Healthcare management fusion system and method for ejection lifesaving system homogeneity and isomerism
By using a health management fusion system with a homogeneous yet heterogeneous architecture, the structural redundancy and insufficient data integration of traditional ejection rescue systems have been resolved. This has enabled lightweight design and enhanced safety, ensuring accurate fault level determination and reliable data reporting.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA AVIATION LIFESAVING INST
- Filing Date
- 2025-12-31
- Publication Date
- 2026-04-21
AI Technical Summary
Traditional ejection escape systems suffer from structural redundancy, low information integration efficiency, incomplete health management data, weak fault location and severity assessment capabilities, and false alarms and missed alarms, making it difficult to meet the requirements of lightweight design and safety.
The health management fusion system adopts a homogeneous heterogeneous architecture, which divides multiple processors into control units that serve as backups for each other, establishes a master-slave relationship, sets up multi-channel data transmission, implements preset rule verification and integration of health management data, clarifies fault level judgment logic, and ensures accurate data reporting.
The system achieves a lightweight design for the ejection escape system, improves the accuracy and reliability of fault characterization, ensures flight rescue safety, and provides comprehensive system status feedback and fault handling basis.
Smart Images

Figure CN121901030A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of ejection rescue control technology, and in particular to a health management fusion system and method for ejection rescue systems with homogeneous but heterogeneous structures. Background Technology
[0002] Ejection escape systems are critical devices for ensuring the safety of pilots, requiring extremely high levels of safety and reliability. Furthermore, due to onboard installation constraints, lightweight design is essential within limited space. Traditional ejection escape systems, with their core control component being an electronic programmable controller, typically employ an architecture of "two independent control systems + an independent information integration board + an auxiliary control board" to ensure reliability and the integrity of control functions.
[0003] While this design meets basic life-saving control requirements, it suffers from significant technical deficiencies in areas such as lightweight design for the adaptable aircraft, data integration efficiency, accuracy of status representation, and fault handling capabilities. These deficiencies include: structural redundancy (traditional controllers require separate information integration and auxiliary control boards, resulting in high functional overlap between the two control systems, numerous components, large overall weight, and significant space occupation, making it difficult to adapt to the lightweight design requirements of limited installation space on the aircraft); information integration relies on third-party processors (traditional systems use independent third-party processors to integrate multi-source health data, resulting in simple and rigid integration logic with insufficient flexibility and adaptability); and limited health management information representation (traditional controllers' health management data only reflect the controller's own operating status, not the overall control logic and operating status of the seat, failing to provide effective feedback on the seat's full status to the onboard system, leading to a lack of subsequent assessment of the overall safety of the ejection life-saving system). Comprehensive data support is lacking; however, the traditional system lacks a clear master-slave priority rule for processors, resulting in an inefficient data integration logic for scenarios with multiple processors working in parallel. Furthermore, the system's fault location and severity assessment capabilities are weak. The traditional system's health data integration logic is simplistic, making it difficult to accurately locate specific faulty units within multiple processors using a single set of health data. It also lacks clear fault severity classification standards, making it impossible to accurately express the severity of faults through data, and resulting in inaccurate transmission of core fault information. Finally, the system lacks rules for handling conflicting fault states. When two control systems have inconsistent state assessments due to different fault items, the traditional system lacks a clear priority logic for state reporting, making it unable to filter out states that truly reflect the seat's performance level for reporting. This can easily lead to false alarms, missed reports, or incomplete characterization, affecting the accurate assessment of the system's operating status and potentially jeopardizing ejection safety. Summary of the Invention
[0004] The main objective of this invention is to provide a health management fusion system and method for ejection escape systems with homogeneous but heterogeneous designs, to solve the problem of integrating health data of ejection escape systems, and to accurately report faults and seat status while achieving lightweight design.
[0005] The technical solution adopted in this invention is: a health management fusion system based on a homogeneous yet heterogeneous ejection rescue system, comprising: Multiple processors for collecting health management data are divided into a first control unit and a second control unit that serve as backups for each other. The first control unit includes a first main processor and at least one first slave processor, and the second control unit includes a second main processor and at least one second slave processor. Channels for transmitting health management data are provided between the first main processor and each first slave processor, between the second main processor and each second slave processor, and between the first main processor and the second main processor. The first main processor and the second main processor are used to verify and integrate the received health management data according to preset rules, and to determine the fault level of the ejection rescue system based on the standardized health status data after integration and verification. The fault level includes normal state, performance degradation state and functional failure state. The fault level of the ejection rescue system and the standardized health status data after integration and verification are reported to external devices.
