Conformance verification method for CCAR-25 aircraft-oriented integrated modular avionics platform

By adopting a four-level verification system and a hardware-level partitioning and isolation strategy, the hardware and software issues of the IMA platform in the CCAR-25 airworthiness requirements were resolved, thereby improving safety and airworthiness and simplifying the airworthiness review process.

CN122018480APending Publication Date: 2026-05-12CHINESE AERONAUTICAL RADIO ELECTRONICS RES INST
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINESE AERONAUTICAL RADIO ELECTRONICS RES INST
Filing Date
2025-12-27
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

The existing IMA platform, when adapting to the CCAR-25 airworthiness requirements, has several issues: the hardware architecture does not comply with the ARINC653 partition specifications, the software is deeply coupled, resulting in high maintenance costs, incomplete compliance verification, and it cannot pass airworthiness reviews, and there are potential flight safety hazards.

Method used

A conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft is designed, employing a four-level verification system, including configuration integration testing, pathway testing, platform service testing, and robustness testing. Combining the ARINC653 specification and ARINC615A protocol, hardware-level and partition-level isolation is achieved, forming a closed-loop mechanism.

Benefits of technology

It has achieved full-process airworthiness compliance for the IMA platform, reduced the risk of system failure, improved the safety of avionics operation, simplified the airworthiness review process, reduced maintenance costs, and provided technical reference for the development of similar aircraft platforms in the future.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122018480A_ABST
    Figure CN122018480A_ABST
Patent Text Reader

Abstract

The invention provides a CCAR-25 aircraft-oriented comprehensive modular avionics platform conformity verification method, which comprises the following steps of: accessing a modular hardware platform architecture into a system integration verification platform, and carrying out hardware cross-linking and software deployment; testing is executed step by step according to a configuration integration testing-path testing-platform service testing-robustness testing four-level conformity verification system, and testing results are recorded; s2, judging whether all the test results pass or not, if the test results do not pass, issuing a problem report according to a quality problem processing method, performing targeted optimization according to a root cause analysis result, and executing S2 again; if all the test data and the problem return-to-zero report pass, verifying the closed loop to form a verification document containing the test data and the problem return-to-zero report. The compatibility and maintainability of the system are improved through modular design, the requirement of airworthiness clauses is ensured to be met through a full-dimension verification system, and the method is suitable for the design and airworthiness verification process of a CCAR-25 transportation type aircraft comprehensive modular avionics platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of integrated avionics technology, specifically relating to a conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft. Background Technology

[0002] As civil aviation demands for aircraft safety, economy, and maintainability continue to rise, avionics systems have evolved from a traditional discrete architecture with one-to-one correspondence between functions and hardware to an integrated, modular (IMA) platform architecture. While the IMA platform achieves resource sharing by integrating multiple avionics functions through standardized hardware modules, becoming the mainstream development direction for avionics systems of this type of aircraft, key technological barriers still exist when adapting to the stringent airworthiness requirements of CCAR-25.

[0003] At the hardware architecture level, core processing units often integrate only 1-2 general-purpose processing modules and fail to implement resource isolation in accordance with the ARINC 653 partitioning specification. Alternatively, the module functional divisions may not match the real-time requirements of different avionics applications, making critical applications susceptible to interference. At the software level, configuration and operational functions are deeply coupled, with no clear distinction between the configuration and operational software layers. This necessitates a complete software system refactoring when hardware modules are replaced or parameters are adjusted, significantly extending maintenance cycles and increasing maintenance costs. Furthermore, many systems employ custom loading protocols, which are incompatible with the ARINC 615A avionics software loading standard, resulting in poor compatibility with airborne maintenance systems and ground support equipment. Regarding compliance verification, a complete compliance verification system is lacking, verification coverage is incomplete, and a closed-loop mechanism is not established when tests fail, leading to recurring issues. These deficiencies directly cause existing IMA platforms to fail CCAR-25 airworthiness reviews. Domestically developed CCAR-25 category aircraft are highly dependent on imported IMA platforms, experience long system upgrade cycles, and pose flight safety hazards in extreme environments.

[0004] Therefore, there is an urgent need for an IMA platform conformity verification method that accurately matches the CCAR-25 airworthiness requirements and can solve the above-mentioned technical problems, so as to support the independent research and development and airworthiness certification of the avionics system of this type of aircraft. Summary of the Invention

[0005] This invention provides a conformity verification method for an integrated modular avionics platform (IMA) for CCAR-25 aircraft, ensuring that the IMA platform meets the requirements of CCAR-25 for system redundancy, reliability, environmental adaptability, and verification traceability, and supporting the independent research and development and airworthiness certification of avionics systems for transport-type civil aircraft.

