An aircraft digital emergency backup control system

By using heterogeneous architecture and multi-source sensor data fusion technology, combined with standard semantic description and dynamic simulation, safety attributes are verified in real time, solving common fault risks and intelligent decision-making problems in the emergency backup control system of aircraft, and achieving high reliability and cross-system collaborative control.

CN121455218BActive Publication Date: 2026-07-31AVIC SHAANXI DONGFANG AVIATION INSTR
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
AVIC SHAANXI DONGFANG AVIATION INSTR
Filing Date
2025-11-21
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing aircraft emergency backup control systems suffer from common failure risks due to homogeneous redundancy design, insufficient intelligent decision-making capabilities of traditional switching mechanisms, and a lack of systematic and reliable verification mechanisms, making it difficult to ensure the consistency of system behavior and the reliability of output in cross-system collaborative scenarios.

Method used

By employing a heterogeneous architecture and multi-source sensor data fusion technology, the system evaluates the differences in system behavior through standard semantic description and dynamic simulation, verifies security attributes in real time using time-series logic formulas, generates a credibility proof, and achieves cross-system intelligent mutual recognition through policy matching.

Benefits of technology

It enables reliable coordination and switching between primary and backup systems, improves the system's adaptability, intelligence, and coordination, and ensures the safe control capability of the aircraft.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121455218B_ABST
    Figure CN121455218B_ABST
Patent Text Reader

Abstract

This application discloses a digital emergency backup control system for aircraft, relating to the field of unmanned aerial vehicle technology, including: acquiring multi-source sensor data and constructing an actuator characteristic database; converting unified control commands into drive signals for specific actuators to achieve switching between primary and backup systems; converting drive signals into standard semantic descriptions, simulating the standard semantic descriptions using a dynamic model, evaluating behavioral differences between different systems, and generating a consistency verification report; performing parameter calibration based on the verification report; converting airspace rules, safety constraints, and mission objectives into verifiable temporal logic formulas, verifying the satisfaction of safety attributes in real time during system operation, and generating credibility proofs for verified safety attributes; and standardizing the credibility proofs into a mutually recognized format through aviation credibility proofs to achieve cross-system credibility mutual recognition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of unmanned aerial vehicle technology, and in particular to a digital emergency backup control system for aircraft. Background Technology

[0002] With the rapid development of unmanned aerial vehicle (UAV) technology, the reliability and safety requirements of flight control systems are increasing. Modern avionics systems typically employ multiple flight control systems in a redundant architecture to improve system reliability. However, existing multi-system backup schemes still face several technical bottlenecks and limitations in practical applications.

[0003] Currently, mainstream aircraft emergency backup control systems primarily employ the following technical solutions: firstly, system backup is achieved through hardware redundancy; secondly, fault monitoring is performed using a heartbeat detection mechanism; and finally, system switching is conducted through simple majority voting or preset threshold values. While these traditional solutions improve system reliability to some extent, they have significant shortcomings. Existing solutions often employ homogeneous redundancy designs, with each backup system having completely identical hardware and software architectures. Although this design simplifies system development, it cannot effectively address common fault problems. When encountering common faults caused by design flaws or environmental factors, multiple backup systems may fail simultaneously, seriously threatening flight safety. Traditional methods mainly rely on hardware and software reliability design, lacking a systematic and reliable verification mechanism. Especially in cross-system collaboration scenarios, it is difficult to ensure the consistency of behavior and output reliability of each system. Existing verification methods are mostly post-event testing, unable to achieve real-time reliability assessment during runtime. Therefore, there is an urgent need for a digital emergency backup control system for aircraft that can comprehensively solve the above problems, ensuring system reliability while improving system adaptability, intelligence, and collaboration. Summary of the Invention

[0004] This application provides a digital emergency backup control system for aircraft, which solves the problems of common failure risks caused by homogeneous redundancy design, insufficient intelligent decision-making capabilities of traditional switching mechanisms, and lack of systematic reliable verification mechanisms in the prior art. It achieves the technical effects of reliable collaboration and fault isolation of heterogeneous systems, adaptive intelligent switching of multi-dimensional state assessment, and seamless collaboration and command compatibility of cross-vendor equipment.

[0005] This application provides a digital emergency backup control system for aircraft, including:

[0006] Actuator control module: acquires multi-source sensor data and constructs a database of actuator characteristics including hydraulic, electric, and pneumatic actuators; based on the actuator characteristic database, it converts unified control commands into drive signals for specific actuators to achieve switching between primary and backup systems;

[0007] The semantic consistency management module converts driving signals into standard semantic descriptions, simulates these standard semantic descriptions using a dynamic model, evaluates behavioral differences between different systems, generates a consistency verification report, and performs parameter calibration based on the verification report.

[0008] Trustworthiness self-guarantee module: It transforms spatial rules, security constraints and mission objectives into verifiable temporal logic formulas, verifies the satisfaction of security attributes in real time during system operation, and generates trustworthiness proofs for verified security attributes;

[0009] Trustworthiness Collaboration Module: Standardizes trustworthiness proofs into a mutually recognized format using aviation trustworthiness proofs, calculates the matching degree with the target system requirements through a policy matching engine, generates a mutual recognition proposal, and achieves cross-system trustworthiness mutual recognition.

[0010] Furthermore, the actuation mechanism characteristic database includes: hydraulic actuation mechanism oil compressibility and pipeline dynamic characteristic parameters; electric actuation mechanism motor torque characteristics and transmission clearance parameters; pneumatic actuation mechanism gas compressibility and valve orifice flow characteristic parameters.

