Unmanned aerial vehicle with reversibly detachable components
By disassembling UAVs into components with parachutes for controlled descent, the technology addresses crash risks, enhancing safety and expanding operational altitudes, thus overcoming regulatory limitations.
Patent Information
- Application Number
- PCT/US2024/052935
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-30
- Filing Date
- 2024-10-25
- Publication Date
- 2025-09-18
AI Technical Summary
Unmanned aerial vehicles (UAVs) face limitations in flight operations due to the risk of crashes causing property damage and personal injury, restricted by FAA regulations, especially over populated areas, and lack of systems to safely manage mid-air collisions and crashes.
The aircraft is designed to controllably disassemble into separate components during flight using component release actuators, with each component slowed by individual parachutes for controlled descent, and optional self-destruction of sensitive components to prevent recovery.
This approach reduces the risk of damage and injury by distributing the aircraft's mass and energy into smaller, manageable components, allowing safer flight in various altitudes and increasing public confidence in UAVs, potentially opening lower airspaces for commercial use.
Smart Images

Figure US2024052935_18092025_PF_FP_ABST
Abstract
Description
UNMANNED AERIAL VEHICLE WITH REVERSIBLY DETACHABLE COMPONENTSRELATED APPLICATIONS
[0001] This application claims the priority benefit of U.S. Provisional Patent Application Serial No. 63 / 594,273, filed on October 30, 2023, and entitled “Unmanned Aerial Vehicle With Reversibly Detachable Components,” which provisional application is hereby incorporated by reference in its entirety for all purposes.FIELD OF THE DISCLOSURE
[0002] The present disclosure generally relates to the field of aviation safety. More particularly, the disclosure provides a system for reducing the probability of property damage and personal injury from failures and resulting crashes of unmanned aerial vehicles.BACKGROUND
[0003] Unmanned aerial vehicles (sometimes called UAVs or unmanned aerial systems UASs) have become increasingly popular in recent years due to their ability to perform tasks that are too dangerous or difficult for human pilots. They may also be less expensive than manned aircraft for some tasks. Both the commercial availability and public need (including military need) for unmanned aerial vehicles are rising.
[0004] However, there is always a risk of these vehicles malfunctioning and causing harm. As a result, the use of unmanned aerial vehicles is restricted by the Federal Aviation Administration (FAA). All domestic unmanned aerial vehicle operations must be conducted in accordance with FAA policies and regulations.
[0005] At present, unmanned aerial vehicles are not generally free to fly in civilian airspace (sometimes referred to as the National Airspace System or NAS). All unmanned aerial vehiclesused by the Department of Defense currently need special waivers and approval to fly in the NAS, so are often limited to areas specifically allocated for such flights. These limitations severely limit the military and commercial missions that can be conducted by unmanned aircraft.
[0006] Rules for small unmanned aerial vehicles, meeting weight-based classifications, limit their flight operations to line-of-sight conditions, so their human operators can observe them directly. While many lightweight unmanned aerial vehicles are available, these aircraft are typically inadequate for carrying many higher-quality sensors that weigh more. Commercial aerial imaging companies need unmanned aircraft that weigh more but may be flown outside the visual range of a human operator.
[0007] Commercially available satellite image resolution may be too low for most businesses to derive useful information. High resolution remote sensing is best conducted at lower altitudes, typically below 5000 feet above ground level. However, much of the demand for data collection is over urban or at least populated areas, which is precisely where unmanned aircraft flights are most restricted.
[0008] The FAA evaluates operational risk for crewed aircraft by examining the risks to three different groups or parties that may be harmed. The first party comprises persons onboard the aircraft itself. The second party comprises persons onboard other aircraft, who are at risk of a mid-air collision with the aircraft of interest. The third party comprises persons and property on the ground.
[0009] For unmanned aircraft, there is no first party, so the FAA’s risk analysis focuses on the second and third parties. Risk reduction for persons aboard another aircraft, i.e., the second party, is typically dependent on various mid-air collision avoidance systems. These systems are known in the art and operate by identifying nearby aircraft or other obstacles and then takingsteps to navigate away from them, in what is termed a “detect and avoid” process. W-band radar and light detection and ranging (LIDAR) are technologies enabling unmanned aerial vehicles to operate autonomously near obstacles or other aircraft and while avoiding collisions, for example.
[0010] The FAA is slowly modifying the regulatory situation to balance the viability of flight and the risk of harm to people and property on the ground. For agricultural flights, the risk is primarily to the pilot since the flights are generally not over populated areas. Nonetheless, fifty- four accidents related to manned agricultural flight occurred in 2020, with twelve fatal accidents resulting in thirteen deaths. The FAA has therefore begun certifying more unmanned agricultural aircraft recently, as they typically avoid flights over populated areas.
[0011] Thus, an improved method for minimizing aircraft crash damage would be advantageous in overcoming the legal and practical limitations currently in place. This disclosure is directed to mitigating the risk of an aircraft crash that could damage property and / or injure persons on the ground. This disclosure provides a safety approach that may moot the risk avoidance issue by preventing harm to people in flight areas altogether.SUMMARY
[0012] In some aspects, the techniques described herein relate to a method for safely terminating a flight of an aircraft to mitigate air to ground damage risk, including: controllably disassembling the aircraft into separate components during the flight; and slowing component descent trajectories with individual parachutes.
[0013] In some aspects, the techniques described herein relate to a non-transitory computer- readable storage medium having embedded therein a set of instructions which, when executed by one or more processors of a computer, causes the computer to execute operations for safely terminating a flight of an aircraft to mitigate air to ground damage risk, the operations including:controllably disassembling the aircraft into separate components during the flight; and slowing component descent trajectories with individual parachutes.
[0014] In some aspects, the techniques described herein relate to a system for safely terminating a flight of an aircraft to mitigate air to ground damage risk, including: controllably disassembling the aircraft into separate components during the flight, using component release actuators; and slowing component descent trajectories using individual parachutes.
[0015] In some aspects, the techniques described herein relate to an apparatus for safely terminating a flight of an aircraft to mitigate air to ground damage risk, including: a plurality of individual components connected with component release actuators that, when activated, are configured to detach at least some of the components from each other to disassemble the aircraft during the flight; at least one parachute for each component configured to deploy upon the disassembly; and at least one trigger mechanism that is configured to controllably activate the component release actuators and the parachutes.
[0016] Other technical features may be readily apparent to one skilled in the art from the following figures, descriptions and claims.BRIEF DESCRIPTION OF THE DRAWINGS
[0017] For a more complete understanding of this disclosure, reference is now made to the following description, taken in conjunction with the accompanying drawings, in which:
[0018] FIG. 1 is a first view of an aircraft system, according to one aspect.
[0019] FIG. 2 is a second view of an aircraft system, according to one aspect.
[0020] FIG. 3 is a third view of an aircraft system, according to one aspect.
[0021] FIG. 4 is a diagram of a controller for the aircraft system, according to one aspect.
