High-reliability concurrency transmission method for multi-redundancy equipment under switched network architecture

By configuring multiple network terminal systems for the flight management system and dividing tasks according to security levels, and utilizing the routing and multicast functions of switches for data distribution and differentiated internal communication paths, the problem of insufficient parallelism in redundant data transmission under the switched network architecture is solved. This achieves deterministic transmission of high-security tasks and high-performance throughput of low-security tasks, thereby improving the system's concurrency and real-time performance.

CN121864623APending Publication Date: 2026-04-14XIAN AVIATION COMPUTING TECH RES INST OF AVIATION IND CORP OF CHINA +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-26
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

In a switched network architecture, the parallelism of redundant data transmission in the flight management system is insufficient, resulting in low data transmission efficiency, affecting mission cycle and system real-time performance, and lacking a systematic solution.

Method used

Each computer in the flight management system is configured with multiple network terminal systems. Tasks are divided according to security level and assigned independent network terminal systems. Data is distributed in parallel using the routing and multicast functions of the switch, and task-level output is aggregated through differentiated internal communication paths to ensure determinism for high-security tasks and high-performance throughput for low-security tasks.

Benefits of technology

It significantly improves the system's concurrency, reliability, and real-time performance, solves the serialization bottleneck of redundant data transmission in switched network architectures, and meets the deterministic transmission requirements of high-security tasks and the high-performance throughput requirements of low-security tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864623A_ABST
    Figure CN121864623A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of high-reliability design of an aircraft flight management system, provides a high-reliability concurrency transmission method for redundant equipment under a switched network architecture, and aims to solve the problems of serialization and poor concurrency of redundant data caused by network end system convergence of an existing switched flight management system. According to the method, no less than N network end systems are configured in each N-redundancy computer; dividing tasks according to high, medium and low security levels and allocating independent end systems; task-level input distribution is realized by utilizing switch routing and multicast; the certainty of the high-security task is guaranteed through a dual-port memory, and the low-security task supports DMA high-performance transmission through direct connection of a high-speed bus; and each end system independently transmits back the output data to complete task-level summarization. According to the method, the concurrency and the reliability are remarkably improved, and the method is suitable for high-security embedded platforms such as unmanned aerial vehicles and IMA.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of high reliability design technology for aircraft control systems, and relates to a method for ensuring high reliability and high concurrency data transmission of redundant devices in an aircraft control system under a switched network architecture. Background Technology

[0002] With the increasing payload capacity and continuously improving intelligence level of future unmanned equipment missions, the demand for highly integrated hardware platforms in terms of both physical and functional aspects is becoming increasingly urgent to meet the stringent constraints of equipment in terms of size, weight, and power consumption (SWaP). Under this trend, the scale and complexity of embedded computing systems in unmanned equipment are increasing significantly, and flight management systems are also shifting towards an integrated management computer (IMC) and airborne unified network model.

[0003] Compared to traditional airborne architectures, although the functional requirements of avionics mission systems have not fundamentally changed, their underlying architecture has undergone significant transformations. Currently, avionics mission system architectures that use switched communication networks to connect various computing nodes and devices are widely used in many types of aircraft. Among these, the system architecture and communication methods of the aircraft management system (i.e., flight control system) have undergone particularly significant changes, gradually shifting from a traditional multi-channel fault-tolerant architecture based on channel isolation to a holistic switched network fault-tolerant architecture. Channel boundaries have been broken down, and channel division is no longer necessary, resulting in a highly integrated system.

[0004] Currently, in traditional multi-channel fault-tolerant architectures, all devices in each redundancy channel communicate with the computer in that channel via a device bus. At the same time, data is cross-transmitted between channels via high-speed serial links to achieve concurrent transmission of redundant data, thereby ensuring high bandwidth and low latency.

[0005] However, in a monolithic switching network architecture, all devices and computers are interconnected through a central switch. Although the topology is simplified, data often converges to a single network terminal system before entering the computer. The parallelism of data transmission severely affects the total transmission bandwidth and efficiency, which in turn directly affects the duration of the flight control system's mission cycle and ultimately the overall performance of the aircraft platform.

[0006] Therefore, how to effectively ensure the parallelism of redundant data transmission in the flight control system under a switched network architecture has become a key technical bottleneck in the design of current high-reliability flight control systems.

