Redundancy control method and device for hybrid bus communication, electronic equipment and storage medium

CN122845451APending Publication Date: 2026-09-29CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610910303.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-23
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0004]然而,上述双网络冗余控制故障后被动切换的处理机制,即仅在主链路发生明确故障后方能感知并启动切换,存在检测延迟和决策延迟的风险,备用链路仅在故障发生后被动接管全部业务,长期处于空闲待机状态,导致带宽资源利用效率低下

Benefits of technology

[0029]本申请的有益效果:通过多项状态参数计算用于表征第一通信总线的质量的特征量,将特征量输入预测模型,以提前感知链路质量恶化趋势,能够在故障发生前主动准备应对措施,保障关键控制指令的连续性。另外,根据预测值与阈值的偏差程度确定故障等级,根据故障等级动态调整备用链路的参与程度,实现带宽资源的按需分配,提升带宽资源的利用效率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845451A_ABST
    Figure CN122845451A_ABST
Patent Text Reader

Abstract

The application provides a redundancy control method and device for hybrid bus communication, electronic equipment and a storage medium, and relates to the technical field of communication. The method comprises the following steps: calculating a characteristic quantity for representing the quality of a first communication bus through a plurality of state parameters, and inputting the characteristic quantity into a prediction model to perceive the link quality deterioration trend in advance, so that the countermeasures can be prepared actively before the fault occurs, the continuity of the key control instruction is guaranteed, in addition, the fault level is determined according to the deviation degree of the prediction value and the threshold value, the participation degree of the backup link is dynamically adjusted according to the fault level, the on-demand allocation of the bandwidth resource is realized, and the utilization efficiency of the bandwidth resource is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a redundancy control method, apparatus, electronic device and storage medium for hybrid bus communication. Background Technology

[0002] Currently, eVTOL (electric vertical takeoff and landing aircraft), UAVs, and aviation electric propulsion systems generally use CAN bus (Controller Area Network) as the main communication network for data exchange between nodes such as ESCs, sensors, and controllers.

[0003] As system intelligence and redundancy requirements increase, related technologies adopt dual-network redundancy control, setting up a primary communication link and a backup communication link. The primary link typically uses a CAN bus or a TSN (Time-Sensitive Networking) network, while the backup link uses the same or different types of communication buses. When a clear fault is detected in the primary link, such as communication interruption, node offline, or data timeout, the system triggers a switching operation to switch the data transmission task from the primary link to the backup link.

[0004] However, the aforementioned passive switching mechanism after a dual-network redundancy control failure, which only detects and initiates switching after a clear failure occurs in the primary link, carries the risk of detection and decision-making delays. The backup link passively takes over all services only after a failure occurs and remains idle for a long time, resulting in low bandwidth resource utilization efficiency. Summary of the Invention

[0005] Therefore, it is necessary to provide a redundancy control method, device, electronic device, and storage medium for hybrid bus communication to address the aforementioned technical problems and improve the utilization efficiency of bandwidth resources.

[0006] In a first aspect, embodiments of this application provide a redundancy control method for hybrid bus communication, comprising: acquiring input variables, wherein the input variables are calculated through multiple state parameters, and the multiple state parameters characterize the quality of a first communication bus; inputting the input variables into a pre-trained or real-time trained link multi-observation index prediction model to obtain predicted values ​​of the observed index, wherein the link multi-observation index prediction model is trained using samples containing statistical features of multiple state parameters as training data and a supervised learning algorithm; determining the fault level of the first communication bus based on the predicted values ​​of the observed index and a preset threshold; and performing redundancy control on the first communication bus and the second communication bus according to different fault levels.

[0007] Using the above method, characteristic quantities characterizing the quality of the first communication bus are calculated through multiple state parameters. These characteristic quantities are then input into a prediction model to detect link quality deterioration trends in advance. This allows for proactive preparation of countermeasures before a fault occurs, ensuring the continuity of critical control commands. Furthermore, the fault level is determined based on the deviation between the predicted value and a threshold. The participation level of backup links is dynamically adjusted according to the fault level, enabling on-demand allocation of bandwidth resources and improving bandwidth utilization efficiency.

[0008] In some embodiments, determining the fault level of the first communication bus based on the predicted value of the observed indicator and a preset threshold includes: configuring a first preset threshold, a second preset threshold, and a third preset threshold for each type of observed indicator; the first preset threshold is less than the second preset threshold, and the second preset threshold is less than the third preset threshold; if the observed indicator output in multiple consecutive sampling periods is greater than the corresponding first preset threshold and less than or equal to the corresponding second preset threshold, then the fault level of the first communication bus is determined to be a level three fault; if the observed indicator output in multiple consecutive sampling periods is greater than the corresponding second preset threshold and less than or equal to the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level two fault; if the observed indicator output in multiple consecutive sampling periods is greater than the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level one fault.

[0009] By employing the above method, three incrementally preset thresholds are configured for each observed indicator, and combined with continuous judgment over multiple sampling periods, a refined classification of communication bus fault levels is achieved. This effectively distinguishes between minor degradation, moderate deterioration, and severe failure of link quality, improving the accuracy and reliability of fault determination and providing a basis for subsequent implementation of differentiated redundancy control strategies.

[0010] In some embodiments, redundancy control includes message priority redundancy control, which performs redundancy control on the first communication bus and the second communication bus according to different fault levels. This includes: transmitting messages in the hybrid bus according to a preset transmission strategy based on the fault level; wherein different fault levels correspond to different preset transmission strategies, and the preset transmission strategy represents a transmission sub-strategy generated according to message priority under different fault levels; message priorities include first priority, second priority, and third priority messages; first priority messages include at least one of attitude stability control data and power control data; second priority messages include at least one of flight status data, navigation data, sensor acquisition data, and equipment health monitoring data; and third priority messages include at least one of log data, maintenance data, and debugging data.

[0011] By using the above method, messages are divided into three priority levels and the specific types of messages at each level are clearly defined, hierarchical management of critical control commands, auxiliary status data, and non-critical log data is achieved. This also enables the implementation of differentiated redundancy control strategies based on different fault levels.

[0012] In some embodiments, according to the fault level, the message is transmitted on the hybrid bus through a preset transmission strategy, including: under a level 3 fault, executing the transmission sub-strategy corresponding to the level 3 fault, maintaining the service transmission of the first communication bus, and down-frequency processing of the third priority message; starting the second communication bus as a redundant channel to back up the transmission of the first priority message; and increasing the synchronization frequency of timestamp and sequence number information between the first communication bus and the second communication bus.

[0013] By using the above methods, the hot backup status of the backup link is strengthened in advance when the link quality deteriorates slightly. This provides redundancy protection for critical control commands without interrupting the main link service, improves the immediate takeover capability of the backup link, and prepares for a smooth switchover in case of more serious failures in the future.

[0014] In some embodiments, according to the fault level, the message is transmitted on the hybrid bus through a preset transmission strategy, including: under a level 2 fault, executing the transmission sub-strategy corresponding to the level 2 fault, including both the first priority message and the second priority message in the backup transmission, and continuously evaluating its takeover capability according to the operating parameters of the second communication bus; wherein, when the load rate of the second communication bus is less than a preset load rate threshold and the error status is less than a preset error rate threshold, it is determined that the second communication bus has takeover capability.

