Man-machine collaborative aerospace design method
By employing a human-machine collaborative aerospace design method, and utilizing design contracts and hypergraphs, differentiable physical models, reachability cone fields, and flutter critical frequency fields, multi-objective optimization and manufacturing feasibility of spacecraft structural design are achieved simultaneously. This solves the problems of interface inconsistency and semantic loss in traditional design methods, and provides auditable evidence traceability and change management.
Patent Information
- Application Number
- CN202511310786.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-15
- Publication Date
- 2026-02-13
AI Technical Summary
Spacecraft structural design faces a multi-objective game of lightweighting versus stiffness, thermal and vibration, and safety versus assembly. It also bears the engineering pressure of compressed model cycles and frequent changes. The traditional process operates in a segmented manner, namely "geometric design - analysis and evaluation - process programming - quality inspection planning". This results in knowledge being translated multiple times between CAD, CAE, CAM and metrology systems, leading to inconsistent interfaces and loss of semantics, resulting in rework and amplified risks.
A human-machine collaborative aerospace design method is adopted. The design contract and design hypergraph are used as the sole source of facts. The configuration parameters of satisfaction are obtained under a differentiable physical model. The feasibility certificate is generated by combining the reachability cone field and the flutter critical frequency field. Continuous relaxation and type projection are performed on the process resource hypergraph. The safety and measurement closed loop is completed by using the control barrier function and the harmonic field. The resulting evidence is auditable and the changes can be locally converged.
It enables calculable expression and bidirectional traceability of requirements, geometric objects, and constraints; configuration parameters inherently satisfy contract terms during the design phase; pre-constraints on manufacturing feasibility and processing stability; process-oriented solution and type correctness assurance; minimal intervention and rapid reuse of changes; and a unified evidence base for release review and quality traceability.
Smart Images

Figure CN121525152A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of integrated spacecraft structural design and manufacturing technology, and in particular to a human-machine collaborative spacecraft design method. Background Technology
[0002] Spacecraft structural design faces a multi-objective trade-off between lightweighting and stiffness, thermal and vibration considerations, and safety and assembly requirements, while also bearing the engineering pressures of compressed model cycles and frequent changes. The traditional workflow operates in a segmented manner: "geometric design—analysis and evaluation—process programming—quality control planning." Knowledge is translated multiple times between CAD, CAE, CAM, and metrology systems, leading to interface inconsistencies and semantic loss, resulting in rework and amplified risks. The industry urgently needs to place requirements, geometric entities, manufacturing constraints, and metrological constraints under a unified data carrier, enabling design decisions and manufacturing feasibility to converge simultaneously, and providing auditable evidence to support release and changes. Summary of the Invention
[0003] To address the numerous problems existing in the prior art, this invention provides a human-machine collaborative aerospace design method. This invention uses the design contract and design hypergraph as the sole source of facts, and obtains the configuration parameters of satisfaction under a differentiable physical model; it verifies and generates a feasibility certificate by combining the reachability cone field and the flutter critical frequency field; it obtains a discrete process through continuous relaxation and type projection on the process resource hypergraph, and completes the safety and measurement closed loop with the control obstacle function and harmonic field, making the evidence auditable and the changes locally convergent.
[0004] A human-machine collaborative aerospace design method includes the following steps:
[0005] It receives multi-source design inputs, compiles design rules and engineering boundaries into a design contract, and establishes a design hypergraph in the graph structure;
[0006] Under the constraints of the design contract, the configuration parameters are constrained and optimized in a differentiable physical model to obtain the configuration parameters that satisfy the requirements. The reachability cone field is calculated using analytical geometry methods, the flutter critical frequency field is calculated using a dynamic model, and a feasibility certificate covering reachability and stability is generated through formal verification.
[0007] A process resource hypergraph is constructed on the design hypergraph, continuous relaxation programming is performed, discrete process parameters are obtained through constraint projection based on type system, a safety trajectory is generated using control obstacle function, a measurement path is generated, and process certificates and feasibility certificates are compiled.
[0008] The minimum hit set is generated based on the set of counterexamples. The synthetic contract patch configuration patch and process patch are written back, triggering local re-solution and re-verification. The final configuration parameters and the final process resource hypergraph are output, and the evidence log is recorded.
[0009] Preferably, the multi-source design inputs include natural language, engineering sketches, images, and interactive parameters. The design contract is compiled and generated using a contract description language and bound to the design hypergraph with constraint edges and reference nodes.
[0010] Preferably, the constraint optimization in the differentiable physical model adopts the Lagrange multiplier method, and the constraints are tightened step by step according to the homotopy strategy to obtain the configuration parameters of satisfaction.
[0011] Preferably, the calculation of the accessibility cone field involves determining the analytical geometric intersection of the tool axis direction and the surface patch in three-dimensional space, and calculating the solid angle volume of the legal direction set to obtain a regional accessibility index.
[0012] Preferably, the flutter critical frequency field is calculated based on the equivalent stiffness and equivalent mass obtained from the dynamic modal model, and the critical frequency of the spatial location is determined according to the stability domain criterion.
[0013] Preferably, the formal verification uses the sum of squares method to generate a joint feasibility certificate for the reachability cone field and the flutter critical frequency field, and binds the joint feasibility certificate to the corresponding region in the design hypergraph.
[0014] Preferably, continuous relaxation programming sets continuous selection variables for candidate process edges in the process resource hypergraph, and transforms the continuous solution into discrete process parameters that satisfy resource mutual exclusion constraints and sequence constraints through constraint projection based on type system.
[0015] Preferably, the safe trajectory is generated by applying inequality constraints to the machine tool pose and control input using a control obstacle function, and solving the constrained optimization problem in discrete time steps to ensure that the trajectory meets the safety requirements.
[0016] Preferably, the measurement path is generated in the target area through harmonic field contour lines, and the visibility and incident angle are formally verified to form a process certificate, which is then bound to the measurement edge in the process resource hypergraph.
[0017] Preferably, the minimum hit set is solved based on the bipartite graph between the triggering factors of the counterexample set and the violated constraints. After the contract patch configuration patch and process patch are written back, the previous solution state is used as the initial value to perform local re-solution, and the revision record and certificate version are written to the evidence log.
[0018] Compared to existing technologies, the advantages and beneficial effects of this invention are as follows: Through unified modeling of design contracts and design hypergraphs, it achieves computable expression and bidirectional traceability of requirement clauses, geometric objects, and constraints; through differentiable physical models and homotopy constraint optimization, it achieves endogenous satisfaction of contract clauses by configuration parameters during the design phase; through analytical geometry construction of reachability cone fields and dynamic modes to obtain flutter critical frequency fields, it achieves pre-constraints for manufacturing feasibility and processing stability; through square sum form verification to generate feasibility certificates, it achieves constructive proof and versioned archiving of "reachability and stability" within the regional domain; and through process resource hypergraphs... Continuous relaxation programming of graphs and constraint projection based on type systems enable guided solutions and type correctness assurance for large-scale processes; generating safe trajectories through control obstacle functions enables online assurance and verifiable recording of collision, line-of-sight, and stability margins; generating measurement paths through harmonic field contour lines and binding them to certificates enables full-segment compliance and rapid reuse of visibility and incident angles; achieving minimal intervention, local re-solution, and local re-verification closed loops for changes through minimum hit sets based on counterexample sets and three types of patch write-backs; and establishing a unified evidence base for release review, quality traceability, and cross-model migration through evidence logs. Attached Figure Description
[0019] Figure 1 This is a flowchart illustrating the method of the present invention. Detailed Implementation
[0020] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.
[0021] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0022] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0023] like Figure 1As shown, a human-machine collaborative aerospace design method includes the following steps:
[0024] It receives multi-source design inputs, compiles design rules and engineering boundaries into a design contract, and establishes a design hypergraph in the graph structure;
[0025] Preferably, the multi-source design inputs include natural language, engineering sketches, images, and interactive parameters. The design contract is compiled and generated using a contract description language and bound to the design hypergraph with constraint edges and reference nodes.
