Carrier rocket safety control method, device and equipment

By distinguishing between the test state and flight state of the launch vehicle, loading the corresponding control logic, and generating control timing signals and state data, the problems of poor test flexibility and imperfect state switching in the existing technology are solved, and efficient and reliable rocket safety control is achieved.

CN121782945APending Publication Date: 2026-04-03HENAN TIANZHANG ROCKET CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-16
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

The existing launch vehicle safety control system has poor testing flexibility and imperfect state switching. It lacks a clear state division between pre-launch testing and post-launch flight, and has insufficient safety redundancy.

Method used

A launch vehicle safety control method is designed. By acquiring the current mission stage identifier and preset timing configuration data, the test state and flight state are distinguished. The corresponding control logic is loaded, and control timing signals and status data are generated to achieve precise control of the safety control equipment. This method supports multiple unlocking, detonation tests and reset operations to ensure safety and reliability during flight.

Benefits of technology

This improved the reliability of the rocket safety control testing process, enhanced the safety of rocket flight, ensured the sufficiency and efficiency of ground testing, and guaranteed safety and reliability during flight.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121782945A_ABST
    Figure CN121782945A_ABST
Patent Text Reader

Abstract

The invention provides a carrier rocket safety control method, device and equipment, belongs to the technical field of rocket launching, and solves the problems that a carrier rocket safety control system is poor in test flexibility and incomplete in state switching, and safety redundancy is insufficient. The method comprises the following steps: acquiring a current task stage identifier and preset time sequence configuration data; according to the current task stage identifier, the working state of the carrier rocket safety control equipment is determined, and the working state comprises a test state and a flight state; loading corresponding preset control logic according to the working state and the time sequence configuration data; according to preset control logic, the safety control equipment is controlled, a control sequence signal and safety control state data corresponding to the working state are obtained, the control sequence signal is output, and the safety control state data comprise a test completion mark determined in the test state or an insurance release state mark determined in the flight state. According to the scheme, the reliability of the rocket safety control test process is improved, and the safety of rocket flight is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of rocket launch technology, and in particular to a method, device and equipment for the safety control of launch vehicles. Background Technology

[0002] The safety control system of a launch vehicle is a critical subsystem that ensures reliable flight termination and avoids loss of life and property on the ground, especially in the event of an irreversible failure. Existing technologies mainly focus on two directions: hardware logic solidification and finite state machine management. One approach is a fixed-sequence control scheme based on hardware logic. This scheme controls the release and detonation processes of safety mechanisms sequentially through preset hardware circuits and fixed timing, offering high execution determinism and anti-interference capabilities. However, its logic is rigid, lacking flexibility for adjustment and repeated testing. The other approach is a control method based on software state machines. This method defines multiple states (such as standby, release, and detonation) and transition conditions to achieve process control, offering a degree of programmability and logic complexity management compared to pure hardware solutions. These existing technologies collectively constitute the mainstream implementation methods in the current launch vehicle safety control field. Their core objective is to reliably issue safety commands under specific conditions, but their design paradigms generally emphasize the final safety decision during flight, while providing insufficient support for comprehensive ground testing and verification before takeoff.

[0003] While existing technologies have achieved basic safety control functions, several key deficiencies have been exposed in practical applications, restricting the sufficiency of system testing, the flexibility of use, and the ultimate reliability of missions. First, testing flexibility is severely lacking. Traditional systems typically do not support, or only support, a very limited number of ground tests of the deactivation and detonation functions. This prevents sufficient and repeated functional verification and boundary condition drills before flight missions, potentially leaving some logical flaws or interface problems to surface during flight, posing significant risks. Second, the state management mechanism is inadequate. The system lacks clear state division and switching management between the fundamentally different stages of "pre-flight testing" and "post-flight flight." This makes it susceptible to state confusion due to signal interference, operational timing deviations, or software logic vulnerabilities. Third, the reset function is missing or weak. After completing a test, the system often cannot completely reset the security mechanisms and control circuits to a defined, clean, and safe initial state through standard and reliable procedures. This not only affects subsequent tests but may also leave uncertain states after testing, creating potential hazards for later procedures. Finally, there are loopholes in in-flight safety redundancy. Some solutions lack a mechanism to continuously lock or maintain the unlocked state after the system is deactivated during flight. This poses a risk of accidental reset due to a single signal jump or software reset, which contradicts the extremely high reliability requirements of the security control system. Summary of the Invention

[0004] This invention provides a method, apparatus, and equipment for the safety control of launch vehicles, which solves the problems of poor testing flexibility, imperfect state switching, and insufficient safety redundancy in the safety control system of launch vehicles.

[0005] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows: This invention provides a launch vehicle safety control method, comprising: Obtain the current task stage identifier and preset timing configuration data; Based on the current mission phase identifier, determine the operational status of the launch vehicle's safety control equipment, including testing status and flight status. Based on the working state and the timing configuration data, the corresponding preset control logic is loaded; wherein, when the working state is the test state, the preset test state control logic is loaded; when the working state is the flight state, the preset flight state control logic is loaded. According to the preset control logic, the security control equipment is controlled to obtain control timing signals and security control status data corresponding to the working state, and the control timing signals are output. The security control status data includes a test completion flag determined in the test state, or a release status flag determined in the flight state.

[0006] Optionally, obtaining the current task stage identifier and preset timing configuration data includes: Receive a phase switching instruction from the launch vehicle mission management system, and parse the phase switching instruction to obtain the current mission phase identifier; Read pre-stored timing configuration data from the memory of the launch vehicle's safety control equipment. The timing configuration data includes at least a first timing sequence corresponding to the test state and a second timing sequence corresponding to the flight state.

[0007] Optionally, based on the current mission phase identifier, the operational status of the launch vehicle's safety control equipment is determined, including: When the current task stage is identified as a first preset value, the working state is determined as a test state; When the current task stage is identified as the second preset value, the working state is determined to be the flight state.

[0008] Optionally, based on the working state and the timing configuration data, corresponding preset control logic is loaded, including: When the working state is the test state, the preset test state control logic is loaded and initialized from the control logic library preset in the security control device according to the first timing sequence contained in the timing configuration data. When the working state is flight state, the preset flight state control logic is loaded and initialized from the control logic library according to the second timing sequence contained in the timing configuration data.

