Method and apparatus for automatically handling one or more alerts in an aircraft
The automated processing system solves the complexity of alarm management under major aircraft malfunctions, enabling partially or fully automated alarm processing, reducing pilot workload, and improving processing efficiency and flight safety.
Patent Information
- Application Number
- CN202480028540.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-04-27
- Filing Date
- 2024-04-22
- Publication Date
- 2025-11-25
AI Technical Summary
When an aircraft encounters a major malfunction, pilots face a large number of complex alerts that need to be handled quickly. Existing technology cannot automate the management of these alerts, resulting in an excessive burden on pilots and making it difficult for them to make quick decisions.
An automated processing system is adopted, which uses a digital control panel and computing unit to store alarms and their severity, assess and classify the processing procedures, select manual or automatic execution mode, automatically execute alarm processing steps, and display processing progress and results.
It reduces the burden on pilots, improves the efficiency of handling abnormal situations, ensures flight safety, reduces decision-making time, and improves the stability and airworthiness of aircraft.
Smart Images

Figure CN121014022A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The technical field of the invention is the management of alerts in an aircraft.
[0002] The invention relates to a method for processing alerts in an aircraft, in particular a method for partially or completely automating said processing. BACKGROUND
[0003] When an aircraft is confronted with a series of major failures, the pilot(s) must perform a series of procedures to determine whether the aircraft can maintain a stable flight condition and be sufficiently airworthy to continue the ongoing flight / mission, or whether it is necessary to divert to land as soon as possible.
[0004] During a major event such as an engine explosion damaging a part of the aircraft wing, dozens of alerts related to major system failures are displayed to the pilot. Such a large number of alerts requires rapid processing and decision making, which can be very complex. When there are several pilots on board the aircraft, they can, for example, check all the systems of the aircraft by dividing the work in order to determine which systems are available to process the large number of alerts. However, this division of work and their collaborative processing in a crisis situation is not easy. In addition, when the pilot is alone, he / she sometimes cannot process all the alerts because of the large number of alerts and the complexity thereof. Therefore, assistance is needed to manage the alerts for the pilot(s).
[0005] To assist the pilot(s) in managing the alerts, the document WO 2021130520 A1 provides a fault management system for complex systems. More specifically, this system uses an intervention method based on a directed graph of system states to determine and restore the functionality of the failed systems and subsystems. However, while such a system improves the information available to the pilot, it does not even allow partial automation of the alert solution.
[0006] Therefore, there is a need for a device and a method for at least partially automating the management of alerts. SUMMARY
[0007] The invention provides a solution to the problems discussed earlier by providing a method for automatically processing one or more alerts in an aircraft.
[0008] To this end, a first aspect of the invention relates to a method for automatically processing one or more alerts in an aircraft, wherein the alerts are associated with events related to the state of the aircraft, the events being able to be associated with one or more alerts, the method being implemented by an automatic processing system comprising one or more digitized control panels and a computing unit, the method comprising:
[0009] - a step of preparing the processing of the alerts, comprising:
[0010] a sub-step of storing the alerts and the severity associated with each alert;
[0011] a sub-step of checking that no other automatic alert processing is already in progress;
[0012] a step of evaluating one or more processes associated with each alert, said evaluation comprising:
[0013] a sub-step of classifying and ordering the processes according to the list of actions and checks associated with each process in order to obtain an ordered list of processes to be implemented;
[0014] a sub-step of displaying the ordered list of processes to be implemented, wherein the processes associated with the alerts having the highest severity and / or capable of ensuring stable flight conditions are displayed first;
[0015] a step of selecting the execution mode of the processes to be implemented from among a manual mode, in which the actions associated with each process are performed by the user himself, and an automatic mode, in which the actions associated with each process are performed by the automatic processing system;
[0016] a step of executing the processes from the ordered list of processes to be implemented, in the order of said list, when the user selects the automatic execution mode, said step comprising, for each action associated with each process:
[0017] a sub-step of performing the action by the automatic processing system when the user selects the automatic execution mode;
[0018] a sub-step of updating the progress of each process and the obtained changes in the state of the aircraft associated with this progress for each action performed during the previous sub-step or performed by the user;
[0019] a step of displaying the actions implemented in the previous steps, the obtained and / or expected changes associated with each of these actions, and the matching between the obtained changes and the expected changes.
