A self-destruct circuit, system and aircraft for an aircraft

CN122569561APending Publication Date: 2026-08-14BEIJING INST OF RADIO METROLOGY & MEASUREMENT
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-29
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

此外,飞行器自毁程序启动前若未及时激活备用动力装置,飞行器坠地后残余燃料可能引发剧烈爆炸,造成严重的次生灾害

Benefits of technology

[0015]由以上技术方案可知,本申请采用解保控制与执行控制两级串联冗余架构,融合解保控制双指令和无源触发信号的双重控制逻辑,通过逻辑与和逻辑或协同配合实现性能互补,既依托多重冗余控制指令与逻辑闭锁方式规避单通道异常导致的误触发问题,保障系统安全运行。同时,本申请增加无源触发信号的时长校验与有效性判别机制,保证飞行器和级间分离后的分离段在安全距离范围内自毁。在此基础上,本申请结合飞行器级间物理分离状态联动激活备用自毁支路,对分离段备用动力装置进行兜底触发,有效解决飞行器分离段残余动力失控问题,充分消耗残余燃料,从根源上规避残余燃料爆炸引发的地面次生灾害、人员伤亡及财产损毁风险,同时可通过飞行器受控自毁避免核心技术泄露。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122569561A_ABST
    Figure CN122569561A_ABST
Patent Text Reader

Abstract

This application provides a self-destruct control circuit, system, and aircraft for an aircraft. The circuit includes: a release control module with two parallel branches, where the release control branch requires two self-destruct release commands to be activated simultaneously; and a backup release branch that can be activated in response to at least one release command and at least one aircraft separation passive trigger signal. The execution control module also has two parallel branches, where the self-destruct control branch outputs an ignition signal based on any one ignition command to drive the self-destruction pyrotechnics of the aircraft, and the backup self-destruct branch outputs a backup ignition signal based on a passive trigger signal of a specified duration to drive the self-destruction of the backup power unit pyrotechnics in the separation section. This application adopts a two-level series multi-redundancy architecture and a dual hardware and software trigger mechanism, combined with passive signal delay verification, to improve the reliability of self-destruct control and effectively avoid the risk of aircraft residual power runaway and secondary disasters.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of aircraft control technology, specifically relating to an aircraft self-destruct circuit, system, and aircraft. Background Technology

[0002] During the testing and mission execution of aircraft, situations such as loss of control or deviation from the predetermined trajectory due to hardware failure, abnormal software operation, or external environmental interference may occur, resulting in personal injury and property damage. In order to prevent technology leakage, a self-destruct control function is usually set up to enable the aircraft to self-destruct under control and eliminate safety hazards.

[0003] Existing aircraft self-destruct systems mostly employ a coordinated control mechanism of release and execution commands. However, in actual operation, due to hardware failures or software anomalies, even with a dual-redundancy architecture, it remains difficult to simultaneously meet the requirements of execution reliability and safety. When release control simply uses a logical AND relationship, failure of any node in the redundant channel will lead to release failure. If a simple logical OR relationship is used, a single-channel anomaly may cause false triggering. This contradictory relationship makes it difficult for the system to simultaneously meet the dual requirements of high reliability and high safety. Furthermore, if the backup power unit is not activated in time before the aircraft self-destruct procedure is initiated, residual fuel after the aircraft crashes may cause a violent explosion, resulting in serious secondary disasters. Therefore, there is currently a lack of aircraft self-destruct control technology that can simultaneously ensure high system reliability and high safety, avoid the drawbacks of single-logic judgment, effectively suppress false triggering, and avoid secondary disasters caused by residual fuel. Summary of the Invention

[0004] This application provides a self-destruct control circuit and system for an aircraft, which adopts a two-level series multi-redundancy architecture and a dual hardware and software triggering mechanism, combined with passive trigger signal delay verification, to improve the reliability of self-destruct control and effectively avoid the risk of aircraft residual power runaway and secondary disasters.

[0005] This application provides an aircraft self-destruct control circuit, including a deactivation control module and an execution control module connected in series; The protection release control module includes a protection release control branch and a backup protection release branch connected in parallel. The protection release control branch is activated in response to a first self-destruct protection release command and a second self-destruct protection release command to form an aircraft protection release control signal. The backup protection release branch is activated in response to at least one of the first self-destruct protection release command and the second self-destruct protection release command, as well as at least one of the first passive trigger signal and the second passive trigger signal formed by the separation between aircraft stages. The execution control module includes a self-destruct control branch and a backup self-destruct branch connected in parallel. The self-destruct control branch responds to at least one of the first self-destruct ignition command and the second self-destruct ignition command by conducting to form a self-destruct ignition signal for the aircraft. The self-destruct ignition signal is transmitted to the self-destruct pyrotechnic device of the aircraft to cause the aircraft to self-destruct. The backup ignition branch responds to at least one of the first passive trigger signal and the second passive trigger signal by conducting for a duration of more than a predetermined duration and forms a backup ignition signal. The backup ignition signal is transmitted to the backup power unit pyrotechnic device of the aircraft separation section to cause the aircraft separation section to self-destruct.

