Ground facility equipment redundancy control system and method
By constructing a system consisting of a centralized control module, a redundant network, a field control module, and an equipment execution module, and combining a multi-dimensional intelligent redundancy architecture and AI-driven intelligent fault tolerance, the system solves the problems of decentralized redundancy design and insufficient intelligence in ground facility control systems, achieving highly reliable and efficient execution of space launch missions.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- AEROSPACE NEW LONG MARCH AVENUE TECH CO LTD
- Filing Date
- 2025-11-25
- Publication Date
- 2026-04-10
AI Technical Summary
The existing ground facility control system suffers from redundant design, poor coordination, and insufficient intelligence, making it difficult to meet the high reliability requirements of space launch missions.
The system is constructed by establishing a centralized control module, a redundant network, a field control module, and an equipment execution module. It adopts a multi-dimensional intelligent redundancy architecture and combines data and AI-driven intelligent fault tolerance and predictive maintenance to achieve a full-cycle, full-scenario control system.
It improves the reliability, safety, and operational efficiency of ground facilities and equipment in space launch missions, ensures the system continues to operate stably in the event of a failure, reduces operational complexity, and enhances emergency response speed.
Smart Images

Figure CN121832418A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of industrial automation control technology, and in particular to a redundant control system and method for ground facilities and equipment. Background Technology
[0002] This section is intended to provide background or context for the embodiments of this disclosure as set forth in the claims. The description herein is not intended to be a prior art simply because it is included in this section.
[0003] In space launch missions, the control systems of ground facilities and equipment are responsible for monitoring and executing critical processes such as rocket assembly, testing, and transportation. Their reliability directly affects the success of the launch mission. Traditional control systems mostly adopt distributed control methods based on programmable logic controllers (PLCs). Although they have a certain degree of local autonomy, they have significant shortcomings in overall reliability, fault tolerance, and system integration. Currently, redundancy design has become a common practice in the field of industrial control to improve system reliability.
[0004] However, the relevant technologies suffer from problems such as redundant and dispersed design of ground facility control systems, poor coordination, and insufficient intelligence. Summary of the Invention
[0005] In view of this, the purpose of this disclosure is to propose a redundant control system and method for ground facilities and equipment, which at least partially solves one of the technical problems in the related art.
[0006] In view of the above objectives, the first aspect of the exemplary embodiments of this disclosure provides a redundant control system for ground facilities and equipment, the system comprising: a centralized control module, a redundant network, a field control module, and an equipment execution module; The centralized control module is connected to the field control module through a redundant network and is configured to generate control commands and transmit the control commands to the field control module. The field control module is connected to the device execution module through the redundant network and is configured to receive the control command transmitted by the centralized control module and then transmit the control command to the device execution module. The device execution module is configured to receive control commands transmitted by the field control module and execute physical actions; The redundant network is configured to provide a communication channel between the centralized control module, the field control module, and the device execution module.
[0007] Based on the same inventive concept, a second aspect of the exemplary embodiments of this disclosure provides a method for redundancy control of ground facilities and equipment, the method comprising: The system acquires the device operating parameters used to control the device execution module, analyzes the device operating parameters based on the centralized control module, and obtains control commands. The field control module transmits the control commands to the equipment execution module through a redundant network, and the equipment execution module executes the control commands to drive the ground facilities and equipment to complete the corresponding physical actions.
[0008] As can be seen from the above description, the ground facility equipment redundancy control system and method provided in this disclosure includes: a centralized control module, a redundant network, a field control module, and an equipment execution module. The centralized control module is connected to the field control module through the redundant network and is configured to generate control commands and transmit the control commands to the field control module. The field control module is connected to the equipment execution module through the redundant network and is configured to receive the control commands transmitted by the centralized control module and then transmit the control commands to the equipment execution module. The equipment execution module is configured to receive the control commands transmitted by the field control module and execute physical actions. The redundant network is configured to provide a communication channel between the centralized control module, the field control module, and the equipment execution module. This disclosure can solve the defects of existing ground facility control systems, such as dispersed redundancy design, poor coordination, and insufficient intelligence. Attached Figure Description
[0009] To more clearly illustrate the technical solutions in this disclosure or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0010] Figure 1 A schematic diagram of a redundant control system for ground facilities and equipment provided in an embodiment of this disclosure; Figure 2 A schematic diagram of a core redundancy module of a ground facility and equipment redundancy control system provided in an embodiment of this disclosure; Figure 3 A schematic diagram of a high-availability network redundancy for a ground facility and equipment redundancy control system provided in an embodiment of this disclosure; Figure 4 A schematic diagram of full-system equipment redundancy for a ground facility and equipment redundancy control system provided in this disclosure embodiment; Figure 5 A schematic diagram of deep hardware redundancy of a PLC for a ground facility and equipment redundancy control system provided in an embodiment of this disclosure; Figure 6 A schematic diagram of intelligent software redundancy for a ground facility and equipment redundancy control system provided in an embodiment of this disclosure; Figure 7 A flowchart illustrating a redundancy control method for ground facilities and equipment provided in an embodiment of this disclosure; Figure 8 This is a schematic diagram of an integrated three-level control mode redundancy of a ground facility and equipment redundancy control system provided in an embodiment of this disclosure. Detailed Implementation
[0011] It is understood that before using the technical solutions disclosed in the various embodiments of this application, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this application in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.
