Embedded peripheral computing device, electronic system for executing software applications and associated method for executing software applications
Patent Information
- Application Number
- FR2022014319
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-12-22
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2042-12-22
AI Technical Summary
Aircraft on-board computing devices face limitations in computational resources due to certification standards, which are rigid and expensive to evolve, hindering the execution of sophisticated software applications needed for new aeronautical operations, while offloading to ground systems is not always feasible due to bandwidth, latency, and reliability issues.
A peripheral computing device on board the aircraft manages local and remote computing resources through a communication interface with certified on-board devices and ground systems, dynamically allocating execution of software applications between local and remote processors based on availability, connectivity, and priority criteria.
This approach significantly enhances on-board computing capacity and flexibility, allowing execution of complex applications while ensuring reliability and security, adapting to weight and energy constraints, and facilitating secure data transmission.
Abstract
Description
Description Title of the invention: Embedded peripheral computing device, electronic system for running software applications and method for executing associated software applications
[0001] — The present invention relates to an embedded peripheral computing device of an aircraft, as well as an electronic system for running software applications associated and an associated software application execution method.
[0002] = The invention lies in the field of avionics, and more particularly in the domain of running embedded software applications on an aircraft.
[0003] — The invention applies to any type of aircraft, with or without a pilot on board, both in a civilian or military context.
[0004] …— As is known, aircraft include on-board electronic devices (or on-board computers) with certified operation according to a certification standard avionics. In particular, any software application embedded in this type of The device must be compliant and certified. Therefore, embedded software applications, which are useful for navigation, for controlling onboard equipment, by Examples of various sensors, e.g. optical or thermal cameras, radars, etc., are in limited number, because they are expensive to develop and certify. Furthermore, the computing resources (e.g., CPU, ROM, RAM) of certified onboard computers are in general pre-allocated resources, to guarantee security and limit any risk of hacking or external intrusion. Thus, the hardware and software structure of computers The certified operating edge is rigid, any evolution or modification being slow and expensive.
[0005] — However, the need for computing resources, e.g. processors and memory, for Aeronautical operations are constantly increasing, as are software applications of increasingly sophisticated methods that can be advantageously implemented. Furthermore, New uses are developing with the advent of new types of aircraft. lightweight aircraft, such as drones or urban taxi aircraft, enabling in particular the use of onboard sensors for new data collection missions, for monitoring, maintenance, etc. applications.
[0006] There is therefore a need to increase the computing capacity of on-board devices to allow the execution of software applications related to these new needs.
[0007] — Systems for remotely executing software applications on the ground, in Ground-based computing centers have been proposed. However, insofar as... commands for on-board equipment and data retrieval provided by Such equipment is necessary, but remote deployment of applications to the ground is not always possible, depending on the needs, particularly in terms of bandwidth and latency, and, where applicable, in terms of reliability / integrity of calculations and data protection. There is therefore a need for the execution of software applications related to equipment embedded in an aircraft, which combines increased available computing resources and reliability. To this end, the invention proposes, according to one aspect, a peripheral computing device for use on board an aircraft, comprising a first communication interface configured to communicate, according to a first communication protocol, with one or more certified operating onboard electronic devices, a second radio communication interface configured to communicate, according to a second radio communication protocol, with at least one remote computing system located on the ground, the peripheral computing device comprising at least one electronic memory unit and at least one computing processor, configured to implement: - a management module for a plurality of software applications, said software applications being stored in said electronic memory, each software application being adapted to provide at least one control parameter and / or receive at least one data point from at least one certified operating on-board electronic device: - an execution activation module for at least one of said stored software applications, configured to receive at least one execution request for at least one software application from an external control device and / or to validate a condition for activating the execution of at least one software application, - a module for managing an execution stack, configured to determine, for each software application to be executed, an allocation of local computing resources of said peripheral computing device to execute all or part of said software application to be executed, and to launch the local execution of said part of the application to be executed and to request, in the case where a first part of said application is executed locally, a remote execution, by the remote computing system, of a second part of the application to be executed, complementary to the first part. Advantageously, such a peripheral computing device makes it possible to considerably increase the computing resources available on board, while managing the execution of the software application(s) between local on-board computing resources and remote computing resources. The embedded peripheral computing device according to the invention may also have one or more of the characteristics below, taken independently or according to all technically feasible combinations. The execution stack management module implements, for the determination of local computing resources allocated by software application to be executed, at least one criterion among: a computing resource availability criterion, a connectivity