A test apparatus and test method for a redundant flight control system

CN122569313APending Publication Date: 2026-08-14BEIJING KEYIN JINGCHENG TECH +2
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-26
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0004]但是TSN报文和TSN报文的传输如何满足飞控时间的传输和表决还尚未可知

Benefits of technology

[0039] As described above, the voting method covers all scenarios where the voting dataset meets the voting conditions. Furthermore, by removing abnormal data through the difference between the maximum and minimum values ​​and the difference between the second largest and minimum values ​​in the voting dataset, the voting dataset is gradually approximated to meet the voting conditions. This method not only has a small computational load but is also suitable for scenarios where flight control data with continuously changing values ​​is voted on. It solves the problem that the traditional majority voting method cannot be used for voting on flight control data with continuously changing values.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122569313A_ABST
    Figure CN122569313A_ABST
Patent Text Reader

Abstract

This application provides a testing apparatus and method for a redundant flight control system. The flight control simulators in the apparatus are interconnected via a TSN network, which sets up a test environment for flight control data. Each flight control simulator broadcasts a TSN message carrying its own channel's flight control data to other flight control simulators via the TSN network. Each flight control simulator retains flight control data from TSN messages received from other channels whose latency meets deterministic requirements. Each flight control simulator aligns its own channel's flight control data with the retained data from other channels and then votes to test the voting algorithm for redundant flight control data of the corresponding flight controller. In this application embodiment, the flight control simulators are interconnected via a TSN network and synchronized with a clock server. They are cross-connected at the application layer via a CCDL bus. A test environment for transmitting flight control data in the TSN network is set up to simulate the transmission and voting of flight control data in the flight control system, thereby verifying the applicability of the TSN network to redundant flight control systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of aircraft control technology, and in particular to a test apparatus and test method for a redundant flight control system. Background Technology

[0002] Traditional redundant flight control systems achieve channel synchronization through high-low level handshakes, offering high security and strong real-time performance. However, the airborne bus of traditional flight control systems faces technical bottlenecks when dealing with future distributed, highly integrated, and highly deterministic business architectures, such as insufficient bandwidth, single-point controller failures, manual static configuration, and the inability to hard isolate traffic.

[0003] TSN technology features high-precision time synchronization, high reliability, data determinism, and low latency. It also boasts dynamic bandwidth management capabilities and natively possesses the same high-speed forwarding capabilities as Ethernet. Addressing the high security, high reliability, and high determinism challenges that need to be solved in flight control engineering, [TCS technology is described here].

[0004] However, how the transmission of TSN messages satisfies the transmission and voting of flight control time is still unknown. Summary of the Invention

[0005] In view of this, embodiments of this application provide a testing apparatus and method for a redundant flight control system. In this embodiment, each flight control simulator is interconnected via a TSN network and synchronized with the clock server of the TSN network. Cross-connection via CCDL bus is implemented at the application layer. A test environment for transmitting flight control data in the TSN network is set up. By broadcasting and receiving TSN messages carrying flight control data through each channel flight control simulator, and aligning and voting on the flight control data therein, the applicability of the TSN network to flight control data transmission and voting in a redundant flight control system is tested and verified.

[0006] In a first aspect, embodiments of this application provide a testing apparatus for a redundant flight control system, comprising: a plurality of flight control simulators, each flight control simulator being interconnected via a TSN network and synchronized with a clock server of the TSN network time, and cross-connected at the application layer via a CCDL bus; each flight control simulator simulating a flight controller of the flight control system; the TSN network loading background data packets with a set load, and setting the QCI parameters of the TSN network according to the maximum length of flight control data carried by a single TSN message; After obtaining flight control data for its own channel, each flight control simulator broadcasts a TSN message carrying that flight control data to flight control simulators on other channels via the TSN network. Each TSN message carrying control data includes a TSN timestamp at the time of its generation. The TSN network configures a QBV time slice for each TSN message carrying flight control data for each channel. Each flight control simulator retains the flight control data in TSN messages whose delay meets the deterministic requirement received from flight control simulators on other channels, aligns them with the flight control data of its own channel, and then votes on them to test the redundancy flight control data voting algorithm of the flight control system. Each TSN message whose delay meets the deterministic requirement is defined as one where the time difference between the time when the message is received and the TSN timestamp in the message is less than a set delay threshold.

[0007] As described above, the flight controller simulators are interconnected via the TSN network and synchronized with the clock server of the TSN network. At the application layer, cross-connection is implemented via the CCDL bus. Background traffic, QCI parameters, and QBV time slices are set in the TSN network to simulate the transmission of flight control data of each flight controller. By broadcasting and receiving TSN messages carrying flight control data through each channel flight controller simulator, as well as aligning and voting on the flight control data, the voting on flight control data of the redundant flight control system is simulated to test and verify the applicability of the TSN network to the redundant flight control system.

[0008] In one possible implementation of the first aspect, the flight control data obtained by each flight control simulator includes one of the following: aircraft state data simulated by the simulated sensors, simulated aircraft control commands sent to the control surface simulator; each flight control simulator obtains aircraft state data from the simulated sensors of its own channel via a TSN switch; the simulated sensors of each channel simulate sensors on the aircraft; each flight control simulator sends simulated aircraft control commands to the control surface simulator of its own channel via a TSN switch; and the control surface simulator of each channel simulates control surfaces on the aircraft.

[0009] As described above, the flight control simulator connects the simulated sensors and control surface simulator through the TSN switch to test the real-time performance of flight control data transmission between the flight controller and the connected aircraft sensors and control surface actuators, thereby further testing the applicability of the TSN network to the redundant flight control system.

[0010] In one possible implementation of the first aspect, the clock server of the TSN network is a GPTP clock server; the clock server is used to synchronize time with each TSN switch, each flight controller simulator, the simulated sensor, and the control surface simulator via the GPTP protocol; and to test the clock accuracy of each flight controller simulator, the simulated sensor, and the control surface simulator after time synchronization.

[0011] As described above, by synchronizing time between each flight controller simulator and the GPTP clock server of the TSN network, the equipment in each shift of the test device is aligned in absolute time, providing a unified time reference for verifying the consistency of flight control system actions in the TSN network.

[0012] In one possible implementation of the first aspect, the QBV time slice configured by the TSN network for sending TSN messages carrying flight control data for each channel is aligned with the working time slice of the operating system of the computing device where the flight control simulator of that channel is located for the task scheduling of obtaining the flight control data of that channel; after configuring the QBV time slice and the working time slice, the latency jitter and packet loss of the TSN messages carrying flight control data for each channel are tested to test the time determinism of the flight control data transmission in the TSN network.

[0013] Based on the above, the QBV time slice of the TSN message carrying the flight control data of each channel is configured in the TSN network and aligned with the working time slice configured on the computing device where the flight control simulator of that channel is located to obtain the flight control data of that channel. The latency jitter and packet loss of the TSN message carrying the flight control data are tested to eliminate the influence of the flight control simulator's operating system scheduling on the flight control data transmission delay in the TSN network, so as to accurately verify the determinism of the QBV protocol of the TSN network for the transmission of flight control data.

[0014] In one possible implementation of the first aspect, while sending TSN messages carrying flight control data in the TSN network, TSN messages with a payload length exceeding the length allowed by the QCI filtering parameters are also sent to test whether the two types of TSN messages are filtered in the TSN network.

[0015] Therefore, by testing the TSN network's filtering capabilities for TSN messages with payload lengths exceeding the allowable length of the QCI filtering parameters and TSN messages carrying flight control data, we can verify whether the TSN network meets the deterministic requirements for flight control data transmission when the load is heavy.

[0016] In one possible implementation of the first aspect, each flight controller simulator is configured with several DMA channels between its CPU and TSN network card, and each DMA channel corresponds to a channel where the flight controller simulator is located; each TSN message also includes the channel identifier of the flight controller simulator carrying the flight control data; when the network card of each flight controller simulator receives flight control data from other channels, it transmits the received flight control data to the CPU of the flight controller simulator through the DMA channel corresponding to the channel identifier.

