Reusable rocket attitude control system redundancy verification and fault tolerance evaluation method
By designing multiple types of disturbance units and a hardware-in-the-loop simulation platform, a dynamic response path map was constructed, solving the problem that existing technologies cannot fully cover multi-dimensional disturbance scenarios, and realizing efficient evaluation and optimization of the redundancy of reusable rocket attitude control systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-05
- Publication Date
- 2026-03-31
AI Technical Summary
Existing methods for redundancy verification of reusable rocket attitude control systems lack comprehensive modeling and injection of multi-dimensional disturbance scenarios, making it difficult to effectively cover system response performance. Furthermore, the evaluation methods are unable to fully reconstruct the time-series link from failure detection to functional recovery, and cannot identify potential timing conflicts or resource contention.
The design incorporates various types of control disturbance units, including trajectory change disturbances, attitude angle offset disturbances, actuator hysteresis disturbances, sensor drift disturbances, and command loss disturbances. These units are combined in multiple dimensions using a hardware-in-the-loop simulation platform to construct an induced task profile. The redundant response mechanism of the attitude control system is recorded in real time, and a dynamic response path graph is constructed. The cascade structure features are extracted and quantitatively evaluated.
This system enables the systematic verification and evaluation of the redundancy response capability of the attitude control system, improves the authenticity and accuracy of fault tolerance testing, supports optimization in the design phase, and enhances the system's fault tolerance capability and the objectivity of the evaluation results.
Smart Images

Figure CN121763693A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of verification and evaluation technology, and in particular to a method for verifying the redundancy and assessing the fault tolerance of a reusable rocket attitude control system. Background Technology
[0002] With the rapid development of spacecraft reusability technology, reusable launch vehicles have become an important development direction in the current space launch field. Compared with traditional expendable rockets, reusable rockets have higher requirements in terms of structural complexity, control precision and flight safety. Especially in critical flight phases such as vertical takeoff and landing, powered return and atmospheric reentry, the attitude control system needs to have stronger fault tolerance and redundancy mechanism response speed to ensure mission safety and system reliability.
[0003] Existing reusable rocket attitude control systems typically employ dual-redundant flight control channels (primary and backup), dual IMU inertial navigation modules, and multi-actuator fault-tolerant configurations to improve system robustness through hardware redundancy, control law switching, and fault detection algorithms.
[0004] However, most existing methods for redundancy verification of attitude control systems rely on static simulations of single disturbance sources, such as actuator failure or IMU bias. These methods lack comprehensive modeling and injection of complex disturbance factors such as trajectory disturbances, sensor drift, and control hysteresis, making it difficult to effectively cover system response performance under multi-dimensional disturbance scenarios. This results in incomplete and insufficiently comprehensive verification results. Furthermore, the redundancy response process of attitude control systems after a disturbance involves multiple dynamic stages, including control path switching, component intervention, and function takeover. Existing evaluation methods often remain at the level of qualitative observation or single-parameter quantification, making it difficult to fully reconstruct the timing chain of the system from failure detection to functional recovery. They also fail to identify potential problems such as timing conflicts or resource contention in the switching logic. Summary of the Invention
[0005] This invention provides a reusable method for verifying the redundancy and assessing the fault tolerance of a rocket attitude control system. It is a systematic verification and assessment method with multi-disturbance excitation capability, redundant response structure modeling capability, and multi-dimensional performance evaluation capability. It can realistically reproduce various abnormal situations that may be encountered during rocket flight in a simulation environment, and comprehensively identify and quantify the redundancy response capability and fault tolerance characteristics of the attitude control system.
[0006] A method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system includes the following steps: S1. In the hardware-in-the-loop simulation platform, based on the orbital parameters and attitude control characteristics of the reusable rocket, multiple types of control disturbance units are designed, including trajectory change disturbances, attitude angle offset disturbances, actuator hysteresis disturbances, sensor drift disturbances, and command loss disturbances. The disturbance units are combined in multiple dimensions according to the disturbance type, duration, and intensity level to form a disturbance combination set. Based on the disturbance combination set and typical flight stages (such as first-stage flight, attitude turning, and reentry adjustment), a set of induced mission profiles covering different attitude control anomaly scenarios is constructed. The induced mission profiles are used to trigger the redundant response mechanism in the attitude control system and serve as verification inputs. S2, run a hardware-in-the-loop simulation system under the induction task profile, record in real time the switching status of the internal control path of the attitude control system, the intervention sequence of redundant components and the function takeover sequence, construct the dynamic response path map of the redundant link, and extract the cascade structure features including link connection time, redundant response overlap interval and number of conflicting chain segments. S3. Input the cascaded structure features into the evaluation mechanism to determine the redundancy response coverage of the redundancy mechanism under different induced task profiles, calculate the convergence capability of the attitude control deviation stabilization time and attitude disturbance suppression curve, and generate the response integrity index and fault tolerance conflict criterion of the redundancy configuration as the fault tolerance capability evaluation result of the attitude control system.
[0007] Optionally, the trajectory abrupt change disturbance is achieved by superimposing a time-varying wind field model or aerodynamic coefficient deviation over a period of time, the amplitude of which is determined according to the current flight pressure and a preset disturbance intensity level; the attitude angle offset disturbance is achieved by injecting an initial attitude angle deviation in the form of a step or ramp into the attitude control loop; the actuator hysteresis disturbance is simulated by introducing nonlinear delay elements and dead zone characteristics into the instruction response model of the actuator; the sensor drift disturbance is simulated by superimposing a slowly varying drift signal or white noise onto the simulation output signal of the inertial measurement unit; and the instruction loss disturbance is simulated by randomly shielding or delaying the control instructions sent to the designated actuator with a predetermined probability.
[0008] Optionally, the formation of the disturbance combination set includes orthogonally combining each designed disturbance unit according to three dimensions: its disturbance type, the time period of its effect in the flight mission, and the intensity level based on the mission criticality, to generate a disturbance combination set that includes multiple single disturbances and mixed disturbances.
