Propulsion control terminal reliability test analysis method
By constructing a fault diagnosis library and progressive verification, the problem of evaluation distortion in the reliability testing of propulsion control terminals was solved, realizing full-process reliability evaluation, ensuring functional state matching and instantaneous anomaly detection, and improving the accuracy of evaluation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-15
- Publication Date
- 2026-04-07
AI Technical Summary
In the existing technology, the reliability test of the propulsion control terminal failed to fully evaluate the consistency of functional parameters before and after the master-slave switchover and the real-time data during the switchover process, resulting in distorted evaluation results and failure to effectively detect instantaneous anomalies such as functional interruption, data loss or instruction error.
By constructing a fault diagnosis library, randomly injecting faults and verifying path compliance, and combining the accuracy assessment of fault diagnosis, the reliability of fault diagnosis is determined, the primary and backup unit switching is triggered, timing and status parameters are collected, the switching timing and functional continuity are evaluated, and a progressive verification is formed to ensure the reliability of diagnosis and switching.
It enables full-process reliability assessment of propulsion control terminals, avoids invalid switching caused by misdiagnosis, ensures functional status matching, captures instantaneous anomalies, improves the accuracy and authenticity of assessment, and significantly enhances the accuracy rate of reliability assessment.
Smart Images

Figure CN120972863B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of propulsion control terminal reliability testing, and relates to a propulsion control terminal reliability testing and analysis method. BACKGROUND
[0002] The propulsion control terminal is a core device for real-time control, state monitoring and fault handling of various propulsion systems, and its functions include receiving external control instructions, collecting key parameters of the propulsion system, executing adjustment operations, and ensuring continuous operation of the system in fault scenarios through the main and backup unit redundancy design. In the field of aviation, the reliability of the propulsion control terminal is particularly critical. As the core power device of an airplane, the propulsion control terminal of an aero-engine may cause serious consequences such as sudden change of engine thrust and power interruption if it fails, directly threatening flight safety. Therefore, its reliability needs to be tested and analyzed.
[0003] In the prior art, although there are means for testing the reliability of the control terminal, most of them focus on single-dimensional evaluation, and there are still several deficiencies in the following aspects: 1. The current only focuses on whether the main and backup switching is completed, and does not perform full-dimensional consistency verification on the functional parameter values, data transmission format and instruction execution results before and after the switching, thereby causing abnormal fluctuations in engine thrust.
[0004] 2. The existing technology focuses on the static state after the switching is completed, and does not continuously track the real-time running data of the key functions in the switching process, making it difficult to find transient abnormalities such as function interruption, data loss or instruction error, and thus leading to distorted reliability evaluation results. SUMMARY
[0005] In view of this, in order to solve the problems raised in the background art, a propulsion control terminal reliability testing and analysis method is proposed.
[0006] The purpose of the application can be achieved by the following technical solutions: The application provides a propulsion control terminal reliability testing and analysis method, comprising: S1, constructing a fault diagnosis library based on historical fault diagnosis data, randomly selecting a fault type to inject a fault into the propulsion control terminal, collecting fault diagnosis data, and verifying the compliance of the fault diagnosis path in combination with the fault diagnosis library.
[0007] S2, if the path is compliant, based on the response time and the actual fault location, the accuracy of fault diagnosis is evaluated.
[0008] S3, based on the fault diagnosis path compliance verification result and the fault diagnosis accuracy evaluation result, it is determined whether the fault diagnosis is reliable.
[0009] S4. When the fault diagnosis is reliable, trigger the main and backup unit fault switching, collect timing parameters and status parameters, and determine whether the switching timing continuity is qualified based on the timing parameters.
[0010] S5. Based on the output function status data of the main / standby unit switching in the status parameters, perform a consistency assessment and combine it with the real-time operation data of key functions during the switching process to determine whether the function continuity is qualified.
[0011] S6. Based on the pass / fail judgment results of handover timing continuity and functional continuity, determine whether the handover is reliable.
[0012] S7. Integrate the fault diagnosis reliability judgment results and the switching reliability judgment results to generate and output the reliability assessment results of the propulsion control terminal.
[0013] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) The present invention first ensures that the detection nodes, jump order and execution logic of the diagnostic process comply with the standard through path compliance verification, and then verifies the validity of the results through diagnostic accuracy assessment. The two form a progressive verification. Only when the path is compliant and the diagnosis is accurate is the diagnosis deemed reliable, providing a reliable premise for fault switching and avoiding invalid or erroneous switching caused by misdiagnosis.