[0017] As described above, when each flight controller simulator's network card receives flight control data from other channels, it obtains the corresponding DMA channel based on the channel identifier in the TSN message. The received flight control data is then transmitted to the flight controller simulator's CPU via the DMA channel corresponding to the gauge. This allows for the reception of large amounts of flight control data without the need for processing by the flight controller simulator's CPU. This eliminates the impact of the flight controller simulator's CPU's delay in obtaining flight control data on the flight control data transmission delay in the TSN network, thus accurately verifying whether the flight control data transmission in the TSN network meets the real-time requirements.

[0018] In one possible implementation of the first aspect, when the flight control data for voting is a digitized analog quantity, the flight control data obtained by each flight control simulator itself and aligned with other flight control simulators constitute the voting dataset. When the voting dataset contains three or more data points and the difference between the maximum and minimum values ​​is less than or equal to the voting threshold, the voting dataset meets the voting conditions, and the mean or median of all flight control data points in the voting dataset is used as the voting data after voting. When the voting dataset contains only two flight control data points, the voting dataset meets the voting conditions, and the mean of the two flight control data points in the voting dataset is used as the voting data after voting. When the voting dataset contains only one flight control data point, the voting dataset meets the voting conditions, and the mean of that flight control data point is used as the voting data after voting. When the voting dataset does not meet the voting conditions, abnormal flight control data is deleted from the voting dataset based on the difference between the maximum and minimum values ​​and the difference between the second largest and minimum values ​​in the voting dataset, and then the next round of voting is conducted until the voting dataset meets the voting conditions.

[0019] As described above, the voting method covers all scenarios where the voting dataset meets the voting conditions. Furthermore, by removing abnormal data through the difference between the maximum and minimum values ​​and the difference between the second largest and minimum values ​​in the voting dataset, the voting dataset is gradually approximated to meet the voting conditions. This method not only has a small computational load but is also suitable for scenarios where flight control data with continuously changing values ​​is voted on. It solves the problem that the traditional majority voting method cannot be used for voting on flight control data with continuously changing values.

[0020] In one possible implementation of the first aspect, when the difference between the maximum and the second smallest value is greater than the voting threshold, the abnormal flight control data is the maximum value in the voting data set; when the difference between the second largest and the minimum value is greater than the voting threshold, the abnormal flight control data is the minimum value in the voting data set; when the difference between the maximum and the second smallest value and the difference between the second largest and the minimum value are both less than or equal to the voting threshold, the abnormal flight control data is the maximum or minimum value in the voting data set.

[0021] As described above, removing abnormal data by using the difference between the maximum and minimum values ​​and the difference between the second largest and minimum values ​​in the voting dataset covers all scenarios for deleting abnormal flight control data in the voting dataset, thus enabling the successive approximation of data in the flight control dataset to meet the voting conditions.

[0022] In one possible implementation of the first aspect, each TSN message also includes a checksum of the flight control data it carries. Each flight control simulator verifies the flight control data received from other flight control simulators based on the checksum and deletes flight control data that fails the verification.

[0023] As described above, each flight controller simulator verifies the flight control data received from other flight controllers based on the verification value of the flight control data, in order to verify the data isolation function when errors occur in the flight controller data transmission.

[0024] In one possible implementation of the first aspect, each TSN message carrying flight control data also includes a flow identifier and a sequence number of the flight control data it carries. Each flight control simulator aligns the flight control data of its own channel and the reserved other channels according to the flow identifier and the sequence number and then votes.

[0025] As described above, by aligning the flight control data of each channel according to the stream identifier and sequence number, each flight control simulator can vote on the redundant flight control data.

[0026] Secondly, embodiments of this application provide a testing method for a redundant flight control system. The method operates on a testing device for a redundant flight control system. The testing device includes: several flight control simulators, each interconnected via a TSN network and synchronized with a clock server of the TSN network time, and cross-connected at the application layer via a CCDL bus; each flight control simulator simulates a flight controller of the flight control system; the maximum length of flight control data carried by a single TSN message is set, and the QCI parameters of the TSN network are set accordingly, and a background data packet with a set load is loaded into the TSN network; after obtaining flight control data from its own channel, each flight control simulator transmits the data through the TSN network... The network broadcasts TSN messages carrying the flight control data to flight control simulators on other channels; each TSN message carrying control data includes a TSN timestamp when the message was generated; the TSN network configures a QBV time slice for each TSN message carrying flight control data from each channel; each flight control simulator retains the flight control data in TSN messages whose delay meets the deterministic requirement received from flight control simulators on other channels, aligns them with the flight control data of its own channel, and then votes on them to test the redundancy flight control data voting algorithm of the flight control system; each TSN message whose delay meets the deterministic requirement is defined as a TSN message whose time difference between the time when the message is received and the TSN timestamp in the message is less than a set delay threshold.

[0027] As described above, the flight controller simulators are interconnected via the TSN network and synchronized with the clock server of the TSN network. At the application layer, cross-connection is implemented via the CCDL bus. Background traffic, QCI parameters, and QBV time slices are set in the TSN network to simulate the transmission of flight control data of each flight controller. By broadcasting and receiving TSN messages carrying flight control data through each channel flight controller simulator, as well as aligning and voting on the flight control data, the voting on flight control data of the redundant flight control system is simulated to test and verify the applicability of the TSN network to the redundant flight control system.

[0028] In one possible implementation of the second aspect, the flight control data obtained by each flight control simulator includes one of the following: aircraft status data simulated by the simulated sensors, simulated aircraft control commands sent to the control surface simulator; each flight control simulator obtains aircraft status data from the simulated sensors of its own channel via a TSN switch; the simulated sensors of each channel simulate the sensors on the aircraft; each flight control simulator sends simulated aircraft control commands to the control surface simulator of its own channel via a TSN switch; the control surface simulator of each channel simulates the control surfaces on the aircraft.

[0029] As described above, the flight control simulator connects the simulated sensors and control surface simulator through the TSN switch to test the real-time performance of flight control data transmission between the flight controller and the connected aircraft sensors and control surface actuators, thereby further testing the applicability of the TSN network to the redundant flight control system.

[0030] In one possible implementation of the second aspect, the TSN network includes a GPTP clock server; the clock server is used to synchronize time with each TSN switch, each flight controller simulator, the simulated sensor, and the control surface simulator via the GPTP protocol; and to test the time-synchronized clock accuracy of each flight controller simulator, the simulated sensor, and the control surface simulator.

[0031] As described above, by synchronizing the clock of each flight controller simulator with the clock server of the TSN network for the GPTP clock server, the equipment of each shift in the test device is aligned in absolute time, providing a unified time reference for verifying the consistency of flight control system actions in the TSN network.

[0032] In one possible implementation of the second aspect, the QBV time slice configured by the TSN network for sending TSN messages carrying flight control data for each channel is aligned with the working time slice of the operating system of the computing device where the flight control simulator of that channel is located for the task scheduling of obtaining flight control data for that channel; after configuring the QBV time slice and the working time slice, the latency jitter and packet loss of the TSN messages carrying flight control data for each channel are tested to test the time determinism of the transmission of flight control data in the TSN network.

[0033] Therefore, the QBV time slice of the TSN message carrying the flight control data of each channel is aligned with the working time slice configured on the computing device where the flight control simulator of that channel is located to obtain the flight control data of that channel. The latency jitter and packet loss of the TSN message carrying the flight control data are tested to eliminate the impact of the flight control simulator's operating system scheduling on the flight control data transmission delay in the TSN network, so as to accurately verify the determinism of the QBV protocol of the TSN network for the transmission of flight control data.

[0034] In one possible implementation of the second aspect, while sending TSN messages carrying flight control data in the TSN network, TSN messages with a payload length exceeding the length allowed by the QCI filtering parameters are also sent to test whether the two types of TSN messages are filtered in the TSN network.

[0035] Therefore, by testing the TSN network's filtering capabilities for TSN messages with payload lengths exceeding the allowable length of the QCI filtering parameters and TSN messages carrying flight control data, we can verify whether the TSN network meets the deterministic requirements for flight control data transmission when the load is heavy.