[0006] This invention provides a conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft, comprising: S1. Integrate the modular hardware platform architecture into the system integration and verification platform to perform hardware cross-linking and software deployment; The modular hardware platform architecture includes: a first core processing unit, a second core processing unit, a first remote data interface unit, a second remote data interface unit, a third remote data interface unit, a fourth remote data interface unit, a first external switch, and a second external switch; S2. Perform tests step by step according to the four-level compliance verification system of configuration integration test, path test, platform service test, and robustness test, and record the test results. Among them, configuration integration testing is used to verify the compliance of partitioned scheduling, the correctness of data conversion logic, and ARINC664 network connectivity; path testing is used to verify the correctness of end-to-end data transmission; platform service testing is used to verify the reliability of the core management services of the integrated modular avionics platform; and robustness testing is used to verify the system stability and environmental adaptability under extreme scenarios. S3. Determine whether all test results pass. If any test results fail, issue a problem report according to the quality problem handling procedure, perform targeted optimization based on the root cause analysis results, and execute S2 again. If all results pass, verify the closed loop and generate a verification document containing test data and a problem-resolved report.

[0007] Optionally, the core processing unit integrates a first general-purpose processing module, a second general-purpose processing module, a third general-purpose processing module, and a fourth general-purpose processing module. The first general-purpose processing module, the second general-purpose processing module, the third general-purpose processing module, and the fourth general-purpose processing module are equipped with programmable logic, an ARINC664 network terminal system, and initial boot software, supporting partitioned computing according to the ARINC653 specification, and allocating independent operating resources for resident applications.

[0008] Optionally, the first general-purpose processing module hosts Level 1 avionics application software; the second general-purpose processing module hosts Level 2 avionics application software; the third general-purpose processing module hosts Level 3 avionics application software; and the fourth general-purpose processing module hosts Level 4 avionics application software.

[0009] Optionally, the Level 1, Level 2, Level 3, and Level 4 avionics application software are divided according to the development and support levels of different avionics applications, so as to achieve hardware-level isolation between different general-purpose processing modules for avionics application software of different development and support levels, and partition-level isolation of avionics application software of the same development and support level on the same general-purpose processing module.

[0010] Optionally, the modular software architecture adapted to the modular hardware platform architecture includes a configuration software layer and an operating software layer.

[0011] Optionally, the configuration software layer includes core processing unit configuration software, remote data interface unit configuration software, and external switch configuration software, which are used to define hardware interface mapping rules, data conversion logic, and ARINC664 network communication parameters. The operating software layer includes the core processing unit operating software, the remote data interface unit operating software, and the external switch operating software, which are used to implement data calculation, data conversion, and data transmission functions.

[0012] Optionally, the remote data interface unit is equipped with programmable logic and an ARINC664 network terminal system, providing bidirectional conversion capabilities for ARINC429, ARINC664, ARINC717, discrete and analog data.

[0013] Optionally, the modular hardware platform architecture can be integrated into the system integration and verification platform for hardware interconnection and software deployment, including: The first core processing unit, the second core processing unit, the first remote data interface unit, the second remote data interface unit, the third remote data interface unit, the fourth remote data interface unit, the first external switch, and the second external switch are connected to the system integration verification platform. The core processing unit configuration software and core processing unit operation software are loaded into the first core processing unit and the second core processing unit via the ARINC615A protocol; The remote data interface unit configuration software and remote data interface unit operation software are loaded into the first remote data interface unit, the second remote data interface unit, the third remote data interface unit, and the fourth remote data interface unit via the ARINC615A protocol. The configuration software and operation software of the external switch are loaded into the first external switch and the second external switch via the ARINC615A protocol.

[0014] The beneficial effects of this invention compared to the prior art are as follows: 1. This invention designs and develops a compliance verification method for an integrated modular avionics platform for CCAR-25 aircraft. It innovatively designs a four-level verification system of "configuration integration - pathway - platform service - robustness", covering basic functions, data transmission, core services and extreme scenarios, forming a closed loop of airworthiness compliance from hardware architecture to testing and verification.

[0015] 2. In this invention, the core processing unit implements the strategy of "hardware-level isolation for applications of different development and support levels and partition-level isolation for applications of the same level" through the ARINC653 partition design of four general processing modules, and builds a dual fault barrier from hardware to partition to prevent the spread of low-level application faults to critical high-level applications; the synergy of redundant hardware and modular software can also realize automatic fault switching and rapid fault location, significantly reduce the risk of system paralysis, and improve the safety of avionics operation.