[0011] Furthermore, the actuator control module also includes an interface performance monitoring unit, which evaluates the control effect in real time through the actuator position feedback signal, adjusts the interface conversion parameters using the gradient descent method, continuously reduces the control error through an iterative optimization process, and refreshes the interface parameters according to a periodic update mechanism to maintain control accuracy.

[0012] Furthermore, the standard semantic description includes: establishing a control semantic dictionary, collecting control command sets and parameter definitions from various manufacturers' flight control systems; defining a standard control semantic description language, including command type, parameter range, and timeliness attributes; and establishing a semantic mapping table to provide a mapping relationship between commands and standard semantics for each manufacturer's system.

[0013] Furthermore, the conformance verification report includes:

[0014] Quantitative data on differences in behavior between systems: including comparative analysis results of response time deviation, overshoot differences, and steady-state error;

[0015] Consistency status assessment conclusion: The consistency of behavior between systems is classified and determined according to preset thresholds;

[0016] Data analysis of sources of discrepancies: identifying the main influencing factors and their contribution to behavioral inconsistencies;

[0017] Warning and handling recommendations: Provide parameter calibration and system switching recommendations for discrepancies exceeding the tolerance range.

[0018] Furthermore, the temporal logic formula adopts a linear temporal logic formalization method to encode multiple key constraints, including: encoding altitude layer preservation constraints in airspace rules, flight envelope restrictions in safety constraints, and waypoint arrival timing requirements in mission objectives. It also defines the properties of constancy, finality, responsiveness, and persistence through modal operators to achieve a verifiable description of the system's safety behavior.

[0019] Furthermore, the satisfaction level refers to the quantitative evaluation index of the security attribute verification results. By measuring the consistency between the system's runtime state and the preset security standards, a multi-dimensional credibility evaluation system is formed, including time compliance rate, spatial compliance rate, and logical compliance rate.

[0020] OCS=w1×TCR+w2×SCR+w3×LCR,

[0021] Wherein, OCS is the overall satisfaction score, TCR is the time compliance rate, SCR is the spatial compliance rate, LCR is the logical compliance rate, w1, w2, and w3 are the corresponding weights, and w1+w2+w3=1.

[0022] Furthermore, the time compliance rate is used to assess the degree to which security attributes are satisfied over time.

[0023]

[0024] Where TCR is the time compliance rate, T satisfy,i T represents the time period during which the i-th security attribute is continuously satisfied within the evaluation period. total The total evaluation time is n, and the total number of security attributes is n.

[0025] The spatial compliance rate is used to assess the degree to which spatial constraints are met:

[0026]

[0027] Where SCR is the spatial compliance rate, and N within N represents the number of times the system state point falls within the preset safe zone. total This represents the total number of state point samples.

[0028] The logical compliance rate is used to evaluate the degree to which logical rules and conditions are met.

[0029]

[0030] Where LCR is the logical compliance rate, and C satisfy,j Let m be the total number of logical conditions, where j is the j-th logical condition satisfied at the evaluation point.

[0031] Furthermore, the credibility proof is a standardized digital credential generated based on the verification results, which includes security attribute verification conclusions, timestamp information, digital signatures, and validity period metadata; and is output through a standardized serialization format to ensure parsing and verifiability in cross-system environments.

[0032] Furthermore, the proposed mutual recognition scheme includes:

[0033] Matching score unit: Generates a numerical matching score by quantitatively analyzing the degree of conformity between standardized credibility proof and the requirements of the target system;

[0034] Disposal Decision Unit: Based on the output of the matching degree scoring unit, it generates disposal recommendations including direct mutual recognition, downgraded mutual recognition, and rejection of mutual recognition, along with corresponding explanations of the decision reasons;

[0035] Certificate Reference Unit: Provides the hash index information and distributed storage location identifier of the certificate in the blockchain evidence storage network.

[0036] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0037] By employing heterogeneous architecture and multi-source sensor data fusion technology, reliable coordination and switching between primary and backup systems were achieved. System behavior evaluation and parameter calibration were completed using standard semantic description and dynamic simulation. Safety attributes were verified in real time using time-series logic formulas, establishing a reliable guarantee throughout the entire lifecycle. Cross-system intelligent mutual recognition was achieved through standardized reliable proof and policy matching. Ultimately, while ensuring high reliability, the system's adaptability, intelligence, and coordination were significantly improved, providing a comprehensive safety control solution for unmanned aerial vehicles. Attached Figure Description

[0038] Figure 1 This is a diagram illustrating the architecture of a digital emergency backup control system for an aircraft, as described in an embodiment of the present invention. Detailed Implementation

[0039] To facilitate understanding of the present invention, a more complete description of this application will be given below with reference to the accompanying drawings, which illustrate preferred embodiments of the invention. However, the invention can be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to enable a more thorough and complete understanding of the disclosure of the present invention.

[0040] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to limit the invention; the term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0041] Example 1: As Figure 1 As shown, a digital emergency backup control system for aircraft.

[0042] The actuator control module acquires multi-source sensor data and constructs a characteristic database of actuators including hydraulic, electric, and pneumatic systems. Based on the actuator characteristic database, it converts unified control commands into drive signals for specific actuators, thereby enabling the switching between the main and backup systems.

[0043] The actuation mechanism characteristic database includes: hydraulic actuation mechanism oil compressibility and pipeline dynamic characteristic parameters; electric actuation mechanism motor torque characteristics and transmission clearance parameters; pneumatic actuation mechanism gas compressibility and valve orifice flow characteristic parameters.

