COMPUTING UNIT OF AN AIRCRAFT FLIGHT CONTROL SYSTEM, AND CORRESPONDING COMPUTING PLATFORM AND AIRCRAFT.
The computing unit architecture with multiple partitions and schedulers addresses inefficiencies in aircraft flight control systems by enabling parallel execution and reduced adaptation, improving design efficiency and performance.
Patent Information
- Application Number
- FR2024001945
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-28
- Publication Date
- 2025-08-29
AI Technical Summary
Existing flight control systems for aircraft require extensive redevelopment, verification, and certification for each new aircraft program, leading to inefficiencies in design and operation.
A computing unit architecture with multiple partitions and schedulers, along with input/output management and communication blocks, allows for parallel execution and reduced adaptation needs across different aircraft programs.
Facilitates the design of computing platforms by minimizing the need for redevelopment and certification, while enhancing flight control function execution and control loop performance.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: COMPUTING UNIT OF AN AIRCRAFT FLIGHT CONTROL SYSTEM, AND CORRESPONDING COMPUTING PLATFORM AND AIRCRAFT. Technical field
[0001] The field of the invention is that of aircraft flight control systems (or FCS for "Flight Control Systems" in English), also sometimes called flight control systems.
[0002] More specifically, the present invention relates to a computing unit of such a flight control system. The present invention also relates to a computing platform of such a flight control system, comprising a pair of computing units. STATE OF PRIOR ART
[0003] The flight control system of an aircraft generally comprises several calculation units which are included and executed on several calculation platforms, also called "flight control computer" or "flight control computer" (or FCC for "Flight Control Computer" in English) which are "avionics computers".
[0004] In a first known architecture, a computing platform comprises a pair of computing units, often called COM and MON (for "Command" and "Monitoring" in English respectively), the first (COM computing unit) acting in command mode and the second (MON computing unit) acting in monitoring mode of the first.
[0005] In a second known architecture, a computing platform comprises a single computing unit. The computing platforms are distributed in COM / MON pairs, the first (COM computing platform) acting in command mode and the second (MON computing platform) acting in monitoring mode of the first.
[0006] The present invention applies in particular with the two aforementioned known architectures.
[0007] The computing units can communicate with each other. More specifically, there are communications between computing units hosted by the same computing platform, as well as communications between computing units hosted by different computing platforms. For this purpose, the aircraft comprises one or more communication networks for which there are different standards (for example ARINC 664 part 7 (AFDX), Ethernet, ARINC 429 (often simply called A429), etc.).
[0008] Conventionally, each computing unit comprises a single partition. The computing unit implements flight control functions (also called "lo functions"). avionics software"), for example to control actuators of a control surface. The computing unit includes control loops. In a particular implementation, the computing platform also offers a synchronization service between the computing units that the computing platform hosts.
[0009] In summary, conventionally, the flight control system (FCS) of the aircraft comprises one or more computing platforms (FCC). Each computing platform comprises one or more computing units which perform flight control functions.
[0010] In the state of the art, each computing platform (FCC) of a flight control system is a dedicated product for a specific aircraft program. For each new aircraft program, it is currently necessary to perform several operations: - redevelop, with a dedicated team, each computing platform (FCC) of the flight control system; - carry out new dedicated verification and control activities; - carry out new dedicated certification activities; - update a dissimilarity strategy; - design dedicated specifications; - etc.
[0011] It is desirable to provide a solution to facilitate the design of the computing platforms (FCC) of a flight control system, by avoiding or limiting the aforementioned operations for each new aircraft program.
[0012] It is also desirable that the solution provided makes it possible to favor, in terms of execution, certain flight control functions as well as certain control loops. Statement of the invention
[0013] An object of the present invention is to propose a calculation unit of a flight control system of an aircraft, comprising:
[0014] - a top layer comprising:
[0015] * a first set of partitions, comprising partitions which are associated each at a first priority level and which each perform at least a first flight control function; and
[0016] * a first scheduler, carrying out a scheduling of the partitions of the first set, each partition of the first set being repeated by the first scheduler with a first frequency; and
[0017] - an intermediate layer comprising:
[0018] * an input / output management block providing the partitions of the first set with a access to at least one aircraft interface;
[0019] * a first communication block between partitions, allowing each partition of the first set of communicating, via a first dedicated communication channel or via at least one first communication network of the aircraft, with at least one other partition associated with the first priority level and included in another computing unit of the aircraft; and
[0020] * a second scheduler, managing the latency of data flows exchanged between on the one hand the partitions of the first set and on the other hand the input / output management block and the first communication block between partitions.