[0012] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this application's technical solution, based on the prompt message.
[0013] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0014] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this application. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this application.
[0015] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.
[0016] To make the objectives, technical solutions, and advantages of this disclosure clearer, the principles and spirit of this disclosure will be described below with reference to several exemplary embodiments. It should be understood that these embodiments are provided merely to enable those skilled in the art to better understand and implement this disclosure, and are not intended to limit the scope of this disclosure in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of this disclosure to those skilled in the art.
[0017] In this article, it is important to understand that any number of elements in the accompanying figures is for illustrative purposes and not for limitation, and any naming is for distinction only and has no limiting meaning.
[0018] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this disclosure should have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms "first," "second," and similar words used in the embodiments of this disclosure do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are used only to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly. The article "a" or "an" preceding an element does not exclude the existence of multiple such elements.
[0019] The principles and spirit of this disclosure will be explained in detail below with reference to several representative embodiments.
[0020] As described in the background section, related technologies suffer from problems such as dispersed redundancy design, poor coordination, and insufficient intelligence in ground facility control systems. Specifically, to improve system reliability, redundancy design has become a common practice in industrial control. Existing technologies mainly include various methods such as control mode redundancy, network redundancy, system redundancy, PLC redundancy, I / O redundancy, and software redundancy. For example, by setting up three levels of control modes—remote control, on-site automatic control, and local manual control—operation can continue through other levels even in the event of a failure at one level; network redundancy, such as a dual-fiber ring network structure, avoids single-point communication failures; and PLC redundancy, such as a dual-CPU, dual-power supply design, ensures that the controller can still operate normally in the event of component failure.
[0021] However, existing redundancy solutions mostly focus on the redundancy of local components or subsystems, lacking system-level integration and coordination. For example: While single redundancy modes such as heterogeneous redundancy can reduce the risk of common-mode failures, the integration complexity of devices from different manufacturers is high, and the data formats and interface standards are not uniform, which makes debugging and maintenance difficult. While control mode redundancy provides multi-level operational protection, there may be delays or inconsistencies in status during the switching process. While network redundancy and PLC redundancy improve communication and processing reliability, if end devices such as sensors and actuators are not redundant, they may still become single points of failure in the system. In addition, existing systems often lack a unified data platform and intelligent analysis capabilities, making it difficult to achieve fault prediction, simulation and closed-loop optimization, which limits the overall performance of the system when dealing with high-density and high-reliability tasks.
[0022] Therefore, existing technologies have not yet formed a highly reliable redundant control system that integrates control modes, platform capabilities, application scenarios, and operating carriers, making it difficult to meet the full-process, full-scenario, and highly reliable control requirements of aerospace launch sites for ground facilities and equipment during routine maintenance and high-density missions.
[0023] To address the aforementioned problems, this disclosure provides a redundant control system and method for ground facilities and equipment. The system specifically includes: The system comprises a centralized control module, a redundant network, a field control module, and an equipment execution module. The centralized control module is connected to the field control module via the redundant network and is configured to generate control commands and transmit them to the field control module. The field control module is connected to the equipment execution module via the redundant network and is configured to receive the control commands transmitted by the centralized control module and then transmit them to the equipment execution module. The equipment execution module is configured to receive the control commands transmitted by the field control module and execute physical actions. The redundant network is configured to provide a communication channel between the centralized control module, the field control module, and the equipment execution module. This disclosure systematically integrates multiple redundancy modes, such as control mode redundancy, network redundancy, system redundancy, PLC redundancy, IO redundancy, and software redundancy, and introduces a data, AI, and simulation-driven intelligent platform to construct a control system covering the entire lifecycle and all scenarios. Ultimately, this ensures that the system can continue to operate continuously, stably, and safely even when any single or multiple components fail, significantly improving the reliability, safety, and operational efficiency of aerospace launch site ground facilities in critical tasks such as testing, transportation, and launch.
[0024] The core highlight of this disclosure lies in its system-level integrated design philosophy and multi-dimensional intelligent redundancy architecture, specifically reflected in: "Three-dimensional" deep redundancy architecture This disclosure is not simply about piling up redundant components, but rather about constructing a three-dimensional, deep redundancy system encompassing control modes (remote / field / local), hardware systems (network / PLC / IO), and software logic (task-level / cross-PLC). These three dimensions of redundancy are intertwined and mutually reinforcing, forming a "three-dimensional" defense system that completely eliminates single points of failure in the control system at every stage, including instruction execution, data transmission, and logical operations.
[0025] Seamless transfer of control and operational equivalence Through integrated control logic, a smooth, controlled, and seamless switching between three control modes—remote centralized control, on-site PLC automatic control, and local manual control—is achieved. Regardless of the operator's location, the user interface, feedback mechanism, and execution effect remain consistent, ensuring flexible transfer of control without causing system disturbances or interruptions, greatly improving the flexibility and reliability of task execution.
[0026] Data and AI-driven intelligent fault tolerance and predictive maintenance This upgrades redundant systems from passive failover to proactive intelligent fault tolerance. The system utilizes a machine learning engine to analyze real-time data across the entire domain, predicting potential failures in critical components and generating maintenance alerts before failures occur. Simultaneously, AI can dynamically recommend optimal execution strategies for complex tasks, assisting operator decision-making and further enhancing system reliability from a fault-prevention perspective.