[0014] (2) This invention ensures that no diagnostic steps are missed by matching the actual path with the detection nodes of the standard diagnostic path one by one, avoiding the failure to be diagnosed due to missing detection nodes. When matching detection nodes, the path compliance is verified based on the node jump order and execution logic, thereby effectively reducing diagnostic errors caused by process confusion.
[0015] (3) By comparing the output functional status data of the main unit before switching and the backup unit after switching and determining the preset threshold, this invention obtains whether the continuity of the function before and after switching is qualified, realizes the accurate matching of the functional status before and after switching of the main and backup units, and effectively avoids abnormal thrust fluctuations caused by parameter mismatch.
[0016] (4) This invention dynamically detects the real-time operation data of key functions during the switching process, captures instantaneous anomalies such as function interruption, data loss or instruction error, and combines the qualified judgment criteria for functional continuity to solve the problem of evaluation distortion caused by only focusing on static results, ensuring the authenticity of the switching reliability assessment and forming a closed loop with the progressive logic of the diagnostic process.
[0017] (5) This invention integrates the full-process evaluation data of diagnosis and switching through the progressive judgment criteria of path compliance, accurate diagnosis and reliable switching, forming a complete closed loop of diagnosis-switching-evaluation. At the same time, it accurately marks non-conforming items, avoids the limitations of single-dimensional evaluation, and significantly improves the accuracy of reliability evaluation. Attached Figure Description
[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a schematic diagram showing the connections between the steps of the method of the present invention.
[0020] Figure 2 This is a schematic diagram showing the connection steps of the fault diagnosis path compliance verification in this invention.
[0021] Figure 3 This is a schematic diagram showing the connection steps for determining the functional continuity of the present invention. Detailed Implementation
[0022] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0023] Please see Figure 1 As shown, the present invention provides a method for reliability testing and analysis of propulsion control terminals. The method includes: S1, constructing a fault diagnosis library based on historical fault diagnosis data, randomly selecting fault types to inject faults into the propulsion control terminal, collecting fault diagnosis data, and verifying the compliance of fault diagnosis paths in conjunction with the fault diagnosis library.
[0024] It should be added that randomly selecting fault types to inject faults into the propulsion control terminal is to avoid test blind spots, cover diverse fault scenarios, simulate the uncertainty of real operation, improve the realism of the test and objectively evaluate the generalization ability of the diagnostic algorithm. At the same time, randomly selecting fault types provides a comprehensive and realistic test data foundation for subsequent fault diagnosis reliability analysis and switching reliability assessment, ensuring that the final reliability assessment results can objectively reflect the actual performance of the propulsion control terminal.
[0025] For example, the construction of the fault diagnosis library includes: extracting each fault type from historical fault diagnosis data and filtering data records with correct fault diagnosis results.
[0026] It should be added that the classification of the fault types includes: extracting the component identification and fault phenomenon at the time of each fault occurrence from historical fault diagnosis data.
[0027] Each fault is grouped using the K-means clustering algorithm: when the component identifier points to a signal acquisition component such as a temperature sensor, and the fault phenomenon is manifested as abnormal signal acquisition or conversion, it is clustered as a sensor-related fault.
[0028] When the component identifier points to actuating components such as fuel valves, and the fault manifests as abnormal mechanical movement or power output, it is clustered as an actuator-related fault.
[0029] When the component identifier points to an internal circuit module such as the central processing unit, and the fault manifests as abnormal data processing or instruction transmission, it is clustered as an internal module fault.
[0030] Among them, sensor-related faults refer to faults in signal acquisition components such as temperature and pressure, such as signal distortion or disconnection; actuator-related faults refer to faults in moving components such as motors and valves, such as jamming or output deviation; and internal module-related faults refer to faults in core processing modules such as CPUs and memory, such as calculation errors or data loss.
[0031] For each fault type, multiple correct diagnostic paths are extracted. By comparing node sequences, the detection node sequence with the highest frequency is selected as the baseline path for the fault type.
