Coupling method for redundant servo devices in actuator control systems, related systems and devices

The method corrects actuator commands by calculating a correction factor based on the median of redundant servo unit values, addressing discrepancies and improving reliability and accuracy in redundant servo systems.

JP2025536132AActive Publication Date: 2025-10-31ZIPAIR
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025518286
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-09-29
Filing Date
2023-09-26
Publication Date
2025-10-31
Estimated Expiration
2043-09-26

AI Technical Summary

Technical Problem

Existing multiple redundant servo systems for actuators face challenges in accurately generating commands due to discrepancies among redundant servo units, leading to suboptimal performance and reliability issues, especially when servo units generate significantly different values.

Method used

A method for controlling actuators using a processing unit that corrects generated values by calculating a correction factor based on the difference between current and reference values, with the reference value being the median of values from multiple redundant servo devices, ensuring accurate and adaptive command generation.

Benefits of technology

This approach enhances the reliability and accuracy of actuator commands by automatically correcting discrepancies among redundant servo units, maintaining responsiveness without increasing complexity or cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025536132000001_ABST
    Figure 2025536132000001_ABST
Patent Text Reader

Abstract

The present invention relates to a system (30) for controlling actuators (TS) comprising a plurality of redundant servo units (FC-1, FC-2, FC-3) generating values ​​of the same magnitude (Δ1, Δ2, Δ3) from the same setpoint (Gsp) and the same measurement data (Gs1, Gs2, Gs3), the redundant servo units (FC-1, FC-2, FC-3) further communicating with each other (B) so that each redundant servo unit (FC-1, FC-2, FC-3) has access by reading the most recent values ​​of the variables (Δ1, Δ2, Δ3) generated by the redundant servo unit and implements a method for correcting each generated value by combining them. Thus, the present invention prevents discrepancies between these variables (Δ1, Δ2, Δ3). Such a system (30) may be equipped in a vehicle having a driver, passengers, and / or a load consisting of goods or cargo, and having one or more actuators controlled in this manner.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to the field of servo systems for actuators. A "servo system" refers to any system designed to reach a set point as quickly as possible and maintain it as much as possible, regardless of disturbances caused by the system's environment. The present invention particularly relates to the field of such servo systems, which are called "redundant" or "multiple redundant" and are used, for example, in land, water, or air vehicles. The present invention is primarily described in the context of aircraft flight control, whether the pilot is present on board the aircraft or remote from it, as may be the case with a drone, but this does not limit the present invention in any way. Such aircraft generally take the form of a propulsion device, preferably but not exclusively a vertical propulsion device, adapted or designed to ensure the lifting and movement of a load, whether the load consists of a pilot, one or more human or animal passengers, and / or one or more solid or liquid objects that the propulsion device ensures transportation. [Background technology]

[0002] The principle of servo-controlling a variable or its characteristic generally consists of measuring the variable generated by the system and comparing it to a setpoint. To ensure that the generated variable reaches and maintains the target value defined by the setpoint as quickly as possible, the setpoint is corrected to account for any difference between the value generated by the system and the setpoint. Certain servo-control systems act on one or more characteristics of the servo-controlled variable, such as position, velocity, or acceleration. For this reason, such systems are sometimes described as "negative feedback," "degenerate feedback," or "closed-loop" control systems. Furthermore, various variables and / or characteristics of these variables can be servo-controlled to ultimately generate commands to actuators. The concepts of stability and accuracy are often at odds with the concepts of speed. To improve the performance of a servo system, it is generally necessary to include a compensator in the servo loop. There are various types of compensators, and their operation can be integral, differential, and / or proportional to the measured difference between the servo-controlled variable and the setpoint. Hence the term "PID compensator," an acronym for "proportional, integral, and derivative." Such regulators are set by gains or coefficients to weight the corrective actions that are proportional to, integral with, and derivative of said difference, respectively. Actions that can be described as "proportional" contribute directly to the responsiveness and stability of the servo control. "Integral" actions make it possible to eliminate residuals, bringing precision to the system, while "derivative" actions make it possible to limit oscillations around the setpoint of the servo-controlled variable.

[0003] Furthermore, depending on the reliability required, particularly for systems used in land, sea, air, and / or space transportation, such servo systems may be multi-redundant systems, requiring multiple devices for arbitration of such multi-redundancy.

[0004] In engineering, the concept of "redundancy" consists of duplicating important elements or functions of a system with the aim of increasing the reliability of said system. When the safety of the expected passengers is at risk, as may be the case during the flight of an aircraft, certain parts of the aircraft's control system may be duplicated or triplicated, hence the term double or triple redundant system. Thus, errors occurring in said elements, for example related to the failure or performance drift of said elements, can be offset or compensated by the use of one or other of the other redundant elements. Multiple redundant systems, also known as "majority voting / logic systems" or "voting logic systems", use multiple generations of identical variables, for example to control actuators.

[0005] There are several modes of operation for multiple redundant servo systems for actuators. Take the example of a system for controlling actuators using three similar servo systems, called "twin systems" or "redundant systems," each generating, i.e., in parallel with each other, variables that must represent identical setpoints. Commands for the actuators are ultimately generated based on only one or several variables generated by the redundant systems. According to a first known mode of operation, commands for such actuators are generated based on variables generated by one of three servo systems, sometimes referred to as "primary." Only if the primary is observed to have failed does the control system or its operator select a new primary from among these redundant servo systems to replace the previous primary. Such a failure can be detected by a too large difference between the average values ​​of the variables provided by the primary and those provided by its twin. This solution may be suboptimal if the values ​​of the servo control variables generated by each of the redundant servo systems differ. Reassigning a primary system becomes difficult if the three redundant servo systems exhibit variables with very different values. This is because, if consensus is not evident between the other redundant systems, it is no longer possible to assess a possible failure or drift of the current primary. Another technique consists in calculating the average of the variables generated by each redundant servo system and generating commands for the actuators based on said average. This second embodiment sometimes becomes problematic, especially when one of the systems provides variables that take on values ​​very different from those generated by its twin. In fact, the average obtained will be adversely affected by the strong drift of the faulty system and will itself be very different from the values ​​that are plausible for ultimately generating the appropriate actuator commands. Summary of the Invention

[0006] The present invention makes it possible to overcome the drawbacks indicated above. Among the numerous advantages that result from the implementation of the invention, the following may be mentioned: Automatic correction of the generated values ​​from a servo unit to the generated values ​​from a twin servo unit in a multiple redundant control system prevents the risk of discrepancies in the generated values ​​and increases their validity. The distribution within the system for controlling arbitration and / or correction of redundantly generated values ​​improves the reliability of the actuator command generation without complicating it or hindering its responsiveness. - Accurate and adaptive correction of redundantly generated values ​​with respect to the characteristics of the signals or data being generated improves the accuracy and validity of the commands generated without burdening responsiveness or increasing the cost and complexity of the system implementing the invention. - The recommendation of a median value taking into account the respective generated values ​​from at least three redundant servo devices and the delay caused by information sharing between the redundant servo devices provides a reasonable compromise, especially during the generation of outliers or deviations.

[0007] To this end, the present invention provides a method implemented by a processing unit of one of several redundant servo devices of a system for controlling actuators, each of which generates a value of an identical variable based on an identical set value and identical measurement data, the generated values ​​being used by the system to control the actuators, and the redundant servo devices communicating with each other so that each redundant servo device has access by reading the most recent value of the variable generated by the redundant servo device.

[0008] In order to prevent any drift in each generation of the values ​​of the variables, the method comprises: - generating a current variable value based on the setpoint and the measurement data; - reading the last known values ​​of variables generated by redundant servo devices of said control system and constructing a set of current values ​​of said variables; - determining a reference value of said variable taken from said set; - calculating the difference between the current value of the generated variable and said reference value; - correcting said current value by subtracting from said current value a correction value resulting from a calculation of multiplying said difference by a correction factor for the current value, thereby generating a corrected current value of the variable.

[0009] In order to increase the validity of the generated values ​​of the variables, if the control system includes at least three redundant servo devices capable of generating such values ​​of the variables, the step of determining the reference value advantageously consists in selecting the median value of the set of current values ​​of the variables.

[0010] In a variant, if the control system includes only two redundant servo devices capable of generating such a value of the variable, the step of determining the reference value may consist of selecting one of the values ​​of the set of current values ​​of the variable.

[0011] The value of the correction factor may be predetermined to determine the combination of the generated values ​​from the redundant servo devices.