[0009] Optionally, the construction of the induced mission profile includes: defining multiple typical flight stages based on the rocket's dynamic model and flight trajectory, including first-stage flight, attitude steering, and reentry adjustment; selecting one or more disturbance combinations from the disturbance combination set according to the typical failure modes and stress environment faced by the attitude control system in each flight stage, and matching and mapping them to the corresponding flight time period, thereby constructing a set of induced mission profiles that can cover different attitude control anomaly scenarios, used to trigger and verify the redundant response mechanism in the attitude control system.
[0010] Optionally, S2 includes loading and running the induced task profile in a hardware-in-the-loop simulation system, and capturing and recording key events within the attitude control system in real time via the simulation system's data bus and built-in probes, including: Control path switching status: Record the switching actions and triggering conditions between primary and backup control channels, control laws or navigation algorithms; Redundant component activation timing: Record the timestamps of when each redundant backup component is activated after the primary component is disturbed or a simulated failure is encountered; Function takeover sequence: Records the specific logical sequence and success or failure status of each backup component taking over control functions in a chained or parallel redundant structure.
[0011] Optionally, the construction of the dynamic response path map includes constructing a directed graph structure based on recorded data, with time as the horizontal axis, control paths and component states within the system as nodes, and actions such as switching, takeover, and coordination as edges, to display the dynamic trajectory of the entire process of activation, switching, and recovery of redundant links in the attitude control system under disturbance.
[0012] Optionally, structural features characterizing the cascade response of redundant systems are quantitatively extracted from the dynamic response path map, including: Link continuity time: The time interval from the failure of the primary function or the disturbance exceeding the tolerance to the complete takeover and stable output of the backup function; Redundant response overlap interval: The length of the time interval during which multiple redundant components are in an active state when they respond simultaneously or when there is cross-backup. Number of conflicting chain segments: During the redundancy switchover process, the number of unexpected and contradictory control command paths or component action states that occur due to timing, logic, or resource contention.
[0013] Optionally, the evaluation mechanism determines the actual response coverage of the redundancy mechanism by comparing the redundant links successfully activated under the induced task profile with all the redundant logic preset by the system. Specifically, it includes calculating the redundancy response coverage rate for each induced task profile, defined as the ratio of the number of items in which the system successfully performed redundancy switching or function takeover under all expected fault modes triggered in the profile to the total number of redundancy management items designed by the system.
[0014] Optionally, the calculation of the attitude control deviation stabilization time includes: the duration from the moment the disturbance occurs in the system or the redundancy switching action occurs, to the time during which the key parameters recover to and stabilize within the preset task envelope range; The evaluation of the convergence capability of the attitude disturbance suppression curve includes: analyzing the time-domain response curve of the attitude parameters, calculating its overshoot, attenuation ratio, and the time constant required to recover from the peak value to the stable value, and comprehensively evaluating the dynamic convergence performance and disturbance suppression efficiency of the system after redundancy intervention.
[0015] Optionally, S3 further includes: Response integrity index: Calculated as a weighted fusion result of redundancy response coverage, attitude control deviation stabilization time, and disturbance suppression convergence capability, used to quantify the overall response effectiveness of redundancy configuration in response to a specific induced profile; Fault tolerance conflict criterion: Based on the number of extracted conflict chain segments, and combined with the severity level of resource competition or logical mutual exclusion events occurring within the redundant response overlap interval, a metric value is formed to characterize the internal coordination and conflict-free nature of the redundant management logic. Finally, the response integrity index and the fault tolerance conflict criterion are used together as the evaluation result to output a quantitative evaluation of the fault tolerance capability of the attitude control system under different fault scenarios.
[0016] The beneficial effects of this invention are: 1. This invention constructs multiple types of control disturbance units covering trajectory abrupt changes, attitude deviations, actuator hysteresis, sensor drift, and command loss. It forms a disturbance combination set through a three-dimensional combination of disturbance type, duration, and intensity level, and then maps it to the typical flight phase of a reusable rocket to generate an induced mission profile. In a hardware-in-the-loop simulation platform, it simulates the real flight disturbance environment, effectively stimulating the redundant response mechanism of the attitude control system. Compared with existing methods that only verify individual static disturbance scenarios, this invention can realize the systematic design and composite excitation of disturbance conditions, enhance the scenario complexity and coverage of redundant verification, and improve the authenticity and representativeness of fault-tolerant testing.
[0017] 2. In the process of redundant response simulation, this invention records the control path switching, the timing of redundant component intervention, and the sequence of function takeover in real time, constructing a dynamic response path map of redundant links with time series as the main line and control state as the node. Based on this map, the hierarchical structural features of link connection time, redundant response overlap interval, and number of conflicting chain segments are further extracted and correlated with the induced task profile to form a multi-dimensional fault-tolerant evaluation system with coverage index, convergence performance index, and coordination conflict criterion. Compared with traditional evaluation methods that rely on manual scoring or single indexes, this invention can realize structured analysis and quantitative output of redundant response quality, improving the accuracy, objectivity, and interpretability of the evaluation results.
[0018] 3. The evaluation mechanism established by this invention can automatically compare the deviation between the actual system response and the design expectation under each induced task profile, calculate the redundant response coverage, attitude deviation stabilization time and dynamic convergence capability, and integrate them to form a response integrity index. At the same time, it combines the conflict chain segment and the severity level of resource competition events to form a fault tolerance conflict degree criterion. This result can serve as the basis for scoring the fault tolerance capability of the attitude control system under different disturbance scenarios, and support targeted optimization of redundancy strategies, response logic and resource allocation during the design phase, thereby achieving the advanced fault tolerance design goal of reconfigurable fault tolerance structure, controllable configuration path and closed-loop optimization of response strategy. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only for this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 This is a schematic diagram of the evaluation method flow according to an embodiment of the present invention; Figure 2 This is a schematic diagram illustrating the fault tolerance capability assessment in an embodiment of the present invention. Detailed Implementation
[0021] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments. For some well-known technologies, those skilled in the art may also use other alternative methods to implement the invention. Moreover, the accompanying drawings are only for more specific description of the embodiments and are not intended to specifically limit the present invention.