[0006] Optionally, the release control branch includes a first release switch and a first AND gate; The first AND gate forms a first closing instruction based on the first self-destruct unlock instruction and the second self-destruct unlock instruction, and transmits it to the first unlock switch; The first release switch closes in response to the first closing command.

[0007] Optionally, the backup protection release branch includes a second protection release switch and a second OR gate; The second OR gate generates a second closing instruction based on the first self-destruct unlock instruction or the second self-destruct unlock instruction and transmits it to the second unlock switch; The second release switch closes in response to the second closing command.

[0008] Optionally, the backup protection release branch includes a third protection release switch and a third OR gate; The third OR gate generates a third closing command based on the first passive trigger signal or the second passive trigger signal and transmits it to the third release switch; The third release switch closes in response to the third closing command.

[0009] Optionally, the backup self-destruct branch includes a fourth execution control switch and a fourth OR gate; The fourth OR gate generates a fourth closing command based on the first passive trigger signal or the second passive trigger signal and transmits it to the fourth execution control switch; The fourth execution control switch closes in response to the fourth closing command.

[0010] Optionally, at least one of the first delay judgment module and the second delay judgment module corresponding to the first passive trigger signal and the second passive trigger signal determines whether the duration of the first passive trigger signal or the second passive trigger signal reaches or exceeds the predetermined duration. If the first delay judgment module or the second delay judgment module determines that the duration of the first passive trigger signal or the second passive trigger signal reaches or exceeds the predetermined duration, the output signal of the first delay judgment module or the second delay judgment module is valid.

[0011] Optionally, the first self-destruct ignition command and the second self-destruct ignition command are generated and output by the flight controller, and the flight controller outputs the first self-destruct ignition command or the second self-destruct ignition command under any of the following conditions: The flight controller analyzes the mission phase and flight status parameters of the aircraft in real time and determines that the current mission phase requires a self-destruct mission. The flight controller effectively receives the self-destruct control information sent by the external controller and determines that a self-destruct mission needs to be executed.

[0012] Optionally, the first passive trigger signal and the second passive trigger signal are hardware status signals that characterize the physical state between aircraft stages; When the spacecraft completes the mechanical separation between stages and the inter-stage structure is disengaged, the corresponding first passive trigger signal and the second passive trigger signal are both set to an active state.

[0013] An aircraft self-destruct control system includes an aircraft self-destruct control circuit as described in this embodiment.

[0014] An aircraft includes an aircraft self-destruct control system as described in this embodiment.

[0015] As can be seen from the above technical solutions, this application adopts a two-level serial redundant architecture of release control and execution control, integrating dual control logic of release control dual instructions and passive trigger signals. Through logical AND and OR operations, complementary performance is achieved. This relies on multiple redundant control instructions and logical interlocking to avoid false triggering caused by single-channel anomalies, ensuring safe system operation. Simultaneously, this application adds a duration verification and validity judgment mechanism for the passive trigger signal, ensuring that the aircraft and the separation segment after interstage separation self-destruct within a safe distance. Based on this, this application combines the physical separation state of the aircraft interstages with the activation of the backup self-destruct branch to trigger the backup power unit of the separation segment as a fallback, effectively solving the problem of residual power runaway in the aircraft separation segment, fully consuming residual fuel, and fundamentally avoiding the risk of secondary ground disasters, casualties, and property damage caused by residual fuel explosions. Furthermore, the controlled self-destruction of the aircraft prevents the leakage of core technologies. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a schematic diagram of the structure of an aircraft self-destruct control circuit according to an embodiment of this application; Figure 2 This is a circuit diagram of an aircraft self-destruct control according to an embodiment of this application. Detailed Implementation

[0018] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not limiting, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application can also be implemented in other embodiments without such specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods are omitted so as not to obscure the description of this application with unnecessary detail.