[0015] By using the above methods, it is possible to proactively confirm whether the backup link has the ability to take over before the handover occurs, and at the same time, the handover process is transformed from an instantaneous action to a gradual preparation, making full preparations for possible subsequent level one failures, thereby improving the success rate and smoothness of the handover.

[0016] In some embodiments, according to the fault level, the message is transmitted on the hybrid bus through a preset transmission strategy, which further includes: under a level one fault, if it is determined that the second communication bus has the ability to take over, the transmission sub-strategy corresponding to the level one fault is executed; when the load rate of the second communication bus is less than the load rate threshold and the error rate is less than the error rate threshold, it is confirmed that the second communication bus has the ability to take over; the second communication bus is controlled to take over the transmission of all messages, wherein the first priority message is transmitted normally, the second priority message is transmitted at a reduced frequency, and the third priority message is suspended from transmission; a minimum dwell time is set, and the switchback to the first communication bus is prohibited within the minimum dwell time.

[0017] Using the above method, in the event of a Level 1 failure, the backup link is first confirmed to have takeover capability, and then takeover is performed in stages according to message priority. At the same time, a minimum dwell time is set to prevent frequent back-switching when the main link fluctuates near the threshold, so as to achieve smooth and reliable takeover when the main link fails severely, and ensure the continuous transmission of critical control commands.

[0018] In some embodiments, the method includes: if a fault is confirmed in the first communication bus, and if all the indicators to be observed output in multiple consecutive sampling periods are less than a fourth preset threshold, and the execution time of the sending sub-strategy corresponding to the first-level fault is greater than the minimum dwell time, a self-recovery operation is performed; wherein the self-recovery operation includes: after determining that the first communication bus has the ability to take over, switching the first communication bus back to the network control mode before the fault.

[0019] By using the above methods, the system ensures that the main link has fully recovered and stabilized before the switchback is performed. At the same time, the self-recovery operation corresponding to the fault level is performed, so that the system can smoothly switch back to the network control mode before the fault, thus ensuring the stability and reliability of the switching process.

[0020] Secondly, embodiments of this application provide a redundancy control device for hybrid bus communication, comprising: an acquisition module for acquiring input variables, wherein the input variables are calculated through multiple state parameters, and the multiple state parameters characterize the quality of a first communication bus; an inference module for inputting the input variables into a pre-trained or real-time trained link multi-observation index prediction model to obtain predicted values ​​of the observed index, wherein the link multi-observation index prediction model is trained using samples containing statistical features of multiple state parameters as training data and a supervised learning algorithm; a grading module for determining the fault level of the first communication bus based on the predicted values ​​of the observed index and a preset threshold; and a control module for performing redundancy control on the first communication bus and the second communication bus according to different fault levels.

[0021] In some embodiments, the grading module is used to configure a first preset threshold, a second preset threshold, and a third preset threshold for each type of observable index; the first preset threshold is less than the second preset threshold, and the second preset threshold is less than the third preset threshold; if the observable index output in multiple consecutive sampling periods is greater than the corresponding first preset threshold and less than or equal to the corresponding second preset threshold, then the fault level of the first communication bus is determined to be a level three fault; if the observable index output in multiple consecutive sampling periods is greater than the corresponding second preset threshold and less than or equal to the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level two fault; if the observable index output in multiple consecutive sampling periods is greater than the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level one fault.

[0022] In some embodiments, the control module is used to perform redundant control on the first communication bus and the second communication bus according to different fault levels, including: transmitting messages in the hybrid bus according to the fault level through a preset transmission strategy; wherein, different fault levels correspond to different preset transmission strategies, and the preset transmission strategy represents the transmission sub-strategy generated according to the message priority under different fault levels; the message priority includes a first priority message, a second priority message, and a third priority message; the first priority message includes at least one of attitude stability control data and power control data; the second priority message includes at least one of flight status data, navigation data, sensor acquisition data, and equipment health monitoring data; the third priority message includes at least one of log data, maintenance data, and debugging data.

[0023] In some embodiments, the control module is used to execute the transmission sub-strategy corresponding to the level 3 fault under level 3 fault conditions, maintain the service transmission of the first communication bus, reduce the frequency of the third priority message, start the second communication bus as a redundant channel, and back up the transmission of the first priority message; and increase the synchronization frequency of timestamp and sequence number information between the first communication bus and the second communication bus.

[0024] In some embodiments, the control module is used to execute the transmission sub-strategy corresponding to the second-level fault under the second-level fault, to include both the first priority message and the second priority message in the backup transmission, and to continuously evaluate its takeover capability based on the operating parameters of the second communication bus; wherein, when the load rate of the second communication bus is less than a preset load rate threshold and the error status is less than a preset error rate threshold, it is determined that the second communication bus has takeover capability.

[0025] In some embodiments, the control module is configured to, under a first-level fault, if it is determined that the second communication bus has takeover capability, execute the transmission sub-strategy corresponding to the first-level fault. When the load rate of the second communication bus is less than the load rate threshold and the error rate is less than the error rate threshold, it confirms that the second communication bus has takeover capability; controls the second communication bus to take over all message transmissions, wherein the first priority message is transmitted normally, the second priority message is transmitted at a reduced frequency, and the third priority message is suspended from transmission; sets a minimum dwell time, and prohibits switching back to the first communication bus within the minimum dwell time.

[0026] In some embodiments, the redundant control device for hybrid bus communication further includes a recovery module, which is used to perform a self-recovery operation if, in the event that a fault is confirmed in the first communication bus, all the indicators to be observed output in multiple consecutive sampling cycles are less than a fourth preset threshold, and the execution time of the sending sub-strategy corresponding to the first-level fault is greater than the minimum dwell time; wherein, the self-recovery operation includes: after determining that the first communication bus has the ability to take over, switching the first communication bus back to the network control mode before the fault.

[0027] Thirdly, embodiments of this application provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the first aspect and any possible implementation method.

[0028] Fourthly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the method of the first aspect and any possible implementation.

[0029] The beneficial effects of this application are as follows: By calculating characteristic quantities representing the quality of the first communication bus through multiple state parameters, and inputting these characteristic quantities into the prediction model, the deterioration trend of the link quality can be detected in advance. This allows for proactive preparation of countermeasures before a fault occurs, ensuring the continuity of critical control commands. Furthermore, the fault level is determined based on the deviation between the predicted value and the threshold. The participation level of the backup link is dynamically adjusted according to the fault level, enabling on-demand allocation of bandwidth resources and improving bandwidth resource utilization efficiency. Attached Figure Description

[0030] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0031] Figure 1 A schematic diagram of a hardware system topology provided in an embodiment of this application; Figure 2 A schematic diagram of a CAN / TSN hybrid bus communication system topology provided in this application embodiment; Figure 3 A schematic diagram of the topology and hardware block diagram of an HCM module system provided in this application embodiment; Figure 4 A flowchart illustrating a redundancy control method for hybrid bus communication provided in this application embodiment; Figure 5 A flowchart of a CAN / TSN hybrid bus redundancy control method for an eVTOL flight control system provided in this application embodiment; Figure 6 A schematic diagram of a redundancy control device for hybrid bus communication provided in an embodiment of this application; Figure 7 This is a schematic diagram of the internal structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0032] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Unless otherwise specified, the embodiments and features in the embodiments of this application can be arbitrarily combined with each other. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.

