Browse Topic: Airworthiness

Items (134)
Generally, the allowable strain design is adopted for composite structures, which should ensure that the structure has sufficient strength and stiffness under the service load, and the safety margin should be greater than zero under the design load. The thesis develops a structured design for a stabilizer of civil aircraft based on standards and airworthiness requirements. The main task of this thesis is to compare the results of the all-mental structure and composite material structure of stabilizer on weight reduction at sufficient strength and stiffness.
Pi, RungeLv, BaoliangZhang, Liang
In response to the current airworthiness regulations’ inability to cover the stall flight test requirements under icing conditions of civil aircraft with high-angle-of-attack restriction function and the lack of relevant flight test technologies in China, a study was conducted on the differences in airworthiness provisions for stall characteristics under icing conditions of such aircraft. Key technologies, including simulated ice accretion stall flight test methods, ice installation strategies, and data analysis techniques, are proposed and successfully applied to a specific civil aircraft. The results demonstrate that the methodologies proposed in this paper can effectively support simulated ice accretion stall tests, providing valuable insights for other similar aircraft.
Zhang, Haini
Pollution in the oxygen system of civil aircraft may lead to fire accidents, and maintaining the cleanliness of oxygen equipment is the most effective measure to reduce the risk of fire. This paper introduces the cleanliness requirements, cleaning methods, and procedures of oxygen equipment, and combines the cleanliness level requirements of oxygen equipment for a certain type of civil aircraft. By detecting the total weight of Non-Volatile Residue and the size and quantity of particles on the surface of the parts, it verifies whether the specific cleaning process can meet the cleanliness level required by the design. In addition, the possible sources of pollutants are analyzed based on the first unqualified verification results, and targeted improvement directions for the process are provided. After re-performing the cleanliness verification test, the results passed successfully, indicating that the process improvement is effective and has passed the airworthiness certification of the reviewer.
Huang, Jingqi
Analysis of cabin depressurization is key to ensuring civil aircraft airworthiness safety. In this study, we use a comprehensive approach to analyze depressurization scenes under regulations such as CCAR 25.841. For cases with and without cabin altitude warnings, we calculated critical leakage areas using an orifice flow model and iterative numerical methods. This combines inputs like emergency descent envelopes, air supply rates, and cabin parameters. In our analysis, we evaluate system failure impact and structural breaches on cabin pressure dynamics. For cases where the critical leakage area failed to meet the limits, we use an equivalent safety analysis based on the Depressurization Exposure Index (DEI). This combines pressure and exposure duration to measure physiological risks. We validated this approach through Simulink simulations and case studies, and found that it supports airworthiness verification, emergency descent optimization, and structural design improvements. This method provides a robust framework for enhancing civil aircraft depressurization safety.
Zheng, Bian
The climb gradient along the takeoff trajectory at each point during takeoff reflects the aircraft’s ability to clear obstacles and reach a safe altitude, ensuring the safety of civil flights. Airworthiness regulations specify certain requirements for the single-engine-out climb gradient. Given that the data used in conventional calculation methods are significantly influenced by the flight status during the process, this paper explores two new climb performance calculation methods based on the existing ones. A set of data was calculated, and the resulting errors were all no more than 10%, indicating that both new calculation methods are effective and reliable. Therefore, they provide a certain reference value for the climb gradient calculation of transport category aircraft.
Jiang, TianjunLiu, Tao
Rolling-element bearings in rotorcraft dynamic systems are critical components susceptible to rolling contact fatigue (RCF), a dominant degradation mechanism manifesting through subsurface-initiated spalling, surface micropitting, and fatigue fractures. Robust inspection strategies compliant with EASA and FAA requirements are therefore essential. Traditional methods are often invasive, requiring disassembly, and are susceptible to human-factor errors. Smart Duplex introduces a design-for-monitoring architecture integrating in-situ videoscopic and coherence scanning interferometry (CSI) for high-resolution 3D surface mapping, including under partial grease coverage. This paper details a repeatability and reproducibility (R&R) framework ensuring metric consistency; a maintainability assessment projecting significant man-hour reductions and high availability; certification rationale emphasizing airworthiness improvements via enhanced detectability, workload reduction, and digitized inspection records; and an airworthiness mapping supporting threat assessments, Airworthiness Limitations Section (ALS) entries, and usage-based maintenance credits. By embedding sensing capability and digitizing inspection records, Smart Duplex minimizes downtime, mitigates human-factor errors, and facilitates predictive maintenance, optimizing cost, enhancing performance, and ultimately improving safety.
Delli Paoli, MicheleAnaclerio, Mario Alberto
This paper details comprehensive analysis modeling and analysis supporting the development of the Research Aircraft for eVTOL Enabling techNologies (RAVEN). An isolated rotor model was developed in CAMRAD II, and predictions of rotor performance and rotor aeroelastic stability were generated. The rotor stability predictions are part of assessing airworthiness of the RAVEN vehicle. The performance predictions were used to calibrate the surrogate model for the NASA Design of Rotorcraft (NDARC).