[0021] Thus, the proposed architecture, with the high layer (comprising the first set of partitions and the first scheduler) and the intermediate layer (comprising the input / output management block, the first inter-partition communication block and the second scheduler), allows operation with multiple partitions ("multipartition operation"), with several partitions of the first set being executed in parallel. Furthermore, this architecture is generic and requires few adaptations for the design of the computing platforms (and the computing units included therein) for each new aircraft program. It therefore makes it possible to facilitate the design of the computing platforms (FCC) of a flight control system, by avoiding or limiting the aforementioned operations of the state of the art.
[0022] According to a particular embodiment, the upper layer further comprises:
[0023] * a second set of partitions, comprising partitions which are associated each at a second priority level, higher than the first priority level, and which each perform at least one second flight control function; and
[0024] * a third scheduler, carrying out a scheduling of the partitions of the second set, each partition of the second set being repeated by the second scheduler with a second frequency that is greater than the first repetition frequency of each partition of the first set;
[0025] the intermediate layer further comprises:
[0026] * a second communication block between partitions, allowing each partition of the second set to communicate, via a second dedicated communication channel or via at least one second communication network of the aircraft, with at least one other partition associated with the second priority level and included in another computing unit of the aircraft;
[0027] the input / output management block further provides the partitions of the second set with access to said at least one interface of the aircraft,
[0028] and the second scheduler also manages the latency of exchanged data flows between on the one hand the partitions of the second set and on the other hand the input / output management block and the second communication block between partitions.
[0029] According to a particular embodiment, the first scheduler and the second scheduler are synchronized with each other.
[0030] According to a particular embodiment, the first scheduler and the third scheduler are synchronized with each other.
[0031] According to a particular embodiment, the input / output management block comprises:
[0032] * a first input / output management sub-block providing the partitions of the first together a first access to said at least one interface of the aircraft; and
[0033] * a second input / output management sub-block providing partitions of the second set a second access to said at least one interface of the aircraft.
[0034] According to a particular embodiment, at least some of the partitions of the first and second sets comprise at least one control loop, each control loop benefiting from the first or second repetition frequency of the partition in which said control loop is included.
[0035] According to a particular embodiment, the input / output management block or the high layer comprises at least one first other control loop which has access to said at least one interface of the aircraft, which is repeated with a third frequency higher than the second frequency, and which can communicate with the partitions of the second set.
[0036] According to a particular embodiment, the input / output management block comprises at least one second other control loop, which is repeated with a fourth frequency higher than the third frequency. Furthermore, said at least one first other control loop accesses said at least one interface of the aircraft via said at least one second other control loop.
[0037] According to a particular embodiment, each partition associated with the first priority level is a partition of a first type, called a user partition, or a partition of a second type, called a system partition, which corresponds to at least one service offered to partitions of the first type. Furthermore, each partition associated with the second priority level is a partition of the first type.
[0038] According to a particular embodiment, the upper layer is configured to perform a communication service between partitions, allowing the partitions of the first set to communicate, via at least one memory interface, with the partitions of the second set.
[0039] Also provided is a computing platform for an aircraft, comprising a pair of computing units such as that discussed above (in any of its embodiments), a first of the two computing units acting in control and a second of the two computing units acting in monitoring mode of the first computing unit.
[0040] Also provided is an aircraft comprising a flight control system comprising at least two computing units such as that mentioned above (in any of its embodiments).
