A fault self-checking system for a parachute opening system of a UAV at high altitude
By employing a four-level unidirectional, time-sequential, progressive fault self-checking logic, the problems of unclear fault location and mechanical structure wear in the high-altitude parachute deployment system of UAVs have been resolved, enabling efficient fault location and emergency response, and improving the safety and reliability of UAV high-altitude flight.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUBEI LIULIU TECHNOLOGY CO LTD
- Filing Date
- 2026-06-09
- Publication Date
- 2026-07-24
AI Technical Summary
Existing fault self-diagnosis technologies for high-altitude parachute deployment systems for unmanned aerial vehicles (UAVs) suffer from problems such as signal crosstalk, unclear fault tracing, mechanical structure wear and tear, and improper emergency response, leading to missed detections, misjudgments, and mechanical structure wear and tear.
A four-level unidirectional, time-progressive fault self-testing logic is adopted. Through power ripple detection, signal link detection, drive circuit detection, and umbrella opening mechanism detection, the fault level is determined step by step, and corresponding emergency measures are executed according to the fault level to avoid invalid detection of mechanical structure.
It enables precise location and timely emergency response to high-altitude parachute deployment failures, reduces mechanical structural wear, and improves the reliability of self-inspection and flight safety.
Smart Images

Figure CN122450189A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of emergency safety control and airborne fault self-diagnosis technology for unmanned aerial vehicles (UAVs), specifically relating to a fault self-diagnosis system for a UAV high-altitude parachute deployment system. Background Technology
[0002] Currently, the industry's common self-diagnosis method for high-altitude parachute deployment systems of drones adopts a hardware module-based parallel and piecemeal detection mode. This mode divides the parachute deployment system into four independent units: a power module, a signal transmission module, an ignition drive module, and a parachute mechanical ejection module. The airborne flight controller simultaneously collects the operating parameters of all modules, completes the full-domain detection at once, and outputs the fault results. This is a typical multi-module parallel synchronous self-diagnosis architecture. However, this approach has the following drawbacks: 1. High-altitude drones are characterized by low pressure, low temperature, and strong airflow electromagnetic interference. Simultaneous sampling of multiple parameters can cause crosstalk between airborne sensor signals and instantaneous overload of flight control computing power. At the same time, minor, latent faults in weak current systems are easily masked by normal mechanical parameters, resulting in missed detection of early hidden dangers and misjudgment of false faults.
[0003] 2. Parallel detection cannot distinguish the timing and propagation path of faults; it can only determine whether the system has a fault, but cannot locate the source of the fault. At the same time, self-testing and emergency response are disconnected, which can easily lead to two types of problems: excessive emergency parachute deployment and delayed emergency response. In addition, frequent participation of mechanical structures in synchronous self-testing can cause fatigue of the ejection springs, loosening of the parachute compartment, and increased irreversible wear. Summary of the Invention
[0004] To address the shortcomings of the existing technology, this invention proposes a self-diagnostic system for high-altitude parachute deployment systems of unmanned aerial vehicles (UAVs).
[0005] The technical solution adopted in this invention is as follows: In a first aspect, the present invention provides a fault self-diagnosis system for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV), comprising: The main control unit and its connected power ripple detection device, signal link detection device, drive circuit detection device, umbrella opening mechanism detection device, fault judgment module, and graded handling module; The power supply ripple detection device is used to detect the amplitude of DC bus voltage ripple. The signal link detection device is used to detect the unidirectional transmission delay of the differential command signal; The drive circuit detection device is used to detect the turn-on response time of the drive transistor; The umbrella opening mechanism detection device is used to detect the static deformation displacement error of the ejection spring. The fault determination module determines the fault level based on the collected signals and according to preset rules. The tiered response module executes corresponding emergency measures based on fault level matching.
[0006] The main control device controls the power supply ripple detection device to be normally open, while the control signal link detection device, drive circuit detection device, umbrella opening mechanism detection device, fault determination module, and graded handling module are normally closed.
[0007] During high-altitude flight, the drone's system performs a self-test procedure; During the first-level test, the power ripple detection device collects the static voltage ripple amplitude of the dedicated power supply bus for umbrella opening in real time and compares it with the system's standard threshold. If the detection parameters are normal, the umbrella opening system is determined to be fault-free, and the self-test process is terminated directly. If the detection parameters are abnormal, the fault determination module determines that there is a low-risk hidden power supply at the first level and triggers the signal link detection device to start. The secondary test is performed. The signal link detection device collects the one-way transmission delay of the umbrella opening differential command signal and compares it with the system standard threshold. If the detection parameters are normal, the fault is determined to be only at the primary power level. The self-test process is terminated and the primary emergency measures are executed. If the detection parameters are abnormal, the fault determination module determines that there is a secondary signal transmission intermediate risk and triggers the drive circuit detection device to open. The system performs a three-level test. The drive circuit detection device collects the ignition drive MOSFET turn-on response time and compares it with the system standard threshold. If the test parameters are normal, the fault is determined to be a combined level one and level two fault. The self-test process is terminated and level two emergency measures are executed. If the test parameters are abnormal, the fault determination module determines that the level three drive is superimposed and executes a high-risk operation, triggering the umbrella opening mechanism detection device to open. A level 4 test is performed. The parachute opening mechanism detection device collects the static deformation displacement of the parachute compartment ejection spring pretension force and compares it with the system standard threshold. If the test parameters are normal, the fault is determined to be a level 1 + level 2 + level 3 composite fault, and level 3 emergency measures are implemented. If the test parameters are abnormal, the fault determination module determines that there is a level 4 fatal risk of the entire aircraft opening the parachute, and level 4 emergency landing measures are implemented.