Wright, StephenSilva, Christopher
This paper focuses on the performance of the high-pressure oxygen cylinder oxygen supplemental system in the lavatory of civil aircraft. Due to the potential safety hazards of chemical oxygen generators in the lavatory, high-pressure gaseous oxygen cylinders are used instead. Through theoretical and study, the influence of the orifice on the oxygen flow rate is thoroughly investigated. Based on relevant principles, the calculation method of the gas flow characteristics in the orifice is determined. Considering the high initial pressure of the oxygen cylinder, the supersonic flow condition within approximately 20 minutes is mainly considered. The Simulink is used to simulate the system flow rate under different temperatures during cabin depressurization. Experimental verification shows that the oxygen flow rate under different temperatures meets the minimum oxygen demand, and the simulation results are highly consistent with the experimental results, indicating that the simulation accuracy meets the airworthiness standards and provides a strong basis for the design and optimization of the system.
Wan, ShutingLei, MingjunYu, Xiaoying
The process detailed within this document is generic and applies to the entire end-to-end health management capability, covering both on-board and on-ground elements in both commercial and military applications throughout their life cycle. While some guidance related to usage of ground-based health management equipment for airworthiness credit exists in certain areas, this document provides a general mechanism to ensure a level of integrity commensurate with the potential aircraft-level consequences of the relevant failure conditions. The practical application of this standardized process is detailed in the form of a checklist. In order to provide some detailed guidance utilizing the process and checklist, some high-level examples of successful cases of approved “Maintenance Credit” applications for airworthiness credit (and one case where the approval is in process in 2024) are included. This document does not teach how to design an IVHM function, how to do a safety or risk analysis, prescribe hardware or software assurance levels, or answer the question, “How much mitigation and evidence are enough?” The criticality level and mitigation methods will be determined between the applicant and the regulator, using existing guidance from SAE International and other sources. Note that the focus of this document is to ensure appropriate process integrity for the creation of a candidate IVHM function, but it may not address all the elements required to operationalize that function. This document uses the term IVHM to refer to any health management function applied to an air vehicle. The SAE standards committees have been using this term for decades; however, other communities within this industry have used terms such as Aircraft Health Management or Monitoring (AHM), Integrated Aircraft Health Management (IAHM), Vehicle Health Management (VHM), and Rotorcraft Health and Usage Monitoring System (HUMS) to refer to the same concept. At the subsystem level, terms such as Structural Health Monitoring (SHM), Equipment Health Management (EHM), Engine Condition Monitoring (ECM), and Engine Health Management (EHM) are also commonly used. It should be understood that all these terms refer to the same function. There are cases where this process is applicable but is not required because of historic precedents. For example, there is a historical precedent for using an off-board health management solution to achieve compliance with extended-range twin-engine operations performance standards (ETOPS) (refer to AC 120-42A).
HM-1 Integrated Vehicle Health Management Committee
Civil and military rotorcraft operators desire enhanced capabilities from their vehicles in terms of mission efficiency, effectiveness, productivity, and availability. A critical element of this challenge is associated with providing cold weather availability. Currently, cold weather operations are enabled by regulatory actions leading to Limited Approvals, Qualifications, Clearances, and Restrictions. Cold weather certification (clearance of a new aircraft) and continuing airworthiness (maintaining effectiveness of fielded aircraft) are data driven processes. This work provides guidance on an Icing Encounters Survey (IES) based data gathering method supporting continuing airworthiness organizations in improving fleet safety and capabilities during cold weather operations.
Alexander, Marc
Airworthiness certification of aircraft requires an Airworthiness Security Process (AWSP) to ensure safe operation under potential unauthorized interactions, particularly in the context of growing cyber threats. Regulatory authorities mandate the consideration of Intentional Unauthorized Electronic Interactions (IUEI) in the development of aircraft, airborne software, and equipment. As the industry increasingly adopts Model-Based Systems Engineering (MBSE) to accelerate development, we aim to enhance this effort by focusing on security scope definitions – a critical step within the AWSP for security risk assessment that establishes the boundaries and extent of security measures. However, our findings indicate that, despite the increasing use of model-based tools in development, these security scope definitions often remain either document-based or, when modeled, are presented at overly abstract levels, both of which limit their utility. Furthermore, we found that these definitions frequently lack alignment with airworthiness security regulations. To address these two distinct gaps, this paper presents a model-based approach for detailed security scope definitions using the Systems Modelling Language (SysML). Our approach aligns with airworthiness security regulations ED-202A / DO-326A and ED-203A / DO-356A and incorporates a SysML profile based on the CORAS language for accurate modeling of security scopes. This facilitates a model-based security risk assessment by creating unambiguously system models that represent assets through model elements, document entry points to the assets and determine their environment. This SysML-based approach supports certification related activities by ensuring that security scope definitions are comprehensive and aligned with airworthiness regulations, directly addressing the identified gaps. The approach's applicability and effectiveness are demonstrated through an illustrative example in the domain of aircraft cabin system development. Moreover, the approach provides valuable inputs that assist operators in deriving guidance for the safe operation and maintenance of the aircraft, complementing existing methods and practices.
