Browse Topic: Aircraft certification

Items (167)
This document defines the technical guidelines for the safe integration of Proton Exchange Membrane (PEM) Fuel Cell Systems (FCS), fuel (considered to be liquid and compressed hydrogen storage types only), fuel storage, fuel distribution and appropriate electrical systems into the aircraft. Editorial Note: Today PEM systems and fuel storage represent the most mature FCS technology and currently forms the basis for this standard. Other types of fuel cell systems and fuels (including reforming technologies and electrolyzers), may be covered by a further update to this document.
AE-7F Hydrogen and Fuel Cells
This document and the EUROCAE equivalent, ED-107, provides detailed information, guidance, and methods in support of the Federal Aviation Administration (FAA) Advisory Circular (AC) 20-158 and to the European Union Aviation Safety Agency (EASA) AMC 20-158. AC 20-158 provides a means, but not the only means, for demonstrating compliance with Title 14 of the Code of Federal Regulations (14 CFR) 23.1308 (Amendment 57 and lower), 23.2520 (Amendment 64 and higher), 25.1317, 27.1317, 29.1317, and applicable FAA HIRF special conditions addressing HIRF Protection. AMC 20-158 is applicable to Certification Specifications CS 23.1308 (Amendment 4 and lower), 23.2520 (Amendment 5 and higher), 25.1317, 27.1317, and 29.1317. It should be noted that this document is neither mandatory nor regulatory in nature and does not constitute a regulation or legal interpretation of the regulation. Therefore, an applicant may elect to establish an alternative method of compliance that is acceptable to the certifying airworthiness authorities. The information in this guide represents a collection of the best engineering practices that have been used to certify aircraft HIRF protection. It provides: Practical design considerations HIRF compliance steps Aircraft level verification and testing guidance Detailed guidance for Level A system compliance and testing Detailed guidance for Level B and C system compliance and testing Guidance in the area of continued airworthiness This document provides guidelines for testing the aircraft and equipment for HIRF compliance, with the latter using RTCA DO-160/EUROCAE ED-14 Section 20. This document also contains guidance applicable to both new applications for aircraft certification and historic information applicable to continued compliance with existing aircraft certifications. When establishing continued compliance, it is necessary to review the basis on which the original certification was granted to determine the requirements that were in force at that time in all jurisdictions where the certification was granted.
AE-4 Electromagnetic Compatibility (EMC) Committee
Commercial and military aircraft increasingly rely on Integrated Vehicle Health Management (IVHM) as a critical enabler for predictive maintenance, operational efficiency, and mission availability. The evolution of IVHM data communication architecture- from legacy wire-based networks to more wireless based architecture involving onboard wireless sensor networks (WSN) and IP-based air to ground communication networks introduces multidomain cyber-physical attack surfaces that challenge both functional safety and continued airworthiness. DO-326A/ED-202A and DO-356A/ED-203A standards define aviation cybersecurity requirements within a safety-driven assurance context, and IEC 62443 standard offers a defense-in-depth, lifecycle-based control framework for industrial systems. A unified approach by mapping and harmonizing the complimentary aspects of these two standards has the potential to simplify and expedite the security assurance and certification process for the IVHM and other digital avionic systems. The proposed work is a unified, standard-aligned cybersecurity assurance framework for aircraft IVHM systems covering both airborne ground segments as a single integrated entity. The novel methodology evaluates risks by performing Fundamental Requirements (FR) analysis, mapping IEC 62443 to DO-326A/ED-202A requirements through qualitative risk assessment, protocol vulnerability analysis, and attack tree modelling on zone-conduits as per the Security Level (SL) requirements. The resulting risk treatment plan demonstrates a verifiable and auditable method to achieve security assurance and certification of aircraft IVHM system which is extendable to other digital avionic systems.
Samudrala, RamakrishnaRamamurthy, Prasanna
Modern avionics programs contend with escalating complexity driven by concurrent safety certification, cybersecurity compliance, and multi-standard regulatory demands. Traditional program management approaches treat risk management as a parallel support function rather than a central governance mechanism, resulting in reactive responses that fail to prevent cost and schedule erosion. This paper introduces the Risk-Driven Program Management Framework (RD-PMF), an eight-phase governance model that embeds quantitative risk assessment, standards-risk mapping across DO-178C, DO-326A, ARP4754A, and ARP4761A, real-time digital dashboards, and earned value management within core program decision-making. The framework integrates probabilistic schedule analysis using Monte Carlo simulation with continuous risk exposure monitoring to enable proactive, data-driven governance. RD-PMF is demonstrated through a representative avionics program scenario modelled on a flight control system development effort with a 24-month baseline schedule, $15 million budget, and 27 identified risks. Simulation parameters, informed by the authors’ professional experience in avionics program management and published industry benchmarks, illustrate framework applicability within industry-typical ranges. Five targeted risk mitigation strategies, with a combined investment of $1.27 million addressing certification review delays, requirements volatility, supplier delays, hardware-software integration, and cybersecurity threats, reduced aggregate risk exposure by 77 percent (64.7 to 15.1 schedule-weeks). The demonstration yields an 11 percent schedule performance index improvement (SPI: 0.88 to 0.98), a 6.5 percent cost performance index improvement (CPI: 0.92 to 0.98), schedule variance reduction from 8.0 to 1.2 weeks, and a 2.5-month acceleration in projected completion. Return on investment analysis shows 2.22x gross (1.22x net) on mitigation spending, with total quantified benefits of $2.82 million. These results illustrate a measurable shift from reactive program control to proactive, risk-informed governance suited to next-generation aerospace development programs.
Rahul, SaurabhBenikireddy, Raghunatha
Advanced air mobility (AAM) seeks to develop a large-scale transportation system to revolutionize how people live and work, with electric vertical take-off and landing (eVTOL) aircraft serving a central role due to reduced emissions and noise impact. An important aspect for eVTOL aircraft certification is safe urban operations, which require understanding of the response due to aerodynamic disturbances. Experimental data are required to support eVTOL aircraft development with respect to flight dynamics and controllability, as well as design specification development. While flight testing of the full-sized air vehicle will be necessary as part of the certification process, subscale testing offers many advantages with respect to cost and flexibility, in addition to examining operational conditions that one would be reluctant to test in flight at full scale such as emergency conditions. These advantages only may be seen if the underlying scaling principles of flight dynamics / control, aerodynamic interactions, and propulsion-airframe integration are understood. This paper describes initial work towards development of a general subscale testing methodology for eVTOL aircraft flight dynamics and disturbance response characteristics including limited degree of freedom (DOF) and free flight testing. An overview of the initial development work is provided, including discussion of scaling relationships, subscale air vehicle model development, and testing activities focusing on flying qualities and stability / control characteristics.
