Controller arrangement

The controller arrangement for electrically powered aircraft addresses common cause faults by adapting to flight conditions and using diverse data sources to safely manage subsystems, enhancing safety and preventing cascading failures.

GB2642064APending Publication Date: 2025-12-31GKN AEROSPACE SERVICES LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
GB2024008946
Authority / Receiving Office
GB · GB
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-21
Publication Date
2025-12-31

AI Technical Summary

Technical Problem

Conventional propulsion system controller arrangements are inadequate for electrically powered aircraft using cryogenic fuel, which are more vulnerable to common cause faults due to limited component variety and increased susceptibility to events like solar flares or lightning strikes, posing safety risks by cascading failures.

Method used

A controller arrangement that detects common cause faults by determining flight characteristics and using multiple measurement techniques to gather diagnostic data, adjusting operation parameters, and selectively resetting subsystems to mitigate faults safely.

Benefits of technology

Enhances aircraft safety by adaptively managing common cause faults based on flight conditions, preventing cascading failures and ensuring safe operation during critical flight phases.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A controller arrangement for an electrical power propulsion system of an electrically powered aircraft, the controller arrangement configured to: determine a flight characteristic of the aircraft (suc
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field and Background The present invention relates to electrical power propulsion systems of electrically powered aircraft, and more particularly but not exclusively, to methods of controlling and controller arrangements for electrical power propulsion systems of electrically powered aircraft. Electrically powered aircraft, for example electrically powered aircraft that use power source options other than typical fossil fuels (such as fuel cell arrangements), are not widespread. Indeed, such electrically powered aircraft are not at present used in commercial-sized aircraft (e.g. 48 or 96 or more passenger aircraft and / or CS-25 related aircraft). The systems and arrangements described herein may be directed toward use of green energy options with any sized aircraft. The use of cryogenic fuel as the primary fuel source for an aircraft is an area of cutting-edge research; conventional propulsion system controller arrangements are not suitable for dealing with the new complexities involved. Cryogenic fuel in particular presents many advantages over contemporary fuels, not least that they are more environmentally-friendly and provide a significant heat sink. However, the use of cryogenics leads to electrical power propulsion system considerations. The controller arrangement and control techniques discussed herein provide improved control and safety performance of electrical power propulsion systems of electrically powered aircraft. Summary Aspects of the invention are set out in the accompanying claims. Viewed from a first aspect, there is provided a controller arrangement for an electrical power propulsion system of an electrically powered aircraft, the controller arrangement configured to: determine a flight characteristic of the aircraft; detect a fault associated with a first subsystem of the electrical power propulsion system; determine whether the fault affects more than one sub-system of the electrical power propulsion system; and in response to determining that the fault affects more than one sub-system of the electrical power propulsion system and based on the determined flight characteristic, perform an action. The present inventors have identified that, in electrical power propulsion systems for electrically powered aircraft (for example an aircraft powered by a high density power source arrangement such as a fuel cell, or a hybridised power source arrangement having a fuel cell, battery arrangement, and super capacitor arrangement), it can be preferable to use components that share technology so as to support scalability of the system, but also to increase the understanding of known physics of failure. Indeed, such systems and aircraft represent an area of cutting-edge technology and development. The present inventors have identified that there exists less variety in component and underlying technology that may be used to support the power propulsion system compared to conventional aircraft systems (that use conventional fossil fuels for example). For aircrafts that use cryogenic fuel, the present inventors have identified that limited options exist for components that are suitable for use in power propulsion systems of such aircrafts. As a result of the limitations associated with operating at the cutting-edge of electrically powered flight and cryogenic fuel source usage (such as with a fuel cell) described above, the present inventors have identified that such electrical power propulsion systems can be more vulnerable to so-called ‘common cause’ or ‘common mode’ faults / failures or errors. Common cause failures can affect a plurality of or all components or sub-systems that are the same or similar, and so in a system where there is a limited variety in the type of components, common cause failures can be problematic. Example common cause failures relate to an external event (such as a solar flare or lightning strike) that can be seen across the whole electrical network or an unknown use event where the flight crew (or vehicle management system) requests unexpected demands. As a result of global warming, this former example may become increasingly common and severe. This latter example may have an increasing likelihood with increasing degradation of safe operation of the aircraft, where the flight crew may be more likely to issue unexpected commands when the aircraft is already in a rare and critical state. The present inventors have identified that existing approaches do not consider the possibility of common cause faults and thus may be unsuitable for use with electrical power propulsion systems of electrically powered aircrafts. Indeed, the present inventors have identified that existing approaches may operate at the expense of aircraft safety. One way to mitigate component failure in electrical power networks may include component isolation once a fault has been detected. This may be performed quickly so as to prevent the fault or failure from cascading across the electrical power network and affecting other components causing a total power blackout, and also to prevent high fault current events such as arc flash. However, for an electrical power network in an aerospace implementation, such as an electrically powered aircraft, the present inventors have identified that such techniques like component isolation for fault detection and mitigation are not suitable as they operate at the expense of aircraft safety, for example by turning off power to components or by isolating components. This can be particularly problematic during certain stages of flight or modes of operation, where high power may be critical (such as take-off), and again may be particularly problematic where a common cause fault affects a number of system components. The present inventors have identified that a novel approach to fault detection and mitigation that does not operate at the expense of the aircraft is required, and indeed that requires a different approach from the approach used in the situation where an error only affects a single sub-system. Thus, the present inventors have devised an improved approach that detects whether a fault is a so-called common cause fault and takes this and a flight characteristic into consideration when performing an action. As a result, the action can be specific to the presence of a common cause fault and to the characteristic of the flight to ensure that the action taken is safe for the flight characteristic, given that a common cause fault has been detected. Indeed, in some cases, an action may be suitable for a given flight characteristic but not another. For example, at cruise, the power requirements are different from during take-off, and so an action that may be safe to be performed during cruise may not be safe to perform during take-off. Similarly, an action that may be safe to perform in a single fault mode scenario may be unsafe to perform during a common fault mode scenario. The present controller arrangement thus provides an improved approach to fault detection and mitigation which increases adaptability of the response and increases aircraft safety. In some examples, the action is associated with resolution of the fault. Thus, the action performed in response to determining the common cause fault and based on the flight characteristic may be associated with fault resolution. In some examples, to perform the action, the controller arrangement is configured to determine diagnostic data associated with the aircraft. Thus, once a common cause fault has been determined, the controller arrangement may gather additional diagnostic data to enable resolution of the fault or increased understanding of the fault. This allows operators of the aircraft to understand the fault and how the fault may be affecting the aircraft sub-systems to enable a more informed response. In examples, to perform the action, the controller arrangement is further configured to: determine a modified operating range of an operation parameter of a sub-system of the electrical power propulsion system based on the flight characteristic of the aircraft; and control operation of the sub-system of the electrical power propulsion system based on the modified operating range for the operation parameter of the sub-system. Thus, in response to detecting the common cause fault, the present approach may modify operation of a sub-system based on modified operating ranges that are specifically adapted to that common-cause fault and flight characteristic. During aircraft operation, various common cause faults may occur that each require particular adjustment to the operation of the electrical power propulsion system. The present controller arrangement may thus modify operation of sub-systems to increase the safety of the aircraft and attempt to counteract certain faults. For example, if a common cause fault is detected during take-off, the controller arrangement may modify the operation parameters to cause a sub-system to operate at a greater power draw than would have been allowed by previous operating parameters. This may enable the power propulsion system to temporarily provide more power during a power critical stage of flight. In this way, the present controller arrangement is able to provide a more adaptable response to detected faults. Indeed, the controller arrangement is able to provide an adaptive approach, whereby operation of the sub-systems is based on the determined flight characteristic and in response to detecting a fault. This allows the controller arrangement to provide a temporary operational state in which a sub-system is able to operate outside of its normal operating ranges to provide an increased period of time to investigate the fault and mitigate the fault. The modification of operation parameters in response to detecting a fault can therefore synergistically interact with other actions performed in response to detecting the fault (such as determining diagnostic data, resetting a sub-system, etc.) to provide an improved response to the detected fault. In some examples, to perform the action, the controller arrangement is configured to perform a reset action associated with a sub-system of the electrical power propulsion system. Thus, the action may include a reset action, such as resetting the sub-system (turning off and on power). In some cases, and for some common cause fault scenarios, such action can clear the fault and return the sub-system to normal operation. It will be appreciated that the reset action may cause a sub-system to be reset or generate a signal indicating that the sub-system is to be reset. The sub-system associated with the reset action may be the first sub-system, or another sub-system. In some examples, to perform the reset action, the controller arrangement is configured to: determine