A method and system for safety testing of the three electrical components (battery, motor, and electronic control system) of manned aircraft.

Through a hierarchical architecture of distributed sensor networks and a central safety controller, cross-system collaborative monitoring and protection of the three electrical systems of manned aircraft are realized, solving the problems of information silos and diagnostic lag, and improving the accuracy of fault diagnosis and system safety.

CN122131803APending Publication Date: 2026-06-02JIANGXI MAIDE ELECTROMECHANICAL PARTS CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
JIANGXI MAIDE ELECTROMECHANICAL PARTS CO LTD
Filing Date
2026-03-10
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

The three-electric systems (battery system, motor system and electronic control system) of manned aircraft suffer from problems such as information silos, diagnostic lag and rigid response in fault diagnosis and response, making it difficult to achieve cross-system collaborative monitoring and protection, and failing to meet aviation-grade safety requirements.

Method used

By adopting a layered architecture of distributed sensor network, edge computing nodes and central security controller, it realizes multi-dimensional real-time parameter acquisition, edge processing, cross-system association rule base analysis and collaborative response strategies, forming a whole-process proactive security protection from decentralized perception to centralized intelligent decision-making.

Benefits of technology

It significantly improves the accuracy and timeliness of fault diagnosis, ensures that the overall operating status of the aircraft is controllable when dealing with local faults, provides real-time, proactive and collaborative safety protection, and meets the high safety requirements of manned aircraft.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122131803A_ABST
    Figure CN122131803A_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for safety detection of the three key electrical components (battery, motor, and electronic control system) of manned aircraft, belonging to the field of aircraft safety control technology. The method collects multi-dimensional real-time operating parameters of the battery, motor, and electronic control system through a distributed sensor network; edge computing nodes perform local feature extraction and preliminary fault diagnosis; a central safety controller performs joint logic analysis based on a cross-system rule base and a system health state machine to generate a safety situation assessment report; and a hierarchical fault processor triggers a graded collaborative response based on the report. The corresponding system includes the components that execute the above steps. This invention achieves end-to-end collaborative proactive safety protection from perception and diagnosis to response, solving the problems of information silos, delayed diagnosis, and rigid response.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of aircraft safety control technology, specifically to a method and system for detecting the three electrical components (battery, motor, and electronic control system) of manned aircraft. Background Technology

[0002] With the rapid development of urban air mobility (UAM), the safety of manned electric aircraft has become a core prerequisite and key challenge for their commercial operation. As the power core of the aircraft, the safety and reliability of the battery system, motor system, and electronic control system (collectively referred to as the "three-electric system") directly determine the overall flight safety and mission success rate.

[0003] Currently, the industry largely follows the technological path of electric vehicle field in the safety monitoring of the three-electric systems, which is gradually revealing the following significant limitations in aviation application scenarios: First, at the system architecture level, the Battery Management System (BMS), Motor Controller (MCU), and Flight Controller (VCU), which are the core control units of the three-electric system (battery, motor, and electronic control), typically operate as independent closed-loop systems. The lack of deep information interaction and coordination mechanisms between these controllers creates "control islands," preventing effective data fusion and joint analysis between the battery, motor, and electronic control systems they manage. Furthermore, the Flight Control System, which is the core of the aircraft's attitude and trajectory control, also lacks sufficient state interaction and coordination capabilities with the aforementioned three-electric systems. This makes it difficult for the entire aircraft to form a unified system-level response strategy when facing complex faults involving power, energy, and control. This fragmented state makes it difficult for the system to identify complex faults caused by the coupling of multiple systems from a holistic perspective.

[0004] Secondly, at the fault diagnosis level, most existing solutions rely on simple alarm logic where each controller sets a fixed threshold for a single parameter within its system. This diagnostic approach, isolated within the battery system, motor system, or electronic control system, lacks the ability to diagnose complex, time-varying fault modes that propagate across systems. It often reacts slowly and is prone to false alarms or missed alarms, making it difficult to meet the stringent requirements of aviation-grade safety for early warning and accurate fault location.

[0005] Finally, at the safety response level, existing fault handling strategies are often isolated and rigid responses from each controller based on its own local perspective. They typically execute pre-set, simple actions for localized faults in the battery, motor, or electronic control systems they manage, failing to systematically balance overall aircraft safety and flight mission continuity. For example, when a localized overheating occurs in the battery system, the BMS might only disconnect the main relay. While this isolates the fault, it could lead to a momentary failure of the aircraft's power system, causing serious secondary safety risks during flight. This highlights the lack of coordination between the battery, motor, and electronic control systems in existing solutions under complex fault scenarios, failing to achieve a tiered, adaptive handling capability that balances fault suppression and overall aircraft functionality.

[0006] Therefore, in order to meet the future development needs of highly safe and reliable manned electric aircraft, it is urgent to break through the traditional passive and fragmented monitoring paradigm centered on independent controllers, and build an integrated safety monitoring and management system that can realize real-time data exchange, intelligent joint diagnosis and active collaborative protection among battery system, motor system and electronic control system. Summary of the Invention

[0007] To overcome the shortcomings of existing technologies, this invention provides a method and system for detecting the three electrical components (battery, motor, and electronic control system) of manned aircraft, realizing proactive safety protection throughout the entire process from decentralized perception to centralized intelligent decision-making and unified collaborative execution.

