Input / output management system for at least one avionics application and method for verifying the operation of such a system
The input/output management system for avionics applications employs similar hardware and software resources with integrated verification mechanisms to reduce development and maintenance costs, ensuring high integrity and low error probability in avionics systems.
Patent Information
- Application Number
- FR2023015096
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2043-12-22
AI Technical Summary
Existing avionics systems require significant development and maintenance costs due to the need for dissimilar hardware and software platforms to ensure high integrity, which is not efficiently addressed by current COM/MON techniques.
An input/output management system using similar hardware and software resources for both computing platforms, with integrated verification applications to ensure data integrity and asymmetrical use of primary stages, along with hardware and software monitoring modules for functional testing.
Reduces development and maintenance costs while maintaining high integrity by utilizing similar hardware and software resources with integrated verification mechanisms, ensuring low probability of undetected errors in avionics systems.
Smart Images

Figure 00000018_0000 
Figure 00000019_0000 
Figure 00000020_0000
Abstract
Description
Title of the invention: Input / output management system for at least one avionics application and method for verifying the operation of such a system
[0001] The present invention relates to an input / output management system for at least one avionics application.
[0002] The present invention also relates to a method for verifying the operation of such a system.
[0003] The field of the invention is that of avionics embedded in an aircraft.
[0004] In a manner known per se, there are several levels of criticality in this field according to the functions implemented by the avionics. Criticality is considered from both an integrity and an availability perspective.
[0005] Generally, flight control systems are among the most critical systems of an aircraft. These systems are generally responsible for:
[0006] - to acquire the inertial and dynamic state of the aircraft;
[0007] - to acquire the positions of the surfaces and / or the state of the motors the aircraft;
[0008] - develop new instructions for the position of surfaces and / or the state of motors following a set trajectory
[0009] It is therefore understood that an erroneous instruction, which would not be detected, for a given surface can lead to an irrecoverable imbalance of the aircraft.
[0010] A highly integrated system is a system whose probability of generating an undetected error is extremely low.
[0011] To obtain a highly integrated system, to date there are two main techniques using a command / monitor type distribution (or COMmand / MONitor in English or simply COM / MON) to ensure the demonstration that an isolated malfunction cannot generate an undetected error.
[0012] The first technique consists of using two dissimilar computing platforms, both in terms of hardware and software, and making application-level comparisons between two independent applications, called COMmand and MONitor, on the inputs consumed. In this way, producing a consistent error on the same functional input at the platform's boundaries is considered very unlikely. Indeed, it would require a hardware failure having the same effect, or a simultaneous and consistent hardware or software error on both dissimilar computing platforms, to somehow mislead the MONitor application, which performs the comparison between its own calculations and those carried out by the COMmand application. In the event of detection of a calculation discrepancy between the two applications a mechanism allows to inhibit the outputs calculated by the COMmand part.
[0013] The second technique consists of using two partially dissimilar computing platforms. In particular, the hardware resources of these platforms are identical, but their underlying software is different. The analysis or demonstration of the absence of common failures or errors then focuses solely on the hardware. This principle also relies on comparing, via the MONitor method, the commands calculated via the COMmand method.
[0014] Both techniques, however, have a number of drawbacks.
[0015] The first technique requires the development of two different types of platforms, both from a hardware perspective and from a basic software perspective. It therefore generates costs for development, but also for industrialization (supply, lower volume effects) and maintenance.
[0016] The second technique proves to be less restrictive than the first technique but nevertheless requires the development of two dissimilar basic software programs with the associated maintenance costs.
[0017] It is therefore understood that each of the two techniques requires significant development at least at the software level and therefore presents a significant development and maintenance cost.
[0018] The present invention aims to reduce the development, particularly software development, required to ensure the high integrity of a system. As a result, the invention reduces the associated cost.