[0009] Optionally, according to the preset control logic, the security control equipment is controlled to obtain control timing signals and security status data corresponding to the working state, including: Based on the preset test state control logic, control timing signals corresponding to the test state are determined. The control timing signals corresponding to the test state include timing signals of multiple preset control actions and corresponding durations. Retrieve the historical number of tests and the preset maximum allowed number of tests; The test feasibility factor is determined based on the historical number of tests and the maximum allowed number of tests, using the following formula: ; in, To test feasibility factors; A test margin factor greater than 0; This refers to the number of historical tests. This represents the maximum number of tests allowed. When the test feasibility factor is greater than the preset feasibility threshold, the test sequence is executed and the test completion flag is obtained.

[0010] Optionally, when the test feasibility factor is greater than a preset feasibility threshold, executing the test sequence and obtaining the test completion flag includes: When the test feasibility factor is greater than the preset feasibility threshold, the control timing signal is parsed and processed to obtain the first control command and the second control command. According to the first control command, the safety command receiver of the security control equipment is reset and the security control equipment is controlled to perform a detonation test to obtain the first test result. According to the second control command, the security mechanism of the security control equipment is reset and the security control equipment is controlled to perform a security unlocking test to obtain the second test result; The test completion flag is obtained based on the first test result and the second test result.

[0011] Optionally, according to the preset control logic, the security control equipment is controlled to obtain control timing signals and security status data corresponding to the working state, and the method further includes: Based on the preset flight state control logic, determine the control timing signal corresponding to the flight state; Acquire flight status data and ground safety control commands; Based on the flight status data and the ground security control instructions, the data for determining the protection requirements is calculated using the following formula: ; in, To solve the data demand for protection, and All are weighted coefficients. This is a function for determining whether to protect data based on flight status data. This is a function for determining whether to release protection based on ground commands. For flight status data; Ground security control instructions; When the insurance release demand data is greater than the preset insurance release threshold, the insurance release operation is performed and the insurance release status flag is obtained.

[0012] Optionally, the launch vehicle safety control method further includes: The control timing signals, the security control status data, and the corresponding timestamps are associated and encapsulated to obtain a structured security control process log file.

[0013] This invention also provides a launch vehicle safety control device, comprising: The acquisition module is used to acquire the current task stage identifier and preset timing configuration data; The processing module is used to determine the working status of the launch vehicle safety control equipment based on the current mission stage identifier, the working status including test status and flight status; and to load the corresponding preset control logic based on the working status and the timing configuration data; wherein, when the working status is test status, preset test status control logic is loaded; and when the working status is flight status, preset flight status control logic is loaded. The determination module is used to control the security control equipment according to the preset control logic, obtain control timing signals and security control status data corresponding to the working state, and output the control timing signals. The security control status data includes a test completion flag determined in the test state, or a release status flag determined in the flight state.

[0014] This invention also provides a computing device, including: a processor and a memory storing a computer program, wherein the computer program, when run by the processor, executes the above-described method.

[0015] The technical solution of the present invention has at least the following effects: The above-described solution of the present invention improves the reliability of the rocket safety control test process and enhances the safety of rocket flight by acquiring the current mission stage identifier and preset timing configuration data; determining the working state of the launch vehicle safety control equipment based on the current mission stage identifier, including test state and flight state; loading the corresponding preset control logic based on the working state and timing configuration data; controlling the safety control equipment according to the preset control logic to obtain control timing signals and safety control status data corresponding to the working state, and outputting the control timing signals. The safety control status data includes a test completion flag determined in the test state or a release status flag determined in the flight state. Attached Figure Description

[0016] Figure 1 This is a flowchart of the launch vehicle safety control method provided in the embodiments of the present invention; Figure 2 This is a schematic diagram of the pre-flight test control timing of the launch vehicle safety control method provided in this embodiment of the invention; Figure 3 This is a schematic diagram of the flight status control timing after takeoff of the launch vehicle safety control method provided in this embodiment of the invention; Figure 4 This is a structural diagram of the launch vehicle safety control device provided in an embodiment of the present invention; Figure 5 This is a schematic diagram of the structure of the computing device provided in an embodiment of the present invention. Detailed Implementation

[0017] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0018] like Figure 1 As shown, an embodiment of the present invention proposes a launch vehicle safety control method, comprising: Step 11: Obtain the current task stage identifier and preset timing configuration data; Step 12: Determine the working status of the launch vehicle's safety control equipment based on the current mission stage identifier. The working status includes testing status and flight status. Step 13: Based on the working state and the timing configuration data, load the corresponding preset control logic; wherein, when the working state is the test state, load the preset test state control logic; when the working state is the flight state, load the preset flight state control logic. Step 14: Control the security control device according to the preset control logic to obtain the control timing signal and security control status data corresponding to the working state, and output the control timing signal. The security control status data includes a test completion flag determined in the test state or a release status flag determined in the flight state.

[0019] In step 11 of this embodiment, the system first obtains the current mission stage identifier, which is used to clarify the current mission stage of the launch vehicle, such as the preparation stage, testing stage, or flight stage. Simultaneously, the system also obtains preset timing configuration data, which details the operations that the safety control equipment should perform and their timing arrangements under different mission stages, providing a basis for subsequent control logic loading. In step 12, based on the current mission phase identifier, the system determines the operational status of the launch vehicle's safety control equipment. The operational status is mainly divided into two types: testing status and flight status. Testing status is used to conduct multiple deactivation and detonation tests on the ground to verify the performance of the safety control equipment; flight status ensures that the safety control equipment can accurately and reliably perform safety control tasks during the actual flight of the rocket. In step 13, based on the determined working state and the acquired timing configuration data, the corresponding preset control logic is loaded. Specifically, when the working state is test state, the system loads the preset test state control logic, which specifies in detail the operation steps, timing requirements, and reset mechanisms to be executed during the test; when the working state is flight state, the system loads the preset flight state control logic, which focuses on ensuring the stability and reliability of the safety control equipment during flight, including the judgment of the unlocking conditions, the execution of the unlocking operation, and the maintenance of the unlocking state. In step 14, the system generates control timing signals corresponding to the current operating state. These signals guide the security control equipment on when to perform which operations. Simultaneously, the system collects and processes security status data, including a test completion flag determined in test mode to indicate whether the test was successfully completed; or a deactivation flag determined in flight mode to indicate whether the security control equipment has been successfully deactivated and remains deactivated. Finally, the system outputs control timing signals so that the security control equipment can perform corresponding operations according to preset timing requirements.

