Shutdown control method, device and equipment for engine of liquid carrier rocket

By dynamically adjusting thresholds and using multi-dimensional parameter judgments, the adaptability problem of fixed thresholds in the emergency shutdown control of liquid launch vehicle engines has been solved, enabling more accurate judgment of operating status and safer fault handling.

CN120906709APending Publication Date: 2025-11-07HENAN TIANZHANG ROCKET CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511265894.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-05
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

In existing emergency shutdown control systems for liquid-fueled rocket engines, fixed thresholds are difficult to adapt to complex and ever-changing dynamic operating conditions, resulting in a high risk of erroneous shutdown and missed shutdown.

Method used

By acquiring the operating data and working condition data of multi-stage parallel engines, dynamically adjusting thresholds, and combining environmental and time parameters, the system can accurately match the operating status and achieve multi-dimensional parameter anomaly judgment and graded shutdown decision-making.

Benefits of technology

It significantly reduces the risk of accidental shutdown and missed shutdown caused by fluctuations in operating conditions, and improves the accuracy of engine operating status judgment and the safety of fault handling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120906709A_ABST
    Figure CN120906709A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a shutdown control method, device and equipment for engines of a liquid carrier rocket. The method comprises the steps that operation data and working condition data of at least three engines in multi-stage parallel engines of the liquid carrier rocket are obtained; determining a dynamic threshold value of the operation data according to the working condition data; according to the dynamic threshold value and the operation data, the operation state of the engine is determined; determining a shutdown action of the multi-stage parallel engine according to the running state; and controlling the multi-stage parallel engine to shut down according to the shutdown action of the multi-stage parallel engine. According to the embodiment of the invention, the problem that the fixed threshold value is not matched with the dynamic working condition can be solved, and the risks of wrong shutdown and shutdown omission caused by working condition fluctuation are greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The embodiment of the present application relates to the field of launch vehicle control, in particular to a liquid launch vehicle engine shutdown control method, device and equipment. BACKGROUND

[0002] The emergency shutdown control of a liquid launch vehicle is a key link to ensure launch safety. In the process of launching a rocket, multi-stage parallel engines need to monitor the operation data of each engine in real time. Once an abnormality occurs, shutdown operation must be performed immediately to prevent catastrophic consequences. The current emergency shutdown mainly uses a fixed threshold detection mechanism to determine whether to trigger shutdown by a preset safety threshold. It is difficult to adapt to complex and variable actual working conditions, such as pressure fluctuations or transient abnormalities caused by fuel temperature changes. SUMMARY

[0003] The technical problem to be solved by the embodiment of the present application is to provide a liquid launch vehicle engine shutdown control method, device and equipment, which can solve the problem of mismatch between fixed threshold and dynamic working conditions, and greatly reduce the risk of false shutdown and missed shutdown caused by working condition fluctuations.

[0004] To solve the above technical problems, the technical solutions of the embodiments of the present application are as follows: A liquid launch vehicle engine shutdown control method, comprising: Obtaining operation data and working condition data of at least three engines in a multi-stage parallel engine of a liquid launch vehicle; Determining a dynamic threshold of the operation data according to the working condition data; Determining the running state of the engine according to the dynamic threshold and the operation data; Determining the shutdown action of the multi-stage parallel engine according to the running state; Controlling the multi-stage parallel engine to shut down according to the shutdown action of the multi-stage parallel engine.

[0005] Optionally, the working condition data includes environmental parameters and time parameters; Determining the dynamic threshold of the operation data according to the working condition data, comprises: Determining a first dynamic threshold of the operation data according to the environmental parameters; Determining a second dynamic threshold of the operation data according to the time parameters.

[0006] Optionally, the environmental parameters include fuel temperature and vibration intensity; Determining the first dynamic threshold of the operation data according to the environmental parameters, comprises: According to DY = T+K × (F - R ) +L ×( P - Q ), determine the first dynamic threshold; in, DY The first dynamic threshold, T The first benchmark threshold, K This is the fuel temperature compensation coefficient. F For fuel temperature, R The fuel reference temperature, L This is the vibration intensity compensation coefficient. P For vibration intensity, Q The vibration reference strength; Determining the second dynamic threshold of the running data based on the time parameter includes: according to Determine the second dynamic threshold; in, DE The second dynamic threshold, A To set the initial threshold, B To set a threshold for the later stages of startup, S For time parameters, H This refers to the critical time between the early and late stages of startup.

[0007] Optionally, the operating data includes: a first operating parameter, a second operating parameter, and a third operating parameter; The first operating parameters include: methane pre-injection pressure and oxygen pre-injection pressure; The second operating parameters include: controlling the outlet pressure of the pressure regulator and purging the outlet pressure of the pressure regulator; The third operating parameter includes: turbine speed and generator methane injection pressure; Based on the dynamic threshold and operating data, the operating status of the engine is determined, including: The first state result is determined based on the first operating parameters and the first dynamic threshold; The second state result is determined based on the second operating parameters and the second dynamic threshold; The third state result is determined based on the third operating parameter and the third fixed threshold. The operating state of the engine is determined based on the first state result, the second state result, and the third state result.

