Input / output management system for at least one avionics application and method for verifying the operation of such a system

The input/output management system for avionics applications addresses the high development and maintenance costs of current systems by using similar hardware and software resources for command and monitoring chains, ensuring high integrity through integrated verification mechanisms.

FR3157583A1Active Publication Date: 2025-06-27THALES SA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
FR2023015099
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-22
Publication Date
2025-06-27
Estimated Expiration
2043-12-22

AI Technical Summary

Technical Problem

Current input/output management systems for avionics applications require significant software development and maintenance costs due to the need for dissimilar hardware and software platforms to ensure high integrity and availability.

Method used

An input/output management system utilizing two calculation platforms with similar hardware and software resources, one forming a command chain and the other a monitoring chain, with hardware and software monitoring modules to verify the integrity of digital data through test signals and digital signatures.

Benefits of technology

This approach reduces development and maintenance costs while ensuring high integrity of avionics systems by implementing mechanisms for verifying the authenticity, integrity, and freshness of digital data, thereby minimizing the risk of undetected errors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Input / output management system of at least one avionics application and method for verifying the operation of such a system The present invention relates to an input / output management system of at least one avionics application (12) comprising at least two computing platforms (16A) implemented using similar hardware and software resources, each platform comprising: - a primary stage (21) configured to acquire analog signals; - an intermediate stage (22) configured to digitally process digital signals; - a final stage (23) configured to make digital data available to the avionics application (12); - a hardware monitoring module (61) configured to implement an operational test, by injecting predetermined test signals into the primary stage (21);- a software monitoring module (62) configured to acquire digital data corresponding to the injected test signals, and to verify their correspondence to predetermined values. Figure for abstract: Figure 2;
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Input / output management system for at least one avionics application and method for verifying the operation of such a system

[0001] The present invention relates to an input / output management system for at least one avionics application.

[0002] The present invention also relates to a method for verifying the operation of such a system.

[0003] The field of the invention is that of avionics on board an aircraft.

[0004] As is known per se, there are several levels of criticality in this field. depending on the functions implemented by the avionics. Criticality is considered from both an integrity and an availability point of view.

[0005] Generally, flight control systems are among the most critical of an aircraft. These systems are generally responsible for:

[0006] - acquiring the inertial and dynamic state of the aircraft;

[0007] - acquire the positions of the surfaces and / or the state of the motors of the aircraft;

[0008] - develop new position instructions for the surfaces and / or the state of the motors according to a set trajectory to follow,

[0009] It is therefore understood that an erroneous instruction, which would not be detected, for a given surface can lead to an irrecoverable imbalance of the aircraft.

[0010] A highly integrated system is a system whose probability of generating an undetected error is extremely low.

[0011] To obtain a highly integrated system, to date, there are two main techniques using a command / monitoring type distribution (or COMmand / MONitor in English or simply COM / MON) to ensure the demonstration that an isolated malfunction cannot generate an undetected error.

[0012] The first technique consists of using two computing platforms that are dissimilar both at the hardware and software level and making comparisons at the application level between two independent applications called COMmand and MONitor on the consumed inputs. In this way, producing a coherent error on the same functional input at the platform terminals is considered very unlikely. It would indeed take a hardware failure having the same effect or a simultaneous and coherent hardware or software error on the two dissimilar computing platforms to somehow trick the MONitor application which ensures the comparison between its own calculations and those carried out by the COMmand application. In the event of detection of a calculation discrepancy between the two applications a mechanism allows to inhibit the outputs calculated by the COMmand part.

[0013] The second technique consists of using two partially dissimilar computing platforms. In particular, the hardware resources of these platforms are identical but their basic software is different. The analysis or demonstration of the absence of a common failure or error then relates only to the hardware scope. This principle is also based on the comparison by the MONitor channel of the commands calculated by the COMmand channel.

[0014] However, both techniques have a number of drawbacks.

[0015] The first technique requires the development of two different types of platforms from both a hardware and a basic software point of view. It is therefore a source of costs for development but also for industrialization (supply, lower volume effect) and maintenance.

[0016] The second technique proves to be less restrictive than the first technique but nevertheless requires the development of two dissimilar basic software programs with the associated maintenance costs.

[0017] It is then understood that each of the two techniques requires significant development at least at the software level and therefore presents a significant development and maintenance cost.

[0018] The present invention aims to reduce the development, in particular software development, necessary to ensure the high integrity of a system. As a result, the invention makes it possible to reduce the associated cost.