[0041] According to a particular embodiment, the flight control system comprises at least two computing platforms such as that mentioned above. In addition, the partitions of the first sets of computing units of the at least two platforms communicate with each other via the first communication services of said computing units. Brief description of the drawings
[0042] The characteristics of the invention mentioned above, as well as others, will appear more clearly on reading the following description of at least one exemplary embodiment, said description being made in relation to the attached drawings, among which:
[0043] [Fig.l] schematically illustrates, in side view, an aircraft equipped with a flight control system;
[0044] [Fig.2] schematically illustrates the flight control system, in one embodiment;
[0045] [Fig.3] schematically illustrates an example of hardware architecture of a computing platform included in the flight control system, in one embodiment;
[0046] [Fig.4] schematically illustrates a computing unit included in a computing platform, in a first embodiment;
[0047] [Fig.5] schematically illustrates a block, included in the intermediate layer of the calculation unit and performing a first communication service between partitions, according to one embodiment;
[0048] [Fig.6] schematically illustrates a block, included in the intermediate layer of the calculation unit and performing an input / output management service, according to one embodiment;
[0049] [Fig.7] schematically illustrates a block, included in the intermediate layer of the computing unit and performing a second communication service between partitions, according to one embodiment;
[0050] [Fig.8] schematically illustrates a computing unit included in a computing platform, in a second embodiment; and
[0051] [Fig.9] schematically illustrates a computing unit included in a computing platform, in a third embodiment.
[0052] DETAILED DESCRIPTION OF EMBODIMENTS
[0053] [Fig.l] schematically illustrates, in side view, an aircraft 100 equipped with a flight control system (FCS) 101. The flight control system 101 is an on-board electronic equipment. For example, it is part of an electronic circuitry of the avionics of the aircraft 100.
[0054] The flight control system 101 is schematically illustrated in [Fig. 2], in an embodiment in which it comprises N computing platforms referenced 202-1 to 202-N. Each computing platform comprises a pair of computing units (“Dual Unit Mode”): one, named COM (for “Command”) and referenced 203-A, acts in command mode and the other, named MON (for “Monitoring”) and referenced 203-B, acts in monitoring mode of the COM computing unit. The computing units of the same platform can communicate on the one hand with each other, as illustrated by the arrow referenced 204, and on the other hand with the computing units of the other platforms, as illustrated by the arrows referenced 205 and 206.
[0055] It will be noted that the present invention also applies in the case where the flight control system 101 comprises a single computing platform (“Single Unit Mode”).
[0056] It will also be noted that the present invention also applies in the case where each computing platform comprises a single computing unit. In this case, the computing platforms (and therefore the computing units) can be distributed in COM / MON pairs.
[0057] [Fig. 3] schematically illustrates an example of hardware architecture of a computing platform (generically referenced 202 and corresponding to one of the platforms 202-1 to 202-N of [Fig. 2]) included in the flight control system 101, in one embodiment.
[0058] In this embodiment, the computing platform 202 comprises, connected by a communication bus 310: a processor or CPU (Central Processing Unit) 301; a RAM (Random Access Memory) 302; a ROM (Read Only Memory) 303, for example a Flash memory; a data storage device, such as a hard disk HDD (Hard Disk Drive), or a storage media reader, such as an SD (Secure Digital) card reader 304; at least one communication interface 305 allowing the computing platform 202 to interact in the avionics of the aircraft 100.
[0059] The processor 301 is capable of executing instructions loaded into the RAM 302 from the ROM 303, from an external memory (not shown), from a storage medium, such as an SD card, or from a communication network (not shown). When the computing platform 202 is powered on, the processor 301 is capable of reading instructions from RAM 302 and executing them. These instructions form a computer program causing the processor 301 to implement the behaviors described herein. Alternatively, the instructions are executed directly from ROM 303.
[0060] All or part of the behaviors described herein may thus be implemented in software form by executing a set of instructions by a programmable machine, such as a DSP (Digital Signal Processor) or a microcontroller, or be implemented in hardware form by a machine or a dedicated component (chip) or a set of components (chipset), such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit). Generally speaking, the computing platform 202 comprises electronic circuitry arranged and configured to implement the behaviors described herein.
[0061] [Fig.4] schematically illustrates a computing unit (generically referenced 203 and corresponding to one of the computing units 203-A (COM) and 203-B (MON) of [Fig.2]) included in a computing platform 202, in a first embodiment.
[0062] The computing unit 203 comprises a high layer 401 and an intermediate layer 402.
[0063] The upper layer 401 comprises partitions performing flight control functions (avionics software functions) and comprising control loops. More specifically, in the embodiment presented, the upper layer comprises two sets of partitions 4011 and 4012. Each partition of the first set 4011 is associated with a first priority level and performs at least a first flight control function. Each partition of the second set 4012 is associated with a second priority level, higher than the first priority level, and performs at least a second flight control function.
