Emergency shutdown control system and test device for ground test of liquid rocket engine
By employing multiple sensors and a redundant control system, the problem of low reliability in ground tests of liquid rocket engines was solved, enabling highly reliable and flexible emergency shutdown control, and enhancing test safety and comprehensiveness of detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- LANDSPACE TECH HUZHOU CO LTD
- Filing Date
- 2025-06-26
- Publication Date
- 2026-06-23
AI Technical Summary
The emergency shutdown control system of existing liquid rocket engine ground test facilities suffers from low reliability, poor control strategy configuration flexibility, and insufficient redundancy, making it difficult to meet increasingly stringent test safety requirements.
A redundant control system is composed of multiple sensors, PXI devices, SIS systems, and programmable logic controllers. It includes first and second engine operating condition anomaly detection sensors, pressure sensors, combustible hydrocarbon gas detectors, flame detectors, and control electrical circuits. Redundant control is achieved through relays and solenoid valves to enhance system reliability.
It improves the reliability of emergency shutdown in ground tests of liquid rocket engines, enhances test safety, enables comprehensive and rapid on-site testing, and has a high degree of configuration flexibility.
Smart Images

Figure CN224399764U_ABST
Abstract
Description
Technical Field
[0001] This utility model relates to the field of rocket technology, and in particular to an emergency shutdown control system and test device for ground testing of liquid rocket engines. Background Technology
[0002] With the rapid development of commercial spaceflight in my country, ground tests of liquid rocket engines are becoming more frequent, and the possibility of dangerous incidents during these tests is also increasing. Any anomalies that occur during testing and are not properly controlled could have serious consequences for personal safety and property. Currently, the emergency shutdown control systems used by some rocket engine ground test facilities suffer from drawbacks such as limited sensor variety, low reliability, poor flexibility in control strategy configuration, and insufficient redundancy, making it difficult to meet increasingly stringent test safety requirements. Utility Model Content
[0003] The purpose of this invention is to provide an emergency shutdown control system and test device for ground testing of a liquid rocket engine, so as to at least solve the problem of low reliability in the prior art.
[0004] To achieve the above objectives, this utility model provides the following solution:
[0005] In the first aspect, this utility model provides an emergency shutdown control system for a liquid rocket engine ground test, including a PXI device, a SIS system, a programmable logic controller, a first engine operating condition abnormality judgment sensor, a second engine operating condition abnormality judgment sensor, a pressure sensor, a combustible hydrocarbon gas detector, a flame detector, a control electrical circuit, and a solenoid valve.
[0006] The first engine operating condition anomaly detection sensor is electrically connected to the input terminal of the PXI device. The programmable logic controller (PLC) provides timing signals to the PXI device and the SIS system respectively. The emergency shutdown signal of the PXI device is input to the PLC. The second engine operating condition anomaly detection sensor, pressure sensor, combustible hydrocarbon gas detector, and flame detector are all electrically connected to the input terminal of the SIS system. The output terminals of the PLC and the SIS system are electrically connected to the respective control electrical circuits. The control electrical circuits are electrically connected to the solenoid valves.
[0007] Optionally, the control electrical circuit includes relays K1, K3, and K5;
[0008] The input terminals of relay K1 coil, relay K3 coil, and relay K5 coil are electrically connected to the output terminals of the programmable logic controller, and the output terminals of relay K1 coil, relay K3 coil, and relay K5 coil are all electrically connected to a 24V power supply.
[0009] The input terminals of relay K1, relay K3, and relay K5 are all electrically connected to a 24V power supply, and the output terminals of relay K1, relay K3, and relay K5 are respectively electrically connected to a solenoid valve.
[0010] Optionally, the control electrical circuit further includes relays K2, K4, and K6;
[0011] The input terminals of relay K2 coil, relay K4 coil, and relay K6 coil are electrically connected to the output terminals of the SIS system, respectively. The output terminals of relay K2 coil, relay K4 coil, and relay K6 coil are all electrically connected to a 0V power supply.
[0012] The input terminals of relay K2, relay K4, and relay K6 are all electrically connected to a 24V power supply, and the output terminals of relay K2, relay K4, and relay K6 are respectively electrically connected to a solenoid valve.