[0036] In one possible implementation of the second aspect, each flight controller simulator is configured with several DMA channels between its CPU and TSN network card, and each DMA channel corresponds to a channel where the flight controller simulator is located; each TSN message also includes the channel identifier of the flight controller simulator carrying the flight control data; when the network card of each flight controller simulator receives flight control data from other channels, it transmits the received flight control data to the CPU of the flight controller simulator through the DMA channel corresponding to the channel identifier.

[0037] As described above, when each flight controller simulator's network card receives flight control data from other channels, it obtains the corresponding DMA channel based on the channel identifier in the TSN message. The received flight control data is then transmitted to the flight controller simulator's CPU through the corresponding DMA channel. This allows for the reception of large amounts of flight control data without the need for processing by the flight controller simulator's CPU. This eliminates the impact of the flight controller simulator's CPU's delay in obtaining flight control data on the flight control data transmission delay in the TSN network, thus accurately verifying whether the flight control data transmission in the TSN network meets the real-time requirements.

[0038] In one possible implementation of the second aspect, when the flight control data for voting is a digitized analog quantity, the flight control data obtained by each flight control simulator itself and aligned with other flight control simulators constitute the voting dataset. When the voting dataset contains three or more data points and the difference between the maximum and minimum values ​​is less than or equal to the voting threshold, the voting dataset meets the voting conditions, and the mean or median of all flight control data in the voting dataset is used as the voting data after voting. When the voting dataset contains only two flight control data points, the voting dataset meets the voting conditions, and the mean of the two flight control data points in the voting dataset is used as the voting data after voting. When the voting dataset contains only one flight control data point, the voting dataset meets the voting conditions, and the mean of that flight control data point is used as the voting data after voting. When the voting dataset does not meet the voting conditions, abnormal flight control data is deleted from the voting dataset based on the difference between the maximum and minimum values ​​and the difference between the second largest and minimum values ​​in the voting dataset, and then the next round of voting is conducted until the voting dataset meets the voting conditions.

[0039] As described above, the voting method covers all scenarios where the voting dataset meets the voting conditions. Furthermore, by removing abnormal data through the difference between the maximum and minimum values ​​and the difference between the second largest and minimum values ​​in the voting dataset, the voting dataset is gradually approximated to meet the voting conditions. This method not only has a small computational load but is also suitable for scenarios where flight control data with continuously changing values ​​is voted on. It solves the problem that the traditional majority voting method cannot be used for voting on flight control data with continuously changing values.

[0040] In one possible implementation of the second aspect, when the difference between the maximum and the second smallest value is greater than the voting threshold, the abnormal flight control data is the maximum value in the voting data set; when the difference between the second largest and the minimum value is greater than the voting threshold, the abnormal flight control data is the minimum value in the voting data set; when the difference between the maximum and the second smallest value, and the difference between the second largest and the minimum value are both less than or equal to the voting threshold, the abnormal flight control data is the maximum or minimum value in the voting data set.

[0041] As described above, removing abnormal data by using the difference between the maximum and minimum values ​​and the difference between the second largest and minimum values ​​in the voting dataset covers all scenarios for deleting abnormal flight control data in the voting dataset, thus enabling the successive approximation of data in the flight control dataset to meet the voting conditions.

[0042] In one possible implementation of the second aspect, each TSN message also includes a checksum of the flight control data it carries. Each flight control simulator verifies the flight control data received from other flight control simulators based on the checksum and deletes flight control data that fails the verification.

[0043] As described above, each flight controller simulator verifies the flight control data received from other flight controllers based on the verification value of the flight control data, in order to verify the data isolation function when errors occur in the flight controller data transmission.

[0044] In one possible implementation of the first aspect, each TSN message carrying flight control data also includes a flow identifier and a sequence number of the flight control data it carries. Each flight control simulator aligns the flight control data of its own channel and the reserved other channels according to the flow identifier and the sequence number and then votes.

[0045] As described above, by aligning the flight control data of each channel according to the stream identifier and sequence number, each flight control simulator can vote on the redundant flight control data. Attached Figure Description

[0046] Figure 1 This is a schematic diagram of the structure of a test device for a redundant flight control system according to an embodiment of this application;

[0047] Figure 2 This is a flowchart illustrating a test method for a redundant flight control system according to this application.

[0048] Figure 3 This is a schematic diagram of the structure of a test device for a redundant flight control system according to a second embodiment of this application;

[0049] Figure 4 This is a schematic diagram showing the alignment of the scheduling time of each task on a VMC with the QBV of the TSN in a second embodiment of the test device for a redundant flight control system according to this application.

[0050] Figure 5 This is a flowchart illustrating a second embodiment of a test method for a redundant flight control system according to this application.

[0051] Figure 6 This is a schematic diagram of the configuration result of a one-frame filter in Embodiment 2 of the test method for a redundant flight control system of this application. Detailed Implementation

[0052] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0053] In the following description, the terms “first, second, third, etc.” or module A, module B, module C, etc. are used only to distinguish similar objects or different embodiments, and do not represent a specific ordering of objects. It is understood that a specific order or sequence may be interchanged where permitted so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0054] In the following description, the labels of the steps, such as S110, S120, etc., do not necessarily mean that the steps will be executed in this way. The order of the steps can be interchanged or executed simultaneously if permitted.

[0055] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0056] This application provides a testing device and method for a redundant flight control system. The testing device includes several flight control simulators, which are interconnected via a TSN network and cross-connected at the application layer via a CCDL bus. The flight control system includes several flight controllers, with each flight control simulator simulating one flight controller. After obtaining the flight control data of the aircraft, each flight control simulator broadcasts a TSN message carrying the flight control data to other flight control simulators through the TSN network. Each TSN message carrying control data includes a TSN timestamp at the time of its generation, a flow identifier of the flight control data it carries, and a sequence number. The flight control data obtained by each flight control simulator includes one of the following: aircraft state data simulated by simulated sensors, or simulated aircraft control commands sent to the control surface simulator. Each flight control simulator retains the flight control data in TSN messages received from other flight control simulators that meet the deterministic delay requirement. Each TSN message that meets the deterministic delay requirement is defined as having a time difference between the time it was received and the TSN timestamp in the message that is less than a set delay threshold. Each flight control simulator aligns its own obtained and retained flight control data from other flight control simulators according to the flow identifier and the sequence number, and then votes to obtain the voted flight control data, thereby verifying the voting algorithm for redundant flight control data of the flight controller in the TSN network.

[0057] In the technical solution of this application embodiment, the flight controller simulators are interconnected through a TSN network and synchronized with the clock server of the TSN network. At the application layer, cross-connection is implemented through a CCDL bus. Background traffic, QCI parameters, and QBV time slices are set in the TSN network to simulate the transmission of flight control data of each flight controller in the TSN network. By broadcasting and receiving TSN messages carrying flight control data through each channel flight controller simulator, as well as aligning and voting on the flight control data therein, the flight control data voting of the redundant flight control system is simulated to test and verify the applicability of the TSN network to the redundant flight control system.

[0058] The embodiments of this application are described below with reference to the accompanying drawings. First, the terminology involved in the embodiments of this application will be introduced.

[0059] CCDL bus (Cross-Channel Data Link bus) is a high-efficiency data communication technology for industrial automation and embedded systems. It mainly improves the reliability and real-time performance of communication through a multi-channel cross-transmission mechanism. It is widely used in redundant communication between devices and complex monitoring systems. In flight control systems, it enables data synchronization and communication between redundant flight control computers.

[0060] Time-Sensitive Networking (TSN) is an Ethernet enhancement standard developed by the IEEE 802.1 working group. It aims to provide microsecond-level deterministic latency and high-precision time synchronization for mission-critical applications, and is widely used in real-time control fields such as the Industrial Internet, intelligent vehicles, and rail transportation. Time synchronization (IEEE 802.1AS) allows all devices to share a unified time base, ensuring coordinated and consistent actions. Traffic scheduling and shaping (IEEE 802.1Qbv) allocates dedicated transmission time slots to data of different priorities, allowing high-priority data to preempt low-priority traffic and avoid congestion.