Keller, Jeffrey D.McKillip, Jr., Robert M.Horn, JosephLee, Soohyeon
The aerospace industry is undergoing a profound transformation driven by emerging aviation technologies, including Advanced Air Mobility (AAM), electric vertical takeoff and landing (eVTOL) aircraft, and highly automated flight control systems. These complex systems often feature tightly coupled flight controls and power plants where traditional methods of compliance — relying heavily on physical ground and flight testing — are becoming increasingly impractical due to the vast number of potential interaction cases. To address this challenge, the SAE G-35 Modeling, Simulation, and Training for Emerging Aviation Technologies and Concepts Committee was formed to develop industry consensus standards. This presentation discusses the landmark release of SAE ARP7094, "Recommended Practice for Using Modeling and Simulation for Certification of Aircraft, Products, and Systems" and its role in establishing a standardized, simulation-based path to certification. The SAE G35C group is responsible for developing standards and procedures for using modeling and simulation as a method of compliance for the certification of AAM aircraft similar to the RCbS project conducted in collaboration between EASA, academia and industry in Europe.
Goericke, JanYates, CraigvanHoudt, John
This SAE Aerospace Recommended Practice (ARP) defines lightning strike zones and provides guidelines for locating them on particular aircraft, together with examples. The zone definitions and location guidelines described herein are applicable to Parts 23, 25, 27, and 29 aircraft. The zone location guidelines and examples are representative of in-flight lightning exposures.
AE-2 Lightning Committee
This paper outlines observations from an FAA-sponsored research project that examined aviation Fly-By-Wire (FBW) accidents. The goal was to identify risk areas that will help guide a focus for FAA certification testing. Part of this study specifically focused on current powered-lift tiltrotors, identifying six general categories of causal factors for accidents, which will be discussed in detail regarding how they influenced flight control designs. The results of this survey, along with extrapolation to current designs, will be discussed and will illustrate why manufacturers are moving toward state-based flight control designs. In a state-based flight control scheme, the pilot does not have direct control over aircraft attitudes and motor tilt angles. Instead, the pilot requests a speed and or flight path with inceptor input, and the commanded attitudes and motor tilts are scheduled by the flight control computer. Additionally, recent lessons learned from electric Vertical Takeoff and Landing (eVTOL) aircraft accidents will be discussed, along with a comparison of powered-lift causal factors to accidents in the transport category FBW fixed-wing aircraft. From this analysis, broad observations will be offered about the trend of how accident-causal factors may evolve with greater maturity in aircraft design. This accident survey will be detailed further as part of an upcoming FAA Research Report.
Shubert, MartinSizoo, David
In the last years, new rotorcraft configurations have increased the attention among industries, through which the tiltrotor one due to its capability of combining both rotorcraft and aircraft advantages. However, there are situations where the vertical take-off mode could be enhanced in hard environmental and flight conditions. Therefore, to address this challenge, this work aims to develop a methodology to characterize a roll take-off model for a general tiltrotor configuration in such situations. By combining the integration of the equation of motion and geometrical assumptions, the runway distance is determined for an acceptable range of nacelle tilting angles. The process is developed by meeting the requirements defined by the regulations, combining the aircraft certification standards (CS23 and CS25) with the available tiltrotor certification basis from the FAA project #TC3419RC-R. Following the Nominal application, a sensitivity analysis is carried out, which studies the main effects on the results by varying one variable at a time in terms of weight, wing-loading, and disk-loading.
Passarelli D'Onofrio, Anna SofiaPecoraro, Matteo
Aircraft Certification is a mature and complex bureaucracy that has successfully ensured a very high degree of safety of aircraft design, construction, operation and maintenance. Outside of a very few doing the work, there is a general lack of knowledge of certification details. For novel technologies such as electric power, and innovative configurations such as multi-rotors, the rules are far less mature and still emerging and so also poorly understood. Within the Advanced Air Mobility (AAM) initiative, many new aircraft developments are underway using novel configurations, and the public announcements of regulatory progress toward FAA or EASA Type Certification capitalize on this ignorance by being vague or even misleading. Honeywell conceived the Regulatory Readiness Level (RRL) indicator as an objective measure of certification status to serve the AAM industry and ecosystem, with applicability across aviation. The released RRL Version 1 now enables credible, objective assessment of new aircraft progress toward FAA Type Certification, and Operational Approval for Part 135 operations, to allow consistent apples-to-apples comparisons with other aircraft in development. An emerging complementary version of the rubric for EASA Type Certification is ready for publication to enable RRL determination against the European Union criteria. Future releases will consider other Nation's regulatory authorities, supplemental types certifications (STCs), and risk-based airworthiness assessments such as the Specific Operations Risk Assessments (SORA).
Agrawal, PulkitNewman, Daniel
Airworthiness certification of aircraft requires an Airworthiness Security Process (AWSP) to ensure safe operation under potential unauthorized interactions, particularly in the context of growing cyber threats. Regulatory authorities mandate the consideration of Intentional Unauthorized Electronic Interactions (IUEI) in the development of aircraft, airborne software, and equipment. As the industry increasingly adopts Model-Based Systems Engineering (MBSE) to accelerate development, we aim to enhance this effort by focusing on security scope definitions – a critical step within the AWSP for security risk assessment that establishes the boundaries and extent of security measures. However, our findings indicate that, despite the increasing use of model-based tools in development, these security scope definitions often remain either document-based or, when modeled, are presented at overly abstract levels, both of which limit their utility. Furthermore, we found that these definitions frequently lack alignment with airworthiness security regulations. To address these two distinct gaps, this paper presents a model-based approach for detailed security scope definitions using the Systems Modelling Language (SysML). Our approach aligns with airworthiness security regulations ED-202A / DO-326A and ED-203A / DO-356A and incorporates a SysML profile based on the CORAS language for accurate modeling of security scopes. This facilitates a model-based security risk assessment by creating unambiguously system models that represent assets through model elements, document entry points to the assets and determine their environment. This SysML-based approach supports certification related activities by ensuring that security scope definitions are comprehensive and aligned with airworthiness regulations, directly addressing the identified gaps. The approach's applicability and effectiveness are demonstrated through an illustrative example in the domain of aircraft cabin system development. Moreover, the approach provides valuable inputs that assist operators in deriving guidance for the safe operation and maintenance of the aircraft, complementing existing methods and practices.
