Emergency backup dual-redundancy broadband digital servo system

By using an emergency backup dual-redundancy wideband digital servo system, two emergency backup control redundancies are connected through a data interaction module and a synchronization signal module. This integrates the backup flight control function with the main rotor servo drive function, solves the problem of signal acquisition and rapid calculation of servo control commands between redundancies, and meets the frequency response requirements of the main rotor digital servo loop.

CN223796834UActive Publication Date: 2026-01-13AVIC SHAANXI DONGFANG AVIATION INSTR
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202520159476.3
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2026-01-13
Estimated Expiration
2035-01-23

AI Technical Summary

Technical Problem

When the main flight controller fails, how can the backup flight control function be integrated with the main propeller servo drive function to meet the requirements of redundancy signal acquisition and rapid calculation of servo control commands, and achieve the main propeller digital servo loop frequency response (8Hz) technical specification?

Method used

An emergency backup dual-redundant wideband digital servo system is adopted, which connects two emergency backup control redundancies through two redundancy data interaction modules and a dual-redundant synchronization signal module. The modules include ADin, bus driver, FPGA, DSP, DAout and power amplifier modules, respectively. Data interaction channels with different cycles are configured to achieve rapid signal acquisition and synchronization to meet frequency response requirements.

Benefits of technology

It enables rapid acquisition of redundancy signals and rapid computation of servo control commands, meets the frequency response technical specifications of the main propeller digital servo loop, and ensures the reliability and rapid response of the backup system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN223796834U_ABST
    Figure CN223796834U_ABST
Patent Text Reader

Abstract

An emergency backup dual-redundancy broadband digital servo system comprises two emergency backup control redundancies with the same module configuration, and the dual redundancies are electrically connected through two redundancy data interaction modules and a dual-redundancy synchronization signal module. Each of the two redundancies comprises an ADin module, a bus driving module, an FPGA module, a DSP module, a DAout module and a power amplification module. The FPGA module of the redundancy 1 and the FPGA module of the redundancy 2 are electrically connected through two redundancy data interaction modules, and the DSP module of the redundancy 1 and the DSP module of the redundancy 2 are electrically connected through a dual-redundancy synchronization signal module; two redundancies are connected through the two data interaction modules and the redundancy synchronization signal module, so that the redundancy and hardware architecture based on the backup system realizes acquisition of signals between the redundancies and rapid operation of servo control instructions, and the frequency response technical index requirements of a main paddle digital servo loop are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This utility model belongs to the field of backup systems for fly-by-wire flight control systems, specifically an emergency backup dual-redundancy wideband digital servo system. Background Technology

[0002] When the primary flight controller fails, the emergency backup control system needs to implement backup flight controller functionality. Considering the redundancy and hardware architecture of the primary flight controller, the emergency backup and primary flight controller need to be completely dissimilar. The project development requires integrating the backup flight controller function and the main propeller servo drive function within the same product. Based on the redundancy and hardware architecture of the backup system, how to achieve the acquisition of redundancy signals and the rapid computation of servo control commands to meet the frequency response (8Hz) technical requirements of the main propeller digital servo loop is the problem this invention aims to solve. Summary of the Invention

[0003] In view of this, the present invention provides an emergency backup dual-redundancy wideband digital servo system to solve the above problems.

[0004] The technical solution adopted by this utility model is: an emergency backup dual-redundancy broadband digital servo system, including a first emergency backup control redundancy and a second emergency backup control redundancy with identical module configuration, characterized in that: the first emergency backup control redundancy and the second emergency backup control redundancy are electrically connected through two redundancy data interaction modules and a dual-redundancy synchronization signal module.

[0005] Both the first and second emergency backup control redundancy include an ADin module, a bus driver module, an FPGA module, a DSP module, a DAout module, and a power amplifier module. The FPGA module is electrically connected to the ADin module, the bus driver module, the DSP module, and the DAout module. The DAout_a module is electrically connected to the power amplifier module. The FPGA module in the first and second emergency backup control redundancy is electrically connected through two redundancy data interaction modules. The DSP module in the first and second emergency backup control redundancy is electrically connected through a dual-redundancy synchronization signal module.