[0019] To this end, the invention relates to an input / output management system for at least one avionics application configured to generate at least one integrated setpoint, the management system comprising at least two computing platforms implemented using similar hardware and software resources, one computing platform forming a command chain and the other forming a monitoring chain, each computing platform comprising:
[0020] - a primary stage configured to acquire analog signals and convert them in digital signals;
[0021] - an intermediate stage configured to digitally process bare signals merical by forming numerical data;
[0022] - a final stage configured to make available to the avionics application the numerical data;
[0023] the intermediate stage being further configured to encapsulate each processed digital data;
[0024] each computing platform further comprising a verification application configured to verify the encapsulation of each received data.
[0025] According to other advantageous aspects of the invention, the system comprises one or more of the following features taken individually or in all technically possible combinations:
[0026] - the encapsulation of each digital data item includes the formation of an aggregate including this data and at least one of the following:
[0027] - an authentication means for authenticating the origin of this given; and
[0028] - a dating method for dating this data and / or measuring its freshness;
[0029] - the encapsulation of each digital data point further includes the formation of a digital signature of all or part of the corresponding aggregate;
[0030] - the digital signature includes a CRC verification code.
[0031] - the verification application is configured to check at least one of the elements following for each piece of data received:
[0032] - the origin of this data;
[0033] - the integrity of this data;
[0034] - the dating of this data;
[0035] - the verification application is integrated into the final stage or into the application avionics;
[0036] - each computing platform further comprises:
[0037] - a hardware monitoring module configured to implement a function test operation of the primary, intermediate and final stages, by injecting predetermined test signals into the primary stage;
[0038] - a software monitoring module configured to acquire from the final stage digital data corresponding to the test signals injected by the hardware monitoring module into the primary stage, and to verify their correspondence to predetermined values;
[0039] - the primary stages of the different computing platforms are configured to be used asymmetrically;
[0040] - the primary stage of each computing platform includes a connector, a analog filtering module and an input signal conversion module;
[0041] The use of the primary stages of different computing platforms in an asymmetrical manner includes at least one of the following:
[0042] - allocation of different connection points between the different connectors;
[0043] - assignment of different routing paths and / or analog filters between the different analog filtering modules;
[0044] - asymmetrical use of the different signal conversion modules entry;
[0045] - the intermediate stage of each computing platform comprises a module digital acquisition, the digital acquisition modules of the different computing platforms being configured to be used asymmetrically;
[0046] - the predetermined test signals correspond to analog signals, digital signals or discrete signals;
[0047] - the software monitoring module is further configured to control the selection of test signals via the hardware monitoring module;
[0048] - the software monitoring module is configured to check the match of at least one of the following elements of the digital data acquired at predetermined values:
[0049] - authenticity;
[0050] - dating;
[0051] -integrity;
[0052] - expected value.
[0053] - the software monitoring and hardware monitoring modules are im implemented using different technologies independent of those of the primary, intermediate and final stages;
[0054] - the hardware monitoring module includes a monitoring function execution of the primary, intermediate and final stage functional tests, the software monitoring module being configured to periodically reactivate the monitoring function.
[0055] The invention also relates to a method for verifying the operation of a management system as defined above;
[0056] the process comprising the following steps:
[0057] - encapsulation of each digital data processed by the intermediate stage;
[0058] - verification of the encapsulation of each data received by the verification application fication.
[0059] Alternatively or optionally, the invention also relates to a method for verifying the operation of a management system as defined above;
[0060] the verification process comprising the following steps:
[0061] - injection into the primary stage of predetermined test signals;
[0062] - acquisition from the final stage of the digital data corresponding to test signals injected into the primary stage; and for
[0063] - verification of the correspondence of said numerical data to predetermined values finished.
[0064] The invention will become clearer upon reading the following description, given solely by way of non-limiting example and with reference to the drawings in which:
[0065] - [Fig. 1] [Fig. 1] is a schematic view of a management system according to the invention, the management system comprising at least two computing platforms;
[0066] - [Fig.2] [Fig.2] is a schematic view of one of the computing platforms of the [Fig. 1] ; and
[0067] - [Fig.3] [Fig.3] is a flowchart of a verification process according to the invention, the verification process being implemented by the management system of the [Fig.1],
[0068] We have indeed represented on [Fig.1] a management system 10 of inputs / outputs of at least one avionics application 12.
