Download as pdf or txt
Download as pdf or txt
You are on page 1of 6

Fault Tree Analyses as a Tool for Flight Control System

Architecture Design
Estella Chung, Woodward, Inc.
John S. Hanks, Woodward, Inc.

Key Words: Fault Tree Analysis (FTA), Loss of Function (LOF), Failure to Dispatch (FTD), System Safety

SUMMARY & CONCLUSIONS


Woodward Inc. was tasked with evaluating several flight
control rotorcraft requirements to derive an architecture that
would best support those requirements. Each architecture was
assessed using various models, including a fault tree model, to
determine if failure rate allocations to the partitions would
support the needed availability and safety performance. An
optimal system architecture was developed that would meet
regulatory compliance for system safety [1, 2] given
constraints such as cost, weight, envelope, and complexity.
System Safety was the primary driver considered in the
development phase of the Fly-By-Wire (FBW) project. The
designs consist of Flight Control Computer (FCC) electrical
Figure 1. Rotorcraft FBW Flight Controls
lanes that interface with main and tail rotor electrohydraulic
servoactuators. modeling of the system and used to determine levels of system
The system concept designs evaluated involved traditional safety that ensures risk to people and equipment is as remote
and hybrid architectural schemes for functional redundancy or improbable as possible. The fault tree is a top-down
and operation. The options included duplex, triplex, quadruplex approach used to identify the propagation of failures across
control channel redundancy and various combinations of system partitions for each undesirable event, as well as the
electrical, mechanical, or hydraulic connections. probability for a combination of events that lead to the
A primary system safety analysis tool in the decision undesirable event to occur over a given flight mission time.
making process for the optimal system architecture in this Fault tree model results help determine if the system safety
application was the Fault Tree Analysis (FTA). The FTA requirements are met or optimized. If not met satisfactorily,
model provided both a visual qualitative tool to validate the system architecture models are revised, and the systematic
proper system logic and a quantitative tool [3] to validate process of analyzing the system is repeated until the
probability of Loss of Function (LOF) and Failure to Dispatch requirements are met.
(FTD). While Woodward also applies this process to fixed- High priority safety requirements are drivers in flight
winged aircraft, the focus of this study was a FBW rotorcraft vehicle applications. Risk assessment is necessary to quantify
flight control platform (see Figure 1). The result of this study the risk of LOF or FTD of a flight vehicle leading to total loss
found that a hybrid Dual-Triplex architectural scheme proved or degraded performance for a given concept system
optimal given the project constraints. This Dual-Triplex architecture. Once system partitions are defined and isolated
architecture consists of four FCC channels through triplex for an architecture concept, the fault tree is used to understand
control lanes to dual electrohydraulic servoactuators. allowable failure rate probabilities that support the system
safety objective pertaining to hazard protection. Risk
1 INTRODUCTION
assessment includes quantifying risk by assigning probabilities
This study illustrates how upfront collaboration between to basic events in the fault tree and then propagating these
Reliability, System Safety, and System Engineering probabilities to determine the final probability of the undesired
disciplines is crucial during the system architecture concept event. The risk assessment is also used to identify the major
development phase to enable the realization of a successful contributing elements. Anomalies leading to LOF or FTD are
system. considered for electrical components such as electrohydraulic
A fundamental reliability tool used in this study was the servovalve (EHSV) coil and solenoid coil failures, mechanical
FTA. The FTA was performed in early design risk assessment failure modes such as valve spool/sleeve jams and single point

