Multi-redundancy flight control system, method and equipment based on multi-channel communication bus
The redundant flight control system, which utilizes a multi-channel communication bus and the ARINC659 bus, solves the problem of insufficient fault tolerance in traditional flight control computers, and enables automatic fault isolation and switching in the event of multiple faults, thereby improving the reliability and safety of flight control.
Patent Information
- Application Number
- CN202511095855.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-11-21
AI Technical Summary
Traditional flight control computers lack fault tolerance, struggle to handle multiple faults, have limited fault isolation capabilities, are weak against electromagnetic interference, are prone to bit errors or signal loss during data transmission, and lack automatic fault detection and switching mechanisms, thus affecting the reliability and safety of flight control.
The redundant flight control system, based on a multi-channel communication bus, achieves redundancy through multiple independent computing and processing circuits and the ARINC659 bus. It has fault detection and automatic switching functions to ensure that the system continues to operate normally when some units fail.
It improves the reliability and safety of the flight control system, and can automatically isolate faulty units in complex flight environments to maintain normal system operation and meet high safety requirements.
Smart Images

Figure CN120993966A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of aircraft, and particularly relates to a multi-redundancy flight control system, method and device based on a multi-path communication bus. BACKGROUND
[0002] With the development of aviation technology, modern aircraft have increasingly high requirements for the safety and reliability of flight computer. As the core control device of the aircraft, the flight computer is directly responsible for the attitude control, flight parameter calculation and emergency state processing of the aircraft. Therefore, ensuring the robustness and reliability of the flight computer is crucial to flight safety.
[0003] At present, redundancy design is usually adopted, and multiple sets of flight computers are carried on the aircraft. When one set of flight computer fails, manual operation is performed to switch to another set of flight computer for continuous work.
[0004] However, such manual switching of flight computers is prone to poor reliability of the flight control system. SUMMARY
[0005] The embodiments of the present application provide a multi-redundancy flight control system, method and device based on a multi-path communication bus, which can realize redundancy processing of flight control, ensure that the system can continue to operate normally when some units fail, and thus improve the reliability of the flight control system.
[0006] In one aspect, the embodiments of the present application provide a multi-redundancy flight control system based on a multi-path communication bus, which comprises at least two computing processing circuits, a communication bus and an interface processing circuit, each computing processing circuit being connected with the interface processing circuit through the communication bus.
[0007] The interface processing circuit is configured to obtain to-be-processed data and store the to-be-processed data in a data buffer.
[0008] The computing processing circuit is configured to, in the case where no failure occurs, obtain the to-be-processed data from the data buffer through the communication bus, process the to-be-processed data to obtain a data processing result, and store the data processing result in the data buffer through the communication bus.
[0009] The computing processing circuit is further configured to, in the case where a failure occurs, output a failure signal to the interface processing circuit.
[0010] The interface processing circuit is further configured to, in the case where it is detected that the computing processing circuit fails, cut off the data interaction between the computing processing circuit and the data buffer.
[0011] In another aspect, the embodiment of the present application provides a fault processing method applied to a redundant flight control system, the redundant flight control system comprising at least two computing processing circuits, a communication bus and an interface processing circuit, each computing processing circuit being connected with the interface processing circuit through the communication bus, and the method comprising:
[0012] acquiring to-be-processed data and storing the to-be-processed data into a data buffer;
[0013] in a case where no fault occurs in the computing processing circuit, acquiring the to-be-processed data from the data buffer to process the to-be-processed data to obtain a data processing result, and storing the data processing result into the data buffer;
[0014] in a case where a fault occurs in the computing processing circuit, cutting off data interaction between the computing processing circuit and the data buffer.
[0015] In still another aspect, the embodiment of the present application provides an electronic device comprising the redundant flight control system.
[0016] The redundant flight control system, method and device based on a multi-path communication bus provided by the embodiment of the present application can realize redundant processing of flight control by setting at least two computing processing circuits, ensure that data processing is still performed by other computing processing circuits not having faults when a fault occurs in a certain computing processing circuit, keep the flight control system continuously operating normally, and thus improve flight management reliability. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments of the present application will be briefly introduced. Those skilled in the art can obtain other drawings according to these drawings without any creative effort.
[0018] Figure 1 A structure schematic diagram of the redundant flight control system based on a multi-path communication bus provided by the embodiment of the present application;
[0019] Figure 2 A circuit structure schematic diagram provided by the embodiment of the present application;
[0020] Figure 3 A pin connection relationship schematic diagram of each CPU provided by the embodiment of the present application;
[0021] Figure 4 A channel identification method schematic diagram provided by the embodiment of the present application;
[0022] Figure 5 A local CPU validity judgment logic schematic diagram provided by the embodiment of the present application;
[0023] Figure 6 A channel voting fault determination logic diagram provided for the embodiment of the present application is shown in FIG. 4.
[0024] Figure 7 A fault logic output diagram provided for the embodiment of the present application is shown in FIG. 5.
[0025] Figure 8 A fault clearing logic diagram provided for the embodiment of the present application is shown in FIG. 6.
[0026] Figure 9 A fault channel removal logic diagram provided for the embodiment of the present application is shown in FIG. 7.
