Formal specification of requirements for analytical redundancy ba

Xây dựng đặc tả yêu cầu phân tích dự phòng chính xác. Đảm bảo tính tin cậy và hiệu quả cho hệ thống.

Trường ĐH

West Virginia University

Chuyên ngành

Aerospace Engineering

Tác giả

Luan An

Thể loại

Luận án tiến sĩ

Năm xuất bản

Số trang

195

Thời gian đọc

30 phút

Lượt xem

0

Lượt tải

0

Phí lưu trữ

50 Point

Tổng quan nhanh

Chủ đề:
1. Đặc tả Yêu cầu Chính thức cho Dư thừa Phân tích
Số trang:
195 trang
Trường:
West Virginia University
Chuyên ngành:
Aerospace Engineering
Tác giả:
Năm:

Tóm tắt nội dung luận án

I. Đặc tả Yêu cầu Chính thức cho Dư thừa Phân tích

Hệ thống điều khiển bay đang trải qua quá trình tự động hóa nhanh chóng. Điều này dẫn đến sự phức tạp gia tăng, ảnh hưởng trực tiếp đến độ tin cậy và an toàn. Yêu cầu chống lỗi nghiêm ngặt là cần thiết. Nghiên cứu này tập trung vào đặc tả yêu cầu chính thức cho các kỹ thuật dư thừa phân tích. Phương pháp chính thức đóng vai trò thiết yếu trong kỹ thuật yêu cầu. Chúng đảm bảo tính chính xác và đầy đủ của các yêu cầu. Việc áp dụng phương pháp này giúp xác định rõ ràng các chức năng và giới hạn của hệ thống. Điều này đặc biệt quan trọng đối với hệ thống an toàn tới hạn, nơi lỗi có thể gây ra hậu quả nghiêm trọng.

1.1. Nhu cầu Đặc tả Yêu cầu Chính thức cho FDI

Phát hiện và cô lập lỗi (FDI) là chức năng cốt lõi của hệ thống chống lỗi. Đặc tả chính thức cung cấp một cách tiếp cận nghiêm ngặt để xác định các yêu cầu FDI. Nó giúp loại bỏ sự mơ hồ và mâu thuẫn trong các yêu cầu phi chính thức. Điều này cải thiện đáng kể khả năng xây dựng một hệ thống FDI mạnh mẽ. Quá trình này hỗ trợ việc đảm bảo rằng hệ thống phản ứng chính xác với các sự cố lỗi.

1.2. Kỹ thuật Dư thừa Phân tích trong Hệ thống Phức tạp

Dư thừa phân tích sử dụng các mối quan hệ toán học giữa các biến hệ thống. Mục tiêu là phát hiện và chẩn đoán lỗi mà không cần phần cứng bổ sung. Kỹ thuật này giảm thiểu sự phức tạp vật lý. Tuy nhiên, việc áp dụng nó đòi hỏi một phương pháp luận thiết kế rõ ràng. Điều này bao gồm đặc tả yêu cầu và phân tích khả thi. Nghiên cứu này xây dựng khung chính thức cho việc này.

1.3. Phương pháp Chính thức Nâng cao Độ tin cậy Hệ thống

Các phương pháp chính thức, như đại số quan hệ, cung cấp công cụ mạnh mẽ. Chúng cho phép mô hình hóa và phân tích hành vi hệ thống một cách chặt chẽ. Điều này góp phần nâng cao độ tin cậy hệ thống tổng thể. Đặc biệt trong các hệ thống an toàn tới hạn, khả năng chứng minh tính đúng đắn là vô cùng giá trị. Nó giúp phát hiện sớm các vấn đề tiềm ẩn trong giai đoạn thiết kế.

II. Hệ thống Điều khiển Bay Chống lỗi Dựa trên Dư thừa

Hệ thống điều khiển bay kỹ thuật số "Fly-By-Wire" đã trở nên phổ biến. Xu hướng tự động hóa này đi kèm với sự gia tăng đáng kể về độ phức tạp. Điều này đặt ra những thách thức lớn về độ tin cậy và an toàn hệ thống. Hệ thống điều khiển bay phải đáp ứng các yêu cầu chống lỗi nghiêm ngặt. Giải pháp tiêu chuẩn thường dựa vào kiến trúc đa chuỗi. Tuy nhiên, điều này lại làm tăng thêm sự phức tạp. Điều này có thể làm giảm độ tin cậy tổng thể của hệ thống. Nghiên cứu khám phá các giải pháp thay thế hiệu quả hơn.

