Run-time Assurance Module Dynamic Contingency Planning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional run-time assurance modules for autonomous aerospace systems struggle to adapt to dynamic contexts, such as mission planning and online flight trajectory planning, due to the requirement of pre-defined safety limits and recovery control response times, which limits their applicability in scenarios involving adverse weather conditions or unknown hazards.
Innovation Solution
A run-time assurance module that includes a contingency planner capable of generating and updating contingency plans based on real-time condition inputs, storing new plans if they meet safety criteria and have a later safety-critical decision point, allowing for dynamic adjustment of safety limits and hazard responses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional run-time assurance modules use pre-defined safety limits and recovery control response times, then safety monitoring can be performed, but the system cannot adapt to dynamic contexts such as mission planning or online flight trajectory planning
Solution Approach 1:
The patent implements dynamic contingency planning where the system continuously generates and updates contingency plans based on current flight conditions and hazards. The contingency planner dynamically adjusts safety-critical decision points and recovery controls in real-time during mission execution, allowing adaptation to evolving weather conditions and unknown hazards while maintaining systematic safety monitoring
Solution Approach 2:
The system performs preliminary generation of multiple contingency plans with associated safety-critical decision points before flight execution. These pre-computed contingency plans are stored and selectively activated during flight based on actual conditions, enabling rapid response to dynamic situations without requiring complex real-time optimization calculations
2Reliability
If traditional offline verification methods are used for autonomous systems, then verification can be performed, but confidence in safety-critical systems cannot be sufficiently increased
Solution Approach 1:
The system implements runtime verification where the safety monitor continuously checks actual flight parameters against the contingency plans and safety-critical decision points. This feedback mechanism provides ongoing confidence in system safety during operation, complementing traditional offline verification methods and enabling certification of complex autonomous functions
Solution Approach 2:
The contingency plans are generated and verified offline before flight execution, with safety-critical decision points predetermined. This preliminary verification approach allows thorough analysis of safety logic before deployment, building confidence in the system while avoiding the need for complex real-time verification during flight
3Adaptability or versatility
If pre-defined recovery control response times are used, then safety monitoring can be implemented, but the system cannot handle unknown hazards or dynamically evolving weather conditions
Solution Approach 1:
Multiple contingency plans with different recovery control strategies and associated safety-critical decision points are pre-computed for various potential hazard scenarios. When an unknown hazard or changing weather condition is detected, the system can quickly select and activate the appropriate pre-planned contingency without requiring time-consuming real-time analysis
Solution Approach 2:
The system dynamically updates contingency plans during flight based on actual conditions. The contingency planner continuously monitors flight parameters and hazard conditions, generating updated contingency plans with adjusted safety-critical decision points that reflect current situational awareness, enabling rapid adaptation to new hazards
Data Source
AI summary
A run-time assurance module (6) comprises a contingency planner (26) arranged to generate an initial contingency plan having an associated safety-critical decision point, where the initial contingency plan (ICP) is stored as a current contingency plan in a memory (30). The assurance module (6) receives a mission plan (MP) from a mission planner (4). When the mission plan (MP) is being carried out, the contingency planner (26) processes at least one condition input, and generates a new contingency plan (NCP) based on the condition input. When the new contingency plan (NCP) satisfies a safety criterion and the safety-critical decision point associated with the new contingency plan (NCP) will occur later in time than the safety-critical decision point associated with the current contingency plan (CCP), the new contingency plan (NCP) is stored in the memory (30) as the current contingency plan (CCP).