[0032] It should be added that the node sequence alignment uses the Levenshtein edit distance algorithm: the node sequence of each diagnostic path is converted into characters, the edit distance between each pair of all path strings is calculated, the top K paths with the smallest edit distance are selected, the frequency of each node is counted, and the highest frequency node sequence is used as the baseline path.
[0033] Extract the fault location accuracy and response time values from the correct diagnostic results, take the minimum location deviation as the benchmark location accuracy, and take the 95th percentile value as the benchmark response time.
[0034] It should be added that the 95th percentile value was selected as the benchmark response time to ensure that the response speed of fault diagnosis is not lower than 95% of the normal cases in historical fault diagnosis data, so as to avoid the spread of faults due to slow response.
[0035] A fault diagnosis library is constructed based on fault type, baseline path, and baseline diagnosis results.
[0036] The fault types include sensor-related faults, actuator-related faults, and internal module-related faults.
[0037] Please see Figure 2 As shown, for example, the verification of the compliance of the fault diagnosis path includes: obtaining the detection nodes, node jump order and execution logic of the actual path in the fault diagnosis process from the fault diagnosis data.
[0038] Each detection node in the actual path is matched one by one with the corresponding standard detection nodes in the standard diagnostic path. If there is a mismatch between the detection nodes, the fault diagnosis path is determined to be non-compliant.
[0039] When all detected nodes match, the node jump order and execution logic corresponding to the actual path and the standard diagnostic path are dynamically verified for fault tolerance. When the node jump order is within the fault tolerance range and the core conditions of the execution logic are consistent with the standard logic, the fault diagnosis path is deemed compliant; otherwise, the fault diagnosis path is deemed non-compliant.
[0040] It should be added that dynamic fault-tolerant verification can adapt to the real-time changes in the operating conditions of the propulsion control terminal. By adjusting the fault tolerance range based on the operating conditions, it avoids misjudging reasonable fluctuations as path anomalies. On the other hand, it can balance the flexibility and rigor of diagnostic logic, allowing minor deviations in non-core links and strictly verifying only core conditions, thereby improving the accuracy and practicality of verification.
[0041] The fault tolerance range is dynamically adjusted based on the real-time operating conditions of the engine. For example, the fault tolerance threshold is switched by collecting the engine speed signal: if the speed is <80% of the rated value, the idle speed threshold is ±3ms; if the speed is ≥80% of the rated value, the high load threshold is ±10ms.
[0042] It should be added that the dynamic fault tolerance verification of node jump order and execution logic is as follows: Through sequence comparison algorithm, the actual order such as [A→B→C] and the standard order such as [A→B→C] are converted into character sequences and the matching degree is calculated. If the absolute value of the deviation between the jump time difference of adjacent nodes is less than or equal to the dynamic fault tolerance threshold, the node jump order is considered to be compliant. The dynamic fault tolerance threshold is determined with reference to the industry standard of similar terminals or historical operating data. For example, statistical analysis of historical operating data is performed to calculate the standard deviation under different working conditions, and 3 times the standard deviation is used as the dynamic fault tolerance threshold.
[0043] If the structure, key parameter values, and logical relationships of the core condition nodes in the execution logic completely match the standard execution logic, and there are no missing or misjudged core conditions, the execution logic is deemed compliant; if there are missing core condition nodes, incorrect core parameters, contradictory core logical relationships, or substantial deviations between the branch jump path and the standard logic, the execution logic is deemed abnormal.
[0044] S2. If the path is compliant, conduct an assessment of the accuracy of fault diagnosis based on the response time and the actual fault location.
[0045] This invention ensures no diagnostic omissions by matching the actual path with each detection node of the standard diagnostic path, avoiding missed faults due to missing detection nodes. Furthermore, during node matching, path compliance is verified based on the node jump order and execution logic, effectively reducing diagnostic errors caused by process confusion.
[0046] For example, the fault diagnosis accuracy assessment includes: obtaining the injection time of the fault injection and the generation time of the fault diagnosis result from the fault diagnosis data, and using the time difference between the injection time and the generation time as the response time of the fault diagnosis.
[0047] The response time is compared with the baseline response time corresponding to the fault diagnosis library. If the response time is less than or equal to the baseline response time, the fault diagnosis response is determined to be timely; otherwise, the fault diagnosis response is determined to be abnormal.
[0048] The actual fault location is obtained from the fault diagnosis data, and the actual fault location is mapped and matched with the reference fault location of the injected fault.