[0013] Optionally, a solenoid valve electrically connected to the output terminals of relay K1 and relay K2 is used to control the engine;
[0014] The solenoid valve, which is electrically connected to the output terminals of relay K3 and relay K4, is used to control the main propellant pipeline.
[0015] The solenoid valve, which is electrically connected to the output terminals of relay K5 and relay K6, is used to control fire-fighting equipment.
[0016] Optionally, the fire-fighting equipment includes nitrogen fire suppression.
[0017] Optionally, the pressure sensor is used to detect the propellant tank pressure, the combustible hydrocarbon gas detector is used to detect the propellant tank and main pipeline, and the flame detector is used to detect the engine test chamber.
[0018] Optionally, a fire alarm device may also be included, which is electrically connected to the SIS system.
[0019] Optionally, a manual emergency shutdown button is also included, which is electrically connected to both the programmable logic controller and the SIS system.
[0020] Optionally, the PXI device uses an NI chassis.
[0021] Secondly, this utility model also provides a liquid rocket engine test device, using any of the control systems described in the first aspect.
[0022] This utility model has at least the following technical effects:
[0023] The emergency shutdown control system for liquid rocket engine ground testing provided by this utility model improves the reliability of emergency shutdown in liquid rocket engine ground testing by applying multiple sensors and using PXI equipment, SIS system and programmable logic controller to form a redundant control system, thereby enhancing the safety of liquid rocket engine ground testing. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in the embodiments of this utility model or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this utility model. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 A schematic diagram of the emergency shutdown control system for a liquid rocket engine ground test provided in this embodiment;
[0026] Figure 2 The electrical diagram of the control circuit provided in this embodiment. Detailed Implementation
[0027] The features and exemplary embodiments of various aspects of this utility model will be described in detail below. To make the objectives, technical solutions, and advantages of this utility model clearer, the following detailed description is provided in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only configured to explain this utility model and to exemplarily illustrate the principles of this utility model, and are not configured to limit this utility model. In addition, the structural components in the drawings are not necessarily drawn to scale. For example, the dimensions of some structural components or regions in the drawings may be enlarged for other structural components or regions to aid in the understanding of the embodiments of this utility model.
[0028] The directional terms used in the following description refer to the directions shown in the figures and are not intended to limit the specific structure of the embodiments of this utility model. In the description of this utility model, it should be noted that, unless otherwise stated, the terms "installation," "connection," and "joining" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a direct connection or an indirect connection through an intermediate medium. Those skilled in the art can understand the specific meaning of the above terms in this utility model according to the specific circumstances.
[0029] Furthermore, the terms "comprising," "including," "having," or any other variations thereof are intended to cover non-exclusive inclusion, such that a structure or component that includes a list of elements includes not only those elements but also other structural elements that are not expressly listed or inherent to the structure or component. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of other identical elements in the article or apparatus that includes the element.
[0030] Spatial relation terms such as "below," "under," "under," "low," "above," "on," and "high" are used for descriptive convenience to explain the positioning of one element relative to a second element, indicating that these terms are intended to cover different orientations of the device, in addition to those different from those shown in the figure. Furthermore, phrases such as "one element on / below another element" can indicate that two elements are in direct contact, or that there are other elements between the two elements. In addition, terms such as "first" and "second" are also used to describe individual elements, areas, parts, etc., without specifically indicating order or sequence, and should not be considered restrictive. Similar terms are used throughout the description to represent similar elements.
[0031] In the following description of this utility model, the terms "rocket," "launch vehicle," "spacecraft," "space launch vehicle," or "missile" may be used in certain scenarios for ease of description only, and their connotations are not limited to the specific terms used. Generally, the launch vehicle of this utility model includes space launch vehicles and rockets used to launch satellites, spacecraft, or other probes, as well as weapons such as missiles and rockets, and similar products capable of delivering payloads into the air. Those skilled in the art, when interpreting the above specific terms, should not limit the launch vehicle to only one of space launch vehicles, rockets, or missiles based on the specific terms used in the description, thereby narrowing the scope of protection of this utility model.
[0032] For those skilled in the art, this invention can be implemented without some of these specific details. The following description of the embodiments is merely intended to provide a better understanding of the invention by illustrating examples.