[0006] According to the above technical solution, the first control unit and the second control unit constitute a homogeneous heterogeneous architecture, and the first main processor and the second main processor, and the first slave processor and the second slave processor respectively have corresponding homogeneous heterogeneous relationships; The first master processor receives health management data from the first slave processor via a serial port; the second master processor receives health management data from the second slave processor via a serial port; and the first master processor receives health management data from the second master processor via an SPI interface.
[0007] According to the above technical solution, the step of verifying the received health management data according to preset rules specifically includes: if a preset number of erroneous data packets are received consecutively, the corresponding slave processor is set to a receiving state failure; if a correct data packet is received once, the slave processor with a receiving state failure is set to a receiving state normal.
[0008] According to the above technical solution, the number of health management data types acquired by the first main processor is greater than the number of health management data types acquired by all the first slave processors; the number of health management data types acquired by the second main processor is greater than the number of health management data types acquired by all the second slave processors.
[0009] According to the above technical solution, the step of integrating the received health management data according to preset rules specifically includes: When the first main processor is collecting health management data normally: if the first main processor receives health management data from the first slave processor, then the health management data from the first main processor and the first slave processor are integrated; if the first main processor does not receive health management data from the first slave processor, but the second main processor receives health management data from the second slave processor, then the health management data from the first main processor, the second main processor, and the second slave processor are integrated; if the first main processor does not receive health management data from the first slave processor, and the second main processor does not receive health management data from the second slave processor, then the health management data from the first main processor and the second main processor are integrated. When the first main processor fails to collect health management data normally: if the second main processor does not receive health management data from the second slave processor, the health management data of the second main processor is integrated; if the second main processor receives health management data from the second slave processor, the health management data of the second main processor and the second slave processor are integrated.
[0010] When integrating the above technical solution: The priority of health management data acquired by the first main processor in the first control unit is higher than the priority of health management data acquired by each of the first slave processors; The priority of health management data acquired by the second main processor in the second control unit is higher than the priority of health management data acquired by each second slave processor. The priority of health management data acquired by the first main processor is higher than that of health management data acquired by the second main processor.
[0011] According to the above technical solution, the determination of the fault level of the ejection escape system specifically includes: For a single control unit, if the main processor has at least one fault that causes functional failure, then the health feedback function failure status bit of that side's main processor is set to failure; for a main processor that is not set to failure, if at least one fault that causes performance degradation occurs or the performance degradation status bit of any processor on that side is set to degradation, then the performance degradation status bit of that side's main processor is set to degradation; otherwise, it is set to normal state.
[0012] According to the above technical solution, for the ejection life-saving system as a whole, if there are functional failures in both the first control unit and the second control unit, the fault level is determined to be a functional failure state; if there are performance degradations in both the first control unit and the second control unit, the fault level is determined to be a performance degradation state.
[0013] According to the above technical solution, the fault level of the ejection escape system is reported to external equipment, specifically including: In normal flight mode, the integrated health management data is reported to external devices at a preset cycle; After the ejection escape system has finished operating, health management data is sent cyclically. If the first main processor malfunctions, it will automatically switch to the second main processor to upload data, and switch back to the first main processor after the first main processor recovers.
[0014] Another aspect of the present invention provides a health management fusion method for homogeneous and heterogeneous ejection rescue systems, the method being based on the aforementioned health management fusion system for homogeneous and heterogeneous ejection rescue systems, comprising: Communication connections for health management data are established between the first main processor and the first slave processor of the first control unit, between the second main processor and the second slave processor of the second control unit, and between the first main processor and the second main processor, respectively. According to the preset priority strategy, the health management data of the first master processor, the first slave processor, the second master processor and the second slave processor are integrated and processed. The fault level of the ejection escape system is determined based on the integrated health management data of each processor. The fault level includes performance degradation state and functional failure state. The integrated health management data of each processor and the fault level of the ejection escape system are reported to external devices.