[0019] For this purpose, the invention relates to an input / output management system for at least one avionics application configured to generate at least one integrated instruction, the management system comprising at least two calculation platforms implemented using similar hardware and software resources, one of the calculation platforms forming a command chain and the other forming a monitoring chain, each calculation platform comprising:

[0020] - a primary stage configured to acquire analog signals and convert them in digital signals;

[0021] - an intermediate stage configured to digitally process the signals merics by forming digital data;

[0022] - a final stage configured to make available to the avionics application the digital data;

[0023] - a hardware monitoring module configured to implement a function test operation of the primary, intermediate and final stages, by injecting predetermined test signals into the primary stage;

[0024] - a software monitoring module configured to acquire from the final stage digital data corresponding to the test signals injected by the hardware monitoring module into the primary stage, and to verify their correspondence to predetermined values.

[0025] According to other advantageous aspects of the invention, the system comprises one or more of the following characteristics taken in isolation or in all technically possible combinations:

[0026] - the predetermined test signals correspond to analog signals, digital signals or discrete signals;

[0027] - the software monitoring module is further configured to control the choice of test signals by the hardware monitoring module;

[0028] - the software monitoring module is configured to check for correspondence of at least one of the following elements of the acquired digital data to predetermined values:

[0029] - authenticity;

[0030] - dating;

[0031] -integrity;

[0032] - expected value.

[0033] - the software monitoring and hardware monitoring modules are im implemented using different technologies independent of those of the primary, intermediate and final stages;

[0034] - the hardware monitoring module comprises a monitoring function performing operational tests of the primary, intermediate and final stages, the software monitoring module being configured to periodically reactivate the monitoring function;

[0035] - the primary stages of the different computing platforms are configured to be used asymmetrically.

[0036] - the primary stage of each computing platform comprises a connector, a analog filtering module and an input signal conversion module;

[0037] the use of the primary stages of the different computing platforms in an asymmetric manner comprises at least one of the following elements:

[0038] - allocation of different connection points between the different connectors;

[0039] - allocation of different routing paths and / or analog filters between the various analog filtering modules;

[0040] - asymmetrical use of the different signal conversion modules entrance;

[0041] - the intermediate stage of each computing platform comprises a module digital acquisition, the digital acquisition modules of the different computing platforms being configured to be used asymmetrically;

[0042] - the use of digital acquisition modules of the dif calculation platforms asymmetrically differing includes different sequencing between acquisitions on digital buses and analog / digital conversions;

[0043] - the intermediate stage of each computing platform comprises a module of digital processing configured to encapsulate each digital data in such a way as to be able to:

[0044] - verify the origin of this data by the other modules of the platform;

[0045] - verify the integrity of this data by the other modules of the platform;

[0046] - verify the dating of this data using the other modules of the platform.

[0047] - the intermediate stage is further configured to encapsulate each data digitally processed;

[0048] each computing platform further comprising a verification application configured to verify the encapsulation of each received data;

[0049] - the encapsulation of each digital data comprises the formation of an aggregate including this data and at least one of the following elements:

[0050] - an authentication means making it possible to authenticate the origin of this given; and

[0051] - a dating means making it possible to date this data and / or to measure its freshness;

[0052] - the encapsulation of each digital data further comprises the formation of a digital signature of all or part of the corresponding aggregate;

[0053] - the digital signature includes a CRC verification code;

[0054] - the verification application is configured to verify at least one of the elements following of each data received:

[0055] - the origin of this data;

[0056] - the integrity of this data;

[0057] - the dating of this data.

[0058] - the verification application is integrated into the final stage or into the application avionics.

[0059] The invention also relates to a method for verifying the operation of a management system as defined previously;

[0060] the verification method comprising the following steps:

[0061] - injection into the primary stage of the predetermined test signals;

[0062] - acquisition from the final stage of the digital data corresponding to the test signals injected into the primary stage; and for

[0063] - verification of the correspondence of said digital data to predefined values completed.

[0064] Alternatively or in addition, the invention relates to a verification method operation of a management system as defined above;

[0065] the method comprising the following steps:

[0066] - encapsulation of each digital data processed by the intermediate stage;

[0067] - verification of the encapsulation of each data received by the verification application information.

