Civil aircraft airborne software delivery-to-host process design method

By breaking down the civil aircraft onboard software loading process into loading drive, preparation, implementation, verification, and recording, the system solves the error problem caused by unsystematic loading process, ensuring the integrity and correctness of the loading process, and improving loading efficiency and flight safety.

CN121786812APending Publication Date: 2026-04-03AVIC GENERAL HUANAN AIRCRAFT IND CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-19
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

In the existing technology, the loading process of airborne software for civil aircraft lacks a systematic process design, which leads to frequent loading errors and affects flight safety.

Method used

Design a process for the modification of airborne software for civil aircraft after delivery to the host, which is divided into sub-processes such as loading drive, pre-loading preparation, loading implementation, loading verification, and loading recording. The procedures and activities of each sub-process are clearly defined to ensure the integrity and correctness of the loading process.

Benefits of technology

By designing detailed processes, we can ensure the correctness, timeliness, and controllability of the loading process, reduce loading errors, improve loading efficiency, and minimize the impact on flight safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121786812A_ABST
    Figure CN121786812A_ABST
Patent Text Reader

Abstract

The invention provides a method for designing a penetration and modification process after civil aircraft airborne software is delivered to a host. According to the method, a set of rigorous work flow is provided for loading after airborne equipment software is delivered according to loading drive, preparation and inspection before loading implementation, loading implementation, loading verification, loading recording and management and control flow requirements and activity requirements in the loading completion process after civil aircraft airborne software is delivered to a host; activity and rules which should be followed in the loading process are completely planned, wrong software configuration items are prevented from being loaded, and the loading process is prevented from being out of control. A set of perfect and executable control program is provided for loading after the civil aircraft airborne software is delivered, it is guaranteed that software loading is correct, complete and controlled, and powerful guarantee is provided for flight safety of civil aircrafts.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of civil aircraft airborne software loading management, and relates to a design method for the process modification of civil aircraft airborne software after delivery to the host. Background Technology

[0002] With the rapid development of computer technology and the increasing integration of civil aircraft, airborne software, as the most fundamental design element of an aircraft, is being used more extensively in critical systems such as flight control, hydraulics, display and control, communication and navigation, mission control, fuel, and power. The performance of airborne software has an increasingly significant impact on aircraft safety. The increasing functionality of airborne software has led to a higher frequency of changes. Loading incorrect software can, at best, affect aircraft functionality, and at worst, compromise flight safety. Therefore, the correctness and completeness of the software loading process are paramount. To meet the safety requirements of airborne software, a high-quality software loading process has become a fundamental requirement for ensuring flight safety. Summary of the Invention

[0003] This invention proposes a process design method for the post-delivery modification of airborne software for civil aircraft. Based on the necessary procedures and activities required in the loading process, the loading process is subdivided into loading-driven, pre-loading preparation, loading implementation, loading verification, loading recording, and loading completion sub-processes, clearly defining the procedures, activities, criteria, and outputs for each sub-process. This provides an efficient process for the post-delivery loading of airborne hardware and software, offering clear guidance for the activities during the loading process.

[0004] Purpose of the invention

[0005] While simplifying the loading process, it effectively ensures the integrity and correctness of the loading of airborne software and hardware for civil aircraft, avoids loading errors after software delivery, and greatly reduces post-delivery loading costs.

[0006] The impact of the load on flight safety.

[0007] Technical solution

[0008] A method for designing a process for the modification of airborne software after delivery to the host computer for civil aircraft is proposed. Based on the requirements for loading driver, pre-loading preparation and inspection, loading implementation, loading verification, loading recording, and control processes and activities during the loading completion process after the airborne software is delivered to the host computer, the following steps are taken: First, the airborne software loading process for civil aircraft is confirmed. Then, the relevant procedures for the airborne software loading driver subprocess are confirmed. The pre-loading preparation procedures for civil aircraft airborne software are determined. Then, the airborne software loading implementation process procedures are determined. The airborne software loading verification process procedures are determined. Finally, the airborne software loading recording process procedures are determined.

