Autonomous Aircraft Control Switching for Safe Flight Envelopes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for controlling autonomous aircraft lack guaranteed safety mechanisms, relying on human supervision or unproven artificial intelligence, which poses risks to human life in case of accidents or system failures.
Innovation Solution
A fully autonomous control system for robot aircraft utilizing a simplex architecture with a high-performance controller (HPC) and a high-safety controller (HAC) to maintain the aircraft within a safe state envelope, switching between modes to ensure safety and execute emergency procedures as needed, leveraging sensors like lidar, radar, and GPS for real-time decision-making.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If human supervision is used to control autonomous aircraft, then safety can be monitored, but the system cannot operate fully autonomously and requires human intervention
Solution Approach 1:
The control system is segmented into three independent modules: HPC for high-performance control, HAC for high-safety monitoring, and DM for decision-making. Each module operates autonomously with specific responsibilities, allowing the system to achieve full automation while maintaining safety through modular independence and specialized functions.
Solution Approach 2:
The decision module (DM) acts as an intermediary between HPC and HAC, receiving commands from both controllers and autonomously selecting which command to execute. This mediator resolves conflicts between performance-oriented and safety-oriented commands without requiring human intervention, enabling full autonomy while guaranteeing safety through structured arbitration.
2Extent of automation
If artificial intelligence and machine learning are used for control, then autonomous operation is achieved, but safety mechanisms are not currently guaranteed or recognized
Solution Approach 1:
The system employs a backup controller (HAC) that can take over immediately when the primary controller (HPC) fails or produces unsafe commands. This redundant, fail-safe approach provides guaranteed safety mechanisms that can be certified, while the primary AI-based HPC maintains autonomous operation capabilities.
Solution Approach 2:
The system changes the operational parameters of different controllers based on their strengths: HPC operates with high autonomy and AI-based decision-making, while HAC operates with conservative, safety-certified parameters. The DM dynamically switches between these parameter sets based on situational assessment, achieving both autonomy and safety certification.
3Reliability
If a simplex control structure is used, then safety monitoring is improved, but the system complexity increases with multiple controllers and decision modules
Solution Approach 1:
The control system dynamically adapts its structure through the DM, which continuously assesses flight conditions and adjusts which controller (HPC or HAC) has authority. This dynamic arbitration simplifies the operational complexity by providing clear, situation-dependent control pathways while maintaining the safety benefits of multiple controllers.
Solution Approach 2:
Instead of having a single complex controller that tries to do everything, the system inverts the approach by having simple, specialized controllers (HPC for performance, HAC for safety) and a simple arbitration rule set in the DM. This inversion reduces overall system complexity while achieving superior safety monitoring through the simplex structure.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for controlling a robot-aircraft piloted by a fully autonomous control system (20) comprising a first decision module (51) and a simplex piloting control module (2) comprising a high-performance controller (21), a high-safety controller (31) and a second decision module (41), the high-performance (21) and high-safety (31) controllers determining piloting commands for the robot-aircraft (1), wherein: - as long as a set of conditions is verified, implementation by the first decision module (51) of a nominal piloting mode with supply at the output of the automatic control system (20) of the piloting commands delivered at the output of the simplex piloting control module (2); - otherwise, switching to an emergency piloting mode, an emergency piloting command is supplied at the output of the automatic control system (20) for execution by the robot-aircraft, the first decision module (51) preventing the supply at the output of the automatic control system (20) of the piloting commands supplied at the output of the simplex module (2).