[0044] Specifically, high-precision sensors collect dynamic response data of the actuating mechanisms. The hydraulic actuating mechanism includes hydraulic compressibility parameters such as bulk modulus, compressibility coefficient, and temperature-viscosity characteristic curves; and pipeline dynamic parameters such as frequency response curves, resonant frequency identification strategies, and pressure fluctuation transfer functions. These parameters collectively ensure the stability and responsiveness of the hydraulic system under complex operating conditions. The electro-actuating mechanism encompasses motor torque characteristics such as torque-speed curves, efficiency mapping diagrams, and thermal characteristic parameters; and transmission clearance parameters such as backlash compensation range, load-deformation relationship curves, and friction coefficients. These parameters optimize the efficiency and reliability of the motor drive system, supporting high-precision control. The pneumatic actuating mechanism includes gas compressibility parameters such as adiabatic index, density-pressure relationship, and sound propagation characteristics; and valve flow characteristics such as flow coefficient, flow-pressure characteristic curves, and opening / closing time constants. These parameters ensure the pneumatic system's performance in terms of rapid response and flow control.

[0045] The actuator control module also includes an interface performance monitoring unit, which evaluates the control effect in real time through the actuator position feedback signal, adjusts the interface conversion parameters using the gradient descent method, continuously reduces the control error through an iterative optimization process, and refreshes the interface parameters according to a periodic update mechanism to maintain control accuracy.

[0046] Specifically, the interface performance monitoring unit is responsible for real-time monitoring of the control interface performance and continuous optimization of conversion parameters. A unified control description language is used to standardize commands, including position commands such as target position, motion trajectory, and positioning tolerance; speed commands such as defining target speed, acceleration, and jerk limits; and force commands such as setting target torque, force control stiffness, and damping coefficient. After receiving the commands, the interface converter calls the corresponding conversion algorithm based on the type of the target actuator.

[0047] The interface performance monitoring unit adopts the incremental gradient descent method, performing a maximum of 5 iterations per control cycle to ensure a response time of less than 1ms; the dynamic model uses a pre-calculated reduced-order model, with a simulation cycle of no more than 10ms; the blockchain notarization of the trustworthiness proof is executed asynchronously in a low-priority thread, without affecting real-time control.

[0048] After receiving standardized control commands, the hydraulic mechanism interface converter performs high-precision dynamic conversion based on the hydraulic characteristic parameters in the actuator characteristic database. According to the target position or force command, it calculates the required oil volume and system pressure requirements in combination with the oil compressibility parameters. It integrates pipeline dynamic characteristic parameters and compensates for delay and oscillation effects through a fluid transmission model. It generates the control current signal of the electro-hydraulic servo valve and embeds the oil compressibility dynamic correction parameters to ensure the accuracy and stability of the hydraulic actuator output.

[0049] After receiving standardized commands, the electric mechanism interface converter performs electromechanical conversion based on motor torque characteristics and transmission clearance parameters. According to the target position or torque command, it calculates the required electromagnetic torque by combining the motor torque-speed curve and efficiency mapping diagram, and integrates thermal characteristic parameters to achieve energy consumption optimization and overheat protection. Based on the transmission clearance parameters, it eliminates backlash and elastic deformation errors in mechanical transmission through a pre-compensation algorithm. It generates motor drive signals and embeds real-time thermal protection strategies to support adaptive control of various types of electric actuators such as servo motors and stepper motors.

[0050] After receiving the command, the pneumatic mechanism interface converter performs a precise fluid dynamics conversion based on the gas compressibility parameters and valve orifice flow characteristics. According to the target position or force command, it calculates the required gas mass flow rate and chamber pressure by combining the gas adiabatic index and density-pressure relationship model. Based on the valve orifice flow characteristic parameters, it compensates for the delay and pressure fluctuation caused by gas compressibility. It outputs the control signal of the proportional valve or on / off valve and integrates the sonic propagation characteristics to optimize the response timing, ensuring the rapid and accurate response of the pneumatic actuator.

[0051] The system acquires position feedback signals from multiple sensor sources in real time, filters, denoises, and performs AD conversion on the signals, extracts the actual position values ​​as input for evaluating the control effect, and sets the error function between the control target value and the actual feedback value.

[0052] E(t) = r(t) - y(t),

[0053] Where E(t) is the error value, r(t) is the command target value, and y(t) is the actual position feedback value.

[0054] Construct the objective function for parameter optimization:

[0055] J(θ)=∑E(t),

[0056] Where J(θ) is the objective function for optimization, and θ is the set of interface conversion parameters to be optimized.

[0057] The parameters are updated iteratively using gradient descent:

[0058]

[0059] Where, θ new For the updated parameter vector, θ old Let be the parameter vector to be optimized, and α be the learning rate, which controls the magnitude of each parameter update and takes a value in the range of (0, 0.1]. This represents the gradient of the objective function with respect to the parameters. Within each control cycle, the gradient is calculated based on the real-time error, and the interface parameters are dynamically adjusted to gradually reduce the control error.

[0060] The system is configured to perform parameter updates and refreshes at a fixed period, such as every 100ms. The updated parameters are immediately applied to the control signal conversion stage, ensuring that control commands can be adapted in real-time to the dynamic characteristics of the actuator. The system also records parameter update history and error change curves. After each parameter update, the control error is reassessed; if the error continues to decrease, the new parameters are retained; if the optimization effect does not meet expectations, an exception handling mechanism is triggered. A parameter update rollback strategy is supported; when system oscillation or divergence is detected, the system automatically reverts to the previous stable parameter set.

