An aircraft airworthiness monitoring method based on operation data

By using fault tree models and multi-period Bayesian update methods, key equipment is identified and the airworthiness status of aircraft is dynamically monitored. This solves the problem of risk assessment in the early stages of aircraft commissioning, enables real-time airworthiness monitoring and timely detection of safety hazards, and improves the accuracy and timeliness of aircraft safety assessment.

CN121706265BActive Publication Date: 2026-05-12CIVIL AVIATION UNIV OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CIVIL AVIATION UNIV OF CHINA
Filing Date
2026-02-10
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In the early stages of aircraft deployment, especially for high-reliability airborne systems, existing technologies have limited accumulated operating hours and failure samples, making it difficult to assess the true risks using classical statistical methods. Furthermore, the lack of real-time airworthiness monitoring methods based on operational data makes it difficult to detect potential safety hazards in a timely manner.

Method used

By employing a fault tree model combined with operational data, key equipment is identified based on the importance of fault contribution. Multi-cycle Bayesian updates are performed, equipment failure rates are dynamically monitored and compared with airworthiness and safety target values, triggering an early warning mechanism to achieve real-time assessment of the system's airworthiness status.

Benefits of technology

It improves the accuracy and timeliness of airworthiness monitoring under limited data conditions, enabling the timely detection of potential safety hazards and enhancing the stability and reliability of aircraft safety assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121706265B_ABST
    Figure CN121706265B_ABST
Patent Text Reader

Abstract

The application discloses a kind of airplane airworthiness monitoring methods based on operation data.It includes obtaining system safety evaluation data in the airworthiness certification phase of aircraft;Determine the failure contribution importance;Obtain operational observation failure rate;Obtain the posterior failure rate estimation mean of each airworthiness monitoring cycle;Calculate the real-time failure probability of top event and other steps.The application effect: reasonably utilize the effective operation data collected by civil aircraft to monitor the safety of equipment.Through fault tree model, the failure contribution importance of each bottom event to top event is calculated.The multi-cycle Bayesian updating method is used to determine the conservative initial prior information, prevent the influence caused by extreme value in small sample situation, ensure the stability of the initial result based on operation data airworthiness monitoring, and improve the accuracy of equipment reliability calculation result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of civil aviation technology, and specifically relates to an aircraft airworthiness monitoring method based on operational data. Background Technology

[0002] During the service life of certain types of civil aircraft, the actual airworthiness risk level may exceed the safety standards set at the initial design stage due to the complexity of the operating environment, limitations in standard setting, and potential undiscovered changes in compliance methodologies. Therefore, commercial aircraft entering service should undergo continuous safety assessments to maintain their airworthiness and thereby improve their overall safety level.

[0003] In terms of operational data collection and management, the international aviation industry has established relatively mature standards. Operators typically collect operational data according to ATA Spec 2000 Chapter 11, Reliability Data Collection and Exchange, or the S5000F standard (International specification for in-service data feedback) published by the European Aeronautical and Defence Industries Association (EADA), and feed the raw data back to the main manufacturers' digital big data systems, such as Boeing's AnalytX platform or Airbus's Skywise platform. my country is also gradually improving its supporting system for collecting, integrating, and analyzing aircraft lifecycle safety data in this field. Despite increasingly sophisticated data collection standards, in the early stages of aircraft deployment, actual airworthiness monitoring still faces core technical challenges.

[0004] 1. Operational data reflects the true inherent reliability of equipment, and its reliability is far higher than that of design data. However, in the early stages of an aircraft's service, especially for high-reliability airborne systems, the accumulated operating hours and failure samples are generally very limited.

[0005] 2. Classical statistical methods based on large samples are no longer applicable when the amount of data is insufficient, making it difficult to assess the current true risk.

[0006] 3. Existing management systems focus primarily on data storage and reporting, lacking a dynamic assessment method that can leverage system security data from the certification phase, combined with limited operational data, to achieve real-time airworthiness monitoring of operational safety in the short term and promptly identify potential safety hazards.

[0007] In conclusion, developing an airworthiness monitoring method that integrates prior design knowledge with post-operational data has significant engineering application value for improving flight safety, meeting the reliability requirements of aviation operations, and perfecting the airworthiness management system for domestically produced civil aircraft.

[0008] Furthermore, regarding the safety data acquisition process, operational data, as a reflection of the inherent reliability of equipment, is more reliable than safety data acquired during the design and verification phases. Therefore, it is necessary to acquire and monitor the safety data of domestically produced airborne equipment during the operational phase. This not only allows for understanding the reliability status of the operational fleet's equipment but also provides feedback to suppliers for analysis, enabling them to identify potential problems and improve equipment design, thereby enhancing the overall safety level of my country's aviation industry.

[0009] Chu Yanyun's publicly disclosed aviation operation data acquisition system based on big data technology can collect raw data reflecting the reliability status of the operating fleet, such as ACARS data, QAR data, and text data. This data is uploaded to a big data analysis platform monthly for analysis, improving the automation of operation data acquisition and solving the problem of data silos after traditional data acquisition (Aviation Operation Data Acquisition System Based on Big Data Technology [P]. Shanghai: CN201810489479.8, 2019-11-29.); Guo et al. proposed a data-driven integrated safety risk warning model based on deep learning. Combining QAR data and the characteristics of aircraft system failures, it uses failure mode and effects analysis, causal chain analysis, and long short-term memory methods to describe the risk development caused by system failures and predict the trends of flight parameters of each system, thereby improving the predictive ability of aviation system risks and their severity (A Data-Driven integrated safety risk warning model based on deep learning for Civil Aircraft [J]. IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONICSYSTEMS, 2023, 59(2): 1707-1719); Sun et al., based on a large number of specific aircraft condition monitoring system (ACMS) reports, used nonparametric modeling techniques to monitor the health of air conditioning systems (ACS), and the proposed health indicators can effectively monitor the degradation state of ACS (A data-driven health indicator extraction method for aircraft air conditioning system health monitoring[J].CHINESE JOURNAL OF AERONAUTICS, 2019, 32(2): 409-416).