[0022] FIG. 5 is a diagram of the controller and remote nodes for the aircraft system,according to one aspect.
[0023] FIG. 6 is a diagram of the controller for the aircraft system, according to one aspect.
[0024] FIG. 7 is a further diagram of the controller for the aircraft system, according to one aspect.
[0025] FIG. 8A is a diagram of a graphical user interface (GUI) for the aircraft system, according to one aspect.
[0026] FIG. 8B is a diagram of a portion of a detailed depiction in the GUI for the aircraft system, according to one aspect.
[0027] FIG. 9 is a diagram of the logic operations performed by the controller for the aircraft system when operated by a human, according to an aspect.
[0028] FIG. 10 is a diagram of the logic operations performed by the controller for an aircraft system when operated by the controller, according to an aspect.DETAILED DESCRIPTION
[0029] Various aspects of the disclosure are described more fully hereinafter with reference to the accompanying drawings. This disclosure may, however, be implemented in many different forms and should not be construed as limited to any specific structure or function presented throughout this disclosure. Rather, these aspects are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art. Based on the teachings herein one skilled in the art should appreciate that the scope of the disclosure is intended to cover any aspect of the disclosure disclosed herein, whether implemented independently of or combined with any other aspect of the disclosure. For example, an apparatus may be implemented or a method may be practiced using any number of the aspects set forth herein. In addition, the scope of the disclosure is intended to cover such anapparatus or method which is practiced using other structure, functionality, or structure and functionality in addition to or other than the various aspects of the disclosure set forth herein. It should be understood that any aspect of the disclosure disclosed herein may be embodied by one or more elements of a claim. The word “exemplary” is used herein to mean “serving as an example, instance, or illustration.” Any aspect described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other aspects. Although particular aspects are described herein, many variations and permutations of these aspects fall within the scope of the disclosure. Although some benefits and advantages of the preferred aspects are mentioned, the scope of the disclosure is not intended to be limited to particular benefits, uses, or objectives. The detailed description and drawings are merely illustrative of the disclosure rather than limiting, the scope of the disclosure being defined by the appended claims and equivalents thereof.
[0030] This application discloses a new approach to increasing aviation safety. The approach reduces the probability of property damage and personal injury from crashes of unmanned aerial vehicles. Briefly, the approach is to controllably disperse an aircraft into a number of individual components, each of which may then undergo a controlled descent to the ground by parachute. Sensitive components and data may also be subjected to self-destruction, e.g., via explosive device detonations, application of high voltage discharges, or other destructive methodologies, to prevent their recovery.
[0031] The maximum weight and terminal velocity of each component are designed such that little to no damage will occur to property and persons on the ground. Components may also be padded and may emit audible and / or visual warnings to this end. This disclosure therefore offers a safer and more sustainable future for unmanned aerial vehicles.
[0032] One benefit of the technology described here is that an unmanned aerial vehicle may be designed that can carry larger sensor packs at lower altitudes with FAA type certification. Another benefit of this approach is that it can increase public confidence in unmanned aerial vehicles. Demonstrations showing these aircraft have built-in safety features may alleviate concerns about their use and increase public support for their adoption in a wide range of applications. It is possible that aircraft implementing the technology described herein will open the lower airspaces (200 to 7500 feet above ground level) for increased commercial use.
[0033] FIG. 1 illustrates a first view of an aircraft system 100, according to one aspect. Aircraft system 100 comprises a fuselage 102, a left wing assembly 104, a right wing assembly 106, a tail assembly 108, and one or more optional cargo carriers (not shown). Fuselage 102 typically contains systems for navigation, communication, and propulsion, as well as any additional instrumentation for carrying out specific missions.
[0034] In a conventional aircraft, the various components are permanently assembled together at the factory, so the aircraft (whether manned or unmanned) is effectively a single unit. If a major failure occurs in flight, the aircraft may crash as a unit into properties (buildings, vehicles, etc.) and / or persons on the ground, causing significant damage and / or injury. For manned aircraft, the pilot may be able to navigate to a safe landing in spite of a major failure, by gliding if necessary. In other cases, the pilot may be able to navigate to a location where a crash landing will at least avoid significant damage to property or injury to people on the ground. The crash may nonetheless cause damage to the aircraft and / or injury to the pilot and any passengers.
[0035] With unmanned aerial vehicles, there is no pilot (nor passengers) onboard but there may instead be a human operator directing the flight remotely, e.g., via electromagnetic communication links. There may also be an electronic controller 200 onboard that is capable offlying the aircraft along a programmed route and communicating with the operator. Aircraft system 100 may be capable of flying the route without human guidance, but there may be legal restrictions preventing such flight without the aircraft system 100 being within a direct line of sight of a human operator. In the event of a major malfunction, controller 200 may or may not be able to safely land or crash land aircraft system 100 as capably as a human pilot.
[0036] FIG. 2 illustrates a second view of aircraft system 100, according to one aspect. Aircraft system 100 embodies the technology disclosed herein that allows it to disperse or disassemble in a controlled manner, during flight, into a plurality of individual components. For example, fuselage 102, left wing assembly 104, right wing assembly 106, and tail assembly 108 may all detach from each other, so aircraft system 100 is no longer a single unit thereafter but a collection of separate components.
[0037] Prior to disassembly, each component is normally connected to one or more other components with sufficient strength to withstand the various aerodynamic forces aircraft system 100 may experience in flight. During disassembly, component release actuators are activated to separate the components as shown. The actuators may operate according to a variety of operational principles, including electromagnetic, mechanical, pneumatic, hydraulic, aerodynamic, and explosive mechanisms, as known in the art with the aid of this disclosure. In one embodiment, an electromechanical solenoid or servo or set of electromagnets may cause one or more mechanical pins to be pulled in response to an electrical signal, to mechanically disassemble components, for example. The electrical signal may be provided by a rechargeable battery, for example, or from an onboard alternator or auxiliary power unit or other electrical power source. Likewise, in another aspect, a controlled valve may provide pneumatic or hydraulic pressure to cause components to mechanically disassemble, for example. Further, inanother exemplary aspect, an aerodynamic component may be moved into exterior airflow to cause or help cause components to disassemble.
[0038] Further, the component release actuators may be reset after landing and retrieval, so that a plurality of the components may be easily attached together again or reconnected. Thus, an aircraft system 100 may be disassembled in flight and then reassembled later for re-use. Further, this feature allows damaged components to be replaced with undamaged components while the damaged components are being repaired or discarded.
[0039] FIG. 3 illustrates a third view of aircraft system 100, according to one aspect. After disassembly, separate components 102-108 may each be configured to deploy at least one parachute 112, 114, 116, or 118 as shown, to decrease their velocity via enhanced drag. The parachutes may be designed to safely convey a component of a given weight to the ground.