[0012] In a variant, such a combination may be dynamic. To this end, the method according to the invention may comprise a step of recording the current or corrected values ​​of the generated variables in a data memory of the servo device to build a log of a defined number of values. Such a method therefore comprises, before the correction step, a step of generating a value of a correction factor that depends on the variability of the values ​​taken from said log and on the repetition frequency of the step of reading the last known values ​​of the generated variables by the redundant servo device.

[0013] Furthermore, in order to prevent any sudden corrections or even to smooth the process of correcting the generation of the value of the variable, the calculation of the correction value is adjusted so that the absolute value of said correction value does not exceed a predetermined limit value.

[0014] According to a preferred embodiment in which the redundant servo device includes a PID compensator providing three components of an output signal representing proportional, integral, and derivative action, respectively, the variable may be comprised of the component representing the integral action of the PID compensator.

[0015] To increase the reliability of the system for controlling the actuators, it may include redundant sources arranged to jointly provide a plurality of setpoints. If the control system includes only two redundant sources, one of the plurality of values ​​is If the control system comprises at least three redundant sources, the step of generating a setpoint value may include taking the median value of the plurality of values ​​as the setpoint value.

[0016] In order to increase the reliability of the system for controlling the actuators, it may include redundant sources arranged to jointly provide a plurality of measurement data values. If the control system includes only two redundant sources, one of the plurality of values ​​is If the control system includes at least three redundant sources, the control system may include a step of generating measurement data so that the value taken is the median value of the plurality of values.

[0017] According to a second subject, the invention relates to one of several redundant servo units of a system for controlling actuators, each generating identical values ​​of a variable based on identical setpoints and identical measurement data, the redundant servo units also communicating with each other such that each servo unit has access by reading to the most recent value of the variable generated by the redundant servo unit, the servo unit being adapted to implement the method according to the invention.

[0018] According to a third subject, the invention relates to a system for controlling an actuator comprising several redundant servo devices, said actuator commands being generated based on a plurality of values ​​of variables jointly generated by the redundant servo devices.

[0019] According to an advantageous embodiment, the control system is adapted such that the command: - if the plurality of values ​​includes only two values, one of the plurality of values ​​of the variable generated by the redundant servo device; If the plurality of values ​​includes at least three values, the generated variable may be generated based on the median of the plurality of values.

[0020] According to a fourth subject, the invention relates to a vehicle carrying a pilot, passengers and / or a load constituted by goods or merchandise, the vehicle comprising one or more actuators in the form of at least one thrust unit for moving said vehicle, the commands to the actuators being generated by a control system according to the invention.

[0021] According to a preferred application, such a vehicle may be an aircraft.

[0022] Furthermore, according to a fifth subject, the invention relates to a computer program comprising one or more program instructions that can be interpreted by a processing unit of one of a plurality of redundant servo devices of a system for controlling an actuator according to the invention, said program instructions being located in a non-volatile memory of the servo device and being designed such that their execution by said processing unit implements the method according to the invention.

[0023] According to a sixth subject, the invention relates to a storage medium readable by such a processing unit, comprising instructions for such a computer program.

[0024] Other features and advantages will be more clearly understood from a reading of the following description and a consideration of the accompanying drawings. [Brief explanation of the drawings]

[0025] [Figure 1] FIG. 1 shows a first known propulsion system arranged to provide substantially vertical take-off and landing capability. [Figure 2] FIG. 2 shows the configuration of the thrust system of a known propulsion device such as that shown in FIGS. 1 and 1A. [Figure 3] FIG. 3 shows the configuration of a setpoint unit including a human-machine input interface for translating human commands for piloting an aircraft as described with reference to the previous figures. [Figure 4] Figure 4 shows an example of the functional architecture of a flight control device intended to be equipped on a drone. [Figure 5] FIG. 5 shows an example of a functional architecture of a system according to the present invention for controlling actuators such as thrust units of an aircraft including multiple redundant flight control units, which may possibly be similar to the flight control units shown in the previous figures. [Figure 6] FIG. 6 shows a functional description of an example of a method for correcting data generated by a servo device of a system for controlling an actuator such as that illustrated in FIG. [Figure 7] FIG. 7 illustrates a first significant contribution obtained by implementing the present invention with respect to the generation of pitch actuator commands by a control system according to FIG. [Figure 7A] FIG. 7A shows a second contribution obtained by implementing the present invention with respect to such a pitch actuator command generated by a control system according to FIG. [Figure 8] FIG. 8 shows a significant benefit obtained by implementing the present invention with respect to roll actuator commands generated by a control system also according to FIG. DETAILED DESCRIPTION OF THE INVENTION

[0026] The present invention is illustrated in a preferred, but non-limiting way, through its application in the field of flight control of an aircraft or aerobatic vehicle arranged to provide a substantially vertical take-off and landing capability. By way of non-limiting example, such a propulsion device may consist of a drone, a quadcopter, or an octocopter. Document EP 3 495 262 A1 describes an example of such a propulsion device. However, the present invention is not limited to these applications only, but may instead be used in connection with any type of device for propelling a load, a pilot, or passengers.

[0027] According to the present invention, such a vertical take-off and landing aircraft is powered by a plurality of thrust units, which differs from the one taken from document EP 3 495 262 A1 in that the actuation commands for each of said thrust units are generated by a multiple redundant control system.

[0028] As shown in Fig. 1, the aircraft 10, which allows lifting a load carried by the aircraft 10 according to the technical teachings taken from document EP 3 495 262 A1, consists of a quadcopter including thruster support means 14, said support means 14 taking the form of four arms that describe an "X" above a substantially planar platform 11. Each arm supports a thrust system TSa, TSb, TSc, TSd, each of which includes a thrust unit 12a, 12b, 12c, 12d, consisting of a thermal thruster in the form of a turbojet. To lift a load carried by the platform 11, not shown in Fig. 2, the four thrust units 12a, 12b, 12c, 12d provide thrust vectors AL12a, AL12b, AL12c, AL12d, respectively, that are substantially perpendicular to the platform 11. To land without damaging the turbojets' jet nozzles or fluid outlets of the thrust units 12a-12d, the arms of the support means 14 of the thrust systems TSa, TSb, TSc, and TSd advantageously cooperate at their respective distal ends with telescopic extension means or legs 17. A control system 30 in the form of electronic processing means provides thrust commands to the thrust systems TSa, TSb, TSc, TSd, for example in the form of PPM (Pulse Position Modulation) signals according to known modulation techniques transmitted over a "point-to-point" connection, a code of several bits in a single coded pulse among 2M possible temporal transition symbols, or any other suitable format. The fluid outlets of the thrusters of the thrust systems are located above or below, or substantially at the height of, the center of gravity CG10 of the device 10, depending on the configuration and arrangement of the support means 14. In order to change and stabilize the attitude of the platform 11, each thrust system TSa to TSd comprises means 19a, 19b, 19c, 19d for correcting the thrust vector AL12a, AL12b, AL12c, AL12d provided by the turbojets of the thrust units 12a to 12d, respectively.