[0010] However, the above studies still have certain limitations. Due to some special circumstances, such as the operation of new aircraft, small airlines, or aircraft in remote areas, the amount of data may be very limited or difficult to obtain in the short term. Traditional methods may not be immediately effective in such cases, so a new approach is needed to address this issue. Summary of the Invention

[0011] To address the aforementioned problems, the present invention aims to provide an aircraft airworthiness monitoring method based on operational data.

[0012] To achieve the above objectives, the aircraft airworthiness monitoring method based on operational data provided by the present invention includes the following steps performed in sequence:

[0013] 1) Obtain system safety assessment data during the aircraft airworthiness certification phase, including information such as fault tree models, reliability data of each device / component, logical relationships of system composition, and basic system description, as well as initial design reliability data representing each basic event of the equipment in the fault tree model;

[0014] 2) Based on the above system safety assessment data, determine the fault contribution importance of each underlying event in the fault tree model, and then determine the key equipment as key airworthiness monitoring objects according to the fault contribution importance.

[0015] 3) Set an airworthiness monitoring cycle, collect the operational data of the above-mentioned key equipment during the airworthiness monitoring cycle, and perform data preprocessing and transformation to obtain the operational failure rate during the cycle;

[0016] 4) Combining the system safety assessment data obtained in step 1), perform multi-period Bayesian updates on the equipment failure rate to obtain the mean posterior failure rate estimate for each airworthiness monitoring cycle.

[0017] 5) Substitute the mean posterior failure rate estimates of each key device obtained in step 4) back into the fault tree model obtained in step 1) as new basic event probability input parameters to calculate the real-time failure probability of the top event. Compare this probability with the set system airworthiness safety target value to determine the system airworthiness status. If the comparison result indicates that the system safety no longer meets the airworthiness requirements, the failure contribution importance obtained in step 2) and the operational observation failure rate obtained in step 3) will be combined. Early warning displays are provided to dynamically monitor top and bottom events.

[0018] In step 1), the method for obtaining system safety assessment data during the aircraft airworthiness certification phase, including information such as fault tree models, reliability data of each device / component, logical relationships of system composition, and basic system description, as well as the initial design reliability data representing each basic event of the device in the fault tree model, is as follows:

[0019] First, system safety assessment data for a specific aircraft model during the airworthiness certification phase is obtained from the aircraft manufacturer or design department as the initial benchmark for airworthiness monitoring. This system safety assessment data includes information such as fault tree models, reliability data for each device / component, logical relationships within the system, and a basic system description. Simultaneously, initial design reliability data representing the basic events of each device in the fault tree model is obtained, primarily including design failure rates. Design parameters, including those included.

[0020] In step 2), the method for determining the fault contribution importance of each underlying event in the fault tree model based on the aforementioned system safety assessment data, and then identifying key equipment as key airworthiness monitoring objects based on the fault contribution importance, is as follows:

[0021] 2.1) Based on the above fault tree model, the occurrence of the top event in the system is taken as a prerequisite;

[0022] 2.2) Quantitative analysis of the fault tree model was performed, and the fault contribution importance of each bottom event was calculated using formula (1). Fault contribution importance refers to the percentage of time a top event has occurred in the system. Under the conditions, the first The bottom line event is also in a state of failure. conditional probability , recorded as To quantify the consequences of system failures, by the first The percentage of failures caused by individual events;

[0023] (1)

[0024] In the formula, This represents the top event in the system. This indicates that the top event has occurred; Indicates the first The bottom line event, Indicates the first The bottom-level event occurred;

[0025] 2.3) All bottom events are ranked according to their contribution to the fault. Sort by size from largest to smallest;

[0026] 2.4) Select several top-ranked basic events, or select a set of basic events whose cumulative failure contribution importance reaches a set threshold, and identify these basic events as key equipment as key airworthiness monitoring objects to prioritize the allocation of monitoring resources. These key airworthiness monitoring objects will undergo operational data collection and parameter updates in subsequent steps.

[0027] In step 3), the method for setting an airworthiness monitoring cycle, collecting operational data of the aforementioned key equipment within the airworthiness monitoring cycle, and performing data preprocessing and transformation to obtain the operational failure rate within that cycle is as follows:

[0028] 3.1) Set an airworthiness monitoring cycle, and then collect the operational data of the above-mentioned key equipment during the airworthiness monitoring cycle, mainly including: total fleet flight time, number of equipment installed, and detailed unplanned replacement records; sort the unplanned replacement intervals in the collected unplanned replacement records, and then use formula (2) and formula (3) to construct the sample quantile statistics. Set a threshold value. If the calculated sample quantile statistic exceeds the threshold value, it is determined to be abnormal data caused by recording errors or extreme cases and is removed to obtain processed operational data.