[0040] The dispersal of the components serves to distribute the overall mass and kinetic energy of aircraft system 100 into multiple pieces, each of lower mass and energy. There may be a maximum weight value allowed for each component. For example, in one aspect each component may be limited to a weight of twenty-five pounds, to reduce the mass that might impact persons or property on the ground when the component descends. In another aspect, a component may be padded to absorb more impact energy without causing more damage when the component completes its descent. Operational rules may, for example, allow a component to weigh more (e.g., fifty pounds) when it is padded.
[0041] Some components may be provided with more than one parachute. Some components may be padded instead of using a parachute to reduce impact damage, while other components may be both padded and have a parachute for additional protection. The parachutes may have their own deployment mechanisms that are activated upon disassembly, or may simplybe exposed to airflow upon disassembly for self-deployment. Further, the parachutes may actually assist with the disassembly in some embodiments, by providing drag forces that help separate at least one of the components.
[0042] In one embodiment, fuselage 102 is the heaviest component with the most valuable equipment. Thus, fuselage 102 may be both padded and may deploy at least one parachute 112 when separated, and may, for example, even have means for guiding its descent by steering toward a low-impact landing location after disassembly. In another embodiment, aircraft system 100 may carry cargo in a carrier that could also include valuable equipment, such as photographic equipment, typically to be saved via the controlled dispersal. In most cases, all data and components may be fully recovered, although in some scenarios some data may be lost and / or some components may be damaged or destroyed, so that only a partial recovery is feasible.
[0043] Alternatively, in other cases, reliable destruction of components or data may be very desirable, such as in covert espionage missions, for example. To that end, selected components of aircraft system 100 may be equipped with self-destruct devices that may be activated to ensure destruction of such equipment or data. The self-destruct devices may be activated concurrently with a disassembly or may activate shortly thereafter, when different components of aircraft system 100 have moved apart some distance, such that explosive self-destruct devices will not damage other components unintentionally, for example.
[0044] At least one of the components may include one or more tracking devices to simplify recovery of the component upon arrival at the ground. For example, a component may include an emergency radio beacon, a flashing light or strobe light, a GPS transponder, or an ADS-B system. In an ADS-B (Automatic Dependent Surveillance-Broadcast) system, an aircraftdetermines its position via satellite navigation or other sensors and periodically broadcasts it, enabling it to be tracked. The information can be received by air traffic control ground stations. The position data may also be transmitted and received by other aircraft. ADS-B is “automatic” in that it requires no pilot or external input, and is “dependent’ as it depends on data from the aircraft's own navigation system. Exemplary satellite navigation systems may include GNSS (Global Navigation Satellite Systems), such as the GPS (Global Positioning System) commonly used in North America (and elsewhere) and other similar systems used elsewhere.
[0045] Tethers may remain controllably attached between components of aircraft system 100 as the components otherwise detach, to help keep disassembled components within a given distance of each other during descent so they descend as a group, in one embodiment. In some aspects, one or more balloons may be released to assist with identification and recovery of one or more components, such as via a separate aerial vehicle. The balloons may be inflated with a lifting gas and released upon disassembly of aircraft system 100, or upon later receipt of an electronically transmitted deployment command, for example.
[0046] Note that although aircraft system 100 is often described as unmanned throughout this disclosure, the controlled disassembly aspects could also be applicable to manned aircraft. The technology described could provide a safer outcome for everyone when a pilot becomes incapacitated. Likewise, if a pilot dies during flight, the technology could help a non-pilot passenger avoid a damaging or injurious crash. The parachutes used in such cases would necessarily need to handle more weight than with a typical unmanned aircraft system 100. Even if disassembly is not required, aircraft system 100 may increase flight safety via its autonomous flight control capabilities or by assisting a human pilot with flight operations.
[0047] FIG. 4 illustrates a diagram of controller 200 for aircraft system 100, according to oneaspect. Controller 200 may carry out the functionality described herein. Controller 200 may represent, for example, computing or processing capabilities found within desktop, laptop and notebook computers, hand-held computing devices (personal digital assistants (PDAs), smart phones, cell phones, palmtops, etc.), mainframes, supercomputers, workstations or servers, or any other type of special-purpose computing devices as may be desirable or appropriate for a given application or environment. Controller 200 might also represent computing capabilities embedded within or otherwise available to a given device.
[0048] Controller 200 might include, for example, one or more processors, controllers, control components, or other processing devices, such as a processor 204. Processor 204 might be implemented using a special-purpose processing engine such as, for example, a microprocessor, controller, or other control logic. In one embodiment, controller 200 may include a redundant processor system, such that if one processor 204 fails, a separate backup processor 204 can automatically operate as is replacement. In the illustrated example, processor 204 is connected to an exemplary bus 202, although any communication medium may be used to facilitate interaction with other components of controller 200 or to communicate externally.
[0049] Bus 202 may be implemented using known communications standards, such as CAN (Controller Area Network), CAN FD, DroneBUS, Ethernet, and Flexnet, or other standards promulgated by IEEE, ANSI, ASTM, or other standards bodies, for example. Bus 202 may transmit various heartbeat signals from connected devices to controller 200, such that an absence of such signals can indicate a problem with a device. Controller 200 and bus 202 may also implement security management protocols to protect communications channels from unauthorized access, cyber threats, or other nefarious activities. Bus 202 may actually comprise a primary network that connects remote nodes 230 directly to controller 200, and a secondarynetwork that connect remote nodes 230 to each other. A third network, perhaps using a different communications protocol such as Ethernet, may provide additional communications redundancy.
[0050] Controller 200 might also include one or more memory components, simply referred to herein as main memory 208. For example, random access memory (RAM) or other dynamic memory, might be used for storing information and instructions to be executed by processor 204. Main memory 208 might also be used for storing temporary variables, encryption keys, sensor data, operating software, mission profile data, or other intermediate information during execution of instructions to be executed by processor 204. Controller 200 might likewise include a read only memory (ROM) or other static storage device coupled to bus 202 for storing static information and instructions for processor 204.
[0051] Controller 200 might also include one or more various forms of nonvolatile information storage mechanism 210, which might include, for example, a media drive 212 and a storage unit interface 220. Media drive 212 might include a drive or other mechanism to support fixed or removable storage media 214. For example, a hard disk drive, a floppy disk drive, a magnetic tape drive, an optical disk drive, a compact disc (CD) or digital versatile disc (DVD) drive (read-only or read / write), or other removable or fixed media drive might be provided. Accordingly, storage media 214 might include, for example, a hard disk, a floppy disk, magnetic tape, cartridge, optical disk, a CD or DVD, or other fixed or removable medium that is read by, written to or accessed by media drive 212. As these examples illustrate, storage media 214 may include a non-transitory computer-readable storage medium having tangibly stored therein computer software or data.
[0052] Generally, where components of the technology described are implemented in whole or in part using software in one aspect, these software elements may be implemented to operatewith a computing or processing component capable of carrying out the functionality described. Controller 200 shown in Figure 4 is thus an exemplary computing component that may represent multiple such components in practice. After reading this description, it will become apparent to a person skilled in the relevant art how to implement the technology using other computing components or architectures.