[0068] The invention will appear more clearly on reading the description which follows, given solely by way of non-limiting example and made with reference to the drawings in which:

[0069] - [Fig.l] [Fig.l] is a schematic view of a management system according to the invention, the management system comprising at least two computing platforms;

[0070] - [Fig.2] [Fig.2] is a schematic view of one of the computing platforms of the [Fig.l] ; and

[0071] - [Fig.3] [Fig.3] is a flowchart of a verification method according to the invention, the verification method being implemented by the management system of [Fig.l],

[0072] [Fig.l] in fact shows a system 10 for managing inputs / outputs of at least one avionics application 12.

[0073] The avionics application 12 is configured to generate at least one integrated instruction intended for example for an avionics system.

[0074] By "integrated instruction" is meant an instruction whose probability of being an undetected erroneous instruction is very low. This probability is for example less than 109 considering the two control and monitoring chains, as will be explained below.

[0075] Advantageously, the integrated instruction requirement applied to the avionics application 12 is also accompanied by a “No single failure” requirement meaning in French “No fault”. This latter requirement requires the demonstration of the absence of a common mode between the two control and monitoring chains.

[0076] The avionics application 12 thus implements the operation of a critical system of an aircraft, such as for example a flight control system.

[0077] By "aircraft" is meant any flying machine that can be piloted at least partially automatically and / or manually. In the latter case, the piloting of the aircraft can be carried out by a pilot from a cockpit thereof (for example in the case of an airplane or a helicopter) or by a remote operator (for example in the case of a drone).

[0078] In the context of a highly integrated system, the avionics application 12 implements a command chain 14A, also called COM chain, and a monitoring chain 14B, also called MON chain.

[0079] The purpose of the monitoring chain 14B is to monitor the operation of the control chain 14A, according to techniques known per se. These techniques may for example include a comparison of the outputs of the two chains 14A, 14B and when these outputs differ, treating such a case as a malfunction.

[0080] The management system 10 comprises at least two computing platforms 16A, 16B.

[0081] In particular, the management system 10 comprises a computing platform 16A, 16B for each chain of the avionics application 12.

[0082] Each calculation platform 16A, 16B makes it possible to manage the inputs and / or outputs of the corresponding chain 14A, 14B of the application 12.

[0083] For example, each computing platform 16A, 16B is configured to receive data, for example in the form of analog signals, and to convert and deliver this data to the corresponding chain 14A, 14B of the avionics software 12. Each computing platform 16A, 16B is further configured to receive digital data from the corresponding chain 14A, 14B of the avionics software 12, and to convert and deliver this data to any system concerned, for example in the form of analog signals.

[0084] In a similar manner to the avionics application 12, one of these platforms 16A forms a command chain or simply a COM chain of the management system 10, and the other platform 16B forms a monitoring chain or simply a MON chain of the management system 10.

[0085] In the example of [Fig. 1], the calculation platform 16A forms the COM chain of the management system 10 and the calculation platform 16B forms the MON chain of the management system 10. The calculation platform 16A is therefore associated with the command chain 14A of the avionics application 12 and the calculation platform 16B is associated with the monitoring chain 14B of the avionics application 12.

[0086] Other examples of association of processing chains, their number and their manner of interaction are also possible.

[0087] Each computing platform 16A, 16B is defined by an identifier. Such an identifier has, for example, a hardware digital identifier with a signature. The identifiers of different computing platforms 16A, 16B are, for example, exchanged at the start of the system 10 for a consistency check.

[0088] According to the invention, the computing platforms 16A, 16B are implemented using similar hardware and software resources.

[0089] By “similar hardware and software resources” is meant resources implemented using the same technology, in particular with regard to their production, composition, programming languages, operating algorithm, etc.

[0090] The computing platforms 16A, 16B are therefore analogous. Thus, subsequently, only one platform, for example the platform 16A, will be explained in more detail in reference to [Fig.2].

[0091] Thus, as illustrated in [Fig.2], the computing platform 16 comprises a primary stage 21 configured to acquire analog signals and convert them into digital signals, an intermediate stage 22 configured to digitally process the digital signals by forming digital data, and a final stage 23 configured to make the digital data available to the avionics application 12 and in particular to its corresponding chain 14A.

[0092] The composition of each of the stages 21 to 23 is described below with reference to [Fig.2]. However, it should be understood that other examples of embodiment of these stages are also possible.

[0093] The primary stage 21 comprises a connector 31, an analog filtering module 32 and an input signal conversion module 33.

