High-safety aircraft management system based on switched time-triggered Ethernet

By using switched time-triggered Ethernet, efficient and reliable information exchange between subsystems in the aircraft management system is achieved, solving the problems of increased sensor quantity and limitations on the independence of information exchange, and realizing system architecture optimization and deterministic information transmission.

CN121967450APending Publication Date: 2026-05-01XIAN FLIGHT SELF CONTROL INST OF AVIC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
XIAN FLIGHT SELF CONTROL INST OF AVIC
Filing Date
2025-12-24
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In modern aircraft management systems, the increased number of sensors and cables leads to increased system size and weight, analog signals are susceptible to electromagnetic interference, and the independence of information interaction between subsystems limits the comprehensive optimization of the system architecture.

Method used

It adopts a switched time-triggered Ethernet, which enables efficient and reliable information exchange between subsystems through a unified time-triggered Ethernet interface. It supports the transmission of three data types and uses a time-triggered Ethernet synchronization clock to ensure the determinism of information exchange.

Benefits of technology

It reduces the complexity of system interconnection, improves the convenience of information transmission, meets the control function requirements of different types of subsystems, avoids the risk of data error propagation, and reduces management costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967450A_ABST
    Figure CN121967450A_ABST
Patent Text Reader

Abstract

The invention belongs to an aircraft management system technology, and particularly relates to a high-safety aircraft management system based on a switched time-triggered Ethernet. Sensors, computers and execution mechanism equipment of all subsystems are efficiently interconnected through a network, so that the problems of excessive equipment redundancy, complex cable connection and low cooperative interaction efficiency existing in the design of a traditional aircraft management system are solved. According to the system, data sharing is enhanced, repeated deployment of equipment is reduced, openness is improved, non-safety key information dynamic expansion is supported, meanwhile, the safety level needed by an aircraft management system is not sacrificed, integration of the functions of main flight control, auxiliary flight control, thrust, undercarriage and front wheel steering under a unified network can be achieved, and the system is suitable for large-scale popularization and application. And a basis is provided for further comprehensive design of a future aircraft management system.
Need to check novelty before this filing date? Find Prior Art

Description

A high-security aircraft management system based on switched time-triggered Ethernet Technical Field

[0001] This invention pertains to aircraft management system technology, and particularly relates to a high-security aircraft management system based on switched time-triggered Ethernet. Background Technology

[0002] The aircraft management system covers all key aspects of aircraft operation, enabling the control and management of various devices related to aircraft operation (such as aerodynamic surfaces, engines, and landing gear), ensuring the safe, accurate, and efficient operation of the aircraft in various flight scenarios, and ultimately achieving the flight mission objectives. Aircraft management systems require the coordinated operation of numerous subsystems, typically including: 1) a primary flight control subsystem, which controls the aircraft's pitch, roll, and yaw attitudes by controlling the deflection of the primary aerodynamic surfaces (such as elevators, ailerons, and rudders); 2) an auxiliary flight control subsystem, which, during takeoff and landing, controls the movement of auxiliary aerodynamic surfaces (such as flaps and slats) to change the wing camber, thereby assisting the aircraft in adjusting lift or drag; 3) a thrust control subsystem, which controls the engine thrust by controlling the engine speed, and uses reverse thrust to decelerate the aircraft on the ground during landing; 4) a landing gear control subsystem, which controls the retraction and extension of the landing gear, and helps determine whether the aircraft is in the air or on the ground based on the landing gear load; and 5) a nose wheel steering control subsystem, which controls the angle of the nose landing gear wheels during taxiing to change the aircraft's direction of travel on the ground.

[0003] Modern aircraft management systems use electronic signals to replace mechanical connections (such as the control stick being directly connected to aerodynamic surfaces via steel cables or linkages) to control and manage operating devices, involving the integration and collaborative work of complex hardware and software.

[0004] The aircraft management system (AMS) is a critical system related to flight safety. Depending on the dynamic performance and safety level of the controlled target, the architecture, system composition, information interaction, and system operation of each subsystem within the AMS vary. Typically, each subsystem contains multiple redundant (backup) sensors, computers, actuators, and other equipment, connected via various buses and hardwired connections to meet data transmission requirements between devices.