[0053] In alternative aspects, information storage mechanism 210 might include other similar instrumentalities for allowing computer programs or other instructions or data to be loaded into controller 200. Such instrumentalities might include, for example, a fixed or removable storage unit 222 and a storage unit interface 220. Examples of such storage units 222 and storage unit interfaces 220 may include a program cartridge and cartridge interface, a removable memory (for example, a flash memory or other removable memory component) and memory slot, a personal computer memory card international association (PCMCIA) slot and card, and other fixed or removable storage units 222 and storage unit interfaces 220 that allow software and data to be transferred from storage unit 222 to controller 200.
[0054] Controller 200 might also include a communications interface 224. Communications interface 224 might be used to allow software and data to be transferred between controller 200 and external devices. Examples of communications interface 224 might include a modem or softmodem, a network interface (such as an Ethernet, network interface card, WiMedia, IEEE 802. XX or other interface), a communications port (such as for example, a USB port, IR port, RS232 port Bluetooth® interface, or other port), or other communications interface. Software and data transferred via communications interface 224 might typically be carried on signals, which may be electronic, electromagnetic (which includes optical) or other signals capable of being exchanged by a given communications interface 224. These signals might be provided tocommunications interface 224 via a channel 228. Channel 228 might carry signals and might be implemented using a wired or wireless communication medium. Some examples of a channel might include a phone line, a cellular link, an RF link, an optical link, a network interface, a local or wide area network, and other wired or wireless communications channels. Various radio communications protocols may be used, including but not limited to the VITA 49.2 radio transport protocol, for example.
[0055] In this document, the terms “computer program medium” and “computer usable medium” are used to generally refer to media such as, for example, memory 208, storage unit interface 220, storage media 214, and channel 228. These and other various forms of computer program media or computer usable media may be involved in carrying one or more sequences of one or more instructions to a processing device for execution. Such instructions tangibly embodied on the medium, are generally referred to as “computer program code” or a “computer program product” (which may be grouped in the form of computer programs or other groupings). When executed, such instructions might enable controller 200 to perform features or functions of the disclosed technology as discussed herein. Controller 200 may use a real-time operating system, in one embodiment. Controller 200 and indeed all onboard electronic systems may be powered by rechargeable batteries, which may optionally be recharged in flight.
[0056] Controller 200 is the computing nexus of the aircraft system 100. Controller 200 may receive input signals from various sensors within aircraft system 100 indicating altitude, velocity, orientation in space, course of travel, and data regarding different onboard systems, for example. Onboard sensors may also include an IMU (inertial measurement unit) that provide acceleration data, as well as other sensors providing fuel level, avionics status, and data regarding the onboard electrical system. Additional onboard sensors may provide data from measurements of light,vibration, humidity, temperature, air pressure, air quality (e g., whether smoke or gases from combustion or explosions are present), and magnetic anomalies. Such measurements may provide information that is useful in determining if aircraft system 100 is suffering from various failures or combat damage. Controller 200 may also generate output signals to control various actuators within aircraft system 100 controlling aspects of flight, such as settings for flaps, rudder, ailerons, engine speed, actuators for disassembly and / or self-destruct events, and communication settings.
[0057] Controller 200 may be programmed to implement commands provided by a human operator via a communication link and to provide feedback to the operator via such a link. Further, controller 200 may be programmed to control aircraft system 100 to follow a predetermined flight plan, including altitudes, geographical waypoints, and air speeds.Controller 200 may also gather data and issue commands to mission-specific hardware, such as high resolution digital cameras, radars, and other equipment as may be required for a given mission.
[0058] In the event that the law allows, controller 200 may be allowed to determine the flight plan of aircraft system 100 on its own, based on various conditions that occur during a flight. This may include making the decision to disperse or disassemble the aircraft rather than attempting to make a landing. Further, in the event that a dispersal is deemed appropriate, controller 200 may modify the flight of aircraft system 100 prior to the dispersal, for example, to identify the best feasible location where the dispersal should occur to minimize damage and injury.
[0059] FIG. 5 is a diagram of controller 200 and remote nodes 230 for aircraft system 100, according to one aspect. Each remote node 230 may include at least one trigger mechanism.The trigger mechanisms of remote nodes 230 may be configured to controllably activate the component release actuators, self-destruct actuators, and parachutes, either in response to commands from a human operator or from electronic controller 200. In one embodiment, each actuator may be triggered by its own trigger mechanism.
[0060] Each remote node 230 may further comprise a sensor to determine the actuator status, and a transceiver to relay (i.e., send and receive) status messages and disassembly commands to / from controller 200 and to / from other remote nodes 230 over bus 202. The status messages may, for example, indicate whether an actuator is in an assembled state or is in a disassembled state. Such status messages may help controller 200 determine if (and ensure that) the vehicle has detached all its components when commanded to do so. Each remote node 230 may thus serve as an interconnected intelligent networked computing element that assists controller 200 with status monitoring and disassembly / self-destruct operations.
[0061] In some embodiments, each vehicle component may have multiple remote nodes 230, optionally with more than one trigger mechanism for each actuator for redundancy, to ensure reliable disassembly. Likewise, during reassembly, remote nodes 230 may confirm to controller 200 that various actuators for various components have been properly returned to attached status. Controller 200 and remote nodes 230 and other onboard systems may be powered by one or more rechargeable batteries, either directly or as a backup mechanism to provide redundancy.
[0062] FIG. 6 is a diagram of controller 200 for aircraft system 100, according to one aspect.In this example, controller 200 comprises three separate computational units, which may comprise hardware elements or software elements, or combinations thereof. The first such unit, 232, may comprise a flight control unit that processes navigational data and aircraft system data, and issues various flight control signals to keep aircraft system 100 on a desired trajectory (e.g.,course, altitude, and speed). The second such unit, 234, may comprise a mission support unit that processes sensor data and controls equipment specific to a particular mission to which aircraft system 100 has been assigned, via provided mission profile data. The third such unit, 236, may comprise an integrity control unit that processes status messages regarding actuator status and may issue disassembly commands to cause aircraft system 100 to disassemble. Note, however, that the separate units described here may instead actually be incorporated into a single controller 200.
[0063] The mission profile data may comprise, for example, predetermined or securely remotely updatable information regarding the trajectory that aircraft system 100 is to follow and the political or military status of different geographical regions. For example, maps of safe airspace, contested regions, and hostile airspace may be provided to aircraft system 100 for use by controller 200 as it performs various and potentially covert, sensitive, and / or hostile mission tasks. The mission profile data may also describe whether aircraft system 100 is to either preserve or destroy equipment and / or critical data under various conditions and at various locations. For example, if aircraft system 100 is to be disassembled while over contested or hostile territory, perhaps as the result of probable combat damage, controller 200 may responsively destroy component instrumentation and / or stored data to prevent either from being recovered. Such destruction may comprise deliberately crashing aircraft system 100 without disassembly, triggering one or more self-destruct devices to ensure that working instrumentation cannot be recovered, and / or deleting stored data including cryptographic keys, for example. In contrast, if aircraft system 100 is to be disassembled while in safe airspace on an overt mission, controller 200 may act to preserve all instrumentation and stored data to maximize their recovery.