[0049] If the actual fault location is inconsistent with the reference fault location, the fault diagnosis and location are deemed inaccurate.
[0050] If the actual fault location is consistent with the reference fault location, then the location range of the actual fault location is defined, and the spatial overlap ratio between the location range and the reference fault range is calculated.
[0051] It should be added that the positioning range for defining the actual fault location includes: a spherical area defined by a preset radius with the actual fault location as the center, and the standard fault range is preset according to the fault type, such as a radius of 3cm for sensor faults.
[0052] It should be added that the calculation process of the spatial overlap ratio includes: obtaining the overlap area between the positioning range and the standard fault range, and using the ratio of the overlap area to the standard fault range area as the spatial overlap ratio.
[0053] If the spatial overlap ratio is greater than or equal to the preset baseline overlap ratio, the fault diagnosis and location are determined to be accurate; otherwise, the fault diagnosis and location are determined to be inaccurate.
[0054] The setting of the preset baseline overlap ratio needs to be determined comprehensively based on the characteristics of the fault type, industry safety standards, and historical fault diagnosis data. Specifically, for sensor-related faults, when the spatial overlap ratio is at a certain threshold, the fault repair accuracy is significantly improved with no risk of secondary fault propagation; below this threshold, the repair misjudgment rate increases significantly. The preset baseline overlap ratio for sensor-related faults is determined by combining the critical characteristics of repair effectiveness in the aforementioned historical data. For actuator-related faults, when the spatial overlap ratio reaches a certain threshold, the action response after master / slave switching meets dynamic control requirements; below this threshold, abnormal fluctuations affecting system operation may occur. The preset baseline overlap ratio for actuator-related faults is set based on the critical values of operational stability in historical data. For internal module-related faults, when the spatial overlap ratio is at a certain threshold, it satisfies both the accuracy requirements of fault tracing and the real-time performance of the diagnostic response; if it exceeds this threshold, the diagnostic response performance will decrease. The preset baseline overlap ratio for internal module-related faults is determined by combining the balance point between accuracy and real-time performance in historical data.
[0055] It should be added that, in advancing the reliability testing of control terminals, the accuracy of fault diagnosis and location provides precise guidance for fault repair, directly pinpointing the specific location, avoiding blind troubleshooting, and shortening repair time. This, in turn, ensures the effectiveness of primary / backup switching, ensuring that the backup unit accurately avoids the fault area and maintains functional continuity. Simultaneously, it quickly identifies problems to reduce the risk of fault propagation, ensuring the overall reliable operation and operational safety of the system.
[0056] It should be added that if there are associated faults, the actual fault location should be determined first based on the fault propagation path verification; otherwise, the mapping and matching between the actual fault location and the standard location should be performed directly.
[0057] If the fault diagnosis and location are accurate and the fault diagnosis response is timely, then the fault diagnosis is considered accurate; otherwise, the fault diagnosis is considered inaccurate.
[0058] S3. Based on the compliance verification results of the fault diagnosis path and the accuracy assessment results of the fault diagnosis, determine whether the fault diagnosis is reliable.
[0059] In this embodiment of the invention, the detection nodes, jump order and execution logic of the diagnostic process are first verified through path compliance to ensure that they meet the standards. Then, the validity of the results is verified through diagnostic accuracy assessment. The two form a progressive verification. The diagnosis is deemed reliable only when the path is compliant and the diagnosis is accurate, which provides a reliable premise for fault switching and avoids invalid or erroneous switching caused by misdiagnosis.
[0060] For example, determining whether the fault diagnosis is reliable includes: when the fault diagnosis path is compliant and the fault diagnosis is accurate, the fault diagnosis is determined to be reliable.
[0061] When there are non-compliant fault diagnosis paths or inaccurate fault diagnosis, the fault diagnosis is deemed unreliable.
[0062] S4. When the fault diagnosis is reliable, trigger the main and backup unit fault switching, collect timing parameters and status parameters, and determine whether the switching timing continuity is qualified based on the timing parameters.
[0063] It should be added that the timing parameters include: the switching trigger time, the primary unit stop responding time, the backup unit start responding time, and the switching completion time. The status parameters include: output functional status data before the primary unit switches over and after the backup unit switches over, such as functional parameter values, data transmission format, and instruction execution results; and real-time operating data of key functions during the switching process, such as whether there are functional interruptions, data loss, or instruction errors. Among these, key functions include thrust adjustment of the propulsion system, instruction transmission, and status monitoring, which directly affect the core performance of the terminal.