criterion, a data protection criterion, a priority criterion. The device is configured to dynamically receive, from an external control device, at least one parameter for allocating computing resources and / or connectivity and / or an execution priority. The device also includes a data and results management module, configured to consolidate and store results obtained by the execution of each software application, to communicate the results to the external control device and / or the remote computing system. The module for managing multiple software applications is configured to download new software applications or an update to a previously stored software application and / or to delete a previously stored software application. According to another aspect, the invention relates to an electronic system for executing software applications comprising an on-board computing system on an aircraft, and at least one remote computing system located on the ground, the on-board computing system comprising at least one on-board electronic device with operation certified according to an avionics certification standard, and a peripheral computing device as briefly described above. The electronic system for executing software applications may also have one or more of the following characteristics, taken independently or in all technically feasible combinations. The remote computing system further includes a supervisory device comprising a human-machine interface and configured to receive observability signals from said peripheral computing device, said observability signals comprising data relating to local computing resources and information relating to the execution of at least one of said software applications, to calculate an operating state of said peripheral computing device and an execution state of said at least one software application from the observability signals received, and to display said operating state and said execution state on said human-machine interface. The peripheral computing device is configured to record, during an aircraft mission, a set of information in at least one execution report, including status and execution information of the peripheral computing device and certified operating onboard electronic devices, as well as supplementary information including environmental data. and connectivity information, and to transmit said execution report to the monitoring device, the monitoring device being further configured to execute and display on the human-machine interface a replay of the states of the peripheral computing device and the on-board electronic devices. According to another aspect, the invention relates to a method for executing software applications, implemented in an electronic application execution system of the type described above, comprising the following steps: - receipt of a command to add / delete a software application, from an external control device, or from a ground-based computing system or from one of the on-board devices; -updating the storage of software applications based on the aforementioned command received; - activation of execution of one or more of the stored software applications, based either on the receipt of a request to execute at least one software application from an external device, or on the validation of a condition for activation of execution and / or pausing or stopping the execution of one or more software applications upon receipt of a command or automatic validation of a stopping condition. According to a particular feature, the process further includes an application stack management step, implementing, for each software application to be executed, an allocation of local computing resources to execute a first part of the software application, and, in the case where said first part is less than 100%, a step of transmitting a command to execute a second part of said software application, complementary to the first part, to the remote computing system. According to another aspect, the invention relates to a computer program comprising software instructions which, when executed by a programmable electronic device, implement a method for executing software applications as briefly described above. Other features and advantages of the invention will become apparent from the description given below, by way of example and not limitation, with reference to the attached figures, including: [Fig.1] [Fig.1] illustrates an electronic system for executing software applications according to one embodiment; [Fig.2] [Fig.2] illustrates a method of executing software applications according to a first embodiment; [Fig.3] [Fig.3] illustrates a method of executing software applications according to a second embodiment. The electronic system for executing software applications, embedded on board an aircraft, finds applications in all types of aircraft, and more particularly for lightweight aircraft such as drones, carrying equipment such as image sensors, such as optical cameras, thermal cameras, imaging radar, positioning sensors (GNSS, inertial units, anemo-barometric sensors, radio navigation beacons, triangulation), measurement systems such as rangefinders, sensors and systems for monitoring weather, traffic or terrain, radio or digital communication systems, radio frequency (RF) antennas etc. Figure 1 schematically illustrates a system 2 which is an embedded software execution electronic system. System 2 is a system enabling ship-to-ground cooperation. System 2 comprises, on the one hand, an on-board computing system 4, comprising devices on board an aircraft 6, and on the other hand, one or more ground-based computing systems 8. The on-board computing system 4 comprises a set 10 of on-board electronic devices certified to operate according to an avionics certification standard, including at least one on-board computer 12, and on-board equipment 14, e.g. sensors, for example cameras, radars, actuator, navigation system, autopilot system, flight controls, geolocation system, certified monitoring systems (Traffic, weather), certified communication systems (e.g. Radios). For example, certified operating on-board devices comply with one or more of the following standards: RTCA DO178B for the software level certification and RTCA DO160 for the hardware certification part, AEEC Arinc 702A for the Flight Management System, etc. In one embodiment, the on-board computer 12 is configured to implement certified software applications, for example, applications for navigation assistance, control of the operation of sensors 14 and reception and processing of data from sensors 14. The on-board computer 12 includes hardware resources, in particular a central processing unit comprising one or more processors 15, adapted to execute computer