Dual power and triple redundancy single point failure handling system

CN122660199APending Publication Date: 2026-08-28ZERO GRAVITY NANJING AIRCRAFT IND CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610740459.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-27
Publication Date
2026-08-28

AI Technical Summary

Technical Problem

针对现有技术的不足,本发明提供了一种双电源与三冗余的单点故障处理系统,具备实现全链路供电冗余、控制与监视物理隔离、双席位热备接管,显著提升系统可靠性与安全性等优点,解决了缺乏冗余备份机制,难以满足航空器高可靠、高安全的运行的问题

Benefits of technology

1、全链路双电源硬件冗余,从市电入口到设备终端全程双路独立供电,关键设备内置硬件切换电路,微秒级无缝切换,无软件依赖、无操作干预、无感知中断,彻底消除供电单点故障,提升任务可靠性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122660199A_ABST
    Figure CN122660199A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of aviation fault processing, and discloses a single-point fault processing system with double power supply and three redundancies, which comprises a double-path independent power supply link, a control unit, a main pilot seat computer, a vice pilot seat computer, a GCU ground communication unit, an Ethernet switch, an MFD multifunctional display and a PFD main flight display. The double-path independent power supply link is composed of two-path independent power input, two independent UPSs, two independent power distributors and two independent power controllers, and provides double-path power input for all key devices; the control unit adopts an asymmetric double-microcontroller architecture, realizes physical isolation of a control plane and a monitoring plane, and is only responsible for collection and sending of flight control instructions. The application has the advantages of realizing full-link power supply redundancy, control and monitoring physical isolation, double-seat hot backup takeover, significantly improving system reliability and safety, and the like, and solves the problems of lacking a redundant backup mechanism and being difficult to meet the high reliability and high safety operation of an aircraft.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of aviation fault handling technology, specifically to a single-point fault handling system with dual power supply and triple redundancy. Background Technology

[0002] Existing aircraft remote control stations generally employ a single-power-path architecture. Failure in any component—mains power, UPS, or power distributor—can easily lead to the complete shutdown of the remote control station, posing a significant risk of a single point of failure. Furthermore, control commands and network monitoring functions share the same processor and software stack, making them vulnerable to network attacks, software crashes, network storms, and protocol stack anomalies, posing a security risk of control commands being unable to be sent or being tampered with. In addition, most remote control stations use a single-seat monitoring and display architecture; flight situational awareness is interrupted after the main computer fails, lacking redundancy backup mechanisms, making it difficult to meet the high reliability and safety requirements of aircraft operation.

[0003] Therefore, we propose a dual-power supply and triple-redundancy single-point-of-failure handling system to solve the above problems. Summary of the Invention

[0004] (a) Technical problems to be solved To address the shortcomings of existing technologies, this invention provides a single-point-of-failure handling system with dual power supplies and triple redundancy. It features full-link power supply redundancy, physical isolation between control and monitoring, and dual-seat hot standby takeover, significantly improving system reliability and safety. This solves the problem of lacking a redundancy backup mechanism, which makes it difficult to meet the high reliability and high safety requirements of aircraft operation.

[0005] (II) Technical Solution To achieve the aforementioned goals of full-link power redundancy, physical isolation between control and monitoring, and dual-seat hot standby takeover, thereby significantly improving system reliability and security, this invention provides the following technical solution: A dual-power and triple-redundancy single-point-of-failure handling system, comprising dual independent power supply links, a control unit, a pilot's computer, a co-pilot's computer, a GCU ground communication unit, an Ethernet switch, an MFD multifunction display, and a PFD main flight display; the dual independent power supply links consist of two independent AC power inputs, two independent UPS units, two independent power distributors, and two independent power controllers, providing dual power inputs for all critical equipment; the control unit adopts an asymmetric dual-microcontroller architecture, achieving physical isolation between the control plane and the monitoring plane, and is only responsible for the acquisition and transmission of flight control commands; the pilot's computer and co-pilot's computer have completely identical hardware, software, and peripherals, providing hot standby redundancy for each other, and synchronously realizing flight monitoring, route management, alarm display, and audio-visual services; all critical equipment is equipped with dual power input interfaces and internal hardware dual power switching circuits, supporting microsecond-level automatic seamless switching.