[0033] The terms "first" and "second" in the specification, claims, and accompanying drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising" and any variations thereof are intended to cover non-exclusive protection. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. The term "multiple" in this application can mean at least two, for example, two, three, or more, and the embodiments of this application do not impose limitations.

[0034] Currently, eVTOL, UAVs, and aerospace electric propulsion systems commonly use CAN bus as the primary communication network for data exchange between nodes such as ESCs, sensors, and controllers. With increasing demands for system intelligence and redundancy, some solutions are exploring the use of technologies such as Time-Sensitive Networking (TSN) to meet high bandwidth and real-time requirements. Therefore, current communication systems can be broadly categorized into two types: The pure CAN bus communication system 1) uses CAN / CAN-FD bus as the bus communication medium between various functional modules; 2) ensures a certain level of real-time performance through a bus arbitration mechanism; 3) is suitable for low-speed control signals (such as motor status and battery management).

[0035] However, pure CAN bus communication has the following drawbacks: 1) The bandwidth limit of CAN / CAN-FD is about 1-5 Mbps (megabits per second), which cannot meet the high-speed data requirements of sensor fusion, attitude calculation, etc.; 2) Real-time performance is uncertain; 3) Multi-node communication under the arbitration mechanism will introduce non-deterministic delays, making it difficult to achieve task-level synchronization; 4) Insufficient redundancy; 5) Single-line physical topology, any line failure or node disconnection will cause bus paralysis; 6) Weak time synchronization capability; 7) CAN frames have no global time base, making it difficult to perform time alignment or fusion of multiple modules; 8) Fault recovery depends on manual or upper-layer software restart, and cannot achieve automatic self-recovery; 9) Limited bandwidth.

[0036] A pure TSN deterministic Ethernet communication system 1) adopts controllers and switches that comply with at least one of the following standards: IEEE 802.1AS (time synchronization standard), IEEE 802.1Qbv (time-aware shaper standard), and IEEE 802.1CB (frame duplication and elimination standard); 2) establishes a deterministic time synchronization and scheduling mechanism; and 3) improves real-time control and big data stream transmission capabilities.

[0037] However, pure TSN deterministic Ethernet communication has the following drawbacks: 1) Increased system reliability risks; 2) If the TSN network experiences synchronization failure or frame loss, the recovery process is lengthy and critical control links may be interrupted; 3) Fully Ethernet-based systems still have uncertainties in redundancy isolation and security protection, requiring complex software fault-tolerant design.

[0038] Therefore, in existing eVTOL systems, traditional CAN communication suffers from limited bandwidth and uncontrollable latency issues due to bus contention; while TSN networks, although possessing latency characteristics, lack rapid recovery capabilities in node failure scenarios, failing to meet the flight safety requirements of eVTOL systems.

[0039] To address this, this application provides a redundancy control method for hybrid bus communication. A dual-domain communication control module enables bidirectional real-time state synchronization of control messages between the backbone network and the redundant network. Multiple state parameters are used to calculate characteristic quantities characterizing the quality of the first communication bus. These characteristic quantities are input into a prediction model to proactively detect link quality deterioration trends, allowing for preemptive countermeasures before faults occur and ensuring the continuity of critical control commands. Furthermore, the fault level is determined based on the deviation between the predicted value and a threshold. The participation level of the backup link is dynamically adjusted according to the fault level, achieving on-demand allocation of bandwidth resources and improving bandwidth utilization efficiency.

[0040] This application uses a TSN network as the first communication bus and a CAN network as the second communication bus as an example for introduction.

[0041] Those skilled in the art should understand that the first and second communication buses can also employ other combinations of communication protocols with complementary characteristics. For example, the first communication bus can be Ethernet, ARINC 664 (Avionics Full-Duplex Switched Ethernet), or other communication buses with high bandwidth; the second communication bus can be LIN (Local Area Network) bus, SPI (Serial Peripheral Interface), I²C (Integrated Circuit Bus), or other communication buses with high reliability or low cost. Any substitution, combination, or equivalent variation of the specific types of the first and second communication buses, based on the core technical concept of this application—namely, using a hybrid communication management module to predict link quality, determine fault levels, and implement differentiated redundancy control for heterogeneous dual networks—falls within the scope of protection of this application.

[0042] In some embodiments, Figure 1 This is a schematic diagram of the hardware system topology of this application, including a flight control ECU (Electronic Control Unit) and sub-ECUs (slave electronic control units). The flight control ECU includes a flight control CPU (main processor), which is connected to an HCM module (Hybrid Communication Management Module) control board via an internal bus. The HCM module control board integrates two physical ports: TSN PHY Port A (for time-sensitive network communication) and CAN PHY Port B (for controller area network communication). This HCM module control board is connected to the TSN network and the CAN network respectively, and finally connected to the sub-ECU, forming a dual-network communication architecture from the flight control ECU to the sub-ECU.

[0043] It can be seen that, Figure 1 The hardware architecture of the flight control ECU is shown, in which the HCM module control board is connected to the TSN network and the CAN network through TSN PHYPort A and CAN PHY Port B respectively, forming a dual network communication link.

[0044] In some embodiments, Figure 2 A schematic diagram of a CAN / TSN hybrid bus communication system topology is shown, including a main control unit and a hybrid communication management module (HCM module). The HCM module is located in the communication backbone layer of eVTOL and is used to implement redundant management of the TSN and CAN buses. The HCM module is installed on the main control board of the flight control ECU and is connected to the flight control main CPU through a communication bus (PCIe / SPI) interface. The main CPU is responsible for high-level control and command issuance, which is issued by the HCM module simultaneously through both CAN and TSN channels according to the protocol. The HCM module has an independent microcontroller unit and logic circuits, and can independently complete message scheduling and PTP time synchronization.

[0045] The HCM module integrates a link quality assessment model with multi-observation metric prediction, as well as a clock synchronization unit, a data consistency management unit, a link status detection unit, and a channel switching unit. The HCM module connects to both the TSN backbone network and the CAN redundancy network: the TSN backbone network includes the TSN controller, TSN switch, and flight control nodes; the CAN redundancy network includes actuators, sensor nodes, and power / drive nodes.

[0046] It can be seen that, Figure 2 The HCM module integrates a link quality assessment model for multi-observation index prediction, a clock synchronization unit, a data consistency management unit, a link status detection unit, and a channel switching unit, which respectively realize quality prediction, clock synchronization, data consistency maintenance, link status monitoring, and channel switching control for the dual communication buses.