[0006] The ADin module is used to acquire RVDT and LVDT signals and transmit them to the FPGA module;

[0007] The bus driver module is used to collect atmospheric turbine signals and inertial measurement signals and transmit them to the FPGA module.

[0008] The FPGA module is used to complete the acquisition and output of analog signals and bus signals, as well as the data interaction between the two redundancies;

[0009] The DSP module is used for voting and instruction calculation of signal sources between two redundancies, as well as degree synchronization signals between two redundancies;

[0010] The DAout module is used to output servo control commands to the power amplifier module;

[0011] The power amplifier module is used to convert servo control commands into servo valve drive signals.

[0012] Furthermore, the two redundancy data interaction modules include a first data interaction module and a second data interaction module. The first data interaction module includes an FPGA_a module U1_a and a bus driver module U2_a set in the first emergency backup control redundancy, a bus signal transceiver cross area J1, and an FPGA_b module U1_b and a bus driver module U2_b set in the second emergency backup control redundancy.

[0013] In the first emergency backup control redundancy, the K1 pin of the FPGA_a module U1_a is connected to the 3 pin of the bus driver module U2_a through the transmit channel TX1_a, and the K2 pin of the FPGA_a module U1_a is connected to the 2 pin of the bus driver module U2_a through the receive channel RX1_a.

[0014] Pin 5 of bus driver module U2_a is connected to pin 1 of bus signal transceiver cross area J1 via the positive signal line TX1+_a of the transmit channel; pin 6 of bus driver module U2_a is connected to pin 2 of bus signal transceiver cross area J1 via the negative signal line TX1-_a of the transmit channel; pin 8 of bus driver module U2_a is connected to pin 3 of bus signal transceiver cross area J1 via the positive signal line RX1+_a of the receive channel; pin 7 of bus driver module U2_a is connected to pin 4 of bus signal transceiver cross area J1 via the negative signal line RX1-_a of the receive channel; a resistor R1_a is connected between pins 8 and 7 of bus driver module U2_a.

[0015] Pins 1 and 2 of the bus signal transceiver crossover area J1 are connected to pins 8 and 7 of the bus driver module U2_b, respectively. A resistor R1_b is connected in parallel between pins 8 and 7 of the bus driver module U2_b. Pins 3 and 4 of the bus signal transceiver crossover area J1 are connected to pins 5 and 6 of the bus driver module U2_b, respectively. Pins 3 and 2 of the bus driver module U2_b are connected to pins K1 and K2 of the FPGA_b module U1_b, which is located in the second emergency backup control redundancy.

[0016] Furthermore, the second data interaction module includes an FPGA_a module U1_a and a bus driver module U3_a set in the first emergency backup control redundancy, a bus signal transceiver cross area J1, and an FPGA_b module U1_b and a bus driver module U3_b set in the second emergency backup control redundancy;

[0017] In the first emergency backup control redundancy, pin K6 of FPGA_a module U1_a is connected to pin 3 of bus driver module U3_a through transmission channel TX2_a, and pin J6 of FPGA_a module U1_a is connected to pin 2 of bus driver module U3_a through reception channel RX2_a.

[0018] Pin 5 of bus driver module U3_a is connected to pin 5 of bus signal transceiver cross area J1 via the positive signal line TX2+_a of the transmit channel; pin 6 of bus driver module U3_a is connected to pin 6 of bus signal transceiver cross area J1 via the negative signal line TX2-_a of the transmit channel; pin 8 of bus driver module U3_a is connected to pin 7 of bus signal transceiver cross area J1 via the positive signal line RX2+_a of the receive channel; pin 7 of bus driver module U3_a is connected to pin 8 of bus signal transceiver cross area J1 via the negative signal line RX2-_a of the receive channel; a resistor R2_a is connected between pins 8 and 7 of bus driver module U3_a.