[0064] Among them, the switching trigger time: when the fault diagnosis is reliable, the system will automatically generate an instruction to trigger the switching of the main and backup units. The system time of the instruction is the switching trigger time, which is recorded by the central monitoring system of the propulsion control terminal.
[0065] Master unit stops responding: When the master unit stops sending feedback signals and the duration exceeds the preset response timeout threshold, this moment is recorded as the master unit stops responding. The response timeout threshold is the minimum response interval based on the terminal communication protocol.
[0066] Backup unit start response time: The central monitoring system of the propulsion control terminal receives the backup unit status signal and uses it as the backup unit start response time.
[0067] Switchover completion time: When the standby unit has completely taken over the functions of the main unit and has been running stably for a preset period of time, the system time at this time is recorded as the switchover completion time.
[0068] Output function status data before main unit switching: Data is collected in real time through the main unit's function output interface, including: function parameter values, data transmission format, and instruction execution results.
[0069] Output functional status data after standby unit switching: After the switch is completed, the functional output interface of the standby unit is used to acquire the functional parameter values, data transmission format and instruction execution results of the standby unit through the same acquisition method as the main unit, so as to ensure the comparability with the main unit data.
[0070] Real-time operational data of key functions during the switching process: Recorded using the terminal's built-in real-time data monitoring system. Functional interruption is determined by detecting whether there are continuous disconnections in the signal transmission of key functions. Data loss is determined by comparing the data sequences before and after the switch and counting the number of missing data frames or key parameter values. Instruction errors are determined by verifying the matching degree between the result of the standby unit's executed instructions and the expected result of the standard instructions.
[0071] For example, determining whether the switching timing continuity is qualified includes: extracting the switching trigger time, the primary unit stop responding time, the backup unit start responding time, and the switching completion time from the timing parameters of the primary and backup unit fault switching.
[0072] The switching interval is obtained by calculating the time difference between the time when the primary unit stops responding and the time when the backup unit starts responding.
[0073] The handover trigger time and handover completion time are extracted from the timing parameters, and the time difference between the two is calculated to obtain the total handover time.
[0074] The switching interval duration is compared with the preset maximum allowable interruption duration. If the switching interval duration is less than or equal to the preset maximum allowable interruption duration, the switching interval is deemed qualified; otherwise, the switching interval is deemed abnormal.
[0075] It should be noted that the preset maximum allowable interruption duration is based on historical fault diagnosis data. A large number of cases related to primary / standby unit fault switching were selected from the historical fault diagnosis data, and the time difference between the primary unit's stop response and the standby unit's start response was extracted for each case. All extracted switching interval duration data were categorized and organized according to fault type. For the switching interval duration data corresponding to each fault type, the average value was calculated and used as the preset maximum allowable interruption duration.
[0076] The total handover time is compared with the preset baseline handover time. If the total handover time is less than or equal to the preset baseline handover time, the total handover time is deemed acceptable; otherwise, the total handover time is deemed abnormal.
[0077] It should be added that the reference total switching time is determined by theoretical calculations based on terminal design parameters, such as the data synchronization rate of the primary and backup units and the startup time of the backup unit. For example, if the backup unit startup of a certain type of terminal requires 30ms and the data synchronization requires 20ms, then the reference total switching time is preset to 50ms.
[0078] When both the switching interval and the total switching time are qualified, the continuity of the fault switching sequence of the primary and backup units is deemed to meet the requirements. If any one of them is abnormal, the continuity of the switching sequence is deemed to not meet the requirements.
[0079] It should be added that temporal continuity is directly related to the terminal's responsiveness to dynamic scenarios. For example, if the switching interval exceeds the maximum allowable interruption duration during fault switching of the spacecraft propulsion control terminal, it may cause delays in engine thrust adjustment and lead to orbital deviations. However, compliant temporal continuity can ensure that control commands are not significantly delayed during the switching process, maintaining the real-time control accuracy of the system.
[0080] S5. Based on the output function status data of the main / standby unit switching in the status parameters, perform a consistency assessment and combine it with the real-time operation data of key functions during the switching process to determine whether the function continuity is qualified.