[0047] Based on the above introduction, this application deploys a multi-index predictive communication bus quality assessment model on the HCM module. It utilizes hardware capabilities to sample multi-source channel quality parameters such as clock skew, frame loss count, and CRC error count, forming a feature vector input to the prediction model. This yields predicted values ​​of communication bus observation indicators within a certain future time window to assess the future link health. The HCM module then determines whether a link switch is necessary. Furthermore, a function degradation strategy is initiated, retaining only core functions such as attitude stabilization, power maintenance, and basic sensors, while suspending higher-level tasks and payload communication to ensure the aircraft remains in a controllable and stable state.

[0048] This redundancy strategy improves the overall reliability, security, and performance of the eVTOL communication system. It also maintains a direct connection between the flight controller CPU and the TSN communication module, allowing the flight controller CPU to adaptively switch to the direct connection to maintain normal communication when the HCM module chip malfunctions.

[0049] In some embodiments, Figure 3 The diagram illustrates the system topology and hardware block diagram of the HCM module, including the MCU (main control unit), FPGA (coprocessor unit), communication interface module, clock synchronization module, and power supply and isolation protection module. As an example, Table 1 shows an example of an HCM module hardware module: Table 1

[0050] The FPGA performs signal processing in pure hardware parallelism, which is fast and ensures low deterministic latency. Therefore, it undertakes real-time communication control tasks, including time synchronization, scheduling arbitration, channel redundancy switching, and status detection. The MCU undertakes communication management and protocol processing tasks, including parameter configuration, protocol parsing, health diagnosis, and fault-tolerant control.

[0051] Based on the functional requirements of the HCM modules, each module undertakes different tasks. Table 2 shows an example table of hardware functions, as detailed below: Table 2

[0052] Through this task division, key real-time functions achieve deterministic responses at the hardware level, while complex management functions are flexibly configured through software, thereby simultaneously achieving real-time performance, reliability, and scalability in the eVTOL control system.

[0053] Based on the aforementioned hardware platform, the HCM module is further configured with corresponding software functional modules to achieve intelligent management and redundancy control of dual network links. The following is a detailed introduction at the software level: To facilitate understanding of the technical solutions provided in the embodiments of this application, the design concept of the embodiments of this application will be introduced first below: First, the redundancy control method for hybrid bus communication provided in this application can be applied to, for example... Figure 1 The hardware system topology diagram shown is illustrated. The HCM module integrates a link quality assessment model with multi-observation metric prediction. This model predicts the communication quality of the first communication bus based on input variables, determines the fault level of the first communication bus based on the predicted values ​​of the observed metrics and preset thresholds, and performs redundancy control on the first and second communication buses according to different fault levels.

[0054] The following section provides a detailed description of the redundancy control method for hybrid bus communication proposed in this application: In some embodiments, such as Figure 4 As shown, a redundancy control method for hybrid bus communication is provided, including the following steps: Step S401: Obtain input variables. The input variables are calculated through multiple state parameters, which characterize the quality of the first communication bus.

[0055] As described above, the first communication bus can be a TSN network (primary channel), and the second communication bus can be a CAN network (backup channel). Because time-sensitive networks like TSN exhibit predictive warning signs of communication quality degradation and instability, a link quality assessment model based on multi-observation indicators can be used for network link switching. Unlike common methods that trigger switching solely based on fixed thresholds, this approach collects multiple state parameters of the TSN primary network channel within a continuous time window. It anticipates risks such as timeouts and frame drops within a certain future time window and implements a graded fault handling strategy, setting early warning conditions and hard link fault judgment conditions. When the risk reaches the early warning condition, the backup channel is preheated and synchronized; when the hard link fault judgment condition is met, the formal link switching is executed. This achieves predictive graded switching for link faults.

[0056] In some embodiments, multiple state parameters of the TSN main network channel are collected within a continuous time window. For each state parameter, multiple sample points are collected at preset time intervals within a given time window to obtain multiple sets of sample points. For each state parameter, a statistical indicator corresponding to each state parameter is selected from multiple statistical indicators. The statistical indicators include one or more of the following: mean, variance, maximum value, minimum value, and slope. For each set of sample points, the indicator calculation is performed according to the statistical indicator corresponding to each state parameter, and the statistical characteristic values ​​of each state parameter are output. All statistical characteristic values ​​are combined into a one-dimensional vector as input variables.

[0057] The predicted value of the observed index is calculated through multiple state parameters, which include one or more of the following: maximum clock deviation within a preset time window, maximum delay jitter within a preset time window, and maximum delay jitter within a preset time window. The preset time window includes the time window after the current moment.

[0058] In some embodiments, the preset time window is a Tms (milliseconds) time window. The HCM module needs to continuously collect the TSN main channel operating status parameters for a Tms time window according to a fixed sampling period. Table 3 is an example table of status parameters. The collected status quantities and statistical features are shown in the following table: Table 3

[0059] In the above embodiment, if the time window T is set to 10ms and the sampling frequency is set to 1ms for each sampling, then 10 sample points can be collected for each variable in one time window. Based on the characteristics of the input variables, the statistical feature values ​​of each input variable in this time window are selected and calculated. As shown in the table above, there are a total of 20 statistical features for the 6 input variables. All statistical features are combined into a set of one-dimensional vectors, which are used as inputs to the prediction model to obtain the input vector.

[0060] Using the above method, characteristic quantities that characterize the quality of the first communication bus are calculated using multiple state parameters. These characteristic quantities are then input into the prediction model to detect the trend of link quality deterioration in advance. This allows for proactive preparation of countermeasures before a failure occurs, ensuring the continuity of critical control commands.

[0061] The multi-observation index prediction model for links aims to predict the risk of network failure in the next future period based on the current main channel network link status values ​​within a certain time window.

[0062] Step S402: Input the input variables into the pre-trained or real-time trained multi-observation index prediction model of the link to obtain the predicted value of the index to be observed. The multi-observation index prediction model of the link is trained using samples containing statistical features of multiple state parameters as training data and a supervised learning algorithm.

[0063] After calculating the input variables, the input variables are fed into the link multi-observation index prediction model to obtain the model prediction results. Network switching decisions are then made based on the prediction model results. The microcontroller unit (MCU) in the HCM module performs model calculations and state decisions, while the FPGA module completes the acquisition of state variables for the main link channel.

[0064] In some embodiments, the model output is a predicted value of the link observation indicators for a future time window. Multiple indicators closely related to the link quality judgment can be selected as observations. Since the semantics of the prediction result is the probability or risk value of network link failure within a certain period of time in the future, the output is not the original value of the selected observation, but the result quantity of the future window.

[0065] Therefore, the worst-case link quality metric can be selected as the model output for the HCM module to make a judgment. Table 4 shows an example of the output variables. The selection of output metrics and the quality meaning reflected by the metrics are shown in the following table: Table 4

[0066] In the above embodiment, if the time window M is set to 20ms, when preparing the dataset, faults can be manually injected within the time window T, and the above four observation indicators can be observed within the subsequent time window M. The maximum value is then taken as the training supervision value.

[0067] Step S403: Determine the fault level of the first communication bus based on the predicted value of the observed index and the preset threshold.