[0006] Preferably, the two independent AC mains power supplies are respectively connected to the corresponding UPS, and after passing through the power distributor and power controller, provide 220V independent power supply to the driver's and passenger's seat computers, and provide dual 28V DC power supply to the GCU, control unit, Ethernet switch, MFD, PFD, and RTK.

[0007] Preferably, the internal hardware dual power supply switching circuit is a pure hardware circuit, requiring no software or operating system involvement, with a switching time in the microsecond range, and the system remains uninterrupted and unnoticed by the operator during the switching process.

[0008] Preferably, the control unit includes an STM32 main control processor and an ESP32 network coprocessor; the STM32 runs a bare-metal program and has no Ethernet protocol stack, and is responsible for collecting and verifying key commands and sending control commands through the RS422 bus; the ESP32 only handles network communication, interacts with the STM32 with clean data through the SPI bus, and cannot generate or tamper with control commands.

[0009] Preferably, the STM32 and ESP32 synchronize data transmission and reception states through two GPIO interrupt handshake lines, and are completely isolated in terms of physical link and functional permissions.

[0010] Preferably, the control unit also integrates a BIT self-test circuit, a watchdog monitoring circuit, a secondary power supply module, a data / program memory, and an ESD interface protection circuit.

[0011] Preferably, the computers in the driver's and passenger's seats both use the Linux system and run the same remote control station software, synchronously receiving monitoring data through a dedicated network and independently driving the corresponding MFD and PFD displays.

[0012] Preferably, when the primary pilot's computer fails, the secondary pilot's computer automatically and seamlessly takes over all monitoring, route management, alarm display, and audio-visual services without manual operation and without interruption of situational awareness.

[0013] Preferably, the control unit communicates with the GCU via an RS422 private network, and the GCU interacts with the airborne ACU via 1.4G, 4G / 5G links.

[0014] Preferably, the authority to send flight control commands is solely handled by the physical button panel of the control unit; the computers in the pilot's and co-pilot's seats do not participate in command generation and transmission. (III) Beneficial Effects Compared with the prior art, the present invention provides a single-point fault handling system with dual power supply and triple redundancy, which has the following beneficial effects: 1. Full-link dual power supply hardware redundancy: from the mains power input to the equipment terminal, there are two independent power supplies. Key equipment has built-in hardware switching circuits for seamless switching at the microsecond level. There is no software dependency, no operation intervention, and no perceptible interruption, which completely eliminates single point of failure in power supply and improves mission reliability.

[0015] 2. The control plane and the monitoring plane are physically isolated. The control unit adopts an asymmetric dual microcontroller architecture. The main control processor runs bare-metal programs without an Ethernet protocol stack. The network coprocessor cannot generate or tamper with instructions, thus eliminating control failures caused by network attacks and software crashes at the source and ensuring the highest level of flight control safety.

[0016] 3. The primary and secondary pilot seats are hot-standby and redundant. The two computers have completely identical hardware and software peripherals, operate synchronously, and display independently. If either seat fails, it can be automatically taken over seamlessly, ensuring uninterrupted flight situational awareness and providing dual protection for flight safety. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of the remote control station architecture of the present invention; Figure 2 This is a schematic diagram of the end-to-end dual-power redundant power supply structure of the present invention; Figure 3 This is a schematic diagram of the asymmetric dual-microcontroller architecture of the present invention; Figure 4 This is a schematic diagram of the hardware configuration structure of the present invention. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] Example 1: End-to-End Dual Power Supply Redundancy Example This embodiment provides an aircraft remote control station architecture with dual-power redundant power supply, including two independent mains power inputs, two independent UPS, two independent power distributors, two independent power controllers, as well as key equipment such as GCU ground communication unit, control unit, pilot's seat computer, co-pilot's seat computer, MFD multifunction display, PFD main flight display, Ethernet switch, RTK, etc.

[0020] The system has two independent AC power inputs, AC power input 1 and AC power input 2, which are connected to UPS1 and UPS2 respectively, and then to power distributors 1 and 2 respectively. After passing through power controllers 1 and 2, they form two completely independent power supply links. The driver's seat computer and the passenger's seat computer are independently powered by two 220V AC power sources; the GCU, control unit, Ethernet switch, MFD, PFD, RTK and other equipment are powered by dual 28V DC power sources.