[0008] Optionally, the first state result is determined based on the first operating parameters and the first dynamic threshold, including: like DYJ i >DY ithe first state result is abnormal for the first operating parameter; wherein, DYJ i is the first operating parameter, DY i is the first dynamic threshold, i= 1, 2; determining a second state result according to the second operating parameter and a second dynamic threshold, comprising: if DEJ i >DE i the second state result is abnormal for the second operating parameter; wherein, DEJ i is the second operating parameter, DE i is the second dynamic threshold, i= 1, 2; determining a third state result according to the third operating parameter and a third fixed threshold, comprising: if DSJ i >DS i the third state result is abnormal for the third operating parameter; wherein, DSJ i is the third operating parameter, DS i is the third fixed threshold, i= 1, 2; determining the operating state of the engine according to the first state result, the second state result and the third state result, comprising: if CDYJ i ≧ 3, or CDEJ i ≧ 3, or CDSJ i ≧ 3, determining that the operating state of the engine is a fault; wherein, CDYJ i is the number of consecutive abnormalities of the first operating parameter of a single engine, CDEJ i is the number of consecutive abnormalities of the second operating parameter of a single engine, CDSJ i is the number of consecutive abnormalities of the third operating parameter of a single engine, i= 1, 2.

[0009] Optionally, according to the running state, the shutdown action of the multi-stage parallel engine is determined, including: According to the running state, the number and type of faults of the engine are determined; According to the number and type of faults of the engine, the shutdown action of the engine is determined.

[0010] Optionally, according to the number and type of faults of the engine, the shutdown action of the engine is determined, including: If N e ≧ 3, the shutdown action is determined as global shutdown; Wherein, N e The number of engines triggering the same type of fault is e= 1, 2,..., 6; If N e < 3, and M=1 The shutdown action of the engine is determined as single-engine fault isolation; If 1 <M< 3, the shutdown action of the engine is determined as single-engine shutdown and fault isolation; Wherein, M The number of faults of the engine; In other cases, the shutdown action is determined as re-acquisition of judgment processing.

[0011] Embodiments of the present application also provide an engine shutdown control device of a liquid carrier rocket, including: An acquisition module is configured to acquire running data and working condition data of at least three engines in a multi-stage parallel engine of a liquid carrier rocket; A processing module is configured to determine a dynamic threshold of the running data according to the working condition data, determine a running state of the engine according to the dynamic threshold and the running data, determine a shutdown action of the multi-stage parallel engine according to the running state, and control the multi-stage parallel engine to shut down according to the shutdown action of the multi-stage parallel engine.

[0012] Embodiments of the present application also provide a computing device, including: One or more processors; a storage device configured to store one or more programs, when the one or more programs are executed by the one or more processors, so that the one or more processors implement the method as described above.

[0013] Embodiments of the present application also provide a computing device readable storage medium, the computing device readable storage medium stores a program, the program is executed by a processor to implement the method as described above.

[0014] The above scheme of the embodiment of the present application at least includes the following beneficial effects: The above scheme of the embodiment of the present application, by determining the dynamic threshold value according to the working condition data, binds the threshold value with the real-time working condition depth, so that the judgment standard is dynamically adjusted with the working condition: fundamentally solves the problem of mismatch between the fixed threshold value and the dynamic working condition, and greatly reduces the risk of false shutdown and missed shutdown caused by working condition fluctuation.

[0015] According to the dynamic threshold value and the running data, the running state is determined, which is not a single parameter judgment, but a comprehensive evaluation combined with the running data of multiple engines (at least three), to avoid missed judgment. BRIEF DESCRIPTION OF DRAWINGS

[0016] Figure 1 is a flowchart of the engine shutdown control method of the liquid carrier rocket provided by the embodiment of the present application.

[0017] Figure 2 is a module schematic diagram of the engine shutdown control device of the liquid carrier rocket provided by the embodiment of the present application. DETAILED DESCRIPTION

[0018] Exemplary embodiments of the present application will be described in greater detail below with reference to the accompanying drawings. Although exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present application can be more thoroughly understood and the scope of the present application can be accurately conveyed to those skilled in the art.

[0019] As Figure 1 shown, the embodiment of the present application provides an engine shutdown control method of a liquid carrier rocket, comprising: Step 11, obtaining running data and working condition data of at least three engines in a multi-stage parallel engine of a liquid carrier rocket; Step 12, determining a dynamic threshold value of the running data according to the working condition data; Step 13, determining a running state of the engine according to the dynamic threshold value and the running data; Step 14, determining a shutdown action of the multi-stage parallel engine according to the running state; Step 15, controlling the multi-stage parallel engine to shut down according to the shutdown action of the multi-stage parallel engine.

[0020] In this example, by determining the dynamic threshold value according to the working condition data, the threshold value is bound with the real-time working condition depth, so that the judgment standard is dynamically adjusted with the working condition: the problem of mismatching between the fixed threshold value and the dynamic working condition is fundamentally solved, and the risk of false shutdown and missed shutdown caused by working condition fluctuation is greatly reduced.

[0021] The running state is determined according to the dynamic threshold value and the running data, not a single parameter judgment, but a comprehensive evaluation combined with the running data of multiple engines (at least three engines), so as to avoid missed judgment.

[0022] In an optional embodiment of the present application, in step 11, the running data and working condition data of at least three engines are obtained, including: In step 111, the running data and working condition data of at least three engines are obtained through distributed sensors and communication channels; The engine can be seven engines; the running data includes first running parameters, second running parameters and third running parameters; the first running parameters include methane pre-injection pressure and oxygen pre-injection pressure; the second running parameters include control pressure reducer outlet pressure and blowdown pressure reducer outlet pressure; the third running parameters include turbine speed and generator methane pre-injection pressure; and the working condition data includes environmental parameters and time parameters.