[0020] Thanks to the invention, the processing of these alerts can be partially or completely automated, in particular by classifying and ordering the alerts to be processed and the actions and checks to be performed. The invention can also guide the user (e.g. the pilot) in processing all or part of these alerts when he chooses to process them manually. In particular, the invention relieves the user (e.g. the pilot) of the burden during the management of abnormal situations, allowing him / her to focus on the aircraft flight.
[0021] In addition to the features discussed in the preceding paragraphs, the method can also have one or more additional features from among the following, according to an aspect of the application, considered alone or according to any technically possible combination.
[0022] In one embodiment, the step of selecting the execution mode of the process to be implemented comprises a sub-step of displaying a dialog box allowing the user to select the execution mode.
[0023] In one embodiment, the step of executing the process comprises, for at least one action associated with the process:
[0024] - a sub-step of actuating the (digital) elements of the control panel(s); and / or
[0025] - a sub-step of actuating one or more electrical contactors associated with at least one action associated with the process, in order to shut down a faulty component and / or start up a backup component.
[0026] In one embodiment, during the sub-step of updating the progress of each process, when an action is executed and the obtained result associated with said action is consistent with the expected result, a check box is displayed.
[0027] By "obtained result associated with an action", it is meant the result produced by the obtained change associated with said action. By "expected result associated with an action", it is meant the result produced by the expected change associated with said action.
[0028] In one embodiment, at the end of the sub-step of updating the progress of the process under consideration, when the obtained change associated with the action under consideration is not consistent with the expected change associated with said action, the method comprises a sub-step of selecting by the user from among two steps to be taken:
[0029] - continuing the current process by performing the previous sub-step for the next action or, if the current process has been completed, continuing with the next process; or
[0030] - when the obtained change associated with the action under consideration requires the implementation of a new process, executing this process according to the previous sub-step and resuming the processing of the current process after the end of the implementation of the new process;
[0031] The selected step to be taken is implemented by the automatic processing system.
[0032] In one embodiment, at the end of the step of displaying the actions implemented, the method comprises a step of transitioning the automatic processing system into a monitoring mode in which the processing system is configured to detect the occurrence of one or more alarms.
[0033] A second aspect of the present application relates to an automatic alarm processing system comprising at least one digital control panel, a computing unit connected to the digital control panel, and means for verifying the status of the unit elements that make up the digital control panel, said automatic alarm processing system being configured to implement the method according to the first aspect of the present application.
[0034] A third aspect of the present application relates to a computer program comprising instructions which, when the program is executed by a computer, cause the apparatus according to the second aspect of the present application to carry out the steps of the method according to the first aspect of the present application.
[0035] A fourth aspect of the present application relates to a computer readable medium having recorded thereon a computer program according to the third aspect of the present application.
[0036] The application and its different applications will be better understood on reading the following description and examining the attached drawings. BRIEF DESCRIPTION OF DRAWINGS
[0037] The attached drawings illustrate the application by way of example and do not limit the object of the application in any way.
[0038] Figures 1A to 1E A schematic representation of the method according to the present application is shown.
[0039] [ Figure 2 A schematic representation of the system according to the present application is shown.
[0040] [ Figure 3 An extract from a MEL document is shown.
[0041] [ Figure 4 A schematic representation of a GEP function is shown. DETAILED DESCRIPTION
[0042] The attached drawings illustrate the application by way of example and do not limit the object of the application in any way. Identical elements appearing in the different drawings have a single reference number, unless otherwise indicated. Throughout the description and the claims, the expressions "comprise", "include" and "contain" are used synonymously.
[0043] Hereinafter, a process is defined as one or more actions and / or checks to be performed. Furthermore, an action can be associated with multiple processes and can be performed one or more times in each process.
[0044] Method for automatically processing one or more alerts in an aircraft
[0045] [ Figure 1A ] to [ Figure 1EThe first aspect of the invention illustrated in the figure below relates to a method for automatically processing one or more alerts in an aircraft, wherein an alert is associated with an event or situation related to the state of the aircraft and the event or situation can be associated with one or more alerts.