[0064] In the embodiment presented, the first set 4011 comprises two subsets of partitions. The first subset comprises partitions 4011a of a first type, called PU user partitions (also called “application partitions” or “aircraft partitions”). The second subset comprises partitions 4011b of a second type, called PS system partitions. The PS system partitions correspond to services offered to the PU user partitions. For example, data loading is a service offered to the user partitions. In the embodiment presented, each partition 4012a of the second set 4012 is a PU user partition.
[0065] In the illustrated embodiment, the upper layer 401 is configured to perform a communication service (illustrated by the arrow referenced 413) between partitions, allowing the partition(s) of the first set 4011 to communicate, for example via at least one memory interface, with the partition(s) of the second set 4012.
[0066] In a variant not illustrated, the upper layer comprises one or more sets of additional partitions (for example a third set of partitions). Each additional set comprises partitions associated with the same priority level which is different from the priority levels associated with the partitions of the other sets (for example the first and second sets).
[0067] The upper layer 401 also comprises two schedulers. One, named “scheduler A” and referenced 4013, performs a scheduling of the partitions of the first set. These are for example related to the primary flight control system (PFCS for “Primary Flight Control System” in English), to the secondary flight control system (HLS for “High Lift System” in English), to the autopilot system (AFS for “Automatic Flight System” in English), etc. The other, named “scheduler B” and referenced 4014, performs a scheduling of the partitions of the second set. These are for example related to the control surface servo functions, to the critical organ monitoring functions, etc.
[0068] Each partition of the first set 4011 is repeated by the scheduler A 4013 with a first frequency FL. Each partition of the second set 4012 is repeated by the scheduler B 4014 with a second frequency F2 which is higher than the first frequency. In particular implementations, the first frequency Fl is less than or equal to 200 Hz and the second frequency F2 is between 500 Hz and 2 kHz. For example, Fl = 200 Hz and F2 = 1 kHz.
[0069] Thus, the partitions 4012a of the second set 4012 are favored, in terms of execution, compared to those 4011a and 4011b of the first set 4011 since the second frequency F2 is higher than the first frequency FL. By favoring the partitions of the second set, the flight control functions and the control loops included in these partitions of the second set are favored. A partition of the second set can be called a “fast partition”, by comparison with a partition of the first set which can be called a “slow partition”. Similarly, a control loop included in a fast partition can be called a “fast control loop” and a control loop included in a slow partition can be called a “slow control loop”.In other words, the performance (especially end-to-end latencies) of the fast 4012a partitions and fast control loops is improved compared to the slow 4011a and 4011b partitions and slow control loops.
[0070] The intermediate layer 402 comprises several entities: another scheduler (referenced 4020 and named “scheduler C”), an input / output management block (illustrated by the block referenced 4022 and named “I / O Manager”), a first block of communication between partitions (illustrated by the block referenced 4021 and named “SCI”) and a second block of communication between partitions (illustrated by the block referenced 4021 and named “SC2”).
[0071] The intermediate layer 402 is also configured to perform one or more types of synchronization. An intra-computing unit synchronization corresponds to the real-time clock (RTC for "Real Time Clock") of the platform which hosts the computing unit. The intra-computing unit synchronization is useful for guaranteeing a proven latency acquisition for a critical interface of the aircraft (for example the flight control sensors). An inter-computing unit synchronization corresponds to a synchronization between partitions of a pair of computing units (COM / MON) hosted by the same computing platform ("Dual Unit Mode"). The inter-computing unit synchronization is not managed in the case where each computing platform comprises a single computing unit ("Single Unit Mode").
[0072] The input / output management block 4022 provides the partitions of the first and second sets 4011 and 4012 with access to at least one interface 404 of the aircraft. This is illustrated by the arrows referenced 407 and 411, for the partitions of the first set 4011, and by the arrows referenced 408 and 411, for the partitions of the second set 4012. The interfaces 404 of the aircraft correspond, for example, to the overall physical interfaces of the aircraft, including in particular the analog sensors (which provide data) and the control surface actuators (which receive commands) accessible via at least one bus or network (for example, ARINC 429 bus, CAN bus, discrete signals, analog signals, etc.).Preferably, for analog sensors, the 4022 input / output management service is configured to manage sensors with proven latency, by guaranteeing an access and partitioning policy (access to a sensor can be private (dedicated to a partition) or shared between partitions). And preferably, for actuators and commands (actuator commands, sensor excitations, switch commands, etc.), the 4022 input / output management service is configured to manage strong partitioning and commands with proven latency (a command cannot be shared between several partitions).