[0026] In the human-machine collaborative aerospace design of this invention, multi-source design inputs are received and design rules and engineering boundaries are compiled into a design contract. Simultaneously, a design hypergraph is established within a graph structure, serving as the sole source of facts for subsequent configuration generation and process planning. The principle behind this step is to transform human expressions and corporate specifications into computable constraints and preferences, and to uniformly represent geometric objects, process objects, and inspection objects, along with their interdependencies, using a graph structure. This enables traceable optimization and verification in subsequent steps.
[0027] The reception and standardization of multi-source design inputs involves four channels. Natural language is parsed into structured clauses using a terminology dictionary and syntactic templates, distinguishing between hard constraint clauses, preference clauses, and explanatory clauses. Engineering sketches are vectorized to obtain splines and baselines, preserving control vertices, orders, and connectivity relationships, and recording their subordinate relationships with the baseline chain. Images are segmented and semantically labeled to obtain intent heatmaps, marking design interest areas, occlusion risk areas, and clamping candidate areas. Interaction parameters are normalized and standardized into a parameter set, including importance weights and regional scope. All results are stored in a unified measurement system, with the source and confidence level indicated in the entries to ensure consistent meaning in subsequent calls.
[0028] The design contract is compiled using a contract description language. This language allows three types of sentence structures. Environmental assumption clauses are used to fix machine tool travel, tool magazine, temperature range, and vibration spectrum range. Guardian function clauses are used to constrain indicators such as curvature continuity, minimum thickness, datum transfer, clamping accessibility, measurement visibility, and chatter margin. Preference clauses are used to express visual streamlines, lightweight preferences, and region weights. For guards that are difficult to differentiate, both differentiable proxies and strict check entries are registered, and their invocation order and triggering conditions are identified in the contract. The contract undergoes consistency checks during compilation, including unit and dimension consistency checks, threshold range and boundary conflict checks, and region overlap priority checks. After passing the checks, a versioned contract object is generated, and a binding table is recorded between clauses and geometric entities and process resources.
[0029] The design hypergraph uses a graph structure to represent design facts. The node layer includes geometric fragment nodes, feature nodes, datum nodes, clamping surface nodes, probe position nodes, and line-of-sight cone nodes. The hyperedge layer includes adjacency relationships, dependencies, constraint binding relationships, and candidate relationships. The intent heatmap is transformed into a set of regions and a weight mask, which is then attached to the geometric fragment nodes via mask hyperedges. Each constraint binding relationship points to a specific clause in the contract, while also referencing its gradient hints or strict check entry points. This forms a two-way index from clauses to geometric and process objects, allowing for rapid location of subsequent optimization and verification based on scope.
[0030] The key implementation details of this step include two points. First, clause computability. Each guard function clause corresponds to an evaluation interface and visible input / output specifications. The interface name is consistent with the contract clause number, and temporary abbreviations are not used. Second, fine-grained binding. Constraint binding relationships are not only associated with a single geometric fragment node, but also record the spatial weight of the constraint within the region set and save the propagation direction with the baseline chain, facilitating subsequent form and position error evaluation and the generation of process sequence constraints.
[0031] The benefits of this step are reflected in three aspects. First, the loss from semantics to constraints is controllable. Natural language, sketches, and images are transcribed into contract terms and graph structure objects under unified terminology and metrics, avoiding ambiguity caused by multiple names for the same concept. Second, constraints are traceable. Any subsequent decision can be traced back to the terms and input sources along the constraint binding relationship, facilitating design review and compliance audit. Third, the solution is verifiable. Because there is a one-to-one correspondence between contract terms and graph structure nodes, subsequently generated certificates and process certificates can be directly attached to the same objects, forming a verifiable chain.
[0032] Example Description. The objective is a human-machine collaborative design for the reentry capsule's outer shell and window area. Designers provide natural language descriptions, specifying requirements for surface continuity, window field of view, weight control, and measurement access, along with engineering sketches annotated with streamline directions. Priority for window boundaries is set via interactive parameters. The system parses the natural language into hard constraint clauses and preference clauses, converts the engineering sketches into spline sets and generates a reference chain, and performs image segmentation to obtain an intent heatmap of the window perimeter and outer shell. The contract description language is compiled to obtain contract objects, including minimum thickness clauses, curvature continuity clauses, clamping accessibility clauses, measurement visibility clauses, and flutter margin clauses, and registers the visual preference weights for the window area. The design hypergraph establishes geometric segment nodes representing the outer shell pieces and window chamfer pieces, establishes reference nodes representing reference A and reference B, and establishes clamping surface nodes and probe position nodes. Constraint binding relationships associate the minimum thickness clause with the outer shell pieces, bind the measurement visibility clause with the window chamfer pieces and line-of-sight cone nodes, and include area weight masks. Contractual consistency checks confirm that there are no unsatisfactory intersections between thickness thresholds and travel ranges, and between safety horizons and structural continuity. In subsequent steps, this embodiment directly reads the contract and hypergraph for configuration optimization, accessibility and flutter assessment, and process planning. All generated certificates and trajectory safety results can be backed onto the base object. During design reviews, source clauses and data evidence can be viewed at each node, thereby achieving an auditable and traceable design process under human-machine collaboration.
[0033] Under the constraints of the design contract, the configuration parameters are constrained and optimized in a differentiable physical model to obtain the configuration parameters that satisfy the requirements. The reachability cone field is calculated using analytical geometry methods, the flutter critical frequency field is calculated using a dynamic model, and a feasibility certificate covering reachability and stability is generated through formal verification.
[0034] This invention, under the constraints of a design contract, optimizes configuration parameters using a differentiable physical model, and constructs an accessibility cone field and a flutter critical frequency field using analytical geometry and dynamic models, respectively. Finally, a feasibility certificate covering accessibility and stability is generated through formal verification. This process unifies key criteria from the design and manufacturing sides into a computable and verifiable framework, avoiding repeated rework in subsequent processes.
[0035] The differentiable physical model in this invention refers to a physical computational kernel capable of providing continuous derivative information for minute changes in geometric and material parameters, including geometric smoothing, local stiffness and mass estimation, and modal response evaluation. The design contract provides hard constraints and preference clauses, upon which the differentiable physical model establishes its objective and constraint functions. The core optimization problem is expressed as follows: g i (θ)≤0,i=1,…,m, where θ is the configuration parameter vector, J(θ) is the geometric and structural integration objective under region weights, and g i(θ) is the guard function obtained by compiling the design contract. The gradient method with Lagrange multipliers is used in combination with step-size backtracking to ensure convergence. The derivative is obtained by automatic differentiation, thus achieving contract satisfaction without introducing discontinuous heuristics.
[0036] The reachability cone field is used to characterize the tool or measure the set of permissible incident directions of the line of sight at each surface point. This invention employs analytical geometry to determine the intersection of rays and solids in three-dimensional space, defined as follows:
[0037]
[0038] Where x is a point on the surface, d is the unit direction vector, n(x) is the normal at that point, α is the maximum allowable angle, and solid(θ) is the solid geometry defined by the configuration parameters. The reachability index is obtained by calculating the solid angle volume of the direction set, and then integrated over the region to form a regionalized lower bound. Analytic geometry intersection is used to avoid missed sampling. The direction set is expressed using a spherical parametric mesh and boundary curves for easy binding with subsequent certificates.
[0039] The flutter critical frequency field reflects the coupling relationship between the machining stability domain and geometric stiffness. This invention calculates the equivalent stiffness and equivalent mass at the regional scale and provides an estimate of the critical frequency accordingly.
