Triple-Redundant Flight Controller Shutdown for Second Lane Failures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current triple redundant systems in aircraft control systems face inefficiencies in managing second lane failures, leading to undesired operations where failed lanes can reactivate and take control, compromising system safety.
Innovation Solution
A method and apparatus that monitor activity indicators and cyclic redundancy check values from each lane to detect anomalies and mismatches, enabling the system to disable the controller and prevent second lane failures from causing system instability by using a master controller to manage messages and error checking data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If triple redundancy is implemented in the control system, then system reliability is improved, but device complexity increases
Solution Approach 1:
The control system is divided into three independent computing lanes, each capable of independent operation. This segmentation allows the system to maintain functionality even when one lane fails, as the remaining lanes can continue to execute control functions independently.
Solution Approach 2:
Each computing lane is equipped with dedicated monitoring resources and error detection capabilities specific to that lane. The system implements localized fault detection and isolation mechanisms at each lane level, allowing precise identification and management of failures without affecting the entire system's operation.
2Ease of operation
If majority voting is used for fault detection, then ease of operation is improved, but measurement precision deteriorates for detecting subtle failures
Solution Approach 1:
The system implements continuous monitoring and comparison of outputs from all three computing lanes with immediate feedback mechanisms. When discrepancies are detected between lane outputs, the system provides real-time feedback to identify and isolate the failed lane, enabling precise fault detection while maintaining operational simplicity through automated decision-making.
3Productivity
If the system continues operation after first lane failure, then productivity is improved, but reliability deteriorates due to potential second failure
Solution Approach 1:
The system performs preliminary monitoring and comparison of lane outputs to detect the first failure before it can cause harmful effects. By identifying and isolating the failed lane proactively, the system prepares for potential second failures by maintaining strict monitoring of the remaining operational lanes, thus preserving both availability and safety.
Solution Approach 2:
A dedicated monitoring and comparison mechanism acts as an intermediary between the three computing lanes. This intermediary continuously compares lane outputs, detects discrepancies indicating failures, and coordinates the isolation of failed lanes, thereby managing the transition from triple to dual redundancy while maintaining system safety and reliability.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
A method and system for managing a control system having triple redundancy for an aircraft. The method comprises receiving a group of messages from a transmitting lane in a controller including three lanes in which a first lane failure has previously occurred. The method identifies an activity indicator, a status generated by each lane in a group of lanes, and a cyclic redundancy check value generated by each lane in the group of lanes in the group of messages. The cyclic redundancy check value generated by a lane in the group of lanes is generated using a key assigned to the lane. The method disables the controller when at least one of an anomaly is indicated in the status, an activity indicator mismatch is present, or a cyclic redundancy check value mismatch is present in the group of messages that indicates a second lane failure has occurred.