Distributed Engine Control Architecture for Harsh-Environment I/O

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current gas turbine engine control systems face challenges with high data throughput, harsh environmental conditions, rapid processor obsolescence, and cybersecurity requirements, necessitating a distributed control system architecture that can handle extreme temperatures and vibrational loads while minimizing redesign costs and ensuring cyber security.

Innovation Solution

A distributed control system architecture is implemented, with a computation module and I/O module designed to operate in different environments, utilizing commercial-off-the-shelf processors in benign areas and low-power processors in harsh areas, connected by a high-bandwidth network, allowing for flexible allocation of processing tasks and enhanced cybersecurity through fiber optic communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If control systems use multiple I/O data connections to handle high data throughput rates, then data throughput capability is improved, but physical location constraints and system complexity increase

Engineering Contradiction:
Improvedata throughput rateVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The control system is divided into multiple independent control nodes, each capable of autonomous operation. This segmentation allows data processing to be distributed across multiple nodes rather than requiring all data to flow through a single centralized system, thereby handling high data throughput rates while reducing the complexity of any single node's I/O connections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical control architecture with multiple levels (engine-level, platform-level, and facility-level control nodes). This dimensional expansion from a flat to a hierarchical structure allows data throughput to be managed across different levels of abstraction, reducing the immediate I/O burden at any single level while maintaining overall system capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If control systems are customized in a bespoke manner for specific purposes, then adaptability to specific applications is improved, but manufacturing cost and development time increase

Engineering Contradiction:
Improveapplication-specific adaptabilityVSAvoidmanufacturing cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The control nodes are designed with universal, standardized interfaces and communication protocols that allow them to be deployed across multiple different applications and platforms. This universality enables the same hardware platform to be adapted to various specific purposes through software configuration rather than hardware customization, thereby reducing manufacturing costs while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The control system employs dynamic, reconfigurable software modules that can be loaded and unloaded based on specific application requirements. This dynamic adaptability allows a single standardized hardware platform to perform multiple different functions by changing its software configuration, eliminating the need for costly bespoke hardware design for each application.

Inventive Principle:
Principle #15Dynamics

3Productivity

If control systems use commercially available processors to handle future data throughput requirements, then processing capability is improved, but cybersecurity vulnerability and reliability in harsh environments worsen

Engineering Contradiction:
Improveprocessing capabilityVSAvoidcybersecurity and environmental reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The control system separates critical safety functions from general processing functions by distributing them across different control nodes with appropriate security levels. Commercial processors handle non-critical data processing while dedicated, hardened processors handle safety-critical functions, thereby maintaining cybersecurity and reliability while utilizing the high processing capability of commercial processors where appropriate.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces secure communication interfaces and protocol layers as intermediaries between commercial processors and the control system's critical functions. These intermediary layers provide cybersecurity protection and environmental hardening, allowing commercial processors to be used for high-capacity data processing while maintaining system-wide reliability and security through the protective intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3608734B1Distributed control and monitoring system for multiple platforms
Publication Date: 2022.10.19 ROLLS ROYCE CORP
  • EP3608734B1 patent drawingFigure 1
  • EP3608734B1 patent drawingFigure 2A
  • EP3608734B1 patent drawingFigure 2B

AI summary

Control systems and methods for controlling an engine. The control system (202, 300) includes a computation module (204, 306) and an input/output (I/O) module attached to the engine. The computation module is located in an area of the engine, or off-engine, which provides a more benign environment than the environment that the I/O module is subject to during operation of the engine. The I/O module includes a first processor (210, 324); and a first network interface device (330). The computation module includes a second processor (208, 320) with higher processing power than the first processor, and a second network interface device (322). The control system also includes a sensor (318) configured to provide sensor readings to the first processor. The first processor transmits data based on the sensor readings to the second processor. The control system also includes an actuator (316) operably coupled to the I/O module and that is controlled by the first processor based on commands from the second processor.