[0027] Simulation Pre-run and Security Verification Based on Digital Twin A high-precision digital twin model synchronized with the physical entity has been constructed. Any control strategy or operational procedure can be simulated and verified in the virtual environment beforehand. The system automatically calculates collision risks and process times, thereby eliminating potential safety hazards before actual execution. This function not only serves as operator training but also acts as a "safety sandbox" before control commands are issued, achieving inherent safety.
[0028] Heterogeneous resource integration management under a unified platform This disclosure successfully integrates various heterogeneous control subsystems (such as air conditioning, hydraulics, cranes, etc.) and redundant resources into a single operating interface through a unified software framework and standardized interfaces. Operators no longer need to deal with multiple distributed systems; they can achieve "what you see is what you control" on a unified "scenario-based integrated interface," greatly reducing operational complexity and improving emergency response speed.
[0029] Closed-loop optimization capabilities across the entire lifecycle and all scenarios The system covers the entire spectrum from simulation training and intelligent operation and maintenance during non-task periods to automated process execution during task periods. All task execution data is fully recorded and fed back to the AI analysis engine, forming a continuous improvement loop of "execution-analysis-optimization," enabling the system's reliability and efficiency to continuously evolve as the runtime increases.
[0030] In summary, this disclosure combines hard redundancy with soft intelligence to construct an integrated redundant control system that is not only "not easily damaged" but also "more intelligent," providing a brand-new solution for ground facilities of aerospace launch sites with high reliability requirements.
[0031] After introducing the basic principles of this disclosure, various non-limiting embodiments of this disclosure will be described in detail below.
[0032] refer to Figure 1 This is an example diagram of a redundant control system for ground facilities and equipment provided as an exemplary embodiment of the present disclosure.
[0033] The redundant control system for ground facilities and equipment includes: a centralized control module, a redundant network, a field control module, and an equipment execution module; The centralized control module is connected to the field control module through a redundant network and is configured to generate control commands and transmit the control commands to the field control module. The field control module is connected to the device execution module through the redundant network and is configured to receive the control command transmitted by the centralized control module and then transmit the control command to the device execution module. The device execution module is configured to receive control commands transmitted by the field control module and execute physical actions; The redundant network is configured to provide a communication channel between the centralized control module, the field control module, and the device execution module.
[0034] In specific implementation, the centralized control module is connected to the field control module through a redundant network and is configured to generate control commands and transmit the control commands to the field control module, which means: The centralized control module, as the system's central hub, is responsible for monitoring and analyzing the operational status of all ground facilities and equipment, and generating corresponding control commands based on preset control logic or real-time data. These commands are transmitted through a redundant network to ensure that, in the event of any single network failure, the commands can still safely and accurately reach the field control module, thereby achieving precise control and management of the equipment.
[0035] In specific implementation, the field control module is connected to the device execution module through the redundant network and is configured to receive the control commands transmitted by the centralized control module and then transmit the control commands to the device execution module. The field control module connects to the equipment execution module via a redundant network. Its main function is to receive control commands from the centralized control module and accurately transmit these commands to the equipment execution module to drive the equipment to perform corresponding physical actions. When remote communication is interrupted or the central control fails, the PLC can independently run a preset program, automatically control its subsystems (such as air conditioning and hydraulic platforms), and send critical status updates. This process relies on the high reliability of the redundant network to ensure that even in the event of partial network failure, control commands can still be seamlessly transmitted to the equipment execution module, thereby guaranteeing stable system operation and continuous equipment operation.
[0036] In specific implementation, the equipment execution module is configured to receive control commands transmitted by the field control module and perform physical actions, which means: The equipment execution module includes components such as sensors, actuators, motors, and valves. Upon receiving commands, these components can precisely perform operations such as starting, stopping, adjusting parameters, or executing specific tasks, thereby achieving actual control of ground facilities and equipment. The design of this module ensures that system commands can be efficiently translated into specific equipment actions.
[0037] In specific implementation, the redundant network is configured to provide a communication channel between the centralized control module, the field control module, and the device execution module, meaning: The redundant network is configured to provide a highly reliable communication channel between the central control module, field control module, and device execution module. This network employs a dual-fiber ring network and a star-redundant topology, ensuring that in the event of any single network failure, the communication link automatically switches to the backup path, thereby guaranteeing the continuity and stability of data transmission. The redundant network design not only improves the system's fault tolerance but also ensures that control commands and device status data can be transmitted efficiently and reliably between the central control module, field control module, and device execution module.
[0038] As a specific embodiment, refer to Figure 2 External systems A and B are connected to the core of the system via a convergence switch. This connection method not only ensures efficient data exchange between the external systems and the core control system, but also enhances the compatibility and scalability of the entire system.
[0039] Each plant is equipped with two redundant PLC master stations, labeled A and B respectively. Each master station is connected to an access switch, forming a redundant structure in the control layer. This redundancy design ensures that in the event of a master station failure, the backup station can seamlessly switch over and take over the control tasks, thereby significantly improving the system's reliability and fault tolerance.
[0040] Furthermore, each PLC master station is connected to multiple PLC slave stations, which are responsible for performing specific control tasks, such as hydraulic gate control, air conditioning and refrigeration station management, gas concentration monitoring and alarm, and sliding door control systems. Each slave station is connected to the master station through a redundant network. This design further enhances the system's communication reliability, ensuring that even if a network connection fails, the system can still maintain communication through other paths.