[0027] Figure 10 A flow diagram of a fault processing method provided for the embodiment of the present application is shown in FIG. 8.
[0028] Figure 11 A hardware structure diagram of an electronic device provided for the embodiment of the present application is shown in FIG. 9. DETAILED DESCRIPTION
[0029] The features and exemplary embodiments of various aspects of the present application will be described in detail below with reference to the drawings. The following detailed description is merely intended to explain the present application, and is not intended to limit the present application. The present application can be implemented without some of the specific details, which will be apparent to those skilled in the art. The following description of the embodiments is merely intended to provide a better understanding of the present application by showing examples of the present application.
[0030] It should be noted that, in this document, the terms such as first and second are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. Also, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such a process, method, article or device. Without more limitations, the elements defined by the statement "include" do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0031] With the development of aviation technology, modern aircraft puts forward higher and higher requirements for the safety and reliability of the flight tube computer (i.e. flight management computer). As the core control device of the aircraft, the flight tube computer is directly responsible for the attitude control, flight parameter calculation and emergency state processing of the aircraft. Therefore, ensuring the robustness and reliability of the flight tube computer is crucial to flight safety.
[0032] Traditional flight tube computers mostly adopt single-redundancy or double-redundancy design, which improves the fault tolerance of the system to a certain extent, but in complex flight environment or severe weather conditions, single-redundancy or double-redundancy system may not fully meet the high reliability requirements. Especially during flight, uncertain factors such as electromagnetic interference, temperature change and mechanical vibration faced by the system may cause the control system to fail, thereby posing a serious threat to flight safety. Specifically, the traditional single-redundancy design completely fails in the case of single-point failure, and the double-redundancy design also has limitations in dealing with multiple failures, which cannot meet the high safety requirements. On this basis, if the redundancy design is continued to increase, it may be difficult to synchronize data, which may lead to inconsistent data and affect the accuracy and real-time performance of control commands. In summary, the traditional flight tube computer has insufficient fault tolerance, cannot cope with multiple failures, has limited fault isolation capability, and may cause fault propagation to affect the overall system. At the same time, the anti-electromagnetic interference capability is weak, and errors or signal loss may occur during data transmission, affecting control accuracy. Moreover, there is no automatic fault detection and switching mechanism, and fault recovery relies on manual operation, which is difficult to meet the real-time response requirements during flight.
[0033] To solve the above problems, the embodiments of the present application provide a multi-redundancy flight control system based on a multi-channel communication bus and an aircraft, which aims to realize redundant processing of flight control through multiple independent computing units, ensure that the system can continue to operate normally when some units fail, and greatly improve the safety and reliability of the flight management computer.
[0034] Firstly, the multi-redundancy flight control system based on a multi-channel communication bus provided by the embodiments of the present application will be introduced.
[0035] Figure 1 The structure diagram of the multi-redundancy flight control system based on a multi-channel communication bus provided by the embodiments of the present application is shown in Figure 1 The multi-redundancy flight control system 10 includes a first interface processing circuit 110, a second interface processing circuit 111, at least two computing processing circuits 12 and a communication bus, and each computing processing circuit is connected with the interface processing circuit through a communication bus.
[0036] In the embodiment, the redundancy refers to a plurality of redundant computing processing circuits, each of which can be directly responsible for attitude control of the aircraft, flight parameter calculation and emergency state processing. When one of the computing processing circuits fails, another normal computing processing circuit can be switched to continue the attitude control of the aircraft, flight parameter calculation and emergency state processing, and the failed computing processing circuit is isolated.
[0037] In the embodiment, the first interface processing circuit 110 can be used to obtain the to-be-processed data of the input device and store the data in the data buffer. The input device can be a sensor in the aircraft, such as a radar sensor, an attitude sensor, a camera, etc.
[0038] The to-be-processed data can be one or more of serial signals and discrete signals. The first interface processing circuit 110 can include a discrete quantity input interface and a serial input interface. Based on the serial input interface, the first interface processing circuit 110 can store the required serial signals in the data buffer in real time through the microcontroller thereon. Based on the discrete quantity input interface, the first interface processing circuit 110 can store the required discrete signals in the data buffer in real time through the microcontroller thereon.
[0039] The first interface processing circuit 110 can transmit the data in the buffer to the computing processing circuit 12 for calculation through the communication bus, and store the calculation result in the data buffer. The communication bus transmits the data in the buffer to the interface processing circuit 111, and the interface processing circuit 111 converts the digital quantity of the calculation result into corresponding I / O quantity under the control of the microcontroller and outputs the I / O quantity through the output device. The output device can be a rudder of the aircraft.
[0040] In the embodiment, each computing processing circuit is redundantly designed. When one of the computing processing circuits fails, the interface processing circuit can cut off the data interaction between the computing processing circuit and the data buffer, thereby isolating the failed computing processing circuit. Meanwhile, another computing processing circuit without failure can be started and continue data processing.
[0041] Further, in some embodiments, Figure 2 The circuit structure schematic diagram provided by the embodiment of the application is shown in FIG. 1. Figure 2 As shown in FIG. 1, a backboard combined with a functional board is adopted, the backboard is provided with a communication bus, and the functional board includes a computing processing circuit and an interface processing circuit. Figure 2 Taking three computing processing circuits as an example, the first computing processing circuit includes a CPU board card A, the second computing processing circuit includes a CPU board card B, and the third computing processing circuit includes a CPU board card C.
