Airbus flight control system

Similar documents
Embedded Real-Time Systems (TI-IRTS) Safety and Reliability Patterns B.D. Chapter

Innovation Takes Off

Socio technical Systems. Ian Sommerville 2006 Software Engineering, 8th edition. Chapter 2 Slide 1

Analog Amplifier Rexroth RA: Easy, user-friendly control of pumps and valves

Oral Preparation Questions

PROCESS MONITORING FOR DEEP ROLLING IN THE SERIAL PRODUCTION

Systems Engineering. Designing, implementing, deploying and operating systems which include hardware, software and people

Assembly and Operating Manual Nano warbirds FW 190 Specification: *Length: 18 1/2"(470mm) *Wing Span: 21 7/10"(550mm)

Commandes de vol électriques Airbus: une approche globale de la sûreté de fonctionnement

Service & Support. Higher-level safe switch-off of the power supply of functionally nonsafe standard modules? Wiring Examples.

Value Paper Author: Edgar C. Ramirez. Diverse redundancy used in SIS technology to achieve higher safety integrity

Adaptive Cruise Control System Overview

VARIABLE STABILITY FLIGHT OPERATIONS MANUAL

SINGLE ENGINE PISTON AEROPLANE ENDORSEMENT

Overview of IEC Design of electrical / electronic / programmable electronic safety-related systems

Electronic Flight Instrument System (EFIS)

Exchange High Availability

Introduction to the iefis Explorer

A distributed data processing architecture for real time intelligent transport systems

MULTI-ENGINE PISTON AEROPLANE ENDORSEMENT

Michel TREMAUD Retired, Airbus / Aerotour / Air Martinique / Bureau Veritas. Crew Coordination. Highlighting the Monitoring Role of the PNF

Software solution for management of flying training and operation

b) Describe the concept of ERROR CHAIN in aviation.

Electronic Power Control

CYCLOPS OSD USER MANUAL 5.0

Safety Critical & High Availability Systems

Safety Requirements Specification Guideline

Memorandum Date: February 5, 2014

Linear Motion and Assembly Technologies Pneumatics Service. Industrial Ethernet: The key advantages of SERCOS III

SINGLE ENGINE TURBO-PROP AEROPLANE ENDORSEMENT

Using Multipathing Technology to Achieve a High Availability Solution

Bristol ControlWave Redundant Control

LED Anti-Collision Lighting System for Airbus A320 Family

S a f e G u i d a n c e. Single Lamp Control and Monitoring

Rapid Modular Software Integration (RMSI)

SAN Conceptual and Design Basics

Low Level Windshear Alert System (LLWAS) An integral part of the U.S. FAA Wind-shear safety program

MP2128 3X MicroPilot's. Triple Redundant UAV Autopilot

Project Flight Controls

Chapter 2. Basic Airplane Anatomy Delmar, Cengage Learning

Brief introduction

Program Update June G500, G600 Program Update 06.15

U g CS for DJI Phantom 2 Vision+, Phantom 3 and Inspire 1

Automatic Dependent Surveillance Broadcast (ADS-B)

AIRBUS A320/A330/A340 Electrical Flight Controls A Family of Fault-Tolerant Systems

Fault Tolerant Computing in Industrial Automation Hubert Kirrmann ABB Research Center CH-5405 Baden, Switzerland

B777. Landing Gear DO NOT USE FOR FLIGHT

Suggested Application Options Settings for Autodesk Inventor

SERIOUS INCIDENT. Aircraft Type and Registration: No & Type of Engines: 2 SNECMA CFM 56-7B turbofan engines. Year of Manufacture: 1999

Chapter 11 I/O Management and Disk Scheduling

AutoGlow Installation and User s Manual. Installation and User s Manual. OSA AutoGlow. Figure 1. AutoGlow Introduction

Information regarding the Lockheed F-104 Starfighter F-104 LN-3. An article published in the Zipper Magazine #48. December Theo N.M.M.

