Interlocking Redundancy System for Aircraft Control Timing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems with multiple processors, such as those in aircraft control systems, experience delays or interruptions in control operations when a processor malfunctions, leading to safety concerns and potential system uncontrol.

Innovation Solution

An independent and interlocking redundancy system with two operation processors and a standby processor, where the processors transmit control commands independently and alternately, ensuring continuous control without delays even if one processor fails, by having the standby processor take over and synchronize with the remaining operational processors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a redundancy processor is introduced to take over logical setting of malfunctioning processors, then system reliability is improved, but control timing may be delayed due to the switchover process

Engineering Contradiction:
Improvesystem reliabilityVSAvoidcontrol timing
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The standby processor is pre-configured with the same program as the operation processors and maintains readiness to execute. When a malfunction is detected, the standby processor can immediately take over without requiring time-consuming reconfiguration or loading of programs, thus preventing control timing delays while ensuring system reliability

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple processors operate independently with turn-based control, then continuous control without interruptions is achieved, but system complexity increases

Engineering Contradiction:
Improvecontinuous controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control function is segmented across multiple processors (operation processors and standby processor), with each processor capable of independently executing the control program. This segmentation allows continuous control operation even when one processor malfunctions, while the modular architecture manages complexity through standardized processor designs

Inventive Principle:
Principle #1Segmentation

3Reliability

If the standby processor immediately takes over upon malfunction detection, then control continuity is maintained, but control timing may be delayed during the transition

Engineering Contradiction:
Improvecontrol continuityVSAvoidcontrol timing
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The standby processor is pre-configured with the same program as the operation processors and maintains readiness to execute. When a malfunction is detected, the standby processor can immediately take over without requiring time-consuming reconfiguration or loading of programs, thus preventing control timing delays while ensuring system reliability

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3663923B1Independent and interlocking redundancy system
Publication Date: 2023.07.05 SUBARU CORP
  • EP3663923B1 patent drawingFigure 1~2
  • EP3663923B1 patent drawingFigure 3

AI summary

An independent and interlocking redundancy system (1) includes one or more control targets (2), operation processors (3α, 3β), and one or more standby processors (3y). The one or more standby processors (3y) is configured to make transition from a standby state to a warming-up state when one of the operation processors (3α, 3β) malfunctions, transmit, in the warming-up state and to the one or more control targets (2), a control command same as that transmitted to the one or more control targets (2) by non-malfunctioning one of the operation processors (3α, 3β), at a timing at which the malfunctioning one of the operation processors (3α, 3β) is supposed to transmit the control command, and determine and transmit the control command independently from and by taking turns with respect to the non-malfunctioning one or more of the operation processors (3α, 3β), after warm-up of the one or more standby processors (3y) is completed.