[0094] The connector 31 makes it possible to connect the platform 16A to any interested system producing / consuming data, in the form of analog signals. For example, such a system has one or more sensors (for example position, pressure, speed sensor, etc.) or one or more controllable surfaces (for example surfaces used by the flight controls).

[0095] To do this, the connector 31 has a plurality of connection points arranged for example on a physical medium according to a predetermined format. Each of these connection points is then capable of receiving / sending a sub-signal of a particular type. All of the sub-signals transmitted / received then form the analog signal transmitted / received by the connector 31.

[0096] The analog filtering module 32 makes it possible to apply analog filtering to the received analog signals. This filtering may comprise one or more successive filters. For example, such filtering may form elements of protection against environmental attacks: lightning attacks, electromagnetic disturbances in particular, etc.

[0097] The input signal conversion module 33 makes it possible to convert the received and possibly filtered analog signals into digital signals or to format digital bus signals into signals usable by a digital core of the platform 16A. For this, analog / digital converters and / or other shaping means known per se can be used. The input signal conversion module 33 is therefore capable of receiving digital signals via one or more digital buses and analog signals via one or more analog inputs.

[0098] The intermediate stage 22 comprises a digital acquisition module 41, a digital processing module 42, a storage area 43 and a communication bus 44.

[0099] The digital acquisition module 41 is connected to the input signal conversion module 33 by one or more buses and makes it possible to acquire the digital signals supplied by this conversion module 33. In particular, this module 41 makes it possible to carry out three types of acquisition:

[0100] - acquisitions of digital data input on the various digital buses ; for example, it may be a “legacy” bus of the ARINC 429 type or specific buses such as serial lines of the RS485 or Ethernet type. In the latter case, the arrival of digital data is done asynchronously and not requested by this module 41. To manage this asynchronism, the digital acquisition module 41 can perform a technique called “polling”. This technique is applied to all the buses to be managed quickly enough to avoid data loss.

[0101] - acquisitions of digital information corresponding to analog conversions logical / digital. In this case, the acquisitions are controlled by the digital acquisition module 41 which manages the configuration, sequencing and acquisition of the conversion. In other words, in this case, the acquisitions are done synchronously.

[0102] - acquisitions of discrete inputs including a confirmation function of a change of state of a discrete input.

[0103] The digital processing module 42 is connected to the digital acquisition module 41 and makes it possible to digitally process the digital data acquired by this digital acquisition module 4L.

[0104] This processing can be chosen according to the digital data acquired and includes for example:

[0105] - for the data from the conversion module 33, bare filtering treatments merics to carry out the extraction of physical values ​​usable by applications; these treatments can consist of more or less complex filters to ensure for example:

[0106] - a signal conversion according to the type and level of precision expected;

[0107] - specific additional filtering allowing applications running at low frequency of reading filtered values ​​accordingly.

[0108] - protocol management treatments typically for digital buses, processing which consists of extracting useful information from the signals according to the protocol chosen for these buses.

[0109] The storage area 43 makes it possible to store at least temporarily the digital data produced by the digital processing module 42. In particular, most often a piece of data after conversion corresponding to an input will be stored at a fixed address or in a data file. The storage method is chosen before carefully depending on the type of data (analog / digital conversion, protocol data, etc.) and / or the data acquisition mode by the basic software (direct access to inputs by the software, input / output software server, etc.).

[0110] The communication bus 44 makes it possible to transmit this data to the final stage 23.

[0111] In particular, this communication bus represents the physical interface between the software and hardware part of the platform 16A. Data acquisitions by the software are therefore carried out via this interface.

[0112] Advantageously, the operation of the digital acquisition module 41 and the storage area 43 is controlled by a plurality of parameters. These parameters are for example stored in a database 46 also forming part of the intermediate stage 22.

[0113] The final stage 23 comprises a logical decomposition which can be chosen differently depending on the implementation chosen to carry out the acquisitions by the software.

[0114] For example, in a “client-server” model, the final stage 23 comprises an input acquisition process 51 which is asynchronous with the user and which acquires the data from the communication bus 44 to store them in a buffer memory 52. ​​The final stage 23 further comprises a client service 53 allowing the avionics application 12 to acquire the data from the buffer memory 52 asynchronously.

[0115] In another model, the elements 51, 52, 53 can be seen as a single element then constituting the final stage 23.

[0116] According to the invention, the computing platforms 16A, 16B implement at least one of the four mechanisms for making the inputs of the avionics application 12 provided by the management system 10 integral. It should be noted that each of the mechanisms can be implemented independently of each other.