[0020] This invention proposes the above-mentioned technical solution, which, through the design of a dual-mode safety control architecture, distinguishes between the pre-launch test state and the post-launch flight state, and loads preset control logic and timing configuration data for each state, achieving precise control of the launch vehicle's safety control equipment at different mission stages. In the test state, it supports multiple release, detonation tests, and reset operations, ensuring the sufficiency and efficiency of ground testing. In the flight state, through clear release condition judgments and state locking mechanisms, it ensures safety and reliability during flight. Simultaneously, this solution also achieves real-time monitoring and status feedback of the safety control equipment's operation process by generating precise control timing signals and collecting safety control status data, further improving the overall performance of the launch vehicle's safety control system.

[0021] In an optional embodiment of the present invention, step 11, obtaining the current task stage identifier and preset timing configuration data, includes: Step 111: Receive a phase switching instruction from the launch vehicle mission management system, and parse the phase switching instruction to obtain the current mission phase identifier; Step 112: Read the pre-stored timing configuration data from the memory of the launch vehicle safety control equipment. The timing configuration data includes at least a first timing sequence corresponding to the test state and a second timing sequence corresponding to the flight state.

[0022] In step 111 of this embodiment, the process of receiving and parsing the phase switching instruction is a key interface for the collaborative work between the security control system and the launch vehicle mission management system. Specifically, the "phase switching instruction" is a structured digital message that includes at least an instruction type field, a mission phase code, a timestamp, and an integrity check code. After receiving the message, the instruction receiving unit of the security control system first performs frame synchronization and format verification, and then extracts the "current mission phase identifier," which is usually an enumerated value, such as "TEST" (test status) or "FLIGHT" (flight status). To ensure the absolute reliability and tamper-proof nature of the instruction, the parsing process also includes verification of the check code (such as CRC32 or digital signature). The verification logic can be expressed as: Verify(Instruction_RAW, Key) = TRUE, where Instruction_RAW is the received raw instruction data, and Key is a preset verification key or algorithm parameter. Only when the verification passes is the parsed mission phase identifier considered valid and used as input for subsequent logic; otherwise, the system will discard the instruction and request a retransmission or trigger an exception handling process.

[0023] In step 112, the process of reading the pre-stored timing configuration data is the foundation for realizing dual-mode differentiated control. The "memory" specifically refers to a non-volatile memory chip (such as EEPROM or Flash) within the security control equipment, which stores a "timing configuration database." This database organizes the complete control timing corresponding to different task stages in a structured data format (such as lookup tables or configuration files). The "first timing sequence" corresponds to the test state, and its data structure contains a series of ordered action nodes. Each node defines the action type (such as "reset command receiver," "blocking control"), the electrical parameters of the output signal (such as level, pulse width), and the duration of the action or the delay between it and the preceding action. Similarly, the "second timing sequence" corresponds to the flight state, and its node definitions focus on the state monitoring cycle, condition judgment interval, and upper limit of command response delay. The read operation is driven by the memory, using the "current task stage identifier" parsed in step 111 as the index key to perform a data retrieval, thereby accurately loading the corresponding timing sequence data structure into the system memory for the timing generator to call. To ensure data reliability, a cyclic redundancy check is usually performed after reading to ensure that the loaded configuration data is consistent with the data stored.

[0024] In an optional embodiment of the present invention, step 12, determining the working status of the launch vehicle safety control equipment based on the current mission stage identifier, includes: Step 121: When the current task stage is identified as a first preset value, the working state is determined as a test state; Step 122: When the current task stage is identified as the second preset value, the working state is determined to be the flight state.

[0025] In step 121 of this embodiment, the "first preset value" is a data enumeration value predefined in the system constant table, such as PHASE. TEST A value of 0 uniquely maps to the "ground verification phase". When the system parses the "current task phase identifier" (denoted as Phase)... ID If the value is equal to this preset value, then the logical condition Phase is satisfied. ID ==PHASE TEST At that time, the system's main control logic executes the state decision function Determine_WorkState(Phase). IDThe system outputs its "working status" as "test status." In this state, the system's internal resource configuration and control strategy are restructured: all test interfaces and repeatable verification logic are allowed and enabled; the safety command channel is set to receive and respond to ground test commands; and the test count counter, function enable flag, and buffer for recording test process data are initialized. Determining this state is a fundamental prerequisite for subsequently executing a complete and repeatable test sequence, including detonation, bolt sealing, release protection tests, and detonation tests.

[0026] In step 122, the "second preset value" is another predefined enumerated value, such as PHASE. FLIGHT Or the value 1, uniquely mapped to the "flight mission phase". When the logical condition Phase is met... ID ==PHASE FLIGHT At that time, the state decision function Determine_WorkState (Phase) ID The output of the test is determined to be "flight status". This determination triggers a series of irreversible or high-priority system configuration changes: First, all ground testing functions are forcibly disabled, and test command channels are closed or invalidated; second, the system switches to a high-frequency, low-latency flight parameter monitoring mode and activates the active safety control condition calculation task based on real-time data; finally, the system prepares to receive and respond only to safety commands (such as pre-warning commands and action commands) from the flight link. This determination signifies that the system has transitioned from a flexible, repeatable verification environment to a unidirectional, deterministic operational environment that ensures flight safety with the highest reliability. It is the necessary state foundation for executing in-flight safety control decisions and command generation logic.

[0027] In an optional embodiment of the present invention, step 13, loading corresponding preset control logic according to the working state and the timing configuration data, includes: Step 131: When the working state is the test state, the preset test state control logic is loaded and initialized from the control logic library preset in the security control device according to the first timing sequence contained in the timing configuration data. Step 132: When the working state is flight state, the preset flight state control logic is loaded and initialized from the control logic library according to the second timing sequence contained in the timing configuration data.

[0028] In step 131 of this embodiment, the "control logic library" is a set of structured functions and rules embedded in the executable memory of the security control equipment. When the working state is determined to be the test state, the system core scheduler uses the "first time sequence" as the key configuration parameter and executes the loading operation Load_Logic(TEST, First_Sequence). Specifically, the system dynamically links and instantiates the corresponding functional modules from the logic library according to the action node sequence defined in the first time sequence (e.g., "detonation control" → "locking control" → "defense test" → "detonation test"). These modules include: the instruction receiver reset driver module, the security mechanism locking driver module, the defense test excitation generation module, the detonation test excitation generation module, and their corresponding feedback verification modules. The initialization process Initialize_Logic() includes: allocating runtime memory for the above modules; injecting the time parameters in the first time sequence (e.g., the duration T_duration of each action) into the corresponding timer controller; clearing the test count counter; and setting the system's internal security state machine to an initial security state S_init=SAFE that accepts repeated testing. This step ensures that all control behaviors in the test state are strictly constrained within a pre-defined, cyclically executable timing framework.