[0008] The first-level detection threshold standard is as follows: the peak value of bus voltage ripple ≤50mV is normal under high-altitude environment, and greater than 50mV is abnormal; the first-level detection is used to investigate hidden power disturbance hazards caused by power supply capacitor attenuation and line oxidation under low-temperature environment.
[0009] The secondary detection threshold standard is as follows: a one-way transmission delay of ≤8ms for differential command signals is normal, and a delay greater than 8ms is abnormal; the secondary detection is used to verify whether the front-end power supply disturbance is transmitted to the signal transmission link and to determine the integrity of the command issuance link.
[0010] The three-level detection threshold standard is as follows: the MOSFET turn-on response time is ≤3ms as normal and greater than 3ms as abnormal; the three-level detection is used to determine whether the electrical drive circuit has suffered permanent damage under the dual interference of power supply and signal.
[0011] The four-level detection threshold standard is as follows: the deformation displacement error of the ejector spring is ≤0.2mm as normal, and greater than 0.2mm as abnormal. The four-level detection is the last level of detection in the entire process. It is only started after all the first three electronic links are abnormal, so as to avoid unnecessary losses of mechanical structure.
[0012] The specific emergency measures at levels one, two, three, and four include: Level 1 emergency measures: bus voltage stabilization and compensation, background log recording, ground yellow warning, do not interfere with flight path, do not activate mechanical parachute deployment; Level 2 emergency measures: switch redundant signal channels, reissue commands, issue orange pop-up alarms on the ground, and retain the electronically controlled parachute deployment channel; Level 3 emergency measures: Cut off the electronic control drive circuit, preheat the mechanical parachute opening mechanism, issue a red ground alarm, and revoke the airborne electronic control parachute opening authority; Level 4 emergency response measures: Plan an emergency landing route, abandon parachute deployment, and issue a dark red emergency audible and visual alarm on the ground.
[0013] The second aspect of this invention provides a self-diagnosis method for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV). Based on the operation of the self-diagnosis system, a four-level unidirectional, sequential, progressive, and non-skipping self-diagnosis logic is adopted, strictly following the fixed sequence of Level 1, Level 2, Level 3, and Level 4. The detection parameters at each level are completely non-repetitive, and the severity of the risk increases progressively. If the detection parameters of the upper level are normal, the self-diagnosis ends directly; if the upper level is abnormal, the lower level is triggered. If the detection parameters of the lower level are normal, it is determined that the fault exists only at the upper level. If the detection parameters of the lower level are abnormal, the lower level is triggered. After each level of detection is completed, corresponding emergency response measures are matched, and the measures are progressively added with the fault level.
[0014] A third aspect of the present invention provides a computer storage medium storing a computer executable program, characterized in that, when the computer executable program is run by an airborne flight control processor, it executes all the steps of the self-diagnosis method for the high-altitude parachute deployment system fault of the unmanned aerial vehicle.
[0015] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are: This solution differs from existing UAV parachute deployment fault self-testing methods, which employ parallel synchronous hardware module detection without a fixed detection sequence, are prone to redundant and wasted computing power, miss hidden power supply faults, have unclear fault tracing, and easily cause ineffective wear and tear on mechanical structures. The core of this solution is to replicate the real fault chain transmission pattern of the parachute deployment system—power supply-signal-drive-mechanical components—and construct a new four-level unidirectional, non-skipping, and non-backtracking sequential self-testing logic. Combined with a partitioned start-stop control strategy that keeps power supply detection always on while other modules are in sleep mode, it achieves tiered, on-demand release of computing power. Furthermore, relying on a hierarchical fault judgment and layered emergency measures control logic, it accurately distinguishes between single faults and multi-level composite faults. Mechanical mechanism detection is only initiated after all three levels of electronic links have failed, minimizing fatigue wear on the ejector springs. This solution balances self-testing accuracy under complex high-altitude conditions, onboard computing power consumption, mechanical structure lifespan, and the timeliness of tiered emergency response, comprehensively improving the reliability of UAV high-altitude parachute deployment fault self-testing and flight operation safety. Attached Figure Description
[0016] The present invention will be described by way of example and with reference to the accompanying drawings, wherein: Figure 1 This is a flowchart of the method in this invention; Figure 2 This is a schematic diagram of the system structure in this invention. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0018] Example 1: This embodiment provides a self-diagnostic system for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV). This system is adaptable to flight conditions from 0 to 12000 meters and can withstand harsh environments such as -45°C low temperatures, low air pressure, and strong electromagnetic interference from onboard motors. It is specifically designed to address the cascading transmission characteristics of parachute deployment faults in UAVs. (See reference...) Figure 1 It includes: a main control unit and connected to it a power ripple detection device, a signal link detection device, a drive circuit detection device, a parachute opening mechanism detection device, a fault determination module, a graded handling module, and a ground station interaction module.