[0029] (2)

[0030] (3)

[0031] In the formula, This represents the upper quartile value. This represents the lower quartile value. , These represent the outlier statistics for the right and left sides, respectively.

[0032] 3.2) Using the above-processed operational data, assess the frequency of replacement of key equipment at the operational site; calculate the average unplanned replacement interval (MTBUR) within the airworthiness monitoring cycle using formula (4);

[0033] (4)

[0034] In the formula, This indicates the total flight time of the fleet during the airworthiness monitoring period. This indicates the number of units of this critical equipment installed per machine. This indicates the total number of unplanned replacements of the critical equipment during the airworthiness monitoring period.

[0035] 3.3) Using empirical data correction method to measure the fault-free detection rate Configure settings; No fault detection rate Typically, this data is based on empirical data generated from the service history of systems and equipment, expressed as a percentage; then, formula (5) is used, combined with the fault-free detection rate. The aforementioned Mean Unplanned Replacement Interval (MTBUR) is converted into Mean Time Between Failures (MTBF), which better reflects the inherent reliability of critical equipment. Subsequently, the reciprocal of the MTBF is taken to obtain the operational observation failure rate within the airworthiness monitoring cycle. ;

[0036] (5)

[0037] In step 4), the method for combining the system safety assessment data obtained in step 1) to perform multi-period Bayesian updates on the equipment failure rate and obtain the posterior failure rate estimate mean for each airworthiness monitoring cycle is as follows:

[0038] 4.1) Assume that the lifespan of the identified critical equipment follows an exponential distribution. According to Bayesian conjugate theory, the equipment failure rate of an exponential distribution... The conjugate prior distribution parameters are gamma distributions. In the initial stage of operation, the initial shape parameters of the gamma distribution are set. and scale parameters ; Take the design failure rate obtained in step 1) during the airworthiness certification phase. ;

[0039] 4.2) For each airworthiness monitoring cycle, i.e. the 1st cycle... During each airworthiness monitoring cycle, failure flight time data of key equipment is collected; let a set of failure flight time data collected be... ,in , This is the total number of failures observed in critical equipment. This is the failure flight time data at the end of the airworthiness monitoring cycle; assuming equipment failure interval time. Then the sample set of equipment failure interval times within this airworthiness monitoring period is: The equipment failure interval time can be calculated using formula (6). The probability density function;

[0040] (6)

[0041] In the formula, The equipment failure interval is the time between equipment failures. ;

[0042] Finally, the above-obtained sample set of equipment failure interval times will be used. Substitute into formula (6) to construct the likelihood function of the airworthiness monitoring cycle data;

[0043] 4.3) According to Bayes' theorem, the prior distribution parameters are multiplied by the above likelihood function and normalized. The equipment failure rate is then calculated using formula (7). The posterior probability density function; based on the properties of the gamma distribution, the equipment failure rate is calculated using formula (8). Mean of posterior loss rate estimate after Bayes update ;

[0044] Equipment failure rate The formula for calculating the posterior probability density function is as follows:

[0045] (7)

[0046] For equipment failure rate It can be seen that its posterior probability density function is still in the form of a gamma distribution, i.e., the equipment failure rate. posterior distribution parameters ;

[0047] Equipment failure rate The formula for calculating the mean of the posterior failure rate estimate after Bayesian update is as follows:

[0048] (8)

[0049] In the formula, , These represent the shape and scale parameters of the gamma distribution, respectively. The initial values ​​are used in the first airworthiness monitoring cycle, and the updated values ​​are used in subsequent airworthiness monitoring cycles. This indicates the total number of equipment failures observed during the airworthiness monitoring period; This represents the sum of the failure intervals of all equipment within the airworthiness monitoring period;

[0050] 4.4) A rolling update strategy is adopted to adapt to continuous airworthiness monitoring, based on the gamma distribution parameters determined by the design parameters. Using the prior distribution parameters and combining the operational data from the first airworthiness monitoring cycle, the shape parameters for the first airworthiness monitoring cycle are output. and scale parameters and the mean of the posterior failure rate estimate Next, operational data for the second airworthiness monitoring cycle is collected, using the posterior distribution parameters from the first airworthiness monitoring cycle. As the prior distribution parameters for the second airworthiness monitoring cycle, the shape parameters for the second airworthiness monitoring cycle are calculated according to formulas (7) and (8). and scale parameters and the mean of the posterior failure rate estimate Repeat the above operations, using the first... The posterior distribution parameters of the first airworthiness monitoring cycle are used as the first... Prior distribution parameters for each airworthiness monitoring cycle are used to achieve intergenerational data transfer and knowledge accumulation, ultimately obtaining the first... Mean of post-hoc failure efficiency estimate for each airworthiness monitoring cycle .

[0051] In step 5), the mean posterior failure rate estimate of each key device obtained in step 4) is used as a new basic event probability input parameter and substituted back into the fault tree model obtained in step 1). The real-time failure probability of the top event is calculated and compared with the set system airworthiness safety target value to determine the system airworthiness status. If the comparison result shows that the system safety no longer meets the airworthiness requirements, the failure contribution importance obtained in step 2) and the operational observation failure rate obtained in step 3) will be combined. The method for providing early warnings and dynamically monitoring top and bottom events is as follows:

[0052] 5.1) The mean of the post-hoc failure rate estimates for each key piece of equipment obtained in step 4) during the current airworthiness monitoring cycle. As the new basic event probability input parameter, it is substituted back into the fault tree model obtained in step 1), and the Boolean logic operation of the fault tree model is used to recalculate the real-time failure probability of the top event in the current operating state from bottom to top. ;

[0053] 5.2) Set the target value for system airworthiness safety Then, the above real-time failure probability Compare with the system's airworthiness safety target value: If If the current airworthiness status of the system is determined to be good, the existing monitoring strategy will be maintained, and the system will automatically enter the next airworthiness monitoring cycle of operational data collection and monitoring.