[0068] In some embodiments, determining the fault level of the first communication bus based on the predicted value of the observed indicator and a preset threshold includes: configuring a first preset threshold, a second preset threshold, and a third preset threshold for each type of observed indicator; the first preset threshold is less than the second preset threshold, and the second preset threshold is less than the third preset threshold; if the observed indicator output in multiple consecutive sampling periods is greater than the corresponding first preset threshold and less than or equal to the corresponding second preset threshold, then the fault level of the first communication bus is determined to be a level three fault; if the observed indicator output in multiple consecutive sampling periods is greater than the corresponding second preset threshold and less than or equal to the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level two fault; if the observed indicator output in multiple consecutive sampling periods is greater than the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level one fault.

[0069] After obtaining the predicted values ​​of each observation index output by the model, the HCM module compares them with the corresponding multi-level preset thresholds, thereby triggering the corresponding hierarchical decision logic.

[0070] In some embodiments, the HCM module classification decision includes: During the online operation phase, the HCM module collects samples in real time within a time window T according to a preset sampling period, extracts feature vectors, and calls the prediction model to make predictions, obtaining predicted values ​​for multiple link observation indicators within the future prediction window M. The HCM module performs hierarchical state decisions based on preset thresholds for the observation indicators. The state machine of the HCM module includes at least a normal state, an early warning state, a formal switching state, and a recovery verification state.

[0071] To make tiered decisions, multiple threshold levels need to be set. For observed indicators within a future time window, a first preset threshold, a second preset threshold, and a third preset threshold are configured for each type of observed indicator. For example, if the observed indicator is clock deviation, the first preset threshold is the clock deviation warning threshold, set to... The second preset threshold is the clock skew pre-switching threshold, set to... The third preset threshold is the clock skew switching threshold, set to... Clock skew recovery threshold This refers to the network control mode used before the fault, whereby, after executing the response actions corresponding to each level of fault, the observed index recovers to its pre-fault state and remains so for a preset time. Specifically, Table 5 provides an example table of multi-level thresholds, with the following table showing the tiered thresholds set for the observed index: Table 5

[0072] In one possible implementation, the second preset threshold can be an η (0.75 or 0.8) ratio of the third preset threshold.

[0073] By employing the above method, three incrementally preset thresholds are configured for each observed indicator, and combined with continuous judgment over multiple sampling periods, a refined classification of communication bus fault levels is achieved. This effectively distinguishes between minor degradation, moderate deterioration, and severe failure of link quality, improving the accuracy and reliability of fault determination and providing a basis for subsequent implementation of differentiated redundancy control strategies.

[0074] Step S404: Redundancy control is performed on the first communication bus and the second communication bus according to different fault levels.

[0075] In some embodiments, redundancy control includes redundancy control of a first communication bus and a second communication bus according to different fault levels, including: transmitting messages in the hybrid bus according to a preset transmission strategy based on the fault level; wherein different fault levels correspond to different preset transmission strategies, and the preset transmission strategy represents a transmission sub-strategy generated according to message priority under different fault levels; message priorities include first priority, second priority, and third priority messages; first priority messages include at least one of attitude stability control data and power control data; second priority messages include at least one of flight status data, navigation data, sensor acquisition data, and equipment health monitoring data; and third priority messages include at least one of log data, maintenance data, and debugging data.

[0076] By using the above method, messages are divided into three priority levels and the specific types of messages at each level are clearly defined, hierarchical management of critical control commands, auxiliary status data, and non-critical log data is achieved. This also enables the implementation of differentiated redundancy control strategies based on different fault levels.

[0077] In some embodiments, redundancy control is performed on the first communication bus and the second communication bus according to different fault levels, including: under a level 3 fault, executing the transmission sub-strategy corresponding to the level 3 fault, maintaining the service transmission of the first communication bus, and down-frequency processing of the third priority message; starting the second communication bus as a redundant channel to back up the transmission of the first priority message; and increasing the synchronization frequency of timestamp and sequence number information between the first communication bus and the second communication bus.

[0078] By using the above methods, the hot backup status of the backup link is strengthened in advance when the link quality deteriorates slightly. This provides redundancy protection for critical control commands without interrupting the main link service, improves the immediate takeover capability of the backup link, and prepares for a smooth switchover in case of more serious failures in the future.

[0079] In some embodiments, redundancy control is performed on the first communication bus and the second communication bus according to different fault levels, including: under a level 2 fault, executing the transmission sub-strategy corresponding to the level 2 fault, including both the first priority message and the second priority message in the backup transmission, and continuously evaluating the takeover capability of the second communication bus according to its operating parameters; wherein, when the load rate of the second communication bus is less than a preset load rate threshold and the error status is less than a preset error rate threshold, it is determined that the second communication bus has the takeover capability.

[0080] By using the above methods, it is possible to proactively confirm whether the backup link has the ability to take over before the handover occurs, and at the same time, the handover process is transformed from an instantaneous action to a gradual preparation, making full preparations for possible subsequent level one failures, thereby improving the success rate and smoothness of the handover.

[0081] In some embodiments, redundancy control of the first communication bus and the second communication bus according to different fault levels further includes: under a level one fault, if it is determined that the second communication bus has takeover capability, then the transmission sub-strategy corresponding to the level one fault is executed; when the load rate of the second communication bus is less than the load rate threshold and the error rate is less than the error rate threshold, it is confirmed that the second communication bus has takeover capability; controlling the second communication bus to take over all message transmissions, wherein the first priority message is transmitted normally, the second priority message is transmitted at a reduced frequency, and the third priority message is suspended from transmission; setting a minimum dwell time, and prohibiting switchback to the first communication bus within the minimum dwell time.

[0082] Using the above method, in the event of a Level 1 failure, the backup link is first confirmed to have takeover capability, and then takeover is performed in stages according to message priority. At the same time, a minimum dwell time is set to prevent frequent back-switching when the main link fluctuates near the threshold, so as to achieve smooth and reliable takeover when the main link fails severely, and ensure the continuous transmission of critical control commands.

[0083] The following examples illustrate the different actions to be executed in response to faults at various levels. In some embodiments, when the predicted maximum clock skew, maximum message delay jitter, cumulative CRC error count, and maximum number of consecutive timeouts are all below the warning threshold... In this case, the TSN main channel maintains its primary service transmission, while the CAN redundant channel remains in hot standby synchronization. The HCM module uses the aforementioned thresholds as the basis for classifying the state. Based on the predicted value of the observed index reaching the threshold within the sampling period, it enters different state machines and executes corresponding switching actions. Table 6 shows the HCM module's classifying control table. Table 6

[0084] By employing differentiated response methods for Level 3, Level 2, and Level 1 faults, in the case of a Level 3 fault (minor anomaly), the main link maintains normal transmission, only reducing the frequency of non-critical packets, while simultaneously activating the backup link to back up critical packets and increasing the synchronization frequency of the two links. This approach can strengthen the hot backup status of the backup link at minimal cost in the early stages of a fault, without interrupting the main link service, and preparing for a smooth switchover in the event of subsequent deterioration.

[0085] In the event of a Level 2 failure (moderate degradation), the backup scope of the standby link is expanded to include critical and high-priority packets in backup transmission, and the load rate and error status of the standby link are continuously assessed. Proactively confirming the standby link's takeover capability before the switchover occurs improves the success rate and smoothness of the switchover.