Integration of Engine & Hydraulic Controls for Best Operation

Signature and ISX CM870 Electronics

Socio-Technical Systems

Electric Landing Gear controllers and sequencer LGC12 / LGC 13C

Communication Management Unit : Single Solution of Voice and Data Routing Unit

Digital Systems Based on Principles and Applications of Electrical Engineering/Rizzoni (McGraw Hill

Backup Exec 9.1 for Windows Servers. SAN Shared Storage Option

International Journal of Advancements in Research & Technology, Volume 3, Issue 4, April ISSN

Integrated surface management Herve Drevillon (DSNA) Airport safety support tools for pilots, vehicle drivers and controllers Nicolas Leon (DSNA)

AIRCRAFT PERFORMANCE Pressure Altitude And Density Altitude

Flight Operations Briefing Notes

Requirements Engineering Processes. Feasibility studies. Elicitation and analysis. Problems of requirements analysis

MULTI-ENGINE TURBO-PROP AEROPLANE ENDORSEMENT

The CREDOS Project. Human Machine Interface Design

Frequently Asked Questions: EMC UnityVSA

ABB Technology Days Fall 2013 System 800xA Server and Client Virtualization. ABB Inc 3BSE en. October 29, 2013 Slide 1

Multi Engine Oral Exam Questions

Assessment Specifications for Remotely Piloted Aircraft Systems, Class 1 AS-RPAS1

Distributed System Principles

How to choose the right RAID for your Dedicated Server

OUTCOME 1 TUTORIAL 1 - MECHATRONIC SYSTEMS AND PRODUCTS

Failure Analysis Methods What, Why and How. MEEG 466 Special Topics in Design Jim Glancey Spring, 2006

Chapter 2 Logic Gates and Introduction to Computer Architecture

CIRRUS AIRPLANE MAINTENANCE MANUAL

Introduction to Aircraft Design and Aviation Systems (ENG3005)

ELECTROMECHANICAL ACTUATOR ( EMA ) ADVANCED TECHNOLOGIES FOR FLIGHT CONTROLS

Committed to keeping you flying Controls and Avionics Solutions

A dual redundant SIP service. White paper

UNCLASSIFIED. UNCLASSIFIED United States Special Operations Command Page 1 of 7 R-1 Line #261

Airbus A320 wingstrike at Hamburg Airport going around the world within hours via YouTube. Johann Reuss

IBM Global Technology Services March Virtualization for disaster recovery: areas of focus and consideration.

ZONE SELECTIVE INTERLOCKING (ZSI) APPLICATION AND TESTING GUIDE SIEMENS WL UL489 AND UL1066 AIR CIRCUIT BREAKERS

Use of RPAS/Drones in Norway

Certificate IV Aeroskills (Mechanical) MEA The largest CASR and EASA Part 147 approved Maintenance Training Organisation in Australia.

CASE STUDY. Uniphore Software Systems Contact: Website: 1

Purchase of Replacement Force Helicopter

Fault Tolerance in the Internet: Servers and Routers

NJ ASK PREP. Investigation: Mathematics. Paper Airplanes & Measurement. Grade 3 Benchmark 3 Geometry & Measurement

Version : 1.0. SR3620-2S-SB2 User Manual. SOHORAID Series

UNIT 1 INTRODUCTION TO NC MACHINE TOOLS

FINAL REPORT. AAIU Synoptic Report No: AAIU File No: 2005/0030 Published: 24/7/06

LANDING GEAR & BRAKES GTM CONTENTS INTRODUCTION

Nomad WINGS FLAP OPERATING LIMITATIONS

Introduction to Process Control Actuators

ZIMBABWE SCHOOL EXAMINATIONS COUNCIL. COMPUTER STUDIES 7014/01 PAPER 1 Multiple Choice SPECIMEN PAPER

Transcription:

Airbus flight control system The organisation of the Airbus A330/340 flight control system Ian Sommerville 2004 Software Engineering Case Studies Slide 1