[0022] like Figures 1-2 As shown, a method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system includes the following steps: S1. In the hardware-in-the-loop simulation platform, based on the orbital parameters and attitude control characteristics of the reusable rocket, multiple types of control disturbance units are designed, including trajectory change disturbances, attitude angle offset disturbances, actuator hysteresis disturbances, sensor drift disturbances, and command loss disturbances. The disturbance units are combined in multiple dimensions according to the disturbance type, duration, and intensity level to form a disturbance combination set. Based on the disturbance combination set and typical flight stages (such as first-stage flight, attitude turning, and reentry adjustment), a set of induced mission profiles covering different attitude control anomaly scenarios is constructed. The induced mission profiles are used to trigger the redundant response mechanism in the attitude control system and serve as verification inputs.
[0023] S11, Design of Multiple Types of Control Disturbance Units: To address the various attitude control interference sources that reusable rockets may encounter during flight missions, the following five types of control disturbance units are designed: S111, Trajectory Abrupt Change Disturbance: This is achieved by superimposing a time-varying wind field disturbance or aerodynamic coefficient deviation into the spacecraft orbit calculation module. The disturbance term is expressed as: ;in, This represents the perturbation term of the trajectory change. Indicates the flight motion pressure at the current moment. This represents the time-varying perturbation coefficient function. This represents the disturbance intensity level coefficient. The value of the disturbance intensity coefficient is determined based on the sensitivity of the mission phase. For the most critical phase of attitude control, a higher disturbance level should be selected to evaluate the system's limit response capability. Generally, it can be divided into three disturbance intensity levels: low intensity 0.05, medium intensity 0.10, and high intensity 0.15~0.20. The spacecraft's trajectory calculation module is responsible for calculating its trajectory evolution based on information such as current attitude, velocity, and aerodynamic loads. Under normal circumstances, this module outputs a smooth trajectory based on the environmental model and dynamic equations.
[0024] Flight pressure is the aerodynamic pressure experienced by an aircraft as it travels through the atmosphere at high speeds, i.e., the aforementioned... Its definition is as follows: ;in, The atmospheric density at the rocket's current altitude can be calculated using a standard atmospheric model. This indicates the rocket's speed at that moment. Flight time. Flight pressure reflects the strength of the current aerodynamic load. During rocket flight, as speed increases and altitude changes, the combined effect of air density and velocity causes... It exhibits a trend of first rising and then falling, and usually reaches its peak at the point of maximum dynamic pressure, which is one of the most stress-sensitive moments for the flight structure and attitude control system.
[0025] So-called time-varying disturbance coefficient function It is an artificially designed disturbance model used to simulate external aerodynamic disturbances, and its design is as follows: 1. Simplified style Field model: Using a sine wave to simulate gust disturbances, it can be represented as: ; indicates that periodic wind speed changes affect the aircraft. This represents the amplitude of the wind speed disturbance (representing the maximum disturbance intensity). This represents the initial phase shift of the sinusoidal perturbation. This is the current time.
[0026] 2. Modeling deviation term: The drift error of aerodynamic parameters (drag coefficient) over time is simulated by a linear variation and can be expressed as: This indicates that the control model has continuously increasing parameter errors. This represents the time drift rate of the modeling error.
[0027] 3. Integrated Disturbance Model: Superimposed with wind field variations, modeling errors, and random noise terms: It is used to simulate more complex and unpredictable atmospheric disturbance environments. Indicates the frequency of wind field disturbances (indicating how fast the disturbances change). This represents the Gaussian white noise perturbation term.
[0028] S112, Attitude Angle Offset Disturbance: Attitude angle offset is simulated by injecting a step or ramp signal into the initial input of the attitude control loop. The disturbance term is represented as follows: ;in, This represents the attitude angle perturbation value. This indicates the initial offset angle (fixed). This section is for the disturbance slope (angular velocity deviation). It aims to simulate the initial attitude angle deviation disturbance caused by attitude perception error or control error during rocket flight. That is, the rocket should maintain a stable attitude angle in a certain flight phase, but due to the disturbance, there is a sudden or gradual deviation in the angle, thereby testing the attitude control system's response and correction capability to such deviations.
[0029] This disturbance is achieved by artificially injecting an additional angle signal at the input of the attitude control loop. This disturbance signal can take two forms: Step disturbance: This refers to a sudden, fixed-amplitude jump in the attitude angle at a specific moment. For example, the rocket's attitude angle might initially shift by 5° and then remain constant. This is often used to simulate initial calibration errors in attitude measurements or sudden misalignment of the control system at a certain point. It is expressed as: ; Ramp disturbance: This indicates that the attitude angle gradually shifts over time, with the deviation value continuously increasing. This change more closely resembles the slow error accumulation caused by sensor drift or minor actuator failure, and is expressed as: .
[0030] S113, Actuator Hysteresis Disturbance: A nonlinear hysteresis characteristic is introduced into the actuator dynamic response model. The simulation model can use the Preisach model or a simplified hysteresis function, expressed as: ;in, Indicates the actual actuator output. Indicates theoretical command input, , This represents the dead zone width, i.e., the minimum reaction threshold. Hysteresis delay time indicates the delayed response of the actuator to instructions. This section models the error term or disturbance residual; it aims to simulate the non-ideal response of rocket actuators during actual operation, specifically actuator hysteresis disturbances. Actuators include thrust vectoring devices for attitude control, reaction wheels, or aerodynamic control surfaces. After receiving commands from the control system, they do not always execute them immediately and accurately. Sometimes, due to mechanical or electronic control characteristics, they exhibit response delays, nonlinear hysteresis, or dead zones where small commands cannot be driven. This scheme introduces a nonlinear hysteresis mechanism and dead-zone characteristics into the actuator simulation model to approximate the actual control hysteresis behavior. Its response logic is as follows: When the input changes too little, such as when the adjustment is too weak, the actuator will not respond, which is dead zone behavior. In this case, the output will be zero. The actuator will only respond after the input changes exceed a certain threshold, but this response has a delayed characteristic, such as taking effect after a few milliseconds. The response may also introduce certain disturbance residuals due to factors such as model errors or structural friction.