program instructions when the processing unit is powered on. The on-board computer 12 also includes information storage units 16, including random access memory (RAM) units, ROM-type memory units adapted to store data and executable code instructions, a communication interface 18, and a human-machine interface 17. Furthermore, the embedded computing system 4 advantageously includes an embedded peripheral computing device 20. This peripheral computing device 20 advantageously increases the on-board computing capacity in a more flexible manner, allowing for easier and less expensive software and hardware updates than for the on-board computer 12. The peripheral computing device 20 includes a first communication interface 22 configured to communicate, according to a first communication protocol, with the certified operating electronic device(s) on board, and in particular with the on-board computer 12. In particular, the first communication interface 22 is configured to communicate, via bidirectional communication, with the communication interface 18 of the on-board computer 12. For example, communication between the peripheral computing device 20 and the on-board computer 12 is wired. Alternatively, communication between the peripheral computing device 20 and the on-board computer 12 is wireless, for example, using Wi-Fi or Bluetooth. In addition, the peripheral computing device 20 includes a second radio communication interface 24, configured to communicate, according to a second radio communication protocol, with the remote computing system(s) 8 located on the ground. The second communication protocol is a radio communication protocol, for example a standard 4G or 5G mobile telephony protocol, the SATCOM satellite communication protocol, the Datalink AOC / ATC protocol (for "Aeronautical Operation Control" / "Air Traffic Control"). Depending on variants, the peripheral computing device 20 includes several second radio communication interfaces 24, according to several radio communication protocols, allowing communication with external devices, by a second radio communication interface 24A allowing communication with the computing system 8 and a second radio communication interface 24B allowing communication according to another radio communication protocol, for example with one or more external control devices 25, configured to send commands to implement software applications by the peripheral computing device 20 and to receive data, including data from on-board sensors, in return. An external control device 25 is for example a tablet, a laptop, a smartphone (or smartphone). Such an external control device 25 is for example also carried on board the aircraft. In one embodiment, such an external control device 25 is operated by an operator on board the aircraft, for example an aircraft pilot, via a human-machine interface, e.g. a touch screen or any other suitable type of human-machine interface (not shown here). Thus, the peripheral computing device 20 is configured to communicate, bidirectionally, with the remote computing system 8 and with at least one external control device 25. The peripheral computing device 20 further comprises a processing unit 26, comprising one or more processors (CPU or GPU), and at least one electronic memory unit 28, these elements being adapted to communicate via a communication bus (not shown). In the example of [Fig.1] only a processing unit 26 and an electronic memory unit 28 are shown. The electronic memory unit 28 includes, in particular, RAM, ROM, and all types of non-volatile memory (e.g. EPROM, EEPROM, FLASH, NVRAM). The set of processing unit(s) 26 and electronic memory unit(s) 28 form the local computing resources of the peripheral computing device 20. Preferably, the peripheral computing device 20 is modular, with multiple processing and memory units that can be added, allowing for a dynamic increase in available resources, depending on the needs. The dynamic increase in available resources is limited, in practice, in certain embodiments, by the electrical power consumption and / or the total weight of such a peripheral computing device. Indeed, the total weight may be limited for certain types of aircraft, for example, drones, depending on the drone's aerodynamic lift and / or maneuverability. Similarly, the electrical power consumption when the peripheral computing device executes software applications with maximum utilization of computing and storage resources must be taken into account to ensure the completion of a planned mission over its planned duration. Here, a mission is understood to be a set of tasks to be performed, for example by onboard sensors, in connection with associated flight indications (trajectories, durations, waypoints, etc.). The electronic memory unit 28 is configured in particular to store a library of software applications 35, comprising a variable number of software applications APP, APP, APP; Each software application is stored as executable program code. The term "executable application" is also used to refer to a such a software application. For example, software applications are obtained by downloading (in English “Dataloading”), from an external control device 25 or from a ground-based computing system 8. Alternatively or in addition, a software application (APP) can be obtained from a computer-readable medium, for example a medium capable of storing electronic instructions and being coupled to a bus of a computer system (e.g., USB key, non-volatile memory (e.g., EPROM, EEPROM, FLASH, NVRAM), magnetic card or optical card). In addition, the electronic memory unit 28 is also configured to store data and results 37, including data obtained from certified functioning onboard electronic devices (e.g., images obtained from onboard sensors, operational data, data relating to the aircraft's trajectory or performance), and results obtained from the execution of APP software applications. This data and these results 37 can be transmitted to the ground as "observability signals," enabling a human operator or a system to monitor the proper functioning of the overall system, perform debugging, and conduct mission simulations or replays. In addition, the electronic memory unit 28 is configured to store parameters useful for implementing a software application execution process as described below, including parameters relating to the allocation of computing resources per software application, where appropriate, an execution priority table or a set of static rules defining software application execution priorities. Processing unit 26 is configured to run: - a module 30 for managing a plurality of software applications, the software applications being stored in the electronic memory unit 28, in particular in an