[0015] The beneficial effects of this invention are: by dividing the processor into dual control units and setting up a master-slave architecture, and combining it with multi-channel health management data transmission for orderly integration and verification, it not only eliminates the need for traditional independent information integration boards, achieving system lightweighting and miniaturization, but also comprehensively reflects the overall status of the ejection rescue system through clear fault level judgment and accurate data reporting, improving the accuracy and reliability of fault characterization, and effectively ensuring flight rescue safety.
[0016] Furthermore, by employing a verification logic that establishes faults upon continuous errors and restores correct data, abnormal data reception can be quickly identified while avoiding misjudgments, ensuring the accuracy of health management data verification and providing a reliable data source for data integration.
[0017] Furthermore, the priority rules between master and slave processors and master and master processors are clearly defined, so that when there are differences in data among multiple processors, precise selection can be made to ensure that the integrated data meets the core control requirements of the system and improve the effectiveness of data integration.
[0018] Furthermore, based on the fault level determination rules of dual control unit collaboration, the state of a single unit is not misled by the overall judgment, ensuring that the fault level truly reflects the overall system performance and providing a reliable basis for subsequent handling.
[0019] Furthermore, the scenario-specific reporting strategy, combined with the main processor redundancy switching mechanism, ensures the continuity and stability of health data reporting. Even if the first main processor fails, data can be transmitted without interruption, meeting the reporting needs under different operating conditions.
[0020] Of course, any product implementing this invention does not necessarily need to achieve all of the advantages described above at the same time. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1 This is a schematic diagram of the control system structure of the ejection life-saving system according to an embodiment of the present invention; Figure 2 This is a flowchart of the control method of the ejection lifesaving system according to an embodiment of the present invention; Figure 3 This is a flowchart of the health management data receiving process of the control method of the ejection lifesaving system according to an embodiment of the present invention; Figure 4 This is another health management data receiving flowchart of the control method of the ejection lifesaving system according to an embodiment of the present invention. Detailed Implementation
[0023] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0024] It should be noted that the illustrations provided in the embodiments of the present invention are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the number, shape and size of the components in actual implementation. In actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.
[0025] In this invention, it should also be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application. Furthermore, the terms "first" and "second" are used only for descriptive and distinguishing purposes and should not be construed as indicating or implying relative importance.
[0026] Example 1 This embodiment provides a health management fusion system with a homogeneous yet heterogeneous ejection rescue system, the structure of which is as follows: Figure 1 As shown. To meet the extremely high safety and reliability requirements of the ejection escape system, and to adapt to the lightweight design requirements of limited onboard space, this system adopts a homogeneous heterogeneous architecture design, specifically including: Multiple processors that collect health management data are divided into a first control unit and a second control unit that serve as backups for each other. The first control unit includes a first master processor and at least one first slave processor, and the second control unit includes a second master processor and at least one second slave processor. The two control units have the same main functions related to ejection rescue control and serve as backups for each other. Channels for transmitting health management data are provided between the first master processor and each first slave processor, between the second master processor and each second slave processor, and between the first master processor and the second master processor, to ensure data communication between the multiple processors.
[0027] Specifically, the first control unit and the second control unit form a homogeneous heterogeneous architecture, and the first main processor and the second main processor, as well as the first slave processor and the second slave processor, respectively have corresponding homogeneous heterogeneous relationships.
[0028] Specifically, the similarity is reflected in the following: the core functions of the ejection rescue control of the first control unit and the second control unit are the same; the core responsibilities of the first main processor and the second main processor in health management data verification, integration and fault level judgment are the same; and the core responsibilities of the first slave processor and the second slave processor in health management data acquisition are the same.
[0029] The heterogeneity is specifically manifested in the following ways: there are clear differences in the pre-launch auxiliary function configuration and self-test item range between the first control unit and the second control unit; there are preset differences in the pre-launch self-test content, non-core function allocation and data processing priority between the first main processor and the second main processor, and between the first slave processor and the second slave processor, and these differences are adapted to the functional division of each processor.
[0030] Specifically, health management data is a set of key data collected and generated by the processors within the ejection life-saving control system's programmable controller. It includes self-test results, operating status, fault information, and other content. After fusion processing, it can characterize the performance degradation or functional failure status of a single processor, the same-side combination, and the entire programmable controller. It can accurately locate faults and transmit data back through a single external port, providing a basis for system status monitoring and fault response.