[0040]
[0041] Where Ω crit (x) is the critical angular frequency at that position, k eff (x) represents the equivalent stiffness, m eff (x) represents the equivalent mass. The equivalent parameters are derived from the local modes of the differentiable physical model or the simplified beam-shell model, ensuring consistency with the configuration parameters. This provides a stability criterion in the parameter space and cross-constrains it with the reachability results. To solidify reachability and stability in a verifiable manner, this invention uses formal verification to generate a feasibility certificate. First, a polynomial approximation is performed on the reachability index and critical frequency in each region, denoted as:
[0042] p1(x) = vol(K(x)) - κ min
[0043] p2(x)=Ω crit (x)-Ω min
[0044] Where vol(K(x)) is the reachability solid volume, κ min Ω is the reachability threshold. min Let be the frequency threshold. Then, within the contract-bound parameter domain, find a sum-of-squares decomposition such that p1(x) and p2(x) can be expressed as the sum of a combination of a nonnegative polynomial and a polynomial generated by the domain constraint, if a corresponding multiplier σ exists.j If the above expression holds true, then a proof object that simultaneously satisfies accessibility and stability within the region is obtained. The certificate is stored as structured data and applicable domain, and bound to the corresponding node and region of the design hypergraph for direct reference in subsequent process planning.
[0045] The effects of this invention are reflected in three aspects. First, the optimization results are coupled synchronously with manufacturing feasibility. While meeting the design contract, the configuration parameters also guarantee the lower bound of local clamping and measurement accessibility, as well as the lower bound of processing stability frequency, avoiding conflicts such as "can be done but not stable" or "can be stable but cannot proceed" in subsequent processes. Second, the verification results are reusable. Feasibility certificates are managed with the design version, and subsequent verification only needs to be performed locally within the change domain, significantly reducing global recalculation. Third, human-machine collaboration is transparent. The human-machine interface displays the accessibility boundaries, critical frequencies, and certificate status of each region, making the impact of adjustments clear to designers.
[0046] Example: Configuration synthesis is performed on the transition area between the outer shell and the hatch of the return capsule. Curvature continuity, minimum thickness, clamping accessibility, and flutter margin clauses are set according to the design contract. A differentiable physical model is used to parameterize the configuration parameters using shell elements and local ribs, and the geometric and thickness distributions of satisfaction are obtained by solving using the gradient method. An accessibility cone field is constructed for each surface point around the hatch, and the solid angle volume distribution is obtained using normal angle constraints and solid occlusion judgment. Equivalent stiffness and equivalent mass are calculated in the same region, and a critical frequency distribution is generated. Polynomial approximation is performed on two types of functions in this region, constructing a sum-of-squares constraint to obtain a joint certificate proving p1(x)≥0 and p2(x)≥0, and the certificate is bound to the geometric segment nodes of this region. This example directly uses the certificate to limit the feasible set of process parameters and tool attitudes during process planning, achieving seamless integration from design to manufacturing.
[0047] Preferably, the constraint optimization in the differentiable physical model adopts the Lagrange multiplier method, and the constraints are tightened step by step according to the homotopy strategy to obtain the configuration parameters of satisfaction.
[0048] This invention employs the Lagrange multiplier method and homotopy strategy to optimize configuration parameters under design contract constraints. The design contract provides hard constraints and preference clauses, and the differentiable physical model is constructed with automatically differentiable numerical operators, covering geometric smoothness, equivalent stiffness and equivalent mass assessment, and local strain energy and mass distribution estimation, thereby providing stable gradients for small changes in configuration parameters. The optimization problem in the application of this invention is formulated as follows: g i (θ)≤0, i=1,…,m, where θ is the configuration parameter vector, J(θ) is the geometric and structural objective aggregated by region weight, and g i(θ) is the guard function obtained by compiling the design contract. To avoid infeasibility or oscillations from direct solution, this invention tightens the constraints stepwise along the homotopy parameter, defined as follows:
[0049]
[0050] σ i Let be the relaxation quantity, and τ be the homotopy parameter, initially less than 1. The corresponding Lagrangian function is:
[0051]
[0052] λ i Let be a Lagrange multiplier. According to the necessary conditions of KKT, the satisfaction point must satisfy both the standing condition and the complementarity condition. To obtain this point, this invention employs a primitive-dual iteration with backtracking search, and the update formula is:
[0053]
[0054] Where α k Let ρ be the step size and ρ be the multiplier update coefficient. If the current homotopy level reaches... The homotopy parameter is then increased by a preset step size; if this increase is violated, the step size is decreased or the homotopy parameter is rolled back, and the multiplier is adjusted on the active constraint to maintain iterative stability. All the above derivatives are obtained automatically from the differentiable physical model, avoiding noise caused by numerical differences.
[0055] The homotopy strategy in this invention transforms "difficult contracts" into "easy contracts" through continuous transformation, enabling feasible trajectories to traverse local traps in non-convex regions. The initial relaxation amount is set according to historical design or engineering boundaries. Low-energy solutions are first searched on the relaxed contracts, and then the constraint strength is gradually increased. The original dual variables provide "dual pressure" indicating the spatial distribution of active constraints, which is displayed in real-time on the human-machine interface for weight adjustment. To ensure consistency in regional focus, the objective function uses a regional weight mask as the integration weight, ensuring that the gradient primarily acts on the region of interest, reducing perturbations in irrelevant areas.
[0056] The advantages of this invention are reflected in three aspects. First, feasibility is controllable: each contract layer under homotopy advancement has clear tolerance and multiplier convergence criteria, avoiding significant infeasibility caused by one-time tightening. Second, gradient reliability: the operators of the differentiable physical model remain numerically stable, and the primal-dual iteration does not rely on discontinuous heuristics, facilitating convergence under large-scale parameter dimensions. Third, human-machine collaboration is transparent: dual pressure and active constraints are output in a structured manner, allowing designers to directly see at the interface layer which type of clause dominates the current deformation, thus enabling informed choices.
[0057] Example: Optimization is performed on the transition area between the outer shell and the hatch of the return capsule. The configuration parameter vector includes shell thickness distribution, surface control points, and local fillet radii. The guard functions of the design contract include curvature continuity, minimum thickness, and form and position transfer clauses. Clamping reachability and flutter margin-related thresholds are set but retained as constraint functions in this step. The initial homotopy parameter is less than 1, and the relaxation amount is set based on the enterprise experience database. Iteration proceeds in a primitive dual manner, using a backtracking search step size, with fixed multiplier update coefficients. Whenever the maximum violation is below the tolerance, the homotopy parameter is increased; if the violation increases, the homotopy parameter is rolled back and the multipliers are strengthened on the active constraints. After approximately 10 increases, the homotopy parameter reaches 1, and the configuration parameters simultaneously satisfy the curvature continuity and minimum thickness clauses. The system records the peak distribution of the dual pressure at the hatch boundary, and the interface indicates that this area is a key region for subsequent reachability and stability assessments. The optimized configuration parameters directly enter the calculation stage of the reachability cone field and flutter critical frequency field; the results of these two calculations will be further used for certificate generation and process planning. Through the above process, designers can obtain satisfactory configurations with fewer interactions, while retaining clear constraint progression paths and dual information, which facilitates review and reuse.
[0058] Preferably, the calculation of the accessibility cone field involves determining the analytical geometric intersection of the tool axis direction and the surface patch in three-dimensional space, and calculating the solid angle volume of the legal direction set to obtain a regional accessibility index.
[0059] In the context of integrated design and manufacturing, this invention uses the accessibility cone field as a unified quantitative object for geometric accessibility and process feasibility. The core idea is to establish a local coordinate system for each surface point in three-dimensional space, analyze and determine the accessibility of the tool axis along each incident direction, and then measure the set of legal directions of the point using solid angular volume. This set is then summarized into an accessibility index field at a regional scale, serving as the basis for human-machine collaborative decision-making and subsequent formal verification.
[0060] To avoid missed sampling and numerical instability, this invention employs a two-level representation using analytical geometric intersection and spherical set operations. First, the surface geometry is represented by non-uniform rational splines or triangular meshes; obstacles include the part entity, clamping body, probe, and machine tool structure, accelerated by hierarchical bounding volumes. For a given point on the surface, an angular constraint on the incident direction is established based on the normal and the maximum allowable deflection angle. Then, starting from that point with a ray along the reverse incident direction, analytical intersection is performed between the ray and the entity. If there is no intersection within the allowable travel and the tool overhang and travel limits are satisfied, it is considered "passable".