[0069] The avionics application 12 is configured to generate at least one integrated instruction intended for example for an avionics system.
[0070] By "integrated setpoint," we mean a setpoint whose probability of being an undetected erroneous setpoint is very low. This probability is, for example, less than 10⁹ when considering both the control and monitoring chains, as will be explained below.
[0071] Advantageously, the integrated instruction requirement applied to avionics application 12 is also accompanied by a "No single failure" requirement. This latter requirement necessitates demonstrating the absence of a common mode between the two control and monitoring chains.
[0072] The avionics application 12 thus implements the operation of a critical aircraft system, such as a flight control system.
[0073] The term "aircraft" means any flying machine that can be piloted at least partially automatically and / or manually. In the latter case, the aircraft can be piloted by a pilot from a cockpit (for example, in the case of an airplane or helicopter) or by a remote operator (for example, in the case of a drone).
[0074] Within the framework of a highly integrated system, the avionics application 12 implements a control chain 14A, also called COM chain, and a monitoring chain 14B, also called MON chain.
[0075] The monitoring chain 14B is intended to monitor the operation of the control chain 14A, using techniques known per se. These techniques may, for example, include comparing the outputs of the two chains 14A and 14B and, when these outputs differ, treating such a case as a malfunction.
[0076] The management system 10 includes at least two computing platforms 16A, 16B.
[0077] In particular, the management system 10 includes a computing platform 16A, 16B for each chain of the avionics application 12.
[0078] Each computing platform 16A, 16B allows the management of inputs and / or outputs of the corresponding chain 14A, 14B of application 12.
[0079] For example, each computing platform 16A, 16B is configured to receive data, for example in the form of analog signals, and to convert and deliver this data to the corresponding chain 14A, 14B of the avionics software 12. Each computing platform 16A, 16B is further configured to receive digital data from the corresponding chain 14A, 14B of the avionics software 12, and to convert and deliver this data to any interested system, for example in the form of analog signals.
[0080] In a manner analogous to the avionics application 12, one of these platforms 16A forms a command chain or simply a COM chain of the management system 10, and the other platform 16B forms a monitoring chain or simply a MON chain of the management system 10.
[0081] In the example of [Fig.1], the computing platform 16A forms the COM chain of the management system 10 and the computing platform 16B forms the MON chain of the management system 10. The computing platform 16A is therefore associated with the control chain 14A of the avionics application 12 and the computing platform 16B is associated with the monitoring chain 14B of the avionics application 12.
[0082] Other examples of the association of processing chains, their number and their manner of interaction are also possible.
[0083] Each computing platform 16A, 16B is defined by an identifier. Such an identifier may, for example, be a physical digital identifier with a signature. The identifiers of different computing platforms 16A, 16B are, for example, exchanged at system 10 startup for consistency verification.
[0084] According to the invention, the computing platforms 16A, 16B are implemented using similar hardware and software resources.
[0085] By "similar hardware and software resources" we mean resources implemented according to the same technology, particularly with regard to their production, composition, programming languages, operating algorithm, etc.
[0086] The computing platforms 16A, 16B are therefore analogous. Thus, subsequently, only one platform, for example platform 16A, will be explained in more detail with reference to [Fig.2].
[0087] Thus, as illustrated in [Fig.2], the computing platform 16 includes a primary stage 21 configured to acquire analog signals and convert them into digital signals, an intermediate stage 22 configured to digitally process the digital signals by forming digital data, and a final stage 23 configured to make the digital data available to the avionics application 12 and in particular to its corresponding chain 14A.
[0088] The composition of each of the floors 21 to 23 is described below with reference to [Fig.2]. However, it should be understood that other embodiments of these floors are also possible.
[0089] The primary stage 21 includes a connector 31, an analog filtering module 32 and an input signal conversion module 33.
[0090] Connector 31 allows the platform 16A to be connected to any interested system that produces / consumes data in the form of analog signals. For example, such a system has one or more sensors (e.g., position, pressure, speed sensors, etc.) or one or more controllable surfaces (e.g., surfaces used by flight controls).