[0031] Furthermore, the first master processor receives health management data from the first slave processor via a serial port; the second master processor receives health management data from the second slave processor via a serial port; and the first master processor receives health management data from the second master processor via an SPI interface. Based on the transmission characteristics of the serial port and SPI interface, different data transmission requirements between master and slave processors and between master and master processors are adapted to ensure transmission stability and efficiency.
[0032] Furthermore, the first main processor acquires more types of health management data than all the first slave processors acquire; similarly, the second main processor acquires more types of health management data than all the second slave processors acquire. Specifically, the periodic self-test of the first main processor includes multi-channel voltage detection, while the periodic self-test of the first slave processor does not. Likewise, the periodic self-test of the second main processor also includes multi-channel voltage detection, while the second slave processor does not. This functional differentiation design reduces redundancy and balances lightweight design with comprehensive data acquisition.
[0033] The first and second main processors are used to verify and integrate the received health management data according to preset rules, solving the problem of orderliness and accuracy in multi-processor data integration under a homogeneous heterogeneous architecture. Based on the standardized health status data after integration and verification, the fault level of the ejection rescue system is determined. The fault level includes normal state, performance degradation state, and functional failure state, where performance degradation state indicates that the system performance has decreased but can still complete the preset functions, and functional failure state indicates that the preset functions cannot be completed. The fault level of the ejection rescue system and the standardized health status data after integration and verification are reported to external devices.
[0034] Furthermore, the step of verifying the health management data acquired by each processor according to preset rules specifically includes: if a preset number of erroneous data packets are received consecutively, the corresponding slave processor is set to a receiving state failure; if a correct data packet is received once, the slave processor with a receiving state failure is set to a receiving state normal. Considering the stability characteristics of serial transmission between master and slave processors, the preset number of times is set to 6 clock cycles. However, since the real-time requirements for data transmission between master and master processors via the SPI interface are higher, a failure is set after only 1 clock cycle of error, ensuring the relevance and accuracy of data verification. The receiving function is immediately restored after receiving normal data to avoid continuous misjudgment.
[0035] Furthermore, when the first main processor is collecting health management data normally: if the first main processor receives health management data from the first slave processor, then the health management data of the first main processor and the first slave processor are integrated; if the first main processor does not receive health management data from the first slave processor, but the second main processor receives health management data from the second slave processor, then the health management data of the first main processor, the second main processor, and the second slave processor are integrated; if the first main processor does not receive health management data from the first slave processor, and the second main processor does not receive health management data from the second slave processor, then the health management data of the first main processor and the second main processor are integrated.
[0036] When the first main processor fails to collect health management data normally: if the second main processor does not receive health management data from the second slave processor, it integrates the health management data from the second main processor; if the second main processor receives health management data from the second slave processor, it integrates the health management data from both the second main processor and the second slave processor. Normal collection of health management data by the first main processor means that the first main processor itself is fault-free and can successfully collect its own health management data.
[0037] Given the design limitation of the system having only one external communication output port, this integration logic covers various data receiving scenarios, ensuring that the health management data of the four processors can be effectively included, avoiding data omissions or integration chaos.
[0038] Furthermore, during integration: the priority of health management data acquired by the first main processor in the first control unit is higher than the priority of health management data acquired by each first slave processor; the priority of health management data acquired by the second main processor in the second control unit is higher than the priority of health management data acquired by each second slave processor; and the priority of health management data acquired by the first main processor is higher than the priority of health management data acquired by the second main processor. This priority setting is based on the allocation logic of core control functions under a homogeneous heterogeneous architecture, ensuring that when there are differences in data from multiple processors, the data from the main processor with stronger core control capabilities is used first, ensuring that the integration result conforms to the core control requirements of the system.
[0039] Furthermore, for a single control unit, if the main processor experiences at least one fault that causes functional failure, the health feedback function failure status bit of that side's main processor is set to "failed." For a main processor not set to "failed," if at least one fault that causes performance degradation occurs, or if the performance degradation status bit of any processor on that side is set to "degraded," the performance degradation status bit of that side's main processor is set to "degraded." Otherwise, it is set to "normal." The fault status determination of a single control unit is used to accurately characterize the operating status of that side, providing basic data support for the overall system status assessment. Faults causing functional failure include, but are not limited to, core control link interruption, complete sensor malfunction, and processor inability to execute rescue control commands; faults causing performance degradation include, but are not limited to, data transmission delay, non-core function anomalies, and failure of some self-test items.
