Browse Topic: Safety critical systems
Time-Sensitive Networking (TSN) is an emerging technology that has garnered popularity among the US DoD and others for its deterministic properties while using flexible, ubiquitous Ethernet as its core. However, individual TSN devices will support the TSN features of only some of the vast array of amendments and extensions that make up the full IEEE 802 TSN standards. This functional and modular approach offers great flexibility, but it also increases the complexity of network planning, analysis, verification, etc. as well as potentially leading to unexpected emergent behavior that must be addressed before a TSN network can be truly said to be qualified for use with safety-critical systems. Using industry experience gained certifying other deterministic networks to DO-254 and DO-178C Design Assurance Level A (DAL-A) and applying it to the analysis, testing, and validation of a deterministic TSN Ethernet digital backbone offers a roadmap for overcoming these challenges. Such an approach must seek to satisfy the three basic building-blocks of 1) Device-Level Standards Conformance, 2) System-Level Performance and Interoperability, and 3) Network Composability and Determinism.
To this point in aviation history, a typical aircraft type certification program has focused on the constituent systems that make up the aircraft, decomposing them further and further down until reaching their elemental parts and how they interact. This approach has traditionally treated the actual communication technology as only an interface, with technology and implementation based on a decision between multiple stakeholders via an ICD and high-level requirements. This has been necessary to ensure the accurate and on-time delivery of safety-critical data between nodes. When using legacy point-to-point or bus-based data communication technologies like ARINC 429 or MIL-STD-1553, this approach has worked well enough as these technologies are relatively straightforward and proven technologies. However, as onboard bandwidth needs for safety-critical data increase, these legacy technologies are increasingly no longer capable of meeting the needs of system integrators. Ubiquitous, high-bandwidth Ethernet is the obvious solution to these needs and, indeed, it has been used for quite some time in onboard networking applications for low Development Assurance Level (DAL)/non-safety critical data. However, as Ethernet moves into high-DAL applications, the certification of the Ethernet network itself becomes a major complexity that must be addressed directly.
Modern aircraft have an established need for a high-performance, open standards solution to interconnect increasing number of digital components including sensors, actuators, controllers, processors, displays and data concentrators. The aircraft can be envisioned as a distributed system requiring highly available, reliable, and deterministic communication network - often termed as digital backbone - for safe operation. This paper introduces a new zonal architecture for aerospace onboard networks using Time-Sensitive Networking (TSN). TSN is an open standard based deterministic Ethernet solution for mission and safety critical networks in aerospace industry that truly meets the Modular Open Standards Approach (MOSA) requirements. This paper also presents a reference implementation of the proposed digital backbone architecture using commercial-off-the-shelf hardware from multiple vendors. Experimental data from laboratory evaluation shows stability, performance, and reliability that meets or exceeds the needs of aerospace use cases. The proposed next generation digital backbone provides significant size, weight, and power savings as well as enables hardware and software modularity using open standards. A specific use case of such a digital backbone is the US Army's Future Vertical Lift (FVL) program, but the proposed architecture is generally applicable to all aircraft networks.
The paper deals with the status of development and qualification/certification of electromechanical actuation for Helicopters and VTOL applications with the focus on aspects relevant to the Fault-Tolerance. In particular a linear Electromechanical Actuator (EMA) architecture is presented, derived from a fault tolerant ballscrew-based differential (speed-summing arrangement) actuation system patented by UMBRAGROUP S.p.A. The focus is on safety-critical and high reliability/availability requirements for electromechanical actuation certification. The main characteristic is the use of two independent mechanical actuation channels in the same envelope driven by independent Motor Control Electronics (MCEs). At the state of the art, the presented fault-tolerant architecture is under development in flight-critical swashplate application for eVTOL platform and under feasibility study in flight-critical swashplate application for CS27 platform.
The security of connected health technology is often assumed to exist when it does not, or considered to be prohibitively expensive or complex, or, worst of all, relegated to an afterthought. This is dangerous thinking, especially as the industry increasingly moves to a smartphone-based command-and-control model for these safety-critical applications.
As the complexities of avionic systems increase, our system-level verification methods have remained stagnant. New requirements are added with each iteration of design, impacting the level of testing needed for full test coverage, while hardware or software updates require verification testing that transcends its predecessors. At Triumph Integrated Systems, (Triumph), DO-178 B/C level A formal qualification testing requires several engineer reviewers to verify a system works as intended. Generally, it takes a week or less to execute a test and gather data, but several weeks to evaluate said test. There is opportunity for improvement in this system. This paper describes how Triumph Engine Control Systems' Automated Criteria Evaluation (ACE) takes the test case review process time and reduces it effectively. ACE is intended to replace one human reviewer using MathWorks® based programing, which breaks down natural criteria language for interpretation and evaluation. ACE aims to increase efficiency, assure precision, improve repeatability, and has the potential to lower development costs. This paper highlights how ACE will drastically cut criteria evaluation time while increasing productivity and accuracy of test review results without impacting the integrity or safety of the tested Level A software.