whether resetting a second sub-system of the electrical power propulsion system satisfies a reset condition based on the determined diagnostic data and the determined flight characteristic of the aircraft, and reset the second sub-system in response to determining that resetting the second sub-system satisfies the reset condition. Thus, resetting takes into account not only additional diagnostic data, but also the current flight characteristic of the aircraft, for example take-off, cruise, landing etc. The power requirements at different stages of flight can vary significantly and so what may be considered safe to reset during a certain flight stage or when a certain flight characteristic is determined may not be considered safe during a different flight stage or when a different flight characteristic is detected. Thus, the approach ensures that a reset decision is taken that is suitable for a current stage of flight to increase the safety of operation of the aircraft. The reset condition may include one or more predetermined safety conditions. Such predetermined safety conditions may allow for the evaluation of proposed reset against stored safety scenarios that are known to be allowable for a given flight characteristic and common cause fault scenario. For example, the controller arrangement may store information indicating whether resetting sub-systems at a given flight characteristic may be considered safe and thus satisfy the safety condition. Resetting a sub-system may include powering off the sub-system and powering on the subsystem. As an example, resetting a sub-system that is critical for providing power during takeoff may not be considered safe, however, it may be safe to reset such a sub-system during cruise when the propulsive power demand is lower. In a large majority of cases, resetting a component or sub-system can clear the error experienced by the component or sub-system. The present controller arrangement provides a novel controller arrangement that is able to detect and mitigate common cause faults in a manner that prioritises the safety of the electrically powered aircraft and adapts to the current flight characteristic of the aircraft. In examples, to detect a fault associated with a sub-system of the electrical power propulsion system, the controller arrangement is configured to determine first measurement data using a first measurement technique; and to determine diagnostic data associated with the aircraft, the controller arrangement is configured to determine the diagnostic data using a second measurement technique different from the first measurement technique. When a fault has been detected, and in particular a common cause fault, the measurement technique used to detect the fault may have been affected in a similar way to the sub-system affected by the fault. Thus, the measurement technique may not be trusted to also provide accurate diagnostic data associated with the aircraft and so it can be advantageous to determine the diagnostic data using a different measurement technique. This increases the likelihood that the diagnostic data is accurate and thus that an informed and appropriate action that reflects the actual state of the aircraft can be performed, such as when determining whether to reset components or sub-systems. In examples, the first measurement technique comprises determining first measurement data associated with a first sensor arrangement, and the second measurement technique comprises determining the diagnostic data based on one of more of: determining data associated with a second sensor arrangement different from the first sensor arrangement; determining data associated with a system of the aircraft other than the electrical power propulsion system; an analytical model; and measuring a property of a sub-system of the electrical power propulsion system in response to modifying a power demand of the subsystem. As discussed above, a fault may be detected by a sensor arrangement which is then itself affected by the event that caused the fault, such as a solar flare event. This could present itself as a changed speed of the aircraft as detected by a speed sensor for example, or a change or spike in a voltage measurement of a voltage sensor. In the event of a common cause fault, the present approach assumes that the original measurement technique or sensor arrangement has been corrupted by the event that caused the error and thus cannot be trusted to provide diagnostic information relating to the aircraft. By operating in this way, the likelihood that incorrect information is used in the determination of whether it is safe to reset a subsystem is reduced, ultimately leading to improved aircraft safety. The second measurement technique may comprise determining the diagnostic data with a different sensor arrangement from the sensor arrangement that detected the fault. In some implementations, redundancy of sensor arrangements may be provided and so a back-up sensor arrangement may be used instead. In some examples, the second arrangement is also a different type of sensor to the first sensor arrangement, thereby increasing the likelihood that the second sensor arrangement has not also been corrupted by the event that caused the common cause fault. In some examples, the second measurement technique comprises determining data associated with a system of the aircraft other than the electrical power propulsion system. In this way, the controller arrangement interrogates a different system altogether of the aircraft. For example, a vehicle management system may be able to provide useful diagnostic data for diagnosing the fault experienced by the sub-systems of the electrical power propulsion system. Unknown external events that typically cause common cause errors are likely to have also impacted other electrical systems on the aircraft. Thus, by sharing data at the aircraft level rather than just at the electrical power propulsion system level, greater information on the event can be understood and thus a more informed decision as to fault mitigation can be taken (such as whether or not it is safe to reset a sub-system). The second measurement technique may comprise using an analytical model. For example, mappings of properties or operating ranges may be stored in memory that allow measurements to be derived based on a pre-determined relationship or model. Again, by having a different measurement technique from the technique that detected the fault, a more informed decision as to fault mitigation can be taken. The second measurement technique may also comprise measuring a property of a subsystem of the electrical power propulsion system in response to modifying a power demand of the sub-system. Thus, in some cases, active steps can be taken to modify operation of the electrical power propulsion system and the resulting performance of the system can be measured to determine diagnostic data. Again, by having a different measurement technique from the technique that detected the fault, a more informed decision as to fault mitigation can be taken. In examples, the first and / or second sub-systems comprise one or more of: a propulsion arrangement, a motor arrangement, and a measurement arrangement. Thus, the present arrangement may detect faults associated with major components of the aircraft’s electrical power propulsion system and mitigate faults while increasing safety of aircraft operation. In examples, the first and second sub-system are the same. Thus, the sub-system that experiences the detected fault may also be the sub-system that is reset in the event that the reset condition is satisfied. In other examples, the first and second sub-system are different. Thus, a sub-system may be reset based on detecting a fault with a different sub-system. In some cases, it can be advantageous, depending on system implementation, to provide increased configurability with the reset response. For example, for some implementations it may be advantageous to reset a second measurement arrangement after detecting a fault with a different measurement arrangement. In examples, the first sensor arrangement and second sensor arrangement comprise one or more of: a vehicle management system sensor, a speed sensor, a fuel flow sensor, an airflow sensor, a water flow sensor, a voltage sensor, a current sensor, and a power sensor, a position sensor, a vibration sensor, and a temperature sensor. Thus, the present techniques may be applied to and take input from a large variety of different sensor arrangements that may be used within an electrical power propulsion system of an electrically powered aircraft. In examples, the controller arrangement is further configured to: determine an operating range for an operation parameter of a sub-system of the electrical power propulsion system based on the flight characteristic of the aircraft; and control operation of the sub-system of the electrical power propulsion system based on the operating range for the operation parameter of the sub-system. The present controller arrangement may be adaptable to current flight characteristics of the aircraft and advantageously control operation of sub-systems of the electrical power propulsion system to ensure that operation remains within predefined safe operating ranges for the given flight characteristic. As a result, safety of aircraft operation is increased. In examples, determining the operating range and modified operating range for the operation parameters is based on a predetermined mapping between operating ranges and flight characteristics. The operating ranges may be stored in memory and efficiently referred to when needed. In examples, determining the operating range and the modified operating range is also based on a determined aircraft degradation state and / or a determined fault severity. Thus, the controller arrangement may be able to respond to different levels of aircraft degradation and error severity and provide optimised control of sub-systems based on the level of aircraft degradation and error severity in such a way as to maximise aircraft safety. For example, the controller arrangement may control operation of a sub-system beyond a normal or recommended operating range in safety critical circumstances where the aircraft degradation or error severity dictates that this is required. In examples, to detect the fault associated with a first sub-system of the electrical power propulsion system, the controller arrangement is configured to: determine that an operation parameter associated with operation of the first sub-system of the electrical power propulsion system satisfies a fault condition for the determined flight characteristic of the aircraft. Thus, the controller arrangement can efficiently determine whether a fault associated with the first sub-system is present. The operation parameter may in some examples comprise a propulsive power or electrical parameter associated with the first sub-system. In examples, determining that an operation parameter associated with operation of the first sub-system of the electrical power propulsion system satisfies a fault condition for the determined flight characteristic of the aircraft is based on determining sensor data associated with the first sub-system. Thus, in these examples, sensor data can be used to detect the fault associated with the first sub-system, thereby allowing for a direct measurement of the first sub-system. In examples, to determine whether the fault affects more than one sub-system of the electrical power propulsion system, the controller arrangement is configured to: determine whether operation parameters of one or more sub-systems of the electrical power propulsion system other than the first sub-system associated with the fault satisfy an error condition for the determined flight characteristic of the aircraft. The present inventors have identified that subsystems other than the first-system can be used to detect a fault associated with the first subsystem. Indeed, as described herein, in some common cause failure modes, measurement of the first sub-system may not be trusted (given that the fault may have affected that sub system), and thus a measurement of a different sub-system can still allow a fault to be detected. As a result, the reliability of fault detection is increased. In examples, the diagnostic data comprises data associated with an aircraft system other than the electrical