[0023] The distributed sensors include pressure sensors (for collecting methane pre-injection pressure and oxygen pre-injection pressure), speed sensors (for collecting turbine speed), temperature sensors (for collecting fuel temperature) and vibration sensors (for collecting vibration intensity), and the sampling frequency is greater than or equal to 100 Hz; the communication channel uses a high-speed parallel bus and a 1553B bus.

[0024] In this example, multi-dimensional parameter acquisition covers the engine fuel-power-regulating system, and combined with environmental and time parameters, complete basis is provided for dynamic threshold value calculation, so as to avoid one-sided judgment caused by parameter missing. The distributed sensors are matched with special types (such as pressure and speed sensors), and the sampling frequency is greater than or equal to 100 Hz, so as to balance data accuracy and fault isolation. The vibration sensor can also capture mechanical abnormalities, and the overall monitoring is improved. Seven parallel engines are adapted, the multi-engine data cross verification is performed, individual and systematic faults can be quickly distinguished, load balancing is monitored, and system-level collaborative monitoring is realized. The high-speed parallel bus and the 1553B bus are used for hybrid communication, which not only meets the real-time transmission demand of high sampling rate data, but also relies on the anti-interference of the 1553B bus to ensure transmission reliability, and balances speed and stability.

[0025] In an optional embodiment of the present application, in step 12, a dynamic threshold value of the running data is determined according to the working condition data, including: In step 121, a first dynamic threshold value of the running data is determined according to the environmental parameters; Step 122, according to the time parameter, determine the second dynamic threshold of the running data.

[0026] Specifically, the environmental parameters include fuel temperature and vibration intensity.

[0027] In this example, the first dynamic threshold is determined according to the environmental parameters, and the working condition is adaptively adjusted. The environmental parameters include fuel temperature and vibration intensity. The fuel temperature affects the normal range of running data such as fuel pressure, and the threshold is adjusted accordingly to avoid misjudgment due to temperature fluctuations. The vibration intensity is related to the mechanical state of the engine, and the threshold is set in combination with it, which can more accurately identify the deviation of running parameters related to mechanical abnormalities. The second dynamic threshold is determined according to the time parameter, which meets the needs of different stages. The time parameter reflects the cumulative working time of the engine and the flight stage, and the normal range of running data is different in different stages. By adjusting the threshold according to the time parameter, the threshold can be adapted to different stages such as starting and stable running, avoiding the problem that a single threshold cannot meet the monitoring requirements of the whole cycle. By setting the threshold according to the environment and time parameters, the dynamic threshold is more suitable for actual working conditions and running stages, greatly improving the accuracy of running data judgment, providing a reliable basis for subsequent determination of engine running state and execution of shutdown action, and further reducing the risk of false shutdown and missed shutdown.

[0028] In an optional embodiment of the present application, in step 121, the first dynamic threshold of the running data is determined according to the environmental parameters, including: Step 1211, according to DY = T+K ×( F - R ) +L ×( P - Q ),determine the first dynamic threshold; Among them, DY is the first dynamic threshold, T is the first reference threshold, K is the fuel temperature compensation coefficient, F is the fuel temperature, R is the fuel reference temperature, L is the vibration intensity compensation coefficient, P is the vibration intensity, Q is the vibration reference intensity. In an optional embodiment of the present application, in step 122, the second dynamic threshold of the running data is determined according to the time parameter, including: Step 1221, according to , determine the second dynamic threshold; Among them, DE is the second dynamic threshold, A is the pre-start threshold, Bto start the late threshold, S to time parameter, H to critical time of the early stage and the late stage of starting.

[0029] In this example, the influence of the quantitative environmental parameters on the threshold value is quantified. The difference between the actual value of the fuel temperature and the reference value is multiplied by the corresponding compensation coefficient, and then the first reference threshold value is superimposed. This can accurately quantify the influence of temperature fluctuations and vibration abnormalities on the normal range of operation data, avoid ambiguous judgment of environmental parameter influence, and make the first dynamic threshold value more suitable for real-time environmental conditions.

[0030] The time stage threshold value is clearly divided. According to the time parameter, the early stage threshold value or the late stage threshold value of starting is matched, the threshold value standard of different time stages is clearly defined, the threshold value adaptation deviation caused by the ambiguity of the time stage is avoided, and the second dynamic threshold value is accurately matched with the engine in different running stages.

[0031] In an optional embodiment of the present application, in step 13, the running state of the engine is determined according to the dynamic threshold value and the operation data, comprising: Step 131, determining a first state result according to the first operation parameter and the first dynamic threshold value; Step 132, determining a second state result according to the second operation parameter and the second dynamic threshold value; Step 133, determining a third state result according to the third operation parameter and the third fixed threshold value; Step 134, determining the running state of the engine according to the first state result, the second state result and the third state result.