[0091] To achieve this, the connector 31 has a plurality of connection points arranged, for example, on a physical medium according to a predetermined format. Each of these connection points is then capable of receiving / sending a sub-signal of a particular type. The set of transmitted / received sub-signals then forms the analog signal transmitted / received by the connector 31.
[0092] The analog filtering module 32 allows analog filtering to be applied to the received analog signals. This filtering may comprise one or more successive filters. For example, such filtering may form protective elements against environmental aggressions: lightning strikes, electromagnetic interference, etc.
[0093] The input signal conversion module 33 converts received and optionally filtered analog signals into digital signals, or shapes digital bus signals into signals usable by a digital core of the 16A platform. For this purpose, analog-to-digital converters and / or other shaping methods known per se can be used. The input signal conversion module 33 is therefore capable of receiving digital signals via one or more digital buses and analog signals via one or more analog inputs.
[0094] The intermediate stage 22 includes a digital acquisition module 41, a digital processing module 42, a storage area 43 and a communication bus 44.
[0095] The digital acquisition module 41 is connected to the input signal conversion module 33 by one or more buses and allows the acquisition of digital signals supplied by this conversion module 33. In particular, this module 41 allows three types of acquisition:
[0096] - the acquisition of digital input data on the various digital buses For example, this could involve legacy buses such as ARINC 429 or specific buses like RS485 or Ethernet serial lines. In the latter case, The arrival of digital data is asynchronous and unsolicited by module 41. To manage this asynchronicity, the digital acquisition module 41 can perform a technique called "polling". This technique is applied to all the buses to be managed quickly enough to avoid data loss.
[0097] - the acquisition of digital information corresponding to analog conversions Logical / digital. In this case, the acquisitions are controlled by the digital acquisition module 41, which manages the configuration, sequencing, and acquisition of the conversion. In other words, in this case, the acquisitions are performed synchronously.
[0098] - the acquisition of discrete inputs including a confirmation function of a change of state of a discrete input.
[0099] The digital processing module 42 is connected to the digital acquisition module 41 and allows the digital data acquired by this digital acquisition module 41 to be processed digitally.
[0100] This processing can be chosen according to the acquired numerical data and includes, for example:
[0101] - for data from conversion module 33, bare filtering processes metric methods for extracting physical values usable by applications; these processes may consist of more or less complex filters to ensure, for example:
[0102] - a signal conversion according to the type and level of precision expected;
[0103] - a specific additional filtering allowing applications running at low frequency of reading filtered values accordingly.
[0104] - protocol management processes typically for digital buses, processes that consist of extracting useful information from the signals according to the protocol chosen for these buses.
[0105] The storage area 43 allows for the at least temporary storage of digital data produced by the digital processing module 42. In particular, data after conversion corresponding to an input will most often be stored at a fixed address or in a data queue. The storage method is advantageously chosen according to the type of data (analog / digital conversion, protocol data, etc.) and / or the data acquisition method of the base software (direct access to the inputs by the software, software input / output server, etc.).
[0106] The communication bus 44 allows this data to be transmitted to the final stage 23.
[0107] In particular, this communication bus represents the physical interface between the software and hardware parts of the platform 16A. Data acquisition by the software is therefore carried out via this interface.
[0108] Advantageously, the operation of the digital acquisition module 41 and the storage area 43 is controlled by a plurality of parameters. These parameters are, for example, stored in a database 46 which is also part of the intermediate stage 22.
[0109] The final stage 23 includes a logical decomposition which can be chosen differently depending on the implementation chosen to perform the acquisitions by the software.
[0110] For example, in a "client-server" model, the final stage 23 includes an input acquisition process 51 which is asynchronous to the user and which acquires data from the communication bus 44 to store it in a buffer 52. The final stage 23 further includes a client service 53 enabling the avionics application 12 to acquire data from the buffer 52 asynchronously.
[0111] In another model, the elements 51, 52, 53 can be seen as a single element constituting the final stage 23.
[0112] According to the invention, the computing platforms 16A, 16B implement at least one of four mechanisms to ensure the integrity of the inputs to the avionics application 12 provided by the management system 10. It should be noted that each of the mechanisms can be implemented independently of each other.