[0046] More specifically, in an aircraft, the cockpit is generally equipped with a system that alerts the user in the event of a dangerous or mission-impacting system failure. These alerts take various forms, such as:
[0047] - a message displayed on the cockpit screen;
[0048] - a visual indication of a dedicated indicator (for example: orange or red depending on the criticality of the situation), also known as an "attention grabber";
[0049] - a sensory alert emitted via a vibration or pressure applied to an element with which the user interacts with the aircraft.
[0050] - a sound alert emitted via a voice message or sound.
[0051] These alerts can be of various kinds and are triggered in some cases (for example, in the event of a risk of collision with other aircraft, in the event of a risk of collision with an obstacle or terrain), or even according to certain events (for example, in the event of a serious failure of one or more systems affecting the airworthiness of the aircraft).
[0052] The method according to the invention aims to partially or completely automate the processing of these alerts, in particular by classifying and ordering the alerts to be processed as well as the actions and checks to be performed. The method also guides the user in the processing of these alerts when the user chooses to manually process all or part of these alerts.
[0053] The method according to the invention is implemented by an automated processing system according to the invention (described in more detail in the second part of the description and illustrated in figures Figure 2 ] to [ Figure 4 ], which comprises a computing unit and one or more digitized control panels. The computing unit comprises computing components (such as a processor) and a memory (for example: a RAM type memory and / or a hard disk) configured to store the data and instructions necessary to implement the method according to the invention.
[0054] With the aid of digitization, the behavior of unit components and integrated panels in the control panels of modern aircraft can be verified through user actions or through software functions executed by the system's computing units. These are commonly referred to as digital control panels. In the system according to the invention, when one or more alarms are triggered, the method according to the invention is implemented to perform the steps now described.
[0055] Step of preparing the processing of the alerts
[0056] like[ Figure 1A As illustrated in the figure, the method according to the invention first includes a step E1 of preparing alarm processing. This step E1 includes (e.g., in the memory of the system according to the invention) storing alarms and a sub-step associated with the severity of each alarm.
[0057] This step also includes a sub-step of checking for other automated alarm processing that is not already in progress (e.g., not related to previous implementations of the method according to the invention). If no process is in progress, the method according to the invention continues. Otherwise, the method according to the invention is paused until one or more processes(s) associated with the processing of the current alarm are completed. Alternatively, multiple processes associated with the processing of one or more alarms can be processed in parallel. The term "parallel" as used herein means that their processing is simultaneous and independent.
[0058] Step of evaluating one or more processes associated with each alert
[0059] like[ Figure 1B As illustrated in the figure, the method also includes step E2, which evaluates one or more processes associated with each alarm, the evaluation including:
[0060] - For example, a sub-step to classify and sort processes to obtain an ordered list of processes to be implemented based on a list of actions and checks associated with each process (or a "non-normal checklist");
[0061] - Displays sub-steps of an ordered list of procedures to be implemented, with the procedures associated with alarms of the highest severity and / or those ensuring stable flight conditions being displayed first.
[0062] In one exemplary embodiment, the classification and ordering sub-step comprises studying the fault tree set of all components and systems of the aircraft during the definition of the aircraft. Moreover, this study can be more precise for systems or components having a major impact on flight safety / airworthiness. This study enables the manufacturer to prepare a document called "Master Minimum Equipment List or MMEL". This document assesses the impact of each component or system on flight airworthiness. The MMEL document can be provided by the aircraft manufacturer and used to prepare a more restrictive document, the MEL, which is the responsibility of the operator. In the case where there are multiple alerts to be processed, the classification phase can determine which alerts can be done in parallel, one criterion being that the systems / components involved in the alerts have no functional link between them.
[0063] In one exemplary embodiment, the severity of the processes associated with the alerts can be determined by considering two criteria: the degree of impact of the failure of the component and / or system on the maintenance of the stability of the aircraft, and / or, when there are multiple failures, which process should be performed first to ensure aircraft stability as quickly as possible. Thus, the processes comprising the list of actions and checks to be performed will be ordered according to their severity.
