3*3 dissimilar flight control computing architecture, system and control method thereof

By adopting a 3×3 dissimilar flight control computing architecture and fault monitoring method, the availability and integrity issues of fly-by-wire flight control systems in the event of electronic component failures are solved, achieving efficient fault-tolerant control and fault isolation, and improving the reliability of the system.

CN121900131APending Publication Date: 2026-04-21COMMERCIAL AIRCRAFT CORP OF CHINA LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
COMMERCIAL AIRCRAFT CORP OF CHINA LTD
Filing Date
2026-01-22
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing fly-by-wire flight control systems struggle to guarantee system availability and integrity when faced with electronic component failures, especially the 3×2 architecture, which presents design challenges in channel management and fault isolation.

Method used

A 3×3 dissimilar flight control computing architecture is adopted, including three dissimilar flight control computers (FCMs) and four dissimilar actuator control electronics (ACEs). Dissimilar branch design and fault-tolerant control are achieved through point-to-point communication and fault monitoring methods.

Benefits of technology

It improves the availability and integrity of the flight control computing system, reduces the number of communication lines, avoids computer loss due to single-branch failure, and enhances the system's fault tolerance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121900131A_ABST
    Figure CN121900131A_ABST
Patent Text Reader

Abstract

The invention relates to a 3 * 3 dissimilar flight control computing architecture and system and a control method thereof, and the architecture comprises three FCMs, and each FCM comprises three dissimilar branches; four actuators which are dissimilar in pairs are used for controlling the electronic ACE; wherein the two branches in each FCM share point-to-point communication through the IOC, the remaining branches are in single-branch point-to-point communication with the remaining branches of the other two FCMs, and meanwhile, the remaining branches are also in point-to-point communication with the IOC of the other two FCMs; wherein the IOC and the remaining branches of each FCM are respectively in bus communication with each ACE in a point-to-point manner.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of aircraft flight control, and more particularly to fly-by-wire flight control systems and control methods thereof, especially a 3×3 dissimilar flight control computing architecture, a flight control computing system using the architecture, and the corresponding control method thereof. Background Technology

[0002] Modern fly-by-wire flight control systems place extremely high demands on the availability and integrity of flight control calculations. Any electronic component, computer, sensor, or circuit in the system may fail. Therefore, redundancy technology is needed to construct multiple redundant channels to cope with potential failure risks, that is, to ensure that the system can continue to operate safely even if one or more components fail.

[0003] Typical redundancy architectures include dissimilar redundancy computers with 2×2 and 3×2 architectures, which achieve fault isolation under single-branch failure by cross-comparison of instruction branches and monitoring branches.

[0004] The first "2" in the 2×2 architecture's dissimilarity redundancy technology refers to two completely independent, physically isolated computing channels (such as two different computers, or two completely isolated computing regions within a single computer). The second "2" refers to the use of a "dual-branch dissimilarity" design within each channel. That is, each channel has two sets of parallel, dissimilarity (different hardware and / or software) computing branches. While dual-branch dissimilarity can improve the integrity of flight control computing, it cannot improve the availability of flight control computing.

[0005] The 3×3 architecture with dissimilar redundancy can tolerate single-branch failures and improve the availability of flight control calculations. However, it will significantly increase the difficulty of system design in areas such as channel management, fault isolation, and system communication. Summary of the Invention

[0006] This application provides a 3×3 dissimilar flight control computing architecture, a flight control computing system using this architecture, and a corresponding control method. Specifically, it describes in detail the 3×3 dissimilar flight control computing architecture, the flight control system incorporating this architecture, and the corresponding control scheme for the flight control system.

[0007] According to a first aspect of this application, a 3×3 dissimilar flight control computing architecture is provided, comprising: There are 3 FCMs, each of which includes three dissimilar branches; Four pairwise dissimilar actuators control the electronic ACE; In each FCM, two branches share point-to-point communication through IOC, while the remaining branches communicate with the remaining branches of the other two FCMs via single-branch point-to-point communication. At the same time, the remaining branches also communicate with the IOCs of the other two FCMs via point-to-point communication. In this context, the IOC and remaining branches of each FCM communicate with each of the ACEs in a point-to-point manner via a bus.