ABSTRACT It is impossible to open a newspaper, turn on a television, or visit a news website these days without being barraged with cybersecurity related news. Every domain is being attacked, penetrated, and impacted by cyber-crime and the range, complexity, and frequency of attacks is expanding daily. Across the board we face a wide range of adversaries from disgruntled employees to nation states that are bent on taking our critical systems down temporarily or permanently. Avionics systems are not immune from this and over the past several years, cybersecurity policies and the Risk Management Framework (DoD 8510.01) approach to securing US cyber systems, have been maturing and rapidly growing in adoption. However, many in the avionics community remain uninformed regarding the impacts of these new policies and initiatives to their systems nor how best to ensure they are taking a practical and efficient approach to implementing them. Gone are the days of a magic box that all of the security requirements are allocated to. Modern Cybersecurity is a systems discipline and cuts across the entire avionics suite. This paper will introduce the Risk Management Framework (RMF) and Cybersecurity and discuss what they are, how we got here, how they are related, and how they are impacting and will impact legacy and future avionics systems on tactical military aircraft. The paper will present some observations and best practices associated with application of Cybersecurity and RMF to avionics. It will also include some benefits of safety critical designs toward cyber-hardening and where safety and security are mutually exclusive. It will touch briefly on some impacts to avionics systems related to hot Cybersecurity topics such as HBSS (Host Based Security System), STIGs (Security Technical Implementation Guides), Static code analysis, DoD PKI (Department of Defense Public Key Infrastructure), electronic delivery, and insider threats. The paper will include a perspective on the development environment, the deployed systems, and deployment sites and how RMF and Cybersecurity impact both the contractor and the DoD customer related to these perspectives.
ABSTRACT Power Architecture® processors have dominated aviation safety-critical processing since the late 1990s, when major processing vendors exited the MIL-qualified and/or aviation-certified markets. Since that time, four trends have emerged: 1. Military and commercial safety certification has become more rigorous 2. Server/desktop architectures have focused on performance at the expense of determinism 3. System-on-Chip (SoC) architectures are offered, with multiple processing cores (multicore) in a single package to increase performance over single-core processors 4. The industrial automation industry is increasing safety requirements for autonomous manufacturing, and the automotive industry is offering driver assistance, including autonomous operation, creating a large market for relatively low-power, high-integrity processing Although the Power Architecture will remain a viable aviation processor technology for some time, new-to-our-industry processing products and architectures are poised to enter (or re-enter) the aviation market. Automotive and aviation markets require similar capabilities that make the avionics market attractive to processing vendors currently supplying the automotive market: • Longer product availability lifetimes (5-15 years) than consumer/server-grade processors • Low power draw • Extended temperature operation • High safety integrity This paper introduces the microprocessor industry support and certification issues. High-level activities to bring safetycritical products to civil and military aviation using Multi-Core Processors (MCPs) are also discussed, based on current Rockwell Collins MCP civil aviation development, with all cores operational, supporting Design Assurance Level (DAL) A. A high-level comparison between automotive and civil /military aviation safety requirements will be discussed. The leading alternative processing architectures are introduced with their history and their vendor’s interest and activities in support of the aviation market. Next steps are described in the areas of MCP certification, alignment of automotive/avionics safety requirements, and potential vendor activities. Finally, our conclusions are summarized.
ABSTRACT Loss of the primary lubrication in a helicopter gearbox can result in a very rapid or even immediate failure of the system due to the much-reduced heat removal and the degrading tribological performance of the highly loaded gear contacts. While a limited understanding of this topic may be an acceptable risk for ground vehicles, however, a properly functioning gearbox is flight safety critical for helicopters. Therefore a deeper understanding of the degradation mechanisms is essential to accurately assess the time duration in which the helicopter gearbox can function under oil-out conditions and evaluate designs targeting the desired extension. Current methods for predicting the gearbox life and performance under the loss-of-lubrication situation are indeed largely experimental and experience-based and they provide only limited insights into the underlying physics of the evolving tribology of gears and bearings. One of the major technical barriers that currently limit the physics-based predictive capability is a lack of reliable, quantitative modeling of lubricant retention on the gear tooth surface after the loss of lubrication. This paper first describes the film thickness measurement with the white light interferometry for the lubricant remaining on a glass disc after a certain number of revolutions at a given speed. This is followed by a description of a 3D numerical ANSYS CFX® model which mimics the experimental set-up. The controlling model parameters are the centrifugal and viscous forces, surface tension, temperature, and lubricant-disc contact angle. The predicted effects of rotation speed and temperature are validated by the experimental results. Finally, the modeling methodology is used to simulate the lubricant retention on a gear tooth surface over the range of temperature and speed of a typical helicopter gearbox.
Items per page:
50
1 – 50 of 336