Fault tolerant control system
First Claim
1. Fault-tolerant control system, comprising:
- a first controller, adapted to;
control operation of a first system, monitor operation of a second controller, and, self-monitor;
the second controller, adapted to;
control operation of a second system, monitor operation of the first controller, and, self-monitor;
each said controller operable to identify faults occurring in the first and the second controller;
the first controller operable to implement an alternate control scheme for operating the first propulsion system when a fault is identified therein; and
, the second controller operable to implement an alternate control scheme for operating the second propulsion system when a fault is identified therein.
12 Assignments
0 Petitions
Accused Products
Abstract
A dual-redundant propulsion-by-wire control architecture with robust monitoring is presented to increase system availability without compromising safety. The dual-redundant controllers are able to cross-monitor and self-monitor. Self monitoring is effected at the application level and built-in system tests are performed. The monitor functions are set as high priority tasks. The first controller controls operation of a first propulsion system, monitors operation of a second controller, and, self-monitors. The second controller controls operation of a second propulsion system, monitors operation of the first controller, and, self-monitors. Each controller is operable to identify faults occurring in the first and the second controller, and implement an alternate operating control scheme for the respective propulsion system when a fault is identified. The first controller is signally connected to the second controller by substantially redundant communications buses.
29 Citations
21 Claims
-
1. Fault-tolerant control system, comprising:
-
a first controller, adapted to;
control operation of a first system, monitor operation of a second controller, and, self-monitor;
the second controller, adapted to;
control operation of a second system, monitor operation of the first controller, and, self-monitor;
each said controller operable to identify faults occurring in the first and the second controller;
the first controller operable to implement an alternate control scheme for operating the first propulsion system when a fault is identified therein; and
,the second controller operable to implement an alternate control scheme for operating the second propulsion system when a fault is identified therein. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14)
-
-
15. Fault tolerant control system comprising:
-
a first system including a first system control unit;
a second system including a second system control unit;
a first supervisory control module including a first control and a second system monitor;
a second supervisory control module including a second control and a first system monitor;
a first system control bus operatively coupled to said first control, said first system control unit and said first system monitor;
a second system control bus operatively coupled to said second control, said second system control unit and said second system monitor;
said first control providing a first system command to said first system control unit and said first system monitor, and providing a virtual second system command to said second system monitor;
said second control providing a second system command to said second system control unit and said second system monitor, and providing a virtual first system command to said first system monitor; and
,said first and second supervisory control modules characterized by cross-monitoring and self-monitoring. - View Dependent Claims (16, 17, 18, 19, 20)
-
-
21. Fault tolerant control system for a vehicle having first and second propulsion systems comprising:
-
a first control module including a) a first control for providing the first propulsion system with a primary first propulsion system command and b) a first monitor;
a second control module including a) a second control for providing the second propulsion system with a primary second propulsion system command and b) a second monitor;
said first monitor adapted to receive said primary second propulsion system command and perform rationality checks thereon to detect faults of the second control module; and
,said second monitor adapted to receive said primary first propulsion system command and perform rationality checks thereon to detect faults of the first control module.
-
Specification