[0061] To facilitate the calculation of solid angular volume, this invention embeds the set of legal directions into a unit sphere. Angular constraints correspond to the inner domain of the spherical cap, and occlusion corresponds to the outer domain of the curved polygon obtained by projecting the occluding volume onto the sphere. The intersection of these two domains yields the legal domain of the sphere. To obtain the volume, spherical polygon subdivision and curved triangulation are employed, and the solid angles of each subdomain are calculated and summed. This yields a scalar reachability at each surface point, which is then mapped to a heatmap visualization, providing a visual indication of key restricted areas in human-computer interaction.
[0062] To support subsequent parameter sensitivity analysis and linkage optimization, this invention maintains automatic differentiation paths during intersection and spherical operations. The derivatives of the intersection equations of rays with triangular patches and spline surfaces with respect to configuration parameters are obtained through implicit function differentiation; the derivatives of the occlusion projection boundary with respect to configuration parameters and clamping attitude are accumulated through the chain rule. Since the reachable domain exhibits non-smoothness at topological changes, this invention introduces smoothing barriers for angle constraints and occlusion constraints to ensure that derivatives are continuously and stably fed back to configuration optimization.
[0063] This invention only provides calculation formulas for the core quantitative relationships, and defines the set of legal directions and regional indicators as follows:
[0064]
[0065]
[0066]
[0067] Where x is a point on the surface, d is the unit incident direction vector, n(x) is the unit normal at that point, α is the maximum allowable deflection angle, ray(x,-d) represents the ray emitted from point x along the reverse incident direction, solid(θ) is the solid geometry defined by the configuration parameter θ, and L(d) is the required tool overhang along direction d. max Let dΩ be the maximum allowable overhang of the equipment, dΩ be the solid angle of the spherical element, and A(R) be the area of region R. Point-level accessibility κ(x) and region-level accessibility κ R The meaning remains consistent throughout the text.
[0068] Unlike traditional methods that only perform accessibility checks during the process programming stage, this invention provides accessibility cone fields and their derivatives during the configuration optimization stage, making the "machinability" condition intrinsic to the geometric generation and constraint satisfaction process. When designers adjust local surfaces or clamping candidates at the interface layer, the system provides millisecond-level feedback on accessibility heat and threshold exceedance alerts, avoiding occlusion issues that only surface later in the path generation stage. The accessibility cone field is also attached as a structured object to the geometric nodes and region edges of the design hypergraph, providing a candidate set for subsequent formal verification certificate generation and process planning to limit tool and measurement postures.
[0069] The advantages of this invention are reflected in three aspects. First, complete coverage: analytical intersection and spherical set operations avoid missed detections caused by sparse sampling, maintaining complete judgment in complex concave surfaces and multi-obstacle scenarios. Second, usable feedback: automatic differentiation provides sensitivity to configuration parameters and clamping attitude, directly participating in homotopy advancement and primal-dual updates, significantly reducing the number of infeasible backoffs. Third, convenient verification: point-level and region-level indicators can be directly compared with threshold clauses to form signatureable accessibility evidence, facilitating design review and manufacturing release.
[0070] Example: For the transition area of the return capsule window and the outer shell surface, two clamping attitudes are selected, and the maximum deflection angle and maximum overhang are set. The surface is described by non-uniform rational splines, and the obstacle includes the internal ribs of the outer shell and the clamping claws. The system establishes a normal and local coordinate system at each sampling point, calculates the spherical cap corresponding to the angle constraint, and projects the ribs and clamping claws as spherical curved polygons; then, it performs ray and solid intersection analysis, removes the occluded directions, obtains the spherical legal domain, and calculates the solid angular volume. Point-level accessibility shows a significant decrease at the window boundary, and subdomains with regional accessibility below the threshold are marked. The designer increases the fillet radius at this boundary and fine-tunes the clamping attitude. The system provides the accessibility upward trend based on the derivative until the regional accessibility meets the contract threshold. The accessibility cone field and regional indexes generated in this example are then written into the design hypergraph and converted into accessibility certificates in subsequent formal verification, while limiting the tool axis attitude search domain of process planning to achieve continuous consistency from configuration to process.
[0071] Preferably, the flutter critical frequency field is calculated based on the equivalent stiffness and equivalent mass obtained from the dynamic modal model, and the critical frequency of the spatial location is determined according to the stability domain criterion.
[0072] This invention, within an integrated design and manufacturing framework, uses the flutter critical frequency field as a bridging variable between geometric configuration and processing stability. The core approach involves using a dynamic modal model to determine the equivalent stiffness and equivalent mass at a regional scale, thereby identifying the critical frequency for spatial location. Then, a stability domain criterion is used to directly constrain the critical frequency field to a feasible set of process parameters and clamping postures, enabling real-time replacement selection under human-machine collaboration.
[0073] The dynamic modal model originates from modal truncation of the configuration parameter-driven structural model, yielding the mass matrix, stiffness matrix, and several mode pairs. To ensure consistency with the differentiable physical model, the modal vectors and characteristic frequencies remain differentiable with variations in configuration parameters. For any point on the surface and the tool axis or the force incidence direction, an equivalent distribution vector of the unit direction load on the discrete degrees of freedom is constructed, and directional compliance is obtained using modal superposition. The core expression for directional compliance is defined as follows:
[0074]
[0075] Where x represents a point on the surface, φ r Let ω represent the r-th mode vector. r Let represent the r-th natural angular frequency, b(x) represent the equivalent distribution vector of unit force at point x along the incident direction, and p represent the retained modal order. The equivalent stiffness is obtained from the directional compliance. The equivalent mass is represented by the kinetic energy equivalent mapping m. eff (x)=b(x) T Mb(x), where M represents the mass matrix. This leads to the critical angular frequency field: The meaning of the above letters remains consistent throughout the text and will not be repeated.
[0076] To utilize the critical frequency field for stability constraints, this invention employs a stability domain criterion: for the planned principal axis angular frequency and the contact position of the direction, the planned principal axis angular frequency must not exceed the product of the critical angular frequency and the margin coefficient, where the margin coefficient is denoted as η and its value is within an open interval. This criterion displays the "stability margin" in the form of a heatmap at the interface layer. When the local configuration or clamping attitude changes, the critical frequency field and stability margin are updated immediately. To avoid gradient jumps caused by local non-smoothness, this invention smooths the mapping between modal participation coefficients and directional loads, and uses shape function interpolation and total variation regularization in the region, making the critical frequency field spatially smooth and maintaining a differentiable relationship with the configuration parameters, facilitating homotopy advancement and primal-dual updates.
[0077] The advantages of this invention are reflected in three aspects. First, early manufacturability constraint endogenization: the critical frequency field can be incorporated as a hard or soft constraint during the configuration optimization stage, avoiding "geometric satisfaction but manufacturing instability". Second, intuitive human-machine collaboration: designers can directly see the low critical frequency region and dominant modes in the view, and make informed adjustments based on the sensitivity of equivalent stiffness and equivalent mass. Third, certification and reuse: the critical frequency field is approximated by a polynomial within the region, and a joint feasibility certificate is generated together with the reachability index, which only needs to be re-verified locally in the changed subdomain later.
[0078] Example: For the transition area between the outer shell and the hatch of the return capsule, a finite element model including the outer shell and ribs is constructed. The first p=6th order modes are extracted, generating the mass matrix, stiffness matrix, modal vector, and natural angular frequency. The incident direction of the tool axis is selected, and the equivalent distribution vector of the unit direction load is constructed by nodal interpolation. The equivalent stiffness is calculated according to the directional compliance formula, and the equivalent mass is obtained by kinetic energy equivalent mapping, thus forming the critical angular frequency field. The results show that there is a low critical frequency band above the hatch boundary. The designer moves the position of the ribs in this band outward and slightly increases the shell thickness in the interface. The system updates the directional compliance, equivalent stiffness, and equivalent mass in real time, and the critical angular frequency is significantly raised. Then, the updated critical frequency field is written into the design hypergraph together with the previously obtained accessibility cone field, and the "allowable interval" for the combination of spindle angular frequency and tool overhang is given according to the stability domain judgment criterion, forming a joint feasibility certificate for the process planning to limit the parameter search domain. Through this example, the critical frequency field achieves continuous connection from configuration to process, enabling design and manufacturing decisions to converge within the same data and evidence system.
