Centralized Vehicle Appliance Interface with Segmented Data Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing apparatuses for controlling appliances aboard vehicles, such as aircraft, face complexity and cost issues due to the need for separate data processing devices and graphics processors, leading to inflexible and cumbersome graphical user interfaces that complicate operation and fail to meet safety requirements effectively.

Innovation Solution

A centralized graphical user interface managed by a first data processing device with a network interface and a user interface module, allowing bidirectional data transmission with separate second data processing devices, which simplifies the graphical user interface and ensures safety by restricting data transmission to predefined records and types, eliminating the need for separate graphics processors in these devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate data processing devices and graphics processors are provided for each appliance domain, then safety requirements are met through hardware separation, but device complexity and cost increase

Engineering Contradiction:
ImprovesafetyVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments data processing functions by creating a master data processing device that handles safety-critical appliance domains and slave data processing devices that handle non-safety-critical domains. This segmentation maintains safety through functional separation while reducing overall device complexity by consolidating graphics processing resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The master data processing device serves multiple functions: it processes data from safety-critical appliances, controls the graphical user interface, and manages communication with non-safety-critical slave devices. This multi-functionality eliminates the need for separate dedicated graphics processors in each slave device, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate data processing devices are used for different safety levels, then safety isolation is ensured, but the graphical user interface becomes inflexible and cumbersome

Engineering Contradiction:
Improvesafety isolationVSAvoidgraphical user interface flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The master data processing device acts as an intermediary between safety-critical and non-safety-critical domains. It receives graphical user interface control inputs, processes them appropriately based on safety requirements, and forwards commands to the relevant slave devices. This intermediary approach maintains safety isolation while enabling flexible and unified graphical user interface operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system merges the graphical user interface control functions into a single master data processing device that serves all appliance domains. This consolidation allows for a unified, flexible graphical user interface while maintaining safety isolation through the master device's intelligent routing and control of commands to different slave devices.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If bidirectional data transmission is allowed between all data processing devices, then operational flexibility increases, but safety risks arise from unauthorized access

Engineering Contradiction:
Improveoperational flexibilityVSAvoidsafety
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system applies different communication permissions to different data processing devices based on their safety classification. The master data processing device has bidirectional communication capabilities with safety-critical domains, while non-safety-critical slave devices have unidirectional-only communication. This local quality approach allows operational flexibility where needed while maintaining safety through restricted communication paths.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system preemptively prevents unauthorized access by designing the communication architecture so that slave devices can only transmit data unidirectionally to the master device. This preliminary anti-action blocks potential security gaps before they can be exploited, while still allowing operational flexibility through the master device's ability to process and act on data from all sources.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP2775402B1Apparatus for controlling a plurality of appliances aboard a vehicle
Publication Date: 2019.11.27 AIRBUS OPERATIONS GMBH
  • EP2775402B1 patent drawingFigure 1
  • EP2775402B1 patent drawingFigure 2

AI summary

The present invention relates to an apparatus for controlling a plurality of appliances (5a, 5b, 5c) aboard a vehicle. It has a first data processing device (2a) having a network interface (3a) that can have a vehicle network (4a) for bidirectional data transmission between the first data processing device (2a) and network appliances (5a) connected to it. It also has an input/output device (6), a graphics processor device (7) that is connected to the screen thereof and to the first data processing device (2a), a user interface module (9) that is provided in the first data processing device (2a) and that implements a graphical user interface (10) having a plurality of pages (10a, 10b, 10c), and at least one separate second data processing device (2b, 2c) that is connected to the first data processing device (2a) via a separate bidirectional data link (12b, 12c) and has a network interface (3b, 3c) for connection to a vehicle network (4b, 4c). The pages have at least one page on which data are presented that have been transmitted from a second data processing device (2b, 2c) via the corresponding bidirectional data link (12b, 12c), and/or data can be input that are subsequently transmitted from the first data processing device (2a) via the corresponding bidirectional data link (12b, 12c). Via each bidirectional data link (12b, 12c) it is exclusively possible to transmit predefined data records (15, 16, 17) having data of predefined data types for display on pages (10b, 10c) from the respective second data processing device (2b, 2c) to the first data processing device (2a).