[0117] According to a first mechanism, each of the computing platforms 16A, 16B further comprises a hardware monitoring module 61 and a software monitoring module 62. These modules 61, 62 will be explained below with reference to the computing platform 16A and in particular to [Fig.2].

[0118] The hardware monitoring module 61 is configured to implement an operational test of all of the stages 21, 22, 23, by injecting predetermined test signals into the primary stage 21.

[0119] To do this, the hardware monitoring module 61 is connected to the primary stage 21 and in particular to the input signal conversion module 31, to inject the corresponding test signals into this module 31.

[0120] The predetermined test signals correspond to analog signals, digital signals or discrete signals.

[0121] In particular, the test signals in the form of digital signals may include any type of digital data received on one or more buses reserved at the input of the input signal conversion module 33. The test signals in the form of digital signals make it possible to cover all possible values ​​on one or more digital buses to verify the correct decoding of any value in particular by the input signal conversion module 33 and the correct processing by the digital processing module 42.

[0122] The test signals in the form of analog signals can comprise any type of possible analog data on one or more analog inputs of the input signal conversion module 33. The test signals in the form of analog signals make it possible to cover all analog values ​​to verify the different types of digital filtering implemented by the digital processing module 42.

[0123] The test signals in the form of discrete signals make it possible to test the digital acquisition module 41 and to confirm input discretes in this module.

[0124] The software monitoring module 62 is configured to acquire from the final stage 23 digital data corresponding to the test signals injected by the hardware monitoring module 61 into the primary stage 21, and to verify their correspondence to predetermined values. In particular, these predetermined values ​​are determined from the test signals injected by the module 61 and are for example stored in the software monitoring module 62.

[0125] Even more particularly, the software monitoring module 62 is configured to verify at least one of the following elements of the acquired digital data:

[0126] - authenticity;

[0127] - dating;

[0128] - integrity;

[0129] - expected value.

[0130] To acquire the corresponding digital data, the software monitoring module 62 is connected to the final stage 23 and in particular to the customer service 53 in the exemplary embodiment of [Fig.2].

[0131] The software monitoring module 62 is further configured to control the selection of test signals by the hardware monitoring module 61.

[0132] The software monitoring modules 62 and hardware monitoring 61 are implemented using technologies that are different and independent from those of the primary 21, intermediate 22 and final 23 stages.

[0133] In particular, the hardware monitoring module 61 is implemented in a digital component completely independent of each of the following elements:

[0134] - the communication bus 44;

[0135] - the digital processing module 42;

[0136] - storage area 43;

[0137] - the digital acquisition module 41.

[0138] The software monitoring module 62 is implemented in a software component independent of the software components of the final stage 23 and in particular of the input acquisition process 51 and of the customer service 53.

[0139] Finally, the hardware monitoring module 61 comprises a function for monitoring the execution of the operating tests of the primary 21, intermediate 22 and final 23 stages. The software monitoring module 62 is configured to periodically reactivate this monitoring function in order to carry out operating tests of the stages 21 to 23.

[0140] According to a second mechanism, the intermediate stage 22 of each of the calculation platforms 16A, 16B makes it possible to encapsulate each digital data item acquired and processed respectively by the digital acquisition module 41 and the digital processing module 42. This encapsulation is done in such a way as to be able to verify at least one of the following elements:

[0141] - the origin of this data (i.e. the digital acquisition module 41 or the digital processing module 42);

[0142] - the integrity of this data (in particular during its transmission between the module of digital processing 42 and its reception by an application);

[0143] - the dating of this data (in particular, for example, its freshness).

[0144] This verification is carried out for example by a verification application 65 integrated in the final stage 23 (for example in the customer service 53) or in the avionics application 12, as illustrated in [Fig.2].

[0145] The encapsulation of each data item is done for example by the digital processing module 42, for example, by forming an aggregate comprising this data item (i.e. useful data item) and at least one of the following elements:

[0146] - a means of authentication making it possible to authenticate the origin of this given; and

[0147] - a dating means making it possible to date this data and / or to measure its freshness.

[0148] The authentication means comprises for example one or more data corresponding to an identifier of the entity having produced the corresponding data.

[0149] The dating means comprises for example one or more data corresponding to the date of production of the corresponding data.