[0008] To achieve the above objectives, the technical solution adopted by the present invention is as follows: On the one hand, a method for safety testing of the three electrical components (battery, motor, and electronic control system) of a manned aircraft is provided, including: S1. Collect multiple real-time operating parameters of the aircraft's battery system, motor system, and electronic control system through a distributed sensor network; S2. By deploying corresponding edge computing nodes near the battery system, motor system and electronic control system, localize the multi-dimensional real-time operating parameters to obtain local characteristic parameters, and perform threshold-based primary fault judgment. S3. Through the central security controller, receive and synchronize data from each edge computing node, which includes local feature parameters and primary fault judgment results, and perform joint logical analysis based on the pre-set cross-system association rule base and system health state machine; S4. Based on the results of the joint logic analysis, generate a security situation assessment report. The report should include at least the overall risk level, the primary suspected fault location, related impact information, and recommended handling priorities. S5. Through the hierarchical fault processor, based on the global risk level in the security situation assessment report, the pre-stored collaborative response strategy library is indexed, and the corresponding collaborative response instruction set is triggered and executed.

[0009] Furthermore, in S2, localization processing includes localized feature extraction, specifically including: Statistical calculations are performed on the single-cell voltage data from the battery system to obtain voltage consistency parameters characterizing cell consistency; Differential calculations are performed on temperature sensor data from the battery system to obtain the rate of temperature change characterizing the trend of thermal change. The vibration sensor signal from the motor system is transformed in the time-frequency domain to extract the characteristic frequency amplitude related to the mechanical state; Spectral analysis is performed on the three-phase current signals from the motor system to calculate the total harmonic distortion rate, which characterizes the power quality.

[0010] Furthermore, in S2, a threshold-based preliminary fault determination is performed, specifically including: The voltage consistency parameter is compared with a first preset threshold. If it exceeds the threshold, it is determined that the battery voltage is unbalanced. The rate of temperature change is compared with a second preset threshold. If the rate of change exceeds the threshold, the battery temperature rise is deemed abnormal. The characteristic frequency amplitude is compared with a dynamic baseline established based on historical data. If there is a significant deviation, it is judged that the mechanical condition of the motor is abnormal. The total harmonic distortion rate is compared with the third preset threshold. If it exceeds the threshold, the motor's electrical performance is judged to be abnormal. The control commands from the electronic control system are compared with the corresponding actual feedback signals for logical consistency. If a conflict occurs, it is determined that the control system logic is abnormal.

[0011] Furthermore, in S3, joint logic analysis specifically includes: Maintain a cross-system association rule base containing multiple production rules. The premise of each rule is a combination of conditions consisting of state parameters or events from at least two different subsystems in the battery system, motor system, and electronic control system. The conclusion includes the fault hypothesis, confidence level, and primary risk level. Maintain a system health state machine that describes the overall health status of the battery system, motor system, and electronic control system; The time-synchronized multi-dimensional real-time operating parameters, local feature parameters, and primary fault judgment results are used as inputs, and dynamic matching and confidence fusion are performed with the cross-system association rule base. Among them, dynamic matching supports dynamically adjusting the judgment threshold of the state parameters referenced in the rule premise based on the system operation baseline; Confidence fusion allows multiple rules to be partially activated and merges the confidence of the conclusions, contributing together to the final judgment; Based on the results of dynamic matching and confidence fusion, the state transition of the state machine is driven to generate a comprehensive diagnostic conclusion.

[0012] Furthermore, joint logic analysis also includes temporal correlation analysis: The cross-system association rule base contains causal inference rules with pre-defined expected time intervals; When the first abnormal event is identified through joint logic analysis, based on the causal inference rule, the second abnormal event with a preset causal relationship with the first abnormal event and the expected time interval between the two are determined, and a time series monitoring window is started based on the expected time interval. Within the timing monitoring window, monitor for the occurrence of a second abnormal event; If the second abnormal event occurs within the timing monitoring window, the causal relationship between the first and second abnormal events is confirmed.

[0013] Furthermore, confirming the establishment of a causal relationship specifically involves: Generate or update a causal relationship record that represents how the first anomalous event led to the second anomalous event; In joint logic analysis, increase the confidence weight of the corresponding causal inference rules; The driving state machine transitions to a fault state that represents a causal relationship.

[0014] Furthermore, in S5, the collaborative response strategy library is defined based on the global risk level and includes at least: The strategy corresponding to the global risk level of early warning is to send graphic and textual early warning information to the cockpit displays of the aircraft and / or ground monitoring stations; The strategy corresponding to the global risk level of minor failure is as follows: based on the primary suspected failure location identified in the safety situation assessment report, automatically reduce or limit the performance output limit of the subsystem to which the failure location belongs, and provide maintenance guidance through the aircraft's human-machine interface. For a global risk level of severe failure, the strategy is to automatically execute a sequence of instructions containing at least two of the following operations: isolate the source of failure, adjust the operating parameters of adjacent subsystems to compensate for functional loss, and trigger the flight control system to enter a predefined emergency landing mode.

[0015] Furthermore, the method also includes: S6. Through an independent security data black box, the various real-time operating parameters, local characteristic parameters, primary fault judgment results, security situation assessment reports and collaborative response instruction sets generated throughout the entire process from S1 to S5 are encrypted and persistently stored.