[0032] Specifically, in step 131, the first state result is determined according to the first operation parameter and the first dynamic threshold value, comprising: Step 1311, if DYJ i >DY i the first state result is the first operation parameter abnormality; wherein, DYJ i the first operation parameter, DY i the first dynamic threshold value, i= 1, 2; In step 132, the second state result is determined according to the second operation parameter and the second dynamic threshold value, comprising: Step 1321, if DEJ i >DE i the second state result is the second operation parameter abnormality; wherein, DEJ i is a second operating parameter, DE i is a second dynamic threshold, i= 1, 2; In step 133, a third state result is determined according to the third operating parameter and a third fixed threshold, comprising: In step 1331, if DSJ i >DS i the third state result is that the third operating parameter is abnormal; wherein, DSJ i is a third operating parameter, DS i is a third fixed threshold, i= 1, 2; In step 134, the operating state of the engine is determined according to the first state result, the second state result and the third state result, comprising: In step 1341, if CDYJ i ≧ 3, or CDEJ i ≧ 3, or CDSJ i ≧ 3, it is determined that the operating state of the engine is failure; wherein, CDYJ i is a continuous abnormal number of the first operating parameter of a single engine, CDEJ i is a continuous abnormal number of the second operating parameter of a single engine, CDSJ i is a continuous abnormal number of the third operating parameter of a single engine, i= 1, 2.

[0033] In this example, the parameters and thresholds are accurately matched, improving the accuracy of single parameter judgment. The first operating parameter corresponds to the first dynamic threshold, and the second operating parameter corresponds to the second dynamic threshold, which adapts to changes in environment and time working conditions; the third operating parameter uses the third fixed threshold, which accurately judges according to its characteristics (such as relatively stable turbine speed), avoids the deviation of a single threshold adaptation, and makes the abnormal judgment of each parameter more in line with the actual situation. The continuous abnormal number determination reduces the false judgment of transient interference. Taking the continuous abnormal number ≥ 3 as the failure standard, instead of determining abnormality by single threshold value, can filter out interference such as sensor transient fluctuation, avoid false judgment of engine failure due to accidental parameter fluctuation, and improve the rigor of abnormal judgment. The multi-state result comprehensive decision ensures the overall judgment of the running state. The running state is determined from the multi-dimensional parameter abnormal situation in combination with the first, second and third state results, instead of relying on a single parameter, so that the engine failure can be more comprehensively captured, the risk of missed judgment can be reduced, a reliable basis can be provided for subsequent shutdown action execution, and the safety of the rocket launch can be further ensured.

[0034] In an optional embodiment of the present application, in step 14, the shutdown action of the multi-stage parallel engine is determined according to the running state, including: Step 141, determining the number and type of faults of the engine according to the running state; Step 142, determining the shutdown action of the engine according to the number and type of faults of the engine.

[0035] Specifically, the number and type of faults of the engine can be obtained by aggregating the running states of all engines.

[0036] In this example, the overall situation of the fault is accurately grasped to provide sufficient basis for the shutdown decision. By aggregating the running states of all engines, the number and type of faults are determined, avoiding the one-sided decision caused by only focusing on partial fault information, so that the subsequent shutdown action is more in line with the actual fault scenario. Customize the shutdown action as needed to balance safety and task continuity. Differentiate the decision according to the number and type of faults: if only a single engine has a local fault, only the faulty engine can be shut down to avoid overall shutdown causing task interruption; if multiple engines have systemic faults, overall shutdown is triggered in time to prevent fault propagation and cause catastrophic consequences, achieving hierarchical shutdown and balancing launch safety and task success rate. Improve the management and control ability of the multi-stage parallel system and strengthen the efficiency of risk response. For the complex configuration of the multi-stage parallel engine, this scheme quickly responds to different fault conditions through clear fault analysis-action decision logic, avoids the drawbacks of the traditional one-size-fits-all shutdown mode, and further ensures the system stability and safety during the rocket launch process.

[0037] In an optional embodiment of the present application, in step 142, the shutdown action of the engine is determined according to the number and type of faults of the engine, including: Step 1421, if N e ≧ 3, determining the shutdown action as global shutdown; specifically, the global shutdown can be synchronous shutdown of all engines of the multi-stage parallel engine; Wherein, N e The number of engines with the same type of fault is e= 1, 2,..., 6; Step 1422, if N e < 3, and M=1 determine the shutdown action of the engine as single engine fault isolation; specifically, the single engine fault isolation can be physical and command isolation of the fault engine of the multi-stage parallel engine; Step 1423, if 1 <M< 3, determine the shutdown action of the engine as single engine shutdown and fault isolation; specifically, the single engine shutdown and fault isolation can be shutdown and physical and command isolation of the fault engine of the multi-stage parallel engine; wherein, M is the number of faults of the engine; Step 1424, in other cases, determine the shutdown action as re-collection judgment processing; specifically, the re-collection judgment processing can be to adjust the continuous abnormal number threshold of the same operating parameter of a single engine to 2 from 3, re-judge until the operating parameter is normal or the above action condition is triggered, if it is other cases for three times in a row, switch to the ground control channel, and ground command verification.

[0038] In this example, the decision is made according to the number of faults, and different risk levels are accurately matched. When the number of same type fault engines is greater than or equal to 3, global shutdown is triggered to quickly contain systemic fault diffusion and avoid catastrophic consequences; when the number of faults is less than 3, the faults are processed differently according to the number of faults; when the number of faults is 1, only single engine fault isolation is performed; and when the number of faults is between 1 and 3, single engine shutdown and isolation are performed, which balances risk and task continuity while ensuring safety and maximizing the use of normal engines. The fault isolation mechanism is clear and blocks the fault transmission path. Whether it is single engine fault isolation or single engine shutdown and isolation, the fault engine is physically and command isolated to prevent faults such as fuel leakage and abnormal load from being transmitted to other normal engines, avoid local faults from evolving into global problems, and strengthen the anti-fault capability of the multi-stage parallel system. Re-collection judgment and ground verification bottom-up, reduce the risk of decision-making errors. In other cases, re-judge by increasing the sampling frequency and lowering the continuous abnormal number threshold (from 3 to 2), ensuring that no potential faults are missed; if there is no result for three times in a row, switch to the ground control channel for verification, forming a fault-tolerant closed loop of autonomous judgment-secondary verification-ground bottom-up, which avoids misjudgment and prevents missed judgment, further improving the reliability and safety of the shutdown decision.