,(((
failure mechanisms, and control issues such as force fighting The EHSV is a two-stage valve design with a LVDT to
between actuator stages. sense second-stage spool position. The EHSV incorporates a
The FTA is only one of several assessment tools. Other multi-coil torque motor. Each coil is independently con-
modeling tools include system architecture diagrams depicting trolled. There are two EHSVs and each controls flow to one
the partitions in the system, closed-loop control system block side of the actuator in response to electrical control signals
diagrams, and logic tables. While the closed-loop control from the FCCs. Each EHSV contains a C1 port that flows to
system block diagrams and logic tables are not a focus of this the extend port of the cylinder and a C2 port that flows to the
paper, both tools were used alongside the FTA in the final retract port.
decision making process. The de-activated solenoid operated bypass valve is spring
Other trade study criteria include basic reliability, loaded to interconnect the actuator cylinder chambers in the
interface complexity, relative weight, and relative cost. bypass state. The bypass valve is commanded to the operate
The flight control system consists of two hydraulic state by energizing any or all of the independent solenoid
systems and two, three or four electrical systems. As a result, coils. In the operate state, porting of the hydraulic pressure
these systems are referred to as Dual-Dual, Dual-Tri, and from the EHSV to the cylinder ports to control actuator
Dual-Quad, respectively. motion is enabled.
2 SYSTEM FUNCTIONAL AND ARCHITECTURAL A differential pressure sensor is used to measure the
DESCRIPTION difference between the pressures on each side of the piston of
each hydraulic power stage. These signals provide the
The rotorcraft FBW flight control system consists of three difference between the pressures in the extend and retract
main rotor actuators connected to a swashplate. The chambers on each hydraulic power stage. The information is
swashplate is used to translate the reciprocating motion of the used to assist in balancing the force exerted by each of the two
actuators into rotating motion of the rotor blades. The cyclic cylinders to reduce the amount of force differential, thus force
stick is located between the pilots knees. This control pushes fight. When the force difference between the two systems is
one side of the swashplate upward or downward. Cyclic stick minimized, force fight is minimized. This enables improved
lateral input tilts the main rotor disk left and right through the actuator performance and a lower fatigue duty cycle on certain
swashplate, which induces rotorcraft roll to move sideways. actuator power stage components. The BPV spool position
Cyclic stick longitudinal input tilts the main rotor disk forward sensor senses whether the bypass valve is in the bypass or
and back through the swashplate, which induces rotorcraft normal operation position.
pitch to move forward and backwards. The collective stick is Multi-coil LVDTs are used to measure actuator output
located on the pilots left side. The collective stick input piston position. Each LVDT channel is electrically, but not
equally increases or decreases the pitch angle of all main rotor mechanically, independent.
blades, which provides rotorcraft ascend and descend. The actuator converts hydraulic pressure and flow into
The tail rotor actuator is controlled by the pilots pedals linear force and motion to provide rotorcraft main and tail
and provides rotorcraft yaw that induces the direction the nose rotor actuation control.
of the aircraft is pointed by increasing or reducing the thrust of
the tail rotor blades. 2.2 Dual-Dual Architecture
2.1 Electrohydraulic Servoactuator The Dual-Dual design represents a baseline against which
other options can be measured [4]. The Dual-Dual design
There are two redundant hydraulic supplies that each schematic depicts two hydraulic systems and four electrical
control hydraulic flow to one side of the dual-tandem piston/ control lanes partitioned among four different FCCs as shown
cylinder (actuator) as shown in Figure 2. in Figure 3. Two electrical lanes are associated with each
hydraulic system. FCC1 and FCC2 are dedicated to system 1
and FCC3 and FCC4 are dedicated to System 2. Each of the
four FCCs share data with the other three FCCs across the
shared data bus. In this trade study, comparison of probability
of LOF of an actuator (Figure 4) and the probability of FTD
(Figure 5), with a minimum of three of the four control
channels available, are studied. The FTD hazard can be
modeled by using a two-of-four voting gate for the FTA where
Figure 2. Dual-Tandem Piston/Cylinder Actuator
one failure can be tolerated.
There are four redundant FCCs that provide redundant The benefit of this architecture is that it is the simplest of
electrical interfaces to the two sets of EHSV coils, solenoid- the three architectures in terms of cost, weight, and
bypass valve (SO-BPV) coils, linear variable differential complexity. The disadvantage is when operating in a state
transformer (LVDT) position feedback on the EHSV spool, where one FCC fails, the system is only two faults away from
differential pressure/bypass valve sensor feedback, and LVDT a catastrophic hazardanother FCC fails on the same
position feedback on the actuator ram position. hydraulic system and the remaining hydraulic systems
Figure 3. Dual-Dual Functional Schematic

Figure 4. Dual-Dual LOF FTA Figure 5. Dual-Dual FTA FTD


hydraulic or electrical supply fails. This is a marginally FCCs across the shared data bus. In this trade study,
acceptable risk. The probability of LOF is the highest of the comparison of probability of LOF (Figure 7) of an actuator
three architectures. and the probability of FTD (Figure 8), with a minimum of
three of the four control channels available, are studied. The
2.3 Dual-Quad Architecture
FTD hazard can be modeled by using two-of-four voting gates
The Dual-Quad design schematic depicts two hydraulic for the FTA where one failure per gate can be tolerated. Basic
systems and eight electrical lanes partitioned among four events FCC1, FCC2, FCC3, and FCC4 in System A are
different FCCs as shown in Figure 6. Four electrical control repeated in System B.
lanes and all four FCCs are associated with each hydraulic The benefit of this architecture is that it is the most
system. Each of the four FCCs share data with the other three redundant of the three architectures. There is an over-
Figure 6. Dual-Quad Functional Schematic