[0021] All critical equipment is equipped with dual power input interfaces and built-in hardware dual power switching circuits. Both power sources operate simultaneously, providing power to the equipment at the same time, forming a full-link parallel redundancy architecture. When any mains power, UPS, power distributor, or power controller fails, the internal dual power switching circuit automatically and seamlessly switches to the other normal power source within microseconds. The entire switching process is completed autonomously by hardware, requiring no software intervention, and is imperceptible to the operator. The system remains uninterrupted, does not restart, and does not lose connection, completely eliminating the risk of remote station paralysis due to a single point of power failure.

[0022] Example 2: Asymmetric Dual Microcontroller Security Isolation Example for Control Unit This embodiment provides a control unit that physically isolates control commands from network communication. It adopts an asymmetric dual microcontroller architecture and includes an STM32 main control processor, an ESP32 network coprocessor, a bit processing circuit, a watchdog and monitoring circuit, a secondary power supply, a data memory, a program memory, a boot memory, an interface and protection circuit, a keypad, a display screen, and an audible and visual alarm device.

[0023] The STM32 acts as the main control processor, running bare-metal code. It does not integrate any Ethernet protocol stack and is solely responsible for acquiring physical button commands, verifying commands, sending control commands to the GCU via the RS422 bus, and driving the screen to display flight status and alarm information. The ESP32 acts as a network coprocessor, handling only Ethernet communication protocols. It connects to the STM32 via a high-speed SPI bus, transmitting only the decrypted clean data payload and synchronizing transmit and receive status in real time via two GPIO interrupt handshake lines. The ESP32 does not have the authority to generate or modify control commands and is completely isolated from the main control command channel both physically and functionally.

[0024] The control unit also integrates a bit processing circuit for power-on self-test and periodic self-test, monitoring the internal module's operating status in real time. A watchdog and monitoring circuit monitors the STM32 and ESP32's operating status in real time, automatically performing a hardware reset if either processor malfunctions. The secondary power supply converts the externally input dual 28V DC power into the operating voltage required by the internal chips. Interface and protection circuits provide ESD electrostatic protection and signal isolation.

[0025] Through the above structure, this embodiment achieves physical-level isolation between the control plane and the network plane, fundamentally eliminating the risk of control commands being unable to be sent or tampered with due to network attacks, network storms, software crashes, and protocol stack anomalies, thus ensuring the highest level of flight control security.

[0026] Example 3: Hot standby redundancy implementation for both driver and passenger seats This embodiment provides an aircraft remote control station architecture with hot standby for both the primary and co-pilot positions, including a primary pilot's computer, a co-pilot's computer, two independent MFD multifunction displays, two independent PFD primary flight displays, independent headsets, independent keyboards and mice, and other peripherals.

[0027] The pilot's computer and the co-pilot's computer use identical hardware configurations, the same Linux operating system, the same peripheral interfaces, and the same remote control station software. They simultaneously receive flight surveillance data via a dedicated network, and each independently parses, processes, and drives the corresponding MFD and PFD displays, achieving dual-channel synchronous output of flight status, equipment parameters, route information, alarm information, and audio-visual services.

[0028] During normal operation, both seats simultaneously display complete situational information, providing mutual monitoring and redundancy. When the pilot's computer becomes unusable due to software crashes, system freezes, hardware malfunctions, or other reasons, the co-pilot's computer automatically continues to provide all flight surveillance, route management, alarm display, and audio-visual services without requiring any switching commands. The crew can directly complete situational awareness through the co-pilot's seat without any operation, delay, or data loss, ensuring uninterrupted flight situational awareness.

[0029] Example 4: Example of an integrated complete system This embodiment provides a complete aircraft remote control station system that integrates dual power supply redundancy, control-monitoring physical isolation, and dual-seat hot standby.

[0030] The system power supply adopts two completely independent mains power inputs, dual UPS, dual power distributors, and dual power controllers to provide dual power supply for all critical equipment, achieving full-link redundancy from the mains power input to the equipment terminal.