[0009] Further, specific steps include:

[0010] Step 1: Confirm the airborne software loading process for civil aircraft. Based on the different activities, inputs, and outputs of each stage in the loading process, the loading process is subdivided into loading drive, pre-loading preparation, loading implementation, loading verification, loading recording, and loading completion sub-processes.

[0011] Step Two: Confirm the relevant procedures for the civil aircraft's onboard software loading driver sub-process. Identify different loading driver process flows and activities based on the different post-delivery driver loading scenarios;

[0012] Step 3: Determine the preparation procedures before loading airborne software for civil aircraft. Based on the different responsibilities of each specialty, fully identify the preparation processes and activity requirements for each specialty before software loading.

[0013] Step 4: Determine the onboard software loading implementation process. Based on the host's requirements for boarding operation management, identify the onboard loading implementation process activities and the host monitoring process and activities.

[0014] Step 5: Determine the airborne software loading and verification process. Based on the civil airborne software delivery loading and verification control requirements and the loading and verification requirements in the loading driver, identify the verification procedures and activities after loading.

[0015] Step Six: Determine the airborne software loading record process procedure. Based on the airworthiness and main structure management requirements of civil aircraft, identify the loading implementation record requirements, loading verification record process, and activity requirements.

[0016] Furthermore, the aforementioned post-delivery software loading driver exists in two scenarios: one is that software design changes trigger the onboard software loading after delivery, and the other is that a fault directly drives the software loading.

[0017] Furthermore, the preparatory activities for each discipline before software loading include the supplier preparing the executable target code of the software to be loaded, the supplier and the host preparing loading process instructions, coordinating and determining the loading work plan, and handling the application procedures for loading.

[0018] Furthermore, the host computer's requirements for boarding operations management include: processing boarding procedures before boarding; monitoring boarding personnel and their belongings according to approved application procedures; loading software according to approved instructions after boarding; and monitoring the loading process according to quality assurance requirements to ensure that the loading process is under control.

[0019] Furthermore, the aforementioned requirements for post-delivery loading verification and control of civilian airborne software include ensuring the correctness and integrity of the software loaded on board.

[0020] Furthermore, the civil aircraft loading record for the civil airborne software includes the loading application, process instructions, loading plan, onboard application, boarding record, loading and verification record, update logbook, and, when necessary, the recording of loading process failures.

[0021] Furthermore, a type of airborne software for civil aircraft adopts the aforementioned post-delivery host modification process design method for software management.

[0022] The beneficial effects of this application are as follows:

[0023] Traditional loading processes, including design changes and field faults, are managed independently. The loading driver and the loading trigger are disconnected, resulting in loose control over the loading process. For example, critical processes such as loading driver implementation, onboarding procedures, and the qualifications of loading personnel lack oversight. These deficiencies in the loading process lead to redundancy in loading procedures and documents, untimely loading, loading of incorrect hardware and software configuration items, and the risk of uncontrolled aircraft hardware and software configurations, posing a threat to flight safety.

[0024] Compared with the traditional loading process, the present invention has the following advantages:

[0025] 1) The loading process is correct and traceable.

[0026] This invention meticulously plans the goals, activities, data, and transition criteria for each loading process and subprocess. Only after meeting the transition criteria can the next subprocess proceed smoothly, avoiding redundant processes and ensuring no necessary process control is overlooked. Seamless integration between processes and complete process logging guarantee the accuracy and traceability of the loading process.

[0027] 3) Ensure timely loading

[0028] The loading driver and loading implementation are strongly correlated. Before loading is implemented, the loading driver state is always in an open state to avoid missing or delaying loading activities and ensure timely loading.

[0029] 4) Ensure the loading process is controlled

[0030] Key loading sub-processes are assigned on-site monitoring roles to oversee the implementation of related activities. The output records of the loading sub-processes are periodically or triggered afterward for quality review to ensure the loading process is under control.

[0031] 5) Ensure the integrity of records related to the loading process.

[0032] Loading records are a necessary condition for each loading process to proceed, ensuring the integrity of the loading process records.

[0033] 6) Ensure that problems during the loading process are tracked and resolved.

[0034] If a problem occurs during the loading process, the loading driver will not be able to close the loop, and relevant professionals must continuously track and resolve the loading problem to ensure that the loading process issues are tracked and resolved.