[0064] FIG. 7 is a diagram of controller 200 for aircraft system 100, according to one aspect. In this example, controller 200 comprises computing components such as a hypervisor 238, a first state machine 240, a second state machine 242, a neural network 244 such as a convolutional neural network or other type of neural network, a data synthesizer 246, a geospatial data storage device 248, and a mission command data storage device 252. Controller 200 may receive input data from remote nodes 230 including from their status sensors, any available separate sensors, and an autopilot (which may output, for example, position, velocity, orientation, altitude, and acceleration data, etc.). Controller 200 may responsively output various commands to remote nodes 230 and other flight controls and instruments, to direct the operation of aircraft system 100.
[0065] Hypervisor 238 may manage the computational and memory resources available within controller 200, in one example, which may vary if aircraft system 100 sustains damage or runs low on power. First state machine 240 may handle flight control decisions, and second state machine 242 may handle disassembly decisions, for example. Neural network 244 may make decisions that best implement the assigned mission under various scenarios in which different problems occur, for example. Data synthesizer 246 may integrate outputs from different components of controller 200 to formulate specific commands to be sent to various remote nodes 230. Controller 200 may further comprise a GUI configurator 254 that allows an operator of aircraft system 100 arrange a GUI 250 (described further) to both send and receive information to / from controller 200.
[0066] In one embodiment, the data provided to controller 200 may comprise training data, generated by an external simulator engine, that mimics real flight data. The training data may also comprise recorded data from actual flights. Controller 200 may carry out logic operationsbased on the training data and its previously programmed mission data within an iterative training loop, such that its logic operations are refined to best handle aircraft system 100 in order to best carry out an assigned mission. For example, sensor mismatches may occur such that conflicting data regarding an aspect of aircraft system 100 operation is presented to controller 200. Controller 200 may be trained to determine how to best handle such mismatches during different scenarios, e.g., to be more likely or less likely to trigger a disassembly depending on mission data, sensor data, and geospatial data. For covert surveillance missions or military missions, particularly in contested or hostile airspace, for example, controller 200 may be trained to behave quite differently than for overt civilian missions in friendly territory. Hundreds of different inputs may be varied slightly during each of numerous simulated missions to evaluate and adjust the actions taken by controller 200. During both training missions and actual flight missions, aircraft system 100 may store its last received input data values and / or the last commands issued by controller 200 to help operators or recovery teams better understand its mission history.
[0067] Controller 200 may be trained to predict aircraft system 100 health problems based on sensor data, and to plan for different mission outcomes that may result, for example. Controller 200 may thus be reliably granted more mission autonomy as a result of its thorough training. Controller 200 may also serve as a pilot or assistant pilot for manned flights.
[0068] FIG. 8 A is a diagram of the GUI 250 for aircraft system 100, according to one aspect. GUI 250 allows an operator to observe a graphical depiction of information regarding the operation of aircraft system 100, whether during a simulation or an actual flight. For example, GUI 250 may comprise a moving map indicator 256 that shows the past and current geographic location of aircraft system 100. Moving map indicator 256 may also display regions of airspacethat are safe, contested, or definitely hostile, such as via different colors or other indicia for example, since the status of the airspace may influence the way a human pilot may operate aircraft system 100. Hostile regions may be denoted as red, safe areas may be denoted as green, and contested areas may be denoted as yellow, for example. The geometric shapes of various regions to be treated as safe, contested, or hostile may be provided to controller 200 at the beginning of a mission or may be securely and remotely updated during a mission, perhaps as battlefield conditions change, for example. Airspace status may also be a major factor in determining controller 200 behavior for military or covert surveillance missions, for example, as mission risks and consequences of mission failure may be more severe in hostile territory.
[0069] GUI 250 may also comprise a summary depiction 258 of the status of the remote nodes 230 within aircraft system 100. As with moving map indicator 256, colors or other indicia for example may provide an operator with an immediate understanding of remote node 230 relevant locations and status. For example, whether remote nodes 230 are operating normally or instead have sensor data indicating potential problems may affect whether aircraft system 100 will be able to carry out its mission. A more detailed depiction 260 of flight data and sensor data from various remote nodes 230 may also be provided to the operator. Readouts may comprise navigational data types (e.g., airspeed, heading, location, etc.) and locations of the various remote nodes 230 (e.g., fuselage, left wing, right wing, etc.), for example.
[0070] FIG. 8B depicts a portion of GUI detailed depiction 260 in more detail. Particular readings from sensors and / or status indicia for each remote node 230 and data type may be visually displayed to an operator, again with colors or other indicia providing the operator with an immediate and intuitive understanding of the various aspects of aircraft system 100 health. Definite indications of error due to operational failure or instrument damage may be denoted inred, while warnings of somewhat anomalous or inconsistent readings may be denoted in yellow, while normal operations may be denoted in green, for example. An operator of aircraft system 100 may touch or click on an element of GUI 250 to see more detail, e.g., a log of actual sensor readings versus time for a particular measured quantity, etc. The operator may also issue commands to controller 200 via GUI 250, to guide the actions of controller 200 rather than to directly control operations of aircraft system 100.
[0071] FIG. 9 illustrates logic operations 300 performed by controller 200 for aircraft system 100 when operated by a human, according to an aspect. In the case where a human operator is directing aircraft system 100, the human operator may trigger the disassembly of aircraft system 100 into its separate components. This decision could be part of the predetermined plan regarding the operation of aircraft system 100. For example, the human operator may wish to deliver the aircraft and its cargo to a location where a regular landing is infeasible. The operator may elect to cause a self-destruct of selected components and / or data of aircraft system 100, based on the mission profde data and flight situation, e g., to prevent recovery by an adversary.
[0072] In most cases, however, it is likely the human operator would trigger the dispersal of aircraft system 100 into its separate components only as a result of a major malfunction that is likely to lead to a crash of aircraft system 100. For example, if there is a failure of the communication system, the navigation system, or the propulsion system, or various combinations thereof, the operator may decide that the flight cannot be safely continued. If a safe landing is deemed unlikely, the operator may elect to disassemble aircraft system 100 so the flight may be controllably and safely terminated.
[0073] At 302, aircraft system 100 is in communication with a human operator, as normal. At 304, aircraft system 100 is responding properly to guidance from a human operator.Controller 200 can determine, based on known flight characteristics of aircraft system 100, what responses can be expected from aircraft system 100 to various inputs from the operator. Such responses could include changes in course, altitude, and speed, for example.