[0016] 3. In this invention, the closed-loop mechanism of "testing-problem analysis-optimization-secondary verification" can accurately solve testing problems and generate a problem-zeroing report. The final output test data and verification documents can directly support airworthiness review, reducing the difficulty of certification. At the same time, the hardware architecture, software layering, and isolation strategy of this design are universal and can provide technical reference for the development of integrated modular avionics platforms for similar CCAR-25 aircraft, improving the technology reuse rate and the efficiency of results transformation. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. The drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This invention provides a design architecture diagram for an integrated modular avionics platform for CCAR-25 aircraft.

[0019] Figure 2 This invention provides a conformity verification of an integrated modular avionics platform for CCAR-25 aircraft. Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] The features and illustrative embodiments of various aspects of the present invention will now be described in detail. Numerous specific details are set forth in the following detailed description to provide a thorough understanding of the invention. However, it will be apparent to those skilled in the art that the invention may be practiced without requiring some of these specific details. The following description of embodiments is merely intended to provide a better understanding of the invention by illustrating examples of the invention. The invention is by no means limited to any specific setups and methods set forth below, but covers any improvements, substitutions, and modifications to structures, methods, and devices without departing from the spirit of the invention. Well-known structures and techniques are not shown in the drawings and the following description to avoid unnecessarily obscuring the invention.

[0022] In the description of this invention, it should be noted that the directions or positional relationships indicated by terms such as "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer" are based on the directions or positional relationships shown in the accompanying drawings and are only for the convenience of describing and simplifying the invention, and should not be construed as limiting the invention. Furthermore, the use of ordinal numbers (e.g., "first and second," etc.) is for distinguishing objects and is not limited to this order, and should not be construed as indicating or implying relative importance.

[0023] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly, encompassing both direct connection and indirect connection via an intermediate medium. Those skilled in the art can understand the specific meaning of these terms in this invention based on the specific circumstances.

[0024] It should be noted that, unless otherwise specified, the embodiments of the present invention and the features thereof can be combined with each other, and the various embodiments can be referenced and cited in each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0025] The present invention will be further described in detail below with reference to the embodiments and accompanying drawings, but the embodiments of the present invention are not limited thereto.

[0026] This invention provides a conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft, comprising the following steps: Step 1: Based on the CCAR-25 requirements for redundancy and reliability of integrated modular avionics systems, a modular hardware platform architecture is constructed, consisting of a first core processing unit, a second core processing unit, a first remote data interface unit, a second remote data interface unit, a third remote data interface unit, a fourth remote data interface unit, a first external switch, and a second external switch. Step Two: Develop a modular software architecture adapted to the hardware architecture, including a configuration software layer and an operation software layer; where: The configuration software layer includes core processing unit configuration software, remote data interface unit configuration software, and external switch configuration software, which are used to define hardware interface mapping rules, data conversion logic, and ARINC664 network communication parameters. The operating software layer includes the core processing unit operating software, the remote data interface unit operating software, and the external switch operating software, which are used to implement data calculation functions, data conversion functions, and data transmission functions. Step 3: Based on the system integration verification platform, design a four-level compliance verification system: configuration integration testing, path testing, platform service testing, and robustness testing. Configuration integration testing verifies the compliance of partitioned scheduling, the correctness of data conversion logic, and ARINC664 network connectivity; path testing verifies the correctness of end-to-end data transmission; platform service testing verifies the reliability of the core management services of the integrated modular avionics platform; and robustness testing verifies system stability and environmental adaptability under extreme scenarios.

[0027] Step 4: Set up the test environment and perform hardware interconnection and software deployment. Connect the first core processing unit, the second core processing unit, the first remote data interface unit, the second remote data interface unit, the third remote data interface unit, the fourth remote data interface unit, the first external switch, and the second external switch to the system integration verification platform; load the core processing unit configuration software and core processing unit operation software into the first core processing unit and the second core processing unit via the ARINC615A protocol; load the remote data interface unit configuration software and remote data interface unit operation software into the first remote data interface unit, the second remote data interface unit, the third remote data interface unit, and the fourth remote data interface unit via the ARINC615A protocol; load the external switch configuration software and external switch operation software into the first external switch and the second external switch via the ARINC615A protocol. Step 5: Perform tests step by step according to the four-level compliance verification system of configuration integration test, path test, platform service test, and robustness test, and record the test results.

