Browse Topic: Certification
Aircraft verification and certification entail a variety of testing tasks and require coordination among numerous stakeholders across different disciplines to ensure alignment on requirements. Historically, certification strategies have relied on both physical testing and high-fidelity simulation. The integration of these complementary approaches is essential to address their respective blind spots and to support credible certification evidence. A key challenge lies in the rigorous correlation of simulation models with physical test data. Flutter verification, for instance, is a critical component in defining the aircraft’s flight envelope and plays a foundational role in certifying safe operational boundaries. In this work, the process of freedom from flutter verification is demonstrated. This work introduces a novel approach to combining simulation and test data with the aim to accelerate and streamline the verification process leading to more efficient and cost-effective aircraft development. In addition, it is shown how the flutter verification process can be deployed using a simulation process and data management (SPDM) tool from which tasks are assigned and results are collected allowing transparency about the status of the workflow and providing stakeholders access to the data they need when they need it. The workflow is demonstrated using ground vibration test measurement performed on a full-scale F16 aircraft. Throughout the process, simulation data, test results, requirements, and supporting documentation are systematically managed within the SPDM framework. This enables effective cross domain collaboration between simulation and test engineers while also maintaining a single source of truth for proof of compliance and progressively building a robust digital thread throughout the development lifecycle.
Advanced air mobility (AAM) seeks to develop a large-scale transportation system to revolutionize how people live and work, with electric vertical take-off and landing (eVTOL) aircraft serving a central role due to reduced emissions and noise impact. An important aspect for eVTOL aircraft certification is safe urban operations, which require understanding of the response due to aerodynamic disturbances. Experimental data are required to support eVTOL aircraft development with respect to flight dynamics and controllability, as well as design specification development. While flight testing of the full-sized air vehicle will be necessary as part of the certification process, subscale testing offers many advantages with respect to cost and flexibility, in addition to examining operational conditions that one would be reluctant to test in flight at full scale such as emergency conditions. These advantages only may be seen if the underlying scaling principles of flight dynamics / control, aerodynamic interactions, and propulsion-airframe integration are understood. This paper describes initial work towards development of a general subscale testing methodology for eVTOL aircraft flight dynamics and disturbance response characteristics including limited degree of freedom (DOF) and free flight testing. An overview of the initial development work is provided, including discussion of scaling relationships, subscale air vehicle model development, and testing activities focusing on flying qualities and stability / control characteristics.
This paper presents an integrated simulation workflow for aircraft seat development that combines (i) structural dynamics and certification load cases, (ii) occupant comfort and living-space assessment using finite-element digital humans, and (iii) airbag folding, deployment, and calibration using a coupled gas-dynamics solver suited to early-time transients. The workflow is built around a single manufacturing-aware, as-built seat model that is reused across comfort, certification, and restraint-system studies, allowing design iterations to move upstream before design freeze. Each stage is paired with validation or industrial case examples, and the airbag-calibration process is accelerated through reduced-order modeling (ROM) of parameter identification. The result is a practical virtual-seat-development methodology that is sufficiently predictive to de-risk physical testing while remaining fast enough for concept iteration and late-stage compliance support.
When surveying the current landscape of Deterministic Ethernet avionics solutions in the aerospace industry, the three main technologies in the market are ARINC 664 part 7 rate-constrained Ethernet (commonly known by its trademark name "AFDX®"), TTEthernet (which combines ARINC 664 part 7 with Best-Effort Ethernet, while adding a new class of synchronous determinism defined in SAE AS6802 [Time-Triggered Ethernet]), and IEEE 802.1 Time-Sensitive Networking (TSN). No single deterministic Ethernet technology optimally satisfies certification, MOSA, and lifecycle goals across all avionics domains. Instead, successful digital backbones require intentional partitioning of responsibilities across technologies. This paper will seek to identify a number of those considerations and provide guidance on which technologies offer the best fit. After first opening with an explanation of the market forces driving the trends towards these technologies, this paper will delve into a short outline of each of these Ethernet standards. Following that, this paper will compare a variety of characteristics of each of the above Ethernet technologies pertaining to certifiability, MOSA conformance for DoD use cases, and supply chain considerations. Finally, the paper will synthesize those comparisons into a number of recommendations regarding the most appropriate uses for each Ethernet technology.