[0031] The control unit adopts an asymmetric dual microcontroller architecture, which independently undertakes the acquisition and transmission of flight control commands without relying on the primary and co-pilot computers. The control commands are transmitted to the GCU ground communication unit via RS422 bus, and the GCU then communicates with the airborne ACU via 1.4G, 4G / 5G wireless links to complete the command upload.

[0032] The primary and secondary computer systems are only responsible for flight monitoring, route management, alarm display, and audio / video services. They do not participate in the generation and transmission of any control commands, thus achieving physical isolation between the control plane and the monitoring plane.

[0033] The system maintains continuous operation even under any single point of failure: automatic and seamless hardware switching in the event of a power supply failure; automatic takeover by the co-pilot in the event of a primary pilot computer failure; and absolute safety and reliability of the command channel maintained by the control unit through a dual-processor architecture and hardware self-test and reset mechanisms. The overall system possesses high mission reliability, high safety, and high availability, making it suitable for aircraft remote control scenarios with stringent requirements for safety and continuous operation.

[0034] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A single-point fault handling system with dual power supply and triple redundancy, characterized in that, The system includes dual independent power supply links, a control unit, a pilot's computer, a co-pilot's computer, a GCU ground communication unit, an Ethernet switch, an MFD multifunction display, and a PFD main flight display. The dual independent power supply links consist of two independent AC power inputs, two independent UPS units, two independent power distributors, and two independent power controllers, providing dual power inputs for all critical equipment. The control unit adopts an asymmetric dual microcontroller architecture for physical isolation between the control and surveillance planes, and is only responsible for the acquisition and transmission of flight control commands. The pilot's computer and co-pilot's computer have identical hardware, software, and peripherals, providing hot standby redundancy for each other, and synchronously performing flight surveillance, route management, alarm display, and audio / video services. All critical equipment is equipped with dual power input interfaces and internal hardware dual power switching circuits, supporting microsecond-level automatic seamless switching.

2. The fault handling system according to claim 1, characterized in that, The two independent AC power supplies are connected to their respective UPSs. After passing through the power distributor and power controller, they provide 220V independent power to the driver's and passenger's seats computer, and provide dual 28V DC power to the GCU, control unit, Ethernet switch, MFD, PFD, and RTK.

3. The fault handling system according to claim 1, characterized in that, The internal hardware dual power supply switching circuit is a pure hardware circuit that requires no software or operating system. The switching time is in the microsecond range, and the system is uninterrupted during the switching process, without the operator's awareness.

4. The fault handling system according to claim 1, characterized in that, The control unit includes an STM32 main control processor and an ESP32 network coprocessor. The STM32 runs a bare-metal program and has no Ethernet protocol stack. It is responsible for collecting and verifying key commands and sending control commands via the RS422 bus. The ESP32 only handles network communication and interacts with the STM32 with clean data via the SPI bus. It cannot generate or tamper with control commands.

5. The fault handling system according to claim 4, characterized in that, The STM32 and ESP32 synchronize data transmission and reception states through two GPIO interrupt handshake lines, and are completely isolated in terms of physical link and functional permissions.

6. The fault handling system according to claim 1, characterized in that, The control unit also integrates a BIT self-test circuit, a watchdog monitoring circuit, a secondary power supply module, a data / program memory, and an ESD interface protection circuit.

7. The fault handling system according to claim 1, characterized in that, Both the driver's and passenger's computers use the Linux system and run the same remote control station software. They receive monitoring data synchronously via a dedicated network and independently drive the corresponding MFD and PFD displays.

8. The fault handling system according to claim 1, characterized in that, In the event of a malfunction in the pilot's computer, the co-pilot's computer automatically and seamlessly takes over all monitoring, flight path management, alarm display, and audio-visual services without requiring manual intervention and without interrupting situational awareness.

9. The fault handling system according to claim 1, characterized in that, The control unit communicates with the GCU via a dedicated RS422 network, and the GCU interacts with the airborne ACU via 1.4G, 4G / 5G links.

10. The fault handling system according to claim 1, characterized in that, The authority to send flight control commands is solely exercised by the physical button panel of the control unit; the computers in the pilot's and co-pilot's seats do not participate in command generation and transmission.