High-integrity triplex avionics
Patent Information
- Application Number
- EP2023748792
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-04
- Filing Date
- 2023-07-31
- Publication Date
- 2025-06-11
AI Technical Summary
Current avionics systems for drones lack high safety levels, being several orders of magnitude lower than required for operations beyond visual range and in populated areas, and are incompatible with the size, weight, power, and cost constraints of drones, especially those in the specific and certified categories, as they are based on architectures designed for larger aircraft.
A triplex avionics system with a computer housing three physically separated processing channels, each with distinct sensors and modules for navigation parameter estimation and command verification, ensuring high safety levels while reducing mass, volume, and cost, by using external and internal sensors, and implementing distributed triplex voting logic for command validation.
The system achieves high integrity and safety avionics with reduced mass, volume, and cost, suitable for drones, by integrating sensors and calculation means within a single box, limiting cabling, and using separate measuring equipment to facilitate integration and reduce costs, while ensuring valid commands through distributed voting logic.
Smart Images

Figure 1.1
Abstract
Description
[0001] HIGH INTEGRITY TRIPLEX AVIONICS
[0002] The invention relates to the field of avionics on board an aircraft (in a drone for example).
[0003] BACKGROUND OF THE INVENTION
[0004] A recently adopted European regulation defines three categories for civil drones: open category, specific category and certified category.
[0005] The open category concerns operations with low risk to aviation safety, the specific category concerns operations with moderate risk, and the certified category concerns operations with high risk.
[0006] Each category lists acceptable flight types and operations based on the characteristics of the drones, including their mass and the control systems they are equipped with.
[0007] The invention is particularly interesting for civil drones of the specific and certified categories - but it can be applied more generally to any type of drone, civil or military, and even to any type of aircraft.
[0008] Currently, the majority of professional civilian drones have a mass of less than 25 kg and can only operate in very sparsely populated areas, within sight and under special regulations. Drones are used, for example, to monitor high-voltage lines.
[0009] There is no flight control avionics system that offers both a high level of safety, and a mass, volume and cost compatible with such drones, which would allow the scope and functions implemented by these drones to be extended, which would open up new market opportunities.
[0010] The solutions available to drone pilots are avionics whose safety level is neither demonstrated nor even claimed. These avionics have safety levels that are in reality several orders of magnitude lower than what is necessary to operate beyond visual range and above areas with higher population density.
[0011] We therefore decided, in order to meet the safety constraints imposed, to work on a reference system similar to that of certified aircraft organized in ATA (for Air Transport Association), in order to incorporate the functions necessary for flight safety.
[0012] Embedding these functions allows you to benefit from certification evidence associated with standards such as ETSO (for European Technical Standard Order, ETSO 0145 for example, Airborne navigation sensors using the GPS...). In such an architecture, the different functions, carried by different equipment, communicate with each other using digital buses. Avionics available on the market mostly meet this type of architecture, which is common today in aeronautics.
[0013] However, these ATA architectures are clearly incompatible with the targeted drones, due to their mass, volume and cost.
[0014] Therefore, it was considered to use existing solutions developed for aircraft designed to comply with the EASA CS-23 certification specification, which is applicable to normal, utility, aerobatic or commuter category aircraft. The safety requirements for this type of aircraft are less than those achieved by ATA architectures, and are relatively close to the requirements required for drones.
[0015] However, again, these existing avionics solutions are not applicable to the targeted drones, due to their mass, volume and cost.
[0016] It is therefore understood that existing avionics architectures, which allow acceptable safety levels to be obtained, are not compatible with the design requirements of drones, which are governed by the so-called "SWaP-C" constraints (for Size, Weight, Power and Cost). These existing avionics cannot be embedded in drones, and to date there is no avionics offering an acceptable level of safety in a volume and costs compatible with a drone with a mass of less than two hundred kilograms.
[0017] Documents US20140027564A1 and US 2018 / 001994A1 disclose computers that have multiple processing paths.
[0018] The processing paths of each computer differ from each other, each given processing path having its own specificity which differs from the specificities of the other processing paths.
[0019] SUBJECT OF THE INVENTION
[0020] The invention aims to provide avionics with a high level of safety, and reduced mass, volume and cost.