[0035] 7) Reduce processes and process documents to improve loading efficiency.

[0036] By merging loading drivers and change processes, the number of process documents is reduced, and work efficiency is improved.

[0037] This invention is applicable not only to the management of onboard software and hardware loading in civil aircraft, but also to the management of software and hardware loading in highly complex electronic industries such as military aircraft, drones, and automobiles. Attached Figure Description

[0038] Figure 1 This is a flowchart of the process for modifying the onboard software of a civil aircraft after delivery to the host computer, provided by the present invention. Detailed Implementation

[0039] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0040] The features and illustrative embodiments of various aspects of the present invention will now be described in detail. In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the invention. However, it will be apparent to those skilled in the art that the invention may be practiced without requiring some of these specific details. The following description of embodiments is merely intended to provide a better understanding of the invention by illustrating examples of the invention. The invention is by no means limited to any specific setup and method set forth below, but covers any improvements, substitutions, and modifications to the structures, methods, and devices without departing from the spirit of the invention. In the following description, well-known structures and techniques are not shown to avoid unnecessarily obscuring the invention.

[0041] In the description of this invention, it should be noted that the directions or positional relationships indicated by terms such as "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer" are based on the stated directions or positional relationships and are only for the convenience of describing and simplifying the invention, and should not be construed as limiting the invention. Furthermore, the use of ordinal numbers (e.g., "first and second," etc.) is for distinguishing objects and is not limited to this order, and should not be construed as indicating or implying relative importance.

[0042] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly, encompassing both direct connection and indirect connection via an intermediate medium. Those skilled in the art can understand the specific meaning of these terms in this invention based on the specific circumstances.

[0043] It should be noted that, unless otherwise specified, the embodiments of the present invention and the features thereof can be combined with each other, and the various embodiments can be referenced and cited in each other. The present invention will now be described in detail with reference to and in conjunction with the embodiments.

[0044] The basic idea of ​​this invention is:

[0045] 1) Considering different scenarios that trigger loading, two loading drivers were designed for scenarios of software design change-triggered loading and fault-triggered software loading;

[0046] 2) Considering the readiness state that the aircraft and various specialties should achieve before software loading, a preparatory procedure for software loading was designed.

[0047] 3) Considering the control requirements of the airborne software loading implementation process, a software loading implementation preparation procedure was designed;

[0048] 4) Considering the impact of the integrity and correctness of airborne software loading on flight safety, a preparation procedure for the software loading verification process was designed.

[0049] 5) Considering the requirements for airworthiness and main structure management records of civil aircraft, a loading process recording activity was designed.

[0050] This invention first clarifies the basic requirements for the post-delivery loading management of airborne software for civil aircraft. Based on this, and combined with the control requirements of the host unit during the software modification process, it aims to reduce manual workload while preventing the loading process from spiraling out of control. The specific steps of the post-delivery modification process design method for airborne software for civil aircraft provided by this invention are as follows:

[0051] Step 1: Determine the basic requirements for the management of onboard software for civil aircraft. Based on the airworthiness standards for civil aircraft, identify the basic requirements for software loading management.

[0052] For example, as required in DO-178B:

[0053] Onboard software delivery and loading should include:

[0054] Take security measures to ensure that executable object code is correctly loaded into aircraft systems or equipment;

[0055] A record of software compatibility with airborne equipment or systems should be maintained.

[0056] Step Two: Based on the control requirements during the software implementation process of the host unit, identify the post-delivery loading requirements for civil aircraft software:

[0057] For example:

[0058] The instructions require;

[0059] Preparations before boarding;

[0060] Control of the computer lab process;

[0061] Verify after loading.

[0062] Step 3: Ensure the loading process is under control;

[0063] For example, such as:

[0064] Loading process monitoring requirements.

[0065] This invention provides a method for designing a post-delivery modification process for airborne software in civil aircraft. This method can accurately and efficiently manage the loading of airborne software after delivery, ensuring the accuracy and integrity of the loading process, and guaranteeing the airworthiness of the airborne software, thereby greatly improving the safety and reliability of the aircraft.