[0019] In this application embodiment, the collaborative control mechanism of release and execution commands has been widely used in various aircraft self-destruct schemes, and the dual-command redundancy architecture has become a common means to improve the basic reliability of the system. Existing aircraft self-destruct control schemes have obvious technical defects in practical engineering applications. The release control logic mostly adopts a single fixed logical AND-OR-OR discrimination mechanism. If the logical AND release is used alone, the failure of any node in the redundant channel will lead to release failure. If the logical OR release is used alone, a single channel abnormality may cause false triggering, making it impossible for the system to achieve both high reliability and high safety. At the same time, existing self-destruct schemes generally rely on active commands issued by the flight controller to complete the entire release and ignition execution process, without setting up independent passive backup trigger branches based on the actual physical hardware states such as mechanical separation and structural disengagement between aircraft stages. When the aircraft loses control and deviates from the predetermined trajectory due to hardware failure, software malfunction, external environmental interference, etc., the active control command fails, the self-destruct system loses its emergency response capability, and lacks a hardware fallback protection mechanism. Furthermore, existing technologies lack duration verification and validity assessment mechanisms for passive trigger signals, failing to guarantee that the aircraft and the separation stage after interstage separation will self-destruct within a safe distance. Moreover, existing self-destruct schemes only incorporate self-destruct control logic for the aircraft itself, neglecting to design backup power units for the residual power and fuel in the separation stage. If the aircraft crashes after a malfunction, the residual fuel could easily trigger a violent explosion, causing secondary disasters such as casualties and facility damage on the ground. The overall performance of existing aircraft self-destruct schemes is insufficient, unable to meet multiple usage requirements, and ill-suited for the high reliability and safety control needs under complex operating conditions.

[0020] Based on this, embodiments of this application provide an aircraft self-destruct control circuit, such as... Figure 1 and Figure 2 As shown, it includes a release control module 10 and an execution control module 11 connected in series; The self-destruction control module 10 includes a parallel self-destruction control branch 101 and a backup self-destruction branch 102. The self-destruction control branch 101 is activated in response to a first self-destruction self-destruction command and a second self-destruction self-destruction command to form an aircraft disintegration control signal. The backup self-destruction branch 102 is activated in response to at least one of the first self-destruction self-destruction command and the second self-destruction self-destruction command, as well as at least one of the first passive trigger signal and the second passive trigger signal formed by the separation of the aircraft module. The execution control module 11 includes a self-destruct control branch 111 and a backup self-destruct branch 112 connected in parallel. The self-destruct control branch 111 responds to at least one of the first self-destruct ignition command and the second self-destruct ignition command to form a self-destruct ignition signal for the aircraft. The self-destruct ignition signal is transmitted to the self-destruct pyrotechnic device of the aircraft to cause the aircraft to self-destruct. The backup ignition branch 112 responds to at least one of the first passive trigger signal and the second passive trigger signal to form a backup ignition signal. The backup ignition signal is transmitted to the backup power unit pyrotechnic device of the aircraft separation section to cause the aircraft separation section to self-destruct.

[0021] This application provides an aircraft self-destruct control circuit that adopts a two-stage serial redundant architecture of release control and execution control. It integrates dual control logic of release control dual commands and passive trigger signals, achieving complementary performance through logical AND and OR operations. This multi-redundant control command and logic interlocking method avoids false triggering caused by single-channel anomalies, ensuring safe system operation. Simultaneously, this application adds a duration verification and validity judgment mechanism for the passive trigger signal, ensuring that the aircraft and the separation segment after interstage separation self-destruct within a safe distance. Furthermore, this application combines the physical separation state of the aircraft interstages with the activation of the backup self-destruct branch 112 to provide a fallback trigger for the backup power unit of the separation segment. This effectively solves the problem of residual power runaway in the aircraft separation segment, fully consumes residual fuel, and fundamentally avoids the risk of secondary disasters, casualties, and property damage on the ground caused by residual fuel explosions. At the same time, controlled self-destruction of the aircraft prevents the leakage of core technologies.

[0022] In this embodiment, the serially arranged self-destruct control module 10 and execution control module 11 form the core architecture for implementing multi-level redundant self-destruct control. The two modules work in sequence to form a complete self-destruct control branch 111. The self-destruct control module 10, as the front-end self-destruct unit, is controlled by two parallel branches and logic gates. The self-destruct control branch 101 can only be activated when it simultaneously receives the first and second self-destruct commands. This dual-command interlocking mechanism effectively avoids mis-self-destruction caused by a single abnormal signal, ensuring the safety of the aircraft in normal flight. The backup self-destruct branch 102 is activated when either the first or second self-destruct self-destruct command is valid, or when either the first or second passive trigger signal generated by the separation of the aircraft module is valid. This solves the problem of self-destruction paralysis caused by a single command failure and also provides fallback self-destruction capabilities in the event of hardware failure, software malfunction, or external environmental interference (this application is not limited to these scenarios). It relies on passive trigger signals to complete fallback self-destruction, improving the system's fault tolerance.