[0021] SUMMARY OF THE INVENTION
[0022] With a view to achieving this aim, a computer is proposed which is arranged to be embedded in an aircraft which comprises at least one flight control actuator, the computer comprising a housing in which at least three processing channels which are physically separated are integrated, each processing channel comprising: a first module arranged to acquire measurements produced by at least one sensor associated with said processing channel, to estimate navigation parameters from these measurements, and to verify a first validity of the navigation parameters by comparing them with those estimated by the first modules of the other processing channels;
[0023] - a second module arranged to generate commands from an aircraft trajectory instruction and navigation parameters estimated by the first module of said processing channel and the first validity of which has been verified;
[0024] - a third module arranged to verify a second validity of the commands by comparing them with those generated by the second modules of the other processing channels; the computer being arranged to transmit the commands, the second validity of which has been verified, to control the flight control actuator(s).
[0025] The integration, in a single computer, of three physically separate processing channels, each associated with at least one separate sensor, and each comprising modules which calculate and verify the navigation parameters and the commands, makes it possible to obtain avionics with a high level of safety and presenting reduced mass, volume and cost.
[0026] We further propose a calculator as previously described, in which, for each processing channel, the sensor(s) associated with said processing channel comprise at least one external sensor located outside the calculator, and / or at least one internal sensor integrated into said processing channel.
[0027] We further propose a calculator as previously described, in which, for each processing channel, the external sensor(s) associated with said processing channel comprise at least one pressure sensor and one magnetometer, and in which the navigation parameters comprise an air speed, an altitude and a magnetic heading.
[0028] We further propose a calculator as previously described, in which, for each processing channel, the internal sensor(s) associated with said processing channel comprise sensors integrated into a satellite positioning system and into an inertial measurement unit integrated into said processing channel, and in which the navigation parameters comprise a position and an attitude.
[0029] We further propose a calculator as previously described, in which, for each processing channel, the calculator is arranged to, if the first validity of a navigation parameter estimated by the first module of said processing channel is not verified, no longer use a sensor which is associated with said processing channel and which was used to estimate said navigation parameter.
[0030] We further propose a calculator as previously described, in which, for each processing channel, the calculator is arranged to, if the first validity of a navigation parameter estimated by the first module of said processing channel is not verified, deactivate said processing channel.
[0031] We further propose a computer as previously described, in which, at a time T, the processing channels comprise a current master channel, the computer being arranged to:
[0032] - if the second validity of the commands generated by the second module of the current master channel is verified, use said commands to control the flight control actuator(s);
[0033] - otherwise, deactivate the current master channel and designate a new master channel.
[0034] We further propose a calculator as previously described, in which, for each processing channel, the verification of the second validity carried out by the third module includes a bit-by-bit comparison and a majority vote.
[0035] We also offer an avionics system comprising:
[0036] - at least three measuring devices each integrating at least one external sensor;
[0037] - a calculator as previously described, each processing channel of the calculator being connected to one of the measuring devices;
[0038] - at least one flight control actuator;
[0039] - separate interface equipment associated with each flight control actuator, each interface equipment being connected to the computer and to said flight control actuator and being arranged to acquire a command issued by the computer, to transmit said command to said flight control actuator to control it, and to send uplink signals representative of an operation of said flight control actuator back to the computer.
[0040] An avionics system as previously described is further provided, said interface equipment being arranged to be connected to a power source integrated in the aircraft, and to provide a supply voltage to the flight control actuator to power it.
[0041] Further provided is an avionics system as previously described, wherein the uplink signals comprise monitoring signals representative of a state of the flight control actuator.
[0042] Further provided is an avionics system as previously described, wherein the uplink signals include return signals which are used by the second modules of the computer processing paths to produce the commands.
[0043] We further propose an avionics system as previously described, in which the return signals are representative of a position of a rotor of an electric motor of the flight control actuator and / or a position of a member actuated by said electric motor.
[0044] Further provided is an aircraft comprising an avionics system as previously described.
[0045] An aircraft as previously described is further provided, the aircraft being a drone.
[0046] The invention will be better understood in light of the following description of a particular, non-limiting embodiment of the invention.
[0047] BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Reference will be made to the attached drawings, including:
[0049] [Fig. 1] Figure 1 represents an avionics system of a drone, which includes a computer, measurement equipment, interface equipment, and flight control actuators; [Fig. 2] Figure 2 is a view similar to Figure 1, the computer being represented in more detail; [Fig. 3] Figure 3 represents interface equipment.