[0079] Preferably, the formal verification uses the sum of squares method to generate a joint feasibility certificate for the reachability cone field and the flutter critical frequency field, and binds the joint feasibility certificate to the corresponding region in the design hypergraph.
[0080] This invention introduces a formal verification-generated joint feasibility certificate within a design-and-manufacturing integrated framework. This certificate simultaneously proves that the reachability cone field and the flutter critical frequency field meet the thresholds of the design contract. The certificate is then linked to the corresponding region in the design hypergraph, serving as a reliable basis for subsequent process planning and change review. The core idea is to perform polynomial approximation of the continuous field within the region, transforming threshold comparison into a nonnegativity determination over a semi-algebraic field, and finally providing a constructive proof using the sum-of-squares method.
[0081] Within each candidate region, the region is first mapped to the standard square domain using local coordinates. An orthogonal polynomial is then used to fit the reachability solid angular volume field and the critical frequency field, yielding a two-term polynomial approximation. Subsequently, two polynomial functions to be proven to be nonnegative are defined, and the expression for the threshold difference is given:
[0082]
[0083] Where u is the local coordinate. For the polynomial approximation of the reachable solid angular volume, For the polynomial approximation of the critical angular frequency, κ min Ω is the lower bound for reachability. min h is the lower bound of the frequency. The standard square domain of the region is described by the set of polynomial inequalities h. l (u)≥0. The sum-of-squares method uses this to find sum-of-squares multipliers such that both functions are non-negative within the region:
[0084]
[0085] Where, σ r0 (u) and σ rl (u) is a sum-of-squares polynomial, r∈{1,2}. If the above equation has a solution, a joint feasibility certificate for the region is obtained; the certificate contains the coefficients of the two polynomials, the coefficients of the sum-of-squares multipliers, the domain description polynomial, the approximation order, and the numerical tolerance.
[0086] To ensure consistency between the certificate and the design data, the certificate is attached to the region edge of the design hypermap as a structured object, and the valid domain, threshold source, and corresponding geometric fragment node identifier are marked. When a region, thickness, or rib location is locally modified, only the two polynomials are reconstructed in the affected region and the sum of squares problem is resolved. The certificate version is updated accordingly, while historical versions are retained to support change auditing.
[0087] This mechanism offers three direct benefits for human-machine collaboration. First, evidence is portable. Certificates, as small-volume data, migrate between different design branches across regions, eliminating the need for large-scale recalculation of numerical fields. Second, diagnosis is clear. If the sum-of-squares problem has no solution, the system returns the difference between the location of the maximum violation and the corresponding threshold, allowing the human-machine interface to suggest increasing accessibility or raising the critical frequency in a specific subdomain. Third, linkage constraints are natural. Process planning directly reads the certificate and restricts parameters such as tool axis posture and spindle angular frequency within the domain where the proof is valid, avoiding inefficient loops of generation followed by rollback.
[0088] Example: For the transition area of the return capsule window, based on the discrete evaluation results of the accessibility cone field and the critical frequency field, a polynomial of fixed order is fitted to this area to obtain a two-term polynomial approximation. Lower bounds for accessibility and frequency are set, and a two-term threshold difference function is constructed. Using the boundary polynomial of the standard domain of the area as the domain constraint, two sum-of-squares constraints are established, and the semidefinite programming problem is solved after selecting the multiplier order. The solution is then used to form a certificate object containing the coefficients of the two-term polynomial, the sum-of-squares multiplier coefficients, the domain description coefficients, the order, and the tolerance, and is bound to the edge of this area in the design hypergraph. After the designer increases the fillet radius of the window boundary and fine-tunes the rib position, the fitting and solution are reconstructed only in this area, and the certificate is automatically upgraded. The process planning is based on this to limit the candidate set of the tool axis incident direction and the spindle angular frequency, ensuring that both tool attitude and machining stability are satisfied simultaneously, thereby achieving continuous consistency and verifiability from configuration to process.
[0089] A process resource hypergraph is constructed on the design hypergraph, continuous relaxation programming is performed, discrete process parameters are obtained through constraint projection based on type system, a safety trajectory is generated using control obstacle function, a measurement path is generated, and process certificates and feasibility certificates are compiled.
[0090] This invention constructs a process resource hypergraph based on the design hypergraph, and typifies and associates geometry, datum and region constraints with clamping, tools, machine tool channels and measurement resources. Discrete process parameters are obtained by continuous relaxation programming and constraint projection based on type system. At the same time, safe trajectories are generated by using control obstacle functions and measurement paths are generated by field functions. The above results are compiled into a process certificate and linked with a feasibility certificate to form verifiable process-level evidence.
[0091] The process resource hypergraph stores three types of nodes and two types of hyperedges using an identifier system derived from the design hypergraph: process nodes, resource nodes, trajectory nodes, as well as constraint-bound hyperedges and candidate relationship hyperedges. Each candidate relationship hyperedge carries constraint references, reachability references, and stability references, making process selection subject to the joint constraints of contract terms, reachability cone fields, and flutter critical frequency fields.
[0092] Continuous relaxation programming is used to make differentiable global selections from a set of candidate edges. The selection variable for the candidate edge set is defined as s. k Cost and timing evaluation is c k The soft-constraint residuals are aggregated into g. j (s), the penalty is γ j The core objective is:
[0093]
[0094] in Let R represent the set of candidate processes for region R, [·] + For nonnegative operators, 0 ≤ s k ≤1. The gradient of the selected variable is automatically passed by the reachability and stability approximation polynomials bound to the candidate edges, making the process selection sensitive to design-level evidence. Constraint projection based on the type system maps continuous solutions to discrete process parameters that satisfy session type and resource mutual exclusion. Let the type-synthesizable domain be... Projection writing Where p is a discrete process parameter. To maintain resource mutual exclusion, sequential causality, and the minimum modification projection operator for the locking and releasing protocol. If the type is not synthesizable, the system returns the conflict set and adds the corresponding penalty to the continuous relaxation objective, solving again until it is synthesizable.
[0095] The safe trajectory generation uses an obstacle control function to correct the robot pose or machine tool joint trajectory online. Let the system state be q, the control input be u, the obstacle function be h(q), and the nominal input be u. nom The gain is α>0. Solve for each discrete time step:
[0096]
[0097] in The solution is derived from the composite obstacle function consisting of the kinematic and geometric safety shell, the line-of-sight cone redundancy, and the stability margin, ensuring that the trajectory always maintains a positive safety margin. This quadratic programming solution is also recorded as part of the process certificate.
[0098] The measurement path generation constructs a family of contour lines within the region using a harmonic field and is linked to the measurement visibility and incident angle threshold. The harmonic potential within the region is defined as ψ, satisfying Δψ = 0.
[0099] When the boundary conditions are jointly set by the reference chain, occlusion edge, and device travel, the contour line with ψ = c is taken as the scanning path. The path density and attitude are filtered by a polynomial approximation of visibility and incident angle, and the results of comparing the filtered path set with its threshold are written into the process certificate.
[0100] The compilation of evidence follows the principles of "traceable source, identifiable domain, and comparable version." The process certificate comprises three elements: first, a synthesizable evidentiary fragment of the selected and projected path; second, obstacle redundancy curves and constraint satisfaction records for the safety trajectory; and third, the visibility and incident angle criterion results of the measurement path. The feasibility certificate, serving as the entry point for design-level evidence, provides domain constraints on accessibility and stability. Both types of certificates are bound together by reference relationships at the region and process edges, ensuring that any process modification can be traced back to the design contract and geometric references.