[0029] In step 132, when the working state is determined to be the flight state, the system executes an irreversible logic switching operation Load_Logic(FLIGHT, Second_Sequence). Unlike the test state, the system loads a different set of highly optimized control logic based on the "second time sequence," prioritizing reliability and real-time performance. This includes: a high-speed flight parameter acquisition and filtering module, a real-time calculation module for active safety control conditions based on multi-source information, a ground safety command parsing and priority arbitration module, and a final drive module for release / detonation commands. The initialization process Initialize_Logic() focuses on establishing the flight mission context: configuring a high-speed data buffer; setting the active safety control condition judgment threshold; setting the release status lock flag L_arm to unlocked (FALSE); and disabling all test-related functional interfaces. The monitoring period, judgment interval, and other time parameters defined in the second time sequence are directly applied to the initialized mission scheduler, thereby ensuring that the flight state control logic can run at a defined rhythm and priority until the mission ends.

[0030] In an optional embodiment of the present invention, step 14 involves controlling the security control device according to the preset control logic to obtain control timing signals and security control status data corresponding to the working state, including: Step 1411: Based on the preset test state control logic, determine the control timing signal corresponding to the test state. The control timing signal corresponding to the test state includes multiple preset control actions and timing signals with corresponding durations. Step 1412: Obtain the historical number of tests and the preset maximum allowed number of tests; Step 1413: Determine the test feasibility factor based on the historical number of tests and the maximum allowed number of tests, using the following formula: ; in, To test feasibility factors; A test margin factor greater than 0; This refers to the number of historical tests. This represents the maximum number of tests allowed. Step 1414: When the test feasibility factor is greater than the preset feasibility threshold, the control timing signal is parsed and processed to obtain the first control command and the second control command. Step 1415: According to the first control command, control the safety command receiver of the security control equipment to reset and control the security control equipment to perform a detonation test to obtain the first test result; Step 1416: According to the second control command, control the security mechanism of the security control equipment to reset and control the security control equipment to perform a security unlocking test to obtain the second test result; Step 1417: Obtain the test completion flag based on the first test result and the second test result.

[0031] In step 1411 of this embodiment, determining the control timing signal corresponding to the test state according to the preset test state control logic means that the system generates a sequence of action instructions with a strict time order based on the loaded test logic. This sequence can be formally represented as: Seq test =[( A 1, T 1, P 1), ( A 2, T 2, P 2), …, ( A n , T n , P n ], where each tuple contains: action type identifier A i (Such as "detonation control", "bolt control", etc.), the preset duration of this action. T iand the output signal parameter set of this action. P i (Such as level, pulse width, drive current, etc.). This timing signal completely defines the execution order and timing plan of all control actions within a single test cycle, and serves as the direct basis for subsequent hardware driving.

[0032] In step 1412, obtaining the historical test count and the preset maximum allowed test count refers to the system reading two key integer parameters from the non-volatile memory unit: and . This is the cumulative number of complete tests that have been successfully executed since the start of this task cycle or since the last hardware reset; This is the maximum number of tests allowed to be performed, preset according to the equipment reliability model or task outline. Its value is determined during system initialization.

[0033] In step 1413, the test feasibility factor is determined based on the historical number of tests and the maximum allowed number of tests. This is used to assess the rationale for continuing the test, and the specific formula is as follows: ; Where α is a test margin coefficient greater than 0, used to introduce design margin to prevent testing at critical number of cycles; This indicates the remaining number of allowed tests. This factor... The range is [0, The larger the value, the more sufficient the test margin.

[0034] In step 1414, the system will With a pre-set threshold (usually meets) Compare them. If the conditions are met... If the system deems the testing conditions met, it will then analyze the timing signal: based on the functional coupling relationship between actions, the action elements in the sequence are grouped and mapped into two types of hardware driver instruction sets that can be executed in parallel or sequentially, denoted as the first control instruction Cmd1 (associated instruction receiver reset and detonation test) and the second control instruction Cmd2 (associated security agency reset and de-escalation test). If the test fails, the process will be terminated and an alarm status of "insufficient number of tests" will be generated.

[0035] In step 1415, the step of resetting the safety command receiver of the security control equipment according to the first control command and controlling the security control equipment to perform the detonation test refers to the system executing Cmd1. This process is divided into two sub-stages: First, a reset pulse signal with specific electrical characteristics is output to the safety command receiver to clear its internal logic state, and then the system waits for the receiver to return a "reset confirmation" signal. S reset Subsequently, a test excitation signal simulating a real detonation command is output to the detonation circuit, while the circuit's self-test feedback signal is monitored. S detfb First test results R 1. By logical functions R 1=( S reset ==OK)∩( S detfb ==OK) Decision, if both are normal. R 1 indicates "success", otherwise it indicates "failure".

[0036] In step 1416, the step of resetting the security mechanism of the security control equipment according to the second control command and controlling the security control equipment to perform the security release test refers to the system executing Cmd2. This process is also divided into two sub-stages: First, the bolt-closing drive signal is output to the bolt-closing actuator of the security mechanism to drive its mechanical parts back to the safe position, and the "bolt in place" signal returned by the position sensor is received. S lock Subsequently, a release test excitation signal is output to the release drive circuit, enabling the mechanism to complete the release action rehearsal without disengaging the final insurance, and receiving the action feedback signal. S armfb Second test results R 2 by R 2=( S lock ==OK)∩( S armfb ==OK) Decision.

[0037] In step 1417, obtaining the test completion flag based on the first and second test results refers to the system's comprehensive assessment of the execution effect of a single test. The test completion flag is a composite data structure, containing at least the global execution state (State) and the detailed result code (Code). Its generation logic is as follows: If... R 1 and R If both tests are "successful", then State is set to "successfully completed", and the historical test count is updated. If any result is "failure", then State is set to "failure", and Code records the specific failure details (such as reset timeout, feedback exception, etc.). This flag remains unchanged. It will serve as the final output of this test, used to update the system state and notify the upper-level control flow.