[0008] According to a second aspect of this application, a flight control computing system is provided, comprising: The 3×3 dissimilar flight control computing architecture described in the first aspect; The actuator system is configured to communicate with the ACE in the flight control computing architecture to receive actuator control commands; The PCM is configured to power the flight control computing system.

[0009] According to a third aspect of this application, a control method for fault monitoring and fault tolerance of a flight control computing architecture as described in the first aspect is provided, comprising: Monitor the control output commands of each branch in each FCM; The control output commands of the three branches in each FCM are compared in pairs: If the control output command of one branch exceeds the threshold when compared with the control output commands of the other two branches, the fault monitor will be triggered to determine that the branch has a fault and isolate it. When the IOC is fault-free, the two branches of the dual-branch IOC communication of each FCM serve as the command branch and the backup branch, and the remaining branch that performs single-branch point-to-point communication serves as the monitoring branch. The backup branch serves as the monitoring branch when the command branch is normal, and replaces the function of the original command branch when the command branch fails. In the event of an IOC failure, the remaining branches of the single-branch point-to-point communication of the FCM of the failed IOC are used as command branches, while the branches of the dual-branch IOC communication are used as monitoring branches. When both the IOC and the remaining branches fail, the FCM of both the failed IOC and the remaining branches is isolated.

[0010] This overview is provided to introduce, in a simplified form, some of the concepts further described in the detailed description below. This overview is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter. Attached Figure Description

[0011] To describe how the above and other advantages and features of the invention are obtained, a more detailed description of the invention, which has been briefly described above, will be presented with reference to specific embodiments of the invention shown in the accompanying drawings. It will be understood that these drawings depict only exemplary embodiments of the invention and are therefore not intended to limit its scope. The invention will be described and explained using the drawings and with the aid of additional features and details, in which: Figure 1 A schematic structural diagram of a flight control system comprising a 3×3 dissimilar flight control computing architecture according to an embodiment of this application is shown.

[0012] Figure 2 A schematic structure and data flow diagram of three FCMs in a 3×3 dissimilar flight control computing architecture according to an embodiment of this application are shown.

[0013] Figure 3 A schematic data flow diagram is shown between a certain FCM (FCM1 in the figure) and four ACEs in a 3×3 dissimilar flight control computing architecture according to an embodiment of this application.

[0014] Figure 4 A fault monitoring and fault-tolerant control method for the 3×3 dissimilar flight control computing architecture is illustrated according to an embodiment of this application. Detailed Implementation

[0015] This application provides a 3×3 dissimilar flight control computing (point-to-point communication) architecture, a flight control computing system including the 3×3 dissimilar flight control computing architecture, and a corresponding control method.

[0016] Overall, the 3×3 dissimilar flight control computing architecture uses three three-branch dissimilar flight control computing units (FCMs) and four two-way dissimilar actuator control electronic units (ACEs) as the system control core. Communication between FCMs and between FCMs and ACEs is conducted via a point-to-point bus. In normal and auxiliary modes, FCMs calculate actuator control commands, and communicate with other aircraft systems via a network bus. ACEs receive signals from cockpit controls / switches, important interface signals, and flight control sensors. ACEs communicate with the actuation system to send actuator control commands, and four PCMs provide centralized power to the flight control computing system equipment.

[0017] In this system, the three branches of the FCM communicate with each other in pairs. Two branches in each FCM share point-to-point communication through IOC (also known as "dual-branch IOC communication"). The remaining branches communicate with the remaining branches of the other two FCMs in single-branch point-to-point communication. At the same time, the remaining branches also communicate with the IOCs of the other two FCMs in point-to-point communication. The dual-branch IOC communication combinations shared by each FCM are also dissimilar. Consequently, the single-branch point-to-point communication of each FCM also remains dissimilar. That is, in FCM1, branch TYPE I + TYPE II share point-to-point communication through IOC (Input / Output Controller) 1 to form dual-branch IOC communication, while branch TYPE III is a single-branch point-to-point communication; in FCM2, branch TYPE I + TYPE IIII share point-to-point communication through IOC2 to form dual-branch IOC communication, while branch TYPE II is a single-branch point-to-point communication; in FCM3, branch TYPE II + TYPE III share point-to-point communication through IOC3 to form dual-branch IOC communication, while branch TYPE I is a single-branch point-to-point communication.

