Aircraft Autopilot Error Recovery Without Full Computer Shutdown
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for managing exceptional errors in aircraft autopilot systems, such as software errors and single event upsets, often result in the complete deactivation of computers, disrupting flight safety and requiring redundant systems, which are not always necessary.
Innovation Solution
A method that identifies and counts exceptional errors over a predetermined period, allowing for the temporary stopping and reinitialization of faulty step sequences, enabling the computer to remain active while preventing anomalous outputs, and implementing gradual software sanctions to maintain safety.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If redundant systems are used to detect and manage errors in autopilot computers, then reliability is improved, but device complexity increases
Solution Approach 1:
The autopilot computer performs self-diagnostics by monitoring its own operational parameters and detecting anomalies in its calculation processes. The system automatically identifies errors in succession of steps, counts error occurrences, and triggers reinitialization without requiring external redundant systems, thereby maintaining reliability while reducing complexity
Solution Approach 2:
The system implements a feedback mechanism where the computer continuously monitors its own operational status, detects errors in real-time, and automatically responds by stopping and reinitializing faulty successions of steps. This closed-loop feedback enables the system to maintain reliability through self-correction rather than through redundant hardware
2Reliability
If the computer is completely deactivated when an error is detected, then reliability is improved, but productivity decreases
Solution Approach 1:
Instead of deactivating the entire computer system, the invention segments the error handling to affect only the specific succession of steps that generated the error. The faulty sequence is stopped and reinitialized while other independent successions continue to operate, maintaining overall autopilot functionality while addressing the specific reliability issue
Solution Approach 2:
The system applies partial deactivation by stopping only the problematic succession of steps rather than the entire computer. This partial action is sufficient to eliminate the error source while preserving the majority of autopilot functions, thus balancing reliability improvement with productivity maintenance
3Reliability
If error monitoring and reinitialization procedures are implemented, then reliability is improved, but loss of time increases
Solution Approach 1:
The system performs preliminary error detection by continuously monitoring operational parameters during normal operation. By detecting errors early in the succession of steps rather than waiting for complete failure, the system can initiate reinitialization sooner, reducing the overall time loss while maintaining reliability
Data Source
AI summary
A management method for managing an autopilot system fitted to an aircraft, the management method being adapted to manage at least one error in at least one succession of steps serving to generate at least one autopilot setpoint for the aircraft, the autopilot system comprising at least one computer serving to implement a plurality of successions of steps generating different autopilot setpoints for the aircraft. Such a method comprises an identification step serving to identify the at least one error, a calculation step for determining a total number of occurrences of the at least one error, a stop step serving to stop the at least one succession of steps, a reinitialization step for reinitializing the at least one succession of steps, and a relaunch step for relaunching the at least one succession of steps.