[0042] The interface processing circuit can include a plurality of multi-function input / output (MIO) cards, each of which is connected to a different interface, for example, in Figure 2 each MIO card is connected to a first interface and a second interface, wherein the first interface can be any one of a serial input interface and a discrete quantity input interface, and the second interface can be an interface other than the serial input interface and the discrete quantity input interface, for example, a Fieldbus Terminal Interface (FTI) for realizing data interaction between an industrial Fieldbus and the MIO card.
[0043] Each CPU card can be connected to the communication bus, and then obtain the data to be processed through the MIO card connected to the communication bus. After the CPU card completes the calculation and processing of the data to be processed, the data processing result can be fed back to the MIO card through the communication bus.
[0044] For example, the communication bus on the backplane can be an ARINC659 bus. The ARINC659 bus on the backplane is physically composed of four sets of buses, Ax, Ay, Bx, and By, each set of bus including an independent clock line and two data lines. The four sets of buses use a double-redundancy monitoring method, and have the ability of fault tolerance and fault isolation.
[0045] The ARINC659 bus has high reliability, high fault tolerance, high bandwidth, strong anti-interference ability, and fault tolerance characteristics, and can realize high-speed data transmission and fault isolation in a multi-redundancy system. By using the ARINC659 bus, the reliability and real-time performance of the system can be greatly improved.
[0046] Referring back to the above Figure 2 each CPU card can be used as a separate computing unit and run independently, and the CPU card and the MIO card can be connected to the ARINC659 bus in a resource manner to realize data interaction and communication between the CPU and the MIO card. The power supply circuit is used to provide power supply for the CPU card and the MIO card and driving power for the ARINC659 bus.
[0047] Referring back to the above Figure 2 The data processing results of each computing processing circuit of the flight tube computer are transmitted through the communication bus on the backplane, and the interface processing circuit can cross-compare and arbitrate the data processing results of each computing processing circuit and then output.
[0048] Specifically, the interface processing circuit can detect the data processing results of the respective computing processing circuits, generate a detection result, and then isolate a target data processing result and other data processing results other than the target data processing result from the respective data processing results according to the detection result.
[0049] The detection result is used to represent whether the data processing results of the respective computing processing circuits are the same, and the target data processing result is a data processing result that is different from the other data processing results.
[0050] For example, the data processing result of the first computing processing circuit is D1, the data processing result of the second computing processing circuit is D2, and the data processing result of the third computing processing circuit is D1. The detection result represents that there is a case where the data processing results are not the same. The data processing result D2 of the second computing processing circuit is the target data processing result. The data processing results of the first computing processing circuit and the second computing processing circuit are the other data processing results.
[0051] By isolating the data processing results, the reliability of data transmission can be ensured by effectively detecting and isolating error data through the fault-tolerant feature of the ARINC659 bus.
[0052] In addition, each computing processing circuit can not only execute a flight control algorithm, but also has a fault detection and automatic switching function, so that when a fault occurs, the redundant flight control system can automatically isolate the faulty fault unit and switch to the backup other computing processing circuit to maintain normal operation of the system.
[0053] In the embodiments of the present application, by introducing a three-redundancy architecture and combining the high-speed and fault-tolerant features of the ARINC659 communication bus, redundant processing and transmission of flight control data are realized. The multi-redundancy flight control system adopts three independent computing units, each of which exchanges data through the ARINC659 bus to ensure that the system can still operate normally even if some computing units fail, thereby ensuring flight safety.
[0054] Optionally, in some embodiments, the multi-redundancy flight control system can include three independent computing processing circuits, i.e., a first computing processing circuit, a second computing processing circuit, and a third computing processing circuit. The first computing processing circuit includes a first CPU, the second computing processing circuit includes a second CPU, and the third computing processing circuit includes a third CPU.
[0055] The first output pin of the first CPU is connected to the first input pin of the second CPU, and the second output pin of the first CPU is connected to the first input pin of the third CPU in the third computing processing circuit.
[0056] wherein the first output pin of the second CPU is connected with the first input pin of the first CPU, and the second output pin of the second CPU is connected with the second input pin of the third CPU;
[0057] wherein the first output pin of the third CPU is connected with the second input pin of the first CPU, and the second output pin of the third CPU is connected with the second input pin of the second CPU.
[0058] Specifically, Figure 3 The pin connection relationship of each CPU provided by the embodiment of the present application is shown in the following table: Figure 3 As shown in the table, the first output pin of the first CPU can refer to DPV_TX and CHV_TX on the first CPU, the second output pin of the first CPU can refer to DPV_TY and CHV_TY on the first CPU, the first input pin of the first CPU can refer to DPV_FX and CHV_FX on the first CPU, and the second input pin of the first CPU can refer to DPV_FY and CHV_FY on the first CPU.
[0059] The first output pin of the second CPU can refer to DPV_TY and CHV_TY on the second CPU, the second output pin of the second CPU can refer to DPV_TX and CHV_TX on the second CPU, the first input pin of the second CPU can refer to DPV_FY and CHV_FY on the second CPU, and the second input pin of the second CPU can refer to DPV_FX and CHV_FX on the first CPU.
