Triple-Redundant Flight Controller Shutdown for Second Lane Failures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current triple redundant systems in aircraft control systems face inefficiencies in managing second lane failures, leading to undesired operations where failed lanes can reactivate and take control, compromising system safety.

Innovation Solution

A method and apparatus that monitor activity indicators and cyclic redundancy check values from each lane to detect anomalies and mismatches, enabling the system to disable the controller and prevent second lane failures from causing system instability by using a master controller to manage messages and error checking data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If triple redundancy is implemented in the control system, then system reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control system is divided into three independent computing lanes, each capable of independent operation. This segmentation allows the system to maintain functionality even when one lane fails, as the remaining lanes can continue to execute control functions independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each computing lane is equipped with dedicated monitoring resources and error detection capabilities specific to that lane. The system implements localized fault detection and isolation mechanisms at each lane level, allowing precise identification and management of failures without affecting the entire system's operation.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If majority voting is used for fault detection, then ease of operation is improved, but measurement precision deteriorates for detecting subtle failures

Engineering Contradiction:
Improveease of operationVSAvoidfault detection precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system implements continuous monitoring and comparison of outputs from all three computing lanes with immediate feedback mechanisms. When discrepancies are detected between lane outputs, the system provides real-time feedback to identify and isolate the failed lane, enabling precise fault detection while maintaining operational simplicity through automated decision-making.

Inventive Principle:
Principle #23Feedback

3Productivity

If the system continues operation after first lane failure, then productivity is improved, but reliability deteriorates due to potential second failure

Engineering Contradiction:
Improvesystem availabilityVSAvoidsystem safety
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary monitoring and comparison of lane outputs to detect the first failure before it can cause harmful effects. By identifying and isolating the failed lane proactively, the system prepares for potential second failures by maintaining strict monitoring of the remaining operational lanes, thus preserving both availability and safety.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A dedicated monitoring and comparison mechanism acts as an intermediary between the three computing lanes. This intermediary continuously compares lane outputs, detects discrepancies indicating failures, and coordinates the isolation of failed lanes, thereby managing the transition from triple to dual redundancy while maintaining system safety and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3422125B1Fault coverage for multiple failures in redundant systems
Publication Date: 2021.11.03 THE BOEING CO
  • EP3422125B1 patent drawingFigure 1
  • EP3422125B1 patent drawingFigure 2
  • EP3422125B1 patent drawingFigure 3~4

AI summary

A method and system for managing a control system having triple redundancy for an aircraft. The method comprises receiving a group of messages from a transmitting lane in a controller including three lanes in which a first lane failure has previously occurred. The method identifies an activity indicator, a status generated by each lane in a group of lanes, and a cyclic redundancy check value generated by each lane in the group of lanes in the group of messages. The cyclic redundancy check value generated by a lane in the group of lanes is generated using a key assigned to the lane. The method disables the controller when at least one of an anomaly is indicated in the status, an activity indicator mismatch is present, or a cyclic redundancy check value mismatch is present in the group of messages that indicates a second lane failure has occurred.