[0086] In the event of a Level 1 failure (severe failure), after confirming that the backup link is capable of taking over, takeover is implemented in a tiered manner according to message priority: critical messages are sent normally, high-priority messages are sent at a reduced frequency, and non-critical messages are suspended. A minimum dwell time is set to prevent frequent switchbacks. This approach ensures that the most critical flight control services receive priority transmission, guaranteeing the continuity of critical control commands and the stability of the system.

[0087] In some embodiments, if all the indicators to be observed are greater than a fourth preset threshold and the execution time is greater than the minimum dwell time within multiple consecutive sampling periods, a self-recovery operation corresponding to the fault level is executed, and the network control mode before the fault is switched back.

[0088] For example, the fourth preset threshold is a recovery threshold, whose value is less than or equal to the first preset threshold, used to determine whether the first network link has recovered to a stable state. In some possible implementations, the fourth preset threshold is set to 0.7 times the first preset threshold. Only when the predicted values ​​of all observed indicators are lower than this recovery threshold for five consecutive periods is the main link deemed to have the conditions for back-switch, thereby enabling a smooth switchback to the network control mode before the fault, achieving lossless back-switch after the main link recovers, and further improving the stability and reliability of the system.

[0089] It should be noted that the link degradation prediction software algorithm module is not limited to a specific model implementation. It can adopt multiple regression models, neural network models, etc. The choice of mathematical model does not affect the core idea of ​​this invention, which is based on multi-observation index prediction and performs hierarchical switching.

[0090] In some embodiments, based on the above hardware architecture and software function configuration, Figure 5 A flowchart of a CAN / TSN hybrid bus redundancy control method applied to an eVTOL flight control system is shown. The specific implementation process is as follows: Initialization phase: After the main control unit starts up, it completes the initialization of the dual network channels, and the HCM module establishes the TSN and CAN link status tables.

[0091] Real-time synchronization and basic hot backup phase: The main control unit periodically sends clock synchronization frames, and the HCM module updates the timestamp of the CAN link accordingly, initiating the basic hot backup of the CAN link.

[0092] Link monitoring and communication quality prediction stage: The HCM module continuously collects status variables such as clock deviation, frame loss count, and timeout count of the current TSN link, extracts sample statistical features and inputs them into the prediction model to obtain the predicted values ​​of link observation indicators for future time windows; the HCM module then evaluates the network degradation trend and processes it in a graded manner based on the predicted values.

[0093] Early warning and pre-switching phase: When the predicted index value meets the early warning criteria, the HCM module enters the early warning state, enhances the hot backup capability on the basis of the original CAN hot backup, performs backup transmission of critical control messages, and increases the frequency of synchronizing the timestamp and sequence number information of the two channels; when the predicted index value continues to deteriorate to near the switching threshold, the HCM module enters the pre-switching state, further strengthening the CAN channel takeover preparation.

[0094] Formal switching phase: When the observed indicators reach the switching threshold, or when a hard fault such as link interruption or synchronization loss occurs, the HCM module directly switches to CAN channel transmission.

[0095] Self-recovery phase: During CAN channel takeover, the HCM module continuously monitors the main channel. When the real-time status of the main channel and the model prediction results both meet the recovery threshold, the dual-channel timestamp consistency and data consistency checks pass, and the time is greater than the minimum hold time, the task smoothly switches back. The entire process can be completed in milliseconds, thus ensuring the real-time adaptive and fault-tolerant recovery capabilities of the eVTOL control system's communication path.

[0096] This application implements full lifecycle redundancy management for dual network links. By using predictive models to detect link degradation trends in advance, the early warning and pre-switching mechanisms transform the switching process from instantaneous action to gradual preparation. The formal switching ensures seamless takeover of critical services, and the self-recovery mechanism ensures smooth back-switching after the main link recovers. This enables real-time adaptive and fault-tolerant recovery capabilities of the eVTOL control system's communication path, significantly improving the system's reliability, switching smoothness, and autonomous recovery capabilities.

[0097] It should be understood that, although Figure 4 , Figure 5The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 4 , Figure 5 At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.

[0098] Based on the same inventive concept, embodiments of this application provide a redundant control device for hybrid bus communication, such as... Figure 6 As shown, it includes: an acquisition module 601, an inference module 602, a hierarchical module 603, a control module 604, and a recovery module 605, wherein: The acquisition module 601 is used to acquire input variables, which are calculated through multiple state parameters, which characterize the quality of the first communication bus.

[0099] The inference module 602 is used to input the input variables into the pre-trained or real-time training multi-observation index prediction model of the link to obtain the predicted value of the observed index. The multi-observation index prediction model of the link is trained using samples containing statistical features of multiple state parameters as training data and a supervised learning algorithm.

[0100] The grading module 603 is used to determine the fault level of the first communication bus based on the predicted value of the observed index and the preset threshold.

[0101] The control module 604 is used to perform redundant control of the first communication bus and the second communication bus according to different fault levels.

[0102] In some embodiments, the grading module 603 is used to configure a first preset threshold, a second preset threshold, and a third preset threshold for each type of observable index; the first preset threshold is less than the second preset threshold, and the second preset threshold is less than the third preset threshold; if the observable index output in multiple consecutive sampling periods is greater than the corresponding first preset threshold and less than or equal to the corresponding second preset threshold, then the fault level of the first communication bus is determined to be a level three fault; if the observable index output in multiple consecutive sampling periods is greater than the corresponding second preset threshold and less than or equal to the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level two fault; if the observable index output in multiple consecutive sampling periods is greater than the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level one fault.

[0103] In some embodiments, the control module 604 is used to perform redundant control on the first communication bus and the second communication bus according to different fault levels, including: transmitting messages in the hybrid bus according to the fault level through a preset transmission strategy; wherein, different fault levels correspond to different preset transmission strategies, and the preset transmission strategy represents the transmission sub-strategy generated according to the message priority under different fault levels; the message priority includes a first priority message, a second priority message, and a third priority message; the first priority message includes at least one of attitude stability control data and power control data; the second priority message includes at least one of flight status data, navigation data, sensor acquisition data, and equipment health monitoring data; the third priority message includes at least one of log data, maintenance data, and debugging data.

[0104] In some embodiments, the control module 604 is used to execute the transmission sub-strategy corresponding to the level 3 fault under level 3 fault conditions, maintain the service transmission of the first communication bus, reduce the frequency of the third priority message, start the second communication bus as a redundant channel, back up the transmission of the first priority message, and increase the synchronization frequency of timestamp and sequence number information between the first communication bus and the second communication bus.

[0105] In some embodiments, the control module 604 is used to execute the transmission sub-strategy corresponding to the second-level fault under the second-level fault, to include both the first priority message and the second priority message in the backup transmission, and to continuously evaluate its takeover capability based on the operating parameters of the second communication bus; wherein, when the load rate of the second communication bus is less than a preset load rate threshold and the error status is less than a preset error rate threshold, it is determined that the second communication bus has the takeover capability.

