Distributed crosslinking actuation system general architecture for aircraft and software design method

By designing a general architecture for a distributed interconnected actuation system, and adopting a distributed redundant controller and a master/backup control mode, the problem of the lack of a unified standard for redundant architecture was solved, and a highly reliable and high power-to-weight ratio aircraft actuation system was achieved, thereby improving the fault tolerance and safety of the aircraft.

CN121934445APending Publication Date: 2026-04-28BEIJING AUTOMATION CONTROL EQUIP INST
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING AUTOMATION CONTROL EQUIP INST
Filing Date
2025-12-18
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing aircraft actuation systems, in their designs for high power-to-weight ratio and high reliability, exhibit diverse redundancy architectures without a unified standard. This leads to an increase in overall weight and prevents proper switching and management in the event of controller chip failure, thus impacting flight safety.

Method used

Design a general architecture for a distributed interconnected actuation system, adopting a distributed redundant controller and actuators. Based on the power-to-weight ratio and reliability constraints, design the interconnection relationship of the redundant controller, and combine the master/standby control mode and state intelligent decision-making to achieve intelligent stress-response fault-tolerant reconfiguration.

Benefits of technology

It improves the reliability and power-to-weight ratio of the aircraft, enables intelligent fault-tolerant switching in the event of controller failure, and enhances the overall performance and safety of the aircraft.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121934445A_ABST
    Figure CN121934445A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of aircraft system / subsystem architecture design and software algorithms, and discloses a distributed cross-linking actuation system general architecture and software design method for an aircraft, and the method comprises the steps: designing a distributed redundancy controller and an actuator of an actuation system according to the overall aerodynamic layout and servo actuation requirements of the aircraft, designing a redundancy controller cross-linking relation and an actuation link single / double configuration relation based on the power-to-weight ratio and the reliability safety constraint; based on distributed layout and control requirements of an aircraft actuation system, a general software architecture process with a main / standby control mode and state intelligent decision judgment is designed; and designing performance state monitoring based on a real-time dynamic virtual model and a channel switching algorithm based on a key fault discrimination signal, and implanting the designed monitoring and switching algorithm into a software architecture to realize intelligent stress fault-tolerant reconstruction of the comprehensive servo actuation system corresponding to different fault working conditions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of aircraft system / subsystem architecture design and software algorithm technology, and in particular to a general architecture and software design method for a distributed cross-linking actuation system for aircraft. Background Technology

[0002] As a servo subsystem of various aircraft, the actuation system is used for attitude control and maintenance, and its reliability directly determines the flight safety of the aircraft. Current aircraft design shows a trend towards high power-to-weight ratio, high reliability, and high intelligence. The actuation system architecture design must comprehensively consider these requirements and be optimized accordingly. To achieve this type of design, based on overall architecture optimization, the use of redundancy design technology in the actuation system can greatly improve the mission reliability of the actuation system.

[0003] However, when using redundancy design technology to design aircraft for high reliability and high power-to-weight ratio, the redundancy architecture takes many forms and lacks a unified standard. Typical redundancy architecture configurations include... Figure 1 As shown, each actuation element adopts a redundancy design, which increases the overall weight of the actuation system and reduces the power-to-weight ratio. Secondly, the switching and management strategy of a typical redundancy actuation system is based on a single model solution within a single redundancy controller. When the controller chip fails, the model and solution process cannot operate normally, and normal channel switching and redundancy management functions cannot continue. In other words, it cannot cope with the extreme situation of such controller chip failure.

[0004] In summary, the fundamental technical challenge that restricts the performance of an aircraft's integrated servo actuation system and the aircraft itself is how to design a redundant architecture with a high power-to-weight ratio and, based on the existing architecture, what software algorithm architecture to achieve generalization and interchangeability, thereby further improving reliability. Summary of the Invention

[0005] The purpose of this invention is to overcome the shortcomings of the prior art and provide a general architecture and software design method for a distributed cross-linking actuation system for aircraft, which can solve the problems in the prior art.

[0006] The technical solution of this invention: a general architecture and software design method for a distributed cross-linking actuation system for aircraft, wherein the method includes:

[0007] Based on the overall aerodynamic layout and servo actuation requirements of the aircraft, a distributed redundant controller and actuators for the actuation system are designed. Based on the power-to-weight ratio and reliability and safety constraints, the interconnection relationship of the redundant controller and the "single / dual" configuration relationship of the actuation links are designed.