2.1. Tự động hóa và Sự phức tạp Hệ thống Điều khiển Bay

Tự động hóa hiện đại mang lại nhiều lợi ích. Đồng thời, nó cũng tạo ra các hệ thống phức tạp hơn. Ví dụ, máy bay Airbus 320 và Boeing FBW-B777 sử dụng công nghệ Fly-By-Wire. Độ phức tạp này yêu cầu cách tiếp cận mới để đảm bảo an toàn. Các phương pháp kỹ thuật yêu cầu cần phải phát triển. Điều này để đối phó với những hệ thống có nhiều thành phần tương tác.

2.2. Giải pháp Chống lỗi Truyền thống so với Dư thừa Phân tích

Kiến trúc đa chuỗi là một giải pháp chống lỗi truyền thống. Nó sử dụng nhiều bản sao của cùng một phần cứng. Điều này nhằm duy trì hoạt động khi một bản sao bị lỗi. Tuy nhiên, điều này làm tăng trọng lượng, chi phí và sự phức tạp. Kỹ thuật dư thừa phân tích cung cấp một giải pháp thay thế. Nó sử dụng mô hình toán học và thuật toán. Mục đích là để đạt được khả năng chống lỗi mà không cần phần cứng dư thừa.

2.3. Đảm bảo Độ tin cậy và An toàn cho Hệ thống Quan trọng

Hệ thống điều khiển bay là một hệ thống an toàn tới hạn. Sai sót có thể dẫn đến hậu quả thảm khốc. Do đó, việc đảm bảo độ tin cậy hệ thống là tối quan trọng. Khả năng chống lỗi là một yếu tố then chốt. Đặc tả chính thức các yêu cầu giúp đạt được mục tiêu này. Nó cho phép phân tích và xác minh chặt chẽ. Điều này cải thiện đáng kể mức độ an toàn và tin cậy.

III. Thách thức và Giải pháp Dư thừa Phân tích trong FTC

Trong hai thập kỷ qua, nhiều kỹ thuật dư thừa phân tích đã được đề xuất. Mục tiêu là cho mục đích chẩn đoán lỗi. Nghiên cứu về dư thừa phân tích đã đạt được kết quả đáng mong đợi. Tuy nhiên, một lỗ hổng quan trọng vẫn tồn tại. Một phương pháp luận thiết kế toàn diện còn thiếu. Phương pháp này bao gồm đặc tả yêu cầu và phân tích khả thi. Đặc biệt là cho các hệ thống điều khiển bay chống lỗi dựa trên dư thừa phân tích. Nghiên cứu này giải quyết khoảng trống phương pháp luận này. Nó tạo ra một khung chính thức cho việc tích hợp dư thừa phân tích.

3.1. Khoảng trống Phương pháp luận trong Kỹ thuật Yêu cầu

Kỹ thuật yêu cầu là giai đoạn quan trọng nhất của phát triển hệ thống. Việc thiếu một phương pháp luận rõ ràng là một rào cản. Nó cản trở việc áp dụng rộng rãi dư thừa phân tích. Khoảng trống này bao gồm việc xác định các yêu cầu chính thức. Nó cũng bao gồm phân tích hiệu quả của các kỹ thuật này. Nghiên cứu này đề xuất một quy trình có cấu trúc. Mục đích là để thu hẹp khoảng cách này.

3.2. Chẩn đoán Lỗi Dựa trên Mô hình và Dư thừa Phân tích

Chẩn đoán lỗi dựa trên mô hình là một ứng dụng chính của dư thừa phân tích. Nó liên quan đến việc so sánh hành vi hệ thống thực tế với một mô hình tham chiếu. Bất kỳ sự khác biệt nào cũng chỉ ra khả năng có lỗi. Việc đặc tả chính thức các mô hình này là cần thiết. Nó đảm bảo tính nhất quán và chính xác. Điều này rất quan trọng đối với khả năng phát hiện và cô lập lỗi hiệu quả.