[0060] The first output pin of the third CPU can refer to DPV_TX and CHV_TX on the third CPU, the second output pin of the third CPU can refer to DPV_TY and CHV_TY on the third CPU, the first input pin of the third CPU can refer to DPV_FX and CHV_FX on the third CPU, and the second input pin of the third CPU can refer to DPV_FY and CHV_FY on the third CPU.
[0061] Continuing to refer to the above Figure 3 , each CPU board solves the channel fault logic through DPV and CHV signals. Specifically, DPV_TX, DPV_TY, DPV_FX and DPV_FY can be used to output data valid signals, which are used to indicate whether the data output by a certain CPU board is valid. CHV_TX, CHV_TY, CHV_FX and CHV_FY can be used to output channel valid signals, which are used to indicate whether the channel of a certain CPU board is in a normal working state.
[0062] In addition, in Figure 3In the circuit, the power board communicates with the CPU board via three hardwired signals, providing three different power states: 28V, 15V, and 5V. Additionally, in the event of a fault in a computing circuit, the CPU can send a CUT signal (including...) Figure 3 The CUT_MIO1_A, CUT_MIO2_A, CUT_MIO3_A, CUT_MIO1_B, CUT_MIO2_B, CUT_MIO3_B, CUT_MIO1_C, CUT_MIO2_C, and CUT_MIO3_C signals are sent to the three MIO boards in a discrete signal manner. After receiving the CUT signal from the MIO board, the interface processing circuit can isolate the faulty computing processing circuit.
[0063] In this embodiment, to achieve automatic fault detection and automatic isolation of the faulty computing circuit, fault determination is required through relevant fault logic. This fault logic needs to identify and isolate faulty channels, while referencing the judgments of other channels regarding this channel during isolation. Furthermore, the fault logic needs to preserve the availability of the VMC as much as possible, support single-channel operation, and prevent transients and erroneous channel disconnection caused by channel removal.
[0064] In addition, an effective data interaction method needs to be established. Specifically, the data interaction link between each computing processing circuit and the interface processing circuit via the communication bus is regarded as a channel, and each computing processing circuit corresponds to a channel. Each channel needs to know the decision status of other channels regarding its own channel, and also needs to know the fault status of other channels. Finally, it outputs the fault status of its own channel, and after comprehensive judgment, the faulty channel is disconnected to avoid the wrong disconnection of channels due to single point of failure.
[0065] In some embodiments, taking a redundant flight control system including three computing processing circuits as an example, three channels, A, B, and C, can be set up. For example, Figure 4 This is a schematic diagram of the channel identification method provided in the embodiments of this application, such as... Figure 4 As shown, the three channels A, B, and C are arranged clockwise. The adjacent channel clockwise for each channel is defined as the X channel, and the corresponding adjacent channel counter-clockwise is defined as the Y channel. That is, for channel A, channel B is the X channel and channel C is the Y channel; for channel B, channel C is the X channel and channel A is the Y channel; and for channel C, channel A is the X channel and channel B is the Y channel.
[0066] When no failure occurs, the three channels of the flight tube computer work in parallel and synchronously, and the validity of each channel is determined by majority voting. Each channel informs the other channels of the current channel working state through CHV_TX or CHV_TY signals, so as to avoid invalidation of the flight tube computer caused by simultaneous cutting of the three channels. At the same time, the X processor state in the current channel validity information is informed to the X channel through DPV_TX, and the Y processor state in the current channel validity information is informed to the Y channel through DPV_TY, so as to avoid false cutting caused by single-channel judgment failure.
[0067] After realizing the data interaction between the channels, the following describes how to set the related failure logic for failure determination through some embodiments.
[0068] In some embodiments, each computing processing circuit can further be provided with a power supply circuit and a timer circuit, both of which are connected with the CPU in the computing processing circuit.
[0069] The CPU in each computing processing circuit is configured to generate a first output signal according to the power supply signal of the power supply circuit, the timing signal of the timer circuit and the validity signal of the CPU. The first output signal can be a high-level signal or a low-level signal, and the high / low level represents whether the computing processing circuit has a failure.
[0070] For example, Figure 5 The local CPU validity judgment logic provided by the embodiments of the present application is shown in FIG. 1. Figure 5 As shown in FIG. 1, the failure logic comprehensively considers the local CPU validity signal, the local 5-volt power supply signal (i.e., the power supply signal of the power supply circuit) and the timing signal of the timer circuit to obtain the local validity signal result.
[0071] When all the three signals are 1 (1 represents high level and 0 represents low level), the first output signal is valid. When any one of the three signals is 0, the first output signal is 0 (low level signal), which represents that the computing processing circuit has a failure.
[0072] In this embodiment, the timer circuit can refer to a watchdog timer (WDT). The timing signal can be the signal generated by the watchdog timer, which can be used to monitor whether the CPU is stuck or unresponsive for a long time. Specifically, the watchdog timer starts counting at a preset time interval (e.g., 1 second). When the CPU is running normally, the CPU will periodically (before the counter overflows) reset the watchdog timer to start counting again. If the CPU fails to reset the watchdog timer in time due to a fault (such as program freeze, unhandled interrupt, etc.), the counter will overflow, thereby triggering the watchdog signal to change from 1 to 0. That is, when the CPU fails to reset the watchdog timer in time due to a fault (such as program freeze, unhandled interrupt, etc.), the timing signal is 0, and when the CPU can reset the watchdog timer in time, the timing signal is 1.
