Browse Topic: Integrated modular avionics
Garmin International, Inc Olathe, KS 800-800-1020
This document is applicable to commercial and military aircraft fuel quantity indication systems. It is intended to give guidance for system design and installation. It describes key areas to be considered in the design of a modern fuel system and builds upon experiences gained in the industry in the last 10 years.
In the early days of quality management, prior to 1980s, the focus seemed to be on "Quality Control" or "Quality Assurance". Emphasis was placed on inspection and testing. Quality was about conformance to specification. Non-Conformance Reports were representative of quality control. Our understanding of quality management has evolved, largely based on the Toyota Quality and Concurrent Engineering Approach of moving it off the production line for Integrated Product and Process Development (IPPD) [1]. In the late 1980s industry experienced similar difficulties in understanding and adopting quality management. The ideas behind managing quality are quite abstract. Quality is primarily about understanding and satisfying a customer's expectations. This includes implicit expectations, as well as explicit expectations. The techniques of specification, inspection and testing only make sense in that wider context. Formal risk management was developed in the late 1980s and throughout the 1990s. Risk management principles are now widely understood and applied. Functional Safety Management (FSM) simply applies quality management to systems that are designed to control risk. [2] The standards for FSM and Development Assurance (DA) are relatively new. SAE ARP 4754 and ARP 4761 for complex aircraft systems were introduced in 1996 and DO-178 for software in 1998. In 2010 ARP 4754A [3] was created for movement from federated avionics systems to distributed integrated avionics systems which set the stage for Integrated Modular Avionics (IMA) in DO 297 [4]. The Army identified IMA as a critical technology in its Joint Common Architecture (JCA) Final Report [5] and is seeking to provide a Modular Open Systems Architecture (MOSA) approach to its Future Vertical Lift (FVL) programs. [6] The aim is to build and upgrade FVL mission systems without expensive proprietary interfaces. New capabilities from a choice of developers will adapt to emerging threats. The mission system architecture demonstration (MSAD) Program has awarded six contracts to avionics vendors to develop MOSA tools and rules. A capstone demonstration wraps-up this December 2020 and will generate a final report and provide guidance for Future Attack and Reconnaissance Aircraft (FARA), FLRAA and FUAS architectures. MOSA flexibility and economy come to legacy helicopters with the Aviation Mission Common Server (AMCS), which transitions the legacy fleet from single-purpose/single-vendor architectures to more adaptable modules and components. Nonproprietary, government-controlled, open system standards interface new software applications without going to each platform maker for integration. [6] This paper will review FSM, DA, and Open IMA in these civil aircraft standards, compare them with Army Aviation's current Army Military Airworthiness Certification Criteria (AMACC) [7] and recommend a Civil Military FSM DA Framework for FVL and on how AMACC could be modified for FVL Open Systems Architectures (OSA) Certification using a Modular Open Systems Approach (MOSA). [8]
Integrated Modular Avionics (IMA) system comprises IMA platform and hosted applications. The IMA platform provides the hosted applications with shared resources, e.g. computing, memory, communication, health monitoring resources. As a bridge between them, the IMA configuration data specifies how these shared resources are allocated to each hosted application. The IMA configuration data, which is different from real hardware and software code, should be validated and verified as an important portion of IMA system. After a brief introduction of IMA system, development processes, and general means of compliance for certification, this paper proposed an Architecture Analysis and Design Language (AADL) model of IMA configuration based on a case study of airborne datalink system. Based on the model, the IMA configuration data is abstracted and categorized into several types, with the correspondent means of compliance identified for each type. Furthermore, the associated roles and responsibilities are discussed for IMA configuration data validation and verification. The IMA configuration data specific means of compliance, the validation and verification processes, the roles and responsibilities, together form a method for validating and verifying the IMA configuration data for shared resources allocation, which can be applied to all partitioning systems beyond avionics.
Most of today’s collision-avoidance, in-flight-entertainment (IFE), air-to-ground-communications, and other avionics systems employ electronics packaging based on the Aeronautics Radio INC (ARINC) 600 standard. Compared to the older ARINC 404 standard dating from the 1970s that defined “black box” enclosures and racks within aircraft, ARINC 600 specified a Modular Concept Unit (MCU) – the basic building block module for avionics. An ARINC 600 metal enclosure can hold up to 12 MCUs, allowing a lot of computing power to be placed in a centralized “box.” By making it possible to run numerous applications over a real-time network, ARINC 600 enabled “next generation” integrated modular avionics (IMA).
This document is applicable to commercial and military aircraft fuel quantity indication systems. It is intended to give guidance for system design and installation. It describes key areas to be considered in the design of a modern fuel system, and builds upon experiences gained in the industry in the last 10 years.