[0007] Furthermore, the industry currently lacks a systematic solution and a clear design methodology, making it difficult for flight control systems to balance concurrency, determinism, and security while pursuing integration, which severely restricts their engineering applications and reliability assurance. Summary of the Invention

[0008] To address the technical challenges of serialization and insufficient parallelism of redundant data in flight control systems under switched network architectures, which lead to network-side system aggregation and consequently affect mission cycle time, system real-time performance, and reliability, this invention discloses a highly reliable concurrent transmission method for redundant devices in switched network architectures. This method is applicable to embedded high-security computing systems such as unmanned aerial vehicles and integrated modular avionics (IMA) platforms.

[0009] Specifically, the method includes the following steps: S1. Configure multiple network terminal systems for each computer in the flight control system, and the number of network terminal systems in the computer shall not be less than the computer redundancy. S2. Classify flight management tasks into high-security, medium-security, and low-security tasks according to their security levels, and assign independent network terminal systems to flight management tasks of different security levels. S3. Utilize the routing and multicast functions of the switch to distribute data from each device in parallel to the corresponding network end system according to the task security level, thereby realizing task-level input distribution. S4. Within each computer, different internal communication paths are used for data interaction between the processor and network system corresponding to different security level tasks. S5. Output data is independently sent to the switch through the dedicated network terminal system for each flight control mission, and the switch aggregates and concurrently transmits the data back to achieve mission-level output summary.

[0010] Furthermore, in step S2, high-safety tasks include flight control core command processing, medium-safety tasks include electromechanical status monitoring, and low-safety tasks include non-critical telemetry or log uploading.

[0011] Furthermore, in step S3, the switch ensures that redundant device data of the same security level is distributed to the network end system bound to the security level of the task through pre-configured multicast group or virtual LAN policies.

[0012] Further, in step S4, the differentiated internal communication path includes: S41. For high-security tasks, a dual-port memory is set up between the processor and the network system as a data buffer to ensure the determinism of processor operation. S42. For low-security tasks, a high-speed serial bus is used for direct connection between the processor and the network system. The network system writes data directly into the processor's DDR memory via DMA.

[0013] Furthermore, in step S41, the dual-port memory supports an asynchronous read / write arbitration mechanism to avoid bus conflicts when the processor CPU and the network system access the memory concurrently, and to maintain data consistency under single-point failure.

[0014] Furthermore, the network end systems within each computer are physically or logically isolated from each other, so that the failure of any one network end system does not affect the communication path of other security level tasks.

[0015] Furthermore, the switched network architecture is implemented based on AFDX, ARINC 664 Part 7, or Time-Sensitive Networking (TSN) protocol.

[0016] This invention fundamentally solves the serialization bottleneck problem caused by the convergence of redundant data in flight management systems under switched network architecture by configuring multiple network end systems in each redundant computer with no less than its computer redundancy, and combining task security level division, switch task-level routing distribution, differentiated internal communication paths and multi-end system independent backhaul mechanism. This invention achieves the coexistence of deterministic transmission of high-security tasks and high-performance throughput of low-security tasks, and significantly improves the overall concurrency, reliability and real-time performance of the system. Attached Figure Description

[0017] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is a flowchart of a highly reliable concurrent transmission method for redundant devices in a switched network architecture according to the present invention. Figure 2 It is the data transmission path of the air traffic control system's switching network; Figure 3 This refers to the implementation method between the switch and the end system in the flight control system; Figure 4 It refers to the implementation method between the processor and the end system in the flight control system. Detailed Implementation

[0019] The embodiments of this application will now be described in detail with reference to the accompanying drawings.

[0020] The following specific examples illustrate the implementation of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. This application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application. It should be noted that, in the absence of conflict, the following embodiments and features of the embodiments can be combined with each other. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0021] This invention discloses a highly reliable concurrent transmission method for redundant devices in a switched network architecture. It provides a method for calculating data transmission time in a switched network architecture and compares it with traditional multi-channel fault-tolerant transmission. The implementation path of the computing platform is defined from three aspects: the number of network end systems, data allocation method, and internal computer implementation path. The connection method between each internal processing node and the network end systems is clarified. Multiple network end systems are partitioned according to their task security levels, and differentiated communication services are implemented for different types of task data transmission requirements. Utilizing four communication resources—internal computer interconnection network, computer network end systems, communication links between computer network end systems and switches, and switch routing functions—task-level input distribution and output aggregation are ultimately achieved. This method effectively solves the problem of poor data concurrency faced by flight management systems in switched network architectures.