[0033] "NI chassis" refers to a PXI device, which is an advanced test and measurement solution that integrates hardware and software components, including a chassis, controller, and various modules.
[0034] "SIS system" refers to Safety Instrumented System. SIS is a safety protection system composed of sensors, logic controllers, and actuators, designed to perform one or more Safety Instrumented Functions (SIFs) to ensure that potential hazards in industrial processes can be effectively monitored and responded to in a timely manner.
[0035] like Figure 1 As shown, this utility model provides an emergency shutdown control system for a liquid rocket engine ground test, including a PXI device, a SIS system, a programmable logic controller, a first engine operating condition anomaly judgment sensor, a second engine operating condition anomaly judgment sensor, a pressure sensor, a combustible hydrocarbon gas detector, a flame detector, a control electrical circuit, and a solenoid valve.
[0036] The first engine operating condition anomaly detection sensor is electrically connected to the input terminal of the PXI device (i.e., the NI chassis shown in the figure). The programmable logic controller (PLC) provides timing signals to both the PXI device and the SIS system. The emergency shutdown signal of the PXI device is input to the PLC. The second engine operating condition anomaly detection sensor, pressure sensor, combustible hydrocarbon gas detector, and flame detector are all electrically connected to the input terminal of the SIS system. The output terminals of the PLC and the SIS system are electrically connected to their respective control electrical circuits, and these control electrical circuits are electrically connected to solenoid valves.
[0037] like Figure 2 As shown, the control electrical circuit includes relays K1, K3, and K5;
[0038] The input terminals of relay K1 coil, relay K3 coil, and relay K5 coil are electrically connected to the output terminals of the programmable logic controller, and the output terminals of relay K1 coil, relay K3 coil, and relay K5 coil are all electrically connected to a 24V power supply.
[0039] The input terminals of relay K1, relay K3, and relay K5 are all electrically connected to a 24V power supply, and the output terminals of relay K1, relay K3, and relay K5 are respectively electrically connected to a solenoid valve.
[0040] Optionally, the control electrical circuit further includes relays K2, K4, and K6;
[0041] The input terminals of relay K2 coil, relay K4 coil, and relay K6 coil are electrically connected to the output terminals of the SIS system, respectively. The output terminals of relay K2 coil, relay K4 coil, and relay K6 coil are all electrically connected to a 0V power supply.
[0042] The input terminals of relay K2, relay K4, and relay K6 are all electrically connected to a 24V power supply, and the output terminals of relay K2, relay K4, and relay K6 are respectively electrically connected to a solenoid valve.
[0043] Optionally, a solenoid valve electrically connected to the output terminals of relay K1 and relay K2 is used to control the engine; for example, the solenoid valve can control the engine to shut down.
[0044] A solenoid valve electrically connected to the output terminals of relay K3 and relay K4 is used to control the propellant main pipeline; for example, the solenoid valve can control the main pipeline to close.
[0045] The solenoid valve, which is electrically connected to the output terminals of relay K5 and relay K6, is used to control fire-fighting equipment, such as controlling the opening of fire-fighting equipment.
[0046] Optionally, the fire-fighting equipment includes nitrogen fire-fighting equipment.
[0047] Optionally, the pressure sensor is used to detect the propellant tank pressure, the combustible hydrocarbon gas detector is used to detect the propellant tank and main pipeline, and the flame detector is used to detect the engine test chamber.
[0048] Optionally, a fire alarm device may also be included, which is electrically connected to the SIS system.
[0049] Optionally, a manual emergency shutdown button is also included, which is electrically connected to both the programmable logic controller and the SIS system.
[0050] Optionally, the PXI device uses an NI chassis.
[0051] This embodiment utilizes various field sensors, an NI chassis, a PLC (Programmable Logic Controller), a SIS (Safety Instrumented System), and redundant electrical circuits to construct an emergency shutdown control system for ground testing of a liquid rocket engine. This control system allows for convenient and flexible configuration of various emergency shutdown control strategies and features comprehensive field detection, high configuration flexibility, high reliability, fast response, and physical redundancy in both the controller and signal inputs / outputs.