Rolling-element bearings in rotorcraft dynamic systems are critical components susceptible to rolling contact fatigue (RCF), a dominant degradation mechanism manifesting through subsurface-initiated spalling, surface micropitting, and fatigue fractures. Robust inspection strategies compliant with EASA and FAA requirements are therefore essential. Traditional methods are often invasive, requiring disassembly, and are susceptible to human-factor errors. Smart Duplex introduces a design-for-monitoring architecture integrating in-situ videoscopic and coherence scanning interferometry (CSI) for high-resolution 3D surface mapping, including under partial grease coverage. This paper details a repeatability and reproducibility (R&R) framework ensuring metric consistency; a maintainability assessment projecting significant man-hour reductions and high availability; certification rationale emphasizing airworthiness improvements via enhanced detectability, workload reduction, and digitized inspection records; and an airworthiness mapping supporting threat assessments, Airworthiness Limitations Section (ALS) entries, and usage-based maintenance credits. By embedding sensing capability and digitizing inspection records, Smart Duplex minimizes downtime, mitigates human-factor errors, and facilitates predictive maintenance, optimizing cost, enhancing performance, and ultimately improving safety.
The aerospace industry is undergoing a profound transformation driven by emerging aviation technologies, including Advanced Air Mobility (AAM), electric vertical takeoff and landing (eVTOL) aircraft, and highly automated flight control systems. These complex systems often feature tightly coupled flight controls and power plants where traditional methods of compliance — relying heavily on physical ground and flight testing — are becoming increasingly impractical due to the vast number of potential interaction cases. To address this challenge, the SAE G-35 Modeling, Simulation, and Training for Emerging Aviation Technologies and Concepts Committee was formed to develop industry consensus standards. This presentation discusses the landmark release of SAE ARP7094, "Recommended Practice for Using Modeling and Simulation for Certification of Aircraft, Products, and Systems" and its role in establishing a standardized, simulation-based path to certification. The SAE G35C group is responsible for developing standards and procedures for using modeling and simulation as a method of compliance for the certification of AAM aircraft similar to the RCbS project conducted in collaboration between EASA, academia and industry in Europe.
Patching vulnerabilities in safety-critical domains such as automotive and aerospace is costly and complex. A small code modification can trigger a complete rebuild, producing a binary with widespread changes. This inflates patch size, complicates regression testing, and makes over-the-air (OTA) updates inefficient, as traditional binary patches often replace large portions of the executable. We present a binary rewriting–based experiment that shows the feasibility of a patch that updates only the affected bytes by computing the impact of a code change at the binary level. This produces minimal, localized patches rather than regenerated executables. The preliminary experiment shows that a single source change, which leads to thousands of modified bytes after recompilation, can be captured with only a few bytes using our method. For automotive and aerospace systems, this technique reduces patch size, conserves bandwidth, and minimizes disruption to certified software, offering a promising direction for efficient and reliable vulnerability remediation.
Military and aerospace applications have become increasingly complex real-time systems. Multi-core SoCs improve performance but create new challenges in maintaining and verifying deterministic behavior. Connected systems require exceptional security to protect code from external cyberattacks. Evolving functional safety and reliability standards that keep raising the bar mean developers need to begin comprehensive testing sooner if they are going to meet tighter design schedules. Finally, certifying these complex systems has become even more difficult. To help OEMs meet these challenges, the RISC-V architecture has been designed with unique capabilities that support reliability and security in the development of safety-critical applications. With its open instruction set architecture, modularity, and extensibility, RISC-V accelerates the design of functionally safe systems while reducing the complexity, cost, and risk associated with certification to standards like DO-178C and ISO 26262.