[0074] At 306, controller 200 evaluates sensor data regarding the operation of aircraft system 100 and decides whether a major malfunction or error condition exists that will lead to a loss of control and, eventually, a crash of aircraft system 100. For example, a failure of the propulsion system could impede a normal continuation of the flight. Similarly, a failure of the navigation system or flight controls could lead to aircraft system 100 colliding with a terrain feature or a structure, or flight into restricted airspace. A failure of the communication system could also lead to difficulties, but controller 200 may be able to safely proceed with its mission if the mission does not legally or practically require in-flight communications. The precise definition of what constitutes a major malfunction may depend on the details of provided mission profile data.
[0075] At 308, if a major malfunction has occurred, controller 200 responsively alerts the human operator of the problem and advises the operator to attempt to navigate the aircraft system 100 to the safest feasible location where the operator may trigger a disassembly. The human operator may follow this advice or may choose to disregard this advice. The human operator may, for example, order controller 200 to initiate diagnostic measures to learn more about the malfunction. If the propulsion system has failed, the human operator may try to glide aircraft system 100 to a landing, or may order dispersal and / or self-destruct, as previously described. If the navigation system has failed, the human operator may manually navigate aircraft system 100 to a landing or to a dispersal location. If the communication system has failed, controller 200 may programmatically alter course to fly closer to the human operator so that communicationmay be resumed.
[0076] At 310, if no major error occurs, controller 200 may maintain the current flight of aircraft system 100. However, controller 200 may continue to monitor and report minor errors to the human operator. Many crashes are the result of an accumulation of difficulties that are left unaddressed by the pilot, so controller 200 may escalate warnings of minor errors that persist and / or worsen.
[0077] At 312, controller 200 programmatically decides if it has received instructions from the operator to halt is normal operations, or if it has detected an internal error in its own operations. The operator may, for example, upload a new set of instructions to the controller 200 to alter the mission of aircraft system 100 during its flight. Controller 200 may be programmed to abort the mission and return to base in the event it determines that it, controller 200, versus aircraft system 100, is malfunctioning. Otherwise, controller 200 returns to its prior operations of maintaining communications with the operator and determining if aircraft system 100 is responding properly to commands.
[0078] FIG. 10 illustrates logic operations 400 performed by controller 200 for aircraft system 100 when operated by controller 200, according to an aspect. Controller 200 generally implements a repeating control loop that typically does not end unless expressly halted by a user or unless a controller error condition arises. However, a user might halt controller 200 operations to conduct repairs or equipment upgrades, for example.
[0079] In the case where no human operator is directing aircraft system 100, controller 200 may trigger the disassembly of aircraft system 100 into its separate components. As described before, this programmatic decision could be part of the predetermined plan regarding the operation of aircraft system 100. For example, controller 200 may be programmed to deliver theaircraft and its cargo to a location where a regular landing is infeasible. Self-destruct of selected components and / or data may also be an activated option.
[0080] In most cases, however, it is likely controller 200 would trigger the dispersal of aircraft system 100 into its separate components only as a result of a major malfunction that is likely to lead to a crash of aircraft system 100. For example, if there is a failure of the communication system, the navigation system, or the propulsion system, or various combinations thereof, controller 200 may programmatically decide that the flight cannot be safely continued. If a safe landing is deemed unlikely controller 200 may programmatically decide to disassemble aircraft system 100 so the flight may be controllably and safely terminated.
[0081] Such major failures would normally lead to an uncontrolled crash, but in this case controller 200 may detect a major malfunction and do what it can to alter the trajectory (including altitude, speed, and direction) of aircraft system 100 toward the safest feasible location for a landing or controlled disassembly. Such areas might include rural regions, open fields, golf courses, or vacant lots, for example. Controller 200 may use a variety of sensors and mapping tools to rapidly determine which areas on the ground are unoccupied by people, vehicles, buildings, or other obstacles that could be damaged by or cause damage to descending components. Controller 200 may include an artificial intelligence or machine learning algorithm that is, in a sense, always looking for a place to land aircraft system 100 or disperse its components for a minimally damaging descent, or to self-destruct selected components and / or data.
[0082] Controller 200 may thus be entrusted with more autonomy (to the extent allowed by law) over the flight operations of aircraft system 100 than would be the case with a conventional unmanned aircraft, because aircraft system 100 implements the in-flight disassembly technologydescribed in this disclosure. For example, if a conventional unmanned aerial vehicle experiences an engine failure over a populated or urban area, it creates a serious safety hazard. An unmanned aerial vehicle as described in this disclosure can experience an engine failure over a populated or urban area without creating a serious safety hazard, because it can controllably break apart into several lighter-weight, less dangerous components, which may each safely descend to the ground. This “breakable by design” feature may decrease risks to people and property. Such an inherently safe platform may at some point receive an FAA Supplemental Type Certificate (STC), allowing relatively uninhibited travel throughout the National Airspace System.
[0083] At 402, controller 200 may operate aircraft system 100 and communicate with a human operator, as normal. At 404, aircraft system 100 is responding properly to guidance from controller 200. Controller 200 can determine, based on known flight characteristics of aircraft system 100, what responses can be expected from aircraft system 100 to various inputs from controller 200. Such responses could include changes in position, course, altitude, and speed, for example.
[0084] At 406, controller 200 evaluates sensor data regarding the operation of aircraft system 100 and decides whether a major malfunction or error condition exists that will lead to a loss of control and, eventually, a crash of aircraft system 100. For example, a failure of the propulsion system could impede a normal continuation of the flight. Similarly, a failure of the navigation system or flight controls could lead to aircraft system 100 colliding with a terrain feature or a structure, or flight into restricted airspace. A failure of the communication system could also lead to difficulties, but controller 200 may be able to safely proceed with its mission if the mission does not legally or practically require in-flight communications.
[0085] At 408, in response to determining that a major malfunction has occurred, controller200 responsively alerts the human operator of the problem and attempts to navigate the aircraft system 100 to the safest feasible location where controller 200 may trigger a disassembly. The human operator may decide to override this decision and assume manual control. The human operator may then, for example, order controller 200 to initiate diagnostic measures to learn more about the malfunction.
[0086] If the propulsion system has failed, controller 200 may try to glide aircraft system 100 to a landing as a human operator would. If the navigation system has failed, controller 200 may navigate aircraft system 100 to a landing or to a dispersal location. If the communication system has failed, controller 200 may programmatically alter course to fly closer to the human operator so that communication may be resumed, so that the human operator may resume manual control if desired.
[0087] At 410, in response to determining that no major error has occurred, the controller 200 may maintain the current flight of aircraft system 100. However, controller 200 may continue to monitor and report minor errors to the human operator. Many crashes are the result of an accumulation of difficulties that are left unaddressed by the pilot, so controller 200 may escalate warnings of minor errors that persist and / or worsen.
[0088] At 412, controller 200 determines if a halt request has been received or if an internal error condition has occurred in its own operations. If either is true, then the controller 200 may halt its usually-ongoing operation of aircraft system 100, such as to allow a human operator to take command. If neither is true, then the controller 200 may resume its ongoing operation of aircraft system 100.