[0023] The execution control module 11, as a back-end execution unit, works in conjunction with the front-end protection and deactivation module. It is also configured with three parallel branches to achieve redundant ignition control. The self-destruct control branch 111 includes a fifth execution control switch S5 and a sixth execution control switch S6 connected in parallel. The front end is connected to the protection and deactivation control module 10, and the back end generates a self-destruct ignition signal. The self-destruct control branch 111 responds to ignition-type active commands. If either the first self-destruct ignition command or the second self-destruct ignition command is valid, it will drive the fifth execution control switch S5 or the sixth execution control switch S6 to close, thereby conducting the self-destruct control branch 111 and generating a self-destruct ignition signal. After receiving the signal, the aircraft's self-destruct pyrotechnic device completes the aircraft's self-destruction. The backup self-destruct branch 112 incorporates a signal duration verification mechanism to monitor the duration of the first and second passive trigger signals in real time. Only when the signal duration reaches a preset threshold is it deemed a valid operating condition signal, and the backup ignition branch 112 is activated to generate a backup ignition signal. This ensures that the aircraft and the separation section after interstage separation self-destruct within a safe distance. The generated backup ignition signal is then transmitted to the backup power unit pyrotechnics in the separation section, independently completing the separation section's self-destruction operation. This fully consumes residual fuel, preventing secondary disasters caused by explosions after impact, and completely destroying the separation section structure, thus mitigating the risk of core technology leakage. The entire circuit, through its integrated design of complementary main and backup branches and signal duration verification, balances control safety, fault tolerance, and environmental adaptability, meeting the high reliability and high safety self-destruction control requirements of the aircraft under all operating conditions.

[0024] In alternative implementations, such as Figure 2 As shown, the unlock control branch 101 includes a first unlock switch S1 and a first AND gate T1; The first AND gate T1 forms a first closing instruction based on the first self-destruct unlocking instruction and the second self-destruct unlocking instruction, and transmits it to the first unlocking switch S1; The first release switch S1 closes in response to the first closing command.

[0025] In this specific example, the first AND gate T1 is a dual-input logic device specifically used to perform a logical AND operation on the first self-destruct and unlock commands and the second self-destruct and unlock commands. It is the core device for implementing unlocking and preventing false triggering. The two input terminals of the first AND gate T1 are independently connected to the first self-destruct and unlock commands and the second self-destruct and unlock commands, respectively. Both commands are active control level signals output by the aircraft controller. The first AND gate T1 will only output a valid first closing command when both input commands are simultaneously in a low-level state; if either command is invalid, the first AND gate T1 will not output a valid command, and the back-end switch will remain in the open state.

[0026] The first release switch S1 acts as a branch on / off actuator. Its control terminal is connected to the output terminal of the first AND gate T1. Under normal conditions, it is in the open state, blocking the transmission of the release control signal. When the first release switch S1 detects a valid first closing command from the front end, the switch contacts reliably close, and the entire release control branch 101 forms a complete circuit.

[0027] For example, during normal flight, at least one of the first self-destruct and protection release commands is high, the first AND gate T1 does not output a closing command, the first protection release switch S1 remains open, and the protection release control branch 101 is always in the open state, preventing the aircraft from being falsely protected or self-destructed. When the flight controller determines that a fault has occurred and the self-destruct procedure needs to be executed, the flight controller simultaneously issues two valid self-destruct and protection release commands. The first AND gate T1 completes the logical AND operation and outputs the first closing command, driving the first protection release switch S1 to close, and the branch is normally connected, strictly implementing the dual-command interlocking control logic, greatly improving the system's operational safety.

[0028] It should be noted that in this application, the input low-level signal of the AND gate and OR gate logic device is a valid state. Of course, in other embodiments, a high level can also be set as a valid state, which is a conventional technical means in the field. Those skilled in the art can set the signal level according to actual needs, and this application does not limit it in this regard.

[0029] In alternative implementations, such as Figure 2 As shown, the backup protection release branch 102 includes a second protection release switch S2 and a second OR gate T2; The second OR gate T2 forms a second closing instruction based on the first self-destruct unlock instruction or the second self-destruct unlock instruction and transmits it to the second unlock switch S2; The second release switch S2 closes in response to the second closing command.

[0030] In this specific example, the second OR gate T2 is an input logic device and the core component for the fault-tolerant triggering of the backup protection release branch 102. Its input terminals are connected to the first and second self-destruct protection release instructions. This device follows the OR operation rule: as long as any input signal is low, the second OR gate T2 can output a valid second closing instruction; only when all input signals are high will the second OR gate T2 not output a valid instruction. The second protection release switch S2 is the on / off execution component of the backup protection release branch 102. It is normally open, and its contacts close only when the second closing instruction is received, thus ensuring that the backup protection release branch 102 is switched on and off as needed. The entire branch relies on the OR operation characteristic, weakening the requirement for multiple instructions to be valid simultaneously. Even if a single branch has a normal active instruction, or relies solely on the passive trigger signal generated by inter-stage separation, protection release triggering can be completed, effectively solving the problem of protection release function paralysis due to single branch failure and improving the system's fault adaptability.