[0022] Specifically, the switched network architecture is implemented based on AFDX, ARINC 664 Part 7, or Time-Sensitive Networking (TSN) protocols. See also Figure 1 and Figure 2 As shown, the method includes the following steps: S1. Configure multiple network terminal systems for each computer in the flight control system, and the number of network terminal systems in the computer shall not be less than the computer redundancy. S2. Classify flight management tasks into high-security, medium-security, and low-security tasks according to their security levels, and assign independent network terminal systems to flight management tasks of different security levels. S3. Utilize the routing and multicast functions of the switch to distribute data from each device in parallel to the corresponding network end system according to the task security level, thereby realizing task-level input distribution. S4. Within each computer, different internal communication paths are used for data interaction between the processor and network system corresponding to different security level tasks. S5. Output data is independently sent to the switch through the dedicated network terminal system for each flight control mission, and the switch aggregates and concurrently transmits the data back to achieve mission-level output summary.

[0023] In one embodiment of step S1, the design requirement that the number of network end systems in the computer is not less than the computer redundancy is obtained by the following method: based on the task cycle, the number of network end systems L, the link bandwidth B and the total data volume Q, the data transmission time T of the flight management system is calculated, where T≈Q / (L·B), and the concurrent performance of the system is verified to meet the real-time requirements.

[0024] Specifically, see Figure 2 As shown, data from the redundant devices 2 (2A, 2B, ..., 2X) in the flight control system passes through network switch 2A, then through the cascade ports and communication links of the redundant switches, and finally undergoes multicast transmission in network switch 1A before being sent to various computers. The analysis focuses on the transmission of data from various redundant devices to a single computer in the system. In the following transmission steps, there can be multiple paths for data transmission from various redundant devices to a single computer, supporting parallel transmission: (1) Each device sends data to the network switch; (2) The routing and transmission of data from each device within the network switch; (3) Data from each device is cascaded and transmitted between network switches.

[0025] The parallelism of the above transmission steps depends on the total number of devices and the redundancy of the cascaded ports of the switch. However, in the last transmission step, when the network switch directly connected to the computer transmits data from each device to the computer, the number of transmission paths depends on the number of network end systems within that computer and may not support parallel transmission.

[0026] If the computer accesses the switched communication network through only one network terminal system, the final transmission step has only a single transmission path, and the data from each device can only be transmitted serially to the computer after aggregation. Only if the computer accesses the switched communication network through multiple network terminal systems will the final transmission step have multiple transmission paths, thus supporting parallel transmission.

[0027] In summary, the parallelism of data transmission from various redundant devices within the flight control system to a computer depends on three factors: 1) the number of network end systems within the computer; 2) the total number of devices connected to the switched communication network; and 3) the redundancy of the cascaded ports of the switch.

[0028] A simple model is used to compare the first type of data transmission concurrency of traditional air traffic control systems and air traffic control systems.

[0029] Assume a traditional flight control system has N redundant channels, with all redundant devices also having N redundancy. Devices with different redundancies reside on different channels, and each channel's computer connects to its peripheral devices via M device buses. Assume the total data volume generated by all redundant devices in each task cycle is Q. Assume the transmission bandwidth of each device bus and each CCDL communication link is B. In such a traditional flight control system, in each task cycle, the data transmission time for the first part is approximately Q / (N*M*B), and the data transmission time for the second part is approximately Q / (N*B). Since the two parts of data transmission can occur concurrently, the total data transmission time for each task cycle of the traditional flight control system is approximately Q / (N*B).

[0030] Under identical conditions (same redundancy, same data volume, same communication link bandwidth), assume the flight management system contains N computers, each computer contains L network end systems, all types of redundant devices have N redundancy, and the number of redundant device types is not less than L (i.e., the total number of devices is not less than N*L). Assume the total data volume generated by all redundant devices in each task cycle is Q. Assume the transmission bandwidth of each communication link in the switched communication network is B. Assume the internal bandwidth of the network switches can support full-speed parallel transmission of all network end systems of all computers. Assume the number of cascaded ports of the network switches can support full-speed parallel transmission of all network end systems of all computers (in the flight management system shown in the previous figure, the number of cascaded ports between network switches 1A and 2A needs to be not less than L). In such a flight management system, the time for the first type of data transmission in each task cycle is approximately Q / (L*B).