3.3. Phân tích Khả thi cho Hệ thống Chống lỗi Phức tạp

Trước khi triển khai một giải pháp chống lỗi, phân tích khả thi là bắt buộc. Điều này đặc biệt đúng với các hệ thống phức tạp như điều khiển bay. Nó đánh giá tính khả thi kỹ thuật và hiệu quả chi phí. Phân tích này cũng xem xét tác động đến hiệu suất tổng thể của hệ thống. Nghiên cứu này cung cấp cái nhìn sâu sắc về những cân nhắc này. Nó giúp đưa ra quyết định thiết kế sáng suốt.

IV. Áp dụng Đại số Quan hệ vào Đặc tả Yêu cầu Hệ thống

Nghiên cứu này áp dụng đại số quan hệ làm khung chính thức. Mục đích là để đặc tả các yêu cầu. Đại số quan hệ cung cấp một cách tiếp cận toán học nghiêm ngặt. Nó cho phép mô hình hóa các mối quan hệ phức tạp giữa các thành phần hệ thống. Phương pháp này đảm bảo sự rõ ràng và không mơ hồ của các yêu cầu. Các yêu cầu phi chính thức ban đầu được lấy từ đặc tả quân sự USAF MIL-F-9490D. Những yêu cầu này sau đó được tái kỹ thuật. Chúng được mô hình hóa và đặc tả lại trong khung chính thức.

4.1. Khung Hình thức Đại số Quan hệ cho Đặc tả

Đại số quan hệ là một ngôn ngữ chính thức mạnh mẽ. Nó thích hợp để biểu diễn các tập hợp và mối quan hệ giữa chúng. Việc sử dụng nó cho phép các nhà thiết kế định nghĩa chính xác các yêu cầu. Điều này bao gồm các điều kiện hoạt động và các kịch bản lỗi. Khung này hỗ trợ phân tích và xác minh yêu cầu một cách chặt chẽ. Nó giúp đảm bảo rằng tất cả các ràng buộc được đáp ứng.

4.2. Kỹ thuật Yêu cầu Lại cho Hệ thống Điều khiển Bay

Quá trình kỹ thuật yêu cầu lại bao gồm việc phân tích các yêu cầu hiện có. Sau đó, chúng được chuyển đổi thành một dạng chính thức và có cấu trúc hơn. Với hệ thống điều khiển bay, điều này giúp làm rõ các yêu cầu chống lỗi. Nghiên cứu sử dụng máy bay hàng không tổng hợp De Havilland DHC-2. Nó được trang bị chức năng lái tự động tiêu chuẩn. Đây là ứng dụng thí điểm để minh họa phương pháp.

4.3. Xác minh Chính thức Các Yêu cầu Chống lỗi

Xác minh chính thức là quá trình chứng minh tính đúng đắn của một thiết kế. Nó chống lại các đặc tả yêu cầu. Bằng cách sử dụng đại số quan hệ, có thể thực hiện kiểm tra nghiêm ngặt. Điều này đảm bảo rằng các yêu cầu chống lỗi là nhất quán và đầy đủ. Nó cũng giúp phát hiện bất kỳ mâu thuẫn hoặc lỗ hổng nào. Quá trình này góp phần nâng cao đáng kể độ tin cậy và an toàn tổng thể.

V. Cải thiện An toàn và Chứng nhận Hệ thống Quan trọng

Phân tích chi tiết và chính thức hóa các yêu cầu đã mang lại kết quả quan trọng. Nó giúp định nghĩa rõ ràng hơn về bài toán chống lỗi. Đặc biệt trong khuôn khổ dư thừa phân tích. Các yêu cầu chống lỗi và quy trình chứng nhận liên quan. Chúng được chứng minh là đòi hỏi cao hơn đáng kể. So với những gì thường được áp dụng trong tài liệu hiện có. Nghiên cứu cũng chỉ ra các vấn đề quan trọng. Những vấn đề này nằm trong tất cả các lĩnh vực liên quan đến quy trình đặc tả. Điều này bao gồm yêu cầu hệ thống điều khiển bay, dư thừa phân tích và kỹ thuật yêu cầu.

5.1. Định nghĩa Rõ ràng hơn về Bài toán Chống lỗi

Việc áp dụng khung chính thức đã loại bỏ sự mơ hồ. Nó cho phép hiểu sâu sắc hơn về các thách thức chống lỗi. Định nghĩa rõ ràng này là nền tảng. Nó giúp phát triển các giải pháp mạnh mẽ và đáng tin cậy. Nó cũng giúp các nhà thiết kế xác định các kịch bản lỗi một cách chính xác. Điều này cải thiện khả năng phản ứng của hệ thống.