[0038] In an optional embodiment of the present invention, step 14, controlling the security control device according to the preset control logic to obtain control timing signals and security control status data corresponding to the working state, further includes: Step 1421: Determine the control timing signal corresponding to the flight state according to the preset flight state control logic; Step 1422: Obtain flight status data and ground security control commands; Step 1423: Based on the flight status data and the ground security control command, determine the protection requirement data. The specific formula is as follows: ; in, To solve the data demand for protection, and All are weighted coefficients. This is a function for determining whether to protect data based on flight status data. This is a function for determining whether to release protection based on ground commands. For flight status data; Ground security control instructions; Step 1424: When the insurance release demand data is greater than the preset insurance release threshold, perform the insurance release operation and obtain the insurance release status flag.

[0039] In step 1421 of this embodiment, the system generates a periodic command scheduling framework based on monitoring, judgment, and response, according to the loaded and initialized flight state control logic. This timing signal defines the execution rhythm and priority of each task in the flight state, and can be represented as: Seq flight = { (Monitor, T m , P m ), (Judge, T j , P j ),(Act, T a , P a )}, where Monitor is the task of continuously or periodically collecting flight status data (such as attitude and trajectory); Judge is the task of calculating and judging security control conditions based on the collected data and instructions; Act is the task of performing actions such as deactivation or detonation when the conditions are met. T m T j T a These represent the various task cycles or allowed execution windows, P m P j P aThese are the configuration parameters for the corresponding tasks, such as sensor channels, filtering algorithms, judgment thresholds, and driving parameters.

[0040] In step 1422, the system executes two data input processes in parallel. First, based on the timing signal Seq... flight The Monitor task configuration in the system periodically collects multi-dimensional V data from the onboard sensor network (such as inertial navigation, satellite navigation, and rate gyroscope). flight This data is typically a real-time vector containing elements such as position, velocity, attitude angle, and angular velocity. Secondly, the system continuously listens for and receives safety commands from ground control stations via an independent, highly reliable uplink command receiving channel. After format verification and decryption, it obtains structured C... ground The instruction object includes the instruction type (such as pre-order or active order), instruction effective time, and verification information.

[0041] In step 1423, the determination of the protection requirement data D based on flight status data and ground security control instructions is performed. arm This is a core calculation step in flight safety control decision-making. Its specific formula is: ; Among them, D arm The data for resolving protection needs is a dimensionless scalar value or a scalar value with specific physical meaning. The larger the value, the more urgent the protection needs. β and γ are the weighting coefficients of autonomous flight status judgment and ground command response, respectively, satisfying β≥0 and γ≥0. Usually, β+γ=1 is normalized. The specific values ​​reflect the trust weight of different decision sources. This is a function for determining whether to release the protection based on flight status data. This function processes real-time acquired flight status data. Processing is performed, such as calculating the magnitude of its deviation from the nominal orbit, evaluating attitude stability indicators, or performing fault mode identification, and finally outputting a quantitative value that characterizes the "degree of flight anomaly" or "necessity of active safety control". This is a function for determining whether to disable or restore security based on ground commands; this function parses ground security control commands. If a valid release or activation command is received, a high level (such as logic value 1 or a large fixed value) is output; otherwise, a low level (such as 0) is output.

[0042] This formula quantitatively integrates autonomous judgment with external instructions, D arm This comprehensively reflects the intensity of demand for protection actions from both internal and external aspects of the system.

[0043] In step 1424, the step of performing the insurance release operation and obtaining the insurance release status flag when the insurance release demand data is greater than the preset insurance release threshold means that the system will calculate the D armWith a pre-set release threshold θ arm Compare them. If D is satisfied... arm >θ arm If the condition for releasing the protection is met, the system will then proceed according to the timing signal Seq. flight The configuration of the Act task generates and outputs a high-energy, high-reliability release drive pulse sequence to the security mechanism, controlling it to perform a physical release action. After the operation is executed, the system immediately collects the mechanism's status feedback signal for verification. The release status flag is used. armed The generation logic is as follows: if the drive signal output is normal and a valid "release and protection in place" feedback is received, then the Flag is set. armed The condition is set to "TRUE" (protection has been released), and state locking logic is usually initiated simultaneously; if any step fails, the flag is set. armed The value is "FALSE", and the fault code is recorded.

[0044] In an optional embodiment of the present invention, the launch vehicle safety control method further includes: Step 15: The control timing signal, the security control status data and the corresponding timestamp are associated and encapsulated to obtain a structured security control process log file.

[0045] In step 15 of this embodiment, the system executes a parallel, uninterrupted data recording and synthesis process throughout the entire task cycle. Specifically, the system assigns a high-precision, synchronized absolute timestamp T to each key event (such as state switching, control signal generation, test result generation, and protection judgment and execution) or periodic data. stamp Subsequently, the system correlates, sorts, and encapsulates discrete data tuples according to a predefined log structure model. The encapsulation process can be formalized as a data block generation function: Data Block =Package(Event Type , T stamp Signa lSnapshot State Snapshot Hash prev ), Among them, Event Type Identify the event type, Signa lSnapshot It is a snapshot of the key parameters of the relevant control timing signals when the event is triggered, State Snapshot It is a snapshot of the corresponding system security status data, Hash prev This is the hash value of the previous data block, used to form a tamper-proof chain structure. All Data blocks generated in chronological order... BlockUltimately, the data is serialized and written to a non-volatile storage medium, forming a complete, time-series correlated, comprehensive, and verifiable structured file. This file not only serves as the basis for post-event analysis but also acts as a "chain of evidence for the security control process," constituting a key data product for verifying whether the system's behavior conforms to preset logic.

[0046] In an optional embodiment of the present invention, the launch vehicle safety control method further includes: Step 161: Obtain the flight mission completion confirmation signal; Step 162: Based on the flight mission completion confirmation signal, unlock the security mechanism's unsecured status and reset the launch vehicle's security control equipment to standby status.

[0047] In step 161 of this embodiment, after the flight phase ends, the launch vehicle safety control system listens for and receives the termination command from the ground control center through its uplink command receiving channel. This signal is a digital command with a specific encoding format and a very high level of authority. Its data structure includes at least the "command type" (clearly identifying it as mission termination), the "mission unique identifier," the "timestamp," and a "digital signature" based on an asymmetric encryption algorithm. After receiving the raw data, the system first performs communication link verification and frame synchronization, and then initiates a strict verification process. Only when the digital signature verification passes and the command type matches is the signal confirmed as a legitimate and valid "flight mission termination confirmation signal" and sent to subsequent processing logic.