[0073] In this embodiment, when the local 5V power supply signal is 1, it indicates that the power supply circuit can normally supply power to the CPU, while when the local 5V power supply signal is 0, it indicates that the power supply circuit cannot normally supply power to the CPU.
[0074] In addition, referring to the above Figure 5 ,exist Figure 5 The system employs an AND logic gate circuit. Specifically, the local CPU valid signal, the local 5V power supply signal, and the timer signal from the timer circuit are all 1. After these three signals are input to the AND logic gate, the gate outputs a first output signal of 1 (where 1 represents a high level and 0 represents a low level). A first output signal of 1 indicates that the current computing and processing circuit is functioning correctly, while a first output signal of 0 indicates that the current computing and processing circuit is faulty. In other embodiments, other logic gate circuits may be used, which will not be detailed here.
[0075] In this embodiment, by combining the local CPU valid signal, the local 5V power supply signal, and the timing signal of the timer circuit, it is possible to determine whether the CPU itself has malfunctioned. This allows for real-time detection of whether the computing and processing circuit itself has malfunctioned, thus improving the real-time performance of fault detection.
[0076] Optionally, in some embodiments, each computing processing circuit can also perform fault logic judgment based on the validity judgment results of the current channel from other channels. Specifically, each computing processing circuit includes a CPU reset circuit, which is connected to the CPU in the computing processing circuit.
[0077] In addition, please continue to refer to the above. Figure 3The CPU in each computing processing circuit is connected with each other through input pins and output pins, so that the CPU in a certain computing processing circuit can obtain the fault judgment signal of the CPU in other computing processing circuit. The fault judgment signal is obtained by the CPU in other computing processing circuit judging the fault of the CPU in the computing processing circuit.
[0078] Taking the above Figure 3 For example, assuming that the second CPU and the third CPU both judge that the first CPU is faulty, the second CPU can output the fault judgment signal to the first CPU through the DPV_TX and CHV_TX pins of the second CPU. Similarly, the third CPU can also output the fault judgment signal to the first CPU through the DPV_TX and CHV_TX pins of the third CPU.
[0079] Taking the first CPU as the CPU in a certain computing processing circuit and the second CPU and the third CPU as the CPUs in other computing processing circuits as an example, the first CPU can obtain the reset signal of the CPU reset circuit connected to the first CPU, and then generate a second output signal based on the fault judgment signals sent by the second CPU and the third CPU and the reset signal.
[0080] The second output signal is used to represent whether the computing processing circuit is faulty. For example, when the second output signal is high, it indicates that the computing processing circuit where the first CPU is located is not faulty, and when the second output signal is low, it indicates that the computing processing circuit where the first CPU is located is faulty.
[0081] Specifically, taking the first CPU as the CPU in a certain computing processing circuit and the second CPU and the third CPU as the CPUs in other computing processing circuits as an example, Figure 6 The channel voting fault judgment logic diagram provided by the embodiment of the present application is shown in FIG. 1, or the input of the logic gate includes the first fault judgment signal DPV_FX, the second fault judgment signal DPV_FY and the reset signal CPU_RESET, and the output of the logic gate is the second output signal. Figure 6
[0082] The first fault judgment signal can be the fault judgment signal sent by the second CPU mentioned above, and the second fault judgment signal can be the fault judgment signal sent by the third CPU mentioned above.
[0083] When the first fault judgment signal DPV_FX or the second fault judgment signal DPV_FY is valid, it means that the other channel considers the current channel to be valid. Only when the X channel and the Y channel consider the current channel to be faulty at the same time, it means that the other channel considers the current channel to be faulty.
[0084] Meanwhile, when the first CPU is in the process of resetting, the CPU reset circuit outputs a high level signal for a period of time (for example, 400 milliseconds) as a reset signal, at this time, the reset signal is 1, and after the reset is completed, the reset circuit outputs a low level signal as a reset signal, at this time, the reset signal is 0.
[0085] In addition, in some embodiments, in the process of resetting, the first CPU ignores the judgment of other channels on the validity of the current channel, and after the current channel returns to the normal working state and can output normal working signals, the judgment of the validity of other channels is used. In this way, during the period when the current channel is reset and has not yet reached a stable working state, other channels do not obtain valid data, and the working state of the current channel is incorrectly determined.
[0086] Continuing to refer to the above Figure 6 When the first fault discrimination signal DPV_FX is valid, it means that the first fault discrimination signal is 1, and if the first fault discrimination signal DPV_FX is invalid, it means that the first fault discrimination signal is 0. Similarly, when the second fault discrimination signal DPV_FY is valid, it means that the second fault discrimination signal is 1, and if the second fault discrimination signal DPV_FX is invalid, it means that the second fault discrimination signal is 0.