Treat foundational AV safety like seatbelts - make it non-proprietary and universal. An open safety stack, shared scenarios, benchmarks, and core validation tools can speed certification, reduce duplicated V&V and build public trust while preserving vendor differentiation. The bottleneck isn't compute - it's verification. Autonomous features are shipping in more vehicles and markets, but the gating factor is no longer raw compute. It's whether developers and regulators can verify systems against requirements and validate them against real-world operating design domains (ODDs) with confidence and repeatability. Today, many safety-critical components, from scenario libraries to pass/fail criteria, live in proprietary silos. That fragmentation slows regression testing, complicates regulator audits across regions, and duplicates effort across the industry. The result is an expensive, bespoke path to certification for every program and geography.
How engineers can ensure safety, reliability and quality in aerospace systems. Courbevoie, Île-de-France In an industry where failure is not an option and precision is paramount, aerospace manufacturers and suppliers are constantly seeking components and system solutions that deliver trusted reliability, performance, and compliance. Industry standards are a key part of achieving these high expectations, bringing together global leaders in the mobility industries to create defined, repeatable methods and consistent processes. One of these aerospace standards is AS1895 developed by SAE International - a critical standard due to the need for durable components that can withstand extreme conditions and offer high performance: high-temperature resistance, pressure sealing, and long service life with a cost-effective installation method. Leading aerospace companies such as Eaton and Honeywell have been manufacturing components that meet this standard for a long period of time.
Researchers from the National University of Singapore (NUS) have developed a novel triple-junction perovskite/Si tandem solar cell that can achieve a certified world-record power conversion efficiency of 27.1 percent across a solar energy absorption area of 1 sq cm, representing the best-performing triple-junction perovskite/Si tandem solar cell thus far. To achieve this, the team engineered a new cyanate-integrated perovskite solar cell that is stable and energy efficient.
Celebrating its 35th year, the National Aerospace Defense Contractors Accreditation Program (Nadcap) continues to advance quality assurance and regulatory compliance for aviation, defense, and space OEMs and suppliers. This article summarizes how Nadcap accreditation works, its benefits for manufacturers, and its role in expanding additive manufacturing through industry-wide consensus. The Nadcap program was first established in 1990 by a small group of aerospace and defense OEMs. Their goal was to create an accreditation initiative that provides a common approach to auditing the manufacturing and production processes used by companies supplying parts, components, structures, and services to major aerospace and defense OEMs. This foundation set the stage for Nadcap's continued focus on quality assurance and regulatory compliance in the industry.
Wind Tunnels are complex and cost-intensive test facilities. Thus, increasing the test efficiency is an important aspect. At the same time, active aerodynamic elements gain importance for the efficiency of modern cars. For homologation, such active aero-components pose an extra level of test complexity as their control strategies, the relevant drive cycles and their aerodynamics in different positions must be considered for homologation-relevant data. Often, active components have to be manually adjusted between test runs, which is a time-consuming process because the vehicle is not integrated into the test automation. Even if so, designing a test sequence stepping through the individual settings for each component of a vehicle is a tedious task in the test session. Thus, a sophisticated integration of the wind tunnel control system with a test management system, supporting the full homologation process is one aspect of a solution. The other is the integration of the vehicle’s active aero components as controllable assets into the control system. We present an architecture of a comprehensive set of software modules, which enhance the capabilities of an automation system making highly automated homologation tests of active components possible with minimal manual actions during the test. This includes a fully traceable test process from the vehicle components to the results of each step within an automatically generated test run, during which the active components’ parameters are varied in such way, that all test requirements are satisfied. Finally, these results are transferred back to the test requirements, from which in combination with control characteristics and market-specific drive cycles the relevant homologation data of the active aero components can be obtained.
In this paper, we describe an innovative V&V approach using the SCADE product, enabling significant reduction of effort while preserving compliance with DO-178C/DO-331. This new approach relies on a unique capability: automatic generation of Low-Level Tests. Details about savings will be provided to show how we can reduce costs, speed up certifications, and bring products to the market faster. We will conclude by summarizing the actual benefits and describing ongoing work to bring other savings in the future.