[0031] Dead zone width This refers to the situation where the actuator only responds when the amplitude of the input signal change exceeds a certain threshold; otherwise, the actuator output is zero. This phenomenon objectively exists in many physical actuators. For example, a servo motor may not move due to mechanical backlash when the angle changes slightly, or an electric actuator may need to overcome initial friction to produce displacement. The existence of dead zone necessitates that the control system consider nonlinear characteristics; otherwise, in stages where attitude control accuracy is required, it may lose control due to invalid micro-instructions. Therefore, introducing a dead zone model can be used to test whether the attitude control system has sufficient control margin and fault tolerance.
[0032] S114, Sensor Drift Disturbance: To simulate sensor drift disturbances that may occur in the inertial measurement unit (IMU) during actual flight, i.e., the systematic deviation and random noise between the sensor measurement value and the true value due to equipment aging, temperature changes, electromagnetic interference, etc., this disturbance input is constructed in the simulation system to test whether the attitude control system still has effective control and fault tolerance capabilities when there are deviations in the perceived data. In the simulation, ideal values are not directly used as the input for attitude calculation. Instead, a simulated sensor output value is artificially constructed, including a low-frequency drift term and a high-frequency noise term superimposed on the inertial measurement unit (IMU) signal, expressed as: ;in, This indicates the analog output of the sensor. Indicates time The actual state value, This represents a slowly varying drift term, i.e., a slowly changing systematic drift disturbance term, used to simulate persistent deviations caused by factors such as temperature, aging, and gyroscope bias. , Gaussian white noise (zero mean, variance) , The magnitude of the drift represents the maximum error offset. The frequency controls how fast the drift changes. The initial phase allows drift to occur randomly during flight; the above three parts combined generate... This is the output value of the sensor in the simulation. This value seems reasonable, but it actually includes system offset plus random interference. The attitude control system must make judgments and controls based on such input. If the system does not have filtering and fault tolerance capabilities, it is easy to generate attitude estimation errors, which in turn affect the control.
[0033] S115, Command Loss Disturbance: This simulation addresses command loss disturbances, where control commands issued by the rocket attitude control system during flight may be lost or delayed in arrival at the actuators. This phenomenon can be caused by bus congestion, electromagnetic interference, actuator malfunction, or other issues. To test the attitude control system's response capability under such command execution failure conditions, the simulation system introduces disturbance logic into the actuator command input channel. A probability value is set in the simulation. This is used to control whether control commands are blocked or delayed at a certain moment. The specific implementation is as follows: 1. In each control cycle, the system generates a random variable. It follows a uniform distribution from 0 to 1, that is... ; 2. Combine this random number with the set loss probability. Comparison: if This indicates that the instructions in this round were discarded, and the executor received a zero signal (i.e., no action was taken); if This indicates that the instruction was not lost, but a delay will be introduced. That is, the executor receives the instruction from the previous moment.
[0034] The perturbation function is expressed as: ; in, This indicates the actual instructions received by the actuator. To delay time, The original command currently issued by the control system. This represents the probability of instruction loss and can be set to different levels. This represents the random number generated each period, which determines whether a loss disturbance is triggered. The values range from 0 to 1, and each value has an equal probability of appearing. This type of random number is said to follow a uniform distribution in the interval [0,1], denoted as . .
[0035] S12, forming a perturbation combination set: The five types of perturbation units defined in S11 are orthogonally combined according to the following three dimensions to generate a perturbation combination set D: Disturbance type dimension (T): such as trajectory, attitude angle, actuator, sensor, command loss; The time period of action (τ): such as 0–30 s, 30–60 s, 60–90 s, etc.; Intensity level dimension (L): set as low (L1), medium (L2), high (L3); The perturbation combination is as follows: ;in, This represents a specific combination of disturbances (such as actuator hysteresis + medium intensity + medium duration).
[0036] The purpose of this part is to combine the five previously designed disturbance types according to three dimensions: type, time period, and intensity, thereby constructing a comprehensive set of disturbance combinations to trigger the abnormal response mechanism of the attitude control system in subsequent simulation tests.
[0037] The disturbance type dimension refers to the types of disturbances, which include five categories: trajectory change disturbances, attitude angle deviation disturbances, actuator hysteresis disturbances, sensor drift disturbances, and command loss disturbances. Each type corresponds to a specific problem that the rocket attitude control system may encounter.
[0038] The time period dimension refers to the time period during which the disturbance occurs in the flight mission: within the first 30 seconds of flight (0–30 s), during the middle of flight (30–60 s), and during the later stage of flight (60–90 s); this can be used to simulate the impact of the disturbance on the system at different stages of flight.
[0039] The disturbance intensity level dimension indicates the severity of the disturbance and is divided into three levels: low intensity (L1), medium intensity (L2), and high intensity (L3). The intensity level affects the amplitude of the disturbance.
[0040] S13, Constructing Induced Mission Profiles: Matching the previously constructed perturbation combinations with different stages of rocket flight to generate a set of induced mission profiles, used to systematically trigger and verify the effective operation of the attitude control system's redundancy mechanism. Specifically, this includes: Defining the flight phases: Based on the mission flow and trajectory planning of reusable rockets, the flight is typically divided into several key phases: : First stage of flight (engine ascent phase); Attitude steering phase (mid-range control phase); : Re-entering the adjustment phase (return segment); Each stage has different attitude control tasks, which place different demands on the load and response capabilities of the control system.