[0029] FIG. 2 shows the configuration of such a means for correcting the thrust vector 19a of the thrust unit 12a of the thrust system TSa according to FIG. 1. The means for correcting the thrust vector 19a includes a pair of deflector guides 19a-1 and 19a-5 movably mounted, more specifically by respective pivot links 19a-2 and 19a-6. The deflector guides 19a-1 and 19a-5 are arranged to deflect all or part of the thrust vector AL12a in the area near the fluid outlet 12a-o of the turbojet 12a-e of the thrust unit 12a. Thus, the deflector assembly consisting of the deflector guides 19a-1 and 19a-5 can "sandwich" the thrust vector AL12a. The deflector guides 19a-1 and 19a-5 are advantageously actuated by a pair of cam actuators or servomotors, respectively. Only the actuator 19a-3 of these is visible in FIG. 1. The actuator 19a-3 thus cooperates with the deflector guide 19a-1 by means of a control rod 19a-4. The actuation of the cam of the actuator 19a-3 causes a rotational movement r of the deflector guide 19a-1 around a shaft 19a-2 placed above the fluid discharge area of ​​the turbojet 12a, thereby limiting the torque required by the actuator 19a-3 to overcome and withstand the suction or discharge generated by the thrust vector AL12a provided by the turbojet 12a-e of the thrust unit 12a during opening or closing of the deflector guide 19a-1. When cam actuators, such as actuator 19a-3, associated with deflector guides 19a-1 and 19a-5, respectively, cause the thrust vector AL12a to be pinched by these deflector guides 19a-1 and 19a-5, said thrust vector AL12a is subdivided downstream of said deflector guides into two or three components AL12a, AL12a', AL12a" depending on whether the particular deflector guide 19a-1 or 19a-5 is in the flow discharged at the fluid outlet 12a-o of the turbojet 12a-e. In an "open" configuration, in which deflector guides 19a-1 and 19a-5 are located substantially outside the trajectory of thrust vector AL12a, the force of thrust vector AL12a is at a maximum.Conversely, if one (or both) of the two deflector guides 19a-1 and 19a-5 "sandwich" the thrust vector, the thrust resulting from the thrust vector AL12a is reduced downstream of the deflector guides 19a-1 and 19a-5 until it is canceled during the "full sandwich" of the flow from the turbojet's injection nozzle outlet 12a-o between the deflector guides 19a-1 and 19a-5. Depending on the design of the deflector guides 19a-1 and 19a-5, a "closed" arrangement of the two guides 19a-1 and 19a-5 can result in a reverse thrust, i.e., a thrust vector in the opposite direction to the thrust vector AL12a at the fluid outlet 12a-o. These deflector guides 19a-1 and 19a-5 resemble two substantially curved scoops or semicircular surfaces facing each other in FIG. 3. Such a reverse thrust, for example of the order of 10 to 30 percent, may be possible thanks to the shape of the guides, which may in fact be arranged to guide fluid flows that result, at their outlets (terminal parts), in secondary thrust vectors AL12a' and AL12a'', respectively, directed in a direction substantially opposite to that of the original thrust vector AL12a at the fluid outlets 12a-o of the turbojets 12a-e.

[0030] In a variant, each of the thrust systems TSa to TSd of the aircraft 10 may consist of a propeller rotated by an electric engine and / or a heat engine, providing a thrust equivalent to that described by a turbojet-based thrust system as described with reference to Figures 1 and 1A. Regardless of the embodiment of the propulsion system, the electronic control system 30 controls the output of each of the thrust systems TSa to TSd based on measurements provided by an inertial navigation system 40, advantageously located close to the center of gravity CG10 of the aircraft 10, and on maneuver setpoints provided by a setpoint unit 20 in wired or wireless communication CL with the control system 30. Thus, via the setpoint unit 20, the control system 30 converts pilot instructions into commands for actuators (thrusters, deflectors) to adjust the thrust provided by each of the thrust systems TSa to TSd that results in the trajectory of the aircraft 10 required by the pilot relative to the attitude and position of the aircraft estimated by the measurement unit 40.

[0031] FIG. 1A illustrates such an aircraft 10 in terms of a reference system determined by three axes x, y, and z, each of which is inscribed in the plane of the platform 11 relative to the x- and y-axes and perpendicular to the x- and y-axes relative to the z-axis. The three axes x, y, and z intersect at the center of gravity CG10 of the aircraft 10. The x-axis extends from the aircraft's tail to its nose, and the y-axis extends from starboard to port. The z-axis represents a vertical line from the ground to the ground when the platform is horizontal. Such an aircraft 10 can move through the air according to rotations R, P, and Y induced about the x-, y-, and z-axes, respectively, by the control system 30 strategically adjusting the respective thrusts provided by the thrust units TSa through TSd. Thus, vertical lift of the aircraft 10 is induced by a simultaneous and identical increase in the thrusts provided by the four thrust units TSa through TSd, an increase sufficient to generate a lift greater than the weight of the aircraft 10. Conversely, vertical displacement of the aircraft from top to bottom is obtained by an identical and coordinated reduction in the thrust provided by the four thrust units TSa to TSd, which produces a lift force less than the weight of the aircraft 10.

[0032] To induce a forward (nose) or aft (tail) displacement of the aircraft 10, the control system 30 induces a thrust difference between the pairs of thrust units formed by thrust units TSa and TSd on the one hand and thrust units TSb and TSc on the other hand, respectively. Thus, a rotation P about the y-axis, also known as "pitch," is induced. The relative and combined lift of the pair {TSa, TSd} with respect to the pair {TSb, TSc}, induced by a positive thrust difference, induces a forward displacement of the aircraft. The opposite induces a rearward displacement of the aircraft 10.

[0033] To induce a displacement to port or starboard, the control system 30 induces a thrust difference between the pairs of thrust units formed by thrust units TSa and TSc on the one hand and thrust units TSd and TSb on the other hand, respectively. Thus, a rotation R about the x-axis, also known as "roll," is induced. The relative and combined lift of the pair {TSa, TSc} with respect to the pair {TSb, TSd}, induced by a positive thrust difference, induces a displacement of the aircraft 10 to port. The opposite induces a displacement of the aircraft 10 to starboard.

[0034] The control system 30 may further induce a Y-rotation of the aircraft about the z-axis, also known as "yaw." To this end, the control system 30 induces an asymmetrical tucking of the deflector guides of each thrust unit TSa-TSd of at least one pair of thrust units {TSa, TSb} or {TSc, TSd}. Referring to FIG. 2, such an asymmetrical tucking of the deflector guides 19a1, 19a-5 of the thrust unit TSa generates three components of thrust emanating from said thrust unit. These components are not strictly parallel to the direction of fluid discharge from the turbojets 12a-e, and thus perpendicular to the platform, but are oblique to the platform under the combined effect of one of the components AL12a, which remains parallel to the direction of fluid discharge by the turbojets 12a-e, and the dominant component AL12a' or AL12a" which is substantially perpendicular thereto. Depending on whether the component AL12a' is greater or less than the component AL12a'', a Y rotation about the y axis is induced in the clockwise or counterclockwise direction.

[0035] To ensure that no increase or decrease in altitude is caused during yaw, roll, or pitch, the control system 30 induces an increase equal to the decrease in the combined thrust provided by one or more pairs of thrust units involved by such asymmetrical sandwiching of the deflector guides, so that the total lift provided by all thrust units remains constant.

[0036] 3, for translating the pilot's instructions, the setpoint unit 20 may consist of a human-machine input interface including an input peripheral in the form of a pair of handles or levers, also called joysticks, 21 and 22. The invention is not limited to this choice of input peripheral, which may additionally or alternatively comprise a number of buttons, a tactile surface, or any other equally suitable means.

[0037] By way of example, according to Figures 3 and 3A (Figure 3A shows a top view of the joysticks 21 and 22), the joystick 21 can detect four displacements D21-1, D21-2, D21-3, D21-4 of the end part 21d of the lever 21 relative to its support part 21b, namely: The displacement D21-1 may indicate a setting from the pilot that increases the overall thrust of the aircraft and induces an increase in altitude; Contrary to the displacement D21-1, the displacement D21-2 indicates a setting from the pilot to reduce the overall thrust of the aircraft, which may induce a loss of altitude; Displacement D21-3 may indicate a setting from the pilot to rotate the aircraft 10 in a counterclockwise direction about the z-axis of FIG. 1A; Contrary to displacement D21-3, displacement D21-4 may indicate a setting from the pilot to rotate the aircraft 10 in a clockwise direction about the z-axis of FIG. 1A.

[0038] 3A, the joystick 22 allows four displacements D22-1, D22-2, D22-3, D22-4 of the end part 22d of the lever 22 relative to its support part 22b to be detected, namely: The displacement D22-1 may indicate a setting from the pilot that is intended to induce a forward displacement of the aircraft; Contrary to the displacement D22-1, the displacement D22-2 may indicate a setting from the pilot that induces a rearward displacement of the aircraft; Displacement D22-3 may indicate a setting from the pilot that induces a displacement of the aircraft to port, Contrary to the displacement D22-3, the displacement D22-4 may indicate a setting from the pilot who wishes to induce a displacement of the aircraft to starboard.

[0039] The set point unit 20 further comprises electronic means 23, such as one or more microcontrollers or microprocessors, for converting such displacements of the ends 21d and 22d of the levers 21 and 22 into electrical set point signals Gsp, which are intended to be transmitted to the control system 30 by wireless or wired paths CL. Such electronic means 23 may be duplicated in some redundant manner to provide a plurality of set point signals Gsp. → can be jointly generated.

[0040] The setpoint unit 20 may further comprise other components such as pushbuttons for translating commands to fire thrusters, for example, for signalling a loss of pilot capability and thus ensuring control of the aircraft, or for switching from manual to auxiliary piloting mode. The electronic means 23 of the setpoint unit 20 are arranged to further communicate the information provided by the components. Thus, the setpoint unit 20 sends a signal Gsp, for example of the PPM type, carrying a vector of information, or, if the means 23 are redundant, several signals Gsp → Among the vectors of information, there may be listed position Xsp settings, heading / yaw ψsp settings, settings for starting or stopping thrusters, steering mode identifiers, etc.