[0106] In some embodiments, the control module 604 is configured to, under a first-level fault, if it is determined that the second communication bus has takeover capability, execute the transmission sub-strategy corresponding to the first-level fault. When the load rate of the second communication bus is less than the load rate threshold and the error rate is less than the error rate threshold, it confirms that the second communication bus has takeover capability; controls the second communication bus to take over all message transmissions, wherein the first priority message is transmitted normally, the second priority message is transmitted at a reduced frequency, and the third priority message is suspended from transmission; sets a minimum dwell time, and prohibits switching back to the first communication bus within the minimum dwell time.

[0107] In some embodiments, the redundant control device for hybrid bus communication further includes a recovery module, which is used to perform a self-recovery operation if, in the event that a fault is confirmed in the first communication bus, all the indicators to be observed output in multiple consecutive sampling cycles are less than a fourth preset threshold, and the execution time of the sending sub-strategy corresponding to the first-level fault is greater than the minimum dwell time; wherein, the self-recovery operation includes: after determining that the first communication bus has the ability to take over, switching the first communication bus back to the network control mode before the fault.

[0108] Specific limitations regarding the redundancy control device for hybrid bus communication can be found in the limitations on speech recognition methods described above, and will not be repeated here. Each module in the aforementioned redundancy control device for hybrid bus communication can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in hardware or independently of the processor in the computer device, or stored in software in the memory of the computer device, so that the processor can call and execute the corresponding operations of each module.

[0109] Based on the same inventive concept, embodiments of this application provide a computer device, which may be a server, and its internal structure diagram may be as follows: Figure 7 As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used for communication with external terminals via a network connection. When the computer program is executed by the processor, it implements a redundant control method using hybrid bus communication.

[0110] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0111] Based on the same inventive concept, embodiments of this application provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it performs the following steps: acquiring input variables, which are calculated using multiple state parameters, the multiple state parameters characterizing the quality of a first communication bus; inputting the input variables into a pre-trained or real-time trained multi-observation index prediction model to obtain predicted values ​​of the observed index, the multi-observation index prediction model being trained using samples containing statistical features of multiple state parameters as training data and trained using a supervised learning algorithm; determining the fault level of the first communication bus based on the predicted values ​​of the observed index and a preset threshold; and performing redundancy control on the first and second communication buses according to different fault levels.

[0112] In some embodiments, when the processor executes the computer program, it further implements the following steps: configuring a first preset threshold, a second preset threshold, and a third preset threshold for each type of observable index; the first preset threshold is less than the second preset threshold, and the second preset threshold is less than the third preset threshold; if the observable index output in multiple consecutive sampling periods is greater than the corresponding first preset threshold and less than or equal to the corresponding second preset threshold, then the fault level of the first communication bus is determined to be a level three fault; if the observable index output in multiple consecutive sampling periods is greater than the corresponding second preset threshold and less than or equal to the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level two fault; if the observable index output in multiple consecutive sampling periods is greater than the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level one fault.

[0113] In some embodiments, when the processor executes the computer program, it further implements the following steps: redundancy control includes redundancy control of the first communication bus and the second communication bus according to different fault levels, including: transmitting messages in the hybrid bus according to the fault level through a preset transmission strategy; wherein, different fault levels correspond to different preset transmission strategies, and the preset transmission strategy represents the transmission sub-strategy generated according to the message priority under different fault levels; the message priority includes a first priority message, a second priority message, and a third priority message; the first priority message includes at least one of attitude stability control data and power control data; the second priority message includes at least one of flight status data, navigation data, sensor acquisition data, and equipment health monitoring data; the third priority message includes at least one of log data, maintenance data, and debugging data.

[0114] In some embodiments, when the processor executes the computer program, it further implements the following steps: under a level 3 fault, it executes the transmission sub-strategy corresponding to the level 3 fault, maintains the service transmission of the first communication bus, and performs frequency reduction processing on the third priority message; it starts the second communication bus as a redundant channel to back up the transmission of the first priority message; and it increases the synchronization frequency of timestamp and sequence number information between the first communication bus and the second communication bus.

[0115] In some embodiments, when the processor executes the computer program, it further implements the following steps: under a level 2 fault, it executes the transmission sub-policy corresponding to the level 2 fault, includes both the first priority message and the second priority message in the backup transmission, and continuously evaluates its takeover capability based on the operating parameters of the second communication bus; wherein, when the load rate of the second communication bus is less than a preset load rate threshold and the error status is less than a preset error rate threshold, it is determined that the second communication bus has takeover capability.

[0116] In some embodiments, when the processor executes the computer program, it further implements the following steps: under a first-level fault, if it is determined that the second communication bus has takeover capability, the transmission sub-policy corresponding to the first-level fault is executed. When the load rate of the second communication bus is less than the load rate threshold and the error rate is less than the error rate threshold, it is confirmed that the second communication bus has takeover capability; the second communication bus is controlled to take over all message transmissions, wherein the first priority message is transmitted normally, the second priority message is transmitted at a reduced frequency, and the third priority message is suspended from transmission; a minimum dwell time is set, and the switchback to the first communication bus is prohibited within the minimum dwell time.

[0117] In some embodiments, when the processor executes the computer program, it further implements the following steps: if a fault is confirmed in the first communication bus, and if all the indicators to be observed output in multiple consecutive sampling cycles are less than a fourth preset threshold, and the execution time of the sending sub-strategy corresponding to the first-level fault is greater than the minimum dwell time, a self-recovery operation is performed; wherein, the self-recovery operation includes: after determining that the first communication bus has the ability to take over, switching the first communication bus back to the network control mode before the fault.

[0118] Based on the same inventive concept, embodiments of this application provide a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it performs the following steps: acquiring input variables, which are calculated using multiple state parameters, the multiple state parameters characterizing the quality of a first communication bus; inputting the input variables into a pre-trained or real-time trained multi-observation index prediction model to obtain predicted values ​​of the observed index, the multi-observation index prediction model being trained using samples containing statistical features of multiple state parameters as training data and a supervised learning algorithm; determining the fault level of the first communication bus based on the predicted value of the observed index and a preset threshold; and performing redundancy control on the first and second communication buses according to different fault levels.

[0119] In some embodiments, when the computer program is executed by the processor, it further implements the following steps: configuring a first preset threshold, a second preset threshold, and a third preset threshold for each type of observable index; the first preset threshold is less than the second preset threshold, and the second preset threshold is less than the third preset threshold; if the observable index output in multiple consecutive sampling periods is greater than the corresponding first preset threshold and less than or equal to the corresponding second preset threshold, then the fault level of the first communication bus is determined to be a level three fault; if the observable index output in multiple consecutive sampling periods is greater than the corresponding second preset threshold and less than or equal to the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level two fault; if the observable index output in multiple consecutive sampling periods is greater than the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level one fault.

[0120] In some embodiments, when the computer program is executed by the processor, it further implements the following steps: Redundancy control includes redundancy control of the first communication bus and the second communication bus according to different fault levels, including: transmitting messages in the hybrid bus according to the fault level through a preset transmission strategy; wherein, different fault levels correspond to different preset transmission strategies, and the preset transmission strategy represents the transmission sub-strategy generated according to the message priority under different fault levels; the message priority includes a first priority message, a second priority message, and a third priority message; the first priority message includes at least one of attitude stability control data and power control data; the second priority message includes at least one of flight status data, navigation data, sensor acquisition data, and equipment health monitoring data; the third priority message includes at least one of log data, maintenance data, and debugging data.