[0041] Identify key risk points in each phase: During each flight phase, the system may face different types of anomalies, including: aerodynamic disturbances, attitude angle deviations, actuator failures or delays, sensor drift, and loss of control commands. These anomalies need to be handled through redundancy mechanisms (such as activating backup sensors or switching control laws).
[0042] Using the set of disturbance combinations constructed in the previous part (each disturbance has type, time period, and intensity), select the disturbance that is most likely to occur or is the most threatening in the current flight phase, and apply it to that phase.
[0043] By mapping each flight phase to a combination of disturbances, a guided mission profile is created. For example: "Inject medium-intensity sensor drift disturbances during the attitude steering phase (P2)"; "High-intensity trajectory abrupt disturbances are superimposed during the reentry phase (P3); These are the so-called induced task profiles, which are used to systematically induce the control system to expose problems and trigger redundancy mechanisms, making the testing more targeted and effective.
[0044] That is, based on the typical attitude control anomalies encountered at each stage (aerodynamic disturbances, attitude angle deviations, actuator failures or delays, sensor drift, and loss of control commands), from the disturbance set Select matching perturbation combinations And apply it to the corresponding flight time period to construct a set of induced mission profiles. Its definition is: ; This represents the set of induced task profiles used to verify the redundancy response capability and the rationality of the fault-tolerant path configuration of the attitude control system. Indicates the first A typical flight phase.
[0045] S2, run a hardware-in-the-loop simulation system under the induced task profile, record in real time the switching status of the internal control path of the attitude control system, the intervention sequence of redundant components and the function takeover sequence, construct the dynamic response path map of the redundant links, and extract the cascade structure features including link connection time, redundant response overlap interval and number of conflicting chain segments.
[0046] S21, loads and executes the constructed induced task profile in the hardware-in-the-loop simulation system, and collects key redundant response events within the attitude control system in real time based on the system bus communication interface and embedded data probes, including: S211, Control Path Switching Status: Records the switching actions, switching conditions, and switching flag status between the main control channel and the redundant control channel, or between different control laws and navigation algorithms, to identify the triggering mechanism of the response behavior. When the system detects a disturbance or failure in the main control path, it will automatically or according to set conditions switch to the redundant path, including: Switch from the primary flight control computer to the backup flight control computer; Switch from the primary attitude control algorithm to the backup control law; Switch from the primary navigation filter to the backup algorithm.
[0047] The simulation system records how the switch is triggered, when the switch occurs, whether the switch is successful, and the internal switching flag signals, making it easy to reconstruct the entire control logic change process.
[0048] S212, Redundant Component Intervention Timing: Records the precise timestamps at which each redundant backup component in the system, including the redundant IMU, redundant flight control computer, and redundant servo motors, is activated after a disturbance or simulated fault occurs in the main component. This is denoted as: ;in, Indicates the first One redundant component, This indicates the absolute moment when it was invoked by the system. Specifically, after the system detects a malfunction in the main component, it will activate redundant components sequentially or in parallel, and the simulation system will record this: When is each redundant component activated (timestamp)? How long after the main controller malfunctioned did the intervention occur? Did a delay or activation failure occur?
[0049] This information reflects the system's response speed and redundancy chain activation efficiency under abnormal conditions.
[0050] S213, Functional Takeover Sequence: For series or parallel redundant structures, record the takeover sequence of each backup component in the control chain, the logic of the switching order, and whether the takeover was successful to mark the responsiveness of the redundant chain. In complex redundant structures, not all components take over control tasks simultaneously. The system must follow the logically defined sequence to ensure correct control relay, uninterrupted redundant chains, and no conflicts between multiple channels. Simulation recordings capture the sequence in which these redundant components take over control tasks, whether the switching is as expected, and whether flight control stability is successfully maintained.
[0051] A serial redundancy structure (serial type) refers to a system where backup components stand by sequentially and take over step by step. When the primary component fails, the primary backup is activated first; if the primary fails, the secondary backup is activated, and so on. The advantage is resource saving, but the disadvantage is that the takeover speed may be slower.
[0052] Parallel redundancy (parallel type) refers to a configuration where multiple redundant components are monitored online simultaneously. If the primary component malfunctions, the system immediately switches to any backup, and multiple backups can even participate in control in parallel. Its advantages include rapid response and strong fault tolerance, but it also has a complex structure and high power consumption.
[0053] S22, based on the time series and status data collected in S21, constructs a directed graph structure G=(V,E) with time evolution as the main line, where V represents the status nodes of each control path node and redundant component in the system, E represents events such as switching actions, function takeover, and synchronization coordination, and the horizontal axis is time. The vertical axis represents the sequence of events, with the component or path number in the control chain on the vertical axis. Each vertical channel represents a control component, path, or redundant node. The core of this section is to structurally represent all redundant response behaviors of the attitude control system during disturbance response using a graph. This clearly demonstrates the entire process of the system from anomaly detection, control switching, redundancy intervention to functional recovery, providing a foundation for subsequent quantitative analysis. In S21, detailed information on redundant responses is recorded, including control path switching, when redundant components intervene, and whether control functions are successfully taken over. Arranging this raw data chronologically allows the construction of a response trajectory graph, graphically representing the entire response process. A directed graph structure G=(V,E) is constructed with time evolution as the main thread, where V represents the state nodes of each control path and redundant component in the system, E represents events such as switching actions, functional takeover, and synchronization coordination, and the horizontal axis represents time. The vertical axis represents the component or path number in the control chain. The overall shape of the graph resembles a control behavior sequence diagram, but it is more complex than a traditional flowchart. It can display information such as multi-path, parallel switching, overlapping responses, and conflicting links. This response path diagram intuitively shows which components participate in redundant responses, how the switching process proceeds, whether there are conflicts or coordinated responses, and whether the overall system can effectively recover under disturbances. Quantitative indicators, such as connection time and the number of conflicting link segments, can be extracted from this graph to evaluate the reliability and efficiency of the redundancy strategy.