[0061] DMA (Direct Memory Access) channels are hardware mechanisms that allow direct data transfer between peripherals and memory, or between memory and peripherals, without the CPU's full involvement, thus significantly improving system efficiency. DMA implements data transfer through a DMA controller (DMAC): the CPU only configures parameters such as source address, destination address, and transfer length during initialization; subsequently, the DMA controller takes over the system bus and directly completes the data transfer; after the transfer is complete, the DMA sends an interrupt notification to the CPU, indicating that the task is complete.

[0062] The following is combined with Figure 1 and Figure 2 This application introduces a test apparatus embodiment for a redundant flight control system and a test method embodiment for a redundant flight control system.

[0063] Figure 1 The structure of a test device for a redundant flight control system is shown in Embodiment 1, including: a flight control simulator with several channels, each flight control simulator is interconnected through a TSN network and the clock server of the TSN network is time-synchronized, and they are cross-connected at the application layer through a CCDL bus.

[0064] The tested flight control system also included several flight controllers interconnected via a TSN network. Each flight controller simulator simulated a flight controller receiving and sending flight control data, as well as voting on the flight control data. Each channel's flight controller simulator interacted with other channels' flight controller simulators via TSN messages. The flight control data of each channel's flight controller simulator was redundant.

[0065] The test conditions for setting up a redundancy flight control system in the TSN network include: loading background data packets with a set load, including data packets of various priorities, to simulate the TSN network environment of the flight control system; setting the QCI parameters of the TSN network according to the maximum length of flight control data carried by a single TSN message to monitor TSN network traffic and load, and to activate the QCI protocol for filtering, thereby further simulating the TSN network environment of the flight control system; and setting a QBV time slice for each channel's TSN message carrying flight control data to transmit flight control data through the QBV protocol.

[0066] Each flight control simulator obtains flight control data including one of the following: simulated aircraft status data obtained from the simulated sensors in its own channel, or simulated aircraft control commands sent to the control surface simulator in its own channel, thereby simulating the reception, transmission, and voting of aircraft status data and aircraft control commands.

[0067] Each TSN message includes a TSN timestamp at the time of its generation. The TSN timestamp is used to determine whether the received TSN message meets the real-time requirements of the flight control data it carries. The flight control data is carried in the TSN message in the form of CCDL payload. Therefore, the flight control simulators are interconnected at the application layer via the CCDL bus.

[0068] In some implementations of this embodiment, each flight control simulator connects to the simulated sensor of its own channel via a TSN switch, obtains simulated aircraft state data from the simulated sensor of its own channel, and realizes the simulation of the sensors on the aircraft of the corresponding channel; each flight control simulator connects to the control surface simulator of its own channel via a TSN switch, sends simulated aircraft control commands to the control surface simulator of its own channel, and realizes the simulation of control surface control of its own channel.

[0069] In some implementations of this embodiment, each flight control simulator connects to the sensors on its own channel on the aircraft via a TSN switch to obtain aircraft status data, enabling the flight control simulator to collect real aircraft status data in real time via the TSN network; each flight control simulator connects to the control surfaces of its own channel via a TSN switch to send aircraft control commands to the control surfaces of its own channel, enabling the flight control simulator to control the control surfaces in real time via the TSN network.

[0070] In some embodiments of this example, the clock server of the TSN network is a gPTP clock server, used to synchronize time with each TSN switch, each flight controller simulator, the simulated sensors, and the control surface simulator via the gPTP protocol, enabling each TSN switch, flight controller simulator, sensor simulator, and control surface simulator to operate based on the same reference time; and testing the clock accuracy of each flight controller simulator, sensor simulator, and control surface simulator after constant synchronization. Each device in the testing apparatus is aligned in absolute time, providing a unified time reference for verifying the consistency of actions of the flight control system in the TSN network.

[0071] In some embodiments of this example, each flight controller simulator is implemented on a computing device using a time-division multiplexing real-time operating system. Obtaining flight control data for its own channel is a task for each flight controller simulator on that computing device. The QBV time slice configured by the TSN network for each flight control data stream of each flight controller simulator during the TSN scheduling cycle is aligned with the working time slice configured by the operating system of the computing device hosting the flight controller simulator for the task of obtaining flight control data for its own channel during the scheduling cycle. This achieves alignment between the task time scheduling of each flight controller simulator and the transmission time in the TSN network, improving the time determinism of the flight controller simulator's tasks. After configuring the aforementioned QBV time slice and working time slice in the TSN network, the latency jitter and packet loss of the TSN packets carrying flight control data for each channel are tested to test the actual determinism of flight control data transmission. Furthermore, the influence of the flight controller simulator's operating system scheduling on the flight control data transmission delay in the TSN network is eliminated to accurately verify the actual determinism of the TSN network's QBV protocol for flight control data transmission.

[0072] In some implementations of this embodiment, in the TSN network, for each TSN message carrying flight control data, the QCI filtering parameters of the TSN message are configured according to the source flight controller simulator, the target flight controller simulator, and the maximum allowed flight control data length in a single TSN message; a TSN message with a payload length exceeding the allowed length of the QCI filtering parameters is sent, and it is tested whether this TSN message and the TSN message carrying flight control data are filtered. By testing TSN messages with payload lengths exceeding the allowed length of the QCI filtering parameters and TSN messages carrying flight control data, it is verified whether the deterministic transmission of flight control data is satisfied under high load in the TSN network.

[0073] In some embodiments of this example, each flight controller simulator has several DMA channels between its CPU and network interface card (NIC), with each DMA channel corresponding to a flight controller simulator on a given channel. Each TSN message also includes the channel identifier of the flight controller simulator carrying the flight control data. When the NIC of each flight controller simulator receives flight control data from other channels, it transmits the received flight control data to the CPU of that flight controller simulator through the DMA channel corresponding to the channel identifier in the flight control data, improving the real-time performance of flight control data reception. When each flight controller simulator broadcasts its own channel's flight control data through TSN messages, it transmits the flight control data to be broadcast from the CPU to the NIC of that flight controller simulator through the DMA channel corresponding to the channel identifier in the flight control data, improving the real-time performance of flight control data broadcasting. This also eliminates the impact of the delay in the flight controller simulator's CPU obtaining flight control data on the flight control data transmission delay in the TSN network, thus accurately verifying whether the flight control data transmission in the TSN network meets the real-time requirements.

[0074] In some implementations of this embodiment, each TSN message also includes a checksum, a stream identifier, and a sequence number of the flight control data it carries; wherein, the stream identifier and sequence number of the flight control data are used for flight control data alignment of each flight control simulator; and the checksum is used to verify the received flight control data.

[0075] Each flight control data stream identifier is generated based on its intended use and is different from the TSN stream identifier. The TSN stream identifier cannot be used to replace the flight control data stream identifier. Similarly, the sequence number of each flight control data stream is also different from the sequence number of the TSN data frame. The sequence number of the TSN data frame is meaningful within the same TSN stream, while the sequence number of the flight control data in this application is meaningful within the same flight control data stream identifier.

[0076] The following is combined with Figure 2 This document introduces a test method for a redundant flight control system, embodiment one. The method described in embodiment one is the working principle of a test device for a redundant flight control system. When executed on the test device of embodiment one, it possesses all its advantages.

[0077] Figure 2 The flowchart of a test method for a redundant flight control system is shown in Embodiment 1, including steps S110 to S130.

[0078] In step S110, after obtaining the flight control data of its own channel, each flight control simulator broadcasts a TSN message carrying the flight control data to the flight control simulators of other channels through the TSN network.

[0079] Each TSN message carrying flight control data includes a TSN timestamp when the message was generated.

[0080] In step S120, each flight controller simulator retains the flight control data in the TSN messages received from other flight controller simulators whose delays meet the deterministic requirements.

[0081] Specifically, each TSN message that meets the deterministic delay requirement is one in which the time difference between the time the message is received and the TSN timestamp in the message is less than a set delay threshold.