Hechelmann, AdrianMannchen, Thomas
In the domain of aircraft certification, Development Assurance is what some would call a useful tool to gain confidence in the development of complex systems, and what others would call a necessary evil. But what does it actually do? Why is it necessary for certification of modern aircraft? What, epistemologically, does it bring to the table? This paper aims to show how Development Assurance (DA) activities, at all levels from aircraft to item, close the epistemological holes created when complex systems are chosen for implementation. It will map the different sources and types of uncertainty encountered in system and aircraft verification and explain how each type is dealt with within a certification context, working from simple mechanical systems up to complex and highly integrated systems using software and airborne electronic hardware and beyond. It will show that Development Assurance, far from being an arbitrary set of activities, systematically brings personal and corporate expertise to bear to provide confidence that development errors have been sufficiently identified and mitigated or eliminated.
Laflin, Cory R.
This SAE Aerospace Recommended Practice (ARP) is intended to provide guidance on verifying the integrity of inflation pressure sealing systems of aircraft wheel/tire assemblies.
A-5A Wheels, Brakes and Skid Controls Committee
Headquartered in San Juan, Puerto Rico, Unusual Machines describes itself as a “classic American technology company born from garage tinkerers and hobbyists, focused on serving the emerging drone industry with unique and innovative products.” The company recently launched a new low-cost flight controller for drones, the Riot Brave F7, that achieved “Blue UAS” certification from the Department of Defense's (DoD) Defense Innovation Unit (DIU) in August. The Riot Brave F7 - just $58 - features a STMF722RET6 processor equipped with Bosch accelerometer and barometer, and has 16Mb of built in Blackbox Memory. While the company developed Riot Brave F7 primarily as a low cost flight controller option for FPV drones, there are broader possibilities for it, including military applications.
The scope of this ARP is as follows: Use of M&S for type certification of the Advanced Air Mobility (AAM) aircraft, product, or system. However, this does not preclude this ARP being used for certification of other aircraft types and associated products and systems. This ARP is not applicable to flight simulation training device (FSTD) qualifications or pilot certification. If a qualified FSTD is proposed for aircraft, product, or system certification, it must demonstrate sufficient M&S substantiation to meet the related requirement. Structural design and modeling are not addressed by this document. EMI/EMC certification is not addressed by this document.
G-35C Modeling Simulation for Aircraft Certification Committ
Aircraft Certification is a mature and complex bureaucracy that has successfully ensured a very high degree of safety of aircraft design, construction, operation and maintenance. Outside of a very few professionals doing the work, there is a general lack of knowledge of certification details. For novel technologies such as electric power, and for innovative configurations such as distributed lift and lift-plus-lift-cruise, the rules are far less mature and still emerging and so also poorly understood. Within the Advanced Air Mobility (AAM) initiative, many new aircraft developments are underway using novel configurations, and the public announcements of regulatory progress toward FAA or EASA Type Certification capitalize on this unfamiliarity by being vague or even misleading. Honeywell conceived the Regulatory Readiness Level (RRL) indicator as an objective measure of certification status to serve the AAM industry and ecosystem, with applicability across all of aviation. RRL Version 1 enables a credible, objective assessment of new aircraft progress toward FAA Type Certification, and Operational Approval for Part 135 operations, to allow consistent apples-to-apples comparisons with other aircraft in development. Future RRL releases with allow determination of progress against criteria from EASA and other regulatory authorities, for supplemental types certifications STCs), and for risk-based airworthiness assessments such as EASA Specific Operations Risk Assessments (SORA).
Newman, DanielAgrawal, Pulkit
This SAE Aerospace Information Report (AIR) provides information on air quality and some of the factors affecting the perception of cabin air quality in commercial aircraft cabin air. Also a typical safety analysis process utilizing a Functional Hazard Assessment approach is discussed.
AC-9 Aircraft Environmental Systems Committee
The extent of automation and autonomy used in general aviation (GA) has been steadily increasing for decades, with the pace of development accelerating recently. This has huge potential benefits for safety given that it is estimated that 75% of the accidents in personal and on-demand GA are due to pilot error. However, an approach to certifying autonomous systems that relies on reversionary modes limits their potential to improve safety. Placing a human pilot in a situation where they are suddenly tasked with flying an airplane in a failed situation, often without sufficient situational awareness, is overly demanding. This consideration, coupled with advancing technology that may not align with a deterministic certification paradigm, creates an opportunity for new approaches to certifying autonomous and highly automated aircraft systems. The new paths must account for the multifaceted aviation approach to risk management which has interlocking requirements for airworthiness and operations (including training and airspace integration). They occur across a variety of different operational paradigms with varying roles for the human and the systems in question. If implemented properly, autonomy can take GA safety to the next level while simultaneously increasing the number and variety of aircraft and transportation options they provide.
Dietrich, Anna MracekRajamani, Ravi
Additive manufacturing (AM) is currently being used to produce many aerospace components, with its inherent design flexibility enabling an array of unique and novel possibilities. But, in order to grow the application space of polymer AM, the industry has to provide an offering with improved mechanical properties. Several entities are working toward introducing continuous fibers embedded into either a thermoplastic or thermoset resin system. This approach can enable significant improvement in mechanical properties and could be what is needed to open new and exciting applications within the aerospace industry. However, as the technology begins to mature, there are a couple of unsettled issues that are beginning to come to light. The most common question raised is whether composite AM can achieve the performance of traditional composite manufacturing. If AM cannot reach this level, is there enough application potential to warrant the development investment? The answers are highly dependent on the individual processors and will require significant research. Yet, there are still other common challenges that are not isolated to a singular processor. The focuses of this chapter are the capability to design and provide robust structural analysis for continuous fiber-reinforced polymer AM—two unsung aspects that can make or break this new technology as it finds its way into the aerospace market. These two unsettled issues, out of many, may require fundamental changes to the design, analysis, and manufacturing process. Without solutions to them, adoption by the aerospace industry will be limited to point design applications, thus constraining the technology to being nothing more than a specialized tool.