[0054] S23, Extracting Cascade Structure Features: Extract the following quantifiable structural feature indicators from the response path graph to reflect the dynamic adaptability of the redundant system to disturbances: S231, Link Setup Time Link uptime represents the time interval from the occurrence of a problem in the primary control path to the complete takeover and restoration of stable control by the redundant system. It measures the response speed of the redundancy mechanism and is a direct reflection of the speed of a fault-tolerant system. In the response path graph, the nodes of the primary control chain are marked with their failure times, denoted as [missing information]. Nodes in a redundant link will be marked with the time when they successfully took over and began stable output, denoted as . Calculate the time difference between the two: This time interval corresponds to the time range from the breakage of the main chain to the closure of the backup chain in the spectrum. The time when the main functional module fails or is triggered by a disturbance. This metric measures the time it takes for the backup function to complete takeover and output a stable control signal; it is the time-efficiency measure of the redundant takeover response.
[0055] S232, Redundant Response Overlap Interval When multiple redundant components are activated and participate in control simultaneously, their response behaviors may overlap in time intervals. This metric reflects the cooperative capability or redundancy of the redundant system and helps assess whether there is resource waste or cooperative advantage. Identify two redundant components (numbered as follows). and Each component has two points in the graph: one when it is activated and the other when it is deactivated. ; ; The overlapping time intervals of the two can be calculated by taking the overlapping portion of the two: ; This indicates two redundant components that participate in the response simultaneously. For components Activation time For components Activation time For components The time when the response ends, Indicates components The response end time is an indicator that reflects whether multiple redundant components are responding cross-responding or working together.
[0056] S233, Number of conflicting chain segments A conflicting chain segment refers to a path segment in a redundant response process where logical, temporal, or resource conflicts occur. For example: Conflicting control commands were issued simultaneously from two different paths; Two controllers are attempting to schedule the same actuator; A redundant node intervenes prematurely or delayed, causing chaos in the control chain logic.
[0057] This indicator is used to measure the potential conflict risk in redundancy mechanisms and is an important assessment point for stability.
[0058] Each path segment (i.e., edge) in the graph represents a switching or response action; Iterate through all path segments (numbered k=1 to K) and perform conflict checks on each segment: Are there mutually exclusive instructions (e.g., simultaneously requiring both left and right turns)? Does resource competition exist (e.g., two control laws attempt to control the same servo motor)? Are there any timing conflicts (such as a channel that should have been taken over first being preempted by a channel that was taken over later)? For each conflict discovered, set this segment. Otherwise, the result is 0; finally, the total number is calculated: ; This represents the total number of path segments. Indicates the first Does each chain segment have a conflict (1 indicates conflict)?
[0059] The above three indicators respectively reflect: System recovery speed (link connection time); Multi-redundancy collaborative capability (overlapping interval); Internal logical conflict risk (number of conflict chain segments); These are all quantitative features extracted from the time-series and structural data in the response path map, forming the core basis for evaluating the redundancy performance of the attitude control system. Through comprehensive analysis of these indicators, it can be clearly determined whether the redundant system has a rapid, coordinated, and conflict-free emergency response capability.
[0060] S3. Input the cascaded structure features into the evaluation mechanism to determine the redundancy response coverage of the redundancy mechanism under different induced task profiles, calculate the convergence capability of the attitude control deviation stabilization time and attitude disturbance suppression curve, and generate the response integrity index and fault tolerance conflict criterion of the redundancy configuration as the fault tolerance capability evaluation result of the attitude control system.
[0061] S31, Evaluate the redundancy response coverage: The input data comes from S2 and includes the activation time of redundant links, response paths, function takeover order, and conflict situations, which are called cascade structure characteristics. A set of redundancy management logic is preset in the design phase, including: Which control paths have primary and backup configurations? Which components should be redundantly replaced under what conditions; Which redundant channels should be activated under each type of failure mode? In short, what the system is supposed to do is known.
[0062] The current focus is on comparison: What actually happened during the simulation (i.e., the response data extracted by S2); What the system should do by default (i.e., the redundancy response strategy during design). Determine whether the two are consistent, whether the response is sufficient, and whether there are any omissions.
[0063] Ultimately, the redundant response coverage is calculated by setting a ratio.
[0064] Specifically, this includes: taking the cascaded structure features extracted by S2 as input, loading them into the evaluation mechanism, and comparing the actual triggered and responded redundant links in the induced task profile according to the system's preset redundant control logic to determine the response coverage of the redundant mechanism.
[0065] Define redundant response coverage for: ;in, This indicates the number of items in the system that successfully completed redundancy switching or functional takeover under this induced task profile. This indicates the total number of system-preset redundant management items corresponding to this task profile. The higher the value, the more complete the response of the redundant system.
[0066] The evaluation mechanism is a structural comparison and matching analysis framework, which includes the following key modules: S311. Task Profile Interpretation Module: Reads the input information of the current induced task profile, identifies the corresponding disturbance type, duration, and expected failure mode, and outputs a list of redundant units to be activated. The output result is denoted as: Each of them This indicates a preset redundant response action, including switching channels, alternative components, and backup control laws.
[0067] S312. Response Log Parsing Module: Extracts actual redundant response behaviors that occurred in the system from the simulation log, confirming whether a backup path or functional replacement unit was activated. The output is recorded as: Each of them These are the actual response events identified by the system during the simulation process.
[0068] S313. Comparison and Matching Module: [This module will...] and A one-by-one comparison is performed: if a anticipated response actually occurs, it is counted as a successful response; otherwise, it is counted as a non-response or missed response. The number of successful responses is... .