[0040] Furthermore, for the ejection seat system as a whole, if both the first and second control units exhibit functional failures, the fault level is determined to be a functional failure state; if both the first and second control units exhibit performance degradation faults, the fault level is determined to be a performance degradation state. This judgment logic is based on the design concept of the dual control units serving as backups for each other, ensuring that the final reported health management information accurately reflects the overall performance level of the ejection seat and avoiding misleading the overall judgment by the status of a single unit.
[0041] Furthermore, in normal flight mode, the integrated health management data is reported to external devices at a preset cycle of 120±5ms. After the ejection escape system finishes operating, health management data is sent cyclically. If the first main processor malfunctions, the system automatically switches to the second main processor to upload data, and switches back to the first main processor after it recovers. This reporting strategy not only meets the real-time data requirements during normal flight but also provides continuous status feedback after the system finishes operating. The redundancy switching mechanism for the main processor ensures the continuity of data reporting and avoids data interruption due to the malfunction of a single main processor.
[0042] This embodiment also provides a health management fusion method for homogeneous and heterogeneous ejection rescue systems. The implementation of this method is based on the aforementioned health management fusion system for homogeneous and heterogeneous ejection rescue systems, and specifically includes: Communication connections for health management data are established between the first master processor and the first slave processor of the first control unit, between the second master processor and the second slave processor of the second control unit, and between the first master processor and the second master processor. Based on the transmission characteristics of serial port and SPI interface, the transmission requirements between different processors are adapted to ensure stable and efficient data transmission.
[0043] Based on a preset priority strategy, the health management data of the first master processor, the first slave processor, the second master processor, and the second slave processor are integrated and processed. The integration rules are strictly followed to adapt to the homogeneous heterogeneous architecture, covering various data receiving scenarios and ensuring the integrity and effectiveness of data integration.
[0044] The fault level of the ejection escape system is determined based on the integrated health management data of each processor. The fault level includes performance degradation state and functional failure state. First, the refined state judgment of the individual control unit is completed, and then the overall fault level of the system is determined based on the collaborative logic of the two control units to ensure that the judgment result is accurate and reliable.
[0045] The integrated health management data of each processor and the fault level of the ejection rescue system are reported to external devices. The data is continuously and stably transmitted according to the reporting rules of different scenarios, providing a comprehensive and accurate basis for the safety assessment and subsequent handling of the ejection rescue system.
[0046] Example 2 Based on Example 1, this example provides another method for integrating health management data across homogeneous and heterogeneous ejection escape systems. This method, by defining the health management chain, integration strategy, and fault reporting logic, achieves accurate integration of health management data and accurate reporting of fault status under homogeneous and heterogeneous architectures. The process is as follows: Figure 2 As shown.
[0047] After the process starts, the system first enters the health management data receiving stage. Simultaneously, the system monitors the health management data status of processor A receiving data from processor B, processor A receiving data from processor C, and processor C receiving data from processor D, and determines in real time whether the data reception is normal: if processor A receives data from processor B or processor C receives data from processor D and experiences 6 consecutive errors, or processor A receives data from processor C and experiences 1 error, the corresponding data reception status is immediately set to fault and the system continues to wait for reception. Once a normal data packet is received, the reception function is immediately restored; if there are no errors in the reception, the reception status is recorded as "received"; if the corresponding signal is not received, it is recorded as "not received".
[0048] Subsequently, based on the signal reception results, the data integration branch is initiated: If processor A receives a signal from processor B and processor C receives a signal from processor D, then the health management data of processors A, B, C, and D are fully integrated; if processor A does not receive a signal from processor B but processor C receives a signal from processor D, then the data of processors A, C, and D are integrated; if processor A does not receive a signal from processor B and processor C does not receive a signal from processor D, then the data of processors A and C are integrated; if only processor C does not receive a signal from processor D, then the data of processor C is integrated separately. During the integration process, processor C directly sets its own and processor D's fault locations as the corresponding fault states. Processor A is responsible for overall fault location and state determination, meaning that it needs to determine whether there are functional failures or performance degradation fault items on one side and set the corresponding state bit. Overall, the controller's overall functional failure state or performance degradation state is only set if any processor on both sides has a corresponding fault item.