application library 35, each software application being adapted to provide at least one control parameter and / or receive at least one data from at least one certified operating electronic device on board; - a module 32 for activating the execution of at least one of said stored software applications, configured to receive at least one execution request from at least one executable application from an external control device and / or to validate a condition for activating the execution of at least one software application, -a 34 execution stack management module, configured to determine, for each software application to be executed, an allocation of local computing resources 26, 28 of the peripheral computing device 20 to execute all or part of the application to be executed, and to launch the local execution of said part of the application to be executed and to request, in the case where only a first part of said application is executed locally, a remote execution, by the remote computing system 8, of a second part of the application to be executed, complementary to the first part; -a 36 module for data and results management, configured to consolidate and store results, and communicate results to the external control device and / or remote computing system. Modules 30, 32, 34, 36 are adapted to cooperate, as described in more detail below, to implement a software application execution process as described in more detail below. In one embodiment, modules 30, 32, 34, 36 are implemented in the form of software instructions forming a computer program, which, when executed by a computer, implements a method for executing software applications according to the invention. The computer program, containing software instructions, is also capable of being stored on a non-transient, computer-readable medium. A computer-readable medium is, for example, a medium capable of storing electronic instructions and being connected to a bus of a computer system. Examples of such readable media include optical discs, magneto-optical discs, ROMs, RAMs, any type of non-volatile memory (e.g., EPROM, EEPROM, FLASH, NVRAM), magnetic cards, or optical cards. In an alternative not shown, modules 30, 32, 34, 36 are each implemented as programmable logic components, such as FPGAs (Field Programmable Gate Arrays), microprocessors, GPGPUs (General-purpose processing on graphics processing), or dedicated integrated circuits, such as ASICs (Application Specific Integrated Circuits). The peripheral computing device 20 is configured to execute locally a first part of the applications to be executed, and to delegate, if necessary, a second part of execution to the remote computing system 8. Indeed, in some cases, the first part is equal to 100% of the software application to be executed, in which case there is no need to delegate a second part of execution to the remote computing system. In one embodiment, the remote computing system 8 comprises one or more interconnected electronic computing devices. Alternatively, the remote computing system 8 includes or is connected to a cloud of computers or "cloud". In a functional representation, the remote computing system 8 comprises a processing unit 40, including one or more computing processors, an electronic memory unit 42, a ground communication interface 44, adapted to communicate with the second communication interface 24 of the onboard peripheral computing device 20, and a human-machine interface 46. The processing unit 40 is configured to execute parts of the software applications APPi, by executing a corresponding part of the executable code, stored in the electronic memory unit 42, on request from the peripheral computing device 20, to store data and calculation results and to transmit these calculation results, via the communication interface 44, to the peripheral computing device 20 and / or to an external control device 25. According to one variant, the remote computing system 8 located on the ground is also configured to transmit data and computing results to another aircraft 6, for example as part of a mission involving a plurality of aircraft. Advantageously, such execution stack management is dynamic and flexible, and allows one or more criteria to be taken into account among: a criterion of availability of computing resources, a criterion of connectivity, a criterion of data criticality, a criterion of priority, as explained in more detail below. Fig. 2 is a synoptic diagram of the main steps of a software application execution process, implemented in the electronic software application execution system 2, in a first embodiment. As will become clearer from the description that follows, the process comprises a set of steps implemented by a processing unit, including at least one processor, of an embedded peripheral computing device 20. These steps are executed after the peripheral computing device is powered on. The process includes an initialization step 50, which is a preliminary step, executed at a later time than the other steps in the process. During the initialization stage, in particular, the first and second communication interfaces are initialized, specifically configured with respective communication addresses, so as to allow communication, on the one hand with the certified operating on-board electronic devices 10, on the other hand with the external devices 25, and with the ground computing system 8. Alternatively, the peripheral computing device performs the initialization of the communication interfaces following a request, for example transmitted by an operator or by an external application via an external control device 25. Furthermore, at initialization step 50, during the initialization of the first communication interface with the on-board equipment, the first configuration structures configuration, e.g. initial configuration tables are received from at least one on-board computer 12, and stored in a local electronic memory unit of the peripheral computing device. Similarly, during the initialization of the second communication interface with the remote computing system, second configuration structures, e.g. second configuration tables are received from at least one remote computing system 8, and stored in a local electronic memory unit of the peripheral computing device. The first and second configuration structures contain, among other things, connectivity information (e.g., identifiers and communication addresses). Optionally, during the initialization step, the APP software application library is re-initialized. Optionally, the data and result 37 stored in the memory unit of the peripheral computing device are erased during initialization 50. Depending on the variants, the APP applications and / or the data and results stored