[0018] It should be understood that the symbols “FCM1, FCM2 and FCM3”, “TYPE I, TYPE II, TYPE III” and “IOC1, IOC2 and IOC3” are only used to distinguish different FCMs, branches and IOCs, and are not intended to limit or specifically refer to any particular component.

[0019] To ensure sufficient dissimilarity design, when all branches and IOCs are normal, the instruction branch, backup branch, and monitoring branch of each FCM are dissimilarity. For example: FCM1's branch TYPE I is the instruction branch, branch TYPE II is the backup branch, and branch TYPE III is the monitoring branch; FCM2's branch TYPE III is the instruction branch, branch TYPE I is the backup branch, and branch TYPE II is the monitoring branch; FCM3's branch TYPE II is the instruction branch, branch TYPE III is the backup branch, and branch TYPE I is the monitoring branch.

[0020] In this context, the IOC and remaining branches of each FCM communicate with each ACE in a point-to-point bus manner, see [link to relevant documentation]. Figure 3 .

[0021] Compared to existing 2×2 and 3×2 dissimilar redundant computer architectures, this application proposes a three-branch flight control computing architecture and a corresponding fault monitoring and fault-tolerant control scheme. Addressing the issue of complex redundancy in the three-branch point-to-point communication architecture of a triple-redundant flight control computer, this architecture can reduce the number of communication lines by half. Furthermore, addressing the potential risk of FCM loss due to a single-branch IO failure in the two-branch point-to-point communication architecture of a triple-redundant flight control computer, this architecture enables point-to-point communication through a single branch.

[0022] In addition, the solution of this application can avoid computer loss due to single-point failure of a single branch; in view of the hidden danger of FCM loss due to IOC failure in the three-branch shared IOC point-to-point communication architecture of triple-redundant flight control computer, this architecture monitors IOC single-point failure through a single branch between FCMs, and uses the single branch as the command branch when IOC fails, so as to avoid computer loss of communication function due to IOC single-point failure.

[0023] The specific scheme of this application will be further explained below with reference to the accompanying drawings.

[0024] exist Figure 1 The diagram shows an overall schematic structure of a flight control computing system including a 3×3 dissimilar flight control computing architecture according to an embodiment of this application.

[0025] As shown in the figure, the flight control computing system includes three FCMs, four ACEs, four PCMs, and an actuation system (REU / MCE), and it communicates with various data sources.

[0026] In normal and auxiliary modes, the pilot issues simulated control commands via cockpit controls / switches, which are then transmitted to four ACEs. After signal shaping and A / D conversion by the ACEs, the signals are fed back to the three FCMs via point-to-point data buses. Simultaneously, the ACEs also receive digital signals from external sensors, such as signals from critical interfaces and from flight control system sensors, and transmit them to the FCMs as well.

[0027] The FCM performs integrity verification and voting on the received signals, uses the results for control law calculation, and returns the control output commands generated according to the control law to the four ACEs. After receiving the control output commands from the FCM, the ACEs output the corresponding command signals to the actuation system, control the corresponding actuators to drive the control surfaces, thereby achieving control of the aircraft attitude.

[0028] To meet the high safety requirements of fly-by-wire flight control systems, the flight control computing system employs three FCMs to calculate control commands in normal and auxiliary modes. These commands are then transmitted to the actuation system via four ACEs to control the actuators of all control surfaces. The three FCMs operate in a master-master-master mode, with a single FCM capable of performing both normal and auxiliary mode control functions. If one FCM fails and cannot support normal functions, its connection to peripheral devices is severed, while the other two FCMs continue to operate normally. If the second FCM also fails, its peripheral device connection is severed, while the third FCM remains operational. When all FCMs fail, the system enters direct mode, disconnecting all FCMs from the flight control computing system and calculating flight control commands via ACEs.

[0029] On the other hand, redundancy configuration ensures that each ACE controls approximately 1 / 4 of the actuators, 1 / 4 of the interface signals, and sensor signals, while guaranteeing that any two ACEs satisfy MAC (Minimum Aircraft Control). The four ACEs employ a pairwise dissimilar design to avoid common-mode failures that could render the flight control computing system unusable.

[0030] Point-to-point bus transmission is used between FCMs and between FCMs and ACEs. This is a highly efficient, high-bandwidth, and simple internal communication solution for flight control systems, capable of withstanding harsh electromagnetic and lightning environments. See [link to relevant documentation]. Figure 2 and 3 .