[0061] The primary and backup systems share interface conversion parameters and optimization results in real time. When a primary-backup switch occurs, the backup system immediately obtains the current actuator interface parameters. The interface performance monitoring module detects control deviations in real time. When an anomaly is detected, it automatically switches to the redundant interface channel and sends alarms to other systems via the data bus to collaboratively isolate faults.

[0062] The technical solutions described in the embodiments of this application have at least the following technical effects or advantages:

[0063] This application employs multi-source sensor data fusion technology to construct a database containing the characteristics of hydraulic, electric, and pneumatic actuators. This enables unified control command conversion and drive signal generation for heterogeneous actuators, effectively addressing the common fault risks faced by traditional homogeneous redundant systems. By using an interface performance monitoring unit to collect position feedback signals in real time and employing a gradient descent method to iteratively optimize interface conversion parameters, continuous reduction of control error and dynamic maintenance of control accuracy are achieved, ensuring the smoothness and reliability of the primary / backup system switching process. Through high-precision sensor data acquisition and characteristic parameter integration, stable response and high-precision control of multiple types of actuators under complex operating conditions are achieved. Furthermore, through a periodic parameter update mechanism and anomaly handling strategies, adaptive optimization and fault isolation are realized throughout the system's entire lifecycle, enhancing the adaptability, intelligence, and coordination of the aircraft's emergency backup control system.

[0064] Example 2: Example 1 focuses on the control optimization of a single actuator, but lacks an evaluation and calibration mechanism for the consistency of behavior between different systems. This may lead to differences in response between systems, affecting the reliability of coordination. This example further supplements the content of Example 1.

[0065] The semantic consistency management module: converts driving signals into standard semantic descriptions, simulates the standard semantic descriptions using a dynamic model, evaluates the behavioral differences between different systems, generates a consistency verification report, and performs parameter calibration based on the verification report;

[0066] The standard semantic description includes: establishing a control semantic dictionary, collecting control command sets and parameter definitions from various manufacturers' flight control systems; defining a standard control semantic description language, including command type, parameter range, and timeliness attributes; and establishing a semantic mapping table to provide a mapping relationship between commands and standard semantics for each manufacturer's system.

[0067] Specifically, drive signals from the actuator control module are converted into unified standard semantic descriptions to ensure machine readability and cross-system compatibility of the commands. Control command sets and parameter definitions from various flight control systems are collected, including command syntax, semantics, parameter ranges, and units. The dictionary structure is in database form, with each entry containing command ID, vendor ID, command type, name, data type, minimum value, maximum value, default value, and description. The dictionary supports dynamic updates to ensure compatibility with new vendor equipment.

[0068] A standard semantic description language is employed to ensure structure and scalability, providing mapping rules from instructions to standard semantics for each vendor's system. The converted standard semantic description is input into a dynamic model for simulation to predict system behavior and assess consistency. The simulation process includes: inputting the standard semantic description; the model executing instructions and calculating system responses, such as position trajectories, velocity curves, and force outputs; considering environmental factors such as wind speed, gravity, temperature changes, and system state, outputting time-series state variables, including position data, velocity data, and acceleration data. Differences in key performance indicators are calculated by comparing simulation results with actual system responses; a consistency verification report is generated based on the dynamic model simulation and the assessment of inter-system behavior differences.

[0069] The consistency verification report includes: quantitative data on behavioral differences between systems, consistency status assessment conclusions, data on the analysis of the sources of differences, and early warning and handling suggestions;

[0070] Specifically, the quantitative data on inter-system behavioral differences is obtained through dynamic simulation and real-time data acquisition. This quantifies the differences in key performance indicators between systems, including comparative analysis of response time deviation, overshoot difference, and steady-state error. Response time deviation is used to calculate the time difference from command issuance to the system output reaching 90% of the target value. By repeatedly cyclically performing simulations, the average deviation, standard deviation, and maximum deviation are statistically analyzed to identify the statistical patterns of response delay. Overshoot difference measures the maximum magnitude difference exceeding the target value during the system response, assessing the inconsistency in system stability. The comparative analysis of steady-state error assesses the persistent deviation between the system's output and the target value after stabilization. Through long-term operating data, such as continuous sampling over 10 minutes, the mean and variance of the error are calculated to identify systematic deviation trends.

[0071] The consistency status assessment conclusion is based on preset thresholds and industry standards, classifying and judging the consistency of behavior between systems, and providing assessment conclusions, including classification criteria, judgment logic, and output format. The classification criteria set multiple threshold levels based on quantitative difference data. When the response time deviation is ≤2ms, the overshoot difference is ≤1%, and the steady-state error is ≤0.1mm, it is classified as excellent, indicating that all difference indicators are within tolerance; when the response time deviation is ≤5ms and the overshoot difference is ≤3%, it is classified as good, indicating that 1-2 indicators are slightly out of tolerance; when the response time deviation is ≤10ms and the steady-state error is ≤0.5mm, it is classified as warning level, indicating that multiple indicators are out of tolerance but do not endanger safety; when the response time deviation is >10ms and the steady-state error is >1mm, it is classified as fault level, indicating that the indicators are severely out of tolerance and may cause system failure.