[0019] The main control device uses a 32-bit ARM Cortex-M4 industrial-grade main control chip and communicates with all other modules through an isolated CAN2.0B bus. The detection circuit is electrically isolated from the original parachute opening working circuit to avoid the self-test signal interfering with the normal operation of the parachute opening. The entire system adopts a dedicated independent power supply bus for parachute opening, which is completely isolated from the power supply bus of the UAV, eliminating the interference of power fluctuations of the whole machine with the accuracy of the self-test.
[0020] The power ripple detection device has a built-in RC passive filter circuit, differential isolation sampling chip and peak hold circuit, with a sampling frequency of 10kHz. It is used to detect the peak value of DC bus voltage ripple and can capture millisecond-level transient power supply spike disturbances. This allows for the investigation of underlying hidden power supply aging disturbances caused by the decay of power supply capacitor value and line oxidation and loose connection under high altitude and low temperature conditions, and accurately pinpoints the source of umbrella opening fault. The signal link detection device is equipped with a high-precision microsecond-level timing counter to detect the one-way transmission delay of the umbrella opening differential command signal and synchronously verify the signal bit error rate, thereby verifying whether the power disturbance has spread to the signal transmission link through ground coupling and line crosstalk, and distinguishing whether the fault is a simple power fault or a power + signal composite fault. The drive circuit detection device uses a gate and drain synchronous sampling method to detect the turn-on response time of the ignition drive MOS transistor, thereby checking whether the drive chip and power MOS transistor have suffered permanent electrical damage such as gate aging or breakdown under the dual interference of power supply and signal. The parachute opening mechanism detection device uses a 0.01mm high-precision non-contact laser displacement sensor to detect the static deformation displacement error of the ejection spring. The sensor only completes sampling during the stable attitude window of the UAV, thereby determining whether the mechanical passive parachute opening mechanism has normal ejection capability after all electronic systems have failed. The fault determination module has a built-in temperature-altitude environmental compensation algorithm and a one-way chain determination logic. Based on the collected multi-channel detection signals, it determines the fault level according to the preset non-backtracking progressive rule and prohibits skipping levels to determine faults. The graded handling module is executed in conjunction with hardware and software, and has a built-in hardware disconnection relay and route planning algorithm. It executes corresponding hardware and software collaborative emergency measures based on fault level matching. The ground station interaction module is equipped with a 433MHz airborne data radio, which is used to push different levels of fault alarm information to the ground station, and simultaneously package the original airborne detection data, fault timestamp, UAV location and altitude data. At the same time, the fault log is stored locally in non-volatile flash memory, which supports post-event traceability and review.
[0021] Furthermore, the main control device controls the power ripple detection device to be in a normally open state, operating in the background with low power consumption throughout the process; the control signal link detection device, drive circuit detection device, parachute opening mechanism detection device, fault judgment module, and graded handling module are normally in a normally closed sleep state. In the sleep state, the power supply is completely cut off and there is no computing power occupation. They only receive the main control wake-up command and then power on to work, minimizing the idle power consumption and computing power occupation of the UAV during cruise flight.