Hechelmann, AdrianMannchen, Thomas
Aerospace engineering programmes typically cover airworthiness philosophies, principles, structures, processes, and procedures. The industry has recently recognized the need to enhance the graduate engineers’ skills around airworthiness. This has led to introduction of standards acting as guides for developing curricula and content for university airworthiness courses. Concept maps, a visual mapping of concepts in a hierarchical way, enjoy wide use in engineering education (teaching and assessment). Airworthiness courses are both technical and legalistic, presenting challenges to students when it comes to understanding complex and intertwined regulations. Schematic representations of concepts can foster the cognitive processes of learning. Concept maps can assess efficiently and comprehensively a multitude of airworthiness topics. This study examines the feasibility of applying concept maps in airworthiness education. Fill-in-a-map concept maps were developed as assessment tools for an airworthiness course, covering topics in aircraft type design, production organization approvals, and maintenance documentation. They were used in tests alongside multiple-choice questions. The results were analyzed via descriptive and inferential statistics, complemented by qualitative evaluation of the concept map results. The students gained experience in concept maps, while the multiple-choice questions were present to compensate the overall test grade. Prior exposure to concept maps can assist the students to familiarize with their structure and function. The gradual increase in the concept maps’ difficulty was consistent with the increasing complexity of the airworthiness material. When concept maps are not accompanied by lists of concept words they can be challenging to complete.
Kourousis, KyriakosChatzi, Anna
Airworthiness Considerations for Human Engineering in Acquisition.
Copeland, Bob
This study leverages the temperature impact data obtained from the battery systems of airworthiness-certified fixed-wing electric aircraft to predict and correct the performance of eVTOL battery systems under various temperature conditions. Due to the lack of airworthiness-certified eVTOL models, it is challenging to directly test battery system parameters under temperature variations. However, using data from Ma Xin's team's production batteries tested on certified fixed-wing electric aircraft, we can accurately measure the effects of temperature changes. The capacity retention data at temperatures of -40°C, -20°C, -10°C, 0°C, 0°C, 25°C, 35°C, 45°C, 55°Care 78.14%, 83.3%, 84.1%, 88.1%, 92.3%, 100.0%, 102.0%, 103.9%, 104.6%. These quantified results provide a basis for modeling and experimental validation of eVTOL battery systems, ensuring their performance and safety across a wide range of temperatures. Although there are some research of battery system of eVtol in room temperature, the data and research of impact of various temperature on battery systems of eVTOLin this article is not published before.
Ma, XinDing, ShuitingPan, Yilun
With the capability of predicting detailed injury of occupants, the Human Body Model (HBM) was used to identify potential injuries for occupants in car impact events. However, there are few publications on using HBM in the aviation industry. This study aims to investigate and compare the head, neck, lumbar spine and thoracic responses of the Hybrid III and the THUMS (Total Human Model for Safety) model in the horizontal 26g and vertical 19g sled tests required by the General Aviation Aircraft Airworthiness Regulations. The HIC of THUMS and Hybrid III did not exceed the requirements of airworthiness regulations. Still, THUMS had higher intracranial pressures and intracranial stresses, which could result in brain injury to the occupants. In vertical impact, the highest stress of the neck of THUMS appears at the cervical spine C2 and the upper neck is easily injured; in horizontal impact, the cervical spine C7 has the highest load, and the lower neck is easily injured. Due to the low biofidelity of the Hybrid III ATD neck structure, the injuries that appeared at different neck locations cannot be identified by the Hybrid III ATD. Because of the submarining phenomenon, the lumbar spine load and bending moment of the THUMS are much smaller than that of the ATD model, which shows a lower risk of injuries. In both impact scenarios, the THUMS chest deformation was higher. In the vertical 19g impact, the THUMS developed much higher shoulder belt loads than the ATD. The results indicate the Hybrid III ATD underestimates the risk of injury to passengers' heads and chests, while overestimating the risk to the lumbar spine compared to THUMS. Furthermore, due to limitations in the locations of sensors, the Hybrid III ATD is unable to identify the severe injury at lower neck and upper lumbar.
Shi, XiaopengDing, XiangheGuo, KaiLiu, TianfuXie, Jiang
RTCA DO-178C, guideline in the aviation industry for the development of airworthiness of aviation software mandates the analysis of data and control coupling using requirement-based testing for safety-critical avionics software (Refer the Table 1). DO-178C defines Control Coupling as the manner or degree by which one software component influences the execution of another software component. Data Coupling as the dependence of a software component on data not exclusively under the control of that software component. The intent of the analysis of data coupling and control coupling is to ensure that each module/component are interacting with each other as expected. That is, the intent is to show that the software modules/components affect one another in the ways in which the software designer intended and do not affect one another in ways in which they were not intended, thus resulting in unplanned, anomalous, or erroneous behavior. The measurements and assurance should be conducted using requirements-based testing of the integrated components on the final software build in order to ensure that the interactions and dependencies are correct, the coverage is complete, and the objective is satisfied. The proposed method involves using software execution and data trace information to derive data and control coupling insights from requirement-based test execution. This technique focuses on analyzing how software components interact during actual program execution. By capturing and examining execution traces and data flows, it can identify the dependencies and interactions between different software modules.
Ramegowda, Yogesha Aralakuppe
Aerospace is an industry where competition is high and the need to ensure safety and security while managing costs is foremost. Stakeholders, who gain the most by working together, do not necessarily trust each other. Changing backbone technologies that drive enterprise systems and secure historical records does not happen quickly (if at all). At best, businesses adapt incrementally, building customized applications on top of legacy systems. The complexity of these legacy systems leads to duplication of efforts and data storage, making them very inefficient. Technology that augments, rather than replaces, is needed to transform these complex systems into efficient, digital processes. Blockchain technology offers collaborative opportunities for solving some of the data problems that have long challenged the aerospace industry. The industry has been slow to adopt the technology even though experts agree that it has real potential to revolutionize the global supply chain—including maintenance, repair, and overhaul (MRO)—driving tremendous cost, excess inventory, and inefficiencies out of the system. This chapter discusses how the adoption of blockchain technology could have a significant impact on the aerospace industry and addresses some of the unsettled concerns surrounding the implementation of the technology.
