Download as pdf or txt
Download as pdf or txt
You are on page 1of 34

System Design & Development

2
System Design & Development

Aircraft systems
more complex & Increasingly
sophisticated for difficult
technology and development
performance process
reasons
Need to capture/cover:
• All system requirements
• Interdependencies between systems
• Safety and integrity analyses
• Analytical activities

Regulations – Development Process - Analyses

3
Feed-pump fuel system
System Design
Key Agencies & Documentation

SAE Aerospace Recommended Practice (ARP) 4754, 4761

FAA Advisory Circular (AC) 25.1309-1A

EASA Acceptable Means of Compliance (AMC) 25.1309

Air Transport Association (ATA) standard ATA-100

Radio Technical Committee Association (RTCA) Document


(DO) DO-178b, etc

USED BY AIRCRAFT & SYSTEM DESIGNERS


TO SATISFY MANDATORY REQUIREMENTS

4
Feed-pump fuel system
System Design
Design Guidelines & Certification Techniques
set of tools and
Military Aircraft techniques

Def Stan 00-970


set of design
processes

Guidance for
hardware design
& development

Advice for
software design
& certification

5
Feed-pump fuel system
System Design
Design Guidelines & Certification Techniques
SAE ARP 4754 – System Development Processes
• System Development
• Certification process & coordination
• Requirements determination & assignment of development
assurance level
• Safety assessment process
• Validation of requirements
• Implementation verification
• Configuration management
• Process assurance
• Modified aircraft

6
Feed-pump fuel system
System Design
Design Guidelines & Certification Techniques
SAE ARP 4761 – Methodologies & Techniques
• Functional Hazard Assessment (FHA)
• Preliminary System Safety Analysis (PSSA)
• System Safety Analysis (SSA)
• Fault Tree Analysis (FTA)
• Dependency Diagrams
• Markov Analysis (MA)
• Failure Modes & Effects Analysis (FMEA)
• Failure Modes & Effects Summary (FMES)
• Zonal Safety Analysis (ZSA)
• Common Mode Analysis (CMA)
• Contiguous safety assessment process example

7
Feed-pump fuel system
System Design
Design Guidelines & Certification Techniques
DO-178B Overview Design Assurance for Airborne Software
• Introduction
• System Aspects relating to Software Development
• Software Life Cycle
• Software Planning Process
• Software Development Process
• …

DO-254 Overview Design Assurance for Airborne Electronic Hardware


• Introduction
• System Aspects of Hardware Design Assurance
• Hardware Design Life Cycle
• Planning Process
• …

8
Feed-pump fuel system
System Design

9
Feed-pump fuel system
System Design
Requirements Capture

Key activity in identifying and qualifying all necessary


strands of information which contribute to a complete and
coherent system design.

Different ways to do that:


• Top-down approach
• Bottom-up approach

10
Feed-pump fuel system
System Design
Requirements Capture: Top-down Approach

smaller functional modules

functional sub-modules

11
Feed-pump fuel system
System Design
Requirements Capture: Bottom-up Approach

12
Feed-pump fuel system
System Design
Requirements Capture Example

13
Feed-pump fuel system
System Design
Requirements Capture Example

System requirements from flight crew perspective:


• Need to jettison excess fuel in an emergency situation
for aircraft land under max. landing weight
• Able to jettison down to a preselected fuel quantity
• Be given indications that fuel jettison is under way

14
Feed-pump fuel system
System Design
Requirements Capture Example
Fuel quantity function: 52 probes required to measure field held in 3
Measures aircraft fuel quantity tanks
by sensing fuel in the aircraft fuel
tanks Fuel quantity calculations measure amount of
fuel which aircraft has onboard taking into
account fuel density and temperature,

Dual power supply inputs to assure availability


in event of aircraft electrical system bus bar
failure

When calculations are completed passed to


flight deck, displayed to flight crew

Fuel quantity relayed to fuel management


function so that in event of jettison the amount
of fuel onboard may be compared with preset
jettison value
15
Feed-pump fuel system
System Design
Requirements Capture Example
Fuel quantity function interfaces to:

• Fuel quantity system measurement


probes and sensors

• Flight deck multi-function displays

• Fuel management systems

• Aircraft electrical system

16
Feed-pump fuel system
System Design
Requirements Capture Example

Fuel management function:


Accepts information regarding
aircraft fuel state from the fuel
quantity function.