[0039] In an optional embodiment of the present application, in step 15, the multi-stage parallel engine is shut down according to the shutdown action of the multi-stage parallel engine, comprising: Step 151, if the shutdown action of the engine is global shutdown, control all engines of the multi-stage parallel engine to stop synchronously; Step 152, if the shutdown action of the engine is single engine fault isolation, control the fault engine of the multi-stage parallel engine to perform physical and command isolation action; Step 153, if the shutdown action of the engine is single engine shutdown and fault isolation, control the fault engine of the multi-stage parallel engine to stop and perform physical and command isolation; Step 154, if the re-collection judgment process is executed, the sampling frequency of the collected operation data is increased, the threshold of the continuous abnormal number of the same operation parameter of a single engine is adjusted from 3 to 2, and the judgment is re-performed until the operation parameter is normal or the above action condition is triggered, if the continuous three times are all other conditions, switch to the ground control channel, and perform ground command verification action.

[0040] In this example, the action execution corresponds to the accurate decision, which ensures efficient fault response. The global shutdown decision corresponds to the synchronous stop of all engines, ensuring rapid termination of risks under systematic failure; the single engine fault isolation decision matches the physical and command isolation of the fault engine, and the single engine shutdown + isolation decision corresponds to the stop and isolation of the fault engine, avoiding unnecessary operations affecting normal engines, realizing decision-execution without deviation, and improving fault handling efficiency. The isolation action is executed in a standardized manner, strengthening the defense line against fault expansion. Whether it is single engine fault isolation or single engine shutdown + isolation, the physical and command isolation action is strictly executed, cutting off the association between the fault engine and the system from two aspects of hardware connection and control command, completely blocking the conduction path of fuel leakage, load abnormality and other faults, preventing local faults from expanding into global disasters, and strengthening system safety. The re-collection judgment action is executed in detail, and the fault tolerance mechanism is improved. The operation of increasing the sampling frequency and adjusting the continuous abnormal number threshold can more sensitively capture potential faults; switching to ground verification for three consecutive times avoids the limitations of autonomous judgment, forms an execution closed loop of rapid response-fine verification-ground backup, greatly reduces the risk of decision and execution errors, and provides an additional guarantee for rocket launch safety.

[0041] Example 1 A certain liquid carrier rocket adopts 7 parallel engines (numbers 1-7), and at the 45th second after launch (late start-up, critical time H =30 seconds), the system performs shutdown judgment according to the following steps: Example 1 provides a shutdown control method for the engines of a liquid carrier rocket, comprising: Step 21, acquiring operation data and working condition data: The data of the 7 engines is collected in real time through distributed sensors and communication channels (high-speed parallel bus and 1553B bus), and the sampling frequency is 100 Hz; First operating parameter: Real-time methane pre-injection pressure of 7 engines: 2.6, 2.5, 2.7, 2.3, 2.4, 2.3, 2.4; Real-time oxygen pre-injection pressure of 7 engines: 3.3, 3.4, 3.5, 3.1, 3.2, 3.1, 3.2; Second operating parameter: Real-time control pressure reducer outlet pressure of 7 engines: 1.9, 2.1, 2.2, 1.8, 1.7, 1.8, 1.7; Blowdown pressure reducer outlet pressure: 0.7, 0.8, 0.9, 0.6, 0.5, 0.6, 0.5; Third operating parameter: Turbine rotating speed: 26000, 27000, 28000, 25000, 24000, 25000, 24000; Generator methane pre-injection pressure: 1.3, 1.4, 1.5, 1.2, 1.1, 1.2, 1.1; Working condition data: Environmental parameter (fuel temperature F = 285K, vibration intensity P = 0.03g); Time parameter S = 45s); Reference parameter: Fuel reference temperature R = 293K, vibration reference intensity Q = 0.01g, pre-start threshold A = 1.5MPa, post-start threshold B = 2.0MPa; Step 22, determine dynamic threshold: Calculate first dynamic threshold: first reference threshold T 1 (methane pre-injection pressure) = 2.2MPa, T 2 (oxygen pre-injection pressure) = 3.0MPa; Fuel temperature compensation coefficient K = 0.01, vibration intensity compensation coefficient L = 5; DY 1 (methane pre-injection pressure threshold) = 2.22MPa; DY 2 (oxygen pre-injection pressure threshold): = 3.02MPa; Calculate second dynamic threshold: Because S = 45s H = 30s, the post-start threshold B is adopted; DE 1 ( control pressure reducer outlet pressure threshold) = B = 2.0MPa; DE 2 (Blowdown pressure reducer outlet pressure threshold B = 0.8 MPa Third fixed threshold DS 1 (turbine rotation speed threshold) = 28000 r / min DS 2 (generator methane pre-injection pressure threshold) = 1.5 MPa Step 23, determine the engine operating state: According to the parameter abnormality judgment rule (parameter > threshold, then abnormal), the number of abnormality of continuous 3 times sampling is counted CDYJ 、 CDEJ 、 CDSJ ): Determination result: engines 1, 2 and 3 are fault machines (a total of 3, M = 3); Step 24, determine and execute shutdown action: Fault statistics: fault number M = 3; Same kind of fault: engines 1, 2 and 3 all have methane pre-injection pressure abnormality (1), that is DYJ = 3 (number of same kind of fault); Ne Determine shutdown action: because = 3 >= 3, global shutdown is triggered; Ne Execute action: control 7 engines to synchronously cut off fuel supply, close turbine pump, complete global shutdown, and ensure the safety of the rocket. If only engine 1 fails in the above case (1,