[0050] DETAILED DESCRIPTION OF THE INVENTION
[0051] With reference to figures 1 and 2, a drone 1 integrates an avionics system 2 which comprises a computer 3, at least one measuring device 4 (here three measuring devices 4a, 4b, 4c are represented), at least one flight control actuator 5 (here two flight control actuators 5a, 5b are represented), and an interface device 6 for each flight control actuator 5 (and therefore here two interface devices 6a, 6b).
[0052] Of course, the architecture shown is in no way limiting and, in particular, the number of measuring devices 4, the number of flight control actuators 5 and the number of interface devices 6, which are actually on board the drone 1, may be different. In particular, the number of flight control actuators 5 is in reality probably greater and for example equal to six or eight.
[0053] The three measuring devices 4 are identical, but independent and physically separated. The three measuring devices 4 measure the same quantities.
[0054] The calculator 3 is connected to each measuring equipment 4 by digital links 7: 7a, 7b, 7c.
[0055] Each measuring equipment 4 integrates at least one external sensor 8, as well as a processing module 11. By “external sensor”, it is meant that the sensor(s) are not integrated into the computer 3. Each measuring equipment 4 integrates at least one pressure sensor (in this case a barometer and a pitot probe) and a magnetometer. The processing module 11 of each measuring equipment 4 digitizes the measurements produced by the external sensors 8 of said measuring equipment 4, and transmits these digitized “raw” measurements to the computer 3 via the corresponding digital link 7.
[0056] The measurements therefore travel from the measuring equipment 4 to the computer 3, according to flows Fl, which are unidirectional and independent flows.
[0057] The flight control actuators 5 (hereinafter referred to as "actuators" to simplify the description) comprise, for example, one or more control surface actuators of the drone 1 and / or one or more motor actuators of the drone 1. The actuators 5 are so-called COTS actuators (for Commercial Off-The-Shelf, i.e. they are available actuators which do not have any particular characteristics for being integrated into the avionics system 2 described here).
[0058] The computer 3 is connected to the actuator 5a via the interface equipment 6a and to the actuator 5b via the interface equipment 6b.
[0059] The computer 3 is connected to the interface equipment 6a and to the interface equipment 6b by two separate CAN 9 buses (CAN for Controller Area Network): a CAN 9a bus and a CAN 9b bus.
[0060] Each interface device 6 is connected to an actuator 5 by a CAN bus 10: the interface device 6a is connected to the actuator 5a by a CAN bus 10a, and the interface device 6b is connected to the actuator 5b by a CAN bus 10b.
[0061] The computer 3 comprises a housing in which at least three physically separate processing channels 12 are integrated. Here, the computer 3 comprises three processing channels 12a, 12b and 12c.
[0062] Each processing channel 12 is connected to a (distinct) measuring device 4: the processing channel 12a is connected to the measuring device 4a by the link 7a, the processing channel 12b is connected to the measuring device 4b by the link 7b and the processing channel 12c is connected to the measuring device 4c by the link 7c.
[0063] Each processing channel 12 comprises at least one internal sensor. Each processing channel 12 here comprises several internal sensors, which include sensors integrated into a satellite positioning system 14 (or GNSS, for Global Navigation Satellite System) and into an inertial measurement unit 15 (or IMU, for Inertial Measurement Unit), which are themselves integrated into said processing channel 12.
[0064] Each processing channel 12 further comprises power supply components 16 which supply said processing channel 12 from two power sources 18 of the drone 1 to which the computer 3 is connected. The two power sources 18 are generally batteries.
[0065] Each processing channel 12 further comprises one or more processing components 19, and for example any processor or microprocessor(s), general or specialized (for example a DSP, for Digital Signal Processor, or a GPU, for Graphics Processing Unit), a microcontroller, or a programmable logic circuit such as an FPGA (for Field Programmable Gate Arrays) or an ASIC (for Application Specific Integrated Circuit).
[0066] Each processing path 12 also comprises one or more memories 20. At least one of these memories 20 forms a computer-readable recording medium, on which is recorded at least one computer program comprising instructions which enable the processing path 12 to carry out the functions described herein. One of these memories 20 may be integrated into one of the processing components 19.
[0067] Each processing channel 12 further comprises a first module 21, a second module 22 and a third module 23.
[0068] The modules 21, 22, 23 are here functional modules and are implemented in the processing component(s) 19 which have just been described. The modules 21, 22, 23 can be purely software modules, purely hardware modules, or partly software and partly hardware modules.