[0016] On the other hand, a system for implementing the above method is also provided, comprising: Distributed sensor networks are deployed in the aircraft's battery system, motor system, and electronic control system to collect multiple real-time operating parameters of the aircraft's battery system, motor system, and electronic control system. Multiple edge computing nodes are connected to the sensor networks of the battery system, motor system and electronic control system respectively, to perform localized processing of multiple real-time operating parameters to obtain local characteristic parameters and perform threshold-based primary fault judgment. The central security controller communicates with all edge computing nodes to receive and synchronize data from each edge computing node, including local characteristic parameters and preliminary fault judgment results. Based on a pre-built cross-system association rule base and system health state machine, it performs joint logic analysis and generates a security situation assessment report based on the joint logic analysis results. The hierarchical fault processor, connected to the central security controller, is used to index the pre-stored collaborative response strategy library based on the global risk level in the security situation assessment report, and trigger and execute the corresponding collaborative response instruction set.

[0017] Furthermore, distributed sensor networks include: The battery sensing unit, located within the battery system, includes a voltage sensor for measuring the voltage of the cell or module, a first temperature sensor for measuring the battery temperature, a total current sensor for measuring the total current, and an insulation resistance detection module for detecting the insulation status. The motor sensing unit, installed on the motor system, includes a second temperature sensor for measuring motor temperature, a position sensor for measuring rotor position and speed, a three-phase current sensor for measuring drive current, and a vibration sensor for detecting mechanical vibration. The electronic control sensing unit, integrated within the electronic control system, includes a third temperature sensor for monitoring the internal temperature of the controller, a DC bus voltage sensor for monitoring the power supply voltage, and a hardware watchdog circuit for monitoring the controller's operating logic. Edge computing nodes include: The battery management node is used to perform differential calculations on temperature sensor data from the battery system to obtain the temperature change rate characterizing the thermal change trend; and to perform statistical calculations on the cell voltage data from the battery system to obtain voltage consistency parameters characterizing cell consistency. The motor control node integrates a digital signal processor to perform time-frequency domain transformation on vibration sensor signals from the motor system to extract characteristic frequency amplitudes, and to perform spectral analysis on the three-phase current signals from the motor system to calculate the total harmonic distortion rate. The master control node communicates with the flight controller to obtain control commands. It is used to perform logical consistency verification between the obtained control commands and the corresponding actual feedback signals, and generates a judgment result of the control system logic anomaly when a logical conflict is detected. The hierarchical fault processor has pre-stored collaborative response programs corresponding to different global risk levels. The collaborative response programs can be triggered by the safety situation assessment report output by the central safety controller and execute a collaborative response instruction set, which includes collaborative control instructions issued to at least two of the battery management system, motor controller and flight controller. It also includes a security data black box, which is connected to the distributed sensor network, edge computing nodes, central security controller and hierarchical fault processor to encrypt and persistently store the generated multi-dimensional real-time operating parameters, local characteristic parameters, primary fault judgment results, security situation assessment reports and collaborative response instruction sets.

[0018] Compared with the prior art, the present invention has the following beneficial effects: 1. In existing technologies, the Battery Management System (BMS), Motor Controller (MCU), and Flight Controller (VCU) operate independently with isolated data. This invention utilizes a Central Safety Controller (CSC) running a joint logic analysis engine to synchronize and contextualize data from the battery, motor, and electronic control systems. It then performs comprehensive analysis based on a cross-system association rule base and a system health state machine. This enables the system to identify complex, cascading fault modes that cannot be detected by a single system (e.g., "rapid battery temperature rise and low motor load" indicating abnormal internal battery overheating). This represents a fundamental shift from isolated threshold alarms to contextualized intelligent diagnosis, significantly improving the accuracy, timeliness, and reliability of fault diagnosis.

[0019] 2. Existing fault responses are often localized, rigid, and reactive, potentially leading to secondary risks (such as power loss due to only disconnecting the main relay when the battery overheats). This invention, through a hierarchical fault processor, triggers pre-stored, standardized hierarchical collaborative response strategies based on the risk level in the safety situation assessment report. For different levels (early warning, minor, severe), the system can automatically execute an integrated collaborative command sequence from information reporting and power coordination to fault isolation, system reconfiguration, and even emergency landing. This ensures that the overall operational status of the aircraft remains controllable when handling localized faults, achieving fault tolerance and functional maintenance while ensuring the highest safety level.

[0020] 3. This invention innovatively adopts a hierarchical system of "edge perception - central intelligence - collaborative execution". Edge computing nodes perform millisecond-level local preprocessing and preliminary diagnosis, significantly reducing the central burden and improving response speed; the central safety controller focuses on multi-source information fusion and intelligent decision-making; and the hierarchical fault processors are responsible for precise execution. This architecture not only solves the pain point of lagging diagnosis in existing solutions, but also achieves encrypted recording of end-to-end data through a safety data black box, providing a complete and reliable data foundation for accident tracing and system optimization. The entire system achieves real-time, proactive, and collaborative protection of the safety status of the three-electric systems of manned aircraft, providing crucial safety assurance for the commercial application of manned urban air mobility (UAM) aircraft. Attached Figure Description

[0021] Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation

[0022] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0023] In the description of this invention, it should be noted that the terms "first," "second," "third," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0024] like Figure 1 As shown, the present invention provides a method for safety testing of the three electrical components (battery, motor, and electronic control system) of a manned aircraft, comprising: S1. Collect multiple real-time operating parameters of the aircraft's battery system, motor system, and electronic control system through a distributed sensor network; S2. By deploying corresponding edge computing nodes near the battery system, motor system and electronic control system, localize the multi-dimensional real-time operating parameters to obtain local characteristic parameters, and perform threshold-based primary fault judgment. S3. Through the central security controller, receive and synchronize data from each edge computing node, which includes local feature parameters and primary fault judgment results, and perform joint logical analysis based on the pre-set cross-system association rule base and system health state machine; S4. Based on the results of the joint logic analysis, generate a security situation assessment report. The report should include at least the risk level, the primary suspected fault location, related impact information, and recommended handling priorities. S5. Through the hierarchical fault processor, based on the risk level in the security situation assessment report, the pre-stored collaborative response strategy library is indexed, and the corresponding collaborative response instruction set is triggered and executed.