Hayes, MichaelMuelaner, JodyRoye, ThorstenWebb, Philip
This AIR provides a detailed example of the aircraft and systems development for a function of a hypothetical S18 aircraft. In order to present a clear picture, an aircraft function was broken down into a single system. A function was chosen which had sufficient complexity to allow use of all the methodologies, yet was simple enough to present a clear picture of the flow through the process. This function/system was analyzed using the methods and tools described in ARP4754A/ED-79A. The aircraft level function is “Decelerate Aircraft On Ground” and the system is the braking system. The interaction of the braking system functions with the aircraft are identified with the relative importance based on implied aircraft interactions and system availabilities at the aircraft level. This example does not include validation and verification of the aircraft level hazards and interactions with the braking system. However, the principles used at the braking system level can be applied at the higher aircraft level. The methodologies applied here are an example of one way to utilize the principles defined in ARP4754A/ED-79A. The function chosen was the braking system. Other formats may be used to accomplish the documentation, so long as the principles outlined in ARP4754A/ED-79A are followed. This example contains references to documentation that a company may use to assure itself of the safety of its products but does not include the documentation that the Original Equipment Manufacturer (OEM) would be required to submit at the aircraft level for aircraft certification. Some of these documents are submitted to the regulatory agencies for the purpose of certification (e.g. the Wheel Brake System FHA). Other documents are internal to the company and not required to be submitted for certification. No implication is made that these documents should be submitted to a regulatory agency and none should be implied, although all documents should be available for submission if requested by the regulatory agency. Safety and Certification are not synonymous terms. The example shows the systems engineering process as applied to the development of an aircraft, including some processes that are beyond certification requirements. Figure 1 depicts the flow of activities within this example. This figure provides a guide to the structure of this AIR and should allow the reader to quickly find specific areas within the example using the cross references. Figure 1 includes the top aircraft level tasks to provide the reader a reference point. The detailed example in Section 3 of this AIR covers only the activities related to the braking system. Figure 1 presents a sequence of activities found in a typical development program. In a real development program, the development process is usually far more complex. For example, in a real development program, development of the different levels (aircraft, system and item) often occurs concurrently, rather than serially as depicted in example flow. The top row of Figure 1 represents the activities that will occur within the aircraft development. The middle row represents the activities that occur within the wheel brake system development. The bottom row represents the activities that are covered for the subsystem-level Brake System Control Unit (BSCU) development, as well as the integration and verification activities at the higher levels. The Figure 1 example flow also shows where major artifacts from the System Safety Process (ARP4761) will be utilized. The example flow shows how the sections and artifacts are laid out and represents the step by step process detailed in ARP4754A/ED-79A. In a real development program, the System Safety Process occurs concurrently with ARP4754A/ED-79A, constantly receiving inputs from the ARP4754A/ED-79A process and providing feedback to ARP4754A/ED-79A processes. Figure 1 also shows a box titled Integral Processes to illustrate to the reader that the integral processes are utilized throughout the development process. The reader is encouraged to use this example flow diagram to help navigate the example. This will allow the reader to either read the example in its entirety or use it as a quick reference guide in order to quickly find the desired section.
S-18 Aircraft and Sys Dev and Safety Assessment Committee
As model-based systems engineering is proliferating throughout the aerospace industry as a method to manage the development of complex cyber-physical systems, opportunities to leverage formal methods for verification and validation purposes are significant. As a system model described in SysML can contain the level of semantics required to define strict system requirements, it is possible to create a translation tool to generate SRL (SADL (Semantic Application Design Language) Requirements Language) to leverage ASSERT™ (Analysis of Semantic Specifications and Efficient generation of requirements-based Tests) for verification and validation of the system requirements. SADL [13] is a controlled English grammar that translates directly into OWL (Web Ontology Language) [14]. As part of the validation of the SRL requirements, ASSERT™ leverages a theorem prover to look for conflict and completeness errors. For verification, ASSERT™ uses a Satisfiability Modulo Theories (SMT) solver for the generation of test cases and procedures. This paper extends the Braking System Control Unit (BSCU) portion of the Wheel Braking System (WBS) example within Appendix E of ARP4754B [2] described in [1] to demonstrate an example of capturing system requirements in Cameo using SysML, creating test cases and procedures from ASSERT™ exporting from SysML and translating to SRL/SADL, and exporting the Cameo system model data along with the test cases, test procedures, and requirements analysis data from ASSERT™ into the Rapid Assurance Curation Kit (RACK). RACK is a data curation platform which facilitates reporting on Development Assurance and safety assessments guidelines like those used for aircraft certification.
McMillan, CraigLee, LawrenceRussell, DanielPrince, DanielHasanovic, NihadDurling, MichaelSiu, KitVaranasi, Sarat ChandraMeng, BaoluoKleven, Everett
Protecting against atmospheric icing conditions is critical for the safety of aircraft during flight. Sensors and probes are often used to indicate the presence of icing conditions, enabling the aircraft to engage their ice protection systems and exit the icing cloud. Supercooled large drop icing conditions, which are defined in Appendix O of 14 CFR Part 25, pose additional aircraft certification challenges and requirements as compared to conventional icing conditions, which are defined in Appendix C of 14 CFR Part 25. For this reason, developing sensors that can not only indicate the presence of ice, but can also differentiate between Appendix O and Appendix C icing conditions, is of particular interest to the aviation industry and to federal agencies. Developing detectors capable of meeting this challenge is the focus of SENS4ICE, a European Union sponsored project. While participating in the SENS4ICE Project, Collins Aerospace has developed an ice detection and differentiation sensor known as the Collins Ice Differentiator System (Collins-IDS). A flight test campaign evaluating the performance of the Collins-IDS in natural icing conditions was completed; the results of which are the focus of this technical paper. During the campaign, the Collins-IDS successfully detected the presence of ice and determined, with high accuracy whether that ice was Appendix C or Appendix O. Additional testing in Appendix O icing conditions, either in an icing wind tunnel or during a flight test in natural icing conditions, will benefit the future development of the Collins-IDS.