[0031] After understanding the overall structure of the flight control computing system, the following will combine... Figure 2 and 3 This section will explain in detail the schematic structure and data signal flow of the FCM and ACE parts of the flight control computing architecture.

[0032] first, Figure 2 An example structure of the FCM portion in a 3×3 dissimilar flight control computing architecture according to an embodiment of this application and the data flow between them are shown.

[0033] like Figure 2 As shown, each FCM's two branches communicate point-to-point with the IOCs and single branches of the other two FCMs through the IOC, and the remaining single branch (also called the "remaining branch") communicates point-to-point with the IOCs and single branches of the other two FCMs.

[0034] Specifically, in Figure 2In the example, in FCM1, branch TYPE I and TYPE II share point-to-point communication through IOC (Input / Output Controller) 1 to form dual-branch IOC communication, while branch TYPE III is a single-branch point-to-point communication; in FCM2, branch TYPE I and TYPE III share point-to-point communication through IOC2 to form dual-branch IOC communication, while branch TYPE II is a single-branch point-to-point communication; in FCM3, branch TYPE II and TYPE III share point-to-point communication through IOC3 to form dual-branch IOC communication, while branch TYPE I is a single-branch point-to-point communication.

[0035] Meanwhile, IOC1 in FCM1 communicates point-to-point with IOC2 and single-branch TYPE II in FCM2, and also with IOC3 and single-branch TYPE I in FCM3; while single-branch TYPE III in FCM1 communicates point-to-point with IOC2 and single-branch TYPE II in FCM2, and also with IOC3 and single-branch TYPE I in FCM3.

[0036] IOC2 in FCM2 communicates point-to-point with IOC1 and single-branch TYPE III in FCM1, and also with IOC3 and single-branch TYPE I in FCM3; single-branch TYPE II in FCM2 communicates point-to-point with IOC1 and single-branch TYPE III in FCM1, and also with IOC3 and single-branch TYPE I in FCM3.

[0037] In FCM3, IOC3 communicates point-to-point with IOC1 and single-branch TYPE III in FCM1, and also with IOC2 and single-branch TYPE II in FCM2; in FCM3, single-branch TYPE I communicates point-to-point with IOC1 and single-branch TYPE III in FCM1, and also with IOC2 and single-branch TYPE II in FCM2.

[0038] The three-branch dissimilar design described above uses three dissimilar branches as command, backup, and monitoring branches, respectively. The backup branch functions as a monitoring branch when the command branch is functioning normally, and supports the original command branch's functionality in case of command branch failure. Each FCM's three dissimilar branches can function as either command or monitoring branches. Compared to the command / monitor dissimilar architecture, the three-branch dissimilar design can tolerate the failure of one branch without affecting FCM functionality, thus improving FCM availability.

[0039] Figure 3The schematic structure and data flow between a certain FCM (FCM1 in the figure) and four ACEs in a 3×3 dissimilar flight control computing architecture according to an embodiment of this application are shown.

[0040] like Figure 3 As shown, taking FCM1 as an example, the two branches of a single FCM communicate point-to-point with the IOC and four ACEs, while the remaining branches communicate point-to-point independently with the four ACEs.

[0041] Having understood the 3×3 dissimilar flight control computing architecture and system of this application, this application also proposes a corresponding fault monitoring and fault-tolerant control method.

[0042] In general, the principle of fault monitoring in this application is as follows: The three dissimilar branches perform cross-branch comparisons of the control output commands. If the control output command of one branch exceeds the threshold when compared with the control output commands of the other two branches, the fault monitor will be triggered to determine that the branch has a fault and isolate it.

[0043] When the IOC is fault-free, the two branches of the dual-branch IOC communication for each FCM serve as the command branch and the backup branch, while the remaining branch performing single-branch point-to-point communication serves as the monitoring branch. The backup branch functions as the monitoring branch when the command branch is normal, and replaces the original command branch function when the command branch fails.

[0044] In the event of an IOC failure, the dual-branch IOC communication cannot independently complete the FCM command output. As a fault-tolerance mechanism, the remaining branch of the single-branch point-to-point communication of the FCM is used as the command branch, while the branch of the dual-branch IOC communication is used as the monitoring branch.