[0073] The first inter-partition communication block 4021 allows each partition of the first set 4011 to communicate, via a first dedicated communication channel or via at least one first communication network 403 of the aircraft (as illustrated by the arrows referenced 406 and 410), with at least one other partition associated with the first priority level and included in another calculation unit of the aircraft. This other computing unit is included on the same computing platform as the computing unit 203 discussed (case illustrated by the arrow referenced 204 in [Fig.2]) or on another computing platform (case illustrated by the arrows referenced 205 and 206 in [Fig.2]). In the case of shared access to a first communication network 403, the first communication service 4021 manages an access policy (bandwidth allocation, partitioning, data integrity, etc.).
[0074] Thanks to the first communication block 4021 implemented in each of the calculation units of the calculation platform(s), all the slow partitions (i.e. associated with the first priority level) of the different calculation units can communicate with each other, either via intra-calculation platform communications (case of communication between two slow partitions included in two calculation units (203-A and 203-B for example) hosted by the same calculation platform (202-1 for example)), or via inter-calculation platform communications (case of communication between two slow partitions included in two calculation units hosted by two distinct calculation platforms (202-1 and 202-2 for example)).
[0075] The second inter-partition communication block 4023 allows each partition of the second set 4012 to communicate, via a second dedicated communication channel or via at least one second communication network 405 of the aircraft (as illustrated by the arrows referenced 409 and 412), with at least one other partition associated with the second priority level and included in another computing unit of the aircraft. This other computing unit is included on the same computing platform as the computing unit 203 discussed (case illustrated by the arrow referenced 204 in [Fig. 2]) or on another computing platform (case illustrated by the arrows referenced 205 and 206 in [Fig. 2]). In the case of shared access to a second communication network 405, the second communication block 4023 manages an access policy (bandwidth allocation, partitioning, data integrity, etc.).
[0076] Thanks to the second communication block 4023 implemented in each of the calculation units of the calculation platform(s), all the partitions associated with the second priority level (fast partitions) can communicate with each other, via intra-calculation platform communications or via inter-calculation platform communications.
[0077] The scheduler C (4020) manages the latency for different data flows from or to the partitions (i.e. guarantees the latency of the information received and sent by the partitions of the first and second sets 4011 and 4012), for example: - data flows exchanged between the partitions of the first set 4011 and the input / output management block 4022; - data flows exchanged between the partitions of the first set 4011 and the first communication block between partitions 4021; - data flow exchanged between the partitions of the second set 4012 and the input / output management block 4022; and - data flows exchanged between the partitions of the second set 4012 and the second communication block between partitions 4023.
[0078] In some implementations, the scheduler C comprises several sub-schedulers each managing one or more types of flows. For example, in the implementation illustrated in [Fig. 4], the sub-scheduler C1 manages the latency of the data flows exchanged between the partitions of the first set 4011 and the first communication block 4021, the sub-scheduler C2 manages the latency of the data flows exchanged between the partitions of the first and second sets 4011 and 4012 and the input / output management block 4022, and the sub-scheduler C3 manages the latency of the data flows exchanged between the partitions of the second set 4012 and the second communication block 4023.
[0079] In a particular implementation, depending on the aircraft 100 and the quantity of interfaces to be managed 404, the sub-scheduler C2 itself comprises several sub-schedulers C2a, C2b, ... (see for example below the description of [Fig.8]). In this case, the sub-schedulers C2a, C2b, ... are synchronized with each other.
[0080] The three schedulers A, B and C (4013, 4014 and 4020) being independent, there are embodiments in which one or more additional mechanisms are put in place to guarantee the exchanges between the main entities (first set of partitions 4011, second set of partitions 4012, first communication block 4021, input / output management block 4022 and second communication block 4023). This is for example one or more of the following mechanisms: - the basic clocks of the schedulers A, B and C are stable over time; - the environments of the main entities guarantee partitioning robust temporal on interfaces; - the partitions of the first and second sets 4011 and 4012 and the input / output management block 4022 have digital filters to prevent spectrum folding phenomena; - in a COM / MON implementation (see [Fig.2]), the scheduler A (respectively B) of the high layer 401 of the computing unit 203-A is synchronized with the scheduler A (respectively B) of the high layer 401 of the computing unit 203-B; - the schedulers A and B of the high layer 401 are synchronized with each other (whether or not remaining independent of the scheduler C of the intermediate layer 402); - each of the schedulers A and B of the high layer 401 is synchronized with the scheduler C of the intermediate layer 402; - etc.