[0028] Step Six: Determine if all test results pass. If any test results fail, issue a problem report according to the quality problem handling procedure, perform targeted optimization based on the root cause analysis results, and re-enter Step Four. If all test results pass, verify the closed loop and generate a verification document containing test data and a problem-resolved report.

[0029] Optionally, the core processing unit integrates a first general-purpose processing module, a second general-purpose processing module, a third general-purpose processing module, and a fourth general-purpose processing module. The first general-purpose processing module, the second general-purpose processing module, the third general-purpose processing module, and the fourth general-purpose processing module are equipped with programmable logic, an ARINC664 network terminal system, and initial boot software, supporting partitioned computing according to the ARINC653 specification, and allocating independent operating resources for resident applications.

[0030] Optionally, the remote data interface unit is equipped with programmable logic and an ARINC664 network terminal system, providing bidirectional conversion capabilities for ARINC429, ARINC664, ARINC717, discrete and analog data.

[0031] Optionally, Level 1 avionics application software resides on the first general-purpose processing module; Level 2 avionics application software resides on the second general-purpose processing module; Level 3 avionics application software resides on the third general-purpose processing module; and Level 4 avionics application software resides on the fourth general-purpose processing module.

[0032] Optionally, Level 1, Level 2, Level 3, and Level 4 avionics application software are classified according to the development and support levels of different avionics applications, so as to achieve hardware-level isolation between different general-purpose processing modules for avionics application software of different development and support levels, and partition-level isolation of avionics application software of the same development and support level on the same general-purpose processing module.

[0033] See Figure 1 As shown, this embodiment provides a conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft, comprising the following steps: Step 1: Based on the CCAR-25 requirements for redundancy and reliability of integrated modular avionics systems, a modular hardware platform architecture is constructed, consisting of a first core processing unit, a second core processing unit, a first remote data interface unit, a second remote data interface unit, a third remote data interface unit, a fourth remote data interface unit, a first external switch, and a second external switch. The core processing unit integrates a first, second, third, and fourth general-purpose processing module. These modules are equipped with programmable logic, an ARINC664 network interface system, and initial boot software, supporting ARINC653-compliant partitioned computing and allocating independent operating resources for resident applications. The remote data interface unit, also equipped with programmable logic and an ARINC664 network interface system, provides bidirectional conversion capabilities between ARINC429, ARINC664, ARINC717, discrete, and analog data. An external switch provides data transmission capabilities based on the ARINC664 protocol.

[0034] The first general-purpose processing module hosts Level 1 avionics application software (main flight control software); the second general-purpose processing module hosts Level 2 avionics application software (crew alarm software); the third general-purpose processing module hosts Level 3 avionics application software (emergency communication management software); and the fourth general-purpose processing module hosts Level 4 avionics application software (airborne maintenance software).

[0035] The Level 1 avionics application software (main flight control software), Level 2 avionics application software (crew alarm software), Level 3 avionics application software (emergency communication management software), and Level 4 avionics application software (airborne maintenance software) are classified according to the development support levels of avionics applications DALA, B, C, and D. This achieves hardware-level isolation between different general-purpose processing modules for avionics application software of different development support levels, and partition-level isolation within the same general-purpose processing module for avionics application software of the same development support level.

[0036] Step Two: Develop a modular software architecture adapted to the hardware architecture, including a configuration software layer and an operation software layer; where: The configuration software layer includes core processing unit configuration software, remote data interface unit configuration software, and external switch configuration software, which are used to define hardware interface mapping rules, data conversion logic, and ARINC664 network communication parameters; the operation software layer includes core processing unit operation software, remote data interface unit operation software, and external switch operation software, which are used to implement data calculation functions, data conversion functions, and data transmission functions. Step 3: Based on the system integration verification platform, design a four-level compliance verification system: configuration integration testing, path testing, platform service testing, and robustness testing. Configuration integration testing verifies the compliance of partitioned scheduling, the correctness of data conversion logic, and ARINC664 network connectivity; path testing verifies the correctness of end-to-end data transmission; platform service testing verifies the reliability of the core management services of the integrated modular avionics platform; and robustness testing verifies system stability and environmental adaptability under extreme scenarios.

[0037] Step 4: Set up the test environment and perform hardware interconnection and software deployment. Connect the first core processing unit, the second core processing unit, the first remote data interface unit, the second remote data interface unit, the third remote data interface unit, the fourth remote data interface unit, the first external switch, and the second external switch to the system integration verification platform; load the core processing unit configuration software and core processing unit operation software into the first core processing unit and the second core processing unit via the ARINC615A protocol; load the remote data interface unit configuration software and remote data interface unit operation software into the first remote data interface unit, the second remote data interface unit, the third remote data interface unit, and the fourth remote data interface unit via the ARINC615A protocol; load the external switch configuration software and external switch operation software into the first external switch and the second external switch via the ARINC615A protocol. Step 5: Perform tests step by step according to the four-level compliance verification system of configuration integration test, path test, platform service test, and robustness test, and record the test results.