[0019] Pins 5 and 6 of the bus signal transceiver crossover area J1 are connected to pins 8 and 7 of the bus driver module U3_b, respectively. A resistor R2_b is connected in parallel between pins 8 and 7 of the bus driver module U3_b. Pins 7 and 8 of the bus signal transceiver crossover area J1 are connected to pins 5 and 6 of the bus driver module U3_b, respectively. Pins 3 and 2 of the bus driver module U3_b are connected to pins K6 and J6 of the FPGA_b module U1_b, which is located in the second emergency backup control redundancy.

[0020] Furthermore, the period of the first data interaction module is configured to be 12.5ms; the period of the second data interaction module is configured to be 2.5ms.

[0021] Furthermore, the dual-redundancy synchronization signal module includes a DSP_a module U4_a and a level conversion_a module U5_a disposed in the first emergency backup control redundancy, a synchronization signal crossover area J2, and a DSP_b module U4_b and a level conversion_b module U5_b disposed in the second emergency backup control redundancy;

[0022] The L12 pin of the DSP_a module U4_a is connected to the 36 pin of the level conversion module U5_a to receive the synchronization signal in the second emergency backup control redundancy; the J12 pin of the DSP_a module U4_a is connected to the 47 pin of the level conversion module U5_a to output the synchronization signal to the second emergency backup control redundancy.

[0023] Pin 1 of the level conversion module U5_a is connected to the +5V power supply, and pin 24 is grounded; pin 13 of the level conversion module U5_a is connected to pin 10 of the synchronization signal crossover area J2, and pin 2 of the level conversion module U5_a is connected to pin 9 of the synchronization signal crossover area J2.

[0024] The L12 pin of the DSP_b module U4_b is connected to the 36 pin of the level conversion_b module U5_b to receive the synchronization signal in the first emergency backup control redundancy; the J12 pin of the DSP_b module U4_b is connected to the 47 pin of the level conversion_b module U5_b to output the synchronization signal to the first emergency backup control redundancy.

[0025] Pin 1 of the level conversion module U5_b is connected to a +5V power supply, and pin 24 is grounded; pin 13 of the level conversion module U5_b is connected to pin 9 of the synchronization signal crossover area J2, and pin 2 of the level conversion module U5_b is connected to pin 10 of the synchronization signal crossover area J2.

[0026] Furthermore, the synchronization of the dual-redundant synchronization signal module is divided into power-on initial synchronization and periodic synchronization. The maximum waiting time for power-on initial synchronization is 500ms, the maximum waiting time for periodic synchronization is 50μs, and the synchronization period is 12.5ms.

[0027] The beneficial effects of this utility model are: by connecting the two redundancies through two data interaction modules and a redundancy synchronization signal module, the redundancy and hardware architecture of the backup system are based on the acquisition of signals between redundancies and the rapid calculation of servo control commands, thus meeting the frequency response technical requirements of the main propeller digital servo loop. Attached Figure Description

[0028] Figure 1 This is a schematic diagram of the redundancy interconnection of the emergency backup control system;

[0029] Figure 2 This is a functional module block diagram of this utility model;

[0030] Figure 3 This is a circuit connection diagram of the redundancy data interaction module;

[0031] Figure 4 This is a circuit connection diagram of the redundancy synchronization signal module. Detailed Implementation

[0032] To enable those skilled in the art to better understand the technical solution of this utility model, the present utility model will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0033] like Figure 1 As shown, an emergency backup dual-redundancy broadband digital servo system includes two emergency backup control redundancies, namely a first emergency backup control redundancy and a second emergency backup control redundancy. For ease of description, they will be referred to as Redundancy 1 and Redundancy 2 below. Redundancy 1 and Redundancy 2 are electrically connected through two redundancy data interaction modules and a dual-redundancy synchronization signal module, respectively.