[0041] FIG. 4 shows a system 30 for controlling actuators TS, for example thrust units TSa-TSd of the aircraft 10 according to FIG. 1. The control system 30 integrates or cooperates with one or more inertial navigation systems 40 (accelerometers, gyroscopes, magnetometers), inertial navigation units (INUs), or even inertial measurement units (IMUs). Such measurement units 40 are designed in particular to estimate the position X^ and linear velocity V^ or angular velocity Ω^ of the aircraft 10. The linear velocity V^ and position X^ can be estimated with respect to the "NED (North East Down) coordinate" reference system, which is determined by three orthogonal axes, the first of which points in the direction of true north, the second in the direction of the center of the Earth, and the third in the direction of the east. The attitude Ψ^ and quaternion q^ of the aircraft, as well as any angular velocity Ω^, are generally estimated with respect to a reference system specific to the aircraft 10, as shown by the x, y, and z axes in FIG. 1A. The linear velocity and the position may optionally be corrected by a Kalman filter.

[0042] The control system 30 includes one or more flight control devices FC, the purpose of which is to integrate measurements provided by one or more measurement units 40 and maneuver setpoints provided by the setpoint unit 20 to provide to each thrust unit TSa-TSd (or more generally to the actuators TS) commands Δ, e.g. in the form of PPM signals or the like, which may convey components mainly related to pitch δp, roll δr, yaw δy and power / thrust δt.

[0043] FIG. 4 shows more specifically a schematic diagram of the architecture of a flight control device FC for an aircraft such as the drone 10 shown in FIG. 1. According to this example, the flight control device FC includes a number of controllers constituting two main stages, labeled STA and STB in FIG. 4. Stage STA is responsible for adjusting the position of the aircraft in the NED coordinate reference system. According to the example shown in FIG. 4, overall, stage STA generates a setpoint acceleration Asp on the one hand based on measurements coming from measurement unit 40, in this case estimates of the aircraft's position X̂ and linear velocity V̂, and on the other hand based on a position setpoint Xsp provided by setpoint unit 20 as described above with reference to FIGS. 3 and 3A.

[0044] The stage STB is responsible for adjusting the position of the aircraft in a reference system called the "body coordinate" reference system specific to the platform of the aircraft 10, as indicated by the x, y, z axes in Fig. 1A, and provides actuator command elements Δ for pitch δp, roll δr, yaw δy, based on, on the one hand, the outputs from the step STA (set acceleration Asp) and the heading / yaw setpoint ψsp coming from the control unit, and, on the other hand, on the measurements provided by the measurement unit 40 for the attitude ψ^, the quaternion q^, and the angular velocity Ω^. For this purpose, the interface 33 ensures the displacement of the reference point so that the set acceleration Asp and the heading / yaw setpoint ψsp are converted into the set quaternion qsp and the element δt of the power / thrust command Δ.

[0045] Each stage STA and STB may be "tuned" according to a different period or frequency. The frequency of the modulation performed by the two main stages STA and STB may be 50 Hz for the stage STA and 250 Hz to 1000 Hz for the stage STB.

[0046] According to the example shown in FIG. 4, each of the stages STA and STB includes two control devices 31, 32 for the stage STA and two control devices 34, 35 for the stage STB, respectively.

[0047] The device 31 for controlling the position of the aircraft provides a set velocity Vsp based on the difference between the set position Xsp and the estimated position X̂, and the control device 32 then compares this set velocity Vsp with the linear velocity V̂ estimated by the measurement unit 40 to generate the above-mentioned set acceleration Asp.

[0048] The device 34 for controlling the attitude of the stage STB, for its part, provides a set angular velocity Ωsp by comparing the set quaternion qsp with the estimated values ​​of the quaternion q̂ and the attitude Ψ̂ provided by the measurement unit 40. The device 35 for controlling the angular velocity of the stage STB then compares this set angular velocity Ωsp with the angular velocity Ω̂ of the aircraft estimated by said measurement unit 40 to finally generate the components of the control vector Δ for pitch δp, roll δr and yaw δy.

[0049] Advantageously, the device for controlling position 31 and the device for controlling attitude 34 generate respective outputs proportional to the difference between their inputs. On the other hand, the devices for controlling linear and angular velocity 32 and 35 generate outputs based on factors representing corrective actions proportional to the difference between their inputs, the integral and the derivative of said difference, respectively, using, for example, a PID controller. Each controller may advantageously include its own processing unit Ut (e.g., in the form of one or more microprocessors or microcontrollers cooperating with a data and / or program memory M) that samples, according to a predetermined frequency, the measured values ​​and / or setpoints provided by the measurement unit 40 and / or the setpoint unit 20, or more generally, by a source providing setpoints or measurement data. Such a source, which may therefore be called a "setpoint source," may be comprised of the setpoint unit 20 as described above with reference to FIG. 3. This is the case for the flight control device 30 if the flight control device 30 is considered as a whole, or for just the position controller 31 of such a flight control device FC. Such a setting source may furthermore consist of a device for controlling the position 31, a device for controlling the attitude 34 and also an interface device 33 for the linear velocity control module 31 and the angular velocity control module 35.

[0050] In a variant, such a flight control device FC may include only one processing unit Ut responsible for implementing the generation methods specific to the different electronic elements (position controller 31, attitude controller 34, linear velocity controller 32, or angular velocity controller 35, or interface 33). Regardless of whether the processing unit Ut of the flight control device is centralized or distributed, i.e. whether all or some of the different electronic elements of the flight control device include their own processing unit Ut (FIG. 4 shows such a situation for the control modules 34 and 35), the operation of the processing unit Ut may advantageously be determined by a suitable computer program, the program instructions of which are located in one or more data and / or program memories M cooperating with said processing unit.

[0051] 5 shows an embodiment of such a system 30 for controlling actuators TS according to the present invention, in which measurement, communication, and / or data processing elements are duplicated for reliability. According to this example, three flight control devices FC-1, FC-2, and FC-3 are similar to the control devices FC described above with reference to FIG. 4, but are provided within said control system 30 and perform similar processing based on measurement data coming from a measurement unit 40 and setpoint data provided by a setpoint unit 20. Thus, the three flight control devices FC-1 to FC-3 are individually responsible for generating commands Δ1, Δ2, or Δ3 for actuators TS, such as thrust units TSa to TSd of aircraft 10 already described with reference to FIG. 1. Thus, said commands Δ1, Δ2, or Δ3 collectively constitute the commands Δ of the control system 30. → Form.

[0052] Unlike known control systems with multiple redundancy, i.e., including several flight control units that generate commands Δ1, Δ2, and Δ3 independently based on measurement data GS and a common setpoint Gsp, the control system 30 according to the present invention is arranged so that the commands Δ1, Δ2, and Δ3 are jointly generated by redundant flight control units. To this end, the three flight control units FC-1, FC-2, and FC-3 are arranged to communicate with each other via a communication bus B so that each flight control unit knows the values ​​generated by its twin. More specifically, the control units (such as units 31, 32, 34, and 35 shown in FIG. 4 ) that respectively generate these values ​​and ensure the regulation of position, attitude, and linear and angular velocities are themselves aware of the data generated by their twins in the different flight control units FC-1 to FC-3. According to an advantageous embodiment, such communication bus B can consist of a CAN (Controller Area Network) data bus, which is advantageously redundant, i.e., duplicated for reliability, for example. Such a technical choice is advantageous for transmitting many data through only one cable and dividing them between different electronic elements of the control system 30 .