[0031] Comparative analysis using this simple model shows that, under the same conditions, if the flight control system's computer accesses the switched communication network through only one network terminal system, the data transmission time of the flight control system will be several times that of the traditional flight control system.

[0032] Under the same conditions, the data transmission efficiency of the flight control system will not be lower than the first type of data transmission efficiency of the traditional flight control system only when the number of network terminal systems in the flight control system computer is not less than the computer redundancy.

[0033] Therefore, it can be concluded that the data transmission efficiency of the flight control system will not be lower than that of the traditional flight control system only when the number of network terminal systems within the computer is not less than the computer redundancy.

[0034] In one embodiment of step S2, high-safety tasks include flight control core command processing, medium-safety tasks include electromechanical status monitoring, and low-safety tasks include non-critical telemetry or log uploading.

[0035] In one embodiment of step S3, the switch ensures that redundant device data of the same security level is distributed to the network end system bound to the security level of the task through a pre-configured multicast group or virtual LAN policy.

[0036] In one embodiment of step S4, the differentiated internal communication path includes: S41. For high-security tasks, a dual-port memory is set up between the processor and the network system as a data buffer to ensure the determinism of processor operation. S42. For low-security tasks, a high-speed serial bus is used for direct connection between the processor and the network system. The network system writes data directly into the processor's DDR memory via DMA.

[0037] Furthermore, in step S41, the dual-port memory supports an asynchronous read / write arbitration mechanism to avoid bus conflicts when the processor CPU and the network system access the memory concurrently, and to maintain data consistency under single-point failure.

[0038] Furthermore, the network end systems within each computer are physically or logically isolated from each other, so that the failure of any one network end system does not affect the communication path of other security level tasks.

[0039] The design of steps S2 to S5 above is implemented and verified in the following way: In step S2, classifying flight control tasks according to safety levels is one of the important means to ensure that data transmission efficiency is no less than that of traditional flight control systems. The design process analyzes the data transmission and allocation problem, and the specific process is as follows: First, analyze the communication link between the computer network terminal system and the switch.

[0040] By utilizing the routing configuration and multicast transmission functions of network switches, task-level "input distribution" and "output aggregation" are achieved. These two communication resources classify and distribute input data from other computers and all peripheral devices within the system to this computer according to their respective tasks, and distribute the output data sent from each task's dedicated network terminal system to the outside world to the computer via the network switch before sending it to other computers and all peripheral devices within the system.

[0041] For example, such as Figure 3 As shown, equipment data related to high-security-level flight control missions can be transmitted to network-side system 1; equipment data related to medium-security-level electromechanical missions can be transmitted to network-side system 2; and so on. Under this parallel transmission allocation method, missions of different security levels can use different network-side systems, providing strong security isolation capabilities.

[0042] The task-level input distribution in step S3 and the data interaction design of the differentiated internal communication paths in step S4 are achieved by analyzing the communication links of the computer's internal interconnection communication network.

[0043] Specifically, when different security level tasks use different network endpoints, the input distribution and output aggregation data transmission functions that the computer's internal interconnection communication network needs to implement are greatly simplified. Each network endpoint is dedicated to a specific type of task, and only performs "input distribution" and "output aggregation" data transmission with the processor (CPU) running that type of task. The transmission requirements are singular, the transmission mode is singular, and the number of communication nodes is greatly reduced.

[0044] Internally, the design of the processor and network end-system varies depending on the type of task. For example... Figure 4 As shown, for tasks with high deterministic requirements, a dual-port memory is added between the CPU and the network system to implement a transmission buffer, ensuring the deterministic operation of the CPU; for tasks with low deterministic requirements but high transmission performance requirements, the network system can directly write the received data into the CPU's DDR memory quickly via a high-speed serial bus (PCIe / SRIO).