[0034] In one embodiment, such as Figure 2 As shown, the module configuration structures in Redundancy 1 and Redundancy 2 are identical. It should be noted that "_a" represents a device in Redundancy 1, and "_b" represents a device in Redundancy 2. The structure will now be explained using Redundancy 1 as an example:

[0035] Redundancy 1 includes the ADin_a module, bus driver_a module, FPGA_a module, DSP_a module, DAout_a module, and power amplifier module. The FPGA_a module is electrically connected to the ADin_a module, bus driver_a module, DSP_a module, and DAout_a module, respectively. The DAout_a module is electrically connected to the power amplifier module.

[0036] The ADin_a module is used to acquire RVDT and LVDT signals and transmit them to the FPGA_a module. Specifically, the ADin_a module uses an A / D conversion chip to acquire the analog signal rod displacement RVDT signal and the actuator position feedback LVDT signal. The A / D conversion chip then inputs the acquisition results to the FPGA_a module for further acquisition.

[0037] The bus driver_a module is used to acquire atmospheric and inertial measurement signals and transmit them to the FPGA_a module. Specifically, the bus driver_a module uses a bus driver to drive and convert the bus signals (atmospheric and inertial measurement signals) before inputting them to the FPGA_a module for acquisition.

[0038] The FPGA_a module is used to acquire and output analog and bus signals, as well as handle data exchange between the two redundancies. The FPGA_a module also interacts with the DSP_a module. Specifically, the FPGA_a module acquires analog and bus signals through the ADin_a and bus driver_a modules, and transmits the acquired signals to the outside via the DAout_a module to send servo control commands. The FPGA_a module interacts with the DSP_a module and simultaneously transmits control commands between the two redundancies.

[0039] The DSP_a module is used for voting on signal sources and executing commands between two redundancies, as well as for synchronizing signals between the two redundancies. Specifically, the DSP_a module performs voting on input signal sources between the two redundancies, voting on control command outputs, executing control commands, executing servo control commands for the servo loop, and implementing synchronization signals between the two redundancies.

[0040] The DAout_a module uses a D / A converter chip to output servo control commands to the power amplifier circuit.

[0041] The power amplifier module uses a power operational amplifier to convert servo control commands into servo valve drive signals.

[0042] The module configuration structure in emergency backup control redundancy b is consistent with that in emergency backup control redundancy a, including ADin_b module, bus driver_b module, FPGA_b module, DSP_b module, DAout_b module, and power amplifier module.

[0043] In emergency backup control redundancy a and emergency backup control redundancy b, a redundancy synchronization module is electrically connected between FPGA_a and FPGA_b modules. The redundancy data interaction module is used to acquire redundancy data information and manage redundancy. A redundancy synchronization module is also electrically connected between DSP_a and DSP_b modules. For the emergency backup system, the performance of the components in each redundancy is not entirely the same, resulting in different startup times and operating cycles for the two redundancies. To achieve synchronized operation between the two redundancies and realize real-time data interaction, synchronization between the two redundancies is required; therefore, a dual-redundancy synchronization signal module is set up.

[0044] The most important aspect of this invention is achieving synchronization between the two redundancies. To meet the frequency response requirements of the digital servo loop, two sets of data interaction channels are configured: one for cross-acquiring data from the external loop (first data interaction module), with a period of 12.5ms; and the other for cross-acquiring data from the internal digital servo loop (second data interaction module), with a period of 2.5ms. By using different interaction periods, the high-frequency response requirements of the servo loop are achieved. The redundancy data interaction module is described in detail below:

[0045] The two redundancy data interaction modules have the same hardware configuration, consisting of a first data interaction module and a second data interaction module, such as... Figure 3 As shown. A detailed description will now be provided.

[0046] Since the two redundancy data interaction modules connect the two redundancies, "_a" in the device represents redundancy 1 and "_b" represents redundancy 2.

[0047] In one embodiment, the first data interaction module includes FPGA_a module U1_a, bus driver module U2_a, bus signal transceiver cross area J1, bus driver module U2_b, and FPGA_b module U1_b.