[0005] Taking the main flight control subsystem as an example, a typical current aircraft management system is shown in the dashed box in Figure 1. Sensors include stick displacement sensors, aircraft status sensors (such as accelerometers and gyroscopes), actuator position sensors, and aerodynamic surface position sensors. The actuators include a remote electronic control unit (NEU) and actuators. During system operation, the mechanical movement of the control stick is converted into electrical signals, which are collected by the stick displacement sensors. The computer then generates control commands, which drive the actuators through the NEU, ultimately causing the aerodynamic surfaces to deflect. When generating control commands, the computer combines information such as the aircraft's angle of attack and attitude provided by the aircraft status sensors to correct the control commands. When driving the actuators, the NEU combines the actuator positions and aerodynamic surface deflections provided by the actuator position sensors and aerodynamic surface position sensors to achieve a closed-loop control effect.

[0006] Figure 1 shows a control stick, such as the control stick of the main flight control subsystem, equipped with two stick displacement sensors (first stick displacement sensor and second stick displacement sensor), which provide stick displacement information to the computer that calculates flight control commands. Based on the information received from the control stick and the aircraft status sensors, the computer determines the aerodynamic surface deflection control command. This command is transmitted and amplified into an analog electrical signal via a remote electronic control unit (ECU), driving the actuators to move and deflect the aerodynamic surfaces. The actuators and aerodynamic surfaces are equipped with actuator position sensors and aerodynamic surface position sensors, respectively, providing the ECU with the motion position or deflection angle of the actuators and control surfaces. The ECU monitors the status of the actuators and control surfaces, verifying whether the control commands are executed correctly.

[0007] When multiple control subsystems in an aircraft management system operate together, each subsystem has its own independent set of sensors, computers, actuators, and information interactions. For simplicity, Figure 2 schematically illustrates the architectural relationship between two control subsystems (first control subsystem and second control subsystem). Each control subsystem includes at least one dedicated computer (first computer and second computer) for processing signals received from one or more sensors (first sensor, second sensor, and third sensor) and transmitting commands to one or more actuators (first actuator and second actuator) via multiple cables. The control subsystems are connected by cables, such as an ADB bus. When the second computer needs to acquire sensor measurements from a sensing device belonging to the first control subsystem, the first computer, responsible for acquiring the sensor measurements, transmits the measurements to the second computer via the ADB bus. However, to meet availability constraints (such as in case of first computer failure) or latency constraints (longer transmission time between the first and second computers), the aircraft management system needs to deploy an additional identical second sensor on the sensing device and connect it directly (usually via hardwired) to the second computer.

[0008] The differences between the various subsystems of the aircraft management system are mainly due to the different information interaction modes and system operation modes of each subsystem. For example, when redundant computers or actuators need to meet the requirements of strong real-time operation, they still need to rely on additional redundancy synchronization links.

[0009] Current aircraft management systems, with the continuous expansion of subsystem functions and the increase in the number of sensors and related cables, have led to a sustained increase in aircraft size and weight. Furthermore, the analog signals used in sensor transmission are more susceptible to noise caused by electromagnetic interference. At the same time, the independent nature of information interaction between systems greatly limits the comprehensive design of the subsystem architecture. While each subsystem, defined by function, is undergoing gradual optimization, there is still room for comprehensive optimization at the system architecture level from the perspective of the overall aircraft management system. Summary of the Invention

[0010] Purpose of the invention: To propose a high-safety aircraft management system based on switched time-triggered Ethernet, so as to meet the coordinated operation of the control functions of the main aerodynamic surfaces, auxiliary aerodynamic surfaces, thrust, landing gear, nose wheel steering and other related subsystems of the aircraft management system under the same system architecture, and to ensure efficient and reliable information exchange of information at different safety levels through a unified time-triggered Ethernet interface.

[0011] Technical Solution: A high-safety aircraft management system based on switched time-triggered Ethernet includes: M computers, N sensors, K actuators, and a time-triggered Ethernet network. The actuators include remote electronic actuation units. M, N, and K are positive integers greater than or equal to 1. The M computers, N sensors, and K actuators are each independently mounted on the time-triggered Ethernet network as network end nodes. The time-triggered Ethernet network includes at least one level of switches. Each network end node is connected to a unique switch, and the switches at each level are optically interconnected.

[0012] Furthermore, when the distance between devices exchanging information is far, a multi-level switch cascading method is adopted. When cascading, the number of switches in each level must be the same, and adjacent switches in each level must be connected in a one-to-one correspondence.

