a preset time threshold, or the cumulative number of instantaneous faults exceeds a set threshold, it is determined that the first system board is in an abnormal state.
3. The method according to claim 2, characterized in that The method further comprises: When it is detected that the first system board is in an abnormal state, a master / slave switch request signal is sent to the second system board, and a state value update is performed after a confirmation response from the second system board is received.
4. The method according to claim 3, characterized in that The state values of the first system board and the second system board are mutually exclusive through a NAND gate logic circuit, and the dominance of the state value change of the system board whose state value is the first logic value belongs to its own logic unit.
5. The method according to claim 4, characterized in that The method further comprises: After the state value of the first system board is updated to the second logic value, a self-check and repair process is entered; After the repair is completed, the system applies to the second system board for permission recovery, and after verification by the second system board, it re-participates in the active / standby status competition.
6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Acquire a fault signal of the first system board, and periodically verify a presence signal and a working status signal of the second system board; When it is detected that the fault signal of the first system board lasts for more than a threshold time, and the presence signal of the second system board is valid and the working status signal is normal, a switching instruction is sent to the second system board, so that the second system board updates its own state value to the first logic value through the NAND gate logic circuit, and reversely triggers the first system board to update its state value to the second logic value; After the switch is completed, the state value of the second system board is locked to the first logic value, and the first system board is prohibited from requesting the state value to be written back before the fault repair is completed; When the first system board is repaired, a permission recovery request is sent to the second system board. After verification, the first system board re-enters the active / standby competition process.
7. An aircraft switching system, characterized in that: The system comprises a first system board and a second system board which serve as backup for each other, and the system is used to execute the aircraft control system switching method according to any one of claims 1 to 6.
8. The system according to claim 7, characterized in that The system includes a first system board and a second system board that back up each other, a backplane, and a master-slave switching module; The first system board and the second system board are connected via a backplane, the backplane comprising a first slot and a second slot, wherein the first system board inserted into the first slot is initially a primary board, and the second system board inserted into the second slot is a backup board; The main board and the standby board each include an independent logic control unit for achieving state interlocking through a logic circuit. The logic control unit of the main board monitors the fault signal of the system board and the presence signal and working status signal of the standby board in real time. The master-slave switching module is configured to trigger a master-slave switch when an abnormality occurs in the first system board and the second system board is in a normal state; identify the master-slave state by mutually exclusive logical values, update the second system board to the first logical value to take over the control instruction output during the switch, and update the first system board to the second logical value to release the control authority; After the switch is completed, the status value of the second system board is locked, and the first system board is prohibited from writing back the control permission.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the aircraft control system switching method according to any one of claims 1 to 6 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the aircraft control system switching method according to any one of claims 1 to 6.