[0069] 4. Calculate and output coverage metrics .
[0070] S32, Calculate the attitude control performance recovery index: S321, Attitude control deviation stabilization time This refers to the time required from the start of a disturbance or redundancy switch until the aircraft's attitude parameters re-enter and remain within the safe control range (mission envelope). The shorter this time, the faster the system recovers control after a disturbance. ;in, Indicates the time when the disturbance begins or the redundancy switch occurs. This indicates the time it takes for the attitude parameters to first enter the mission tolerance and remain stable. The mission envelope is usually defined as the attitude angle error being less than the set value (±2°) and the angular velocity error being less than the set value (±0.1° / s).
[0071] S322, Disturbance Suppression Convergence Ability Index : To further evaluate the control dynamic performance after redundancy intervention, it is necessary to analyze the time-domain response curves of attitude angles or angular velocities and extract the following indicators: Overshoot : Represents the maximum deviation of the response curve from the steady-state target value, calculated as: ;in, This represents the maximum value reached by the response curve. It represents the desired steady-state attitude angle; it reflects whether the system has overshooted after a disturbance. Attenuation ratio : Represents the rate of decay of the response oscillation, i.e., the proportion of decay between adjacent amplitudes; it can be obtained by the logarithmic ratio between two consecutive peaks: ;in, It represents the amplitude of two adjacent peaks. The larger the amplitude, the stronger the system damping; the smaller the amplitude, the stronger the system response oscillation. Convergence time constant This represents the time required for the system to converge to a certain range (±5%) of the target value from the start of a disturbance, defined as: the time to reach 95% of the final steady-state value is approximately 3 times the time constant. (), reaching over 98% is approximately The smaller this value, the faster the control system responds.
[0072] A dynamic performance evaluation function is formed by combining the results: ;in, Weighting coefficients set for experience, The smaller the value, the faster the system response and the more effective the suppression of disturbances.
[0073] S33, Generate tolerance assessment criteria and results: S331, Response Integrity Metrics This is a positive evaluation metric used to measure the integrity and recovery effectiveness of redundant responses. It integrates information from three aspects: Redundancy response coverage: Whether the system has successfully activated all expected redundancy mechanisms; Attitude control deviation recovery speed: the time it takes for the system to recover to a stable state after a disturbance occurs; Disturbance suppression effect: Whether the system has problems such as overshoot, oscillation, and slow convergence during the recovery process.
[0074] These three quantitative indicators are weighted and combined into a single score to construct an overall response capability index for the attitude control system under the current induced profile: ;in, These are the weighting coefficients. The maximum allowable time and maximum disturbance evaluation criteria are set for the system. A larger value indicates a stronger response capability.
[0075] S332, Fault Tolerance Conflict Criterion This is a reverse evaluation metric used to measure whether there are potential problems such as coordination issues, conflicting behaviors, or resource contention during redundant response processes. It combines conflict information from two aspects: Number of conflicting chain segments: Redundant switching or mutually exclusive conflicting parts in the control path found in the path graph; Severity of resource conflict or logical mutual exclusion events: If multiple controllers or components contend for the same resource or issue conflicting commands simultaneously within the redundant response overlap range, it will be identified as a conflict event, and each event has a severity level.
[0076] After merging these two types of conflicting information, the redundancy coordination and conflict risk are quantified: ;in, This indicates the number of conflicting chain segments identified from the path map. This indicates the number of resource contention or mutual exclusion events that occur within the overlapping interval. Indicates the first The severity level of each conflict event (set to levels 1-5), This is the event weighting coefficient; a larger value indicates a more severe conflict and poorer redundancy coordination. The event weighting coefficient represents the degree of impact of a certain type of conflict event on the system's operational safety or stability. Its value can be set based on the following factors: 1. Severity of Conflict Type: If a conflict will directly cause flight attitude instability, such as when two controllers output opposite control angles, or when the primary and backup controllers take over and issue mutually exclusive commands, or assign high weight values. If the conflict only causes control delays or waste of redundant resources, such as backup components mistakenly taking over and then exiting, or primary and backup paths responding repeatedly, assign a medium weight value. If the conflict has no substantial impact on the result and is merely a flaw in the structural design logic, such as slight overlap in control channel switching but without causing an output error, assign a low weight value. 2. Mission Phase Sensitivity: During certain critical flight phases, including reentry and return landing, higher control precision is required, and the aircraft is more sensitive to conflicts. Related events should be given higher weight.
[0077] S333, ultimately the two indicators are combined as the evaluation result of the attitude control system's fault tolerance capability under the current induced task profile: ;if Approaching 1 and A value close to 0 indicates that the system is both responsive and free of significant conflicts, demonstrating excellent fault tolerance. If both are poor, it indicates that the system is incomplete in its response and suffers from coordination failures, requiring structural optimization.
[0078] The results can be used for cross-sectional comparisons of different task profiles, supporting redundant design optimization, failure mode refactoring, and control strategy adjustment.
[0079] This invention encompasses any substitutions, modifications, equivalent methods, and solutions made within the spirit and scope of this invention. To provide the public with a thorough understanding of this invention, specific details are described in detail in the following preferred embodiments; however, those skilled in the art will fully understand the invention even without these details. Furthermore, to avoid unnecessary misunderstanding of the essence of this invention, well-known methods, processes, procedures, components, and circuits are not described in detail.