Walthall, RhondaDavid, AharonFarell, JamesHann, RichardJohansen, Tor A.
The extent of automation and autonomy used in general aviation (GA) has been steadily increasing for decades, with the pace of development accelerating recently. This has huge potential benefits for safety given that it is estimated that 75% of the accidents in personal and on-demand GA are due to pilot error. However, an approach to certifying autonomous systems that relies on reversionary modes limits their potential to improve safety. Placing a human pilot in a situation where they are suddenly tasked with flying an airplane in a failed situation, often without sufficient situational awareness, is overly demanding. This consideration, coupled with advancing technology that may not align with a deterministic certification paradigm, creates an opportunity for new approaches to certifying autonomous and highly automated aircraft systems. The new paths must account for the multifaceted aviation approach to risk management which has interlocking requirements for airworthiness and operations (including training and airspace integration). They occur across a variety of different operational paradigms with varying roles for the human and the systems in question. If implemented properly, autonomy can take GA safety to the next level while simultaneously increasing the number and variety of aircraft and transportation options they provide.
Dietrich, Anna MracekRajamani, Ravi
To this point in aviation history, a typical aircraft type certification program has focused on the constituent systems that make up the aircraft, decomposing them further and further down until reaching their elemental parts and how they interact. This approach has traditionally treated the actual communication technology as only an interface, with technology and implementation based on a decision between multiple stakeholders via an ICD and high-level requirements. This has been necessary to ensure the accurate and on-time delivery of safety-critical data between nodes. When using legacy point-to-point or bus-based data communication technologies like ARINC 429 or MIL-STD-1553, this approach has worked well enough as these technologies are relatively straightforward and proven technologies. However, as onboard bandwidth needs for safety-critical data increase, these legacy technologies are increasingly no longer capable of meeting the needs of system integrators. Ubiquitous, high-bandwidth Ethernet is the obvious solution to these needs and, indeed, it has been used for quite some time in onboard networking applications for low Development Assurance Level (DAL)/non-safety critical data. However, as Ethernet moves into high-DAL applications, the certification of the Ethernet network itself becomes a major complexity that must be addressed directly.
Mustillo, MichaelFinnegan, DanielZischka, Wolfram
The development of turbulence criteria to provide early guidance for the design of vertiports is presented in this paper. For any aircraft, winds, in particular crosswinds and gusty winds, are top of mind for all pilots engaging in take-off and landing maneuvers. It is anticipated that the same will be true for VTOL and eVTOLs landing on vertiports, in particular as new vertiports are built closer and closer to urban centres. First, a review of the current design criteria for vertiports around the world related to wind is presented, highlighting the commonality between the guidance and the gaps in their content. Second, the controllability criteria that VTOL and eVTOLs will likely need to meet in the pursuit of an airworthiness certification are reviewed and their pertinence with regards to vertiport design are discussed. Third, the characters of the wind and their impact on eVTOL flights at or near take-off and landing infrastructure is explored. Finally, a set of turbulence criteria for vertiports and a turbulence index are proposed. The index includes a scale for conditions ranging from favorable for take-off and landing; to more and more demanding conditions; up to turbulence conditions to be firmly avoided.
Larose, GuyAl Labbad, MaryamSchajnoha, Sharon
This paper describes the methodology, involving testing and simulation activities, to assess malfunction conditions of complex systems installed on fly-by-wire vehicles, including the evaluation of their effects. This paper provides also a description about how the system malfunction tests are designed, driven by input requirements and systems capability and behavior. With respect to prior publications, this paper includes some practical test examples, based on systems monitoring, logics and alerting functions. The case study described here comes from a portion of multiple laboratory certification tests done for AW609 Tiltrotor, focused on Avionics System malfunctions. These tests and simulations are a valuable Means of Compliance with respect to applicable airworthiness rules, and a suitable means to verify the design safety requirements. Three relevant examples are presented, grouped by input requirement and safety conditions. The effect of such malfunctions is evaluated, with respect to the Avionics System output produced to keep adequate flightcrew awareness about the vehicle status.
Taumaturgo, VincenzoAbbagnato, Elena Sofia
Additive manufacturing (AM) is currently being used to produce many aerospace components, with its inherent design flexibility enabling an array of unique and novel possibilities. But, in order to grow the application space of polymer AM, the industry has to provide an offering with improved mechanical properties. Several entities are working toward introducing continuous fibers embedded into either a thermoplastic or thermoset resin system. This approach can enable significant improvement in mechanical properties and could be what is needed to open new and exciting applications within the aerospace industry. However, as the technology begins to mature, there are a couple of unsettled issues that are beginning to come to light. The most common question raised is whether composite AM can achieve the performance of traditional composite manufacturing. If AM cannot reach this level, is there enough application potential to warrant the development investment? The answers are highly dependent on the individual processors and will require significant research. Yet, there are still other common challenges that are not isolated to a singular processor. The focuses of this chapter are the capability to design and provide robust structural analysis for continuous fiber-reinforced polymer AM—two unsung aspects that can make or break this new technology as it finds its way into the aerospace market. These two unsettled issues, out of many, may require fundamental changes to the design, analysis, and manufacturing process. Without solutions to them, adoption by the aerospace industry will be limited to point design applications, thus constraining the technology to being nothing more than a specialized tool.