[0081] Please see Figure 3 As shown, for example, the determination of whether the function continuity is qualified includes: Q1, comparing the output function status data before the main unit switchover with that after the backup unit switchover to determine whether the function status connection is qualified.
[0082] Furthermore, determining whether the functional status connection is qualified includes: Q1-1, calculating the relative deviation of each functional parameter value in the output functional status data before the main unit switchover and after the backup unit switchover, and obtaining the relative deviation rate of each functional parameter value.
[0083] Q1-2. Verify whether the structure identifier, byte order and verification method in the output functional status data before the main unit switchover and after the backup unit switchover are completely consistent. If they are completely consistent, it indicates that the data transmission format is consistent. If they are inconsistent, it indicates that the data transmission format is inconsistent.
[0084] Q1-3. Verify that the feedback status codes of the primary and backup units for the same instruction are both success codes.
[0085] Q1-4. When the relative deviation rate of all functional parameter values is less than the preset value, the data transmission format is consistent, and the status codes of the instruction execution results are all success codes, the functional status connection is deemed to be qualified.
[0086] The preset values are determined based on extensive historical operating data and industry standards to ensure the reliability and stability of functional state transitions. Specifically, through long-term monitoring and statistical analysis of the propulsion control terminal's functional parameter values under various operating conditions, statistical methods are used to calculate the fluctuation range of functional parameter values under normal operating conditions. For example, after referring to industry standards of similar mature products and combining the actual performance indicators of this terminal, the relative deviation rate preset value for the thrust adjustment parameter is set at ±5%. This preset value can effectively distinguish between parameter fluctuations during normal operation and parameter deviations caused by faults or anomalies. It avoids misjudgments caused by overly strict preset values and prevents the failure to detect potential problems in a timely manner due to overly lenient preset values, thereby ensuring the accuracy and reliability of functional state transitions during operations such as primary / standby switching of the propulsion control terminal.
[0087] Q1-5. If any condition is not met, the functional state connection is determined to be abnormal.
[0088] Q2. Analyze the real-time operation data of key functions during the switching process to detect any abnormalities such as function interruption, data loss, or instruction errors.
[0089] Q3. If the critical functions are normal during the switching process, the switching process is considered to be functionally acceptable; otherwise, the switching process is considered to be functionally unacceptable.
[0090] Q4. When the functional status is connected successfully and the switching process remains successful, the functional continuity of the main and backup unit fault switching is deemed to meet the requirements. If any abnormality exists, the functional continuity is deemed to fail to meet the requirements.
[0091] It should be added that functional continuity analysis can verify the consistency of the state before and after the switching of the main and backup units, avoid functional gaps caused by parameter mismatch, and promptly identify functional connection anomalies to prevent the propulsion system from causing operational deviations due to sudden thrust changes. At the same time, real-time monitoring of the switching process can detect hidden problems where the time continuity is qualified but the function is abnormal, thereby avoiding potential risks in advance.
[0092] This invention achieves accurate matching of the functional status before and after the switching of the main unit and the backup unit by comparing the consistency of the output functional status data before and after the switching of the main unit and determining the preset threshold, thereby obtaining whether the functional continuity before and after the switching is qualified. This effectively avoids abnormal thrust fluctuations caused by parameter mismatch.
[0093] S6. Based on the pass / fail judgment results of handover timing continuity and functional continuity, determine whether the handover is reliable.
[0094] For example, determining whether the switching is reliable includes: when the switching timing continuity and functional continuity in the switching reliability parameters meet the requirements, the fault switching is determined to be reliable.
[0095] When the switching reliability parameters fail to meet the requirements for switching timing continuity, functional continuity, or both, the fault switching is deemed unreliable.
[0096] This invention addresses the problem of evaluation distortion caused by focusing only on static results by dynamically detecting real-time operational data of key functions during the switching process, capturing instantaneous anomalies such as function interruption, data loss, or instruction errors, and combining this with the qualification criteria for functional continuity. This ensures the authenticity of the switching reliability assessment and forms a closed loop with the progressive logic of the diagnostic process.
[0097] S7. Integrate the fault diagnosis reliability judgment results and the switching reliability judgment results to generate and output the reliability assessment results of the propulsion control terminal.
[0098] For example, the reliability assessment result of the generated propulsion control terminal includes: when the fault diagnosis is reliable and the fault switching is reliable, the reliability of the propulsion control terminal is determined to meet the standard.