5.2. Các Thủ tục Chứng nhận Nghiêm ngặt hơn cho An toàn

Kết quả nghiên cứu cho thấy cần có các quy trình chứng nhận chặt chẽ hơn. Đặc biệt là cho các hệ thống sử dụng dư thừa phân tích. Những yêu cầu này vượt xa các tiêu chuẩn hiện hành. Việc đáp ứng chúng đòi hỏi sự xác minh chính thức. Nó cũng đòi hỏi một sự hiểu biết toàn diện về hành vi hệ thống dưới lỗi. Điều này tăng cường đáng kể mức độ an toàn của hệ thống.

5.3. Vấn đề Phát sinh trong Kỹ thuật Yêu cầu và FDI

Quá trình đặc tả đã làm nổi bật nhiều vấn đề. Chúng liên quan đến thiết kế hệ thống điều khiển bay. Chúng cũng liên quan đến việc triển khai dư thừa phân tích. Các vấn đề này bao gồm sự phức tạp của việc tích hợp. Nó cũng bao gồm việc đảm bảo tính tương thích giữa các thành phần khác nhau. Kỹ thuật yêu cầu cần tiếp tục phát triển. Mục tiêu là để giải quyết hiệu quả những thách thức này.

Mục lục chi tiết luận án

1. Introduction
2. Background information
2.1. Issues on the analytical redundancy approach in fault tolerant flight control systems
2.2. Analytical redundancy in flight control systems
2.3. Formal specification of system requirements
2.4. Advantages of adopting a formal specification language
3. FTC: the system to be specified
3.1. Main functions of the FTC system
3.2. FTC interface with its environment
3.3. Military specification for AFCS
4. Formal specification of the FTC environment
4.1. Relational specification of elementary requirements
4.2. Composition of elementary requirements
4.3. Formal specification of the FTC environment
4.3.1. Performance requirement composition
4.3.2. DHC-2 detail-specification
4.3.3. Correctness of AFCS design
5. Formal requirements specification of the FTC
5.1. FTC functional requirements
5.2. FTC non-functional requirements
5.3. FTC-AR requirements
5.3.1. Formal specification of FTC-AR
5.3.2. Formal specification of fault hypotheses
5.3.3. Relational specification of the FTC-AR requirements
5.3.3.1. Traditional interpretation of detectability and identifiability
5.3.3.2. Formal definition of detectability and identifiability
6. Conclusions
Predicate Logic and Relational Algebra
A.2. Relational algebra and requirements specification
A.2.1. Basics of relational algebra
Elementary specifications of the AR-FTC environment
B.1. Elementary requirements of AFCS performance specification
B.2. Elementary requirements of DHC-2 detail-specification
B.2.1. DHC-2 airplane dynamics
B.2.2. DHC-2 Flight Control System Hardware
B.2.3. DHC-2 Flight Control System Software
B.2.3.1. Control-surface fault modes
B.2.3.2. Engine fault modes
B.2.3.3. Actuator fault modes
B.2.3.4. Rate gyro fault modes
B.2.3.5. Accelerometer fault modes
B.2.3.6. Air data sensor fault modes
B.2.3.7. Angle of attack sensor fault modes
B.2.3.8. Attitude and heading sensor fault modes
B.2.4. DHC-2 requirement space restriction sets
B.2.5. Elementary requirements of interface blocks to AR-FTC system
Support tables of the specification
Xem trước tài liệu
Tải đầy đủ để xem toàn bộ nội dung
Formal specification of requirements for analytical redundancy ba

Tải xuống file đầy đủ để xem toàn bộ nội dung

Tải đầy đủ (195 trang)

Trích đoạn nội dung luận án

Tải xuống để đọc toàn bộ

Graduate Theses, Dissertations, and Problem Reports 2000 Formal specification of requirements for analytical redundancy- based fault -tolerant flight control systems Diego Del Gobbo West Virginia University Follow this and additional works at: https://researchrepository.edu/etd Recommended Citation Del Gobbo, Diego, "Formal specification of requirements for analytical redundancy-based fault -tolerant flight control systems" (2000). Graduate Theses, Dissertations, and Problem Reports.edu/etd/2378 This Dissertation is protected by copyright and/or related rights. It has been brought to you by the The Research Repository @ WVU with permission from the rights-holder(s). You are free to use this Dissertation in any way that is permitted by the copyright and related rights legislation that applies to your use.