Hayes, MichaelMuelaner, JodyRoye, ThorstenWebb, Philip
The process detailed within this document is generic and applies to the entire end-to-end health management capability, covering both on-board and on-ground elements, in both commercial and military applications throughout their lifecycle. This ARP addresses a gap in guidance related to usage of ground-based health management equipment for airworthiness credit, ensuring a level of integrity commensurate with the potential aircraft-level consequences of the relevant failure conditions. The practical application of this standardized process is detailed in the form of a checklist. The on-board elements described here are typically the source of the data acquisition used for off-board analysis. The on-board aspects relating to airworthiness and/or safety of flight, e.g., pilot notification, are addressed by existing guidance and policy documents. If a proposed health management capability for airworthiness credit involves modification of the on-board systems, the substantiation of those changes should be based on the applicable type certification guidance. This document does not prescribe hardware or software assurance levels, nor does it answer the question “how much mitigation and evidence are enough?” The criticality level and mitigation methods will be determined between the applicant and the regulator. There are cases where this process is applicable but may not be appropriate due to historical precedents. For example, there is a historical precedent for using an off-board health management solution to achieve compliance with Extended-Range Twin-Engine Operations Performance Standards (ETOPS) (refer to FAA AC 120-42A). In order to provide some detailed guidance utilizing the process and checklist, some high-level examples of previous successful cases of maintenance credit applications for airworthiness credit are included. Refer to ARP5120 for additional examples of practical mitigating measures applicable to health management systems. At this point, it is incumbent on the applicant to explain any differences in terminology between the health management system they are seeking credit for and the appropriate regulatory references. For example, the system name often uses interchangeable terms such as “Engine Health Monitoring,” “Equipment Health Management,” “Prognostic Health Management,” “Powerplant Health Management,” etc.
E-32 Aerospace Propulsion Systems Health Management
Airworthiness Directives (ADs) serve as a medium through which commercial and military regulators improve the system’s performance by responding to the failure of the airplanes. The Federal Aviation Administration (FAA) and United States Air Force (USAF) provide ADs that detail overall cost on operators. The dataset derived from the Boeing 767 (B767) and its military derivatives, USAF’s KC-46A gives ideas into sensor solutions and maintenance approaches that may reduce these costs. Given the ADs significant costs for Boeing 767 operations, an analytical failure framework that determines the failure modes and failure mechanisms is introduced. For example, a huge portion of severe impairment (e.g., cracking, corrosion, and chafing) constitutes 27% of failure mechanisms in these systems. To reduce future B767 ADs for commercial and military operators, sensor solution and maintenance strategies using performance metric and genetic algorithm are assessed. As a result, maintenance downtimes may be decreased by this framework by providing prompt warning to any fault that would require time and money to fix.
Rasaq, LukmonFerguson, KorbinYadav, OmKyle, BlondSiddula, Madhuri
This SAE Aerospace Recommended Practice (ARP) identifies and defines methods of compliance with power available and inlet distortion requirements for rotorcraft with inlet barrier filter (IBF) installations. The material developed herein is intended to provide industry-recommended methods of compliance with civil airworthiness regulations. It is intended to serve as a basis for new or revised FAA advisory material describing acceptable methods for determining power assurance, establishing power available, and for substantiating acceptable engine inlet distortion for IBF installations. The ARP does not address other types of inlet protection systems such as inertial separator, electrostatic precipitators, or foreign object debris (FOD) screens. It is agreed to treat dust, ice, salt, water, and snow as contaminants to the IBF for the purpose of establishing power available and assessing inlet distortion, but any other effects of ice and snow on inlet airworthiness are outside the scope of this ARP.
S-12 Powered Lift Propulsion Committee
The purpose of this SAE Aerospace Information Report (AIR) is to provide guidance for aircraft engine and propeller systems (hereafter referred to as propulsion systems) certification for cybersecurity. Compliance for cybersecurity requires that the engine control, propeller control, monitoring system, and all auxiliary equipment systems and networks associated with the propulsion system (such as nacelle systems, overspeed governors, and thrust reversers) be protected from intentional unauthorized electronic interactions (IUEI) that may result in an adverse effect on the safety of the propulsion system or the airplane. This involves identification of security risks, their mitigation, verification of protections, and their maintenance in service. This document is intended to serve as suitable guidance for propulsion system manufacturers and applicants for propulsion system type certification. It is also intended to provide guidance for subsequent propulsion system integration into aircraft systems for aircraft certification and operational use.
E-36 Electronic Engine Controls Committee
Carter, H.Rupert, JasonChan, AlexanderVinegar, Chris
In view of the structural accidental events in the ongoing airworthiness stage of civil aircraft, it is necessary to conduct a risk assessment to ensure that the risk level is within an acceptable range. However, the existing models of risk assessment have not effectively dealt with the risk of accidental structural damage due to random failure. This article focuses on probabilistic risk assessment using the Transport Airplane Risk Assessment Methodology (TARAM) of accidental structural damage of civil aircraft. Based on the TARAM and probability reliability integral, a refined failure frequency probability calculation model is established to elaborate on composite structure failure frequency. A case study is analyzed for the outer wing plane of an aircraft having impact damage of composite materials. Finally, results of the risk assessment without correction and risk assessment with correction are presented for detailed visual inspection and general visual inspection.