[0054] 5.3) If If the system safety is determined to no longer meet airworthiness requirements, a system-level early warning mechanism is immediately triggered. Attribution analysis is performed based on the fault contribution importance obtained in step 2), and the top event state of the fault tree model is highlighted on the system interface, along with a list of the main causal sources leading to increased risk. Based on the key airworthiness monitoring objects identified in step 2), and combined with the latest real-time failure probability calculated in 5.1, the observed failure rates from actual operations are screened and displayed. The key airworthiness monitoring object is significantly higher than the design expectation and contributes the most to the current system failure probability, thus leading to a decline in the overall safety level of the system.

[0055] The aircraft airworthiness monitoring method based on operational data provided by this invention has the following beneficial effects: It rationally utilizes effective operational data collected from civil aircraft to monitor equipment safety. Quantitative analysis is performed using a fault tree model to calculate the importance of each bottom event's contribution to the top event's failure. A multi-period Bayesian update method is employed to determine conservative initial prior information, preventing the influence of extreme values ​​in small sample cases. This ensures the stability of the initial results of airworthiness monitoring based on operational data while improving the accuracy of equipment reliability calculation results. Attached Figure Description

[0056] Figure 1 The flowchart of the aircraft airworthiness monitoring method based on operational data provided by the present invention is shown.

[0057] Figure 2 This is a fault tree model of the inertial navigation system during the airworthiness certification stage in an embodiment of the present invention. Detailed Implementation

[0058] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments.

[0059] like Figure 1 As shown, the aircraft airworthiness monitoring method based on operational data provided by the present invention includes the following steps performed in sequence:

[0060] 1) Obtain system safety assessment data during the aircraft airworthiness certification phase, including information such as fault tree models, reliability data of each device / component, logical relationships of system composition, and basic system description, as well as initial design reliability data representing each basic event of the equipment in the fault tree model;

[0061] In the early stages of civil aircraft operation, due to the limited cumulative flight time and insufficient operational sample size, it is impossible to directly utilize statistical data for safety assessment. Therefore, the first step is to obtain System Safety Assessment (SSA) data for a specific aircraft model during the airworthiness certification phase from the aircraft manufacturer or design department as the initial benchmark for airworthiness monitoring. This SSA data includes information such as fault tree models, reliability data for each device / component, logical relationships within the system, and a basic system description. Simultaneously, initial design reliability data representing the basic events of the equipment in the fault tree model is obtained, primarily including design failure rates. The design parameters, including these, will serve as the basis for calculating the importance of fault contributions and the Bayesian prior distribution parameters in subsequent steps.

[0062] 2) Based on the above system safety assessment data, determine the fault contribution importance of each underlying event in the fault tree model, and then determine the key equipment as key airworthiness monitoring objects according to the fault contribution importance.

[0063] To achieve efficient monitoring with limited maintenance resources, it is necessary to identify the critical equipment that has the greatest impact on system security.

[0064] 2.1) Based on the above fault tree model, the occurrence of the top event in the system is taken as a prerequisite;

[0065] 2.2) Quantitative analysis of the fault tree model was performed, and the fault contribution importance of each bottom event was calculated using formula (1). Fault contribution importance refers to the percentage of time a top event has occurred in the system. Under the conditions, the first The bottom line event is also in a state of failure. conditional probability , recorded as To quantify the consequences of system failures, by the first The percentage of failures caused by individual events;

[0066] (1)

[0067] In the formula, This represents the top event in the system. This indicates that the top event has occurred; Indicates the first The bottom line event, Indicates the first The bottom-level event occurred;

[0068] 2.3) All bottom events are ranked according to their contribution to the fault. Sort by size from largest to smallest;

[0069] 2.4) Select several top-ranked basic events, or select a set of basic events whose cumulative failure contribution importance reaches a set threshold, and identify these basic events as key equipment as key airworthiness monitoring objects to prioritize the allocation of monitoring resources. These key airworthiness monitoring objects will undergo operational data collection and parameter updates in subsequent steps.

[0070] 3) Set an airworthiness monitoring cycle, collect the operational data of the above-mentioned key equipment during the airworthiness monitoring cycle, and perform data preprocessing and transformation to obtain the operational failure rate during the cycle;

[0071] 3.1) Set an airworthiness monitoring cycle, and then collect the operational data of the above-mentioned key equipment during the airworthiness monitoring cycle, mainly including: total fleet flight time, number of equipment installed, and detailed unplanned replacement records; considering that there may be human input errors or extreme random situations in the unplanned replacement records, directly using the raw data may lead to statistical bias. Therefore, the unplanned replacement interval time in the collected unplanned replacement records is sorted first, and then the sample quantile statistics are constructed using formula (2) and formula (3). Set a threshold value. If the calculated sample quantile statistic exceeds the threshold value, it is determined to be abnormal data caused by recording errors or extreme cases and is removed to obtain processed operational data.

[0072] (2)

[0073] (3)

[0074] In the formula, This represents the upper quartile value. This represents the lower quartile value. , These represent the outlier statistics for the right and left sides, respectively.