during a previous use of the peripheral computing device are retained. Furthermore, during the initialization phase, in one embodiment, parameters useful for implementing the software application execution process are obtained and stored. These parameters include, in particular, parameters relating to resource allocation per software application, for example, for a minimum allocation per software application, a maximum allocation, or an average allocation, and / or an execution priority table or a set of static rules defining the execution priorities of software applications. Resource allocation parameters include, for example: computing power, for example expressed in processor clock frequency (e.g. in GHz), and / or associated storage capacity, expressed for example in kilobytes, and / or a percentage of first communication bandwidth with certified operating onboard electronic devices, and / or a percentage of second communication bandwidth with the remote computing system. In one embodiment, the resource allocation parameters are grouped as a parameter vector, containing a value for each of the parameters mentioned below: - P1: allocated computing power; - P2: allocated storage capacity; - P3: percentage of bandwidth for the first communication; - P4: percentage of second communication bandwidth. In some variants, a vector containing only a subset of the allocation parameters is defined. In another variant, only one of the parameters mentioned above is used. The process includes a step 52 of receiving a command to add / delete a software application, from an external control device, or from the ground computing system or one of the on-board devices. Preferably, a deletion command is received from an external control device or an authorized operator, for example, the owner of the software application to be deleted. For example, authorized operator authentication is implemented, by an authentication process, many variants of such authentication processes being known. According to one embodiment, the addition / update of an application is carried out by an operator, preferably an authorized operator, using a data storage medium (e.g., USB key). Following the receipt of such an order, the process includes an application management step 54, which performs an update of the software application library based on the orders received. Step 54 includes receiving a new software application or an update to a previously stored software application, either via a wired connection or by downloading it via a radio communication link, and then storing the new applications (APP), and / or deleting the applications (APP); from the application library. The software applications stored in application library 35 are adapted to provide at least one control parameter and / or receive at least one data point from at least one onboard electronic device. As an optional addition, following the receipt of a new software application or an update to an existing software application, the process implements integrity and validity validations of the downloaded applications, using standard methods (authentication, cyclic redundancy check (CRC) validation, etc.). Subsequently, the process involves activating the execution of one or more of the stored software applications, which then become software applications to be executed. Indeed, the parallel execution of multiple software applications is supported. Execution activation is based either on receiving an execution request from at least one software application from an external device, or on the validation of an execution activation condition. In the case of validation of an execution activation condition, activation is automatic. For example, the activation condition for the execution of a software application APP is the end of the execution of a software application APP, or corresponds to a reduction in the resource requirement of the software application Appj compatible with its operation. In addition, commands to pause or stop the execution of one or more software applications can also be received (step 58), and their management is carried out directly. Stopping execution frees up resources and thus allows for the redistribution of available resources. Similar to execution, automatic validation of a stop condition can also trigger the stopping or pausing of an application's execution. Steps 54, 56, 58 are preferably executed in the background, substantially in parallel, so as to constantly take into account the receipt of new software applications or the updating of existing software applications, as well as execution activations and commands to stop or pause execution. The process also includes a step 60 for managing a stack of execution of the software applications to be executed. This step is repeated regularly, at predetermined time intervals or on event (for example, a request to start a new application, an event that terminates or significantly modifies the computing resource requirements of an application). Management step 60 implements, for each application to be executed (APP), an allocation of resources, in particular computing resources (processor and memory) of the peripheral computing device, called local resources, to execute all or part of the application to be executed (APP). For example, in one embodiment, the same amount of local resources is allocated to each APP, the amount being predetermined at the initialization step 50. According to one variant, resources are allocated dynamically, for example based on an expected response time per application, which allows for the dynamic definition of execution priorities. According to an alternative, resource allocation is carried out according to priorities, defined in a previously recorded execution priority table or according to a set of static rules previously programmed. According to one variant, priorities are updated dynamically using an external control device. Thus, the management module also implements a priority criterion. For each software application to be executed (APP), depending on the resources required for its execution, it is possible to determine, where applicable, a first part of the application (APP,1) which is executed locally, and a second part (APP,2). , complementary to the first part, to be executed by the remote ground computing system. In other words, local and remote resources are allocated for the execution of the same software application (APP). Thus, a criterion of availability of computing resources is implemented to determine the local or remote execution of each software application. Furthermore, the availability of communication bandwidth with the ground-based computing system is also taken into consideration. Thus, a connectivity criterion is