[0099] When fault diagnosis or fault switching is unreliable, the propulsion control terminal is deemed unreliable and marked as unreliable.
[0100] It should be added that the unreliable items mentioned are unreliable items for fault diagnosis and unreliable items for fault switching.
[0101] This invention integrates the full-process evaluation data of diagnosis and switching through a progressive judgment standard of path compliance, accurate diagnosis, and reliable switching, forming a complete closed loop of diagnosis-switching-evaluation. At the same time, it accurately marks non-compliant items, avoiding the limitations of single-dimensional evaluation and significantly improving the accuracy of reliability evaluation.
[0102] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.
[0103] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, in the form of a computer program product.
[0104] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0105] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.
[0106] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0107] Finally, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for reliability testing and analysis of propulsion control terminals, characterized in that: include: S1. Construct a fault diagnosis library based on historical fault diagnosis data, randomly select fault types to inject faults into the propulsion control terminal, and collect fault diagnosis data through intelligent sensors. S2. Combine the fault diagnosis library to verify the compliance of the fault diagnosis path. If the path is compliant, evaluate the accuracy of the fault diagnosis based on the response time and the actual fault location. S3. Based on the compliance verification results of the fault diagnosis path and the accuracy assessment results of the fault diagnosis, determine whether the fault diagnosis is reliable. S4. When the fault diagnosis is reliable, trigger the main and backup unit fault switching, collect timing parameters and status parameters, and determine whether the switching timing continuity is qualified based on the timing parameters. S5. Based on the output function status data of the main and backup unit switching in the status parameters, perform consistency evaluation, and combine the real-time operation data of key functions during the switching process to determine whether the function continuity is qualified. S6. Based on the pass / fail judgment results of handover timing continuity and functional continuity, determine whether the handover is reliable; S7. Integrate the fault diagnosis reliability judgment results and the switching reliability judgment results to generate and output the reliability assessment results of the propulsion control terminal; The construction of the fault diagnosis library includes: Extract each fault type from historical fault diagnosis data and filter the data records with correct fault diagnosis results; For each fault type, multiple correct diagnostic paths are extracted, and the detection node sequence with the highest frequency is selected as the baseline path for the fault type by comparing node sequences. Extract the fault location accuracy and response time values from the correct diagnostic results, take the minimum location deviation as the benchmark location accuracy, and take the 95th percentile value as the benchmark response time; A fault diagnosis library is constructed based on fault type, baseline path, and baseline diagnosis results; The fault types include sensor-related faults, actuator-related faults, and internal module-related faults; The assessment of the accuracy of fault diagnosis includes: The injection time of the fault injection and the generation time of the fault diagnosis result are obtained from the fault diagnosis data, and the time difference between the injection time and the generation time is used as the response time of the fault diagnosis. The response time is compared with the baseline response time corresponding to the fault diagnosis library. If the response time is less than or equal to the baseline response time, the fault diagnosis response is determined to be timely; otherwise, the fault diagnosis response is determined to be abnormal. The actual fault location is obtained from the fault diagnosis data, and the actual fault location is mapped and matched with the reference fault location of the injected fault. If the actual fault location is inconsistent with the reference fault location, the fault diagnosis and location are determined to be inaccurate. If the actual fault location is consistent with the reference fault location, then define the location range of the actual fault location and calculate the spatial overlap ratio between the location range and the reference fault range. If the spatial overlap ratio is greater than or equal to the preset baseline overlap ratio, the fault diagnosis and location are determined to be accurate; otherwise, the fault diagnosis and location are determined to be inaccurate. If the fault diagnosis and location are accurate and the fault diagnosis response is timely, then the fault diagnosis is considered accurate; otherwise, the fault diagnosis is considered inaccurate.
2. The method for reliability testing and analysis of a propulsion control terminal according to claim 1, characterized in that: The compliance verification of the fault diagnosis path includes: Obtain the detection nodes, node jump order, and execution logic of the actual path during the fault diagnosis process from the fault diagnosis data; Each detection node in the actual path is matched one by one with each standard detection node in the standard diagnostic path. If there is a mismatch in the detection nodes, the fault diagnosis path is determined to be non-compliant. When all detected nodes match, the node jump order and execution logic corresponding to the actual path and the standard diagnostic path are dynamically verified for fault tolerance. When the node jump order is within the fault tolerance range and the core conditions of the execution logic are consistent with the standard logic, the fault diagnosis path is deemed compliant; otherwise, the fault diagnosis path is deemed non-compliant.