[0008] Based on the distributed layout and control requirements of the aircraft's actuation system, a general software architecture process with "master / backup" control modes and intelligent state decision-making is designed.

[0009] The design incorporates a performance status monitoring algorithm based on a real-time dynamic virtual model and a channel switching algorithm based on key fault discrimination signals. The designed monitoring and switching algorithms are then integrated into the software architecture to achieve intelligent stress-tolerant reconfiguration of the integrated servo actuation system for different fault conditions.

[0010] Preferably, the method further includes:

[0011] The effectiveness of the designed distributed redundant controller and actuator, as well as the designed general software architecture process, was verified through simulation.

[0012] Preferably, the distributed redundant controller and actuators of the actuation system are designed according to the overall aerodynamic layout and servo actuation requirements of the aircraft, and the interconnection relationship of the redundant controller and the "single / dual" configuration relationship of the actuation links are designed based on the power-to-weight ratio and reliability and safety constraints, including:

[0013] A1.1 Design a redundant controller with redundant drive control function. Each redundant controller has two MCU processors. Each MCU processor is used to control at least two actuation channels. The hardware of the redundant controllers adopts the same design. The interchangeability is ensured by software configuration. The MCU processors of different redundant controllers are designed to exchange redundancy information to realize the distributed layout of MCU processors.

[0014] A1.2 At the aircraft level, if the flight control system has redundant configuration on the actuation surface, the actuator used for actuation will be configured as "single redundancy". If the actuation surface has no redundancy, the actuator used for actuation will be configured as "double redundancy".

[0015] Preferably, based on the distributed layout and control requirements of the aircraft's actuation system, the design process of a general software architecture with "master / backup" control modes and intelligent state decision-making includes:

[0016] Each MCU processor in the redundancy controller controls two actuation channels, Channel-0 and Channel-1. After the MCU processor number is determined, the actuator redundancy type of the two actuation channels is determined according to the hardware connection relationship, and the main / standby redundancy control mode or the general control mode is determined according to the redundancy type.

[0017] If the redundancy type is a single redundancy configuration, the system will enter the general control mode; if the redundancy type is a multi-redundancy configuration, the system will enter the primary / standby redundancy control mode.

[0018] If the normal control mode is entered, no channel switching is performed. The main process control calculation is performed normally and the status is monitored through the distributed sub-model in the large model. If a fault is detected, the control calculation enters the single-channel fault-tolerant processing mode; otherwise, the control calculation continues to be performed normally.

[0019] If the primary / backup redundancy control mode is entered, the primary / backup channel is further determined. The primary channel is the default controller, and the backup channel is the follower. If it is the primary channel, the main process control calculation is performed normally, and the status is monitored through the distributed sub-model in the large model. If a fault is detected, the control switches from the primary channel to the backup channel. Otherwise, the primary channel continues to perform the main process control calculation normally. If it is the backup channel, the follower channel control calculation is performed, and the status is monitored through the distributed sub-model in the large model. If a fault is detected and the primary / backup interaction information determines that the primary channel has recovered from the fault state, the control switches from the backup channel to the primary channel. Otherwise, the backup channel continues to perform the follower channel control calculation.

[0020] Preferably, a performance status monitoring algorithm based on a real-time dynamic virtual model and a channel switching algorithm based on key fault discrimination signals are designed. The designed monitoring and switching algorithms are embedded into the software architecture to realize intelligent stress-response fault-tolerant reconfiguration of the integrated servo actuation system for different fault conditions, including:

[0021] A3.1. To determine whether the actuation system is functioning normally, a functional judgment based on periodic inspection signals is made: the comprehensive electrical signals are judged, and if a functional fault occurs, the protection processing mode is directly entered. If the actuation channel function fails completely, the channel switching fault-tolerant reconfiguration mechanism is triggered.

[0022] A3.2 Real-time monitoring of the status of the actuation system based on the virtual model to determine whether the performance of the actuation system meets the index requirements: The sliding window data quantization processing algorithm of the intelligent distributed model is used to calculate the performance of the actuation system and determine whether the calculated performance of the actuation system is within the model interval. If it exceeds the model interval, the channel switching fault tolerance mechanism is triggered.