[0064] In one exemplary embodiment, the processes are evaluated by considering two types of information: the first type is the list of actions associated with each alert and defined by the alert system; the second type is the list of actions and checks associated with each system and defined by the predictive function MEL, which identifies the checks and potential operational limitations to be taken into account during the flight or during the pre-flight maintenance. In one embodiment, the method comprises the step of displaying to the user the limitations to be taken into account upon arrival at the flight phase in question.
[0065] In one embodiment, the list of processes and checks to be performed is displayed in order of priority from the most important to the least important, wherein the display also includes the elements of the MEL document presented to the user corresponding to the highest priority alert to be processed.
[0066] Step of selecting an execution mode
[0067] As Figure 1C illustrated in
[00015] , the method also comprises a step E3 of selecting the execution mode of the processes to be implemented among a manual mode and an automatic mode, wherein in the manual mode the actions associated with each process are performed by the user himself; in the automatic mode the actions associated with each process are performed by the automated processing system according to the application. In other words, once the list of processes to be implemented has been identified, the computing unit of the system according to the application is configured to request authorization from the user before starting the automatic execution of the processes.
[0068] To this end, in one embodiment, the method comprises generating a message in a window on the screen (e.g. a pop-up window). The user can choose to confirm the automatic execution of the procedure (e.g. by selecting "Y") or not (e.g. by selecting "N"). If the user chooses "N", he / she will have to manually perform the set of actions associated with the procedure(s). However, since all the elements with which the pilot interacts have been digitized, the computing unit is configured to record all the state changes resulting from the user's actions. The computing unit is also configured to broadcast these state changes to other functions, such as the prediction function MEL. This sharing of the current state of the cockpit and of the aircraft systems allows the on-board functions to correlate the information, thereby improving user assistance when performing tasks.
[0069] Step of executing the processes
[0070] As illustrated in [ Figure 1D ], the method also comprises a step E4 of executing the procedures of the ordered list of procedures to be implemented, this execution taking place in the order of said list when the user chooses the automatic execution mode.
[0071] For each action associated with each procedure, this step comprises a sub-step of performing the action by the automated processing system when the user chooses the automatic execution mode. When the execution mode is the manual mode, each action is performed by the user and only the following sub-steps are implemented for each action performed by the user.
[0072] For each action considered to have been performed during a previous sub-step or performed by the user, this step also comprises a sub-step of updating the progress of the procedure under consideration and of the obtained changes in the state of the aircraft associated with this progress.
[0073] This step also comprises a sub-step of choosing by the user, from among two steps, the step to be taken when the obtained changes associated with the considered action are not consistent with the expected changes associated with said action:
[0074] - continuing the current procedure or, if the current procedure has been completed, the next procedure by implementing the previous sub-steps for the next action, i.e. performing the next action in the current procedure, or, if the current procedure has been completed, performing the first action in the next procedure; or
[0075] - when the obtained changes associated with the considered action require the implementation of a new procedure, performing this procedure according to the previous sub-steps and resuming the processing of the current procedure after the end of the implementation of the new procedure;
[0076] The chosen step to be taken is then implemented by the automated processing system. In one embodiment, the computing unit is configured to evaluate the impact and decide whether:
[0077] - continue the execution of the following actions in the process - if the action or process that did not give the expected result does not affect the execution of the following actions or processes;
[0078] - suspend the execution of the following actions in the process and inform the user that the result obtained from the automatic action is different from the expected result. It is up to the pilot / user to decide whether to continue. The handling of this case is described in step E4bis.
[0079] Thus, the user only needs to intervene if the process affects the execution of the following actions and processes. Typically, the user will assess the impact of the expected result of the suspended action. If the impact is small (or zero), the user can decide to restart the automatic execution of the following actions in the current process or, if the current process is completed, to restart the automatic execution of the following processes.
[0080] On the other hand, if the impact can be significant and / or can lead to one or more new processes (also called additional processes or nested processes) related to this new, unexpected state of the system, the user can choose between manually or automatically executing the actions of one or more nested processes.