Jia, BaohuiFang, JiachenLu, XiangXiong, Yijie
Validation of Mission Performance Calculator (MPC) for Airworthiness Applications of Future Vertical Lift Platforms, presentation by US Army DEVCOM AvMC.
Sims, John
The extent of automation and autonomy used in general aviation (GA) has been accelerating dramatically. This has huge potential benefits for safety given that 75% of accidents in personal and on-demand GA are due to pilot error. However, an approach to certifying autonomous systems that relies on reversionary modes limits their potential to improve safety. Placing a human pilot in a situation where they are suddenly tasked with flying an airplane in a failed situation, often without sufficient situational awareness, is overly demanding. This, coupled with advancing technology that may not align with a deterministic certification paradigm, creates an opportunity for new approaches to certifying autonomous and highly automated aircraft systems. Unsettled Topics in the General Aviation Autonomy Landscape discusses how these new approaches must account for the multifaceted aviation approach to risk management which has interlocking requirements for airworthiness and operations (including training and airspace integration). If implemented properly, autonomy can take GA safety to the next level while simultaneously increasing the number and variety of aircraft and transportation options they provide. Click here to access the full SAE EDGETM Research Report portfolio.
Dietrich, Anna Mracek
Australia has embarked on an extraordinary reform to design, develop and implement a new and contemporary Defence Aviation Safety Framework. The program seeks to establish a single Defence Aviation Safety Authority (DASA) and issue a comprehensive and integrated suite of Defence Aviation Safety Regulation (DASR) for initial and continuing airworthiness, flight operations, air navigation, aerodromes (inclusive of ship-borne heliports) and safety management systems. While reforms of this scale can often be triggered by reviews into major aircraft accidents, such as The Nimrod Review by Charles Haddon-Cave QC in October 2009, Australia initiated the reform when new aircraft fleets were being introduced and at a time of arguably high-levels of aviation safety. The purpose of this paper is therefore to explain the compelling reason for change; providing a twenty-five-year retrospective analysis of Australia’s previous Defence aviation safety framework to give a rich picture of the difficulties faced by increased commercialization from the late 1990s, globalization in the 2000s, and the recent emergence of strict work, health and safety legislation in Australia.
Hood, JamesMarzocca, PierSinha, Arvind
As imbedded as it is in technology, the history of flight is also chock full of people stories. The history of the helicopter, one of the most versatile flying machines ever designed, abounds in such stories. This text looks at the development of Intercity Airlines Company's SG Mark VI by a unique team based for a time in Montreal, Quebec. Bernard W. Sznycer and Selma G. Gottlieb conceived one of the most advanced and innovative helicopter of its day. Designed to minimize vibrations and facilitate production, the SG Mark VI first flew in July 1947. Canada's Department of Transport awarded a Certificate of Airworthiness to a second prototype, in April 1951. The SG Mark VI was the first helicopter designed within the British Commonwealth of Nations to be so honored. Sadly, by then, American helicopters all but dominated the civilian and military markets. The SG Mark VI was abandoned during the winter of 1953-54 and both Sznycer and Gottlieb returned to the United States.
Fortier, Renald
Under the Rotorcraft Structural Integrity Program (RSIP) Pilot Demonstration effort, the requirements defined in MILSTD-3063 were applied to a Future Vertical Lift (FVL) representative, model performance specification objective aircraft to demonstrate a standardized RSIP process. This paper covers application of the MIL-STD-3063 approach on SB>1 DEFIANTTM airframe structural components and presents the evolution of the resulting RSIP Master Plan. Elements of the resulting Master Plan are discussed in detail. The Master Plan is the basis for collaborative establishment of structural integrity with an efficient and effective airworthiness substantiation footprint. The discussion includes case studies of the application of logic flow to requirements in MIL-STD-3063 for the determination of specific, relevant action items to airframe structural demonstration components. Execution of this pilot effort led to lessons learned and highlighted feedback to inform the ongoing development of the MIL-STD-3063 process, through ongoing collaboration between the SB>1 DEFIANTTM team and the U.S. Army.
Chiu, LisaKrastel, MatthiasLorthridge, DerrellMcCarthy, Dennis
The certification process of the Boeing 787, starting in 2005, marked a watershed for airworthiness regulation. The “Dreamliner,” the first true “flying data center,” could no longer be certified for airworthiness ignoring “sabotage,” like the classic safety regulation for commercial passenger aircraft. Its extensive application of data networks, including enhanced external digital communication, forced the Federal Aviation Administration (FAA), for the first time, to set “Special Conditions” for cybersecurity. In the 15 years that ensued, airworthiness regulation followed suit, and all key rule-, regulation-, and standard-making organizations weighed in to establish a new airworthiness cybersecurity superset of legislation, regulation, and standardization. The resulting International Civil Aviation Organization (ICAO) resolutions, US and European Union (EU) legislations, FAA and European Aviation Safety Agency (EASA) regulations, and the DO-326/ED-202 set of standards are already the de-facto, and soon becoming the official, standards for legislation, regulation, and best practices, with the FAA already mandating it to a constantly growing extent for a few years now—and EASA adopting the set in its entirety in July 2020. This emerging superset of documents is now carefully studied by all relevant actors—including industry, regulators, and academia—as the aviation ecosystem moves forward with DO-326/ED-202 set training, gap analysis, and even with certification itself. This report suggests a deeper analysis of these sets of regulatory documents and their effects on the aviation sector as they gradually become the law of the land, starting with their expected effects on the aviation ecosystem, the issues they pose to supply chains, and the challenges they present to the airworthiness certification process itself. Then, this report examines the major DO-326/ED-202 set gaps, inherent dilemmas, and methodological uncertainties. For each such unsettled domain, six aspects are reviewed. Finally, practical solution-seeking processes are proposed, and some specific potential frameworks and solutions are pointed out whenever applicable. It is the intention of this report that these insights and observations would assist regulators, applicants, and standard makers through, at least, the 2020s with accommodating this new regulation and start adjusting it to emerging realities. NOTE: SAE EDGE™ Research Reports are intended to identify and illuminate key issues in emerging, but still unsettled, technologies of interest to the mobility industry. The goal of SAE EDGE™ Research Reports is to stimulate discussion and work in the hope of promoting and speeding resolution of identified issues. SAE EDGE™ Research Reports are not intended to resolve the challenges they identify or close any topic to further scrutiny. Click here to access The Mobility Frontier: Cybersecurity on the Air & Ground Click here to access the full SAE EDGETM Research Report portfolio.