[0045] This invention achieves the following significant technical effects by constructing a transmission architecture that coordinates multi-terminal systems, secure partitioning, and differentiated communication paths: 1. Effectively solves the data serialization problem caused by end system aggregation in flight management systems under switched network architecture, significantly improves the parallelism of redundant data transmission, and ensures that the mission cycle meets real-time requirements; 2. A concurrency design criterion applicable to switched flight control systems is proposed: the number of network terminal systems L configured in the computer should not be less than the remaining number N (i.e., L ≥ N), providing a quantitative basis for system-level concurrency capability; 3. Establish a data transmission allocation mechanism based on mission security level, divide flight management missions into three levels: high security, medium security, and low security, and allocate independent network terminal systems to each level of mission to achieve logical isolation of communication resources; 4. Enhance system security isolation capabilities, with dedicated network terminals for tasks of different security levels to avoid cross-level data interference and meet the requirements of airworthiness standards such as DO-178C / DO-254 for zone isolation; 5. Enable point-to-point direct communication between the processor and the network end system. Each end system only interacts with the processor running the corresponding security level task, which greatly reduces the number of internal communication nodes and simplifies the interconnection topology. Different internal communication paths are used for tasks with different security levels: For high-security tasks, a dual-port memory is set up as a buffer between the processor and the network system to support asynchronous read / write arbitration, ensuring determinism and predictable timing of data access. For low-security tasks, the processor and the network system are directly connected via a high-speed serial bus (such as PCIe or SRIO). The network system can write data directly to the processor's DDR memory via DMA to achieve high throughput and low latency transmission. 6. The overall architecture is compatible with mainstream airborne network protocols (such as AFDX, ARINC 664 Part 7, TSN) and can be seamlessly integrated into the Integrated Modular Avionics (IMA) platform, taking into account both high reliability and high performance requirements.

[0046] Obviously, those skilled in the art should understand that the steps of the above-described embodiments of the present invention can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using device-executable program code, thereby storing them in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented here, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the embodiments of the present invention are not limited to any particular combination of hardware and software.

[0047] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, various modifications and variations can be made to the embodiments of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A highly reliable concurrent transmission method for redundant devices in a switched network architecture, characterized in that, The include: Configure multiple network terminal systems for each computer in the flight control system, and the number of network terminal systems in the computer shall not be less than the computer redundancy. Flight control missions are divided into high-safety, medium-safety, and low-safety missions according to their safety levels, and independent network terminal systems are allocated to each flight control mission of different safety levels. By utilizing the routing and multicast functions of the switch, data from each device is distributed in parallel to the corresponding network end system according to the task security level, thereby realizing task-level input distribution; Within each computer, different internal communication paths are used for data interaction between the processor and network system corresponding to different security level tasks. The output data is sent independently to the switch through the dedicated network terminal system for each flight control mission, and then aggregated and concurrently transmitted back by the switch to achieve mission-level output summary.

2. The method for highly reliable concurrent transmission of redundant devices in a switched network architecture according to claim 1, characterized in that, High-safety tasks include processing core flight control commands, medium-safety tasks include monitoring electromechanical status, and low-safety tasks include non-critical telemetry or log uploading.

3. The method for high-reliability concurrent transmission of redundant devices in a switched network architecture according to claim 1, characterized in that, The switch ensures that redundant device data of the same security level is distributed to the network end system bound to the security level of the task through pre-configured multicast group or virtual LAN policies.

4. The method for highly reliable concurrent transmission of redundant devices in a switched network architecture according to claim 1, characterized in that, Differentiated internal communication paths include: For high-security tasks, a dual-port memory is set up between the processor and the network system as a data buffer to ensure the determinism of processor operation; For low-security tasks, a high-speed serial bus is used for direct connection between the processor and the network system, and the network system writes data directly into the processor's DDR memory via DMA.

5. The method for highly reliable concurrent transmission of redundant devices in a switched network architecture according to claim 4, characterized in that, The dual-port memory supports an asynchronous read / write arbitration mechanism to avoid bus conflicts when the processor CPU and network system access the memory concurrently, and to maintain data consistency under single point of failure.

6. The method for highly reliable concurrent transmission of redundant devices in a switched network architecture according to claim 1, characterized in that, Each network terminal system within a computer is physically or logically isolated from each other, and the failure of any one network terminal system does not affect the communication path of other security level tasks.

7. The method for highly reliable concurrent transmission of redundant devices in a switched network architecture according to claim 1, characterized in that, The switched network architecture is implemented based on AFDX, ARINC 664 Part 7, or Time-Sensitive Networking (TSN) protocol.