[0045] The following procedure is used to determine whether the IOC is faulty: If the comparison between the control output command of a dual-branch IOC communication of an FCM and its single-branch communication exceeds a threshold, and simultaneously the comparison between the control output command of the dual-branch IOC communication of the same FCM and the control output commands of two other single-branch communications of the same FCM exceeds a threshold, but the comparison between the control output command of the single-branch communication of the same FCM and the control output commands of the other two single-branch communications of the same FCM does not exceed a threshold, then a common-mode fault is determined to have occurred within the IOC of that FCM. This IOC common-mode monitoring mode has a faster response than the cross-branch comparison monitoring within the FCM.

[0046] Specifically, if the IOC and the remaining branches of a certain FCM fail, that FCM is isolated.

[0047] Based on the above monitoring principles, Figure 4An example flowchart of a fault monitoring and fault-tolerant control method according to an embodiment of this application is shown.

[0048] In the illustrated embodiment, for simplicity, FCM1 is used as an example to describe the fault monitoring and fault-tolerant control process in detail. However, it should be understood that the process is equally applicable to FCM2 and FCM3. In practical applications, the system continuously executes the control method on FCM1, FCM2, and FCM3 simultaneously to monitor and correct potential faults in real time.

[0049] First, in step 402, the system monitors the control output commands of each branch (branch TYPE I, branch TYPE II and branch TYPE III) in FCM1, which includes three branches.

[0050] Subsequently, in step 404, the control output commands of the three branches are compared in pairs. Specifically, the control output command of branch TYPE I (hereinafter referred to as "Command 1") is compared with the control output command of branch TYPE II (hereinafter referred to as "Command 2"), the control output command of branch TYPE I is compared with the control output command of branch TYPE III (hereinafter referred to as "Command 3"), and the control output command of branch TYPE II is compared with the control output command of branch TYPE III.

[0051] Specifically, the comparison is actually a judgment: Is |FCM1 instruction 1 - FCM1 instruction 2| greater than the threshold? Is the value of instruction 1-3 of FCM1 greater than the threshold? Is |FCM1 instruction 2 - FCM1 instruction 3| greater than the threshold?

[0052] Specifically, if the result exceeds a threshold, the comparison result of the combination is considered inconsistent; otherwise, if the result does not exceed the threshold, the comparison result is considered consistent. This threshold is determined by considering the accuracy and tolerance requirements of the multi-branch flight control computing architecture, as well as design experience, and will be verified through subsequent testing and flight path adjustments. This is a commonly used parameter for branch fault determination in the field of science.

[0053] The above comparison results may have the following situations: 1) If the comparison results in all combinations are inconsistent, it indicates that at least two of the three branches of FCM1 are faulty, and FCM1 cannot perform its original function. Therefore, the process proceeds to step 406, where FCM1 is isolated, and the process ends here.

[0054] 2) If the comparison results of the control output commands of branch TYPE I and branch TYPE II are inconsistent, and the comparison results of the control output commands of branch TYPE I and branch TYPE III are also inconsistent, but the comparison results of the control output commands of branch TYPE II and branch TYPE III are consistent, it indicates that branch TYPE I of FCM1 has failed. Therefore, the process proceeds to step 408, isolates branch TYPE I, uses branch TYPE II as the command branch, and uses branch TYPE III as the monitoring branch, and the process ends here.

[0055] 3) If the comparison results of the control output commands of branch TYPE I and branch TYPE II are inconsistent, and the comparison results of the control output commands of branch TYPE II and branch TYPE III are also inconsistent, but the comparison results of the control output commands of branch TYPE I and branch TYPE III are consistent, it indicates that branch TYPE II of FCM1 has failed. Therefore, the process proceeds to step 410, isolates branch TYPE II, uses branch TYPE I as the command branch, and uses branch TYPE III as the monitoring branch, and the process ends here.

[0056] 4) If the comparison results of the control output commands of branch TYPE I and branch TYPE III are inconsistent, and the comparison results of the control output commands of branch TYPE II and branch TYPE III are also inconsistent, but the comparison results of the control output commands of branch TYPE I and branch TYPE II are consistent, it indicates that branch TYPE III of FCM1 may be faulty, which is the special case mentioned above. In this case, the process proceeds to step 412 to further determine whether the comparison results of the control output commands of branch TYPE I and branch TYPE II of FCM1 are consistent with the two remaining branches of the external FCM (i.e., the other two FCMs: FCM2 and FCM3), that is, to determine: Is the value of |FCM1 instruction 1 - FCM2 instruction 2| greater than the threshold? Is the value of instruction 1 from FCM1 to instruction 1 from FCM3 greater than the threshold? Is | Instruction 2 of FCM1 - Instruction 2 of FCM2| greater than the threshold? Is the instruction 2 of FCM1 greater than the threshold of instruction 1 of FCM3?