Fly by wire control Conventional aircraft control systems rely on mechanical and hydraulic links between the aircraft s controls and the flight surfaces on the wings and tail. The controls and flight surfaces are directly connected. Mechanical links are also used for the engine control. In fly-by-wire systems, the cockpit controls generate electronic signals that are interpreted by a computer system and are then converted into outputs that drive the hydraulic system connected to the flight surfaces. Engine control is also mediated by the FCS computers. Ian Sommerville 2004 Software Engineering Case Studies Slide 2

Advantages of fly-by-wire Pilot workload reduction The fly-by-wire system provides a more usable interface and takes over some computations that previously would have to be carried out by the pilots. Airframe safety By mediating the control commands, the system can ensure that the pilot cannot put the aircraft into a state that stresses the airframe or stalls the aircraft. Weight reduction By reducing the mechanical linkages, a significant amount of weight (and hence fuel) is saved. Ian Sommerville 2004 Software Engineering Case Studies Slide 3

Fault tolerance Fly-by-wire systems must be fault tolerant as there is no fail-safe state when the aircraft is in operation. In the Airbus, this is achieved by replicating sensors, computers and actuators and providing graceful degradation in the event of a system failure. In a degraded state, essential facilities remain available allowing the pilot to fly and land the plane. Ian Sommerville 2004 Software Engineering Case Studies Slide 4

Hardware organisation Three primary flight control computers Responsible for calculations concerned with aircraft control and with sending signals to the actuators associated with the control surfaces and engines. Two secondary flight control computers Backup systems for the flight control computers. Control switches automatically to these systems if the primary computers are unavailable. Only one computer is required for flight control. Therefore, quintuple redundancy is supported. All operational computers operate in parallel so there is no switching delay. Two data concentrator computers Gather information from the flight control system and pass this to warning and display systems, flight data recorders and maintenance systems. Ian Sommerville 2004 Software Engineering Case Studies Slide 5

Hardware diversity The primary and secondary flight control computers use different processors. The primary and secondary flight control computers are designed and supplied by different companies. The processor chips for the different computers are supplied by different manufacturers. All of this reduces the probability of common errors in the hardware causing system failure. Ian Sommerville 2004 Software Engineering Case Studies Slide 6

Computer organisation Command unit Input Splitter Monitor unit Comparator Output Flight control computer Ian Sommerville 2004 Software Engineering Case Studies Slide 7

Computer organisation The command unit and the monitor unit are separate channels within a single computer. Each channel has separate hardware and different software. If the results of the channels disagree (as checked by the comparator) or are not produced at the same time then an error is assumed and control switches to another machine. Ian Sommerville 2004 Software Engineering Case Studies Slide 8

Software diversity The software for the different channels in each computer has been developed by different teams using different programming languages. The software for the primary and secondary flight control computers has been developed by different teams. For the secondary computers, different languages are again used for the different channels in each machine. Ian Sommerville 2004 Software Engineering Case Studies Slide 9

Dynamic reconfiguration The FCS may be reconfigured dynamically to cope with a loss of system resources. Dynamic reconfiguration involves switching to alternative control software while maintaining system availability. Three operational modes are supported Normal - control plus reduction of workload; Alternate - minimal computer-mediated control; Direct - no computer-mediation of pilot commands. At least 2 failures must occur before normal operation is lost. Ian Sommerville 2004 Software Engineering Case Studies Slide 10

Control diversity The linkages between the flight control computers and the flight surfaces are arranged so that each surface is controlled by multiple independent actuators. Each actuator is controlled by different computers so loss of a single actuator or computer will not mean loss of control of that surface. The hydraulic system is 3-way replicated and these take different routes through the plane. Ian Sommerville 2004 Software Engineering Case Studies Slide 11

Airbus FCS problems There have been a number of Airbus accidents that may be related to problems with the FCS. One accident (Warsaw runway overrun) has been clearly identified as a problem with the specification and not with the system itself. There is no evidence of any failures of the FCS hardware or software. However, the pilots may misinterpret how the system operates and hence make errors that it can t cope with. Most likely when the system was newly introduced. Ian Sommerville 2004 Software Engineering Case Studies Slide 12