power propulsion system. The present inventors have identified that other aircraft systems can provide valuable data that may indicate the status of the electrical power propulsion system. Indeed, by determining diagnostic data from other aircraft systems, more information regarding the fault and a more detailed view of the error can be determined, resulting in a more accurate and informed decision as to whether a sub-system is to be reset. This advantageously increases aircraft safety in the event of a fault as the likelihood that a decision on whether or not to reset is incorrectly made is reduced. In some examples, the aircraft system other than the electrical power propulsion system comprises a vehicle management system. The present inventors have identified that the vehicle management system may advantageously provide information that indicates the fault state of the electrical power propulsion system and thus acts as a reliable ‘proxy’ for the electrical power propulsion system. In some examples, the first sub-system comprises a power electronic converter and a propulsion motor. Thus, the present techniques may be particularly well-suited for fault detection of electrically powered aircraft. In examples, the fault is associated with an externally induced power surge or an externally generated unexpected demand on the electrical power propulsion system. As discussed herein, common cause / mode faults may be caused by a variety of events, including an external power surge, such as a lightning strike or a solar flare, and also an unexpected demand on the system, for example caused by erratic or unpredictable human behaviour. In examples, the flight characteristic comprises at least one of: dormancy; start-up; stationary; taxi; take-off; initial climb; climb; cruise; descent; landing; go-around; emergency; and, shutdown. Thus, the present controller arrangement increases the safety of operation at various stages of flight and during various flight characteristics. As discussed herein, the flight characteristic experiences by the aircraft at a given point time can affect whether a certain reset is safe or not. As a result, the controller arrangement increases safety across various flight characteristics. In examples, the electrically powered aircraft comprises a fuel cell as a high energy density power source arrangement. As described herein, the present inventors have identified that cutting-edge fuel cell powered electrical aircraft can be susceptible to common cause errors and thus the present techniques increase the safety against such errors to increase the safety of electrically-powered flight. According to a second aspect, there is provided a method for controlling an electrical power propulsion system of an electrically powered aircraft, the method comprising: determining a flight characteristic of the aircraft; detecting a fault associated with a first sub-system of the electrical power propulsion system; determining whether the fault affects more than one subsystem of the electrical power propulsion system; and in response to determining that the fault affects more than one sub-system of the electrical power propulsion system and based on the determined flight characteristic, performing an action. In examples, the action may comprise: determining diagnostic data associated with the aircraft; determining whether resetting a second sub-system of the electrical power propulsion system satisfies a reset condition based on the diagnostic data and the determined flight characteristic of the aircraft; and resetting the second sub-system of the electrical power system in response to determining that resetting the component of the electrical power system satisfies the reset condition. According to a third aspect, there is provided a computer-readable medium comprising instructions which, when executed by one or more processors, cause the one or more processors to perform the method described herein. According to a fourth aspect, there is provided an electrical power propulsion system for an electrically powered aircraft comprising: a high energy density power source arrangement for providing electrical power; a propulsion motor arrangement for receiving electrical power from the high energy density electrical power source arrangement and providing propulsion; and a controller arrangement configured to perform the method described herein. In examples, the high energy density power source arrangement comprises a fuel cell arrangement. According to a fifth aspect, there is provided an at least partially electrically powered aircraft comprising the controller arrangement described herein or the electrical power propulsion system described herein. Other aspects will also become apparent upon review of the present disclosure, in particular upon review of the Brief Description of the Drawings, Detailed Description and Claims sections. Brief Description of the Drawings Examples of the disclosure will now be described, by way of example only, with reference to the accompanying drawings in which: Figure 1: schematically illustrates an electrical power propulsion system according to the present teachings. Figure 2: schematically illustrates steps that may be performed by a controller arrangement according to the present teachings. Figure 3: schematically illustrates steps for detecting a fault according to the present teachings. Figure 4: schematically illustrates steps for performing actions in response to detecting a fault according to the present teachings. Figure 5: schematically illustrates an example relationship between operation parameters and three operating ranges according to the present teachings. Figure 6: schematically illustrates steps for controlling operation of a sub-system based on a modified operating range according to the present teachings. Figure 7: schematically illustrates an example electronic device that may implement the present teachings. While the disclosure is susceptible to various modifications and alternative forms, specific example approaches are shown by way of example in the drawings and are herein described in detail. It should be understood however that the drawings and detailed description attached hereto are not intended to limit the disclosure to the particular form disclosed but rather the disclosure is to cover all modifications, equivalents and alternatives falling within the spirit and scope of the claimed invention. It will be recognised that the features of the above-described examples of the disclosure can conveniently and interchangeably be used in any suitable combination. Detailed Description An invention described herein relates to controller arrangements for electrically powered aircraft. The controller arrangements herein may be used with any vehicles however it is a particularly advantageous arrangement for use in aircraft. A particular use for this invention may be in an aircraft with an electrically drivable motor or a drivable motor that is at least partially electrically driven. For example, the propulsion in the aircraft in which the controller arrangements disclosed herein are used may be fully or partially electrically powered. Indeed, it will be appreciated that the term ‘electrically powered aircraft’ refers to an aircraft that is at least partially electrically powered (and may also be at least partially combustion powered). Partially powered aircraft may use thrust provided in part by electrical means and in part by combustion means. This invention may be used in a fully or partially combustion powered aircraft. The electrical and combustion aspects may be provided by one or by a few fuels. In some examples a cryogenic fuel may be used. For example, a high energy density power source arrangement may comprise a cryogenic fuel arrangement arranged to provide fuel for power generation. Figure 1 shows a schematic view of an electrical power propulsion system 100 of an electrically powered aircraft according to an example of the present disclosure, and in which the present techniques may be implemented. It will be appreciated that electrical power propulsion system 100 may include one or more of the components illustrated in figure 1, and is not restricted to including all of the shown components. Electrical power propulsion system 100 includes a number of sub-systems. As described herein, a sub-system may refer to a single component or a plurality of components. Electrical power propulsion system 100 includes a high energy density power source arrangement 102 and a propulsion arrangement 104. High energy density power source arrangement 102 provides electrical power, for example to the propulsion arrangement 104 (indicated by the dashed arrow). The propulsion arrangement 104 may receive the electrical power from the high energy density power source arrangement 102 and provide propulsion (for example propulsive power for an electrically powered aircraft). The propulsion arrangement may comprise a propulsion motor. It will be appreciated that the electrical power propulsion system 100 may include a plurality of propulsion channels (e.g. propulsion sub-systems), with each propulsion channel / sub-system comprising a propulsion motor, which may be combined with an associated measurement arrangement for measuring a speed of the propulsion motor (based on voltage). In some cases, the propulsion sub-system may include a power electronic converter associated with the propulsion motor. In examples, the high energy density power source arrangement 102 is at least one of a fuel cell and a combustion turbine. The high energy density power source arrangement 102 may be a fuel cell stack or a series of fuel cell stacks or the like. The electrical power propulsion system 100 may also comprise a fuel container (not shown) for containing a fuel for use in the electrical power propulsion system 100. For example, the fuel container (not shown) may provide fuel to the high energy density power source arrangement 102. In an example, the high energy density power source arrangement 102 is a fuel cell stack and the fuel is hydrogen. The hydrogen may be stored in the fuel container (not shown) as a liquid cryogen. As shown, electrical power propulsion system 100 also includes a battery arrangement 106. Battery arrangement 106 may be configured to store energy and provide electrical energy to the propulsion arrangement 104. Further, the battery arrangement 106 may be configured to receive electrical energy from the high energy density power source arrangement 102 and store that energy. The battery arrangement 106 may include one or more battery cells. The battery arrangement 106 can provide peak power relative to the high energy density power source arrangement 102 As shown, electrical power propulsion system 100 also includes a super-capacitor (or a capacitor or the like) arrangement 108. Super-capacitor arrangement 108 may be configured to store energy and provide electrical energy to the propulsion arrangement 104. Further, the super-capacitor arrangement 106 may be configured to receive electrical energy from the high energy density power source arrangement 102 and store that energy. The super-capacitor arrangement 108 can provide a burst of power over a relatively short period of time, and thus may be advantageous during safety events or during short periods of high power demand. Also included in electrical power propulsion system 100 are a number of power electronic converters (PEC) 102a, 104a, 106a, 108a that are configured to receive electrical power and convert electrical power (for example into a type of power suitable for a certain component). It will be appreciated that PECs 102a, 104a, 106a, 108a may be similar or different. Further in some examples where multiple fuel cells and multiple propulsion motors are provided, a PEC may be provided with each of the fuel cells and propulsion motors. In some cases, a first-subsystem of the electrical power propulsion system 100 corresponds to propulsion arrangement 104 and PEC 104a. Other sub-systems of the electrical power propulsion system 100 may correspond to the high energy density power source arrangement 102 and its associated PEC 102a, the battery arrangement 106 and its associated PEC 106a, and the super-capacitor arrangement 108 an its associated PEC 108a. It will be appreciated that the electrical power propulsion system 100 may include further components and sub-systems (not