[0150] The encapsulation of each digital data item may further comprise the formation of a digital signature of all or part of the aggregate comprising this data item (for example only the authentication means and / or the dating means). The digital signature may correspond to a CRC verification code and may be included in the aggregate to be transmitted with the data.

[0151] Thus, upon receipt of each data item, the verification application 65 is configured to verify the origin, integrity and freshness of the received data item. The integrity is verified using the digital signature.

[0152] The verification application 65 may further be configured to perform a decapsulation of the corresponding data. In other words, the verification application 65 may further be configured to extract the useful data from each corresponding aggregate and then transmit it to the corresponding application.

[0153] The second mechanism allows in particular:

[0154] - to authenticate data from a digital bus after protocol decoding and add a digital signature to this data to verify the complete integrity of the data at the application level;

[0155] - to authenticate digital data resulting from digital filtering (conversion of analog values) and add a digital signature to this data to verify the complete integrity of the data at the application level;

[0156] - to ensure that data is not frozen and with consistent refreshing of the system refresh time 10.

[0157] This mechanism therefore makes it possible to cover an error which could be introduced by the storage area 43, the communication bus 44 and possibly, by the input acquisition process 51, the buffer memory 52 and the customer service 53.

[0158] According to a third mechanism, the primary stages 21 of the different computing platforms 16A, 16B are configured to be used asymmetrically.

[0159] In particular, such use in an asymmetrical manner comprises at least one of the following elements:

[0160] - allocation of different connection points between the different connectors 31;

[0161] - allocation of different routing paths and / or analog filters between the various 32 analog filter modules;

[0162] - asymmetrical use of the different input signal conversion modules 33.

[0163] More particularly, this latter element may include the asymmetrical use of the different buses / inputs used by these modules 33.

[0164] Advantageously, the asymmetrical use of the primary stages 21 comprises at least two of the aforementioned elements.

[0165] According to a fourth mechanism, the digital acquisition modules 41 of the different computing platforms 16A, 16B are configured to be used asymmetrically.

[0166] This asymmetry can be introduced into the sequencing of the acquisitions of the signals from the input signal conversion module 33 between the different computing platforms 16A, 16B. This sequencing consists for example of:

[0167] - to make the acquisitions by the input signal conversion module 33 on the digital buses;

[0168] - to perform analog / digital conversions by the conversion module of input signals 33.

[0169] This sequencing can be done in a different order in the different computing platforms 16A, 16B.

[0170] A method for verifying the operation of the management system 10 will now be explained with reference to [Fig.3] showing a flowchart of its steps.

[0171] This method comprises implementing the first mechanism and the second mechanism independently of each other. Thus, only one of these two mechanisms can be implemented. It is further considered that the third mechanism and / or the fourth mechanism is (are) implemented optionally when executing this method.

[0172] In particular, the implementation of the first mechanism comprises steps 110 to 130 and the implementation of the second mechanism comprises steps 210 to 220, explained below.

[0173] During step 110, the hardware monitoring module 61 injects predetermined test signals into the primary stage 21. As explained previously, the choice of these signals can be made by the software monitoring module 62.

[0174] Furthermore, depending on the nature of these signals, they can be injected via digital buses or analog inputs of the input signal conversion module 33.

[0175] The injected signals then pass through the intermediate stage 22 and the final stage 23.

[0176] During the following step 120, the software monitoring module 62 acquires the digital data corresponding to the test signals injected and then passed through the stages 22 and 23.

[0177] During the following step 130, the software monitoring module 62 verifies the correspondence of these acquired digital data to predetermined values.

[0178] In particular, as explained above, these predetermined values ​​can verify the authenticity, dating, integrity and / or expected value of the acquired digital data.

[0179] During step 210, the intermediate stage 22 and in particular the digital processing module 42 encapsulates each piece of data acquired by the digital acquisition module 41 and possibly processed by the module 42.

[0180] As explained previously, this encapsulation notably comprises the addition of an authentication means and / or a dating means. The encapsulation may further comprise the addition of a digital signature.

[0181] Then, the encapsulated data passes through the rest of the intermediate stage 22 and the final stage 23.

[0182] During the following step 220, the verification application 65 receives the encapsulated data and verifies its encapsulation. In particular, this verification may comprise the verification of the authenticity and / or the freshness and / or the integrity of this data.

[0183] Then, the verification application 65 possibly decapsulates the data (i.e. extraction of the useful data from the corresponding aggregate) before transmitting this data to the avionics application 12.