considered. Indeed, for example, for software applications that use high-bandwidth data, such as video data, significant bandwidth is required for data processing by the remote computing system located on the ground. Furthermore, for a moving aircraft, communication conditions using the second radio communication protocol can vary depending on the aircraft's position, weather conditions, etc. Let us consider, for example, a drone for detecting and mapping obstacles such as electrical pylons, whose mission is to fly over a determined geographical area, detect obstacles of the "pylon" type, characterize them (width, height), geo-reference them (i.e. calculate their geographical position in a given reference frame), and deduce the network of electrical cables that connects them. Detection can be done using cameras mounted on the drone, whose resolution, field of view and shooting rate will have a direct impact on the need for resources: A video sequence in 4K definition / resolution, wide field, at 50 frames / sec will require, for example, much more storage resources (RAM / ROM) and CPU (or GPU) resources for its processing, than a low resolution video sequence (480p for example), or with a smaller field of view or at 25 frames / sec. Power consumption, and therefore the drone's autonomy, depends directly on CPU / RAM / ROM usage. In the case of a distributed calculation between the local application APP, 1, and the application to be executed by the remote ground computing system APP, >, the power consumption of the drone will also be a function of the communication bandwidth between the edge and the ground, and of the quality of the network, which conditions the means of communication used and the power needed to power the transmitting and receiving antennas. If the computing power (CPU / GPU) and / or storage capacity (RAM / ROM) is sufficient to process a 4K video sequence (criterion 1), and if the power consumption is compatible with the drone's flight time objectives (criterion 2), the system may choose to perform all mapping, detection, and geo- calculations. local referencing via the APP application, If the computing capacity (CPU / GPU) and / or storage (RAM / ROM) is insufficient to process a 4K video sequence (criterion 1), and if the power consumption is compatible with the drone's flight time objectives (criterion 2), the system may choose to have the mapping, detection and geo-referencing calculations performed locally by the APP application, by sending the images taken locally by the camera to the ground device. If the computing power (CPU / GPU) and / or storage capacity (RAM / ROM) is sufficient to process a 4K video sequence (criterion 1), but the power consumption is incompatible with the drone's flight time objectives (criterion 2), the system will be able to choose between several solutions: If electricity consumption is too high due to the processing of the all onboard images (CPU / RAM / ROM), but only the consumption The electrical cost for sending images to the ground is not too high (for example (in the case where the communication link is of good quality), the system will be able to choose to have part of the mapping calculations and detection and local georeferencing by the APP application, and a another part via the APP application, by sending a part of the images taken locally by the camera on the ground device. If the electricity consumption is not too high due to the processing of the all onboard images (CPU / RAM / ROM), but only the consumption The electrical current for sending images to the ground is too high (for example, in the (in cases where the communication link is of good quality), the system will be able to choose to have all mapping and detection calculations performed and local georeferencing via the APP application. There will be no sending images to the ground. If electricity consumption is too high due to the processing of the all onboard images (CPU / RAM / ROM), and that the consumption The electrical power required to send images to the ground is also too high (per (e.g., in the case where the communication link is of lower quality), the system will be able to choose to switch to a lower image resolution, or It's good to store the images for longer, while waiting to find a better bandwidth. If the computing capacity (CPU / GPU) and / or storage capacity (RAM / ROM) is in- sufficient to process a 4K video sequence (criterion 1), but that the electrical consumption is compatible with the flight duration objectives of the drone (criterion 2), the system will be able to choose to have all of the calculations by the APP application,,, by sending the images taken lo- camera feed to the ground device. Finally, if the computing capacity (CPU / GPU) and / or storage capacity (RAM / ROM) is insufficient to process a 4K video sequence (criterion 1), and that the electrical consumption is incompatible with the flight duration objectives of the drone (criterion 2), switch to a lower resolution and repeat the steps below. above. If there is no solution, even for the lowest possible resolution, the The system will be able to disable the APP application and record a message. error towards the ground. The first and second parts to be executed locally / remotely respectively are defined, for example, in terms of the percentage of code to be executed. In some cases, the first part is equal to 100% of the application to be executed, in which case there is no need to offload part of the execution to the ground computing system. Preferably, software applications are coded in such a way that they are executed in parts. In one embodiment, all or part of each software application is also pre-stored in the electronic memory 42 of the remote computing system 8, which facilitates the delegation of calculations. In one embodiment, a data criticality criterion is implemented to determine the second part APP, to be executed on the ground, thus avoiding the transmission of data or results considered sensitive or confidential to the ground computing system via the second transmission interface. Such data, considered confidential and therefore to be protected, includes, for example, data relating to aircraft performance, or confidential data of the client who owns the application to be executed (e.g., airline, institution, company). In particular, this helps to limit any transmission of data associated with a critical flight or mission phase. In the case where a second part of the software application is to be executed by the remote computing system, the process includes a remote execution request 62, including the transmission of associated information (e.g. execution point, data to be used, intermediate results). In one variant, in the absence of prior storage in