[0041] Furthermore, the connection between the touchscreen and the host computer and the PLC master station provides operators with an intuitive user interface, enabling them to monitor and control the system's operational status in real time. The touchscreen and host computer are connected to the PLC master station via a redundant network, ensuring high availability and stability of the operating interface.
[0042] In some embodiments, the redundant network includes a backbone network and an access network, wherein the backbone network adopts a dual-fiber ring network topology and the access network adopts a star redundant topology.
[0043] In specific implementation, the backbone network adopts a dual-fiber ring network topology, and the access network adopts a star-redundant topology, meaning: The redundant network consists of two parts: a backbone network and an access network. The backbone network adopts a dual-fiber ring network topology, enabling millisecond-level self-healing capabilities. This means that even if a single line or node fails, the network can be quickly reconfigured to ensure that overall communication is unaffected, thereby guaranteeing the stability and reliability of the control system.
[0044] At the access network layer, the system adopts a star-redundant topology. This topology configures redundant access switches in each subsystem, providing additional redundant paths for the network.
[0045] As a specific example, regarding high-availability network redundancy, please refer to [link / reference]. Figure 3 In the main network portion, the IoT platform serves as the core, connecting multiple cloud configuration clients, including platform gates, sliding gates, cranes, air conditioning and refrigeration stations, gas concentration monitoring, and gas supply systems. These clients are connected to the industrial control system via a redundant aggregation switch, enabling centralized data management and monitoring.
[0046] The redundant network section showcases a more detailed control system architecture. Each control system, such as the platform gate control system, sliding door control system, plant air conditioning and refrigeration station control system, plant gas concentration monitoring and alarm system, and gas supply control system, is equipped with a master PLC and slave PLCs, as well as a touch screen and remote I / O. This design ensures that in the event of a failure of the master PLC, the slave PLC can quickly take over the control tasks, guaranteeing continuous system operation.
[0047] Furthermore, remote I / O modules connected to the field devices via the I / O bus are responsible for direct input / output operations with the field devices. In addition, network redundancy is achieved through a main gateway and redundant gateways, ensuring high reliability of network communication.
[0048] As a specific example, regarding system-wide device redundancy, please refer to [link / reference]. Figure 4In the industrial control aggregation layer, the access switch serves as the core component, connecting multiple PLCs (Programmable Logic Controllers) and a touchscreen. These PLCs and the touchscreen are connected to the access switch via PN1 and PN2 network interfaces, forming a local area network (LAN). This design allows for centralized control and monitoring of industrial equipment.
[0049] Furthermore, both the main PLC and the redundant PLC are equipped with key components such as power supplies and CPUs to ensure that the redundant PLC can seamlessly take over control tasks and guarantee production continuity when the main PLC fails.
[0050] At the cloud server layer, the primary cloud server and redundant cloud servers are connected to the industrial control aggregation layer through the primary gateway and redundant gateway, respectively. This design not only provides centralized data storage and management but also improves data security and reliability through redundant configuration of the cloud servers. Connections between cloud servers are achieved through cloud data (primary and backup) network ports, ensuring data synchronization and consistency.
[0051] In addition, the host computer system, including Host Computer 1 and Host Computer 2, is connected to the cloud server layer through a main gateway and a redundant gateway. The host computer system provides operators with a user interface for monitoring and controlling the system's operational status.
[0052] In some embodiments, the field control module includes a redundant programmable logic controller (PLC), wherein the redundant PLC employs a dual-CPU, dual-power supply, and dual-backplane architecture.
[0053] In practical implementation, the field control module includes: a redundant programmable logic controller (PLC), wherein the redundant PLC adopts a dual-CPU, dual-power supply, and dual-backplane architecture, meaning: refer to Figure 5 The redundant programmable logic controller employs a dual-backplane, dual-CPU, and dual-power supply architecture. Both power modules supply power simultaneously, ensuring that a failure in either does not affect system operation. The primary and backup CPUs synchronize status and process data in real time via two independent synchronous buses.
[0054] Furthermore, the fieldbus adopts a ring network topology, coupled with couplers and I / O modules that support ring networks. Any single point of failure will cause the network to self-heal into a linear structure at the point of failure, ensuring that the communication of all subsequent I / O modules is unaffected.
[0055] As a specific example, regarding intelligent software redundancy, please refer to [link / reference]. Figure 6The primary and backup PLCs run the same control program. The backup PLC continuously monitors the primary PLC's heartbeat. When the primary PLC fails, the backup PLC can take over the control tasks within seconds, achieving a seamless switchover. Within the primary PLC, the process begins by reading input information, followed by executing the non-redundant program. Next, the primary PLC analyzes the status information from the backup PLC and then executes the redundant program. After completing these steps, the primary PLC sends its own status and the data requiring redundant backup to the backup PLC, and outputs both non-redundant and redundant output information.
[0056] The backup PLC's process is similar to that of the main PLC, but it first reads the input information and executes the non-redundant program. The backup PLC then analyzes the status information from the main PLC, selects to skip redundant programs, and sends the status information back to the main PLC. Finally, the backup PLC outputs both non-redundant and redundant output information.