[0075] 3.2) Using the above-processed operational data, assess the frequency of replacement of critical equipment at the operational site; calculate the mean time between unscheduled removals (MTBUR) within the airworthiness monitoring period using formula (4); this indicator reflects the degree of impact of critical equipment on airline operations.

[0076] (4)

[0077] In the formula, This indicates the total flight time of the fleet during the airworthiness monitoring period. This indicates the number of units of this critical equipment installed per machine. This indicates the total number of unplanned replacements of the critical equipment during the airworthiness monitoring period.

[0078] 3.3) Not every "unplanned replacement" signifies a physical failure in critical equipment. In actual engineering, a certain percentage of critical equipment, after being removed and sent for repair, proves to be functionally normal upon testing, i.e., No Fault Found (NFF). Given the typically significant lag in obtaining final repair analysis reports from critical equipment manufacturers, to meet the timeliness requirements of airworthiness monitoring, this invention employs an empirical data correction method to adjust the NFF rate. Configure settings; No fault detection rate This data is typically based on experience derived from the service history of systems and equipment, representing the percentage of replaced parts that have been tested and found to meet airworthiness requirements and can continue to be used, as well as the fault-free detection rate for different equipment. The differences are generally expressed as percentages, such as 20%, 10%, 5%, etc.; then, using formula (5), combined with the fault-free detection rate... The aforementioned Mean Unplanned Replacement Interval (MTBUR) is converted into Mean Time Between Failures (MTBF), which better reflects the inherent reliability of critical equipment. Subsequently, the reciprocal of the MTBF is taken to obtain the operational observation failure rate within the airworthiness monitoring cycle. ;

[0079] (5)

[0080] 4) Combining the system safety assessment data obtained in step 1), perform multi-period Bayesian updates on the equipment failure rate to obtain the mean posterior failure rate estimate for each airworthiness monitoring cycle.

[0081] 4.1) Assume that the lifespan of the identified critical equipment follows an exponential distribution. According to Bayesian conjugate theory, the equipment failure rate of an exponential distribution... The conjugate prior distribution parameters are gamma distributions. In the initial stage of operation, the initial shape parameters of the gamma distribution are set. and scale parameters This setting is because when the initial shape parameters When the sample size is too small, the posterior estimate tends to be conservative, which can effectively avoid overly optimistic estimates due to the small sample size. Moreover, as the sample size increases, the error of the initial parameters will be quickly ignored. Take the design failure rate obtained in step 1) during the airworthiness certification phase. ;

[0082] 4.2) For each airworthiness monitoring cycle, i.e. the 1st cycle... During each airworthiness monitoring cycle, failure flight time data of key equipment is collected; let a set of failure flight time data collected be... ,in , This is the total number of failures observed in critical equipment. This is the failure flight time data at the end of the airworthiness monitoring cycle; assuming equipment failure interval time. Then the sample set of equipment failure interval times within this airworthiness monitoring period is: The equipment failure interval time can be calculated using formula (6). The probability density function. These observational data form the basis of the likelihood function for correcting the prior distribution parameters.

[0083] (6)

[0084] In the formula, The equipment failure interval is the time between equipment failures. ;

[0085] Finally, the above-obtained sample set of equipment failure interval times will be used. Substitute these values ​​into formula (6) to construct the likelihood function of the airworthiness monitoring cycle data, which will serve as the basis for subsequent correction of the prior distribution parameters.

[0086] 4.3) According to Bayes' theorem, the prior distribution parameters are multiplied by the above likelihood function and normalized. The equipment failure rate is then calculated using formula (7). The posterior probability density function of the exponential distribution; it can be seen that the conjugate posterior distribution of the exponential distribution is still in the form of a gamma distribution. Based on the properties of the gamma distribution, the equipment failure rate is calculated using formula (8). Mean of posterior loss rate estimate after Bayes update This value is the latest reliability estimate, which combines design experience with actual operational performance.

[0087] Equipment failure rate The formula for calculating the posterior probability density function is as follows:

[0088] (7)

[0089] For equipment failure rate It can be seen that its posterior probability density function is still in the form of a gamma distribution, i.e., the equipment failure rate. posterior distribution parameters ;

[0090] Equipment failure rate The formula for calculating the mean of the posterior failure rate estimate after Bayesian update is as follows:

[0091] (8)

[0092] In the formula, , These represent the shape and scale parameters of the gamma distribution, respectively. The initial values ​​are used in the first airworthiness monitoring cycle, and the updated values ​​are used in subsequent airworthiness monitoring cycles. This indicates the total number of equipment failures observed during the airworthiness monitoring period; This represents the sum of the failure intervals of all equipment within the airworthiness monitoring period;

[0093] 4.4) This invention employs a rolling update strategy to adapt to continuous airworthiness monitoring, using gamma distribution parameters determined by design parameters. Using the prior distribution parameters and combining the operational data from the first airworthiness monitoring cycle, output the shape parameters for the first airworthiness monitoring cycle. and scale parameters and the mean of the posterior failure rate estimate Next, operational data for the second airworthiness monitoring cycle is collected, using the posterior distribution parameters from the first airworthiness monitoring cycle. As the prior distribution parameters for the second airworthiness monitoring cycle, the shape parameters for the second airworthiness monitoring cycle are calculated according to formulas (7) and (8). and scale parameters and the mean of the posterior failure rate estimate Repeat the above operations, using the first... The posterior distribution parameters of the first airworthiness monitoring cycle are used as the first... Prior distribution parameters for each airworthiness monitoring cycle are used to achieve intergenerational data transfer and knowledge accumulation, ultimately obtaining the first... Mean of post-hoc failure efficiency estimate for each airworthiness monitoring cycle .