[0042] = 1, M = 1), single machine fault isolation (physical and instruction isolation, without affecting other engines) is executed; if the fault machines are 2 (2, Ne = 2, M = 2), single machine shutdown + isolation (only close the fault machines and isolate) is executed. Through dynamic threshold and hierarchical judgment, accurate identification and safe handling of faults are realized. Ne The application collects data through distributed special sensors and hybrid communication buses, covers engine fuel-power-regulation core system parameters, combines environment (fuel temperature, vibration intensity) and time parameters, and the sampling frequency is >= 100 Hz, taking into account data comprehensiveness and real-time performance. At the same time, the anti-interference of 1553B bus ensures stable transmission, and the adaptive seven parallel engines can cross-verify multi-machine data to distinguish individual and systematic faults, avoid one-sided decision-making caused by parameter missing or distortion, and provide high-quality data support for subsequent judgment.

[0043]

[0044] ​Employing a dual-dimensional dynamic threshold design based on both environment and time, it overcomes the limitations of fixed thresholds. A first dynamic threshold is calculated based on fuel temperature and vibration intensity, accurately adapting to the impact of environmental fluctuations on the normal range of parameters. A second dynamic threshold is matched to the pre- and post-start stages, using critical times to align with the characteristics of different engine operating phases. This completely solves the problem of traditional fixed thresholds being unable to handle dynamic operating conditions such as temperature changes and transient interference, significantly reducing the risk of accidental or missed shutdowns caused by operating condition fluctuations, and making the judgment criteria more closely aligned with real-world scenarios.

[0045] By employing precise parameter-threshold matching, continuous anomaly detection, and multi-result comprehensive logic, the accuracy of anomaly identification is improved. The first and second operating parameters correspond to dynamic thresholds, while the third stable parameter (such as turbine speed) uses a fixed threshold to avoid deviations from a single threshold. A fault criterion of ≥3 consecutive anomalies is used to filter out interference from transient fluctuations in sensors. Finally, the engine operating status is comprehensively judged by combining the results of the three types of parameter states, rather than relying on a single parameter. This approach can capture slowly deteriorating faults (such as a slow drop in pressure) while avoiding misjudgments due to random fluctuations, thus improving the rigor and comprehensiveness of anomaly identification.

[0046] The shutdown decision-making and execution process establishes a fault quantity-type tiered decision-making system, standardized execution, and ground-based backup to balance safety and mission continuity. When ≥3 engines exhibit the same type of fault, a global shutdown is triggered to quickly mitigate systemic risks; when the number of faults is <3, differentiated handling is applied based on the quantity. M =1 indicates single-machine isolation, 1< M When the fault is less than 3, the engine is shut down and isolated. The fault transmission is blocked by physical and command isolation to preserve the normal operation of the engine to the greatest extent and avoid interrupting the task by shutting down the engine. In other cases, the sampling frequency is increased and the threshold for the number of abnormalities is lowered for secondary judgment. If there are no results after three consecutive times, the system is switched to ground verification. This forms a closed loop of autonomous judgment, secondary verification and ground backup to ensure both the efficiency of fault handling and the enhancement of safety redundancy.

[0047] like Figure 2 As shown, embodiments of the present invention also provide a shutdown control device 20 for the engine of a liquid-fueled launch vehicle, comprising: The acquisition module 21 is used to acquire the operating data and condition data of at least three engines in the multi-stage parallel engines of a liquid launch vehicle; The processing module 22 is used to determine the dynamic threshold of the operating data based on the operating condition data; determine the operating state of the engine based on the dynamic threshold and the operating data; determine the shutdown action of the multi-stage parallel engine based on the operating state; and control the shutdown of the multi-stage parallel engine based on the shutdown action of the multi-stage parallel engine.

[0048] Optionally, the operating condition data includes: environmental parameters and time parameters; According to the working condition data, a dynamic threshold of the running data is determined, comprising: According to the environmental parameter, a first dynamic threshold of the running data is determined; According to the time parameter, a second dynamic threshold of the running data is determined.

[0049] Optionally, the environmental parameter comprises fuel temperature and vibration intensity; According to the environmental parameter, a first dynamic threshold of the running data is determined, comprising: According to DY = T+K ×( F - R ) +L ×( P - Q ),determine the first dynamic threshold; wherein, DY is the first dynamic threshold, T is the first reference threshold, K is a fuel temperature compensation coefficient, F is the fuel temperature, R is the fuel reference temperature, L is a vibration intensity compensation coefficient, P is the vibration intensity, Q is the vibration reference intensity; According to the time parameter, a second dynamic threshold of the running data is determined, comprising: According to , determine the second dynamic threshold; wherein, DE is the second dynamic threshold, A is a pre-start threshold, B is a post-start threshold, S is the time parameter, H is a critical time of the pre-start and post-start.