[0013] Furthermore, the time-triggered Ethernet used should support the simultaneous transmission of three data types under the same physical network; the three data types are time-triggered data (TT), aviation full-duplex Ethernet data (RC), and ordinary Ethernet data (BE); the three data types are transmitted in different switching planes within the switch.

[0014] Furthermore, when using time-triggered Ethernet to transmit TT type data, transmission is performed according to the pre-configured device port requirements and time requirements of the virtual link; data that does not meet the requirements should be discarded. When using time-triggered Ethernet to transmit RC type data, transmission is performed on idle ports and during idle times for TT type data lines, and transmission is performed according to the pre-configured device port requirements and rate requirements of the virtual link. When using time-triggered Ethernet to transmit BE type data, transmission is performed on idle ports and during idle times for TT and RC type data lines. Dynamic configuration of ports and rates for BE type data based on idle ports and idle times for TT and RC type data lines is used to achieve "plug-and-play" information interaction for external devices in the system. When transmitting BE type data, traditional Ethernet transport layer and network layer protocols such as User Datagram Protocol (UDP) and Internet Protocol (IP) can be added.

[0015] Furthermore, the switching devices using time-triggered Ethernet should adopt a command COM / monitor MON pair design, that is, have independent command working channels and monitoring working channels. When the information exchange between the command working channel and the monitoring working channel is inconsistent, the silent switch forwards TT and RC type data, while maintaining the forwarding of BE type data.

[0016] Furthermore, the time-triggered Ethernet used will silence the transmission of TT type data for a device when it is detected that the time of a device in the network is inconsistent with the network synchronization clock, while maintaining the transmission of RC and BE type data.

[0017] Furthermore, the system adopts a time-triggered system operation mode. The local time of the computer, sensors, and actuators should be consistent with the time-triggered Ethernet synchronous clock. The system operation is scheduled through the time-triggered Ethernet synchronous clock signal.

[0018] Furthermore, the system adopts a time-triggered information interaction mode. The information interaction between system devices, namely the information sending time, forwarding time, and receiving time, are all based on the time-triggered Ethernet synchronization clock offset setting to ensure the determinism of information interaction. At the same time, it is compatible with non-time-triggered information interaction when time-triggered information interaction is idle.

[0019] Furthermore, when used for primary flight control, the switches in the system are connected to the control stick via redundant interface units; and to the corresponding control surface actuator position sensors, corresponding aerodynamic surface position sensors, and corresponding actuators via redundant remote electronic actuation units.

[0020] Furthermore, when data between different types of network endpoints is transmitted through multi-level switches, the data transmission path between adjacent level switches is as follows: first, data is transmitted between switches of the same level so that each switch can obtain data from each redundancy, and then cross-level transmission is achieved through a one-to-one correspondence between adjacent level switches.

[0021] Beneficial effects: Applying time-triggered Ethernet provides determinism for system operation and information interaction in the aircraft management system, realizes the unification of subsystem time bases, and reduces the complexity of cross-system function co-design in terms of timing.

[0022] By using switched time-triggered Ethernet, the complexity of system interconnection caused by the multiple information transmission methods and complex technologies of traditional aircraft management systems is reduced, and the convenience of transmitting local information to other devices in the system is improved.

[0023] By supporting the transmission of three types of data within the same physical network, it can simultaneously meet the differentiated needs of different types of subsystem control functions in terms of transmission timeliness, bandwidth load, and target flexibility. Through the proposed security measures for different types of data transmission, the reliability and accuracy of data behavior during network transmission are guaranteed, effectively avoiding the risk of local data errors spreading to the entire system in a unified data environment, and reducing the user's management costs for network data. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. The drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 schematically illustrates the current aircraft management system; Figure 2 schematically illustrates the subsystem connections of the current aircraft management system; Figure 3 schematically illustrates the aircraft management system of the present invention; Figure 4 schematically illustrates the connection between switches in the aircraft management system of the present invention; Figure 5 schematically illustrates the cascading of switches in the aircraft management system of the present invention; Figure 6 is the aircraft management system in Embodiment 1 of the present invention; Figure 7 is the aircraft management system in Embodiment 2 of the present invention; Figure 8 is the aircraft management system in Embodiment 3 of the present invention; Figure 9 is a schematic diagram of the aircraft management system of the present invention. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0027] The features and illustrative embodiments of various aspects of the present invention will now be described in detail. Numerous specific details are set forth in the following detailed description to provide a thorough understanding of the invention. However, it will be apparent to those skilled in the art that the invention may be practiced without requiring some of these specific details. The following description of embodiments is merely intended to provide a better understanding of the invention by illustrating examples of the invention. The invention is by no means limited to any specific setups and methods set forth below, but covers any improvements, substitutions, and modifications to structures, methods, and devices without departing from the spirit of the invention. Well-known structures and techniques are not shown in the drawings and the following description to avoid unnecessarily obscuring the invention.