[0048] The K1 pin of FPGA_a module U1_a is connected to the 3 pin of bus driver module U2_a through the transmit channel TX1_a, and the K2 pin of FPGA_a module U1_a is connected to the 2 pin of bus driver module U2_a through the receive channel RX1_a.

[0049] Pin 5 of bus driver module U2_a is connected to pin 1 of bus signal transceiver crossover area J1 via the positive signal line TX1+_a of the transmit channel. Pin 6 of bus driver module U2_a is connected to pin 2 of bus signal transceiver crossover area J1 via the negative signal line TX1-_a of the transmit channel. Pin 8 of bus driver module U2_a is connected to pin 3 of bus signal transceiver crossover area J1 via the positive signal line RX1+_a of the receive channel. Pin 7 of bus driver module U2_a is connected to pin 4 of bus signal transceiver crossover area J1 via the negative signal line RX1-_a of the receive channel. A resistor R1_a is connected between pins 8 and 7 of bus driver module U2_a.

[0050] Pins 1 and 2 of the bus signal transceiver crossover area J1 are connected to pins 8 and 7 of the bus driver module U2_b, respectively. A resistor R1_b is connected in parallel between pins 8 and 7 of the bus driver module U2_b. Pins 3 and 4 of the bus signal transceiver crossover area J1 are connected to pins 5 and 6 of the bus driver module U2_b, respectively. Pins 3 and 2 of the bus driver module U2_b are connected to pins K1 and K2 of the FPGA_b module U1_b, respectively.

[0051] The specific function of the first data interaction module is to acquire flight control law data. With the communication period set to 12.5ms, the first data interaction module sends data information to redundancy 2 via the transmission channel TX1_a. This data information includes signal data from redundancy 1 sources, namely RVDT, atmospheric engine, and inertial measurement unit (INS), voting results, and control law calculation results. The receiving channel RX1_a in the first data interaction module receives data information sent by redundancy 2. This data information includes signal data from redundancy 2 sources, namely RVDT, atmospheric engine, and INS, voting results, and control law calculation results.

[0052] In one embodiment, the second data interaction module includes FPGA_a module U1_a, bus driver module U3_a, bus signal transceiver cross area J1, bus driver module U3_b, and FPGA_b module U1_b.

[0053] The K6 pin of FPGA_a module U1_a is connected to the 3rd pin of bus driver module U3_a through the transmit channel TX2_a, and the J6 pin of FPGA_a module U1_a is connected to the 2nd pin of bus driver module U3_a through the receive channel RX2_a.

[0054] Pin 5 of bus driver module U3_a is connected to pin 5 of bus signal transceiver cross section J1 via the positive signal line TX2+_a of the transmit channel. Pin 6 of bus driver module U3_a is connected to pin 6 of bus signal transceiver cross section J1 via the negative signal line TX2-_a of the transmit channel. Pin 8 of bus driver module U3_a is connected to pin 7 of bus signal transceiver cross section J1 via the positive signal line RX2+_a of the receive channel. Pin 7 of bus driver module U3_a is connected to pin 8 of bus signal transceiver cross section J1 via the negative signal line RX2-_a of the receive channel. A resistor R2_a is connected between pins 8 and 7 of bus driver module U3_a.

[0055] Pins 5 and 6 of the bus signal transceiver crossover area J1 are connected to pins 8 and 7 of the bus driver module U3_b, respectively. A resistor R2_b is connected in parallel between pins 8 and 7 of the bus driver module U3_b. Pins 7 and 8 of the bus signal transceiver crossover area J1 are connected to pins 5 and 6 of the bus driver module U3_b, respectively. Pins 3 and 2 of the bus driver module U3_b are connected to pins K6 and J6 of the FPGA_b module U1_b, respectively.

[0056] The specific function of the second data interaction module is to acquire digital servo loop data. The communication period is set to 2.5ms. In the second data interaction module, the sending channel TX2_a sends data information to redundancy 2. This data information includes data from the LVDT (Low Level Display Threshold Sensor) of the redundancy 1 signal source and the calculation results of the servo loop control commands. The receiving channel RX2_a in the second data interaction module receives data information sent by redundancy 2. This data information includes data from the LVDT of the redundancy 2 signal source and the calculation results of the servo loop control commands.