[0031] For example, when any self-destruct and protection release command from the flight controller is output normally, but other self-destruct and protection release commands are lost or abnormal, the second OR gate T2 can still recognize a valid signal and output a second closing command, driving the second protection release switch S2 to close, and the backup protection release branch 102 will work normally. This triggering hardware logic adapts to various fault conditions, ensuring the reliability of basic functions while significantly improving the fault redundancy capability of the protection release process by relying on the fault-tolerant characteristics of logical OR operations.

[0032] In alternative implementations, such as Figure 2 As shown, the backup protection release branch 102 includes a third protection release switch S3 and a third OR gate T3; The third OR gate T3 forms a third closing command based on the first passive trigger signal or the second passive trigger signal and transmits it to the third release switch S3; The third release switch S3 closes in response to the third closing command.

[0033] In a specific example, the third OR gate T3 is a dual-input hardware logic device. Its inputs are respectively connected to the first and second passive trigger signals generated by the separation of the aircraft stages. Both signals are hardware status level signals generated by the optocoupler after the separation of the aircraft's mechanical structure, indicating that the separation of the aircraft stages is complete. No active command is required from the onboard flight controller. The third OR gate T3 strictly follows the OR operation rules. As long as either of the two passive trigger signals is low, a valid third closing command is output. Only when both passive trigger signals are invalid will the third OR gate T3 output no valid command. The third release switch S3, as the on / off actuator of the backup release branch 102, is normally always in the off state, stably isolating the downstream self-destruct ignition signal and eliminating the risk of false triggering under non-separation conditions. It only reliably closes after receiving the third closing command output by the third OR gate T3. The third protection switch S3 is triggered entirely by hardware logic and the physical state of the aircraft's hierarchical separation. It does not rely on software program calculations or active command transmission. The hardware execution response speed is fast and the ability to resist abnormal software interference is strong. It can work independently in extreme failure scenarios such as failure of the airborne control system and complete loss of active commands.

[0034] For example, under normal flight conditions without separation, there is no passive trigger signal output, the third OR gate T3 has no valid command output, the third protection release switch S3 remains open, and the backup protection release branch 102 remains dormant and does not participate in protection release control. When the aircraft experiences a serious malfunction, onboard software anomaly, or active commands completely fail, and the aircraft completes interstage mechanical separation, a first passive trigger signal and a second passive trigger signal will be generated simultaneously. The validity of either signal will drive the third OR gate T3 to output a third closing command, controlling the third protection release switch S3 to close, activating the backup protection release branch 102 to complete the fallback protection release action. This hardware trigger logic eliminates dependence on the onboard control system, compensates for the shortcomings of active control links failing under extreme conditions, constructs hardware fallback protection capabilities during the aircraft separation phase, and significantly improves the fault tolerance limit and safety redundancy of the self-destruct control throughout the entire mission cycle.

[0035] In alternative implementations, such as Figure 2 As shown, the backup self-destruct branch 112 includes a fourth execution control switch S4 and a fourth OR gate T4; The fourth OR gate T4 forms a fourth closing command based on the first passive trigger signal or the second passive trigger signal and transmits it to the fourth execution control switch S4; The fourth execution control switch S4 closes in response to the fourth closing command.

[0036] In this specific example, the fourth OR gate T4 is a dual-input hardware logic device. Its inputs are respectively connected to the first and second passive trigger signals generated by the mechanical separation between the aircraft stages. Both passive trigger signals are physical state signals generated by the hardware switches that trigger the aircraft separation structure action. They do not require the flight controller to output an active ignition command and are completely independent of the flight controller. The fourth OR gate T4 uses a hardware logic OR discrimination mechanism. It does not require both signals to be valid simultaneously. As long as either passive trigger signal is low, it can be determined that the aircraft has completed a reliable stage separation, and then output a stable and valid fourth closing command. Only when both passive trigger signals are invalid will there be no command output, thus preventing false triggering. The fourth execution control switch S4, as a branch on / off execution device, is reliably disconnected under normal conditions, isolating the backend backup ignition signal output and avoiding the risk of false ignition in non-separation conditions throughout the flight. This branch circuit adopts a pure hardware link architecture. Logic discrimination, signal transmission, and switch conduction are all completed by hardware circuits. It does not rely on software program calculations, does not occupy flight controller resources, and is not affected by software crashes, command anomalies, electromagnetic interference, or other issues. The hardware has a fast response speed and high reliability under operating conditions. It can independently complete emergency ignition control when the active ignition link fails completely.