For other uses you must obtain permission from the rights-holder(s) directly, unless additional rights are indicated by a Creative Commons license in the record and/ or on the work itself. This Dissertation has been accepted for inclusion in WVU Graduate Theses, Dissertations, and Problem Reports collection by an authorized administrator of The Research Repository @ WVU. For more information, please contact researchrepository@mail. Formal Specification of Requirements for Analytical Redundancy based Fault Tolerant Flight Control Systems Diego Del Gobbo Dissertation submitted to the College of Engineering and Mineral Resources at West Virginia University in partial fulfillment of the requirements for the degree of Doctor of Philosophy in Aerospace Engineering Marcello Napolitano, Ph., Chair Larry Banta, Ph.

Robert Bond, Ph. Ali Mili, Ph. Gary Morris, Ph. Department of Mechanical and Aerospace Engineering Morgantown, West Virginia 2000 Keywords: Fault Tolerance, Flight Control System, Analytic Redundancy, System Requirements Specification, Relational Algebra Copyright 2000 Diego Del Gobbo Abstract Formal Specification of Requirements for Analytical Redundancy based Fault Tolerant Flight Control Systems By Diego Del Gobbo Flight control systems are undergoing a rapid process of automation.

The use of Fly-By-Wire digital flight control systems in commercial aviation (Airbus 320 and Boeing FBW-B777) is a clear sign of this trend. The increased automation goes in par- allel with an increased complexity of flight control systems with obvious consequences on reliability and safety. Flight control systems must meet strict fault-tolerance re- quirements. The standard solution to achieving fault tolerance capability relies on multi-string architectures.

On the other hand, multi-string architectures further in- crease the complexity of the system inducing a reduction of overall reliability. In the past two decades a variety of techniques based on analytical redundancy have been suggested for fault diagnosis purposes. While research on analytical redun- dancy has obtained desirable results, a design methodology involving requirements specification and feasibility analysis of analytical redundancy based fault tolerant flight control systems is missing. The main objective of this research work is to describe within a formal frame- work the implications of adopting analytical redundancy as a basis to achieve fault tolerance.

The research activity involves analysis of the analytical redundancy ap- proach, analysis of flight control system informal requirements, and re-engineering (modeling and specification) of the fault tolerance requirements. The USAF mili- tary specification MIL-F-9490D and supporting documents are adopted as source for the flight control informal requirements. The De Havilland DHC-2 general aviation aircraft equipped with standard autopilot control functions is adopted as pilot appli- cation. Relational algebra is adopted as formal framework for the specification of the requirements.

The detailed analysis and formalization of the requirements resulted in a better definition of the fault tolerance problem in the framework of analytical redundancy. Fault tolerance requirements and related certification procedures turned out to be considerably more demanding than those typically adopted in the literature. Fur- thermore, the research work brought up to light important issues in all fields involved in the specification process, namely flight control system requirements, analytical redundancy, and requirements engineering. Acknowledgments I would like to thank Dr.

Marcello Napolitano, my advisor, for his support during this research. I am thankful to Dr. Ali Mili for having brought some light in the chaos that characterized the early phases of this work. His guidance was crucial to the successful completion of this project.

I am also thankful to Dr. Francesco Nasuti for his friendship and for the numerous helpful discussions on the many faces of analytical redundancy. I wish to thank all of the Drs., researchers, and students who played a role in this research work. Among them I would like to cite Dr.

Wu Wen, Dr. Jack Callahan, Dr. Steve Easterbrook, Dr. Bojan Cukic, Dr.

Mark Shereshevsky, Dr. Harjinder Sandhu, and Dr. In the years of meetings and discussions since the start of the project, they helped me understand the hidden truth behind a multidisciplinary research work. I have no words to thank my wife Teresa, without her love and support I would not be here now.

Of course, I am grateful to my parents for their unbounded love, and to my grandmother for ”being the origin of the family”, as she says. I am also grateful to my brothers for not hanging me upside down this time, and to my sister for her unforgettable shout of joy. Finally, I wish to thank all of those who kept asking: ”So. have you done?”.