[0057] If any of these comparison results are consistent, the branch TYPE III of FCM1 is determined to be faulty, and the process proceeds to step 414; if all comparison results are inconsistent, the process proceeds to step 416.

[0058] In step 414, branch TYPE III of FCM1 is isolated, branch TYPE I is used as the command branch, and branch TYPE II is used as the monitoring branch, and the process ends.

[0059] In step 416, it is further determined whether the comparison result of the control output command of the branch TYPE III of FCM1 is consistent with that of the two remaining branches of the external FCM (i.e., the other two FCMs: FCM2 and FCM3), that is, to determine: Is the value of |FCM1 instruction 3 - FCM2 instruction 2| greater than the threshold? Is the value of instruction 3 of FCM1 - instruction 1 of FCM3 greater than the threshold? If any of the above comparison results are consistent, it means that TYPE III of FCM1 is normal and IOC1 of FCM1 is faulty. Therefore, the process proceeds to step 418. If none of the above comparison results are consistent, it means that both IOC1 and TYPE III of FCM1 are faulty. The process proceeds to step 420.

[0060] In step 418, IOC1 is isolated, branch TYPE III is designated as the instruction branch, while branch TYPE I and branch TYPE II are designated as monitoring branches, and the process ends here.

[0061] In step 420, FCM1 is isolated, and the process ends here.

[0062] If the comparison results in all combinations are consistent, it indicates that the FCM1 is working normally and no further processing is required; the control method can then be terminated directly.

[0063] In summary, Table 1 below lists the schematic diagram of the FCM branch fault-tolerant control logic.

[0064]

[0065] As described above, the design scheme meets the high safety requirements of fly-by-wire flight control systems for FCMs and fully leverages the advantages of 3×3 dissimilar FCM designs. It has the following design features: 1. The FCM adopts a dissimilar architecture of instruction branch, backup branch and monitoring branch, and each FCM can provide a full-featured computing platform with high availability and high integrity.

[0066] 2. When all branches and IOC are normal, the functions of the isomorphic branches of the three FCMs are not similar. For example: FCM1's branch TYPE I is the command branch, branch TYPE II is the backup branch, and branch TYPE III is the monitoring branch; FCM2's branch TYPE III is the command branch, branch TYPE I is the backup branch, and branch TYPE II is the monitoring branch; FCM3's branch TYPE II is the command branch, branch TYPE III is the backup branch, and branch TYPE I is the monitoring branch.

[0067] 3. The connection between the FCM and peripheral devices is not the same. The command branch and backup branch of the FCM are connected to the peripheral device through the IOC, while the monitoring branch is connected to the peripheral device separately. For example: FCM1's branch TYPE I and branch TYPE II are connected to the peripheral device through the IOC, while branch TYPE III is directly connected to the peripheral device; FCM2's branch TYPE III and branch TYPE I are connected to the peripheral device through the IOC, while branch TYPE II is directly connected to the peripheral device; FCM3's branch TYPE II and branch TYPE III are connected to the peripheral device through the IOC, while branch TYPE I is directly connected to the peripheral device.

[0068] 4. To address the issue of incompatibility between different FCM configurations, a dual-branch combination of two FCMs sharing IOC communication can be configured with the same architecture to reduce line operation costs. While this modified approach will not reduce FCM availability, it will increase the likelihood of multiple FCM command branch switching.

[0069] 5. Three dissimilar branches perform cross-branch comparison of the control output command. If the comparison between the command of one branch and the commands of the other two branches exceeds the threshold for a specified duration, the fault monitor will be triggered to determine that the branch has a fault and isolate it.

[0070] 6. The IOC of the FCM monitors internal common-mode faults through two other FCM single-branch monitoring.

[0071] 7. When the IOC is normal, if a single branch of the FCM fails, the FCM still has a dissimilar instruction / monitor architecture, ensuring the integrity of the FCM's instructions.