[0082] In particular, steps S110 and S120 verify the function of each flight controller simulator in receiving and sending flight control data in real time through the TSN network. When the delay of the TSN message carrying the flight control data received by each flight controller simulator meets the deterministic requirement, it verifies that the real-time performance of the flight controller in receiving and sending flight control data through the TSN network meets the requirements.

[0083] In step S130, each flight control simulator aligns its own channel's flight control data with the reserved data from other channels and then votes to obtain the voted flight control data.

[0084] This step tests the voting algorithm for the redundant flight control data of the corresponding flight controller. If the voted flight control data matches the prediction result of the voting algorithm, then the voting algorithm for the redundant flight control data of the flight controller passes the test.

[0085] In some embodiments of this example, each TSN message carrying flight control data also includes a checksum of the flight control data. After step S120 and before S130, each flight control simulator verifies the flight control data received from other flight control simulators based on the checksum, and deletes flight control data that fails the verification, thereby removing erroneous data transmitted by problematic flight control simulators. Each flight control simulator can simulate sending erroneous checksums.

[0086] In some implementations of this embodiment, each TSN message carrying flight control data also includes the flow identifier and sequence number of the flight control data it carries; each flight control simulator aligns the flight control data of its own channel and the reserved other channels according to the flow identifier and sequence number of the flight control data, so that flight control data that perform the same control function at the same time in different channels can vote together.

[0087] In some implementations of this embodiment, when the flight control data being voted is a digitized analog quantity, the flight control data aligned to each channel may differ numerically. The voting dataset is composed of the flight control data from each flight controller simulator's own channel and the flight control data aligned to it from other channels. The flight control data voting in this step includes the following process:

[0088] (1) When there are more than or equal to 3 data in the voting dataset and the difference between the maximum and minimum values ​​is less than or equal to the voting threshold, the voting dataset meets the voting conditions, and the mean of all flight control data in the voting dataset is used as the flight control data after voting.

[0089] (2) When there is only one flight control data in the voting dataset, the voting dataset meets the voting conditions, and the flight control data is used as the flight control data after voting;

[0090] (3) When there are only two flight control data in the voting dataset, the voting dataset meets the voting conditions. The average of these two flight control data or any one of the flight control data will be used as the flight control data after voting. As for whether it is the average or which flight control data, it will be determined based on the specific voting scheme and security.

[0091] (4) When the voting dataset does not meet the voting conditions, the abnormal flight control data is deleted from the voting dataset based on the difference between the maximum and minimum values ​​and the difference between the second largest and minimum values ​​in the voting dataset, and then the next round of voting is carried out until the voting dataset meets the voting conditions.

[0092] The above steps (1) to (3) cover all scenarios in which the voting dataset meets the voting conditions. In the above step (4), the voting dataset is made to approximate the voting conditions one by one. This not only has a small amount of computation, but is also suitable for voting scenarios of flight control data with continuously changing values. This solves the problem that the traditional majority voting method cannot be used for voting of flight control data with continuously changing values.

[0093] In some embodiments of this example, the aforementioned abnormal flight control data includes:

[0094] (1) When the difference between the maximum and the second smallest value in the voting data set is greater than the set voting threshold, the abnormal flight control data is the maximum value in the voting data set;

[0095] (2) When the difference between the second largest value and the smallest value in the voting data is greater than the set voting threshold, the abnormal flight control data is the smallest value in the voting data;

[0096] (3) When the difference between the maximum and the second smallest value, and the difference between the second largest value and the minimum value in the voting data are both less than or equal to the set voting threshold, the abnormal flight control data is the maximum or minimum value in the voting data.

[0097] The above steps (1) to (3) cover all scenarios with abnormal flight control data in the voting dataset, and all scenarios that meet the voting conditions.

[0098] In summary, in Embodiment 1 of the test device for a redundant flight control system, the flight control simulators are interconnected via a TSN network and synchronized with the clock server of the TSN network. At the application layer, cross-connection is implemented via a CCDL bus. Background traffic, QCI parameters, and QBV time slices are set in the TSN network to simulate the transmission of flight control data from each flight controller. By broadcasting and receiving TSN messages carrying flight control data through each channel flight control simulator, and aligning and voting on the flight control data, the voting on flight control data in the redundant flight control system is simulated to test and verify the applicability of the TSN network to the redundant flight control system.

[0099] The following is combined with Figures 3 to 6 This application introduces a second embodiment of a test apparatus for a redundant flight control system and a second embodiment of a test method for a redundant flight control system.

[0100] Embodiment 2 of a test device for a redundant flight control system is a specific implementation of Embodiment 1 of a test device for a redundant flight control system, and has all its advantages.

[0101] For ease of description, the flight control system to be tested in this embodiment includes four flight controllers connected via a TSN network, making it a quadruple-redundant flight control system.

[0102] Figure 3 The diagram illustrates the structure of a test apparatus for a redundant flight control system, as shown in Embodiment 2. The apparatus includes: VMC simulation interfaces 1-4, a GPTP clock server, a data aggregation switch, four TSN switches 1-4, simulation remote terminals 1-8, simulation interface units 1-4, and a test computer. The data aggregation switch is also a type of TSN switch. Each simulation interface unit is a control surface simulator, and each simulation remote terminal is a simulated sensor.

[0103] Each VMC emulation interface, each emulation remote terminal, and each emulation interface unit is equipped with a TSN network card and connected to the TSN network.

[0104] Each VMC emulation interface is implemented on a computing device, simulated by a CPU motherboard, TSN network card, and real-time operating system. It generates and receives flight control data traffic, simulating a flight controller. Each VMC emulation interface connects to a data aggregation switch, forming a quadruple-redundant CCDL bus interconnect at the application layer. The real-time operating system can be a time-sharing and partitioned RTOS.

[0105] Each simulation remote terminal uses the Xintai test instrument interface to simulate the sensor data source of the aircraft and communicates with the corresponding VMC simulation interface via a TSN switch. Each simulation remote terminal simulates the acquisition of aircraft status data by the aircraft sensors and sends it to the corresponding VMC simulation interface. Each simulation interface unit simulates the actuator of the control surface and receives control commands from the corresponding VMC simulation interface.

[0106] Each VMC emulation interface, its two connected emulation remote terminals, and one emulation interface unit constitute an independent channel. These channels are physically isolated from each other. For example, emulation remote terminals 1-2 and emulation interface unit 1 are connected to VMC emulation interface 1 via TSN switch 1. VMC emulation interface 1, emulation remote terminals 1-2, and emulation interface unit 1 form an independent hardware channel, known as channel 1.

[0107] TSN switches 1-4 and the data aggregation switch support the TSN protocol, enabling functions such as time synchronization, gating, and traffic scheduling within the TSN network. The data aggregation switch is used to implement the CCDL data exchange process and also to mirror traffic between TSN switches for analysis by the test computer. The test computer is connected to the data aggregation switch.

[0108] Each VMC simulation interface simulates the corresponding flight controller, encapsulates its own channel's flight control data into TSN messages, and sends them to other channel's VMC simulation interfaces through a data aggregation switch. The flight control data of each VMC simulation interface includes simulated aircraft status data obtained from its own channel's simulation remote terminal and simulated aircraft control surface control commands sent to its own channel's simulation interface unit.

[0109] Each TSN message carrying flight control data includes the following TSN frame: the TSN timestamp that generated the TSN message and its payload, namely CCDL data. The CCDL data frame header includes the corresponding flight control data's stream identifier, sequence number, channel number, and checksum. The flight control data stream identifier is based on the flight control data's path and differs from the TSN stream identifier. The flight control data channel corresponds to the channel through which the flight control data was acquired. When the flight control data is simulated aircraft status data, the CCDL data frame header also includes the TSN timestamp of the status data acquisition.