[0113] According to a first mechanism, each of the computing platforms 16A, 16B further comprises a hardware monitoring module 61 and a software monitoring module 62. These modules 61, 62 will be explained below with reference to the computing platform 16A and in particular to [Fig.2].
[0114] The hardware monitoring module 61 is configured to implement a functional test of the set of stages 21, 22, 23, by injecting predetermined test signals into the primary stage 21.
[0115] To do this, the hardware monitoring module 61 is connected to the primary stage 21 and in particular to the input signal conversion module 31, to inject the corresponding test signals into this module 31.
[0116] The predetermined test signals correspond to analog signals, digital signals or discrete signals.
[0117] In particular, the test signals in the form of digital signals can include any type of digital data received on one or more buses reserved as input to the input signal conversion module 33. The test signals in the form of digital signals make it possible to cover all possible values on one or more digital buses to verify the correct decoding of any value in particular by the input signal conversion module 33 and the correct processing by the digital processing module 42.
[0118] Test signals in the form of analog signals may include any type of analog data possible on one or more analog inputs of the input signal conversion module 33. The test signals in the form of analog signals allow to cover all analog values to check the different types of digital filtering implemented by the digital processing module 42.
[0119] The test signals in the form of discrete signals allow testing of the digital acquisition module 41 and confirmation of input discretes in this module.
[0120] The software monitoring module 62 is configured to acquire digital data from the output stage 23 corresponding to the test signals injected by the hardware monitoring module 61 into the primary stage 21, and to verify their correspondence to predetermined values. In particular, these predetermined values are determined from the test signals injected by the module 61 and are, for example, stored in the software monitoring module 62.
[0121] More specifically, the software monitoring module 62 is configured to check at least one of the following elements of the acquired digital data:
[0122] - authenticity;
[0123] - dating;
[0124] - integrity;
[0125] - expected value.
[0126] To acquire the corresponding digital data, the software monitoring module 62 is connected to the final stage 23 and in particular to the customer service 53 in the embodiment example of [Fig.2].
[0127] The software monitoring module 62 is further configured to control the selection of test signals by the hardware monitoring module 61.
[0128] The software monitoring modules 62 and hardware monitoring modules 61 are implemented using different and independent technologies from those of the primary 21, intermediate 22 and final 23 stages.
[0129] In particular, the hardware monitoring module 61 is implemented in a digital component that is totally independent of each of the following elements:
[0130] - the communication bus 44;
[0131] - the digital processing module 42;
[0132] - storage area 43;
[0133] - the 4L digital acquisition module
[0134] The software monitoring module 62 is implemented in a software component independent of the software components of the final stage 23 and in particular of the input acquisition process 51 and the customer service 53.
[0135] Finally, the hardware monitoring module 61 includes a function for monitoring the execution of functional tests of the primary stage 21, intermediate stage 22 and final 23. The software monitoring module 62 is configured to periodically reactivate this monitoring function in order to perform functional tests of stages 21 to 23.
[0136] According to a second mechanism, the intermediate stage 22 of each of the computing platforms 16A, 16B allows for the encapsulation of each digital data acquired and processed respectively by the digital acquisition module 41 and the digital processing module 42. This encapsulation is carried out in such a way as to be able to verify at least one of the following elements:
[0137] - the origin of this data (i.e. the digital acquisition module 41 or the digital processing module 42);
[0138] - the integrity of this data (particularly during its transmission between the module of digital processing 42 and its reception by an application);
[0139] - the dating of this data (in particular for example its freshness).
[0140] This verification is carried out for example by a verification application 65 integrated into the final stage 23 (for example in the customer service 53) or in the avionics application 12, as illustrated in [Fig.2].
[0141] The encapsulation of each data item is done, for example, by the digital processing module 42, for example, by forming an aggregate comprising this data item (i.e., useful data) and at least one of the following elements:
[0142] - an authentication means for authenticating the origin of this given; and
[0143] - a dating method allowing this data to be dated and / or its freshness.
[0144] The authentication means includes, for example, one or more data corresponding to an identifier of the entity that produced the corresponding data.