[0025] The method of this invention achieves a proactive safety closed loop through a layered architecture of "edge perception - central intelligence - collaborative execution". First, a distributed sensor network comprehensively collects multi-dimensional real-time operating parameters of the battery, motor, and electronic control systems. Second, edge computing nodes deployed near the subsystems of the battery, motor, and electronic control systems perform localized feature extraction and rapid primary fault diagnosis. Third, the central safety controller integrates multi-source data, performs joint logical analysis based on a cross-system association rule base and a system health state machine, and generates a safety situation assessment report including risk level and fault location. Finally, the layered fault processor automatically triggers a graded collaborative response from early warning and power coordination to fault isolation and emergency landing based on the risk level in the report. This method achieves end-to-end protection from decentralized monitoring to intelligent diagnosis and systematic collaborative protection, effectively solving the problems of information silos, delayed diagnosis, and rigid response in traditional solutions.

[0026] The present invention, S1, involves using a high-density distributed sensor network deployed across key components of the battery system, motor system, and electronic control system to synchronously collect all specific data constituting multiple real-time operating parameters based on a unified time base. In specific implementation, the multiple real-time operating parameters include: individual cell voltage data, temperature sensor data, total current, and insulation resistance data from the battery system; temperature sensor data, position sensor data, three-phase current signals, and vibration sensor signals from the motor system; and temperature sensor data, DC bus voltage data, logic status signals, and control commands issued by the electronic control system. All collected data is converted into a standardized format with timestamps.

[0027] In this invention, S2 involves localizing the received multivariate real-time operating parameters. This processing specifically involves localized feature extraction followed by threshold-based primary fault assessment. The specific implementation of the calculation and assessment process subsystem is as follows: Localized feature extraction for the battery system includes acquiring voltage consistency parameters and temperature change rates. More specifically, voltage samples from all cells are statistically analyzed over a fixed time window (e.g., 100ms), and their standard deviation is calculated in real-time as the voltage consistency parameter. This parameter is continuously compared to a first preset threshold dynamically adjusted based on battery state of charge, temperature, and health status. When this parameter exceeds this dynamic threshold for several consecutive cycles, a primary fault judgment result labeled "battery voltage imbalance" is generated. Simultaneously, the slope of temperature change for any cell within a short time window (e.g., 1 second) is monitored in real-time and used as the temperature change rate parameter. This rate parameter is compared to a second preset threshold dynamically adjusted based on the current load current and heatsink operating status. When the temperature rise slope at a certain point exceeds this dynamic threshold, a local early warning message (i.e., a primary fault judgment result) containing the specific module location and the "abnormal battery temperature rise" type is generated.

[0028] Localized feature extraction for the motor system includes acquiring characteristic frequency amplitudes and total harmonic distortion (THD). More specifically, the vibration sensor signals of the motor system undergo time-frequency domain transformation (e.g., Fast Fourier Transform (FFT)) to extract characteristic frequency amplitudes related to the condition of mechanical components such as bearings. These amplitudes are compared to a dynamic baseline established based on historical health data; if a significant and persistent deviation occurs, it is determined as "abnormal motor mechanical condition." Simultaneously, spectral analysis is performed on the three-phase current signals of the motor system to calculate the THD. This THD is compared to a third preset threshold; if it exceeds this threshold, it is determined as "abnormal motor electrical performance."

[0029] In addition, it includes performing logic verification of the electronic control system: continuously comparing control commands (such as throttle commands) from the flight controller with corresponding actual feedback signals (such as actual motor speed and bus current), and performing logic consistency verification based on the basic physical relationship model of the motor. If a logical conflict that violates the above basic physical relationship, such as "high throttle command, low speed, high current", is detected, it is immediately judged as "control system logic abnormality", and a corresponding primary fault identifier is generated.

[0030] The present invention S3 is executed through a central security controller. Its core is to run a set of joint logic analysis engines to achieve the leap from multi-source information fusion to intelligent diagnosis.

[0031] First, the controller receives data uploaded from each edge computing node via a highly reliable communication bus (such as CAN 2.0). This data is the information generated by S2, containing local characteristic parameters and preliminary fault diagnosis results. Then, a high-precision time synchronization protocol is used to assign a unified time reference to the received data, forming a globally consistent data snapshot, thus solving the inherent time deviation problem of distributed acquisition.