This paper outlines observations from an FAA-sponsored research project that examined aviation Fly-By-Wire (FBW) accidents. The goal was to identify risk areas that will help guide a focus for FAA certification testing. Part of this study specifically focused on current powered-lift tiltrotors, identifying six general categories of causal factors for accidents, which will be discussed in detail regarding how they influenced flight control designs. The results of this survey, along with extrapolation to current designs, will be discussed and will illustrate why manufacturers are moving toward state-based flight control designs. In a state-based flight control scheme, the pilot does not have direct control over aircraft attitudes and motor tilt angles. Instead, the pilot requests a speed and or flight path with inceptor input, and the commanded attitudes and motor tilts are scheduled by the flight control computer. Additionally, recent lessons learned from electric Vertical Takeoff and Landing (eVTOL) aircraft accidents will be discussed, along with a comparison of powered-lift causal factors to accidents in the transport category FBW fixed-wing aircraft. From this analysis, broad observations will be offered about the trend of how accident-causal factors may evolve with greater maturity in aircraft design. This accident survey will be detailed further as part of an upcoming FAA Research Report.
Ever-increasing modeling and simulation capabilities and the desire to use simulations in support of system qualification, regulatory compliance, and other critical decision-making roles, raises the bar on the need for rigorous V&V of all aspects of the models used to create the simulation data. US Department of Defense Directives and Instructions, and emerging regulatory and industry standards on Modeling and Simulation in a Digital Engineering context require rigorous M&S Verification, Validation, and Accreditation (M&S VV&A). These specifications aim to create trusted and credible simulation data that can be used in critical decision-making roles on complex systems. Implementing a well-defined, structured, model-based and standards-based M&S VV&A Process early in the program lifecycle facilitates collaboration and documented buy-in on M&S VV&A for program with customers and/or regulatory agencies. This collaboration increases acceptance throughout the program and product lifecycles. This paper describes how Model-Based Systems Engineering tools and Digital Engineering ecosystems can support the M&S VV&A Process. The model-based construct facilitates creating metrics dashboards, leveraging model-based artifacts for improved communication of M&S VV&A status, quality, maturity, and completeness.
Full-scale static test (FSST) is a key test program for the certification of new helicopter airframe. The strength and deformation requirements in airframe certification are substantiated by full-scale tests of the airframe structures. It provides experimental evidence that the structure is able to support limit loads without detrimental permanent deformation and carry ultimate loads for at least three seconds. In design stage, the total number of flight and ground limit load conditions is around 500. In FSST, the number of test load cases should be remarkably reduced. However, the selected load scenarios should cover all of the critical design load scenarios. In this paper, test load generation procedures in FSST of a light utility helicopter is explained. The comparison of design load envelope and static test load envelopes are provided.
In the last years, new rotorcraft configurations have increased the attention among industries, through which the tiltrotor one due to its capability of combining both rotorcraft and aircraft advantages. However, there are situations where the vertical take-off mode could be enhanced in hard environmental and flight conditions. Therefore, to address this challenge, this work aims to develop a methodology to characterize a roll take-off model for a general tiltrotor configuration in such situations. By combining the integration of the equation of motion and geometrical assumptions, the runway distance is determined for an acceptable range of nacelle tilting angles. The process is developed by meeting the requirements defined by the regulations, combining the aircraft certification standards (CS23 and CS25) with the available tiltrotor certification basis from the FAA project #TC3419RC-R. Following the Nominal application, a sensitivity analysis is carried out, which studies the main effects on the results by varying one variable at a time in terms of weight, wing-loading, and disk-loading.