[0037] For example, under normal controllable flight conditions, no interstage mechanical separation occurs, no passive trigger signal is output, the fourth OR gate T4 does not output a valid fourth closing command, the fourth execution control switch S4 remains open, and the backup self-destruct branch 112 is in a locked dormant state, not outputting a backup ignition signal, thus ensuring the aircraft's normal flight safety. When the aircraft experiences extreme fault conditions such as flight control software failure, loss of active ignition command, or failure of the aircraft's self-destruct branch, and the aircraft has completed interstage mechanical separation, the separation structure triggers a hardware switch to generate a passive trigger signal. If either the first or second passive trigger signal is valid, it can drive the fourth OR gate T4 to output a fourth closing command, control the fourth execution control switch S4 to close, conduct the backup self-destruct branch 112 and output a backup ignition signal, activate the pyrotechnics of the separation section's backup power unit, and complete the separation section's last-ditch self-destruction. This hardware triggering logic effectively compensates for the shortcomings of the active ignition link failure, constructs an independent emergency self-destruct mechanism for the separation section, and completely eliminates the secondary risks of falling to the ground and the hidden dangers of technology leakage caused by residual fuel and residual structure in the separation section.

[0038] In an optional implementation, at least one of the first delay judgment module and the second delay judgment module corresponding to the first passive trigger signal and the second passive trigger signal determines whether the duration of the first passive trigger signal or the second passive trigger signal reaches or exceeds a predetermined duration. If the first delay judgment module or the second delay judgment module determines that the duration of the first passive trigger signal or the second passive trigger signal reaches or exceeds the predetermined duration, the output signal of the first delay judgment module or the second delay judgment module is valid.

[0039] It should be noted that those skilled in the art can use existing signal delay circuits to implement the function of the delay judgment module, or set the specific implementation method or specific circuit structure of the delay judgment module in actual applications according to the function of the delay judgment module. These are conventional technical means in the field and will not be elaborated here.

[0040] In a specific example, the first and second delay judgment modules are independently configured hardware duration verification units. They are matched one-to-one with the first and second passive trigger signals, respectively, to achieve independent and parallel duration monitoring of the two passive trigger signals, avoiding mutual interference from single-channel signal anomalies. The predetermined duration is the theoretical maximum separation duration calibrated based on the inter-stage separation safety distance of the aircraft. It is a fixed threshold parameter that can be pre-defined in the hardware verification module according to the aircraft model and separation conditions, without requiring real-time dynamic calculation by software. The core function of the delay judgment module is to distinguish between the continuous valid signals of the actual stage separation conditions and the instantaneous false signals generated by flight vibration, electromagnetic interference, and circuit jitter. Only continuous and stable valid signals are allowed, while ultra-short-term interference signals are directly blocked. The two delay judgment modules adopt a redundant parallel architecture. As long as either passive trigger signal passes the duration verification, it can be determined that the aircraft has completed safe separation and the signal status is real and reliable, providing effective preliminary basis for subsequent OR gate logic judgment and switch conduction.

[0041] It should be noted that the hardware duration verification mechanism relies entirely on hardware circuit timing and judgment, without the flight controller participating in the calculation. Even if the flight controller system malfunctions or the program freezes, it can still stably complete signal duration verification and validity judgment without problems such as verification failure, false judgment, or false triggering. At the same time, the independent dual-module redundant verification architecture not only improves the signal judgment accuracy and system anti-interference capability, but also takes into account system security, reliability, and real-time response.

[0042] Specifically, the interstage separation action of the aircraft is triggered by a preset flight program. When the aircraft's flight altitude and flight time reach the system's preset thresholds, the aircraft automatically completes reliable interstage separation, thereby triggering the generation of a passive trigger signal. This separation determination logic is based on the aircraft's inherent flight condition parameters, ensuring stable determination criteria and high condition identification. This guarantees that the passive trigger signal is stably generated only after the aircraft reaches the preset separation conditions, effectively avoiding the problem of erroneous signal generation under abnormal operating conditions. Simultaneously, combined with a hardware duration verification mechanism, the signal validity is double-screened, further ensuring the accuracy and safety of the backup self-destruct branch 112 trigger.

[0043] In an optional implementation, the first self-destruct ignition command and the second self-destruct ignition command are generated and output by the flight controller, and the flight controller outputs the first self-destruct ignition command or the second self-destruct ignition command under any of the following conditions: The flight controller analyzes the mission phase and flight status parameters of the aircraft in real time and determines that the current mission phase requires a self-destruct mission. The flight controller effectively receives the self-destruct control information sent by the external controller and determines that a self-destruct mission needs to be executed.