[0145] The dating means includes, for example, one or more data points corresponding to the production date of the corresponding data point.
[0146] The encapsulation of each digital data item may further include the formation of a digital signature of all or part of the aggregate comprising that data (for example, only the authentication means and / or the time-tracing means). The digital signature may correspond to a CRC verification code and may be included in the aggregate for transmission with the data.
[0147] Thus, upon receipt of each data item, the verification application 65 is configured to verify the origin, integrity, and freshness of the received data. Integrity is verified using the digital signature.
[0148] The verification application 65 can further be configured to perform a decapsulation of the corresponding data. In other words, the verification application 65 can further be configured to extract the useful data from each cor- aggregate responding and then to transmit it to the corresponding application.
[0149] The second mechanism allows in particular:
[0150] - to authenticate data from a digital bus after protocol decoding and add a digital signature to this data to verify the complete integrity of the data at the application level;
[0151] - to authenticate digital data resulting from digital filtering (conversion of analog values) and add a digital signature to this data to verify the complete integrity of the data at the application level;
[0152] - to ensure that data is not static and with consistent refreshing of system refresh time 10.
[0153] This mechanism therefore makes it possible to cover an error which could be introduced by the storage area 43, the communication bus 44 and possibly, by the input acquisition process 51, the buffer memory 52 and the client service 53.
[0154] According to a third mechanism, the primary stages 21 of the different computing platforms 16A, 16B are configured to be used asymmetrically.
[0155] In particular, such asymmetrical use includes at least one of the following:
[0156] - allocation of different connection points between the different connectors 31;
[0157] - assignment of different routing paths and / or analog filters between the different analog filtering modules 32;
[0158] - asymmetrical use of the different input signal conversion modules 33.
[0159] More specifically, this last element may include the asymmetrical use of the different buses / inputs used by these modules 33.
[0160] Advantageously, the asymmetrical use of the primary stages 21 includes at least two of the aforementioned elements.
[0161] According to a fourth mechanism, the digital acquisition modules 41 of the different computing platforms 16A, 16B are configured to be used asymmetrically.
[0162] This asymmetry can be introduced into the sequencing of the acquisitions of signals from the input signal conversion module 33 between the different computing platforms 16A, 16B. This sequencing consists, for example:
[0163] - to perform the acquisitions by the input signal conversion module 33 on the digital buses;
[0164] - to perform the analog / digital conversions by the conversion module input signals 33.
[0165] This sequencing can be done in a different order in the different computing platforms 16A, 16B.
[0166] A method for verifying the operation of the management system 10 will now be explained with reference to [Fig.3] showing an organizational chart of its steps.
[0167] This method comprises implementing the first and second mechanisms independently of each other. Thus, only one of these two mechanisms may be implemented. Furthermore, the third and / or fourth mechanisms are considered to be implemented optionally during the execution of this method.
[0168] In particular, the implementation of the first mechanism includes steps 110 to 130 and the implementation of the second mechanism includes steps 210 to 220, explained below.
[0169] During step 110, the hardware monitoring module 61 injects predetermined test signals into the primary stage 21. As explained previously, the selection of these signals can be made by the software monitoring module 62.
[0170] Furthermore, depending on the nature of these signals, they can be injected via digital buses or analog inputs of the input signal conversion module 33.
[0171] The injected signals then pass through the intermediate stage 22 and the final stage 23.
[0172] During the next step 120, the software monitoring module 62 acquires the digital data corresponding to the test signals injected and then transmitted through stages 22 and 23.
[0173] During the next step 130, the software monitoring module 62 checks the correspondence of these acquired digital data to predetermined values.
[0174] In particular, as explained previously, these predetermined values can verify the authenticity, dating, integrity and / or expected value of the acquired digital data.
[0175] During step 210, the intermediate stage 22 and in particular the digital processing module 42 encapsulates each data acquired by the digital acquisition module 41 and possibly processed by module 42.
[0176] As explained previously, this encapsulation includes, in particular, the addition of an authentication method and / or a timestamping method. The encapsulation may further include the addition of a digital signature.
