Run-time Assurance Module Dynamic Contingency Planning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional run-time assurance modules for autonomous aerospace systems struggle to adapt to dynamic contexts, such as mission planning and online flight trajectory planning, due to the requirement of pre-defined safety limits and recovery control response times, which limits their applicability in scenarios involving adverse weather conditions or unknown hazards.

Innovation Solution

A run-time assurance module that includes a contingency planner capable of generating and updating contingency plans based on real-time condition inputs, storing new plans if they meet safety criteria and have a later safety-critical decision point, allowing for dynamic adjustment of safety limits and hazard responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional run-time assurance modules use pre-defined safety limits and recovery control response times, then safety monitoring can be performed, but the system cannot adapt to dynamic contexts such as mission planning or online flight trajectory planning

Engineering Contradiction:
Improveadaptability to dynamic contextsVSAvoidcomplexity of safety monitoring system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic contingency planning where the system continuously generates and updates contingency plans based on current flight conditions and hazards. The contingency planner dynamically adjusts safety-critical decision points and recovery controls in real-time during mission execution, allowing adaptation to evolving weather conditions and unknown hazards while maintaining systematic safety monitoring

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary generation of multiple contingency plans with associated safety-critical decision points before flight execution. These pre-computed contingency plans are stored and selectively activated during flight based on actual conditions, enabling rapid response to dynamic situations without requiring complex real-time optimization calculations

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional offline verification methods are used for autonomous systems, then verification can be performed, but confidence in safety-critical systems cannot be sufficiently increased

Engineering Contradiction:
Improveconfidence in safety-critical systemsVSAvoidcomplexity of verification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements runtime verification where the safety monitor continuously checks actual flight parameters against the contingency plans and safety-critical decision points. This feedback mechanism provides ongoing confidence in system safety during operation, complementing traditional offline verification methods and enabling certification of complex autonomous functions

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The contingency plans are generated and verified offline before flight execution, with safety-critical decision points predetermined. This preliminary verification approach allows thorough analysis of safety logic before deployment, building confidence in the system while avoiding the need for complex real-time verification during flight

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If pre-defined recovery control response times are used, then safety monitoring can be implemented, but the system cannot handle unknown hazards or dynamically evolving weather conditions

Engineering Contradiction:
Improveresponse to unknown hazardsVSAvoidtime for hazard assessment and response
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

Multiple contingency plans with different recovery control strategies and associated safety-critical decision points are pre-computed for various potential hazard scenarios. When an unknown hazard or changing weather condition is detected, the system can quickly select and activate the appropriate pre-planned contingency without requiring time-consuming real-time analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically updates contingency plans during flight based on actual conditions. The contingency planner continuously monitors flight parameters and hazard conditions, generating updated contingency plans with adjusted safety-critical decision points that reflect current situational awareness, enabling rapid adaptation to new hazards

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12087171B2Assurance module
Publication Date: 2024.09.10 ROCKWELL COLLINS INC
  • US12087171B2 patent drawing
  • US12087171B2 patent drawing
  • US12087171B2 patent drawing

AI summary

A run-time assurance module (6) comprises a contingency planner (26) arranged to generate an initial contingency plan having an associated safety-critical decision point, where the initial contingency plan (ICP) is stored as a current contingency plan in a memory (30). The assurance module (6) receives a mission plan (MP) from a mission planner (4). When the mission plan (MP) is being carried out, the contingency planner (26) processes at least one condition input, and generates a new contingency plan (NCP) based on the condition input. When the new contingency plan (NCP) satisfies a safety criterion and the safety-critical decision point associated with the new contingency plan (NCP) will occur later in time than the safety-critical decision point associated with the current contingency plan (CCP), the new contingency plan (NCP) is stored in the memory (30) as the current contingency plan (CCP).