Hamman, MatthewGelao, GiancarloRidouane, El HassanChabukswar, RohanBotura, Galdemir
The ground vibration test (GVT) is an important phase in a new aircraft development program, or the structural modification of a certified aircraft, to experimentally determine the structural vibrational modes of the aircraft and their modal parameters. These modal parameters are used to validate and correlate the dynamic finite element model of the aircraft to predict potential structural instabilities (such as flutter), assessing the significance of modifications to research vehicles by comparing the modal data before and after the modification and helping to resolve in-flight anomalies. Due to the high cost and the extensive preparations of such tests, a new method of vibration testing called the taxi vibration test (TVT) rooted in operational modal analysis (OMA) was recently proposed and investigated as an alternative method to conventional GVT. In this investigation, an experimental setup was constructed to further investigate the applicability of the TVT to flexible airframes encountered in fixed-wing autonomous aerial systems with oleo-pneumatic shock absorber landing gears in a tricycle configuration. The influence of the taxiing speed and the landing gear–shock absorber damping setting on the outcome of the TVT is also investigated. The taxiing speed was found to strongly influence the success of the test with an optimal taxiing speed existing for the assembled airframe that allows for the best TVT outcome. The shock absorber damping setting was found to increase the level of the airframe excitation during the TVT; however, it did not impact its outcome as compared to the taxiing speed. Certain modes were not identified during the TVT tests, which was attributed to the way the assembled aircraft is secured to the moving belt and to the lack of sufficient excitation through taxiing. The experimental vibrational modes were successfully matched against the modes obtained from the normal modal analysis of an uncorrelated flexible multibody dynamics model. Further investigations are suggested before the TVT method can be deemed suitable for all classes of fixed-wing aerial systems.
Al-bess, LohayKhouli, Fidel
Electrical Vertical Takeoff and Landing (eVTOL) vehicles hold great promises for revolutionizing urban mobility. Their emergences as a transformative transportation technology has led multiple Original Equipment Manufacturers (OEM) competing for market share, with important variety of technical solutions, all necessitating to demonstrate the compliance to safety requirements and regulations. Model Based Safety Analysis (MBSA), newly introduced in ARP4761A and based on compositional and modular representation of failure propagation paths within one system, provides a unique opportunity to increase efficiency by maximizing the possible reuse of safety analyses elements across multiple architectures (“product line” philosophy). Generic library of safety models for elements of variant architectures can be efficiently constructed using MBSA techniques that can then support safety analyses on variant architectures or architectures trade-off. This approach can facilitate a safety process that enable customized safety solutions without complete re-engineering of the safety analyses for each architecture. The purpose of this paper is to present and illustrate one work performed on the definition of a safe Flight Control System for eVTOL, leveraging the capacity of a MBSA based approach to ensure high level of agility and rapid responsiveness. The first sections will present the need, the MBSA approach and a general modelling process that can be used to employ MBSA methodology. Then, an example of eVTOL Flight Control System architecture and safety analyses will be detailed to picture how MBSA, coupled with a generic component library, can provide an easily adaptable safety solution. Finally, we discuss some possible next steps and future work identified in order to certify a solution thanks to this method.
Adeline, RomainWang, JiaHua, Angelina
Advanced flight control system, aviation battery and motor technologies are driving the rapid development of eVTOL to offer possibilities for Urban Air Mobility. The safety and airworthiness of eVTOL aircraft and systems are the critical issues to be considered in eVTOL design process. Regarding to the flight control system, its complexity of design and interfaces with other airborne systems require detailed safety assessment through the development process. Based on SAE ARP4754A, a forward architecture design process with comprehensive safety assessment is introduced to achieve complete safety and hazard analysis. The new features of flight control system for eVTOL are described to start function capture and architecture design. Model-based system engineering method is applied to establish the functional architecture in a traceable way. SFHA and STPA methods are applied in a complementary way to identify the potential safety risk caused by failure and unsafe control action. PSSA with FTA assists to allocate safety requirements and modify the architecture of flight control system. Through the practice of safety-oriented architecture design of flight control system for eVTOL, safety requirements are identified, and related modifications and design are implemented to optimize the system architecture design. Comparing to the safety assessment method with only ARP4761 methods, the combination of ARP4761 and STPA will extend the perspective to deal with potential unsafety issues. Hazards caused by random failure and incorrected control are all tackled. The work of this paper can serve as a useful reference for the system safety assessment and architecture design for eVTOL and airborne systems.
Ning, ChengweiZhang, HaoWeng, HaiminMa, Ran
ARP4761A and its EUROCAE counterpart, ED-135, present guidelines for performing safety assessments of civil aircraft, systems, and equipment. They may be used when addressing compliance with certification requirements (e.g., 14 CFR/CS Parts 23, 25, 27, and 29 and 14 CFR Parts 33, 35, CS-E, and CS-P). ARP4761A/ED-135 may also be used to assist a company in meeting its own internal safety assessment standards. While the safety assessment processes described are primarily associated with civil aircraft, systems, and equipment, these processes may be used in many other applications. The guidelines herein identify a systematic safety assessment process, but other processes may be equally effective. The processes described herein are usually applicable to the new designs or to existing designs that are affected by changes to design or functions. In the case of the implementation of existing design(s) in a derivative application, complementary means such as service experience in a similar application may be used in the safety assessment. ARP4761A/ED-135 does not address safety assessment of in-service products but does include references to those processes. ARP5150A and ARP5151A contain processes for conducting in-service safety assessments. This document does not include information on security threat considerations.
S-18 Aircraft and Sys Dev and Safety Assessment Committee
This SAE Aerospace Recommended Practice (ARP) provides recommendations for the development of aircraft and systems, taking into account aircraft functions and operating environment. It provides practices for ensuring the safety of the overall aircraft design, showing compliance with regulations, and assisting a company in developing and meeting its own internal standards. These practices include validation of requirements and verification of the design implementation for safety, certification, and product assurance. The guidelines in this document were developed in the context of U.S. Title 14 Code of Federal Regulations (14 CFR) Part 25 and European Union Aviation Safety Agency (EASA) Certification Specification (CS) CS-25. They may be applicable in the context of other regulations, such as 14 CFR Parts 23, 27, 29, 33, and 35, and CS-23, CS-27, CS-29, CS-E, and CS-P. This document addresses the development cycle for aircraft and systems that implement aircraft and system functions. It does not include detailed information on the following subjects and references: Software development; refer to RTCA DO-178C/EUROCAE ED-12C. Electronic hardware development; refer to RTCA DO-254/EUROCAE ED-80. Integrated modular avionics development; refer to RTCA DO-297/EUROCAE ED-124. Airworthiness security process; refer to RTCA DO-326A/EUROCAE ED-202A. Safety assessment processes; refer to ARP4761A/EUROCAE ED-135. A process for accomplishing in-service safety assessment is described in ARP5150A and ARP5151A or in other documents such as the guidance material of EASA Part 21 (GM21) when required by applicable regulation. In this document, wherever references to ARP5150A/ARP5151A are made, the reader should understand this also implies EASA Part 21 (GM21). Master Minimum Equipment List (MMEL) or Configuration Deviation List (CDL) development; refer to applicable regulatory guidance from the applicable Certification Authority. Aircraft structure and aerodynamics development. Figure 1 outlines the relationships between the various development documents, which provide guidelines for safety assessment, electronic hardware and software life cycle processes, and the system development process described herein.