[0032] Subsequently, the controller invokes a pre-built cross-system association rule base and the system health state machine for analysis. This rule base contains hundreds of production rules in the form of "IF-THEN," where the premise (IF part) involves a combination of conditions consisting of state parameters or events from at least two different subsystems within the battery system, motor system, and electronic control system. For example, rule R1: IF (Battery temperature rises too quickly AND motor load > 80% AND heat dissipation is normal) THEN (Conclusion: Normal heat generation under high load, confidence level: high, primary risk level: low); rule R2: IF (Battery temperature rises too quickly AND motor load < 30%) THEN (Conclusion: Abnormal internal heat release in the battery, confidence level: medium-high, primary risk level: high). During analysis, data snapshots are dynamically matched with the rule base. This process supports dynamic adjustment of the judgment thresholds for state parameters (such as "too quick temperature rise") referenced in the rule premises based on the system's operating baseline, allowing the diagnosis to adapt to changes in system operating conditions. Furthermore, it allows multiple rules to be partially activated and integrates the confidence scores attached to the conclusions of each rule to contribute to the final judgment, thus handling uncertainty and complex failure modes.

[0033] Simultaneously, based on the results of dynamic matching and confidence fusion, the system health state machine model is driven to perform state transitions and generate comprehensive diagnostic conclusions. The system health state realization model clearly defines multiple overall health states (such as "fully normal" and "battery performance degradation") and composite fault states (such as "severe battery fault affecting power output") covering the battery, motor, and electronic control systems.

[0034] The model's state transitions are triggered by two types of core information: first, the initial fault judgment results from edge computing nodes (i.e., "input events," such as an "abnormal battery temperature rise" alarm); and second, the comprehensive diagnostic conclusions generated by joint logic analysis (i.e., "rule outputs," which include specific fault assumptions and initial risk levels). For example, if the system is initially in a "fully normal" state, when it matches rule R2 based on real-time data and outputs the comprehensive diagnostic conclusion of "abnormal internal battery heat dissipation," this conclusion will serve as a trigger condition, driving the state machine to transition from the "fully normal" state to the "severe battery fault" state.

[0035] Furthermore, joint logic analysis also integrates temporal correlation analysis to determine the causal relationships between events across subsystems. Technically, this function corresponds to pre-defined causal inference rules with expected time intervals in the cross-system correlation rule base. A typical example is rule R3: IF (Motor bearing vibration abnormality EVENT_OCCURS_BEFORE (100ms) Main control logic conflict) THEN (Conclusion: Mechanical failure caused control abnormality).

[0036] In practice, when a primary fault diagnosis result (i.e., the first abnormal event, such as "abnormal motor vibration") is detected, a timing monitoring window (e.g., 100ms) will be immediately initiated according to the preset causal inference rule (e.g., rule R3). Within this window, it actively monitors whether the expected and related second abnormal event (e.g., "abnormal control system logic") occurs.

[0037] If the second abnormal event occurs within the timing monitoring window, the causal relationship between the first and second abnormal events is confirmed.

[0038] Confirmation of establishment is specifically manifested by performing one or more of the following operations: Generate or update a causal relationship record that represents how the first anomalous event led to the second anomalous event; In joint logic analysis, increase the confidence weight of the corresponding causal inference rule (such as rule R3); The driving state machine transitions to a fault state that represents a causal relationship.

[0039] The aforementioned temporal correlation analysis verifies whether abnormal events across subsystems occur according to a preset temporal relationship, transforming isolated alarms into a fault evidence chain with causal logic, thereby significantly improving the diagnostic confidence and analysis depth of complex cascading faults.

[0040] S4 of this invention generates a security situation assessment report based on the joint logic analysis results. The central security controller executes the report generation step, and the specific implementation is as follows: A security situation assessment report is a structured data object that includes at least the overall risk level, the primary suspected fault location, related impact information, and recommended handling priorities.

[0041] The global risk level is calculated by combining the primary risk level output by all activated rules, the confidence level of the causal inference rules after time-series correlation analysis, and the current state of the composite fault in the system health state machine through preset weighted and arbitration logic. It is ultimately divided into finite discrete levels such as "normal", "early warning", "minor fault" and "serious fault".

[0042] The primary suspected fault location is taken directly from the physical component corresponding to the fault hypothesis with the highest confidence level, such as "Battery Pack A Module 3" and "Motor Drive End Bearing".

[0043] The associated impact information automatically lists the adjacent subsystems or functions directly affected by the primary fault based on the fault propagation path defined in the system health state machine and the associated impact field in the rule conclusion. For example, the associated impact of "battery module voltage imbalance" is "reduction in total available capacity" and "bus voltage fluctuation".

[0044] The recommended handling priorities are based on the overall risk level and the criticality of the fault location, and are mapped to a predefined handling strategy library to generate actionable command priorities such as "continuous monitoring", "planned maintenance", "immediate power reduction" and "emergency landing".

[0045] In practice, the security situation assessment report is encapsulated in a machine-readable format (such as JSON) and serves as the final output of the entire diagnostic process. It is directly provided to the hierarchical fault processor as the sole decision-making basis for its coordinated response.

[0046] In this invention, S5 uses a hierarchical fault processor to index a pre-stored collaborative response strategy library based on the global risk level in the security situation assessment report, and triggers and executes the corresponding collaborative response instruction set.

[0047] The collaborative response strategy library is defined based on the global risk level and includes at least: The strategy corresponding to the global risk level of early warning is to send graphic and textual early warning information to the cockpit displays of the aircraft and / or ground monitoring stations; The strategy corresponding to the global risk level of minor failure is as follows: based on the primary suspected failure location identified in the safety situation assessment report, automatically reduce or limit the performance output limit of the subsystem to which the failure location belongs, and provide maintenance guidance through the aircraft's human-machine interface. For a global risk level of severe failure, the strategy is to automatically execute a sequence of instructions containing at least two of the following operations: isolate the source of failure, adjust the operating parameters of adjacent subsystems to compensate for functional loss, and trigger the flight control system to enter a predefined emergency landing mode.