[0121] In some embodiments, when the computer program is executed by the processor, it further implements the following steps: under a level 3 fault, it executes the transmission sub-strategy corresponding to the level 3 fault, maintains the service transmission of the first communication bus, and performs frequency reduction processing on the third priority message; it starts the second communication bus as a redundant channel to back up the transmission of the first priority message; and it increases the synchronization frequency of timestamp and sequence number information between the first communication bus and the second communication bus.

[0122] In some embodiments, when the computer program is executed by the processor, it further implements the following steps: under a level 2 fault, it executes the transmission sub-policy corresponding to the level 2 fault, includes both the first priority message and the second priority message in the backup transmission, and continuously evaluates its takeover capability based on the operating parameters of the second communication bus; wherein, when the load rate of the second communication bus is less than a preset load rate threshold and the error status is less than a preset error rate threshold, it is determined that the second communication bus has takeover capability.

[0123] In some embodiments, when the computer program is executed by the processor, it further implements the following steps: under a first-level fault, if it is determined that the second communication bus has takeover capability, the transmission sub-policy corresponding to the first-level fault is executed; when the load rate of the second communication bus is less than the load rate threshold and the error rate is less than the error rate threshold, it is confirmed that the second communication bus has takeover capability; the second communication bus is controlled to take over all message transmissions, wherein the first priority message is transmitted normally, the second priority message is transmitted at a reduced frequency, and the third priority message is suspended from transmission; a minimum dwell time is set, and the switchback to the first communication bus is prohibited within the minimum dwell time.

[0124] In some embodiments, when the computer program is executed by the processor, it further implements the following steps: if a fault is confirmed in the first communication bus, and if all the indicators to be observed output in multiple consecutive sampling periods are less than a fourth preset threshold, and the execution time of the sending sub-strategy corresponding to the first-level fault is greater than the minimum dwell time, a self-recovery operation is performed; wherein, the self-recovery operation includes: after determining that the first communication bus has the ability to take over, switching the first communication bus back to the network control mode before the fault.

[0125] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink), DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0126] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0127] The above embodiments merely illustrate several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.

Claims

1. A redundancy control method for hybrid bus communication, wherein the hybrid bus communication includes a first communication bus and a second communication bus, characterized in that, include: The input variables are obtained by calculating multiple state parameters, which characterize the quality of the first communication bus. The input variables are input into a pre-trained or real-time trained multi-observation index prediction model for the link to obtain the predicted value of the index to be observed. The multi-observation index prediction model for the link is trained using a supervised learning algorithm with samples containing statistical features of multiple state parameters as training data. The fault level of the first communication bus is determined based on the predicted value of the observed index and the preset threshold. Redundancy control is implemented for the first and second communication buses based on different fault levels.

2. The method according to claim 1, characterized in that, Determining the fault level of the first communication bus based on the predicted value of the observed indicator and a preset threshold includes: For each type of indicator to be observed, a first preset threshold, a second preset threshold, and a third preset threshold are configured respectively; the first preset threshold is less than the second preset threshold, and the second preset threshold is less than the third preset threshold. If the observed index output in multiple consecutive sampling periods is greater than the corresponding first preset threshold and less than or equal to the corresponding second preset threshold, then the fault level of the first communication bus is determined to be a level three fault. If the observed index output in multiple consecutive sampling periods is greater than the corresponding second preset threshold and less than or equal to the corresponding third preset threshold, then the fault level of the first communication bus is determined to be a level two fault. If the output of the observed index in multiple consecutive sampling cycles is greater than the corresponding third preset threshold, the fault level of the first communication bus is determined to be a level one fault.

3. The method according to claim 2, characterized in that, The redundancy control includes message priority redundancy control, which performs redundancy control on the first communication bus and the second communication bus according to different fault levels, including: Based on the fault level, the message is transmitted in the hybrid bus using a preset transmission strategy; Different fault levels correspond to different preset transmission strategies, and the preset transmission strategy represents the sending sub-strategy generated according to the message priority under different fault levels. The message priorities include first priority, second priority, and third priority messages; The first priority message includes at least one of attitude stabilization control data and dynamic control data; The second priority messages include at least one of flight status data, navigation data, sensor data, and equipment health monitoring data; The third priority message includes at least one of log data, maintenance data, and debugging data.

4. The method according to claim 3, characterized in that, Based on the fault level, messages are transmitted on the hybrid bus using a preset transmission strategy, including: Under the aforementioned level three fault, the corresponding transmission sub-policy is executed: Maintain the service transmission of the first communication bus and down-frequency the third priority message; The second communication bus is activated as a redundant channel to back up and transmit the first priority message; Increase the synchronization frequency of timestamp and serial number information between the first communication bus and the second communication bus.

5. The method according to claim 3, characterized in that, Based on the fault level, messages are transmitted on the hybrid bus using a preset transmission strategy, including: Under the level 2 fault, execute the transmission sub-policy corresponding to the level 2 fault: Both the first priority message and the second priority message are included in the backup transmission, and their takeover capability is continuously evaluated based on the operating parameters of the second communication bus. Specifically, when the load rate of the second communication bus is less than a preset load rate threshold and the error status is less than a preset error rate threshold, the second communication bus is determined to have takeover capability.

6. The method according to claim 5, characterized in that, Based on the fault level, the message is transmitted on the hybrid bus using a preset transmission strategy, further including: Under the first-level fault, if it is determined that the second communication bus has takeover capability, then the transmission sub-strategy corresponding to the first-level fault is executed: The second communication bus is controlled to take over all message transmissions, wherein the first priority message is sent normally, the second priority message is sent at a reduced frequency, and the third priority message is suspended from transmission. Set a minimum dwell time, during which switching back to the first communication bus is prohibited.

7. The method according to claim 6, characterized in that, The method further includes: If a fault is confirmed in the first communication bus, and all the indicators to be observed output in multiple consecutive sampling periods are less than the fourth preset threshold, and the execution time of the sending sub-strategy corresponding to the first-level fault is greater than the minimum dwell time, a self-recovery operation is performed. The self-recovery operation includes: After determining that the first communication bus has takeover capability, the first communication bus is switched back to the network control mode before the fault.

8. A redundant control device with hybrid bus communication, characterized in that, include: An acquisition module is used to acquire input variables, which are calculated through multiple state parameters, and the multiple state parameters characterize the quality of the first communication bus. The inference module is used to input the input variables into a pre-trained or real-time trained multi-observation index prediction model of the link to obtain the predicted value of the index to be observed. The multi-observation index prediction model of the link is trained using a supervised learning algorithm with samples containing statistical features of multiple state parameters as training data. A grading module is used to determine the fault level of the first communication bus based on the predicted value of the observed indicator and a preset threshold. The control module is used to perform redundant control on the first communication bus and the second communication bus according to different fault levels.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the redundancy control method for hybrid bus communication as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a plurality of instructions adapted for loading by a processor and implementing the redundancy control method for hybrid bus communication as described in any one of claims 1 to 7.