[0087] Among them, when the first fault discrimination signal is 1 or the second fault discrimination signal is 1 or the reset signal is 1, the second output signal is 1 after passing through the or logic gate circuit, at this time, it means that the computing processing circuit has not failed. If the first fault discrimination signal is 0, the second fault discrimination signal is 0, and the reset signal is 0, the second output signal is 0 after passing through the or logic gate circuit, at this time, it means that the computing processing circuit has failed.
[0088] In other embodiments, other logic gate circuits can also be used to replace the above or logic gate circuit, which will not be described in detail one by one.
[0089] In this embodiment, by using the fault discrimination signals of other channels, the computing processing circuit can judge whether it has failed, improve the accuracy of fault discrimination, and ensure the stability and reliability of the redundant flight control system.
[0090] In addition, in some embodiments, after obtaining the first output signal and the second output signal, a latch signal can also be generated based on the first output signal and the second output signal to inform other computing processing circuits, so that other computing processing circuits can obtain whether the current computing processing circuit has failed.
[0091] Specifically, a latch can be set in each computing processing circuit, and the latch is connected to the CPU in the computing processing circuit. The CPU in the computing processing circuit is used to output a first output signal and a second output signal to the latch; the latch is used to output a latch signal to the interface processing circuit according to the first output signal and the second output signal.
[0092] The latch signal is used to characterize whether a fault has occurred in the computational processing circuit.
[0093] In this embodiment, if the current computing circuit determines that it has malfunctioned, or if other computing circuits determine that the current computing circuit has malfunctioned, a fault signal needs to be generated. This signal is then latched by a latch and sent to other computing circuits via relevant pins. The latch's function is to preserve the fault state and prevent the circuit from switching between fault and normal states.
[0094] The following detailed explanation is provided in conjunction with the accompanying drawings. Figure 7 A schematic diagram of the fault logic output provided in the embodiments of this application is shown below. Figure 7 As shown above, Figure 3 Taking the three computing circuits shown as an example, if a certain computing circuit corresponds to the current channel, and the current channel itself believes that a fault has occurred, or if the other two channels simultaneously believe that the current channel has failed, then the current channel is considered to be faulty. The generated fault signal is latched by a latch and then sent to the X channel and Y channel (i.e., the other two channels) through the CHV_TX and CHV_TY pins on the CPU.
[0095] Refer to the above Figure 7 When the current channel itself considers a fault to have occurred, the first output signal is 0. In addition, if the other two channels simultaneously consider the current channel to have failed, the second output signal is 0. The first and second output signals are used as inputs to the AND logic gate circuit. At this time, the AND logic gate outputs a fault signal, which indicates that the current channel is faulty.
[0096] Furthermore, if both the first output signal and the second output signal are 1, then the AND gate outputs a normal signal, indicating that no fault has occurred in the current channel. In some other embodiments, other logic gates can be used to replace the above-mentioned AND gates, which will not be described in detail here.
[0097] In this embodiment, by outputting a fault signal through a latch, other channels can identify that the current channel has a fault. At the same time, setting the latch to store the current fault state can avoid the back-and-forth switching between fault and normal states, thereby improving the reliability of fault detection.
[0098] Furthermore, in some embodiments, the latch can also be connected to the aforementioned CPU reset circuit. The latch can update the latch signal based on the first output signal, the second output signal, and the reset signal output by the CPU reset circuit.
[0099] In this embodiment, when a fault occurs in the computing processing circuit, the CPU in the current computing processing circuit can be reset by the CPU reset circuit to perform fault self-repair. Specifically, when a fault signal is latched in the latch, the CPU reset circuit outputs a reset signal of 1, which can update the state of the latch so that the latch no longer outputs a fault signal and instead outputs a normal signal.
[0100] The following detailed explanation is provided in conjunction with the accompanying drawings. Figure 8 This is a schematic diagram of the fault clearing logic provided in the embodiments of this application, such as... Figure 8 As shown, the CPU_RESET signal generated by the CPU reset circuit from the hardware can clear the channel fault state in the latch, allowing the latch to output a normal signal. The duration of the CPU_RESET signal can be 400 milliseconds.
[0101] In addition, in some embodiments, besides triggering the CPU reset circuit to generate the CPU_RESET signal through hardware, users can also manually reset the CPU through software, such as by clicking the shutdown button in the operating system to manually reset the CPU.
[0102] At this point, continue to refer to the above. Figure 8 The software reset signal FR and the CPU_RESET signal generated by the hardware CPU reset circuit can be used as inputs to an OR logic gate. That is, when either the software reset signal FR or the hardware CPU reset signal CPU_RESET is valid (i.e., has a value of 1), the OR logic gate outputs a signal with a value of 1 to update the channel fault state in the latch, that is, to update the fault signal with a value of 0 to a normal signal with a value of 1.
[0103] Furthermore, Figure 9 This is a schematic diagram of the fault channel removal logic provided in the embodiments of this application, such as... Figure 9As shown, whether the current channel is faulty is represented by the latch signal, and whether the other channels are faulty is represented by the CHV_FX signal and the CHV_FY signal. If the current is a three-channel normal working state, if only the current channel is faulty, the latch signal is output through an or logic gate circuit to output a third output signal, driving the CPU of the current channel to send a cut-off instruction, and the ARINC659 transmission enable signal of the CPU board of the current channel is cut off to realize the cut-off of the data of the current channel. If the current is in a two-channel working state, one channel is in a faulty state, and the two-channel or three-channel fault signal is valid (represented by the number 1). The first output signal is output to isolate the fault by monitoring the local watchdog of the current channel, the power supply, and the bus communication. If the current working state of the current channel is normal, that is, the first output signal is valid, then the single-channel working mode is entered, and the OLC signal is invalid. No data cut-off of the current channel is performed.