[0044] In a specific example, the first and second self-destruct ignition commands are the core command signals for the autonomous self-destruct control of the aircraft. The flight controller has the ability to analyze the aircraft's flight status in real time, and can collect multi-dimensional flight status parameters such as flight altitude, flight attitude, flight speed, trajectory deviation, and hardware operating status throughout the entire flight. Combined with the preset flight mission phase division logic, it matches the current flight mission phase of the aircraft in real time. When the aircraft deviates from the preset flight trajectory, exhibits abnormal attitude, experiences hardware failure, or exceeds the safe flight airspace, and it is determined that the current mission phase cannot be completed normally and there is a safety risk, the flight controller meets the onboard autonomous self-destruct trigger conditions and actively generates and outputs the self-destruct ignition command. At the same time, the flight controller reserves an external control interaction interface, which can receive aircraft self-destruct control information issued by external controllers such as ground stations and host computers in real time, perform validity verification on external commands, and when the verification passes and it is determined that a self-destruct mission needs to be executed, it passively responds to the external commands to generate and output the self-destruct ignition command. The two triggering conditions are independent of each other and redundant. As long as either condition is met, the flight controller can output the corresponding first self-destruct ignition command or the second self-destruct ignition command, providing a reliable command input for the active controlled self-destruction of the aircraft.

[0045] For example, when the aircraft is flying normally along the preset route and mission phase, the flight controller analyzes the flight status parameters and finds them normal with no risk of failure. Since it has not received any external self-destruct control information, it does not generate any self-destruct ignition command, and the aircraft maintains normal flight conditions. The aircraft will reach the preset uninhabited desert or ocean during the inter-stage separation phase. However, if the aircraft experiences internal anomalies such as attitude loss, trajectory deviation exceeding thresholds, or power system failure during flight, the flight controller autonomously determines the need for self-destruction by analyzing flight parameters in real time, and then outputs the first and second self-destruct ignition commands. Alternatively, if the aircraft's flight status is not significantly abnormal, but the ground control terminal issues external self-destruct control information based on airspace safety and mission control requirements, the flight controller, after verifying the command's validity, responds to the external command by outputting the corresponding self-destruct ignition command, initiating the aircraft's active controlled self-destruct process, comprehensively ensuring aircraft flight safety and airspace control compliance.

[0046] In an optional implementation, the first passive trigger signal and the second passive trigger signal are hardware status signals characterizing the physical state between aircraft stages; When the spacecraft completes the mechanical separation between stages and the inter-stage structure is disengaged, the corresponding first passive trigger signal and the second passive trigger signal are both set to an active state.

[0047] In a specific example, interstage separation is a pre-programmed flight maneuver, a fixed condition designed by the aircraft based on its own flight mission profile. When the aircraft reaches a preset flight altitude and time point, it automatically triggers the interstage unlocking and mechanical disengagement process. By jettisoning the weight of useless stage structures, the flight trajectory is optimized, ensuring the stable conduct of subsequent flight missions. The first and second passive trigger signals are hardware status signals generated based on this physical separation condition. Unlike the active command signals issued by the flight controller, they do not require software program calculations and are passively triggered entirely by the actual physical state of the aircraft. The flight altitude and flight time thresholds used to determine the separation timing are fixed parameters pre-defined based on the aircraft's ballistic characteristics and mission conditions. They can be flexibly calibrated to adapt to the mission requirements of different aircraft models, accurately defining the standard separation node. When the aircraft's flight parameters meet the standards, and the interstage structure is completely separated, with no contact or jamming at the separation surface and the separation in place, the hardware switch associated with the separation surface will stably flip. The hardware circuit will passively identify this effective separation condition and simultaneously set the two passive trigger signals to low level. This can provide a true and objective feedback on the physical state of the aircraft's successful separation. This signal generation method is not affected by software crashes, abnormal commands, or electromagnetic interference, and the reliability of condition identification is extremely high.

[0048] It should be noted that the effective setting conditions of the passive trigger signals are strictly bound to the preset flight profile and physical separation state of the aircraft. The triggering logic is rigorous and highly fault-tolerant, and is only effective under standard operating conditions where the aircraft's altitude and time parameters meet the requirements and mechanical separation is in place. Under abnormal operating conditions such as flight parameters not meeting the requirements, separation mechanism jamming, or structure not detaching, both passive trigger signals remain invalid. For example, the aircraft separation altitude can be preset to 50km and the separation flight time to 80s. After the aircraft flies normally to the corresponding operating condition parameters and completes reliable separation, the passive trigger signals become effective synchronously. If the flight is terminated prematurely, the parameters are not met, or separation fails, the signals remain invalid. This effectively avoids the problem of false triggering of the backup self-destruct branch 112 under non-design conditions, ensuring the safety and rigor of the hardware-based self-destruct control logic from the source.

[0049] This embodiment provides an aircraft self-destruct control system that executes the aircraft self-destruct control circuit as described in this embodiment.

[0050] In a specific example, the aircraft self-destruct control system uses the aircraft self-destruct control circuit as its core hardware carrier, integrating multiple levels of hardware logic branches, signal delay verification modules, and pyrotechnic actuators to form a highly reliable safety control system that combines hardware and software collaboration with primary and backup complementarity. The system is divided into a deactivation / protection level and an ignition execution level. The two levels of modules work in series, strictly adhering to the safety control logic of deactivation before ignition, thus eliminating the risk of accidental ignition and accidental self-destruction from the process perspective.