[0022] When the UAV is flying at an altitude of over 500m, the system automatically executes a self-check procedure every 10 seconds. The longest time for a single complete self-check is no more than 300ms, which does not consume flight control computing power or affect the normal flight attitude of the UAV. The system strictly follows a one-way progressive test from level one to four, and cannot skip levels or reverse backtrack for retesting, replicating the real fault propagation path. The specific self-check process is as follows: The system performs a first-level test to investigate underlying hidden power supply aging disturbances, pinpoint the source of the umbrella opening failure, and continuously collect the static voltage ripple amplitude of the dedicated power supply bus for umbrella opening for 200ms using the power ripple detection device. After compensation and correction based on real-time ambient temperature, the amplitude is compared with the system's standard threshold. If the test parameters are normal, the umbrella opening system is determined to be fault-free, the self-test process terminates directly, and all sleep modules remain in sleep mode. If the test parameters are abnormal, the fault determination module determines that there is a low risk of a first-level hidden power supply and immediately outputs a wake-up signal, triggering the signal link detection device to start. Power supply is the foundation of the entire system's energy. Power supply disturbances will inevitably interfere with downstream signal transmission through line coupling. Therefore, after a power supply anomaly, it is necessary to progressively detect the signal link, perform secondary detection, verify whether the power supply disturbance has spread to the signal transmission link, and distinguish whether the fault is a simple power supply fault or a power supply + signal combined fault. Specifically, a standard test differential command is sent through the signal link detection device to collect the one-way transmission delay of the umbrella opening differential command signal. After data compensation is completed by combining the high-altitude electromagnetic interference intensity, it is compared with the system's standard threshold. If the detection parameters are normal, it is determined that the fault is only at the primary power supply level, the self-test process terminates, and primary emergency measures are executed. If the detection parameters are abnormal, the fault determination module determines that there is an additional secondary signal transmission intermediate risk, triggering the drive circuit detection device to open. An abnormal signal link can cause the parachute deployment command to fail to be issued on time, easily leading to a missed deployment opportunity. Further investigation is needed to determine if the backend drive execution unit is damaged by coupling interference. Therefore, a three-level detection is performed to check for permanent electrical damage to the drive circuit under dual interference from power supply and signal. Specifically, the drive circuit detection device synchronously samples the gate trigger signal and conduction signal of the MOS transistor, collects the ignition drive MOS transistor turn-on response time, removes flight current interference noise, and compares it with the system standard threshold. If the detection parameters are normal, the fault is determined to be a combined level one and level two fault, the self-test process terminates, and level two emergency measures are executed. If the detection parameters are abnormal, the fault determination module determines that a level three drive execution high risk is superimposed, triggering the parachute deployment mechanism detection device to open. A Level 4 test is performed to determine whether the mechanical passive parachute deployment mechanism is usable after all electronic systems have failed. This test is only initiated after all three levels of electronic links have failed to avoid unnecessary reciprocating deformation losses in the mechanical structure. Specifically, during the UAV's horizontal attitude stabilization window, the parachute deployment mechanism detection device collects the static deformation displacement of the parachute chamber ejection spring preload, calculates the error value with the factory standard displacement, and compares it with the system's standard threshold. If the detection parameters are normal, the fault is determined to be a Level 1 + Level 2 + Level 3 composite fault, and Level 3 emergency measures are implemented. If the detection parameters are abnormal, the fault determination module determines that there is a Level 4 fatal risk of the entire aircraft deploying the parachute, and Level 4 emergency landing measures are immediately implemented.
[0023] The first-level detection threshold standard is as follows: after temperature compensation under full working conditions at high altitude, the peak value of the bus voltage ripple is ≤50mV as normal, and greater than 50mV as abnormal. The first-level detection is used to investigate hidden power disturbance hazards caused by power supply capacitor attenuation and line oxidation under high altitude and low temperature conditions. This threshold is the critical ripple value for the safety of the umbrella circuit. If it is lower than this value, no back-end link coupling interference will occur.
[0024] The secondary detection threshold standard is as follows: a one-way transmission delay of ≤8ms for differential command signals is normal, and a delay greater than 8ms is abnormal. The secondary detection is used to verify whether the front-end power supply disturbance is transmitted to the signal transmission link and to determine the integrity of the command issuance link. This delay threshold matches the requirements of the optimal parachute opening response window for UAVs at high altitudes.
[0025] The three-level detection threshold standard is as follows: the MOSFET turn-on response time is ≤3ms for normal and greater than 3ms for abnormal. The three-level detection is used to determine whether the electrical drive circuit has suffered irreversible damage such as permanent breakdown or device aging under the dual interference of power supply and signal. If the delay exceeds this time, it is determined that the hardware is permanently damaged and cannot be repaired by software.
[0026] The fourth-level detection threshold standard is as follows: the deformation displacement error of the ejection spring is ≤0.2mm as normal and greater than 0.2mm as abnormal. The fourth-level detection is the last level of detection in the entire process. It is only started after all the first three electronic links are abnormal, so as to avoid premature detection and cause fatigue wear of the ejection spring. This error threshold can ensure that the mechanical parachute ejection thrust meets the requirements for high-altitude parachute opening.