[0038]

[0039] Step Six: All test results pass, the verification loop is closed, and a verification document containing test data and a problem-resolved report is generated.

[0040] The above detailed embodiments are a description of the present invention. It should not be considered that the specific embodiments of the present invention are limited to these descriptions. For those skilled in the art, several simple deductions and substitutions can be made without departing from the concept of the present invention, and all of these should be considered to fall within the protection scope of the present invention.

Claims

1. A conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft, characterized in that, include: S1. Integrate the modular hardware platform architecture into the system integration and verification platform to perform hardware cross-linking and software deployment; The modular hardware platform architecture includes: a first core processing unit, a second core processing unit, a first remote data interface unit, a second remote data interface unit, a third remote data interface unit, a fourth remote data interface unit, a first external switch, and a second external switch; S2. Perform tests step by step according to the four-level compliance verification system of configuration integration test, path test, platform service test, and robustness test, and record the test results. Among them, configuration integration testing is used to verify the compliance of partitioned scheduling, the correctness of data conversion logic, and ARINC664 network connectivity; path testing is used to verify the correctness of end-to-end data transmission; platform service testing is used to verify the reliability of the core management services of the integrated modular avionics platform; and robustness testing is used to verify the system stability and environmental adaptability under extreme scenarios. S3. Determine whether all test results pass. If any test results fail, issue a problem report according to the quality problem handling procedure, perform targeted optimization based on the root cause analysis results, and execute S2 again. If all results pass, verify the closed loop and generate a verification document containing test data and a problem-resolved report.

2. The conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft according to claim 1, characterized in that, The core processing unit integrates a first general-purpose processing module, a second general-purpose processing module, a third general-purpose processing module, and a fourth general-purpose processing module. The first, second, third, and fourth general-purpose processing modules are equipped with programmable logic, an ARINC664 network terminal system, and initial boot software, supporting partitioned computing according to the ARINC653 specification and allocating independent operating resources for resident applications.

3. The conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft according to claim 2, characterized in that, Level 1 avionics application software resides on the first general-purpose processing module; Level 2 avionics application software resides on the second general-purpose processing module; Level 3 avionics application software resides on the third general-purpose processing module; and Level 4 avionics application software resides on the fourth general-purpose processing module.

4. The conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft according to claim 3, characterized in that, The Level 1, Level 2, Level 3, and Level 4 avionics application software are classified according to the development and support levels of different avionics applications. This achieves hardware-level isolation between different general-purpose processing modules for avionics application software of different development and support levels, and partition-level isolation for avionics application software of the same development and support level on the same general-purpose processing module.

5. The conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft according to claim 1, characterized in that, The modular software system adapted to the modular hardware platform architecture includes a configuration software layer and an operating software layer.

6. The conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft according to claim 5, characterized in that, The configuration software layer includes core processing unit configuration software, remote data interface unit configuration software, and external switch configuration software, which are used to define hardware interface mapping rules, data conversion logic, and ARINC664 network communication parameters. The operating software layer includes the core processing unit operating software, the remote data interface unit operating software, and the external switch operating software, which are used to implement data calculation, data conversion, and data transmission functions.

7. The conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft according to claim 1, characterized in that, The remote data interface unit is equipped with programmable logic and ARINC664 network terminal system, providing bidirectional conversion capability for ARINC429, ARINC664, ARINC717, discrete and analog data.

8. The conformity verification method for an integrated modular avionics platform for CCAR-25 aircraft according to claim 1, characterized in that, Integrating the modular hardware platform architecture into the system integration and verification platform enables hardware interconnection and software deployment, including: The first core processing unit, the second core processing unit, the first remote data interface unit, the second remote data interface unit, the third remote data interface unit, the fourth remote data interface unit, the first external switch, and the second external switch are connected to the system integration verification platform. The core processing unit configuration software and core processing unit operation software are loaded into the first core processing unit and the second core processing unit via the ARINC615A protocol; The remote data interface unit configuration software and remote data interface unit operation software are loaded into the first remote data interface unit, the second remote data interface unit, the third remote data interface unit, and the fourth remote data interface unit via the ARINC615A protocol. The configuration software and operation software of the external switch are loaded into the first external switch and the second external switch via the ARINC615A protocol.