[0028] In the description of this invention, it should be noted that the directions or positional relationships indicated by terms such as "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer" are based on the directions or positional relationships shown in the accompanying drawings and are only for the convenience of describing and simplifying the invention, and should not be construed as limiting the invention. Furthermore, the use of ordinal numbers (e.g., "first and second," etc.) is for distinguishing objects and is not limited to this order, and should not be construed as indicating or implying relative importance.

[0029] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly, encompassing both direct connection and indirect connection via an intermediate medium. Those skilled in the art can understand the specific meaning of these terms in this invention based on the specific circumstances.

[0030] It should be noted that, unless otherwise specified, the embodiments of the present invention and the features thereof can be combined with each other, and the various embodiments can be referenced and cited in each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0031] The present invention will be further described in detail below with reference to the embodiments and accompanying drawings, but the embodiments of the present invention are not limited thereto.

[0032] The purpose of this invention is to propose an aircraft management system that overcomes the above-mentioned shortcomings. Specifically, it is an aircraft management system that can reduce wiring between system devices such as sensors, computers, and actuators, reduce the number of sensors on the devices, meet the diverse information interaction needs across subsystems, and at the same time, without sacrificing the required level of safety.

[0033] Figure 3 is a schematic diagram of the aircraft management system of the present invention. The core of the present invention is to use switched time-triggered Ethernet to connect the devices such as the first computer, the second computer, the first sensor, the second sensor, the first actuator, and the second actuator in the various subsystems of the aircraft management system into a unified network, so as to meet the needs of information interaction between devices. At the same time, the time-triggered Ethernet uses its own synchronous clock to provide a unified time reference for the operation of the devices. Through time-triggered Ethernet, information interaction between devices is realized, and flexible transmission is achieved by using virtual links. According to the information interaction logic relationship (the figure shows the first computer sending to the first and second remote electronic actuation units at the same time), the switched time-triggered Ethernet controls the switches in the network to connect the virtual links between devices at specific time periods or when specific information interaction occurs, so as to build a real information interaction path. The typical features of the present invention are as follows: 1) Switched time-triggered Ethernet is used as the system communication medium, and information interaction between system devices is realized by virtual links in the form of "one sender and one receiver" or "one sender and multiple receivers".

[0034] 2) Time-triggered Ethernet includes switches and end devices connected to the switches (referring to devices in the system that are directly connected to the Internet). Switches are required to be interconnected in pairs, as shown in Figure 4 (taking an aircraft management system that includes 4 switches as an example). Optical connections are required between switches to reduce the noise impact caused by electromagnetic interference.

[0035] 3) The system adopts a time-triggered system operation mode. The local time of each subsystem or device in the system should be consistent with the time-triggered Ethernet synchronization clock. The system operation is scheduled by the time-triggered Ethernet synchronization clock signal, which eliminates the need for additional synchronization link design and ensures the determinism of system operation.

[0036] 4) The system adopts a time-triggered information interaction mode. Information interaction between system devices—namely, the time of information transmission, forwarding, and reception—is based on the time-triggered Ethernet synchronization clock offset setting, ensuring the determinism of information interaction. Simultaneously, it is compatible with non-time-triggered information interaction during idle periods of time-triggered information interaction.

[0037] 5) Based on the actual system deployment and installation location, system devices are connected to the nearest switch to simplify the interactive information transmission process. The switch forwards the information, improving the reachability of interactive information within the system. For sensor devices, the collected information is connected to the nearest time-triggered Ethernet network, allowing multiple subsystems to share the data simultaneously without requiring additional sensors or connecting cables. For actuation devices, the collected location information used for monitoring is connected to the nearest time-triggered Ethernet network, enabling the simultaneous reporting of monitoring information to multiple target devices.

[0038] 6) Depending on the actual system deployment and installation location, when the distance between information interaction devices is far, a switch cascading method can be used. When cascading, the number of switches at each level should be the same, and the switches between levels should be connected by only one cable, as shown in the cascading cable in Figure 5. This further reduces cable weight, reduces signal attenuation over long distances, and allows devices to access the Internet nearby in the deployment and installation area.