S-18 Aircraft and Sys Dev and Safety Assessment Committee
Unmanned Aircraft Systems (UAS) have been growing over the past few years and will continue to grow at a faster pace in future. UAS faces many challenges in certification, airspace management, operations, supply chain, and maintenance. Blockchain, defined as a distributed ledger technology for the enterprise that features immutability, traceability, automation, data privacy, and security, can help address some of these challenges. However, blockchain also has certain challenges and is still evolving. Hence it is essential to study on how blockchain can help UAS. G-31 technical committee of SAE International responsible for electronic transactions for aerospace has published AIR 7356 [1] entitled Opportunities, Challenges and Requirements for use of Blockchain in Unmanned Aircraft Systems Operating below 400ft above ground level for Commercial Use. This paper is a teaser for AIR 7356 [1] document. It presents the current opportunities, challenges of UAS operating at or below 400 ft Above Ground Level (AGL) altitude for commercial use and how blockchain can help meet these challenges. It also provides requirements for developing a blockchain solution for UAS along with the need for the standardization of blockchain enabled processes.
Manoharan, DineshG.V.V., Ravi KumarR, PrithivirajGhimire, RiteshRencher, RobertMarkou, ChrisFabre, ChrisRoboff, MarkBudeanu, DragosRajamani, RaviWalthall, RhondaVeluri, Sastry
In an application first, the physics of why the sky is blue is used to measure gas flows without obstructive sensors. A longstanding industry partnership between Virginia Polytechnic Institute and State University (Virginia Tech) and Pratt & Whitney has resulted in a new laser-optical technology that aims to revolutionize in-flight thrust measurement.
Hazardous atmospheric icing conditions occur at sub-zero temperatures when droplets come into contact with aircraft and freeze, degrading aircraft performance and handling, introducing bias into some of the vital measurements needed for aircraft operation (e.g., air speed). Nonetheless, government regulations allow certified aircraft to fly in limited icing environments. The capability of aircraft sensors to identify all hazardous icing environments is limited. To address the current challenges in aircraft icing detection and protection, we present herein a platform designed for in-flight testing of ice protection solutions and icing detection technologies. The recently developed Platform for Ice-accretion and Coatings Tests with Ultrasonic Readings (PICTUR) was evaluated using CFD simulations and installed on the National Research Council Canada (NRC) Convair-580 aircraft that has flown in icing conditions over North East USA, during February 2022. This aircraft is a flying laboratory, equipped with more than 40 sensors providing a comprehensive characterization of the flight environment including measurements of temperature, pressure, wind speed and direction, water droplet size and number distribution, and hydrometeor habits imagery. The flight tests of the platform included assessment of passive icephobic coatings as well as heat-assisted tests. Monitoring tools included visual high resolution, real-time inspection of the surface as well as detection of surface ice using NRC’s Ultrasonic Ice Accretion Sensors (UIAS). In this paper, we present the new platform and show some preliminary commissioning results of PICTUR, collected inflight under, predominantly, supercooled small droplets and supercooled large drops (SLD) icing conditions. The combination of the platform and the complementary sensors on the aircraft demonstrated an effective and unique technique for icing studies in a natural environment.
Nichman, LeonidFuleki, DanSong, NaihengBenmeddour, AliWolde, MengistuOrchard, DavidMatida, EdgarBala, KennySun, ZhigangBliankinshtein, NataliaRanjbar, KeyvanDiVito, Stephanie
Distinct atmospheric conditions containing supercooled large droplets (SLD) have been identified as cause of severe accidents over the last decades as existing countermeasures even on modern aircraft are not necessarily effective against SLD-ice. Therefore, the detection of such conditions is crucial and required for future transport aircraft certification. However, the reliable detection is a very challenging task. The EU funded Horizon 2020 project SENS4ICE targets this gap with new ice detection approaches and innovative sensor hybridization. The indirect ice detection methodology presented herein is key to this approach and based on the changes of airplane flight characteristics under icing influence. A performance-based approach is chosen detecting an abnormal flight performance throughout the normal operational flight. It is solely based on a priori knowledge about the aircraft characteristic and the current measurable flight state. This paper provides a proof of concept for the performance-based ice detection: starting with the evaluation of operational flight data for different example aircraft the expectable flight performance variation within a fleet of same type is shown which must be smaller than the expected icing influence for reliable detection. Next, the implementation of the indirect ice detection system (IIDS) algorithms in SENS4ICE is detailed with certain regard to the flight test implementation for final validation. Finally, the initial methodology verification and validation results are presented and discussed.
Deiler, ChristophSachs, Falk
This paper presents impingement analysis on a nacelle inlet, multibody airfoil, and swept tail under Supercooled Large Droplet (SLD) conditions in icing tunnels. Impingement and collection efficiency calculations are crucial for ice shape and protection analyses. The aerospace icing community selected three cases for simulation, focusing on SLD conditions, which require specific mathematical models for accurate representation. The present authors used a Reynolds-averaged Navier-Stokes computational fluid dynamics (CFD) tool to evaluate pressure coefficients and collection efficiency, comparing them with experimental data. CFD simulations incorporated fully turbulent flow using various turbulence models and Eulerian droplet transport, considering experimental droplet distribution. The results showed acceptable deviations despite SLD simulation challenges and experimental data problems. A secondary conclusion suggests simplifying a 27-bin distribution to a 10-bin distribution to take into account the cumulative mass curve. An accumulated mass index is proposed to compare different simulations. Importantly, the CFD accurately captures the impingement limits, enhancing its value for engineering purposes. This study demonstrates the suitability of the CFD method by showcasing its application to address aircraft certification challenges, emphasizing the importance of integrating engineering perspectives within CFD simulation results.