an electronic memory unit of the remote computing system, the executable code forming the second part APP,2, complementary to the first part, to be executed by the remote computing system, is transmitted to the remote computing system during step 62. The remote computing system runs the second part of the APP, the lo- application. software (step 64), and transmits the results of the calculations to the on-board peripheral computing device (step 66). The peripheral computing device receives the results at step 68. In one embodiment, the results are consolidated at consolidation step 70. For example, consolidation involves the temporal and / or spatial synchronization of results, and / or a fusion of data, for example a fusion of inertial sensor data with positions calculated by software processing from image capture camera data. Following this consolidation step 70, the consolidated results are stored and / or transmitted (step 72) to the external control device, which initiates the execution of the software application. Figure 3 illustrates a second embodiment of the application execution process implemented in application execution system 2. In this second embodiment of the application execution process implemented in the application execution system 2, a supervisory device, which is either one of the external control devices or the remote ground computing system, implements real-time supervision of the operation of the onboard peripheral computing device. Preferably, the supervisory device is part of the remote ground computing system and includes a human-machine interface, allowing the display of information to an operator and the reception of commands from the operator. In this embodiment, in addition to all the steps described previously and which are not described again here, the process includes a supervision 80 implemented by the supervision device. The supervision 80 is performed continuously, the supervision device having a human-machine interface and being configured to receive observability signals from the peripheral computing device 20. In this embodiment, observability signals from the peripheral computing device, including data relating to local computing resources and information relating to the execution of at least one of the software applications, are transmitted to the monitoring device. The observability signals include, in particular, information relating to the use of local resources of the peripheral computing device and the application stack to be executed / currently being executed. The monitoring device is configured to calculate an operating state of the peripheral computing device and an execution state of the software application(s) from the observability signals received. The monitoring system then implements, for example, displays on The human-machine interface displays the operating status of the peripheral computing device (local resource status, connectivity) and the execution status of applications, optionally including data and results from these applications. In one embodiment, these displays track the operation of the peripheral computing device in near real-time. This allows an operator to define real-time execution priorities, enabling them to prioritize the execution of certain software applications and to lower the priority of or pause other software applications, and / or to modify resource allocations in real time. Commands relating to the execution priorities of software applications and / or changes to resource allocation are then transmitted via the monitoring device to the embedded peripheral computing device. In one embodiment, the monitoring extends to all on-board devices, including certified operating devices, thus enabling comprehensive monitoring of on-board resource utilization. Indeed, via the on-board peripheral computing device, data provided by sensors or on-board devices are also transmitted to the monitoring device for display. In addition, in either of the embodiments described above, it is planned to record, for example in execution reports (e.g. files, tables) or any other suitable data structure, in a suitable format, a set of status and execution information of the peripheral computing device and of the certified operating on-board electronic devices, as well as additional information including environmental information and connectivity information, over the entire duration of the aircraft mission. For example, the information set includes all the states of the execution stack, and the computing / hardware resources of the peripheral computing device, for example the software applications executed, the description of the computing resources allocated, the data and results, as well as additional information such as: the weather situation, the availability of communication interfaces, the bandwidth available for communications with the ground computing system, internal operating data of the systems, the energy consumption taken by each application, and by the other systems of the aircraft, the flight profile. The execution report(s) containing this set of information are transmitted to the ground-based monitoring device. These execution reports can then be used to perform a subsequent replay phase, executed on the ground by the monitoring system. The monitoring system is configured to display, in cooperation with graphical representation mechanisms on the human-machine interface, a complete sequence of the mission (replay), in particular of successive states of the peripheral computing device and, optionally, of the on-board electronic devices, which allows for maintenance and debugging operations. Among other things, such a replay phase also allows for recalculating the parameters provided in the initialization step 50, such as the minimum, maximum, or average allocation of the peripheral computing device's resources. Thanks to the application execution system described, the onboard hardware resources of an aircraft (computing resources, memory) are augmented dynamically and flexibly, and the implementation of client software applications is then possible, while ensuring execution security. Advantageously, an aircraft carrying a peripheral computing device as described can be used as a mobile means of data capture, like satellites. Advantageously, the invention makes it possible to perform calculations with complex algorithms, which would not be feasible by certified on-board devices due to the limitations imposed by the certifications. Advantageously, the flexibility introduced by the possibility of offloading parts of the execution of applications to the ground makes it possible to adapt to the constraints of the aircraft, in particular the constraints of onboard weight and electrical energy consumption.