[0039] 7) The time-triggered Ethernet used should support simultaneous transmission, i.e., sending, forwarding and receiving, of three data types under the same physical network: TT (time-triggered data), RC (aviation full-duplex Ethernet AFDX data), and BE (normal Ethernet data). The three data types use different switching planes and the transmission functions are physically isolated.

[0040] 8) When using time-triggered Ethernet to transmit TT type data, the transmission shall be carried out according to the pre-configured device port requirements and time requirements of the virtual link. Data that does not meet the requirements shall be discarded.

[0041] 9) When using time-triggered Ethernet to transmit RC type data, the TT type data line is transmitted on idle ports and during idle time, and the transmission is carried out according to the virtual link pre-configured device port requirements and rate requirements.

[0042] 10) When using time-triggered Ethernet to transmit BE type data, the TT and RC type data lines are transmitted on idle ports and during idle time. No pre-configuration is required. It supports "plug and play" information interaction with external devices and can be expanded to include traditional Ethernet transport layer and network layer protocols such as UDP (User Datagram Protocol) and IP (Internet Protocol).

[0043] 11) The switching equipment using time-triggered Ethernet should adopt a command / monitor (COM / MON) pair design, that is, it has independent command working channels and monitoring working channels. When the information exchange between the command working channel and the monitoring working channel is inconsistent, the TT and RC type data of the silent switch is forwarded, while the forwarding of BE type data is maintained.

[0044] 12) When using time-triggered Ethernet, if the time of a device in the network is inconsistent with the network's synchronous clock, the device should be isolated from the network, the transmission of TT type data of the device should be silenced, and the transmission of RC and BE type data should be maintained.

[0045] Example 1: Main Flight Control (Elevator) Subsystem This example uses a quadruple redundancy system to introduce a main flight control subsystem and the implementation of elevator control in the main flight control function within the subsystem.

[0046] The system of Embodiment 1 is shown in Figure 6. Typically, the aircraft equipment bay is located in the front middle of the fuselage, which is far from the elevator. This embodiment uses time-triggered Ethernet in the form of cascaded switches.

[0047] Based on the principle of connecting system devices to the nearest switch, the interface unit directly receives the electrical signals generated by the stick sensor, converts the information into network data packets, and enables the collected information to access the internet from the nearest switch. According to redundancy allocation, each interface unit only needs to connect to one stick sensor. Other devices, such as the main flight control computer and the elevator remote electronic actuation unit, are also connected to the nearest switch; for example, the first main flight control computer connects to the first switch, and the first elevator remote electronic actuation unit connects to the fifth switch, thus achieving the connection of the core digital information acquisition, command calculation, and motion monitoring components.

[0048] The number of elevator actuators is determined based on the actual system safety level, typically ranging from 2 to 4 units. This embodiment will not delve into this detail; instead, it will only use the elevator actuator connected to the remote electronic actuation unit of the elevator as an example to illustrate the connection relationship of the actuators. The position sensors of the elevator actuators and the elevator aerodynamic surfaces are connected to the first remote electronic actuation unit of the elevator, converting the collected electrical signals into network data packets. The collected information is then accessed via the fifth switch, allowing for local internet access.

[0049] When the pilot manipulates the control stick, the stick's movement causes four sensors deployed on it to generate corresponding electrical signals. These signals are collected by four interface units, and according to the virtual link configuration, data transmission is achieved in a "one-to-many" manner. That is, the data packet generated by the first interface unit is simultaneously received by the first, second, third, and fourth main flight control computers. Taking the first main flight control computer as an example, it will receive a total of four data packets from different interface units. Based on the calculations of the collected information, the main flight control computer generates a command data packet containing elevator control instructions and sends it to the elevator remote electronic actuation unit. Similar to the data packet collection, the first elevator remote electronic actuation unit receives four command data packets from different main flight control computers. After comparing the instructions in the four command data packets, the first elevator remote electronic actuation unit sends the matching elevator control command to the elevator actuator.

[0050] After receiving the elevator control command and executing the movement, the elevator actuator position sensor and the elevator aerodynamic surface position sensor sense the corresponding movement, generate electrical signals, which are then collected by the first elevator remote electronic actuation unit. After generating a monitoring data packet, the data packet is sent to the first, second, third, and fourth main flight control computers to achieve effective monitoring of the command execution results.