[0094] 5) Substitute the mean posterior failure rate estimates of each key device obtained in step 4) back into the fault tree model obtained in step 1) as new basic event probability input parameters to calculate the real-time failure probability of the top event. Compare this probability with the set system airworthiness safety target value to determine the system airworthiness status. If the comparison result indicates that the system safety no longer meets the airworthiness requirements, the failure contribution importance obtained in step 2) and the operational observation failure rate obtained in step 3) will be combined. Provide early warnings to dynamically monitor top and bottom events;

[0095] 5.1) The mean of the post-failure efficiency estimates for each key piece of equipment obtained in step 4) during the current airworthiness monitoring cycle. As the new basic event probability input parameter, it is substituted back into the fault tree model obtained in step 1), and the Boolean logic operation of the fault tree model is used to recalculate the real-time failure probability of the top event in the current operating state from bottom to top. This value represents the real-time risk level of the system losing functionality within the next flight hour under the current level of operation and maintenance;

[0096] 5.2) Set the target value for system airworthiness safety Then, the above real-time failure probability Compare with the system's airworthiness safety target value: If If the current airworthiness status of the system is determined to be good, the existing monitoring strategy will be maintained, and the system will automatically enter the next airworthiness monitoring cycle of operational data collection and monitoring.

[0097] 5.3) If If the system safety is determined to no longer meet airworthiness requirements, a system-level early warning mechanism is immediately triggered. To assist engineers in quickly locating the root cause of the problem, attribution analysis is performed based on the fault contribution importance obtained in step 2). The system interface highlights the top event state of the fault tree model and marks the list of main causes leading to increased risk. Based on the key airworthiness monitoring objects identified in step 2) and the latest real-time failure probability calculated in 5.1), the actual operational observed failure rates are screened and displayed. The key airworthiness monitoring object is significantly higher than the design expectation and contributes the most to the current system failure probability, thus leading to a decline in the overall safety level of the system.

[0098] The following example uses an airborne inertial navigation system to simulate the entire process of dynamic airworthiness monitoring using the method of this invention in the early stages of operation.

[0099] First, obtain the fault tree model of the inertial navigation system during the airworthiness certification phase, such as... Figure 2 As shown. Define the top event in this system. The error message is "The inertial navigation system cannot output correct information." The inertial navigation system mainly consists of components such as accelerometers, gyroscopes, drive power devices, power supplies, and control display consoles. It should be noted that, unless otherwise specified, the time unit "hour" (h) mentioned in this specification and claims refers to flight hours (FH) or the effective operating time of the equipment.

[0100] Assuming the top event occurs Under the given conditions, the fault contribution importance of each underlying event representing the device is calculated. Considering the large number of underlying events in the system, to clearly demonstrate the method of this invention, this embodiment selects the most representative (top three in fault contribution importance) key components as samples for display based on the calculation results. The calculation results are shown in Table 1.

[0101] Table 1. Occurrence of Top Events The importance of each bottom event's failure contribution under the given conditions

[0102]

[0103] According to the sorting results in Table 1, the equipment The fault contribution significance of the (single-drive power device) is the highest at 0.68, meaning that when the inertial navigation system fails, there is a greater than 68% probability that the failure is caused by this device. Therefore, this embodiment will use the device... It has been identified as a key piece of equipment and will be subject to airworthiness monitoring. The subsequent focus will be on showcasing the process of collecting and updating operational data for this key piece of equipment.

[0104] For equipment After the fleet enters operation, operational data is collected in three airworthiness monitoring cycles, assuming each cycle is approximately 12 months. After outlier removal and Mean Time Between Failures (MTBF) conversion, the effective MTBF is as follows:

[0105] First airworthiness monitoring cycle: 2702 hours, 2890 hours, 4700 hours;

[0106] Second airworthiness monitoring cycle: 1900 hours, 2480 hours, 3100 hours, 1870 hours;

[0107] The third airworthiness monitoring cycle: 2100 hours, 1680 hours, and 1870 hours.

[0108] According to the design documents, the equipment Equipment failure rate Then its equipment failure interval time The probability density function is Assuming the equipment lifespan follows an exponential distribution, a relatively conservative conjugate prior distribution parameter is selected. ,Right now Based on the formula and the operational data for each airworthiness monitoring cycle, the mean estimated post-test failure rate for the first airworthiness monitoring cycle can be obtained. The mean of the post-hoc failure rate estimate for the second airworthiness monitoring cycle The mean of the post-hoc failure rate estimate for the third airworthiness monitoring cycle The results are shown in Table 2.

[0109] Table 2 Equipment Updated results of the mean post-failure efficiency estimates over three airworthiness monitoring cycles

[0110]

[0111] Update the equipment failure rate for each airworthiness monitoring cycle in Table 2. Substitute the fault tree model back into the model and recalculate the real-time failure probability of the top event through forward reasoning. The monitoring results are shown in Table 3.

[0112] Table 3 Real-time failure probability monitoring results of the top event in each airworthiness monitoring cycle.