[0081] [Fig.5] schematically illustrates an exemplary embodiment of the communication block 4021, included in the intermediate layer 402 of the calculation unit 202 and performing a communication service between slow partitions.
[0082] Block 4021 itself comprises a “Network Server” block 501 (also called “NTW_SERVER”) and a “Switch” block 502 (“also called “Switch”).
[0083] The “Network Server” block 501 allows a slow partition of the first set 4011 to access:
[0084] - via a first type of connection (symbolized by the arrow referenced 503; by example an ARINC 429 bus or an RS 485 bus for communication with high latency, low bandwidth and no configuration (point-to-point)), to a slow partition of the other computing unit hosted by the same computing platform as that hosting the described computing unit 203; or
[0085] - via a second type of connection (symbolized by the arrow referenced 504; by example an AFDX network or a generic Ethernet network with the ability to offer configuration, low latency and high bandwidth), to a slow partition hosted by another platform.
[0086] The “Switch” block 502 is configured to extend the connection capabilities of the “Server-Network” block (switch with improved characteristics to manage high quality of service (“High QoS”) with medium latency and medium bandwidth) and allow a slow partition of the first set 4011 to access:
[0087] - via a third type of connection (symbolized by the arrow referenced 505 and more efficient than the first type of connection symbolized by the arrow referenced 503), to a slow partition of the other computing unit hosted by the same computing platform as that hosting the computing unit described; or
[0088] - via a fourth type of connection (symbolized by the arrow referenced 506 and more efficient than the second type of connection symbolized by the arrow referenced 504) to a slow partition hosted by another platform.
[0089] [Fig.6] schematically illustrates an exemplary embodiment of the input / output management block 4022, included in the intermediate layer 402 of the calculation unit.
[0090] Block 4022 itself comprises:
[0091] - an “I / O-Server” block 601 (also called “IO-SERVER”) which provides the partitions of the first and second sets 4011 and 4012 access to the interface(s) 404 of the aircraft (this is illustrated by the arrows referenced 407, 605 and 606, for the partitions of the first set 4011, and by the arrows referenced 408, 605 and 606, for the partitions of the second set 4012). The “Server-I / O” block 601 is capable of managing different interfaces 404 while ensuring latency (proven latency) and temporal consistency between the interfaces. It is also capable of customizing the pre-processing treatment in order to offer a configuration that adapts to the aircraft program in question. It ensures the partitioning of the inputs-outputs according to the user partitions (slow and fast);
[0092] - a “Very Fast Loop” block 602 (also called “VFL” for “Very Fast Loop"), which is (at least) a control loop having access to the aircraft interfaces 404, which is repeated by the scheduling service 4020 with a third frequency F3 higher than the second frequency F2 (for example F2 = 1 kHz and F3 = 16 kHz), and which can communicate with the partitions of the second set 4012. The "Very Fast Loop" block 602 is suitable for high-speed aircraft. Proposing such an increase in the execution frequency makes it possible to reduce latency times and increase the control bandwidth. These characteristics define the performance of the aircraft. Very fast loops are designed according to the aircraft actuators (electrical interfaces) and are fixed. In an alternative embodiment, the block 602 is included in the high layer 401, for example in the block 4012 comprising the second set of partitions;
[0093] - a “Control Loop” block 603 (also called “CTRL LOOP”), which is a control loop repeated by the scheduling service 4020 with a fourth frequency F4 higher than the third frequency F3 (for example F3 = 16 kHz and F4 = 64 kHz). The “Very Fast Loop” block 602 accesses the aircraft interfaces 404 via the “Control Loop” block 603 (see arrow referenced 607). The “Control Loop” 603 is an analog control loop managing for example the position, speed and acceleration of the actuators; and
[0094] - a “Field Bus Controller” block 604 (“also called “FB CTRL” for “Field Bus controller”) allowing to manage a remote 404 interface by managing a field bus (for example a MIL-STD-1553 type bus) (see arrow referenced 608).