[0049] After data integration is completed, the integrated health management data packet is sent back to the UMC (upper management computer) at a cycle of 120±5ms in normal flight mode. The packet is sent cyclically after the product finishes its work. If processor A malfunctions, the system automatically switches to processor C to upload health data. Once processor A returns to normal, the system switches back to processor A to handle data uploading, and the process ends there.
[0050] Specifically, it also includes: Based on the classification principle that the control boards on both sides have the same function, each side is assigned a designated processor to undertake the information integration responsibility, and a full-link data transmission channel is constructed. The first master processor (corresponding to processor A) receives the health management data of the first slave processor (corresponding to processor B) in real time through the serial port, and the second master processor (corresponding to processor C) receives the health management data of the second slave processor (corresponding to processor D) in real time through the serial port. At the same time, the first master processor receives the health management data of the second master processor in real time through the SPI interface, thereby realizing the interconnection of health management data of all processors and providing basic support for the information integration of the entire product.
[0051] Regarding the data integration strategy, priority rules are first clarified: within a single control unit, the first master processor has a higher priority than the first slave processor, and the second master processor has a higher priority than the second slave processor. For the system as a whole, the first master processor has a higher priority than the second master processor, ensuring that data from the processor with stronger core control capabilities is prioritized during data integration. Then, based on the data reception status of each processor, scenario-specific integration operations are performed. If the first master processor receives health management data from the first slave processor, then the health management data of the first master processor and the first slave processor are integrated. If the second master processor receives health management data from the second slave processor, then the health management data of the second master processor and the second slave processor are integrated. If the first master processor does not receive health management data from the first slave processor but the second master processor does receive health management data from the second slave processor, then the health management data of the first master processor, the second master processor, and the second slave processor are integrated. If the first master processor does not receive health management data from the first slave processor and the second master processor does not receive health management data from the second slave processor... For health management data, the system integrates the health management data from the first main processor and the second main processor. If the second main processor does not receive health management data from the second slave processor, only the health management data from the second main processor is integrated. Simultaneously, differentiated data reception error handling rules are established based on the characteristics of different transmission links. When the first main processor receives data from the first slave processor or the second main processor receives data from the second slave processor, if there are six consecutive data packet reception errors, the corresponding data reception status is set to fault and the system continues to wait for data reception. When the first main processor receives data from the second main processor, even a single data packet reception error will set the corresponding data reception status to fault and continue to wait for data reception. In both scenarios, data reception is immediately restored after receiving a normal data packet to avoid continuous misjudgments. Furthermore, the system has a processor fault bit. When any processor reports a fault, the processor's fault bit is set to fault status for precise fault location. The second main processor directly sets its own and the second slave processor's fault status without additional processing.
[0052] Regarding the fault reporting logic, two fault levels are first defined: a performance degradation state indicates that the system performance has decreased but the preset functions can still be completed, and a function failure state indicates that the preset functions cannot be completed, clearly distinguishing the severity of the fault. Next, the status of a single control unit is determined. Each control unit only represents its own operating status. If at least one fault item causing function failure exists within the unit, the function failure status bit in the health feedback of the main processor on that side is set to failure; otherwise, it is set to not failure. If at least one fault item causing performance degradation exists within the unit, or if the performance degradation status bit in the health management data of any processor within the unit is set to degradation, the main processor on that side is set to failure. The system's overall performance degradation status is set to "degraded" if the device's performance degradation status is set to "degraded" otherwise. Finally, the overall system status is determined by combining the statuses of the two control units. If there is a functional failure fault item in the first master processor or the first slave processor in the first control unit, and there is a functional failure fault item in the second master processor or the second slave processor in the second control unit, then the overall system functional failure status is set to "failed" otherwise. If there is a performance degradation fault item in the first master processor or the first slave processor in the first control unit, and there is a performance degradation fault item in the second master processor or the second slave processor in the second control unit, then the overall system performance degradation status is set to "degraded" otherwise.
[0053] The specific execution process of this control method proceeds sequentially from signal reception, integration, and feedback.
[0054] The signal reception process is as follows: Figure 3 and Figure 4 As shown: like Figure 3 As shown, after the process starts, it first enters the monitoring stage of the 120ms timer interrupt, continuously judging whether the interrupt has occurred: if the interrupt has not yet been triggered, it maintains a loop waiting state; after the 120ms interrupt occurs, it immediately sends health data through the serial port. After the data sending operation is completed, the entire process ends.