[0069] We now describe in more detail the operation of calculator 3.
[0070] As we have seen, each processing channel 12 is associated with at least one external sensor 8 (here three) and / or (here and) with at least one internal sensor (which are integrated here in a GNSS 14 and in an IMU 15).
[0071] In each processing channel 12, the first module 21 acquires the measurements produced by the sensors associated with said processing channel 12, that is to say by the external sensors 8 of the measuring equipment 4 to which said processing channel 12 is connected, and by the internal sensors 14, 15 integrated in said processing channel 12.
[0072] The first module 21 of said processing channel 12 then estimates, from these measurements, navigation parameters.
[0073] The navigation parameters here include an air speed, an altitude and a magnetic heading (of the drone 1), obtained from the measurements produced by the external sensors 8, and a position and an attitude (of the drone 1), obtained from the measurements produced by the satellite positioning system 14 and by the inertial measurement unit 15.
[0074] The first modules 21 of the three processing channels 12 then exchange the navigation parameters that they have each estimated from the sensors associated with their processing channel 12.
[0075] The navigation parameters travel between the first 21 modules according to F2 flows, on an internal 24 inter-channel bus.
[0076] Each first module 21 also transmits on the internal bus 24 monitoring signals for the internal sensors 14, 15 and external sensors 8 associated with the processing channel 12 to which said first module 21 belongs. For each sensor, the monitoring signals include information on the state of said sensor (for example normal state, fault, sensor connection problem, etc.).
[0077] The first module 21 of each processing channel 12 then verifies a first validity of the navigation parameters that it has estimated by comparing them with those estimated by the first modules 21 of the other processing channels 12.
[0078] To do this, the first module 21 of each processing channel 12, for each navigation parameter, compares the value of said navigation parameter that it has estimated with an average of the values of the same navigation parameter used estimated by the first modules 21 of the other processing channels 12.
[0079] A first vote is therefore carried out by each first module 21 on the navigation parameters. If the value of the navigation parameter that said first module 21 has estimated is included in an interval [Ma; M+a], where M is the average and a is a tolerance margin, the first module 21 considers that the first validity of said navigation parameter is verified, that is to say that the navigation parameter that it has estimated is valid.
[0080] If the value of said navigation parameter is not included in this interval, the first module 21 considers that the first validity of said navigation parameter is not verified, that is to say that the navigation parameter that it has estimated is not valid.
[0081] For each processing channel 12, if the first validity of a navigation parameter estimated by the first module 21 of said processing channel 12 is not verified, the computer 3 no longer uses the sensor (external or internal) which is associated with said processing channel 12 and which was used to estimate said navigation parameter.
[0082] Alternatively, for each processing channel 12, if the first validity of a navigation parameter estimated by the first module 21 of said processing channel 12 is not verified, the computer 3 deactivates said processing channel 12. The computer 3 therefore switches from a triplex configuration (three lanes) to a dual lane configuration (two lanes). The external sensors 8 and internal sensors 14, 15 associated with said processing channel 12 are no longer used.
[0083] Each processing channel 12 receives, via a digital link 25, a trajectory instruction Ct from the drone 1.
[0084] The trajectory instruction Ct of the drone 1 is for example pre-recorded in the computer 3 or in another piece of equipment of the drone 1, or is calculated in real time by the computer 3 or by another piece of equipment of the drone 1, or is sent by a ground station, by another aircraft, etc.
[0085] Each processing channel 12 also receives, via a digital link 26, flight control monitoring signals, which are transmitted to the computer 3 by equipment which monitors the flight controls, or by functions internal to the computer 3.
[0086] The second module 22 of each processing channel 12 then generates commands from the trajectory instruction Ct of the drone 1 and the navigation parameters estimated by the first module 21 of said processing channel 12, the first validity of which has been verified.
[0087] For each flight control, commands are generated only if the flight control monitoring signals indicate that it is functioning correctly.
[0088] Each second module 22 then transmits to all the third modules 23 the commands that it has generated.
[0089] The commands therefore travel from the second modules 22 to the third modules 23 according to F3 flows. This data circulates on an internal bus 28 (an Ethernet bus in this case), inter-channel.
[0090] In each processing channel 12, the third module 23 of said processing channel 12 verifies a second validity of the commands that the second module 22 of said processing channel 12 has generated, by comparing them with the commands generated by the second modules 22 of the other processing channels 12.