[0023] Through the above technical solutions, a distributed redundant controller with information interconnection function can be designed based on the aerodynamic layout, attitude control, and servo actuation requirements of the aircraft. Considering the power-to-weight ratio requirements, redundant actuators are designed only on some main control surfaces. Furthermore, a general software flow algorithm matching actuation system can be designed, thereby achieving high reliability, fault tolerance, high power-to-weight ratio, and intelligent flight performance of the aircraft. Attached Figure Description

[0024] The accompanying drawings, which form part of this specification, are provided to further illustrate embodiments of the invention and, together with the textual description, explain the principles of the invention. It is obvious that the drawings described below are merely some embodiments of the invention, and those skilled in the art can obtain other drawings based on these drawings without any creative effort.

[0025] Figure 1 A schematic diagram of a traditional redundant actuation system architecture;

[0026] Figure 2 This is a schematic diagram of the redundancy configuration architecture of a highly reliable distributed crosslinked actuation system provided in an embodiment of the present invention;

[0027] Figure 3 This is a schematic diagram of the software flow algorithm in an embodiment of the present invention;

[0028] Figure 4 This is a schematic diagram illustrating the principle of real-time monitoring of the actuation system status based on a virtual model in an embodiment of the present invention;

[0029] Figure 5 This is a simulation effect verification diagram of the distributed cross-linking actuation system fault simulation (MCU failure) in an embodiment of the present invention. Detailed Implementation

[0030] Specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings. In the following description, specific details are set forth for purposes of explanation and not limitation, in order to aid in a thorough understanding of the invention. However, it will be apparent to those skilled in the art that the invention may be practiced in other embodiments departing from these specific details.

[0031] It should be noted that, in order to avoid obscuring the invention with unnecessary details, only the device structure and / or processing steps closely related to the solution according to the invention are shown in the accompanying drawings, while other details that are not closely related to the invention are omitted.

[0032] This invention is applicable to aircraft with long flight time and high reliability requirements. Through this architecture and software process algorithm, the power-to-weight ratio and fault-tolerant operational reliability of the aircraft can be comprehensively improved.

[0033] This invention provides a general architecture and software design method for a distributed cross-linking actuation system for aircraft, wherein the method includes:

[0034] like Figure 2As shown, a distributed redundant controller and actuator of the actuation system are designed according to the overall aerodynamic layout and servo actuation requirements of the aircraft. Based on the power-to-weight ratio and reliability and safety constraints, the interconnection relationship of the redundant controller and the "single / dual" configuration relationship of the actuation link are designed.

[0035] like Figure 3 As shown, based on the distributed layout and control requirements of the aircraft's actuation system, a general software architecture process with "master / backup" control modes and intelligent state decision-making is designed.

[0036] like Figure 4 As shown, a performance status monitoring algorithm based on a real-time dynamic virtual model and a channel switching algorithm based on key fault discrimination signals are designed. The designed monitoring and switching algorithms are embedded into the software architecture to realize intelligent stress-tolerant reconfiguration of the integrated servo actuation system for different fault conditions.

[0037] Through the above technical solutions, a distributed redundant controller with information interconnection function can be designed based on the aerodynamic layout, attitude control, and servo actuation requirements of the aircraft. Considering the power-to-weight ratio requirements, redundant actuators are designed only on some main control surfaces. Furthermore, a general software flow algorithm matching actuation system (integrated servo actuation system) can be designed, thereby achieving high reliability, fault tolerance, high power-to-weight ratio, and intelligent flight performance of the aircraft.

[0038] According to one embodiment of the present invention, the method further includes:

[0039] The effectiveness of the designed distributed redundant controller and actuator, as well as the designed general software architecture process, was verified through simulation.

[0040] Furthermore, regression optimization can further improve the fitting accuracy of the virtual model and the accuracy of various criteria.

[0041] According to one embodiment of the present invention, a distributed redundant controller and actuator of the actuation system are designed based on the overall aerodynamic layout and servo actuation requirements of the aircraft, and the interconnection relationship of the redundant controller and the "single / dual" configuration relationship of the actuation links are designed based on power-to-weight ratio and reliability and safety constraints, including:

[0042] A1.1 Design a redundant controller with redundant drive control function. Each redundant controller has two MCU processors. Each MCU processor is used to control at least two actuation channels (therefore, hardware resource waste can be avoided and a single controller can drive control of at least four actuation channels). The hardware of the redundant controllers adopts the same design. The interchangeability is ensured by software configuration. The MCU processors of different redundant controllers are designed to exchange redundancy information to realize the distributed layout of MCU processors.