By adopting the latest developments from other critical (e.g. integrated modular avionics) and high-volume automotive industries with safety requirements (ADAS and autonomous driving), the rotorcraft industry could reduce system lifecycle costs and gain new integrated platform capabilities which support incremental modernization, simplify upgrades and modifications for different missions or rotorcraft platforms. A specific set of architecture design patterns and computational models, used in integrated modular architectures, enables the design of less complex integrated systems which can collect and process all system sensor data in (hard) real-time, supports seamless sensor data fusion for IVHM, and enables the integration of critical and non-critical functions. Accompanied with robust system engineering, RTCA DO-254 / DO-178C DAL A/B design assurance and extended use of ASIL-D-compliant (automotive) components, novel integrated architectures for rotorcraft can be designed to fit with robust modular form factors such as VPX. Such integrated architectures can be extended with COTS computing and sensor fusion LRUs/ECUs used for automotive ADAS/ADS (advanced driver assistance systems/autonomous driver systems) and rapidly progressing autonomous driving applications.
Advanced Integrated Modular Avionics (A-IMA) will drive new focus and challenges for Model Based Engineering (MBE). First, there is the need to bridge MBE to legacy system elements that were developed without MBE along with the need to handle hybrid Open System Architecture / Integrated Modular Avionics (OSA/IMA) based architectures. Second, there is the need for MBE to be reusable and interoperable across product development cycles as technology insertions occur. Third, there is the need for integration of MBE into synthesizable descriptions that can also be effectively validated for mixed general purpose, safety, and secure computing and networking environments. Fourth is the need for effective application of MBE in hybrid waterfall and agile development environments where target infrastructure is scalable in capability and cost. Fifth is the need for MBE to support partitioned roles across companies, government, and universities where one entity does requirements, one does architecture, one develops components, one provides formal test, and another provides system sustainment. There are a number of industry and university efforts underway to address these focus items and challenges spread across these adjacent MBE complex system domains. This paper is focused on the current state of each of these areas relative to use in A-IMA systems based on industry initiatives and academic research. It uses the driverless car for comparison as an emerging "Advanced Integrated Modular Architecture" and identifies its parallel approaches to address these focused items and challenges. This work is being built on the authors' work exploring dual use technologies being developed for the driverless car domain that will lead to a market of 10 Million autonomous cars operating in 2020. Previous papers have addressed identification of potential advanced automotive dual use transformational hardware and software technologies including many core processing, advanced software autonomy and data fusion components, unified mixed criticality networking, and integrated cyber security for A-IMA. A testbed has also been recently proposed as a mechanism to evaluate these dual use technologies in an A-IMA context. This paper extends the dual use view to include understanding of the best-of-breed avionics MBE environment and how it can be complementary to leveraging a testbed environment in addressing affordable, scalable, and open solutions.
In the Integrated Modular Avionics (IMA) domain, THALES developed a high performance communication network named SAEN (Self Adaptive Embedded Network). SAEN is a switchless network solution, fully embedded in a single Network Component Interface (NCI), aimed to interconnect easily several modules of a system, in any mesh network topology. Once each module is equipped with its network component, just connect them together to realize the wanted topology and switch ‘on’ the modules power supplies. At power-on, all the nodes of the network aggregate to form a complete global and coherent network, autonomously managing its configuration and the optimal static routing between any emitter and receiver. The constituted network is deterministic, autonomous, self-discovering, and auto-adapting to the network variations and guarantees an optimal routing in any situation of the graph, as long as a path exists. The interest of managing mesh topology resides in the intrinsic robustness offered by the graph connectivity. This solution is being implemented in the new mission computer embedded in the latest French combat aircraft. For this application, the components drive a 2 Gigabits per second (Gbps) physical layer on a copper backplane. It is to be noticed that for this application, the network is highly constrained since the mission computer is likely to reallocate dynamically the applications on various processing modules. The paper describes the basic elements of graph theory that allow to explain the robustness properties linked to the graph connectivity. Then some linear algebra used to compute the optimal routing and its optimization in a wired logic module of the component. Finally, the paper presents a brief description of the application on the aircraft mission computer.