[0091] For each processing channel 12, the comparison carried out by the third module 23 is a bit-by-bit comparison between the data in order to detect, via a majority vote (2 out of 3), a faulty processing channel 12. The bit-by-bit vote makes it possible to avoid using threshold or average logic, and makes the vote simpler and more robust. This method, however, requires synchronization of the processes between the different processing channels 12, in order to guarantee that the calculations are carried out simultaneously from the same data.
[0092] The third modules 23 send on the bus 28 a status of the validity of the calculation of commands on each of the channels 12.
[0093] Each third module 23 is connected to two CAN transceivers 27, one being connected to the CAN bus 9a and the other to the CAN bus 9b. The CAN transceivers 27 convert the signals produced by the third modules 23 into signals compatible with a CAN bus.
[0094] Each processing channel 12a, 12b, 12c is connected to the interface equipment 6a by the CAN bus 9a and by the CAN bus 9b, and to the interface equipment 6b by the CAN bus 9a and the CAN bus 9b. The use of the two CAN buses 9a and 9b makes it possible to introduce redundancy into the link.
[0095] At time T, processing channels 12 include a current master channel. For example, when computer 3 starts, the master channel is processing channel 12a.
[0096] If the second validity of the commands generated by the second module 22 of the current master channel 12a is verified, the commands generated by said second module 22 of the processing channel 12a are sent on the CAN buses 9a and 9b to control the actuators 5a, 5b.
[0097] On the other hand, if the second validity of the commands generated by the second module 22 of the current master channel 12a is not verified, that is to say if at least one command intended for at least one actuator is not valid, the computer 3 deactivates the current master channel and designates a new master channel. For example, it can be provided that, when the current master channel is channel 12a and the commands produced by this channel are not valid, channel 12b becomes the new master channel. Similarly, after channel 12b, channel 12c becomes the new master channel.
[0098] As seen, the computer 3 is connected to each actuator 5 via separate interface equipment 6.
[0099] With reference to Figure 3, each interface equipment 6 comprises a computer interface module 30, an actuator interface module 31, a power management module 32, a power supply and supervision module 33, a return module 34, and a processing and diagnostic module 35.
[0100] The power management module 32 is connected to the power source 18. The power management module 32 receives power energy generated by the power source 18 and produces at least one power supply voltage to power the interface equipment 6 and the actuator 5 to which the interface equipment 6 is connected. The power management module 32 produces monitoring signals representative of a state of the power source 18, and transmits them to the processing and diagnostic module 35.
[0101] The power supply and supervision module 33 supplies the power supply voltage V to the actuator 5 (more precisely, to the electric motor of the actuator 5). The power supply and supervision module 33 monitors the consumption of the actuator 5. The power supply and supervision module 33 attempts in particular to detect an anomaly in the current consumed (zero, too high, etc.). The power supply and supervision module 33 produces monitoring signals representative of an electrical consumption of the actuator 5, and transmits them to the processing and diagnostic module 35.
[0102] The computer interface module 30 is connected to the computer 3 via the CAN buses 9a and 9b, and receives the Cm commands sent by the current master channel (here channel 12a).
[0103] The processing and diagnostic module 35 acquires the Corn commands and, possibly, performs processing on the Corn commands. In particular, if necessary, the processing and diagnostic module 35 converts the Corn commands into a format compatible with the actuator 5. The processing and diagnostic module 35 also checks that the data traveling on the two CAN buses 9a and 9b are consistent.
[0104] The processing and diagnostic module 35 then transmits the Corn commands to the actuator 5 to control it, via the actuator interface module 31 and the bus 10.
[0105] The processing and diagnostic module 35 also acquires, via the actuator interface module 31 and the bus 10, monitoring signals, produced by the actuator 5, and representative of a state of the actuator 5.
[0106] The feedback module 34 acquires feedback signals Sr. The feedback signals Sr are here analog signals, produced by the actuator 5 (i.e. by one or more sensors integrated in or connected to the actuator 5).
[0107] The actuator 5 comprises an electric motor and a member which is actuated by the electric motor.
[0108] The feedback signals Sr are representative of a position of the rotor of the electric motor and / or a position of the member actuated by the electric motor of the actuator 5. The position feedback is independent of the control.
[0109] The return module 34 transmits the return signals Sr to the processing and diagnostic module 35.