[0089] As used herein, the term component might describe a given unit of functionality that may be performed in accordance with one or more aspects of the technology disclosed herein.As used herein, a component might be implemented utilizing any form of hardware, software, or a combination thereof. For example, one or more processors, controllers, ASICs, programmable logic arrays (PLAs), programmable array logics (PALs), complex programmable logic devices (CPLDs), FPGAs, logical components, software routines or other mechanisms might be implemented to make up a component. Hardware logic, including programmable logic for use with a programmable logic device (PLD) implementing all or part of the functionality previously described herein, may be designed using traditional manual methods or may be designed, captured, simulated, or documented electronically using various tools, such as Computer Aided Design (CAD) programs, a hardware description language (e.g., VHDL or AHDL), or a PLD programming language. Hardware logic may also be generated by a non-transitory computer- readable medium storing instructions that, when executed by a processor, manage parameters of a semiconductor component, a cell, a library of components, or a library of cells in electronic design automation (EDA) software to generate a manufacturable design for an integrated circuit. In implementation, the various components described herein might be implemented as discrete components or the functions and features described may be shared in part or in total among one or more components. In other words, as would be apparent to one of ordinary skill in the art after reading this description, the various features and functionality described herein may be implemented in any given application and may be implemented in one or more separate or shared components in various combinations and permutations. Even though various features or elements of functionality may be individually described or claimed as separate components, one of ordinary skill in the art will understand that these features and functionality may be shared among one or more common software and hardware elements, and such description shall not require or imply that separate hardware or software components are used to implement suchfeatures or functionality.
[0090] Although the present disclosure and its advantages have been described in detail, it should be understood that various changes, substitutions and alterations may be made herein without departing from the scope of the disclosure as defined by the appended claims. Moreover, the scope of the present application is not intended to be limited to the particular aspects of the process, machine, manufacture, composition of matter, means, methods, and steps described in the specification. As one of ordinary skill in the art will readily appreciate from the disclosure, processes, machines, manufacture, compositions of matter, means, methods, or steps, presently existing or later to be developed that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein may be utilized according to the present disclosure. Accordingly, the appended claims are intended to include within their scope such processes, machines, manufacture, compositions of matter, means, methods, or steps.
[0091] While various aspects of the disclosed technology have been described above, it should be understood that they have been presented by way of example only, and not of limitation. Likewise, the various diagrams may depict an example architectural or other configuration for the disclosed technology, which is done to aid in understanding the features and functionality that may be included in the disclosed technology. The disclosed technology is not restricted to the illustrated example architectures or configurations, but the desired features may be implemented using a variety of alternative architectures and configurations. Indeed, with the aid of this disclosure it will be apparent to one of skill in the art how alternative functional, logical or physical partitioning and configurations may be implemented to implement the desired features of the technology disclosed herein. Also, a multitude of different constituent componentnames other than those depicted herein may be applied to the various partitions. Additionally, with regard to flow diagrams, operational descriptions and method claims, the order in which the steps are presented herein shall not mandate that various aspects be implemented to perform the recited functionality in the same order unless the context dictates otherwise.
[0092] Although the disclosed technology is described above in terms of various exemplary aspects and implementations, it should be understood that the various features, aspects and functionality described in one or more of the individual aspects are not limited in their applicability to the particular aspect with which they are described, but instead may be applied, alone or in various combinations, to one or more of the other aspects of the disclosed technology, whether or not such aspects are described and whether or not such features are presented as being a part of a described aspect. Thus, the breadth and scope of the technology disclosed herein should not be limited by any of the above-described exemplary aspects.
[0093] Terms and phrases used in this document, and variations thereof, unless otherwise expressly stated, should be construed as open ended as opposed to limiting. As examples of the foregoing: the term “including” should be read as meaning “including, without limitation” or the like; the term “example” is used to provide exemplary instances of the item in discussion, not an exhaustive or limiting list thereof; the terms “a” or “an” should be read as meaning “at least one,” “one or more” or the like; and adjectives such as “conventional,” “traditional,” “normal,” “standard,” “known” and terms of similar meaning should not be construed as limiting the item described to a given time period or to an item available as of a given time, but instead should be read to encompass conventional, traditional, normal, or standard technologies that may be available or known now or at any time in the future. Likewise, where this document refers to technologies that would be apparent or known to one of ordinary skill in the art, suchtechnologies encompass those apparent or known to the skilled artisan now or at any time in the future.
[0094] The presence of broadening words and phrases such as “one or more,” “at least,” “but not limited to,” or other like phrases in some instances shall not be read to mean that the narrower case is intended or required in instances where such broadening phrases may be absent. The use of the term “component” does not imply that the components or functionality described or claimed as part of the component are all configured in a common package. Indeed, any or all of the various components of a component, whether control logic or other components, may be combined in a single package or separately maintained and may further be distributed in multiple groupings or packages or across multiple locations.
[0095] Additionally, the various aspects set forth herein are described in terms of exemplary block diagrams, flow charts and other illustrations. As will become apparent to one of ordinary skill in the art after reading this document, the illustrated aspects and their various alternatives may be implemented without confinement to the illustrated examples. For example, block diagrams and their accompanying description should not be construed as mandating a particular architecture or configuration.
[0096] The Abstract of the Disclosure is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description, it may be seen that various features are grouped together in a single aspect for the purpose of streamlining the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed aspects require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter lies in less than all features of a single disclosed aspect. Thus the following claims are hereby incorporated intothe Detailed Description, with each claim standing on its own as a separate aspect.
[0097] Further descriptive detail:
[0098] Clause 1. A method for safely terminating a flight of an aircraft to mitigate air to ground damage risk, comprising: controllably disassembling the aircraft into separate components during the flight; and slowing component descent trajectories with individual parachutes.
[0099] Clause 2. The method of clause 1, wherein one of a human operator and an electronic controller triggers the disassembling.
[0100] Clause 3. The method of clause 1, further comprising controllably destroying at least one of an instrument and stored data with at least one self-destruct device.
[0101] Clause 4. The method of clause 1, wherein the aircraft is an unmanned aerial vehicle.
[0102] Clause 5. The method of clause 1, wherein the aircraft is manned.
[0103] Clause 6. The method of clause 1, wherein the disassembling further comprises activating component release actuators that separate a plurality of the components from each other.
[0104] Clause 7. The method of clause 1, further comprising resetting component release actuators to reconnect a plurality of the components to each other.
[0105] Clause 8. The method of clause 1, wherein the components comprise at least one of a wing assembly, a fuselage, a cargo carrier, and a tail assembly.
[0106] Clause 9. The method of clause 1, wherein at least one of the components guides its descent trajectory.
[0107] Clause 10. The method of clause 1, wherein an electronic controller modifies the flight of the aircraft prior to the disassembling.
[0108] Clause 11 . A non-transitory computer-readable storage medium having embedded therein a set of instructions which, when executed by one or more processors of a computer, causes the computer to execute operations for safely terminating a flight of an aircraft to mitigate air to ground damage risk, the operations comprising: controllably disassembling the aircraft into separate components during the flight; and slowing component descent trajectories with individual parachutes.