David, Aharon
Inspecting an aircraft after a known or suspected lightning strike can be a tedious and subjective task. While aircraft technical manuals do provide conditional inspections following a lightning strike, these inspections tend to be broad in their approach and based solely on the presence of visual damage. This paper discusses the simple technique of tracing the lightning path through the aircraft by the use of an analog magnetometer to identify ferromagnetic parts that have been magnetized by the substantial electrical current of a lightning strike. While this technique is not novel, it is not often published as an inspection technique. Knowing the approximate path of the lightning can assist aircrews and maintainers in the identification of suspect parts that may require further inspection, repair and/or replacement thereby increasing safety and ensuring continued airworthiness of the aircraft.
Massa, Travis
As the U.S. Army endeavors to maintain overmatch capability in the global arena, Future Vertical Lift has become a high priority. In a climate that demands a more efficient and affordable acquisition process, it is imperative that structural integrity requirements are maintained as a priority to ensure initial quality, supportability, and maintainability considerations. Therefore, it is paramount that a standard practice be utilized so that structural integrity requirements are clearly understood by the Product Office, the Airworthiness Authority, and the Original Equipment Manufacturer(s). This paper highlights how the MIL-STD-3063 U.S. Army Standard Practice for Rotorcraft Structural Integrity Programs can meet these demands by laying out interrelated functional tasks in a concise manner to allow for decision makers to make sound choices with regards to structural integrity for any new developmental aircraft. The paper also details how the standard practice is being utilized to assist and guide Future Vertical Lift efforts.
Kiser, Michael
As autonomous-drone and air-taxi concepts debut, legal hurdles will need to be cleared before the skies are automated. Autonomous vehicle technology literally has nowhere to go but up. At CES '19, more than 170 exhibitors showed aerial drones of various shapes and sizes. Potential use cases for these devices appear to be limitless, but technical, legal and regulatory hurdles must first be overcome. Drones are categorized by vehicle weight. The small devices weighing between 0.55 and 55 pounds (.25 kg to 25 kg) are known as Unmanned Aircraft Systems (UAS) and are lightly regulated. Drones exceeding 55 lb are regulated as traditional aircraft. Operators must obtain proper registration, licenses and certification for airworthiness.
Dukarski, Jennifer
Oxygen system integration and performance precautions are in particularly dependent on applicable sections of airworthiness requirements per FAR/JAR 25. In this document information will be provided on common principles and good practices regarding design criteria, installation, manufacturing, safety aspects and system handling during maintenance and inspection.
A-10 Aircraft Oxygen Equipment Committee
Over the past several years, a focus on and vision for data science in operational aviation data sets has emerged from the United States Armys Aviation Engineering Directorate (AED) team that has traditionally focused on vibration diagnostics and HUMS applications. Recently formed into a separate team under the Aerodynamics and Simulation Branch, this team has pursued the organizational, technological and intellectual challenges required to apply data science to aviation data, and to field data science products to systems under airworthiness governance. This paper provides an update on several of the specific areas of accomplishment and direction, with further detailed information referenced.
Wilson, AndrewWade, Daniel
Limited to the commercial aerospace industry where a request is made for a PO to have Direct Delivery Authorization (DDA), which includes an Appropriate Arrangement (AA) between the PO and the Design Organization (DO). In this process the DO is responsible for ensuring the continuous updating of design and airworthiness data to the PO, whilst the PO is responsible for assurance that the manufactured article conforms to approved design and airworthiness data. The PO is responsible to provide airworthiness release documentation.
G-14 Americas Aerospace Quality Standards Committee (AAQSC)
This paper provides insight into the methods used by U.S. Army Aviation Engineering Directorate personnel to assess airworthiness impacts due to changes in loads, usage, or strength, and resulting effects on calculated safe-life retirement times. Statistical analysis of system reliability for overflight of the safe-life time for components with assumed failure distributions forms the mathematical basis for the method. Topics include failure rate, baseline failure rate, percent change in system level risk, immeasurable risk, and mathematical relationships between each. Results include figures to aid in visualization and tables to enable the reader to check an implementation of the method for specific examples. The paper presents the results of analysis used to derive Weibull slope parameters based on recently developed fatigue reliability methods and available mission loads spectra. Finally, the paper presents a new method to establish life factors required to convert retirement intervals with a delta failure rate (for an airworthiness impact) into retirement intervals with immeasurable risk. Modified life factors address special cases of incompatible confidence and analysis uncertainty.