3. The method for reliability testing and analysis of a propulsion control terminal according to claim 1, characterized in that: The determination of whether the fault diagnosis is reliable includes: When the fault diagnosis path is compliant and the fault diagnosis is accurate, the fault diagnosis is considered reliable. When there are non-compliant fault diagnosis paths or inaccurate fault diagnosis, the fault diagnosis is deemed unreliable.
4. The method for reliability testing and analysis of a propulsion control terminal according to claim 1, characterized in that: The determination of whether the switching timing continuity is qualified includes: Extract the switching trigger time, primary unit stop response time, standby unit start response time, and switching completion time from the timing parameters of primary and standby unit fault switching; The time difference between the time when the main unit stops responding and the time when the standby unit starts responding is calculated to obtain the switching interval duration. Extract the handover trigger time and handover completion time from the timing parameters, calculate the time difference between the two, and obtain the total handover time. The switching interval duration is compared with the preset maximum allowable interruption duration. If the switching interval duration is less than or equal to the preset maximum allowable interruption duration, the switching interval is deemed qualified; otherwise, the switching interval is deemed abnormal. The total handover time is compared with the preset baseline handover time. If the total handover time is less than or equal to the baseline handover time, the total handover time is deemed acceptable; otherwise, the total handover time is deemed abnormal. When both the switching interval and the total switching time are qualified, the continuity of the fault switching sequence of the primary and backup units is deemed to meet the requirements. If any one of them is abnormal, the continuity of the switching sequence is deemed to not meet the requirements.
5. The method for reliability testing and analysis of a propulsion control terminal according to claim 1, characterized in that: The determination of whether the continuity of the function is qualified includes: Q1. Compare the output function status data before the main unit switchover with the backup unit switchover to determine whether the function status connection is qualified. Q2. Analyze the real-time operation data of key functions during the switching process to detect whether there are any abnormal situations such as function interruption, data loss or command error. Q3. If the critical functions are normal during the switching process, the switching process is considered to be functionally acceptable; otherwise, the switching process is considered to be functionally unacceptable. Q4. When the functional status is connected successfully and the switching process remains successful, the functional continuity of the main and backup unit fault switching is deemed to meet the requirements. If any abnormality exists, the functional continuity is deemed to fail to meet the requirements.
6. The method for reliability testing and analysis of a propulsion control terminal according to claim 5, characterized in that: The determination of whether the functional status connection is qualified includes: The relative deviation of each function parameter value in the output function status data before the main unit switching and after the backup unit switching is calculated to obtain the relative deviation rate of each function parameter value. Verify whether the structure identifier, byte order and verification method in the output functional status data before the main unit switchover and after the backup unit switchover are completely consistent. If they are completely consistent, it indicates that the data transmission format is consistent. If there is inconsistency, it indicates that the data transmission format is inconsistent. Verify that the feedback status codes from both the primary and backup units for the same instruction are success codes. When the relative deviation rate of all functional parameter values is less than the preset value, the data transmission format is consistent, and the status codes of the instruction execution results are all success codes, the functional status connection is deemed to be qualified. If any condition is not met, the functional state connection is determined to be abnormal.
7. The method for reliability testing and analysis of a propulsion control terminal according to claim 1, characterized in that: The determination of whether the switching is reliable includes: When the switching timing continuity and functional continuity in the switching reliability parameters meet the requirements, the fault switching is deemed reliable. When the switching reliability parameters fail to meet the requirements for switching timing continuity, functional continuity, or both, the fault switching is deemed unreliable.
8. The method for reliability testing and analysis of a propulsion control terminal according to claim 1, characterized in that: The reliability assessment results of the generated propulsion control terminal include: When fault diagnosis and fault switching are reliable, the reliability of the propulsion control terminal is deemed to meet the standard. When fault diagnosis or fault switching is unreliable, the propulsion control terminal is deemed unreliable and marked as unreliable.
Citation Information
Patent Citations
Reference model-based servo system on-orbit fault diagnosing and processing system and method
CN106527393A
AI-based railway signal system abnormality detection and diagnosis method
KR102730303B1