[0048] In step 162 of this embodiment, the system performs a series of irreversible state transitions and initialization operations. First, the system core state machine, based on the verified confirmation signal, sets the internally maintained "unlocked state lock flag" L... arm The system is forced to FALSE, releasing the hardware or logic lock on the security facility and restoring its controllability. A complete state reset is then performed, changing the current operational status from "FLIGHT" to "STANDBY" (standby); all dynamic control parameters, cached data, and temporary status flags related to this flight mission are cleared or restored to factory default values; and the ground test interface is re-enabled. Simultaneously, the system generates a final "mission termination" event record, including the lock release time and reset operation results, and appends it to the security process log. This forms a complete, closed-loop chain of state evidence from startup, operation to termination, ensuring the system returns to a certain, safe, and ready-to-accept the next mission initial state.

[0049] A specific embodiment of the launch vehicle safety control method provided by this invention is as follows: Step 1: Obtain the current task stage identifier and the preset timing configuration data.

[0050] The system first continuously monitors and receives phase switching commands from the launch vehicle mission management system via a highly reliable command receiving link. These commands are structured data packets containing command codes, timestamps, and digital signatures. After decrypting, formatting, and verifying the signature to ensure authenticity and integrity, the system parses out the "current mission phase identifier," representing the rocket's current macroscopic phase, such as a specific enumerated value "PHASE." TEST "PHASE" represents the ground testing phase. FLIGHT This represents the on-orbit flight phase. Simultaneously, the system accesses a pre-stored "timing configuration database" in its internal non-volatile memory. This database is a structured set of parameters. The system uses the parsed phase identifier as an index key to perform a retrieval operation and accurately read the timing configuration data associated with it. This data contains at least two independent timing sequences: one is the "first timing sequence," which defines in detail the various control actions, their sequence, and their strict durations from system reset to functional verification in the test state; the other is the "second timing sequence," which specifies the rhythm and time constraints of periodic tasks from parameter acquisition and condition judgment to command execution in the flight state.

[0051] Step 2: Determine the working status of the launch vehicle's safety control equipment based on the current mission stage identifier.

[0052] The system compares the parsed "current task stage identifier" with an internally preset constant to drive the core state decision logic. Specifically, when the identifier equals the preset value "PHASE", the system will determine the current task stage. TEST When the system determines that the rocket is in a period requiring thorough ground verification, it sets the "operating status" of the safety control equipment to "test status." In this state, the system's internal flags, resource allocation, and control strategies are configured to support a flexible and repeatable test verification mode. For example, it allows ground commands to repeatedly trigger the test process and prepares to record test data. Conversely, when the flag equals another preset value "PHASE,"... FLIGHT When the system determines that the rocket has entered an irreversible flight mission phase, it changes the "operating status" to "flight status." This determination is a critical turning point, meaning that the system must completely switch from a test and verification mode to a mission execution mode that prioritizes mission safety with the highest reliability and real-time performance. All test functions will be disabled, and system resources will be focused on flight monitoring and safety decisions.

[0053] Step 3: Load the corresponding preset control logic according to the working status and the timing configuration data.

[0054] Based on the established operating state, the system dynamically loads the corresponding execution logic from the "control logic library" stored in memory. If the operating state is test state, the system instantiates and initializes the "test state control logic" from the logic library according to the action framework described by the "first timing sequence" in the acquired timing configuration data, controlling the timing as follows: Figure 2 As shown, Figure 2 The control timing flow of the present invention in the pre-flight test state is shown, including the timing relationship between the two control modes of active safety control and passive safety control.

[0055] Active security control mode sequence flow: Detonation (40-unit reset): First, output the detonation control signal to reset the safety command receiver and ensure that it is in the initial state where it can receive commands.

[0056] Bolt Closure: Outputs a bolt closure control signal to reset the security mechanism to the safe locking state.

[0057] Unlocking (opening the bolt): After the bolt is closed, an unlocking test is performed to simulate the bolt opening action of the security mechanism and verify its response capability.

[0058] Self-destruct detonation: After the protection is released, a self-destruct detonation test is performed to verify the reliability of the detonation control link.

[0059] Passive security control mode timing process: Detonation (40-unit reset): Similarly, first reset the safety command receiver.

[0060] Close the bolt: Reset the security mechanism to a safe state.

[0061] Pre-command (Opening): Receives a pre-command control signal sent from the ground, triggering the security agency to enter the pre-disarming state.

[0062] Action Command: Receives ground action command control signals, performs detonation tests, and verifies the response of the passive control link.

[0063] Timing characteristics: Both modes use de-explosion → closure as the initial reset steps to ensure consistent test starting points; the test process supports repeated execution, meeting the design goal of "supporting multiple tests"; each step in the timing sequence has a clear duration control to ensure the repeatability and controllability of the test.

[0064] If the operating state is flight state, the system loads and initializes a completely different "flight state control logic" according to the "second timing sequence," with the control timing as follows: Figure 3 As shown, Figure 3 The control timing flow of the present invention in the flight state after takeoff is shown, and the two control modes of active safety control and passive safety control are also distinguished.

[0065] Active security control mode sequence flow: Release protection: When active safety control conditions are met (such as rocket flight abnormalities), the system automatically triggers the release protection operation.

[0066] Self-destruct detonation: If the detonation conditions are still met after the protection is lifted, self-destruct detonation will be executed.

[0067] Passive security control mode timing process: Pre-command: Receives pre-command control signals sent from the ground and prepares to release protection.

[0068] Action Command: Receives ground action command control signals and executes release and subsequent detonation operations.

[0069] Timing characteristics: Unlocked Status: Once the system enters flight mode and unlocks, it will maintain this status until the mission ends to prevent accidental reset.

[0070] Rapid response: The sequence from condition assessment to action execution is compact, ensuring a rapid response in emergency situations.

[0071] Dual-path parallel operation: Active and passive control modes can be triggered independently or in parallel depending on the actual situation, enhancing system redundancy and security.

[0072] This logic focuses on loading modules such as high-speed data acquisition and filtering, real-time calculation of security control conditions through multi-source information fusion, ground command arbitration, and final action driving, and configures its task scheduling cycle according to the second time sequence. This step completes the conversion and binding from high-level state description to specific executable control code.

[0073] Step 4: Control the security control equipment according to the preset control logic to obtain control timing signals and security control status data corresponding to the working state.