[0055] like Figure 4As shown, after the process starts, it first determines whether there is an interruption or reception error in 5C reception. If so, it performs a 5C reset operation; otherwise, it checks whether there is data in the 5C receive buffer. If there is, it initializes the checksum ChkSum to the current data rxdata. Next, it checks if the current byte is the first one. If so, it checks if rxdata equals 0xAA. Then it checks if it is the second byte. If so, it checks if rxdata equals 0x55. It continues to check if it is the third byte. If so, it checks if rxdata equals 0x48. This process continues until the current byte is the 72nd byte. If it is not the 72nd byte, the current rxdata is stored in the corresponding index of the receive array Rx_Buf, and the count is incremented. When the current byte is the 72nd byte, the count is set to 0. Then, it checks if ChkSum is equal to 0xFF. If they are equal, the complete health data of this packet is saved, and the process ends. If they are not equal, the count is set to 0, and the process also ends (where ChkSum is the checksum for successful or failed reception of the block, and Rx_Buf is the receive array storing the data successfully received by block A or B).
[0056] The entry condition for receiving health management data is that the first slave processor, the second master processor, and the second slave processor all have health management data input. During processing, the first master processor receives health management data from the first slave processor in real time via a serial port, and the second master processor receives health management data from the second slave processor in real time via a serial port. Both receive data packets in real time and determine their status. If the data packet reception is normal, the corresponding data reception status word is set to normal and data reception continues. If there are six consecutive data packet reception errors, the corresponding data reception status word is set to fault and the processor continues to wait for data reception. Simultaneously, the first master processor receives health management data from the second master processor in real time via the SPI interface and determines its status in real time. If the data packet reception is normal, the data reception status word is set to normal and data reception continues. If there is only one data packet reception error, the data reception status word is set to fault and the processor continues to wait for data reception. Anomaly handling is the same as the above process, with no specific time requirement. The input is the health management data from the first slave processor, the second master processor, and the second slave processor, and the output is data. The entry condition for health management data integration is that after each processor completes its periodic self-check, a 120ms health management data integration cycle arrives. The processing is executed according to the aforementioned scenario-based integration logic, with no exception handling or time requirements. The inputs are the health management data and status data of the first master processor, the first slave processor, the second master processor, and the second slave processor. The output is the integrated health management data packet. The entry condition for health management data return is that health management data integration is completed in normal flight mode, before system reset, or after product operation ends. During the processing, in normal flight mode, the integrated health management data is transmitted to the UMC at a 120ms cycle. After product operation ends, it is sent to the UMC cyclically. In exception handling, if the first master processor is abnormal, it automatically switches to the second master processor to upload health data. After the first master processor recovers, it switches back to the first master processor to ensure data transmission continuity. The time requirement is a data return cycle of 120±5ms with no input. The output is the integrated health management data packet.
[0057] In summary, this invention provides a health management fusion system and method for homogeneous and heterogeneous ejection escape systems, which solves the problem of integrating health data of ejection escape systems and accurately reports faults and seat status while achieving lightweight design.
[0058] It should be noted that, depending on the implementation needs, the various steps / components described in this application can be broken down into more steps / components, or two or more steps / components or parts of the operation of steps / components can be combined into new steps / components to achieve the purpose of this invention.
[0059] The sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0060] It should be understood that those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims.
Claims
1. A health management fusion system based on a homogeneous yet heterogeneous ejection rescue system, characterized in that, include: Multiple processors that collect health management data are divided into a first control unit and a second control unit that serve as backups for each other; The first control unit includes a first main processor and at least one first slave processor, and the second control unit includes a second main processor and at least one second slave processor; channels for transmitting health management data are respectively provided between the first main processor and each first slave processor, between the second main processor and each second slave processor, and between the first main processor and the second main processor; The first main processor and the second main processor are used to verify and integrate the received health management data according to preset rules, and to determine the fault level of the ejection rescue system based on the standardized health status data after integration and verification. The fault level includes normal state, performance degradation state and functional failure state. The fault level of the ejection rescue system and the standardized health status data after integration and verification are reported to external devices.