[0080] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system, characterized in that, Includes the following steps: S1. In the hardware-in-the-loop simulation platform, based on the orbital parameters and attitude control characteristics of the reusable rocket, multiple types of control disturbance units are designed, including trajectory change disturbances, attitude angle offset disturbances, actuator hysteresis disturbances, sensor drift disturbances, and command loss disturbances. The disturbance units are combined in multiple dimensions according to the disturbance type, duration of action, and intensity level to form a disturbance combination set. Based on the disturbance combination set and typical flight phases, a set of induced mission profiles covering different attitude control anomaly scenarios is constructed. S2, run a hardware-in-the-loop simulation system under the induction task profile, record in real time the switching status of the internal control path of the attitude control system, the intervention sequence of redundant components and the function takeover sequence, construct the dynamic response path map of the redundant link, and extract the cascade structure features including link connection time, redundant response overlap interval and number of conflicting chain segments. S3. Input the cascaded structure features into the evaluation mechanism to determine the redundancy response coverage of the redundancy mechanism under different induced task profiles, calculate the convergence capability of the attitude control deviation stabilization time and attitude disturbance suppression curve, and generate the response integrity index and fault tolerance conflict criterion of the redundancy configuration as the fault tolerance capability evaluation result of the attitude control system.
2. The method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system according to claim 1, characterized in that, The trajectory abrupt change disturbance is achieved by superimposing a time-varying wind field model or aerodynamic coefficient deviation over a period of time, the amplitude of which is determined based on the current flight pressure and a preset disturbance intensity level; the attitude angle offset disturbance is achieved by injecting an initial attitude angle deviation in the form of a step or ramp into the attitude control loop; the actuator hysteresis disturbance is simulated by introducing nonlinear delay elements and dead zone characteristics into the instruction response model of the actuator; the sensor drift disturbance is simulated by superimposing a slowly varying drift signal or white noise onto the simulation output signal of the inertial measurement unit; the instruction loss disturbance is simulated by randomly shielding or delaying control instructions sent to a designated actuator with a predetermined probability.
3. The method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system according to claim 1, characterized in that, The formation of the disturbance combination set involves orthogonally combining the designed disturbance units according to three dimensions: their disturbance type, the duration of their effect in the flight mission, and the intensity level based on the mission criticality, to generate a disturbance combination set that includes multiple single disturbances and mixed disturbances.
4. The method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system according to claim 1, characterized in that, The construction of the induced mission profile includes: defining multiple typical flight stages based on the rocket's dynamic model and flight trajectory, including first-stage flight, attitude steering, and reentry adjustment; selecting one or more disturbance combinations from the disturbance combination set according to the typical failure modes and stress environment faced by the attitude control system in each flight stage, and matching and mapping them to the corresponding flight time period, thereby constructing a set of induced mission profiles that can cover different attitude control anomaly scenarios, used to trigger and verify the redundant response mechanism in the attitude control system.
5. The method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system according to claim 1, characterized in that, S2 includes loading and running the induced task profile in a hardware-in-the-loop simulation system, and capturing and recording key events within the attitude control system in real time through the simulation system's data bus and built-in probes, including: Control path switching status: Record the switching actions and triggering conditions between primary and backup control channels, control laws or navigation algorithms; Redundant component activation timing: Record the timestamps of when each redundant backup component is activated after the primary component is disturbed or a simulated failure is encountered; Function takeover sequence: Records the specific logical sequence and success or failure status of each backup component taking over control functions in a chained or parallel redundant structure.
6. The method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system according to claim 5, characterized in that, The construction of the dynamic response path map involves using recorded data, with time as the horizontal axis, control paths and component states within the system as nodes, and actions such as switching, takeover, and coordination as edges to construct a directed graph structure of the dynamic response path map, which displays the dynamic trajectory of the entire process of activation, switching, and recovery of redundant links in the attitude control system under disturbance.
7. The method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system according to claim 5, characterized in that, From the dynamic response path map, structural features used to characterize the cascade response of redundant systems are quantitatively extracted, including: Link continuity time: The time interval from the failure of the primary function or the disturbance exceeding the tolerance to the complete takeover and stable output of the backup function; Redundant response overlap interval: The length of the time interval during which multiple redundant components are in an active state when they respond simultaneously or when there is cross-backup. Number of conflicting chain segments: During the redundancy switchover process, the number of unexpected and contradictory control command paths or component action states that occur due to timing, logic, or resource contention.
8. The method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system according to claim 1, characterized in that, The evaluation mechanism determines the actual response coverage of the redundancy mechanism by comparing the redundant links successfully activated under the induced task profile with all the redundant logic preset by the system. Specifically, it calculates the redundancy response coverage rate for each induced task profile, which is defined as the ratio of the number of items in which the system successfully performed redundancy switching or function takeover under all expected fault modes triggered in the profile to the total number of redundancy management items designed by the system.
9. The method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system according to claim 8, characterized in that, The calculation of the attitude control deviation stabilization time includes: the duration from the moment the disturbance occurs in the system or the redundancy switching action occurs until the key parameters recover to and stabilize within the preset task envelope range. The evaluation of the convergence capability of the attitude disturbance suppression curve includes: analyzing the time-domain response curve of the attitude parameters, calculating its overshoot, attenuation ratio, and the time constant required to recover from the peak value to the stable value, and comprehensively evaluating the dynamic convergence performance and disturbance suppression efficiency of the system after redundancy intervention.
10. The method for redundancy verification and fault tolerance assessment of a reusable rocket attitude control system according to claim 9, characterized in that, S3 further includes: Response integrity index: Calculated as a weighted fusion result of redundancy response coverage, attitude control deviation stabilization time, and disturbance suppression convergence capability, used to quantify the overall response effectiveness of redundancy configuration in response to a specific induced profile; Fault tolerance conflict criterion: Based on the number of extracted conflict chain segments, and combined with the severity level of resource competition or logical mutual exclusion events occurring within the redundant response overlap interval, a metric value is formed to characterize the internal coordination and conflict-free nature of the redundant management logic. Finally, the response integrity index and the fault tolerance conflict criterion are used together as the evaluation result to output a quantitative evaluation of the fault tolerance capability of the attitude control system under different fault scenarios.
Citation Information
Cited By
Launch vehicle engine redundant valve motor assembly control system and method
CN122292947A
Launch vehicle engine redundant valve motor assembly control system and method
CN122292947B