[0101] The mechanism demonstrates its effectiveness in human-machine collaboration in three aspects. First, planning is guided: the gradient of continuous relaxation planning is directly influenced by the certificate, and the selection tends to automatically avoid unreachable or unstable candidate paths. Second, execution is feasible: type projection and control barrier functions ensure that discrete processes and trajectories meet resource and safety constraints, reducing offline parameter tuning. Third, review is verifiable: process certificates and feasibility certificates are archived in a unified format, and local changes only trigger local re-verification, shortening the cycle.
[0102] Example: For the finishing and scanning inspection of the outer shell of the return capsule window transition area, firstly, the geometric segments and reference chains of this area are selected in the design hypergraph, automatically generating candidate edges for clamping, tools, and probes, and constructing a process resource hypergraph. Through continuous relaxation programming, the continuous selection results of clamping attitude, tool axis attitude, and tool path strategy are obtained, and then... Projection yields discrete process parameters that satisfy resource mutual exclusion and sequence protocols. Subsequently, quadratic programming of the control obstacle function is solved on three types of trajectories: tool feed, tool retraction, and probe approach, resulting in positive obstacle redundancy curves. Within the same region, Δψ = 0 is solved, and several contour lines with ψ = c are selected as measurement paths. Visibility and incident angle thresholds are verified point-by-point for each path. The system archives the projection synthesis conclusion, obstacle redundancy curves, measurement threshold determinations, and their referenced reachability and stability feasibility certificates as a process certificate, binding them to the region edge and the corresponding process edge. If subsequent design layers make minor adjustments to fillet radii or rib positions, continuous relaxation and type projection are re-executed only in the affected subdomains. The original safe trajectories and measurement paths are locally reused according to certificate references, achieving a rapid closed loop from design to execution.
[0103] Preferably, continuous relaxation programming sets continuous selection variables for candidate process edges in the process resource hypergraph, and transforms the continuous solution into discrete process parameters that satisfy resource mutual exclusion constraints and sequence constraints through constraint projection based on type system.
[0104] This invention transforms discrete process selection into differentiable continuous optimization in a process resource hypergraph, and then restores it to executable discrete process parameters through constraint projection based on a type system, achieving guided planning and verifiable implementation under human-machine collaboration. The process resource hypergraph represents processing, clamping, measurement, and motion elements with process nodes, resource nodes, and trajectory nodes. Candidate process edges carry references to design contracts, reachability cone fields, and flutter critical frequency fields, thus being directly constrained by design-level evidence during the planning stage.
[0105] Continuous relaxation programming takes candidate process edges as the decision objects, sets continuous selection variables for each candidate process edge, and performs constrained optimization under the comprehensive objectives of cost, time, and quality risk:
[0106]
[0107] Among them, s k For the continuous selection variable of the candidate process edge, 0≤s k ≤1, c k γ represents the total cost of this edge. j For the penalty power of the j-th soft constraint, g j (s) represents the residual aggregation related to the reachability cone field or flutter critical frequency field, [·] + For nonnegative part operators, Let R be the candidate set for region R. The gradient of the objective is automatically passed by the feasibility certificate polynomial bound to the candidate edges, making the selection sensitive to evidence of "reachability" and "stability". The optimized solution can be updated instantly when the designer adjusts the weights or candidate set in the interface.
[0108] To ensure executable sequences and resource allocation, this invention introduces constraint projection based on a type system. First, it defines the legal state sequences and transition rules for each resource type based on resource session type. Clamped resources follow a "lock-use-release" pattern, while probe resources follow a "zeroing-approach-measurement-zeroing" pattern. Then, it defines causal relationships between processes using partial order constraints, such as "roughing precedes finishing" and "finishing precedes measurement." These rules are then used to form a type-synthesizable domain. Apply minimum modification projection to continuous solutions:
[0109]
[0110] Where p is a discrete process parameter. The projection operator satisfies resource mutual exclusion and order constraints. If a non-synthesizable solution is encountered, the system derives a minimum conflict set, adds the corresponding violation to the penalty term of the continuous objective, and solves again until a type-synthesizable discrete solution is obtained. This closed loop of "continuous selection—type projection—conflict writeback" enables the search of the combinatorial space to converge based on gradient-driven and type-correctness-based approaches.
[0111] From a human-machine collaboration perspective, continuous relaxation planning provides a visualized "selection heat," and the minimum modification step size returned by type projection is presented at the interface layer as "the necessary adjustment from scheme A to scheme B." Designers can make preference decisions within the boundaries of satisfying evidence and type. Since all constraints and evidence come from a unified carrier, discrete results can be directly incorporated into the trajectory solution of the control barrier function and the generation of the harmonic field measurement path. The process certificate is then compiled, forming a seamless connection from planning to execution.
[0112] The advantages of this invention are reflected in three aspects. First, it reduces the risk of combinatorial explosion: continuous variables converge within a differentiable space, and type projections only undergo local minimum modifications. Second, it ensures consistent evidence: feasibility certificates participate in the objective and constraints with domain constraints, avoiding posterior unreachability or unstable processes. Third, it is audit-friendly: type-synthesizable proof fragments and conflict sets are recorded in a structured manner, providing the source and reasons for modification for any discrete decision.
[0113] Example: In the finishing and measurement tasks in the transition area of the return capsule window, the process resource hypergraph includes candidate process edges for clamping, roughing, finishing, and measurement, as well as three types of resource nodes. When constructing the objective function, the cost term is superimposed with time and tool change count, and the residual term comes from the lower bound of the reachability and the lower bound of the critical frequency of the region. Continuous solving yields high selection values for several candidate process edges. Type projection is based on the session type and partial order constraint of "clamping lock—roughing—finishing—measurement—clamping release," outputting coherent discrete process parameters. A conflict of "simultaneous occupation of probe and tool resources" occurs during the first projection. The system generates a conflict set and adds a mutual exclusion penalty term to the continuous objective. After a second solution, a sequence of mutually exclusive conditions is obtained. Finally, the discrete process enters the trajectory stage. The control obstacle function generates feed and approach trajectories with positive safety margins; the measurement path is filtered by harmonic field contour lines and passes through visibility and incident angle thresholds. The process certificate compiles discrete parameters, synthetic proof, and safety and measurement criteria, and binds them to the region edges with the feasibility certificate, providing verifiable evidence for subsequent changes.
[0114] Preferably, the safe trajectory is generated by applying inequality constraints to the machine tool pose and control input using a control obstacle function, and solving the constrained optimization problem in discrete time steps to ensure that the trajectory meets the safety requirements.
[0115] This invention introduces a control barrier function between process planning and trajectory execution, ensuring that the machine tool pose and control input consistently meet constraints related to geometric safety, line-of-sight geometry, and machining stability within discrete time steps. The control barrier function represents the safety requirements as a scalar function of the machine tool state and control input, and uses derivative inequalities to constrain nominal control at each time step, thereby obtaining an executable trajectory that meets the safety requirements without altering the discrete process parameters.
[0116] The machine tool motion is represented using a control affine model, with the state denoted as q (including pose and joint variables), the control input denoted as u, the system vector field denoted as f(q), and the input matrix denoted as G(q). The family of obstacle functions is denoted as {h k (q)}, corresponding to the collision distance, measurement line-of-sight geometry, and machining stability margin, respectively. The control obstacle function condition is written as:
[0117]
[0118] in Let α be the gradient of the barrier function with respect to the state. k >0 is a class The linear gain of the function. This inequality guarantees that when h... k When (q)≥0, the system will not enter the unsafe set if the nominal control is modified.
