control//fault-tolerant control//reconfiguration
Reconfiguration is the step of active fault-tolerant control in which, after a fault has been diagnosed, the system changes its sensor set, its actuator allocation, its control law or its mission so that it can continue in a known way. It turns a diagnosis (*the left front motor has lost thrust*) into an action, and it is only as good as the fault isolation in front of it: reconfiguring around the wrong component is worse than not reconfiguring at all.
Reconfiguration is the step of active fault-tolerant control in which, after a fault has been diagnosed, the system changes its sensor set, its actuator allocation, its control law or its mission so that it can continue in a known way. It turns a diagnosis (the left front motor has lost thrust) into an action, and it is only as good as the fault isolation in front of it: reconfiguring around the wrong component is worse than not reconfiguring at all.
A multirotor shows the range of what is possible. A hexacopter that loses a motor recomputes the thrust split among the remaining five (control allocation) and keeps flying, because six motors leave spare authority. A quadcopter is worse off: four motors are the minimum to control thrust, roll, pitch and yaw at once. Mueller and D'Andrea (2014) showed it can still stay up by giving up yaw and letting the vehicle spin about its own axis, abandoning the part it can no longer control and keeping the part that matters. That is research. In almost every product the reconfiguration is more modest: a degraded mode, return to home or a controlled landing.
Reconfiguration code is the code that runs least and hides the most bugs.
It executes only when something has already gone wrong, so ordinary flights and production runs never exercise it. Test it by injecting faults in simulation and on the bench (fault injection, hardware-in-the-loop).
In a plant the same idea is a production decision: divert the flow through the twin station at half rate, switch a level loop from a failed transmitter to a flow balance, run a compressor at reduced load. The degraded mode should be designed and approved before it is needed, with its own limits.
Changing the controller is a transient. Switching from one gain set to another while the plant is moving can bump the actuators; bumpless transfer (initializing the new controller's states from the old one's output) is part of the design.
Sensor reconfiguration is the cheapest kind when redundancy exists: drop the voted-out channel, or replace it with a virtual sensor built from the others (redundancy).
A reconfigured system is a different system. Its margins, its limits and the mission it can still accept must be known, which is why many products have one or two degraded modes rather than a reconfiguration for every fault.