[0072] 8. When the IOC fails, the two branches connected to the IOC cannot directly output commands. In this case, the branch that is independently connected to the peripheral device is used as the command branch, and the other two branches are used as monitoring branches.

[0073] Although the techniques have been described using language specific to structural features and / or methodological actions, it should be understood that the appended claims are not necessarily limited to the described features or actions. Rather, these features and actions are described as exemplary forms of implementing these techniques.

[0074] The operations of the example processes are shown in separate boxes and are summarized with reference to these boxes. These processes are shown as a flow of logical boxes, each of which may represent one or more operations that can be implemented using hardware, software, or a combination thereof. In the context of software, these operations represent computer-executable instructions stored on one or more computer-readable media that, when executed by one or more processors, cause one or more processors to perform a given operation. Generally, computer-executable instructions include routines, programs, objects, modules, components, data structures, etc., that perform a particular function or implement a particular abstract data type. The order in which the operations are described is not intended to be construed as limiting, and any number of the operations may be executed in any order, combined in any order, subdivided into multiple sub-operations, and / or executed in parallel to implement the described process. The described process may be executed by resources associated with one or more computing devices, such as one or more internal or external CPUs or GPUs, and / or one or more pieces of hardware logic, such as FPGAs, DSPs, or other types of accelerators.

[0075] All of the methods and processes described above can be embodied in software code modules executed by one or more general-purpose computers or processors, and can be fully automated via these software code modules. These code modules can be stored on any type of computer-executable storage medium or other computer storage device. This code can also be packaged into corresponding computer program products. Some or all of these methods can alternatively be embodied in dedicated computer hardware.

[0076] Any routine description, element, or box in the flowcharts described herein and / or in the accompanying drawings should be understood as potentially representing a module, segment, or portion of code comprising one or more executable instructions for implementing a specific logical function or element in that routine. Alternative implementations are included within the scope of the examples described herein, wherein elements or functions may be removed or performed inconsistently with the order shown or discussed, including substantially synchronous or reverse order execution, depending on the functionality involved, as will be understood by those skilled in the art.

[0077] While different embodiments have been described above, it should be understood that they are merely examples and not limitations. Those skilled in the art will appreciate that various modifications in form and detail may be made without departing from the spirit and scope of the invention as defined in the appended claims. Therefore, the breadth and scope of the invention disclosed herein should not be limited by the exemplary embodiments disclosed above, but should be defined solely by the appended claims and their equivalents.

Claims

1. A 3×3 dissimilar flight control computing architecture, comprising: There are 3 FCMs, each of which includes three dissimilar branches; Four pairwise dissimilar actuators control the electronic ACE; In each FCM, two branches share point-to-point communication through IOC, while the remaining branches communicate with the remaining branches of the other two FCMs via single-branch point-to-point communication. At the same time, the remaining branches also communicate with the IOCs of the other two FCMs via point-to-point communication. In this context, the IOC and remaining branches of each FCM communicate with each of the ACEs in a point-to-point manner via a bus.

2. The flight control computing architecture as described in claim 1, characterized in that, in, The dual-branch IOC communication combinations of the shared IOC communication in each FCM are dissimilar, and consequently, the single-branch point-to-point communication of each FCM also remains dissimilar.

3. The flight control computing architecture as described in claim 2, characterized in that, In FCM1, branch TYPE I and TYPE II share point-to-point communication through IOC1 to form a dual-branch IOC communication, while the remaining branch TYPE III is a single-branch point-to-point communication; in FCM2, branch TYPE I and TYPE IIII share point-to-point communication through IOC2 to form a dual-branch IOC communication, while branch TYPE II is a single-branch point-to-point communication. In FCM3, branch TYPE II and TYPE III share point-to-point communication through IOC3 to form a dual-branch IOC communication, while branch TYPE I is a single-branch point-to-point communication.

4. The flight control computing architecture as described in claim 1, characterized in that, The three dissimilar branches are respectively designated as instruction / backup / monitoring branches. The backup branch serves as the monitoring branch when the instruction branch is normal, and supports the original instruction branch function when the instruction branch fails.

5. A flight control computing system, comprising: The 3×3 dissimilar flight control computing architecture as described in any one of claims 1-4; The actuator system is configured to communicate with the ACE in the flight control computing architecture to receive actuator control commands; The PCM is configured to power the flight control computing system.