2. The health management fusion system based on the same type but different structure of the ejection life-saving system according to claim 1, characterized in that, The first control unit and the second control unit form a homogeneous heterogeneous architecture, and the first main processor and the second main processor, and the first slave processor and the second slave processor respectively have corresponding homogeneous heterogeneous relationships; The first master processor receives health management data from the first slave processor via a serial port; The second master processor receives health management data from the second slave processor via a serial port; The first main processor receives health management data from the second main processor via the SPI interface.
3. The health management fusion system based on the homogeneous and heterogeneous ejection rescue system according to claim 1, characterized in that, The step of verifying the received health management data according to preset rules specifically includes: if a preset number of erroneous data packets are received consecutively, the corresponding slave processor is set to a receiving state failure; if a correct data packet is received once, the slave processor with a receiving state failure is set to a receiving state normal.
4. The health management fusion system based on the same type but different structure of the ejection rescue system according to claim 1, characterized in that, The first main processor acquires more types of health management data than all the first slave processors acquire; the second main processor acquires more types of health management data than all the second slave processors acquire.
5. The health management fusion system based on the same type but different structure of the ejection life-saving system according to claim 1, characterized in that, The integration of received health management data according to preset rules specifically includes: When the first main processor is collecting health management data normally: if the first main processor receives health management data from the first slave processor, then the health management data from the first main processor and the first slave processor are integrated; if the first main processor does not receive health management data from the first slave processor, but the second main processor receives health management data from the second slave processor, then the health management data from the first main processor, the second main processor, and the second slave processor are integrated; if the first main processor does not receive health management data from the first slave processor, and the second main processor does not receive health management data from the second slave processor, then the health management data from the first main processor and the second main processor are integrated. When the first main processor fails to collect health management data normally: if the second main processor does not receive health management data from the second slave processor, the health management data of the second main processor is integrated; if the second main processor receives health management data from the second slave processor, the health management data of the second main processor and the second slave processor are integrated.
6. The health management fusion system based on the same type but different configuration of the ejection life-saving system according to claim 5, characterized in that, During integration: The priority of health management data acquired by the first main processor in the first control unit is higher than the priority of health management data acquired by each of the first slave processors; The priority of health management data acquired by the second main processor in the second control unit is higher than the priority of health management data acquired by each second slave processor. The priority of health management data acquired by the first main processor is higher than that of health management data acquired by the second main processor.
7. The health management fusion system based on the same type but different structure of the ejection life-saving system according to claim 1, characterized in that, Determining the fault level of the ejection escape system specifically includes: For a single control unit, if the main processor has at least one fault that causes functional failure, then the health feedback function failure status bit of that side's main processor is set to failure; for a main processor that is not set to failure, if at least one fault that causes performance degradation occurs or the performance degradation status bit of any processor on that side is set to degradation, then the performance degradation status bit of that side's main processor is set to degradation; otherwise, it is set to normal state.
8. The health management fusion system based on the same type but different structure of the ejection life-saving system according to claim 1, characterized in that, For the ejection escape system as a whole, if there are fault items with functional failure in both the first control unit and the second control unit, the fault level is determined to be a functional failure state. If both the first control unit and the second control unit have performance degradation faults, then the fault level is determined to be a performance degradation state.
9. The health management fusion system based on the same type but different structure of the ejection life-saving system according to claim 1, characterized in that, The fault level of the ejection escape system is reported to external equipment, specifically including: In normal flight mode, the integrated health management data is reported to external devices at a preset cycle; After the ejection escape system has finished operating, health management data is sent cyclically. If the first main processor malfunctions, it will automatically switch to the second main processor to upload data, and switch back to the first main processor after the first main processor recovers.
10. A health management fusion method for a homogeneous yet heterogeneous ejection rescue system, the method being implemented based on the health management fusion system for a homogeneous yet heterogeneous ejection rescue system as described in claim 1, characterized in that... include: Communication connections for health management data are established between the first main processor and the first slave processor of the first control unit, between the second main processor and the second slave processor of the second control unit, and between the first main processor and the second main processor, respectively. According to the preset priority strategy, the health management data of the first master processor, the first slave processor, the second master processor and the second slave processor are verified and integrated. The fault level of the ejection escape system is determined based on the integrated health management data of each processor. The fault level includes performance degradation state and functional failure state. The integrated health management data of each processor and the fault level of the ejection escape system are reported to external devices.