[0095] [Fig.7] schematically illustrates an exemplary embodiment of the communication block 4023, included in the intermediate layer 402 of the calculation unit 202 and performing a communication service between fast partitions.
[0096] The communication block 4023 itself comprises a “FCOM Controller” block 701 (also called “FCOM controller”) and a “Switch” block 702 (“also called “Switch”). The “FCOM Controller” block 701 is adapted, compared to the “Network Server” block 501, to have better performance and thus be able to meet the needs of the fast partitions of the second set 4012, and therefore of the fast control loops included without these fast partitions.
[0097] The “FCOM Controller” block 701 allows a rapid partition of the second set 4012 to access:
[0098] - via a fifth type of connection (symbolized by the arrow referenced 703), to a fast partition of the other computing unit hosted by the same computing platform as that hosting the computing unit described 203; or
[0099] - via a sixth type of connection (symbolized by the arrow referenced 704), to a quick partition hosted by another platform.
[0100] The “Switch” block 702 is configured to extend the connection capabilities of the “FCOM Controller” block 701 and allow a fast partition of the second set 4012 to access:
[0101] - via a seventh type of connection (symbolized by the arrow referenced 705 and more efficient than the fifth connection symbolized by the arrow referenced 703), to a fast partition of the other computing unit hosted by the same computing platform as that hosting the computing unit described; or
[0102] - via an eighth type of connection (symbolized by the arrow referenced 706 and more efficient than the sixth type of connection symbolized by the arrow referenced 704) to a fast partition hosted by another platform.
[0103] [Fig.8] schematically illustrates a computing unit (generically referenced 203 and corresponding to one of the computing units 203-A (COM) and 203-B (MON) of [Fig.2]) included in a computing platform 202, in a second embodiment. This second embodiment is distinguished from the first embodiment of [Fig.4] by the following differences: - the 4022 input / output management block includes: • a first input / output management sub-block 4022a providing the partitions of the first set 4011 with a first access 411a to at least one interface 404 of the aircraft; and • a second input / output management sub-block 4022b providing the partitions of the second set 4012 with a second access 411b to the at least one interface 404 of the aircraft. - the sub-scheduler C2 includes two sub-schedulers C2a and C2b: • the sub-scheduler C2a manages the latency of the data flows exchanged between the partitions of the first set 4011 and the first input / output management sub-block 4022a; and • the C2b sub-scheduler manages the latency of the data flows exchanged between the partitions of the second set 4012 and the second input / output management sub-block 4022b.
[0104] The first embodiment described above in relation to Figs. 1 to 7, and the second embodiment described above in relation to [Fig.8], each correspond to a complete generic architecture.
[0105] In order to adapt to different aircraft programs, various embodiment variants can be envisaged by modifying the complete generic architecture in blocks. Thus, design, development, updating, verification and certification are greatly simplified.
[0106] In a first variant (forming a third embodiment): - the upper layer 401 does not include the second set of partitions 4012 nor the scheduler B; - the intermediate layer 402 does not include the second communication block 4023 between fast partitions; and - in the intermediate layer 402, the scheduler C comprises only the sub-schedulers C1 and C2a and the input / output management block 4022 comprises only the first input / output management sub-block 4022a (the input / output management block 4022 does not comprise the blocks 602 (“Very Fast Loop”), 603 (“Control Loop”) and 604 (“Field Bus Controller”)).
[0107] In a second variant, the input / output management block 4022 does not include the blocks 602 (“Very Fast Loop”), 603 (“Control Loop”) and 604 (“Field Bus Controller”), and the intermediate layer 402 does not include the second communication block 4023 between fast partitions.
[0108] In a third variant, the input / output management block 4022 does not include the blocks 602 (“Very Fast Loop”), 603 (“Control Loop”) and 604 (“Field Bus Controller”), and the second communication block 4023 between fast partitions does not include the “Switch” block 702.
[0109] In a fourth variant, block 602 (“Very Fast Loop”) is included in the upper layer 401.
[0110] In a fifth variant, the input / output management block 4022 does not include the blocks 602 (“Very Fast Loop”) and 603 (“Control Loop”), and the intermediate layer 402 does not include the second communication block 4023 between fast partitions.