[0113]

[0114] The data above shows that as operating time increases, the equipment... The failure rate shows a significant upward trend, and this micro-change directly leads to a year-on-year deterioration in the real-time failure probability of the top event in the system. In this embodiment, after the first airworthiness monitoring cycle ends, the real-time failure probability of the top event has already exceeded the set airworthiness safety target value. The system will immediately trigger an early warning mechanism and, based on the fault contribution importance obtained in step 2), clearly indicate on the human-machine interface: "The actual operational reliability of the single-drive power equipment deviates significantly from the design expectations, which is the main reason for the increased airworthiness risk of the system," and recommend that the airline immediately conduct a reliability investigation of the equipment or shorten the maintenance interval.

Claims

1. A method for monitoring aircraft airworthiness based on operational data, characterized in that: The aircraft airworthiness monitoring method based on operational data includes the following steps performed in sequence: 1) Obtain system safety assessment data during the aircraft airworthiness certification phase, including information such as fault tree models, reliability data of each device / component, logical relationships of system composition, and basic system description, as well as initial design reliability data representing each basic event of the equipment in the fault tree model; 2) Based on the above system safety assessment data, determine the fault contribution importance of each underlying event in the fault tree model, and then determine the key equipment as key airworthiness monitoring objects according to the fault contribution importance. 3) Set an airworthiness monitoring cycle, collect the operational data of the above-mentioned key equipment during the airworthiness monitoring cycle, and perform data preprocessing and transformation to obtain the operational failure rate during the cycle; The method is: 3.1) Set an airworthiness monitoring cycle, and then collect the operational data of the above-mentioned key equipment during the airworthiness monitoring cycle, mainly including: total fleet flight time, number of equipment installed, and detailed unplanned replacement records; sort the unplanned replacement intervals in the collected unplanned replacement records, and then use formula (2) and formula (3) to construct the sample quantile statistics. Set a threshold value. If the calculated sample quantile statistic exceeds the threshold value, it is determined to be abnormal data caused by recording errors or extreme cases and is removed to obtain processed operational data. (2); (3); In the formula, This represents the upper quartile value. This represents the lower quartile value. , These represent the outlier statistics for the right and left sides, respectively. 3.2) Using the above-processed operational data, assess the frequency of replacement of key equipment at the operational site; calculate the average unplanned replacement interval (MTBUR) within the airworthiness monitoring cycle using formula (4); (4); In the formula, This indicates the total flight time of the fleet during the airworthiness monitoring period. This indicates the number of units of this critical equipment installed per machine. This indicates the total number of unplanned replacements of the critical equipment during the airworthiness monitoring period. 3.3) Using empirical data correction method to measure the fault-free detection rate Configure settings; No fault detection rate Typically, this data is based on empirical data generated from the service history of systems and equipment, expressed as a percentage; then, formula (5) is used, combined with the fault-free detection rate. The aforementioned Mean Unplanned Replacement Interval (MTBUR) is converted into Mean Time Between Failures (MTBF), which better reflects the inherent reliability of critical equipment. Subsequently, the reciprocal of the MTBF is taken to obtain the operational observation failure rate within the airworthiness monitoring cycle. ; (5); 4) Combining the system safety assessment data obtained in step 1), perform multi-period Bayesian updates on the equipment failure rate to obtain the mean posterior failure rate estimate for each airworthiness monitoring cycle. 5) Substitute the mean posterior failure rate estimates of each key device obtained in step 4) back into the fault tree model obtained in step 1) as new basic event probability input parameters to calculate the real-time failure probability of the top event. Compare this probability with the set system airworthiness safety target value to determine the system airworthiness status. If the comparison result indicates that the system safety no longer meets the airworthiness requirements, the failure contribution importance obtained in step 2) and the operational observation failure rate obtained in step 3) will be combined. Early warning displays are provided to dynamically monitor top and bottom events.

2. The aircraft airworthiness monitoring method based on operational data according to claim 1, characterized in that: In step 1), the method for obtaining system safety assessment data during the aircraft airworthiness certification phase, including information such as fault tree models, reliability data of each device / component, logical relationships of system composition, and basic system description, as well as the initial design reliability data representing each basic event of the device in the fault tree model, is as follows: First, system safety assessment data for a specific aircraft model during the airworthiness certification phase is obtained from the aircraft manufacturer or design department as the initial benchmark for airworthiness monitoring. This system safety assessment data includes information such as fault tree models, reliability data for each device / component, logical relationships within the system, and a basic system description. Simultaneously, initial design reliability data representing the basic events of each device in the fault tree model is obtained, primarily including design failure rates. Design parameters, including those included.

3. The aircraft airworthiness monitoring method based on operational data according to claim 1, characterized in that: In step 2), the method for determining the fault contribution importance of each underlying event in the fault tree model based on the aforementioned system safety assessment data, and then identifying key equipment as key airworthiness monitoring objects based on the fault contribution importance, is as follows: 2.1) Based on the above fault tree model, the occurrence of the top event in the system is taken as a prerequisite; 2.2) Quantitative analysis of the fault tree model was performed, and the fault contribution importance of each bottom event was calculated using formula (1). ; Fault contribution importance refers to the percentage of time a top event has occurred in the system. Under the conditions, the first The bottom line event is also in a state of failure. conditional probability , recorded as To quantify the consequences of system failures, by the first The percentage of failures caused by individual events; (1); In the formula, This represents the top event in the system. This indicates that the top event has occurred; Indicates the first The bottom line event, Indicates the first The bottom-level event occurred; 2.3) All bottom events are ranked according to their contribution to the fault. Sort by size from largest to smallest; 2.4) Select several top-ranked bottom events, or select a set of bottom events whose cumulative fault contribution importance reaches a set threshold, and identify these bottom events as key equipment as key airworthiness monitoring objects, so as to prioritize the allocation of monitoring resources.