E., RobertRogers, Martin
This SAE Aerospace Standard (AS) specifies the testing methods to be used to substantiate performance of air cargo containers, pallets and nets (Unit Load Devices) for airworthiness approval in accordance with NAS 3610 or AS36100.
AGE-2 Air Cargo
The Future Airborne Capability Environment (FACETM) Technical Standard has set the stage for avionics software reuse by establishing a computing environment for the deployment of portable software components. This reduces the rework necessary to integrate an avionics software component into multiple aviation platforms with varying operating environments. Since the evaluation and demonstration of airworthiness of software components and the systems they comprise can add significant cost and schedule impact, areas most affected by the portability of the software need to be considered in order to maximize the benefits of reuse. Existing guidance for the acquisition of airworthy software often does not specifically address the reuse of components across multiple platforms, although work is being done in this area. Within United States (U.S.) Army Aviation, airworthiness evaluators concerned with the qualification of software conceived a Reusable Verification Component (RVC) that would be portable alongside the reusable software component. This RVC could ensure proper integration and correct functionality of the component for future systems. Existing developmental processes could be leveraged when using the RVC to verify the software implementation, resulting in efficient regression testing over the software lifecycle. The U.S. Army's Joint Common Architecture Demonstration (JCA Demo) project procured a FACE software component and an RVC from two vendors that were then integrated into multiple undisclosed operating environments. This paper captures the effort, results, conclusions, and recommendations for an RVC as an outcome of the experiment.
Wigginton, ScottGlenn, H.
In recent year, with the booming of Chinese economy and domestic civil air transportation market, China's aircraft manufacturers have been trying to develop their own commercial aircraft and changing from the subcontracting-manufacturer to aircraft developer, which turned to be a very hard task. One of the main challenges in front of China's aircraft manufacturers and airborne equipment suppliers is how to apply the airworthiness standards, such as ARP4754A, ARP4761, DO-178B(C) and DO-254, etc, into their engineering practice. Chinese companies are struggling in improving their capabilities to satisfy certification requirements and are making some remarkable progress these years. The paper first introduces the current status of Chinese aviation industry, and then the challenges to China's airborne equipment suppliers are analyzed. Based on these, the customization considerations of airworthiness standards and ARP4754 Practice in Chinese context are discussed.
Lirong, TianMing, Mu
Avionics Reference Embedded System (ARES) is a Government owned reconfigurable avionics software integration environment developed by the United States (U.S.) Army's Aviation and Missile Research, Development, and Engineering Center (AMRDEC) Software Engineering Directorate (SED). ARES was developed in support of multiple Aviation Development Directorate (ADD) Science and Technology (S&T) programs including Modular Integrated Survivability (MIS), Route Optimization for Survivability Against Sensors (ROSAS), Architecture Centric Virtual Integration Process (ACVIP), Joint Common Architecture (JCA), and Joint Multi-Role Technology Demonstrator (JMR TD). The creation and evolution of ARES was born out of the need to demonstrate an innovative software integration approach by exercising integration of 3rd party-developed software capabilities on multiple operating environments. Development of ARES utilized a Model Based Engineering (MBE) approach to implement a rapid capability integration strategy incorporating Systems Modeling Language (SysML) models incorporating Unified Modeling Language (UML), Systems Modeling Language (SysML), and Architecture Analysis & Design Language (AADL); optimization of airworthiness resources through automatic artifact generation and asset reuse; and alignment of DO-178C, DO-331, AC 20-148, and the Future Airborne Capability Environment (FACE) Technical Standard for application to Aviation Engineering Directorate's (AED's) AR 70-62 airworthiness qualification process.
Boyett, DavidCarter, H. GlennDenny, AshleyEdwards, AnthonyKellow, ChrisPittman, JenniferYork, Jason
The current avionics integration approach is becoming unaffordable partly due to the schedule and cost associated with integrating an avionics system into each configuration of each platform using its native interface. The United States (U.S.) Army's Aviation and Missile Research, Development, and Engineering Center (AMRDEC) Director for Aviation Development tasked the Modular Integrated Survivability (MIS) team to work with the U.S. Army Aviation Engineering Directorate (AED), the Army's airworthiness authority, to explore innovative integration approaches to streamline the integration process while still satisfying airworthiness certification requirements. AED has been engaged since the inception of the MIS Science and Technology (S&T) program. The MIS team, along with AED, has focused on developing the concept of using capability interfaces to communicate with similar avionics systems. The capability interfaces are built by abstracting the native interfaces allowing for a single integration into the platform for an entire suite of avionics systems. To build upon the capability interface approach, the AMRDEC MIS team has aligned its approach with the Future Airborne Capability Environment (FACE™) Technical Standard to enable portability and reuse of the capability interfaces across platforms. The paper discusses the time and cost challenges of the current avionics integration approach. It explores the MIS integration approach of developing and utilizing capability interfaces to integrate entire avionics system suites. The paper also discusses how incorporating the FACE Reference Architecture into the approach promotes software portability and reuse to reduce integration effort. The paper concludes by discussing the synergy realized by combining the MIS capability interface approach with the software portability enabled by the FACE Technical Standard.
Boyett, DavidYork, JasonEdwards, AnthonyDennis, ScottCarter, H.
Items per page:
1 – 50 of 134