Da Silva, GuilhermePio, DiogoRafael, CaioVillela, PedroRezende, SabrinaTeixeira Da Silva, Jayme
This standard covers all types of oxygen breathing equipment used in non-military aircraft. It is intended that this standard supplements the requirements of the detail specification or drawings of specific components or assemblies (e.g., regulators, masks, cylinders, etc.). Where a conflict exists between this standard and detail specifications, detail specifications shall take precedence.
A-10 Aircraft Oxygen Equipment Committee
Autonomy is a key enabling factor in uncrewed aircraft system (UAS) and advanced air mobility (AAM) applications ranging from cargo delivery to structure inspection to passenger transport, across multiple sectors. In addition to guiding the UAS, autonomy will ensure that they stay safe in a large number of off-nominal situations without requiring the operator to intervene. While the addition of autonomy enables the safety case for the overall operation, there is a question as to how we can assure that the autonomy itself will work as intended. Specifically, we need assurable technical approaches, operational considerations, and a framework to develop, test, maintain, and improve these capabilities. We make the case that many of the key autonomy functions can be realized in the near term with readily assurable, even certifiable, design approaches and assurance methods, combined with risk mitigations and strategically defined concepts of operations. We present specific autonomy functions common to many civil beyond visual line of sight (BVLOS) operations and corresponding design assurance strategies, along with their contributions to an overall safety case. We provide examples of functions that can be certified under existing standards, those that will need runtime assurance (RTA) and those that will need to be qualified with statistical evidence.
Bartlett, PaulChamberlain, LyleSingh, SanjivCoblenz, Lauren
This SAE Aerospace Information Report (AIR) focuses on opportunities, challenges, and requirements in use of blockchain for Unmanned Aircraft Systems (UAS) operating at and below 400 feet above ground level (AGL) for commercial use. UAS stakeholders like original equipment manufacturers (OEMs), suppliers, operators, owners, regulators, and maintenance repair and overhaul (MRO) providers face many challenges in certification, airspace management, operations, supply chain, and maintenance. Blockchain—defined as a distributed ledger technology that includes enterprise blockchain—can help address some of these challenges. Blockchain technology is evolving and also poses certain concerns in adoption. This AIR provides information on the current UAS challenges and how these challenges can be addressed by deploying blockchain technology along with identified areas of concern when using this technology. The scope of this AIR includes elicitation of key requirements for blockchain in UAS across its life cycle and the need for the standardization of blockchain-enabled processes.
G-31 Digital Transactions for Aerospace
This SAE Aerospace Standard (AS) provides general design and test requirements for a flat cut-off pressure compensated, variable delivery hydraulic pump for use in a civil aircraft hydraulic system with a rated system pressure up to 5000 psi (34500 kPa). NOTE: Hydraulic pumps may incorporate features such as a clutch in the input drive, which will not be covered by this standard.
A-6C4 Power Sources Committee
This guide provides detailed information, guidance, and methods for demonstrating electromagnetic compatibility (EMC) on civil aircraft. This guide addresses aircraft EMC compliance for safety and functional performance of installed electrical and electronic systems. The EMC guidance considers conducted and radiated electromagnetic emissions and transients generated by the installed electrical and electronic systems which may affect other installed electrical and electronic systems on the aircraft. Application of appropriate electrical and electronic equipment EMC requirements are discussed. Methods for aircraft EMC tests and analysis are described. This guide does not address aircraft compatibility with the internal electromagnetic environments of portable electronic devices (PED) or with the external electromagnetic environments, such as high-intensity radiated fields (HIRF), lightning, and precipitation static.
AE-4 Electromagnetic Compatibility (EMC) Committee
A-5A Wheels, Brakes and Skid Controls Committee
This document contains minimum operational performance specification (MOPS) of active on-board INFLIGHT ICING DETECTION SYSTEMS (FIDS). This MOPS specifies FIDS operational performance which is the minimum necessary to satisfy regulatory requirements for the design and manufacture of the equipment to a minimum standard and guidance towards acceptable means of compliance when installed on an AIRCRAFT. Detection of ICE accreted on the AIRCRAFT during ground operations is not considered in this document. This MOPS was written for the use of FIDS on AIRCRAFT as defined in 1.3 and 2.3. Expected minimum performance specifications for FIDS and their functions are provided in Section 3. The minimum performance requirements as defined in Section 3 do not consider SYSTEM performance as installed on the AIRCRAFT. Performance in excess of the minimum performance may be required by the SYSTEM installed on an AIRCRAFT in order to meet regulatory or operational requirements. This topic is considered in Section 6. This MOPS document is structured as follows: Operational performance specifications for functions or COMPONENTS that refer to equipment capabilities that exceed the stated minimum requirements are identified as optional features. The word “equipment” as used in this document includes all COMPONENTS and units necessary for the SYSTEM to properly perform its intended function(s). For example, the “equipment” may include all of the COMPONENTS listed in 1.4. It should not be inferred that each FIDS design will necessarily include all of the COMPONENTS or units listed in that Section. This will depend on the specific design chosen by the FIDS manufacturer.
AC-9C Aircraft Icing Technology Committee
The advent of electrified propulsion in the aerospace sector, captured in microcosm by the fast-emerging eVTOL market, both threatens to upset the establishment of major aerospace players and offers significant new opportunities for start-up companies. In all cases, it is forcing a marriage of system simulation and architecture definition techniques from markets already meeting these challenges, such as automotive. The demands of these aerospace applications are causing engineers on both sides to find the best blend of tools and approaches to meet their goals.
Standard Approach to Identifying and Defining Functions for Systems Development and Safety Assessments2022-01-00083/8/2022
The Safety Assessment Process, defined by SAE ARP4761 and associated regulatory guidance and the system development process defined by SAE ARP4754 are built on an understanding of the functions performed by a system or systems. [1, 2] These recommended practices do not provide, or reference, specific guidance regarding function definition, though they do provide some conventional airplane examples. ASTM E2013-20 describes function identification principles for cost evaluations, but does not consider how functions are used in safety assessments.[3] Without a systematic process for establishing and describing functions for safety assessments, the application of the development and safety assessment processes can be complicated by inappropriate function selections. Such functions may be overly inclusive, applied at the wrong level of abstraction, or might not describe the intended behaviors adequately. While these concerns can be managed as developers gain experience with these processes, the continually increasing complexity of system behaviors and the introduction of multi-vehicle “swarms” promises to increase these concerns. This paper proposes a process to assist the system or product developer with identifying and describing functions at each level of abstraction used in describing the architecture. This includes establishing system boundaries and checking the appropriateness of the resulting function lists.