In the aerospace industry, as the modern avionics systems became more and more complex, the Integrated Modular Avionics (IMA) architecture has been proposed as a replacement of the federated architecture, in order to offer better solutions on SWaP constraints (Size, Weigh and Power). However, the development process of IMA avionics systems is much more difficult. This paper aims to propose to the aerospace industry a set of time-effective and cost-effective solutions for the integration and functional validation of IMA systems. Based on MBE methodology, which is considered as an interesting solution for the IMA systems development [8], this paper proposes a design flow, that integrates three steps of refinement, for the configuration and the validation of IMA platforms. In the first step of the design flow, the modeling language AADL is used to describe the IMA architecture. The AADL modeling environment OCARINA, a code generator initially designed for the real-time operating system POK, has been modified to generate software integration code and system configuration files for the IMA simulator named SIMA. This solution is a cost effective alternative to expensive commercial development environments to validate ARINC653 software applications. In the second step of the design flow, a cosimulation platform composed of two simulators is proposed: Simulink for the simulation of peripherals and SIMA for the simulation of IMA modules. In the third step, the validated avionics applications and system configuration can be ported with minimum effort from the cosimulation environment to an implementation platform. A case study, which consists in integrating several avionics applications to SIMA and then porting them to PikeOS development environment, was brought in the purpose of demonstrating the proposed design flows and co-simulation platform. The research work realized in this paper is a part of collaboration between industrials and academics through the CRIAQ AVIO509 project.
Since 2000, avionics is facing several changes, mostly driven by technological improvements in the electronics industry and innovation requirements from aircraft manufacturers. First, it has progressively lost its technological leadership over innovation processes. Second, the explosion of the electronics consumer industry has contributed to shorten even more its technology life cycles, and promoted the use of COTS. Third, the increasing complexity of avionics systems, which integrate more and more functions, have encouraged new players to enter the market. The aim of this article is to analyze how technological changes can affect the competitiveness of avionics firms. We refer to criticality levels as a determinant of the market competitiveness. Certification processes and costs could stop new comers to bring innovations from the consumer electronics industry and protects traditional players. The study will compare three avionics systems regarding their patent dynamics since 1980: flight controls, Integrated Modular avionics and Head-Up Displays. We assume that differences in the market competitiveness may appear due to their differences in their related criticality level. Systems belonging to Design Assurance Level A or B required wide-range of capabilities and long-term experience. The opportunity for new comers to introduce a certified-version of their product could be constrained by certification requirements.
For Orion Exploration Flight Test One (EFT-1), the unit-under-test for flight software verification has been chosen as the entire integrated flight software load. At the time of this reporting, the unit test tool, while powerful, operates on very small units, usually classes. This leaves a sizable gap between unit testing and verification. Orion flight software is divided into ARINC 653 partitions, and partition level testing is in this large gap.
An Integrated Modular Avionics (IMA) architecture provides a common platform for software partitions with shared processing and input/output (I/O) resources. A key feature of the IMA architecture is I/O partitioning. An IMA system will prevent one software partition from changing an I/O resource that is owned by another software partition. This prevents one software partition from controlling the outputs of another due to hardware fault or software error. The IMA system must have protection mechanisms in place to enforce the I/O partitioning.
ABSTRACT This paper describes recent results from the Georgia Institute of Technology to develop, improve, and flight test a multi-aircraft collaborative architecture, focused on decentralized autonomous decision-making. The architecture includes a search coverage algorithm, behavior estimation, and a pursuit algorithm designed to solve a scenario-driven challenge problem. The architecture was implemented on a pair of Yamaha RMAX helicopters outfitted with modular avionics, as well as an associated set of simulation tools. Simulation and flight test results for single- and multiple-aircraft scenarios are presented. Further work suggested includes identification and development of more sophisticated methods that can replace the simpler elements in modular fashion.
The Integrated Modular Avionics (IMA) architecture has been a crucial concern for the aerospace industry in developing more complex systems, while seeking to reduce space, weight and power (SWaP), as well as development, certification and production time. From a software perspective, that objective pushes developers to migrate toward safety critical space and time partitioning environment. However, mainstream commercial real-time operating systems (RTOS) offering such partitioning can be restrictive in early development due to very high licensing costs. That situation is even more striking when considering that low-cost alternatives could instead be used for system modeling and early simulation before acquisition of a target platform. This paper reviews existing low-cost and open-source development environments to propose a novel design flow. The proposed methodology starts with model-based analysis in the AADL modeling language. Then, configuration files and software integration code are generated and executed using the Simulated IMA (SIMA) software from GMV. A case study experiment was created using a Multi-purpose Control and Display Unit (MCDU) communicating with an external Flight Management System (FMS) simulation provided by our industrial partner CMC Electronics. Results show reduction of time for system and partition configurations from hours to seconds, notably by reducing human error. It also proves useful in identifying design flaws in early development as well as facilitating software architectural exploration for integrated modular avionics.
Items per page:
50
1 – 50 of 99