[0074] The system runs the loaded control logic, generating precise "control timing signals" and driving the hardware, while simultaneously producing crucial "security control status data." In test mode, the control logic first generates a detailed action command flow conforming to the "first timing sequence." It then queries the historical test count and the preset maximum count, calculating the test feasibility factor. Only when the test feasibility factor exceeds the feasibility threshold will the logic continue: parsing the timing signals into specific "first control commands" and "second control commands," sequentially driving the security command receiver reset and detonation test, and the security agency reset and deactivation test, while collecting response feedback. Finally, by combining the feedback results of the two tests, a "test completion flag" representing the success or failure of this test is generated. In flight mode, the control logic operates according to the rhythm of the "second timing sequence," periodically collecting flight status data and listening for ground commands. It also calculates deactivation requirement data. When the deactivation requirement data exceeds the preset deactivation threshold, the logic immediately triggers the deactivation operation and, based on the operation execution result and agency feedback, generates a "deactivation status flag" indicating whether the security control system is in a ready-to-go state. Regardless of the state, the final generated control timing signal is output to the drive circuit of the security control equipment to control the action of the physical mechanism.

[0075] Step 5: Associate and encapsulate the control timing signal, the security control status data, and the corresponding timestamp to obtain a structured security control process log file.

[0076] Throughout the control process and at all state transition points, the system uses a high-precision clock source as a reference to assign a unique "timestamp" to every generated control timing signal segment and every updated security control status data (such as test completion flags and de-escalation flags). Subsequently, a parallel log service runs continuously, associating and encapsulating elements such as timestamps, event types, signal snapshots, and status snapshots according to a predefined structured format. For example, the initiation of a test, the output of each control command, and every calculation and judgment result of the de-escalation requirement data are all recorded as a data block with contextual information. All these chronologically ordered data blocks are eventually serialized and written to non-volatile memory, forming a complete "security control process log file." This file is not only a detailed record of system behavior, but its inherent temporal correlation and content integrity also constitute an immutable "security control process evidence chain" for post-task analysis, system evaluation, and accountability.

[0077] The launch vehicle safety control method proposed in this invention realizes intelligent and reliable management of the launch vehicle safety control system throughout its entire lifecycle, from ground testing to in-orbit flight, by constructing a complete dual-mode state decision-making and control execution process based on clear stage identifiers. This achieves a comprehensive improvement in testing flexibility, state isolation, decision accuracy, execution reliability, and process traceability, effectively ensuring the safety control requirements of the launch vehicle at different mission stages.

[0078] like Figure 4 As shown, this embodiment of the invention also provides a launch vehicle safety control device 40, comprising: The acquisition module 41 is used to acquire the current task stage identifier and the preset timing configuration data; Processing module 42 is used to determine the working status of the launch vehicle safety control equipment according to the current mission stage identifier, the working status including test status and flight status; and to load the corresponding preset control logic according to the working status and the timing configuration data; wherein, when the working status is test status, preset test status control logic is loaded; and when the working status is flight status, preset flight status control logic is loaded. The determination module 43 is used to control the security control equipment according to the preset control logic, obtain the control timing signal and security control status data corresponding to the working state, and output the control timing signal. The security control status data includes a test completion flag determined in the test state or a release status flag determined in the flight state.

[0079] Optionally, module 41 is specifically used for: Receive a phase switching instruction from the launch vehicle mission management system, and parse the phase switching instruction to obtain the current mission phase identifier; Read pre-stored timing configuration data from the memory of the launch vehicle's safety control equipment. The timing configuration data includes at least a first timing sequence corresponding to the test state and a second timing sequence corresponding to the flight state.

[0080] Optionally, processing module 42 is specifically used for: When the current task stage is identified as a first preset value, the working state is determined as a test state; When the current task stage is identified as the second preset value, the working state is determined to be the flight state.

[0081] Optionally, the processing module 42 is also specifically used for: When the working state is the test state, the preset test state control logic is loaded and initialized from the control logic library preset in the security control device according to the first timing sequence contained in the timing configuration data. When the working state is flight state, the preset flight state control logic is loaded and initialized from the control logic library according to the second timing sequence contained in the timing configuration data.

[0082] Optionally, module 43 is specifically used for: Based on the preset test state control logic, control timing signals corresponding to the test state are determined. The control timing signals corresponding to the test state include timing signals of multiple preset control actions and corresponding durations. Retrieve the historical number of tests and the preset maximum allowed number of tests; The test feasibility factor is determined based on the historical number of tests and the maximum allowed number of tests, using the following formula: ; in, To test feasibility factors; A test margin factor greater than 0; This refers to the number of historical tests. This represents the maximum number of tests allowed. When the test feasibility factor is greater than the preset feasibility threshold, the test sequence is executed and the test completion flag is obtained.

[0083] Optionally, when the test feasibility factor is greater than a preset feasibility threshold, executing the test sequence and obtaining the test completion flag includes: When the test feasibility factor is greater than the preset feasibility threshold, the control timing signal is parsed and processed to obtain the first control command and the second control command. According to the first control command, the safety command receiver of the security control equipment is reset and the security control equipment is controlled to perform a detonation test to obtain the first test result. According to the second control command, the security mechanism of the security control equipment is reset and the security control equipment is controlled to perform a security unlocking test to obtain the second test result; The test completion flag is obtained based on the first test result and the second test result.

[0084] Optionally, module 43 is also specifically used for: Based on the preset flight state control logic, determine the control timing signal corresponding to the flight state; Acquire flight status data and ground safety control commands; Based on the flight status data and the ground security control instructions, the data for determining the protection requirements is calculated using the following formula: ; in, To solve the data demand for protection, and All are weighted coefficients. This is a function for determining whether to protect data based on flight status data. This is a function for determining whether to release protection based on ground commands. For flight status data; Ground security control instructions; When the insurance release demand data is greater than the preset insurance release threshold, the insurance release operation is performed and the insurance release status flag is obtained.

[0085] Optionally, the launch vehicle safety control device 40 further includes: The generation module 44 is used to associate and encapsulate the control timing signal, the security control status data and the corresponding timestamp to obtain a structured security control process log file.

[0086] It should be noted that this device is a device corresponding to the above method. All implementation methods in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.