6. A fault monitoring and fault-tolerant control method for a 3×3 dissimilar flight control computing architecture as described in any one of claims 1-4, comprising: Monitor the control output commands of each branch in each FCM; The control output commands of the three branches in each FCM are compared in pairs: If the control output command of one branch exceeds the threshold when compared with the control output commands of the other two branches, the fault monitor will be triggered to determine that the branch has a fault and isolate it. When the IOC is fault-free, the two branches of the dual-branch IOC communication of each FCM serve as the command branch and the backup branch, and the remaining branch that performs single-branch point-to-point communication serves as the monitoring branch. The backup branch serves as the monitoring branch when the command branch is normal, and replaces the function of the original command branch when the command branch fails. In the event of an IOC failure, the remaining branches of the single-branch point-to-point communication of the FCM of the failed IOC are used as command branches, while the branches of the dual-branch IOC communication are used as monitoring branches. When both the IOC and the remaining branches fail, the FCM of both the failed IOC and the remaining branches is isolated.

7. The control method as described in claim 6, characterized in that, The IOC fault is determined according to the following procedure: If the comparison between the control output command of a dual-branch IOC communication of an FCM and its single-branch communication exceeds a threshold, and the comparison between the control output command of the dual-branch IOC communication of the FCM and the control output commands of the single-branch communication of the other two FCMs exceeds a threshold, but the comparison between the control output command of the single-branch communication of the FCM and the control output commands of the single-branch communication of the other two FCMs does not exceed a threshold, then it is determined that a common-mode fault has occurred inside the IOC of the FCM.

8. The control method as described in claim 6, characterized in that, The control output commands of the three branches in each FCM are compared in pairs, including: 1) If the comparison results in all combinations are inconsistent, it indicates that at least two of the three branches of the FCM are faulty, and the FCM should be isolated. 2) If the comparison results of the control output commands of branch TYPE I and branch TYPE II are inconsistent, and the comparison results of the control output commands of branch TYPE I and branch TYPE III are also inconsistent, but the comparison results of the control output commands of branch TYPE II and branch TYPE III are consistent, then it indicates that branch TYPE I of the FCM has failed. Isolate branch TYPE I, use branch TYPE II as the command branch, and use branch TYPE III as the monitoring branch. 3) If the comparison results of the control output commands of branch TYPE I and branch TYPE II are inconsistent, and the comparison results of the control output commands of branch TYPE II and branch TYPE III are also inconsistent, but the comparison results of the control output commands of branch TYPE I and branch TYPE III are consistent, then it indicates that branch TYPE II of the FCM has failed. Isolate branch TYPE II, use branch TYPE I as the command branch, and use branch TYPE III as the monitoring branch. 4) If the comparison results of the control output commands of branch TYPE I and branch TYPE III are inconsistent, and the comparison results of the control output commands of branch TYPE II and branch TYPE III are also inconsistent, but the comparison results of the control output commands of branch TYPE I and branch TYPE II are consistent, then it indicates that branch TYPE III of the FCM may be faulty.

9. The control method as described in claim 8, characterized in that, If the FCM's branch TYPE III may fail, then it is further determined whether the comparison results of the control output commands of the FCM's branch TYPE I and branch TYPE II are consistent with those of the two remaining branches of the other two FCMs: If any of the comparison results are consistent, the FCM's branch TYPE III is determined to be faulty, the FCM's branch TYPE III is isolated, branch TYPE I is used as the command branch, and branch TYPE II is used as the monitoring branch. If all comparison results are inconsistent, then it is further determined whether the comparison results of the control output commands of the branch TYPE III of the FCM are consistent with those of the two remaining branches of the other two FCMs.

10. The control method as described in claim 8, characterized in that, Determining whether the comparison result of the control output command of the branch TYPE III of the FCM is consistent with that of the two remaining branches of the other two FCMs includes: If any of the comparison results are consistent, it means that the FCM's branch TYPE III is normal, and the fault is the FCM's IOC. Isolate the IOC, use branch TYPE III as the instruction branch, and use branch TYPE I and branch TYPE II as monitoring branches. If all comparison results are inconsistent, it indicates that the IOC and the branch TYPE III of the FCM are faulty, and the FCM should be isolated.