Fly-By-Wire Control System Redundancy Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Fly-by-wire (FBW) avionics systems face challenges in mitigating generic fault effects due to the complexity of components and communications paths, making it difficult to implement dissimilar redundancy effectively, which is critical for ensuring system integrity and availability, especially in highly critical functionalities like aircraft control systems.
Innovation Solution
The implementation of a control system with a common processing partition and two distinct processing partitions (normal mode and direct mode) that operate in conjunction with a simple common partition to produce control signals, allowing for architectural mitigation of failures by detecting corruption and switching to a backup mode when necessary, using encoded data packets and error detection encoding.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dissimilar redundancy is implemented in FBW systems, then system integrity and verification rigor are improved, but device complexity and difficulty of implementation increase
Solution Approach 1:
The system is divided into separate processing partitions (normal mode partition and direct mode partition) that are functionally independent but architecturally similar. This segmentation allows redundancy to be implemented at the partition level rather than requiring complex dissimilar components throughout the entire system, thereby maintaining reliability while reducing overall device complexity.
Solution Approach 2:
The common processing partition serves multiple functions by supporting both normal mode and direct mode operations. This universal design allows the same hardware infrastructure to provide redundant functionality through software/configuration changes rather than requiring separate dedicated hardware for each mode, reducing complexity while maintaining reliability.
2Reliability
If redundant computing lanes are added to FBW systems, then fault detection capability is improved, but device complexity increases
Solution Approach 1:
The system creates a redundant copy of the processing partition with identical architecture and functionality. This copy (direct mode partition) mirrors the normal mode partition, allowing for straightforward comparison and fault detection without the complexity of designing and verifying dissimilar redundant systems. The copying approach simplifies verification while maintaining fault detection capability.
3Adaptability or versatility
If complex components are used in FBW systems, then functionality and performance are improved, but susceptibility to generic faults increases
Solution Approach 1:
By segmenting the complex processing functionality into separate, isolated partitions (normal mode and direct mode), the system limits the propagation of generic faults. If a fault occurs in one partition, the architectural isolation prevents it from affecting the other partition, thereby maintaining reliability despite using complex components.
Solution Approach 2:
The common processing partition acts as an intermediary that manages both normal mode and direct mode operations. This intermediary structure allows complex functionality to be implemented while providing a controlled interface between redundant partitions, enabling fault isolation and mitigation strategies to be applied systematically.
Data Source
AI summary
Methods and systems are provided for redundancy management of a fly-by-wire avionics system. A control module for producing a control signal is provided comprising a common processing partition for receiving a flight input signal and at least one first mode input signal, a first processing partition coupled to the common processing partition and configured to receive the first mode input signals and flight input signal from the common processing partition, and a second processing partition coupled to the common processing partition. The first processing partition produces a first mode output signal in response to one of the first mode input signals and flight input signal. The second processing partition generates a second mode signal in response to the flight input signal when the first processing partition fails. The common processing partition produces the control signal in response to one of the first mode output signal and second mode signal.