[0052] This system adopts a dual redundancy architecture design, with redundancy implemented in the field measurement sensors, core control modules, and electrical circuits. The system consists of two different automatic control loops and one manual shutdown control loop. All three control loops are online simultaneously and mutually redundant. If one control loop fails, the other loop can seamlessly switch over and continue executing the emergency shutdown procedure, greatly improving the overall reliability of the emergency shutdown control system.
[0053] In terms of control strategy, this system offers high configuration flexibility. For example, emergency shutdown strategies can be configured within the NI chassis and SIS system controller, enabling rapid adjustment of the emergency shutdown triggering conditions and execution logic based on different test conditions, engine models, and potential risk factors.
[0054] The system in this embodiment consists of two automatic control loops (A and B) and one manual emergency shutdown control loop. All three control loops are online simultaneously and are redundant with each other.
[0055] In this embodiment, the emergency shutdown command of the system is executed by a redundant control electrical circuit. The function of the redundant control electrical circuit is to control the closure of the field valves and the opening of the field fire extinguishing device, and to complete the emergency shutdown during the test run.
[0056] Within a redundant control electrical circuit, emergency shutdown commands for either automatic control circuit A or automatic control circuit B can be executed separately through relay isolation, or emergency shutdown commands for both automatic control circuit A and automatic control circuit B can be executed simultaneously (including the execution of manual emergency shutdown commands).
[0057] Automatic control loop A includes field sensors (first engine operating condition abnormality judgment sensor), NI chassis, PLC (programmable logic controller) and redundant control electrical loops.
[0058] In automatic control loop A, the emergency shutdown strategy is deployed in the NI chassis. The NI chassis collects the signals from the sensor that judges the abnormal operating condition of the first engine on site, and the emergency shutdown strategy deployed in the NI chassis makes a determination on whether to shut down the engine in an emergency.
[0059] In automatic control loop A, after the NI chassis makes an emergency shutdown decision, it sends a shutdown signal to the PLC. After receiving the shutdown signal from the NI chassis, the PLC immediately drives the redundant control electrical circuit to close the field valves and open the fire extinguishing device, thus completing the emergency shutdown of the test run.
[0060] Automatic control loop B includes field sensors (field second engine condition anomaly detection sensor, propellant tank pressure sensor, propellant tank compartment and main pipeline combustible hydroxide gas detector and engine test workshop flame detector), SIS (safety instrument system), and redundant control electrical loops.
[0061] In automatic control loop B, the emergency shutdown strategy is deployed in the SIS controller. The AI input card (analog input module) of the SIS system collects field sensor signals, and the emergency shutdown strategy deployed in the SIS system controller determines whether to perform an emergency shutdown.
[0062] In automatic control loop B, after the SIS system controller makes an emergency shutdown decision, it sends an emergency shutdown command to the DO output card (switching output module) via the I / O bus. The DO output card in the SIS system immediately drives the redundant control electrical circuit to close the field valves and open the field fire extinguishing device, thus completing the emergency shutdown of the test run.
[0063] The manual emergency shutdown control circuit allows the test commander to manually press the "manual emergency shutdown button" when an emergency shutdown is required. The PLC and SIS system simultaneously receive the instruction and drive the redundant control electrical circuit to close the field valves and open the field fire extinguishing device, thus completing the emergency shutdown of the test run.
[0064] The emergency shutdown control system for a liquid rocket engine ground test disclosed in this embodiment operates as follows:
[0065] (1) At the start of the test run, the PLC (Programmable Logic Controller) digital output module sends a timing signal V0 to the NI chassis and SIS (Safety Instrumented System); (Timing signal V0: The starting point of the timing signal is the rising edge from 0V to 5V, and the ending point of the timing signal is the falling edge from 5V to 0V. Its function is to align and unify the timing of all devices)
[0066] (2) In the automatic control loop A, the NI chassis collects the measurement data of the sensor for judging the abnormal operating condition of the first engine on site;
[0067] (3) When the test begins, after the NI chassis receives the timing signal V0 from the PLC, it begins to compare the real-time data of the first engine working condition abnormal judgment sensor with the safety belt in the emergency shutdown strategy preset in the NI chassis (which can be flexibly configured according to different engines and different working conditions).
[0068] (4) When the real-time data of the first engine working condition abnormality judgment sensor collected on site exceeds the upper or lower limit of the safety belt in the emergency shutdown strategy deployed in the NI chassis, the NI chassis immediately sends an emergency shutdown command to the PLC. The entire detection and automatic decision-making process takes no more than 40ms.