Claims
Claims
1. Calculation unit (203) of a flight control system (101) of an aircraft (100), comprising: - a top layer (401) comprising: * a first set of partitions (4011), comprising partitions which are each associated with a first priority level and which each perform at least a first flight control function; and * a first scheduler (4013), performing a scheduling of the partitions of the first set, each partition of the first set being repeated by the first scheduler with a first frequency; and - an intermediate layer (402) comprising: * an input / output management block (4022) providing the partitions of the first set with access to at least one interface (404) of the aircraft; * a first inter-partition communication block (4021), allowing each partition of the first set to communicate, via a first dedicated communication channel or via at least one first communication network (403) of the aircraft, with at least one other partition associated with the first priority level and included in another computing unit of the aircraft; and * a second scheduler (4020), managing the latency of data flows exchanged between, on the one hand, the partitions of the first set and, on the other hand, the input / output management block (4022) and the first communication block between partitions (4021).
2. A computing unit according to claim 1, wherein the upper layer (401) further comprises: * a second set of partitions (4012), comprising partitions which are each associated with a second priority level, higher than the first priority level, and which each perform at least a second flight control function; and * a third scheduler (4014), performing a scheduling of the partitions of the second set, each partition of the second set being repeated by the second scheduler with a second frequency which is greater than the first repetition frequency of each partition of the first set; wherein the intermediate layer (402) further comprises: * a second communication block between partitions (4023), allowing each partition of the second set to communicate, via a second dedicated communication channel or via at least one second communication network (405) of the aircraft, with at least one other partition associated with the second priority level and included in another computing unit of the aircraft; in which the input / output management block (4022) further offers the partitions of the second set access to said at least one interface (404) of the aircraft, and in which the second scheduler (4020) also manages the latency of data flows exchanged between, on the one hand, the partitions of the second set and, on the other hand, the input / output management block (4022) and the second inter-partition communication block (4023).
3. A computing unit according to claim 1 or 2, wherein the first scheduler (4013) and the second scheduler (4020) are synchronized with each other.
4. A computing unit according to claim 2, wherein the first scheduler (4013) and the third scheduler (4014) are synchronized with each other.
5. Calculation unit according to claim 2, in which the input / output management block (4022) comprises: * a first input / output management sub-block (4022a) offering the partitions of the first set a first access (411a) to said at least one interface (404) of the aircraft; and * a second input / output management sub-block (4022b) offering the partitions of the second set a second access (411b) to said at least one interface (404) of the aircraft.
6. A computing unit according to any one of claims 1 to 5, wherein at least some of the partitions of the first and second sets comprise at least one control loop, each control loop benefiting from the first or second repetition frequency of the partition in which said control loop is included.
7. Computing unit according to claim 6, wherein the input / output management block (4022) or the high layer (401) comprises at least one first other control loop (602) which has access to said at least one interface (404) of the aircraft, which is repeated with a third frequency higher than the second frequency, and which can communicate with the partitions of the second set (4012).
8. A computing unit according to claim 7, wherein the input / output management block comprises at least one second other control loop (603), which is repeated with a fourth frequency higher than the third frequency, and wherein said at least one first other control loop (602) accesses said at least one interface (404) of the aircraft via said at least one second other control loop (603).
9. Computing unit according to any one of claims 1 to 8, in which each partition associated with the first priority level is a partition of a first type, called user partition (4011a), or a partition of a second type, called system partition (4011b), which corresponds to at least one service offered to partitions of the first type, and in which each partition (4012a) associated with the second priority level is a partition of the first type.
10. Computing unit according to any one of claims 1 to 9, in which the high layer (401) is configured to perform a communication service (413) between partitions, allowing the partitions of the first set to communicate, via at least one memory interface, with the partitions of the second set.
11. Computing platform (202-1 to 202-N) of an aircraft (100), characterized in that it comprises a pair of computing units (203-A, 203-B) according to any one of claims 1 to 10, a first (203-A, COM) of the two computing units acting in command mode and a second (203-B, MON) of the two computing units acting in monitoring mode of the first computing unit.
12. Aircraft (100), characterized in that it comprises a flight control system (101) comprising at least two computing units (203) according to any one of claims 1 to 10.
13. An aircraft according to claim 12, wherein the flight control system (101) comprises at least two computing platforms (202-1 to 202-N) according to claim 11, and wherein the partitions of the first sets (4011) of the computing units (203) of the at least two platforms (202-1 to 202-N) communicate with each other via the first communication blocks (4021) of said computing units.