I have! iii Contents 1 Introduction 1 2 Background information 5 2.1 Issues on the analytical redundancy approach in fault tolerant flight control systems .2 Analytical redundancy in flight control systems .2 Formal specification of system requirements .2 Advantages of adopting a formal specification language .1 FTC: the system to be specified .2 Main functions of the FTC system .3 FTC interface with its environment .3 Military specification for AFCS. 31 4 Formal specification of the FTC environment 35 4.1 Relational specification of elementary requirements .2 Composition of elementary requirements .3 Formal specification of the FTC environment .1 Performance requirement composition .2 DHC-2 detail-specification .3 Correctness of AFCS design. 60 5 Formal requirements specification of the FTC 62 5.1 FTC functional requirements .2 FTC non-functional requirements .3 FTC-AR requirements .2 Formal specification of FTC-AR .2 Formal specification of fault hypotheses .3 Relational specification of the FTC-AR requirements .1 Traditional interpretation of detectability and identifiability .2 Formal definition of detectability and identifiability. 80 6 Conclusions 82 A Predicate Logic and Relational Algebra 92 A.2 Relational algebra and requirements specification .1 Basics of relational algebra.

97 B Elementary specifications of the AR-FTC environment 102 B.1 Elementary requirements of AFCS performance specification .2 Elementary requirements of DHC-2 detail-specification .1 DHC-2 airplane dynamics .2 DHC-2 Flight Control System Hardware .3 DHC-2 Flight Control System Software .1 Control-surface fault modes .2 Engine fault modes .3 Actuator fault modes .4 Rate gyro fault modes .5 Accelerometer fault modes .6 Air data sensor fault modes .7 Angle of attack sensor fault modes .8 Attitude and heading sensor fault modes .4 DHC-2 requirement space restriction sets .5 Elementary requirements of interface blocks to AR-FTC system. 138 C Support tables of the specification 141 v List of Tables 3.1 DHC-2 autopilot functions and related controls .1 Constants used within the specification of the HH function.2 Domain and image variables used within the specification of the HH function.3 Quantified variables used within the specification of the HH function.4 Predicates and functions used within the specification of the HH function.1 Syntax of propositional logic .2 Semantics of propositional logic .3 Syntax of predicate logic .1 Minimum acceptable control accuracy for ALH function .5 Spaces used within the requirements specification .6 Domain and image variables. 182 vi List of Figures 3.1 Environment of the FTC system.2 FTC within its environment.3 Block diagram of DHC-2 aircraft and its FCS.1 Sample requirements specification structure.2 Structure of the AFCS performance requirements specification.3 Structure of the DHC-2 detail-specification.1 DHC-2 and FTFCS requirements specification structure. 68 vii List of Symbols and Abbreviations ACT Actuator ADC Analog to Digital Converter AFCS Automatic Flight Control System ALH Altitude Hold AR Analytical Redundancy AR-FTFCS Analytical Redundancy based Fault Tolerant Flight Control System CP Control Panel Cin Computer input Cout Computer output DAC Digital to Analog Converter DHC-2 De Havilland DHC-2 aircraft DP Display Panel FBW Fly-By-Wire FCC Flight Control Computer FCL Flight Control Law FCS Flight Control System FCSw Flight Control Software FDC Flight Dynamics and Control FTC Fault Tolerance Capability FTC-ADC Fault Tolerance Capability – Analog to Digital Converter FTC-AR Fault Tolerance Capability – Analytical Redundancy module FTC-CP Fault Tolerance Capability – Control Panel module FTC-DAC Fault Tolerance Capability – Digital to Analog Converter FTC-DP Fault Tolerance Capability – Display Panel module FTC-IN Fault Tolerance Capability – software Input interface FTC-OUT Fault Tolerance Capability – software Output interface FTC-SW Fault Tolerance Capability – Safety switch FTFCS Fault Tolerant Flight Control System HH Heading Hold HS Heading Select MFCS Manual Flight Control System PAH Pitch Attitude Hold RAH Roll Attitude Hold UAV Unmanned Aerial Vehicle viii , Infallible / fail-operational software component Infallible / fail-operational hardware component Subsystem made of more than one component Fallible hardware component Directional data stream Infallible / fail-operational software component of FTC system Infallible / fail-operational hardware component of FTC system Physics law Note: Symbols used in the document are collected in the tables of Appendix C ix Chapter 1 Introduction The use of Fly-By-Wire (FBW) digital flight control systems is playing a more and more prominent role in commercial aviation.