[0110] In the tested flight control system, each flight controller is also connected to the aircraft's sensors and control surface actuators via an independent TSN switch. The test setup in this embodiment fully simulates the connection relationships between the various devices in the flight control system, verifying the end-to-end real-time transmission of flight control data in this embodiment's test setup, which in turn verifies the end-to-end real-time transmission of flight control data in the flight control system. Verifying the voting on flight control data in the test setup of this embodiment also verifies the voting on flight control data within the flight control system.

[0111] The gPTP clock server provides a global clock reference and synchronizes time with TSN switches and data aggregation switches via the gPTP protocol. It also synchronizes time with each VMC emulation interface, each emulation remote terminal, and each emulation interface unit via the gPTP protocol.

[0112] Each VMC emulation interface, each emulation remote terminal, and each emulation interface unit is equipped with a TSN network card. The clock of each TSN network card is synchronized with the GPTP clock server. Each TSN network card can trigger a clock-based interrupt signal to verify whether each VMC emulation interface, each emulation remote terminal, and each emulation interface unit has achieved time synchronization based on the time accuracy of the interrupt signal.

[0113] Several DMA channels are established between the CPU of each VMC emulation interface and the TSN network card of that VMC emulation interface. Each DMA channel corresponds to the channel where the VMC emulation interface is located. Each TSN message also includes the channel identifier of the VMC emulation interface carrying the flight control data. The DMA channels are implemented through dual-channel RAM (DPRAM), and the DMA channels are managed by FPGA.

[0114] When each VMC emulation interface's network card receives flight control data from other VMC emulation interfaces, it obtains the corresponding DMA channel based on the channel identifier and transmits the received flight control data to the CPU of that VMC emulation interface via the DMA channel. Simultaneously, when each VMC emulation interface's CPU broadcasts a TSN message carrying its own channel's flight control data, it transmits that flight control data to the corresponding VMC emulation interface's TSN network card via the corresponding DMA channel. In scenarios involving time synchronization between the operating system and the TSN network, the DMA channel triggers rapid flight control data transmission from the network card to the CPU via an interrupt signal (second pulse interrupt) when receiving data.

[0115] Each simulation interface unit is implemented on a computing device using a time-division and partitioned RTOS operating system. Traditional TSN only focuses on time synchronization at the network and terminal MAC layers, failing to achieve application-layer time synchronization among multiple distributed nodes. To ensure deterministic transmission of high-security services in the flight control system, application-layer deterministic transmission is essential. Traditional TSN only focuses on the gating list scheduling mechanism at the network and terminal sides, neglecting the impact of uncertainties in operating system-level scheduling, thus undermining the intended use of TSN.

[0116] To achieve time determinism in end-to-end transmission of flight control data in the test device of this embodiment, each VMC simulation interface is installed on a flight management computer (VMC). A time-division RTOS operating system runs on this VMC. Periodic time synchronization between the RTOS and the TSN network card is used to synchronize the operating system clock and the TSN network clock, thus providing a unified time reference for task scheduling in each partition with the TSN network. A strong time-sensitive scheduling algorithm runs on each VMC simulation interface to meet the TSN's requirement for deterministic scheduling of real-time system tasks. The strong time-sensitive scheduling algorithm is a scheduling strategy based on a task time scheduler table. This scheduling strategy meets the requirements of the TSN protocol and formulates corresponding task scheduling strategies. The task execution cycle can be matched with the frame scheduling mechanism in TSN, thereby meeting the application's real-time requirements.

[0117] First, the time length of the time schedule is calculated on each VMC based on the number of tasks and the duration of each task. The time schedule is then created based on this time length. Each VMC simulation interface obtaining flight control data for its own channel is also considered a task on that VMC. Next, tasks need to be created according to business requirements and added to the time schedule, with start and duration settings configured in the schedule. These start and duration times must correspond to the gate switching time (QBV time) in the TSN. The scheduler of each VMC schedules tasks sequentially based on the tasks configured in the time schedule. Since the task execution time corresponds to the gate switching time in the TSN, each task obtaining flight control data for its own channel can send a TSN message carrying that channel's flight control data as soon as it runs.

[0118] Figure 4 This diagram illustrates the alignment of the scheduling time of each task on a VMC with the QBV of the TSN. The RTOS operating system is time-synchronized with the TSN network and has the same scheduling period. Tasks 1, 2, and 3 are scheduled on the VMC at time slice t0 within the scheduling period. Their TSN data streams are allocated to queue 1 in the TSN scheduling (corresponding to column G7 in the lower left of the diagram), and their QBV time slices are the same as t0 within the scheduling period. Similarly, Task 4 (Task 14) has a scheduling time slice of t2 within the VMC's scheduling period, and its TSN data stream also has a QBV time slice of t2 within the TSN scheduling period. Likewise, Tasks 5 and 6 have a scheduling time slice of t1 within the VMC's scheduling period, and their TSN data streams also have a QBV time slice of t1 within the TSN scheduling period.

[0119] The following is combined with Figures 5 to 6 This paper introduces a second embodiment of a test method for a redundant flight control system. The second embodiment of the test method for a redundant flight control system describes the working principle of a second embodiment of a test device for a redundant flight control system. When executed on the second embodiment of the test device for a redundant flight control system, it possesses all its advantages.

[0120] Figure 5 The flowchart of a test method for a redundant flight control system, embodiment two, is shown, including steps S210 to S270.

[0121] For ease of explanation, this embodiment will be described using an analog quantity in which the flight control data in the control command changes continuously as an example.

[0122] S210: Sensor Input: The simulation remote terminal of each channel simulates the aircraft's sensors to collect the aircraft's status data and sends the aircraft status data to the corresponding VMC simulation interface through its own channel's TSN switch.

[0123] S220: Parallel computing across four channels: Each channel's VMC simulation interface independently executes the same control law algorithm to generate control commands for the control surfaces.

[0124] S230: Broadcast Control Commands: Each channel's VMC emulation interface broadcasts the control commands it calculates to the VMC emulation interfaces of the other three channels via the data aggregation switch in the form of TSN messages, while simultaneously receiving control commands from other channels.

[0125] The control commands are carried in the form of CCDL in the TSN message. At the application layer, each VMC emulation interface sends control commands to the other three VMC emulation interfaces through the CCDL bus.

[0126] S240: Data Alignment and Comparison: Each channel's VMC emulation interface retains the TSN messages that meet real-time requirements received from other VMC emulation interfaces and obtains the flight control data within them; each channel's VMC emulation interface aligns its own and other control command flight control data according to the stream identifier and sequence number.

[0127] Specifically, the transmission delay of the TSN message is set to be less than Δt. Before sending control commands to the control surfaces, the system waits for Δt for a period of time. Within this time range, it receives flight control data from the VMC simulation interfaces of the other three channels and flight control data from its own channel.

[0128] S250: Fault Detection and Isolation: Each VMC simulation interface verifies the flight control data received from other channels based on the checksum value, and marks the channel containing the flight control data that fails the verification as an unhealthy channel.

[0129] S260: Control command voting: Each VMC emulation interface uses an appropriate voting algorithm based on the number and type of remaining healthy channels.

[0130] a) All four channels are healthy: Voting is performed according to the four-redundancy voting algorithm to obtain the voting value of the flight control data;

[0131] b) Three-channel health: Voting is performed according to the triple redundancy voting algorithm to obtain the voting value of the flight control data;

[0132] c) Two-channel health: Take the average of the flight control data from these two channels;

[0133] d) Single-channel health: Directly outputs the flight control data for this channel.

[0134] The process of the four-redundancy voting algorithm includes:

[0135] (1) The flight control data of the four effective channels are combined into a quadruple redundancy dataset, which is sorted in ascending order as X1, X2, X3, X4;

[0136] (2) Calculate the pairwise differences ΔX21, ΔX32, ΔX43, ΔX41, ΔX31, ΔX42;

[0137] (3) Compare each difference with the preset threshold L, and approximate the voting output step by step:

[0138] 4.3.1 If ΔX41≤L, then the four flight control data are consistent, satisfying the voting conditions, and the voting value V=(X1+X2+X3+X4) / 4;

[0139] 4.3.2 If ΔX41>L and ΔX31≤L and ΔX42≤L, then X1 and X4 are abnormal data, X2 and X3 satisfy the voting conditions, and the voting value V=(X2+X3) / 2;

[0140] 4.3.3 If ΔX41>L and ΔX31>L and ΔX42≤L, then X1 is abnormal data, X2, X3 and X4 are reliable, and the voting conditions are met. The voting value V=(X2+X3+X4) / 3;

[0141] 4.3.4 If ΔX41>L and ΔX42>L and ΔX31≤L, then X4 is abnormal data, X1, X2, and X3 are reliable, and the voting conditions are met. The voting value V=(X1+X2+X3) / 3.