[0119] This invention concretizes three types of engineering constraints into differentiable obstacle functions. The collision safety function uses the signed distance in the forbidden region, defined as h. col (q)=d(q)-d min Where d(q) is the minimum signed distance between the end and the containment shell, d min The minimum safe distance. The line-of-sight geometric safety function is represented by the angle between the surface point and the optical axis of the probe, defined as h. fov (q)=cosβ(q,x)-cosβ max Where β(q,x) is the angle between the pose and the measured point, β max The maximum allowable included angle. The machining stability safety function is defined using the aforementioned flutter critical frequency field:
[0120] h stab (q)=ηΩ crit (x(q))-Ω op
[0121] Where η is the stability margin coefficient, Ω crit (x(q)) is the critical angular frequency at the contact point, Ω op The planned principal axis angular frequency is given by the gradients of the three terms above, which are provided by differentiable geometric and differentiable physical kernels, ensuring their applicability to linearization constraints in trajectory optimization. A constrained quadratic optimization problem is solved at discrete time step t to correct the nominal control:
[0122]
[0123]
[0124] in For nominal control generated by discrete process parameters and interpolators, ξ t w is a slack variable. ξ This represents the relaxation penalty coefficient. The optimization is solved independently at each time step and warm-started with the solution from the previous time step, thus maintaining online feasibility with low computational load. If a constraint is maintained for a long period using relaxation variables, the system will write the constraint number, timestamp, and spatial location to a process certificate to indicate that the upper-level planning or configuration needs local adjustments.
[0125] To balance differentiability and conservatism, this invention employs smooth approximations for the non-smooth "minimum distance" and "minimum redundancy," introducing differentiable maximum and minimum value approximations in the calculation of the distance and angle fields. Simultaneously, the weight of the obstacle function automatically increases as it approaches the insecurity set, ensuring that the observable "safety redundancy curve" is monotonically non-negative. The reachability and stability regions in the joint certificate are incorporated into candidate process edges using hard constraints, controlling the obstacle function to only handle trajectory-level spatiotemporal constraints and avoiding redundant penalties.
[0126] The effects of this mechanism at the human-machine collaboration level include: First, on-the-fly verification. Each step of the trajectory generates constraint satisfaction records and safety margin curves, which are bound to the region object as part of the process certificate. Second, interpretable feedback. The interface displays the activity level and relaxation usage of each type of constraint using heat and curves, allowing designers to identify whether the safety pressure is caused by clamping posture, tool axis posture, or geometric curvature. Third, local reuse. When the configuration or process is fine-tuned locally, the optimization problem can be locally resolved within the affected time window, while existing solutions and evidence are reused for the remaining segments.
[0127] Example: For the finishing and measurement of the transition area of the return capsule window, a five-axis machine tool control affine model is constructed. The nominal control is generated by discrete process parameters and spline interpolation. The collision safety function uses a signed distance field based on a triangular mesh, the line-of-sight geometric safety function calculates the angle between the probe coordinate system and the normal of the measured point, and the stability safety function takes values from the critical frequency field according to the contact point and compares them with the planned spindle angular frequency. The system solves the quadratic optimization at a fixed frequency to obtain a continuous control correction sequence, generating feed, retraction, and approach trajectories with positive safety margins. When the path approaches the window boundary, the collision safety function relaxes. The system records this moment and spatial position in the process certificate. Based on the record, the planning layer fine-tunes the clamping posture and shortens the tool overhang. After the second solution, the relaxation disappears. The final generated safety trajectory, constraint satisfaction record, and safety margin curve are archived together and referenced on the region edge with the accessibility certificate and stability certificate to support subsequent review and change verification.
[0128] Preferably, the measurement path is generated in the target area through harmonic field contour lines, and the visibility and incident angle are formally verified to form a process certificate, which is then bound to the measurement edge in the process resource hypergraph.
[0129] This invention unifies the generation and verification of measurement paths within a framework of "harmonic field—contour lines—formal certificate," enabling path design, visibility constraints, and incident angle constraints to form a closed loop within the same data carrier. The core idea is to construct a harmonic potential function on the surface of the target region, using contour lines as non-self-intersecting, uniformly covered scanning trajectories. Then, a formal method is used to verify the visibility and incident angle segment by segment within the region. The verification results are then used as a process certificate and bound to the measurement edges of the process resource hypergraph for subsequent review and local reuse.
[0130] A local parameter domain and boundary classification are established on the surface of the target region. Dirichlet and Neumann conditions are applied to the allowed entry boundary, the prohibited entry boundary, and the reference datum, respectively. The Laplace-Beltrami equation of the surface is solved to obtain the harmonic potential function. The core equation is Δ S ψ = 0, where ψ is the harmonic potential function, Δ SIt is a Laplace-Beltramian operator on a surface. The contour lines of the harmonic potential function do not intersect each other and are orthogonal to the gradient, making it naturally suitable as a family of scanning trajectories; by intercepting curves at different contour values and adaptively setting the spacing according to curvature and tolerance, complex geometry can be covered without backtracking.
[0131] To define the measurement attitude and sampling density, the contour lines are parameterized by arc length. Let x be a point on the surface, t be the parameter of the contour line, n(x) be the unit normal, v(x) be the sensor's line-of-sight direction (unit vector), α(x) be the angle of incidence (the angle between the normal and the line of sight), and v(x) be the visibility rate (the reachable proportion after considering occlusion and field of view). The angle of incidence and line-of-sight constraints are expressed in cosine form to avoid numerical instability caused by inverse trigonometric functions. The core criterion is cosα(x) = |v(x)·n(x)|, cosα(x) ≥ cosα max , where α max The maximum permissible incident angle threshold is defined. Visibility v(x) is obtained by resolving occlusion in several directions within the sensor aperture and normalizing the result; its range is within the specified interval. The sampling interval along the trajectory is jointly set based on the potential function gradient and the principal curvature of the surface. Where Δs(x) is the sampling interval, τ m For measurement error tolerance, κ(x) is the principal curvature, and c κ These are the weighting coefficients. From this, we obtain the point sequence, attitude sequence, and sampling time series, forming a candidate measurement path set.
[0132] In the formal verification phase, the joint conditions of "path-pose-threshold" are transformed into a nonnegativity problem over a one-dimensional parameter domain. The arc length of each path interval is normalized to obtain t∈[0,1]. Visibility and cosine incidence angle are approximated using polynomials over this interval, denoted as [equations to be filled in]. and The joint constraint is written as:
[0133]
[0134] Where v min This is the lower bound for visibility. The sum-of-squares method is used to find the sum-of-squares multiplier σ over the interval. r0 (t) and σ r1 (t), so that q r (t)=σ r0 (t)+σ r1 The condition (t)t(1-t), r∈{1,2}, holds true for all cases. If a solution exists, then a constructive proof is obtained that the path segment satisfies the visibility and incident angle thresholds. The certificate contains the coefficients of the two approximation polynomials, the coefficients of the sum of squares multipliers, the identifiers of the intervals and thresholds, and records the numerical tolerance and order for subsequent consistency checks.
[0135] To achieve interpretable feedback under human-machine collaboration, the system superimposes a "certificate coverage band" on each contour line in the graphical interface, marking the intervals that have been proven qualified and the intervals that need to be repaired; when the designer adjusts the geometry or switches the probe attitude within the area, only the affected path segments are refitted and the sum-of-squares problem is solved, and the certificate version is automatically updated. A two-way reference is established between the certificate object and the measurement edge of the process resource hypergraph, and at the same time it is associated with the area edge of the design hypergraph to ensure the consistency of design-process-evidence.
[0136] The effects of this mechanism are reflected in three aspects. First, integration of path generation and constraint verification: The contour lines provide a stable coverage structure, and the formal certificate ensures the visibility and incident angle hold throughout the segment, avoiding the situation of "the path is feasible but locally fails". Second, efficient change reuse: The certificate is archived with small-volume data, and local geometric or attitude changes only trigger local re-verification without recalculating the entire domain. Third, complete audit chain: Each measurement edge is accompanied by path parameters, threshold sources, sum-of-squares multipliers and tolerances, facilitating quality review and release.