[0048] In practice, after the hierarchical fault processor indexes the corresponding policy based on the report, it generates a specific set of coordinated response instructions. The coordinated response instruction set contains at least two instructions sent to different subsystem controllers, and the instructions are logically related to each other, forming a closed-loop response from fault suppression to system function maintenance or task adjustment.

[0049] For example, for a diagnosis of "abnormal internal battery overheating (serious fault)," the generated instruction set will be specified as follows: To the Battery Management System (BMS): Immediately close the trip relay of the faulty module, electrically isolating it from the main circuit; simultaneously activate the phase change material cooling unit inside the module. This corresponds to "isolieving the fault source".

[0050] To the Flight Controller (VCU): Based on the remaining battery capacity and power output capability after isolation, recalculate and issue new maximum available thrust and endurance. This corresponds to "adjusting the operating parameters of adjacent subsystems to compensate for functional losses".

[0051] To the Flight Control System (FCS): Based on the new performance boundaries issued by the VCU, automatically plan a path to the nearest alternative landing site and request the execution of landing procedures. This corresponds to "triggering the flight control system to enter a predefined emergency landing mode".

[0052] Finally, the hierarchical fault processor distributes the instruction set as an atomic transaction to multiple relevant subsystem controllers through a highly deterministic communication protocol, thereby ensuring that when dealing with serious faults, it can both suppress risks and maintain the controllability and mission safety of the aircraft to the maximum extent, forming a complete closed loop from intelligent diagnosis to collaborative protection.

[0053] The method of this invention also includes S6, which uses a security data black box to persistently and immutably record key data across the entire security detection chain. Specifically, this black box receives and encrypts the core data generated throughout the entire process from S1 to S5 via a dedicated data interface. This includes raw, multi-dimensional real-time operating parameters, local feature parameters extracted through edge computing, preliminary fault judgment results generated by each node, security situation assessment reports output by the central security controller, and all collaborative response instruction sets and their execution status feedback issued by the hierarchical fault processor. The data employs a storage strategy combining cyclic recording and critical event locking, and is subject to hardware-level encryption to ensure the integrity, confidentiality, and resilience of the recorded data, meeting the highest level of aviation safety investigation and system behavior auditing requirements.

[0054] The present invention also provides a system for implementing the above method, comprising: Distributed sensor networks are deployed in the aircraft's battery system, motor system, and electronic control system to collect multiple real-time operating parameters of the aircraft's battery system, motor system, and electronic control system. Multiple edge computing nodes are connected to the sensor networks of the battery system, motor system and electronic control system respectively, to perform localized processing of multiple real-time operating parameters to obtain local characteristic parameters and perform threshold-based primary fault judgment. The central security controller communicates with all edge computing nodes to receive and synchronize data from each edge computing node, including local characteristic parameters and preliminary fault judgment results. Based on a pre-built cross-system association rule base and system health state machine, it performs joint logic analysis and generates a security situation assessment report based on the joint logic analysis results. The hierarchical fault processor, connected to the central security controller, is used to index the pre-stored collaborative response strategy library based on the global risk level in the security situation assessment report, and trigger and execute the corresponding collaborative response instruction set.

[0055] In practical implementation, distributed sensor networks include: The battery sensing unit, located within the battery system, includes a voltage sensor for measuring the voltage of the cell or module, a first temperature sensor for measuring the battery temperature, a total current sensor for measuring the total current, and an insulation resistance detection module for detecting the insulation status. The motor sensing unit, installed on the motor system, includes a second temperature sensor for measuring motor temperature, a position sensor for measuring rotor position and speed, a three-phase current sensor for measuring drive current, and a vibration sensor for detecting mechanical vibration. The electronic control sensing unit, integrated within the electronic control system, includes a third temperature sensor for monitoring the internal temperature of the controller, a DC bus voltage sensor for monitoring the power supply voltage, and a hardware watchdog circuit for monitoring the controller's operating logic.

[0056] In one embodiment, the voltage sensor and the first temperature sensor in the battery system are arranged at a density higher than that at the module level, for example, sampling points are set on each cell or every two cells to ensure that individual inconsistencies can be captured.

[0057] In one embodiment, vibration sensors in the motor system are mounted on the bearing housings at both the drive and non-drive ends of the motor to detect mechanical fault characteristics.

[0058] In one embodiment, a third temperature sensor in the electronic control system is mounted close to the heat sink of the IGBT (Insulated Gate Bipolar Transistor) power module, and the logic levels of key PWM signals and feedback signals are monitored by hardware circuitry.

[0059] In practical implementation, edge computing nodes include: The battery management node is used to perform differential calculations on temperature sensor data from the battery system to obtain the temperature change rate characterizing the thermal change trend; and to perform statistical calculations on the cell voltage data from the battery system to obtain voltage consistency parameters characterizing cell consistency. The motor control node integrates a digital signal processor (DSP) to perform time-frequency domain transformation on vibration sensor signals from the motor system to extract characteristic frequency amplitudes, and to perform spectral analysis on the three-phase current signals from the motor system to calculate the total harmonic distortion rate. The master control node communicates with the flight controller to obtain control commands. It is used to perform logical consistency verification between the obtained control commands and the corresponding actual feedback signals, and generates a judgment result of the control system logic anomaly when a logical conflict is detected. In one embodiment, the battery management node is also used to monitor the slope of temperature change of any cell within a short time window (e.g., 1 second) in real time, using this as a temperature change rate parameter. This rate parameter is compared with a second preset threshold that dynamically adjusts based on the current load current and the heat sink's operating state. When the temperature rise slope at a certain point exceeds this dynamic threshold, a local early warning message (i.e., a primary fault judgment result) is generated, containing the specific module location and the "abnormal battery temperature rise" type.