[0057] Data interaction channels 1 and 2 have the same hardware configuration, but different bus configurations for data interaction cycles: the first data interaction module is configured with 12.5ms, and the second data interaction module with 2.5ms. The function of the bus signal transceiver crossover area J1 in the redundancy data interaction circuit is to connect the transmission of redundancy 1 bus signals to the reception of redundancy 2 bus signals, and vice versa.

[0058] In this invention, the dual-redundancy synchronization signal module functions as follows: each redundancy is configured to send and receive synchronization signals from other redundancies via hardware synchronization signals. If all synchronization signals arrive within a specified time, synchronization is considered normal. Synchronization in this scheme is divided into initial power-on synchronization and periodic synchronization. The maximum waiting time for initial power-on synchronization is 500ms, the maximum waiting time for periodic synchronization is 50μs, and the synchronization period is 12.5ms.

[0059] In one embodiment, such as Figure 4 As shown, the dual-redundant synchronization signal module includes a DSP_a module U4_a, a level conversion_a module U5_a, a synchronization signal crossover area J2, a level conversion_b module U5_b, and a DSP_b module U4_b. Similarly, since the two dual-redundant synchronization signal modules connect two redundancies, "_a" in the device represents redundancy 1, and "_b" represents redundancy 2.

[0060] Pin L12 of DSP_a module U4_a is connected to pin 36 of level conversion module U5_a to receive the synchronization signal of redundancy 2; pin J12 of DSP_a module U4_a is connected to pin 47 of level conversion module U5_a to output the synchronization signal to redundancy 2.

[0061] The level conversion module U5_a has pin 1 connected to a +5V power supply and pin 24 grounded.

[0062] Pin 13 of the level conversion module U5_a is connected to pin 10 of the synchronization signal crossover area J2, and pin 2 of the level conversion module U5_a is connected to pin 9 of the synchronization signal crossover area J2.

[0063] Pin L12 of DSP_b module U4_b is connected to pin 36 of level conversion_b module U5_b to receive the synchronization signal of redundancy 1; pin J12 of DSP_b module U4_b is connected to pin 47 of level conversion_b module U5_b to output the synchronization signal to redundancy 1.

[0064] The level conversion module U5_b has pin 1 connected to a +5V power supply and pin 24 grounded.

[0065] Pin 13 of the level conversion module U5_b is connected to pin 9 of the synchronization signal crossover area J2, and pin 2 of the level conversion module U5_b is connected to pin 10 of the synchronization signal crossover area J2.

[0066] The function of the synchronization signal crossover zone J2 is to connect the synchronization signal output of redundancy 1 to the reception of the synchronization signal of redundancy 2, and to connect the reception of the synchronization signal of redundancy 1 to the output of the synchronization signal of redundancy 2.

[0067] In this utility model, the chip model of FPGA module U1 is XC6SLX75-3FGG484I;

[0068] The bus driver module U2 used in the first data interaction module and the bus driver module U3 used in the second data interaction module are both MAX3490ESA chips.

[0069] The chip model of DSP module U4 is TMS320F28335-176ZJZ;

[0070] The chip model of level conversion module U5 in the dual-redundancy synchronization signal module is JC 54ALVC164245H;

[0071] Resistors R1 and R2 are RMK1608KB121FPB surface mount resistors.

[0072] The time parameters involved in this invention, such as 500ms, 50μs, 12.5ms, and 2.5ms, are set and implemented by the flight control software of the emergency backup system.