[0137] Example: In the transition area of the return capsule window, the window boundary and the outer cladding ring belt are selected as the target area, the allowable entry boundary is set as the outer edge of the window, and the prohibited entry boundary is set as the clamping jaw and the shielding edge. The harmonic potential function is obtained by solving the surface Laplace-Beltrami equation, several contour lines are intercepted as candidate paths, and the sampling interval is set according to the formula. The unit normal and visibility rate are calculated for each sampling point, and the attitude sequence is generated based on the cosine criterion. The visibility rate and cosine incident angle are fitted for each path segment in the interval, two sum-of-squares constraints are established and solved to obtain the joint certificate of all qualified segments; the proof fails for some intervals near the clamping jaw, and after it is marked on the interface, the designer fine-tunes the probe attitude and reduces the step size, and the local re-verification passes. Finally, the path set, attitude sequence, certificate object and threshold identifier are archived as the process certificate and bound to the corresponding measurement edge in the process resource hypergraph, providing a复验able basis for subsequent beat scheduling and quality acceptance.
[0138] Generate the minimum hitting set based on the counterexample set, synthesize the contract patch, configuration patch and process patch for backwriting, trigger local re-solving and re-verification, output the final configuration parameters and the final process resource hypergraph, and record the evidence log.
[0139] Preferably, the minimum hitting set is solved based on the bipartite graph between the triggering factors of the counterexample set and the violated constraints. After the contract patch, configuration patch and process patch are backwritten, local re-solving is performed with the previous solution state as the initial value, and the revision record and certificate version are written into the evidence log.
[0140] This invention, within an integrated design and manufacturing framework, uses a set of counterexamples to drive human-machine co-creation and selection. The core process involves extracting a set of triggering factors from the counterexamples, forming a bipartite graph with the set of violated constraints, obtaining the minimum hit set, and then synthesizing contract patches, configuration patches, and process patches. After writing back, it performs local re-solution and re-verification with the previous solution state as the initial value, while simultaneously writing the entire process into an evidence log to achieve evidence-oriented closed-loop improvement.
[0141] The set of counterexamples is derived from rigorous verification and trajectory-level safety checks. Each counterexample includes elements such as the violated guard number, spatial region identifier, clamping posture, tool overhang, and trigger trajectory segment. A bipartite graph is constructed with the triggering factor as the left vertex and the violated constraint as the right vertex, and factors are assigned weights. The weights are calculated by weighting the dual pressure, influence domain area, and estimated cost. The minimum hit set is solved using integer programming.
[0142]
[0143] x f ∈{0,1}
[0144] Where x f For the factor, select variable 0 or 1 to indicate whether factor f is selected or not. Set of triggering factors Let F(c) be the set of violated constraints, and w be the subset of factors that cover the violation of constraint c. f The factors are weighted. The hit set output by the model gives the minimum intervention surface.
[0145] Three types of patches are synthesized under hit set constraints. Contract patches localize threshold or weight clauses and perform synchronous consistency checks. Configuration patches solve the minimum norm increment problem within the trigger region. Where Δθ is the configuration parameter increment and W is the weight matrix s θ The sensitivity vector ε, given by the differentiable physical model, serves as the improvement threshold; Δθ only supports the trigger region. The process patch uses resource session type and partial order constraints as boundaries, replacing the clamping posture or tool family and limiting the tool axis posture and spindle angular frequency to fall within the joint feasible region.
[0146] After the patch is written back to the design contract, design hypergraph, and process resource hypergraph, a local re-solution is triggered. Both the differentiable physical model and continuous relaxation programming employ a warm start, with initial values derived from the previous configuration parameters and selection variables, respectively. Dual variables retain their previous values to maintain a consistent convergence direction. After re-solution, rigorous re-verification is performed only in the affected area and related processes. The joint feasibility certificate and process certificate are regenerated or upgraded, and the evidence version, change domain, polynomial order, and tolerance are recorded. The evidence log is indexed by time and object, supporting queries of change chains and evidence chains for a specific design object.
[0147] The mechanism's effectiveness in human-machine collaboration is threefold. First, precise localization. The minimum hit set reduces multiple counterexamples to a small number of intervention factors, minimizing ineffective modifications. Second, verifiable modifications. Each patch is accompanied by a new joint feasibility certificate or process certificate, avoiding reliance on trial and error alone. Third, stable convergence. Warm start-up and local re-verification avoid global recalculation, shortening the iteration time and maintaining solution continuity, allowing designers to make informed choices.
[0148] The example focuses on the transition area of the return capsule window. Rigorous verification yields three counterexamples: 1) insufficient lower bound for accessibility due to clamping posture; 2) negative stability margin due to tool overhang; and 3) probe line of sight obstructed by ribs. After constructing a bipartite graph, the hit set is selected based on three factors: clamping posture, fillet radius, and overhang. The system synthesizes three types of patches: Contract Patch (reducing curvature preference weight in the region without changing the safety threshold), Configuration Patch (increasing fillet radius in the boundary zone and slightly shifting rib position along the reference chain), and Process Patch (rotating the clamping posture by a fixed angle and shortening the overhang). After patch rewriting, local re-solution is performed using the old solution as initial values, updating the accessibility cone field and flutter critical frequency field. Type projection yields a new discrete process, and the control obstacle function generates a positive safety margin trajectory. After successful local re-verification, the log is written with the patch summary, hit set content, certificate number, and applicable domain, while marking the old certificate as a historical version. Finally, new configuration parameters and a new process resource hypergraph are formed, and the latest certificate is directly referenced during the measurement and machining stages, completing an evidence-based closed-loop selection process.
[0149] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects.
[0150] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A human-in-the-loop space design method, characterized by, The method comprises the following steps: Receiving multi-source design input, compiling design rules and engineering boundaries into design contract, and establishing design hypergraph in graph structure; Constrained optimization of configuration parameters in differentiable physical model under design contract constraints to obtain satisfactory configuration parameters, calculating reachable cone field by analytical geometry method, calculating flutter critical frequency field by dynamic model, and generating feasibility certificate covering reachability and stability through formal verification; Building process resource hypergraph on design hypergraph, executing continuous relaxation programming and obtaining discrete process parameters through constraint projection based on type system, generating safe trajectory using control barrier function, generating measurement path, and assembling process certificate and feasibility certificate; Generating minimum hit set based on counterexample set, synthesizing contract patch configuration patch and process patch for writeback, triggering local resolvation and revalidation, outputting final configuration parameters and final process resource hypergraph, and recording evidence log.
2. The method of claim 1, wherein, Multi-source design input includes natural language, engineering sketch, image and interactive parameter, design contract is compiled by contract description language, and is bound in design hypergraph by constraint edge and benchmark node.
3. The method of claim 1, wherein, Constrained optimization in differentiable physical model uses Lagrange multiplier method, and constraint is tightened step by step according to homotopy strategy to obtain satisfactory configuration parameters.
4. The method of claim 1, wherein, The calculation of reachable cone field determines the intersection point of tool axis direction and curved surface sheet in three-dimensional space by analytical geometry, and calculates the solid angle volume of legal direction set to obtain regionalized reachability index.
5. The method of claim 1, wherein, The calculation of flutter critical frequency field is based on dynamic modal model to obtain equivalent stiffness and equivalent mass, and determines the critical frequency of spatial position according to stability domain determination criterion.
6. The method of claim 1, wherein, Formal verification generates joint feasibility certificate about reachable cone field and flutter critical frequency field by sum of squares method, and binds joint feasibility certificate with corresponding area in design hypergraph.
7. The method of claim 1, wherein, Continuous relaxation programming sets continuous selection variables for candidate process edges in process resource hypergraph, and converts continuous solution into discrete process parameters satisfying resource mutual exclusion constraint and sequence constraint through constraint projection based on type system.
8. The method of claim 1, wherein, The generation of safe trajectory uses control barrier function to impose inequality constraint on machine tool posture and control input, and solves the constrained optimization problem at discrete time step to ensure that the trajectory meets the safety requirements.
9. The method of claim 1, wherein, The measurement path is generated by the harmonic field contour in the target area, and the process certificate is formed by the formal verification of visibility and incident angle, and is bound with the measurement edge in the process resource hypergraph.
10. The method of claim 1, wherein, The minimum hit set is solved based on the bipartite graph between trigger factors and violated constraints of counterexample set, and the local resolvation is executed with the previous solving state as the initial value after the writeback of contract patch configuration patch and process patch, and the revision record and certificate version are written into the evidence log.