This paper demonstrates the training, optimisation, and predictive capabilities of Machine Learning (ML) for helicopter-ship certification. The work focuses on the development of a Linear Discriminant Analysis (LDA) model, trained specifically on pilot control activity data recorded during the hover phase of a recovery to a ship, to determine an operational boundary driven by pilot workload. The certification process currently relies heavily on embarked trials and the subjective workload assessment of test pilots. Modelling and Simulation (M&S), however, offers a potentially more efficient approach to addressing the high costs, resource-intensive nature, and inherent dangers associated with traditional clearance methods. By providing a relatively large amount of data for analysis, this approach creates an opportunity to bridge the gap between subjective and objective measures, enabling the prediction of workload limitations. An LDA model was trained using cross-validation on pilot control activity data and optimised through the inclusion of a penalty factor to reduce overfitting. Throughout the training process, the model demonstrated good performance, effectively distinguishing between high and low workload conditions based on pilot control activity data. When tested on unseen data, the model accurately predicted the Ship-Helicopter Operating Limit (SHOL) boundary for most cases. These results support the application of ML in the helicopter-ship certification process and demonstrate the model's ability to identify correlations within high-dimensional datasets, offering a more data-driven and objective approach to determining workload and clearance boundaries.
Aircraft Certification is a mature and complex bureaucracy that has successfully ensured a very high degree of safety of aircraft design, construction, operation and maintenance. Outside of a very few doing the work, there is a general lack of knowledge of certification details. For novel technologies such as electric power, and innovative configurations such as multi-rotors, the rules are far less mature and still emerging and so also poorly understood. Within the Advanced Air Mobility (AAM) initiative, many new aircraft developments are underway using novel configurations, and the public announcements of regulatory progress toward FAA or EASA Type Certification capitalize on this ignorance by being vague or even misleading. Honeywell conceived the Regulatory Readiness Level (RRL) indicator as an objective measure of certification status to serve the AAM industry and ecosystem, with applicability across aviation. The released RRL Version 1 now enables credible, objective assessment of new aircraft progress toward FAA Type Certification, and Operational Approval for Part 135 operations, to allow consistent apples-to-apples comparisons with other aircraft in development. An emerging complementary version of the rubric for EASA Type Certification is ready for publication to enable RRL determination against the European Union criteria. Future releases will consider other Nation's regulatory authorities, supplemental types certifications (STCs), and risk-based airworthiness assessments such as the Specific Operations Risk Assessments (SORA).
There is an increasing effort to reduce noise pollution across different industries worldwide. From a transportation standpoint, pass-by regulations aim to achieve this and have been implementing increasingly stricter emissions limits. Testing according to these standards is a requirement for homologation, but does little to help manufacturers understand why their vehicles may be failing to meet limits. Using a developed methodology such as Pass-by Source Path Contribution (SPC, also known as TPA) allows for identification of dominant contributors to the pass-by receivers along with corresponding acoustic source strengths. This approach is commonly used for passenger vehicles, but can be impractical for off-highway applications, where vehicles are often too large for most pass-by-suitable chassis dynamometers. A hybrid approach is thereby needed, where the same techniques and instrumentation used in the indoor test are applied to scenarios in an outdoor environment. This allows for determination of all the useful contribution results in a more representative environment and without limitations associated with indoor facilities. This paper demonstrates the application of this method on an off-highway vehicle for several scenarios.
Airworthiness certification of aircraft requires an Airworthiness Security Process (AWSP) to ensure safe operation under potential unauthorized interactions, particularly in the context of growing cyber threats. Regulatory authorities mandate the consideration of Intentional Unauthorized Electronic Interactions (IUEI) in the development of aircraft, airborne software, and equipment. As the industry increasingly adopts Model-Based Systems Engineering (MBSE) to accelerate development, we aim to enhance this effort by focusing on security scope definitions – a critical step within the AWSP for security risk assessment that establishes the boundaries and extent of security measures. However, our findings indicate that, despite the increasing use of model-based tools in development, these security scope definitions often remain either document-based or, when modeled, are presented at overly abstract levels, both of which limit their utility. Furthermore, we found that these definitions frequently lack alignment with airworthiness security regulations. To address these two distinct gaps, this paper presents a model-based approach for detailed security scope definitions using the Systems Modelling Language (SysML). Our approach aligns with airworthiness security regulations ED-202A / DO-326A and ED-203A / DO-356A and incorporates a SysML profile based on the CORAS language for accurate modeling of security scopes. This facilitates a model-based security risk assessment by creating unambiguously system models that represent assets through model elements, document entry points to the assets and determine their environment. This SysML-based approach supports certification related activities by ensuring that security scope definitions are comprehensive and aligned with airworthiness regulations, directly addressing the identified gaps. The approach's applicability and effectiveness are demonstrated through an illustrative example in the domain of aircraft cabin system development. Moreover, the approach provides valuable inputs that assist operators in deriving guidance for the safe operation and maintenance of the aircraft, complementing existing methods and practices.