[0104] The embodiment of the present application adopts the ARINC659 bus and three processing circuits to form a three-redundancy design, improves the reliability, fault tolerance, data transmission efficiency and anti-interference of the system, and has automatic fault detection and switching capability, and meets the high safety requirement in a complex flight environment.
[0105] Figure 10 A flowchart of a fault processing method provided by the embodiment of the present application is shown in the figure. The method can be applied to the above-mentioned multi-redundancy flight control system, and the multi-redundancy flight control system includes at least two computing processing circuits, a communication bus and an interface processing circuit. As shown in the figure, the method includes the following steps: Figure 10
[0106] Step S1010: acquiring the to-be-processed data and storing the to-be-processed data in a data buffer;
[0107] Step S1020: in the case where the computing processing circuit is not faulty, acquiring the to-be-processed data from the data buffer for processing to obtain a data processing result, and storing the data processing result in the data buffer;
[0108] Step S1030: in the case where the computing processing circuit is faulty, cutting off the data interaction between the computing processing circuit and the data buffer.
[0109] In the embodiment, the flight control system can be a core control device in an aircraft, and the multi-redundancy flight control system, that is, multiple independent flight control systems, can be directly responsible for the attitude control of the aircraft, the flight parameter calculation and the emergency state processing.
[0110] Each flight control system includes at least one computing processing circuit. This circuit may contain a CPU to perform flight parameter calculations and emergency response. If a computing processing circuit in one flight control system malfunctions, the system can switch to another functioning flight control system to continue attitude control, flight parameter calculations, and emergency response.
[0111] In this embodiment, the computing processing circuit can communicate with the interface processing circuit via a communication bus to achieve data interaction. The communication bus can be an ARINC659 bus.
[0112] For example, redundancy can refer to triple redundancy, which means three independent flight control systems. A triple-redundant flight control computer system based on the ARINC659 bus aims to achieve redundant processing of flight control through three independent computing circuits, ensuring that the system can continue to operate normally even when some units fail, thereby greatly improving the safety and reliability of the flight management computer.
[0113] Figure 11 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. This electronic device can be equipped with the aforementioned redundant flight control system; for example, the electronic device can be an aircraft. Figure 11 As shown, the electronic device may include a processor 1101 and a memory 1102 storing computer program instructions.
[0114] Specifically, the processor 1101 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0115] Memory 1102 may include mass storage for data or instructions. For example, and not limitingly, memory 1102 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 1102 may include removable or non-removable (or fixed) media. Where appropriate, memory 1102 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 1102 is non-volatile solid-state memory.
[0116] In specific embodiments, the memory 1102 can be realized in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1102 can store an operating system and other application programs. When the technical solutions provided by the embodiments of the present specification are implemented by software or firmware, the related program codes are stored in the memory 1102 and are called and executed by the processor 1101. The processor 1101 reads and executes the computer program instructions stored in the memory 1102 to implement any method steps in the above embodiments.
[0117] In one example, the electronic device can further include a communication interface 1103 and a bus 1110. As shown, the processor 1101, the memory 1102, and the communication interface 1103 are connected through the bus 1110 and complete communication with each other. Figure 11
[0118] The communication interface 1103 is mainly used to realize the communication between the modules, devices, units and / or equipment in the embodiments of the present application.
[0119] The bus 1110 includes hardware, software or both to couple components of the online data traffic billing device to each other. By way of example, and not limitation, the bus can include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand (IB) interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association local (VLB) bus, or another suitable bus or a combination of two or more of these. Where appropriate, the bus 1110 can include one or more buses. Although the present application describes and illustrates a particular bus, the present application contemplates any suitable bus or interconnect.
[0120] In addition, in combination with the method in the above embodiments, the embodiments of the present application can provide a computer storage medium to realize. The computer storage medium has computer program instructions stored thereon; the computer program instructions are executed by the processor to implement any method steps in the above embodiments.
[0121] The computer readable medium of the embodiments can include permanent and non-permanent, removable and non-removable media, which can be implemented by any method or technology to store information. The information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage device, or any other non-transmission medium that can be used to store information accessible by a computing device.
[0122] The storage medium of the above embodiments stores computer instructions for causing a computer to execute the method steps provided by any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which are not described here again.
[0123] The embodiments of the present application also provide a computer program product, which includes a computer program, and the computer program is processed to implement the method steps provided by any of the above embodiments when executed.
[0124] It should be clear that the present application is not limited to the specific configurations and processes described above and shown in the drawings. For the sake of brevity, detailed descriptions of well-known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between steps, after understanding the spirit of the present application.