[0053] Thus, the outputs or commands Δ1, Δ2, and Δ3 provided by the flight control devices FC-1, FC-2, and FC-3, respectively, may also be generated by these flight control devices jointly, i.e., taking into account the outputs from the redundant flight control devices, rather than independently of one another. Thus, the commands Δ1, Δ2, and Δ3 jointly form the multiple redundant commands Δ → and transmitted to the actuator TS, more particularly its electronic control device, said control device of the actuator TS itself may optionally be multiple and redundant. Such control devices are subsumed in the concept of actuators in Fig. 5 for simplicity. Such control devices and / or actuators TS perform a process for selecting and / or arbitrating between the different commands Δ1, Δ2, and Δ3 to realize their function. Advantageously, such control devices may be configured to operate in response to the multiple commands Δ1, Δ2, and Δ3 provided by the control system 30. → Based on this, a "single" command Δ is generated, where the command Δ is one of the commands Δ1, Δ2, and Δ3 jointly generated by the redundant flight control devices FC-1, FC-2, and FC-3, respectively, if only two of the redundant flight control devices FC-1, FC-2, and FC-3 retain their capability to generate such a command (this situation may occur if one of the three flight control devices fails); the plurality of commands Δ1, Δ2, and Δ3 jointly generated by the redundant flight control devices; → The median of

[0054] In a variant, such a control system according to the invention may be implemented by a plurality of commands Δ1, Δ2 and Δ3 jointly generated by three flight control devices FC-1, FC-2 and FC-3, respectively. → , thus relieving the actuator TS of such arbitration tasks. In this case, such control system 30 may include arbitration means (not shown in FIG. 5 for simplicity) for formulating such command Δ according to techniques similar to those disclosed above for arbitration that the actuator may perform.

[0055] According to the example shown in FIG. 5, the measurement unit 40 may be further augmented by three redundant measurement units 40-1, 40-2, and 40-3, which respectively provide their measurements to three flight control devices FC-1, FC-2, and FC-3. These flight control devices FC-1, FC-2, and FC-3 may transmit to their twins, via communication bus B, the measurement data provided by the measurement units dedicated to each flight control device. Thus, according to the example shown in FIG. 5, the measurement unit 40-1 provides measurement data Gs1 to the flight control device FC-1 in the form of estimates of the position X1^, linear velocity V1^, and angular velocity Ω1^ of the aircraft 10, its attitude Ψ1^, and quaternion q1^. Similarly, the measurement unit 40-2 provides measurement data Gs2 to the flight control device FC-2 in the form of estimates of the position X2^, linear velocity V2^, and angular velocity Ω2^ of the aircraft 10, its attitude Ψ2^, and quaternion q2^. Finally, the measurement unit 40-3 provides measurement data Gs3 to the flight control device FC-3 in the form of estimates of the position V3^, linear velocity V3^ and angular velocity Ω3^ of the aircraft 10, its attitude Ψ3^ and the quaternion q3^. In a variant, the three measurement units 40-1, 40-2, 40-3 can be connected to the three flight control devices FC-1, FC-2, FC-3 via a communication bus B.

[0056] Via communication bus B, setpoint unit 20 provides setpoints Gsp for position Xsp, heading and yaw ψsp to the three flight control units FC-1, FC-2 and FC-3. Such setpoints may further be provided by a plurality of Gsp if the setpoint unit has multiple redundancy. → Figure 5 further shows that instead of or in addition to the setpoint unit 20, there may be a navigation aid module 20a that can assist the pilot and provide setpoints Gsp for position Xsp, heading and yaw ψsp as a complement.

[0057] In an ideal world, the three flight control units FC-1, FC-2, and FC-3 would be completely identical, capable of sampling the data or signals transmitted by data bus B at infinite frequency, and would therefore immediately share their generated data with their twins. The measurement units, for their part, would provide identical, noise-free estimates. In such an ideal world, there could be no difference or discrepancy between the commands Δ1, Δ2, and Δ3 provided to the actuators TS. However, this ideal world is unrealistic. Therefore, there is a delay between each flight control unit's reading or sampling of the data generated by its twin and its own generation of that data. In reality, the sampling frequency of the data available via communication bus B cannot be infinite, the measurement data may be noisy and may vary depending on the measurement units 40-1, 40-2, and 40-3 under consideration, and the electronics and clocks in each of the redundant flight control units FC-1, FC-2, and FC-3 cannot be perfectly replicated or synchronized. Therefore, the commands Δ1, Δ2, and Δ3 often deviate or even differ from one another, losing accuracy and validity, to the detriment of aircraft operation. To address such real-world and / or technical constraints, the present invention provides for assigning, in each flight control device FC-1, FC-2, FC-3 in the control system 30, or even in each respective controller 31, 32, 34, 35 of each of said flight control devices FC-1, FC-2, FC-3, a method for correcting the generated values ​​of variables, taking into account the generated values ​​from the controller and / or twin flight control devices. Thanks to the implementation of such a method according to the present invention, the commands Δ1, Δ2, and Δ3 are jointly generated by the flight control devices FC-1, FC-2, FC-3 and do not differ in the planned operation (i.e., according to the design constraints), so that the actuators TS can take into account consistent and accurate commands Δ1, Δ2, and Δ3.

[0058] It is important to emphasize that if the control system 30 includes only two redundant flight control devices, or if only two of the three flight control devices shown in FIG. 5 retain their generation capability, it is particularly advantageous for the redundant commands to remain consistent and not contradict each other. Indeed, even if the actuator TS considers only one of the two commands during its arbitration, if a failure occurs in the flight control device generating the command used up to that point, and the actuator TS must then select and use the second command in place of the now unavailable first command, the actuator will not experience any significant change in control, and therefore operation. If the generation by the two redundant flight control devices were performed in parallel, i.e., independently of each other, and not jointly as in accordance with the present invention, the situation would be significantly different. In fact, without the contribution of the present invention, the commands provided by the two redundant flight control devices may gradually diverge from each other. During the command switchover, the aircraft's operation would lose continuity. Such a correction method, specific to the invention, allowing the joint generation of redundant commands, can be implemented by a processing unit of the flight control device FC itself (i.e., in a centralized manner) or by one of the processing units of the different control devices 31, 32, 34, and 35 contained therein (i.e., in a distributed manner). Hereinafter, the expression "servo device" will be used indifferently to denote such a flight control device itself or a control device contained therein.

[0059] In order to adapt the operation of such a servo device, program instructions that can be interpreted by the processing unit of said servo device can be placed in its non-volatile memory M. Such program instructions are therefore designed so that their execution by the processing unit Ut of such a servo device implements the method for correcting the generation of the value of the variable in question according to the invention. Such program instructions constitute the computer program itself and can be transmitted or stored on any suitable storage medium.

[0060] 6 shows such a method 100 according to the invention, intended to be implemented by a processing unit Ut of one of several redundant servo devices of a system for controlling actuators. Advantageously, such a method 100 is provided to be implemented by each of the redundant servo devices. These redundant servo devices are arranged to generate identical values ​​of the variable G based on identical setpoint values ​​Gsp and identical measurement data Gs. To jointly generate such a variable, the servo devices communicate with each other, for example via a communication bus B as shown in FIG. 5, so that each servo device can know, i.e., access, by reading, via the communication bus B, the latest value of the variable G generated by the redundant servo device.

[0061] Such a method 100 is carried out iteratively according to a predetermined frequency SP. As mentioned above, without limiting the invention in any way, such frequency SP can be selected to be comprised between 50 and 100 Hz for the control device of stage STA or between 250 and 1000 Hz for the control device of stage STB in the control device FC according to FIG.

[0062] Such a method 100 includes an initial step 110 of generating a value Gl of a variable G based on a setpoint Gsp and measured data Gs.

[0063] It then reads, for example via communication bus B, the most recent values ​​of the variables generated by the redundant servo device, and based on the read and accessed values ​​and the values ​​generated in step 110, calculates a set G of current values ​​of the variables G. → 120.

[0064] According to a first example of implementation by the system 30 for controlling the actuators TS according to Fig. 5, the servo system implementing the method 100 may consist of a flight control device FC-1, flight control devices FC-2 and FC-3 which are twin servo systems of the control device FC-1. In this case, the mentioned variable G is the actuator command Δ → and its value G1 is a command Δ1 if the servo unit implementing the method 100 is the control unit FC-1, or a command Δ2 if the servo unit FC-2 is implementing the method 100 for that matter, the flight control units FC-1 and FC-3 being twin servo units, and the same applies to the flight control unit FC-3. According to this first example, the set G → is composed of the commands Δ1, Δ2, and Δ3. The setpoint Gsp, for its part, is composed of elements relating to the position Xsp, the heading, and the yaw ψsp coming from a setpoint unit such as unit 20 according to Fig. 5. The measurement data Gs, for its part, is composed of the totality of the estimates of the position X̂, the linear velocity V̂, the attitude ψ̂, and the quaternion q̂, and the angular velocity Ω̂ provided by the measurement unit 40 according to said Fig. 4, as well as the estimates provided by the redundant measurement units 40-1, 40-2, and 40-3, respectively, according to the example shown in Fig. 5.