[0072] The source analysis of discrepancies identified the main influencing factors and their contributions to behavioral inconsistencies using root cause analysis techniques. Key factors were identified through simulation data and system logs, including: sensor calibration deviation (30%), actuator characteristic degradation (25%), environmental disturbances (20%), software parameter mismatch (15%), and other factors (10%). Variance decomposition was used to quantify the percentage impact of each factor on the overall discrepancy, and the accuracy of the contribution was verified through disturbance testing.

[0073] For discrepancies exceeding tolerance limits, the system provides actionable warnings and handling recommendations to ensure timely system consistency restoration. When an indicator exceeds limits, an early warning is immediately triggered, and a structured message containing the anomaly timestamp, affected system identifier, and severity level is sent to the monitoring system via the data bus, ensuring immediate detection and tracing of the anomaly. Based on the analysis of the source of the discrepancy, the system automatically generates parameter calibration recommendations, including adjusting the PID controller gain, updating actuator characteristic database parameters, and optimizing feedforward compensation values ​​to suppress overshoot, thereby restoring system consistency through fine-tuning. If the discrepancy cannot be eliminated through calibration, the system provides intelligent switching recommendations: for fault-level discrepancies, it recommends immediate switching to the backup system within 100ms to ensure operational continuity; for warning-level discrepancies, it recommends switching during the planned maintenance window, accompanied by detailed switching procedure documentation to minimize service interruption.

[0074] The conformance verification report is output in a standardized format, integrating timestamps, version numbers, and digital signatures to ensure data integrity and traceability.

[0075] Based on the consistency verification report, targeted calibration methods are employed according to the type and source of discrepancies, dynamically adjusting parameters to minimize errors. Hydraulic system parameters are updated to address response delays caused by oil compressibility.

[0076] β=β0·[1+γ(T-T0)],

[0077] Where β is the calibrated bulk modulus of the oil, β0 is the initial bulk modulus of the oil at the reference temperature, γ is the coefficient of thermal expansion of the oil (obtained experimentally), T is the real-time collected oil temperature, and T0 is the reference temperature.

[0078] To address the degradation of torque characteristics, the motor system parameters are updated; based on real-time current and speed data, linear regression is used to update the curve coefficients, and the backlash value is measured and the database is updated through reverse motion testing.

[0079] To address the gas compressibility effect, the pneumatic system parameters are updated:

[0080]

[0081] Where Q is the volumetric flow rate, and C v ρ is the flow coefficient, ΔP is the pressure difference before and after the valve orifice, and ρ is the fluid density.

[0082] To compensate for calibration deviations, inject offset or scaling factors to perform sensor bias compensation:

[0083] Δx=x mea -x true ,

[0084] Where Δx is the sensor calibration deviation value, x mea x represents the real-time measurement value from the sensor. true This is the standard reference value. Write the sensor calibration deviation value into the calibration table.

[0085] The technical solutions described in the embodiments of this application have at least the following technical effects or advantages:

[0086] This application uses a semantic consistency management module to convert the drive signals output by the actuator control module into standard semantic descriptions, establishing a unified instruction mapping relationship across vendor systems and solving the instruction set compatibility problem between heterogeneous devices. It simulates the standard semantic descriptions using a dynamic model, quantitatively assessing behavioral differences between different systems and generating a consistency verification report that includes an analysis of the sources and contributions of these differences. Based on the report data, a targeted parameter calibration method is used to eliminate behavioral inconsistencies between systems in real time. Ultimately, this achieves high-precision consistency assurance for multi-system collaborative control, significantly improving the cross-platform interoperability and collaborative reliability of the aircraft emergency backup system, and overcoming the risk of collaborative failure caused by heterogeneous differences in traditional solutions.

[0087] Example 3: Example 2, through its semantic consistency management module, achieves standardized conversion of driving signals, dynamic simulation, and difference analysis, generates a consistency verification report, and performs parameter calibration, thereby solving the problem of instruction compatibility and behavior synchronization between heterogeneous systems. However, it lacks real-time self-verification capabilities. This example further supplements the content of Example 2.

[0088] The self-reliability guarantee module transforms spatial rules, security constraints, and task objectives into verifiable temporal logic formulas. During system operation, it verifies the satisfaction of security attributes in real time and generates a reliability proof for the verified security attributes.

[0089] Specifically, the semantic consistency management module outputs the behavioral consistency index (such as response time deviation and steady-state error) to the trustworthiness self-assurance module; the trustworthiness self-assurance module combines the behavioral consistency index and the timing logic verification results to generate a comprehensive security assessment report and uniformly trigger early warnings or handling suggestions.

[0090] The temporal logic formula adopts a linear temporal logic formalization method to encode multiple key constraints, including: encoding altitude layer preservation constraints in airspace rules, flight envelope restrictions in safety constraints, and waypoint arrival timing requirements in mission objectives. It also defines the properties of constancy, finality, responsiveness, and persistence through modal operators to achieve a verifiable description of the system's safety behavior.

[0091] Specifically, linear temporal logic (LTL) is used as the formal expression basis. Temporal constraints of security attributes are defined through modal operators. Atomic propositions are combined using LTL operators to encode key constraints: constancy (□) requires the attribute to be satisfied at all points in time; finality (◇) requires the attribute to be satisfied at a certain future point in time; responsiveness (→) defines the temporal response of causal relationships; and persistence (〇) requires the attribute to be continuously satisfied within a specific period of time.