[0073] The functional division of each redundancy in this emergency backup control system is as follows: The FPGA module completes the acquisition and calculation of the signal source. The data interaction interface between redundancies is implemented on the FPGA interface. To ensure the frequency response requirements of the digital servo loop, the data interaction between redundancies is implemented using two sets of bus transceivers: one set is used for cross-acquisition of control law data, with a period set to 12.5ms; the other set is used for cross-acquisition of digital servo loop data, with a period set to 2.5ms. The digital signal processor (DSP) module establishes a synchronization signal between the two redundancies, completes the calculation of the control law and the servo control command; the FPGA module and the DSP module exchange data through the data line. The FPGA module outputs the servo control command to the D / A conversion unit. After power amplification, the servo control command is sent to the servo valve to realize the servo drive function under the backup function.

[0074] After environmental testing, ground-based joint testing, and in-flight verification, this utility model can meet the technical requirements of wideband digital servo loop in emergency backup systems.

Claims

1. An emergency back-up dual-redundant wideband digital servo system comprising a first emergency back-up control redundancy and a second emergency back-up control redundancy configured identically, characterized in that: The first emergency backup control redundancy and the second emergency backup control redundancy are electrically connected through two redundancy data interaction modules and a dual-redundancy synchronization signal module; The first emergency backup control redundancy and the second emergency backup control redundancy each include an ADin module, a bus driving module, an FPGA module, a DSP module, a DAout module, and a power amplification module; the FPGA module is electrically connected with the ADin module, the bus driving module, the DSP module, and the DAout module; the DAout_a module is electrically connected with the power amplification module; the FPGA module of the first emergency backup control redundancy and the FPGA module of the second emergency backup control redundancy are electrically connected through the two redundancy data interaction modules, and the DSP module of the first emergency backup control redundancy and the DSP module of the second emergency backup control redundancy are electrically connected through the dual-redundancy synchronization signal module; The ADin module is used for collecting RVDT signals and LVDT signals and transmitting the signals to the FPGA module; The bus driving module is used for collecting atmospheric machine signals and inertial measurement signals and transmitting the signals to the FPGA module; The FPGA module is used for completing collection and output of analog signals and bus signals and data interaction between the two redundancies; The DSP module is used for voting of signal sources between the two redundancies and instruction operation and dual-redundancy synchronization signals; The DAout module is used for outputting servo control instructions to the power amplification module; The power amplification module is used for converting the servo control instructions into servo valve driving signals.

2. An emergency backup dual-redundant wideband digital servo system as recited in claim 1, characterized by: The two redundancy data interaction modules include a first data interaction module and a second data interaction module; the first data interaction module includes an FPGA_a module U1_a and a bus driving module U2_a arranged in the first emergency backup control redundancy, a bus signal transceiving cross area J1, and an FPGA_b module U1_b and a bus driving module U2_b arranged in the second emergency backup control redundancy; A K1 pin of the FPGA_a module U1_a arranged in the first emergency backup control redundancy is connected with a 3 pin of the bus driving module U2_a through a sending channel TX1_a, and a K2 pin of the FPGA_a module U1_a is connected with a 2 pin of the bus driving module U2_a through a receiving channel RX1_a; A 5 pin of the bus driving module U2_a is connected with a 1 pin of the bus signal transceiving cross area J1 through a forward signal line TX1+_a of a sending channel, a 6 pin of the bus driving module U2_a is connected with a 2 pin of the bus signal transceiving cross area J1 through a reverse signal line TX1-_a of the sending channel, an 8 pin of the bus driving module U2_a is connected with a 3 pin of the bus signal transceiving cross area J1 through a forward signal line RX1+_a of a receiving channel, and a 7 pin of the bus driving module U2_a is connected with a 4 pin of the bus signal transceiving cross area J1 through a reverse signal line RX1-_a of the receiving channel; a resistance R1_a is connected between the 8 pin and the 7 pin of the bus driving module U2_a; The pin 1 and the pin 2 of the bus signal transceiving cross area J1 are connected with the pin 8 and the pin 7 of the bus driving module U2_b respectively, and the pin 8 and the pin 7 of the bus driving module U2_b are connected in parallel with the resistance R1_b. The pin 3 and the pin 4 of the bus signal transceiving cross area J1 are connected with the pin 5 and the pin 6 of the bus driving module U2_b respectively; the pin 3 and the pin 2 of the bus driving module U2_b are connected with the pin K1 and the pin K2 of the FPGA_b module U1_b arranged in the second emergency backup control margin respectively.