[0051] The main flight control is a high-safety control function; therefore, TT type data is used for transmission between devices. When data is transmitted between redundancies, forwarding is achieved through port connections between switches. Data forwarding between switches, like sending and receiving acquisition information data packets, command data packets, and monitoring data packets, is pre-configured. For example, acquisition information data packets generated by the interface unit are transmitted to the first elevator remote electronic actuation unit via the path "second switch - first switch - fifth switch." Simultaneously, the path "second switch - sixth switch - fifth switch" serves as a backup transmission path used when the aforementioned paths fail.

[0052] Example 2: Thrust Control Subsystem This example, based on Example 1, describes how to integrate the thrust control subsystem with the main flight control subsystem.

[0053] The system of Embodiment 2 is shown in Figure 7. Typically, the aircraft equipment bay is located in the front middle of the fuselage, close to the engine. Therefore, this embodiment does not require the use of time-triggered Ethernet in the form of cascaded switches.

[0054] When the thrust control subsystem described in Embodiment 2 belongs to the same aircraft management system as the main flight control subsystem of Embodiment 1, the included interface units and switch devices can be reused across subsystems by means of a time-triggered network. Embodiment 2 shares the first, second, third, and fourth interface units in Embodiment 1 for information acquisition, and the first, second, third, and fourth switches for information transmission.

[0055] The first and second interface units collect the left throttle lever electrical signal, while the third and fourth interface units collect the right throttle lever electrical signal. Without increasing the number of sensors, through data sharing between switches, each engine control unit obtains a total of 4 left throttle lever signal acquisition values ​​and 4 right throttle lever signal acquisition values. Taking the first interface unit as an example, the information acquisition data packet it generates is sent together with two left throttle lever acquisition values ​​acquired directly by the unit itself and acquired by the second interface unit through the "second interface unit - second switch - first switch - first interface unit" information transmission path. Similarly, the second interface unit also sends 2 left throttle lever acquisition values, resulting in a total of 4 left throttle lever signal acquisition values ​​for each engine control unit.

[0056] Because the thrust control of the aircraft is implemented using an independent engine unit, unlike the main flight control function, the information collected by the interface unit can be directly forwarded to the first, second, third, and fourth engine control units via a switch. Simultaneously, in the advanced functions of the main flight control, if a corresponding throttle signal is required as input, the signal can be synchronously sent to the main flight control computer (refer to the system in Embodiment 1). Ultimately, the left engine obtains two command data packets by connecting to the first and second engine control units, achieving dual-redundancy engine control; the same applies to the right engine.

[0057] Thrust control is a high-safety control function, but because the rate of change of engine thrust is relatively low, the requirements for dynamic performance of the control are not high. Therefore, RC type data transmission between devices is sufficient to meet the control requirements. Typically, engine control is deployed integrated with the engine, so there is no need for additional sensors to sense the engine's operating status. The acquisition and monitoring of command execution results can be directly implemented at the nearest engine control unit.

[0058] Example 3: Front Wheel Turning Control Subsystem This example, based on Example 1, describes how to integrate the front wheel turning control subsystem with the main flight control subsystem.

[0059] The system of Embodiment 3 is shown in Figure 8. Typically, the aircraft equipment bay is located in the front middle of the fuselage, close to the nose wheel. Therefore, this embodiment does not require the use of time-triggered Ethernet in the form of cascaded switches.

[0060] When the front wheel turning control subsystem described in Embodiment 3 belongs to the same aircraft management system as the main flight control subsystem of Embodiment 1, the included interface units and switch devices can be reused across subsystems through the time-triggered network. Embodiment 3 shares the first, second, third, and fourth interface units in Embodiment 1 for information acquisition, and the first, second, third, and fourth switches for information transmission, and the first, second, third, and fourth main flight control computers for control command calculation.

[0061] The front wheel steering control generates electrical signals via the steering handle, which are then collected by the first and third interface units and transmitted through the first, second, third, and fourth switches (the transmission path is the same as in Embodiment 2). This generates four sets of steering handle signal acquisition values, which are then sent to the first, second, third, and fourth main flight control computers, respectively. In this embodiment, the command calculation for front wheel steering control is also deployed in the main flight control computer. The front wheel steering control unit transmits and amplifies the command signals, ultimately driving the front wheel steering motion.