[0057] This involves information exchange between the main PLC and the backup PLC when executing redundant programs. This ensures that if the main PLC fails, the backup PLC can quickly take over control tasks, guaranteeing system continuity and reliability.
[0058] In one specific embodiment, regarding task-level redundancy, within a single PLC, critical control tasks can be programmed multiple times and subjected to logical voting to prevent malfunctions caused by a single program running out of control.
[0059] In some embodiments, the field control module includes a data acquisition module, which is configured to acquire device status data from the device execution module and then transmit the device status data to the centralized control module.
[0060] In specific implementation, the data acquisition module is configured to acquire the device status data of the device execution module and then transmit the device status data to the centralized control module, which means: The edge gateway aggregates device status data from the device execution modules in real time. This data includes device operating parameters, sensor signals, and alarm information. After collection, the data acquisition module transmits the device status data to the centralized control module through a redundant network, providing real-time and accurate data support for centralized system monitoring, intelligent decision-making, and fault diagnosis, ensuring the system operates efficiently and reliably.
[0061] In some embodiments, the centralized control module includes a data analysis platform configured to analyze the device status data based on machine learning algorithms, predict potential faults, and generate maintenance alarms.
[0062] In specific implementation, the data analysis platform is configured to analyze the device status data based on machine learning algorithms, predict potential faults, and generate maintenance alarms. The data analysis platform analyzes equipment status data based on machine learning models, predicts potential faults such as motor bearing wear, and generates maintenance work orders in advance.
[0063] In some embodiments, the system further includes a local manual control module, which is hardwired to the device execution module.
[0064] In specific implementation, the local manual control module, which is connected to the device execution module via hardwiring, refers to: The system also features a dedicated local manual control module, which is directly connected to the equipment's execution module via hardwiring. This design ensures that in the event of remote or automatic control failure, operators can directly control the equipment on-site via the local manual control module to perform basic start-up, stop, and emergency stop operations. This provides a final safety guarantee for the system and further enhances its reliability and emergency response capabilities.
[0065] In some embodiments, the local manual control module includes an emergency operation button box, which is configured to directly drive the device execution module in response to the failure of both the centralized control module and the field control module.
[0066] In specific implementation, the local manual control module includes an emergency operation button box, which is configured to directly drive the equipment execution module via the emergency operation button box when both the centralized control module and the field control module fail. The core component of the local manual control module is the emergency operation button box, which is configured to directly drive the equipment execution module through hard wiring in the extreme case where both the centralized control module and the field control module fail, so as to realize the basic operation functions of the equipment, such as start, stop and emergency braking. This ensures that critical equipment can still be operated in an emergency when the system's high-level control level fails, thus guaranteeing the safety and reliability of the system.
[0067] In some embodiments, the device actuation module includes: a sensor, an actuator, a motor, and a valve.
[0068] In specific implementation, the device execution module includes: sensors, actuators, motors, and valves, which refer to: The equipment execution module is a key part of the system, encompassing various field devices such as sensors, actuators, motors, and valves. Sensors are responsible for collecting real-time data on equipment operating status and environmental parameters, providing data support for the system; actuators, motors, and valves execute specific actions according to control commands, such as driving equipment operation and regulating valve opening and closing, thereby achieving precise control and operation of ground facilities and equipment.
[0069] In some embodiments, the system further includes a digital twin module configured to build a virtual model synchronized with the physical device for operation rehearsal and fault simulation.
[0070] In practical implementation, the system also includes a digital twin module, which is configured to build a virtual model synchronized with the physical device for operation rehearsal and fault simulation. The system also includes a digital twin module, which is configured to build a high-precision virtual model that is synchronized with the physical equipment in real time. Through this virtual model, the system can perform operation rehearsals, simulate key operation processes (such as equipment docking, process switching, etc.), and identify potential collision risks and logical errors in advance; it also supports fault simulation, simulating various fault scenarios to optimize emergency response strategies and for operator training, thereby eliminating safety hazards before actual operation and improving the system's safety and reliability.
[0071] It should be noted that the method of this disclosure embodiment can be executed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method of this disclosure embodiment, and the multiple devices will interact with each other to complete the method described.
[0072] It should be noted that the above description describes some embodiments of this disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0073] Based on the same inventive concept, corresponding to any of the above-described embodiments, this disclosure also provides a method for redundancy control of ground facilities and equipment.
[0074] refer to Figure 7 The ground facility and equipment redundancy control method includes: Step S710: Obtain the target operating parameters for controlling the device execution module, and analyze the target operating parameters based on the centralized control module to obtain control commands.
[0075] The method of obtaining control commands by acquiring target operating parameters for controlling the device execution module, and analyzing the target operating parameters based on the centralized control module is as follows: Operators input target operating parameters through the integrated software interface of the centralized control center. These parameters explicitly specify the operating states that the equipment's execution modules need to achieve, such as key indicators like start-up conditions, operating speed, and position accuracy. After receiving these target operating parameters, the centralized control module combines them with real-time collected data on the equipment's current operating status, performing a comprehensive analysis using built-in algorithms and control logic. During the analysis, the system compares the differences between the target operating parameters and the current status data to determine if adjustments are needed and generates corresponding control commands. These control commands are then transmitted to the equipment execution modules via a redundant network, driving sensors, actuators, motors, valves, and other equipment to operate precisely according to the target operating parameters, thereby achieving automated control and optimized operation of the equipment.