[0060] In one embodiment, the motor control node is also used to perform time-frequency domain transformation (e.g., Fast Fourier Transform (FFT)) on the vibration sensor signals of the motor system to extract characteristic frequency amplitudes related to the state of mechanical components such as bearings. This amplitude is then compared with a dynamic baseline established based on historical health data. If a significant and persistent deviation occurs, it is determined as "abnormal motor mechanical condition" and marked.

[0061] In one embodiment, the master control node is also used to continuously compare control commands (such as throttle commands) from the flight controller with corresponding actual feedback signals (such as actual motor speed and bus current), and perform logical consistency checks based on the basic physical relationship model of the motor. If a logical conflict that violates the above basic physical relationship, such as "high throttle command, low speed, high current", is detected, it is immediately judged as "control system logic abnormality", and a corresponding primary fault identifier is generated.

[0062] In practice, the hierarchical fault processor has pre-stored collaborative response programs corresponding to different global risk levels. The collaborative response programs can be triggered by the safety situation assessment report output by the central safety controller and execute the collaborative response instruction set, which includes collaborative control instructions issued to at least two of the battery management system, motor controller and flight controller.

[0063] The system of the present invention also includes a security data black box, which is connected to a distributed sensor network, edge computing nodes, a central security controller and a hierarchical fault processor for encrypting and persistently storing the generated multi-dimensional real-time operating parameters, local characteristic parameters, primary fault judgment results, security situation assessment reports and collaborative response instruction sets.

[0064] Finally, it should be noted that the above embodiments are merely preferred embodiments of the present invention used to illustrate the technical solutions of the present invention, and are not intended to limit the invention, nor are they intended to limit the patent scope of the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. These modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention. That is to say, any changes or refinements made to the main design concept and spirit of the present invention that are not of substantial significance, but whose technical problems are still consistent with the present invention, should be included within the protection scope of the present invention. In addition, the direct or indirect application of the technical solutions of the present invention to other related technical fields are similarly included within the patent protection scope of the present invention.

Claims

1. A method for safety testing of the three electrical components (battery, motor, and electronic control system) of a manned aircraft, characterized in that, include: S1. Collect multiple real-time operating parameters of the aircraft's battery system, motor system, and electronic control system through a distributed sensor network; S2. By deploying corresponding edge computing nodes near the battery system, motor system and electronic control system, localize the multi-dimensional real-time operating parameters to obtain local characteristic parameters, and perform threshold-based primary fault judgment. S3. Through the central security controller, receive and synchronize data from each edge computing node, which includes local feature parameters and primary fault judgment results, and perform joint logical analysis based on the pre-set cross-system association rule base and system health state machine; S4. Based on the results of the joint logic analysis, generate a security situation assessment report. The report should include at least the overall risk level, the primary suspected fault location, related impact information, and recommended handling priorities. S5. Through the hierarchical fault processor, based on the global risk level in the security situation assessment report, the pre-stored collaborative response strategy library is indexed, and the corresponding collaborative response instruction set is triggered and executed.

2. The method according to claim 1, characterized in that, In S2, localization processing includes local feature extraction, specifically including: Statistical calculations are performed on the single-cell voltage data from the battery system to obtain voltage consistency parameters characterizing cell consistency; Differential calculations are performed on temperature sensor data from the battery system to obtain the rate of temperature change characterizing the trend of thermal change. The vibration sensor signal from the motor system is transformed in the time-frequency domain to extract the characteristic frequency amplitude related to the mechanical state; Spectral analysis is performed on the three-phase current signals from the motor system to calculate the total harmonic distortion rate, which characterizes the power quality.

3. The method according to claim 2, characterized in that, In S2, a threshold-based preliminary fault determination is performed, specifically including: The voltage consistency parameter is compared with a first preset threshold. If it exceeds the threshold, it is determined that the battery voltage is unbalanced. The rate of temperature change is compared with a second preset threshold. If the rate of change exceeds the threshold, the battery temperature rise is deemed abnormal. The characteristic frequency amplitude is compared with a dynamic baseline established based on historical data. If there is a significant deviation, it is judged that the mechanical condition of the motor is abnormal. The total harmonic distortion rate is compared with the third preset threshold. If it exceeds the threshold, the motor's electrical performance is judged to be abnormal. The control commands from the electronic control system are compared with the corresponding actual feedback signals for logical consistency. If a conflict occurs, it is determined that the control system logic is abnormal.

4. The method according to claim 1, characterized in that, In S3, joint logic analysis specifically includes: Maintain a cross-system association rule base containing multiple production rules. The premise of each rule is a combination of conditions consisting of state parameters or events from at least two different subsystems in the battery system, motor system, and electronic control system. The conclusion includes the fault hypothesis, confidence level, and primary risk level. Maintain a system health state machine that describes the overall health status of the battery system, motor system, and electronic control system; The time-synchronized multi-dimensional real-time operating parameters, local feature parameters, and primary fault judgment results are used as inputs, and dynamic matching and confidence fusion are performed with the cross-system association rule base. Among them, dynamic matching supports dynamically adjusting the judgment threshold of the state parameters referenced in the rule premise based on the system operation baseline; Confidence fusion allows multiple rules to be partially activated and merges the confidence of the conclusions, contributing together to the final judgment; Based on the results of dynamic matching and confidence fusion, the state transition of the state machine is driven to generate a comprehensive diagnostic conclusion.