[0027] The Level 1, Level 2, Level 3, and Level 4 emergency measures all employ a dual-protection mode of software control and hardware loop linkage to prevent the failure of a single program from causing the emergency action to fail. Specific emergency measures include: Level 1 emergency measures: On the hardware side, activate the bus active voltage regulator compensation circuit to suppress ripple; on the software side, solidify the fault log in the background and do not allow manual deletion; on the ground station, push a yellow constant-on warning and a low-frequency buzzer alarm; do not interfere with the flight path, do not activate the mechanical parachute preheating, and do not switch the signal redundancy channel to ensure that the normal mission of the UAV is not affected. Level 2 emergency measures: retain the primary bus voltage stabilization compensation action, superimpose automatic switching of redundant signal channels, hardware-level retransmission of delayed commands, orange pop-up alarm at the ground station, and intermediate frequency buzzer prompt; retain the dual-channel availability of electronically controlled parachute opening throughout the process, and still prioritize electronically controlled parachute opening as the preferred execution plan, without touching the mechanical parachute opening structure; Level 3 emergency measures: Hardware relays hard-cut off all electronic control drive circuits to prevent abnormal signals from triggering parachute deployment; preheat the mechanical ejection mechanism to eliminate low-temperature rigidity deviation; trigger a red continuous alarm at the ground station; permanently revoke the airborne electronic control parachute deployment authority; subsequent emergency parachute deployment will rely entirely on the passive mechanical parachute deployment mechanism. Level 4 emergency response: The flight control system immediately terminates the original flight mission, automatically plans the shortest emergency landing route in an open, uninhabited area, and locks all active electronic parachute deployment and passive mechanical parachute deployment actions to prevent ineffective parachute deployment from causing mid-air disintegration; the ground station triggers a dark red interface with high-frequency audible and visual emergency alarm, and all fault data is transmitted back to the ground backend in real time to remind ground personnel to take over the monitoring of the drone.
[0028] This invention breaks away from the conventional approach of parallel and separate testing of existing parachute self-test hardware modules. It completely replicates the actual transmission sequence of faults in a drone's parachute opening system from power supply to signal, drive, and mechanical components, constructing a new four-level unidirectional chain-based progressive self-test logic. This logic sequentially achieves layered fault tracing, tiered release of computing power, minimization of mechanical losses, and precise matching of emergency measures at different levels. It thoroughly solves pain points in the industry such as missed detection of hidden power supply hazards, overload of computing power during routine self-tests, ambiguous fault tracing paths, and ineffective structural losses caused by pre-emptive mechanical testing.
[0029] It should be noted that this embodiment fully discloses the hardware composition, sampling parameters, compensation rules, judgment logic, software and hardware emergency actions and all critical thresholds of each module. UAV flight control, embedded software and electromechanical structure technicians in the relevant fields can replicate and build the system and complete the debugging and whole machine testing by following the contents described in this document without any creative effort.
[0030] Example 2 This embodiment provides a self-diagnosis method for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV). Based on the operation of the self-diagnosis system for a high-altitude parachute deployment system of an UAV described in Embodiment 1, it is adapted to the same flight conditions of 0-12000m altitude, low temperature, low air pressure, and strong electromagnetic interference. This self-diagnosis method adopts a four-level unidirectional sequential progressive self-diagnosis logic without skipping levels. The entire process strictly follows the fixed sequence of the first-level power supply detection, the second-level signal link detection, the third-level drive circuit detection, and the fourth-level mechanical parachute deployment mechanism detection. It is prohibited to skip the preceding levels and start the detection directly at any level. The core parameters and detection principles collected at each level are completely unique, and the severity of the fault risk increases progressively with the detection level. The core rules of the overall self-inspection are as follows: if the upper-level detection parameters are normal, the self-inspection process ends directly and prematurely, without starting any subsequent lower-level detection modules; if the upper-level detection parameters are abnormal, the corresponding lower-level detection module is rigidly triggered to power on and start working; when the lower-level detection parameters are normal, it is determined that the fault exists only in isolation at the upper-level single fault level, with no fault propagation downwards; when the lower-level detection parameters are abnormal, it is determined that the fault has undergone chain propagation, and the next level of detection is triggered level by level; and after the closed-loop judgment of each level of detection is completed, the corresponding level of emergency response measures are immediately matched, and subsequent higher-level emergency measures are superimposed on lower-level measures level by level, rather than replacing them individually, to ensure that emergency protection capabilities are upgraded synchronously.
[0031] Specifically, see Figure 2 The self-diagnostic method for the high-altitude parachute deployment system of this UAV includes the following steps: S1. System Normal Standby and Self-Test Wake-up Preparation: After the UAV takes off, it collects flight altitude data in real time. When the flight altitude is higher than 500m and it enters the high-altitude parachute deployment standby zone, the main control device starts a periodic self-test task with a fixed self-test cycle of 10s. The power ripple detection device is kept powered on and always open, while all other detection modules, logic processing modules, and handling modules are kept in a power-off sleep state. The cached data of the previous round of self-test is cleared, and the pre-self-test preparation is completed.
[0032] S2. Perform Level 1 power supply fault detection: Collect the peak value of the DC bus voltage ripple on the parachute-dedicated circuit using a normally open power ripple detection device. Combine this with real-time airborne ambient temperature and altitude to perform environmental error compensation. Compare the compensated peak value with the Level 1 detection standard threshold. If the peak value of the bus voltage ripple is ≤50mV, the system is deemed fault-free, and the current self-test is terminated. All sleep modules remain powered off, awaiting the next self-test cycle. If the peak value of the bus voltage ripple is >50mV, a low-risk Level 1 hidden power supply is identified. The Level 1 emergency measures are maintained in operation, and a wake-up command is issued to initiate Level 2 signal link detection.