[0051] This embodiment provides an aircraft that includes the self-destruct control system described in this embodiment.

[0052] In a specific example, this aircraft is a multi-stage flight device equipped with a redundant and highly reliable self-destruct protection system. The overall hardware architecture includes a flight controller, inter-stage separation mechanism, hardware status acquisition switch, self-destruct pyrotechnics, backup power pyrotechnics, and a built-in aircraft self-destruct control system. The self-destruct control system runs through the entire mission cycle of the aircraft, from takeoff, cruise, stage separation, to flight termination.

[0053] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A self-destruct control circuit for an aircraft, characterized in that, It includes a series-connected release control module and an execution control module; The protection release control module includes a protection release control branch and a backup protection release branch connected in parallel. The protection release control branch is activated in response to a first self-destruct protection release command and a second self-destruct protection release command to form an aircraft protection release control signal. The backup protection release branch is activated in response to at least one of the first self-destruct protection release command and the second self-destruct protection release command, as well as at least one of the first passive trigger signal and the second passive trigger signal formed by the separation between aircraft stages. The execution control module includes a self-destruct control branch and a backup self-destruct branch connected in parallel. The self-destruct control branch responds to at least one of the first self-destruct ignition command and the second self-destruct ignition command by conducting to form a self-destruct ignition signal for the aircraft. The self-destruct ignition signal is transmitted to the self-destruct pyrotechnic device of the aircraft to cause the aircraft to self-destruct. The backup ignition branch responds to at least one of the first passive trigger signal and the second passive trigger signal by conducting for a duration of more than a predetermined duration and forms a backup ignition signal. The backup ignition signal is transmitted to the backup power unit pyrotechnic device of the aircraft separation section to cause the aircraft separation section to self-destruct.

2. The aircraft self-destruct control circuit according to claim 1, characterized in that, The protection release control branch includes a first protection release switch and a first AND gate; The first AND gate forms a first closing instruction based on the first self-destruct unlock instruction and the second self-destruct unlock instruction, and transmits it to the first unlock switch; The first release switch closes in response to the first closing command.

3. The aircraft self-destruct control circuit according to claim 1, characterized in that, The backup protection release branch includes a second protection release switch and a second OR gate; The second OR gate generates a second closing instruction based on the first self-destruct unlock instruction or the second self-destruct unlock instruction and transmits it to the second unlock switch; The second release switch closes in response to the second closing command.

4. The aircraft self-destruct control circuit according to claim 1, characterized in that, The backup protection release branch includes a third protection release switch and a third OR gate; The third OR gate generates a third closing command based on the first passive trigger signal or the second passive trigger signal and transmits it to the third release switch; The third release switch closes in response to the third closing command.

5. The aircraft self-destruct control circuit according to claim 1, characterized in that, The backup self-destruct branch includes a fourth execution control switch and a fourth OR gate; The fourth OR gate generates a fourth closing command based on the first passive trigger signal or the second passive trigger signal and transmits it to the fourth execution control switch; The fourth execution control switch closes in response to the fourth closing command.

6. The aircraft self-destruct control circuit according to claim 1, characterized in that, At least one of the first delay judgment module and the second delay judgment module corresponding to the first passive trigger signal and the second passive trigger signal determines whether the duration of the first passive trigger signal or the second passive trigger signal reaches or exceeds the predetermined duration; If the first delay judgment module or the second delay judgment module determines that the duration of the first passive trigger signal or the second passive trigger signal reaches or exceeds the predetermined duration, the output signal of the first delay judgment module or the second delay judgment module is valid.

7. The aircraft self-destruct control circuit according to claim 1, characterized in that, The first self-destruct ignition command and the second self-destruct ignition command are generated and output by the flight controller. The flight controller outputs the first self-destruct ignition command or the second self-destruct ignition command under any of the following conditions: The flight controller analyzes the mission phase and flight status parameters of the aircraft in real time and determines that the current mission phase requires a self-destruct mission. The flight controller effectively receives the self-destruct control information sent by the external controller and determines that a self-destruct mission needs to be executed.

8. The aircraft self-destruct control circuit according to claim 1, characterized in that, The first passive trigger signal and the second passive trigger signal are hardware status signals that characterize the physical state between aircraft stages; When the spacecraft completes the mechanical separation between stages and the inter-stage structure is disengaged, the corresponding first passive trigger signal and the second passive trigger signal are both set to an active state.

9. A self-destruct control system for an aircraft, characterized in that, Includes the aircraft self-destruct control circuit as described in any one of claims 1-8.

10. An aircraft, characterized in that, Including the aircraft self-destruct control system as described in claim 9.