shown), such as measurement arrangements. Further, it will be appreciated that electrical power propulsion system 100 may include multiple propulsion arrangements 104 and associated PECs 104, multiple high energy density power source arrangements 102 and associated PECs 102a, multiple battery arrangements 106 and associated PECs 106, and multiple super-capacitors 108 and associated PECs 108a. The arrangement is not limited in this respect. As described herein and in further detail below, one or more of the sub-systems of the electrical power propulsion system 100 may experience a fault, and thus the electrical power propulsion system 100 also includes a controller arrangement 110. It will be appreciated that the controller arrangement 110 may be provided as a single controller or device, or multiple controllers or devices. The controller arrangement 110 may be connected or in (indirect or direct) communication with the various sub-systems of the electrical power propulsion system 100 and may be configured to control the various sub-systems. For example, the controller arrangement 110 may be configured to signal sub-systems to reset or control the sub-systems to reset / power off and on. The controller arrangement 110 may implement the techniques as described herein. As discussed, the present inventors have identified that as a result of operating at the cutting-edge of electrically powered flight, such electrically powered aircraft / power propulsion systems can be more vulnerable to common cause faults than conventionally powered aircraft (i.e. combustion powered aircraft powered by traditional fuel sources). For example, while the PECs 102a, 104a, 106a, 108a may vary in design between their implementation and depending on the component they are associated with (i.e. PEC 102a may differ from PEC 104a), these components are still based on the same physical principles and indeed their underlying technology may still be similar. The present inventors have identified that some implementations may have 40% similar PECs. In some cases, multiple fuels cells and propulsion motors may be advantageous, and in this case, the PECs associated with the fuel cells may all be the same, and the PECs associated with the propulsion motors may all the be the same. Thus, in some sub-systems, PECs may be 100% similar. The present inventors have identified that, as a result, if an event occurs (such as an unexpected event like a solar flare or lightning strike or unexpected demand), a fault that affects a given PEC is also likely to affect other PECs (i.e. ones associated with additional provisions of the same component type, but also PECs associated with other component types) due to the similarities. The present controller arrangement therefore acts to detect these so-called common cause faults and take action accordingly, to increase aircraft safety and ensure that the electrical systems of the aircraft do not operate at the expense of aircraft safety (for example in following conventional isolation techniques). The action taken is based on a determined flight characteristic, thereby taking into account the different power levels required for different flight characteristics. An example method 200 performed by a controller arrangement as described herein will now be described in relation to figure 2. Method 200 may be performed by controller arrangement 110 of figure 1, for example. The electrical power propulsion system and sub-systems referred to in method 200 may correspond to the electrical power propulsion system 100 and subsystems of figure 1. Step 202 includes determining a flight characteristic of the aircraft. The flight characteristic may comprise at least one of dormancy; start-up; stationary; taxi; take-off; initial climb; climb; cruise; descent; landing; go-around; emergency; and shut-down. The controller arrangement may determine the flight characteristic by receiving information indicating the flight characteristic from another aircraft system, for example, or alternatively the controller arrangement may detect the flight characteristic, for example based on measurement or sensor data from an aircraft system. The controller arrangement is not particularly limited in this respect. Step 204 includes detecting a fault associated with a first sub-system of the electrical power propulsion system. To do this, the controller arrangement may be configured to determine first measurement data using a measurement technique, for example with a sensor arrangement. The sensor arrangement may comprise a vehicle management system sensor, a speed sensor, a fuel flow sensor, an air flow sensor, a water flow sensor, a voltage sensor, a current sensor, and a power sensor, a position sensor, a vibration sensor, and a temperature sensor. Thus, the controller arrangement may detect the fault based on one or more sensors as described above. For example, the sensor may report a certain measurement value and the controller arrangement may compare that measurement value against predetermined fault thresholds for that measurement to determine the presence of a fault. Additionally, or alternatively, the controller arrangement may determine that an operation parameter associated with operation of the first sub-system satisfies a fault condition for the determined flight characteristic. The operation parameter may include a power or current for example. The controller arrangement may determine that the operation parameter satisfies a fault condition based on determining sensor data associated with the first sub-system. The first sub-system of step 204 may correspond to any of the sub-systems described in relation to figure 1. For example, the first sub-system may comprise one or more of a propulsion arrangement, a motor arrangement, a high density power source arrangement, a battery arrangement, a super-capacitor arrangement and a measurement arrangement. In some examples, the first sub-system comprises a power electronic converter and a propulsion motor. Step 206 includes determining whether the fault affects more than one sub-system of the electrical power propulsion system. In other words, at this step, the controller arrangement determines whether a common mode / cause fault has occurred. As mentioned above, the present inventors have identified that electrically powered aircraft may be particularly vulnerable to such faults, and it would be advantageous for aircraft safety to be able to detect these faults and perform an action in response. In order to detect whether the fault affects more than one sub-system, the controller arrangement may determine whether operation parameters of one or more sub-systems other than the first sub-system satisfy a fault condition for the determine flight characteristic of the aircraft. For example, during take-off, a power of the propulsion arrangement is higher than during cruise. Thus, what might be considered a fault level power at cruise may not necessarily be a fault level power during take-off. Thus, the controller arrangement is able to determine whether fault conditions are satisfied in dependence on the flight characteristics. The controller arrangement may store predetermined fault conditions for one or more flight characteristics in order to determine whether a determined operation parameter corresponds to a fault or not. Step 208 includes in response to determining that the fault affects more than one sub-system of the electrical power propulsion system and based on the determined flight characteristic, perform an action. As discussed, the action is performed based on the flight characteristic because the flight characteristic can affect the action that should be performed. Indeed, as mentioned, fault conditions at take-off, i.e. during a time of high power demand, can be significantly different from fault conditions at cruise or shut down, for example. Thus, the present controller arrangement provides an improved detection of faults in an electrically powered aircraft, and in particular detects so-called common cause faults. Consequently, appropriate action can be taken in dependence on the flight characteristic of the aircraft, thereby increasing safety of the aircraft. Thus, the controller arrangement supports improved detection and an improved response to faults in an electrically powered aircraft. The action may be associated with resolution of the fault. Performing the action may comprise determining diagnostic data associated with the aircraft. Thus, the nature of the fault may be more efficiently determined to support an improved response to the fault. The diagnostic data may be determined using a measurement technique different from the measurement technique used to detect the fault associated with the first sub-system. This recognises that, where a fault has occurred, the measurement technique for detecting the fault may not be reliable. For example, a sensor system used to detect the fault may also have been affected by the fault (such as a power surge caused by a solar flare or lightning, for example), and thus more accurate information can be determined using a different technique. The different technique may include determining the diagnostic data based on one of more of: determining data associated with a second sensor arrangement different from the first sensor arrangement; determining data associated with a system of the aircraft other than the electrical power propulsion system; using an analytical model; and measuring a property of a subsystem of the electrical power propulsion system in response to modifying a power demand of the sub-system. In other words, the diagnostic data can be determined in a different manner to the measurement data used to detect the fault. As discussed, the action may comprise determining whether to reset a sub-system satisfies a reset condition based on the diagnostic data and the determined flight characteristic, and resetting the second sub-system in response to determining that resetting the second subsystem satisfies the reset condition. The present inventors have identified that resetting a sub-system can often clear a fault, but that resetting a sub-system cannot safely be performed in some situations. For example, during take-off, it may not be safe to reset a propulsion system as take-off requires a high power output. Thus, the resetting of a sub-system is performed based on the determined flight characteristic. It will be appreciated that the first sub-system and the second sub-system may be the same. That is to say, the sub-system that experiences a fault may be reset. This can clear certain faults. Alternatively, a different sub-system may be reset from the sub-system that experiences the fault. In some failure modes, other sub-systems may also necessarily be affected if a first sub-system has a fault, and so it can be advantageous to reset these sub-systems. The action performed at step 208 may include determining a modified operating range of an operation parameter of a sub-system of the electrical power propulsion system based on the flight characteristic of the aircraft, and controlling operation of the sub-system of the electrical power propulsion system based on the modified operating range for the operation parameter of the sub-system. An example fault detection method according to the present teachings will now be described with reference to figure 3. Method 300 shows how a controller arrangement according to the present teachings may detect a fault, and further classify the fault into a single cause fault and a common cause fault (i.e. a fault that affects a plurality of sub-systems and is to be handled differently). At 301, the controller arrangement determines a flight characteristic of the aircraft. As discussed herein, the flight characteristic may refer to a variety of characteristics (such as relating to a stage of flight, a power draw status, etc.). As also discussed herein, the controller arrangement may determine the flight characteristic in a variety of ways, such as through direct sensing, or receiving information indicative of the flight characteristic (for example from one or more aircraft systems or sub-systems). At 302, the controller arrangement determines an operation parameter associated with operation of a sub-system of the electrical power propulsion system. The operation parameter may correspond to an electrical parameter of the sub-system, such as a voltage or current