[0033] S3. Perform secondary signal link fault detection: After the signal link detection device is powered on, it sends a standard umbrella opening differential test command, collects the one-way transmission delay of the command signal and completes high-altitude electromagnetic interference compensation, and compares the delay data with the secondary detection standard threshold. If the one-way transmission delay is ≤8ms, it is determined that the power disturbance has not been coupled to the signal link, and the fault is limited to the primary power level. The current primary emergency measures remain unchanged, and the self-test is terminated directly. If the one-way transmission delay is >8ms, it is determined that the fault has been transmitted to the signal link, forming a secondary composite intermediate risk of power + signal. The secondary emergency response action is superimposed on the primary emergency measures, and a wake-up command is issued to start the tertiary drive circuit detection.
[0034] S4. Perform Level 3 Drive Circuit Fault Detection: After the drive circuit detection device is powered on, it synchronously acquires the gate trigger signal and drain conduction signal of the drive MOSFET, calculates the MOSFET turn-on response time and removes flying current noise interference, and compares the response time with the Level 3 detection standard threshold. If the MOSFET turn-on response time is ≤3ms, it is determined that the dual interference has not caused permanent hardware damage to the drive circuit, and the fault stops at the Level 2 composite fault. The current Level 1 + Level 2 superimposed emergency measures remain unchanged, and the self-test is terminated directly. If the MOSFET turn-on response time is >3ms, it is determined that irreversible electrical damage has occurred in the drive circuit, and the fault is transmitted to the drive execution end, forming a Level 3 high-level composite risk. On the basis of the existing superimposed emergency measures, Level 3 emergency response actions are added, and a wake-up command is issued to start the Level 4 mechanical parachute opening mechanism detection.
[0035] S5. Perform Level 4 Mechanical Parachute Deployment Mechanism Fault Detection: Only under the premise that all three levels of electronic detection are abnormal, the parachute deployment mechanism detection device collects the static deformation displacement error of the ejection spring during the window period when the UAV's attitude is stable and without shaking, and compares the displacement error with the Level 4 detection standard threshold; if the ejection spring deformation displacement error is ≤0.2mm, it is determined that the entire electronic link has failed but the mechanical passive parachute deployment mechanism is intact, the fault stops at the Level 3 composite fault, the Level 1 + Level 2 + Level 3 superimposed emergency measures remain unchanged, and this self-test is terminated; if the ejection spring deformation displacement error is >0.2mm, it is determined that the electronic control system and mechanical actuator have all failed, the whole aircraft has no parachute deployment redundancy guarantee, it is determined to be a Level 4 fatal fault, all pre-level emergency measures are immediately shut down, and the entire domain is switched to Level 4 emergency landing measures.
[0036] Furthermore, this self-testing method sets up a triple self-testing fault tolerance mechanism to adapt to the complex high-altitude flight conditions of UAVs and avoid false detection and missed detection problems: The first fault tolerance is continuous sampling fault tolerance. A single abnormality in a single-level detection does not directly determine the fault. Only when parameters exceed the standard in three consecutive cycle detections is the corresponding level of the actual fault confirmed, eliminating misjudgments caused by transient electromagnetic interference; The second fault tolerance is timing lock-in fault tolerance. Once the self-testing process progresses to the next level, it is prohibited to backtrack to the previous level for repeated re-inspection, ensuring the uniqueness of the fault propagation path determination; The third fault tolerance is emergency measure latch-in fault tolerance. Low-level emergency measures that have been activated will not be closed when higher-level detections are activated, and they always maintain a progressively superimposed state, ensuring the safety of system operation throughout the entire process.
[0037] Furthermore, after each round of self-inspection, regardless of whether the self-inspection terminates early or detects a fault, the fault determination module will package all original sampling data, environmental compensation parameters, fault determination results, and emergency execution records, and upload them to the ground station through the ground station interaction module. At the same time, the log data will be permanently stored locally in non-volatile flash memory to facilitate fault tracing and system operation and maintenance optimization after the flight.
[0038] It should be noted that the self-testing method provided in this embodiment is fully compatible with the hardware system of Embodiment 1. It relies on the normally open + normally closed partitioned architecture of the hardware to achieve on-demand scheduling of computing power. Through unidirectional, non-skipping, and non-backtracking time-series self-testing logic, it perfectly matches the actual fault propagation path of the parachute deployment system. Unlike the problems of parameter redundancy, logical confusion, and unclear fault level definition in traditional parallel synchronous self-testing methods, the detection parameters at each level of this method are independent and non-overlapping, and the emergency strategies are superimposed for protection at each level. This can not only minimize the waste of computing power and mechanical structure wear during high-altitude flight, but also achieve accurate fault level positioning and seamless emergency response. At the same time, the method steps are complete and the time-series logic is clear. Those skilled in the art can directly write corresponding embedded control programs in conjunction with the hardware system of Embodiment 1, and implement them without additional creative work.