4. The aircraft airworthiness monitoring method based on operational data according to claim 1, characterized in that: In step 4), the method for combining the system safety assessment data obtained in step 1) to perform multi-period Bayesian updates on the equipment failure rate and obtain the posterior failure rate estimate mean for each airworthiness monitoring cycle is as follows: 4.1) Assume that the lifespan of the identified critical equipment follows an exponential distribution. According to Bayesian conjugate theory, the equipment failure rate of an exponential distribution... The conjugate prior distribution parameters are gamma distributions. ; In the initial stage of operation, the initial shape parameters of the gamma distribution are set. and scale parameters ; Take the design failure rate obtained in step 1) during the airworthiness certification phase. ; 4.2) For the first During each airworthiness monitoring cycle, failure flight time data of key equipment is collected; let a set of failure flight time data collected be... ,in , This is the total number of failures observed in critical equipment. This is the failure flight time data at the end of the airworthiness monitoring cycle; assuming equipment failure interval time. Then the sample set of equipment failure interval times within this airworthiness monitoring period is: The equipment failure interval time can be calculated using formula (6). The probability density function; (6); In the formula, Equipment failure interval ; Finally, the above-obtained sample set of equipment failure interval times will be used. Substitute into formula (6) to construct the likelihood function of the airworthiness monitoring cycle data; 4.3) According to Bayes' theorem, the prior distribution parameters are multiplied by the above likelihood function and normalized. The equipment failure rate is then calculated using formula (7). The posterior probability density function; based on the properties of the gamma distribution, the equipment failure rate is calculated using formula (8). Mean of posterior loss rate estimate after Bayes update ; Equipment failure rate The formula for calculating the posterior probability density function is as follows: (7); For equipment failure rate It can be seen that its posterior probability density function is still in the form of a gamma distribution, i.e., the equipment failure rate. posterior distribution parameters ; Equipment failure rate The formula for calculating the mean of the posterior failure rate estimate after Bayesian update is as follows: (8); In the formula, , These represent the shape and scale parameters of the gamma distribution, respectively. The initial values ​​are used in the first airworthiness monitoring cycle, and the updated values ​​are used in subsequent airworthiness monitoring cycles. This indicates the total number of equipment failures observed during the airworthiness monitoring period; This represents the sum of the failure intervals of all equipment within the airworthiness monitoring period; 4.4) A rolling update strategy is adopted to adapt to continuous airworthiness monitoring, based on the gamma distribution parameters determined by the design parameters. Using the prior distribution parameters and combining the operational data from the first airworthiness monitoring cycle, the shape parameters for the first airworthiness monitoring cycle are output. and scale parameters and the mean of the posterior failure rate estimate Next, operational data for the second airworthiness monitoring cycle is collected, using the posterior distribution parameters from the first airworthiness monitoring cycle. As the prior distribution parameters for the second airworthiness monitoring cycle, the shape parameters for the second airworthiness monitoring cycle are calculated according to formulas (7) and (8). and scale parameters and the mean of the posterior failure rate estimate Repeat the above operations, using the first... The posterior distribution parameters of the first airworthiness monitoring cycle are used as the first... Prior distribution parameters for each airworthiness monitoring cycle are used to achieve intergenerational data transfer and knowledge accumulation, ultimately obtaining the first... Mean of post-hoc failure efficiency estimate for each airworthiness monitoring cycle .

5. The aircraft airworthiness monitoring method based on operational data according to claim 1, characterized in that: In step 5), the mean posterior failure rate estimate of each key device obtained in step 4) is used as a new basic event probability input parameter and substituted back into the fault tree model obtained in step 1). The real-time failure probability of the top event is calculated and compared with the set system airworthiness safety target value to determine the system airworthiness status. If the comparison result shows that the system safety no longer meets the airworthiness requirements, the failure contribution importance obtained in step 2) and the operational observation failure rate obtained in step 3) will be combined. The method for providing early warnings and dynamically monitoring top and bottom events is as follows: 5.1) The mean of the post-failure efficiency estimates for each key piece of equipment obtained in step 4) during the current airworthiness monitoring cycle. As the new basic event probability input parameter, it is substituted back into the fault tree model obtained in step 1), and the Boolean logic operation of the fault tree model is used to recalculate the real-time failure probability of the top event in the current operating state from bottom to top. ; 5.2) Set the target value for system airworthiness safety Then, the above real-time failure probability Compare with the system's airworthiness safety target value: If If the current airworthiness status of the system is determined to be good, the existing monitoring strategy will be maintained, and the system will automatically enter the next airworthiness monitoring cycle of operational data collection and monitoring. 5.3) If If the system safety no longer meets the airworthiness requirements, the system-level early warning mechanism is immediately triggered; combined with the fault contribution importance obtained in step 2), the cause analysis is performed, the top event status of the fault tree model is highlighted on the system interface, and the list of main causes that lead to increased risk is marked. Based on the key airworthiness monitoring targets identified in step 2), and combined with the latest real-time failure probabilities calculated in 5.1, the actual operational failure rates observed are screened and displayed. The key airworthiness monitoring object is significantly higher than the design expectation and contributes the most to the current system failure probability, thus leading to a decline in the overall safety level of the system.