3. An emergency backup dual-redundant wideband digital servo system as recited in claim 2, wherein: The second data interaction module comprises the FPGA_a module U1_a and the bus driving module U3_a arranged in the first emergency backup control margin, the bus signal transceiving cross area J1 and the FPGA_b module U1_b and the bus driving module U3_b arranged in the second emergency backup control margin; The pin K6 of the FPGA_a module U1_a in the first emergency backup control margin is connected with the pin 3 of the bus driving module U3_a through the sending channel TX2_a, and the pin J6 of the FPGA_a module U1_a is connected with the pin 2 of the bus driving module U3_a through the receiving channel RX2_a; The pin 5 of the bus driving module U3_a is connected with the pin 5 of the bus signal transceiving cross area J1 through the positive signal line TX2+_a of the sending channel, and the pin 6 of the bus driving module U3_a is connected with the pin 6 of the bus signal transceiving cross area J1 through the negative signal line TX2-_a of the sending channel; the pin 8 of the bus driving module U3_a is connected with the pin 7 of the bus signal transceiving cross area J1 through the positive signal line RX2+_a of the receiving channel, and the pin 7 of the bus driving module U3_a is connected with the pin 8 of the bus signal transceiving cross area J1 through the negative signal line RX2-_a of the receiving channel; the pin 8 and the pin 7 of the bus driving module U3_a are connected with the resistance R2_a. The pin 5 and the pin 6 of the bus signal transceiving cross area J1 are connected with the pin 8 and the pin 7 of the bus driving module U3_b respectively, and the pin 8 and the pin 7 of the bus driving module U3_b are connected in parallel with the resistance R2_b; the pin 7 and the pin 8 of the bus signal transceiving cross area J1 are connected with the pin 5 and the pin 6 of the bus driving module U3_b respectively; the pin 3 and the pin 2 of the bus driving module U3_b are connected with the pin K6 and the pin J6 of the FPGA_b module U1_b arranged in the second emergency backup control margin respectively.

4. An emergency backup dual-redundant wideband digital servo system as recited in claim 2, characterized by: The period of the first data interaction module is configured as 12.5ms, and the period of the second data interaction module is configured as 2.5ms.

5. An emergency backup dual-redundant wideband digital servo system as recited in claim 1, characterized by: The double-margin synchronous signal module comprises the DSP_a module U4_a and the level conversion_a module U5_a arranged in the first emergency backup control margin, the synchronous signal cross area J2, and the DSP_b module U4_b and the level conversion_b module U5_b arranged in the second emergency backup control margin. The L12 pin of the DSP_a module U4_a is connected to the 36 pin of the level conversion module U5_a for receiving the synchronization signal in the second emergency backup control margin; the J12 pin of the DSP_a module U4_a is connected to the 47 pin of the level conversion_a module U5_a for outputting the synchronization signal to the second emergency backup control margin; The 1 pin of the level conversion_a module U5_a is connected to the +5V power supply, and the 24 pin is connected to the ground; the 13 pin of the level conversion_a module U5_a is connected to the 10 pin of the synchronization signal cross region J2, and the 2 pin of the level conversion_a module U5_a is connected to the 9 pin of the synchronization signal cross region J2; The L12 pin of the DSP_b module U4_b is connected to the 36 pin of the level conversion_b module U5_b for receiving the synchronization signal in the first emergency backup control margin; The J12 pin of the DSP_b module U4_b is connected to the 47 pin of the level conversion_b module U5_b for outputting the synchronization signal to the first emergency backup control margin; The 1 pin of the level conversion_b module U5_b is connected to the +5V power supply, and the 24 pin is connected to the ground; The 13 pin of the level conversion_b module U5_b is connected to the 9 pin of the synchronization signal cross region J2, and the 2 pin of the level conversion_b module U5_b is connected to the 10 pin of the synchronization signal cross region J2.