[0081] When the user decides to start the automatic process, the computing unit is configured to execute the actions of the nested check list process. Once this set of actions is successfully completed, the computing unit is configured to inform the user of the result obtained from the nested process. The user confirms the result obtained from the nested process while confirming the continuation of the initial process. If a new "unexpected" result is obtained during the execution of the actions of the nested process, the previously described process is implemented again. The computing unit is configured to implement the previous steps (and sub-steps) as many times as necessary until the set of alerts is processed.
[0082] In one embodiment, during the execution of the sub-steps, the computing unit is configured to execute the actions associated with each process as follows:
[0083] - by automatically driving the digital elements of the control panel to modify the behavior of the aircraft functions or systems according to the alert system process and / or the MEL prediction process;
[0084] - by automatically driving the modifications of the electronic contactors managed via the power distribution electronic contactors manager function to shut down the faulty systems according to the alert system process and / or the MEL prediction process, or to activate the compensating or backup systems according to the alert system process and / or the MEL prediction process.
[0085] In one embodiment, during the update sub-step, the computing unit is configured to display the progress of the actions listed in the process, for example, using a confirmed checkbox each time an action is successfully executed. This allows the user to track the progress of the actions. The displayed information relates, for example, to modifications to components of the digital control panel, system pages, and / or the processes being performed. Furthermore, the computing unit is configured to record all state changes resulting from automated actions. Additionally, the computing unit is configured to broadcast these state changes to other functions, such as the predictive flight function (MEL) and flight and system parameter acquisition functions. This sharing of the current state of the cockpit and aircraft systems allows onboard functions to correlate information, thereby improving user assistance during mission execution.
[0086] Display step
[0087] like[ Figure 1E As illustrated in the figure, the method further includes step E5, for displaying the actions performed in the previous steps, the acquired and / or expected changes associated with each of these actions, and the matching between the acquired and expected changes.
[0088] In one embodiment, once a process group (and its corresponding action) has been executed, the computing unit is configured to generate an information pop-up window listing the executed process groups and associated checkboxes showing the results obtained from those actions. In another embodiment, after the user confirms the obtained results, the computing unit is configured to return to a state of continuously monitoring for aircraft system fault alarms.
[0089] System according to the invention
[0090] In order to implement the method according to the invention, a second aspect of the invention relates to an automated processing system comprising components configured to implement the method.
[0091] More specifically, the system according to the invention includes a digital control panel. [In [ Figure 2 In one exemplary embodiment illustrated in the figure, the digital control panel PCN according to the invention is configured to interact with a touch panel PT. These control panels or touch panels can be customized and / or modified by means of digitization, for example, by reconfiguring the use of buttons and / or panels, or by improving the functional monitoring of buttons and / or panels. These panel groups are connected to a computing unit UC (sometimes referred to as RCCP / UCAP or RCCP for remote central control panels) and a UCAP (Ultra-Compact Avionics Platform). The computing unit UC includes a group of service modules, and specifically includes:
[0092] - Arinc 661 Graphical Generation Module (standard for defining and making certified aeronautical human-machine interfaces), which is particularly associated with the FIA, FIL and FIR functions;
[0093] - MP module for managing / driving the control panel, which is particularly associated with the driving function FIP;
[0094] - central computing module MC.
[0095] The computing unit UC of the system according to the present application is configured to perform the main functions associated with the method of the present application: screen page manager function, NNC (Non Normal Check List) execution and RCCP driving, hereinafter indicated as function GEP. This function GEP makes it possible, in particular, to modify the state of the digital elements of the cockpit, while recording the initial state and the modified situation, in order to track any changes. It also makes it possible to automatically perform, during the flight preparation phase, all or part of the routine check list procedures.
[0096] If an abnormal situation or system failure occurs, it is also associated to the content of the minimum equipment list, which is accessible through the prediction function of the minimum equipment list (generally known as MEL), in order to automatically perform all or part of the procedures (and corresponding actions and checks) associated with the management of the non-normal check list (NNC). It should be noted that the information in the MEL document is organized by system (chapter of the Air Transport Association, ATA, in the example above ATA 36), sub-system (sub-chapter ATA 36-11), sub-sub-system or component (sub-sub-chapter ATA 36-11-05). This organization makes it possible to identify in detail the elements that contribute to the airworthiness of the aircraft.