Demonstrating deadline adherence for real-time tasks is a common requirement in all safety norms. Timing verification has to address two levels: the code level (worst-case execution time) and the scheduling level (worst-case response time). Determining which methodology is suited best depends on the characteristics of the target processor. All contemporary microprocessors try to maximize the instruction-level parallelism by sophisticated performance-enhancing features that make the execution time of a particular instruction dependent on the execution history. On multi-core systems, the execution time additionally is influenced by interference effects on shared resources caused by concurrent activities on the different cores, which are not controlled by the scheduling algorithm. In the avionics domain, the new FAA AC 20-193 / EASA AMC 20-193 guidance documents formalize predictability aspects of multi-core systems and derive adequate measures for timing verification. Timing verification is a long standing and still very challenging topic. Established techniques include response time analysis, worst-case execution time analysis and real-time tracing. The goal of this article is to summarize the aspects relevant for timing verification, and give an overview of the available techniques. We also explicitly address multi-core considerations, focusing on the latest certification authorities’ publications from the avionics domain.
Performing highly representative tests of aircraft equipment is a critical feature for gaining utmost confidence on their ability to perform flawlessly in flight under the entire spectrum of operating conditions. This can also contribute to accelerate the certification process of a new equipment. A research project (E-LISA) was performed in recent years, as part of the European funded Clean Sky 2 framework, with the objective of building an innovative facility for testing an electrically actuated landing gear and brake for a small air transport. The project eventually led to the development and construction of an Iron Bird able to reproduce in a realistic and comprehensive way a full variety of landing test cases consistent with certification specifications and landing histories available in the repository of the airframer. The Iron Bird that was eventually developed is a multi-functional intelligent and easy reconfigurable facility integrating hardware and software allowing to perform a full verification and validation of an electrically actuated landing gear and brake over the representative operating conditions, and under normal, degraded and faulty conditions.
In the domain of aircraft certification, Development Assurance is what some would call a useful tool to gain confidence in the development of complex systems, and what others would call a necessary evil. But what does it actually do? Why is it necessary for certification of modern aircraft? What, epistemologically, does it bring to the table? This paper aims to show how Development Assurance (DA) activities, at all levels from aircraft to item, close the epistemological holes created when complex systems are chosen for implementation. It will map the different sources and types of uncertainty encountered in system and aircraft verification and explain how each type is dealt with within a certification context, working from simple mechanical systems up to complex and highly integrated systems using software and airborne electronic hardware and beyond. It will show that Development Assurance, far from being an arbitrary set of activities, systematically brings personal and corporate expertise to bear to provide confidence that development errors have been sufficiently identified and mitigated or eliminated.
This Recommended Practice is intended to establish a procedure to certify the trailer towing driving skill levels of professional drivers. This certification can be used by the individual driver to qualify their skills when seeking employment or other professional activity. These certification levels may also be used by test facilities or other organizations when seeking test or professional drivers of various skills. This document provides directions for obtaining certification through Probitas Authentication®1 and associated trailer towing driving skill examination requirements. This document is a supplement to SAE J3300, providing information specific to the trailer towing driving skill certification and clarifying the application of the rules set forth in SAE J3300 to the trailer towing certification. While the references, definitions, rules, and guidelines presented in SAE J3300 Sections 1 through 5 apply to the trailer towing certification, they are not repeated in this document.
Items per page:
50
1 – 50 of 1603