[0069] (5) After receiving the emergency shutdown command from the NI chassis, the PLC immediately connects the outputs of Y0, Y1, and Y2, energizes the coils of relays K1, K3, and K5 in the redundant control electrical circuit, closes the normally open contacts of relays K1, K3, and K5, energizes the engine shutdown control valve coil, the propellant main pipeline valve closing coil, and the nitrogen fire-fighting valve opening coil, and the engine shuts down in an emergency, the propellant pipeline is cut off, the nitrogen fire-fighting system is activated, and the emergency shutdown of the test run is completed.
[0070] (6) Automatic control loop B, the AI input card of the SIS system collects the measurement data of field sensors (field second engine operating condition abnormal judgment sensor, propellant tank pressure sensor, propellant tank room and main pipeline combustible hydroxide gas detector and engine test workshop flame detector);
[0071] (7) When the test begins, after the SIS system receives the timing signal V0 from the PLC, it begins to compare the real-time data of the on-site second engine operating condition abnormal judgment sensor, propellant tank pressure sensor, propellant tank room and main pipeline combustible hydroxide gas detector and engine test workshop flame detector with the safety belt of the emergency shutdown strategy deployed in the SIS system controller (which can be flexibly configured according to different engine operating conditions).
[0072] (8) When the real-time data collected from the second engine operating condition abnormality judgment sensor, propellant tank pressure sensor, propellant tank room and main pipeline combustible hydroxide gas detector and engine test workshop flame detector exceed the upper or lower limit of the emergency shutdown strategy safety belt in the SIS system controller, the SIS controller determines that the test is in an emergency shutdown. The entire detection and automatic decision-making process takes no more than 40ms.
[0073] (9) For example: During the test, the on-site second engine operating condition abnormality judgment sensor exceeds the preset upper or lower limit of the safety belt, the propellant tank pressure is high, the main pipeline combustible hydroxide gas detector alarms (combustible material leakage), the engine test workshop flame detector alarms (unexplained fire), triggering the emergency shutdown strategy. The SIS controller determines that the test is in emergency shutdown and immediately sends an emergency shutdown command to the DO card in the SIS cabinet. The P1.0, P1.1, and P1.2 on the DO card output 24V voltage, the relay coils K2, K4, and K6 in the redundant control electrical circuit are energized, the normally open contacts of relays K2, K4, and K6 are closed, the engine shutdown control coil, the propellant main pipeline valve closing coil, and the nitrogen fire-fighting valve opening coil are energized, the engine is shut down in emergency, the propellant pipeline is cut off, the nitrogen fire-fighting is activated, and the emergency shutdown of the test is completed.
[0074] (11) Manual emergency shutdown: When the test commander manually determines that an emergency shutdown is required, he / she manually presses the "manual emergency shutdown button". The PLC and SIS system receive the instruction at the same time and immediately drive the redundant control electrical circuit. All coils of relays K1 to K6 are energized and all normally open contacts of relays K1 to K6 are closed. The engine shutdown control coil, the propellant main pipeline valve closing coil and the nitrogen fire extinguishing valve opening coil are energized. The engine is shut down in an emergency, the propellant pipeline is cut off and the nitrogen fire extinguishing is activated, thus completing the emergency shutdown of the test run.
[0075] This system uses multiple types of sensors for comprehensive on-site detection. Whether it is abnormal temperature, sudden pressure change, pipeline leakage, or abnormal flame, this system can accurately and automatically identify and respond quickly.
[0076] In addition, this system can monitor various parameters of engine operation in real time. Once an abnormal signal is detected during a ground test of the engine, it can complete signal analysis and judgment within milliseconds and immediately initiate the emergency shutdown procedure, effectively shortening the emergency shutdown time.
[0077] The system disclosed in this embodiment has the following effects:
[0078] (1) Redundancy was achieved in the emergency shutdown control for ground testing of liquid engines;
[0079] (2) The emergency shutdown system of the liquid rocket engine ground test has achieved SIL3 level safety instrument function;
[0080] (3) Improved the reliability of emergency shutdown during ground tests of liquid rocket engines;
[0081] (4) Enhanced the safety of ground testing of liquid rocket engines;
[0082] (5) Using multiple types of sensors for measurement makes the detection of hazards at the test site more comprehensive.