[0097] [ Figure 3 ] An excerpt example of the FAA published A350XWB MEL document is shown in which it is explained how the information is structured. In this example, when the "engine bleed IP check valve" condition is detected as non-functional but in the "open" position, two types of recommendations are proposed:
[0098] - (O): check the operational impact during the flight to ensure the continuity of the operation
[0099] - (M): if the failure occurs when the aircraft is on the ground, the decision to fly depends on the verification of the functional impact and the consideration of these impacts by the user.
[0100] In this example, the device (or method) according to the present application is configured, through the GEP software function, to drive the execution of the checks described in the procedure (O) during the flight, i.e.:
[0101] - Check: Check that the engine bleed air system not affected by the fault is fully operating normally; and
[0102] - Check: Check that the high pressure valve of the engine affected by the bleed air fault has been deactivated and is in the "closed" position; and
[0103] - Limitation: At low power, do not use the bleed air system of the affected engine during descent and taxi.
[0104] Furthermore, the electronic power distribution switch manager makes it possible to verify the driving of the operation of the electronic contactors. Indeed, some procedures can require the shutdown of the faulty system to avoid any disturbance to the overall behavior of the aircraft. In other cases, the procedure can require a system power cycle (off-on) to switch it to a specific operating mode. In other words, the association between the GEP software functions and the power distribution electronic contactor manager functions allows the automation of the electronic contactor driving.
[0105] Furthermore, the GEP functions generate system pages with a set of parameters and a high level architecture plane. The system pages are displayed on a screen dedicated to system pages. The system pages provide a simplified view of the potentially complex system architecture and focus on the main elements. These pages are designed as a means to inform the pilot in a concise way about the operating status of the system. The systems displayed are those that have an impact on the flight, whatever the phase. For example, if one of the cabin doors is not properly locked, the aircraft will not be able to take off, this condition must be detected on the ground before the taxi phase. Examples of system pages can include the following information (based on the definition of the A350XWB):
[0106] - APU page - (ATA 49)
[0107] - BLEED page - (ATA 36)
[0108] - C / B page - status of the electronic contactors that are open or tripped (ATA 24)
[0109] - CABIN PRESSURE page - cabin pressure and temperature (ATA 21)
[0110] - AIR CONDITIONING page - (ATA 21) smoke detection indication and avionics bay and cargo bay
[0111] - CRUISE page - fuel, air conditioning and cabin pressure status.
[0112] - DOOR page - (ATA 52)
[0113] - OXYGEN (Oxygen) page (ATA 35)
[0114] - ELEC AC (Alternating Current) page - (ATA 24)
[0115] - ELEC DC (Direct Current) page - (ATA 24)
[0116] - ENG (Engine) page - supplementary page dedicated to engine display (ATA 70)
[0117] - FLIGHT / CTRL (Flight / Control) page - (ATA 27)
[0118] - FUEL (Fuel) page - (ATA 28 & 47)
[0119] - HYDRAULIC (Hydraulic) page - (ATA 29) & hydraulic circuit status and main parameters exposed through valves
[0120] - WHEEL (Wheel) page - (ATA 32) status of landing gear, brakes and tire pressure.
[0121] The GEP software function is therefore configured to give the pilot, via the system page(s), the results of the checks and to indicate any operational limitations that need to be taken into account, and possibly to remind the pilot to pay attention to these limitations during the descent and taxi phases (in relation to the illustrative example used in this document).
[0122] The GEP function is also linked to the flight warning (FW) function, which manages the alerts communicated to the user via the screen, dedicated indicators or even sound. More specifically, the flight warning function FW generates an alert not only in the event of a system malfunction, but also in the event of the aircraft flying too close to the ground, a risk of collision and more generally in any situation requiring the attention of the user and the taking of corrective measures. Likewise, during normal operation or when there is no alert active (a situation not covered by the method according to the invention), the FWS system receives the information circulating on the interconnection bus(es) of all the supervised aircraft systems. The central function FC also receives the information circulating on the interconnection bus(es) of all the supervised aircraft systems and generates the system pages from this information.