[0076] Step S720: Based on the field control module, the control command is transmitted to the equipment execution module through a redundant network, and the equipment execution module executes the control command so that the equipment execution module drives the ground facilities and equipment to complete the corresponding physical actions.
[0077] In specific implementation, the control commands are transmitted from the field control module to the equipment execution module via a redundant network, and the equipment execution module executes the control commands to drive the ground facilities and equipment to complete the corresponding physical actions. After receiving control commands generated by the centralized control module, the field control module transmits these commands securely and reliably to the equipment execution module via a redundant network. Upon receiving the control commands, the equipment execution module drives its internal sensors, actuators, motors, valves, and other components to precisely execute the corresponding operations, thereby driving the ground facilities and equipment to complete the specified physical actions, such as opening hydraulic doors, adjusting air conditioning system parameters, and moving platform positions, ensuring that the ground facilities and equipment operate efficiently and accurately according to the requirements of the control commands.
[0078] As a specific embodiment, this disclosure provides a solution to the problems of "control island" and "switching interruption" in a redundant control system for ground facilities and equipment: Under normal circumstances, the centralized control module generates control commands and transmits them to the field control module via a redundant network. The redundant PLCs then execute the specific operations, while equipment status data is fed back to the centralized control module in real time, forming a closed-loop monitoring system. When the remote control center or network fails, the field control module can seamlessly switch to automatic field control mode, operating independently according to a preset program to ensure the normal operation of critical subsystems, achieving "seamless switching." If the PLC system itself fails, the local manual control module can directly drive the equipment execution module via hardwiring, providing the highest level of control assurance. This three-level control mechanism, through hardware interlocking and software state synchronization logic, ensures a safe and smooth transfer of control between different levels, avoiding command confusion or sudden equipment shutdowns caused by permission conflicts or state asynchrony.
[0079] As a specific embodiment, this disclosure provides a solution to the "single point of failure in the network" problem through a ground facility and equipment redundancy control system. By coordinating the centralized control module, field control module, and local manual control module, combined with a hybrid redundant topology of "ring network + star" and a "dual network card" access strategy, the problems of "control islands," "switching interruptions," and single points of network failure are comprehensively resolved. (Reference) Figure 8 Under a three-tiered control mechanism, the system ensures a safe and smooth transfer of control between remote, on-site automatic, and local manual control through hardware interlocks and software state synchronization logic. This avoids command confusion or sudden equipment shutdowns caused by permission conflicts or state asynchrony. Simultaneously, the backbone layer employs a dual-fiber ring network, whose protocol can automatically reconverge to form a temporary linear network when the fiber optic cable is interrupted. At the subsystem level, a redundant star network is used, with each PLC cabinet equipped with two access switches, each connected to a different node in the backbone ring network. Key terminal devices are equipped with dual network cards, redundantly driving real-time monitoring of link status and automatically switching to the backup link when the primary link is interrupted. This design fundamentally solves the "one-break-all-break" risk in traditional network designs, ensuring that the system can still achieve millisecond-level automatic switching under any network failure scenario, guaranteeing communication continuity and reliability.
[0080] As a specific embodiment, this disclosure provides a solution to the problem of "single point of failure in critical hardware (CPU / power supply)" in a ground facility equipment redundancy control system: This solution achieves extremely high system reliability and fault tolerance through a "fully symmetrical hot standby" redundancy architecture. In the redundant control system for ground facilities and equipment, the redundant PLCs of the field control modules adopt a dual-CPU, dual-power-supply, and dual-backplane architecture. Both the primary and backup systems operate simultaneously. The backup system is not in a "standby" state but maintains strict real-time data synchronization with the primary system, acting like a "shadow" ready to take over control at any time. The redundant CPU system is configured with two identical CPU modules, mounted on a dual-slot redundant backplane, and connected by two dedicated synchronous optical fibers: one for transmitting periodic "heartbeat" signals to confirm the other's survival, and the other for real-time synchronization of all process input / output images, timers, counters, and other data. The redundant power supply system ensures that each backplane is powered by two independent power modules. When one power module fails, the other can immediately take over the entire load, preventing the CPU from ceasing operation due to a momentary power outage. Under the seamless switching mechanism, when the main CPU fails or loses power, the backup CPU can detect the main CPU's "heartbeat" stopping within a few scan cycles (usually in milliseconds), and immediately take over control of the fieldbus, continuing program execution based on the latest synchronized data. For field devices and control processes, this switching process is seamless and disturbance-free, completely solving the "all-or-nothing" drawback of traditional single-CPU systems and significantly improving system reliability and stability.
