Engine Control Modules Split Between Harsh and Benign Zones
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current control systems for gas turbine engines face challenges such as high data throughput requirements, obsolescence, harsh environmental limitations, and cybersecurity needs, particularly in handling complex data processing and maintaining cyber security, especially in harsh operating conditions.
Innovation Solution
A distributed control system architecture is implemented, where a computation module with higher processing power is located in a benign environment, and an I/O module with lower power processors is in a harsh environment, connected via a network, allowing for efficient data communication and processing while ensuring engine safety functions are executed near sensors and actuators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If control systems use high processing power processors to handle future data throughput requirements, then data throughput capability is improved, but the system becomes vulnerable to harsh operating environments and processor obsolescence
Solution Approach 1:
The control system is divided into two separate modules: an I/O module located in the harsh environment with basic processing capabilities, and a computation module located in a benign environment with high processing power. This segmentation allows each module to be optimized for its specific operational context, resolving the contradiction between processing power and environmental hardness.
Solution Approach 2:
A communication network acts as an intermediary between the I/O module and computation module, transmitting sensor data and control commands. This intermediary enables the high-processing-power computation module to handle data throughput requirements while the I/O module maintains reliability in the harsh environment through its hardened design.
2Device complexity
If control systems are tightly integrated with interconnected components to minimize connection lengths, then connection complexity is reduced, but the system becomes highly customized and lacks adaptability
Solution Approach 1:
The system is segmented into modular components (I/O module and computation module) that can be independently designed and configured. The I/O module handles local sensor/actuator connections with minimized harness lengths, while the computation module provides adaptable processing capabilities, achieving both low connection complexity and high adaptability.
Solution Approach 2:
The computation module serves multiple functions including data processing, control algorithm execution, and communication coordination. This universal module can be configured for different applications without requiring custom integration of all components, reducing connection complexity while maintaining versatility.
3Ease of manufacture
If control systems use commercially available processors to reduce costs, then manufacturing cost is reduced, but the processors become obsolete quickly requiring costly redesign
Solution Approach 1:
The computation module using commercially available processors is separated from the hardened I/O module. This allows the computation module to be periodically upgraded or replaced as processors become obsolete, while the I/O module maintains long-term operational reliability in the harsh environment, reducing overall system redesign costs.
Solution Approach 2:
The system architecture allows changing the processing power parameter of the computation module independently from the I/O module. When processors become obsolete, only the computation module needs to be updated with new processors, maintaining cost-effectiveness while extending the operational lifecycle of the critical I/O functions.
4Loss of time
If safety functions are executed locally near sensors and actuators in harsh environments, then response time is reduced, but the processing power available for safety functions is limited
Solution Approach 1:
Safety-critical functions are segmented into two categories: time-critical functions executed locally in the I/O module near sensors and actuators, and computationally intensive functions executed in the benign environment computation module. This segmentation ensures both rapid local response and access to high processing power for comprehensive safety analysis.
Solution Approach 2:
The communication network acts as an intermediary that rapidly transmits safety-relevant data between the I/O module and computation module. This enables the computation module to perform complex safety analyses with high processing power while maintaining effectively reduced response time through fast data exchange.
Data Source
AI summary
Control systems and methods for controlling an engine. The control system includes a computation module and an input/output (I/O) module attached to the engine. The computation module is located in an area of the engine, or off-engine, that provides a more benign environment than the environment that the I/O module is subject to during operation of the engine. The I/O module includes a first processor and a first network interface device. The computation module includes a second processor with higher processing power than the first processor, and a second network interface device. The control system also includes a sensor configured to provide sensor readings to the first processor. The first processor transmits data based on the sensor readings to the second processor. The control system also includes an actuator operably coupled to the I/O module and that is controlled by the first processor based on commands from the second processor.