[0123] The function GEP also implements the automatic execution of the step-by-step procedures, while providing the necessary feedback to the user. Generally, this feedback takes the form of system page displays on the display system, with screens or screen areas dedicated to these displays (or "system displays"), changes in the state of the digital cockpit controls, and / or any other means of informing the user of the current situation or progress thereof. For example, when a procedure can affect or interfere with a control action, this function can be configured to generate a message requesting the pilot / user's approval before executing the procedure.
[0124] The function GEP is also associated, in whole or in part, to the prediction function MEL, to evaluate the operational impact of a system failure, if the NNC checks list does not already provide this information.
[0125] To this end, as illustrated in
[0001] , Figure 4 ] the function GEP is organized around a central automatic execution function (hereafter the central FC function). This central FC function is associated to the following external functions (i.e. those that do not belong to the function GEP):
[0126] - the function (FWS) or (CAS) ("Flight Warning System" or "Crew Alerting System"), which, among other functions, is used to display alerts in the aircraft cockpit;
[0127] - a management function (FD) for electrical contactors and electrical distribution;
[0128] - the prediction function MEL;
[0129] - the learning function FA;
[0130] - an acquisition function FP for flight parameters and systems.
[0131] In addition, within the function GEP, the central function FC is associated to the following internal functions:
[0132] - the driving function FIP (RCCP);
[0133] - a function for generating and displaying FIA system pages and procedures in the event of an alert;
[0134] - the NNC (Non Normal Check List) function FIL;
[0135] - the routine check list (RC) procedure function FIR.
[0136] In one embodiment, the different aircraft systems are interconnected through one or more interconnection buses, and the central function FC is connected to the interconnection bus to enable it to interact with the different aircraft systems, for example using the external functions described previously. At the same time, the central function FC generates system pages via a trusted graphical generation function (based on the Arinc 661 standard), via which it acquires and records the state of the digital control panels, acquires and records the state of the electronic contactors of the power distribution system, and provides all or part of this information to the prediction function MEL in order to feed the knowledge base from which the learning function will learn and update. The learning function will learn from all the abnormal situations encountered and, above all, from the way these abnormal situations are managed and resolved. One of the objectives is to improve the classification and ordering of the execution procedures in the case of multiple alerts, and to determine whether the alerts should be managed in sequence or whether some of them can be processed in parallel. The idea is therefore to deploy this learning function on all the aircraft of the fleet and to integrate all the learning at the fleet level. The objective is to take full advantage of the increasing knowledge accumulated at the fleet level.
[0137] With this organization, the computing unit UC (sometimes referred to as avionics platform) can continuously monitor the occurrence of failure alerts. This monitoring can benefit from the functional association between the GEP software functions and the FWS functions. In addition, the prediction function MEL, based on the MEL structure, provides functionality to achieve optimal efficiency. The combination of the MEL function with the GEP software functions (on the one hand) and the OMS (onboard maintenance system) functions (on the other hand) will thus make it possible to create an embedded collaborative space and collect all the actions performed by the user and / or the results obtained from the GEP functions to process the alerts.
[0138] The OMS function is a centralized onboard maintenance function or system. Typically, the function OMS encompasses several functions such as the acquisition of flight parameters for the processing by the prediction function, and the acquisition of maintenance messages for the processing by the diagnostic function. Thus, the flight and system parameter acquisition function receives information circulating on the interconnection bus(s) of all the aircraft systems, as well as information from all the systems capable of generating information in digital format and available on the interconnection bus(es).
[0139] In addition, with the cockpit digitization mentioned previously, the GEP software function allows the learning function to be associated with the central function FC (so-called automated procedure driving and execution function). The purpose of this learning function is to continuously improve the level of user support. With this overall continuous improvement of the management of alerts in the cockpit, the invention makes it possible to move between the different levels of autonomy defined by the EASA, namely: level 1 = human assistance; level 2 = human-machine collaboration; level 3 = machine execution, human in the loop.