drawn by the sub-system. In some examples, the operation parameter may be a propulsive power. The operation parameter may then be used to determine whether the sub-system is operating within a ‘normal’ or expected operational range for the determined flight characteristic, which can be used to indicate whether the sub-system is experiencing a fault. The operation parameter may be determined in a variety of ways. For example, the operation parameter may be determined by the controller arrangement receiving information indicative of the operation parameter, for example from one or more other controller arrangements. In an example, the controller arrangement is configured to receive information indicative of the operation parameter associated with a sub-system from a controller or sensor device associated with the sub-system. In this way, the controller arrangement may communicate with a plurality of other controllers (for example lower-level controllers associated with individual components or cub-systems) or sensor devices to determine operation parameters. In some examples, the controller arrangement is configured to determine first measurement data corresponding to the operation parameter using a first measurement technique. The first measurement technique may for example include determining first measurement data (i.e. corresponding to the operation parameter) with a first sensor arrangement. In some examples, steps 302 and 303 are combined are omitted, and replaced by a single step of determining whether a fault is affecting a sub-system. In some cases, the sub-systems may flag faults to the controller arrangement and thus rather than the controller arrangement determining the operation parameter, the controller arrangement may be notified when a fault is present by the sub-system. Thus, the controller arrangement may detect whether a fault is affecting a sub-system based on receiving information that indicates whether a fault is affecting a sub-system. At 303, the controller arrangement determines whether the operation parameter associated with operation of the sub-system satisfies a fault condition for the determined flight characteristic. This may include comparison of the operation parameter to one or more predefined thresholds or operation parameter ranges. For example, a first threshold or range may correspond to ‘normal’ or expected operation for the given flight characteristic. A second threshold or range may correspond to operation indicative of a fault - for example, the operation parameter may excess one or more predefined fault thresholds defined for the flight characteristic. It will be appreciated that the controller arrangement may store a plurality of predefined thresholds or ranges to define normal operation and fault operation for each of a plurality of flight characteristics. In this way, the controller arrangement can determine when a fault is present for each of the flight characteristics, based on different fault thresholds for example. The predetermined thresholds may be set based on user input and may vary depending on implementation (such as aircraft type, maximum power, aircraft weight, aircraft size, etc.). Furthermore, as discussed further below, the predetermined thresholds may be updated based on action by the controller to provide an adaptable approach to aircraft operation. At 304, i.e. when the controller arrangement determines that the operation parameter does not satisfy a fault condition for the determined flight characteristic (or that the operation parameter satisfies a normal operation condition indicative of normal operation for the determined flight characteristic), the controller arrangement detects normal operation. That is to say, at 304, the controller arrangement detects the absence of a fault associated with the sub-system. At this point, the fault detection process may then terminate, and restart after a period of time or in response to a change in flight characteristic, or based on input. In some cases, the controller arrangement periodically returns to step 302 (assuming the flight characteristic has not changed) and performs steps 302 and 303 again and in a loop. At 305, the controller arrangement determines that the operation parameter satisfies a fault condition for the determined flight characteristic (or that the operation parameter does not satisfy a normal operation condition indicative of normal operation for the determined flight characteristic). That is to say, at 305, the controller arrangement detects a fault associated with the sub-system. The present inventors have identified that alternative approaches to fault detection in conventional aircraft may terminate at this point. However, the present fault detection approach continues to classify the fault into a single cause fault or a common cause fault. At 306, the controller arrangement determines an operation parameter of one or more other sub-systems. This may be performed in a similar manner to step 302. For example, at 302, an operation parameter of a first propulsion sub-system (including a power electronic converter and propulsive motor) may be determined, and at 306 an operation parameter of a different propulsion sub-system (i.e. a different power electronic converter and a propulsive motor), or a measurement sub-system, or a fuel cell sub-system, may be determined. In this way, the controller arrangement checks whether the fault has affected a plurality of subsystems of the electrical power propulsion system of the aircraft. As discussed herein, common cause events such as solar flares or lightning strikes may affect a plurality of sub-systems of the electrical power propulsion system and thus the present method differentiates such a cause from a single cause event which affects only one subsystem (such as an isolated component failure). At 307, in a similar manner to 303, the controller arrangement determines whether an operation parameter associated with operation of the one or more other sub-systems satisfies a fault condition for the determined flight characteristic. Again, this may be performed based on a comparison to one or more predefined thresholds set for the sub-system and the flight characteristic. At 308, i.e. when the controller arrangement determines that the operation parameter associated with the one or more other sub-systems does not satisfy a fault condition for the determined flight characteristic (or that the operation parameter satisfies a normal operation condition indicative of normal operation for the determined flight characteristic), the controller arrangement detects a single cause fault. In other words, while a fault was detected with a sub-system in 304 (e.g. a first sub-system), a fault was not detected with one or more other sub-systems (e.g. a second sub-system). Thus, the controller arrangement determines that the fault is a fault affecting one sub-system of the electrical power propulsion system and thus classifies the fault as a single cause fault. Example single cause faults may be an individual component failure or short circuit. Having determined that the fault is a single cause fault, the controller arrangement may perform an action including controlling isolation of the sub-system experiencing the fault In some examples, fault mitigation techniques may be performed such as component isolation or sub-system shutdown. The exact steps performed for the single cause fault scenario will depend on implementation. At 309, i.e. when the controller arrangement determines that the operation parameter associated with the one or more other sub-systems satisfies a fault condition for the determined flight characteristic (or that the operation parameter does not satisfy a normal operation condition indicative of normal operation for the determined flight characteristic), the controller arrangement detects a common cause fault. That is to say, the controller arrangement detects that the fault is affecting a plurality of sub-systems of the electrical power propulsion system. As discussed herein, common cause faults may be associated with or caused by externally induced power surges (such as solar flares or lightning strikes) or externally generated unexpected demand on the electrical power propulsion system (such as a pilot or crew member performing an unexpected action resulting in an unexpected demand on the electrical power propulsion system, for example an unplanned sudden increase in ascent / descent / speed / direction of the aircraft). The controller arrangement may be additionally configured to determine that the fault affecting the first sub-system is the same or related to the fault affecting the one or more other subsystems based on analysis of the determined operation parameters. For example, based on determining a change in the operation parameters or a rate of change of operation parameters, In some examples, the controller arrangement may determine based on timing information associated with the operation parameters that a change in operation parameters occurred at substantially the same time or was caused by the same external event. In some example, the controller arrangement may thus determine that the same fault affected both the first subsystem (i.e. the sub-system of 302, 303) and the one or more other sub-systems (i.e. from 306, 307). Based on whether normal operation (304), a single cause fault (308), or a common cause fault (309) is detected by the controller arrangement, the controller arrangement may perform different actions as discussed herein. In particular, in response to determining the common cause fault, the controller arrangement may be configured to suppress controlling isolation of the sub-systems (in contrast to isolation that may be performed at step 308 in response to detecting single cause fault). A further fault detection example will now be described for an example where the sub-system corresponds to a propulsion sub-system (i.e. a propulsion channel). The operation parameter may correspond to a voltage, current, or motor speed (which is measured based on the current or voltage). In this example, one of the propulsion sub-systems may report to the controller arrangement a high current (i.e. a current above a predetermined threshold). This may initially be flagged by the controller arrangement as a fault. The controller arrangement may then compare this fault with the other propulsion sub-systems and determine that the other propulsion subsystems are not experiencing this fault (i.e. that the currents associated with these propulsion sub-systems is not greater than the predetermined threshold, for example), i.e. step 307. As only one propulsion system has been flagged as having a fault, a single cause fault will be determined (i.e. not a common cause fault). In other words, the 307 No branch is taken to step 308. The controller arrangement may then control the sub-system to isolate, for example, or may take no further action. Another possibility is that all propulsion sub-systems show the same fault. For example, an external event may cause all propulsion sub-systems to register the same fault. In this example, all propulsion sub-systems may measure their motor speed using the same measurement technique, and when 8 volts is measured this represents maximum speed. It will be appreciated that 8 volts may be measured across the positive terminal at 8V and the negative terminal at 0V. When a solar flare occurs, for example, the impact may be seen across the whole aircraft and thus all propulsion motors (and thus propulsion sub-systems). A consequence of this external event may be that the negative terminal of all the similar measurement systems rises by +4V, for example. The impact of this may be that every propulsion channel now measures 4V (and not 8V). This would suggest the propulsion motor is now at half speed (instead of actually still being at full speed). The measured speed derivation will be flagged as a fault by all propulsion sub-systems (as this is now not within the operating range) and reported to the controller arrangement. The controller arrangement will therefore determine at 303 that the operation parameter (speed or voltage) satisfies a fault condition based on receiving data reported by a first propulsion sub-system and will follow the YES 303 branch to step 305. As more than one channel is showing the same fault and these channels / sub-systems are reporting this fault, the