[0065] According to a second example of implementation of the method 100 according to the invention, implemented by the control system 30 of the actuator TS according to Fig. 5, the redundant servo device implementing said method 100 can be the linear velocity controller 32 of each of the flight control devices FC-1, FC-2 and FC-3, or even the angular velocity controller 35 of each of the flight control devices FC-1, FC-2 and FC-3 (if the flight control devices FC-1, FC-2 and FC-3 are configured like the flight control devices FC shown in Fig. 4). If the redundant servo device is a linear velocity controller 32, the variable G is the set acceleration Asp, or more specifically, its element representing integral action if the velocity controller 32 comprises a PID controller. The set value Gsp, for its part, consists of the set linear velocity Vsp, which is itself generated by the position controller of the flight control device FC-1, FC-2 or FC-3 in question. The set value Gsp is → is composed of the set acceleration Asp generated by the twin speed controller 32 or just one component of said set acceleration Asp which represents the integral action of the PID controller of the twin speed controller.

[0066] Alternatively or additionally, the redundant servo system implementing the method 100 according to the invention may consist of the position controller 31 of each of the flight control systems FC-1, FC-2 and FC-3. The variable G under consideration is therefore the setpoint linear velocity Vsp. The setpoint Gsp, for its part, is composed of elements relating to the position Xsp, the heading and the yaw ψsp coming from the setpoint unit 20, while the measurement data Gs are the aircraft position estimated by the measurement units 40, 40-1, 40-2, 40-3.

[0067] In order to combine or jointly generate values ​​of variables for redundant servo devices, it is necessary to correct the values ​​generated in step 110 to take into account the generated values ​​from said redundant or twin servo devices. For this purpose, the method 100 according to the invention further comprises the step of generating a set G → , i.e., in step 120, the set G →The step 130 includes determining a reference value Gr of said variable selected from among the values ​​forming

[0068] Although the elements of the actuator control system 30 each perform the method 100 in a distributed manner, if the actuator control system 30 includes at least three redundant servo devices (such as controllers FC-1, FC-2, FC-3, or their position, orientation, and / or linear or angular velocity controllers) capable of generating and communicating values ​​for the variable G, the present invention provides that the step 130 of determining the reference value Gr is performed by using the set G of current values ​​of the variable G. → The "median" may consist of determining the median of the values ​​forming a data set, in this case the set G → The median means the midpoint of a set G, where 50 percent of the data have a value less than or equal to the median and 50 percent of the data have a value greater than or equal to the median. For small data sets, it is sufficient to count the number of data and rank them in increasing order according to their respective values. If the number of data is odd, it is necessary to increase the number by 1 and divide it by 2 to obtain the rank indicating the median. The rank is calculated by dividing the set G by the number of data points G. → is the position of the value when the values ​​are ordered. That is, the lowest value corresponds to the first rank, the second lowest value corresponds to the second rank, and so on. Thus, following the example of a triple redundant system, the median value would be selected as the value of the second-ranked variable, or again as the midpoint between the two minimum and maximum values. Selecting the median value avoids deviations caused by certain prior art techniques that favor an average or single selection when the output value from one of the servo devices clearly deviates from all the rest.

[0069] On the other hand, if the control system 30 includes only two redundant servo units, or even if only two of the servo units are still capable of generating values ​​for the variable G, the step 130 of determining the reference value Gr may be performed using the set G of current values ​​of the variable G. →and selecting, from among the current values ​​of the variable G generated by the first or second servo unit that is still capable of generating a value for the variable G, one of the current values ​​of the variable G generated by the first or second servo unit. Such selection may be biased towards the servo unit with the lowest index number if the redundant servo units are identified by index, or according to any other technique for choosing an alternating or random selection.

[0070] Subsequently, the method 100 includes a step 140 of calculating a difference Ge between the current value Gl of the variable G generated in step 110 and the reference value Gr, and a step 150 of generating a corrected current value Gl' of the variable G, which comprises performing an operation of subtracting a correction value Gc. The correction value Gc is the result of multiplying the difference Ge by a correction factor Kc of the current value Gl resulting from step 110. In this way, the final generated value Gl' from each of the redundant servo units is combined with that of the other redundant servo units. These redundant servo units in effect jointly generate the corrected value Gl' of the variable G.

[0071] To perform step 150 of generating a corrected current value Gl' of the variable G, the value of the correction coefficient Kc, which induces the combination of the respective generated values ​​from the redundant servo devices, can be predetermined and written, for example, to the memory M of each servo device. The selection of the value of the correction coefficient Kc has different notable technical effects on the behavior required of the control system 30, as will be seen later with reference to FIGS. 7, 7A, and 8. Depending on the variable G under consideration, the value of the correction coefficient Kc can be selected as equal to 1, which means that the entire difference Ge between the current value Gl of the variable G and the reference value Gr generated by one of the redundant servo devices is subtracted from the current value Gl, which takes the reference value Gr as its value. In a variant, only a part of the difference Ge can be subtracted from the current value Gl to generate the corrected value Gl'. Thus, to sample the values ​​generated by one or more twin servo devices in step 120, i.e., the set G of current values ​​of the variable G generated by the set of redundant servo devices, →To construct the set G, the correction factor value Kc may be empirically selected, for example, according to criteria based on the variability of the variable G with respect to the frequency SP. For example, a correction factor Kc having a low value, for example, on the order of 5 percent, would be preferred for a variable G whose value varies greatly with the frequency SP, and conversely, a factor close to or equal to 100 percent would be preferred in the opposite case. Furthermore, the set G → To construct the correction coefficient Kc, it is possible to select a small correction coefficient Kc when there is a large delay between the current values ​​generated by the different redundant servo devices, and a value close to or equal to 100 percent in the opposite case. Thus, if the variable G in question is a factor representing the integral action of the PID controller 32 for linear velocity control, it is possible to support a Kc value between 80 and 100 percent. Alternatively or additionally, if the variable G in question is a factor representing the integral action of the PID controller 35 for angular velocity control, it is possible to support a Kc value between 5 and 30 percent. The present invention will not be limited to these configuration examples. Therefore, in order to exchange the respective generated values ​​from the redundant servo devices, or even the respective repetition frequencies SP of each of these redundant servo devices, the memory M of the servo device can contain a table of possible values ​​for the correction coefficient Kc depending on the variable G in question, depending on the performance of the communication means B.

[0072] The correction value Kc may be predetermined during the design or tuning phase of the control system or during the simulation phase of such a system 30 to adjust the technical coupling effect determined by implementing the method 100 depending on one or more variables G under consideration.

[0073] In a variant, the value of the correction factor Kc can be dynamic and adjusted in real time by each redundant servo device of the control system. In this case, the invention provides that such a servo device can, in step 151, build a log of a defined number of values ​​of the variable Gl generated in step 110 or the variable Gl' corrected in step 150 to estimate its variability. Thus, before the implementation of step 150, or even according to an execution frequency lower than the iteration frequency SP of steps 110, 120, 130, 140 and 150, in step 101 the value of the correction factor Kc is calculated based on an estimate of the variability of the previous value of the variable G and the set G → The step 120 of constructing the parameter .sub.i can be dynamically adjusted depending on the repetition frequency SP of the step 120 of constructing the parameter . Such adjustment 101 can be determined by pre-established calculation rules. According to a variant of the embodiment, such adjustment 101 can be performed, for example, via a number of flight simulations or more generally by a neural network pre-trained using data collected from the servo control of various variables.

[0074] Alternatively or additionally to weighting the correction value Gc by selecting an appropriate correction coefficient Kc for the particular variable G in question, the invention provides for limiting said correction value Gc in absolute value before subtracting it from the value Gl generated in step 110. For this purpose, step 150 for generating the correction value Gc may be arranged to limit the correction value Gc in absolute value to a limit value L. Thus, if the correction value Gc calculated on the basis of the difference Ge between the current value Gl of the variable G and the reference value Gr exceeds said limit value L in absolute value, the absolute value of said correction value Gc takes on said limit value L as value. By way of non-limiting example, such value L may be calculated as a percentage of the reference variable Gr strictly above 0% and strictly below 30%.

[0075] This double setting of step 150, on the one hand by the value of the correction factor Kc and on the other hand by the limit value L, provides a very sophisticated procedure for adjusting the behavior expected by the control system 30 of the actuator TS according to the invention.