Figure 7. Dual-Quad LOF FTA Figure 8. Dual-Quad FTD FTA


abundance of coverage margin. When operating in a state hydraulic systems and six electrical control lanes partitioned
where one FCC fails, the system is four faults away from a among four different FCCs as shown in Figure 9. Three
catastrophic hazardthree FCCs must fail and the remaining electrical lanes are associated with each hydraulic system.
hydraulic systems hydraulic or electrical supply must fail to FCC1 is dedicated to System 1 only and FCC4 is dedicated to
lead to a total loss of control. This architecture will offer the System 2 only. FCC2 and FCC3 are used in both systems.
lowest probability of total loss. The disadvantage is that it has Each of the four FCCs share data with the other three FCCs
the highest cost, weight, and interface complexity because it across the shared data bus. In this trade study comparison of
carries with it additional redundant coils and sensors when probability of LOF (Figure 10) of an actuator and the
compared to the other two architectures. probability of FTD (Figure 11), with a minimum of three of
the four control channels available, are studied. The FTD
2.4 Dual-Tri Architecture
hazard can be modeled by using two-of-three voting gates for
The Dual-Tri architecture is the preferred innovative approach the FTA where one failure per gate can be tolerated. Basic
for the rotorcraft. The Dual-Tri design schematic depicts two events FCC2 and FCC3 in System A are repeated in System B.
Figure 9. Dual-Tri Functional Schematic

Figure 10. Dual-Tri LOF FTA Figure 11. Dual-Tri FTD FTA
The benefit of this architecture is that it offers an of the results of the trade study of the three architectures. The
additional control channel beyond what the Dual-Dual Dual-Dual architecture is not the best acceptably safe solution
architecture offers. When operating in a state where one FCC for the FBW rotorcraft application, but, forms a good baseline
fails, the system is three faults away from a catastrophic for further analysis. Woodward provided an alternative viable
hazardtwo FCCs must fail and the remaining hydraulic option in the Dual-Tri architecture that demonstrates by FTA
systems hydraulic or electrical supply must fail to lead to a that there is no degradation of probability of LOF versus the
total loss of control. Along with the Dual-Quad this Dual-Quad option. In addition, the probability of FTD is the
architecture offers a lower probability of LOF compared to the lowest of the three options. Based on fewer parts associated
Dual-Dual architecture. In addition, the Dual-Tri offers the with fewer channels for the Dual-Tri architecture, the basic
lowest probability of FTD. reliability, complexity, weight, and cost are all favorable
versus the Dual-Quad. The FTA validates that system safety
3 SUMMARY
for probability of LOF is not compromised with a Dual-Tri
Analyzing a conceptual design in the earliest stages of the architecture option and further provides many other benefits
system development lifecycle allows for early design risk for a more efficient flight control system.
assessment of system scenarios. Table 1 illustrates a summary
Table 1. Summary Table of Architecture Trade Study Results
several patents for Woodward as co-inventor for methods to
REFERENCES
improve control of brushless DC motors. She joined
1. SAE ARP4754, Certification Considerations for Highly- Woodwards System Engineering Department in 2014. She
Integrated or Complex Aircraft Systems. holds a Bachelor degree in Electrical Engineering from
2. SAE ARP4761, Guidelines and Methods for Conducting UCLA.
the Safety Assessment Process on Civil Airborne Systems
John S. Hanks, PE
and Equipment.
Woodward
3. John Andrews, Introduction to Fault Tree Analysis.
25200 W. Rye Canyon Road
2015 Annual Reliability and Maintainability Symposium.
Santa Clarita, California 91355 USA
4. G. Jacazio, P. Serena Guinzio, and M. Sorli, A Dual-
Duplex Electrohydraulic System for the Fly-By-Wire e-mail: John.Hanks@Woodward.com
Control of a Helicopter Main Rotor, 26th International
Mr. Hanks is a Reliability Engineer Analyst for Woodward.
Congress of the Aeronautical Sciences, ICAS 2008.
He has worked at Woodward for over 27 years. His expertise
BIOGRAPHIES is in hydraulic aircraft servo controls and electromechanical
flight controls. These analyses include development,
Estella Chung
production, and test activity for military and commercial
Woodward
programs. Over his 27-year tenure with Woodward he has
25200 W. Rye Canyon Road
accumulated over 12 years of Reliability and Maintainability
Santa Clarita, California 91355 USA
Engineering experience. John also has Test Engineering,
e-mail: Estella.Chung@Woodward.com Project Engineering, and Operations Management experience.
He has received several Corporate Innovation Awards and
Ms. Chung is a Systems Engineer for Woodward. She joined
holds a patent for improvement in systems product testing.
Woodward in 1991 as an Electronics Engineer in the
Mr. Hanks is a Certified Reliability Engineer, Registered
Electronics Flight Control Group. She has over 24 years of
Professional Engineer, and Six Sigma Master Black Belt. He
experience in design, development, testing, and production of
holds a Bachelor degree in Mechanical Engineering and a
electronic control systems for electromechanical actuation
Masters degree in Engineering from California State
systems for several military and commercial programs. She
University, Northridge.
has received several Corporate Innovation Awards and holds

You might also like