controller arrangement will determine that the fault is a common cause fault (i.e. the 307 Yes branch is taken to step 309). Having determined that the fault is a common cause fault, the controller arrangement may suppress isolation associated with the propulsion sub-systems (in contrast to when a single cause fault is detected). Instead, the controller arrangement performs the actions(s) described herein to enable enhanced diagnostics and fault definition to take place. If the controller arrangement didn’t take this action and instead allowed the propulsion sub-systems to isolate their faults, all propulsion sub-systems would isolate and the aircraft would lose all propulsion from one single external event. The actions performed in response to detecting a single cause fault or a common cause fault will now be described with reference to figure 4. Figure 4 shows a method 400. Method 400 illustrates examples actions that may be performed by the controller arrangement described herein response to detecting a single cause or a common cause fault. Steps 401 and 402 correspond to steps 301 and 302 of figure 3. At 402, the controller arrangement detects the fault associated with the sub-system based on determining first measurement data (corresponding to the operation parameter associated with the subsystem) using a first measurement technique. For example, the controller arrangement may determine first measurement data associated with a first sensor arrangement. Step 403 corresponds to the Yes branch of 303 and thus corresponds to steps 305, 306 and 307, but are shown as a single step for clarity. At 404, and in response to detecting a single cause fault (i.e. that the fault does not affect more than one sub-system), a single cause fault action is performed. As described in relation to step 308 of figure 3, the controller arrangement may perform an action including controlling isolation of the sub-system experiencing the fault. In some examples, fault mitigation techniques may be performed such as component isolation or sub-system shutdown. This action may be performed by communicating with one or more other controller devices, such as a lower-level controller associated with an individual component or sub-system. As such, the action may comprise signalling a command to one or more other controllers associated with the sub-system to cause the one or more other controllers to control the sub-system to isolate a component or perform a shutdown. In response to detecting a common cause fault (the Yes branch of 403), the controller may perform an action, including one or more steps. The Yes branch of 403, i.e. steps 405 onwards, correspond to an action having one or more steps that may be performed. It will be appreciated that the action may include one or more of the steps, and does not necessarily include all of the steps. Indeed, in some cases, the action may comprise different combinations of steps 405 onwards. At 405, and in response to determining that the fault affects more than one sub-system (i.e. that a common cause fault is present), the controller arrangement determines diagnostic data associated with the aircraft. To determine the diagnostic data, the controller arrangement may be configured to use a second measurement technique different from the first measurement technique (that was used to detect the fault and determine the first measurement data that corresponds to the operation parameter). The present inventors have identified that in common cause fault scenarios, the likelihood that the measurement technique (such as the first sensor arrangement) has also been affected by the fault and thus cannot be trusted to provide an accurate measurement is increased. Thus, for a common cause fault, diagnostic data is determined using a different measurement technique from the measurement technique that was used to detect the fault in the first place. The different technique for determining the diagnostic data may take a variety of forms. For example, the second measurement technique may comprise determining the diagnostic data based on one of more of: determining data associated with a second sensor arrangement different from the first sensor arrangement; determining data associated with a system of the aircraft other than the electrical power propulsion system; using an analytical model; and measuring a property of a sub-system of the electrical power propulsion system in response to modifying a power demand of the sub-system. At 406, the controller arrangement may be configured to modify an operation range of an operation parameter of the first and / or second sub-systems. Step 406 may be based on the determined flight characteristic. Thus, the controller arrangement may modify an operation range for an operation parameter, and control the first and / or second sub-systems to be based on the modified operation range. It will be appreciated that controlling the first and / or second sub-systems based on the modified operating range may comprises signalling one or more other controllers to cause the one or more other controllers to control operation of the first and / or second sub-systems based on the modified operating ranges. In this way, the present controller arrangement may communicate with one or more other (e.g. low-level) controllers. By modifying the operating range for the first and / or second sub-systems in response to detecting the common cause fault, the controller arrangement is able to provide a temporary operational state in which the first and / or second sub-systems are able to operate outside of their normal operating ranges to provide an increased period of time to investigate the fault and mitigate the fault. At 407, the controller arrangement determines whether resetting a second sub-system satisfies a reset condition. The second sub-system may correspond to the first sub-system and / or the one or more other sub-systems that were used to detect the presence of the common cause fault. The present inventors have identified that performing a reset (i.e. the powering off / shutting down and then powering on / turning on) for a sub-system can in a number of fault scenarios, clear the fault and return the sub-system to normal operation. However, such resets can be performed safely for certain flight characteristics but not others. Thus, the controller arrangement determines whether resetting the second sub-system satisfies a reset condition. This could be based on the determined flight characteristic and / or the diagnostic data. For example, the controller arrangement may evaluate predetermined safe reset thresholds to determine whether a reset of the second sub-system can be performed safely and without sacrificing aircraft safety. For example, the controller arrangement may compare the operation parameters, flight characteristic and diagnostic data to one or more predetermined safe reset thresholds or profiles to determine whether a reset can be performed safely. For example, a reset condition may not be satisfied when an operation parameter of a propulsion sub-system indicates a high power draw and the flight characteristic indicates that the aircraft is taking off. In such a case, resetting the propulsion sub-system may be considered not to satisfy the reset condition. At 408, in response to determining that the reset condition is not satisfied, the controller arrangement does not reset the second sub-system (for example, suppresses resetting the second sub-system). This may be because it is considered not safe to reset the second subsystem at this point. In some cases, step 408 also comprises suppressing controlling isolation of the second sub-system. The controller arrangement may then take a variety of actions. For example, the controller arrangement may determine further diagnostic data (409) to investigate the fault further. It may then re-evaluate the reset condition at 407 based on the further diagnostic data. As discussed above, in an example where the speed measurements from the propulsion motor of the propulsion sub-system are commonly corrupted by the common cause event (e.g. the solar flare) then the effects of this will register as an unwanted change in the speed of the aircraft that other aircraft sensors will detect aiding fault diagnostics. By sharing data at the aircraft level, greater diagnostic information on the event can be understood. At 410, the controller arrangement may modify an operation range of an operation parameter of the second sub-system. For example, after determining that it is not safe to reset the second sub-system, the controller arrangement may modify an operating range (such as to near a limit of the possible operating range) of the second sub-system, in an attempt to ride-through the fault by allowing the second sub-system to operate at a level which may affect its long term lifespan. This may provide a short-term solution to allow the aircraft to progress through its current flight characteristic (such as take-off), to a point where it may be safe to reset the sub-system. Thus, after step 410, the method may return to step 407 to re-evaluate the reset condition. After a predetermined number of modifications to the operating range at 410, the controller arrangement may generate a notification (not shown), for example notifying that the fault has not been resolved. This may be used to warn an operator of the aircraft that a fault has not been resolved and that the fault may be catastrophic. When the reset condition is satisfied, the controller arrangement may perform a reset of the second sub-system at 411. As discussed, this may comprise powering off the second subsystem and then powering on the second sub-system after a predetermined time period. At 412, the controller arrangement determines whether the fault has cleared. For example, the controller arrangement may determine an operation parameter of the second sub-system and determine whether the operation parameter indicates that the fault has cleared. For example, the operation parameter may have returned to a predefined ‘normal’ or expected operating range. At 414, when the controller arrangement determines that the fault has not cleared at 412, the controller arrangement may determine further diagnostic data (in a similar manner to step 409) and re-evaluate step 412. The controller may move from step 413 to modify an operation range of an operation parameter of the second sub-system (in a similar manner to step 410). Step 412 may then be re-evaluated, or alternatively step 407 may be re-evaluated and the second sub-system may be reset again. At step 414, when the controller arrangement determines that the fault has cleared, the process may end. The controller arrangement has in this case cleared the common cause fault. A further example based on a solar flare event will now be described. In the event of a solar flare, as discussed above, all propulsion sub-systems may be registering a fault and thus the speed measurement (which in some cases may be based on a voltage measurement) may no longer be accurate. For example, the solar flare event may cause readings to change by +4V as discussed above, thus resulting a determined terminal voltage to half if the original positive terminal voltage was 8V. In some cases, the common cause fault may naturally clear and thus no action is required. Indeed, common cause events (such as solar flares and lightning strikes) may be transient in nature and thus the fault may only be temporary. Therefore at any stage during the process the common cause event can cease. This can be determined by the controller arrangement periodically detecting whether a fault is present (for example determining the operation parameter, such as voltage or speed). However, in some cases the fault does not naturally clear and so the controller arrangement may perform an action, such as reset. The controller arrangement may then determine an optimal time and way in which to perform the reset, which is based on the determined flight characteristic. For example, when the aircraft is in a short-term state where it is necessary for a safe aircraft to maintain maximum propulsion (early stages of take-off), the loss of any propulsion at this stage may be hazardous. Under this condition a “Safe to Reset” flag will be false - i.e. resetting the second sub-system does not satisfy the reset condition of step 407. In this case, the controller arrangement