Claims
Claims
1. Peripheral computing device on board an aircraft, comprising a first communication interface (22) configured to communicate, according to a first communication protocol, with one or more on-board electronic devices (12, 14) to function- certified operation, a second radio communication interface (24, 24A, 24B), configured to communicate, according to a second radio communication protocol, with at least one computing system remote (8) located on the ground, the peripheral computing device comprising at least one electronic memory unit (28) and at least one calculation processor (26) forming local calculation resources, characterized in that the calculation processor (26) is configured to im- supplement: - a module (30) for managing a plurality of software applications (APP,,APP,,APP,,APP;), said software applications being stored in said electronic memory (26), each software application being adapted to provide at least one control parameter and / or receive at least one data from at least one electronic device certified operating edge (12, 14); - a module (32) for activating the execution of at least one of said ap- stored software applications, configured to receive at least one request to execute at least one software application of a device external control (25) and / or to validate an activation condition execution of at least one software application, - a module (34) for managing an execution stack, configured to de- complete, for each software application to be executed, an allocation of local computing resources of said peripheral computing device to run all or part of said software application to be run, and to launch the local execution of the said part of the application to be executed and require, in the event that a first part of said application is executed locally, a remote execution, by the computing system remote (8), of a second part of the application to be executed, comple- commentary of the first part.
2. Device according to claim 1, wherein said module (34) of management of an execution stack implements, for the determination of local computing resources allocated per application to be executed, at at least one criterion from among: a criterion of availability of calculated resources latories, a connectivity criterion, a data protection criterion, a priority criterion.
3. Device according to one of claims 1 or 2, configured to receive dynamically, of an external control device (25), at least one computing resource allocation and / or connectivity parameter and / or an execution priority.
4. Device according to one of claims 1 to 3, further comprising a data and results management module (36), configured for consolidate and memorize results obtained by the execution of each software application, to communicate the results to the device external control module (25) and / or to the remote computing system (8).
5. Device according to one of claims 1 to 4, wherein said module management (30) of a plurality of software applications is configured to download new software applications or an update of a previously stored software application and / or delete a previously stored software application.
6. Electronic system for executing software applications comprising an on-board computing system (4) on an aircraft (6), and at least one remote computing system (8) located on the ground, the on-board computing system (4) comprising at least one on-board electronic device (12) with func- operation certified according to an avionics certification standard, and a A peripheral computing device (20) according to claims 1 to 5.
7. The system of claim 6, wherein the computing system remote also includes a supervision device, the device of supervision comprising a human-machine interface and being configured to receive observability signals from said peripheral computing device spherical, said observability signals comprising data relating to local computing resources and information relating to the execution of at least one of said software applications, and to calculate an operating state of said pe- calculating device peripheral and an execution state of said at least one lo- software from the received observability signals and to display said operating state and said execution state on said inter[ace man machine.
8. The system of claim 7, wherein the peripheral computing device spherical is configured to record, during an aircraft mission, a set of information in at least one execution report, including device status and execution information peripheral computing and on-board electronic devices to function- certified operation, as well as additional information including environmental information and information from connectivity, and to transmit said execution report to the device supervision, the supervision device being further configured to execute and display on the human-machine interface a replay of the states of the peripheral computing device and on-board electronic devices.
9. A method of executing software applications implemented by a electronic system for running compliant software applications to claims 6 to 8, characterized in that it comprises steps of: - reception (52) of command to add / delete lo- application software, from an external control device, or from a ground computing system or one of the on-board devices; -update (54) of a storage of software applications according to of said order received; - activation of execution (56) of one or more of the lo- applications stored software, based either on the reception of a request running at least one software application on a device external, or on the validation of an activation condition execution and / or pausing or stopping execution (58) of one or several software applications upon receipt of an order or va- automatic setting of a stop condition.
10. The method of claim 9, further comprising a step of application stack management (60), implementing, for each app- software application to be executed, an allocation of computing resources local to run a first part of the software application, and, in the event that said first part is less than 100%, a step of transmission of execution command of a second part of said software application, complementary to the first part, to the system remote computing.
11. | Computer program comprising software instructions which, when executed by a programmable electronic device, implement a method for executing software applications in accordance with claims 9 to 10.