[0066] See Figure 1 This is a flowchart of the process for modifying civil aircraft-borne software after delivery to the host computer, provided by the present invention.

[0067] The loading driver explicitly specifies the software part number, version, and loading verification requirements.

[0068] The loading of airborne software is completed through loading implementation and loading verification to ensure the integrity and correctness of the loading process.

[0069] By loading records, necessary evidence demonstrating compliance is provided for the airworthiness review of civil aircraft.

[0070] The steps of the method provided by this invention are as follows:

[0071] (1) Determine the airworthiness requirements for civil aircraft after delivery;

[0072] (2) Determine the processes and activities involved in different loading scenarios after delivery;

[0073] (3) Determine the host requirements after delivery.

[0074] The above detailed embodiments are a description of the present invention. It should not be considered that the specific embodiments of the present invention are limited to these descriptions. For those skilled in the art, several simple deductions and substitutions can be made without departing from the concept of the present invention, and all of these should be considered to fall within the protection scope of the present invention.

Claims

1. A method for designing a post-delivery modification process for airborne software in civil aircraft, characterized in that, Based on the requirements of the loading process and activities during the delivery of airborne software to the host, including loading driver, pre-loading preparation and inspection, loading implementation, loading verification, loading recording, and control process during loading completion, the airborne software loading process for civil aircraft is first confirmed. The relevant procedures for the airborne software loading driver sub-process are confirmed, the pre-loading preparation procedures for civil aircraft airborne software are determined, the airborne software loading implementation process procedures are then determined, the airborne software loading verification process procedures are determined, and finally the airborne software loading recording process procedures are determined.

2. The method as described in claim 1, characterized in that, The specific steps include: Step 1: Confirm the civil aircraft airborne software loading process; based on the different activities, inputs, and outputs of each step in the loading process, the loading process is subdivided into loading drive, pre-loading preparation, loading implementation, loading verification, loading recording, and loading completion sub-processes; Step 2: Confirm the relevant procedures for the civil aircraft airborne software loading driver sub-process; identify different loading driver process flows and activities based on different post-delivery loading driver scenarios; Step 3: Determine the preparation procedures before loading airborne software for civil aircraft; based on the different responsibilities of each specialty, fully identify the preparation processes and activity requirements for each specialty before software loading; Step 4: Determine the onboard software loading and implementation process. Based on the host's requirements for boarding operations management, identify the onboard loading and implementation process activities and the host monitoring process and activities. Step 5: Determine the airborne software loading and verification process. Based on the civil airborne software delivery loading and verification control requirements and the loading and verification requirements in the loading driver, identify the verification procedures and activities after loading. Step Six: Determine the airborne software loading record process procedure. Based on the airworthiness and main structure management requirements of civil aircraft, identify the loading implementation record requirements, loading verification record process, and activity requirements.

3. The method as described in claim 2, characterized in that, There are two scenarios for the post-delivery software loading driver: one is that software design changes trigger the onboard software loading after delivery, and the other is that a fault directly drives the software loading.

4. The method as described in claim 2, characterized in that, The preparatory activities for each discipline before software loading include the supplier preparing the executable target code of the software to be loaded, both the supplier and the host preparing loading process instructions, coordinating and determining the loading work plan, and handling the application procedures for machine loading.

5. The method as described in claim 2, characterized in that, The host computer's requirements for boarding operations management include: handling boarding procedures before boarding; monitoring boarding personnel and their belongings according to approved application procedures; loading software according to approved instructions after boarding; and monitoring the loading process according to quality assurance requirements to ensure that the loading process is under control.

6. The method as described in claim 2, characterized in that, The aforementioned requirements for post-delivery verification and control of civilian airborne software include ensuring the correctness and completeness of the software loaded on board.

7. The method as described in claim 2, characterized in that, The civil airborne software civil aircraft loading record includes loading applications, process instructions, loading plans, onboard applications, boarding records, loading and verification records, update logbooks, and, when necessary, records of loading process failures generated during the loading process.

8. A type of airborne software for civil aircraft, characterized in that, The software management adopts the post-delivery modification process design method as described in any one of claims 1-7.