Airbus and Boeing FBW-airliners pro- vide a clear sign of this trend. In FBW technology electronic devices coupled to a digital computer replace conventional mechanical controls. The net result is a more efficient, easier to control aircraft. However, this increased automation goes in parallel with an increased complexity of flight control systems with obvious conse- quences on reliability and safety.

A FBW flight control system is made up of several subsystems including mechanical, electronic, and software components. Each of these subsystems may fail during flight, with disastrous consequences. For this reason flight control systems must meet strict fault-tolerance requirements. The standard solution to achieving fault tolerance capability is the adoption of a multi-string architecture.

This architecture is based on redundant units working in parallel and a voting scheme that disengages a unit when faulty. Triple and quadruple string architectures are cur- rent practice in flight control systems of both military and commercial aviation [62], [21]. On the other hand, multi-string architectures further increase the complexity of the system, induce a reduction of overall reliability, bind to closer maintenance 1 schedule, and require larger budgets. These factors have induced in recent years an increased interest toward alternative approaches to achieving fault tolerance in flight control systems.

Similar interest comes from fields related to satellite and Unmanned Aerial Ve- hicle (UAV) applications. Under the ongoing process of globalization the telecom- munication industry is growing without rest and commercial satellites are playing an important role in this growth. Weight and size largely affect launching costs of satellites. Weight and size also affect UAV applications.

Starting in the late ’80s a variety of UAVs have been built for either military or scientific purposes. They vary significantly in size, mission profile, and payload weight carrying capability. With some of them having a payload weight below 20 lbs and dimensions below 15 feet it is clear how weight and room requirements are a major issue. Despite costs, complexity, and weight drawbacks physical redundancy is adopted to achieve fault tolerance.

Redundancy is a must in achieving fault tolerance; the question is whether re- dundancy other than physical can be adopted. In the past two decades a variety of techniques based on analytical redundancy have been suggested for fault diagnosis purposes. Analytical redundancy identifies with the functional redundancy of the sys- tem. No extra hardware is required; fault tolerance is achieved by means of software routines that process sensor outputs and actuator inputs to check for consistency with respect to the analytical model of the system.

If an inconsistency is detected, the faulty component is isolated and the control law is reconfigured accordingly. The first analytical redundancy scheme implemented within a flight control systems dates 2 back to the 70’s, when the same aircraft used to conduct research on fly-by-wire tech- nology was also used as testbed for an analytical redundancy management algorithm [56].

Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ

Trích dẫn luận án này

Diego Del Gobbo (2000). Formal specification of requirements for analytical redundan [Luận án tiến sĩ, West Virginia University]. LuanAn.net. https://luanan.net/cong-nghe-thong-tin/khoa-hoc-may-tinh/formal-specification-of-requirements-for-analytical-redundancy-ba

Câu hỏi thường gặp

Luận án "Formal specification of requirements for analytical redundan" nghiên cứu về vấn đề gì?

Xây dựng đặc tả yêu cầu phân tích dự phòng chính xác. Đảm bảo tính tin cậy và hiệu quả cho hệ thống.

Luận án "Formal specification of requirements for analytical redundan" được bảo vệ tại trường nào?

Luận án này được bảo vệ tại West Virginia University. Năm bảo vệ: 2000.

Luận án "Formal specification of requirements for analytical redundan" thuộc chuyên ngành gì?

Luận án "Formal specification of requirements for analytical redundan" thuộc chuyên ngành Aerospace Engineering. Danh mục: Khoa Học Máy Tính.

Luận án "Formal specification of requirements for analytical redundan" có bao nhiêu trang?

Luận án "Formal specification of requirements for analytical redundan" có 195 trang. Bạn có thể xem trước một phần tài liệu ngay trên trang web trước khi tải về.

Cách tải luận án "Formal specification of requirements for analytical redundan" về máy như thế nào?

Để tải luận án về máy, bạn nhấn nút "Tải xuống ngay" trên trang này, sau đó hoàn tất thanh toán phí lưu trữ. File sẽ được tải xuống ngay sau khi thanh toán thành công. Hỗ trợ qua Zalo: 0559 297 239.

Luận án liên quan

Chia sẻ tài liệu: Facebook Twitter