[0043] A1.2 At the aircraft level, if the flight control system has redundant configurations on the actuation surfaces (such as having left and right ailerons or left and right elevator surfaces), the actuators used for actuation will be configured in a "single redundancy" form. If the actuation surfaces have no redundancy, the actuators used for actuation will be configured in a "double redundancy" form.

[0044] In this way, the integrated servo actuation system completes redundancy configuration at the actuation or flight control level, ensuring that hardware resources available for reconfiguration and fault tolerance are available.

[0045] According to one embodiment of the present invention, based on the distributed layout and control requirements of the aircraft actuation system, the design process of a general software architecture with "master / backup" control mode and intelligent state decision-making includes:

[0046] Each MCU processor in the redundancy controller controls two actuation channels, Channel-0 and Channel-1. After the MCU processor number is determined, the actuator redundancy type of the two actuation channels is determined according to the hardware connection relationship, and the main / standby redundancy control mode or the general control mode is determined according to the redundancy type.

[0047] If the redundancy type is a single redundancy configuration, the system will enter the general control mode; if the redundancy type is a multi-redundancy configuration, the system will enter the primary / standby redundancy control mode.

[0048] If the normal control mode is entered, no channel switching is performed. The main process control calculation is performed normally and the status is monitored through the distributed sub-model in the large model. If a fault is detected, the control calculation enters the single-channel fault-tolerant processing mode; otherwise, the control calculation continues to be performed normally.

[0049] In other words, for the general control mode, there is no channel switching involved. The control calculation is performed normally, and the state is monitored through the distributed sub-model in the large model.

[0050] If the primary / backup redundancy control mode is entered, the primary / backup channel is further determined. The primary channel is the default controller, and the backup channel is the follower. If it is the primary channel, the main process control calculation is performed normally, and the status is monitored through the distributed sub-model in the large model. If a fault is detected, the control switches from the primary channel to the backup channel. Otherwise, the primary channel continues to perform the main process control calculation normally. If it is the backup channel, the follower channel control calculation is performed, and the status is monitored through the distributed sub-model in the large model. If a fault is detected and the primary / backup interaction information determines that the primary channel has recovered from the fault state, the control switches from the backup channel to the primary channel. Otherwise, the backup channel continues to perform the follower channel control calculation.

[0051] Specifically, the main branch functions are as follows:

[0052]

[0053] According to one embodiment of the present invention, a performance status monitoring algorithm based on a real-time dynamic virtual model and a channel switching algorithm based on key fault discrimination signals are designed. The designed monitoring and switching algorithms are embedded into the software architecture to realize intelligent stress-response fault-tolerant reconfiguration of the integrated servo actuation system corresponding to different fault conditions, including:

[0054] A3.1, such as Figure 4 As shown in the hardware and software architecture, the function of the actuation system is judged based on the periodic inspection signal: the comprehensive electrical signal is judged, and if a functional fault occurs, the protection processing mode is directly entered. If the actuation channel function fails completely, the channel switching fault-tolerant reconstruction mechanism is triggered.

[0055] A3.2, such as Figure 4 As shown in the hardware and software architecture, the system performs real-time state monitoring based on a virtual model to determine whether the performance of the actuation system meets the requirements: the sliding window data quantization processing algorithm of the intelligent distributed model is used to calculate the performance of the actuation system and determine whether the calculated performance of the actuation system is within the model interval. If it exceeds the model interval, a channel switching fault tolerance mechanism is triggered.