[0050] Optionally, the running data comprises a first running parameter, a second running parameter and a third running parameter; The first running parameter comprises methane pre-injection pressure and oxygen pre-injection pressure; The second running parameter comprises control pressure reducer outlet pressure and blowdown pressure reducer outlet pressure; The third running parameter comprises turbine rotation speed and generator methane pre-injection pressure; According to the dynamic threshold and running data, the running state of the engine is determined, comprising: According to the first running parameter and the first dynamic threshold, a first state result is determined; determining a second state result according to the second operating parameter and a second dynamic threshold value; determining a third state result according to the third operating parameter and a third fixed threshold value; determining the operating state of the engine according to the first state result, the second state result and the third state result.

[0051] Optionally, the first state result is determined according to the first operating parameter and a first dynamic threshold value, including: if DYJ i >DY i the first state result is that the first operating parameter is abnormal; wherein, DYJ i the first operating parameter is DY i the first dynamic threshold value is i= 1, 2; determining a second state result according to the second operating parameter and a second dynamic threshold value, including: if DEJ i >DE i the second state result is that the second operating parameter is abnormal; wherein, DEJ i the second operating parameter is DE i the second dynamic threshold value is i= 1, 2; determining a third state result according to the third operating parameter and a third fixed threshold value, including: if DSJ i >DS i the third state result is that the third operating parameter is abnormal; wherein, DSJ i the third operating parameter is DS i the third fixed threshold value is i= 1, 2; determining the operating state of the multi-stage parallel engine according to the first state result, the second state result and the third state result, including: if CDYJ i ≧ 3, or CDEJ i ≧ 3, or CDSJ i≧ 3, determining that the running state of the engine is a fault; wherein, CDYJ i is the continuous abnormal number of the first running parameter of the single engine, CDEJ i is the continuous abnormal number of the second running parameter of the single engine, CDSJ i is the continuous abnormal number of the third running parameter of the single engine, i= 1, 2.

[0052] Optionally, according to the running state, determining the shutdown action of the engine comprises: determining the fault number and type of the engine according to the running state; determining the shutdown action of the engine according to the fault number and type of the engine.

[0053] Optionally, according to the fault number and type of the engine, determining the shutdown action of the engine comprises: if N e ≧ 3, determining the shutdown action as a global shutdown; wherein, N e is the number of engines triggering the same fault, e= 1, 2, …, 6; if N e < 3, and M=1 determining the shutdown action of the engine as a single-engine fault isolation; if 1 <M< 3, determining the shutdown action of the engine as a single-engine shutdown and fault isolation; wherein, M is the fault number of the engine; otherwise, determining the shutdown action as re-acquiring the judgment processing.

[0054] It should be noted that the device is a device corresponding to the above method, and all implementation manners in the above method embodiments are applicable to this embodiment and can also achieve the same technical effects.

[0055] The embodiment of the present application further provides a computing device, comprising: one or more processors; a storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described above. All implementation manners in the above method embodiment are applicable to this embodiment, and the same technical effects can also be achieved.

[0056] The embodiment of the present application further provides a computing device readable storage medium, storing instructions, when the instructions are run on the computing device, the computing device executes the method as described above. All implementation manners in the above method embodiment are applicable to this embodiment, and the same technical effects can also be achieved.

[0057] Those skilled in the art can understand that the units and algorithm steps of the examples described in combination with the embodiments disclosed in the present application can be realized by electronic hardware or a combination of software and electronic hardware of the computing device. Whether the functions are realized in hardware or software mode depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0058] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.

[0059] In the embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented by other ways. For example, the device embodiments described above are only schematic, and the division of the units is only a logical function division, and there can be another division manner in actual implementation, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between the units can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0060] The units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0061] In addition, each functional unit in various embodiments of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.

[0062] If the functions are realized in the form of software functional units and sold or used as independent products, they can be stored in a storage medium readable by a computing device. Based on such understanding, the technical solutions of the present application or the parts of the present application that essentially contribute to the prior art can be embodied in the form of software products. The software product of the computing device is stored in a storage medium, and includes a plurality of instructions for causing a computing device (which can be a personal computing device, a server, or a network device, etc.) to execute all or part of the steps of the method described in various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk, and various program code storage media.

[0063] In addition, it should be noted that in the device and method of the present application, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombination should be considered as equivalent solutions of the present application. Moreover, the steps of performing the above series of processes can naturally be executed in time sequence according to the order of description, but do not necessarily have to be executed in time sequence. Some steps can be executed in parallel or independently of each other. It can be understood by those skilled in the art that all or any steps or components of the method and device of the present application can be realized in hardware, firmware, software or a combination thereof in any computing device (including a processor, a storage medium, etc.) or a network of computing devices, which can be realized by those skilled in the art with basic programming skills by reading the description of the present application.

[0064] Therefore, the object of the present application can also be realized by running a program or a set of programs on any computing device. The computing device can be a commonly known general-purpose device. Therefore, the object of the present application can also be realized only by providing a program product containing program code for realizing the method or device. That is, such a program product also constitutes the present application, and a storage medium storing such a program product also constitutes the present application. Obviously, the storage medium can be any commonly known storage medium or any storage medium developed in the future. It should be noted that in the device and method of the present application, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombination should be considered as equivalent solutions of the present application. Moreover, the steps of performing the above series of processes can naturally be executed in time sequence according to the order of description, but do not necessarily have to be executed in time sequence. Some steps can be executed in parallel or independently of each other.