[0125] The functional blocks shown in the above structural block diagram can be implemented as hardware, software, firmware or their combination. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, etc. When implemented in software, the elements of the present application are program or code segments used to perform the required tasks. The program or code segments can be stored in a machine readable medium or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. The "machine readable medium" can include any medium capable of storing or transmitting information. Examples of machine readable medium include electronic circuit, semiconductor memory device, ROM, flash memory, erasable ROM (EROM), floppy disk, CD-ROM, optical disk, hard disk, optical fiber medium, radio frequency (RF) link, etc. The code segments can be downloaded via a computer network such as the Internet, intranet, etc.
[0126] It should also be noted that the example embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiments, or in an order different from the embodiments, or several steps can be performed simultaneously.
[0127] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other processing device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other processing device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer program instructions can also be stored in a computer readable medium that can direct a computer, other programmable data processing apparatus, or other processing device to operate in a particular manner, such that the computer readable medium having instructions stored therein comprises an article of manufacture including a computer program of instructions which implement the function / act specified in the flowchart and / or block diagram block or blocks.
[0128] The above is merely specific implementation of the present application, and those skilled in the art can clearly understand the specific working process of the system, module and unit described above for the convenience and brevity of description, which can refer to the corresponding process in the foregoing method embodiments, and will not be described here. It should be understood that the protection scope of the present application is not limited to this, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed in the present application, and these modifications or replacements should be covered within the protection scope of the present application.
Claims
1. A redundant flight control system based on a multi-channel communication bus, characterized in that, The system includes: a communication bus, an interface processing circuit, and at least two computing processing circuits, each computing processing circuit being connected to the interface processing circuit via the communication bus; The interface processing circuit is used to acquire the data to be processed and store it in the data buffer; The computing processing circuit is used to obtain data to be processed from the data buffer through the communication bus when no fault occurs, process the data to be processed to obtain data processing results, and store the data processing results in the data buffer through the communication bus. The computing processing circuit is also used to output a fault signal to the interface processing circuit in the event of a fault. The interface processing circuit is also used to cut off the data interaction between the computing processing circuit and the data buffer when a fault is detected in the computing processing circuit.
2. The system according to claim 1, characterized in that, The interface processing circuit is also used for: The data processing results of each computing processing circuit are detected, and the detection results are obtained. The detection results are used to characterize whether the data processing results of each computing processing circuit are the same. Based on the detection results, the target data processing result and other data processing results are isolated from each data processing result. The target data processing result is a data processing result that is different from the other data processing results.
3. The system according to claim 1 or 2, characterized in that, The communication bus is the ARINC659 communication bus.
4. The system according to claim 1, characterized in that, The at least two computing processing circuits include a first computing processing circuit, a second computing processing circuit, and a third computing processing circuit. The first computing processing circuit includes a first CPU, the second computing processing circuit includes a second CPU, and the third computing processing circuit includes a third CPU. The first output pin of the first CPU is connected to the first input pin of the second CPU, and the second output pin of the first CPU is connected to the first input pin of the third CPU in the third computing circuit. The first output pin of the second CPU is connected to the first input pin of the first CPU, and the second output pin of the second CPU is connected to the second input pin of the third CPU. The first output pin of the third CPU is connected to the second input pin of the first CPU, and the second output pin of the third CPU is connected to the second input pin of the second CPU.
5. The system according to claim 4, characterized in that, The computing processing circuit also includes a power supply circuit and a timer circuit, both of which are connected to the CPU in the computing processing circuit. The CPU in the computing processing circuit is used to generate a first output signal based on the power supply signal of the power supply circuit, the timing signal of the timer circuit, and the effective signal of the CPU. The first output signal is used to characterize whether there is a fault in the computing processing circuit.
6. The system according to claim 4, characterized in that, The computing processing circuit also includes a CPU reset circuit, which is connected to the CPU in the computing processing circuit. The CPU in the computing processing circuit is also used to acquire a fault discrimination signal and generate a second output signal based on the fault discrimination signal and the reset signal of the CPU reset circuit. The fault discrimination signal is obtained by performing fault discrimination on the CPU in the computing processing circuit other than the computing processing circuit. The second output signal is used to characterize whether the computing processing circuit has failed.
7. The system according to claim 5 or 6, characterized in that, The computing processing circuit also includes a latch, which is connected to the CPU in the computing processing circuit; The CPU in the computing processing circuit is also used to output a first output signal and a second output signal to the latch; The latch is used to output a latch signal to the interface processing circuit based on the first output signal and the second output signal. The latch signal is used to characterize whether the computing processing circuit has malfunctioned.
8. The system according to claim 7, characterized in that, The latch is connected to the CPU reset circuit. The latch is also used to update the latch signal according to the reset signal output by the CPU reset circuit.
9. A fault handling method, characterized in that, An application to a redundancy flight control system, the redundancy flight control system comprising at least two computational processing circuits, a communication bus, and an interface processing circuit, wherein each computational processing circuit is connected to the interface processing circuit via the communication bus, the method comprising: Acquire the data to be processed and store it in the data buffer; If the computing processing circuit does not malfunction, the data to be processed is obtained from the data buffer, processed to obtain the data processing result, and the data processing result is stored in the data buffer. In the event of a failure in the computing processing circuit, the data interaction between the computing processing circuit and the data buffer is cut off.
10. An electronic device, characterized in that, The redundant flight control system includes any one of claims 1-8.