[0109] Clause 12. The medium of clause 11, wherein one of a human operator and an electronic controller triggers the disassembling.
[0110] Clause 13. The medium of clause 11, wherein the operations further comprise controllably destroying at least one of an instrument and stored data with at least one self- destruct device.
[0111] Clause 14. The medium of clause 11, wherein the aircraft is an unmanned aerial vehicle.
[0112] Clause 15. The medium of clause 11, wherein the aircraft is manned.
[0113] Clause 16. The medium of clause 11, wherein the disassembling further comprises activating component release actuators that separate a plurality of the components from each other.
[0114] Clause 17. The medium of clause 11, further comprising resetting component release actuators to reconnect a plurality of the components to each other.
[0115] Clause 18. The medium of clause 11, wherein the components comprise at least one of a wing assembly, a fuselage, a cargo carrier, and a tail assembly.
[0116] Clause 19. The medium of clause 11, wherein an electronic controller modifies the flight of the aircraft prior to the disassembling.
[0117] Clause 20. A system for safely terminating a flight of an aircraft to mitigate air to ground damage risk, comprising: controllably disassembling the aircraft into separate components during the flight, using component release actuators; and slowing component descent trajectories using individual parachutes.
[0118] Clause 21. An apparatus for safely terminating a flight of an aircraft to mitigate air to ground damage risk, comprising: a plurality of individual components connected with component release actuators that, when activated, are configured to detach at least some of the components from each other to disassemble the aircraft during the flight; at least one parachute for each component configured to deploy upon the disassembly; and at least one trigger mechanism that is configured to controllably activate the component release actuators and the parachutes.
[0119] Clause 22. The apparatus of clause 21, wherein one of a human operator and an electronic controller activates the trigger mechanism.
[0120] Clause 23. The apparatus of clause 21, further comprising at least one self-destruct device configured to controllably destroy at least one of an instrument and stored data.
[0121] Clause 24. The apparatus of clause 21, wherein the aircraft is an unmanned aerial vehicle.
[0122] Clause 25. The apparatus of clause 21, wherein the components are configured to emit an audible warning during descent.
[0123] Clause 26. The apparatus of clause 21, wherein the components each weigh less than a maximum specified weight that depends on whether the component is padded.
[0124] Clause 27. The apparatus of clause 21, further comprising component release actuators that are configured to reset to reconnect a plurality of the components to each other.
[0125] Clause 28. The apparatus of clause 21 , wherein the components comprise at least one of a wing assembly, a fuselage, a cargo carrier, and a tail assembly.
[0126] Clause 29. The apparatus of clause 21, wherein at least one of the components is configured to guide its descent trajectory following the disassembly.
[0127] Clause 30. The apparatus of clause 21, wherein an electronic controller is configured to modify the flight of the aircraft prior to the disassembly.
Claims
CLAIMSWhat is claimed is:
1. A method for safely terminating a flight of an aircraft to mitigate air to ground damage risk, comprising: controllably disassembling the aircraft into separate components during the flight; and slowing component descent trajectories with individual parachutes.
2. The method of claim 1, wherein one of a human operator and an electronic controller triggers the disassembling.
3. The method of claim 1, further comprising controllably destroying at least one of an instrument and stored data with at least one self-destruct device.
4. The method of claim 1, wherein the aircraft is an unmanned aerial vehicle.
5. The method of claim 1, wherein the aircraft is manned.
6. The method of claim 1, wherein the disassembling further comprises activating component release actuators that separate a plurality of the components from each other.
7. The method of claim 1, further comprising resetting component release actuators to reconnect a plurality of the components to each other.
8. The method of claim 1, wherein the components comprise at least one of a wing assembly, a fuselage, a cargo carrier, and a tail assembly.
9. The method of claim 1, wherein at least one of the components guides its descent trajectory.
10. The method of claim 1, wherein an electronic controller modifies the flight of the aircraft prior to the disassembling.
11. A non-transitory computer-readable storage medium having embedded therein a set of instructions which, when executed by one or more processors of a computer, causes thecomputer to execute operations for safely terminating a flight of an aircraft to mitigate air to ground damage risk, the operations comprising: controllably disassembling the aircraft into separate components during the flight; and slowing component descent trajectories with individual parachutes.
12. The medium of claim 11, wherein one of a human operator and an electronic controller triggers the disassembling.
13. The medium of claim 11, wherein the operations further comprise controllably destroying at least one of an instrument and stored data with at least one self-destruct device.
14. The medium of claim 11, wherein the aircraft is an unmanned aerial vehicle.
15. The medium of claim 11, wherein the aircraft is manned.
16. The medium of claim 11, wherein the disassembling further comprises activating component release actuators that separate a plurality of the components from each other.
17. The medium of claim 11, further comprising resetting component release actuators to reconnect a plurality of the components to each other.
18. The medium of claim 11, wherein the components comprise at least one of a wing assembly, a fuselage, a cargo carrier, and a tail assembly.
19. The medium of claim 11, wherein an electronic controller modifies the flight of the aircraft prior to the disassembling.
20. A system for safely terminating a flight of an aircraft to mitigate air to ground damage risk, comprising: controllably disassembling the aircraft into separate components during the flight, using component release actuators; and slowing component descent trajectories using individual parachutes.21 . An apparatus for safely terminating a flight of an aircraft to mitigate air to ground damage risk, comprising: a plurality of individual components connected with component release actuators that, when activated, are configured to detach at least some of the components from each other to disassemble the aircraft during the flight; at least one parachute for each component configured to deploy upon the disassembly; and at least one trigger mechanism that is configured to controllably activate the component release actuators and the parachutes.
22. The apparatus of claim 21, wherein one of a human operator and an electronic controller activates the trigger mechanism.
23. The apparatus of claim 21, further comprising at least one self-destruct device configured to controllably destroy at least one of an instrument and stored data.
24. The apparatus of claim 21, wherein the aircraft is an unmanned aerial vehicle.
25. The apparatus of claim 21, wherein the components are configured to emit an audible warning during descent.
26. The apparatus of claim 21, wherein the components each weigh less than a maximum specified weight that depends on whether the component is padded.
27. The apparatus of claim 21, further comprising component release actuators that are configured to reset to reconnect a plurality of the components to each other.
28. The apparatus of claim 21, wherein the components comprise at least one of a wing assembly, a fuselage, a cargo carrier, and a tail assembly.
29. The apparatus of claim 21, wherein at least one of the components is configured to guide its descent trajectory following the disassembly.
30. The apparatus of claim 21, wherein an electronic controller is configured to modify the flight of the aircraft prior to the disassembly.
Citation Information
Patent Citations
air cushion
JP3932210B2
Movable control surface ejection system
US20170240281A1
Secure system for emergency-mode operation, system monitoring and trusted access vehicle location and recovery
US20180279105A1
Aircraft ejection system
US3520500A
Jettisonable aerodynamic control surfaces
US5150858A