[0110] The processing and diagnostic module 35 carries out processing and diagnostics relating to the operation of the actuator 5 and the power source 18, using the different monitoring signals produced by the different modules of the interface equipment 6.
[0111] The processing and diagnostic module 35 goes back to the uplink signal calculator Sm.
[0112] The Corn commands and the Sm uplink signals travel according to F4 flows on the CAN buses 9a and 9b.
[0113] The uplink signals Sm comprise monitoring signals representative of a state of the flight control actuator 5.
[0114] The uplink signals Sm also include the return signals Sr.
[0115] The monitoring signals are used by the computer 3 to deactivate the actuator 5 if it fails. The computer 3 takes this failure into account in the actuator control laws. Indeed, the control laws can adapt to the loss of part of the actuators (control allocation).
[0116] The return signals are used by the second modules 22 of the processing channels 12 of the computer 3 to implement the control laws and to produce the commands making it possible to control the actuators 5.
[0117] It is noted that the return signals could be different. In the case where the control of the actuator 5 is carried out via a control on another quantity (torque, current, etc.), the return signals are then representative of this other quantity.
[0118] The computer 3 and the avionics system 2 which have just been described are particularly advantageous.
[0119] The calculator 3 implements the following functions: I / O management 40 (input / output management), localization 41, navigation 42, guidance 43, piloting 44, calculation of aerodynamic quantities 45, attitude and heading calculation 46, GNSS sensors 47, inertial sensors 48, state machine 49 (for control laws), monitoring and voting 50.
[0120] The computer 3 and the avionics system 2 make it possible to obtain avionics with a high level of integrity and safety, in a mass, volume and cost adapted to civil professional drones. The mass of the avionics system 2 is typically less than 2 kilograms.
[0121] The integration, in a single box, of the three channels, each including their position and attitude sensors, calculation means, power supply components, and input / output management, makes it possible to limit the mass of wiring between channels that is traditionally found on triplex architectures with three separate computers.
[0122] Implementing distributed triplex voting logic on navigation parameters and commands ensures that the commands provided are valid.
[0123] The use of a separate measuring equipment 4 associated with each processing channel 12, integrating the static pressure, total pressure and magnetometer sensors, and communicating with the associated processing channel 12 via a digital link 7, makes it possible to dispense with the pneumatic connections generally used, which facilitates the integration of the system 2 in the drone 1 and limits the mass thereof. In order to limit costs, each measuring equipment 4 only performs the acquisition of the measurements, the digitization of these and the communication of these via the digital link 7. The calculations of the useful quantities (air speed, atmospheric pressure) are carried out in each channel 12 of the computer 3, in order to communalize the critical calculation functions. In addition, by limiting the length of the tires, by placing the electronics as close as possible, the different equipment of the system 2 are less sensitive to icing.
[0124] The 3 calculator implements a limited number of digital interfaces, which allows to reduce the mass of the connectors.
[0125] The use of interface equipment 6, communicating by digital link with the computer 3, makes it possible to manage the specific interfaces of the drone 1 in which the avionics is integrated. These interface equipment 6 have the minimum communication and acquisition functions.
[0126] Each interface device 6 performs the monitoring functions of the actuators 5, which makes it possible to achieve the required safety levels on the functional flight control chain, while using COTS actuators (which do not necessarily themselves integrate monitoring devices).
[0127] The monitoring of each actuator 5 by the associated interface equipment 6 makes it possible in particular to detect abnormal operation of the actuator 5 and therefore to deactivate it quickly, for example by cutting off its power supply. This prevents the abnormal operation of the actuator 5 from significantly or even dangerously degrading the operation of the drone 1. The data sent back by the interface equipment 6 makes it possible to implement Health Monitoring functions (which can be translated as predictive maintenance) on the actuators 5. Similarly, the comparison of the measurements carried out by the first modules 21 of the computer 3 makes it possible to implement Health Monitoring functions on the external sensors 8 of the measuring equipment and on the internal sensors.
[0128] Of course, the invention is not limited to the embodiment described but encompasses any variant falling within the scope of the invention as defined by the claims.
[0129] The invention is not necessarily implemented in a civilian drone, but can be applied to any type of drone.
[0130] The invention can also be implemented in an aircraft other than a drone, and for example in an aircraft certified according to the EASA CS-23 certification specification.
[0131] The calculator could include a number of channels other than three.