17
Feed-pump fuel system
System Design
Requirements Capture Example
Flight crew inputs ‘Fuel
Jettison Select’ command
and minimum fuel quantity
crew wises to have
available at end of fuel
jettison.

Fuel management
function accepts
commands for the fuel
transfer valves, fuel dump
(jettison) valves and fuel
isolation valves.

Provides ‘Open/Closed’ Two separate power


status info on fuel system inputs are received
valves to flight crew from aircraft
electrical system
18
Feed-pump fuel system
System Design
Requirements Capture Example

Fuel management function


interfaces to:

• Fuel system valves


• Flight deck displays
multifunction displays and
overhead panel
• Fuel quantity function
• Aircraft electrical system

19
Feed-pump fuel system
Development Processes
The Product Life Cycle

20
Feed-pump fuel system
Development Processes
The Product Life Cycle: Concept Phase

21
Feed-pump fuel system
Development Processes
The Product Life Cycle: Definition Phase

22
Feed-pump fuel system
Development Processes
The Product Life Cycle: Design Phase

23
Feed-pump fuel system
Development Processes
The Product Life Cycle: Build Phase

24
Feed-pump fuel system
Development Processes
The Product Life Cycle: Test Phase (Qualification Phase)

25
Feed-pump fuel system
Development Processes
The Product Life Cycle: Operate Phase

26
Feed-pump fuel system
Development Processes
The Product Life Cycle: Disposal or Refurbish

27
Feed-pump fuel system
Development Processes
Development Programme

28
Feed-pump fuel system
Development Processes
Development Programme

SRR is first top-level, multidisciplinary review of the


perceived system requirements

• Sanity check upon what the system is required to achieve


• Top level overview of requirements
• Review of against original objectives

Successful attainment of this milestone leads to a preliminary


system design,

leading in turn to the parallel development of the hardware


and software requirements analysis, albeit with significant
coordination between the two.

29
Feed-pump fuel system
Development Processes
Development Programme

Hardware SDR immediately follows


the preliminary design phase and

will encompass a top-level review of


system hardware characteristics
such that preliminary design may
proceed with confidence

Key hardware characteristics will be


reviewed at this stage to ensure that
there are no major mismatches
between the system requirements
and what hardware can support.

30
Feed-pump fuel system
Development Processes
Development Programme

Software Specification Review


SSR essential similar process to
hardware SDR but

applying to software when a better


appreciation of software
requirements has become apparent
and possibly embracing any
limitations such as: throughput,
timing or memory which the adopted
hardware solution may impose

Both SDR and SSR allow the


preliminary design to be developed
up to the Preliminary Design Review
(PDR)

31
Feed-pump fuel system
Development Processes
Development Programme

Preliminary Design Review (PDR)


reviews process in the first detailed
review of the initial design
(hardware & software) vs derived
requirements

This is usually the last review before


committing major design resource to
the detailed design process.

This stage in the design process is


the last before major commitment to
providing the necessary programme
resources and investment.

32
Feed-pump fuel system
Development Processes
Development Programme
By the time of the CDR major effort
will have been committed to the
programme design effort.

Critical Design Review (PDR)


offers possibility of identifying final
design flaw, or more likely, trading
the risks of one implementation path
vs another

CDR represents the last opportunity


to review and alter the direction of
the design before very large
commitments and final design
decisions are taken.

Major changes in the system design


after the CDR will be very costly. 33
Feed-pump fuel system
Development Processes
Development Programme

Final stages following CDR will realise


hardware build and software coding and
test processes which bring together
hardware and software into the eventual
product realisations.

Even following system validation and


equipment certification it is unusual for
there to be a period free of modification
either at this stage or later in service when
airlines may demand equipment changes
for performance, reliability or maintainability
reasons.

34
Feed-pump fuel system
Development Processes
‘V’ Diagram

35
Feed-pump fuel system

You might also like