[0076] As shown in Figure 5, certain input data for a servo system may be redundant, i.e., originate from multiple sources. This may be the case when measurement data is provided to the servo system by multiple redundant sources, or when deliberate injection of values ​​generated by similarly redundant third-party servo systems is provided at the input to the servo system via communication bus B. For example, with reference to Figures 4 and 5, it may be possible to provide at the input to linear velocity servo system 32 an estimate of the aircraft's linear velocity provided by measurement units 40-1, 40-2, and 40-3 on the one hand, and a set linear velocity provided by position controllers 31 of different flight control systems FC-1, FC-2, and FC-3, respectively, on the other hand.

[0077] The same can be said for the position controller 31, attitude controller 34, or angular velocity controller 35 of each of the redundant flight controllers FC-1, FC-2, and FC-3.

[0078] Thus, with reference to FIG. 6, the setpoint Gsp may be a setpoint of multiple Gsp values ​​each provided by a redundant source providing said setpoint for the actuator control system. → In this case, the method 100 according to the present invention is such that the set value Gsp is -This multiple value Gsp → contains only two values, i.e., only two redundant sources provide such a setting value, one of the plurality of values ​​may be -This multiple value Gsp → comprises at least three values, i.e., at least three redundant sources provide such a setting value, the method may include a step 102 of generating the setting value Gsp so that it takes the median value of the plurality of values.

[0079] Similarly, the step 110 for generating the value Gl of the variable G is performed by using a setpoint Gsp and a number of values ​​Gs respectively provided by redundant sources of the control system (for example measuring units 40-1, 40-2, 40-3 according to FIG. 5). → and measurement data Gs consisting of: -This multiple value Gs → If Gs contains only two values, i.e., only two redundant sources provide measurement data, then the plurality of values ​​Gs → One of the -This multiple value Gs → If Gs includes at least three values, i.e., if at least three redundant sources provide such measurement data, the method may include a step 103 of generating the measurement data Gs so that it takes the median value of the plurality of values ​​as its value.

[0080] 4 and 5, and with reference to FIGS. 7, 7A and 8, it is possible to explain the different contributions obtained by implementing the invention and the influence of the choice of the value of the correction coefficient Kc on the operation of the control system according to the invention. The two FIGS. 7 and 8 respectively show the relationship between two variables G, in this case the command Δ → 4. In particular, the elements of these variables that represent the integral action of the PID controller of the angular velocity controller 35 according to FIG.

[0081] FIG. 7 shows the pitch δp command Δ generated by the flight control units FC-1, FC-2, and FC-3, respectively. → Therefore, each generated value related to the pitch δp of the flight control device is - the curve with a solid line for the control device FC-1 (element δp1), - the curve shown with a dotted line for the control device FC-2 (element δp2), - Appears in the curve with dashed lines for the control device FC-3 (element δp3).

[0082] 7 shows, via three separate graphs, the respective generated values ​​from the flight control devices FC-1, FC-2, and FC-3 over time t, depending on three different values ​​of the correction coefficient Kc, respectively equal to 0, 0.05, and 1. The top graph corresponds to the case where the correction coefficient Kc is zero (Kc=0), i.e., the situation according to the prior art (no correction of the respective generated values ​​from the flight control devices FC-1, FC-2, and FC-3). The middle graph corresponds to the case where the correction coefficient Kc is equal to 0.05 (Kc=0.05), i.e., the partial combination of the respective generated values ​​from the flight control devices FC-1, FC-2, and FC-3. Finally, the bottom graph corresponds to the case where the correction coefficient Kc is equal to 1 (Kc=1), i.e., the full combination of the respective generated values ​​from the flight control devices FC-1, FC-2, and FC-3.

[0083] It may be noted that when the value of the correction coefficient Kc is 0 (the situation shown in the top graph of FIG. 7), the servo systems—in this case, the PID controllers of the angular velocity controllers 35 of the flight control devices FC-1, FC-2, and FC-3—are not coupled. The three curves δp1, δp2, and δp3 show their respective output values, but they differ greatly and fluctuate significantly. However, the implementation of the present invention results in a significant technical effect of convergence and consistency of the output values ​​from the flight control devices FC-1, FC-2, and FC-3, as shown in the middle and bottom graphs of FIG. 7. These graphs show three curves δp1, δp2, and δp3 that are nearly superimposable to the naked eye, indicating excellent instantaneous coupling as soon as the correction coefficient Kc becomes greater than 0. A very low value, 0.05 for example shown in the middle graph of Figure 7, leads to very good coupling, symbolized by the almost perfect overlap of the three curves δp1, δp2, and δp3 (as shown by the partial enlargement of the three curves δp1, δp2, and δp3). The same applies to the total coupling obtained by choosing a value of the correction coefficient Kc equal to 1. The curves δp1, δp2, and δp3 are furthermore perfectly overlapping, which is synonymous with very strong coupling and complete coherence, as shown by the partial enlargement of the curves δp1, δp2, and δp3. Considering more specifically the middle and bottom two graphs for values ​​of 0.05 and 1, respectively, of the correction coefficient Kc, it can be noted that a value of the correction coefficient Kc equal to 0.05 maintains high responsiveness (the slopes of the curves δp1, δp2, and δp3 are very steep or vertical at the instant t i when the system responds to a setpoint that would result in a significant slope in the values ​​of the elements δp1, δp2, and δp3) over the aligned and combined product values ​​from the three flight control devices FC-1, FC-2, and FC-3. Nevertheless, such responsiveness can be reduced by a larger value of the correction coefficient Kc (in this case, a value equal to 1, for the bottom graph of FIG. 7). The slopes of the curves δp1, δp2, and δp3 become, in fact, less vertical at the instant t i.However, the superimposed curves δp1, δp2, and δp3 are smoother or more stable than those represented by the middle graph, and even more so than those shown in the top graph (without correction). Thus, the choice of correction factor value Kc determines the desired compromise between responsiveness and stability. This effect on responsiveness and stability is more precisely illustrated by Figure 7A, which shows three curves each representing the value of a single component, pitch δp1, generated by the flight control device FC-1 for three different values ​​of the correction factor Kc. - As a curve with a solid line for a Kc value of 0 (K=0), As the dotted curve for a Kc value equal to -0.05 (K=0.05), It is superimposed as a curve with a dashed line for Kc values ​​equal to -1 (K=1).

[0084] FIG. 7A shows the tangents tg0, tg1, and tg2 of the three δp1 curves (for Kc=0, Kc=0.05, and Kc=1, respectively) at the instant t when the system responds to a setpoint that would likely result in a significant change in the value of the δp1 element. Tangent line tg0, shown as a solid line, is nearly vertical and indicates the very high responsiveness of the control system when there is no coupling (Kc=0) with the respective outputs from the redundant flight control devices FC-2 and FC-3. Tangent line tg1, shown as a dotted line, still indicates the very high responsiveness of the control system during weak coupling (Kc=0.05). In fact, the angle α1, determined by the tangents tg0 and tg1, has a small value, indicating a slight decrease in responsiveness. Tangent line tg2, shown as a dashed line, indicates the responsiveness of the control system during strong coupling (Kc=1). The angle α2 determined by the tangents tg0 and tg2 is much larger than the angle α1, indicating a lower response.

[0085] However, Figure 7A shows that this offers stability, possibly at the expense of reduced responsiveness. Thus, although the average amplitude of the fluctuations of the component δp1 is very large (this is shown by the line A0 in Figure 7), which is synonymous with instability, as soon as the present invention obtains coupling between the respective outputs from the redundant flight control devices, even at a minimum (correction coefficient value Kc = 0.05), such average amplitude, shown by the line A1, becomes very small, or even approaches zero, as shown by the line A2, which shows the average amplitude for a strong coupling (Kc = 1).

[0086] Other respective generated values ​​from the three flight control units FC-1, FC-2, and FC-3, in this case the command Δ for roll δr → When the present invention is implemented to combine elements representing the integral action of the PID controller of angular velocity controller 35 associated with the elements of , one can notice the remarkable similar contribution obtained by the present invention by observing FIG.

[0087] In fact, Figure 8 shows the generated values ​​for the pitch δp command generated by the flight control devices FC-1, FC-2, and FC-3, respectively. - as a curve with a solid line for the control device FC-1 (element δr1), - as the curve shown by the dotted line for the control device FC-2 (element δr2), - Appears as a curve with a dashed line for the control device FC-3 (element δr3).