Darrah, Paul D.
This document covers information concerning the use of oxygen when flying into and out of high elevation airports for both pressurized and non-pressurized aircraft. Oxygen requirements for pressurized aircraft operating at high altitudes have for decades emphasized the potential failures that could lead to a loss of cabin pressurization coupled with the potential severe hypoxic hazard that decompressions represent. This document is intended to address the case where the relationship between cabin and ambient pressures are complicated by operations at high terrestrial altitudes. Operators who fly into these high-altitude airports should address the issues related to this environment because it carries the potential for insidious hypoxia and other conditions which can affect safety. It provides information to consider in developing operational procedures to address hypoxia concerns consistent with regulatory mandates. In some sections, procedures are discussed that may mitigate the deleterious effects of hypoxia in a non-flight regime yet still have the potential to represent risk factors associated with flight operations. All the information is provided as a framework for potential oxygen management and other procedures to facilitate responsible practices and facilitate compliance with existing regulatory requirements. This document cannot address every type aircraft pressurization system, oxygen system or operational condition the flight may encounter. Any threat or hazard not discussed in AIR6829 should be brought to the attention of the OEM, the regulatory authority and the flight operations department for proper guidance.
A-10 Aircraft Oxygen Equipment Committee
Various emergency situations may require the dispensing of oxygen to all occupants of aircraft during flight. During an emergency event, depending on the aircraft operational flight capability, all cabin occupants must be serviced by a mask presentation system connected to an operational oxygen source. Several regulations specify the functional characteristics and requirements of the oxygen systems for aircraft in support of different missions. These should be referred to for the exact functional performance requirements. It is not the intent of this document to ensure conformance with these regulations, but only to recommend general concepts for the location of the oxygen masks and oxygen system outlets for proper accessibility by the aircraft occupants, whether cabin occupants or crew members. Different requirements may apply when the mission of the pressurized aircraft or the operational altitude of the aircraft is not in excess of FL250. When the aircraft is operating above FL100, oxygen masks, either distributed to each cabin occupant or stowed and readily accessible, must be available in the event of a pressurization failure. Oxygen masks must also be connected to an operational source, available and within easy reach of each seated flight deck crew member and observer. For unpressurized aircraft, during flight operations above FL125, oxygen masks connected to an operational oxygen source must be available to all occupants. This document defines the accessibility requirements that should be considered in the placement of oxygen masks for presentation to the user and the connections for such oxygen masks to the operational oxygen systems. This is of interest when designing the interior of the aircraft, placing the seats in relationship to such outlets and mask connections, or placing oxygen mask outlets in relation to the seats. The accessibility requirements contained in this document are applicable to installation and arrangement of such equipment in different locations in the aircraft as shown on typical examples of installation areas as shown in Figures 3 through 15. Furthermore, this document does not discuss operational needs with respect to oxygen supply duration, nor the detail design of portable oxygen system or protective breathing equipment. Please refer to other SAE documents for such information. Portable Oxygen System and Protective Breathing Equipment are to be installed to meet the requirements of 25.1447(c) and 25.1439. Also, if portable oxygen equipment is installed, they need to meet the requirements of 14 CFR Part 25, Section 25.1443(d)& (e).
A-10 Aircraft Oxygen Equipment Committee
This document establishes the general requirements for the quality management of aircraft ground deicing/anti-icing systems and processes. It covers the areas of: Quality system, documentation, and control of records; Management responsibility; Resource management; Product realization; and Measurement, analysis, and improvement. This document defines these areas and their key aspects so they can be practically managed, and that deicing operations can become safer with time. In alignment with AS6285 and AS6286, the primary focus of this standard is on the deicing/anti-icing of aircraft using deicing and anti-icing fluids.
G-12T Training and Quality Programs Committee
This document provides guidance for applying aircraft equipment electromagnetic, electrical, and mechanical qualification standards (i.e., DO-160, MIL-STD-461, MIL-STD-704, and MIL-STD-810) to civil aircraft certification intended for military use and for military aircraft equipment installed on civil aircraft. The guidance identifies where the equipment environmental qualification standards meet the intent of both the civil or military aircraft certification requirements. Conversely, the guidance will identify where the equipment environmental qualification standards have differences that do not meet the intent of the civil or military aircraft certification requirements and when these differences matter based on equipment criticality, installation location, and/or other variables.
AE-4 Electromagnetic Compatibility (EMC) Committee
This document describes a method for measuring forces during an impact between a soft or frangible projectile and a relatively rigid flat normal surface. The document describes the hardware and instrumentation required, as well as the processing and data reduction required to compute force. In this test, a projectile impacts one end of a long cylindrical bar with flat ends, called a Hopkinson bar. The impact occurs on the centerline of the bar in the axial direction. The diameter of the cylindrical bar is large compared to the lateral dimension of the projectile so that, during and after the impact, the projectile material moves radially or backward, rather than extruding around the perimeter of the impact surface. The bar is instrumented with strain gages at some distance from the impacted end to measure the longitudinal strain in the bar. The bar must be sufficiently long so that the duration of the impact is less than the time it takes for the transient stress wave generated by the impact to travel to the end of the bar and back to the location of the strain gages. This test is intended for measuring the transient force generated by the projectile when it impacts the cylindrical bar. Projectile breakup pattern data may also be captured during this test. The projectile material is expected to be soft compared with the bar material. Impact stresses are expected to be small compared with the yield strength of the bar material so that all deformations in the bar are elastic. The values stated in either SI units or inch-pound units are considered separate standards. The values stated in each system may not be exactly equivalent; therefore, each system must be considered as independent. This standard does not address all of the safety concerns associated with its use. It is the responsibility of each user of this standard to ensure that any safety issues are properly addressed.
G-28 Simulants for Impact and Ingestion Testing Committee
Items per page:
1 – 50 of 167