[0092] The altitude layer maintenance constraint ensures that the aircraft flies stably within a specified altitude layer, preventing collisions with other aircraft. Its linear sequential logic formal expression is as follows:

[0093] □(|h(t)-h target |≤Δh tol ),

[0094] Where □ is the timeliness operator, h(t) is the actual altitude of the aircraft at time t, h target For the target height layer, Δh tol This refers to the allowable altitude deviation tolerance. It requires that the altitude deviation remain within the tolerance range throughout the entire flight.

[0095] Flight envelope limits define the boundaries of parameters such as speed, angle of attack, and overload for safe flight of an aircraft, and their encoding includes:

[0096] Speed ​​envelope: V min ≤V(t)≤V max , where V min For the minimum permissible airspeed, V max V(t) represents the maximum permissible airspeed, and V(t) represents the actual airspeed at time t. min and V min Related to the current height and configuration;

[0097] Angle of attack envelope: α min ≤α(t)≤α stall , where α min For the minimum usable angle of attack, α stall Let α(t) be the stall angle of attack, and α(t) be the real-time angle of attack at time t.

[0098] Overload envelope: n z (t)∈[n z,min ,nz,max ], where n z (t) is the normal overload coefficient, representing the ratio of the net force acting on the aircraft in the vertical direction to its weight: F z The net force in the vertical direction is m, where m is the mass of the aircraft and g is the acceleration due to gravity; [n z,min ,n z,max The normal overload range defines the limit boundaries that the structural strength and passenger comfort of an aircraft can withstand.

[0099] The linear sequential logic formal expression of the flight envelope constraint is as follows:

[0100] □(Λ i P i (t)∈SafeRange i ),

[0101] Among them, P i (t) represents the state value of the i-th system parameter (speed, angle of attack, overload) at time t, SafeRange i For its safe space, ∧ i To perform a logical AND operation on all i, all conditions must be satisfied simultaneously. It is required that all critical safety parameters P remain constant throughout the entire system operation. i The values ​​must always remain within their respective preset safety ranges.

[0102] Waypoint arrival timing requirements ensure that the aircraft arrives at the waypoint within the planned time window. Its linear timing logic formal expression is as follows:

[0103] ∧ j ◇[t j,ear ,t j,lat ](At(WP j )),

[0104] Among them, ∧ j For all j, a logical AND operation is performed; ◇ is the finality operator; t j t represents the actual arrival time. j,ear For the earliest allowed time, t j,lat The latest allowed time, ◇[t j,ear ,t j,lat ](At(WP j )) is located at waypoint WP j It must be in the future time interval [t] j,ear ,t j,lat This must occur at least once within [a certain timeframe]. For each waypoint WP in the mission, [the condition must be met]. j All aircraft must be within the planned time window [t] j,ear ,tj,lat Within [the area], it eventually arrives at and is located at that waypoint.

[0105] During operation, the system continuously monitors various status parameters and performs real-time verification based on the LTL formula, quantifying the results into a multi-dimensional reliability assessment system, namely, satisfaction level.

[0106] OCS=w1×TCR+w2×SCR+w3×LCR,

[0107] Wherein, OCS is the overall satisfaction score, TCR is the time compliance rate, SCR is the spatial compliance rate, LCR is the logical compliance rate, and w1, w2, and w3 are the corresponding weights, with w1+w2+w3=1. During takeoff and landing, the time compliance rate is given a higher weight; during cruise or obstacle avoidance, the spatial compliance rate is given a higher weight; and in scenarios with complex logical constraints, the logical compliance rate is given a higher weight.

[0108] The time compliance rate is used to assess the degree to which security attributes are satisfied over time.

[0109]

[0110] Where TCR is the time compliance rate, T satisfy,i T represents the time period during which the i-th security attribute is continuously satisfied within the evaluation period. total The total evaluation time is n, and the total number of security attributes is n.

[0111] The spatial compliance rate is used to assess the degree to which spatial constraints are met:

[0112]

[0113] Where SCR is the spatial compliance rate, and N within N represents the number of times the system state point falls within the preset safe zone. total This represents the total number of state point samples.

[0114] The logical compliance rate is used to evaluate the degree to which logical rules and conditions are met.

[0115]

[0116] Where LCR is the logical compliance rate, and C satisfy,j Let m be the total number of logical conditions, where j is the j-th logical condition satisfied at the evaluation point.

[0117] The credibility proof is a standardized digital credential generated based on the verification results, which includes security attribute verification conclusions, timestamp information, digital signatures, and validity period metadata; and is output through a standardized serialization format to ensure parsing and verifiability in cross-system environments.

[0118] Specifically, a standardized digital proof of trust is generated for each verified security attribute. This proof includes a security attribute verification conclusion that explicitly lists the verified attribute and its verification result, quantitative evidence, timestamp information, digital signature, and metadata containing information such as system identifier and verification algorithm version. The proof is output in a standardized serialized format to ensure that it can be correctly parsed and understood across different vendors and system platforms.

[0119] For example, to monitor flight envelope limits in real time, the system samples airspeed, angle of attack, and overload at a fixed frequency (e.g., 100Hz), and verifies the data at each sampling point to ensure it falls within [V]. min V max Within a preset safety range, count the number of sampling points N within that range. within Total number of sampling points N total The system calculates the SCR in real time. At the end of an evaluation period, the system calculates the TCR, SCR, and OCS for that period. If the OCS ≥ 99%, the system determines that the attribute has passed verification and automatically generates a credibility certificate with a timestamp and digital signature, proving that the flight envelope was complied with during the period.