[0088] Similar to FIG. 7, FIG. 8 shows, in three separate graphs at the top, middle, and bottom of FIG. 8, the respective generated values ​​from the flight control devices FC-1, FC-2, and FC-3 over time t, depending on three different values ​​of the correction coefficient Kc equal to 0, 0.05, and 1, respectively. The top graph corresponds to a zero value for the correction coefficient Kc, i.e., the prior art situation (no correction of the respective generated values ​​from the flight control devices FC-1, FC-2, and FC-3). The middle graph corresponds to a value for the correction coefficient Kc equal to 0.05, i.e., a partial combination of the respective generated values ​​from the flight control devices FC-1, FC-2, and FC-3. Finally, the bottom graph corresponds to a value for the correction coefficient Kc equal to 1, i.e., a full combination of the respective generated values ​​from the flight control devices FC-1, FC-2, and FC-3.

[0089] It may be noted that when the value of the correction coefficient Kc is 0 (the situation shown in the top graph of FIG. 8), the servo systems—in this case, the PID controllers of the angular velocity controllers 35 of flight control units FC-1, FC-2, and FC-3—are not coupled. The three curves δr1, δr2, and δr3 show their respective product values, but with increasing divergence and very significant fluctuations. Conversely, with the implementation of the present invention, as soon as the correction coefficient Kc is greater than 0, immediate coupling is demonstrated. A very low value, 0.05, as shown in the middle graph of FIG. 8, results in almost perfect overlap of the three curves δr1, δr2, and δr3. The same applies to the total coupling obtained by selecting a value of the correction coefficient Kc equal to 1. The curves δr1, δr2, and δr3 completely overlap, which is synonymous with very strong coupling and strong cohesion. Considering the two middle and bottom graphs more specifically, for values ​​of the correction coefficient Kc of 0.05 and 1, respectively, it can be noted that a value of the correction coefficient Kc equal to 0.05 maintains high responsiveness over consistent output values ​​from the three flight control devices FC-1, FC-2, and FC-3. Indeed, the slopes of the curves δr1, δr2, and δr3 are very steep or vertical at the moment tj when the system responds to a setpoint that would likely result in a significant change in the values ​​of the elements δr1, δr2, or δr3. However, when considering values ​​of the elements δr1, δr2, and δr3 resulting from a larger value of the correction coefficient Kc (in this case, a value equal to 1 for the bottom graph of FIG. 8), such slopes become less vertical. Conversely, the superimposed curves are smoother or more stable than those represented by the middle graph. FIG. 8 thus confirms that the choice of the correction coefficient Kc value allows for determining a compromise between the desired responsiveness and stability of the system.

[0090] The present invention has been described with reference to various configurations of systems for controlling actuators, more particularly thrust units of aircraft. The present invention is not limited to this single example of a system for controlling actuators. It relates more generally to any control system including one or more multiple redundant servo devices applied to home automation, industry, or land, sea, air, or space vehicles, whether said actuators enable them to move or regulate their internal temperature, atmosphere, or lighting.

Claims

1. A method (100) implemented by a processing unit of one of several redundant servo devices (FC-1, FC-2, FC-3) of a system (30) for controlling an actuator (TS), each of which generates identical values ​​of a variable (G) based on identical set values ​​(Gsp) and identical measurement data (Gs), said generated values ​​being used by the system (30) to control said actuator (TS), said redundant servo devices (FC-1, FC-2, FC-3) furthermore communicating with each other such that each redundant servo device has access by reading to the latest value of said variable (G) generated by said redundant servo device, said method comprising: generating (110) a current value (Gl) of the variable (G) based on the set value (Gsp) and the measurement data (Gs); Read the latest value of the variable (G) generated by the redundant servo device, and generate a set of current values ​​of the variable (G) (G → ) (120); The set (G → determining (130) a reference value (Gr) of said variable (G) taken from Calculating (140) the difference (Ge) between the current value (Gl) of the generated variable (G) and the reference value (Gr); and a step (150) of correcting the current value (Gl) by subtracting from the current value (Gl) a correction value (Gc) resulting from multiplying the difference (Ge) by a correction coefficient (Kc) for the current value (Gl) to generate a corrected current value (Gl') of the variable (G).

2. the system includes at least three redundant servo units capable of generating values ​​of the variable (G); The step of determining (130) the reference value (Gr) is performed by determining the set (G → 2. The method (100) of claim 1, comprising selecting the median value of .

3. the system includes only two redundant servo units capable of generating values ​​for the variable (G); The step of determining (130) the reference value (Gr) is performed by determining the set (G → 2. The method of claim 1, further comprising selecting one of the values ​​of

4. The method (100) according to any one of claims 1 to 3, wherein the value of the correction factor (Kc) is predetermined.

5. 4. A method (100) according to claim 1, comprising a step (151) of recording the current value (Gl) or the corrected value (Gl') of the variable (G) in a data memory (M) of a first servo device to build a log of a defined number of values, and a step (101) of generating, before the correction step (150), a value of the correction coefficient (Kc) that depends on the variability of the values ​​taken from the log and on the repetition frequency (SP) of the step (120) of reading the latest value of the variable (G) generated by the redundant servo device.

6. 6. The method (100) according to any one of claims 1 to 5, wherein the calculation of the correction value (Gc) is adjusted so that the absolute value of the correction value (Gc) does not exceed a predetermined limit value (L).

7. 7. A method (100) according to any one of claims 1 to 6, wherein the redundant servo devices each include a PID compensator providing three components of an output signal representing proportional action, integral action, and derivative action, respectively, and the variable (G) is composed of the component representing the integral action of the PID compensator.

8. The control system (30) controls a plurality of set points (Gsp → ), the setpoint (Gsp) is If the control system (30) includes only two redundant sources, the plurality of values ​​(Gsp → ) one of If the control system has at least three redundant sources, the plurality of values ​​(Gsp → 8. The method (100) according to claim 1, further comprising the step (102) of generating the setpoint (Gsp) so that it takes the median value of

9. The control system (30) → ) in the case where the measurement data (Gs) includes redundant sources arranged to jointly provide a plurality of values ​​of If the control system includes only two redundant sources, the plurality of values ​​(Gs → ) one of If the control system includes at least three redundant sources, the plurality of values ​​(Gs → 9. The method (100) according to claim 1, further comprising generating (103) the measurement data (Gs) so that the measurement data (Gs) takes a median value of

10. A servo system (30) for controlling an actuator (TS), said system (30) having identical setpoints (Gsp, Gsp → 10. A servo device comprising: a plurality of redundant servo devices (FC-1, FC-2, FC-3) each generating identical variable values ​​(Δ1, Δ2, Δ3) based on a first parameter (Gs1) and identical measurement data (Gs1, Gs2, Gs3), the redundant servo devices (FC-1, FC-2, FC-3) communicating with each other such that each servo device accesses by reading the latest value (Δ1, Δ2, Δ3) of the variable generated by the redundant servo device (B), the servo devices (FC-1, FC-2, FC-3) being configured to perform a method (100) according to any one of claims 1 to 9.

11. A control system (30) for an actuator (TS) including a plurality of redundant servo devices (FC-1, FC-2, FC-3) according to claim 10, wherein the command (Δ → , Δ) is generated based on a plurality of values ​​(Δ1, Δ2, Δ3) of the variable jointly generated by the redundant servo devices.

12. The command (Δ) is The plurality of values ​​(Δ → , Δ1, Δ2, Δ3) includes only two values, → , Δ1, Δ2, Δ3) The plurality of values ​​(Δ → , Δ1, Δ2, Δ3) includes at least three values, → 12. The system (30) of claim 11, wherein the ΔΨ is generated based on a median of ΔΨ, ΔΨ, ΔΨ, ΔΨ.

13. A vehicle (10) for a pilot, passengers and / or a load constituted by goods or merchandise, comprising one or more actuators in the form of at least one thrust unit (TSa, TSb, TSc, TSd) for moving said vehicle (10), and commands (Δ → , Δ) is generated by a control system (30) according to claim 12.

14. 14. A vehicle (10) according to claim 13, comprising an aircraft (10).

15. A computer program comprising one or more program instructions that can be interpreted by a processing unit (Ut) of one of a plurality of redundant servo devices (FC-1, FC-2, FC-3) of a system (30) for controlling an actuator (TS), the program instructions being placed in a non-volatile memory (M) of the servo device, and that can be designed such that execution of the instructions by the processing unit (Ut) implements a method (100) according to any one of claims 1 to 9.

16. 16. A computer-readable storage medium containing the instructions of the computer program of claim 15.

Citation Information

Patent Citations

  • Control system

    JP1994324702A

  • House provided with garage

    JP2002021341A

  • Distributed Flight Control System

    JP2020503209A

  • Improved Flight System

    JP2021505480A