[0062] Because the safety level of front wheel steering control is lower than that of the main aerodynamic surfaces and thrust control, a dual-redundant front wheel steering control unit is sufficient to meet safety requirements. The first and second front wheel steering control units each receive four instruction data packets containing front wheel steering control commands. After comparing the commands, the matching commands are sent to the front wheels. The front wheel steering employs an open-loop control strategy, allowing the pilot to directly determine the steering handle input requirements based on changes in the aircraft's direction of flight. The execution results of the front wheel control commands do not require computer monitoring.

[0063] Front wheel steering control is a high-safety control function. To ensure consistency between data acquisition and calculation, the information acquisition data packets use TT type data transmission. The control and monitoring of the front wheels are relatively stable in ground operation, and the command data packets use RC type data transmission.

[0064] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A high-security aircraft management system based on switched time-triggered Ethernet, characterized in that, include: The system consists of M computers, N sensors, K actuators, and a time-triggered Ethernet network. The actuators include remote electronic actuation units. M, N, and K are positive integers greater than or equal to 1. Each of the M computers, N sensors, and K actuators is independently mounted on the time-triggered Ethernet network as a network end node. The time-triggered Ethernet network contains at least one level of switches, and each network end node is connected to a unique switch. The switches at each level are optically interconnected with each other.

2. The system according to claim 1, characterized in that, When the devices exchanging information are far apart, a multi-level switch cascading method is used. When cascading, the number of switches in each level must be the same, and adjacent switches must be connected one-to-one.

3. The system according to claim 2, characterized in that, The time-triggered Ethernet used should support the simultaneous transmission of three data types under the same physical network; the three data types are time-triggered data (TT), aviation full-duplex Ethernet data (RC), and ordinary Ethernet data (BE); the three data types are transmitted in different switching planes within the switch.

4. The system according to claim 3, characterized in that, When using time-triggered Ethernet to transmit TT type data, transmission is performed according to the pre-configured device port requirements and time requirements of the virtual link; data that does not meet the requirements should be discarded. When using time-triggered Ethernet to transmit RC type data, transmission is performed on idle ports and during idle time for TT type data lines, and transmission is performed according to the pre-configured device port requirements and rate requirements of the virtual link. When using time-triggered Ethernet to transmit BE type data, transmission is performed on idle ports and during idle time for TT and RC type data lines. Dynamic configuration of ports and rates for BE type data based on idle ports and idle time for TT and RC type data lines is used to achieve "plug-and-play" information interaction for external devices. When transmitting BE type data, traditional Ethernet transport layer and network layer protocols such as User Datagram Protocol (UDP) and Internet Protocol (IP) can be added.

5. The system according to claim 4, characterized in that, The switching equipment using time-triggered Ethernet should adopt a command COM / monitor MON pair design, that is, it has independent command working channels and monitoring working channels. When the information exchange between the command working channel and the monitoring working channel is inconsistent, the switch should silently forward TT and RC type data, and maintain the forwarding of BE type data.

6. The system according to claim 5, characterized in that, The time-triggered Ethernet used will silence the transmission of TT type data for a device when it is detected that the time of the device in the network is inconsistent with the network synchronization clock, while maintaining the transmission of RC and BE type data.

7. The system according to claim 6, characterized in that, The system adopts a time-triggered system operation mode. The local time of the computer, sensors, and actuators should be consistent with the time-triggered Ethernet synchronous clock. The system operation is scheduled through the time-triggered Ethernet synchronous clock signal.

8. The system according to claim 7, characterized in that, The system adopts a time-triggered information interaction mode. The information interaction between system devices, namely the information sending time, forwarding time, and receiving time, are all based on the time-triggered Ethernet synchronization clock offset setting to ensure the determinism of information interaction. At the same time, it is compatible with non-time-triggered information interaction when time-triggered information interaction is idle.

9. The system according to claim 8, characterized in that, When used for primary flight control, the switches in the system are connected to the control stick via redundant interface units; and to the corresponding control surface actuator position sensors, corresponding aerodynamic surface position sensors, and corresponding actuators via redundant remote electronic actuation units.

10. The system according to claim 9, characterized in that, When data between different types of network endpoints is transmitted through multi-level switches, the data transmission path between adjacent level switches is as follows: first, data is transmitted between switches of the same level so that each switch can obtain data from each redundancy, and then cross-level transmission is achieved through a one-to-one correspondence between adjacent level switches.