Aircraft Control Command Verification for Virtualized Cockpit Inputs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtualized control architectures for aircraft are unreliable for critical functions due to the risk of command corruption during generation or transmission, which can lead to unintended execution of functions, compromising aircraft safety.

Innovation Solution

A control architecture that includes a main command confirmation module generating a safety command, which is sent to the control module only when both the main and safety commands correspond to the expected configurations, ensuring accurate execution of intended functions by using distinct bytes and a verification unit for authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a virtualized control architecture is used to control aircraft functional elements, then the ease of operation is improved through touch screen interfaces, but the reliability deteriorates due to command corruption risks during generation or transmission

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary verification by generating a safety command from the main command and validating it against expected values before the command is executed. This advance checking prevents corrupted commands from causing harmful actions, thus improving reliability while maintaining the virtualized interface benefits

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The safety command acts as an intermediary verification layer between the main command and the functional element execution. By introducing this intermediate validation step, the system ensures command integrity without eliminating the virtualized interface, resolving the contradiction between ease of operation and reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If command validation and safety checks are added to the control architecture, then the reliability is improved, but the device complexity increases due to additional modules and verification steps

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control architecture is segmented into distinct functional modules: main command generation, safety command generation, verification, and execution. This modular segmentation allows each component to have a specific, simple function while the overall system achieves high reliability through their coordinated interaction

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transforms the command representation by generating a safety command with specific bit distinctions from the main command. This parameter transformation approach enables verification through comparative analysis, improving reliability while maintaining manageable system complexity through systematic parameter manipulation

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20230202671A1Virtualized aircraft control architecture and associated method
Publication Date: 2023.06.29 DASSAULT AVIATION SA
  • US20230202671A1 patent drawing
  • US20230202671A1 patent drawing
  • US20230202671A1 patent drawing

AI summary

A virtualized aircraft control architecture comprises a human-machine interface configured for generating a main command for arranging a functional element into a target configuration among a plurality of configurations; and a control module for controlling the functional element between its configurations. The architecture comprises a confirmation module of the main command configured for generating an associated safety command, an interface module configured for sending the main command and the safety command to the control module; the control module moving the functional element into the target configuration when the main command and the safety command, respectively, correspond to an expected main command and an expected safety command for arranging the at least one functional element in the target configuration.