[0177] Then, the encapsulated data passes through the rest of the intermediate stage 22 and the final stage 23.
[0178] In the next step 220, the verification application 65 receives the encapsulated data and verifies its encapsulation. In particular, this verification may include verifying the authenticity and / or freshness and / or integrity of this data.
[0179] Then, the verification application 65 may perform a decapsulation of the data (i.e., extraction of the useful data from the corresponding aggregate) before transmit this data to the avionics application 12.
[0180] It is therefore understood that the present invention has a number of advantages.
[0181] In particular, the management system according to the invention implements at least one The aforementioned mechanisms allow for verification of the integrity of each piece of data provided to the avionics application. In some examples, the management system may implement at least two mechanisms, or at least three mechanisms. In yet other examples, the management system implements all four mechanisms.
[0182] This allows the various computing platforms constituting such a system to be implemented in a similar way at the hardware and software level. This thus makes it possible to considerably reduce the development and maintenance costs of such computing platforms.
[0183] Of course, other examples of implementation of the management system as claimed are also possible.
[0184]
Claims
Demands
1. Input / output management system (10) of at least one avionics application (12) configured to generate at least one integrated setpoint, the management system (10) comprising at least two computing platforms (16A, 16B) implemented using similar hardware and software resources, one of the computing platforms (16A, 16B) forming a control chain and the other forming a monitoring chain, each computing platform (16A, 16B) comprising: - a primary stage (21) configured to acquire analog signals and convert them into digital signals; - an intermediate stage (22) configured to digitally process the digital signals by forming digital data; - a final stage (23) configured to make the digital data available to the avionics application (12); the intermediate stage (22) being further configured to encapsulate each processed digital data;each computing platform (16A, 16B) further comprising a verification application (65) configured to verify the encapsulation of each received data.;
2. System (10) according to claim 1, wherein the encapsulation of each digital data includes the formation of an aggregate comprising this data and at least one of the following: - an authentication means enabling the origin of this data to be authenticated; and - a dating means enabling the data to be dated and / or its freshness to be measured.
3. System (10) according to claim 2, wherein the encapsulation of each digital data further comprises the formation of a digital signature of all or part of the corresponding aggregate.
4. System (10) according to claim 3, wherein the digital signature includes a CRC verification code.
5. System (10) according to any one of the preceding claims, wherein the verification application (65) is configured to verify at least one of the following elements of each data received: - the origin of this data; - the integrity of this data; - the date of this data.
6. System (10) according to any one of the preceding claims, wherein the verification application (65) is integrated into the final stage (23) or into the avionics application (12).
7. System (10) according to any one of the preceding claims, wherein each computing platform (16A, 16B) further comprises: - a hardware monitoring module (61) configured to implement a functional test of the primary (21), intermediate (22) and final (23) stages, by injecting predetermined test signals into the primary stage (21); - a software monitoring module (62) configured to acquire from the final stage (23) digital data corresponding to the test signals injected by the hardware monitoring module (61) into the primary stage (21), and to verify their correspondence to predetermined values.
8. System (10) according to any one of the preceding claims, wherein the primary stages (21) of the different computing platforms (16A, 16B) are configured to be used asymmetrically.
9. System (10) according to claim 8, wherein the primary stage (21) of each computing platform comprises a connector (31), an analog filtering module (32) and an input signal conversion module (33); the use of the primary stages (21) of the different computing platforms (16A, 16B) in an asymmetrical manner comprises at least one of the following: - allocation of different connection points between the different connectors (31); - allocation of different routing paths and / or analog filters between the different analog filtering modules (32); - asymmetrical use of the different input signal conversion modules (33).
10. System (10) according to any one of the preceding claims, wherein the intermediate stage (22) of each computing platform (16A, 16B) comprises a digital acquisition module (41), the digital acquisition modules (41) of the different computing platforms (16A, 16B) being configured to be used asymmetrically.
11. Method for verifying the operation of a management system (10) according to any one of the preceding claims; The process includes the following steps: - encapsulation of each digital data processed by the intermediate stage (22); - verification of the encapsulation of each data received by the verification application (65).