[0120] If the OCS continues to drop below 95%, the system triggers a low-level warning. The warning message indicates which specific parameter (such as airspeed) is deviating and predicts the time it may reach the boundary. If the OCS drops sharply below 90%, or any parameter momentarily exceeds the safety boundary, the system immediately triggers a high-level alarm. At this time, the reliability self-assertion module issues the highest priority instruction to the flight control system, requiring it to take immediate corrective action. Simultaneously, this failed verification is generated and marked as an alarm status. All warnings and alarms are attached as handling recommendations to the conformance verification report or sent directly to the control module. These recommendations may include switching to a backup system or limiting flight maneuvers.

[0121] The actuator control module sends drive signals and real-time sensor data to the semantic consistency management module via a high-speed data bus; the consistency verification report generated by the semantic consistency management module is fed back to the parameter calibration unit of the actuator control module in real time, forming a closed-loop control; the reliability self-guarantee module obtains multi-source sensor data from the actuator control module and shares the system behavior consistency status with the semantic consistency management module.

[0122] The technical solutions described in the embodiments of this application have at least the following technical effects or advantages:

[0123] This application employs a linear temporal logic formalization method to encode airspace rules, safety constraints, and mission objectives into verifiable temporal logic formulas, enabling real-time verification and quantitative evaluation of system safety behavior. It dynamically monitors the degree of compliance with safety attributes through multi-dimensional satisfaction indicators and generates standardized credibility proofs based on the verification results, including digital signatures and timestamps, ensuring the traceability and cross-system resolvability of the verification process. Simultaneously, by leveraging early warning and alarm mechanisms, it triggers tiered responses when the overall satisfaction level is abnormal, achieving immediate perception and handling of potential risks and significantly improving the real-time self-verification capability and safety reliability of the aircraft emergency backup system.

[0124] Example 4: Example 3 focuses on real-time verification of internal security attributes and generation of credibility proofs, but the generated proofs only reflect the system's own state and lack the ability to collaborate and mutually recognize with other systems. This example further supplements the content of Example 3.

[0125] The credibility collaboration module standardizes credibility proofs into a mutually recognized format using aviation credibility proofs, calculates the matching degree with the target system requirements through a policy matching engine, generates a mutual recognition suggestion scheme, and realizes cross-system credibility mutual recognition.

[0126] Specifically, the received credibility proof is converted into a format conforming to the mutual recognition standards in the aviation field. Based on the general mutual recognition protocols in the aviation industry, the timestamps, signature algorithms, attribute encodings, and other elements in the proof are standardized to ensure that its structure, semantics, and syntax conform to industry standards. Using a predefined mutual recognition semantic dictionary, the logical formulas and satisfaction indicators in the proof are mapped to cross-system understandable standard terms, eliminating ambiguities in semantic expression between different systems.

[0127] Based on the matching score, the decision-making unit generates a mutual recognition suggestion scheme, which includes:

[0128] The policy matching engine calculates the degree of matching between the standardized credibility proof and the security requirements of the target system. A multi-dimensional weighted scoring algorithm is employed to quantify the degree of compliance between the current proof and the target system requirements from multiple perspectives, including temporal compliance, spatial compliance, and logical compliance.

[0129] MDS = w1 × S TCR +w2×S SCR +w3×S LCR ,

[0130] Wherein, MDS is the match score, with a value range of [0,1], and a higher value indicates a higher match score; S TCR S SCR S LCRThe original compliance rate indicators (TCR, SCR, LCR) are obtained through normalization; w1, w2, and w3 are the corresponding weights, and w1+w2+w3=1. During takeoff and landing, time compliance rate is given higher weight; during cruise or obstacle avoidance, spatial compliance rate is given higher weight; and logical compliance rate in complex logical constraint scenarios is given higher weight.

[0131] When MDS ≥ 0.95, direct mutual recognition is determined, indicating that the supporting documentation fully meets the target system requirements and that key security attributes (such as flight envelope and timing logic constraints) show no significant deviations. Automatic authorization of inter-system control transfer is implemented, and the trusted state is synchronously updated to the collaborative network. When MDS ≤ 0.8 < 0.95, downgraded mutual recognition is determined, indicating slight deviations in some non-core parameters, but not affecting the overall security objective. The system restricts the scope of collaborative functions, such as allowing only data sharing and prohibiting control transfer. A real-time monitoring mechanism is triggered to dynamically track deviation parameters, and calibration recommendations are generated and pushed to the semantic consistency management module. When MDS < 0.8, mutual recognition is rejected, indicating serious deviations in core security attributes or invalid supporting documentation. Cross-system collaborative operations are immediately terminated, an alarm is triggered and reported to the security audit node, and the backup system switchover process is initiated.

[0132] A distributed identifier for trusted proof is generated through a credential referencing unit, comprising a hash value, a storage node address, and a timestamp. A collision-resistant cryptographic hash algorithm (SHA-256) is used to calculate the complete trusted proof data, generating a fixed-length unique hash string. This hash value serves as the primary key identifier for the credential in the storage network, allowing other systems or auditors to quickly retrieve and verify the authenticity of a specific proof document. The storage node address identifies the network address of one or more blockchain nodes or distributed storage nodes storing a copy of the proof document; it exists as addressing information in a set of IP addresses and port numbers. By recording the addresses of multiple nodes, redundant backup of storage is achieved, ensuring that even if some nodes fail, the credential can still be obtained from other nodes.