[0083] This embodiment also discloses a liquid rocket engine test apparatus, which uses the control system disclosed in this embodiment.
[0084] The above embodiments of this utility model can be combined with each other and have corresponding technical effects.
[0085] In this invention, the PLC can implement the technical solution using existing programs.
[0086] The above are merely preferred embodiments of the present utility model and are not intended to limit the present utility model. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present utility model shall be included within the protection scope of the present utility model.
Claims
1. An emergency shutdown control system for ground testing of a liquid rocket engine, characterized in that, Includes PXI equipment, SIS system, programmable logic controller, first engine operating condition anomaly detection sensor, second engine operating condition anomaly detection sensor, pressure sensor, combustible hydrocarbon gas detector, flame detector, control electrical circuit and solenoid valve; The first engine operating condition anomaly detection sensor is electrically connected to the input terminal of the PXI device. The programmable logic controller (PLC) provides timing signals to the PXI device and the SIS system respectively. The emergency shutdown signal of the PXI device is input to the PLC. The second engine operating condition anomaly detection sensor, pressure sensor, combustible hydrocarbon gas detector, and flame detector are all electrically connected to the input terminal of the SIS system. The output terminals of the PLC and the SIS system are electrically connected to the respective control electrical circuits. The control electrical circuits are electrically connected to the solenoid valves.
2. The emergency shutdown control system for ground testing of a liquid rocket engine of claim 1, wherein, The control electrical circuit includes relays K1, K3, and K5; The input terminals of relay K1 coil, relay K3 coil, and relay K5 coil are electrically connected to the output terminals of the programmable logic controller, and the output terminals of relay K1 coil, relay K3 coil, and relay K5 coil are all electrically connected to a 24V power supply. The input terminals of relay K1, relay K3, and relay K5 are all electrically connected to a 24V power supply, and the output terminals of relay K1, relay K3, and relay K5 are respectively electrically connected to a solenoid valve.
3. The emergency shutdown control system for ground testing of a liquid rocket engine of claim 2, wherein, The control electrical circuit also includes relays K2, K4 and K6; The input terminals of relay K2 coil, relay K4 coil, and relay K6 coil are electrically connected to the output terminals of the SIS system, respectively. The output terminals of relay K2 coil, relay K4 coil, and relay K6 coil are all electrically connected to a 0V power supply. The input terminals of relay K2, relay K4, and relay K6 are all electrically connected to a 24V power supply, and the output terminals of relay K2, relay K4, and relay K6 are respectively electrically connected to a solenoid valve.
4. The emergency shutdown control system for ground testing of a liquid rocket engine according to claim 3, characterized in that, The solenoid valve, which is electrically connected to the output terminals of relay K1 and relay K2, is used to control the engine. The solenoid valve, which is electrically connected to the output terminals of relay K3 and relay K4, is used to control the main propellant pipeline. The solenoid valve, which is electrically connected to the output terminals of relay K5 and relay K6, is used to control fire-fighting equipment.
5. The emergency shutdown control system for ground testing of a liquid rocket engine according to claim 4, characterized in that, The fire-fighting equipment includes nitrogen fire-fighting equipment.
6. The emergency shutdown control system for ground testing of a liquid rocket engine according to claim 1, characterized in that, The pressure sensor is used to detect the propellant tank pressure, the combustible hydrocarbon gas detector is used to detect the propellant tank and main pipeline; and the flame detector is used to detect the engine test chamber.
7. The emergency shutdown control system for ground testing of a liquid rocket engine according to claim 1, characterized in that, It also includes a fire alarm device, which is electrically connected to the SIS system.
8. The emergency shutdown control system for ground testing of a liquid rocket engine according to claim 1, characterized in that, It also includes a manual emergency shutdown button, which is electrically connected to both the programmable logic controller and the SIS system.
9. The emergency shutdown control system for a liquid rocket engine ground test as described in claim 1, characterized in that, The PXI device uses an NI chassis.
10. A liquid rocket engine test apparatus, characterized in that, Use the control system according to any one of claims 1 to 9.