[0142] 4.3.5 If none of the above conditions are met, then X1 and X4 are abnormal data, and X2 or X3 is taken as the voting value V=X2 or X3.

[0143] In this embodiment, the voting algorithm adopts the idea of ​​successive approximation. It first judges the overall consistency from the maximum deviation Δ41, and then gradually shrinks to the reliability judgment of local data clusters. Compared with the traditional full sort median method, it has low computational complexity and high real-time performance.

[0144] It should be noted that after deleting an abnormal data in steps 4.3.3 and 4.3.4 above, the process directly proceeds to the following triduplex voting process, and the obtained voting value is the same, which is also based on the idea of ​​successive approximation.

[0145] The triple-redundancy voting process includes the following steps:

[0146] (1) Sort the flight control data in the triple redundancy dataset in ascending order as X1, X2, X3;

[0147] (2) Calculate the pairwise differences ΔX21, ΔX32, and ΔX31;

[0148] (3) Compare each difference with the preset threshold L, and approximate the voting output step by step:

[0149] 3.3.1 If ΔX31≤L, then the three flight control data are consistent and the voting conditions are met. The voting value V=(X1+X2+X3) / 3;

[0150] 3.3.2 If ΔX31>L and ΔX21≤L and ΔX32≤L, then X1 and X3 are abnormal data, X2 is reliable, the voting conditions are met, and the voting value V=X2;

[0151] 3.3.3 If ΔX31>L and ΔX21>L and ΔX32≤L, then X1 is abnormal data, X2 and X3 are reliable, and the voting conditions are met. The voting value V=(X2+X3) / 2.

[0152] 3.3.4 If ΔX31>L and ΔX32>L and ΔX21≤L, then X2 is abnormal data, X1 and X2 are reliable, and the voting conditions are met. The voting value V=(X1+X2) / 2.

[0153] 3.3.5 If none of the above conditions are met, then X1 and X3 are abnormal data, and the median value X2 is taken as the voting value V=X2.

[0154] S270: Output commands to control surface simulator: Each channel's VMC simulation interface encapsulates the flight control data after its own vote into control commands and sends them to its own control surface simulator.

[0155] In some embodiments of this example, between steps S210 and S220, each VMC simulation interface votes on the received aircraft status data. The voting method is the same as the voting method for the data in the control commands in steps S230 to S260, and will not be described in detail here.

[0156] During the testing of the voting algorithm, mirror data from each TSN switch 1-4 and data from the data aggregation switch were obtained through a test computer. Based on the analysis of this data, the correctness of the voting results of each test VMC simulation interface was verified.

[0157] Before verifying the voting of flight control data in the flight control system by testing the VMC simulation interface, the real-time performance of the end-to-end transmission of flight control data in the flight control system is also verified by testing the end-to-end transmission delay of flight control data in the test device. This includes: clock accuracy testing of each TSN device in the test device, accuracy testing of QBV of TSN messages in the test device, and QCI filtering testing of TSN messages in the test device.

[0158] I. Clock accuracy test of each TSN device in the test setup.

[0159] Test method: Test the applicability of IEEE 802.1as (gPTP protocol) in single redundancy in the test device. For example, test the clock accuracy in VMC emulation interface 1, TSN switch 1, and emulation interface unit 1.

[0160] The testing process is as follows:

[0161] (1) Configure clock instance 0 on the above TSN device, with clock type as ord-bound and profile as 802.1as. Enable time synchronization on the port. The gPTP clock server is the clock master device, and VMC emulation interface 1, TSN switch 1, and emulation interface unit 1 are clock slave devices. Configure the PTP interface parameters between the master and slave devices, including message encapsulation, message transmission mode, message type, and message transmission interval.

[0162] (2) Configure clock priorities on the device: the clock priority of gPTP clock server is Priority1=10, the clock priority of VMC emulation interface 1 is Priority1=80, the clock priority of TSN switch 1 is Priority1=100, and the clock priority of emulation interface unit 1 is Priority1=140.

[0163] (3) View the clock source selection result and clock accuracy on the TSN switch 1 WEB page, VMC simulation interface 1 and simulation interface unit 1 serial port page.

[0164] The test results are as follows:

[0165] The clock source selection results for the TSN switch, VMC emulation interface 1, and emulation interface unit are gPTP clock server. The time of each device is stably synchronized with gPTP clock server, and the clock accuracy is better than 100ns, which meets expectations.

[0166] II. Accuracy test of TSN message QBV in the test device.

[0167] Test method: The accuracy of IEEE 802.1qbv in the TSN network card and TSN switch of the TSN device is determined by measuring the end-to-end TSN message transmission delay in the test device, including whether the QBV gating function is effective and whether the TSN message transmission delay meets the real-time requirements.

[0168] 1. QBV gating function testing process:

[0169] (1) Before voting at each VMC simulation interface, time synchronization is performed on each TSN device in the test device, and the task scheduling time of the operating system is also synchronized with the QBV time slice of the TSN network.

[0170] (2) Based on time synchronization, each VMC simulation interface starts sending simulated control commands after voting, and records the timestamp T1 of sending the control commands. After being transmitted through their respective TSN switches, the commands arrive at the timestamp T2 of their respective simulation interface units. Each VMC simulation interface obtains a transmission delay of T2-T1.

[0171] (3) Inject high-priority background traffic into the TSN network transmission path in each TSN switch, measure the link delay again, and obtain a new T2-T1 transmission delay for each VMC simulation interface.

[0172] The test results are as follows:

[0173] The transmission delay link delay T2-T1 of each VMC simulation interface remains unchanged (i.e., jitter is better than 1µs), indicating that the IEEE 802.1qbv function is effective.

[0174] 2. The test procedure for TSN message transmission delay is as follows:

[0175] (1) Configure QBV gating based on the abstract flight control data model.

[0176] The data model from each VMC emulation interface to its respective emulation interface unit is shown in Table 1. Each data packet is 128 bytes in size; the transmission period is 20ms. The QBV time slice is located at the same time slice as the task that generates the data packet on the VMC emulation interface.

[0177] Table 1

[0178]

[0179] The data model from each VMC emulation interface to other VMC emulation interface units via the CCDL bus is shown in Table 2. The data packet size is 128 bytes; the transmission period is 20ms. The QBV time slice position is consistent with the task time slice on the VMC emulation interface that generates the data packet.

[0180] Table 2

[0181]

[0182] (2) The data packets sent by each VMC simulation interface of the source node to the VMC simulation interface unit have a length range of 64-1518, a period of 20ms, 30 data packets of service level type TT (Time Triggered), and 20 data packets of service level type BE (Best Effort). (3) Packet capture at each simulation interface unit can receive 50 data packets, 30 TT packets and 20 BE packets per period. Observe the number of packet loss and transmission delay to evaluate the adaptability of the TSN network QBV in the flight control environment.

[0183] The test results are as follows:

[0184] With no packet loss, stable transmission latency, and stable message exchange cycle, the TSN network QBV is suitable for the flight control environment. This indicates that flight control data is suitable for being correctly transmitted in the TSN network according to the QBV time of the corresponding TSN message, and meets the deterministic requirements of flight control data transmission.

[0185] III. QCI filtering test of TSN messages in the test device.

[0186] IEEE 802.1qci provides flow filtering and policing capabilities to prevent traffic overload, thereby improving network security.

[0187] Test method: Test the applicability of 802.1QCI in a single redundancy test device. For example, test the 802.1QCI functionality of TSN switch 1.