[0087] like Figure 5 As shown, this embodiment of the invention also provides a computing device 50, including a processor 51, a memory 52, and a program or instructions stored in the memory 52 and executable on the processor 51. When the program or instructions are executed by the processor 51, they implement the various processes of the above-described carrier rocket safety control method embodiment and achieve the same technical effects. To avoid repetition, they will not be described again here. It should be noted that the computing device in this embodiment of the invention includes the aforementioned mobile electronic devices and non-mobile electronic devices.

[0088] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0089] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0090] In the embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0091] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0092] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0093] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0094] Furthermore, it should be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent solutions of the present invention. Moreover, the steps performing the above series of processes can naturally be executed in the order described, but are not necessarily required to be executed in chronological order; some steps can be executed in parallel or independently of each other. Those skilled in the art will understand that all or any step or component of the method and apparatus of the present invention can be implemented in any computing device (including processors, storage media, etc.) or network of computing devices, in hardware, firmware, software, or a combination thereof. This is something that those skilled in the art can achieve by using their basic programming skills after reading the description of the present invention.

[0095] Therefore, the object of the present invention can also be achieved by running a program or a set of programs on any computing device. The computing device can be a known general-purpose device. Therefore, the object of the present invention can also be achieved simply by providing a program product containing program code for implementing the method or apparatus. That is, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any known storage medium or any storage medium developed in the future. It should also be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent to the present invention. Furthermore, the steps for performing the above series of processes can naturally be performed in the order described, but are not necessarily required to be performed in chronological order. Some steps can be performed in parallel or independently of each other.

[0096] The above are preferred embodiments of the present invention. It should be noted that, for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for safety control of a launch vehicle, characterized in that, include: Obtain the current task stage identifier and preset timing configuration data; Based on the current mission phase identifier, determine the working status of the launch vehicle's safety control equipment, including the testing status and the flight status. Based on the working state and the timing configuration data, the corresponding preset control logic is loaded; wherein, when the working state is the test state, the preset test state control logic is loaded; when the working state is the flight state, the preset flight state control logic is loaded. According to the preset control logic, the security control equipment is controlled to obtain control timing signals and security control status data corresponding to the working state, and the control timing signals are output. The security control status data includes a test completion flag determined in the test state, or a release status flag determined in the flight state.

2. The launch vehicle safety control method according to claim 1, characterized in that, The step of obtaining the current task stage identifier and preset timing configuration data includes: Receive a phase switching instruction from the launch vehicle mission management system, and parse the phase switching instruction to obtain the current mission phase identifier; Read pre-stored timing configuration data from the memory of the launch vehicle's safety control equipment. The timing configuration data includes at least a first timing sequence corresponding to the test state and a second timing sequence corresponding to the flight state.

3. The launch vehicle safety control method according to claim 2, characterized in that, Based on the current mission phase identifier, determine the operational status of the launch vehicle's safety control equipment, including: When the current task stage is identified as a first preset value, the working state is determined as a test state; When the current task stage is identified as the second preset value, the working state is determined to be the flight state.

4. The launch vehicle safety control method according to claim 2, characterized in that, Based on the working status and the timing configuration data, load the corresponding preset control logic, including: When the working state is the test state, the preset test state control logic is loaded and initialized from the control logic library preset in the security control device according to the first timing sequence contained in the timing configuration data. When the working state is flight state, the preset flight state control logic is loaded and initialized from the control logic library according to the second timing sequence contained in the timing configuration data.

5. The launch vehicle safety control method according to claim 1, characterized in that, According to the preset control logic, the security control equipment is controlled to obtain control timing signals and security status data corresponding to the working state, including: Based on the preset test state control logic, control timing signals corresponding to the test state are determined. The control timing signals corresponding to the test state include timing signals of multiple preset control actions and corresponding durations. Retrieve the historical number of tests and the preset maximum allowed number of tests; The test feasibility factor is determined based on the historical number of tests and the maximum allowed number of tests, using the following formula: ; in, To test feasibility factors; A test margin factor greater than 0; This refers to the number of historical tests. This represents the maximum number of tests allowed. When the test feasibility factor is greater than the preset feasibility threshold, the test sequence is executed and the test completion flag is obtained.

6. The launch vehicle safety control method according to claim 5, characterized in that, When the test feasibility factor is greater than a preset feasibility threshold, the test sequence is executed and the test completion flag is obtained, including: When the test feasibility factor is greater than the preset feasibility threshold, the control timing signal is parsed and processed to obtain the first control command and the second control command. According to the first control command, the safety command receiver of the security control equipment is reset and the security control equipment is controlled to perform a detonation test to obtain the first test result. According to the second control command, the security mechanism of the security control equipment is reset and the security control equipment is controlled to perform a security unlocking test to obtain the second test result; The test completion flag is obtained based on the first test result and the second test result.

7. The launch vehicle safety control method according to claim 1, characterized in that, According to the preset control logic, the security control equipment is controlled to obtain control timing signals and security status data corresponding to the working state, and the system further includes: Based on the preset flight state control logic, determine the control timing signal corresponding to the flight state; Acquire flight status data and ground safety control commands; Based on the flight status data and the ground security control instructions, the data for determining the protection requirements is calculated using the following formula: ; in, To solve the data demand for protection, and All are weighted coefficients. This is a function for determining whether to protect the flight based on flight status data. This is a function for determining whether to release protection based on ground commands. For flight status data; Ground security control instructions; When the insurance release demand data is greater than the preset insurance release threshold, the insurance release operation is performed and the insurance release status flag is obtained.

8. The launch vehicle safety control method according to claim 1, characterized in that, Also includes: The control timing signals, the security control status data, and the corresponding timestamps are associated and encapsulated to obtain a structured security control process log file.

9. A launch vehicle safety control device, characterized in that, include: The acquisition module is used to acquire the current task stage identifier and preset timing configuration data; The processing module is used to determine the working status of the launch vehicle safety control equipment based on the current mission stage identifier, the working status including test status and flight status; and to load the corresponding preset control logic based on the working status and the timing configuration data; wherein, when the working status is test status, preset test status control logic is loaded; and when the working status is flight status, preset flight status control logic is loaded. The determination module is used to control the security control equipment according to the preset control logic, obtain control timing signals and security control status data corresponding to the working state, and output the control timing signals. The security control status data includes a test completion flag determined in the test state, or a release status flag determined in the flight state.

10. A computing device, characterized in that, include: A processor, a memory storing a computer program, wherein the computer program, when executed by the processor, performs the method as described in any one of claims 1 to 8.