5. The method according to claim 4, characterized in that, Joint logic analysis also includes temporal correlation analysis: The cross-system association rule base contains causal inference rules with pre-defined expected time intervals; When the first abnormal event is identified through joint logic analysis, based on the causal inference rule, the second abnormal event with a preset causal relationship with the first abnormal event and the expected time interval between the two are determined, and a time series monitoring window is started based on the expected time interval. Within the timing monitoring window, monitor for the occurrence of a second abnormal event; If the second abnormal event occurs within the timing monitoring window, the causal relationship between the first and second abnormal events is confirmed.

6. The method according to claim 5, characterized in that, Confirming the establishment of a causal relationship specifically involves: Generate or update a causal relationship record that represents how the first anomalous event led to the second anomalous event; In joint logic analysis, increase the confidence weight of the corresponding causal inference rules; The driving state machine transitions to a fault state that represents a causal relationship.

7. The method according to claim 4, characterized in that, In S5, the collaborative response strategy library is defined based on the global risk level and includes at least: The strategy corresponding to the global risk level of early warning is to send graphic and textual early warning information to the cockpit displays of the aircraft and / or ground monitoring stations; The strategy corresponding to the global risk level of minor failure is as follows: based on the primary suspected failure location identified in the safety situation assessment report, automatically reduce or limit the performance output limit of the subsystem to which the failure location belongs, and provide maintenance guidance through the aircraft's human-machine interface. For a global risk level of severe failure, the strategy is to automatically execute a sequence of instructions containing at least two of the following operations: isolate the source of failure, adjust the operating parameters of adjacent subsystems to compensate for functional loss, and trigger the flight control system to enter a predefined emergency landing mode.

8. The method according to claim 1, characterized in that, The method further includes: S6. Through an independent security data black box, the various real-time operating parameters, local characteristic parameters, primary fault judgment results, security situation assessment reports and collaborative response instruction sets generated throughout the entire process from S1 to S5 are encrypted and persistently stored.

9. A system for implementing the method as described in any one of claims 1-8, characterized in that, include: Distributed sensor networks are deployed in the aircraft's battery system, motor system, and electronic control system to collect multiple real-time operating parameters of the aircraft's battery system, motor system, and electronic control system. Multiple edge computing nodes are connected to the sensor networks of the battery system, motor system and electronic control system respectively, to perform localized processing of multiple real-time operating parameters to obtain local characteristic parameters and perform threshold-based primary fault judgment. The central security controller communicates with all edge computing nodes to receive and synchronize data from each edge computing node, including local characteristic parameters and preliminary fault judgment results. Based on a pre-built cross-system association rule base and system health state machine, it performs joint logic analysis and generates a security situation assessment report based on the joint logic analysis results. The hierarchical fault processor, connected to the central security controller, is used to index the pre-stored collaborative response strategy library based on the global risk level in the security situation assessment report, and trigger and execute the corresponding collaborative response instruction set.

10. The system according to claim 9, characterized in that, Distributed sensor networks include: The battery sensing unit, located within the battery system, includes a voltage sensor for measuring the voltage of the cell or module, a first temperature sensor for measuring the battery temperature, a total current sensor for measuring the total current, and an insulation resistance detection module for detecting the insulation status. The motor sensing unit, installed on the motor system, includes a second temperature sensor for measuring motor temperature, a position sensor for measuring rotor position and speed, a three-phase current sensor for measuring drive current, and a vibration sensor for detecting mechanical vibration. The electronic control sensing unit, integrated within the electronic control system, includes a third temperature sensor for monitoring the internal temperature of the controller, a DC bus voltage sensor for monitoring the power supply voltage, and a hardware watchdog circuit for monitoring the controller's operating logic. Edge computing nodes include: The battery management node is used to perform differential calculations on temperature sensor data from the battery system to obtain the temperature change rate characterizing the thermal change trend; and to perform statistical calculations on the cell voltage data from the battery system to obtain voltage consistency parameters characterizing cell consistency. The motor control node integrates a digital signal processor to perform time-frequency domain transformation on vibration sensor signals from the motor system to extract characteristic frequency amplitudes, and to perform spectral analysis on the three-phase current signals from the motor system to calculate the total harmonic distortion rate. The master control node communicates with the flight controller to obtain control commands. It is used to perform logical consistency verification between the obtained control commands and the corresponding actual feedback signals, and generates a judgment result of the control system logic anomaly when a logical conflict is detected. The hierarchical fault processor has pre-stored collaborative response programs corresponding to different global risk levels. The collaborative response programs can be triggered by the safety situation assessment report output by the central safety controller and execute a collaborative response instruction set, which includes collaborative control instructions issued to at least two of the battery management system, motor controller and flight controller. It also includes a security data black box, which is connected to the distributed sensor network, edge computing nodes, central security controller and hierarchical fault processor to encrypt and persistently store the generated multi-dimensional real-time operating parameters, local characteristic parameters, primary fault judgment results, security situation assessment reports and collaborative response instruction sets.