[0188] The testing process is as follows:

[0189] (1) Configure TSN switch-1 with TSN stream id 1, matching source MAC 00-00-00-00-00-01 / ff-ff-ff-ff-ff-ff, create a stream filter instance 100 to manage TSN stream id 1, and configure SDU size to 1200 bytes. The SDU size can be determined based on the largest data packet of flight control data corresponding to TSN stream id 1 in the TSN message.

[0190] Figure 6 The configuration result of the filter is shown. The filter name is filter 1, which filters the stream with stream id 1. The maximum allowed payload is 1200 (max-sdu 1200). The filter is enabled.

[0191] (2) Configure a flow in VMC simulation interface 1 with source MAC address 00-00-00-00-00-01, 30 packets, and a packet size of 1200 bytes. Send the flow to TSN switch 1. Observe the number of received flows forwarded to simulation interface 1 by TSN switch 1 on the serial port page of simulation interface unit 1. The expected result is 30.

[0192] (3) Configure a flow in VMC simulation interface 1 with source MAC address 00-00-00-00-00-01, 30 packets, and a packet size of 1300 bytes, and send the flow to TSN switch 1. Observe the number of received flows forwarded to simulation interface 1 by TSN switch 1 on the serial port page of simulation interface unit 1. The expected result is 0.

[0193] The test results are as follows:

[0194] 30 packets of 1200 bytes each were received, and 0 packets of 1300 bytes each were received, which complies with the IEEE 802.1 QCI security filtering requirements. In this experiment, packets with a total length greater than 1222 bytes were discarded. When the test packet carried flight control data, it indicates that the flight control data was filtered according to the QCI filtering parameters of the corresponding TSN stream.

[0195] Messages with a total length greater than 1222 bytes are filtered out. QCI max SDU controls the size of the Ethernet frame payload, which needs to be calculated after removing the Layer 2 encapsulation length. In the test case, the payload size is 1200 bytes + MAC header (12 bytes) + VLAN header (4 bytes) + ethtype (2 bytes) + CRC (4 bytes), totaling 1222 bytes. Therefore, frames exceeding 1222 bytes will be discarded.

[0196] Note that the above are merely preferred embodiments and the technical principles employed in this application. Those skilled in the art will understand that this application is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of this application. Therefore, although this application has been described in detail through the above embodiments, this application is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of this application, all of which fall within the scope of protection of this application.

Claims

1. A test apparatus for a redundant flight control system, characterized in that, include: Several flight control simulators are interconnected via a TSN network and synchronized with a clock server of the TSN network. They are also cross-connected at the application layer via a CCDL bus. Each flight control simulator simulates a flight controller of the flight control system. The TSN network loads background data packets with a set load, and sets the QCI parameters of the TSN network according to the maximum length of flight control data carried by a single TSN message; After obtaining the flight control data for its own channel, each flight control simulator broadcasts a TSN message carrying the flight control data to other flight control simulators through the TSN network. Each TSN message carrying control data includes a TSN timestamp when the message was generated. The TSN network configures a QBV time slice for the TSN message carrying flight control data for each channel. Each flight controller simulator retains flight control data from TSN messages whose delay meets the deterministic requirement received from other flight controller simulators, and aligns them with the flight control data of its own channel before voting to test the redundancy flight control data voting algorithm of the flight control system; each TSN message whose delay meets the deterministic requirement is defined as a message whose time difference between the time it is received and the TSN timestamp in the message is less than a set delay threshold.

2. The testing apparatus according to claim 1, characterized in that, The flight control data obtained by each flight control simulator includes one of the following: aircraft state data simulated by the simulated sensors, or simulated aircraft control commands sent to the control surface simulator; Each flight controller simulator obtains aircraft status data from the simulated sensors on its own channel via a TSN switch; the simulated sensors on each channel simulate the sensors on the aircraft. Each flight control simulator sends simulated aircraft control commands to the control surface simulators on its own channel via a TSN switch; each channel's control surface simulator simulates the control surfaces on the aircraft.

3. The testing apparatus according to claim 2, characterized in that, The clock server of the TSN network is a GPTP clock server. The clock server is used to synchronize time with each TSN switch, each flight controller simulator, the simulated sensor, and the control surface simulator via the GPTP protocol. The clock accuracy of each flight control simulator, the simulated sensor, and the control surface simulator after time synchronization was tested.

4. The testing apparatus according to claim 1, characterized in that, The QBV time slice configured by the TSN network for sending TSN messages carrying flight control data for each channel is aligned with the working time slice of the operating system of the computing device where the flight control simulator of that channel is located for the task scheduling to obtain the flight control data of this channel. After configuring the QBV time slice and the working time slice, test the latency jitter and packet loss of TSN messages carrying flight control data in each channel to verify the time determinism of flight control data transmission in the TSN network.

5. The testing apparatus according to claim 1, characterized in that, While sending TSN messages carrying flight control data in the TSN network, a TSN message with a payload length exceeding the allowed length of the QCI filtering parameter is also sent to test whether the above two types of TSN messages are filtered in the TSN network.

6. The testing apparatus according to claim 1, characterized in that, Each flight controller simulator is configured with several DMA channels between its CPU and TSN network card, and each DMA channel corresponds to the channel where the flight controller simulator is located. Each TSN message also includes the channel identifier of the flight controller simulator carrying the flight control data; when the network card of each flight controller simulator receives flight control data from other channels, it transmits the received flight control data to the CPU of the flight controller simulator through the DMA channel corresponding to the channel identifier.

7. The testing apparatus according to claim 1, characterized in that, When the flight control data being voted on is a digitized analog quantity, the voting dataset consists of the flight control data obtained by each flight control simulator itself and the flight control data of other flight control simulators that are aligned with it. When there are 3 or more data points in the voting dataset and the difference between the maximum and minimum values ​​is less than or equal to the voting threshold, or when there are only 2 flight control data points, the mean or median of all flight control data points in the voting dataset is used as the flight control data after voting. Otherwise, based on the difference between the maximum and minimum values ​​and the difference between the second largest and minimum values ​​in the voting dataset, abnormal flight control data is deleted from the voting dataset, and the next round of voting is conducted.

8. The testing apparatus according to claim 7, characterized in that, When the difference between the maximum and the second smallest value is greater than the voting threshold, the abnormal flight control data is the maximum value in the voting data set; When the difference between the second largest value and the smallest value is greater than the voting threshold, the abnormal flight control data is the minimum value in the voting data set; When the difference between the maximum and the second smallest value, and the difference between the second largest value and the minimum value are both less than or equal to the voting threshold, the abnormal flight control data is the maximum or minimum value in the voting data set.

9. The testing apparatus according to claim 1, characterized in that, Each TSN message carrying flight control data also includes the flow identifier, sequence number, and checksum of the flight control data it carries; Each flight controller simulator aligns its own channel and the reserved other channels' flight control data according to the stream identifier and the sequence number, and then votes. Each flight controller simulator verifies the flight control data of the other channels based on the verification value and deletes the flight control data that fails the verification.

10. A test method for a redundant flight control system, characterized in that, The method is run on a test device for redundant flight controllers, which includes: several flight controller simulators, each interconnected via a TSN network and synchronized with a clock server of the TSN network time, and cross-connected at the application layer via a CCDL bus; each flight controller simulator simulates a flight controller of the flight control system; Set the maximum length of flight control data carried by a single TSN message, and set the QCI parameters of the TSN network accordingly, and load background data packets with a set load into the TSN network; After obtaining the flight control data for its own channel, each flight control simulator broadcasts a TSN message carrying the flight control data to flight control simulators on other channels through the TSN network; each TSN message carrying control data includes a TSN timestamp when the message was generated. Each flight controller simulator retains flight control data from TSN messages whose delay meets the deterministic requirement received from other flight controller simulators, and aligns them with the flight control data of its own channel before voting to test the redundancy flight control data voting algorithm of the flight control system; each TSN message whose delay meets the deterministic requirement is defined as a message whose time difference between the time it is received and the TSN timestamp in the message is less than a set delay threshold.