[0081] As a specific embodiment, this disclosure provides a solution to the problem of "lack of intelligent early warning and decision support" in the form of a redundant control system for ground facilities and equipment. By constructing a digital twin-driven intelligent operation and maintenance and decision-making platform, the redundancy mechanism is transformed from the traditional passive defense mode of "failure switching" to a proactive protection mode of "failure early warning" and "operation pre-verification." The system utilizes a data analysis platform within the centralized control module to continuously collect key operational data (such as vibration, temperature, and current time-series data) from the equipment's execution modules. This data is then analyzed using a built-in machine learning engine and compared with historical fault models. Once early fault characteristics are identified, the system generates predictive maintenance work orders several days or weeks in advance and pushes them to maintenance personnel, thus solving the problems of blindness in traditional periodic maintenance and passivity in reactive repairs. Furthermore, before performing complex and high-risk operations (such as platform docking with the rocket body), operators can activate a "simulation mode" in the integrated software, calling upon a high-precision digital twin model to simulate the entire operation process based on the current equipment status. This simulates the motion trajectory, predicts collision risks, and assesses completion time in real time. If interference or overtravel risks are detected, the system will forcibly prohibit or prompt modification of operating instructions, providing safety assurance for critical operations and solving the high-risk problem of traditional systems relying on experience and the risk of success or failure on the first attempt. This proactive protection model combines the data analysis capabilities of the centralized control module, the high reliability of the redundant network, and the virtual simulation function of the digital twin module, significantly improving the system's security and operational efficiency.
[0082] As a specific embodiment, this disclosure provides a solution to the problem of "dispersed user interfaces and inconsistent user experiences" in the redundant control system for ground facilities and equipment: This disclosure also allows for the design of integrated intelligent control software as the "nerve center" and unified entry point of the system. Through scenario-based and visual design, it hides underlying redundancy and complexity, providing users with a consistent, intuitive, and efficient interactive experience. The software uses a unified portal, allowing operators to monitor and operate all subsystems after logging in, without switching between multiple interfaces. Its main interface, based on digital twin technology, provides 3D / 2D scenario-based views. Clicking on a device brings up an operation panel containing all relevant buttons, status indicators, and real-time parameters, achieving "what you see is what you control," reducing training costs and the probability of misoperation. Furthermore, the software embeds intelligent guidance functions, providing step-by-step guidance and condition checklists when executing standard procedures. When the AI system or simulation module detects a risk, it alerts the operator with prominent prompts and alarms, and can automatically prohibit dangerous operations. This design, combining a deeply redundant architecture with an intelligent fusion platform, constructs a system with high fault tolerance, self-healing, predictive, and optimization capabilities. It solves core pain points in existing technologies such as fragmented redundant design, passive fault response, and complex human-machine interaction, providing a solid technical foundation for the "absolute reliability" and "intelligent and efficient" operation of ground facilities and equipment.
[0083] Based on the above exemplary embodiments, this disclosure achieves significant technical effects by systematically integrating multiple redundancy modes and intelligent technologies, specifically in the following aspects: 1. Reliability is improved by orders of magnitude, completely eliminating single points of failure: The system's mean time between failures (MTBF) has been significantly extended, and the mean time to repair (MTTR) is extremely short, achieving near-uninterrupted high-reliability operation. This is specifically reflected in the following aspects: By employing a "three-level control mode redundancy" approach, the system can maintain basic or full functionality even if any single control level (remote, on-site, or local) fails completely, fundamentally preventing system-wide downtime caused by control center or network paralysis.
[0084] By using "deep redundancy of PLC" (dual CPU, dual power supply, dual backplane) and "IO network ring redundancy", the continuity of the control core and the end sensing / execution link is ensured. The failure of a single CPU, power supply or any communication line can achieve millisecond-level seamless switching with zero impact on the production process.
[0085] By using "full network redundancy" (dual-ring network + dual-star topology + dual network ports on each device), single-point communication failures from the control center to every terminal device on site are eliminated, achieving "ubiquitous resilience" of the communication network.
[0086] 2. System security and intrinsic security have been fundamentally enhanced: This model significantly reduces the risk of safety accidents caused by control system failures, providing an intrinsically safe level of protection for space launch missions. Specifically, this is reflected in the following aspects: The seamless switching mechanism avoids the loss of instructions or state confusion during the transfer of control, and prevents equipment from malfunctioning.
[0087] The digital twin simulation and pre-run function brings safety verification to the forefront, eliminating risks such as collisions and interference in a virtual environment before actual operation, thus realizing a safety paradigm shift of "simulation first, execution later".
[0088] The local manual control level, acting as the final safety barrier, provides emergency control capabilities in the most extreme failure scenarios through hard-wiring, ensuring that the system is always under control.
[0089] 3. The operation and maintenance mode has shifted from "passive response" to "proactive prediction and intelligent assistance": The change in operation and maintenance model significantly reduced unplanned downtime, improved operational efficiency, and lowered total lifecycle costs. Specifically, this is reflected in the following aspects: AI-based predictive maintenance can identify potential equipment failures in advance, transforming maintenance work from "regular inspections" and "reactive repairs" to "on-demand predictive maintenance," avoiding unexpected downtime during critical mission periods and reducing waste caused by over-maintenance.
[0090] The unified, integrated user interface provides a global view and scenario-based operation, simplifies the operation process, greatly reduces the cognitive burden and probability of errors for operators, and shortens the training cycle.
[0091] Software redundancy and online maintenance / upgrade capabilities enable the system to maintain, test, and even upgrade backup modules without interrupting the production process, achieving true "online evolution."
[0092] 4. Maximize the overall economic benefits throughout the system's entire lifecycle: Although initial hardware investment increased, the total cost of ownership (TCO) over the entire lifecycle decreased significantly, resulting in a high return on investment. This is specifically reflected in the following aspects: The initial investment in redundant design can be covered by avoiding the losses caused by a major mission interruption or security incident.
[0093] The reduced unplanned downtime directly increased the facility's workload and utilization efficiency.