[0056] For the actuation performance of a certain actuation channel, the general expression of the sub-model corresponding to the large model is as follows:

[0057]

[0058] Submodel + (s) is the positive control torque submodel in transfer function form, which outputs when synchronously responding to a given command. + -out, represented as y at time k. m+ (k), where the transfer function sign a0 in this model is positive, representing the positive control torque coefficient acting on the load of the actuation system; Submodel - (s) is the negative maneuvering torque submodel in transfer function form, which outputs when synchronously responding to a given command. - -out, represented as y at time k. m- (k), where the negative sign of the transfer function a0 in this model represents the negative control torque coefficient acting on the load of the actuation system; the positive and negative control torque sub-models form the performance response envelope of the actuation system. The output of the actual system plant at time k is defined as y. plant (k). The data processing sliding window step size for real-time model monitoring is selected as N. The root mean square index is used for quantization and serves as the performance deviation threshold criterion. The specific form is as follows:

[0059]

[0060] Define the error quantization values ​​between the system response and the model under positive and negative control torques as follows: and When the two sliding window quantization results at time k satisfy or If the main channel of the redundancy actuation system fails, its response performance cannot meet the requirements, necessitating channel switching to use the backup channel for continued operation. Based on the configuration relationship of the same intelligent distributed sub-model in the main and backup MCUs, after the sub-model in the main MCU detects the switching trigger condition, the system controls to turn off PWM, cut off power output, and send a channel switching command to the backup channel. After the sub-model in the backup MCU detects the switching trigger condition and receives the MCU switching command, the system controls to turn on PWM and enable power output. If the backup MCU does not receive a switching command from the main channel, but the switching trigger condition is met, it is inferred that the main MCU cannot send the switching command normally (the main MCU may be faulty). Therefore, after a fixed set delay, channel switching continues, and PWM is turned on for operation.

[0061] The general architecture and software design method of the distributed cross-linking actuation system for aircraft described in this invention are described below with examples. Specifically:

[0062] 1) Hardware architecture design of a high-reliability distributed cross-linking actuation system

[0063] Different from Figure 1 The controller in the non-interconnected control system, according to Figure 2 The method of designing the actuation system architecture can ensure that the main and backup channels of the same type of actuator can be controlled by different redundant controllers, thereby ensuring that even if one controller fails completely, the actuator can still be controlled normally by the controller that has not failed.

[0064] 2) Software architecture design for a highly reliable distributed cross-linked actuation system

[0065] according to Figure 3 The software architecture process shown is used for specific software architecture design. The number of redundant controllers is set to 2, so the total number of controller MCUs is 4. Each MCU controls two actuator channels, so a total of 8 actuator channels can be controlled. According to the software architecture, the intelligent distribution unified large model of the 8 actuator channels is trained and fitted. After confirming the model parameters, it is distributed and embedded into the corresponding controller MCUs.

[0066] 3) Injection of intelligent stress response mechanisms based on distribution models

[0067] according to Figure 4The integrated servo actuation system fault diagnosis and fault tolerance decision-making mechanism shown is injected and activated with the intelligent stress mechanism of the distributed model, enabling the actuation system to monitor and identify functional faults and performance degradation faults, and to realize fault stress based on the injected intelligent stress mechanism, ensuring rapid fault isolation and reconstruction.

[0068] 4) Simulation comparison and verification

[0069] The state-space form of the aircraft flight control model is selected as follows:

[0070]

[0071] Where the state variable x = [β pr φ] T β, p, r, and φ represent sideslip angle, roll rate, yaw rate, and roll angle, respectively. The specific form of the flight control input is as follows: Within the vector These correspond to the deflection angles of the inner and outer ailerons, spoilers, and upper and lower rudders, respectively. The inner and outer ailerons are controlled by single-redundant actuators, the spoilers by dual-channel single-redundant actuators, and the remaining upper and lower rudders by dual-redundant actuators. The total number of actuator channels is 8, with control input provided by two controllers that can provide 4-channel actuation control. Traditional redundancy configurations lack distributed cross-linking (the upper rudder is controlled by two redundant channels of controller 1, and the lower rudder by two redundant channels of controller 2). According to the distributed cross-linking configuration of this invention, the redundancy control servos have a distributed cross-linking relationship, controlled by different controllers (the upper rudder selects two channels from controller 1 and controller 2 respectively to form redundancy for control, and the lower rudder is configured similarly). w(t) represents the uncontrollable disturbance, and y(t) represents the aircraft output. A normal B normal C normal Let G represent the system matrices for state, input, output, and disturbance, respectively. The parameter matrix of the flight control model is shown below:

[0072]

[0073] The flight controller employs a fixed structure design. For a given flight command r... flight (t) and the aircraft output state S out The controller must guarantee the achievement of the desired performance for y(t). That is, it can effectively track the reference command e track (t)=r flight (t)-S out y(t). The controller type is selected as... The dimension of the parameter matrix indicates the dimension of the simulation model controller selected in this invention [K]. x K eThe value is 5×6. The control law matrix under normal operating conditions is:

[0074]

[0075] The aforementioned integrated servo actuation system architecture was applied to an aircraft, and its reconfiguration and fault tolerance capabilities were verified at the aircraft level. Compared with a traditional non-interconnected redundant actuation system architecture, the beneficial effects of the distributed interconnected integrated servo actuation system were verified. Specific simulation comparison results are shown in the figures below. Figure 5 As shown: When an actuator fault (not a controller fault) fault-1 occurs, fault tolerance can be achieved by switching between the primary and backup channels, as follows: Figure 5 At time 13s, when a servo failure occurs in the main directional control channel, both the traditional configuration and the configuration in this invention can continue to execute flight control. Since channel switching has already been performed at the actuator level for fault tolerance, the control law at the flight control level does not need to be updated.

[0076]

[0077] Depend on Figure 5 Simulation results show that, under non-controller faults, both the traditional redundancy configuration and the redundancy configuration in this invention can achieve fault tolerance. However, when a controller module failure occurs in the control redundancy actuator, the input gain of the control surface of the redundancy actuator will become 0 under the traditional redundancy configuration architecture. At this time, the flight control level control law corresponding to the traditional redundancy configuration will become:

[0078]

[0079] Depend on Figure 5 Simulation results show that the aircraft's ball bearing command following performance deteriorates at this point, and the sideslip angle exhibits significant jitter. By employing the distributed cross-linking strategy of this invention, since the redundant actuator's redundant control module originates from different controllers, control can continue to be executed based on the backup channel of another controller. Therefore, even if the main channel controller module fails at 43 seconds, the flight control law can still be maintained. Continuing with the control, the simulation curves show that the fault tolerance effect is good.

[0080] As can be seen from the above embodiments, the general architecture and software design method for a distributed cross-linking actuation system for aircraft described in this invention have at least the following advantages compared with existing technical solutions:

[0081] 1. The distributed cross-linking actuation system general architecture in this invention, compared with the traditional redundant actuation system architecture, features a main control surface with redundant actuation configuration, an auxiliary control surface with traditional configuration, and a redundant controller that cross-links and controls different actuation channels. This architecture can reduce the impact of single-point failures with a higher power-to-weight ratio and higher reliability.

[0082] 2. The software flow algorithm in this invention has universality and interchangeability. Under a unified software architecture, it can control all actuators through intelligent identification and loading of corresponding module parameters, which facilitates software version management.

[0083] 3. By adding status monitoring based on intelligent distributed real-time dynamic virtual models and functional fault identification based on key electrical signals to the software process, real-time monitoring of the functional performance of the corresponding integrated actuation system is realized. It can achieve intelligent stress response and fault tolerance under extreme conditions, including controller chip failure, and at the same time, it adds technical implementation methods for improving the overall intelligence level of the aircraft.

[0084] The features described and / or illustrated above with respect to one embodiment may be used in the same or similar manner in one or more other embodiments, and / or in combination with or in lieu of features in other embodiments.

[0085] It should be emphasized that the term "including / comprises" as used herein refers to the presence of a feature, whole, step, or component, but does not exclude the presence or addition of one or more other features, wholes, steps, components, or combinations thereof.

[0086] The apparatus and methods described above can be implemented in hardware or in combination with software. This invention relates to computer-readable programs that, when executed by a logic component, enable that logic component to implement the apparatus or constituent parts described above, or to implement the various methods or steps described above. This invention also relates to storage media for storing the above programs, such as hard disks, magnetic disks, optical disks, DVDs, flash memory, etc.

[0087] Many features and advantages of these embodiments are apparent from this detailed description, and therefore the appended claims are intended to cover all such features and advantages of these embodiments that fall within their true spirit and scope. Furthermore, since many modifications and alterations will readily occur to those skilled in the art, the embodiments of the invention are not intended to be limited to the precise structures and operations illustrated and described, but rather to encompass all suitable modifications and equivalents falling within their scope.

[0088] The parts of this invention not described in detail are techniques known to those skilled in the art.