[0140] In one embodiment, the central function FC of the GEP function is developed according to the most stringent aeronautical standards, in order to ensure the highest reliability in the execution of the process. More specifically, the development of this function is based on the application of standards that comply with the Design Assurance Level (DAL) objectives; in this case, the target DAL level will be B, i.e. a design that ensures that abnormal behaviour with hazardous consequences does not have a probability greater than 10 e-7 -9
[0141] Therefore, by implementing the method according to the present application, the system according to the present application just described relieves the user of the burden of performing "low-level" processes and tasks, allowing him to be able to focus on the stability and airworthiness of the aircraft, while providing a knowledge base based on the airworthiness status of the aircraft.
Claims
1. A method for automatically processing one or more alarms in an aircraft, wherein the alarms are associated with events related to the aircraft's state, and the events are capable of being associated with one or more alarms, the method being implemented by an automated processing system including one or more digital control panels and a computing unit, the method comprising: - The steps for preparing to handle an alarm (E1) include: o Store alerts and sub-steps for the severity level associated with each alert; o Check if there are any other sub-steps that are already in the process of automated alarm handling; - Step (E2) of evaluating one or more processes associated with each alarm, the evaluation including: o Sub-steps that categorize and sort processes based on a list of actions to be performed and checks associated with each process in order to obtain an ordered list of processes to be implemented; o Displays an ordered list of sub-steps of the process to be implemented, with the process associated with the alarm of the highest severity and / or ensuring stable flight conditions being displayed first; - Step (E3) to select the execution mode of the process to be implemented from manual mode and automatic mode, wherein in manual mode, the actions associated with each process are performed by the user, and in automatic mode, the actions associated with each process are performed by the automatic processing system; - Step (E4) of executing processes from an ordered list of processes to be implemented, which, when the user selects automatic execution mode, is performed in the order of the list, and for each action associated with each process, the step includes: When the user selects the automatic execution mode, the automatic processing system executes the sub-steps of the action; o For each action performed during a previous sub-step or performed by the user, update the progress of each process and the sub-steps that have been changed in the state of the aircraft associated with that progress; - Show the actions performed in the previous steps, the changes that have been achieved and / or are expected associated with each of these actions, and the steps for matching the changes achieved with the expected changes (E5).
2. The method according to the preceding claim, wherein the step of selecting the execution mode of the process to be implemented includes a sub-step of displaying a dialog window, the dialog window allowing the user to select the execution mode.
3. The method according to any one of the preceding claims, wherein for at least one action associated with the process, the step of performing the process includes: - A sub-step that actuates (one or more) digital components of a control panel; and / or - Actuate at least one action associated with the process of one or more electrical contactors in a sub-step to shut down the faulty component and / or turn on the backup component.
4. The method according to any one of the preceding claims, wherein during the sub-step of updating the progress of each process, a checkbox is displayed when an action is performed and the obtained result associated with said action is consistent with the expected result.
5. The method according to any one of the preceding claims, comprising the following sub-step: at the end of the sub-step of updating the progress of the considered process, when the obtained changes associated with the considered action are inconsistent with the expected changes associated with the action, the user selects one of the following two steps to take: - Continue the current process by executing the previous sub-step for the next action, or continue to the next process if the current process has been completed; or - When changes associated with the action under consideration require the implementation of a new process, execute the process according to the previous sub-steps, and resume the processing of the current process after the new process has been implemented; The selected steps are implemented by an automated processing system.
6. The method according to any one of the preceding claims, further comprising, at the end of the step of displaying the performed action, switching the automatic processing system to a monitoring mode, in which the processing system is configured to detect the occurrence of one or more alarms.
7. An automatic alarm processing system comprising at least one digital control panel, a computing unit connected to the digital control panel, and components for verifying the status of unit elements constituting the digital control panel, the automatic alarm processing system being configured to implement the method according to the preceding claims.
8. A computer program comprising instructions that, when executed by a computer, cause the apparatus according to any one of the preceding claims to perform the steps of the method according to any one of claims 1 to 6.
9. A computer-readable medium having a computer program according to the preceding claims recorded thereon.
Citation Information
Patent Citations
Systems and methods for an agnostic system functional status determination and automatic management of failures
WO2021130520A1