[0039] Example 3: This embodiment provides a computer storage medium, which is an airborne embedded non-volatile Flash memory chip. It is suitable for the confined installation space of UAVs and the harsh storage conditions of high altitude, low temperature and low air pressure. It has the characteristics of airborne dedicated storage, such as no data loss when power is off, resistance to electromagnetic interference, resistance to high and low temperatures (-55℃-85℃), and read / write response latency ≤1ms. The storage medium stores a computer executable program, which is compiled and solidified using embedded C language, has no external program dependencies, and can be directly adapted to run on the 32-bit ARM Cortex-M4 core airborne flight control processor in Embodiment 1.
[0040] Specifically, when the computer execution program is called and run by the airborne flight control processor, it fully executes all the steps of the self-test method for the high-altitude parachute deployment system of the UAV described in Embodiment 2, including system standby wake-up, four-level progressive timing detection, fault level determination, graded emergency measures superposition, high-altitude environmental parameter compensation, triple fault tolerance verification, local storage of fault data and uplink transmission to the ground. At the same time, all detection thresholds, self-test cycle parameters and emergency action timing parameters are fixed in the program, and the self-test logic can run autonomously upon power-up without secondary configuration of external airborne equipment.
[0041] Furthermore, the computer's executable program adopts a modular encapsulation design, with corresponding subroutines for power detection, signal link detection, drive circuit detection, mechanical mechanism detection, fault determination, graded emergency response, and ground communication interaction. Each subroutine is independently encapsulated and linked according to a one-way chain call rule, prohibiting unordered calls across modules, and matching the normally open / normally closed partitioning working logic of the hardware system one by one.
[0042] When the onboard flight control processor detects that the drone's altitude has reached the 500m parachute deployment standby threshold, it automatically loads and starts the computer execution program stored in this storage medium. If a momentary program flight abnormality occurs during program operation, the built-in hardware watchdog can automatically reset and restart the program within 20ms, without affecting the normal flight of the drone and the basic operation of the parachute deployment system.
[0043] The computer storage medium disclosed in this embodiment can be directly mounted on the existing UAV airborne flight control hardware platform without modifying the original hardware circuit structure. The aforementioned four-level progressive fault self-test function can be realized simply by burning the program. Embedded developers in the field can directly complete the program burning and software-hardware integration according to the contents described in this embodiment. The solution can be implemented without additional creative work. At the same time, it forms a complete hardware-method-storage medium three-in-one protection system with the hardware system of Embodiment 1 and the self-test method of Embodiment 2. The overall technical solution is mutually supportive and logically closed.
[0044] It should be noted that the device structure and accompanying drawings of this invention mainly describe the principle of this invention. In terms of the technical aspects of this design principle, the setting of the power mechanism, power supply system and control system of the device is not fully described. However, those skilled in the art can clearly understand the specifics of its power mechanism, power supply system and control system if they understand the principle of the invention. The control method in the application document is automatic control through a controller. The control circuit of the controller can be implemented by those skilled in the art through simple programming.
[0045] All standard parts used can be purchased from the market, and can be customized according to the instructions and drawings. The specific connection methods of each part adopt conventional methods such as bolts, rivets, and welding that are mature in the existing technology. The machinery, parts and equipment adopt conventional models in the existing technology, and the structure and principle of the components known to those skilled in the art can be known by those skilled in the art through technical manuals or conventional experimental methods.
[0046] It should be noted that the controller and its automatic control program involved in this invention can be implemented by those skilled in the art based on the principles of similar control programs in the prior art, and are not the inventive aspect of this invention. Furthermore, the electronic components and corresponding electronic circuits involved in this application are all prior art, which can be fully implemented by those skilled in the art, and need not be elaborated upon. The scope of protection of this invention does not involve improvements to software, algorithms, or methods.
[0047] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A self-diagnostic system for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV), characterized in that, include: The main control unit and its connected power ripple detection device, signal link detection device, drive circuit detection device, umbrella opening mechanism detection device, fault judgment module, and graded handling module; The power supply ripple detection device is used to detect the amplitude of DC bus voltage ripple. The signal link detection device is used to detect the unidirectional transmission delay of the differential command signal; The drive circuit detection device is used to detect the turn-on response time of the drive transistor; The umbrella opening mechanism detection device is used to detect the static deformation displacement error of the ejection spring. The fault determination module determines the fault level based on the collected signals and according to preset rules. The tiered response module executes corresponding emergency measures based on fault level matching.
2. The self-diagnostic system for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV) according to claim 1, characterized in that, The main control device controls the power supply ripple detection device to be normally open, while the control signal link detection device, drive circuit detection device, umbrella opening mechanism detection device, fault determination module, and graded handling module are normally closed.