[0065] The above is the preferred embodiment of the present application, it should be noted that for those skilled in the art, without departing from the principles described in the present application, can also be made several improvements and refinements, these improvements and refinements should also be considered the scope of protection of the present application.

Claims

1. A method of shutdown control of an engine of a liquid propellant rocket, characterized by, The method comprises the following steps: acquiring operation data and working condition data of at least three engines in a multi-stage parallel engine of a liquid carrier rocket; determining a dynamic threshold of the operation data according to the working condition data; determining an operation state of the engine according to the dynamic threshold and the operation data; determining a shutdown action of the multi-stage parallel engine according to the operation state; controlling the multi-stage parallel engine to shut down according to the shutdown action of the multi-stage parallel engine.

2. The method of claim 1, wherein The working condition data comprises environmental parameters and time parameters; determining a dynamic threshold of the operation data according to the working condition data comprises: determining a first dynamic threshold of the operation data according to the environmental parameters; determining a second dynamic threshold of the operation data according to the time parameters.

3. The method of claim 2, wherein The environmental parameters comprise fuel temperature and vibration intensity; determining a first dynamic threshold of the operation data according to the environmental parameters comprises: According to DY = T+K ×( F - R ) +L ×( P - Q ), determine the first dynamic threshold; wherein, DY is a first dynamic threshold, T is a first reference threshold, K is a fuel temperature compensation factor, F is a fuel temperature, R is a fuel reference temperature, L is a vibration intensity compensation factor, P is a vibration intensity, Q is a vibration reference intensity; determining a second dynamic threshold of the operation data according to the time parameters comprises: According to , a second dynamic threshold is determined; wherein DE is a second dynamic threshold, A is a pre-activation threshold, B is a post-activation threshold, S is a time parameter, H is a critical time between the pre-activation and the post-activation.

4. The method of claim 1, wherein The operation data comprises first operation parameters, second operation parameters and third operation parameters; The first operation parameters comprise methane pre-injection pressure and oxygen pre-injection pressure; The second operation parameters comprise control pressure reducer outlet pressure and blowdown pressure reducer outlet pressure; The third operation parameters comprise turbine rotating speed and generator methane pre-injection pressure; determining an operation state of the engine according to the dynamic threshold and the operation data comprises: determining a first state result according to the first operation parameters and the first dynamic threshold; determining a second state result according to the second operation parameters and the second dynamic threshold; determining a third state result according to the third operation parameters and a third fixed threshold; determining the operation state of the engine according to the first state result, the second state result and the third state result.

5. The method of claim 4, wherein the engine is a liquid propellant rocket engine. determining a first state result according to the first operation parameters and the first dynamic threshold comprises: If DYJ i >DY i then the first state result is a first operating parameter anomaly; wherein DYJ i is a first operating parameter, DY i is a first dynamic threshold, i= 1,2; determining a second state result according to the second operation parameters and the second dynamic threshold comprises: If DEJ i >DE i then the second state result is a second operating parameter anomaly; wherein DEJ i is a second operating parameter, DE i is a second dynamic threshold, i= 1, 2; determining a third state result according to the third operation parameters and a third fixed threshold comprises: If DSJ i >DS i then the third state result is that the third operating parameter is abnormal; wherein DSJ i is a third operating parameter, DS i is a third fixed threshold, i= 1, 2; determining the operation state of the engine according to the first state result, the second state result and the third state result comprises: If CDYJ i ≧ 3, or CDEJ i ≧ 3, or CDSJ i ≧ 3, determine that the operating state of the engine is a fault; wherein CDYJ i a number of consecutive abnormalities of a first operating parameter of the single engine, CDEJ i a number of consecutive abnormalities of a second operating parameter of the single engine, CDSJ i a number of consecutive abnormalities of a third operating parameter of the single engine, i= 1, 2.

6. The method of claim 1, wherein determining a shutdown action of the multi-stage parallel engine according to the operation state comprises: determining a fault number and a fault type of the engine according to the operation state; determining a shutdown action of the engine according to the fault number and the fault type of the engine.

7. The method of claim 6, wherein the method further comprises: determining a shutdown action of the engine according to the fault number and the fault type of the engine comprises: If N e ≧ 3. Determine the shutdown action as global shutdown. wherein N e number of engines triggering the same fault, e= 1, 2,..., 6; If N e < 3, and M=1 determining the engine shutdown maneuver as a single engine fault isolation; If 1 <M< 3. determining that the engine shutdown maneuver is a single engine shutdown and fault isolation; wherein, M is the number of faults for the engine; in other cases, determining the shutdown action as re-acquiring and processing.

8. A shutdown control device for an engine of a liquid propellant rocket, characterized by comprising: The method comprises the following steps: an acquiring module, configured to acquire operation data and working condition data of at least three engines in a multi-stage parallel engine of a liquid carrier rocket; The processing module is configured to determine a dynamic threshold of the operation data according to the working condition data, determine an operation state of the engine according to the dynamic threshold and the operation data, determine a shutdown action of the multi-stage parallel engine according to the operation state, and control the multi-stage parallel engine to shut down according to the shutdown action of the multi-stage parallel engine.

9. A computing device, comprising: The method comprises: one or more processors; a memory device storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method as claimed in any one of claims 1 to 7.

10. A computing device readable storage medium characterized by, The computing device readable storage medium stores a program, and the program is executed by the processor to implement the method as claimed in any one of claims 1 to 7.