[0094] Predictive maintenance and intelligent operation and maintenance reduce long-term maintenance costs and spare parts inventory pressure.
[0095] The system's standardized and modular design reduces the complexity and cost of later expansion, upgrades, and maintenance.
[0096] 5. A future-oriented intelligent and flexible control system architecture has been constructed: The system not only solves current reliability issues, but also possesses the ability to adapt to future technological developments and changing mission requirements. This is specifically reflected in the following aspects: The integrated platform driven by "data + AI + simulation" enables the system to become an "intelligent agent" that can continuously learn and optimize, laying the foundation for future access to higher-level intelligent decision-making algorithms.
[0097] Standardized interfaces and a layered, decoupled design make it simple and quick to add new devices, subsystems, or functions, giving the system excellent scalability and flexibility.
[0098] The methods described above are used to implement the corresponding ground facility and equipment redundancy control system in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0099] Those skilled in the art will recognize that embodiments of this disclosure can be implemented as a system, method, or computer program product. Therefore, this disclosure can be implemented as entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, generally referred to herein as a "circuit," "module," or "system." Furthermore, in some embodiments, this disclosure can also be implemented as a computer program product contained in one or more computer-readable media, which includes computer-readable program code.
[0100] Any combination of one or more computer-readable media may be used. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium can be, for example,, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (not exhaustive) of a computer-readable storage medium may include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device.
[0101] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of sending, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.
[0102] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0103] Computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0104] It should be understood that each block of a flowchart and / or block diagram, as well as combinations of blocks in a flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine that, when executed by a computer or other programmable data processing device, creates means for implementing the functions / operations specified in the blocks of the flowchart and / or block diagram.
[0105] These computer program instructions may also be stored in a computer-readable medium that enables a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable medium produce a product comprising an instruction apparatus that implements the functions / operations specified in the boxes of a flowchart and / or block diagram.
[0106] Computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, such that the instructions that execute on the computer or other programmable apparatus can provide a process for implementing the functions / operations specified in the boxes of a flowchart and / or block diagram.
[0107] Furthermore, although the operations of the methods of this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all of the operations shown must be performed to achieve the desired result. Rather, the steps depicted in the flowcharts may be executed in a different order. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0108] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0109] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of this application, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0110] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this application (including the claims) is limited to these examples; within the framework of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this application as described above, which are not provided in the details for the sake of brevity.
[0111] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this application, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this application, and this also takes into account the fact that the details of the implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this application will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuits) have been set forth to describe exemplary embodiments of this application, it will be apparent to those skilled in the art that the embodiments of this application can be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0112] Although this application has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0113] The embodiments of this application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this application should be included within the protection scope of this application.
[0114] While the spirit and principles of this disclosure have been described with reference to several specific embodiments, it should be understood that this disclosure is not limited to the disclosed specific embodiments, and the division of aspects does not imply that features in these aspects cannot be combined for benefit; such division is merely for convenience of expression. This disclosure is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims. The scope of the appended claims is to be interpreted in the broadest sense, thereby encompassing all such modifications and equivalent structures and functions.
Claims
1. A redundant control system for ground facilities and equipment, characterized in that, include: Centralized control module, redundant network, field control module, and equipment execution module; The centralized control module is connected to the field control module through a redundant network and is configured to generate control commands and transmit the control commands to the field control module. The field control module is connected to the device execution module through the redundant network and is configured to receive the control command transmitted by the centralized control module and then transmit the control command to the device execution module. The device execution module is configured to receive control commands transmitted by the field control module and execute physical actions; The redundant network is configured to provide a communication channel between the centralized control module, the field control module, and the device execution module.
2. The system according to claim 1, characterized in that, The redundant network includes a backbone network and an access network. The backbone network adopts a dual-fiber ring network topology, and the access network adopts a star redundant topology.
3. The system according to claim 1, characterized in that, The field control module includes a redundant programmable logic controller (PLC), which adopts a dual-CPU, dual-power supply, and dual-backplane architecture.
4. The system according to claim 1, characterized in that, The field control module includes a data acquisition module, which is configured to acquire the device status data of the device execution module and then transmit the device status data to the centralized control module.
5. The system according to claim 4, characterized in that, The centralized control module includes a data analysis platform configured to analyze the device status data based on machine learning algorithms, predict potential faults, and generate maintenance alarms.
6. The system according to claim 1, characterized in that, The system also includes a local manual control module, which is hardwired to the device execution module.
7. The system according to claim 6, characterized in that, The local manual control module includes an emergency operation button box, which is configured to directly drive the device execution module in response to the failure of both the centralized control module and the field control module.
8. The system according to claim 1, characterized in that, The device execution module includes: sensors, actuators, motors, and valves.
9. The system according to claim 1, characterized in that, The system also includes a digital twin module, which is configured to build a virtual model synchronized with the physical device for operation rehearsal and fault simulation.
10. A ground facility and equipment redundancy control method, comprising a ground facility and equipment redundancy control system as described in any one of claims 1 to 9, the method comprising: The target operating parameters for controlling the device execution module are obtained, and the control commands are obtained based on the analysis of the target operating parameters by the centralized control module. The field control module transmits the control commands to the equipment execution module through a redundant network, and the equipment execution module executes the control commands to drive the ground facilities and equipment to complete the corresponding physical actions.