Claims

1. A general architecture and software design method for a distributed cross-linking actuation system for aircraft, characterized in that, The method includes: Based on the overall aerodynamic layout and servo actuation requirements of the aircraft, a distributed redundant controller and actuators for the actuation system are designed. Based on the power-to-weight ratio and reliability and safety constraints, the interconnection relationship of the redundant controller and the "single / dual" configuration relationship of the actuation links are designed. Based on the distributed layout and control requirements of the aircraft's actuation system, a general software architecture process with "master / backup" control modes and intelligent state decision-making is designed. The design incorporates a performance status monitoring algorithm based on a real-time dynamic virtual model and a channel switching algorithm based on key fault discrimination signals. The designed monitoring and switching algorithms are then integrated into the software architecture to achieve intelligent stress-tolerant reconfiguration of the integrated servo actuation system for different fault conditions.

2. The method according to claim 1, characterized in that, The method also includes: The effectiveness of the designed distributed redundant controller and actuator, as well as the designed general software architecture process, was verified through simulation.

3. The method according to claim 2, characterized in that, Based on the overall aerodynamic layout and servo actuation requirements of the aircraft, a distributed redundant controller and actuators for the actuation system are designed. Furthermore, based on power-to-weight ratio and reliability / safety constraints, the interconnection relationships of the redundant controller and the "single / dual" configuration relationships of the actuation components are designed, including: A1.1 Design a redundant controller with redundant drive control function. Each redundant controller has two MCU processors. Each MCU processor is used to control at least two actuation channels. The hardware of the redundant controllers adopts the same design. The interchangeability is ensured by software configuration. The MCU processors of different redundant controllers are designed to exchange redundancy information to realize the distributed layout of MCU processors. A1.2 At the aircraft level, if the flight control system has redundant configuration on the actuation surface, the actuator used for actuation will be configured in a "single redundancy" form; if the actuation surface has no redundancy, the actuator used for actuation will be configured in a "double redundancy" form.

4. The method according to claim 3, characterized in that, Based on the distributed layout and control requirements of aircraft actuation systems, the design process for a general software architecture with "master / backup" control modes and intelligent state decision-making includes: Each MCU processor in the redundancy controller controls two actuation channels, Channel-0 and Channel-1. After the MCU processor number is determined, the actuator redundancy type of the two actuation channels is determined according to the hardware connection relationship, and the main / standby redundancy control mode or the general control mode is determined according to the redundancy type. If the redundancy type is a single redundancy configuration, the system will enter the general control mode; if the redundancy type is a multi-redundancy configuration, the system will enter the primary / standby redundancy control mode. If the normal control mode is entered, no channel switching is performed. The main process control calculation is performed normally and the status is monitored through the distributed sub-model in the large model. If a fault is detected, the control calculation enters the single-channel fault-tolerant processing mode; otherwise, the control calculation continues to be performed normally. If the primary / backup redundancy control mode is entered, the primary / backup channel is further determined. The primary channel is the default controller, and the backup channel is the follower. If it is the primary channel, the main process control calculation is performed normally, and the status is monitored through the distributed sub-model in the large model. If a fault is detected, the control switches from the primary channel to the backup channel. Otherwise, the primary channel continues to perform the main process control calculation normally. If it is the backup channel, the follower channel control calculation is performed, and the status is monitored through the distributed sub-model in the large model. If a fault is detected and the primary / backup interaction information determines that the primary channel has recovered from the fault state, the control switches from the backup channel to the primary channel. Otherwise, the backup channel continues to perform the follower channel control calculation.

5. The method according to claim 4, characterized in that, Design a performance status monitoring algorithm based on a real-time dynamic virtual model and a channel switching algorithm based on key fault discrimination signals. Integrate the designed monitoring and switching algorithms into the software architecture to achieve intelligent stress-response and fault-tolerant reconfiguration of the integrated servo actuation system for different fault conditions, including: A3.

1. To determine whether the actuation system is functioning normally, a functional judgment based on periodic inspection signals is made: the comprehensive electrical signals are judged, and if a functional fault occurs, the protection processing mode is directly entered. If the actuation channel function fails completely, the channel switching fault-tolerant reconfiguration mechanism is triggered. A3.2 Real-time monitoring of the status of the actuation system based on the virtual model to determine whether the performance of the actuation system meets the index requirements: The sliding window data quantization processing algorithm of the intelligent distributed model is used to calculate the performance of the actuation system and determine whether the calculated performance of the actuation system is within the model interval. If it exceeds the model interval, the channel switching fault tolerance mechanism is triggered.