acts to determine a continuous operating approach in the knowledge that the speed measurement (due to the solar flare affecting the voltage read-outs, as described above) is inaccurate. One way to do this is for the controller arrangement to determine further diagnostic data (i.e. step 409). This may be done by determining the further diagnostic data from a different measurement system, such as by determining from the Vehicle Management System the aircraft speed. In some examples, it may be possible to reset the measurement sub-system associated with the propulsion sub-system (i.e. the measurement sub-system that erroneously outputs half speed) without resetting the propulsion sub-systems themselves. Thus, in some cases, the controller arrangement may reset the measurement sub-system and this itself clears the fault, as the measurement sub-systems were experiencing a fault but the underlying propulsion sub-systems were not. When the aircraft then enters a flight phase where only 50% propulsion sub-systems are required to maintain a safe aircraft, the controller arrangement may then be able to safely reset 50% of the propulsion sub-systems. Thus, in response to determining that the flight characteristics has changed, the controller arrangement may then re-evaluate step 407. In this case, the controller arrangement may then determine that 50% of the propulsion subsystems are safe to reset and thus satisfy the reset condition. Accordingly, the controller arrangement may be configured to control the sub-systems to reset (i.e. step 411). Operation ranges, operation parameters, and modification of operating ranges will now be described in greater detail with reference to figures 5 and 6. Figure 3 shows an example relationship 500 between propulsive power and propulsive current (i.e. operation parameters) for an example component or sub-system of the electrical power propulsion system (such as those shown in figure 1) for a given flight characteristic and fault scenario. As shown, there are three operating ranges 501, 502, 503 for the propulsion power and current. The first operating range 501 represents a normal operating range associated with a nominal maximum component lifetime. This first operating range 501 may for example correspond to a rating of the component that is associated with normal and safe operation. During a non-fault scenario, components of the electrical power propulsion system may have operation parameters that fall within the first operating range. Figure 5 shows a second operating range 502 that extends further on the x and y-axes than the first operating range 501. The second operating range 502 represents a deviation from normal operation parameters, and may be utilised during certain fault scenarios (such as common cause fault scenarios). While the second operation range 502 is not a worst-case operating range, it may be associated with a greater risk of component damage than the first operating range 501. Figure 5 also shows a third operating range 503 that extends further on the x and y-axes than the first operating range 501 and the second operating range 502. The third operating range 503 represents a worst case scenario, where the component is operating at a level where the component lifetime is impacted. It will be appreciated that figure 5 shows an example relationship for a given sub-system and a given flight characteristic. The controller arrangement may store such relationships for each sub-system and each flight characteristic. In some examples, the controller arrangement may store a maximum value of an operation parameter for one or more operating ranges (i.e. an end point of the range). Indeed, a first operating range for cruise may differ from a first operating range for take-off, etc., because the power demand may be significantly different. In some examples, the controller arrangement may store operational ranges for each flight characteristic for one or more sub-systems also for a plurality of aircraft degradation states and determined fault severities. Thus, in some examples, the controller arrangement may be configured to determine an aircraft degradation state and then determining the modified operating range may also be based on the degradation state. The degradation state may be indicative of an aircraft operational health. In some examples, the controller arrangement may be configured to determine a fault severity. For example, the controller arrangement may be configured to determine based on analysis of an operation parameter, for example over a time period, a fault severity. This may be based on one or more predetermined thresholds that indicate whether a severity of the fault. For example, if an operational parameter is power drawn, and the power drawn exceeds a first fault threshold, the fault may be determined as a least severe fault. If the power drawn excess a second fault threshold greater than the first threshold, the fault may be determined as a more severe fault. The controller arrangement may be configured to control operation of sub-systems of the electrical power propulsion system based on an operating range ata given time. For example, during cruise, the controller arrangement may be configured to control operation of a propulsion sub-system to operate within a first operating range. The controller arrangement may be configured to control sub-systems in this manner by communicating with one or more other aircraft systems to provide a maximum operation parameter that may be used. In this way, the controller arrangement may be configured to cause a sub-system to be controlled based on the operating range. An example process 600 for modifying an operation parameter based on detecting a fault will now be described with reference to figure 6. Figure 6 may be performed by the controller arrangement described herein. At 601, the controller arrangement determines a flight characteristic of the aircraft. This may be performed as described variously above. At 602, the controller arrangement determines an operation range for an operation parameter associated with operation of the sub-system. For example, the controller arrangement may determine an operating range corresponding to a ‘normal’ operation range for the sub-system, for example the first operating range 501 of figure 5. This may correspond to operation when a fault has not been detected. Step 602 may be based on the determined flight characteristic of 601. As mentioned in relation to figure 5, the controller arrangement may store a plurality of mappings between flight characteristics and operating ranges for each sub-system and for each fault state (for example, no fault, single cause fault, common cause fault). At 603, the controller arrangement controls operation of the sub-system based on the operating range. This may comprise the controller arrangement signalling to one or more other controller devices to control operation of the sub-system based on the operating range. In this way, the controller arrangement may comprise with one or more other controllers to control operation of the sub-system (such as with one or more lower level controllers). In some examples, the controller arrangement itself controls operation of the sub-system, for example by increasing a power / current draw of the sub-system. At 604, the controller arrangement may detect a fault. For example, the controller arrangement may detect a fault as described in relation to figure 3 or 4. The fault of 604 may be a single cause fault or common cause fault as determined at steps 303, 403, for example. In this way, steps 605 and 606 may be performed as part of an action that is performed in response to detecting a common cause fault or single cause fault. At 605, the controller arrangement determines a modified operating range for the operation parameter. This may comprise determining, based on one or more predetermined mappings / relationships, the modified operating range based on the determined flight characteristic and detected fault. As mentioned, the controller arrangement may store, for a plurality of fault scenarios, predetermined operating ranges for different flight characteristics for each sub-system. Thus, modifying the operating range may correspond changing from a first operating range to a second operating range. At 606, the controller arrangement controls operation of the sub-system based on the modified operating range. This may be performed in a similar manner to step 603 but based on the modified operating range. In this way, the controller arrangement is able to provide an adaptive approach, whereby operation of the sub-systems is based on the determined flight characteristic and in response to detecting a fault. This allows the controller arrangement to provide a temporary operational state in which a sub-system is able to operate outside of its normal operating ranges to provide an increased period of time to investigate the fault and mitigate the fault. The modification of operation parameters in response to detecting a fault can therefore synergistically interact with other actions performed in response to detecting the fault (such as determining diagnostic data, resetting a sub-system, etc.) to provide an improved response to the detected fault. Figure 7 schematically illustrates an example of an electronic device 700 which can be used to implement teachings described above, including method 200, 300, 400, and 600, and which may correspond to a controller or controller arrangement as described herein. The electronic device 700 has processing circuitry 710 for performing data processing in response to program instructions and data storage 720 for storing data and instructions to be processed by the processing circuitry 710. In some examples, the processing circuitry 710 includes one or more caches for caching recent data or instructions. The data storage 720 may have a database 730 which can, for example, store received information such as flight characteristic information or data received from sensor arrangements. The device further includes a communication interface 740 which can be used, for example, to obtain / receive information relating to the sub-systems and diagnostic data. It will be appreciated that Figure 7 is merely an example of possible hardware that may be provided in the device and other components may also be provided. The device 700 may additionally or alternatively be provided with one or more user input / output device(s) 750 to receive input from a user device (e.g. to detect the fault) or to output information (e.g. information relating to the detected fault or the performed action) to a user device. The methods discussed above may be performed under control of a computer program executing on a device. Hence a computer program may comprise instructions for controlling a device to perform any of the methods discussed above. The program can be encoded in a computer-readable medium. A computer-readable medium may include non-transitory type media such as physical storage media including storage discs and solid state devices. A computer-readable medium may also or alternatively include transient media such as carrier signals and transmission media. A computer-readable storage medium is defined herein as a non-transitory memory device. A memory device includes memory space within a single physical storage device or memory space spread across multiple physical storage devices. In the present application, the words “configured to...” are used to mean that an element of an apparatus has a configuration able to carry out the defined operation. In this context, a “configuration” means an arrangement or manner of interconnection of hardware or software. For example, the apparatus may have dedicated hardware which provides the defined operation, or a processor or other processing device may be programmed to perform the function. “Configured to” does not imply that the apparatus element needs to be changed in any way in order to provide the defined operation. Although illustrative teachings of the disclosure have been described in detail herein with reference to the accompanying drawings, it is to be understood that the invention is not limited to those precise teachings, and that various changes and modifications can be effected therein by one skilled in the art without departing from the scope and spirit of the invention as defined by the appended claims.