[0133] The technical solutions described in the embodiments of this application have at least the following technical effects or advantages:

[0134] This application standardizes trustworthiness proofs into a mutually recognized format through a trustworthiness collaboration module, utilizes a strategy matching engine to quantify the matching degree with the target system requirements, and generates intelligent suggestion schemes including direct mutual recognition, downgraded mutual recognition, or rejection of mutual recognition, thus achieving cross-system trustworthiness mutual recognition. Through a credential citation unit, it provides hash indexes and distributed storage location identifiers in the blockchain evidence storage network, ensuring the immutability and traceability of the proofs. Ultimately, it solves the problem of traditional systems lacking real-time cross-system verification and collaboration capabilities, significantly improving the interoperability, decision automation, and safety reliability of the aircraft emergency backup control system in heterogeneous environments.

[0135] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. For those skilled in the art, the present invention can have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. An aircraft digital emergency backup control system, characterized in that, include: Actuator control module: acquires multi-source sensor data and constructs a database of actuator characteristics including hydraulic, electric, and pneumatic actuators; based on the actuator characteristic database, it converts unified control commands into drive signals for specific actuators to achieve switching between primary and backup systems; The actuation mechanism characteristic database includes: hydraulic actuation mechanism oil compressibility and pipeline dynamic characteristic parameters; electric actuation mechanism motor torque characteristics and transmission clearance parameters; pneumatic actuation mechanism gas compressibility and valve orifice flow characteristic parameters. The semantic consistency management module converts driving signals into standard semantic descriptions, simulates these standard semantic descriptions using a dynamic model, evaluates behavioral differences between different systems, generates a consistency verification report, and performs parameter calibration based on the verification report. The conformance verification report includes: Quantitative data on differences in behavior between systems: including comparative analysis results of response time deviation, overshoot differences, and steady-state error; Consistency status assessment conclusion: The consistency of behavior between systems is classified and determined according to preset thresholds; Data analysis of sources of discrepancies: identifying the main influencing factors and their contribution to behavioral inconsistencies; Early warning and handling recommendations: Provide parameter calibration and system switching suggestions for discrepancies exceeding the tolerance range; Trustworthiness self-guarantee module: It transforms spatial rules, security constraints and mission objectives into verifiable temporal logic formulas, verifies the satisfaction of security attributes in real time during system operation, and generates trustworthiness proofs for verified security attributes; The temporal logic formula adopts a linear temporal logic formalization method to encode multiple key constraints, including: encoding the altitude layer preservation constraint in the airspace rules, the flight envelope limit in the safety constraints, and the waypoint arrival timing requirements in the mission objectives. It also defines the persistence, finality, responsiveness, and persistence attributes through modal operators to achieve a verifiable description of the system's safety behavior. The satisfaction rate refers to the quantitative evaluation index of the security attribute verification results. By measuring the consistency between the system's runtime state and the preset security standards, a multi-dimensional credibility evaluation system is formed, which includes time compliance rate, spatial compliance rate, and logical compliance rate. , wherein, is the overall satisfaction, is the temporal agreement, is the spatial agreement, is the logical agreement, , is the corresponding weight, and ; Trustworthiness Collaboration Module: Standardizes trustworthiness proofs into a mutually recognized format using aviation trustworthiness proofs, calculates the matching degree with the target system requirements through a policy matching engine, generates a mutual recognition proposal, and achieves cross-system trustworthiness mutual recognition.

2. A digital emergency backup control system for an aircraft as recited in claim 1, wherein The actuator control module also includes an interface performance monitoring unit, which evaluates the control effect in real time through the actuator position feedback signal, adjusts the interface conversion parameters using the gradient descent method, continuously reduces the control error through an iterative optimization process, and refreshes the interface parameters according to a periodic update mechanism to maintain control accuracy.

3. A digital emergency backup control system for an aircraft as recited in claim 1, wherein The standard semantic description includes: establishing a control semantic dictionary, collecting control command sets and parameter definitions from various manufacturers' flight control systems; defining a standard control semantic description language, including command type, parameter range, and timeliness attributes; and establishing a semantic mapping table to provide a mapping relationship between commands and standard semantics for each manufacturer's system.

4. A digital emergency backup control system for an aircraft as recited in claim 1, wherein The time compliance rate is used to assess the degree to which security attributes are satisfied over time. , wherein, is the time coincidence rate, is the time period in which the ith safety property is continuously satisfied within the evaluation period, is the total evaluation time, and n is the total number of safety properties; The spatial compliance rate is used to assess the degree to which spatial constraints are met: , wherein, is the spatial coincidence rate, is the number of times the system state point is located in the preset safe region, is the total state point sampling number; The logical compliance rate is used to evaluate the degree to which logical rules and conditions are satisfied: , wherein, is the logical agreement rate, is the jth logical condition satisfied at the evaluation point, is the total number of logical conditions.

5. A digital emergency backup control system for an aircraft as recited in claim 1, wherein, The credibility proof is a standardized digital credential generated based on the verification results, which includes security attribute verification conclusions, timestamp information, digital signatures, and validity period metadata; and is output through a standardized serialization format to ensure parsing and verifiability in cross-system environments.

6. A digital emergency backup control system for an aircraft as recited in claim 1, wherein, The proposed mutual recognition scheme includes: Matching score unit: Generates a numerical matching score by quantitatively analyzing the degree of conformity between standardized credibility proof and the requirements of the target system; Disposal Decision Unit: Based on the output of the matching degree scoring unit, it generates disposal recommendations including direct mutual recognition, downgraded mutual recognition, and rejection of mutual recognition, along with corresponding explanations of the decision reasons; Certificate Reference Unit: Provides the hash index information and distributed storage location identifier of the certificate in the blockchain evidence storage network.