[0132] External sensors may differ from those described here, and are not necessarily grouped into measuring equipment. They may be individual sensors. Internal sensors may also differ.
[0133] In the embodiment described, the buses used between the computer and the interface equipment, and between the interface equipment and the actuators, are CAN buses; it is of course possible to use different buses, and for example RS buses (RS485 for example) or buses using the PWM technique (for Pulse Width Modulation).
Claims
CLAIMS 1. Computer (3) arranged to be mounted in an aircraft (1) which integrates at least one flight control actuator (5a, 5b), the computer comprising a housing in which at least three processing channels (12a, 12b, 12c) are integrated which are physically separated, characterized in that each processing channel comprises: - a first module (21) arranged to acquire measurements produced by at least one sensor (8, 14, 15) associated with said processing channel, to estimate navigation parameters from these measurements, and to verify a first validity of the navigation parameters by comparing them with those estimated by the first modules of the other processing channels; - a second module (22) arranged to generate commands from a trajectory instruction of the aircraft and navigation parameters estimated by the first module of said processing channel and the first validity of which has been verified; - a third module (23) arranged to verify a second validity of the commands by comparing them with those generated by the second modules of the other processing channels; the computer being arranged to transmit the commands, the second validity of which has been verified, to control the flight control actuator(s) (5); the computer being arranged so that at a time T, the processing channels (12) comprise a current master channel (12a), the computer (3) being arranged so that: - if the second validity of the commands generated by the second module (22) of the current master channel is verified, use said commands to control the flight control actuators (5); - otherwise, deactivate the current master channel and designate a new master channel.
2. Calculator according to claim 1, in which, for each processing channel (12), the sensor(s) associated with said processing channel comprise at least one external sensor (8) located outside the calculator, and / or at least one internal sensor integrated into said processing channel.
3. Calculator according to claim 2, in which, for each processing channel (12), the external sensor(s) (8) associated with said processing channel comprise at least one pressure sensor and one magnetometer, and in which the navigation parameters comprise an air speed, an altitude and a magnetic heading.
4. Calculator according to one of claims 2 or 3, in which, for each processing channel (12), the internal sensor(s) associated with said processing channel comprise sensors integrated into a satellite positioning system (14) and into an inertial measurement unit (15) integrated into said processing channel, and in which the navigation parameters comprise a position and an attitude.
5. Calculator according to one of claims 1 to 4, in which, for each processing channel (12), the calculator (3) is arranged to, if the first validity of a navigation parameter estimated by the first module (21) of said processing channel is not verified, no longer use a sensor which is associated with said processing path and which was used to estimate said navigation parameter.
6. Calculator according to one of claims 2 to 4, in which, for each processing channel (12), the calculator (3) is arranged to, if the first validity of a navigation parameter estimated by the first module (21) of said processing channel (12) is not verified, deactivate said processing channel.
7. Calculator according to one of claims 1 to 6, in which, for each processing channel (12), the verification of the second validity carried out by the third module (23) comprises a bit-by-bit comparison and a majority vote.
8. Avionics system (2) comprising: - at least three measuring devices (4) each integrating at least one external sensor (8); - a calculator (3) according to one of claims 1 to 7, each processing channel (12) of the calculator being connected to one of the measuring equipment; - at least one flight control actuator (5); - separate interface equipment (6) associated with each flight control actuator, each interface equipment (6) being connected to the computer (3) and to said flight control actuator (5) and being arranged to acquire a command issued by the computer (3), to transmit said command to said flight control actuator to control it, and to send uplink signals representative of an operation of said flight control actuator back to the computer.
9. Avionics system according to claim 8, said interface equipment (6) being arranged to be connected to a power source (18) integrated in the aircraft (1), and to provide a supply voltage (V) to the flight control actuator (5) to power it.
10. Avionics system according to one of claims 8 or 9, wherein the uplink signals comprise monitoring signals representative of a state of the flight control actuator.
11. Avionics system according to one of claims 8 to 10, wherein the uplink signals comprise return signals which are used by the second modules (22) of the processing paths (12) of the computer (3) to produce the commands.
12. Avionics system according to claim 11, wherein the return signals (Sr) are representative of a position of a rotor of an electric motor of the flight control actuator and / or a position of a member actuated by said electric motor.
13. Aircraft (1) comprising an avionics system (2) according to one of claims 8 to 12.
14. Aircraft according to claim 13, the aircraft being a drone.