3. The self-diagnostic system for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV) according to claim 2, characterized in that, During high-altitude flight, the drone's system performs a self-test procedure; During the first-level test, the power ripple detection device collects the static voltage ripple amplitude of the dedicated power supply bus for umbrella opening in real time and compares it with the system standard threshold. If the detection parameters are normal, the umbrella opening system is determined to be fault-free, and the self-test process is terminated directly; if the detection parameters are abnormal, the fault determination module determines that there is a low risk of a first-level hidden power supply and triggers the signal link detection device to start. The secondary detection is performed, and the signal link detection device collects the one-way transmission delay of the umbrella opening differential command signal and compares it with the system standard threshold. If the test parameters are normal, the fault is determined to be only at the first-level power supply level. The self-test process is terminated and the first-level emergency measures are executed. If the detection parameters are abnormal, the fault determination module determines that there is a medium risk in the superimposed secondary signal transmission and triggers the drive circuit detection device to open. The three-level test is performed, and the drive circuit test device collects the turn-on response time of the ignition drive MOSFET and compares it with the system standard threshold. If the test parameters are normal, the fault is determined to be a combined Level 1 and Level 2 fault. The self-test process is terminated and Level 2 emergency measures are implemented. If the detection parameters are abnormal, the fault determination module determines that the three-level drive execution is advanced risk and triggers the umbrella opening mechanism detection device to open. The fourth-level test is performed. The parachute mechanism testing device collects the static deformation displacement of the parachute compartment ejection spring preload and compares it with the system standard threshold. If the test parameters are normal, the fault is determined to be a combined level 1, level 2, and level 3 fault, and level 3 emergency measures are implemented. If the detected parameters are abnormal, the fault determination module determines that there is a Level 4 fatal risk of the entire aircraft opening its parachute and executes Level 4 emergency landing measures.
4. A self-diagnostic system for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV) according to claim 3, characterized in that, The first-level detection threshold standard is as follows: the peak value of bus voltage ripple ≤50mV is normal under high-altitude environment, and greater than 50mV is abnormal; the first-level detection is used to investigate hidden power disturbance hazards caused by power supply capacitor attenuation and line oxidation under low-temperature environment.
5. A self-diagnostic system for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV) according to claim 3, characterized in that, The secondary detection threshold standard is as follows: a one-way transmission delay of differential command signal ≤8ms is normal, and a delay greater than 8ms is abnormal. Level 2 detection is used to verify whether front-end power supply disturbances are transmitted to the signal transmission link and to determine the integrity of the command issuance link.
6. A self-diagnostic system for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV) according to claim 3, characterized in that, The three-level detection threshold standard is as follows: the MOSFET turn-on response time is ≤3ms as normal and greater than 3ms as abnormal; the three-level detection is used to determine whether the electrical drive circuit has suffered permanent damage under the dual interference of power supply and signal.
7. A self-diagnostic system for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV) according to claim 3, characterized in that, The four-level detection threshold standard is as follows: the deformation displacement error of the ejector spring is ≤0.2mm as normal, and greater than 0.2mm as abnormal. The four-level detection is the last level of detection in the entire process. It is only started after all the first three electronic links are abnormal, so as to avoid unnecessary losses of mechanical structure.
8. A self-diagnostic system for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV) according to claim 3, characterized in that, The specific emergency measures at levels one, two, three, and four include: Level 1 emergency measures: bus voltage stabilization and compensation, background log recording, ground yellow warning, do not interfere with flight path, do not activate mechanical parachute deployment; Level 2 emergency measures: switch redundant signal channels, reissue commands, issue orange pop-up alarms on the ground, and retain the electronically controlled parachute deployment channel; Level 3 emergency measures: Cut off the electronic control drive circuit, preheat the mechanical parachute opening mechanism, issue a red ground alarm, and revoke the airborne electronic control parachute opening authority; Level 4 emergency response measures: Plan an emergency landing route, abandon parachute deployment, and issue a dark red emergency audible and visual alarm on the ground.
9. A self-diagnostic method for a high-altitude parachute deployment system of an unmanned aerial vehicle (UAV), characterized in that, Based on the operation of the self-test system for high-altitude parachute deployment system of UAV as described in any one of claims 1-8, a four-level unidirectional time-sequential progressive self-test logic without skipping levels is adopted, strictly following the fixed time sequence of level 1, level 2, level 3, and level 4, with no repetition of detection parameters at each level, and the severity of risk increases step by step. If the upper-level detection parameters are normal, the self-test will end directly; if the upper-level is abnormal, the lower-level test will be triggered; if the lower-level detection parameters are normal, the fault is determined to exist only at the upper level. If the lower-level detection parameters are abnormal, the next level of detection will be triggered. After each level of detection is completed, corresponding emergency response measures will be matched, and the measures will be stacked up level by level as the fault level increases.
10. A computer storage medium, characterized in that, The storage medium stores a computer-executable program, characterized in that, when the computer-executable program is run by the airborne flight control processor, it executes all the steps of the self-diagnosis method for the high-altitude parachute deployment system of the unmanned aerial vehicle as described in claim 9.