[0184] It is then understood that the present invention presents a certain number of advantages.

[0185] In particular, the management system according to the invention implements at least one of the aforementioned mechanisms for proving the integrity of each data provided to the avionics application. In some examples, the management system may implement at least two mechanisms or at least three mechanisms. In some examples, the management system implements all four mechanisms.

[0186] This then makes it possible to implement the different computing platforms constituting such a system in a similar manner at the hardware and software level. This thus makes it possible to considerably reduce the cost of developing and maintaining such computing platforms.

[0187] Of course, other examples of embodiment of the management system as claimed are also possible.

Claims

Claims

1. Input / output management system (10) of at least one avionics application (12) configured to generate at least one integrated instruction, the management system (10) comprising at least two computing platforms (16A, 16B) implemented using similar hardware and software resources, one of the computing platforms (16A, 16B) forming a command chain and the other forming a monitoring chain, each computing platform (16A, 16B) comprising: - a primary stage (21) configured to acquire analog signals and convert them into digital signals; - an intermediate stage (22) configured to digitally process the digital signals by forming digital data; - a final stage (23) configured to make the digital data available to the avionics application (12);- a hardware monitoring module (61) configured to implement an operational test of the primary (21), intermediate (22) and final (23) stages, by injecting into the primary stage (21) predetermined test signals; - a software monitoring module (62) configured to acquire from the final stage (23) digital data corresponding to the test signals injected by the hardware monitoring module (61) into the primary stage (21), and to verify their correspondence to predetermined values.;

2. The system (10) of claim 1, wherein the predetermined test signals correspond to analog signals, digital signals, or discrete signals.

3. The system (10) of claim 1 or 2, wherein the software monitoring module (62) is further configured to control the selection of test signals by the hardware monitoring module (61).

4. System (10) according to any one of the preceding claims, wherein the software monitoring module (62) is configured to verify the correspondence of at least one of the following elements of the acquired digital data to predetermined values: - authenticity; - dating; - integrity; - expected value.

5. System (10) according to any one of the preceding claims, in which the software monitoring (62) and hardware monitoring (61) modules are implemented according to technologies different and independent from those of the primary (21), intermediate (22) and final (23) stages.

6. System (10) according to any one of the preceding claims, wherein the hardware monitoring module (61) comprises a function for monitoring the execution of the operational tests of the primary (21), intermediate (22) and final (23) stages, the software monitoring module (62) being configured to periodically reactivate the monitoring function.

7. System (10) according to any one of the preceding claims, wherein the primary stages (21) of the different computing platforms (16A, 16B) are configured to be used asymmetrically.

8. System (10) according to claim 7, wherein the primary stage (21) of each computing platform comprises a connector (31), an analog filtering module (32) and an input signal conversion module (33); the use of the primary stages (21) of the different computing platforms (16A, 16B) in an asymmetric manner comprises at least one of the following elements: - allocation of different connection points between the different connectors (31); - allocation of different routing paths and / or analog filters between the different analog filtering modules (32); - asymmetric use of the different input signal conversion modules (33).

9. System (10) according to any one of the preceding claims, wherein the intermediate stage (22) of each computing platform (16A, 16B) comprises a digital acquisition module (41), the digital acquisition modules (41) of the different computing platforms (16A, 16B) being configured to be used asymmetrically.

10. System (10) according to claim 9, in which the use of the digital acquisition modules (41) of the different computing platforms (16A, 16B) in an asymmetric manner comprises a different sequencing between the acquisitions on digital buses and the conversions analog / digital.

11. System (10) according to any one of the preceding claims, wherein the intermediate stage (22) of each computing platform (16A, 16B) comprises a digital processing module (42) configured to encapsulate each digital data so as to be able to: - verify the origin of this data using other modules of the platform; - verify the integrity of this data by the other modules of the platform; - check the dating of this data using other modules of the platform.

12. Method for verifying the operation of a management system (10) according to any one of the preceding claims; the verification process comprising the following steps: - injection into the primary stage (21) of the predetermined test signals; - acquisition from the final stage (23) of the digital data corresponding to the test signals injected into the primary stage (21); and for - verification of the correspondence of said digital data to predetermined values.

Citation Information

Patent Citations

  • Method for monitoring the execution of a graphical calculation and display chain associated with an aircraft cockpit display screen

    EP4027244A1

  • System and method for testing an aircraft flight control computer.

    FR3092411A1

  • Semiconductor device

    US20190155680A1