Claims

1. A controller arrangement for an electrical power propulsion system of an electrically powered aircraft, the controller arrangement configured to:determine a flight characteristic of the aircraft;detect a fault associated with a first sub-system of the electrical power propulsion system;determine whether the fault affects more than one sub-system of the electrical power propulsion system; andin response to determining that the fault affects more than one sub-system of the electrical power propulsion system and based on the determined flight characteristic, perform an action.

2. The controller arrangement of claim 1, wherein to perform the action, the controller arrangement is configured to:determine diagnostic data associated with the aircraft.

3. The controller arrangement of any preceding claim, wherein to perform the action, the controller is configured to:determine a modified operating range of an operation parameter of a sub-system of the electrical power propulsion system based on the flight characteristic of the aircraft; andcontrol operation of the sub-system of the electrical power propulsion system based on the modified operating range for the operation parameter of the sub-system.

4. The controller arrangement of any preceding claim, wherein to perform the action, the controller arrangement is configured to perform a reset action associated with a sub-system of the electrical power propulsion system.

5. The controller arrangement of claim 4, wherein to perform the reset action, the controller arrangement is configured to:determine whether resetting a second sub-system of the electrical power propulsion system satisfies a reset condition based on the diagnostic data and the determined flight characteristic of the aircraft; andreset the second sub-system of the electrical power system in response to determining that resetting the second sub-system of the electrical power system satisfies the reset condition.

6. The controller arrangement of any of claims 2 to 5, wherein:to detect the fault associated with the first sub-system of the electrical power propulsion system, the controller arrangement is configured to determine first measurement data using a first measurement technique; andto determine diagnostic data associated with the aircraft, the controller arrangement is configured to determine the diagnostic data using a second measurement technique different from the first measurement technique.

7. The controller arrangement of claim 6, wherein the first measurement technique comprises determining first measurement data associated with a first sensor arrangement, and the second measurement technique comprises determining the diagnostic data based on one of more of: determining data associated with a second sensor arrangement different from the first sensor arrangement; determining data associated with a system of the aircraft other than the electrical power propulsion system; using an analytical model; and measuring a property of a sub-system of the electrical power propulsion system in response to modifying a power demand of the sub-system.

8. The controller arrangement of any preceding claim, wherein the first and / or second sub-systems comprise one or more of: a propulsion arrangement, a motor arrangement, a high density power source arrangement, a battery arrangement, a super-capacitor arrangement and a measurement arrangement.

9. The controller arrangement of any of claims 5 to 8, wherein the first and second subsystem are the same or are different.

10. The controller arrangement of claims 7 to 9, wherein the first sensor arrangement and second sensor arrangement comprise one or more of: a vehicle management system sensor, a speed sensor, a fuel flow sensor, an air flow sensor, a water flow sensor, a voltage sensor, a current sensor, a power sensor, a position sensor, a vibration sensor, and a temperature sensor.

11. The controller arrangement of any preceding claim, wherein the controller arrangement is further configured to:determine an operating range for an operation parameter of a sub-system of the electrical power propulsion system based on the flight characteristic of the aircraft; andcontrol operation of the sub-system of the electrical power propulsion system based on the operating range for the operation parameter of the sub-system.

12. The controller arrangement of claims 3 to 11, wherein determining the operating range and modified operating range for the operation parameters is based on a predetermined mapping between operating ranges and flight characteristics.

13. The controller arrangement of claims 3 to 12, wherein determining the operating range and the modified operating range is also based on a determined aircraft degradation state and / or a determined fault severity.

14. The controller arrangement of any preceding claim, wherein to detect the fault associated with the first sub-system of the electrical power propulsion system, the controller arrangement is configured to:determine that an operation parameter associated with operation of the first subsystem of the electrical power propulsion system satisfies a fault condition for the determined flight characteristic of the aircraft.

15. The controller arrangement of claim 14, wherein determining that the operation parameter associated with operation of the first sub-system of the electrical power propulsion system satisfies the fault condition for the determined flight characteristic of the aircraft is based on determining sensor data associated with the first sub-system.

16. The controller arrangement of any preceding claim, wherein to determine whether the fault affects more than one sub-system of the electrical power propulsion system, the controller arrangement is configured to:determine whether operation parameters of one or more sub-systems of the electrical power propulsion system other than the first sub-system associated with the fault satisfy a fault condition for the determined flight characteristic of the aircraft.

17. The controller arrangement of any of claims 2 to 16, wherein the diagnostic data comprises data associated with an aircraft system other than the electrical power propulsion system, wherein optionally the aircraft system other than the electrical power propulsion system comprises a vehicle management system.

18. The controller arrangement of any preceding claim, wherein the first sub-system comprises a power electronic converter and a propulsion motor.

19. The controller arrangement of any preceding claim, wherein the fault is associated with an externally induced power surge or an externally generated unexpected demand on the electrical power propulsion system.

20. The controller arrangement of any preceding claim, wherein the electrically powered aircraft comprises a fuel cell as a high energy density power source arrangement.

21. A method for controlling an electrical power propulsion system of an electrically powered aircraft, the method comprising:determining a flight characteristic of the aircraft;detecting a fault associated with a first sub-system of the electrical power propulsion system;determining whether the error affects more than one sub-system of the electrical power propulsion system; andin response to determining that the error affects more than one sub-system of the electrical power propulsion system and based on the determined flight characteristic, performing an action.

22. A computer-readable medium comprising instructions which, when executed by one or more processors, cause the one or more processors to perform the method of claim 21.

23. An electrical power propulsion system for an electrically powered aircraft comprising: a high energy density power source arrangement for providing electrical power;a propulsion motor arrangement for receiving electrical power from the high energy density electrical power source arrangement and providing propulsion;and a controller arrangement configured to perform the steps of claim 21.

24. The electrical power propulsion system of claim 23, wherein the high energy density power source arrangement comprises a fuel cell.

25. An at least partially electrically powered aircraft comprising the controller arrangement of any of claims 1 to 20 or the electrical power propulsion system of any of claims 23 or 24.36

Citation Information

Patent Citations

  • A vehicle comprising an engine restart system

    US20180273195A1

  • Construction and operation of electric or hybrid aircraft

    US20200298728A1

  • In-flight stabilization of an aircraft

    US20210339882A1